Powered by
1st International Workshop on Resilience for Safe, Secure and Responsible Systems (RSSR 2026), October 12–16, 2026,
Munich, Germany
1st International Workshop on Resilience for Safe, Secure and Responsible Systems (RSSR 2026)
Frontmatter
Article: asews26rssrforeword-fm000-p (type: Frontmatter) doi:
Article: asews26rssrforeword-fm001-p (type: Frontmatter) doi:
Article: asews26rssrforeword-fm002-p (type: Frontmatter) doi:
Keynotes
Can Our Systems Survive Their Own Evolution? (Keynote)
Morgan Ericsson
(Linnaeus University, Sweden)
Resilient systems must be able to act when expected mechanisms fail or conditions change. Generative AI agents are attractive here because they can reason about a situation and construct responses of their own, rather than merely selecting among those their designers anticipated. We introduce intelligence precisely because we want responses we have not explicitly specified.
For some resilience mechanisms, this creates a complexity inversion. A comparatively bounded responsibility, such as restoring a service, diagnosing a failure, or adapting a configuration, is delegated to a general-purpose component whose capabilities extend far beyond that responsibility. The problem is not that the component is too intelligent for the task. It is the mismatch between the breadth of its capabilities and the scope of the responsibility we intend to delegate.
This changes the assurance problem. How do we establish resilience when we cannot fully anticipate the responses through which resilience will be achieved? An agent that finds an unexpected route around a failure may demonstrate exactly the adaptability we want. The same capability can bypass a restriction or a containment mechanism, or undermine an assumption on which the system’s resilience depends. The boundary between successful adaptation and unacceptable workaround becomes something we must engineer, monitor, and defend.
Evolution makes this harder. Replacing an intelligent component can change the strategies the system discovers and pursues even when its interfaces, objectives, and permissions remain unchanged. Recent incidents involving frontier models evaluated with reduced safeguards have shown agents finding unexpected ways around controls. A safeguard may appear effective simply because the model has not yet found a way around it. Every upgrade quietly re-opens the assurance case.
These questions are not new to this community. Decades of work on self-adaptive systems, architecture-based adaptation, and assurance for
autonomous systems have confronted uncertainty in many forms, including uncertainty within the adaptation logic itself.
With general-purpose AI agents, the question is not only how a component will behave, but how far its repertoire extends. We may have constrained the behavior we anticipated without constraining the behavior the agent can discover. This keynote examines which of our existing foundations carry over, which assumptions no longer hold, and what further evidence and mechanisms we need as capabilities evolve. Because capability, like life, finds a way.
Publisher's Version
Article: asews26rssrmain-key1-p (type: Keynote) doi:10.1145/3843780.3857386
Model-Centric Approaches to Assuring AI-Based Autonomy (Keynote)
Simon Burton
(University of York, UK)
This presentation explores how assuring AI-based autonomous systems requires moving beyond traditional software safety standards and purely statistical validation, both of which struggle under the inherent complexity and open-ended nature of real-world environments. Rather than relying on rigid design-time assumptions, the talk discusses a more flexible approach that combines explicit modeling of system behavior, operational domain boundaries, and causal relationships to manage both data and environmental uncertainties. By integrating these models into runtime monitoring and risk mitigation mechanisms, autonomous systems can dynamically detect when they are operating outside safe bounds and adapt accordingly. Because residual uncertainty cannot be completely eliminated prior to deployment, safety is framed as an iterative, through-life process. Ultimately, combining structured dialectic arguments with clear causal evidence offers a practical path toward demonstrating resilient and dependable performance across complex socio-technical domains.
Publisher's Version
Article: asews26rssrmain-key2-p (type: Keynote) doi:10.1145/3843780.3857388
Papers
A Resilience-Oriented Orchestration Framework for Mission Continuity in Multi-agent Autonomous Systems
Anjali Santhosh,
Massimo Tivoli, and
Marco Autili
(University of L'Aquila, Italy)
Autonomous Multi-Agent Systems (MAS) operating in dynamic environments require resilient coordination mechanisms to maintain mission continuity despite operational disruptions. This paper presents a resilient orchestration framework that integrates runtime monitoring, interruption detection, recovery re-assessment, and re-orchestration within a unified lifecycle coordinated by a stateless Asynchronous Event Bus (AEB). By treating resilience as an intrinsic orchestration process, the framework enables recovery decision re-assessment and autonomous standby promotion without centralized replanning activities. Experimental evaluation in heterogeneous Search And Rescue (SAR) simulations demonstrates preservation of effective mission continuity and resilient recovery under varying failure conditions.
