A fault-tolerant control method for explosion-proof industrial robots with multi-level security redundancy
By employing a dual-layer physical protection and dual-source redundant air supply architecture, combined with distributed sensing and pressure gradient prediction, active fault-tolerant control of explosion-proof industrial robots is achieved. This solves the problems of insufficient protection depth and passive control in existing technologies, thereby improving the system's safety and operational continuity.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- WUXI LONGDUN INTELLIGENT EQUIPMENT CO LTD
- Filing Date
- 2026-05-09
- Publication Date
- 2026-06-09
Smart Images

Figure CN122165438A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the technical field of explosion-proof industrial robot control, specifically relating to a fault-tolerant control method for explosion-proof industrial robots with multi-level safety redundancy. Background Technology
[0002] Explosion-proof industrial robots are primarily used in flammable and explosive environments, including petrochemical, coal chemical, natural gas processing, hazardous materials storage, and military manufacturing. These robots typically require long-term stable operation in environments containing flammable gases, dust, or high temperatures and pressures. As crucial equipment for replacing manual labor in hazardous environments, the safe and reliable operation of explosion-proof industrial robots directly impacts production safety and personnel safety.
[0003] Existing positive-pressure explosion-proof industrial robots typically employ an external, continuous air supply system. This system uses a connected compressed air network to create a positive pressure inside the robot, higher than the external environment, to prevent the intrusion of flammable and explosive gases. This is complemented by pressure monitoring and emergency stop interlocks for safe operation. However, this single-point vulnerable structure and reliance on a single physical isolation method result in insufficient protection depth and difficulty in handling complex industrial environments. Current technologies introduce layered designs and multi-level redundancy mechanisms, significantly improving the reliability of the explosion-proof gas circuit under extreme conditions. The boundaries of physical protection levels are also clearer, providing extremely strong external interference resistance.
[0004] Although existing positive pressure explosion-proof technology is relatively mature, it still has the following shortcomings when dealing with sudden working conditions in complex industrial sites: 1. Limited Reliability of Single-Layer Shell Protection: Current technologies primarily rely on a single, integral shell of the robot body to form a positive pressure chamber. This single-layer protection design focuses on external isolation, lacking deep internal protection. Once the shell ruptures due to an accidental impact, or the seals fail to maintain airtightness due to long-term aging, the sole explosion-proof barrier will lose its original protective effect. Internally, core ignition sources such as high-temperature servo motors, encoders, and controllers will be directly exposed to the hazardous environment, lacking independent isolation protection.
[0005] 2. Air Supply Line Based on a Single External Air Source: The safety protection of existing systems relies heavily on a single external air supply line. Lacking redundant air source reserves, in the event of an air compressor failure, air supply line damage, or sudden pressure fluctuations, the robot's internal air pressure will rapidly depressurize. The system often has to resort to the extreme measure of a complete power outage, and may even face the risk of negative pressure inhalation before the power outage, lacking buffer time and fault tolerance to cope with sudden air source failures.
[0006] 3. Passive control strategy based on fixed threshold: Existing explosion-proof control systems mostly adopt simple pressure threshold interlocking logic, which lacks comprehensive judgment and active intervention capabilities for internal pressure change trends. They cannot adaptively compensate for minor leaks caused by aging of seals, resulting in frequent unnecessary shutdowns. They also cannot identify risks and initiate emergency measures in the early stages of a sharp drop in pressure, posing a potential safety hazard of passively waiting for the threshold to be triggered under high-risk conditions.
[0007] With the continuous development of industrial robot technology and intelligent sensing algorithms, the internal operating data of explosion-proof industrial robots can be continuously collected and analyzed, including multi-dimensional data such as micro-pressure change rate, gas flow consumption, leakage rate, and environmental concentration. However, existing research mainly focuses on static pressure maintenance and single airtightness detection, lacking an overall design method that deeply couples the physical dual redundancy of "gas source-structure" with "prediction-compensation" active fault-tolerant control. This makes it difficult to achieve active prediction, graded response, and fault-tolerant control of abnormal states under extreme conditions such as gas source failure or shell damage. Summary of the Invention
[0008] The purpose of this invention is to address the aforementioned shortcomings in the prior art by providing a fault-tolerant control method for explosion-proof industrial robots with multi-level safety redundancy. This method solves the problem that the prior art lacks an overall design method that deeply couples the physical dual redundancy of "air source-structure" with "prediction-compensation" active fault-tolerant control, making it difficult to achieve active prediction, graded response, and fault-tolerant control of abnormal states under extreme conditions such as air source failure or shell damage.
[0009] To achieve the above objectives, the technical solution adopted by the present invention is as follows: A fault-tolerant control method for explosion-proof industrial robots with multi-level safety redundancy includes the following steps: S1. Construct a double-layer physical protection nested structure and a dual-air source redundant parallel air supply architecture for explosion-proof industrial robots, and configure a distributed redundant sensor network and cavity pressure field equalization structure in the positive pressure cavity. S2. A clock synchronization mechanism is used to perform time-series alignment, filtering and noise reduction, and environmental decoupling on the multi-source sensor data of the explosion-proof industrial robot. S3. Based on the pressure data of the positive pressure cavity processed in S2 and the robot's motion state, leakage is identified by decoupling discrete pressure gradient calculation and motion disturbance, and abnormal leakage states are identified by Taylor series pressure trend prediction and dynamic model residual integral analysis. S4. Perform static airtightness self-test on the explosion-proof industrial robot and construct a dynamic leakage map of the full attitude space. Use the normalization correction factor of environmental parameters to dynamically adjust the pressure threshold. Combine the threshold drift adjustment of the sealing aging trend and the sealing fatigue cumulative loss model to complete the dynamic compensation calibration of the dynamic leakage benchmark. S5. Based on the sensor data processed in S2, the leakage identification results in S3, and the leakage benchmark after dynamic compensation calibration in S4, a multi-dimensional risk assessment is performed on the positive pressure cavity, and the explosion-proof industrial robot is divided into four operating states and the logical switching and hysteresis self-healing confirmation between operating states are realized. S6. Based on the four-level operating status, perform graded active fault-tolerant control on the positive pressure chamber and the dual-gas-source supply architecture, and implement leakage compensation, dual-gas-source switching, motion degradation constraints and hardware emergency blocking.
