July 23, 2026
We propose a notion of robust adaptive backup control barrier functions for nonlinear control affine systems with parametric uncertainty in both the drift dynamics and actuation matrix. Backup control barrier functions guarantee safety by predicting the system’s trajectory under a pre-certified safe controller. However, these predictions rely on the model and can be inaccurate when the system contains unknown parameters. To address this issue, we estimate the unknown parameters using element-wise certified adaptive estimators that provide a parameter adaptation law and component-wise estimation error bounds. We compute the backup flow using the estimated model and tighten the safety conditions using these certified bounds. The resulting safety conditions account for the sensitivity of the predicted flow to parameter estimation errors. Moreover, to handle uncertainty in the actuation matrix, we use a duality-based reformulation that enables the use of a computationally efficient quadratic-program-based safety filter. We prove that controllers satisfying the proposed robust adaptive backup control barrier function constraints guarantee safety under parametric uncertainty and input constraints.
0.892
Safety-critical control is essential for autonomous systems that operate in complex real-world environments. Control barrier functions (CBFs) provide a constructive framework for synthesizing controllers that render a prescribed safe set forward invariant, ensuring safety w.r.t. state constraints [1]. This can be realized by safety filters, often formulated as quadratic programs (QPs), that modify a nominal controller when safety necessitates intervention. However, CBF design requires a safe set in which feasible safe control inputs are available. Constructing such a set is difficult for input-constrained nonlinear systems, especially when the system must be steered close to the safe set boundary [2], [3].
Model predictive control (MPC) provides another way to handle state and input constraints. It predicts the system evolution over a finite horizon while enforcing constraints along the predicted trajectory. This makes MPC effective for constrained nonlinear systems, but recursive feasibility and safety guarantees require additional terminal conditions, invariant sets, or robustness margins. Adaptive MPC and robust sensitivity-based MPC reduce conservatism by updating model information online [4]–[6] or by propagating the effect of parametric uncertainty along the prediction horizon [7].
Backup control barrier functions (bCBFs) use a similar finite horizon prediction idea for safety-critical control to construct an implicit safe set online [8]. Instead of requiring an explicit controlled invariant set, bCBFs predict the evolution of the system under a pre-certified safe controller, called a backup controller, over a finite time horizon. A system is considered safe if the predicted backup trajectory satisfies the state constraints and reaches a known backup set [8]. This approach guarantees feasibility for input-constrained systems by providing a constructive certificate that the state remains safe. However, bCBFs rely on forward integration to compute the flow of the system model. Thus, model uncertainty can cause the computed backup trajectory to differ from the true trajectory, invalidating safety [9].
This limitation becomes more severe when the uncertainty appears in both the drift dynamics and the actuation matrix. Actuation uncertainty complicates robust safety filter design because the worst-case uncertainty involves the control input that is the decision variable of the underlying optimization problem. Recent robust CBF methods address related issues by using worst-case bounds, set-membership identification, or duality-based reformulations [10], [11]. Adaptive CBF methods reduce conservatism by estimating uncertain parameters online [12], [13]. However, robust bCBFs require more than a pointwise estimate of uncertain parameters. Since the safety condition depends on the predicted backup flow, it must account for the sensitivity of the flow to the parameter estimation errors. Moreover, if the estimator returns only a set-valued update, it may not provide the parameter estimate required for computing the backup flow sensitivity.
In this letter, we propose a robust adaptive bCBF framework for nonlinear systems with structured parametric uncertainty in the drift dynamics and actuation matrix. We consider a parameter affine uncertainty model and use element-wise certified adaptive estimators. These estimators provide a parameter adaptation law and certified component-wise bounds on the parameter estimation error. The proposed method computes the backup flow using the estimated model and tightens the safety conditions using the certified error bounds. These tightened conditions define an inner approximation of the implicit safe set. To handle uncertainty in the actuation matrix, we use a duality-based robustification that preserves a QP-based safety filter. We demonstrate the effectiveness of the proposed approach through a planar quadrotor example.
We consider a nonlinear control affine system of the form \[\dot{\boldsymbol{ x }} = \boldsymbol{ f }(\boldsymbol{ x }) + \boldsymbol{ g }(\boldsymbol{ x })\boldsymbol{ u }, \;\; \boldsymbol{ x } \in \mathcal{X} \subset \mathbb{R}^n, \;\; \boldsymbol{ u } \in \mathcal{U} \subset \mathbb{R}^m, \label{eq:nom95sys}\tag{1}\] where \({\boldsymbol{ f }:\mathcal{X}\to\mathbb{R}^n}\) and \({\boldsymbol{ g }:\mathcal{X}\to\mathbb{R}^{n\times m}}\) are continuously differentiable, and \({\mathcal{U}}\) is a convex polytope. To capture state constraints that characterize safety, we define the safe set \[\label{eq:safeset} \mathcal{C}_{\rm S}\triangleq\{\boldsymbol{ x }\in\mathcal{X}: h(\boldsymbol{ x }) \geq 0\},\tag{2}\] where \({h:\mathcal{X}\to\mathbb{R}}\) is continuously differentiable. Safety requires that 1 evolves inside the safe set, i.e., \(\mathcal{C}_{\rm S}\) must be forward invariant. Control barrier functions (CBFs) enable the synthesis of safe controllers. The function \({h}\) is a CBF if there exists an extended class-\(\mathcal{K}_{\infty}\) function \(\alpha\) such that \[\label{eq:CBF} \sup_{\boldsymbol{ u }\in\mathcal{U}} \big [ \nabla h(\boldsymbol{ x }) \big( \boldsymbol{ f }(\boldsymbol{ x }) + \boldsymbol{ g }(\boldsymbol{ x })\boldsymbol{ u } \big) \big ] > -\alpha\big(h(\boldsymbol{ x })\big),\tag{3}\] holds for all \({\boldsymbol{ x } \in \mathcal{C}_{\rm S}}\). Then, any locally Lipschitz controller \({ \boldsymbol{ u } = \boldsymbol{ k }(\boldsymbol{ x })}\), \({\boldsymbol{ k }: \mathcal{X} \to \mathcal{U}}\), satisfying \[\label{eq:CBF95constraint} \nabla h(\boldsymbol{ x }) \big( \boldsymbol{ f }(\boldsymbol{ x }) + \boldsymbol{ g }(\boldsymbol{ x })\boldsymbol{ u } \big) \geq -\alpha\big(h(\boldsymbol{ x })\big), \;\; \forall\boldsymbol{ x }\in\mathcal{C}_{\rm S},\tag{4}\] renders \({\mathcal{C}_{\rm S}}\) forward invariant [1], ensuring the safety of 1 .
While CBFs provide a systematic way to synthesize safe controllers, an arbitrary safety function \(h\) may not satisfy the CBF condition 3 , especially with bounded inputs. In this case, there may exist states in \(\mathcal{C}_{\rm S}\) for which there is no admissible input satisfying the constraint 4 . Backup CBFs [8] address this issue by constructing a subset of \(\mathcal{C}_{\rm S}\) where safe inputs are guaranteed to exist and by generating corresponding safe controllers within the CBF framework.
The backup CBF method leverages a backup controller and a backup set that typically represent safe but conservative behavior. Let \(\mathcal{C}_{\rm B}\subseteq \mathcal{C}_{\rm S}\) be a backup set, defined by \[\label{eq:backup95set} \mathcal{C}_{\rm B}\triangleq\{\boldsymbol{ x } \in \mathcal{X}: h_{\rm b}(\boldsymbol{ x }) \geq 0\},\tag{5}\] with a continuously differentiable safety function \({h_{\rm b} \!:\! \mathcal{X} \!\to\! \mathbb{R}}\), and \({\boldsymbol{k}_{\rm b}\!:\! \mathcal{X} \!\to\! \mathcal{U}}\) be a backup controller that renders \(\mathcal{C}_{\rm B}\) forward invariant. The closed-loop dynamics under \({\boldsymbol{k}_{\rm b}}\) are \({\dot{\boldsymbol{ x }} \!=\! \boldsymbol{ f }(\boldsymbol{ x }) \!+\! \boldsymbol{ g }(\boldsymbol{ x })\boldsymbol{k}_{\rm b}(\boldsymbol{ x })}\), and the backup flow \({\boldsymbol{ \varphi }_{\rm b}(\tau,\boldsymbol{ x })}\) denotes the solution of this system starting from state \(\boldsymbol{ x }\), over time \({\tau \!\in\! [0,T]}\) with a backup horizon \({T \!>\! 0}\).
The key idea of bCBFs is to define the implicit safe set \[\label{eq:implicit95set} \mathcal{C}_{\rm I} \triangleq \left\{ \boldsymbol{ x } \in \mathcal{X} : ~ \begin{array}{@{}l@{}} h\big(\boldsymbol{ \varphi }_{\rm b}(\tau,\boldsymbol{ x })\big) \geq 0, \;\; \forall \tau \in [0,T], \\ h_{\rm b}\big(\boldsymbol{ \varphi }_{\rm b}(T,\boldsymbol{ x })\big) \geq 0 \end{array} \right\}.\tag{6}\] This represents the states from which the system can safely reach the backup set in time \(T\) via the backup controller. The set \(\mathcal{C}_{\rm I}\) is a subset of \(\mathcal{C}_{\rm S}\), and it is forward invariant under the backup controller. Therefore, by construction, safe inputs are guaranteed to exist in \(\mathcal{C}_{\rm I}\). This construction is useful for input-constrained systems because feasibility can be inherited from the backup controller [8].
We extend bCBFs to systems with model uncertainty as \[\dot{\boldsymbol{ x }} = \boldsymbol{ f }(\boldsymbol{ x }) + \boldsymbol{ g }(\boldsymbol{ x })\boldsymbol{ u } + \Delta\boldsymbol{ f }(\boldsymbol{ x }) + \Delta\boldsymbol{ g }(\boldsymbol{ x })\boldsymbol{ u }, \label{eq:unc95sys95raw}\tag{7}\] where \({\boldsymbol{ f }:\mathcal{X}\to\mathbb{R}^n}\) and \({\boldsymbol{ g }:\mathcal{X}\to\mathbb{R}^{n\times m}}\) are the known nominal components of the dynamics, while \({\Delta\boldsymbol{ f }:\mathcal{X}\to\mathbb{R}^n}\) and \({\Delta\boldsymbol{ g }:\mathcal{X}\to\mathbb{R}^{n\times m}}\) represent unknown structured uncertainty in the drift vector field and actuation matrix. We assume that the uncertainty admits the parameter affine representation \[\Delta\boldsymbol{ f }(\boldsymbol{ x }) = \boldsymbol{ F }(\boldsymbol{ x })\boldsymbol{ \theta }_{\rm f}, \quad \Delta\boldsymbol{ g }(\boldsymbol{ x })\boldsymbol{ u } = \sum_{j=1}^{N_{\rm g}} \boldsymbol{ G }_j(\boldsymbol{ x }) ~\! \boldsymbol{ u } ~\! \theta_{{\rm g},j}, \label{eq:param95unc}\tag{8}\] where \({\boldsymbol{ F } \!:\! \mathcal{X} \! \to \! \mathbb{R}^{n\times N_{\rm f}}}\) and \({\boldsymbol{ G }_j \!:\! \mathcal{X} \!\to\! \mathbb{R}^{n \times m}}\) are known terms, while \({\boldsymbol{ \theta }_{\rm f} \in \mathbb{R}^{N_{\rm f}}}\) and \({\boldsymbol{ \theta }_{\rm g} \in \mathbb{R}^{N_{\rm g}}}\) are unknown parameters.
