Certifying Plans under Model Mismatch: A Trilemma for Reachability from Scarce Data

📄 arXiv: 2608.02453v1 📥 PDF

作者: Yanliang Huang, Zhen Zhang, Ahmad Hafez, Wenyuan Wu, Peng Xie, Zhuoqi Zeng, Amr Alanwar

分类: cs.RO

发布日期: 2026-08-03


💡 一句话要点

提出一种新方法以解决模型不匹配下的计划认证问题

🎯 匹配领域: 支柱一:机器人控制 (Robot Control)

关键词: 模型不匹配 控制序列认证 可达性分析 模型误差 动态系统 安全性保障

📋 核心要点

  1. 现有方法在模型不匹配情况下难以有效认证控制序列,尤其是在数据稀缺时。
  2. 本文提出了一种基于集合成员包络和可达管道传播的认证方法,以应对模型误差的挑战。
  3. 在两个基准系统中,所提方法在数据支持外拒绝认证不支持的序列,表现出更好的稳健性。

📝 摘要(中文)

在模拟到现实的政策设计中,目标系统的试验可能仅产生少量孤立的一步转移。本文研究了固定控制序列的执行前认证问题,特别是当序列到达未观察到的状态输入区域时,观察结果可能与目标系统的轨迹存在任意大的分离。我们推导出针对目标-名义模型误差的有限计划依赖投影宽度下界,揭示了均匀轨迹包含性、有限投影宽度和不受限模型误差行为之间的三难选择。我们的方法在有效声明的条件下构建模型误差的集合成员包络,传播可达管道,并在传播保持在认证域内时进行认证。实验表明,相较于校准基线,我们的方法在相关目标数据和足够障碍清除时能够恢复认证。

🔬 方法详解

问题定义:本文旨在解决在模型不匹配情况下,如何有效认证固定控制序列的问题。现有方法在面对稀缺数据时,往往无法保证认证的可靠性,导致潜在的安全隐患。

核心思路:我们的方法通过构建模型误差的集合成员包络,并传播可达管道,确保在认证过程中保持在安全域内,从而提高认证的可靠性。

技术框架:整体架构包括三个主要模块:首先是模型误差的声明和包络构建,其次是可达管道的传播,最后是认证过程的执行,确保每个投影管道切片避免不安全集。

关键创新:本研究的关键创新在于揭示了均匀轨迹包含性、有限投影宽度和不受限模型误差行为之间的三难选择,并提出了一种有效的认证机制,克服了现有方法的局限性。

关键设计:方法中关键的参数设置包括对模型误差的分量Lipschitz界限的要求,此外,采用了基于观察到的转移对的推理机制,以增强认证的准确性。

🖼️ 关键图片

fig_0
fig_1
fig_2

📊 实验亮点

在两个基准系统的实验中,所提方法在数据支持外拒绝认证不支持的序列,表现出更好的稳健性,相较于校准基线,认证的可靠性显著提高,确保了系统在复杂环境下的安全性。

🎯 应用场景

该研究的潜在应用领域包括自动驾驶、机器人控制和智能制造等,能够在数据稀缺的情况下,提供更为可靠的控制序列认证,确保系统的安全性和稳定性。未来,该方法有望推广到更广泛的动态系统中,提升智能系统的自主决策能力。

📄 摘要(原文)

Sim-to-real policies are designed under nominal dynamics, but target-system trials may yield only a few isolated one-step transitions. We study pre-execution certification of a fixed control sequence, such as an action chunk produced by a learned policy. If the sequence reaches an unobserved state-input region, the observations remain consistent with target systems whose trajectories separate along it by an arbitrarily large amount. Any deterministic certifier sound for all of them must then decline to certify or return a reachable tube with arbitrarily large projected width. For bounded smooth classes of the target-nominal model error, we derive a finite plan-dependent projected-width lower bound. These results expose a trilemma among uniform trajectory containment, finite projected width, and unrestricted model-error behavior beyond the observations. ForeReach requires a supplied componentwise Lipschitz bound on the model error. Observed transition pairs can refute this declaration but cannot establish it outside the observed locations. Conditional on a valid declaration, our method constructs a set-membership envelope for the model error, propagates a zonotopic reachable tube, and certifies only when propagation remains within the certification domain and every projected tube slice avoids the unsafe set. In two benchmark systems, calibration baselines may remain narrow after losing trajectory containment outside data support, whereas our method declines to certify unsupported sequences and recovers certification when relevant target data and sufficient obstacle clearance are available.