REVIEW 2 major objections 5 minor 35 references
Characterizing Safety: Minimal Barrier Functions from Scalar Comparison Systems
T0 review · 2 major / 5 minor · reviewed 2026-08-14 · deepseek-v4-flash
Pith's one-line read This paper claims that positive invariance of a set {x: h(x) ≥ 0} is, under mild regularity assumptions, equivalent to the existence of a minimal function μ satisfying L_f h(x) ≥ −μ(h(x)) for all x in the domain.
desk verdict The paper's central theorem as printed is false because it omits the positive-invariance hypothesis, but the intended result is correct and the rest of the contribution is solid enough to warrant a serious referee. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The central mechanism is the minimal function μ together with the scalar comparison principle (Proposition 1). A continuous μ is minimal when the minimal solution of the initial value problem \dot w = −μ(w), w(0) = 0 stays nonnegative for all time. That same scalar system acts as a worst-case lower bound: if η(t) satisfies \dot η ≥ −μ(η) and η(0) ≥ 0, then η(t) stays above the minimal solution, so the inequality L_f h(x) ≥ −μ(h(x)) over the whole domain forces h(x(t)) to remain nonnegative. Theorem 2 turns 'minimal' into four explicit local conditions on μ near zero, and Theorem 3 uses the infimum of L_f h over level sets of h to construct a locally Lipschitz μ under regularity assumptions.
What would settle it
The cleanest check is to test the necessity direction: construct a smooth h and locally Lipschitz f such that S is positively invariant, 0 is a regular value, and every strip {x : −δ ≤ h(x) ≤ δ} is compact, then attempt to build μ from the infimum of L_f h over each level set; Theorem 3 asserts this always yields a locally Lipschitz minimal function, so any example where no such μ exists, or where the minimal solution of \dot w = −μ(w) becomes negative, would falsify the claim.
Extended reading notes
Core claim
On the paper's own terms: positive invariance of S = {x : h(x) ≥ 0} is characterized by the existence of a minimal function μ with L_f h(x) ≥ −μ(h(x)) for all x ∈ D. The comparison system \dot w = −μ(w), w(0) = 0 serves as a worst-case model for the evolution of h along trajectories; if its minimal solution never goes negative, no trajectory of the original system can push h below zero. This condition is sufficient without any boundary regularity of h, and under assumptions of compact level-set strips and 0 as a regular value it is necessary as well, so a locally Lipschitz μ always exists when the set is invariant. The four cases of Theorem 2 give the exact class of admissible μ and include non-Lipschitz examples, showing that the barrier-function framework extends beyond extended class K functions and beyond comparison systems with unique solutions.
Load-bearing premise
The load-bearing premise is that the differential inequality L_f h(x) ≥ −μ(h(x)) holds for every x in the whole domain D, including the region where h(x) < 0; if it only holds on the safe set S, a trajectory that starts at the boundary can slip out without being caught by the comparison argument.
Editorial extensions
If this is right
- Any set defined by a smooth h is certifiably invariant as soon as a minimal function μ is found, with no requirement that the gradient of h be nonzero on the boundary; this covers safe sets that are points, limit cycles, subspaces, or sets with corners.
- Theorem 2 gives a finite checklist for whether a continuous μ is minimal: μ(0) < 0, or μ(0) = 0 with a left neighborhood where μ ≤ 0, or μ changes sign arbitrarily near 0, or μ ≥ 0 on a left interval with a divergent integral of −1/μ.
- Under mild regularity assumptions (h twice differentiable, 0 a regular value, and compact level-set strips), positive invariance and the existence of a minimal barrier function are equivalent, so no information is lost by using this condition.
- For control-affine systems, if the set of viable controls K(x) is nonempty and strictly feasible at every state, there exists a continuous controller satisfying the safety constraint, and a quadratic program selecting the closest controller to a nominal one yields a continuous feedback law.
Reading between the lines
- Nothing in the proof of Theorem 1 uses uniqueness of the original system's solutions, so the same comparison argument should certify invariance for differential inclusions and hybrid systems, a direction the paper only sketches.
- Because the four cases of Theorem 2 are stated purely in terms of the local behavior of μ near 0, the minimal-function condition could be checked numerically by sampling μ on small left neighborhoods, suggesting a computational safety-verification procedure.
- The global-domain requirement means that when a barrier h is naturally defined only on S, the certificate depends on how h is extended to the rest of the domain; the paper's Example 4 shows that a careless extension can produce a false safety certificate.
