{"id":"24c93e25-b6c8-40ed-bb2f-31674a0d90d7","arxiv_id":"2607.15961","paper_version":1,"verdict":"REJECT","confidence":"MODERATE","novelty_score":4.0,"correctness_risk":"high","formal_verification":"none","parameter_count":3,"one_line_summary":"DCR-CBF reconstructs HOCBF safety constraints online from ESO disturbance estimates plus a safety margin, and reports zero violations in a 4-DOF excavator simulation.","lead":"This paper proposes a control-barrier-function safety method that uses an online disturbance estimate to update safety constraints for a robot arm, tested in simulation on a 4-DOF excavator model. It reports no safety violations and better tracking than standard and worst-case-robust CBF methods, but its safety proof assumes the arm stays safe during the observer's start-up transient.","discovery_kind":"extension","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Forward-invariance proof is circular: Assumption 2 assumes transient safety, so Theorem 1 does not prove x(t)∈C for all t≥0.","rationale":"I agree with the reader's weakest assumption. The proof's reliance on Assumption 2 is a genuine circularity: the theorem claims x(t)∈C for all t, but the proof takes safety during the transient as an assumption. This is the most load-bearing concern because the abstract and conclusion explicitly promise 'zero safety violation' and 'forward invariance' under disturbances. Even if the steady-state part were correct, the theorem fails to provide a complete guarantee. The margin condition (25) is also not verified in simulation—c_h and \\bar{e} are never computed—but that is secondary because even with exact numbers the transient issue remains. My proposed check would test the assumption in the paper's own scenario; the absence of such a test in the paper leaves the central claim unsubstantiated.","tokens_in":10199,"tokens_out":4430,"duration_ms":46777,"concrete_test":"Run the Section V simulation with the same parameters but initialize the ESO with \\hat{d}(0)=0 while the true disturbance is at its maximum d(0)=d_max, and start q(0) on the boundary of C_ε (e.g., q_i(0)=q_max,i-ε_i). If the trajectory leaves C during the first 0.5 s, then Assumption 2 is not automatically satisfied and the theorem's all-time guarantee is false; if it stays safe, the assumption is still unproven but the practical risk is lower.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The proof of Theorem 1 (Appendix A) splits the time axis into an initial ESO transient and a later bounded-error regime. For the transient it invokes Assumption 2, which explicitly requires that the disturbance and estimation error 'do not destabilize the closed-loop system or cause violations of the state constraints.' This is precisely the forward-invariance property the theorem is supposed to establish. Consequently, the theorem only shows safety after the transient, conditional on safety before it. No bound on the transient is derived from the observer error dynamics (12), and the safety margin condition (25) is derived only for the steady-state error bound \\bar{e}. Thus the central claim 'x(t)∈C for all t≥0' (and the abstract's 'zero safety violation' guarantee) is not supported by the proof. The single deterministic simulation starts from a favorable initial condition and does not test the transient assumption.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper proposes a dynamic constraint reconstruction based control barrier function (DCR-CBF) framework for high-dimensional robotic manipulators under unknown disturbances. An extended state observer (ESO) estimates the lumped disturbance, and the estimate is substituted into high-order CBF (HOCBF) constraints, replacing the fixed nominal constraints with adaptively reconstructed ones. A safety margin ε is introduced to compensate for estimation error, and a sufficient condition (25) is claimed to guarantee forward invariance of the safe set. Simulations on a 4-DOF excavation manipulator compare the method with standard CBF and robust CBF, reporting zero safety violations and improved tracking performance.","tokens_in":10466,"tokens_out":3080,"duration_ms":38374,"significance":"The core idea—reconstructing HOCBF constraints online using disturbance estimates instead of using fixed nominal or conservative robust constraints—is timely and practically motivated. The algebraic derivation of the reconstructed constraints (19)–(20) is straightforward and correct, and the steady-state part of the forward-invariance reasoning in Appendix A (bounding the perturbation M^{-1}(q)e_d once ∥e_d∥≤\\bar{e}) is sound. If a rigorous transient analysis were supplied, the framework could be a useful alternative to robust CBFs for manipulator safety control. However, as presented, the theoretical guarantee relies on an assumption that already contains the desired safety property, and the simulation evidence is limited to a single deterministic scenario; the central claims are therefore not yet substantiated.","major_comments":[{"comment":"","section":"Assumption 2 / Theorem 1 / Appendix A"},{"comment":"The