arXiv AI

Large Language Models in the Loop: A Stability- and Network-Aware Survey in Networked Control, Cyber-Physical, and Multi-Agent Systems

The article surveys how large language models (LLMs) can be incorporated into networked control systems, cyber‑physical systems, and multi‑agent networks without violating stability and safety guarantees. It proposes treating the LLM as a slow supervisor that sets high‑level goals, while a fast, certified inner loop preserves physical stability. The survey maps LLM characteristics—such as inference latency, API failures, tokenization, and hallucinations—to classical control challenges and highlights the growing gap between model capability and formal safety assurances, calling for future research on stability proofs.

arXiv AI
Aug 28

Safety Does Not Compose: Non-Decaying Loop State for Autonomous LLM Agents

The paper demonstrates that safety mechanisms for autonomous large language model agents fail to compose across iterative loops, as trajectory‑scoped monitors cannot detect attacks whose evidence is spread over multiple iterations. It introduces LoopHarness, a system that maintains a persistent, non‑decaying safety state across loops, bounding unauthorized actions with a constant that does not grow with the number of iterations. The authors provide a comprehensive evaluation protocol, including attacks that require cross‑iteration evidence, module ablations, and adaptive white‑box red‑team testing.

By Chenhao Wu, Haoxuan Jia, Yang Liu, Yingguang Yang, Yuhan Lin, Chongyang Zhang, Hao Zheng, Yulin Huang, Jianshen Zhang, Yongzhi Qi, Shang Luo, Kefu Xu, Jifeng Zhu, Bin Chong
arXiv AI
Sep 17

Autonomy in Check: Governor-Mediated Adaptive Security at the Edge

The paper proposes a split‑control architecture for adaptive security at the network edge, where an untrusted planner emits typed security intents that are vetted by a deterministic governor before being enacted. The governor checks each intent against safety, resource, temporal‑stability, and proportionality invariants, issuing signed receipts for admitted actions that are compiled into eBPF map updates. Experiments on a Raspberry Pi 5 connected to a university 5G test network show the governor can admit, reject, and bound intents at microsecond cost without disrupting protected‑flow regularity.

By Ijaz Ahmad, Ijaz Ahmad, Flavio Esposito, Erkki Harjula