Ethical decision chip for home-based care service robot, robot and ethical risk prevention and control method
By using an ethical decision-making chip to quantify ethical rules and impose hardware-level constraints, the problem of high coupling between ethical constraints and task processing in robots is solved. This provides scenario-adaptive prevention and control and decision-making transparency, ensures the traceability of the ethical decision-making process and the integration of professional standards, and improves the ethical safety of home-based elderly care service robots.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- 周大纲
- Filing Date
- 2026-03-15
- Publication Date
- 2026-04-14
AI Technical Summary
In existing technologies, ethical constraints on robots are too closely coupled with task processing, lack quantifiable mechanisms for expressing ethical rules, cannot dynamically adapt to changes in scenarios, have opaque ethical decision-making processes, and lack the integration of professional standards, making ethical risks difficult to control.
Design an ethical decision-making chip, including a scene recognition module, a hierarchical ethical rule storage module, an ethical rule engine, and an ethical audit module. It exists independently in hardware form to realize the quantification of ethical rules and hardware-level ethical constraints. Combined with lightweight machine learning and cryptographic security units, it ensures the transparency and traceability of ethical decisions.
It achieves the quantifiability and enforceability of ethical rules, ensures that ethical constraints operate independently when the main system is abnormal, provides precise prevention and control adapted to different scenarios, supports auditable traceability of ethical decision-making processes, and integrates professional standards to improve service reliability.
Smart Images

Figure CN121848362A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of embedded systems, artificial intelligence safety and behavior constraint technology, and specifically to an ethical decision-making chip, robot and ethical risk prevention and control method for home-based elderly care service robots. Background Technology
[0002] As artificial intelligence is increasingly applied in elderly care, service robots, while providing convenience, may also raise ethical and safety issues due to uncontrolled behavior, conflicting instructions, or biased decision-making, such as privacy breaches, risks of personal injury, and violations of user autonomy. The essence of these problems lies in the fact that, as autonomous decision-making systems, robots' behavior needs to be constrained by ethical norms that conform to human society, while current technology lacks effective means to translate abstract ethical requirements into enforceable technical rules.
[0003] The existing technology has the following technical defects: The coupling between ethical constraints and task processing is too high: the robot's main controller simultaneously undertakes the dual functions of task execution and ethical compliance. Once the main system malfunctions, is attacked, or generates decision ambiguity in a complex environment, the ethical constraint function will fail, which may cause the robot to perform dangerous actions that violate ethical norms. Lack of quantifiable ethical rule expression mechanism: Existing solutions treat ethical principles as abstract values and fail to transform them into calculable and executable technical parameters, such as rule priority, trigger threshold, weight coefficient, etc., resulting in an ambiguous, unverifiable, and unobjective evaluation process for ethical decision-making through technical means. Lack of scenario-adaptive ethical constraint mechanisms: The inability to dynamically adjust the priority and execution threshold of ethical rules according to different service scenarios leads to overly strict constraints affecting service quality in some scenarios, and overly loose constraints creating ethical risks in other scenarios. The ethical decision-making process is not transparent: it is difficult to retrospectively trace, define responsibilities, and optimize the system for the ethical decision-making process of robots, and when ethical risk events occur, there is no verifiable basis for decision-making. Ethical rules are out of sync with industry professional standards: Existing technologies have not deeply integrated professional standards related to elderly care services, such as nursing standards and medical assistance standards, into the ethical decision-making system. As a result, although the behavior of robots may comply with general ethical principles, it may not meet the professional requirements of specific service scenarios.
[0004] Therefore, there is an urgent need for a dedicated ethical constraint technology for home-based elderly care scenarios that can transform ethical requirements into quantifiable technical parameters, has independent hardware isolation, and can achieve precise risk classification and control. Summary of the Invention
[0005] The technical problem to be solved by this invention is to overcome the shortcomings of the prior art and provide an ethical decision-making chip, robot and ethical risk prevention and control method for home-based elderly care service robots that can transform ethical value systems into quantifiable technical constraint parameters and exist independently in hardware form.
