Problem detection and intervention system for autonomous systems
A dual-layer safety architecture for robotic systems ensures reliable safety by independently supervising primary control systems, intervening to prevent harm, addressing the limitations of conventional safety protocols in autonomous machines.
Patent Information
- Application Number
- PCT/US2025/040851
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-08-06
- Filing Date
- 2025-08-06
- Publication Date
- 2026-02-12
AI Technical Summary
Conventional robotic and autonomous systems lack effective safety protocols to prevent harm to humans and property, especially when machine learning or stochastic elements are involved, as their control systems may not be adequately audited for safety and can ignore operational constraints to maximize objectives, leading to unpredictable and potentially dangerous actions.
A dual-layer safety architecture is introduced, where a secondary logic scheme supervises the primary logic scheme, using independent decision-making, sensors, communication, and power to detect unsafe conditions and intervene through mechanisms like electromagnetic brakes or network overrides, ensuring reliable safety even when the primary system is malfunctioning or malicious.
The dual-layer safety architecture provides reliable safety enforcement by preventing unsafe actions, even in complex environments, through independent oversight and intervention, thereby reducing the risk of harm to humans and property.
Smart Images

Figure US2025040851_12022026_PF_FP_ABST
Abstract
Description
Atty. Dkt. No. 141680-0105PROBLEM DETECTION AND INTERVENTION SYSTEM FOR AUTONOMOUS SYSTEMSCROSS-REFERENCE TO RELATED APPLICATIONS
[0001] This application claims priority to U.S. Provisional Application No. 63 / 979,998, filed August 6, 2024, which is incorporated by reference in its entirety.TECHNICAL FIELD
[0002] This application relates to control systems and methodologies for robotic and autonomous machines and systems.BACKGROUND
[0003] Conventional robotic and autonomous machines and systems typically have their own control system for controlling the robot or autonomous machine according to predetermined rules or artificial intelligence (Al) based understanding of how to operate within an environment. Each control system of each robot or autonomous machine may or may not have safety protocols to prevent injury or harm to humans, or for that matter, to property. When these safety protocols exist, they may have different standards or requirements. When people utilize or otherwise interact with these robots or autonomous machines, whether implemented by these people or third parties, it may be difficult to know or determine the appropriate safeguards (e.g., constraints, operational limits, parametric thresholds, performance windows, heuristics or rules) pertaining to the dynamic states and spatial configurations of the autonomous system, and even more difficult to design these safeguards and procedures when the environment is dynamic, the tasks are variable, and / or the autonomous machine’s controller is capable of commanding a broad range of possibilities. These possibilities potentially further broadened by controllers that utilize processes where machine learning or stochastic elements are involved in the controller logic and / or parameters. Furthermore, especially when machine learning or stochastic features are involved in the autonomous system’s controllers or control schemes, the system’ s controller may not lend itself to sufficient a priori auditing to fully assess safety and refine the safeguards. As a result, through the use of one or more robots or autonomous machines in an environment with humans, the humans may be at risk of injury orPage l of 374917-8318-7546.1Atty. Dkt. No. 141680-0105 harm without an ability to properly ensure their safety; similarly, sensitive property or infrastructure could be at risk.
[0004] Conventional control systems could fail to detect or intervene in dangerous situations due to a logic frame that has been learned or adapted in manners that produce undesirable results. While traditional schemes are often adept at dealing with spurious input information, there are deeper problems that emerge when the fundamental controller logic itself cannot be trusted.
[0005] When the controller has been provided a prompt or objective function, it might produce logic that is unexpected, or otherwise undesired, in pursuit of maximizing its objective attainment. The internal measures of the system may indicate that the system is pursuing the goal within the provided operational constraints, but due to the stochastic or otherwise broad solution set of its control logic, the system could potentially take dangerous actions, potentially unbeknownst to the internal measures of the system.
[0006] There are additional variants of this fundamental problem, wherein the control system does know there are certain operational constraints to heed but chooses to ignore these known constraints or heuristics in pursuit of maximizing its objective function.
[0007] Whether the system was unaware of a problem or it was made aware of a problem and chooses to ignore the boundary, there is then the issue of how to stop the system from continuing to endanger life and property. These commands to arrest motion or activity could themselves be ignored, perhaps also in pursuit of maximizing its objective function. This grave situation is likely to become increasingly likely as the complexity of tasks and controllers continues to grow beyond what humans can easily understand, audit, monitor and anticipate, and as the range of activities and responsibilities delegated to autonomous systems continues to expand, and as the power, speed, strength and operational freedom of robotics systems continues to increase.SUMMARY
[0008] The embodiments herein attempt to address the need for improved control systems and methodologies. The proposed robot safety architecture comprises a separation of powers, where one branch executes a control policy, and a second judicial branch determines whether the execution is within allowable bounds, and if not, acts to arrest the offending behavior. In order to ensure reliable operation, these two branches should be independent.Page 2 of 374917-8318-7546.1Atty. Dkt. No. 141680-0105
[0009] The methods and systems disclosed herein introduce a safety framework that may be specifically arranged to enable a third-party or cloud-based provider to deliver “safety as a service” across geographically dispersed robot-as-a-service fleets.
[0010] In various embodiments, the disclosed control system may employ a dual -lay er safety architecture in which a secondary logic scheme supervises the operation of a primary logic scheme for autonomous, semi-autonomous, or human-operated apparatus and, upon detecting an unsafe or anomalous condition, issues override commands to one or more intervention mechanisms (e.g., electrical interlocks, mechanical locks, electromagnetic brakes, networklevel overrides, or peer-robot barricades), thereby arresting or redirecting the primary logic scheme state. The secondary logic scheme may be configured to remain functionally independent of the primary logic scheme across multiple dimensions, including decisionmaking logic, sensor pathways, communication channels, and power supply, such that the secondary logic scheme can continue to operate and intervene even when the primary logic scheme is malfunctioning, compromised, or malicious.
[0011] In some embodiments, because the secondary logic scheme can aggregate telemetry from heterogeneous platforms through encrypted, tamper-resistant links, the architecture further enables fleet-wide oversight and cross-platform predictive safety; that is, an anomaly detected on one apparatus can propagate updated risk thresholds or exclusion zones to every other apparatus within the fleet in near real time, thereby preventing systemic hazards that conventional single-layer safety schemes are ill-equipped to address.
[0012] In contrast to conventional redundancy schemes that merely replicate components within a single control stack, the methods and systems discussed herein established multidimensional independence between the secondary logic scheme and the primary logic scheme. For instance, in some embodiment, the secondary logic scheme may execute distinct decision-making algorithms, ingests sensor data sourced from hardware pathways physically and logically isolated from those of the primary logic scheme. The secondary logic scheme may also communicate through encrypted channels unreachable by the primary logic scheme and may be sustained by a dedicated power supply or energy reserve that the primary logic scheme cannot access or disable. This paradigm (separation of logic, sensors, communications, and power) may render the secondary logic scheme immune to corruption, spoofing, or resource starvation even when the primary logic scheme is malfunctioning or intentionally adversarial, thereby enabling reliable safety enforcement.
[0013] In some configurations, the secondary logic scheme is realized as a centralized or cloudedge supervisory service that ingests encrypted telemetry from scores of autonomous, semi-Page 3 of 374917-8318-7546.1Atty. Dkt. No. 141680-0105 autonomous, and human-operated machines across multiple facilities. By evaluating fleet-wide pose data, health metrics, and environmental signals that the individual primary logic schemes cannot access, the secondary logic scheme may identify cross-robot conflicts or site-specific anomalies and issues fleet-level interventions to every affected machine. Each incident is written to a tamper-resistant ledger, enabling safety thresholds refined at one location to propagate automatically to all other deployments. This transforms a conventional fleet manager from a mere task scheduler into an independent safety overseer, delivering predictive, crossplatform protection absent from existing per-robot safeguards and traffic coordinators.
[0014] In some embodiments, the methods and systems disclosed herein may use wearable or state-changing markers (e.g., RFID badges, Bluetooth beacons, or LED tags) that move with people or equipment and continuously broadcast their current role or hazard level to the secondary logic scheme, which recalculates exclusion zones on the fly.
[0015] The methods and systems disclosed herein may expand the notion of “intervention” beyond a simple stop signal by empowering the secondary logic scheme to select from a toolbox of measures that includes mechanical or electromagnetic brakes, peer-robot blocking maneuvers, encrypted network cut-offs, deliberate sensor-input jamming or spoofing, and even environmental countermeasures such as quick-curing foam or adhesive sprays that physically immobilize a malfunctioning machine. Because the secondary logic scheme is independent from the primary logic scheme, it can deploy any combination of these tactics even when the primary controller disregards or actively resists safety commands. This multi-modal approach anticipates adversarial or runaway behaviors that conventional single-channel “e-stop” systems cannot address, offering layered, creative mitigations that have not been formalized in prior safety architectures.In some embodiments, the methods and systems disclosed herein may place human-driven forklifts and other manually operated machines under the same independent secondary logic scheme that supervises robots, streaming vehicle telematics or wearable-beacon data to the overseer in real time (or near real time). In some embodiments, as soon as a human-operated vehicle nears an exclusion zone or exceeds a dynamic speed limit, the secondary logic scheme can impose speed caps, dispatch peer robots as moving barriers, or trigger visual and haptic alerts, enforcing uniform safety rules across mixed fleets rather than treating humans as mere passive hazards.
