Endogenous self-adaptive security constraint method and system
By employing an endogenous behavior constraint method and utilizing the fusion of confidence scores of multi-source heterogeneous states within the system and nonlinear mapping, the continuous safety problem of dynamic physical systems in complex environments is solved, achieving autonomous and smooth adjustment of safety boundaries and performance optimization.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- 潮州市玉律探索科技有限公司
- Filing Date
- 2025-12-23
- Publication Date
- 2026-05-15
AI Technical Summary
Existing technologies cannot integrate the confidence of multi-source heterogeneous states within a dynamic physical system in real time and adaptively, resulting in a lack of endogenous and dynamic security constraints, making it difficult to achieve continuous security in complex environments.
An endogenous behavior constraint method is adopted, which generates a continuous overall system health metric by fusing the real-time self-evaluation confidence of multiple heterogeneous functional units within the system, and dynamically adjusts the safety boundary using a nonlinear mapping function to achieve real-time and adaptive behavior constraints.
It achieves absolute security and performance optimization of system behavior, possesses autonomous protection capabilities, can smoothly degrade in complex environments, meets high-level security regulatory requirements, and has cross-platform versatility.
Smart Images

Figure CN122043934A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of automatic control and functional safety technology, and in particular to a method, system and storage medium for ensuring that dynamic physical systems such as autonomous vehicles and mobile robots achieve endogenous behavioral constraints by fusing internal state confidence in real time under complex and uncertain environments. Background Technology
[0002] Ensuring the safe operation of dynamic physical systems (such as autonomous vehicles) under conditions of inherent uncertainty and external disturbances is a core technical challenge in this field. Existing technical solutions and standards have systemic defects in addressing this challenge, mainly manifested in four major limitations: "result verification, external dependence, static rigidity, and lack of closed-loop processing." These precisely constitute the technical problem that this invention aims to solve.
[0003] 1. Existing safety specifications and models have the defects of "static rigidity" and "passive verification". Current mainstream safety models (such as responsibility-sensitive safety RSS) and standard specifications have been proven to have fundamental deficiencies. The literature "Robustre responsibility-sensitive safety: Noise disturbed adaptive cruise control" (Qi Hongsheng et al., *Systems & Control Letters*, 2025) clearly points out through rigorous empirical analysis that the time-varying randomness of the adaptive cruise control system will inevitably lead to the violation of the RSS safety distance based on fixed rules [1]. This reveals that the safety framework that relies on deterministic and static models has inherent and insurmountable defects when facing the inherent uncertainty of the system. At the same time, as shown in "Safety Requirements for Intelligent Connected Vehicle Combined Driving Assistance System" [2], the existing functional safety standards mainly define the final performance output threshold and test verification method in discrete scenarios, which is a typical "result verification" or "post-verification" paradigm. The literature "Towards a Complete Safety Framework for Longitudinal Driving" [3] also clearly points out that the coverage of such classic models is insufficient and a new framework that is more general and computable is needed. However, none of these specifications reveal how to enable the system to possess an endogenous, proactive mechanism to ensure that every action it takes is spontaneously and deterministically within the safety domain during continuous and unpredictable operation.
[0004] 2. Existing technologies lack integrated perception of the internal health status of the system, and safety constraints exhibit "external dependence". Most advanced safety constraint methods mainly rely on external environmental perception information as constraint input. For example, the paper "SafeAutonomous Driving with Latent Dynamics and State-Wise Constraints" [4] encodes safety constraints into the decision-making process through a barrier function, but the generation of its constraints mainly depends on environmental perception data such as external bird's-eye view. These methods fail to deeply integrate and utilize the real-time output state confidence of multiple heterogeneous functional units (e.g., perception, positioning, and control modules) within the system. When the performance of internal functional units is potentially or actually degraded due to interference such as sensor noise, computational delay, and model mismatch, existing solutions cannot quantify this degradation, let alone dynamically and accurately feed it back and constrain system behavior, forming a "blind spot" in safety monitoring.
[0005] 3. Advanced regulations and ethical requirements highlight the lack of technical pathways to achieve 'continuous safety'. The UK's Autonomous Vehicles Act 2024 clearly defines safety benchmarks in legal form. Article 2 stipulates that authorized vehicles must **"achieve a level of safety equivalent to or higher than that of a prudent and competent human driver"** and requires operating entities to "continuously ensure" this level of safety [5]. The Act establishes legal responsibilities, but does not provide any specific and engineerable technical pathways to achieve this goal. China's Ethical Guidelines for the Research and Development of Driving Automation Technology [6] also places "safety first, respect for life" and "risk control" at the core of ethics, requiring the design of sound risk monitoring and emergency response mechanisms. These regulations and guidelines jointly propose the high-level goal of "continuous safety", but do not provide any specific and engineerable technical pathways to achieve this goal. In particular, they lack a methodology that can continuously and quantitatively assess the internal operating status of the system and dynamically and in a closed loop transform it into behavioral constraints at the decision-making level.
[0006] 4. Existing advanced solutions have limitations in terms of "universality" and "endogenousness", making it difficult to form a complete closed loop. The literature "Computing Safe Stop Trajectories for Autonomous Driving Utilizing Clustering and Parametric Optimization" (Johannes Langhorst et al., *Vehicles*, 2024) [7] uses "pre-computation combined with real-time parameter adjustment" to generate trajectories for specific scenarios (safe parking). Its idea is inspiring, but it is not a universal framework. The literature "Online Safety Verification of Autonomous Driving Decision-MakingBased on Dynamic Reachability Analysis" [8] performs online safety verification of a given trajectory through dynamic reachability analysis, which belongs to the category of "post-verification". These solutions are either for specific functions or are downstream of the safety chain. None of them provide a universal, endogenous framework that can generate safety constraints in real time based on its own multi-dimensional health status.
