>
Multi-AI Cyber-Physical Control Engineering
RAPTOR-MultiAI™ is a real-time cyber-physical control architecture that coordinates multiple specialized artificial intelligences over a shared world model, weights their reliability and fuses them into a single command. Every physical action remains under the supervision and decision authority of a human operator.
Intellectual Property Status
USPTO Provisional Patent No. 63/999,217
Applicant and IP owner: ONMAKE S.R.L. · Inventor and CEO: Massimiliano Tulli · Patent Pending
The whole architecture rests on four design choices that define its identity and set it apart from control systems based on a single model: the plurality of intelligences, technological governance, dynamic adaptation and human decision present across all processes.
01
Control is not entrusted to one model, but to a set of specialized AI modules analyzing different domains of the same scenario in parallel: detection, classification, trajectory prediction, collective behavior, environmental conditions, energy, actuation optimization. Every module works on the same shared global state, and none holds absolute control.
A supervisory orchestrator assigns each module a dynamic confidence weight, reflecting the estimated reliability of its outputs under current operating conditions. The decision fusion engine combines candidate commands into a single command in which more reliable modules carry more weight. It is the opposite of a single-point-of-failure system: if one module degrades, the others compensate.
03
RAPTOR's governance is not a statement of intent written alongside the system: it is a set of technical mechanisms that constrain how the architecture behaves. The decision chain is separated by construction into generation, aggregation and authorization; the thresholds determining what may be executed autonomously and what requires approval are configurable system parameters, not organizational practice; the recording of every decision cycle is a function of the architecture, not a subsequent formality.
This choice has a practical consequence: the properties the architecture claims are verifiable. One can inspect which modules contributed to a decision, with what weight, on the basis of which sensor data and with what margin of uncertainty. It is the difference between asserting that a system is under control and building it so that control is a structural property of it, reconstructable afterwards by those who must account for it.
04
Nothing in the architecture is fixed once and for all. The confidence weights assigned to modules are not static parameters calibrated at design time, but values continuously updated according to current environmental conditions, the quality of available sensor data, observed performance and cross-validation between module outputs. A module that is the most reliable source in one situation may become marginal when conditions change.
The same applies to operational configuration: the orchestrator selectively activates and deactivates modules according to context, so as not to consume computational resources when full analysis is unnecessary, and adjusts the balance between predictive and reactive components according to model certainty and scenario volatility. The architecture reconfigures itself while operating, and this continuous adaptation is what allows it to stay stable as the operational tempo changes.
02
The architecture generates commands that change the physical world. That is why the decision chain is deliberately separated into three distinct moments: AI modules generate the proposals, the fusion engine aggregates them, the orchestrator with human supervision authorizes them. Critical decisions, particularly those involving engagement, require explicit authorization from an authorized operator.
Supervision is not a layer added afterwards: it is built throughout the architecture, through configurable authorization thresholds, a common operational picture that keeps the operator aware of the situation, the ability to intervene and override an automated decision, and a complete record of every decision cycle (sensor inputs, module outputs, reliability weights, fusion calculations and final command) supporting analysis, validation and accountability.
The availability of inexpensive drones, coordinated swarms and increasingly sophisticated missile systems has changed the nature of threats to critical infrastructure, installations, transport networks and populated areas. Traditional systems were designed to counter a limited number of high-value targets; an adversary today can saturate a point defense with many low-cost, coordinated objects.
The difficulty multiplies with the diversity of profiles: size, speed, radar cross-section, thermal signature and flight behavior vary enormously. Some threats use evasive maneuvers, terrain masking or electronic countermeasures. Fog, rain, dust, smoke, darkness and atmospheric turbulence further degrade the performance of individual sensor modalities.
The same pattern appears, under different names, in industrial automation and remote operations: many simultaneous variables, rapidly changing conditions, environments where error carries an immediate physical cost and where the human operator often cannot be present.
The design conclusion is the same in all three cases: what is needed is an architecture able to process multiple sensor modalities simultaneously, analyze different dimensions of the problem through specialized AI modules and generate a coordinated real-time response, while remaining governable.
A single model, however sophisticated, remains a compromise across heterogeneous domains and a single point of failure. Orchestration distributes both risk and specialization.