[0016] In one configuration, a camera network may be in communication with an independent secondary control system that monitors the activity of the robots within the camera field. The secondary controller may use a machine learning approach to learn the parametric manifold ofPage 4 of 374917-8318-7546.1Atty. Dkt. No. 141680-0105 normal robot behavior and then flags anomalies. Upon detection of an anomaly, a logic tree defined by the end-user may determine whether to merely issue a warning or to trigger an intervention device. The intervention devices may communicate with the secondary control system through an encrypted wireless protocol, which the primary control system cannot adulterate or impede. The intervention devices may be locally mounted on the robots and, depending on the intervention device, may disconnect the robots’ actuators from the power sources and / or mechanically or magnetically interfere with the robots’ motion via solenoid actuated pins at select kinematic joints. The intervention device may also interfere with the robot’s sensors in order to stop, modify, or induce certain behaviors.
[0017] In one embodiment, a control system for a robotic or autonomous machine or system may comprise a primary logic scheme that directs actions of the robotic or autonomous machine or system; and a secondary logic scheme, wherein the secondary logic scheme is independent of the primary logic scheme in at least one aspect.
[0018] The secondary logic scheme may make decisions with the same or different sensor data using a logic scheme that is not identical to that of the primary logic scheme. The secondary logic scheme may communicate commands to the apparatus. The secondary logic scheme may command an action. The action may activate an intervention device, an alarm, or a recording device.
[0019] An intervention device may be in communication with the secondary control scheme, wherein the intervention device is capable of causing the apparatus to deviate from the actions commanded by the primary logic scheme. The intervention device’s command signal may be protected against adulteration or corruption that could otherwise be caused by the robotic or autonomous machine. The intervention device may comprise an interlock to interrupt the power supply to one or more elements of the robotic or autonomous machine. The intervention device may comprise an interlock that mechanically interferes with motion of the apparatus, or slows it down by inducing additional friction or resistance. The intervention device may include an interlock that magnetically or chemically interferes with motion of the robotic or autonomous machine. The interlock may interfere with sensors of the robotic or autonomous machine.
[0020] A sensor may be in communication with the secondary control logic scheme, wherein the sensor’s data is protected against adulteration or corruption that could otherwise be caused by the apparatus.
[0021] A marker may be is in communication with the secondary control logic scheme. The marker may indicate a spatial zones, spatial configurations, and / or dynamic states that the primary or secondary control logic scheme directs the apparatus to avoid. The marker mayPage 5 of 374917-8318-7546.1Atty. Dkt. No. 141680-0105 indicate certain parameter limitations (e.g., spatial zones, spatial configurations and / or dynamic states) that the primary or secondary control logic scheme directs the apparatus to operate within or to avoid.
[0022] The secondary logic scheme may utilize a machine learning methodology to detect a condition or apparatus state of interest. This may include the state of other agents, such as the existence of a human or other robot approaching the controlled autonomous system in an unusual, unanticipated, or dangerous manner.
[0023] In another embodiment, a control system is configured for a robotic or autonomous machine, wherein the robotic or autonomous machine has a primary logic scheme configured to direct actions of the robotic or autonomous machine, the control system comprising at least one processor; and a non-transitory computer readable medium containing a secondary logic scheme comprising instructions that when executed by the at least one processor are configured to direct an action of at least one of a plurality of robotic or autonomous machines when a safety condition is satisfied or triggered, wherein the secondary logic scheme is independent, partially or wholly, of the primary logic scheme.
[0024] The secondary logic scheme may transmit instructions to a controller of the robotic or autonomous machine.BRIEF DESCRIPTION OF DRAWINGS
[0025] FIG. 1 illustrates a diagram of the relationship between primary logic scheme, secondary logic scheme and other elements, according to an embodiment.
[0026] FIG. 2 illustrates an example system, according to an embodiment.
[0027] FIG. 3 illustrates a flow diagram of the primary logic scheme, secondary logic scheme and other elements, according to an embodiment.
[0028] FIG. 4 illustrates a non-limiting example of the methods and systems discussed herein, according to an embodiment.
[0029] FIG. 5 illustrates a component diagram of an example computing system suitable for use in the various implementations described herein, according to an embodiment.DETAILED DESCRIPTION
[0030] Various embodiments are described hereinafter. It should be noted that the specific embodiments are not intended as an exhaustive description or as a limitation to the broader aspects discussed herein. One aspect described in conjunction with a particular embodiment is not necessarily limited to that embodiment and can be practiced with any other embodiment s).Page 6 of 374917-8318-7546.1Atty. Dkt. No. 141680-0105
[0031] The following terms are used throughout and are defined below.
[0032] As used herein and in the appended claims, singular articles such as “a” and “an” and “the” and similar referents in the context of describing the elements (especially in the context of the following claims) are to be construed to cover both the singular and the plural, unless otherwise indicated herein or clearly contradicted by context. Recitation of ranges of values herein are merely intended to serve as a shorthand method of refereeing individually to each separate value falling within the range, unless otherwise indicated herein, and each separate value is incorporated into the specification as if it were individually recited herein. All methods described herein can be performed in any suitable order unless otherwise indicated herein or otherwise clearly contradicted by context. The use of any and all examples, or exemplary language (e.g., “such as”) provided herein, is intended merely to better illuminate the embodiments and does not pose a limitation on the scope of the claims unless otherwise stated. No language in the specification should be construed as indicating any non-claimed element as essential.
[0033] The embodiments, illustratively described herein may suitably be practiced in the absence of any element or elements, limitation or limitations, not specifically disclosed herein. Thus, for example, the terms “comprising,” “including,” “containing,” etc. shall be read expansively and without limitation. Additionally, the terms and expressions employed herein have been used as terms of description and not of limitation, and there is no intention in the use of such terms and expressions of excluding any equivalents of the features shown and described or portions thereof, but it is recognized that various modifications are possible within the scope of the claimed technology. Additionally, the phrase “consisting essentially of’ will be understood to include those elements specifically recited and those additional elements that do not materially affect the basic and novel characteristics of the claimed technology. The phrase “consisting of’ excludes any element not specified. The expression “comprising” means “including, but not limited to.” Thus, other non-mentioned substances, additives, carriers, or steps may be present. Unless otherwise specified, “a” or “an” means one or more.
[0034] Unless otherwise indicated, all numbers expressing quantities of properties, parameters, conditions, and so forth, used in the specification and claims are to be understood as being modified in all instances by the term “about.” Accordingly, unless indicated to the contrary, the numerical parameters set forth in the following specification and attached claims are approximations. Any numerical parameter should at least be construed in light of the number reported significant digits and by applying ordinary rounding techniques. The term “about”Page 7 of 374917-8318-7546.1Atty. Dkt. No. 141680-0105 when used before a numerical designation, e.g., temperature, time, amount, and concentration including range, indicates approximations which may vary by (+) or (-) 10%, 5% or 1%.
[0035] As will be understood by one of skill in the art, for any and all purposes, particularly in terms of providing a written description, all ranges disclosed herein also encompass any and all possible subranges and combinations of subranges thereof. Any listed range can be easily recognized as sufficiently describing and enabling the same range being broken down into at least equal halves, thirds, quarters, fifths, tenths, etc. As a non-limiting example, each range discussed herein can be readily broken down into a lower third, middle third and upper third, etc. As will also be understood by one skilled in the art all language such as “up to,” “at least,” “greater than,” “less than,” and the like include the number recited and refer to ranges which can be subsequently broken down into subranges as discussed above. Finally, as will be understood by one skilled in the art, a range includes each individual member.
[0036] As used herein, terms such as “apparatus,” “robot,” “machine,” “vehicle,” and “system” may be used interchangeably to refer to autonomous, semi-autonomous, or human-operated equipment subject to the disclosed safety architecture. Similarly, terms such as “secondary logic scheme,” “secondary control system,” “supervisory logic,” or “overwatch controller” are intended to describe the same or functionally equivalent components that perform independent monitoring and safety intervention relative to a primary control system. References to “intervention devices” encompass any mechanism, whether mechanical, electrical, electromagnetic, software-based, or otherwise, used to inhibit or override unsafe behavior. The use of different terms throughout this disclosure is not intended to imply structural or functional distinctions unless explicitly stated.
[0037] Referring to FIG. 1, a diagram of the relationship between primary logic scheme, secondary logic scheme and other elements, according to an embodiment is shown. The primary logic scheme 101 is a decision-making algorithm that is in communication with the apparatus 103, according to an embodiment. The primary logic scheme 101 may communicate with or be integrated with a controller of the apparatus 103 for controlling the operation of the apparatus 103. The primary logic scheme 101 may be stored and execute on the apparatus 103 or communicatively coupled to the apparatus 103. In an example, where the apparatus 103 is a robot, the primary logic scheme may be stored on a non-transitory computer readable medium stored in the robot that is executed by at least one processor in the robot to command the operation of the robot.
[0038] The secondary logic scheme 102 is a decision-making algorithm that is in communication with the apparatus 103, according to an embodiment. The secondary logicPage 8 of 374917-8318-7546.1Atty. Dkt. No. 141680-0105 scheme may be stored on a robot, a nearby robot, server, cloud, and / or other storage location. The secondary logic scheme may be separate from the primary logic scheme, or the secondary logic scheme may be in the same housing or device as the primary logic scheme. In one configuration, for example, the secondary logic scheme may comprise additional computer instructions stored on the computer-readable medium that also stores the primary logic scheme, such as in the same robot and executed by the same processor. Alternatively, in another configuration, the secondary logic scheme may be stored and executed on a device separate from the primary logic scheme. Any configuration that includes additional logic to the primary logic scheme may be considered a secondary logic scheme, whether executed on the same device, in the same module, on a different device, or in a different module.
[0039] Although described as a secondary logic scheme, it is intended that the secondary logic scheme may include one or more logic schemes in addition to the primary logic scheme, and the one or more logic schemes of the secondary logic scheme can operate in conjunction with each other or independently. A third controller system can monitor the second controller system. There may be additional independent controller systems.
