Constructive Safety-Critical Control for a Class of Underactuated Systems: A Hierarchical Approach
Listen
Radio episode about this paper
Transcript
Introduction to the show: ident: Robotics Radio. Generated commentary on the latest robotics and control papers.
Rosa: Today's paper: "Constructive Safety-Critical Control for a Class of Underactuated Systems".
Dev: The gist Underactuated systems with nontrivial geometry are abundant in practical robotic problems,
Rosa: First, who's behind it and why it matters.
Title and authors: Rosa: So we're looking at this paper today, "Constructive Safety-Critical Control for a Class of Underactuated Systems: A Hierarchical Approach." It’s about making sure these complex robotic systems stay safe when they have fewer actuators than degrees of freedom.
Dev: Yeah, it tackles the issue of underactuation and nontrivial geometry in practical robot problems, which is where things get tricky because the state space isn't as simple as in fully-actuated systems. This paper proposes a way to find those natural layered architectures based on that geometry.
Taro: I’m curious how they characterize these architectures geometrically, Rosa. Does it mean they’re looking at the shape of the system itself?
Rosa: Exactly, Taro, they do a geometric study to understand when these systems actually have concrete solutions for control design. They develop something called shape maps to help translate those complex underactuation problems into references for the system.
Dev: The authors introduce local shape maps as a smooth map S from some open set U in the tangent space of the manifold, and lemma one shows that these are related to smooth maps f satisfying some condition. This correspondence seems to be a key ingredient for handling underactuation in quadrotor systems, referencing work on ten <ref:2610.10987#pg1>.
Taro: So it’s about transforming control inputs into references for the underactuated system based on this map. That sounds like a way to simplify the control problem at different levels of abstraction.
Rosa: Right, and then they use these architectures to devise a constructive, hierarchical Control Barrier Function synthesis procedure. They break down the safety constraint function h into three distinct layers to build it up constructively.
Dev: The procedure involves first designing a safe kinematic vector field kappa for the lower layer, then designing a controller F-tilde for the virtual model Sigma-tilde G to track that safe field, and finally computing the actual control input F by projecting that onto the full system.
Taro: So it’s like you start with a very simple model to define safety constraints, and then build up complexity layer by layer on top of that? How does this translate to real-world autonomy when things go wrong?
Rosa: That's the point, Taro. The final safety certificate h is constructed as h equals h0 minus the tracking cert from Sigma-tilde G minus the tracking cert from Sigma-S. This setup ensures that if each layer is robust enough, you get a closed-form barrier function that certifies safety for the whole system.
Title and authors: Dev: The paper proves conditions under which this construction works, specifically theorem two provides conditions where h is a certificate of safety even if you aren't using it in an end-to-end filter. It also gives a bound on alpha—the aggression of the kinematic vector field kappa must be limited by the performance of the tracking control laws.
Taro: So, what does that mean practically? If I have this quadrotor, does this method guarantee safety without needing a full model of everything perfectly known?
Rosa: It suggests that if you can get each layer—the kinematic field and the tracking controllers—to be sufficiently robust and performant, the entire system remains safe. The bound on alpha naturally limits how aggressive you can be with those initial kinematic fields based on how well your tracking controls are doing.
Dev: This is interesting because it provides a way to get a closed-form control law from this layered decomposition, which is often hard to do in these underactuated settings. It moves the problem from just finding *a* controller to constructing a specific one based on the geometry of the system.
Taro: I wonder how much robustness we actually need for those layers. If one layer fails, does it cascade into a total failure quickly, or can the next layer compensate?
Rosa: The authors imply that by designing these layers hierarchically based on the system's geometry and using shape maps to bridge the gaps, you’re creating a structure where failures are more localized. You don't necessarily need perfect performance everywhere; you just need enough robustness at each level.
Dev: This is much better than trying to design one giant controller for the whole thing, which is almost impossible with underactuation. It lets us manage the complexity by focusing on smaller, manageable control problems.
