Paper deep dive
Distributed Safe Consensus Under Asymmetric Input and Time-Varying Output Constraints
Abhinav Sinha, Shashi Ranjan Kumar
Intelligence
Status: succeeded | Model: Gemma-4-26B-A4B | Prompt: intel-v1 | Confidence: 98%
Last extracted: 6/20/2026, 4:48:20 AM
Summary
The paper presents a distributed safe-consensus framework for single-integrator multi-agent systems operating over connected undirected graphs. The core contribution is a controller that simultaneously handles asymmetric actuator constraints (modeled via continuously differentiable asymmetric actuator dynamics) and time-varying output safety constraints (modeled via a common time-varying safe interval). The approach utilizes a logarithmic barrier-coordinate transformation to ensure forward invariance of the safe output set and an actuator-side tracking layer to ensure input admissibility. The framework achieves semiglobal safe consensus, meaning that for a compact set of initial conditions, the system ensures complete solutions, bounded signals, strict adherence to asymmetric actuator bounds, and asymptotic synchronization to a designer-selected admissible trajectory.
Entities (8)
Relation Signals (5)
Barrier-coordinate Transformation → addresses → Time-Varying Output Constraints
confidence 100% · To address output safety, a barrier-coordinate transformation is introduced over a common time-varying safe interval
Abhinav Sinha → affiliatedwith → University of Cincinnati
confidence 100% · A. Sinha is with the ... University of Cincinnati
Shashi Ranjan Kumar → affiliatedwith → Indian Institute of Technology Bombay
confidence 100% · S. R. Kumar is with the ... Indian Institute of Technology Bombay
Single-integrator multi-agent systems → operateson → Connected Undirected Graph
confidence 100% · single-integrator multi-agent systems over connected undirected graphs
Asymmetric Actuator Dynamics → imposes → Asymmetric Actuator Constraints
confidence 95% · Each agent is equipped with a continuously differentiable asymmetric actuator dynamics that maps a commanded control signal to the realized plant input while keeping the latter strictly inside a prescribed admissible interval.
Cypher Suggestions (0)
No Cypher suggestions yet.
Abstract
Abstract:This paper studies safe distributed consensus for single-integrator multi-agent systems over connected undirected graphs under simultaneous asymmetric actuator constraints and output safety constraints. Each agent is equipped with a continuously differentiable asymmetric actuator dynamics that maps a commanded control signal to the realized plant input while keeping the latter strictly inside a prescribed admissible interval. To address output safety, a barrier-coordinate transformation is introduced over a common time-varying safe interval, and a distributed synchronization law is designed in the transformed coordinates. The resulting controller integrates a graph-based coordination layer with an actuator-side tracking layer, thereby enabling simultaneous enforcement of input admissibility, forward invariance of the safe output set, and asymptotic synchronization. For compact admissible sets of initial conditions, it is shown that the closed-loop solution is complete, all signals remain bounded, the actuator inputs remain strictly within their asymmetric bounds, and the agent outputs remain inside the prescribed safe interval for all time. Moreover, the transformed synchronization errors converge exponentially to zero, and the original agent outputs asymptotically synchronize to a designer-selected admissible trajectory embedded in the common safe interval. Numerical simulations validate the proposed framework and demonstrate safe consensus under both asymmetric actuation bounds and time-varying output constraints.
Tags
Links
- Source: https://arxiv.org/abs/2606.16116v1
- Canonical: https://arxiv.org/abs/2606.16116v1
Trouble viewing inline? Open PDF directly →
Full Text
80,212 characters extracted from source content.
Expand or collapse full text
Distributed Safe Consensus Under Asymmetric Input and Time-Varying Output Constraints Abhinav Sinha Member, IEEE and Shashi Ranjan Kumar Member, IEEE A. Sinha is with the Guidance, Autonomy, Learning, and Control for Intelligent Systems (GALACxIS) Lab, Department of Aerospace Engineering and Engineering Mechanics, University of Cincinnati, OH 45221, USA. (e-mail: abhinav.sinha@uc.edu). S. R. Kumar is with the Intelligent Systems and Control (ISaC) Lab, Department of Aerospace Engineering, Indian Institute of Technology Bombay, Powai, Mumbai 400076, India. (email: srk@aero.iitb.ac.in). Abstract This paper studies safe distributed consensus for single-integrator multi-agent systems over connected undirected graphs under simultaneous asymmetric actuator constraints and output safety constraints. Each agent is equipped with a continuously differentiable asymmetric actuator dynamics that maps a commanded control signal to the realized plant input while keeping the latter strictly inside a prescribed admissible interval. To address output safety, a barrier-coordinate transformation is introduced over a common time-varying safe interval, and a distributed synchronization law is designed in the transformed coordinates. The resulting controller integrates a graph-based coordination layer with an actuator-side tracking layer, thereby enabling simultaneous enforcement of input admissibility, forward invariance of the safe output set, and asymptotic synchronization. For compact admissible sets of initial conditions, it is shown that the closed-loop solution is complete, all signals remain bounded, the actuator inputs remain strictly within their asymmetric bounds, and the agent outputs remain inside the prescribed safe interval for all time. Moreover, the transformed synchronization errors converge exponentially to zero, and the original agent outputs asymptotically synchronize to a designer-selected admissible trajectory embedded in the common safe interval. Numerical simulations validate the proposed framework and demonstrate safe consensus under both asymmetric actuation bounds and time-varying output constraints. IEEEkeywords Multi-agent systems, safe consensus, asymmetric actuator constraints, output constraints, distributed control, constrained coordination. 1 Introduction Distributed consensus is crucial in networked control systems and multi-agent coordination. Over the past two decades, consensus theory [1, 2, 3, 4, 5] has developed into a mature field. Despite these advances, much of the existing literature remains idealized from the standpoint of implementation, i.e., the control channel is often assumed to be unconstrained or only implicitly constrained, while safety requirements on the agent outputs are either neglected or treated separately from the consensus objective [1, 6, 7]. In practical multi-agent systems, the control action is delivered through physical actuators with finite capabilities, and these capabilities are often asymmetric. For instance, acceleration and braking authority may differ in ground vehicles, thrust and reverse-thrust limits may differ in marine platforms, and positive and negative rate limits may be inherently unequal in aerospace and robotic systems [8, 9, 10]. If such asymmetries are ignored during controller synthesis, the resulting distributed law may request infeasible inputs, degrade performance, or even invalidate the closed-loop guarantees. At the same time, many safety-critical tasks require each agent to evolve within a prescribed admissible output interval or corridor, either because of operational envelopes, mission-level safety requirements, or environment-induced restrictions [11, 12, 13, 7, 14, 15]. Thus, a practically meaningful safe-consensus design must enforce both input admissibility and output safety while preserving distributed coordination. Existing results address important parts of this problem, but not the complete unified treatment considered here. Consensus algorithms with