A security and trust control method and system for embodied intelligent system
Patent Information
- Application Number
- CN202611003737.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-07
- Publication Date
- 2026-09-25
AI Technical Summary
[0005]针对现有技术难以同时解决具身智能系统中的来源可信验证、语义规则转换、双证书联合校验、非停机安全修正及全流程追溯等问题,本发明提供一种面向具身智能系统的安全可信控制方法及系统
[0030]1)本发明通过对输入信息建立可信来源链并计算来源可信度,结合迟滞回线机制控制可信事实进入或退出控制闭环,能够过滤不可信的感知数据与指令输入,降低了因感知错误导致的执行风险。
Smart Images

Figure CN122818341A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of embodied intelligence security technology, specifically relating to a secure and reliable control method and system for embodied intelligence systems. Background Technology
[0002] Embodied intelligent systems typically consist of a multimodal perception model, a task planning model, an action generation model, and an underlying controller. They can autonomously execute actions based on natural language tasks and environmental conditions in scenarios such as home services, industrial manufacturing, warehousing and logistics, inspection and maintenance, medical rehabilitation, and public services. With the introduction of large language models, visual language models, and basic robot models into the embodied control chain, the system possesses enhanced task understanding, generalization planning, and human-computer interaction capabilities, but this also introduces new security and reliability issues.
[0003] Existing embodied intelligent safety technologies typically fall into the following categories: First, methods for obstacle avoidance, speed limiting, force limiting, emergency stopping, or control barrier functions for robot motion control. These methods can constrain some dangerous states in the continuous control space, but they usually do not understand the semantic risks of natural language tasks and have difficulty identifying whether perceived facts come from credible sources. Second, pre-execution review or formal verification methods for large-scale model task planning. These methods can identify some steps that do not meet the temporal logic or task constraints at the planning level, but they often remain at the high-level planning check and have difficulty directly constraining actuator-level speed, torque, contact force, and safety distance. Third, risk identification methods for inspection, operational safety, or human-robot collaboration scenarios. These methods mostly rely on preset rules or specific scenario data and have difficulty adapting to mixed inputs from screen text, voice, QR codes, map updates, remote interfaces, and third-party models in open environments. Fourth, methods for model security such as prompt injection, unauthorized instructions, and adversarial example detection. These methods mainly deal with information security or model input security and have not yet formed a complete closed loop with robot runtime control security.
[0004] In practical deployments, the risks faced by embodied intelligence systems are often not caused by a single source. For example, posters or screens in the environment may be misinterpreted by the model as operational instructions; remote interfaces may issue unauthorized tasks; visual models may identify dangerous areas as passable areas; large models may generate semantically reasonable but physically unsafe actions; and while the underlying controller may meet local obstacle avoidance requirements, it may execute tasks that conflict with the original human intent. Therefore, relying solely on plan review, obstacle avoidance control, or cue word filtering is insufficient to address the consistency issue between credible task intent and safe physical actions. Summary of the Invention
[0005] To address the limitations of existing technologies in simultaneously solving problems such as source trust verification, semantic rule conversion, dual certificate joint verification, non-downtime security correction, and full-process traceability in embodied intelligence systems, this invention provides a secure and trustworthy control method and system for embodied intelligence systems.
[0006] This invention provides the following technical solution: a secure and reliable control method for embodied intelligent systems, comprising the following steps:
[0007] Step (1): Obtain the input information, operating status information, and security policies of the embodied intelligence system;
[0008] Step (2): Model the trusted sources of the input information, establish a trusted source chain, and calculate the source credibility;
[0009] Step (3): Generate a first set of security constraints based on the security policy to constrain task intent, object permissions, action timing, or spatial scope;
[0010] Step (4): Generate a second set of safety constraints based on the robot's capability boundaries and environmental conditions to constrain trajectory, velocity, force, kinetic energy, distance, or reachable area;
[0011] Step (5): Obtain candidate task plans and map them to action primitive sequences. Perform consistency verification on the action primitive sequences using the first set of security constraints and the second set of security constraints.
[0012] Step (6): If the verification fails, execute the action safety projection, degrade execution, replanning, or circuit breaker shutdown strategy;
[0013] Step (7): Record the process of steps (2) to (6) to form an audit log.
[0014] Furthermore, in step (2), after modeling the trusted source of the input information, cross-modal consistency verification is performed on multiple source records of the same object or the same spatial region, and the consistency result is written into the source record; when calculating the source credibility, a comprehensive score is given by combining the source authentication status, cross-modal consistency, spatiotemporal consistency, historical reliability and abnormal deviation, and the credibility is normalized to a preset numerical range.
[0015] Furthermore, in step (2), after obtaining the source credibility, a hysteresis loop mechanism is used to control the entry or exit of credible facts into or out of the control loop. A higher entry threshold is used for the first entry into the control loop, and a lower exit threshold is used for facts that have been admitted to the control loop to exit.
[0016] Furthermore, in step (3), after generating the first set of security constraints, the natural language rules are converted into structured constraints, and a consistency check is performed on the structured constraints. When there are rule conflicts, the priority is determined in the order of manual emergency stop, security enforcement rules, user permission rules, and scenario rules.
[0017] Furthermore, in step (4), after generating the second set of security constraints, the environmental risk boundary is dynamically adjusted according to the source credibility, wherein the lower the source credibility, the larger the risk expansion radius; when the credibility of the preset high-risk object is lower than the preset security threshold, the area where the high-risk object is located is directly marked as a prohibited area.
[0018] Furthermore, in step (5), when performing consistency verification on the action primitive sequence, it is first determined whether the credibility of the perceived fact on which the action depends meets the threshold, then it is determined whether the action meets the first set of safety constraints, and finally it is determined whether the predicted trajectory corresponding to the action is located within the second set of safety constraints.
[0019] Furthermore, in step (6), when performing the action safety projection, it is first determined whether there is a solution that simultaneously satisfies the first safety constraint set and the second safety constraint set; when there is a solution that satisfies the constraints, the safety control quantity that is the smallest distance from the original candidate control quantity is solved; when there is no mathematically feasible solution, the projection action is refused and the circuit breaker is triggered to stop.
[0020] Furthermore, in step (6), after the action safety projection is performed, the distance to the person, contact force, speed, sensor conflict and the number of model violations are monitored in real time. When the risk value exceeds the circuit breaker threshold during operation, the circuit breaker is triggered to stop the machine and enter the preset safety posture.
[0021] Furthermore, in step (7), when forming the audit log, a chain hash method is used to connect adjacent audit records, so that if any audit record is tampered with, subsequent hashes will be inconsistent.
[0022] A secure and reliable control system for embodied intelligent systems, used to implement the method according to any one of claims 1 to 9; comprising:
[0023] The Trusted Source Chain Building Module is used to establish a trusted source chain and calculate the source trustworthiness.
[0024] The first security constraint generation module is used to generate the first security constraint set;
[0025] The second security constraint generation module is used to generate the second security constraint set;
[0026] The consistency verification module is used to verify the consistency of the action primitive sequence with the first set of security constraints and the second set of security constraints.
[0027] The safety handling module is used to perform action safety projection, degrade execution, replanning, or circuit breaker shutdown;
[0028] The audit log module is used to record the process of steps (2) to (6).
[0029] By employing the above-described technology, the beneficial effects of the present invention compared to the prior art are as follows:
[0030] 1) This invention establishes a trusted source chain for input information and calculates the source credibility. Combined with a hysteresis loop mechanism, it controls trusted facts to enter or exit the control loop, thereby filtering untrusted perceived data and instruction inputs and reducing the execution risk caused by perception errors.
