Safe: Automaton-Theoretic Runtime Monitoring of Blackbox Distributed Systems
Abstract
Modern safety-critical systems are increasingly built from blackbox components: cloud services, third-party APIs, autonomous systems, and AI agents whose source code or internal state may be unavailable for inspection. To certify safe and secure inter-component interactions in such systems, security and compliance teams must enforce policies over sequential and nested call/return patterns in the execution, along with the data values exchanged between the components. Furthermore, the blackbox setting necessitates decoupling the policy enforcement mechanism from the system implementation. To this end, I design Safe⟨ T⟩, an automaton-theoretic runtime monitoring framework for specifying and enforcing control-flow and data-aware policies over black-box distributed systems. My technique is blackbox and non-invasive, i.e., it requires no code access or implementation changes. To realize this framework, I have built a distributed runtime monitor on top of an emerging network infrastructure layer that can control inter-component communication. I have demonstrated Safe⟨ T⟩ on cloud microservices and am now extending it to agentic AI systems.