[0010] Furthermore, step S1 includes the following sub-steps: S101. Construct a double-layer physical protection nested structure. The inner layer uses high-strength lightweight alloy material to construct the positive pressure cavity of the explosion-proof industrial robot, and wraps the robot body and wiring harness inside the positive pressure cavity. The outer layer designs independent modular explosion-proof encapsulation cavities for the servo motor, driver, and controller respectively. S102. Construct a dual-loop parallel air supply architecture at the robot fluid input end. The main loop is connected to the external explosion-proof air supply network, and the secondary loop is connected to the high-pressure carbon fiber wound air storage tank integrated in the robot base. The two air sources are merged into the explosion-proof industrial robot air inlet pipeline through a high-speed electromagnetic switching valve to form a dual redundant air supply path. S103. Real-time acquisition of the volume change rate of the positive pressure cavity, calculation of the cavity pressure change rate based on the fluid mechanics continuity equation and gas state equation, and feedforward adjustment of gas flow rate to compensate for pressure fluctuations caused by the expansion and contraction of the positive pressure cavity, so as to maintain the pressure in the positive pressure cavity in a safe state that is higher than the external environment pressure. S104. Multiple pressure sensors and temperature probes are deployed at the far end, near end and airflow dead zone of the positive pressure cavity to construct a distributed redundant sensor network. The variance inverse weighted fusion algorithm is used to fuse the multiple sensor signals and remove abnormal sensor data to obtain the actual pressure observation value of the positive pressure cavity. S105. A Venturi jet is installed at the position with the largest length-to-diameter ratio in the positive pressure cavity. The high-pressure air intake drives the residual gas in the positive pressure cavity to circulate, suppressing the generation of local airflow dead zones and achieving a uniform distribution of the pressure field inside the positive pressure cavity.
[0011] Furthermore, step S2 includes the following sub-steps: S201, based on the IEEE 1588 time protocol, synchronizes clocks between the master controller and distributed nodes, calculates the phase deviation and path delay of the master and slave clocks, and corrects all the collected raw pressure data and maps them to a unified time axis to achieve unified alignment of multi-source signal timing. S202. For continuous analog quantities such as pressure and temperature and discrete digital quantities such as joint angles, a linear interpolation method is used to map low-frequency data to a high-frequency time axis to complete resampling, and then the state vector of the whole system at the corresponding time is constructed. S203. The pressure signal is filtered and denoised using the Kalman filter algorithm. S204. Introduce absolute pressure, combine the filtered and denoised data with ambient temperature and atmospheric pressure parameters for normalization and decoupling processing, and obtain pressure data under standard working conditions. Furthermore, step S3 includes the following sub-steps: S301. Based on the pressure data after time-series unification and alignment in S2, the five-point central difference method is used to calculate the first and second derivatives of the pressure, thereby obtaining leakage indicators, including the pressure drop rate and the pressure drop acceleration rate. S302. Based on the joint angles resampled by S2, the volume change rate caused by mechanical motion is calculated through the kinematic Jacobian matrix. Combined with the pressure data processed by S2, the true leakage pressure gradient is calculated to distinguish between false leakage and physical leakage. S303. Construct a pressure trend prediction model based on Taylor series, set the prediction step size to the actuator response time, use the pressure trend prediction model to predict the pressure value at future moments, and immediately trigger an early warning if the predicted pressure will fall below the safety threshold. S304. Run the physical model observer to calculate the theoretical steady-state pressure, and identify minor leaks by calculating the residual integral of the theoretical steady-state pressure.
[0012] Furthermore, step S4 includes the following sub-steps: S401. After the system is powered on, a static air tightness self-test is performed. The robot is statically inflated to the rated pressure and then locked. The static leakage rate is calculated based on the natural pressure drop within a preset time. The safety baseline of the whole machine for this operation is established based on the static leakage rate. When the static leakage rate exceeds the allowable threshold, the system is locked and an error is reported. S402. During the initialization phase, control the explosion-proof industrial robot to traverse typical posture trajectories, obtain the maintenance flow rate under each typical posture trajectory, and then construct the "posture-leakage mapping" model; calculate the abnormal deviation between the actual leakage value and the output value of the "posture-leakage mapping" model to eliminate leakage interference caused by posture changes. S403. Introduce an environmental normalization correction factor to dynamically adjust the pressure threshold in combination with ambient temperature and atmospheric pressure. S404. Introduce a forgetting factor to dynamically adjust the alarm threshold based on the historical average leakage rate. S405. Establish a seal fatigue loss correction factor based on total operating mileage and average internal pressure, and use this seal fatigue loss correction factor to automatically fine-tune the "attitude-leakage mapping" model.
[0013] Furthermore, step S5 includes the following sub-steps: S501. When the explosion-proof industrial robot is in a safe range and there is no abnormal flow consumption, the energy efficiency priority control strategy is adopted to enter the first-level steady-state cruise state and reduce the number of solenoid valve actions; the intake valve is controlled to open and close through the hysteresis comparison mechanism, and the Pearson correlation coefficient between the real-time pressure gradient and the theoretical volume change rate is calculated. The pressure fluctuation caused by motion and the actual leakage are distinguished according to the Pearson correlation coefficient. If it is a pressure fluctuation caused by motion, the first-level state is maintained; otherwise, the second-level leakage compensation state is switched. S502. When an unexpected micro-crack caused by aging or slight displacement of the sealing ring is detected, the gas leakage enters the second-level leakage compensation state. The constant pressure control mode is used to maintain the positive pressure chamber pressure. The equivalent leakage area is calculated in reverse based on the Saint-Venant equation. The second derivative is used to distinguish between stability damage and expansion damage. An early warning is sent for stability damage and constant pressure compensation is maintained. For expansion damage, the state is upgraded to the third level. S503. When the leakage rate exceeds the compensation capacity of a single gas source, it enters the third-level active hot backup state, switches to dual gas source parallel gas supply, predicts the remaining safe time for the pressure in the positive pressure cavity to decay to the critical value based on Boyle's Law, and establishes an inverse mapping relationship between the leakage rate and the maximum speed of the joint to limit the dynamic movement, and judges whether to continue to execute the task or return to the position in an emergency based on the remaining safe time and the time required to complete the current process. S504. When the physical protection layer fails or the sensor is detected to be tampered with or disconnected, a level four emergency blocking state is triggered, and the ignition source energy is cut off through the hardware safety relay, and the bus capacitor discharge circuit is closed. S505. To avoid state oscillation, a state recovery hysteresis criterion is set. A real-time health function is constructed based on pressure, pressure change rate and gas source status. When regressing from a high-risk state to a low-risk state, both overshoot condition and time dwell condition must be met simultaneously. After completing self-healing confirmation, the state is switched.
[0014] Furthermore, in S502, a time integral constraint is introduced, and the transition to the third-level state is triggered only when the duration of the abnormal state satisfies the following formula. in, For the current moment, The length of the sliding time window. For the equivalent leakage area, The safe threshold for the leakage area. For indicator functions, This is the minimum confirmation time window.
[0015] Furthermore, in step S505, a real-time health function is constructed, which is expressed as: in, For real-time health status, , , These are the weighting coefficients. This represents the current actual pressure value. The pressure data are under standard operating conditions. The rate of change of pressure, The maximum allowable rate of pressure change, To supply energy pressure to the gas source, This is the rated value for the gas source.
[0016] When rolling back from a high-risk state to a low-risk state, both the overshoot condition and the time dwell condition must be met simultaneously, which are expressed as follows: in, This is a state transition action. The current risk level is relatively high. The next lowest risk level. The baseline threshold for the state. To allow for retracement, For a period of time during which the health status has remained stable, Minimum stay confirmation time.
