---
title: Robust Control Barrier Functions
url: https://www.emergentmind.com/topics/robust-control-barrier-function-rcbf
type: topic
---

# Robust Control Barrier Functions

Robust control barrier functions are safety certificates for controlled dynamical systems that extend ordinary control barrier functions to nonideal settings such as bounded disturbances, model uncertainty, estimation error, sampled-data implementation, and learned or approximate controllers. In the foundational continuous-time treatment, safety is recast through a zeroing control barrier function whose inequality guarantees forward invariance of a safe set and admits an input-to-state-stability interpretation under perturbations: vanishing disturbances preserve asymptotic stability of the original safe set, while bounded non-vanishing disturbances yield asymptotic stability of a relaxed neighborhood of that set [1612.01554]. Subsequent work generalized this template to discrete time, high-relative-degree constraints, online learning, disturbance observers, environmental uncertainty, and predictive control [2306.17270].

## 1. Foundational zeroing formulation and robust invariance

For the control-affine system
\[
\dot x = f(x) + g(x)u,
\]
with \(f,g\) locally Lipschitz, the foundational robust CBF paper defines the safe set by a continuously differentiable function \(h\),
\[
C=\{x\in \mathbb{R}^n : h(x)\ge 0\},
\]
and calls \(h\) a zeroing barrier function if there exists an extended class-\(\mathcal K\) function \(\alpha\) such that
\[
L_f h(x)\ge -\alpha(h(x)).
\]
Its control analogue, the zeroing control barrier function, requires
\[
\sup_{u\in U}\big[L_f h(x)+L_g h(x)u+\alpha(h(x))\big]\ge 0.
\]
When a Lipschitz controller satisfies this inequality pointwise, \(C\) is forward invariant. A key distinction emphasized there is that this is a relaxed invariance condition relative to older barrier-certificate formulations: only the single set \(C=\{h\ge 0\}\) must be invariant, rather than all sublevel or superlevel sets [1612.01554].

The same paper introduces the Lyapunov-like set function
\[
V_C(x)=
\begin{cases}
0, & x\in C,\\
-h(x), & x\in D\setminus C,
\end{cases}
\]
and uses it to analyze perturbations. For vanishing perturbations, if the disturbance magnitude decreases with distance to \(C\), then \(C\) remains asymptotically stable. For bounded non-vanishing disturbances, exact invariance of \(C\) is no longer expected; instead, a relaxed set \(C_{\gamma(\|g_2\|_\infty)}\) is locally asymptotically stable. This is one of the central clarifications in the RCBF literature: bounded disturbances generally imply stability of a disturbance-dependent neighborhood of the safe set, not preservation of the nominal set itself [1612.01554].

The “zeroing” construction is also treated as a robustness choice. Because \(h\) vanishes on \(\partial C\), the system can cross the boundary under sufficiently adverse disturbance without forcing the barrier-related control input to blow up. That contrasts with reciprocal formulations whose control action may become unbounded near the boundary when exact invariance is impossible [1612.01554].

## 2. Robustification strategies across uncertainty models

Later work developed several non-equivalent robustification mechanisms. One common deterministic construction begins from a disturbed system
\[
\dot{x} = f(x)+g(x)u+p(x)d,\qquad \|d\|\le M,
\]
and imposes the Janković-style robust barrier inequality
\[
\sup_{u}\Bigl[L_f h(x)+L_g h(x)u-\|L_p h(x)\|M\Bigr]\ge -\alpha(h(x)).
\]
Because \(\|L_p h(x)\|\) is non-smooth, a smooth robust control barrier function replaces it with
\[
M\sqrt{\varepsilon+\|L_p h(x)\|^2},
\]
which is slightly more conservative but differentiable-friendly. This smooth variant was introduced specifically to support high-relative-degree backstepping for collision avoidance with unknown moving obstacles treated as disturbances [2412.03678].