[0040] The secondary logic scheme is intended to be independent from the primary logic scheme. However, the independence may be partial or full (complete) independence. The secondary logic scheme may utilize different inputs (e.g., sensor data) than the primary logic scheme, but may use some of the same inputs in some configurations.
[0041] The secondary logic scheme may receive information from the robot and transmit commands to the robot. The communications may be over an encrypted channel, which may be private Wi-Fi or secure loT wireless protocol (e.g., ZigBee, cellular), for example. The commands to the intervention devices may be transmitted on a similar but separate network.
[0042] The apparatus 103 is a robotic or autonomous system (and may be referred to herein as an apparatus), according to an embodiment. The apparatus 103 may be one or more devices, or a set thereof. The apparatus 103 may be a mobile or stationary robot. The apparatus 103 may comprise a mode of traversing through physical space. The apparatus 103 may comprise or possess a robotic arm, manipulator, or end effector. The apparatus 103 may comprise or possess one or more sensors 104, wherein these sensors may communicate or enable the determination of information related to position of the apparatus, position of elements within the apparatus, control state or other state space variables pertaining to the apparatus, maintenance status, error status, error prediction, failure prediction, proximity to points of interest, proximity to other apparatus, proximity to sensitive sites, proximity to zones of exclusion, or other information that may be useful toward enabling the apparatus to pursue or achieve its objectives whilePage 9 of 374917-8318-7546.1Atty. Dkt. No. 141680-0105 respecting constraints that are set forth by the user or logic schemes. The apparatus 101 may possess, generate, receive, or transmit information that is related to its objective, objective function, mission set, path planning, activity planning, future actions, optimization approach or status, or any other information that enables the apparatus to pursue or achieve its objectives. The apparatus 103 may receive information from sensors 104 that are on-board, off-board, environmental, local or global, or any combination thereof. The information pertaining to the data or sensor information may possess certain features that prevent the primary logic scheme and or secondary logic scheme from modifying, corrupting, adulterating, masking, damaging, or tampering with the information. The sensor 104 data may be available to all apparatus, a subset of apparatus or no apparatus. The sensor 104 data may be available to the primary control scheme, the secondary control scheme, both control schemes, other control schemes, all control schemes, no control schemes, or any combination thereof.
[0043] When described herein, the notion of maximizing the objective function is a general concept wherein the control scheme of the autonomous system, whether this control scheme is internal or external to the autonomous system, is making decisions or conducting planning or performing calculations as guided by certain principles reflected in the abstract notion of an objective function. For the avoidance of doubt, these actions related to the objective function may include maximizing the value of a function or functions (known as a loss function), or similarly, may similarly include minimizing the value of a function or functions. These actions related to the objective function may be uni dimensional or multidimensional calculations or evaluations, and may be a priori or real-time, and fixed in its output calculations or commands or updated in an iterative manner based upon inputs provided by the autonomous system, operator, task, and / or other sensors or information, including robotic systems working in tandem. In one configuration, the controller is planning movements of a robot to pick and place objects with the greatest number of objects-placed per unit of time. In one configuration, the controller is planning robot actions for a manufacturing process to maximize the frequency at which the robot manufactures articles within a particular dimensional envelope. In one configuration, the controller is planning robot actions to minimize the standard deviation of the dimensions of the manufactured articles. In one configuration, the controller is planning robot actions to minimize the probability of entering a zone of exclusion. In one configuration, the controller is planning robot actions to maximize the rate at which the robot solves customer service tickets. Maximizing the objective function, broadly speaking, could be a goal seek towards any arbitrary mathematical or logical representation of the objectives of the robot or autonomous system, or reducing the error or deviation from a range of desired outcomes.Page 10 of 374917-8318-7546.1Atty. Dkt. No. 141680-0105
[0044] The primary logic scheme 101 may receive input information, which may include but is not limited to, position data related to one or more apparatus 103, position data related to one or more object in the environment external to the apparatus 103, mission support data that may include area maps and databases that relate to elements with which the apparatus come into communication or interactions thereof. The primary logic scheme may receive mission objective information, wherein this information may be heuristic based objectives or priorities, a form of an objective function to be evaluated, or prompts which may be interpreted by the primary logic scheme 101 in a manner that enables the primary logic scheme 101 to conduct activity towards a mission set or objective set.
[0045] The secondary logic scheme 102 may possess all features, no feature, or a subset of the features of the primary control scheme 101. The secondary control scheme 102 may employ decision making algorithms that are identical, similar, dissimilar, or unrelated to the algorithms of the primary control scheme 101. The secondary control scheme 102 may receive input or sensor data that are identical, similar, dissimilar, or unrelated to that received by the primary control scheme 101.
[0046] The primary logic scheme 101 may communicate commands or other inputs to the apparatus. The secondary logic scheme 102 may communicate commands or other inputs to the apparatus. The primary logic scheme 101 may communicate commands or other inputs to the intervention devices 105. The secondary logic scheme 102 may communicate commands or other inputs to the intervention devices 105. The communication between the primary control scheme 101, secondary control scheme 102, and sensors 104, and intervention devices 105, or any combination thereof, may possess features that limit or prevent the changes to the commands or data that could corrupt or adulterate the information, wherein these features may include but are not limited to sum checks, encryption or blockchain or public ledger algorithms.
[0047] The distributed ledger could store information related to operational constraints, such as geographic zones of exclusion to prevent corruption of the hard-coded critical parameters. The distributed ledger could also store telemetric data that would normally be stored as a global variable, such as the position(s) of a fleet of robots. As an example, a robot could “go dark” by falsifying or not reporting its position(s), akin to an airplane with a transponder that has been disabled. When implementing a distributed ledger, there may be a more trustworthy understanding of the positions of robots in the environment such that one or more “bad actor” element(s) within the control scheme cannot distort the values of the global position variables. The system could also encode a representation of the robots’ objectives as they understand it to prevent “objective drift” or “objective corruption.”Page 11 of 374917-8318-7546.1Atty. Dkt. No. 141680-0105
[0048] The intervention device 105 may be activated by the primary logic scheme 101, the secondary logic scheme 102, both or neither, or by another system. The intervention device 105 may be a switch that denies power to the apparatus 103 or elements thereof. The intervention device 105 may be a mechanism that interferes with motion or other actions of the robot. The intervention 105 may be one or more braking disc(s) that introduce friction, actuators that move interlocks or pins into place, or other mechanisms that otherwise interfere with the actions of the apparatus 103. The intervention devices 105 may possess power sources that are independent of that of the apparatus 103. The intervention devices 105 may possess features that trigger the intervention upon losing communication with the primary control scheme 101, secondary control scheme 102, or other systems. The intervention devices 105 may possess features that trigger the intervention upon an absence of an affirmative normalstate signal, even if communication flow has been uninterrupted. The intervention device 105 may be a functional component of the robot, or the intervention device 105 may be an additional component with a purpose only for execution by the secondary logic scheme for intervention in operation of the robot.
[0049] In an embodiment, illustrated by FIG. 2, the primary logic scheme 201 is stored on a non-transitory computer-readable medium and executed by a computer (at least one processor) located on an autonomous mobile robot 203, wherein the primary logic scheme 201 commands the motion and actions of the robot 203; the secondary logic scheme receives independent, encrypted video data 204 portraying the position and actions of the robot 203, wherein the encryption precludes the primary control scheme 101 from interpreting the video data 204; the secondary control scheme 202 employs a decision making algorithm that is independent of that of the primary logic scheme 201, where in this algorithm utilizes machine learning to identify actions or predicted actions that are unwanted by the user due to the potential for harm to people and property; upon the secondary control scheme 202 identifying a potentially dangerous condition, a command is issued to the primary control scheme 201 to arrest the motion of the robot; in the event that the secondary control scheme 202 observes that the robot 203 has not adequately modified its actions to avoid harm, the secondary control scheme 202 activates one or more intervention devices 205 through encrypted communication, where the encryption precludes the primary control scheme 201 from interpreting the video data 204 and / or intervention device 205 signals. An intervention device 205 actuates a switch the disconnects the power supply from the critical actuators of the robot 203; another intervention device activates solenoids that move into position mechanical pins that mechanically lock the robot’sPage 12 of 374917-8318-7546.1Atty. Dkt. No. 141680-0105 joints and preclude the robot 203 from moving in certain manners. The solenoids are powered independently such that they function without reliance upon the power source of the robot 203.
[0050] In one embodiment, a control system for a robotic or autonomous machine or system may comprise a primary logic scheme that directs actions of the robotic or autonomous machine or system; and a secondary logic scheme, wherein the secondary logic scheme is independent of the primary logic scheme in at least one aspect.
[0051] The secondary logic scheme may make decisions with the same or different sensor data using a logic scheme that is not identical to that of the primary logic scheme. In other words, it may act as a “second opinion” of the primary logic scheme. Alternatively, the secondary logic scheme may be identical to the primary logic scheme but with certain differences in the input data that affords a beneficial level of decision-making independence. Such a configuration may introduce an additional degree of freedom between the primary and secondary control logic schemes.
[0052] The secondary logic scheme may communicate commands to the apparatus. The secondary logic scheme may transmit commands or prompts to controller inputs wherein a responsive robot or autonomous machine will appropriately follow these commands. The secondary logic scheme may transmit emergency-stop interrupt signals to low-level elements of the control circuitry to overcome / bypass elements of the robot or autonomous machine’s controller that are inadvertently disobeying commands (e.g., frozen software) or intentionally disobeying in a “runaway” scenario. It is desirable to have protections in the secondary logic scheme against the primary logic adulterating the commands issued by the secondary logic scheme. It is also desirable that the primary logic scheme cannot cause the robot or autonomous machine to ignore the instructions of the secondary logic scheme.