- The appendix's stability result implies a single scalar comparison function can serve as both a safety certificate and a Lyapunov-like stability certificate, so minimal barrier functions may unify safety and stability analysis for the same set.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper introduces "minimal barrier functions" (MBFs) for certifying positive invariance of sets S = {x : h(x) >= 0} for continuous, not necessarily Lipschitz, dynamics. The core idea is to impose a differential inequality Lf h(x) >= -mu(h(x)) for all x in the domain D, where mu is a "minimal function" in the sense that the minimal solution of w_dot = -mu(w), w(0) = 0 stays nonnegative. Theorem 1 establishes sufficiency of this condition. Theorem 2 gives four verifiable necessary-and-sufficient conditions for a continuous function mu to be minimal. Theorem 3 claims that, under regularity conditions (twice differentiability of h, compactness of level sets, 0 a regular value of h, and f locally Lipschitz), a locally Lipschitz minimal function always exists; Corollary 2 then concludes that positive invariance is equivalent to h being a minimal barrier function. The paper also extends the framework to control-affine systems with state-dependent input constraints, gives conditions for existence of continuous controllers, and includes appendices on time-varying systems, Lyapunov stability, and connections to Nagumo-type boundary conditions.
Significance. If the central characterization is corrected, the paper makes a valuable contribution: it enlarges the class of comparison functions beyond extended class K and locally Lipschitz functions while retaining a simple sufficient condition, and it provides explicit, checkable conditions for the comparison function (Theorem 2). The paper correctly emphasizes that the differential inequality must hold on the whole domain D, not only on S, and Example 4 shows that violating this leads to false invariance certificates. The extension to control barrier functions with state-dependent input constraints is also useful. However, the main necessary-and-sufficient claim currently rests on Theorem 3, whose printed statement is false; the intended fix is clear and local, so the contribution is salvageable with a major revision.
major comments (2)
- [Section III, Theorem 3, and Appendix D, Proposition 6] The statement of Theorem 3 is false as printed because it omits the positive-invariance assumption that the proof explicitly uses. The proof concludes "Since S is assumed to be invariant..." but positive invariance of S is not among the hypotheses. A one-dimensional counterexample satisfies every stated hypothesis: take D = R, h(x) = x, f(x) = -1. Then h is twice differentiable, Lambda_delta = [-delta, delta] is compact, 0 is a regular value of h, and f is locally Lipschitz. But Lf h(0) = -1, so the claimed inequality Lf h(x) >= -mu_L(h(x)) at x = 0 requires -1 >= -mu_L(0), i.e., mu_L(0) >= 1, contradicting the claimed mu_L(0) <= 0. Thus no admissible mu_L exists. The same omission occurs in Proposition 6 of Appendix D, whose proof also invokes "Since S is assumed to be invariant" without this being a hypothesis. Because Corollary 2's necessity direction relies on Theorem 3, the theorem statement must be corrected by adding "if S is positively invariant" to the hypotheses, exactly as the proof and Corollary 2 use it, and Proposition 6 should be corrected in the same way.
- [Section III, proof of Theorem 3] The proof contains a sign inconsistency in the construction of mu_L. The text states that "mu_L restricted to U' is equal to Gamma", but the barrier inequality Lf h(x) >= Gamma(h(x)) >= -mu_L(h(x)) and the subsequent conclusion mu_L(0) = -Gamma(0) are compatible only if mu_L equals -Gamma on U'. Please correct the sign so that the construction matches the intended inequality and the concluding line.
minor comments (5)
- [Section II, Lemma 1] The comparison of reciprocals in the proof is not fully justified: the inequality 1/mu(h(x)) <= -1/Gamma(h(x)) a.e. requires that -Gamma(h(x)) > 0 a.e. on the relevant interval, but the proof only establishes mu >= -Gamma and asserts Gamma != 0 a.e. Please justify this step or restate the argument.
- [Section II, Theorem 2, Case 4] The condition "mu(w) >= 0 on [-epsilon, 0]" should be stated as "mu(w) > 0 a.e. on [-epsilon, 0]" so that the reciprocal -1/mu(w) is defined almost everywhere and the nonintegrability condition is meaningful.
- [Section II, proof of Proposition 1, Eq. (10)] In the limit equation after Cauchy convergence, the integrand should be g(r(s)) rather than g(r_n(s)); the subscript n is a leftover from the approximation sequence.
- [Section III, proof of Theorem 3] In the Lipschitz estimate, the notation "Lf(x1)" should be "Lf h(x1)" to match the Lie derivative notation used throughout the paper.
