REVIEW 3 major objections 4 minor 32 references
Safety-Critical Controller Synthesis with Reduced-Order Models
T0 review · 3 major / 4 minor · reviewed 2026-08-12 · deepseek-v4-flash
Pith's one-line read Provable safety for complex systems via simplified models.
desk verdict Theorem 2 proves invariance of a superset of the intended safe set, so the advertised full-order safety guarantee does not follow as stated. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing objects are the simulation function $V$ and the interface $k$. $V$ is a continuously differentiable, positive function satisfying $V(x) \ge \rho\|\psi(x) - \kappa(\pi(x))\|^2$ and $\nabla V(x)\cdot F(x,k(x)) \le -\lambda V(x) + \iota$; it certifies that the full-order system tracks the reduced-order controller $\kappa$ with an exponentially decaying error bound (Lemma 1). The interface $k$ maps reduced-order inputs back to full-order inputs. The second central object is the combined barrier $B(x) = h(\pi(x)) - \frac{1}{\mu}V(x)$, which merges the reduced-order CBF $h$ with the simulation function. The derivative inequality $\dot{B}_\delta(x) > -\alpha B_\delta(x)$ on $W$, together with Nagumo's theorem, is what yields forward invariance. Condition (18) is the exact inequality that makes the tracking error term small enough to preserve this derivative bound.
What would settle it
For the ARCHER hardware setup, record $\psi(x(t))$ and $\kappa(\pi(x(t)))$ over several runs, compute the Lyapunov values $V(x(t))$ from the zero dynamics policy, and verify whether inequality (9) holds with the parameters claimed; if (9) or (18) fails while the robot still stays safe, then the theorem's conditions are not necessary. To test the theorem itself, simulate a full-order system with a known simulation function, pick parameters satisfying (18), and search for an initial condition in $W$ whose trajectory leaves $W$; any such exit would contradict forward invariance and expose a flaw in the proof.
Extended reading notes
Core claim
The central claim is Theorem 2: if a simulation function $V$ and interface $k$ exist, with parameters satisfying $\lambda \ge \alpha + \varepsilon\mu/(4\rho)$, then the set $W = S_\delta \cap \Omega_\beta$ is forward invariant for the closed-loop full-order system $\dot{x} = F(x, k(x))$. Here $S_\delta$ is the zero superlevel set of $B(x) + \frac{1}{\alpha}(\frac{\sigma}{4}\delta^2 + \frac{\iota}{\mu})$, a slightly inflated version of the candidate safe set $S = \{x : h(\pi(x)) \ge V(x)/\mu\}$, and $\Omega_\beta$ is the largest sublevel set of $V$ inside the domain. Since $B(x) \ge 0$ implies $h(\pi(x)) \ge 0$, forward invariance of $W$ guarantees that the original state constraint $h(\pi(x)) \ge 0$ is satisfied along trajectories. The theorem is an extension of earlier ROM-CBF results: it allows general projection mappings, handles disturbances in the reduced-order dynamics, gives time-invariant safe sets, and relaxes prior restrictions such as bounded-gradient CBFs. The proof combines Nagumo's theorem with derivative bounds: along the boundary of $W$, the barrier derivative is positive because condition (18) compensates for the tracking error term from the simulation function.
Load-bearing premise
The entire argument rests on the existence of a simulation function and interface with known parameters $\lambda, \iota, \rho, \beta$ that bound how well the full-order system tracks the reduced-order controller, and on the ability to verify inequalities (9) and (18) for the actual system; for the ARCHER demo, the paper assumes the Lyapunov function from the zero dynamics policy certifies tracking but does not provide those numerical bounds, and it applies a continuous-ODE theorem to a hybrid robot.
Editorial extensions
If this is right
- If the theorem's conditions hold, the full-order system satisfies the original safety constraint $h(\pi(x)) \ge 0$ for all time, even though the controller was designed on the reduced-order model.
- For a fixed interface, the condition $\lambda \ge \alpha + \varepsilon\mu/(4\rho)$ can always be met by choosing $\alpha$ and $\varepsilon$ small, so the framework gives a tuning rule for safe implementation.
- The safe set for the full-order system is time-invariant, unlike earlier ROM-CBF constructions that produced time-varying safe sets.
- The framework permits black-box tracking interfaces, so existing high-performance controllers on drones or legged robots can be upgraded with safety filters without redesigning them.
- The hardware demonstration on ARCHER indicates the approach can be applied to highly underactuated, hybrid robotic systems despite the theorem being stated for continuous ODEs.
