Projects: from a model to a defensible decision
Three connected cases with full worked reasoning, assumptions, transfer exercises and solution checks
Attempt each model before opening the worked route. Identify what is measured, what is chosen, what is uncertain and what “safe” means. All numbers are constructed teaching data. Each conclusion is conditional on the displayed assumptions; the exercises ask what happens when those assumptions change.
1. Measured tank and robust action filtering
Background: norms and intervals, state updates, action filters. A tank contains volume $x_k$ litres and must stay in $[0,10]$. During one sample, a bidirectional pump changes volume by $u_k\in[-1,1]$ litres. An unknown net inflow $w_k\in[-0.2,0.2]$ gives $x_{k+1}=x_k+u_k+w_k$. The measurement is $y_k=x_k+v_k$ with $|v_k|\le0.1$. The sample period is fixed; the bounds describe changes per sample, not litres per second.
A learned policy suggests a pump action. We want to retain that preference when possible while making the next volume safe for every state consistent with the measurement and every allowed inflow. Assume the current true state is safe and the measurement and inflow bounds remain valid. No probability model is required for this robust calculation.
Worked route — construct, filter and audit the action
Step 1: derive both sides. A conservative interval for the current state is $[y_k-0.1,y_k+0.1]$. The smallest next volume is bounded below by $y_k-0.1+u_k-0.2$; the largest is bounded above by $y_k+0.1+u_k+0.2$. Requiring these to lie in $[0,10]$ gives
Intersecting the measurement interval with the known safe set could reduce conservatism near its boundary. The wider interval used here remains a valid sufficient certificate. It is important that both inequalities include sensor error and inflow; accounting for one while forgetting the other changes the guarantee.
Step 2: make a particular decision. At $y_k=0.4$, the safety interval is $[-0.1,9.3]$ and the actuator intersection is $[-0.1,1]$. If the learned policy asks for $u_{\rm nom}=-1$, the nearest feasible input is $u^\star=-0.1$. The extreme combinations give next volume between $0.4-0.1-0.1-0.2=0$ and $0.4+0.1-0.1+0.2=0.6$. The correction is 0.9 litres of commanded change.
Step 3: check that the design can keep operating. A true state in $[0,10]$ produces a valid measurement in $[-0.1,10.1]$. Throughout this measurement range, the lower safety endpoint is at most 0.4, the upper endpoint is at least $-0.4$, and the safety interval has width 9.4. Consequently it intersects $[-1,1]$. For each allowed measurement there is an action, and any selected action in the intersection preserves the safe interval for the next step. Starting from a safe state, induction gives safety for every finite sequence of allowed errors and inflows.
Step 4: say what the proof did not establish. It does not prove that the learned policy is efficient, that the bounds describe a real pump, or that a volume remains safe between sampling instants. The discrete model would need an intersample argument for that last claim. A stuck pump, delayed measurement or larger inflow is outside this certificate.
Exercise P1.B1 — Medium: The upper boundary needs its own filter
At $y=9.8$, a nominal input asks for 0.7. Find the feasible action interval, nearest filtered action and extreme next volumes.
Show hint
Compute the two safety endpoints before intersecting the actuator limits.
Show solution
The safety interval is $[-9.5,-0.1]$, giving actuator intersection $[-1,-0.1]$. Projection gives $u^\star=-0.1$. The extreme next volumes are $9.8-0.1-0.1-0.2=9.4$ and $9.8+0.1-0.1+0.2=10$. A lower-bound-only filter would miss overflow.
Exercise P1.B2 — Hard: A larger inflow can destroy recursive feasibility
Increase the disturbance bound to $|w|\le1.2$ while retaining sensor error 0.1 and actuator limit 1. Derive the new sufficient action interval. Show that a valid state/measurement at the lower boundary can make it empty after actuator intersection.
Show hint
Replace the combined uncertainty 0.3 by 1.3, then take $x=0$, $y=-0.1$.
Show solution
The interval becomes $[1.3-y,8.7-y]$. At the valid measurement $y=-0.1$ it requires $u\ge1.4$, impossible with $u\le1$. This is not only conservatism from the wider state interval: even knowing $x=0$ exactly, the disturbance $w=-1.2$ requires $u\ge1.2$. The actuator cannot preserve this safe set under the new disturbance model.
Exercise P1.B3 — Hard: Write the quantifiers in the right order
For the original model, write the filtering requirement using “for every measurement, there exists an action, for every compatible state and disturbance.” Explain why one fixed input need not work for all tank volumes.
Show hint
An action may depend on the observed measurement. Compare the requirements at the true lower and upper boundaries.
