Discrepancy Computation for Nonlinear System Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current simulation-based verification algorithms for nonlinear and hybrid systems are limited in providing formal safety guarantees, especially for models with large sets of initial conditions, inputs, and unknown parameters, as they rely on user-provided discrepancy functions and are not effective for large systems.

Innovation Solution

The development of an algorithm that computes piecewise exponential discrepancy functions for control systems interacting with physical processes, eliminating the need for user-provided annotations by using local convergence or divergence rates of trajectories and bounding the maximal eigenvalue of the Jacobian, allowing for compositional analysis and verification of safety without requiring all subsystem discrepancies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If simulation-based verification algorithms are used for nonlinear and hybrid systems, then confidence for design and testing is improved, but formal safety guarantees are insufficient

Engineering Contradiction:
Improveformal safety guaranteesVSAvoidverification algorithm complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces reachtubes as an intermediary mathematical construct that bridges simulation-based verification and formal safety guarantees. Reachtubes provide over-approximations of reachable states, enabling formal verification of safety properties while maintaining compatibility with simulation approaches for nonlinear and hybrid systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent performs preliminary computation of discrepancy functions and reachtubes before formal verification. By pre-computing these mathematical constructs that capture system behavior over time intervals, the algorithm establishes formal safety guarantees in advance rather than requiring exhaustive exploration during verification.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If user-provided discrepancy functions are used, then verification can be performed, but the method is not effective for large systems with many initial conditions and parameters

Engineering Contradiction:
Improveverification efficiencyVSAvoidsystem size
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements self-service by automatically computing discrepancy functions from the system model itself, eliminating the need for manual user provision. The algorithm derives discrepancy functions by analyzing the system's own dynamics and Jacobian matrices, enabling scalable verification of large systems without requiring extensive user annotation effort.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent transforms the verification approach by changing from fixed user-provided discrepancy functions to dynamically computed ones based on system parameters. By computing discrepancy functions that adapt to the specific system being verified, the method efficiently handles large systems with varying initial conditions and parameters.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If reachtubes are computed from simulations, then over-approximations of all possible behaviors are obtained, but the computation requires user-provided annotations

Engineering Contradiction:
Improvecompleteness of behavior coverageVSAvoiduser annotation requirement
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent enables reachtube computation to be self-sufficient by automatically generating discrepancy functions from the system model. The algorithm computes these functions by evaluating the system's Jacobian matrices along simulation trajectories, eliminating the need for users to manually provide annotations while maintaining complete behavior coverage.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary computation of discrepancy functions by analyzing system dynamics before reachtube construction. By pre-computing the mathematical constructs needed for over-approximation from the system model itself, the method achieves complete behavior coverage without requiring user annotations during the reachtube computation phase.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10061876B2Bounded verification through discrepancy computations
Publication Date: 2018.08.28 THE BOARD OF TRUSTEES OF THE UNIV OF ILLINOIS
  • US10061876B2 patent drawing
  • US10061876B2 patent drawing
  • US10061876B2 patent drawing

AI summary

A system and methods store initial states and unsafe states (e.g., safety requirements) of a non-linear model of a control system that interacts with a physical system. The system performs simulations of the non-linear model using a set of sampled initial states, to first generate trajectories (numerical approximations of actual behaviors) over bounded time. The system further determines, for respective pairs of neighboring trajectories: an over-approximation of reachable states as an upper bound of a distance between a pair of neighboring trajectories; a linear over-approximation of the reachable states as piece-wise linear segments over a plurality of time intervals; and whether the linear over-approximation overlaps in any of the piece-wise linear segments with the unsafe states, to verify the non-linear model of the control system is safe.