Pith. sign in

REVIEW 3 major objections 3 minor 23 references

For linear systems under an affine safety constraint, a CBF safety filter renders the origin globally exponentially stable exactly when the filter-active dynamics matrix is Hurwitz, and provokes unbounded trajectories when that matrix has a

Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →

T0 review · deepseek-v4-flash

2026-08-02 17:58 UTC pith:K4MWJYKS

load-bearing objection Solid linear/affine CBF-filter results with a genuinely useful eigenstructure test, but Theorem 7's GES proof has a real gap in how it applies the cited PWA theorem. the 3 major comments →

arxiv 2603.17401 v2 pith:K4MWJYKS submitted 2026-03-18 math.OC

Dynamical Properties of Safety Filters for Linear Systems and Affine Control Barrier Functions

classification math.OC MSC 93D2393D3093C0593C30
keywords control barrier functionssafety filterspiecewise affine systemsglobal exponential stabilityundesired equilibriaunbounded trajectorieslinear systemslinear matrix inequalities
verification ladder T0 review T1 audit T2 compute T3 formal T4 reserved

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The paper proves that the long-term behavior of a control-barrier-function safety filter on a linear system with an affine constraint is controlled by one matrix: the dynamics of the mode in which the filter is active. If this matrix is Hurwitz, the filtered system keeps the origin globally exponentially stable; if it has a positive real eigenvalue, some trajectories escape to infinity. The paper gives an algebraic sign test on the scalar ξ = cᵀA₀⁻¹BG⁻¹Bᵀ(Aᵀ)ʳ⁻¹c that decides whether a spurious equilibrium appears, and ties that sign to the parity of the number of positive real eigenvalues of the active-mode matrix. These results reduce safety-filter design for linear plants to a convex linear matrix inequality problem, so a nominal controller can be chosen to make the filter both safe and stable.

Core claim

The closed loop under the safety filter is piecewise affine: in the safe region it runs the nominal stable dynamics A₀, and in the region where the filter intervenes it runs ẋ = Ãx + b̃. The central claim is that the stability and equilibria of this hybrid system are governed by the eigenstructure of Ã, which is a rank-one modification of A₀. Proposition 4 shows that an undesired equilibrium exists exactly when ξ := cᵀA₀⁻¹BG⁻¹Bᵀ(Aᵀ)ʳ⁻¹c is positive; Proposition 5 recasts this as 'the number of positive real eigenvalues of à is odd.' Theorem 7 states that if à is Hurwitz, the origin is globally exponentially stable, established via a common quadratic Lyapunov function for A₀ and Ã. Propositio

What carries the argument

The piecewise-affine closed loop (5) and the rank-one structure of the filter-active matrix à = A₀ + v₁v₂ᵀ. Because the safety filter modifies the nominal controller by at most a rank-one term, the matrix determinant lemma yields the full eigenstructure of Ã, the Sherman–Morrison formula gives its inverse, and the single scalar ξ — essentially the DC gain of the transfer function from the filtered output back through the safety constraint — determines whether a second equilibrium exists. A common quadratic Lyapunov function between A₀ and à is the bridge from eigenstructure to global exponential stability.

Load-bearing premise

The global-exponential-stability proof relies on a quoted theorem about convergent piecewise-affine systems, applied to a system whose filter-active mode contains a nonzero affine offset; the paper does not verify that the theorem's hypotheses still hold when the two modes do not share a common equilibrium.

What would settle it

Simulate the piecewise-affine system (5) for randomly generated instances satisfying Assumptions 1–3 with a Hurwitz à (e.g., obtained from the LMIs of Lemma 9), sweeping the affine offset b̃ and the switching hyperplane η(x)=0. If any bounded initial condition produces a trajectory that fails to converge to the origin — a limit cycle, a second attractor, or a non-exponentially decaying solution — then the global-exponential-stability conclusion of Theorem 7 is false. A targeted check is to test whether the hypotheses of the convergence theorem used in the proof are satisfied when b̃ ≠ 0; if th

Watch this falsifier — get emailed when new claim-graph text bears on it.