Single-model AI control
RAPTOR Multi-AI orchestration
RAPTOR is organized as a layered cyber-physical control system, traversed by a continuous loop: sense, analyze, decide, act. The layers group into three logical moments, each with a precise function and defined interfaces towards the others, so that every part can be developed and validated separately without compromising the whole.
01
The first moment turns the physical world into a usable representation. The sensor layer gathers data from a heterogeneous network of devices chosen to cover complementary physical modalities: phased-array radar, providing range, azimuth, elevation and Doppler velocity across multiple simultaneous targets; high-resolution LiDAR for three-dimensional mapping at centimeter precision; electro-optical and thermal infrared cameras for visual identification by day and night; acoustic sensors, particularly effective against low-altitude threats; radio-frequency detectors to characterize emitted communication and telemetry signals; environmental instruments for temperature, humidity, pressure, wind and visibility.
This diversity is not superfluous redundancy, it is the condition for robustness: when fog or dust degrade optical sensors, radar and infrared keep providing tracking; when radar is disturbed by electromagnetic interference, acoustic and optical modalities maintain situational awareness. The fusion subsystem then integrates these signals through multispectral correlation algorithms that resolve inconsistencies between modalities, statistically reduce measurement uncertainty and associate detections from different sensors with the same physical object, producing coherent, persistent tracks even in cluttered environments.
The result flows into the global system state, the shared data structure that is the true centre of the architecture. It holds detected objects with position, velocity, acceleration, classification and confidence level; high-resolution environmental maps; persistent calibration and sensor alignment parameters; the state of computational and bandwidth resources; the thermal and energy state of subsystems; and the common operational picture intended for the operator. The decisive point is that all AI modules read from this same representation: this is what prevents contradictory assessments between intelligences that would otherwise reason on different snapshots of reality.
02
The second moment is where the originality of the architecture concentrates. On the shared global state, multiple AI modules operate in parallel, each specialized in a distinct domain of the problem, each developable, trainable and validatable independently of the others. None of them has the decisive voice: all produce an analysis and a candidate command reflecting their own specialized perspective.
Above them operates the supervisory orchestrator, which constitutes a genuine meta-control layer rather than a mere collector of results. It assigns each module a confidence weight continuously updated based on environmental conditions, the quality of available sensor data, observed historical performance and cross-validation between the outputs of different modules. It selectively activates and deactivates modules according to context, so as not to consume computational resources when full analysis is unnecessary. It adjusts the balance between predictive and reactive components. It reconciles contradictory recommendations through weighted arbitration.
The decision fusion engine closes the moment: it collects the candidate commands of active modules and computes the unified command as their weighted combination, in which modules more reliable under current conditions contribute proportionally more. Weights are normalized to sum to one, so the result is a balanced integration of all contributions rather than the arbitrary prevalence of any one of them.
03
The third moment carries the decision into the physical world, and is the point where the architecture takes on its design responsibility. The actuation layer executes the unified command through the mechanisms the scenario calls for, remaining independent of specific hardware; execution feedback (outcomes, energy consumption, thermal measurements, mechanical state) returns into the global state and feeds the continuous adaptation of the control strategy, closing the loop.
The distributed network layer allows multiple autonomous nodes to operate in coordination across extended geographic areas, each with its own local state and all contributing to a shared one, with the ability to keep functioning autonomously if the link is lost and to reconcile state on restoration.
Crossing and overarching all these layers is the human supervision interface. It is not the last link in a chain, but a transversal layer accompanying the entire architecture: it defines authorization thresholds, keeps the operator aware through the common operational picture, enables intervention and override, and records every decision cycle in full. It is the layer that makes actuation governed rather than merely automatic.
The core of RAPTOR is a continuous high-frequency loop integrating a predictive and a reactive component. The predictive component anticipates future states and generates compensatory signals before change is directly observed; the reactive component maintains direct sensor-to-actuator responsiveness for unexpected events. The balance between the two is dynamically adjusted by the orchestrator based on the certainty of predictive models and the volatility of the scenario.
The control loop may operate on a microsecond or millisecond scale depending on the computational platform, sensing configuration and specific implementation.
Each module is designed to analyze a specific domain of the operational environment and can be independently developed, validated and updated. No module holds absolute control: all contribute in parallel to solving the cyber-physical problem.
