REVIEW 4 major objections 5 minor 20 references
The paper claims that a single convex LMI program can synthesize an ellipsoidal safe region and a backup controller that keeps a quadrotor's attitude within constraints despite bounded disturbances.
Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →
T0 review · deepseek-v4-flash
2026-08-04 08:00 UTC pith:PUZDCB4T
load-bearing objection A correct but classical linear RCI-synthesis paper whose advertised quaternion sector-bound result is missing; the nonlinear safety guarantee is calibrated, not proven. the 4 major comments →
Robust Safety Filter Synthesis for Quaternion Attitude Dynamics via LMI-Based Ellipsoidal Invariant Sets
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
Core claim
On the paper's own terms, the central claim is Theorem 2: if positive-definite Q, matrix Y, and scalar lambda > 0 satisfy LMI (15), then the ellipsoid E(Q^{-1}) is a robust controlled invariant set for the linear system with additive disturbances under the feedback u = Y Q^{-1} x. Combined with the input and output constraint LMIs (28) and (34), the solution of the convex program yields a maximal-volume ellipsoidal RCI set and its backup controller. The paper then extends this to the quadrotor attitude loop by linearizing around hover and folding the linearization error into the disturbance set as a norm-bounded term with a constant bound, and the safety filter blends nominal and backup torq
What carries the argument
The load-bearing object is the ellipsoidal robust controlled invariant set E(P) = {x : x^T P x <= 1}, together with its associated state-feedback backup law u = Kx. Invariance is certified through Nagumo's tangent-cone condition (11), and the S-procedure converts the semi-infinite invariance condition into the tractable LMI (15) with variables Q = P^{-1} and Y = KQ. A mixing function alpha(x) switches smoothly from the nominal controller to the backup controller as the state approaches the boundary; at the boundary, alpha = 1 and the certified backup law keeps the velocity pointing inward.
Load-bearing premise
The guarantee collapses if the norm of the linearization error exceeds the chosen bound Delta_max = 0.65 anywhere on the computed ellipsoid, because the invariance certificate is only as strong as that disturbance bound.
What would settle it
Evaluate the true nonlinear attitude dynamics at many points on the boundary of the computed ellipsoid E(P*) and compute the norm of the difference between the actual dynamics and the linear model under the backup control; if the norm exceeds 0.65 at any such point, the Nagumo condition is violated and the claimed invariance certificate fails. Alternatively, simulate with a disturbance realization that pushes the state to the boundary and check whether the mixed control law drives the state outside the ellipsoid.
If this is right
- For any constrained linear system with bounded additive disturbances and a feasible LMI solution, the resulting ellipsoid and backup controller give a formal safety certificate that is verifiable by a single convex feasibility check.
- The safety filter is minimally invasive: because mixing occurs only in a boundary layer, nominal tracking performance is preserved during normal operation.
- For the quadrotor, the method prevents the cascade failure where large position errors saturate the outer loop and drive the inner-loop attitude unstable, as demonstrated in the three simulation scenarios.
- The approach scales to high-dimensional state spaces because the LMI is convex and the ellipsoid parameterization is dimension-tractable.
Where Pith is reading between the lines
- If the linearization error bound were derived a priori (e.g., from sector bounds on the kinematics) instead of set after simulation, the safety certificate would become a true nonlinear guarantee rather than a linearized one with a posteriori validation.
- The same LMI machinery could be applied to other nonlinear systems whose nonlinearity can be bounded by a norm over the operating region, provided the bound is certified over the entire invariant set.
- A testable extension is to check whether the smooth mixing law with 0 < alpha < 1 preserves invariance; the paper proves invariance only for the pure backup law at the boundary, so the blended controller's guarantee is an open point.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The manuscript proposes an LMI-based synthesis of ellipsoidal robust controlled invariant (RCI) sets for linear systems with additive bounded disturbances, together with a safety filter that smoothly blends a nominal controller with an LMI-derived backup controller as the state approaches the boundary of the invariant ellipsoid. The authors state in the abstract that the framework extends to nonlinear quaternion attitude dynamics through exact closed-form sector bounds on the quaternion kinematic nonlinearity embedded via the S-procedure, and they present quadrotor simulations under three scenarios. In the full text, however, the nonlinear extension is confined to Remark 9, where linearization error is treated as an additional bounded disturbance with an asserted bound Δ_max; no quaternion sector bound is derived, and the quadrotor model is written in Euler angles, not quaternions. The linear LMI theory in Sections III–IV is mostly standard and appears correct, but the advertised nonlinear safety guarantee is not established.