Collecting the parameters in a vector \({\boldsymbol{ \theta } \in \mathbb{R}^{N}}\) such that \(\boldsymbol{ \theta } \triangleq \begin{bmatrix} \boldsymbol{ \theta }_{\rm f}^{\top} & \boldsymbol{ \theta }_{\rm g}^{\top} \end{bmatrix}^{\top} = \begin{bmatrix} \theta_1 & \theta_2 & \ldots & \theta_{N} \end{bmatrix}^{\top}\), with \({N \!=\! N_{\rm f} \!+\! N_{\rm g}}\) parameters, and by defining a regression matrix as \[\label{eq:regressor95affine} \boldsymbol{ \phi }(\boldsymbol{ x },\boldsymbol{ u }) \triangleq \begin{bmatrix} \boldsymbol{ F }(\boldsymbol{ x }) & \boldsymbol{ G }_1(\boldsymbol{ x })\boldsymbol{ u } & \cdots & \boldsymbol{ G }_{N_{\rm g}}(\boldsymbol{ x })\boldsymbol{ u } \end{bmatrix},\tag{9}\] system 7 can be written compactly as \[\dot{\boldsymbol{ x }} = \boldsymbol{ f }(\boldsymbol{ x }) + \boldsymbol{ g }(\boldsymbol{ x })\boldsymbol{ u } + \boldsymbol{ \phi }(\boldsymbol{ x },\boldsymbol{ u })\boldsymbol{ \theta }. \label{eq:unc95sys95affine}\tag{10}\] The uncertainty representation in 10 is essential for our subsequent results. In particular, the control direction uncertainty term \({\Delta\boldsymbol{ g }(\boldsymbol{ x })\boldsymbol{ u }}\) will preserve affine dependence on the control input in the robust bCBF conditions and is therefore critical for constructing a QP-based safety filter.
While \(\boldsymbol{ \theta }\) is unknown, it represents fixed coefficients that parameterize model uncertainty, a structure also common to adaptive and learning-based control. In robotic systems, these coefficients often correspond to physical quantities or model mismatches, such as damping coefficients, gravity mismatch, mass or inertia errors, for which conservative ranges can be obtained from system identification, nominal specifications, or physical limits. Accordingly, we assume that we know lower and upper bounds on each component of \(\boldsymbol{ \theta }\).
Assumption 1. There exist known constants \({\theta_i^{-}, \theta_i^{+} \!\in\! \mathbb{R}}\) for \({i \!\in\! \{1, \dots, N\}}\) such that \({\theta_i^{-} \!\leq\! \theta_i \!\leq\! \theta_i^{+}}\). Therefore, \({\boldsymbol{ \theta } \!\in\! \Theta}\), where \({ \Theta \!\triangleq\! [\theta_1^{-},\theta_1^{+}] \times \cdots \times [\theta_{N}^{-},\theta_{N}^{+}]}\).
Given Assumption 1, the unknown parameter \(\boldsymbol{ \theta }\) will be estimated, and the estimate will be used for safe control design. The proposed safety result does not require a specific adaptive law for estimation. Instead, it requires a differentiable parameter estimate and certified component-wise bounds on the estimation error. We next define an estimator class that can provide the required estimate and bounds.
Let \(\mathcal{H}_{t}\) denote the measured state and input data history available at time \(t\), which may contain filtered regressions, integral regressions, or stored data. These data are used for calculating an estimate \({\hat{\boldsymbol{\theta}}(t) \in \mathbb{R}^{N}}\) of the parameter \(\boldsymbol{ \theta }\). We consider general parameter estimation dynamics of the form \[\dot{\hat{\boldsymbol{\theta}}} = \boldsymbol{ q }(\hat{\boldsymbol{\theta}}, \mathcal{H}_{t}, t). \label{eq:theta95adaptation95law}\tag{11}\] Assume the estimator is initialized as \({\hat{\boldsymbol{\theta}}(0)\! \in \!\Theta}\) and satisfies \[\hat{\boldsymbol{\theta}}(t) \in \Theta, \quad \forall t \geq 0. \label{eq:estimate95in95theta}\tag{12}\]
Definition 1 (Element-wise certified adaptive estimator). An estimator satisfying 11 and 12 is an element-wise certified adaptive estimator if it provides a known signal \({\boldsymbol{ \rho }(t) \in \mathbb{R}_{\geq 0}^{N}}\) such that the estimation error \(\tilde{\boldsymbol{\theta}}(t) \triangleq\boldsymbol{ \theta } - \hat{\boldsymbol{\theta}}(t)\) satisfies \[\!|\tilde{\theta}_i(t)| \!\leq\! \rho_i(t), \; \boldsymbol{ \rho }(t) \!=\! \begin{bmatrix} \rho_1\!(t) & \!\!\!\!\!\!\ldots\!\!\!\!\! & \rho_N\!(t) \end{bmatrix}^{\top}\!\!, \; i \!\in\!\! \{1,\dots,\!N\!\}, \label{eq:rho95componentwise95bound}\tag{13}\] for all \({t \geq 0}\). Equivalently, this can be expressed as \[\label{eq:error95set} \tilde{\boldsymbol{\theta}}(t) \in \widetilde{\Theta}(t) \triangleq \{ \boldsymbol{ \eta } \in \mathbb{R}^{N}: \boldsymbol{ A }\boldsymbol{ \eta } \leq \boldsymbol{ b }(t) \},\tag{14}\] with \({\boldsymbol{ A } \!\triangleq\! \begin{bmatrix} \boldsymbol{I}&\!\! -\boldsymbol{I} \end{bmatrix}^\top}\) and \({\boldsymbol{ b }(t) \!\triangleq\! \begin{bmatrix} \boldsymbol{ \rho }(t)^\top &\!\! \boldsymbol{ \rho }(t)^\top \end{bmatrix}^\top}\). Note that, since \({\boldsymbol{ \theta }, \hat{\boldsymbol{\theta}}(t) \in \Theta}\), the bounds satisfy \({\rho_i(t) \leq \theta_i^{+} - \theta_i^{-}}\).
Example 1 (Dynamic regressor extension and mixing (DREM) parameter estimator [14], [15]). Consider a linear regression \({y_{\rm r}(t) = \boldsymbol{ m }_{\rm r}^{\top}(t)\boldsymbol{ \theta }}\), where \({y_{\rm r}(t) \in \mathbb{R}}\) and \({\boldsymbol{ m }_{\rm r}(t) \in \mathbb{R}^{N}}\) are known. DREM estimator estimates a parameter in two steps. First, the extension step constructs known signals \({\boldsymbol{ Y }_{\rm e}(t)\in\mathbb{R}^{N}}\) and \({\boldsymbol{ M }_{\rm e}(t)\in\mathbb{R}^{N \times N}}\) satisfying \({\boldsymbol{ Y }_{\rm e}(t) = \boldsymbol{ M }_{\rm e}(t)\boldsymbol{ \theta }}\). This extended regression can be obtained, for example, by stacking the original regression with filtered regressions generated by stable linear operators [14]. Second, the mixing step multiplies the extended regression by the adjugate of \(\boldsymbol{ M }_{\rm e}(t)\) as \({\boldsymbol{ Y }_{\rm D}(t) \triangleq\operatorname{adj}(\boldsymbol{ M }_{\rm e}(t))\boldsymbol{ Y }_{\rm e}(t)}\). By defining \({\chi(t) \triangleq\det(\boldsymbol{ M }_{\rm e}(t))}\), it can be shown that \({\boldsymbol{ Y }_{\rm D}(t) = \chi(t)\boldsymbol{ \theta }}\) holds because \({\operatorname{adj}(\boldsymbol{ M }_{\rm e})\boldsymbol{ M }_{\rm e} = \det(\boldsymbol{ M }_{\rm e})\boldsymbol{ I }_{N}}\). Then, each parameter is estimated with the update law \[\dot{\hat{\theta}}_i(t) = \gamma_i\chi(t) \big( Y_{{\rm D},i}(t) - \chi(t)\hat{\theta}_i(t) \big), \;\; \gamma_i>0, \label{eq:DREM95law}\tag{15}\] which yields the estimation error dynamics \[\dot{\tilde{\theta}}_i(t) = -\gamma_i\chi^2(t)\tilde{\theta}_i(t). \label{eq:DREM95err95dyn}\tag{16}\]
Lemma 1. Consider the uncertain system 10 and update law 15 for the estimation of the parameter \(\boldsymbol{ \theta }\). Under Assumption 1 and the initialization \({\hat{\boldsymbol{\theta}}(0) \in \Theta}\), the DREM estimator in Example 1 satisfies 12 and 13 .
Let \({\nu_i(t) \!\triangleq\! {\rm e}^{ -\gamma_i \int_0^t \chi^2(s) \!~d s }}\). Since \({\gamma_i \!>\! 0}\), we have \({0 \!<\! \nu_i(t) \!\leq\! 1}\) for all \({t \!\geq\! 0}\). The solution of 16 with the initial condition \(\tilde{\theta}_i(0)\) is given by \({\tilde{\theta}_i(t) \!=\! \nu_i(t) \tilde{\theta}_i(0)}\). Thus, \(|\tilde{\theta}_i(t)|\) satisfies the error bound 13 with \({\rho_i(t) \!=\! \nu_i(t) \rho_i(0)}\), if \({\rho_i(0) \!\geq\! |\tilde{\theta}_i(0)|}\). For \(\rho_i(0)\), Assumption 1 and \({\hat{\boldsymbol{\theta}}(0) \!\in\! \Theta}\) allow the choice \({\rho_i(0) \!=\! \max\{ \hat{\theta}_i(0) \!- \theta_i^{-},~ \theta_i^{+} \! -\hat{\theta}_i(0) \}}\). Note that the least conservative bound is obtained for \(\rho_i(t)\) if the initial value of \(\hat{\theta}_i\) is the midpoint of the interval, given by \({\hat{\theta}_i(0) \!=\! (\theta_i^{-} \!+\! \theta_i^{+})/2}\). Finally, we prove that \({\hat{\boldsymbol{\theta}}(t) \!\in\! \Theta}\) for all \({t \!\geq\! 0}\). Using \({\tilde{\theta}_i(t) \!=\! \theta_i - \hat{\theta}_i(t)}\) gives \({\hat{\theta}_i(t) \!=\! \big(1 \!- \nu_i(t) \big) \theta_i \!+\! \nu_i(t) \hat{\theta}_i(0)}\). By Assumption 1, \({\theta_i \!\in\! [\theta_i^{-}, \theta_i^{+}]}\), and by \({\hat{\boldsymbol{\theta}}(0) \!\in\! \Theta}\), \({\hat{\theta}_i(0) \!\in\! [\theta_i^{-}, \theta_i^{+}]}\). Hence, \({\hat{\theta}_i(t) \!\in\! [\theta_i^{-}, \theta_i^{+}]}\) for all \({t \!\geq\! 0}\) and \({i \!\in\! \{1, \dots, N\}}\), implying \({\hat{\boldsymbol{\theta}}(t) \!\in\! \Theta, \!\;\forall t \!\geq\! 0}\). Thus, the estimator satisfies Def. 1.
We remark that DREM is only one example realization of the estimator class. For instance, recursive least-squares estimators with zonotopic uncertainty propagation also provide an adaptation law with a set-valued uncertainty certificate [13]. More generally, any adaptive, composite learning, or set-membership estimator can be used if it provides the adaptation law in 11 and an element-wise bound [11], [13].
We are now in a position to state the considered problem, which will be addressed using robust adaptive bCBFs.
Problem 1. Given the uncertain system 10 , the safe set \(\mathcal{C}_{\rm S}\) in 2 , and an element-wise certified adaptive estimator 11 , design a control law \({\boldsymbol{ u }=\boldsymbol{ k }(t,\boldsymbol{ x },\hat{\boldsymbol{\theta}}) \in \mathcal{U}}\) that renders a subset of \(\mathcal{C}_{\rm S}\) forward invariant, ensuring the safety of 10 .
We now develop the proposed robust adaptive bCBF method in four steps. First, we propagate the backup flow using the current parameter estimate. Second, we bound the mismatch between the true and estimated backup flows using the certified component-wise parameter error bounds. Third, we use this bound to define a tightened inner approximation of the implicit safe set. Fourth, we derive duality-based robust safety conditions that preserve a QP implementation.
Similar to the standard bCBF method outlined in Section 2, the proposed approach leverages a backup controller \({\boldsymbol{k}_{\rm b}:\mathcal{X}\to\mathcal{U}}\) and a backup set \({\mathcal{C}_{\rm B}\subseteq \mathcal{C}_{\rm S}}\) given in 5 . This time, we assume that \(\boldsymbol{k}_{\rm b}\) is a robust backup controller.
Assumption 2. The backup controller \(\boldsymbol{k}_{\rm b}\) renders \(\mathcal{C}_{\rm B}\) forward invariant for 10 for any \(\boldsymbol{ \theta } \in \Theta\).
In practice, robust backup sets can often be obtained by robustifying Lyapunov level sets around a stabilizable equilibrium point and verifying their invariance under the corresponding stabilizing feedback control law [9]. In Section 5, we utilize this approach to synthesize a robust backup controller and a robust backup set for a quadrotor model.
We introduce the closed-loop dynamics of the system 10 under the robust backup controller as \[\dot{\boldsymbol{ x }} = \boldsymbol{ f }_{\rm b}(\boldsymbol{ x },\boldsymbol{ \theta }) \triangleq \boldsymbol{ f }(\boldsymbol{ x }) + \boldsymbol{ g }(\boldsymbol{ x })\boldsymbol{k}_{\rm b}(\boldsymbol{ x }) + \boldsymbol{ \psi }_{\rm b}(\boldsymbol{ x })\boldsymbol{ \theta }, \label{eq:backup95dyn95param}\tag{17}\] where \(\boldsymbol{ \psi }_{\rm b}\) indicates the regression matrix in 9 evaluated along the backup controller: \[\label{eq:regression95backup} \boldsymbol{ \psi }_{\rm b}(\boldsymbol{ x }) \triangleq \boldsymbol{ \phi }(\boldsymbol{ x },\boldsymbol{k}_{\rm b}(\boldsymbol{ x })).\tag{18}\] Then, the backup flow satisfies \[\tfrac{\partial}{\partial \tau}\boldsymbol{\varphi}_{\rm b}(\tau,\boldsymbol{ x }) = \boldsymbol{ f }_{\rm b}\big(\boldsymbol{\varphi}_{\rm b}(\tau,\boldsymbol{ x }),\boldsymbol{ \theta }\big), \;\; \boldsymbol{\varphi}_{\rm b}(0,\boldsymbol{ x }) = \boldsymbol{ x }. \label{eq:true95backup95flow95main}\tag{19}\]
Ideally, one would use the backup flow to enforce the forward invariance of the implicit safe set \(\mathcal{C}_{\rm I}\) defined in 6 . However, since the parameter \(\boldsymbol{ \theta }\) is unknown, the backup flow \(\boldsymbol{ \varphi }_{\rm b}\) and the implicit set \(\mathcal{C}_{\rm I}\) may not be known. Therefore, we instead establish a known subset of \(\mathcal{C}_{\rm I}\) and enforce the forward invariance thereof. To this end, we propagate an estimated backup flow \(\widehat{\boldsymbol{ \varphi }}_{\rm b}\) using the current parameter estimate \(\hat{\boldsymbol{\theta}}(t)\) that is frozen over the backup horizon: \[\! \! \! \tfrac{\partial}{\partial \tau}\widehat{\boldsymbol{\varphi}}_{\rm b}(\tau,\boldsymbol{ x },t) \!=\! \boldsymbol{ f }_{\rm b}\big(\widehat{\boldsymbol{\varphi}}_{\rm b}(\tau,\boldsymbol{ x },t),\hat{\boldsymbol{\theta}}(t)\big), \; \widehat{\boldsymbol{\varphi}}_{\rm b}(0,\boldsymbol{ x },t) \!=\! \boldsymbol{ x }. \label{eq:estimated95backup95flow95main}\tag{20}\]
While the estimated flow \(\widehat{\boldsymbol{ \varphi }}_{\rm b}\) is known, it is not sufficient for ensuring safety by itself, since the true parameter \(\boldsymbol{ \theta }\) can differ from the estimated parameter \(\hat{\boldsymbol{\theta}}\). Therefore, we bound the difference between the true and estimated backup flows: \[\label{eq:flow95bound} \big \| { \boldsymbol{\varphi}_{\rm b}(\tau,\boldsymbol{ x }) - \widehat{\boldsymbol{\varphi}}_{\rm b}(\tau,\boldsymbol{ x },t) } \big \| \leq \delta_{\varphi}(\tau,\boldsymbol{ x },t),\tag{21}\] and use these bounds to establish robust safety. The following lemma provides one possible flow error bound \(\delta_{\varphi}\).
Lemma 2. Assume that \(\boldsymbol{ f }_{\rm b}(\boldsymbol{ x },\boldsymbol{ \theta })\) in 17 is uniformly Lipschitz on \(\mathcal{X}\) over all \(\boldsymbol{ \theta }\in\Theta\) with Lipschitz constant \(L_{\rm b}\). Then, 21 holds for all \(\tau\in[0, T]\), \(\boldsymbol{ x }\in\mathcal{X}\), and \({t \geq 0}\) with \[\label{eq:delta95Gronwall} \begin{align} \delta_{\varphi}(\tau,\boldsymbol{ x },t) & \triangleq \int_0^{\tau} {\rm e}^{L_{\rm b}(\tau-s)} d_{\rm b}(s,\boldsymbol{ x },t) ~\!d s, \\ d_{\rm b}(\tau,\boldsymbol{ x },t) & \triangleq \sum_{i=1}^{N} \left\Vert \boldsymbol{ \psi }_{{\rm b},i} \big(\widehat{\boldsymbol{\varphi}}_{\rm b}(\tau,\boldsymbol{ x },t)\big) \right\Vert_{\rm s} \rho_i(t), \end{align}\tag{22}\] where \(\boldsymbol{ \psi }_{{\rm b},i}\) is the \(i\)th column of \(\boldsymbol{ \psi }_{\rm b}\) in 18 , \(\left\Vert \cdot \right\Vert_{\rm s}\) represents a smooth upper bound of the Euclidean norm4, and \(\rho_i(t)\) is the element-wise parameter estimation error bound in 13 .
