Rehabilitation treadmill active safety protection system based on multi-modal brain-machine visual perception

By using multimodal brain-computer visual perception technology, a full-process active safety protection system was constructed, which solved the problems of low data timing alignment accuracy and rigid safety decision-making on the rehabilitation treadmill. It achieved graded and precise protection and continuous optimization, improving the safety and comfort of rehabilitation training.

CN122266699APending Publication Date: 2026-06-23JIANGSU VESP TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
JIANGSU VESP TECH CO LTD
Filing Date
2026-05-18
Publication Date
2026-06-23

AI Technical Summary

Technical Problem

Existing rehabilitation treadmill safety protection systems suffer from low data timing alignment accuracy, are unable to adapt to individual differences and gait changes, resulting in high rates of false alarms and missed risk reports, rigid safety decisions, lack of tiered protection, and a high risk of secondary injuries. Furthermore, their thresholds are fixed and cannot be dynamically adjusted.

Method used

Employing multimodal brain-computer visual perception technology, the system generates a raw multimodal dataset through a quality control unit, performs dynamic temporal alignment through a temporal synchronization unit, generates a weighted five-dimensional security state vector through a security intent unit, makes hierarchical protection decisions through a security decision unit, and performs closed-loop effect verification and anomaly escalation through an execution iteration unit, thus forming a full-process proactive security protection system.

Benefits of technology

It enables early risk warning, tiered and precise protection, and continuous self-optimization, significantly improving the safety and comfort of rehabilitation training, and is suitable for medical institutions at all levels and home rehabilitation scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122266699A_ABST
    Figure CN122266699A_ABST
Patent Text Reader

Abstract

The present application belongs to the field of medical rehabilitation equipment and intelligent safety protection technology, and discloses a rehabilitation treadmill active safety protection system based on multi-modal brain-computer visual perception, which comprises: collecting original multi-modal data, performing hierarchical quality marking, and generating an original multi-modal data set; real-time detection of twin physiological event anchors, dynamic time alignment to generate a multi-modal synchronous data set; extraction of multi-dimensional safety features, generation of a weighted five-dimensional safety state vector through environmental factor weight modulation, generation of a non-constrained intention suggestion package through synchronous intention suggestion generation; intention legality and safety verification, generation of legal execution instructions, and then multi-state hierarchical protection decision, formation of standardized execution control instructions; execution of hierarchical protection actions, phased closed-loop effect verification and abnormal execution safety upgrade, acquisition of full-process operation data and intervention events, reverse optimization update combined with therapist feedback, and closed-loop iteration.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of medical rehabilitation equipment and intelligent safety protection technology, and more specifically, to an active safety protection system for a rehabilitation treadmill based on multimodal brain-computer visual perception. Background Technology

[0002] With the rising incidence of neurological diseases such as stroke, the clinical demand for rehabilitation treadmills, as core equipment for lower limb motor function rehabilitation, continues to grow. However, during rehabilitation training, traditional passive protection relies on manual monitoring, resulting in delayed responses. Existing intelligent solutions are mostly based on single or simple multimodal data, making it difficult to achieve a balance between training safety and rehabilitation effectiveness.

[0003] Existing safety protection solutions for rehabilitation treadmills still have some shortcomings. The timing alignment accuracy of multimodal data is low, and fixed delay compensation cannot adapt to individual differences and gait changes, resulting in a high rate of false alarms and missed risk detections. Furthermore, safety decisions are rigid, only achieving binary control, lacking graded protection, which can easily cause secondary injuries, and the fixed thresholds cannot be dynamically adjusted. Summary of the Invention

[0004] To overcome the aforementioned deficiencies of the prior art and to achieve the above objectives, the present invention provides the following technical solution: an active safety protection system for a rehabilitation treadmill based on multimodal brain-computer visual perception, comprising: The data acquisition and quality control unit collects raw multimodal data, performs hierarchical quality labeling, binds it to the corresponding data throughout the entire data chain, and generates the raw multimodal dataset. Timing synchronization unit: Based on the original multimodal dataset, it detects dual physiological event anchors in real time, and then performs global timing calibration and timing deviation classification to dynamically align multimodal data and generate a multimodal synchronization dataset. Security Intent Unit: Based on a multimodal synchronous dataset, extract multi-dimensional security features and compare them with preset anomaly detection thresholds to generate basic state flags. Through environmental factor weight modulation, generate a weighted five-dimensional security state vector. Simultaneously, generate non-constrained intent suggestions and generate intent suggestion packages through environmental factor intent interception verification. Security Decision Unit: Based on a weighted five-dimensional security state vector and intent suggestion package, it verifies the legality and security of intents through security interlock gating and generates legal execution instructions; then, based on pre-set solidified priorities, it makes multi-state hierarchical protection decisions and generates corresponding protection execution instructions, forming standardized execution control instructions; Execution Iteration Unit: Based on standardized execution control instructions, it executes graded protection actions, conducts phased closed-loop effect verification and abnormal execution safety upgrades, obtains full-process operation data and intervention events, and optimizes abnormal detection thresholds in combination with therapist feedback to form a closed-loop iteration.

[0005] Furthermore, the method for generating the original multimodal dataset includes: Based on a global synchronization clock, the system synchronously collects the current patient's multimodal raw data and adds a globally unified timestamp to each sampled data point. For each data point with a timestamp, a three-level data quality assessment is performed and the quality level is marked. The quality mark is then bound to the corresponding data point as metadata and transmitted throughout the entire data chain. Then, the original multimodal data with timestamps and quality labels are integrated in chronological order to generate the original multimodal dataset.

[0006] Furthermore, the method for real-time detection of dual physiological event anchor points includes: Based on the original multimodal dataset, inherent delay compensation was performed on the detection times of the three independent domains: EEG domain, visual domain, and stress domain, to obtain the true occurrence time of the anchor event; The main anchor point is based on the pressure domain, and the auxiliary anchor point is based on the visual domain. They are detected by weighted voting logic to obtain the corresponding anchor points for the two physiological events. Invalid anchor points are eliminated by dynamic time window matching and gait cycle rationality verification to generate a set of actual occurrence times of the two anchor points.

[0007] Furthermore, the method for generating the multimodal synchronization dataset includes: Based on the set of actual occurrence times of dual anchor points, the main anchor point calibration queue and the auxiliary anchor point calibration queue are initialized. The main anchor point is based on the actual time of the pressure domain, and the auxiliary anchor point is based on the actual time of the visual domain. The time difference between the EEG domain, the pressure domain and the visual domain is calculated and pushed into the corresponding calibration queue. Once both calibration queues are full, the weighted median calibration parameters are calculated independently by anchor point according to the time-series calibration rules. Then, global time-series calibration parameters are generated through deviation rationality verification and dynamic fusion, and time-series deviation classification and anomaly handling are performed. Furthermore, based on the latest global time-series calibration parameters, taking the time period between two adjacent master anchor points as a gait cycle, linear interpolation is used to perform continuous time axis translation and alignment throughout the gait cycle, thereby dynamically aligning multimodal data and generating a time-aligned multimodal synchronization dataset.

[0008] Furthermore, the method for generating the weighted security state vector includes: Preset time slices are used to extract the four-dimensional security features of neural, visual, physical and artifact dimensions of the corresponding time slices one by one based on the multimodal synchronous dataset. The corresponding basic state flag bits are generated by comparing with the corresponding preset anomaly detection thresholds and default decision weights are added. Based on the current equipment operating environment and patient training status, environmental pre-modulation is performed with the highest priority, the basic status flag is corrected and the default decision weights of each dimension are modulated. Then, the four-dimensional basic state flags and modulated decision weights are weighted and calculated, and an independent environmental dimension flag is added to generate a weighted five-dimensional security state vector, and security event markers are generated simultaneously.

[0009] Furthermore, the method for generating the intent suggestion package includes: Based on a multimodal synchronous dataset, only neural dimension intention features and artifact dimension physiological features are extracted to generate unconstrained deceleration or maintenance intention suggestions; Based on the environmental dimension flags, the intent suggestions are subjected to environmental factor intent interception and verification. The intent suggestions that pass the verification are then encapsulated to generate an intent suggestion package.

