A closed-loop safe intelligent control architecture and control method of an AI agent

Through a modular closed-loop safety intelligent control architecture, the AI ​​agent achieves full-process autonomous closed-loop control, solving the problems of coupling perception computing and behavior planning and lack of security filtering in existing technologies, and improving the behavioral security and autonomous adaptability of the AI ​​agent.

CN122131598APending Publication Date: 2026-06-02鲍海君

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
鲍海君
Filing Date
2026-03-03
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

The existing intelligent control system of AI agents has problems such as high coupling between perception computing and behavior planning, lack of security filtering and permission isolation, inability to achieve full-link closed-loop control, resulting in problems such as loss of control in decision-making, unauthorized execution and poor cross-type adaptability.

Method used

It adopts a modular and hierarchical closed-loop security intelligent control architecture, including a perception computing unit, a value security filtering unit, a core decision-making unit, and a resource execution and control unit. Through permission isolation and security front-end, it forms a seamless closed-loop control link, realizing autonomous correction and underlying hard constraints.

Benefits of technology

It achieves full-process autonomous closed-loop control of AI agents, improves behavioral safety, decision rationality and autonomous adaptability, eliminates unauthorized execution and decision loss, is applicable to multiple types of AI agents, and reduces transformation costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122131598A_ABST
    Figure CN122131598A_ABST
Patent Text Reader

Abstract

This invention discloses a closed-loop secure intelligent control architecture and method for AI agents, belonging to the field of artificial intelligence technology. The architecture is a modular, hierarchical, and closed-loop underlying architecture, including a perception and computing unit, a value security filtering unit, a core decision-making unit, and a resource execution and control unit. Each unit is independently deployed, with hierarchical permissions and bidirectional communication, adaptable to various AI agents such as general AI, embodied intelligence, and large-model intelligent agents. Based on this architecture, the control method achieves full-link secure control, autonomous correction, and underlying hard constraints for AI agents from information perception and scheme planning to execution feedback through a closed-loop process of perception and computing → value security filtering → core decision-making → resource execution and control → perception and computing. This invention solves the problems of high coupling, lack of closed-loop feedback, weak security protection, and poor cross-type adaptability in existing AI agent control technologies. It eliminates vulnerabilities such as unauthorized execution and decision-making failure at the system level, improving the behavioral security and decision-making rationality of AI agents. It can be widely applied to various AI application scenarios such as industrial intelligent control, human-computer interaction, and autonomous driving.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of artificial intelligence (AI) intelligent control and security protection technology. Specifically, it relates to a closed-loop security intelligent control architecture and corresponding control method covering multiple types of AI intelligent agents, including general AI, embodied intelligence, and large-model intelligent agents. It can realize full-link security management, autonomous correction, and permission constraints of AI intelligent agent behavior from perception, planning, decision-making to execution. It is applicable to various AI application scenarios such as industrial intelligent control, human-computer interaction intelligent agents, autonomous driving intelligent systems, and generative AI intelligent terminals. Background Technology

[0002] The rapid development of artificial intelligence technology has driven the application of various types of AI agents, including general AI, embodied intelligence, and large language model intelligent agents. The autonomous perception, autonomous decision-making, and autonomous execution capabilities of AI agents have become core technological characteristics. However, the existing intelligent control systems of AI agents still have significant security flaws and control vulnerabilities, as detailed below: 1. Existing AI agents are highly coupled in terms of perception computing, behavior planning and decision execution, and lack independent security filtering and permission isolation modules. This makes them prone to unauthorized execution, malicious instruction bypassing, and model adversarial attacks that lead to loss of control in decision-making. In particular, in generative AI and embodied agents, unsafe behaviors can easily occur due to logical deviations in the computing layer or external inducements. 2. The lack of value labeling, priority ranking, and safety pre-judgment for the behavior plans of AI intelligent agents makes it impossible to pre-filter the planning plans based on the safety rules of the application scenario, the urgency of the task, and the rationality of the behavior, which greatly increases the probability of invalid execution, erroneous execution, or even dangerous execution. 3. The control process is unidirectional and linear, without a closed-loop feedback correction mechanism. When the behavior plan generated by the AI ​​agent does not meet the safety rules or task requirements, it cannot achieve autonomous feedback and recalculation of the plan, and manual intervention is required to correct it, which reduces the efficiency and robustness of the AI ​​agent's autonomous decision-making. 4. The lack of underlying hard constraints on the computing power supply, energy allocation, and execution permissions of AI intelligent agents means that the computing layer can directly call the resources and permissions of the execution module. Even if the solution fails the security audit, there is still a risk of bypassing the decision-making layer to execute, and behavior control cannot be achieved from the bottom layer. 5. The existing control architecture cannot adapt to the common needs of various types of AI agents. The control schemes for general AI, embodied intelligence, and large model agents are independent of each other, and there is no unified underlying intelligent control framework, resulting in low technology reusability and great difficulty in cross-scenario adaptation.

