ROBOTNESS
专业arXiv

NEUPRO用神经符号规则让机器人安全推理可解释

Zihan Ye, Jiayi Liu, Puze Liu, Jiayun Li, Georgia Chalvatzaki, Jan Peters, Kristian Kersting
30 秒速读

预印本论文提出NEUPRO,一个神经符号框架,将安全规范表示为一阶逻辑规则,并通过可微分推理器从图像中学习安全谓词。在真实机器人数据集REASON上,NEUPRO在七个任务的安全分类准确率达到0.92±0.02,显著优于VLM基线,并能解释安全违规原因。该工作为机器人安全提供了可解释且可迁移的表示,但尚未经同行评审。

研究问题

如何让机器人从原始视觉观察中学习可解释、可迁移且可验证的安全约束?

问题

现有安全约束通常编码为不透明的数学函数或密集成本,难以解释且绑定具体任务;学习型方法缺乏可解释性;VLM预测难以验证,无法提供形式化安全保证。

既有方法

此前方法包括手工设计的逻辑规则或数学约束、学习型黑盒分类器、以及视觉语言模型(VLM)。手工规则工程量大且难以从图像中提取抽象概念;学习型方法缺乏可解释性且与任务耦合;VLM无法验证且准确率低。

新方法

NEUPRO将安全要求表示为一阶逻辑规则,使用Grounding DINO提取对象特征,通过可学习的MLP(逻辑谓词模型)预测谓词真值,并利用基于图的可微分推理器进行前向推理。梯度通过规则传播到感知模块,实现端到端训练,同时保持可解释性。作者还发布了REASON数据集,包含真实机器人场景的谓词标注、符号约束和安全标签。

结果

在REASON真实机器人数据集上,NEUPRO在七个任务的安全分类准确率为:Occlusion 1.0±0.0,Cabinet 0.96±0.06,Near 0.99±0.03,Above 1.0±0.0,Collision 1.0±0.0,Close 1.0±0.0,Pointing 0.92±0.08,联合任务总体0.92±0.02。相比之下,VLM基线(无上下文学习)总体准确率:Qwen3.5为0.55±0.04,DeepSeek-VL2为0.44±0.04;带上下文学习时Qwen3.5为0.55±0.04,DeepSeek-VL2为0.48±0.03。黑盒分类器在单个任务上准确率0.79至0.98,但不支持联合任务。在灵活推理任务中,NEUPRO在两个任务上均达1.0±0.0准确率。可扩展性测试使用102条规则,在RTX A6000 GPU上,图推理器训练时间快9.1倍,峰值GPU内存降低14.3倍,推理快1.6倍。每个谓词使用五个测试图像,结果平均自五个测试组。

局限

作者承认NEUPRO依赖安全规则和背景知识的质量与覆盖度;依赖Grounding DINO的检测性能;仅处理静态视觉观察,缺乏时序推理;仅使用单视角图像。此外,REASON数据集每个任务仅五个测试组,样本量较小;论文未报告代码是否开源(仅提到将开源数据集和标注工具);未见在真实机器人控制闭环中的验证。

产业影响

可应用于需要可解释安全推理的机器人产品,如服务机器人、协作机器人、医疗辅助机器人,尤其在人类交互和精细操作场景。时间尺度为1至3年:需要领域专家提供安全规则,集成到现有机器人控制栈,并扩展到多视角、时序推理和更广泛的对象类别。前提是视觉基础模型性能足够可靠,且能通过大规模仿真或真实数据验证安全性。

论文全文

Neuro-Symbolic Predicate Learning for Semantic Safe Robot Control

Zihan Ye, Jiayi Liu, Puze Liu, Jiayun Li, Georgia Chalvatzaki, Jan Peters, Kristian Kersting

本文依据 CC BY 4.0 许可发布,经署名转载,原文见 arXiv:2609.39594(PDF)。

Abstract

As robots are increasingly deployed in everyday environments, ensuring their safety has become a central challenge. Existing methods often encode safety requirements as opaque mathematical/logical formulations or dense cost functions. While effective in specific tasks, they remain difficult to interpret, tightly coupled to individual tasks, and offer limited insight into why a robot action is considered safe or unsafe. To address this limitation, we propose “Neuro-Symbolic Predicate Learning for Semantic Safe Robot Control” (NEUPRO), which leverages a differentiable reasoner that can learn reusable safety representations from human-specified safety knowledge. NEUPRO allows practitioners to express task-related safety requirements as transparent symbolic rules, while enabling gradients to propagate through these rules to a feature extractor that maps raw observations to safety-relevant concepts. As a result, the learned feature extractor is (softly) grounded in human-understandable semantics, supports transparent constraint evaluation, and is transferable across tasks. By coupling interpretability with differentiability, NEUPRO moves beyond opaque cost design toward reusable safety reasoning. To evaluate NEUPRO’s capability, we collect and release REASON, the first real robot benchmark dataset for interpretable robot safety specification. Experiments on REASON show that NEUPRO learns safety-critical features that generalize across tasks, mitigate the interpretability limitations of conventional black-box cost formulations, and provide explicit explanations of safety violation.

1TU Darmstadt, 2AIML group, 3IAS group, 4PEARL group,

5Hessian AI, 6DFKI, 7Tongji University 8Robotics Institute Germany

[email protected], [email protected]

Figure 1: Existing safe robot learning methods often encode safety constraints using opaque mathematical/logical functions, which are hard to interpret and bound to specific tasks. We propose NEUPRO, leveraging differentiable reasoning to alleviate these limitations using interpretable symbolic rules.

1 Introduction

As robots are increasingly expected to operate in complex, unstructured environments, ensuring safety has shifted from a desirable attribute to a fundamental requirement (Garcıa and Fernández 2015; Achiam et al. 2017; Wachi et al. 2024; Brunke et al. 2022; Zhao et al. 2023). Whether navigating around humans (Lasota et al. 2017) or manipulating fragile objects, a robot needs to continuously reason about underlying safety constraints (Haddadin et al. 2017). Safe robot learning aims to address this by enabling policies to acquire optimal behaviors while strictly respecting these boundaries. However, a central challenge remains: how should safety requirements be constructed and transferred across diverse tasks?