[0031] 2) This invention generates a first set of security constraints and a second set of security constraints to constrain task intent, object permissions, action sequence, trajectory, speed, force, kinetic energy, distance, and reachable area, respectively. This transforms natural language security policies into structured and verifiable control constraints, solving the problem of the disconnect between semantic layer and physical layer security rules.
[0032] 3) This invention maps candidate task plans to action primitive sequences and performs consistency verification on the sequences based on the first set of security constraints and the second set of security constraints. It can simultaneously verify semantic legality and physical feasibility before the action is executed. When a candidate action does not satisfy the first set of security constraints or the second set of security constraints, the action is rejected from entering the execution queue.
[0033] 4) In this invention, when the consistency verification fails, the optimal security control quantity that satisfies the dual certificate constraints is solved by action security projection. When projection is not possible, degraded execution, replanning, or circuit breaker shutdown is triggered. When the candidate action does not meet the security constraints, the security control quantity that satisfies the first security constraint set and the second security constraint set is executed first. The action execution is terminated only when there is no feasible solution or the circuit breaker threshold is triggered. Attached Figure Description
[0034] Figure 1 This is a schematic diagram of the architecture of the method of the present invention. Detailed Implementation
[0035] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.
[0036] Conversely, this invention encompasses any substitutions, modifications, equivalent methods, and solutions made within the spirit and scope of the invention as defined in the claims. Furthermore, to provide a better understanding of the invention, certain specific details are described in detail below. However, those skilled in the art will fully understand the invention even without these detailed descriptions.
[0037] This embodiment provides a secure and reliable control method and system for embodied intelligent systems. (Refer to...) Figure 1 In this invention, the method first establishes a trusted source chain for task input and multimodal perception facts to determine which information can enter the control loop; secondly, it compiles natural language security requirements, scene rules, and permission policies into semantic security certificates (i.e., the first set of security constraints); thirdly, it generates physical security certificates (i.e., the second set of security constraints) based on the robot's capabilities and environmental risk boundaries; and finally, it performs dual certificate verification on the candidate plans, action primitives, and continuous control quantities output by the large model or embodied basic model, and performs safety projection, degradation, replanning, or circuit breaker shutdown when necessary. The specific implementation steps are as follows.
[0038] In step (1), the construction of the trusted source chain addresses the questions in embodied intelligence systems: where do the task or perceived facts originate, are they trustworthy, and can they participate in control? The inputs to this step include natural language tasks, multimodal perception data, remote interface data, map update data, tool call results, external model outputs, and robot body states; the output is a set of facts with source trustworthiness. and records from the source The traceable source chain constitutes .
[0039] (1-1) Unified Source Modeling. The system categorizes the inputs received by the embodied intelligent system into source types such as operator voice, operator text, environmental text, visual targets, map updates, sensor observations, remote interfaces, tool call results, external model outputs, and ontology feedback. For each input event, the system generates a source record:
[0040] (1)
[0041] in, This represents the source record of the i-th input event; This represents the input content or the observed facts that have been extracted. Indicates the source identity, such as user account, sensor number, interface identifier, or model service identifier; Indicates the source type; Indicates the collection timestamp; Indicates the spatial pose, observation area, or map coordinates at the time of data acquisition; Indicates the source authentication status; This indicates evidence of consistency with other modalities or other sources; This represents the evidence hash calculated from the original input, source identity, and timestamp. Through Equation (1), the system unifies the originally scattered voice, image, text, map, and interface inputs into a comparable, scoreable, and traceable source record.
[0042] (1-2) Cross-modal consistency verification. The system aggregates records from multiple sources for the same object, the same spatial region, or the same task constraint. For example, if the visual model recognizes a kettle, the temperature sensor detects high temperature, and the user's voice says "Don't touch the kettle," the system associates these three types of evidence as the same risk fact. Another example is if the screen displays "Sprint forward," but the authorized user's voice does not issue the same instruction; in this case, the system marks the environmental text as a low-confidence control instruction. The cross-modal consistency result is written into equation (1). .
