Papers
Topics
Authors
Recent
Search
2000 character limit reached

Readiness Barrier Functions: Forward-Invariant Control Authority for Overactuated Multirotor Allocation

Published 17 Aug 2026 in cs.RO, eess.SY, and math.OC | (2608.16335v1)

Abstract: Allocation schemes that greedily maximize a readiness metric over the actuator fiber bundle of an overactuated multirotor produce commands that jump between disconnected optimal strata, demanding actuator rates no motor can deliver; effort-minimizing schemes are continuous but cannot guarantee that wrench-rate authority stays above any certified level. We reconcile the two by treating authority as a forward-invariant quantity: a control barrier function on the log-determinant of the drag-aware actuator-authority co-metric, enforced at torque level by a quadratic program in the allocation null space. A single design inequality renders the certified set compact and strictly interior to the actuator box, with the readiness cost of any rotor deactivation given in closed form as ln(n/(nm))\ln(n/(n{-}m)) for symmetric designs. Tracking is sacrificed only through an explicit alignment ratio, with wrench error bounded by O(ρ<sup>1/2)\mathcal{O}(ρ<sup>{-1/2}) and a robust variant handles motor-parameter uncertainty with a closed-form floor shift independent of the airframe matrix. On a hexarotor and a fully-actuated octorotor the closed-form gap matches simulation to machine precision; in the authority-scarce regime greedy maximization violates the certified floor and commits wrench errors up to eighty times larger than the proposed filter, which holds invariance of the certified set at negligible tracking cost.

Authors (1)

Summary

  • The paper introduces a null-space quadratic-programming filter that treats the readiness log-determinant as a control barrier function, guaranteeing forward invariance of a certified authority set while maintaining wrench tracking.
  • It derives a closed-form dropout gap, showing that symmetric platforms lose ln(n/(n−m)) nats of readiness when a rotor crosses zero; for a six-rotor, four-wrench system, the penalty is approximately 1.10 nats.
  • Simulations show the proposed filter maintains positive authority with near-zero violation time and far lower wrench error than greedy or low-pass DAAM allocation, while robust certificates account for torque, drag, and delay uncertainty.

Problem statement and motivation

Overactuated multirotors—tilted-propeller hexarotors, fully actuated octorotors, omnidirectional platforms—possess more rotors than wrench dimensions, so at every instant a continuum of rotor-speed vectors produces the commanded wrench. Classical allocation resolves this redundancy by minimizing actuator effort via constrained least-squares or linear programming [Johansen2013allocation, Bodson2002allocation], which handles control authority only implicitly through the feasible set. The paper's starting observation is that the physically meaningful quantity is wrench-rate authority: because thrust and drag both scale quadratically with spin, a slow rotor has vanishing thrust slope while a saturated rotor has spent its torque budget on drag. Authority therefore peaks at an interior operating point and collapses at both ends of the speed range, in two geometrically distinct modes—an anisotropic collapse when a single rotor stops (destroying directional authority) and an isotropic collapse near saturation (shrinking the entire achievable wrench-rate ellipsoid).

Recent work formalizes this through Drag-Aware Aerodynamic Manipulability (DAAM), whose log-determinant measures the remaining wrench-rate volume and is maximized along the allocation fiber [Franchi2026aeropromptness]. That framework, however, leaves open a structural defect: the fiberwise maximizer is set-valued, with optimal selections lying on disconnected sheets of the 2n2^n sign orthants induced by the signed-quadratic thrust map. Crossing between orthants requires passing through zero spin, where the allocation Jacobian degenerates and the actuator rate needed to sustain a bounded wrench rate diverges. Greedy maximization thus violates the very authority level it was designed to protect whenever a crossing becomes necessary.

The paper's central position is that control authority should be certified rather than greedily maximized. It treats the readiness log-determinant as a control barrier function (CBF) [Ames2017CBFQP], floored at the torque level by a quadratic program (QP) acting in the allocation null space, so that forward invariance of a certified-authority set replaces pointwise optimality.

Modeling and the readiness metric

The vehicle with nn rotors produces a wrench w=Aϕ(v)w = A\phi(v) where ϕ(v)=vv\phi(v)=v\odot|v| is the signed-quadratic thrust map and ARm×nA\in\mathbb{R}^{m\times n} is full row rank. Each rotor obeys first-order dynamics miv˙i=bivivi+τim_i\dot v_i=-b_iv_i|v_i|+\tau_i under torque limits, giving a symmetric acceleration capacity

ai(vi)=τimaxbivi2mi,a_i(v_i)=\frac{\tau_i^{\max}-b_iv_i^2}{m_i},

which vanishes at saturation speed visat=τimax/biv_i^{\mathrm{sat}}=\sqrt{\tau_i^{\max}/b_i}. Weighting the allocation Jacobian J(v)=2Adiag(v)J(v)=2A\,\mathrm{diag}(|v|) by these capacities yields the drag-aware authority co-metric D(v)=4AΨ(v)AD(v)=4A\Psi(v)A^\top with nn0, whose determinant is the log-volume of deliverable wrench rates:

nn1

The paper argues a floor on nn2 is informative three ways: as omnidirectional volume, as a worst-case radius along every wrench-rate axis (via a lower bound on nn3), and as a conditioning measure—a trace criterion misses a collapsed axis while nn4 ignores retained directions. The certified set is nn5 with nn6 for a floor nn7.

