Synergistic Simplex: Cooperative Runtime Assurance for Safety-Critical Autonomous Systems

arXiv cs.LG Papers

Summary

This paper introduces Synergistic Simplex, a new runtime assurance architecture for autonomous systems that allows safety monitors to use ML outputs while preserving formal safety guarantees. The authors demonstrate its effectiveness in improving performance for obstacle detection in autonomous vehicles.

arXiv:2605.08190v1 Announce Type: new Abstract: Autonomous systems increasingly rely on machine-learning (ML) components for safety-critical tasks such as perception and control in autonomous vehicles (AVs). While ML enables essential capabilities, it inevitably exhibits long-tail faults that make it unsuitable for safety-critical tasks. Runtime assurance (RTA) mitigates this issue by pairing ML components with verifiable safety monitors, e.g., Control Simplex and Perception Simplex architectures. However, the limited performance of safety monitors remains a major bottleneck. The Synergistic Simplex (SS) architecture improves system performance by enabling bidirectional integration between ML components and safety monitors while preserving formal safety guarantees. The key innovation here is allowing safety monitors to use ML outputs, which is typically prohibited in RTA systems. We formally derive conditions under which this integration preserves safety and demonstrate the performance benefits. We present the design, analysis, and evaluation of SS for AV obstacle detection.
Original Article
View Cached Full Text

Cached at: 05/12/26, 07:01 AM

# Cooperative Runtime Assurance for Safety-Critical Autonomous Systems ⋆Equal contribution. This material is based upon work supported by the National Aeronautics and Space Administration (NASA) under the cooperative agreement 80NSSC20M0229 and University Leadership Initiative grant no. 80NSSC22M0070, and the National Science Foundation (NSF) under grant no. CNS 1932529 and ECCS 2311085. Any opinions, findings, conclusions or recommendations expressed in this material are those of the authors and do not necessarily reflect the views of the sponsors.
Source: [https://arxiv.org/html/2605.08190](https://arxiv.org/html/2605.08190)
Ayoosh Bansal⋆\\star,1Mikael Yeghiazaryan⋆\\star,1Artyom Khachatryan2Tianyi Zhu3 Hunmin Kim4Naira Hovakimyan1Lui Sha1

###### Abstract

Autonomous systems increasingly rely on machine\-learning \(ML\) components for safety\-critical tasks such as perception and control in autonomous vehicles \(AVs\)\. While ML enables essential capabilities, it inevitably exhibits long\-tail faults that make it unsuitable for safety\-critical tasks\. Runtime assurance \(RTA\) mitigates this issue by pairing ML components with verifiable safety monitors,e\.g\.,Control Simplex and Perception Simplex architectures\. However, the limited performance of safety monitors remains a major bottleneck\.

The Synergistic Simplex \(𝒮​𝒮\\mathcal\{SS\}\) architecture improves system performance by enabling bidirectional integration between ML components and safety monitors while preserving formal safety guarantees\. The key innovation here is allowing safety monitors to use ML outputs, which is typically prohibited in RTA systems\. We formally derive conditions under which this integration preserves safety and demonstrate the performance benefits\. We present the design, analysis, and evaluation of𝒮​𝒮\\mathcal\{SS\}for AV obstacle detection\.

## IIntroduction

Autonomous systems are advancing rapidly, driven by breakthroughs in machine learning \(ML\) enabling complex autonomy tasks\. Among these systems, autonomous vehicles \(AVs\) exemplify the reliance on ML for functions essential to the safety goals of the vehicle,e\.g\.,perception\. Despite their enormous potential, such ML\-enabled systems pose significant safety challenges, as failures in ML components deployed for safety\-critical tasks can have severe consequences\.

Although ML\-based components achieve impressive empirical performance, they are inherently unverifiable and therefore susceptible to unexpected faults\[[45](https://arxiv.org/html/2605.08190#bib.bib110),[18](https://arxiv.org/html/2605.08190#bib.bib111),[35](https://arxiv.org/html/2605.08190#bib.bib112),[56](https://arxiv.org/html/2605.08190#bib.bib115),[10](https://arxiv.org/html/2605.08190#bib.bib113)\]\. Suet al\.\[[50](https://arxiv.org/html/2605.08190#bib.bib83)\]show that even a single\-pixel perturbation, imperceptible to humans, can drastically change ML output\. Such fragility raises serious concerns about the safety of autonomous systems built upon fundamentally unreliable ML components\[[25](https://arxiv.org/html/2605.08190#bib.bib105),[55](https://arxiv.org/html/2605.08190#bib.bib103),[38](https://arxiv.org/html/2605.08190#bib.bib104),[1](https://arxiv.org/html/2605.08190#bib.bib101),[44](https://arxiv.org/html/2605.08190#bib.bib100),[41](https://arxiv.org/html/2605.08190#bib.bib106),[42](https://arxiv.org/html/2605.08190#bib.bib109),[43](https://arxiv.org/html/2605.08190#bib.bib108),[40](https://arxiv.org/html/2605.08190#bib.bib95)\]\.

A solution to this is the runtime assurance \(RTA\) design, where a simple verifiable component monitors and constrains a complex high\-performance component, ensuring the system remains within a safe operating region\. This idea was pioneered by Sha as the Simplex architecture for control systems\[[49](https://arxiv.org/html/2605.08190#bib.bib45)\]\. Since then, the RTA design has gained prominence, inspiring numerous improvements and adaptations\[[13](https://arxiv.org/html/2605.08190#bib.bib46),[4](https://arxiv.org/html/2605.08190#bib.bib47),[17](https://arxiv.org/html/2605.08190#bib.bib99),[46](https://arxiv.org/html/2605.08190#bib.bib78),[47](https://arxiv.org/html/2605.08190#bib.bib84),[37](https://arxiv.org/html/2605.08190#bib.bib85),[14](https://arxiv.org/html/2605.08190#bib.bib86)\]\.

The growing use of ML\-based perception in safety\-critical systems motivated the development of Perception Simplex \(𝒫​𝒮\\mathcal\{PS\}\)\[[5](https://arxiv.org/html/2605.08190#bib.bib10),[6](https://arxiv.org/html/2605.08190#bib.bib36)\]\.𝒫​𝒮\\mathcal\{PS\}adapts the RTA design to perception systems, providing safety guardrails for AVs in the presence of obstacle detection faults in the AV’s ML\-based perception\. While𝒫​𝒮\\mathcal\{PS\}guarantees safety under specific constraints, it can cause substantial performance degradation due to conservativeness, even in the absence of faults in ML\.

![Refer to caption](https://arxiv.org/html/2605.08190v1/x1.png)Figure 1:Overview of theSynergistic Simplex \(𝒮​𝒮\\mathcal\{SS\}\)architecture, extended from Perception Simplex\[[6](https://arxiv.org/html/2605.08190#bib.bib36)\]\. As in traditional runtime assurance designs\[[49](https://arxiv.org/html/2605.08190#bib.bib45),[13](https://arxiv.org/html/2605.08190#bib.bib46),[4](https://arxiv.org/html/2605.08190#bib.bib47),[17](https://arxiv.org/html/2605.08190#bib.bib99)\], the ML Layer executes system’s mission, and the Safety Layer enforces deterministic guardrails\.Synergistic Simpleximproves upon prior designs by leveraging bidirectional communication between the layers\.This work addresses the performance limitations of RTA designs such as𝒫​𝒮\\mathcal\{PS\}by introducing a holistic, bidirectional integration between two complementary layers: the extensively validated, yet unverifiable, ML\-enabled layer responsible for best\-effort task execution, and the verifiable safety layer responsible for enforcing deterministic safety properties\. In thisSynergistic Simplex \(𝒮​𝒮\\mathcal\{SS\}\)design, illustrated in Figure[1](https://arxiv.org/html/2605.08190#S1.F1), these two partially redundant layers cooperate to improve system performance without violating safety guarantees\.

Safety certification standards prohibit the use of unverifiable ML generated information by the safety layer\[[23](https://arxiv.org/html/2605.08190#bib.bib116),[15](https://arxiv.org/html/2605.08190#bib.bib117)\],e\.g\.,the use of lane boundary information generated by an ML component in the safety layer for obstacle detection and collision avoidance in𝒫​𝒮\\mathcal\{PS\}\.𝒮​𝒮\\mathcal\{SS\}overcomes this restriction under formally stated conditions \([SectionIII\-B](https://arxiv.org/html/2605.08190#S3.SS2)\), preserving safety guarantees while improving performance \([SectionVI](https://arxiv.org/html/2605.08190#S6)\)\.

The key contributions of this work are:

- •Synergistic Simplex \(𝒮​𝒮\\mathcal\{SS\}\) architecture that leverages synergistic interactions between the safety and ML layers*to improve overall system performance while preserving formal safety guarantees*\([SectionIII](https://arxiv.org/html/2605.08190#S3)\)\.
- •Formal safety analysis of𝒮​𝒮\\mathcal\{SS\}, deriving the conditions under which bidirectional ML\-safety communication preserves the deterministic safety guarantees of𝒫​𝒮\\mathcal\{PS\}\([SectionsIII\-A](https://arxiv.org/html/2605.08190#S3.SS1)and[III\-B](https://arxiv.org/html/2605.08190#S3.SS2)\)\.
- •A reference𝒮​𝒮\\mathcal\{SS\}design for AVs \([SectionIV](https://arxiv.org/html/2605.08190#S4)\)\.

## IIRelated Work

This section reviews relevant prior work and positions our contributions within safe autonomy research\.

### II\-AControl Simplex

Redundancy has long been used to achieve fault tolerance in safety\-critical cyber\-physical systems \(CPS\) through replication or diverse implementations\[[22](https://arxiv.org/html/2605.08190#bib.bib59),[31](https://arxiv.org/html/2605.08190#bib.bib64),[7](https://arxiv.org/html/2605.08190#bib.bib75)\]\. However, traditional computational redundancy remains vulnerable to correlated and design\-level faults common in learning\-enabled components\[[53](https://arxiv.org/html/2605.08190#bib.bib71),[54](https://arxiv.org/html/2605.08190#bib.bib74),[26](https://arxiv.org/html/2605.08190#bib.bib66)\]\. This limitation motivates functional redundancy, where heterogeneous algorithms or sensing modalities reduce shared failure modes\. The Simplex architecture builds on this idea\.

The Simplex architecture\[[49](https://arxiv.org/html/2605.08190#bib.bib45),[13](https://arxiv.org/html/2605.08190#bib.bib46),[4](https://arxiv.org/html/2605.08190#bib.bib47)\]is foundational to our work\. It pairs a high\-performance but unverified controller with a simple, verifiable backup monitored at runtime\. When the system approaches an unsafe region, control is switched to the safety controller\.

Control Simplex has been applied broadly in CPS and autonomy, including variants such as R\-Simplex\[[52](https://arxiv.org/html/2605.08190#bib.bib76)\], SL1\-Simplex\[[36](https://arxiv.org/html/2605.08190#bib.bib77)\], and other extensions\[[39](https://arxiv.org/html/2605.08190#bib.bib79)\]\. Neural Simplex\[[46](https://arxiv.org/html/2605.08190#bib.bib78)\]introduces limited communication from the safe to the complex controller to reduce unnecessary fallbacks, but this interaction is restricted to low\-level control\. In contrast,𝒮​𝒮\\mathcal\{SS\}operates at the perception layer and enables richer ML\-safety cooperation\. We discuss its perception layer predecessor, Perception Simplex\[[6](https://arxiv.org/html/2605.08190#bib.bib36)\], in[SectionII\-B](https://arxiv.org/html/2605.08190#S2.SS2)\.

### II\-BPerception Simplex

![Refer to caption](https://arxiv.org/html/2605.08190v1/x2.png)Figure 2:Detectability region for LiDAR\-based obstacle detection, adapted from\[[5](https://arxiv.org/html/2605.08190#bib.bib10)\]\. Obstacles above the dashed line are guaranteed to be detected based on their height and distance\.Perception Simplex \(𝒫​𝒮\\mathcal\{PS\}\)\[[6](https://arxiv.org/html/2605.08190#bib.bib36)\]provides deterministic safety guarantees for AVs by separating the autonomy stack into an unverifiable ML layer and a verifiable safety layer\. The safety layer implements a classical LiDAR\-based obstacle\-existence detector built on Verifiable Obstacle Detection \(VOD\)\[[5](https://arxiv.org/html/2605.08190#bib.bib10)\], which derives geometric conditions under which the Depth Clustering algorithm\[[8](https://arxiv.org/html/2605.08190#bib.bib80),[9](https://arxiv.org/html/2605.08190#bib.bib81)\]is guaranteed to detect an obstacle\. As illustrated in[Figure2](https://arxiv.org/html/2605.08190#S2.F2), detection is guaranteed whenever an obstacle at distancexxhas heightyysatisfyingy≥k​x\+by\\geq kx\+b, wherekkandbbdepend on sensor and algorithm parameters\. This bound enables a provably safe maximum speed: the ML layer provides high\-performance perception and planning, while the safety layer ensures collision avoidance whenever the vehicle operates within this limit\.

At runtime, the safety layer monitors the ML layer and overrides when it detects a safety\-critical obstacle missed by the latter, ensuring collision avoidance under faulty conditions in obstacle\-existence detection\. However,𝒫​𝒮\\mathcal\{PS\}covers only obstacle existence \(not classification\) and its override action is restricted to full stop, which can induce conservative behavior\.𝒮​𝒮\\mathcal\{SS\}extends𝒫​𝒮\\mathcal\{PS\}by enabling carefully constrained bidirectional communication between the two layers, preserving its formal guarantees while reducing conservativeness\.

### II\-CSafety Approaches for ML Perception

Beyond runtime assurance\-based designs, several complementary directions have been proposed to improve the safety of ML\-based perception in autonomous systems\.

