Paper deep dive
Decentralized Geometric Control for Cable-Suspended Payload Transport with Adaptive Mass Estimation
Hadi Hajieghrary, Benedikt Walter, Paul Schmitt, Miguel Hurtado
Intelligence
Status: succeeded | Model: Gemma-4-26B-A4B | Prompt: intel-v1 | Confidence: 92%
Last extracted: 7/9/2026, 6:37:08 AM
Summary
This paper introduces GPAC, a decentralized four-layer hierarchical architecture for cooperative aerial transport of cable-suspended payloads using multiple quadrotors. GPAC enables implicit coordination through local cable measurements, geometric control on nonlinear manifolds, anti-swing regulation, an extended-state observer for wind rejection, concurrent learning-based mass estimation, and a CBF-inspired safety filter. High-fidelity simulations demonstrate robust payload tracking with low computational cost.
Entities (8)
Relation Signals (7)
GPAC → achieves → 33.8 cm RMSE
confidence 96% · yields a 33.8 cm mean payload-tracking RMSE (2.8% coefficient of variation over 13 seeds) at a low per-agent computational cost
GPAC → enables → Decentralized Coordination
confidence 96% · enables N quadrotors to transport a cable-suspended payload without a central coordinator
GPAC → implements → Geometric Control
confidence 95% · GPAC operates directly on the full nonlinear configuration manifold and integrates geometric position and attitude control
GPAC → utilizes → Control Barrier Function
confidence 94% · priority-ordered control barrier function (CBF)-inspired safety filter that reduces operational risk
GPAC → integrates → Extended-State Observer
confidence 92% · GPAC operates directly on the full nonlinear configuration manifold and integrates geometric position and attitude control, anti-swing regulation, an extended-state observer for wind rejection
GPAC → employs → Concurrent Learning
confidence 90% · concurrent learning-based mass estimation without persistent excitation
GPAC → validateson → Drake
confidence 88% · High-fidelity Drake-based simulation with bead-chain cables, onboard sensor fusion, and Dryden wind turbulence
Cypher Suggestions (0)
No Cypher suggestions yet.
Abstract
Abstract:Cooperative aerial transport requires controllers that respect nonlinear manifold geometry, operate without centralized coordination, and respect operational safety constraints. To address these demands, we present GPAC, a four-layer hierarchical architecture that enables $N$ quadrotors to transport a cable-suspended payload without a central coordinator or by exchanging cable states or adaptive parameters. The key insight is implicit coordination: each quadrotor independently estimates its effective load share from local cable measurements, so combined forces converge to the correct total, even without knowledge of $N$ or the payload mass; the payload position is reconstructed locally from each agent's own cable geometry, and the only inter-agent communication is a low-rate neighbor-position broadcast for collision avoidance. GPAC operates directly on the full nonlinear configuration manifold and integrates geometric position and attitude control, anti-swing regulation, an extended-state observer for wind rejection, concurrent learning-based mass estimation without persistent excitation, and a priority-ordered control barrier function (CBF)-inspired safety filter that reduces operational risk, with input-to-state safety (ISSf) margins that hold exactly under single-constraint activation. A compatibility result shows that the filter's force modifications keep the desired attitude within the almost-global stability region of the $\mathrm{SO}(3)$ attitude controller. Finally, high-fidelity simulation with flexible cables, onboard sensor fusion, and wind turbulence -- with all control and estimation loops closed through the estimator -- yields a mean payload-tracking RMSE of 33.8 cm (2.8\% coefficient of variation over 13 seeds) at a low per-agent computational cost.
Tags
Links
- Source: https://arxiv.org/abs/2607.00024v1
- Canonical: https://arxiv.org/abs/2607.00024v1
Trouble viewing inline? Open PDF directly →
Full Text
67,049 characters extracted from source content.
