Edge network security improved by governor checks on automated actions

Autonomy in Check: Governor-Mediated Adaptive Security at the Edge

Cryptography and SecurityArtificial Intelligence

Summary

Security systems at the edge of networks use automatic planners to decide actions, but these planners can make mistakes or be tricked by bad information. The paper shows that just checking if an action looks correct on the surface is not enough. Instead, the authors propose a middleman called a governor that carefully checks each action before it is carried out to make sure it follows safety and fairness rules. They tested this approach on small devices connected to a 5G network and found it works very quickly without messing up normal network flows.

What this means in practice

  • For edge network operators: Control and verify automatic security actions at the network edge to prevent unsafe or malicious policy changes in real time.
  • For iot device managers: Enforce safer dynamic security policies on resource-constrained devices by mediating planner decisions with a governor.

Authors

Ijaz Ahmad, Ijaz Ahmad, Flavio Esposito, Erkki Harjula

Abstract

Adaptive security at the network edge increasingly relies on automated planners, including rule-based controllers, learned policies, and LLM-assisted agents, that translate observations into enforcement actions. Once such a planner can influence live policy state, syntactic validity is not enough. A semantically wrong action, produced from incomplete or manipulated observations, can be faithfully executed by an enforcement substrate that cannot judge mission context. We address this problem by treating the boundary between planner output and kernel enforcement input as the primary security object. We propose a split-control architecture in which an untrusted planner emits typed security intents, a deterministic governor checks each intent against safety, resource, temporal-stability, and proportionality invariants, and only admitted actions are bound to signed receipts and compiled into pre-installed eBPF map updates. The paper formalizes this trust-boundary problem, defines three threat classes, develops the governor admission predicate, and reports an end-to-end prototype. Across rule-based and LLM-assisted planners on a Raspberry Pi 5 testbed connected to the university 5G Test Network, the governor admits, rejects, and bounds intents at microsecond cost without disrupting protected-flow regularity. The contribution is conceptual as much as empirical: adaptive security does not need to trust the author of an action. It needs a mediation boundary that decides whether the action is admissible.