Papers
Topics
Authors
Recent
Search
2000 character limit reached

Viability Kernel in Control Theory

Updated 11 July 2026
  • Viability kernel is the set of states ensuring the existence of at least one control that maintains system trajectories within a prescribed safe or desirable set.
  • The concept extends to robust, discriminating, and stochastic formulations by altering quantifiers to address uncertainties and disturbances.
  • Analytical characterizations and computational methods—such as grid-based algorithms, Hamilton–Jacobi reachability, and dynamic programming—enable practical approximations and diverse applications.

The viability kernel is the set of states from which a constrained dynamical system admits at least one admissible evolution that remains inside a prescribed desirable or safe set. In the cited literature, it appears as the standard viability-theoretic object for continuous-time and discrete-time control systems, as the largest control-invariant safe set for constrained nonlinear systems, and as a weak forward invariant set when only the existence of a non-failing continuation is required rather than invariance under all trajectories (Alvarez et al., 2021, Rocca et al., 2023, Yeganegi et al., 2020). Across applications, the notion is extended by changing the quantifiers: deterministic viability requires existence of an admissible control; robust or discriminating formulations require existence of a control against all admissible disturbances; stochastic viability replaces hard satisfaction by a chance constraint; and guaranteed viability addresses disagreement on the dynamics themselves (Doyen et al., 2010, Sepulveda et al., 2017, Alvarez et al., 2021).

1. Classical definition and set-theoretic meaning

For continuous-time controlled dynamics

Sc(f,U){x(t)=f(x(t),u(t)) u(t)U(x(t))Rp  ,Sc(f,U)\left\{ \begin{array}{lcl} x'(t)&=&f(x(t),u(t))\ u(t)&\in &U(x(t))\subset \mathbb{R}^{p}\; , \end{array} \right.

and discrete-time controlled dynamics

Sd(f,U){xk+1=f(xk,uk) ukU(xk)Rp  ,Sd(f,U)\left\{ \begin{array}{lcl} x^{k+1}&=&f(x^k,u^k)\ u^k&\in &U(x^k)\subset \mathbb{R}^{p}\; , \end{array} \right.

a trajectory is viable in a constraint set KK if it remains in KK for all future time. A set LL is viable if every xLx\in L admits at least one evolution that stays in LL. The viability kernel associated to the system under constraint KK is therefore the set of all states in KK from which there exists an evolution starting at that state and viable in KK (Alvarez et al., 2021).

In explicit continuous-time form, one paper writes

Sd(f,U){xk+1=f(xk,uk) ukU(xk)Rp  ,Sd(f,U)\left\{ \begin{array}{lcl} x^{k+1}&=&f(x^k,u^k)\ u^k&\in &U(x^k)\subset \mathbb{R}^{p}\; , \end{array} \right.0

with an analogous discrete-time definition (Alvarez et al., 2021). In finite-horizon form, the same idea becomes

Sd(f,U){xk+1=f(xk,uk) ukU(xk)Rp  ,Sd(f,U)\left\{ \begin{array}{lcl} x^{k+1}&=&f(x^k,u^k)\ u^k&\in &U(x^k)\subset \mathbb{R}^{p}\; , \end{array} \right.1

which is the formulation used for constrained LTI safety analysis (Kaynama et al., 2013).

For discrete-time difference inclusions Sd(f,U){xk+1=f(xk,uk) ukU(xk)Rp  ,Sd(f,U)\left\{ \begin{array}{lcl} x^{k+1}&=&f(x^k,u^k)\ u^k&\in &U(x^k)\subset \mathbb{R}^{p}\; , \end{array} \right.2, a set Sd(f,U){xk+1=f(xk,uk) ukU(xk)Rp  ,Sd(f,U)\left\{ \begin{array}{lcl} x^{k+1}&=&f(x^k,u^k)\ u^k&\in &U(x^k)\subset \mathbb{R}^{p}\; , \end{array} \right.3 is a discrete viability domain if

Sd(f,U){xk+1=f(xk,uk) ukU(xk)Rp  ,Sd(f,U)\left\{ \begin{array}{lcl} x^{k+1}&=&f(x^k,u^k)\ u^k&\in &U(x^k)\subset \mathbb{R}^{p}\; , \end{array} \right.4

The discrete viability kernel Sd(f,U){xk+1=f(xk,uk) ukU(xk)Rp  ,Sd(f,U)\left\{ \begin{array}{lcl} x^{k+1}&=&f(x^k,u^k)\ u^k&\in &U(x^k)\subset \mathbb{R}^{p}\; , \end{array} \right.5 is then the largest closed discrete viability domain contained in Sd(f,U){xk+1=f(xk,uk) ukU(xk)Rp  ,Sd(f,U)\left\{ \begin{array}{lcl} x^{k+1}&=&f(x^k,u^k)\ u^k&\in &U(x^k)\subset \mathbb{R}^{p}\; , \end{array} \right.6 (Liniger et al., 2017). This formulation makes the existential quantifier explicit: viability requires that at each state there exists at least one admissible successor that remains in the candidate set.

