C.C. de Visser
Please Note
75 records found
1
This paper introduces KANReach, a novel solver that leverages Kolmogorov-Arnold Networks (KANs) with B-spline activation functions for grid-free reachable set estimation. The architecture is evaluated using three case studies: a first-order regulator, a double integrator, and a 3D Dubins car. Benchmarking against DeepReach reveals that at comparable model sizes, KANReach achieves superior accuracy via Value Function Regression (VFR). However, it currently faces difficulties in Physics-Informed Learning (PIL) that limit its training efficiency relative to traditional DNNs. Additionally, this paper proposes Absolute Maximum Error Bounding (AMEB), a technique that exploits the unique convex-hull property of B-splines to derive formal safety guarantees that verify the computed SFE. ...
This paper introduces KANReach, a novel solver that leverages Kolmogorov-Arnold Networks (KANs) with B-spline activation functions for grid-free reachable set estimation. The architecture is evaluated using three case studies: a first-order regulator, a double integrator, and a 3D Dubins car. Benchmarking against DeepReach reveals that at comparable model sizes, KANReach achieves superior accuracy via Value Function Regression (VFR). However, it currently faces difficulties in Physics-Informed Learning (PIL) that limit its training efficiency relative to traditional DNNs. Additionally, this paper proposes Absolute Maximum Error Bounding (AMEB), a technique that exploits the unique convex-hull property of B-splines to derive formal safety guarantees that verify the computed SFE.
...
System identification techniques provide a means to derive these models from flight test measurements. State-of-the-art system identification methods successfully capture the effects of structural dynamics. However, they rely on the assumption of (quasi-) steady aerodynamics. In steady aerodynamic models, changes in parameters such as angle of attack or control surface deflections are assumed to result in instantaneous changes in aerodynamic forces and moments. In reality, due to wake effects from unsteady aerodynamics, these forces and moments take time to develop, introducing delays in the response. Accurately capturing these delays is crucial for correctly predicting and modelling the aircraft’s dynamic behaviour. Failure to account for unsteady aerodynamics can lead to errors in load predictions, degraded handling quality assessments, and suboptimal control law design.
This dissertation develops a methodology for identifying a parametric flight dynamics and loads model from flight test measurements for a flexible aircraft that also include the effects of structural dynamics and unsteady aerodynamics. A two-step approach was adopted where the identification procedure consists of separate state estimation and parameter estimation steps. This allowed to perform model parameter estimation using a linear least squares approach. In contrast, alternative methods such as the output-error approach perform state estimation and model parameter estimation in a single nonlinear optimisation process. While this method can provide accurate results, it requires accurate initial parameter estimates to achieve convergence and a good fit, and it imposes a significantly higher computational load, making it less efficient for larger and more complex models.
A scaled Diana 2 glider unmanned aerial vehicle (UAV) was used as the flight test platform in this research. Using a UAV allowed to conduct flight testing with much fewer rules and regulations compared to full-scale aircraft testing, while also significantly lowering costs. A glider configuration was selected due to its high aspect ratio and flexible structure, making it well-suited for studying aeroelastic effects. Furthermore, the flight tests could be conducted at airspeeds and reduced frequencies corresponding to unsteady aerodynamic conditions... ...
System identification techniques provide a means to derive these models from flight test measurements. State-of-the-art system identification methods successfully capture the effects of structural dynamics. However, they rely on the assumption of (quasi-) steady aerodynamics. In steady aerodynamic models, changes in parameters such as angle of attack or control surface deflections are assumed to result in instantaneous changes in aerodynamic forces and moments. In reality, due to wake effects from unsteady aerodynamics, these forces and moments take time to develop, introducing delays in the response. Accurately capturing these delays is crucial for correctly predicting and modelling the aircraft’s dynamic behaviour. Failure to account for unsteady aerodynamics can lead to errors in load predictions, degraded handling quality assessments, and suboptimal control law design.
This dissertation develops a methodology for identifying a parametric flight dynamics and loads model from flight test measurements for a flexible aircraft that also include the effects of structural dynamics and unsteady aerodynamics. A two-step approach was adopted where the identification procedure consists of separate state estimation and parameter estimation steps. This allowed to perform model parameter estimation using a linear least squares approach. In contrast, alternative methods such as the output-error approach perform state estimation and model parameter estimation in a single nonlinear optimisation process. While this method can provide accurate results, it requires accurate initial parameter estimates to achieve convergence and a good fit, and it imposes a significantly higher computational load, making it less efficient for larger and more complex models.