sufficient condition (25) involves c_h and \\bar{e}, but neither is computed. In the simulation, ε=[0.1,0.1,0.1,0.2]^T is simply asserted to satisfy (25), with no evaluation of c_h (which depends on M^{-1} over the operating set) or of \\bar{e} (which depends on the ESO gain and disturbance derivative bound). Consequently, the simulation does not validate the theoretical margin condition; it only demonstrates that a heuristically chosen ε happens to work for one scenario. The authors should provide explicit bounds or numerical values for c_h and \\bar{e}, and verify (25) pointwise or at least over the simulated operating region.","section":"Equation (25) and Section V.A"},{"comment":"The claimed 'zero safety violation' result is based on a single deterministic simulation with one initial condition and one cosine disturbance profile. There is no uncertainty analysis, no variation of d_max or ω, no perturbed initial conditions, and no Monte Carlo trials. Therefore the statement 'achieves zero safety violation under strong unknown disturbances' is supported only for that particular trajectory, not as a general property. A formal proof is needed for the general claim; otherwise the experimental section should be framed as an illustrative case study, and the 'zero violation' wording should be softened accordingly.","section":"Section V (Experimental Validation) and Table I"},{"comment":"","section":"Section III.B, Eq. (12)"},{"comment":"Line 9 says 'Reconstruct system dynamics using (18) [14]' — the citation marker [14] appears where an equation reference is expected. More importantly, the algorithm simply implements the reconstruction without addressing the transient issue identified in the first major comment; the theoretical guarantee stated in Theorem 1 is not actually established by Algorithm 1 as written.","section":"Algorithm 1, line 9"}],"minor_comments":[{"comment":"The paper calls the simulations 'experimental validation' and later 'experiments'; these are numerical simulations only. The wording should be adjusted for accuracy.","section":"Abstract and Section V"},{"comment":"The displayed 12×4 observer gain has its first eight rows all zero. This is not inherently wrong, but the observability concern in the major comments is reinforced; please clarify the design and whether the zero rows are intentional.","section":"Section V.A, L_k display"},{"comment":"Some references are duplicated (e.g., [6] and [14] are the same 'Disturbance observer-based robust control barrier functions'), and the citation numbering in the text should be checked. Also, line 9 of Algorithm 1 contains a stray '[14]'.","section":"Throughout"},{"comment":"The notation Ψ(x,u;f_0) is introduced but never precisely defined. Since the paper does not use it in the derivations, it could be simplified or defined rigorously to avoid confusion.","section":"Section II.B"}],"recommendation":"major_revision","confidential_remarks":"The central theoretical guarantee currently rests on an assumption that is logically equivalent to the desired invariant property. I would be reluctant to accept the manuscript without a genuinely new transient analysis or a revised theorem that explicitly acknowledges the conditional nature of the result. If the authors can provide such an analysis, the paper could be salvageable; otherwise, the contribution reduces to a heuristic algorithm with a post-transient guarantee. The single-deterministic-simulation evidence also needs strengthening before publication."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"The paper combines ESO disturbance estimates with HOCBFs to adapt safety constraints online. The core reconstruction equation (19) is not new—the authors cite [12] for it—and the new contribution is the safety-margin condition (25) plus Theorem 1. The simulation on a 4-DOF excavator shows DCR-CBF beating both standard and robust CBF on tracking error while keeping zero violations. The engineering motivation is real: fixed nominal constraints can become inconsistent under strong disturbances, and adapting the constraint to the estimated disturbance is a natural way to reduce conservatism.\n\nThe paper is honestly written. It clearly distinguishes inherited ideas from new ones, and the error analysis in Appendix A is correct as far as it goes: the mismatch between reconstructed and actual HOCBF conditions is the additive term -M^{-1} e_d, and the constant c_h is well-defined under Assumption 1. The safety-margin idea is clean and plausible.\n\nThe problem is that Theorem 1 does not prove what the abstract claims. Assumption 2 explicitly requires that the system remains safe and bounded during the ESO transient—exactly the forward-invariance property the theorem is meant to establish. The proof splits time at the transient and then invokes the assumption to cover the first interval. So the result is conditional: if the system is safe during the transient, it is safe afterward. No transient bound is derived from the observer error dynamics. The safety-margin condition (25) is stated in terms of c_h and e_bar, but neither is computed in the experiments; the margin epsilon is simply asserted to satisfy (25). That leaves the zero-violation claim supported by a single deterministic simulation, not by the theorem.