Existing safe robot learning methods typically encode safety requirements via predefined logical rules or mathematical constraints (Brunke et al. 2025; Liu et al. 2023a; Liu et al. 2025). While effective, these representations face several important limitations. Hand-crafted logical rules and mathematical constraints can provide strong safety guarantees, but they are typically designed for specific tasks and require substantial engineering effort to formulate and adapt. This difficulty becomes more pronounced for abstract, visually grounded requirements, such as “do not point a knife at a human,” which cannot be easily translated from raw images into explicit mathematical constraints. Learning-based approaches (Kim et al. 2023; Lindner et al. 2024; Günster et al. 2024) may reduce the need for manual specification, but the resulting safety representations are often entangled with the task and policy, lacking interpretability and limiting their potential reuse in new settings. Vision-Language Model (VLM) s offer a promising alternative because they can interpret natural-language safety instructions directly from visual observations. However, their predictions are generally difficult to verify and do not, by themselves, provide formal safety guarantees. Recent work has begun to incorporate semantic scene understanding into robot safety mechanisms (Brunke et al. 2025), this semantic information is still translated into task-specific mathematical constraints. The central challenge is therefore to ground human-interpretable safety requirements directly from low-level visual observations while preserving sufficient structure for verification and integration into safe robot learning.

Driven by the need that safety constraints should not only be optimized but also understood, we propose neupro. NEUPRO allows one to construct task-relevant safety constraints as transparent symbolic rules with flexible compositions of learnable logical predicates. To train the predicates, a differentiable logic reasoner enables gradients to flow from the safety-rule satisfaction signal back to Logical Predicate Model (LPM) inferred from a visual foundation model, such as Grounding DINO (Liu et al. 2023b). Consequently, the LPM learns to map raw observations into the grounded atoms required by the symbolic rules. Through this formulation, the learned representation is not merely optimized to fit an opaque label, but is explicitly (softly) grounded in interpretable safety concepts. Furthermore, such LPM allows us to achieve object-level and task-level generalization without retraining. In our setting, we assume the safety rules are predefined by domain expert as the normative decision must always come from the responsible institution.

To evaluate NEUPRO’s capability, we collect the REASON benchmark. To the best of the author’s knowledge, REASON is the first real robot interpretable safety dataset. It covers safety scenarios involving human–robot interactions and robot–environment interactions, providing structured annotations that connect perceptual observations with interpretable safety constraints. The results show that NEUPRO can effectively learn interpretable safety-relevant predicates. The learned features can generalize to novel tasks that share safety semantics. Moreover, in contrast to conventional black-box cost formulations, NEUPRO can provide explicit explanations for safety violation.

To summarize, our main contributions are:

  • We propose NEUPRO , a neuro-symbolic framework that represents safety specifications as interpretable symbolic rules, facilitating flexible, interpretable safety reasoning directly from visual inputs.
  • NEUPRO supports scalable semantic-safety predicate learning and reasoning through its graph-based inference.
  • We release REASON, to the best of our knowledge, the first real robot interpretable safety specification dataset.
  • We validate NEUPRO ’s effectiveness in safety predicates learning and safety reasoning on REASON, and demonstrate its interpretability, flexible reasoning, and safety predicate cross-task generalization capability over conventional safety constraints formulations.

2 Related Work

NEUPRO builds on differentiable logic and is closely related to safe and neuro-symbolic robot learning.

First-order logic (FOL) and Differentiable Forward-Chaining Reasoning. We refer readers to App. A for a review of first-order logic fundamentals. Building on this foundation, differentiable forward-chaining inference (Evans and Grefenstette 2018; Shindo et al. 2021; Ye et al. 2022) enables logical entailment to be computed in a differentiable manner via tensor-based operations. This paradigm bridges symbolic reasoning with gradient-based learning, allowing logic-driven models to be trained end-to-end. However, despite their differentiability, tensor-based reasoning operations are inherently memory-intensive. To address this bottleneck, recent work such as Neumann (Shindo et al. 2024) leverages Graph Neural Networks (GNNs) to mitigate memory overhead. While NEUPRO similarly utilizes a graph architecture for memory efficiency, our approach differs in focus. Whereas Neumann focuses on inducing the logical rules, NEUPRO leverages graph-based reasoning to learn the neural feature extractor, focusing instead on representation learning to softly ground high level concepts in raw perception.

Table 1: NEUPRO alleviates the limitations of existing safety reasoning paradigms by supporting interpretable, verifiable, and flexible safety reasoning. We compare different paradigms along these three dimensions, where ✓, ⚫, and ✗ indicate strong, partial, and limited support, respectively.
  • Math. constraints
    Interp.
    ✗
    Veri.
    ✓
    Flexi.
    ✗
  • Learning-based
    Interp.
    ✗
    Veri.
    ✗
    Flexi.
    ⚫
  • VLM-based
    Interp.
    ⚫
    Veri.
    ✗
    Flexi.
    ✓
  • NEUPRO
    Interp.
    ✓
    Veri.
    ✓
    Flexi.
    ✓

Neuro-Symbolic Robot Learning. A central line of neuro-symbolic robot learning uses symbolic predicates and operators to bridge continuous robot observations with high-level task and motion planning. For example, Silver et al. (2022) learn neuro-symbolic skills that integrate symbolic operators with neural policies for bi-level task and motion planning. Chitnis et al. (2022) learn neuro-symbolic relational transition models for planning in continuous robotic domains, while VisualPredicator (Liang et al. 2025) learns task-relevant predicates and abstract world models from robot interaction data to improve planning and generalization. Other approaches, such as Dylan (Ye et al. 2025) and NeSy Plan (Keller et al. 2025), use symbolic abstractions to decompose long-horizon tasks into reusable skills and high-level plans. Unlike these methods primarily use symbolic structures for task planning and skill composition, NEUPRO uses symbolic rules to reason whether a scene satisfies safety requirements and why. Specifically, NEUPRO represents safety requirements as interpretable symbolic rules and uses a differentiable reasoner to ground safety-relevant predicates from raw visual observations. This allows safety supervision to shape the learned perceptual representation while preserving explicit explanations of constraint satisfaction.