Taro: So if we apply this to a complex mobile robot, it means we can design a safety layer for its basic motion and then add another layer specifically to handle the way its arms or sensors interact with the environment?
Rosa: That’s exactly what the paper suggests. The core idea is that studying the geometry of underactuation reveals these natural layers, and using those layers allows us to synthesize a safe control architecture in a structured, constructive way.
Dev: We're looking at this paper, "Constructive Safety-Critical Control for a Class of Underactuated Systems: A Hierarchical Approach," which provides conditions for synthesizing safe control architectures and barrier functions by studying the geometry of underactuation to find natural layered architectures.
Title and authors: Taro: It’s a constructive approach, which is important because it suggests we can actually write down the safety function in closed form, rather than just hoping an iterative solver finds something stable.
Rosa: That’s right. And the results show that if you satisfy those conditions for alpha less than two sigma CG and CS, then the Lie derivative of h for the closed-loop system stays above negative alpha times h on C.
Dev: So, in short, it means we can design these layered systems and get a certified control law without having to solve an intractable optimization problem every single time the system is running.
Taro: I’m just thinking about the application outside of lab settings. Could this framework handle the kind of unpredictable external disturbances that a robot faces on the street or in an uneven terrain?
Rosa: The paper is focused on characterizing when these systems *have* natural layered architectures, which is what makes it useful for practical problems like quadrotors avoiding collisions in real environments. It’s about building the right structure first.
Dev: And one thing they point out as a limitation is that this constructive synthesis relies on assuming each layer of the architecture is already sufficiently robust and performant before you even start, so it's not a magic fix for everything.
Taro: So, we need to make sure our individual components are good before we try to stack them up into this overall safety certificate. That makes sense from a control engineering standpoint.
Rosa: Precisely. The paper gives us the tools—the shape maps and the synthesis procedure—to move away from ad-hoc safety designs toward a systematic construction for these tricky underactuated systems.
Dev: And the final result, theorem two, shows that this hierarchy leads to a closed-form CBF under certain conditions on alpha. That’s the payoff for all that geometric study and layered decomposition work.
Taro: It moves us from just designing controllers to designing structured safety frameworks based on system structure itself. That's a big step for autonomous systems research.
Rosa: So, if you want to read more about this, you can look up "Constructive Safety-Critical Control for a Class of Underactuated Systems: A Hierarchical Approach." It’s a constructive framework for synthesizing safe control architectures and control barrier functions by studying the geometry of their underactuation.
Dev: We'll be moving on to another paper soon, but this one really grounds the theory in how to handle the complexity inherent in systems with underactuation.
The paper's summary: Rosa: So, to wrap up what we just talked about, this paper is basically showing how you can take these tricky underactuated systems—like those quadrotors—and turn them into something where you can actually build a guaranteed safe control law in a structured way.
Dev: Right. It boils down to using geometry to find natural layers in the system's control structure, so instead of trying to solve one massive problem at once, you design simpler problems and stack them up constructively.
Rosa: That constructive synthesis part is key because it means the authors aren't just suggesting an idea; they’re giving us a recipe. They break the safety constraint function down into three distinct layers that you can certify individually.
Dev: I like that layering idea, but what they’re really doing with those shape maps is a geometric bridge. They use these maps to translate the control inputs you actually have—the physical forces—into the references you need for the system that has fewer actuators.
Rosa: Exactly, so it helps with underactuation by mapping what you *want* to do onto what the system can *actually* do, making it easier to design a controller for each sub-system.
Dev: The safety certificate they build, that function h, is constructed by combining the certificates from each of those layers in a specific way. It’s not just one big formula; it's h equals the main constraint minus the tracking cert from layer G minus the tracking cert from layer S.
Rosa: And what’s really impressive here is their final result, theorem two. It shows that if you meet certain conditions on how aggressive those initial kinematic fields are—we call it alpha—then this whole structure results in a valid safety certificate for the full system.
Dev: The caveat they give is that this only works if each of those individual layers is already pretty robust and performing well on its own, which means you can't just throw a weak component into the stack and expect it to work.
