Papers
Topics
Authors
Recent
Search
2000 character limit reached

Backup Control Barrier Functions

Updated 14 July 2026
  • Backup Control Barrier Functions (bCBFs) are trajectory-based safety certificates that use backup controllers and safe sets to guarantee safety over a finite horizon.
  • They leverage forward simulation and smoothing techniques to manage nonsmooth min-operators and sensitivity computations under actuator limits.
  • Recent extensions include robust formulations, learning-based backup synthesis, and projections for mixed state-input constraints, expanding their practical applications.

Backup Control Barrier Functions (bCBFs) are trajectory-based safety certificates for control-affine systems with bounded inputs that construct an implicitly defined control invariant set from a backup controller and a backup-safe set. Instead of certifying safety only from the instantaneous state, a bCBF asks whether the state can evolve under a prescribed backup policy for a finite horizon while remaining in the safe set and reaching a terminal backup set that is itself forward invariant. This construction makes bCBFs especially relevant when standard CBF inequalities become infeasible under actuation limits, but it also introduces distinctive issues—most notably nonsmooth min-operators, flow-sensitivity computations, and dependence on the backup design—that have motivated a substantial recent literature on smoothing, robustness, aggregation, learning, and computational simplification (Chen et al., 2021, Alan et al., 17 Nov 2025).

1. Core construction and mathematical setting

For a control-affine system

x˙=f(x)+g(x)u,\dot{x} = f(x) + g(x)u,

a standard safe set is given by the superlevel set of a differentiable barrier hh. The bCBF construction augments this with a backup-safe set Sb={xhb(x)0}S_b=\{x\mid h_b(x)\ge 0\} and a backup controller ub(x)u_b(x), then studies the closed-loop backup flow generated by

x˙=Fb(x)f(x,ub(x)).\dot{x}=F_b(x)\triangleq f(x,u_b(x)).

A canonical finite-horizon backup barrier is defined by the minimum safety margin along the backup trajectory together with the terminal backup-set margin: hT(x)min{minτ[0,T]h(ϕ(x,τ)), hb(ϕ(x,T))}.h_T(x) \triangleq \min\Big\{ \min_{\tau\in[0,T]} h\big(\phi(x,\tau)\big),~h_b\big(\phi(x,T)\big) \Big\}. Its zero superlevel set contains precisely those states from which the backup policy stays safe over [0,T][0,T] and reaches the backup set at time TT (Alan et al., 17 Nov 2025).

This same idea appears in equivalent formulations based on constrained reachable sets. A tutorial treatment defines

S  =  R(S0,C,fπ,T)\mathcal{S} \;=\; \mathcal{R}(\mathcal{S}_0,\mathcal{C},f_\pi,T)

as the set of states that, under a fixed backup policy π\pi, remain in the safe set hh0 for the whole horizon and reach a known invariant set hh1 at time hh2. That set is control invariant, satisfies hh3, and is monotonically nondecreasing with the horizon hh4 (Chen et al., 2021).

In implementation, the horizon is usually discretized, so the continuous-time minimum becomes a minimum over time-indexed “slice” constraints hh5. This yields a nonsmooth composite barrier

hh6

and the online safety filter enforces either the composite CBF constraint directly, when that is tractable, or sufficient slice-wise inequalities of the form

hh7

For affine-in-control systems, these conditions are embedded in a quadratic program that minimally modifies a desired input while respecting input bounds (Alan et al., 17 Nov 2025).

A notable structural result is that, under mild assumptions, the backup CBF construction “always has a relative degree 1.” The key mechanism is that the current control enters the derivative of the composed functions hh8 and hh9 through flow sensitivities, so high-order backstepping is not required merely because the barrier was defined by forward simulation (Chen et al., 2021).

