Machine-speed protection doctrine
Autonomous Defense Strategy
Direct answer
Autonomous defense is a layered control system, not an unconstrained agent. It observes continuously, reasons across cyber and physical context, selects only actions already allowed for the present authority and confidence state, verifies effect, preserves evidence, and falls back safely when context or trust fails.
Action tiers
| Tier | Permitted public concept | Required control |
|---|---|---|
| Observe | Collect, correlate, classify, and preserve telemetry. | Source integrity, privacy scope, time synchronization, and evidence retention. |
| Recommend | Generate prioritized defensive options and predicted physical consequences. | Explainability, confidence, alternatives, and conflict disclosure. |
| Contain | Apply reversible internal actions such as session revocation, route restriction, workload isolation, or service migration. | Pre-authorization, blast-radius limits, safety-envelope check, rollback, and signed record. |
| Protect | Invoke tested fail-safe modes, protected shutdown, islanding, barrier control, or alternate service paths. | Independent deterministic interlocks and consequence-aware arbitration. |
| Restore | Rebuild from verified state, rotate identity, validate dependencies, and return service progressively. | Clean provenance, dual validation, recovery checkpoints, and post-event review. |
| External effects | Support only a specifically authorized governmental mission package. | Competent authority, target validation, jurisdiction, deconfliction, effect limits, abort, oversight, and state responsibility. |
Autonomous-defense control loop
Failure-resistance requirements
Model compromise
Separate models from authority, isolate tools, distrust retrieved content, validate commands, and require deterministic policy enforcement outside the model.
Sensor deception
Use independent modalities, physical invariants, trust weighting, timing validation, and graceful degradation rather than single-sensor certainty.
False-positive harm
Simulate physical consequences, prefer reversible containment, protect safety functions, and encode hard limits on what automation may isolate or shut down.
Byzantine or insider behavior
Use quorum, identity-bound actions, tamper evidence, least privilege, independent monitors, and rapid revocation of compromised agents or nodes.