{"id":"5fe54788-a677-4fe4-bb59-7b8771ea218e","arxiv_id":"2505.12583","paper_version":2,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":5.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"A three-phase taxonomy of physical risk control for foundation-model-enabled robots, with identified research gaps.","lead":"This survey organizes robot safety research for foundation-model robots into pre-deployment, pre-incident, and post-incident phases. It argues that the field under-studies risk mitigation before incidents, physical interaction with humans, and safety issues inside the foundation models themselves.","discovery_kind":"review","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The survey's gap claims depend on a phase taxonomy that places runtime safety controls (e.g., velocity/torque limits and control-barrier-function safety in §4.1) in the pre-deployment phase, so the reported pre-incident gap may be an artifact of categorization rather than a real field-level…","rationale":"The reader's weakest assumption was that the selected paper set is representative enough to support field-level gap conclusions. I agree that the lack of a documented search protocol and inclusion criteria is a serious limitation. My concern is slightly different and more internal: even accepting the selected set, the phase definitions are applied inconsistently. Section 4.1 places runtime enforcement mechanisms (velocity/torque limits, virtual fences, fault monitoring, admittance control, control barrier functions) in the pre-deployment phase, while Section 4.2 restricts the pre-incident phase to runtime monitoring and OOD handling. This categorization directly shapes the paper's central finding that pre-incident mitigation is under-studied. Because the claimed gaps are the survey's main intellectual contribution, a reclassification that shifts runtime safety work into the pre-incident phase would materially change the conclusions. The paper also explicitly acknowledges including non-foundation-model works, which further complicates any claim about FMR-specific research gaps. A systematic search plus a reclassification audit would settle whether the gaps are real or an artifact of taxonomy. Until then, a conditional verdict is appropriate; I would not reject the survey, since its taxonomy and curated references retain value even if the gap analysis needs revision.","tokens_in":17565,"tokens_out":4188,"duration_ms":47570,"concrete_test":"Run a reclassification audit: take every mechanism cited in §4.1's 'Hardware and Software for Safety' and assign it one label—(a) design-time/offline only, (b) runtime before an incident, or (c) post-incident—based on when the mechanism actually acts. Then compare the resulting per-phase counts with those implied by the paper's presentation. If the pre-incident category grows by more than roughly 30% relative to the survey's apparent count, the claimed pre-incident gap is an artifact of the taxonomy. As a secondary check, restrict all counts to papers whose methods actually use foundation models; if the pre-incident and physical-interaction counts are no longer sparse under this restriction, the FMR-specific framing of the gaps is unsupported.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central findings—that pre-incident risk mitigation, physical-interaction research, and foundation-model-specific issues are under-studied—are inferred from the distribution of papers across the survey's own three-phase taxonomy. That inference is not secure because the taxonomy conflates design-time and runtime mechanisms. Section 4.1, under 'Hardware and Software for Safety', lists velocity and torque limits, virtual fences, fault monitoring systems, admittance control, and control-barrier-function-based safety [Ferraguti et al., 2022] as pre-deployment measures, even though these mechanisms operate after deployment and before an incident occurs. Section 4.2 then defines the pre-incident phase narrowly as runtime monitoring and out-of-distribution handling. As a result, a substantial existing literature on reactive collision avoidance, safety filters, and physical human-robot interaction safety is either filed under pre-deployment or omitted entirely. The paper also states at the start of Section 4 that 'some of the surveyed papers include studies that do not use foundation models', so claims about sparsity of FM-specific or physical-interaction work are difficult to separate from the authors' selection and categorization choices. If the runtime controls in §4.1 were reclassified as pre-incident, the headline claim that 'there is much room to study pre-incident risk mitigation strategies' would be substantially weakened. The survey remains a useful taxonomy, but its gap analysis is not robust to reclassification.