2. Nonsmoothness, smoothing, and feasibility guarantees

The defining minimum in a bCBF is typically nonsmooth. This is not a cosmetic issue: converse safety theorems used to certify feasibility of CBF-based safety filters generally require Sb={xhb(x)0}S_b=\{x\mid h_b(x)\ge 0\}0 barrier functions. The recent smoothing literature therefore replaces the hard minimum by a log-sum-exp soft minimum,

Sb={xhb(x)0}S_b=\{x\mid h_b(x)\ge 0\}1

which is a smooth inner approximation of Sb={xhb(x)0}S_b=\{x\mid h_b(x)\ge 0\}2. It satisfies

Sb={xhb(x)0}S_b=\{x\mid h_b(x)\ge 0\}3

and its gradient is a convex combination of the slice gradients,

Sb={xhb(x)0}S_b=\{x\mid h_b(x)\ge 0\}4

These formulas make the smooth approximation directly compatible with Lie-derivative-based constraints (Alan et al., 17 Nov 2025).

The principal theoretical result in this direction is a uniform, a priori feasibility guarantee. For compact safe sets, if MFCQ holds and the closed-loop vector field is strictly safe with respect to the nonsmooth min-set, then the smoothed barrier is a valid CBF for all

Sb={xhb(x)0}S_b=\{x\mid h_b(x)\ge 0\}5

For unbounded sets, analogous results hold under tail conditions that impose a radially coercive inactive-constraint gap, polynomial growth of inactive Lie derivatives, and uniform positivity of the active part, yielding an explicit threshold for extended-CBF certification on noncompact domains (Alan et al., 17 Nov 2025).

Applied to backup CBFs, these results give a concrete recipe: safety of a compact terminal backup set under a backup controller, together with positivity of Sb={xhb(x)0}S_b=\{x\mid h_b(x)\ge 0\}6 on the backup-reachable portion of the original safe-set boundary, is sufficient for the smoothed backup barrier

Sb={xhb(x)0}S_b=\{x\mid h_b(x)\ge 0\}7

to be a CBF for all Sb={xhb(x)0}S_b=\{x\mid h_b(x)\ge 0\}8 beyond an explicit threshold. The significance is that feasibility is then guaranteed on the entire smoothed set “without the need for additional online certification” (Alan et al., 17 Nov 2025).

A related soft-minimum construction uses predicted trajectories under a backup controller to define a single smooth barrier and then enforces one CBF-style affine constraint with actuator limits. That formulation introduces an LP-based feasibility metric

Sb={xhb(x)0}S_b=\{x\mid h_b(x)\ge 0\}9

followed by a one-constraint QP and a continuous blend between the QP solution and the backup controller. Its guarantees are continuity of the applied control, satisfaction of actuator constraints, return to the sampled safe set by the next sample if excursions occur, and forward invariance of a subset when ub(x)u_b(x)0 exceeds a computable margin (Rabiee et al., 2023).

A common misconception is that smoothing is merely a numerical convenience. The recent theory shows instead that, under explicit boundary and tail conditions, smoothing can be made part of a formal feasibility proof rather than a heuristic approximation (Alan et al., 17 Nov 2025).

3. Generalizations beyond a single backup trajectory

The basic bCBF template has been generalized in several directions. The most direct extension uses a single backup set–backup controller pair to enforce multiple decoupled constraints, and then projects mixed state-input constraints into state space along the backup controller. For a mixed constraint ub(x)u_b(x)1, the projected barrier is

ub(x)u_b(x)2

The current implemented control still enforces ub(x)u_b(x)3 at the present state, while the projected ub(x)u_b(x)4 is used in the predictive inequalities along the backup flow. In the special case of decoupled state and input constraints, this removes the need for globally saturating backup laws and can simplify backup-controller synthesis (Gacsi et al., 17 Mar 2026).

A second extension aggregates multiple implicit safe sets built from different backup controllers. If ub(x)u_b(x)5 denotes the discretized implicit safe-set function associated with backup controller ub(x)u_b(x)6, the aggregate safe set is formed by the union

ub(x)u_b(x)7

To preserve feasibility under input constraints, the aggregation is implemented through a generalized combinatorial CBF with an auxiliary variable ub(x)u_b(x)8, together with a condition termed conjunctive compatibility. The resulting QP yields a continuous safety filter over the aggregated implicit region (Ong et al., 4 Apr 2026).

