Towards a balancing safety against performance approach in human–robot co-manipulation for door-closing emergencies

Telemanipulation in power stations commonly require robots first to open doors and then gain access to a new workspace. However, the opened doors can easily close by disturbances, interrupt the operations, and potentially lead to collision damages. Although existing telemanipulation is a highly efficient master–slave work pattern due to human-in-the-loop control, it is not trivial for a user to specify the optimal measures to guarantee safety. This paper investigates the safety-critical motion planning and control problem to balance robotic safety against manipulation performance during work emergencies. Based on a dynamic workspace released by door-closing, the interactions between the workspace and robot are analyzed using a partially observable Markov decision process, thereby making the balance mechanism executed as belief tree planning. To act the planning, apart from telemanipulation actions, we clarify other three safety-guaranteed actions: on guard, defense and escape for self-protection by estimating collision risk levels to trigger them. Besides, our experiments show that the proposed method is capable of determining multiple solutions for balancing robotic safety and work efficiency during telemanipulation tasks.


Introduction
People always pursue high-efficiency performance in emergencies while ensuring personal safety [1]. For example, in fire rescue work, putting out fires, smoke-diving and the handling of patients and heavy tools are typical tasks, in which good balance ability can be critical for safety-guaranteed Autonomous Systems and Robotics Lab, ENSTA Paris, Institut Polytechnique de Paris, Palaiseau, France and task productivity [2]. Uncertain fire conditions and the excessive use of protective equipment further increase the challenges placed on the balance control system. Although existing telemanipulation is a highly efficient master-slave work pattern because of human-in-the-loop control, it is not trivial for the human operators to specify the optimal measures to guarantee robotic safety [3][4][5].
The ability to balance safety against performance in humans is coordinated and fast even when a work-related accident is not anticipated. Unfortunately, the robots are always not well trained such knowledge, to take appropriate measures to deal with the potential emergency during telemanipulation tasks. Beyond the basic capabilities of moving and acting autonomously, it is also essential to assure the robots' survival to protect themselves from harmful states or collisions when physically interacting with their workspace [6][7][8]. It is really true, especially in the search-and-rescue process [9][10][11], robotic dexterous performing task is easy to encounter uncertainties coming from environments in real human-robot collaborative manipulation. Moreover, these conditions to perform a task may need robots to open doors first and then gain access to a new workspace for their end-effectors operations [12][13][14][15]. For example, utilize robots to manipulate the electronic equipments in power stations [16][17][18][19][20]. Typical power station operations are involved a large number of refrigerator-like electric cabinets equipped with electronic monitoring, which need to be checked at close range or switching operated by hands after opening the cabinet door. Similar with many robot-environment interactive processes, leverage robots to further operations in the cabinet's internal workspace released by door-opening; this procedure is susceptible to environmental uncertainty such as the wind force. The uncertain force could significantly drive the opened door with close trends and then lead to collision damages, threatening the robots' mechanical safety and work performance. In such cases, the balance ability is essential and vital to interrupt the current manipulation and display the corresponding self-protection at appropriate times.
In this work, we propose a novel balancing robotic safety against manipulation performance approach by planning safety-critical motions and control during work emergencies in the door-closing scenario. Specifically, a dynamic disturbance model of the restricted workspace released by door-opening is established. And then, the workspace and robot interactions are analyzed using a partially observable Markov decision process (POMDP), thereby making the balance mechanism executed as belief tree planning. To perform the planning, besides the telemanipulation actions, we clarify other three types of safety-guaranteed actions: on guard, escape, and defense for self-protection by estimating collision risk levels to trigger them. Finally, we propose three motion controllers based on risk-time optimization to act the planned self-protective actions.
The main contributions of this paper are summarized as follows: 1. To our knowledge, this paper yields the first evaluative framework to balance robotic safety against its operation performance during dynamic interactions in a door-closing workspace, within the collision risk consideration coming from environmental uncertainty; 2. Apart from the manipulation actions, this paper clarifies other three safety-guaranteed actions: on guard, elbow defense the door, and escape out respectively to the collision risk with low, middle or high levels to act the balance policy, which is verified real true based on the experiments with our build-up robot platform; 3. Additionally, this paper is to provide guidance for the safe manipulation and deal with emergencies of a class of rescue robot operations and the upgrade of motion planning.
The rest of this paper is organized as follows. Related works are described in "Related work", "Workspace construction and problem formulation" explains the workspace construction and problem formulation. A novel balancing safety against performance method is proposed in "Proposed method". "Experiments and results" validates the efficiency of the proposed method by experiments. Finally, conclusions are drawn in "Conclusions".