When the uncertainty is control-dependent rather than purely additive, the robust term changes structure. For sector-bounded uncertainty at the plant input, loop shifting yields a perturbation satisfying \(\|\mathbf{w}(t)\|_2 \le \theta \|\mathbf{u}(t)\|_2\), and the worst-case barrier degradation becomes a penalty of the form
\[
-\theta \|\mathbf{u}\|_2 \|L_{\tilde{\mathbf{g}}}h(\mathbf{x})\|_2.
\]
The resulting min-norm safety filter is convex but not quadratic; it is recast as a second-order cone program for online implementation [2109.02537]. A closely related phenomenon appears for environmental uncertainty. When the barrier depends on an uncertain dynamic environment state \(x_s\), the robust residual is
\[
\Delta(x,x_s,\hat{x}_s,u)=e_{\frac{\partial h}{\partial t}}^*+\alpha(e_h^*)-e_{\nabla h}^*\|f(x)+g(x)u\|,
\]
so the direct robust design again becomes an SOCP because the control appears inside the norm of an affine vector field [2304.11600].

Another line of work reduces conservatism by estimating disturbances online. Disturbance observer-based robust CBFs insert an estimated disturbance \(\hat d\) into the barrier condition and compensate only the residual observer error inside the QP constraint. The safety proof is carried through a modified barrier certificate such as \(\bar h(x(t),t)=\beta h(x(t))-\|e_d\|^2\), where \(e_d=\hat d-d\), and the resulting controller can remain much closer to nominal performance than worst-case robust CBFs [2203.12855]. For state-estimation uncertainty, a different robustification strengthens the barrier inequality itself:
\[
L_fh(x)+L_gh(x)k(x)+\alpha(h(x)) \ge \rho(\|L_gh(x)\|).
\]
This formulation guarantees forward invariance of the original safe set for sufficiently small uncertainty and forward invariance of an inflated set for larger uncertainty, while not requiring prior knowledge of the uncertainty magnitude [2508.17226]. This suggests that “robustness” in the RCBF literature is not a single algebraic recipe but a family of constructions tailored to the uncertainty channel.

## 3. Optimization-based synthesis, feasibility, and regularity

A major reason for the influence of RCBFs is their compatibility with optimization-based control synthesis. The foundational CLF-CBF construction combines a control Lyapunov function \(V\) with a zeroing control barrier function \(h\) through the quadratic program
\[
\begin{aligned}
\mathcal P_2(x):\quad \min_{u,\delta}\quad & \|u\|^2 + p\,\delta^2 \\
\text{s.t.}\quad &
L_f V(x)+L_g V(x)u + cV(x)-\delta \le 0,\\
&
L_f h(x)+L_g h(x)u+\alpha(h(x)) \ge 0.
\end{aligned}
\]
The CBF constraint is hard, the CLF constraint is softened by the relaxation variable \(\delta\), and feasibility follows from the relative-degree-one assumption \(L_g h(x)\neq 0\) together with the soft CLF constraint. The same paper proves that, under local Lipschitz assumptions and \(L_g h(x)\neq 0\), both the CBF-only min-norm controller and the full CLF-CBF-QP controller are locally Lipschitz, which gives well-defined closed-loop solutions [1612.01554].

Discrete-time robust predictive control adopts the same safety-filter philosophy but at the trajectory level. In a unified online data-driven predictive control framework, model uncertainty is decomposed into system identification error \(e_s(k)\), control-learning error \(e_c(k)\), and disturbance \(w(k)\). The robust barrier is defined by
\[
h_r(\hat{x}) = h(\hat{x}) + \eta(\varepsilon_w + \varepsilon_s + \varepsilon_c),
\]
and safety is enforced by the discrete-time robust decay condition
\[
h(\hat{x}(k+1)) \le (1-\gamma)h(\hat{x}(k)) - \gamma\eta(\varepsilon_w+\varepsilon_s+\varepsilon_c),
\qquad 0<\gamma\le 1.
\]
Here \(\gamma\) is optimized inside the NMPC problem, with regularization \(\varphi(\gamma)=P\gamma^2\), to balance safety and feasibility while keeping the true state safe under bounded model and policy errors [2306.17270].

