---
title: Poisson Safety Function (PSF) in Robotics
url: https://www.emergentmind.com/topics/poisson-safety-function-psf
type: topic
---

# Poisson Safety Function (PSF) in Robotics

In recent robotics and safety-filtering work, a Poisson Safety Function (PSF) is a smooth scalar function obtained by solving a Dirichlet problem for Poisson’s equation on free space, with the safe region defined by its \(0\)-superlevel set. In the basic formulation, \(h(y) > 0\) denotes safe interior states, \(h(y)=0\) the boundary of the safe set, and \(h(y)<0\) unsafe states or states outside the safe set. The construction is used as a safety certificate and as a control barrier function (CBF) ingredient in dynamic collision avoidance, risk-aware safety filters, geometry-aware predictive control, and full-body manipulator safety [2510.25913, 2505.06794].

## 1. Core definition and Poisson formulation

The canonical PSF definition treats safety as a sign structure on a scalar field. One paper states the safe set as
\[
C = \{y \in \Omega : h(y) \geq 0\}, \qquad \partial C = \{y \in \Omega : h(y) = 0\}, \qquad \mathrm{Int}(C) = \{y \in \Omega : h(y) > 0\},
\]
so the \(0\)-superlevel set is the safe set and the zero level set is the boundary [2510.25913]. In the layered-safety formulation for robot navigation, the PSF is similarly denoted \(h_0\), with \(\Omega\) taken as an open, bounded, connected free-space domain whose boundary corresponds to obstacle surfaces [2603.00338].

The defining PDE is a Dirichlet problem for Poisson’s equation:
\[
\left\{ \begin{aligned}
\Delta h(y) &= f(y) && \text{in } \Omega, \\
h(y) &= 0 && \text{on } \partial \Omega,
\end{aligned} \right.
\]
with
\[
\Delta = \frac{\partial^2 }{\partial x^2} + \frac{\partial^2 }{\partial y^2} + \frac{\partial^2 }{\partial z^2},
\qquad
f(y) < 0 \quad \text{for all } y \in \Omega.
\]
Across the relevant papers, the boundary condition places the obstacle surface at the zero level set, while the negative forcing term is chosen so that the solution is positive in free space and has the boundary-gradient sign needed for repulsion [2510.25913, 2508.11129].

A standard interpretation follows from Hopf’s lemma: solving the Poisson equation with negative forcing implies
\[
Dh(y)\cdot \hat{n}(y) < 0 \quad \text{for all } y \in \partial\Omega.
\]
This makes the gradient point inward relative to the obstacle boundary and is the key analytic fact behind barrier-style safety guarantees [2510.25913].

## 2. Analytic properties and safe-set semantics

The PSF construction is used because it yields a smooth, globally defined safety field rather than a binary occupancy indicator. Several papers state that if the forcing is smooth, then the solution is smooth; for example, \(f \in C^\infty(\Omega)\) implies \(h \in C^\infty(\Omega)\), and one theoretical result is stated for \(f \in C^{k,\alpha}(\Omega;\mathbb{R}_{<0})\), yielding a safety function of order \(2+k\) [2505.06794].

The sign structure is tied to classical elliptic theory. One paper states that \(f<0\) implies
\[
\Delta h < 0 \quad \text{in } \Omega,
\]
so \(h\) is superharmonic. By the weak minimum principle, the minimum is attained on the boundary, and since \(h=0\) on \(\partial\Omega\), the interior satisfies \(h(y)\ge 0\) in the free-space domain. Hopf’s lemma then gives a nonzero boundary gradient, so the zero level set is not merely symbolic but has the differential structure needed by barrier-based control [2505.06794].

