一次演讲:从自动驾驶 SOTIF 到 Robot SOTIF · RoboSec 2026 — 用 25 分钟把「为什么没撞仍不安全」走成一条可审查的证据链,并从智能汽车安全扩展到移动物理 AI 安全的双支柱全景: 汽车侧的安全内核与三大领域,具身侧的母体重构、标准组合拳与新增威胁面,最后落到跨本体类人测评与 Safety Case。 想先看总览,从这里开始:打开演讲材料(全景版)→ 上一版 25 页保留在 原链接。

A talk: From Automated Driving SOTIF to Robot SOTIF · RoboSec 2026 — a 25-minute path from “why no collision is not yet safe” to an auditable evidence chain, extended into a two-pillar panorama from intelligent-vehicle safety to mobile physical AI safety: the automotive safety core, the rebuilt standards parentage for embodied systems, and cross-embodiment human-like evaluation. Start here for the overview: Open the talk (full panorama) → The earlier 25-slide version stays at the original link.

这个专题为什么现在做 Why This Topic Matters Now

我一直认为,机器人安全不能只沿着传统机械安全、工业机器人防护栏、协作机器人限力这些路径继续外推。 当机器人具备移动能力、开放环境感知能力、自然语言任务理解能力和跨场景泛化能力以后,真正困难的问题不再只是故障, 而是功能本身在合理使用、可预见误用和复杂环境下是否仍然安全。

Robot safety cannot simply be extrapolated from traditional machinery safety, fenced industrial robots, or force-limited collaborative operation. Once a robot becomes mobile, perceives open environments, interprets natural-language tasks, and generalizes across scenarios, the difficult question is no longer only component failure. It is whether the intended function remains safe under reasonable use, foreseeable misuse, and complex operating conditions.

这正是 SOTIF 的问题域。ISO 21448 最初服务于道路车辆语境,GB/T 43267 也把“预期功能安全”引入了中国智能网联汽车标准体系。 但今天的具身智能和通用移动物理 AI,已经把这个问题推到了机器人领域。

That is precisely the domain of SOTIF. ISO 21448 was developed in the road-vehicle context, and GB/T 43267 introduced safety of the intended functionality into China’s intelligent and connected vehicle standards system. Today, embodied intelligence and general-purpose mobile physical AI are pushing the same question into robotics.

如果一个机器人没有零部件故障,AI 也没有“恶意”,但它在某个任务、用户、空间、地面、光照、障碍物或交互语境下做出了危险行为, 这不是传统故障安全可以完全覆盖的问题。它更接近机器人版 SOTIF。

If a robot has no component fault and the AI is not “malicious,” yet it behaves dangerously because of a task, user, space, floor condition, lighting state, obstacle, or interaction context, traditional fault safety does not fully cover the problem. This is closer to Robot SOTIF.

我看到的三个信号 Three Signals I Am Watching

01 · Standard Signal

强制性国家标准拟立项,说明监管层已经意识到通用移动物理 AI 的公共安全属性。

A proposed mandatory national standard shows that regulators now recognize the public-safety nature of general-purpose mobile physical AI.

02 · Method Signal

ISO 21448、ISO/PAS 8800、ISO 34502 等方法论正在从汽车延展到 AI 系统与场景工程。

Methodologies from ISO 21448, ISO/PAS 8800, and ISO 34502 are extending from vehicles into AI systems and scenario engineering.

03 · Data Signal

机器人安全评价需要真实场景数据、接近/接触/避让行为数据,以及运行时边界证据。

Robot safety evaluation needs real-world scenario data, approach/contact/avoidance behavior data, and runtime boundary evidence.

我建议把开放问题拆成三条线索 A Three-Track Research Decomposition

与移动物理 AI 测评平台的关系 Connection to Mobile Physical AI Evaluation

如果未来要真正评价通用移动物理 AI,不能只做演示视频、Benchmark 排名或单点任务成功率。 更关键的是建立一套可复现的场景库、行为触发条件、风险量化指标和证据链。

Evaluating general-purpose mobile physical AI cannot stop at demo videos, benchmark rankings, or single-task success rates. The core need is a reproducible system of scenario libraries, behavioral trigger conditions, risk metrics, and evidence chains.

这也是我把这个专题放在 OpenTopic 里的原因:它不应该只是某个实验室、某家公司或某个标准工作组的闭门问题。 机器人 SOTIF 需要开放讨论、公开案例、可复用场景和跨行业语言。

This is why I place the topic in OpenTopic. It should not remain a closed issue inside one laboratory, one company, or one standards group. Robot SOTIF needs open discussion, public cases, reusable scenarios, and a shared cross-industry language.

研究人员可以从哪里继续做 Where Researchers Can Start