[0010] Furthermore, the method for generating valid execution instructions includes: Based on a weighted five-dimensional security state vector and intent suggestion package, a two-level security interlock gating verification is performed: First, the legality of the intent suggestion packet is verified. Then, combined with the weighted five-dimensional security state vector, the intent that passes the legality verification is finally verified for security, generating a legal execution instruction or a security rejection signal. Simultaneously, based on the security event markers, corresponding linked security event operations are performed.

[0011] Furthermore, the method for forming standardized execution control instructions includes: Based on the legal execution instructions, security rejection signals and security event markers, the system uses multi-state hierarchical protection decision logic to make hierarchical protection decisions for the corresponding security state according to the preset solidified priorities and the current security state, and generates corresponding protection execution instructions. All protection execution commands are subjected to parameter hard-limiting verification, and after passing the verification, they are encapsulated into standardized execution control commands.

[0012] Furthermore, the methods for performing phased closed-loop effect verification and abnormal execution security upgrades include: Based on standardized execution control commands, the corresponding execution mechanism is driven to perform graded protection actions; the entire execution process is verified in stages to achieve closed-loop effectiveness. When any stage verification fails, it is judged as abnormal execution, triggering a step-by-step security upgrade mechanism to execute higher-level protection actions and provide feedback on the execution status.

[0013] Furthermore, the method of optimizing the abnormality detection threshold by incorporating therapist feedback includes: After the graded protection actions are completed, the entire process operation data and traceable data of therapist intervention are obtained. By analyzing the correlation between intervention events, deviations in the safety decision-making logic are identified, and the anomaly detection threshold is adaptively optimized. Then, after therapist review and verification and gray-scale release, reverse updates are performed to form a closed-loop iterative proactive safety protection mechanism.

[0014] The technical effects and advantages of the active safety protection system for rehabilitation treadmills based on multimodal brain-computer visual perception in this invention are as follows: This invention focuses on the clinical safety pain points of rehabilitation treadmills, constructs a full-process proactive safety protection system, realizes early risk warning, graded and precise protection, and continuous self-optimization, and significantly improves the safety and comfort of rehabilitation training; First, multi-sensor fusion is used to collect multi-dimensional data, and combined with three-level quality control and end-to-end binding, data reliability is improved from the source; Secondly, by employing dual physiological event anchor point detection technology, combined with weighted median calibration and gait cycle interpolation, millisecond-level dynamic temporal alignment is achieved, solving the adaptability problem of traditional fixed delay compensation. Then, a five-dimensional safety state vector is constructed, and a three-level hierarchical protection is achieved by relying on an independent safety core and two-level interlocking gating, which avoids the risk of secondary damage from traditional binary control and improves training smoothness. Next, a primary and backup dual-control hot standby architecture and phased closed-loop verification are adopted. If the execution fails, a step-by-step safety upgrade is automatically triggered to ensure patient safety in abnormal situations and that a single point of failure does not affect operation. Finally, through a fully encrypted and traceable record and therapist feedback mechanism, the protection rules are continuously iterated and optimized to adapt to different patients and training stages. This invention integrates hardware-level security with software-level intelligent decision-making, enabling a shift from passive protection to proactive early warning. It is applicable to medical institutions at all levels and home rehabilitation scenarios, significantly improving the safety, reliability, and clinical applicability of rehabilitation treadmills. Attached Figure Description

[0015] Figure 1 This is a schematic diagram of the active safety protection system for a rehabilitation treadmill based on multimodal brain-computer visual perception according to the present invention. Figure 2 This is a schematic diagram of the dual-anchor timing calibration process in the active safety protection system for rehabilitation treadmills based on multimodal brain-computer visual perception of the present invention. Figure 3 This is a schematic diagram of the active safety protection method for rehabilitation treadmills based on multimodal brain-computer visual perception according to the present invention. Detailed Implementation

[0016] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention. Example 1

[0017] Please see Figure 1 and Figure 2 As shown in this embodiment, the active safety protection system for a rehabilitation treadmill based on multimodal brain-computer visual perception includes: The data acquisition and quality control unit collects raw multimodal data, performs hierarchical quality labeling, binds it to the corresponding data throughout the entire data chain, and generates the raw multimodal dataset. Timing synchronization unit: Based on the original multimodal dataset, it detects dual physiological event anchors in real time, and then performs global timing calibration and timing deviation classification to dynamically align multimodal data and generate a multimodal synchronization dataset. Security Intent Unit: Based on a multimodal synchronous dataset, extract multi-dimensional security features and compare them with preset anomaly detection thresholds to generate basic state flags. Through environmental factor weight modulation, generate a weighted five-dimensional security state vector. Simultaneously, generate non-constrained intent suggestions and generate intent suggestion packages through environmental factor intent interception verification. Security Decision Unit: Based on a weighted five-dimensional security state vector and intent suggestion package, it verifies the legality and security of intents through security interlock gating and generates legal execution instructions; then, based on pre-set solidified priorities, it makes multi-state hierarchical protection decisions and generates corresponding protection execution instructions, forming standardized execution control instructions; Execution Iteration Unit: Based on standardized execution control instructions, it executes graded protection actions, conducts phased closed-loop effect verification and abnormal execution safety upgrades, obtains full-process operation data and intervention events, and optimizes abnormal detection thresholds in combination with therapist feedback to form a closed-loop iteration.

[0018] Methods for generating raw multimodal datasets include: All acquisition devices are connected to the same global master clock through a precision timing synchronization bus, thereby achieving hardware-level clock synchronization and ensuring that the time base of all devices is completely consistent. Based on a global synchronization clock, the system continuously collects multimodal raw data of the current patient, including neurophysiological data, head movement data, electrode contact status data, cardiovascular physiological data, visual posture data, plantar pressure data, and equipment operation data. The neurophysiological data was collected by a 32-channel multi-physics field integrated electrode array, covering key brain regions such as the prefrontal cortex, temporal lobe, parietal lobe, and central region, and included electrical activity signals of the cerebral cortex. Head motion data is collected by a triaxial accelerometer built into the electrode array, which includes real-time acceleration information of the patient's head in the X, Y, and Z directions; Electrode contact status data is collected by the contact force sensor and impedance detection component built into the electrode array, including the contact pressure value and contact impedance value between each electrode and the scalp. Cardiovascular physiological data were acquired by a built-in near-infrared pulse wave sensor, including pulse wave signals from the patient's superficial temporal artery; Visual pose data was acquired by dual RGB cameras (front and rear) and one NIR camera, including color images of the patient's full-body pose and near-infrared images of the face; The plantar pressure data is collected by a high-density pressure sensor array under the running belt, including real-time pressure distribution values ​​of the patient's feet at different positions on the running belt; The equipment operation data is collected by the treadmill motor encoder, safety harness tension sensor, and infrared boundary sensor, including the real-time speed of the treadmill motor, the tension value of the safety harness, and the infrared trigger status of the treadmill boundary. At the same instant that each data point is acquired, a high-precision global unified timestamp is injected into the data point by dedicated hardware based on the global master clock. The timestamp corresponds one-to-one with the corresponding data point and is permanently bound. If an abnormal timestamp jump occurs, the corresponding data is immediately marked and the abnormal event is recorded. For each timestamped data point, a three-level data quality assessment is performed and a quality level is marked. The quality mark is then bound to the corresponding data point as metadata and transmitted throughout the entire data chain. Specifically: Quality assessment involves classifying collected data into three categories: invalid data, low-reliability data, and valid data. Specifically, if the electrode contact force corresponding to neurophysiological data, head movement data, electrode contact status data, and cardiovascular data is less than 0.5N or greater than 5N, or the contact impedance is greater than 50kΩ; or if the pressure value of the plantar pressure data is less than 3N or greater than 3000N and there is no change in value for 100ms; or if all types of data acquisition devices experience communication interruption or hardware failure alarms; these data will be judged and marked as invalid and will not be included in subsequent calculations. If the average brightness of the visual posture data image is too low or too high, or if key human body parts are not detected for more than 3 consecutive frames; or if the electrode contact force corresponding to the neurophysiological data, head movement data, electrode contact status data and cardiovascular data is in the range of 0.5-1N or 3-5N, or the contact impedance is in the range of 20-50kΩ; or if all types of data have slight signal fluctuations but do not meet the invalid criteria; these data will be judged and marked as low reliability data. All data that does not meet the invalid or low reliability conditions will be marked as valid data and can participate in subsequent calculations normally. All raw data from each modality with global timestamps and quality markers are integrated into a structured raw multimodal dataset in chronological order. Each record in the original multimodal dataset contains all types of data at the corresponding time, their respective quality markers, and a unified timestamp.