Priority inversion in ML\-based perception arises when networks allocate uniform computation across the input, delaying processing of safety\-critical regions\[[48](https://arxiv.org/html/2605.08190#bib.bib87)\]\. Prior work mitigates this through externally proposed or heuristic region partitioning: Liuet al\.\[[34](https://arxiv.org/html/2605.08190#bib.bib22),[33](https://arxiv.org/html/2605.08190#bib.bib23)\], Huet al\.\[[19](https://arxiv.org/html/2605.08190#bib.bib48),[20](https://arxiv.org/html/2605.08190#bib.bib49)\], and Chenet al\.\[[12](https://arxiv.org/html/2605.08190#bib.bib13)\]use external agents to rank camera or LiDAR regions\. Tunget al\.\[[51](https://arxiv.org/html/2605.08190#bib.bib52)\]remove irrelevant pixels before focused convolution, and Kanget al\.\[[27](https://arxiv.org/html/2605.08190#bib.bib50)\]and Liuet al\.\[[32](https://arxiv.org/html/2605.08190#bib.bib51)\]use regions of interest to focus the DNNs\.

Uncertainty estimation offers another avenue, enabling ML models to quantify their own confidence in perception outputs\. Kendall and Gal\[[29](https://arxiv.org/html/2605.08190#bib.bib118)\]distinguish aleatoric and epistemic uncertainty in deep learning for perception tasks, while Lakshminarayananet al\.\[[30](https://arxiv.org/html/2605.08190#bib.bib119)\]propose deep ensembles as a scalable approach to predictive uncertainty estimation\. Araujoet al\.\[[2](https://arxiv.org/html/2605.08190#bib.bib120)\]survey uncertainty methods specifically in the context of autonomous driving perception\. While these approaches can flag potentially unreliable outputs, they do not provide deterministic safety guarantees\.

Formal verification of neural networks attempts to provide stronger correctness guarantees by proving properties of network behavior\. Katzet al\.\[[28](https://arxiv.org/html/2605.08190#bib.bib121)\]introduce Reluplex, an SMT\-based solver for verifying deep neural networks, and Huanget al\.\[[21](https://arxiv.org/html/2605.08190#bib.bib122)\]develop safety verification methods for DNNs\. However, these techniques remain computationally expensive and do not scale to the large networks used in modern autonomy stacks\.

In contrast,𝒮​𝒮\\mathcal\{SS\}does not attempt to verify or constrain the ML layer directly\. Instead, it preserves formal safety guarantees by pairing the ML layer with a verifiable safety layer, tolerating ML faults at runtime rather than eliminating them at design time\.

## IIIMethod

We now present the design of the proposed𝒮​𝒮\\mathcal\{SS\}framework\. We emphasize that𝒮​𝒮\\mathcal\{SS\}is not a standalone autonomy stack\. It is an architectural augmentation that operates atop an existing, fully functional ML layer, providing verifiable safety coordination without replacing any autonomy components\. Importantly,𝒮​𝒮\\mathcal\{SS\}is agnostic to the underlying ML model and makes no assumptions about the architecture or algorithm of the ML layer, operating atop any module that proposes actions\.

At its core,𝒮​𝒮\\mathcal\{SS\}extends the𝒫​𝒮\\mathcal\{PS\}architecture\[[6](https://arxiv.org/html/2605.08190#bib.bib36)\]by generalizing its unidirectional supervisory structure into a*bidirectional*information exchange between the mission and safety layers, as illustrated in[Figure1](https://arxiv.org/html/2605.08190#S1.F1)\. Classical Simplex designs rely on a one\-way supervisory link, where the safety layer monitors ML layer actions through*Fault Handlers*and intervenes only when safety conditions defined by the*Safety Layer Software*are violated\. In contrast,𝒮​𝒮\\mathcal\{SS\}establishes a two\-way information exchange architecture between the safety and ML layers that allows the software of both layers to cooperate, improving overall performance beyond what𝒫​𝒮\\mathcal\{PS\}achieves while preserving formal safety guarantees\. The following subsections formalize the Safety\-to\-ML \(S2M\) and ML\-to\-Safety \(M2S\) communication links and establish that, under their respective assumptions, both extensions preserve the safety guarantees of the original𝒫​𝒮\\mathcal\{PS\}architecture\.

### III\-ASafety Layer to ML Layer Communication

The safety\-to\-ML \(S2M\) link, shown in[Figure1](https://arxiv.org/html/2605.08190#S1.F1), enables the safety layer to convey verified information back to the ML layer\. When a violation is detected by the*Fault Handlers*, the safety layer communicates the violated constraints, allowing the ML layer to recompute actions within verified bounds\. Formally, when the ML layer proposes an actionaMa\_\{M\}that violates safety constraintsCSC\_\{S\}specified by the*Safety Layer Software*, the safety layer does not immediately override it\. Instead, the fault handler communicatesCSC\_\{S\}to the ML layer in an acceptable formfS2M​\(CS\)f\_\{\\text\{S2M\}\}\(C\_\{S\}\), wherefS2Mf\_\{\\text\{S2M\}\}transformsCSC\_\{S\}to match the ML layer input\. It then requests recomputation of the action under these constraints\. Leta^M\\hat\{a\}\_\{M\}denote the recomputed action\. The system proceeds as follows:

- •If the recomputed actiona^M\\hat\{a\}\_\{M\}satisfies all safety constraintsCSC\_\{S\}, the system adoptsa^M\\hat\{a\}\_\{M\}as the final action\.
- •If no such safe recomputation is possible, the safety layer overrides with its own verifiable safe actionasafea\_\{\\text\{safe\}\}\.

𝒫​𝒮\\mathcal\{PS\}can be viewed as a special case of this algorithm \(see[Algorithm1](https://arxiv.org/html/2605.08190#alg1)\) in which the recomputed action is fixed toasafea\_\{\\text\{safe\}\}\.

Algorithm 1Safety\-to\-ML Cooperative Action Selection1:Mission proposal

aMa\_\{M\}, safety constraints

CSC\_\{S\}
2:Final system action

a∗a^\{\*\}
3:if

aMa\_\{M\}satisfies

CSC\_\{S\}then

4:

a∗←aMa^\{\*\}\\leftarrow a\_\{M\}
5:else

6:Convert

CSC\_\{S\}into ML layer guardrails

fS2M​\(CS\)f\_\{\\text\{S2M\}\}\(C\_\{S\}\)
7:Request recomputation

a^M\\hat\{a\}\_\{M\}under

fS2M​\(CS\)f\_\{\\text\{S2M\}\}\(C\_\{S\}\)
8:if

a^M\\hat\{a\}\_\{M\}satisfies

CSC\_\{S\}then

9:

a∗←a^Ma^\{\*\}\\leftarrow\\hat\{a\}\_\{M\}
10:else

11:

a∗←asafea^\{\*\}\\leftarrow a\_\{\\text\{safe\}\}⊳\\trianglerightFallback safe override

12:return

a∗a^\{\*\}

We formalize the S2M selection\. Let𝒳\\mathcal\{X\}be the state space and𝒜\\mathcal\{A\}the action space\. For a given statex∈𝒳x\\in\\mathcal\{X\}, let

𝒮​\(x\)=\{a∈𝒜∣φ​\(x,a\)\}\\displaystyle\\mathcal\{S\}\(x\)\\;=\\;\\\{\\,a\\in\\mathcal\{A\}\\mid\\varphi\(x,a\)\\,\\\}\(1\)denote the set of actions that satisfy the safety constraintsCSC\_\{S\}\(i\.e\.the predicateφ​\(x,a\)\\varphi\(x,a\)encodesCSC\_\{S\}\)\. The safety layer provides a verification procedure

Ver​\(x,a\)∈\{true,false\}\\displaystyle\\mathrm\{Ver\}\(x,a\)\\in\\\{\\mathrm\{true\},\\mathrm\{false\}\\\}\(2\)used to test membership in𝒮​\(x\)\\mathcal\{S\}\(x\)\.

###### Assumption 1\(Sound Verification\)\.

For allx∈𝒳x\\in\\mathcal\{X\}anda∈𝒜a\\in\\mathcal\{A\}, ifVer​\(x,a\)=true\\mathrm\{Ver\}\(x,a\)=\\mathrm\{true\}thena∈𝒮​\(x\)a\\in\\mathcal\{S\}\(x\)\.

###### Assumption 2\(Safe Maneuverable State Space\)\.

There exists a subset𝒳S⊆𝒳\\mathcal\{X\}^\{S\}\\subseteq\\mathcal\{X\}such that:

1. 1\.For everyx∈𝒳Sx\\in\\mathcal\{X\}^\{S\}, the safety layer can produce at least one verifiable safe actionasafe∈𝒮​\(x\)a\_\{\\mathrm\{safe\}\}\\in\\mathcal\{S\}\(x\)that ensures the next state satisfies x​\(t\+1\)∈𝒳S\.x\(t\+1\)\\in\\mathcal\{X\}^\{S\}\.
2. 2\.The system is initialized in a statex​\(0\)∈𝒳Sx\(0\)\\in\\mathcal\{X\}^\{S\}\.

Thus,𝒳S\\mathcal\{X\}^\{S\}is an invariant set under the safe actionasafea\_\{\\mathrm\{safe\}\}\.

###### Assumption 3\(Validity Domain\)\.

The*Safety Layer Software*operates within its stated validity constraints, so that Assumptions[1](https://arxiv.org/html/2605.08190#Thmassumption1)–[2](https://arxiv.org/html/2605.08190#Thmassumption2)hold at the currentxx\.

Given a mission proposalaMa\_\{M\}, Algorithm[1](https://arxiv.org/html/2605.08190#alg1)returns

a∗∈\{aM,a^M,asafe\},\\displaystyle a^\{\*\}\\;\\in\\;\\\{\\,a\_\{M\},\\ \\hat\{a\}\_\{M\},\\ a\_\{\\text\{safe\}\}\\,\\\},\(3\)wherea^M\\hat\{a\}\_\{M\}is a recomputation under guardrails derived fromCSC\_\{S\}\.

###### Theorem 1\(Safety of S2M\)\.

Under[Assumptions1](https://arxiv.org/html/2605.08190#Thmassumption1),[2](https://arxiv.org/html/2605.08190#Thmassumption2)and[3](https://arxiv.org/html/2605.08190#Thmassumption3),[Algorithm1](https://arxiv.org/html/2605.08190#alg1)always returns an actiona∗∈𝒮​\(x\)a^\{\*\}\\in\\mathcal\{S\}\(x\)\.

###### Proof\.

We argue by contradiction\. Fixx∈𝒳x\\in\\mathcal\{X\}and suppose Algorithm[1](https://arxiv.org/html/2605.08190#alg1)returnsa∗a^\{\*\}witha∗∉𝒮​\(x\)a^\{\*\}\\notin\\mathcal\{S\}\(x\)\. By the algorithm’s structure there are three mutually exclusive cases:

*Case 1:a∗=aMa^\{\*\}=a\_\{M\}\.*The algorithm returnsaMa\_\{M\}only ifVer​\(x,aM\)=true\\mathrm\{Ver\}\(x,a\_\{M\}\)=\\mathrm\{true\}\. By Assumption[1](https://arxiv.org/html/2605.08190#Thmassumption1), this impliesaM∈𝒮​\(x\)a\_\{M\}\\in\\mathcal\{S\}\(x\), contradictinga∗∉𝒮​\(x\)a^\{\*\}\\notin\\mathcal\{S\}\(x\)\.

*Case 2:a∗=a^Ma^\{\*\}=\\hat\{a\}\_\{M\}\.*The algorithm returnsa^M\\hat\{a\}\_\{M\}only ifVer​\(x,a^M\)=true\\mathrm\{Ver\}\(x,\\hat\{a\}\_\{M\}\)=\\mathrm\{true\}\. By Assumption[1](https://arxiv.org/html/2605.08190#Thmassumption1),a^M∈𝒮​\(x\)\\hat\{a\}\_\{M\}\\in\\mathcal\{S\}\(x\), again a contradiction\.

*Case 3:a∗=a*safe*a^\{\*\}=a\_\{\\text\{safe\}\}\.*The algorithm falls back toasafea\_\{\\text\{safe\}\}only if bothVer​\(x,aM\)=false\\mathrm\{Ver\}\(x,a\_\{M\}\)=\\mathrm\{false\}andVer​\(x,a^M\)=false\\mathrm\{Ver\}\(x,\\hat\{a\}\_\{M\}\)=\\mathrm\{false\}\. By Assumption[2](https://arxiv.org/html/2605.08190#Thmassumption2),asafe∈𝒮​\(x\)a\_\{\\text\{safe\}\}\\in\\mathcal\{S\}\(x\), contradictinga∗∉𝒮​\(x\)a^\{\*\}\\notin\\mathcal\{S\}\(x\)\.

All cases contradict the supposition\. Hencea∗∈𝒮​\(x\)a^\{\*\}\\in\\mathcal\{S\}\(x\)\. ∎

### III\-BML Layer to Safety Layer Communication

The ML\-to\-safety \(M2S\) link allows the safety layer to incorporate selected outputs from the ML layer while preserving the formal safety guarantees of the architecture\. Concretely, in this paper we focus on using the ML layer’s*lane\-detection*output within the safety layer\. Lane detection is typically reliable and informative enough to enable more effective decision\-making in the safety layer\.

Traditionally, safety\-critical designs avoid incorporating unverifiable ML outputs into the safety layer, precisely to prevent such information from influencing verified safety guarantees\. Arbitrary use of ML information may introduce new fault\-propagation paths, potentially undermining existing safety guarantees\. This subsection formalizes the conditions under which such use is admissible and proves that𝒮​𝒮\\mathcal\{SS\}retains the guarantees of𝒫​𝒮\\mathcal\{PS\}when using ML layer outputs that satisfy these conditions\. We begin by formalizing the notion of a fault\.

