Inspiration

In the film Twisters, the storm-chasers build TINA — a system meant not just to watch a tornado but to understand and act on it in real time. That fictional ambition — turn raw atmospheric chaos into an actionable, explainable decision — is the north star we borrowed the name from. TINA-X is our attempt at the real, sober version: a symbolic reasoning system that predicts not the hazard itself, but the collapse of the systems humans depend on to survive it.

The other half of the inspiration came from a simple, humbling observation about the sensors such a system would need bearing in mind the catasrophe that hit Kumamoto. A housefly — with about a million neurons — out-flies, out-navigates, and out-survives our most expensive drones. It stabilizes in turbulence, dodges obstacles, and does it on microwatts. That gap between biological elegance and robotic brittleness became the guiding question: what if the eyes and hands of TINA-X were robots that think like colonies of insects, not like fleets of dumb machines waiting on a central server?

So TINA-X has two halves that meet in one idea — symbolic reasoning you can trust and verify:

  • a cascade-reasoning brain that deduces systemic failure from infrastructure dependencies, and
  • a decentralized bio-inspired swarm (our robotics layer) that is both its mobile sensor fleet and a proving ground for the same verifiable-decision machinery.

What it does

TINA-X predicts the domino, not just the first tile. Where most disaster tools forecast the hazard (the wind, the quake), TINA-X ingests infrastructure dependencies into a MeTTa Atomspace and forward-chains symbolic rules to deduce the cascading failures a hazard triggers — including compound "black swan" combinations it has never seen, where deep learning fails. Every alert is explainable, traceable to the exact rule and facts that produced it.

Underneath it, the swarm layer is a decentralized fleet of precision-agriculture robots that reason like a colony — fast reflexes in the individual, slow deliberation shared across the group — and can prove what they decided. It does real economic work today (weed treatment) and doubles as TINA-X's in-situ sensor network.

Concretely, a swarm agent:

  • Flies itself. A hard real-time reflex loop holds attitude on all three axes at \(500\,\text{Hz}\), in under \(13\,\text{ms}\) — the insect "spine," with no cloud and no central controller in the loop.
  • Reasons about what it's doing, and checks itself. A slow symbolic brain proposes each setpoint and runs it through a fail-closed verification gate that catches five distinct classes of agent "hallucination" before anything reaches the flight controller. Doubt is never treated as approval.
  • Does something economically real. It looks at a crop patch, classifies weed vs. crop vs. soil, and applies a symbolic treat/don't-treat rule that sprays only confident weed detections — cutting pesticide use \(\sim 70\%\) while the decision stays explainable (accuracy \(\sim 0.88\), weed \(\text{F1} \approx 0.85\)).
  • Coordinates as a colony, not a fleet. Agents talk only to their neighbors. A hierarchy self-organizes at runtime, the "brain" role is re-elected in \(O(\text{diameter})\) time if a leader dies, and field coverage spreads through stigmergy — marks left in the environment — with no central scheduler. A \(400\)-agent swarm still converges to a single leader.
  • Nowcasts hazards honestly. A weather stack fuses an ensemble forecast, in-situ swarm readings, thermodynamic (pbit) denoising, and symbolic calibration — reported in Brier / reliability / ETS, never a headline "accuracy" number.
  • Proves its safety-critical decisions. A zk-SNARK attests a "safe-to-fly" decision while keeping the inputs private (prove \(161\,\text{ms}\), verify \(3.5\,\text{ms}\)).

The through-line across both halves: every real-time decision cites a measured number, and every decision the system makes, it can prove.

How we built it

Everything is unified by one commitment: symbolic reasoning (MeTTa/Hyperon) that is explainable and verifiable, with the safety-critical logic kept in Rust.

The cascade-reasoning brain (TINA-X core). Infrastructure dependencies live as facts in a MeTTa Atomspace; forward-chaining rules deduce catastrophic cascades from compound events — combinations never seen in training, where a pattern-matching model would miss them. Every alert is traceable to the rule and facts that produced it. This is the "predict the collapse, not the tremor" engine.

The swarm layer is itself a two-rate brain, mirroring the fly's split between fast reflexes and slow cognition:

  • Fast loop (Rust, \(< 13\,\text{ms}\)): a 3-axis delayed-PD attitude stabilizer running at \(500\,\text{Hz}\) — the "spine." It never calls the symbolic layer, preserving its hard real-time budget.
  • Slow loop (MeTTa/Hyperon symbolic brain): proposes setpoints, then verifies every decision against five hallucination types (reasoning, execution, perception, memorization, communication) through a fail-closed gate — an unrecognized answer is never treated as approval.

