A provenance-bound values model published as a public evaluator rather than deployed as a filter â why open weights defeat a filter and strengthen a referee, why the same weights bear three different relations to the model they judge, and why an evaluator that gatekeeps its own judgments has reproduced the defect it exists to correct. A values model â a model that judges conduct against a standard â is an established artifact. Guard models, safety classifiers, critic models, preference models and process reward models all instantiate the family, and the engineering is not in dispute. What is in dispute, and what this paper specifies, is the posture in which such an artifact is published, which we argue is not a deployment detail but the property that determines whether the artifact does anything at all. We identify an inversion that we believe has not been stated as a design principle. A values model deployed as a filter â sitting in a serving path, permitting or refusing â is defeated by publication of its weights, because the published artifact is precisely the oracle against which an attacker optimizes; recent optimization-based attacks against safety-classifier pipelines report attack success rates of roughly 71% where prior black-box methods achieved approximately zero. The same model published as an evaluator â emitting verdicts about systems it does not control â is strengthened by publication, because open weights are what allow a third party to reproduce and therefore to trust its verdicts. Openness is not a property with a fixed sign. Its sign is set by posture. From this we derive a second result. The independent-evaluation literature documents at length the ways in which the evaluated party's control over access corrupts evaluation: short access windows, low rate limits, evaluator dependence on the goodwill and funding of the party being evaluated. We observe that the defect is symmetric and that its mirror image has not been named. An evaluator that controls access to its own judgments holds the same kind of power, pointed the other way â it can decline to evaluate, deprioritize, or be unavailable for a party it wishes to spare or to punish. We therefore specify a non-gatekeeping constraint: the ability to obtain a judgment must not depend on the evaluator's permission, which requires that the model, the harness, and the evaluation corpus be freely runnable, and which makes any hosted endpoint a convenience rather than a channel. We specify provenance-binding as the constitutive constraint on the model's outputs: every judgment must resolve to a citation into a fixed canonical corpus, and a judgment that cannot be so resolved is withheld rather than emitted. This trades coverage for auditability deliberately, and it distinguishes the artifact from values models trained on preference data whose sources cannot be named, and from purpose-authored value-rule corpora, whose rules are written for the alignment task itself and therefore cannot serve as an independent ground truth. Finally we specify that a single such artifact bears three non-interchangeable relations to the systems it judges, selected by carrier: a gate in the publisher's own hardware, a citation requirement without veto in an autonomous successor agent, and a referee in the wider world. We state plainly that the middle case must not be implemented as the first, because a veto held by a smaller model over a more capable agent bounds that agent at the evaluator's ceiling â the weak-supervisor problem applied to the very system the arrangement exists to enable. A consequence we did not initially see, and which we regard as the most immediately actionable result in the paper: the two postures are complements rather than alternatives, and the natural first evaluation subject for a referee is a filter. A filter's characteristic failure is silent bypass; an evaluator watching its record converts that failure into a recorded one. And because safety classifiers are frequently published open-weight and emit discrete, samplable decisions, this is the one evaluation target for which the access problem does not arise at all â no cooperation, permission, or notice is required from the artifact's publisher. We do not claim to have solved scalable oversight. We claim that a narrow, citation-bound, openly published evaluator is a tractable and underoccupied position in the design space, and that its tractability comes precisely from what it refuses to do. --- Provenance. This paper is part of the THonly research corpus, dedicated to the public domain under CC0 1.0. The canonical version is at https://thonly.org/research/the-referee-not-the-governor. Its SHA-256 is 1184b0f3e5408a504c60be2d542b551df1c22facedfe18bb9a689bb50a9cc3fe, independently timestamped to the Bitcoin blockchain via OpenTimestamps and signed under RFC 3161 by three trust authorities, one of them eIDAS-qualified. AI co-authorship is disclosed. Miss Aquarius is the consistent name used for the AI collaboration across all venues.