[0019] Methods for real-time detection of dual physiological event anchors include: In the original multimodal dataset, data marked as invalid are removed, and only valid and low-reliability data are retained for subsequent detection; Then, the three core data types of EEG, vision, and stress are extracted synchronously according to the timestamp and preprocessed. Among them, EEG data extraction and preprocessing: extracting EEG signals collected by the electrode array, performing 0.5-4Hz bandpass filtering, and retaining cortical potential components related to motor preparation; Visual data extraction and preprocessing: Extract the two-dimensional coordinates of key points of the heel and toe bones from the full-body posture image to obtain the vertical movement velocity of the key points; Pressure data extraction and preprocessing: Dynamic baseline calibration is performed on the plantar pressure data, and the baselines of the heel region (the second third of the running belt) and the toe region (the first third of the running belt) are divided, and the total pressure value of the two regions is calculated respectively. It should be noted that there is an inherent detection delay that is physically unavoidable between the pressure domain, the visual domain, and the EEG domain. Generally speaking, the total delay is approximately 2ms in the pressure domain (physical impact of heel strike → deformation of piezoelectric sensor → analog-to-digital (AD) conversion output); in the visual domain (light entering camera → CMOS exposure → image transmission → detection of key skeletal points); and in the EEG domain (mechanical stimulation of the sole of the foot → spinal cord conduction → evoked potentials in the cerebral cortex → acquisition of EEG signals). Therefore, in real-world scenarios, the detection times of the three domains must have a fixed order and phase difference (pressure first, vision second, and EEG last). Therefore, it is necessary to compensate for the inherent delay of each domain detection time in order to obtain the true occurrence time of the anchor event; Inherent delay compensation logic: The actual time in the pressure domain = the pressure detection time - 2ms (the inherent delay of the pressure sensor); Real time in visual domain = visual detection time - 20ms (average processing latency of visual device). Real time in the EEG domain = EEG detection time - 45ms (mean latency of EEG evoked potentials). The specific fixed delay compensation parameters are default values, and can be fine-tuned by the therapist manually inputting them or by loading the patient's personalized delay parameters (if historical training data is available). The primary anchor point for heel strike is based on the pressure domain, while the secondary anchor point for toe lift is based on the visual domain. Both are detected using a weighted voting logic to obtain the anchor points for the dual physiological events. The main anchor point weighted voting logic detection involves: independently detecting features in each domain and recording the actual occurrence time after compensation. Pressure domain detection: Real-time monitoring of total pressure value in the heel area; when the pressure value jumps from the baseline level to more than 5 times the baseline standard deviation, the timestamp of the detection moment is recorded. Visual domain detection: Real-time monitoring of the vertical velocity of the heel key point; when the velocity changes from negative (downward movement) to positive (upward movement), the timestamp of the detection moment is recorded. EEG domain detection: Real-time monitoring of filtered EEG signals; when the signal shows a negative potential zero-crossing point (potential value changes from positive to negative), the timestamp of the detection moment is recorded. Based on the average duration of the patient's most recent 10 gait cycles, the time window size is set to 5% of the average gait cycle (the default upper and lower limits are a minimum of 20ms and a maximum of 80ms). Centered on the stress domain detection time, the detection results of the visual domain and EEG domain are searched within the time window, and the total score is calculated; The specific scoring rules are as follows: the base score is based on the detected stress domain (if the data quality is valid, the base score is 5 points; if the data quality is low reliability, the base score is 2.5 points); if the visual domain result is detected, 3 points are added if the data quality is valid, and only 1.5 points are added if the data quality is low reliability; if the EEG domain result is detected, 2 points are added if valid, and 1 point is added if low reliability. A total score of ≥6 points is considered a valid main anchor point and a high-confidence anchor point, with the actual occurrence time taken as the actual time in the pressure domain; a total score of ≤5 points and ≥4 points is considered a low-confidence anchor point, and a total score <4 points is considered invalid. The auxiliary anchor point weighted voting logic detection uses the same detection logic as the main anchor point to identify the auxiliary anchor point where the toes leave the ground. Specifically, EEG domain detection: Real-time monitoring of filtered EEG signals, and recording the timestamp of the detection moment when the signal shows a positive potential zero crossing (potential value changes from negative to positive); Visual domain detection: Real-time monitoring of the vertical velocity of key points on the toes; when the velocity changes from positive (upward movement) to negative (downward movement), the timestamp of the detection moment is recorded. Pressure domain detection: Real-time monitoring of total pressure value in the toe area; when the pressure value drops from the peak value to 30% of the peak value, the timestamp of the detection moment is recorded. Using the same dynamic time window as the main anchor point, with the visual detection moment as the center, the detection results of the stress domain and EEG domain are searched within the time window, and the total score is calculated. The specific scoring rules are the same as the main anchor point logic: the detected visual domain is used as the base score (if the data quality is valid, the base score is 5 points; if the data quality is low reliability, the base score is 2.5 points); if the stress domain result is detected, if the data quality is valid, add 3 points; if the data quality is low reliability, add only 1.5 points; if the EEG domain result is detected, if valid, add 2 points; if low reliability, add 1 point. A total score of ≥6 points is considered a valid auxiliary anchor point and a high-confidence anchor point, with the actual occurrence time taken from the actual time in the visual field; if the total score is ≤5 points and ≥4 points, it is considered a low-confidence anchor point, and if the total score is <4 points, it is considered invalid. For the two types of anchor point events, invalid anchor points are eliminated through gait cycle rationality check. Specifically: the normal human gait cycle is usually 0.5 to 2 seconds, and the time interval between the main anchor point and the subsequent auxiliary anchor point is usually 0.2 to 1.2 seconds. If it exceeds the range, it is judged as invalid. If no effective anchor point is detected for 5 consecutive gait cycles, reduce the treadmill speed to 0.5 meters per second and prompt the therapist to check the equipment. The verified main anchor point and auxiliary anchor point events are organized in chronological order into a set of actual occurrence times for dual anchor points. Each anchor point event includes: event type, actual occurrence time, three-domain detection time, total score, and confidence level.