On top of this we built:

  • Precision-ag perception — a weed/pest classifier fused with a symbolic treat/don't-treat rule that sprays only confident detections, yielding \(\sim 70\%\) pesticide reduction with an accuracy of \(\sim 0.88\) and weed \(\text{F1} \approx 0.85\).
  • A headless self-organizing swarm (SoNS) — self-organizing hierarchy via distributed max-consensus, stigmergic coverage, and an interchangeable "brain" that is re-elected in \(O(\text{diameter})\) time when a leader dies. A \(400\)-agent swarm still converges to one leader.
  • A weather-nowcasting stack — the honest counterpart to the Twisters fantasy: ensemble → swarm-sensor fusion → thermodynamic (Extropic-style pbit Gibbs) denoising → symbolic calibration, improving reliability at every stage.
  • Verifiable decisions — a zk-SNARK (arkworks Groth16) proving a "safe-to-fly" decision with private inputs (prove \(161\,\text{ms}\), verify \(3.5\,\text{ms}\)).

Recently we enriched the swarm's brain with bee + ant collective intelligence, backed by an adversarially fact-checked deep-research pass: quorum-threshold commitment and cross-inhibition in the slow MeTTa brain (so the swarm commits to a shared target only past a risk-tuned quorum, and breaks deadlock between equal options with directed stop-signals), and pheromone evaporation — "useful forgetting" — added to the swarm's stigmergy so coverage self-heals and re-flows to stale gaps.

Challenges we ran into

  • No linkable Hyperon. MeTTa isn't on crates.io and has no libhyperon, so we couldn't call it natively from Rust. We built a trait seam (SymbolicBrain) with a subprocess bridge and a fake test double — keeping the safety-critical gate in Rust while the reasoning rules live in .metta files.
  • An \(O(n)\) query trap. Direct Atomspace queries scaled at \(\sim 2\,\text{s}\) @ 100k atoms, \(\sim 23\,\text{s}\) @ 1M. We partitioned into a tiny hot working-space, flattening \(p_{99}\) query latency from a \(92\times\) blowup to essentially flat.
  • MeTTa's non-obvious gotchas. Overlapping equality clauses silently produce non-determinism; a single long-lived MeTTa() space accumulates rules and hangs super-linearly; and data terms with function-like sub-wrappers get evaluated away before your accessors can match them. Each cost real debugging time and became a hard-won documented lesson.
  • Honesty under pressure. The hardest challenge wasn't technical — it was resisting the inflated claim. Every real-time decision now cites a measured number, and every "wow" metric is one we can defend.

One great bot before a fleet — that was the discipline. Everything runs, everything is measured, and every decision the swarm makes, it can prove.

Accomplishments that we're proud of

  • A reflex loop that meets the fly's spec. Three-axis attitude stabilization at \(500\,\text{Hz}\), measured under the \(13\,\text{ms}\) halteres budget — with the symbolic layer provably kept out of the hot path.
  • A verification moat that actually catches faults. The fail-closed gate rejects an injected fault for each of the five hallucination types, in Rust, before it can act — proven by fault-injection tests, not hoped for.
  • A pesticide-reduction story we can defend. \(\sim 70\%\) less spraying with the symbolic gate able only ever to spray less than raw detection — reduction by construction, not by tuning.
  • A swarm that heals itself. Kill the brain and a survivor is re-elected in \(O(\text{diameter})\); coverage survives partial loss. Verified by emergent-behavior tests, and it scales to \(400\) agents converging to one leader.
  • Biology turned into working code, honestly. We took bee quorum + cross-inhibition and ant pheromone-decay from an adversarially fact-checked research pass (\(105\) agents, \(24/25\) claims independently verified) straight into runnable rules — and we shipped only the mechanisms that survived verification, deferring the ones that didn't.
  • Cryptographically verifiable decisions. A working zk-SNARK proving a safe-to-fly decision with private inputs — a foundation for on-chain, auditable autonomy.
  • A refusal to ship a number we can't back. No "99% accuracy" claim anywhere; calibrated skill instead. That restraint is, we think, the most valuable thing we built.

