Skip to content
Preprint

A Safety-Driven Architectural Framework for Fail-Operational Drone Swarms in Critical Missions

Aug 2026 · 0 citations · 28 references
Engineering Computer Science

TL;DR

A mixed-criticality architectural framework that applies SAE ARP4754B methods to swarm reconfiguration, enabling intelligent swarm behaviors without compromising flight-critical isolation is proposed.

Abstract

The certification of Unmanned Aerial Vehicle (UAV) swarms for safety-critical operations requires verifiable design assurance. Airworthiness standards demand deterministic reliability, whereas multi-agent coordination algorithms execute non-deterministic models. This paper proposes a mixed-criticality architectural framework that applies SAE ARP4754B methods to swarm reconfiguration. First, a hardware-isolated Safety Monitor functions as a Run-Time Assurance (RTA) gateway, decoupling the flight-critical core from the non-deterministic Swarm Manager. Second, the monitor enforces formal safety contracts based on agent Health Vectors derived systematically from a Functional Hazard Assessment (FHA). Third, the framework propagates these Health Vectors to the collective planner to trigger fail-operational task reallocation, enabling intelligent swarm behaviors without compromising flight-critical isolation. Markov reliability modeling demonstrates that the $10^{-7}$ failures per flight hour Hazardous target is theoretically achievable for our SAIL IV scenario, provided the Safety Monitor meets $C_{monitor}>0.9991$, consistent with DAL B CMD/MON implementations.

View source

Similar papers

Preprint Aug 2026

Sensor-Driven Mission Synthesis for UAV/UGV Swarms: A TB-CSPN Coordination Architecture with Hardware-Enforced Safety

This paper presents a coordination architecture for heterogeneous UAV/UGV swarms that synthesises mission actions from uncertain, multi-modal sensor evidence while preserving hardware-enforced safety at the actuation boundary. The approach combines radar, RF, acoustic, and visual observations with Topic-Based Communication Space Petri Net (TB-CSPN) orchestration to support incremental mission formation under partial and evolving information. Consultant agents transform sensor outputs into temporally bounded semantic tokens, while supervisor agents provide authorisation and policy-governed release of mission transitions. This separation between interpretation, coordination, and execution yields auditable decision paths, constrains non-determinism within the coordination layer through guards and synchronisation, and enables bounded-time integration of heterogeneous evidence. To improve resilience in contested environments, including cyber compromise, spoofing, jamming, and communication loss, the digital coordination layer is complemented by independent analogue safety envelopes that clamp or veto unsafe actuator commands issued to individual vehicles. A coastal-surveillance case study illustrates how the proposed architecture enables dependable, governed, and physically safe swarm coordination under operational uncertainty.

Uwe M. Borghoff, Paolo Bottoni, R. Pareschi · 0 citations
Preprint Aug 2026

Agentic AI for Safety-critical Multi-drone Systems: Challenges and Opportunities

It is argued that agentic AI should be approached as a socio-technical design problem, where interfaces, oversight mechanisms, and evaluation practices are as critical as algorithms.

Timothy Merritt, Alejandro Jarabo-Peñas, Juan Bravo-Arrabal et al. · 0 citations
Open access Aug 2026

An Adaptive Six-Layer Safety Bubble for Non-Cooperative UAV Self-Separation

The integration of unmanned aerial vehicles (UAVs) into shared airspace requires on-board safety mechanisms for self-separation without cooperation between platforms or centralised air-traffic services. This paper proposes the UAV Safety Bubble (USB), which is a six-layer geometric model that defines an adaptive safety envelope around the UAV. Each layer corresponds to a distinct physical contribution: platform dimensions, positioning uncertainty, communication performance, wind disturbance, detection-processing latency, and avoidance manoeuvrability. The model was evaluated through 5300 closed-loop Monte Carlo simulation instances across six conflict scenarios: static-obstacle avoidance; head-to-head encounters; 90°, 30°, and 60° approaches between two dynamic UAVs; and a non-reacting-intruder case. Platform, sensing, communication, and environmental parameters were sampled from uniform distributions across operational ranges. Under these simulation assumptions, no instance produced an intrusion into the fifth layer (USB5), which was the model’s operational separation boundary. The smallest clearance between the USB5 outer edge and the obstacle’s centre of mass was 35.36 m, recorded in the 90° approach scenario, and the one-sided 95% upper bound on the composite intrusion probability over the 1000 independent parameter sets was 0.299%. The adaptive envelope achieved this at per-scenario median route-length overheads of 15–46% relative to nominal straight-line routes. The USB complements downstream planners by providing an adaptive no-go region. The avoidance manoeuvres evaluated are restricted to the horizontal plane; full 3D avoidance is left for future work.