Reading between the lines
- A natural extension would be to state a hybrid-system version of Theorem 2, since ARCHER is a hybrid system and the current proof relies on Nagumo's theorem for continuous dynamics; the hardware demo suggests the inequality may tolerate the mismatch, but a formal treatment would close the gap.
- The inflation term $\frac{1}{\alpha}(\frac{\sigma}{4}\delta^2 + \frac{\iota}{\mu})$ quantifies conservatism: users could trade off safety margin against performance by measuring $\delta$ and $\iota$ experimentally rather than assuming them.
- The framework could also be applied in the reverse direction—using simulation functions to certify when a reduced-order model is not safe enough—or to other abstraction-based control settings where approximate simulation relations are available.
- One testable prediction is that, for a fixed full-order system, decreasing $\alpha$ should monotonically enlarge the verified safe region $W$, which practitioners could check by sweeping $\alpha$ in simulation.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper presents a framework for safety-critical control of high-dimensional full-order models (FOMs) using reduced-order models (ROMs). The authors define projection maps from the FOM to a ROM, introduce a simulation function V and an interface k that relate the ROM controller to the FOM controller, and combine V with an input-to-state safe control barrier function h for the ROM. The main result, Theorem 2, states that under a simulation-function inequality (9), an ISS-CBF condition (13), and the parameter condition (18), the set W = S_delta ∩ Omega_beta is forward invariant for the closed-loop FOM, where S_delta is an inflated version of the candidate safe set S. The paper also presents a quadrotor simulation and a hardware demonstration on the ARCHER hopping robot.
Significance. The framework is a natural and potentially useful generalization of earlier ROM-based CBF work, and the algebraic core of the proof of Theorem 2 is coherent: the derivative estimates and the use of Nagumo's theorem are standard and check out. The paper also clearly identifies the role of the simulation function and gives a concrete route to transferring ROM safety filters to full-order systems. However, the advertised safety guarantee is not actually delivered by the stated theorem, because forward invariance is proved only for an inflated set S_delta that is not a subset of the constraint set C. In addition, the examples do not verify the numerical assumptions of the theorem, and the hardware demonstration involves a hybrid system while the theorem applies to continuous ODEs. The contribution is therefore conditional: the main idea is promising, but the central safety claim needs repair before the paper can be accepted.
major comments (3)
- [Section IV, Theorem 2, Eq. (17)] Theorem 2 proves forward invariance of S_delta, not of the candidate safe set S defined by B(x) >= 0. The set S_delta contains points with h(pi(x)) < 0 because the offset (1/alpha)(sigma/4 delta^2 + iota/mu) is positive whenever delta or iota is positive. For instance, a point with V(x)=0 and B_delta(x)=0 satisfies h(pi(x)) = -(1/alpha)(sigma/4 delta^2 + iota/mu) < 0, so the boundary of W includes states that violate the state constraint C in Eq. (11). Forward invariance of a superset of S does not imply that trajectories starting in S remain in C; a trajectory may leave S and enter W \setminus C. Thus the theorem, as stated, does not establish the safety guarantee h(pi(x)) >= 0 that the paper claims in the abstract and conclusions. The authors should either prove forward invariance of a subset of S (or of C), or explicitly reframe the result as a practical-safety statement with a quantified worst-case violation and adjust all claims accordingly.
- [Section V, ARCHER demonstration] The hardware example does not verify the hypotheses of Theorem 2. The zero dynamics policy from [21], [30] is invoked as the interface k, and its Lyapunov function is used as the simulation function V, but the required constants lambda, iota, rho, beta, and the bound delta = sup_{Omega_beta} d(x) are not computed. Condition (18) is asserted to hold by choosing alpha = 0.4, but this cannot be checked without values for lambda, epsilon, mu, and rho. The statement in Remark 1 that one can 'initialize alpha and epsilon very small to ensure safety and then increase' is a heuristic, not a verification of the theorem's assumptions. Without these numerical certificates, the demonstration does not show that the observed safety of ARCHER is explained by Theorem 2.
- [Section V and Theorem 2] ARCHER is described as a high-dimensional, hybrid, underactuated system, whereas Theorem 2 applies to the continuous ODE (2) with locally Lipschitz dynamics and uses Nagumo's theorem on a closed set. The paper does not provide a hybrid-system extension of the invariance argument, nor does it state conditions under which the simulation function inequalities (8) and (9) survive resets or impacts. The prior work [21], [30] may indeed provide a hybrid Lyapunov function for the tracking interface, but this is not established here. The hardware claim therefore requires either a hybrid version of Theorem 2 or a clear argument that the continuous theory applies to the closed-loop hopping behavior.
minor comments (4)
- [Section IV, definition of delta] The definition delta := sup_{x in Omega_beta} d(x) requires the supremum to be finite, but no assumptions are stated that guarantee this (for example, compactness of Omega_beta and continuity of d). The authors should add such assumptions or discuss the degenerate case.