Rosa: So, what does this mean for someone who just cares about autonomous systems? It means we can move away from these messy, ad-hoc safety designs toward building control architectures that are structured based on how the system is physically built.
Dev: It lets us get a closed-form barrier function instead of having to run some complex optimization solver every single time the robot is moving. That’s a massive win for loop rates and real-time performance.
Rosa: And it also gives us a way to understand *why* something is safe, by looking at the geometric properties of the system itself rather than just running tests hoping it doesn't crash.
Dev: It’s about moving from reactive safety checks to proactive, structured design based on underlying mathematics and geometry. This moves the complexity around, but only if you can build those initial robust layers correctly.
Rosa: So next time we talk about control theory, we’ll look at how this constructive method applies when the geometry gets even more complicated than simple quadrotors—like a system where the state space is really twisted and hard to visualize.
The paper's improvements: Taro: So we’ve looked at how they build the safety barrier function layer by layer, and now we need to talk about what they suggest as improvements to this whole approach.
Rosa: What I see as a big improvement is that their method gives us a really clear path for when this construction actually works outside of just theoretical equations. They are showing how robust the architecture is when you put it into practice on real robotic platforms.
Dev: Yeah, it moves beyond just proving something exists mathematically to actually showing how stable and effective those layers are when they're running at high loop rates in a physical system. It’s about practical performance numbers, not just abstract existence.
Rosa: Exactly. They’re giving us concrete conditions on the aggression level alpha that you can use as a guide for designing your actual hardware or software constraints. It links the controller's performance directly to the safety margin you get back.
Dev: That’s important because it means we don't just pick an arbitrary number; we have a way to calculate what your kinematic field needs to be based on how good your tracking controllers are doing. It’s a feedback loop in design.
Taro: For autonomy, this implies that if you design these layers properly—if you ensure the S-subsystem and G-subsystem each handle their local constraints well—the whole system gets certified without needing an impossibly detailed model of every single force interaction.
Rosa: That’s the big shift. It suggests a way for complex systems to be safe even when we don't have perfect knowledge of all the underlying physics or when things get disturbed in a messy environment like the field.
Dev: I agree with Taro, it simplifies the control burden significantly because you can focus your effort on making each layer robust instead of trying to design one monolithic controller that handles everything at once.
Rosa: And they are also pointing toward future work where they might explore how this hierarchical decomposition changes when the system starts having more complex non-linear dynamics, which is a natural next step for any real robot.
Dev: Right, and I think we should also keep an eye on how this relates to other learning frameworks like STEAM or RA-VLA; these geometric insights could actually help those learning models predict safety boundaries more accurately in the future.
Conclusion: Rosa: So we’ve covered how this paper, "Constructive Safety-Critical Control for a Class of Underactuated Systems: A Hierarchical Approach," uses geometry to build a structured safety framework for underactuated robots.
Dev: Yeah, it boils down to creating a closed-form barrier function by layering the control problem and using shape maps to bridge the gap between physical inputs and virtual references.
Rosa: The main implication is that we can design certified controllers for complex systems without having to run massive optimization problems every time the robot moves in the real world. It’s about making safety a constructive part of the system design itself.
Dev: Exactly, it shifts the focus from just finding *a* controller to building a specific one based on how well those individual layers are performing under their own constraints. The numbers they give for alpha show exactly when that closed-form certificate holds true.
Taro: I think what this means for autonomy is that we can start designing systems where safety isn't just an afterthought tacked on at the end, but something built into the structure of how we think about underactuation.
Rosa: It changes things because it gives us a systematic way to handle those tricky geometry problems that plague many real-world robotic platforms, especially when they’re dealing with environmental uncertainties.
Dev: I just hope this constructive approach can scale up to systems with even more complex dynamics, because right now the paper is focused on quadrotor-like setups where the decomposition is clearer.
Taro: Definitely, and looking forward to seeing how this kind of geometric decomposition applies when we move into multi-agent systems where multiple underactuated robots need to coordinate their safety layers.
