With a completely autonomous drone in contested space (presumably with EW around), there's no way for a pilot to tell the drone "fly a little to the left to see what's behind that tree." Each drone has very specific use cases.
Litter your trenches in inflatable mannequins (anti-CV), put all your soldiers in ghillie suits (anti-CV), have cheap fireworks ready to spread chaff (anti-radar) and flares (anti-IR).
At that point, isn't it easier to just shell those civilians if they are in drone range, or cluster/fire bomb them if you need to fly in an aircraft to deliver the drones anyway?
Terrorism by non-state actors is a danger, of course, but guys with AKs and pipe bombs storming a football stadium seems easier to pull off and yet hasn't happend so far anyway.
Even then, if they just put a bullet into anything that has the approximate optical & heat signature of a human, it'll work fine. Who cares if you blow up a few inflatable mannequins and flares if you also get all the soldiers?
* A Kalman filter is an algorithm, not a magical wand. How is that algorithm implemented? What are the parameters? How are they tuned? How is the state, and uncertainty thereof, modeled? How accurate is that model in the field? Details and implementations matter. Finding answers that work reliably in the field, even for a limited set of circumstances, takes huge amounts of time, money and talent, and involves a continuous process of trial and error.
* Drones have a limited payload capacity, which means a limited amount of ammo to burn on false positives, and a limited amount of smarts and sensors with which to process their environment.
* Many attacks rely on the element of surprise to catch the enemy unaware, or leave them with little time to plan - shooting fake targets alerts others to your presence and can quickly give away your position, providing time to take cover and/or stage a counterattack.
* The people developing the smarts for these drones are a limited resource that need to be found, hired, and paid, and they have to play a cat-and-mouse game to maintain the robustness of the targeting system.
* Asymmetric warfare is a time-honored guerilla favorite. It doesn't matter how fancy and sophisticated your drone's targeting system is if rendering it useless is cheaper, and wasting ammo on non-targets can very much tip the scales here.
And more importantly, that's what I mean with arms race. Now the mannequins in the trenches get a little heater element to keep them at body temperature, and they get internal water bladders with the appropriate radar cross section, ect. Easily doable today, and orders of magnitude cheaper than a sensor fusion drone.
Add counter drones and point defense cannons, and the attack drones need rocket motors for final approach, which makes CV another order of magnitude more difficult, ect
When the launcher and the drone connect they make up a completely random key. It is known only to the launcher and the drone. The drone will self destruct if it receives said key. The enemy could jam the destruct but they couldn't trigger it. Note that no encryption is even needed.
One time pads are inherently unbreakable crypto other than by compromising the pad. And in this case the secret is known only to the drone and controller.
You even have different types of drones providing different function. A mama drone carrying smaller drones to the place of operation for example.
"But they have to test to guarantee safety"
Nobody cares, there's a reason Ukraine is using cheap consumer/commercial drones, because they're effective as hell, and you get much more bang for buck without most of your money going into the back pockets of defense company executives.
If national defense is sooooo important, why aren't defense companies publicly owned?