Related works
Related works about emergency measures, balance mechanism and workspace construction are introduced briefly in this section. The studies on robotic emergency measures for selfprotection are both control and planning interesting. From the perspective of the reflex-based control, self-protective behaviors are categorized as the state-action association of behaviors, which traditionally depends on the subsumption architecture [21]. In this paradigm, the robot can quickly react to the stimulus since the sensory input from the dynamic environment directly triggers the coupled action from a wide variety of measures. Given this, many studies have focused on time-delay compensation [22,23] or reflex-based self-protective patterns and successfully applied to some humanoid robots, i.e., grasp reflex [24] and mainly slip [25]. For them, facing accidental collision risks, generating and maintaining stable controllers are their preventive measures. From the perspective of motion planning in some constrained environments [26], the self-protective response is to avoid one or more dynamic obstacles with uncertain motion patterns [27]. For them, it is necessary to plan smooth and collision-free orbits or trajectories to perform the desired task [28]. In the sense that, the self-protection to guarantee safety in the situation is based on around the dynamic obstacles to avoid collision paths.
Robotic balance mechanism is the prerequisite optimization policy-decision process for taking emergency measures, knowing when to pursue high-efficiency performance, or prefer a security guarantee. Traditionally, owing to the exclusive pursuit of the best performance value, this mechanism is not so flexible even redundant that it could be ignored in both subjective and objective aspects. Similarly, the exclusive pursuit in another extreme case is absolute security.
The aforementioned control and planning technologies are applied to a typical workspace released by door-opening [29,30], which has also received abundant attention during the last decades. When door-opening actions work in practice [31], the opened door matches external disturbances, such as uncontrolled rotational inertia to get closing trends, are unavoidably encountered. Unless dealt with in a proper way, they would deteriorate the performances of the following operations and even give rise to inconsistent task results, which leads to mission failure. In some cases, the researchers would suitably treat the unlocked door driven by external dis-turbances depending on the further task's difficulty. For easy tasks such as opening the door only to traverse it [32,33], it is no need to care too much about the unlocked door's state information due to a quick pass through after door-opening. However, complex tasks such as opening the door to get handwork inside [34,35], are generally more time-consuming and need more operating precision. We can not ignore the uncertain disturbances [36] coming from the unlocked door leading to a potential risk of collision damages. Compared with the above-mentioned simple task, cabinet handwork inside limits the end-effector's workspace and keeps the robot in the unlocked door's adverse influence range for a long time. To solve this problem, professional roboticists initially took a dual-arm mobile manipulator scheme [37,38]. More precisely, using one arm to defense the unlocked door's closing trends disturbances while planning another arm to work inside. They applied this theoretical pattern to an expensive PR2 (Personal Robot 2) to fetch a beer from a refrigerator [39]. Based on this pattern, the scheme mentioned above even could be used in multi-arm robot systems; unfortunately, it is not friendly for robots with only one arm.
In this work, we focus on a single-arm mobile manipulator robot in human-robot collaborative manipulation to respond to emergencies. The unlocked door has closing disturbances during handwork after door-opening.

Workspace construction and problem formulation
Consider a time-varying workspace W (t) released from its door-opening action, is constrained by the door's frame D frame and its leaf D leaf . In the top view to see W (t), Fig.  1 shows the dynamic interactive progress, which seems like a shrinking Chinese folding fan when D leaf is driven by the force such as a sudden wind F w (t).
Simultaneously, due to the resisting force F r (t) coming from rotation friction and air resistance, D leaf would stop close at a certain position p n . After these, the state equation for W (t) can be written as: where θ (t) denotes the angle between D frame and D leaf , ω (t) denotes the angular velocity and f (·) denotes a timevariation function.
In this paper, note that we do not concern about W (t) having the enlarged dynamic space situation. Thus, standing in the fan-shaped area, the robot is always facing the potential collision risk. We assume that the robotic chassis is necessarily treated as a collision-free part due to equipped with some indispensable precision sensors. After these, the goal is to plan a policy π in W (t) to get the maximum value func-tion V (π ) and then control to execute π between the start configuration q 0 ∈ R D and the goal configuration q d ∈ R D , which can be written as: where q is the robotic degree of freedom (DOF) and D is the number of the DOF.

