{"id":"b80a1bc5-e244-4285-9b6f-a75e3eb6a249","arxiv_id":"2509.12182","paper_version":2,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"Strictly compatible CLF-CBF pairs are equivalent to a single smooth Lyapunov function certifying both safety and stability, via an explicit hitting-time construction.","lead":"The paper proves that safety and stability certificates can always be merged into one function when they are strictly compatible. This gives control designers a single mathematical object to verify, and a way to see when the two goals are fundamentally in conflict.","discovery_kind":"unification","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Proposition 1's proof imposes the wrong sign on the barrier derivative: Assumption 1 requires ψ>0 on ∂C, but the construction enforces ψ≤−ε<0, so the closed-loop field points outward and C is not invariant.","rationale":"The reader's weakest-assumption analysis identified the strict boundary condition (10) as the delicate point, and the rationale correctly pinpointed the systematic sign error in Proposition 1: Assumption 1 requires ψ>0 on ∂C, while the proof imposes ψ≤−ε everywhere on the boundary. My reading confirms this is the single most load-bearing defect. The main construction—defining W(x)=V(x)/V(ϕ(T(x),x)) on the domain of attraction, with the PDE ∇W·F=−ω1 and level sets {W≤1}=C—is elegant and would be valid if the controller from Proposition 1 were established. The sign error breaks the prerequisite for Lemma 1 (strictly inward-pointing field on ∂C), so the hitting time may not exist and the level-set identification fails. I do not see another independent fatal gap: Lemma 1's backward-trajectory argument is terse but repairable, and the smoothing step under Assumption 3 references known results and is plausible. The paper has no formal verification, but the construction is explicit and parameter-free, so a targeted re-derivation can settle the issue. The verdict should remain CONDITIONAL on correcting the sign in Proposition 1 and making the partition-of-unity argument sound with respect to the barrier inequality; no change from the reader's verdict is needed.","tokens_in":10778,"tokens_out":7799,"duration_ms":94289,"concrete_test":"On the scalar system ẋ=u with C=[-1,1], h(x)=1−x², V(x)=x², write the partition-of-unity controller from the proof as written. At x=1 the proof selects u with ψ=∇h·(g u)=−2u<0, so u>0; at x=−1 it selects u with ψ=2u<0, so u<0. Evaluating ψ=∇h·k on ∂C gives ψ<0, contradicting Assumption 1(2), and the set C is not forward invariant. Recompute the same construction with the sign corrected (require ψ>0, ε=min{−φ,ψ}, and ψ≥ε/2); the resulting controller k(x)=−x yields ψ=2>0 on ∂C and invariance. If the corrected partition-of-unity proof cannot be written with the same local neighborhoods, Proposition 1 fails and Theorem 1 has no supporting controller.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central claim (Theorem 1) rests on Proposition 1, which must produce a safe stabilizing controller whose closed-loop field F satisfies ∇h(x)·F(x)>0 on ∂C (so that Lemma 1’s hitting time T(x) is well-defined and the level sets of W=V/V(ϕ(T)) coincide with C). In the proof of Proposition 1, the authors define ψ(x,u)=L_f h(x)+L_g h(x)u. Assumption 1(2) requires ψ>0 on ∂C. But the proof states: for x∈∂C, φ(x,u_x)<0 and ψ(x,u_x)<0, then sets ε_x=min{−φ,−ψ}>0 and later requires ψ(y,u_x)≤−ε/2 on a neighborhood. These inequalities are inconsistent with Assumption 1(2) by a sign flip. Consequently the constructed controller u_1, and hence k, satisfies ψ<0 on ∂C, i.e., the closed-loop vector field points strictly outward. This would render C repelling rather than invariant, so the conclusions of Lemma 1—unique crossing time, ∇h·F>0 on ∂C—do not follow. The same flawed inequality is used again in part (b). The error is not a one-line typo: the epsilon construction and the subsequent chain of inequalities all use the wrong sign, so Theorem 1 lacks a valid controller as written. With a corrected sign, the partition-of-unity argument plausibly goes through, but the paper must be repaired.