\n\nI agree with the stress-test note: the circularity is load-bearing. The comparison against robust CBF also uses the worst-case bound at every instant, so the RMSE improvement is partly by construction—though the margin is large enough to suggest the method has real appeal.\n\nWho is this for? Researchers working on ESO/CBF integration will find a useful worked example and a clear illustration of the transient-safety trap. The paper is not ready in its current form if the goal is a formal guarantee. With a reframed theorem (safety after an admissible transient, or a proper transient analysis) and hardware or randomized multi-scenario validation, it could become a solid paper.\n\nI would send this to peer review rather than desk reject: the problem is relevant, the flaw is identifiable and potentially repairable, and there is enough working code-adjacent detail to give a referee something to evaluate. But I would expect major revision, and if the venue demands rigorous guarantees, the current version would likely be rejected as-is.","headline":"The DCR-CBF method is sensible and the simulations are encouraging, but Theorem 1's forward-invariance guarantee is circular because Assumption 2 already assumes transient safety.","tokens_in":10882,"tokens_out":2272,"would_cite":false,"duration_ms":26972,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["93C10","93C85","93B53"],"pacs":[],"model":"deepseek-v4-flash","headline":"The paper claims that control-barrier safety filters fail under unknown disturbance because the constraints themselves are built from the wrong dynamics, and that rebuilding them online from an observer's disturbance estimate — with a safet","keywords":["control barrier functions","high-order control barrier functions","extended state observer","disturbance estimation","safety-critical control","robotic manipulators","forward invariance","constraint reconstruction"],"falsifier":"Run the same 4-DOF simulation with the initial joint positions on the contracted boundary ∂C_ε, an initial disturbance-estimation error equal to its bound, and a disturbance spike within the first few sampling periods (before the ESO settles). If the HOCBF expression in (16) turns negative or a joint limit is crossed under controller (21), the forward-invariance claim fails as stated. A cheaper check: measure the ESO error bound ē from the existing simulation and verify whether the chosen ε actually satisfies (25); choosing ε below the required product should produce violations if the conditio","tokens_in":10111,"feed_emoji":"🛡️","tokens_out":11057,"duration_ms":114633,"temperature":0.7,"pith_summary":"What safety does a control barrier function guarantee when the model it trusts is wrong? This paper argues that under unknown disturbances the failure of standard CBF methods is not mainly disturbance magnitude but constraint inconsistency: rules built from nominal dynamics can demand unsafe inputs or over-tighten, because the system's true evolution differs from the model's. The proposed fix, dynamic constraint reconstruction, feeds an extended state observer's online disturbance estimate into the high-order barrier condition so the safety constraint tracks the estimated true dynamics instead of the nominal ones, and adds a joint-wise safety margin sized so the constraint can absorb the remaining estimation error. The paper proves (Theorem 1) that if the margin condition (λ1⊙λ2)⊙ε ≥ c_h·ē·1 holds, the safe set stays forward invariant once the observer has converged, and in simulation on a 4-DOF excavation manipulator the method keeps zero joint-limit violations while cutting the worst-case robust method's average tracking error by roughly 60%. The payoff if true: safety and aggression in constrained robots become a tunable trade instead of a forced choice.","feed_headline":"Zero violations, a third of the error: live-rebuilt safety limits","feed_subtitle":"Rebuilt-from-live-estimates safety constraints keep a 4-DOF arm inside its joint limits with lower tracking error.","key_machinery":"The carrying mechanism is the reconstructed HOCBF constraint. For joint limits, the barrier h = q_max − q has relative degree two; the paper rewrites the standard second-order condition ¨h + (λ1+λ2)⊙˙h + (λ1⊙λ2)⊙h ≥ 0 with the acceleration model replaced by its disturbed version including the ESO estimate d̂, which shifts the constraint by the term −M⁻¹(q)d̂(t) (and symmetrically for the lower bound). The second piece is the safety margin: contracting the admissible interval to [q_min+ε, q_max−ε] injects the extra term (λ1⊙λ2)⊙ε into the constraint. The proof's hinge is the identity that the actual second derivative of the barrier differs from the reconstructed one by exactly M⁻¹(q)e_d(t), b","core_discovery":"On its own terms, the paper claims that the right object to adapt is the constraint itself, not just the control input. It shows