Operating a robot control system, method and operating a robot

By constructing an integrated architecture of macro navigation, micro perception, and global arbitration modules, and combining a global state machine and physical constraint units, the island problem and insufficient safety of the operating robot system are solved, and high-precision and high-safety operation control is achieved.

CN122480942APending Publication Date: 2026-07-31BEIJING SAIJIE ZONGHENG TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING SAIJIE ZONGHENG TECHNOLOGY CO LTD
Filing Date
2026-04-24
Publication Date
2026-07-31

AI Technical Summary

Technical Problem

Existing robot control systems suffer from system silos, inaccurate dynamic positioning, insufficient emergency response, and a lack of hardware safety safeguards, resulting in low collaborative efficiency, inadequate operational accuracy, and insufficient safety.

Method used

It adopts a fusion architecture of macro navigation, micro perception and global arbitration modules, realizes high bandwidth and low latency data interaction through global data bus, and introduces global state machine for control management, including normal collaboration, abnormal handling and failure safety mode, and uses physical restriction unit and hardware monitoring unit to ensure security.

Benefits of technology

It achieves real-time alignment of multi-dimensional information, ensuring operational accuracy and safety, providing reliable emergency response and ultimate hardware security, and improving the system's collaborative efficiency and stability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122480942A_ABST
    Figure CN122480942A_ABST
Patent Text Reader

Abstract

This application discloses a control system, method, and robot for operating a robot. The system includes a macroscopic navigation module, a microscopic perception and operation module, and a global arbitration module connected via a global data bus. The global arbitration module maintains a global state machine that switches between normal, abnormal, and failure modes. Under normal conditions, operation is authorized only when three compliance conditions—macroscopic space, microscopic characteristics, and target dynamic stability—are simultaneously met, through a physical constraint unit built into the microscopic module. In abnormal conditions, the system forcibly locks and autonomously executes emergency procedures. In failure conditions, an irrevocable self-locking mechanism of the physical constraint unit is triggered. This application improves the accuracy, safety, and reliability of operation through real-time alignment of multi-dimensional information, forced switching of human-machine control, and an independent hardware fallback mechanism.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of robotics, and more particularly, to a control system, method, computer-readable storage medium, and operating robot. More specifically, this invention relates to a system and method for multi-system fusion, state arbitration, and safety control of operating robots, particularly a control architecture that integrates macroscopic navigation, microscopic perception, and global decision-making modules through a low-level bus, and utilizes a cross-level physical interlocking mechanism to achieve high-safety and high-precision collaborative operation, a corresponding computer-readable storage medium, and an operating robot containing this system. Background Technology

[0002] Operating robots, especially in applications requiring high precision and stability, typically integrates multiple complex subsystems to assist operators in completing tasks. A typical system configuration includes: a navigation system for planning paths and tracking targets on a macroscopic scale; a perception and operating system for providing fine visual feedback and executing specific operations on a microscopic scale; and a safety system for monitoring the overall system status.

[0003] However, existing robot control systems generally suffer from the following technical problems:

[0004] 1. System Silo Problem: In traditional robot control architectures, the macro-navigation system, micro-operating system, and safety monitoring system are often functionally independent and loosely connected information silos. They lack low-level, low-latency data sharing and control interaction mechanisms. This fragmented architecture leads to low coordination efficiency and high response latency between systems, making it difficult to handle complex dynamic scenarios requiring close cooperation among multiple systems.

[0005] 2. Dynamic Positioning Drift Problem: When operating on targets with physiologically periodic movements, robots face the challenge of the time lag between accurate targeting and accurate execution. The target point located by the macro-navigation system may have already deviated from its position due to the target's periodic displacement at the moment the operator actually performs the operation. This spatiotemporal asynchrony can easily lead to operational errors, reducing the accuracy and success rate of the operation.

[0006] 3. Human Risks in Emergency Situations: Unexpected emergency situations may occur during operation. In such cases, operators may make unintended inputs due to the urgency of the situation, potentially exacerbating the problem. Existing systems lack a reliable, instantaneous mechanism that can immediately and forcibly revoke the operator's control when an emergency is detected, and automatically execute the optimal emergency response method.

[0007] 4. System crash risk: Modern robotic systems heavily rely on complex software and artificial intelligence algorithms. In the face of extreme failures such as core algorithm crashes, computing unit malfunctions, or system communication interruptions, without a hardware-based, software-independent ultimate safety mechanism, the robot may exhibit unpredictable and uncontrolled behavior, potentially leading to serious safety incidents.

[0008] Therefore, how to design an operational robot control system that can break down system silos, achieve real-time alignment of multi-dimensional information, enable reliable control switching in emergency situations, and have ultimate hardware safety guarantees is a technical challenge that urgently needs to be solved in this field. Summary of the Invention

[0009] This invention provides a control system, method, computer-readable storage medium, and operating robot, which solves the problems of system silos, inaccurate dynamic positioning, insufficient emergency response, and lack of hardware safety mechanisms in the prior art.

[0010] To achieve the above objectives, a first aspect of the present invention provides a robot control system, comprising:

[0011] The system includes a macro navigation module, a micro perception and operation module, and a global arbitration module. The micro perception and operation module has a built-in physical restriction unit for applying or removing restrictions on an operator's physical input.