A scaled Diana 2 glider unmanned aerial vehicle (UAV) was used as the flight test platform in this research. Using a UAV allowed to conduct flight testing with much fewer rules and regulations compared to full-scale aircraft testing, while also significantly lowering costs. A glider configuration was selected due to its high aspect ratio and flexible structure, making it well-suited for studying aeroelastic effects. Furthermore, the flight tests could be conducted at airspeeds and reduced frequencies corresponding to unsteady aerodynamic conditions...
The first contribution focuses on the notion of safe sets themselves. \Cref{ch:maneuverable} introduces the concept of the maneuverable control-invariant set—a novel refinement of traditional invariant sets. Unlike classical safe sets, which guarantee that the system can remain within a given region, maneuverable sets also ensure the system's ability to move between any two states within the set in a given time horizon. Although such maneuverability and invariance cannot always be achieved simultaneously, this definition adds a valuable dimension to safety characterisation. The set is computed using a combination of forward and backward reachable sets derived from Hamilton-Jacobi (HJ) reachability analysis. Building on this, \Cref{ch:safeset} presents an improved definition of a safe set that does guarantee both viability and full internal maneuverability simultaneously. It is obtained through a different combination of forward and backward reachable sets. While the first two chapters establish refined definitions of safe sets under idealised dynamics, real-world systems rarely operate with perfect models. To address this, the next contribution turns to the challenge of ensuring safety under model uncertainty and disturbances.
\Cref{ch:RobustBRT} addresses robustness under model uncertainty. It extends the HJ reachability framework by formulating a three-player differential game that includes unmodelled dynamics as an additional adversary alongside external disturbances. The resulting Robust Avoid Backward Reachable Tube (RABRT) generalises previous formulations by ensuring safety in the presence of both disturbances and uncertain system dynamics. The associated value function is shown to be the viscosity solution to a well-defined Hamilton-Jacobi-Isaacs (HJI) partial differential equation (PDE), and the method integrates with existing level-set tools, preserving compatibility with standard computational frameworks. While this formulation provides robustness to unmodelled dynamics, its computational demands grow quickly with system dimensionality. As classical level-set methods struggle in high-dimensional settings, recent work has turned to neural network–based approximations. The next chapter explores how such approximations can be made verifiable and trustworthy through formal certification.
To overcome the curse of dimensionality inherent in classical reachability methods, \Cref{ch:Care} introduces the Certified Approximate Reachability (CARe) framework. Instead of solving PDEs directly on grids, CARe leverages neural networks to approximate the value function and then uses formal verification tools—specifically Satisfiability Modulo Theory (SMT) solvers and Counterexample-Guided Inductive Synthesis (CEGIS)—to certify the learned approximation within a bounded error. This framework bridges the gap between deep learning and formal safety verification, offering a scalable method for high-dimensional systems while preserving correctness guarantees. While CARe provides a scalable and certifiable solution for deterministic systems, many real-world applications involve stochastic dynamics and probabilistic safety requirements. To address this, the final part of the thesis extends the reachability framework to systems governed by uncertainty and noise.
Chapters \ref{ch:StochasticABRT} and \ref{ch:stochasticsafeBRT} extend the thesis into the stochastic domain. \Cref{ch:StochasticABRT} introduces the Probabilistic Forced Backward Reachable Set, which identifies states from which the system enters an undesirable set with high probability, regardless of the control policy. The chapter develops convergent algorithms for computing this set in both discrete and continuous settings and provides error bounds under discretisation. \Cref{ch:stochasticsafeBRT} then presents the Safe Probable Backward Reachable Set (SPBRS), which guarantees not only that the system will reach a target with a given probability but also that it will remain inside a certified safe set throughout the trajectory. This is especially important in stochastic systems where intermediate safety violations can occur despite a safe terminal state. Two algorithms are developed—one computationally efficient and the other optimal—and their convergence and tractability are formally analysed.
Each chapter is supported by theoretical proofs, algorithmic implementation, and numerical validation on benchmark systems such as the Dubins car and double integrator. This dissertation offers a cohesive and extensible framework for analysing and certifying safety in both deterministic and stochastic systems. By introducing new definitions of safety, developing scalable algorithms, and integrating formal verification with deep learning, the work makes contributions that are both foundational and practical. It addresses longstanding limitations in the scalability, conservatism, and verifiability of reachability-based safety analysis. The results have direct implications for real-world autonomous systems, including autonomous vehicles, robotics, air traffic management, and safety-critical embedded systems. More broadly, the methods contribute to the growing effort to make machine learning and autonomy formally trustworthy, especially in domains where safety cannot be left to statistical performance alone. Looking ahead, this work lays the groundwork for future research in adaptive safety verification, stochastic control synthesis, and trustworthy decision-making in uncertain environments—pushing the boundaries of what is possible at the intersection of formal methods, control theory, and autonomy. ...