[0017] Furthermore, step S6 includes the following sub-steps: S601. A feedforward PID pressure regulator is built based on a leakage observer. In the secondary leakage compensation state, it switches to the constant pressure holding mode. The feedforward compensation control command is generated according to the real-time leakage flow estimate and drives the intake proportional valve to achieve predictive pressure regulation. S602. In the three-level active hot backup state, the backup air source is switched in milliseconds by segmented overexcitation drive. At the same time, the joint speed is dynamically constrained according to the real-time leakage rate. The execution time is reset through the motion controller trajectory planning layer, so that the robot can decelerate smoothly to a safe state along the original path. S603. In the fourth-level emergency interruption state, the physical interface of the servo driver STO is cut off by the safety controller hardware, and a parallel bus capacitor active discharge circuit is designed to ensure that the bus voltage drops to the safety extra-low voltage before the explosion-proof enclosure is completely depressurized.
[0018] The fault-tolerant control method for explosion-proof industrial robots with multi-level safety redundancy provided by this invention has the following beneficial effects: 1. This invention provides an explosion-proof industrial robot with a dual-redundancy architecture of "external air source + air tank source". This invention breaks through the traditional robot's absolute dependence on a single external air source. When the system detects a loss of pressure in the main air path, a pipe break, or an interruption in external air supply in real time through a pressure sensor network, the control algorithm immediately triggers a millisecond-level seamless switch, automatically transferring the air supply to the positive pressure chamber from the external pipeline network to the high-pressure air tank source carried by the robot itself. This redundant air supply mechanism ensures that even in extreme conditions where the external air source is completely lost, the explosion-proof inner cavity can still maintain a positive pressure environment, giving the robot valuable time to complete emergency reset, critical posture adjustments, or perform controlled safety shutdown. This transforms passive protection into active survival, significantly improving the system's inherent safety.
[0019] 2. Construct a dual-layer physical protection system consisting of an overall positive pressure outer shell and independent explosion-proof enclosures for core components. While maintaining an overall positive pressure environment for the robot, core electrical components that are prone to sparking, such as servo motors and controllers, are independently and modularly sealed or explosion-proof encapsulated. Even if the outer shell suffers physical damage leading to pressure loss, the inner independent chamber can still maintain a short-term protection level to prevent ignition sources from leaking out, achieving dual safety assurance.
[0020] 3. A four-level active fault-tolerant control method based on pressure gradient prediction is proposed. Unlike the traditional on-and-off control mode, this method establishes four layers of control logic: stable cruise, leakage compensation, active hot backup, and emergency shutdown. The system can automatically adjust the flow rate for dynamic compensation in the face of minor leaks caused by seal aging. When faced with gas source fluctuations, it actively provides a hot backup gas source to maintain pressure, and triggers an emergency power cut-off only in the event of an irreversible serious fault. This method maximizes the continuity of robot operation and reduces unnecessary downtime while ensuring explosion-proof safety. Attached Figure Description
[0021] Figure 1 This is a flowchart of a fault-tolerant control method for an explosion-proof industrial robot with multi-level safety redundancy, as shown in the embodiment.
[0022] Figure 2 This is a schematic diagram of the robot hardware system with double-layer protection and dual-air source redundancy in the embodiment.
[0023] Figure 3 This is a schematic diagram of the hierarchical fault-tolerant control technology method in the embodiment. Detailed Implementation
[0024] The specific embodiments of the present invention are described below to enable those skilled in the art to understand the present invention. However, it should be understood that the present invention is not limited to the scope of the specific embodiments. For those skilled in the art, various changes are obvious as long as they are within the spirit and scope of the present invention as defined and determined by the appended claims. All inventions utilizing the concept of the present invention are protected.
[0025] This embodiment presents a fault-tolerant control method for explosion-proof industrial robots with multi-level safety redundancy. It employs a dual-source redundancy architecture of "external main air supply + gas tank air source," supplemented by a dual-layer physical isolation protection system. This provides hardware support for the algorithm layer. By integrating high-frequency data acquisition, data alignment, and a pressure gradient-based trend prediction mechanism, the system can compare dynamic leakage models in real time, thereby achieving four levels of active fault-tolerant control from steady-state cruise to emergency shutdown. The method mainly includes constructing a robot hardware system with dual-layer protection and dual-gas-source redundancy, real-time data acquisition and alignment, data preprocessing and pressure gradient trend prediction, system initialization and dynamic leakage benchmark calibration, risk assessment and four-level state judgment, and graded active fault-tolerant control and safe execution. (Reference...) Figure 1 Specifically, it includes the following: S1. Construct a robot hardware system with double-layer protection and dual-air source redundancy; A double-layer physical protection nested structure and a dual-air-source redundant parallel air supply architecture are constructed for an explosion-proof industrial robot. A distributed redundant sensor network and a cavity pressure field equalization structure are configured within the positive pressure cavity. (Reference) Figure 2 Specifically, it includes the following sub-steps: S101. Construct a double-layered physical protection nested structure; In some embodiments, a nested structure of "overall positive pressure outer shell + independent explosion-proof core components" is designed. The outer layer is constructed from a high-strength, lightweight alloy material to form an overall positive pressure cavity, used to enclose the robot body and wiring harness; the inner layer, for high-risk spark sources such as servo motors, drivers, and controllers, is designed with independent modular explosion-proof enclosures, forming... The robot has a double-layered volumetric structure. From a thermodynamic volumetric perspective, let the total volume of the robot's outer shell be... It integrates an independent high-level explosion-proof module, the size of which is [missing information]. The system requires an effective control volume to maintain positive pressure via an air passage. Defined as: in, The volume of the outer positive pressure cavity. For the first The volume of each internal independent explosion-proof module, To effectively control the volume, This represents the total number of internally independent explosion-proof modules. For the first The volume of an internally independent explosion-proof module.
[0026] The physical significance of this nested design lies in establishing spatial redundancy in the pressure gradient. Assuming the outer shell ruptures, resulting in an effective volume... Even in the event of pressure loss, the inner explosion-proof cavity can still rely on its own mechanical sealing strength. And internal residual pressure, within the time window The inner cavity must prevent explosive gases from contacting electric sparks. Based on this, design constraints require the inner cavity to meet the following explosion-proof pressure requirements: in, For safety reasons, This represents the estimated maximum blast shock wave pressure.
[0027] S102. Construct a dual-loop parallel air supply architecture at the robot's fluid input end; In some embodiments, the main circuit is connected to an explosion-proof pipeline (source). The secondary circuit integrates a high-pressure carbon fiber wound air tank and an air source cavity (source) within the robot base. Both flow through a set of high-speed electromagnetic switching valves to the intake pipe. The output pressure of the air supply system is modeled as a binary switching function. Let the external pipeline pressure be... The regulated pressure of the gas storage tank after passing through the pressure reducing valve is Switch the control variable to (1 represents the main gas source is normal, 0 represents switching to standby). The combined gas supply pressure is then... Described as: in, This refers to the external pipeline pressure.
[0028] In a specific embodiment, the physical logic of the gas storage tank's capacity design must meet the requirements. Its minimum volume... The calculation is not based on steady-state gas consumption, but on the maximum permissible leakage rate. Emergency evacuation time According to Boyle's Law, the minimum volume constraint for a safe evacuation is: in, Standard atmospheric pressure, For gas release efficiency, This is the initial high pressure of the gas storage tank. To maintain the minimum operating pressure required for explosion protection.
