Paper deep dive
Resilient Output Containment under Undisclosed Leader Dynamics and Actuator Attacks
Mohammadreza Nematollahi, Khashayar Khorasani, Nader Meskin
Intelligence
Status: succeeded | Model: Gemma-4-26B-A4B | Prompt: intel-v1 | Confidence: 90%
Last extracted: 7/9/2026, 8:25:48 AM
Summary
This paper addresses resilient output containment for heterogeneous linear multi-agent systems subject to undisclosed leader dynamics and actuator cyber-attacks. It proposes a continuous two-layer adaptive control architecture comprising a virtual-actuator reconfiguration layer to compensate for local actuator attacks and a network interface layer that generates task-space commands via a distributed adaptive protocol. Theoretical analysis using nonsmooth Lyapunov methods proves asymptotic command containment over directed graphs with a leader-rooted united spanning-tree, while physical outputs converge to the leaders' convex hull. Simulation with quadrotors validates the approach.
Entities (8)
Relation Signals (7)
Multi-agent systems → studiedfor → Output containment
confidence 95% · This work studies resilient output containment for heterogeneous linear multi-agent systems with actuator cyber-attacks over directed network topologies.
Virtual-actuator → compensatesfor → Actuator cyber-attacks
confidence 90% · The first layer is a virtual-actuator reconfiguration layer that uses partial state measurements to compensate for actuator attacks in the local tracking-error dynamics.
Adaptive control architecture → comprises → Virtual-actuator
confidence 90% · A continuous two-layer adaptive control architecture is proposed. The first layer is a virtual-actuator reconfiguration layer that uses partial state measurements to compensate for actuator attacks in the local tracking-error dynamics.
Actuator cyber-attacks → compromise → Output containment
confidence 90% · This work studies resilient output containment for heterogeneous linear multi-agent systems with actuator cyber-attacks over directed network topologies.
Nonsmooth Lyapunov analysis → establishes → Asymptotic containment
confidence 90% · For directed graphs, under a leader-rooted united spanning-tree condition, a nonsmooth Lyapunov analysis yields asymptotic containment at the command level.
Directed network topologies → requirecondition → Leader-rooted united spanning-tree
confidence 90% · For directed graphs, under a leader-rooted united spanning-tree condition, a nonsmooth Lyapunov analysis yields asymptotic containment at the command level.
Cypher Suggestions (0)
No Cypher suggestions yet.
Abstract
Abstract:This work studies resilient output containment for heterogeneous linear multi-agent systems with actuator cyber-attacks over directed network topologies. The leaders generate bounded locally absolutely continuous trajectories; however, their dynamics, velocity bounds, and motion envelopes are undisclosed to the followers. The cyber-attack model includes state- and input-correlated, as well as bounded exogenous actuator false-data terms. A continuous two-layer adaptive control architecture is proposed. The first layer is a virtual-actuator reconfiguration layer that uses partial state measurements to compensate for actuator attacks in the local tracking-error dynamics. The second layer is a network interface that generates task-space commands via an adaptive interaction protocol. This protocol uses only neighbor-exchanged network-interface states whose dimensions match those of the plant output, and it does not require global graph knowledge for parameter tuning. For directed graphs, under a leader-rooted united spanning-tree condition, a nonsmooth Lyapunov analysis yields asymptotic containment at the command level. The physical outputs then converge to the leader convex hull up to a residual determined by the command-tracking local controllers. Simulation results using a network of quadrotors with damped suspended loads illustrate the performance of attack recovery and containment tracking.
Tags
Links
- Source: https://arxiv.org/abs/2606.27257v1
- Canonical: https://arxiv.org/abs/2606.27257v1
Trouble viewing inline? Open PDF directly →
Full Text
120,940 characters extracted from source content.
Expand or collapse full text
Resilient Output Containment under Undisclosed Leader Dynamics and Actuator Attacks Mohammadreza Nematollahi1, Khashayar Khorasani1, and Nader Meskin2 1Department of Electrical and Computer Engineering, Concordia University, Montreal, Canada. Emails: m_nemato@encs.concordia.ca; kash@ece.concordia.ca.2Department of Electrical Engineering, Qatar University, Doha, Qatar. Email: nader.meskin@qu.edu.qa.Supported by NATO (Emerging Security Challenges Division), NSERC Discovery, DND Supplemental, and DND IDEaS. The views expressed are those of the authors and not necessarily those of the sponsors or the Government of Canada. Abstract This work studies resilient output containment for heterogeneous linear multi-agent systems with actuator cyber-attacks over directed network topologies. The leaders generate bounded locally absolutely continuous trajectories; however, their dynamics, velocity bounds, and motion envelopes are undisclosed to the followers. The cyber-attack model includes state- and input-correlated, as well as bounded exogenous actuator false-data terms. A continuous two-layer adaptive control architecture is proposed. The first layer is a virtual-actuator reconfiguration layer that uses partial state measurements to compensate for actuator attacks in the local tracking-error dynamics. The second layer is a network interface that generates task-space commands via an adaptive interaction protocol. This protocol uses only neighbor-exchanged network-interface states whose dimensions match those of the plant output, and it does not require global graph knowledge for parameter tuning. For directed graphs, under a leader-rooted united spanning-tree condition, a nonsmooth Lyapunov analysis yields asymptotic containment at the command level. The physical outputs then converge to the leader convex hull up to a residual determined by the command-tracking local controllers. Simulation results using a network of quadrotors with damped suspended loads illustrate the performance of attack recovery and containment tracking. I INTRODUCTION In multi-agent systems (MAS), containment tracking requires the outputs of a follower network to converge to the time-varying convex hull generated by multiple leaders [1]. In security-critical cyber-physical deployments, two cybersecurity constraints complicate this objective. First, the leaders’ dynamics often encode sensitive mission objectives or maneuvering patterns, and if exposed, this model knowledge equips adversaries with the information needed to synthesize stealthy cyber-attacks [2], necessitating strict nondisclosure policies that, in turn, restrict designers’ access to such information. Second, such confidentiality does not, by itself, rule out local actuator-channel compromises, and adversaries can still corrupt the execution of containment commands. These disruptions may propagate through the network and undermine its collective objective. Therefore, local control architectures must compensate for admissible actuator effects while preventing their propagation into the coordination layer. These two considerations motivate a two-layer control design, namely a network layer that generates containment commands without relying on the models of leaders, paired with a local layer that guarantees execution resilience. Distributed observer-based containment frameworks and their adaptive variants [3, 4, 5, 6] typically introduce an estimation layer that requires followers to know or reconstruct, under suitable structural assumptions, the leaders’ exosystem dynamic parameters, thereby conflicting with nondisclosure constraints. Sliding mode protocols [7, 8, 9] can avoid this requirement by treating leader trajectories as bounded exogenous signals whose generator dynamics are unknown. However, these approaches have two main shortcomings: first, they often introduce discontinuous terms, leading to undesired chattering; and second, their reliance on a priori knowledge of velocity bounds or motion envelopes results in conservative design. To alleviate chattering, the boundary-layer approximation of the discontinuous terms is used at the cost of demoting asymptotic convergence to mere ultimate boundedness. Continuous approximations with integrable residuals instead recover asymptotic convergence [10, 11] and have recently been extended to multi-agent settings [12]. On the other hand, relaxing the requirement for known leaders’ bounds requires adaptive mechanisms and has received comparatively little attention. Although the approach in [13] addresses this issue using higher-order differentiators, the resulting protocol remains discontinuous and susceptible to chattering. Continuous adaptive protocols, in turn, have been largely confined to undirected or detailed-balanced directed topologies [14, 15], or are conditioned on local command approximability by adaptive PIDs [16]. Consequently, continuous asymptotic containment over general directed leader-rooted graphs, without leader-model reconstruction or known bounds on leaders’ motion, remains underexplored. Observer-based containment designs separate network-level signal generation from local tracking through an explicit leader model or exosystem layer. This separation ensures that actuator attacks affect only the plant-level execution of a command, not the task-space protocol that generates it, so their effects remain local, non-propagating, and compensable. Under the undisclosed leader models considered here, this separation therefore cannot be inherited from a distributed observer layer and must instead be built directly into the architecture. Virtual-actuator and fault-hiding methods provide a natural mechanism for this purpose by inserting a recovery block between the nominal controller and the compromised actuator channel [17]. Existing Virtual-actuator results, however, typically provide ultimate boundedness under exogenous or fault-like attacks [18, 19], whereas asymptotic recovery results commonly require full state measurements [14]. Thus, continuous recovery with asymptotic tracking-error convergence under partial state measurements, while allowing combined state-correlated, input-correlated, and bounded exogenous actuator false-data terms, needs to be addressed. To address the above gaps, this work develops a continuous two-layer architecture for resilient output containment of heterogeneous linear followers under actuator attacks and undisclosed leader dynamics. The contributions are as follows. First, a continuous adaptive protocol is proposed to generate local commands using only neighbor-exchanged network interface states, whose dimension matches the plant-output dimension. The protocol does not require global graph knowledge for tuning, nor does it require a priori leader-velocity bounds, motion envelopes, or exosystem models. Second, a novel nonsmooth Lyapunov analysis is used to establish asymptotic command-containment results for the proposed protocol over directed graphs with a leader-rooted united spanning tree, without imposing symmetry restrictions on the follower subgraph. Third, a continuous adaptive virtual-actuator layer is proposed to asymptotically compensate for the actuator attacks, comprising state-correlated, input-correlated, and bounded false-data terms, while using only partial state measurements. Finally, the interconnection of the network-interface and virtual-actuator layers is shown to yield asymptotic convergence of the task-space command errors, while the physical outputs of the heterogeneous followers achieve practical containment. I Problem Formulation I-A Network Topology Consider a network of followers ℱF and leaders T, with |ℱ|=M|F|=M and ||=N>1|T|=N>1, interacting over a fixed weighted digraph (,ℰ)G(V,E), where =1,…,M,M+1,…,M+NV=\1,…,M,M+1,…,M+N\ and ℰ⊆×E ×V. Followers are indexed by i∈ℱ=1,…,Mi =\1,…,M\, while leaders are indexed by ℓ∈=1,…,N =\1,…,N\. Let =[aij≥0]A_G=[a_ij≥ 0] denote the adjacency matrix, with aij>0a_ij>0 whenever there is a directed link from agent j to agent i, and let ℒL_G denote the graph Laplacian. Partitioning the agents into