Search arXivSearch

arXiv · 2605.06630

Quantifying Trade-Offs Between Stability and Goal-Obfuscation

Abstract

Safety-critical autonomy in adversarial settings demands more than Lyapunov stability of tracking error signals. An agent executing a goal-directed trajectory is intrinsically legible to a passive observer running online Bayesian inference, because the contractive dynamics of any Lyapunov basin of attraction concentrates posterior belief over the latent intent parameters. We initiates the study of intent privacy over a continuous state space as a joint control problem on the physical state combined with the latent belief state of a putative observer. With the main challenges concentrated around the analysis of the belief-state dynamics, the agent dynamics is assumed to be simple, modeled by the differential inclusion $\dot{x}\in u+\bar{d}\mathbb{B}$. That is, the agent is fully actuated with bounded unknown disturbance to the control input. The observer's intent inference process is modeled as a discrete-time stochastic dynamical system evolving over the belief state space of a Rao Blackwellized particle filter reasoning over large random samples of possible agent goals. The agent's control input is modeled as a piecewise constant signal, with jumps matching the RBPF update times. Building on a prior intent-inference framework and its KL-based information leakage measurement, a privacy constraint is imposed, which amounts to maintaining information leakage above a prescribed threshold with high probability, using probabilistic discrete-time control barrier functions. A key technical contribution is the derivation of separate PCBF results for the Bayesian update step and the resampling step of the RBPF, enabling a PCBF result for the full update as well as integration of the privacy constraint with the agent's task-side tracking requirement. Finally, a joint feasibility analysis is carried out by examining the interplay between the privacy constraint and the tracking envelope.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Yixuan Wang, Dan P. Guralnik, Warren E. Dixon. 2026-09-18. Quantifying Trade-Offs Between Stability and Goal-Obfuscation. https://arxiv.org/abs/2605.06630

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Failure-Aware Iterative Learning of State-Control Invariant Sets

In this paper, we address the problem of computing maximal state-control invariant sets for deterministic linear systems using failing trajectories. We introduce the concept of state-control invariance, which extends control invariance from the state space to the joint state-control space. The maximal state-control invariant (MSCI) set simultaneously encodes the maximal control invariant set (MCI) and, for each state in the MCI, the set of control inputs that preserve invariance. We prove that the state projection of the MSCI is the MCI and the state-dependent sections of the MSCI are the admissible invariance-preserving inputs. Building on this framework, we develop a Failure-Aware Iterative Learning (FAIL) algorithm for deterministic linear time-invariant systems with polytopic constraints. The algorithm iteratively updates a constraint set in the state-control space by learning predecessor halfspaces from one-step failing state-input pairs, without knowing the dynamics. For each failure, FAIL learns the violated halfspaces of the predecessor of the constraint set by a regression on failing trajectories. We prove that the learned constraint set converges monotonically to the MSCI. Numerical experiments on a double integrator system validate the proposed approach.

eess.SY

Consensus and Synchronization of Multi-agent Systems over Finite Fields - Graph Topologies

This paper presents cooperative protocols for multi-agent systems with agents having a finite state-space. Both scalar single-integrator consensus and general LTI system synchronization are considered. Systems having a finite state-space describe agents with minimal memory capacity processing only a finite alphabet. Such systems are remarkably resilient to communication noise. The crucial problem, however, is to construct the admissible communication topology, which is NP-hard. We address this by efficiently exploring the subsets of admissible graph matrices and propose two new algorithms to generate them. Simulations validate the proposed approach.

eess.SY

Extracting Exact Lie Derivatives Without Backpropagation: A Dual Compiler for Neural Control Barrier Functions

A safety filter based on a neural control barrier function (CBF) deployed in an embedded control loop evaluates, at each control cycle, the trained network and its Lie derivatives along the system vector fields, under the memory and worst-case execution time (WCET) constraints that safety-oriented coding standards impose. Reverse-mode automatic differentiation, by which training frameworks obtain these derivatives, retains an activation cache whose size grows with the sum of the layer widths, and general-purpose differentiation runtimes allocate the computational graph from the heap at each call. This paper presents a compiler that evaluates a neural CBF and its exact Lie derivatives by forward-mode dual-number arithmetic. The compiler emits self-contained C++ code in which a single forward pass, without backpropagation, returns the barrier value and its exact Lie derivative along a given vector field; the drift and input Lie derivatives of the safety constraint are obtained from one such pass per vector field, and a second-order extension based on hyper-dual numbers returns the exact second-order Lie derivatives required by CBFs of relative degree two. The dual forward pass requires a workspace bounded by four times the widest layer, independent of network depth, and the emitted code contains no allocation call sites, so the absence of dynamic allocation is verifiable by inspection of the code. On an ESP32-S3 microcontroller, the compiled filter assembles the complete safety constraint in under one millisecond from statically allocated buffers of at most 768 bytes, and the maximum execution time over 1000 evaluations lies within 5% of the median in all three examples, whereas a heap-allocating reverse-mode baseline shows maxima 33% and 70% above its median in the two first-order examples. The compiler and the embedded experiments are released as open-source software.

eess.SY