Robust adaptive discrete-time control barrier certificates push the same idea further by separating estimation and safety. For
\[
x_{t+1}=f(x_t,u_t;\theta^\ast)+w_t,
\]
with unknown parameter \(\theta^\ast\), the adaptive barrier is
\[
B_t(x) := B(x) - \frac{1}{2}\tilde\theta_t^\top \Gamma^{-1}\tilde\theta_t,
\]
and the safety filter is
\[
\pi_t^{\text{safe}}(x)=\arg\min_{\nu\in U(x;\hat\theta_t,\delta_\theta)} \|\nu-\pi_{\mathrm{nom},t}(x)\|.
\]
The corresponding guarantee is sequential positive invariance of the time-varying safe sets \(S_t=\{x\in X\mid B_t(x)\ge 0\}\), with \(S_t\subseteq S\). The estimator can be any online method that provides a point estimate and an error bound, so the certificate is estimator-agnostic rather than tied to a particular adaptive law [2508.08153].

## 4. High-relative-degree constraints, sampled-data implementations, and multi-barrier feasibility

High-relative-degree safety constraints are a recurrent source of technical difficulty because the control input does not appear in the first derivative of the safety function. One smooth robust backstepping construction starts from a candidate barrier \(h_1\) and recursively defines
\[
h_i(x)=c_{i-1}h_{i-1}(x)+L_f h_{i-1}(x)-M\delta_{i-1}(x), \qquad
\delta_k(x)=\sqrt{\varepsilon_k+\|L_p h_k(x)\|^2},
\]
with final QP constraint
\[
L_f h_n(x)+L_g h_n(x)u - M\delta_n(x)\ge -c_n h_n(x).
\]
This produces forward invariance of the original safe set \(h_1(x)\ge 0\) despite bounded disturbances, and in the moving-obstacle example it requires only a bound \(M\) on obstacle motion rather than explicit obstacle-state estimation [2412.03678].

A different robustification of high-relative-degree barriers is the sliding mode control barrier function. For relative degree \(r=2\), a sliding surface
\[
S=\dot{\tilde h}+\lambda \tilde h,\qquad \tilde h=h-h_d,
\]
is combined with a robust barrier input
\[
\mu_b=\bar\mu_b-K_{smc}\,\mathrm{sat}(S/\Phi),
\]
subject to the gain condition
\[
K_{smc}\ge \Delta+\eta.
\]
Embedded in a QP that minimizes deviation from a nominal controller, this construction preserved safety under model uncertainty in Furuta pendulum and magnetic levitation examples where nominal ECBFs failed [2010.03673].

Sampled-data implementations require an additional layer of robustness because the control is held constant between updates. High-Order Doubly Robust Control Barrier Functions and their sampled-data variants incorporate both disturbance and measurement error, together with bounds on state evolution over the sampling period, so that forward invariance holds for zero-order-hold controllers. The approach also introduces reachability-based margins to reduce the conservatism of global Lipschitz bounds [2309.08050].

A separate issue is joint feasibility. Multiple valid robust barrier constraints are not automatically compatible. For time-varying upper and lower bounding-box constraints on a second-order system with limited control authority and bounded disturbance, feasibility requires overlap of the induced input intervals,
\[
\Phi_{lb}(t,x)\le \Phi_{ub}(t,x),
\]
and the paper derives an explicit sufficient gain condition,
\[
\alpha_{ub}=\alpha_{lb}\ge 2w_{\max}\sqrt{\frac{2}{(l_{ub}(t_0)-l_{lb}(t_0))a_{\max}}},
\]
under which the admissible input set remains nonempty throughout the residual safe set [2503.18524]. Satellite work makes the same point in a different way: it constructs inner safe sets via RCBFs and enforces the barrier only in a switched manner near the boundary, allowing the system to operate safely without enforcing the RCBF condition when far from the safe set boundary and permitting tuning of how closely trajectories approach the boundary [2107.04094]. Disturbance rejection CBFs extend this direction to arbitrary relative degree under matched or unmatched, differentiable or non-differentiable disturbances, including adaptive variants that do not require a disturbance bound [2508.01601].