What we learned

The deepest lesson was intellectual honesty as an engineering discipline. Twisters gave us the dream of TINA; reality gave us the fine print. Early on we were tempted by a "99% weather-prediction accuracy" headline — until we discovered that the one \(0.99\) figure in the literature is pixel-wise accuracy on one city, one variable, whose companion skill score was only \(\text{ETS} \approx 0.18\). Severe weather is rare, so a model that always predicts "no hazard" scores \(\sim 99\%\) accuracy while being useless. We learned to report calibrated skill instead — Brier score, reliability, and the Equitable Threat Score:

$$\text{ETS} = \frac{H - H_{\text{random}}}{H + M + F - H_{\text{random}}}, \qquad H_{\text{random}} = \frac{(H+M)(H+F)}{N}$$

which is not fooled by class imbalance. That principle — never ship a number you can't defend — reshaped the whole project.

We also learned how biology formalizes into math. Honeybee nest-site selection is quorum-based evidence accumulation with cross-inhibitory stop-signals; ant coordination is stigmergy with pheromone that must decay to stay adaptive. Ant Colony Optimization gave us the exact update rule:

$$\tau_{ij} \leftarrow (1-\rho)\,\tau_{ij} + \Delta\tau_{ij}, \qquad \rho \in (0,1]$$

and taught us a subtle bug hiding in plain sight: our coverage field only ever incremented — the broken \(\rho = 0\) case where trails never fade and the swarm can never re-adapt. Adding evaporation turned a one-shot coverage sweep into a living, self-healing field.

Finally, we learned to respect the tooling: MeTTa/Hyperon is powerful but pre-alpha, and the honest move was to benchmark it ourselves before designing on top of it, then keep the safety-critical logic in Rust.

What's next for TINA-X

The cascade-reasoning core is where TINA-X earns its name — and the 2016 Kumamoto disaster is our motivating case. A foreshock, then a larger mainshock, didn't just shake buildings — they severed the systems: the Aso Ohashi bridge was destroyed by a massive landslide, roads and rail were cut, and power, water, and gas went out for hundreds of thousands of people. Critical facilities that "looked fine" in isolation — a hospital with a backup generator, a shelter with stored supplies — were quietly stranded, because the roads their diesel and water depended on were gone. A naive per-asset model sees "generator present, hospital OK." TINA-X follows the chain: earthquake → landslide destroys the Aso bridge → resupply road severed → hospital's backup generator can't be refueled → hospital fails — and flags it before the tank runs dry. That is the difference between predicting the tremor and predicting the collapse.

  • Real regions, real feeds — starting with Kumamoto. Ingest OpenStreetMap infrastructure for the Kumamoto region and replay the 2016 cascade, then wire live API feeds (USGS/NOAA/DSCOVR) so the reasoning runs on the actual world. If TINA-X can reconstruct the Aso-bridge-to-hospital chain from the dependency graph alone, it earns the right to warn about the next one.
  • New failure domains. Supply-chain and space-weather modules on top of the same dependency-graph engine.
  • ZK-attested alerts. Carry our verifiable-decision machinery into the cascade brain so a collapse alert ships with a proof it came from the signed ruleset — auditable early warning, not a black box.
  • The swarm as a live sensor. Feed the swarm's in-situ observations into TINA-X as a mobile ground-truth layer for the fragility model — closing the loop between the two halves.

What's next for the swarm layer

  • Close the loop on physical reality. Everything today is proven headless or in a control model; next is the Unity physics plant (optic-flow avoidance, collision tolerance) and a first cheap physical node — confronting insect-scale power head-on.
  • Wire the colony intelligence end-to-end. The bee quorum + cross-inhibition rules are verified in MeTTa; next we wire them into the Rust supervisor and emit the directed stop-signal over the swarm's neighbor-local gossip, then verify the whole best-of-N target selection in the swarm.
  • Settle decisions on-chain. Take the working zk-SNARK from "safe-to-fly" to "this decision came from the signed MeTTa ruleset," and attach proofs to signed telemetry on a testnet.
  • Push calibrated nowcasting toward real data. Swap the synthetic testbed for real WoFS/radar behind the same interfaces, and validate the thermodynamic-denoise + symbolic-calibration stack across regions and seasons.

Built With

Share this project:

Updates

Submission history