[0007] It should be noted that the four major technical limitations mentioned above—"result verification, external dependence, static rigidity, and lack of closed-loop"—are not limited to the field of autonomous driving, but rather represent common safety challenges faced by all dynamic physical systems (including but not limited to autonomous vehicles, mobile robots, and drones) operating in open and uncertain environments. Therefore, the field needs a universal safety constraint framework, rather than a patchwork solution for specific scenarios.
[0008] In summary, the core technical problem urgently needing to be solved in this field is: how to create a general method that can integrate multi-source heterogeneous state confidence scores within a system in real time and adaptively, and thereby generate behavioral safety boundaries endogenously, dynamically, and nonlinearly, thus achieving deterministic constraints at the source of decision-making. Existing technologies, due to their "exogenous" and "open-loop" characteristics, cannot fundamentally solve this problem. This invention aims to bridge the methodological gap from "passive result testing" to "active process assurance," providing a completely new technical path to meet the regulatory requirements of "continuous safety." Purpose of the invention
[0009] The present invention aims to overcome all the defects of the prior art and provide a method, system and medium for constraining the endogenous behavior of dynamic physical systems.
[0010] The core of this invention lies in transforming security constraints from an "additional verification" component that relies on external fixed rules or environmental information into an "endogenous attribute" that originates from the autonomous fusion and nonlinear mapping of multi-source state confidence within the system. This enables real-time, dynamic, and adaptive adjustment of the security boundary, ensuring that the system behavior spontaneously resides within the absolute security domain defined by its own health state at any given moment.
[0011] To achieve the above objectives, the present invention adopts the following technical solution: The core of the "endogenous behavioral constraint" proposed in the present invention lies in the fact that the generation of the security boundary is directly and mainly derived from the confidence fusion result of real-time self-evaluation of multiple heterogeneous functional units within the system, which is fundamentally different from security models that rely on external environment perception information, fixed rule tables or pre-stored maps.
[0012] The "endogenous behavioral constraint" paradigm of this invention is fundamentally different from existing technologies that rely on external environmental information (such as the method of generating safety constraints based on external bird's-eye view used in reference [4] "Safe Autonomous Driving with Latent Dynamics and State-Wise Constraints"). The safety constraints in reference [4] are driven by externally perceived information and belong to "exogenous safety"; while the safety boundary of this invention is driven by the fusion of real-time confidence of each functional unit within the system and belongs to "endogenous safety". This shift from "exogenous" to "endogenous" is the key to solving the problem of achieving continuous safety of the system under internal uncertainty. Summary of the Invention
[0013] To make the technical solution of this invention clearer, the core terms appearing below will first be explained: 1. System Integrity Continuous Scalar Metric: This refers to a single, continuous, and quantitative overall system health index generated by fusing the **self-operating state reliability** of multiple heterogeneous functional units (such as sensing, positioning, and control modules) within a system through a specific algorithm. This metric **does not directly characterize the safety level of the external environment** (e.g., the presence of obstacles), but is specifically designed to reflect the **internal reliability and confidence level of the system in fulfilling its intended functions**. Its value range is typically continuous (e.g., 0 to 1), aiming to achieve a sensitive and continuous characterization of system performance degradation.
[0014] 2. Endogenous behavioral constraints: These refer to the generation of system behavioral safety boundaries, where the **data source and decision-making logic are both rooted within the system**. Specifically, the input information upon which the constraint boundaries are based (i.e., the "output state confidence" of each functional unit) is the system's assessment of its own operational state; the mapping function used to generate the constraint boundaries directly and primarily relies on the aforementioned internal fusion metrics, rather than external environmental perception data or pre-stored static safety rule tables.
[0015] 3. Feasible instruction subspace: This refers to a **continuous, closed geometric region** defined at a given moment by the "dynamic constraint boundary parameters" (such as maximum acceleration and maximum curvature) within the space of all possible instructions of the system. Only instructions falling within this region are considered safe to execute under the current healthy state of the system.
[0016] The “system integrity continuous scalar measure” is a quantitative representation of this endogenous process; for example, it can be characterized as a normalized, continuously changing scalar value.
[0017] An endogenous behavior constraint method for dynamic physical systems, characterized by comprising the following sequentially executed steps: The system integrity continuous scalar metric generation steps are as follows: The output state confidence levels of multiple heterogeneous functional units within the dynamic physical system are fused in real time to generate a system integrity continuous scalar metric. This metric is a comprehensive scalar value used to quantitatively characterize the overall reliability and health of the system at the current moment.
[0018] Regarding the aforementioned technical problems 1 and 2: This step directly addresses the deficiencies of "lack of internal state fusion perception" and "external dependence." Fundamentally different from methods in reference [4] that rely on externally perceived data, this invention innovatively focuses on the confidence level of the fusion system's internal self-assessment, providing an endogenous and quantifiable data foundation for the "risk monitoring" mechanism required by reference [6]. The fusion can be achieved in various ways, such as using evidence theory (DS) fusion, Bayesian network inference, or weight-adjustable evidence fusion networks.
[0019] In particular, the "weight adjustable" feature enables the fusion strategy to adapt to changes in the reliability of each functional unit, thereby enhancing the robustness and accuracy of the measurement.
