Papers
Topics
Authors
Recent
Search
2000 character limit reached

Output-to-Output Gain (OOG) in Control Systems

Updated 11 July 2026
  • OOG is a gain-based metric that measures maximum performance degradation while ensuring the residual output remains below a detection threshold.
  • It unifies performance impact and detectability by formulating the problem as a constrained induced L2 gain between performance and residual outputs using LMI, frequency-domain, and Hamiltonian methods.
  • A high OOG value indicates that significant performance damage can occur with minimal detection, highlighting vulnerabilities in both linear and nonlinear networked control systems.

Output-to-Output Gain (OOG) is a gain-based metric that measures the maximum performance degradation attainable while a detection-oriented output remains small. In networked control and cyber-physical security, it is formulated as a constrained induced L2L_2 gain between a performance output ypy_{\rm p} and a residual output yry_{\rm r}, thereby unifying impact and detectability in a single quantity; later work extends the notion from linear systems to nonlinear networked control systems with quadratically constrained nonlinearities and develops LMI, frequency-domain, and Hamiltonian-matrix methods for analysis and computation (Seifullaev et al., 15 Dec 2025, Arnström et al., 20 Sep 2025).

1. Definition and core interpretation

In the nonlinear networked-control formulation, the two outputs are the performance output yp(t)y_{\rm p}(t), which captures regulation or tracking quality, and the residual output yr(t)y_{\rm r}(t), which is used by an anomaly detector. With augmented closed-loop state x(t)x(t), the paper writes

yp(t)=Cpx(t),yr(t)=Crx(t)+ξm(t)+Dra(t),y_{\rm p}(t)=C_{\rm p}x(t), \qquad y_{\rm r}(t)=C_{\rm r}x(t)+\xi_{\rm m}(t)+D_{\rm r}a(t),

where a(t)a(t) is an additive injected signal and ξm(t)=φ(ym(t),t)\xi_{\rm m}(t)=\varphi(y_{\rm m}(t),t) is a nonlinear sensor fault or attack. The attack signal belongs to the extended space

L2e={a:R+RnaaL2[0,T]<, T<}.L_{2e}=\left\{a:\mathbb{R}_+\to\mathbb{R}^{n_a}\,\big|\,\|a\|_{L_{2[0,T]}}<\infty,\ \forall T<\infty\right\}.

The OOG is then defined by

ypy_{\rm p}0

Here ypy_{\rm p}1. The quantity ypy_{\rm p}2 measures total performance degradation, while the constraint on ypy_{\rm p}3 encodes stealthiness relative to a detector threshold (Seifullaev et al., 15 Dec 2025).

In the linear LTI security formulation, the same idea appears for

ypy_{\rm p}4

with OOG defined as the supremum of ypy_{\rm p}5 subject to ypy_{\rm p}6, ypy_{\rm p}7, and ypy_{\rm p}8. This makes OOG the worst-case performance damage per unit residual energy and gives it a direct security interpretation: large OOG indicates that large damage is compatible with small residuals, whereas small OOG indicates that impactful attacks necessarily produce a significant residual (Arnström et al., 20 Sep 2025).

A common misconception is to regard OOG as an ordinary input-to-output induced norm. It is not. Classical ypy_{\rm p}9 norms use the attack or disturbance magnitude in the denominator, whereas OOG uses the residual output as the constraint. In that sense, it is closer to an induced gain from one output to another output, with detectability embedded directly in the definition rather than treated as a separate metric (Seifullaev et al., 15 Dec 2025).

2. System classes, outputs, and attack models

The most developed OOG setting is the closed-loop networked control system with observer-based state feedback, plant nonlinearities, and compromised measurements. The plant is

yry_{\rm r}0

with nonlinear blocks yry_{\rm r}1 constrained by quadratic forms

yry_{\rm r}2

A typical example is a sector-bounded nonlinearity satisfying

yry_{\rm r}3

equivalently

yry_{\rm r}4

The observer-based controller uses

yry_{\rm r}5

and the compromised measurement is modeled as

yry_{\rm r}6

This attack model covers additive false-data injection and nonlinear sensor manipulation at the firmware level (Seifullaev et al., 15 Dec 2025).