The first contribution focuses on the notion of safe sets themselves. \Cref{ch:maneuverable} introduces the concept of the maneuverable control-invariant set—a novel refinement of traditional invariant sets. Unlike classical safe sets, which guarantee that the system can remain within a given region, maneuverable sets also ensure the system's ability to move between any two states within the set in a given time horizon. Although such maneuverability and invariance cannot always be achieved simultaneously, this definition adds a valuable dimension to safety characterisation. The set is computed using a combination of forward and backward reachable sets derived from Hamilton-Jacobi (HJ) reachability analysis. Building on this, \Cref{ch:safeset} presents an improved definition of a safe set that does guarantee both viability and full internal maneuverability simultaneously. It is obtained through a different combination of forward and backward reachable sets. While the first two chapters establish refined definitions of safe sets under idealised dynamics, real-world systems rarely operate with perfect models. To address this, the next contribution turns to the challenge of ensuring safety under model uncertainty and disturbances.
\Cref{ch:RobustBRT} addresses robustness under model uncertainty. It extends the HJ reachability framework by formulating a three-player differential game that includes unmodelled dynamics as an additional adversary alongside external disturbances. The resulting Robust Avoid Backward Reachable Tube (RABRT) generalises previous formulations by ensuring safety in the presence of both disturbances and uncertain system dynamics. The associated value function is shown to be the viscosity solution to a well-defined Hamilton-Jacobi-Isaacs (HJI) partial differential equation (PDE), and the method integrates with existing level-set tools, preserving compatibility with standard computational frameworks. While this formulation provides robustness to unmodelled dynamics, its computational demands grow quickly with system dimensionality. As classical level-set methods struggle in high-dimensional settings, recent work has turned to neural network–based approximations. The next chapter explores how such approximations can be made verifiable and trustworthy through formal certification.
To overcome the curse of dimensionality inherent in classical reachability methods, \Cref{ch:Care} introduces the Certified Approximate Reachability (CARe) framework. Instead of solving PDEs directly on grids, CARe leverages neural networks to approximate the value function and then uses formal verification tools—specifically Satisfiability Modulo Theory (SMT) solvers and Counterexample-Guided Inductive Synthesis (CEGIS)—to certify the learned approximation within a bounded error. This framework bridges the gap between deep learning and formal safety verification, offering a scalable method for high-dimensional systems while preserving correctness guarantees. While CARe provides a scalable and certifiable solution for deterministic systems, many real-world applications involve stochastic dynamics and probabilistic safety requirements. To address this, the final part of the thesis extends the reachability framework to systems governed by uncertainty and noise.
Chapters \ref{ch:StochasticABRT} and \ref{ch:stochasticsafeBRT} extend the thesis into the stochastic domain. \Cref{ch:StochasticABRT} introduces the Probabilistic Forced Backward Reachable Set, which identifies states from which the system enters an undesirable set with high probability, regardless of the control policy. The chapter develops convergent algorithms for computing this set in both discrete and continuous settings and provides error bounds under discretisation. \Cref{ch:stochasticsafeBRT} then presents the Safe Probable Backward Reachable Set (SPBRS), which guarantees not only that the system will reach a target with a given probability but also that it will remain inside a certified safe set throughout the trajectory. This is especially important in stochastic systems where intermediate safety violations can occur despite a safe terminal state. Two algorithms are developed—one computationally efficient and the other optimal—and their convergence and tractability are formally analysed.
Each chapter is supported by theoretical proofs, algorithmic implementation, and numerical validation on benchmark systems such as the Dubins car and double integrator. This dissertation offers a cohesive and extensible framework for analysing and certifying safety in both deterministic and stochastic systems. By introducing new definitions of safety, developing scalable algorithms, and integrating formal verification with deep learning, the work makes contributions that are both foundational and practical. It addresses longstanding limitations in the scalability, conservatism, and verifiability of reachability-based safety analysis. The results have direct implications for real-world autonomous systems, including autonomous vehicles, robotics, air traffic management, and safety-critical embedded systems. More broadly, the methods contribute to the growing effort to make machine learning and autonomy formally trustworthy, especially in domains where safety cannot be left to statistical performance alone. Looking ahead, this work lays the groundwork for future research in adaptive safety verification, stochastic control synthesis, and trustworthy decision-making in uncertain environments—pushing the boundaries of what is possible at the intersection of formal methods, control theory, and autonomy.
function selection and suggests future research in optimizing simplices for improved performance. Applying B-spline scheduling functions with gain scheduled controllers in closed-loop control is the next direction for increasing control performance in complex, high-dimensional systems. ...
function selection and suggests future research in optimizing simplices for improved performance. Applying B-spline scheduling functions with gain scheduled controllers in closed-loop control is the next direction for increasing control performance in complex, high-dimensional systems.
