1 Guard the whole arm
Many safety filters for these policies only guard the gripper. Ours also guards the wrist and forearm, which can hit things before the gripper does as the arm reaches across the table.
School of Electrical and Computer Engineering, Purdue University
Many safety filters for these policies only guard the gripper. Ours also guards the wrist and forearm, which can hit things before the gripper does as the arm reaches across the table.
The object to avoid is found once, at the start. After that a lightweight tracker follows it as it moves, instead of searching for it again in every frame.
The robot policy, the object finder and the safety filter all run on a single laptop processor. The filter only nudges the policy's commands when the arm gets too close.
We built a simulated test in which the object to avoid moves while the robot works.
Averaged over all six:
Each clip runs the same scene and start twice: left, no filter; right, with our filter.
These are hand-picked examples in which the policy alone finishes the task but hits the object. The numbers above come from the full test in the paper.
The same filter runs on a low-cost SO-101 arm while a person carries a bottle into its path. The robot's task is to place a sugar cube in a cup.
Intel Core Ultra X7 358H
Across four tasks with four tries each, the arm touched the bottle in 3 of 16 tries with the filter and in 11 of 16 without it. It finished the task in 11 tries with the filter and in 13 without.
Nothing runs on a server or over the network.
A vision–language–action (VLA) policy can finish a manipulation task while knocking over objects unrelated to it, so task success alone does not show that the policy is safe to deploy in clutter. We study how to keep a pretrained VLA policy clear of such hazards at run time without retraining it, which requires guarding more of the arm than the end effector, following the hazard as it moves, and sharing onboard compute with the policy. Our training-free shield covers the gripper, wrist, and forearm with five ellipsoids and filters every commanded motion through one barrier program against a keep-out ellipsoid fitted from RGB-D perception at reset. Sparse optical flow then carries that ellipsoid's center along with the hazard, with no repeated detection or refitting. Over six simulated hazard-motion conditions, the shield lowers collision from 65.62% to 27.27% and raises safe-success, task completion without collision, from 29.35% to 50.43%. Ablations show that guarding the arm links protects beyond end-effector shielding, and that tracking recovers most of the protection lost when the hazard estimate is frozen at reset. On heterogeneous edge hardware, the five-ellipsoid barrier runs on the CPU in 2.2 ms at the 99th percentile, and trimming the vision–language prefix and taking fewer flow-matching steps shortens each π0.5 policy call on the integrated GPU from 343 to 177.3 ms. On a physical SO-101 arm across four tasks, the arm touched the hazard in 3 of 16 shielded episodes versus 11 of 16 unshielded ones.
@misc{agarwal2026multilink,
title = {Multi-Link Safety Filtering for {VLA} Policies
Around Moving Hazards},
author = {Agarwal, Yatharth and Raghunathan, Vijay},
year = {2026},
note = {Preprint}
}