[0020] The dynamic constraint boundary parameter calculation steps are as follows: The continuous scalar metric for system integrity is input into a parameterized nonlinear boundary mapping function to calculate a set of dynamic constraint boundary parameters corresponding to the current moment (for example, it may include: maximum longitudinal acceleration, maximum lateral acceleration, maximum steering angular velocity, position error tolerance, etc.).
[0021] Regarding the aforementioned technical problems 1 and 3: This step aims to overcome the "static rigidity" problem of security boundaries and respond to the regulatory requirements of "continuous security". As demonstrated in reference [1], static models inevitably fail under uncertainty.
[0022] This invention employs a nonlinear mapping, and its key inventive feature lies in the fact that the mapping function has nonlinear saturation characteristics. When the continuous scalar metric for system integrity falls below a certain preset threshold, the dynamic constraint boundary parameters shrink nonlinearly and rapidly, resulting in a nonlinear shrinkage of the feasible instruction subspace defined by these parameters. This achieves a protective stress response and smooth performance degradation similar to that of a biological system, rather than a simple "on / off" switch.
[0023] The idea of “pre-calculation combined with real-time parameter adjustment” in reference [7] can prove the engineering feasibility of using parameterized functions for dynamic adjustment in this step. However, this invention elevates it to a general nonlinear mapping paradigm that is strongly coupled with the internal state.
[0024] Online instruction projection arbitration steps: Using an online instruction arbitrator, the original instruction sequence from the upstream planning module is subjected to constrained optimization projection based on the feasible instruction subspace defined by the dynamic constraint boundary parameters, and finally outputs a safe instruction located in the feasible instruction subspace that is closest to the original instruction intent.
[0025] Regarding the aforementioned technical issues 1 and 4: This step ensures that safety constraints are strictly, in real time, and optimally executed. The arbitration can be mathematically transformed into solving a constrained optimization problem. In a preferred embodiment, projection arbitration is achieved by solving a constrained quadratic programming problem. Its mathematical essence is to find the point with the closest Euclidean distance to the original instruction (or satisfying other optimization objectives) within the feasible instruction subspace defined by the dynamic boundary, thereby mathematically guaranteeing the absolute safety of the output while maximizing the retention of driving intention. The "online safety verification based on dynamic reachability analysis" method proposed in reference [8] can be used as a downstream independent verification tool for the output of this step. Combined with it, it forms a dual guarantee chain of "endogenous constraint generation - external formal verification", which provides a complete technical implementation path for meeting the deterministic and verifiable requirements of "safe and legal" in the UK legislation [5].
[0026] The closed loop described above, from "intrinsic state awareness" to "real-time behavioral constraints," constitutes a **general security constraint framework independent of specific application platforms**. The framework's input is the system's internal state confidence level, and its output is arbitrated security instructions. Its core logic can be applied to any dynamic physical system composed of multiple heterogeneous functional units that needs to ensure behavioral safety under uncertainty. It should be understood that the above method and system are a general security constraint framework, and their application is not limited to any specific dynamic physical system platform.
[0027] The above three steps constitute a tightly closed-loop intrinsic security link from "intrinsic state perception" to "dynamic boundary generation" and then to "real-time behavior constraints", realizing a fundamental paradigm shift in security mechanisms from "external post-verification" to "built-in prior constraints".
[0028] Based on the same inventive concept, the present invention also provides a dynamic behavior constraint system for implementing the above method, characterized in that it includes: A multi-source confidence fusion module is configured to perform the system integrity continuous scalar metric generation step; A nonlinear boundary mapping module is configured to perform the dynamic constraint boundary parameter calculation step; An online instruction arbitration module is configured to perform the online instruction projection arbitration step; The modules are connected in sequence for communication.
[0029] Furthermore, the present invention also claims protection for a vehicle characterized by integrating the dynamic behavior constraint system as described above.
[0030] And a computer-readable storage medium having a computer program stored thereon that, when executed by a processor, implements the endogenous behavior constraint method for dynamic physical systems as described above. Beneficial effects
[0031] Compared with existing technologies, the technical solution provided by this invention can bring the following significant benefits: This invention not only solves the security problems in specific scenarios, but also provides a fundamental security paradigm applicable to **fully autonomous systems**.
[0032] 1. A new paradigm of "endogenous initiative" in security constraints has been created, resulting in a fundamental improvement in security capabilities.
[0033] This invention, for the first time, anchors the generation of security boundaries to the real-time health status (confidence level) of the system's internal environment, rather than external fixed rules or environmental information, enabling the system to possess "autonomous protection" capabilities based on "self-awareness." This directly responds to and surpasses the core concept of "risk monitoring" advocated in reference [6], and fundamentally distinguishes it from external data-dependent schemes such as reference [4]. Through specific implementations such as the "weight-adjustable evidence fusion network" in claim 2, the adaptability and accuracy of internal state assessment are ensured.
[0034] 2. It achieves "dynamic nonlinear adaptive" safety boundary, perfectly balancing safety and performance.
[0035] Through the nonlinear boundary mapping function and its nonlinear contraction characteristics defined in claim 3, the safety boundary can be continuously, smoothly, and intelligently adjusted according to the system's health status. When the system confidence decreases, the boundary nonlinearity tightens sharply, proactively and forward-lookingly avoiding risks; when the confidence is high, the system performance is fully released. This fundamentally solves the conservatism problem caused by the static threshold in reference [2], and the fundamental defect that the static model will inevitably fail under uncertainty as confirmed in reference [1]. Combined with the "quadratic programming projection" in claim 4, optimal performance is achieved under the premise of absolute safety.