followers and leaders, after possibly permuting the agent indices, gives ℒ=[HFLFLN×MN×N].L_G= bmatrixH_F&L_FL\\ 0_N× M&0_N× N bmatrix. (1) Here, HF∈ℝM×MH_F ^M× M denotes the information-exchange matrix [20], defined by (HF)ii=∑j∈ℱaij+∑ℓ∈aiℓ(H_F)_i= _j a_ij+ _ a_i and (HF)ij=−aij(H_F)_ij=-a_ij for i≠ji≠ j, while (LFL)iℓ=−aiℓ(L_FL)_i =-a_i . Since each row of ℒL_G sums to zero, HFM+LFLN=0H_F1_M+L_FL1_N=0. The digraph G is said to have a united spanning tree rooted at the leaders if every follower is reachable from at least one leader. Assumption 1 The digraph G has a united spanning tree rooted at the leaders. Under Assumption 1, HFH_F is a nonsingular M-matrix [21]. Consequently, HF−1≥0H_F^-1≥ 0, −HF−1LFL≥0-H_F^-1L_FL≥ 0, and −HF−1LFLN=M-H_F^-1L_FL1_N=1_M, which implies that −HF−1LFL-H_F^-1L_FL is row stochastic [1]. It should be noted that the existence of a united spanning tree rooted at the leaders is a necessary topological condition for containment tracking [1]. I-B Followers’ Dynamics Each follower in this work is modeled as a linear MIMO system with a control input ui∈ℝmu_i ^m and an output yi∈ℝmy_i ^m with a vector relative degree denoted by i=[d1i,…,dmi]⊤d_i=[d_1^i,…,d_m^i] , with respect to the output yiy_i. The followers’ dynamics are expressed in the normal-form coordinates [22] as, x˙i=Aixi+Bi(Liηi+ψiui)η˙i=Γiηi+Λiyiyi=Cixi cases x_i=A_ix_i+B_i(L_i _i+ _iu_i)\\ η_i= _i _i+ _iy_i\\ y_i=C_ix_i cases (2) where the external-state xi∈ℝ∑k=1mdkix_i _k=1^md_k^i contains the outputs and their derivatives up to order dki−1d_k^i-1 in each output channel and ηi∈ℝni−∑k=1mdki _i ^n_i- _k=1^md_k^i contains the zero-dynamics coordinates. The matrices AiA_i and BiB_i are in the normal controllable canonical form; CiC_i is a selector matrix that extracts the output yiy_i from xix_i; and LiL_i, Γi _i, and Λi _i describe the coupling between the external dynamics and the zero dynamics and are known to designers. The matrix ψi∈ℝm×m _i ^m× m is known and invertible. We refer the reader to [22] for more details on the structure of matrices. Assumption 2 The matrix Γi _i associated with the followers’ zero dynamics is Hurwitz. Since the followers do not have access to the leaders’ model to embed a leader exosystem and solve the regulator equations for that model, the local tracking problem must remain solvable for every admissible bounded leader trajectory, which requires this minimum-phase condition. In this setup, the same condition also rules out unstable zero dynamics, which are known to create vulnerabilities to zero-dynamic attacks in cyber-physical systems [23]. Assumption 3 The variables xix_i are available for control implementation. For the present normal-form model, this assumption does not require measurement of the zero-dynamics state ηi _i, in contrast to full-state implementations commonly used in resilient containment designs [14, 18]. An output-feedback extension can be obtained under the standard regularity assumptions required by exact differentiators [24, 25], but this extension is not pursued here. I-C Leaders’ Dynamics For each leader ℓ∈ , the state ϕℓ _ evolves according to ϕ˙ℓ(t)=νℓ(t),ϕℓ(t)∈ℝm φ_ (t)= _ (t), _ (t) ^m (3) Assumption 4 For each leader ℓ∈ , the signal ϕℓ:[0,∞)→ℝm _ :[0,∞) ^m is defined for all t≥0t≥ 0 and is locally absolutely continuous. Moreover, for every admissible realization of the leader motion, there exist finite constants ϕ¯ℓ>0 φ_ >0 and ν¯ℓ>0 ν_ >0, possibly depending on the realized trajectory and its initial condition, such that ‖ϕℓ(t)‖≤ϕ¯ℓ,‖ϕ˙ℓ(t)‖≤ν¯ℓ\| _ (t)\|≤ φ_ , \| φ_ (t)\|≤ ν_ for almost all t≥0t≥ 0. These constants, however, are unknown. Assumption 4 is imposed at the trajectory level. It does not require followers to know a leader model, an exosystem realization, or bounds on motion. It includes trajectories generated by the classical marginally stable LTI exosystems ω˙ℓ=Sℓωℓ ω_ =S_ _ , ϕℓ=Cℓωℓ _ =C_ _ , whenever the eigenvalues of SℓS_ on the imaginary axis are semisimple. More generally, nonlinear exosystems are also covered whenever the realized trajectory remains in a compact set, and the generated output and its derivative are bounded along that trajectory. The information received from a leader-neighbor is limited to the instantaneous task-space signal ϕℓ(t) _ (t), or equivalently to the relative signal used in the distributed protocol. No follower is assumed to know νℓ(t) _ (t), a bound on ‖νℓ‖\| _ \|, a leader exosystem realization, a motion envelope, or any future value of ϕℓ _ . The boundedness constants in Assumption 4 are used only for analysis and are unavailable for tuning the controller parameters. With Φ=col(ϕ1,…,ϕN),ΦL(t)=ϕℓ(t):ℓ∈ =col( _1,…, _N), _L(t)=\ _ (t): \ and νL=Φ˙ _L= , one has Φ∈W1,∞([0,∞);ℝNm) ∈ W^1,∞([0,∞);R^Nm) and νL∈L∞([0,∞);ℝNm) _L∈ L_∞([0,∞);R^Nm), with unknown finite essential bounds. We also denote by co(ΦL(t))co( _L(t)) the convex hull of the leaders’ positions at each instant, with point-to-set distance defined as dist(y,S)=infq∈S‖y−q‖dist(y,S)= _q∈ S\|y-q\|. I-D Actuator Attacks Followers are subject to actuator attacks modeled as ui(t)=ui,nom(t)+wai(t),wai(t)=waic(t)+waiuc(t).u_i(t)=u_i,nom(t)+w_a_i(t), w_a_i(t)=w_a_i^c(t)+w_a_i^uc(t). (4) The correlated component waicw_a_i^c is generated by waic(t)=Kaix(xi,t)xi(t)+Kaiu(t)ui,nom(t),w_a_i^c(t)=K_a_i^x(x_i,t)x_i(t)+K_a_i^u(t)u_i,nom(t), (5) where Kaix(xi,t)xi(t)K_a_i^x(x_i,t)x_i(t) denotes the state-correlated actuator-side component and Kaiu(t)ui,nom(t)K_a_i^u(t)u_i,nom(t) denotes the input-correlated part. The term waiuc(t)w_a_i^uc(t) is an exogenous false-data injection. Assumption 5 For each follower i, the state-correlated attack coefficient Kaix(xi,t)K_a_i^x(x_i,t) is Carathéodory in (xi,t)(x_i,t) and locally Lipschitz in x on compact sets, uniformly on finite time intervals up to a locally integrable Lipschitz modulus. Moreover, there exist an unknown constant κxi>0 _x^i>0 and a known envelope ωxi:ℝ∑k=1mdki×[0,∞)→[0,∞) _x_i:R _k=1^md_k^i×[0,∞)→[0,∞) such that ωxi _x_i is continuous, locally Lipschitz in x, and satisfies, for every R>0R>0, sup‖x‖≤R,t≥0ωxi(x,t)<∞. _\|x\|≤ R,\ t≥ 0 _x_i(x,t)<∞. (6) Furthermore, ‖Kaix(xi,t)‖≤κxiωxi(xi,t)\|K_a_i^x(x_i,t)\|≤ _x^i _x_i(x_i,t) (7) for all x and for almost all t≥0t≥ 0. Assumption 5 specifies the actuator-attack classes for which recovery guarantees are sought. The defender does not need to know the magnitude of the state-correlated actuator attack, but must choose a known envelope ωxi _x_i that upper-bounds the growth of the presumed cyber-attacks. This reflects the standard adaptive-robust-control tradeoffs, where unknown uncertainty magnitudes are handled by adaptive gains, whereas the admissible growth structure must be specified through a known envelope [26]. The envelope ωxi _x_i can be selected from a prescribed admissible class for the state-correlated actuator attack. One convenient way to obtain such an envelope is through a reproducing-kernel Hilbert space (RKHS) description [26, 27]. Briefly, an RKHS ℋxiH_x_i is a Hilbert space of functions associated with a positive definite kernel kxik_x_i, where point evaluations are represented by the kernel. Thus, for any f∈ℋxif _x_i, we have f(x)=⟨f,kxi(⋅,x)⟩ℋxif(x)= f,k_x_i(·,x) _H_x_i, and then Cauchy-Schwarz inequality gives |f(x)|≤‖f‖ℋxikxi(x,x)|f(x)|≤\|f\|_H_x_i k_x_i(x,x). Therefore, if each scalar entry of Kaix(⋅,t)K_a_i^x(·,t) belongs to ℋxiH_x_i for almost all t, with an unknown finite essential supremum of its RKHS norm over time, then Assumption 5 is satisfied, after absorbing fixed dimension-dependent constants into κxi _x^i, with the known envelope ωxi(x,t)=kxi(x,x) _x_i(x,t)= k_x_i(x,x). If kxik_x_i is a Gaussian kernel, then ωxi≡1 _x_i≡ 1, and the usual bounded state-correlated attack gain is recovered. Assumption 6 For each follower i, the map Kaiu:[0,∞)→ℝm×mK_a_i^u:[0,∞) ^m× m is continuous and essentially bounded satisfying supt≥0‖Kaiu(t)‖≤kui¯ _t≥ 0 \|K_a_i^u(t) \|≤ k_u^i for some unknown kui¯ k_u^i. Denoting Δui(t)=Im+ψiKaiu(t)ψi−1 _u_i(t)=I_m+ _iK_a_i^u(t) _i^-1, we further assume that there exists an unknown constant χi>0 _i>0 such that s⊤Δui(t)s≥χi‖s‖2s _u_i(t)s≥ _i\|s\|^2 for all s∈ℝms ^m and for almost all t≥0t≥ 0. Assumption 7 For each follower i, the exogenous false-data injection waiuc(t)w_a_i^uc(t) is continuous and essentially bounded, i.e., there exists an unknown finite constant kwi>0k_w^i>0 such that supt≥0‖waiuc(t)‖≤kwi _t≥ 0 \|w_a_i^uc(t) \|≤ k_w^i. The condition in Assumption 6 preserves the defender’s strictly positive effective input authority and prevents the input-correlated attack from canceling the defender’s command direction. For example, in a UAV application, an actuator-side adversary may attempt to drive the vehicle toward an adversarial reference trajectory and hijack the vehicle while partially rejecting the defender’s nominal corrections. If the adversarial reference is generated by a bounded marginally stable exosystem, its feedforward contribution can be represented through waiuc(t)w_a_i^uc(t). The feedback component induced by the compromised actuator channel can then be represented by Kaix(xi,t)xiK_a_i^x(x_i,t)x_i that can be an unknown nonlinear function of the disclosed variables xix_i, with an admissible amplitude class that can be bounded, polynomial-growth, or belonging to a prescribed kernel-induced class. Destabilizing actuator attacks [28] can also be captured by this parameterization whenever their dependence on xix_i admits a known envelope of the form required in Assumption 5. With the system description and attack models in place, we now state the control objective. In this setup, we distinguish command-level containment from physical-output containment. In fact, for followers with heterogeneous higher-order relative degrees, exact physical-output tracking of arbitrary moving commands would generally require higher-order command derivatives. However, since the available leader information is limited to locally absolutely continuous trajectories with unknown velocity bounds, and under the information pattern considered in this paper, such information is nonexistent or unavailable. Accordingly, the physical outputs are required to converge to the leaders’ convex hull, with a residual determined by the local command-tracking error, whereas the local commands need to converge asymptotically. Problem 1 Consider the heterogeneous MAS (2) over the graph (1), with leaders (3) and actuator attacks (4)-(5). Under Assumptions 1-7, design continuous local nominal controllers ui,nomu_i,nom and a continuous distributed interaction law such that all closed-loop follower signals remain bounded and, for every follower i∈ℱi , lim supt→∞dist(yi(t),co(ΦL(t)))≤εi, _t→∞dist (y_i(t),co( _L(t)) )≤ _i, (8) where εi≥0 _i≥ 0 is to be determined by the closed-loop architecture. The local controller may use only the external state xix_i and local adaptive variables. The distributed interaction law may use only neighbor-exchanged network-interface states and instantaneous leader-neighbor task-space signals when leader-neighbor edges exist. I Control Architecture and Main Results I-A Command Filter, Immersion, and Error Dynamics For each follower i∈ℱi , let ri∈ℝmr_i ^m denote the task-space command supplied by the network-interface layer to be designed later, and choose a stable local command filter z˙i=Fizi+Giri, z_i=F_iz_i+G_ir_i, (9) where FiF_i is Hurwitz. The filter (9) is a local design object and is not a model of the leaders. It is called admissible for follower i if there exist matrices Πi1 _i_1, Πi2 _i_2, QiQ_i, and KiK_i, with Πi=col(Πi1,Πi2) _i=col( _i_1, _i_2) and Hi=CiΠi1H_i=C_i _i_1, such that ΠiFi=[AiBiLiΛiCiΓi]Πi+[Bi0]Qi,ΠiGi=[Bi0]Ki,rankHi=m,rank(HiFi−1Gi)=m. split _iF_i&= bmatrixA_i&B_iL_i\\ _iC_i& _i bmatrix _i+ bmatrixB_i\\ 0 bmatrixQ_i,\\ _iG_i&= bmatrixB_i\\ 0 bmatrixK_i,\\ rankH_i&=m, (H_iF_i^-1G_i )=m. split (10) The two matching equations in (10) ensure that every trajectory generated by the command filter can be embedded into the nominal follower dynamics. The rank condition on HiH_i ensures that the embedded nominal output spans the m-dimensional task space. The rank condition on HiFi−1GiH_iF_i^-1G_i ensures that the command-interface map used later is well defined. We next show that admissible command filters are not an additional restrictive