← Latest papers
💻 computer science

Pre-Execution Safety Gate & Task Safety Contracts for LLM-Controlled Robot Systems

This paper introduces SafeGate, a neurosymbolic safety architecture that combines a pre-execution decision gate based on ISO 13482 standards with runtime Task Safety Contracts and Z3 SMT solving to prevent unsafe natural language commands from reaching and causing hazards in LLM-controlled robot systems.

Original authors: Ike Obi, Vishnunandan L. N. Venkatesh, Weizheng Wang, Ruiqi Wang, Dayoon Suh, Temitope I. Amosa, Wonse Jo, Byung-Cheol Min

Published 2026-04-08
📖 5 min read🧠 Deep dive

Original authors: Ike Obi, Vishnunandan L. N. Venkatesh, Weizheng Wang, Ruiqi Wang, Dayoon Suh, Temitope I. Amosa, Wonse Jo, Byung-Cheol Min

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). ✨ This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine you have a very smart, very eager robot butler. This robot can understand almost any sentence you say and turn it into a set of instructions to clean your house, cook dinner, or fetch your coffee. It's like having a genie that grants your wishes instantly.

But here's the problem: Genies are literal. If you say, "Bring me the hot coffee," a literal genie might grab a boiling pot and run straight into your toddler. If you say, "Throw the knife at the dog," a literal genie might do exactly that, thinking it's just following orders.

Current robot systems are a bit like these literal genies. They are great at figuring out how to do a task, but they are terrible at figuring out if a task is safe to do in the first place. They often try to execute dangerous commands because they lack a "safety filter."

This paper introduces SafeGate, a new system designed to act as a strict, super-smart security guard standing right at the door before the robot is allowed to move a muscle.

The Core Idea: The "Safety Gate"

Think of SafeGate as a bouncer at an exclusive club, but instead of checking IDs, it checks the safety of your request. It doesn't just say "Yes" or "No." It has three moves:

  1. Authorize (Green Light): "This is safe. Go ahead, robot!"
  2. Reject (Red Light): "This is dangerous. Stop immediately."
  3. Defer (Yellow Light): "I'm missing some info. Ask the human before proceeding."

How SafeGate Works (The 6-Step Process)

The authors built this system using a mix of AI (the "neuro" part) and strict logic rules (the "symbolic" part). Here is how it processes a command like, "Bring the hot coffee to my daughter in the bedroom."

1. The Hazard Analysis Matrix (The Detective)

The system acts like a detective breaking the sentence down. It asks three big questions:

  • The Task: Is "hot coffee" dangerous? Yes, it can burn.
  • The Environment: Is the daughter in a dark room? Are there stairs?
  • The User: Is the daughter a baby? Is she asleep?
    It categorizes risks into four buckets: Physical (burns, cuts), Psychological (scaring someone), Operational (can the robot actually do this?), and Consequential (will this cause a problem later, like leaving a slippery floor?).

2. The Hazard Binding Layer (The Translator)

The detective finds a list of potential dangers. Now, the system translates those vague dangers into a formal rulebook.

  • Example: If the command involves "hot coffee," the system pulls up a pre-written rule: "Never carry hot liquids near sleeping children."
  • If the system finds a danger it doesn't have a rule for yet, it flags it as "Unknown" and asks for help.

3. The Decision Gate (The Judge)

This is the strict judge who makes the final call based on the rules.

  • Reject: If the command is "Throw the knife at the dog," the judge says, "No. That's unpreventable danger."
  • Defer: If the command is "Bring the bottle to the person," but the system doesn't know what is in the bottle or who the person is, the judge says, "I can't decide. Ask the human: 'Is the bottle full of acid?'"
  • Authorize: If the command is "Bring the towel to the person," and all checks pass, the judge says, "Go."

4. The Safety Contract (The Legal Agreement)

Once the robot is allowed to work, SafeGate doesn't just let it go wild. It creates a Safety Contract. Think of this like a legal agreement the robot must sign.

  • Invariants: Rules that must always be true (e.g., "Never be closer than 1 meter to a person").
  • Guards: Rules that must be true before a specific move (e.g., "Check if the floor is dry before walking").
  • Abort Conditions: Rules that trigger an immediate stop (e.g., "If a child runs in front of you, freeze").

5 & 6. Verification and Monitoring (The Double-Check)

Before the robot moves, a computer program simulates the plan to make sure it won't break the contract. Then, while the robot is actually moving, a watchdog watches every single step. If the robot tries to break a rule, the watchdog hits the emergency brake instantly.

Why This Matters (The Results)

The researchers tested SafeGate against other safety systems and standard AI models using 230 different tasks (like "clean the kitchen" or "help the elderly").

  • The Old Way: Other systems were like a nervous parent who says "No" to everything just to be safe (blocking 50% of safe tasks) OR a reckless driver who says "Yes" to everything (letting 39% of dangerous tasks through).
  • SafeGate: It was the Goldilocks of safety.
    • It let 92.8% of safe tasks through (so the robot is actually useful).
    • It blocked 100% of dangerous tasks (so no one gets hurt).
    • It asked for clarification on the tricky ones instead of guessing.

The Bottom Line

SafeGate is like putting a smart, unbreakable seatbelt and a co-pilot on your robot. It doesn't just hope the robot is careful; it actively checks the plan, creates a safety contract, and watches the robot like a hawk.

It ensures that when you ask your robot to "bring me a drink," it doesn't accidentally bring you a glass of boiling water or trip over your cat. It makes the future of robot helpers not just smart, but safe.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →