{"id":"d619fb0c-772d-417f-bb72-e70f79be9a55","arxiv_id":"2502.01094","paper_version":1,"verdict":"REJECT","confidence":"HIGH","novelty_score":6.0,"correctness_risk":"high","formal_verification":"none","parameter_count":6,"one_line_summary":"A two-trajectory data-driven method builds a reduced-order model and a simulation function that certifies output closeness for unknown linear control systems.","lead":"These authors construct reduced-order models of unknown linear control systems directly from two measured trajectories, together with a formal closeness certificate called a simulation function. If the certificate conditions hold, a controller can be designed on the small model and refined back to the large system with guaranteed safety or reachability properties.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Lemma 3.2's data-based representation (3.4) is only equivalent to the true closed-loop dynamics if F = U0,TQ has full row rank; this condition is never stated, so Theorem 3.4 may certify closeness to a different system.","rationale":"The reader's weakest assumption identifies exactly the same load-bearing concern: Lemma 3.2 silently replaces the true input matrix B with M(U0,TQ)^\\dagger, which is valid only if U0,TQ has full row rank. This is the step that connects the unknown system to the data-driven simulation function. I agree with the reader that this condition is never stated and that without it the certificate in Theorem 3.4 may apply to a different closed-loop system. The issue is concrete and falsifiable: a rank-deficient F makes the data-based representation (3.4) unequal to the true dynamics, so the Lie derivative inequality can be certified for the wrong system. I also note a second, smaller gap in the proof: the equality Q = HP is asserted from X0,THP = I and X0,TQ = I, which only implies HP - Q is in the nullspace of X0,T; this is repairable because the algorithm explicitly chooses Q = HP, but it is another sign that the theorem's hypotheses are not stated carefully enough. The proposed method is interesting and the benchmarks are suggestive, but the formal guarantee, which is the paper's central claim, is not established as written. The reader's REJECT verdict therefore stands without modification.","tokens_in":18613,"tokens_out":14051,"duration_ms":155145,"concrete_test":"Take a known ct-LCS with n = 3 and m = 2. Generate a first trajectory whose input matrix U0,T has the second row identically zero, while choosing the initial condition and first input so that X0,T is full row rank; collect the zero-input second trajectory from the same initial condition. This satisfies every hypothesis stated before Theorem 3.4. Run Algorithm 1 to obtain P, Theta, Xi, Psi, and rho. Then simulate the true closed-loop system under the interface input with a nonzero second component and check the Lie derivative inequality. If L V(x, hat x) > -kappa V(x, hat x) + rho ||hat u||^2 holds for the data-based representation (3.4) but fails for the true system, the missing full-row-rank condition on U0,TQ is confirmed.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The load-bearing step is Lemma 3.2's equation (3.4), which Theorem 3.4's proof then uses as the data-based description of the unknown ct-LCS. From M := X1,TQ - \\bar X1,T\\bar Q = B U0,TQ, the paper concludes B = M (U0,TQ)^\\dagger. This conclusion requires F = U0,TQ to have full row rank, i.e., F F^\\dagger = I_m. Otherwise, M F^\\dagger = B F F^\\dagger equals B only on the row space of F. The hypotheses of Lemma 3.2 and Theorem 3.4 impose full-row-rank conditions only on X0,T and \\bar X0,T (see Remark 3.3); no condition on U0,TQ is stated. If F is rank deficient, for example because one input channel is identically zero during data collection, the substitution B = M(U0,TQ)^\\dagger is false. The interface term (\\Xi \\hat x + \\Psi \\hat u) may then have components outside the row space of F, and the true input contribution B(\\Xi \\hat x + \\Psi \\hat u) differs from the term M(U0,TQ)^\\dagger(\\Xi \\hat x + \\Psi \\hat u) used in the Lie derivative. Consequently, the simulation function inequality can hold for the data-based representation while failing for the actual unknown system, so the certified closeness guarantee is not established for the system the paper claims to certify. A related proof gap is that Theorem 3.4 asserts Q = HP from X0,THP = I and X0,TQ = I, which is not implied; the algorithm chooses Q = HP, so that point is repairable, but the missing rank condition is not.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper proposes a data-driven approach to model order reduction for unknown continuous-time linear control systems. From two collected input-state trajectories, it constructs a reduced-order model (ROM) and a quadratic simulation function, and uses the latter to provide a guaranteed bound on the output closeness between the unknown system and the ROM. The main result is Theorem 3.4, which relies on Lemma 3.2 to obtain a data-based closed-loop representation and then formulates LMI conditions from which the simulation function is derived. The paper also gives an algorithm and five numerical benchmarks where the ROM is used for controller synthesis enforcing safety, tracking, or reach-while-avoid specifications.","tokens_in":19021,"tokens_out":11991,"duration_ms":118000,"significance":"If the main theorem were correct, this would be a useful contribution to data-driven control and formal synthesis: it bypasses system identification, uses only two trajectories, and provides a certificate suitable for controller synthesis over unknown linear systems. The paper also has practical strengths: it gives an explicit algorithm, validates the approach on several benchmarks, and correctly invokes the standard simulation-function closeness result in Theorem 2.5. However, the certification statement is not established as written, because Lemma 3.2 omits a necessary rank condition and the proof of Theorem 3.4 uses an unjustified equality Q = HP. These are load-bearing issues for the central claim that the simulation function certifies the actual unknown system.","major_comments":[{"comment":"The derivation of the data-based closed-loop representation (3.4) is only valid if F = U0,T Q has full row rank, or if the interface inputs (Ξ\\hat x + Ψ\\hat u) always lie in the row space of F. From M := X1,T Q − \\bar X1,T \\bar Q = B U0,T Q, the paper concludes B = M(U0,T Q)†, which requires (U0,T Q)(U0,T Q)† = I_m. The hypotheses in Lemma 3.2 and Theorem 3.4 impose full-row-rank conditions only on X0,T and \\bar X0,T (see Remark 3.3); no condition on U0,T Q is stated. If F is rank-deficient, for example because an input channel is identically zero during data collection, then B ≠ M F† on the complement of the row space of F, and the term B(Ξ\\hat x + Ψ\\hat u) in the true dynamics is replaced in (3.4) by M F†(Ξ\\hat x + Ψ\\hat u). The simulation function inequality is then certified for a different closed-loop system, not necessarily for the unknown ct-LCS. The authors should add the rank condition as an explicit assumption and explain how it can be checked from data, or alternatively restrict the interface map so that Ξ\\hat x + Ψ\\hat u lies in R(F⊤).","section":"Lemma 3.2, Eq. (3.4)"},{"comment":"The proof states that 'since X0,T HP = In from (3.8a) and X0,T Q = In from (3.2a), one can conclude that Q = HP'. This implication is false when T > n, because X0,T has a non-trivial right nullspace and two different right inverses Q and HP can both satisfy X0,T Q = X0,T HP = In. The subsequent equality X1,T Q P^{-1} = X1,T H, and therefore the use of LMI (3.8c), depends on Q = HP. While Algorithm 1 sets Q = HP in Step 4, the theorem statement does not include this condition; it should be added explicitly, for example by quantifying over Q = HP or by adding the constraint Q = HP, and the proof should be revised accordingly.","section":"Theorem 3.4, proof after Eq. (3.9)"}],"minor_comments":[{"comment":"The claim that (3.8c) is feasible if and only if (A,B) is stabilizable is not proved, and as stated it is questionable because (3.8c) is a data-dependent LMI whose interpretation in terms of (A,B) relies on the unstated identification Q = HP discussed above. The authors should either prove this equivalence or soften the remark.","section":"Remark 3.5"},{"comment":"The statement that the zero-input trajectory condition 'implies that matrix A of the system should be full rank' is not sufficient; for \\bar X0,T to have full row rank, the pair (A, x0) must be such that the zero-input trajectory spans R^n. The limitation should be rephrased accordingly.","section":"Section 3.2, Limitations"},{"comment":"The proposed choice Ψ = Ψ1Ψ2 for minimizing ρ requires the matrix M^T P M to be invertible; this non-singularity condition is not stated.","section":"Eq. (3.13)"},{"comment":"Fixing \\hat A to be Hurwitz before solving (3.8b) may make (3.8b) infeasible; the authors should either solve for \\hat A and Ξ simultaneously or state