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"This paper surveys robot-control approaches for mitigating physical risks in foundation-model-enabled robotics (FMRs). It organizes the robot lifetime into three phases—pre-deployment, pre-incident, and post-incident—and reviews hardware and software safety mechanisms, dataset curation, simulation, red-teaming, formal safety guarantees, runtime monitoring, out-of-distribution handling, robot recovery, first-aid measures, and human-in-the-loop improvement. From its organization of the literature, the paper concludes that pre-incident risk mitigation, research assuming physical interaction with humans, and foundation-model-specific safety issues are under-studied.","tokens_in":17978,"tokens_out":4390,"duration_ms":45115,"significance":"The proposed three-phase temporal taxonomy is a genuinely useful organizing device, and the paper draws attention to post-incident recovery and first-aid considerations that prior FMR surveys largely omit. It also usefully connects red-teaming and formal safety guarantees to robotics. However, the survey's central gap findings rest on a categorization scheme and a non-transparent literature selection, so the significance of those findings is not yet established. If the taxonomy were corrected and the selection made systematic, the survey could become a valuable reference for the community.","major_comments":[{"comment":"The taxonomy places runtime control mechanisms such as velocity/torque limits, virtual fences, fault monitoring, admittance control, and control-barrier-function safety [Ferraguti et al., 2022] under the pre-deployment phase, while §4.2 defines the pre-incident phase narrowly as runtime monitoring and out-of-distribution handling. Because these mechanisms operate after deployment and before an incident, the reported scarcity of pre-incident work is at least partly an artifact of this categorization; reclassifying these mechanisms as pre-incident would substantially weaken the headline gap claim made in the Abstract and §5.","section":"§4.1, Hardware and Software for Safety"},{"comment":"The survey provides no search protocol, inclusion or exclusion criteria, or counts of papers per category, and it explicitly states that “some of the surveyed papers include studies that do not use foundation models.” Consequently, the paper's conclusions about sparsity of physical-interaction research and foundation-model-specific issues cannot be separated from the authors' selection and categorization choices. To support the gap claims, the authors should report the retrieval process, screening criteria, per-category counts, and a repeatable classification procedure.","section":"Section 4 opening and Conclusion"},{"comment":"The paper concludes that research assuming physical interaction with humans is under-studied, yet §4.1 cites a body of physical human-robot interaction safety work (e.g., [Haddadin et al., 2007; Haddadin et al., 2008; Sun et al., 2024b]) and §4.3 discusses human-in-the-loop methods. Without a clear definition of what counts as “physical interaction research” and a quantitative comparison of that research to other categories, this conclusion is not supported as stated.","section":"§5, claim (ii)"},{"comment":"The boundary between the pre-incident and post-incident phases is unclear for recovery mechanisms such as dynamic replanning [Shirasaka et al., 2024], teleoperation, and reset policies [Kim et al., 2024]. These mechanisms are also run-time safety functions that can act before any damage occurs. The authors should define the temporal boundary more precisely (for example, specifying that the post-incident phase begins only after physical damage has occurred), or explicitly acknowledge that the phases overlap for learning-based systems.","section":"§4.3 and Figure 3"}],"minor_comments":[{"comment":"The caption contains the typo “suvey” and should read “survey.”","section":"Figure 2 caption"},{"comment":"The paragraph ending “Together, these hardware and software measures… reliable and safe robotic deployment” repeats a nearly identical sentence twice; one copy should be removed.","section":"§4.1"},{"comment":"Several inline citations are duplicated, for example [La Valle, 2011; La Valle, 2011] and [Yamamoto et al., 2019; Zhu et al., 2019; Yamamoto et al., 2019; Hossain, 2023; Zhu et al., 2019]; these should be cleaned up.","section":"§2.1"},{"comment":"The heading “First Aid Measurement” should be “First Aid Measures.”","section":"§4.3"},{"comment":"The phrase “Test-time Adaption / Training” should be “Test-time Adaptation / Training.”","section":"§4.2"}],"recommendation":"major_revision","confidential_remarks":null},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"What should you know about this survey? It is worth reading as an organizing frame, but treat its headline claims about under-studied areas as hypotheses, not findings. The three-phase timeline (pre-deployment, pre-incident, post-incident) is a genuinely useful way to lay out safety research for foundation-model robots, and the paper does something prior surveys didn't: it takes post-incident recovery and first aid seriously. It also names plausible gaps—work that assumes physical interaction with humans, and issues specific to foundation models themselves—that deserve attention.