K05 assurance architecture
Sensor and model disagreement cannot directly control force
Direct answer
Physical-security autonomy separates sensing, classification, access denial, non-destructive protection, authorized responder routing, and any force-enabled response into independently governed layers.
Claim
Physical-security autonomy separates sensing, classification, access denial, non-destructive protection, authorized responder routing, and any force-enabled response into independently governed layers.
Argument
No single model or sensor should convert uncertain perception into destructive action, and technical confidence does not create legal authority.
Evidence requirements
- multi-sensor confidence record
- sensor-health evidence
- disagreement policy
- access-control tests
- authorized responder interface
- force-authority record where applicable
- runtime assurance tests
Assurance defeaters
- single-sensor dependency
- unknown object class
- compromised clock
- adversarial input
- missing authority
- unsafe collateral envelope
Hazards
- misclassification
- harm to authorized personnel
- airspace interference
- fratricide
- unauthorized force
Recovery objectives
- degrade to tracking and delay
- notify authorized responder
- preserve sensor evidence
- disable suspect actuator path
Site-tailoring questions
- site perimeter
- airspace environment
- public access
- authorized federal support
- local emergency response
Sources and record
DoD Directive 3000.09 — Autonomy in Weapon Systems · Restricting Drones Near Critical Infrastructure Sites — Proposed Rule · 6 U.S.C. § 124n — Protection of Certain Facilities and Assets from Unmanned Aircraft · 47 U.S.C. § 333 — Willful or Malicious Interference