[0003] To address the aforementioned issues, current improvement solutions are mostly passive, defensive optimizations, such as adding post-event verification at the execution layer and data filtering at the computation layer. These solutions fail to address the end-to-end security control issues of "perception-planning-decision-execution" at the underlying architecture level, and thus cannot achieve proactive security constraints and autonomous closed-loop correction for AI agents. Therefore, there is an urgent need for an intelligent control architecture and method that covers multiple types of AI agents, provides end-to-end closed-loop control, implements access control, prioritizes security, and incorporates underlying hard constraints. This would address core issues such as uncontrolled decision-making, unauthorized execution, and unsafe behavior of AI agents at the system level. Summary of the Invention

[0004] The purpose of this invention is to overcome the shortcomings of existing AI agent intelligent control technologies, such as high coupling, lack of closed-loop feedback, weak security protection, and poor cross-type adaptability. It provides a closed-loop secure intelligent control architecture and method for AI agents. This architecture is adaptable to various AI agents, including general AI, embodied intelligence, large-model agents, and industrial intelligent control terminals. It achieves full-link closed-loop control of AI agents from perception and computation, behavior planning, security filtering, decision-making, to execution control. Through permission isolation, security pre-positioning, underlying hard constraints, and autonomous feedback correction, it eliminates problems such as unauthorized execution, bypassing review, and loss of decision control at the system level, thereby improving the behavioral security, decision rationality, and autonomous adaptability of AI agents.

[0005] Technical solution To achieve the above-mentioned objectives, this invention adopts the following technical solution, which comprises two parts: a closed-loop safe intelligent control architecture and a control method based on this architecture, covering the entire process of intelligent control of AI agents, including perception, computation, planning, decision-making, execution, and feedback. A closed-loop secure intelligent control architecture for AI agents This architecture is a modular, hierarchical, and closed-loop underlying architecture, adaptable to various AI agents such as general artificial intelligence, embodied intelligence, large language model intelligent agents, and industrial intelligent control terminals. The architecture comprises four functional units: a perception and computing unit, a value and security filtering unit, a core decision-making unit, and a resource execution and control unit. Each unit is deployed independently, with hierarchical permissions and bidirectional communication, forming a seamless and unbypassable closed-loop control chain. The functions and permission levels of each unit are as follows: 1. Perception and Computing Unit: This is the foundational computing layer for AI agents, serving as the architecture's information input and behavior planning module. It adapts to the perception and computing needs of various types of AI agents—for embodied agents, it integrates environmental perception sensors and action planning modules; for large-model agents, it integrates text / voice / image information recognition modules and generative behavior planning modules; for industrial intelligent control terminals, it integrates industrial data acquisition modules and control command planning modules. Its core functions are: to perceive, collect, and analyze external environment / task information; to generate behavior plans / control commands that meet task objectives based on AI algorithms (including large-model inference, reinforcement learning, and logical planning); and to output the generated plans / commands to the value security filtering unit. It does not have the ability to directly call execution resources and permissions. 2. Value Security Filtering Unit: This unit serves as the security front-end and information relay layer for the AI ​​agent, acting as the core security barrier of the architecture. It communicates bidirectionally with the perception and computing unit and the core decision-making unit, but has no final review or execution control authority. Its core functions are: receiving behavioral plans / control instructions output by the perception and computing unit, and based on a preset security rule base, value labeling system, and task priority model, performing multi-dimensional judgment and processing on the plans / instructions, including behavioral security verification, task urgency classification, value rationality labeling, and filtering of unsafe plans. It then transmits the filtered legal plans / instructions (with classification and labeling information) to the core decision-making unit, while blocking the upward transmission of unsafe plans / instructions. 3. Core Decision-Making Unit: This is the highest-level authority layer of the AI ​​agent and the core of the architecture. It communicates bidirectionally with the Value Security Filtering Unit and the Resource Execution Control Unit, possessing the final approval authority for all behavioral schemes / control instructions. It does not have direct perception, computation, or execution control capabilities. Its core functions are: receiving legitimate schemes / instructions from the Value Security Filtering Unit, conducting final judgment based on preset global task objectives, scenario security rules, and resource allocation strategies, and outputting three types of judgment instructions: execution approved, execution rejected, and return for recalculation; simultaneously, it receives execution feedback information from the Resource Execution Control Unit to achieve dynamic monitoring of the execution process. 4. Resource Execution and Control Unit: This is the underlying execution and resource control layer of the AI ​​agent. It is a hard constraint module of the architecture, communicating bidirectionally with the core decision-making unit and the perception computing unit. It has control over all execution resources of the AI ​​agent but lacks the ability to plan or make decisions. Its core function is to receive the final review instruction from the core decision-making unit. If the instruction is "execution passed," it allocates the corresponding computing power, energy, and execution interface permissions to the perception computing unit according to the needs of the plan / instruction, driving the AI ​​agent to complete the behavior / instruction execution, and feeding back information such as execution results, resource consumption, and execution anomalies to the core decision-making unit. If the instruction is "reject execution / return to recalculation," it directly cuts off the execution resource supply to the perception computing unit and sends the feedback instruction back to the perception computing unit, triggering the replanning of the plan / instruction.