[0012] A global data bus is used to transmit data and control commands between the macro navigation module, the micro perception and operation module, and the global arbitration module;

[0013] The global arbitration module is configured to maintain a global state machine and switch between the following modes based on the global state machine:

[0014] In the normal collaborative mode, the physical restriction unit is locked by default. Only when a macroscopic spatial compliance condition, a microscopic feature compliance condition, and a target dynamic stability condition are met simultaneously will the global arbitration module send an unlock command to the physical restriction unit through the global data bus to authorize the operator to perform the operation.

[0015] In the abnormal handling mode, when the global arbitration module determines that an abnormal event has occurred, it sends a high-priority locking command via the global data bus to forcibly activate the physical restriction unit, deprive the operator of the operating authority, and autonomously generates and issues control commands to execute the preset emergency handling process.

[0016] In fail-safe mode, when a system communication timeout or core algorithm failure is detected, the physical limiting unit is triggered to enter an irrevocable in-situ self-locking state.

[0017] In a preferred embodiment, the system further includes: the physical restriction unit is configured to: immediately trigger a perceptible physical force feedback action upon receiving an unlock command, and the triggering time of the physical force feedback action is configured to be earlier than the time of system software interface state update, so as to construct an operator-perceptible security confirmation fingerprint through hardware-level timing difference.

[0018] To achieve the above objectives, a second aspect of the present invention provides a method for controlling an operating robot, comprising the following steps:

[0019] Data and control commands are transmitted between the macro navigation module, the micro perception and operation module, and the global arbitration module through a global data bus. The micro perception and operation module has a built-in physical constraint unit.

[0020] The global arbitration module maintains a global state machine and performs the following switching control based on the global state machine:

[0021] When in normal collaborative mode, the physical restriction unit is kept in a locked state by default, and it continuously determines whether a macroscopic spatial compliance condition, a microscopic feature compliance condition, and a target dynamic stability condition are simultaneously satisfied. When all three are satisfied, an unlocking command is sent to the physical restriction unit.

[0022] When an abnormal event is detected, the system switches to the abnormal handling mode. In this mode, a high-priority locking command is sent to forcibly activate the physical restriction unit, and control commands are automatically generated and issued to execute the preset emergency handling procedures.

[0023] When a system communication timeout or core algorithm failure is detected, the system switches to fail-safe mode. In this mode, the physical limiting unit is triggered to enter an irrevocable in-situ self-locking state.

[0024] To achieve the above objectives, a third aspect of the present invention provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the method described above.

[0025] To achieve the above objectives, a fourth aspect of the present invention provides an operating robot, including a robot body and an operating robot control system as described above.

[0026] The technical solution provided by this invention, by constructing a bottom-level fusion architecture comprising three modules—macro navigation, micro perception, and global arbitration—and utilizing a global state machine for proactive management and switching of control, brings significant beneficial effects:

[0027] 1. In the normal collaborative mode, the system innovatively proposes a logical release mechanism that rigidly binds the operator's physical operation permissions to three dimensions: macroscopic spatial compliance, microscopic feature compliance, and target dynamic stability. This absolute alignment of the spatial-pathological-temporal dimensions ensures that every critical operation occurs at the optimal time and in the most accurate location, fundamentally eliminating positioning errors introduced by the target's dynamic displacement and improving operational accuracy and safety.

[0028] 2. This invention establishes a clear control switching mechanism. Upon detecting an abnormal event, the system can instantly and forcibly strip the operator of control through physical restriction units, creating an exclusive control window free from human interference for the AI ​​to autonomously execute emergency responses, thus avoiding secondary damage caused by human error. The AI's execution of standardized emergency plans demonstrates significant advantages in response speed and decision-making quality compared to human operators.

[0029] 3. This invention constructs a multi-layered security defense system from software to hardware. The first layer is artificial intelligence decision-making and security verification at the software layer; the second layer is a cross-module physical interlocking mechanism to ensure reliable transfer of control; the third layer is a hardware monitoring unit independent of the main system, providing the system with ultimate failure safety assurance unaffected by software state. This system ensures that under any foreseeable software, hardware, or communication failure, the system can enter a deterministic safe state, minimizing risks.

[0030] 4. By introducing a low-latency, deterministic global data bus, this invention breaks down the information silos between functional modules in traditional robot systems. Data can be shared and integrated in real time among modules, providing solid underlying architectural support for achieving higher-level collaborative intelligence and global optimization, and solving the problems of traditional robot systems operating independently and having low collaborative efficiency. Attached Figure Description

[0031] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0032] Figure 1This is a structural block diagram of an operating robot control system provided in an embodiment of the present invention.

[0033] Figure 2 This is a general flowchart of an operational robot control method provided in an embodiment of the present invention.

[0034] Figure 3 This is a control flowchart under the normal collaborative mode provided in the embodiment of the present invention.

[0035] Figure 4 This is a control flowchart under the abnormal handling mode provided in the embodiment of the present invention.

