Communication-Aware Synthesis of Safety Controller for Networked Control Systems

arXiv:2603.29392 · eess.SY, cs.SY · Submitted 2026-03-31 · Read on arXiv

Listen

Radio episode about this paper

Transcript

Introduction to the show: ident: Robotics Radio. Generated commentary on the latest robotics and control papers.

Rosa: Today's paper: "Communication-Aware Synthesis of Safety Controller for Networked Control Systems".

Dev: Networked control systems (NCS) are widely used in safety-critical applications, but they are often analyzed under the assumption of ideal communication channels.

Rosa: First, who's behind it and why it matters.

Paper summary: Rosa: So, to recap where we are, this paper proposes a communication-aware co-design framework that integrates communication uncertainty into safety controller synthesis by leveraging its intrinsic dependence on the feedback controller without explicitly modeling the imperfect communication channel.

Dev: The core claim is that they derive the system state error bound induced by imperfect communication and state estimation without needing to model the actual physical channel structure. This allows them to formulate a Robust Safety Invariant set that tolerates both those communication-induced errors and external disturbances.

Taro: What matters here is that they are able to compute this error bound based on the uplink communication error bound, epsilon up, which is derived from the Kalman filter structure with process noise Q and measurement noise R.

Rosa: That derivation leads to a computable system state error bound epsilon, which they find by incorporating epsilon up into the closed-loop error dynamics, where they state that if squared one then the squared norm of the error e(k) is less than or equal to this bound for all k <ref:2603.29392#pg1>.

Dev: They further establish that this bound is computable by solving a semi-definite programming problem, and they achieve this by setting:= sqrt kappa rho, with kappa between zero and one, and rho between one and one/kappa, ensuring the condition for boundedness from Theorem two holds <ref:2603.29392#pg1>.

Taro: It seems the crucial part is establishing that coupling between the controller design and the state error on the system induced by communication channel introduces extra challenges to synthesizing a communication-aware controller, which they address by formulating it as a problem where they design both at once.

Rosa: It’s about moving away from analyzing systems under ideal conditions and creating a method that works even when the network isn't perfect, which is what makes this paper relevant for real-world field robotics applications.

Dev: The authors claim their key contributions are deriving the system state error bound without modeling the channel, formulating an RSI set that tolerates those errors and disturbances, and developing a co-design framework that integrates communication error analysis with controller synthesis.

Taro: So, it’s not just about making the controller better; it’s about building a safety guarantee around the control system considering its communication limitations from the start.

Rosa: That's right; this paper shows how to achieve that safety guarantee using an LMI-based method formulated as semi-definite programming to jointly compute the RSI set and design the controller.

Conclusion: Dev: Thinking about "Communication-Aware Synthesis of Safety Controller for Networked Control Systems," the paper by Liu, Tian, Yan, Zhong, and their team is essentially providing a structured way to handle safety when communication isn't perfect in networked systems.

Rosa: It moves the analysis away from assuming perfect channels and instead focuses on how errors in state estimation due to imperfect communication directly impact the controller design itself through that coupled error term e(k).

Taro: The implication for autonomy is huge because it means we can design autonomous systems that are inherently safe even when they're communicating over unreliable links, as long as we can bound those communication errors effectively.

Dev: Specifically, it gives a practical methodology to construct an ellipsoidal robust safety invariant set and verify its robustness using LMI constraints solved via semi-definite programming problems.

Rosa: In simple terms, this means for field robots or any safety-critical system relying on networked control, you can design a controller that is guaranteed to keep the system within a safe boundary even when the communication is dropping packets or introducing delays.

Taro: I see it as enabling more reliable deployment in environments where network quality fluctuates significantly, moving beyond lab settings into truly uncertain operational zones.

Dev: The paper suggests that this co-design approach allows engineers to simultaneously find the best controller gain and the most conservative safety envelope, balancing communication efficiency with safety assurance.

Rosa: It’s about making sure that as you optimize for control performance, you don't accidentally compromise the system's fundamental safety by ignoring its communication constraints.

Taro: I think this work has significant implications for how we approach the design of autonomous systems in real-world settings where communication is an inherent and unavoidable uncertainty.

