Output-to-Output Gain (OOG) in Control Systems
- OOG is a gain-based metric that measures maximum performance degradation while ensuring the residual output remains below a detection threshold.
- It unifies performance impact and detectability by formulating the problem as a constrained induced L2 gain between performance and residual outputs using LMI, frequency-domain, and Hamiltonian methods.
- A high OOG value indicates that significant performance damage can occur with minimal detection, highlighting vulnerabilities in both linear and nonlinear networked control systems.
Output-to-Output Gain (OOG) is a gain-based metric that measures the maximum performance degradation attainable while a detection-oriented output remains small. In networked control and cyber-physical security, it is formulated as a constrained induced gain between a performance output and a residual output , thereby unifying impact and detectability in a single quantity; later work extends the notion from linear systems to nonlinear networked control systems with quadratically constrained nonlinearities and develops LMI, frequency-domain, and Hamiltonian-matrix methods for analysis and computation (Seifullaev et al., 15 Dec 2025, Arnström et al., 20 Sep 2025).
1. Definition and core interpretation
In the nonlinear networked-control formulation, the two outputs are the performance output , which captures regulation or tracking quality, and the residual output , which is used by an anomaly detector. With augmented closed-loop state , the paper writes
where is an additive injected signal and is a nonlinear sensor fault or attack. The attack signal belongs to the extended space
The OOG is then defined by
0
Here 1. The quantity 2 measures total performance degradation, while the constraint on 3 encodes stealthiness relative to a detector threshold (Seifullaev et al., 15 Dec 2025).
In the linear LTI security formulation, the same idea appears for
4
with OOG defined as the supremum of 5 subject to 6, 7, and 8. This makes OOG the worst-case performance damage per unit residual energy and gives it a direct security interpretation: large OOG indicates that large damage is compatible with small residuals, whereas small OOG indicates that impactful attacks necessarily produce a significant residual (Arnström et al., 20 Sep 2025).
A common misconception is to regard OOG as an ordinary input-to-output induced norm. It is not. Classical 9 norms use the attack or disturbance magnitude in the denominator, whereas OOG uses the residual output as the constraint. In that sense, it is closer to an induced gain from one output to another output, with detectability embedded directly in the definition rather than treated as a separate metric (Seifullaev et al., 15 Dec 2025).
2. System classes, outputs, and attack models
The most developed OOG setting is the closed-loop networked control system with observer-based state feedback, plant nonlinearities, and compromised measurements. The plant is
0
with nonlinear blocks 1 constrained by quadratic forms
2
A typical example is a sector-bounded nonlinearity satisfying
3
equivalently
4
The observer-based controller uses
5
and the compromised measurement is modeled as
6
This attack model covers additive false-data injection and nonlinear sensor manipulation at the firmware level (Seifullaev et al., 15 Dec 2025).
The resulting closed-loop system has augmented state
7
and dynamics
8
All nonlinearities can be aggregated into a composite nonlinearity 9 with a combined quadratic form
0
Within this framework, OOG is meaningful only when the closed loop is absolutely stable in the nonlinearity class, ensuring 1 (Seifullaev et al., 15 Dec 2025).
A second common misconception is that OOG is tied to additive attacks alone. In the nonlinear NCS formulation, hidden faults include nonlinear sensor transformations satisfying local or integral quadratic constraints, and the framework explicitly accommodates both additive attacks and quadratically constrained nonlinear malfunctions (Seifullaev et al., 15 Dec 2025).
3. Dissipativity, LMIs, and frequency-domain computation
The basic computational device is output strict dissipativity with supply rate 2. If there exists a storage function 3 such that
4
then integration gives
5
and for 6 with 7,
8
Thus OOG bounding reduces to maximizing 9 subject to a dissipativity inequality (Seifullaev et al., 15 Dec 2025).
With a quadratic storage 0, 1, and a quadratic constraint
2
the S-procedure leads to the LMI
3
and the theorem: if there exist 4, 5, 6 satisfying this LMI, then 7. The practical optimization is
8
The maximal feasible 9 gives the tightest upper bound available from the certificate (Seifullaev et al., 15 Dec 2025).
The same paper derives complementary frequency-domain conditions by applying the KYP lemma. Under 0 Hurwitz and suitable controllability conditions, if there exist 1 and 2 such that
3
and
4
then again 5. The state-space LMI test and the frequency-domain inequalities are presented as complementary rather than competing formulations (Seifullaev et al., 15 Dec 2025).
For linear systems, the cyclic and regularized cyclic variants sharpen the frequency-domain characterization. The cyclic OOG (COOG) adds the asymptotic state-return condition 6, and the paper shows the exact identity
7
where 8 denotes the maximum generalized singular value. The regularized cyclic OOG (RCOOG) replaces the residual constraint by
9
equivalently augmenting the residual with 0. In frequency domain,
1
This enables a Hamiltonian-matrix algorithm analogous to classical 2 norm computation, but with generalized singular values rather than regular singular values (Arnström et al., 20 Sep 2025).
4. Structural limitations and relation to classical gain theory
The security interpretation of OOG is sharpened by a frequency-domain factorization result. For the LTI system
3
let 4 and 5 be the transfer functions from attack input to residual and performance outputs. Using a right coprime factorization
6
the paper proves
7
with equality under periodic trajectories. This rewrites OOG in terms of an 8 norm of a ratio of numerator factors, and thereby places stealthy-attack sensitivity inside classical frequency-domain machinery (Dong et al., 14 Sep 2025).