Reachability in Vehicle Lateral Stability
Application of Hamilton-Jacobi Safety Filter as Electronic Stability Control
The second investigation establishes a comprehensive methodology for identifying and characterizing fuel transport delays using GT-SUITE/MATLAB co-simulation calibrated with Jenbacher engine data. Virtual sensors at multiple locations quantified delay behavior across load acceptance, rejection, and steady-state operating conditions. Quadratic models were developed to enable real-time delay prediction based on boost pressure and operating mode. Both investigations provide control-theoretic frameworks and empirical models directly applicable to INNIO’s current and future engine platforms.
...
The second investigation establishes a comprehensive methodology for identifying and characterizing fuel transport delays using GT-SUITE/MATLAB co-simulation calibrated with Jenbacher engine data. Virtual sensors at multiple locations quantified delay behavior across load acceptance, rejection, and steady-state operating conditions. Quadratic models were developed to enable real-time delay prediction based on boost pressure and operating mode. Both investigations provide control-theoretic frameworks and empirical models directly applicable to INNIO’s current and future engine platforms.
Flow Separation Modeling from Tuft Motion
An Image-Based Approach Applied to In-Flight Stall Testing on PH-LAB
High-speed video was analyzed through a dedicated image-processing pipeline to classify tuft states and reconstruct separation patterns. The resulting maps provide direct, spatially resolved evidence of stall onset and progression. This allows for a direct validation of existing Kirchhoff-inspired formulations, while highlighting their shortcomings in capturing spanwise variations and local effects of separation. Furthermore, synchronization with flight-test data allows for correlation of tuft measurements with global aircraft states and supports the development of a logistic model to describe local separation behavior. Beyond validating existing models, the proposed approach establishes a robust experimental framework for integrating flow visualization into stall model identification, with direct implications for the improvement of stall models and, ultimately, flight safety. ...
High-speed video was analyzed through a dedicated image-processing pipeline to classify tuft states and reconstruct separation patterns. The resulting maps provide direct, spatially resolved evidence of stall onset and progression. This allows for a direct validation of existing Kirchhoff-inspired formulations, while highlighting their shortcomings in capturing spanwise variations and local effects of separation. Furthermore, synchronization with flight-test data allows for correlation of tuft measurements with global aircraft states and supports the development of a logistic model to describe local separation behavior. Beyond validating existing models, the proposed approach establishes a robust experimental framework for integrating flow visualization into stall model identification, with direct implications for the improvement of stall models and, ultimately, flight safety.
Aircraft Stall Dynamics
Improved Longitudinal Stall Modeling with Separable Nonlinear Least Squares and Dynamic Stall Maneuvers
...
Adaptive dynamic incremental nonlinear control allocation
An actuator fault-tolerant control solution for high-performance aircraft
Evaluation and Comparison of Linear Quadratic Control Techniques
Exploring Stability and Robustness in Loop Transfer Recovery Approaches
...
Development of Input Design Methodology & Flight Testing Pipeline
For High Speed Quadrotor Model Identification
Data Driven Control Barrier Functions
Using Multivariate Splines
INDI and H-infinity LSDP in quadrotors
Towards Incremental Nonlinear Dynamic Inverions with guaranteed stability
Advances in Dynamic Inversion-based Flight Control Law Design
Multivariable Analysis and Synthesis of Robust and Multi-Objective Design Solutions
Nonlinear Dynamic Inversion (NDI) was developed as an alternative to the divide-and-conquer strategy. Instead of subdividing the operating domain into many different local regions, NDI brings the notional benefit of automatic gain scheduling. This drastically simplifies the nonlinear implementation step. Moreover, as it enables a decoupling of different parts of the control design, NDI brings advantages in terms of design modularity. In its classical form, these aspects are achieved through the use of an on-board model embedded in the control law. Alternatively, in an effort to reduce this model-dependency, a sensor-based incremental variant of NDI (INDI) was proposed in the past. This form aims to increase control law robustness in the face of parametric modeling offsets by relying more directly on sensor measurements instead. Accordingly, different inversion strategies (model-based, sensor-based, or combinations of these) lead to vastly different robust stability and performance characteristics. However, a systematic understanding of these robustness implications has long been missing. In this thesis, this problem is approached using H∞-based multivariable analysis and synthesis techniques.