[0036] In the diagram: 100 - Robot control system; 110 - Macroscopic navigation module; 120 - Microscopic perception and manipulation module; 121 - Physical constraint unit; 130 - Global arbitration module; 140 - Hardware monitoring unit; 150 - Global data bus; 160 - Independent hard connection; S201 - System starts and enters normal collaborative mode; S202 - Operation in normal collaborative mode; S203 - Determine if an abnormal event has occurred; S204 - Determine if unlocking conditions are met; S205 - Send unlocking command and authorize operation; S206 - Switch to abnormal handling mode; S207 - Switch to fail-safe mode. S208 - Hardware monitoring unit monitors system status; S301 - Determines macroscopic spatial compliance; S302 - Determines microscopic feature compliance; S303 - Determines target dynamic stability; S304 - Checks if the three conditions are met simultaneously with logical judgment; S305 - Sends unlock command; S401 - Detects abnormal event; S402 - Sends high-priority lock command, forcibly activating physical restriction unit; S403 - AI generates emergency response control command; S404 - Command sent to kinematic safety verification module for review; S405 - Executes verification, determines command safety; S406 - Issues safe emergency response command. Detailed Implementation

[0037] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0038] Example 1

[0039] This embodiment provides a robot control system and corresponding method, which solves the problems caused by system fragmentation, inaccurate dynamic target tracking, insufficient emergency response capabilities, and lack of ultimate hardware security in the prior art.

[0040] See Figure 1 This diagram illustrates a preferred hardware topology of the robot control system 100 in this embodiment. The core of the system 100 lies in constructing a deeply integrated, collaborative control architecture. The system 100 includes a macroscopic navigation module 110, a microscopic sensing and manipulation module 120, and a global arbitration module 130. These three core functional modules are connected via a global data bus 150, enabling high-bandwidth, low-latency data interaction and deterministic transmission of control commands. In some embodiments, the global data bus 150 can be implemented based on industrial Ethernet protocols, such as Ethernet control automation technology or controller area network protocols with flexible data rates, to ensure real-time and reliable communication.

[0041] The macro-navigation module 110 is responsible for localizing the robot, planning its path, and tracking dynamic targets within a large-scale environment. In a specific application scenario, this module 110 can receive high-frequency data from a physiological signal acquisition device and use an internal predictive model to predict the periodic motion patterns of the target. The output of this module 110 includes not only the target's parameters at specific times... Dynamic pose coordinates It can also include the safety operating area boundaries that the robot end effector needs to follow, calculated based on a four-dimensional dynamic model.

[0042] The microscopic sensing and manipulation module 120 serves as the interface for physical interaction between the operator and the robot, and also as a window for acquiring fine information about the target. This module 120 typically includes an operator-gripable handle and a high-resolution sensor deployed at the robot's end effector to acquire real-time microscopic image and video streams of the target. Crucially, this module 120 integrates a physical restraint unit 121. This physical restraint unit 121 is used to actively restrict or release the physical input applied by the operator to the handle. In this embodiment, the physical restraint unit 121 can specifically be a high-frequency responsive electromagnetic solenoid lock. When energized, the latch retracts, allowing the handle to move freely; when de-energized, the latch springs out, locking the handle and achieving physical locking. It should be noted that although this embodiment uses an electromagnetic lock as an example, the physical restraint unit 121 is not limited to this. In other embodiments, the physical restraint unit 121 can also be a servo brake or other device capable of rapidly responding to electrical signals to apply or release mechanical braking, as long as it can forcibly restrict the operator's physical input.

[0043] The global arbitration module 130 is the brain and decision-making center of the entire system. It is responsible for integrating multimodal data from the macro navigation module 110 and the micro perception and operation module 120, performing real-time evaluation of the system's global state, and making the final control decision. This module 130 monitors all data streams through the global data bus 150 and has the highest software control authority, enabling it to issue control commands to other modules, including unlocking or locking commands to the physical restriction unit 121.

[0044] To address extreme risks such as system crashes, system 100 also includes a hardware monitoring unit 140, also referred to as the hardware monitoring unit. This hardware monitoring unit 140 is a computing unit independent of the global arbitration module 130, typically a highly reliable microcontroller unit. It does not participate in complex business logic calculations; its sole responsibility is to monitor the operating status of the core system. The hardware monitoring unit 140 is directly connected to the physical restriction unit 121 via a separate hard connection 160. The signal priority of this hard connection 160 is higher than any software instructions from the global data bus 150, forming the system's last line of hardware security.

[0045] Based on the aforementioned hardware architecture, the global arbitration module 130 is responsible for maintaining a global state machine, which defines three mutually exclusive operating modes of the system: normal cooperative mode, exception handling mode, and fail-safe mode. The workflow of system 100 can be found in [reference needed]. Figure 2 The overall flowchart shown.

[0046] In step S201, the system starts and initializes, and the global arbitration module 130 enters the normal collaborative mode by default.

[0047] In step S202, the system operates in normal collaborative mode. In this mode, the physical restriction unit 121 is locked by default, and the operator cannot directly operate the robot. The global arbitration module 130 continuously performs multi-condition composite judgments.

[0048] In step S203, the global arbitration module 130 determines whether an abnormal event has occurred. An abnormal event is defined as a pre-defined, sudden situation that may harm the operation task or equipment. If an abnormal event is detected, the process jumps to step S206, and the system switches to the abnormal handling mode.