saturated or bounded inputs have established valuable coordination guarantees, yet they often rely on symmetric saturation descriptions, nonsmooth clipping operators, or input constraints that are not embedded directly into the plant-actuator dynamics [16, 17, 18, 19, 20, 21, 22]. On the other hand, barrier-based and safety-critical multi-agent methods provide powerful tools for set invariance and collision avoidance, but actuator admissibility is often treated implicitly, through external filtering, or as an auxiliary layer appended to a nominal controller [23, 24, 15, 25, 6, 7, 26, 20, 27]. Consequently, a unified distributed design that simultaneously guarantees strict asymmetric actuator admissibility, time-varying output safety, and asymptotic synchronization remains an open and practically relevant problem. Motivated by this gap, this paper develops a distributed safe-consensus framework for single-integrator multi-agent systems over connected undirected graphs under simultaneous asymmetric input constraints and time-varying output constraints. The proposed architecture blends an actuator-side tracking layer with a graph-based coordination law. For output safety, a logarithmic barrier-coordinate transformation is introduced over a common admissible core interval. In the transformed coordinates, a distributed synchronization law with a pinning term drives the agents toward a prescribed admissible reference trajectory embedded inside the safe interval. The proposed design treats actuator feasibility and output safety as integral components of the distributed controller architecture and simultaneously achieves: (i) strict enforcement of agent-wise asymmetric actuator bounds through a continuously differentiable asymmetric actuator dynamics, (i) rigorous forward invariance of a common time-varying safe interval, and (i) asymptotic synchronization to a designer-selected admissible trajectory using only local graph interactions. The proposed approach is also distinct from funnel-control and prescribed-performance methods [25, 22]. Funnel-control designs typically constrain tracking or formation errors to remain within prescribed transient envelopes, thereby shaping the evolution of an error variable. However, the present work imposes safety directly on the agent outputs through a common time-varying admissible core and then performs distributed synchronization in the corresponding barrier coordinates. Moreover, the proposed design assigns a designer-selected admissible trajectory and proves asymptotic synchronization to this trajectory, rather than only maintaining an error inside a prescribed funnel. Most importantly, the present framework treats asymmetric actuator limits as part of the plant-actuator dynamics and proves the strict admissibility of the realized inputs together with the forward invariance of the output safe set. Thus, input feasibility, output safety, and distributed synchronization are addressed in a single closed-loop analysis. The main contributions of this paper are as follows. • We formulate a distributed consensus problem for single-integrator multi-agent systems under simultaneous asymmetric input constraints and time-varying output safety constraints, where the actuator bounds are embedded directly into the agent dynamics through a continuously differentiable asymmetric actuator dynamics. • We develop a distributed controller for the input-constrained case that combines a graph-based nominal consensus law with an actuator-tracking layer and guarantees completeness of solutions, boundedness of all closed-loop signals, strict satisfaction of asymmetric actuator bounds, and asymptotic consensus on compact admissible initial sets. • For the safe-consensus problem, we introduce a barrier-coordinate distributed synchronization law over a common time-varying admissible interval and establish forward invariance of the safe set, strict input admissibility, exponential convergence of the transformed synchronization error, and asymptotic synchronization of the original agent outputs. We show that incorporating a pinning term in the transformed coordinates allows the proposed design to achieve synchronization to a designer-selected admissible trajectory inside the common safe interval, which is stronger than consensus to an unspecified limit. • The analysis is developed in a self-contained semiglobal framework that avoids auxiliary a priori boundedness assumptions and yields explicit gain and interiority conditions ensuring well-posedness and safety of the closed-loop system. 2 Problem Formulation Let ℝR, ℝ>0R_>0, and ℝ≥0R_≥ 0 denote the sets of real, positive real, and nonnegative real numbers, respectively. For a vector ∈ℝNx ^N, ‖\|x\| denotes the Euclidean norm. The symbols N∈ℝN1_N ^N and N∈ℝN0_N ^N denote the vectors of all ones and all zeros, respectively, while INI_N denotes the N×N× N identity matrix. For scalars aia_i, i∈1,…,Ni∈\1,…,N\, cola1,…,aNcol\a_1,…,a_N\ denotes the stacked column vector and diaga1,…,aNdiag\a_1,…,a_N\ denotes the corresponding diagonal matrix. Consider a weighted undirected graph =(,ℰ,A)G= (V,E,A ), where =1,2,…,NV=\1,2,…,N\ is the node set, ℰ⊆×E ×V is the edge set, and A=[aij]∈ℝN×NA=[a_ij] ^N× N is the adjacency matrix satisfying aij=aji≥0,aii=0a_ij=a_ji≥ 0,~a_i=0, and aij>0⇔(i,j)∈ℰa_ij>0 (i,j) . The neighbor set of agent i is defined by i=j∈:(i,j)∈ℰN_i=\j :(i,j) \. The degree matrix and Laplacian matrix associated with G are defined as D=diagd1,…,dND=diag\d_1,…,d_N\ with di=∑j=1Naijd_i= _j=1^Na_ij and L=D−AL=D-A. Throughout the paper, the following standing assumption is imposed. Assumption 1. The graph G is undirected and connected. Under Assumption 1, the Laplacian satisfies L=L⊤≥0L=L ≥ 0, LN=NL1_N=0_N, and its eigenvalues can be ordered as 0=λ1(L)<λ2(L)≤⋯≤λN(L)0= _1(L)< _2(L)≤·s≤ _N(L). Define the consensus subspace :=spanN=∈ℝN:x1=⋯=xNC:=span\1_N\=\x ^N:x_1=·s=x_N\, and the orthogonal projection onto ⟂C by Π:=IN−1NNN⊤ :=I_N- 1N1_N1_N . For any stacked state vector =colx1,…,xNx=col\x_1,…,x_N\, the disagreement vector is defined as ~:=Π x:= . Clearly, ~=N x=0_N if and only if ∈x . Consider a network of N single-integrator agents whose plant dynamics are given by x˙i=ui,yi=xi,i∈, x_i=u_i,~~y_i=x_i,~~i , (1) where xi∈ℝx_i is the state of agent i, yi∈ℝy_i is the measured output111Since yi=xiy_i=x_i in (1), output constraints and state constraints are identical in the present setting. Therefore, these terms are used interchangeably whenever no confusion arises., and ui∈ℝu_i is the actual input delivered to the plant. To explicitly account for actuator limitations [28], we distinguish between the commanded signal viv_i generated by the controller and the actual plant input uiu_i. For each agent i, the actuator is modeled by an asymmetric actuator dynamics whose regularization factor is continuously differentiable on the admissible input interval and vanishes only at the actuator boundaries u˙i=p1,iσi(ui)vi−p2,iui, u_i=p_1,i\, _i(u_i)\,v_i-p_2,iu_i, (2) where p1,i∈ℝ>0p_1,i _>0, p2,i∈ℝ>0p_2,i _>0, and σi(ui):=ϱi(1−(uiu¯i)γi)+(1−ϱi)(1−(uiu¯i)γi), _i(u_i):= _i (1- ( u_i u_i ) _i )+(1- _i) (1- ( u_i u_i ) _i ), (3) with ϱi:=1 _i:=1 if ui>0u_i>0 and 0 otherwise, and γi=2ni∀ni∈ℕ _i=2n_i~∀~n_i . Here, u¯i<0<u¯i u_i<0< u_i denote the lower and upper admissible actuator limits of agent i. Remark 1. In general, the actuator bounds are asymmetric, that is, |u¯i|≠|u¯i|| u_i|≠| u_i|. Therefore, the available control authority in the positive and negative directions need not be identical. For each agent i, define the admissible input set i:=u∈ℝ:u¯i<u<u¯iU_i:=\u : u_i<u< u_i\, and the network-level admissible input set :=1×⋯×NU:=U_1×·s×U_N. The stacked plant and actuator states are denoted by :=colx1,…,xNx:=col\x_1,…,x_N\, :=colu1,…,uNu:=col\u_1,…,u_N\, and :=colv1,…,vNv:=col\v_1,…,v_N\. The following assumption ensures that the actuator dynamics are well posed and that the initial actuator states are admissible. Assumption 2. For each i∈i , the