Pith. sign in

REVIEW 3 major objections 4 minor 28 references

Backstepping Reach-avoid Controller Synthesis for Multi-input Multi-output Systems with Mixed Relative Degrees

T0 review · 3 major / 4 minor · reviewed 2026-08-15 · deepseek-v4-flash

Pith's one-line read Reach-avoid guarantees for MIMO systems reduce to one output-level certificate plus backstepping.

desk verdict Main theorem's proof drops cross-coupling derivative terms, so the reach-avoid guarantee does not follow as stated; promising idea, needs a serious rewrite. read the letter →

arxiv 2505.03612 v1 pith:IVVYB3AN submitted 2025-05-06 eess.SY cs.SY

classification eess.SYcs.SY MSC 93C1093B1893C3593D30
keywords reach-avoidcontrolbarrierfunctionsbacksteppingfeedbacklinearizationmulti-inputmulti-outputsystemsmixedrelativedegreessum-of-squaresoptimizationformalcertificates
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper aims to show that a reach-avoid controller for a multi-input multi-output (MIMO) nonlinear system can be synthesized from a scalar reach-avoid certificate on the outputs alone, using feedback linearization and backstepping to lift that certificate to the full state. The main theorem states: if $\psi(y(x))$ certifies reach-avoid for the single-integrator dynamics $\dot y = v$, then subtracting squared virtual-tracking-error terms for each level of the relative-degree chains produces a certificate $\Psi(x)$ for the original system, and the recursive construction simultaneously produces a state-feedback controller $k(x)$. The significance is that safety and reachability are handled by one certificate rather than two competing constraints, and the expensive sum-of-squares search is done only in the low-dimensional output dynamics, not in the full state space. If the theorem is right, formal reach-avoid guarantees for high-dimensional MIMO systems become a tractable extension of low-dimensional certificate synthesis.

What carries the argument

The load-bearing object is the backstepping ECGBF candidate $$\Psi(x)=\psi(y(x))-\sum_{i,l}\frac{1}{2\mu_i^l}\|\$eta_i^{{l+1}}$-k_i^l(z_i^l)\|^2,$$ a scalar function that keeps the output-level certificate $\psi$ and penalizes, in each relative-degree chain, the deviation of the virtual state $\eta_i^{l+1}$ from the stabilizing function $k_i^l(z_i^l)$. The recursive choice of $k_i^l$ makes every cross term in $\dot{\Psi}$ equal to $\frac{\lambda}{2\mu_i^l}\|\eta_i^{l+1}-k_i^l\|^2$, so the derivative inequality $\dot{\Psi}\ge\lambda\Psi$ follows directly from the single-integrator inequality $\partial_y\psi\cdot k_1\ge\lambda\psi$. The controller is recovered from the last layer via the decoupling matrix $A(x)$, which is the same matrix used in the feedback linearization (14)-(16).

What would settle it

Find a MIMO system satisfying the assumptions where $A(x)$ is singular at some point $x^*\in C_{\Psi}$; at that point $k(x)=A(x)^{-1}b(x)$ does not exist, so either $C_{\Psi}$ must be shrunk to exclude $x^*$ or the claimed reach-avoid guarantee fails for trajectories starting arbitrarily close to $x^*$.

Watch

Extended reading notes

Core claim

On its own terms, the paper's central discovery is Theorem 2. For a control-affine MIMO system (1) with output $y=h(x)$ and vector relative degree $\{\gamma_1,\ldots,\gamma_m\}$ at a point $x_0$, suppose $\psi(y(x))$ is an ECGBF for the single-integrator system (18) with respect to safe set $C$ and target set $X_r$. Then the function $$\Psi(x)=\psi(y(x))-\sum_{i=1}^m\sum_{l=1}^{\gamma_i-1}\frac{1}{2\mu_i^l}\|\$eta_i^{{l+1}}$-k_i^l(z_i^l)\|^2$$ is an ECGBF for the original MIMO system with respect to the safe set $C_{\Psi}=\{x:\Psi(x)>0\}\subseteq C$ and the same target set $X_r$. The proof is constructive: the auxiliary functions $k_i^l$ are chosen recursively so that the time derivative of $\Psi$ collapses to $\lambda\Psi$, and the final layer defines $b(x)$ with the actual controller $k(x)=A(x)^{-1}b(x)$. Hence every trajectory starting in $C_{\Psi}$ stays in $C_{\Psi}$ and eventually enters $X_r$.