[0020] Methods for generating multimodal synchronization datasets include: Based on the set of actual occurrence times of the dual anchor points, two circular calibration queues of length 10 are initialized, namely the main anchor point calibration queue and the auxiliary anchor point calibration queue. Each queue contains three fields: two time difference values ​​and one confidence weight. All initial values ​​of the queues are set to zero. The primary anchor point is based on the real time in the stress domain, and the secondary anchor point is based on the real time in the visual domain. The time differences between the EEG domain, the stress domain, and the visual domain are calculated and pushed into the corresponding calibration queues. Specifically: Calculation of time difference between main anchor points: For each valid main anchor point event received, the time difference T1_EP between the actual time of occurrence in the pressure domain and the actual time of occurrence in the pressure domain is calculated, based on the actual time of occurrence in the pressure domain (the main anchor pressure domain has the highest signal-to-noise ratio), and the time difference T1_VP between the actual time of occurrence in the visual domain and the actual time of occurrence in the pressure domain. Weights are set based on the anchor point confidence level: high confidence anchor point weight = 1.0, low confidence anchor point weight = 0.5; (T1_EP, T1_VP, weight) is pushed into the main anchor calibration queue, and a first-in-first-out mechanism is used. When the queue is full, the earliest data is directly overwritten. Calculation of auxiliary anchor time difference: For each valid auxiliary anchor event received, based on the actual occurrence time in the visual domain (the auxiliary anchor has the highest signal-to-noise ratio in the visual domain), the time difference T2_EV between the actual time in the EEG domain and the actual time in the visual domain, as well as the time difference T2_PV between the actual time in the pressure domain and the actual time in the visual domain are calculated. Set the confidence weights according to the same rules, and push (T2_EV, T2_PV, weights) into the auxiliary anchor calibration queue; Invalid anchors are discarded directly without entering any queue, and an exception log is recorded at the same time; Once both the primary anchor calibration queue and the secondary anchor calibration queue are filled with 10 sets of data, the weighted median calibration parameters are calculated independently for each anchor point according to the time-series calibration rules. Specifically: Calculation of the calibration parameters for the weighted median of the principal anchor point: Sort the T1_EP values ​​in the main anchor queue in ascending order, while retaining the corresponding confidence weights; accumulate the weights starting from the minimum value, and when the sum reaches 50% of the total weight, the corresponding value is the weighted median of T1_EP. Similarly, the weighted median of T1_VP is calculated and integrated to obtain the independent calibration parameter set for the main anchor point; Auxiliary anchor point calibration parameter calculation: Using the same weighted median algorithm as the main anchor point, the T2_EV weighted median and T2_PV weighted median are calculated and integrated to obtain the independent calibration parameter set for the auxiliary anchor point; Each time a new valid anchor point event is detected, the corresponding queue is updated and the calibration parameters are recalculated to ensure real-time parameter accuracy. Then, the deviation between the main anchor point and the auxiliary anchor point is checked for reasonableness and dynamically fused to generate global timing calibration parameters. Specifically: The absolute difference between the weighted median of T1_EP and the weighted median of T2_EV is calculated to obtain the main and auxiliary anchor point deviation difference in the EEG domain; the absolute difference between the weighted median of T1_VP and (-T2_PV weighted median) is calculated to obtain the main and auxiliary anchor point deviation difference in the visual domain. It should be noted that T2_PV is used to reflect how many milliseconds earlier the pressure is than the visual perception, while what is needed here is the time difference between the visual perception and the pressure at the auxiliary anchor point of the pressure domain, which is how many milliseconds later the visual perception is than the pressure. The two are inversely related, so the inverse of the weighted median of T2_PV is needed to calculate the deviation difference between the main and auxiliary anchor points of the pressure domain. The difference between the main and auxiliary anchor points in the EEG domain is used to reflect the degree of difference in the "temporal deviation of the EEG signal relative to the physical signal" measured by the main anchor point and the auxiliary anchor point respectively. Since the inherent delay of the EEG signal is stable, the deviation values ​​measured by the two anchor points should theoretically be equal. If the difference is too large, it indicates that the detection result of one of the anchor points has a systematic deviation. The visual domain primary and secondary anchor point deviation difference is used to reflect the degree of difference in the "temporal deviation of the visual signal relative to the pressure signal" measured by the primary anchor point and the secondary anchor point respectively. This is the most stable pair of deviations among the three modes because pressure and vision are modes that directly measure physical motion and are least affected by physiological factors, making them more reliable indicators for hardware fault detection. Both parameters must meet the threshold requirements to determine that the measurement results of the primary and secondary anchor points are consistent. Dynamic fusion rules: If the deviation between the primary and secondary anchor points in the EEG domain and the primary and secondary anchor points in the visual domain are both ≤10ms, it is considered normal fusion, and the average value is taken as the global calibration parameter. Global temporal bias in the EEG domain T_EP = (weighted median of T1_EP + weighted median of T2_EV) ÷ 2; Global temporal deviation in the visual domain T_VP = (weighted median of T1_VP + (-weighted median of T2_PV)) ÷ 2; If either of the two main and auxiliary anchor point deviations is ≤20ms and >10ms, it is judged as a slight difference. The main anchor point parameters are preferred (the main anchor point detection has higher reliability), that is, T_EP = T1_EP weighted median, T_VP = T1_VP weighted median. At the same time, the difference is recorded for subsequent personalized calibration. If the deviation between the two main and auxiliary anchor points is greater than 20ms, it is judged as a serious difference, one of the anchor points is judged to have failed detection, an anchor point deviation abnormality warning is triggered, the runway speed is reduced to 0.5m / s, calibration is performed using only the main anchor point parameters, and the update of the auxiliary anchor point parameters is suspended. A typical abnormal scenario: If the deviation between the primary and secondary anchor points in the EEG domain is 25ms and the deviation between the primary and secondary anchor points in the visual domain is 8ms, it indicates that there is an abnormality in the EEG signal detection (such as poor electrode contact leading to a prolonged latency), but the pressure and visual signals are normal. If both exceed 20ms simultaneously: it indicates a serious fault in the entire timing center, requiring immediate triggering of safety protection. It should be noted that the global timing deviation T_EP in the EEG domain is used to reflect the fixed delay of the EEG signal relative to the global reference time axis (pressure domain). When an event in the pressure domain occurs at time t, the corresponding EEG signal will appear at time t+T_EP. The global timing deviation T_VP of the visual domain is used to reflect the fixed delay of the visual signal relative to the global reference time axis (pressure domain). When an event in the pressure domain occurs at time t, the corresponding visual signal will appear at time t+T_VP. Assuming the calculated global calibration parameters at a certain moment are T_EP=42ms and T_VP=18ms, then for any moment t on the time axis of the pressure domain, the corresponding moments for other modalities are: EEG signal: t+42ms, visual signal: t+18ms. Through this mapping relationship, all data from the three modes can be unified onto the stress domain, which is the most stable and least delayed global time base. For the generated global timing calibration parameters, timing deviation classification and anomaly handling are performed, and the degree of anomaly is divided into minor anomaly, moderate anomaly and severe anomaly; the baseline is the T_EP and T_VP values ​​obtained from the first calibration after the device is started; Among them, minor anomaly handling: when the global calibration parameters deviate from the baseline by more than 5ms but less than 10ms for 3 consecutive times, the length of the two calibration queues is increased to 15 (the original data is retained and the cycle is continued to cover), the calibration frequency is doubled, and the anomaly log is recorded. Moderate anomaly: When there are 5 consecutive deviations greater than 10ms but less than 20ms, the treadmill speed will be reduced to 0.5m / s, triggering the voice prompt "Timing calibration abnormal, please check the equipment", and the training parameter adjustment will be paused. Serious anomaly: When the deviation is greater than 20ms for 10 consecutive times, the safety rejection state is triggered directly through the dual redundant safety control bus of CAN FD bus and Ethernet bus, and the emergency braking macro instruction is executed. At the same time, the full anchor point data of the 15 seconds before the trigger is recorded for post-event analysis. Furthermore, based on the latest global timing calibration parameters, taking two adjacent master anchor points as a complete gait cycle, a continuously changing calibration parameter curve is generated within the gait cycle through linear interpolation: The heel-landing time (i.e., the time of the main anchor point, t=t_heel) uses the main anchor point calibration parameters: T_EP(t_heel)=T1_EP, T_VP(t_heel)=T1_VP; The time of toe lift-off (i.e., the time of the auxiliary anchor point, t=t_toe) is calculated using the auxiliary anchor point calibration parameters: T_EP(t_toe)=T2_EV, T_VP(t_toe)=-T2_PV; The calibration parameters for the corresponding time point are obtained by linear interpolation according to the time ratio at intermediate time points. The linear interpolation formula is: within a complete gait cycle (t_heel≤t≤t_toe): T_EP(t)=T1_EP+(T2_EV-T1_EP)×(t-t_heel)÷(t_toe-t_heel); T_VP(t)=T1_VP+(-T2_PV-T1_VP)×(t-t_heel)÷(t_toe-t_heel); To ensure that calibration parameters transition smoothly throughout the gait cycle and avoid data jitter and feature extraction errors caused by parameter abrupt changes; Based on the continuous calibration parameter curve, time-by-time time axis translation and alignment are performed on all multimodal data in the original multimodal dataset: The EEG data D_E(t) corresponds to the stress data D_F(t-T_EP(t)); Visual data D_V(t) corresponds to pressure data D_F(t-T_VP(t)); The equipment operating data (motor speed, sling tension, etc.) are consistent with the pressure data in terms of time reference, so no additional translation is required; During the alignment process, the original timestamps, quality markers, and confidence information of all data are preserved, and only the temporal correlation between data of different modalities is established; All aligned data are reassembled in the order of the timestamps of the stress data to generate a multimodal synchronization dataset.