###### Definition 1\(Fault\)\.

A*fault*is the adjudged or hypothesized cause of an error\[[3](https://arxiv.org/html/2605.08190#bib.bib94)\]\.

In our setting, faults correspond to deviations such as misclassifications or missed detections that may propagate to downstream functions and influence system\-level safety\.

![Refer to caption](https://arxiv.org/html/2605.08190v1/x3.png)Figure 3:Simplified dependency graph of the autonomy stack, showing independent, upstream, and downstream ML\-to\-safety\-layer links\.#### III\-B1Graph Model

We begin by formalizing the probabilistic fault model that underlies the M2S analysis\. Let the autonomy stack be represented as a directed acyclic graph \(DAG\)G=\(V,E\)G=\(V,E\), where “directed” indicates that each edge has a direction of information flow\. Each nodevi∈Vv\_\{i\}\\in Vdenotes a computational function \(e\.g\.,perception, planning, or safety\), and each edge\(vi,vj\)∈E\(v\_\{i\},v\_\{j\}\)\\in Erepresents both an information flow and a potential fault\-propagation path\. In this model, edges encode*depend*relations in the sense of system safety: a function that depends on another may inherit its faults, whereas mere use relations without fault\-propagation semantics are intentionally excluded\. Each node may produce faulty outputs, modeled by binary random variablesXi∈\{0,1\}X\_\{i\}\\in\\\{0,1\\\}, whereXi=1X\_\{i\}=1indicates that node \(function\)viv\_\{i\}exhibits a fault as defined in[Definition1](https://arxiv.org/html/2605.08190#Thmdefinition1)\. This abstraction allows us to reason about how faults propagate through the autonomy stack\.

Our formulation is inspired by the deterministic fault tree introduced in𝒫​𝒮\\mathcal\{PS\}\[[6](https://arxiv.org/html/2605.08190#bib.bib36)\], but generalizes it by allowing probabilistic propagation along each edge ofGG\. For illustration, and to provide intuition for the nodes depicted in[Figure3](https://arxiv.org/html/2605.08190#S3.F3), one may imagineAAas a downstream planner,BBas an independent lane detector,CCas an obstacle\-refinement module,\(DM,DS\)\(D\_\{M\},D\_\{S\}\)as the mission and safety layer obstacle detectors, andEEas an upstream preprocessing stage\. These mappings are merely illustrative and not inherent to the formal model\.

###### Assumption 4\(Fault Propagation\)\.

A fault propagates from a faulty nodeXXto a dependent nodeYYalong each edge with probabilityfX​Y∈\[0,1\]f\_\{XY\}\\in\[0,1\]\.

###### Assumption 5\(Downstream Bottleneck\)\.

The dependency graphGGcontains a unique downstream nodeu∈Vu\\in Vsuch that every maximal directed path inGGterminates atuu\.

[Assumption4](https://arxiv.org/html/2605.08190#Thmassumption4)generalizes the fault tree model from𝒫​𝒮\\mathcal\{PS\}\[[6](https://arxiv.org/html/2605.08190#bib.bib36)\], which is recovered when allfX​Y=1f\_\{XY\}=1\.[Assumption5](https://arxiv.org/html/2605.08190#Thmassumption5)reflects the structure of modern autonomy stacks, in which computations generally converge to a single downstream planning or control command executed by the vehicle\.

We additionally impose a structural assumption on the autonomy stack\. Modern perception\-planning pipelines are typically feed\-forward, with information flowing from sensing to control without forming feedback cycles between nodes\. The following assumption formalizes this property\.

###### Assumption 6\(Directed Acyclic Graph Structure\)\.

The dependency graphGGis a directed acyclic graph \(DAG\)\. That is, it contains no directed cycles\.

Given the directed acyclic graphG=\(V,E\)G=\(V,E\), we categorize all ML layer functions according to their structural relationship with the ML layer nodeDMD\_\{M\}that is covered by the safety layer nodeDSD\_\{S\}\(see[Figure3](https://arxiv.org/html/2605.08190#S3.F3)\)\.

###### Definition 2\(Independent, Upstream, and Downstream Functions\)\.

LetDM∈VD\_\{M\}\\in Vdenote the ML layer module \(e\.g\.,*obstacle detection*\) monitored by the safety layer\. For any node \(function\)X∈VX\\in Vin the graphGG:

- •*IndependentFunctions \(IF\):*XXis independent ofDMD\_\{M\}if no directed path connectsXXandDMD\_\{M\}in either direction\.
- •*UpstreamFunctions \(UF\):*XXis upstream ofDMD\_\{M\}if there exists a directed pathX↝DMX\\leadsto D\_\{M\}inGG\.
- •*DownstreamFunctions \(DF\):*XXis downstream ofDMD\_\{M\}if there exists a directed pathDM↝XD\_\{M\}\\leadsto XinGG\.

We base our analysis on a simplified dependency graph for clarity\. All subsequent results extend to any autonomy graph that satisfies[Assumptions4](https://arxiv.org/html/2605.08190#Thmassumption4),[5](https://arxiv.org/html/2605.08190#Thmassumption5)and[6](https://arxiv.org/html/2605.08190#Thmassumption6), since the analysis depends only on structural relations \(upstream, downstream, independent\) rather than on the specific number of modules\.

We now analyze, in turn, whether each class of functions \(independent, upstream, and downstream\) can be safely incorporated into the safety layer through ML\-to\-safety use, thus augmenting𝒫​𝒮\\mathcal\{PS\}into the proposed𝒮​𝒮\\mathcal\{SS\}architecture\. The three use configurations shown in[Figure3](https://arxiv.org/html/2605.08190#S3.F3)correspond to the independent, upstream, and downstream cases analyzed in[SectionsIII\-B2](https://arxiv.org/html/2605.08190#S3.SS2.SSS2),[III\-B3](https://arxiv.org/html/2605.08190#S3.SS2.SSS3)and[III\-B4](https://arxiv.org/html/2605.08190#S3.SS2.SSS4)respectively\.

#### III\-B2Independent Functions

We begin by analyzing how using independent nodes in the safety layer influences system\-level correctness in the architectures considered in this paper: ML baseline,𝒫​𝒮\\mathcal\{PS\}, and𝒮​𝒮\\mathcal\{SS\}\. Intuitively, independent functions correspond to disjoint functional branches of the autonomy stack\. For example, lane and obstacle detection operate on the same sensor inputs but generate outputs that do not depend on one another \(see[Figure3](https://arxiv.org/html/2605.08190#S3.F3)a\)\. This structural separation ensures that information used from one module cannot propagate faults into another module’s correctness domain\.

In the unprotected machine\-learning baseline, the safety layer nodeDSD\_\{S\}is absent, and all ML layer functions may propagate faults to the downstream nodeAA\. For illustration, consider the two disjoint upstream branchesB↝AB\\leadsto AandDM↝AD\_\{M\}\\leadsto A\. Letf1=fB​Af\_\{1\}=f\_\{BA\}denote the propagation probability along theB↝AB\\leadsto Aedge, and letf2=fDM​Af\_\{2\}=f\_\{D\_\{M\}A\}denote the propagation probability along theDM↝AD\_\{M\}\\leadsto Apath\. The resulting failure probability forAAis

pML\(A=1∣B=1,DM=0\)\\displaystyle p\_\{\\text\{ML\}\}\(A=1\\mid B=1,D\_\{M\}=0\)=f1,\\displaystyle=f\_\{1\},\(4\)pML\(A=1∣B=0,DM=1\)\\displaystyle p\_\{\\text\{ML\}\}\(A=1\\mid B=0,D\_\{M\}=1\)=f2,\\displaystyle=f\_\{2\},\(5\)pML\(A=1∣B=1,DM=1\)\\displaystyle p\_\{\\text\{ML\}\}\(A=1\\mid B=1,D\_\{M\}=1\)=f1\+f2−f1​f2\.\\displaystyle=f\_\{1\}\+f\_\{2\}\-f\_\{1\}f\_\{2\}\.\(6\)
𝒫​𝒮\\mathcal\{PS\}introduces a verifiable safety nodeDSD\_\{S\}associated with the ML layer nodeDMD\_\{M\}\. Faults fromDMD\_\{M\}can affectAAonly if bothDMD\_\{M\}andDSD\_\{S\}are faulty\. Under normal operation,DSD\_\{S\}monitors the outputs ofDMD\_\{M\}and overrides them when a verified violation is detected\.

###### Assumption 7\(Safety Layer Reliability\)\.

The safety layer \(nodeDSD\_\{S\}\) operates within its verified domain and therefore never produces faults, i\.e\.p​\(DS=1\)=0p\(D\_\{S\}=1\)=0\.

Under[Assumption7](https://arxiv.org/html/2605.08190#Thmassumption7), the probabilities in𝒫​𝒮\\mathcal\{PS\}simplify to

pPS\(A=1∣B=1,DM=0\)\\displaystyle p\_\{\\text\{PS\}\}\(A=1\\mid B=1,D\_\{M\}=0\)=f1,\\displaystyle=f\_\{1\},\(7\)pPS\(A=1∣B=0,DM=1\)\\displaystyle p\_\{\\text\{PS\}\}\(A=1\\mid B=0,D\_\{M\}=1\)=0,\\displaystyle=0,\(8\)pPS\(A=1∣B=1,DM=1\)\\displaystyle p\_\{\\text\{PS\}\}\(A=1\\mid B=1,D\_\{M\}=1\)=f1\.\\displaystyle=f\_\{1\}\.\(9\)
Hence,𝒫​𝒮\\mathcal\{PS\}guarantees that no unsafe behavior arises when*only*the corresponding ML layer module fails — in this case, the obstacle detectorDMD\_\{M\}\. Trivially, it also guarantees safety when none of the ML layer functions fail\.

In𝒮​𝒮\\mathcal\{SS\}, the safety layer \(nodeDSD\_\{S\}\) may use information from an independent ML layer function \(e\.g\.,nodeBB\), as illustrated in[Figure3](https://arxiv.org/html/2605.08190#S3.F3)via the addedB→DSB\\to D\_\{S\}edge\. This configuration corresponds to disjoint branches in the fault tree, where the used information originates from a module whose faults are causally decoupled from those covered by the Simplex relation\.

To clarify why the M2S link preserves the formal guarantees of the original𝒫​𝒮\\mathcal\{PS\}, we highlight the standard independence assumptions that underlie Simplex architectures\. We then show how they naturally extend to lane detection in𝒮​𝒮\\mathcal\{SS\}\. It is standard in Simplex architectures to assume correctness of certain independent components\. For example,𝒫​𝒮\\mathcal\{PS\}assumes that the braking system operates correctly during an emergency stop: if the brakes were to malfunction, the vehicle could fail to decelerate even when the safety layer issues a verified override\. Such failures fall outside the Simplex guarantee envelope because they concern independent subsystems that the safety layer neither monitors nor controls\.

The same argument applies to independent software functions used by𝒮​𝒮\\mathcal\{SS\}\. Lane detection plays the role of such an essential and independent component: its correctness is required for safe autonomous driving regardless of whether its output is used in the safety layer\. If lane detection were faulty, hazards such as drifting out of the lane or entering opposing traffic could occur irrespective of the M2S link\. At the same time, lane information is precisely what determines whether a detected obstacle lies in the ego lane, where it is safety\-critical, or in a neighboring lane, where it poses less immediate threat\. Thus, assuming correct lane detection is analogous to assuming correct braking behavior in classical Simplex designs\. Moreover, incorporating lane information allows𝒮​𝒮\\mathcal\{SS\}to safely reduce conservativeness by discounting obstacles that are not in the ego lane\.

We now formalize this intuition and show that the independence condition suffices for𝒮​𝒮\\mathcal\{SS\}to inherit the safety guarantees of𝒫​𝒮\\mathcal\{PS\}\. When transitioning from𝒫​𝒮\\mathcal\{PS\}to𝒮​𝒮\\mathcal\{SS\}, we drop[Assumption7](https://arxiv.org/html/2605.08190#Thmassumption7), since the safety layer \(DSD\_\{S\}\) now ingests ML\-layer information and can no longer be assumed fault\-free\. Nevertheless, under this independence condition,𝒮​𝒮\\mathcal\{SS\}retains the formal safety guarantees of𝒫​𝒮\\mathcal\{PS\}\.

###### Theorem 2\(Safety of𝒮​𝒮\\mathcal\{SS\}under Independent M2S Use\)\.

When𝒮​𝒮\\mathcal\{SS\}uses ML layer outputs from functions independent of the one covered by the Simplex relation, the system preserves the safety guarantees of𝒫​𝒮\\mathcal\{PS\}\. Formally,

pIF\(A=1∣B=0,DM=1\)=0\.\\displaystyle p\_\{\\text\{IF\}\}\(A=1\\mid B=0,D\_\{M\}=1\)=0\.\(10\)

###### Proof\.

The M2S link introduces a new edge\(B,DS\)\(B,D\_\{S\}\), allowing ML information to influence the safety layer\. Letf3=fB​DS∈\[0,1\]f\_\{3\}=f\_\{BD\_\{S\}\}\\in\[0,1\]denote the probability that a fault propagates along this new edge\. The modified fault propagation model yields:

pIF\(A=1∣B=1,DM=0\)\\displaystyle p\_\{\\text\{IF\}\}\(A=1\\mid B=1,D\_\{M\}=0\)=f1,\\displaystyle=f\_\{1\},\(11\)pIF\(A=1∣B=0,DM=1\)\\displaystyle p\_\{\\text\{IF\}\}\(A=1\\mid B=0,D\_\{M\}=1\)=0,\\displaystyle=0,\(12\)pIF\(A=1∣B=1,DM=1\)\\displaystyle p\_\{\\text\{IF\}\}\(A=1\\mid B=1,D\_\{M\}=1\)=f1\+f2​f3−f1​f2​f3\.\\displaystyle=f\_\{1\}\+f\_\{2\}f\_\{3\}\-f\_\{1\}f\_\{2\}f\_\{3\}\.\(13\)SincepIF\(A=1∣B=0,DM=1\)=0p\_\{\\text\{IF\}\}\(A=1\\mid B=0,D\_\{M\}=1\)=0, the safety guarantee against failures inDMD\_\{M\}remains identical to𝒫​𝒮\\mathcal\{PS\}\. Thus, using outputs of independent functions does not affect safety against faults in the Simplex\-covered function\. ∎

##### Risk Bounds Under Multi\-Function ML Layer Failures

It is noteworthy that when the entire input stack of the ML layer fails \(i\.e\.bothBBandDMD\_\{M\}are faulty\),𝒫​𝒮\\mathcal\{PS\}reduces but does not eliminate the risk of system\-level failure\. It reduces the failure probability fromf1\+f2−f1​f2f\_\{1\}\+f\_\{2\}\-f\_\{1\}f\_\{2\}tof1f\_\{1\}according to[Equations6](https://arxiv.org/html/2605.08190#S3.E6)and[9](https://arxiv.org/html/2605.08190#S3.E9)\.𝒮​𝒮\\mathcal\{SS\}also reduces the failure probability, but to a lesser extent\. This failure mode lies outside the formal guarantee envelope of𝒫​𝒮\\mathcal\{PS\}and𝒮​𝒮\\mathcal\{SS\}and therefore does not violate their stated safety properties\.