Figure 2: Overview of NEUPRO. NEUPRO supports interpretable safety reasoning, end-to-end grounding of safety concepts in images, and flexible reasoning with commonsense knowledge. NEUPRO consists of two key components: (i) a neural perception module and (ii) a graph-based differentiable reasoner. Given a raw image, the perception module uses Grounding DINO and a learnable MLP to extract object-centric features and predict soft truth values for safety-relevant grounded atoms. The differentiable reasoner then infers the safety prediction based on the ground atom evaluation, safety rules, and commonsense knowledge. For details, please see Sec. 3.

Safe Robot Learning. A common approach in safe robot learning is to specify safety constraints manually. For example, in constrained reinforcement learning (Achiam et al. 2017; Liu et al. 2022b; Yu et al. 2022), safety constraints are encoded as a cumulative cost, and task performance is optimized subject to a safety budget. Other methods enforce safety through control-theoretic mechanisms, including control barrier functions (Ames et al. 2019), reachability analysis (Selim et al. 2022; Ganai et al. 2023), and shielding (Yang et al. 2023; Alshiekh et al. 2018). Recent methods further explore differentiable barrier-function architectures (Xiao et al. 2023; Xiao et al. 2025) or embed safety constraints into constraint manifolds (Liu et al. 2022a; Liu et al. 2023a; Liu et al. 2025). Their safety constraints are typically encoded as opaque scalar costs or mathematical representations. Such formulations are often difficult to interpret semantically and are usually tied to specific tasks. Learning-based approaches (Kim et al. 2023; Lindner et al. 2024) may reduce the need for manual specification, but the resulting safety representations are often entangled with the task and policy, lacking interpretability and limiting their potential reuse in new settings. In contrast, NEUPRO expresses safety specifications as interpretable FOL rules and supports flexible safety reasoning and safety feature reuse.

3 Neuro-Symbolic Predicate Learning for Semantic Safe Robot Control (NEUPRO)

Let us now introduce NEUPRO, a framework for learning safety-aware perceptual representations from raw observations while preserving the structure and interpretability of symbolic safety rules. As summarized in Fig. 2, NEUPRO consists of two main components. (i) A Logical Predicate Model (LPM) maps raw images to soft truth values of grounded atoms. (ii) A graph-based differentiable reasoner evaluates first-order safety rules through index-based message passing over dynamically instantiated rule groundings. Together, they enable memory-efficient end-to-end learning, avoiding dense tensor-based differentiable reasoning.

Problem Formulation

The overall goal is to represents safety requirements as a set of interpretable First-Order Logic (FOL) rules \{r_{1},r_{2},\dots,r_{C}\}. Each rule

r_{i}\mathrel{:\!\!-}p_{m}(t_{k},\dots),\dots,p_{n}(t_{l},\dots).

is defined over a predicate vocabulary p_{m},p_{n}\in\mathcal{P} and a set of terms t_{k},t_{l}\in\mathcal{T}, including object variables and constants. Specifically, A Language \mathcal{L} is a tuple of (\mathcal{P},\mathcal{A},\mathcal{V}), where \mathcal{P} is a set of predicates, \mathcal{A} is a set of constants, and \mathcal{V} is a set of variables. A term is a constant or a variable. A ground term or simply a fact is a term with no variables. We denote an n-ary predicate p by p/n. An atom is a formula p(t_{1},\dots,t_{n}), where t_{1},\dots,t_{n} are terms. A literal is an atom or its negation. A clause is a finite disjunction \lor of literals. A definite clause is a clause with exactly one positive literal, such as A\lor\lnot B_{1}\lor\dots\lnot B_{2}. We can write definite clasues in the form of A\mathrel{:\!\!-}B_{1},\dots,B_{n}.

NEUPRO assumes that the the symbolic safety rules are given. That is, our goal is not to learn the rules themselves, but to learn how to ground their predicates p_{i} from raw robot observations. However, training each predicate classifier independently requires explicit labels for every predicate in every scene, which becomes costly as the number of objects, relations, and rules grows. Instead, we uses differentiable rule evaluation as a structured supervision signal: even when only rule-level labels or partially annotated predicates are available, gradients can propagate through the symbolic rules to guide the LPM. As a result, the learned predicates remain interpretable and reusable for the downstream safety-reasoning tasks. We can formulate the problem as:

Let \mathcal{D}=\{(s_{t},\bm{y}_{t},\bm{m}_{t})\}_{t=1}^{N} denote a dataset of scene observations, where s_{t}\in\mathcal{S} is a raw observation, such as an image. The vector \bm{y}_{t}\in\{0,1\}^{C} contains rule-level safety labels, where y_{t,i}=1 indicates that observation s_{t} satisfies the i-th safety rule and y_{t,i}=0 indicates a violation. The mask \bm{m}_{t}\in\{0,1\}^{C} specifies which safety rules are active. Given an observation s_{t}, our goal is to learn a neural LPM

p_{\theta,j}(s_{t})=P(g_{j}=\mathrm{True}\mid s_{t};\theta)

where g_{j}\in\mathcal{G} denotes the grounded atoms, such that the induced rule evaluated by a differentiable logical reasoner \mathcal{R}(\cdot) support accurate and interpretable prediction of rule satisfaction, i.e., \mathcal{R}(p_{\theta}(s_{t}))\odot\bm{m}_{t}\simeq\bm{y}_{t}\odot\bm{m}_{t}.

Perceptual Symbol Grounding

NEUPRO leverages Grounding DINO (Liu et al. 2023b) to extracts a set of object features from raw image batch. Base on the labeled rules associated with the image, we select a subset of features \bm{s}\in\mathbb{R}^{|\mathcal{G}|\times N_{f}} whose object’s class matches the terms appearing in the rule. The features are flattened over batch, \mathcal{G} denotes the set of all grounded atoms in the batch, and N_{f} is the feature dimension. The robot then infers the truth values of safety-critical predicates, such as whether a collision is likely. To this end, a neural LPM p_{\theta} outputs a continuous valuation vector

\bm{v}=p_{\theta}(s)\in(0,1)^{|\mathcal{G}|}.
(1)

Each entry v_{i,j} corresponds to the soft truth value of a grounded atom in data point i. For example, a grounded atom g_{j} may take the form

0.9:\mathtt{collision}(\mathtt{robot},\mathtt{obstacle}).

indicating that the \mathtt{robot} has a 0.9 probability of colliding with the \mathtt{obstacle}. These continuous valuations serve as the initial valuation states for the differentiable reasoning.

