---
title: Viability Kernel in Control Theory
url: https://www.emergentmind.com/topics/viability-kernel
type: topic
---

# Viability Kernel in Control Theory

The viability kernel is the set of states from which a constrained dynamical system admits at least one admissible evolution that remains inside a prescribed desirable or safe set. In the cited literature, it appears as the standard viability-theoretic object for continuous-time and discrete-time control systems, as the largest control-invariant safe set for constrained nonlinear systems, and as a weak forward invariant set when only the existence of a non-failing continuation is required rather than invariance under all trajectories [2107.02684, 2305.07535, 2010.04514]. Across applications, the notion is extended by changing the quantifiers: deterministic viability requires existence of an admissible control; robust or discriminating formulations require existence of a control against all admissible disturbances; stochastic viability replaces hard satisfaction by a chance constraint; and guaranteed viability addresses disagreement on the dynamics themselves [1002.1140, 1708.08287, 2107.02684].

## 1. Classical definition and set-theoretic meaning

For continuous-time controlled dynamics
$$
Sc(f,U)\left\{
\begin{array}{lcl}
x'(t)&=&f(x(t),u(t))\\
u(t)&\in &U(x(t))\subset \mathbb{R}^{p}\; ,
\end{array}
\right.
$$
and discrete-time controlled dynamics
$$
Sd(f,U)\left\{
\begin{array}{lcl}
x^{k+1}&=&f(x^k,u^k)\\
u^k&\in &U(x^k)\subset \mathbb{R}^{p}\; ,
\end{array}
\right.
$$
a trajectory is viable in a constraint set \(K\) if it remains in \(K\) for all future time. A set \(L\) is viable if every \(x\in L\) admits at least one evolution that stays in \(L\). The viability kernel associated to the system under constraint \(K\) is therefore the set of all states in \(K\) from which there exists an evolution starting at that state and viable in \(K\) [2107.02684].

In explicit continuous-time form, one paper writes
$$
\viab_{Sc(f,U)}(K) = \left\{ x_0\in K \;:\; \exists u(\cdot)\ \text{with } u(t)\in U(x(t)),\ \forall t\ge 0,\ x(t)\in K \right\},
$$
with an analogous discrete-time definition [2107.02684]. In finite-horizon form, the same idea becomes
$$
Viab_{[0,\tau]}(K,U):= \left\{ x_0 \in K \mid  \exists  u(\cdot)\in U_{[0,\tau]}, \,  \forall  t\in [0,\tau],\, \xi_{x_0,u}(t) \in K \right\},
$$
which is the formulation used for constrained LTI safety analysis [1302.5990].

For discrete-time difference inclusions \(x_{k+1}\in F(x_k)\), a set \(D\subset \mathbb{R}^n\) is a discrete viability domain if
$$
F(x)\cap D \neq \emptyset \qquad \forall x\in D.
$$
The discrete viability kernel \(Viab_F(K)\) is then the largest closed discrete viability domain contained in \(K\) [1701.08735]. This formulation makes the existential quantifier explicit: viability requires that at each state there exists at least one admissible successor that remains in the candidate set.

Several papers stress that this is weaker than positive invariance. In walking control, the viability kernel is “also called weak forward invariant set,” precisely because it does not require that every solution starting in the set remain there [2010.04514]. In robot-manipulator safety, the same object is described as the “largest control-invariant safe set” inside the feasible state set \(\mathcal X\) [2305.07535].

## 2. Quantifier structure and principal variants

The deterministic viability kernel uses an existential control quantifier. Robust formulations strengthen the requirement by adding a universal disturbance quantifier. In a controlled Ross–Macdonald dengue model, the robust viability kernel is the set of initial epidemic states for which there exists at least one admissible fumigation strategy such that, for every uncertainty scenario in \(S^{T-t_0}\), the resulting trajectory always respects the infection cap \(H(t)\le \bar H\) [1708.08287]. In the waste-to-energy setting, the finite-horizon backward reachable set
$$
\mathcal{R}_Q(t)=\Big\{ y\in\mathcal{D}: \exists \mathbf{u}(\cdot)\in\mathcal{U},\ \forall \eta(\cdot)\in\mathcal{A},\; \mathbf{z}_y^\eta(s)\in\mathcal{D},\ \forall s\in[t,T],\; \mathbf{z}_y^\eta(T)\in\mathcal{M}_Q \Big\}
$$
is stated to “coincide with the viability kernel for \((\mathcal{D},\mathcal{M}_Q)\) under uncertainty,” with the infinite-horizon limit identified as the classical viability kernel [2510.11396].