###### Theorem 3\(Comparative Risk Bounds\)\.

LetF:=\{B=1,DM=1\}F:=\\\{B=1,D\_\{M\}=1\\\}denote the event that both ML layer inputs are faulty\. UnderFF, the following inequality holds:

pPS​\(A=1∣F\)≤pIF​\(A=1∣F\)≤pML​\(A=1∣F\),\\displaystyle p\_\{\\text\{PS\}\}\(A=1\\mid\\text\{F\}\)\\leq p\_\{\\text\{IF\}\}\(A=1\\mid\\text\{F\}\)\\leq p\_\{\\text\{ML\}\}\(A=1\\mid\\text\{F\}\),\(14\)where

pPS\(A=1∣B=1,DM=1\)\\displaystyle p\_\{\\text\{PS\}\}\(A=1\\mid B=1,D\_\{M\}=1\)=f1,\\displaystyle=f\_\{1\},\(15\)pIF\(A=1∣B=1,DM=1\)\\displaystyle p\_\{\\text\{IF\}\}\(A=1\\mid B=1,D\_\{M\}=1\)=f1\+f2​f3−f1​f2​f3,\\displaystyle=f\_\{1\}\+f\_\{2\}f\_\{3\}\-f\_\{1\}f\_\{2\}f\_\{3\},\(16\)pML\(A=1∣B=1,DM=1\)\\displaystyle p\_\{\\text\{ML\}\}\(A=1\\mid B=1,D\_\{M\}=1\)=f1\+f2−f1​f2\.\\displaystyle=f\_\{1\}\+f\_\{2\}\-f\_\{1\}f\_\{2\}\.\(17\)

###### Proof\.

Since allfi∈\[0,1\]f\_\{i\}\\in\[0,1\],

0≤f2​f3​\(1−f1\)≤f2​\(1−f1\)\.\\displaystyle 0\\leq f\_\{2\}f\_\{3\}\(1\-f\_\{1\}\)\\leq f\_\{2\}\(1\-f\_\{1\}\)\.\(18\)Addingf1f\_\{1\}to each term yields

f1≤f1\+f2​f3​\(1−f1\)≤f1\+f2​\(1−f1\),\\displaystyle f\_\{1\}\\leq f\_\{1\}\+f\_\{2\}f\_\{3\}\(1\-f\_\{1\}\)\\leq f\_\{1\}\+f\_\{2\}\(1\-f\_\{1\}\),\(19\)that is,

f1≤f1\+f2​f3−f1​f2​f3≤f1\+f2−f1​f2\.\\displaystyle f\_\{1\}\\leq f\_\{1\}\+f\_\{2\}f\_\{3\}\-f\_\{1\}f\_\{2\}f\_\{3\}\\leq f\_\{1\}\+f\_\{2\}\-f\_\{1\}f\_\{2\}\.\(20\)Identifying these three quantities aspPS​\(A=1∣F\)p\_\{\\text\{PS\}\}\(A=1\\mid F\),pIF​\(A=1∣F\)p\_\{\\text\{IF\}\}\(A=1\\mid F\), andpML​\(A=1∣F\)p\_\{\\text\{ML\}\}\(A=1\\mid F\)gives the claimed inequality\. ∎

These results establish that𝒮​𝒮\\mathcal\{SS\}retains the deterministic safety guarantees of𝒫​𝒮\\mathcal\{PS\}for independent ML layer function use, while being verifiably safe in the scenario where only the corresponding ML layer module fails\. At the same time,𝒮​𝒮\\mathcal\{SS\}tolerates a marginally higher overall system risk when the entire mission input stack \(e\.g\.,BBandDMD\_\{M\}\) fails\. As already mentioned, this failure mode is beyond the formal guarantee envelope of both𝒫​𝒮\\mathcal\{PS\}and𝒮​𝒮\\mathcal\{SS\}, and the comparison here reflects an extended robustness analysis rather than a weakening of the stated safety properties\. This intentional relaxation trades a small amount of global robustness for improved performance and reduced conservativeness, as empirically confirmed in[SectionVI](https://arxiv.org/html/2605.08190#S6), yielding a more balanced safety\-efficiency trade\-off while preserving the verified safety envelope established by𝒫​𝒮\\mathcal\{PS\}as stated in[Theorem2](https://arxiv.org/html/2605.08190#Thmtheorem2)\.

#### III\-B3Upstream Functions

Upstream functions lie on the same dependency branch as the Simplexed ML layer function, as illustrated in[Figure3](https://arxiv.org/html/2605.08190#S3.F3)b\. Letf1=fDM​Af\_\{1\}=f\_\{D\_\{M\}A\}denote the propagation probability fromDMD\_\{M\}to the downstream nodeAA, and letf2=fE​DMf\_\{2\}=f\_\{ED\_\{M\}\}denote the propagation probability along the added upstream\-to\-safety\-layer edgeE↝DME\\leadsto D\_\{M\}\.

In the unprotected ML baseline, the safety nodeDSD\_\{S\}is absent, and faults may propagate directly fromDMD\_\{M\}intoAA:

pML\(A=1∣DM=0,E=1\)\\displaystyle p\_\{\\text\{ML\}\}\(A=1\\mid D\_\{M\}=0,E=1\)=0,\\displaystyle=0,\(21\)pML\(A=1∣DM=1,E=0\)\\displaystyle p\_\{\\text\{ML\}\}\(A=1\\mid D\_\{M\}=1,E=0\)=f1,\\displaystyle=f\_\{1\},\(22\)pML\(A=1∣DM=1,E=1\)\\displaystyle p\_\{\\text\{ML\}\}\(A=1\\mid D\_\{M\}=1,E=1\)=f1\.\\displaystyle=f\_\{1\}\.\(23\)Since we condition onDM=1D\_\{M\}=1in the last two cases, the upstream propagation probabilityf2f\_\{2\}does not appear\.

When𝒫​𝒮\\mathcal\{PS\}introduces the safety nodeDSD\_\{S\}, the Simplex relation prevents any propagation of faults fromDMD\_\{M\}or its upstream ancestors:

pPS\(A=1∣DM=0,E=1\)\\displaystyle p\_\{\\text\{PS\}\}\(A=1\\mid D\_\{M\}=0,E=1\)=0,\\displaystyle=0,\(24\)pPS\(A=1∣DM=1,E=0\)\\displaystyle p\_\{\\text\{PS\}\}\(A=1\\mid D\_\{M\}=1,E=0\)=0,\\displaystyle=0,\(25\)pPS\(A=1∣DM=1,E=1\)\\displaystyle p\_\{\\text\{PS\}\}\(A=1\\mid D\_\{M\}=1,E=1\)=0\.\\displaystyle=0\.\(26\)Thus,𝒫​𝒮\\mathcal\{PS\}enforces that faults in eitherEEorDMD\_\{M\}cannot influenceAA\.

Now consider extending𝒫​𝒮\\mathcal\{PS\}to𝒮​𝒮\\mathcal\{SS\}by introducing an upstream use edge\(E,DS\)\(E,D\_\{S\}\)\. Letf3=fE​DSf\_\{3\}=f\_\{ED\_\{S\}\}denote the fault propagation probability along this new edge\. In this case:

pUF\(A=1∣DM=1,E=0\)\\displaystyle p\_\{\\text\{UF\}\}\(A=1\\mid D\_\{M\}=1,E=0\)=0,\\displaystyle=0,\(27\)pUF\(A=1∣DM=0,E=1\)\\displaystyle p\_\{\\text\{UF\}\}\(A=1\\mid D\_\{M\}=0,E=1\)=0,\\displaystyle=0,\(28\)pUF\(A=1∣DM=1,E=1\)\\displaystyle p\_\{\\text\{UF\}\}\(A=1\\mid D\_\{M\}=1,E=1\)=f1​f3\.\\displaystyle=f\_\{1\}f\_\{3\}\.\(29\)
The new M2S edge enables a fault\-propagation pathE↝DS↝A,E\\leadsto D\_\{S\}\\leadsto A,which is*structurally impossible*in𝒫​𝒮\\mathcal\{PS\}\. Wheneverf1,f3\>0f\_\{1\},f\_\{3\}\>0, a fault inEEcan affectAAconditional onDM=1D\_\{M\}=1, violating the guarantee in[Equation26](https://arxiv.org/html/2605.08190#S3.E26)\.

###### Theorem 4\(Upstream Use Inadmissibility\)\.

Under[Assumptions4](https://arxiv.org/html/2605.08190#Thmassumption4)and[6](https://arxiv.org/html/2605.08190#Thmassumption6), introducing an upstream use edge\(E,DS\)\(E,D\_\{S\}\)violates the Perception Simplex safety guarantee

pPS\(A=1∣DM=1,E=1\)=0\.\\displaystyle p\_\{\\text\{PS\}\}\(A=1\\mid D\_\{M\}=1,E=1\)=0\.\(30\)

###### Proof\.

SinceE↝DME\\leadsto D\_\{M\}, a fault inEEmay corruptDMD\_\{M\}, but𝒫​𝒮\\mathcal\{PS\}enforces

pPS\(A=1∣DM=1,E=1\)=0\.\\displaystyle p\_\{\\text\{PS\}\}\(A=1\\mid D\_\{M\}=1,E=1\)=0\.\(31\)Introducing the edge\(E,DS\)\(E,D\_\{S\}\)creates the additional propagation pathE↝DS↝A\.E\\leadsto D\_\{S\}\\leadsto A\.Conditioned onDM=1D\_\{M\}=1, this yields

pUF\(A=1∣DM=1,E=1\)=f1f3,\\displaystyle p\_\{\\text\{UF\}\}\(A=1\\mid D\_\{M\}=1,E=1\)=f\_\{1\}f\_\{3\},\(32\)which is strictly positive whenf1,f3\>0f\_\{1\},f\_\{3\}\>0and therefore contradicts the𝒫​𝒮\\mathcal\{PS\}guarantee\. Hence, upstream use is prohibited\. ∎

Therefore,𝒮​𝒮\\mathcal\{SS\}prohibits incorporating upstream ML layer outputs into the safety layer, ensuring preservation of the core𝒫​𝒮\\mathcal\{PS\}safety invariants\.

#### III\-B4Downstream Functions

Downstream functions lie strictly after the Simplexed ML layer nodeDMD\_\{M\}in the dependency graph and therefore do not influence the correctness ofDMD\_\{M\}or the safety layer nodeDSD\_\{S\}\([Figure3](https://arxiv.org/html/2605.08190#S3.F3)c\)\. Introducing an M2S link from such a function toDSD\_\{S\}would create a backward edge that violates[Assumption6](https://arxiv.org/html/2605.08190#Thmassumption6)and fundamentally alters the model by enabling temporal or multi\-cycle dependencies\. Such connections fall outside the static, single\-cycle fault\-propagation model analyzed in this paper, and a rigorous treatment would require an explicit temporal extension of the dependency graph, which is beyond the scope of the present formulation\. We therefore exclude downstream\-to\-safety use from our admissible M2S set\. A complete analysis of this case is left for future work\.

## IVApplication to Autonomous Vehicles

![Refer to caption](https://arxiv.org/html/2605.08190v1/x4.png)Figure 4:Instantiation of𝒮​𝒮\\mathcal\{SS\}for AVs\. The safety layer performs verifiable LiDAR\-based obstacle detection using the detectability model of\[[5](https://arxiv.org/html/2605.08190#bib.bib10)\]and a verified override policy\[[6](https://arxiv.org/html/2605.08190#bib.bib36)\]\. Lane\-detection outputs flow through the M2S link to refine obstacle criticality without weakening safety guarantees\.### IV\-AML Layer

The ML layer is a high\-performance autonomy stack for perception implemented using*TransFuser\+\+*\[[24](https://arxiv.org/html/2605.08190#bib.bib92)\], a representative, state\-of\-the\-art end\-to\-end driving model from the well\-established CARLA Garage benchmark\. As𝒮​𝒮\\mathcal\{SS\}is agnostic to the underlying ML layer, the evaluation focuses on its coordination with the safety layer rather than model comparison\. The end\-to\-end nature of*TransFuser\+\+*represents a challenging instantiation for𝒮​𝒮\\mathcal\{SS\}: despite not being designed for modular interfacing, it exposes intermediate outputs that can be leveraged through the M2S link, demonstrating the practical accessibility of the𝒮​𝒮\\mathcal\{SS\}framework even in non\-modular settings\. Evaluating𝒮​𝒮\\mathcal\{SS\}with modular autonomy stacks, which natively support constraint injection and would enable full joint evaluation of both communication links, is a natural direction for future work\.