If this is right

  • If à is Hurwitz, adding a CBF safety filter to a stabilizing linear controller preserves global exponential stability, so safety need not be bought at the price of stability.
  • If à has any positive real eigenvalue, the filtered system is guaranteed to have unbounded trajectories, giving a simple spectral test to reject bad filter designs.
  • A spurious equilibrium appears if and only if the number of positive real eigenvalues of à is odd; equivalently, checking the sign of ξ = cᵀA₀⁻¹BG⁻¹Bᵀ(Aᵀ)ʳ⁻¹c is enough to detect it.
  • For single-input systems, the stability verdict is independent of the nominal gain K, the class-K slopes αᵢ, and the weight G — only the plant and constraint matter.
  • The design problem 'choose K so that the filtered system is globally exponentially stable' is a pair of LMIs, so standard convex-optimization tools can certify and synthesize safe-stable controllers.

Where Pith is reading between the lines

These are editorial extensions of the paper, not claims the author makes directly.

  • If the cited convergence theorem is verified to cover affine offsets, the same common-Lyapunov argument would likely prove global exponential stability for a larger class of piecewise-affine safety filters, including those with multiple affine constraints — a direct but unproven extension.
  • The ξ sign test suggests a numerically cheap way to detect filter-induced equilibria in practice: evaluate one transfer-function quantity at zero rather than solving for all equilibria of the hybrid system.
  • The revealed gap for complex eigenvalues with positive real part may be resolved by a refined condition involving how the affine offset projects onto the unstable subspace; the simulations hint that both global exponential stability and unboundedness are possible, so a sharper criterion would complete the picture.
  • For nonlinear systems with locally linear structure, the same rank-one analysis could give a local version of the equilibrium test, indicating whether a CBF filter can create spurious fixed points near an operating point.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, simulated authors' rebuttal, and a circularity audit.

Referee Report

3 major / 3 minor

Summary. The paper studies CBF-based safety filters for linear systems with affine safety constraints. By exploiting the closed-form QP solution, it writes the filtered closed loop as the piecewise-affine system (5). The main claims are: (i) undesired equilibria exist exactly when an algebraic quantity ξ has positive sign (with a degenerate infinite-equilibrium case when ξ=0); (ii) their existence is equivalent to an odd number of positive real eigenvalues of the active-mode matrix \tilde A; (iii) if \tilde A is Hurwitz, the origin is globally exponentially stable; (iv) if \tilde A has a positive real eigenvalue, unbounded trajectories exist; and (v) the results are interpretable via invariant zeros and lead to an LMI-based design. A simulation on aircraft roll-yaw dynamics is also provided.

Significance. If the results are correct, the paper gives simple, checkable algebraic conditions for the three qualitative behaviors — spurious equilibria, unbounded trajectories, and global exponential stability — of a CBF-filtered linear system. This is a useful step toward principled design of safety filters. The paper's strengths are its explicit piecewise-affine closed form, the eigenstructure characterization in Lemma 3, the transparent algebraic sign tests in Propositions 4 and 5, the LMI design of Lemma 9, and the illustrative simulations. However, two load-bearing issues — the proof of the main GES theorem and the degenerate case of Proposition 4 — currently prevent the results from being accepted as stated.