[0049] If no abnormal event is detected, the process continues to step S204, where the global arbitration module 130 determines whether the preset unlocking conditions are met. Only when the unlocking conditions are met is the operator authorized to perform physical operations. If the unlocking conditions are not met, the process returns to step S202, and the system continues to maintain the locked state and monitor cyclically. If the unlocking conditions are met, the process proceeds to step S205, where the global arbitration module 130 sends an unlocking command. During this step, the system follows a physical-first confirmation timing sequence: at time T1 when the physical restriction unit receives the unlocking command, it immediately generates perceptible physical force feedback characteristics (such as instantaneous unloading of operating damping or vibration prompts at a specific frequency); while at time T2, lagging behind time T1, the image processing host or display terminal completes the update of the software interface state (such as resetting visual icons or switching colors). This preset time difference ensures that the operator's tactile confirmation of the security boundary precedes logical confirmation, and provides the system with a detectable hardware-level security fingerprint. Subsequently, the operator officially gains operating privileges.

[0050] At any operating state of the system, the independent hardware monitoring unit 140 executes step S208 in parallel in the background, that is, monitors the working status of the core components of the system. If the hardware monitoring unit 140 detects a system failure, it will immediately trigger step S207, forcing the system to enter fail-safe mode.

[0051] In step S206, the system enters an emergency handling mode. The global arbitration module 130 will immediately send a high-priority lock command, forcibly activate the physical restriction unit 121, deprive the operator of control, and autonomously execute the preset emergency handling procedure.

[0052] In step S207, the system enters fail-safe mode. In this mode, the physical restraint unit 121 is triggered to enter an irrevocable in-situ self-locking state, ensuring that the robot stops all actions under any circumstances and maintains its current posture until human intervention.

[0053] The following will combine Figure 3 and Figure 4 The specific working logic of the normal collaborative mode and the abnormal handling mode is explained in detail.

[0054] Normal collaborative mode and logical release mechanism

[0055] See Figure 3 This diagram details the multi-condition composite judgment logic executed by the system for authorized operators in the normal collaborative mode, namely... Figure 2Internal details of step S204. The core idea of ​​this mechanism is that the operator is granted the authority to perform physical operations only when the timing, location, and personnel are all in harmony, thereby achieving alignment in the three dimensions of space, pathology, and time.

[0056] In this mode, the physical restriction unit 121 is locked by default. The global arbitration module 130 must confirm that the following three conditions are met simultaneously before sending an unlock command.

[0057] Step S301: Determine the compliance conditions of the macro space.

[0058] This condition ensures that the robot's end effector remains within a predefined safe operating area. Specifically, the macro-navigation module 110 calculates a three-dimensional safe volume in real time based on its internal dynamic environment model. The macro-navigation module 110 continuously updates the current spatial coordinates of the robot's end effector. Compare with this dynamic safety volume. If and only if The macroscopic spatial compliance condition is considered met only when the object is located within this volume. This determination is then sent to the global arbitration module 130 via the global data bus 150.

[0059] When determining macroscopic spatial compliance conditions, the system does not use static safety boundaries. The macroscopic navigation module acquires the current respiratory phase parameters in real time. and the opacity field extracted from the four-dimensional dynamic organ model. and normal gradient field The system uses these three parameters to calculate and generate a dynamic virtual red line that fluctuates in real time with the patient's breathing. Macroscopic spatial compliance is only determined when the real-time coordinates of the robot's end effector fall within the volume enclosed by this dynamic virtual red line. This design solves the positioning drift problem caused by organ fluctuations during respiration.

[0060] Step S302: Determine the compliance conditions of micro-features.

[0061] This condition is used to confirm at a microscopic level that the tissue observed by the robot's end effector is indeed the expected target tissue. The image sensor of the microscopic perception and manipulation module 120 continuously acquires high-frequency video streams. Before processing, the system can first calculate the Laplacian variance of the image. To filter out blurred frames caused by motion, an image recognition model deployed within the global arbitration module 130 then analyzes the clear image frames. In this embodiment, the image recognition model can be a convolutional neural network model, such as a Siamese network. This network is pre-trained to distinguish between target tissue features and non-target tissue features. During runtime, the network extracts feature vectors from the current field of view image and compares them with a pre-stored target tissue feature template to calculate a similarity score. In a preferred embodiment, the above calculation logic is implemented as follows: similarity is defined as feature matching confidence. Only when the cumulative average within a sliding time window... The micro-feature compliance condition is considered met only when the value exceeds a preset matching threshold.

[0062] When determining the compliance conditions of microscopic features, the microscopic perception and manipulation module needs to perform a pre-processing step of fuzzy frame filtering before inputting the image into the image recognition model. Specifically, the system calculates the Laplacian variance of the current microscopic image frame in real time. This is used to quantify the sharpness of the image. If If the image clarity is below a preset threshold, the frame is considered a blurry, unusable image caused by breathing or heartbeat fluctuations and is discarded directly; only when... Only when the value is greater than or equal to this threshold will the clear frame be input into the convolutional neural network to calculate the feature matching confidence. This step ensures the accuracy and reliability of subsequent pathology AI assessments.

[0063] Step S303: Determine the target's dynamic stability conditions.

[0064] This condition ensures that the operation occurs during the quiescent window when the target's physiological movement is at its most stable. The macro-navigation module 110 determines the target's dynamic stability by analyzing physiological signals. Specifically, it calculates the instantaneous rate of change of physiological signals related to the target tissue's movement. When this rate of change is below a preset stability threshold, it means that the target is at the peak or trough of its motion cycle, i.e., a relatively static phase. At this point, the target's dynamic stability condition is considered satisfied. This condition can also be determined by calculating the rate of change of the probe's pose relative to the target tissue. To achieve, when The condition is met when the motion threshold is below the preset threshold.