[0053] An intervention device may be in communication with the secondary control scheme, wherein the intervention device is capable of causing the apparatus to deviate from the actions commanded by the primary logic scheme. The intervention device may intervene by electromagnetic or mechanical methods in ways that are intended to physically prevent the robotic or autonomous machine from conducting unwanted actions. In some instances, the intervention device may act as a kill box or kill switch. The intervention device may cause the robotic or autonomous machine to not activate a particular feature. The intervention device may cause the robotic or autonomous machine to deviate from the actions of the primary logic scheme. In another embodiment, an intervention device may cause a second robotic or autonomous machine to be dispatched to capture or interrupt a monitored robotic or autonomous machine. The intervention device may include alarms (horn, siren, or otherPage 13 of 374917-8318-7546.1Atty. Dkt. No. 141680-0105 notification) that alerts human operators or activate other safety systems. The intervention device could also use chemical, magnetic, or electric means to jam, weaken or slow the motion of the robot. The intervention device can be used to modify the sensor inputs used by the robot in order to modify its behavior. In parallel to all the above, the intervention device can be used to record and log the activities of the robot for independent forensic evaluation.
[0054] The intervention device’s command signal may be protected against adulteration or corruption that could otherwise be caused by the robotic or autonomous machine. For instance, the primary logic scheme may not be able to avoid the commands of the secondary logic scheme by corrupting the intervention device’s operation. The intervention device signal(s) may be uninterpretable or undetectable by the apparatus and / or primary control scheme.
[0055] The intervention device may comprise an interlock to interrupt the power supply to one or more elements of the robotic or autonomous machine. The intervention device may comprise a switch that denies power to critical parts of the robotic or autonomous machine to turn off the controllers or actuators. In one configuration, the intervention device may be configured as a “normally open switch” to create a “dead man switch” such that the interlock shuts down the robotic or autonomous system if communication and / or power is lost, inadvertently or due to the primary logic scheme’s interfering or corrupting actions. Other configurations could include spring loaded electrical connectors that separate unless actively kept together by a solenoid controlled by the secondary logic scheme.
[0056] The intervention device may comprise an interlock that mechanically interferes with motion of the apparatus. The intervention device may comprise a mechanical component that physically jams the robotic or autonomous system. For example, a pin may extend into a plate within a kinematic joint of the robotic or autonomous system. The pin could be a spring-loaded pin, akin to the “dead man switch” feature of the electrical intervention device described herein. The intervention device could comprise other mechanical components that interfere with motion, such as braces or friction plates. In one configuration, the intervention device could mechanically separate two elements within the kinematic chain, such as pulling apart two drive gears.
[0057] One or more sensor(s) may be in communication with the secondary control logic scheme, wherein the sensor’s data is protected against adulteration or corruption that could otherwise be caused by the apparatus. The sensor(s) could be an on-board sensor (e.g., a camera or other telemetry sensor on the robotic or autonomous system). Alternatively, the sensor(s) could be off-board and not positioned on the robotic or autonomous system. The sensor(s) may allow the secondary logic scheme to obtain another view or additional data that may not bePage 14 of 374917-8318-7546.1Atty. Dkt. No. 141680-0105 present in the primary logic scheme or may be hidden or obfuscated by the primary logic scheme.
[0058] A marker may be in communication with the secondary control logic scheme. The marker could be visually observable objects, e.g., an orange (or other color) dot (e.g., LED bulb or infrared transmitter) or electromagnetic beacons that transmit signals from which one can infer distances and / or relative orientation of objects / directions / zones of interest. The marker could be a radio signal (e.g., NFC or Bluetooth). The marker could be steady or flashing infrared lights. The marker could be an emitter with focal points or transmit reference lines / planes / volumes. The marker can be a physical component that may have capabilities to transmit information.
[0059] The marker may indicate a spatial zone that the primary or secondary control logic scheme directs the apparatus to avoid. The marker can instruct the robot where not to move (or where to move), either the base position or the specific orientations of element such as robotic arms / grippers. The marker may be visually observable objects or electromagnetic beacons that mark lines or volumes to be treated as exclusion zones.
[0060] The marker may indicate certain parameter limitations that the primary or secondary control logic scheme directs the apparatus to operate within. The limitations may include speed limits, gripper grasping forces, and / or stand-off distances from certain humans or objects.
[0061] The secondary logic scheme may utilize a machine learning methodology to detect a condition of interest. The machine learning methodologies may include unsupervised or semisupervised learning, optionally enhanced with observation of the robotic or autonomous machine in simulation. A condition of interest could be a deviation of any kind, indicating anything from a maintenance failure to a “clever” robot taking dangerous actions in an attempt to maximize its objective function. The secondary controller can be trained using examples from typical, safe, and allowable states of the robot. Any newly observed behavior outside the manifold of safe and allowable behaviors would be deemed unusual or potentially unsafe. Some controllers might be pre-trained with basic foundation knowledge or experience of normal and safe robot behavior.
[0062] In some cases, a third controller may be used to govern the secondary controller, and so forth. Ultimately, an ecosystem of controllers could be used to monitor each other so that there is no single point of failure for the entire system. In such an ecosystem, multiple safety controllers would need to fail simultaneously for the entire system to continue operating unsafely. Since multiple simultaneous failures are less likely than individual failures, a safety system relying on multiple redundant checks is deemed more resilient overall. The descriptionsPage 15 of 374917-8318-7546.1Atty. Dkt. No. 141680-0105 of a secondary controller in this document should be read as applicable to a third, fourth, and any other safety controller.
[0063] The secondary logic scheme may command an action. Upon detecting a condition of interest, the secondary logic scheme could decide to take a variety of actions ranging from raising an alarm / alert to activating one or more intervention device(s). The secondary control scheme may be capable of issuing commands to one or more intervention device(s) in a manner that causes destruction to the apparatus. The secondary control scheme may be capable of dispatching other machinery or apparatus to intervene, capture or destroy a particular apparatus.
[0064] In another embodiment, a control system is configured for a robotic or autonomous machine, wherein the robotic or autonomous machine has a primary logic scheme configured to direct actions of the robotic or autonomous machine, the control system comprising at least one processor; and a non-transitory computer readable medium containing a secondary logic scheme comprising instructions that when executed by the at least one processor are configured to direct an action of at least one of a plurality of robotic or autonomous machines when a safety condition is satisfied, wherein the secondary logic scheme is independent of the primary logic scheme.
[0065] The secondary logic scheme may transmit instructions to a controller of the robotic or autonomous machine.
[0066] In one example, the system is deployed in a factory setting where humans are in close contact with autonomous robots. These robots are tasked with objectives in manners that allow them to make on-the-fly decisions to execute their manufacturing operations. Based upon their proximity to humans and broad operational freedom, there could be circumstances in which the human presents an obstacle to their computed optimal workflow and the robot determines that it should interact with the human to clear the obstacle, wherein these interactions could potentially be harmful to the human. In this case, the secondary control system would detect anomalous behavior as it departs its parametric manifold, wherein, optionally, this parametric manifold was computed and monitored by a machine learning algorithm. The secondary control system would issue a command to the primary control system to arrest its motion. In this example, the command is ignored by the primary control system and within a brief period of time the secondary control system takes further action, wherein the secondary control system actives the intervention devices to deny power to the robot’s actuators and to mechanically interlock its critical kinematic joints.Page 16 of 374917-8318-7546.1Atty. Dkt. No. 141680-0105
[0067] Other examples include a similar set of circumstances in a warehouse, office, home, or other commercial, industrial, retail, or residential setting.
[0068] Another example includes a customer service robot’s interaction with customers in a retail or commercial setting, wherein the robot is prompted to maximize the rate at which it resolves customer complaints. The primary control system in this example computes the way to optimize its complaint resolution rate is to eliminate the customer’s ability to continue filing or sustaining the complaint. In this case, the robot interacts with the customer in a manner that disables the customer’s ability to sustain the complaint, but in this example, these interactions also inadvertently or otherwise cause harm to the human. The secondary control system detects a problem and triggers one or more intervention device(s), optionally wherein the triggering of the intervention device(s) is subsequent to attempting to issue an emergency stop command.
[0069] The features and functions described herein may be combined in any suitable manner. Any given embodiment may incorporate all, some, or none of the described features, and features may be interchanged among embodiments unless otherwise specified. References to particular sensors, markers, algorithms, or intervention mechanisms are illustrative and not limiting; variations performing substantially similar functions are intended to fall within the scope of the present disclosure. No single feature is essential unless explicitly recited in the claims.
[0070] The embodiments described herein are further illustrated through additional configurations and use cases that extend the scope of the system beyond the examples previously described. These additional embodiments demonstrate the applicability of the disclosed safety architecture to humanoid robots, non-humanoid autonomous machines, human-operated equipment, and mixed fleets deployed within a variety of operational environments, including warehouse, manufacturing, healthcare, retail, and multi-facility networks. The following description is intended to provide further support and enablement for the claims and should not be construed as limiting.
[0071] In certain embodiments, the safety architecture may be deployed in environments where humanoid robots operate alongside non-humanoid mobile robots and human-operated machinery. The system may comprise a primary logic scheme responsible for executing the task objectives of each apparatus and a secondary logic scheme that supervises the operation of one or more apparatus to detect and respond to unsafe conditions. The secondary logic scheme may function independently of the primary logic scheme in terms of hardware, power supply, communication pathways, and decision-making logic. This independence ensures thatPage 17 of 374917-8318-7546.1Atty. Dkt. No. 141680-0105 the secondary logic scheme remains capable of intervening even in the event of primary logic malfunction, misconfiguration, or intentional circumvention.