- [Section IV, Example 6] The sentence "Notice all of the assumptions for Proposition 5 are satisfied" should refer to Theorem 5, which is the result on continuity of the quadratic-program controller, rather than to Proposition 5.
Circularity Check
No load-bearing circularity; comparison argument is self-contained, but Theorem 3 has a missing-invariance correctness flaw.
full rationale
Walking the derivation chain: Theorem 1's sufficiency is a direct application of the external comparison principle (Proposition 1, attributed to [17] with a proof included in the paper), not an assumption of invariance; it assumes the MBF differential inequality (12) over all of D and compares h(x(t)) with the minimal solution of w˙ = −μ(w) with w(0)=0. Theorem 2's characterization of minimal functions is proved from uniqueness/nonuniqueness criteria [18], not from the MBF theorem. Lemma 1 and the construction in Theorem 3 derive comparison functions from Γ(w)=inf_{x:h(x)=w} L_f h(x); the proofs use Lyusternik's theorem, compactness, and semicontinuity arguments, not the target invariance conclusion. The one genuinely load-bearing defect is in Theorem 3: its proof uses the sentence 'Since S is assumed to be invariant, Lf h(x) ≥ 0 for all x∈h−1(0), so μL(0)=−Γ(0)≤0,' but positive invariance is not stated as a hypothesis of Theorem 3, and the skeptic's one-dimensional example shows the printed statement is false as stated. That is a missing-hypothesis/correctness flaw in the necessity argument for Corollary 2, not a circular reduction: the theorem's conclusion is not identical to an input assumption, and the missing hypothesis is recoverable from the proof. The paper's self-citations ([3], [22], which overlap with the authors) are used for context, motivation, and comparison with zeroing barrier functions, not as the engine of Theorems 1–2; no fitted parameter is renamed as a prediction. Therefore no specific circular step is identified; the score of 2 reflects only minor non-load-bearing self-citation, not a circular derivation.
Assumptions & free parameters
assumptions (8)
- standard math Continuous f on an open domain D guarantees local existence, but not uniqueness, of solutions to xdot=f(x).
- standard math For continuous scalar g, the initial value problem wdot=g(w), w(0)=w0 has a unique minimal solution on its maximal interval.
- standard math Comparison lemma [17, Thm 6.3]: if eta dot >= g(eta) and eta(0) >= w0, then eta is bounded below by the minimal solution of the comparison system.
- standard math Scalar ODE uniqueness and non-uniqueness criteria from Agarwal and Lakshmikantham [18], including integrability of -1/mu in deciding whether solutions reach zero.
- standard math Lyusternik's theorem: for h in C^2 with nonzero gradient on h^{-1}(0), distance to the level set h^{-1}(w) is bounded by a constant times |h(x')-w| locally.
- domain assumption h is twice continuously differentiable, the sublevel sets Lambda_delta are compact for all delta >= 0, and 0 is a regular value of h.
- standard math Michael's selection theorem: a lower semicontinuous set-valued map with nonempty closed convex values admits a continuous selection.
- domain assumption Input constraint sets U(x) are described by continuous strictly quasiconvex inequalities e_i(x,u) <= 0.
Cite this review
Pith. "Pith review of Characterizing Safety: Minimal Barrier Functions from Scalar Comparison Systems." pith.science (2026). https://pith.science/paper/3LQKXLE7
@misc{pith2026190809323,
author = {Pith},
title = {Pith review of: Characterizing Safety: Minimal Barrier Functions from Scalar Comparison Systems},
year = {2026},
howpublished = {\url{https://pith.science/paper/3LQKXLE7}},
note = {Machine review of arXiv:1908.09323}
}
read the original abstract
Verifying set invariance has classical solutions stemming from the seminal work by Nagumo, and defining sets via a smooth barrier function constraint inequality results in computable flow conditions for guaranteeing set invariance. While a majority of these historic results on set invariance consider flow conditions on the boundary, recent results on control barrier functions extended these conditions to the entire set, although they required regularity conditions on the barrier function. This paper fully characterizes set invariance through \emph{minimal barrier functions} by directly appealing to a comparison result to define a flow condition over the entire domain of the system. A considerable benefit of this approach is the removal of regularity assumptions of the barrier function. This paper also outlines necessary and sufficient conditions for a valid differential inequality condition, giving the minimum conditions for this type of approach. We also show when minimal barrier functions are necessary and sufficient for set invariance.