[0029] S103, Dynamic differential pressure balance fluid control; In some embodiments, when the robot moves at high speed, the extension and retraction of the robotic arm will cause the volume of the positive pressure cavity to increase. Dramatic changes. To maintain internal pressure. , Given the current environmental pressure of the robot, a dynamic flow balance must be established. Based on the fluid dynamics continuity equation and the gas state equation, the internal cavity pressure... rate of change over time From the difference in inflow and outflow rates and the rate of change in volume Joint decision: in For airflow rate, The volume of the cavity. The thermal insulation index. When the robot extends rapidly... When the pressure drops naturally, the control system must feedforward to increase the intake airflow. To counteract the negative pressure tendency caused by volume expansion, thereby ensuring It always stays above the safety threshold.
[0030] S104. Arrange at the far end, near end, and airflow dead zone of the positive pressure cavity. A pressure sensor group is assembled, and temperature probes are placed at key heat-generating components to construct a distributed redundant sensor network; In some embodiments, a weighted fusion algorithm based on the inverse variance is used to eliminate single-sensor drift.
[0031] in, For system pressure fusion observations, The total number of effective sensors participating in the fusion. For the first The current weights of each sensor, For the first Real-time readings from each sensor. For historical variance, For the traversal variable in the summation formula, No. Historical noise variance of each sensor.
[0032] The hardware circuit has a self-test function for disconnection; if any sensor reading is broken... Deviation from the group mean More than 3 standard deviations, i.e. The system automatically removes the node to ensure the physical authenticity of the input data.
[0033] S105. Analysis of cavity pressure field homogenization based on thermodynamic equilibrium; To avoid airflow dead zones within the large-volume positive pressure cavity, which could lead to localized explosive gas accumulation, a multi-point turbulence compensation mechanism is incorporated into the physical structure design. The system utilizes a Venturi jet positioned at the location with the largest length-to-diameter ratio within the cavity, employing high-pressure air intake to drive the circulation of residual gas within the cavity. Let any point within the cavity... Pressure deviation is Define the spatial pressure uniformity factor Through fluid simulation optimization, we ensure that the minimum sustaining flow rate is maintained. The following conditions must be met: in, This is a preset uniformity threshold. This physical constraint ensures the uniformity of the sensor observations. It can accurately represent the pressure state of the entire cavity, avoiding safety blind spots caused by local pressure loss.
[0034] S2. A clock synchronization mechanism is used to perform time-series alignment, filtering, noise reduction, and environmental decoupling processing on the multi-source sensor data of the explosion-proof industrial robot; this specifically includes the following sub-steps: S201. Due to the high propagation speed of pressure waves and the short control cycle of the robot, time deviations in sensor data can cause model failure. Therefore, the internal control system of the explosion-proof industrial robot adopts the Precision Time Protocol (PTP) to synchronize clocks between the main controller and distributed nodes. This is achieved by recording the four time intervals of the synchronization messages on the physical link. Calculate the phase deviation between the master and slave clocks. and path delay All collected raw pressure data All are mapped to a unified time axis using a correction formula. : in, This is the original local timestamp. For the delay compensation strategy coefficient.
[0035] This design ensures that the pressure value recorded at a certain moment strictly corresponds to the robot's robotic arm posture at that moment, controlling the synchronization error to the sub-microsecond level.
[0036] S202, Data resampling and vectorization; In some embodiments, the data includes continuous analog pressure. ,temperature and discrete digital joint angle Due to the different sampling rates, multi-rate signal processing is necessary. Linear interpolation is used to map low-frequency data onto a high-frequency time axis. For the aligned time, the resampled value for: in, In the original low-frequency data, The most recent sampling time on the right, In the original low-frequency data, The most recent sampling time on the left.
[0037] After alignment is complete, build time The state vector of the entire system This vector, which integrates thermodynamic and kinematic states, serves as the unified input interface for subsequent algorithmic steps. ; in, For a moment The cavity pressure, For a moment The rate of change of pressure, For a moment The cavity temperature, For a moment The joint angle, For a moment The joint angular velocity.
[0038] S203. The pressure signal is filtered and denoised using the Kalman filter algorithm. In some embodiments, a discrete Kalman filter is used to optimally estimate the pressure signal to address the high-frequency noise generated by the frequency converter, and state prediction equations and observation equations are established: in, For prior state estimation, Here is the state transition matrix. For posterior state estimation, To control the input matrix, To control the input vector, This is the actual sensor measurement value. For the observation matrix, For the true state vector, For measuring noise.
[0039] Using Kalman gain Dynamically corrected predicted values, optimal estimate after denoising for: When the system is in steady state Convergence is used to suppress noise; when a sudden leakage occurs, the filter can quickly track the real change.
[0040] S204. Introduce absolute pressure, combine the filtered and denoised data with ambient temperature and atmospheric pressure parameters for normalization and decoupling processing, and obtain pressure data under standard working conditions. Specifically, due to the current atmospheric pressure and current ambient temperature Directly using absolute pressure can lead to misjudgments due to seasonal variations. The system incorporates dimensionless processing, applying the ideal gas law to the real-time measured absolute pressure. Converted to standard operating conditions: in, For standard reference temperature, Standard atmospheric pressure.
[0041] After this treatment It only reflects the sealing performance of the system, completely eliminating physical interference caused by changes in ambient temperature and humidity.
[0042] S3. Based on the pressure data of the positive pressure cavity processed in S2 and the robot's motion state, leakage is identified through discrete pressure gradient calculation and decoupling from motion disturbance. Abnormal leakage states are then identified using Taylor series pressure trend prediction and dynamic model residual integral analysis. This process includes the following steps: S301, Real-time calculation of discrete pressure gradient; In some embodiments, purely monitoring pressure values is often too late. Based on the pressure data after time-series unification and alignment in S2, the derivative is calculated using the five-point central difference method: in, For the first derivative of pressure and the rate of change of pressure, These are the pressure values from the first two sampling points. This is the pressure value from the previous sampling point. This is the pressure value at the next sampling point. The sampling interval; For the second derivative of pressure and the rate of acceleration of pressure change; The more negative the value, the faster the leakage. The more negative the value, the larger the leak is. The rate of pressure drop and the acceleration rate of pressure drop are far more sensitive to minor faults than the pressure value itself.
[0043] S302, Decoupling of motion interference and identification of true and false leakage; In some embodiments, the volume of each joint cavity during robot movement... Changes can lead to false leaks. The system uses a kinematic Jacobian matrix to calculate the theoretical volume change rate. According to the total differential formula, the actual leakage pressure gradient... Equal to measuring gradient Subtract the gradient caused by the motion: in, For the first The sensitivity of individual joint movements to the overall volume. Only when decoupled... A physical leak is only considered to exist when the value is significantly less than zero.
[0044] S303, Time Prediction Based on Taylor Series; In some embodiments, to overcome the physical response delay of the solenoid valve, the system constructs a pressure trend prediction model based on Taylor series, using the current state to predict future moments. pressure value : in, The leakage pressure drop rate at the current moment. The current rate of increase in leakage pressure drop. This represents the truncation error.