A third generalization makes the backup policy itself dynamic and reference-parameterized. In that setting the bCBF is defined on the augmented state–reference space by

ub(x)u_b(x)9

where x˙=Fb(x)f(x,ub(x)).\dot{x}=F_b(x)\triangleq f(x,u_b(x)).0 indexes an equilibrium manifold and is held constant during the backup rollout. Sensitivity analysis with respect to both x˙=Fb(x)f(x,ub(x)).\dot{x}=F_b(x)\triangleq f(x,u_b(x)).1 and x˙=Fb(x)f(x,ub(x)).\dot{x}=F_b(x)\triangleq f(x,u_b(x)).2 then produces Jacobians or, in the nonsmooth case, Clarke generalized gradients, allowing a standard CBF-QP to enforce safety on the augmented system (Freire et al., 10 Oct 2025).

A fourth line of work separates the controller used to expand the implicit safe set from the verified backup controller that certifies invariance of the backup set. The generalized switched controller

x˙=Fb(x)f(x,ub(x)).\dot{x}=F_b(x)\triangleq f(x,u_b(x)).3

equals the certified backup controller on the backup set, but can be more aggressive elsewhere. This decoupling enlarges the expanded safe set and extends naturally to parameterized controller families whose expansion policy can be adapted online while preserving safety guarantees (Wijk et al., 19 Mar 2026).

Variant Defining idea Representative paper
Multiple and mixed constraints Project x˙=Fb(x)f(x,ub(x)).\dot{x}=F_b(x)\triangleq f(x,u_b(x)).4 to x˙=Fb(x)f(x,ub(x)).\dot{x}=F_b(x)\triangleq f(x,u_b(x)).5 and enforce current-state x˙=Fb(x)f(x,ub(x)).\dot{x}=F_b(x)\triangleq f(x,u_b(x)).6 plus predictive backup constraints (Gacsi et al., 17 Mar 2026)
Aggregated implicit sets Use x˙=Fb(x)f(x,ub(x)).\dot{x}=F_b(x)\triangleq f(x,u_b(x)).7 with auxiliary-variable combinatorial CBF constraints (Ong et al., 4 Apr 2026)
Dynamic or generalized backup policies Define barriers on augmented state–reference space or separate set expansion from backup certification (Freire et al., 10 Oct 2025, Wijk et al., 19 Mar 2026)

These developments suggest that “backup” is better viewed as a design pattern than as a single construction: the common structure is finite-horizon safety-to-backup reachability, while the particular backup objects may be multiple, aggregated, projected, parameterized, or dynamically adapted.

4. Robustness to disturbances, estimation error, and imperfect measurements

The nominal bCBF framework assumes that the backup flow can be computed accurately. Under unmodeled disturbances, this assumption fails, so recent work replaces the nominal backup trajectory by a nominal centerline plus a disturbance tube. For additive disturbances x˙=Fb(x)f(x,ub(x)).\dot{x}=F_b(x)\triangleq f(x,u_b(x)).8 with x˙=Fb(x)f(x,ub(x)).\dot{x}=F_b(x)\triangleq f(x,u_b(x)).9, one can bound the deviation between disturbed and nominal backup flows by an expanding norm-ball radius

hT(x)min{minτ[0,T]h(ϕ(x,τ)), hb(ϕ(x,T))}.h_T(x) \triangleq \min\Big\{ \min_{\tau\in[0,T]} h\big(\phi(x,\tau)\big),~h_b\big(\phi(x,T)\big) \Big\}.0

where hT(x)min{minτ[0,T]h(ϕ(x,τ)), hb(ϕ(x,T))}.h_T(x) \triangleq \min\Big\{ \min_{\tau\in[0,T]} h\big(\phi(x,\tau)\big),~h_b\big(\phi(x,T)\big) \Big\}.1 is a Lipschitz constant of the backup closed-loop vector field. Tightening the nominal barrier values by Lipschitz margins such as hT(x)min{minτ[0,T]h(ϕ(x,τ)), hb(ϕ(x,T))}.h_T(x) \triangleq \min\Big\{ \min_{\tau\in[0,T]} h\big(\phi(x,\tau)\big),~h_b\big(\phi(x,T)\big) \Big\}.2 then yields a robust inner approximation whose forward invariance guarantees safety of the disturbed system (Wijk et al., 2024).