[0036] 3. It provides a deterministic and verifiable technical path to meet high-level "continuous security" regulations.
[0037] This invention provides a computable and verifiable intrinsic security mechanism. The "quadratic programming" method explicitly stated in claim 4 provides mathematical determinism and optimality guarantees for instruction generation. The continuous scalar metrics and dynamic parameters generated by this method provide specific, feasible, and advanced technical solutions for system auditing, liability delineation (in line with the "clear record" spirit of reference [6]), and meeting the "continuous security" requirements of the UK legislation [5] and the "risk control" requirements of Chinese ethical guidelines.
[0038] 4. Possesses inherent robustness to cope with the inherent uncertainties of the system, enabling graceful degradation.
[0039] By fusing internal confidence and triggering nonlinear contraction of the boundary, this method can effectively manage the inherent randomness disturbances of the system as revealed in reference [7]. When some functions of the system degrade, it can achieve smooth and predictable "graceful degradation", always ensuring basic safety and significantly improving the overall robustness and survivability of the system in complex environments.
[0040] 5. It has a fundamental advantage in dealing with uncertainties within the system.
[0041] Compared to security constraint mechanisms that rely on external environmental information, the "endogenous behavior constraint" paradigm provided by this invention has a fundamental advantage in dealing with internal system uncertainties. When internal functional units (such as cameras, LiDAR, and positioning algorithms) experience uncertainties due to their own malfunctions, performance degradation, or model mismatch, traditional "exogenous security" schemes, unable to perceive this internal state change, maintain their security boundaries unchanged. This allows for aggressive control commands even when the system's actual capabilities have declined, leading to risk accumulation. Conversely, this invention, through real-time fusion of internal confidence levels, enables the security boundaries to contract synchronously with the system's **real-time, true capabilities**. This "self-awareness" mechanism allows the system to proactively and smoothly limit its behavior **before external dangers occur**, preventing security incidents caused by "capability-task mismatch" from the decision-making source. This represents a paradigm shift from "passively avoiding external dangers" to "proactively matching internal capabilities."
[0042] Furthermore, the nonlinear continuous mapping employed in this invention, compared to simplified adjustment strategies such as "discrete levels" or "piecewise linearity," achieves **true smooth performance degradation**. When system integrity metrics fluctuate slightly around a threshold, the boundary parameter changes generated by the nonlinear continuous mapping are also slight and continuous, thus avoiding stuttering, instability, or unpredictability in system behavior caused by sudden shifts in safety levels. This **continuous and smooth characteristic of control commands** is a key intrinsic property ensuring that various dynamic physical systems achieve 'graceful degradation' rather than 'abrupt failure'.
[0043] 6. It has significant cross-platform versatility and strategic value.
[0044] As illustrated in the examples, this framework can be seamlessly applied to vastly different dynamic physical systems such as autonomous vehicles, industrial mobile robots, and drone swarms. This versatility means that this invention is not a patchwork solution for a specific scenario, but rather a **unified security paradigm** that can be embedded into the underlying layers of various autonomous systems.
[0045] Once an advantage is established in key areas (such as autonomous driving), a powerful technological spillover effect will be generated, providing an indispensable core security foundation for building a **fully trusted autonomous system ecosystem** that spans from the ground to the air and from transportation to manufacturing, and creating a strategic high ground for the era of intelligent machines.
[0046] In particular, for various dynamic physical systems such as high-level autonomous driving (e.g., Level 3 and above), mobile robots, and drones, the core commonality of their safe operation is that the system must possess the ability to autonomously and smoothly enter a state of minimum risk when internal uncertainties increase. The "endogenous behavioral constraint" general framework provided by this invention offers a deterministic technical path to achieving this core safety goal by dynamically and non-linearly shrinking the behavioral safety boundary through real-time fusion of internal state confidence levels. This ensures that when the system's performance degrades, it can proactively match its actual capabilities based on "self-awareness," preventing safety incidents caused by a mismatch between capabilities and tasks from the decision-making source.
[0047] In summary, the "endogenous behavior constraint" framework proposed in this invention possesses significant cross-platform versatility, demonstrating its strategic value as a fundamental security technology. Its core technology—the closed-loop logic of "**perceiving internal state → fusing into health metrics → nonlinear mapping into behavioral boundaries → optimizing projected execution**"—is **independent of any specific execution vehicle or task scenario**. Attached Figure Description
[0048] Figure 1 This is a flowchart illustrating the dynamic behavior constraint method provided in an embodiment of the present invention. Detailed Implementation Example 1
[0049] An Intrinsic Behavior Constraint Method for Land Motor Vehicles
[0050] Figure 1 This diagram illustrates the core architecture and information flow of the endogenous behavior constraint system of this invention. The system comprises a multi-source confidence fusion module, a nonlinear boundary mapping module, and an online instruction arbitration module, connected sequentially. These modules work collaboratively to achieve a complete closed loop, from the fusion of internal state confidence, to the generation of system integrity metrics, to the calculation of dynamic safety boundary parameters, and finally to the arbitration and output of the original instructions. This process clearly embodies the core principle of "generating safety boundaries based on endogenous data, thereby constraining behavior."
[0051] It should be understood that the specific embodiments described herein are for illustrative purposes only and do not constitute a limitation thereof. Any equivalent substitutions, combinations, or modifications made by those skilled in the art based on the principles of this invention after reading this invention should be included within the scope of protection of this invention.
