{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,24]],"date-time":"2026-01-24T19:48:10Z","timestamp":1769284090425,"version":"3.49.0"},"reference-count":52,"publisher":"MDPI AG","issue":"1","license":[{"start":{"date-parts":[[2026,1,21]],"date-time":"2026-01-21T00:00:00Z","timestamp":1768953600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100000780","name":"European Union","doi-asserted-by":"publisher","award":["ECS00000041-VITALITY---CUP E13C22001060006"],"award-info":[{"award-number":["ECS00000041-VITALITY---CUP E13C22001060006"]}],"id":[{"id":"10.13039\/501100000780","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>Autonomous UAV\/UGV swarms increasingly operate in contested environments where purely digital control architectures are vulnerable to cyber compromise, communication denial, and timing faults. This paper presents Guarded Swarms, a hybrid framework that combines digital coordination with hardware-level analog safety enforcement. The architecture builds on Topic-Based Communication Space Petri Nets (TB-CSPN) for structured multi-agent coordination, extending this digital foundation with independent analog guard channels\u2014thrust clamps, attitude limiters, proximity sensors, and emergency stops\u2014that operate in parallel at the actuator interface. Each channel can unilaterally veto unsafe commands within microseconds, independently of software state. The digital\u2013analog interface is formalized via timing contracts that specify sensor-consistency windows and actuation latency bounds. A two-robot case study demonstrates token-based arbitration at the digital level and OR-style inhibition at the analog level. The framework ensures local safety deterministically while maintaining global coordination as a best-effort property. This paper presents an architectural contribution establishing design principles and interface contracts. Empirical validation remains future work.<\/jats:p>","DOI":"10.3390\/fi18010064","type":"journal-article","created":{"date-parts":[[2026,1,21]],"date-time":"2026-01-21T13:59:54Z","timestamp":1769003994000},"page":"64","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Guarded Swarms: Building Trusted Autonomy Through Digital Intelligence and Physical Safeguards"],"prefix":"10.3390","volume":"18","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7688-2367","authenticated-orcid":false,"given":"Uwe M.","family":"Borghoff","sequence":"first","affiliation":[{"name":"Institute for Software Technology, University of the Bundeswehr Munich, 85579 Neubiberg, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4662-2019","authenticated-orcid":false,"given":"Paolo","family":"Bottoni","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Sapienza University of Rome, 00161 Rome, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4912-582X","authenticated-orcid":false,"given":"Remo","family":"Pareschi","sequence":"additional","affiliation":[{"name":"Software and Knowledge Engineering Laboratory, University of Molise, 86100 Campobasso, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2026,1,21]]},"reference":[{"key":"ref_1","unstructured":"Borghoff, U.M., Bottoni, P., and Pareschi, R. (2025, January 5\u20137). Guarded Swarms: Hybrid Digital\u2013Analog Coordination for AI\u2013Robot Systems. Proceedings of the IEEE International Workshop on Technologies for Defense and Security (TechDefense 2025), Rome, Italy."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"1186","DOI":"10.1016\/j.icte.2025.10.006","article-title":"RIS-assisted UAV communications: A review of system models, frameworks and outage performance","volume":"11","author":"Rubab","year":"2025","journal-title":"ICT Express"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"96564","DOI":"10.1109\/ACCESS.2025.3575583","article-title":"Reconfigurable Intelligent Surfaces: A Hardware-Centric Review of Structures, Implementation, Evaluation, and Integration with UAV and Machine Learning","volume":"13","author":"Thai","year":"2025","journal-title":"IEEE Access"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Chang, G., Ren, S., Zhang, S., and Zhang, X. (2025). Hierarchical Decision Making-Based Intelligent Game Confrontation on UAV Swarm. Aerospace, 12.","DOI":"10.3390\/aerospace12121033"},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"285","DOI":"10.1142\/S2737480725030013","article-title":"New Explorations in Autonomous Low-Altitude Area Defense Decision-Making and Control Methods of UAV Swarms","volume":"5","author":"Xu","year":"2025","journal-title":"Guid. Navig. Control"},{"key":"ref_6","unstructured":"Abro, G.E.M., Abdallah, A.M., and Elshaar, M.E. (2025). Swarm Coordination and Trajectory Tracking in Quadrotor UAVs Using Fractional-Order PID Control Strategy. IEEE Trans. Autom. Sci. Eng., early access."