\n\nWhat's good: the paper is honest. It explicitly says some cited works do not use foundation models and are listed as expected future technologies. The coverage is broad and reasonably organized, and the diagrams are clear. The authors are not overselling novelty.\n\nThe soft spots are real and central. There is no method section, no search protocol, no inclusion/exclusion criteria, and no quantitative counts. The conclusions about 'much room to study' are drawn from the distribution of papers across the taxonomy, but the taxonomy is doing a lot of work. The stress-test note is right: placing velocity/torque limits, control barrier functions, collision detection, admittance control under 'pre-deployment' is a categorization choice. These mechanisms run after deployment and before an incident; if you reclassify them as pre-incident, the headline gap weakens substantially. Similarly, because the selection of papers is not systematic, the claim that FM-specific and physical-interaction work is sparse could be overstated. This is not fatal to the survey as a map, but it means the gap analysis should be read as informed opinion, not empirical result.\n\nWho is this for? Graduate students and researchers wanting a quick map of safety approaches in FMR, and anyone planning research directions. It deserves a serious referee, but a revision that adds a methods paragraph, a count of papers per category, and a more careful justification of the phase boundaries would make a real difference. I'd send it out, with the expectation of heavy revision.","headline":"Useful three-phase taxonomy of robot safety, but the headline gap claims rest on a shaky categorization and no systematic lit review.","tokens_in":18416,"tokens_out":1803,"would_cite":true,"duration_ms":19467,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"This survey argues that physical-risk control for foundation-model-enabled robots is lopsided: most research targets the pre-deployment phase, while pre-incident mitigation, physical human-robot interaction, and foundation-model-specific…","keywords":["foundation models","robot safety","physical risk","human-robot interaction","runtime monitoring","post-accident recovery","survey"],"falsifier":"A systematic review with explicit inclusion criteria that counts papers by phase would settle the claim; finding that pre-incident or physical-interaction research is as abundant as pre-deployment work in comparable venues would directly contradict the survey's gap diagnosis.","tokens_in":17355,"feed_emoji":"🤖","tokens_out":5577,"duration_ms":53355,"temperature":0.7,"pith_summary":"Foundation-model-enabled robots (FMRs) are leaving closed factory settings for open environments where people and robots share space, so accidents cannot be designed away. This survey organizes existing robot-control work on physical risk into three phases of a robot's lifespan—before deployment, after deployment but before an incident, and after an incident—and argues that research is lopsided. Most effort concentrates in the pre-deployment phase, while pre-incident mitigation, studies that assume real physical contact with humans, and problems specific to the foundation models themselves remain under-served. The authors propose that closing these gaps, together with social measures like legislation and insurance, is what safe human-robot coexistence will require.","feed_headline":"Survey: robot safety research skips the moments before a crash","feed_subtitle":"A broad survey maps physical-risk controls across a robot's lifespan and finds the pre-incident phase is the least studied.","key_machinery":"The analytical instrument is the three-phase lifespan taxonomy. It divides all surveyed approaches by when they act: pre-deployment (preventing risk while designing, training, and evaluating the system), pre-incident (guarding the deployed system in the moments before harm), and post-incident (recovering the robot, aiding the injured, and improving through human feedback). The taxonomy does the argument's work: by slotting each approach into one phase, it makes the relative emptiness of the pre-incident and post-incident categories visible, and that visible skew is the survey's main finding.","core_discovery":"The survey's central claim is that physical-risk control for FMRs should be understood across the full lifespan, and that the field has largely failed to cover the latter two stretches. It classifies the literature into pre-deployment risk prevention (hardware and software safeguards, dataset curation, simulation, red-teaming, formal safety guarantees), pre-incident risk mitigation after deployment (runtime monitoring and out-of-distribution measures), and post-incident response (robot recovery, first aid, human-in-the-loop improvement). Surveying these bodies, it concludes that the pre-incident phase, research that assumes physical human-robot interaction, and foundation-model-specific issues each have much room for study. The paper frames this not as a claim that the surveyed techniques are ineffective, but as a map of where the field's attention is sparse relative to the risks of open-world deployment.","pith_inferences":["The taxonomy is a natural counting