The Thrust of Artificial Intelligence, Information Hub, Hong Kong University of Science and Technology (Guangzhou) · The Thrust of Intelligent Transportation, System Hub, Hong Kong University of Science and Technology (Guangzhou)

eess.SY, cs.SY

Submitted: 2026-03-31

Updated: 2026-10-02

License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/

Importance score: 73/100

The gist: Networked control systems (NCS) are widely used in safety-critical applications, but they are often analyzed under the assumption of ideal communication channels.

Key concepts

Ellipsoidal Robust Safety Invariant (RSI) Sets
These are geometric shapes that define a safe region in the system's state space. The paper uses ellipsoids to create a robust safety boundary that guarantees the system will remain within this safe zone, even when facing external disturbances and communication errors.
Linear Matrix Inequalities (LMI)
LMIs are mathematical constraints used to verify if a desired property, like safety or stability, holds for a given controller design. The paper formulates the safety requirements as LMIs and solves them using semi-definite programming (SDP) to find feasible solutions.
System State Error Bound ($\epsilon$)
This is a quantifiable measure of how much the actual system state can deviate from its ideal model due to communication imperfections. The paper derives a specific bound for this error based on the uplink communication error, which is crucial for setting the size of the safety region.
Semi-Definite Programming (SDP)
SDP is a powerful mathematical optimization technique used to solve complex problems involving matrices and quadratic forms. It is employed here to find the optimal controller parameters and verify the invariance conditions for the safety sets in a convex manner.

Terminology

Summary

Networked control systems (NCS) are widely used in safety-critical applications, but they are often analyzed under the assumption of ideal communication channels. This work focuses on synthesizing safety controllers for discrete-time linear systems affected by unknown disturbances operating in imperfect communication channels, guaranteeing safety by constructing ellipsoidal robust safety invariant (RSI) sets and verifying their invariance through linear matrix inequalities (LMI).

The gist

The proposed method guarantees safety by constructing ellipsoidal robust safety invariant (RSI) sets and verifying their invariance through linear matrix inequalities (LMI), which are formulated and solved as semi-definite programming (SDP), simultaneously considering controller synthesis and communication errors without requiring explicit modeling of the communication channel.

System Model and Error Characterization

The paper considers a discrete-time linear system described by the equation:

x(k + 1) = Ax(k) + Bu(k) + d(k), k ∈ N, where A is the system matrix, B is the input matrix, x(k) is the state of the system, u(k) is the control input, and d(k) denotes external disturbance. The control input is defined as u(k):= Kxˆ(k), where xˆ(k) is the estimated state produced by a Kalman filter influenced by communication channels and estimation errors. Due to imperfections like packet drops or time delays, an uplink communication error eup(k) is introduced, characterized by eup(k):= ˆx(k) − x(k). Substituting these into the system dynamics generates the closed-loop equation: x(k + 1) = (A + BK)x(k) + BKeup(k) + d(k). This leads to defining the system state error induced by imperfect communication and state estimation as e(k):= BK eup(k), which belongs to the bounded set ∆(ε), where ε is the system state error bound.

Communication Error Bound Analysis

The objective of this section is to derive a system state error bound ε based on the uplink communication error bound εup. The analysis begins by defining a Kalman filter structure with process noise Q and measurement noise R, and defines the conservative process uncertainty covariance Q¯:= Q + γIn. Theorem 1 establishes that the error covariance Pk of the Kalman filter has an upper bound Pk ⪯ p¯kIn, where p¯k is recursively defined. By applying a standard notion of exponential boundedness (Definition 2), Theorem 2 provides a computable bound for the uplink communication error: εup = (¯p0g¯ squared + q¯ 1 − g¯ 2)χ 2n, 1−δ, where δ is a design parameter. This bound is independent of real-time measurement data and depends on the closed-loop matrix G = A + BK.

System State Error Bound Derivation

The system state error bound ε is then computed by incorporating the uplink communication error bound εup into the closed-loop error dynamics (8). Theorem 3 states that if ¯g squared ≤ 1, then e(k)⊤e(k) ≤ ε for all k ∈ N, where ε = (¯g + A2) 2εup. This bound is computable by solving a semi-definite programming (SDP) problem. The key insight is that the coupling between the controller and the state error is handled by setting ¯g:= √κρ, with κ ∈ (0, 1] and ρ ∈ [1, 1/κ], ensuring that the condition for boundedness in Theorem 2 is satisfied.

