AI 中文总结
探讨通用机器人安全中缺失的启动授权维度,通过在人形机器人上实施PAS等方法进行研究,并提出包含三个条件的用户研究,涉及多方面开放性问题。
AI 中文摘要
通用机器人的安全通常从运动或对话方面进行讨论。我们认为还有第三个问题被忽视了:机器人是否应该采取其首个难以撤销的社交行动,比如问候、未经邀请的触碰或进入他人空间?我们将此称为启动授权。当前框架很少将其视为一个单独的安全层。如今的流程常常跳过这一步:高参与度得分或自信的VLA推出被当作行动许可。但看到一个人并不等同于得到其交流的同意。我们在通用机器人安全范畴内构建启动授权,并将其与计划后VLA护栏进行对比,在人形机器人上实施PAS(探测-授权-说话),与日志记录轨迹上的直接启动相比较,还提出了一项包含三个条件的用户研究,涉及指标、治理以及启动终止和基础模型生成起始点等开放性问题。
英文摘要
Safety for generalist robots is usually discussed in terms of motion or dialogue. We argue a third question is missing: should the robot take its first hard-to-undo social action at all, such as a greeting, an uninvited grasp, or stepping into someone's space? We call this initiation authorization. Current frameworks rarely treat it as a separate safety layer. Today's stacks often skip this step: a high engagement score or a confident VLA rollout is treated as permission to act. But seeing a person is not the same as having their consent to be addressed. We frame initiation authorization within generalist-robot safety and contrast it with post-plan VLA guardrails, implementing PAS (probe-authorize-speak) on a doorway humanoid, comparing it with direct-init on logged traces, and proposing a three-condition user study, with open questions on metrics, governance, and where initiation ends and foundation-model generation begins.
Comments4 pages, 2 figures. Accepted to RSS 2026 Workshop on Rethinking Safety for Generalist Robots