Skip to main content
QUICK REVIEW

[Paper Review] Run Time Assurance for Autonomous Spacecraft Inspection

Kyle Dunlap, David van Wijk|arXiv (Cornell University)|Feb 6, 2023
Risk and Safety AnalysisDecision Sciences3 citations
TL;DR

This paper proposes a Run Time Assurance (RTA) framework using Control Barrier Functions (CBF) and the Active Set Invariance Filter (ASIF) to enforce multiple safety constraints—such as safe separation, velocity limits, and keep-out zones—during autonomous multi-spacecraft inspection. It demonstrates via Monte Carlo simulations that centralized RTA ensures safety in 100% of cases, while decentralized RTA succeeds in 90.95% of cases, with failure due to conflicting multi-agent keep-out zone constraints, which can be mitigated through constraint relaxation or adaptive strengthening functions.

ABSTRACT

As autonomous systems become more prevalent in the real world, it is critical to ensure they operate safely. One approach is the use of Run Time Assurance (RTA), which is a real-time safety assurance technique that monitors a primary controller and intervenes to assure safety when necessary. As these autonomous systems become more complex, RTA is useful because it can be designed completely independent of the primary controller. This paper develops several translational motion safety constraints for a multi-agent autonomous spacecraft inspection problem, where all of these constraints can be enforced with RTA. A comparison is made between centralized and decentralized control, where simulations of the inspection problem then demonstrate that RTA can assure safety of all constraints. Monte Carlo analysis is then used to show that no scenarios were found where the centralized RTA cannot assure safety. While some scenarios were found where decentralized RTA cannot assure safety, solutions are discussed to mitigate these failures.

Motivation & Objective

  • To develop safety constraints for autonomous multi-spacecraft inspection missions involving a passive chief and active deputy spacecraft.
  • To evaluate the effectiveness of Run Time Assurance (RTA) in enforcing multiple translational motion safety constraints in real time.
  • To compare centralized versus decentralized RTA architectures for safety assurance in multi-agent spacecraft inspection.
  • To identify failure scenarios in decentralized RTA and propose mitigation strategies for constraint conflicts.
  • To demonstrate the utility of combining ASIF-based RTA with switching-based RTA for fuel-constrained maneuvers.

Proposed method

  • The authors model the spacecraft inspection problem as a control-affine dynamical system governed by ordinary differential equations.
  • They define multiple safety constraints using Control Barrier Functions (CBF), including safe separation, velocity limits, keep-out zones, and dynamic speed constraints.
  • An Active Set Invariance Filter (ASIF) is used to enforce these constraints via quadratic programming, minimizing deviation from the primary controller while ensuring safety.
  • Centralized and decentralized RTA architectures are implemented, where the centralized version has global knowledge of all deputies’ states and constraints.
  • For fuel limit enforcement, a switching-based RTA approach is introduced, transitioning from an aggressive LQR controller to a backup controller that guides the deputy to an extremal non-maneuvering trajectory (eNMT).
  • Monte Carlo simulations are conducted over 2,000 initial conditions to evaluate safety assurance performance under both RTA architectures.

Experimental results

Research questions

  • RQ1Can ASIF-based RTA effectively enforce multiple translational safety constraints simultaneously in a multi-spacecraft inspection scenario?
  • RQ2How does centralized RTA compare to decentralized RTA in terms of safety assurance reliability for the same set of constraints?
  • RQ3What causes failure in decentralized RTA, and can these failures be mitigated through constraint design or adaptive strengthening?
  • RQ4In what scenarios is switching-based RTA more effective than ASIF for enforcing safety constraints, such as fuel limits?
  • RQ5Can the combination of ASIF and switching-based RTA provide a robust safety assurance framework for complex spacecraft inspection tasks?

Key findings

  • Centralized RTA successfully assured safety for all 2,000 Monte Carlo test cases, achieving 100% success rate.
  • Decentralized RTA achieved safety assurance in 90.95% of test cases, with failures attributed to conflicting multi-agent keep-out zone constraints.
  • The failures in decentralized RTA occurred when multiple deputies attempted to avoid the same exclusion zone simultaneously, leading to insufficient acceleration to satisfy all constraints.
  • Removing or relaxing the multi-agent keep-out zone constraint restored 100% safety assurance in decentralized RTA, indicating the constraint's sensitivity to coordination.
  • The switching-based RTA approach effectively enforced the fuel limit by transitioning to a backup controller that guided the deputy to an eNMT before violating the Δv budget.
  • The simulation results confirmed that ASIF-based RTA is highly effective for most constraints, but hybrid approaches combining ASIF and switching-based RTA are necessary for optimal safety in complex, resource-constrained scenarios.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.