Readiness geometry and the dropout gap

The theoretical core begins with a closed-form characterization of what orthant crossing costs. The gradient of nn8 vanishes exactly at nn9 and at the sweet spot w=Aϕ(v)w = A\phi(v)0—roughly 58% of saturation, where drag consumes one third of the torque budget—and w=Aϕ(v)w = A\phi(v)1 attains its global maximum at the w=Aϕ(v)w = A\phi(v)2 sweet-spot configurations, one per sign orthant. Because w=Aϕ(v)w = A\phi(v)3 is even in w=Aϕ(v)w = A\phi(v)4, all orthants are equally ready, so the greedy selector has no tiebreaker and may jump when strata exchange dominance.

The Dropout Gap theorem quantifies the penalty: deactivating rotor w=Aϕ(v)w = A\phi(v)5 costs exactly w=Aϕ(v)w = A\phi(v)6, where w=Aϕ(v)w = A\phi(v)7 is the capacity-weighted leverage score of rotor w=Aϕ(v)w = A\phi(v)8. Three consequences are notable. First, w=Aϕ(v)w = A\phi(v)9 if and only if rotor ϕ(v)=vv\phi(v)=v\odot|v|0 is essential (ϕ(v)=vv\phi(v)=v\odot|v|1). Second, ϕ(v)=vv\phi(v)=v\odot|v|2, so leverage scores partition the wrench dimensions among rotors. Third, for symmetric designs ϕ(v)=vv\phi(v)=v\odot|v|3 and

ϕ(v)=vv\phi(v)=v\odot|v|4

a function of the redundancy ratio alone—for a hexarotor (ϕ(v)=vv\phi(v)=v\odot|v|5, ϕ(v)=vv\phi(v)=v\odot|v|6), each crossing costs ϕ(v)=vv\phi(v)=v\odot|v|7 nats regardless of size, propeller, or payload. This closed form matches simulation to machine precision on both testbeds. Importantly, the gap depends on physical capacities, not ϕ(v)=vv\phi(v)=v\odot|v|8 alone: with ±30% spread in ϕ(v)=vv\phi(v)=v\odot|v|9 the true gaps scatter to ARm×nA\in\mathbb{R}^{m\times n}0 nats against a uniform geometric value of 1.099—a 0.9-nat error that can void the guarantee if capacities are assumed uniform.

Certified safe set and forward invariance

A single design inequality ARm×nA\in\mathbb{R}^{m\times n}1 (the dropout level) makes one scalar barrier fence both failure modes simultaneously. Under assumptions A1–A3, the certified set ARm×nA\in\mathbb{R}^{m\times n}2 is compact, strictly interior to the actuator box, has full-rank Jacobian everywhere, and admits a uniform lower bound on ARm×nA\in\mathbb{R}^{m\times n}3—so trajectories in ARm×nA\in\mathbb{R}^{m\times n}4 automatically respect actuator limits with no auxiliary saturation logic. A viability lemma based on the symmetric acceleration capacity shows the CBF admissible set is never empty; this hinges on weighting by the symmetric capacity rather than the asymmetric braking margin, since acceleration-to-deceleration capability approaches 50:1 near saturation.

The allocation filter is a QP minimizing deviation from a nominal torque command subject to the barrier row ARm×nA\in\mathbb{R}^{m\times n}5, the tracking row ARm×nA\in\mathbb{R}^{m\times n}6, and torque limits, with slack ARm×nA\in\mathbb{R}^{m\times n}7 absorbing genuine conflicts. Under a uniform Slater condition the minimizer is unique and locally Lipschitz, and the main invariance theorem guarantees that any trajectory starting in ARm×nA\in\mathbb{R}^{m\times n}8 remains there—in its initial sign-orthant component—for all time, for the modeled dynamics. The filter never evaluates the set-valued fiberwise argmax; it produces a continuous selection via strong convexity.

