REVIEW 3 major objections 6 minor 30 references
Secure Safety Filter Design for Sampled-data Nonlinear Systems under Sensor Spoofing Attacks
T0 review · 3 major / 6 minor · reviewed 2026-08-15 · deepseek-v4-flash
Pith's one-line read The paper claims that secure safety filters, previously limited to linear or differentially flat systems, can be extended to general sampled-data nonlinear systems under sensor spoofing attacks, provided the system satisfies a sparse…
desk verdict Novel extension of secure safety filters to nonlinear systems, but the relaxed-case Theorem 2 has a genuine induction gap that needs fixing before publication. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing objects are exact and relaxed observability maps. An exact map $L^{\Gamma}(\cdot)$ reconstructs the state $l$ sampling steps in the past from a window of inputs and the measurements of sensor subset $\Gamma$; its relaxed counterpart $L_D^{\Gamma}$ is set-valued and returns a set inside a $\delta$-ball around an estimate, accommodating bounded process disturbance. These maps abstract whichever state estimator a user has available, so the subsequent arguments hold for any concrete estimator satisfying the observability definition. The other half is the zero-order control barrier function, a function $h$ whose sampled-data decrease condition guarantees $h$ stays nonnegative throughout the sampling interval. The secure filter couples the two: it collects the union of consistent estimates over all $p-s$ sensor subsets, propagates them to the present, and demands the CBF constraint hold for every plausible state simultaneously, giving the quadratic programs (13) and (26). The consistency condition, together with the proved Lemma 1 in the exact case and the unproved Lemma 2 in the relaxed case, is what lets nested sensor sets be compared so that redundancy can identify the true state or bound it.
What would settle it
Run a search over a nonlinear system that is $\delta$-bounded observable, with nested sensor sets $\Gamma_1\subset\Gamma_2$, for input-output data that is consistent for $\Gamma_2$ under (19) but for which $L_D^{\Gamma_1}\cap L_D^{\Gamma_2}=\varnothing$; a single such instance would refute the $B_{4\delta}$ bound of Corollary 2 and the relaxed $2s$-sparse guarantee. For the exact claim, simulate a $2s$-sparse observable sampled-data nonlinear system with an omniscient $s$-sensor spoofing attack and check whether the QP (13), feasible at every step, ever lets $h(x(t))<0$; any violation would refute Theorem 1.
Extended reading notes
Core claim
The central claim is that a safety filter can be made attack-robust for general sampled-data nonlinear systems by basing it on observability maps rather than on any one estimator. For each subset $\Gamma$ of $p-s$ sensors, an observability map $L^{\Gamma}$ reconstructs the state $l$ steps in the past from input-output data, and a consistency condition labels those reconstructions that agree with the dynamics and with uncorrupted sensors. When the system is $s$-sparse observable, the set of all plausible states is exactly the union of consistent reconstructions (Proposition 1), so a zero-order CBF filter that keeps every plausible state inside $\mathcal{C}$ keeps the true state inside $\mathcal{C}$; when $2s$-sparse observability holds, the true state is the only consistent reconstruction (Corollary 1), making the filter feasible automatically. The relaxed case replaces points by set-valued maps $L_D^{\Gamma}$ enclosed in $\delta$-balls, over-approximates plausible states by a $B_{4\delta}$ ball under $2s$-sparse $\delta$-bounded observability (Corollary 2), and uses a robust CBF filter (26) to preserve safety despite bounded process disturbance. The paper therefore asserts provable safety guarantees for nonlinear sampled-data systems under arbitrary spoofing of at most $s$ sensors, contingent on an offline-checkable observability property and, in the weaker $s$-sparse cases, online feasibility.
Load-bearing premise
The relaxed-case guarantees stand on an unproved step: for nested sensor sets, consistency of data from the larger set must imply consistency of the smaller set and nonempty intersection of their two estimate sets ($L_D^{\Gamma_1}\cap L_D^{\Gamma_2}\neq\varnothing$), a claim stated as Lemma 2 in Section IV with its proof omitted; if that step fails, the $B_{4\delta}$ bound and the relaxed safety guarantee no longer follow.
