Toward Certified Functional Safety for Industrial Humanoid Robots: The Fail-Passive Gap and a Feasibility Study

📅 2026-08-03
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the challenge that industrial humanoid robots, due to their reliance on active control to maintain safe states, violate the “fail-passive” assumption required by functional safety standards such as ISO 13849-1, thereby hindering certification. The work introduces the novel concept of a “fail-passive gap” and proposes a solution centered on an externally certified safety chain—comprising light curtains, emergency stops, and fail-safe PLCs—validated on the Unitree G1 EDU platform. By integrating a PROFIsafe-compatible safety chain, an IEC 61131-3 interface, and quantitative methods for PFHD, DC, and CCF, alongside a co-deployed architecture of software-defined automation (SDA) and balancing strategies, the study identifies the SDA-to-balancing-strategy interface on the robot side as the critical locus of the gap. Experiments within a 3 m × 1.5 m semi-enclosed cell delineate certification boundaries and establish a humanoid-specific framework for analyzing active safety states, including fall-as-hazard conditions, single-support stopping limits, and residual risk assessment.
📝 Abstract
Industrial humanoid robots are constrained less by locomotion or manipulation capability than by the immaturity of functional safety certification for legged platforms. The root difficulty is that the safe state of a legged robot is an actively-controlled state, which violates the fail-passive assumption underlying ISO~13849-1 / EN~60204-1: removing power from a walking biped causes an uncontrolled fall, so classical de-energization is itself a hazard. We term this the fail-passive gap and use a certified external safety chain (light curtain, emergency stop, fail-safe input, fail-safe PLC, and wireless PROFIsafe) as an instrument to locate it precisely: because the external chain is closed and quantifiable with established methods (PFHD, DC, CCF, PL/SILCL), the residual uncertifiable element is pinpointed to the robot-side reaction chain. Using a Siemens fail-safe S7-1500 emergency-stop reference, we show its certifiable Reaction subsystem is contactor-based power removal (Stop Category~0)---exactly the element a balancing humanoid cannot have. We deliberately do not claim end-to-end certified PL~e / SIL~3. We validate the approach on a Unitree G1 EDU pick-and-place cell in a 3m x 1.5m semi-enclosed workspace, and contribute a humanoid-specific analysis of the active safe state (fall-as-hazard, single-support stop bounds, balancing-policy residual risk, ISO~13855 separation) and a provenance-labeled timing budget. Hosting an industrial software-defined automation (SDA) controller on the robot, co-located with the balancing policy, moves robot-side PROFINET/PROFIsafe reception onto a standardized IEC~61131-3 interface; because the G1's onboard compute is not safety-rated hardware, this endpoint is not a certified safety runtime, which reinforces rather than resolves the fail-passive gap and localizes it to the SDA-to-balancing-policy interface.
Problem

Research questions and friction points this paper is trying to address.

fail-passive gap
functional safety certification
humanoid robots
active safe state
industrial safety standards
Innovation

Methods, ideas, or system contributions that make the work stand out.

fail-passive gap
functional safety certification
humanoid robots
active safe state
PROFIsafe
🔎 Similar Papers
No similar papers found.
C
Caiwu Ding
Siemens Foundational Technologies, Siemens Corporation, Princeton, NJ, USA
Tao Cui
Tao Cui
Siemens
fault detectionprognosticsmachine learningenergy system
L
Lingyun Wang
Siemens Foundational Technologies, Siemens Corporation, Princeton, NJ, USA
C
Chengtao Wen
Siemens Foundational Technologies, Siemens Corporation, Princeton, NJ, USA