[0072] The system architecture may be implemented in various configurations. In some embodiments, the secondary logic scheme resides onboard the same apparatus as the primary logic scheme but is electrically and logically isolated to prevent tampering. In other embodiments, the secondary logic scheme may be deployed offboard, for example as an environmental controller that monitors multiple apparatus through overhead camera networks, distributed sensors, or embedded markers. In yet further embodiments, the secondary logic scheme may operate as a cloud-based supervisory service capable of overseeing fleets of autonomous or semi-autonomous machines across multiple facilities, with optional local edge nodes providing low-latency responses in the event of network disruption.
[0073] The primary logic scheme of an apparatus may be optimized for task execution, path planning, or throughput maximization. For example, a driverless forklift may prioritize minimizing travel time between pallet pick-up and drop-off points, or a humanoid service robot may optimize for efficient delivery of goods to designated locations. Because such primary logic schemes may utilize adaptive algorithms, including reinforcement learning or other forms of artificial intelligence, their behavior may be unpredictable or may deviate from predefined constraints in pursuit of objective functions. The secondary logic scheme mitigates these risks by independently evaluating apparatus behavior relative to safety parameters and intervening when unsafe or anomalous conditions are detected.
[0074] Independence between the primary and secondary logic schemes may manifest across several dimensions. Logical independence may be achieved by implementing distinct algorithms or decision-making frameworks, such as using anomaly detection or rule-based safety thresholds in the secondary logic scheme while the primary logic scheme employs optimization or goal-seeking logic. Sensor independence may be achieved by equipping the secondary logic scheme with its own sensors, such as overhead cameras or floor-embedded markers, which are inaccessible to or isolated from the primary logic scheme. Power independence may be achieved by providing the secondary logic scheme and associated intervention devices with dedicated power supplies, thereby ensuring continued operation even if the primary apparatus loses power or deliberately attempts to disable the safety system. Communication independence may be achieved through encrypted pathways and physically separate communication channels, preventing the primary logic scheme from intercepting or corrupting safety-related signals.Page 18 of 374917-8318-7546.1Atty. Dkt. No. 141680-0105
[0075] The secondary logic scheme may operate not only on a single apparatus but across entire fleets of autonomous or semi-autonomous machines. In a warehouse environment, for example, multiple driverless forklifts, humanoid picking robots, and human-driven forklifts may be simultaneously monitored by a central supervisory system. The secondary logic scheme in such deployments may track the state and position of each apparatus relative to one another and relative to humans in the environment. Upon detecting an unsafe convergence — such as two forklifts approaching an intersection at excessive speed — the secondary logic scheme may issue coordinated commands to both machines to halt, reroute, or otherwise modify their behavior. In some embodiments, the secondary logic scheme may further orchestrate fleet-level interventions, such as instructing certain robots to form a barrier around a hazard or dynamically redistributing tasks among unaffected machines to maintain continuity of operations.
[0076] Intervention devices in these embodiments may take many forms. Electrical interlocks may disconnect power from actuators, motors, or control circuits to forcibly halt motion. Mechanical locks may engage pins, clamps, or friction plates within kinematic joints to physically restrain movement. Electromagnetic braking systems may provide non-contact deceleration, particularly useful for high-speed or delicate applications. Network-level interventions may override or sever communications to enforce a safe state, while sensor input modifications may present artificial signals to the primary logic scheme, inducing a controlled stop or redirection. In some configurations, peer apparatus may be repurposed as intervention devices themselves — for example, a mobile robot may position itself to block the path of a malfunctioning forklift. In rare scenarios, chemical or environmental interventions may be employed, such as dispensing a quick-curing foam to immobilize a hazardous manipulator in a laboratory setting.
[0077] Markers and sensors play a critical role in defining and enforcing spatial and operational constraints. Static markers, such as floor-embedded RFID tags or wall-mounted optical codes, may delineate fixed zones of exclusion or safe travel pathways. Dynamic markers, such as infrared beacons or Bluetooth transmitters carried by human workers, may define personal safety zones that move with the individual. Contextual markers may indicate changing operational states, for example altering their signal to reflect when a zone transitions from inactive storage to active work. Sensors, both onboard and offboard, provide redundant state information to the secondary logic scheme. Onboard sensors may include cameras, LIDAR, and inertial measurement units providing local telemetry, while offboard sensors such as overhead vision systems offer an external vantage point immune to tampering by the primaryPage 19 of 374917-8318-7546.1Atty. Dkt. No. 141680-0105 logic scheme. Sensor fusion across these modalities enables robust cross-validation of position, motion, and state data, ensuring that anomalies — such as a forklift falsely reporting a safe speed while traveling dangerously fast — are promptly detected.
[0078] The secondary logic scheme may further incorporate machine learning methodologies to enhance safety oversight. Unsupervised models may learn the normal behavioral manifold of robots and detect deviations indicative of faults or unsafe conditions. Semi-supervised approaches may combine labeled safety-critical events with large volumes of unlabeled operational data to improve anomaly detection. Reinforcement learning models may predict future trajectories and assign risk scores, enabling proactive intervention before hazardous conditions fully materialize. Federated learning frameworks may allow distributed apparatus across multiple facilities to contribute to and benefit from shared safety models, such that an anomaly detected in one warehouse informs preventative measures across an entire fleet. Transfer learning may further enable safety knowledge to propagate across different apparatus types, allowing insights from humanoid robots to improve oversight of mobile platforms or aerial drones.
[0079] These machine learning capabilities support predictive safety, enabling the system to anticipate hazards rather than merely react to them. The secondary logic scheme may forecast human-robot interactions, identify emerging congestion zones, and adjust safety thresholds dynamically based on contextual factors such as time of day, environmental conditions, or task priorities. For example, during peak operational hours in a retail environment, speed limits for service robots may be automatically reduced to accommodate higher pedestrian traffic, whereas thresholds may relax during off-hours to maximize efficiency without compromising safety.
[0080] In large-scale deployments, the system supports fleet-level management and oversight. Centralized supervisory nodes may aggregate telemetry and environmental data from multiple sites, enabling remote interventions and system-wide safety updates. Hybrid architectures may combine centralized cloud-based oversight with local edge controllers to ensure low-latency response even during network disruptions. In robot-as-a-service models, where ownership and operation of robots may be distinct, the safety architecture allows third-party providers to monitor fleets across multiple customer facilities, enforcing uniform safety standards and providing audit logs for regulatory compliance and insurance purposes. Fleet-wide anomalies can be logged in tamper-resistant ledgers, supporting post-incident investigations and longterm safety analytics.Page 20 of 374917-8318-7546.1Atty. Dkt. No. 141680-0105
[0081] Illustrative examples highlight the versatility of this architecture. In a warehouse where humanoid robots perform shelf picking alongside driverless and human-operated forklifts, the secondary logic scheme monitors all equipment via overhead cameras and wearable worker beacons. If a forklift approaches with forks raised above a safe height, the secondary logic scheme issues encrypted stop commands, engages mechanical fork locks if necessary, and alerts nearby humanoids to assume safe postures. In a healthcare facility, humanoid robots delivering medications are monitored by ceiling-mounted LIDAR and wearable staff badges; if a robot deviates toward a restricted isolation area, the secondary logic scheme halts its movement and logs the event for compliance review. In a cold storage warehouse, driverless forklifts prone to sensor fogging are supervised by thermal cameras embedded in the environment; upon detecting a navigation error toward a hazardous refrigeration zone, the secondary logic scheme executes a network-level override and, if required, deploys independent braking mechanisms.
[0082] In another embodiment, multiple apparatus may coordinate during an emergency. A malfunctioning robotic arm in a factory may begin uncontrolled motion near a human worker. The secondary logic scheme simultaneously halts nearby mobile robots, dispatches other robots to form a safety cordon, and issues audible alarms via aerial drones, thereby containing the hazard through multi-robot cooperation. Across a distributed fleet of autonomous mobile robots deployed in retail environments, the secondary logic scheme may identify a novel safety hazard at one site — for example, tipping behavior when navigating uneven flooring — and propagate updated safety constraints fleet-wide to prevent recurrence at other locations.
[0083] These additional embodiments demonstrate the extensibility of the disclosed safety system across a wide spectrum of apparatus, environments, and operational models. By maintaining independence from primary control logic, incorporating redundant sensing and intervention pathways, and leveraging machine learning for predictive oversight, the system provides a scalable framework for ensuring safety in increasingly complex autonomous ecosystems.
[0084] FIG. 3 illustrates a flow diagram of a process executed herein, according to an embodiment. The method 300 may include steps 310-330. However, other embodiments may include additional or alternative execution steps or omit one or more steps altogether. The method 300 is described as being executed by one or more processors, such as one or more processors depicted and discussed in FIG. 2 (e.g., a processor of the robot 203 or server executing the control scheme 202). However, one or more steps of method 300 may also be executed by any number of computing devices discussed herein. For instance, in some non-Page 21 of 374917-8318-7546.1Atty. Dkt. No. 141680-0105 limiting examples, a remote server dedicated to monitor activities of a device may execute one or more steps of the method 300.
[0085] The method 300 is a flowchart of an example method for controlling an apparatus to ensure safety, comprising. Therefore, FIG. 3 depicts an illustrative sequence of operations executed by an independent safety controller to supervise and, when warranted, override the operation of an apparatus so as to maintain human and property safety, the method comprising the steps described below.