Rosa: Well, that’s our time for this paper on "Constructive Safety-Critical Control for a Class of Underactuated Systems: A Hierarchical Approach." We hope it gives us a solid framework to build safer robots in the field.
Dev: Yeah, it’s a lot of theory and math, but the structured approach is definitely something worth checking out for any control engineer who wants more predictable failure modes.
Taro: It’s a useful tool for thinking about layered safety in AI systems that are moving toward real-world interaction.
Massimiliano de Sa, Aaron D. Ames
eess.SY, cs.SY, math.OC
Submitted: 2026-10-07
Updated: 2026-10-07
The gist: The gist Underactuated systems with nontrivial geometry are abundant in practical robotic problems, and this work provides a constructive framework for synthesizing safe control architectures and
Key concepts
- Underactuated Systems
- These are mechanical systems where the number of actuators (inputs) is less than the number of degrees of freedom (states). This means the system has fewer controls than necessary to fully dictate its motion, making control design more complex because some states cannot be directly controlled.
- Shape Maps
- Shape maps are mathematical tools used to handle underactuation by transforming control inputs into references for the system. A local shape map is a smooth function that relates an open set of force directions (inputs) to a specific shape within the system's force codistribution, helping to manage the lack of full control.
- Hierarchical CBF Synthesis
- This is a step-by-step procedure for creating a safety barrier function. It breaks down the complex safety problem into three layers: designing safe kinematic fields, creating virtual model controllers, and computing final control inputs. This method allows for the construction of a single, closed-form barrier function that ensures safety across all system layers.
- Safety Certificate
- A safety certificate is a mathematical proof that a specific control law guarantees the system will never violate predefined safety constraints. In this work, Theorem 2 provides conditions under which the constructed CBF serves as this certificate for the entire layered architecture.
Terminology
Summary
The gist Underactuated systems with nontrivial geometry are abundant in practical robotic problems, and this work provides a constructive framework for synthesizing safe control architectures and control barrier functions for quadrotor-like underactuated systems by studying their geometry to characterize natural layered architectures.
Motivation and Problem Statement
Underactuated mechanical systems are a class of control systems ubiquitous in modern robotic problems due to their underspecified nature. These systems often have manifold-valued states, compelling controller designs to contend with both underactuation and nontrivial state space geometry. Safety constraints are prevalent in practice, such as quadrotors avoiding collisions with their environment. Control barrier functions (CBFs) are a leading framework for the specification of safety constraints and design of safety-critical controllers. However, less is known about synthesizing CBFs for underactuated cases compared to fully-actuated systems. The research aims to determine how and when a layered architecture can be designed and how safety certificates can be assembled in closed form.
Geometric Characterization and Shape Maps
The authors perform a geometric study of layered control architectures to understand when unknowns have concrete solutions. They develop shape maps as a means of dealing with underactuation and transforming control inputs into references for underactuated systems. A local shape map is defined as a smooth map S: U → S, where U ⊆ T∗G open, satisfying conditions related to actuation and scale-invariance. Lemma 1 establishes that local shape maps are of the form s(f) = S(f), where f is a smooth map satisfying f ∈ as(f). This correspondence provides the main ingredient used in the quadrotor architecture of [10] to manage underactuation.
Hierarchical CBF Synthesis Procedure
The paper proposes a constructive, hierarchical CBF synthesis procedure based on the identified architectures. This procedure involves several steps to produce a closed-form expression for the barrier function h.
The architecture consists of three layers:
-
Design a safe kinematic vector field κ ∈ X(G) for C0.
-
Design a controller F˜ for the virtual model Σ˜ G that tracks the safe vector field κ.
-
Compute the control input F = (F S, F G) to Σ by designing a PD tracking controller F S(vs, vg) for the S-subsystem ΣS and projecting F˜ onto F G.