Proposed method
In this section, Fig. 2 shows the proposed balancing safety against performance method, which is mainly completed by three aspects, i.e., balance mechanism, interaction estimators and responding measures, that will be presented in detail.

Balance mechanism
The balance mechanism is a collaborative control based on the risk estimators, choosing the manual or automated policy decisions to deal with the workspace. The upper part of Fig. 2 shows the human-robot interaction for master-slave manipulation tasks after door-opening. The control system to generate action sequences involves an autonomous controller's network interaction with the human operators. Under the received manual policy and action commands, assuming no significant delays or communication issues occur between the master and the slave, the robot platform could perform dexterous manipulation in efficiencycritical applications such as turn on a power switch for the human in the control loop.
The lower part of Fig. 2 shows the robot-environment interaction for door-closing emergencies. In the policy decisions block, a partially observable Markov decision process (POMDP) [26] architecture simulates the interaction relationship between agents decisions and their environment, which models our robot acting in the partially observable stochastic compressed workspace. It is defined formally as   As analyzed previously, the POMDP planning aims to choose a policy π that maximizes its value based on A and S, but S is not known exactly due to imperfect observation. Instead, the robot maintains a belief, which is a probability distribution over S. The robot starts with an initial belief b 0 . At time t, it infers a new belief, according to Bayes' rule [40], by incorporating information from the action a t taken and the observation z t received: where η is a normalizing constant. Figure 3 shows that a POMDP policy prescribes the action at a belief. With the policy π and an initial belief b 0 , the expected value function V π can be written as: where s t is the state at time t, a t+1 = π(b t ) is the action that the policy π chooses at time t, and γ ∈ [0, 1] is a discount factor. The expectation V is taken over the sequence of uncertain state transitions and observations over time.
A key idea in POMDP planning is the belief tree [41], as shown in Fig. 3. Each node of a belief tree corresponds to a belief b. At each node, the tree branches on all actions in A and all observations in Z. If a node with belief b has a child node with belief b , then b = π(b, a, z). Conceptually, we may think of POMDP planning as a tree search in the belief space, the space of all possible beliefs that the mobile manipulator may encounter. To find an optimal plan for a POMDP, using Bellman's equation relationship [42], we traverse the belief tree from the bottom up and compute an optimal action recursively at each node: where we notice that every value function V π that satisfies Eq. (5) is both necessary and sufficient for the induced policy to be optimal. Based on the above discussions, in the sense that, our POMDP planning is a special case of belief space planning. In other words, the belief space planning is more general and does not require the planning model to satisfy the mathematical structure of POMDPs. For example, the reward function R may depend on the belief b and not just on S and A. Additionally, at each node, all observations in Z are key points for the searching progress, for a reason is the following child node of the belief tree branches on all possible actions in A.

Interaction estimators
In what follows, the observations and risk estimators block shown in Fig. 2 switch the control priority to trigger the mentioned manual or automated modes in detail. Figure 4 shows the observation progress for the dynamic D leaf . Let O denote the robot's sensing position, P i , P i+1 and Q denote three marked feature points on D frame and they are coplanar with O. O O is parallel to |P i+1 G i+1 | and O O = |P i+1 G i+1 | = |P i G i | = h where h denotes the height between the marked point and the ground. Likewise, |P i Q| is parallel to d and |P i Q| = |P i+1 Q| = d where d denotes the unlocked door leaf's width.
In such case, we can get |P i O|, |P i+1 O| and |O Q| by measurement. According to the geometric relationship, the observed rotation angle θ i can be written as: where For D leaf , the moment of inertia around the door axis is: where m denotes the D leaf mass. Based on Eqs. (6) and (7), the observed angular kinetic energyÊ D leaf around the door axis can be written as: whereω = θ t and t denotes the observation of time unit. In this paper,Ê D leaf indicates the risk estimators block to switch and trigger the above balance mechanism. Combing with Eq. (8), we treat the risk levels coming from D leaf as inputs, train and divide them into four pre-defined parts (e.g., no risk, low risk, middle risk and high risk), which can be written as: where E min and E max denote the minimum energy and maximum energy to trigger the child node in belief tree (see Fig.  3). In addition, due to the resisting force F r (t) coming from rotation friction and air resistance,Ê D leaf could gradually decrease to zero in the door-closing progress.

