---
title: Robust Control Barrier Certificates
url: https://www.emergentmind.com/topics/robust-control-barrier-certificates-r-cbcs
type: topic
---

# Robust Control Barrier Certificates

Robust Control Barrier Certificates (R-CBCs) are barrier-certificate-based safety conditions and associated controller constructions that are strengthened to remain valid under uncertainty, disturbances, estimation error, adversarial inputs, or incomplete models. In the cited literature, the term is used for several closely related objects: a robustified continuous-time barrier inequality for control-affine systems, a robust discrete-time barrier certificate for worst-case disturbances, and controller-side certificates that certify safe action selection under uncertainty. Across these formulations, the common purpose is to preserve safety of a set, or of an appropriate relaxation of that set, when nominal Control Barrier Function (CBF) conditions are insufficient [1612.01554, 2109.02537, 2508.17226, 2604.13192].

## 1. Nominal barrier certificates and the robustification step

For continuous-time control-affine dynamics
\[
\dot x = f(x)+g(x)u,
\]
the nominal safe set is typically written as
\[
C=\{x\in\mathbb{R}^n:h(x)\ge 0\}
\quad\text{or}\quad
S=\{x\in\mathbb R^n:h(x)\ge 0\}.
\]
A zeroing control barrier function (ZCBF) satisfies
\[
\sup_{u\in U}\big[L_f h(x)+L_g h(x)u+\alpha(h(x))\big]\ge 0,
\]
and any Lipschitz control law selecting from
\[
K(x)=\{u\in U:\; L_f h(x)+L_g h(x)u+\alpha(h(x))\ge 0\}
\]
renders the safe set forward invariant. A standard CBF controller likewise enforces
\[
L_f h(x)+L_g h(x)k(x)+\alpha(h(x))\ge 0,
\]
which, under exact state feedback, renders the set forward invariant and asymptotically stable [1612.01554, 2508.17226].

The robustification step begins from the observation that nominal CBF conditions are pointwise in the true state. If implementation uses an estimate \(\hat x\) rather than \(x\), then the relevant expression becomes
\[
L_f h(x)+L_g h(x)k(\hat x),
\]
and the mismatch term
\[
L_g h(x)\big(k(\hat x)-k(x)\big)
\]
can destroy safety. In the 2025 state-uncertainty formulation, this motivates replacing the nominal inequality by the stronger requirement
\[
L_f h(x)+L_g h(x)k(x)+\alpha(h(x)) \ge \rho(\|L_g h(x)\|),
\]
where \(\rho\) is a robustness function. In that terminology, \(h\) is an R-CBF and \(k\) is an R-CBC controller [2508.17226].

## 2. Principal formulations of R-CBCs

One major R-CBC formulation targets state uncertainty without prior knowledge of the uncertainty magnitude. The controller has access only to an estimate satisfying
\[
\|x(t)-\hat x(t)\|\le \delta,\qquad \forall t\ge 0,
\]
and the robustifying term is specified through a function \(\rho:\mathbb R_{\ge 0}\to \mathbb R_{\ge 0}\) with \(\rho(0)=0\), \(\rho(y)\ge \varepsilon y\), and
\[
\zeta(d):=-\inf_{y\ge 0}\big(\rho(y)-yd\big)
\]
well-defined for every \(d\ge 0\). The resulting R-CBF condition is
\[
\sup_{u\in U}\Big(L_f h(x)+L_g h(x)u+\alpha(h(x))\Big)\ge \rho(\|L_g h(x)\|), \qquad \forall x,
\]
with the controller-side R-CBC inequality obtained by substituting \(u=k(x)\) [2508.17226].

A second formulation addresses sector-bounded plant-input uncertainty. The uncertain input channel is
\[
\dot{\mathbf{x}}(t) = \mathbf{f}(\mathbf{x}(t)) + \mathbf{g}(\mathbf{x}(t))\,\mathbf{v}(t),
\qquad
\mathbf{v}(t)=\phi(\mathbf{u}(t),t),
\]
with sector condition
\[
\left[\mathbf{v}(t)-\alpha \mathbf{u}(t)\right]^\top \left[\beta \mathbf{u}(t)-\mathbf{v}(t)\right]\ge 0.
\]
After loop shifting,
\[
\mathbf{v}(t)=\frac{1}{2}(\alpha+\beta)\big(\mathbf{u}(t)+\mathbf{w}(t)\big),
\qquad
\|\mathbf{w}(t)\|_2 \le \theta \|\mathbf{u}(t)\|_2,
\qquad
\theta=\frac{\beta-\alpha}{\beta+\alpha},
\]
and the robust barrier condition becomes
\[
\sup_{\mathbf{u}\in\mathcal{U}}\; \inf_{\mathbf{w}\in\mathcal{W}(\mathbf{u})}
\left[
L_{\mathbf{f}}h(\mathbf{x}) + L_{\tilde{\mathbf{g}}}h(\mathbf{x})\,(\mathbf{u}+\mathbf{w})
\right]
\ge -\eta(h(\mathbf{x})).
\]
This is an RCBF/R-CBC framework in which the uncertainty depends on the commanded control itself [2109.02537].

