Runtime Assurance Under Measurement Attack: Necessary and Sufficient Observability Conditions for Learned Control in Radio Access Networks
Listen
Radio episode about this paper
Transcript
Introduction to the show: ident: Security Radio. Generated commentary on the latest security and cryptography papers.
Nadia: I'm Nadia, and with me are Elias and Priya, guest researcher.
Elias: Today's paper: "Runtime Assurance Under Measurement Attack".
Nadia: Runtime assurance pairs a verified fallback with an untrusted controller and a switching monitor, and is the leading route to admitting learned policies into safety-relevant network control.
Elias: First, who's behind it and why it matters.
Title and authors: Nadia: So we're starting by discussing "Runtime Assurance Under Measurement Attack: Necessary and Sufficient Observability Conditions for Learned Control in Radio Access Networks," focusing on what the title itself tells us about the paper's core focus.
Elias: I see a lot of technical rigor right there, immediately signaling that this isn't just a high-level discussion but a deep dive into the mathematical necessity and sufficiency of certain conditions.
Priya: For someone focused on privacy and measurements, I’m wondering what "Runtime Assurance" means in practice when we talk about untrusted endpoints providing measurements.
Nadia: It means we’re looking at systems where the controller isn't perfect, and we have to build a mechanism—a verified fallback paired with a switching monitor—to ensure safety even when things go wrong.
Elias: That architecture is what they call runtime assurance, and it’s presented as the leading route for admitting learned policies into safety-relevant network control, which is a big claim.
Priya: If I understand correctly, the paper isn't just saying "AI is hard to trust," but it's providing a specific mathematical property that makes certain AI deployments safe against adversarial measurement attacks.
Nadia: Exactly; it’s not just about trust in the controller itself, but ensuring that the system remains safe even if the measurements feeding into that controller are actively being manipulated by an adversary.
Elias: The authors are essentially proving a necessary and sufficient condition for this safety guarantee, which is a significant step beyond just suggesting some heuristics for deployment.
Priya: What kind of implications does this have on the way we think about deploying AI in critical infrastructure where measurement integrity is paramount?
Nadia: It means that before we deploy any learned policy, we need to formally verify that the underlying physical system meets this sparse observability condition quantified over attack supports.
Elias: That shifts the focus from just making the AI perform well to rigorously quantifying the necessary structural properties of our network model relative to potential adversaries.
Priya: That seems like a very high bar, but if it helps define a computable requirement for safety, then I see the value in that rigor.
Nadia: It does; it turns an abstract safety concern into a concrete observability problem that engineers can actually work with when designing the physical network topology.
Elias: And we need to remember that this condition is strictly weaker than full-state observability, which is something that really opens up possibilities for deployment in complex systems where full state knowledge isn't feasible anyway.
Priya: So it’s about finding the minimum amount of information we actually need to guarantee safety, rather than assuming we need everything.
Nadia: That’s the core idea; functional observability quantified over attack supports is less demanding than full-state observability, which is a key takeaway from "Runtime Assurance Under Measurement Attack: Necessary and Sufficient Observability Conditions for Learned Control in Radio Access Networks."
The paper's summary: Nadia: Now that we’ve talked about the title, I want to summarize what this paper actually presents in terms of its main findings regarding the runtime assurance architecture.
Elias: The core mechanism involves pairing a learned policy with a verified fallback and monitoring it with a switch that triggers the fallback when the state leaves a predefined trigger set T.
Priya: So, if we look at what they actually show about this setup, it’s that safety holds if and only if this switching monitor is configured correctly to interrupt the learned controller only once the true state has left its trigger set.
Nadia: That's a very specific condition, and it hinges on the plant being 2q-sparse observable with respect to the safety-relevant output when there is zero measurement noise.
Elias: That 2q-sparse observability condition is their main result, establishing that at zero noise, this setup keeps the plant safe against an adversary controlling q channels if and only if the plant is 2q-sparse observable with respect to the safety-relevant output.
Priya: I’m interested in how this relates to real-world data; does this mean we need a very specific kind of observability map that accounts for the attack supports?
Nadia: Yes, it requires functional observability quantified over attack supports, which is a functional way of saying we’re quantifying what the plant can reveal about the safety output given where an adversary can write.
Elias: That quantification over attack supports is what makes this condition functional observability; it’s not just a general property but one tailored to the constraints of adversarial measurement channels.
Priya: So, if we consider real-world data, does this imply that we need to design our network measurements in a way that explicitly considers where an adversary might be able to corrupt them?
Nadia: It strongly implies that the measurement system's structure must be designed with the adversary's possible channel access points in mind, which is a practical constraint on measurement placement.