Identifies objects in the environment using computer vision and multispectral analysis. It distinguishes threat categories from non-hostile entities (birds, weather phenomena, civilian aircraft) applying models that combine kinematic, thermal, electromagnetic and morphological features.
Estimates future motion combining classical kinematic models and machine learning algorithms. For ballistic or linear paths, kinematic extrapolation provides reliable short-term predictions; for non-ballistic behavior (evasive maneuvers, sudden course changes, coordination patterns) it employs recurrent neural architectures able to learn temporal dependencies in observed motion.
Analyzes the collective behavior of groups of objects to recognize coordination patterns, formation structures and collective threat behavior. It provides strategic-level assessment that individual target tracking cannot capture.
Analyzes atmospheric conditions, electromagnetic propagation and other factors affecting both sensor performance and actuation accuracy, generating probabilistic predictions of their evolution over short horizons.
Monitors and optimizes the allocation of energy resources, particularly for energy-intensive actuation subsystems, balancing operational capability, available reserves and thermal constraints.
Refines actuation parameters to maximize performance within physical and operational constraints, incorporating real-time feedback from the actuation subsystem to continuously adapt the control strategy.
The supervisory orchestrator is what distinguishes RAPTOR from a mere collection of independent modules. It does not just collect outputs: it actively governs their operation.
Continuously assesses the confidence and reliability of each module based on environmental conditions, sensor data quality and historical performance.
Enables or disables modules according to operational context, conserving computational resources when full analysis is not required.
Adjusts the balance between anticipation and reaction to maintain control stability as the operational tempo changes.
Reconciles contradictory recommendations from different modules through weighted arbitration.
The fusion engine collects the candidate commands produced by each active module and computes the final command as a weighted combination: modules assessed as more reliable under current conditions contribute proportionally more. Weights are normalized so they sum to one, ensuring the resulting command is a balanced integration of all contributions. They are not fixed parameters: they are continuously updated based on real-time reliability assessment.
The result is robust behavior even when individual modules go through a phase of degraded performance due to sensor limitations, adverse environmental conditions or cases outside their training distribution. Temporarily less reliable modules automatically receive lower influence over the final command.
02 (Human decision across all processes
RAPTOR is designed as a defensive and control system, not as an autonomous weapon system. Authority over critical decisions remains human, and the architecture is built to make this structurally true, not merely stated. Governance is not a policy written alongside the system: it is a layer of the architecture, with its own mechanisms and verifiable consequences for how the system behaves.
Critical decisions, particularly those involving the authorization of engagement, require explicit human approval before execution. The architecture supports configurable authorization thresholds that determine which decisions may be executed autonomously and which may not.
The operator maintains continuous situational awareness through the common operational picture synthesized in the global state: they can observe system performance, review individual module outputs, examine the decision fusion rationale and override an automated decision when warranted.
For every decision cycle the architecture records sensor inputs, module outputs, reliability weights, fusion calculations and the final command. This traceability supports post-event analysis, system validation and compliance with governance frameworks applicable to autonomous systems.
RAPTOR is a hardware-agnostic control framework. The actuation subsystem may incorporate different mechanisms according to the scenario: directed-energy emitters, beam steering systems with adaptive optics for atmospheric compensation, phased-array targeting systems, robotic actuators for platform and sensor orientation. Actuation feedback (outcomes, energy consumption, thermal measurements, mechanical state) returns into the global state and feeds the continuous adaptation of the control strategy.
RAPTOR did not emerge in isolation. It derives from the experience ONMAKE built with LINKALL™ (Cognitive Multi-AI Unified Interaction System, USPTO Provisional Patent Application No. 63/927,664), the architecture through which we first addressed the problem of making multiple heterogeneous artificial intelligences cooperate while maintaining a coherent shared state, defined interaction protocols and a reconstructable chain of accountability.
LINKALL addresses that problem on the cognitive and governance plane: coordinating multiple AI systems across organizational boundaries, with unified state management and accountability frameworks. RAPTOR carries those principles into the domain where decisions do not remain information but become physical effect in real time, adding what that leap demands: multispectral sensor fusion, dynamic reliability weighting, a predictive-reactive control loop and a governed actuation layer. It is the same underlying idea (no single intelligence decides alone, and coordination is itself a designed object) applied to the cyber-physical world.