First, we derive the dynamics of the error term \({\boldsymbol{ e }(\tau,\boldsymbol{ x },t) \triangleq\boldsymbol{\varphi}_{\rm b}(\tau,\boldsymbol{ x }) - \widehat{\boldsymbol{\varphi}}_{\rm b}(\tau,\boldsymbol{ x },t)}\). Using 19 and 20 , and adding and subtracting \(\boldsymbol{ f }_{\rm b}(\widehat{\boldsymbol{\varphi}}_{\rm b}(\tau,\boldsymbol{ x },t),\boldsymbol{ \theta })\), we have \[\begin{align} \tfrac{\partial}{\partial \tau} \boldsymbol{ e }(\tau,\boldsymbol{ x },t) &= \boldsymbol{ f }_{\rm b} \big(\boldsymbol{\varphi}_{\rm b}(\tau,\boldsymbol{ x }),\boldsymbol{ \theta }\big) - \boldsymbol{ f }_{\rm b} \big(\widehat{\boldsymbol{\varphi}}_{\rm b}(\tau,\boldsymbol{ x },t),\boldsymbol{ \theta }\big) \\ & \quad + \boldsymbol{ \psi }_{\rm b} \big(\widehat{\boldsymbol{\varphi}}_{\rm b}(\tau,\boldsymbol{ x },t)\big) \tilde{\boldsymbol{\theta}}(t). \end{align}\] The last term can be bounded using \(d_{\rm b}\) as \[\begin{align} & \left\Vert \boldsymbol{ \psi }_{\rm b} \big(\widehat{\boldsymbol{\varphi}}_{\rm b}(\tau,\boldsymbol{ x },t)\big) \tilde{\boldsymbol{\theta}}(t) \right\Vert = \left\Vert \sum_{i=1}^{N} \boldsymbol{ \psi }_{{\rm b},i} \big(\widehat{\boldsymbol{\varphi}}_{\rm b}(\tau,\boldsymbol{ x },t)\big) \tilde{\theta}_i(t) \right\Vert \\ & ~~~~~~~~~~~ \leq \sum_{i=1}^{N} \left\Vert \boldsymbol{ \psi }_{{\rm b},i} \big(\widehat{\boldsymbol{\varphi}}_{\rm b}(\tau,\boldsymbol{ x },t)\big) \right\Vert_{\rm s} \rho_i(t) = d_{\rm b}(\tau,\boldsymbol{ x },t). \end{align}\]
Next, using the integral form of the error dynamics and \({\boldsymbol{ e }(0,\boldsymbol{ x },t) = \mathbf{0}}\), we get \[\begin{align} \left\Vert \boldsymbol{ e }(\tau,\boldsymbol{ x },t) \right\Vert & \!\leq \! \! \int_0^{\tau} \!\! \left\Vert \boldsymbol{ f }_{\rm b} \big(\boldsymbol{\varphi}_{\rm b}(s,\boldsymbol{ x }),\boldsymbol{ \theta }\big) \!-\! \boldsymbol{ f }_{\rm b} \big(\widehat{\boldsymbol{\varphi}}_{\rm b}(s,\boldsymbol{ x },t),\boldsymbol{ \theta }\big) \right\Vert d s \\ & \quad + \int_0^{\tau} \left\Vert \boldsymbol{ \psi }_{\rm b} \big(\widehat{\boldsymbol{\varphi}}_{\rm b}(s,\boldsymbol{ x },t)\big) \tilde{\boldsymbol{\theta}}(t) \right\Vert d s, \\ & \leq \int_0^{\tau} \big( L_{\rm b} \left\Vert \boldsymbol{ e }(s,\boldsymbol{ x },t) \right\Vert + d_{\rm b}(s,\boldsymbol{ x },t) \big) d s, \end{align}\] where the first inequality follows from the triangle inequality and the second inequality holds because of the uniform Lipschitz property of \(\boldsymbol{ f }_{\rm b}\) and the definition of \(d_{\rm b}\). Thus, the bound in 22 follows from the Gronwall–Bellman inequality.
We note that \(\delta_{\varphi}\) in 22 is one possible flow bound. When more information about the closed-loop system may be leveraged (e.g., contraction, one-sided Lipschitzness [16], or linearity), this bound can be made tighter [17].
Having established the flow error bound in 21 , we now introduce tightening terms that allow us to make constraints on the estimated backup flow sufficient for satisfying constraints on the true backup flow. These tightening terms are denoted as \(\epsilon\) and \(\epsilon_{\rm b}\), and they are constructed such that \[\label{eq:epsilon} \begin{align} \epsilon(\tau, \boldsymbol{ x }, t) & \geq h(\widehat{\boldsymbol{\varphi}}_{\rm b}(\tau,\boldsymbol{ x },t)) - h(\boldsymbol{\varphi}_{\rm b}(\tau,\boldsymbol{ x })), \\ \epsilon_{\rm b}(\boldsymbol{ x },t) & \geq h_{\rm b}(\widehat{\boldsymbol{\varphi}}_{\rm b}(T,\boldsymbol{ x },t)) - h_{\rm b}(\boldsymbol{\varphi}_{\rm b}(T,\boldsymbol{ x })), \end{align}\tag{23}\] hold for all \({\tau \in [0, T]}\), \({\boldsymbol{ x }\in\mathcal{X}}\), and \({t \geq 0}\), providing bounds on the effect of the parameter uncertainty on safety. For example, by the Lipschitz continuity of \(h\) and \(h_{\rm b}\), we may define continuously differentiable tightening functions as \[\label{eq:eps95b95choice95main} \begin{align} \epsilon(\tau, \boldsymbol{ x }, t) & \triangleq L_h \delta_{\varphi}(\tau,\boldsymbol{ x },t), \\ \epsilon_{\rm b}(\boldsymbol{ x }, t) & \triangleq L_{h_{\rm b}}\delta_{\varphi}(T,\boldsymbol{ x }, t), \end{align}\tag{24}\] where \(L_h\) and \(L_{h_{\rm b}}\) are the Lipschitz constants of \(h\) and \(h_{\rm b}\). For convex or quadratic barriers, even tighter \(\epsilon\) and \(\epsilon_{\rm b}\) terms may be obtained [18].
To enhance robustness against parameter estimation errors, similar to the uncertainty estimator-based bCBF method proposed in [17], we define a time-varying inner approximation \(\widehat{\mathcal{C}}_{\rm I}(t)\) of the true implicit safe set \(\mathcal{C}_{\rm I}\) in 6 : \[\label{eq:implicit95set95approx} \widehat{\mathcal{C}}_{\rm I}(t) \triangleq \left\{ \boldsymbol{ x } \in \mathcal{X} : ~ \begin{array}{@{}l@{}} \bar h(\tau, \boldsymbol{ x }, t) \geq 0, \;\; \forall \tau \in [0, T], \\ \bar h_{\rm b}(\boldsymbol{ x },t) \geq 0 \end{array} \right\},\tag{25}\] for all \({t \geq 0}\), where the tightening terms are incorporated in \[\label{eq:barriers95subset} \begin{align} \bar h(\tau, \boldsymbol{ x }, t) & \triangleq h(\widehat{\boldsymbol{\varphi}}_{\rm b}(\tau,\boldsymbol{ x },t)) \!-\! \epsilon(\tau, \boldsymbol{ x }, t), \\ \bar h_{\rm b}(\boldsymbol{ x },t) & \triangleq h_{\rm b}(\widehat{\boldsymbol{\varphi}}_{\rm b}(T,\boldsymbol{ x },t)) - \epsilon_{\rm b}(\boldsymbol{ x }, t). \end{align}\tag{26}\] We remark that, since \({\epsilon, \epsilon_{\rm b} \geq 0}\), \(\widehat{\mathcal{C}}_{\rm I}(t)\subseteq\mathcal{C}_{\rm I}\).
Having constructed a known subset of \(\mathcal{C}_{\rm I}\), we are now in a position to enforce the forward invariance of \(\widehat{\mathcal{C}}_{\rm I}(t)\). We impose that the control input \(\boldsymbol{ u }\) must satisfy \[\label{eq:sufficient95cond} \begin{align} \dot{\bar h}(\tau,\boldsymbol{ x },t,\boldsymbol{ u }) &\geq -\alpha\big(\bar h(\tau,\boldsymbol{ x },t)\big), \;\; \forall ~\! \tau\in[0,T], \\ \dot{\bar h}_{\rm b}(\boldsymbol{ x },t,\boldsymbol{ u }) &\geq -\alpha_{\rm b}\big(\bar h_{\rm b}(\boldsymbol{ x },t)\big), \end{align}\tag{27}\] for all \({\boldsymbol{ x } \in \widehat{\mathcal{C}}_{\rm I}(t)}\) and \({t \geq 0}\). By calculating the time derivatives via the chain rule, these inequalities can be written as \[\label{eq:uncertain95bCBF95constraint} \begin{align} a(\tau,\boldsymbol{ x },\boldsymbol{ u },t) + \boldsymbol{ c }(\tau,\boldsymbol{ x },\boldsymbol{ u },t)^{\top} \tilde{\boldsymbol{\theta}}(t) & \geq 0, \\ a_{\rm b}(\boldsymbol{ x },\boldsymbol{ u },t) + \boldsymbol{ c }_{\rm b}(\boldsymbol{ x },\boldsymbol{ u },t)^{\top} \tilde{\boldsymbol{\theta}}(t) & \geq 0, \end{align}\tag{28}\] where the expressions of \(a\), \(a_{\rm b}\), \(\boldsymbol{ c }\), and \(\boldsymbol{ c }_{\rm b}\) are derived in the Appendix. Note that while the \(a\), \(a_{\rm b}\), \(\boldsymbol{ c }\), and \(\boldsymbol{ c }_{\rm b}\) coefficients are known, the parameter estimation error \(\tilde{\boldsymbol{\theta}}(t)\) is unknown, and hence 28 cannot be enforced directly.
Instead, we apply the robust adaptive bCBF conditions \[\begin{align} a(\tau,\boldsymbol{ x },\boldsymbol{ u },t) + \inf_{\boldsymbol{ \eta }\in\widetilde{\Theta}(t)} \boldsymbol{ c }(\tau,\boldsymbol{ x },\boldsymbol{ u },t)^{\top}\boldsymbol{ \eta } & \geq 0, \tag{29} \\ a_{\rm b}(\boldsymbol{ x },\boldsymbol{ u },t) + \inf_{\boldsymbol{ \eta }\in\widetilde{\Theta}(t)} \boldsymbol{ c }_{\rm b}(\boldsymbol{ x },\boldsymbol{ u },t)^{\top}\boldsymbol{ \eta } & \geq 0. \tag{30} \end{align}\] These inequalities enforce the bCBF conditions for all admissible parameter estimation errors inside the known error set \(\widetilde{\Theta}(t)\) given by 14 . The inner minimizations are linear programs (LPs) over the component-wise estimation error set. Using LP duality [10], the robust constraints are enforced by the existence of dual variables \(\boldsymbol{ \mu }_{\tau},\boldsymbol{ \mu }_{\rm b} \in \mathbb{R}^{2N}\) such that \[\begin{align} & a(\tau,\boldsymbol{ x },\boldsymbol{ u },t) + \boldsymbol{ b }(t)^{\top}\boldsymbol{ \mu }_{\tau} \geq 0, \tag{31} \\ & \boldsymbol{ \mu }_{\tau}^{\top}\boldsymbol{ A } = \boldsymbol{ c }(\tau,\boldsymbol{ x },\boldsymbol{ u },t)^{\top}, ~~~~\boldsymbol{ \mu }_{\tau} \leq \mathbf{0}, \tag{32} \\ & a_{\rm b}(\boldsymbol{ x },\boldsymbol{ u },t) + \boldsymbol{ b }(t)^{\top}\boldsymbol{ \mu }_{\rm b} \geq 0, \tag{33} \\ & \boldsymbol{ \mu }_{\rm b}^{\top}\boldsymbol{ A } = \boldsymbol{ c }_{\rm b}(\boldsymbol{ x },\boldsymbol{ u },t)^{\top}, ~~~~~ \boldsymbol{ \mu }_{\rm b} \leq \mathbf{0}, \tag{34} \end{align}\] with \(\boldsymbol{ A }\) and \(\boldsymbol{ b }(t)\) from 14 . Note that the functions \(a\), \(a_{\rm b}\), \(\boldsymbol{ c }\), and \(\boldsymbol{ c }_{\rm b}\) are affine in \(\boldsymbol{ u }\) as \(\boldsymbol{ \phi }(\boldsymbol{ x },\boldsymbol{ u })\) is affine in \(\boldsymbol{ u }\). Hence, 31 –34 are affine in the decision variables \(\boldsymbol{ u }\), \(\boldsymbol{ \mu }_{\tau}\), and \(\boldsymbol{ \mu }_{\rm b}\).