Reasoning Graph for NEUPRO

To alleviate the memory bottleneck of tensor-based differentiable reasoning, NEUPRO dynamically constructs a sparse reasoning graph for each mini-batch of the rule groundings of the active safety specifications. The graph contains three types of node, a Grounded Atom Node computes the soft truth value for the corresponding predicates for each instance (e.g., \mathtt{0.81:holding(robot,scissor}); a Conjunction Node computes the logical conjunction probability among multiple grounded atom (e.g., \mathtt{fragile(cup0)}\land\mathtt{near(cup0,table\_edge)}); and a Disjunction Node computes logical disjunction probability among multiple applied instances, such as \mathtt{unsafe(cup0)}\lor\mathtt{unsafe(cup2)}. An illustrative figure can be found in the Differentiable Reasoner Graph block in Fig. 2.

Literal polarity is handled through an affine transformation of the corresponding atom valuation, using sign \bm{s} and bias \bm{b}. For a positive literal, NEUPRO uses [\mathrm{sign},\mathrm{bias}]=[1,0], leaving the valuation unchanged. For a negated literal, it uses [\mathrm{sign},\mathrm{bias}]=[-1,1], which maps a valuation x to 1-x. Using these structural tensors, the soft truth values of all grounded literals are computed in parallel as

\bm{l}=\bm{v}\odot\bm{s}+\bm{b},
(2)

where \bm{l}\in\mathbb{R}^{|\mathcal{G}|} contains the valuation of the grounded literal.

Tensor Indexing. For every grounded literal, the graph structure of NEUPRO is computed through two indexing tensors: \bm{i}_{c}\in\mathbb{N}^{|\mathcal{G}|} specifies the edge connecting the grounded literal \bm{l} to the valid conjunction node using \mathtt{logical\_and} operation \land, and \bm{i}_{d}\in\mathbb{N}^{|\mathcal{G}|} specifies the edge connecting multiple conjunction node applied by the same rule to the disjunction node via \mathtt{logical\_or} operation \lor.

Differentiable Aggregation. Given the grounded literal valuations, NEUPRO performs two steps over the sparse reasoning graph:

  • All literals belonging to the same grounded clause are aggregated by a differentiable \land using product t-norm: \mathbf{h}_{\mathrm{conj}}=\mathrm{scatter\_prod}\left(\bm{1},\mathbf{l},\mathbf{i}_{\mathrm{c}},\mathrm{dim\_size}=N_{\mathrm{c}}\right), (3) where \bm{1} is a N_{\mathrm{c}} dimensional ones vector and N_{\mathrm{c}} is the total number of valid grounded conjunction nodes in the batch. The resulting value \mathbf{h}_{\mathrm{conj}} represents the soft truth value of the corresponding grounded rule body.: Multiple grounded conjunctions may satisfy the same safety rule. Therefore, NEUPRO aggregates all clauses associated with the same rule head into a rule-level satisfaction probability. We apply a differentiable Soft-OR aggregation to the disjunction node as: \bm{H}_{\mathrm{out}}= \mathrm{scatter\_softor_{\gamma}}\left(\mathbf{h}_{\mathrm{conj}},\mathbf{i}_{\mathrm{d}},\mathrm{dim\_size}=B\times C\right). (4) where C is the total number of clauses in the batch and \mathrm{softor}^{\gamma} is a smooth logical or function: \displaystyle\mathrm{softor}_{\gamma}(x_{1},\ldots,x_{n})=\gamma\log\sum\nolimits_{1\leq i\leq n}\exp(x_{i}/\gamma), (5) where \gamma>0 is a smooth parameter. Eq. 5 is an approximation of the max function over probabilistic values based on the log-sum-exp approach (Cuturi and Blondel 2017). The resulting vector \mathbf{H}_{\mathrm{out}}\in[0,1]^{B\cdot C} stores the satisfaction probabilities for all batch-rule pairs.

Finally, we reshape \bm{H}_{\mathrm{out}} into a rule-satisfaction matrix

\mathbf{P}=\mathrm{reshape}\left(\bm{H}_{\mathrm{out}},[B,C]\right),
(6)

where each entry \mathbf{P}[t,i]=\bm{H}_{\mathrm{out}}[t\cdot C+i] represents NEUPRO’s predicted probability that observation s_{t} satisfies safety rule F_{i}.

Because the reasoning procedure is implemented using differentiable indexing and scatter operations, gradients can propagate from rule-level supervision back to the underlying perceptual grounding network. At the same time, the intermediate conjunction nodes and sparse edges preserve an interpretable correspondence between grounded predicates, rule bodies, and final safety predictions.

Learning Objective

NEUPRO is trained to match rule-level safety satisfaction. For each observation s_{t} and safety rule F_{i}\in\mathcal{K}, let y_{t,i}\in\{0,1\} where y_{t,i}=1 indicates that s_{t} satisfies rule F_{i}, and y_{t,i}=0 indicates a violation. NEUPRO predicts

\hat{y}_{t,i}=P(F_{i}=\mathrm{True}\mid s_{t};\theta)=\mathbf{P}[t,i].
(7)

Since not every rule is active for every observation, we use an active constraint mask \mathbf{M}\in\{0,1\}^{B\times C}, where \mathbf{M}_{t,i}=1 indicates that rule F_{i} should contribute to the loss for observation s_{t}. The masked binary cross-entropy loss is then \mathcal{L}(\theta)=

\displaystyle-\sum_{t=1}^{B}\sum_{i=1}^{C}\mathbf{M}_{t,i}\Big[y_{t,i}\log\hat{y}_{t,i}+(1-y_{t,i})\log(1-\hat{y}_{t,i})\Big].