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The manuscript claims an iff characterization of joint safety and stability certificates: a strictly compatible CLF-CBF pair exists iff a single smooth CLBF exists with the safe set appearing exactly as a sublevel set. The proof route is constructive: Proposition 1 builds a safe stabilizing feedback from the compatible pair; Lemma 1 establishes C^1 regularity and gradient estimates for the boundary hitting time T(x); Theorem 1 then defines W(x)=V(x)/V(phi(T(x),x)), shows that W solves the PDE grad W . F = -omega_1, and verifies the level-set conditions {W<=1}=C, {W=1}=partial C. An example illustrates that without exponential stabilizability the unsmoothed W need not be C^1 at the origin, motivating a composition-based smoothing step.","tokens_in":11071,"tokens_out":11742,"duration_ms":139686,"significance":"If the proof can be repaired, this is a valuable converse theorem: it reduces the existence of a compatible CLF-CBF pair to the existence of a single Lyapunov-like function with a prescribed boundary level set, and it provides an explicit PDE characterization. The construction is parameter-free, the hitting-time regularity estimate is of independent interest, and the paper names the precise regularity trade-off through Assumptions 2 and 3. The current version, however, contains sign errors in two load-bearing places, so the main theorem is not proven as written.","major_comments":[{"comment":"The proof defines psi(x,u)=L_f h(x)+L_g h(x)u and then states that for x in partial C we have phi(x,u_x)<0 and psi(x,u_x)<0. This contradicts Assumption 1(2), Eq. (10), which requires psi(x,u_x)>0. The subsequent construction sets epsilon_x = min{-phi,-psi}>0 and requires psi(y,u_x) <= -epsilon/2 on a neighborhood, so the final feedback k satisfies grad h . F < 0 on partial C. This is the outward-pointing condition; Corollary 1, Eq. (6), requires the opposite sign for forward invariance. Since Proposition 1 supplies the vector field F used in Lemma 1 (which needs grad h . F > 0 on partial C) and in Theorem 1, the main result is not established as written. The error appears again in the summary of the construction in part (b). Replacing the sign so that psi>0 and setting epsilon_x = min{-phi, psi} seems to make the partition-of-unity argument go through, but this must be redone carefully.","section":"III.A, Proposition 1 proof"},{"comment":"For x in Int(C), T(x)<0, and the display V(phi(T(x),x)) = V(x) - integral_{T(x)}^0 omega(phi(t,x)) dt > V(x) has the wrong sign. Since omega is positive and the integration interval is [T(x),0] with T(x)<0, the integral is positive, so the right-hand side is less than V(x). The correct identity is V(phi(T(x),x)) = V(x) + integral_{T(x)}^0 omega(phi(t,x)) dt, which gives V(phi(T(x),x)) > V(x) and hence W(x)<1, as required. As written the displayed identity would give W(x)>1 in Int(C), contradicting condition (2) of Definition 4.","section":"III.B, Theorem 1 proof, after Eq. (16)"},{"comment":"Assumption 2 defines P = grad^2 V(0), where V is only assumed continuously differentiable in Assumption 1. A C^1 function need not possess a Hessian at the origin, so the statement is not well-posed. Either Assumption 1 should be strengthened to require V to be C^2 in a neighborhood of 0, or Assumption 2 should be reformulated using stabilizability of (A,B) alone (e.g., taking P from the Lyapunov equation, as is actually done later in Lemma 1). As written, Proposition 1(a) and the part of Theorem 1 that relies on Assumption 2 rest on an ill-defined object.","section":"Assumption 2"}],"minor_comments":[{"comment":"In the quadratic Lyapunov estimate, the term '-|x|^top' should read '-|x|^2'.","section":"Lemma 1 proof"},{"comment":"The sentence 'T(x)=O(1/|x|)' should be 'grad T(x)=O(1/|x|)'; Lemma 1 proves |T(x)| = O(log(1/|x|)), not O(1/|x|).","section":"Theorem 1 proof"},{"comment":"The notation 'D \\(delta C \\cup {0}\\)' and 'delta C' appears to be a typo for 'D \\setminus \\partial C' and '\\partial C'.","section":"III.A, Proposition 1 proof"},{"comment":"The abstract and introduction state an 'iff' characterization, but Theorem 1 only proves the direction from a strictly compatible pair to a CLBF. The converse direction follows easily from Definition 4 by taking h=1-W and V=W, but it should be stated explicitly for the claimed equivalence.","section":"Abstract and Section I"}],"recommendation":"major_revision","confidential_remarks":null},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Short version: the construction W=V/V(phi(T)) is genuinely new and the main equivalence is plausible, but Proposition 1's proof as written has a sign error that breaks the safety guarantee. The stress-test note is right.\n\nWhat's actually new: the paper gives a converse theorem that turns a strictly compatible CLF-CBF pair into a single smooth CLBF, with a PDE characterization and exact level sets {W<=1}=C. The formula W(x)=V(x)/V(phi(T(x),x)) and the boundary-only strict compatibility condition are stronger than what [16] and [18] offer, and the level-set verification in Theorem 1 is clean. The backward hitting time argument in Lemma 1 is a nice piece of work, aside from the O(1/|x|) typo for T(x) (the proof actually gives logarithmic growth).