{"id":"6a45f4be-b3e4-4528-a5fb-28721345b7f5","arxiv_id":"2505.08559","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":5,"one_line_summary":"The paper derives SDPs that co-design quadratic control barrier functions and linear feedback controllers, certifying worst-case or probabilistic safety for discrete-time uncertain linear systems.","lead":"This paper provides two convex optimization programs (SDPs) that jointly design a safety certificate and a controller for discrete-time linear systems under additive noise. The first guarantees safety for all time under bounded disturbances, while the second guarantees high-probability safety over a finite horizon for unbounded, stochastic disturbances.","discovery_kind":"new_method","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Problem (14) does not enforce the trace term of the expected-increase condition: (14d) gives Tr(Ω^{-1}Σ) ≤ nλ, not ≤ λ, so Theorem 3.7's probability bound can fail for n>1.","rationale":"The reader's conditional verdict attributed the risk to Assumptions 2.1/3.1 and to the initial-margin step. My pass found a more basic failure: the LMI (14d) is not equivalent to the trace inequality used in the proof of Theorem 3.7. The counterexample above falsifies the finite-horizon claim as written. The infinite-horizon SDP (8) may still be sound, and the ambiguity-robust reformulation may be repairable, but the stochastic finite-horizon contribution—one of the two headline results and the one used in the pendulum example—does not hold. A corrected constraint, such as enforcing the trace bound directly, would likely restore the result, but the current text should not be accepted with Theorem 3.7 stated this way.","tokens_in":27936,"tokens_out":30873,"duration_ms":314668,"concrete_test":"Run the n=100 instance above as an SDP feasibility check and compare the theorem's bound with the exact exit probability. Set A=0, B=0, D=I, Σ=I, β=0.99, δ=0, λ=0.99, Ω=1.21I, R=I, σ=0.999, S=[−1.1,1.1]^100. Verify that (14d)–(14h) are all feasible. Then for x0=0 and T=1, compute Prexit = 1 − (P(|N(0,1)| ≤ 1.1))^100 ≈ 1. The theorem's bound is 0.99001, so the exact exit probability exceeds it. If this reproduces, Theorem 3.7 is false as stated.","verdict_should_be":"REJECT","load_bearing_attack":"The finite-horizon claim (Theorem 3.7) stands or falls on Problem (14) encoding the expected-increase condition (10). In the proof, (10) reduces to a quadratic matrix inequality plus the scalar condition β−δ−Tr(Ω^{−1}Σ) ≥ 0. The paper encodes that scalar condition by (14e) β−δ−λ ≥ 0 together with (14d) [λI, Σ^{1/2}; Σ^{1/2}, Ω] ⪰ 0. But the Schur complement of (14d) with respect to Ω is λI − Σ^{1/2}Ω^{−1}Σ^{1/2} ⪰ 0, which gives Tr(Ω^{−1}Σ) ≤ nλ, not ≤ λ. Thus feasibility of (14) does not imply (10). This is an internal LMI gap, not a model-misspecification issue. Concrete witness: take n=100, A=0, B=0, D=I, Σ=I, β=0.99, δ=0, λ=0.99, Ω=1.21I, R=I, σ=0.999, and S=[−1.1,1.1]^100 represented by a_j=±e_j/1.1. All constraints of (14) are satisfied, and Ω=1.21I attains the logdet maximum under the safe-set upper bounds, with I ⊆ B ⊆ S. For x0=0 and T=1, the theorem's bound is Prexit ≤ 1−σ(1−β) = 0.99001, but the actual exit probability is 1 − (P(|N(0,1)| ≤ 1.1))^100 ≈ 1, which violates the claimed bound. The fix is to enforce Tr(Ω^{−1}Σ) ≤ β−δ directly, and to include D when D ≠ I.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper proposes convex semidefinite programs for the joint synthesis of a quadratic control barrier function b(x)=1-x^T Omega^{-1}x and a linear feedback u=Y Omega^{-1}x for discrete-time linear systems with additive disturbances. Problem (8) is intended to certify infinite-horizon, worst-case safety under bounded disturbances, while Problem (14) is intended to certify finite-horizon, joint-in-time (1-alpha)-safety under i.i.d. sub-Gaussian noise using a martingale argument based on Ville's inequality. The paper also discusses input constraints, distributional ambiguity, safety filters, and SOS-based extensions to general semialgebraic safe sets. The main claims are Theorems 3.3 and 3.7, with the finite-horizon result being the principal contribution for unbounded noise.","tokens_in":28381,"tokens_out":15611,"duration_ms":157324,"significance":"If