Editorial extensions
If this is right
- Under $2s$-sparse observability, the exact secure filter (13) needs no online feasibility check: the true state is the unique consistent estimate, so the CBF constraint is always satisfiable.
- With only $s$-sparse observability, the same filter is safe whenever its QP stays feasible, and the paper argues feasibility cannot be checked a priori because arbitrary $s$ sensors may be compromised.
- For sampled-data implementations using approximate discrete-time models, the relaxed filter (26) preserves safety with an inflated margin; using fourth-order Runge-Kutta makes the margin shrink like $T^5$ as the sampling period goes to zero.
- In the unicycle example, the filter leaves the nominal controller untouched away from the boundary and only corrects near the safety band, so the price of security is localized in time.
Reading between the lines
- Inference: if a proof of Lemma 2 is supplied, the $B_{4\delta}$ bound can be used as a deterministic, computationally checkable safety certificate for approximate nonlinear models under spoofing.
- Inference: the observability-map abstraction makes the filter modular—improving the underlying estimator directly tightens $\delta$, and hence shrinks the safety margin, without redesigning the filter.
- Inference: the $2s$ redundancy threshold mirrors error-correction bounds, which suggests that compressed-sensing or coding-theoretic attack models could be imported to reduce conservatism below the worst-case subset union.
- Inference: a testable extension is to make the data window length $l$ adaptive, since longer windows improve observability depth but delay detection of attacks that begin mid-window; the trade-off is not analyzed in the paper.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper proposes a secure safety filter for sampled-data nonlinear systems under sensor spoofing attacks, building on zero-order control barrier functions. It introduces exact and relaxed "observability maps" that abstract state estimators, defines sparse variants of differential observability, and uses consistency checks to compute an over-approximation of the set of plausible states. A safety filter is then formulated as a quadratic program enforcing the CBF condition over all plausible states; Theorem 1 covers the exact observability case and Theorem 2 the relaxed δ-bounded case. The claims are validated in simulation on a unicycle with two spoofed sensors.
Significance. The conceptual contribution is valuable: it extends secure safety filters from linear and differentially flat systems to general sampled-data nonlinear systems, and it cleanly separates secure state reconstruction from safety filtering by abstracting estimators as set-valued maps. The paper also provides reproducible code and a concrete simulation. However, the relaxed-case safety theorem is not yet proved: it relies on an omitted proof of Lemma 2 and on an unjustified recursive-positivity argument in the proof of Theorem 2. These are load-bearing for the relaxed case, which is the case exercised in the simulation, so the paper needs major revision.
major comments (3)
- [Section IV, proof of Theorem 2 (after Eq. (27))] The sentence "By recursive reasoning, we know h(hat x_k) remains positive if it starts positive" is not justified. The quantity hat x_k is produced from current input-output data by the observability map, and it need not equal the state propagated from the previous estimate F(hat x_{k-1}, u_{k-1}); the filter constraint (26) is enforced at the current estimate and does not control the next estimate. The proof needs an explicit margin condition on the estimator states, e.g., a lower bound on h(hat x_k)-gamma(h(hat x_k))+epsilon relative to the Lipschitz terms L1 delta' and L1 bar-w, or a direct argument that h(hat x_{k+1}) >= (1-gamma)h(hat x_k)+epsilon. Without such a condition the induction collapses. This gap affects exactly the relaxed case used in the simulation.
- [Section IV, Lemma 2 and Definition 8] Lemma 2 is the key step for Corollary 2 and Theorem 2, yet its proof is omitted with the statement "neglected due to space limitations." This is not acceptable for a load-bearing lemma. In addition, Definition 8 only requires ||z - hat x_{k-l}^Gamma|| <= delta and does not require z to lie in L_D^Gamma(...), which makes the intersection claim (20) ambiguous: a point outside L_D^Gamma2 but inside its enclosing ball need not satisfy the consistency equations for the smaller sensor set. Please provide a full proof and clarify the exact role of L_D^Gamma in the consistency condition.