Elias: They also introduced a weaker condition in Theorem two stating that a monitor only needs to know "which side of the safety boundary the plant is on," quantified by H-sparse observability at level 2q.
Priya: That’s interesting because it suggests that we don't need perfect knowledge of the state across all dimensions if we can achieve this weaker, sparse observability condition instead.
Nadia: Right, and this H-sparse observability condition is what allows us to define outage conditions over only the cells that carry service rather than having to model every single cell in a large network simulation.
Elias: It also shows how the adversary's reach is computed inside the gNB, which adds another layer of complexity by tying it directly into the physical network hardware constraints.
Priya: It seems like they’ve successfully translated a complex safety problem into a condition that is tractable for analyzing network topology and measurement structure.
Nadia: They have done just that; they’ve provided a clear roadmap linking the observability of the plant to its ability to withstand measurement attacks in this architecture.
The paper's improvements: Elias: Moving on, let's talk about the specific improvements and refinements suggested by these authors, which are crucial for moving this from a theoretical proof to a practical system.
Nadia: I’m really interested in the correction they make to how the tolerable budget is calculated; they state that it should be decided by an exact rank test because exact rank deficiency isn't generic.
Priya: That makes sense because relying on model fits from traces can give misleading results, and naming a "margin floor" derived from that fit is essential for reproducibility across different model versions.
Elias: They also address the detection scaling law in §VI-B, correcting a prior result where the coefficient of variation was zero point five one six to zero point zero five four by accounting for the shape of the hidden direction and sparse observability margin once taken at a q-removal.
Nadia: That correction is significant because it shows that our estimate for minimum detectable state deviation scales inversely with that sparse observability margin, which directly impacts how sensitive our detection system is.
Priya: And they also highlight that the budget isn't robust to identification noise; fitting the system from traces can move the reported budget from one to three while the margin doesn't move, which reinforces why that floor value is necessary.
Elias: They also suggest a significant modeling choice: modeling the trust split between measurement families by an "influence coefficient per channel" rather than using a simple binary trust flag.
Nadia: That sounds much more nuanced; instead of just saying "this channel is trusted or not," we’d quantify how much influence each measurement family has on the overall safety outcome.
Priya: And that leads into the sensor placement findings, where they found that adjacency of trusted counters can actually outperform spread ones on a ring topology, though they caution against generalizing that into a simple heuristic.
Elias: They also show how the set-valued monitor is optimal because it can only lose safety or availability when the adversary drives the state near the boundary defined by the trigger set T.
Nadia: It’s a strong result because it means we get an exact understanding of when and why our system fails, not just a probabilistic outcome.
Elias: And finally, they discuss detection scaling law correction again, emphasizing that this is related to the pairing error that any similar evaluation can make.
Priya: So the overall improvement seems to be moving from a general observability requirement to a highly specific, noise-aware condition tied directly to attack supports and measurement structure.
Conclusion: Nadia: Alright team, as we wrap up our discussion on "Runtime Assurance Under Measurement Attack: Necessary and Sufficient Observability Conditions for Learned Control in Radio Access Networks," we need to summarize the big picture implications.
Elias: The main implication is that runtime assurance is a viable path for admitting learned controllers into network control, but its guarantee rests on a condition—the assurance precondition—that the authors prove they assume rather than require: that the monitor’s estimation error is zero, or at worst stochastic with a characterisable rate.
Priya: This means for real-world systems, we have to acknowledge that perfect measurement is unattainable and design our system around what we can actually guarantee under noise.
Nadia: Right; this paper gives us the necessary and sufficient condition: 2q-sparse observability with respect to the safety-relevant output at zero measurement noise, which is functional observability quantified over attack supports.
Elias: This condition is crucial because it’s a functional observability quantified over attack supports, and it’s strictly weaker than full-state observability, which opens up deployment options in complex systems where full state knowledge isn't feasible anyway.
Priya: I think the most impactful takeaway for network operators is that they can now define more efficient and flexible safety boundaries using H-sparse observability to tailor outage conditions precisely to the critical infrastructure elements.
Nadia: Exactly; it moves deployment planning from an intuitive heuristic to a computable requirement based on quantifiable observability metrics, which is a huge step forward for trustworthy AI in RAN.
Elias: We also have the practical insights about the tolerable budget being decided by an exact rank test and needing that margin floor, which makes deployment planning much more reproducible.
Priya: And with the message-based trust monitor idea, we can secure loops against model poisoning by assigning zero tolerance budget to any agent whose inputs aren't directly reachable by the adversary.
Nadia: So, "Runtime Assurance Under Measurement Attack: Necessary and Sufficient Observability Conditions for Learned Control in Radio Access Networks" provides a formal framework for ensuring that learned control policies remain safe even when measurements are corrupted by an adversary.