In addition to the question of robustness, this thesis also focuses on multi-objective control design in the context of control allocation for input-redundant plants. This concerns over-determined control problems, for which secondary performance criteria can be addressed in addition to the primary motion control task. In particular, it is investigated how the framework of incremental control allocation (INCA) can be used in such multi-objective design scenarios. ...
Nonlinear Dynamic Inversion (NDI) was developed as an alternative to the divide-and-conquer strategy. Instead of subdividing the operating domain into many different local regions, NDI brings the notional benefit of automatic gain scheduling. This drastically simplifies the nonlinear implementation step. Moreover, as it enables a decoupling of different parts of the control design, NDI brings advantages in terms of design modularity. In its classical form, these aspects are achieved through the use of an on-board model embedded in the control law. Alternatively, in an effort to reduce this model-dependency, a sensor-based incremental variant of NDI (INDI) was proposed in the past. This form aims to increase control law robustness in the face of parametric modeling offsets by relying more directly on sensor measurements instead. Accordingly, different inversion strategies (model-based, sensor-based, or combinations of these) lead to vastly different robust stability and performance characteristics. However, a systematic understanding of these robustness implications has long been missing. In this thesis, this problem is approached using H∞-based multivariable analysis and synthesis techniques.
In addition to the question of robustness, this thesis also focuses on multi-objective control design in the context of control allocation for input-redundant plants. This concerns over-determined control problems, for which secondary performance criteria can be addressed in addition to the primary motion control task. In particular, it is investigated how the framework of incremental control allocation (INCA) can be used in such multi-objective design scenarios.
Output Error Estimation for Unsteady Flows Using Reconstructed Solutions
Effect of Compression and Reconstruction of Unsteady CFD Data using Neural Networks and PODs on Error Estimates
The one-dimensional unsteady Burgers equation is used as validation for the methods using a manufactured solution while the lid-driven cavity flow is investigated using the proposed method. The manufactured solution of the one-dimensional Burgers case could be exactly reconstructed using two POD modes. For the autoencoder a small latent space was used. For low resolutions, the small latent space did not prove to be a problem as the primal and residual could be captured accurately. However, for higher resolutions, the reconstruction error of the autoencoder became dominant for the residuals and resulted in erroneous adjoint-based error estimates while the primal remained qualitatively similar.
For the lid-driven cavity flow, the POD was still able to capture the solution using a low number of modes due to the smoothness of the solution. This resulted in an unfair comparison between the POD and autoencoder reconstructed solutions. The reconstructed autoencoder error estimates for lower resolutions were more accurate due to the latent space being large enough to capture the residual of the discrete primal accurately enough. When moving to higher resolutions, the autoencoder was not able to reconstruct the residual accurately enough leading to erroneous error estimates. Therefore, the latent space of autoencoders should be sufficiently large in order to gain an accurate reconstruction of the residual. If the latent space is large enough, the error estimate is accurate and the local error estimates can be used as a first iteration error indicator for mesh refinement. ...
The one-dimensional unsteady Burgers equation is used as validation for the methods using a manufactured solution while the lid-driven cavity flow is investigated using the proposed method. The manufactured solution of the one-dimensional Burgers case could be exactly reconstructed using two POD modes. For the autoencoder a small latent space was used. For low resolutions, the small latent space did not prove to be a problem as the primal and residual could be captured accurately. However, for higher resolutions, the reconstruction error of the autoencoder became dominant for the residuals and resulted in erroneous adjoint-based error estimates while the primal remained qualitatively similar.
For the lid-driven cavity flow, the POD was still able to capture the solution using a low number of modes due to the smoothness of the solution. This resulted in an unfair comparison between the POD and autoencoder reconstructed solutions. The reconstructed autoencoder error estimates for lower resolutions were more accurate due to the latent space being large enough to capture the residual of the discrete primal accurately enough. When moving to higher resolutions, the autoencoder was not able to reconstruct the residual accurately enough leading to erroneous error estimates. Therefore, the latent space of autoencoders should be sufficiently large in order to gain an accurate reconstruction of the residual. If the latent space is large enough, the error estimate is accurate and the local error estimates can be used as a first iteration error indicator for mesh refinement.