Source-linked AI summary

On the Degree of Safety: Beyond Safe or Unsafe with Control Barrier Functions

Ruoyu Lin, Fabio Pasqualetti, Magnus Egerstedt

arXiv:2609.03319v1eess.SY

TL;DR

The paper addresses the lack of a representation-independent degree of safety beyond CBF-based binary safety indications. It proves that CBF values, gradients, and candidate-constraint feasibility are insufficient, distinguishes intrinsic from representational infeasibility, and introduces IAD to quantify required control authority for controlled invariance.

  • Problem

    CBF values, gradients, and candidate CBF-optimization feasibility do not by themselves provide a representation-independent degree of safety.

  • Method

    The paper analyzes valid CBF representations and candidate-constraint infeasibility, distinguishes intrinsic from representational causes, and introduces the invariance authority demand (IAD).

  • Results

    Valid CBF values and gradients can be arbitrarily modified for the same safe set, while candidate-constraint infeasibility may reflect either non-invariance or representation failure.

  • Takeaways & Limitations

    IAD provides a representation-independent safety degree based on required control authority and can guide set or actuator repair.

Abstract

from arXiv · show

A valid control barrier function (CBF) certifies if its represented safe set can be rendered forward invariant, and the sign of its value indicates whether a state is safe or not, but it does not quantify a degree of safety beyond the binary indication. In this paper, we show that among valid CBFs representing the same safe set, interior values and gradients can be changed arbitrarily, so neither quantity determines a degree of safety that is independent of how the set is represented. We also show that whether a candidate CBF-based inequality constraint is feasible does not by itself quantify a degree of safety. In particular, infeasibility can occur either because the safe set is not controlled invariant or because the candidate CBF representation fails. This motivates our distinction between intrinsic and representational infeasibility. Finally, we introduce the invariance authority demand (IAD), a representation-independent degree of safety that quantifies the control authority required for controlled invariance and can be used to guide set or actuator repair.

I. INTRODUCTION

The paper asks how to quantify degree of safety beyond a CBF’s binary safe/unsafe indication. It argues that CBF values, gradients, and candidate optimization feasibility are representation-dependent or otherwise inconclusive, motivating diagnosis of infeasibility and a control-authority measure.

  • The paper asks how degree of safety should be quantified beyond whether a state lies inside the safe set.
  • Verifying that a continuously differentiable candidate is a valid CBF remains challenging and is outside this paper’s scope.
  • CBF values and gradients cannot provide a representation-independent safety degree because valid CBFs for the same set can assign different values and gradients.
  • Candidate CBF-optimization feasibility is inconclusive: infeasibility can occur when the safe set is not controlled invariant or when the candidate representation fails.
  • The paper distinguishes intrinsic from representational infeasibility to identify whether repair should target the CBF representation, safe set, or controlled system.

II. PRELIMINARIES

The preliminaries define controlled and forward invariance, safe-set representations, and valid CBFs. They then relate the CBF inequality to controller synthesis while distinguishing verified CBF constraints from candidate constraints and defining feasibility diagnostics.

  • Controlled invariance requires an admissible control keeping trajectories in a set, whereas forward invariance concerns a particular closed-loop feedback controller.
  • A safe set is represented by a C1 function whose positive superlevel set is the interior and whose zero level set forms the boundary.
  • A CBF requires an extended class K∞ function α such that the maximum controlled barrier derivative term remains nonnegative throughout the domain.
  • If h is a valid CBF, any locally Lipschitz controller satisfying its CBF inequality renders the safe set forward invariant.
  • CBF optimization provides an efficient synthesis route after h is verified, while an unverified h defines only a candidate CBF-OP and cannot support the same guarantee.
  • Jh,α ≥0 certifies the selected h and α as a valid CBF, whereas Jh,α < 0 indicates candidate-constraint infeasibility somewhere without proving that the safe set lacks controlled invariance.

A. What CBF Values and Gradients Do Not Tell

CBF values and gradients cannot provide a representation-independent degree of safety because valid representations of the same safe set can alter them arbitrarily in the interior. The paper therefore distinguishes geometric safety cues from representation-dependent quantities, including CBF-based reward and derivative terms.