Theorem 1. Consider the uncertain system 10 , an estimator in Definition 1, the safe set \(\mathcal{C}_{\rm S}\) in 2 , the backup controller \(\boldsymbol{k}_{\rm b}\), the backup set \(\mathcal{C}_{\rm B}\) in 5 , and the time-varying set \(\widehat{\mathcal{C}}_{\rm I}(t)\) in 25 . Suppose Assumptions 1 and 2 hold. Then, any locally Lipschitz controller satisfying 31 –34 for all \({\tau\in[0,T]}\) renders \(\widehat{\mathcal{C}}_{\rm I}(t)\) forward invariant for 10 . Consequently, every closed-loop trajectory starting in \(\widehat{\mathcal{C}}_{\rm I}(0)\) remains in \(\mathcal{C}_{\rm S}\): \({\mathbf{x}(0) \in \widehat{\mathcal{C}}_{\rm I}(0) \implies \mathbf{x}(t) \in \mathcal{C}_{\rm S}}\), \({\forall t \geq 0}\).
By strong duality, the dual inequality and equality conditions in 31 –34 imply the primal robust inequalities 29 and 30 . Since \(\tilde{\boldsymbol{\theta}}(t)\in\widetilde{\Theta}(t)\), these primal inequalities imply 27 . Consequently, the comparison lemma gives the forward invariance of \(\widehat{\mathcal{C}}_{\rm I}(t)\). From the tightening construction 23 , we have \(\widehat{\mathcal{C}}_{\rm I}(t)\subseteq \mathcal{C}_{\rm I}\). Since \({\tau=0}\) is included in the definition of \(\mathcal{C}_{\rm I}\), we also have \({\mathcal{C}_{\rm I}\subseteq\mathcal{C}_{\rm S}}\). Therefore, every closed-loop trajectory starting in \(\widehat{\mathcal{C}}_{\rm I}(0)\) remains in \(\mathcal{C}_{\rm S}\).
Having established the robust safety constraints in 31 –34 , we now introduce an optimization problem, in the form of a QP, that enables the synthesis of safe controllers. Let the backup horizon be discretized by \({\tau_j \!=\! j ~\! T/N_T}\) for \({j \!\in\! \{0,\dots,N_T\}}\), and define the decision variable vector as \({\boldsymbol{ w } \!\triangleq\! \big( \boldsymbol{ u }, \{\boldsymbol{ \mu }_{\tau_j}\}_{j=0}^{N_T}, \boldsymbol{ \mu }_{\rm b} \big)}\) that contains \({N_w \!\triangleq\! m + (N_T+2) 2 N}\) elements. With \(\boldsymbol{ w }\), we formulate an adaptive safety filter that minimally modifies a potentially unsafe primary controller \({\boldsymbol{k}_{\rm p}:\mathcal{X}\to\mathcal{U}}\) into a safe controller: \[\begin{align} \boldsymbol{ k }^{\star}(t, \boldsymbol{ x }, \hat{\boldsymbol{\theta}}) = \mathop{\mathrm{\operatorname{argmin}}}_{\boldsymbol{ w } \in \mathbb{R}^{N_w}} \;\; & \left\Vert \boldsymbol{ u }-\boldsymbol{k}_{\rm p}(\boldsymbol{ x }) \right\Vert^2 \label{eq:adaptive95qp95main} \\ \operatorname{s.t.}\;\; & \boldsymbol{ u } \in \mathcal{U}, ~ \eqref{eq:main95hb95dual95main}, \eqref{eq:main95eq95hb95main}, \nonumber\\ & \eqref{eq:main95h95dual95main},\eqref{eq:main95eq95h95main} \text{ at } \tau_j, \;j \in \{0,\dots,N_T\}. \nonumber \end{align}\tag{35}\] Note that 35 is a QP, since its constraints are affine in \(\boldsymbol{ w }\).
Remark 1. Theorem 1 uses continuous time safety conditions over \({\tau\in[0,T]}\), while the QP in 35 enforces discretized constraints on a grid using \(\tau_j\). As in standard bCBF implementations, one can add inter-sample margins or choose a sufficiently fine grid to account for the discretization error.
Remark 2. The proposed method with the QP in 35 ensures safety without requiring the notoriously restrictive persistent excitation (PE) condition on the regression matrix. Furthermore, as the certified bounds \(\rho_i(t)\) decrease, the flow error bound \(\delta_{\varphi}\) and the tightening terms \(\epsilon,\epsilon_{\rm b}\) shrink; therefore, the inner approximation \(\widehat{\mathcal{C}}_{\rm I}(t)\) approaches \(\mathcal{C}_{\rm I}\) as \({\rho_i(t) \to 0}\).
Remark 3. Since the set \(\widehat{\mathcal{C}}_{\rm I}(t)\) is not necessarily controlled invariant by construction, the QP in 35 can be infeasible for some \({t \!\geq\! 0}\) because of the input bounds or the emptiness of the set \(\widehat{\mathcal{C}}_{\rm I}(t)\). Note that the non-emptiness of \(\widehat{\mathcal{C}}_{\rm I}(t)\) depends on the size of the tightening terms \(\epsilon,\epsilon_{\rm b}\), which are largest at \({t \!=\! 0}\) and shrink as the certified bounds \(\rho_i(t)\) decrease. In practice, \(\widehat{\mathcal{C}}_{\rm I}(t)\) can be made non-empty by choosing a sufficiently short backup horizon \(T\) or a sufficiently tight initial parameter box \(\Theta\), and becomes progressively less conservative as the estimator refines the parameter estimate. To ensure robust safety in the case of potential infeasibility of the QP, the robust backup controller \(\boldsymbol{k}_{\rm b}\) can be utilized. By Assumption 2, \(\boldsymbol{k}_{\rm b}\) renders \(\mathcal{C}_{\rm I}\) forward invariant along 10 , and satisfies \({\boldsymbol{k}_{\rm b}(\boldsymbol{ x }) \in \mathcal{U}}\) for all \({\boldsymbol{ x } \in \mathcal{C}_{\rm I}}\). Therefore, if 35 becomes infeasible, one can switch to \(\boldsymbol{k}_{\rm b}\) to keep the state in \({\mathcal{C}_{\rm I} \!\subseteq\! \mathcal{C}_{\rm S}}\) while satisfying the input constraints. A smooth switching between \(\boldsymbol{ k }^{\star}\) and \(\boldsymbol{k}_{\rm b}\) can also be used, as in [19].
We illustrate the proposed control method using a planar quadrotor example with parametric uncertainty in both the drift and input matrices5. The state and input vectors are \(\boldsymbol{ x } \!\triangleq\! \begin{bmatrix} p_x & p_z & \vartheta & v_x & v_z & \omega \end{bmatrix}^{\top} \!\!\in\! \mathcal{X}, ~~ \!\boldsymbol{ u }\! \triangleq \begin{bmatrix} F & M \end{bmatrix}^{\top} \!\!\in\! \mathcal{U}\), where \(\mathcal{X} \subset \mathbb{R}^{2}\times \mathbb{S}^{1}\times \mathbb{R}^{3}\), \(p_x\) and \(p_z\) denote the horizontal and vertical quadrotor positions, \(\vartheta\) is its pitch angle, and \((v_x, v_z,\omega)\) are the translational and angular velocities. The inputs are the thrust force \(F\) and pitch moment \(M\), with \(\mathcal{U} \triangleq[0,F_{\max}] \times [-M_{\max},M_{\max}] \subset \mathbb{R}^{2}\). The planar quadrotor model is \[\label{eq:uncertain95drone95dyn} \begin{align} \dot{p}_x & = v_x, \quad \dot{p}_z = v_z, \quad \dot{\vartheta} = \omega, \quad \dot{\omega} = \delta_{\ell} F -\tfrac{1}{J} M, \\ \dot{v}_x &= -c_x v_x + \tfrac{\sin\vartheta}{m} F, \quad \dot{v}_z = -c_z v_z - g + \tfrac{\cos\vartheta}{m} F, \end{align}\tag{36}\] where \(c_x\) and \(c_z\) are damping coefficients, \(g\) is the gravitational acceleration, \(m\) is the mass of the quadrotor, \(J\) is its mass moment of inertia, and \(\delta_{\ell}\) captures an unknown pitch moment generated by thrust. We assume that each of these six parameters is uncertain, and the nominal values used for control design are \(0\), \(0\), \(g_0\), \(m_0\), \(J_0\), and \(0\), respectively.
Accordingly, we introduce the unknown parameter vector \(\boldsymbol{ \theta } \triangleq \begin{bmatrix} c_x & c_z & \delta_g & \delta_m & \delta_J & \delta_{\ell} \end{bmatrix}^{\top} \in \Theta \subset \mathbb{R}^{6}\), with \({\delta_g \triangleq g-g_0}\), \({\delta_m \triangleq\frac{1}{m} - \frac{1}{m_0}}\), \({\delta_J \triangleq\frac{1}{J} - \frac{1}{J_0}}\), and we separate the nominal model and the uncertainty as \[{ \setlength{\arraycolsep}{1.5pt} \dot{\boldsymbol{ x }} \!=\!\!\! \underbrace{{ \begin{bmatrix} \!v_x\! \\ \!v_z\! \\ \!\omega\! \\ \!0\! \\ \!-g_0\! \\ \!0\! \end{bmatrix}}}_{\boldsymbol{ f }(\boldsymbol{ x })} \!\!+\!\! \underbrace{{ \begin{bmatrix} \!0 & 0 \\ \!0 & 0 \\ \!0 & 0 \\ \!\frac{\sin\vartheta}{m_0} & 0 \\ \!\frac{\cos\vartheta}{m_0} & 0 \\ \!0 & -\frac{1}{J_0} \end{bmatrix}}}_{\boldsymbol{ g }(\boldsymbol{ x })} \!\!\boldsymbol{ u } +\! \underbrace{{ \begin{bmatrix} \!0 & 0 & 0 & 0 & 0 & 0 \\ \!0 & 0 & 0 & 0 & 0 & 0 \\ \!0 & 0 & 0 & 0 & 0 & 0 \\ \!-v_x & 0 & 0 & F\! \sin \!\vartheta & 0 & 0 \\ \!0 & -v_z & -1 & F\! \cos \!\vartheta & 0 & 0 \\ \!0 & 0 & 0 & 0 & -M & F \end{bmatrix}}}_{\boldsymbol{ \phi }(\boldsymbol{ x },\boldsymbol{ u })} \!\!\boldsymbol{ \theta }. }\] We remark that \(c_x\), \(c_z\), and \(\delta_g\) introduce drift uncertainty, while the uncertainties \(\delta_m\), \(\delta_J\), and \(\delta_{\ell}\) enter through the actuation matrix and multiply the control input, which is addressed by the duality-based robustification in Section 4. Note that the regression matrix \(\boldsymbol{ \phi }(\boldsymbol{ x },\boldsymbol{ u })\) is affine in \(\boldsymbol{ u }\).