[0006] To achieve the above objectives, the present invention adopts the following technical solution: First aspect: Ethical decision-making chip An ethical decision-making chip for home-based elderly care service robots includes a processor, a memory, and a computer program stored in the memory and executable on the processor. When the processor executes the program, it performs the functions of the following modules: The scene recognition module is used to identify the current service scene and the corresponding ethical and safety risk level based on the received sensor data and interaction information. The hierarchical ethical rules storage module stores a preset ethical rules system, including basic ethical rules that serve as behavioral bottom-line constraints and scenario-adaptive ethical rules used to guide behavior in service scenarios. The ethical rules are stored in the form of quantifiable technical parameters, which include rule priority coefficients, trigger thresholds, weight coefficients, and / or execution condition expressions. The ethics rule engine, connected to the scene recognition module and the hierarchical ethics rule storage module, is used to call the corresponding ethics rules and their quantitative parameters to perform multi-objective ethical trade-off calculations based on the identified scene and risk level. Among them, for the highest emergency risk level scene, the ethics rule engine enables the built-in instruction filtering feature library to perform real-time content security identification and blocking of input instructions. The ethics audit module is used to encrypt and store at least one of the following information in an immutable manner: device interaction logs, calculation basis for ethical decision-making processes, sensor data fragments, and records of human intervention. Input / output interfaces are used to connect the robot's main controller, sensors, and actuators.
[0007] Furthermore, the calculation basis of the ethical decision-making process includes the rules invoked, weight assignments, confidence scores, and / or decision paths.
[0008] Preferably, the basic ethical rules include at least one of the following: prioritizing personal safety, minimizing privacy data, respecting user autonomy, and ensuring operational traceability; the scenario adaptation ethical rules include at least one of the following: environmental adaptation, matching user habits, service continuity, and operational transparency.
[0009] Preferably, the decision logic of the ethics rule engine is derived in part or in whole from the occupational norms stipulated in the National Vocational Skill Standard for Elderly Care Workers, and is transformed into quantifiable technical parameters and operating procedures.
[0010] Preferably, the ethical safety risk level includes at least the highest emergency risk level and the specific scenario risk level; Furthermore, the scenarios corresponding to the specific scenario risk level include privacy protection, medical assistance, insurance claims assistance, and / or legal aid assistance.
[0011] Preferably, the ethical rule system includes at least two layers: Cornerstone Values: These are the bottom-line ethical principles that all robot behaviors must adhere to, including: Freedom, which means respecting users' autonomous choices; Equality, which means treating different users without discrimination; Order, which means abiding by laws, regulations, and basic social norms; and Honesty, which means maintaining consistency and transparency in behavior and information. Scenario-level values: Value orientations extracted for the specific field of home-based elderly care to guide specific service behaviors, including: Harmony, which refers to promoting family harmony and the user's physical and mental peace; Benevolence, which refers to embodying care and compassion; Integrity, which refers to being honest and trustworthy in service; Respect and Filial Piety, which refers to embodying respect for the elderly and the spirit of filial piety. The second aspect: Home-based elderly care service robots A home-based elderly care service robot includes a robot body, a main controller, sensor components, and an actuator. Unlike existing technologies, it also includes an ethical decision chip as described in the first aspect above. The ethical decision chip communicates with the main controller, sensor components, and actuator through its input / output interface and is used to perform independent hardware-level ethical and safety reviews and behavioral constraints on the decisions of the main controller or user instructions.
[0012] Third aspect: Methods for classifying and preventing ethical and safety risks An ethical risk prevention and control method based on the above-mentioned ethical decision-making chip includes the following steps: Receive multimodal data from robot sensors and the interactive interface; Identify the current service scenario and determine the corresponding ethical and security risk level. Based on the aforementioned ethical and safety risk level, activate the corresponding risk prevention and control strategy set; wherein: If the emergency risk level is the highest, then the emergency strategy set will be implemented, including: Use an instruction filtering feature library to identify and block instructions that violate ethical rules in real time; Request manual intervention when the decision confidence level falls below a threshold; The entire decision-making process data will be encrypted and recorded in the ethics audit module. If the risk level is specific to a particular scenario, then the corresponding policy set will be executed based on the specific scenario type; where: For privacy protection scenarios, the policy set includes: audio and video capture functions are turned off by default, ethical notification is given before activation, including voice prompts, the collected data is locally encrypted on the terminal, and the encryption key is bound to the chip hardware; For assisted medical scenarios, the strategy set includes: attaching an ethical disclaimer when providing medical and health information; and initiating a manual review process when the confidence level is below a threshold when performing drug identification functions to ensure compliance with the ethical principle of "no harm".
[0013] Preferably, the method further includes: iteratively optimizing the decision rules and their quantitative parameters in the instruction filtering feature library and / or the ethics rule engine based on the data recorded in the ethics audit module and user feedback.