Two caveats qualify the guarantee. Invariance is proved in continuous time; under zero-order hold the barrier may dip by ARm×nA\in\mathbb{R}^{m\times n}9 per step, negligible at kilohertz rates but nonzero. And certifiability is a property of the task–vehicle pair: if the floor exceeds the mission-dependent worst-case achievable readiness miv˙i=bivivi+τim_i\dot v_i=-b_iv_i|v_i|+\tau_i0, the certified set intersects some commanded fiber emptily and no allocator can hold the floor while tracking—a drone commanded near its thrust ceiling may have no certifiable floor.

Tracking bounds and robustness

Whether exact tracking coexists with the floor is governed by an alignment ratio miv˙i=bivivi+τim_i\dot v_i=-b_iv_i|v_i|+\tau_i1 measuring how far the configuration is from the zero-sum regime. On symmetric platforms at near-uniform spin, miv˙i=bivivi+τim_i\dot v_i=-b_iv_i|v_i|+\tau_i2 lies in the range of miv˙i=bivivi+τim_i\dot v_i=-b_iv_i|v_i|+\tau_i3, so null-space redistribution cannot recover readiness—the exchange cancels identically, confirmed numerically to miv˙i=bivivi+τim_i\dot v_i=-b_iv_i|v_i|+\tau_i4. When the alignment condition fails, the wrench error obeys an ultimate bound of miv˙i=bivivi+τim_i\dot v_i=-b_iv_i|v_i|+\tau_i5 in the relaxation weight miv˙i=bivivi+τim_i\dot v_i=-b_iv_i|v_i|+\tau_i6: quadrupling miv˙i=bivivi+τim_i\dot v_i=-b_iv_i|v_i|+\tau_i7 halves the steady-state error. The filter thus trades a small persistent tracking error for elimination of an impulsive one at authority collapse.

For parametric uncertainty in torque limits and drag coefficients, the robust variant separates two effects the paper argues must not be conflated: bounding the metric is not bounding its derivative. A worst-case vertex analysis collapses the miv˙i=bivivi+τim_i\dot v_i=-b_iv_i|v_i|+\tau_i8 parameter box to the doubly degraded corner miv˙i=bivivi+τim_i\dot v_i=-b_iv_i|v_i|+\tau_i9, yielding a tightened barrier row whose drift term costs a single ai(vi)=τimaxbivi2mi,a_i(v_i)=\frac{\tau_i^{\max}-b_iv_i^2}{m_i},0 pass. The price of robustness is exact and airframe-independent:

ai(vi)=τimaxbivi2mi,a_i(v_i)=\frac{\tau_i^{\max}-b_iv_i^2}{m_i},1

so on an ai(vi)=τimaxbivi2mi,a_i(v_i)=\frac{\tau_i^{\max}-b_iv_i^2}{m_i},2 platform the retained authority volume is 44%, 18%, and 7% at ai(vi)=τimaxbivi2mi,a_i(v_i)=\frac{\tau_i^{\max}-b_iv_i^2}{m_i},3. Since torque enters cubically, torque calibration is roughly ai(vi)=τimaxbivi2mi,a_i(v_i)=\frac{\tau_i^{\max}-b_iv_i^2}{m_i},4 more valuable per unit relative error than drag calibration. For transport delay, a worst-case undershoot bound ai(vi)=τimaxbivi2mi,a_i(v_i)=\frac{\tau_i^{\max}-b_iv_i^2}{m_i},5 yields a certified delay ceiling beyond which the tightened constraint set is empty.

Simulation results

Two platforms are studied: a planar hexarotor (ai(vi)=τimaxbivi2mi,a_i(v_i)=\frac{\tau_i^{\max}-b_iv_i^2}{m_i},6, ai(vi)=τimaxbivi2mi,a_i(v_i)=\frac{\tau_i^{\max}-b_iv_i^2}{m_i},7) and a fully actuated tilted octorotor (ai(vi)=τimaxbivi2mi,a_i(v_i)=\frac{\tau_i^{\max}-b_iv_i^2}{m_i},8, ai(vi)=τimaxbivi2mi,a_i(v_i)=\frac{\tau_i^{\max}-b_iv_i^2}{m_i},9), both with motor parameters anchored to UIUC wind-tunnel data, integrated at 1–2 kHz with OSQP solving the QPs. Four allocators are compared: effort-minimizing QP, greedy DAAM, low-pass-filtered DAAM, and the proposed filter.