the stated results were correct, the paper would be a useful contribution: it offers an explicit convex SDP for co-designing a CBF and a feedback law, avoiding the usual bilinearities and alternating SOS schemes, and it provides a reasonably detailed derivation of the infinite-horizon invariance conditions. The distributionally robust extension and the safety-filter formulation are also natural and potentially valuable. However, the finite-horizon result is the advertised headline for unbounded disturbances, and that result is false as stated. The error is internal to the SDP encoding: Problem (14) does not enforce the scalar trace condition needed in the expected-increase inequality, and Theorem 3.7 is contradicted by a small feasible instance. Because the numerical example in Section 5 rests on this SDP, the central contribution cannot stand without a substantial redesign.","major_comments":[{"comment":"Algorithm 1 is described as having guaranteed convergence to a feasible CBF and controller, but no convergence proof or termination argument is provided. The initialization step (27) may not produce B subset of S, and the alternating iterations (28)--(29) are not shown to preserve feasibility or to converge. This does not affect the main theorems, but if the extension is to be claimed with a guarantee, the proof is missing.","section":"Section 4.4, Algorithm 1"}],"minor_comments":[{"comment":"The statement of Theorem 3.7 should explicitly restate the hypotheses on the safe set S and the initial set I from Assumption 3.1, including the role of the vectors a_j and the scalar sigma; as written, the theorem refers to S and I without defining them in its own statement.","section":"Section 3.2, Theorem 3.7 statement"},{"comment":"The proof of Lemma 4.4 is omitted with the comment that it follows directly from the definition of convexity; for a journal submission, the short proof should be included or a precise citation given.","section":"Section 4.3, Lemma 4.4"},{"comment":"The formulas for a(t), kappa, and the cases delta<0 and delta>=0 are hard to follow because some symbols in the displayed derivation are garbled, and the relationship between the formulas for alpha_1 and alpha_2 and the later simplified bounds is not shown step by step. Please rewrite this part with consistent notation.","section":"Example 1, Eq. (11) and surrounding display"},{"comment":"The symbol R is used both for a given matrix defining the initial ellipsoid and for the real numbers, and the appearance R^n in the same context can be confusing. This should be clarified in the notation subsection.","section":"Notation"}],"recommendation":"reject","confidential_remarks":"The finite-horizon theorem is false as written. The counterexample in major comment 1 is feasible for Problem (14) and violates the claimed alpha-bound, and the issue is internal to the LMI encoding rather than a matter of model misspecification. The advertised finite-horizon SDP would need to be redesigned, and the numerical results in Section 5 would need to be recomputed. I see no issue with the use of the self-citation [34] for the quadratic parametrization."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Short version: the deterministic half is solid; the finite-horizon probabilistic guarantee in Theorem 3.7 is not correct as stated for n>1. The genuinely new contribution is a one-shot convex SDP for co-designing a quadratic CBF and linear feedback for discrete-time linear systems with additive stochastic noise, plus a distributionally robust extension and a safety-filter reformulation. The infinite-horizon SDP (8) is clean; the Schur-complement/S-Procedure proof checks out, as does the martingale mechanism for joint-in-time bounds. The extensions are useful and mostly standard.\n\nThe load-bearing flaw is the encoding of the expected-increase condition (10) into (14). Condition (10) reduces to a quadratic matrix inequality plus the scalar condition β−δ−Tr(DΣD^TΩ^{-1}) ≥ 0. The paper instead uses (14e) β−δ−λ ≥ 0 and (14d) [λI, Σ^{1/2}; Σ^{1/2}, Ω] ⪰ 0. The Schur complement of (14d) only gives Σ^{1/2}Ω^{-1}Σ^{1/2} ⪯ λI, hence Tr(Ω^{-1}Σ) ≤ nλ, not ≤ λ, and D does not appear at all. So feasibility of (14) does not imply (10) for n>1. The stress-test counterexample is valid: with n=100, A=0, B=0, D=I, Σ=I, β=0.99, δ=0, λ=0.99, Ω=1.21I, all constraints hold, but the actual T=1 exit probability from x0=0 is about 1, far above the claimed α≈0.99001. That is not a minor gap.