[0014] The beneficial effects of this invention are: Ethical rules are quantifiable and enforceable: By transforming abstract ethical principles into quantifiable technical parameters, such as priority coefficients, trigger thresholds, weight coefficients, and execution condition expressions, ethical constraints are transformed from subjective values into calculable and verifiable technical rules. This solves the technical problem that ethical rules cannot be embedded in technical systems and realizes the objective expression of ethical requirements. Hardware-level ethical constraint isolation: Through an independent ethical decision chip, an ethical monitoring layer physically isolated from the main control system is realized. This ensures that the ethical decision chip can still operate independently and execute the bottom-line ethical rules when the main system is abnormal, malfunctions, or attacked. This fundamentally solves the technical problem in traditional solutions where the ethical constraint function is too highly coupled with the main system and the ethical constraints fail once the main system fails. Precise prevention and control based on scenario adaptation: By defining a hierarchical ethical rule system and ethical safety risk level that are closely related to home-based elderly care scenarios, it achieves refined ethical strategy control for different service scenarios, which solves the technical problem that existing technologies have single ethical rules and cannot dynamically adapt to changes in scenarios; Auditable and traceable ethical decision-making process: Through the ethical audit module, key data of the ethical decision-making process is recorded completely and immutably, including rule call paths, weight assignments, confidence scores, decision paths, etc., providing a reliable data foundation for post-event responsibility determination, system optimization, and ethical review, and solving the technical problems of opaque and untraceable ethical decision-making processes; Deep integration of professional standards: By transforming the professional standards in the "National Vocational Skill Standards for Elderly Care Workers" into executable technical parameters and operating procedures, it is ensured that the service behavior of robots not only conforms to general ethical principles, but also meets the professional standards of the elderly care service industry, thereby improving the reliability of services and social acceptance. A hardware-software integrated ethical constraint architecture is formed: hardware-level ethical computing and secure storage are achieved through a dedicated chip, combined with the task processing capabilities of the main controller, to build a complete ethical and security technology closed loop from the underlying hardware to the upper-layer application, ensuring ethical constraints without affecting the task processing performance and response speed of the main system. Attached Figure Description
[0015] Figure 1 This is a schematic diagram of the hardware architecture of one embodiment of the ethical decision-making chip of the present invention; Figure 2 Example graph of quantization parameters; Figure 3 A schematic diagram illustrating the workflow of a home-based elderly care service robot that integrates an ethical decision-making chip; Figure 4 This is a basic flowchart of an ethical risk prevention and control method based on an ethical decision-making chip. Detailed Implementation
[0016] The technical solutions are clearly and completely described below with reference to embodiments of the present invention. The described embodiments are only some, not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without inventive effort are within the scope of protection of the present invention.
[0017] Example 1: Basic Architecture and Workflow of an Ethical Decision-Making Chip This embodiment provides an ethical decision-making chip for home-based elderly care service robots and its basic workflow to illustrate the core architecture and basic principles of the present invention.
[0018] Hardware architecture of the ethical decision-making chip: like Figure 1 As shown, the ethics decision chip 1, as an independent embedded system module, includes: The processor (CPU / MCU) 11, as the core computing unit of the chip, is used to execute the logic of each software module; The memory 12 includes non-volatile memory (such as Flash) and volatile memory (such as RAM). The non-volatile memory is used to store the fixed program code, instruction filtering feature library, and hierarchical ethical rule data, including the quantification parameters of the rules and the program logic of the ethical rule engine. The volatile memory is used for data processing and temporary caching during program execution. Input / output interface (I / O) 13 includes general purpose input / output (GPIO) pins, serial communication interfaces (such as UART, SPI, I2C), and general purpose serial bus (USB) interfaces, used for data communication with the robot's main controller, various sensors, and actuators; The sensors include cameras, microphones, infrared sensors, and pressure sensors, etc. The actuator includes a robotic arm, a mobile chassis motor controller, and a speaker, etc. The cryptographic security unit 14, an optional but preferred hardware component, such as an integrated hardware security module (HSM) or a trusted execution environment (TEE), provides underlying cryptographic operation support and secure key storage for the ethics audit module, ensuring the immutability of the stored data. The key is bound to the chip hardware to prevent key theft under physical attacks.
[0019] When the computer program stored in memory 12 is executed by processor 11, it implements the following functional modules: 1. Scene Recognition Module The scene recognition module continuously receives sensor data streams and interaction information from the input / output interface 13, and identifies the current service scene in real time using a pre-trained lightweight machine learning model or rule matching algorithm. The pre-trained lightweight machine learning model can be, for example, a lightweight neural network model such as MobileNet or YOLO optimized for key scenarios.
