Source-linked AI summary

A Survey on Trust Metrics for Autonomous Robotic Systems

Vincenzo DiLuoffo, William R. Michalson

arXiv:2106.15015v2cs.ROcs.CR

TL;DR

Autonomous robotic systems require security trust assessment across interconnected system, hardware, software, cognitive/AI, and supply-chain components, but existing metrics cover only subsets. The paper surveys and structures prior techniques, proposes Bayesian inference for computationally feasible modeling, and concludes that a holistic system trust model remains difficult while offering a foundation for developing one.

  • Problem

    Existing trust metrics do not consistently cover complete autonomous robotic systems or account for the complexity and costs relevant to holistic security assessment.

  • Method

    The paper surveys trust metrics across system layers and uses Bayesian inference as a proposed basis for representing complex system trust computationally.

  • Results

    The survey finds that existing approaches generally scale to small component sets or specific system areas rather than providing a complete holistic trust model.

  • Takeaways & Limitations

    A useful foundation for autonomous-robot security evaluation combines trust metrics spanning system, hardware, software, cognitive/AI, and supplier levels.

Abstract

from arXiv · show

This paper surveys the area of Trust Metrics related to security for autonomous robotic systems. As the robotics industry undergoes a transformation from programmed, task oriented, systems to Artificial Intelligence-enabled learning, these autonomous systems become vulnerable to several security risks, making a security assessment of these systems of critical importance. Therefore, our focus is on a holistic approach for assessing system trust which requires incorporating system, hardware, software, cognitive robustness, and supplier level trust metrics into a unified model of trust. We set out to determine if there were already trust metrics that defined such a holistic system approach. While there are extensive writings related to various aspects of robotic systems such as, risk management, safety, security assurance and so on, each source only covered subsets of an overall system and did not consistently incorporate the relevant costs in their metrics. This paper attempts to put this prior work into perspective, and to show how it might be extended to develop useful system-level trust metrics for evaluating complex robotic (and other) systems.

I. INTRODUCTION

The paper identifies a gap in holistic, computationally tractable trust assessment for autonomous robots, whose hardware, software, AI, cognitive, and supply-chain components create complex security interactions. It surveys existing approaches and proposes structured system-level assessment using internal/external trust distinctions and Bayesian modeling.

  • Research gap: No current trust-metric set fully spans autonomous robotic architectures, including system, hardware, software, cognitive robustness, and supply-chain vulnerabilities.Existing work commonly evaluates only subsets of the overall system, while autonomous robots integrate many interdependent components.
  • System complexity: Component integration can alter expected behavior and expose security side channels, motivating holistic trust metrics rather than isolated component assessments.This risk applies even when individual components work as designed.
  • Research gap: Trust evaluation must address both defining system trust and bounding computational complexity so assessments remain solvable with reasonable resources.Large numbers of interrelated variables make existing holistic approaches difficult to evaluate directly.
  • Trust concepts: Internal and external trust should be differentiated because autonomous systems can introspect about their capabilities and security before fulfilling external requests.This differs from conventional authenticate-then-authorize models, which do not introspect the decision itself.
  • Approach: Bayesian Networks are proposed as one way to represent internal system models compactly by combining evidence while limiting parent nodes to control computational complexity.The local Markov property reduces joint probabilities to a compact form and supports probabilistic inference.
  • Approach: The survey aims to organize current trust-evaluation techniques across system layers while reducing subjectivity and extending them toward autonomous robotic systems.Its scope includes system, hardware, software, cognitive/AI, and supplier-chain levels.

II. SEARCH RESULTS

The search organizes trust-evaluation literature across system, hardware, software, AI, and supply-chain dimensions. It finds useful level-specific methods but shows that conventional evaluations leave gaps, motivating a broader computationally tractable framework.

  • Search organization: Figure 1 organizes trust evaluation into system architecture, hardware, and software levels, highlighting the layered structure used to compare approaches.The figure’s three levels represent the architectural categories discussed in the search results.
  • Level-specific trust evaluation: Existing trust evaluations commonly formalize criteria for system, software, or hardware features, but these level-specific approaches can leave gaps in the overall security posture.The survey uses established evaluation standards and lifecycle criteria as pieces of a broader trust model.
  • Limitations of prior work: The literature includes recognized system-evaluation standards, but examples such as GreenHills INTEGRITY show that evaluating only software can omit services, applications, hardware, and possible side channels.The cited EAL 6+ evaluation covered only a small operating-system portion and excluded broader system architecture.
  • Search methodology: The search categorized relevant work by robot component and analyzed each contribution for alignment with the survey’s system-architecture objectives.The process used component-specific search terms and a second pass to discard unrelated findings.
  • Search organization: Figure 2 maps search results to robot components, including software and cognitive/AI layers, hardware, sensors, actuators, IoT devices, and supply-chain influences.The mapping treats cognitive or AI functionality as an explicit system component and places supply-chain effects across the architecture.
  • Holistic framework: A holistic evaluation should combine metrics for system, hardware, software, AI, and supplier levels rather than treating these dimensions independently.The paper presents this combination as a basis for security evaluation that can be extended to additional system aspects.