[0065] Synergistic relationship between macro-level spatial compliance, micro-level characteristic compliance, and target dynamic stability conditions

[0066] It should be noted that the macroscopic spatial compliance condition defined in step S301 and the target dynamic stability condition defined in step S303 are not independent parallel judgments, but rather constitute two mutually supporting dimensions of the "spatiotemporal dual constraint" mechanism of this invention. Specifically, the macroscopic spatial compliance condition, through real-time deformation reasoning of the dynamic three-dimensional safety volume, solves the spatial positioning problem of "where should the robot's end effector operate"—that is, ensuring that the operation occurs in the correct spatial location allowed by the anatomical structure. Meanwhile, the target dynamic stability condition, through real-time monitoring of the instantaneous rate of change of physiological signals, solves the timing problem of "when should the operation be performed"—that is, ensuring that the operation occurs during the time window when the target's physiological movement is most gradual. Together with the microscopic feature compliance condition in step S302 (solving the target confirmation problem of "what to operate on"), they constitute a complete three-dimensional safety verification system of "space-timing-target".

[0067] The combined effect of these three elements ensures that each authorized operation is aligned with the target in space, the timing in time, and the target point in the object, fundamentally eliminating the spatiotemporal mismatch problem caused by the dynamic displacement of the target—"accurate spatial positioning, but incorrect time window"—while also avoiding invalid operations due to target recognition errors. This multi-dimensional collaborative constraint is one of the key features that distinguishes this invention from existing technologies that only perform single spatial positioning, single dynamic compensation, or single image recognition.

[0068] In step S304, the global arbitration module 130 performs logical judgments on the above three conditions. The process will proceed to step S305 only if the results of steps S301, S302, and S303 are all yes. Otherwise, the process will return to the loop waiting state, and the physical restriction unit 121 will remain locked.

[0069] In step S305, the global arbitration module 130 sends an unlocking command to the microscopic perception and operation module 120 through the global data bus 150, the physical restriction unit 121 is released, and the operator gains physical control of the robot.

[0070] By employing this multi-condition composite physical release logic, this invention hard-binds macroscopic dynamic alignment with microscopic feature confidence at the underlying level, resolving the risk of misoperation caused by target dynamic drift and ensuring the accuracy and safety of operations.

[0071] AI-based exclusive control mechanism for abnormal handling modes

[0072] See Figure 4 This diagram details the workflow when the system detects an abnormal event and enters the exception handling mode. Figure 2The internal details of step S206. The core of this mechanism lies in creating a sterile execution environment for artificial intelligence decision-making and execution, free from human interference, through physical means.

[0073] In step S401, the global arbitration module 130 monitors data from multiple sensors in real time to instantly capture anomalies. Events that trigger an anomaly may include: a force sensor in the micro-sensing and manipulation module 120 detecting a force or torque exceeding an emergency threshold; or a vision sensor in the micro-sensing and manipulation module capturing image features representing an anomaly.

[0074] Once an anomaly is detected, the process immediately proceeds to step S402. The global arbitration module 130 immediately broadcasts a high-priority lock command via the global data bus 150. Upon receiving this command, the micro-sensing and operation module 120 ignores any current input from the operator and forcibly activates the physical restriction unit 121, physically locking the operating handle. Simultaneously, module 120 can also drive the vibration motor within the handle to provide the operator with clear tactile alarm feedback, informing them that the system has taken over control.

[0075] When the global arbitration module sends a high-priority lock command to forcibly activate the physical restriction unit (such as an electromagnetic lock), the system immediately enters the exclusive control window. The physical restriction unit locks the operating handle, not only to stop the current dangerous action, but also to physically block any unintended input commands from the surgeon due to instinct or panic. This creates a sterile execution environment free from human interference for the subsequent autonomous issuance and execution of emergency commands by the artificial intelligence, eliminating the risk of human-machine confrontation where the AI ​​attempts to stop the bleeding in an abnormal situation, while the doctor forcibly withdraws.

[0076] In step S403, the system enters an exclusive AI control window. During this window, only AI can generate and issue control commands. The global arbitration module 130 embeds a decision model, which generates a structured sequence of emergency response control commands based on the type and context information of the current abnormal event. In this embodiment, the decision model can be a deep neural network-based computing architecture. In a specific preferred embodiment, the model can be a language model based on process retrieval enhancement. This model can quickly retrieve the most matching plan from an emergency plan library and translate it into standardized instructions that the robot can understand. For example, an instruction to perform a compression action can be represented in a structured format, such as: `{"action": "compress", "target_pose": [x,y,z],"force": "2.0N"}`, which specifies the action type, target pose, and force constraints.

[0077] However, the instructions generated by artificial intelligence cannot be directly issued to the robot actuators. In step S404, the instruction sequence must first be reviewed by a kinematic safety verification module. This verification module is a crucial part of the system's safety architecture.

