control//safety filter//Simplex architecture
The Simplex architecture is a safety design in which an uncertified high-performance controller runs under a decision module that hands control to a simple, verified backup controller whenever the state approaches the edge of the region from which the backup can still recover; it is the way a network or an MPC can fly an aircraft or drive a robot while a certifiable component keeps the final say. Lui Sha formalized it in 2001, and aeronautics knows the same idea as **run-time assurance**.
The Simplex architecture is a safety design in which an uncertified high-performance controller runs under a decision module that hands control to a simple, verified backup controller whenever the state approaches the edge of the region from which the backup can still recover; it is the way a network or an MPC can fly an aircraft or drive a robot while a certifiable component keeps the final say. Lui Sha formalized it in 2001, and aeronautics knows the same idea as run-time assurance.
It has three parts. The complex controller is good at the task and is not trusted. The backup controller is simple enough to verify (a well-understood linear law, a hover-and-hold, a controlled stop), and for it the designers have computed a recoverable region: the set of states from which the backup is proven to bring the system back to safety without violating limits. The decision module watches the state, and before the complex controller can push it out of that region, it switches. The complex controller is free to do anything inside the region, and its quality decides performance; the backup and the switch decide safety.
Safety rests on a simple, reliable core, and the complex part never has to be perfect.
Certification effort concentrates on the backup, the recoverable region and the switching logic, which are small; the network or the optimizer can then be updated without recertifying everything, as long as the core is untouched.
The recoverable region must include margin for the switch itself: detection latency, the decision period and the backup's own transient. A switch decided too late hands the backup a state it cannot rescue.
Switching is coarse. Control passes entirely to the backup, which is usually conservative, so a complex controller that often wanders near the boundary gives a jerky, slow system. A control barrier function corrects the command minimally at every step instead of switching wholesale; the two are complementary, and some designs use the barrier for small corrections and the switch for emergencies.
It is a cousin of fault-tolerant control: the complex controller is treated as a component that may fail, and the switch is a reconfiguration triggered by a monitor (reconfiguration).
Regulators publish guidance for learned components (EASA in aviation; in the EU, the AI Act for high-risk systems), and the monitored-component architecture is the common answer they point toward (safety filter, functional safety). Maturity: growing niche.