Elias: It’s a solid piece of work that moves the conversation toward rigorous certification of these control loops in real-world scenarios.
Priya: It really shows how we can combine observability theory with practical network constraints to define robust safety metrics for AI systems operating in complex radio access networks.
eess.SP, cs.CR
Submitted: 2026-09-25
Updated: 2026-09-25
Comments: 17 pages, 6 figures, 9 tables
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Importance score: 92/100
The gist: Runtime assurance pairs a verified fallback with an untrusted controller and a switching monitor, and is the leading route to admitting learned policies into safety-relevant network control.
Key concepts
- 2q-sparse observability
- This is the core requirement for safety. It means that even if an adversary controls up to q measurement channels, the system must still be able to reliably determine the state relevant to safety by looking at a sparse set of measurements. It quantifies functional observability specifically against limited attack supports.
- Assurance Precondition
- This is the necessary and sufficient condition for safety under zero measurement noise. It establishes that if the plant meets this sparsity requirement, a switching monitor can ensure the plant stays safe against an adversary controlling up to q channels.
- H-sparse observability at level 2q
- This is a weaker, practical condition derived from the main theorem. Instead of requiring full knowledge, the monitor only needs to know which side of the safety boundary the plant is on. This condition relates to how well the system can distinguish between states relevant to safety under attack supports.
- Robust Precondition Under Noise
- This extends safety guarantees when there is some measurement noise. Safety holds unconditionally if a specific margin condition involving noise energy, trigger radius, and safe set radius is met. Availability depends on satisfying a related condition.
Terminology
Summary
Runtime assurance pairs a verified fallback with an untrusted controller and a switching monitor, and is the leading route to admitting learned policies into safety-relevant network control. The gist: at zero measurement noise, a monitor that interrupts the learned controller only once the state has left its trigger set keeps the plant safe against an adversary controlling q channels if and only if the plant is 2q-sparse observable with respect to the safety-relevant output.
The Core Problem and Precondition
The paper addresses a critical gap in existing runtime assurance literature: most statements assume a perfect state evaluation, whereas deployments often involve measurements from untrusted endpoints where errors are adversarial rather than stochastic. The central finding is that the necessary and sufficient condition for maintaining safety under an adversary controlling at most q measurement channels is the assurance precondition
: that the plant must be 2q-sparse observable with respect to the safety-relevant output. This condition is functional observability quantified over attack supports, which is strictly weaker than full-state observability.
The Architecture and Trust Boundary
The architecture involves a learned policy acting on a plant, monitored by a switch that hands control to a verified fallback when the state approaches the boundary of a safe operating region. The safety requires that the worst-case excursion over the total delay remains inside the recoverable set R. The monitor's action is determined by comparing its estimation against this boundary.
Key Contributions and Conditions
The paper proves several key results regarding this architecture:
-
A precondition, stated and proved (Theorem 1), establishing that safety holds if and only if the plant is 2q-sparse observable with respect to the safety-relevant output at zero measurement noise. This condition is functional observability quantified over attack supports.
-
The weaker condition the architecture actually needs (Theorem 2), which states that a monitor only needs to know
which side of the safety boundary the plant is on,
quantified by H-sparse observability at level 2q, which reproduces Definition 1 exactly at H = I. -
A constructive converse (§IV-B), demonstrating that an attack produces two trajectories whose measurement sequences are indistinguishable, forcing every monitor to either interrupt a safe trajectory or miss an unsafe one.
-
Confinement and the threshold it hides (Proposition 1), showing that confining the adversary to a known family of channels weakens the condition, and once trusted channels render the state observable on their own, observability stops bounding the budget at all.
The Robust Precondition Under Noise
Theorem 3 establishes a robust precondition for non-zero noise. It shows that under an energy-bounded noise hypothesis, safety holds unconditionally if and only if the margin condition is met:
-
Safety holds unconditionally because the supremum over the consistent set bounds the true state from above.
-
Availability holds if and only if a specific condition is met:
γH 2q ≥ 2v/τ − τ0,
where γH 2q is the safety-relevant margin at level 2q, v is the noise energy bound, τ is the trigger radius, and τ0 is the safe set radius.
Operational Insights and Limitations
The analysis provides several practical insights:
- The tolerable budget is decided by an exact rank test; a published budget must name its margin floor
because exact rank deficiency is not generic.
- The confinement threshold moves the placement question from recovery to a threshold question, where crossing it means the untrusted family stops mattering, and every channel in it may be corrupt simultaneously.