Show solution
For each valid $y$, choose $u(y)\in[-1,1]$ such that for every $x\in[0,10]$ with $|y-x|\le0.1$ and every $|w|\le0.2$, $x+u(y)+w\in[0,10]$. At $x=0$, the worst negative disturbance requires $u\ge0.2$; at $x=10$, the worst positive disturbance requires $u\le-0.2$. No single constant input meets both. State-dependent feedback changes the quantifier order and makes this model controllably invariant.
2. Safe controller tuning with bounded observations
Background: Lipschitz continuity, safe exploration, bounded-noise safety. A scalar controller parameter is $a\in[0,1]$. An unknown steady-operation safety margin $g(a)$ must satisfy $g(a)\ge0$. Assume a valid global Lipschitz bound $|g(a)-g(b)|\le0.5|a-b|$ and observation errors bounded by 0.02. These assumptions describe the margin of a completed experiment; any transient safety requirement needs to be part of the margin definition or handled separately.
A previously safe experiment at $a_0=0.2$ produced $y_0=0.18$. The performance model favors $a=0.6$. Can the next experiment use that parameter, or must exploration first build a larger certified region?
Worked route — expand a certificate without confusing it with an objective
Step 1: lower-bound the unknown margin. At the observed point, $g(a_0)\ge0.18-0.02=0.16$. At any other parameter, $g(a)\ge0.16-0.5|a-0.2|$. This lower bound is nonnegative when $|a-0.2|\le0.32$, certifying $[0,0.52]$ after intersecting the parameter domain.
Step 2: test the proposed decision. At 0.6, the lower bound is $0.16-0.5(0.4)=-0.04$. This does not prove that 0.6 is unsafe; it means the current data and assumptions do not certify it. At 0.5 the lower bound is 0.01, so that query is admissible within the stated model.
Step 3: incorporate a second observation. Suppose the admissible query at 0.5 produces $y_1=0.14$. Its lower margin is 0.12 and its certification radius is $0.12/0.5=0.24$, giving interval $[0.26,0.74]$. The union with the first certificate is $[0,0.74]$, which now includes 0.6. The decision to query 0.5 was safe from previous information; using its favorable result to justify the earlier query would have been circular.
Step 4: separate safety and performance. A Gaussian-process model may rank admissible candidates by predicted productivity or uncertainty. The bounded-error Lipschitz argument supplies the safety certificate in this example. A wide performance confidence interval need not make an already certified point unsafe. Conversely, an attractive predicted mean cannot create a missing safety certificate.
The whole argument relies on the margin’s valid Lipschitz and observation bounds. An empirical slope computed between a few observed pairs is generally a lower bound on the required global Lipschitz constant, not an upper certificate. The project therefore begins by stating a bound as an assumption rather than pretending that two measurements establish it.
Exercise P2.B1 — Medium: A noisier observation changes the first experiment
Increase the error bound to 0.05. Use only the first observation at 0.2. Find the certified interval and decide whether 0.5 can still be queried. Propose a largest certified point to the right.
Show hint
The lower observed margin is now 0.13.
Show solution
The radius becomes $0.13/0.5=0.26$, giving $[0,0.46]$. At 0.5 the lower bound is $0.13-0.15=-0.02$, so the query is uncertified. The largest certified right endpoint is 0.46. A strict positive-margin requirement would instead require choosing a point below that endpoint.
Exercise P2.B2 — Hard: Safety data need not certify optimal performance
After the second observation in the worked route, can the data establish that 0.6 is the productivity-maximizing safe parameter? What additional mathematical object would be needed even to pose that optimization problem?
Show hint
The function $g$ is a safety margin, not a performance score.
Show solution
No. The observations constrain $g$ and certify a set of admissible parameters. One must also define a performance function, its objective direction and the available information or uncertainty about it. Even then, optimizing over the currently certified set need not find the optimum over the full truly safe set. Safety certification, safe-set expansion and performance optimization are separate tasks.
Exercise P2.B3 — Hard: Handle a zero Lipschitz constant honestly
If a valid bound is $L=0$, explain the safe-set update without dividing a margin by $L$. Apply your reasoning first to $y_0-E=0.16$, then to a negative lower margin.
Show hint
A zero Lipschitz bound forces $g$ to be constant throughout the domain.
Show solution
For all $a,b$, $|g(a)-g(b)|\le0$ makes $g(a)=g(b)$. A nonnegative lower margin at one point certifies the entire domain $[0,1]$. A negative lower margin alone certifies no new point by that lower-bound test; it does not prove that the true constant is negative. The radius formula is unnecessary and undefined at $L=0$.
3. Learned decisions: robustness and calibration
Background: dual norms, network sensitivity, calibration. A classifier or decision system selects a positive action when the difference between two scores is positive. At one input $x_0$, suppose a certified analysis gives score gap $m(x_0)=0.6$ and the exact affine change $m(x_0+\delta)-m(x_0)=a^\top\delta$, with $a=(2,-1)$, for every perturbation satisfying $\|\delta\|_\infty\le0.3$. This uniform identity covers the balls and boxes used below; a linear approximation at one point would not establish it. Coordinates are normalized features; converting a physical sensor error into these coordinates is part of the model.