that inserting the disturbance estimate d̂(t) into the acceleration that feeds the high-order barrier condition turns the fixed nominal constraint M⁻¹u ≤ η₀⁺ into the adaptive constraint M⁻¹u ≤ η₀⁺ − M⁻¹d̂, and that the true barrier evolution then differs from the reconstructed one by exactly the additive term M⁻¹(q)e_d(t) — the estimation error mapped through the inverse inertia. Because that term is bounded componentwise by c_h·ē, the paper introduces a safety margin ε that contracts the admissible joint interval inward and proves that the margin dominates the er","pith_inferences":["Editorial inference: the same substitution — estimating a matched disturbance and rewriting the barrier's Lie derivative with it — transfers to other relative-degree-two constraints (velocity limits, torque limits, end-effector clearance), so the framework's scope is likely wider than the joint-limit experiments shown.","Editorial inference: condition (25) suggests an adaptive-margin extension the paper does not develop: estimate ē online and scale ε down as the observer converges, recovering performance during normal operation and inflating the margin only when the error bound grows.","Editorial inference: the transient assumption is the part most likely to bind in practice; a natural stress test is to start the trajectory inside the contracted set with an initial observer error at its bound and a disturbance spike in the first few samples — the proof currently delegates that interval to Assumption 2.","Editorial inference: the very large observer gains reported (entries on the order of 10⁷) hint that measurement noise would be amplified on hardware; a practical version would likely schedule or filter the gains, trading a bit of the margin for noise immunity."],"forward_implications":["If Theorem 1 is right, the controller design gets an explicit margin rule: pick ε so that (λ1⊙λ2)⊙ε ≥ c_h·ē·1, and the contracted safe set is invariant after the observer settles — conservatism becomes a dial, not a gamble.","The QP's feasible set becomes adaptive: when the disturbance estimate is small, the constraints loosen and tracking improves; when it grows, the constraints tighten in the same direction the real dynamics push — removing the need to assume the worst-case disturbance magnitude at every instant.","Simulation on the 4-DOF excavation manipulator shows the corollary in numbers: zero safety violations under a strong cosine disturbance, with average tracking RMSE of 0.1398 versus 0.2279 for standard CBF and 0.3741 for the worst-case robust CBF.","Because the disturbance enters through the same channel as the control input, the reconstruction argument covers any matched, state-dependent perturbing force, not just the specific cosine test case.","The guarantee's operating envelope is set by the estimation-error bound rather than by the disturbance bound itself, which is why the approach can be less conservative than worst-case methods while still formal."],"fun_headline_variants":["Adapt safety limits live: zero violations, less error","Disturbance-aware CBFs: rebuilt constraints shrink tracking error","Dynamic constraints for arms: safe and precise under attack","Safety margins from live estimates keep manipulators in line"],"cache_read_input_tokens":2304,"weakest_assumption_plain":"The proof assumes the system stays safe and bounded by itself during the initial observer transient, so the safety margin and reconstruction never have to act in the very interval where the disturbance estimate is still wrong — if a strong disturbance arrives before the observer converges, the guarantee does not cover it.","fun_headline_variants_meta":{"raw":{"variants":["Adapt safety limits live: zero violations, less error","Disturbance-aware CBFs: rebuilt constraints shrink tracking error","Dynamic constraints for arms: safe and precise under attack","Safety margins from live estimates keep manipulators in line"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000166,"raw_usage":{"total_tokens":1079,"prompt_tokens":722,"completion_tokens":357,"prompt_tokens_details":{"cached_tokens":256},"prompt_cache_hit_tokens":256,"prompt_cache_miss_tokens":466,"completion_tokens_details":{"reasoning_tokens":291}},"tokens_in":466,"tokens_out":357,"duration_ms":4958,"temperature":1.0,"reasoning_tokens":291,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-01T21:46:03.905264+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Run the same 4-DOF simulation with the initial joint positions on the contracted boundary ∂C_ε, an initial disturbance-estimation error equal to its bound, and a disturbance spike within the first few sampling periods (before the ESO settles). If the HOCBF expression in (16) turns negative or a joint limit is crossed under controller (21), the forward-invariance claim fails as stated. A cheaper check: measure the ESO error bound ē from the existing simulation and verify whether the chosen ε actually satisfies (25); choosing ε below the required product should produce violations if the conditio","supporting_citations":[],"review_version":1}