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Feng, C., Fan, J., Liu, Z., Jin, G., and Chen, S. (2025). Unmanned Aerial Vehicle Anomaly Detection Based on Causality-Enhanced Graph Neural Networks. Drones, 9.","DOI":"10.3390\/drones9060408"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Carovilla, A., Pareschi, R., and Salzano, F. (2023, January 20\u201322). Integrating Blockchain for Enhanced Coordination and Security in Semi-Centralized Robotic Swarms. Proceedings of the IEEE International Workshop on Technologies for Defense and Security (TechDefense 2023), Rome, Italy.","DOI":"10.1109\/TechDefense59795.2023.10380842"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"1579166","DOI":"10.3389\/fhumd.2025.1579166","article-title":"Human-Artificial Interaction in the Age of Agentic AI: A System-Theoretical Approach","volume":"7","author":"Borghoff","year":"2025","journal-title":"Front. Hum. Dyn."},{"key":"ref_10","unstructured":"Wooldridge, M.J. (2002). Introduction to Multiagent Systems, Wiley."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Pareschi, R. (2024). Beyond Human and Machine: An Architecture and Methodology Guideline for Centaurian Design. Sci, 6.","DOI":"10.3390\/sci6040071"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"138","DOI":"10.1007\/s10791-025-09667-2","article-title":"An Organizational Theory for Multi-Agent Interactions Integrating Human Agents, LLMs, and Specialized AI","volume":"28","author":"Borghoff","year":"2025","journal-title":"Discov. Comput."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Borghoff, U.M., Bottoni, P., and Pareschi, R. (2025). Beyond Prompt Chaining: The TB-CSPN Architecture for Agentic AI. Future Internet, 17.","DOI":"10.20944\/preprints202507.1294.v1"},{"key":"ref_14","unstructured":"Lesser, V.R., and Gasser, L. (1995, January 12\u201314). BDI Agents: From Theory to Practice. Proceedings of the First International Conference on Multiagent Systems, San Francisco, CA, USA."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"1104","DOI":"10.1109\/TC.1980.1675516","article-title":"The Contract Net Protocol: High-Level Communication and Control in a Distributed Problem Solver","volume":"29","author":"Smith","year":"1980","journal-title":"IEEE Trans. Comput."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"201","DOI":"10.1016\/S0167-6423(97)00011-7","article-title":"Constraint-Based Protocols for Distributed Problem Solving","volume":"30","author":"Borghoff","year":"1998","journal-title":"Sci. Comput. Program."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Mutzari, D., Deb, T., Molinaro, C., Pugliese, A., Subrahmanian, V.S., and Kraus, S. (2025). Defending a City from Multi-Drone Attacks: A Sequential Stackelberg Security Games Approach. arXiv.","DOI":"10.1016\/j.artint.2025.104425"},{"key":"ref_18","unstructured":"Team, P., Xiang, J., Gu, Y., Liu, Z., Feng, Z., Gao, Q., Hu, Y., Huang, B., Liu, G., and Yang, Y. (2025). PAN: A World Model for General, Interactable, and Long-Horizon World Simulation. arXiv."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"293","DOI":"10.1016\/j.jlap.2008.08.004","article-title":"A Brief Account of Runtime Verification","volume":"78","author":"Leucker","year":"2009","journal-title":"J. Log. Algebr. Program."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"255","DOI":"10.1007\/s10009-021-00609-z","article-title":"A taxonomy for classifying runtime verification tools","volume":"23","author":"Falcone","year":"2021","journal-title":"Int. J. Softw. Tools Technol. Transf."