The same paper gives a variational formulation. In the direct forcing form,
\[
J[h] = \iiint_{\Omega}\left(\frac{1}{2}\lVert Dh(y)\rVert^2 + h(y)f(y)\right)\,dV,
\]
with admissible set
\[
H=\{h\in C^2(\Omega)\mid h=0 \text{ on } \partial\Omega\}.
\]
The Euler–Lagrange equation is precisely \(\Delta h=f\). A closely related formulation starts from a smooth guidance vector field \(\vec v\) and minimizes
\[
I[h] = \iiint_{\Omega}\frac{1}{2}\lVert Dh(y)-\vec v(y)\rVert^2\,dV,
\]
which, after integration by parts with \(h|_{\partial\Omega}=0\), yields \(\Delta h=\nabla\cdot \vec v\). The corresponding minimizer is unique [2505.06794].

The PSF is also distinguished from a signed distance function. One manipulator paper explicitly contrasts the Poisson construction with signed distance functions, noting that signed distance functions may lose differentiability inside free space when the closest obstacle is not unique, whereas the Poisson construction gives a smooth task-space barrier field suitable for CBF inequalities and QPs [2604.21189].

## 3. Guidance fields, flux modulation, and risk-aware shaping

A major extension of the PSF framework is the introduction of a separately synthesized guidance field. In the risk-aware formulation, a vector field \(v \in C^k(\overline{\Omega};\mathbb{R}^3)\) is called a guidance field if, on the boundary,
\[
v(y)\cdot \hat{n}(y) = b(y), \qquad v(y)\parallel \hat{n}(y), \qquad b(y)\in \mathbb{R}_{<0}.
\]
The field is obtained componentwise by solving harmonic Dirichlet problems,
\[
\left\{ \begin{aligned}
\Delta v_i(y) &= 0 && \text{in } \Omega, \\
v_i(y) &= b(y)n_i(y) && \text{on } \partial\Omega,
\end{aligned} \right.
\qquad i\in\{x,y,z\},
\]
so the prescribed boundary flux is smoothly extended into the interior [2510.25913].

This guidance field is generally nonconservative. The formulation does not require \(v=\nabla h\); instead, \(h\) and \(v\) play different roles. The PSF defines where safety is, while the guidance field shapes how strongly and where the controller reacts [2510.25913].

Risk-awareness enters through the boundary flux \(b(y)\). One paper gives the pipeline
\[
\text{State} \to \text{Feature} \to \text{Priority} \to \text{Assigned Risk} \to \text{Flux}.
\]
Obstacle features such as uncertainty, speed, and semantic class are converted into a user-defined priority and then mapped to flux values. The paper states that larger magnitude \(\lvert b(y)\rvert\) gives steeper repulsion, steeper repulsion yields larger activation zones, and larger activation zones make the controller react earlier and more conservatively. Smaller \(\lvert b(y)\rvert\) yields weaker repulsion and less conservative behavior [2510.25913].

A semantic extension appears in "Safe-SAGE" [2603.05497]. There, a Laplace guidance field is modulated on two boundaries: normal repulsion on the actual obstacle boundary \(\partial\Omega\), and tangential flow on a buffered interface
\[
\overline{\Omega}_r = \overline{\Omega}\ominus B_r.
\]
The boundary-value problem is
\[
\begin{cases}
\Delta v_i(\mathbf{q}) = 0, & \mathbf{q}\in \Omega\setminus \partial\Omega_r, \\
v_i(\mathbf{q}) = \lambda(\mathbf{q})\,\hat\tau_i(\mathbf{q}), & \mathbf{q}\in \partial\Omega_r, \\
v_i(\mathbf{q}) = b(\mathbf{q})\,\hat n_i(\mathbf{q}), & \mathbf{q}\in \partial\Omega,
\end{cases}
\qquad i\in\{x,y\},
\]
with \(\lambda(\mathbf q)<0\) controlling social flow magnitude and \(b(\mathbf q)<0\) controlling repulsion magnitude. This allows obstacle-class-dependent conservatism and directional passing norms such as pass-on-the-right or pass-on-the-left [2603.05497].

The forcing term itself can also be constructed from a guidance field. In one synthesis method,
\[
f(y)=\nabla\cdot \vec v(y),
\]
followed by the smooth negative transformation
\[
f(y) = -\frac{1}{\beta}\ln\!\big(1+e^{-\beta \nabla\cdot \vec v(y)}\big), \qquad \beta>0,
\]
which guarantees \(f(y)<0\) while preserving smoothness [2505.06794].