[0052] It is important to note that the intrinsic behavioral constraints implemented in this invention are technically embodied in two complementary levels: Regarding data sources, the "output state information" upon which the system relies refers to raw data, intermediate features, or local decision results generated by each functional unit itself without global fusion; regarding decision logic, the generation of security boundary parameters strictly and exclusively depends on the fusion results of this type of intrinsic information, rather than directly on external environmental perception information or static rules. The following embodiments are all specific applications of this core principle.
[0053] To make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments.
[0054] This embodiment uses a land-based motor vehicle with conditional autonomous driving capabilities—a representative dynamic physical system—as an example to illustrate in detail how the present invention achieves endogenous behavioral constraints in its longitudinal and lateral control. Those skilled in the art will understand that this specific application is merely an example to illustrate the general architecture of the present invention.
[0055] System architecture and process The vehicle's decision control system includes modules for environmental perception, localization, and planning, as well as the dynamic behavior constraint system of this invention. The constraint system receives **internal state confidence levels** from each functional module, as well as raw control commands from the trajectory planning module, and outputs arbitrated safety commands to the underlying actuators. Its core process is as follows: Figure 1 As shown, this forms an information loop of "endogenous data -> security boundary -> constrained behavior".
[0056] System integrity metric generation This step is performed by the multi-source confidence fusion module. The module receives confidence inputs from different functional units in real time, such as the confidence of the perception system in detecting key obstacles, the accuracy confidence of the positioning system, and the trajectory feasibility confidence of the planning system. These confidence scores are quantitative assessments of the reliability of each unit's own operating status.
[0057] To fuse these heterogeneous confidence levels, this embodiment employs a **weight-adjustable evidence fusion network**. The core advantage of this network lies in its **adaptive capability**: when an abnormally rapid decline in the confidence level of a functional unit is detected (e.g., the performance of a sensing system degrades due to a sudden weather change), the network can dynamically adjust the weight allocation, amplifying the **negative impact** of that unit on the final fusion result. This allows the system integrity metric to more sensitively and proactively reflect local system degradation. This "focusing on weak links" mechanism is not present in simple fixed-weight fusion.
[0058] The fusion aims to generate a **continuous, time-varying** continuous scalar metric for system integrity, `S_integrity`. Its value range is typically designed to be between 0 and 1, with higher values indicating higher overall system health and reliability. **Crucially, this fusion mechanism ensures that `S_integrity` produces a sensitive and monotonic response when the confidence of any functional unit decays, which forms the basis for triggering subsequent nonlinear contraction of the safety boundary.**
[0059] Dynamic constraint boundary parameter solution This step is performed by the nonlinear boundary mapping module. The module has a built-in **parameterized nonlinear boundary mapping function**, for example, using a family of sigmoid functions, to map the scalar metric `S_integrity` to a set of specific dynamic boundary parameters.
[0060] The mapping function is designed to have **nonlinear saturation characteristics**. Its input-output relationship is as follows: when `S_integrity` is above a high threshold, the output boundary parameters change gradually, allowing the system to perform close to its design performance; when `S_integrity` is below a low threshold, the function enters a region of rapid nonlinear change, and the output value **decreases rapidly** as the input decreases.
[0061] The output dynamic constraint boundary parameters include, but are not limited to: maximum permissible longitudinal acceleration `a_long_max`, maximum permissible lateral acceleration `a_lat_max`, and maximum permissible path curvature `κ_max`. These parameters collectively define the **feasible instruction subspace** of the vehicle control commands at the current moment.
[0062] The key to this step lies in the nonlinearity of the mapping function, which enables a **nonlinear contraction** of the feasible instruction subspace as the system integrity metric decreases. That is, the boundary parameters do not decrease proportionally, but are compressed to a conservative range with a steeper slope, thus mathematically and proactively limiting the system's potential aggressive behavior.
[0063] Online command projection arbitration This step is performed by the online command arbitration module. The module is activated every control cycle (e.g., 10 milliseconds) and receives raw commands `u_raw` (such as acceleration and steering angle commands) and dynamic constraint boundary parameters.
[0064] The arbitration process is mathematically constructed as a **constrained convex optimization problem** (e.g., quadratic programming). Its optimization objective is to minimize the deviation (e.g., the square of the Euclidean distance) between the output safe instruction `u_safe` and the original instruction `u_raw`, with the constraints being the **feasible instruction subspace** (a convex set) defined by dynamic boundary parameters.
[0065] By solving this optimization problem, the obtained `u_safe` is mathematically guaranteed to lie within the absolutely safe feasible region and is also the instruction closest to the original intent. This achieves precise arbitration that maximizes the performance preservation intent while **unconditionally satisfying safety constraints**.
[0066] Summarize The above embodiments illustrate in detail the application of this invention in autonomous vehicles. Those skilled in the art should understand that replacing the "heterogeneous functional units" and "dynamic constraint boundary parameters" in the described method with corresponding modules and constraints of other dynamic physical systems (such as robots or drones), while adhering to the same "fusion-mapping-arbitration" core logic, is within the scope of protection of this invention. This confirms the universal value of this invention as an intrinsically safe and general architecture independent of any specific platform. Example 2:
[0067] An Intrinsic Behavior Constraint Method for Industrial Logistics Robots The following Examples 2 and 3 aim to further illustrate and demonstrate that the 'endogenous behavior constraint method' defined in claim 1 is a universal safety architecture independent of specific execution platforms or task scenarios. By mapping the 'heterogeneous functional units' and 'dynamic constraint boundary parameters' to specific entities in different domains (such as robot joints, drone formation parameters), the core process of this universal architecture—namely, 'fusion of endogenous confidence, nonlinear mapping to dynamic boundaries, and optimization of projection arbitration'—can be completely and isomorphically applied to a wide range of dynamic physical systems such as industrial robots and drone swarms. This confirms the universal value of this invention as a fundamental safety paradigm.