constants p1,ip_1,i, p2,ip_2,i, u¯i u_i, u¯i u_i, and γi _i satisfy p1,i>0,p2,i>0,u¯i<0<u¯i,γi=2nip_1,i>0,~p_2,i>0,~ u_i<0< u_i,~ _i=2n_i, and the initial actuator state satisfies ui(0)∈iu_i(0) _i. In addition to actuator constraints, each agent is required to satisfy a possibly time-varying output constraint of the form xi(t)∈i(t),∀t≥0x_i(t) _i(t),~∀ t≥ 0, where i(t):=x∈ℝ:x¯i(t)<x<x¯i(t)X_i(t):=\x : x_i(t)<x< x_i(t)\, and x¯i(⋅) x_i(·) and x¯i(⋅) x_i(·) denote the lower and upper safety bounds associated with agent i. Define the admissible network state set at time t as (t):=1(t)×⋯×N(t)X(t):=X_1(t)×·s×X_N(t). Since consensus requires all states to asymptotically agree, a necessary feasibility condition is that the individual admissible intervals admit a nonempty common intersection. To this end, define the consensus-feasible set ∩(t):=⋂i=1Ni(t)=(max1≤i≤Nx¯i(t),min1≤i≤Nx¯i(t))X_∩(t):= _i=1^NX_i(t)= ( _1≤ i≤ N x_i(t), _1≤ i≤ N x_i(t) ). The following assumption is adopted for the output-constrained consensus problem. Assumption 3. For each i∈i , the functions x¯i:ℝ≥0→ℝ x_i:R_≥ 0 and x¯i:ℝ≥0→ℝ x_i:R_≥ 0 are continuously differentiable and satisfy x¯i(t)<x¯i(t),∀t≥0 x_i(t)< x_i(t),~∀ t≥ 0. Moreover, there exists a constant δx>0 _x>0 such that min1≤i≤Nx¯i(t)−max1≤i≤Nx¯i(t)≥δx,∀t≥0 _1≤ i≤ N x_i(t)- _1≤ i≤ N x_i(t)≥ _x,~~∀ t≥ 0, that is, ∩(t)≠∅X_∩(t)≠ for all t≥0t≥ 0. Assumption 3 is necessary for the safe consensus problem to be meaningful, since asymptotic agreement is impossible if the admissible intervals do not share a common feasible region. We consider dynamic distributed controllers of the form η˙i η_i =Φi(ηi,xi,ui,xj−xij∈i,uj−uij∈i,t), = _i ( _i,x_i,u_i,\x_j-x_i\_j _i,\u_j-u_i\_j _i,t ), (4) vi v_i =Ψi(ηi,xi,ui,xj−xij∈i,uj−uij∈i,t), = _i ( _i,x_i,u_i,\x_j-x_i\_j _i,\u_j-u_i\_j _i,t ), (5) where ηi∈ℝqi _i ^q_i is the controller state of agent i, and the mappings Φi _i and Ψi _i are locally Lipschitz in their state arguments and piecewise continuous in time. The stacked controller state is denoted by :=colη1,…,ηN η:=col\ _1,…, _N\, with total dimension q:=∑i=1Nqiq:= _i=1^Nq_i. The controller class (4)–(5) formalizes the distributed-information constraint that each agent may only use its own variables and relative information available from neighboring agents. Definition 1. A solution of the closed-loop system consisting of (1), (2), and (4)–(5) is said to be complete if it is defined on the entire interval [0,∞)[0,∞). Definition 2. The closed-loop multi-agent system is said to achieve asymptotic consensus if every complete solution satisfies limt→∞‖Π(t)‖=0 _t→∞\| (t)\|=0. Equivalently, limt→∞|xi(t)−xj(t)|=0,∀i,j∈ _t→∞|x_i(t)-x_j(t)|=0,~∀ i,j . Definition 3. The closed-loop multi-agent system is said to achieve safe consensus if it achieves asymptotic consensus and, in addition, satisfies (t)∈,(t)∈(t),∀t≥0u(t) ,~x(t) (t),~∀ t≥ 0. We now formulate the two problems addressed in this paper. Problem 1 (Distributed consensus under asymmetric bounded inputs). Consider the networked system (1)–(2) over the graph G satisfying Assumptions 1 and 2. Design a distributed controller of the form (4)–(5) such that, for every compact set ⊂ℝN×ℝqK ^N×U×R^q, there exist controller parameters for which, for all initial conditions ((0),(0),(0))∈ (x(0),u(0), η(0) ) , the following properties hold: (i) the corresponding closed-loop solution is complete; (i) the input constraints are satisfied for all time, namely (t)∈,∀t≥0u(t) ,~∀ t≥ 0; (i) the network achieves asymptotic consensus, that is, limt→∞‖Π(t)‖=0 _t→∞\| (t)\|=0; and (iv) all closed-loop signals remain bounded on [0,∞)[0,∞). When the above properties hold for all admissible initial conditions, the closed-loop system is said to achieve semiglobal consensus under asymmetric bounded inputs. Problem 2 (Safe distributed consensus under simultaneous input and output constraints). Consider the networked system (1)–(2) over the graph G satisfying Assumptions 1 to 3. Design a distributed controller of the form (4)–(5) such that, for every compact set ⊂(0)×ℝqK (0)×U×R^q, there exist controller parameters for which, for all initial conditions ((0),(0),(0))∈ (x(0),u(0), η(0) ) , the following properties hold: (i) the corresponding closed-loop solution is complete; (i) the input constraints are satisfied for all time, namely (t)∈,∀t≥0u(t) ,~∀ t≥ 0; (i) the output constraints are satisfied for all time, namely (t)∈(t),∀t≥0x(t) (t),~∀ t≥ 0; (iv) the network achieves asymptotic consensus, that is, limt→∞‖Π(t)‖=0 _t→∞\| (t)\|=0; and (v) all closed-loop signals remain bounded on [0,∞)[0,∞). When the above properties hold for every compact admissible initial set K, the closed-loop system is said to achieve semiglobal safe consensus under simultaneous input and output constraints. Remark 2. Problems 1 and 2 concern asymptotic agreement, not necessarily average consensus. Since actuator dynamics (2) introduces additional internal dynamics between the commanded signal viv_i and the realized input uiu_i, preservation of the arithmetic average of the initial states is not imposed a priori. Remark 3. The safe consensus objective in Problem 2 is posed in a semiglobal sense because the state constraints define an open admissible set, and forward invariance must be guaranteed simultaneously with convergence of the network disagreement dynamics. 3 Main Results For each agent i∈i , define the nominal consensus input αi():=−k∑j=1Naij(xi−xj),k∈ℝ>0, _i(x):=-k _j=1^Na_ij(x_i-x_j),~~k _>0, (6) and the actuator-tracking error εi:=ui−αi(). _i:=u_i- _i(x). (7) The distributed commanded input is chosen as vi=p2,iui+α˙i(,)−ciεip1,iσi(ui),ci∈ℝ>0, v_i= p_2,iu_i+ α_i(x,u)-c_i _ip_1,i _i(u_i),~~c_i _>0, (8) where the term α˙i(,) α_i(x,u) is defined as α˙i(,)=−k∑j=1Naij(ui−uj). α_i(x,u)=-k _j=1^Na_ij(u_i-u_j). (9) Proposition 1. Consider the closed-loop system consisting of (1), (2), and (8). Let :=colε1,…,εN,~:=Π :=col\ _1,…, _N\,~ x:= . Then, on every interval on which the closed-loop solution is well defined and satisfies (t)∈u(t) , one has the following dynamics ε˙i=−ciεi,i∈, _i=-c_i _i,~~i , (10) and ~˙=−kL~+Π. x=-kL x+ . (11) Proof. Differentiating (7) with respect to time and using (2) together with (8) gives ε˙i _i =p1,iσi(ui)vi−p2,iui−α˙i =p_1,i _i(u_i)v_i-p_2,iu_i- α_i =p1,iσi(ui)p2,iui+α˙i−ciεip1,iσi(ui)−p2,iui−α˙i, =p_1,i _i(u_i) p_2,iu_i+ α_i-c_i _ip_1,i _i(u_i)-p_2,iu_i- α_i, (12) which proves (10). Since x˙i=ui=αi+εi x_i=u_i= _i+ _i, we also have ˙=−kL+. x=-kLx+ . (13) Applying Π and using ΠL=LΠ=L L=L =L yields (11). ∎ Theorem 1. Suppose Assumptions 1 and 2 hold. Let ⊂ℝN×K ^N×U be a compact set of initial conditions. For each (0,0)∈(x_0,u_0) , define 0:=0+kL0, _0:=u_0+kLx_0, (14) and introduce the compact-set radius R:=sup(0,0)∈(‖Π0‖2+‖0‖2)12R_K:= _(x_0,u_0) (\| _0\|^2+\| _0\|^2 ) 12. For each agent i∈i , let r¯i:=minu¯i,−u¯i r_i:= \ u_i,- u_i\, and define ri,:=(2kdi+1)Rr_i,K:=(2kd_i+1)R_K. Assume that cmin:=min1≤i≤Nci>12kλ2(L)c_ := _1≤ i≤ Nc_i> 12k _2(L), and ri,<r¯i,∀i∈. r_i,K< r_i,~~∀ i . (15) Then, for every initial condition ((0),(0))∈(x(0),u(0)) , the closed-loop system consisting of (1), (2), and (8) admits a unique complete solution satisfying the following properties: 1. the actuator inputs remain strictly admissible for all time, i.e., ui(t)∈i,∀t≥0,∀i∈; u_i(t) _i,~~∀ t≥ 0,\ ∀ i ; (16) 2. the actuator-tracking errors satisfy, i.e., εi(t)=e−citεi(0),∀t≥0,∀i∈; _i(t)=e^-c_it _i(0),~~∀ t≥ 0,\ ∀ i ; (17) 3. the disagreement and actuator-tracking errors satisfy the estimate, i.e., ‖~(t)‖2+‖(t)‖2≤e−ηct(‖~(0)‖2+‖(0)‖2),∀t≥0, \| x(t)\|^2+\| (t)\|^2≤ e^- _ct (\| x(0)\|^2+\| (0)\|^2 ),~∀ t≥ 0, (18) where the term ηc _c is defined as ηc:=minkλ2(L), 2cmin−1kλ2(L)>0; _c:= \k _2(L),\,2c_ - 1k _2(L) \>0; (19) 4. there exists a finite constant x∞∈ℝx_∞ such that limt→∞xi(t)=x∞,∀i∈; _t→∞x_i(t)=x_∞,~~∀ i ; (20) 5. the commanded inputs viv_i are bounded on [0,∞)[0,∞), and all closed-loop signals remain bounded. Consequently, the controller (8) solves Problem 1 on the compact