For a safe control scenario, we consider a payload insertion task inspired by the deployment of aerial payloads on natural surfaces. The robot must remain \(p_{x}^{\min} \geq 0\) away from a wall while maintaining a minimum height and a bounded pitch angle. This is captured by the functions \[h_x(\boldsymbol{ x }) \!=\! p_x \!- p_{x}^{\min},~ h_z(\boldsymbol{ x }) \!=\! p_z \! - p_{z}^{\min},~ h_\vartheta(\boldsymbol{ x }) \!=\! \vartheta_{\max}^2 \! -\vartheta^2,\] which are combined into a single safety function as \[\label{eq:safety95function} h(\boldsymbol{ x }) = -\tfrac{1}{\kappa} \ln \! \big( {\rm e}^{-\kappa h_x(\boldsymbol{ x })} + {\rm e}^{-\kappa h_z(\boldsymbol{ x })} + {\rm e}^{-\kappa h_\vartheta(\boldsymbol{ x })} \big),\tag{37}\] with a smoothing parameter \({\kappa > 0}\) and safe set \(\mathcal{C}_{\rm S}\) in 2 .
The insertion task is executed by a primary controller \(\boldsymbol{k}_{\rm p}\) that is a cascaded position–attitude law steering the quadrotor to a goal \({(p_x^{\rm g},p_z^{\rm g})}\): \({a_x = - k^x_{\rm p}(p_x - p_x^{\rm g}) - k^x_{\rm d}v_x}\), \({a_z = -k^z_{\rm p}(p_z - p_z^{\rm g}) - k^z_{\rm d} v_z}\), \({F = m_0\sqrt{a_x^2+(g_0+a_z)^2}}\), \({\vartheta_{\rm d} = \operatorname{atan2}(a_x, g_0 + a_z)}\), \({M = J_0 \big(k^\vartheta_{\rm p}(\vartheta - \vartheta_{\rm d}) + k^\vartheta_{\rm d} \omega \big)}\), saturated to \(\mathcal{U}\). Since \(\boldsymbol{k}_{\rm p}\) is agnostic to both the safety constraint and the parametric uncertainty, we apply the proposed QP-based safety filter in 35 : the DREM estimator of Example 1 provides the parameter estimate \(\hat{\boldsymbol{\theta}}(t)\) and the certified error bounds \(\rho_i(t)\), the backup flow is propagated with \(\hat{\boldsymbol{\theta}}(t)\), and the safety conditions tightened by \(\rho_i(t)\) are enforced along this flow.
The robust backup controller takes the form \[\boldsymbol{k}_{\rm b}(\boldsymbol{ x }) = \begin{bmatrix} F_{\max} & \operatorname{sat} \big( k_\vartheta (\vartheta - \vartheta_{\rm r}) + k_\omega\omega \big) \end{bmatrix}^\top, \label{eq:quad95backup95controller}\tag{38}\] where \({k_\vartheta > 0}\) and \({k_\omega > 0}\) are gains, \({\vartheta_{\rm r} \in (0, \vartheta_{\max})}\) is a reference pitch angle, and \(\operatorname{sat}\) is a smooth saturation map into \([-M_{\max}, M_{\max}]\). The corresponding backup set is \[\!\!\!\mathcal{C}_{\rm B}\!\triangleq\! \bigg\{\! \boldsymbol{ x } \!\in\! \mathcal{X} \!: \begin{array}{@{}l@{}} h_{x,\rm b}(\boldsymbol{ x }) \!\geq\! 0, \;h_{z,\rm b}(\boldsymbol{ x }) \!\geq\! 0, \;h_{\vartheta,\rm b}(\boldsymbol{ x }) \!\geq\! 0 \\ h_{v_x,\rm b}(\boldsymbol{ x }) \!\geq\! 0, \;h_{v_z,\rm b}(\boldsymbol{ x }) \!\geq\! 0 \end{array} \!\bigg\}\!, \label{eq:quad95backup95set}\tag{39}\] where \({h_{x, \rm b}(\boldsymbol{ x }) \!=\! p_x \!-\! p_{x}^{\rm min} \!-\! r_x}\) and \({h_{z,\rm b}(\boldsymbol{ x }) \!=\! p_z \!-\! p_{z}^{\rm min} \!-\! r_z}\) represent surface and altitude clearance with margins \({r_x \!>\! 0}\) and \({r_z \!>\! 0}\), while \({h_{v_x,\rm b}(\boldsymbol{ x }) \!=\! v_x}\) and \({h_{v_z,\rm b}(\boldsymbol{ x }) \!=\! v_z}\) prescribe positive velocities. For the pitch dynamics, we let \({\boldsymbol{ y }_\vartheta \!\triangleq\! \begin{bmatrix} \vartheta - \vartheta_{\rm r} \!&\! \omega \end{bmatrix}^{\top}}\) and \({h_{\vartheta,\rm b}(\boldsymbol{ x }) \!=\! \varrho_\vartheta - \boldsymbol{ y }_\vartheta^{\top} \boldsymbol{ P }_\vartheta \boldsymbol{ y }_\vartheta}\), with \({\varrho_\vartheta \!>\! 0}\) and \({\boldsymbol{ P }_\vartheta \!=\! \boldsymbol{ P }_\vartheta^{\top} \succ 0}\). Further details on the construction of \(\boldsymbol{k}_{\rm b}\) and \(\mathcal{C}_{\rm B}\) can be found in the supplementary material, where it is shown that 38 renders \(\mathcal{C}_{\rm B}\) in 39 robustly forward invariant for suitable choices of \(\boldsymbol{ P }_\vartheta\), \(\varrho_\vartheta\), \(r_x\), \(r_z\), and \(\vartheta_{\rm r}\).
Fig. 1 shows a simulation of the planar quadrotor using the proposed robust adaptive bCBF and the DREM estimator of Example 1. We compare our method against two baselines: the primary controller \(\boldsymbol{k}_{\rm p}\) alone, and the nominal bCBF method of Section 2 that propagates the backup flow with the nominal model (\({\boldsymbol{ \theta } = \mathbf{0}}\)) and applies no tightening or robustification. The true parameters \({\boldsymbol{ \theta } = \begin{bmatrix}0.08 \!\!& 0.08 \!\!& 0.22 \!\!& -0.32 \!\!& 0.008 \!\!& 0.003\end{bmatrix}^\top}\) correspond to a quadrotor that is approximately \(47\%\) heavier than the nominal model; the remaining simulation parameters are provided in the code repository. As shown in Fig. 1, the primary controller alone enters the unsafe set. The nominal bCBF intervenes late and violates the surface clearance as the true quadrotor is heavier than the nominal model. On the other hand, the proposed robust adaptive bCBF ensures safety by keeping the quadrotor within \(\mathcal{C}_{\rm S}\) and satisfying the input constraints despite parametric uncertainty. This is achieved using the parameter estimates, whose certified bounds shrink over time. Accordingly, the estimated backup flows \(\widehat{\boldsymbol{\varphi}}_{\rm b}(\tau,\boldsymbol{ x },t)\) initially deviate from the true backup flows \(\boldsymbol{\varphi}_{\rm b}(\tau,\boldsymbol{ x })\) and later coincide with them as the estimates converge, making the tightening terms vanish and the inner approximation \(\widehat{\mathcal{C}}_{\rm I}(t)\) approach the implicit safe set \(\mathcal{C}_{\rm I}\).
We presented a robust adaptive backup CBF framework for the safety-critical control of nonlinear systems with parametric uncertainty and bounded inputs. This method computes the backup flow using an online parameter estimate and tightens the backup safety constraints with certified component-wise error bounds. A duality-based robustification yielded a safety filter in the form of a convex QP. Future work will focus on tighter bounds for flow prediction errors.
