SRI International Computer Science Laboratory


Assurance 2.0

Robin Bloomfield and John Rushby

Assurance cases augment earlier approaches to assurance such as standards and guidelines by allowing more choice in selection of techniques for ensuring and justifying safety and other critical properties.

Building on this, Assurance 2.0 is an approach to the development and presentation of assurance cases that is intended to make their construction and assessment more straightforward, yet also more rigorous. In fact, it is rigor that enables straightforwardness because it reduces the "bewilderment of choice" and makes assurance cases more systematic and predictable. Assurance 2.0 employs several ideas that are not in themselves new, but integrates them in a way that we believe is coherent and effective.

Our papers on Assurance 2.0 are listed below in reverse chronological order. We suggest starting with either the "Manifesto" paper (broad but light on details) or the one from Cliff Jones' Festschrift (more technical but also more narrowly focused). Look at the 2-page "Nutshell" (pdf) when you need a really high-level overview or memory aid.

An overview of my other papers on assurance

Clarissa/ASCE Tool support for Assurance 2.0

Honeywell, Adelard (now part of NCC Group), SRI, and UT Dallas

Clarissa is a tool suite that supports Assurance 2.0. It builds on Adelard's ASCE and Clarissa/ASCE is available from Adelard: see the
CAE website.

Clarissa supports the construction and evaluation of assurance cases using Assurance 2.0, and provides tools for logical and probabilistic assessment, defeaters, and residual doubts. It also has a synthesis assistant that can synthesize assurance (sub)cases from templates provided in a theory.

In addition Clarissa has tools for exploring semantic properties. It can use an LLM to translate claims into a logical representation, then perform reasoning using Answer Set Programming with s(CASP) to examine properties such as consistency, certain forms of well-formedness, and completeness.

Applications

 *NEW* GDM Inability Case

In 2024, Google Deep Mind reported an investigation they performed to see if LLMs could manifest "dangerous capabilities." Their initial report is available as
arXiv 2403.13793 with a detailed treatment at arXiv 2505.01420. This is organized as a safety case but does not follow any specifc method.

Recently, Arcadia Impact (UK) Government Task Force performed an external review of this "GDM Inability Case" as they call it, structured using Assurance 2.0.

There's an informal blog description and a full paper available as arXiv 2604.21964.

Return to my bibliography page.

John Rushby (R u s h b y @ c s l . s r i . c o m)