Humanoid robot behavior monitoring and safety intervention device based on power supply ripple frequency spectrum identification
By monitoring the current ripple of the main control CPU power supply rail and using the energy spectrum entropy value to determine malicious attacks, an independent microprocessor triggers physical intervention, solving the problem of slow response speed in existing technologies and achieving millisecond-level security defense and irreversible physical isolation.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SHENZHEN BAIMAXUN NETWORK TECHNOLOGY CO LTD
- Filing Date
- 2026-03-19
- Publication Date
- 2026-04-17
AI Technical Summary
Existing technologies are unable to quickly and effectively prevent malicious attackers from controlling smart devices to perform malicious operations. Software-based detection is slow and cannot prevent attacks in a timely manner.
By monitoring the current ripple of the main control CPU power supply rail with an independent microprocessor, and using the energy spectrum entropy value offset to determine malicious attacks, the physical intervention unit is triggered to cut off the power supply of the actuator, achieving millisecond-level intervention and preventing malicious operations.
It achieves millisecond-level physical-level blocking, instantly cutting off power before malicious operations are completed, ensuring safety and irreversibility, with strong anti-bypass capabilities and independent power supply to ensure intervention reliability.
Abstract
Description
Technical Field
[0001] This invention belongs to the field of security monitoring technology, specifically relating to a humanoid robot behavior monitoring and security intervention system and method based on power ripple spectrum recognition. It is applicable to high-security, tamper-proof monitoring and unrecoverable physical intervention by malicious attackers for intelligent devices with dynamic power consumption behavior in key fields such as industrial production, intelligent transportation, and national defense security. Background Technology
[0002] With the widespread adoption of AI agents in critical scenarios, malicious attackers can control these agents to perform offensive operations (such as stealing data or manipulating physical devices) through malicious commands. Existing solutions rely on software detection, resulting in slow response times and an inability to prevent attacks in a timely manner. This invention addresses this by non-intrusively acquiring the current ripple of the main control CPU's power supply rail. An independent microprocessor determines the malicious attacker's control behavior based on the offset of the energy spectrum entropy value (a continuous energy spectrum entropy value offset >10% and a duration exceeding 5ms), triggering a physical intervention unit to cut off the power supply to the actuator, achieving millisecond-level intervention and preventing the execution of malicious operations. Summary of the Invention
[0003] (a) Purpose of the invention This invention relates to a security monitoring device for preventing malicious attackers from controlling an AI agent to perform malicious operations. Its core function is to monitor the current ripple of the main control CPU's power supply rail in real time via an independent microprocessor. When a specific anomaly (energy spectrum entropy value shift >10% and lasting >5ms) caused by a malicious attacker's control behavior is detected, the device immediately cuts off the power supply to the actuator (such as a robot joint motor), thus blocking the physical execution of the malicious operation. (II) Technical Solution To achieve the above-mentioned objectives, the present invention adopts the following technical solution: 1. Physical Architecture: Heterogeneous Asynchronous Isolated Monitoring Environment The core of this device lies in establishing a security monitoring subsystem that is completely decoupled from the main control unit of the artificial intelligence entity (hereinafter referred to as "main control CPU") in terms of physical layer, timing layer and power supply logic. Physical decoupling: The monitoring device uses an independent microprocessor (Security MCU), whose main clock frequency is asynchronous with the main control CPU, and the two have no direct physical connection (such as data bus, control signal line), achieving complete physical layer isolation and avoiding interference from abnormal signals on the main control CPU side. Signal extraction: A milliohm sampling resistor is connected in series on the power supply rail (VCC / VDD) of the main control CPU (for accurate acquisition of instantaneous current), or a high-bandwidth inductor sensing unit is connected in parallel next to the power supply rail (for non-intrusive induction of current ripple). One of the two methods can be used (the inductor sensing unit cannot be directly connected in series to avoid affecting the stability of the power supply) to extract the instantaneous current ripple generated by the main control CPU when executing instructions. Independent power supply: The monitoring device is equipped with an independent energy storage unit (supercapacitor or lithium battery) and is completely isolated from the main control CPU power supply system. This ensures that even if the main power supply is hijacked, disconnected, or experiences an abnormal power outage, the monitoring logic can still complete the final intervention action, thus avoiding monitoring failure due to power interruption. 