Load-bearing premise

The controller formula divides by the decoupling matrix $A(x)$, and the paper only assumes a vector relative degree at a single point $x_0$; nothing confines the certified set $C_{\Psi}$ to the neighborhood where $A(x)$ is invertible and the feedback-linearized strict-feedback form is valid.

Editorial extensions

If this is right

  • For any MIMO system with a vector relative degree, an SOS-computed ECGBF on the output dynamics is enough to synthesize a provable reach-avoid controller for the full state-space system.
  • The certified set is $C_{\Psi}\subseteq C$, and it can be made arbitrarily close to $C$ by increasing the tuning parameters $\mu_i^l$.
  • Trajectories starting in $C_{\Psi}$ satisfy both safety (stay in $C_{\Psi}$) and reachability (enter $X_r$) simultaneously, so safety and goal constraints do not need separate, possibly conflicting certificates.
  • Each output channel with relative degree $\gamma_i$ gets its own chain of virtual controllers, so the construction handles mixed relative degrees without a uniform-degree assumption.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • The constraints defining $K(x)$ in Proposition 1 are conditions that could be enforced in a real-time quadratic program around a nominal controller, turning the synthesis into an online safety filter with reach-avoid guarantees on $C_{\Psi}$; the paper itself does not develop this online variant.
  • Because the optimization is performed only on the output-level single-integrator system, the cost of certificate search is governed by the output dimension and relative degrees rather than the full state dimension; whether this scaling holds for very high-dimensional examples is a testable prediction beyond the paper's simulations.
  • The same dissipation-style cancellation may extend to sampled-data or uncertain versions of the recursion, but the paper does not analyze robustness to disturbances or discretization.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 4 minor

Summary. The paper proposes a backstepping framework for reach-avoid controller synthesis in multi-input multi-output (MIMO) nonlinear systems with mixed relative degrees. The method first synthesizes a reach-avoid controller k1(y) for a single-integrator system (18) via sum-of-squares optimization, then constructs an exponential control guidance-barrier function (ECGBF) Psi(x) by subtracting squared error terms between virtual controls and transformed state variables, and finally derives the actual controller k(x) recursively through feedback linearization and backstepping. Theorem 2 claims that Psi is an ECGBF for the original system with respect to the safe set C_Psi, and Proposition 1 provides the recursive controller. The paper reports numerical simulations on a four-state example, a Dubins car, and a two-link robotic arm.

Significance. If correct, the proposal would be a valuable scalable alternative to direct SOS synthesis for high-relative-degree MIMO systems, because it reduces the certificate construction to a lower-dimensional single-integrator problem. The paper addresses an important problem and the single-integrator SOS step is standard. However, the central derivation contains a fundamental error in the treatment of virtual-control derivatives, and a concrete counterexample shows that the claimed ECGBF inequality fails; consequently, the main theorem is false as stated. The local-global gap between the pointwise vector relative degree and the global reach-avoid guarantee is a further unresolved issue. The simulations are illustrative only and do not compensate for the invalid proof.