major comments (3)
  1. [Section IV-A, Theorem 7 proof] The proof applies [21, Thm. 1] after establishing a CQLF only for the homogeneous modes \dot x=A_0 x and \dot x=\tilde A x (Lemma 6). The closed loop (5) in R^- is \dot x=\tilde A x+\tilde b with \tilde b=\alpha d v_1, generally nonzero. For V(x)=x^T P x, along this mode \dot V=x^T(P\tilde A+\tilde A^T P)x+2x^T P\tilde b, and the linear term is indefinite; a homogeneous CQLF does not directly prove convergence for the affine subsystem. The proof neither quotes [21, Thm. 1] nor verifies that its hypotheses cover affine offsets (there is no common equilibrium in general: when \xi<0 the unsafe-mode equilibrium lies outside R^-). This is the main stability guarantee, so the argument must be repaired, e.g., by stating the theorem or by giving a direct Lyapunov argument that exploits \eta(0)=\alpha d>0, which makes R^- bounded away from the origin.
  2. [Section III, Proposition 4] The third case of Proposition 4, claiming that \xi=0 implies an infinite set of equilibria, is false as stated. Counterexample: n=2, A0=[[-1,2],[-2,-1]], B=[1;0], c=[2;1], G=1, K=0, \alpha=1, d=0.5. Then relative degree r=1, A0 is Hurwitz, and \xi=c^T A0^{-1}B B^T c=0. Using (5) gives \tilde A=[[0,0],[-2,-1]] and \tilde b=[-0.25;0], so \tilde A x=-\tilde b has no solution and the only equilibrium is the origin. A singular \tilde A does not imply \tilde b\in range(\tilde A); the proof's inference 'therefore infinite' is not valid. The statement and proof need correction.
  3. [Section IV-B, Proposition 10 proof] The proof relies on [13, Lemma 4.1] for the fact \tilde p\in\partial C_{r-1}. This lemma is from a preprint by the same first author and is neither stated nor proved in the manuscript. Since the construction of the diverging trajectories on \partial C_{r-1} depends on this fact, the authors should either provide a self-contained proof or state the lemma explicitly and verify its hypotheses. This is a load-bearing step in the unboundedness result, not merely a citation-policy issue.
minor comments (3)
  1. [Section III, Proposition 5 proof] The sentence 'there must be n−r−1 zero-pole cancellations in (11)' appears to be a miscount. To obtain H(λ)=θ/λ^r+O(λ^{−r−1}) from a rational function with numerator degree n−1 and denominator degree n, the required number of cancellations is r−1, not n−r−1. Please correct this and re-check the subsequent sign argument.
  2. [Section V] The aircraft example uses the affine system (13) with an external command y_cmd. The statement that the results 'carry over analogously' is not justified by a formal reduction. A short explanation of the modifications needed for affine dynamics and a nonzero target would improve rigor.
  3. [Section II, closed-form definitions] The definitions of θ and v1 are typeset in a way that invites confusion (the denominator appears as θ^2 but the correct closed form from the QP projection has division by θ). Please display these definitions unambiguously, e.g., θ=||B^T(A^T)^{r−1}c||^2_{G^{-1}} and v1=−B G^{-1}B^T(A^T)^{r−1}c/θ, and ensure that all subsequent uses of θ match.

Circularity Check

0 steps flagged

No significant circularity; the derivation is algebraic and self-contained, and the self-citations are non-load-bearing.

full rationale

The paper's central chain—closed-loop form (5), eigenstructure of \tilde A (Lemma 3), equilibrium sign test (Prop. 4), parity characterization (Prop. 5), CQLF existence (Lemma 6), and GES/unboundedness conclusions (Thm. 7, Prop. 10)—is derived in-text from the HOCBF QP and linear algebra, not from fitting or from renaming an assumed conclusion. The closed-form (5) is attributed to [7] and [13], both with overlapping authors, but it is a parameter-free algebraic expression of the QP solution and is not used as a substitute for the paper's claims. The only self-cited fact used in a proof, '\tilde p \in \partial C_{r-1} (cf. [13, Lemma 4.1])' in Prop. 10, is not load-bearing: the unbounded trajectory is obtained by choosing the half-line x(t)=\tilde p \pm e^{\lambda t}v that enters R^-, where the dynamics are \dot x=\tilde A x+\tilde b; this requires only \tilde A \tilde p+\tilde b=0 and v_2^\top v\neq 0, not membership in \partial C_{r-1}. No fitted parameter is relabeled as a prediction, no uniqueness theorem is imported to force a choice, and no ansatz is smuggled in through citation. The possible gap in Thm. 7—invoking [21, Thm. 1] for the affine mode after checking a CQLF only for the homogeneous modes A0 and \tilde A—is a question of whether the external theorem's hypotheses cover the offset \tilde b; it is an omitted verification, not a circular reduction, so it does not affect the circularity score.