},{"key":"ref_21","first-page":"387","article-title":"ROSMonitoring: A Runtime Verification Framework for ROS","volume":"Volume 12228","author":"Mohammad","year":"2020","journal-title":"Proceedings of the Towards Autonomous Robotic Systems\u201421st Annual Conference, TAROS 2020"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Kopetz, H., and Steiner, W. (2022). Real-Time Systems\u2014Design Principles for Distributed Embedded Applications, Springer. [3rd ed.].","DOI":"10.1007\/978-3-031-11992-7"},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"84","DOI":"10.1109\/JPROC.2002.805825","article-title":"Giotto: A time-triggered language for embedded programming","volume":"91","author":"Henzinger","year":"2003","journal-title":"Proc. IEEE"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"87","DOI":"10.1016\/0167-6423(92)90005-V","article-title":"The Esterel Synchronous Programming Language: Design, Semantics, Implementation","volume":"19","author":"Berry","year":"1992","journal-title":"Sci. Comput. Program."},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Caspi, P., Pilaud, D., Halbwachs, N., and Plaice, J. (1987, January 21\u201323). LUSTRE: A Declarative Language for Real-Time Programming. Proceedings of the 14th ACM SIGPLAN-SIGACT Symposium on Principles of Programming Languages (POPL), Munich, Germany.","DOI":"10.1145\/41625.41641"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Zhao, Y., Liu, J., and Lee, E.A. (2007, January 3\u20136). A Programming Model for Time-Synchronized Distributed Real-Time Systems. Proceedings of the 13th IEEE Real-Time and Embedded Technology and Applications Symposium (RTAS 2007), Bellevue, WA, USA.","DOI":"10.1109\/RTAS.2007.5"},{"key":"ref_27","unstructured":"Chapiro, D.M. (1985). Globally-Asynchronous Locally-Synchronous Systems. [Ph.D. Thesis, Stanford University]."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"1465","DOI":"10.1109\/TSMCC.2012.2191404","article-title":"Synthesizing Globally Asynchronous Locally Synchronous Systems with IEC 61499","volume":"42","author":"Yoong","year":"2012","journal-title":"IEEE Trans. Syst. Man Cybern. Part C"},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"255","DOI":"10.1007\/BF01995674","article-title":"Specifying Real-Time Properties with Metric Temporal Logic","volume":"2","author":"Koymans","year":"1990","journal-title":"Real-Time Syst."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Lakhnech, Y., and Yovine, S. (2004, January 22\u201324). Monitoring Temporal Properties of Continuous Signals. Proceedings of the Formal Techniques, Modelling and Analysis of Timed and Fault-Tolerant Systems, Joint International Conferences on Formal Modelling and Analysis of Timed Systems (FORMATS 2004) and Formal Techniques in Real-Time and Fault-Tolerant Systems (FTRTFT 2004), Grenoble, France. LNCS 3253.","DOI":"10.1007\/b100824"},{"key":"ref_31","unstructured":"Greenberg, A.G., and Sohraby, K. (2012, January 25\u201330). Real-time status: How often should one update?. Proceedings of the IEEE INFOCOM 2012, Orlando, FL, USA."},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Bar-Shalom, Y., Li, X., and Kirubarajan, T. (2001). Estimation with Applications to Tracking and Navigation: Theory, Algorithms and Software, Wiley.","DOI":"10.1002\/0471221279"},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"20","DOI":"10.1109\/MS.2001.936213","article-title":"Using Simplicity to Control Complexity","volume":"18","author":"Sha","year":"2001","journal-title":"IEEE Softw."},{"key":"ref_34","unstructured":"(2010). Functional Safety of Electrical\/Electronic\/Programmable Electronic Safety-Related Systems (Standard No. IEC 61508)."},{"key":"ref_35","unstructured":"(2018). ISO 26262: Road Vehicles\u2014Functional Safety (Standard No. ISO 26262-1:2018)."},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"217","DOI":"10.3166\/ejc.18.217-238","article-title":"Taming Dr. Frankenstein: Contract-Based Design for Cyber-Physical Systems","volume":"18","author":"Damm","year":"2012","journal-title":"Eur. J. Control"},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"2104","DOI":"10.1109\/JPROC.2015.2453253","article-title":"A Platform-Based Design Methodology with Contracts and Related Tools for the Design of Cyber-Physical Systems","volume":"103","author":"Nuzzo","year":"2015","journal-title":"Proc. IEEE"},{"key":"ref_38","unstructured":"Talpin, J., Derler, P., and Schneider, K. (October, January 29). Stochastic Contracts for Cyber-physical System Design under Probabilistic Requirements. Proceedings of the 15th ACM-IEEE International Conference on Formal Methods and Models for System Design, MEMOCODE 2017, Vienna, Austria."