[0068] This embodiment applies the present invention to an autonomous mobile robot in a factory environment, demonstrating the versatility of its technical solution. The robot needs to perform material handling tasks in a dynamic environment with both pedestrian and material flow.
[0069] The core steps of the endogenous behavior constraint method are isomorphic to the general process defined in claim 1, as follows: System integrity metric generation: A scalar metric characterizing the overall integrity of the robot's "mobility-operation-communication" process is generated through an evidence fusion network, fusing confidence scores from LiDAR positioning (based on matching scores), robotic arm grasping operations, and wireless communication link quality. The core of this evidence fusion network lies in adaptive weight adjustment based on the changing trends and uncertainty levels of the confidence scores of each functional unit. For example, confidence scores can be negatively correlated with the uncertainty metric of the unit's output state (e.g., quantified using mathematical tools such as information entropy and variance). A feasible strategy for weight adjustment is to make it negatively correlated with the rate of change of uncertainty, so that when the performance of a unit rapidly deteriorates, the system integrity metric can more sensitively reflect this degradation. In this embodiment, the following three real-time confidence scores are specifically fused: 1. `C_localization` (Localization Confidence): The matching score between the current frame's LiDAR point cloud and the preset map is normalized to a value of `[0,1]` using a sigmoid function. When the matching score is below a threshold, the confidence level decreases non-linearly.
[0070] 2. `C_manipulation` (operation confidence): Based on real-time states, such as the current joint torque error of the robotic arm, the visual servo error of the end effector, and the variance of the posture estimation of the object to be grasped, it is mapped to confidence through a pre-calibrated model.
[0071] 3. `C_communication` (Communication Confidence): Calculated based on real-time monitored wireless signal strength (RSSI) and packet reception rate (PRR).
[0072] Dynamic constraint boundary parameter calculation: The system integrity metric is input to a parameterized nonlinear boundary mapping function to calculate a set of dynamic constraint boundary parameters. This mapping function is designed to have nonlinear saturation characteristics; for example, a family of sigmoid functions can be used. When the input metric value is below a preset threshold, the output parameters shrink at a significantly accelerated rate. Thus, the instruction feasible region defined by this function mathematically constitutes a convex set. In this embodiment, when the communication confidence `C_communication` decreases due to interference, causing the system integrity metric to fall below the threshold, the output dynamic constraint boundary parameters include, but are not limited to: 1. Maximum moving speed `v_max`: Reduced from the usual 1.5m / s non-linearly to below 0.5m / s.
[0073] 2. Maximum planning replanning frequency `f_replan_max`: Reduced from 10Hz to 2Hz.
[0074] 3. Safe stopping distance `d_stop`: Requires an increased distance from dynamic obstacles.
[0075] Online command projection arbitration: The original command is projected and arbitrated using an online command arbitrator based on the feasible command subspace defined by the dynamic constraint boundary parameters. Mathematically, this process can be modeled as a constrained convex optimization problem, the standard form of which is minimizing the norm deviation between the safe command and the original command. The constraint condition is that the command must lie within a convex set defined by the dynamic boundary parameters. In this embodiment, the velocity command `[v_cmd, ω_cmd]` issued by the path planner is treated as a two-dimensional vector. By solving a quadratic programming problem, it is forcibly constrained within the feasible region formed by the shrunk `v_max`, `ω_max`, and the acceleration boundary, thus outputting a safe command. Example 3
[0076] An Intrinsic Behavioral Constraint Method for Cooperative Flight of Unmanned Aerial Vehicle Swarms This embodiment applies the invention to drone formation, demonstrating its constraint on individual behavior in a multi-agent system.
[0077] The core steps of the endogenous behavior constraint method are isomorphic to the general process defined in claim 1, as follows: System integrity metric generation: Each UAV integrates its own navigation system confidence level, its confidence level in its perception of neighboring UAVs, and its confidence level in inter-UAV communication to generate an individual system integrity metric within the formation. In a distributed system, the confidence level in its neighbors can be evaluated based on data consistency, for example, by comparing the differences between its own observations and the information received through communication (such as Mahalanobis distance). One fusion strategy to ensure the security of cluster collaboration is to adopt a pessimistic principle, making the system integrity metric sensitive to the most unreliable collaborative links. In this embodiment, the specific fusion for a single UAV is as follows: 1. `C_ego_gnss` (self-GNSS positioning reliability): calculated based on the number of satellites, carrier-to-noise ratio, and DOP value.
[0078] 2. `C_relative` (Relative Position Confidence): Calculated based on the UWB / visual measurement residuals and communication delays of the lead drone or neighboring drones. This confidence level decreases significantly when the communication delay exceeds 100ms.
[0079] 3. `C_formation_health` (Flock Network Health): Calculated based on the completeness rate of neighbor state information received in the most recent period.
[0080] Dynamic constraint boundary parameter calculation: The system integrity metric is input to a parameterized nonlinear boundary mapping function to calculate a set of dynamic constraint boundary parameters. For UAV swarms, these parameters, in addition to dynamic constraints, can be extended to parameters related to formation keeping and collision avoidance, which also follow the law of nonlinear contraction of output as the input metric decreases. In this embodiment, when its own GNSS confidence `C_ego_gnss` decreases due to entering an obstruction zone, the dynamic constraint boundary parameters output by the mapping function include: 1. Formation preservation tolerance `δ_pos_max`: The upper limit of the error allowed to deviate from the preset formation position is drastically reduced.