The two architectures remain complementary and can operate together: the combination produces a system-of-systems approach in which multi-AI coordination operates within a structured governance envelope, with RAPTOR's operational control and LINKALL's accountability layer.
The orchestration and decision fusion engine stays the same. What changes are the connected sensor modules, the populated cyber-physical model, the operational constraints and the actuation systems. It is this separation between core and domain adaptation that makes the architecture scalable from a small installation to a large facility, and on to environments where the human operator cannot physically be present.
What changes from one domain to another
Radar, LiDAR, EO/IR, RF and acoustic in defense; 3D vision, vibration, thermal, gas and pressure in industry; optical and thermal imaging, radar, environmental sensors and telemetry in space.
Urban, rural, maritime, airspace and border contexts; factories, plants, warehouses and remote sites; orbit, planetary surface, vacuum, extreme temperatures and radiation.
Hostile threats and asymmetric attacks; equipment failure, safety incidents, downtime and quality; high latency, loss of link, component degradation.
Interception systems, electronic warfare and unmanned platforms; robotic arms, AGVs, valves and process controls; thrusters, robotic manipulators, instruments and payloads.
Protect lives and assets; operate safely with greater uptime and quality; complete the mission and return the data.
01 / 03
Detect. Classify. Predict. Respond. Protect.
The primary application the architecture was conceived for is the protection of territorial infrastructure, critical installations and civilian populations against dynamic aerial threats: unmanned aerial vehicles, coordinated swarms, missiles and other hostile objects. The system is conceived as a coordinated defensive response architecture.
In a fixed configuration it provides continuous surveillance and defensive capability around high-value assets: airports, power generation facilities, water treatment plants, data centers, government buildings and military installations. In urban defense configurations the architecture must operate in environments marked by dense structural clutter, restricted lines of sight and the presence of civilian populations.
For border surveillance and large-area monitoring, the distributed network configuration enables coverage of extended geographic regions through multiple coordinated nodes; satellite-assisted configurations may extend detection range by contributing orbital observation to the sensor fusion pipeline. Modularity and remote command interfaces also allow temporary deployments, for example to secure large public events or diplomatic gatherings.
The architecture is aimed at defense research agencies, government bodies and organizations and collective-security alliances, particularly in contexts most exposed to asymmetric threats from drones and missile systems.
02 / 03
From a single robotic cell to the large plant where humans cannot operate.
The same cognitive framework, applied to complex industrial control, generates a digital twin of the system: a live model consistent with the physics of the plant, its assets and its processes. RAPTOR orchestrates autonomous guided vehicles, robotic arms, quality inspection and predictive maintenance while maintaining a unified view over people, machines, processes and decisions.
Scale is the point: the same architecture governs an autonomous robotic cell, a connected production line, a coordinated fleet of AGVs and cobots, and a large facility with hazardous zones where human presence is limited or excluded. The stated goal is not to replace the operator, but to move them out of dangerous areas while leaving them in supervision.
Workplace safety is one of the most direct outcomes. RAPTOR makes it possible to move operators away from hazardous zones while leaving them in control: areas with explosive or toxic atmospheres, confined spaces, high-temperature or pressurized plants, robotic cells in motion, work at height. Where physical presence remains necessary, multi-sensor perception monitors proximity between people and machines in real time, recognizes anomalous behavior and risk conditions, and intervenes with slowdowns, interlocks and stops before a situation escalates, integrating with the safety instrumented systems already present in the plant.
Organizationally, the complete recording of every decision cycle produces traceability that serves prevention: it makes it possible to reconstruct the events preceding a near miss, to identify the recurring conditions that generate risk and to document the measures adopted. The same logic that governs actuation, with human decision present across all processes, applies here as a guarantee that automation does not take shortcuts at the expense of safety.
03 / 03
Autonomy where humans cannot be present.
This is the domain where constraints become extreme, and where the architecture therefore shows its rationale most clearly: high and intermittent communication latency, hostile environments with radiation, dust, thermal swings and vacuum, unmanned installations, the material impossibility of immediate human intervention. A command sent from the ground may arrive when the situation that motivated it has already changed. Here multi-AI orchestration is not a performance optimization, but the condition for the mission to continue at all.