- [Section IV, Theorem 2 statement] The proof of Theorem 2 uses, without stating them as assumptions, that F(x,u) is Lipschitz in x uniformly in u (with constant L), that h is Lipschitz (with constant L1), and that these constants are known so that epsilon1 can be chosen. The theorem statement as written only assumes Assumption 1, zero-order CBF, and s-sparse delta-bounded observability. Please add the Lipschitz/global-constant assumptions to the theorem statement, or make clear that they are inherited from Proposition 3 and the choice of epsilon1 after Eq. (26).
minor comments (6)
- [Introduction] There is a duplicated article in "available to the the controller" and again in "with the the Department" in the author footnote.
- [Theorems 1 and 2] Theorem 1 refers to "system (7)" for the sparse observability condition, but the system equation is (5) and (7) is the plausible-state equation; Theorem 2 refers to "system (17)", which should be (14).
- [Definitions 1 and 3; proofs] The notation (1-gamma)h(x) is not defined; since gamma is a function, it should be written as h(x)-gamma(h(x)) to avoid ambiguity.
- [Definition 8] The quantity hat x_{k-l}^Gamma is used but not defined in the definition; it presumably denotes the center of the ball from Definition 6. Please state this explicitly.
- [Proposition 3] In the proof of (23), the index Gamma is chosen after fixing an element z_{k-l}; the statement should clarify that the union is over Gamma and that for each Gamma the propagated bound uses the same Gamma throughout the l steps.
- [Section V, Simulation] The claim that the sampled-data unicycle is 2-sparse delta-bounded observable is asserted without a formal verification; given that Theorem 2 is the main relaxed-case result, a few details on how delta, delta', and epsilon1 are chosen would improve reproducibility.
Circularity Check
No significant circularity: the safety guarantees are conditional on explicitly stated observability and feasibility assumptions, and the derivation does not reduce to its inputs by construction.
full rationale
The paper's central claims, Theorems 1 and 2, state safety guarantees for the secure safety filters (13) and (26) under explicit conditions: s-sparse (or 2s-sparse) observability, zero-order CBF, and (in the relaxed case) filter feasibility. These conditions are not derived from the desired safety conclusion; they are separate assumptions. The filters enforce CBF constraints on the set of plausible states (or their centers), and safety follows from the definition of zero-order CBF as stated in Definition 1. No parameter is fitted to data and then renamed as a prediction; the observability maps are abstractions of assumed state-estimation algorithms, not quantities fitted to the safety outcome. The paper does cite prior work by the same authors ([13], [22], [15]), but these citations supply definitions and linear-case building blocks that are restated or extended in the present manuscript, and the nonlinear extension is a new construction. Two correctness concerns are noted but they are not circularity: (i) the proof of Lemma 2 is omitted ("The proof of Lemma 2 follows similar steps to those of Lemma 1 and is neglected due to space limitations."), and (ii) Theorem 2's proof contains an unjustified recursive step ("By recursive reasoning, we know h(hat x^Gamma_k) remains positive if it starts positive.") that assumes the next estimator output inherits positivity without a margin condition. These are rigor gaps in a non-circular derivation; the safety result is not obtained by fitting or by defining the conclusion into the assumptions.
Assumptions & free parameters
free parameters (1)
- Consistency-check threshold tau =
Not reported; described as a small empirically obtained threshold
assumptions (7)
- domain assumption The system (1) has unique trajectories over each sampling interval ('regular enough').
- domain assumption Assumption 1: the attacker is omniscient and corrupts at most s sensors, with the attacked set fixed over time.
