Search papers, labs, and topics across Lattice.
This paper investigates the challenges of certifying control sequences in sim-to-real applications under model mismatch, focusing on the limitations of pre-execution certification when faced with sparse observational data. The authors reveal a trilemma involving uniform trajectory containment, finite projected width, and unrestricted model-error behavior, demonstrating that deterministic certifiers must either decline certification or provide overly conservative estimates. By deriving a plan-dependent projected-width lower bound and employing a set-membership envelope for model error, the proposed method effectively certifies reachable sequences while avoiding unsafe states, outperforming calibration baselines in two benchmark systems.
Certifying control sequences in the face of model mismatch reveals a trilemma that challenges traditional approaches to safety in sim-to-real transitions.
Sim-to-real policies are designed under nominal dynamics, but target-system trials may yield only a few isolated one-step transitions. We study pre-execution certification of a fixed control sequence, such as an action chunk produced by a learned policy. If the sequence reaches an unobserved state-input region, the observations remain consistent with target systems whose trajectories separate along it by an arbitrarily large amount. Any deterministic certifier sound for all of them must then decline to certify or return a reachable tube with arbitrarily large projected width. For bounded smooth classes of the target-nominal model error, we derive a finite plan-dependent projected-width lower bound. These results expose a trilemma among uniform trajectory containment, finite projected width, and unrestricted model-error behavior beyond the observations. ForeReach requires a supplied componentwise Lipschitz bound on the model error. Observed transition pairs can refute this declaration but cannot establish it outside the observed locations. Conditional on a valid declaration, our method constructs a set-membership envelope for the model error, propagates a zonotopic reachable tube, and certifies only when propagation remains within the certification domain and every projected tube slice avoids the unsafe set. In two benchmark systems, calibration baselines may remain narrow after losing trajectory containment outside data support, whereas our method declines to certify unsupported sequences and recovers certification when relevant target data and sufficient obstacle clearance are available.