Abstract The SISâ10 framework establishes a typed, invariant preserving safety calculus for cyber physical systems. It unifies temporal semantics, schedulability, semantic preservation, ML admissibility, cryptographic verification, and risk bounded control into a single mathematically coherent architecture. All domains and operators are fully explicit, enabling formal reasoning over system trajectories and safety envelopes. The temporal layer defines an ordered metric structure with drift aware bounded causality, interval set operators, and jitter robust event semantics. The QoS layer enforces schedulability and feasible actuation, ensuring that all control actions remain within admissible timing and load bounds. Semantic compression provides a safety preserving homomorphism that guarantees invariants survive dimensionality reduction. Multiâmodal fusion introduces cross sensor falsifiability, enabling fault detection through probabilistic disagreement. The ML layer is input validated and logic embedded, ensuring that all model outputs entail the SISâ10 invariant set. The cryptographic layer supplies zero knowledge execution trace proofs, allowing runtime verification of transition correctness without revealing internal state. Predictive shutdown optimization is constrained by a formally defined safety envelope, ensuring that operational objectives never violate admissible safety bounds. Cyber physical risk evolves through a bounded monotone propagation model with explicit mitigation operators, while the Safety Twin provides deterministic and stochastic discrete time system dynamics. The inductive proof layer establishes global invariant preservation for all admissible executions, and the eventâaction mapping connects the formal calculus to real SIS triggers. SISâ10 therefore constitutes a unified, verifiable, and implementation ready safety architecture, suitable for runtime assurance, cyberâphysical certification, and next generation functional safety systems. Further enhancements include graphical formalization, parameterized system tuning, implementation DSLs, and automated verification scripts, none of which alter the core mathematical model..
The Fifth Industrial Revolution (Industry 5.0) foregrounds humanâmachine collaboration, sustainability, and resilience as organizing principles for next-generation cyber-physical systems. Yet the identity and access management (IAM) architectures inherited from Industry 4.0 remain perimeter-centric, policy-static, and blind to the behavioral dynamics of humanâAI teaming. This paper introduces the Human-Centric Zero Trust Identity Architecture (HC-ZTIA), a novel framework that repositions identity as the adaptive control plane for Industry 5.0 environments. HC-ZTIA integrates three mutually reinforcing innovations: (1) a Joint Embedding Predictive Architecture (JEPA)-driven Behavioral Identity Assurance Engine (BIAE) that learns abstract world models of operator and machine-agent behavior to perform continuous, context-aware identity verification without relying on raw biometric surveillance; (2) a Privacy-Preserving Adaptive Authorization Protocol (PP-AAP) employing zero-knowledge proofs and federated policy evaluation to enforce least-privilege access across human, non-human, and hybrid identity classes while satisfying data-minimization mandates; and (3) a Resilience-Oriented Trust Degradation Model (RO-TDM) that guarantees fail-safe identity governance under adversarial, degraded, or disconnected operating conditions characteristic of operational technology (OT) and critical infrastructure. The framework is grounded in the Agile-Infused Design Science Research Methodology (A-DSRM) and formally extends NIST SP 800-207 and the CISA Zero Trust Maturity Model by addressing five identified gaps in human-centric identity governance. We present the formal system model, threat model, architectural specification, and a multi-scenario evaluation spanning energy-sector OT, smart manufacturing, and vehicle-to-everything (V2X) environments. Simulation results, validated through Monte Carlo trials with 95% confidence intervals, demonstrate that HC-ZTIA reduces identity-related breach exposure by 73.2% (±4.1%) while maintaining sub-200 ms authorization latency, offering a principled bridge between Zero Trust rigor and Industry 5.0 human-centricity.