[0021] Methods for generating weighted security state vectors include: A fixed time window (default 100ms) is preset as a time slice. The full data of the corresponding time slice is extracted one by one from the multimodal synchronous dataset. Each slice contains four types of data at that moment: EEG, vision, stress, and device operation, as well as their respective quality labels. Then, quantitative feature values ​​of four dimensions—neural, visual, physical, and artifact—are extracted from the full data of the time slice as security features. Among them, the neural dimension features are: extracting EEG signals, using the sliding window power spectrum estimation method to calculate the power ratio of the θ band (4-8Hz) to the α band (8-13Hz), which is denoted as the neural feature; Visual dimension features: Based on the plantar pressure distribution, the coordinates of the center of pressure (COP) at the current moment are identified. Combined with the key points of the two foot bones, a support polygon of the two feet is constructed. The minimum distance from the COP to each side of the support polygon is calculated and recorded as the visual feature. Physical dimension features: Calculate the total pressure values ​​of the left and right soles respectively to obtain the ratio of the total pressure of one sole to the total pressure of both soles; calculate the displacement of COP in two consecutive time slices, divide it by the time window to obtain the velocity of the pressure center movement, and record it as a physical feature; Artifact dimensional features: Extract the AC component of the near-infrared pulse wave signal and calculate its rate of decrease relative to the preset baseline; extract the triaxial acceleration signal of the head and calculate the bandpass energy of the 4-6 Hz frequency band, which is denoted as the artifact feature; The feature values ​​of each dimension are compared with the corresponding preset anomaly detection thresholds to generate corresponding binary basic status flags (0 = normal, 1 = abnormal), which can be specifically divided into: N1 (Neurological Abnormality Marker): When the neurological characteristic is >2 and the state lasts for more than 10 seconds, it is set to 1, indicating that the patient has a decrease in intrinsic vigilance and poor concentration; Z1 (Posture Abnormality Marker): Set to 1 when visual feature is <8cm, indicating that the patient's center of gravity is close to the support boundary and there is a risk of falling. L1 (Biomechanical abnormality marker): When the total plantar pressure on one side drops to less than 30% of the baseline value, or the physical characteristics are >0.4m / s, it is set to 1, indicating that the patient's gait is unstable and is about to lose balance; W1 (artifact or physiological abnormality marker): When the decrease rate of the AC component of the pulse wave is >35%, or the artifact feature is >0.05g and lasts for more than 500ms, it is set to 1, which indicates the presence of severe signal artifacts or the patient's cardiovascular abnormalities or frozen gait precursors. Add a default decision weight to each basic state flag bit, with a default value of 1 (i.e., 1x). Then, based on the current device operating environment and the patient's training status, pre-modulation of the environment is performed with the highest priority. The basic status flags are corrected and the default decision weights of each dimension are modulated. Specifically, the device operating environment and the patient's training status can be combined to divide the environment into different scenarios. This embodiment takes three typical scenarios as examples: Assisted training scenario: Triggered when the infrared boundary sensors around the treadmill detect that the therapist is less than 50cm away from the patient. Force the N1 flag to be set to 0 (ignore neurological dimension abnormalities and have direct monitoring by the therapist); increase the decision weight of the physical dimension (L1) to twice; send an intercept signal to the subsequent intent generation process to prohibit all intent suggestion output; Low-light environment scenario: Triggered when the visual sensor component detects an average image brightness of <100 lux: Freeze the Z1 flag to the previous state (not updated based on low-quality visual data); increase the decision weights of the physical dimension (L1) and artifact dimension (W1) by 1.5 times; High-risk fatigue period scenario: Triggered when continuous training duration exceeds 30 minutes: The abnormal activation thresholds for all dimensions are automatically tightened by 15% (e.g., the N1 threshold is reduced from 2 to 1.7); an interception signal is sent to subsequent intent generation processes to prohibit the output of all acceleration-type intent suggestions; The basic state flags and modulated decision weights of the four dimensions are weighted and calculated respectively. Taking the neural dimension as an example, the calculation method is: neural dimension weighted value = N1 flag bit × neural dimension decision weight; And add independent environmental dimension flags, environmental dimension flags (0=normal environment, 1=assisted training, 2=low light, 3=high risk of fatigue). Then, the vectors are horizontally concatenated to generate a weighted five-dimensional security state vector. Based on the activated status flags and the environment status, corresponding standardized security event tags are generated. Each tag contains the event type and the timestamp of occurrence. When N1 is activated, an "endogenous decrease in vigilance" event is generated. If Z1 is activated, an "attitude instability risk" event will be generated. L1 activation generates a "gait mechanics anomaly" event; When W1 is activated, a "signal artifact or physiological abnormality" event is generated. If the environmental state changes, a corresponding environmental event tag is generated.

[0022] Methods for generating intent suggestion packages include: Based on a multimodal synchronous dataset, only effective data in the neural and artifact dimensions are extracted, and visual, physical, and device operation data are not used to participate in intent calculation, thus avoiding interference from physical state on intent judgment from the root. From the extracted valid data, quantitative features related to the patient’s motor intention and physiological state were extracted respectively, serving as neural dimension intention features and artifact dimension physiological features. Among them, the neuro-dimensional intention feature is: extracting EEG signals, calculating the power ratio of the 0.5-4Hz slow wave band to the 13-30Hz β band, and recording it as the intention feature, which is used to assess the patient's motor readiness and alertness level; Physiological characteristics of artifacts: Heart rate variability (HRV) index of near-infrared pulse wave signal was extracted, and the standard deviation of RR interval for 5 consecutive cardiac cycles was calculated; the root mean square value of head triaxial acceleration signal was extracted to assess the degree of body tremor in patients. Based on the extracted feature values, and following the principles of safety priority and conservative decision-making, unconstrained intent suggestions are generated. Only two intent suggestions are generated: deceleration and maintenance. No acceleration suggestions are generated. The deceleration suggestion generation logic is as follows: an intention feature greater than 2.5 and lasting for more than 3 fixed time windows (300ms) indicates that the patient is not adequately prepared for movement and has a significantly decreased level of alertness; a HRV standard deviation lower than 40% of the preset baseline value indicates that the patient is showing signs of cardiovascular decompensation; a root mean square value of head acceleration greater than 0.1g and lasting for more than 2 time windows indicates that the patient is showing signs of frozen gait or severe body tremors. A deceleration suggestion can be generated if any one of the above three conditions is met. The logic for generating the suggestion is as follows: In all cases where the above deceleration conditions are not met, a suggestion to maintain the current speed is generated. Based on the environmental dimension status flags, the generated intent suggestions are subjected to the highest priority environmental factor intent interception and verification: Assisted training state scenario (environmental dimension flag = 1): Forcefully intercept all intention suggestions, do not generate any instructions, and the treadmill is completely manually controlled by the therapist; High-risk fatigue scenario (environmental dimension flag = 3): Forcefully block all potential acceleration suggestions (no acceleration suggestions are allowed by default in this embodiment; this rule is a reserved extensible option), and only allow the output of deceleration and maintenance suggestions; Normal environment (environment dimension flag = 0) and low light environment (environment dimension flag = 2): Do not intercept any legally generated intent suggestions; The intent suggestions that pass the interception verification will be encapsulated to generate an intent suggestion package, which includes the instruction type (decelerate or maintain), instruction parameters (decelerate suggestions include the target speed value, and maintain suggestions have a parameter of 0), and generation timestamp.