This representation immediately clarifies several structural limitations. If 9 is non-proper, then
0
so the corresponding lower bound on OOG is infinite. More generally, non-minimum-phase zeros in the residual path are decisive. The paper states that if 1 has non-minimum-phase zeros not shared with 2, the OOG can become infinite; if those zeros are shared, they cancel in the ratio and the analysis reduces to the case without such unmatched zeros (Dong et al., 14 Sep 2025).
In the proper case, define
3
Factoring 4 and 5 into minimum-phase terms and Blaschke products, the Poisson integral relation yields the lower bound
6
The bound is determined entirely by non-minimum-phase zeros. If only one of 7 or 8 has non-minimum-phase zeros, the lower bound is exactly 9; if both have them, the lower bound is strictly larger than 0 and increases as the zeros approach one another in the right half-plane (Dong et al., 14 Sep 2025).
Against this background, the contrast with classical robust-control metrics is precise rather than rhetorical. In the nonlinear NCS treatment, 1 measures impact from an exogenous input to a performance output, and the 2 index measures gain from fault to residual, so impact and detectability are separated. OOG is distinguished by using the residual output as the constraining quantity and thus directly measuring maximum impact under a detectability constraint (Seifullaev et al., 15 Dec 2025).
5. Cyclic, periodic, and broader output-to-output variants
Although the security-oriented definition is the dominant one, adjacent literature uses the phrase or an explicitly analogous construction in other ways. One such case is gain of entrainment (GOE) for stable linear dynamics with a nonlinear static output map. There, for a 3-periodic input 4 with average
5
the entrained periodic orbit is 6, the average output is
7
and the equilibrium corresponding to the averaged input is
8
The GOE is
9
That paper explicitly analyzes GOE as a concrete OOG notion: it compares the average output under periodic forcing with the output under the constant input having the same mean. For linear outputs, GOE is zero; for nonlinear outputs, its leading-order term is governed by the Hessian of 0, and convexity or concavity on the controllable subspace implies nonnegative or nonpositive GOE for every periodic input. The same work also identifies GOE as the average Bregman divergence between the entrained periodic orbit and the equilibrium associated with the averaged input (Massas et al., 22 Jun 2026).
A second neighboring use appears in quadratic-output systems. For
1
the paper derives explicit 2–3 bounds for the quadratic-output map. In the purely quadratic-in-state case,
4
the main bound is
5
where 6 is a bivariate transfer function and the norm is evaluated on the anti-diagonal 7. The paper presents this as an OOG-type bound from the linear state trajectory to a quadratic performance output, and shows that the associated norm can be computed from Lyapunov and Sylvester equations rather than numerical frequency integration (Hillebrecht, 1 Jul 2026).
These variants do not replace the security-oriented definition. They show instead that “output-to-output gain” can denote a broader family of gain comparisons in which the object of interest is a relation between outputs—residual versus performance output, average periodic versus DC-equivalent output, or linear versus quadratic output channels—rather than a conventional input-to-output map.
6. Examples, computation at scale, and limitations
The nonlinear NCS case study makes the interpretation concrete. In the linear attack case 8, linear LMIs give 9, and a suboptimal attack computed by sampled-data approximation over a finite horizon achieves 00. When a nonlinear transformation is introduced on the first measurement component,
01
which lies in the sector 02, the LMI bound becomes
03
while the same suboptimal attack signal now realizes approximately 04. The paper states that the nonlinear attack increases the performance energy by a factor of about 05 compared to the linear case, without increasing the residual energy enough to trigger detection (Seifullaev et al., 15 Dec 2025).
For large-scale linear systems, the computational issue is no longer the conceptual definition but the cost of solving semidefinite programs. The Hamiltonian-matrix paper reports that Algorithm 1 for RCOOG is 1–3 orders of magnitude faster than solving the SDP with MOSEK on random LTI systems with 06, and that the speed advantage increases with system size. On positive networked control systems with up to 07 nodes, dense-08 SDPs quickly become impractical, diagonal-09 approximations can exhibit average relative error 10 and worst-case relative error exceeding 11, whereas the Hamiltonian method remains largely insensitive to graph sparsity because it reduces the problem to dense eigenvalue computations for a matrix of dimension 12 (Arnström et al., 20 Sep 2025).
The present literature also makes the main limitations explicit. In the nonlinear security setting, the S-procedure is sufficient but not necessary, so OOG bounds can be conservative; admissible nonlinearities must be representable by quadratic constraints or IQCs; the analysis is deterministic rather than stochastic; and network effects such as varying delays, packet loss, and time-varying topology are not explicitly modeled in the nonlinear OOG framework. Suggested extensions include multiplicative attacks, nonlinear time-delay systems, and more general classes of time-varying or stochastic nonlinearities (Seifullaev et al., 15 Dec 2025).
Additional limitations appear in the frequency-domain theory. The factorization-based fundamental-limit results are presented for one-dimensional input and output signals, with multi-input–multi-output extensions left for future work (Dong et al., 14 Sep 2025). The Hamiltonian method likewise assumes continuous-time LTI dynamics and requires regularization to guarantee existence of the Hamiltonian matrix in important security cases such as 13 and 14; the paper notes that a discrete-time extension is technically straightforward but not developed there (Arnström et al., 20 Sep 2025).
Taken together, these results establish OOG as both a precise induced-gain concept and a design-oriented vulnerability metric. In its principal security formulation, it quantifies the maximum performance loss compatible with residual stealthiness; in adjacent formulations, it also serves as a comparative framework for periodic forcing and nonlinear output maps. Across these variants, the central theme is unchanged: OOG measures how one output channel constrains, amplifies, or conceals another.