\n\nThe soft spot is proportionally large. In the proof of Proposition 1, Assumption 1(2) says for each x in partial C there is a u_x with phi(x,u_x)<0 and psi(x,u_x)>0. The proof instead states phi<0 and psi<0, then defines epsilon_x from both negative values and later imposes psi<=-epsilon/2 on a neighborhood. So the constructed controller satisfies psi<0 on partial C, meaning the closed-loop field points outward and C is not forward invariant. That is exactly the property Lemma 1 needs, so Theorem 1 has no valid controller to lean on. The same wrong inequality is used in both parts (a) and (b). This is a fixable sign flip, not a structural flaw -- flip the sign, set epsilon_x from -phi and psi, and the partition-of-unity argument plausibly works. But as written, the central implication is unsupported.\n\nTwo smaller issues: the smoothing step under Assumption 3 is sketched rather than demonstrated, and the example only shows that the unsmoothed W can fail to be C^1 at 0; it doesn't validate the actual smoothing construction. Neither is in the same league as the sign error. The citation to [15] for the integral identity is fine; it's a standard result, and there are no fitted parameters or hidden compatibility assumptions.\n\nWho should read this: anyone working on CLF-CBF compatibility, safe stabilization, or converse Lyapunov theorems. It deserves a serious referee, with the explicit instruction to have the authors repair Proposition 1 and make the smoothing lemma explicit. I would not desk-reject it; I'd send it to review with the expectation of major revision.","headline":"A genuinely new converse CLBF construction that is likely right, but Proposition 1's proof as written flips the sign of the CBF condition, so the supporting controller does not actually guarantee safety.","tokens_in":11603,"tokens_out":4244,"would_cite":true,"duration_ms":46800,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["93D30","93D15","93C10"],"pacs":[],"model":"deepseek-v4-flash","headline":"The paper proves that a strictly compatible control Lyapunov–barrier pair exists if and only if a single smooth Lyapunov function certifies both asymptotic stability and safety.","keywords":["control Lyapunov function","control barrier function","control Lyapunov-barrier function","converse Lyapunov theorem","safety","stability","hitting time","forward invariance"],"falsifier":"Take any control-affine system satisfying Assumptions 1 and 2, explicitly compute T(x) by backward integration and W(x) = V(x)/V(φ(T(x),x)); the central theorem would be refuted if W is not continuously differentiable on the domain of attraction (excluding the origin as appropriate), or if {x: W(x) ≤ 1} differs from the safe set C by more than a set of measure zero, or if ∇W·F = −ω₁ fails off the origin.","tokens_in":10614,"feed_emoji":"🛡️","tokens_out":4929,"duration_ms":45051,"temperature":0.7,"pith_summary":"This paper establishes a converse Lyapunov theorem for joint safety and stability. It shows that, under mild assumptions, having a pair of certificates—one for stability (a control Lyapunov function) and one for safety (a control barrier function) that are strictly compatible at the safe set's boundary—is exactly equivalent to having one smooth Lyapunov function that does both jobs at once. The construction produces the combined function explicitly as a ratio of the original Lyapunov function evaluated along trajectories up to the time they hit the safe set's boundary. This matters because it turns a two-certificate design problem into a single-function certificate with a PDE characterization and prescribed boundary conditions, and it reveals when the two goals are fundamentally in conflict.","feed_headline":"One smooth function certifies safety and stability together","feed_subtitle":"A strictly compatible barrier–Lyapunov pair exists exactly when one smooth function can certify both safety and stability.","key_machinery":"The hitting time T(x) to the safe set boundary, whose continuous differentiability follows from the implicit function theorem because the closed-loop field points strictly inward at ∂C. Using T, the paper forms the ratio W(x) = V(x)/V(φ(T(x),x)); this ratio is constant along trajectories, splits the domain into W > 1 outside C, W < 1 inside, and W = 1 on the boundary, and