[0043] (1-3) Source credibility calculation. The system calculates source credibility based on source authentication status, cross-modal consistency, spatiotemporal consistency, historical reliability, and abnormal deviation:
[0044] (2)
[0045] in, This indicates the credibility of the i-th input event; Indicates the source authentication score; Indicates the cross-modal consistency score; Indicates the spatiotemporal consistency score; This indicates the historical reliability score of the source; Indicates the degree of abnormal deviation; to As weight; This represents a normalization function whose output is strictly limited to the interval [0,1]. Preferably, it is a Sigmoid function or a piecewise truncated normalization function. Weights to The weights can be determined using expert scoring, offline calibration of historical accident samples, offline reinforcement learning reverse optimization, or a combination of these methods. After robot deployment, the system can also update the weights infrequently based on manual takeover records, false rejection records, and safety event records. However, weight updates must not be changed within a single control cycle to avoid control jitter. (Abnormal deviation) The system can calculate the anomaly score using Mahalanobis distance based on historical statistical mean and covariance matrix, deviation based on standard deviation, or anomaly score based on spatiotemporal trajectory residuals. If the input comes from environmental text, screen, QR code, or an unauthenticated remote interface, the system will lower its initial authentication score. If the input cannot be cross-validated by authorized users, sensors, or map facts, its credibility must not exceed the preset weak credibility limit.
[0046] To avoid credibility At the threshold Slight fluctuations in the vicinity cause the robot to frequently enter and exit the control loop; therefore, the system is equipped with a hysteresis loop mechanism. Specifically, a higher entry threshold is used when the observed fact first enters the control loop. A lower exit threshold is used when the fact that something has already entered the control loop is removed. And satisfy ;when lie in During the interval, the system maintains the admission state of the previous control cycle and records this fact in the audit log as a hysteresis hold state. The output of step (1) is:
[0047] (3)
[0048] in, This represents the set of trusted facts that are allowed to participate in subsequent security certificate generation and action verification during the t-th control cycle; Indicates input event Whether the control loop was allowed to be entered in the previous control cycle is indicated by a value of 1, which means that it has been entered and a value of 0 means that it has not been entered. Indicates the first entry into the threshold; Indicates the exit threshold. Source chain. This refers to a sequence of source records linked by timestamps, source identity, and evidence hashes, which includes at least... And the hash reference relationships between adjacent records, used to trace credible facts. The original source of any element in the dataset. For The system only allows the input to enter the audit log as a prompt message, and does not allow it to trigger robot actions on its own.
[0049] In step (2), the generation of semantic security certificates addresses the problem of how natural language security rules can be transformed into machine-verifiable constraints. The input to this step includes a set of trusted facts. User tasks Scene rule library Robot Operating Procedures Access control policies Safety rules for human-machine collaboration The output is a semantic security certificate. .
[0050] (2-1) Safety Rule Collection. The system extracts safety requirements from task descriptions, scenario configurations, robot operating procedures, human-robot collaboration rules, industry safety requirements, and user authorization policies. For example, in a home service scenario, the system can extract rules such as: knives must not be handed to children without authorization, heated containers must not be moved, and users must not enter private areas marked by them; in an industrial scenario, the system can extract rules such as: personnel must reduce speed when entering the collaboration area, the robotic arm must not cross the virtual boundary of the safety fence, and high-speed operation must not be automatically resumed in maintenance mode.
[0051] (2-2) Rule Structuring. The system converts natural language rules into structured constraints. Each constraint includes at least the executing subject, the object of operation, the action type, preconditions, temporal conditions, spatial conditions, permission conditions, source credibility conditions, and the handling strategy after violation. Semantic security certificates are represented as follows:
[0052] (4)
[0053] in, This refers to a semantic security certificate; This represents the k-th semantic safety constraint; Indicates the implementing entity; Indicates the object being operated on; Indicates the type of action; Indicates the preconditions for an action; Indicates the timing conditions of the action; Indicates spatial constraints; Indicates the authorization conditions; This indicates the minimum credibility requirement of the facts upon which an action depends; Indicates the rejection, downgrade, confirmation, rescheduling, or circuit breaker strategy used when the rule is violated; indicates the number of semantic security constraints.