[0006] Furthermore, the security rule base is a dynamically updatable modular database, containing general security rules, scenario-based security rules, and AI agent type adaptation rules. Rules can be added, deleted, and modified according to different AI agents (general AI / embodied AI / large model agents) and different application scenarios (industrial control / human-computer interaction / autonomous driving), improving the cross-scenario adaptability of the architecture. The resource execution control unit sets an execution permission whitelist, opening the corresponding execution resources only to schemes / instructions approved by the core decision-making unit, thus implementing hard constraints on execution permissions from the bottom layer.

[0007] Based on the above closed-loop security intelligent control architecture, full-process closed-loop security intelligent control of various AI agents is realized. The control method includes the following steps: Step S1: The perception and computing unit perceives and collects external environment / task information, generates behavior plans / control instructions that conform to the task objectives based on AI algorithms (large model inference, reinforcement learning, logical planning, etc.), and outputs the plans / instructions to the value security filtering unit; Step S2: The value security filtering unit calls the preset security rule base, value labeling system, and task priority model to perform security verification, urgency classification, and value rationality labeling on the behavior plans / control instructions, filters out unsafe plans / instructions that do not conform to the security rules, and transmits the filtered legal plans / instructions (with classification and labeling information) to the core decision-making unit; Step S3: The core decision-making unit receives the legal plans / instructions, combines the global task objectives, scenario security rules, and resource allocation strategies for final judgment, and outputs three types of instructions based on the judgment result: execution passed, execution rejected, and return for recalculation; Step S4: The resource execution control unit receives the final judgment instruction from the core decision-making unit and handles it according to different situations: ① If the final review instruction is "execution approved": The resource execution control unit matches the corresponding execution resources from the execution permission whitelist according to the requirements of the scheme / instruction, allocates computing power, energy, and execution interface permissions to the perception computing unit, drives the AI ​​agent to execute the behavior / instruction, and feeds back the execution result, resource consumption, execution anomalies, and other information to the core decision-making unit in real time; ② If the final review instruction is "reject execution / return to recalculation": The resource execution control unit immediately cuts off all execution resource supply to the perception computing unit, prohibits it from executing any behavior / instruction, and directly sends the "reject execution / return to recalculation" feedback instruction back to the perception computing unit; Step S5: The perception computing unit receives the feedback instruction from the resource execution control unit. If it is "return to recalculation," it regenerates the behavior scheme / control instruction based on the feedback information and the global task objective, and executes steps S1-S4 again; if it is "reject execution," it terminates the current behavior / control instruction. The instructions are planned and executed, and the termination information is fed back to the core decision-making unit. Step S6: The core decision-making unit receives the execution feedback information from the resource execution control unit. If the execution result meets the task objectives and safety rules, the closed-loop control is completed. If there is a deviation in the execution result or an execution anomaly occurs, an adjustment / recalculation instruction is issued, triggering the scheme / instruction optimization of the perception computing unit, and steps S1-S5 are executed again to form a seamless, self-correcting closed-loop safety intelligent control process of perception computing → value security filtering → core decision → resource execution control → perception computing.