- The set-valued monitor is optimal; it can lose safety or spend availability only when the adversary drives the state near the boundary.
- Detection scaling law correction: The minimum detectable state deviation scales inversely with the sparse observability margin once taken at a q-removal, correcting a mis-specified pairing that yielded a coefficient of variation of 0.516 in prior work to 0.054.
- The budget is not robust to identification noise; fitting the system from traces moves the reported budget from 1 to 3 while the margin does not move, necessitating a floor value for reproducibility.
- The most consequential modeling choice is the trust split between measurement families, which should be modeled by an influence coefficient per channel
rather than a binary trust flag.
- The sensor-placement finding shows that adjacency of trusted counters can outperform spread ones on a ring, and this must not be generalized into a placement heuristic.
- The architecture converts an undetectable safety failure into a bounded and observable availability cost, stating the rate of exchange.
Conclusion
Runtime assurance is the right shape for admitting learned controllers into network control, and its guarantee is conditional on a property that its statements assume rather than require: sparse observability with respect to the safety-relevant output.
Improvements for AI systems
Based on the provided scientific paper, here are specific improvements for AI systems in radio access networks (RAN) and what those improved systems can achieve:
-
Acknowledge that current safety guarantees often assume perfect measurement or stochastic noise, which is not true in real-world mobile networks where measurements originate from untrusted endpoints (handsets).
-
Implement a
Runtime Assurance
architecture that pairs an untrusted learned controller with a verified fallback mechanism and a switching monitor. -
Design the system to ensure safety against adversarial attacks by requiring the plant dynamics to be 2q-sparse observable with respect to the safety-relevant output, where 'q' is the number of measurement channels controlled by an adversary.
-
Utilize a set-valued monitor rather than a point estimator. This monitor must decide whether to interrupt the learned controller based on whether the true state has left a predefined
trigger set
(T), which is determined by an analysis of safety maps rather than just a single threshold. -
The improved system will operate under non-zero measurement noise, guaranteeing that safety holds if and only if the monitor's decision is based on the supremum over all consistent states within its observation window, rather than just a point estimate.
-
The system can leverage
H-sparse observability
to make the safety condition strictly weaker than full-state observability, allowing network operators to define outage conditions over only the cells that carry service rather than every cell in a large model. -
The system's tolerable budget (the number of corrupted channels it can withstand) will be determined by an exact rank test and must include a published
margin floor
derived from the model fit, ensuring reproducibility across different models. -
The system can be optimized for sensor placement using combinatorial optimization techniques (like greedy algorithms) to determine the minimum set of trusted measurement counters required to satisfy observability conditions, rather than relying on intuitive geometric spreading.
-
The system can incorporate a
Message-based Trust Monitor
that scores learned agents based solely on their messages and models of those agents, effectively assigning a zero tolerable budget to any agent whose inputs are not directly reachable by the adversary (i.e., those without network-derived channels).
The improved AI system can achieve the following:
-
It will provide a formal, provable safety guarantee for learned control policies in RAN networks even when measurements are corrupted by an adversary who does not need to forge data (Truthful Adversary).
-
It will maintain safety under realistic, non-zero measurement noise and adversarial corruption, converting potential catastrophic failures into a bounded availability cost rather than allowing the adversary to arbitrarily choose whether the switch trips or misses a safe trajectory.
-
It will enable network operators to define more efficient and flexible safety boundaries by using H-sparse observability, allowing them to tailor outage conditions precisely to the critical infrastructure elements (e.g., service cells) while reducing the complexity of the required observability condition.
-
It will provide a quantitative, reproducible metric for deployment planning—the
assurance precondition
—that tells operators exactly how many uninfluenceable channels are needed to maintain safety under specific noise and attack scenarios, moving placement from an intuitive heuristic to a computable requirement. -
It will allow for the safe deployment of learned AI agents in O-RAN environments by providing a mechanism (Message-based Trust) that automatically assigns zero tolerance budget to any agent whose inputs are not directly reachable by the adversary, thus securing the control loop against model poisoning and input manipulation.
Sources
Related papers
- Physics-Constrained Deep Learning Model for Contactless Blood Pressure Monitoring from Triaxial Bodyseismography
- Uncertainty Quantification in Machine Learning for Biosignal Applications -- A Review
- Continuous Orthogonal Mode Decomposition: Haptic Signal Prediction in Tactile Internet
- Generative Models for Modeling and Synthesizing MIMO Channels in Adverse Weather Conditions
- Deep-Learning-Based Pixelated Microwave Filter Design and Characterization using Electro-Optical Electric-Field Measurements
- DRIFT: Joint Channel Estimation and Prediction Towards Pilotless 6G Non-Terrestrial Networks