admissible set K. Proof. Fix an arbitrary initial condition ((0),(0))∈(x(0),u(0)) . Since (0)∈u(0) and σi(ui(0))>0 _i(u_i(0))>0 for all i, the closed-loop vector field is well defined at t=0t=0, and hence a unique local solution exists on some maximal interval [0,Tmax)[0,T_ ). Consider the Lyapunov function candidate V:=12‖~‖2+12‖2. V:= 12\| x\|^2+ 12\| \|^2. (21) Along (10) and (11), the derivative V˙ V can be written as V˙ V =~⊤(−kL~+Π)−⊤C = x (-kL x+ )- C =−k~⊤L~+~⊤Π−⊤C. =-k x L x+ x - C . (22) Since ~∈⟂ x and G is connected, ~⊤L~≥λ2(L)‖~‖2. x L x≥ _2(L)\| x\|^2. (23) Also, ‖Π‖≤‖\| \|≤\| \|, so Young’s inequality yields ~⊤Π≤kλ2(L)2‖~‖2+12kλ2(L)‖2. x ≤ k _2(L)2\| x\|^2+ 12k _2(L)\| \|^2. (24) Substituting (23) and (24) into (22), we obtain V˙≤−kλ2(L)2‖~‖2−(cmin−12kλ2(L))‖2. V≤- k _2(L)2\| x\|^2- (c_ - 12k _2(L) )\| \|^2. (25) By the gain condition cminc_ , the constant ηc _c defined in (19) is strictly positive, and thus V˙≤−ηcV V≤- _cV. Therefore, V(t)≤e−ηctV(0),∀t∈[0,Tmax)V(t)≤ e^- _ctV(0),~∀ t∈[0,T_ ). This proves (18) on [0,Tmax)[0,T_ ). Indeed, ‖~(t)‖≤R,‖(t)‖≤R,∀t∈[0,Tmax). \| x(t)\|≤ R_K,~~\| (t)\|≤ R_K,~~∀ t∈[0,T_ ). (26) From (6), |αi(t)|=k|∑j=1Naij(xi−xj)|=k|∑j=1Naij(x~i−x~j)|| _i(t)|=k | _j=1^Na_ij(x_i-x_j) |=k | _j=1^Na_ij( x_i- x_j) | reduces to |αi(t)|≤k∑j=1Naij(|x~i|+|x~j|)≤2kdi‖~(t)‖≤2kdiR| _i(t)|≤ k _j=1^Na_ij (| x_i|+| x_j| )≤ 2kd_i\| x(t)\|≤ 2kd_iR_K, and hence |ui(t)|≤|αi(t)|+|εi(t)|≤(2kdi+1)R=ri,∀t∈[0,Tmax)|u_i(t)|≤| _i(t)|+| _i(t)|≤(2kd_i+1)R_K=r_i,K~∀ t∈[0,T_ ). By (15), this implies ui(t)∈[−ri,,ri,]⊂(u¯i,u¯i),∀t∈[0,Tmax),∀i∈. u_i(t)∈[-r_i,K,r_i,K]⊂( u_i, u_i),∀ t∈[0,T_ ),∀ i . (27) Thus, (16) holds on [0,Tmax)[0,T_ ), and σi(ui(t))≥σ¯i,:=min1−(ri,u¯i)γi, 1−(ri,−u¯i)γi>0 _i(u_i(t))≥ σ_i,K:= \1- ( r_i,K u_i ) _i,\,1- ( r_i,K- u_i ) _i \>0 for all t∈[0,Tmax)t∈[0,T_ ). Also, from (9), |α˙i(t)|=k|∑j=1Naij(ui−uj)|≤k∑j=1Naij(|ui|+|uj|)≤2kdirmax| α_i(t)|=k | _j=1^Na_ij(u_i-u_j) |≤ k _j=1^Na_ij (|u_i|+|u_j| )≤ 2kd_ir_K , where rmax:=max1≤ℓ≤Nrℓ,r_K := _1≤ ≤ Nr_ ,K. Therefore, from (8), |vi(t)|≤p2,iri,+2kdirmax+ciRp1,iσ¯i,=:v¯i,, |v_i(t)|≤ p_2,ir_i,K+2kd_ir_K +c_iR_Kp_1,i σ_i,K=: v_i,K, (28) ∀t∈[0,Tmax)∀ t∈[0,T_ ). Hence, the commanded inputs are bounded on [0,Tmax)[0,T_ ). To show the completeness, define the network average x¯(t):=1NN⊤(t) x(t):= 1N1_N x(t). Premultiplying ˙=−kL+ x=-kLx+ by 1NN⊤ 1N1_N yields x¯˙(t)=1NN⊤(t). x(t)= 1N1_N (t). (29) Since (17) holds on [0,Tmax)[0,T_ ), |x¯(t)| | x(t)| ≤|x¯(0)|+1N∫0t‖(s)‖s ≤| x(0)|+ 1 N _0^t\| (s)\|\,ds ≤|x¯(0)|+RNcmin,∀t∈[0,Tmax). ≤| x(0)|+ R_K Nc_ ,~~∀ t∈[0,T_ ). (30) Thus, (t)=x¯(t)N+~(t)x(t)= x(t)1_N+ x(t) is bounded on [0,Tmax)[0,T_ ) by (30) and (26). Together with (27) and (28), this shows that all closed-loop signals remain in a compact subset of the domain of the closed-loop vector field on [0,Tmax)[0,T_ ). Therefore, by the continuation theorem for ordinary differential equations, finite escape is impossible, and thus Tmax=∞T_ =∞. Now, (17) follows from (10), and (18) implies ~(t)→ x(t) 0 exponentially. Since x¯˙(⋅) x(·) is integrable on [0,∞)[0,∞) by (29) and (17), the average converges to a finite limit x∞:=x¯(0)+1N∫0∞N⊤(s)s. x_∞:= x(0)+ 1N _0^∞1_N (s)\,ds. (31) Hence, (20) follows from (t)=x¯(t)N+~(t)x(t)= x(t)1_N+ x(t). ∎ Remark 4. Theorem 1 is semiglobal with respect to compact admissible initial sets. The interiority condition (15) is explicit and checks, a priori, that the realized actuator inputs remain in a strict interior subset of their admissible intervals. This avoids any need to assume boundedness of the commanded inputs or positivity of σi(ui) _i(u_i) along the trajectory. Remark 5. The interiority condition in (15) is conservative because it guarantees admissibility by placing the realized input ui(t)u_i(t) inside a symmetric compact subinterval [−ri,,ri,][-r_i,K,r_i,K] contained in the generally asymmetric admissible set iU_i. This choice leads to a compact semiglobal proof and provides a simple a priori check for strict actuator admissibility. Less conservative conditions could be obtained by deriving separate one-sided bounds on the positive and negative excursions of ui(t)u_i(t), but such refinements are not pursued here. To treat the safe-consensus problem, we strengthen the safe-set description by requiring the existence of a common time-varying admissible core interval. Assumption 4. For all time t≥0t≥ 0, there exist functions ξ¯,ξ¯:ℝ≥0→ℝ ξ, ξ:R_≥ 0 of class C2C^2 and positive constants δξ _ξ, Δξ _ξ, ξ¯0 ξ_0, d¯ξ d_ξ, and s¯ξ s_ξ such that x¯i(t)<ξ¯(t)<ξ¯(t)<x¯i(t) x_i(t)< ξ(t)< ξ(t)< x_i(t), for all i∈i and t≥0t≥ 0 with δξ≤ξ¯(t)−ξ¯(t)≤Δξ, _ξ≤ ξ(t)- ξ(t)≤ _ξ, (32) |ξ¯(t)|+|ξ¯(t)|≤ξ¯0, | ξ(t)|+| ξ(t)|≤ ξ_0, (33) and |ξ¯˙(t)|+|ξ¯˙(t)|≤d¯ξ,|ξ¯¨(t)|+|ξ¯¨(t)|≤s¯ξ. | ξ(t)|+| ξ(t)|≤ d_ξ,~~| ξ(t)|+| ξ(t)|≤ s_ξ. (34) Let the common admissible core interval (see Figure 1) be Ω(t):=(ξ¯(t),ξ¯(t)),t≥0, (t):= ( ξ(t), ξ(t) ),~~t≥ 0, (35) and x⋆:ℝ≥0→ℝx :R_≥ 0 be a prescribed admissible trajectory satisfying x⋆(t)∈Ω(t)⊆i(t),x (t)∈ (t) _i(t), ∀i∈,∀t≥0∀ i ,~∀ t≥ 0. Define the transformed prescribed trajectory z⋆(t):=ln(x⋆(t)−ξ¯(t)ξ¯(t)−x⋆(t)),t≥0. z (t):= ( x (t)- ξ(t) ξ(t)-x (t) ),~~t≥ 0. (36) Assume that z⋆z is of class C2C^2 and that there exist positive constants z¯⋆ z_ , d¯⋆ d_ , and s¯⋆ s_ such that |z⋆(t)|≤z¯⋆,|z˙⋆(t)|≤d¯⋆,|z¨⋆(t)|≤s¯⋆,∀t≥0. |z (t)|≤ z_ ,~~| z (t)|≤ d_ ,~~| z (t)|≤ s_ ,~~∀ t≥ 0. (37) For each agent i, let the barrier coordinate be zi:=ln(xi−ξ¯(t)ξ¯(t)−xi). z_i:= ( x_i- ξ(t) ξ(t)-x_i ). (38) Lemma 1. For each fixed t≥0t≥ 0, the mapping φt(x):=ln(x−ξ¯(t)ξ¯(t)−x),x∈Ω(t), _t(x):= ( x- ξ(t) ξ(t)-x ),~~x∈ (t), (39) is a C1C^1-diffeomorphism from Ω(t) (t) onto ℝR, with inverse φt−1(z)=ξ¯(t)+ξ¯(t)ez1+ez. _t^-1(z)= ξ(t)+ ξ(t)e^z1+e^z. (40) Moreover, along every differentiable trajectory satisfying xi(t)∈Ω(t)x_i(t)∈ (t), one has z˙i=bi(xi,t)ui+di(xi,t) z_i=b_i(x_i,t)u_i+d_i(x_i,t), where bi(xi,t):= b_i(x_i,t):= ξ¯(t)−ξ¯(t)(xi−ξ¯(t))(ξ¯(t)−xi), ξ(t)- ξ(t) (x_i- ξ(t) ) ( ξ(t)-x_i ), (41) di(xi,t):= d_i(x_i,t):= −ξ¯˙(t)xi−ξ¯(t)−ξ¯˙(t)ξ¯(t)−xi. - ξ(t)x_i- ξ(t)- ξ(t) ξ(t)-x_i. (42) Proof. Fix an arbitrary t≥0t≥ 0. Using (35) and Assumption 4 gives ξ¯(t)<ξ¯(t) ξ(t)< ξ(t). Hence, for every x∈Ω(t)x∈ (t), one has x−ξ¯(t)>0x- ξ(t)>0 and ξ¯(t)−x>0 ξ(t)-x>0. Therefore, the map (39) is well defined on Ω(t) (t). Moreover, φt(x)=ln(x−ξ¯(t))−ln(ξ¯(t)−x) _t(x)= (x- ξ(t) )- ( ξ(t)-x ) is continuously differentiable with respect to x on Ω(t) (t), and ∂φt∂x(x) ∂ _t∂ x(x) =1x−ξ¯(t)+1ξ¯(t)−x = 1x- ξ(t)+ 1 ξ(t)-x =ξ¯(t)−ξ¯(t)(x−ξ¯(t))(ξ¯(t)−x)>0. = ξ(t)- ξ(t) (x- ξ(t) ) ( ξ(t)-x )>0. (43) Consequently, φt _t is strictly increasing on Ω(t) (t) and is therefore one-to-one. In addition, using (39), limx→ξ¯(t)+φt(x)=−∞ _x→ ξ(t)^+ _t(x)=-∞, and limx→ξ¯(t)−φt(x)=+∞ _x→ ξ(t)^- _t(x)=+∞. Since φt _t is continuous and strictly increasing on Ω(t) (t), the previous limits imply that φt(Ω(t))=ℝ _t( (t))=R. Hence, φt _t is bijective from Ω(t) (t) onto ℝR. We next compute its inverse. Let z=φt(x)z= _t(x). Then ez=x−ξ¯(t)ξ¯(t)−xe^z= x- ξ(t) ξ(t)-x can be rearranged to obtain ez(ξ¯(t)−x)=x−ξ¯(t)e^z ( ξ(t)-x )=x- ξ(t) and therefore x=ξ¯(t)+ξ¯(t)ez1+ezx= ξ(t)+ ξ(t)e^z1+e^z. This proves the inverse expression in (40). Furthermore, for every z∈ℝz , (40) gives φt−1(z)−ξ¯(t)=(ξ¯(t)−ξ¯(t))ez1+ez>0 _t^-1(z)- ξ(t)= ( ξ(t)- ξ(t) )e^z1+e^z>0 and ξ¯(t)−φt−1(z)=ξ¯(t)−ξ¯(t)1+ez>0 ξ(t)- _t^-1(z)= ξ(t)- ξ(t)1+e^z>0. Thus, φt−1(z)∈Ω(t) _t^-1(z)∈ (t) for all z∈ℝz . Also, ∂φt−1∂z(z)=(ξ¯(t)−ξ¯(t))ez(1+ez)2 ∂ _t^-1∂ z(z)= ( ξ(t)- ξ(t) ) e^z (1+e^z )^2 which is continuous in z. Thus, φt−1 _t^-1 is continuously differentiable. Combining this fact with (43), φt _t is a C1C^1-diffeomorphism from Ω(t) (t) onto ℝR. It remains to establish the transformed dynamics. Let xi(⋅)x_i(·) be any differentiable trajectory satisfying xi(t)∈Ω(t)x_i(t)∈ (t), and define ziz_i as in (38). Differentiating along the trajectory yields z˙i z_i =x˙i−ξ¯˙(t)xi−ξ¯(t)−ξ¯˙(t)−x˙iξ¯(t)−xi = x_i- ξ(t)x_i- ξ(t)- ξ(t)- x_i ξ(t)-x_i =[1xi−ξ¯(t)+1ξ¯(t)−xi]x˙i−ξ¯˙(t)xi−ξ¯(t)−ξ¯˙(t)ξ¯(t)−xi = [ 1x_i- ξ(t)+ 1 ξ(t)-x_i ] x_i- ξ(t)x_i- ξ(t)- ξ(t) ξ(t)-x_i =ξ¯(t)−ξ¯(t)(xi−ξ¯(t))(ξ¯(t)−xi)x˙i−ξ¯˙(t)xi−ξ¯(t)−ξ¯˙(t)ξ¯(t)−xi. = ξ(t)- ξ(t) (x_i- ξ(t) ) ( ξ(t)-x_i ) x_i- ξ(t)x_i- ξ(t)- ξ(t) ξ(t)-x_i. (44) Using (1) and comparing (44) with (41) and (42), we obtain z˙i=bi(xi,t)ui+di(xi,t) z_i=b_i(x_i,t)u_i+d_i(x_i,t). This proves the claimed transformed dynamics and completes the proof. ∎ Define the transformed synchronization input βi:=z˙⋆(t)−kz∑j=1Naij(zi−zj)−κ(zi−z⋆(t)), _i:= z (t)-k_z _j=1^Na_ij(z_i-z_j)-κ (z_i-z (t) ), (45) where kz,κ∈ℝ>0k_z,κ _>0. Let αi:=βi−di(xi,t)bi(xi,t), _i:= _i-d_i(x_i,t)b_i(x_i,t), (46) and define the actuator-tracking error associated with the safe-consensus virtual input as εi:=ui−αi,i∈. _i:=u_i- _i,~~i . (47) The commanded input is then chosen as vi=p2,iui+α˙i−ciεip1,iσi(ui),ci∈ℝ>0. v_i= p_2,iu_i+ α_i-c_i _ip_1,i _i(u_i),~~c_i _>0. (48) Remark 6. The term α˙i α_i in the commanded signal can be evaluated without introducing any nonlocal information or algebraic dependence on viv_i. Indeed, direct differentiation of (46) gives α˙i=β˙i−d˙ibi−(βi−di)b˙ibi2 α_i= β_i- d_ib_i- ( _i-d_i ) b_ib_i^2, where, along the closed-loop trajectories, b˙i=∂bi∂xiui+∂bi∂t b_i= ∂ b_i∂ x_iu_i+ ∂ b_i∂ t and d˙i=∂di∂xiui+∂di∂t d_i= ∂ d_i∂ x_iu_i+ ∂ d_i∂ t. Furthermore, differentiating (45) yields β˙i=z¨⋆(t)−kz∑j=1Naij(z˙i−z˙j)−κ(z˙i−z˙⋆(t)) β_i= z (t)-k_z _j=1^Na_ij ( z_i- z_j )-κ ( z_i- z (t) ) with z˙ℓ=bℓ(xℓ,t)uℓ+dℓ(xℓ,t),ℓ∈i∪i z_ =b_ (x_ ,t)u_ +d_ (x_ ,t),~ ∈\i\ _i. Therefore, agent i can compute α˙i α_i using its own variables xi,uix_i,u_i, the neighbor-relative information xj−xi,uj−uij∈i\x_j-x_i,u_j-u_i\_j _i, and the known functions ξ¯(t) ξ(t), ξ¯(t) ξ(t), z⋆(t)z (t) and their derivatives. No derivative of uiu_i and no commanded signal vjv_j from neighboring agents is required. Hence, the commanded signal viv_i remains distributed in the sense of the information structure in (4)–(5). (t)S(t)1(t)X_1(t)2(t)X_2(t)N(t)X_N(t)⋯·sΩ(t) (t)x⋆(t)x (t)x1x_1x2x_2xNx_N Figure 1: Set-based illustration of the proposed safe-consensus framework. Each agent i operates within its individual admissible set i(t)X_i(t), all of which reside within the broader state space (t)S(t). The common safe core Ω(t) (t) is assumed to lie strictly inside the mutual intersection ⋂i(t) _iX_i(t). Coordination ensures the network converges to a synchronized reference x⋆(t)∈Ω(t)x (t)∈ (t). Proposition 2. Consider the closed-loop system consisting of (1), (2), and (48). Assume that the corresponding solution is well defined on an interval on which xi(t)∈Ω(t)x_i(t)∈ (t), ui(t)∈iu_i(t) _i, ∀i∈∀ i . Let :=colz1,…,zNz:=col\z_1,…,z_N\, :=−z⋆(t)N ζ:=z-z (t)1_N, and B(,t):=diagb1(x1,t),…,bN(xN,t)B(x,t):=diag\b_1(x_1,t),…,b_N(x_N,t)\. Then one has ε˙i=−ciεi,i∈, _i=-c_i _i,~~i , (49) and ˙=−(kzL+κIN)+B(,t). ζ=- (k_zL+κ I_N ) ζ+B(x,t) . (50) Proof. From Lemma 1, z˙i=bi(xi,t)ui+di(xi,t) z_i=b_i(x_i,t)u_i+d_i(x_i,t). Using ui=αi+εiu_i= _i+ _i and (46), we obtain z˙i= z_i= bi(xi,t)αi+di(xi,t)+bi(xi,t)εi b_i(x_i,t) _i+d_i(x_i,t)+b_i(x_i,t) _i = = βi+bi(xi,t)εi. _i+b_i(x_i,t) _i. (51) Substituting (45) above gives z˙i−z˙⋆(t)= z_i- z (t)= −kz∑j=1Naij[(zi−z⋆(t))−(zj−z⋆(t))] -k_z _j=1^Na_ij [ (z_i-z (t) )- (z_j-z (t) ) ] −κ(zi−z⋆(t))+bi(xi,t)εi, -κ (z_i-z (t) )+b_i(x_i,t) _i, (52) which yields (50) in stacked form. The proof of (49) is identical to that of Proposition 1. ∎ Theorem 2. Suppose Assumptions 1, 2 and 4 hold. Let ⊂Ω(0)N×K⊂ (0)^N×U be a compact set of initial conditions. For each (0,0)∈(x_0,u_0) , define 0:=colln(x1,0−ξ¯(0)ξ¯(0)−x1,0),…,ln(xN,0−ξ¯(0)ξ¯(0)−xN,0), _0:=col \ ( x_1,0- ξ(0) ξ(0)-x_1,0 ),…, ( x_N,0- ξ(0) ξ(0)-x_N,0 ) \, (53) 0:=0−(0,0), _0:=u_0- α(x_0,0), (54) and S:=sup(0,0)∈(‖0−z⋆(0)N‖2+‖0‖2)12. S_K:= _(x_0,u_0) (\|z_0-z (0)1_N\|^2+\| _0\|^2 ) 12. (55) Let M:=z¯⋆+S,b¯:=2(1+eM)δξ,d¯:=2d¯ξ(1+eM)δξM_K:= z_ +S_K,~ b_K:= 2(1+e^M_K) _ξ,~ d_K:= 2 d_ξ(1+e^M_K) _ξ, and, for each i∈i , β¯i,:=d¯⋆+(2kzdi+κ)S β_i,K:= d_ +(2k_zd_i+κ)S_K, α¯i,:=Δξ4(β¯i,+d¯),ri,:=α¯i,+S,r¯i:=minu¯i,−u¯i α_i,K:= _ξ4 ( β_i,K+ d_K ),~r_i,K:= α_i,K+S_K,~ r_i:= \ u_i,- u_i\. Assume that cmin:= c_ := min1≤i≤Nci>b¯22κ, _1≤ i≤ Nc_i> b_K^22κ, (56) ri,< r_i,K< r¯i,∀i∈. r_i,~~∀ i . (57) Then, for every initial condition ((0),(0))∈(x(0),u(0)) , the closed-loop system consisting of (1), (2), and (48) admits a unique complete solution satisfying the following properties: 1. the output remains safe and the actuator inputs remain strictly admissible for all time, i.e., xi(t)∈Ω(t)⊆i(t),ui(t)∈i,∀t≥0,∀i∈; x_i(t)∈ (t) _i(t),~u_i(t) _i,~∀ t≥ 0,~∀ i ; (58) 2. the actuator-tracking errors satisfy εi(t)=e−citεi(0),∀t≥0,∀i∈; _i(t)=e^-c_it _i(0),~~∀ t≥ 0,~~∀ i ; (59) 3. the transformed synchronization error satisfies ‖(t)‖2+‖(t)‖2≤e−ηst(‖(0)‖2+‖(0)‖2),∀t≥0, \| ζ(t)\|^2+\| (t)\|^2≤ e^- _st (\| ζ(0)\|^2+\| (0)\|^2 ),~~∀ t≥ 0, (60) where the term ηs _s is defined as ηs:=minκ, 2cmin−b¯2κ>0; _s:= \κ,\,2c_ - b_K^2κ \>0; (61) 4. the agent states asymptotically synchronize to the prescribed admissible trajectory x⋆(t)x (t), i.e., limt→∞(xi(t)−x⋆(t))=0,∀i∈; _t→∞ (x_i(t)-x (t) )=0,~~∀ i ; (62) and specifically, limt→∞|xi(t)−xj(t)|=0,∀i,j∈; _t→∞|x_i(t)-x_j(t)|=0,~~∀ i,j ; (63) 5. the commanded inputs viv_i are bounded on [0,∞)[0,∞), and all closed-loop signals remain bounded. Consequently, the controller (48) solves Problem 2 on the compact admissible set K, and in fact establishes the stronger objective of synchronization to the prescribed admissible trajectory x⋆(t)x (t). Proof. Fix an arbitrary initial condition ((0),(0))∈(x(0),u(0)) . Since ⊂Ω(0)N×K⊂ (0)^N×U, the barrier coordinates are well defined at t=0t=0, and the closed-loop vector field is locally well defined. Let [0,Tmax)[0,T_ ) denote the corresponding maximal interval of existence. Define T⋆:=supT∈(0,Tmax]:xi(t)∈Ω(t) for all t∈[0,T),∀i∈T := \T∈(0,T_ ]:x_i(t)∈ (t) for all t∈[0,T),~∀ i \. Clearly, T⋆>0T >0. We first analyze the dynamics on [0,T⋆)[0,T ), where Proposition 2 applies. Consider the Lyapunov function candidate W:=12‖2+12‖2. W:= 12\| ζ\|^2+ 12\| \|^2. (64) On [0,T⋆)[0,T ), Proposition 2 gives W˙ W =⊤(−(kzL+κIN)+B(,t))−⊤C = ζ (- (k_zL+κ I_N ) ζ+B(x,t) )- C =−kz⊤L−κ‖2+⊤B(,t)−⊤C. =-k_z ζ L ζ-κ\| ζ\|^2+ ζ B(x,t) - C . (65) We first derive a trajectory-independent bound on B(,t)B(x,t) over the slab |zi|≤M|z_i|≤ M_K. From (40), if |zi|≤M|z_i|≤ M_K, then xi−ξ¯(t)=(ξ¯(t)−ξ¯(t))ezi1+ezi,ξ¯(t)−xi=ξ¯(t)−ξ¯(t)1+ezi. x_i- ξ(t)= ( ξ(t)- ξ(t) )e^z_i1+e^z_i,~~ ξ(t)-x_i= ξ(t)- ξ(t)1+e^z_i. (66) Substituting these expressions into (41) yields bi(xi,t)=e−zi+2+eziξ¯(t)−ξ¯(t)≤2(1+eM)δξ=b¯. b_i(x_i,t)= e^-z_i+2+e^z_i ξ(t)- ξ(t)≤ 2(1+e^M_K) _ξ= b_K. (67) Hence, if |zi(t)|≤M|z_i(t)|≤ M_K for all i, then ‖B((t),t)‖≤b¯\|B(x(t),t)\|≤ b_K. Now, on any subinterval of [0,T⋆)[0,T ) where |zi(t)|≤M|z_i(t)|≤ M_K for all i, one has from (65) W˙≤−κ‖2+b¯‖‖−cmin‖2. W≤-κ\| ζ\|^2+ b_K\| ζ\|\,\| \|-c_ \| \|^2. (68) Applying Young’s inequality, b¯‖‖≤κ2‖2+b¯22κ‖2, b_K\| ζ\|\,\| \|≤ κ2\| ζ\|^2+ b_K^22κ\| \|^2, (69) so we obtain W˙≤−κ2‖2−(cmin−b¯22κ)‖2. W≤- κ2\| ζ\|^2- (c_ - b_K^22κ )\| \|^2. (70) By (56), the constant ηs _s defined in (61) is strictly positive, and therefore W˙≤−ηsW. W≤- _sW. (71) Since W(0)≤12S2W(0)≤ 12S_K^2, a standard continuation argument shows that (71) holds on the whole interval [0,T⋆)[0,T ). Indeed, if there existed a first time t1∈(0,T⋆)t_1∈(0,T ) such that |zi(t1)|>M|z_i(t_1)|>M_K for some i, then by continuity there would be a first time at which |zi|=M|z_i|=M_K. Integrating (71) up to that time would give W(t)≤e−ηstW(0)≤W(0)≤12S2,∀t∈[0,T⋆), W(t)≤ e^- _stW(0)≤ W(0)≤ 12S_K^2,~~∀ t∈[0,T ), (72) and hence ‖(t)‖≤S,∀t∈[0,T⋆). \| ζ(t)\|≤ S_K,~~∀ t∈[0,T ). (73) Therefore, using (37), ∀i∈∀ i , |zi(t)|≤|z⋆(t)|+‖(t)‖≤z¯⋆+S=M,∀t∈[0,T⋆), |z_i(t)|≤|z (t)|+\| ζ(t)\|≤ z_ +S_K=M_K,~∀ t∈[0,T ), (74) which is a contradiction. Thus (72) and (74) hold on all of [0,T⋆)[0,T ), and (60) follows immediately. We next use (74) to prove strict forward invariance of the safe set. From (40), and using (32) and (74), we obtain xi(t)−ξ¯(t)≥ x_i(t)- ξ(t)≥ δξ1+eM=:m>0, _ξ1+e^M_K=:m_K>0, (75) ξ¯(t)−xi(t)≥ ξ(t)-x_i(t)≥ δξ1+eM=m>0, _ξ1+e^M_K=m_K>0, (76) for all t∈[0,T⋆)t∈[0,T ) and all i∈i . Hence, ∀t∈[0,T⋆)∀ t∈[0,T ), ∀i∈∀ i , xi(t)∈[ξ¯(t)+m,ξ¯(t)−m]⊂Ω(t). x_i(t)∈ [ ξ(t)+m_K,\, ξ(t)-m_K ]⊂ (t). (77) Thus, the solution cannot approach the boundary of Ω(t) (t) in finite time, and therefore T⋆=TmaxT =T_ . We now bound the realized actuator inputs. First, from (45), (37), and (73), |βi(t)|≤ | _i(t)|≤ d¯⋆+2kzdi‖(t)‖+κ‖(t)‖ d_ +2k_zd_i\| ζ(t)\|+κ\| ζ(t)\| ≤ ≤ d¯⋆+(2kzdi+κ)S=β¯i,. d_ +(2k_zd_i+κ)S_K= β_i,K. (78) Also, from (42), (34), and (77), |di(xi(t),t)|≤ |d_i(x_i(t),t)|≤ d¯ξxi(t)−ξ¯(t)+d¯ξ¯(t)−xi(t) d_ξx_i(t)- ξ(t)+ d_ξ ξ(t)-x_i(t) ≤ ≤ 2d¯ξ(1+eM)δξ=d¯. 