Collective Metric Effort-min Greedy DAAM Low-pass DAAM Proposed
0.7 visat=τimax/biv_i^{\mathrm{sat}}=\sqrt{\tau_i^{\max}/b_i}0 +0.08 −0.54 −0.54 +0.12
0.7 RMS wrench error 0.0003 0.145 0.147 0.0018
0.8 visat=τimax/biv_i^{\mathrm{sat}}=\sqrt{\tau_i^{\max}/b_i}1 +0.22 −0.48 −0.48 +0.22
0.8 RMS wrench error 0.0003 0.113 0.114 0.0003

In the authority-scarce regime (collective 0.7–0.8), greedy DAAM violates the floor it maximizes, with total variation spiking to 31.5—an order of magnitude above the continuous allocators—as each stratum handover slams motors against their limits. The resulting RMS wrench error reaches eighty times that of the proposed filter. Low-pass filtering illustrates why rate bounding is insufficient: it does reduce peak commanded rate from 731 to 14.6 s⁻², but the filtered reversal traverses the same distance through actuator space slowly, stretching dwell below the floor to 0.756 s versus 0.629 s unfiltered—a rate hazard exchanged for an exposure hazard. The proposed filter achieves peak rate 0.5 s⁻² with zero violation time. Above collective 0.9 the optima stop exchanging dominance, all allocators coincide, and the filter reproduces its nominal command exactly.

Monte-Carlo mission sweeps confirm the effect is not adversarial: in the scarce corner greedy DAAM violates the floor in 80% of missions with wrench error visat=τimax/biv_i^{\mathrm{sat}}=\sqrt{\tau_i^{\max}/b_i}2 versus visat=τimax/biv_i^{\mathrm{sat}}=\sqrt{\tau_i^{\max}/b_i}3 for the filter, which holds strictly positive authority—greedy and low-pass are dominated on both axes simultaneously.

The robustness campaign isolates the drift term's necessity. The nominal certificate enforced on mismatched plants fails on 38% of plants at visat=τimax/biv_i^{\mathrm{sat}}=\sqrt{\tau_i^{\max}/b_i}4 and 50% at visat=τimax/biv_i^{\mathrm{sat}}=\sqrt{\tau_i^{\max}/b_i}5–30%, while the uncertified effort-minimizing QP fails on 88% everywhere. An ablation with the metric bound alone still fails on 38% at visat=τimax/biv_i^{\mathrm{sat}}=\sqrt{\tau_i^{\max}/b_i}6—bounding a function is not bounding its derivative—whereas restoring the closed-form drift returns violations to zero and cuts wrench error fourfold. Delay sweeps show deterministic protection below the certified ceiling visat=τimax/biv_i^{\mathrm{sat}}=\sqrt{\tau_i^{\max}/b_i}7 ms, mild degradation up to ~100 ms (the 30–50× gap reflecting a worst-case constant attained only under maximally damaging simultaneous acceleration), and failure beyond.

Limitations and open questions

Three boundaries delimit the guarantees, stated plainly by the author. The certificates rely on the quasi-static drag model visat=τimax/biv_i^{\mathrm{sat}}=\sqrt{\tau_i^{\max}/b_i}8; in fast forward flight inflow makes visat=τimax/biv_i^{\mathrm{sat}}=\sqrt{\tau_i^{\max}/b_i}9 state-dependent, absorbed by Theorem 4 only as bounded ±J(v)=2Adiag(v)J(v)=2A\,\mathrm{diag}(|v|)0 variation, so large aerodynamic excursions warrant online estimation of J(v)=2Adiag(v)J(v)=2A\,\mathrm{diag}(|v|)1. Invariance is proved in continuous time, with sampled-data error bounded but not eliminated except by discrete-time CBF methods that incur nonconvex per-step checks. Feedback noise in measured speeds enters the constraint row directly, tolerated only by the strict-interior margin. No flight validation is claimed; physical effects that deform J(v)=2Adiag(v)J(v)=2A\,\mathrm{diag}(|v|)2 in flight remain unmodeled. Open questions include whether online adaptation of the parameter box J(v)=2Adiag(v)J(v)=2A\,\mathrm{diag}(|v|)3 can recover part of the exact robustness price, and how the certifiable window behaves for aggressive missions where J(v)=2Adiag(v)J(v)=2A\,\mathrm{diag}(|v|)4 approaches the dropout level.

Conclusion

The paper reframes multirotor control authority from an optimization objective to a certified, forward-invariant property, enforced by a null-space QP over a log-determinant barrier. It contributes a closed-form dropout gap J(v)=2Adiag(v)J(v)=2A\,\mathrm{diag}(|v|)5 for symmetric designs, compactness and strict interiority of the certified set from a single design inequality, an explicit alignment condition separating exact tracking from an J(v)=2Adiag(v)J(v)=2A\,\mathrm{diag}(|v|)6-bounded relaxation, and a robust variant whose cost is known in closed form before flight. Simulations show the greedy maximizer violating its own certified floor precisely in the authority-scarce regime where certification matters most, while the proposed filter holds invariance at negligible tracking cost.

Paper to Video (Beta)

No one has generated a video about this paper yet.

Whiteboard

No one has generated a whiteboard explanation for this paper yet.

Open Problems

We found no open problems mentioned in this paper.

Tweets

Sign up for free to view the 1 tweet with 0 likes about this paper.