major comments (3)
  1. [Section III, Eq. (22) and Proposition 1, Eq. (26)] The proof of Theorem 2 computes the derivative of each virtual control k_i^l only along the i-th output chain. Since k_i^1 is the i-th component of k1(y(x)), which generally depends on the full output vector y=(eta_1^1,...,eta_m^1), the term dot-k_i^1 contains cross contributions sum_{j!=i} (partial k_i^1 / partial y_j) eta_j^2 that are omitted from (22) and from the recursive formulas (26). The claimed cancellation therefore does not take place. A concrete two-output example with chains dot-eta_i^1=eta_i^2, dot-eta_i^2=v_i, psi=1-y_1^2-y_2^2, X_r={y_1^2+y_2^2<0.01}, k1=(-10y_1-y_2,-10y_2), lambda=0.1, mu_i^1=1, evaluated at (y_1,y_2,eta_1^2,eta_2^2)=(0.11,0,-0.9,1.3), gives Psi=0.1229>0 but dot-Psi=-0.1045, while lambda Psi=0.0123. Hence the controller from (26) violates the ECGBF inequality and the reach-avoid conclusion of Theorem 2 is false as stated.
  2. [Section II, Definition 2; Section III, Theorem 2] The vector relative degree is defined at a single point x0, and the strict feedback form (20) together with the controller k(x)=A(x)^{-1}b(x) is only guaranteed on a neighborhood of x0 where the decoupling matrix A(x) has rank m. The theorem, however, claims the reach-avoid guarantee for all x in C_Psi, with no argument that C_Psi lies in the domain of validity of the feedback linearization. Unless a global relative degree assumption is added or C_Psi is explicitly confined to the region of nonsingularity of A(x), the guarantees cannot be certified.
  3. [Section III, proof of Theorem 2, final paragraph] The assertion that 'C_Psi can arbitrarily approximate C by adjusting each mu_i^l' is unproved and not quantified. Approximation of C alone does not imply that C_Psi cap X_r is nonempty and has no isolated points, which is required by Assumption 1 before Theorem 1 can be applied. This step needs a rigorous argument.
minor comments (4)
  1. [Proposition 1, Eq. (26)] The display (26) contains index errors: the summation in the formula for k_i^l runs to i-1 rather than l-1, and the expression for b_i(x) includes 'mu^{gamma-2}' without a chain subscript or a clear meaning. These should be corrected.
  2. [Example 1] The safe set is defined as C={x | 1-y_1(x)^2-y_2(x)^2 < 0}, which contradicts Assumption 1 where C={psi>0}. The sign should be >0 if psi=1-y_1^2-y_2^2 is the intended certificate.
  3. [Notation] In the notation section, the sum-of-squares set is written as 'X [x]' but the intended symbol is evidently 'P[x]'.
  4. [Theorem 2, proof] The sentence 'The positivity of Psi(y) ensures psi(y)>0' should read Psi(x), since Psi is a function of the state, not only of the output y.

Circularity Check

0 steps flagged · score 0.0 of 10

No circularity: the backstepping recursion is a constructive proof and the key reach-avoid theorem is external.

full rationale

The reach-avoid claim is not equivalent to its inputs. The paper first synthesizes k1(y) for the single-integrator system (18) by SOS on condition (19), an optimization over the lower-dimensional output dynamics. It then defines the candidate Psi in (21) and proves Theorem 2 by recursively choosing k_l so that each term I_l equals lambda(eta_{l+1}-k_l)^2/(2 mu_l), and finally selecting k(x)=A^{-1}(x)b(x) so that L_{Psi,k} >= lambda Psi. This is a standard constructive backstepping argument: the ECGBF inequality is derived rather than assumed. Theorem 1, the bridge from ECGBF to reach-avoid, is cited from [24], an external source; it is not a self-citation, and no uniqueness or ansatz is imported from the authors' prior work. The background self-citations [5] and [8] are not load-bearing. The parameters lambda and mu_i^l are tuning choices, not fitted to the final reach-avoid outcome. The proof's omission of cross-coupling derivatives of k1(y) in (22) and (26) is a soundness concern, but it is a mathematical gap, not a circular reduction; no equation of the paper is identical by construction to the claimed certificate.

Assumptions & free parameters 3 free parameters · 5 assumptions · 0 invented entities

The central claim rests on standard smoothness and relative-degree assumptions, the external ECGBF theorem from [24], and one unproved assertion about C_Psi approximating C. The tuning parameters lambda and mu_i^l are free choices that shape the certified safe set. No new physical entities are introduced.