Discrete-time formulations replace Lie-derivative inequalities by one-step worst-case barrier conditions. For bounded uncertainty,
\[
x_{t+1}=f(x_t,u_t,d_t),
\]
a robust discrete-time CBF is defined by the existence of a class-\(\mathcal K\) function \(\beta\) such that
\[
\sup_{u\in U}\inf_{d\in D} h\bigl(f(x,u,d)\bigr)\ge \beta(h(x)),
\qquad \forall x\in \mathcal{S}.
\]
The same paper shows that the safety value function \(V\) solving the Isaacs equation is itself a valid robust DCBF and that
\[
\mathcal{S}=\{x\in X\mid V(x)\ge 0\}
\]
is exactly the maximal robust safe set. A different discrete-time R-CBC formulation for unknown input-affine polynomial systems under bounded disturbances uses a quadratic barrier
\[
\mathcal B(x)=x^\top P x
\]
together with the robust one-step inequality
\[
\mathcal B(x^+) \le \lambda \mathcal B(x) + \rho \|w\|^2,
\]
plus separation conditions on \(X_0\) and \(X_1\) [2604.13192, 2412.03919].

## 3. Safety guarantees, invariant sets, and maximality

The guarantees certified by R-CBCs depend on the uncertainty model. In the state-uncertainty framework, if a controller satisfies the R-CBC inequality and the actual input is \(u=k(x)+d\) with \(\|d(t)\|\le \bar d\), then two regimes are proved. If \(\bar d\le \varepsilon\), the original safe set
\[
S=\{x:h(x)\ge 0\}
\]
is asymptotically stable and therefore forward invariant. If \(\bar d>\varepsilon\), the inflated set
\[
S_\xi=\{x:h(x)\ge -\xi\},
\qquad
\xi = \alpha^{-1}(-\zeta(\bar d)),
\]
is asymptotically stable and forward invariant. The main measurement-uncertainty theorem gives an analogous dichotomy: sufficiently small estimation error preserves the original safe set, while larger error yields invariance of an inflated set inside a compact superlevel set \(S_\beta\) [2508.17226].

This inflated-set logic is consistent with the earlier robustness theory of zeroing barrier functions. For perturbations of the vector field, vanishing perturbations preserve asymptotic stability of the original safe set \(C\), whereas bounded non-vanishing perturbations yield local asymptotic stability of a disturbance-dependent relaxation
\[
C_{\gamma(\|g_2\|_\infty)}.
\]
That result gives an ISS-type interpretation of robustness: disturbance magnitude is mapped to a set-enlargement radius, rather than to exact invariance of the nominal set [1612.01554].

For sector-bounded input uncertainty, the guarantee is worst-case forward invariance of the safe set for all uncertainties compatible with the sector bound. If \(h\) is an RCBF and \(\frac{\partial h}{\partial \mathbf{x}}(\mathbf{x})\neq 0\) on \(\partial\mathcal C\), then any Lipschitz controller \(\mathbf{u}(\mathbf{x})\in \mathcal{U}_{RCBF}(\mathbf{x})\) renders \(\mathcal C\) robustly control invariant [2109.02537].

Discrete-time robust formulations sharpen the guarantee in a different direction. In the maximal-safe-set construction, the safety value function \(V\) is both a robust DCBF and an exact representation of the maximal robust safe set,
\[
\mathcal{S}=\{x\in X\mid V(x)\ge 0\},
\]
and the associated safety filter is recursively feasible on \(\mathcal S\). In the robust adaptive discrete-time formulation, the time-varying adaptive barrier
\[
B_t(x) := B(x) - \frac{1}{2}\tilde\theta_t^\top \Gamma^{-1}\tilde\theta_t
\]
induces adaptive safe sets \(S_t\subseteq S\), and the main theorem establishes sequential positive invariance,
\[
x_t\in S_t \implies x_{t+1}\in S_{t+1},
\]
hence robust safety with respect to the original safe set as well [2604.13192, 2508.08153].

## 4. Controller synthesis and online safety filtering

A defining feature of the R-CBC literature is that robustness is encoded in optimization-ready constraints rather than only in offline analysis. Under state uncertainty, the safe controller is computed by the minimally invasive quadratic program
\[
k(x)=\arg\min_{u\in U}\|u-k_d(x)\|^2
\]
subject to
\[
L_f h(x)+L_g h(x)u+\alpha(h(x))\ge \rho(\|L_g h(x)\|).
\]
The synthesis does not require the uncertainty magnitude \(\delta\) in advance; the uncertainty appears later through the analysis of the effective disturbance induced by \(k(\hat x)-k(x)\) [2508.17226].