We derive the constraints in 28 by expressing the time derivatives \(\dot{\bar h}\) and \(\dot{\bar h}_{\rm b}\) in 27 . First, we define the derivatives \[\begin{align} \boldsymbol{\Phi}(\tau,\boldsymbol{x},t) \triangleq \tfrac{\partial \widehat{\boldsymbol{\varphi}}_{\rm b}(\tau,\boldsymbol{ x },t) }{\partial \boldsymbol{ x } }, \;\; \boldsymbol{\Gamma}(\tau,\boldsymbol{x},t) \triangleq \tfrac{\partial \widehat{\boldsymbol{\varphi}}_{\rm b}(\tau,\boldsymbol{ x },t) }{\partial \hat{\boldsymbol{\theta}} }, \\ \hat{\boldsymbol{ J }}_{\rm b}(\tau,\boldsymbol{ x },t) \triangleq \left. \tfrac{\partial }{\partial \boldsymbol{ z } } \boldsymbol{ f }_{\rm b}\big(\boldsymbol{ z },\hat{\boldsymbol{\theta}}(t)\big) \right|_{\boldsymbol{ z }=\widehat{\boldsymbol{\varphi}}_{\rm b}(\tau,\boldsymbol{ x },t)}, \end{align}\] where \(\boldsymbol{ \Phi }\) and \(\boldsymbol{ \Gamma }\) represent the sensitivity of the estimated backup flow \(\widehat{\boldsymbol{ \varphi }}_{\rm b}\) to the current state and parameter estimate, while \(\hat{\boldsymbol{ J }}_{\rm b}\) is the Jacobian of the estimated backup system 20 . The sensitivity matrices can be computed by solving \[\begin{align} \tfrac{\partial}{\partial \tau}\boldsymbol{ \Phi }(\tau,\boldsymbol{ x },t) &= \hat{\boldsymbol{ J }}_{\rm b}(\tau,\boldsymbol{ x },t) \boldsymbol{ \Phi }(\tau,\boldsymbol{ x },t), \quad \boldsymbol{ \Phi }(0,\boldsymbol{ x },t) = \boldsymbol{I}, \nonumber\\ \tfrac{\partial}{\partial \tau}\boldsymbol{ \Gamma }(\tau,\boldsymbol{ x },t) &= \hat{\boldsymbol{ J }}_{\rm b}(\tau,\boldsymbol{ x },t) \boldsymbol{ \Gamma }(\tau,\boldsymbol{ x },t) + \boldsymbol{ \psi }_{\rm b}(\widehat{\boldsymbol{\varphi}}_{\rm b}(\tau,\boldsymbol{ x },t)), \\ \boldsymbol{ \Gamma }(0,\boldsymbol{ x },t) &= \mathbf{0}. \nonumber \end{align}\]
Then, by differentiating the expressions of \(\bar{h}\) and \(\bar{h}_{\rm b}\) in 26 , the total time derivatives \(\dot{\bar h}\) and \(\dot{\bar h}_{\rm b}\) become \[\begin{align} \dot{\bar h}(\tau,\boldsymbol{ x },t,\boldsymbol{ u }) & = \tfrac{\partial \bar{h} }{\partial \boldsymbol{ x } }(\tau,\boldsymbol{ x },t) \dot{\boldsymbol{ x }} + \tfrac{\partial \bar{h} }{\partial t }(\tau,\boldsymbol{ x },t), \\ \dot{\bar h}_{\rm b}(\boldsymbol{ x },t,\boldsymbol{ u }) & = \tfrac{\partial \bar{h}_{\rm b} }{\partial \boldsymbol{ x } }(\boldsymbol{ x },t) \dot{\boldsymbol{ x }} + \tfrac{\partial \bar{h}_{\rm b} }{\partial t }(\boldsymbol{ x },t), \end{align}\] where the partial derivatives are expressed via the chain rule: \[\begin{align} \tfrac{\partial \bar{h} }{\partial \boldsymbol{ x } }(\tau,\boldsymbol{ x },t) &= \nabla h(\widehat{\boldsymbol{\varphi}}_{\rm b}(\tau,\boldsymbol{ x },t))\boldsymbol{\Phi}(\tau,\boldsymbol{x},t) - \tfrac{\partial \epsilon }{\partial \boldsymbol{ x } }(\tau,\boldsymbol{ x },t), \\ \tfrac{\partial \bar{h} }{\partial t }(\tau,\boldsymbol{ x },t) &= \nabla h(\widehat{\boldsymbol{\varphi}}_{\rm b}(\tau,\boldsymbol{ x },t)) \boldsymbol{\Gamma}(\tau,\boldsymbol{x},t)\dot{\hat{\boldsymbol{\theta}}} - \tfrac{\partial \epsilon }{\partial t }(\tau,\boldsymbol{ x },t), \end{align}\] \[\begin{align} \tfrac{\partial \bar{h}_{\rm b} }{\partial \boldsymbol{ x } }(\boldsymbol{ x },t) &= \nabla h_{\rm b}(\widehat{\boldsymbol{\varphi}}_{\rm b}(T,\boldsymbol{ x },t))\boldsymbol{\Phi}(T,\boldsymbol{x},t) - \tfrac{\partial \epsilon_{\rm b} }{\partial \boldsymbol{ x } }(\boldsymbol{ x },t), \\ \tfrac{\partial \bar{h}_{\rm b} }{\partial t }(\boldsymbol{ x },t) &= \nabla h_{\rm b}(\widehat{\boldsymbol{\varphi}}_{\rm b}(T,\boldsymbol{ x },t)) \boldsymbol{\Gamma}(T,\boldsymbol{x},t)\dot{\hat{\boldsymbol{\theta}}} - \tfrac{\partial \epsilon_{\rm b} }{\partial t }(\boldsymbol{ x },t). \end{align}\] Here \(\dot{\hat{\boldsymbol{\theta}}}\) is given by the estimator in 11 , while \(\dot{\boldsymbol{ x }}\) is given by the dynamics in 10 as \[\dot{\boldsymbol{ x }} = \boldsymbol{ f }(\boldsymbol{ x }) + \boldsymbol{ g }(\boldsymbol{ x })\boldsymbol{ u } + \boldsymbol{ \phi }(\boldsymbol{ x },\boldsymbol{ u })\hat{\boldsymbol{\theta}}(t) + \boldsymbol{ \phi }(\boldsymbol{ x },\boldsymbol{ u })\tilde{\boldsymbol{\theta}}(t).\]
Next, substituting these derivatives into 27 and moving all terms to the left-hand side, we obtain 28 with \[\begin{align} a(\tau,\boldsymbol{ x },\boldsymbol{ u },t) & \triangleq \tfrac{\partial \bar{h} }{\partial \boldsymbol{ x } }(\tau,\boldsymbol{ x },t) \big( \boldsymbol{ f }(\boldsymbol{ x }) + \boldsymbol{ g }(\boldsymbol{ x })\boldsymbol{ u } + \boldsymbol{ \phi }(\boldsymbol{ x },\boldsymbol{ u })\hat{\boldsymbol{\theta}}(t) \big) \\ & \quad + \tfrac{\partial \bar{h} }{\partial t }(\tau,\boldsymbol{ x },t) + \alpha\big(\bar h(\tau,\boldsymbol{ x },t)\big), \\ \boldsymbol{ c }(\tau,\boldsymbol{ x },\boldsymbol{ u },t)^{\top} & \triangleq \tfrac{\partial \bar{h} }{\partial \boldsymbol{ x } }(\tau,\boldsymbol{ x },t) \boldsymbol{ \phi }(\boldsymbol{ x },\boldsymbol{ u }), \\ a_{\rm b}(\boldsymbol{ x },\boldsymbol{ u },t) & \triangleq \tfrac{\partial \bar{h}_{\rm b} }{\partial \boldsymbol{ x } }(\boldsymbol{ x },t) \big( \boldsymbol{ f }(\boldsymbol{ x }) + \boldsymbol{ g }(\boldsymbol{ x })\boldsymbol{ u } + \boldsymbol{ \phi }(\boldsymbol{ x },\boldsymbol{ u })\hat{\boldsymbol{\theta}}(t) \big) \\ & \quad + \tfrac{\partial \bar{h}_{\rm b} }{\partial t }(\boldsymbol{ x },t) + \alpha_{\rm b}\big(\bar h_{\rm b}(\boldsymbol{ x },t)\big), \\ \boldsymbol{ c }_{\rm b}(\boldsymbol{ x },\boldsymbol{ u },t)^{\top} & \triangleq \tfrac{\partial \bar{h}_{\rm b} }{\partial \boldsymbol{ x } }(\boldsymbol{ x },t) \boldsymbol{ \phi }(\boldsymbol{ x },\boldsymbol{ u }). \end{align}\]
0.9
To simplify the notation used in this section, we use \({\lambda_{\min}(\boldsymbol{ S })}\) and \({\lambda_{\max}(\boldsymbol{ S })}\) to denote the smallest and largest eigenvalues of a symmetric matrix \(\boldsymbol{ S }\), and we define \[\begin{align} & a_m(\boldsymbol{ \theta }) \triangleq\frac{1}{m_0} + \delta_m, \;\; a_J(\boldsymbol{ \theta }) \triangleq\frac{1}{J_0} + \delta_J, \;\;\boldsymbol{ e }_1 \triangleq\begin{bmatrix} 1 & 0 \end{bmatrix}^{\top}, \\ & \boldsymbol{ K }_\vartheta \!\triangleq\! \begin{bmatrix} k_\vartheta & k_\omega \end{bmatrix}, \;\boldsymbol{ b }_\vartheta \!\triangleq\! \begin{bmatrix} 0 & 1 \end{bmatrix}^{\top}, \; \boldsymbol{ A }_\vartheta(a) \!\triangleq\!\! \begin{bmatrix} 0 & \!1 \\ -a k_\vartheta & \!-a k_\omega \end{bmatrix}, \\ & \Delta_\vartheta \!\triangleq\!\! \sqrt{\!\varrho_\vartheta \boldsymbol{ e }_1^{\top} \boldsymbol{ P }_\vartheta^{-1} \boldsymbol{ e }_1}, \; \Delta_M \!\triangleq\!\! \sqrt{\!\varrho_\vartheta\boldsymbol{ K }_\vartheta \boldsymbol{ P }_\vartheta^{-1} \boldsymbol{ K }_\vartheta^{\top}}, \; \bar \vartheta \!\triangleq\! \vartheta_{\rm r} \!+\! \Delta_\vartheta. \end{align}\] Then, parameter bounds in Assumption 1 induce known constants satisfying \[\begin{align} & \delta_g^{-} \leq \delta_g \leq \delta_g^{+}, \;\; \delta_\ell^{-} \leq \delta_\ell \leq \delta_\ell^{+}, \\ & 0 < a_J^{-} \leq a_J(\boldsymbol{ \theta }) \leq a_J^{+}, \;\;0 < a_m^{-} \leq a_m(\boldsymbol{ \theta }) \leq a_m^{+}, \end{align}\] for all \({\boldsymbol{ \theta } \in \Theta}\). The proposition below provides sufficient conditions on the design parameters of the backup controller 38 and the backup set 39 for Assumption 2 to hold for the uncertain quadrotor model 36 .