solves the PDE ∇W·F = −ω₁. The regularity of W rests on the estimate |∇T(x)| = O(1/|x|) obtained under a stabilizable linearization.","core_discovery":"The central claim is Theorem 1: if a control system of the form ẋ = f(x) + g(x)u admits a strictly compatible pair—a control Lyapunov function for asymptotic stability and a control barrier function for forward invariance of a compact safe set C, with strict inequality at ∂C—then there is a single smooth function W whose sublevel set {W ≤ 1} is exactly C, whose boundary {W = 1} is ∂C, and which decreases along the closed-loop flow everywhere off the origin. The proof constructs W(x) = V(x)/V(φ(T(x),x)), where T(x) is the unique time at which the trajectory from x crosses ∂C; this ratio automatically satisfies a PDE ∇W·F = −ω₁ and the level-set conditions. Under a stabilizable linearization a","pith_inferences":["Inference: The ratio construction suggests a time-reparametrization interpretation—W measures how much Lyapunov value is consumed before reaching the safe boundary—which may connect to minimum-time or reach-avoid cost interpretations.","Inference: Because strict inward pointing at the boundary is load-bearing, systems whose barrier condition is only non-strict may require a qualitatively different certificate; exploring boundary tangency cases could extend the theorem.","Inference: A computational recipe follows: integrate the closed-loop flow backward to find T(x), evaluate V at the boundary crossing, and form W; this can be tested numerically on low-dimensional polynomial systems as a fast falsifier for the theorem.","Inference: The equivalence implies that verifying joint safety and stability can be reduced to checking a single function's level sets and PDE, which may simplify controller synthesis for safety-critical robotics."],"forward_implications":["A strict CLF–CBF compatibility condition on the boundary of the safe set is both necessary and sufficient for the existence of a single smooth CLBF.","The combined certificate W satisfies a PDE with prescribed boundary conditions, making it a candidate for PDE-based learning or verification of safe-stabilizing functions.","If a specification admits no smooth single Lyapunov-barrier certificate, then every CLF–CBF pair is conflict-ridden: no pair can be simultaneously satisfied in a robust sense.","The constructed W, together with a universal feedback formula, yields a smooth (resp. continuous) safe-stabilizing controller, with exponential stability when the linearization is stabilizable."],"fun_headline_variants":["One smooth function replaces a barrier–Lyapunov pair","Strict CLF-CBF pair iff one smooth Lyapunov function","One Lyapunov function can certify safety and stability","Single smooth function: equivalent to strict barrier–Lyapunov pair","Barrier and Lyapunov collapse into one function if compatible"],"cache_read_input_tokens":2304,"weakest_assumption_plain":"The assumption that at every boundary point some control makes the barrier's Lie derivative strictly positive (the strict inward-pointing condition) carries the whole construction; if only the usual non-strict barrier inequality holds, the hitting time T(x) may not be differentiable and the ratio W may fail to be a valid CLBF.","fun_headline_variants_meta":{"raw":{"variants":["One smooth function replaces a barrier–Lyapunov pair","Strict CLF-CBF pair iff one smooth Lyapunov function","One Lyapunov function can certify safety and stability","Single smooth function: equivalent to strict barrier–Lyapunov pair","Barrier and Lyapunov collapse into one function if compatible"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000724,"raw_usage":{"total_tokens":3043,"prompt_tokens":665,"completion_tokens":2378,"prompt_tokens_details":{"cached_tokens":256},"prompt_cache_hit_tokens":256,"prompt_cache_miss_tokens":409,"completion_tokens_details":{"reasoning_tokens":2292}},"tokens_in":409,"tokens_out":2378,"duration_ms":17627,"temperature":1.0,"reasoning_tokens":2292,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-04T16:38:10.166067+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Take any control-affine system satisfying Assumptions 1 and 2, explicitly compute T(x) by backward integration and W(x) = V(x)/V(φ(T(x),x)); the central theorem would be refuted if W is not continuously differentiable on the domain of attraction (excluding the origin as appropriate), or if {x: W(x) ≤ 1} differs from the safe set C by more than a set of measure zero, or if ∇W·F = −ω₁ fails off the origin.","supporting_citations":[],"review_version":1}