arXiv:2605.04222eess.SYcs.RO2026-05

分层控制框架让系统既安全又持续运行,适用于电池-电容混合储能系统。

Safety by Invariance, Liveness through Refinement: Heterogeneous Contract Framework for Co-Design of Layered Control

  • 用不变性保证安全,用细化实现持续目标,分层间通过时序兼容约束协调。
  • 在电池与电容器组成的混合储能系统上验证,满足长期运行与实时安全要求。
  • 适合做高可靠性控制系统设计的工程师和研究者参考。

真实世界的控制系统需在长时间内达成目标(活性)的同时,始终满足连续时间的安全约束,这推动了分层控制架构(LCA)的发展。然而现有研究存在三大缺陷:(i)离散规划与连续执行缺乏统一规范语言;(ii)异构时间尺度下子系统互联时无法保证规范一致性;(iii)因依赖简单输入过滤规则,各层间缺乏可组合的分离机制。本文通过将安全-活性分解引入异构假设-保障框架,提出:安全由连续层的不变性保障,活性由离散层的细化实现,层间协调通过垂直细化与时间兼容性条件形式化。我们构建了一种新型分层架构,融合模型预测控制(MPC)规划器、输入到状态稳定(ISS)低层控制器及参考调节器桥接模块,并在包含电池与超级电容的混合储能系统(HESS)上完成验证。实验表明,该框架能有效兼顾长期运行性能与实时安全性,且支持模块化扩展。

原文摘要 · Abstract (English)

Real-world control systems must achieve long-horizon objectives (liveness) while respecting continuous-time safety constraints, a combination that motivates hierarchical layered control architectures (LCAs). Existing LCA research, however, lacks (i) a uniform specification language across discrete planning and continuous execution, (ii) formal guarantees that specifications are preserved when interconnecting subsystems at heterogeneous time scales, and (iii) compositional separation between layers, owing to reliance on naive input-filtering laws. This paper addresses all three gaps by importing the safety--liveness decomposition into a heterogeneous assume--guarantee framework: \emph{safety is enforced by invariance} at the continuous-time layer, while \emph{liveness is achieved through refinement} at the discrete-time layer, with inter-layer coordination formalized via vertical refinement and timing-compatibility conditions. We instantiate this contract with a novel LCA combining an MPC planner, an input-to-state stabilizing (ISS) low-level controller, and a reference-governor bridge, and validate it on a Hybrid Energy Storage System (HESS) comprising a battery and a supercapacitor.

分层控制混合储能安全约束形式化验证

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。