[0045] System setting prediction step size For the response time of the implementing agency, if it is within the prediction window, It will fall below the safety threshold. That is, satisfying: in, By predicting the time window, there is no need to wait for the actual pressure to decrease; an early warning is triggered immediately, thus achieving negative delay control.
[0046] S304, Dynamic Model Residual Integral Analysis; In some embodiments, a physical model-based observer is run to calculate the theoretical steady-state pressure. Calculate the residual integral To identify minute leaks: in, The length of the sliding integral window. For actual pressure measurement, This refers to the current moment.
[0047] When the integral value exceeds the threshold, it indicates a continuous gas loss that cannot be explained by noise, thus accurately identifying slow leaks.
[0048] S4. Perform static airtightness self-test on the explosion-proof industrial robot and construct a dynamic leakage map of the entire attitude space. Then, dynamically adjust the pressure threshold using a normalized correction factor for environmental parameters. Combine this with threshold drift adjustment based on seal aging trends and a seal fatigue cumulative loss model to complete the dynamic compensation calibration of the dynamic leakage benchmark. This process includes the following steps: S401. Static airtightness self-test and baseline establishment; In some embodiments, the control system of the explosion-proof industrial robot performs a static self-test each time it is powered on. The robot is then inflated to its rated pressure while stationary. After locking, time measurement The natural pressure drop within the cavity. Calculate the static leakage rate. : in, The absolute pressure at the start of the lockout. The absolute pressure at the moment the lockout ends.
[0049] Static leakage rate The indicator represents the health of the entire machine's sealing system. If... Greater than the allowable threshold The system locks and reports an error; this step establishes the safety baseline for the current run.
[0050] S402, Construction of dynamic leakage map in all attitude space; In some embodiments, the compression deformation of the seal varies at different joint angles, resulting in a normal leakage rate that is attitude-dependent. The function.
[0051] During the initialization phase, the robot traverses typical trajectories, the system records the maintenance flow rate under each posture, and constructs a "posture-leakage mapping" model. : in, The attitude-related baseline bias leakage rate, For the "attitude-leakage mapping" function, For multi-joint angle vectors, For the 1st, 2nd to the 3rd The angle values of each joint. This represents the total number of joints involved in the modeling.
[0052] During actual operation, abnormal deviations are calculated: in, This is an abnormal deviation amount. For real-time measurement of maintenance flow. In the current posture Below, the model looks up the normal bias leakage rate from the table. Only when the deviation is significant is it considered abnormal, thus masking the influence of attitude changes.
[0053] S403, Normalization correction of environmental parameters; In some embodiments, ambient temperature and atmospheric pressure Changes in the pressure threshold can cause criterion drift. Therefore, the system introduces a normalization correction factor to adjust the pressure threshold. Dynamically adjusted to : in, The current ambient temperature. For standard reference temperature, Standard reference atmospheric pressure, This is the current ambient atmospheric pressure. This formula is based on... This ensures that the system's criteria for judging insufficient gas molar quantity remain constant regardless of environmental changes, thereby achieving cross-regional robustness.
[0054] S404, Threshold drift of aging trend; In some embodiments, considering the irreversible aging of the sealing rubber, a forgetting factor is introduced into the system. Based on historical average leakage rate Dynamically adjust alarm thresholds : in, For the first The current alarm threshold for the step, This is the alarm threshold from the previous step.
[0055] This mechanism allows the system to accept normal linear degradation of sealing performance and focuses on detecting sudden, exponential failures; S405, Fatigue Cumulative Loss Model and Dynamic Compensation Calibration of Sealing System; In some embodiments, the number of cycles of operation of the explosion-proof robot seal is taken into account. Increased damage can occur, so this step introduces a benchmark correction based on cumulative damage theory. This is achieved by recording the robot's total mileage. and mean internal pressure Establish a sealing loss correction factor : in, The characteristic mileage constant, This is the mechanical wear weighting coefficient. This is the pressure fatigue weighting coefficient. This refers to the real-time pressure of the internal cavity. External environmental pressures.
[0056] Regularly according to The "attitude-leakage mapping" model constructed in the automatic fine-tuning step. This long-cycle adaptive mechanism avoids frequent false alarms of level 3 leakage due to sealing ring aging, ensuring the logical consistency of the redundant control algorithm throughout the robot's entire lifecycle.
[0057] S5. Based on the sensor data processed in S2, the leakage identification results in S3, and the leakage benchmark after dynamic compensation calibration in S4, a multi-dimensional risk assessment is performed on the positive pressure cavity. The explosion-proof industrial robot is then divided into four operating states, and logical switching and hysteresis self-healing confirmation between these states are implemented. (Reference) Figure 3 Specifically, it includes the following steps: S501, the first-level steady-state cruise state of the energy efficiency priority optimal control strategy; In some embodiments, when in a green safe zone No abnormal flow consumption was detected, indicating a first-level steady-state cruise state. At this point, the positive pressure chamber's sealing performance was intact, and the pressure drop was solely due to natural permeation of the sealing ring. The control system's objectives were energy efficiency management and mechanical protection, reducing the number of solenoid valve openings and closings and extending actuator life. To prevent high-frequency oscillations in the valves caused by sensor noise, a hysteresis comparison control mechanism was introduced into the algorithm. The dead zone for pressure control was defined as... Intake valve control law Described as: in, The lower limit of the pressure dead zone, The upper limit of the pressure dead zone, This refers to the valve status in the previous control cycle.
[0058] This logic ensures that the inflation action is pulsed, starting only when the pressure reaches its lowest point and immediately shutting off once the maximum pressure is reached.
[0059] When a robot moves at high speed, joint movements cause compression or expansion of the internal cavity volume, resulting in drastic pressure fluctuations. To distinguish these physical fluctuations from actual leakage, the system incorporates an analysis of the correlation between pressure and the rate of volume change, calculating the real-time pressure gradient. Compared with the theoretical volume change rate calculated based on encoder feedback Pearson correlation coefficient between : in, For the first Pressure change rate at each sampling point This represents the mean rate of change of pressure within the window. For the first The theoretical volume change rate at each sampling point This represents the mean rate of volume change within the window. This is the threshold for determining relevance.
[0060] like This indicates that the pressure change is mainly driven by the volume change, which the system determines as a normal physical phenomenon. It maintains a Level 1 state and does not trigger an alarm.
[0061] like Continuous monitoring This indicates the presence of pressure loss that cannot be explained by motion. The system determines that there is a real leak and automatically transitions to the secondary leak compensation state.
[0062] S502, Secondary leakage compensation state based on dynamic compensation of flow resistance model; In some embodiments, the secondary leakage compensation state corresponds to the yellow warning zone; an unexpected gas leak caused by aging microcracks or slight displacement of the sealing ring is detected, but the leakage rate is low. It remains within the compensation capacity range of a single main gas source. At this point, the control strategy no longer pursues energy saving but switches to a constant pressure control mode, maintaining the protection level while performing fault diagnosis. The simple pressure drop rate cannot distinguish whether leakage is rapid or charging is slow. This invention, based on the Saint-Venant equations of compressible fluid dynamics, constructs an observer to inversely calculate the equivalent leakage area, using this as the physical true value for assessing the degree of seal damage: in, For the equivalent leakage area, This is the actual measured value from the flow meter. The outflow coefficient, The adiabatic index, This represents the rate of change of mass within the cavity. The system calculates... Second derivative analysis was performed to differentiate fault types: Stability damage: If This indicates that the leak point orifice diameter is stable, the system maintains constant pressure compensation, and sends a maintenance warning signal to the monitoring system without interrupting production; Extended damage: if This indicates that the leak hole is spreading through the cracks in the pressurized shell, posing a risk of bursting. The system is immediately upgraded to Level 3 active hot backup status.