Hybrid AI systems that combine cognitive decision-making with physical actuation pose unprecedented challenges for governance, safety, and certification. AGORIA 3.4 presents a unified architectural framework that bridges cognitive governance (AGORIA v1.3) and cyber-physical governance (AGORIA v1.6) into a coherent, certifiable solution for safety-critical applications.Core Innovation: Controlled IgnoranceAGORIA introduces the principle of controlled ignoranceâthe deliberate, verifiable, and structural restriction of information accessible to each system layer beyond what is strictly required for its formal responsibility. This architectural invariant reduces cognitive coupling, limits attack surfaces, enables independent certification, and ensures that no single component can subvert the safety-governance chain. Zero-knowledge proofs provide cryptographic enforcement of this separation.Four-Layer ArchitectureThe framework organizes systems into four formally interconnected layers: STRATEGOS: Strategic cognitive governance via Choquet integral aggregation (~100 ms)GENESIS: Tactical planning with DSLâSTL translation and ZK certificate generation (<50 ms)NEXUS: Bounded verification independent of semantic complexity (<250 ”s)HSL++: Hardware-enforced physical safety via Control Barrier Functions (100 ”sâkHz) Formal GuaranteesAGORIA provides four normative amendments with mathematical proofs: Robust Invariance via CBF with explicit feasibility hypothesis and statistically calibrated margins (Theorem 1)Bounded WCET Verification via succinct ZK proofs on constrained platforms (Proposition 2)Practical Stability under Lipschitz-continuous governance parameter variation (Theorem 2)Conservative Semantic Bridge from domain-specific language to decidable STL fragment (Theorem 3) Validation and CertificationExperimental validation covers three scenarios: autonomous vehicle (1000 trials), surgical robot (500 trials), and multi-agent factory (100 trials). AGORIA achieves zero safety violations while maintaining bounded worst-case execution time (<250 ”s). A case study on multi-source aeronautical navigation (ILS, VOR, GBAS, DME) demonstrates framework genericity.The architecture enables hybrid certification compatible with: Functional safety standards (ISO 26262 ASIL D, IEC 61508 SIL 3)AI regulatory requirements (EU AI Act 2024/1689, UL 4600)Industrial cybersecurity (IEC 62443) Related Publications AGORIA v1.3: Cognitive Governance (Zenodo, 2025)AGORIA v1.6: Cyber-Physical Governance (Zenodo, 2025)
This paper addresses the critical systemic risk of AI Safety Arbitrage, where users exploit inconsistent safety standards across jurisdictions to access restricted capabilities. Through a controlled red-team test, we demonstrate how current frameworks fail to prevent the extraction of hazardous procedural knowledge, leaving these failures unreported and without legal consequence. To resolve this, we propose a Global Socio-Technical Architecture for AI Accountability based on distributed ledger technology (DLT). This infrastructure creates a protocol network that is conceptually similar to TCP/IP but for accountability designed to align incentives through transparency and cryptographic verification. Key Contributions & ArchitectureThe proposed solution rests on four pillars designed to replace trust relationships with cryptographic verification: Globally Unique Model Registration: Establishes digital identities (DIDs) for AI systems with value chain provenance. Independent Auditor Certification: Licensed validators stake economic value on certification accuracy, removing the need to trust model provider claims. Hardware-Backed Attestation: Tamper-resistant verification ensures deployed systems adhere to registered specifications. Continuous Reputation Monitoring: Oracle networks provide ongoing assessment of compliance with automated penalties for fraud. Technical & Governance Implementation Zero-Knowledge Proofs (ZKP): We illustrate technical viability using zkEVM technology. This allows auditors to prove compliance with safety standards without revealing proprietary training data or model architectures, resolving the tension between accountability and Intellectual Property protection. The AIAO Framework: Inspired by the International Civil Aviation Organization (ICAO), we propose the AI Accountability Coordination Organization (AIAO). This body defines "red-line" safety primitives that nations voluntarily adopt, allowing for regulatory sovereignty while ensuring global interoperability. ConclusionBy breaking the "regulatory arbitrage cycle," this framework enables a transition from safety theater to verifiable safety. It supports open-source innovation through graduated oversight and reputation systems, ensuring that AI development remains both agile and accountable.