[0023] The methods for generating valid execution instructions include: Based on a weighted five-dimensional security state vector and intent suggestion package, a two-level security interlocking gating verification is performed through an independent security core (lockstep dual-core, a hardware platform that provides physical isolation, fault detection, and hardware-level security assurance): The first level of gating verification is to verify the legality of the intent suggestion packet, and only allow intents that conform to the preset security rules to enter the next level of verification; The specific verification rule is as follows: First, based on the current security state machine state, check whether the intent instruction is allowed: Normal state: Allow deceleration and maintenance commands; Warning state: Allow only deceleration commands, intercept all maintenance commands; Emergency state: Intercept all intention commands, forcibly generate and send emergency braking commands. Next, verify the target speed parameters of the deceleration command: The target speed must not be lower than 0.1 m / s (default minimum operating speed of the equipment); the single deceleration amount must not exceed 30% of the current speed to prevent sudden stops that could cause the patient to fall; the time interval between two consecutive deceleration commands must not be less than 1 second; Intent commands that fail the validity check are directly intercepted, and an "illegal intent" event is logged. It should be noted that the security state machine is a standardized set of state transition rules that runs on the independent lockstep dual-core security core. Based on the principle of finite state machine (FSM), it summarizes all possible security states of the device into a finite number of mutually exclusive states, which are used to uniformly manage security states, state transition rules and corresponding permissions, ensuring that all security decisions follow strict and predictable logic, and avoiding security vulnerabilities caused by fragmented judgments. Without a unified state management system based on safety state machines, the device may receive two conflicting commands simultaneously: one to maintain and one to decelerate, leading to conflicts in the actuators. Different safety states correspond to different command permissions, enabling hierarchical access control to ensure that the higher the risk, the lower the degree of freedom. The security kernel ensures that the code of the security state machine is not tampered with and that its execution process is not interfered with; the security state machine, in turn, ensures that all decisions made by the security kernel comply with preset security rules. The security state machine predefines the types of instructions and permissions that the device is allowed to execute in each state, the triggering conditions for transitioning from one state to another, and the security actions that must be performed during state transitions. The safety state machine used here defines only three mutually exclusive safety states to cover all possible operating scenarios: normal state (operating normally, patient condition is stable, allowing both deceleration and maintenance intention commands to be executed), warning state (potential safety risks exist, requiring increased vigilance, only deceleration commands are allowed to be executed, and all maintenance commands are blocked), and emergency state (clear safety risks exist, requiring immediate intervention, all intention commands are blocked, and an emergency braking command is forcibly output). The triggering condition for state transition is determined solely by the comprehensive risk value of the weighted five-dimensional safety state vector. The transition logic is as follows: if the comprehensive risk value is <1, then it is a normal state; if 1 ≤ comprehensive risk value <2, then it is a warning state; if the comprehensive risk value >2, then it is an emergency state. At each state transition, execute the preset safety action: Normal transition to warning: Triggers the voice prompt "Please be careful" and reduces the treadmill speed by 10%; Warning switched to emergency: Immediately reduce the running platform speed to 0.5m / s and trigger the audible and visual alarm; Transitioning from any state to an emergency state: directly triggers a safety veto via the dual-redundant bus, executing an emergency braking macro instruction; The second-level gating verification combines a weighted five-dimensional security state vector to perform a final security verification on the intent that has passed the legitimacy verification, generating a legitimate execution instruction or a security rejection signal. The specific verification rules are as follows: First, the comprehensive risk value of the weighted five-dimensional security state vector is calculated by using the inherent risk weights of each security dimension. The comprehensive risk value = neural dimension weighted value × corresponding risk weight + physical dimension weighted value × corresponding risk weight + visual dimension weighted value × corresponding risk weight + artifact dimension weighted value × corresponding risk weight + environmental dimension flag × corresponding risk weight. The risk weights for each safety dimension are designed based on inherent constants determined through clinical data statistics and risk analysis. These constants reflect the inherent danger of abnormalities in different dimensions to patient safety. The higher the weight, the higher the probability and severity of safety accidents caused by the abnormality in that dimension. An example of a common and universally applicable risk weight design logic: The weights are designed according to the probability and severity of safety accidents. The physical dimension (weight 2.0, the highest, gait biomechanics abnormalities (such as a sudden drop in plantar pressure on one side) is the most direct precursor to a fall. Once it occurs, the patient may lose balance within 1-2 seconds, so it is given the highest weight) > visual dimension (1.5) > artifact dimension (1.2) > neural dimension (1.0) > environmental dimension (0.5, the lowest, environmental factors themselves do not directly constitute safety risks, but rather play a role by amplifying or reducing the risks of other dimensions, so they are given the lowest weight). Based on the transition logic of the preset state transition trigger conditions, the final security is checked in stages by comprehensive risk value: low risk (comprehensive risk value < 1), all intention commands that pass the legality check are allowed to be executed; medium risk (1 ≤ comprehensive risk value < 2), only deceleration commands are allowed to be executed; high risk (comprehensive risk value ≥ 2), all intention commands are intercepted, and a command to decelerate to 0.5m / s is forcibly generated and sent. If the weighted value of the physical dimension is ≥1 or the weighted value of the artifact dimension is ≥1, regardless of the overall risk value, a safety rejection signal is generated, all intention commands are intercepted, and a deceleration command is forcibly generated and sent. Simultaneously, based on the security event markers, corresponding linked security event actions are performed: Risk of instability: The treadmill speed will be forcibly reduced to 50% of the current speed, triggering a voice prompt; Abnormal gait mechanics: Immediately reduce the treadmill speed to 0.5 m / s and trigger an audible and visual alarm; Signal artifacts or physiological abnormalities: Suspend the execution of all intended commands, monitor continuously for 5 seconds, and trigger emergency braking if the abnormality is not eliminated. Decreased intrinsic alertness: Triggers the voice prompt "Please concentrate" and reduces the treadmill speed by 10%; Legitimate instructions that have passed two levels of gating verification are written into the actuator, and the state of the safety state machine is updated synchronously based on the latest comprehensive risk value.

[0024] The methods for forming standardized execution control instructions include: The legal execution instructions, security rejection signals, and security event markers are sorted according to the preset fixed priorities. Higher priority will immediately preempt the execution rights of lower priority. The priorities from highest to lowest are: security rejection signal (highest priority, cannot be masked), emergency state security event marker, early warning state security event marker, legal execution instructions (deceleration, maintenance), and security status update signal (lowest priority). When multiple instruction signals are received at the same time, only the highest priority signal is processed, and all other signals are discarded; when a high-priority instruction signal arrives, the execution of a low-priority instruction is immediately interrupted; the security veto signal has the highest authority and must be responded to immediately under any circumstances. Through multi-state hierarchical protection decision logic, based on the highest priority signal after sorting and the current security state, hierarchical protection decisions are made for the corresponding security state, and corresponding protection execution instructions are generated. Specifically, the tiered protection decision logic is defined as follows: Upon receiving a safety rejection signal, immediately execute the following: forcibly cut off the main motor power supply and trigger the electromagnetic brake; simultaneously send an emergency braking command to all actuators via the dual-redundant bus; trigger the audible and visual alarm device to issue a continuous audible and visual warning; and lock the operating interface to prohibit any manual operation. When in an emergency state or when an emergency security event is flagged: Immediately generate an emergency deceleration command with a maximum deceleration rate not exceeding 0.5 / s² to prevent new risks caused by sudden stop inertia; prohibit all manual acceleration operations and only allow manual emergency braking; continuously monitor the safety status, and if the abnormality is not eliminated within 5 seconds, upgrade to a safety veto status; When in a warning state or receiving a warning state safety event marker: execute a deceleration command, with a single deceleration not exceeding 30% of the current speed; trigger the corresponding type of voice prompt; limit the maximum speed of the treadmill to no more than 80% of the current speed; reassess the safety status every 500ms, and return to normal status if the risk is eliminated; When in a normal state and without any security event flags: Directly execute legal commands (decelerate or maintain speed), monitor command execution in real time to ensure smooth speed changes, and allow therapists to manually adjust the speed. All generated protective execution commands undergo a final parameter hard limit check to ensure that the command parameters are within an absolutely safe range. This includes: speed lower limit check (the minimum running speed of the treadmill must not be lower than 0.1m / s), speed upper limit check (the maximum running speed of the treadmill must not exceed the patient's preset maximum training speed), acceleration check (acceleration must not exceed 0.2m / s², and deceleration must not exceed 0.5m / s²), and command interval check (the time interval between two consecutive speed adjustment commands must not be less than 500ms). Any protection execution command that exceeds the limit will be corrected to the closest safe value, and the command parameter over-limit event log will be recorded. Finally, the verified protection execution commands are encapsulated into standardized execution control commands, including command type (acceleration, deceleration, maintenance, emergency braking), command parameters (speed value), and command generation time; It should be noted that all specific values ​​mentioned in this embodiment (such as parameters such as 100ms, 30%, 5 seconds, 0.1m / s, <1, >2.5, etc., and specific values ​​of weights and thresholds) are exemplary. Specific values ​​can be adjusted by the therapist according to the actual use scenario and the patient's physical condition.