\n\nA second, independent problem sits in the same theorem: the bound replaces b(x0) with σ, but the containment LMI (14g) only gives b(x0) ≥ 0. For x0 on the boundary of I, b(x0) can be near zero, so the claimed bound cannot hold for all x0∈I unless a stricter containment is used (e.g., [R I; I Ω] ⪰ 0) or the bound is restated with 0.\n\nSmaller issues: the quasi-convexity of g(λ) in Remark 3.4 is asserted without proof, and Algorithm 1 claims guaranteed convergence without a formal argument. These are secondary.\n\nThe deterministic SDP and the extensions are worth having, and the stochastic co-design idea is valuable. This paper deserves a serious referee; the likely fix is to enforce the scalar trace inequality directly and correct the initial-set margin. As it stands, Theorem 3.7 should not be used as a certificate. Send it to peer review, but expect heavy revision.","headline":"The deterministic co-design SDP is solid, but the finite-horizon theorem has a real trace-term LMI gap plus an initial-condition margin problem that invalidate the bound as stated for n>1.","tokens_in":28887,"tokens_out":8065,"would_cite":false,"duration_ms":67874,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["90C22","93C55","93E15"],"pacs":[],"model":"deepseek-v4-flash","headline":"This paper proves that a quadratic control barrier function and a linear feedback controller for a discrete-time linear system with additive disturbances can be co-designed by solving a single convex semidefinite program, guaranteeing…","keywords":["control barrier functions","semidefinite programming","discrete-time systems","stochastic disturbances","martingale inequality","safety certificates","convex optimization","distributionally robust control"],"falsifier":"Run a scalar system $x_{t+1}=0.5x_t+u_t+w_t$ with a chosen safe set and initial ellipsoid, solve SDP (14), and draw $w_t$ from a zero-mean heavy-tailed distribution (e.g., a t-distribution with three degrees of freedom) scaled to have the same covariance $\\Sigma$ as assumed. If the measured exit probability over $T=100$ steps exceeds the $\\alpha$ predicted by Theorem 3.7 for a feasible SDP, the sub-Gaussian assumption is violated and the certificate fails. For the bounded-support case, set $w_t=1$ deterministically at every step starting from a boundary point of $B$; if the state exits $B$ in one step despite SDP (8) being feasible, the invariance certificate is refuted.","tokens_in":27739,"feed_emoji":"🛡️","tokens_out":5905,"duration_ms":58259,"temperature":0.7,"pith_summary":"The paper proves that for a linear discrete-time system with additive disturbances, both a quadratic control barrier function $b(x)=1-x^\\top\\Omega^{-1}x$ and a linear feedback $u(x)=Y\\Omega^{-1}x$ can be co-designed by solving a single semidefinite program. When the disturbance support is bounded, feasibility of the SDP guarantees that the ellipsoid $B=\\{x\\mid b(x)\\ge 0\\}$ contains the initial set, is contained in the safe set, and is invariant under every disturbance in the uncertainty set. When the disturbances are unbounded and sub-Gaussian, a second SDP encodes an expected-increase condition that, via a constructed supermartingale and Ville's inequality, yields a joint-in-time safety probability of at least $1-\\alpha$ over a finite horizon. The value for a practitioner is that safety and control are designed simultaneously in a convex problem, avoiding the alternating sum-of-squares scheme that requires a feasible initial CBF and provides no convergence guarantee.","feed_headline":"Safety barrier and controller co-designed in one convex program","feed_subtitle":"Two concrete guarantees: forever-safe for bounded noise, probabilistic for sub-Gaussian noise.","key_machinery":"The central object is the quadratic control barrier function $b(x)=1-x^\\top\\Omega^{-1}x$ paired with the linear feedback gain $u(x)=Y\\Omega^{-1}x$, where $\\Omega\\succ 0$ and $Y$ are the decision variables. The