The resulting closed-loop system has augmented state

yry_{\rm r}7

and dynamics

yry_{\rm r}8

All nonlinearities can be aggregated into a composite nonlinearity yry_{\rm r}9 with a combined quadratic form

yp(t)y_{\rm p}(t)0

Within this framework, OOG is meaningful only when the closed loop is absolutely stable in the nonlinearity class, ensuring yp(t)y_{\rm p}(t)1 (Seifullaev et al., 15 Dec 2025).

A second common misconception is that OOG is tied to additive attacks alone. In the nonlinear NCS formulation, hidden faults include nonlinear sensor transformations satisfying local or integral quadratic constraints, and the framework explicitly accommodates both additive attacks and quadratically constrained nonlinear malfunctions (Seifullaev et al., 15 Dec 2025).

3. Dissipativity, LMIs, and frequency-domain computation

The basic computational device is output strict dissipativity with supply rate yp(t)y_{\rm p}(t)2. If there exists a storage function yp(t)y_{\rm p}(t)3 such that

yp(t)y_{\rm p}(t)4

then integration gives

yp(t)y_{\rm p}(t)5

and for yp(t)y_{\rm p}(t)6 with yp(t)y_{\rm p}(t)7,

yp(t)y_{\rm p}(t)8

Thus OOG bounding reduces to maximizing yp(t)y_{\rm p}(t)9 subject to a dissipativity inequality (Seifullaev et al., 15 Dec 2025).

With a quadratic storage yr(t)y_{\rm r}(t)0, yr(t)y_{\rm r}(t)1, and a quadratic constraint

yr(t)y_{\rm r}(t)2

the S-procedure leads to the LMI

yr(t)y_{\rm r}(t)3

and the theorem: if there exist yr(t)y_{\rm r}(t)4, yr(t)y_{\rm r}(t)5, yr(t)y_{\rm r}(t)6 satisfying this LMI, then yr(t)y_{\rm r}(t)7. The practical optimization is

yr(t)y_{\rm r}(t)8

The maximal feasible yr(t)y_{\rm r}(t)9 gives the tightest upper bound available from the certificate (Seifullaev et al., 15 Dec 2025).

The same paper derives complementary frequency-domain conditions by applying the KYP lemma. Under x(t)x(t)0 Hurwitz and suitable controllability conditions, if there exist x(t)x(t)1 and x(t)x(t)2 such that

x(t)x(t)3

and

x(t)x(t)4

then again x(t)x(t)5. The state-space LMI test and the frequency-domain inequalities are presented as complementary rather than competing formulations (Seifullaev et al., 15 Dec 2025).

For linear systems, the cyclic and regularized cyclic variants sharpen the frequency-domain characterization. The cyclic OOG (COOG) adds the asymptotic state-return condition x(t)x(t)6, and the paper shows the exact identity

x(t)x(t)7

where x(t)x(t)8 denotes the maximum generalized singular value. The regularized cyclic OOG (RCOOG) replaces the residual constraint by

x(t)x(t)9

equivalently augmenting the residual with yp(t)=Cpx(t),yr(t)=Crx(t)+ξm(t)+Dra(t),y_{\rm p}(t)=C_{\rm p}x(t), \qquad y_{\rm r}(t)=C_{\rm r}x(t)+\xi_{\rm m}(t)+D_{\rm r}a(t),0. In frequency domain,

yp(t)=Cpx(t),yr(t)=Crx(t)+ξm(t)+Dra(t),y_{\rm p}(t)=C_{\rm p}x(t), \qquad y_{\rm r}(t)=C_{\rm r}x(t)+\xi_{\rm m}(t)+D_{\rm r}a(t),1

This enables a Hamiltonian-matrix algorithm analogous to classical yp(t)=Cpx(t),yr(t)=Crx(t)+ξm(t)+Dra(t),y_{\rm p}(t)=C_{\rm p}x(t), \qquad y_{\rm r}(t)=C_{\rm r}x(t)+\xi_{\rm m}(t)+D_{\rm r}a(t),2 norm computation, but with generalized singular values rather than regular singular values (Arnström et al., 20 Sep 2025).