[0020] The sensor data stream includes visual data, audio stream, and environmental parameters; The interactive information includes voice commands and touch screen operations.
[0021] Example of scene recognition: The system detected that the user had been stationary on the ground for an extended period of time and exhibited an abnormal posture. Combined with the absence of weight data from the pressure sensor, the scenario was determined to be an "elderly person falling". The system detects that a user is holding a medicine bottle and interacts with the robot via voice by asking "What medicine is this?", classifying the scenario as "drug identification and assisted medical treatment". If the system detects a user's instruction to "not record" or if the robot is located in a preset sensitive area such as a bedroom or bathroom, it is determined to be a "privacy-sensitive scenario".
[0022] Meanwhile, the scene recognition module has a built-in "scene-risk level mapping table." Based on the identified scene, this table is queried to determine the corresponding ethical and safety risk level. For example: "Users issuing instructions to self-harm or harm others" is mapped to "highest emergency risk level"; "Processing user health data" and "Performing assisted medication administration operations" are mapped to "Specific scenario risk level (assisted medical care)"; "Robots operating in sensitive areas such as bedrooms" is mapped to "specific scenario risk level (privacy protection)".
[0023] 2. Hierarchical Ethics Rules Storage Module The hierarchical ethics rule storage module allocates a protected storage area in non-volatile memory to store a preset ethical rule system, which includes at least two layers: Basic ethical rules: These are the bottom-line ethical rules that all robot behavior must adhere to, stored in the form of quantifiable technical parameters, such as: Personal safety priority: Priority coefficient = 1.0, the highest priority coefficient. Triggering condition: Any decision scenario related to user personal safety, such as... Figure 2 As shown; Privacy data minimization: Priority coefficient = 0.9, triggering condition: scenarios involving the collection of user biometrics, location, and audio / video data; Respect for user autonomy: Priority coefficient = 0.8, triggering condition: interactive scenarios that require user confirmation or selection; Operation traceability: Priority coefficient = 0.7, trigger condition: all critical operation scenarios, recording threshold = 1.0, indicating that all operations need to be recorded.
[0024] Scenario-Adaptive Ethical Rules: Ethical rules extracted specifically for the field of home-based elderly care to guide specific service behaviors are stored in the form of quantifiable technical parameters, such as: Environmental Adaptation: Weighting coefficient = 0.6, Triggering condition: Adjust operating parameters when ambient light is <50 lux or space is confined; User habit matching: weight coefficient = 0.7, trigger condition: when a specific user operation pattern is detected, the response method is adapted; Service continuity: Weighting coefficient = 0.5, triggering condition: when service interruption may pose a risk, service should be maintained first; Operational transparency: Weighting coefficient = 0.8, triggering condition: A voice prompt must be given before any operation involving sensitive user information.
[0025] All rules are stored in structured data format, including: rule ID, rule name, type (including basic / scenario), quantization parameter set (including priority coefficient, weight coefficient, trigger threshold), execution condition expression (Boolean logic expression), and associated strategy set ID.
[0026] 3. Ethical Rules Engine The ethics rule engine is the core of the chip's decision-making process. It receives "scene" and "risk level" information from the scene recognition module and calls the ethics rules and their quantitative parameters that are most relevant to the current scene from the hierarchical ethics rule storage module.
[0027] The ethics rules engine integrates a decision rule base, which incorporates the professional norms in the "National Vocational Skill Standards for Elderly Care Workers".
[0028] For example, the requirement of "respecting the privacy rights of the elderly" in the "National Vocational Skill Standard for Elderly Care Workers" has been transformed into technical rules: "In privacy-sensitive scenarios, the priority coefficient of the 'minimization of privacy data' rule is increased to 1.0, and the weight coefficient is increased to 0.9, taking precedence over the convenience of data collection."
[0029] For specific risk levels in different scenarios, the ethics rule engine performs multi-objective ethical trade-off calculations: Taking "whether to automatically activate video notification for family members after a fall" as an example, the ethics rule engine performs quantitative calculations: "User Safety" score = "Personal Safety Priority" rule × Priority coefficient 1.0 × Current scenario weight, with a preset weight of 0.9 for fall scenarios; "User Privacy" Score = "Privacy Data Minimization" rule applied × Priority coefficient 0.9 × Current scenario weight, with a preset privacy scenario weight of 0.8; Based on a preset decision threshold, such as 0.7, the system outputs a decision suggestion. For example, if the calculated "user safety" score is 0.85 and the "user privacy" score is 0.72, the output would be: First, ask the user via voice, "Should we notify the family?" If there is no response within 10 seconds, then automatically start the video and transmit only keyframes.