For sector-bounded uncertainty, the worst-case robust constraint yields a min-norm problem that can be recast as a Second-Order Cone Program. The online filter has the form
\[
\mathbf{u}^*(\mathbf{x}) = \arg\min_{\mathbf{u}\in\mathcal{U}} \frac{1}{2}\|\mathbf{u}-\mathbf{u}_0\|_2^2
\]
subject to the robust inequality
\[
p(\mathbf{x})+ L_{\tilde{\mathbf{g}}}h(\mathbf{x})\,\mathbf{u}
- \theta\| \mathbf{u}\|_2 \|L_{\tilde{\mathbf{g}}}h(\mathbf{x})\|_2 \ge 0,
\]
with an SOCP reformulation obtained through a slack variable and a rotated second-order cone constraint [2109.02537].

The QP-based safety-filter architecture also inherits a well-posedness question: whether the feedback law generated by the optimization is locally Lipschitz. For ZCBFs, the CBF-only QP and the CLF-CBF QP are proved locally Lipschitz under the relative-degree-one condition
\[
L_g h(x)\neq 0,
\]
which guarantees local existence and uniqueness of closed-loop solutions. This is important because R-CBC implementations often rely on the same safety-filter structure, differing only in the barrier inequality being enforced [1612.01554].

In discrete time, robust safety filtering appears in several forms. The maximal-safe-set formulation uses
\[
u(x_t)=\argmin_{u_t\in U}\|u_t^\mathrm{task}-u_t\|^2
\]
subject to
\[
\min_{d_t\in D}Q(x_t,u_t,d_t)\ge \beta(V(x_t)),
\]
where \(Q\) is the lifted state-action-disturbance safety value. The robust adaptive discrete-time formulation defines
\[
\pi_t^{\text{safe}}(x;p)
=
\arg\min_{\nu\in U(x;\hat\theta_t,p)} \|\nu-\pi_{\mathrm{nom},t}(x)\|,
\]
and explicitly decouples the estimator from the safety filter: the safety layer uses only the current parameter estimate and its error bound [2604.13192, 2508.08153].

## 5. Data-driven, reinforcement-learning, and neural R-CBCs

Recent work extends R-CBC synthesis beyond explicit-model settings. One direct data-driven formulation studies unknown discrete-time input-affine polynomial systems
\[
x^+ = A\mathcal R(x) + g(x)u + w
\]
with unknown constant matrix \(A\), known \(g(x)\), and disturbance set
\[
W(\delta)=\{\,w\in\mathbb R^n \mid w^\top w \le \delta\,\}.
\]
Using a single finite trajectory, a full-row-rank condition on the monomial data matrix \(\mathbb R_{0,T}\), and a quadratic barrier \(\mathcal B(x)=x^\top P x\), the method synthesizes an R-CBC and a robust safety controller directly from data through SOS constraints, without explicit model identification. The case studies report finite-horizon guarantees \(\mathcal T=1700\) for a 2D system and \(\mathcal T=5000\) for a 3D Lorenz system, both with \(\delta=0.001\) [2412.03919].

A different line of work removes explicit dynamics even more aggressively by combining adversarial reinforcement learning with a robust Q-CBF constraint. The central theoretical statement is that the safety value function solving the dynamic programming Isaacs equation is a valid robust DCBF on the maximal robust safe set, and that the lifted Q-function
\[
Q(x_t,u_t,d_t)=\min\Bigl\{g(x_t),V\bigl(f(x_t,u_t,d_t)\bigr)\Bigr\}
\]
permits runtime safety filtering through learned \(V\) and \(Q\), rather than through analytic Lie derivatives or explicit uncertainty models. The paper validates this on a disturbed inverted pendulum and on a black-box 36-dimensional quadruped simulator; under adversarial disturbances, the quadruped experiments report a safe rate of \(16\%\) for the unfiltered policy, \(38\%\) for LRSF, and \(100\%\) safe rate over 50 trials for the neural robust Q-CBF [2604.13192].