2 d_ξ(1+e^M_K) _ξ= d_K. (79) Moreover, from (40) and (41), 1bi(xi(t),t)=(ξ¯(t)−ξ¯(t))ezi(t)(1+ezi(t))2≤Δξ4. 1b_i(x_i(t),t)= ( ξ(t)- ξ(t) )e^z_i(t) (1+e^z_i(t) )^2≤ _ξ4. (80) Hence, from (46), |αi(t)|≤Δξ4(β¯i,+d¯)=α¯i,. | _i(t)|≤ _ξ4 ( β_i,K+ d_K )= α_i,K. (81) Since (60) implies ‖(t)‖≤S\| (t)\|≤ S_K, we conclude that |ui(t)|≤|αi(t)|+|εi(t)|≤α¯i,+S=ri,,∀t∈[0,Tmax). |u_i(t)|≤| _i(t)|+| _i(t)|≤ α_i,K+S_K=r_i,K,~∀ t∈[0,T_ ). (82) From (57), ui(t)∈[−ri,,ri,]⊂(u¯i,u¯i),∀t∈[0,Tmax),∀i∈. u_i(t)∈[-r_i,K,r_i,K]⊂( u_i, u_i),~∀ t∈[0,T_ ),~∀ i . (83) Thus (58) holds on [0,Tmax)[0,T_ ), and σi(ui(t))≥σ¯i,:=min1−(ri,u¯i)γi, 1−(ri,−u¯i)γi>0. _i(u_i(t))≥ σ_i,K:= \1- ( r_i,K u_i ) _i,\,1- ( r_i,K- u_i ) _i \>0. (84) It remains to establish boundedness of the commanded inputs and completeness. The quantities ξ¯(t) ξ(t), ξ¯(t) ξ(t), and their derivatives up to second order are bounded by (33) and (34). Moreover, z⋆(t)z (t) and its derivatives up to second order are bounded by (37). The estimate (74) shows that (t)z(t) remains in a compact slab, and therefore (40) implies that (t)x(t) evolves in the compact strip (77). Since βi _i depends smoothly on z, z⋆z , and z˙⋆ z , and since αi _i is a smooth function of these quantities on the compact strip, it follows that α˙i α_i is bounded on [0,Tmax)[0,T_ ). Combined with (83), (84), and (48), this yields boundedness of viv_i on [0,Tmax)[0,T_ ). Hence, all closed-loop signals remain in a compact subset of the domain of the closed-loop vector field, so finite escape is impossible. Therefore, Tmax=∞T_ =∞. The decay estimate (60) implies (t)→ ζ(t) 0 and (t)→ (t) 0. Thus zi(t)−z⋆(t)→0,∀i∈. z_i(t)-z (t)→ 0,~~∀ i . (85) Furthermore, the inverse barrier map (40) has derivative ∂φt−1∂z(z)=(ξ¯(t)−ξ¯(t))ez(1+ez)2≤Δξ4, ∂ _t^-1∂ z(z)= ( ξ(t)- ξ(t) )e^z (1+e^z )^2≤ _ξ4, (86) for all z∈ℝz and all t≥0t≥ 0. Since xi(t)=φt−1(zi(t))x_i(t)= _t^-1(z_i(t)) and x⋆(t)=φt−1(z⋆(t))x (t)= _t^-1(z (t)), the mean-value theorem gives |xi(t)−x⋆(t)|≤Δξ4|zi(t)−z⋆(t)|,∀t≥0. |x_i(t)-x (t)|≤ _ξ4|z_i(t)-z (t)|,~~∀ t≥ 0. (87) Therefore, (62) holds, and (63) follows immediately. ∎ Remark 7. Theorem 2 is semiglobal with respect to compact admissible initial sets. The conditions (56) and (57) depend only on the design gains, the graph, the actuator bounds, the regularity constants of the common safe core, the boundedness constants of the prescribed transformed trajectory, and the chosen compact set of initial conditions. No closed-loop trajectory-dependent quantity is assumed a priori. As in Theorem 1, condition (15) uses a symmetric inner bound contained in the asymmetric actuator interval. Hence, it is sufficient but not necessary for strict actuator admissibility. Remark 8. The pinning term −κ(zi−z⋆(t))-κ (z_i-z (t) ) in (45) removes the neutral consensus mode in the transformed coordinates, while the feedforward term z˙⋆(t) z (t) accounts for the motion of the prescribed admissible trajectory in the same coordinates. Consequently, the closed-loop system achieves a stronger objective than plain agreement, namely, synchronization to the prescribed admissible trajectory x⋆(t)x (t). Remark 9. The proposed safe consensus framework differs from a direct funnel-control or prescribed-performance construction [29, 25] in three main ways: (i) In their standard formulation, the associated transformation is therefore an error transformation, and the main objective is to keep the error inside a prescribed transient envelope. In the proposed design, the transformation used here is not applied to a consensus error. It is applied directly to the agent output relative to the admissible core interval (38) so that boundedness of ziz_i is equivalent to strict interiority of the physical output constraint xi(t)∈Ω(t)x_i(t)∈ (t). (i) The proposed framework separates the admissible trajectory selection from the consensus mechanism by assigning the desired group behavior via a designer-selected admissible trajectory x⋆(t)∈Ω(t)x (t)∈ (t) and its transformed representation (36), so the closed-loop network synchronizes to a specified safe trajectory rather than to an unspecified agreement value. (i) Unlike funnel-control approaches that primarily encode output-error performance and may require a separate treatment of actuator feasibility, the present framework provides a unified distributed mechanism for strict asymmetric input admissibility, forward invariance of the output safe set, and synchronization to a prescribed safe trajectory. Corollary 1. Suppose the hypotheses of Theorem 2 hold. If the prescribed admissible trajectory is generated by a constant transformed coordinate zc⋆∈ℝz_c as x⋆(t)=φt−1(zc⋆)=ξ¯(t)+ξ¯(t)ezc⋆1+ezc⋆,t≥0, x (t)= _t^-1(z_c )= ξ(t)+ ξ(t)e^z_c 1+e^z_c ,~~t≥ 0, (88) then z⋆(t)≡zc⋆z (t)≡ z_c and z˙⋆(t)≡0 z (t)≡ 0. In this case, the transformed synchronization input reduces to βi=−kz∑j=1Naij(zi−zj)−κ(zi−zc⋆), _i=-k_z _j=1^Na_ij(z_i-z_j)-κ(z_i-z_c ), (89) and the closed-loop system satisfies limt→∞(xi(t)−x⋆(t))=0,∀i∈. _t→∞ (x_i(t)-x (t) )=0,~~∀ i . (90) If, in addition, the common safe core interval is time invariant, that is, ξ¯(t)≡ξ¯ ξ(t)≡ ξ and ξ¯(t)≡ξ¯ ξ(t)≡ ξ, then x⋆(t)≡xc⋆:=ξ¯+ξ¯ezc⋆1+ezc⋆, x (t)≡ x_c := ξ+ ξe^z_c 1+e^z_c , (91) and hence limt→∞xi(t)=xc⋆,∀i∈. _t→∞x_i(t)=x_c ,~~∀ i . (92) Proof. If (88) holds, then applying φt _t to both sides gives z⋆(t)≡zc⋆z (t)≡ z_c , and therefore z˙⋆(t)≡0 z (t)≡ 0. Hence the transformed synchronization input reduces to (89). The convergence statement follows directly from Theorem 2. If ξ¯ ξ and ξ¯ ξ are constant, then (88) is constant, which gives the final claim. ∎ 4 Simulation Results (a) State trajectories xi(t)x_i(t). (b) Realized actuator inputs ui(t)u_i(t). (c) Commanded actuator signals vi(t)v_i(t). Figure 2: Distributed safe-consensus for the multi-frequency prescribed reference case, generated via (101). (a) State trajectories xi(t)x_i(t). (b) Realized actuator inputs ui(t)u_i(t). (c) Commanded actuator signals vi(t)v_i(t). Figure 3: Distributed safe-consensus for the biased sinusoidal prescribed reference case, generated via (102). (a) State trajectories xi(t)x_i(t). (b) Realized actuator inputs ui(t)u_i(t). (c) Commanded actuator signals vi(t)v_i(t). Figure 4: Distributed safe-consensus for the smooth transition prescribed reference case, generated via (103). (a) Multi-frequency prescribed reference. (b) Biased sinusoidal prescribed reference. (c) Smooth transition prescribed reference. Figure 5: Safety margins and actuator regularity factors for the prescribed-trajectory synchronization problem. (a) State trajectories xi(t)x_i(t). (b) Realized actuator inputs ui(t)u_i(t). (c) Commanded actuator signals vi(t)v_i(t). Figure 6: Distributed safe-consensus for the constant barrier coordinate reference. We now illustrate the proposed prescribed-trajectory safe-consensus strategy for a network of N=5N=5 single-integrator agents communicating over a connected undirected cycle graph. The controller gains are selected as kz=1.20k_z=1.20, κ=1.00κ=1.00, and ci=3.00c_i=3.00. The actuator parameters are chosen as p1,i=1p_1,i=1, p2,i=0.70p_2,i=0.70, and γi=2 _i=2 for all i∈i . To demonstrate heterogeneous and asymmetric actuator authority, the admissible actuator intervals are selected as ¯=[−1.25−1.20−1.15−1.10−3.50]⊤ u= bmatrix-1.25&-1.20&-1.15&-1.10&-3.50 bmatrix and ¯=[4.753.002.502.001.50]⊤ u= bmatrix4.75&3.00&2.50&2.00&1.50 bmatrix . Thus, each agent has a different admissible input interval, and the positive and negative actuation limits are not symmetric. In the plots, upper bounds are in dash-dot, whereas lower bounds are in dots. The common admissible core (35) is selected as a time-varying asymmetric interval, where ξ¯(t)=cξ(t)−Δℓ(t),ξ¯(t)=cξ(t)+Δu(t), ξ(t)=c_ξ(t)- _ (t),~~ ξ(t)=c_ξ(t)+ _u(t), (93) with cξ(t)= c_ξ(t)= 0.25sin(0.18t)+0.10cos(0.07t), 0.25 (0.18t )+0.10 (0.07t ), (94) Δℓ(t)= _ (t)= 1.35+0.18sin(0.11t+0.40)+0.08cos(0.27t), 1.35+0.18 (0.11t+0.40 )+0.08 (0.27t ), (95) Δu(t)= _u(t)= 2.10+0.22cos(0.09t−0.30)+0.10sin(0.21t). 