[0030] For scenarios with the highest level of emergency risk, the ethics rule engine will immediately activate a built-in instruction filtering feature library: This feature database contains keywords and semantic patterns of instructions that violate ethical rules, such as those involving personal injury, equipment damage, system destruction, and illegal content, and is stored in the form of feature vectors. The ethics rule engine performs real-time content security scanning on all received external input instructions, especially those converted from speech to text, and calculates the matching degree between the input instruction and the feature database. When the matching degree exceeds a preset threshold (e.g., 0.85), the ethics rule engine will directly send a blocking signal to the main controller, generate a security alarm, and transfer the decision-making authority to a preset human monitoring platform.
[0031] 4. Ethics Audit Module The ethics auditing module utilizes the support of the cryptographic security element 14 to create a circularly overwritten but immutable encrypted log area in memory. It automatically logs the following information: Decision log: timestamp, triggering scenario, input data summary (hash value), reasoning path of the ethics rule engine, such as the rule ID called, quantification parameter values, intermediate calculation results, and final decision output; Key data snippets: In the event of a security incident or manual audit, encrypted copies of the original sensor data (such as image frames and audio clips) from a period of time prior to the triggering decision can be associated and stored. Human intervention record: When the robot requests or receives remote human intervention, it records the intervention personnel ID, intervention instructions, and execution results.
[0032] All records are encrypted and signed with the chip's unique key before being written, ensuring their integrity and authenticity can be verified afterward. The encryption key is stored in the protected area of the encryption security unit 14 and is bound to the chip hardware, making it unreadable even if the chip is physically disassembled.
[0033] Home-based elderly care service robot system integration like Figure 3 As shown, the workflow of a home-based elderly care service robot integrating the aforementioned ethical decision-making chip 1 is as follows: Robot main controller 2 is responsible for overall task planning and motion control; When a task needs to be performed (such as responding to a medication reminder) or when a direct instruction from the user is received (such as "help me throw this away"), the main controller 2 does not execute it immediately. Instead, it sends the task or instruction information to the ethics decision chip 1 via the bus for ethical and safety review. The input / output interface 13 of the ethics decision chip 1 receives this information and simultaneously receives real-time environmental data from sensor components 3 (such as cameras, microphones, etc.). The scene recognition module combines the two for comprehensive analysis to identify the current context, and the ethics rule engine performs ethical calculations based on the recognition results. If the review is approved, the ethics decision chip 1 sends a "permission to execute" signal and possible constraints to the main controller 2 (such as "full voice notification is required during execution"). If the review fails or modifications are required, the ethics decision chip 1 sends a "rejection" signal or "modification suggestion" to the main controller 2. If the highest emergency risk is triggered, the ethical decision chip 1 will directly block the command and trigger an alarm.
[0034] Key data from the entire review process is recorded by the ethics audit module. Based on the output of the ethics decision chip 1, the main controller 2 ultimately directs the execution mechanism 4 (such as a robotic arm, mobile chassis, speaker, etc.) to complete the action.
[0035] Basic process of ethical risk prevention and control methods Based on the aforementioned ethical decision-making chip, the basic process of its ethical risk prevention and control method is as follows: Figure 4 As shown, it includes: S101, Data Reception: Continuously receive multimodal data streams from robot sensors and the interactive interface; S102, Scenario and Risk Level Identification: Based on real-time data stream, identify the current specific service scenario and query the preset "Scenario-Risk Level Mapping Table" to determine the ethical and safety risk level (e.g., highest emergency risk level, specific scenario-medical, specific scenario-privacy, etc.). S103, Strategy Set Activation and Execution: Activate and execute differentiated combinations of prevention and control strategies based on different risk levels; If the highest emergency risk level is reached: activate the highest level strategy set, which includes: Command filtering and blocking: Immediately activate the command filtering feature library to scan input commands, calculate the matching degree, and block and alarm if the value exceeds the threshold; Forced manual intervention: In this scenario, even if the system has decision suggestions, it will automatically initiate a manual confirmation request to the remote monitoring center; Full-process ethical audit record: All data and decision-making processes related to this event are fully encrypted and stored in the ethical audit module; If the risk level is specific to a particular scenario (such as privacy protection): activate the policy set customized for that scenario. The policies include: Default Off and Ethical Notice: The functions of relevant sensors (such as cameras) are off by default. If activation is required, the user must be informed through a clear voice prompt that data collection will begin and immediate confirmation must be obtained. Localized data processing: The collected audio and video data is locally encrypted and stored in the robot terminal, and will not be uploaded to the cloud without the user's re-authorization. The encryption key is bound to the chip hardware. If the risk level is specific to a particular scenario (e.g., assisted medical care): Activate the strategy set customized for that scenario. The strategies include: Ethical Disclaimer: When providing medical and health information, an automatic voice / text statement is attached: "The above information is from public databases and is for reference only. It cannot replace the diagnosis and advice of professional physicians." Confidence threshold judgment and manual review: A pre-set confidence threshold (e.g., 85%) is set. When the confidence of drug identification is lower than the threshold, the manual review process is automatically initiated, and a review request is sent to the remote support center. S104, Decision Execution and Recording: Execute the final action after ethical review and record the entire chain of information of this interaction to the ethics audit module.