A closely related robust object is the discriminating kernel, which formalizes best-case control against worst-case disturbance. For disturbed discrete dynamics, a discrete discriminating domain \(Q\) satisfies
$$
G(x,v)\cap Q\neq \emptyset \qquad \forall x\in Q,\ \forall v\in V,
$$
and the discrete discriminating kernel is the largest closed discriminating domain contained in \(K\) [1701.08735]. A zonotope-based paper uses the same quantifier pattern in finite horizon:
$$
\mathrm{Disc}_{[0,T]}(X) = \left\{ x(0)\in X \;\middle|\; \exists u(\cdot),\ \forall v(\cdot),\ \forall t\in[0,T],\ x(t)\in X \right\}
$$
and distinguishes it from the viability kernel
$$
\mathrm{Viab}_{[0,T]}(X) = \left\{ x(0)\in X \;\middle|\; \exists u(\cdot),\ \forall t\in[0,T],\ x(t)\in X \right\}
$$
and the invariant kernel
$$
\mathrm{Inv}_{[0,T]}(X) = \left\{ x(0)\in X \;\middle|\; \forall v(\cdot),\ \forall t\in[0,T],\ x(t)\in X \right\}
$$
[1901.01006].

Stochastic viability replaces hard pathwise satisfaction by a chance constraint. For uncertain discrete-time dynamics, the stochastic viability kernel at confidence level \(\beta\) is
$$
\mathrm{Viab}_{\beta}(t_0) := \left\{ x_0 \in \mathbb{X} \;\middle|\; \exists \mathfrak{u} \in \mathfrak{U}^{ad}\ \text{s.t. constraints hold over the horizon with probability at least } \beta \right\},
$$
and it is exactly the \(\beta\)-superlevel set of the stochastic viability value function:
$$
\mathrm{Viab}_{\beta}(t_0)=\{x_0\in\mathbb{X}\mid V(t_0,x_0)\ge \beta\}.
$$
The same paper notes that \(\beta=1\) is close to robust viability, while degenerate uncertainty recovers the deterministic viability kernel [1002.1140].

A stronger variant is the guaranteed viability kernel for model disagreement. In environmental-commons management, stakeholders may agree on state variables, admissible controls, and desirable states, while disagreeing on the dynamics. The guaranteed viability kernel is the largest subset of \(K\) for which there exists a shared regulation map such that, for all initial states in that subset and for all perturbations encoding the competing models, all resulting trajectories remain viable in the subset [2107.02684]. The paper identifies this as a “crucial quantifier shift”: classical viability asks for existence of at least one viable trajectory, whereas guaranteed viability requires a regulation map under which all relevant trajectories remain viable.

## 3. Analytical characterizations

A recurring theme is that viability kernels admit exact characterizations as value-function level sets, epigraphs, or invariance objects in augmented spaces. In finite-horizon multiobjective optimal control, the set-valued return function
$$
V(t,\mathbf{x}) = \mathcal{E}(\mathrm{cl}(Y(t,\mathbf{x})))
$$
has the property that its set-valued epigraph
$$
\mathrm{Epi}(V)=\mathrm{Graph}(V+\mathbf{R}_+^p)
$$
coincides with a viability kernel:
$$
\mathrm{Epi}(V) = \mathrm{Viab}_\phi(\mathcal{H}).
$$
This transforms the Pareto-return problem into a viability problem in the augmented space \((t,\mathbf x,\mathbf z)\), with \(\mathbf z\) interpreted as a remaining-cost budget variable [1203.0292].

Robust Hamilton–Jacobi reachability gives a different characterization. In the waste-to-energy model, the robust value function
$$
V(t,y)=\inf_{\mathbf{u}(\cdot)}\sup_{\eta(\cdot)} \max\Big\{ g_Q(\mathbf{z}_y^\eta(T)),\; \sup_{s\in[t,T]} g_D(\mathbf{z}_y^\eta(s)) \Big\}
$$
is the worst-case signed constraint violation under optimal control, and the finite-horizon robust viability set is its zero sublevel set:
$$
\mathcal{R}_Q(t)=\{y\in\mathcal{D}:V(t,y)\le 0\}.
$$
Under the stated Lipschitz, compactness, and Isaacs assumptions, \(V\) is the unique bounded uniformly continuous viscosity solution of a constrained Hamilton–Jacobi equation [2510.11396].

Dynamic programming yields a third standard representation. In stochastic viability, the Bellman recursion
$$
V(T,x)=\mathbf{1}_{\mathbb{A}(T)}(x), \qquad
V(t,x)=\max_{u\in \mathbb{B}(t,x)}\mathbb{E}_\mu\left[\mathbf{1}_{\mathbb{A}(t)}(x)V(t+1,f(t,x,u,w))\right]
$$
computes the maximal probability of remaining viable over the horizon, and the stochastic viability kernel is the corresponding level set \(V\ge \beta\) [1002.1140]. In robust dengue control, a backward recursion of indicator-valued functions plays the same role:
$$
\mathbf{V}_t(M,H) = 1_{\mathbb{A}(M,H)}\, \sup_{u\in[\underline{u},\bar{u}]} \inf_{(A_M,A_H)\in S} \mathbf{V}_{t+1}\bigl( \Phi(M,H,u,A_M,A_H) \bigr),
$$
with the robust kernel given by
$$
V_S(t_0)=\{(M,H)\in[0,1]^2\mid \mathbf{V}_{t_0}(M,H)=1\}
$$
[1708.08287].