4. Structural limitations and relation to classical gain theory

The security interpretation of OOG is sharpened by a frequency-domain factorization result. For the LTI system

yp(t)=Cpx(t),yr(t)=Crx(t)+ξm(t)+Dra(t),y_{\rm p}(t)=C_{\rm p}x(t), \qquad y_{\rm r}(t)=C_{\rm r}x(t)+\xi_{\rm m}(t)+D_{\rm r}a(t),3

let yp(t)=Cpx(t),yr(t)=Crx(t)+ξm(t)+Dra(t),y_{\rm p}(t)=C_{\rm p}x(t), \qquad y_{\rm r}(t)=C_{\rm r}x(t)+\xi_{\rm m}(t)+D_{\rm r}a(t),4 and yp(t)=Cpx(t),yr(t)=Crx(t)+ξm(t)+Dra(t),y_{\rm p}(t)=C_{\rm p}x(t), \qquad y_{\rm r}(t)=C_{\rm r}x(t)+\xi_{\rm m}(t)+D_{\rm r}a(t),5 be the transfer functions from attack input to residual and performance outputs. Using a right coprime factorization

yp(t)=Cpx(t),yr(t)=Crx(t)+ξm(t)+Dra(t),y_{\rm p}(t)=C_{\rm p}x(t), \qquad y_{\rm r}(t)=C_{\rm r}x(t)+\xi_{\rm m}(t)+D_{\rm r}a(t),6

the paper proves

yp(t)=Cpx(t),yr(t)=Crx(t)+ξm(t)+Dra(t),y_{\rm p}(t)=C_{\rm p}x(t), \qquad y_{\rm r}(t)=C_{\rm r}x(t)+\xi_{\rm m}(t)+D_{\rm r}a(t),7

with equality under periodic trajectories. This rewrites OOG in terms of an yp(t)=Cpx(t),yr(t)=Crx(t)+ξm(t)+Dra(t),y_{\rm p}(t)=C_{\rm p}x(t), \qquad y_{\rm r}(t)=C_{\rm r}x(t)+\xi_{\rm m}(t)+D_{\rm r}a(t),8 norm of a ratio of numerator factors, and thereby places stealthy-attack sensitivity inside classical frequency-domain machinery (Dong et al., 14 Sep 2025).

This representation immediately clarifies several structural limitations. If yp(t)=Cpx(t),yr(t)=Crx(t)+ξm(t)+Dra(t),y_{\rm p}(t)=C_{\rm p}x(t), \qquad y_{\rm r}(t)=C_{\rm r}x(t)+\xi_{\rm m}(t)+D_{\rm r}a(t),9 is non-proper, then

a(t)a(t)0

so the corresponding lower bound on OOG is infinite. More generally, non-minimum-phase zeros in the residual path are decisive. The paper states that if a(t)a(t)1 has non-minimum-phase zeros not shared with a(t)a(t)2, the OOG can become infinite; if those zeros are shared, they cancel in the ratio and the analysis reduces to the case without such unmatched zeros (Dong et al., 14 Sep 2025).

In the proper case, define

a(t)a(t)3

Factoring a(t)a(t)4 and a(t)a(t)5 into minimum-phase terms and Blaschke products, the Poisson integral relation yields the lower bound

a(t)a(t)6

The bound is determined entirely by non-minimum-phase zeros. If only one of a(t)a(t)7 or a(t)a(t)8 has non-minimum-phase zeros, the lower bound is exactly a(t)a(t)9; if both have them, the lower bound is strictly larger than ξm(t)=φ(ym(t),t)\xi_{\rm m}(t)=\varphi(y_{\rm m}(t),t)0 and increases as the zeros approach one another in the right half-plane (Dong et al., 14 Sep 2025).

Against this background, the contrast with classical robust-control metrics is precise rather than rhetorical. In the nonlinear NCS treatment, ξm(t)=φ(ym(t),t)\xi_{\rm m}(t)=\varphi(y_{\rm m}(t),t)1 measures impact from an exogenous input to a performance output, and the ξm(t)=φ(ym(t),t)\xi_{\rm m}(t)=\varphi(y_{\rm m}(t),t)2 index measures gain from fault to residual, so impact and detectability are separated. OOG is distinguished by using the residual output as the constraining quantity and thus directly measuring maximum impact under a detectability constraint (Seifullaev et al., 15 Dec 2025).