assumption. They can be constructed directly from the follower’s normal-form representation. Let nxi=∑k=1mdki,nηi=ni−nxi.n_x_i= _k=1^md_k^i, n_ _i=n_i-n_x_i. For each output channel k, choose a Hurwitz polynomial pik(s)=srki+aik,rkisrki−1+⋯+aik,2s+aik,1,aik,1≠0.p_ik(s)=s^r_k^i+a_ik,r_k^is^r_k^i-1+·s+a_ik,2s+a_ik,1, a_ik,1≠ 0. Because AiA_i and BiB_i are in the normal controllable canonical form associated with the vector relative degree [d1i,…,dmi]T[d_1^i,…,d_m^i]^T, one can choose an external-chain feedback matrix KxiK_x_i such that Fxi=Ai+BiKxiF_x_i=A_i+B_iK_x_i has, in channel k, the characteristic polynomial pikp_ik. Hence FxiF_x_i is Hurwitz. More explicitly, for the k-th chain, the last derivative can be assigned as ξ˙ik,rki=−aik,1ξik,1−aik,2ξik,2−⋯−aik,rkiξik,rki+r~ik, ξ_ik,r_k^i=-a_ik,1 _ik,1-a_ik,2 _ik,2-·s-a_ik,r_k^i _ik,r_k^i+ r_ik, which gives the desired stable chain dynamics from r~ik r_ik to the embedded output ξik,1 _ik,1. Consequently, Di=CiFxi−1BiD_i=C_iF_x_i^-1B_i is nonsingular. In the decoupled canonical-chain realization, one has Di=−diag(ai1,1−1,…,aim,1−1),D_i=-diag (a_i1,1^-1,…,a_im,1^-1 ), which is nonsingular because aik,1≠0a_ik,1≠ 0 for all k. Now choose a nonsingular matrix Si∈ℝnηi×nηiS_i ^n_ _i× n_ _i and define the internal filter realization Fηid=Si−1ΓiSi,Λid=Si−1Λi.F_ _i^d=S_i^-1 _iS_i, _i^d=S_i^-1 _i. Since Γi _i is Hurwitz by Assumption 2, FηidF_ _i^d is also Hurwitz. This construction explicitly assigns the zero-dynamics part of the command filter to a prescribed stable realization similar to the follower zero dynamics. In particular, taking Si=IS_i=I gives Fηid=ΓiF_ _i^d= _i. This is the appropriate assignment freedom for the internal part, where the zero-dynamics eigenvalues are intrinsic to the plant normal form and cannot be arbitrarily reassigned by a command filter, but any stable coordinate realization similar to Γi _i can be used. Define Fi=[Fxi0ΛidCiFηid],Gi=[BiKi0],F_i= bmatrixF_x_i&0\\ _i^dC_i&F_ _i^d bmatrix, G_i= bmatrixB_iK_i\\ 0 bmatrix, (11) where Ki∈ℝm×mK_i ^m× m is chosen nonsingular, for example Ki=−Di−1.K_i=-D_i^-1. (12) Also choose Πi1=[Inxi0],Πi2=[0Si],Qi=[Kxi−LiSi]. _i_1= bmatrixI_n_x_i&0 bmatrix, _i_2= bmatrix0&S_i bmatrix, Q_i= bmatrixK_x_i&-L_iS_i bmatrix. (13) Then Πi=col(Πi1,Πi2)=diag(Inxi,Si) _i=col( _i_1, _i_2)=diag(I_n_x_i,S_i). With (11) and (13), ΠiFi=[I00Si][Fxi0Si−1ΛiCiSi−1ΓiSi]=[Fxi0ΛiCiΓiSi]. _iF_i= bmatrixI&0\\ 0&S_i bmatrix bmatrixF_x_i&0\\ S_i^-1 _iC_i&S_i^-1 _iS_i bmatrix= bmatrixF_x_i&0\\ _iC_i& _iS_i bmatrix. On the other hand, [AiBiLiΛiCiΓi]Πi+[Bi0]Qi=[AiBiLiΛiCiΓi][I00Si]+[Bi0][Kxi−LiSi]. split& bmatrixA_i&B_iL_i\\ _iC_i& _i bmatrix _i+ bmatrixB_i\\ 0 bmatrixQ_i\\ &= bmatrixA_i&B_iL_i\\ _iC_i& _i bmatrix bmatrixI&0\\ 0&S_i bmatrix+ bmatrixB_i\\ 0 bmatrix bmatrixK_x_i&-L_iS_i bmatrix. split Therefore, [Ai+BiKxiBiLiSi−BiLiSiΛiCiΓiSi]=[Fxi0ΛiCiΓiSi]=ΠiFi. bmatrixA_i+B_iK_x_i&B_iL_iS_i-B_iL_iS_i\\ _iC_i& _iS_i bmatrix= bmatrixF_x_i&0\\ _iC_i& _iS_i bmatrix= _iF_i. Thus the first matching equation in (10) holds. Similarly, ΠiGi=[I00Si][BiKi0]=[BiKi0]=[Bi0]Ki, _iG_i= bmatrixI&0\\ 0&S_i bmatrix bmatrixB_iK_i\\ 0 bmatrix= bmatrixB_iK_i\\ 0 bmatrix= bmatrixB_i\\ 0 bmatrixK_i, which proves the second matching equation in (10). It remains to verify the rank conditions. Since Hi=CiΠi1=[Ci0],H_i=C_i _i_1= bmatrixC_i&0 bmatrix, and CiC_i extracts the m output coordinates from the external normal-form state, rankHi=mrankH_i=m. Moreover, FiF_i is block lower triangular with diagonal blocks FxiF_x_i and FηidF_ _i^d, both Hurwitz. Hence FiF_i is Hurwitz. Since Gi=col(BiKi,0)G_i=col(B_iK_i,0), the block triangular inverse gives HiFi−1Gi=CiFxi−1BiKi=DiKi.H_iF_i^-1G_i=C_iF_x_i^-1B_iK_i=D_iK_i. With the choice (12), this becomes HiFi−1Gi=−Im,H_iF_i^-1G_i=-I_m, and therefore rank(HiFi−1Gi)=m.rank (H_iF_i^-1G_i )=m. This proves that an admissible command filter satisfying (10) exists for every follower in normal form under Assumption 2. The zero-dynamics part of the filter is explicitly included through Fηid=Si−1ΓiSiF_ _i^d=S_i^-1 _iS_i, which can be chosen as any stable coordinate realization of the plant zero dynamics. Now, choose the nominal actuator command as ui,nom=ψi−1(Qizi+Kiri+uir),u_i,nom= _i^-1 (Q_iz_i+K_ir_i+u_i^r ), (14) where uir∈ℝmu_i^r ^m is the recovery input to be designed. Define the local embedding errors exi=xi−Πi1zi,eηi=ηi−Πi2zi.e_x_i=x_i- _i_1z_i, e_ _i= _i- _i_2z_i. (15) For compactness, set Δxi(xi,t)=ψiKaix(xi,t),d0i(t)=ψiwaiuc(t). _x_i(x_i,t)= _iK_a_i^x(x_i,t), d_0_i(t)= _iw_a_i^uc(t). Using (14), the actuator attack model (4)–(5), and the immersion identities (10), the error dynamics are e˙xi=(Ai+BiΔxi)exi+BiLieηi+BiΔuiuir+Bi(wκi+wri+d0i),e˙ηi=Γieηi+ΛiCiexi, split e_x_i=&(A_i+B_i _x_i)e_x_i+B_iL_ie_ _i+B_i _u_iu_i^r\\ &+B_i(w_ _i+w_r_i+d_0_i),\\ e_ _i=& _ie_ _i+ _iC_ie_x_i, split (16) where wκi=(ΔxiΠi1+ψiKaiuψi−1Qi)zi,wri=ψiKaiuψi−1Kiri. splitw_ _i&=( _x_i _i_1+ _iK_a_i^u _i^-1Q_i)z_i,\\ w_r_i&= _iK_a_i^u _i^-1K_ir_i. split (17) Indeed, if wai=0w_a_i=0, uir=0u_i^r=0, and the follower is initialized on the manifold xi=Πi1zix_i= _i_1z_i, ηi=Πi2zi _i= _i_2z_i, then (10) makes this manifold invariant. We next have the following lemma. Lemma 1 For each follower satisfying Assumption 2, fix any Σi=ΣiT>0 _i= _i^T>0 and 0<εai<λmin(Σi)0< _a_i< _ ( _i). Then there exists α¯i>0 α_i>0 such that, for all αi≥α¯i _i≥ α_i, the Riccati equation AiTPi+PiAi−αiPiBiBiTPi+Σi=0A_i^TP_i+P_iA_i- _iP_iB_iB_i^TP_i+ _i=0 (18) has a stabilizing solution Pi=PiT>0P_i=P_i^T>0, and there exist Ri=RiT>0R_i=R_i^T>0 and ςi>0 _i>0 such that ΓiTRi+RiΓi=−I _i^TR_i+R_i _i=-I (19) and Ξi=[Σi−εaiI−Mi−MiTςiI]>0,Mi=PiBiLi+ςiCiTΛiTRi. _i= bmatrix _i- _a_iI&-M_i\\ -M_i^T& _iI bmatrix>0, M_i=P_iB_iL_i+ _iC_i^T _i^TR_i. (20) Proof: Since (Ai,Bi)(A_i,B_i) is controllable, (18) admits a stabilizing solution Pi(αi)=PiT(αi)>0P_i( _i)=P_i^T( _i)>0 for sufficiently large αi _i. Moreover, by the cheap-control Riccati scaling for controllable normal-form chains [29], Pi(αi)Bi→0as αi→∞.P_i( _i)B_i→ 0 _i→∞. (21) Consequently, Pi(αi)BiLi→0as αi→∞.P_i( _i)B_iL_i→ 0 _i→∞. (22) Since Γi _i is Hurwitz by Assumption 2, the Lyapunov equation (19) has a unique solution Ri=RiT>0R_i=R_i^T>0. Define A0i=Σi−εaiI,Aci=PiBiLi,Bci=CiTΛiTRi.A_0_i= _i- _a_iI, A_c_i=P_iB_iL_i, B_c_i=C_i^T _i^TR_i. Then A0i>0A_0_i>0, and by (22), ai=‖Aci‖→0as αi→∞.a_i=\|A_c_i\|→ 0 _i→∞. With these definitions, Mi=Aci+ςiBciM_i=A_c_i+ _iB_c_i. By the Schur complement, Ξi>0 _i>0 is equivalent to ςiI−(Aci+ςiBci)TA0i−1(Aci+ςiBci)>0. _iI-(A_c_i+ _iB_c_i)^TA_0_i^-1(A_c_i+ _iB_c_i)>0. (23) For every ςi>0 _i>0, (Aci+ςiBci)TA0i−1(Aci+ςiBci)≤‖A0i−1‖‖Aci+ςiBci‖2I≤‖A0i−1‖(ai+ςi‖Bci‖)2I. split&(A_c_i+ _iB_c_i)^TA_0_i^-1(A_c_i+ _iB_c_i)\\ &≤\|A_0_i^-1\|\|A_c_i+ _iB_c_i\|^2I\\ &≤\|A_0_i^-1\| (a_i+ _i\|B_c_i\| )^2I. split If ai>0a_i>0, choose ςi=ai _i= a_i. Then ‖A0i−1‖(ai+ai‖Bci‖)2=O(ai)=o(ai)=o(ςi)\|A_0_i^-1\| (a_i+ a_i\|B_c_i\| )^2=O(a_i)=o( a_i)=o( _i) as αi→∞ _i→∞. Hence, for sufficiently large αi _i, the positive term ςiI _iI dominates the Schur-complement correction in (23). If ai=0a_i=0, then ‖A0i−1‖(ςi‖Bci‖)2=O(ςi2),\|A_0_i^-1\| ( _i\|B_c_i\| )^2=O( _i^2), and any sufficiently small ςi>0 _i>0 makes (23) hold. Therefore, for all sufficiently large αi _i, there exists ςi>0 _i>0 such that Ξi>0 _i>0. ∎ I-B Local Virtual-Actuator Recovery The local recovery layer is designed to ensure convergence of exie_x_i and eηie_ _i despite the admissible class of actuator attacks. Let us set si=BiTPiexi,κψi=‖ψi‖‖ψi−1‖,s_i=B_i^TP_ie_x_i, _ _i=\| _i\|\| _i^-1\|, and write ωxi=ωxi(xi,t) _x_i= _x_i(x_i,t) for compactness. Let us define the known nonnegative regressors, Ωi,1(1)=2‖ψi‖‖Πi1zi‖ωxi,Ωi,2(1)=2κψi‖Qizi‖,Ωi,3(1)=2κψi‖Kiri‖,Ωi,4(1)=2‖ψi‖,Ωi(2)=1+‖ψi‖2ωxi2. split _i,1^(1)&=2\| _i\|\| _i_1z_i\| _x_i,\\ _i,2^(1)&=2 _ _i\|Q_iz_i\|,\\ _i,3^(1)&=2 _ _i\|K_ir_i\|,\\ _i,4^(1)&=2\| _i\|,\\ _i^(2)&=1+\| _i\|^2 _x_i^2. split (24) The following lemma collects the algebraic consequences of Assumptions 5-7 in the direction of sis_i. Lemma 2 Under Assumptions 5–7, there exist unknown finite constants Θi>0 _i>0 and θi,q>0 _i,q>0, q=1,…,4q=1,…,4, such that, for all admissible trajectories and for almost all t≥0t≥ 0, 2siTΔxiexi≤εai‖exi‖2+‖ψi‖2(κxi)2εaiωxi2‖si‖2,2s_i^T _x_ie_x_i≤ _a_i\|e_x_i\|^2+ \| _i\|^2( _x^i)^2 _a_i _x_i^2\|s_i\|^2, (25) and 2siT(wκi+wri+d0i)+αi‖si‖2+‖ψi‖2(κxi)2εaiωxi2‖si‖2≤ΘiΩi(2)‖si‖2+∑q=14θi,qΩi,q(1)‖si‖. split&2s_i^T(w_ _i+w_r_i+d_0_i)+ _i\|s_i\|^2+ \| _i\|^2( _x^i)^2 _a_i _x_i^2\|s_i\|^2\\ &≤ _i _i^(2)\|s_i\|^2+ _q=1^4 _i,q _i,q^(1)\|s_i\|. split (26) Proof: By (7) and the definition Δxi=ψiKaix _x_i= _iK_a_i^x, ‖Δxi(xi,t)‖=‖ψiKaix(xi,t)‖≤‖ψi‖κxiωxi(xi,t).\| _x_i(x_i,t)\|=\| _iK_a_i^x(x_i,t)\|≤\| _i\| _x^i _x_i(x_i,t). Therefore, by Cauchy–Schwarz and Young’s inequality, 2siTΔxiexi≤2‖si‖‖Δxi‖‖exi‖≤2‖ψi‖κxiωxi‖si‖‖exi‖≤εai‖exi‖2+‖ψi‖2(κxi)2εaiωxi2‖si‖2, split2s_i^T _x_ie_x_i&≤ 2\|s_i\|\| _x_i\|\|e_x_i\|\\ &≤ 2\| _i\| _x^i _x_i\|s_i\|\|e_x_i\|\\ &≤ _a_i\|e_x_i\|^2+ \| _i\|^2( _x^i)^2 _a_i _x_i^2\|s_i\|^2, split which proves (25). Next, using (17), the first component of wκiw_ _i satisfies 2siTΔxiΠi1zi≤2‖si‖‖Δxi‖‖Πi1zi‖≤2‖si‖‖ψi‖κxiωxi‖Πi1zi‖=κxiΩi,1(1)‖si‖. split2s_i^T _x_i _i_1z_i&≤ 2\|s_i\|\| _x_i\|\| _i_1z_i\|\\ &≤ 2\|s_i\|\| _i\| _x^i _x_i\| _i_1z_i\|\\ &= _x^i _i,1^(1)\|s_i\|. split By Assumption 6, ‖Kaiu(t)‖≤kui¯.\|K_a_i^u(t)\|≤ k_u^i. Hence the second component of wκiw_ _i satisfies 2siTψiKaiuψi−1Qizi≤2‖si‖‖ψi‖‖Kaiu‖‖ψi−1‖‖Qizi‖≤kui¯Ωi,2(1)‖si‖. split2s_i^T _iK_a_i^u _i^-1Q_iz_i&≤ 2\|s_i\|\| _i\|\|K_a_i^u\|\| _i^-1\|\|Q_iz_i\|\\ &≤ k_u^i _i,2^(1)\|s_i\|. split Similarly, the rir_i-dependent input-correlated term satisfies 2siTψiKaiuψi−1Kiri≤2‖si‖‖ψi‖‖Kaiu‖‖ψi−1‖‖Kiri‖≤kui¯Ωi,3(1)‖si‖. split2s_i^T _iK_a_i^u _i^-1K_ir_i&≤ 2\|s_i\|\| _i\|\|K_a_i^u\|\| _i^-1\|\|K_ir_i\|\\ &≤ k_u^i _i,3^(1)\|s_i\|. split Finally, by Assumption 7, ‖waiuc(t)‖≤kwi,\|w_a_i^uc(t)\|≤ k_w^i, and therefore 2siTd0i=2siTψiwaiuc≤2‖si‖‖ψi‖kwi=kwiΩi,4(1)‖si‖.2s_i^Td_0_i=2s_i^T _iw_a_i^uc≤ 2\|s_i\|\| _i\|k_w^i=k_w^i _i,4^(1)\|s_i\|. Combining these bounds gives 2siT(wκi+wri+d0i)≤∑q=14θi,qΩi,q(1)‖si‖,2s_i^T(w_ _i+w_r_i+d_0_i)≤ _q=1^4 _i,q _i,q^(1)\|s_i\|, where one admissible choice is θi,1=κxi,θi,2=kui¯,θi,3=kui¯,θi,4=kwi. _i,1= _x^i, _i,2= k_u^i, _i,3= k_u^i, _i,4=k_w^i. It remains to combine the purely quadratic terms. Since Ωi(2)=1+‖ψi‖2ωxi2, _i^(2)=1+\| _i\|^2 _x_i^2, we have αi‖si‖2+‖ψi‖2(κxi)2εaiωxi2‖si‖2≤ΘiΩi(2)‖si‖2 _i\|s_i\|^2+ \| _i\|^2( _x^i)^2 _a_i _x_i^2\|s_i\|^2≤ _i _i^(2)\|s_i\|^2 for any finite constant satisfying Θi≥maxαi,(κxi)2εai. _i≥ \ _i, ( _x^i)^2 _a_i \. Adding the linear and quadratic bounds proves (26) and completes the proof of lemma. ∎ Consider now the continuous virtual-actuator law, uir=−∑q=14βi,q2(Ωi,q(1))2siβi,qΩi,q(1)‖si‖+μi(t)−12ρiΩi(2)si,β˙i,q=−bβi,qμi(t)βi,q+bβi,qΩi,q(1)‖si‖,q=1,…,4,ρ˙i=−bρiμi(t)ρi+bρiΩi(2)‖si‖2, casesu_i^r=- _q=1^4 _i,q^2( _i,q^(1))^2s_i _i,q _i,q^(1)\|s_i\|+ _i(t)- 12 _i _i^(2)s_i,\\[8.53581pt] β_i,q=-b_β i,q _i(t) _i,q+b_β i,q _i,q^(1)\|s_i\|, q=1,…,4,\\[2.84526pt] ρ_i=-b_ρ i _i(t) _i+b_ρ i _i^(2)\|s_i\|^2, cases (27) where βi,q(0)>0 _i,q(0)>0, ρi(0)>0 _i(0)>0, bβi,q>0b_β i,q>0, bρi>0b_ρ i>0, and μi:[0,∞)→(0,∞) _i:[0,∞)→(0,∞) is continuous and satisfies μi∈L1[0,∞) _i∈ L_1[0,∞). Theorem 1 Under Assumptions 2, 3, and 5–7, let the local command filter be admissible. Choose PiP_i, RiR_i, and ςi _i as in Lemma 1 with αi≥α¯i _i≥ α_i. If ri∈C([0,∞),ℝm)∩L∞[0,∞),r_i∈ C([0,∞),R^m)∩ L_∞[0,∞), then, for every initial condition satisfying βi,q(0)>0 _i,q(0)>0 and ρi(0)>0 _i(0)>0, the local closed-loop system (9), (16), and (27) has a unique complete Carathéodory solution. All local signals are bounded, uiru_i^r is continuous along the system trajectory, and limt→∞exi(t)=0,limt→∞eηi(t)=0. _t→∞e_x_i(t)=0, _t→∞e_ _i(t)=0. (28) Proof: Consider the comparison inequalities for q=1,…,4q=1,…,4 β˙i,q=−bβi,qμi(t)βi,q+bβi,qΩi,q(1)‖si‖≥−bβi,qμi(t)βi,q, β_i,q=-b_β i,q _i(t) _i,q+b_β i,q _i,q^(1)\|s_i\|≥-b_β i,q _i(t) _i,q, and ρ˙i=−bρiμi(t)ρi+bρiΩi(2)‖si‖2≥−bρiμi(t)ρi. ρ_i=-b_ρ i _i(t) _i+b_ρ i _i^(2)\|s_i\|^2≥-b_ρ i _i(t) _i. With positive initial conditions, these inequalities imply that βi,q(t)>0,ρi(t)>0 _i,q(t)>0, _i(t)>0 on every finite interval on which the solution exists. Hence, the denominators in (27) are strictly positive. Since rir_i and μi _i are continuous, and