The viability kernel also serves as a primitive for more elaborate state-space classifications. In the Topology of Sustainable Management, the shelter is a viability niche under the default control,
$$
\mathcal S := \mathrm{VN}_{u_0}(X^+),
$$
while the manageable region is the viability kernel of the desirable set under the full control family,
$$
\mathcal M := \mathrm{Viab}_{\mathcal U}(X^+).
$$
Capture basins built from these sets then generate the remaining TSM regions [1706.04542].

## 4. Approximation and computational methods

The classical grid-based approximation is the Saint-Pierre viability algorithm and related fixed-point recursions. For a discretized difference inclusion, the recursion
$$
K^0 = K, \qquad
K^{n+1} = \{x\in K^n \mid F(x)\cap K^n \neq \emptyset\}
$$
characterizes the viability kernel as the limit intersection under mild assumptions [1701.08735]. In TSM computations, a discretized Saint-Pierre procedure is used both for viability kernels and for capture basins, with viability approximated from the outside and capture basins from the inside [1706.04542].

In multiobjective optimal control, viability-kernel approximation is combined with dynamic programming on discrete grids. The approximate set-valued return functions \(V_{\epsilon,h}^k\) are defined so that
$$
\mathrm{Graph}(V^{k}_{\epsilon,h} +  \mathbf{R}_{h,+}^p) = A^k,
$$
where \(A^k\) is the \(k\)-th finite discrete viability set. The resulting epigraphs converge to the exact epigraph in the sense of Painlevé–Kuratowski convergence as \(\epsilon\to 0^+\) and \(h/\epsilon\to 0^+\) [1203.0292].

A central practical issue is robustness to discretization. In autonomous racing, standard gridded viability can certify grid points while failing to certify every true state in the corresponding cell. To account for state-discretization error, the paper models the error as an additive disturbance and computes a discriminating kernel instead. The resulting finite algorithm yields an inner approximation with the guarantee that, for all states in the cell surrounding a viable grid point, there exists a control that keeps the system within the kernel [1701.08735].

Hamilton–Jacobi methods provide a different numerical route. The waste-to-energy paper solves the constrained HJ equation on a three-dimensional structured grid using a level-set method with the Local Lax–Friedrichs numerical Hamiltonian. In the reported simulations, the grid has \(100^3=10^6\) nodes, the runtime is about \(1.8\) hours on a 16-core CPU with 64 GB RAM, and grid refinement from \(50^3\) to \(100^3\) yielded an \(L^\infty\) difference below \(10^{-3}\) [2510.11396].

Several papers address the curse of dimensionality by changing the set representation or the state coordinates. One approach is decentralized computation for LTI systems: after a modified Riccati transformation, the full viability kernel is conservatively reconstructed from a product of a subsystem viability kernel and a subsystem invariance kernel, making Eulerian methods usable on systems such as a 6D example that would otherwise require about \(380\) TB just to store the grid [1302.5990]. Another is zonotope scaling: candidate invariant, viable, and discriminating sets are represented as scaled zonotopes in center-generator form, and the scale factors are obtained through efficient convex optimizations, yielding sound under-approximations rather than exact kernels [1901.01006]. A third is direct learning of the viability boundary: VBOC solves optimal control problems whose locally optimal initial states are guaranteed to lie on the viability boundary, then learns the boundary with a neural network; on systems up to dimension 6, the reported result is “more than 2 times as accurate for the same computation time, or 6 times as fast to reach the same accuracy” [2305.07535].

## 5. Applications and domain-specific interpretations

In multiobjective optimal control, the viability kernel is used to characterize and approximate Pareto-optimal costs without convexity assumptions on the objective space. This matters because weighted scalarization can recover the whole Pareto front only when the objective space is convex; for nonconvex objective spaces, weighted methods generally miss unsupported Pareto points, whereas the viability-theoretic formulation directly handles the set-valued Pareto object [1203.0292].

In process systems, the viability kernel becomes a safe operating envelope. For constrained waste-to-energy dynamics with state \(\mathbf z=(x,K,E)\), the kernel is interpreted as the set of initial waste-stock, capital, and energy states from which one can guarantee constraint satisfaction and attainment of sustainable operation despite worst-case inflow uncertainty. The main reported application finding is that increasing inflow uncertainty shrinks the viability kernel or backward reachable set, thereby shrinking the safe operating envelope [2510.11396].