[0078] In the exception handling mode, the global arbitration module calls the language model to generate not natural language text, but JSON instructions with a pre-defined data structure. These JSON instructions include key-value pairs in at least three dimensions: action operator ("action", such as "compress"), target pose ("target_pose", such as Cartesian coordinates $[x,y,z]$), and physical execution constraint ("parameter", such as the applied force "force": "2.0N"). Through this forced format mapping, the decision output of the large language model is directly transformed into deterministic physical parameters that the underlying motor can resolve, fundamentally eliminating the risk of generative AI generating hallucinations during medical procedures.

[0079] In step S405, the kinematic safety verification module performs verification. Specifically, the verification process includes: the module internally maintains a digital twin model that is precisely synchronized with the actual operating robot and its working environment. Upon receiving the emergency response control command sequence to be verified, it first performs virtual execution in the digital twin model, simulating the motion trajectory, velocity, and acceleration of each joint and link of the digital twin model under the drive of the commands. During the simulation, the minimum distance between all components of the digital twin model and the predefined restricted areas in the working environment is calculated in real time. and the angular velocity of each joint and angular acceleration If and only if the following condition is always met throughout the entire simulation: And for all joints All meet as well as Only then does the kinematic safety verification module determine that the instruction sequence is safe and passes the verification.

[0080] When the kinematic safety verification module simulates and reviews structured instructions in the digital twin model, in addition to calculating the minimum distance between the end effector and the restricted area, it must also perform the following two core verifications: Self-collision verification: Calculate the minimum distance between the robot's link bounding boxes (such as axial alignment bounding boxes AABB) to prevent the robot from mechanically interfering and getting tangled during emergency rescue actions; Singularity verification: Calculate the determinant of the Jacobian matrix for each discrete point on the robot's planned trajectory in real time. If detected ( If the threshold value is a very small positive number, it indicates that the robot is about to enter a kinematically singular configuration (which may cause the joint velocity to approach infinity and go out of control). At this time, the firewall will reject the instruction and block its transmission.

[0081] If the verification passes, the process proceeds to step S406, where the safety emergency response control command sequence is formally issued to the robot's underlying controller for execution. If the verification fails, the system will trigger a higher-level alarm or enter a more conservative safety state.

[0082] Hardware bypass fallback mechanism for fail-safe modes

[0083] This mode is the ultimate security guarantee for the system, triggered by a hardware monitoring unit 140 independent of the main system. The hardware monitoring unit 140 determines the working status of core software systems such as the global arbitration module 130 by listening to heartbeat data packets on the global data bus 150.

[0084] The specific judgment logic can be designed as follows: the hardware monitoring unit 140 uses a preset frequency. Send a heartbeat request packet to the global arbitration module 130 and start a timer. If the preset timeout period is reached... No valid heartbeat response packet was received from the global arbitration module 130, or the received response packet contained internal system processing delay. Round-trip transmission delay recorded by the hardware monitoring unit 140 itself The sum exceeded a maximum allowed delay threshold. That is, the conditions are met. If so, the hardware monitoring unit 140 determines that the global arbitration module 130 has failed.

[0085] Once a failure is detected, the hardware monitoring unit 140 will immediately output a high-priority lock signal to the physical restriction unit 121 via a separate hard connection 160. This signal can be designed as a non-maskable interrupt signal, with a higher priority than any software instruction from the global data bus 150, thereby ensuring that in any extreme case of software crash, the robot can instantly enter an absolutely safe, self-locking state in place.

[0086] Example 2

[0087] Based on Embodiment 1, this embodiment provides further explanation and alternative solutions for the specific implementation of each module in the system.

[0088] In the macro navigation module 110, the self-attention mechanism for predicting respiratory rhythm can be specifically implemented as the encoder part of a transformer network. This network receives respiratory signal sampling points over a past period as an input sequence, and captures the long-term dependencies within the sequence through a multi-head self-attention layer, thereby accurately predicting the respiratory phase and the corresponding pose of the target in the near future.

[0089] In the microscopic sensing and manipulation module 120, the confidence level of feature matching is calculated. The Siamese network, specifically, can be structured as two convolutional neural network branches sharing weights. One branch receives a real-time acquired tissue image as input, while the other receives a pre-stored standard target tissue template image. The network outputs two high-dimensional feature vectors, and the cosine similarity between these two vectors is used to obtain... .

[0090] In the global arbitration module 130, the fast retrieval mechanism in the large language model generated based on process retrieval enhancement can be implemented using a vector database. Each emergency plan in the emergency plan library is pre-encoded into a feature vector and stored. When an anomaly occurs, the system also encodes the current context information into a query vector, and quickly finds the most relevant emergency plan by performing an approximate nearest neighbor search in the vector database.

[0091] In addition, this system includes some necessary supporting modules. For example, the system includes a power supply module that provides stable DC power to all electronic components; low-level motor drivers and motion controllers that execute robot motion commands; a central processing unit or embedded computing platform for processing and running algorithms of various modules; and data acquisition interface circuits between various sensors and the processor. These are all conventional technical means well known to those skilled in the art, and will not be described in detail here.

[0092] It should be noted that the specific implementation of the modules and functional units described in this invention is not unique. For example, the global data bus can be an industrial bus or other industrial buses that meet real-time requirements, such as PROFINET IRT or time-sensitive networks. The physical limiting unit can be an electromagnetic lock or servo brake, or a hydraulic or pneumatic brake. The image recognition model can be a convolutional neural network, a support vector machine, or other traditional machine learning models. The decision model can be based on a language model, an expert system, or a decision tree. Those skilled in the art can select or replace these specific implementations according to specific application scenarios and cost requirements, and these changes do not depart from the core ideas and protection scope of this invention.