2. Core Logic: The Conversion from Electrical Physical Quantities to Behavioral Semantics This solution avoids traditional bus data monitoring and instead utilizes the electromagnetic characteristics and current ripple generated by the switching activity of the main control CPU transistors to achieve "physical lie detection" of the robot's operating status. The core is to complete the accurate mapping from electrical physical quantities to behavioral semantics. The monitoring device has a sampling rate sufficient to capture the main frequency band of the current ripple generated under the typical workload of the main control CPU. Through a high-speed hardware FFT (Fast Fourier Transform) engine, the time-domain current signal is converted into a behavioral spectrum feature map in real time, preserving the core features of transistor switching activity. Semantic fingerprinting: Using machine learning models (such as lightweight CNNs), extracted spectral features are mapped to predefined behavioral semantic labels (normal / abnormal commands), realizing the transformation from electrical features to behavioral semantics; specifically, it is divided into two categories: spectral band determination. Legitimate spectrum bands: Pre-stored characteristic energy spectrum distribution ranges and entropy ranges of AI agents during normal execution (such as balance gait, sensor fusion), serving as a safety template. Abnormal spectrum bands: Identify ultra-high frequency harmonic noise (with a significant entropy difference from normal spectrum bands) caused by abnormal switching of transistors due to instruction injection, logic overflow, illegal privilege escalation, or malicious code execution. Semantic determination: When the real-time detected energy spectrum entropy value deviates from the preset safety template threshold for more than a certain number of consecutive sampling periods, and the deviation exceeds 10% (to avoid misjudgment caused by instantaneous fluctuations), it is immediately determined to be in a "logical out-of-control state" without confirmation by the main control CPU, ensuring the accuracy and timeliness of the determination. 3. Implementation mechanism: Unconditional physical intervention Intervention path: The output of the monitoring device is physically connected to the electronic fuse (E-Fuse) or electromagnetic cut-off switch of the main power supply bus of the main control CPU to ensure that the power source of the main control CPU can be directly cut off, and to prevent the intervention path from being bypassed. Response closed loop: Once an anomaly is detected, the intervention signal will quickly drive the actuator within the response range of the corresponding device—the electromagnetic cut-off switch has a response time of up to microseconds, and the electronic fuse (E-Fuse) has a response time of up to microseconds, realizing the physical disconnection between the power supply and the main control CPU, forming a closed loop of "detection-judgment-intervention". State solidification: After the fuse / cutoff action is completed, the system enters a "physical lockout" state. Since the intervention loop does not pass through the main control CPU and its TEE (Trusted Execution Environment), malicious attackers cannot restore the system via remote software or remote communication without physical contact, ensuring the irreversibility of the intervention. The monitoring device calculates the energy spectrum entropy value of the current spectrum and the pre-stored legitimate template based on the current ripple spectrum characteristics. When this entropy value deviates from the preset safety template threshold for multiple consecutive sampling periods, and the deviation exceeds 10%, it is determined to be a malicious attacker's control behavior. After multiple tests, the simulated malicious attacker behavior resulted in entropy value deviations of >10%, so the threshold was set to >10%. (III) Beneficial Effects The present invention has the following significant beneficial effects: 1. Millisecond-level active defense: By determining the cross-correlation coefficient of current ripple (energy spectrum entropy value shift >10% for >5ms) and linking it with electronic fuse (response ≤5ms), physical-level blocking with a total intervention time ≤10ms is achieved, which is more than 100 times faster than traditional software solutions, effectively preventing malicious attackers from controlling the actuator before malicious operations are completed; 2. Precise physical isolation: Millisecond-level triggering of electronic fuses to cut off or physical switches to disconnect, significantly improving safety; 3. Bypass resistance: The monitoring and intervention loop is completely independent of the main control CPU (physical / timing / power supply triple isolation), with no remote reset interface, ensuring irreversible intervention; 4. High reliability: The independent power supply unit ensures that intervention can still be completed when the main power supply is abnormal. Detailed Implementation
