DENSE: Endowing Vision-Language-Action Models with Differentiable Neuro-Symbolic Shields
Abstract
Vision-language-action (VLA) models bring web-scale multimodal reason ing into robot control, but their action heads inherit no notion of phys ical safety: task reward optimizes what to do while remaining silent on what must never happen. Existing remedies trade safety against learn ability. Soft penalties blur the boundary and are discounted by the op timizer; hard shields (e.g., SMT-based action projection) zero the gradi ent exactly where supervision is most needed; and classical neuro-symbolic semantics based on product or Gödel t-norms suffer from vanishing or one-hot (sparse) gradients on conjunctive safety constraints. We propose DENSE, a Differentiable Endogenous Neuro-Symbolic Enforcer that com piles a first-order logic (FOL) physical specification Φ into a smooth barrier function inside the VLA action loop. DENSE fuzzifies atomic constraints with bounded sigmoids, aggregates them with a log-sum-exp soft-min, and shapes the resulting margin with a logarithmic barrier that behaves like an implicit neural control barrier function (CBF). We prove three properties of this construction: gradient density (every atomic constraint receives non vanishing weight wi ≥ e−β/k), non-vanishing repulsion near the boundary (∥∇BΦ∥ → ∞ as the margin approaches δ+), and exact recovery of Gödel semantics in the limit β → ∞. A discrete-time barrier certificate further guarantees forward invariance of the safe set, and a dual-loop (min–max) Lagrangian scheme balances task reward against the barrier cost without hand-tuned penalty weights. On three safety-critical manipulation and nav igation benchmarks built on ManiSkill3, DENSE attains a 90.1% success rate—within 2 points of the unconstrained policy—while reducing cumula tive constraint violations by two orders of magnitude (CC 0.27 vs. 47.4), eliminating the catastrophic long tail of soft penalties, and retaining its margin under out-of-distribution visual stress. Code, derivations, and full proofs are included.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.