Significance. If the nonlinear guarantee claimed in the abstract were rigorously established, the paper would offer a computationally attractive alternative to Hamilton–Jacobi and control-barrier-function methods for high-dimensional attitude safety filtering. The linear core of the paper—Theorem 2 and the constraint LMIs—is correct and well known, and the authors provide a code repository, which is a positive feature. However, the paper's headline contribution is the nonlinear extension, and that contribution is not delivered: the promised sector bounds are absent, and the numerical bound on the linearization error is calibrated post hoc. As a result, the safety certificate for the quadrotor application does not follow from the formal machinery. The current significance is therefore limited to a re-derivation of standard linear ellipsoidal RCI synthesis with an illustrative, but not verified, nonlinear application.
major comments (4)
- [Remark 9 and Section V-B] The central nonlinear guarantee is unsupported. Remark 9 asserts that the linearization error Δ satisfies ∥Δ∥≤Δ_max, but no derivation, formula, or verifiable bound is provided. Section V-B then states: 'We set Δ_max=0.65 in Remark 9 to account for linearization errors using an iterative method. The actual linearization error within the computed RCI set is 0.62, validating our choice of bound.' This is post-hoc calibration: the bound is chosen after observing the quantity it is supposed to bound. Since the Nagumo condition (11) depends on Δ, the invariance certificate for the nonlinear quadrotor fails if ∥Δ∥>0.65 at any reachable state. The abstract's guarantee is therefore not established.
- [Title/Abstract and Section V-A] The paper's title and abstract promise 'exact closed-form sector bounds on the quaternion kinematic nonlinearity' and an S-procedure embedding of these bounds. No quaternion state, quaternion kinematics, or sector bound appears anywhere in the manuscript. The numerical model in Section V-A uses Euler angles η=(φ,θ,ψ) and the kinematic matrix W(η), not quaternions. The claimed quaternion-based synthesis is missing entirely; this is a load-bearing discrepancy between the advertised contribution and the actual content.
- [Section IV-B, Eqs. (40)-(41)] The mixing law is described as 'smooth,' but the implemented ramp function (41) is discontinuous in derivative at h_min and h_max and is discontinuous in value at h_max if h_max<1. More importantly, the paper does not provide a forward-invariance argument for the blended control when h_min<h(x)<h_max. While the boundary argument 'α(x)=1 at h(x)=1' is sufficient in principle to prevent exit from E(P*), the manuscript does not articulate that the invariance of E(P*) is unaffected by the blended control in the interior; it merely asserts the filter works. This gap should be closed by an explicit statement or a short proof.
- [Problem 2] The optimization is posed as maximizing trace(Q), and the abstract calls the result a 'maximal ellipsoidal RCI set.' Maximizing trace(Q) is a heuristic surrogate for volume and does not yield a maximal ellipsoid in any formal set-inclusion sense. Moreover, λ is treated as a fixed parameter rather than optimized, so the claim of maximality is not justified. This is an overstatement that should be corrected in a revision.
minor comments (5)
- [General] The manuscript has no equation numbers, which makes it difficult to refer to specific results; please add them.
- [Figures 2-4] The figure labels are garbled: 'Constraint ?3', '#10!4', and '=1 =2' appear instead of proper axis labels and legends. These figures need to be regenerated with correct LaTeX rendering.
- [Section V-A] The caption of Figure 1 says the safety filter modifies τ_d, but the block diagram output is labeled τ_s; please make notation consistent.
- [References] Reference [19] is missing author and version information, and reference [20] is incomplete. Please provide full bibliographic details.