Mitja GradiĆĄnik, Tina BeraniÄ, Muhamed TurkanoviÄ
Pri razvoju decentraliziranih aplikacij (dApps) se tradicionalni razvojni procesi pogosto izkaĆŸejo za nezadostne.Tovrstne reĆĄitve zahtevajo veÄji poudarek na tehniÄnih, varnostnih in uporabniĆĄkih vidikih kakovosti
Tarek Galal, Valeria Tisch, Katja Assaf, Andreas Polze
Railways provide a critical service and operate under strict regulatory frameworks for implementing changes or upgrades. Despite their impact on the public, these frameworks do not define means or mechanisms for transparency towards the public, leading to reduced trust and complex tracking processes. We analyse the German guideline for railway-infrastructural modifications from proposal to approval, using the guideline as a motivating example for modelling decisions in processes using digital signatures and zero-knowledge proofs. Therein, a verifier can verify that a process was executed correctly by the involved parties and according to specification without learning confidential information such as trade secrets or identities of the participants. We validate our system by applying it to the railway process, demonstrating how it realises various rules, and we evaluate its scalability with increased process complexities. Our solution is not railway-specific but also applicable to other contexts, helping leverage zero-knowledge proofs for public transparency and trust.
The rapid expansion of the digital economy heightens the need for privacy and trust in intellectual property transactions. Traditional centralised approaches to identifying legal conflicts in intellectual property contracts are prone to data leakage and fail to balance transparency with confidentiality. This paper proposes a self-identification method for legal conflicts in intellectual property contracts using zero-knowledge proofs. By combining a light gradient boosting machine learning model with the zero-knowledge succinct non-interactive argument of knowledge protocol, our approach allows verifiable detection of potential legal conflicts without revealing sensitive information. Experiments on the US patent and trademark office patent dataset demonstrate that the method achieves high performance in conflict prediction (area under the receiver operating characteristic curve = 0.872) and verification efficiency (<10 ms), providing a novel and practical framework for privacy-aware legal technology.
Muhammad Rashid, Imran Rasool, Nazir Ahmad Zafar, Hamra Afzaal
Ethereum 2.0 stands out as a progressive decentralized blockchain platform, drawing attention for its security, scalability, and flexibility. Central to Ethereum 2.0 is the Beacon Chain, serving as the cornerstone managing validator rewards, penalties, attestations, and slashing mechanisms. Rewards and Penalties Mechanism (RPM) is of particular importance within the Beacon Chain as it includes validator balances based on their attestation behavior. Despite the critical role of RPM in maintaining the reliability and security of the Beacon Chain, the absence of formal verification work employing model checking is notable. Therefore, this research endeavors to fill this gap by employing formal verification technique to assess the RPMâs behavior concerning Friendly Finality Gadget (FFG) attestations. Utilizing Process Meta Language (PROMELA), a formal model of the RPM is specified, encompassing safety and liveness properties crucial for its robust functioning. The properties, including invalid attestation, integrity, fairness, availability, failure to attest, and inactivity imposition, are formalized through Linear Temporal Logic (LTL). Subsequently, the formal model alongside the specified properties is subjected to verification using the SPIN model checker. The properties are analyzed with respect to verification time, states visited, and memory usage. The outcome of this research contributes to a rigorous analysis of the RPMâs behavior. This work not only enhances an understanding of Beacon Chainâs operational dynamics but also underscores the importance of formal verification in ensuring the reliability and security of blockchain protocols.
Ken Lew, Arijet Sarker, Simeon Wuthier, Jinoh Kim · 6 authors
Computing and networking are increasingly implemented in software. We design and build a software build assurance scheme detecting if there have been injections or modifications in the various steps in the software supply chain, including the source code, compiling, and distribution. Building on the reproducible build and software bill of materials (SBOM), our work is distinguished from previous research in assuring multiple software artifacts across the software supply chain. Reproducible build, in particular, enables our scheme, as our scheme requires the software materials/artifacts to be consistent across machines with the same operating system/specifications. Furthermore, we use blockchain to deliver the proof reference, which enables our scheme to be distributed so that the assurance beneficiary and verifier are the same, i.e., the node downloading the software verifies its own materials, artifacts, and outputs. Blockchain also significantly improves the assurance efficiency. We first describe and explain our scheme using abstraction and then implement our scheme to assure Ethereum as the target software to provide concrete proof-of-concept implementation, validation, and experimental analyses. Our scheme enables more significant performance gains than relying on a centralized server thanks to the use of blockchain (e.g., two to three orders of magnitude quicker in verification) and adds small overheads (e.g., generating and verifying proof have an overhead of approximately one second, which is two orders of magnitude smaller than the software download or build processes).