Reference graph
Works this paper leans on
-
[1]
Blanchini and S
F. Blanchini and S. Miani, Set-theoretic methods in control . Springer, 2008
2008
-
[2]
Control barrie r function based quadratic programs with application to adaptive crui se control,
A. D. Ames, J. W. Grizzle, and P . Tabuada, “Control barrie r function based quadratic programs with application to adaptive crui se control,” in 53rd IEEE Conference on Decision and Control , pp. 6271–6278, IEEE, 2014
work page 2014
-
[3]
Control b arrier function based quadratic programs for safety critical syst ems,
A. D. Ames, X. Xu, J. W. Grizzle, and P . Tabuada, “Control b arrier function based quadratic programs for safety critical syst ems,” IEEE Transactions on Automatic Control , vol. 62, no. 8, pp. 3861–3876, 2017
2017
-
[4]
¨Uber die lage der integralkurven gew¨ ohnlicher differ- entialgleichungen,
M. Nagumo, “ ¨Uber die lage der integralkurven gew¨ ohnlicher differ- entialgleichungen,” Proceedings of the Physico-Mathematical Society of Japan. 3rd Series , vol. 24, pp. 551–559, 1942
work page 1942
-
[5]
J.-M. Bony, “Principe du maximum, in´ egalit´ e de harnac k et unicit´ e du probleme de cauchy pour les op´ erateurs elliptiques d´ eg ´ en´ er´ es,” in Annales de l’institut F ourier , vol. 19, pp. 277–304, 1969
work page 1969
-
[6]
On a characterization of flow-invariant sets ,
H. Brezis, “On a characterization of flow-invariant sets ,” Communica- tions on Pure and Applied Mathematics , vol. 23, no. 2, pp. 261–263, 1970
work page 1970
-
[7]
G. Ladde, V . Lakshmikantham, et al., “On flow-invariant sets.,” Pacific Journal of Mathematics , vol. 51, no. 1, pp. 215–220, 1974
work page 1974
-
[8]
The theorems of bony and brezis on flow-inv ariant sets,
R. Redheffer, “The theorems of bony and brezis on flow-inv ariant sets,” The American Mathematical Monthly , vol. 79, no. 7, pp. 740– 747, 1972
work page 1972
Show all 35 references
-
[9]
Safety verification of hybri d systems us- ing barrier certificates,
S. Prajna and A. Jadbabaie, “Safety verification of hybri d systems us- ing barrier certificates,” in International W orkshop on Hybrid Systems: Computation and Control , pp. 477–492, Springer, 2004
2004
-
[10]
A framework f or worst- case and stochastic safety verification using barrier certi ficates,
S. Prajna, A. Jadbabaie, and G. J. Pappas, “A framework f or worst- case and stochastic safety verification using barrier certi ficates,” IEEE Transactions on Automatic Control , vol. 52, no. 8, pp. 1415–1428, 2007
2007
-
[11]
Converse barrier certifica te theorems,
R. Wisniewski and C. Sloth, “Converse barrier certifica te theorems,” IEEE Transactions on Automatic Control , vol. 61, no. 5, pp. 1356– 1361, 2015
2015
-
[12]
Aubin, Viability theory
J.-P . Aubin, Viability theory . Springer Science & Business Media, 2009
2009
-
[13]
Exponentia l- condition-based barrier certificate generation for safety verification of hybrid systems,
H. Kong, F. He, X. Song, W. N. Hung, and M. Gu, “Exponentia l- condition-based barrier certificate generation for safety verification of hybrid systems,” in International Conference on Computer Aided V erification, pp. 242–257, Springer, 2013
2013
-
[14]
Ordinary differential equations,
P . Hartman, “Ordinary differential equations,” 1964
1964
-
[15]
Pachpatte, Inequalities for differential and integral equations , vol
B. Pachpatte, Inequalities for differential and integral equations , vol. 197. Elsevier, 1997
1997
-
[16]
Lakshmikantham and S
V . Lakshmikantham and S. Leela, Differential and Integral Inequali- ties: Theory and Applications: V olume I: Ordinary Differen tial Equa- tions. Academic press, 1969
1969
-
[17]
D. D. Bainov and P . S. Simeonov, Integral inequalities and applica- tions, vol. 57. Springer Science & Business Media, 2013
2013
-
[18]
R. P . Agarwal and V . Lakshmikantham, Uniqueness and nonunique- ness criteria for ordinary differential equations , vol. 6. World Scientific Publishing Company, 1993
1993
-
[19]