The reversal compared with the other two domains is sharp. In defense and industry, human supervision is continuous and local autonomy serves to keep pace with events; in space, human supervision remains full over mission intent, objectives and constraints, but execution must be able to proceed even when the link is down. The architecture responds by moving the boundary, not removing it: the operator defines what the system may decide alone and within which limits, the system decides locally within that perimeter, and every autonomously taken decision remains recorded and reconstructable for later review. It is the same separation between generation, aggregation and authorization, applied on a different time scale.
Direct applications of the core are numerous. Orbital operations involve coordinating satellites and constellations, attitude management, navigation, communication relay and optimization of onboard energy resources. Planetary surface operations include coordinating multiple rovers, path planning over unmapped terrain, obstacle avoidance and robotic manipulation for sampling, assembly and repair. Continuous monitoring of platform health, with anomaly detection and component degradation estimation, makes it possible to intervene before a failure compromises the mission, in a context where physical maintenance is not an option.
There is also the reverse path, bringing space back into the other two domains: integrating orbital observation systems into the sensor fusion pipeline. Real-time satellite imagery, synthetic aperture radar data and space-based infrared detection can feed the shared world model, extending detection range well beyond the reach of ground sensors and providing early warning that no terrestrial installation can offer on its own. It is one of the architecture's explicit research directions, and one of the points where collaboration with space sector operators creates value in both directions.
ONMAKE S.R.L. is registered in ESA-STAR, the European Space Agency system, and takes part in ESA calls. The company also holds Horizon Europe PIC 879272506 for European Union research programmes.
The themes the architecture works on coincide with open questions in European space programmes: decision autonomy under high latency, orchestration of multiple artificial intelligence systems with structured human supervision, traceability and verifiability of autonomous decisions. ONMAKE is available to participate as a technology partner in research consortia and joint applications, contributing the architecture and its patent framework.
RAPTOR supports distributed deployment in which multiple autonomous nodes operate within a coordinated network. Each node maintains a local state derived from its available sensors and its own feedback parameters, and operates autonomously within its coverage area while contributing to a shared global state.
When a node loses its link to the network it continues to operate independently on its own sensor data and AI modules. When communication is restored the distributed state is reconciled, maintaining system coherence.
Nodes exchange target tracks, environmental assessments and system status information through multiple complementary communication channels, chosen so that the failure or disruption of one does not interrupt coordination. Satellite communication provides wide-area connectivity for coordination between geographically distant nodes, extending to cover large regions; the fiber backbone offers high-bandwidth, low-latency links where deployments are dense and infrastructure allows; the radio-frequency mesh network ensures resilient wireless communication, with redundant paths that maintain connectivity even when individual links are disrupted; all channels operate over encrypted data links, ensuring the integrity and confidentiality of the information exchanged.
This architecture makes it possible to respond in a coordinated way to threats crossing multiple coverage zones: a target tracked by one node stays tracked as it enters another node's area, without loss of continuity and without the decision having to travel back to a single centre, which would itself be a point of failure.
RAPTOR-MultiAI™ is a patented architecture under development. ONMAKE is currently evaluating partnership proposals with leading technology companies across Europe, the United States and Canada, and with research bodies and institutions interested in governed multi-AI cyber-physical control. The goal is to take the architecture from patented definition to field implementation, together with those who hold the complementary industrial expertise and application domains.
What ONMAKE brings
Forms of collaboration
What we look for in a partner
Manufacturers and integrators of phased-array radar, LiDAR, electro-optical and thermal infrared systems, acoustic and radio-frequency sensing. The quality of multispectral fusion depends on how deeply the individual sensors are understood: noise characteristics, degradation behavior, latencies and native formats. This is the layer where the expertise of those who build the hardware enters directly into the quality of the decision.
High-performance hardware for real-time inference, in edge, mobile and onboard configurations, under tight constraints of power, thermal dissipation and timing determinism. Making multiple AI modules coexist on the same platform with cycle guarantees is a systems engineering problem before it is a modeling one, and it requires those who design and optimize these platforms.
Targeting and beam steering systems, adaptive optics for atmospheric compensation, robotic platforms, manipulators and autonomous vehicles. This is where the unified command becomes physical movement: interfaces, response dynamics, mechanical constraints and functional safety define what the architecture can actually ask of actuation.
Industrial and institutional operators in the sector, defense research agencies and government organizations, for validating operational requirements, defining rules of engagement and structured experimentation paths. The value we look for here is knowledge of the real context of use, of regulatory constraints and of authorization procedures.