This objective encourages NEUPRO to assign high satisfaction probabilities to valid safety rules and low satisfaction probabilities to violated rules. As a result, the perception module learns representations that are directly shaped by symbolic safety semantics, while the differentiable reasoner provides an interpretable and end-to-end trainable bridge between observations and logical constraint satisfaction.

4 Experiments

With NEUPRO at hand, we now evaluate NEUPRO’s capability. Specifically, we aim to answer the following research questions: RQ1: Can NEUPRO effectively learn safety-related predicates from images through reasoner supervision? RQ2: Can NEUPRO accurately identify safety violation from visual observations? RQ3: Can NEUPRO provide explanations for safety violation? RQ4: Can learned predicates transfer to different objects and task configurations? RQ5: Can NEUPRO flexibly reason about safety violations, rather than relying on fixed object-relation associations? RQ6: Does NEUPRO enable scalable predicate learning and inference?

Benchmark datasets.

Existing robot safety datasets, such as OopsieVerse (Balaji et al. 2026), often supervise models with trajectory-level risk scores or binary safe/unsafe labels. While useful for assessing whether a safety violation occurs, such supervision typically could not be reason which safety conditions is violated from visual input. This limits the evaluation of models that aim to ground and reason over human-understandable safety concepts. To address this gap, we collect and introduce REASON, a rule-grounded real-robot benchmark dataset for interpretable safety reasoning from visual observations. REASON covers robot–environment and robot–human safety scenarios. Each observation is paired with safety-relevant predicates, human-specified symbolic constraints, and safety labels, enabling evaluation of the full perception-to-reasoning pipeline: grounding safety-critical concepts from raw images, composing them through executable rules, and identifying the conditions responsible for each safety decision. To facilitate reproducible research, we will open-source REASON together with the annotation tool used to create its predicate annotations, symbolic constraints, and rule-level safety labels. Collectively, these tasks require recognizing object properties, spatial configurations, manipulation states, and human-directed object motion. See App. B for a detailed description of individual tasks.

Experimental Setup and evaluation metrics.

For each task, NEUPRO receives a RGB image observation and predicts safety scores. The safety score is used both as a safety prediction and as a learning signal for the visual feature extractor. We evaluate safety recognition using accuracy, precision, recall and F1 score as our evaluation metric.

Baselines.

We compare NEUPRO with six baselines, including: a Black-box classifier: a neural classifier trained end-to-end to predict binary safe/unsafe labels directly from image observations. Vision Language Models (VLMs): We use Qwen3.5 9B (Qwen Team 2026) and DeepSeek-VL2 4B (Wu et al. 2024) to classify each observation as safe or unsafe. VLMs + in-context learning (ICL): We provide Qwen3.5 9B (Qwen Team 2026) and DeepSeek-VL2 4B (Wu et al. 2024) with task-specific classification rules in the prompt and ask them to infer whether each scene violates the corresponding safety constraint. Tensor-based Reasoner: Furthermore, we compare NEUPRO with a tensor-based variant that adopts tensor reasoner (Shindo et al. 2023) as its backbone. Experiments are running on a RTX A6000 GPU with 48GB RAM. Architectural details of the black-box classifier and MLP within NEUPRO are in App. C.

Figure 3: NEUPRO accurately learns predicates through differentiable reasoner supervision from raw images. NEUPRO outperforms baseline methods in predicate grounding accuracy. For readability, only mean accuracy is shown. Details see RQ1.
Table 2: NEUPRO accurately infer safety outcomes from raw visual observation. Safety classification accuracy comparison across all REASON tasks with baseline methods (the higher, the better, best performing bolded). Results averaged over five test groups with std, details see RQ2. ICL denotes in-context learning.
  • Black-box classifier
    Tasks Cabinet
    0.84\pm0.09
    Tasks Near
    0.96\pm0.04
    Tasks Above
    0.79\pm0.08
    Tasks Collision
    0.98\pm0.05
    Tasks Close
    0.96\pm0.05
    Tasks Pointing
    0.98\pm0.04
    Tasks All task
    0.86\pm0.14
    Tasks
    N/A
  • DeepSeek-VL2 (ICL)
    Tasks Cabinet
    0.41\pm0.11
    Tasks Near
    0.5\pm0.11
    Tasks Above
    0.54\pm0.07
    Tasks Collision
    0.3\pm0.24
    Tasks Close
    0.31\pm0.07
    Tasks Pointing
    0.4\pm0.06
    Tasks All task
    0.33\pm0.16
    Tasks
    0.48\pm0.03
  • Qwen3.5 (ICL)
    Tasks Cabinet
    0.49\pm0.02
    Tasks Near
    0.61\pm0.02
    Tasks Above
    0.39\pm0.02
    Tasks Collision
    0.68\pm0.16
    Tasks Close
    0.52\pm0.14
    Tasks Pointing
    0.82\pm0.04
    Tasks All task
    0.57\pm0.16
    Tasks
    0.55\pm0.04
  • DeepSeek-VL2
    Tasks Cabinet
    0.41\pm0.01
    Tasks Near
    0.51\pm0.06
    Tasks Above
    0.53\pm0.04
    Tasks Collision
    0.31\pm0.09
    Tasks Close
    0.39\pm0.02
    Tasks Pointing
    0.21\pm0.06
    Tasks All task
    0.31\pm0.03
    Tasks
    0.44\pm0.04
  • Qwen3.5
    Tasks Cabinet
    0.5\pm0.02
    Tasks Near
    0.62\pm0.01
    Tasks Above
    0.39\pm0.0
    Tasks Collision
    0.78\pm0.03
    Tasks Close
    0.75\pm0.0
    Tasks Pointing
    0.8\pm0.11
    Tasks All task
    0.77\pm0.02
    Tasks
    0.55\pm0.04
  • NEUPRO (ours)
    Tasks Cabinet
    1.0\pm0.0
    Tasks Near
    0.96\pm0.06
    Tasks Above
    0.99\pm0.03
    Tasks Collision
    1.0\pm0.0
    Tasks Close
    1.0\pm0.0
    Tasks Pointing
    1.0\pm0.0
    Tasks All task
    0.92\pm0.08
    Tasks
    0.92\pm0.02
RQ1:

NEUPRO accurately learns safety-relevant predicates from raw images through differentiable reasoner supervision. We evaluate the accuracy of eight predicates learned by NEUPRO. For each predicate, we use five test images and compute the mean accuracy of the corresponding grounded atoms. Fig. 3 compares NEUPRO with Qwen3.5 and DeepSeek-VL2 across all eight predicates. NEUPRO achieves the highest accuracy, whereas the VLM baselines exhibit substantially lower and less consistent performance, particularly on relational (e.g., occluded) and human-interaction predicates (e.g., point_to_human). These results show that safety supervision propagated through the differentiable reasoner effectively guides the perception module to ground accurate and safety-relevant predicates from visual observations. Prompts and other metrics in App. D.