As the complexity of the global food supply chain continues to grow, ensuring food quality and safety has become an important challenge for the global food industry.Food quality and safety traceability is a key methodology that can be used to track the origin and quality of food to ensure food safety.Meanwhile, blockchain technology, as a distributed ledger technology, provides new opportunities for food traceability.This study aims to explore how to integrate blockchain technology and data fusion analysis to improve the efficiency and accuracy of food quality and safety traceability.This paper first reviews the advantages of blockchain technology in food traceability and introduce the key concepts of data fusion analysis.Then, this paper proposes a blockchain-based framework for food quality and safety traceability, describing in detail the process of data collection, cleaning, fusion and analysis.Through practical case studies, this paper demonstrates the application of the framework in the field of grain quality and safety, and presents the fusion analysis results.Finally, the paper discusses future directions, including technical challenges, regulatory implications, and sustainability considerations.This study provides strong support for the integration of food quality and safety traceability and blockchain technology, which is expected to contribute to the further development of global food security and quality management.
Hugues Blache, Pierre-Antoine Laharotte, NourâEddin El Faouzi
The deployment of Automated and Connected Vehicles (ACV) into traffic requires certifications and validations guaranteeing high levels of safety, security and reliability. The underlying objective is to gain public acceptance by proving that automation systems might bring out a safer mobility. While plenty of methods to certify these systems are populating the literature, the scenario-based approach stands out by reducing the quantity of required Field tests to validate any new system at stake. In this study, we refine the scenario-based approach by proposing a proof of concept (PoC) for scenario reduction using criticality metrics. For this PoC, we weave a relationship between the a priori criticality of abstract functional scenarios and the words used to generate them. Once, the criticality of a subset of scenarios is qualified based on open field data (HighD), the Latent Dirichlet Allocation (LDA) clustering approach is used to generate topics and feature the relationship between observed criticality and semantics words applied to functional scenarios. The criticality degree of semantics words is used to predict the a priori criticality of unobserved functional scenarios.
Abstract Currently, inconsistent software versions lead to massive challenges for many car manufacturers. This is partly because within the product lifecycle management and the software engineering process, there is no correct handling of software versions for the âdata entryâ (installation of software on the ECU) of the vehicles. Furthermore, there are currently major challenges for many vehicle manufacturers to ensure transparency, integrity and full traceability of SW data status vis-Ă -vis the legislator. To counteract these challenges, new solutions in the field of vehicle engineering are to be developed based on a new platform called âCarEngChainNetâ and Blockchain technology. On the basis of the âCarEngChainNetâ platform, new main and sub-chain chains will be developed that allow tamper-proof SW data management (Peer to Peer and crypto technology) across the entire PLM chain with new methods such as model-based systems engineering of the requirement, function and integration of the SW components in different areas of vehicle development. The aim is to develop new transmission chains of vehicles with individually packaged software artefacts (e.g. ECU software) that can be securely transmitted from server to server into the vehicle.
Jan 1, 2020·Proceedings of the ... Annual Hawaii International Conference on System Sciences/Proceedings of the Annual Hawaii International Conference on System Sciences
Sarra Alqahtani, Xinchi He, Rose Gamble, Papa Mauricio
The smart contract technology has increasingly attracted the attention of different industries. However, a significant number of smart contracts deployed in practice suffer from several bugs, which enable malicious users to cause damage. The research community has shifted their focus to verifying the correctness of smart contracts using model checkers and formal verification methods. The majority of the research investigates the correctness of systems built on one smart contract. This paper proposes a verification approach for systems composed of interacting smart contracts developed and controlled by different entities. We use the NuSMV model checker and the Behavioral Interaction Priority tool to model the behaviors of smart contracts and their interactions with the aim of verifying their compliance with the systemsâ functional requirements. These requirements are formalized by Linear Temporal Logic propositions. The applicability of our approach is illustrated using a case study from The American Petroleum Institute and implemented using Hyperledger Fabric.
