control//safety filter//control barrier function
A control barrier function is a scalar function of the state whose nonnegative region defines a safe set, used to build a safety filter that minimally corrects a proposed command at every step so the system never leaves that set; it is how a learned policy, a teleoperator or an aggressive planner can be allowed to drive while a few lines of math keep the robot off the wall. The **safe set** is written as \(h(x)\ge0\): for example, distance to the wall minus a margin. At every period the filter solves
A control barrier function is a scalar function of the state whose nonnegative region defines a safe set, used to build a safety filter that minimally corrects a proposed command at every step so the system never leaves that set; it is how a learned policy, a teleoperator or an aggressive planner can be allowed to drive while a few lines of math keep the robot off the wall. The safe set is written as h(x)≥0h(x)\ge0h(x)≥0: for example, distance to the wall minus a margin. At every period the filter solves
u⋆=argminu ∥u−uRL∥2s.t.∇h(x)Tf(x,u)≥−α h(x),u^\star=\arg\min_u\ \lVert u-u_{\text{RL}}\rVert^2\quad\text{s.t.}\quad \nabla h(x)^{\mathsf T}f(x,u)\ge-\alpha\,h(x),u⋆=argumin ∥u−uRL∥2s.t.∇h(x)Tf(x,u)≥−αh(x),
where uRLu_{\text{RL}}uRL is the action the policy proposes, x˙=f(x,u)\dot x=f(x,u)x˙=f(x,u) the dynamics, ∇h\nabla h∇h the direction in which safety grows and α>0\alpha>0α>0 a rate. When the proposed action already satisfies the constraint, the filter returns it unchanged. Its guarantee rests on two assumptions stated outside the QP: a correct model of the dangerous part of the dynamics, and enough actuator authority to deliver the braking it demands.
If the dynamics are a control-affine system, x˙=f(x)+g(x)u\dot x=f(x)+g(x)ux˙=f(x)+g(x)u, the constraint is linear in uuu and the problem is a tiny quadratic program that solves in microseconds on a flight microcontroller. That is the main reason barrier filters are practical: one or two constraints, one small QP per period, no horizon.
Approach the edge, but ever more slowly.
The constraint never forbids moving toward danger; it caps how fast the margin hhh may shrink in proportion to the margin left, so hhh can decay at most exponentially and, in the model, never crosses zero. That makes the filter minimally invasive: far from the edge the policy runs untouched, and near it only the part of the command that points at the edge is trimmed.
α\alphaα sets how early the filter starts to intervene. A small value brakes gently from far away and feels conservative; a large one lets the system run close to the edge and brake hard at the last moment, which is where model errors and delays bite.
It is the dual of a Lyapunov function: a Lyapunov function proves the state goes somewhere (stability), a barrier function proves it stays out of somewhere (safety), and both work by bounding a derivative along the dynamics.
Against the Simplex architecture, a barrier corrects a little at every step instead of handing over control wholesale, which keeps the learned controller in charge most of the time. Maturity: growing niche, with predictive extensions based on MPC in research (safety filter).