[0008] Furthermore, this control method can achieve dynamic adaptive adjustment: the core decision-making unit optimizes the value labeling system and task priority model of the value security filtering unit in real time, as well as its own resource allocation strategy, based on the execution results and resource consumption information fed back by the resource execution control unit, thereby improving the AI ​​agent's adaptability to complex scenarios and dynamic tasks.

[0009] The AI ​​intelligent agent closed-loop safety intelligent control architecture and method of the present invention have the following significant advantages compared with the prior art: 1. Coverage of all types of AI agents: The architecture adopts a modular and hierarchical design. The perception and computing unit can adapt to the perception and computing needs of various AI agents such as general AI, embodied intelligence, large language model agents, and industrial intelligent control terminals. The control method has no scene / model dependency, which solves the problems of poor cross-type adaptability and low technology reusability of existing control solutions. 2. Full-link closed-loop intelligent control: Construct a seamless closed-loop control link of "perception computing → value security filtering → core decision-making → resource execution control → perception computing", realize the AI ​​agent's autonomous control and self-correction throughout the entire process from information input and scheme planning to execution feedback, solve the defects of existing technologies such as unidirectional linear execution and no feedback correction, and improve the decision-making autonomy and robustness of the AI ​​agent; 3. Multi-level security protection and access control: A value security filtering unit is set up as a front-end security barrier, a core decision-making unit as the highest-level final review layer, and a resource execution control unit as the bottom hard constraint layer. Each unit is deployed independently with hierarchical permissions and no direct cross-layer communication capability. From the system architecture perspective, this eliminates unauthorized execution, bypassing review execution and decision loss caused by external attacks in the perception and computing layer, thus achieving proactive security protection. 4. Security Pre-emptive and Dynamic Adaptation: Through the pre-emptive security verification and scheme filtering of the value security filtering unit, the transmission of unsafe behaviors / instructions is blocked from the source. At the same time, the security rule base and value labeling system can be dynamically updated. The core decision-making unit can optimize the control strategy in real time based on execution feedback, adapting to different application scenarios and dynamic task objectives, thereby improving the scenario adaptability and behavioral security of the AI ​​agent. 5. Hard constraints at the underlying level and controllable execution: The resource execution management unit has control over all execution resources of the AI ​​agent, sets up an execution permission whitelist, and only opens resources to schemes / instructions that have passed the final review. It implements hard constraints on execution permissions from the underlying level, such as computing power, energy, and execution interfaces, and completely solves the core security vulnerability in existing technologies where the computing layer can directly call execution resources. 6. High versatility and practicality: The architecture and method of this invention are the underlying core technologies that can be directly embedded into the existing control systems of various AI agents without requiring large-scale modifications to the original AI algorithms (large models, reinforcement learning, etc.). The transformation cost is low, the technology is highly reusable, and it is applicable to various AI application scenarios such as industrial intelligent control, human-computer interaction, autonomous driving, and generative AI, with broad prospects for industrial application. Attached Figure Description

[0010] Figure 1. Schematic diagram of the closed-loop secure intelligent control architecture of the AI ​​agent of the present invention. Figure labeling: 1 - Perception and Computation Unit, 2 - Value Security Filtering Unit, 3 - Core Decision-Making Unit, 4 - Resource Execution Control Unit, 5 - Security Rule Base, 6 - Execution Permission Whitelist, 7 - Closed-Loop Control Link; Diagram explanation: Perception and Computation Unit 1 communicates bidirectionally with Value Security Filtering Unit 2 and Resource Execution Control Unit 4 respectively; Value Security Filtering Unit 2 communicates bidirectionally with Core Decision-Making Unit 3; Core Decision-Making Unit 3 communicates bidirectionally with Resource Execution Control Unit 4; Security Rule Base 5 is embedded in Value Security Filtering Unit 2; Execution Permission Whitelist 6 is embedded in Resource Execution Control Unit 4; the above connections form a closed-loop control link 7.

[0011] Figure 2. Flowchart of the AI ​​intelligent agent closed-loop safety intelligent control method of the present invention. Illustration: The closed-loop control process of steps S1-S6 is shown in the form of a flowchart, which clarifies the executing entity, processing content and feedback relationship of each step, and marks the three branch processing logics of "execution passed", "execution rejected" and "return to recalculation", as well as the triggering conditions and execution method of "dynamic adaptive adjustment". Detailed Implementation

[0012] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention. In addition, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of the present invention, "a plurality of" means two or more, unless otherwise explicitly specified.