free parameters (3)
  • lambda = not specified, chosen positive
    Gain in the ECGBF inequality (2) and in the recursive controller formulas; a user choice bounded below by epsilon in the SOS problem (5).
  • mu_i^l = not given in the examples
    Positive backstepping gains in Psi (21) and the recursive controller (26); they control the size of C_Psi and are tuned by hand.
  • epsilon = user-defined
    Lower bound on lambda in the SOS problem (5); selected by the user.
assumptions (5)
  • domain assumption f, g, h, psi, and phi are sufficiently smooth and the closed-loop system is locally Lipschitz.
    Needed for trajectory existence and for the Lie derivatives used throughout Section II and III.
  • domain assumption Assumption 1: C and X_r are output-defined, C has no isolated point, and C intersect X_r is nonempty with no isolated point.
    Required for Theorem 1 and for the ECGBF condition to imply reach-avoid behavior.
  • domain assumption The system has a vector relative degree at x0 and the decoupling matrix A(x) is invertible in a neighborhood.
    Definition 2 and Section III rely on this to obtain the feedback-linearized strict feedback form (20) and the controller formula (26).
  • standard math Theorem 1 of [24]: an ECGBF with a Lipschitz controller satisfying (4) yields a reach-avoid controller.
    External theorem from the cited work [24], used without reproof.
  • ad hoc to paper C_Psi can arbitrarily approximate C by adjusting mu_i^l, so that C_Psi satisfies Assumption 1.
    Asserted in the proof of Theorem 2 without proof or construction; needed to ensure C_Psi intersect X_r is nonempty and has no isolated point.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Backstepping Reach-avoid Controller Synthesis for Multi-input Multi-output Systems with Mixed Relative Degrees." pith.science (2026). https://pith.science/paper/IVVYB3AN

@misc{pith2026250503612,
  author       = {Pith},
  title        = {Pith review of: Backstepping Reach-avoid Controller Synthesis for Multi-input Multi-output Systems with Mixed Relative Degrees},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/IVVYB3AN}},
  note         = {Machine review of arXiv:2505.03612}
}
read the original abstract

Designing controllers with provable formal guarantees has become an urgent requirement for cyber-physical systems in safety-critical scenarios. Beyond addressing scalability in high-dimensional implementations, controller synthesis methodologies separating safety and reachability objectives may risk optimization infeasibility due to conflicting constraints, thereby significantly undermining their applicability in practical applications. In this paper, by leveraging feedback linearization and backstepping techniques, we present a novel framework for constructing provable reach-avoid formal certificates tailored to multi-input multi-output systems. Based on this, we developed a systematic synthesis approach for controllers with reach-avoid guarantees, which ensures that the outputs of the system eventually enter the predefined target set while staying within the required safe set. Finally, we demonstrate the effectiveness of our method through simulations.

Figures

Figures reproduced from arXiv: 2505.03612 by the authors.

Figure 1
Figure 1. 100 randomly sampled trajectories (dashed line from orange to green cross) of system (27) with synthesized reach-avoid controller. The grey vector-field indicates the function k1(y(x)), from which we construct k(y(x)) via backstepping. the output trajectories remain within the safe set C and eventually enter into the target set X r . By solving the optimization problem (5), we obtain the controller k1(y(x)) with δ =… view at source ↗
Figure 2
Figure 2. Evaluation of Ψ(x) along 100 randomly sampled trajectories [PITH_FULL_IMAGE:figures/full_fig_p005_2.png] view at source ↗
Figure 3
Figure 3. Simulated trajectories (dashed line from orange dot to [PITH_FULL_IMAGE:figures/full_fig_p006_3.png] view at source ↗
Figures from the paper (2 more)
Figure 4
Figure 4. Figure 4: Simulated trajectories (dashed line from orange dot [PITH_FULL_IMAGE:figures/full_fig_p007_4.png]
Figure 5
Figure 5. Figure 5: Impact of increasing µ i l on CΨ. Color bar indicates the different values of µ i l . V. CONCLUSION In this paper, we present a novel framework for con￾structing formal certificates and corresponding controllers with provable reach-avoid guarantees. The proposed method…

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

28 extracted references · 17 canonical work pages

  1. [1]

    Robust control barrier–value functions for safety-critical control,

    J. J. Choi, D. Lee, K. Sreenath, C. J. Tomlin, and S. L. Herbert, “Robust control barrier–value functions for safety-critical control,” in 2021 60th IEEE Conference on Decision and Control (CDC) , pp. 6814–6821, IEEE, 2021

  2. [2]

