Autonomous Defensive AI: An Envelope-and-Evidence Framework for Governed LLMs Acting on Production Infrastructure
This paper defines ADAI (Autonomous Defensive Artificial Intelligence) as a proposed category of governed autonomous cyber defense and develops an envelope-and-evidence framework for systems acting on production infrastructure. DAI, the proprietary domain-specific LLM and its governed defensive architecture, is described separately in the companion paper. The framework specifies defended perimeters, bounded effects, declared rollback and capability-disjoint verification. Admissibility is adjudicated outside the learned model, while hash-linked, seal-terminated receipts provide a self-describing recomputation contract. The paper develops exact tamper localization, per-principal containment at shared enforcement points, element-wise reconciliation under aggregation, atomization conditions, blinded correlation and conditions for composite reversibility. It also separates policy quality, admissibility and evidence integrity in its evaluation methodology. Formal results depend on their stated assumptions. Reported deployment observations refer to the version and period described in the manuscript. This preprint does not assert that every theoretical construction is implemented or independently validated. Post-filing edition prepared on 1 October 2026. U.S. provisional application 64/166,855; patent pending, not granted. English manuscript and Portuguese translation. This is a preprint and is not represented as peer-reviewed.
Authors
- Hiago Kin Levi
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-10-01
- DOI
- https://doi.org/10.5281/zenodo.23089594
- Citations
- 2
- Primary Topic
- Adversarial Robustness in Machine Learning
- Type
- preprint