PNT Resilience Scoring Instability

Arxiv pdf 2026-07-01T00:00:00
arXiv Paper — PDF not available. Only the Executive Summary is available here. To read or download the full paper, visit the arXiv abstract page.

Abstract

Every authoritative positioning, navigation, and timing (PNT) resilience framework, from the DHS Resilient PNT Conformance Framework (RPCF) to the Resist-Detect-RespondRecover model and Yangs resilient-PNT criteria, defines what resilience means but supplies only self-attestation: a checklist or a maturity Level, with no engine, no measurement, and no evidence. We build the missing measurement layer as an open, deterministic scoring engine over a PNT simulator, emitting perdimension sub-scores each traceable to a scenario and an oracle and each tagged with its honest validation status. We then ask whether a single composite score, or a single maturity Level, is a stable basis for a decision. Across a reference panel of seven architectures built to span genuine cross-dimension tradeoffs, a Dirichlet weighting simplex over the seven RPCF categories, and a five-threat ensemble, the answer separates into two regimes. The composite winner is stable under active denial and under near-equal weightings, flipping in about 1 percent of draws, so a single number is safe precisely where one design dominates; but re-weighting alone flips the winner in up to 22 percent of draws under nominal conditions, where designs genuinely contend, and that instability is a domain application of known compositeindicator sensitivity. The sharper and weighting-invariant failure is categorical: a weakest-link maturity Level (our minimumover-categories operationalization of the RPCF ladder, not the frameworks own rule) is a function of the threat assumed rather than of the architecture, changing for one architecture in seven across the ensemble. A constructed example shows that, because the composite rewards declared techniques, a singleband receiver declaring all seven techniques can outscore a genuinely more resilient system: self-attestation can be gamed by declaration. And apparent fourfold GNSS redundancy reduces, by the definition of a shared common-mode failure domain, to an effective diversity of one. The conclusions hold under a plusor-minus 20 percent perturbation of every driver within the modelled reduction. We argue for reporting per-dimension subscores with provenance and a rank range, not a phantom single number. This is a simulation-derived self-assessment aligned to RPCF v2.0, not a certification.

Loading executive summary...

LINK COPIED TO CLIPBOARD