- [Definition 1] The phrase 'the largest sublevel set of V contained within D' is ambiguous if D is not all of R^N and V is not proper. Since Omega_beta is later treated as a closed set in Nagumo's theorem, the authors should clarify the topological properties of Omega_beta.
- [Example 2] The sentence 'we took epsilon = 20 and omitted the sigma term since grad h = L_g h' is unclear: condition (13) includes both the (1/epsilon)||L_g h||^2 and (1/sigma)||grad h||^2 terms, and eliminating one of them needs a justification (for example, that d = 0 in that example so delta = 0).
- [Remark 1] The suggestion to initialize alpha and epsilon 'very small' and then increase them until adequate performance is achieved should be separated from the formal verification of condition (18); as written, it may give the impression that the theorem's hypotheses can be satisfied by parameter tuning without checking the underlying bounds.
Circularity Check
No significant circularity: Theorem 2 is a conditional barrier-invariance result derived from its assumptions; the ARCHER reliance on same-group prior Lyapunov functions is a verification gap, not a circular reduction.
full rationale
The paper's main result, Theorem 2, is a conditional implication with independent content. The proof starts from the assumed simulation-function inequalities (8) and (9), the ISS-CBF inequality (13), the bound delta >= sup_{Omega_beta} d(x), and the parameter condition (18), and derives dot{B_delta} > -alpha B_delta and dot{B_beta} > -lambda B_beta on W; Nagumo's theorem then yields forward invariance of W. Each of these objects is defined before and independently of the conclusion: B_delta is constructed from h, V, and tunable constants, but the theorem does not assume forward invariance of W; invariance is the conclusion. No equation has the conclusion appearing as an assumption, and no fitted parameter is renamed as a prediction. The self-citations [2]-[4] frame the work as a generalization of prior ROM-CBF methods, which is normal lineage rather than a load-bearing circular step. The ARCHER hardware section does invoke same-group prior zero-dynamics-policy Lyapunov functions [21], [30] as a certificate for the simulation-function assumption; however, the paper does not derive the ARCHER safety conclusion from its own theorem alone, and the hardware trajectory with h(pi(x(t))) > 0 serves as an external demonstration. The lack of explicit numerical bounds for V in the ARCHER section is a verification and rigor gap, not a circular reduction. A separate soundness concern is that W = S_delta intersect Omega_beta may not be a subset of C, so forward invariance of W does not by itself imply h(pi(x)) >= 0; that issue is a logical soundness gap, not a circularity of the kind assessed here. Therefore no step of the derivation reduces to its own inputs.
Assumptions & free parameters
free parameters (5)
- alpha =
0.4 (ARCHER), varied 0.5-2.0 (quadrotor)
- epsilon =
20 (quadrotor); unspecified for ARCHER
- mu =
unspecified
- sigma =
unspecified
- simulation function parameters (lambda, iota, rho, beta, delta) =
not computed
assumptions (6)
- standard math Nagumo's theorem provides necessary and sufficient conditions for forward invariance.
- standard math The Comparison Lemma gives the exponential bound on V in Lemma 1.
- domain assumption The projection maps pi and psi are differentiable and the ROM dynamics are locally Lipschitz.
- domain assumption There exists a simulation function V and interface k satisfying Definition 1 with known lambda, iota, rho, beta.
- domain assumption The reduced-order controller kappa satisfies the ISS-CBF condition (13) for all y in R^n.
- ad hoc to paper The zero dynamics policy's Lyapunov function from [21], [30] serves as a simulation function for ARCHER's hybrid dynamics.
Cite this review
Pith. "Pith review of Safety-Critical Controller Synthesis with Reduced-Order Models." pith.science (2026). https://pith.science/paper/PMMRXGBP
@misc{pith2026241116479,
author = {Pith},
title = {Pith review of: Safety-Critical Controller Synthesis with Reduced-Order Models},
year = {2026},
howpublished = {\url{https://pith.science/paper/PMMRXGBP}},
note = {Machine review of arXiv:2411.16479}
}
read the original abstract
Reduced-order models (ROMs) provide lower dimensional representations of complex systems, capturing their salient features while simplifying control design. Building on previous work, this paper presents an overarching framework for the integration of ROMs and control barrier functions, enabling the use of simplified models to construct safety-critical controllers while providing safety guarantees for complex full-order models. To achieve this, we formalize the connection between full and ROMs by defining projection mappings that relate the states and inputs of these models and leverage simulation functions to establish conditions under which safety guarantees may be transferred from a ROM to its corresponding full-order model. The efficacy of our framework is illustrated through simulation results on a drone and hardware demonstrations on ARCHER, a 3D hopping robot.