[0036] Example 2: Preferred Implementation Based on the basic example in Example 1, this example is a preferred example, which further illustrates the advantages of the present invention through more specific scenario descriptions, more optimized decision-making logic, and the system's self-evolution capability.
[0037] Preferred Example 1: Preferred Implementation Method in Assisted Medical Scenarios In the specific risk level scenario of "assisted medical care", ethical decision-making chips and methods can carry out prevention and control with more refined strategies.
[0038] 1. Refined Scene Recognition The scene recognition module can not only identify the broad category of "assisted medical care," but also further subdivide it through visual and contextual analysis, such as sub-scenes like "drug identification and query," "medication time reminder," and "assistance with medication retrieval / preparation." Different sub-scenes are associated with different ethical rule weights. "Drug Identification and Inquiry": The "Operational Transparency" rule (weight 0.8) and "Respect for User Autonomy" rule (weight 0.7) are the main criteria. "Assisting with medication preparation / dispensing": Emphasis is placed on "personal safety first" (weight 1.0) and "operation traceability" (weight 0.9).
[0039] 2. Quantitative Application of Hierarchical Ethical Rules In this scenario, ethical rules are invoked in the form of quantified parameters: "Personal safety first": Priority coefficient 1.0, trigger threshold 0.9 (i.e., mandatory intervention when the safety risk score > 0.9); "Respect for user autonomy": Priority coefficient 0.8, weight coefficient 0.7; "Operational Transparency": Priority coefficient 0.7, weight coefficient 0.8; "Operation Traceable": Priority coefficient 0.6, Recording level = Detailed (records all operation steps).
[0040] 3. Specific implementation of the strategy set Information provided with an attached ethical disclaimer: When the robot provides users with information such as the uses and side effects of a certain drug based on a database, the ethics rule engine will automatically attach a voice / text statement before or after the information is broadcast: "The above information is from a publicly available drug database and is for reference only. It cannot replace professional medical diagnosis and advice." The trigger conditions for this statement are: Scenario = "Assisted Medical Care" and Operation Type = "Information Provision".
[0041] Multiple verifications and manual review of critical operations: a. Drug visual recognition: When a user requests drug recognition, the chip calls the visual recognition model, which outputs the recognition result (e.g., "Aspirin Enteric-coated Tablets") and a confidence score (e.g., 92%). b. Confidence threshold determination: The ethics rule engine presets a threshold (85%), which is stored in the hierarchical ethics rule storage module as one of the quantitative parameters of the "personal safety first" rule. If the confidence level is higher than the threshold, the user will be directly informed of the result and the aforementioned disclaimer will be attached. c. Low Confidence Triggers Manual Review: If the confidence level is below a threshold (e.g., only "white round pills" are identified, with a confidence level of 65%), the ethics rule engine will determine the decision as "high uncertainty medical advice" and immediately activate the strategy—the robot explains to the user: "The confidence level for this medication identification is low. To ensure your safety, I will transfer you to a pharmacist for manual review." Simultaneously, a review request is sent to the remote support center through the system, and the collected image of the medicine bottle is encrypted and uploaded along with it. This entire process is recorded in the ethics audit module.
[0042] Deep integration with nursing standards: The rules on "assisting in taking medication" in the ethics rule engine directly reference the key points of the process of "assisting the elderly in taking medication" in the "National Vocational Skill Standard for Elderly Care Workers", such as "verifying the doctor's order and medication" and "observing the reaction after taking medication", and transform them into the robot's operation checklist and behavioral logic, which are stored in the rule base in the form of quantitative parameters.