## 4. Control barrier integration and safety-filter architectures

The PSF is used operationally by inserting it into safety filters. For the single-integrator system
\[
\dot{y} = w,
\]
one risk-aware filter solves
\[
k_\mathrm{QP}(y) = \arg\min_{w \in \mathbb{R}^3} \|w - k_\mathrm{nom}(y)\|_2^2
\]
subject to
\[
v(y)\cdot w \ge -\gamma h(y).
\]
Here \(k_\mathrm{nom}(y)\) is the nominal controller, \(\gamma>0\) is the barrier gain, \(h\) is the PSF, and \(v\) is the Laplace guidance field. The closed-form solution is reported as
\[
k_{\mathrm{QP}}(y) = k_{\mathrm{nom}}(y) + \frac{\mathrm{ReLU}(-a(y))}{\|v(y)\|^2}\,v(y),
\]
with
\[
a(y) := v(y)\cdot k_{\mathrm{nom}}(y) + \gamma h(y),
\qquad
\mathrm{ReLU}(-a(y)) = \max\{0,-a(y)\},
\]
and activation zone
\[
A \coloneqq \{\, y \in \Omega \mid a(y)=0 \,\}.
\]
If \(a(y)>0\), the filter is inactive; if \(a(y)\le 0\), it adds a correction in the direction of \(v(y)\) [2510.25913].

A more elaborate architecture appears in layered safety filtering. One framework uses the PSF as a CBF in two stages: a predictive safety layer and a real-time safety layer [2603.00338]. For the reduced-order single-integrator model
\[
\dot{\chi} = \mu, \qquad \mu = (v_x, v_y, \omega)\in \mathbb{R}^3,
\]
the predictive layer solves
\[
\underset{\nu_i}{\min } \quad \sum_{i=0}^{N} \left( \mu_\mathrm{d}- \nu_i\right)^\top R(\mu_\mathrm{d}- \nu_i)
\]
subject to
\[
\xi_0 = \chi, \qquad
\xi_{i+1} = \xi_i + \nu_i\delta_t, \qquad
h(\xi_{i+1},t_{i+1}) \geq \rho h(\xi_i,t_i).
\]
The first planned input is used as the safe nominal command. A second-stage real-time ISSf CBF-QP then solves
\[
\mu_\mathrm{s} = \argmin_{\mu \in \mathbb{R}^3} \|\mu - \mu_\mathrm{p}\|_2^2
\]
subject to
\[
\nabla h \cdot \mu + \frac{\partial h}{\partial t} \geq -\alpha h + \frac{1}{\varepsilon}\|\nabla h\|^2.
\]
Under the stated tracking assumptions, safety transfers to the full-order mechanical system through the barrier candidate
\[
B(\mathbf{q}, \dot{\mathbf{q}}, t) = h(\varphi(\mathbf{q}), t) - \frac{1}{\mu}V(\mathbf{q}, \dot{\mathbf{q}}, \dot{\chi}_\mathrm{s}, t),
\]
with the condition
\[
\lambda \geq \alpha + \frac{\varepsilon \mu}{4\beta}
\]
ensuring forward invariance of the full-order safe set [2603.00338].

A related predictive controller uses the PSF as a discrete-time CBF inside nonlinear MPC. In that setting, the reduced-order model is
\[
\dot \chi = \mu, \qquad \chi=[x,y,\theta]^\top, \qquad \mu=[v_x,v_y,\omega]^\top,
\]
and the horizon constraints take the form
\[
h_{QT}(\xi_{i+1},t_{i+1})\ge \rho\, h_{QT}(\xi_i,t_i),
\]
with the nonlinear, nonconvex problem solved by sequential quadratic programming [2508.11129].