Several papers stress that this is weaker than positive invariance. In walking control, the viability kernel is “also called weak forward invariant set,” precisely because it does not require that every solution starting in the set remain there (Yeganegi et al., 2020). In robot-manipulator safety, the same object is described as the “largest control-invariant safe set” inside the feasible state set Sd(f,U){xk+1=f(xk,uk) ukU(xk)Rp  ,Sd(f,U)\left\{ \begin{array}{lcl} x^{k+1}&=&f(x^k,u^k)\ u^k&\in &U(x^k)\subset \mathbb{R}^{p}\; , \end{array} \right.7 (Rocca et al., 2023).

2. Quantifier structure and principal variants

The deterministic viability kernel uses an existential control quantifier. Robust formulations strengthen the requirement by adding a universal disturbance quantifier. In a controlled Ross–Macdonald dengue model, the robust viability kernel is the set of initial epidemic states for which there exists at least one admissible fumigation strategy such that, for every uncertainty scenario in Sd(f,U){xk+1=f(xk,uk) ukU(xk)Rp  ,Sd(f,U)\left\{ \begin{array}{lcl} x^{k+1}&=&f(x^k,u^k)\ u^k&\in &U(x^k)\subset \mathbb{R}^{p}\; , \end{array} \right.8, the resulting trajectory always respects the infection cap Sd(f,U){xk+1=f(xk,uk) ukU(xk)Rp  ,Sd(f,U)\left\{ \begin{array}{lcl} x^{k+1}&=&f(x^k,u^k)\ u^k&\in &U(x^k)\subset \mathbb{R}^{p}\; , \end{array} \right.9 (Sepulveda et al., 2017). In the waste-to-energy setting, the finite-horizon backward reachable set

KK0

is stated to “coincide with the viability kernel for KK1 under uncertainty,” with the infinite-horizon limit identified as the classical viability kernel (Bouhmady et al., 13 Oct 2025).

A closely related robust object is the discriminating kernel, which formalizes best-case control against worst-case disturbance. For disturbed discrete dynamics, a discrete discriminating domain KK2 satisfies

KK3

and the discrete discriminating kernel is the largest closed discriminating domain contained in KK4 (Liniger et al., 2017). A zonotope-based paper uses the same quantifier pattern in finite horizon:

KK5

and distinguishes it from the viability kernel

KK6

and the invariant kernel

KK7

(Mitchell et al., 2019).

Stochastic viability replaces hard pathwise satisfaction by a chance constraint. For uncertain discrete-time dynamics, the stochastic viability kernel at confidence level KK8 is

KK9

and it is exactly the KK0-superlevel set of the stochastic viability value function:

KK1

The same paper notes that KK2 is close to robust viability, while degenerate uncertainty recovers the deterministic viability kernel (Doyen et al., 2010).

A stronger variant is the guaranteed viability kernel for model disagreement. In environmental-commons management, stakeholders may agree on state variables, admissible controls, and desirable states, while disagreeing on the dynamics. The guaranteed viability kernel is the largest subset of KK3 for which there exists a shared regulation map such that, for all initial states in that subset and for all perturbations encoding the competing models, all resulting trajectories remain viable in the subset (Alvarez et al., 2021). The paper identifies this as a “crucial quantifier shift”: classical viability asks for existence of at least one viable trajectory, whereas guaranteed viability requires a regulation map under which all relevant trajectories remain viable.

3. Analytical characterizations

A recurring theme is that viability kernels admit exact characterizations as value-function level sets, epigraphs, or invariance objects in augmented spaces. In finite-horizon multiobjective optimal control, the set-valued return function

KK4

has the property that its set-valued epigraph

KK5

coincides with a viability kernel:

KK6

This transforms the Pareto-return problem into a viability problem in the augmented space KK7, with KK8 interpreted as a remaining-cost budget variable (Guigue, 2012).