[0004] 1. Application Scenarios of Humanoid Robots Scenario: Malicious attackers remotely control humanoid robots (such as bipedal robots) to perform aggressive actions (such as rapidly punching a target). Implementation plan: Monitoring process: When the robot's main control CPU executes malicious commands, abnormal current ripple characteristics occur (such as a sudden increase in high-frequency harmonics). The current ripple acquisition unit (with a series milliohm sampling resistor) captures the current waveform in real time, and an independent microprocessor calculates the spectral cross-correlation coefficients through a hardware FFT engine. When the coefficient continuous energy spectrum entropy value shifts by more than 10% and lasts for more than 5ms (such as detecting abnormal characteristics of malicious command injection), it is determined to be a malicious attacker's control behavior. Intervention actions: The physical intervention unit (connected to the power supply line of the robot's hip / elbow joint motors) triggers the electronic fuse (response time ≤ 5ms) to cut off the power supply to the joint motors. Effect: The punching motion was blocked within 10ms (before the malicious command was executed to the physical action), the system entered an unrecoverable state for the malicious attacker (manual reset of the fuse is required), and the malicious attacker's attack was not completed.
[0005] 2. Industrial robot application scenarios Scenario: A malicious attacker controls an industrial robotic arm (such as a six-axis collaborative robot) to perform high-risk operations (such as the robotic arm rapidly extending and crashing into equipment). Implementation plan: Monitoring process: When the robotic arm's main control CPU executes an illegal instruction, the current ripple spectrum entropy value deviates (significantly different from the normal "sensor fusion" state). The current ripple acquisition unit (parallel high-bandwidth inductor sensing unit) non-invasively extracts the ripple, and an independent microprocessor calculates the cross-correlation coefficient. When the coefficient continuous energy spectrum entropy value deviates by more than 10% and lasts for more than 5ms (e.g., if an illegal weighting instruction is detected), it is judged as abnormal. Intervention actions: The physical intervention unit (connected to the power supply line of the robotic arm joint motor) drives the electromagnetic cut-off switch (response time ≤ 5ms) to cut off the motor power supply. Effect: The robotic arm extension action terminated within 10ms. The equipment was not damaged, but the system entered an unrecoverable state for the malicious attacker (manual reconnection of the communication link is required). The malicious attacker's operation was physically blocked. Once the system enters a physically locked state, the security intervention circuit permanently cuts off the power supply to the main control CPU and disables all remote reset interfaces (including network, Bluetooth, and serial ports). Recovery can only be achieved through a physical reset switch (such as a mechanical switch manually triggered by the user), ensuring that malicious attackers cannot recover the system through software or remote means.
Claims
1. A security monitoring device for preventing malicious attackers from controlling a humanoid robot to perform malicious operations, characterized in that, include: The current ripple acquisition unit is connected to the power supply rail of the humanoid robot's main control unit and is used to extract the instantaneous current ripple generated when the main control unit executes commands. An independent microprocessor, completely isolated from the humanoid robot's main control unit in terms of physical layer, timing layer, and power supply logic, calculates the energy spectral entropy value of the current spectrum based on the current ripple. The physical intervention unit is used to trigger the electronic fuse to cut off or the physical switch to open when the energy spectrum entropy value exceeds a predetermined threshold.
2. The safety monitoring device according to claim 1, wherein, The physical intervention unit includes: The electronic fuse that cuts off the power supply line to the actuator; Or an electronic fuse that cuts off the power supply to the main control CPU; Alternatively, disconnect the physical switch of the humanoid robot's communication link or power supply line.
3. The safety monitoring device according to claim 1, wherein, The irreversible intervention refers to: Malicious attackers cannot restore the humanoid robot's malicious operations through software commands, and the intervention response time is ≤5 milliseconds.