Characterizations of safety in hybrid inclusions via barrier functions,
M. Maghenem and R. G. Sanfelice, “Characterizations of safety in hybrid inclusions via barrier functions,” in Proceedings of the 22nd ACM International Conference on Hybrid Systems: Computati on and Control, pp. 109–118, ACM, 2019
2019
-
[20]
Sufficient conditions for forward invariance and contractivity in hybrid inclusions using ba rrier func- tions,
M. Maghenem and R. G. Sanfelice, “Sufficient conditions for forward invariance and contractivity in hybrid inclusions using ba rrier func- tions,” arXiv preprint arXiv:1908.03980 , 2019
1908 arXiv
-
[21]
Flow-invariant sets and differential inequalities in normed spaces,
R. M. Redheffer and W. Walter, “Flow-invariant sets and differential inequalities in normed spaces,” Applicable Analysis , vol. 5, no. 2, pp. 149–161, 1975
1975
-
[22]
Control barrier functions: Theory and appl ications,
A. D. Ames, S. Coogan, M. Egerstedt, G. Notomista, K. Sre enath, and P . Tabuada, “Control barrier functions: Theory and appl ications,” arXiv preprint arXiv:1903.11199 , 2019
1903 arXiv
-
[23]
Berge, Topological Spaces: including a treatment of multi-valued functions, vector spaces, and convexity
C. Berge, Topological Spaces: including a treatment of multi-valued functions, vector spaces, and convexity . Courier Corporation, 1997
1997
-
[24]
Ly usternik’s theorem and the theory of extrema,
A. V . Dmitruk, A. A. Milyutin, and N. P . Osmolovskii, “Ly usternik’s theorem and the theory of extrema,” Russian Mathematical Surveys , vol. 35, no. 6, p. 11, 1980
1980
-
[25]
Aubin and I
J.-P . Aubin and I. Ekeland, Applied nonlinear analysis . Courier Corporation, 2006
2006
-
[26]
Stability in nonlinear prog ramming,
J. P . Evans and F. J. Gould, “Stability in nonlinear prog ramming,” Operations Research, vol. 18, no. 1, pp. 107–118, 1970
1970
-
[27]
Continuous selections. i,
E. Michael, “Continuous selections. i,” Annals of mathematics , pp. 361–382, 1956
1956
-
[28]
Point-to-set maps in mathematical progra mming,
W. W. Hogan, “Point-to-set maps in mathematical progra mming,” SIAM review, vol. 15, no. 3, pp. 591–603, 1973
1973
-
[29]
Aubin and A
J.-P . Aubin and A. Cellina, Differential inclusions: set-valued maps and viability theory , vol. 264. Springer Science & Business Media, 2012
2012
-
[31]
Continuity an d smooth- ness properties of nonlinear optimization-based feedback controllers,
B. J. Morris, M. J. Powell, and A. D. Ames, “Continuity an d smooth- ness properties of nonlinear optimization-based feedback controllers,” in 2015 54th IEEE Conference on Decision and Control (CDC) , pp. 151–158, IEEE, 2015
2015
-
[32]
Control barrier fu nctions for signal temporal logic tasks,
L. Lindemann and D. V . Dimarogonas, “Control barrier fu nctions for signal temporal logic tasks,” IEEE control systems letters, vol. 3, no. 1, pp. 96–101, 2019
2019
-
[33]
N. P . Bhatia and G. P . Szeg¨ o, Dynamical systems: stability theory and applications, vol. 35. Springer, 2006
2006
-
[34]
Robustn ess of con- trol barrier functions for safety critical control,
X. Xu, P . Tabuada, J. W. Grizzle, and A. D. Ames, “Robustn ess of con- trol barrier functions for safety critical control,” IF AC-PapersOnLine, vol. 48, no. 27, pp. 54–61, 2015
2015
-
[35]
Extensions of the Evans-Gould stability theorems for mathematical programs,
H. J. Greenberg and W. P . Pierskalla, “Extensions of the Evans-Gould stability theorems for mathematical programs,” Operations Research, vol. 20, no. 1, pp. 143–153, 1972. APPENDIX A EXTENDING TO TIME -VARYING BARRIER FUNCTIONS In this appendix, we extend the above results to...
1972
-
[36]
Therefore, minimal barrier functions can be regarded as a direct extension of Lyapunov functions. APPENDIX C COMPARISON BETWEEN BOUNDARY CONDITIONS In this appendix, we recall a few versions of results from Nagumo’s theorem and we then compare minimal barrier functions with th...
Reviewed August 14, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.