How to make military decision-support software reliable when comms go down

Armed forces need greater robustness from the systems they are increasingly using to support combat decision-making.

How to make military decision-support software reliable when comms go down

How to make military decision-support software reliable when comms go down

Armed forces need greater robustness from the systems they are increasingly using to support combat decision-making. These software systems must keep satisfactorily advising officers on decisions even when communications links go down, as they must be expected to go down.

Delegation to lower-level commanders improves combat effectiveness: action continues even when higher officers have lost an ability to direct. Sometimes the higher command, though still in contact, wants lower officers to take control, because they may have better and faster awareness of what is going on.

All this delegation works better if helped by decision-support software, which offers expertise that a local commander may lack and which eases his or her cognitive load. It may, for example, recommend which of three possible dispersal sites for an air-defence battery is best, or which casualty evacuation task needs to go first. In another case, the software may give its assessment of which track of an unknown unit – say, an aircraft or ground vehicle – has met the threshold for reporting as hostile.

But if such software packages themselves rely on links to servers, as in fact most do, they will lose much of their functionality when communications go down. A lower-level officer who understands the limits of isolated decision-support software may distrust it when links are lost and choose inaction just when action is needed. An even worse case is the opposite: isolated software may keep making seemingly confident recommendations using data that is now hours old and not acknowledge the shortcoming.

Communications links are at risk to jamming, air and missile strikes, sabotage and the breaking of undersea cables. Bringing down the enemy’s comms is a basic objective in warfare.

To overcome this threat, decision-support software must have four properties, without which delegation is not safe.

First, the software must make the decision-making computation locally, without relying on a remote server. The model and the rules should sit on the node in front of the operator, where the recommendation should be produced.

This brings unavoidable limitations. A system that fits on a vehicle or a field server is less capable than one running in a data centre, and it sees only what the local node can see. If its link fails, it will hold the theatre picture only as it was at the point of failure. Terrain, obstacles and fixed installations keep their value for days; the position of a moving enemy unit does not. Still, the performance of will not fall off a cliff when the comms go down.

Second, decision-support software must be under national control, so that no vendor and no foreign government can alter, withhold or revoke its behaviour mid-crisis. The system will surely include imported components, but the operating country can and must have the legal right and technical ability to run it without ongoing permission.

Third, the software must produce a traceable reason for each recommendation rather than just a confidence score, because a person accepting legal responsibility for a decision must be able to state the grounds. It must also keep that record in a form that survives a communications outage, because reconstruction happens afterwards.

Traceable reasoning is also at the heart of making these systems interoperable. If two countries’ armed forces are operating side by side, each will need to understand why the other’s decision-support software has made a recommendation: what inputted data was used, what rules applied, what were the thresholds for deciding, and so on. The software’s confidence score for a recommendation won’t be enough.

Fourth, the automatic decision-support must degrade loudly. If it loses access to some data, it must say so. It must indicate when it’s relying on old information and, when the information is just too old, withhold recommendations.

A certification process for all this will be needed, and Australia already has the vehicle to implement such improvements: its 2026 Defence Industry Development Strategy already prioritises national industrial capacity for the integration of battlespace management systems and their testing, evaluation and certification. Australia certifies airworthiness. It certifies seaworthiness. Yet it and other countries have no equivalent standard for decision-support software, even though it is now being used in every warfighting domain. Defence should define such a standard, and the four properties above are a serviceable first draft for its criteria.

About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.