Preprint

Trust-aware planning linked to lower simulated robot-routing backlog

Preprint simulations found the fused monitor had the lowest routing cost and fewest active adversaries, while results depended on planning horizon and cooperative capacity.

Trust-aware planning was associated with a smaller backlog of outstanding requests in simulated robot-routing attacks using false locations, but the results depended on planning horizon and cooperative capacity, an arXiv preprint reports. The system combined two clues: whether a robot's reported position appeared trustworthy and whether it carried out assigned tasks. In the tested configurations, that fused monitor produced the lowest routing cost and the fewest adversarial agents still active. The wider system worked as a loop, assessing information, building a trust-aware planning state, selecting actions and then executing them.

The attack used distance limits

The simulated adversaries did not rely on unrestricted location errors. The paper introduced a distance-constrained spoofing model and a tiered bipartite matching strategy, a structured way to pair targets and attackers. The rules were designed to balance how much an attack could influence assignments against the size of the spoofed movement. The monitor also treated failure to service assigned requests as behavioral evidence, giving it a second signal beyond location data.

That design exposed a trade-off. At smaller spoofing distances, routing degradation persisted while localization evidence became harder to distinguish from nominal operation. In the tested scenarios, the attack therefore remained disruptive even as location evidence became less useful on its own.

Two kinds of evidence worked together

The localization-trust model was built in two stages from real GPS-spoofing data. The calibration used approximately 158,000 observations from an aerial-vehicle dataset, along with about 62,000 nominal and 6,900 adversarial observations from a ground-vehicle dataset. These were calibration observations, separate from the 100 demand realizations used in each routing experiment.

Behavior supplied a different check. The monitor combined calibrated localization trust with task-execution evidence to classify agents and remove detected adversaries from later planning. When the evidence sources were examined separately, localization identified some adversaries earlier, while behavioral evidence became more informative when spoofed positions were less distinguishable from normal ones. The fused monitor had the lowest routing cost and fewest active adversaries in the evaluated configurations.

The planner still needed room to recover

The routing experiment used a San Francisco graph with 1,026 intersections and 2,300 directed road segments. Time advanced in one-minute steps, and each experiment used 100 independently sampled demand realizations. The rollout planner used IA-RA as its base routing policy and compared candidate current actions by looking ahead over sampled future demand, holding the same scenarios fixed for each comparison.

Without monitoring, attack configurations showed sustained policy-cost growth. The paper also reports instability in an IA-RA test with a single adversarial agent.

With monitoring, active-adversary counts declined as evidence accumulated. Reported backlog levels were lower after removal, cancellations could stabilize, and trust-aware rollout eventually became comparable to monitored IA-RA. The results also varied with planning horizon: longer-horizon configurations showed less persistent backlog and cancellations.

In a higher-capacity experiment with 49 cooperative agents, one adversarial agent and a 30-step rollout horizon, trust-aware rollout had lower routing cost, outstanding requests and cancellations than monitored IA-RA. The main rollout used a 10-step horizon with 100 scenarios; additional evaluations used 20 steps with 200 scenarios and 30 steps with 300 scenarios.

The result has clear boundaries

Those findings are empirical, not a general guarantee. The authors do not provide analytical guarantees for detection time, closed-loop stability, meaning whether the repeated planning-and-execution cycle stays stable, or rollout improvement when the planning model and the executing fleet do not match.

The paper is an arXiv preprint, version 1, dated 26 August 2026. It reports partial support from AFOSR award #FA9550-22-1-0223 and DARPA YFA award #D24AP00319-00.

Paper data and sources

Original title: Trust-Aware Sequential Decision Making and Rollout Planning for Resilient Multi-Robot Systems
Authors: Roee M. Francos, Daniel Garces, Orhan Eren Akgün et al.
Journal/Repository: arXiv
Status: Preprint, not yet peer-reviewed
First online: 2026-08-26
DOI: Not available
Original paper · Full text

Versions and corrections

  1. Published automatically after legal-source, freshness, evidence, and independent-verification gates passed.