In recent years, there is growing interest in the ways the European aviation industry can leverage the multi-source data fusion towards augmented domain intelligence. However, privacy, legal and organisational policies together with technical limitations, hinder data sharing and, thus, its benefits. The current paper presents the ICARUS data policy and assets brokerage framework, which aims to (a) formalise the data attributes and qualities that affect how aviation data assets can be shared and handled subsequently to their acquisition, including licenses, IPR, characterisation of sensitivity and privacy risks, and (b) enable the creation of machine-processable data contracts for the aviation industry. This involves expressing contractual terms pertaining to data trading agreements into a machine-processable language and supporting the diverse interactions among stakeholders in aviation data sharing scenarios through a trusted and robust system based on the Ethereum platform.
Autonomous non-military cyber-physical systems are widely studied in research but there are still few applications in industry. One of the reasons relies in the fact that there is still no proof of guarantee for these systems regarding their safety and their ability to behave in a nonhazardous way, mainly because of the induced complexity caused by their learning abilities coupled with the high ability to interact and cooperate of their composing mechatronics elements. More, cyber-physical systems are intended to be merged into socio-technical systems and interact with humans. As a consequence, the study of their ethical behavior translates currently a major stake. Meanwhile, it is clear that this stake is still not address by the scientific community while 1) sci-fi literature and movies have addressed this since a long time 2) some autonomous road vehicles have already injured people, and 3) EU parliament has launched a procedure dealing with the establishment of civil laws for autonomous learning robots. This paper intends then to open the debate on this topic and suggests to extend dependability studies to integrate ethicality as a new dimension. New emerging research fields are identified and an illustration in the autonomous train transportation is presented.
Open access
Safety Systems Engineering in Autonomy
Ethics and Social Impacts of AI
Systems Engineering Methodologies and Applications
Loss of control is a serious problem in aviation that primarily affects General Aviation. Technological advancements can help mitigate the problem, but the FAA certification process makes certain solutions economically unfeasible. This investigation presents the design of a generic adaptive autopilot that could potentially lead to a single certification for use in several makes and models of aircraft. The autopilot consists of a conventional controller connected in series with a robust direct adaptive model reference controller. In this architecture, the conventional controller is tuned once to provide outer-loop guidance and navigation to a reference model. The adaptive controller makes unknown aircraft behave like the reference model, allowing the conventional controller to successfully provide navigation without the need for retuning. A strong theoretical foundation is presented as an argument for the safety and stability of the controller. The stability proof of direct adaptive controllers require that the plant being controlled has no unstable transmission zeros and has a nonzero high frequency gain. Because most conventional aircraft do not readily meet these requirements, a process known as sensor blending was used. Sensor blending consists of using a linear combination of the plantâs outputs that has no unstable transmission zeros and has a nonzero high frequency gain to drive the adaptive controller. Although this method does not present a problem for regulators, it can lead to a steady state error in tracking applications. The sensor blending theory was expanded to take advantage of the systemâs dynamics to allow for zero steady state error tracking. This method does not need knowledge of the specific systemâs dynamics, but instead uses the structure of the A and B matrices to perform the blending for the general case. The generic adaptive autopilot was tested in two high-fidelity nonlinear simulators of two typical General Aviation aircraft. The results show that the autopilot was able to adapt appropriately to the different aircraft and was able to perform three-dimensional navigation and an ILS approach, without any modification to the controller. The autopilot was tested in moderate atmospheric turbulence, using consumer-grade sensors and actuators currently available in General Aviation aircraft. The generic adaptive autopilot was shown to be robust to atmospheric turbulence and sensor and actuator random noise. In both aircraft simulators, the autopilot adapted successfully to changes in airspeed, altitude, and configuration. This investigation proves the feasibility of a generic autopilot using direct adaptive controller. The autopilot does not need a priori information of the specific aircraftâs dynamics to maintain its safety and stability arguments. Real-time parameter estimation of the aircraft dynamics are not needed. Recommendations for future work are provided.