Problem
Drones, air taxis and robot teams are cyberphysical systems: physical machines run by software and linked by networks. Before they can be trusted in safety-critical airspace, we need to know every state they could reach, and whether any of those states is unsafe. The exact answer comes from solving high-dimensional partial differential equations, which is out of reach once a system is nonlinear, learned from data by a neural network, spread across many agents, or under cyberattack.
My doctoral dissertation, Data-Driven Safety & Security of Cyberphysical Systems, computes these safety guarantees without solving those equations. It uses data, Koopman operator theory and optimal control to approximate reachable sets quickly, and then turns the same tools around to show how an attacker could exploit such systems. The work has three thrusts.
Safety of learned systems
When the dynamics are unknown, or learned by a neural network, there is no model to analyze directly. Two questions drive this thrust:
- How much can an unknown system reach, judged from data alone? A Koopman model of the system is learned from data and embedded in a structure (mixed monotonicity) whose reachable sets are cheap to bound. On a 7-state enzymatic benchmark, it over-approximates the reachable set faster than the CORA reachability toolbox for longer time horizons (IEEE Access 2022).

Reachable set of the 7-state Laub-Loomis model: computed by the CORA toolbox (left, green) and over-approximated by the Koopman mixed-monotonicity method (right, yellow boxes), both enclosing the sampled trajectories. From Approximate reachability for Koopman systems using mixed monotonicity, IEEE Access 2022.
- Can safety be checked in real time when the model is a neural network? A network learns a quadrotor’s dynamics offline from trajectory data. Online, it is excited with short windows of inputs, and dynamic mode decomposition turns its response into a sequence of linear models. Optimal control then pushes the edges of the initial set forward in time, giving polytopic reachable sets in real time, with accuracy tuned by how many edges are used. The same pipeline still works after two of the quadrotor’s rotors fail (IEEE TCST 2023).

Quadrotor trajectories from the true dynamics (red), the learned neural network (blue) and the linear approximation used for reachability (black).

Reachable-set approximations (red) along a quadrotor trajectory in the y–z plane, and the optimal rotor inputs that generate them, inside their limits (right). From Approximating Reachable Sets for Neural Network-Based Models in Real Time via Optimal Control, IEEE TCST 2023.
Safety of multi-agent systems
In a team of agents, each agent’s feedback depends on its neighbors, so their reachable sets are coupled, yet no agent knows the whole team’s dynamics.
- Can each agent compute its own reachable set using only its neighbors?
Yes, and the answer rests on two results
(ACC 2025):
- Polytopic reachability. Building on Varaiya’s classic result, every flat face touching the initial set can be tracked forward in time: its contact point follows the system dynamics driven by the solution of a small optimal control problem. Together, the tracked faces bound the reachable set, and adding faces tightens the bound.
- Distributed convergence. The computation splits into steps each agent runs with its neighbors. As long as the communication network, even one that changes over time, is connected often enough (repeatedly jointly strongly connected), the shared linear-algebra steps converge exponentially fast and the optimal control step finishes in finite time.

Agent i sees only its neighborhood, but its reachable set is coupled to its neighbors’. From An Algorithm for Distributed Computation of Reachable Sets for Multi-Agent Systems, ACC 2025.
- How can a team of robots avoid obstacles that only some of them can see? Knowledge of the obstacles is spread across the network, so the planning problem is split into small linear programs, one per robot, which is far cheaper than solving one large nonlinear problem (ACC 2021).
- How fast can a network of agents solve a shared optimization problem? A distributed, fast-tracking version of the ADMM algorithm reaches an optimal convergence rate (IEEE SMC 2021).
Cybersecurity of networked systems
The same data that makes safety analysis possible also helps an attacker. This thrust asks how networked control systems can be attacked, and how they can be defended.
Data-driven attacks on networked control
- What can an attacker do with nothing but observed data? By learning a model of a networked system from data alone, an attacker can design coordinated false-data-injection and denial-of-service attacks, corrupting what agents sense and cutting the links between them, that break a five-drone formation (IFAC World Congress 2023).
- Can an attacker force a switching controller into the wrong mode, and can it be stopped? A neural network learns when the controller switches modes and crafts attacks that trigger the wrong one. On the defense side, a generative adversarial network detects the injected signals and reconstructs clean data, keeping a robot formation on course (ECC 2021).

Left: the formation-control setup. Middle: with the learned defense, all three robots stay in formation. Right: without it, an attack on robot 3 drives it off course. From Learning Based Cyberattack Design and Defense for Supervisory Control Systems, ECC 2021.
- When will a human misread what the automation is doing? For systems that switch between modes, mode confusion is predicted ahead of time using mixed-integer linear programming (IEEE CDC 2019).
Cybersecurity of urban air mobility networks
Air taxis and drones sharing urban airspace will coordinate over networks, which makes those networks a target.
- How can a fleet keep working when the networks that tie it together are attacked? A distributed, optimization-based controller keeps a multi-agent system working under cyberattack when agents interact through two separate networks (AIAA SciTech 2022).
- How exposed is each aircraft to a distributed denial-of-service attack? A graph-based vulnerability score lets each aircraft assess its own exposure, then reorganize with its neighbors to cut collision risk, all without a central coordinator. The resulting control provably reduces vulnerability, in a probabilistic sense, against an attacker with a known budget (Journal of Aerospace Information Systems, 2023).
Outcome
- Real-time safety checks for learned systems. Reachable sets for a neural-network quadrotor model computed in real time, including after rotor failure.
- Part of a NASA program for safe urban air mobility. Research carried out under NASA’s University Leadership Initiative project Secure and Safe Assured Autonomy (S2A2), on its secured-autonomy challenge.
- Follow-on DARPA funding. Co-authored the successful proposal behind Purdue’s collaboration with Saab on DARPA’s Learning Introspective Control (LINC) program, developing adaptive, self-correcting control for uncrewed sea vessels.
- Eleven papers, including journal articles in IEEE Transactions on Control Systems Technology, IEEE Access and the Journal of Aerospace Information Systems, and the basis of my Ph.D. dissertation (Purdue, 2023).