III. SYSTEM LEVEL TRUST EVALUATION

The survey finds that system-level trust evaluation must combine diverse assessment techniques while remaining tractable for complex autonomous robotic systems. It highlights attack paths, behavioral states, trust-resilience-agility relationships, physical protection, and safety as inputs to a holistic model.

  • System-level trust model: A holistic model should integrate attack paths, autonomous-system behavioral states, trust, resilience, agility, physical protection, and safety.These elements are identified as needed for autonomous robotic systems exposed to threats and human interaction.
  • Assessment approaches: The reviewed system-level techniques group into graph-based assessment and system security assessment, with Common Criteria and FIPS addressing complementary assurance needs.FIPS emphasizes cryptographic modules and tamper protection, whereas Common Criteria targets broader system-level assurance.
  • Graph-based assessment: Graph-based techniques identify attack paths and vulnerabilities using Bayesian networks, vulnerability scores, and exploit characteristics such as impact, cost, and difficulty.Shetty’s CRISM connects CVSS and NVD data, while attack graphs represent paths an attacker may use to reach a goal.
  • System security assessment: FIPS 140-3 provides level-dependent, independently tested security evaluation for cryptographic modules and can be extended to robotic security modules and tamper protection.Higher levels include safeguards tested against expected attack vectors, while the methodology uses known algorithm results during implementation and testing.
  • Limitations and integration: Existing assessment methods remain incomplete: detailed modeling can become computationally intractable, and available evidence supports trust without constituting a complete solution.The survey also notes that graph-based approaches can help identify comprehensive assessment areas and assign qualitative weights based on component characteristics.

IV. HARDWARE LEVEL TRUST EVALUATION

Hardware-level trust evaluation examines robotic components, IC design integrity, manufacturing vulnerabilities, and supply-chain provenance as parts of a broader security model.

  • Hardware Trust Motivation: Hardware trust must include design origin because trojans and malware can be introduced during IC design, beneath the robot’s secure operations.The hardware root of trust establishes a trusted base, but the paper argues that hardware assessment should also examine IC design provenance.
  • Design Integrity Metrics: Kimura’s hardware design metric evaluates logical equivalence, signal activity, structural architecture, functional correctness, and power consumption.These characteristics compare actual designs with expected designs, references, simulations, or tests.
  • Design Integrity Metrics: The design-integrity approach combines normalized subcategory measurements with reference design quality into a final trust measure.It also develops Error Implementation Cost to quantify, rank, and rate design errors.
  • Design Integrity Metrics: Functional correctness compares observed verification errors with total test points, producing Fintegrity between 0 and 1.Verification may range from exhaustive testing to corner and basic coverage, and the metric can be used by IC providers or consumers.
  • Scope and Limitations: The hardware design metric provides assurance for expected-versus-built validation but covers logic design only, not foundry risks or design-flaw costs.Consumers may also need additional resources to obtain the design knowledge and artifacts available to an IC provider.
  • Supply Chain and Component Trust: Hardware component trust is constrained by COTS provenance, because prototype components may behave differently in production and expose reliability or security flaws.The paper argues that loss and reward values should also be incorporated into the overall hardware trust model.

V. SOFTWARE LEVEL TRUST EVALUATION

Software-level trust evaluation surveys standards and scoring systems for vulnerabilities, then identifies how their metrics can contribute to a broader robotic-system security model. The section emphasizes impact, damage, target value, dependency relationships, and loss or reward costs as important additions.