[0063] To prevent misjudgments caused by electromagnetic interference, a time integral constraint is introduced for state transitions. A state transition is only confirmed when the duration of the abnormal state satisfies the following formula: in, For indicator functions, Minimum confirmation window, The safe threshold for the leakage area. This represents the length of the sliding time window.
[0064] S503, Level 3 active hot backup state of time window constraint degraded operation; In some embodiments, the Level 3 active hot backup state corresponds to the orange danger zone; phenomena such as main air supply network rupture, air compressor shutdown, or a sharp increase in seal leakage rate may occur. At this point, a single air source can no longer maintain the set pressure, and it is predicted that the internal pressure will drop below the safety threshold within a short period. The control system triggers the dual-source parallel mode and intervenes in the motion control system. The system no longer waits for a true pressure alarm but instead predicts the internal pressure to decay to a critical value based on the current total leakage rate and Boyle's Law. Remaining safe time: in, This represents the remaining safe time.
[0065] To prevent uncontrolled internal pressure fluctuations caused by the bellows effect aggravated by the rapid movement of the robotic arm, the maximum joint speed is established. With leakage rate The inverse mapping relationship reduces the peak value of internal pressure fluctuations by limiting dynamic motion: in, The constant is the airtight coupling constant of the motion. This represents the current equivalent leakage area. Simultaneously, the system will compare this with the remaining safe time. Time required to complete the current process : like : Allows the current command to be completed in slowdown mode.
[0066] like Immediately suspend the task and plan the shortest path back to a safe position.
[0067] S504, Level 4 emergency blocking state of fail-safe interlock; In some embodiments, the Level 4 emergency shutdown state is in the red prohibited zone; the surface physical protective layer has failed, or a fatal error such as sensor tampering or disconnection has been detected. At this time, all possible ignition source energy must be cut off; the trigger signal for this state is directly mapped to a hardware safety relay. To prevent logic deadlock or oscillation, the current Level 4 emergency shutdown state... The system follows a logic that locks upon triggering until manually hard reset: in, This is the critical pressure threshold. This is a manual hard reset signal.
[0068] Even if the sensor reading briefly recovers after triggering, the system remains locked, and automatic restart is strictly prohibited. Simultaneously with disconnecting the servo drive STO, the system closes the active discharge circuit of the bus capacitor. To ensure the elimination of the risk of electrical sparks before the explosion-proof enclosure completely loses pressure, the system must be constantly monitored after power disconnection. Capacitor residual voltage The decay must meet the safety time window. Constraints: in, This formula, representing intrinsically safe voltage, guides the use of bleed resistors in hardware circuits. The maximum resistance value is selected to ensure that the robot quickly becomes electrochemically inert. It is the maximum equivalent capacitance of all energy storage capacitors on the bus.
[0069] S505, Hysteresis Comparison and Self-Healing Confirmation Logic for State Recovery; In some embodiments, to prevent the control system from oscillating at high frequencies between alarm and recovery states, this invention sets stringent hysteresis criteria on the state rollback path. The real-time health of the control system is defined. The weighted normalized function is the sum of pressure, pressure change rate, and gas source status: in, , , These are the weighting coefficients for the three terms. The maximum allowable rate of pressure change, The current pressure of the gas source, This refers to the rated pressure of the gas source.
[0070] When the control system attempts to escape a high-risk state Restored to low-risk status At that time, both the overshoot condition and the time dwell condition must be met simultaneously: in, This serves as the baseline threshold for entering this risk state. The delayed increment demonstrates that the gas source has sufficient refill capacity, rather than being at critical drift. The duration for which health indicators are continuously met. It is the minimum residence time used to filter out transient false signals caused by tracheal vibration or valve operation.
[0071] S6. Based on the four-level operating status, perform graded active fault-tolerant control on the positive pressure chamber and the dual-gas-source supply architecture, implementing leakage compensation, dual-gas-source switching, motion degradation constraints, and hardware emergency shutdown. This specifically includes the following steps: S601, Feedforward PID pressure regulation based on leak observer; In some embodiments, when secondary leakage caused by seal aging is detected, the system no longer pursues the energy efficiency of pulsed inflation but switches to constant pressure maintenance mode. The goal is to eliminate steady-state errors and ensure the internal cavity pressure. Always locked at the security setting. Traditional PID controllers only begin adjusting after the pressure has decreased, exhibiting significant lag. This invention utilizes the calculated real-time leakage flow estimate. A composite controller with feedforward compensation was constructed, and the opening command of the intake proportional valve was... Defined as: in, For pressure tracking error, It is the inverse function of the proportional valve's flow characteristic. For integral gain, For proportional gain, For differential gain, This is the feedforward gain.
[0072] When the system calculates the leakage amount When increasing the pressure, the controller directly increases the valve opening before the pressure sensor reading drops. By replenishing an equal amount of gas, predictive regulation can be achieved.
[0073] S602: Dual-source millisecond-level switching and motion degradation; When the state machine determines that the main air source has failed and a level 3 active hot backup state has been reached, the system must open the solenoid valve of the on-board high-pressure air tank within milliseconds. To overcome the mechanical inertia and inductive delay of the valve core, the overexcitation drive circuit used in this invention designs the drive voltage applied to the backup valve coil as a piecewise function: in, This is the critical response time for the solenoid valve to open. The voltage applied across the solenoid valve coil, For high voltage drive value, This is the low voltage maintenance value.
[0074] This strategy ensures gas path switching delay. Minimize. In Level 3 active hot backup mode, to prevent the robotic arm's high-speed movement from further damaging the already compromised sealing structure, the system forcibly intervenes in the motion controller trajectory planning layer. Define joints. Allowable speed space Its boundary is determined by the real-time leakage rate. Dynamic constraints: in, To constrain the steepness index, For the first The actual angular velocity of each joint This is a dynamic speed limit value. The limit angular velocity allowed by the mechanical structure. This is the critical leakage flow rate.
[0075] when hour, The robot automatically and smoothly decelerates to a stop. This process is not a simple abrupt stop, but a time reset along the original path, ensuring that no additional dynamic impact pressure is generated during the shutdown process. Time reset refers to the control strategy in the Level 3 emergency state of air source failure, where the robot does not directly trigger an abrupt stop, but instead uses the algorithm intervention of the motion controller trajectory planning layer to recalibrate and reset the time axis parameters of the motion trajectory to zero, driving the robot to reverse along the original path and return to a safe state according to the appropriate deceleration sequence.