Responding measures
Last, four types of responding measures shown in Fig. 5, i.e., telemanipulation actions and other three types of emergency actions for self-protection, are presented. For the robot platform, to deal with emergencies in the limited workspace, the simultaneous multi-action between  chassis and arm part leads to complicated movements, even mission failure. To simplify the problem, we assume that action implementation related to the chassis and arm part is mutually exclusive. Based on this, there are four typical classes of actions a ∈ A in the dynamic workspace: where telemanipulation denotes a task-related action subset, which is well-behaved human-in-the-loop operations to deal with work, as shown in Fig. 5a; on guard denotes to stop current actions and estimate the collision risk, ready to take the next action according to circumstances, as shown in Fig. 5b; defense denotes to defense actively the risk of the collision damages using the dexterous arm part. Figure 5d shows the defense part might be the end-effector. Consider that the end- effector has a fragile structure to break and usually expensive, which is not suitable for actual applications. In contrast, using the elbow joint to defense plays a dominant role as active self-protection shown in Fig. 5e; escape denotes to escape out of the workspace before collision damages, as shown in Fig. 5c.
The rewards for taking a i after z i are pre-trained as the following Table 1. Let good = +1, ok = 0, and bad = −1. We treat π(a i , z i | i=0,1,2,3 ) as balance policy between safety and efficiency performance in the dynamic workspace. Among them, π(a 0 , z 0 ) and π(a 3 , z 3 ) are traditional research area to improve performance or stress reaction, which are the subset of our proposed balance method. Note that the higher risk level, the less time can be used to act π(a i , z i | i=1,2,3 ), which requires control based on risk time optimization. Let t z i denote the collision time in the risk level z i without considering safety-critical measures. Obviously, we can get t z 3 < t z 2 < t z 1 , and the action controller  Fig. 6 Schematic of the balance policy and control method f a i (·) can be written as: where t a i denotes the time to perform the telemanipulation configuration q a 0 ∈ a 0 to the desired configuration q a i ∈ a i . It is switching control progress to self-protection during the telemanipulations. Based on these, the schematic of the proposed balance policy and control method is shown in Fig.  6.

Experiments and results
In this section, we will present our experimental conditions first and then set up four types of experiments to verify the proposed balance method's efficiency. Figure 7 shows the outlook of the human-in-the-loop robot platform and the dynamic workspace, which is constructed by a standardized power cabinet. The robot platform is mainly composed of a chassis, a 6-DOFs arm, an end-effector and a Kinect, which faces the opened door and runs at 30 frames per second on the chassis. In the dynamic workspace, the specific telemanipulation task is to turn on a switch for electricity supply. Table 2 shows more detailed information and other components. Figure 8 shows the robot platform's geometric relationship during switch work. In the top view, the chassis is partly standing in the fan-shaped area, whose escape is opposite to the end-effector's working orientation. Without considering safety-guaranteed measures, the collision would be at some position on the chassis after t z i , which could be acquired by using the fan with no, low, middle or full power for door-closing. After that, the 6-DOFs arm indicates the rela- Fig. 7 Human-in-the-loop robot platform and door-closing workspace in a power cabinet box which comes from the telemanipulation current configuration to reach the switch. Figure 9 show the Kinect camera's view and the eye view on hand. Based on the two views, a well-trained human operator could drive our robot platform to activate the policy π(a 0 , z 0 ). In this case, a 0 denote action (a i 0 ∈ a 0 | i=1,···,7 ) step as: move-in workspace; reach, clamp, rotary and loosen the switch; take arm back, and move-out workspace (see Fig. 7). In Kinect camera view, the two-dimensional barcodes are detected and measured by point cloud, which are marked positions P and Q to get the distances |P i O|, |P i+1 O|, and |O Q| (see Fig. 4). In the following experiments, we only use the Kinect camera as the risk estimator.

