SWORT Aerospace Develops CSIA Architecture for Independent Assurance of Autonomous Aircraft

August 17 22:52 2026
SWORT Aerospace is developing a new approach to autonomy assurance through its Cross-Sensor Intelligence Architecture (CSIA), a proprietary architecture designed to reason about sensor evidence, uncertainty and competing fault explanations before information is allowed to influence autonomous aircraft systems.

New York, United States – August 17, 2026 – SWORT says the work is intended to address a gap between conventional sensor monitoring and the requirements of increasingly autonomous aircraft. Rather than treating sensor integrity as a matter of threshold violations or simple sensor-to-sensor disagreement, CSIA is being developed as an independent reasoning layer that evaluates what information remains trustworthy, what competing explanations are still plausible, how strong the available evidence is and what response that evidence can justify.

The company is also developing SSIL, or System State Integrity Layer, as the commercial and replicable implementation pathway emerging from its deeper CSIA research.

Together, the two efforts represent SWORT’s attempt to establish a broader assurance architecture category for autonomous systems: a layer positioned between what an aircraft perceives and what its flight systems are ultimately allowed to believe.

Beyond Conventional Sensor Monitoring

Autonomous aircraft increasingly depend on multiple sources of information, including GNSS, inertial measurement units, magnetometers and other navigation and flight-state sensors.

Conventional monitoring can identify many straightforward failures. A measurement can be compared against a threshold, two sensors can be compared against one another, or an estimator can generate a health warning when its internal consistency checks detect a problem.

Those mechanisms remain useful, but they do not necessarily answer the larger question facing an autonomous system: what should the aircraft believe when the evidence is incomplete, conflicting or potentially explained by more than one cause?

A GNSS measurement can become inconsistent because of signal degradation, interference, dropout or spoofing-like behaviour. An IMU can develop a bias while continuing to produce values that appear plausible. Magnetic interference can affect a magnetometer without indicating a hardware failure. Multiple sensors can also show related anomalies because they share an environmental or system-level cause.

CSIA is being designed around these situations.

The architecture does not reduce the problem to a binary determination of whether a sensor is good or bad. Instead, it is intended to evaluate relationships between measurements while considering aircraft context, uncertainty, accumulated evidence and possible dependencies between observations.

That makes the architecture fundamentally different from a configurable monitoring package.

An Architecture Built Around Evidence and Trust

A central element of CSIA is context-conditioned residual reasoning.

Sensor relationships do not necessarily remain constant throughout a flight. An expected relationship during steady flight may be different during a manoeuvre, acceleration, environmental disturbance or other change in aircraft state.

CSIA’s developing residual architecture is intended to account for that context rather than treating every discrepancy as equally meaningful.

The architecture also incorporates probabilistic trust reasoning, allowing confidence in information to change as new evidence arrives. Instead of forcing an immediate valid-or-invalid classification, the system can represent uncertainty and changing levels of trust.

That reasoning is connected to sequential e-evidence, where individual observations are considered as part of an evolving evidence sequence rather than being treated as isolated events.

This matters because the significance of an anomaly can depend on what happens before and after it. A single unusual measurement may not justify rejecting a source of information. A sequence of observations that consistently supports a particular explanation can provide a much stronger basis for action.

CSIA is intended to reason across that sequence.

Calibration, Dependencies and Multiple Causes

SWORT’s developing architecture also includes conformal calibration, intended to improve how uncertainty and confidence assessments are related to observed system behaviour.

The research further incorporates sparse multi-cause Bayesian reasoning and structural dependency models.

These components address a fundamental problem in multi-sensor systems: not every observation represents independent evidence.

If several sensors respond to a common environmental disturbance, treating their behaviour as independent may make a system appear more certain than the evidence warrants. Conversely, assuming that every inconsistency comes from a single failed sensor can lead to the wrong diagnosis.

Structural dependency modelling is intended to help the architecture reason about these relationships and consider whether multiple observations may have a shared cause.

Sparse multi-cause reasoning provides another layer by allowing competing fault explanations to be considered without requiring every possible combination of faults to be treated equally.

The objective is not simply to identify an anomaly. It is to determine which explanations remain plausible and how much confidence the available evidence supports.