Closely related neural-certificate developments specialize or extend the robust CBC viewpoint. In monotone systems with upper-closed unsafe sets, a robust barrier certificate is defined by
\[
B(x)\le \delta \implies \sup_{u\in U}\{B(f(x,u))\}\le \delta,
\]
and monotonicity reduces verification to boundary representatives of hyper-rectangular covers. The corresponding monotone neural framework reports \(\mathcal O(n)\) sample complexity and empirical certification on a 1,000-dimensional freeway model, a 50-dimensional urban traffic network, and a 13,659-dimensional power grid [2508.12178]. Robust neural Lyapunov-barrier certificates study bounded next-state perturbations
\[
x_{t+1}=f(x_t,u_t)+\delta_t,\qquad \|\delta_t\|_p\le \delta,
\]
and enforce robust decrease via adversarial training and Lipschitz bounds. The reported certified robustness bounds improve by up to \(4.6\) times and empirical success rates under strong perturbations by up to \(2.4\) times relative to the baseline [2602.05311].

## 6. Stochastic, adversarial, and networked generalizations

Not all robust barrier-certificate developments are deterministic worst-case invariance results. In stochastic networked control, the plant, estimator, controller, actuator, and communication network are modeled jointly through an augmented stochastic system
\[
z(k+1)=\tilde A(k)z(k)+\tilde E(k)w(k),
\]
with process noise, measurement noise, Bernoulli packet losses, and network-induced hold behavior. The barrier certificate \(\mathbb B(z)\) satisfies initial-set and unsafe-set separation together with the one-step expected-growth condition
\[
E[\mathbb B(z(k+1))\mid z(k)]\le \mathbb B(z(k))+c,
\]
which yields the finite-horizon bound
\[
P\{\mathbb S\models \Upsilon\}\ge 1-\frac{\eta+c\mathcal T}{\beta}.
\]
For the permanent magnet synchronous motor case study with \(\mu_\theta=\mu_\Phi=0.9\), the reported formal guarantee is \(97.68\%\) over horizon \(\mathcal T=100\) [2309.05570].

In adversarial stochastic games, secure control barrier certificates (S-CBCs) generalize CBCs by making the defender robust against an optimizing adversary. The defining condition is
\[
\inf \limits_{u_d}~ \sup \limits_{u_a} ~\mathbb{E}_w[B(f(x,u_d,u_a,w))\mid x] \leq B(x) +c.
\]
If the dynamics do not depend on the adversary action, this reduces to a control barrier certificate; if the dynamics are independent of both defender and adversary actions, it reduces to a barrier certificate. The framework is paired with safe-LTL\(_F\) automata and yields lower bounds on temporal-logic satisfaction probability under worst-case stationary adversary policies. In the paper’s example, the derived lower bound is
\[
\sup \limits_{\mu^{(d)}} \inf \limits_{\mu^{(a)}} \mathbb{P}_{\mu^{(d)}, \mu^{(a)}}^{x_0}\{L(\mathbf{x}_{\mathcal{N}}) \models \phi\} \geq 0.9922
\]
[1910.12282].

## 7. Scope, limitations, and recurrent distinctions in the literature

The R-CBC label does not cover every CBC-based safe-set construction. A recent SOS-based method for controlled-invariant set synthesis with polynomial control-affine systems uses nominal CBC conditions on the boundary,
\[
\forall \boldsymbol{x}\text{ s.t. } b(\boldsymbol{x})=0,\ \exists \boldsymbol{u}\in\mathcal{U}\text{ such that }
\frac{\partial b(\boldsymbol{x})}{\partial \boldsymbol{x}}\big(f(\boldsymbol{x})+g(\boldsymbol{x})\boldsymbol{u}\big)\ge 0,
\]
and explicitly notes that it is not robust: it introduces no disturbance variables, uncertainty sets, or worst-case barrier inequalities. It is therefore a nominal CBC synthesis and enlargement method, not an R-CBC framework [2411.07640].

A second distinction concerns bibliographic ambiguity. The supplied record for “A Counter-Example Guided Framework for Robust Synthesis of Switched Systems Using Control Certificates” reports only that no PDF/source is available for `1510.06108v3` and states that there is no technical content, theorem statement, or definition available in the supplied text. On that record alone, there is no basis to extract R-CBC definitions, switched-system disturbance models, or synthesis algorithms from the paper [1510.06108].

Across the literature surveyed here, “robustness” therefore denotes several non-equivalent guarantee types: invariance of the original safe set under sufficiently small uncertainty; invariance of an inflated set when uncertainty is larger; worst-case control invariance under sector-bounded or bounded disturbances; exact certification of the maximal robust safe set through a value function; finite-horizon barrier separation with additive disturbance drift; probabilistic safety under stochastic communication losses; and reach-while-avoid guarantees under bounded next-state perturbations. A plausible implication is that R-CBCs are best understood not as a single definition but as a family of barrier-certificate constructions indexed by the uncertainty model, the time domain, and the form of guarantee being certified [2508.17226, 2604.13192, 2412.03919, 2309.05570, 2602.05311].

Source: https://www.emergentmind.com/topics/robust-control-barrier-certificates-r-cbcs