Figures
Reference graph
Works this paper leans on
-
[21]
Robust Agility via Learned Zero Dynamics Policies
N. Csomay-Shanklin, W. Compton, I. D. J. Rodriguez, E. R. Ambrose, Y . Yue, and A. D. Ames, “Robust agility via learned zero dynamics policies,” arXiv preprint arXiv:2409.06125 , 2024
work page Pith review arXiv 2024
-
[30]
Constructive Nonlinear Control of Underactuated Systems via Zero Dynamics Policies
W. Compton, I. D. J. Rodriguez, N. Csomay-Shanklin, Y . Yue, and A. D. Ames, “Constructive nonlinear control of underactuated systems via zero dynamics policies,” arXiv preprint arXiv:2408.14749 , 2024
work page Pith review arXiv 2024
-
[1]
Control barrier function based quadratic programs for safety critical systems,
A. D. Ames, X. Xu, J. W. Grizzle, and P. Tabuada, “Control barrier function based quadratic programs for safety critical systems,” IEEE Trans. Autom. Control, vol. 62, no. 8, pp. 3861–3876, 2017
2017
-
[2]
Safety-critical control for autonomous systems: Control barrier functions via reduced order models,
M. H. Cohen, T. G. Molnar, and A. D. Ames, “Safety-critical control for autonomous systems: Control barrier functions via reduced order models,” Annual Reviews in Control , vol. 57, p. 100947, 2024
2024
-
[3]
Model-free safety-critical control for robotic systems,
T. G. Molnar, R. K. Cosner, A. W. Singletary, W. Ubellacker, and A. D. Ames, “Model-free safety-critical control for robotic systems,” IEEE Robot. Aut. Lett. , vol. 7, no. 2, pp. 944–951, 2022
work page 2022
-
[4]
Safety-critical control with bounded inputs via reduced order models,
T. G. Molnar and A. D. Ames, “Safety-critical control with bounded inputs via reduced order models,” in Proc. Amer. Control Conf. , pp. 1414–1421, 2023
work page 2023
-
[5]
M. Krsti ´c, I. Kanellakopoulus, and P. Kokotovi ´c, Nonlinear and Adaptive Control Design . Wiley, 1995
work page 1995
-
[6]
Fastrack: A modular framework for real-time motion planning and guaranteed safe tracking,
M. Chen, S. L. Herbert, H. Hu, Y . Pu, J. F. Fisac, S. Bansal, S. Han, and C. J. Tomlin, “Fastrack: A modular framework for real-time motion planning and guaranteed safe tracking,” IEEE Trans. Autom. Control , vol. 66, no. 12, pp. 5861–5876, 2021
work page 2021
Show all 32 references
-
[7]
Safe-by-design planner–tracker synthesis with a hierarchy of system models,
K. S. Schweidel, H. Yin, S. W. Smith, and M. Arcak, “Safe-by-design planner–tracker synthesis with a hierarchy of system models,” Annual Reviews in Control, vol. 53, pp. 138–146, 2022
2022
-
[8]
Embedded hierarchical mpc for autonomous navigation,
D. Benders, J. K ¨ohlher, T. Niesten, R. Bab ˘uska, J. Alonso-Mora, and L. Ferranti, “Embedded hierarchical mpc for autonomous navigation,” arXiv preprint arXiv:2406.11506 , 2024
2024 arXiv
-
[9]
Robust feedback motion planning via contraction theory,
S. Singh, B. Landry, A. Majumdar, J. J. Slotine, and M. Pavone, “Robust feedback motion planning via contraction theory,” The In- ternational Journal of Robotics Research, vol. 42, no. 9, pp. 655–688, 2023
2023
-
[10]
Tabuada, Verification and control of hybrid systems: a symbolic approach
P. Tabuada, Verification and control of hybrid systems: a symbolic approach. Spring Science & Business Media, 2009
2009
-
[11]
Belta, B
C. Belta, B. Yordanov, and E. A. Gol, Formal methods for discrete- time dynamical systems . Springer, 2017
2017
-
[12]
Hierarchically consis- tent control systems,
G. J. Pappas, G. Lafferriere, and S. Sastry, “Hierarchically consis- tent control systems,” IEEE Trans. Autom. Control , vol. 45, no. 6, pp. 1144–1160, 2000
2000
-
[13]
Consistent abstractions of affine control systems,
G. J. Pappas and S. Simi ´c, “Consistent abstractions of affine control systems,” IEEE Trans. Autom. Control , vol. 47, no. 5, pp. 745–756, 2002
2002
-
[14]
Hierarchical control system design using approximate simulation,