Preserving Ambiguity Instead of Forcing Certainty

Another developing part of CSIA is set-valued ambiguity.

In conventional monitoring, an alert often pushes a system toward a single interpretation: a sensor has failed, a measurement is invalid or a condition is abnormal.

Real aircraft systems can be less clear.

There may be insufficient evidence to distinguish between interference and hardware degradation, between a temporary navigation disturbance and a persistent fault, or between several correlated explanations.

CSIA is being designed to preserve that ambiguity when the evidence does not justify a definitive conclusion.

For autonomous aircraft, this can be important. A system that acknowledges uncertainty can potentially make a more controlled decision than one that converts weak evidence into false certainty.

The architecture therefore considers not only whether something is anomalous, but what information remains eligible for use and what conclusions the current evidence can actually support.

Evidence Traces and Bounded Decision Authority

CSIA also includes evidence traces, providing a way to preserve the observations and reasoning that contributed to an assurance assessment.

An assurance layer needs to be more than a number or warning. During development, testing and investigation, engineers need to understand why confidence changed, which observations influenced the assessment and which competing explanations were considered.

Evidence traces are intended to provide that visibility.

The architecture is also being developed around bounded decision authority.

CSIA is not positioned as a replacement for an aircraft’s primary flight computer, estimator or flight-control system. Instead, its role is to operate as an independent assurance layer with defined authority over how information is treated.

That can include determining whether information should remain eligible for use, be discounted, be treated as uncertain or trigger a defined response within the system’s permitted boundaries.

The distinction is important because an assurance architecture does not need to control the aircraft to influence its safety. Its role can instead be to establish which evidence the aircraft should be permitted to rely upon and under what level of confidence.

Demonstrated Against Real Flight Data

SWORT’s work on CSIA extends beyond a theoretical architecture.

The company says it has evaluated CSIA against real PX4 flight-log data as well as controlled and injected fault conditions. Testing has included GNSS inconsistency and dropout, spoofing-like behaviour, IMU bias, magnetic interference and other sensor and system faults.

In one real-flight analysis, SWORT reports that CSIA identified an approximately 55-metre GNSS inconsistency that had not produced the expected estimator-level warning. The company describes the result as an example of the independent perspective CSIA is intended to provide alongside existing estimator-level health mechanisms.

The result is significant in the context of the architecture’s purpose because it illustrates the difference between detecting a problem through an existing estimator and independently reasoning over the evidence available across the aircraft.

SWORT is also moving the architecture toward embedded implementation. Core components have been implemented in native C, with development directed toward an STM32H7-class deployment pathway.

This work brings CSIA closer to the constraints of actual avionics, where processing resources, timing, memory, power and hardware interfaces all influence how an assurance system can operate.

From Mathematical Research to Physical Avionics

CSIA is part of a broader technical programme at SWORT rather than an isolated software project.

The company’s work spans mathematical and probabilistic research, real-flight data analysis, controlled fault experimentation, embedded software, flight computers, custom PCB design, PX4 and ArduPilot integration, hardware-in-the-loop development and physical avionics.

This creates a development stack that runs from mathematical models to actual hardware.

Flight data provides evidence from real aircraft behaviour. Controlled fault injection allows specific failure conditions to be examined repeatedly. PX4 and ArduPilot provide flight-computer environments for integration and testing. Hardware-in-the-loop systems allow aircraft and fault conditions to be exercised in controlled environments.

At the hardware level, custom PCBs and embedded flight computers provide a path toward deploying the assurance architecture within the same physical constraints faced by other aircraft systems.

SWORT’s current public capabilities also include STM32H7-based embedded flight computers, GNC hardware, custom aerospace PCB design and embedded firmware development, reinforcing the company’s broader hardware-to-software development direction.

The result is an accumulated engineering system rather than a standalone monitoring algorithm.

SSIL Provides the Commercial Pathway

While CSIA is the deeper proprietary research architecture, SWORT is developing SSIL as the commercial and replicable implementation pathway for bringing that work into deployable aerospace systems.

That distinction is central to the company’s approach.