- domain assumption Definition 1: h is a zero-order control barrier function for the sampled-data system with fixed T, gamma, and epsilon.
- domain assumption The system is s-sparse (or 2s-sparse) differentially observable, and the corresponding observability maps L^Gamma (or L_D^Gamma) are available for every Gamma of size p-s.
- domain assumption For the relaxed case, the process disturbance satisfies ||w_k|| <= w-bar with known w-bar, and F is Lipschitz in x uniformly in u with known constant L.
- ad hoc to paper Online feasibility: the quadratic programs (13) and (26) are feasible at every sampling instant, explicitly assumed in Theorems 1 and 2 for the s-sparse case.
- ad hoc to paper Lemma 2 of Section IV: for nested sensor sets, consistency of the larger set implies consistency of the smaller set and L_D^Gamma1 intersect L_D^Gamma2 is nonempty.
Cite this review
Pith. "Pith review of Secure Safety Filter Design for Sampled-data Nonlinear Systems under Sensor Spoofing Attacks." pith.science (2026). https://pith.science/paper/G7FC3ELN
@misc{pith2026250506842,
author = {Pith},
title = {Pith review of: Secure Safety Filter Design for Sampled-data Nonlinear Systems under Sensor Spoofing Attacks},
year = {2026},
howpublished = {\url{https://pith.science/paper/G7FC3ELN}},
note = {Machine review of arXiv:2505.06842}
}
read the original abstract
This paper presents a secure safety filter design for nonlinear systems under sensor spoofing attacks. Existing approaches primarily focus on linear systems which limits their applications in real-world scenarios. In this work, we extend these results to nonlinear systems in a principled way. We introduce exact observability maps that abstract specific state estimation algorithms and extend them to a secure version capable of handling sensor attacks. Our generalization also applies to the relaxed observability case, with slightly relaxed guarantees. More importantly, we propose a secure safety filter design in both exact and relaxed cases, which incorporates secure state estimation and a control barrier function-enabled safety filter. The proposed approach provides theoretical safety guarantees for nonlinear systems in the presence of sensor attacks. We numerically validate our analysis on a unicycle vehicle equipped with redundant yet partly compromised sensors.
Figures
Figures from the paper (1 more)
Reference graph
Works this paper leans on
-
[1]
Control barrier function based quadratic programs for safety critical systems,
A. D. Ames, X. Xu, J. W. Grizzle, and P. Tabuada, “Control barrier function based quadratic programs for safety critical systems,” IEEE Transaction on Automatic Control , vol. 62, no. 8, pp. 3861–3876, 2016
2016
-
[2]
Continuous-time control synthesis under nested signal temporal logic specifications,
P. Yu, X. Tan, and D. V . Dimarogonas, “Continuous-time control synthesis under nested signal temporal logic specifications,” IEEE Transactions on Robotics , vol. 40, pp. 2272–2286, 2024
work page 2024
-
[3]
Input-to-state stabilizing control under denial-of-service,
C. De Persis and P. Tesi, “Input-to-state stabilizing control under denial-of-service,” IEEE Transactions on Automatic Control , vol. 60, no. 11, pp. 2930–2944, 2015
2015
-
[4]
On the performance analysis of resilient networked control systems under replay attacks,
M. Zhu and S. Martinez, “On the performance analysis of resilient networked control systems under replay attacks,” IEEE Transactions on Automatic Control , vol. 59, no. 3, pp. 804–808, 2013
2013
-
[5]