[0025] The methods for conducting phased closed-loop effect verification and abnormal execution security upgrades include: The main controller and the backup controller simultaneously receive standardized execution control commands via a dual-redundant bus consisting of a CAN FD bus and an Ethernet bus, and then perform consistency verification on the commands received from the two buses. If two bus commands are completely identical and the checksum is correct, the command is considered valid. If the two bus commands are inconsistent or the checksum is incorrect, the command is discarded and the previous valid command is used to continue execution. If no valid command is received for three consecutive times, a command transmission error is triggered, and the system enters an emergency deceleration state. The primary and backup controllers synchronize command status in real time through heartbeat signals. If the primary controller fails, the backup controller will seamlessly take over the execution within 1ms. Based on the valid instruction type, drive the corresponding actuator to perform graded protection actions; The entire execution process of all actions is verified in stages to achieve a closed-loop effect, including staged verification of deceleration commands and staged verification of emergency braking commands. The deceleration command is verified in stages, including the start-up stage (default time period is 0-200ms, verification indicator: motor speed begins to decrease and the decreasing trend is consistent with the command; if no speed decrease is detected within 200ms, it is judged as start-up failure), the execution stage (200ms-deceleration completion, verification indicator: actual deceleration is within the range of 0.3-0.5m / s²; if the deceleration exceeds the range for 500ms, it is judged as execution abnormality), and the completion stage (100ms after deceleration is completed, verification indicator: the deviation between the actual speed and the command target speed is ≤0.05m / s; if the target speed is not reached within 100ms, it is judged as completion failure). The emergency braking command is verified in stages, including power cut-off verification (0-50ms, verification indicator: the inverter main power supply voltage drops to 0V, and the power is not cut off within 50ms, triggering hardware emergency braking), holding brake verification (50-100ms, verification indicator: the electromagnetic holding brake is in the engaged state, and the holding brake is not engaged within 100ms, triggering mechanical braking), and stop verification (100-500ms, verification indicator: the treadmill stops completely, the motor speed is 0, and if it does not stop within 500ms, triggering the highest level safety alarm). If any stage of verification fails, it is determined to be abnormal execution, triggering a hierarchical security escalation mechanism to execute higher-level protection actions. Specifically: Level 1 anomaly (deceleration start failure): Immediately resend the deceleration command, increasing the deceleration rate to 50% of the current speed. If it still fails after resending, it is upgraded to Level 2 anomaly. Level 2 anomaly (deceleration execution anomaly): Immediately trigger an emergency deceleration command to reduce the runway speed to 0.5 m / s. If emergency deceleration still fails, it will be upgraded to a Level 3 anomaly. Level 3 Abnormality (Emergency Deceleration Failure): Immediately trigger the emergency braking command, cut off the power supply and apply the brakes, trigger the audible and visual alarms, notify the therapist, and lock the operating interface until manually reset. Level 4 Anomaly (Emergency Braking Failure): Directly triggers the mechanical braking device, simultaneously cuts off the main power supply to the equipment, generates an emergency event report, and uploads it to the server; The execution status (in progress, completed, abnormal) is fed back to the preceding hierarchical protection decision-making stage in real time, and detailed information of all execution instructions is recorded, including instruction type, parameters, sending time, execution time, and feedback data.

[0026] Methods for optimizing anomaly detection thresholds based on therapist feedback include: After the graded protection actions are completed, full-process operational data is acquired, including raw data (timestamped EEG, visual, stress, and equipment operation raw data), processing data (weighted five-dimensional safety state vector, standardized safety event markers, and intent suggestion packages), decision-making data (safety interlock gate verification results, comprehensive risk values, and safety state machine states), and execution data (execution control instructions, actuator feedback signals, and abnormal execution escalation records). Traceable data on therapist intervention is also acquired (therapist manual operation records, intervention timestamps, and intervention reason notes). Then, it is structured and packaged according to unified medical data standards; Based on the structured and encapsulated data, each intervention by the therapist is treated as an intervention event. All intervention events are divided into two categories and labeled, including automatic intervention by the safety protection system (protective actions such as deceleration and braking automatically triggered by the safety protection system) and manual intervention by the therapist (actions such as speed adjustment and emergency stop performed by the therapist through the operation interface). Using therapist-manual intervention events as a baseline, the data is extracted by looking back 30 seconds and forward 10 seconds on the timeline. All operational data within the corresponding time periods are then analyzed using a timeline-based correlation analysis of intervention events. The specific analysis content includes: Did the safety protection system issue warnings before the therapist intervened? What is the discrepancy between the safety status and the patient's actual condition? How timely and effective are the protective actions? Based on the analysis results, the types of biases in the security decision-making logic were identified, including three types of biases: Underreporting bias: The safety protection system failed to detect any risk and issued no warning before the therapist's intervention; False alarm bias: The safety protection system issues a warning when there is actually no risk, leading to unnecessary protective actions; Response lag bias: The warning time of the safety protection system is more than 1 second later than the therapist's intervention time; Based on the deviation analysis results of historical data and intervention events, the statistical learning method is used to adaptively optimize all relevant anomaly detection thresholds and risk weights. Specifically: First, statistical analysis was performed on the anomaly detection thresholds in four dimensions: neural, visual, physical, and artifact, and the feature value distributions corresponding to missed and false alarm events were calculated. Then, the optimal threshold balance point was found through ROC curve analysis to minimize the sum of the missed and false alarm rates. The optimization range is limited to ±20% of the original threshold to avoid significant adjustments that could lead to a decrease in operational stability. Then, based on the intervention event data, the risk weights of each security dimension are reassessed. The risk weights of dimensions with high false alarm rates are appropriately increased, and the risk weights of dimensions with high false alarm rates are appropriately decreased. The weight adjustment range shall not exceed ±15% of the original weight. Finally, the performance under different environmental conditions (assisted training, low light, fatigue period) was analyzed, and the decision weights of dimensional modulation and the tightening ratio of abnormal thresholds were optimized under each environment. All optimized thresholds and parameters must be reviewed and verified by therapists before they can be applied to the rehabilitation treadmill. Specifically: First, generate an optimization report, which includes: historical data statistical analysis results, a summary of intervention event analysis, a comparison of the original threshold and the optimized threshold, and an evaluation of the expected optimization effect; The therapist then reviews the optimization report and evaluates the optimization suggestions based on clinical experience: whether to accept, reject, or modify the optimized threshold parameters. All review processes are documented, including the reviewer, review time, and review comments; Finally, a security threshold update package is generated for the approved threshold parameters; The safety threshold update package will be released in a canary phase. First, the safety threshold update package will be applied to 10% of the training devices. The operation of the canary devices will be continuously monitored and the performance under the new threshold will be recorded. The canary phase will last for no less than 7 days, during which time feedback from therapists will be collected. If no safety issues arise during the gray-scale operation and the therapists provide positive feedback, the update package will be pushed to all devices; The update process uses an incremental update method, which does not affect the normal use of the device; The original threshold parameter rollback mechanism is retained, so that if a problem occurs, it can be immediately restored to the previous version; Perform full-process data analysis and threshold optimization regularly (default every 30 days). When the cumulative number of intervention events exceeds 100, immediately trigger an emergency optimization process. Establish a closed-loop iterative proactive security protection mechanism that integrates data collection, analysis, optimization, verification, deployment, and continuous iteration. Example 2

[0027] Please see Figure 3 As shown, the parts not described in detail in this embodiment are described in Embodiment 1. This embodiment provides an active safety protection method for a rehabilitation treadmill based on multimodal brain-computer visual perception, including: S1: Collect raw multimodal data, perform hierarchical quality labeling, bind it to the corresponding data throughout the entire link, and generate the raw multimodal dataset; S2: Based on the original multimodal dataset, dual physiological event anchor points are detected in real time. Then, through global time series calibration and time series deviation classification, multimodal data is dynamically time-aligned to generate a multimodal synchronization dataset. S3: Based on a multimodal synchronous dataset, extract multi-dimensional security features and compare them with preset anomaly detection thresholds to generate basic state flags. Through environmental factor weight modulation, generate a weighted five-dimensional security state vector. Simultaneously, generate non-constrained intent suggestions and generate intent suggestion packages through environmental factor intent interception verification. S4: Based on the weighted five-dimensional security state vector and intent suggestion package, the legality and security of intent are verified through security interlock gating to generate legal execution instructions; then, based on the pre-set solidified priority, multi-state hierarchical protection decisions are made to generate corresponding protection execution instructions, forming standardized execution control instructions; S5: Based on standardized execution control instructions, it executes graded protection actions, conducts phased closed-loop effect verification and abnormal execution safety upgrades, obtains full-process operation data and intervention events, and optimizes abnormal detection thresholds in combination with therapist feedback to form a closed-loop iteration. Example 3

[0028] This embodiment discloses an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the operation mode of the rehabilitation treadmill active safety protection system based on multimodal brain-computer visual perception described above.