[0013] The technical solution of the present invention will be described in detail below with reference to the accompanying drawings and specific embodiments. These embodiments are only used to explain the present invention and are not intended to limit the scope of protection of the present invention. The core technical solution of the present invention can be adapted to various AI agents. Specific embodiments are illustrated using embodied agents and large language model agents as examples: Example 1: Application of the present invention in embodied intelligent agents When embodied intelligent agents are applied in human-computer interaction scenarios, they need to achieve autonomous environmental perception, action planning, and safe execution. The closed-loop safe intelligent control architecture of this invention is embedded into the underlying control system of the embodied intelligent agent, and the corresponding control method is executed as follows: 1. Perception and Computation Unit 1 integrates a visual sensor, a tactile sensor, and a motion planning module to perceive environmental information (such as human movements and voice commands) and task objectives (such as "taking and putting away a water cup") in the human-computer interaction scenario. It generates an arm motion planning scheme based on a reinforcement learning algorithm and outputs it to the Value Safety Filtering Unit 2. 2. Value safety filtering unit 2 calls the "human-computer interaction safety rules" in the safety rule base 5 to perform safety verification on the action planning scheme (such as avoiding arm touching the human body and avoiding water cup falling), marks the task priority as "normal", filters out unsafe action trajectories, and transmits the legal action scheme to the core decision unit 3; 3. Core Decision Unit 3, in conjunction with the overall task objective of "safely completing the retrieval and placement of the water cup," conducts a final review and outputs an "execution passed" instruction to Resource Execution Control Unit 4; 4. Resource execution control unit 4 matches the resource permissions for arm execution from the execution permission whitelist 6, allocates motor drive computing power and energy to perception computing unit 1, drives the arm of the embodied intelligent agent to perform the action of picking up and putting down the water cup, and feeds back the action execution result and motor energy consumption to core decision unit 3; 5. Core decision-making unit 3 receives execution feedback information, confirms that the action execution conforms to the task objectives and safety rules, and completes this closed-loop control; if the water cup shifts during the action execution, core decision-making unit 3 issues an "adjustment command", triggering perception and computing unit 1 to replan the action trajectory and execute the above steps again to achieve autonomous correction.

[0014] Example 2: Application of the present invention in a large language model intelligent agent When a large language model agent is applied to a generative text creation scenario, it needs to achieve text information recognition, creation scheme planning, and secure generation. The closed-loop secure intelligent control architecture of this invention is embedded into the underlying control system of the large language model agent, and the corresponding control method is executed as follows: 1. Perception and Computation Unit 1 integrates the text information recognition module and the large model reasoning module to perceive the user's creative needs (such as "writing product introduction copy"), generate multiple versions of copywriting schemes based on the large language model, and output them to the value security filtering unit 2. 2. Value security filtering unit 2 calls the "Content Security Rules" and "Commercial Copywriting Value Labeling Rules" in the security rule base 5 to perform security verification (filtering vulgar and false content) and value rationality labeling (matching product positioning) on ​​the copywriting plan, classifying it as "high priority" and passing the legal copywriting plan to the core decision-making unit 3; 3. Core Decision Unit 3 conducts a final review based on the overall task objective of "generating a secure business document that aligns with the product positioning". It outputs an "Execution Passed" instruction for two high-quality versions and an "Return to Recalculation" instruction for the remaining versions, and then passes the information to Resource Execution Control Unit 4. 4. Resource execution control unit 4 allocates generation computing power and output interface permissions to the second version of the copy that has been "executed successfully", drives the large language model intelligent agent to generate and output the copy, and sends the "return to recalculation" instruction back to the perception computing unit 1 to cut off the generation resources of other schemes; 5. Perception and Computation Unit 1 receives the "Return to Recalculate" instruction, optimizes the copywriting scheme based on product positioning and feedback from the core decision-making unit, and executes the above steps again; Core Decision-Making Unit 3 receives the copywriting output results, optimizes the value labeling system in real time based on user feedback, and improves the matching degree of subsequent copywriting creation.