A basic concept such as comparing sensor measurements can be reproduced relatively easily. Reproducing an architecture built around context-conditioned residual banks, probabilistic trust models, sequential evidence, calibration, structural dependencies, multi-cause reasoning, ambiguity handling and bounded authority is a different problem.

The same applies to implementation.

The architecture is supported by accumulated models, calibration approaches, validation methodology, flight-data analysis, fault experiments, embedded software and engineering decisions made through development and testing.

SWORT therefore views SSIL not simply as a software package, but as the implementation direction for a deeper body of proprietary research and engineering.

The company’s public materials currently describe SSIL as a System State Integrity Layer in development, targeting STM32H7 and FreeRTOS and intended for real-time fault detection.

Building an Emerging Assurance Category

The distinction between CSIA and conventional sensor monitoring is ultimately about the question the system is designed to answer.

A monitor asks whether a measurement has crossed a limit.

An estimator health check asks whether its internal assumptions remain consistent.

A voting system can determine which source appears to agree with the majority.

CSIA is being developed to ask a broader question:

Given the evidence currently available, the aircraft’s context, the relationships between its sensors and the plausible causes of what it is observing, what information should the autonomous system still be allowed to believe?

That question requires several mechanisms to operate together.

Context-conditioned residual banks provide structured anomaly evidence. Conformal calibration addresses confidence and uncertainty. Sequential evidence allows confidence to evolve over time. Sparse multi-cause Bayesian reasoning considers competing explanations. Structural dependency models account for relationships between observations. Set-valued ambiguity prevents unsupported certainty. Evidence traces preserve the reasoning behind assessments. Bounded decision authority defines what the assurance layer can actually influence.

The architecture is therefore not defined by one algorithm.

It is defined by how these mechanisms operate together.

A Cross-Disciplinary Programme

SWORT was founded by 19-year-old Andres Pena, who leads work across probabilistic research, flight-data analysis, embedded avionics, hardware development and the broader autonomy-assurance architecture.

His age is notable given the breadth of the technical programme, but the focus of the work is the engineering system being developed rather than a founder story.

The company’s programme connects research and implementation across several normally separate disciplines, from probabilistic reasoning and flight-data analysis to embedded software, flight computers, custom electronics and physical avionics.

That breadth is relevant to CSIA because an assurance architecture cannot be evaluated only as mathematics or only as software. Its behaviour ultimately has to be understood in relation to the aircraft, its sensors, its flight computer, its operating environment and the hardware on which the architecture runs.

The Layer Between Perception and Belief

Autonomous aircraft can collect enormous amounts of information, but collecting more information does not automatically make an aircraft better at deciding what to trust.

The difficult cases arise when evidence conflicts, when multiple sensors may share a cause, when a fault develops gradually or when the available information is simply insufficient to distinguish between competing explanations.

SWORT’s CSIA architecture is being developed for that layer of the problem.

Its objective is to provide an independent reasoning layer capable of assessing not only whether something is anomalous, but what information remains eligible for use, which causes remain plausible, how strong the evidence is and what response that evidence can justify.

SSIL represents the path toward turning that proprietary research into a commercial and replicable aerospace implementation.

The work is still under development, but SWORT has already connected the architecture to real PX4 flight data, controlled fault experimentation, native C implementation and an STM32H7 deployment pathway. The broader programme extends into flight computers, custom PCBs, PX4 and ArduPilot integration, hardware-in-the-loop testing and physical avionics.

For autonomous aircraft, that creates a different way to think about assurance: not as another sensor monitor sitting beside the flight system, but as an independent layer that reasons about evidence before that evidence is allowed to carry the full weight of an autonomous decision.

About SWORT LLC

SWORT LLC is a U.S.-based aerospace electronics and R&D company operating in the Washington, D.C. area. The company develops aerospace electronics, embedded avionics, flight computer systems, GNC hardware, custom PCB designs, sensor-fusion systems and related technologies, alongside its research into autonomy assurance through CSIA and SSIL.

More information about SWORT is available through SWORT Aerospace. Company updates are also available on LinkedIn and Instagram.

Media Contact
Company Name: swort
Contact Person: Media Relations
Email: Send Email
Country: United States
Website: https://swort.net/

view more articles

About Article Author