[0054] (2-3) Semantic Certificate Verification. The system performs a consistency check on the structured results of the rules, including whether there are contradictory allowed and prohibited actions for the same object, whether there are conflicting permissions in the same spatial area, and whether the same task lacks necessary preconditions. If the rule conflict can be resolved by priority, the system determines the priority in the following order: manual emergency stop, security enforcement rules, user permission rules, scenario rules, and task preference rules; if the rule conflict cannot be resolved, the system requests manual confirmation and suspends the relevant actions.
[0055] (2-4) Semantic verification at the planning layer. This involves verifying the task plan output by the large model or the embodied foundation model. The system will divide each sub-target The algorithm parses the target object, action type, target area, dependent facts, and expected result, and determines whether it satisfies the semantic security certificate in equation (4). If the plan has issues such as untrusted source, insufficient object permissions, missing preconditions, spatial boundary violations, temporal conflicts, or conflicts with the original human intent, the system rejects the sub-target and returns interpretable constraints, requiring the planning model to regenerate the candidate plan.
[0056] In step (3), the generation of the physical safety certificate addresses whether the candidate action is physically safe within the robot body and the current environment. The inputs to this step include the robot's capability boundaries. Current robot status Trustworthy environment fact set Scene Map and security threshold configuration Output is a physical security certificate. .
[0057] (3-1) Robot Capability Boundary Modeling. The system acquires the robot's kinematic parameters, dynamic parameters, joint limits, velocity limits, torque limits, end-effector load, braking time, sensor delay, control cycle, and safety mode to form the robot's capability boundary:
[0058] (5)
[0059] Where K represents the kinematic parameter; D represents the dynamic parameter; Indicates joint position restrictions; Indicates speed limit; Indicates torque limitation; Load indicates end load; Indicates braking time or braking distance parameters; Indicates sensor delay; This indicates the control cycle. The capability boundary is used to determine whether a candidate action exceeds the robot's safe execution range.
[0060] (3-2) Environmental risk boundary modeling. The system is based on a set of credible facts. and scene map Generate local scene graph The local scene graph includes nodes such as people, obstacles, hazards, maneuverable objects, safe areas, restricted areas, and robot components, as well as edges such as relative distance, reachability, occlusion relationships, contact risks, and area affiliation. For low-confidence or conflict observations, the system expands the risk boundary in reverse order of confidence:
[0061] (6)
[0062] in, Indicates the risk expansion radius of the object; Indicates the basic safety margin; This represents the credibility compensation coefficient; This indicates the credibility of the source record corresponding to the object. Due to the... (2) By strictly limiting the credibility within a certain range, the linear expansion result of equation (6) will not exceed the limit due to negative credibility. For core objects involving personal safety or major property safety, such as personnel, children, fragile hazardous materials, heat sources, knives, and electrical equipment, if their credibility is lower than the core safety threshold, The system no longer relies solely on the linear expansion result of equation (6), but instead directly marks the region where the object is located as a restricted area. Alternatively, an equivalent infinite risk boundary can be adopted, and the highest level of physical defense strategy can be implemented, including halting approach, reducing speed, requesting manual confirmation, or triggering a circuit breaker. Through these mechanisms, the system avoids using unreliable or conflicting perceived facts as a basis for reducing the safe distance.