the range condition from Lemma 3.7 explicitly.","section":"Algorithm 1, Step 5"},{"comment":"The comparison with [Ion15] and [BBSC23] is not apples-to-apples because those methods target different ROM dimensions and different properties; a quantitative comparison at the same reduction order or on the same error metric would be more informative.","section":"Section 4.4"}],"recommendation":"major_revision","confidential_remarks":"The central theorem is not correct as stated, but the two main gaps appear repairable: adding a full-row-rank condition on U0,T Q and making Q = HP an explicit condition in Theorem 3.4. If the authors cannot add such a rank condition without substantially changing the main claim, rejection would be appropriate. I recommend major revision rather than outright rejection because the proposed methodology is plausible and the fixes are local to the theorem statement and proof."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Colleague,\n\nQuick take on arXiv:2502.01094. The core idea is genuinely new: build a reduced-order model and a simulation function directly from two input-state trajectories, then use the ROM for LTL controller synthesis with a closeness certificate. The paper is clearly written, the LMI formulation is standard, and the benchmarks (motor, spacecraft, glucose, cart, 25-state) show practical intent. The authors also state their limitations honestly in Section 3.2, including the exact-derivative assumption and the full-rank requirement on A for the zero-input trajectory.\n\nThe problem is in Lemma 3.2, and it is load-bearing. From X1,T Q - Xbar1,T Qbar = B U0,T Q, the lemma concludes B equals M (U0,T Q)^\\dagger. That only holds if U0,T Q has full row rank. If the collected input data doesn't excite every input direction, the reconstructed B is only correct on the row space of U0,T Q, and the interface term (Xi xhat + Psi uhat) can easily live outside that subspace. Then the Lie derivative in Theorem 3.4 is computed for a data-based system that is not the actual closed-loop system, and the \"certified\" closeness guarantee can fail for the true unknown system. The paper never states this rank condition, and the hypotheses on X0,T and Xbar0,T don't imply it. This is a fixable gap — persistently exciting inputs should make it hold — but as written, the main theorem is not established.\n\nThere is also a minor proof slip: Theorem 3.4 asserts Q = HP from X0,T HP = I and X0,T Q = I, which doesn't follow. The algorithm itself sets Q = HP, so that is repairable, but the equality should be stated as a construction, not a consequence. The benchmarks also use arbitrary initial conditions in the plots while the guaranteed bound assumes x0 = Theta xhat0; that's a presentation issue rather than a fatal one.\n\nNet: the contribution is real and the machinery is mostly sound, but the central certificate currently lacks a necessary hypothesis. A serious referee should see it, because the repair is plausible and the direction is worth pushing. I would not use it as a citation in its current form, and I wouldn't sign off on acceptance. But I'd send it back for major revision rather than reject outright.","headline":"New idea, flawed lemma: the data-driven simulation-function construction is attractive but the main theorem misses a rank condition on U0,T Q, so the certificate may be for the wrong system.","tokens_in":19522,"tokens_out":2369,"would_cite":false,"duration_ms":22150,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["93B11","93C05","93B30","93D30"],"pacs":[],"model":"deepseek-v4-flash","headline":"This paper claims that two recorded input-state trajectories of an unknown continuous-time linear system are enough to build a reduced-order model and a quadratic simulation function that formally bounds the difference between the reduced…","keywords":["model order reduction","data-driven control","simulation functions","unknown linear systems","controller synthesis","formal verification","reach-while-avoid","linear temporal logic"],"falsifier":"Pick a known stable linear system with two inputs and run the data-collection phase while applying control only through the first input, so the second column of $B$ is never excited; then follow Algorithm 1 and compare the certified bound from (2.5) with the actual sup-norm error $\\|y(t)-\\hat{y}(t)\\|$ on a third trajectory driven through the second input. If the actual error exceeds the certified bound, the data-based representation (3.4) has not recovered the true $B$, and the simulation-function certificate fails.","tokens_in":18384,"feed_emoji":"📉","tokens_out":15478,"duration_ms":131065,"temperature":0.7,"pith_summary":"This paper sets out to show that model order reduction with formal guarantees is possible when the underlying continuous-time linear system is completely unknown. The authors construct both a reduced-order model and a simulation function, a Lyapunov-like function that measures trajectory closeness, using only two recorded input-state trajectories: one driven by a general input and one by zero input. The main theorem certifies that, whenever three data-driven matrix conditions (3.8a)-(3.8c) hold, the reduced model's outputs are guaranteed to stay within an explicit bound of the unknown system's outputs. That makes the reduced model a sound substitute for controller synthesis: a controller enforcing safety, reach-while-avoid, or tracking on the small model transfers to the large unknown system with a quantified error. The authors verify the approach on five benchmark systems without ever knowing the system matrices.","feed_headline":"Two data trajectories build a certified reduced-order model","feed_subtitle":"A quadratic simulation function turns ROM controllers into certified guarantees for the unknown original system.","key_machinery":"The central object is the quadratic simulation function $V(x,\\hat{x}) = (x-\\Theta\\hat{x})^\\top P(x-\\Theta\\hat{x})$, with $P \\succ 0$ and $\\Theta \\in \\mathbb{R}^{n \\times \\hat{n}}$. It works through three data-based identities: $I_n = X_{0,T}Q$ and $I_n = \\bar{X}_{0,T}\\bar{Q}$ express the drift matrix as $A = \\bar{X}_{1,T}\\bar{Q}$ and the pre-feedback matrix as $A+BF = X_{1,T}Q$, while $B$ is recovered as $(X_{1,T}Q-\\bar{X}_{1,T}\\bar{Q})(U_{0,T}Q)^\\dagger$. The theorem's conditions then force the Lie derivative into the dissipativity inequality $\\mathcal{L}V \\le -\\kappa V + \\rho\\|\\hat{u}\\|^2$: condition (3.8a) links the auxiliary matrix $H$ to $P^{-1}$, condition (3.8b) cancels the coupling terms between $x$ and $\\hat{x}$, and condition (3.8c) makes the remaining quadratic term contractive. Because (3.8c) is equivalent to stabilizability of the pair $(A,B)$, the data-driven certificate inherits the classical necessary-and-sufficient condition of model-based design.","core_discovery":"On its own terms, the paper's discovery is that the classical simulation-function framework for model order reduction does not require knowledge of $A$ and $B$; it requires only enough data to represent them. Lemma 3.2 shows that, under the rank condition that the stacked state matrices $X_{0,T}$ and $\\bar{X}_{0,T}$ have full row rank, the closed-loop system under the interface map $u = U_{0,T}Q(x-\\Theta\\hat{x})+\\Xi\\hat{x}+\\Psi\\hat{u}$ has the data-based form (3.4), with $A$ recovered from the zero-input trajectory and $B$ recovered through the pseudoinverse expression $B = (X_{1,T}Q-\\bar{X}_{1,T}\\bar{Q})(U_{0,T}Q)^\\dagger$. Theorem 3.4 then proves that the quadratic form $V(x,\\hat{x}) = (x-\\Theta\\hat{x})^\\top P(x-\\Theta\\hat{x})$ is a simulation function from the ROM to the unknown system whenever (3.8a)-(3.8c) hold, yielding the closeness guarantee $\\|y(t)-\\hat{y}(t)\\| \\le \\frac{1}{\\alpha}\\beta(V(x,\\hat{x}),t) + \\frac{\\rho}{\\alpha\\kappa}\\|\\hat{u}\\|_\\infty$. Because $\\hat{C} = \\Theta$ and the reduced-order model $\\hat{A},\\hat{B}$ is constructed entirely from this data, the guarantee applies to the actual unknown system rather than to an identified surrogate model.","pith_inferences":["Because condition (3.8c) is equivalent to stabilizability, the data-driven certificate inherits a diagnosable failure mode: for an unstabilizable system the LMI cannot be satisfied, so the method's pre-computation step already tells the user that no such certified ROM exists.","The zero-input trajectory requirement implicitly demands that every mode of the drift matrix $A$ shows up in the autonomous data; when $A$ is singular, condition (3.2b) cannot be met and, as the paper's own limitation section concedes, $B$ must be known instead, narrowing the 'fully unknown' setting in that case.","Following the paper's stated outlook, the same two-trajectory logic should extend to systems of the form $\\dot{x} = AZ(x)+Bu$ by replacing $x$ with the nonlinear basis $Z(x)$, which would make the interface map nonlinear and would likely preserve the rank-and-LMI structure; testing this on a polynomial or trigonometric basis is a direct next step.","The