Covert misappropriation of networked control systems: Presenting a feedback structure,
R. S. Smith, “Covert misappropriation of networked control systems: Presenting a feedback structure,” IEEE Control Systems Magazine , vol. 35, no. 1, pp. 82–92, 2015
2015
-
[6]
False data injection attacks against state estimation in wireless sensor networks,
Y . Mo, E. Garone, A. Casavola, and B. Sinopoli, “False data injection attacks against state estimation in wireless sensor networks,” in 49th IEEE Conference on Decision and Control (CDC) . IEEE, 2010, pp. 5967–5972
2010
-
[7]
Iran–U.S. RQ-170 incident,
“Iran–U.S. RQ-170 incident,” https://en.wikipedia.org/wiki/Iran%E2% 80%93U.S. RQ-170 incident, accessed: 2025-02-14
2025
-
[8]
Non-invasive spoofing attacks for anti-lock braking systems,
Y . Shoukry, P. Martin, P. Tabuada, and M. Srivastava, “Non-invasive spoofing attacks for anti-lock braking systems,” in Cryptographic Hardware and Embedded Systems-CHES 2013. Berlin, Heidelberg. Springer, 2013, pp. 55–72
work page 2013
Show all 30 references
-
[9]
Injected and delivered: Fabricating implicit control over actuation systems by spoofing inertial sensors,
Y . Tu, Z. Lin, I. Lee, and X. Hei, “Injected and delivered: Fabricating implicit control over actuation systems by spoofing inertial sensors,” in 27th USENIX security symposium , 2018, pp. 1545–1562
2018
-
[10]
Secure estimation and control for cyber-physical systems under adversarial attacks,
H. Fawzi, P. Tabuada, and S. Diggavi, “Secure estimation and control for cyber-physical systems under adversarial attacks,” IEEE Transac- tions on Automatic control , vol. 59, no. 6, pp. 1454–1467, 2014
2014
-
[11]
Event-triggered state observers for sparse sensor noise/attacks,
Y . Shoukry and P. Tabuada, “Event-triggered state observers for sparse sensor noise/attacks,” IEEE Transactions on Automatic Control, vol. 61, no. 8, pp. 2079–2091, 2015
2015
-
[12]
Observability of linear systems under adversarial attacks,
M. S. Chong, M. Wakaiki, and J. P. Hespanha, “Observability of linear systems under adversarial attacks,” in 2015 American Control Conference (ACC). IEEE, 2015, pp. 2439–2444
2015
-
[13]
Safety of linear systems under severe sensor attacks,
X. Tan, P. Ong, P. Tabuada, and A. D. Ames, “Safety of linear systems under severe sensor attacks,” in 63rd IEEE Conference on Decision and Control (CDC) . IEEE, 2024, pp. 336–342
2024
-
[14]
Secure state reconstruction in differentially flat systems under sensor attacks using satisfiability modulo theory solving,
Y . Shoukry, P. Nuzzo, N. Bezzo, A. L. Sangiovanni-Vincentelli, S. A. Seshia, and P. Tabuada, “Secure state reconstruction in differentially flat systems under sensor attacks using satisfiability modulo theory solving,” in 2015 54th IEEE conference on decision and control (CDC...
2015
-
[15]
Secure safety filter: Towards safe flight control under sensor attacks,
X. Tan, J. Sundar, R. Bruzzone, P. Ong, W. T. Lunardi, M. Andreoni, P. Tabuada, and A. D. Ames, “Secure safety filter: Towards safe flight control under sensor attacks,” in 2025 IEEE/RSJ International Conference on Intelligent Robots and Systems (IROS), submitted. Available at...
2025
-
[16]
Data-driven safety filters: Hamilton-jacobi reachability, control barrier functions, and predictive methods for uncertain systems,
K. P. Wabersich, A. J. Taylor, J. J. Choi, K. Sreenath, C. J. Tom- lin, A. D. Ames, and M. N. Zeilinger, “Data-driven safety filters: Hamilton-jacobi reachability, control barrier functions, and predictive methods for uncertain systems,” IEEE Control Systems Magazine , vol. 43...