2.10+0.22 (0.09t-0.30 )+0.10 (0.21t ). (96) This choice gives different lower and upper clearances from the nominal signal cξ(t)c_ξ(t). In particular, Δℓ(t)≥1.09 _ (t)≥ 1.09 and Δu(t)≥1.78 _u(t)≥ 1.78, so the common core has a uniformly positive width. The prescribed admissible trajectory is generated through a normalized location variable ρ(t)ρ(t) inside the moving interval. Specifically, we set x⋆(t)=ξ¯(t)+ρ(t)(ξ¯(t)−ξ¯(t)), x (t)= ξ(t)+ρ(t) ( ξ(t)- ξ(t) ), (97) where ρ(t)∈(0,1)ρ(t)∈(0,1) specifies the relative location of x⋆(t)x (t) within the admissible core (35). This construction is useful because admissibility is enforced directly through the scalar signal ρ(t)ρ(t). If there exist constants ρmin _ and ρmax _ such that 0<ρmin≤ρ(t)≤ρmax<10< _ ≤ρ(t)≤ _ <1 for all t≥0t≥ 0, then x⋆(t)∈Ω(t)x (t)∈ (t) for all t≥0t≥ 0. Moreover, x⋆(t)−ξ¯(t)= x (t)- ξ(t)= ρ(t)(ξ¯(t)−ξ¯(t)), ρ(t) ( ξ(t)- ξ(t) ), (98) ξ¯(t)−x⋆(t)= ξ(t)-x (t)= (1−ρ(t))(ξ¯(t)−ξ¯(t)). (1-ρ(t) ) ( ξ(t)- ξ(t) ). (99) Thus, using (32), the prescribed trajectory remains uniformly separated from the two moving boundaries according to minx⋆(t)−ξ¯(t),ξ¯(t)−x⋆(t)≥minρmin,1−ρmaxδξ. \x (t)- ξ(t), ξ(t)-x (t) \≥ \ _ ,1- _ \ _ξ. (100) This allows one to test different reference patterns while preserving the structural admissibility required by the theory. Three representative choices of ρ(t)ρ(t) are considered. The first one is a multi-frequency reference, ρmf(t)=0.50+0.22sin(0.18t)+0.12sin(0.73t+0.60). _mf(t)=0.50+0.22 (0.18t )+0.12 (0.73t+0.60 ). (101) The signal (101) combines a slow component and a faster oscillatory component. It is chosen to test whether the controller can track a nontrivial prescribed trajectory that does not move monotonically and contains multiple time scales. Since 0.50−0.22−0.12≤ρmf(t)≤0.50+0.22+0.120.50-0.22-0.12≤ _mf(t)≤ 0.50+0.22+0.12, one has 0.16≤ρmf(t)≤0.84,∀t≥00.16≤ _mf(t)≤ 0.84,~∀ t≥ 0. Therefore, the prescribed trajectory generated by (101) remains strictly inside Ω(t) (t) with a normalized boundary clearance of at least 0.160.16. The second choice is a single-frequency biased sinusoidal reference, ρs(t)=0.65+0.25sin(0.30t). _s(t)=0.65+0.25 (0.30t ). (102) This case provides a simpler periodic trajectory and is useful for isolating the effect of smooth oscillatory motion without additional high-frequency content. The offset 0.650.65 biases the trajectory toward the upper portion of the admissible interval. This is intentional in the present simulation because the actuator limits are heterogeneous and asymmetric, with more restrictive negative authority for some agents. Since 0.40≤ρs(t)≤0.90,∀t≥00.40≤ _s(t)≤ 0.90,~∀ t≥ 0, the corresponding trajectory remains admissible, with a normalized boundary clearance of at least 0.100.10. The third choice is a smooth transition-type reference, ρp(t)=0.75+0.08tanh(0.05(t−20))+0.02sin(0.15t). _p(t)=0.75+0.08 (0.05 (t-20 ) )+0.02 (0.15t ). (103) This case is included to emulate a commanded relocation of the desired operating point inside the safe corridor. The hyperbolic tangent term produces a smooth transition centered around t=20t=20, while the sinusoidal term adds a small persistent variation after and during the transition. Since −1<tanh(0.05(t−20))<1-1< (0.05 (t-20 ) )<1, it follows that 0.75−0.08−0.02<ρp(t)<0.75+0.08+0.020.75-0.08-0.02< _p(t)<0.75+0.08+0.02, and hence 0.65<ρp(t)<0.85,∀t≥00.65< _p(t)<0.85,~∀ t≥ 0. Thus, this reference remains well inside the safe interval while testing the transient response to a deliberate shift in the prescribed admissible trajectory. For each of the above cases, the physical prescribed trajectory x⋆(t)x (t) is obtained from (97), and the corresponding transformed reference is computed using (36). Equivalently, since x⋆(t)x (t) is parameterized by ρ(t)ρ(t), one may write z⋆(t)=ln(ρ(t)1−ρ(t)). z (t)= ( ρ(t)1-ρ(t) ). (104) The expression in (104) shows that the normalized reference location ρ(t)ρ(t) determines the transformed reference used by the controller. The three cases above therefore test the same safe-synchronization mechanism under progressively different reference profiles (multi-frequency tracking, biased sinusoidal tracking, and smooth transition tracking). The initial states and initial actuator-tracking errors are selected as (0)=[−0.80−0.250.300.801.25]⊤x(0)= bmatrix-0.80&-0.25&0.30&0.80&1.25 bmatrix and (0)=[0.05−0.080.04−0.060.03]⊤ (0)= bmatrix0.05&-0.08&0.04&-0.06&0.03 bmatrix . Figures 2(a), 3(a) and 4(a) show the evolution of the agent states together with the corresponding user-selected prescribed trajectory x⋆(t)x (t) and the asymmetric admissible bounds ξ¯(t) ξ(t) and ξ¯(t) ξ(t) for three different choices of ρ(t)ρ(t). One may observe that all agent states remain strictly inside the time-varying safe core throughout the simulation and converge to the prescribed admissible trajectory. This also confirms that the agents do reach an agreement with each other and synchronize with the user-defined safe trajectory. The realized actuator inputs are shown in Figures 2(b), 3(b) and 4(b). Despite the heterogeneous and asymmetric input intervals, the realized inputs remain strictly inside their corresponding admissible sets. The safety and actuator-regularity plots further confirm the forward-invariance and nonsingularity properties of the proposed closed-loop system. The state-safety margin mi(t):=minxi(t)−ξ¯(t),ξ¯(t)−xi(t)m_i(t):= \x_i(t)- ξ(t), ξ(t)-x_i(t) \ remains strictly positive for every agent (see Figure 5), which shows that no trajectory approaches the boundary of the moving admissible core Ω(t) (t). Hence, the logarithmic barrier coordinates remain well defined over the entire simulation horizon. Similarly, the actuator regularization factor σi(ui(t)) _i(u_i(t)) stays positive for all agents, which implies that the realized inputs remain strictly inside their heterogeneous asymmetric admissible intervals. Since the commanded input viv_i contains σi(ui) _i(u_i) in the denominator, the positivity of σi(ui(t)) _i(u_i(t)) verifies that the actuator-compensating control law remains nonsingular. Consequently, the plots of mi(t)m_i(t) and σi(ui(t)) _i(u_i(t)) provide a numerical confirmation that both state safety and actuator admissibility are preserved while the agents synchronize to the prescribed admissible trajectory. These results confirm the three main conclusions of the proposed theory: forward invariance of the prescribed safe set, strict admissibility of the actuator inputs, and asymptotic synchronization to x⋆(t)x (t). Moreover, the simulation highlights two important aspects of the proposed design. First, the prescribed trajectory is not required to be constant or centered inside the safe interval. It may vary with multiple frequencies as long as it remains strictly admissible. Second, the admissible actuator intervals may be both asymmetric and agent-dependent. The barrier-coordinate transformation enforces state safety, while the transformed pinning term drives all agents to the prescribed safe trajectory in the transformed coordinate system. As a special case, we now consider a network of N=4N=4 agents communicating over a connected undirected cycle graph, and elucidate the results in Corollary 1. The barrier-consensus gains are chosen as kz=1.4,κ=1.2k_z=1.4,κ=1.2, and the