This project proposes a new security layer for AI-enabled geospatial digital twins to prevent sensitive information from being exposed through natural-language queries. As more infrastructure systems adopt chatbot-style interfaces powered by large language models (LLMs), traditional GIS access controls are no longer sufficient—users with valid credentials can unintentionally or maliciously reconstruct restricted infrastructure details through cleverly sequenced prompts. To address this risk, the project develops a locally deployed “AI guardian” that evaluates each query before it reaches the database, classifying it as allow, constrain, or deny based on data sensitivity, spatial resolution, and cumulative session behavior. The system is tested using a realistic geospatial database with public, internal, and restricted layers, and evaluated against thousands of single-turn and multi-turn prompts to measure its ability to detect prompt injection, scope escalation, and reconstruction attacks. The result will be a lightweight, deployable security framework that helps industry partners build more trustworthy, compliant, and mission-ready AI-powered digital twin systems.