[0076] when Approaching the critical leakage rate When, smoothing coefficient The deceleration gradient is adjusted synchronously with the time reset, and the joint angular velocity is adjusted accordingly. Gradually approaching 0. The entire process, through the replanning of the timeline, ensures that the robot's speed and path position are strictly matched at each reset time node, achieving a smooth stop along the original path and according to the new time sequence.
[0077] S603: Intrinsically safe cut-off and active discharge; In some embodiments, once a red alarm for a Level 4 emergency shutdown state is triggered, the safety controller directly disconnects the STO physical interface of the servo drive. This cuts off the rotating magnetic field energy of the motor stator coils at the hardware level, ensuring that software failure will not cause the motor to malfunction. At the moment of power cut-off, the driver bus capacitor still stores high-voltage charge, posing an extremely high-risk ignition source. This invention designs an active discharge circuit in parallel with this capacitor. Design constraints require that the bus voltage must remain constant before the explosion-proof enclosure is completely depressurized. The voltage must be reduced to a safe extra-low level. Assume the casing depressurization time is... Then the bleed resistor The maximum resistance must satisfy the RC discharge inequality: The upper limit for resistor design is derived as follows: During this phase, the system forces the discharge process by closing the discharge circuit with a transistor, ensuring that the robot's electrical properties return to an intrinsically safe state even when the physical explosion protection fails.
[0078] This invention innovatively constructs a dual-source architecture of "external gas supply + gas tank source" at the physical layer, and a nested protection structure of "overall positive pressure shell + independent explosion-proof core components." At the logical layer, a four-level state monitoring machine model is established to dynamically allocate resources based on the severity of leakage. When the external gas source in the main circuit leaks or fails, the system can switch to the gas tank source at millisecond speeds and plan an escape route using the remaining safe time calculated by Boyle's Law. This deep defense system, combining hardware and software, ensures that the robot still possesses short-term autonomous maintenance and safe evacuation capabilities in the event of a catastrophic failure, significantly improving the inherent safety level of the system.
[0079] This invention incorporates hardware-level fault-lock logic. While disconnecting the servo drive STO, it not only reduces the main voltage below the intrinsically safe voltage within a safe time window through an active discharge circuit, but also employs a pneumatic path blocking strategy to prevent external hazardous gases from being drawn back into the cavity using negative pressure. This thorough control over electrical and pneumatic energy ensures that the robot can quickly become electrochemically inert in its final failure state, greatly eliminating the possibility of secondary ignition sources.
[0080] This invention introduces a state-space equation encompassing thermodynamics and kinematics for the entire system. Utilizing Kalman filtering and Jacobian matrix decoupling techniques, it calculates the correlation between pressure gradient and volume change rate in real time, accurately removing motion interference and achieving low false alarm identification of genuine and false leaks. Simultaneously, based on a Taylor series time window prediction algorithm, the system can proactively initiate flow compensation or gas source switching at a negative delay before the internal pressure actually falls below the safety threshold. This proactive intervention mechanism enhances the response capability of the explosion-proof system and effectively solves the problem of unnecessary shutdowns caused by pressure fluctuations under complex operating conditions.
[0081] Although specific embodiments of the invention have been described in detail with reference to the accompanying drawings, this should not be construed as limiting the scope of protection of this patent. Various modifications and variations that can be made by a person skilled in the art without inventive effort within the scope described in the claims still fall within the scope of protection of this patent.
Claims
1. A fault-tolerant control method for explosion-proof industrial robots with multi-level safety redundancy, characterized in that, Includes the following steps: S1. Construct a double-layer physical protection nested structure and a dual-air source redundant parallel air supply architecture for explosion-proof industrial robots, and configure a distributed redundant sensor network and cavity pressure field equalization structure in the positive pressure cavity. S2. A clock synchronization mechanism is used to perform time-series alignment, filtering and noise reduction, and environmental decoupling on the multi-source sensor data of the explosion-proof industrial robot. S3. Based on the pressure data of the positive pressure cavity processed in S2 and the robot's motion state, leakage is identified by decoupling discrete pressure gradient calculation and motion disturbance, and abnormal leakage states are identified by Taylor series pressure trend prediction and dynamic model residual integral analysis. S4. Perform static airtightness self-test on the explosion-proof industrial robot and construct a dynamic leakage map of the full attitude space. Use the normalization correction factor of environmental parameters to dynamically adjust the pressure threshold. Combine the threshold drift adjustment of the sealing aging trend and the sealing fatigue cumulative loss model to complete the dynamic compensation calibration of the dynamic leakage benchmark. S5. Based on the sensor data processed in S2, the leakage identification results in S3, and the leakage benchmark after dynamic compensation calibration in S4, a multi-dimensional risk assessment is performed on the positive pressure cavity, and the explosion-proof industrial robot is divided into four operating states and the logical switching and hysteresis self-healing confirmation between operating states are realized. S6. Based on the four-level operating status, perform graded active fault-tolerant control on the positive pressure chamber and the dual-gas-source supply architecture, and implement leakage compensation, dual-gas-source switching, motion degradation constraints and hardware emergency blocking.
2. The fault-tolerant control method for explosion-proof industrial robots with multi-level safety redundancy as described in claim 1, characterized in that, S1 includes the following sub-steps: S101. Construct a double-layer physical protection nested structure. The inner layer uses high-strength lightweight alloy material to construct the positive pressure cavity of the explosion-proof industrial robot, and wraps the robot body and wiring harness inside the positive pressure cavity. The outer layer designs independent modular explosion-proof encapsulation cavities for the servo motor, driver, and controller respectively. S102. Construct a dual-loop parallel air supply architecture at the robot fluid input end. The main loop is connected to the external explosion-proof air supply network, and the secondary loop is connected to the high-pressure carbon fiber wound air storage tank integrated in the robot base. The two air sources are merged into the explosion-proof industrial robot air inlet pipeline through a high-speed electromagnetic switching valve to form a dual redundant air supply path. S103. Real-time acquisition of the volume change rate of the positive pressure cavity, calculation of the cavity pressure change rate based on the fluid mechanics continuity equation and gas state equation, and feedforward adjustment of gas flow rate to compensate for pressure fluctuations caused by the expansion and contraction of the positive pressure cavity, so as to maintain the pressure in the positive pressure cavity in a safe state that is higher than the external environment pressure. S104. Multiple pressure sensors and temperature probes are deployed at the far end, near end and airflow dead zone of the positive pressure cavity to construct a distributed redundant sensor network. The variance inverse weighted fusion algorithm is used to fuse the multiple sensor signals and remove abnormal sensor data to obtain the actual pressure observation value of the positive pressure cavity. S105. A Venturi jet is installed at the position with the largest length-to-diameter ratio in the positive pressure cavity. The high-pressure air intake drives the residual gas in the positive pressure cavity to circulate, suppressing the generation of local airflow dead zones and achieving a uniform distribution of the pressure field inside the positive pressure cavity.