5. Cyclic, periodic, and broader output-to-output variants

Although the security-oriented definition is the dominant one, adjacent literature uses the phrase or an explicitly analogous construction in other ways. One such case is gain of entrainment (GOE) for stable linear dynamics with a nonlinear static output map. There, for a ξm(t)=φ(ym(t),t)\xi_{\rm m}(t)=\varphi(y_{\rm m}(t),t)3-periodic input ξm(t)=φ(ym(t),t)\xi_{\rm m}(t)=\varphi(y_{\rm m}(t),t)4 with average

ξm(t)=φ(ym(t),t)\xi_{\rm m}(t)=\varphi(y_{\rm m}(t),t)5

the entrained periodic orbit is ξm(t)=φ(ym(t),t)\xi_{\rm m}(t)=\varphi(y_{\rm m}(t),t)6, the average output is

ξm(t)=φ(ym(t),t)\xi_{\rm m}(t)=\varphi(y_{\rm m}(t),t)7

and the equilibrium corresponding to the averaged input is

ξm(t)=φ(ym(t),t)\xi_{\rm m}(t)=\varphi(y_{\rm m}(t),t)8

The GOE is

ξm(t)=φ(ym(t),t)\xi_{\rm m}(t)=\varphi(y_{\rm m}(t),t)9

That paper explicitly analyzes GOE as a concrete OOG notion: it compares the average output under periodic forcing with the output under the constant input having the same mean. For linear outputs, GOE is zero; for nonlinear outputs, its leading-order term is governed by the Hessian of L2e={a:R+RnaaL2[0,T]<, T<}.L_{2e}=\left\{a:\mathbb{R}_+\to\mathbb{R}^{n_a}\,\big|\,\|a\|_{L_{2[0,T]}}<\infty,\ \forall T<\infty\right\}.0, and convexity or concavity on the controllable subspace implies nonnegative or nonpositive GOE for every periodic input. The same work also identifies GOE as the average Bregman divergence between the entrained periodic orbit and the equilibrium associated with the averaged input (Massas et al., 22 Jun 2026).

A second neighboring use appears in quadratic-output systems. For

L2e={a:R+RnaaL2[0,T]<, T<}.L_{2e}=\left\{a:\mathbb{R}_+\to\mathbb{R}^{n_a}\,\big|\,\|a\|_{L_{2[0,T]}}<\infty,\ \forall T<\infty\right\}.1

the paper derives explicit L2e={a:R+RnaaL2[0,T]<, T<}.L_{2e}=\left\{a:\mathbb{R}_+\to\mathbb{R}^{n_a}\,\big|\,\|a\|_{L_{2[0,T]}}<\infty,\ \forall T<\infty\right\}.2–L2e={a:R+RnaaL2[0,T]<, T<}.L_{2e}=\left\{a:\mathbb{R}_+\to\mathbb{R}^{n_a}\,\big|\,\|a\|_{L_{2[0,T]}}<\infty,\ \forall T<\infty\right\}.3 bounds for the quadratic-output map. In the purely quadratic-in-state case,

L2e={a:R+RnaaL2[0,T]<, T<}.L_{2e}=\left\{a:\mathbb{R}_+\to\mathbb{R}^{n_a}\,\big|\,\|a\|_{L_{2[0,T]}}<\infty,\ \forall T<\infty\right\}.4

the main bound is

L2e={a:R+RnaaL2[0,T]<, T<}.L_{2e}=\left\{a:\mathbb{R}_+\to\mathbb{R}^{n_a}\,\big|\,\|a\|_{L_{2[0,T]}}<\infty,\ \forall T<\infty\right\}.5

where L2e={a:R+RnaaL2[0,T]<, T<}.L_{2e}=\left\{a:\mathbb{R}_+\to\mathbb{R}^{n_a}\,\big|\,\|a\|_{L_{2[0,T]}}<\infty,\ \forall T<\infty\right\}.6 is a bivariate transfer function and the norm is evaluated on the anti-diagonal L2e={a:R+RnaaL2[0,T]<, T<}.L_{2e}=\left\{a:\mathbb{R}_+\to\mathbb{R}^{n_a}\,\big|\,\|a\|_{L_{2[0,T]}}<\infty,\ \forall T<\infty\right\}.7. The paper presents this as an OOG-type bound from the linear state trajectory to a quadratic performance output, and shows that the associated norm can be computed from Lyapunov and Sylvester equations rather than numerical frequency integration (Hillebrecht, 1 Jul 2026).