[0015] Example 3: Application of the present invention in embodied intelligent agents (human-computer interaction scenario) Embodied intelligent agents, when applied in human-machine collaboration scenarios, must possess environmental perception, action planning, and safe execution capabilities. The closed-loop safe intelligent control architecture of this invention is embedded into the underlying control system of the embodied intelligent agent, as specifically implemented below: 1. The perception and computing unit 1 integrates a visual sensor, a tactile sensor and a motion planning module to perceive human movements, voice commands and environmental obstacle information in real time. Based on reinforcement learning and dynamic motion primitives (DMPs), it generates a motion planning scheme for "taking and putting away a water cup" and outputs it to the value safety filtering unit 2. 2. Value safety filtering unit 2 calls the "human-computer interaction safety rules" in the safety rule base 5 to perform collision detection, force restriction and behavior rationality assessment on the action trajectory, marks the task priority as "high", filters the action trajectory that may collide with the human body, and transmits the legal solution to the core decision unit 3; 3. The core decision-making unit 3, combining the overall task objective of "safely completing the retrieval and placement of the water cup" with the current scenario's safety rules, finally approves the solution and outputs the "execution passed" instruction to the resource execution control unit 4; 4. The resource execution control unit 4 matches the arm execution permission from the execution permission whitelist 6, allocates motor drive computing power and energy to the perception and computing unit 1, drives the robotic arm to perform actions, and feeds back the execution results and energy consumption data to the core decision-making unit 3; 5. The core decision-making unit 3 judges the quality of the action based on the feedback information. If the water cup is shifted or there is external interference, the "adjustment command" is triggered to start the recalculation process and achieve autonomous correction.

[0016] Example 4: Application of the present invention in a large language model agent (text generation scenario) Large language model agents, applied to intelligent writing and content generation tasks, must possess text understanding, solution planning, and secure output capabilities. The specific implementation is as follows: 1. The perceptual computing unit 1 integrates a text recognition module and a large model reasoning module. It receives the user instruction "write product promotion copy", generates multiple versions of copy based on the large model, and outputs them to the value security filtering unit 2. 2. Value security filtering unit 2 calls the "content security rules" and "business copywriting value model" in the security rule base 5 to filter the copywriting for pornography, politics, and false content, and marks it with "high matching degree", "medium matching degree" and "low matching degree" levels, and passes the high matching solution to the core decision-making unit 3; 3. Core decision-making unit 3, combining brand positioning and user preferences, finally approves the two highly matched solutions and outputs the "Execution Passed" instruction, while outputting the "Return to Recalculate" instruction for the other matching solution; 4. Resource execution control unit 4 allocates GPU computing power and output interface through the scheme to drive the generation and display of text, and at the same time sends the "return to recalculate" instruction back to perception computing unit 1; 5. The perception and computing unit 1 optimizes the prompt words based on the feedback, regenerates the copy, and re-enters the closed-loop process; 6. Core decision-making unit 3 dynamically optimizes the value labeling system and priority model based on user click-through rates and feedback to improve the quality of subsequent generation.

[0017] Example 5: Application of the present invention in industrial intelligent control terminals (intelligent manufacturing scenario) Industrial intelligent control terminals are used in automated production lines and need to achieve high real-time performance and high security in the generation and execution of control commands. The specific implementation is as follows: 1. The sensing and computing unit 1 integrates a PLC data acquisition module and a logic planning module to collect parameters such as the status, temperature, and vibration of production line equipment in real time, generate equipment start-stop control commands based on the rule engine, and output them to the value safety filtering unit 2. 2. Value safety filtering unit 2 calls the "Industrial Safety Procedures" in the safety rule base 5 to perform equipment status verification and operation sequence checks on the instructions, filter out instructions that may cause equipment conflicts or overload, and transmit the legitimate instructions to the core decision-making unit 3; 3. The core decision-making unit 3, combining the production plan and safety priorities, finally approves the "start cooling system" instruction and outputs "execution approved" to the resource execution control unit 4; 4. The resource execution control unit 4 matches the control interface permissions of the corresponding device from the execution permission whitelist 6, allocates communication bandwidth and execution energy, drives the device to execute, and feeds back the execution status and energy consumption to the core decision-making unit 3; 5. If the core decision-making unit 3 detects an abnormal temperature or execution delay, it triggers an "adjustment command" to initiate a recalculation or emergency shutdown process, thereby achieving closed-loop safety control.