- [Remark 8] The statement that the convex combination satisfies input constraints is only valid if the input constraint set is convex; here it is a box, so the statement is true, but this assumption should be stated.
Circularity Check
Nonlinear safety guarantee reduces to a post-hoc calibrated linearization-error bound; the advertised exact quaternion sector-bound derivation is absent.
specific steps
-
fitted input called prediction
[Section V-B (Safety Filter Implementation), after Remark 9; with Remark 9 in Section III-B.]
"We set Δ_max = 0.65 in Remark 9 to account for linearization errors using an iterative method. The actual linearization error within the computed RCI set is 0.62, validating our choice of bound."
Remark 9 extends the linear LMI certificate to the nonlinear system only by assuming ∥Δ∥ ≤ Δ_max and absorbing Δ into the disturbance matrix E_aug = √2[E_d, Δ_max I_n]. Thus Δ_max is an input to the LMI (Problem 2/Theorem 2). Section V-B chooses Δ_max=0.65 after solving the LMI and then verifies the bound on the very RCI set produced using that bound. The 'validation' is therefore self-referential: the nonlinear safety guarantee is not derived from a prior sector bound, as the abstract promises, but is calibrated to the output of the computation it is supposed to certify. If the true error exceeded Δ_max on a reachable state, Nagumo's condition (11) would fail and the certificate would disappear; no independent bound is supplied.
full rationale
The linear LMI core (Theorem 2, Propositions 2-3) is self-contained and not circular: it derives an ellipsoidal RCI condition and constraints from standard S-procedure arguments. The circularity is confined to the nonlinear extension, which is the paper's advertised centerpiece. The abstract claims 'exact closed-form sector bounds on the quaternion kinematic nonlinearity analytically embedded into the LMI via the S-procedure,' but the full text contains no such sector-bound derivation. Instead, Remark 9 asserts without proof that the linearization error can be bounded by Δ_max, and Section V-B sets Δ_max=0.65 'using an iterative method' after observing the actual error within the computed RCI set is 0.62. That is post-hoc model calibration, not a formal certificate. The safety claim for the quadrotor therefore depends on a bound fitted to the output of the very LMI that used the bound, so the nonlinear guarantee is partial-circular even though the linear construction is sound.
Axiom & Free-Parameter Ledger
free parameters (4)
- lambda (LMI multiplier) =
not stated (fixed scalar lambda > 0)
- Delta_max (linearization error bound) =
0.65 (chosen after computing actual error 0.62)
- h_min, h_max (mixing-law thresholds) =
h_min = 0.1, h_max = 0.9
- d_max (disturbance bound) =
1e-5 N.m
axioms (5)
- standard math S-procedure (Lemma 1) yields a valid conversion of the invariance condition to LMI (15).
- standard math Nagumo's theorem for differential inclusions (Theorem 1) characterizes robust controlled invariance.
- ad hoc to paper The linearization error satisfies ||Delta|| <= Delta_max = 0.65 over the computed ellipsoid.
- domain assumption The safe set is defined in Euler angles (|phi|, |theta| <= 40 deg) and the linearized model (60) is valid over that region.
- ad hoc to paper The blended control (1-alpha)u_nom + alpha K x keeps trajectories inside E(P) for 0 < alpha < 1.
Cite this review
Pith. "Pith review of Robust Safety Filter Synthesis for Quaternion Attitude Dynamics via LMI-Based Ellipsoidal Invariant Sets." pith.science (2026). https://pith.science/paper/PUZDCB4T
@misc{pith2026251022790,
author = {Pith},
title = {Pith review of: Robust Safety Filter Synthesis for Quaternion Attitude Dynamics via LMI-Based Ellipsoidal Invariant Sets},
year = {2026},
howpublished = {\url{https://pith.science/paper/PUZDCB4T}},
note = {Machine review of arXiv:2510.22790}
}
read the original abstract
We present a safety filter to guarantee constraint satisfaction on the rotation angle in the presence of disturbances. An LMI-based framework simultaneously synthesizes a maximal ellipsoidal robust controlled invariant (RCI) set and its associated state-feedback backup control law by solving a single convex semidefinite program, subject to state and input constraints. To extend this framework to nonlinear quaternion attitude dynamics, we derive exact closed-form sector bounds on the quaternion kinematic nonlinearity and analytically embed them into the LMI via the S-procedure. A smooth mixing law intervenes only as the state approaches the RCI boundary, preserving nominal performance during safe operation. This work is motivated by hierarchical aerial control architectures, where outer-loop commands can generate attitude references that drive the inner-loop attitude state unstable, a cascade failure mode that endangers the entire system. Quadrotor simulations with hierarchical controller structures under bounded disturbances confirm constraint satisfaction across three scenarios specifically designed to stress-test the cascade failure mode: set-point tracking with small initial errors, set-point tracking with large initial position errors that saturate the outer loop, and high-frequency circular trajectory following that persistently excites the inner-loop attitude dynamics.