Worked route — separate a pointwise certificate from a distributional statement
Step 1: name the perturbation set. For $\|\delta\|_2\le0.2$, Cauchy–Schwarz gives $|a^\top\delta|\le\sqrt5(0.2)$. The gap lower bound is $0.6-0.2\sqrt5\approx0.1528\gt0$, so the decision is preserved throughout that Euclidean ball. For coordinate-wise bounds $\|\delta\|_\infty\le0.2$, the dual 1-norm gives $|a^\top\delta|\le3(0.2)=0.6$. The lower bound is zero, attained by $\delta=(-0.2,0.2)$, so a strictly positive gap is not certified on the closed box.
Step 2: interpret a strict boundary. Every Euclidean radius $r\lt0.6/\sqrt5\approx0.2683$ gives a strict positive certificate. There is no largest such radius for a closed ball; their supremum is $0.6/\sqrt5$. At equality an adversarial point can tie the two scores. Whether a tie changes the chosen label depends on a tie rule; positivity is a clean sufficient condition independent of that rule. A radius is meaningful only after the norm and feature scaling have been specified.
Step 3: calibrate a different quantity. Separately, suppose a fixed prediction model has absolute residual scores 0.1,0.2,…,1.9 on 19 exchangeable calibration cases. For target miscoverage $\alpha=0.1$, the split-conformal rank is $\lceil(19+1)(1-0.1)\rceil=18$, so the threshold is 1.8. Under exchangeability of these cases together with a new test case, the usual marginal coverage statement is at least 90%. It concerns a future residual under a sampling model, not every perturbation around $x_0$.
Step 4: make the comparison. Pointwise robustness answers whether a particular decision survives every allowed input perturbation. Calibration answers how often a prediction set covers an exchangeable new outcome. Neither implies the other. A shifted operating distribution may invalidate exchangeability while leaving the deterministic local algebra unchanged. A locally fragile classifier may still have good average calibration. State the operational requirement before selecting the evidence.
Exercise P3.B1 — Medium: Feature units change the perturbation geometry
Suppose physical errors are $|e_1|\le0.1$ and $|e_2|\le0.4$, and normalization uses $\delta_1=e_1/0.5$, $\delta_2=e_2/2$. Find the normalized box and score-gap lower bound. Would applying the radius 0.2 directly to the unnormalized feature vector be justified?
Show hint
Convert each coordinate before computing $a^\top\delta$.
Show solution
Both normalized coordinate errors are bounded by 0.2, giving the box in the worked example and lower gap 0. No strict positive certificate follows. A Euclidean 0.2 physical radius is a different set with different units; substituting it without transforming the metric would answer another question.
Exercise P3.B2 — Hard: A calibration rank can exceed the data
With 19 calibration cases, change $\alpha$ to 0.01. Compute the required rank. Explain the conservative convention when that order statistic is unavailable, rather than replacing it silently by the largest finite score.
Show hint
Evaluate $\lceil20(0.99)\rceil$.
Show solution
The rank is 20, exceeding the 19 observed scores. The standard conservative augmented-order-statistic convention assigns an infinite threshold, producing a vacuous prediction set rather than claiming 99% coverage from the sample maximum. Clipping the rank to 19 changes the method and does not inherit the desired distribution-free 99% statement.
Exercise P3.B3 — Hard: Joint decisions need a joint guarantee
Suppose four future predictions each have marginal failure probability at most 0.1 under their valid sampling assumptions. Give a dependence-free lower bound on all four succeeding, and explain why multiplying 0.9 four times needs another assumption. What per-prediction bound would suffice for a joint failure budget 0.1 by the union bound?
Show hint
Bound the probability of the union of failure events.
Show solution
The union bound gives joint success at least $1-4(0.1)=0.6$. Multiplication gives $0.9^4=0.6561$ only with suitable independence of the success events, not from marginal coverage alone. Allocating failure at most 0.025 to each gives union failure at most 0.1. Constructing prediction sets that genuinely achieve those marginal bounds still requires their calibration assumptions and enough data.
Write a complete engineering argument
For any project, finish with a short report containing the requirement in words, the model with units, the uncertainty set or sampling assumptions, the decision rule, a worked calculation and the exact conclusion. Then describe one concrete model change that invalidates the conclusion. Include a failed candidate as well as a successful one: explaining why a certificate cannot establish safety is part of understanding what it can establish.
A strong report separates “the model proves the property,” “the numerical procedure found this candidate,” and “the assumptions describe the application.” These statements need different evidence. Return to the book contents for the supporting chapters or use the glossary to reconstruct the terms.