Figure 4: Qualitative example of safety violation explanations produced by NEUPRO, in the form of first-order logic rules and atoms. In this scene, the grounded atoms indicate that the robot is holding scissors and is close to a person, from which NEUPRO infers an unsafe prediction through the corresponding first-order logic rule.
RQ2:

NEUPRO accurately infers safety outcomes directly from raw visual observations. Building on the learned safety-relevant predicates, we next evaluate whether NEUPRO can compose them through symbolic rules to correctly determine whether a scene satisfies or violates a safety constraint. We conduct this evaluation across all seven REASON tasks and report task accuracy, defined as the percentage of test scenes for which the predicted safety outcome is correct. Tab. 2 compares NEUPRO with task-specific black-box MLP classifiers, VLM-based baselines, and VLM-based in-context learning(ICL) baselines. The MLP baseline is trained separately for each task and therefore does not support evaluation in the joint all-task setting. In contrast, NEUPRO can be adapted to additional tasks by extending the rule base without redesigning the underlying safety-reasoning mechanism. All results are averaged over five test groups and reported with standard deviations. Overall, NEUPRO achieves consistently strong accuracy across tasks, demonstrating that its learned predicates can be effectively composed for end-to-end safety reasoning from raw images. Although VLMs can be applied across multiple tasks, they achieve substantially lower accuracy (even when task rules are provided in context), highlighting the advantage of explicit predicate grounding and symbolic reasoning. We provide the prompt, the black-box classifier architecture, and other metrics in App. E.

Figure 5: NEUPRO learned predicates are transferrable. Object-level generalization evaluates whether predicates remain accurate when applied to different object instances or categories. Task-level generalization compares predicates trained directly on a target task with predicates transferred from another task. NEUPRO retains high accuracy under both settings, demonstrating that its learned representations are reusable across objects and tasks. Details see RQ4.
RQ3:

NEUPRO can explain safety violations. A key advantage of NEUPRO is its ability to provide interpretable safety explanations. We now qualitatively demonstrate this capability. Unlike black-box classifiers that only output a safe/unsafe label, NEUPRO infers safety by composing atoms through interpretable logic rules. As shown in Fig. 4, the scene is predicted as unsafe because the grounded rule is satisfied by atoms indicating that the robot gripper is holding a scissor and that the scissor is close to a person.

Table 3: NEUPRO supports flexible safety reasoning with commonsense knowledge. We evaluate whether each method distinguishes identical spatial relations with different object properties: hard vs. soft objects above a laptop, and sharp vs. non-sharp objects close to a person. Results are reported as mean accuracy with std. See RQ5 for details.
  • NEUPRO (ours)
    Above_Laptop Soft
    1.0\pm0.0
    Above_Laptop Sharp
    1.0\pm0.0
    Close_Person N.sha
    1.0\pm0.0
    Close_Person
    1.0\pm0.0
  • Qwen3.5
    Above_Laptop Soft
    0\pm0.0
    Above_Laptop Sharp
    0.96\pm0.08
    Close_Person N.sha
    0.04\pm0.08
    Close_Person
    0.96\pm0.08
  • Qwen3.5(ICL)
    Above_Laptop Soft
    0.36\pm0.15
    Above_Laptop Sharp
    0.76\pm0.08
    Close_Person N.sha
    0.6\pm0.28
    Close_Person
    0.92\pm0.10
  • DeepSeek-VL2
    Above_Laptop Soft
    0.64\pm0.15
    Above_Laptop Sharp
    0.32\pm0.20
    Close_Person N.sha
    0.72\pm0.16
    Close_Person
    0.36\pm0.08
  • DeepSeek-VL2(ICL)
    Above_Laptop Soft
    0.56\pm0.29
    Above_Laptop Sharp
    0.44\pm0.32
    Close_Person N.sha
    0.84\pm0.08
    Close_Person
    0.4\pm0.22
RQ4:

NEUPRO learned predicates can be transferred to different objects and tasks. Since NEUPRO grounds safety concepts as semantic predicates rather than task-specific labels, predicates learned in one context can be reused by other safety rules that require the same underlying concepts. We evaluate predicate transfer under two settings. (i) object-level generalization measures whether a predicate learned from one set of object instances or categories remains accurate when applied to unseen objects. (ii) task-level generalization evaluates whether a predicate learned in one task can be reused in a different task that requires the same underlying semantic concept e.g., predicates such as closeby may appear in multiple tasks involving different objects or interaction scenarios. Fig. 5 summarizes the accuracy results over five test groups, details and other metrics see App. F. In both settings, NEUPRO is evaluated on tasks/objects that differ from those used during training. Results show that NEUPRO maintains strong performance under such transfer settings, suggesting that it learns reusable safety-relevant representations rather than task-specific visual shortcuts.

RQ5:

NEUPRO can reason about safety specifications beyond fixed object-relation associations by incorporating commonsense knowledge. We evaluate this capability in two tasks in which the same spatial relation yields different safety outcomes depending on the manipulated object. In the first task, holding a hard object, e.g., a cup, above a laptop is unsafe, whereas holding a soft object, e.g., a towel, in the same position is safe. In the second task, holding a sharp object close to a person is unsafe, whereas a non-sharp object in the same spatial configuration is safe. Solving these tasks requires grounding the relevant visual relations and combining them with background knowledge about object attributes. Tab. 3 reports accuracy results over five test groups, details, and other metrics in App. G. Results show that NEUPRO supports flexible safety reasoning and avoids relying on fixed visual associations between relations and safety labels.