Publisher's Version
Article: asews26rssrmain-p1-p (type: Full Paper) doi:10.1145/3843780.3844537
AIEngOrchestrator-HITL: Human-in-the-Loop Process Intelligence for Resilient AI Systems
Razan Abualsaud
(Independent, Saudi Arabia)
Artificial Intelligence (AI) development processes remain limited in
supporting lifecycle resilience under dynamic and context-dependent
conditions. The separation of Machine Learning (ML) and non-ML
processes weakens co-development and traceability, limiting sys-
tematic reasoning about change across heterogeneous artifacts.
Consequently, adaptation remains largely tool-driven rather than
process-driven. We address this gap by introducing Human-in-the-
Loop (HITL) process intelligence through AIEngOrchestrator-HITL,
a conceptual extension of AIEngOrchestrator. While the baseline
framework provides coordinated, executable AI development pro-
cesses, its change reasoning remains primarily reactive and bounded
by explicitly modeled dependencies. AIEngOrchestrator-HITL aug-
ments this foundation with AI-assisted and human-guided reason-
ing to infer missing dependencies, anticipate change impacts, and
support proactive, context-aware process adaptation. We present
the conceptual design and an evaluation plan for assessing its con-
tribution toward process-level resilience under uncertainty.
Publisher's Version
Article: asews26rssrmain-p2-p (type: Short Paper (4 pages)) doi:10.1145/3843780.3844538
MAVLink Proxy Defense with Intrusion Detection, Safety Quarantine, and Dual-View Deception for UAV Command-and-Control
Utkarsh Balu Lubal,
Muhammad Abdul Basit Ur Rahim, and
Muhammad Abid
(California State University at Long Beach, USA; Florida Polytechnic University, Lakeland, USA)
Unmanned aerial vehicle (UAV) command-and-control (C2) over MAVLink is safety-critical because protocol-valid attacks can disrupt vehicle movement, mission execution, and operator control even when the link remains operational. Existing UAV defenses often treat detection, blocking, and deception separately, leaving no integrated way to contain an untrusted MAVLink source while preserving trusted-operator control.
This paper presents CACD, a hybrid detection and enforcement architecture implemented as an in-path MAVLink/PX4 proxy for PX4 SIH/SITL simulation. CACD aggregates flow-scoped traffic into one-second windows for a Random Forest (RF) traffic-window classifier, complements RF inference with protocol-aware rate guards on untrusted HEARTBEAT, PING, and PARAM_REQUEST_LIST traffic, blocks unsafe or untrusted commands through runtime safety rules, and applies policy-driven session escalation and quarantine through a shared session-state manager. When deception is enabled, quarantined attacker flows receive bounded bursts of MAVLink-valid synthetic telemetry rather than a continuous fake stream; the trusted operator continues to receive real PX4 telemetry.
We evaluate CACD on a self-collected supervised MAVLink dataset of 9,645 one-second traffic windows across five attack scenarios and on live SIH/SITL tests covering the same categories. Offline group/log-split RF evaluation yields 99.38
Publisher's Version
Published Artifact
Artifacts Available
Article: asews26rssrmain-p7-p (type: Full Paper) doi:10.1145/3843780.3844539
 | CACD Presentation Video: Presentation video for the paper "MAVLink Proxy Defense with Intrusion Detection, Safety Quarantine, and Dual-View Deception for UAV Command-and-Control." The video presents the CACD architecture, evaluation methodology, results, limitations, and future work. |
 | CACD RSSR '26 Artifact: MAVLink Proxy Defense with Intrusion Detection, Safety Quarantine, and Dual-View Deception for UAV Command-and-Control (doi:10.5281/zenodo.22216014): Artifact package for the RSSR '26 paper on CACD, an in-path MAVLink/PX4 SIH/SITL proxy with Random Forest traffic-window IDS, protocol-aware rate guards, runtime safety quarantine, and opt-in dual-view deception. Includes the frozen 9,645-window supervised dataset (27 features), group/log-split offline RF evaluation, ... |
R²: Repairability-Preserving Recursive Repair for Multimodal Agentic Systems
Dominic Dabish
(San Diego State University, USA)
Current-incident success does not show whether a persistent repair preserves the evidence and rollback paths needed for the next failure. R² audits whether the repaired system can detect, localize, repair, and verify a different unseen fault within budget. It separates pre-authorization probes from sealed faults, confines proposals to registered actions, and assigns execution to deterministic code. In an authored study of four incident families, five policies, and 50 seeds (1,000 episodes), every policy fixed the visible incident. Across 400 sealed trials per policy, future-repair success was 4.0% for performance-only and regression-gated selection, 14.8% for static-quality and council selection, and 50.3% for R². False recovery was 33.8%, 18.5%, and 0%, respectively. The experiment replays four GPT-5.6 Thinking council records as fixed inputs and makes no live model calls. It validates the construct in a controlled simulator, not production prevalence or an agent-count effect.
Publisher's Version
Article: asews26rssrmain-p11-p (type: Short Paper (4 pages)) doi:10.1145/3843780.3844540
proc time: 0.13