Figures
Reference graph
Works this paper leans on
-
[1]
K. P. Wabersich, A. J. Taylor, J. J. Choi, K. Sreenath, C. J. Tomlin, A. D. Ames, and M. N. Zeilinger, “Data-Driven Safety Filters: Hamilton-Jacobi Reachability, Control Barrier Functions, and Predictive Methods for Uncertain Systems,”IEEE Control Systems, vol. 43, no. 5, pp. 137–177, Oct. 2023. [Online]. Available: https://ieeexplore.ieee.org/document/10266799/
arXiv 2023
-
[2]
The Safety Filter: A Unified View of Safety-Critical Control in Autonomous Systems,
K.-C. Hsu, H. Hu, and J. F. Fisac, “The Safety Filter: A Unified View of Safety-Critical Control in Autonomous Systems,” Sep. 2023, arXiv:2309.05837 [eess]. [Online]. Available: http://arxiv.org/abs/2309. 05837
Pith/arXiv arXiv 2023
-
[3]
Hamilton-Jacobi Reachability: A Brief Overview and Recent Advances,
S. Bansal, M. Chen, S. Herbert, and C. J. Tomlin, “Hamilton-Jacobi Reachability: A Brief Overview and Recent Advances,” Sep. 2017, arXiv:1709.07523 [cs]. [Online]. Available: http://arxiv.org/abs/1709. 07523
Pith/arXiv arXiv 2017
-
[4]
Control Barrier Functions: Theory and Applications,
A. D. Ames, S. Coogan, M. Egerstedt, G. Notomista, K. Sreenath, and P. Tabuada, “Control Barrier Functions: Theory and Applications,” Mar. 2019, arXiv:1903.11199 [cs]. [Online]. Available: http://arxiv.org/ abs/1903.11199
Pith/arXiv arXiv 2019
-
[5]
Robust Control Barrier-Value Functions for Safety-Critical Control,
J. J. Choi, D. Lee, K. Sreenath, C. J. Tomlin, and S. L. Herbert, “Robust Control Barrier-Value Functions for Safety-Critical Control,” Oct. 2021, arXiv:2104.02808 [eess]. [Online]. Available: http://arxiv.org/abs/2104.02808
Pith/arXiv arXiv 2021
-
[6]
Input-to-State Safety With Control Barrier Functions,
S. Kolathaya and A. D. Ames, “Input-to-State Safety With Control Barrier Functions,”IEEE Control Systems Letters, vol. 3, no. 1, pp. 108–113, Jan. 2019. [Online]. Available: https://ieeexplore.ieee.org/ document/8405547/
arXiv 2019
-
[7]
Control Barrier Functions and Input-to-State Safety with Application to Automated Vehicles,
A. Alan, A. J. Taylor, C. R. He, A. D. Ames, and G. Orosz, “Control Barrier Functions and Input-to-State Safety with Application to Automated Vehicles,” Jun. 2022, arXiv:2206.03568 [eess]. [Online]. Available: http://arxiv.org/abs/2206.03568
Pith/arXiv arXiv 2022
-
[8]
F. Blanchini and S. Miani,Set-Theoretic Methods in Control, ser. Systems & Control: Foundations & Applications. Cham: Springer International Publishing, 2015. [Online]. Available: https: //link.springer.com/10.1007/978-3-319-17933-9
-
[9]
Ellipsoidal set- theoretic control synthesis,
P. Usoro, F. Schweppe, D. Wormley, and L. Gould, “Ellipsoidal set- theoretic control synthesis,”Journal of Dynamic Systems, Measurement, and Control, vol. 104, no. 4, pp. 331–336, 1982
1982
-
[10]
A predictive safety filter for learning-based control of constrained nonlinear dynamical systems,
