arXiv:2609.05962cs.RO2026-09被引 1

设计观测以最大化安全动作的准入范围,揭示了可观测性与可辨识性的分离机制。

Observation Design for Certified Control Authority: Projection--Estimability Separation and Active-Face Equivalence

  • 将约束方向分解为可投影与不可估计部分,区分了可观测性与可辨识性的影响
  • 在预算无限时,只要可投影分量非零,动作即可被可靠判别;否则无法鲁棒认证
  • 适用于需要严格安全认证的系统设计,如自动驾驶与工业控制

一个可靠的运行时准入门限只执行其能验证的动作,并仅基于观测支持进行验证。本文探讨如何设计观测以最大化可安全准入的动作集合,发现该问题并非经典设计问题的同义转换。首先提出投影-可估计性分离:相对于信息矩阵,将约束法向量 $c$ 分解为 $c_{\mathrm{Range}}+c_{\ker}$,当预算增大时,只要 $c_{\mathrm{Range}}\neq 0$,沿 $c$ 的两点判别可趋于可靠;而若 $c_{\ker}\neq 0$,则在任何预算下都无法实现鲁棒准入;此类混合方向在秩不足时普遍存在,满秩时解耦受 Kantorovich 比值限制且随条件数发散。最优判别设计作为线性准则的极值解,恰好落入此区域。其次提出主动面等价定理:最优宽容度设计为某目标矩阵的 $L$-最优,该矩阵由成为认证瓶颈的动作面内生生成,权重为其剩余松弛的倒数;单面坍缩即还原 $c$-最优与目标导向设计。利用 Carathéodory 证明,瓶颈面数量不超过 $r(r+1)/2+1$。围绕这些结果构建了凸合同模式下的精确可验证性,推导出 $\κ\approx 3.29$ 而非校准,体现了合同无关设计的 $\sqrt{r}$ 代价;提出信息-松弛转移定理及其曲率-预算推论;并设计双阶段审计:即使满足所有边际要求,某些动作面的认证成本仍可能超过测试成本十倍以上,在所有探测库中均成立。

原文摘要 · Abstract (English)

A sound runtime admission gate executes only actions it can certify, and certifies only what its observations support. This paper asks how observations should be designed to maximize the set of actions that can be safely admitted, and shows the question is not a re-vocabulary of classical design problems. First, a projection--estimability separation: decomposing a constraint normal as $c=c_{\mathrm{Range}}+c_{\ker}$ relative to an information matrix, two-point discrimination along $c$ becomes arbitrarily reliable as the budget grows whenever $c_{\mathrm{Range}}\neq 0$, while robust admission of an action with normal $c$ is impossible at every budget whenever $c_{\ker}\neq 0$; such mixed directions are generic at any deficient rank, and at full rank the decoupling is bounded by the Kantorovich ratio and diverges with the condition number. Discrimination-optimal designs, being corner solutions of a linear criterion, land in exactly this regime. Second, an active-face equivalence theorem: the permissiveness-optimal design is $L$-optimal for a target matrix generated endogenously by the action faces that become certification bottlenecks, weighted inversely by their remaining slack; single-face collapse recovers $c$-optimal and goal-oriented design exactly, and a Caratheodory argument yields a bottleneck certificate of at most $r(r+1)/2+1$ faces. Around these we assemble exact certifiability per convex contract mode, for which $\kappa\approx 3.29$ is derived rather than calibrated, the $\sqrt{r}$ price of contract-agnostic design, an information-to-slack transfer theorem with a curvature-budget corollary, and a two-part audit in which a design meeting every margin requirement still leaves an action face at a certification cost above ten times its testing cost, in every probe library tested.

控制认证观测设计安全系统凸优化

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。