  • Geometric versus dynamical information: Distance to the safe-set boundary can express geometric safety, but it does not account for system dynamics or input constraints, and CBF gradients do not supply representation-independent missing information.The ordering h(xA) > h(xB) need not match boundary-distance ordering across different CBF representations.
  • Representation dependence: Valid CBFs representing the same safe set can have arbitrarily modified values and gradients at any finite collection of interior states.The construction preserves the represented set and agrees with the original CBF near the boundary while changing selected interior values and gradients.
  • Representation dependence: Because interior CBF values and gradients can vary across valid representations, neither quantity alone defines a nontrivial representation-independent degree of safety.Any measure based on h(x) and ∇h(x) must be independent of their interior values and gradients to remain representation-independent.
  • Derivative-based measures: The same representation dependence extends to quantities involving the total CBF derivative, including dot h and dot h + alpha(h), even when system dynamics are incorporated.These quantities depend on representation-dependent interior gradients and therefore do not provide a meaningful representation-independent safety measure.
  • Implications for reward shaping: CBF-guided reinforcement-learning rewards based on CBF values or derivatives do not encode a representation-independent degree of safety and may favor less safe states under boundary-distance interpretations.With strictly increasing value shaping, a state closer to the boundary may receive a larger reward than one farther away.

B. Intrinsic and Representational Infeasibility

The paper separates infeasibility caused by a non-invariant safe set from infeasibility caused by a poor CBF representation, then uses this diagnosis to select the repair direction.

  • Definitions: Intrinsic infeasibility means JC < 0, whereas representational infeasibility means JC ≥ 0 but Jh,α < 0.The former reflects failure of the set under the dynamics and input limits; the latter reflects failure of the selected h and α.
  • Diagnosis: The two-stage diagnosis first tests intrinsic feasibility of the safe set, then assesses representational feasibility only when the set is controlled invariant.This distinguishes whether repair must target the set itself or its CBF representation.
  • Representational infeasibility: When JC ≥ 0 but Jh,α < 0, modifying h or α may repair candidate-constraint infeasibility without changing the controlled-invariant set.Example III.1 shows repair by changing α, while the same set and input constraints remain fixed.
  • Intrinsic infeasibility: If JC < 0, changing h or α cannot repair safety because no representation of the same set can be a valid CBF.Repair must instead modify the safe set when the existing set contains unrecoverable states.
  • Example III.2: In the collision-avoidance example, changing κ only temporarily restored feasibility, while replacing the workspace set with a braking-aware set produced controlled invariance.The original geometric set was not controlled invariant, so tuning the HOCBF parameter could not provide a lasting repair.
  • Scope: Verifying intrinsic or representational infeasibility can be as challenging as verifying that a scalar function is a valid CBF.The paper identifies the appropriate diagnosis and repair direction rather than providing a universal verification or repair algorithm.

C. A Control Authority-Based Degree of Safety

The invariance authority demand (IAD) provides a representation-independent safety measure based on the control authority required to maintain controlled invariance. Its setwise form also quantifies actuator scaling and guides safe-set repair.

  • The pointwise IAD measures control authority demand relative to full actuator capability at a boundary state, accounting for set and actuator geometry.
  • The pointwise and setwise IAD depend only on the safe set, dynamics, and admissible inputs, so they remain unchanged across CBF representations.
  • The geometry of the admissible-input set determines how directional control authority is measured, inducing weighted L1, L2, or L∞ norms for box, ellipsoidal, or diamond-shaped inputs.
  • ΓC ≤ 1 indicates controlled invariance, while ΓC > 1 quantifies the additional control-authority scaling needed to make C controlled invariant.
  • If the safe set is fixed, ΓC gives the minimum actuator-authority scaling; if actuators are fixed, IAD guides repair of the safe set.
  • For the example system, repair reduces the set along directions with stronger outward drift or weaker control authority while preserving directions with greater authority.

IV. CONCLUSION

The paper argues that CBF values, gradients, and candidate optimization feasibility do not independently quantify safety beyond a binary statement. It distinguishes intrinsic from representational infeasibility and proposes IAD as one representation-independent measure.

  • CBF values, gradients, and candidate CBF-OP feasibility do not by themselves provide a quantitative, representation-independent degree of safety.
Loading 2609.03319v1…