},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Kott, A. (2023). Autonomous Intelligent Cyber Defense Agent (AICA): A Comprehensive Guide, Springer.","DOI":"10.1007\/978-3-031-29269-9"},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"117843","DOI":"10.1109\/ACCESS.2025.3583985","article-title":"A Comprehensive Survey of Security and Privacy in UAV Systems","volume":"13","author":"Cordill","year":"2025","journal-title":"IEEE Access"},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"68660","DOI":"10.1109\/ACCESS.2025.3561068","article-title":"Electronic Warfare Cyberattacks, Countermeasures, and Modern Defensive Strategies of UAV Avionics: A Survey","volume":"13","author":"Yu","year":"2025","journal-title":"IEEE Access"},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"58","DOI":"10.1109\/MCOM.001.2400583","article-title":"Toward Intelligent Distributed Segment-Based Routing in 6G-Era Ultra-Large-Scale UAV Swarm Networks","volume":"63","author":"Wang","year":"2025","journal-title":"IEEE Commun. Mag."},{"key":"ref_43","unstructured":"Allied Command Transformation (NATO) (2025, December 06). NATO Task Force X: Deterring Today and Protecting Tomorrow. Available online: https:\/\/www.act.nato.int\/article\/nato-task-force-x."},{"key":"ref_44","unstructured":"(2025, December 06). Robotic Systems, Joint Project Office (RS JPO), SFAE-GCS-UGV MS. Unmanned Ground Vehicle (UGV) Interoperability Profile (IOP) Overarching Profile, Version 0. Available online: https:\/\/apps.dtic.mil\/sti\/tr\/pdf\/ADA558678.pdf."},{"key":"ref_45","unstructured":"North Atlantic Treaty Organization (NATO) (2025, December 06). Summary of NATO\u2019s Autonomy Implementation Plan. Available online: https:\/\/www.nato.int\/cps\/en\/natohq\/official_texts_208376.htm."},{"key":"ref_46","unstructured":"Arquilla, J., and Ronfeldt, D. (2000). Swarming and the Future of Conflict, RAND Corporation. Available online: https:\/\/www.rand.org\/pubs\/documented_briefings\/DB311.html."},{"key":"ref_47","unstructured":"CCDC Army Research Laboratory (2025, December 06). Autonomous Intelligent Cyber-Defense Agent (AICA) Reference Architecture, Release 2.0. Available online: https:\/\/apps.dtic.mil\/sti\/pdfs\/AD1080471.pdf."},{"key":"ref_48","doi-asserted-by":"crossref","first-page":"260","DOI":"10.1109\/LNET.2025.3610580","article-title":"Symbolic and safety-centric formal verification of MAVLink for autonomous eVTOL systems","volume":"7","author":"Mak","year":"2025","journal-title":"IEEE Netw. Lett."},{"key":"ref_49","unstructured":"\u00c5str\u00f6m, K.J., and Murray, R.M. (2020). Feedback Systems: An Introduction for Scientists and Engineers, Princeton University Press."},{"key":"ref_50","unstructured":"Dawis, E.P., Dawis, J.F., and Koo, W. (2001, January 7\u201310). Architecture of Computer-Based Systems Using Dualistic Petri Nets. Proceedings of the IEEE International Conference on Systems, Man and Cybernetics (SMC 2001), Tucson, AZ, USA."},{"key":"ref_51","unstructured":"North Atlantic Treaty Organization (NATO) (2025, December 06). NATO\u2019s Revised Artificial Intelligence Strategy. Available online: https:\/\/www.nato.int\/cps\/en\/natohq\/official_texts_227237.htm."},{"key":"ref_52","doi-asserted-by":"crossref","unstructured":"Wang, J. (1998). Timed Petri Nets: Theory and Application, Springer.","DOI":"10.1007\/978-1-4615-5537-7"}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/18\/1\/64\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,24]],"date-time":"2026-01-24T05:22:21Z","timestamp":1769232141000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/18\/1\/64"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,1,21]]},"references-count":52,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2026,1]]}},"alternative-id":["fi18010064"],"URL":"https:\/\/doi.org\/10.3390\/fi18010064","relation":{},"ISSN":["1999-5903"],"issn-type":[{"value":"1999-5903","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,1,21]]}}}