Research Assistant · xLab for Safe Autonomous Systems, University of Pennsylvania

Failure-Aware Iterative Learning for Safe MPC

A pipeline that learns state-control invariant sets from observed one-step failures and uses them as MPC terminal constraints — with no model of the dynamics. Recovers the model-based maximal invariant set to under 1e-15 support-function error.

Failure-Aware Iterative Learning for Safe MPC

Period

Jul 2026 – Present

Stack

MPC · Invariant Sets · CVXPY · Control Theory · Python

Highlights

  • 01Failure-Aware Iterative Learning (FAIL) pipeline learning state-control invariant sets from observed one-step failures
  • 02Learned sets serve as MPC terminal constraints without any model of the dynamics
  • 03Halfspace-learning and model-free certification loop built in NumPy / SciPy / CVXPY
  • 04Recovers the model-based maximal invariant set to < 1e-15 support-function error on 10/10 seeds in ~5 s
  • 05Closed-loop benchmark: the learned terminal set stays recursively feasible at N = 1, where plain MPC loses feasibility and a zero terminal set is infeasible until N = 12

How it works

A schematic of the method, not a plot of results. Each observed one-step failure rules out a region of the state-control space, inducing a halfspace; the intersection of those halfspaces is the learned invariant set. The dashed outline is the set the model-based construction produces — in the real runs the two agree to under 1e-15 support-function error, so it is drawn slightly offset here purely to keep both visible.
A schematic of the method, not a plot of results. Each observed one-step failure rules out a region of the state-control space, inducing a halfspace; the intersection of those halfspaces is the learned invariant set. The dashed outline is the set the model-based construction produces — in the real runs the two agree to under 1e-15 support-function error, so it is drawn slightly offset here purely to keep both visible.

Write-up

Model predictive control gives you safety guarantees on paper, but the guarantee is only as good as the terminal set — and computing a terminal set the classical way requires a model of the dynamics you often do not have. This project asks whether the set can be learned instead, from nothing but observed failures.

The FAIL pipeline treats each observed one-step failure as a constraint on where the safe set cannot extend, and iteratively carves a state-control invariant set out of halfspaces consistent with everything seen so far. The certification loop that decides whether the current candidate is genuinely invariant is itself model-free, so the whole construction never needs the dynamics written down. It is built in NumPy, SciPy and CVXPY.

The validation that matters is whether the learned set matches what the model-based construction would have produced if you did have the model. On the benchmark system it recovers the maximal invariant set to under 1e-15 support-function error on 10 out of 10 random seeds, in roughly five seconds.

The payoff shows up in closed loop, at short horizons. With the learned terminal set the controller stays recursively feasible at a horizon of N = 1 — where plain MPC has already lost feasibility, and the conservative zero terminal set stays infeasible all the way out to N = 12. Short horizons are cheap horizons, so this is the difference between a guarantee you can afford to run on a robot and one you cannot.