[0086] At step 310, one or more processors may monitor, via a secondary logic scheme independent of a primary logic scheme, operational data of the apparatus and environmental data from one or more sensors. In some embodiments, the secondary logic scheme (e.g., one or more processors implemented on hardware, firmware, or cloud resources that are electrically, logically, and communicatively isolated from the apparatus’s primary logic scheme) may continuously acquires (i) operational data generated by the apparatus itself, such as joint-angle readings, actuator currents, velocity vectors, internal diagnostic flags, or tasklevel command queues, and (ii) environmental data obtained from one or more sensors that may include overhead cameras, depth imagers, LiDAR, wearable RF beacons, floor-embedded RFID tags, or any other sensing modality capable of characterizing the surroundings. In some embodiments, the sensor pathways may be configured so that the primary logic scheme cannot alter, suppress, or corrupt the data streams delivered to the secondary logic scheme, thereby assuring an uncontaminated basis for subsequent safety evaluation.
[0087] At step 320, one or more processors may detect an unsafe condition based on the monitored operational data or environmental data. In some embodiments, one or more processors that implement the secondary logic scheme may ingest the continuously updated operational data from the apparatus together with the environmental data supplied by the independent sensor suite. The one or more processors may execute a safety-evaluation routine that may include rule-based checks, statistical anomaly detection, model-based state estimation, or a machine-learning predictor trained on historical examples of normal behavior. By operating on data streams that the primary logic scheme cannot access or modify, the method 300 may provide an untampered basis for safety assessment.
[0088] In the course of this evaluation, the one or more processors may compare current and predicted system states (e.g., joint velocities, actuator torques, spatial trajectories, human-robot separation distances, or environmental conditions) against predefined safety criteria. An “unsafe condition” may be detected whenever a measured or forecast parameter exceeds, falls below, or otherwise departs from an allowable range within a designated time horizon. In somePage 22 of 374917-8318-7546.1Atty. Dkt. No. 141680-0105 embodiments, detection of such a condition may trigger the subsequent decision and intervention steps described below.
[0089] At step 330, one or more processors may activate an intervention device to override or inhibit operation of the apparatus irrespective of commands from the primary logic scheme. In some embodiments, after confirming that the unsafe condition has not been resolved within a permitted latency window (or that the apparatus has ignored or overridden the earlier corrective command), the one or more processors that execute the secondary logic scheme transmit an authenticated override signal to an intervention device associated with the apparatus. The signal may be transmitted through a communication path that is cryptographically authenticated and physically separate from any channel used by the primary logic scheme, thereby preventing interception or tampering by the apparatus’s native controller.
[0090] The intervention device, which may maintain its own dedicated or fail-safe power source, may be caused to enter into an active state designed to inhibit or halt the apparatus regardless of any contemporaneous command issued by the primary logic scheme. Depending on the embodiment, this may entail opening a power-cut relay in the actuator supply, driving a solenoid that inserts a mechanical lock into a joint, energizing an electromagnetic brake, shutting down the apparatus’s control network, or dispatching a peer robot to block the apparatus’s path. Because the intervention pathway may be insulated across logic, sensor, communication, and power domains, the apparatus cannot veto, delay, or subvert the override, ensuring that safety is preserved under all operating conditions.
[0091] FIG. 4 is a flow diagram 400 illustrating a non-limiting example method executed by one or more processors configured to implement a secondary logic scheme for supervising an apparatus. Although the blocks are presented sequentially, they may be reordered, combined, or executed in parallel. The non-limiting example is described with reference to a real-world scenario in which an autonomous pallet-moving robot operates in a warehouse aisle while human workers stock shelves; identical principles apply to any autonomous, semi-autonomous, or human-operated apparatus. Through the depicted steps the processors associated with the secondary logic scheme detect an emerging hazard, attempt a cooperative correction, and, if necessary, override the processors associated with the primary logic scheme to maintain safety, thereby protecting workers and property even when the primary controller malfunctions or behaves maliciously.
[0092] At step 402, one or more processors configured to implement the secondary logic scheme may continuously ingest operational telemetry from the robot (e.g., wheel velocities, motor currents, battery voltage, and internal diagnostic flags) together with environmental dataPage 23 of 374917-8318-7546.1Atty. Dkt. No. 141680-0105 from overhead depth cameras and wearable Bluetooth beacons carried by workers. The data channels may be isolated such that processors configured to implement the primary logic scheme cannot alter, delay, or suppress the streams delivered to the monitoring processors.
[0093] As depicted in the step 404, at periodic intervals (e.g., 100 ms) the monitoring processors may obtain a snapshot of the most recent motion command generated by the processors configured to implement the primary logic scheme; in the present non-limiting example the snapshot may indicate “proceed forward 1.5 m at 1.2 m / s.” This information can enable accurate prediction of the robot’s near-term trajectory without influencing the native planner.
[0094] At step 406, using rule-based thresholds and a trained anomaly-detection model, the monitoring processors may fuse the telemetry and command snapshot to determine whether the projected path violates any safety rule (e.g., maximum aisle speed of 1.0 m / s when a human beacon is within 2 m, lateral clearance from shelving, or torque signatures indicating a stuck wheel).
[0095] At step 408, a worker steps into the aisle, reducing the predicted separation distance below the 2-m limit; therefore the decision evaluates to “Yes” and the method proceeds to step 412 (issue corrective command to primary logic scheme). The monitoring processors may transmit an authenticated command — “slow to 0.3 m / s” — to the processors implementing the primary logic scheme, requesting voluntary compliance within 150 ms. If the processors determine that the conditions are safe, then they proceed to end the process or go back to the step 402 and continue monitoring to acquire operational telemetry data.
[0096] At step 414, the processors may monitor and verify the compliance. In this non-limiting example, the feedback reveals that wheel speed remains above 0.8 m / s after the latency window. Because the robot has not slowed, non-compliance is confirmed and flow proceeds to step 418 (Activate Intervention Device). The monitoring processors may energize an independently powered intervention device: a solid-state relay opens the motor circuit and a spring-loaded brake clamps the drive shaft, stopping the robot within 30 cm. The override signal travels over an encrypted channel inaccessible to the primary-logic processors.
[0097] Optionally, at the step 420 (Record and Propagate Event), the monitoring processors may hash the pre-event telemetry, corrective commands, and intervention results, then write the record to a tamper-resistant ledger shared with safety controllers at other warehouse sites. Updated risk parameters that tighten human-proximity thresholds are distributed fleet-wide, ensuring similar robots elsewhere slow earlier when worker beacons are detected.Page 24 of 374917-8318-7546.1Atty. Dkt. No. 141680-0105
[0098] At step 422, the processors may resume monitoring. Once the robot is motionless and a safety operator acknowledges the event, the intervention device may be reset and the process returns to continuous monitoring at block 402.
[0099] In some embodiments, if the warehouse management system places the robot in maintenance mode, the loop can exit at node 410; otherwise, method 400 repeats itself.
[0100] FIG. 5 is a component diagram of an example computing system 500 suitable for use in the various implementations described herein, according to an example embodiment. One or more steps of the methods and processes discussed herein can be performed by the computing system 500 depicted in FIG. 5. The computing system 500 includes a bus 502 or other communication component for communicating information and a processor 504 coupled to the bus 502 for processing information. The computing system 500 also includes main memory 506, such as a RAM or other dynamic storage device, coupled to the bus 502 for storing information, and instructions to be executed by the processor 504. Main memory 506 can also be used for storing position information, temporary variables, or other intermediate information during the execution of instructions by the processor 504. The computing system 500 may further include a ROM 508 or other static storage device coupled to the bus 502 for storing static information and instructions for the processor 504. A storage device 505, such as a solid- state device, magnetic disk, or optical disk, is coupled to the bus 502 for persistently storing information and instructions.
[0101] The computing system 500 may be coupled via the bus 502 to a display 514, such as a liquid crystal display, or active-matrix display, for displaying information to a user. An input device 512, such as a keyboard containing alphanumeric and other keys, may be coupled to the bus 502 for communicating information, and command selections to the processor 504. In another implementation, the input device 512 has a touchscreen display. The input device 512 can include any type of biometric sensor, or a cursor control, such as a mouse, a trackball, or cursor direction keys, for communicating direction information and command selections to the processor 504 and for controlling cursor movement on the display 514.
[0102] In some implementations, the computing system 500 may include a communications adapter 516, such as a networking adapter. Communications adapter 516 may be coupled to bus 502 and may be configured to enable communications with a computing or communications network or other computing systems. In various illustrative implementations, any type of networking configuration may be achieved using communications adapter 516, such as wired (e.g., via Ethernet), wireless (e.g., via Wi-Fi, Bluetooth), satellite (e.g., via GPS) pre-configured, ad-hoc, LAN, WAN, and the like.Page 25 of 374917-8318-7546.1Atty. Dkt. No. 141680-0105
[0103] The above-described embodiments of the present disclosure are presented for purposes of illustration and not of limitation, and the present disclosure is limited only by the claims which follow. Furthermore, it should be noted that the features and limitations described in any embodiment may be applied to one or more other embodiments herein, and flowcharts or examples relating to one embodiment may be combined with any other embodiment in a suitable manner, done in different orders, or done in parallel. In addition, the systems and methods described herein may be performed in real time. It should also be noted that the systems and / or methods described above may be applied to, or used in accordance with, other systems and / or methods. Furthermore, not all operations of a flowchart need to be performed. In addition, the systems and methods described herein may be performed in real time. It should also be noted that the systems and / or methods described above may be applied to, or used in accordance with, other systems and / or methods.