since KaixK_a_i^x satisfies the Carathéodory and local Lipschitz conditions in Assumption 5, the augmented local closed-loop dynamics have a unique maximal Carathéodory solution on some interval [0,Tmax)[0,T_ ). Because FiF_i is Hurwitz and ri∈L∞[0,∞)r_i∈ L_∞[0,∞), the command filter (9) satisfies zi∈L∞[0,Tmax)z_i∈ L_∞[0,T_ ) on every maximal finite interval. Define ζi=col(exi,eηi) _i=col(e_x_i,e_ _i) and consider V0i=exiTPiexi+ςieηiTRieηi.V_0_i=e_x_i^TP_ie_x_i+ _ie_ _i^TR_ie_ _i. (29) Since Pi=PiT>0P_i=P_i^T>0, Ri=RiT>0R_i=R_i^T>0, and ςi>0 _i>0, V0iV_0_i is positive definite in ζi _i. Differentiating V0iV_0_i along (16) gives, for almost all t∈[0,Tmax)t∈[0,T_ ), V˙0i=exiT(AiTPi+PiAi)exi+2exiTPiBiLieηi+2siTΔxiexi+2siTΔuiuir+2siTwκi+2siTwri+2siTd0i+ςieηiT(ΓiTRi+RiΓi)eηi+2ςieηiTRiΛiCiexi. split V_0_i=&e_x_i^T(A_i^TP_i+P_iA_i)e_x_i+2e_x_i^TP_iB_iL_ie_ _i\\ &+2s_i^T _x_ie_x_i+2s_i^T _u_iu_i^r\\ &+2s_i^Tw_ _i+2s_i^Tw_r_i+2s_i^Td_0_i\\ &+ _ie_ _i^T( _i^TR_i+R_i _i)e_ _i+2 _ie_ _i^TR_i _iC_ie_x_i. split (30) Using (18), AiTPi+PiAi=−Σi+αiPiBiBiTPi,A_i^TP_i+P_iA_i=- _i+ _iP_iB_iB_i^TP_i, and using si=BiTPiexis_i=B_i^TP_ie_x_i, we obtain exiT(AiTPi+PiAi)exi=−exiTΣiexi+αi‖si‖2.e_x_i^T(A_i^TP_i+P_iA_i)e_x_i=-e_x_i^T _ie_x_i+ _i\|s_i\|^2. (31) Moreover, by (19), ςieηiT(ΓiTRi+RiΓi)eηi=−ςi‖eηi‖2, _ie_ _i^T( _i^TR_i+R_i _i)e_ _i=- _i\|e_ _i\|^2, (32) and 2exiTPiBiLieηi+2ςieηiTRiΛiCiexi=2exiT(PiBiLi+ςiCiTΛiTRi)eηi=2exiTMieηi. split&2e_x_i^TP_iB_iL_ie_ _i+2 _ie_ _i^TR_i _iC_ie_x_i\\ &=2e_x_i^T (P_iB_iL_i+ _iC_i^T _i^TR_i )e_ _i=2e_x_i^TM_ie_ _i. split (33) Substituting (31)–(33) into (30) gives V˙0i=−exiTΣiexi+2exiTMieηi−ςi‖eηi‖2+αi‖si‖2+2siTΔxiexi+2siTΔuiuir+2siT(wκi+wri+d0i). split V_0_i=&-e_x_i^T _ie_x_i+2e_x_i^TM_ie_ _i- _i\|e_ _i\|^2\\ &+ _i\|s_i\|^2+2s_i^T _x_ie_x_i+2s_i^T _u_iu_i^r\\ &+2s_i^T(w_ _i+w_r_i+d_0_i). split (34) By Lemma 2, 2siTΔxiexi≤εai‖exi‖2+‖ψi‖2(κxi)2εaiωxi2‖si‖2.2s_i^T _x_ie_x_i≤ _a_i\|e_x_i\|^2+ \| _i\|^2( _x^i)^2 _a_i _x_i^2\|s_i\|^2. Using this inequality and (20), we obtain −exiTΣiexi+2exiTMieηi−ςi‖eηi‖2+εai‖exi‖2=−ζiT[Σi−εaiI−Mi−MiTςiI]ζi=−ζiTΞiζi≤−ci‖ζi‖2, split&-e_x_i^T _ie_x_i+2e_x_i^TM_ie_ _i- _i\|e_ _i\|^2+ _a_i\|e_x_i\|^2\\ &=- _i^T bmatrix _i- _a_iI&-M_i\\ -M_i^T& _iI bmatrix _i=- _i^T _i _i≤-c_i\| _i\|^2, split (35) where ci=λmin(Ξi)>0.c_i= _ ( _i)>0. Combining (34), (35), and the envelope inequality (26) in Lemma 2, we get V˙0i≤−ci‖ζi‖2+2siTΔuiuir+ΘiΩi(2)‖si‖2+∑q=14θi,qΩi,q(1)‖si‖. V_0_i≤-c_i\| _i\|^2+2s_i^T _u_iu_i^r+ _i _i^(2)\|s_i\|^2+ _q=1^4 _i,q _i,q^(1)\|s_i\|. (36) Choose proof constants βi,q∗>0 _i,q^*>0, q=1,…,4q=1,…,4, and ρi∗>0 _i^*>0 such that χiβi,q∗≥θi,q,χiρi∗≥Θi. _i _i,q^*≥ _i,q, _i _i^*≥ _i. (37) Let us define Vai=∑q=14χi2bβi,q(βi,q−βi,q∗)2+χi2bρi(ρi−ρi∗)2V_a_i= _q=1^4 _i2b_β i,q( _i,q- _i,q^*)^2+ _i2b_ρ i( _i- _i^*)^2 (38) and i=V0i+Vai.V_i=V_0_i+V_a_i. (39) By Assumption 6, siTΔui(t)si≥χi‖si‖2.s_i^T _u_i(t)s_i≥ _i\|s_i\|^2. (40) Using (27), the control-port term satisfies 2siTΔuiuir=−2∑q=14βi,q2(Ωi,q(1))2βi,qΩi,q(1)‖si‖+μi(t)siTΔuisi−ρiΩi(2)siTΔuisi≤−2χi∑q=14βi,q2(Ωi,q(1))2‖si‖2βi,qΩi,q(1)‖si‖+μi(t)−χiρiΩi(2)‖si‖2. split2s_i^T _u_iu_i^r=&-2 _q=1^4 _i,q^2( _i,q^(1))^2 _i,q _i,q^(1)\|s_i\|+ _i(t)s_i^T _u_is_i\\ &- _i _i^(2)s_i^T _u_is_i\\ ≤&-2 _i _q=1^4 _i,q^2( _i,q^(1))^2\|s_i\|^2 _i,q _i,q^(1)\|s_i\|+ _i(t)\\ &- _i _i _i^(2)\|s_i\|^2. split (41) Differentiating VaiV_a_i along the adaptive laws in (27) gives V˙ai=∑q=14χi(βi,q−βi,q∗)(−μiβi,q+Ωi,q(1)‖si‖)+χi(ρi−ρi∗)(−μiρi+Ωi(2)‖si‖2). split V_a_i=& _q=1^4 _i( _i,q- _i,q^*) (- _i _i,q+ _i,q^(1)\|s_i\| )\\ &+ _i( _i- _i^*) (- _i _i+ _i^(2)\|s_i\|^2 ). split (42) Combining (36), (41), and (42), we obtain ˙i≤−ci‖ζi‖2+ΘiΩi(2)‖si‖2−χiρiΩi(2)‖si‖2+χi(ρi−ρi∗)Ωi(2)‖si‖2−χiμi(ρi−ρi∗)ρi+∑q=14[θi,qΩi,q(1)∥si∥−2χiβi,q2(Ωi,q(1))2‖si‖2βi,qΩi,q(1)‖si‖+μi+χi(βi,q−βi,q∗)Ωi,q(1)∥si∥−χiμi(βi,q−βi,q∗)βi,q]. split V_i≤&-c_i\| _i\|^2\\ &+ _i _i^(2)\|s_i\|^2- _i _i _i^(2)\|s_i\|^2+ _i( _i- _i^*) _i^(2)\|s_i\|^2\\ &- _i _i( _i- _i^*) _i\\ &+ _q=1^4 [ _i,q _i,q^(1)\|s_i\|-2 _i _i,q^2( _i,q^(1))^2\|s_i\|^2 _i,q _i,q^(1)\|s_i\|+ _i\\ &+ _i( _i,q- _i,q^*) _i,q^(1)\|s_i\|- _i _i( _i,q- _i,q^*) _i,q ]. split (43) The quadratic terms satisfy ΘiΩi(2)‖si‖2−χiρiΩi(2)‖si‖2+χi(ρi−ρi∗)Ωi(2)‖si‖2=(Θi−χiρi∗)Ωi(2)‖si‖2≤0, split& _i _i^(2)\|s_i\|^2- _i _i _i^(2)\|s_i\|^2+ _i( _i- _i^*) _i^(2)\|s_i\|^2\\ &= ( _i- _i _i^* ) _i^(2)\|s_i\|^2≤ 0, split (44) where the last inequality follows from χiρi∗≥Θi _i _i^*≥ _i. The leakage term generated by the ρi _i-adaptation satisfies −χiμi(ρi−ρi∗)ρi=−χiμiρi2+χiμiρi∗ρi=−χiμi(ρi−ρi∗2)2+χi(ρi∗)24μi≤χi(ρi∗)24μi. split- _i _i( _i- _i^*) _i&=- _i _i _i^2+ _i _i _i^* _i\\ &=- _i _i ( _i- _i^*2 )^2+ _i( _i^*)^24 _i\\ &≤ _i( _i^*)^24 _i. split (45) Next, fix any q∈1,…,4q∈\1,…,4\ and consider the corresponding βi,q _i,q-dependent terms. First, θi,qΩi,q(1)‖si‖−2χiβi,q2(Ωi,q(1))2‖si‖2βi,qΩi,q(1)‖si‖+μi+χi(βi,q−βi,q∗)Ωi,q(1)‖si‖=(θi,q−χiβi,q∗)Ωi,q(1)‖si‖+χiβi,qΩi,q(1)‖si‖−2χiβi,q2(Ωi,q(1))2‖si‖2βi,qΩi,q(1)‖si‖+μi≤χiβi,qΩi,q(1)‖si‖−2χiβi,q2(Ωi,q(1))2‖si‖2βi,qΩi,q(1)‖si‖+μi, split& _i,q _i,q^(1)\|s_i\|-2 _i _i,q^2( _i,q^(1))^2\|s_i\|^2 _i,q _i,q^(1)\|s_i\|+ _i\\ & + _i( _i,q- _i,q^*) _i,q^(1)\|s_i\|\\ &=( _i,q- _i _i,q^*) _i,q^(1)\|s_i\|+ _i _i,q _i,q^(1)\|s_i\|\\ & -2 _i _i,q^2( _i,q^(1))^2\|s_i\|^2 _i,q _i,q^(1)\|s_i\|+ _i\\ &≤ _i _i,q _i,q^(1)\|s_i\|-2 _i _i,q^2( _i,q^(1))^2\|s_i\|^2 _i,q _i,q^(1)\|s_i\|+ _i, split (46) because θi,q−χiβi,q∗≤0 _i,q- _i _i,q^*≤ 0. Define xi,q(t)=βi,q(t)Ωi,q(1)(t)‖si(t)‖.x_i,q(t)= _i,q(t) _i,q^(1)(t)\|s_i(t)\|. (47) Since βi,q(t)>0 _i,q(t)>0, Ωi,q(1)(t)≥0 _i,q^(1)(t)≥ 0, and ‖si(t)‖≥0\|s_i(t)\|≥ 0, we have xi,q(t)≥0x_i,q(t)≥ 0. Therefore, xi,q−2xi,q2xi,q+μi=xi,q(μi−xi,q)xi,q+μi≤μi.x_i,q- 2x_i,q^2x_i,q+ _i= x_i,q( _i-x_i,q)x_i,q+ _i≤ _i. (48) Indeed, if xi,q≥μix_i,q≥ _i, then the left-hand side is nonpositive; if 0≤xi,q<μi0≤ x_i,q< _i, then xi,q(μi−xi,q)/(xi,q+μi)≤μix_i,q( _i-x_i,q)/(x_i,q+ _i)≤ _i. Hence (46) gives θi,qΩi,q(1)‖si‖−2χiβi,q2(Ωi,q(1))2‖si‖2βi,qΩi,q(1)‖si‖+μi+χi(βi,q−βi,q∗)Ωi,q(1)‖si‖≤χiμi. split& _i,q _i,q^(1)\|s_i\|-2 _i _i,q^2( _i,q^(1))^2\|s_i\|^2 _i,q _i,q^(1)\|s_i\|+ _i\\ & + _i( _i,q- _i,q^*) _i,q^(1)\|s_i\|≤ _i _i. split (49) The leakage term generated by the βi,q _i,q-adaptation satisfies −χiμi(βi,q−βi,q∗)βi,q=−χiμiβi,q2+χiμiβi,q∗βi,q=−χiμi(βi,q−βi,q∗2)2+χi(βi,q∗)24μi≤χi(βi,q∗)24μi. split- _i _i( _i,q- _i,q^*) _i,q&=- _i _i _i,q^2+ _i _i _i,q^* _i,q\\ &=- _i _i ( _i,q- _i,q^*2 )^2+ _i( _i,q^*)^24 _i\\ &≤ _i( _i,q^*)^24 _i. split (50) Substituting (44)–(50) into (43), we obtain ˙i≤−ci‖ζi‖2+iμi(t) V_i≤-c_i\| _i\|^2+C_i _i(t) (51) for almost all t∈[0,Tmax)t∈[0,T_ ), where the finite constant i=4χi+χi4∑q=14(βi,q∗)2+χi(ρi∗)24C_i=4 _i+ _i4 _q=1^4( _i,q^*)^2+ _i( _i^*)^24 (52) depends only on proof constants and unknown attack bounds, not on time. Since μi∈L1[0,∞) _i∈ L_1[0,∞), integration of (51) over [0,t]⊂[0,Tmax)[0,t]⊂[0,T_ ) gives i(t)+ci∫0t‖ζi(τ)‖2τ≤i(0)+i∫0∞μi(τ)τ.V_i(t)+c_i _0^t\| _i(τ)\|^2dτ _i(0)+C_i _0^∞ _i(τ)dτ. (53) Therefore, i∈L∞[0,Tmax),ζi∈L2[0,Tmax)∩L∞[0,Tmax),V_i∈ L_∞[0,T_ ), _i∈ L_2[0,T_ )∩ L_∞[0,T_ ), (54) and βi,q∈L∞[0,Tmax),ρi∈L∞[0,Tmax). _i,q∈ L_∞[0,T_ ), _i∈ L_∞[0,T_ ). (55) Since zi∈L∞[0,Tmax)z_i∈ L_∞[0,T_ ), the relation xi=exi+Πi1zix_i=e_x_i+ _i_1z_i implies xi∈L∞[0,Tmax).x_i∈ L_∞[0,T_ ). (56) By Assumption 5, ωxi(xi,t) _x_i(x_i,t) is bounded on bounded xix_i-sets uniformly in time. Hence ωxi(xi,t)∈L∞[0,Tmax). _x_i(x_i,t)∈ L_∞[0,T_ ). (57) Using (24), together with zi∈L∞z_i∈ L_∞, ri∈L∞r_i∈ L_∞, and (57), we obtain Ωi,q(1)∈L∞[0,Tmax),Ωi(2)∈L∞[0,Tmax),q=1,…,4. _i,q^(1)∈ L_∞[0,T_ ), _i^(2)∈ L_∞[0,T_ ), q=1,…,4. (58) Furthermore, for each q, βi,q2(Ωi,q(1))2‖si‖βi,qΩi,q(1)‖si‖+μi(t)≤βi,qΩi,q(1). _i,q^2( _i,q^(1))^2\|s_i\| _i,q _i,q^(1)\|s_i\|+ _i(t)≤ _i,q _i,q^(1). (59) Indeed, if si=0s_i=0, the left-hand side is zero; otherwise the denominator is at least βi,qΩi,q(1)‖si‖ _i,q _i,q^(1)\|s_i\|. Therefore, by (27), (55), and (58), uir∈L∞[0,Tmax).u_i^r∈ L_∞[0,T_ ). (60) From (14), and using zi,ri,uir∈L∞[0,Tmax)z_i,r_i,u_i^r∈ L_∞[0,T_ ), we get ui,nom∈L∞[0,Tmax).u_i,nom∈ L_∞[0,T_ ). (61) Assumptions 6 and 7, together with (56), (57), and (61), imply that Δxi(xi,t),Δui(t),d0i(t),wκi,wri _x_i(x_i,t), _u_i(t), d_0_i(t), w_ _i, w_r_i are bounded along the solution. Therefore the right-hand side of (16) is bounded on every bounded time interval contained in [0,Tmax)[0,T_ ). Also, the adaptive right-hand sides in (27) are bounded on every such interval because μi _i is continuous and the involved signals are bounded. Consequently, the maximal solution cannot escape to infinity in finite time. Since βi,q(t) _i,q(t) and ρi(t) _i(t) remain strictly positive, the solution also cannot leave the domain on which (27) is well defined. Hence Tmax=∞.T_ =∞. From (16), write ζ˙i=[(Ai+BiΔxi)exi+BiLieηi+BiΔuiuir+Bi(wκi+wri+d0i)Γieηi+ΛiCiexi]. ζ_i= bmatrix(A_i+B_i _x_i)e_x_i+B_iL_ie_ _i+B_i _u_iu_i^r+B_i(w_ _i+w_r_i+d_0_i)\\ _ie_ _i+ _iC_ie_x_i bmatrix. All terms on the right-hand side are bounded along the complete solution. Hence ζ˙i∈L∞[0,∞). ζ_i∈ L_∞[0,∞). (62) From (53), we also have ζi∈L2[0,∞). _i∈ L_2[0,∞). Applying Barbalat’s lemma gives limt→∞ζi(t)=0. _t→∞ _i(t)=0. Therefore, limt→∞exi(t)=0,limt→∞eηi(t)=0. _t→∞e_x_i(t)=0, _t→∞e_ _i(t)=0. Finally, all local signals are bounded. Indeed, ziz_i, exie_x_i, and eηie_ _i are bounded; hence xi=exi+Πi1zix_i=e_x_i+ _i_1z_i and ηi=eηi+Πi2zi _i=e_ _i+ _i_2z_i are bounded. The signals βi,q _i,q, ρi _i, Ωi,q(1) _i,q^(1), Ωi(2) _i^(2), uiru_i^r, and ui,nomu_i,nom are bounded by the preceding arguments. The proof is complete. ∎ I-C Network Interface and Command Containment For each follower i∈ℱi , consider the network-interface protocol ϑi=∑j∈ℱaij(σi−σj)+∑ℓ∈aiℓ(σi−ϕℓ),γ˙i=−bγiϖi(t)γi+bγi‖ϑi‖,σ˙i=−ϑi−γi2ϑiγi‖ϑi‖+ϖi(t), cases _i= _j a_ij( _i- _j)+ _ a_i ( _i- _ ),\\[5.69054pt] γ_i=-b_γ i _i(t) _i+b_γ i\| _i\|,\\[2.84526pt] σ_i=- _i- _i^2 _i _i\| _i\|+ _i(t), cases (63) where γi(0)>0 _i(0)>0, bγi>0b_γ i>0, and ϖi:[0,∞)→(0,∞) _i:[0,∞)→(0,∞) is continuous and satisfies ϖi∈L1[0,∞) _i∈ L_1[0,∞). Theorem 2 Under Assumptions 1 and 4, the protocol (63) admits a unique complete Carathéodory solution for every initial condition with γi(0)>0 _i(0)>0. Moreover, σi(t) _i(t) is bounded and limt→∞dist(σi(t),co(ΦL(t)))=0,i∈ℱ. _t→∞dist ( _i(t),co( _L(t)) )=0, i . (64) Proof: We first establish well-posedness and positivity of the adaptive gains. Let σ=col(σ1,…,σM),γ=col(γ1,…,γM),σ=col( _1,…, _M), γ=col( _1,…, _M), and define the open domain =ℝMm×(0,∞)M.D=R^Mm×(0,∞)^M. For each fixed t, the right-hand side of (63) is continuous in (σ,γ)∈(σ,γ) . Since ϖi(t)>0 _i(t)>0 and is continuous, the map (σ,γ)↦γi2ϑiγi‖ϑi‖+ϖi(t)(σ,γ) _i^2 _i _i\| _i\|+ _i(t) is locally Lipschitz on compact subsets of D, uniformly on finite time intervals. Moreover, Assumption 4 implies that the leader signals are locally absolutely continuous and locally bounded on finite intervals. Hence the right-hand side of (63) satisfies the Carathéodory conditions and is locally Lipschitz in the state on compact subsets of D. Therefore, for every initial condition σ(0)∈ℝMmσ(0) ^Mm, γi(0)>0 _i(0)>0, there exists a unique maximal Carathéodory solution on an interval [0,Tmax)[0,T_ ). Along a solution, the gain equation can be written as γ˙i+bγiϖi(t)γi=bγi‖ϑi‖. γ_i+b_γ i _i(t) _i=b_γ i\| _i\|. The variation-of-constants formula gives, for 0≤t<Tmax0≤ t<T_ , γi(t)=e−bγi∫0tϖi(s)sγi(0)+bγi∫0te−bγi∫stϖi(r)r‖ϑi(s)‖s. split _i(t)=&e^-b_γ i _0^t _i(s)ds _i(0)\\ &+b_γ i _0^te^-b_γ i _s^t _i(r)dr\| _i(s)\|ds. split (65) Both terms on the right-hand side are nonnegative, and the first one is strictly positive. Thus γi(t)>0,0≤t<Tmax. _i(t)>0, 0≤ t<T_ . (66) This proves that the solution cannot leave D through γi=0 _i=0. Next define Φ=col(ϕ1,…,ϕN),ϑ=col(ϑ1,…,ϑM). =col( _1,…, _N), =col( _1,…, _M). From the graph partition, ϑ=(HF⊗Im)σ+(LFL⊗Im)Φ. =(H_F I_m)σ+(L_FL I_m) . (67) Let p=HF−TM.p=H_F^-T1_M. Under Assumption 1, HFH_F is a nonsingular M-matrix. Hence pi>0,pTHF=MT.p_i>0, p^TH_F=1_M^T. (68) Define gΦ(t)=(LFL⊗Im)Φ˙(t).g_ (t)=(L_FL I_m) (t). Assumption 4 gives gΦ∈L∞[0,∞)g_ ∈ L_∞[0,∞). Also define υi=γi2ϑiγi‖ϑi‖+ϖi(t),υ=col(υ1,…,υM). _i= _i^2 _i _i\| _i\|+ _i(t), =col( _1,…, _M). (69) Differentiating (67) along (63) gives, for almost all t, ϑ˙=−(HF⊗Im)ϑ−(HF⊗Im)υ+gΦ(t). =-(H_F I_m) -(H_F I_m) +g_ (t). (70) Consider the nonsmooth gauge J(ϑ)=∑i=1Mpi‖ϑi‖.J( )= _i=1^Mp_i\| _i\|. (71) The function J is locally Lipschitz. Since ϑ is absolutely continuous on every finite interval, ϑ˙(t) (t) exists for almost all t. For such t, the upper Dini derivative of the Euclidean norm satisfies D+‖ϑi(t)‖=maxξi∈∂‖ϑi(t)‖ξiTϑ˙i(t),D^+\| _i(t)\|= _ _i∈∂\| _i(t)\| _i^T _i(t), where ∂‖ϑi‖=ϑi‖ϑi‖,ϑi≠0,ξ∈ℝm:‖ξ‖≤1,ϑi=0.