A disturbance-observer version improves this by estimating the disturbance online and propagating the backup flow under the estimate hT(x)min{minτ[0,T]h(ϕ(x,τ)), hb(ϕ(x,T))}.h_T(x) \triangleq \min\Big\{ \min_{\tau\in[0,T]} h\big(\phi(x,\tau)\big),~h_b\big(\phi(x,T)\big) \Big\}.3 rather than a worst-case bound. The observer produces an estimation error bound

hT(x)min{minτ[0,T]h(ϕ(x,τ)), hb(ϕ(x,T))}.h_T(x) \triangleq \min\Big\{ \min_{\tau\in[0,T]} h\big(\phi(x,\tau)\big),~h_b\big(\phi(x,T)\big) \Big\}.4

and the resulting DO-bCBF constraints add robustness terms proportional to hT(x)min{minτ[0,T]h(ϕ(x,τ)), hb(ϕ(x,T))}.h_T(x) \triangleq \min\Big\{ \min_{\tau\in[0,T]} h\big(\phi(x,\tau)\big),~h_b\big(\phi(x,T)\big) \Big\}.5 and the sensitivity of the estimated backup flow to the disturbance estimate. The effect is to refine the disturbance tube over time, making the method less conservative than a fixed worst-case disturbance-robust bCBF while still guaranteeing safety and input-constraint satisfaction (Wijk et al., 19 Mar 2025).

When the state is not perfectly known, the difficulty is twofold: the initial condition of the backup flow is uncertain, and the true closed-loop flow evolves using feedback from the estimated state. Output-feedback bCBFs address this by centering an uncertainty envelope around an estimated open-loop backup flow and tightening the safety inequalities along that envelope. Under an error-bounded estimator and suitable bounds on the backup-flow deviation, ensuring safety of the envelope implies safety of the true state, and there always exists a feasible control input that can guarantee the safety of the true state even in the presence of input constraints (Wijk et al., 21 Apr 2026).

A related measurement-robust framework incorporates explicit uncertainty terms into CBF and backup-set inequalities. A representative robust inequality is

hT(x)min{minτ[0,T]h(ϕ(x,τ)), hb(ϕ(x,T))}.h_T(x) \triangleq \min\Big\{ \min_{\tau\in[0,T]} h\big(\phi(x,\tau)\big),~h_b\big(\phi(x,T)\big) \Big\}.6

where hT(x)min{minτ[0,T]h(ϕ(x,τ)), hb(ϕ(x,T))}.h_T(x) \triangleq \min\Big\{ \min_{\tau\in[0,T]} h\big(\phi(x,\tau)\big),~h_b\big(\phi(x,T)\big) \Big\}.7 and hT(x)min{minτ[0,T]h(ϕ(x,τ)), hb(ϕ(x,T))}.h_T(x) \triangleq \min\Big\{ \min_{\tau\in[0,T]} h\big(\phi(x,\tau)\big),~h_b\big(\phi(x,T)\big) \Big\}.8 are computed from measurement error bounds and Lipschitz constants. When lifted to sampled backup-trajectory constraints, this yields a measurement-robust backup-set optimization program formulated as an SOCP and validated experimentally on a Segway platform (Cosner et al., 2021).

These robust variants make clear that bCBFs are not inherently robust: disturbance rejection, state-estimation error, and measurement uncertainty require additional tubes, observers, or robust margins rather than following automatically from the nominal backup construction.

5. Computation, refinement, and learning-based backup synthesis

The practical burden of bCBFs comes from online trajectory prediction, sensitivity computation, and repeated quadratic programming. The tutorial study emphasized that most online time is spent in the QP because of the multiple trajectory constraints, although the approach scales to problems where Hamilton–Jacobi PDEs and sum-of-squares methods are inapplicable (Chen et al., 2021). A recent closed-form alternative restricts the safe input to the line segment between a nominal controller and the backup controller,

hT(x)min{minτ[0,T]h(ϕ(x,τ)), hb(ϕ(x,T))}.h_T(x) \triangleq \min\Big\{ \min_{\tau\in[0,T]} h\big(\phi(x,\tau)\big),~h_b\big(\phi(x,T)\big) \Big\}.9

and derives [0,T][0,T]0 analytically as the projection of zero onto the interval defined by the bCBF constraints and input bounds. This reduces the ODE count from [0,T][0,T]1 to [0,T][0,T]2 by replacing full sensitivity matrices with directional pushforwards, and eliminates the runtime QP solve (Wijk et al., 6 Oct 2025).