## 5. Configuration-space, geometry-aware, and full-body generalizations

A central development is the extension from point-robot geometry to configuration-space safety. For legged robots, one paper defines the orientation-dependent safe set using the Pontryagin difference
\[
C(\theta) = C_0 \ominus \mathcal{R}(\theta),
\]
where \(\mathcal{R}(\theta)\subset\mathbb{R}^2\) is the robot footprint at orientation \(\theta\). The corresponding lifted domain is
\[
\Theta = \bigcup_{\theta\in \mathbb{S}^1} C(\theta) \times \{\theta\} \subset \mathbb{R}^2 \times \mathbb{S}^1,
\]
and the parameterized Poisson problem is
\[
\left\{
\begin{aligned}
\frac{\partial^2 h_0}{\partial x^2} + \frac{\partial^2 h_0}{\partial y^2} &= f(x,y,\theta) \quad &&\forall(x,y,\theta)\in \Theta,\\
h_0(x,y,\theta) &= 0 \quad &&\forall(x,y,\theta)\in \partial_\Theta.
\end{aligned}
\right.
\]
The resulting PSF depends on position and heading and captures collision avoidance in a way aligned with the robot’s actual body geometry [2603.00338].

A more general geometry-aware predictive framework uses Minkowski set operations in configuration space. There, the robot-aware safe set is
\[
C_Q(q)=C\ominus \mathcal{R}(q),
\]
with lifted domain
\[
\Omega_Q = \bigcup_{q\in S^3} C_Q(q)\times\{q\}\subset R^3\times S^3.
\]
For dynamic environments, the boundary is represented implicitly by a level-set function,
\[
\partial C_T(t) = \{y\in R^3 : \phi(y,t)=0\},
\]
with transport equation
\[
\frac{\partial \phi}{\partial t}(y,t) + \dot{y}(t)\cdot\nabla \phi(y,t)=0.
\]
The full geometry-and-time lifted domain is
\[
\Omega_{QT} = \bigcup_{q,t} C_{QT}(q,t)\times\{q\}\times\{t\},
\]
and the PSF is synthesized by solving
\[
\left\{
\begin{aligned}
\Delta_y h_{QT}(y,q,t) &= f(y,q,t), \\
h_{QT}(y,q,t) &= 0,
\end{aligned}
\right.
\]
on \(\Omega_{QT}\), with the Laplacian taken only with respect to the spatial variable \(y\) [2508.11129].

For manipulators, the PSF becomes a single smooth task-space barrier evaluated at many sampled surface points. One paper samples the manipulator surface with
\[
\mathcal{Y}=\{y_1,\dots,y_N\}\subset \mathcal{S}(q)
\]
subject to the coverage condition
\[
\forall p \in \mathcal{S}(q), \quad \min_i \|p-y_i\| < \varepsilon,
\]
equivalently
\[
\mathcal{S}(q)\subset \bigcup_{i=1}^N B_\varepsilon(y_i).
\]
The safe set is then buffered by the same resolution,
\[
C_\varepsilon = C \ominus B_\varepsilon.
\]
If \(y_i=\varphi_i(q)\) and \(\dot y_i = J_i(q)\dot q\), each sample generates the barrier constraint
\[
\dot h_\varepsilon(\varphi_i(q),t,v)\ge -\alpha_i\big(h_\varepsilon(\varphi_i(q),t)\big),
\]
and the safety filter is the multi-constraint QP
\[
v_{\text{safe}} = \arg\min_{v\in \mathbb{R}^n}\ \|v-v_{\text{nom}}\|_2^2
\]
subject to all sampled-point inequalities. The key theorem states that if every sample point lies in the buffered safe set \(C_\varepsilon(t)\) for all time, then the entire continuous robot surface remains inside the true safe set \(C(t)\) for all time [2604.21189].

## 6. Empirical demonstrations, tradeoffs, and terminological scope

The PSF literature emphasizes online synthesis from perception. In one dynamic-safety implementation, images from a fixed RGB camera are segmented with Meta SAM2, converted to a 2D occupancy map, buffered by robot size, and used to compute a guidance field and then a PSF. The PDE is discretized with a finite difference scheme and solved by Successive Overrelaxation on an \(N\times N\) grid with \(N=120\), using checkerboard iteration for GPU parallelization on an RTX 4070 GPU with \(10^{-4}\) residual tolerance. Reported solve times are about \(0.2\text{–}0.3\ \text{ms}\), with about \(10\) Hz overall update rate [2505.06794].