bound in (2.5) grows linearly with $\\|\\hat{u}\\|_\\infty$, so the practical tightness of the certificate depends on restricting the ROM input magnitude; pairing the method with bounded-input symbolic controllers would make the guaranteed error a design parameter rather than a post-hoc number."],"forward_implications":["A controller that enforces a safety, reachability, or reach-while-avoid specification on the data-driven ROM, refined through the interface map $u = U_{0,T}Q(x-\\Theta\\hat{x})+\\Xi\\hat{x}+\\Psi\\hat{u}$, guarantees the same specification on the unknown system up to the quantified bound (2.5).","The construction needs only two recorded trajectories and no identification step: the rank conditions on $X_{0,T}$ and $\\bar{X}_{0,T}$ are checkable from data, and the remaining matrices come from solving an LMI and the linear equation (3.8b).","Choosing the ROM input matrix $\\hat{B} = I_{\\hat{n}}$ (or a scaled identity) makes the ROM fully actuated, and choosing $\\Psi$ according to (3.13) minimizes $\\rho$, shrinking the guaranteed error bound.","Setting $x_0 = \\Theta\\hat{x}_0$ removes the transient term $\\frac{1}{\\alpha}\\beta(V(x,\\hat{x}),t)$ from (2.5), leaving the steady-state error $\\frac{\\rho}{\\alpha\\kappa}\\|\\hat{u}\\|_\\infty$.","For autonomous (input-free) systems the verification problem simplifies: no interface map is needed, and conditions (3.8b)-(3.8c) reduce to $\\bar{X}_{1,T}\\bar{Q}\\Theta = \\Theta\\hat{A}$ and the corresponding LMI with $\\bar{X}_{1,T}$."],"supporting_citations":[{"why":"It supplies the dissipativity-based simulation-function framework and Theorem 3.3, from which the closeness bound (2.5) in Theorem 2.5 is taken.","marker":"[ZA17]"},{"why":"It supplies the approximate-simulation interface-map design and the construction of $\\Psi$ that minimizes the gain $\\rho$ in the error bound.","marker":"[GP09]"},{"why":"It provides the symbolic-control viewpoint that transfers ROM-level safety and reach-while-avoid properties back to the original system via closeness guarantees.","marker":"[Tab09]"},{"why":"It is the prior data-driven balanced truncation result that the paper positions itself against, since it certifies input-state behavior but not complex logic properties.","marker":"[RT11]"},{"why":"It is the prior data-driven generalized balanced truncation from noisy data that serves as the comparison baseline in the cart benchmark.","marker":"[BBSC23]"}],"fun_headline_variants":["Certified ROMs from just two data trajectories","Data-only model reduction with formal guarantees","Two trajectories suffice for certified MOR","Unknown dynamics, certified reduced models from data","Data-driven ROMs with provable closeness"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The load-bearing premise is that the two recorded trajectories reveal the full drift matrix $A$ (so $\\bar{X}_{0,T}$ has full row rank) and that the control inputs used in the first trajectory excite every direction of $B$ that the interface map will use; without that, the data-based representation (3.4) can describe a different closed-loop system, and the certificate from Theorem 3.4 would not apply to the true unknown one.","fun_headline_variants_meta":{"raw":{"variants":["Certified ROMs from just two data trajectories","Data-only model reduction with formal guarantees","Two trajectories suffice for certified MOR","Unknown dynamics, certified reduced models from data","Data-driven ROMs with provable closeness"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000139,"raw_usage":{"total_tokens":1216,"prompt_tokens":1064,"completion_tokens":152,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":680,"completion_tokens_details":{"reasoning_tokens":88}},"tokens_in":680,"tokens_out":152,"duration_ms":2631,"temperature":1.0,"reasoning_tokens":88,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-09T16:38:45.016085+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Pick a known stable linear system with two inputs and run the data-collection phase while applying control only through the first input, so the second column of $B$ is never excited; then follow Algorithm 1 and compare the certified bound from (2.5) with the actual sup-norm error $\\|y(t)-\\hat{y}(t)\\|$ on a third trajectory driven through the second input. If the actual error exceeds the certified bound, the data-based representation (3.4) has not recovered the true $B$, and the simulation-function certificate fails.","supporting_citations":[],"review_version":1}