Axiom & Free-Parameter Ledger

3 free parameters · 10 axioms · 0 invented entities

The central claims rest on standard assumptions in the CBF literature: linear dynamics, affine barrier, r=relative degree, d>0, (A,B) stabilizable, and a nominal K making A0 Hurwitz. The main nonstandard reliance is on [13, Lemma 4.1] (p̃∈∂C_{r-1}) and on the external PWA convergence theorem [21, Thm 1]; the latter's hypotheses are not verified. No data-fitted parameters or invented entities appear; α_i, G, and K are design variables, not fitted constants.

free parameters (3)
  • CBF/HOCBF slopes α_i (i=1..r)
    The analysis assumes linear class-K slopes α_i>0. Results (sign of ξ, Hurwitz of \tilde A) depend on α through the product αd in the filter's affine term; not fitted to data.
  • QP weighting matrix G
    G≻0 defines the norm in the safety-filter QP. It enters v1, θ, ξ, and the invariant zeros; a design choice, not estimated.
  • Nominal feedback gain K
    K is chosen so that A0=A-BK is Hurwitz; it determines v2, \tilde A, and the conditions. LMIs in Lemma 9 are solvability conditions on K.
axioms (10)
  • domain assumption Linear dynamics and affine constraint (Assumption 1): f(x)=Ax, g(x)=B, h(x)=c^T x+d.
    Central setup of the paper; all subsequent results are restricted to this class.
  • domain assumption Origin in interior of safe set (Assumption 2): d>0.
    Ensures η(0)>0 and that the origin is an equilibrium; used throughout.
  • domain assumption Stabilizability of (A,B) and existence of K with A0 Hurwitz (Assumption 3 and Section II).
    The nominal controller must stabilize the origin for the GES question to be meaningful.
  • domain assumption h has relative degree r: c^T A^i B=0 for i<r-1 and c^T A^{r-1} B≠0.
    Required for the HOCBF construction and for the closed-form safety filter to be valid.
  • domain assumption HOCBF construction (Thm 1 from [15]) with linear class-K functions.
    The barrier condition (4) and the definition of R+ / R- rest on this external theorem.
  • domain assumption u* is locally Lipschitz, ensuring unique solutions and forward invariance of \bar C (via [16, Thm 2]).
    Needed for the closed-loop system (5) to be well posed.
  • standard math Matrix determinant lemma and Sherman-Morrison formula [18].
    Used in Lemma 3, Prop. 4, and Lemma 6 for rank-one updates.
  • standard math Shorten et al. Lemma 2.3 [20] characterizing common quadratic Lyapunov functions for rank-one perturbations.
    Used in Lemma 6 to prove existence of a CQLF when \tilde A is Hurwitz.
  • standard math Pavlov et al. Theorem 1 [21] for convergent piecewise affine systems.
    Used in Theorem 7 to convert the CQLF into global exponential convergence; its hypotheses are not verified in the affine-offset case.
  • domain assumption [13, Lemma 4.1]: p̃ ∈ ∂C_{r-1}.
    Relied on in Prop. 10 to place the unbounded curves on the boundary of the safe set; this is a self-cited result from a preprint by the first author, not proved in this paper.

pith-pipeline@v1.3.0-alltime-deepseek · 11132 in / 25187 out tokens · 215851 ms · 2026-08-02T17:58:05.801060+00:00 · methodology

0 comments
read the original abstract

This letter studies the dynamical properties of safety filters designed based on Control Barrier Functions (CBF). This mechanism, which is popular in safety-critical applications, takes a nominal controller and minimally modifies it to render it safe. Although CBF-based safety filters make the closed-loop system safe, characterizing their additional dynamical properties, such as stability, boundedness, or existence of spurious equilibria, remains a challenging problem. Here, we address this problem for the case of linear systems and an affine CBF constraint. We provide conditions under which the closed-loop system presents undesired equilibria, unbounded trajectories, or the origin is globally exponentially stable.

Figures

Figures reproduced from arXiv: 2603.17401 by Aaron D. Ames, Pol Mestres, Shima Sadat Mousavi.