  • Software vulnerability scoring: CVSS, CCSS, CMSS, and CWSS provide complementary metrics for known vulnerabilities, misconfigurations, misuse, and software or hardware weaknesses.CVSS is tied to NVD vulnerability records, while CCSS and CMSS address configuration and misuse vulnerabilities, and CWSS supports weakness assessment.
  • Software vulnerability scoring: Impact, collateral damage, and perceived target value emerge as the three most important attributes for calculating a trust metric.Other categories describe supporting exploit conditions, including when and where an exploit occurs.
  • Limitations: Current CVSS score-combination approaches may ignore dependency relationships between vulnerabilities and generally examine only small, software-centric portions of a system.These limitations make direct aggregation insufficient for holistic autonomous-robotic-system assessment.
  • Composed security assessment: Attack-graph approaches combine CVSS-derived probabilities with Bayesian and dynamic Bayesian networks to produce overall network-security assessments.An annotated attack graph is generated first, then used to derive a Bayesian model whose nodes represent exploit-related information.
  • Extensions for holistic trust: The proposed holistic model would add loss and reward values to existing impact and cost coefficients, although robotic-system experience is insufficient to assign all new scores.The surveyed techniques provide a basis for scoring many relevant factors, but additional validation is needed for robotics.

VI. COGNITIVE/AI LEVEL TRUST EVALUATION

Cognitive and AI trust evaluation surveys adversarial-attack models and robustness-certification techniques for autonomous robotic systems. It proposes using minimum perturbation boundaries and certified robustness measures as inputs to AI trust ratings, while noting that the field remains immature.

  • AI robustness motivation: AI robustness matters because adversarial attacks can alter autonomous robots’ object recognition, monitoring results, or behavior in uncertain environments.Examples include misclassifying a modified stop sign and inducing seemingly random behavior through adversarial reinforcement-learning policies.
  • Robustness boundaries: The lower bound is the minimum adversarial distortion required to change a target model’s prediction, while a certified boundary guarantees an attack-free region around an input.Minkowski distance measures distortion in p-norm space, including Manhattan, Euclidean, and Chebyshev distances for p=1, 2, and ∞.
  • Robustness techniques: CLEVER approximates a formal guarantee of AI robustness by finding a lower bound on adversarial perturbation and is described as attack-agnostic, scalable to large neural networks, and computationally feasible.The paper presents this as useful for understanding security limits of AI algorithms in autonomous robotic systems.
  • Robustness techniques: CNN-Cert provides certified robustness guarantees for neural networks and supports architectures including max-pooling, batch normalization, residual blocks, and general activation functions.Its formulation represents neural-network layers and bounds used for adversarial attack detection.
  • AI trust metrics: Minimum-distortion techniques can support AI implementation ratings: detecting smaller perturbations near an original input yields a higher robustness score.For CLEVER and CNN-Cert, a higher score indicates that the network is likely less vulnerable to adversarial examples.
  • Limitations: AI trust metrics and associated costs still need to be fused into a holistic model, because this evaluation area is less mature than other measures.CLEVER was validated on image data and only a limited set of adversarial examples, so broader testing is needed for a generalized solution.

VII. SUPPLY CHAIN LEVEL TRUST EVALUATION

Supply-chain trust evaluation extends security assessment beyond deployed robotic components to the vendors, processes, and AI artifacts that enter the system. The section surveys standards and supplier scorecards for integrating provenance, security practices, and supplier attributes into a holistic trust model.

  • AI supply-chain risks: AI supply-chain assessment must account for training data, adversarial-training data, robustness data, models, hosting or packaging services, and third-party components.Because AI and cognitive algorithms are relatively new in this context, supply-chain attack vectors require explicit security controls and trust metrics.
  • Supply-chain standards: ISO 28001 supplies best practices for supply-chain security assessment and an eight-step process for analyzing threats, consequences, probabilities, incidents, countermeasures, implementation, and evaluation.The associated ISO 28000 security-management framework includes policy, risk assessment, implementation, operations, and control activities.
  • Supply-chain scope: Robotic-system supply chains span complex systems with many processors, sensors, communications components, COTS hardware, and open-source software, increasing the importance of supplier security management.A supplier lacking a security-management system is described as exposed to multiple vulnerabilities.
  • Supplier assessment: Supplier assessment should include product or service quality, reliability, maintainability, organizational security planning, incident history, and related security attributes.These attributes supplement security-management practices when evaluating suppliers.
  • Supplier assessment: The SAMS framework rates eight supplier-assessment categories using color bands: blue 100–91, green 90–75, yellow 74–51, and red 50–0.The scorecard is presented as a supplier-trust assessment approach associated with SAP and Northrop Grumman.
  • Holistic supply-chain model: Combining system, hardware, software, and cognitive layers with supply-chain metrics captures component origins and reveals risk before deployment.The holistic model associates supply-chain trust metrics with components across all four robotic-system layers.