Proposition 1. Consider the uncertain quadrotor model 36 , the safety function 37 with the safe set \(\mathcal{C}_{\rm S}\), the backup controller 38 , and the backup set \(\mathcal{C}_{\rm B}\) in 39 . If the controller gains \({k_\vartheta > 0}\), \({k_\omega > 0}\) and the design parameters \({\boldsymbol{ P }_\vartheta = \boldsymbol{ P }_\vartheta^{\top} \succ 0}\), \({\boldsymbol{ Q }_\vartheta = \boldsymbol{ Q }_\vartheta^{\top} \succ 0}\), \({\varrho_\vartheta > 0}\), \({\vartheta_{\rm r} \in (0,\vartheta_{\max})}\), \({r_x, r_z > 0}\), and \({r_\vartheta \in (0,\vartheta_{\max}^2)}\), with \({\bar\vartheta < \pi/2}\), are chosen such that \[\label{eq:quad95backup95conditions} \begin{align} & \boldsymbol{ A }_\vartheta(a_J^{-})^{\top} \boldsymbol{ P }_\vartheta + \boldsymbol{ P }_\vartheta \boldsymbol{ A }_\vartheta(a_J^{-}) \preceq -\boldsymbol{ Q }_\vartheta, \\ & \boldsymbol{ A }_\vartheta(a_J^{+})^{\top} \boldsymbol{ P }_\vartheta + \boldsymbol{ P }_\vartheta \boldsymbol{ A }_\vartheta(a_J^{+}) \preceq -\boldsymbol{ Q }_\vartheta, \\ & \Delta_M \leq M_{\max}, \\ & \vartheta_{\rm r} - \Delta_\vartheta \geq 0, \\ & \vartheta_{\rm r} + \Delta_\vartheta \leq \sqrt{\vartheta_{\max}^2 - r_\vartheta}, \\ & \varrho_\vartheta \!\geq\! \lambda_{\max}(\boldsymbol{ P }_\vartheta) \! \left(\! \frac{ 2\left\Vert \boldsymbol{ P }_\vartheta\boldsymbol{ b }_\vartheta \right\Vert F_{\max} \max\{|\delta_\ell^{-}|,|\delta_\ell^{+}|\} }{ \lambda_{\min}(\boldsymbol{ Q }_\vartheta) } \!\right)^2, \\ & a_m^{-} F_{\max} \cos(\bar\vartheta) - g_0 -\delta_g^{+} \geq 0, \\ & {\rm e}^{-\kappa r_x} + {\rm e}^{-\kappa r_z} + {\rm e}^{-\kappa r_\vartheta} \leq 1, \end{align}\tag{40}\] then the moment saturation in 38 is inactive on \(\mathcal{C}_{\rm B}\), \({\mathcal{C}_{\rm B}\subseteq \mathcal{C}_{\rm S}}\) holds, and the backup controller 38 renders \(\mathcal{C}_{\rm B}\) robustly forward invariant for 36 for all \({\boldsymbol{ \theta } \in \Theta}\), i.e., Assumption 2 is satisfied.
We first consider the pitch dynamics. On the set \(\mathcal{C}_{\rm B}\), \({h_{\vartheta,\rm b}(\boldsymbol{ x }) \geq 0}\) implies \({\boldsymbol{ y }_\vartheta^{\top} \boldsymbol{ P }_\vartheta \boldsymbol{ y }_\vartheta \leq \varrho_\vartheta}\), and hence \[|\vartheta - \vartheta_{\rm r}| \leq \Delta_\vartheta, \;\;\left| \boldsymbol{ K }_\vartheta \boldsymbol{ y }_\vartheta \right| \leq \Delta_M.\] Thus, by the fourth and fifth conditions in 40 , the pitch angle satisfies \({0 \leq \vartheta \leq \bar\vartheta \leq \sqrt{\vartheta_{\max}^2 - r_\vartheta}}\) on \(\mathcal{C}_{\rm B}\). Moreover, the third condition in 40 yields \({|\boldsymbol{ K }_\vartheta \boldsymbol{ y }_\vartheta| \leq M_{\max}}\), and hence the moment saturation in 38 is inactive on \(\mathcal{C}_{\rm B}\).
We next verify the robust invariance of the pitch dynamics under the backup controller, which satisfy \[\dot{\boldsymbol{ y }}_\vartheta = \boldsymbol{ A }_\vartheta (a_J(\boldsymbol{ \theta })) \boldsymbol{ y }_\vartheta + \boldsymbol{ b }_\vartheta \delta_\ell F_{\max}.\] Since \(\boldsymbol{ A }_\vartheta(a)\) depends affinely on \(a\), the first two conditions in 40 imply \[\boldsymbol{ A }_\vartheta(a)^{\top} \boldsymbol{ P }_\vartheta + \boldsymbol{ P }_\vartheta\boldsymbol{ A }_\vartheta(a) \preceq -\boldsymbol{ Q }_\vartheta, \;\; \forall a \in[a_J^{-}, a_J^{+}].\] Therefore, with \({V_\vartheta \triangleq\boldsymbol{ y }_\vartheta^{\top} \boldsymbol{ P }_\vartheta \boldsymbol{ y }_\vartheta}\), we have \[\begin{align} & \dot{V}_\vartheta = \boldsymbol{ y }_\vartheta^{\top} \!\left( \boldsymbol{ A }_\vartheta(a_J(\boldsymbol{ \theta }))^{\top}\boldsymbol{ P }_\vartheta \!+\! \boldsymbol{ P }_\vartheta\boldsymbol{ A }_\vartheta(a_J(\boldsymbol{ \theta })) \!\right)\! \boldsymbol{ y }_\vartheta \\ & \;\;\;\;+ 2 \boldsymbol{ y }_\vartheta^{\top} \boldsymbol{ P }_\vartheta \boldsymbol{ b }_\vartheta\delta_\ell F_{\max} \\ & \!\leq \!\! -\lambda_{\min}(\boldsymbol{ Q }_\vartheta) \! \left\Vert \boldsymbol{ y }_\vartheta \right\Vert^{2} \!\!+\! 2 F_{\max} \! \left\Vert \boldsymbol{ P }_\vartheta\boldsymbol{ b }_\vartheta \right\Vert \max\{|\delta_\ell^{-}|,|\delta_\ell^{+}|\} \! \left\Vert \boldsymbol{ y }_\vartheta \right\Vert. \end{align}\] On the boundary \({h_{\vartheta,\rm b}(\boldsymbol{ x }) = 0}\), we have \({V_\vartheta = \varrho_\vartheta}\), and hence \({\left\Vert \boldsymbol{ y }_\vartheta \right\Vert \geq \sqrt{\varrho_\vartheta / \lambda_{\max}(\boldsymbol{ P }_\vartheta)} > 0}\). Therefore, by the sixth condition in 40 , \({\dot{V}_\vartheta \leq 0}\) on the boundary of the zero superlevel set of \(h_{\vartheta,\rm b}(\boldsymbol{ x })\). Equivalently, \({\dot{h}_{\vartheta,\rm b}(\boldsymbol{ x }) \geq 0}\) on this boundary, and the pitch component of \(\mathcal{C}_{\rm B}\) is robustly forward invariant.
We now consider the horizontal component of the motion. Since \({0 \leq \vartheta \leq \bar\vartheta < \pi/2}\) on \(\mathcal{C}_{\rm B}\), the horizontal dynamics of 36 under 38 satisfy \[\dot{v}_x = a_m(\boldsymbol{ \theta }) F_{\max} \sin(\vartheta) - c_x v_x.\] On the boundary \({h_{v_x, \rm b}(\boldsymbol{ x }) \!=\! 0}\), we have \({v_x = 0}\), and therefore \[\dot{h}_{v_x,\rm b}(\boldsymbol{ x }) = a_m(\boldsymbol{ \theta }) F_{\max} \sin(\vartheta) \geq 0,\] where we used \({a_m(\boldsymbol{ \theta }) > 0}\) and \({\vartheta \geq 0}\). Hence, the \(v_x\) component of \(\mathcal{C}_{\rm B}\) is robustly forward invariant. Moreover, on \(\mathcal{C}_{\rm B}\), \({v_x \geq 0}\), and hence \({\dot{h}_{x,\rm b}(\boldsymbol{ x }) = v_x \geq 0}\). Therefore, the surface clearance component of \(\mathcal{C}_{\rm B}\) is robustly forward invariant.
We next consider the altitude component of the motion. On the boundary \({h_{v_z,\rm b}(\boldsymbol{ x }) = 0}\), we have \({v_z = 0}\), and the vertical dynamics of 36 satisfy \[\begin{align} \dot{h}_{v_z,\rm b}(\boldsymbol{ x }) = \dot{v}_z & = -g_0 - \delta_g + a_m(\boldsymbol{ \theta })F_{\max}\cos(\vartheta) \\ & \geq -g_0 - \delta_g^{+} + a_m^{-}F_{\max}\cos(\bar\vartheta) \geq 0, \end{align}\] where we used \({0 \leq \vartheta \leq \bar \vartheta < \pi/2}\) and the seventh condition in 40 . Therefore, the \(v_z\) component of \(\mathcal{C}_{\rm B}\) is robustly forward invariant. Furthermore, on \(\mathcal{C}_{\rm B}\), \({v_z \geq 0}\), thus \({\dot{h}_{z,\rm b}(\boldsymbol{ x }) = v_z \geq 0}\), and the altitude clearance component of \(\mathcal{C}_{\rm B}\) is also robustly forward invariant.
Finally, we show that \({\mathcal{C}_{\rm B}\subseteq \mathcal{C}_{\rm S}}\). Since \({h_{x,\rm b}(\boldsymbol{ x }) \geq 0}\) and \({h_{z,\rm b}(\boldsymbol{ x }) \geq 0}\), we have \({h_x(\boldsymbol{ x }) \geq r_x}\) and \({h_z(\boldsymbol{ x }) \geq r_z}\). Moreover, by the fifth condition in 40 , \({h_{\vartheta,\rm b}(\boldsymbol{ x }) \geq 0}\) implies \({h_\vartheta(\boldsymbol{ x }) = \vartheta_{\max}^2-\vartheta^2 \geq r_\vartheta}\). Therefore, by the last condition in 40 , the smooth minimum safety function 37 satisfies \({h(\boldsymbol{ x }) \geq 0}\) for all \({\boldsymbol{ x } \in \mathcal{C}_{\rm B}}\), i.e., \({\mathcal{C}_{\rm B}\subseteq \mathcal{C}_{\rm S}}\).
Combining the pitch, horizontal, and altitude invariance results with the input admissibility and \({\mathcal{C}_{\rm B}\subseteq \mathcal{C}_{\rm S}}\), the backup controller 38 renders the backup set 39 robustly forward invariant for 36 for all \({\boldsymbol{ \theta } \in \Theta}\).
\(^{1}\) E. Daş is with the Department of Mechanical, Materials, and Aerospace Engineering, Illinois Institute of Technology, Chicago, IL 60616, USA, edas2@illinoistech.edu.↩︎
\(^{2}\) D. E. J. van Wijk, A. D. Ames, and J. W. Burdick are with the Mechanical and Civil Engineering, California Institute of Technology, Pasadena, CA 91125, USA,
{vanwijk, ames, jburdick}@caltech.edu.↩︎
\(^{3}\) T. G. Molnar is with Mechanical Engineering, Wichita State University, Wichita, KS 67260, USA, tamas.molnar@wichita.edu.↩︎
In this work, we use \({\left\Vert \boldsymbol{ z } \right\Vert_{\rm s} = \sqrt{\left\Vert \boldsymbol{ z } \right\Vert^2 + \sigma^2}}\) with \({\sigma > 0}\), which is continuously differentiable and satisfies \({\left\Vert \boldsymbol{ z } \right\Vert_{\rm s} \geq \left\Vert \boldsymbol{ z } \right\Vert}\) for all \({\boldsymbol{ z } \in \mathbb{R}^n}\).↩︎
The code and additional details of our simulations can be found at
https://github.com/ersindas/abCBFs↩︎