Figure 1
Figure 1. Figure 1: Overview of the paper. The stable linear nominal dynamics are modified through a CBF-based safety filter with an affine constraint. De￾pending on the stability of the active mode, the resulting closed-loop system is either globally exponentially stable or exhibits unbounded trajectories. control [14], where control designs are implemented to linearized models of the aircraft’s full dynamics. The contributi… view at source ↗
Figure 2
Figure 2. Figure 2: Trajectories for two different systems with n = 3, m = 1, and with A˜ having a pair of complex conjugate eigenvalues with positive real part. (Top) The origin is GES. A = [0.65, 1.18, 0.05; 0.38, 0.93, −0.7; 1.52, 1.12, 0.22], B = [−1.24; 1.93; −0.63], K = [4.57, 6.23, −0.01], c = [−0.1; 1.32; 0.67], d = 0.71. (Bottom) Unbounded trajectories. A = [0.45, −1.47, 1.48; 0.47, −0.12, −0.57; 0.99, −0.11, −2.5], … view at source ↗
Figure 3
Figure 3. Figure 3: Evolution of ps for the filtered (bottom) and nominal (top) systems. [β, ps, rs] ⊤, where β is the sideslip angle (in rad), and ps, rs are roll and yaw rates (in rad/s). The control inputs of the system are aileron and rudder deflections δa and δr (rad). The plant dynamics are x˙ p = Apxp + Bpu, with Ap= " −0.1179 0.0009 −1.000 −7.0113 −1.4492 0.2206 6.3035 0.0651 −0.4117# , Bp= " 0 0.0153 −7.9662 2.6875 0… view at source ↗

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Reference graph

Works this paper leans on

23 extracted references · 3 linked inside Pith

  1. [1]

    Control barrier function based quadratic programs for safety critical systems,

    A. D. Ames, X. Xu, J. W. Grizzle, and P. Tabuada, “Control barrier function based quadratic programs for safety critical systems,”IEEE Trans. Automat. Control, vol. 62, no. 8, pp. 3861–3876, 2017

  2. [2]

    J. B. Rawlings, D. Q. Mayne, and M. M. Diehl,Model Predictive Control: Theory, Computation, and Design. Nob Hill Publishing, 2017

  3. [3]

    Hamilton-Jacobi Reachability: A Brief Overview and Recent Advances,

    S. Bansal, M. Chen, S. Herbert, and C. J. Tomlin, “Hamilton-Jacobi Reachability: A Brief Overview and Recent Advances,” inIEEE Conf. Decis. Control, Melbourne, Australia, Dec. 2017, pp. 2242–2253

  4. [4]

    Reference and command governors for systems with constraints: a survey on theory and applications,

    E. Garone, S. D. Cairano, and I. Kolmanovsky, “Reference and command governors for systems with constraints: a survey on theory and applications,”Automatica, vol. 75, pp. 306–328, 2017

  5. [5]

    Control barrier functions: theory and applications,

    A. D. Ames, S. Coogan, M. Egerstedt, G. Notomista, K. Sreenath, and P. Tabuada, “Control barrier functions: theory and applications,” inEur. Control Conf., Naples, Italy, 2019, pp. 3420–3431

  6. [6]

    On the undesired equilibria induced by control barrier function based quadratic programs,

    X. Tan and D. V . Dimarogonas, “On the undesired equilibria induced by control barrier function based quadratic programs,”Automatica, vol. 159, p. 111359, 2024

  7. [7]

    Explicit control barrier function-based safety filters and their resource-aware computation,

    P. Mestres, S. S. Mousavi, P. Ong, L. Yang, E. Das, J. W. Burdick, and A. D. Ames, “Explicit control barrier function-based safety filters and their resource-aware computation,” 2025, available at https://arxiv.org/pdf/2512.10118

  8. [8]

    From vertices to convex hulls: Certifying set-wise compatibility for cbf constraints,

    S. S. Mousavi, X. Tan, and A. D. Ames, “From vertices to convex hulls: Certifying set-wise compatibility for cbf constraints,”IEEE Control Syst. Lett., vol. 9, pp. 3011–3016, 2025

  9. [9]

