A Model-Based Reference Architecture Toward Trustworthy AI-Assisted SBOM Lifecycle Governance in Safety-Critical Cyber–Physical Systems

Software supply chain vulnerabilities in Safety-Critical Cyber–Physical Systems demand more than a static Software Bill of Materials; decision makers need traceable links among build artifacts, vulnerabilities, deployment context, and remediation evidence. This paper presents a Model-Based Systems Engineering reference architecture that integrates Software Bill of Materials metadata lifecycle management, a semantic knowledge graph, cybersecurity intelligence, and human-reviewed AI advisory support. We instantiated the architecture using a Yocto build and evaluated it on 80 author-adjudicated component/CVE pairs. The knowledge graph preserved complete evidence paths, while GraphRAG used locally hosted Large Language Models to present the retrieved evidence. Target-case GraphRAG with Gemma 3 12B matched the rule-based baseline in both coverage (90%) and exact agreement (80%). Without graph grounding, Gemma issued definite coverage for only three cases, all of which were incorrect, compared with 72 definite verdicts when graph evidence was provided. Changing the model or retrieval scope had little effect on the results but increased latency, while conventional scanners (Trivy, Syft/Grype) covered few Yocto-specific cases. These findings support an architecture in which deterministic, rule-based interpretation of evidence encoded in the knowledge graph remains authoritative, while the Large Language Model serves as a replaceable interface that presents evidence-grounded output for human review rather than making autonomous decisions.

Authors

Institutions

Publication Details

Journal
Future Internet
Published
2026-09-24
DOI
https://doi.org/10.3390/fi18100506
Primary Topic
Information and Cyber Security
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

A Model-Based Reference Architecture Toward Trustworthy AI-Assisted SBOM Lifecycle Governance in Safety-Critical Cyber–Physical Systems

Mars Rayno, Jeremy S. Daily, Teddy Nyambe, Sarah Rudder
Future Internet
Information and Cyber Security
article

A Model-Based Reference Architecture Toward Trustworthy AI-Assisted SBOM Lifecycle Governance in Safety-Critical Cyber–Physical Systems

Mars Rayno, Jeremy S. Daily, Teddy Nyambe, Sarah Rudder
article en

Abstract

Software supply chain vulnerabilities in Safety-Critical Cyber–Physical Systems demand more than a static Software Bill of Materials; decision makers need traceable links among build artifacts, vulnerabilities, deployment context, and remediation evidence. This paper presents a Model-Based Systems Engineering reference architecture that integrates Software Bill of Materials metadata lifecycle management, a semantic knowledge graph, cybersecurity intelligence, and human-reviewed AI advisory support. We instantiated the architecture using a Yocto build and evaluated it on 80 author-adjudicated component/CVE pairs. The knowledge graph preserved complete evidence paths, while GraphRAG used locally hosted Large Language Models to present the retrieved evidence. Target-case GraphRAG with Gemma 3 12B matched the rule-based baseline in both coverage (90%) and exact agreement (80%). Without graph grounding, Gemma issued definite coverage for only three cases, all of which were incorrect, compared with 72 definite verdicts when graph evidence was provided. Changing the model or retrieval scope had little effect on the results but increased latency, while conventional scanners (Trivy, Syft/Grype) covered few Yocto-specific cases. These findings support an architecture in which deterministic, rule-based interpretation of evidence encoded in the knowledge graph remains authoritative, while the Large Language Model serves as a replaceable interface that presents evidence-grounded output for human review rather than making autonomous decisions.

Future InternetVol. 18(10)
Colorado State University (US)
Openalex Percentile: Top 4%
Information and Cyber Security
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.