Shifat Santo

muzzle and imp

A hardware firewall on a robot's servo bus: the brain proposes, a few-dollar chip disposes.

Aug to Sep 2026Open source

0 of 9adversarial breaches with the barrier filter on, 9 of 9 with it off

imp is a desk robot with an untrusted brain and a hardware conscience. The design puts safety below the host, on the servo bus, so a compromised or confused controller cannot command a joint past what a control-barrier filter allows. In simulation, adversarial commands breach the safe set in 9 of 9 episodes with the filter off and 0 of 9 with it on, while the benign task is unaffected. The filter runs today in Python on the host (median 86 microseconds); muzzle is the groundwork for moving it onto the bus.

muzzle is the layer that makes that possible on real hardware: a streaming parser and encoder for the Feetech STS bus that the LeRobot SO-101 arm runs on, in C++17 with no heap, no exceptions and no RTTI, on an ESP32-C3. At 1 Mbps a byte lands every 10 microseconds, so the parser does constant work per byte and never backtracks.

It is checked three ways: unit tests built on the manufacturer's example frames under AddressSanitizer and UBSan, a differential fuzzer against an independently written whole-buffer parser, and cycle counts measured on the chip.