    Control barrier function based quadratic programs for safety critical systems,

    A. D. Ames, X. Xu, J. W. Grizzle, and P. Tabuada, “Control barrier function based quadratic programs for safety critical systems,” IEEE Transactions on Automatic Control , vol. 62, no. 8, pp. 3861–3876, 2016

  3. [3]

    Control barrier functions: Theory and applications,

    A. D. Ames, S. Coogan, M. Egerstedt, G. Notomista, K. Sreenath, and P. Tabuada, “Control barrier functions: Theory and applications,” in 2019 18th European control conference (ECC) , pp. 3420–3431, Ieee, 2019

  4. [4]

    Robust safety-critical control for dy- namic robotics,

    Q. Nguyen and K. Sreenath, “Robust safety-critical control for dy- namic robotics,” IEEE Transactions on Automatic Control , vol. 67, no. 3, pp. 1073–1088, 2021

  5. [5]

    Robust and safe coordination of multiple robotic manipulators: An approach using modified avoidance functions,

    S. A. Deka, X. Li, D. M. Stipanovi ´c, and T. Kesavadas, “Robust and safe coordination of multiple robotic manipulators: An approach using modified avoidance functions,” Journal of Intelligent & Robotic Systems, vol. 90, pp. 419–435, 2018

  6. [6]

    Data-driven safety filters: Hamilton-jacobi reachability, control barrier functions, and predictive methods for uncertain systems,

    K. P. Wabersich, A. J. Taylor, J. J. Choi, K. Sreenath, C. J. Tom- lin, A. D. Ames, and M. N. Zeilinger, “Data-driven safety filters: Hamilton-jacobi reachability, control barrier functions, and predictive methods for uncertain systems,” IEEE Control Systems Magazine , vol. 43, no. 5, pp. 137–177, 2023

  7. [7]

    Safety-critical model predictive control with discrete-time control barrier function,

    J. Zeng, B. Zhang, and K. Sreenath, “Safety-critical model predictive control with discrete-time control barrier function,” in 2021 American Control Conference (ACC), pp. 3882–3889, IEEE, 2021

  8. [8]

    Safe-by-construction autonomous vehicle overtaking using control barrier functions and model predictive control,

    D. Yuan, X. Yu, S. Li, and X. Yin, “Safe-by-construction autonomous vehicle overtaking using control barrier functions and model predictive control,” International Journal of Systems Science , vol. 55, no. 7, pp. 1283–1303, 2024

Show all 28 references
  1. [9]

    Efficient sum of squares-based verification and construction of control barrier functions by sampling on algebraic varieties,

    H. Zhang, Z. Li, H. Dai, and A. Clark, “Efficient sum of squares-based verification and construction of control barrier functions by sampling on algebraic varieties,” in 2023 62nd IEEE Conference on Decision and Control (CDC) , pp. 5384–5391, IEEE, 2023

  2. [10]

    Hamilton-jacobi reachability: A brief overview and recent advances,

    S. Bansal, M. Chen, S. Herbert, and C. J. Tomlin, “Hamilton-jacobi reachability: A brief overview and recent advances,” in 2017 IEEE 56th Annual Conference on Decision and Control (CDC) , pp. 2242– 2253, IEEE, 2017

  3. [11]

    Distributionally robust control synthesis for stochastic systems with safety and reach-avoid specifi- cations,

    Y . Chen, Y . Li, S. Li, and X. Yin, “Distributionally robust control synthesis for stochastic systems with safety and reach-avoid specifi- cations,” arXiv preprint arXiv:2501.03137 , 2025

  4. [12]

    Vaidyanathan and A

    S. Vaidyanathan and A. T. Azar, Backstepping control of nonlinear dynamical systems. Academic Press, 2020

  5. [13]

    Safe backstep- ping with control barrier functions,

    A. J. Taylor, P. Ong, T. G. Molnar, and A. D. Ames, “Safe backstep- ping with control barrier functions,” in 2022 IEEE 61st Conference on Decision and Control (CDC) , pp. 5775–5782, IEEE, 2022

  6. [14]

    Safe control synthesis for multicopter via control barrier function backstepping,