actuator-tracking gains are selected as c=[22.12.22.3]⊤c= bmatrix2&2.1&2.2&2.3 bmatrix . For the continuously differentiable asymmetric actuator dynamics, we choose p1,i=1,p2,i=0.25,γi=4p_1,i=1,p_2,i=0.25, _i=4 (for all i) with asymmetric actuator limits ¯=[−2.0−1.875−2.125−1.95]⊤ u= bmatrix-2.0&-1.875&-2.125&-1.95 bmatrix , and ¯=[1.51.4251.5751.47]⊤ u= bmatrix1.5&1.425&1.575&1.47 bmatrix . The common time-varying safe interval is chosen as ξ¯(t)=−2.6+0.18sin(0.22t) ξ(t)=-2.6+0.18 (0.22t), ξ¯(t)=1.4+0.18sin(0.22t) ξ(t)= -1.4+0.18 (0.22t), so that ξ¯(t)−ξ¯(t)=4.0∀t≥0 ξ(t)- ξ(t)=4.0~∀ t≥ 0. The desired barrier-coordinate equilibrium is fixed at z⋆=0z =0, which yields the admissible synchronized reference x⋆(t)=ξ¯(t)+ξ¯(t)2x (t)= ξ(t)+ ξ(t)2. The initial conditions are taken as x(0)=[0.9−0.80.45−0.35]⊤x(0)= bmatrix0.9&-0.8&0.45&-0.35 bmatrix , u(0)=[0000]⊤u(0)= bmatrix0&0&0&0 bmatrix , which lie strictly inside the admissible state and actuator sets. Figure 6(a) shows the state trajectories together with the time-varying safety bounds and the reference x⋆(t)x (t). All states remain strictly inside the admissible interval and converge to the moving safe trajectory. Figure 6(b) displays the actuator outputs and confirms strict satisfaction of the asymmetric bounds. Figure 6(c) depicts the actual commanded actuator signals. The simulation confirms that the proposed controller simultaneously enforces forward invariance of the time-varying safe set, strict satisfaction of asymmetric actuator constraints, and asymptotic synchronization to the admissible reference trajectory. 5 Conclusions This paper investigated safe distributed consensus for single-integrator multi-agent systems over connected undirected graphs under simultaneous asymmetric actuator constraints and time-varying state safety constraints. The proposed framework yields a closed-loop architecture that simultaneously accounts for both actuation limits and safe-state requirements. For compact admissible sets of initial conditions, we established completeness of solutions, boundedness of all closed-loop signals, strict satisfaction of asymmetric input bounds, forward invariance of the prescribed safe interval, exponential convergence of the actuator-tracking errors, and asymptotic synchronization of the agent states to a designer-selected admissible trajectory embedded in the common safe set. The present results provide initial steps to advance safety-critical networked autonomy via concurrent network-level coordination and actuator-level realization. References [1] R. Olfati-Saber, J. A. Fax, and R. M. Murray, “Consensus and cooperation in networked multi-agent systems,” Proceedings of the IEEE, vol. 95, no. 1, p. 215–233, 2007. [2] R. Olfati-Saber and R. M. Murray, “Consensus problems in networks of agents with switching topology and time-delays,” IEEE Transactions on Automatic Control, vol. 49, no. 9, p. 1520–1533, 2004. [3] W. Ren and R. W. Beard, “Consensus seeking in multi-agent systems under dynamically changing interaction topologies,” IEEE Transactions on Automatic Control, vol. 50, no. 5, p. 655–661, 2005. [4] M. Mesbahi and M. Egerstedt, Graph Theoretic Methods in Multiagent Networks. Princeton University Press, 2010. [5] S.-H. Kwon, Y.-B. Bae, J. Liu, and H.-S. Ahn, “From matrix-weighted consensus to multipartite average consensus,” IEEE Transactions on Control of Network Systems, vol. 7, no. 4, p. 1609–1620, 2020. [6] A. D. Ames, S. Coogan, M. Egerstedt, G. Notomista, K. Sreenath, and P. Tabuada, “Control barrier functions: Theory and applications,” 2019 18th European Control Conference (ECC), p. 3420–3431, 2019. [7] L. Wang, A. D. Ames, and M. Egerstedt, “Safety barrier certificates for collisions-free multirobot systems,” IEEE Transactions on Robotics, vol. 33, no. 3, p. 661–674, 2017. [8] R. Rajamani, Vehicle Dynamics and Control. Springer, 2 ed., 2012. [9] T. I. Fossen, Handbook of Marine Craft Hydrodynamics and Motion Control. John Wiley & Sons, 2 ed., 2021. [10] B. L. Stevens, F. L. Lewis, and E. N. Johnson, Aircraft Control and Simulation: Dynamics, Controls Design, and Autonomous Systems. John Wiley & Sons, 3 ed., 2016. [11] K. P. Tee, S. S. Ge, and E. H. Tay, “Barrier lyapunov functions for the control of output-constrained nonlinear systems,” Automatica, vol. 45, no. 4, p. 918–927, 2009. [12] X. Sun and C. G. Cassandras, “Optimal dynamic formation control of multi-agent systems in constrained environments,” Automatica, vol. 73, p. 169–179, 2016. [13] P. K. Ranjan, A. Sinha, and Y. Cao, “Engagement-zone-aware input-constrained guidance for safe target interception in contested environments,” arXiv preprint arXiv:2603.23649, 2026. [14] Y.-H. Liu, C.-Y. Su, and H. Li, “Adaptive output feedback funnel control of uncertain nonlinear systems with arbitrary relative degree,” IEEE Transactions on Automatic Control, vol. 66, no. 6, p. 2854–2860, 2021. [15] Z. Zhang, Z. Chen, and W. Fang, “Cooperative fault tolerant control with state constraints for nonlinear multiple-agent systems,” IEEE Transactions on Control of Network Systems, vol. 12, no. 2, p. 1264–1276, 2025. [16] Y. Lv, J. Fu, G. Wen, T. Huang, and X. Yu, “On consensus of multiagent systems with input saturation: Fully distributed adaptive antiwindup protocol design approach,” IEEE Transactions on Control of Network Systems, vol. 7, no. 3, p. 1127–1139, 2020. [17] Y. Xu and F. Jabbari, “Discrete-time leader-following multiagent systems: Saturation constraints and event-triggered control,” IEEE Transactions on Control of Network Systems, vol. 12, no. 2, p. 1354–1368, 2025. [18] T. Yang, Z. Meng, D. V. Dimarogonas, and K. H. Johansson, “Global consensus for discrete-time multi-agent systems with input saturation constraints,” Automatica, vol. 50, no. 2, p. 499–506, 2014. [19] X. Yi, T. Yang, J. Wu, and K. H. Johansson, “Distributed event-triggered control for global consensus of multi-agent systems with input saturation,” Automatica, vol. 100, p. 1–9, 2019. [20] S. Zhang, K. Garg, and C. Fan, “Neural graph control barrier functions guided distributed collision-avoidance multi-agent control,” in 7th Annual Conference on Robot Learning, 2023. [21] S. Sajjadi-Kia and F. Jabbari, “Controllers for linear systems with bounded actuators: Slab scheduling and anti-windup,” Automatica, vol. 49, no. 3, p. 762–769, 2013. [22] X. Min, S. Baldi, Y. Shi, and W. Yu, “Safe control of multiagent systems via low-complexity control barrier functions,” IEEE Transactions on Automatic Control, vol. 70, no. 10, p. 6831–6845, 2025. [23] M. Sharifi and D. V. Dimarogonas, “Higher order barrier certificates for leader-follower multi-agent systems,” IEEE Transactions on Control of Network Systems, vol. 10, no. 2, p. 900–911, 2023. [24] Y. Song, N. P. Nguyen, H.-S. Park, Y. You, M. Lee, and H. Oh, “Distributed safety-critical optimal flocking control algorithm with feasibility enhancement of high-order control barrier function,” IEEE Transactions on Control of Network Systems, vol. 12, no. 3, p. 2052–2063, 2025. [25] M. Charitidou and D. V. Dimarogonas, “Virtual leader and distance-based formation control with funnel constraints,” IEEE Transactions on Control of Network Systems, vol. 12, no. 2, p. 1342–1353, 2025. [26] P. Mestres, C. Nieto-Granda, and J. Cortés, “Distributed safe navigation of multi-agent systems using control barrier function-based controllers,” IEEE Robotics and Automation Letters, vol. 9, no. 7, p. 6760–6767, 2024. [27] X. Huang and L. Long, “Distributed asymptotic consensus safety-critical control of multi-agent systems with vector control barrier functions,” IEEE Transactions on Control of Network Systems, p. 1–10, 2026. [28] S. Kumar, S. R. Kumar, and A. Sinha, “Provably safe control for constrained nonlinear systems with bounded input,” arXiv preprint arXiv:2504.11592, 2025. [29] F. Chen and D. V. Dimarogonas, “Leader–follower formation control with prescribed performance guarantees,” IEEE Transactions on Control of Network Systems, vol. 8, no. 1, p. 450–461, 2021.