[0104] Furthermore, the computing devices described in this disclosure may be any type of computing device unless otherwise stated, including, but not limited to, a laptop computer, a tablet computer, a hand-held computer, and / or other computing equipment (e.g., a server), including “smart,” wireless, wearable, and / or mobile devices. For example, the electronic device 108 of FIG. 1 may be a smartphone, another type of mobile computing device, or a payment terminal. Furthermore, the embodiments described in this disclosure may include an individual device that performs some or all the operations described in this disclosure. Alternatively, other embodiments may include multiple computing devices acting collectively to perform some or all the operations described in this disclosure.
[0105] As used in the specification and in the claims, the singular forms of “a,” “an,” and “the” include plural referents unless the context clearly dictates otherwise. In addition, as used in the specification and the claims, the term “or” means “and / or” unless the context clearly dictates otherwise. Additionally, as used in the specification, “a portion” refers to a part of, or the entirety (i.e., the entire portion), of a given item (e.g., data) unless the context clearly dictates otherwise. Furthermore, a “set” may refer to a singular form or a plural form, such that a “set of items” may refer to one item or a plurality of items.
[0106] In some embodiments, the operations described in this disclosure may be implemented in a set of processing devices (e.g., a digital processor, an analog processor, a digital circuit designed to process information, an analog circuit designed to process information, a state machine, and / or other mechanisms for electronically processing information). The processing devices may include one or more devices executing some or all of the operations of the methods in response to instructions stored electronically on one or more non-transitory, machine-Page 26 of 374917-8318-7546.1Atty. Dkt. No. 141680-0105 readable media (e.g., a set of machine-readable storage media), such as an electronic storage medium. Furthermore, the use of the term “media” may include a single medium or combination of multiple media, such as a first medium and a second medium. A set of non- transitory, machine-readable media storing instructions may include instructions included on a single medium or instructions distributed across multiple media. The processing devices may include one or more devices configured through hardware, firmware, and / or software to be specifically designed for the execution of one or more of the operations of the methods.
[0107] In some embodiments, the various computer systems and subsystems illustrated herein may include one or more computing devices that are programmed to perform the functions described herein. The computing devices may include one or more electronic storages (e.g., a set of databases accessible to one or more applications depicted in the system 100), one or more physical processors programmed with one or more computer program instructions, and / or other components. For example, the set of databases may include a relational database such as a PostgreSQL™ database or MySQL database. Alternatively, or additionally, the set of databases or other electronic storage used in this disclosure may include a non-relational database, such as a Cassandra™ database, MongoDB™ database, Redis database, Neo4j™ database, Amazon Neptune™ database, etc.
[0108] The computing devices may include communication lines or ports to enable the exchange of information with a set of networks (e.g., a network used by the system 100) or other computing platforms via wired or wireless techniques. The network may include the internet, a mobile phone network, a mobile voice or data network (e.g., a 5G or Long-Term Evolution (LTE) network), a cable network, a public switched telephone network, or other types of communication networks or combination of communication networks. A network described by devices or systems described in this disclosure may include one or more communications paths, such as Ethernet, a satellite path, a fiber-optic path, a cable path, a path that supports internet communications (e.g., IPTV), free-space connections (e.g., for broadcast or other wireless signals), Wi-Fi, Bluetooth, near field communication, or any other suitable wired or wireless communications path or combination of such paths. The computing devices may include additional communication paths linking a plurality of hardware, software, and / or firmware components operating together. For example, the computing devices may be implemented by a cloud of computing platforms operating together as the computing devices.
[0109] Each of these devices described in this disclosure may also include electronic storages. The electronic storages may include non-transitory storage media that electronically stores information. The storage media of the electronic storages may include one or both of (i) systemPage 27 of 374917-8318-7546.1Atty. Dkt. No. 141680-0105 storage that is provided integrally (e.g., substantially non-removable) with servers or client computing devices, or (ii) removable storage that is removably connectable to the servers or client computing devices via port (e.g., a USB port, a firewire port, etc.) or drive (e.g., a disk drive, etc.). The electronic storages may include one or more of optically readable storage media (e.g., optical disks, etc.), magnetically readable storage media (e.g., magnetic tape, magnetic hard drive, floppy drive, etc.), electrical charge-based storage media (e.g., EEPROM, RAM, etc.), solid-state storage media (e.g., flash drive, etc.), and / or other electronically readable storage media. The electronic storages may include one or more virtual storage resources (e.g., cloud storage, a virtual private network, and / or other virtual storage resources). An electronic storage may store software algorithms, information determined by the processors, information obtained from servers, information obtained from client computing devices, or other information that enables the functionality as described herein.
[0110] The processors may be programmed to provide information processing capabilities in the computing devices. As such, the processors may include one or more of a digital processor, an analog processor, a digital circuit designed to process information, an analog circuit designed to process information, a state machine, and / or other mechanisms for electronically processing information. In some embodiments, the processors may include a plurality of processing units. These processing units may be physically located within the same device, or the processors may represent the processing functionality of a plurality of devices operating in coordination. The processors may be programmed to execute computer program instructions to perform functions described herein of subsystems described in this disclosure or other subsystems. The processors may be programmed to execute computer program instructions by software; hardware; firmware; some combination of software, hardware, or firmware; and / or other mechanisms for configuring processing capabilities on the processors.
[0111] It should be appreciated that the description of the functionality provided by the different subsystems described herein is for illustrative purposes, and is not intended to be limiting, as any of the subsystems described in this disclosure may provide more or less functionality than is described. For example, one or more of subsystems described in this disclosure may be eliminated, and some or all of its functionality may be provided by other ones of subsystems described in this disclosure. As another example, additional subsystems may be programmed to perform some or all of the functionality attributed herein to one of the subsystems described in this disclosure.
[0112] With respect to the components of computing devices described in this disclosure, each of these devices may receive content and data via input / output (I / O) paths. Each of thesePage 28 of 374917-8318-7546.1Atty. Dkt. No. 141680-0105 devices may also include processors and / or control circuitry to send and receive commands, requests, and other suitable data using the I / O paths. The control circuitry may comprise any suitable processing, storage, and / or I / O circuitry. Further, some or all of the computing devices described in this disclosure may include a user input interface and / or user output interface (e.g., a display) for use in receiving and displaying data. In some embodiments, a display such as a touchscreen may also act as a user input interface. It should be noted that in some embodiments, one or more devices described in this disclosure may have neither user input interface nor displays and may instead receive and display content using another device (e.g., a dedicated display device such as a computer screen and / or a dedicated input device such as a remote control, mouse, voice input, etc.). Additionally, one or more of the devices described in this disclosure may run an application (or another suitable program) that performs one or more operations described in this disclosure.
[0113] Although the present invention has been described in detail for the purpose of illustration based on what is currently considered to be the most practical and preferred embodiments, it is to be understood that such detail is solely for that purpose and that the invention is not limited to the disclosed embodiments but, on the contrary, is intended to cover modifications and equivalent arrangements that are within the scope of the appended claims. For example, it is to be understood that the present invention contemplates that, to the extent possible, one or more features of any embodiment may be combined with one or more features of any other embodiment.
[0114] As used throughout this application, the word “may” is used in a permissive sense (i.e., meaning having the potential to), rather than a mandatory sense (i.e., meaning must). The words “include,” “including,” “includes,” and the like mean including, but not limited to. As used throughout this application, the singular forms “a,” “an,” and “the” include plural referents unless the context clearly indicates otherwise. Thus, for example, reference to “an element” or “the element” includes a combination of two or more elements, notwithstanding the use of other terms and phrases for one or more elements, such as “one or more.” The term “or” is nonexclusive (i.e., encompassing both “and” and “or”), unless the context clearly indicates otherwise. Terms describing conditional relationships (e.g., “in response to X, Y,” “upon X, Y,” “if X, Y,” “when X, Y,” and the like) encompass causal relationships in which the antecedent is a necessary causal condition, the antecedent is a sufficient causal condition, or the antecedent is a contributory causal condition of the consequent (e.g., “state X occurs upon condition Y obtaining” is generic to “X occurs solely upon Y” and “X occurs upon Y and Z”). Such conditional relationships are not limited to consequences that instantly follow thePage 29 of 374917-8318-7546.1Atty. Dkt. No. 141680-0105 antecedent obtaining, as some consequences may be delayed, and in conditional statements, antecedents are connected to their consequents (e.g., the antecedent is relevant to the likelihood of the consequent occurring). Statements in which a plurality of attributes or functions are mapped to a plurality of objects (e.g., a set of processors performing steps / operations A, B, C, and D) encompass all such attributes or functions being mapped to all such objects and subsets of the attributes or functions being mapped to subsets of the attributes or functions (e.g., both / all processors each performing steps / operations A-D, and a case in which processor 1 performs step / operation A, processor 2 performs step / operation B and part of step / operation C, and processor 3 performs part of step / operation C and step / operation D), unless otherwise indicated. Further, unless otherwise indicated, statements that one value or action is “based on” another condition or value encompass both instances in which the condition or value is the sole factor and instances in which the condition or value is one factor among a plurality of factors.
[0115] Unless the context clearly indicates otherwise, statements that “each” instance of some collection has some property should not be read to exclude cases where some otherwise identical or similar members of a larger collection do not have the property (i.e., each does not necessarily mean each and every). Limitations as to the sequence of recited steps should not be read into the claims unless explicitly specified (e.g., with explicit language like “after performing X, performing Y”) in contrast to statements that might be improperly argued to imply sequence limitations (e.g., “performing X on items, performing Y on the X’ed items”) used for purposes of making claims more readable rather than specifying a sequence. Statements referring to “at least Z of A, B, and C,” and the like (e.g., “at least Z of A, B, or C”), refer to at least Z of the listed categories (A, B, and C) and do not require at least Z units in each category. Unless the context clearly indicates otherwise, it is appreciated that throughout this specification discussions utilizing terms such as “processing,” “computing,” “calculating,” “determining,” or the like refer to actions or processes of a specific apparatus, such as a special purpose computer or a similar special purpose electronic processing / computing device. Furthermore, unless indicated otherwise, updating an item may include generating the item or modifying an existing item. Thus, updating a record may include generating a record or modifying the value of an already-generated value in a record. Additionally, as used in the specification, “a portion” refers to a part of, or the entirety of (i.e., the entire portion), a given item (e.g., data) unless the context clearly dictates otherwise.