∂\| _i\|= cases \ _i\| _i\| \,& _i≠ 0,\\[5.69054pt] \ξ ^m:\|ξ\|≤ 1\,& _i=0. cases Choose ξi(t)∈∂‖ϑi(t)‖ _i(t)∈∂\| _i(t)\| to attain the maximum. Then ‖ξi(t)‖≤1,ξiT(t)ϑi(t)=‖ϑi(t)‖,\| _i(t)\|≤ 1, _i^T(t) _i(t)=\| _i(t)\|, and D+J(ϑ(t))=∑i=1MpiξiT(t)ϑ˙i(t)D^+J( (t))= _i=1^Mp_i _i^T(t) _i(t) (72) for almost all t. We now estimate the three terms in (70). First, since HFH_F is an M-matrix, its off-diagonal entries satisfy (HF)ij≤0(H_F)_ij≤ 0 for i≠ji≠ j. Therefore, for each j, ∑i=1Mpi(HF)ij=1 _i=1^Mp_i(H_F)_ij=1 by (68). By construction, ξjTϑj=‖ϑj‖ _j^T _j=\| _j\| for all j, including the case ϑj=0 _j=0, and ξiTϑj≤‖ϑj‖ _i^T _j≤\| _j\| for all i,ji,j. Hence, ∑i=1MpiξiT[−(HFϑ)i]=−∑i=1M∑j=1Mpi(HF)ijξiTϑj=−∑j=1Mpj(HF)jjξjTϑj−∑j=1M∑i=1i≠jMpi(HF)ijξiTϑj≤−∑j=1Mpj(HF)jj‖ϑj‖+∑j=1M∑i=1i≠jMpi[−(HF)ij]‖ϑj‖=−∑j=1M(pj(HF)jj+∑i=1i≠jMpi(HF)ij)‖ϑj‖=−∑j=1M‖ϑj‖. split& _i=1^Mp_i _i^T[-(H_F )_i]=- _i=1^M _j=1^Mp_i(H_F)_ij _i^T _j\\ &=- _j=1^Mp_j(H_F)_j _j^T _j- _j=1^M _ subarrayci=1\\ i≠ j subarray^Mp_i(H_F)_ij _i^T _j\\ &≤- _j=1^Mp_j(H_F)_j\| _j\|+ _j=1^M _ subarrayci=1\\ i≠ j subarray^Mp_i[-(H_F)_ij]\| _j\|\\ &=- _j=1^M (p_j(H_F)_j+ _ subarrayci=1\\ i≠ j subarray^Mp_i(H_F)_ij )\| _j\|\\ &=- _j=1^M\| _j\|. split (73) Second, define δj=γj2‖ϑj‖γj‖ϑj‖+ϖj(t),ϑj≠0,0,ϑj=0. _j= cases _j^2\| _j\| _j\| _j\|+ _j(t),& _j≠ 0,\\[8.53581pt] 0,& _j=0. cases (74) Then δj=‖υj‖ _j=\| _j\|, and if ϑj≠0 _j≠ 0, υj=δjξj _j= _j _j. Repeating the same M-matrix column argument gives ∑i=1MpiξiT[−(HFυ)i]≤−∑j=1Mδj. _i=1^Mp_i _i^T[-(H_F )_i]≤- _j=1^M _j. (75) Third, define GΦ=esssupt≥0∑i=1Mpi‖gΦi(t)‖<∞.G_ = *ess\,sup_t≥ 0 _i=1^Mp_i\|g_ i(t)\|<∞. (76) Then ∑i=1MpiξiTgΦi(t)≤∑i=1Mpi‖gΦi(t)‖≤GΦ _i=1^Mp_i _i^Tg_ i(t)≤ _i=1^Mp_i\|g_ i(t)\|≤ G_ (77) for almost all t. Combining (70)–(77), we obtain D+J≤−∑i=1M‖ϑi‖−∑i=1Mδi+GΦ.D^+J≤- _i=1^M\| _i\|- _i=1^M _i+G_ . (78) Since J=∑i=1Mpi‖ϑi‖≤pmax∑i=1M‖ϑi‖,pmax=maxipi,J= _i=1^Mp_i\| _i\|≤ p_ _i=1^M\| _i\|, p_ = _ip_i, we have ∑i=1M‖ϑi‖≥1pmaxJ. _i=1^M\| _i\|≥ 1p_ J. Let c0=1pmax>0.c_0= 1p_ >0. (79) Then D+J≤−c0J−∑i=1Mδi+GΦ.D^+J≤-c_0J- _i=1^M _i+G_ . (80) Set γ⋆=GΦ+1γ =G_ +1 (81) and define W=12J2+∑i=1Mpi2bγi(γi−γ⋆)2.W= 12J^2+ _i=1^M p_i2b_γ i( _i-γ )^2. (82) Using (80) and the adaptive law for γi _i, D+W=JD+J+∑i=1Mpi(γi−γ⋆)(−ϖi(t)γi+‖ϑi‖)≤−c0J2−J∑i=1Mδi+GΦJ+∑i=1Mpiγi‖ϑi‖−γ⋆∑i=1Mpi‖ϑi‖−∑i=1Mpiϖi(t)(γi−γ⋆)γi. splitD^+W&=JD^+J+ _i=1^Mp_i( _i-γ ) (- _i(t) _i+\| _i\| )\\ &≤-c_0J^2-J _i=1^M _i+G_ J\\ & + _i=1^Mp_i _i\| _i\|-γ _i=1^Mp_i\| _i\|\\ & - _i=1^Mp_i _i(t)( _i-γ ) _i. split (83) Since J=∑ipi‖ϑi‖J= _ip_i\| _i\|, the leader-bound term and the ideal gain term combine as GΦJ−γ⋆∑i=1Mpi‖ϑi‖=−(γ⋆−GΦ)J=−J.G_ J-γ _i=1^Mp_i\| _i\|=-(γ -G_ )J=-J. Thus D+W≤−c0J2−J−J∑i=1Mδi+∑i=1Mpiγi‖ϑi‖−∑i=1Mpiϖi(t)(γi−γ⋆)γi. splitD^+W≤&-c_0J^2-J-J _i=1^M _i+ _i=1^Mp_i _i\| _i\|\\ &- _i=1^Mp_i _i(t)( _i-γ ) _i. split (84) Since J≥pi‖ϑi‖J≥ p_i\| _i\| and δi≥0 _i≥ 0, −J∑i=1Mδi≤−∑i=1Mpi‖ϑi‖δi.-J _i=1^M _i≤- _i=1^Mp_i\| _i\| _i. (85) Moreover, by the definition of δi _i, ‖ϑi‖(γi−δi)=‖ϑi‖(γi−γi2‖ϑi‖γi‖ϑi‖+ϖi(t))=γi‖ϑi‖ϖi(t)γi‖ϑi‖+ϖi(t)≤ϖi(t). split\| _i\|( _i- _i)&=\| _i\| ( _i- _i^2\| _i\| _i\| _i\|+ _i(t) )\\ &= _i\| _i\| _i(t) _i\| _i\|+ _i(t)≤ _i(t). split (86) Using (85) and (86), −J∑i=1Mδi+∑i=1Mpiγi‖ϑi‖≤∑i=1Mpiϖi(t).-J _i=1^M _i+ _i=1^Mp_i _i\| _i\|≤ _i=1^Mp_i _i(t). (87) Finally, −ϖi(t)(γi−γ⋆)γi≤(γ⋆)24ϖi(t),- _i(t)( _i-γ ) _i≤ (γ )^24 _i(t), (88) because −(γi−γ⋆)γi=−(γi−γ⋆2)2+(γ⋆)24≤(γ⋆)24.-( _i-γ ) _i=- ( _i- γ 2 )^2+ (γ )^24≤ (γ )^24. Combining (84)–(88), we obtain D+W≤−c0J2−J+CN∑i=1Mpiϖi(t),CN=1+(γ⋆)24.D^+W≤-c_0J^2-J+C_N _i=1^Mp_i _i(t), C_N=1+ (γ )^24. (89) Since ϖi∈L1[0,∞) _i∈ L_1[0,∞), integration of (89) gives W(t)+c0∫0tJ2(τ)τ+∫0tJ(τ)τ≤W(0)+CN∑i=1Mpi∫0∞ϖi(τ)τ. split&W(t)+c_0 _0^tJ^2(τ)dτ+ _0^tJ(τ)dτ\\ &≤ W(0)+C_N _i=1^Mp_i _0^∞ _i(τ)dτ. split (90) Hence W∈L∞,J∈L1[0,∞)∩L2[0,∞),γi∈L∞[0,∞).W∈ L_∞, J∈ L_1[0,∞)∩ L_2[0,∞), _i∈ L_∞[0,∞). Since J=∑ipi‖ϑi‖J= _ip_i\| _i\| and pi>0p_i>0, it follows that ϑ∈L∞ ∈ L_∞. From (67), σ=(HF−1⊗Im)ϑ−(HF−1LFL⊗Im)Φ.σ=(H_F^-1 I_m) -(H_F^-1L_FL I_m) . (91) Assumption 4 gives Φ∈L∞ ∈ L_∞, and hence σ∈L∞σ∈ L_∞. Also, ‖υi‖=γi2‖ϑi‖γi‖ϑi‖+ϖi(t)≤γi,\| _i\|= _i^2\| _i\| _i\| _i\|+ _i(t)≤ _i, so υ∈L∞ ∈ L_∞. The right-hand side of (63) is therefore bounded on every finite interval on which the solution exists. Since γi(t) _i(t) remains positive by (66), and since all components of (σ,γ)(σ,γ) are bounded on finite intervals, the maximal solution cannot escape in finite time. Thus Tmax=∞T_ =∞. It remains to prove convergence. From (70), and using ϑ,υ,gΦ∈L∞ , ,g_ ∈ L_∞, we have ϑ˙∈L∞ ∈ L_∞ almost everywhere. Hence ϑ is uniformly continuous on [0,∞)[0,∞). Since ϑ is bounded and J is Lipschitz on bounded subsets of ℝMmR^Mm, the scalar function t↦J(ϑ(t))t J( (t)) is uniformly continuous. Because J≥0J≥ 0 and J∈L1[0,∞)J∈ L_1[0,∞), Barbalat’s lemma gives J(t)→0.J(t)→ 0. Since pi>0p_i>0 for all i, this implies ϑi(t)→0 _i(t)→ 0 for all i. Define σ∗=−(HF−1LFL⊗Im)Φ.σ^*=-(H_F^-1L_FL I_m) . (92) Then (67) gives ϑ=(HF⊗Im)(σ−σ∗). =(H_F I_m)(σ-σ^*). Since HFH_F is nonsingular, ϑ(t)→0 (t)→ 0 implies σ(t)−σ∗(t)→0.σ(t)-σ^*(t)→ 0. Under Assumption 1, the matrix −HF−1LFL-H_F^-1L_FL is row stochastic. Hence each σi∗(t) _i^*(t) is a convex combination of ϕ1(t),…,ϕN(t) _1(t),…, _N(t), and therefore σi∗(t)∈co(ΦL(t)). _i^*(t) ( _L(t)). Consequently, dist(σi(t),co(ΦL(t)))≤‖σi(t)−σi∗(t)‖→0,dist( _i(t),co( _L(t)))≤\| _i(t)- _i^*(t)\|→ 0, which proves (64). ∎ I-D Interconnection and Physical-Output Containment We now interconnect the network interface with the local recovery layer by setting ri=Tiσi,Ti=−(HiFi−1Gi)−1.r_i=T_i _i, T_i=-(H_iF_i^-1G_i)^-1. (93) The inverse exists by the admissibility condition rank(HiFi−1Gi)=mrank(H_iF_i^-1G_i)=m in (10). Since Theorem 2 gives σi∈L∞[0,∞) _i∈ L_∞[0,∞), the command rir_i is also bounded and therefore satisfies the input requirement of Theorem 1. Define Xi=Fi−1Gi(HiFi−1Gi)−1.X_i=F_i^-1G_i(H_iF_i^-1G_i)^-1. (94) Then, by (93), FiXi+GiTi=0,HiXi=Im.F_iX_i+G_iT_i=0, H_iX_i=I_m. (95) The following result completes the solution of Problem 1. Corollary 1 Under Assumptions 1–7, consider the interconnected design composed of (9), (93), (14), (27), and (63). Then all closed-loop signals are bounded, exi(t)→0,eηi(t)→0,e_x_i(t)→ 0, e_ _i(t)→ 0, and, for every i∈ℱi , lim supt→∞dist(yi(t),co(ΦL(t)))≤εi, _t→∞dist (y_i(t),co( _L(t)) )≤ _i, (96) where εi=(∫0∞‖HieFisXi‖s)lim supt→∞‖σ˙i(t)‖. _i= ( _0^∞\|H_ie^F_isX_i\|\,ds ) _t→∞\| σ_i(t)\|. (97) Proof: By Theorem 2, the network-interface signals are bounded, σi∈C([0,∞),ℝm)∩L∞[0,∞) _i∈ C([0,∞),R^m)∩ L_∞[0,∞), and dist(σi(t),co(ΦL(t)))→0.dist( _i(t),co( _L(t)))→ 0. Hence ri=Tiσi∈C([0,∞),ℝm)∩L∞[0,∞)r_i=T_i _i∈ C([0,∞),R^m)∩ L_∞[0,∞). Applying Theorem 1 gives bounded local closed-loop signals and exi(t)→0,eηi(t)→0.e_x_i(t)→ 0, e_ _i(t)→ 0. Since yi=Cixi=Ci(exi+Πi1zi)=Ciexi+Hizi,y_i=C_ix_i=C_i(e_x_i+ _i_1z_i)=C_ie_x_i+H_iz_i, the point-to-set distance satisfies dist(yi,co(ΦL))≤‖Hizi−σi‖+dist(σi,co(ΦL))+‖Ciexi‖.dist(y_i,co( _L))≤\|H_iz_i- _i\|+dist( _i,co( _L))+\|C_ie_x_i\|. (98) The second term on the right-hand side of (98) converges to zero by Theorem 2, and the third term converges to zero by Theorem 1. It remains to bound the command-filter mismatch. Set z~i=zi−Xiσi. z_i=z_i-X_i _i. Using (9), (93), and (95), one obtains z~˙i=Fiz~i−Xiσ˙i,Hiz~i=Hizi−σi. z_i=F_i z_i-X_i σ_i, H_i z_i=H_iz_i- _i. (99) By the variation-of-constants formula, Hiz~i(t)=HieFitz~i(0)−∫0tHieFi(t−τ)Xiσ˙i(τ)τ.H_i z_i(t)=H_ie^F_it z_i(0)- _0^tH_ie^F_i(t-τ)X_i σ_i(τ)dτ. Since FiF_i is Hurwitz, the kernel Ki(s)=HieFisXiK_i(s)=H_ie^F_isX_i belongs to L1[0,∞)L_1[0,∞), and the homogeneous term HieFitz~i(0)H_ie^F_it z_i(0) converges to zero. For any δ>0δ>0, there exists Tδ>0T_δ>0 such that ‖σ˙i(t)‖≤lim supτ→∞‖σ˙i(τ)‖+δ,t≥Tδ.\| σ_i(t)\|≤ _τ→∞\| σ_i(τ)\|+δ, t≥ T_δ. In the convolution above, the contribution over [0,Tδ][0,T_δ] converges to zero because the interval is fixed and eFi(t−τ)e^F_i(t-τ) decays exponentially. The tail over [Tδ,t][T_δ,t] is bounded by (lim supτ→∞‖σ˙i(τ)‖+δ)∫0∞‖HieFisXi‖s. ( _τ→∞\| σ_i(τ)\|+δ ) _0^∞\|H_ie^F_isX_i\|\,ds. Taking the upper limit as t→∞t→∞, and then letting δ→0+δ→ 0^+, gives lim supt→∞‖Hizi(t)−σi(t)‖≤(∫0∞‖HieFisXi‖s)lim supt→∞‖σ˙i(t)‖. split& _t→∞\|H_iz_i(t)- _i(t)\|≤\\ & ( _0^∞\|H_ie^F_isX_i\|\,ds ) _t→∞\| σ_i(t)\|. split Combining this bound with (98) proves (96)–(97). ∎ Remark 1 The residual εi _i quantifies the mismatch between the generated task-space command σi _i and the realizable filtered command HiziH_iz_i. This residual is induced by the stable local command filter and by the fact that the leader trajectories are only assumed to be locally absolutely continuous with unknown velocity bounds. For heterogeneous followers with relative degrees larger than one, exact physical-output tracking of an arbitrary moving command would generally require higher-order command derivatives, which are not available under the information pattern considered here. Figure 1 illustrates an overview of the proposed two-layer resilient output-containment architecture for each follower i∈ℱi . The first layer is the local execution and recovery layer. It converts the network command σi _i into a realizable local command ri=Tiσir_i=T_i _i, processes it through the admissible stable command filter z˙i=Fizi+Giri z_i=F_iz_i+G_ir_i, and applies the nominal embedding controller ui,nom=ψi−1(Qizi+Kiri+uir)u_i,nom= _i^-1(Q_iz_i+K_ir_i+u_i^r). The adaptive virtual-actuator recovery term uiru_i^r is then generated from the local tracking variable si=BiTPiexis_i=B_i^TP_ie_x_i to compensate for state-correlated, input-correlated, and bounded exogenous actuator attacks. Importantly, the local recovery layer uses only the available external normal-form state xix_i, and it does not require measurement of the zero-dynamics state ηi _i. The second layer is the network-interface layer, which generates the task-space command σi _i using only neighbor-exchanged interface states σj _j and instantaneous leader-neighbor task-space signals ϕℓ _ , when such leader-neighbor links are present. This layer does not require knowledge of the leaders’ dynamics, leader velocity bounds, leader motion envelopes, or global graph parameters to tune the controller. Its role is to enforce command-level containment by driving the generated command σi _i to the convex hull of the leaders’ task-space signals. This two-layer separation also prevents actuator-side compromises from entering the network-interface dynamics, while the local layer ensures resilient realization of the generated command at the physical follower level. LAYER I: NETWORK INTERFACE PROTOCOLLAYER I: RESILIENT LOCAL CONTROLRECOVERY SUBSYSTEM NETWORK ϕℓ(t),σj(t) _ (t), _j(t) ADAPTIVE NETWORK PROTOCOL ϑi=∑jaij(σi−σj)+∑ℓaiℓ(σi−ϕℓ) _i= _ja_ij( _i- _j)+ _ a_i ( _i- _ ) γ˙i=−bγiϖiγi+bγi‖ϑi‖ γ_i=-b_γ i _i _i+b_γ i\| _i\| σ˙i=−ϑi−γi2ϑiγi‖ϑi‖+ϖi σ_i=- _i- _i^2 _i _i\| _i\|+ _i ri=Tiσir_i=T_i _i Ti=−(HiFi−1Gi)−1T_i=-(H_iF_i^-1G_i)^-1 LOCAL COMMAND FILTER z˙i=Fizi+Giri z_i=F_iz_i+G_ir_i Hizi≈σiH_iz_i≈ _i, rank(HiFi−1Gi)=mrank(H_iF_i^-1G_i)=m NOMINAL CONTROLLER ui,nom=ψi−1(Qizi+Kiri+uir)u_i,nom= _i^-1(Q_iz_i+K_ir_i+u_i^r) VIRTUAL ACTUATOR RECOVERY uir=−∑q=14βi,q2(Ωi,q(1))2siβi,qΩi,q(1)‖si‖+μi(t)−12ρiΩi(2)si,β˙i,q=−bβi,qμi(t)βi,q+bβi,qΩi,q(1)‖si‖,ρ˙i=−bρiμi(t)ρi+bρiΩi(2)‖si‖2. aligned &u_i^r=- _q=1^4 _i,q^2( _i,q^(1))^2s_i _i,q _i,q^(1)\|s_i\|+ _i(t)- 12 _i _i^(2)s_i,\\ & β_i,q=-b_β i,q _i(t) _i,q+b_β i,q _i,q^(1)\|s_i\|,\\ & ρ_i=-b_ρ i _i(t) _i+b_ρ i _i^(2)\|s_i\|^2. aligned ERROR COMPUTATION exi=xi−Πi1zie_x_i=x_i- _i_1z_i si=Bi⊤Piexis_i=B_i P_ie_x_i ACTUATOR ATTACK wai=Kaixxi+Kaiuui,nom+waiucw_a_i=K_a_i^xx_i+K_a_i^uu_i,nom+w_a_i^uc Follower Plant i∈ℱi x˙i=Aixi+Bi(Liηi+ψiui),η˙i=Γiηi+Λiyi,yi=Cixi. aligned & x_i=A_ix_i+B_i(L_i _i+ _iu_i),\\ & η_i= _i _i+ _iy_i,\\ &y_i=C_ix_i. aligned ϕℓ,σj _ , _jσi _irir_iziz_iziz_isis_iuiru_i^rui,nomu_i,nomuiu_ixix_i Figure 1: Two-layer resilient output-containment architecture for follower i. The network-interface layer generates the task-space command σi _i