[0093] The present invention also provides a computer-readable storage medium, such as a read-only memory, a random access memory, a solid-state drive, or an optical disk, wherein the computer program instructions stored thereon, when executed by a processor, can implement the robot control method described in the above embodiments.

[0094] The present invention also provides an operating robot that, in addition to a conventional robot body, integrates any of the operating robot control systems described in the above embodiments. By integrating this control system, the operating robot achieves improved operational accuracy, emergency response capability, and system safety.

[0095] In summary, this invention effectively addresses many pain points in existing technologies through its innovative system architecture, multimodal fusion control logic, and in-depth safety design combining hardware and software. It is not merely an improvement on a single technical point, but rather provides a complete and systematic solution, offering a new technological path for the development of high-precision, high-safety operating robots.

[0096] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A robot control system, characterized in that, include: The system includes a macro navigation module, a micro perception and operation module, and a global arbitration module. The micro perception and operation module has a built-in physical restriction unit for applying or removing restrictions on an operator's physical input. A global data bus is used to transmit data and control commands between the macro navigation module, the micro perception and operation module, and the global arbitration module; The global arbitration module is configured to maintain a global state machine and switch between the following modes based on the global state machine: In the normal collaborative mode, the physical restriction unit is locked by default. Only when a macroscopic spatial compliance condition, a microscopic feature compliance condition, and a target dynamic stability condition are met simultaneously will the global arbitration module send an unlock command to the physical restriction unit through the global data bus to authorize the operator to perform the operation. In the abnormal handling mode, when the global arbitration module determines that an abnormal event has occurred, it sends a high-priority locking command via the global data bus to forcibly activate the physical restriction unit, deprive the operator of the operating authority, and autonomously generates and issues control commands to execute the preset emergency handling process. In fail-safe mode, when a system communication timeout or core algorithm failure is detected, the physical limiting unit is triggered to enter an irrevocable in-situ self-locking state.

2. The robot control system according to claim 1, characterized in that: The physical restriction unit is configured to immediately trigger a perceptible physical force feedback action upon receiving an unlock command, and the triggering time of the physical force feedback action is configured to be earlier than the time of system software interface state update, so as to construct an operator-perceptible security confirmation fingerprint through hardware-level timing difference.

3. The robot control system according to claim 2, characterized in that: There is a preset time difference ΔT between the triggering time T1 of the physical force feedback action and the software interface state update time T2, and ΔT>10ms.

4. The system according to claim 1, characterized in that, The physical restraint unit is an electromagnetic lock or a servo brake.

5. The system according to claim 1, characterized in that, The satisfaction of the macroscopic spatial compliance condition is defined as the current spatial coordinates of the robot end effector, as determined by the macroscopic navigation module, being within a preset three-dimensional safety volume. The dynamic three-dimensional safety volume is determined by the macroscopic navigation module based on a preset four-dimensional dynamic organ model and according to the time parameters of real-time physiological signals. Real-time deformation reasoning is performed to obtain real-time spatial compensation for the physiological movement of the target tissue.

6. The system according to claim 1, characterized in that, The satisfaction of the micro-feature compliance condition is defined as the similarity between the target tissue image data collected by the image sensor in the micro-perception and operation module and a pre-stored target tissue feature template being higher than a preset matching threshold.

7. The system according to claim 6, characterized in that, The similarity calculation is performed by an image recognition model deployed within the global arbitration module.

8. The system according to claim 7, characterized in that, The image recognition model is a convolutional neural network model.

9. The system according to claim 1, characterized in that, The dynamic stability condition of the target is defined as the instantaneous rate of change of the physiological signal related to the movement of the target tissue, as monitored by a physiological signal sensor, being lower than a preset stability threshold.

10. The system according to claim 9, characterized in that, The physiological signal is a respiratory signal, and the satisfaction of the target dynamic stability condition corresponds to the respiratory signal being in the stable phase at the end of expiration.

11. The system according to claim 1, characterized in that, In the abnormal handling mode, the abnormal event is determined based on the data of one or more non-image sensors in the microscopic sensing and operation module. When the data of the non-image sensors exceeds a preset emergency threshold, the abnormal handling mode is triggered.

12. The system according to claim 11, characterized in that, In the abnormal handling mode, the global arbitration module includes a decision model with logical reasoning capabilities. The decision model is used to retrieve and generate a structured emergency handling control instruction sequence containing physical constraint parameters from an emergency plan library based on the characteristic type of the abnormal event.

13. The system according to claim 12, characterized in that, The decision model is a computational architecture based on deep neural networks; in a preferred embodiment, the decision model is a large language model based on process retrieval augmented generation (P-RAG).

14. The system according to claim 12, characterized in that, It also includes a kinematic safety verification module, which is configured to perform kinematic verification on the emergency response control command sequence before it is sent to the robot actuator. The command sequence is only allowed to be sent if the verification result shows that executing the command sequence will not cause the robot to exceed the safe movement boundary.