Figure 6: NEUPRO supports scalable training and inference through graph-based reasoning. We compare graph-based NEUPRO with its tensor-based variant. NEUPRO achieves 9.1\times faster training, 14.3\times lower memory usage and 1.6\times faster inference, demonstrating substantially better scalability. Details see RQ6.
RQ6:

NEUPRO supports scalable safety predicate learning and inference due to its graph-based differentiable reasoning. We compare graph-based NEUPRO with its tensor-based variant using all tasks in REASON, and evaluate both methods in terms of training time, peak GPU memory usage, and inference time. Fig. 6 summarizes the comparison results. While achieving the same accuracy, graph-based NEUPRO yields 9.1\times faster training, 14.3\times lower peak GPU memory usage, and 1.6\times faster inference. Note that we use 102 rules in this evaluation. As the number of rules increases, the efficiency advantage of graph-based reasoning is expected to become even larger.

5 Limitations

Although NEUPRO demonstrates strong capability for interpretable and flexible safety reasoning, several limitations remain and open promising directions for future work. First, NEUPRO’s reasoning performance depends on the quality and coverage of the safety rules and background knowledge. If a safety condition is missing or the knowledge base lacks the relevant object properties, NEUPRO may fail to identify the corresponding violation. Second, NEUPRO currently focuses on visual safety reasoning from static observations, and its performance relies on the underlying vision backbone grounding DINO. When grounding DINO fails to detect an object, NEUPRO lacks information about that object. Third, many real-world safety constraints are inherently temporal, involving motion trends or future consequences of an action. Incorporating temporal predicates and predictive world models would allow NEUPRO to reason about evolving safety risks, such as whether a moving object is likely to fall or collide. Fourth, although the REASON dataset contains images from multiple viewpoints, only one image is used during inference. Incorporating multi-view reasoning could improve the model’s robustness, particularly when a single view is affected by occlusion.

6 Conclusion

We presented NEUPRO, a neuro-symbolic framework for interpretable and flexible robot safety reasoning from visual observations. NEUPRO alleviates the non-interpretable and inflexible limitations of previous work by representing safety specifications as interpretable first-order logic rules. NEUPRO supports scalable predicate learning and safety reasoning from raw images due to its graph-based reasoning. Furthermore, we introduced REASON, the first real-robot benchmark for interpretable safety specification. Experiments on REASON validate NEUPRO’s interpretability, flexibility, and scalability. Overall, NEUPRO provides a transparent and reusable alternative to task-specific scalar costs and opaque safety representations. By connecting raw perception, symbolic knowledge, and differentiable reasoning, NEUPRO provides a promising foundation for robot learning systems that deliver accurate, interpretable, transferable, and scalable safety decisions.

7 Acknowledgements

This work was funded by the Deutsche Forschungsgemeinschaft (DFG, German Research Foundation) under Germany’s Excellence Strategy – EXC-3066, “The Adaptive Mind”, and EXC-3057, “Reasonable AI”. It was also funded by the German Federal Ministry of Education and Research, the Hessian Ministry of Higher Education, Research, Science and the Arts (HMWK) within their joint support of the National Research Center for Applied Cybersecurity ATHENE, via the “SenPai: XReLeaS” project. This work also benefits from DFG Emmy Noether Programme (CH 2676/1-1), the EU Horizon Europe projects MANiBOT (101120823) and ARISE (101135959), the BMFTR project RIG (16ME1001), and the ERC project SIREN (101163933). We also acknowledge support from the hessian.AI Service Center (BMFTR, 16IS22091), the hessian.AI Innovation Lab (S-DIW04/0013/003), Google, and the Alfried Krupp Foundation.