Robust Hamilton–Jacobi reachability gives a different characterization. In the waste-to-energy model, the robust value function

KK9

is the worst-case signed constraint violation under optimal control, and the finite-horizon robust viability set is its zero sublevel set:

LL0

Under the stated Lipschitz, compactness, and Isaacs assumptions, LL1 is the unique bounded uniformly continuous viscosity solution of a constrained Hamilton–Jacobi equation (Bouhmady et al., 13 Oct 2025).

Dynamic programming yields a third standard representation. In stochastic viability, the Bellman recursion

LL2

computes the maximal probability of remaining viable over the horizon, and the stochastic viability kernel is the corresponding level set LL3 (Doyen et al., 2010). In robust dengue control, a backward recursion of indicator-valued functions plays the same role:

LL4

with the robust kernel given by

LL5

(Sepulveda et al., 2017).

The viability kernel also serves as a primitive for more elaborate state-space classifications. In the Topology of Sustainable Management, the shelter is a viability niche under the default control,

LL6

while the manageable region is the viability kernel of the desirable set under the full control family,

LL7

Capture basins built from these sets then generate the remaining TSM regions (Kittel et al., 2017).

4. Approximation and computational methods

The classical grid-based approximation is the Saint-Pierre viability algorithm and related fixed-point recursions. For a discretized difference inclusion, the recursion

LL8

characterizes the viability kernel as the limit intersection under mild assumptions (Liniger et al., 2017). In TSM computations, a discretized Saint-Pierre procedure is used both for viability kernels and for capture basins, with viability approximated from the outside and capture basins from the inside (Kittel et al., 2017).

In multiobjective optimal control, viability-kernel approximation is combined with dynamic programming on discrete grids. The approximate set-valued return functions LL9 are defined so that

xLx\in L0

where xLx\in L1 is the xLx\in L2-th finite discrete viability set. The resulting epigraphs converge to the exact epigraph in the sense of Painlevé–Kuratowski convergence as xLx\in L3 and xLx\in L4 (Guigue, 2012).

A central practical issue is robustness to discretization. In autonomous racing, standard gridded viability can certify grid points while failing to certify every true state in the corresponding cell. To account for state-discretization error, the paper models the error as an additive disturbance and computes a discriminating kernel instead. The resulting finite algorithm yields an inner approximation with the guarantee that, for all states in the cell surrounding a viable grid point, there exists a control that keeps the system within the kernel (Liniger et al., 2017).

Hamilton–Jacobi methods provide a different numerical route. The waste-to-energy paper solves the constrained HJ equation on a three-dimensional structured grid using a level-set method with the Local Lax–Friedrichs numerical Hamiltonian. In the reported simulations, the grid has xLx\in L5 nodes, the runtime is about xLx\in L6 hours on a 16-core CPU with 64 GB RAM, and grid refinement from xLx\in L7 to xLx\in L8 yielded an xLx\in L9 difference below LL0 (Bouhmady et al., 13 Oct 2025).

Several papers address the curse of dimensionality by changing the set representation or the state coordinates. One approach is decentralized computation for LTI systems: after a modified Riccati transformation, the full viability kernel is conservatively reconstructed from a product of a subsystem viability kernel and a subsystem invariance kernel, making Eulerian methods usable on systems such as a 6D example that would otherwise require about LL1 TB just to store the grid (Kaynama et al., 2013). Another is zonotope scaling: candidate invariant, viable, and discriminating sets are represented as scaled zonotopes in center-generator form, and the scale factors are obtained through efficient convex optimizations, yielding sound under-approximations rather than exact kernels (Mitchell et al., 2019). A third is direct learning of the viability boundary: VBOC solves optimal control problems whose locally optimal initial states are guaranteed to lie on the viability boundary, then learns the boundary with a neural network; on systems up to dimension 6, the reported result is “more than 2 times as accurate for the same computation time, or 6 times as fast to reach the same accuracy” (Rocca et al., 2023).

5. Applications and domain-specific interpretations

In multiobjective optimal control, the viability kernel is used to characterize and approximate Pareto-optimal costs without convexity assumptions on the objective space. This matters because weighted scalarization can recover the whole Pareto front only when the objective space is convex; for nonconvex objective spaces, weighted methods generally miss unsupported Pareto points, whereas the viability-theoretic formulation directly handles the set-valued Pareto object (Guigue, 2012).

In process systems, the viability kernel becomes a safe operating envelope. For constrained waste-to-energy dynamics with state LL2, the kernel is interpreted as the set of initial waste-stock, capital, and energy states from which one can guarantee constraint satisfaction and attainment of sustainable operation despite worst-case inflow uncertainty. The main reported application finding is that increasing inflow uncertainty shrinks the viability kernel or backward reachable set, thereby shrinking the safe operating envelope (Bouhmady et al., 13 Oct 2025).