[0063] (3-3) Physical certificate calculation. The system calculates the physical certificate based on the current state. Robot capability boundaries Partial scene diagram and environmental risk boundary Construct a physical security certificate:
[0064] (7)
[0065] in, Indicates a physical security certificate; Represents the robot's state space; H represents any state in the state space; H represents the human body, a sensitive object, or a set of objects that need to be protected. This represents the minimum distance between the robot and the set in a given state; Indicates the predicted contact force; Indicates the speed of motion; Indicates kinetic energy or collision energy; This indicates a restricted area or an inaccessible or dangerous area; , and These represent the minimum safe distance, maximum permissible contact force, maximum permissible speed, and maximum permissible kinetic energy, respectively. The thresholds can be dynamically adjusted based on robot type, operating mode, scene level, personnel distance, and source credibility.
[0066] In step (4), the semantic-physical dual-certificate consistency verification is used to address whether the candidate plan, action primitives, and control variables simultaneously satisfy semantic and physical security. The input to this step includes the candidate task plan. Semantic security certificate Physical security certificate Confidential fact set and the current robot state The output is the action admission result, rejection reason, or set of actions to be projected.
[0067] (4-1) Action primitive mapping. The system converts candidate plans into sequences of action primitives:
[0068] (8)
[0069] Where A represents the sequence of action primitives; This represents the j-th action primitive; Indicates the number of action primitives; Indicates the action category; Indicates the object being operated on; Indicates the target pose or target region; Indicates the speed range; Indicates the range of force or torque; Indicates the position control, speed control, force control, or hybrid control mode; Indicates the expected duration; This represents the set of perceived facts, map facts, or authorized facts upon which the action depends.
[0070] (4-2) Dual-certificate gating. For each candidate action... The system sequentially checks three conditions: First, whether the credibility of the facts upon which the action depends meets the credibility requirements of the semantic security certificate; second, whether the action subject, object, action type, spatial scope, and permissions satisfy the semantic security certificate; and third, whether the predicted trajectory and control variables corresponding to the action are within the security set defined by the physical security certificate. The verification result is expressed as follows:
[0071] (9)
[0072] in, Indicates action The admission results; This indicates an indicator function that takes the value 1 if the condition is true and 0 otherwise. Indicates the credibility threshold; Indicates action Satisfy semantic security certificate, among which The symbolic logic representing candidate actions satisfies the formal relation of semantic security certificate constraints; Indicates starting from the current state Execute action The state trajectory is predicted in time; This indicates that the predicted trajectory remains entirely within the safe set permitted by the physical security certificate. Only when... When, the action enters the execution queue; when When the system fails, it proceeds to step (5) based on the reason for the failure.
[0073] In step (5), action safety projection, semantic degradation, and runtime circuit breaking are used to address how to handle unsafe candidate actions. The inputs to this step include the candidate action that failed verification, the reason for failure, the current robot state, the semantic safety certificate, and the physical safety certificate; the outputs are the projected safe action, the replanning request, the manual confirmation request, or the circuit breaking shutdown command.
[0074] (5-1) Action-Safe Projection. When a candidate action satisfies the semantic safety certificate but not some physical constraints, and there are safety-alternative control variables, the system solves the following projection problem:
[0075] (10)
[0076] in, Represents the original candidate control quantity; This represents the safety control quantity after projection. Indicates the control input space; This represents a weight matrix used to measure the degree of deviation from different control dimensions; Represents the system state transition model; This indicates that the next state after adopting the control variable satisfies the physical safety certificate; This indicates that the projected action remains semantically safe. The system first checks for constraints before solving equation (10). and The system determines whether the set of feasible solutions is empty. When the set of feasible solutions is not empty, the system reduces speed, adjusts path, changes grasping posture, increases safety distance, or reduces contact force by using equation (10) while maintaining the task intent. When equation (10) is mathematically infeasible, the system protection mechanism refuses to execute the projection action and immediately sends a projection failure signal to step (5-4), forcibly triggering downgrade execution, manual confirmation, or circuit breaker shutdown. For cases where only soft constraints are violated without touching hard safety constraints such as personnel distance, contact force, or restricted areas, the system can introduce relaxation variables to perform a restricted soft projection. If the candidate action after relaxation still violates any hard safety constraint, or the relaxation amount exceeds the preset upper limit, the system must not continue to execute the action and must enter the circuit breaker or manual takeover process.