In epidemiology, the kernel becomes a public-health feasibility region. In the dengue model, it is the set of initial outbreak states \((M_0,H_0)\) from which bounded daily fumigation can guarantee that the proportion of infected humans never exceeds a prescribed threshold for all days in the horizon and for all admissible uncertainty scenarios [1708.08287].

In environmental management, the viability kernel is used as a governance object. For a common desirable set \(K=\bigcap_i K_i\), a state in stakeholder \(i\)'s viability kernel means that, according to stakeholder \(i\)'s model, there exists some admissible decision sequence capable of maintaining the commons forever within \(K\). The guaranteed viability kernel strengthens this to a shared regulation rule that works across the embedded family of conflicting models, so that the group obtains a consensus-sustainable domain even without agreement on the correct evolution law [2107.02684].

In robotics and autonomous systems, the interpretation is operationally direct. In autonomous racing, the viability kernel is used offline to prune finite look-ahead trajectories so that the online planner generates only recursively feasible motions inside the track [1701.08735]. In humanoid walking, the kernel is derived analytically as bounds on the DCM offset for a constrained LIPM, and the measured state is projected into that kernel before each slow MPC solve; this guarantees existence of at least one non-divergent continuation for the reduced-order model state supplied to the planner [2010.04514]. In robot-manipulator safety, the viability kernel is the largest set of states from which admissible controls can keep the manipulator forever inside the safe state set \(\mathcal X\), and boundary-learning methods are motivated precisely by the difficulty of computing that set for nonlinear systems [2305.07535].

A distinct robotics interpretation appears in model-free learning. For a constrained SLIP running model, the viability kernel is the set of apex states from which there exists at least one time-evolution confined to the desired hopping region. The paper’s counterintuitive claim is that initialization outside that kernel can improve the reward landscape, because some “doomed-to-fail” states still admit one or several non-failing transitions and therefore produce informative reward [1806.06569].

## 6. Misconceptions, conservatism, and current extensions

Several papers emphasize that viability is not interchangeable with more familiar approximations. In multiobjective optimal control, scalarization is not a substitute when the objective space is nonconvex, because unsupported Pareto points can be missed [1203.0292]. In environmental commons with conflicting models, a nonempty intersection of individual viability kernels,
$$
H=\bigcap_{i\in\mathcal N} \viab_i(K),
$$
is not enough: the intersection need not itself be viable for all stakeholders, since viability also depends on compatibility of viable controls and trajectories [2107.02684].

Conservatism enters from multiple sources. Grid-based methods suffer from the curse of dimensionality and from discretization artifacts; the racing paper shows that standard gridded viability can be overoptimistic between grid points, while the discriminating-kernel construction restores a cell-wise guarantee at the cost of a more conservative safe set [1701.08735]. Hamilton–Jacobi methods are computationally tractable for systems of moderate dimension but still limited by the curse of dimensionality [2510.11396]. Modified-Riccati and zonotope methods return under-approximations rather than exact kernels, exchanging completeness for tractability [1302.5990, 1901.01006]. Learned boundaries are likewise approximate: in VBOC, the optimal-control-generated samples are guaranteed boundary points, but the neural-network fit is not exact, so the learned set is only approximately invariant [2305.07535].

Reduced-order models create an additional interpretive limit. In walking MPC, the viability kernel is computed for a constrained LIPM/DCM model, not for the full robot; some full-body states outside the reduced-order kernel may still be recoverable, and some projected reduced-order states may still be poorly trackable by the whole-body controller [2010.04514]. This suggests that model mismatch affects not only control performance but also the operational meaning of the kernel itself.

A common misconception is that training or control should always remain inside the viability kernel. The running paper shows that this is not universally true for learning: in its constrained SLIP example, feasible initialization including unviable states increased the salient gradient set in parameter space by just over 79%, whereas nearly doubling exploration variance from \(8^\circ\) to \(15^\circ\) increased it by only 13%. A plausible implication is that strict viable-only initialization can be too conservative for model-free policy search in systems that can “fall with grace” [1806.06569].

An emerging extension treats viability kernels as random set-valued outputs under parametric uncertainty. A kernel-based sensitivity-analysis paper introduces a characteristic kernel on measurable sets,
$$
k_{set}(\gamma_1,\gamma_2)=e^{- \frac{\lambda(\gamma_1\Delta \gamma_2)}{2\sigma^2}},
$$
and explicitly notes applicability to “viability fields” and to outputs “called viability kernels.” This makes it possible to rank uncertain inputs by their effect on the entire viable region through HSIC-ANOVA indices, rather than through a scalar summary such as volume [2305.09268].

Source: https://www.emergentmind.com/topics/viability-kernel