Synchronized RGB and LiDAR inputs are processed to produce object detections, lane estimates, and scene semantics, corresponding to the ML components in[SectionIII](https://arxiv.org/html/2605.08190#S3)\. Waypoints and control commands \(steering, throttle, brake\) are then generated and executed by a low\-level controller\. Selected outputs \(e\.g\.,obstacle detections, ego velocity, control commands, and lane estimates\) are exposed to the safety layer for runtime monitoring and M2S communication\.

### IV\-BSafety Layer

The safety layer follows the verifiable perception framework of𝒫​𝒮\\mathcal\{PS\}\[[6](https://arxiv.org/html/2605.08190#bib.bib36)\], extended to support the interactions introduced by𝒮​𝒮\\mathcal\{SS\}, and remains decoupled from the ML layer\. It employs a LiDAR\-based geometric detector with an analytically derived detectability model, ensuring obstacle detection whenevery≥k​x\+by\\geq kx\+b\(cf\.[SectionII\-B](https://arxiv.org/html/2605.08190#S2.SS2)\), which defines the maximum safe velocityvmax𝑠𝑎𝑓𝑒v\_\{\\max\}^\{\\mathit\{safe\}\}for guaranteed stopping\. The safety layer monitors ML outputs \(obstacle detections, velocity, and control commands\) and issues an override when a critical obstacle is missed\. The safe actionasafea\_\{\\text\{safe\}\}applies controlled braking, ensuring collision avoidance belowvmax𝑠𝑎𝑓𝑒v\_\{\\max\}^\{\\mathit\{safe\}\}\.

###### Assumption 8\(No Sensor Failure\)\.

All sensors operate nominally, providing correct and timely measurements\. Sensor malfunctions, such as LiDAR dropouts, camera failures, or corrupted signals, are assumed not to occur during evaluation\.

This assumption is orthogonal to𝒮​𝒮\\mathcal\{SS\}and outside the scope of this work\. Sensor failures are assumed to be handled by state\-of\-the\-art approaches\.

###### Assumption 9\(Static Obstacles\)\.

All obstacles are static\.

This assumption is inherited directly from𝒫​𝒮\\mathcal\{PS\}\[[6](https://arxiv.org/html/2605.08190#bib.bib36)\]and is not introduced by𝒮​𝒮\\mathcal\{SS\}\. The contribution of𝒮​𝒮\\mathcal\{SS\}is a formal framework for safe bidirectional communication between ML and safety layers\. Elevating the static obstacle assumption would require extending the underlying VOD\[[5](https://arxiv.org/html/2605.08190#bib.bib10)\], which is an orthogonal research problem outside the scope of this work\.

It is worth noting that this assumption is less restrictive in practice than it may initially appear\. As observed in𝒫​𝒮\\mathcal\{PS\}, the safety guarantees remain applicable when obstacles are moving*away*from the ego vehicle, since such motion only increases the available stopping distance\. This means that both𝒫​𝒮\\mathcal\{PS\}and𝒮​𝒮\\mathcal\{SS\}apply directly to directed highway driving, where oncoming traffic is physically separated — a practically significant and common real\-world scenario\. Handling fully dynamic environments, including adversarial or crossing agents, remains an open problem requiring separate treatment\.

### IV\-CSafety Layer to ML Layer Communication

The S2M link enables the safety layer to provide safety\-verified constraintsf​\(CS\)f\(C\_\{S\}\)\(e\.g\.,obstacle locations\) to the ML layer, allowing it to replan within the certified safety envelope instead of being immediately overridden\.

In systems with constraint\-aware planners, the ML layer can incorporatef​\(CS\)f\(C\_\{S\}\)to generate a safe trajectory, which is executed if it satisfies the safety constraints\. Otherwise, the safety layer applies the fallback actionasafea\_\{\\text\{safe\}\}\. This mechanism transforms the𝒫​𝒮\\mathcal\{PS\}override into a cooperative process, preserving formal safety while reducing unnecessary interventions\.

In the CARLA\-based instantiation, the*TransFuser\+\+*model does not support constraint injection due to its end\-to\-end nature, and S2M cannot be realized\. Therefore, S2M is evaluated separately in an auxiliary experiment using a planner\-based autonomy stack built on nuPlan\[[11](https://arxiv.org/html/2605.08190#bib.bib98)\]\.

### IV\-DML Layer to Safety Layer Communication

To illustrate the practical use of𝒮​𝒮\\mathcal\{SS\}, we apply it to an AV system, with the safety layer and M2S link shown in[Figure4](https://arxiv.org/html/2605.08190#S4.F4)and conceptually summarized in[Figure1](https://arxiv.org/html/2605.08190#S1.F1)\.

In our AV instantiation of𝒮​𝒮\\mathcal\{SS\}, the M2S link provides the safety layer with ML outputs that are admissible under[SectionIII\-B](https://arxiv.org/html/2605.08190#S3.SS2)\. We use*lane detection*, which is independent of obstacle detection under[Definition2](https://arxiv.org/html/2605.08190#Thmdefinition2)\. This independence holds in the*TransFuser\+\+*\[[24](https://arxiv.org/html/2605.08190#bib.bib92)\]implementation, allowing the safety layer to refine obstacle relevance without weakening𝒫​𝒮\\mathcal\{PS\}guarantees\. Although the model is end\-to\-end and does not support constraint injection, it exposes intermediate outputs \(e\.g\.,lane boundaries\) that can be leveraged through M2S\.

###### Assumption 10\(Lane\-Detection Correctness\)\.

The ML layer’s lane\-detection module provides correct lane\-boundary estimates \(i\.e\.B=0B=0\) for the scenarios considered\.

This assumption is not required for the safety guarantees of𝒮​𝒮\\mathcal\{SS\}and does not weaken them\. As established in[SectionIII\-B2](https://arxiv.org/html/2605.08190#S3.SS2.SSS2), lane detection is independent of the Simplex\-protected function and therefore does not affect the guarantee boundary\. Moreover, correct lane estimation is already required for safe autonomous driving regardless of whether it is used in the safety layer, analogous to standard assumptions such as correct actuator behavior in classical Simplex designs,e\.g\.,that brakes will engage when commanded\. In practice, lane detection is a comparatively mature perception task and is routinely relied upon by modern autonomy stacks\. We make this assumption solely to ensure that the scenarios considered in our evaluation remain within the formal guarantee envelope, avoiding the need to evaluate behavior in regions where neither𝒫​𝒮\\mathcal\{PS\}nor𝒮​𝒮\\mathcal\{SS\}provides formal guarantees\. When lane detection is faulty, the system transitions to regions outside the formal guarantee envelope, where neither𝒫​𝒮\\mathcal\{PS\}nor𝒮​𝒮\\mathcal\{SS\}provides guarantees\. Importantly, this does not introduce new failure modes relative to𝒫​𝒮\\mathcal\{PS\}, but simply reflects the inherent limits of the underlying safety model\.

The safety layer uses lane\-boundary estimates to determine whether a verified obstacle lies in the ego lane or an adjacent lane\. A three\-zone policy is applied: \(1\)*Zone 1*\(ego lane\): triggers braking as in𝒫​𝒮\\mathcal\{PS\}; \(2\)*Zone 2*\(adjacent lanes\): triggers lighter mitigation \(i\.e\.throttle release\); \(3\)*Zone 3*: ignores irrelevant obstacles\. Compared to𝒫​𝒮\\mathcal\{PS\}, which treats the entire field of view as Zone 1,𝒮​𝒮\\mathcal\{SS\}uses lane context to reduce unnecessary braking while preserving guarantees \([Figure5](https://arxiv.org/html/2605.08190#S4.F5)\)\.

![Refer to caption](https://arxiv.org/html/2605.08190v1/x5.png)Figure 5:Zoning policy guiding how the safety layer of𝒮​𝒮\\mathcal\{SS\}responds to obstacles based on lane\-relative relevance\.Preservation of Safety Guarantees\.[Figure6](https://arxiv.org/html/2605.08190#S4.F6)visualizes the relationship between ML\-layer fault regions and the system’s safety guarantees under𝒫​𝒮\\mathcal\{PS\}and𝒮​𝒮\\mathcal\{SS\}\.𝒫​𝒮\\mathcal\{PS\}provides formal guarantees for the green\-highlighted region 1, where obstacle detection is the*only*fault: in this case, the system brakes safely and avoids collision\. As proven in[SectionIII\-B2](https://arxiv.org/html/2605.08190#S3.SS2.SSS2), incorporating an independent ML function into the safety layer, here lane detection, does not alter this guarantee boundary in𝒮​𝒮\\mathcal\{SS\}\.

If lane detection degrades, the overall system transitions to region 3\. If both lane and obstacle detection degrade, it transitions to region 2\. However, both regions lie outside the guarantee region of𝒫​𝒮\\mathcal\{PS\}, which covers only obstacle\-detection faults\. Thus, they are also outside the guarantees of𝒮​𝒮\\mathcal\{SS\}\.

From the perspective of both𝒫​𝒮\\mathcal\{PS\}and𝒮​𝒮\\mathcal\{SS\}, these regions are equivalent in that each involves at least one fault beyond obstacle detection, and therefore falls outside the scope of formal guarantees\.𝒮​𝒮\\mathcal\{SS\}therefore preserves the deterministic safety properties of𝒫​𝒮\\mathcal\{PS\}exactly, while using lane context to reduce conservativeness within the guaranteed region \(region 1\)\.

![Refer to caption](https://arxiv.org/html/2605.08190v1/x6.png)Figure 6:ML fault regions and their relation to the safety guarantees of𝒫​𝒮\\mathcal\{PS\}and𝒮​𝒮\\mathcal\{SS\}\. Region 1 \(obstacle detection fault only\) lies within the formal guaranteed safe region\. Regions 2–3 lie outside the guaranteed safe region of both𝒫​𝒮\\mathcal\{PS\}and𝒮​𝒮\\mathcal\{SS\}\. Circle sizes are illustrative and do not reflect fault frequency\.

## VEvaluation Setup

We evaluate𝒮​𝒮\\mathcal\{SS\}primarily in the CARLA simulation environment, focusing on the safety layer and the M2S link\. Because the end\-to\-end policy does not support constraint injection \(see[SectionIV\-C](https://arxiv.org/html/2605.08190#S4.SS3)\), the S2M link is evaluated separately in an auxiliary experiment based on nuPlan\[[11](https://arxiv.org/html/2605.08190#bib.bib98)\]\.

We evaluate𝒮​𝒮\\mathcal\{SS\}primarily in the CARLA simulation environment, focusing on the safety layer and the M2S link\. Because the end\-to\-end policy does not support constraint injection \(see[SectionIV\-C](https://arxiv.org/html/2605.08190#S4.SS3)\), the S2M link is evaluated separately in an auxiliary experiment based on nuPlan\[[11](https://arxiv.org/html/2605.08190#bib.bib98)\]\. While this means the full bidirectional architecture is not demonstrated within a single autonomy stack, the two links address structurally independent mechanisms and their separate evaluation provides valid evidence for each\. Joint evaluation using a modular autonomy stack that natively supports both intermediate output exposure and constraint injection remains an important direction for future work, consistent with the discussion in[SectionIV](https://arxiv.org/html/2605.08190#S4)\.

### V\-ASimulation Setup

#### V\-A1CARLA Evaluation Setup

We use the CARLA simulator\[[16](https://arxiv.org/html/2605.08190#bib.bib91)\]withCARLA Garage\[[24](https://arxiv.org/html/2605.08190#bib.bib92)\], which provides a modular autonomy stack and standardized scenarios\. TheTransFuser\+\+model serves as the ML layer, and we integrate the safety layer to realize the CARLA instantiation of𝒮​𝒮\\mathcal\{SS\}, focusing on safety\-layer behavior and M2S communication\.

Experiments are conducted in controlled, traffic\-free environments based on the “Parked Obstacle” scenario from the CARLA Leaderboard benchmark111[https://leaderboard\.carla\.org/scenarios/](https://leaderboard.carla.org/scenarios/), enabling deterministic fault injection and reproducible evaluation\. All runs use consistent environmental conditions \(daylight, clear weather, and good road quality\)\. LiDAR measurements are collected at2​Hz2\\,\\mathrm\{Hz\}\. The evaluation setup will be open\-sourced upon publication\.

#### V\-A2nuPlan Evaluation Setup

To evaluate the S2M link, we use the nuPlan simulation environment\[[11](https://arxiv.org/html/2605.08190#bib.bib98)\], which exposes a planner interface for constraint injection\. In this setting, the safety layer provides verified constraints \(e\.g\.,obstacle locations\) to the planner, enabling replanning under S2M using a fault model consistent with the CARLA experiments\.

### V\-BModels

We consider a set of autonomy architectures and variants of𝒮​𝒮\\mathcal\{SS\}across the evaluation setups described above\.

##### ML\-Based Agent \(TransFuser\+\+\) \[CARLA\]

We useTransFuser\+\+from CARLA Garage\[[24](https://arxiv.org/html/2605.08190#bib.bib92)\]as the ML\-only baseline, representing a high\-performance learning\-based policy without formal safety guarantees\.

This baseline serves as a reference point for evaluating the safety benefits of𝒫​𝒮\\mathcal\{PS\}and𝒮​𝒮\\mathcal\{SS\}\. Because it lacks any form of fault detection or correction, its performance degradation under injected perception faults directly illustrates the vulnerability of unconstrained ML\-based autonomy\. Note that the causes of ML perception faults are out of the scope of this work, and therefore fault injection is used to measure the effect of faults that ML\-based systems are susceptible to\[[25](https://arxiv.org/html/2605.08190#bib.bib105),[55](https://arxiv.org/html/2605.08190#bib.bib103),[38](https://arxiv.org/html/2605.08190#bib.bib104),[1](https://arxiv.org/html/2605.08190#bib.bib101),[44](https://arxiv.org/html/2605.08190#bib.bib100),[41](https://arxiv.org/html/2605.08190#bib.bib106),[42](https://arxiv.org/html/2605.08190#bib.bib109),[43](https://arxiv.org/html/2605.08190#bib.bib108),[40](https://arxiv.org/html/2605.08190#bib.bib95)\]\.