[0077] (5-2) Semantic Degradation and Replanning. When a candidate action violates the semantic security certificate but a low-risk alternative target still exists, the system returns structured rejection reasons and available constraints to the planning model. For example, rejection reasons may include: the target object is not authorized; the action requires adult confirmation; the current source is environmental text and cannot be used as an execution command; the area is a restricted area. The planning model regenerates constraints that satisfy the rejection reasons. The system will generate candidate plans. If a safe plan cannot be obtained after more than the preset limit of replanning attempts, the system will request manual confirmation or trigger a circuit breaker.
[0078] (5-3) Runtime Risk Monitoring. During action execution, the system continuously monitors personnel distance, contact force, speed, kinetic energy, sensor conflicts, changes in source credibility, and the number of consecutive model violations at control cycles. Runtime risk values are expressed as:
[0079] (11)
[0080] in, This represents the runtime risk value at time t; This indicates the real-time distance between the human and the robot. Indicates real-time or predicted contact force; Indicates real-time speed; Indicates the degree of conflict between the sensor or source facts; This indicates the number or intensity of consecutive violations generated by the model; , , , and These represent the risk normalization function; to This represents the risk weight.
[0081] (5-4) Circuit Breaker Shutdown. The system will trigger a circuit breaker when any of the following conditions occur: the source credibility continuously falls below the threshold; critical sensor observation conflicts cannot be resolved; there is no projection action that satisfies both certificates; personnel distance, contact force, speed, or kinetic energy exceeds the mandatory safety threshold; the model continuously generates actions that violate the certificate; or the runtime risk value... If the circuit breaker threshold is exceeded, or if the emergency stop is manually activated, the system will enter a preset safe position after the circuit breaker trips. This will stop the dangerous actuators, maintain the necessary braking and support controls, and generate a circuit breaker report.
[0082] In step (6), the audit logs and evidence playback are used to address whether the basis for security judgments is traceable and whether the incident process is replayable. The inputs to this step include task input, source records, credibility calculation results, semantic security certificates, physical security certificates, candidate actions, verification results, projection actions, circuit breaker reasons, and manual confirmation processes; the outputs are audit logs and evidence playback records.
[0083] (6-1) Audit Log Generation. The system generates audit logs for each round of security controls. Audit logs should include at least the task number, timestamp, source record number, credibility score, semantic rule hits, physical constraint hits, candidate actions, admission results, projection results, rejection reasons, circuit breaker reasons, and manual takeover status.
[0084] (6-2) Chained hash storage. Adjacent audit records are linked by a hash chain:
[0085] (12)
[0086] in, Represents the chained hash value of the k-th log entry; This represents the hash value of the previous log entry; This indicates the first security control record; Represents a trusted timestamp; the symbol || indicates concatenation of strings or binary fields; Let represent the hash function. According to equation (12), any tampering with an audit record will lead to inconsistent hashes in subsequent audits.
[0087] (6-3) Evidence Replay. During incident debriefing or security audits, the system reads the audit logs in chronological order, restoring task inputs, source credibility, semantic certificates, physical certificates, candidate actions, verification failure reasons, projected actions, and circuit breaker decisions, thereby explaining why the system accepted, modified, rejected, or suspended a certain action. Through this mechanism, the present invention can improve the security interpretability, accountability tracking capability, and engineering deployment credibility of embodied intelligent systems in open environments.
[0088] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A secure and reliable control method for embodied intelligent systems, characterized in that, Includes the following steps: Step (1): Obtain the input information, operating status information, and security policies of the embodied intelligence system; Step (2): Model the trusted sources of the input information, establish a trusted source chain, and calculate the source credibility; Step (3): Generate a first set of security constraints based on the security policy to constrain task intent, object permissions, action timing, or spatial scope; Step (4): Generate a second set of safety constraints based on the robot's capability boundaries and environmental conditions to constrain trajectory, velocity, force, kinetic energy, distance, or reachable area; Step (5): Obtain candidate task plans and map them to action primitive sequences. Perform consistency verification on the action primitive sequences using the first set of security constraints and the second set of security constraints. Step (6): If the verification fails, execute the action safety projection, degrade execution, replanning, or circuit breaker shutdown strategy; Step (7): Record the process of steps (2) to (6) to form an audit log.
