发表机构
CISPA Helmholtz Center for Information Security; Technical University of Munich; beanTech(CISPA亥姆霍兹信息安全中心; 慕尼黑工业大学; beanTech)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文提出预测仿射包归约(PZR)方法,将归约器选择转化为最优控制问题,通过波束搜索模型预测控制及策略蒸馏实现高效精确的不确定性运行时监测,在树莓派5上的机械臂实验中显著降低了监测误报率。
AI 中文摘要
在物理环境中运行的机器人基于不确定的传感器测量值做出控制决策,这可能导致不安全或次优的动作。根据安全规范检查机器人行为的运行时监测器必须合理地表示这种不确定性。仿射包(zonotopes)是一种广泛使用的表示形式,但持续融入新测量值会使其阶数无限制增长,因此监测器必须周期性地应用过近似归约。归约方法的选择会显著影响仿射包的精度,然而现有方法通常在整个运行过程中使用固定方法,尽管最优选择取决于当前状态。本文提出一种预测仿射包归约(Predictive Zonotope Reduction, PZR)方法,该方法将归约器选择表述为最优控制问题,并使用波束搜索模型预测控制求解。将策略蒸馏为小型神经策略后,其执行速度远高于模型预测控制,同时保持了改进的性能,使资源受限的实时系统能够实现感知不确定性的运行时监测。我们在RLola运行时监测框架中实现了该方法,并在MuJoCo中模拟的5自由度机械臂上进行评估,传感器不确定性根据ISO 5725建模。在树莓派5(Raspberry Pi 5)上的实验表明,与静态归约策略相比,动态归约显著降低了监测中的误报率。
英文摘要
Robots operating in physical environments make control decisions based on uncertain sensor measurements, which can lead to unsafe or suboptimal actions. Runtime monitors that check their behavior against safety specifications must represent this uncertainty soundly. Zonotopes are a widely used representation, but continuously incorporating new measurements grows their order unboundedly, so monitors must periodically apply an over-approximating reduction. The choice of the reduction method substantially affects the zonotope's precision, yet existing approaches typically utilize a fixed method throughout the run, even though the optimal choice depends on the current state. This paper presents a Predictive Zonotope Reduction (PZR) approach, which frames reducer selection as an optimal control problem and solves it using beam-search model predictive control. Policy distillation into a small neural policy further provides substantially higher execution speed than model predictive control while maintaining improved performance, enabling uncertainty-aware runtime monitoring on resource-constrained real-time systems. We implement our approach in the RLola runtime monitoring framework and evaluate it on a 5-degree-of-freedom robotic arm simulated in MuJoCo, with sensor uncertainty modeled according to ISO 5725. Experiments on a Raspberry Pi 5 show that dynamic reduction significantly lowers false-positive rates in monitoring compared with static reduction strategies.