Results and analysis
Based on the mentioned experimental conditions, π(a i , z i | i=0,1,2,3 ) were implemented on the robot platform against the door-closing, as shown in Fig. 10. Figure 10a shows a balance policy sequences to humanrobot collaborative experiments with π(a 2 0 |q a 2 0 , z 0 ), π(on−guard ∈ a 1 , z 1 ) and π(elbow−defense ∈ a 2 , z 2 ). The responding results are shown in Fig. 11. In the left column of Fig. 11, |O Q| is a constant because the chassis is stationary in the workspace; |O P| and P i Q O are gradually decreasing with wind force F w (t) after time t 2 , and interrupt the change when the defense collision happens. We use the local maximums inÊ D leaf to judge z i changes. The judgment is true when z i is changed for the first time from z 0 to another higher level. Let E min = 0.2J and E max = 0.4J , we get the time t 2 (E min <Ê D leaf < E max ) to trigger π(elbow−defense ∈ a 2 , z 2 ). During the time (t 2 − t 1 ), robot platform hold on the current configuration q a 2 0 to do next action a 3 0 , with estimating theÊ D leaf to ensure no more than E min = 0.2J . In other words, the robot performed vigilant self-protective awareness compared with the artificial stop or pause in telemanipulation.
Risk getting higher after t 2 , the robot platform would get the damages more than 1.5 J , which is avoided by elbowdefense. Responding to z i , the switch operations that require precise and small-scale motion are assigned to the endeffector, while the large-scale action for self-protection is fast and carried out by the chassis or arm. We let the end-effector's orientation remain to face the switch and keep end-effector horizontal movement (see Fig. 9) to pre-trained defense con- Fig. 10 Execution of π(a i , z i | i=0,1,2,3 ) in real door-closing scenario figuration, hoping to continue current work quickly after the π(elbow−defense, z 2 ). Based on this, the control based on risk-time optimization is treated as a linear move control in the end-effector's workspace with full speed. In the right column of Fig. 11, all the arm joints are related to the configuration's execution and have significant changes. Their angular velocities, ω q1 and ω q5 , to get the full speed in a short time with their physical constraints. The acquired finial defense configuration q a 2 is , z 0 ), π(on−guard ∈ a 1 , z 1 ) and π(line−escape ∈ a 3 , z 3 ). The responding results are shown in Fig. 12. In Fig. 12, bring into correspondence with three policies in Fig. 11, t 1 and t 2 are also the states (z 0 ,z 1 ,z 3 ) change time and the responding action's start time. |O P| and P i Q O both get the horizontal curves after t 2 . What the difference is, the horizontal curves in the elbow-defense case, the defense collision stopped the door close. But in the line-escape case, the reason is that observation is in the camera's blind vision when escape out of the workspace. The local maximum at t 2 indicates the robot is at high risk, which triggers the chassis to escape out straight with chassis' max speed. Additionally, Compared with the line-escape action, the on-guard and elbow defense's advan- Fig. 11 The collaborative experiments of the telemanipulation, on-guard and elbow-defense Fig. 12 The collaborative experiments of the telemanipulation, on-guard and line-escape tage is having a predictable performance to quick callback the interrupted work after the risk was relieved, without the time-consuming cost of re-planning or re-doing move-in the workspace.

Conclusions
In this paper, a balancing safety against performance approach for door-closing emergencies in human-robot collaborative manipulation has been proposed. Specifically, We first established a dynamic disturbance model of the restricted workspace released by door-opening. And then, the workspace and robot interactions are analyzed using a partially observable Markov decision process (POMDP), thereby making the balance mechanism executed as belief tree planning.
Responding to the policy, besides the telemanipulation actions, we clarify other three safety-guaranteed actions: on guard, escape, and defense for self-protection by estimating collision risk levels to trigger them. Finally, we propose a motion controller based on risk time optimization to act the planned self-protective actions. Our build-up robot platform and a power cabinet inner dynamic constrained workspace were setup to verify the validity and efficiency of the pro-posed planning and control. This paper is to provide guidance for the safe manipulation and deal with emergencies of a class of robot operations and the upgrade of motion planning. Open Access This article is licensed under a Creative Commons Attribution 4.0 International License, which permits use, sharing, adaptation, distribution and reproduction in any medium or format, as long as you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons licence, and indicate if changes were made. The images or other third party material in this article are included in the article's Creative Commons licence, unless indicated otherwise in a credit line to the material. If material is not included in the article's Creative Commons licence and your intended use is not permitted by statutory regulation or exceeds the permitted use, you will need to obtain permission directly from the copyright holder. To view a copy of this licence, visit http://creativecomm ons.org/licenses/by/4.0/.