using only neighbor-exchanged interface states and, if available, instantaneous leaders’ signals, without requiring leader dynamics, leader velocity bounds, leader motion envelopes, or global graph parameters for tuning. The local layer maps σi _i into ri=Tiσir_i=T_i _i, realizes it through an admissible stable command filter, and applies a nominal embedding controller augmented by adaptive virtual-actuator recovery. The recovery term is computed adaptively from the available external normal-form state xix_i through si=BiTPiexis_i=B_i^TP_ie_x_i, and compensates for state-correlated, input-correlated, and bounded exogenous actuator attacks without requiring measurement of the zero-dynamics state ηi _i. IV Numerical Simulation We validate the proposed architecture on a heterogeneous output-containment problem with six followers and three leaders. Each follower represents the lateral motion of a quadrotor carrying a cable-suspended payload, with controlled output yi=[pxipyi]T∈ℝ2.y_i= bmatrixp_x_i&p_y_i bmatrix^T ^2. The followers have heterogeneous physical parameters, and their outputs have vector relative degree [4,4]T[4,4]^T. The leaders generate a moving, rotating, and resizing convex hull whose dynamical model and velocity bounds are not available to the followers. Two of the followers are also subjected to persistent actuator attacks combining state-correlated, input-correlated, and bounded exogenous false-data components. The simulation therefore verifies command-level containment of the generated interface states σi _i, resilient local realization of the admissible command-filter trajectories, and practical physical-output containment with the residual characterized in Corollary 1. IV-A Heterogeneous Follower Model The follower model is obtained from a small-angle near-hover linearization of a quadrotor with a cable-suspended payload. The yaw angle is fixed over the lateral-control time scale, and the roll and pitch angles as well as the load swing angles are small. For follower i, let mqim_q_i denote the quadrotor mass, mℓim_ _i the payload mass, ℓai _a_i the arm length, JxiJ_x_i and JyiJ_y_i the roll and pitch inertias, and ℓxi _x_i, ℓyi _y_i the effective cable lengths in the two lateral planes. The loaded hover thrust is taken as T0i=(mqi+mℓi)g0,g0=9.807m/s2.T_0_i=(m_q_i+m_ _i)g_0, g_0=9.807\,m/s^2. For the x-axis, the linearized translational-pendulum equations are (mqi+mℓi)p¨xi+mℓiℓxiα¨xi=T0iθi,(m_q_i+m_ _i) p_x_i+m_ _i _x_i α_x_i=T_0_i _i, p¨xi+ℓxiα¨xi+2ζxiwxiℓxiα˙xi+g0αxi=0,wxi=g0/ℓxi. p_x_i+ _x_i α_x_i+2 _x_iw_x_i _x_i α_x_i+g_0 _x_i=0, w_x_i= g_0/ _x_i. Eliminating α¨xi α_x_i gives p¨xi=aθiθi+aαx,iαxi+aβx,iα˙xi, p_x_i=a_θ i _i+a_α x,i _x_i+a_β x,i α_x_i, where aθi=T0imqi,aαx,i=mℓig0mqi,aβx,i=mℓiℓxi(2ζxiwxi)mqi.a_θ i= T_0_im_q_i, a_α x,i= m_ _ig_0m_q_i, a_β x,i= m_ _i _x_i(2 _x_iw_x_i)m_q_i. Similarly, after absorbing the roll-channel sign into the y-axis input convention, p¨yi=aϕiϕi+aαy,iαyi+aβy,iα˙yi, p_y_i=a_φ i _i+a_α y,i _y_i+a_β y,i α_y_i, with wyi=g0/ℓyiw_y_i= g_0/ _y_i, we have aϕi=T0imqi,aαy,i=mℓig0mqi,aβy,i=mℓiℓyi(2ζyiwyi)mqi.a_φ i= T_0_im_q_i, a_α y,i= m_ _ig_0m_q_i, a_β y,i= m_ _i _y_i(2 _y_iw_y_i)m_q_i. The attitude channels are modeled by θ¨i=bθiuxi,ϕ¨i=bϕiuyi,bθi=ℓaiJyi,bϕi=ℓaiJxi. θ_i=b_θ iu_x_i, φ_i=b_φ iu_y_i, b_θ i= _a_iJ_y_i, b_φ i= _a_iJ_x_i. Thus the physical high-frequency matrix from the actuator input to the fourth output derivative is ψi0=[aθibθi00aϕibϕi]=[T0iℓaimqiJyi00T0iℓaimqiJxi], _i^0= bmatrixa_θ ib_θ i&0\\ 0&a_φ ib_φ i bmatrix= bmatrix T_0_i _a_im_q_iJ_y_i&0\\[2.84526pt] 0& T_0_i _a_im_q_iJ_x_i bmatrix, which is nonsingular. Hence the physical input-output model has vector relative degree [4,4]T[4,4]^T. The raw physical state is chosen as Xi0=col(pxi,p˙xi,θi,θ˙i,αxi,α˙xi,pyi,p˙yi,ϕi,ϕ˙i,αyi,α˙yi).X_i^0=col (p_x_i, p_x_i, _i, θ_i, _x_i, α_x_i,p_y_i, p_y_i, _i, φ_i, _y_i, α_y_i ). It satisfies X˙i0=Ai0Xi0+Bi0ui,yi=Ci0Xi0, X_i^0=A_i^0X_i^0+B_i^0u_i, y_i=C_i^0X_i^0, where ui=col(uxi,uyi)u_i=col(u_x_i,u_y_i), Ci0C_i^0 selects pxip_x_i and pyip_y_i, and the nonzero entries of Ai0A_i^0 and Bi0B_i^0 are Ai0(1,2)=1,Ai0(2,3)=aθi,Ai0(2,5)=aαx,i,Ai0(2,6)=aβx,i,Ai0(3,4)=1,Bi0(4,1)=bθi,Ai0(5,6)=1,Ai0(6,3)=−aθi/ℓxi,Ai0(6,5)=−(wxi2+aαx,i/ℓxi),Ai0(6,6)=−(2ζxiwxi+aβx,i/ℓxi), split&A_i^0(1,2)=1,A_i^0(2,3)=a_θ i,A_i^0(2,5)=a_α x,i,\\ &A_i^0(2,6)=a_β x,i,A_i^0(3,4)=1,B_i^0(4,1)=b_θ i,A_i^0(5,6)=1,\\ &A_i^0(6,3)=-a_θ i/ _x_i,A_i^0(6,5)=-(w_x_i^2+a_α x,i/ _x_i),\\ &A_i^0(6,6)=-(2 _x_iw_x_i+a_β x,i/ _x_i), split and Ai0(7,8)=1,Ai0(8,9)=aϕi,Ai0(8,11)=aαy,i,Ai0(8,12)=aβy,i,Ai0(9,10)=1,Bi0(10,2)=bϕi,Ai0(11,12)=1,Ai0(12,9)=−aϕi/ℓyi,Ai0(12,11)=−(wyi2+aαy,i/ℓyi),Ai0(12,12)=−(2ζyiwyi+aβy,i/ℓyi). split&A_i^0(7,8)=1,A_i^0(8,9)=a_φ i,A_i^0(8,11)=a_α y,i,\\ &A_i^0(8,12)=a_β y,i,A_i^0(9,10)=1,B_i^0(10,2)=b_φ i,\\ &A_i^0(11,12)=1,A_i^0(12,9)=-a_φ i/ _y_i,\\ &A_i^0(12,11)=-(w_y_i^2+a_α y,i/ _y_i),\\ &A_i^0(12,12)=-(2 _y_iw_y_i+a_β y,i/ _y_i). split All other entries are zero. The physical parameters are heterogeneous across the six followers. The quadrotor masses satisfy mqi∈[1.44,1.56]kgm_q_i∈[1.44,1.56]\,kg, the payload masses satisfy mℓi∈[0.301,0.346]kgm_ _i∈[0.301,0.346]\,kg, and the arm lengths satisfy ℓai∈[0.218,0.232]m _a_i∈[0.218,0.232]\,m. The inertias are Jxi∈[2.068,2.332]×10−2kgm2J_x_i∈[2.068,2.332]× 10^-2\,kg\,m^2 and Jyi∈[2.090,2.332]×10−2kgm2J_y_i∈[2.090,2.332]× 10^-2\,kg\,m^2. The cable lengths are ℓxi∈[0.576,0.636]m _x_i∈[0.576,0.636]\,m and ℓyi∈[0.523,0.578]m _y_i∈[0.523,0.578]\,m, and the damping ratios are ζxi∈[0.523,0.594] _x_i∈[0.523,0.594] and ζyi∈[0.528,0.583] _y_i∈[0.528,0.583]. The physical model is then transformed into the normal form (2) using the algorithm of [22], leading to A¯i=[AiBiLiΛiCiΓi],B¯i=[Bi0]. A_i= bmatrixA_i&B_iL_i\\ _iC_i& _i bmatrix, B_i= bmatrixB_i\\ 0 bmatrix. These matrices are the same block matrices that appear in (10). The transformation was verified numerically, and the largest real part among the internal-dynamics eigenvalues was −2.156-2.156. Hence, all transformed internal dynamics are Hurwitz, consistent with Assumption 2. IV-B Command-Filter Construction The command filter is constructed after the physical model has been transformed into the normal form (2). Since each follower has vector relative degree [4,4]T[4,4]^T, the external state dimension is 88, the internal dimension is 44, and the local filter state is selected as zi∈ℝ12z_i ^12. The external part of the filter assigns stable fourth-order chains in the two output channels. Let Ac=[0100001000010000],bc=[0001].A_c= bmatrix0&1&0&0\\ 0&0&1&0\\ 0&0&0&1\\ 0&0&0&0 bmatrix, b_c= bmatrix0\\ 0\\ 0\\ 1 bmatrix. For the command filters, we use a common bandwidth ωcf=10.5rad/s _cf=10.5\,rad/s for all followers, together with a follower-dependent scaling factor to induce heterogeneity at the local controller level: κicf=0.94+0.025(i−1),i=1,…,6. _i^cf=0.94+0.025(i-1), i=1,…,6. The assigned x- and y-channel pole sets are therefore λxicf=−ωcfκicf[0.450.550.650.75], _x_i^cf=- _cf _i^cf bmatrix0.45&0.55&0.65&0.75 bmatrix, λyicf=−ωcfκicf[0.470.570.670.73]. _y_i^cf=- _cf _i^cf bmatrix0.47&0.57&0.67&0.73 bmatrix. Thus, across the six followers, the assigned x-chain poles lie in [−8.39,−4.44][-8.39,-4.44], and the assigned y-chain poles lie in [−8.16,−4.64][-8.16,-4.64]. Let kxicf∈ℝ1×4k_x_i^cf ^1× 4 and kyicf∈ℝ1×4k_y_i^cf ^1× 4 be the pole-placement rows satisfying spec(Ac−bckxicf)=λxicf,spec(Ac−bckyicf)=λyicf.spec (A_c-b_ck_x_i^cf )= _x_i^cf, (A_c-b_ck_y_i^cf )= _y_i^cf. With the normal-form input-selector convention used for BiB_i, the external-chain feedback is Qicf=−[kxicf01×401×4kyicf].Q_i^cf=- bmatrixk_x_i^cf&0_1× 4\\ 0_1× 4&k_y_i^cf bmatrix. Based on this choice, we select Qi=[Qicf−Li],Fi=A¯i+B¯iQi.Q_i= bmatrixQ_i^cf&-L_i bmatrix, F_i= A_i+ B_iQ_i. Equivalently, Fi=[Ai+BiQicf08×4ΛiCiΓi].F_i= bmatrixA_i+B_iQ_i^cf&0_8× 4\\ _iC_i& _i bmatrix. Therefore, FiF_i is block lower triangular. Its external block has the assigned stable chain poles, and its internal block is Γi _i, which is Hurwitz by the verified minimum-phase property of the transformed suspended-load model. Hence, FiF_i is Hurwitz for every simulated follower. The immersion matrices are selected as Πi1=[I808×4],Πi2=[04×8I4],Hi=CiΠi1. _i_1= bmatrixI_8&0_8× 4 bmatrix, _i_2= bmatrix0_4× 8&I_4 bmatrix, H_i=C_i _i_1. Thus, Πi=col(Πi1,Πi2)=I12. _i=col( _i_1, _i_2)=I_12. With the above construction, ΠiFi−A¯iΠi−B¯iQi=0,ΠiGi−B¯iKi=0 _iF_i- A_i _i- B_iQ_i=0, _iG_i- B_iK_i=0 once GiG_i is chosen as below. The second identity also gives Πi2Gi=0 _i_2G_i=0, which is the implemented full-order admissibility condition for the internal part of the filter. The input matrix GiG_i is selected from the DC map between the filter input and the reconstructed task-space output: Dicf=HiFi−1B¯i.D_i^cf=H_iF_i^-1 B_i. The assigned fourth-order chain poles are all nonzero, so this DC map is nonsingular. The simulation code verifies this rank condition for each follower before accepting the model. The command-filter input gain is then Ki=−(Dicf)−1,Gi=B¯iKi.K_i=-(D_i^cf)^-1, G_i= B_iK_i. Consequently, HiFi−1Gi=DicfKi=−I2.H_iF_i^-1G_i=D_i^cfK_i=-I_2. The command-interface matrix in (93) is therefore Ti=−(HiFi−1Gi)−1=I2.T_i=-(H_iF_i^-1G_i)^-1=I_2. Thus, in the reported implementation, ri=σir_i= _i; nevertheless, the construction keeps TiT_i explicitly in the notation because it is part of the general interconnection formula used in Corollary 1. Finally, the matrix used in the filter-residual characterization is Xi=Fi−1Gi(HiFi−1Gi)−1.X_i=F_i^-1G_i (H_iF_i^-1G_i )^-1. With the above choice of TiT_i, this matrix satisfies FiXi+GiTi=0,HiXi=I2,F_iX_i+G_iT_i=0, H_iX_i=I_2, which are precisely the identities used to connect the network-interface command σi _i to the stable local command filter. IV-C Actuator-Attack Scenario In the simulation, only followers 11 and 66 are subjected to attack. Follower 11 is subjected to a combined but moderate state- and input-correlated attack plus an exogenous false-data injection, and follower 66 is subjected to a hijacking-type actuator compromise. For follower 11, the injected actuator signal is wa1=Ka1xx1+E1u1,nom+da1(t),w_a_1=K_a_1^xx_1+E_1u_1,nom+d_a_1(t), where the input-correlated attack gain E1≡Ka1uE_1≡ K^u_a_1 is E1=[−0.4900.056−0.042−0.448].E_1= bmatrix-0.490&0.056\\ -0.042&-0.448 bmatrix. The bounded exogenous false-data component is da1(t)=[2.00sin(0.031t+0.40)1.50cos(0.027t+0.70)].d_a_1(t)= bmatrix2.00 (0.031t+0.40)\\ 1.50 (0.027t+0.70) bmatrix. The state-correlated component is defined in the normal-form external state x1∈ℝ8x_1 ^8, not in the raw physical state. Let Sx=diag(1200,300,120,60,1200,300,120,60),S_x=diag(1200,300,120,60,1200,300,120,60), and define k¯1x=[1.000.350.120.040.050.0200], k_1x= bmatrix1.00&0.35&0.12&0.04&0.05&0.02&0&0 bmatrix, k¯1y=[−0.0400.0200.900.320.110.04]. k_1y= bmatrix-0.04&0&0.02&0&0.90&0.32&0.11&0.04 bmatrix. The shaped state-correlated gain is Ksh,1=[k¯1xk¯1y]Sx−1,Ka1x=ψ1−1Ksh,1.K_sh,1= bmatrix k_1x\\ k_1y bmatrixS_x^-1, K_a_1^x= _1^-1K_sh,1. The corresponding effective input matrix Δu1=I2+ψ1E1ψ1−1 _u_1=I_2+ _1E_1 _1^-1 satisfies Assumption 6. The exogenous component da1d_a_1 satisfies Assumption 7, and since Ka1xK_a_1^x is constant, the state-correlated term satisfies Assumption 5 with a constant envelope. For the follower-6 attack, the input-correlated component is E6=−0.95I2.E_6=-0.95I_2. Consequently, Δu6=I2+ψ6E6ψ6−1=0.05I2, _u_6=I_2+ _6E_6 _6^-1=0.05I_2, so the direct input authority is reduced to 5%5\%, but remains strictly positive. Thus Assumption 6 holds with χ6=0.05 _6=0.05. The attack is designed to force the quadrotor to track the output of ζ˙a6=Sa6ζa6,Sa6=[00.3000−0.300000000.2400−0.240], ζ_a6=S_a6 _a6, S_a6= bmatrix0&0.30&0&0\\ -0.30&0&0&0\\ 0&0&0&0.24\\ 0&0&-0.24&0 bmatrix, with selector Ca6=[10000010].C_a6= bmatrix1&0&0&0\\ 0&0&1&0 bmatrix. The two oscillator frequencies are 0.30rad/s0.30\,rad/s and 0.24rad/s0.24\,rad/s, corresponding to periods of approximately 20.9s20.9\,s and 26.2s26.2\,s. The initial amplitudes are A6x=360A_6x=360 and A6y=260A_6y=260, with phases 0 and π, respectively. Hence, the injected exogenous component remains persistently time-varying over the simulation interval. Define dk(t)=Ca6Sa6kζa6(t),k=0,1,2,3,4.d_k(t)=C_a6S_a6^k _a6(t), k=0,1,2,3,4. The corresponding adversarial external-chain trajectory