In epidemiology, the kernel becomes a public-health feasibility region. In the dengue model, it is the set of initial outbreak states LL3 from which bounded daily fumigation can guarantee that the proportion of infected humans never exceeds a prescribed threshold for all days in the horizon and for all admissible uncertainty scenarios (Sepulveda et al., 2017).

In environmental management, the viability kernel is used as a governance object. For a common desirable set LL4, a state in stakeholder LL5's viability kernel means that, according to stakeholder LL6's model, there exists some admissible decision sequence capable of maintaining the commons forever within LL7. The guaranteed viability kernel strengthens this to a shared regulation rule that works across the embedded family of conflicting models, so that the group obtains a consensus-sustainable domain even without agreement on the correct evolution law (Alvarez et al., 2021).

In robotics and autonomous systems, the interpretation is operationally direct. In autonomous racing, the viability kernel is used offline to prune finite look-ahead trajectories so that the online planner generates only recursively feasible motions inside the track (Liniger et al., 2017). In humanoid walking, the kernel is derived analytically as bounds on the DCM offset for a constrained LIPM, and the measured state is projected into that kernel before each slow MPC solve; this guarantees existence of at least one non-divergent continuation for the reduced-order model state supplied to the planner (Yeganegi et al., 2020). In robot-manipulator safety, the viability kernel is the largest set of states from which admissible controls can keep the manipulator forever inside the safe state set LL8, and boundary-learning methods are motivated precisely by the difficulty of computing that set for nonlinear systems (Rocca et al., 2023).

A distinct robotics interpretation appears in model-free learning. For a constrained SLIP running model, the viability kernel is the set of apex states from which there exists at least one time-evolution confined to the desired hopping region. The paper’s counterintuitive claim is that initialization outside that kernel can improve the reward landscape, because some “doomed-to-fail” states still admit one or several non-failing transitions and therefore produce informative reward (Heim et al., 2018).

6. Misconceptions, conservatism, and current extensions

Several papers emphasize that viability is not interchangeable with more familiar approximations. In multiobjective optimal control, scalarization is not a substitute when the objective space is nonconvex, because unsupported Pareto points can be missed (Guigue, 2012). In environmental commons with conflicting models, a nonempty intersection of individual viability kernels,

LL9

is not enough: the intersection need not itself be viable for all stakeholders, since viability also depends on compatibility of viable controls and trajectories (Alvarez et al., 2021).

Conservatism enters from multiple sources. Grid-based methods suffer from the curse of dimensionality and from discretization artifacts; the racing paper shows that standard gridded viability can be overoptimistic between grid points, while the discriminating-kernel construction restores a cell-wise guarantee at the cost of a more conservative safe set (Liniger et al., 2017). Hamilton–Jacobi methods are computationally tractable for systems of moderate dimension but still limited by the curse of dimensionality (Bouhmady et al., 13 Oct 2025). Modified-Riccati and zonotope methods return under-approximations rather than exact kernels, exchanging completeness for tractability (Kaynama et al., 2013, Mitchell et al., 2019). Learned boundaries are likewise approximate: in VBOC, the optimal-control-generated samples are guaranteed boundary points, but the neural-network fit is not exact, so the learned set is only approximately invariant (Rocca et al., 2023).

Reduced-order models create an additional interpretive limit. In walking MPC, the viability kernel is computed for a constrained LIPM/DCM model, not for the full robot; some full-body states outside the reduced-order kernel may still be recoverable, and some projected reduced-order states may still be poorly trackable by the whole-body controller (Yeganegi et al., 2020). This suggests that model mismatch affects not only control performance but also the operational meaning of the kernel itself.

A common misconception is that training or control should always remain inside the viability kernel. The running paper shows that this is not universally true for learning: in its constrained SLIP example, feasible initialization including unviable states increased the salient gradient set in parameter space by just over 79%, whereas nearly doubling exploration variance from KK0 to KK1 increased it by only 13%. A plausible implication is that strict viable-only initialization can be too conservative for model-free policy search in systems that can “fall with grace” (Heim et al., 2018).

An emerging extension treats viability kernels as random set-valued outputs under parametric uncertainty. A kernel-based sensitivity-analysis paper introduces a characteristic kernel on measurable sets,

KK2

and explicitly notes applicability to “viability fields” and to outputs “called viability kernels.” This makes it possible to rank uncertain inputs by their effect on the entire viable region through HSIC-ANOVA indices, rather than through a scalar summary such as volume (Fellmann et al., 2023).

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to Viability Kernel.