    Control barrier functions based quadratic programming with application to adaptive cruise control,

    A. D. Ames, J. W. Grizzle, and P. Tabuada, “Control barrier functions based quadratic programming with application to adaptive cruise control,” inIEEE Conf. Decis. Control, 2014, pp. 6271–6278

  10. [10]

    Control barrier function based quadratic programs with applications to bipedal robot walking,

    S. Hsu, X. Xu, and A. D. Ames, “Control barrier function based quadratic programs with applications to bipedal robot walking,” in Amer. Control Conf., Chicago, USA, July 2015

  11. [11]

    How to train your neural control barrier function: Learning safety filters for complex input-constrained systems,

    O. So, Z. Serlin, M. Mann, J. Gonzales, K. Rutledge, N. Roy, and C. Fan, “How to train your neural control barrier function: Learning safety filters for complex input-constrained systems,” inIEEE Int. Conf. Robot. Autom., 2024, pp. 11 532–11 539

  12. [12]

    Control barrier function- based quadratic programs introduce undesirable asymptotically stable equilibria,

    M. F. Reis, A. P. Aguilar, and P. Tabuada, “Control barrier function- based quadratic programs introduce undesirable asymptotically stable equilibria,”IEEE Control Syst. Lett., vol. 5, no. 2, pp. 731–736, 2021

  13. [13]

    Control barrier function-based safety filters: characterization of undesired equilib- ria, unbounded trajectories, and limit cycles,

    P. Mestres, Y . Chen, E. Dall’Anese, and J. Cort ´es, “Control barrier function-based safety filters: characterization of undesired equilib- ria, unbounded trajectories, and limit cycles,” 2025, available at https://arxiv.org/pdf/2501.09289

  14. [14]

    Lavretsky and K

    E. Lavretsky and K. A. Wise,Robust and Adaptive Control with Aerospace Applications. Springer, 2024

  15. [15]

    High-order control barrier functions,

    W. Xiao and C. Belta, “High-order control barrier functions,”IEEE Trans. Automat. Control, vol. 67, no. 7, pp. 3655–3662, 2022

  16. [16]

    Robustness of con- trol barrier functions for safety critical control,

    X. Xu, P. Tabuada, J. W. Grizzle, and A. D. Ames, “Robustness of con- trol barrier functions for safety critical control,”IFAC-PapersOnLine, vol. 48, no. 27, pp. 54–61, 2015

  17. [17]

    Regularity properties of optimization-based controllers,

    P. Mestres, A. Allibhoy, and J. Cort ´es, “Regularity properties of optimization-based controllers,”Eur. J. Control, vol. 81, p. 101098, 2025

  18. [18]

    D. S. Bernstein,Matrix Mathematics, 2nd ed. Princeton University Press, 2009

  19. [19]

    R. A. Horn and C. R. Johnson,Matrix Analysis. New York, USA: Cambridge University Press, 2012

  20. [20]

    A unifying framework for the SISO circle criterion and other quadratic stability criteria,

    R. N. Shorten, O. Mason, F. O’Cairbre, and P. Curran, “A unifying framework for the SISO circle criterion and other quadratic stability criteria,”Int. J. Control, vol. 77, no. 1, pp. 1–8, 2004

  21. [21]

    Convergent piecewise affine systems: analysis and design part I continuous case,

    A. Pavlov, N. van de Wouw, and H. Nijmeijer, “Convergent piecewise affine systems: analysis and design part I continuous case,” inIEEE Conf. Decis. Control, 2005, pp. 5391–5396

  22. [22]

    S. Boyd, L. E. Ghaoui, E. Feron, and V . Balakrishnan,Linear Matrix Inequalities in System and Control Theory, ser. Studies in Applied Mathematics. Philadelphia, Pennsylvania: SIAM, 1994, vol. 15

  23. [23]

    When are safety filters safe? on minimum phase conditions of control barrier functions,

    J. J. Choi, C. J. Tomlin, S. Sastry, and K. Sreenath, “When are safety filters safe? on minimum phase conditions of control barrier functions,” arXiv:2508.07684, 2025