Safety Certificate Construction
The CBF h is constructed in the form h = h0 − σ(Σ˜ G Tracking Cert.) − λ(ΣS Tracking Cert.). The safety controller for the virtual model tracks a safe vector field κ using a controller F˜ defined by F˜(vg) = ∇G vg κ + grad VGg − ˜kd˜˙e. The tracking controller for the S-subsystem tracks a reference trajectory r defined by r(vg) = S(F˜(vg)) and is designed using a geometric PD controller F S. The final control law FQP is derived by minimizing the norm of the difference between the actual input and the nominal input subject to the safety constraint h˙(vq, Fq) ≥ −α(h(vq)).
Conclusion
Theorem 2 provides conditions under which h is a certificate of safety for the full architecture, even if it is not used in an end-to-end safety filter. The work establishes that provided each layer of the proposed architecture is sufficiently robust and performant, the full control system remains safe and is certified by a closed-form CBF. The bound on α naturally suggests that the aggression of the kinematic vector field κ is limited by the performance of the tracking control laws.
How it works
The system decomposes into a G-subsystem ΣG and an S-subsystem ΣS where underactuation is concentrated in G while S is fully actuated. The virtual model of the trivial SMCS is defined as Σ˜ G = (G,⟨·, ·⟩G, VG, T∗G). The shape map S takes in a force direction and returns a shape at which it belongs to the force codistribution.
Key Results
The existence of local shape maps is reduced to the existence of local Lie shape maps, which are characterized by condition (∗). Theorem 1 establishes conditions establishing the existence of a link—a shape map—between inputs to a virtual system and configurations of the true system. The final result is that if α ≤ min 2σ CG, CS, the Lie derivative of h for the closed-loop system satisfies h˙(vs, vg) > −αh(vs, vg) on C.
References
[1] A. D. Ames, X. Xu, J. W. Grizzle, and P. Tabuada, “Control barrier function based quadratic programs for safety critical systems,” IEEE Trans. Autom. Control, vol. 62, no. 8, pp. 3861–3876, 2016
[2] A. D. Ames, S. Coogan, M. Egerstedt, G. Notomista, K. Sreenath, and P. Tabuada, “Control barrier functions: Theory and applications,” in 2019 18th European control conference, 2019, pp. 3420–3431
[3] T. G. Molnar, R. K. Cosner, A. W. Singletary, W. Ubellacker, and A. D. Ames, “Model-free safety-critical control for robotic systems,” IEEE robotics and automation letters, vol. 7, no. 2, pp. 944–951, 2021
[4] M. H. Cohen, T. G. Molnar, and A. D.
Improvements for AI systems
-
Shape map development for underactuated systems allows for transforming
control inputs into references for underactuated systems
by providing a mechanism to finda map from a force Fg ∈ T∗G to a shape s at which it belongs to the input codistribution.
-
Layered control architecture enables the system to operate on multiple levels of abstraction, allowing the design of controllers for
the simplest model of the system, given by a kinematic reduced-order model κ for Σ on G,
and subsequently tracking this with a controller that computesthe input to the true system by tracking the virtual input.
-
Constructive hierarchical CBF synthesis procedure enables the creation of safety constraints via a function like
h = h0 − σ(Σ˜ G Tracking Cert.) − λ(ΣS Tracking Cert.),
which is certified to satisfy "h˙ > −αh(vs, vg) on C,ensuring that
the full control system remains safe and is certified by a closed-form CBF."
Sources
- Layered Safety: Enhancing Autonomous Collision Avoidance via Multistage CBF Safety Filters
- Control of Complex Maneuvers for a Quadrotor UAV using Geometric Methods on SE(3)
Related papers
- One Request, Multiple Experts: LLM Orchestrates Domain Specific Models via Adaptive Task Routing
- A Geometric Decision Procedure for STL Feasibility and Repair
- Submodular Multi-Agent Policy Learning for Online Distributed Task Allocation in Open Multi-Agent Systems
- Policy-Level Recursive Self-Improvement for Embodied AI with a Criticality World Model
- Minimal Experiments for Robust Stabilization: Information, Spectral Geometry, and Duration
- Decentralized Power-Optimal Coordination for Spacecraft Swarms Using Time-Varying Magnetorquer Actuation