K. P. Wabersich and M. N. Zeilinger, “A predictive safety filter for learning-based control of constrained nonlinear dynamical systems,” May 2021, arXiv:1812.05506 [cs]. [Online]. Available: http://arxiv.org/abs/1812.05506
Pith/arXiv arXiv 2021
-
[11]
Backup Control Barrier Functions: Formulation and Comparative Study,
Y . Chen, M. Jankovic, M. Santillo, and A. D. Ames, “Backup Control Barrier Functions: Formulation and Comparative Study,” Apr. 2021, arXiv:2104.11332 [eess]. [Online]. Available: http://arxiv.org/abs/2104. 11332
Pith/arXiv arXiv 2021
-
[12]
Onboard Safety Guarantees for Racing Drones: High-Speed Geofencing With Control Barrier Functions,
A. Singletary, A. Swann, Y . Chen, and A. D. Ames, “Onboard Safety Guarantees for Racing Drones: High-Speed Geofencing With Control Barrier Functions,”IEEE Robotics and Automation Letters, vol. 7, no. 2, pp. 2897–2904, Apr. 2022. [Online]. Available: https://ieeexplore.ieee.org/document/9691815/
arXiv 2022
-
[13]
On reachability and minimum cost optimal control,
J. Lygeros, “On reachability and minimum cost optimal control,”Auto- matica, vol. 40, no. 6, pp. 917–927, 2004. 0 1 2 3 4 5 Time(s) 0 0.5 1 1.5 2 Position(m) Setpoint x y 0 1 2 3 4 5 Time(s) -50 0 50 Orientation(deg) Constraint ? 3 0 1 2 3 4 5 Time(s) -1 0 1 Magnitude(N.m) #10!4 =1 =2 w1 w2 0 1 2 3 4 5 Time(s) 0 0.5 1 Value h , Fig. 2. The safety filter d...
2004
-
[14]
Set-valued analysis. modern birkh ¨auser classics,
J.-P. Aubin and H. Frankowska, “Set-valued analysis. modern birkh ¨auser classics,” 2009
2009
-
[15]
Aubin, A
J.-P. Aubin, A. M. Bayen, and P. Saint-Pierre,Viability theory: new directions. Springer Science & Business Media, 2011
2011
-
[16]
S. P. Boyd, L. El Ghaoui, E. Feron, and V . Balakrishnan,Linear matrix inequalities in system and control theory, ser. SIAM studies in applied mathematics. Philadelphia, Pa: SIAM, Society for Industrial and Applied Mathematics, 1994, no. 15
1994
-
[17]
M. V . Khlebnikov, B. T. Polyak, and V . M. Kuntsevich, “Optimization of linear systems subject to bounded exogenous disturbances: The invariant ellipsoid technique,”Automation and Remote Control, vol. 72, no. 11, pp. 2227–2275, Nov. 2011. [Online]. Available: http://link.springer.com/10.1134/S0005117911110026
-
[18]
System identification of the crazyflie 2.0 nano quadrocopter,
J. F ¨orster, “System identification of the crazyflie 2.0 nano quadrocopter,” B.S. thesis, ETH Zurich, 2015
2015
-
[19]
CVX: Matlab software for disciplined convex programming, version 2.0,
I. CVX Research, “CVX: Matlab software for disciplined convex programming, version 2.0,” https://cvxr.com/cvx, Aug. 2012
2012
-
[20]
ApS,MOSEK API for MATLAB 11.0.29, 2025
M. ApS,MOSEK API for MATLAB 11.0.29, 2025. [Online]. Available: https://docs.mosek.com/latest/matlabapi/index.html
2025
discussion (0)
Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.