15. The system according to claim 1, characterized in that, It also includes a hardware monitoring unit independent of the global arbitration module, which is directly hard-connected to the physical restriction unit. The hardware monitoring unit is configured to determine the working status of the global arbitration module by listening to heartbeat data packets on the global data bus, and when it determines that the global arbitration module has failed, it directly sends a high-priority locking signal to the physical restriction unit through the hard connection to force the system to enter the fail-safe mode.

16. The system according to claim 15, characterized in that, The hardware monitoring unit is a microcontroller unit.

17. The system according to claim 15, characterized in that, The logic by which the hardware monitoring unit determines the failure of the global arbitration module includes: the hardware monitoring unit uses a preset frequency... Send a heartbeat request packet to the global arbitration module and start a timer; if within the preset timeout period... If no valid heartbeat response packet is received from the global arbitration module, or if the received response packet contains internal system processing delays... Round-trip transmission delay recorded by the hardware monitoring unit itself The sum exceeded a maximum allowed delay threshold. That is, the conditions are met. If the hardware monitoring unit determines that the global arbitration module has failed, it immediately outputs a high-level lock signal to the physical restriction unit via an independent hard connection. This signal has a higher priority than any instruction from the global data bus.

18. The system according to claim 14, characterized in that, The verification process of the kinematic safety verification module includes: maintaining a digital twin model synchronized with the actual operating robot and its working environment; upon receiving the emergency response control command sequence to be verified, firstly performing virtual execution in the digital twin model, simulating the motion trajectory, velocity, and acceleration of each joint and link of the digital twin model under the drive of the command sequence; during the simulation, calculating in real time the minimum distance between all components of the digital twin model and the predefined restricted area in the working environment. and the angular velocity of each joint and angular acceleration If and only if the following condition is met throughout the entire simulation process: And for all joints All meet as well as Only then does the kinematic safety verification module determine that the instruction sequence is safe and passes the verification.

19. A method for controlling an operating robot, characterized in that, Includes the following steps: Data and control commands are transmitted between the macro navigation module, the micro perception and operation module, and the global arbitration module through a global data bus. The micro perception and operation module has a built-in physical constraint unit. The global arbitration module maintains a global state machine and performs the following switching control based on the global state machine: When in normal collaborative mode, the physical restriction unit is kept in a locked state by default, and it continuously determines whether a macroscopic spatial compliance condition, a microscopic feature compliance condition, and a target dynamic stability condition are simultaneously satisfied. When all three are satisfied, an unlocking command is sent to the physical restriction unit. When an abnormal event is detected, the system switches to the abnormal handling mode. In this mode, a high-priority locking command is sent to forcibly activate the physical restriction unit, and control commands are automatically generated and issued to execute the preset emergency handling procedures. When a system communication timeout or core algorithm failure is detected, the system switches to fail-safe mode. In this mode, the physical limiting unit is triggered to enter an irrevocable in-situ self-locking state.

20. The method according to claim 19, characterized in that, The steps for determining the macroscopic spatial compliance conditions include: determining the current spatial coordinates of the robot end effector, and determining whether the current spatial coordinates are within a preset three-dimensional safety volume.

21. The method according to claim 19, characterized in that, The steps for determining the compliance conditions of microscopic features include: collecting image data of the target tissue and calculating the similarity between the image data and a pre-stored target tissue feature template; when the similarity is higher than a preset matching threshold, it is determined that the condition is met.

22. The method according to claim 19, characterized in that, The steps for determining the dynamic stability condition of the target include: monitoring physiological signals related to the movement of the target tissue and calculating the instantaneous rate of change of the physiological signals. When the instantaneous rate of change is lower than a preset stability threshold, it is determined that the condition is met.

23. The method according to claim 19, characterized in that, The step of switching to the abnormal handling mode further includes: according to the type of the abnormal event, invoking a decision model to retrieve and generate a structured sequence of emergency handling control instructions from an emergency plan library.

24. The method according to claim 23, characterized in that, Before issuing the aforementioned emergency response control command sequence, the following is also included: The instruction sequence is verified through a kinematic safety verification logic to determine whether its execution would cause the robot to exceed the safe movement boundary. The instruction sequence is only issued if the verification passes.

25. The method according to claim 19, characterized in that, The step of switching to fail-safe mode is triggered by a separate hardware monitoring unit, and the method further includes: The hardware monitoring unit listens to heartbeat data packets on the global data bus; When the hardware monitoring unit determines that the global arbitration module has failed, it sends the highest priority lock signal directly to the physical restriction unit via a hard connection.

26. A computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the method as claimed in any one of claims 19 to 25.

27. An operating robot, characterized in that, It includes the robot body and the robot control system as described in any one of claims 1 to 18.

28. The system according to claim 14, characterized in that, The global arbitration module monitors the operating status heartbeat signals of the macro navigation module and the micro perception module in real time through the global data bus. When the heartbeat signal of any module is lost or delayed beyond a preset threshold, the global state machine is forcibly switched to failure mode, triggering the physical restriction unit to perform irrevocable hardware self-locking, and the kinematic safety verification module locks the safety envelope based on the most recently valid four-dimensional dynamic model parameters.

29. The system according to claim 14, characterized in that, The digital twin model maintained by the kinematic safety verification module shares the same spatiotemporal reference with the four-dimensional dynamic organ model in the macro-navigation module, and is updated by real-time physiological parameters provided by the macro-navigation module.