[0081] 2. Maximum tracking speed `v_track_max`: Reduced to avoid losing track or colliding due to high-speed maneuvers when the self-positioning is inaccurate.
[0082] 3. Cooperative decision weight `w_cooperation`: In distributed consensus algorithms, the weight of the local machine's output instructions is automatically reduced.
[0083] Online instruction projection arbitration: An online instruction arbitrator performs projection arbitration on the original instructions based on the feasible instruction subspace defined by the dynamic constraint boundary parameters. In a distributed control architecture, this arbitration can be embedded in a local decision-making module, formalized as an optimization problem that integrates local security constraints and collaborative consistency constraints. In this embodiment, the original tracking instructions generated by the Model Predictive Controller (MPC) will be projected in the instruction arbitrator onto the feasible region defined by parameters such as the shrunk `δ_pos_max` and `v_track_max`, outputting conservative instructions that prioritize the overall safety of the cluster.
[0084] Those skilled in the art should understand that the detailed description of the above examples is only for illustrating the principles and specific implementations of the present invention, and is not intended to limit the scope of protection of the present invention. Without departing from the core concept of the present invention, any application of this method to other dynamic physical systems (such as robots, drones, etc.) should be considered within the scope of protection of the present invention. Example 4
[0085] This embodiment aims to further highlight the inventiveness and universal value of the present invention from a **theoretical and logical perspective** by illustrating the fundamental differences between the present invention and existing technologies, as well as its unique approach to solving core security challenges. This description is strictly based on publicly available academic literature and recognized technical principles.
[0086] 1. Responding to and transcending the limitations of existing technologies As described in the background section, existing security solutions (such as those disclosed in references [1] and [2]) face the risk of failure of their static or externally rule-based security boundaries when the system has inherent uncertainties and random disturbances. The "endogenous behavioral constraint" paradigm proposed in this invention directly addresses this fundamental limitation. Its innovation lies in **originally and dynamically, nonlinearly coupling the security boundary with the system's real-time, multi-source self-state assessment (confidence level).** This provides a completely new solution path: instead of attempting to more accurately describe or resist all external uncertainties, it intrinsically and proactively ensures security by making the security boundary **match the system's own changing "capability boundary" in real time.** This methodological shift constitutes a substantial breakthrough from traditional security paradigms that rely on fixed models or external environment perception.
[0087] 2. The universality and completeness of the core architecture The technical architecture of this invention—"fusion of endogenous confidence levels → nonlinear mapping to dynamic boundaries → optimized projection arbitration"—defines a complete and self-consistent closed loop of security constraints. The input to this architecture is the system's internal confidence level, and the output is a security instruction rigorously arbitrated mathematically, **independent of any specific external environment model or static rule base**.
[0088] Regarding the general significance of nonlinear mapping: The key effect of the nonlinear mapping defined in claims 3 and 8 is that it achieves a "smooth but sharp" contraction of the safety boundary. This is not an arbitrary design choice, but rather a means to provide a **continuous, predictable, and responsive safety degradation mechanism** as system performance begins to degrade. This mechanism is crucial for maintaining the stability and reliability of the system in complex and uncertain environments.
[0089] Regarding the mathematical determinism of optimized arbitration: The value of optimized projective arbitration (such as quadratic programming) as defined in claims 4 and 10 lies in providing a **unique and computationally efficient mathematical framework** for the requirement of "finding the optimal instruction within the safety boundary." This ensures the accuracy and real-time performance of safety constraint enforcement, transforming safety decision-making from a potentially fuzzy rule-based judgment problem into a deterministic mathematical optimization problem.
[0090] 3. Clarification of the relationship with complementary technologies The architecture of this invention is a self-contained, proactive system that generates security instructions. Certain advanced methods in the prior art (such as the "security verification" method based on dynamic reachability analysis mentioned in reference [8]) play different roles—they are typically used for ex-post or parallel security verification of a **given** trajectory or decision. This invention is not logically bound to or dependent on these verification methods, but rather can be functionally **complementary**. For example, a complete system can employ the intrinsic constraint framework of this invention as a **proactive, real-time security instruction generator**, while simultaneously employing an independent verification method as a parallel, formal **security verifier**. This combination can form a stronger security evidence chain, but this does not mean that this invention needs to rely on external verification to achieve its technical objectives. On the contrary, this invention independently provides a **proactive, intrinsic, and continuous security boundary generation capability** that existing verification methods do not possess.
[0091] In summary, Example 4 theoretically demonstrates that this invention is not a simple improvement or combination of existing technologies, but rather proposes a fundamentally different paradigm for security constraints. By anchoring security to the system's own state, it provides a universal, effective, and verifiable new framework for solving the common problem of "persistent security" in dynamic physical systems under uncertainty. References
[0092] [1] Title: Robust responsibility-sensitive safety: Noise disturbed adaptive cruise control; Author: HongSheng QI (pronounced Qi Hongsheng); Journal: Systems & Control Letters (a leading international journal in the field of control, ISSN: 0167-6911); Publisher: Elsevier; Official website: ScienceDirect (an academic database under Elsevier, journal homepage: Systems & Control Letters on ScienceDirect); Publication date: February 2025; Volume: 196; Article number: 106021; https: / / doi.org / 10.1016 / j.sysconle.2025.106021
[0093] [2] Title: Safety Requirements for Intelligent Connected Vehicle Combined Driving Assistance Systems. Ministry of Industry and Information Technology of the People's Republic of China: Draft for Comments.