A geometry-aware predictive implementation uses an overhead ZED 2i stereo camera, robot pose from OptiTrack motion capture, segmentation by eTAM, and OpenCV optical flow to estimate boundary motion. The Poisson solve is reported at about \(20\text{–}100\) ms, and the MPC/SQP loop runs at \(100\) Hz using OSQP for the QP subproblems [2508.11129]. For manipulator safety, a Franka Emika FR3 in a \(100\times100\times100\) voxel occupancy grid uses approximately \(30\) sample points at \(\varepsilon=0.1\), with average PDE solve time about \(0.002\) s and average QP solve time about \(0.003\) s using OSQP [2604.21189].

The reported experimental behaviors are consistent across multiple robot classes. A layered PSF architecture for legged robots is reported to achieve a balance between optimality and robustness in slower dynamic scenarios, and in faster scenarios the layered method succeeds in all \(10\) trials while both single-stage filters experience failures [2603.00338]. A risk-aware formulation reports that larger \(\lVert b(y)\rVert\) creates steeper gradients and larger activation zones, while smaller \(\lVert b(y)\rVert\) creates smaller activation zones [2510.25913]. In the semantic Safe-SAGE ablation, flux modulation with
\[
b_{\text{human}}(\mathbf q)=-1.7,\qquad b_{\text{objects}}(\mathbf q)=-0.5
\]
is compared with a nominal baseline
\[
b_{\text{human}}(\mathbf q)=-1.0,\qquad b_{\text{objects}}(\mathbf q)=-1.0,
\]
and the reported metrics are a Human-robot Margin of \(0.318\pm 0.0774\) m versus \(-0.008\pm 0.0625\) m, and Max Lateral Offset of \(0.75\) m versus \(-0.1\) m [2603.05497].

The limitations are also explicit. One predictive paper states that safety cannot be formally guaranteed in general time-varying environments because future obstacle evolution is inherently uncertain [2508.11129]. Another notes deadlocks or undesired equilibria near obstacles, a familiar issue for non-predictive safety filters [2505.06794]. In the manipulator setting, the buffer radius \(\varepsilon\) creates a direct tradeoff: smaller \(\varepsilon\) gives more sample points, more CBF constraints, better geometric fidelity, and less conservatism, while larger \(\varepsilon\) gives fewer constraints and cheaper QPs but more buffering and more conservatism [2604.21189].

The acronym is not universal across fields. In astronomy and weak lensing, PSF ordinarily means Point Spread Function; one such paper studies spatially correlated residual PSF fluctuations and their effect on shear correlation functions [1712.09736]. In mitigation reliability analysis, the acronym PSF is not used; the relevant proposal is PDF-based modeling of mitigation performance and expected degree of failure, and the paper states explicitly that there is no Poisson Safety Function framing [2508.12814]. Outside robotics, related Poisson-based constructs may exist without the same name; for example, a flexible-skyline paper studies Poisson CDF-based monotone scoring functions but does not formally define a distinct “Poisson Safety Function” [2201.10217].

| Context | Meaning | Relation to PSF in robotics |
|---|---|---|
| Weak lensing [1712.09736] | Point Spread Function | Different acronym usage |
| Mitigation reliability [2508.12814] | Safety function as SF; PDF-based reliability model | No Poisson Safety Function terminology |
| Flexible skylines [2201.10217] | Poisson CDF-based scoring in \(F\)-skyline queries | Poisson-based, but not the robotics PSF construct |

Within robotics and control, the term therefore denotes a PDE-generated safety certificate: a smooth scalar field synthesized from occupancy data, with the obstacle boundary imposed as a zero Dirichlet boundary and free space represented by the positive superlevel set. Its importance lies in combining perception-derived geometry, elliptic regularity, CBF compatibility, and extensibility to risk-aware guidance, semantic modulation, moving boundaries, and full-body safety constraints [2505.06794, 2604.21189].

Source: https://www.emergentmind.com/topics/poisson-safety-function-psf