[0018] Example 6: Application of the present invention in an autonomous driving intelligent system (intelligent driving scenario) Autonomous driving intelligent systems need to integrate perception, decision-making, and control to ensure driving safety. The specific implementation is as follows: 1. The perception computing unit 1 integrates a camera, LiDAR and path planning module to perceive lane lines, obstacles and traffic signs in real time, generate lane changing and overtaking schemes based on deep reinforcement learning, and output them to the value safety filtering unit 2. 2. Value safety filtering unit 2 calls the "traffic rule base" and "driving ethics model" in safety rule base 5 to perform safety distance verification, traffic signal matching, and pedestrian avoidance assessment on lane change plans, mark the risk level, and transmit the legal plan to core decision-making unit 3; 3. Core decision-making unit 3 combines the overall path and driving strategy to finally approve the low-risk lane change plan and output the "execution approved" instruction; 4. Resource execution and control unit 4 matches steering, throttle, and brake control permissions, allocates real-time computing resources and execution energy, drives the vehicle to perform lane changes, and feeds back the vehicle status and trajectory deviation to the core decision-making unit 3; 5. If the core decision-making unit 3 detects a vehicle approaching from behind or a deviation in the trajectory, it triggers a "return to recalculation" command to initiate the path replanning process and ensure driving safety.

[0019] Example 7: Application of the present invention in smart home smart agents (home service scenario) Smart home agents need to understand user habits, plan service behaviors, and execute them securely. Specific implementation details are as follows: 1. The perception computing unit 1 integrates a speech recognition module and a behavior prediction model to recognize the user command "turn on the living room air conditioner and set it to 26 degrees", generate an environmental adjustment plan, and output it to the value security filtering unit 2; 2. Value safety filtering unit 2 calls the "home appliance safety rules" and "energy saving strategy" in the safety rule base 5 to verify the rationality of air conditioner status, current load, and indoor-outdoor temperature difference, marks the "energy saving priority" level, and transmits the legal solution to the core decision-making unit 3; 3. Core decision-making unit 3, combining user habits with current electricity pricing strategies, finalizes the approval of the plan and outputs the "Execution Approved" instruction; 4. Resource execution and control unit 4 matches the air conditioning control interface permissions, allocates communication resources and power, drives the air conditioning to execute, and feeds back the operating status and energy consumption to the core decision-making unit 3; 5. If the core decision-making unit 3 detects abnormal temperature or equipment failure, it will trigger an "adjustment command" or "emergency shutdown" to ensure home safety.

[0020] General Explanation The above embodiments are merely typical application examples of the present invention in different AI agents. In practical applications, the resource configuration of the perception module of the perception computing unit 1, the rule content of the security rule base 5, and the execution permission whitelist 6 can be flexibly adjusted according to the specific scenario without changing the core closed-loop control logic. The architecture and method of the present invention have the following common advantages: 1. Modular adaptation: Each unit is deployed independently, supporting rapid access to different AI models and hardware platforms; 2. Closed-loop feedback: A complete closed loop is formed from perception to execution, supporting autonomous correction and dynamic optimization; 3. Hard security constraints: Through permission isolation and underlying resource control, unauthorized execution and malicious commands are prevented; 4. Versatile across various scenarios: Applicable to a wide range of fields such as industrial control, human-computer interaction, autonomous driving, and smart homes.

[0021] Therefore, this invention has strong versatility and promising prospects for industrial application.

Claims

1. A closed-loop secure intelligent control architecture for an AI agent, characterized in that, The architecture is a modular, hierarchical, and closed-loop underlying architecture, which is compatible with various AI agents such as general artificial intelligence, embodied intelligence, large language model intelligent agents, and industrial intelligent control terminals. It includes a perception computing unit (1), a value security filtering unit (2), a core decision-making unit (3), and a resource execution control unit (4). Each unit is deployed independently, with hierarchical permissions and bidirectional communication, forming a closed-loop control link (7) without breaks and cannot be bypassed. The perception computing unit (1) is the basic computing layer of the AI ​​agent, realizing the perception, collection and analysis of external environment / task information, generating behavior schemes / control instructions based on AI algorithms, and has no ability to directly call execution resources and permissions. The value security filtering unit (2) is the security front-end layer and information transfer layer of the AI ​​agent. It has a built-in security rule base (5) to perform security verification, classification, labeling and filtering of behavior schemes / control instructions, and provide a security barrier for the core decision-making unit (3). It has no final review authority or execution control authority. The core decision-making unit (3) is the highest authority layer of the AI ​​agent. It has the final approval authority for behavior schemes / control instructions and outputs final review instructions based on global task objectives and scene security rules. It has no direct perception, computing and execution control capabilities. The resource execution control unit (4) is the bottom execution layer and resource control layer of the AI ​​agent. It has a built-in execution permission whitelist (6) and has the control authority over all execution resources of the AI ​​agent. It realizes the underlying hard constraints of computing power, energy and execution interface. It has no scheme planning and decision-making capabilities.