Another computational direction refines a candidate or backup-derived barrier offline using Hamilton–Jacobi dynamic programming. Starting from a backup value function

[0,T][0,T]3

the refineCBF procedure warmstarts the control barrier–value function recursion with [0,T][0,T]4 rather than the raw constraint function. Each dynamic-programming iteration is provably at least as safe as the previous one and converges to a valid barrier–value function whose zero superlevel set is a conservative subset of the viability kernel (Tonkens et al., 2022).

Learning-based work uses the bCBF not only as a filter but also as a mechanism for safely enlarging the controllable region. In safe exploration, the reinforcement learning backup shield (RLBUS) trains an additional backup policy while the shield guarantees “zero training time safety violations.” The learned policy is added to the set of backup controllers, and the reward is chosen to enlarge the identified control forward invariant subset of the safe set (Rabiee et al., 2023). In human-robot collaboration, another framework uses learning-based switching between multiple backup controllers to reduce conservatism while preserving safety under bounded control inputs; an LSTM classifier trained on 19,000 labeled hardware datapoints achieved about 97% validation accuracy by epoch 30 and selected backup controllers in real time (Janwani et al., 2023).

These approaches suggest a division of labor. The bCBF remains the formal safety mechanism, while learning is used to choose among backups, synthesize additional backups, or improve performance inside the certified region.

6. Applications, trade-offs, and relation to adjacent methods

The reported application range is broad. Examples include inverted pendulum regulation and a double-integrator ground robot under actuator constraints (Rabiee et al., 2023); simultaneous enforcement of angle, torque, and power constraints in an inverted pendulum through projection-based multiple bCBFs (Gacsi et al., 17 Mar 2026); safe spacecraft attitude control and safe station keeping by aggregating multiple implicit safe regions (Ong et al., 4 Apr 2026); split-[0,T][0,T]5 vehicle braking with bounded per-wheel forces and bounded lateral motion (Gacsi et al., 17 Oct 2025); nonlinear fixed-wing aircraft geofencing with a closed-form bCBF safety filter (Wijk et al., 6 Oct 2025); and generalized bCBF expansions for double integrators and planar quadrotor landing (Wijk et al., 19 Mar 2026).

The main trade-offs are consistent across these works. First, conservatism is shifted rather than removed: the size of the certified set depends strongly on the backup controller, the backup horizon, and—when smoothing is used—the smoothing parameter. Soft-min barriers under-approximate the hard min, so the guaranteed safe set is smaller for finite [0,T][0,T]6 (Alan et al., 17 Nov 2025). Second, feasibility may require stronger assumptions than basic forward invariance, including strict positivity of active Lie derivatives, MFCQ at the boundary, or tail conditions on noncompact sets (Alan et al., 17 Nov 2025). Third, computational cost is dominated by forward integration, sensitivity propagation, and repeated constraints along the horizon; this is favorable relative to HJ or SOS in high dimensions, but still materially higher than a single-state CBF filter (Chen et al., 2021). Fourth, robust and output-feedback extensions add further conservatism through uncertainty envelopes and Lipschitz bounds (Wijk et al., 2024).

Several misunderstandings are therefore worth dispelling. bCBFs are not synonymous with smooth barriers; the native construction is usually nonsmooth and may require either multi-constraint formulations or explicit smoothing. They do not automatically solve robustness, output feedback, or mixed state-input safety; those capabilities come from distinct extensions. And they do not eliminate the need for careful backup design: a poor backup policy yields a small control invariant set, whereas a well-chosen backup can make the certified set close to the maximum control invariant set for many practical problems (Chen et al., 2021).

This suggests that the enduring significance of bCBFs lies less in any single formula than in a reusable synthesis principle: safety is certified by demonstrating that the present state can hand off to a known safe future. Recent work has made that principle smoother, more uniformly feasible, more expressive for multiple and mixed constraints, more robust to uncertainty, and more compatible with learning and low-computation implementations (Alan et al., 17 Nov 2025).

Definition Search Book Streamline Icon: https://streamlinehq.com
References (16)

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to Backup Control Barrier Functions (bCBFs).