A. Girard and G. J. Pappas, “Hierarchical control system design using approximate simulation,” Automatica, vol. 45, pp. 566–571, 2009
2009
-
[15]
Geometric tracking control of a quadrotor UA V on SE(3),
T. Lee, M. Leoky, and N. H. McClamroch, “Geometric tracking control of a quadrotor UA V on SE(3),” in Proc. Conf. Decis. Control, pp. 5420–5425, 2010
2010
-
[16]
Minimum snap trajectory generation and control for quadrotors,
D. Mellinger and V . Kumar, “Minimum snap trajectory generation and control for quadrotors,” in Proc. Int. Conf. Robot. and Autom. , pp. 2520–2525, 2011
2011
-
[17]
Optimization-based control for dynamic legged robots,
P. M. Wensing, M. Posa, Y . Hu, A. Escande, N. Mansard, and A. D. Prete, “Optimization-based control for dynamic legged robots,” IEEE Trans. Robot, vol. 40, 2024
2024
-
[18]
Learning agile and dynamic motor skills for legged robots,
J. Hwangbo, J. Lee, A. Dosovitskiy, D. Bellicoso, V . Tsounis, V . Koltun, and M. Hutter, “Learning agile and dynamic motor skills for legged robots,” Science Robotics, vol. 4, no. 26, 2019
2019
-
[19]
Ambrose, Creating ARCHER: A 3D Hopping Robot with Flywheels for Attitude Control
E. Ambrose, Creating ARCHER: A 3D Hopping Robot with Flywheels for Attitude Control . PhD thesis, California Institute of Technology, 2022
2022
-
[20]
Nonlinear model predictive control of a 3D hopping robot: Leveraging Lie group integrators for dynamically stable behaviors,
N. Csomay-Shanklin, V . D. Dorobantu, and A. D. Ames, “Nonlinear model predictive control of a 3D hopping robot: Leveraging Lie group integrators for dynamically stable behaviors,” inProc. Int. Conf. Robot. and Autom., pp. 12106–12112, 2023
2023
-
[22]
Blanchini and S
F. Blanchini and S. Miani, Set-theoretic methods in control . Springer, 2008
2008
-
[23]
Abraham, J
R. Abraham, J. E. Marsden, and T. Ratiu, Manifolds, tensor analysis, and applications. Addison-Wesley, 1983
1983
-
[24]
Generative modeling of residuals for real-time risk-sensitive safety with discrete-time control barrier functions,
R. K. Cosner, I. Sadalski, J. K. Woo, P. Culbertson, and A. D. Ames, “Generative modeling of residuals for real-time risk-sensitive safety with discrete-time control barrier functions,” in Proc. Int. Conf. Robot. and Autom., pp. 9960–9967, 2024
2024
-
[25]
H. K. Khalil, Nonlinear Systems. Prentice Hall, 3 ed., 2002
2002
-
[26]
Control barrier functions and input-to-state safety with application to automated vehicles,
A. Alan, A. J. Taylor, C. R. He, A. D. Ames, and G. Orosz, “Control barrier functions and input-to-state safety with application to automated vehicles,” IEEE Trans. Contr. Syst. Tech., vol. 31, no. 6, pp. 2744–2759, 2023
2023
-
[27]
K. S. Schweidel, Robust Hierarchical Control with Connected Layers. PhD thesis, University of California, Berkeley, 2023
2023
-
[28]
Hierarchical control via approximate simulation and feedback linearization,
J. Fu, S. Shah, and H. G. Tanner, “Hierarchical control via approximate simulation and feedback linearization,” in Proc. Amer. Control Conf., pp. 1816–1821, 2013
2013
-
[29]
An approximate abstraction approach to safety control of differentially flat systems,
A. Colombo and A. Girard, “An approximate abstraction approach to safety control of differentially flat systems,” in Proc. Eur. Control Conf., pp. 4226–4231, 2013
2013
-
[31]
Characterizing smooth safety filters via the implicit function theorem,
M. H. Cohen, P. Ong, G. Bahati, and A. D. Ames, “Characterizing smooth safety filters via the implicit function theorem,” IEEE Contr. Syst. Lett., vol. 7, pp. 3890–3895, 2023
2023
-
[32]
Composing control barrier functions for complex safety specifications,
T. G. Molnar and A. D. Ames, “Composing control barrier functions for complex safety specifications,” IEEE Contr. Syst. Lett. , vol. 7, pp. 3615–3620, 2023
2023
Reviewed August 12, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.