scheme: a bibliometric tabulation of papers per phase would turn the claimed gaps into measurable proportions, testing the survey's reading of the field.","The pre-incident gap suggests a concrete research agenda: runtime monitors that predict imminent collisions or unsafe contacts—using video or vision-language models as early critics—could be the highest-leverage place to add new work.","Because the survey deliberately imports non-foundation-model techniques as 'expected to be utilized,' the actual empirical evidence for FMR-specific safety may be even thinner than the taxonomy suggests.","If FMRs are to act as first responders to the damage they cause, questions of liability, trust, and permission to touch an injured person will constrain the technical design; those social constraints are named but not developed."],"forward_implications":["If the field's attention is indeed concentrated before deployment, then robots entering homes and cafes will be best protected by training-time measures and least protected at the moment a hazard actually begins to unfold.","The scarcity of research assuming physical contact with humans implies that results from simulated or fenced-off tests may not transfer to the close-proximity settings FMRs are expected to occupy.","Post-incident recovery and first-aid capabilities are not add-ons; they are a third of the risk-control timeline and currently the thinnest part, so deployment plans should budget for failures that will still occur.","Foundation-model-specific risks—training-data quality, physical-world understanding in language and vision models—need to be studied directly rather than inherited from classical robotics safety work.","Technical control alone is not the endpoint: the paper argues that legislation, insurance, and ethical guidelines must accompany the engineering measures to handle the aftermath of physical damage."],"supporting_citations":[{"why":"Defines foundation-model-enabled robotics and frames the open-world deployment risk that motivates the whole survey.","marker":"Firoozi et al., 2023"},{"why":"Supplies RT-1 as the canonical end-to-end robot transformer, the class of system whose physical risks the survey addresses.","marker":"Brohan et al., 2022"},{"why":"Represents the earlier foundation-model risk survey that the authors say covered only partial pre-incident sections, establishing the gap the three-phase taxonomy fills.","marker":"Bommasani et al., 2021"},{"why":"Provides the automated red-teaming example used to show what pre-deployment stress-testing can look like for FMRs.","marker":"Karnik et al., 2024"},{"why":"Code-as-monitor is the representative runtime-monitoring approach in the pre-incident phase.","marker":"Zhou et al., 2024a"},{"why":"Human-in-the-loop weighted imitation learning is the paper's main example of post-incident continuous improvement.","marker":"Liu et al., 2023"},{"why":"Shows the current limit of formal safety guarantees, which the survey uses to argue that robust constrained control for FMRs remains an open question.","marker":"Kitamura et al., 2025"}],"fun_headline_variants":["Robot safety survey: pre-crash phase least studied","Survey: robot risk research misses the pre-incident window","Robot safety gaps: pre-crash mitigation overlooked","FMR risk survey: weakest link is before the incident","Robot safety map shows pre-collision research sparse"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The conclusions about which phases are under-studied rest on the assumption that the papers the survey chose to discuss are representative of the whole field, because the survey does not report a systematic search strategy or inclusion criteria.","fun_headline_variants_meta":{"raw":{"variants":["Robot safety survey: pre-crash phase least studied","Survey: robot risk research misses the pre-incident window","Robot safety gaps: pre-crash mitigation overlooked","FMR risk survey: weakest link is before the incident","Robot safety map shows pre-collision research sparse"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000187,"raw_usage":{"total_tokens":1317,"prompt_tokens":922,"completion_tokens":395,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":538,"completion_tokens_details":{"reasoning_tokens":319}},"tokens_in":538,"tokens_out":395,"duration_ms":4829,"temperature":1.0,"reasoning_tokens":319,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-15T20:29:37.359157+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"A systematic review with explicit inclusion criteria that counts papers by phase would settle the claim; finding that pre-incident or physical-interaction research is as abundant as pre-deployment work in comparable venues would directly contradict the survey's gap diagnosis.","supporting_citations":[{"cited_title":"Near-Optimal Policy Identification in Robust Constrained Markov Decision Processes via Epigraph Form","cited_arxiv_id":null,"evidence_quote":"Shows the current limit of formal safety guarantees, which the survey uses to argue that robust constrained control for FMRs remains an open question."}],"review_version":1}