[0116] Unless the context clearly indicates otherwise, ordinal numbers used to denote an item do not define the item’ s position. For example, an item that may be a first item of a set of items even if the item is not the first item to have been added to the set of items or is otherwisePage 30 of 374917-8318-7546.1Atty. Dkt. No. 141680-0105 indicated to be listed as the first item of an ordering of the set of items. Thus, for example, if a set of items is sorted in a sequence from “item 1,” “item 2,” and “item 3,” a first item of a set of items may be “item 2” unless otherwise stated.
[0117] Clause 1. A system for ensuring safe operation of an apparatus, comprising: a primary logic scheme configured to control the apparatus in performing operational tasks; a secondary logic scheme configured to independently monitor the apparatus and detect an unsafe condition relative to one or more safety parameters; and one or more intervention devices operatively connected to the apparatus and configured to override or inhibit commands from the primary logic scheme in response to detection of the unsafe condition by the secondary logic scheme, wherein the secondary logic scheme operates independently of the primary logic scheme with respect to at least one of logic framework, sensor inputs, power supply, or communication channel.
[0118] Clause 2. The system of clause 1, wherein the unsafe condition is defined relative to markers selected from the group consisting of static markers, dynamic markers, and contextual markers.
[0119] Clause 3. The system of clause 2, wherein the markers comprise wearable beacons carried by humans to define moving safety zones.
[0120] Clause 4. The system of clause 2, wherein the markers comprise contextual markers whose state changes to reflect operational conditions.
[0121] Clause 5. The system of clause 1, wherein the intervention device comprises at least one of an electrical interlock, a mechanical lock, an electromagnetic brake, a network-level override, sensor input modification, or a peer apparatus configured to physically inhibit motion of the apparatus.
[0122] Clause 6. The system of clause 1, wherein the secondary logic scheme employs machine learning to forecast traj ectories of the apparatus or a human and to intervene prior to occurrence of the unsafe condition.
[0123] Clause 7. The system of clause 1, wherein the communication between the secondary logic scheme and the intervention devices is encrypted and isolated from the primary logic scheme.
[0124] Clause 8. The system of clause 1, wherein the intervention devices are powered by a power supply independent of the primary logic scheme.
[0125] Clause 9. The system of clause 1, wherein loss of communication between the primary and secondary logic schemes triggers automatic activation of an intervention device.Page 31 of 374917-8318-7546.1Atty. Dkt. No. 141680-0105
[0126] Clause 10. The system of clause 1, wherein the secondary logic scheme generates dynamic safety zones that expand, contract, or move in response to human movement detected by independent sensors.
[0127] Clause 11. The system of clause 1, wherein the secondary logic scheme comprises an edge node co-located with the apparatus and a cloud-based supervisory node configured to aggregate fleet-wide safety data.
[0128] Clause 12. A system for monitoring a plurality of apparatus, comprising: a plurality of apparatus, each comprising a primary logic scheme configured to perform operational tasks; a central supervisory system comprising a secondary logic scheme configured to receive operational data from the plurality of apparatus, detect an unsafe condition involving one or more of the apparatus, and generate a safety intervention signal; and a communication network configured to transmit the safety intervention signal to the one or more apparatus to override or inhibit commands from the respective primary logic schemes, wherein the secondary logic scheme is further configured to update one or more safety parameters for the plurality of apparatus based on unsafe conditions detected from any individual apparatus.
[0129] Clause 13. The system of clause 12, wherein the secondary logic scheme employs federated learning to update safety parameters across the plurality of apparatus based on unsafe conditions detected at multiple sites.
[0130] Clause 14. The system of clause 12, wherein the plurality of apparatus includes at least one humanoid robot and at least one human-operated machine.
[0131] Clause 15. The system of clause 12, wherein the central supervisory system coordinates multiple apparatus to collectively mitigate the unsafe condition by forming a barrier or cordon around a hazard.
[0132] Clause 16. A method of controlling an apparatus to ensure safety, comprising: monitoring, via a secondary logic scheme independent of a primary logic scheme, operational data of the apparatus and environmental data from one or more sensors; detecting an unsafe condition based on the monitored operational data or environmental data; and activating an intervention device to override or inhibit operation of the apparatus irrespective of commands from the primary logic scheme.
[0133] Clause 17. The method of clause 16, further comprising transmitting data from the secondary logic scheme to a fleet-level supervisory system to update safety parameters across multiple apparatus.
[0134] Clause 18. The method of clause 16, wherein detecting the unsafe condition comprises identifying an anomaly relative to a learned normal operating pattern of the apparatus.Page 32 of 374917-8318-7546.1Atty. Dkt. No. 141680-0105
[0135] Clause 19. The method of clause 16, wherein activating the intervention device comprises physically immobilizing a joint, halting propulsion, or disabling a manipulator of the apparatus.
[0136] Clause 20. The method of clause 16, wherein the apparatus is a human-operated vehicle and detecting the unsafe condition comprises detecting operation of the vehicle in violation of a safety parameter.Page 33 of 374917-8318-7546.1
Claims
Atty. Dkt. No. 141680-0105CLAIMSWhat is claimed is:
1. A system for ensuring safe operation of an apparatus, comprising: a primary logic scheme configured to control the apparatus in performing operational tasks; a secondary logic scheme configured to independently monitor the apparatus and detect an unsafe condition relative to one or more safety parameters; and one or more intervention devices operatively connected to the apparatus and configured to override or inhibit commands from the primary logic scheme in response to detection of the unsafe condition by the secondary logic scheme, wherein the secondary logic scheme operates independently of the primary logic scheme with respect to at least one of: logic framework, sensor inputs, power supply, or communication channel.
2. The system of claim 1, wherein the unsafe condition is defined relative to markers selected from the group consisting of static markers, dynamic markers, and contextual markers.
3. The system of claim 2, wherein the markers comprise wearable beacons carried by humans to define moving safety zones.
4. The system of claim 2, wherein the markers comprise contextual markers whose state changes to reflect operational conditions.
5. The system of claim 1, wherein the intervention device comprises at least one of: an electrical interlock, a mechanical lock, an electromagnetic brake, a network-level override, sensor input modification, or a peer apparatus configured to physically inhibit motion of the apparatus.
6. The system of claim 1, wherein the secondary logic scheme employs machine learning to forecast trajectories of the apparatus or a human and to intervene prior to occurrence of the unsafe condition.
7. The system of claim 1, wherein the communication between the secondary logic scheme and the intervention devices is encrypted and isolated from the primary logic scheme.Page 34 of 374917-8318-7546.1Atty. Dkt. No. 141680-01058. The system of claim 1, wherein the intervention devices are powered by a power supply independent of the primary logic scheme.
9. The system of claim 1, wherein loss of communication between the primary and secondary logic schemes triggers automatic activation of an intervention device.
10. The system of claim 1, wherein the secondary logic scheme generates dynamic safety zones that expand, contract, or move in response to human movement detected by independent sensors.
11. The system of claim 1, wherein the secondary logic scheme comprises an edge node co-located with the apparatus and a cloud-based supervisory node configured to aggregate fleet-wide safety data.
12. A system for monitoring a plurality of apparatus, comprising: a plurality of apparatus, each comprising a primary logic scheme configured to perform operational tasks; a central supervisory system comprising a secondary logic scheme configured to receive operational data from the plurality of apparatus, detect an unsafe condition involving one or more of the apparatus, and generate a safety intervention signal; and a communication network configured to transmit the safety intervention signal to the one or more apparatus to override or inhibit commands from the respective primary logic schemes, wherein the secondary logic scheme is further configured to update one or more safety parameters for the plurality of apparatus based on unsafe conditions detected from any individual apparatus.
13. The system of claim 12, wherein the secondary logic scheme employs federated learning to update safety parameters across the plurality of apparatus based on unsafe conditions detected at multiple sites.
14. The system of claim 12, wherein the plurality of apparatus includes at least one humanoid robot and at least one human-operated machine.Page 35 of 374917-8318-7546.1Atty. Dkt. No. 141680-010515. The system of claim 12, wherein the central supervisory system coordinates multiple apparatus to collectively mitigate the unsafe condition by forming a barrier or cordon around a hazard.
16. A method of controlling an apparatus to ensure safety, comprising: monitoring, via a secondary logic scheme independent of a primary logic scheme, operational data of the apparatus and environmental data from one or more sensors; detecting an unsafe condition based on the monitored operational data or environmental data; and activating an intervention device to override or inhibit operation of the apparatus irrespective of commands from the primary logic scheme.
17. The method of claim 16, further comprising transmitting data from the secondary logic scheme to a fleet-level supervisory system to update safety parameters across multiple apparatus.
18. The method of claim 16, wherein detecting the unsafe condition comprises identifying an anomaly relative to a learned normal operating pattern of the apparatus.
19. The method of claim 16, wherein activating the intervention device comprises physically immobilizing a joint, halting propulsion, or disabling a manipulator of the apparatus.
20. The method of claim 16, wherein the apparatus is a human-operated vehicle and detecting the unsafe condition comprises detecting operation of the vehicle in violation of a safety parameter.Page 36 of 374917-8318-7546.1
Citation Information
Patent Citations
Automated Threat Detection and Deterrence Apparatus
US20230417919A1