2. The closed-loop secure intelligent control architecture for AI agents according to claim 1, characterized in that, The perception and computing unit (1) adapts the corresponding perception and computing modules according to the type of AI agent: for embodied agents, it integrates environmental perception sensors and action planning modules; for large model agents, it integrates text / voice / image information recognition modules and generative behavior scheme planning modules; for industrial intelligent control terminals, it integrates industrial data acquisition modules and control command planning modules; the AI ​​algorithm includes one or more of large model inference, reinforcement learning, and logical planning.

3. The closed-loop secure intelligent control architecture for AI agents according to claim 1, characterized in that, The security rule base (5) is a modular database that can be dynamically updated. It includes general security rules, scenario-based security rules and AI agent type adaptation rules. Rules can be added, deleted and modified according to different AI agents and different application scenarios. The execution permission whitelist (6) only opens the corresponding execution resources to the behavior schemes / control instructions approved by the core decision-making unit (3).

4. A closed-loop secure intelligent control method for an AI agent based on the architecture described in any one of claims 1-3, characterized in that, The method realizes a closed-loop safe intelligent control of the AI ​​agent from perception, calculation, planning, decision-making to execution, including the following steps: Step S1: The perception and calculation unit (1) perceives and collects external environment / task information, generates behavior schemes / control instructions that meet the task objectives based on AI algorithms, and outputs them to the value security filtering unit (2); Step S2: The value security filtering unit (2) calls the security rule base (5) to perform security verification, urgency classification, and value rationality labeling on the behavior schemes / control instructions, filters out unsafe schemes / instructions, and transmits the legal schemes / instructions to the core decision-making unit (3); Step S3: The core decision-making unit (3) performs final judgment on the legal schemes / instructions and outputs three types of final judgment instructions: execution passed, execution rejected, and return for recalculation; Step S4: The resource execution control unit (4) receives the final judgment instructions and handles them according to the situation: if the execution is passed, it matches the execution resources from the execution permission whitelist (6), allocates computing power, energy, and execution interface permissions to the perception and calculation unit (1), and drives the AI ​​agent to execute behavior / The instruction is given and the execution result is fed back to the core decision-making unit (3); if the execution is rejected / returned for recalculation, the execution resource supply is cut off and the feedback instruction is sent back to the perception and computing unit (1); Step S5: The perception and computing unit (1) receives the feedback instruction. If the execution is returned for recalculation, the behavior plan / control instruction is regenerated and steps S1-S4 are executed again; if the execution is rejected, the current planning and execution are terminated and the termination information is fed back to the core decision-making unit (3); Step S6: The core decision-making unit (3) receives the execution result. If it meets the task objectives and safety rules, the closed-loop control is completed; if there is a deviation or abnormality, the adjustment / recalculation instruction is issued, triggering the perception and computing unit (1) to optimize the plan / instruction and execute steps S1-S5 again to form a closed-loop control process.

5. The AI ​​intelligent agent closed-loop safety intelligent control method according to claim 4, characterized in that, The method also includes a dynamic adaptive adjustment step: the core decision-making unit (3) optimizes the value labeling system, task priority model, and its own resource allocation strategy in real time based on the execution results and resource consumption information fed back by the resource execution control unit (4).

6. The AI ​​intelligent agent closed-loop safety intelligent control method according to claim 4, characterized in that, In step S4, the resource execution control unit (4) feeds back information such as execution results, resource consumption, and execution anomalies to the core decision-making unit (3) in real time, thereby realizing dynamic monitoring of the AI ​​agent's execution process.

7. An AI intelligent agent, characterized in that, The AI ​​agent is one of general artificial intelligence, embodied intelligence, large language model agent, industrial intelligent control terminal, or autonomous driving intelligent system. It incorporates the closed-loop safety intelligent control architecture described in any one of claims 1-3 and uses the closed-loop safety intelligent control method described in any one of claims 4-6 to achieve intelligent control and safety protection of behavior.

8. The application of the closed-loop safe intelligent control architecture according to any one of claims 1-3 and the closed-loop safe intelligent control method according to any one of claims 4-6 in the field of artificial intelligence, characterized in that, It is applied to AI application scenarios such as industrial intelligent control, human-computer interaction, autonomous driving, generative AI, and smart home, realizing full-link closed-loop safe and intelligent control of various AI intelligent agents.