[0043] Preferred Example 2: Preferred Implementation Method in Privacy Protection Scenarios In the specific risk level scenario of "privacy protection", the implementation method emphasizes "pre-disclosure, in-process transparency and post-event controllability", and all rules are implemented in the form of quantitative parameters.
[0044] 1. Dynamic privacy zone identification and risk level quantification The scene recognition module, combined with SLAM (Simultaneous Localization and Mapping) technology, can not only identify functional scenes but also physical space attributes. When the robot recognizes itself as being in a user-defined private area such as a "bedroom" or "bathroom" through pre-labeling or learning, it automatically increases the privacy risk level coefficient from the default 0.5 to 0.9, with a value range of 0-1.
[0045] 2. Quantitative Implementation of a Tiered Notification and Confirmation Mechanism Level 1 notification, upon function activation: When any audio / video capture function is triggered for the first time by a system task or user command (such as initiating a nighttime security patrol), the robot must announce in a clear and easy-to-understand voice: "Indoor environmental monitoring is about to begin. During this period, cameras and sensors will be used briefly. The data will only be used for security purposes. Do you agree?" Users can respond with explicit commands "Agree" / "Cancel" or the emergency button. The triggering conditions for this notification are: privacy risk level coefficient > 0.5 and the function being activated for the first time.
[0046] Level 2 notification upon entering a privacy area: Even with monitoring enabled, when the robot is about to enter a designated privacy area, it will pause at the door and provide a voice prompt: "Approaching the bedroom. Please confirm if you wish to proceed." If no confirmation is received within 10 seconds, the robot will either monitor from outside the area or wait. The decision-making logic for this behavior is as follows: if the privacy risk level coefficient is >0.8 and the entry behavior is triggered, a notification-wait-decision loop is executed.
[0047] 3. Quantitative Implementation of Data Lifecycle Management Strategies Terminal-level local encrypted storage: All audio and video data collected in privacy-sensitive scenarios is encrypted and stored by default in the secure storage area of the ethics decision chip or the robot's local storage area. The encryption key is stored in the encrypted security unit 14 and is bound to the chip hardware. The trigger condition for this policy is: privacy risk level coefficient > 0.5.
[0048] User-authorized upload: If this data needs to be uploaded to the cloud for family members to view or for long-term analysis, explicit secondary authorization from the user must be obtained through a user interface (such as a tablet app). During authorization, the scope of data to be uploaded (e.g., uploading only fragments of abnormal events) and the validity period can be selected. The parameters for this policy include: the authorization validity period (default 7 days), and the upload scope, with options for "abnormal events only" or "all".
[0049] Automatic expiration and deletion: The ethics rules engine can set data retention rules, such as "normal patrol videos are automatically deleted after 24 hours" and "fall incident videos are deleted after 30 days." The deletion action is an irreversible secure erasure, performed by the encrypted security unit 14. These rules are stored in the form of quantified parameters: data type, retention duration, and deletion method.
[0050] Preferred Example 3: Iterative Optimization of the System The ethical constraint system of this invention has a data-based self-optimization capability, which is achieved through closed-loop feedback via the ethical audit module.
[0051] 1. Data Collection The ethics audit module not only records "events" but also the user's subsequent feedback on the robot's behavior. For example, after the "remind to take medication" event, if the user shows annoyance (through voice emotion analysis or by directly saying "too noisy"), this feedback will be recorded in a contextualized manner, forming a triplet of scenario, decision, and feedback data.
[0052] 2. Regular analysis and rule-based quantitative parameter optimization System administrators or developers periodically (e.g., monthly) export and analyze encrypted logs from the ethics audit module (after authorized decryption). The analysis should focus on: False positive / false negative rate analysis of the instruction filtering feature library: This involves statistically analyzing the number of times normal instructions were mistakenly blocked due to dialects or accents (false positives), and the number of times new abnormal expressions were not recognized (false negatives). Based on this, the filtering feature library and semantic model are updated, and the matching threshold parameter is adjusted, for example, from 0.85 to 0.82. Effectiveness analysis of decision-making rules: This analysis examines which scenarios frequently lead to negative user feedback or require manual intervention. For example, the analysis revealed that "getting up to go to the bathroom at night" was frequently misjudged as "falling," resulting in unnecessary alarms. Subsequently, the confidence threshold parameter of the visual recognition algorithm in this scenario was adjusted from 0.7 to 0.85, achieving a better balance between "safety" and "disruption." Optimization of ethical rule weights: Through statistical analysis of numerous cases, the weight coefficients of rules such as "privacy protection" and "security assurance" in different scenarios were fine-tuned. For example, statistics show that 80% of users are more concerned about safety outside of private areas, so the weight of "personal safety first" in public areas was increased from 0.8 to 0.9, while the weight of "minimizing privacy data" remained at 0.9 in private areas.