## 5. Data-driven, measurement-aware, and sensor-based robust variants

Recent RCBF formulations increasingly target settings in which the model used by the safety filter is identified, learned, or only partially replaced by measurements. In the data-driven predictive-control setting, the robust barrier margin explicitly aggregates system identification error, control-policy approximation error, and external disturbance,
\[
h_r(\hat{x}) = h(\hat{x}) + \eta(\varepsilon_w+\varepsilon_s+\varepsilon_c),
\]
and the robust constraint satisfaction theorem guarantees forward invariance of the true safe set when the nominal predicted trajectory satisfies the RCBF decay inequality [2306.17270]. This is a shift from model-robust safety to pipeline-robust safety: the certificate accounts simultaneously for model learning, policy learning, and exogenous disturbance.

Measurement Robust Incremental Control Barrier Functions take a different route by replacing uncertain model terms with sensor-based reduced-order dynamics. For the incremental model
\[
\dot{y}= \dot{y}_0 + B_0 \Delta u + \sigma(y,\Delta t),
\]
the robust incremental barrier condition subtracts both an approximation-error term \(\varphi(y,\Delta t)\) and a sensor-error penalty of the form
\[
\left(a(y)+b(y)\right)\|k(y)\|_2.
\]
Under bounded sensor corruption in \(\hat y\) and \(\hat{\dot y}_0\), and Lipschitz assumptions on the barrier derivatives, the resulting MRICBF controller guarantees safety despite model mismatch and sensor bias. The reported demonstrations include a first-order system with time-varying sensor bias and a hypersonic glide vehicle with multiple state constraints [2410.08096].

Sensor-based robustification also appears in field-of-view certified multi-robot control. There, second-order HOCBF/HOCLBF constraints are imposed on minimum separation, maximum sensing range, and field-of-view containment for distributed quadrotor navigation. Because the chosen high-order barrier functions use extended class-\(\mathcal K\) functions, the controller not only preserves safety when inside the visible-and-safe set but also stabilizes the system toward that set when temporary tracking loss places the estimate outside it. The continuous-time certified problem is then approximated by an MPC-CBF scheme with slack variables, particle-filter estimation, and sequential quadratic programming [2502.01009].

## 6. Terminological scope and adjacent barrier notions

The acronym “RCBF” is not unique to robust control barrier functions. In stochastic discrete-time safety, “Risk Control Barrier Functions” define the barrier condition through a dynamic coherent risk measure,
\[
\rho\big(h(x^{t+1})\big)\ge \alpha\big(h(x^t)\big),
\]
so that the resulting guarantee is \(\rho\)-safety rather than worst-case deterministic invariance. Finite-time versions give \(\rho\)-reachability, and intersections or unions of sets are handled through \(\min\) or \(\max\) compositions of multiple barriers [2203.15892].

A different stochastic line studies almost sure safety rather than bounded-uncertainty robustness. In collision avoidance for a two-wheeled vehicle under vibration, an almost sure reciprocal control barrier function uses a reciprocal barrier
\[
B_i(x_i)=\frac{1}{x_{1i}-\alpha_{ci}},
\]
an Itô correction term \(L_\sigma^I(B(x))\), and a closed-form compensator built from
\[
\gamma B(x)-L_\sigma^I(B(x)).
\]
The resulting controller guarantees invariance of the safe set with probability one under Gaussian white-noise vibration [2603.27934].

The acronym is also used for “Recurrent Control Barrier Functions,” which replace invariance by finite-time recurrence. There the core condition is
\[
\max_{t\in (0,\tau]} e^{\gamma(h(\phi(t,x,u)))t}\, h(\phi(t,x,u)) \ge h(x),
\]
and safety is certified when the recurrent set avoids the \(\tau\)-backward reachable tube of the unsafe region. Under mild assumptions, the signed-distance function to a suitable set is itself an RCBF, so the problem becomes set identification rather than direct barrier synthesis [2510.02127]. These notions are barrier-theoretically related, but they are distinct from robust control barrier functions in the bounded-uncertainty sense.

Source: https://www.emergentmind.com/topics/robust-control-barrier-function-rcbf