Erstiva
What is TIVA
TIVA (Temporal Integrity and Validation Architecture) is temporal execution governance for Physical AI under constrained compute. AI sees the world at T0; the robot acts at T1. TIVA determines whether that observation is still valid at actuation time.
Demo
Controlled lab replays on recorded workloads. Mechanism proof, not field ROI or safety certification.
Prithvi Bhat · Independent researcher · pre-incorporation
prithvi.bhat@erstiva.com
Joining on close
- Embedded software, AUTOSAR, ~19 years automotive (Bosch, ETAS class)
- Data and validation, ~7 years automotive ML, IIT Madras
Executive summary
Physical AI systems do not fail only when models are wrong. They fail when limited compute, competing tasks, and deadlines force the stack to keep acting on outdated perception while health checks still look nominal.
TIVA is temporal execution governance at the perception→action boundary: what may enter inference, and what may influence motion, with auditable traces as the substrate. On constrained edge hardware, that means knowing whether perception remains temporally valid for actuation, right now, under load, not only whether the model ran.
TIVA is not another inference framework. It governs execution timing and publishability when compute contention and deadlines collide.
Stage 1 today: live temporal observation and validation on edge traces; two-gate governance proven in governed replay (demos above). Next: the same contract on the live hot path. Stages 2 to 4: multi-stream, criticality-aware governance on shared edge compute, toward a predictive execution layer for Physical AI.
The constraint: Physical AI is not one model
Most AI stacks assume abundant compute and optimize individual models. Deployed robots face a different problem:
- Multiple cameras and sensors
- Planning, localization, mapping
- Safety monitoring and human interaction
- Often one GPU/NPU/CPU budget on the edge
The challenge is allocating finite compute so the system maximizes mission success while respecting safety constraints, especially when overloaded.
Under contention, the failure mode is often freshness: perception falls behind reality, but motion continues. The system appears healthy by traditional metrics, yet acts on stale state.
Target architecture
The full layer is an execution governor for Physical AI under constrained compute: criticality-aware scheduling across competing streams and tasks (Stages 2 to 4 below). It answers system-level questions, not model-level ones:
- Which model or stream should run next?
- Which inference can be delayed or skipped?
- Which perception task must not miss its effective deadline?
- When should a lower-fidelity path be used?
- How should compute be redistributed after a fault or spike?
- What happens when the system is overloaded, gracefully, not catastrophically?
This is runtime governance, not a single scheduler knob: an execution layer Physical AI stacks could depend on, not a point solution for one workload.
Stage 1 wedge
The narrow integration model: two governance checkpoints on a single perception stream (capture → infer → emit), with auditable traces. Perception models stay unchanged. The same gate semantics extend as the governor takes on multi-stream scope.
| Checkpoint | Question | Policy |
|---|---|---|
| Before inference | Should this observation enter inference? | Admit / skip |
| Before actuation | Should this output drive planners and actuators? | Forward / hold / withhold |
Stage 1 today
| Layer | Status |
|---|---|
| Temporal observation contract (JSONL) | Live on Pi edge and sim workloads |
| KPI and classification | Validation pipeline on canonical traces |
| Two-gate governance | Proven in replay (videos above) |
| Edge ingress (Pi) | Live skip-to-latest frame ingress + per-frame timing logs (not full two-gate governor on hot path) |
| Edge / ROS governor | Next: C++ sidecar, wrapper |
| Sim reference governor (Python) | Reference implementation; calibration refinement ongoing |
Observability and runtime policy
Stage 1 delivers two layers on the same contract:
| Layer | What it gives you | Status |
|---|---|---|
| Observability | See timing degradation in audit traces while dashboards still look healthy | Live |
| Runtime policy | Decide what may still drive motion: proceed, wait on last valid output, or skip work that would not be safe to act on | Proven in replay; live deployment next |
What changes in practice
- Stale outputs do not propagate. Under identical stress in our demos, governance prevents stale perception from driving downstream action.
- Problems become visible before the floor does. Timing failure shows up in traces while health checks stay green.
- Less wasted effort when validity is gone. Skip inference and publication that would not be safe to act on anyway.
| What teams care about | Without governance | With TIVA (replay-proven today) |
|---|---|---|
| Decisions under stress | Act on an old sensor picture | Wait or withhold until output is temporally valid |
| Visibility | Intermittent failures, unclear logs | Auditable record of timing and policy each cycle |
Why this category now
Physical AI is moving from demos to always-on deployment. Industry context (third-party estimates; not TIVA performance claims):
| Theme | Industry context |
|---|---|
| Timing gap | Deployed robot stacks often see tens to hundreds of milliseconds between sensing and actuation; acting on stale state is a documented failure mode (observation–execution gap). |
| Cost of failure | Unplanned warehouse and industrial downtime is widely cited at roughly $10K–$100K+ per hour in throughput impact, depending on facility scale (often higher once labor and SLA penalties are included). |
| Market tailwind | Physical AI robotics and edge inference for robots are forecast in the tens of billions of dollars this decade as fleets move to 24/7 operation (analyst definitions and figures vary). |
Sources (external): industrial observation–execution gap (research); warehouse downtime cost commentary; market sizing from industry analyst reports (e.g. Physical AI / edge robotics; estimates vary). TIVA does not claim customer ROI.
Evolution roadmap
| Stage | Scope | Status |
|---|---|---|
| 1a | Observation contract, KPI/classification, Pi edge traces | Live |
| 1b | Two-gate governance on single perception stream | Replay-proven |
| 1c | Live edge / ROS governor on hot path | Next |
| 2 | Multiple inference streams; shared GPU/NPU; criticality-aware execution | Design-partner input |
| 3 | Fleet-wide governance; compute allocation across edge devices | Long-term research |
| 4 | Predictive governor; proactive reconfiguration under anticipated overload | Long-term research |
Differentiation
| Approach | What it optimizes | Gap under overload |
|---|---|---|
| Faster inference | Throughput | Stale output can still drive motion |
| Timestamps / QoS | Age or delivery | No actuation policy |
| Watchdogs | Process liveness | Silent staleness while healthy |
| TIVA | Validity at decision time | Govern before infer and before actuation; audit trail |
Positioning: execution governance for Physical AI, not another foundation model or robot SKU.
For robotics teams
We are looking to speak with teams that have encountered timing-related perception failures under load. Short technical calls to understand the workload; recorded-trace evaluations later by mutual agreement. No hot-path install required to start.
Get in touch
If useful, a 20-minute walkthrough of the demos above, or send per-frame timestamps from a loaded perception run for a temporal validity report.
Research software · early stage · pre-incorporation