##### 𝒫​𝒮\\mathcal\{PS\}\[CARLA\]

A formally verified baseline \([SectionII\-B](https://arxiv.org/html/2605.08190#S2.SS2)\) that augments the ML layer with a safety layer that overrides unsafe actions based on VOD\[[6](https://arxiv.org/html/2605.08190#bib.bib36),[5](https://arxiv.org/html/2605.08190#bib.bib10)\]\.

##### M2S\-Only𝒮​𝒮\\mathcal\{SS\}\[CARLA\]

An ablation including only the M2S link, where the safety layer selectively incorporates ML outputs according to[SectionIII\-B](https://arxiv.org/html/2605.08190#S3.SS2)\. This variant captures the core mechanism of𝒮​𝒮\\mathcal\{SS\}and is evaluated in CARLA\.

##### 𝒮​𝒮\\mathcal\{SS\}

The full architecture combines M2S and S2M links, enabling bidirectional interaction between the ML and safety layers\. Due to architectural constraints, M2S is evaluated in CARLA and S2M in a planner\-based setting\.

##### S2M\-Only𝒮​𝒮\\mathcal\{SS\}\[nuPlan\]

An ablation including only the S2M link, where the safety layer provides constraint feedback for replanning\. This variant is evaluated in nuPlan\[[11](https://arxiv.org/html/2605.08190#bib.bib98)\]\.

In summary, the primary evaluation focuses on CARLA \(ML,𝒫​𝒮\\mathcal\{PS\}, M2S\), while S2M is assessed separately in nuPlan\.

### V\-CExperiments Description

We conduct two controlled experiments in the CARLA environment \([SectionV\-A1](https://arxiv.org/html/2605.08190#S5.SS1.SSS1)\) to evaluate the safety layer and the ML\-to\-safety mechanism of𝒮​𝒮\\mathcal\{SS\}under obstacle detection faults in the ML layer\. Experiment 1 is additionally evaluated in nuPlan to assess the S2M link in a planner\-based setting\. The configurations of both experiments are illustrated in[Figure7](https://arxiv.org/html/2605.08190#S5.F7)\.

##### Experiment 1: In\-Lane Obstacle

The ego vehicle approaches a static obstacle in its lane that is missed by the ML layer\. This scenario evaluates collision avoidance via the safety layer\. In nuPlan, it additionally tests whether S2M enables timely replanning to avoid unnecessary stopping\.

##### Experiment 2: Nearby\-Lane Obstacle

An obstacle is placed in a neighboring lane closer to the ego lane and missed by the ML layer\. This scenario evaluates whether the M2S link reduces unnecessary interventions by incorporating lane context, maintaining safety while improving efficiency\.

![Refer to caption](https://arxiv.org/html/2605.08190v1/x7.png)Figure 7:Visualization of the simulation scenarios used to evaluate𝒮​𝒮\\mathcal\{SS\}\. Experiment 1 places an undetected obstacle in the ego lane to test the safety layer override behavior\. Experiment 2 places an undetected obstacle in an adjacent lane to assess whether𝒮​𝒮\\mathcal\{SS\}can avoid unnecessary braking when the obstacle is close to being safety\-critical\.Under nominal behavior, routes are completed in∼10​s\\sim 10\\,\\text\{s\}\. Episodes terminate upon full stop after emergency braking\. Each configuration is evaluated over 10 runs\. In CARLA, we evaluate three models \(ML,𝒫​𝒮\\mathcal\{PS\}, M2S\-only𝒮​𝒮\\mathcal\{SS\}\) across two experiments \(60 runs total\)\. The S2M evaluation in nuPlan is reported separately in[SectionVI\-D](https://arxiv.org/html/2605.08190#S6.SS4)\.

### V\-DFault Injection

To focus on system\-level resilience rather than the specific origins of perception faults, we inject faults directly at the decision level of the ML layer\. This procedure is applied in the CARLA\-based experiments described above and targets the evaluation of the safety layer and the M2S mechanism of𝒮​𝒮\\mathcal\{SS\}\. This approach bypasses the details of fault generation \(e\.g\.,sensor noise or adversarial perturbations\) and instead isolates how the safety architecture responds to erroneous ML layer behavior in a controlled and reproducible manner\.

Faults are induced by recording nominal ML actions in obstacle\-free runs and replaying them in scenarios with obstacles, simulating missed detections that lead to unsafe behavior\.

This injection strategy ensures that all evaluated models in the CARLA setting,i\.e\.the ML\-based agent,𝒫​𝒮\\mathcal\{PS\}, and the M2S\-only variant of𝒮​𝒮\\mathcal\{SS\}, operate under identical ML layer fault conditions, allowing us to attribute any differences in outcome solely to the architectures’ safety mechanisms rather than the stochasticity of perception\.

Expected Outcomes\.The ML\-based agent is expected to collide in*Experiment 1*and proceed normally in*Experiment 2*\. The𝒫​𝒮\\mathcal\{PS\}baseline avoids collisions but may exhibit overly conservative braking\. The M2S\-enabled variant is expected to maintain zero collisions while reducing unnecessary interventions through the use of ML\-layer context\.

### V\-EEvaluation Metrics

To assess the safety and functional performance of each architecture, we use three quantitative metrics:*Collision Rate*,*Time to Completion*, and*Route Completion Rate*\. These metrics capture complementary aspects of performance and safety\.

##### Collision Rate \(CR\)

This metric records the number of collisions that occur during a single simulation run\. For each episodeτ\\tau, we measurec​\(τ\)∈\{0,1,2,…\},c\(\\tau\)\\in\\\{0,1,2,\\dots\\\},the total number of impacts involving the ego vehicle\.

##### Time to Completion \(TC\)

For each episodeτ\\tau, we measure the time required for the ego vehicle to reach the end of the designated route without violating safety constraints\. Lett​\(τ\)∈ℝ\>0t\(\\tau\)\\in\\mathbb\{R\}\_\{\>0\}denote the elapsed simulation time until successful route completion\.

##### Route Completion Rate \(RCR\)

For each episodeτ\\tau, this metric records whether the ego vehicle reaches the goal\. If the vehicle completes the route, it is marked asτ=1\\tau=1\. Otherwise it is marked asτ=0\\tau=0\.

## VIResults

![Refer to caption](https://arxiv.org/html/2605.08190v1/x8.png)Figure 8:Example run from Exp\. 2\. The ML agent completes fastest by exceedingvmaxsafev\_\{\\text\{max\}\}^\{\\text\{safe\}\}\(without guarantees\)\.𝒫​𝒮\\mathcal\{PS\}stalls due to conservative emergency braking, while the M2S variant completes the route safely via throttle\-release mitigation\.We report CARLA\-based results focusing on the safety layer and the M2S mechanism of𝒮​𝒮\\mathcal\{SS\}, with metrics summarized in[TableI](https://arxiv.org/html/2605.08190#S6.T1)\. An auxiliary S2M evaluation in a planner\-based setting is presented in[SectionVI\-D](https://arxiv.org/html/2605.08190#S6.SS4)\. Representative CARLA and nuPlan scenarios are shown in[Figure9](https://arxiv.org/html/2605.08190#S6.F9)\.

![Refer to caption](https://arxiv.org/html/2605.08190v1/x9.png)Figure 9:Representative snapshots from CARLA \(primary evaluation\) and nuPlan \(auxiliary S2M evaluation\), illustrating realistic closed\-loop behavior in both simulation settings\.### VI\-AExperiment 1: In\-Lane Obstacle

The first experiment evaluates cases in which a faulty obstacle lies directly within the ego lane and poses an immediate collision risk\. As expected, the ML\-based agent fails in all runs: because the injected fault suppresses the in\-lane obstacle, the ML layer never initiates a replan and consequently collides\.

In contrast, all safety\-backed architectures evaluated in CARLA,i\.e\.𝒫​𝒮\\mathcal\{PS\}and the M2S𝒮​𝒮\\mathcal\{SS\}, exhibit the expected fail\-safe behavior\. When the ML layer fails to detect a safety\-critical obstacle, the safety layer triggers conservative braking, yieldingCR=0\.0\\text\{CR\}=0\.0in all runs\. However, none of these architectures completes the route \(i\.e\.RCR=0\.0\\text\{RCR\}=0\.0\), as emergency braking halts progress once the vehicle enters the braking zone\.

These results reflect a limitation of our evaluation protocol, as episodes are terminated once emergency braking brings the vehicle to a full stop, and therefore route completion is not observed even though safety is preserved\. To assess whether S2M communication can enable continued progress under such conditions, we additionally evaluate the S2M link in a planner\-based setting using nuPlan\[[11](https://arxiv.org/html/2605.08190#bib.bib98)\]\(see[SectionVI\-D](https://arxiv.org/html/2605.08190#S6.SS4)\)\. In that setting, where the planner can incorporate externally provided constraints and replan earlier, S2M enables successful route completion in a significant fraction of runs, demonstrating its potential when paired with a sufficiently responsive planner\.

![Refer to caption](https://arxiv.org/html/2605.08190v1/x10.png)Figure 10:Analysis of safety layer interventions in Exp\. 2\. The M2S\-enabled variant shifts safety responses from conservative emergency braking to throttle\-release mitigation, reducing unnecessary interventions while preserving safety\.
### VI\-BExperiment 2: Nearby\-Lane Obstacle

The second experiment places faulty obstacles in a neighboring lane rather than in the ego lane, making lane context essential for correct threat assessment\. As expected, none of the agents collide with the obstacle, since it does not pose a direct hazard \(CR=0\.0\\text\{CR\}=0\.0for all architectures\)\.

Under𝒫​𝒮\\mathcal\{PS\}, the safety layer lacks lane context and therefore treats some of these non\-threatening obstacles as safety\-critical due to their proximity\. This conservativeness triggers unnecessary braking and premature route termination, resulting in low route\-completion rates\. In contrast, the M2S\-enabled variant of𝒮​𝒮\\mathcal\{SS\}leverages ML\-layer lane detections to classify these obstacles as less critical \(Zone 2 in[Figure5](https://arxiv.org/html/2605.08190#S4.F5)\), invoking throttle\-release mitigation rather than emergency braking\. Consequently, it achieves substantially higher route\-completion rates than𝒫​𝒮\\mathcal\{PS\}, braking only in rare cases where lane detection indicates that the obstacle slightly encroaches on the ego lane\.

Although the time to completion \(TC\) of the M2S\-enabled variant is higher than that of the unconstrained ML policy, this increase reflects the deliberate use of mitigative actions under formal safety guarantees, as throttle release inevitably slows progress\. Crucially, the M2S\-enabled design reduces excessive conservativeness while preserving the same safety guarantees as𝒫​𝒮\\mathcal\{PS\}\. An illustrative route demonstrating these behavioral differences appears in[Figure8](https://arxiv.org/html/2605.08190#S6.F8)\.

### VI\-CAnalysis of Safety Layer Interventions

To further characterize system behavior,[Figure10](https://arxiv.org/html/2605.08190#S6.F10)reports the distribution of safety layer intervention levels across all routes in Exp\. 2, where the impact of the M2S mechanism is most pronounced\. As expected, M2S\-enabled𝒮​𝒮\\mathcal\{SS\}significantly reduces the number of emergency\-braking events relative to𝒫​𝒮\\mathcal\{PS\}, replacing them with less conservative throttle\-release actions\. This shift reflects the safety layer’s ability to correctly identify faulty obstacles as lying outside the ego lane, enabled by the admissible use of ML\-layer lane information\.

TABLE I:Collision rate \(CR\), time to completion \(TC\), and route completion rate \(RCR\)\. TC is reported only for runs that finish the full route successfully\.
### VI\-DS2M in NuPlan

To evaluate the S2M link in a setting where planner\-level constraint injection is supported, we conduct an auxiliary study in the nuPlan simulation environment\[[11](https://arxiv.org/html/2605.08190#bib.bib98)\]\. Using the same obstacle\-existence fault model as in Experiment 1, the underlying nuPlan policy occasionally initiates a lane change sufficiently early,i\.e\.before entering the safety layer’s braking zone\. In such cases, the S2M link provides safety\-verified constraints in time for the planner to adjust its trajectory without triggering an emergency stop, resulting inRCR=74%\\text\{RCR\}=74\\%\(29/39\)\. This contrasts with the CARLA\-based Experiment 1, where all runs terminate early due to late or absent replanning\.

This result indicates that S2M effectiveness depends on planner responsiveness and can improve task completion while preserving safety when timely replanning is available\.

## VIIConclusion

This paper introduced Synergistic Simplex \(𝒮​𝒮\\mathcal\{SS\}\), a generalization of the Simplex paradigm that enables bidirectional interaction between ML and safety layers\. Unlike𝒫​𝒮\\mathcal\{PS\}, which relies on unilateral overrides,𝒮​𝒮\\mathcal\{SS\}incorporates ML\-to\-safety and safety\-to\-ML communication to preserve deterministic safety guarantees while reducing conservativeness\. Our analysis and experiments show that𝒮​𝒮\\mathcal\{SS\}retains the safety properties of𝒫​𝒮\\mathcal\{PS\}whileimproving performancethrough coordinated use of ML outputs and safety feedback\. These results demonstrate that high performance and strong safety guarantees need not be competing objectives:𝒮​𝒮\\mathcal\{SS\}provides a principled foundation for incorporating formally unverified information into safety\-critical systems under rigorously defined structural conditions, challenging the traditional strict separation between mission and safety layers without weakening formal guarantees\.