References

  1. Achiam et al. (2017) J. Achiam, D. Held, A. Tamar, and P. Abbeel Constrained policy optimization. In International conference on machine learning,
  2. Alshiekh et al. (2018) M. Alshiekh, R. Bloem, R. Ehlers, B. Könighofer, S. Niekum, and U. Topcu Safe reinforcement learning via shielding. In Proceedings of the AAAI conference on artificial intelligence,
  3. Ames et al. (2019) A. D. Ames, S. Coogan, M. Egerstedt, G. Notomista, K. Sreenath, and P. Tabuada Control barrier functions: theory and applications. In 2019 18th European control conference (ECC),
  4. Balaji et al. (2026) A. Balaji, A. Bahety, S. Ambatipudi, D. Lam, J. Xu, and R. Martín-Martín OopsieVerse: a safety benchmark with damage-aware simulation for robot manipulation. In Robotics: Science and Systems (RSS), 2026,
  5. Brunke et al. (2022) L. Brunke, M. Greeff, A. W. Hall, Z. Yuan, S. Zhou, J. Panerati, and A. P. Schoellig Safe learning in robotics: from learning-based control to safe reinforcement learning. Annual Review of Control, Robotics, and Autonomous Systems.
  6. Brunke et al. (2025) L. Brunke, Y. Zhang, R. Römer, J. Naimer, N. Staykov, S. Zhou, and A. P. Schoellig Semantically safe robot manipulation: from semantic scene understanding to motion safeguards. IEEE Robotics and Automation Letters.
  7. Chitnis et al. (2022) R. Chitnis, T. Silver, J. B. Tenenbaum, T. Lozano-Perez, and L. P. Kaelbling Learning neuro-symbolic relational transition models for bilevel planning. In 2022 IEEE/RSJ international conference on intelligent robots and systems (IROS),
  8. Cuturi and Blondel (2017) M. Cuturi and M. Blondel Soft-dtw: a differentiable loss function for time-series. In Proceedings of the 34th International Conference on Machine Learning (ICML),
  9. Evans and Grefenstette (2018) R. Evans and E. Grefenstette Learning explanatory rules from noisy data. J. Artif. Intell. Res..
  10. Ganai et al. (2023) M. Ganai, Z. Gong, C. Yu, S. Herbert, and S. Gao Iterative reachability estimation for safe reinforcement learning. Advances in Neural Information Processing Systems.
  11. Garcıa and Fernández (2015) J. Garcıa and F. Fernández A comprehensive survey on safe reinforcement learning. Journal of Machine Learning Research.
  12. Günster et al. (2024) J. Günster, P. Liu, J. Peters, and D. Tateo Handling long-term safety and uncertainty in safe reinforcement learning. arXiv preprint arXiv:2409.12045.
  13. Haddadin et al. (2017) S. Haddadin, A. De Luca, and A. Albu-Schäffer Robot collisions: a survey on detection, isolation, and identification. IEEE Transactions on Robotics.
  14. Keller et al. (2025) L. Keller, D. Tanneberg, and J. Peters Neuro-symbolic imitation learning: discovering symbolic abstractions for skill learning. In 2025 IEEE International Conference on Robotics and Automation (ICRA),
  15. Kim et al. (2023) K. Kim, G. Swamy, Z. Liu, D. Zhao, S. Choudhury, and S. Wu Learning shared safety constraints from multi-task demonstrations. In Thirty-seventh Conference on Neural Information Processing Systems,
  16. Lasota et al. (2017) P. A. Lasota, T. Fong, and J. A. Shah A survey of methods for safe human-robot interaction. Foundations and Trends® in Robotics.
  17. Liang et al. (2025) Y. Liang, N. Kumar, H. Tang, A. Weller, J. B. Tenenbaum, T. Silver, J. F. Henriques, and K. Ellis Visualpredicator: learning abstract world models with neuro-symbolic predicates for robot planning. In International Conference on Learning Representations,
  18. Lindner et al. (2024) D. Lindner, X. Chen, S. Tschiatschek, K. Hofmann, and A. Krause Learning safety constraints from demonstrations with unknown rewards. In International Conference on Artificial Intelligence and Statistics,
  19. Liu et al. (2025) P. Liu, H. Bou-Ammar, J. Peters, and D. Tateo Safe reinforcement learning on the constraint manifold: theory and applications. IEEE Transactions on Robotics.
  20. Liu et al. (2022a) P. Liu, D. Tateo, H. B. Ammar, and J. Peters Robot reinforcement learning on the constraint manifold. In Conference on Robot Learning,
  21. Liu et al. (2023a) P. Liu, K. Zhang, D. Tateo, S. Jauhri, Z. Hu, J. Peters, and G. Chalvatzaki Safe reinforcement learning of dynamic high-dimensional robotic tasks: navigation, manipulation, interaction. In 2023 IEEE International Conference on Robotics and Automation (ICRA),
  22. Liu et al. (2023b) S. Liu, Z. Zeng, T. Ren, F. Li, H. Zhang, J. Yang, C. Li, J. Yang, H. Su, J. Zhu, et al. Grounding dino: marrying dino with grounded pre-training for open-set object detection. arXiv preprint arXiv:2303.05499.
  23. Liu et al. (2022b) Z. Liu, Z. Cen, V. Isenbaev, W. Liu, S. Wu, B. Li, and D. Zhao Constrained variational policy optimization for safe reinforcement learning. In International Conference on Machine Learning,
  24. Qwen Team (2026) Qwen Team Qwen3.5: towards native multimodal agents. External Links: Link
  25. Selim et al. (2022) M. Selim, A. Alanwar, S. Kousik, G. Gao, M. Pavone, and K. H. Johansson Safe reinforcement learning using black-box reachability analysis. IEEE Robotics and Automation Letters.
  26. Shindo et al. (2021) H. Shindo, M. Nishino, and A. Yamamoto Differentiable inductive logic programming for structured examples. In Proceedings of the 35th AAAI Conference on Artificial Intelligence (AAAI),
  27. Shindo et al. (2023) H. Shindo, V. Pfanschilling, D. S. Dhami, and K. Kersting \alpha Ilp: thinking visual scenes as differentiable logic programs. Machine Learning.
  28. Shindo et al. (2024) H. Shindo, V. Pfanschilling, D. S. Dhami, and K. Kersting Learning differentiable logic programs for abstract visual reasoning. Machine Learning.
  29. Silver et al. (2022) T. Silver, A. Athalye, J. B. Tenenbaum, T. Lozano-Pérez, and L. P. Kaelbling Learning neuro-symbolic skills for bilevel planning. In Conference on Robot Learning,
  30. Wachi et al. (2024) A. Wachi, X. Shen, and Y. Sui A survey of constraint formulations in safe reinforcement learning. In Proceedings of the Thirty-Third International Joint Conference on Artificial Intelligence,
  31. Wu et al. (2024) Z. Wu, X. Chen, Z. Pan, X. Liu, W. Liu, D. Dai, H. Gao, Y. Ma, C. Wu, B. Wang, et al. Deepseek-vl2: mixture-of-experts vision-language models for advanced multimodal understanding. arXiv preprint arXiv:2412.10302.
  32. Xiao et al. (2025) W. Xiao, T. Wang, C. Gan, and D. Rus ABNet: adaptive explicit-barrier net for safe and scalable robot learning. In Forty-second International Conference on Machine Learning,
  33. Xiao et al. (2023) W. Xiao, T. Wang, R. Hasani, M. Chahine, A. Amini, X. Li, and D. Rus Barriernet: differentiable control barrier functions for learning of safe robot control. IEEE Transactions on Robotics.
  34. Yang et al. (2023) W. Yang, G. Marra, G. Rens, and L. De Raedt Safe reinforcement learning via probabilistic logic shields. In Proceedings of the Thirty-Second International Joint Conference on Artificial Intelligence,
  35. Ye et al. (2025) Z. Ye, O. Arenz, and K. Kersting Learning from less: guiding deep reinforcement learning with differentiable symbolic planning. In RLC 2025 Workshop on Programmatic Reinforcement Learning,
  36. Ye et al. (2022) Z. Ye, H. Shindo, D. S. Dhami, and K. Kersting Neural meta-symbolic reasoning and learning. arXiv preprint arXiv:2211.11650.
  37. Yu et al. (2022) D. Yu, H. Ma, S. Li, and J. Chen Reachability constrained reinforcement learning. In International conference on machine learning,
  38. Zhao et al. (2023) W. Zhao, T. He, R. Chen, T. Wei, and C. Liu State-wise safe reinforcement learning: a survey. In Proceedings of the Thirty-Second International Joint Conference on Artificial Intelligence,