Machine builders, system integrators and end users with complex facilities, continuous processes or high-risk zones. We are particularly interested in contexts where human presence is already limited for safety reasons, because these are where multi-AI orchestration with remote supervision produces the most immediate and measurable benefit.
Satellite operators, space robotics companies and research bodies working on autonomy, high-latency missions and operations in unmanned environments. This is the domain that most severely tests the architecture's ability to decide locally and to account afterwards for the decisions taken.
Requests for in-depth technical documentation are handled confidentially, subject to assessment and a non-disclosure agreement.
Multi-Artificial-Intelligence Control Architecture for Real-Time Cyber-Physical Systems
USPTO Provisional Patent Application No. 63/999,217 · Patent Pending
Cognitive Multi-AI Unified Interaction System
USPTO Provisional Patent Application No. 63/927,664 · Patent Pending
Applicant and owner: ONMAKE S.R.L., innovative startup, Piazza Giuliano della Rovere 8, 00121 Rome, Italy. Inventor: Massimiliano Tulli, CEO and Technical Director. Horizon Europe PIC: 879272506.
The development lines along which the architecture is set to evolve, and where collaboration with technology and research partners matters most.
01
Extending multi-AI orchestration to networks of hundreds or thousands of coordinated nodes raises significant challenges in distributed state management, communication bandwidth and consensus algorithms. Research addresses efficient distributed fusion mechanisms able to maintain decision quality while reducing coordination overhead.
02
Sensor degradation and communication disruption are operating conditions, not exceptions. Directions include graceful degradation mechanisms, adversarial robustness against deliberate spoofing and jamming, physics-informed neural networks for environmental modeling and quantum sensing to increase detection sensitivity.
03
These remain among the most significant challenges for systems that can generate physical effects: formal verification methods for multi-AI decision pipelines, explainability mechanisms allowing operators to understand why a decision was made, international governance frameworks for autonomous defensive systems.
04
Real-time satellite imagery, synthetic aperture radar and space-based infrared detection integrated into the fusion pipeline, extending detection range and providing early warning complementary to ground-based sensors.
05
Efficiency is decisive for mobile or forward-deployed platforms with limited power budgets: inference efficiency, adaptive processing allocating computational resources according to urgency, energy-aware control strategies.
It is a proprietary control architecture, subject of a USPTO provisional patent application. It represents ONMAKE's technical and engineering framework for multi-AI cyber-physical control. The deployments illustrated on this page are conceptual visualizations of possible application scenarios and do not document an operational installation.
The decision chain is separated into three moments: AI modules generate the proposals, the fusion engine aggregates them, the orchestrator with human supervision authorizes them. Critical decisions require explicit approval from an authorized operator, with configurable thresholds, override capability and complete recording of every decision cycle.
Because a single model is at once a compromise across heterogeneous domains and a single point of failure. With multiple specialized modules, each optimized for its own task and dynamically weighted for reliability, the degradation of one module is compensated by the others and each domain can be updated without retraining the entire system.
The orchestration and decision fusion engine is the same. What changes are the connected sensor modules, the populated cyber-physical model, the operational constraints and the actuation systems: threats and topography in defense, digital twin and logistics in industry, telemetry and decision autonomy in space.
Phased-array radar, high-resolution LiDAR, electro-optical and thermal infrared cameras, acoustic sensors, radio-frequency detection systems and environmental monitoring instruments, along with standard industrial signals from PLC, SCADA and IIoT. The multispectral fusion subsystem is designed to integrate heterogeneous sources into a unified representation.
No. RAPTOR is designed primarily as a defensive system and as a general cyber-physical control framework. The patent covers the multi-AI orchestration architecture, not a specific hardware implementation. Authority over critical decisions remains human by construction of the architecture.
By writing to info@onmake.it. We assess proposals for joint research, licensing, co-development and experimentation. In-depth technical documentation is shared confidentially, subject to a non-disclosure agreement.
We are looking for industrial, technological and institutional partners to take the architecture from patented definition to field implementation, across the three application domains.
Partner Program • Research and Development • Europe, United States, Canada
Images and videos on this page are conceptual visualizations generated or processed with AI, subject to human review. AI Transparency