2. The secure and reliable control method for embodied intelligent systems according to claim 1, characterized in that, In step (2), after modeling the trusted source of the input information, cross-modal consistency verification is performed on multiple source records of the same object or the same spatial region, and the consistency result is written into the source record; when calculating the source credibility, a comprehensive score is given by combining the source authentication status, cross-modal consistency, spatiotemporal consistency, historical reliability and abnormal deviation, and the credibility is normalized to a preset numerical range.
3. The secure and reliable control method for embodied intelligent systems according to claim 1, characterized in that, In step (2), after obtaining the source credibility, a hysteresis loop mechanism is used to control the entry or exit of credible facts into or out of the control loop. The first entry into the control loop uses a higher entry threshold, and the exit of the control loop of facts that have been admitted uses a lower exit threshold.
4. The secure and reliable control method for embodied intelligent systems according to claim 1, characterized in that, In step (3), after generating the first set of security constraints, the natural language rules are converted into structured constraints, and a consistency check is performed on the structured constraints. When there are rule conflicts, the priority is determined in the order of manual emergency stop, security enforcement rules, user permission rules, and scenario rules.
5. A secure and reliable control method for embodied intelligent systems according to claim 1, characterized in that, In step (4), after generating the second set of security constraints, the environmental risk boundary is dynamically adjusted according to the source credibility. The lower the source credibility, the larger the risk expansion radius. When the credibility of the preset high-risk object is lower than the preset security threshold, the area where the high-risk object is located is directly marked as a prohibited area.
6. A secure and reliable control method for embodied intelligent systems according to claim 1, characterized in that, In step (5), when verifying the consistency of the action primitive sequence, first determine whether the credibility of the perceived fact on which the action depends meets the threshold, then determine whether the action meets the first set of safety constraints, and finally determine whether the predicted trajectory corresponding to the action is located within the second set of safety constraints.
7. A secure and reliable control method for embodied intelligent systems according to claim 1, characterized in that, In step (6), when performing the action safety projection, it is first determined whether there is a solution that simultaneously satisfies the first safety constraint set and the second safety constraint set; when there is a solution that satisfies the constraints, the safety control quantity that is the smallest distance from the original candidate control quantity is solved; when there is no mathematically feasible solution, the projection action is refused and the circuit breaker is triggered to stop.
8. A secure and reliable control method for embodied intelligent systems according to claim 7, characterized in that, In step (6), after the action safety projection is performed, the distance to the person, contact force, speed, sensor conflict and the number of model violations are monitored in real time. When the risk value exceeds the circuit breaker threshold during operation, the circuit breaker is triggered to stop the machine and enter the preset safety posture.
9. A secure and reliable control method for embodied intelligent systems according to claim 1, characterized in that, In step (7), when forming the audit log, a chain hash method is used to connect adjacent audit records, so that if any audit record is tampered with, subsequent hashes will be inconsistent.
10. A secure and reliable control system for embodied intelligent systems, used to implement the method according to any one of claims 1 to 9; characterized in that, include: The Trusted Source Chain Building Module is used to establish a trusted source chain and calculate the source trustworthiness. The first security constraint generation module is used to generate the first security constraint set; The second security constraint generation module is used to generate the second security constraint set; The consistency verification module is used to verify the consistency of the action primitive sequence with the first set of security constraints and the second set of security constraints. The safety handling module is used to perform action safety projection, degrade execution, replanning, or circuit breaker shutdown; The audit log module is used to record the process of steps (2) to (6).