[0029] Since the electronic device described in this embodiment is the one used to implement the active safety protection method for rehabilitation treadmills based on multimodal brain-computer visual perception in the embodiments of this application, those skilled in the art can understand the specific implementation methods and various variations of the electronic device in this embodiment based on the active safety protection method for rehabilitation treadmills based on multimodal brain-computer visual perception described in the embodiments of this application. Therefore, how the electronic device implements the method in the embodiments of this application will not be described in detail here. Any electronic device used by those skilled in the art to implement the active safety protection method for rehabilitation treadmills based on multimodal brain-computer visual perception in the embodiments of this application falls within the scope of protection of this application.

[0030] The above formulas are all dimensionless calculations. The formulas are derived from software simulations based on a large amount of collected data to obtain the most recent real-world results. The preset parameters and thresholds in the formulas are set by those skilled in the art according to the actual situation.

[0031] The above description is merely a preferred embodiment of the present invention, and the scope of protection of the present invention is not limited to the above embodiments. All technical solutions falling within the scope of the present invention's concept are within the scope of protection of the present invention. It should be noted that for users of ordinary technical skills, any improvements and modifications made without departing from the principles of the present invention should also be considered within the scope of protection of the present invention.

Claims

1. An active safety protection system for a rehabilitation treadmill based on multimodal brain-computer visual perception, characterized in that, include: The data acquisition and quality control unit collects raw multimodal data, performs hierarchical quality labeling, binds it to the corresponding data throughout the entire data chain, and generates the raw multimodal dataset. Timing synchronization unit: Based on the original multimodal dataset, it detects dual physiological event anchors in real time, and then performs global timing calibration and timing deviation classification to dynamically align multimodal data and generate a multimodal synchronization dataset. Security Intent Unit: Based on a multimodal synchronous dataset, extract multi-dimensional security features and compare them with preset anomaly detection thresholds to generate basic state flags. Through environmental factor weight modulation, generate a weighted five-dimensional security state vector. Simultaneously, generate non-constrained intent suggestions and generate intent suggestion packages through environmental factor intent interception verification. Security Decision Unit: Based on a weighted five-dimensional security state vector and intent suggestion package, it verifies the legality and security of intents through security interlock gating and generates legal execution instructions; then, based on pre-set solidified priorities, it makes multi-state hierarchical protection decisions and generates corresponding protection execution instructions, forming standardized execution control instructions; Execution Iteration Unit: Based on standardized execution control instructions, it executes graded protection actions, conducts phased closed-loop effect verification and abnormal execution safety upgrades, obtains full-process operation data and intervention events, and optimizes abnormal detection thresholds in combination with therapist feedback to form a closed-loop iteration.

2. The active safety protection system for a rehabilitation treadmill based on multimodal brain-computer visual perception as described in claim 1, characterized in that, The methods for generating the original multimodal dataset include: Based on a global synchronization clock, the system synchronously collects the current patient's multimodal raw data and adds a globally unified timestamp to each sampled data point. For each data point with a timestamp, a three-level data quality assessment is performed and the quality level is marked. The quality mark is then bound to the corresponding data point as metadata and transmitted throughout the entire data chain. Then, the original multimodal data with timestamps and quality labels are integrated in chronological order to generate the original multimodal dataset.

3. The active safety protection system for a rehabilitation treadmill based on multimodal brain-computer visual perception according to claim 2, characterized in that, The methods for real-time detection of dual physiological event anchor points include: Based on the original multimodal dataset, inherent delay compensation was performed on the detection times of the three independent domains: EEG domain, visual domain, and stress domain, to obtain the true occurrence time of the anchor event; The main anchor point is based on the pressure domain, and the auxiliary anchor point is based on the visual domain. They are detected by weighted voting logic to obtain the corresponding anchor points for the two physiological events. Invalid anchor points are eliminated by dynamic time window matching and gait cycle rationality verification to generate a set of actual occurrence times of the two anchor points.

4. The active safety protection system for a rehabilitation treadmill based on multimodal brain-computer visual perception according to claim 3, characterized in that, The methods for generating multimodal synchronization datasets include: Based on the set of actual occurrence times of dual anchor points, the main anchor point calibration queue and the auxiliary anchor point calibration queue are initialized. The main anchor point is based on the actual time of the pressure domain, and the auxiliary anchor point is based on the actual time of the visual domain. The time difference between the EEG domain, the pressure domain and the visual domain is calculated and pushed into the corresponding calibration queue. Once both calibration queues are full, the weighted median calibration parameters are calculated independently by anchor point according to the time-series calibration rules. Then, global time-series calibration parameters are generated through deviation rationality verification and dynamic fusion, and time-series deviation classification and anomaly handling are performed. Furthermore, based on the latest global time-series calibration parameters, taking the time period between two adjacent master anchor points as a gait cycle, linear interpolation is used to perform continuous time axis translation and alignment throughout the gait cycle, thereby dynamically aligning multimodal data and generating a time-aligned multimodal synchronization dataset.

5. The active safety protection system for a rehabilitation treadmill based on multimodal brain-computer visual perception according to claim 4, characterized in that, The methods for generating the weighted security state vector include: Preset time slices are used to extract the four-dimensional security features of neural, visual, physical and artifact dimensions of the corresponding time slices one by one based on the multimodal synchronous dataset. The corresponding basic state flag bits are generated by comparing with the corresponding preset anomaly detection thresholds and default decision weights are added. Based on the current equipment operating environment and patient training status, environmental pre-modulation is performed with the highest priority, the basic status flag is corrected and the default decision weights of each dimension are modulated. Then, the four-dimensional basic state flags and modulated decision weights are weighted and calculated, and an independent environmental dimension flag is added to generate a weighted five-dimensional security state vector, and security event markers are generated simultaneously.

6. The active safety protection system for a rehabilitation treadmill based on multimodal brain-computer visual perception according to claim 5, characterized in that, The methods for generating intent suggestion packages include: Based on a multimodal synchronous dataset, only neural dimension intention features and artifact dimension physiological features are extracted to generate unconstrained deceleration or maintenance intention suggestions; Based on the environmental dimension flags, the intent suggestions are subjected to environmental factor intent interception and verification. The intent suggestions that pass the verification are then encapsulated to generate an intent suggestion package.

7. The active safety protection system for a rehabilitation treadmill based on multimodal brain-computer visual perception according to claim 6, characterized in that, The methods for generating valid execution instructions include: Based on a weighted five-dimensional security state vector and intent suggestion package, a two-level security interlock gating verification is performed: First, the legality of the intent suggestion packet is verified. Then, combined with the weighted five-dimensional security state vector, the intent that passes the legality verification is finally verified for security, generating a legal execution instruction or a security rejection signal. Simultaneously, based on the security event markers, corresponding linked security event operations are performed.

8. The active safety protection system for a rehabilitation treadmill based on multimodal brain-computer visual perception according to claim 7, characterized in that, The methods for forming standardized execution control instructions include: Based on the legal execution instructions, security rejection signals and security event markers, the system uses multi-state hierarchical protection decision logic to make hierarchical protection decisions for the corresponding security state according to the preset solidified priorities and the current security state, and generates corresponding protection execution instructions. All protection execution commands are subjected to parameter hard-limiting verification, and after passing the verification, they are encapsulated into standardized execution control commands.

9. The active safety protection system for a rehabilitation treadmill based on multimodal brain-computer visual perception according to claim 8, characterized in that, The methods for performing phased closed-loop effect verification and abnormal execution security upgrades include: Based on standardized execution control commands, the corresponding execution mechanism is driven to perform graded protection actions; the entire execution process is verified in stages to achieve closed-loop effectiveness. When any stage verification fails, it is judged as abnormal execution, triggering a step-by-step security upgrade mechanism to execute higher-level protection actions and provide feedback on the execution status.

10. The active safety protection system for a rehabilitation treadmill based on multimodal brain-computer visual perception according to claim 9, characterized in that, The method of optimizing the anomaly detection threshold by incorporating therapist feedback includes: After the graded protection actions are completed, the entire process operation data and traceable data of therapist intervention are obtained. By analyzing the correlation between intervention events, deviations in the safety decision-making logic are identified, and the anomaly detection threshold is adaptively optimized. Then, after therapist review and verification and gray-scale release, reverse updates are performed to form a closed-loop iterative proactive safety protection mechanism.