[0094] [3] Title: "Towards a Complete Safety Framework for Longitudinal Driving" Authors: Galina Sidorenko, Aleksei Fedorov, Johan Thunberg, Alexey Vinel* **Author Affiliation**: Lund University, IEEE Intelligent Vehicles Symposium 2024, Volume and Page Numbers**: Conference Proceedings, p. 3159. Link to this publication: https: / / lup.lub.lu.se / record / db7642ad-86f7-4ec8-95b9-eeba37f8f6c1
[0095] [4] Title: Safe Autonomous Driving with Latent Dynamics and State-Wise Constraints Authors: Changquan Wang, Chen Tang, Zhenning Li, Ming Yang Journal: Sensors (ISSN 1424-8220, IF 3.9) Volume / Issue / Pages: 2024, 24(10), 3139 Publication Date: May 15, 2024; https: / / doi.org / 10.3390 / s24103139 Source: PubMed Central Safe Autonomous Driving with Latent Dynamics and State-Wise Authors: Changquan Wang, Institute of Microelectronics, Chinese Academy of Sciences, University of Chinese Academy of Sciences.
[0096] [5] UK Automated Vehicles Act 2024 URL: https: / / www.bailii.org / uk / legis / num_act / 2024 / ukpga_202410_en_1.html Chapter number: 2024 CHAPTER 10 UK Legislation Automated Vehicles Act 2024 Chapter 10 Effective date: 20 May 2024.
[0097] [6] The “Ethical Guidelines for the Research and Development of Driving Automation Technology” was published on the official website of the Ministry of Science and Technology on July 23, 2025.
[0098] [7] Title: Computing Safe Stop Trajectories for Autonomous Driving Utilizing Clustering and Parametric Optimization; Authors: Johannes Langhorst et al.; Author Affiliations: 1. Topas Industriemathematik, 28359 Bremen, Germany; 2. Center for Industrial Mathematics, University of Bremen, 28359 Bremen, Germany; Journal: Vehicles; Publisher: MDPI AG; ISSN: 2624-8921; Publication Date: March 24, 2024; Volume, Issue, Pages: 2024, Volume 6, Issue 2, pp. 590-610; Digital Object Identifier (DOI): https: / / doi.org / 10.3390 / vehicles6020027
[0099] [8] Title: Online Safety Verification of Autonomous Driving Decision-Making Based on Dynamic Reachability Analysis; Authors: FEI GAO, CHENG LUO, et al. Author Affiliations: 1. State Key Laboratory of Automotive Simulation and Control, Jilin University; 2. School of Automotive Studies, Tongji University; 3. Chongqing Changan Automobile Co., Ltd.; Journal: IEEE Access (a well-known journal under the Institute of Electrical and Electronics Engineers); Publication Date: August 1, 2023; Digital Object Identifier: 10.1109 / ACCESS.2023.3300423 (DOI).
Claims
1. A method for constraining the endogenous behavior of dynamic physical systems, characterized in that, The method includes the following steps: S1. Obtain the output state information of multiple heterogeneous functional units within the dynamic physical system, and obtain the state confidence of each functional unit accordingly; S2. Fuse the multiple state confidences to generate a continuous scalar metric for system integrity; S3. Use the continuous scalar metric for system integrity as the sole input source, input it into a parameterized nonlinear boundary mapping function, and calculate a set of dynamic constraint boundary parameters that uniquely depend on the metric; S4. Through an online instruction arbitrator, perform projection arbitration on the original instruction sequence based on the feasible instruction subspace defined by the dynamic constraint boundary parameters, and output a safe instruction located within the feasible instruction subspace.
2. The method according to claim 1, characterized in that, The fusion in step S2 is achieved by a weighted evidence fusion network.
3. The method according to claim 1, characterized in that, The parameterized nonlinear boundary mapping function is configured such that when the continuous scalar metric for system integrity is below a first threshold, the decay rate of the output dynamic constraint boundary parameters as the metric decreases is higher than the rate of change when the metric is in a high range.
4. The method according to claim 1, characterized in that, The projection arbitration in step S4 is achieved by solving a constrained convex optimization problem, the optimization objective of which is to minimize the deviation between the output instruction and the original instruction sequence under a predetermined norm.
5. The method according to claim 1, characterized in that, The dynamic physical system is a land-based motor vehicle, and the heterogeneous functional units include at least an environmental perception module, a vehicle positioning module, and a planning and control module; the dynamic constraint boundary parameters include at least the maximum longitudinal acceleration and the maximum lateral acceleration.
6. The method according to claim 1, characterized in that, In step S1, the output state information of at least one functional unit is information selected from at least one of the following: raw sensor data, intermediate feature data derived from the raw data, and local decision results generated based on the aforementioned information without global confidence fusion processing. That is, the information is a direct or primary output representation of the corresponding functional unit's own task execution status; obtaining the state confidence includes uncertainty quantification or credibility assessment of the information.
7. The method according to claim 1, characterized in that, The phrase "uniquely depends on" in step S3 is reflected in the fact that the input of the parameterized nonlinear boundary mapping function contains only the continuous scalar metric of system integrity, while excluding any information directly derived from the perception of the external environment of the dynamic physical system and any pre-stored static security rules that are not dynamically adjusted by the metric.
8. A dynamic behavior constraint system, characterized in that, Used to implement the method as described in any one of claims 1 to 7.
9. A vehicle, characterized in that, It integrates the dynamic behavior constraint system as described in claim 8.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the method as described in any one of claims 1 to 7.