These variants do not replace the security-oriented definition. They show instead that “output-to-output gain” can denote a broader family of gain comparisons in which the object of interest is a relation between outputs—residual versus performance output, average periodic versus DC-equivalent output, or linear versus quadratic output channels—rather than a conventional input-to-output map.

6. Examples, computation at scale, and limitations

The nonlinear NCS case study makes the interpretation concrete. In the linear attack case L2e={a:R+RnaaL2[0,T]<, T<}.L_{2e}=\left\{a:\mathbb{R}_+\to\mathbb{R}^{n_a}\,\big|\,\|a\|_{L_{2[0,T]}}<\infty,\ \forall T<\infty\right\}.8, linear LMIs give L2e={a:R+RnaaL2[0,T]<, T<}.L_{2e}=\left\{a:\mathbb{R}_+\to\mathbb{R}^{n_a}\,\big|\,\|a\|_{L_{2[0,T]}}<\infty,\ \forall T<\infty\right\}.9, and a suboptimal attack computed by sampled-data approximation over a finite horizon achieves ypy_{\rm p}00. When a nonlinear transformation is introduced on the first measurement component,

ypy_{\rm p}01

which lies in the sector ypy_{\rm p}02, the LMI bound becomes

ypy_{\rm p}03

while the same suboptimal attack signal now realizes approximately ypy_{\rm p}04. The paper states that the nonlinear attack increases the performance energy by a factor of about ypy_{\rm p}05 compared to the linear case, without increasing the residual energy enough to trigger detection (Seifullaev et al., 15 Dec 2025).

For large-scale linear systems, the computational issue is no longer the conceptual definition but the cost of solving semidefinite programs. The Hamiltonian-matrix paper reports that Algorithm 1 for RCOOG is 1–3 orders of magnitude faster than solving the SDP with MOSEK on random LTI systems with ypy_{\rm p}06, and that the speed advantage increases with system size. On positive networked control systems with up to ypy_{\rm p}07 nodes, dense-ypy_{\rm p}08 SDPs quickly become impractical, diagonal-ypy_{\rm p}09 approximations can exhibit average relative error ypy_{\rm p}10 and worst-case relative error exceeding ypy_{\rm p}11, whereas the Hamiltonian method remains largely insensitive to graph sparsity because it reduces the problem to dense eigenvalue computations for a matrix of dimension ypy_{\rm p}12 (Arnström et al., 20 Sep 2025).

The present literature also makes the main limitations explicit. In the nonlinear security setting, the S-procedure is sufficient but not necessary, so OOG bounds can be conservative; admissible nonlinearities must be representable by quadratic constraints or IQCs; the analysis is deterministic rather than stochastic; and network effects such as varying delays, packet loss, and time-varying topology are not explicitly modeled in the nonlinear OOG framework. Suggested extensions include multiplicative attacks, nonlinear time-delay systems, and more general classes of time-varying or stochastic nonlinearities (Seifullaev et al., 15 Dec 2025).

Additional limitations appear in the frequency-domain theory. The factorization-based fundamental-limit results are presented for one-dimensional input and output signals, with multi-input–multi-output extensions left for future work (Dong et al., 14 Sep 2025). The Hamiltonian method likewise assumes continuous-time LTI dynamics and requires regularization to guarantee existence of the Hamiltonian matrix in important security cases such as ypy_{\rm p}13 and ypy_{\rm p}14; the paper notes that a discrete-time extension is technically straightforward but not developed there (Arnström et al., 20 Sep 2025).

Taken together, these results establish OOG as both a precise induced-gain concept and a design-oriented vulnerability metric. In its principal security formulation, it quantifies the maximum performance loss compatible with residual stealthiness; in adjacent formulations, it also serves as a comparative framework for periodic forcing and nonlinear output maps. Across these variants, the central theme is unchanged: OOG measures how one output channel constrains, amplifies, or conceals another.

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to Output-to-Output Gain (OOG).