    J. Kim and Y . Kim, “Safe control synthesis for multicopter via control barrier function backstepping,” in 2023 62nd IEEE Conference on Decision and Control (CDC) , pp. 8720–8725, IEEE, 2023

  7. [15]

    Safe pde backstepping qp control with high relative degree cbfs: Stefan model with actuator dynamics,

    S. Koga and M. Krstic, “Safe pde backstepping qp control with high relative degree cbfs: Stefan model with actuator dynamics,” IEEE Transactions on Automatic Control , vol. 68, no. 12, pp. 7195–7208, 2023

  8. [16]

    Exponential control barrier functions for enforcing high relative-degree safety-critical constraints,

    Q. Nguyen and K. Sreenath, “Exponential control barrier functions for enforcing high relative-degree safety-critical constraints,” in 2016 American Control Conference (ACC) , pp. 322–328, IEEE, 2016

  9. [17]

    Control barrier functions for systems with high relative degree,

    W. Xiao and C. Belta, “Control barrier functions for systems with high relative degree,” in 2019 IEEE 58th conference on decision and control (CDC), pp. 474–479, IEEE, 2019

  10. [18]

    High-order control barrier functions,

    W. Xiao and C. Belta, “High-order control barrier functions,” IEEE Transactions on Automatic Control , vol. 67, no. 7, pp. 3655–3662, 2021

  11. [19]

    Constructive safety- critical control: Synthesizing control barrier functions for partially feedback linearizable systems,

    M. H. Cohen, R. K. Cosner, and A. D. Ames, “Constructive safety- critical control: Synthesizing control barrier functions for partially feedback linearizable systems,” IEEE Control Systems Letters , 2024

  12. [20]

    Constrained control of input–output linearizable systems using control sharing barrier functions,

    X. Xu, “Constrained control of input–output linearizable systems using control sharing barrier functions,” Automatica, vol. 87, pp. 195–201, 2018

  13. [21]

    Prescribed-time safety design for strict-feedback nonlinear systems,

    I. Abel, D. Steeves, M. Krsti ´c, and M. Jankovi ´c, “Prescribed-time safety design for strict-feedback nonlinear systems,” IEEE Transac- tions on Automatic Control , vol. 69, no. 3, pp. 1464–1479, 2023

  14. [22]

    Learning safe, generalizable perception-based hybrid control with certificates,

    C. Dawson, B. Lowenkamp, D. Goff, and C. Fan, “Learning safe, generalizable perception-based hybrid control with certificates,” IEEE Robotics and Automation Letters , vol. 7, no. 2, pp. 1904–1911, 2022

  15. [23]

    Safety and liveness guarantees through reach-avoid reinforcement learning,

    K.-C. Hsu, V . Rubies-Royo, C. J. Tomlin, and J. F. Fisac, “Safety and liveness guarantees through reach-avoid reinforcement learning,” arXiv preprint arXiv:2112.12288 , 2021

  16. [24]

    Reach-avoid controllers synthesis for safety critical systems,

    B. Xue, “Reach-avoid controllers synthesis for safety critical systems,” IEEE Transactions on Automatic Control , 2024

  17. [25]

    Reach-avoid verification based on convex optimization,

    B. Xue, N. Zhan, M. Fr ¨anzle, J. Wang, and W. Liu, “Reach-avoid verification based on convex optimization,” IEEE Transactions on Automatic Control, vol. 69, no. 1, pp. 598–605, 2023

  18. [26]

    Isidori, Nonlinear control systems: an introduction

    A. Isidori, Nonlinear control systems: an introduction. Springer, 1985

  19. [27]

    Papachristodoulou, J

    A. Papachristodoulou, J. Anderson, G. Valmorbida, S. Prajna, P. Seiler, and P. A. Parrilo, SOSTOOLS: Sum of squares optimization toolbox for MATLAB. http://arxiv.org/abs/1310.4716, 2013

  20. [28]

    Mosek optimization toolbox for matlab,

    M. ApS, “Mosek optimization toolbox for matlab,” User’s Guide and Reference Manual, Version, vol. 4, no. 1, p. 116, 2019

Pith tools

Reviewed August 15, 2026 · model on record in the stance chip above.