key identity is that the robust invariance condition $b(Ax+Bu(x)+Dw) \\ge (1-\\beta)b(x)$ for all $w^\\top w \\le 1$ can be rewritten as a linear matrix inequality in $(\\Omega,Y)$ via the S-lemma, yielding constraint (8c). For the stochastic case, the expected-increase condition in (10) is encoded by the covariance LMI (14d) together with (14e)-(14f), and a shifted and scaled supermartingale $\\zeta_t$ (constructed in Lemma 3.5) converts the one-step drift bound into a joint-in-time exit probability bound using Ville's inequality.","core_discovery":"The central claim is that the co-design of a CBF and a controller, which is generally nonconvex because the CBF appears inside the composition $b(Ax+Bu(x)+Dw)$, becomes convex when the CBF is quadratic and the controller is linear, after a change of variables that lifts the matrix inequalities. Specifically, Problem (8) is a convex SDP whose feasibility implies existence of a quadratic CBF and a linear feedback that render $B$ invariant for all disturbances $w^\\top w \\le 1$, with $I\\subseteq B\\subseteq S$ and $B$ being the largest-volume ellipsoid in this family achieving those properties. For the stochastic case, Problem (14) uses the same parametrization and adds a covariance LMI to enforce the expected-increase condition $\\mathbb{E}[b(x_{t+1})\\mid F_t] \\ge (1-\\beta)b(x_t)+\\delta$; the paper proves that if it is feasible, then $\\Pr(x_t\\in S \\text{ for all } t\\in\\{0,\\ldots,T\\}) \\ge 1-\\alpha$, with $\\alpha$ given by an explicit formula depending on the horizon $T$, the initial ellipsoid parameter $\\sigma$, and the chosen $\\beta,\\delta$. This gives a parameter-free derivation chain from the SDP to a rigorous safety certificate rather than a heuristic one.","pith_inferences":["Because the parametrization is identical to the usual quadratic Lyapunov/controller pair, the same SDP could be recycled for performance objectives such as H2 or H-infinity control by adding LMIs, giving a combined safety-and-performance design.","The martingale bound is a discrete-time analogue of continuous-time supermartingale exit estimates; one could adapt it to time-varying $\\beta_t$ or position-dependent noise, at the cost of a more complex LMI.","The explicit threshold $\\alpha$ in Theorem 3.7 suggests a natural experiment: compare the predicted exit probability against Monte-Carlo counts in high-dimensional systems; the gap between bound and empirical frequency measures the conservatism of the quadratic CBF, not just the martingale step.","For partially observed systems, one could combine the construction with a state estimator and use the same CBF on the estimated state; the paper does not treat output feedback, and the covariance LMI would need a correction term for estimation error."],"forward_implications":["The SDP replaces the standard alternating SOS co-design; no feasible initial CBF guess is required and the problem is convex, so a global solution is certified.","The largest-volume invariant ellipsoid property (Theorem 3.3) gives a direct way to optimize the size of the safety set in one shot, without solving a reachability problem.","For the stochastic case, the method returns an explicit joint-in-time exit probability bound that scales with the horizon $T$ and risk tolerance $\\alpha$, letting designers trade off horizon versus safety in closed form.","Input constraints, both polytopic and norm-bounded, can be added as extra LMIs without destroying convexity, and the same certificate can be used to build a safety filter solved in real time.","Distributionally robust safety certificates can be obtained by replacing the covariance LMI with a Gelbrich-distance ambiguity set (Proposition 4.3), making the bound robust to misspecified covariances within a given radius."],"supporting_citations":[{"why":"Supplies Ville's inequality, the martingale tail bound used to convert the supermartingale $\\zeta_t$ into the exit-probability guarantee of Proposition 3.6.","marker":"[30]"},{"why":"Provides the Positivstellensatz/S-lemma result used to turn the robust invariance and set-containment conditions into the LMIs of Problems (8) and (14).","marker":"[18]"},{"why":"Introduces the quadratic CBF parametrization and the convexifying