is xa6(t)=col(d0,1,d1,1,d2,1,d3,1,d0,2,d1,2,d2,2,d3,2).x_a6(t)=col (d_0,1,d_1,1,d_2,1,d_3,1,d_0,2,d_1,2,d_2,2,d_3,2 ). The internal target associated with this adversarial chain is obtained from the Sylvester equation Πa6Sa6=Γ6Πa6+Λ6Ca6, _a6S_a6= _6 _a6+ _6C_a6, and is given by ηa6⋆(t)=Πa6ζa6(t). _a6 (t)= _a6 _a6(t). This construction gives η˙a6⋆=Γ6ηa6⋆+Λ6C6xa6. η_a6 = _6 _a6 + _6C_6x_a6. The hijacking feedback matrix Ktr,6K_tr,6 is then selected in the external normal-form coordinates. Let p¯h6=[0.801.101.502.000.761.051.421.90]. p_h6= bmatrix0.80&1.10&1.50&2.00&0.76&1.05&1.42&1.90 bmatrix. The initialization routine searches over h=[0.2,20]S_h=[0.2,20] and chooses the first λh6∈h _h6 _h for which the feedback matrix Ktr,6K_tr,6 satisfying spec(A6−B6Ktr,6)=−λh6p¯h6spec(A_6-B_6K_tr,6)=- _h6 p_h6 also makes the coupled hijacking-error matrix Ah6=[A6−B6Ktr,6B6L6Λ6C6Γ6]A_h6= bmatrixA_6-B_6K_tr,6&B_6L_6\\ _6C_6& _6 bmatrix Hurwitz, with maxλ∈spec(Ah6)Reλ<−2.0×10−2 _λ (A_h6)Reλ<-2.0× 10^-2. The state-correlated hijacking gain is then chosen as Ka6x=−ψ6−1Ktr,6.K_a_6^x=- _6^-1K_tr,6. The bounded exogenous term is da6(t)=ψ6−1(d4(t)−L6ηa6⋆(t)+Ktr,6xa6(t)).d_a_6(t)= _6^-1 (d_4(t)-L_6 _a6 (t)+K_tr,6x_a6(t) ). Therefore the actuator attack applied to follower 66 is wa6=Ka6xx6+E6u6,nom+da6(t).w_a_6=K_a_6^xx_6+E_6u_6,nom+d_a_6(t). IV-D Controller Parameters The recovery controller is implemented in the transformed normal-form coordinates. The Riccati matrices PiP_i solving (18) are computed from the follower-specific normal-form data with search initialized at αi=8000,Σi=50diag(σ¯,σ¯),σ¯=(1.20,0.70,0.35,0.12). split& _i=8000,\\ & _i=50diag( σ, σ),\\ & σ=(1.20,0.70,0.35,0.12). split The resulting certificates in Lemma 1 are strictly positive for all followers, with ci=λmin(Ξi)c_i= _ ( _i) ranging over [3.51,5.19]×10−2[3.51,5.19]× 10^-2 and minici=3.51×10−2 _ic_i=3.51× 10^-2. Therefore, the local dissipation inequality (51) is certified for every follower. The virtual actuator then uses the embedding errors exi=xi−Πi1zi,e_x_i=x_i- _i_1z_i, to generate si=BiTPiexis_i=B_i^TP_ie_x_i. We set μi(t)=μ0iexp(−λμit),μ0i=3.0,λμi=0.002. _i(t)= _0i (- _μ it), _0i=3.0, _μ i=0.002. The adaptation gains are bβi,q=0.08b_β i,q=0.08, q=1,…,4q=1,…,4, and bρi=0.03b_ρ i=0.03, and the adaptive variables are initialized at βi,q(0)=ρi(0)=0.5>0 _i,q(0)= _i(0)=0.5>0, satisfying the positivity condition used in Theorem 1. The network interface (63) uses γi(0)=100 _i(0)=100, bγi=0.75b_γ i=0.75, and ϖi(t)=ϖ0iexp[−λϖi((t+τϖi)aϖi−τϖiaϖi)], _i(t)= _0i \! [- _ i ((t+ _ i)^a_ i- _ i^a_ i ) ], with ϖ0i=0.5,λϖi=0.15,aϖi=0.6,τϖi=1000. _0i=0.5, _ i=0.15, a_ i=0.6, _ i=1000. This profile is positive, continuous, decays to zero, and belongs to L1[0,∞)L_1[0,∞), as required in Theorem 2. For comparison on agents 11 and 66, we also implement a baseline controller without any dedicated resiliency mechanism. The non-resilient comparison controller uses the same command filter, immersion matrices, and nominal embedding terms as the resilient controller, but removes the adaptive virtual-actuator recovery law. Specifically, after defining exi=xi−Πi1zie_x_i=x_i- _i_1z_i and si=BiTPiexis_i=B_i^TP_ie_x_i, the recovery input is replaced by the fixed feedback ui,nrr=−knom,isi,knom,i=αi2.u_i,nr^r=-k_nom,is_i, k_nom,i= _i2. Therefore, the non-resilient nominal actuator command is ui,nomnr=ψi−1(Qizi+Kiri−knom,iBiTPiexi).u_i,nom^nr= _i^-1 (Q_iz_i+K_ir_i-k_nom,iB_i^TP_ie_x_i ). IV-E Leaders and Network Topology The three leaders’ trajectories are generated by bounded smooth geometric paths ϕ¯ℓ(τ)∈ℝ2 φ_ (τ) ^2, ℓ=1,2,3 =1,2,3, with ϕℓ(t)=ϕ¯ℓ(τ(t)),τ˙(t)=0.30,τ(0)=0. _ (t)= φ_ (τ(t)), τ(t)=0.30, τ(0)=0. The leaders’ paths have spatial scale 500m500\,m and are defined by ϕ¯ℓ(τ)=500(c0(τ)+R(θ(τ))qℓ(τ)),ℓ=1,2,3. φ_ (τ)=500 (c_0(τ)+R(θ(τ))q_ (τ) ), =1,2,3. The center motion is c0(τ)=[1.10sin(0.050τ)+0.18sin(0.130τ)0.75sin(0.085τ+0.25sin(0.030τ))+0.14cos(0.120τ)], split&c_0(τ)=\\ & bmatrix1.10 (0.050τ)+0.18 (0.130τ)\\ 0.75 (0.085τ+0.25 (0.030τ))+0.14 (0.120τ) bmatrix, split and the rotation angle is θ(τ)=0.065τ+0.18sin(0.035τ).θ(τ)=0.065τ+0.18 (0.035τ). The relative leader offsets are qℓ(τ)=c(τ)S(τ)rℓ(τ)[cosaℓ(τ)sinaℓ(τ)],q_ (τ)=c(τ)S(τ)r_ (τ) bmatrix a_ (τ)\\ a_ (τ) bmatrix, with resizing factor c(τ)=0.18+0.82(1+cos(0.055τ)2)2,c(τ)=0.18+0.82 ( 1+ (0.055τ)2 )^2, the shape matrix S(τ)=[s11(τ)s12(τ)0s22(τ)],S(τ)= bmatrixs_11(τ)&s_12(τ)\\ 0&s_22(τ) bmatrix, and s11(τ) s_11(τ) =1.00+0.18sin(0.038τ), =00+18 (038τ), s12(τ) s_12(τ) =0.12sin(0.050τ+0.30), =12 (050τ+30), s22(τ) s_22(τ) =0.82+0.16cos(0.044τ+0.50). =82+16 (044τ+50). The angular modulations are a1(τ) a_1(τ) =0.20sin(0.041τ), =20 (041τ), a2(τ) a_2(τ) =2π3+0.28sin(0.047τ+0.90), = 2π3+28 (047τ+90), a3(τ) a_3(τ) =4π3+0.24cos(0.052τ+0.40), = 4π3+24 (052τ+40), and the radial modulations are r1(τ) r_1(τ) =0.72+0.18sin(0.060τ+0.20), =72+18 (060τ+20), r2(τ) r_2(τ) =0.62+0.16cos(0.073τ+1.10), =62+16 (073τ+10), r3(τ) r_3(τ) =0.68+0.20sin(0.067τ+2.00). =68+20 (067τ+00). All path-defining functions and their τ-derivatives are bounded. Since τ˙=0.30 τ=0.30, the generated signals ϕℓ(t) _ (t) are bounded and locally absolutely continuous with bounded derivatives, and therefore satisfy Assumption 4. The network topology is depicted in Figure 2. The directed interaction graph uses leader-to-follower weights a1,1L=0.40,a2,2L=0.20,a4,3L=0.30,a_1,1^L=0.40, a_2,2^L=0.20, a_4,3^L=0.30, and follower-to-follower weights a2,1F=0.35,a3,1F=0.25,a3,2F=0.20,a4,2F=0.30,a5,3F=0.25,a5,4F=0.25,a6,5F=0.35,a6,2F=0.15. gathereda_2,1^F=0.35, a_3,1^F=0.25, a_3,2^F=0.20, a_4,2^F=0.30,\\ a_5,3^F=0.25, a_5,4^F=0.25, a_6,5^F=0.35, a_6,2^F=0.15. gathered The graph has a leader-rooted united spanning tree, so Assumption 1 holds. The induced matrix WL=−HF−1LFLW_L=-H_F^-1L_FL is nonnegative and row stochastic to numerical precision, with maximum row-sum error 1.1×10−161.1× 10^-16. Hence the graph-induced target σi⋆(t)=∑ℓ=13Wiℓϕℓ(t) _i (t)= _ =1^3W_i _ (t) lies in co(ΦL(t))co( _L(t)) for every follower and every instant. The gauge vector p=HF−⊤Mp=H_F^- 1_M used in Theorem 2 is positive entrywise, with minipi=0.50 _ip_i=0.50 and maxipi=2.4793 _ip_i=2.4793. L2L1L3F4F2F1F6F3F5 Figure 2: Directed communication graph linking six followers and three leaders. IV-F Results and Discussion We run the simulation for 2000s2000\,s, choosing the verification interval v=[1800,2000]sT_v=[1800,2000]\,s to report the quantitative maxima below. As depicted in Figure 3, over the 2000s2000\,s run, the maximum leader speed is 24.0m/s24.0\,m/s, the maximum leader-position norm is 1.11×103m1.11× 10^3\,m, the hull area ranges over [2.72×103,1.83×105]m2[2.72× 10^3,1.83× 10^5]\,m^2, the minimum pairwise leader distance is 55.9m55.9\,m, and the maximum hull diameter is 706m706\,m. Figure 3: Leaders’ trajectory characteristics over the 2000s2000\,s run: leaders’ speed (top left), convex-hull area (top right), hull diameter (bottom left-solid), minimum pairwise separation of the leaders’ positions (bottom left-dashed), and the leaders’ resizing factor c(t)c(t) (bottom right). Figures 4 and 5 show the follower y- and x-coordinate trajectories, respectively. The plots distinguish the command states σi _i, the admissible-filter outputs HiziH_iz_i, and the physical outputs yiy_i. The command states approach the leader convex hull asymptotically, whereas the physical outputs inherit the practical residual characterized in Corollary 1. Figure 4: Time-domain y-coordinate trajectories. The shaded band shows the instantaneous leader-coordinate range projected in the corresponding coordinate. The command states σi _i, filter outputs HiziH_iz_i, and physical outputs yiy_i are plotted to distinguish command containment from physical-output realization. Figure 5: Time-domain x-coordinate trajectories. The shaded band shows the instantaneous leader-coordinate range projected in the corresponding coordinate. The command states σi _i, filter outputs HiziH_iz_i, and physical outputs yiy_i are plotted to distinguish command containment from physical-output realization. To evaluate the network-interface performance, we use Eσi(t)=‖σi(t)−σi⋆(t)‖,Eσ(t)=maxiEσi(t),E_ _i(t)=\| _i(t)- _i (t)\|, E_σ(t)= _iE_ _i(t), and Dσi(t)=dist(σi(t),co(ΦL(t))),Dσ(t)=maxiDσi(t).D_ _i(t)=dist ( _i(t),co( _L(t)) ), D_σ(t)= _iD_ _i(t). The corresponding values are depicted in Figure 6. Since σi⋆(t)∈co(ΦL(t)) _i (t) ( _L(t)), one has Dσ(t)≤Eσ(t).D_σ(t)≤ E_σ(t). On vT_v, maxt∈vDσ(t)=2.33×10−3m, _t _vD_σ(t)=2.33× 10^-3\,m, which is 3.30×10−63.30× 10^-6 of the maximum leader-hull diameter. At the final time, Eσ(2000)=1.50×10−5m,Dσ(2000)=4.26×10−7m.E_σ(2000)=1.50× 10^-5\,m, D_σ(2000)=4.26× 10^-7\,m. These values support the command-containment conclusion of Theorem 2 over the finite simulation horizon. Considering the zero initial conditions for σi _i and noting that the initial leaders’ convex hull includes the origin, initially Dσi(0)=0D_ _i(0)=0 for all the agents; however, since σi(0) _i(0) is different from the dedicated point σi⋆(0) _i (0), Eσi(0)E_ _i(0) is non-zero. As the agents start tracking σi⋆(t) _i (t) and the leaders start moving in the task space, DσiD_ _i first increases for the agents, and then, as σi _i approaches σi⋆ _i for all the agents, EσE_σ and DσD_σ both converge to zero. Moreover, since the adaptive protocol is not tuned using an a priori bound on the leaders’ velocities, its gains increase only when the realized motion requires stronger interaction. Consequently, when the leaders reach velocity levels or velocity variations not encountered earlier in the finite simulation horizon, a small adaptation transient can appear in EσE_σ and DσD_σ. These variations are consistent with the protocol’s online nature and do not indicate a loss of command containment. Specifically, these transitions are expected to correlate with the leaders’ speed, as illustrated in Figure 3. Figure 6: The curve EσE_σ (left) measures convergence to the graph-induced convex-combination targets σi⋆ _i , while DσD_σ (right) measures the point-to-set distance from the command states to the leader convex hull. Figure 7 reports the local disagreement variables ϑi _i and the command rates σ˙i σ_i. These quantities have different roles. The variables ϑi _i are the local containment disagreements suppressed by the distributed protocol, whereas σ˙i σ_i measures the task-space motion of the generated commands and need not converge to zero when the leader hull continues to move. At t=2000st=2000\,s, the maximum command rate is 8.60m/s8.60\,m/s, while the maximum leader speed over the simulation is 24.0m/s24.0\,m/s. On vT_v, the maximum disagreement norm is 3.38×10−13.38× 10^-1, and the maximum command rate is 16.3m/s16.3\,m/s. Figure 7: The disagreement variables ϑi _i (left) are reduced by the distributed protocol, while the command rates σ˙i σ_i (right) remain time varying because the leader-generated hull continues to move. Figure 8 reports the local-level performance through Dyi(t)=dist(yi(t),co(ΦL(t)))D_y_i(t)=dist(y_i(t),co( _L(t))), ‖yi−σi⋆‖\|y_i- _i \|, ‖yi−σi‖\|y_i- _i\|, and ‖Hizi−σi‖\|H_iz_i- _i\|. The first two metrics describe the overall containment performance supported by Corollary 1. The last two quantify local realization errors: ‖yi−σi‖\|y_i- _i\| measures the output-command mismatch, while ‖Hizi−σi‖\|H_iz_i- _i\| is the command-filter realization residual. Figure 8: The figure shows the distance of yiy_i to the leader hull, the output-command error, the error relative to the graph-induced target, and the command-filter realization residual. Figure 9 shows the residual decomposition associated with Corollary 1. We use Dy(t)=maxiDyi(t)D_y(t)= _iD_y_i(t) as the overall containment-performance measure. Over the interval vT_v, we have maxt∈vDy(t)=7.23m, _t _vD_y(t)=7.23\,m, which is approximately 1.02%1.02\% of the maximum leader-hull diameter 706m706\,m. On the same interval, maxi,t∈v‖Hizi(t)−σi(t)‖=10.5m,maxi,t∈v‖yi(t)−Hizi(t)‖=0.943m. split& _i,\ t _v\|H_iz_i(t)- _i(t)\|=10.5\,m,\\ & _i,\ t _v\|y_i(t)-H_iz_i(t)\|=0.943\,m. split Therefore, the dominant term in the containment residual is the command-filter realization residual Hizi−σiH_iz_i- _i, not the command-layer containment error. The plotted bound is Dy(t)≤ D_y(t)≤ Dσ(t)+maxi‖Hizi(t)−σi(t)‖ D_σ(t)+ _i\|H_iz_i(t)- _i(t)\| +maxi‖yi(t)−Hizi(t)‖. + _i\|y_i(t)-H_iz_i(t)\|. On vT_v, with maxt∈vDσ(t)=2.33×10−3m _t _vD_σ(t)=2.33× 10^-3\,m, this agrees with Corollary 1, where the network layer produces near-exact command containment, while the physical outputs retain a practical residual due to the local realization of moving commands by heterogeneous relative-degree-four followers. The estimate in Corollary 1 holds per follower: with the kernel gain κi=∫0∞‖HieFisXi‖s∈[0.62,0.70] _i= _0^∞\|H_ie^F_isX_i\|\,ds∈[0.62,0.70], the predicted residual εi=κisupv‖σ˙i‖ _i= _i _T_v\| σ_i\| bounds the realized command-filter residual maxv‖Hizi−σi‖ _T_v\|H_iz_i- _i\| for every i; for instance (realized,εi)=(9.82,10.04)m(realized, _i)=(9.82,10.04)\,m for F1 and (7.82,7.93)m(7.82,7.93)\,m for F6. Figure 9: Residual decomposition of Corollary 1. The physical containment distance is shown together with the command-containment term, the command-filter realization residual, the local tracking residual, and the decomposition upper bound. Figure 10 reports the error norms ‖exi‖\|e_x_i\| and ‖eηi‖\|e_ _i\|, which provide conservative indicators of the local recovery performance under actuator attacks. On the interval vT_v, we have maxi,t∈v‖exi(t)‖=0.943,maxi,t∈v‖eηi(t)‖=7.73. _i,\ t _v\|e_x_i(t)\|=0.943, _i,\ t _v\|e_ _i(t)\|=7.73. Both maxima occur for follower 6, which is subjected to the most severe local attack. Since exie_x_i contains the output coordinates and their derivatives up to order three, ‖exi‖\|e_x_i\| is a normal-form tracking-error norm, not a pure position error. The larger value of ‖eη6‖\|e_ _6\| reflects the response of the stable zero-dynamics coordinates. Figure 10: Follower-wise local recovery errors. The two panels show ‖exi‖\|e_x_i\| and ‖eηi‖\|e_ _i\| for each follower, identifying follower 6 as the source of the largest local residuals. Finally, Figures 11 and 12 compare the resilient and non-resilient responses of the two attacked followers, agents 11 and 66. The figures also show the separation between the trajectories generated with the adaptive virtual actuator and those generated by the non-resilient baseline. Fo follower 1 the maximum resilient versus non-resilient baseline separation is 2.50m2.50\,m, and for follower 6 the maximum resilient versus non-resilient separation is 7.57×103m7.57×10^3\,m. Figure 11: Task-space y-coordinate comparison for the attacked followers. The solid curves show resilient physical outputs, the dashed curves show non-resilient physical outputs, the dotted curves show generated commands σi _i, and the green band indicates the instantaneous leader-coordinate range. The right panels show the resilient/non-resilient separation. Figure 12: Task-space x-coordinate comparison for the attacked followers. The solid curves show resilient physical outputs, the dashed curves show non-resilient physical outputs, the dotted curves show generated commands σi _i, and the green band indicates the instantaneous leader-coordinate range. The right panels show the resilient/non-resilient separation. The per-follower metric values over vT_v in Table I clarify the roles of the command layer, the command filter, and the local recovery layer. Define diΦ=maxt∈vdist(yi(t),co(ΦL(t))),eηimax=maxt∈v‖eηi(t)‖,eximax=maxt∈v‖exi(t)‖,δiloc=maxt∈v‖yi(t)−Hizi(t)‖. split&d_i = _t _vdist (y_i(t),co( _L(t)) ),\ e_ _i = _t _v\|e_ _i(t)\|,\\ &e_x_i = _t _v\|e_x_i(t)\|,\ _i^loc= _t _v\|y_i(t)-H_iz_i(t)\|. split The largest point-to-set distance diΦd_i occurs for follower 1, whereas the largest local tracking errors occur for follower 6. The quantity diΦd_i depends on where the realized physical output lies relative to the moving leader hull, whereas the local errors measure how well the attacked plant follows its own command and filtered command. For the two attacked followers the external error is concentrated almost entirely in the output coordinates, i.e. ‖Ciexi‖≈‖exi‖\|C_ie_x_i\|≈\|e_x_i\| on vT_v; hence δiloc _i^loc and eximaxe_x_i coincide to the reported precision for F1 and F6, whereas for the unattacked followers the output component accounts for only about 8%8\% of ‖exi‖\|e_x_i\|. TABLE I: Per-follower maxima on v=[1800,2000]sT_v=[1800,2000]\,s. Follower diΦd_i δiloc _i^loc eximaxe_x_i eηimaxe_ _i F1 7.237.23 7.55×10−37.55×10^-3 7.55×10−37.55×10^-3 6.34×10−26.34×10^-2 F2 5.105.10 1.34×10−51.34×10^-5 1.67×10−41.67×10^-4 1.14×10−41.14×10^-4 F3 3.413.41 1.14×10−51.14×10^-5 1.43×10−41.43×10^-4 9.39×10−59.39×10^-5 F4 0.000.00 1.13×10−51.13×10^-5 1.46×10−41.46×10^-4 9.48×10−59.48×10^-5 F5 0.000.00 1.43×10−51.43×10^-5 1.80×10−41.80×10^-4 1.16×10−41.16×10^-4 F6 0.000.00 9.43×10−19.43×10^-1 9.43×10−19.43×10^-1 7.737.73 Table I summarizes the main evaluation metrics. The command layer reaches a final point-to-set distance of 4.26×10−7m4.26× 10^-7\,m, while the physical outputs achieve practical containment with maximum verification-interval distance 7.23m7.23\,m. The decomposition shows that the dominant term in the residual bound is the command-filter residual Hizi−σiH_iz_i- _i. TABLE I: Main evaluation metric values. Quantity Value Simulation horizon 2000s2000\,s Verification interval [1800,2000]s[1800,2000]\,s Maximum leader speed 24.0m/s24.0\,m/s Maximum leader-hull diameter 706m706\,m Final EσE_σ 1.50×10−5m1.50×10^-5\,m Final DσD_σ 4.26×10−7m4.26×10^-7\,m Max. DσD_σ on vT_v 2.33×10−3m2.33×10^-3\,m Max. DyD_y on vT_v 7.23m7.23\,m Max. ‖Hizi−σi‖\|H_iz_i- _i\| on vT_v 10.5m10.5\,m Max. ‖yi−Hizi‖\|y_i-H_iz_i\| on vT_v 0.943m0.943\,m V Conclusion This work developed a continuous two-layer architecture for resilient practical output containment of heterogeneous linear MIMO followers under actuator attacks and leader-model nondisclosure. The local virtual-actuator layer compensates for state-correlated, input-correlated, and bounded exogenous actuator attack effects in the command-filter tracking-error dynamics. The network layer achieves asymptotic containment of the generated commands over directed leader-rooted graphs without leader-dynamics reconstruction, known leader-motion bounds, or global graph knowledge. The physical-output statement remains practical because implementing the generated task-space command through the selected stable local filter induces the residual characterized in Corollary 1. References [1] Y. Cao, W. Ren, and M. Egerstedt, “Distributed containment control with multiple stationary or dynamic leaders in fixed and switching directed networks,” Automatica, vol. 48, no. 8, p. 1586–1597, 2012. [2] A. Mustafa, H. Modares, and R. Moghadam, “Resilient synchronization of distributed multi-agent systems under attacks,” Automatica, vol. 115, p. 108869, 2020. [3] J. Qin, Q. Ma, X. Yu, and Y. Kang, “Output containment control for heterogeneous linear multiagent systems with fixed and switching topologies,” IEEE Transactions on Cybernetics, vol. 49, no. 12, p. 4117–4128, 2018. [4] W. Huang, H. Liu, and J. Huang, “Distributed robust containment control of linear heterogeneous multi-agent systems: An output regulation approach,” IEEE/CAA Journal of Automatica Sinica, vol. 9, no. 5, p. 864–877, 2022. [5] S. Wang, H. Zhang, and Z. Chen, “Adaptive cooperative tracking and parameter estimation of an uncertain leader over general directed graphs,” IEEE Transactions on Automatic Control, vol. 68, no. 7, p. 3888–3901, 2022. [6] S. Zuo, Y. Song, F. L. Lewis, and A. Davoudi, “Adaptive output containment control of heterogeneous multi-agent systems with unknown leaders,” Automatica, vol. 92, p. 235–239, 2018. [7] Y. Lv, G. Wen, T. Huang, and Z. Duan, “Adaptive attack-free protocol for consensus tracking with pure relative output information,” Automatica, vol. 117, p. 108998, 2020. [8] F. Zhou and Z. Wang, “Containment control of linear multi-agent systems with directed graphs and multiple leaders of time-varying bounded inputs,” IET Control Theory & Applications, vol. 9, no. 16, p. 2466–2473, 2015. [9] Z. Li, X. Liu, W. Ren, and L. Xie, “Distributed tracking control for linear multiagent systems with a leader of bounded unknown input,” IEEE Transactions on Automatic Control, vol. 58, no. 2, p. 518–523, 2012. [10] Z. Qu, “Asymptotic stability of controlling uncertain dynamical systems,” International Journal of Control, vol. 59, no. 5, p. 1345–1355, 1994. [11] H. Wu, “Adaptive robust tracking and model following of uncertain dynamical systems with multiple time delays,” IEEE Transactions on Automatic Control, vol. 49, no. 4, p. 611–616, 2004. [12] P. Wang, G. Wen, W. Yu, T. Huang, and X. Yu, “An adaptive continuous approach to consensus tracking of nonlinear multiagent systems with a nonautonomous leader,” IEEE Transactions on Systems, Man, and Cybernetics: Systems, vol. 53, no. 8, p. 4684–4695, 2023. [13] H. Wang, W. Yu, Z. Ding, and X. Yu, “Tracking consensus of general nonlinear multiagent systems with external disturbances under directed networks,” IEEE Transactions on Automatic Control, vol. 64, no. 11, p. 4772–4779, 2019. [14] S. Xiao and J. Dong, “Distributed fault-tolerant containment control for linear heterogeneous multiagent systems: A hierarchical design approach,” IEEE Transactions on Cybernetics, 2020. [15] H. Tian, P. Wang, and T. Huang, “Fully distributed containment of multiple-input-multiple-output linear multi-agent systems with multiple nonautonomous leaders,” International Journal of Adaptive Control and Signal Processing, vol. 36, no. 10, p. 2604–2619, 2022. [16] D. G. Lui, A. Petrillo, and S. Santini, “Leader tracking control for heterogeneous uncertain nonlinear multi-agent systems via a distributed robust adaptive pid strategy,” Nonlinear Dynamics, vol. 108, no. 1, p. 363–378, 2022. [17] M. Yadegar and N. Meskin, “Fault-tolerant control of nonlinear heterogeneous multi-agent systems,” Automatica, vol. 127, p. 109514, 2021. [18] S. Zuo, Y. Wang, M. Rajabinezhad, and Y. Zhang, “Resilient containment control of heterogeneous multiagent systems against unbounded attacks on sensors and actuators,” IEEE Transactions on Control of Network Systems, vol. 11, no. 3, p. 1537–1547, 2023. [19] X. Jin, W. M. Haddad, and T. Yucelen, “An adaptive control architecture for mitigating sensor and actuator attacks in cyber-physical systems,” IEEE Transactions on Automatic Control, vol. 62, no. 11, p. 6058–6064, 2017. [20] A. Abdessameud, I. G. Polushin, and A. Tayebi, “Distributed coordination of dynamical multi-agent systems under directed graphs and constrained information exchange,” IEEE Transactions on Automatic Control, vol. 62, no. 4, p. 1668–1683, 2016. [21] M. Neumann and R. Plemmons, “M-matrix characterization i: General m-matrices,” Linear and Multilinear Algebra, vol. 9, no. 3, p. 211–225, 1980. [22] M. Mueller, “Normal form for linear systems with respect to its vector relative degree,” Linear algebra and its applications, vol. 430, no. 4, p. 1292–1312, 2009. [23] S. Weerakkody, B. Sinopoli, S. Kar, and A. Datta, “Information flow for security in control systems,” in 2016 IEEE 55th Conference on Decision and Control (CDC). IEEE, 2016, p. 5065–5072. [24] T. R. Oliveira, V. H. P. Rodrigues, and L. Fridman, “Generalized model reference adaptive control by means of global hosm differentiators,” IEEE Transactions on Automatic Control, vol. 64, no. 5, p. 2053–2060, 2018. [25] T. R. Oliveira, A. Estrada, and L. M. Fridman, “Global and exact hosm differentiator with dynamic gains for output-feedback sliding mode control,” Automatica, vol. 81, p. 156–163, 2017. [26] H. Wang, A. J. Kurdila, A. L’Afflitto, D. Oesterheld, and D. J. Stilwell, “Robust model reference adaptive control based on reproducing kernel hilbert spaces,” International Journal of Adaptive Control and Signal Processing, vol. 39, no. 6, p. 1128–1148, 2025. [27] D. I. Oesterheld, D. J. Stilwell, A. J. Kurdila, and J. Guo, “A model reference adaptive controller based on operator-valued kernel functions,” in 2023 62nd IEEE Conference on Decision and Control (CDC). IEEE, 2023, p. 521–528. [28] M. Nematollahi, K. Khorasani, and N. Meskin, “Cyber-resilience certification of cyber-physical systems subject to impactful-stealthy cyber-attacks,” in 2025 IEEE 64th Conference on Decision and Control (CDC). IEEE, 2025, p. 5020–5027. [29] A. Saberi, A. A. Stoorvogel, and P. Sannuti, Control of Linear Systems with Regulation and Input Constraints, ser. Communications and Control Engineering. London: Springer, 2000.