2023
-
[17]
Secondary control for the safety of LTI systems under attacks,
Y . Lin, M. S. Chong, and C. Murguia, “Secondary control for the safety of LTI systems under attacks,” IFAC-PapersOnLine, vol. 56, no. 2, pp. 965–970, 2023
2023
-
[18]
Data-driven and stealthy deactiva- tion of safety filters,
D. Arnstr ¨om and A. M. Teixeira, “Data-driven and stealthy deactiva- tion of safety filters,” Learning for Dynamics and Control, to appear. arXiv preprint arXiv:2412.01346 , 2025
2025 arXiv
-
[19]
Safe control for nonlinear systems under faults and attacks via control barrier functions,
H. Zhang, Z. Li, and A. Clark, “Safe control for nonlinear systems under faults and attacks via control barrier functions,” arXiv preprint arXiv:2207.05146, 2022
2022 arXiv
-
[20]
Measurement-robust control barrier func- tions: Certainty in safety with uncertainty in state,
R. K. Cosner, A. W. Singletary, A. J. Taylor, T. G. Molnar, K. L. Bouman, and A. D. Ames, “Measurement-robust control barrier func- tions: Certainty in safety with uncertainty in state,” in 2021 IEEE/RSJ International Conference on Intelligent Robots and Systems (IROS) . IEEE,...
2021
-
[21]
Learning robust output control barrier functions from safe expert demonstrations,
L. Lindemann, A. Robey, L. Jiang, S. Das, S. Tu, and N. Matni, “Learning robust output control barrier functions from safe expert demonstrations,” IEEE Open Journal of Control Systems , 2024
2024
-
[22]
Zero-order con- trol barrier functions for sampled-data systems with state and input dependent safety constraints,
X. Tan, E. Das, A. D. Ames, and J. W. Burdick, “Zero-order con- trol barrier functions for sampled-data systems with state and input dependent safety constraints,” in 2025 American Control Conference (ACC), to appear. arXiv preprint arXiv:2411.17079 , 2025
2025 arXiv
-
[23]
Bernard, Observer design for nonlinear systems
P. Bernard, Observer design for nonlinear systems . Springer, 2019, vol. 479
2019
-
[24]
A coding theoretic view of secure state reconstruction,
S. Diggavi and P. Tabuada, “A coding theoretic view of secure state reconstruction,” Modeling and Design of Secure Internet of Things , pp. 357–369, 2020
2020
-
[25]
Stuart and A
A. Stuart and A. R. Humphries, Dynamical systems and numerical analysis. Cambridge University Press, 1998, vol. 2
1998
-
[26]
Convergence analysis of the extended Kalman filter used as an observer for nonlinear deterministic discrete-time systems,
M. Boutayeb, H. Rafaralahy, and M. Darouach, “Convergence analysis of the extended Kalman filter used as an observer for nonlinear deterministic discrete-time systems,” IEEE Transactions on Automatic Control, vol. 42, no. 4, pp. 581–586, 1997
1997
-
[27]
Observer design for sampled-data nonlinear systems via approximate discrete-time models,
M. Arcak and D. Nesic, “Observer design for sampled-data nonlinear systems via approximate discrete-time models,” in 42nd IEEE Inter- national Conference on Decision and Control (CDC) , vol. 1. IEEE, 2003, pp. 49–54
2003
-
[28]
Confidently incorrect: nonlinear observers with online error bounds,
J. Bunton and P. Tabuada, “Confidently incorrect: nonlinear observers with online error bounds,” in 2024 American Control Conference (ACC). IEEE, 2024, pp. 4729–4734
2024
-
[29]
Nonlinear observers with tighter online error bounds,
J. P. Silvestre, R. Nanayakkara, and P. Tabuada, “Nonlinear observers with tighter online error bounds,” in 2024 IEEE 63rd Conference on Decision and Control (CDC) . IEEE, 2024, pp. 7728–7733
2024
-
[30]
Robust control barrier functions for constrained sta- bilization of nonlinear systems,
M. Jankovic, “Robust control barrier functions for constrained sta- bilization of nonlinear systems,” Automatica, vol. 96, pp. 359–367, 2018. 8
2018
Reviewed August 15, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.