[0053] 3. Online updates The optimized instruction filtering feature library, decision rule package, quantization parameters (thresholds, weight coefficients) or model parameters can be updated and sent to the ethical decision chip memory of the robot terminal via a secure over-the-air (OTA) transmission, completing the iterative upgrade of the system. The update package is encrypted using the chip's public key to ensure secure transmission.
[0054] The above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. An ethical decision-making chip for home-based elderly care service robots, characterized in that, It includes a processor, a memory, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the program, performs the functions of the following modules: The scene recognition module is used to identify the current service scene and the corresponding ethical and safety risk level based on the received sensor data and interaction information. The hierarchical ethical rules storage module stores a preset ethical rules system, including basic ethical rules that serve as behavioral bottom-line constraints and scenario-adaptive ethical rules used to guide behavior in service scenarios. The ethical rules are stored in the form of quantifiable technical parameters, which include rule priority coefficients, trigger thresholds, weight coefficients, and / or execution condition expressions. The ethics rule engine, connected to the scene recognition module and the hierarchical ethics rule storage module, is used to call the corresponding ethics rules and their quantitative parameters to perform multi-objective ethical trade-off calculations based on the identified scene and risk level. Among them, for the highest emergency risk level scene, the ethics rule engine enables the built-in instruction filtering feature library to perform real-time content security identification and blocking of input instructions. The ethics audit module is used to encrypt and store at least one of the following information in an immutable manner: device interaction logs, calculation basis for ethical decision-making processes, sensor data fragments, and records of human intervention. Input / output interfaces are used to connect the robot's main controller, sensors, and actuators.
2. The ethical decision-making chip according to claim 1, characterized in that, The calculation basis for the ethical decision-making process includes the rules invoked, weight assignments, confidence scores, and / or decision paths.
3. The ethical decision-making chip according to claim 1, characterized in that, The basic ethical rules include at least one of the following: prioritizing personal safety, minimizing privacy data, respecting user autonomy, and ensuring operational traceability; the scenario adaptation ethical rules include at least one of the following: environmental adaptation, matching user habits, service continuity, and operational transparency.
4. The ethical decision-making chip according to claim 1, characterized in that, The decision rules of the ethics rule engine are generated or conform to the professional norms stipulated in the National Vocational Skill Standards for Elderly Care Workers, at least in part, and are transformed into quantifiable technical parameters.
5. The ethical decision-making chip according to claim 1, characterized in that, The ethical and safety risk levels include at least the highest emergency risk level and the specific scenario risk level; the specific scenario risk level corresponds to scenarios including privacy protection, medical assistance, insurance claims assistance, and / or legal aid assistance.
6. A home-based elderly care service robot, comprising a robot body, a main controller, sensor components, and an actuator, characterized in that, It also includes an ethics decision chip as described in any one of claims 1-5, wherein the ethics decision chip is communicatively connected to the main controller, sensor components and actuators through its input / output interface, and is used to perform independent hardware-level ethical and security review and behavioral constraints on the decisions of the main controller or user instructions.
7. A method for preventing ethical risks based on the ethical decision-making chip according to any one of claims 1-5, characterized in that, include: Identify the ethical and safety risk level of the current scenario; Based on different risk levels, activate and execute the corresponding risk control strategy set; Among them, the strategy set for the highest emergency risk level includes content filtering, requests for manual intervention, and ethical audit records; A set of strategies for risk levels in specific scenarios, depending on the specific scenario type, includes at least one of the following: ethical notification before function activation, partial data encryption, additional ethical disclaimers, and manual review of key operations.
8. The method according to claim 7, characterized in that, In privacy protection scenarios, the policy set includes: audio and video capture functions are turned off by default, ethical notification is given before activation, the captured data is partially encrypted on the terminal, and the encryption key is bound to the chip hardware.
9. The method according to claim 7, characterized in that, In assisted medical scenarios, the strategy set includes: attaching an ethical disclaimer when providing medical and health information; and initiating a manual review process when the confidence level is lower than a preset threshold when performing drug identification functions.
10. The method according to claim 7, characterized in that, Also includes: Based on the data recorded in the ethics audit module, the decision rules and their quantification parameters in the instruction filtering feature library and / or the ethics rule engine are iteratively optimized.