The Black-Box Simplex Architecture for Runtime Assurance of Autonomous CPS

The Black-Box Simplex Architecture for Runtime Assurance of Autonomous CPS
复制标题

DOI:
10.1007/978-3-031-06773-0_12
复制
发表时间:
2021-02
期刊:
--
影响因子:
--
通讯作者:
Usama Mehmood;S. Sheikhi;Stanley Bak;S. Smolka;S. Stoller
Usama Mehmood;S. Sheikhi;Stanley Bak;S. Smolka;S. Stoller
中科院分区:
其他
文献类型:
--
作者:
Usama Mehmood;S. Sheikhi;Stanley Bak;S. Smolka;S. Stoller

文献摘要

被引文献

相似文献

Simplex体系结构是一个运行时保证框架,其中控制权限可以从未经验证且可能不安全的高级加密器切换到备份基线加密器,以维护自主网络物理系统的安全性。在这项工作中,我们表明,运行时检查可以取代静态验证基线控制器的安全性的要求。这一点很重要,因为有许多强大的控制技术,如模型预测控制和神经网络控制器,在实践中工作良好,但难以静态验证。由于该方法不使用高级或基线控制器的内部信息,我们称之为黑盒单纯形结构。我们证明了该架构是安全的,并提出了两个案例研究,其中(i)模型预测控制提供了安全的多机器人协调,(ii)神经网络可证明防止碰撞的F-16飞机组,尽管控制器偶尔输出不安全的命令。
The Simplex Architecture is a runtime assurance framework where control authority may switch from an unverified and potentially unsafeadvanced controllerto a backupbaseline controllerin order to maintain the safety of an autonomous cyber-physical system. In this work, we show that runtime checks can replace the requirement to statically verify safety of the baseline controller. This is important as there are many powerful control techniques, such as model-predictive control and neural network controllers, that work well in practice but are difficult to statically verify. Since the method does not use internal information about the advanced or baseline controller, we call the approach theBlack-Box Simplex Architecture. We prove the architecture is safe and present two case studies where (i) model-predictive control provides safe multi-robot coordination, and (ii) neural networks provably prevent collisions in groups of F-16 aircraft, despite the controllers occasionally outputting unsafe commands.