change of variables that this paper builds on for the co-design problem.","marker":"[34]"},{"why":"Supplies the constructive form of the supermartingale coefficients $g_i,h_i$ used in Example 1 to obtain the explicit bounds.","marker":"[5]"},{"why":"Gives the strong duality result for mean-covariance robust risk used in Proposition 4.3 to reformulate the Gelbrich-ambiguity constraint as a semidefinite program.","marker":"[17]"},{"why":"Provides the earlier martingale method that inspires the supermartingale construction in Example 1.","marker":"[11]"},{"why":"Used in the remarks after Proposition 4.3 to connect the Gelbrich distance to a Frobenius-norm covariance perturbation model.","marker":"[14]"}],"fun_headline_variants":["One SDP co-designs safety barrier and linear feedback","Convex program yields safety certificate for uncertain systems","SDP guarantees safe control for bounded or probabilistic noise","Single semidefinite program co-designs CBF and controller","Safety certificate and controller from one convex optimization"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The certificates rest on the disturbance being i.i.d., zero-mean, sub-Gaussian with exactly the covariance $\\Sigma$ used in the SDP, and on the initial state lying in a known ellipsoid; if the true noise violates these assumptions, the stated safety bounds are not certified.","fun_headline_variants_meta":{"raw":{"variants":["One SDP co-designs safety barrier and linear feedback","Convex program yields safety certificate for uncertain systems","SDP guarantees safe control for bounded or probabilistic noise","Single semidefinite program co-designs CBF and controller","Safety certificate and controller from one convex optimization"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000509,"raw_usage":{"total_tokens":2482,"prompt_tokens":949,"completion_tokens":1533,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":565,"completion_tokens_details":{"reasoning_tokens":1457}},"tokens_in":565,"tokens_out":1533,"duration_ms":12409,"temperature":1.0,"reasoning_tokens":1457,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-15T21:52:38.528625+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Run a scalar system $x_{t+1}=0.5x_t+u_t+w_t$ with a chosen safe set and initial ellipsoid, solve SDP (14), and draw $w_t$ from a zero-mean heavy-tailed distribution (e.g., a t-distribution with three degrees of freedom) scaled to have the same covariance $\\Sigma$ as assumed. If the measured exit probability over $T=100$ steps exceeds the $\\alpha$ predicted by Theorem 3.7 for a feasible SDP, the sub-Gaussian assumption is violated and the certificate fails. For the bounded-support case, set $w_t=1$ deterministically at every step starting from a boundary point of $B$; if the state exits $B$ in one step despite SDP (8) being feasible, the invariance certificate is refuted.","supporting_citations":[{"cited_title":"Etude critique de la notion de collectif","cited_arxiv_id":null,"evidence_quote":"Supplies Ville's inequality, the martingale tail bound used to convert the supermartingale $\\zeta_t$ into the exit-probability guarantee of Proposition 3.6."},{"cited_title":"Semideﬁnite programming relaxations for semialgebraic problems","cited_arxiv_id":null,"evidence_quote":"Provides the Positivstellensatz/S-lemma result used to turn the robust invariance and set-containment conditions into the LMIs of Problems (8) and (14)."},{"cited_title":"Convex Co-Design of Control Barrier Function and Safe Feedback Controller Under Input Constraints","cited_arxiv_id":"2403.11763","evidence_quote":"Introduces the quadratic CBF parametrization and the convexifying change of variables that this paper builds on for the co-design problem."},{"cited_title":"Stochastic stability and contr ol","cited_arxiv_id":null,"evidence_quote":"Provides the earlier martingale method that inspires the supermartingale construction in Example 1."},{"cited_title":"Procrustes metrics on covariance operators and optimal transportation of gaussian processes","cited_arxiv_id":null,"evidence_quote":"Used in the remarks after Proposition 4.3 to connect the Gelbrich distance to a Frobenius-norm covariance perturbation model."}],"review_version":1}