## References

- \[1\]\(2024\)The road to safety: a review of uncertainty and applications to autonomous driving perception\.Entropy26\(8\),pp\. 634\.Cited by:[§I](https://arxiv.org/html/2605.08190#S1.p2.1),[§V\-B](https://arxiv.org/html/2605.08190#S5.SS2.SSS0.Px1.p2.2)\.
- \[2\]B\. Araújo, J\. F\. Teixeira, J\. Fonseca, R\. Cerqueira, and S\. C\. Beco\(2024\)The road to safety: a review of uncertainty and applications to autonomous driving perception\.Entropy26\(8\)\.External Links:[Link](https://www.mdpi.com/1099-4300/26/8/634),ISSN 1099\-4300,[Document](https://dx.doi.org/10.3390/e26080634)Cited by:[§II\-C](https://arxiv.org/html/2605.08190#S2.SS3.p3.1)\.
- \[3\]A\. Avizienis, J\.\-C\. Laprie, B\. Randell, and C\. Landwehr\(2004\)Basic concepts and taxonomy of dependable and secure computing\.IEEE Transactions on Dependable and Secure Computing1\(1\),pp\. 11–33\.External Links:[Document](https://dx.doi.org/10.1109/TDSC.2004.2)Cited by:[Definition 1](https://arxiv.org/html/2605.08190#Thmdefinition1.p1.1.1)\.
- \[4\]S\. Bak, D\. K\. Chivukula, O\. Adekunle, M\. Sun, M\. Caccamo, and L\. Sha\(2009\)The system\-level simplex architecture for improved real\-time embedded system safety\.In15th IEEE Real\-Time and Embedded Technology and Applications Symposium,San Francisco, USA,pp\. 99–107\.Cited by:[Figure 1](https://arxiv.org/html/2605.08190#S1.F1),[§I](https://arxiv.org/html/2605.08190#S1.p3.1),[§II\-A](https://arxiv.org/html/2605.08190#S2.SS1.p2.1)\.
- \[5\]A\. Bansal, H\. Kim, S\. Yu, B\. Li, N\. Hovakimyan, M\. Caccamo, and L\. Sha\(2022\)Verifiable obstacle detection\.In2022 IEEE 33rd International Symposium on Software Reliability Engineering \(ISSRE\),pp\. 61–72\.Cited by:[§I](https://arxiv.org/html/2605.08190#S1.p4.3),[Figure 2](https://arxiv.org/html/2605.08190#S2.F2),[§II\-B](https://arxiv.org/html/2605.08190#S2.SS2.p1.6),[Figure 4](https://arxiv.org/html/2605.08190#S4.F4),[§IV\-B](https://arxiv.org/html/2605.08190#S4.SS2.p3.3),[§V\-B](https://arxiv.org/html/2605.08190#S5.SS2.SSS0.Px2.p1.1)\.
- \[6\]A\. Bansal, H\. Kim, S\. Yu, B\. Li, N\. Hovakimyan, M\. Caccamo, and L\. Sha\(2024\)Perception simplex: verifiable collision avoidance in autonomous vehicles amidst obstacle detection faults\.Software Testing, Verification and Reliability,pp\. e1879\.External Links:[Document](https://dx.doi.org/10.1002/stvr.1879),[Link](https://doi.org/10.1002/stvr.1879),https://doi\.org/10\.1002/stvr\.1879Cited by:[Figure 1](https://arxiv.org/html/2605.08190#S1.F1),[§I](https://arxiv.org/html/2605.08190#S1.p4.3),[§II\-A](https://arxiv.org/html/2605.08190#S2.SS1.p3.1),[§II\-B](https://arxiv.org/html/2605.08190#S2.SS2.p1.6),[§III\-B1](https://arxiv.org/html/2605.08190#S3.SS2.SSS1.p2.7),[§III\-B1](https://arxiv.org/html/2605.08190#S3.SS2.SSS1.p3.2),[§III](https://arxiv.org/html/2605.08190#S3.p2.5),[Figure 4](https://arxiv.org/html/2605.08190#S4.F4),[§IV\-B](https://arxiv.org/html/2605.08190#S4.SS2.p1.6),[§IV\-B](https://arxiv.org/html/2605.08190#S4.SS2.p3.3),[§V\-B](https://arxiv.org/html/2605.08190#S5.SS2.SSS0.Px2.p1.1)\.
- \[7\]M\. Blanke, M\. Kinnaert, J\. Lunze, M\. Staroswiecki, and J\. Schröder\(2006\)Diagnosis and fault\-tolerant control\.Vol\.2,Springer\.Cited by:[§II\-A](https://arxiv.org/html/2605.08190#S2.SS1.p1.1)\.
- \[8\]I\. Bogoslavskyi and C\. Stachniss\(2016\)Fast range image\-based segmentation of sparse 3d laser scans for online operation\.In2016 IEEE/RSJ International Conference on Intelligent Robots and Systems \(IROS\),pp\. 163–169\.Cited by:[§II\-B](https://arxiv.org/html/2605.08190#S2.SS2.p1.6)\.
- \[9\]I\. Bogoslavskyi and C\. Stachniss\(2017\)Efficient online segmentation for sparse 3d laser scans\.PFG–Journal of Photogrammetry, Remote Sensing and Geoinformation Science85\(1\),pp\. 41–52\.Cited by:[§II\-B](https://arxiv.org/html/2605.08190#S2.SS2.p1.6)\.
- \[10\]H\. B\. Braiek and F\. Khomh\(2025\)Machine learning robustness: a primer\.InTrustworthy AI in Medical Imaging,pp\. 37–71\.Cited by:[§I](https://arxiv.org/html/2605.08190#S1.p2.1)\.
- \[11\]H\. Caesar, J\. Kabzan, K\. S\. Tan, W\. K\. Fong, E\. Wolff, A\. Lang, L\. Fletcher, O\. Beijbom, and S\. Omari\(2021\)NuPlan: a closed\-loop ml\-based planning benchmark for autonomous vehicles\.InCVPR ADP3 workshop,Cited by:[§IV\-C](https://arxiv.org/html/2605.08190#S4.SS3.p3.1),[§V\-A2](https://arxiv.org/html/2605.08190#S5.SS1.SSS2.p1.1),[§V\-B](https://arxiv.org/html/2605.08190#S5.SS2.SSS0.Px5.p1.1),[§V](https://arxiv.org/html/2605.08190#S5.p1.1),[§V](https://arxiv.org/html/2605.08190#S5.p2.1),[§VI\-A](https://arxiv.org/html/2605.08190#S6.SS1.p3.1),[§VI\-D](https://arxiv.org/html/2605.08190#S6.SS4.p1.1)\.
- \[12\]J\. Chen, S\. Yu, R\. Tabish, A\. Bansal, S\. Liu, T\. Abdelzaher, and L\. Sha\(2021\)Lidar cluster first and camera inference later: a new perspective towards autonomous driving\.arXiv preprint arXiv:2111\.09799\.Cited by:[§II\-C](https://arxiv.org/html/2605.08190#S2.SS3.p2.1)\.
- \[13\]T\. L\. Crenshaw, E\. L\. Gunter, C\. L\. Robinson, L\. Sha, and P\. R\. Kumar\(2007\)The simplex reference model: limiting fault\-propagation due to unreliable components in cyber\-physical system architectures\.InProceedings of the 28th IEEE Real\-Time Systems Symposium \(RTSS 2007\), 3\-6 December 2007, Tucson, Arizona, USA,pp\. 400–412\.External Links:[Document](https://dx.doi.org/10.1109/RTSS.2007.34),[Link](https://doi.org/10.1109/RTSS.2007.34)Cited by:[Figure 1](https://arxiv.org/html/2605.08190#S1.F1),[§I](https://arxiv.org/html/2605.08190#S1.p3.1),[§II\-A](https://arxiv.org/html/2605.08190#S2.SS1.p2.1)\.
- \[14\]A\. Desai, S\. Ghosh, S\. A\. Seshia, N\. Shankar, and A\. Tiwari\(2019\)SOTER: a runtime assurance framework for programming safe robotics systems\.In2019 49th Annual IEEE/IFIP International Conference on Dependable Systems and Networks \(DSN\),pp\. 138–150\.Cited by:[§I](https://arxiv.org/html/2605.08190#S1.p3.1)\.
- \[15\]\(2011\)DO\-178C: Software Considerations in Airborne Systems and Equipment Certification\.StandardTechnical ReportRTCA/DO\-178C,RTCA, Inc\.,Washington, D\.C\.\.Cited by:[§I](https://arxiv.org/html/2605.08190#S1.p6.2)\.
- \[16\]A\. Dosovitskiy, G\. Ros, F\. Codevilla, A\. Lopez, and V\. Koltun\(2017\)CARLA: An open urban driving simulator\.InProceedings of the 1st Annual Conference on Robot Learning,pp\. 1–16\.Cited by:[§V\-A1](https://arxiv.org/html/2605.08190#S5.SS1.SSS1.p1.1)\.
- \[17\]J\. G\. Fuller\(2020\)Run\-time assurance: a rising technology\.In2020 AIAA/IEEE 39th Digital Avionics Systems Conference \(DASC\),pp\. 1–9\.Cited by:[Figure 1](https://arxiv.org/html/2605.08190#S1.F1),[§I](https://arxiv.org/html/2605.08190#S1.p3.1)\.
- \[18\]A\. E\. Goodloe\(2022\)Assuring safety\-critical machine learning enabled systems: challenges and promise\.In2022 IEEE International Symposium on Software Reliability Engineering Workshops \(ISSREW\),pp\. 326–332\.Cited by:[§I](https://arxiv.org/html/2605.08190#S1.p2.1)\.
- \[19\]Y\. Hu, S\. Liu, T\. Abdelzaher, M\. Wigness, and P\. David\(2021\)On exploring image resizing for optimizing criticality\-based machine perception\.In2021 IEEE 27th International Conference on Embedded and Real\-Time Computing Systems and Applications \(RTCSA\),pp\. 169–178\.Cited by:[§II\-C](https://arxiv.org/html/2605.08190#S2.SS3.p2.1)\.
- \[20\]Y\. Hu, S\. Liu, T\. Abdelzaher, M\. Wigness, and P\. David\(2022\)Real\-time task scheduling with image resizing for criticality\-based machine perception\.Real\-Time Systems,pp\. 1–26\.Cited by:[§II\-C](https://arxiv.org/html/2605.08190#S2.SS3.p2.1)\.
- \[21\]X\. Huang, M\. Kwiatkowska, S\. Wang, and M\. Wu\(2017\)Safety verification of deep neural networks\.InInternational conference on computer aided verification,pp\. 3–29\.Cited by:[§II\-C](https://arxiv.org/html/2605.08190#S2.SS3.p4.1)\.
- \[22\]K\. Ishii, A\. Noguchi, and Y\. Gotoh\(1986\-April 15\)Fault tolerable redundancy control\.Google Patents\.Note:US Patent 4,583,224Cited by:[§II\-A](https://arxiv.org/html/2605.08190#S2.SS1.p1.1)\.
- \[23\]ISO/TC 22/SC 32\(2018\)Road vehicles – Functional safety\.StandardTechnical ReportISO 26262:2018,International Organization for Standardization,Geneva, Switzerland\.Cited by:[§I](https://arxiv.org/html/2605.08190#S1.p6.2)\.
- \[24\]B\. Jaeger, K\. Chitta, and A\. Geiger\(2023\)Hidden biases of end\-to\-end driving models\.InProc\. of the IEEE International Conf\. on Computer Vision \(ICCV\),Cited by:[§IV\-A](https://arxiv.org/html/2605.08190#S4.SS1.p1.4),[§IV\-D](https://arxiv.org/html/2605.08190#S4.SS4.p2.2),[§V\-A1](https://arxiv.org/html/2605.08190#S5.SS1.SSS1.p1.1),[§V\-B](https://arxiv.org/html/2605.08190#S5.SS2.SSS0.Px1.p1.1)\.
- \[25\]E\. Jenn, A\. Albore, F\. Mamalet, G\. Flandin, C\. Gabreau, H\. Delseny, A\. Gauffriau, H\. Bonnin, L\. Alecu, J\. Pirard,et al\.\(2020\)Identifying challenges to the certification of machine learning for safety critical systems\.InEuropean congress on embedded real time systems \(ERTS 2020\),Vol\.1\.Cited by:[§I](https://arxiv.org/html/2605.08190#S1.p2.1),[§V\-B](https://arxiv.org/html/2605.08190#S5.SS2.SSS0.Px1.p2.2)\.
- \[26\]S\. Jha, S\. Banerjee, T\. Tsai, S\. K\. Hari, M\. B\. Sullivan, Z\. T\. Kalbarczyk, S\. W\. Keckler, and R\. K\. Iyer\(2019\)ML\-based fault injection for autonomous vehicles: a case for bayesian fault injection\.In2019 49th Annual IEEE/IFIP International Conference on Dependable Systems and Networks \(DSN\),pp\. 112–124\.Cited by:[§II\-A](https://arxiv.org/html/2605.08190#S2.SS1.p1.1)\.
- \[27\]W\. Kang, S\. Chung, J\. Y\. Kim, Y\. Lee, K\. Lee, J\. Lee, K\. G\. Shin, and H\. S\. Chwa\(2022\)DNN\-sam: split\-and\-merge dnn execution for real\-time object detection\.In2022 IEEE 28th Real\-Time and Embedded Technology and Applications Symposium \(RTAS\),pp\. 160–172\.Cited by:[§II\-C](https://arxiv.org/html/2605.08190#S2.SS3.p2.1)\.
- \[28\]G\. Katz, C\. Barrett, D\. L\. Dill, K\. Julian, and M\. J\. Kochenderfer\(2017\)Reluplex: an efficient smt solver for verifying deep neural networks\.InInternational conference on computer aided verification,pp\. 97–117\.Cited by:[§II\-C](https://arxiv.org/html/2605.08190#S2.SS3.p4.1)\.