LMI-Based Controller Synthesis

The core of the framework involves translating invariance conditions into a convex optimization problem (OP) using LMI constraints. The goal is to design a safety envelope S = M−1 and a state-feedback controller u = F L−1xˆ, where F:= KL. The optimization problem OP seeks to minimize-log(det(L)) subject to several constraints:

  1. Contraction and Invariance: κL L⊤A⊤ + F⊤B A L + BF L ⪰ 0, and αI ≤ L (where α is defined based on γ, ε, and κ).

  2. Set Inclusion: cjLc⊤j ≤ 1 for all state constraints cj.

  3. Input Constraints: Constraints involving umax and the communication error set ∆(ε) are enforced through auxiliary variables τi and U, which are relaxed to ensure convexity by imposing U ⪯ λmin(L) 2W.

Co-design Framework and Case Study

The framework is implemented via Algorithm 1, which iteratively searches over contraction parameters κ and scaling parameters ρ to solve OP. This joint design achieves a "balanced tradeoff between communication efficiency and safety assurance.

Improvements for AI systems

Here are the specific improvements to AI systems derived from this scientific paper, focusing on integrating robust safety guarantees under imperfect communication:

  1. Effective Safety Controller Synthesis for Networked Control Systems (NCS):

The primary improvement is the ability to design a state-feedback controller that formally guarantees system safety even when communication channels are unreliable (packet drops, time delays). This moves AI control systems from merely being stable to being provably safe.

  1. Robustness Against Communication Imperfections:

AI systems will be capable of operating reliably in real-world cyber-physical environments where sensor data transmission is noisy or intermittent. The system can handle:

  • Packet Loss and Time Delays: The controller explicitly accounts for delayed or missing state information by bounding the resulting estimation error.

  • Bandwidth Limitations and Quantization Errors: By incorporating these as bounded uncertainties, the controller maintains safety margins even when communication bandwidth is constrained or data is quantized (as demonstrated in the cruise control case study).

  1. Co-Design of Communication Efficiency and Safety:

The proposed framework allows for a simultaneous optimization of two conflicting goals: maintaining high safety assurance and minimizing communication overhead.

  • The system can determine the optimal controller gain matrix (K) and the required safety region (M) that satisfies both state constraints and communication limits simultaneously, leading to a more efficient control law than methods that optimize them separately.
  1. Formal Safety Guarantees via Robust Invariant Sets (RSI):

The core mechanism is the construction of an ellipsoidal Robust Safety Invariant Set (RSI set), defined by the LMI formulation in Problem 1.

  • The AI controller's objective is to ensure that regardless of bounded external disturbances and the computed communication/estimation errors, the system state trajectory remains strictly within this pre-defined safe region. This provides a mathematically rigorous safety envelope rather than heuristic performance guarantees.
  1. Adaptive Safety Margin Management:

The iterative search framework (Algorithm 1) allows the system to dynamically tune its robustness parameters based on communication uncertainty bounds.

  • The AI controller can adapt the size and shape of its safety set (via M) and control gain (K) in response to the estimated level of communication imperfection, ensuring that the safety margin is precisely what is needed for a given network condition, leading to optimal use of resources.
  1. System State Error Bounding:

The framework provides a computable upper bound on the actual system state error induced by the combination of communication errors and estimation inaccuracies.

  • This allows for proactive monitoring: If real-time monitoring indicates that the current state error exceeds this derived bound, it signals an imminent safety violation before it occurs, enabling faster emergency maneuvers or communication recovery protocols.
  1. Applicability to Complex Systems (Cruise Control Analogy):

The methodology is demonstrated on a complex system (truck/trailer dynamics) with multiple simultaneous channel imperfections (packet loss, quantization, delay).

  • The improved AI controller can manage highly coupled systems where various communication failures occur concurrently without losing formal safety guarantees.

Sources

Related papers