3. The fault-tolerant control method for explosion-proof industrial robots with multi-level safety redundancy as described in claim 1, characterized in that, S2 includes the following sub-steps: S201, based on the IEEE 1588 time protocol, synchronizes clocks between the master controller and distributed nodes, calculates the phase deviation and path delay of the master and slave clocks, and corrects all the collected raw pressure data and maps them to a unified time axis to achieve unified alignment of multi-source signal timing. S202. For continuous analog quantities such as pressure and temperature and discrete digital quantities such as joint angles, a linear interpolation method is used to map low-frequency data to a high-frequency time axis to complete resampling, and then the state vector of the whole system at the corresponding time is constructed. S203. The pressure signal is filtered and denoised using the Kalman filter algorithm. S204. Introduce absolute pressure, combine the filtered and denoised data with ambient temperature and atmospheric pressure parameters for normalization and decoupling processing, and obtain pressure data under standard operating conditions.
4. The fault-tolerant control method for explosion-proof industrial robots with multi-level safety redundancy according to claim 3, characterized in that, S3 includes the following steps: S301. Based on the pressure data after time-series unification and alignment in S2, calculate the first and second derivatives of the pressure to obtain leakage indicators, including the pressure drop rate and the pressure drop acceleration rate. S302. Based on the joint angles resampled by S2, the volume change rate caused by mechanical motion is calculated through the kinematic Jacobian matrix. Combined with the pressure data processed by S2, the true leakage pressure gradient is calculated to distinguish between false leakage and physical leakage. S303. Construct a pressure trend prediction model based on Taylor series, set the prediction step size to the actuator response time, use the pressure trend prediction model to predict the pressure value at future moments, and immediately trigger an early warning if the predicted pressure will fall below the safety threshold. S304. Run the physical model observer to calculate the theoretical steady-state pressure, and identify minor leaks by calculating the residual integral of the theoretical steady-state pressure.
5. The fault-tolerant control method for explosion-proof industrial robots with multi-level safety redundancy according to claim 1, characterized in that, S4 includes the following steps: S401. After the system is powered on, a static air tightness self-test is performed. The robot is statically inflated to the rated pressure and then locked. The static leakage rate is calculated based on the natural pressure drop within a preset time. The safety baseline of the whole machine for this operation is established based on the static leakage rate. When the static leakage rate exceeds the allowable threshold, the system is locked and an error is reported. S402. During the initialization phase, control the explosion-proof industrial robot to traverse typical posture trajectories, obtain the maintenance flow rate under each typical posture trajectory, and then construct the "posture-leakage mapping" model; calculate the abnormal deviation between the actual leakage value and the output value of the "posture-leakage mapping" model to eliminate leakage interference caused by posture changes. S403. Introduce an environmental normalization correction factor to dynamically adjust the pressure threshold in combination with ambient temperature and atmospheric pressure. S404. Introduce a forgetting factor to dynamically adjust the alarm threshold based on the historical average leakage rate. S405. Establish a seal fatigue loss correction factor based on total operating mileage and average internal pressure, and use this seal fatigue loss correction factor to automatically fine-tune the attitude-leakage mapping model.
6. The fault-tolerant control method for explosion-proof industrial robots with multi-level safety redundancy according to claim 1, characterized in that, S5 includes the following steps: S501. When the explosion-proof industrial robot is in a safe range and there is no abnormal flow consumption, the energy efficiency priority control strategy is adopted to enter the first-level steady-state cruise state and reduce the number of solenoid valve actions; the intake valve is controlled to open and close through the hysteresis comparison mechanism, and the Pearson correlation coefficient between the real-time pressure gradient and the theoretical volume change rate is calculated. The pressure fluctuation caused by motion and the actual leakage are distinguished according to the Pearson correlation coefficient. If it is a pressure fluctuation caused by motion, the first-level state is maintained; otherwise, the second-level leakage compensation state is switched. S502. When an unexpected micro-crack caused by aging or slight displacement of the sealing ring is detected, the gas leakage enters the second-level leakage compensation state. The constant pressure control mode is used to maintain the positive pressure chamber pressure. The equivalent leakage area is calculated in reverse based on the Saint-Venant equation. The second derivative is used to distinguish between stability damage and expansion damage. An early warning is sent for stability damage and constant pressure compensation is maintained. For expansion damage, the state is upgraded to the third level. S503. When the leakage rate exceeds the compensation capacity of a single gas source, it enters the third-level active hot backup state, switches to dual gas source parallel gas supply, predicts the remaining safe time for the pressure in the positive pressure cavity to decay to the critical value based on Boyle's Law, and establishes an inverse mapping relationship between the leakage rate and the maximum speed of the joint to limit the dynamic movement, and judges whether to continue to execute the task or return to the position in an emergency based on the remaining safe time and the time required to complete the current process. S504. When the physical protection layer fails or the sensor is detected to be tampered with or disconnected, a level four emergency blocking state is triggered, and the ignition source energy is cut off through the hardware safety relay, and the bus capacitor discharge circuit is closed. S505. To avoid state oscillation, a state recovery hysteresis criterion is set. A real-time health function is constructed based on pressure, pressure change rate and gas source status. When regressing from a high-risk state to a low-risk state, both overshoot condition and time dwell condition must be met simultaneously. After completing self-healing confirmation, the state is switched.
7. The fault-tolerant control method for explosion-proof industrial robots with multi-level safety redundancy according to claim 6, characterized in that, In S502, a time integral constraint is introduced. When the duration of the abnormal state satisfies the following formula, the transition to the third-level state is initiated. in, For the current moment, The length of the sliding time window. For the equivalent leakage area, The threshold for the leakage area. For indicator functions, This is the minimum confirmation time window.
8. The fault-tolerant control method for explosion-proof industrial robots with multi-level safety redundancy according to claim 6, characterized in that, In step S505, a real-time health function is constructed, which is expressed as follows: in, For real-time health status, , , These are the weighting coefficients. This represents the current actual pressure value. The pressure data are under standard operating conditions. The rate of change of pressure, The maximum allowable rate of pressure change, To supply energy pressure to the gas source, This is the rated value for the gas source. When rolling back from a high-risk state to a low-risk state, both the overshoot condition and the time dwell condition must be met simultaneously, which are expressed as follows: in, This is a state transition action. The current risk level is relatively high. The next lowest risk level. The baseline threshold for the state. To allow for retracement, For a period of time during which the health status has remained stable, Minimum stay confirmation time.
9. The fault-tolerant control method for explosion-proof industrial robots with multi-level safety redundancy according to claim 6, characterized in that, S6 includes the following sub-steps: S601. A feedforward PID pressure regulator is built based on a leakage observer. In the secondary leakage compensation state, it switches to the constant pressure holding mode. The feedforward compensation control command is generated according to the real-time leakage flow estimate and drives the intake proportional valve to achieve predictive pressure regulation. S602. In the three-level active hot backup state, the backup air source is switched in milliseconds by segmented overexcitation drive. At the same time, the joint speed is dynamically constrained according to the real-time leakage rate. The execution time is reset through the motion controller trajectory planning layer, so that the robot can decelerate smoothly to a safe state along the original path. S603. In the fourth-level emergency interruption state, the physical interface of the servo driver STO is cut off by the safety controller hardware, and a parallel bus capacitor active discharge circuit is designed to ensure that the bus voltage drops to the safety extra-low voltage before the explosion-proof enclosure is completely depressurized.