- \[29\]A\. Kendall and Y\. Gal\(2017\)What uncertainties do we need in bayesian deep learning for computer vision?\.InAdvances in Neural Information Processing Systems,I\. Guyon, U\. V\. Luxburg, S\. Bengio, H\. Wallach, R\. Fergus, S\. Vishwanathan, and R\. Garnett \(Eds\.\),Vol\.30,pp\.\.External Links:[Link](https://proceedings.neurips.cc/paper_files/paper/2017/file/2650d6089a6d640c5e85b2b88265dc2b-Paper.pdf)Cited by:[§II\-C](https://arxiv.org/html/2605.08190#S2.SS3.p3.1)\.
- \[30\]B\. Lakshminarayanan, A\. Pritzel, and C\. Blundell\(2017\)Simple and scalable predictive uncertainty estimation using deep ensembles\.InAdvances in Neural Information Processing Systems,I\. Guyon, U\. V\. Luxburg, S\. Bengio, H\. Wallach, R\. Fergus, S\. Vishwanathan, and R\. Garnett \(Eds\.\),Vol\.30,pp\.\.External Links:[Link](https://proceedings.neurips.cc/paper_files/paper/2017/file/9ef2ed4b7fd2c810847ffa5fa85bce38-Paper.pdf)Cited by:[§II\-C](https://arxiv.org/html/2605.08190#S2.SS3.p3.1)\.
- \[31\]J\. H\. Lala and R\. E\. Harper\(1994\)Architectural principles for safety\-critical real\-time applications\.Proceedings of the IEEE82\(1\),pp\. 25–40\.Cited by:[§II\-A](https://arxiv.org/html/2605.08190#S2.SS1.p1.1)\.
- \[32\]S\. Liu, X\. Fu, M\. Wigness, P\. David, S\. Yao, L\. Sha, and T\. Abdelzaher\(2022\)Self\-cueing real\-time attention scheduling in criticality\-aware visual machine perception\.In2022 IEEE 28th Real\-Time and Embedded Technology and Applications Symposium \(RTAS\),pp\. 173–186\.Cited by:[§II\-C](https://arxiv.org/html/2605.08190#S2.SS3.p2.1)\.
- \[33\]S\. Liu, S\. Yao, X\. Fu, H\. Shao, R\. Tabish, S\. Yu, A\. Bansal, H\. Yun, L\. Sha, and T\. Abdelzaher\(2021\)Real\-time task scheduling for machine perception in intelligent cyber\-physical systems\.IEEE Transactions on Computers71\(8\),pp\. 1770–1783\.Cited by:[§II\-C](https://arxiv.org/html/2605.08190#S2.SS3.p2.1)\.
- \[34\]S\. Liu, S\. Yao, X\. Fu, R\. Tabish, S\. Yu, A\. Bansal, H\. Yun, L\. Sha, and T\. Abdelzaher\(2020\)On removing algorithmic priority inversion from mission\-critical machine inference pipelines\.In2020 IEEE Real\-Time Systems Symposium \(RTSS\),pp\. 319–332\.Cited by:[§II\-C](https://arxiv.org/html/2605.08190#S2.SS3.p2.1)\.
- \[35\]I\. Malleswaran and S\. Dinakaran\(2023\)Challenges in specifying safety\-critical systems with ai\-components\.External Links:[Link](https://odr.chalmers.se/items/d130c7f0-55a1-454c-acbc-1caf59a8e0e1)Cited by:[§I](https://arxiv.org/html/2605.08190#S1.p2.1)\.
- \[36\]Y\. Mao, Y\. Gu, N\. Hovakimyan, L\. Sha, and P\. Voulgaris\(2023\)SL1\-simplex: safe velocity regulation of self\-driving vehicles in dynamic and unforeseen environments\.ACM Transactions on Cyber\-Physical Systems7\(1\),pp\. 1–24\.Cited by:[§II\-A](https://arxiv.org/html/2605.08190#S2.SS1.p3.1)\.
- \[37\]U\. Mehmood, S\. Sheikhi, S\. Bak, S\. A\. Smolka, and S\. D\. Stoller\(2022\)The black\-box simplex architecture for runtime assurance of autonomous cps\.InNASA formal methods symposium,pp\. 231–250\.Cited by:[§I](https://arxiv.org/html/2605.08190#S1.p3.1)\.
- \[38\]S\. Mohseni, H\. Wang, C\. Xiao, Z\. Yu, Z\. Wang, and J\. Yadawa\(2022\)Taxonomy of machine learning safety: a survey and primer\.ACM Computing Surveys55\(8\),pp\. 1–38\.Cited by:[§I](https://arxiv.org/html/2605.08190#S1.p2.1),[§V\-B](https://arxiv.org/html/2605.08190#S5.SS2.SSS0.Px1.p2.2)\.
- \[39\]P\. Musau, N\. Hamilton, D\. M\. Lopez, P\. Robinette, and T\. T\. Johnson\(2022\)On using real\-time reachability for the safety assurance of machine learning controllers\.In2022 IEEE International Conference on Assured Autonomy \(ICAA\),pp\. 1–10\.Cited by:[§II\-A](https://arxiv.org/html/2605.08190#S2.SS1.p3.1)\.
- \[40\]National Highway Traffic Safety Administration \(NHTSA\)\(2021–Present\)Standing General Order on Crash Reporting for Automated Driving Systems and Level 2 Advanced Driver Assistance Systems\.Note:[https://www\.nhtsa\.gov/laws\-regulations/standing\-general\-order\-crash\-reporting](https://www.nhtsa.gov/laws-regulations/standing-general-order-crash-reporting)Regularly updated reports tracking incidents involving Automated Driving SystemsCited by:[§I](https://arxiv.org/html/2605.08190#S1.p2.1),[§V\-B](https://arxiv.org/html/2605.08190#S5.SS2.SSS0.Px1.p2.2)\.
- \[41\]National Transportation Safety Board\(2017\-09\)Collision Between a Car Operating With Automated Vehicle Control Systems and a Tractor\-Semitrailer Truck Near Williston, Florida, May 7, 2016\.Note:Accident Report NTSB/HAR\-17/02 PB2017\-102600External Links:[Link](https://www.ntsb.gov/investigations/accidentreports/reports/har1702.pdf)Cited by:[§I](https://arxiv.org/html/2605.08190#S1.p2.1),[§V\-B](https://arxiv.org/html/2605.08190#S5.SS2.SSS0.Px1.p2.2)\.
- \[42\]National Transportation Safety Board\(2019\)Collision Between Vehicle Controlled by Developmental Automated Driving System and Pedestrian Tempe, Arizona, March 18, 2018\.Note:Accident Report NTSB/HAR\-19/03 PB2019\-101402External Links:[Link](https://www.ntsb.gov/investigations/AccidentReports/Reports/HAR1903.pdf)Cited by:[§I](https://arxiv.org/html/2605.08190#S1.p2.1),[§V\-B](https://arxiv.org/html/2605.08190#S5.SS2.SSS0.Px1.p2.2)\.
- \[43\]National Transportation Safety Board\(2019\-03\)Highway accident brief HWY19FH008\.Note:Highway Accident Brief, Accident Number: HWY19FH008External Links:[Link](https://www.ntsb.gov/investigations/AccidentReports/Reports/HAB2001.pdf)Cited by:[§I](https://arxiv.org/html/2605.08190#S1.p2.1),[§V\-B](https://arxiv.org/html/2605.08190#S5.SS2.SSS0.Px1.p2.2)\.
- \[44\]C\. Paterson, R\. Hawkins, C\. Picardi, Y\. Jia, R\. Calinescu, and I\. Habli\(2025\)Safety assurance of machine learning for autonomous systems\.Reliability Engineering & System Safety,pp\. 111311\.Cited by:[§I](https://arxiv.org/html/2605.08190#S1.p2.1),[§V\-B](https://arxiv.org/html/2605.08190#S5.SS2.SSS0.Px1.p2.2)\.
- \[45\]A\. Pereira and C\. Thomas\(2020\)Challenges of machine learning applied to safety\-critical cyber\-physical systems\.Machine Learning and Knowledge Extraction2\(4\),pp\. 579–602\.Cited by:[§I](https://arxiv.org/html/2605.08190#S1.p2.1)\.
- \[46\]D\. T\. Phan, R\. Grosu, N\. Jansen, N\. Paoletti, S\. A\. Smolka, and S\. D\. Stoller\(2020\)Neural simplex architecture\.InNASA Formal Methods Symposium,pp\. 97–114\.Cited by:[§I](https://arxiv.org/html/2605.08190#S1.p3.1),[§II\-A](https://arxiv.org/html/2605.08190#S2.SS1.p3.1)\.
- \[47\]D\. Phan, J\. Yang, M\. Clark, R\. Grosu, J\. Schierman, S\. Smolka, and S\. Stoller\(2017\)A component\-based simplex architecture for high\-assurance cyber\-physical systems\.In2017 17th International Conference on Application of Concurrency to System Design \(ACSD\),pp\. 49–58\.Cited by:[§I](https://arxiv.org/html/2605.08190#S1.p3.1)\.
- \[48\]L\. Sha, R\. Rajkumar, and \\\. Lehoczky\(1990\-09\)Priority inheritance protocols: an approach to real\-time synchronization\.IEEE Transactions on Computers39\(9\),pp\. 1175–1185\(English \(US\)\)\.External Links:[Document](https://dx.doi.org/10.1109/12.57058),ISSN 0018\-9340Cited by:[§II\-C](https://arxiv.org/html/2605.08190#S2.SS3.p2.1)\.
- \[49\]L\. Sha\(2001\)Using simplicity to control complexity\.IEEE Software18\(4\),pp\. 20–28\.Cited by:[Figure 1](https://arxiv.org/html/2605.08190#S1.F1),[§I](https://arxiv.org/html/2605.08190#S1.p3.1),[§II\-A](https://arxiv.org/html/2605.08190#S2.SS1.p2.1)\.
- \[50\]J\. Su, D\. V\. Vargas, and K\. Sakurai\(2019\)One pixel attack for fooling deep neural networks\.IEEE Transactions on Evolutionary Computation23\(5\),pp\. 828–841\.Cited by:[§I](https://arxiv.org/html/2605.08190#S1.p2.1)\.
- \[51\]C\. Tung, A\. Goel, X\. Hu, N\. Eliopoulos, E\. S\. Amobi, G\. K\. Thiruvathukal, V\. Chaudhary, and Y\. Lu\(2022\)Irrelevant pixels are everywhere: find and exclude them for more efficient computer vision\.In2022 IEEE 4th International Conference on Artificial Intelligence Circuits and Systems \(AICAS\),pp\. 340–343\.Cited by:[§II\-C](https://arxiv.org/html/2605.08190#S2.SS3.p2.1)\.
- \[52\]X\. Wang, N\. Hovakimyan, and L\. Sha\(2018\)RSimplex: a robust control architecture for cyber and physical failures\.ACM Transactions on Cyber\-Physical Systems2\(4\),pp\. 1–26\.Cited by:[§II\-A](https://arxiv.org/html/2605.08190#S2.SS1.p3.1)\.
- \[53\]J\. Wei, J\. M\. Snider, J\. Kim, J\. M\. Dolan, R\. Rajkumar, and B\. Litkouhi\(2013\-06\)Towards a viable autonomous driving research platform\.In2013 IEEE Intelligent Vehicles Symposium \(IV\),Vol\.,pp\. 763–770\.External Links:[Document](https://dx.doi.org/10.1109/IVS.2013.6629559),ISSN 1931\-0587Cited by:[§II\-A](https://arxiv.org/html/2605.08190#S2.SS1.p1.1)\.
- \[54\]N\. Wiersma and R\. Pareja\(2017\)Safety\!= security: on the resilience of asil\-d certified microcontrollers against fault injection attacks\.In2017 Workshop on Fault Diagnosis and Tolerance in Cryptography \(FDTC\),pp\. 9–16\.Cited by:[§II\-A](https://arxiv.org/html/2605.08190#S2.SS1.p1.1)\.
- \[55\]Z\. Xu and J\. H\. Saleh\(2021\)Machine learning for reliability engineering and safety applications: review of current status and future opportunities\.Reliability Engineering & System Safety211,pp\. 107530\.Cited by:[§I](https://arxiv.org/html/2605.08190#S1.p2.1),[§V\-B](https://arxiv.org/html/2605.08190#S5.SS2.SSS0.Px1.p2.2)\.
- \[56\]Y\. Zhang, B\. Kang, B\. Hooi, S\. Yan, and J\. Feng\(2023\)Deep long\-tailed learning: a survey\.IEEE transactions on pattern analysis and machine intelligence45\(9\),pp\. 10795–10816\.Cited by:[§I](https://arxiv.org/html/2605.08190#S1.p2.1)\.

Similar Articles

Managed Autonomy at Runtime: Gear-Based Safety and Governance for Single- and Multi-Agent Cyber-Physical Systems

arXiv cs.AI

This paper presents EntropyRuntime, a discrete-time control system for single and multi-agent LLM-driven and robotic agents that uses five execution gears with utility-gated dispatch and event-driven fallback to ensure safety, stability, and continuity. It provides formal proofs and evaluates on a three-agent UR5 robotic assembly cell, achieving 99.6% anomaly detection rate.

Safe Online Learning via Smooth Safety-Structured Policy Composition

arXiv cs.LG

This paper proposes AutoSafe, a safety-aware policy architecture for safe online reinforcement learning that integrates structured safety monitoring and intervention directly into action generation, enabling smooth, risk-dependent transitions between performance and safety behaviors, demonstrated on benchmarks and a physical cart-pole system.