VIII. ASSESSMENT TECHNIQUES

The paper surveys attack graphs, fault trees, Petri nets, and Bayesian networks as security-assessment techniques, comparing their modeling strengths and scalability limitations. Bayesian networks support probabilistic inference and uncertainty reasoning, while other techniques face limitations such as state-space explosion or incomplete autonomous-system coverage.

  • Assessment Techniques: Assessment techniques range from manual checklists to automated static and dynamic visualization, but manual evaluation becomes unsuitable as system complexity and accounting requirements grow.The survey presents these methods as having different trade-offs rather than a single universally sufficient technique.
  • Attack Graphs and Trees: Attack graphs and trees visually represent attack paths from assets to targets using connectivity, exploits, and preconditions, but require extension for autonomous robotic security architecture.The paths can be ranked from attacker to target using host and network connectivity information.
  • Fault Trees: Fault trees use Boolean gates in top-down failure analysis, while MOCUS deterministically enumerates cut sets to calculate top-event probabilities with fewer resources.Large fault trees remain limited because complex systems require enumerating many possible failure sequences.
  • Petri Nets: Petri nets model concurrent control-flow behavior and dependencies, but complex systems can become analytically intractable through exponential state-space explosion.Their reachable markings grow rapidly as the modeled system becomes more complex.
  • Bayesian Networks: Bayesian networks reason about uncertainty and update posterior system-state probabilities when new evidence, including sensor observations, is available.They use conditional dependencies and probabilistic inference to support autonomous robotics assessment.
  • Bayesian Networks: Bayesian networks compactly encode joint distributions and support causal inference, although constructing them lacks a standard method.Their inference efficiency is presented as an advantage over general-graph reasoning, which is NP-hard,,.

IX. A SOLUTION OUTLINE

The proposed solution combines system, hardware, software, AI-robustness, and supply-chain trust metrics into a holistic model. Bayesian networks make this multi-layer assessment more computationally feasible by factorizing joint probabilities and supporting inference from observations.

  • Holistic Trust Model: The model combines system, hardware, software, cognitive/AI, and supply-chain layers into a holistic autonomous-robotic-system trust model.It is intended to address gaps in prior approaches that did not cover complete systems or consistently include cost values.
  • Novelty and Scope: The proposed Bayesian approach extends prior work by targeting complete autonomous systems and incorporating collateral-damage and perceived-target-value costs.Earlier surveyed Bayesian applications did not define complete systems or include these cost values.
  • Trust-Metric Construction: Each layer’s trust metric combines factor values such as security level, exploit reward, exploit damage, and adversary action likelihood.The general formulation is TM = LV*AER* AED *ATA, where LV is level value and the remaining terms represent adversary-related probabilities.
  • Trust-Metric Construction: System trust is discretized over [0, 1], with five levels, and the hardware, software, AI, and supply-chain layers follow the same pattern.The system-level expression is STn = EALn * AERn * AEDn *ATAn.
  • Holistic Trust Model: The individual layer metrics are ultimately combined into a whole-system trust metric, with Bayesian-network conditional tables linking component values.The model can be expanded to cover additional elements considered important for system security.
  • Bayesian Inference: Bayesian networks factorize the joint distribution into conditional probabilities given parent variables, reducing computational complexity through the local Markov property.This supports reasoning about network outcomes while incorporating observations and posterior evidence.

X. CONCLUSION

The survey finds that existing trust metrics rarely span complete robotic architectures and often reduce the problem to small component sets. It therefore advocates Bayesian inference and broader security standards as foundations for more holistic, computationally feasible trust assessment.

  • Survey Findings: The survey found no well-defined trust-metric set that fully covers a complete robotic system, while existing studies commonly restrict analysis to small component sets or specific system areas.Table 3 summarizes findings concerning holistic system trust models.
  • Proposed Direction: Bayesian inference is proposed as a way to address uncertainty and make complex system-trust evaluation computationally feasible.The paper presents Bayesian inference as the basis for extending trust assessment across multiple robotic-system layers.
  • Implications: Security trust metrics should be considered in standards governing increasingly autonomous robotic systems, alongside existing ethics and AI-transparency efforts.The paper specifically identifies autonomous vehicles as an important application area.
  • Future Work: Future work is to define trust metrics that can be used in a security-analysis model for autonomous robotic systems.The conclusion leaves the metrics themselves as an area for further development.
Loading 2106.15015v2…