Dominik Jerinić, T. Radišić, Karolina Krajček Nikolić et al. · 0 citations
Conference Aug 2026

State-Adaptive Autonomous Drone Systems for Energy Infrastructure Inspection

The increasing use of Unmanned Aerial Vehicles (UAVs) in energy-sector operations- such as pipeline inspection, infrastructure monitoring, and remote asset surveillance- has highlighted critical limitations in predominantly manual and semi-automated drone systems. While current UAV deployments offer improved safety and efficiency over traditional inspection methods, their dependence on continuous human control and stable communication links restricts scalability, resilience, and operational autonomy in complex or hazardous environments. This paper presents a conceptual framework for (state) adaptive autonomous UAV systems designed to address these limitations. The proposed approach emphasizes the integration of intelligent sensing, perception, decision-making, control, and communication as coordinated layers capable of adjusting to changing operational conditions. Rather than focusing on specific implementations, the framework outlines how autonomy-driven design principles can enhance UAV reliability, reduce human intervention, and improve operational continuity in energy-sector applications. By positioning autonomy as a critical enabler rather than an optional feature, this work aligns with ongoing digital transformation and energy transition efforts. The paper discusses potential application scenarios within oil and gas, power infrastructure, and renewable energy systems, and highlights key challenges related to regulation, system validation, and future deployment. The proposed framework provides a foundation for further research and development toward resilient, intelligent UAV operations in the evolving global energy landscape.

G. I. Akanbi, O. Kolade, S. Akande et al. · 0 citations
Open access Jul 2026

Cyber-resilient flight architecture for software-defined UAVs using digital twin-based validation

Software-Defined Unmanned Aerial Vehicles (SD-UAVs) rely heavily on software control and networked communication, making them vulnerable to cyber-physical attacks that threaten flight safety and mission reliability. Traditional UAV security approaches are largely reactive and lack integrated resilience mechanisms capable of sustaining stable flight under adversarial conditions. This study proposes a cyber-resilient flight architecture that integrates software-defined control, AI-driven anomaly detection, and Digital Twin-based validation. A Long Short-Term Memory (LSTM) model was implemented for telemetry anomaly detection, while SHAP-based Explainable AI was used to ensure interpretable resilience decisions. The system was implemented using Pixhawk 6X hardware, NVIDIA Jetson Orin Nano processing, MAVLink communication, and a Gazebo Garden + ROS2 Humble simulation environment. A Lyapunov-based stability analysis was conducted to validate the 50 m synchronization loop. Comparative evaluation demonstrated improved anomaly detection latency, reduced false detection rates, faster recovery time, and lower trajectory deviation compared to a conventional UAV architecture. The proposed system maintained stable flight under simulated cyberattack scenarios including command manipulation and sensor perturbation. The integration of Trustworthy AI with digital twin validation enhances UAV resilience, operational safety, and adaptive recovery under cyber threats, providing a scalable framework for secure autonomous flight systems.

I. Emeto, A. Adamu, I. Ezeh et al. · 0 citations
Aug 2026

An integrated operational safety assurance method for reconfigurable flight control systems based on uncertainty quantification and resilience decision-making

The dynamic reconfigurability of civil aircraft flight control systems (FCS) enhances mission adaptability yet introduces significant operational uncertainty. Traditional static safety assurance methods often fail to cope with such real-time variations. To address this, this paper proposes an integrated safety assurance framework that synergistically combines uncertainty quantification, resilience engineering, and multi-criteria decision-making. First, this paper establishes a multidimensional uncertainty ontology encompassing environmental, system-internal, human–machine, and reconfiguration factors, which is quantified using hybrid probabilistic graphical models. Building on this foundation, this paper develops a closed-loop resilience architecture that embeds the four core capabilities of resilience engineering (anticipating, monitoring, responding, learning) to enable dynamic risk perception and adaptive reconfiguration. Specifically, this paper utilizes a time-evolving multi-attribute utility function coupled with online optimization to support worst-case-oriented robust decision-making. Central to the approach is a time-evolving multi-attribute utility function coupled with online optimization, which supports worst-case-oriented robust decision-making. Validation through a dual-disturbance scenario (severe weather and sensor degradation) demonstrates significant improvements in decision quality and operational resilience. Compared with a traditional fault tree analysis (FTA) baseline under identical simulation settings, the proposed framework demonstrates up to a 25%–35% improvement in the timeliness of risk state identification and an approximately 30–40% enhancement in decision robustness under sensor degradation and dynamic environmental uncertainty.

Wenshen Peng, Jun-Ran Wang, Kai Xue et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.