Expand or collapse full text
Decentralized Geometric Control for Cable-Suspended Payload Transport with Adaptive Mass Estimation Hadi Hajieghrary1, Benedikt Walter2, Paul Schmitt3, and Miguel Hurtado4 1Hadi Hajieghrary (hadi.hajieghrary@gatech.edu), 2Benedikt Walter (walter.benedikt@gmail.com), 3Paul Schmitt (pauls@massrobotics.org), and 4Miguel Hurtado (miguel.hurtadomit@gmail.com) prepared this manuscript and present it solely in their individual capacities. The views expressed in this paper are those of the authors and do not necessarily reflect the views of their employers or affiliated organizations. Abstract Cooperative aerial transport requires controllers that respect nonlinear manifold geometry, operate without centralized coordination, and respect operational safety constraints. To address these demands, we present GPAC, a four-layer hierarchical architecture enabling N quadrotors to transport a cable-suspended payload without a central coordinator and without exchanging cable states or adaptive parameters. The key insight is implicit coordination: each quadrotor independently estimates its effective load share from local cable measurements, so combined forces converge to the correct total, even without knowledge of N or the payload mass; the payload position is reconstructed locally from each agent’s own cable geometry, and the only inter-agent communication is a low-rate neighbor-position broadcast for collision avoidance. GPAC operates directly on the full nonlinear configuration manifold and integrates geometric position and attitude control, anti-swing regulation, an extended-state observer for wind rejection, concurrent learning-based mass estimation without persistent excitation, and a priority-ordered control barrier function (CBF)-inspired safety filter that reduces operational risk, with input-to-state safety (ISSf) margins that hold exactly under single-constraint activation. A compatibility result shows that the filter’s force modifications keep the desired attitude within the almost-global stability region of the SO(3)SO(3) attitude controller. Finally, high-fidelity simulation with flexible cables, onboard sensor fusion, and wind turbulence—with all control and estimation loops closed through the estimator—yields a 33.8 cm mean payload-tracking RMSE (2.8% coefficient of variation over 13 seeds) at a low per-agent computational cost. I Introduction Cooperative aerial transport involves several unmanned aerial vehicles (UAVs) working together to carry a payload with cables. This approach offers greater capacity, a larger workspace, and better fault tolerance than using a single UAV. However, these systems are safety-critical. Issues such as cable slack, excessive swing, vehicle tilt, collisions between UAVs, and disturbances can all cause loss of control or make the payload unstable. To achieve cooperation among N quadrotors, controllers must handle the nonlinear system dynamics, operate without centralized coordination, and address the main failure modes. Lee, Sreenath, and Kumar [9, 14] developed a method for cable-suspended transport using the full nonlinear configuration manifold, achieving almost-global stability without issues arising from Euler-angle singularities. Later, they added anti-swing control for the cables [10]. Sharma and Sundaram [12] created a geometric controller for multi-UAV payload transfer that does not need link information. Sun et al. [15] showed agile cooperative cable manipulation with online kinodynamic planning. A differential-geometric constrained-mechanics framework earlier modeled cooperative cable towing—holonomic cable constraints coupled to nonholonomic vehicle dynamics—and decomposed the team transport problem into agent–load subsystems, validated on planar marine vehicles [6]; GPAC carries this geometric decomposition into the aerial, safety-critical setting, replacing shared payload-state feedback with local cable-based reconstruction and adaptive load-share estimation. However, these controllers require centralized state information or complete feedback on the payload. Each quadrotor must know the number of cooperating UAVs N and the payload mass mLm_L, or the states of all other UAVs. This is not practical if communication is unreliable. Consensus-based formation controllers and distributed optimization methods use linearized dynamics and Euclidean error measures. These methods lose global stability during large-angle maneuvers, which is when stability is most important. Wang et al. [17] introduced Auto-Multilift, a distributed learning system that tunes model predictive control (MPC) cost functions online for cooperative load transport. However, this method relies on optimization-based MPC rather than geometric control and does not provide Lyapunov stability guarantees. Concurrent learning [3, 4] allows convergence without persistent excitation by using stored data, which matters because cooperative hover does not provide enough excitation. So far, concurrent learning has only been used in centralized, single-vehicle cases. Cable-suspended transport requires real-time state constraints. The cables must stay taut, cable angles must be within limits, swing rates must be controlled, and collisions must be avoided. Control Barrier Functions (CBFs) [2, 1] enforce these constraints using online quadratic programs (QPs) that make minimal changes to the main controller. Yang and Xie [20] combined CBFs with disturbance estimators to improve safety for single-quadrotor cable-suspended payloads. They found that disturbance-observer CBFs are less conservative when the model is uncertain. However, combining CBFs with geometric controllers on nonlinear manifolds while maintaining Lyapunov guarantees remains an open problem. This is even harder in decentralized multi-agent systems, where constraints and attitude stability must be managed simultaneously. Most studies on geometric transport assume cables are rigid and state feedback is perfect. In reality, cables are flexible, show wave effects, and can go from slack to taut. These factors have a big impact on system behavior [18]. Onboard estimation must combine noisy IMU and GPS data with nonlinear filters [13]. Wind also adds unpredictable forces. How well geometric cooperative controllers handle these real-world issues remains poorly understood. In short, there is no current framework that provides geometric manifold control, decentralized adaptive estimation without persistent excitation, and runtime safety supervision for multi-UAV cable transport. To close these gaps, safety-critical engineering focuses on identifying and reducing major hazards early [11]. Rather than building a single large controller and checking safety afterward, each GPAC layer targets a specific transport risk: anti-swing control stabilizes swinging, adaptive estimation handles load uncertainty, the extended state observer (ESO) handles disturbances, and the CBF layer acts as a safety supervisor during operation. The system uses a layered, multi-rate structure with separate timescales to limit fault spread, and its coordinator-free design removes single points of failure [8]. Table VII in Section VI shows this mapping with real data. Building on this idea, the GPAC architecture breaks down the cooperative transport problem into N identical single-agent tasks. The key insight is that each quadrotor can estimate its effective load share—its payload share plus the weight of its own cable—from only its local cable measurements. The combined forces from all agents then sum to the total weight the team supports: ∑i=1NFi=∑i=1Nθ^i⋅u⟶(mL+mcab)⋅u, _i=1^NF_i= _i=1^N θ_i· u\; \;(m_L+m_cab)· u, (1) In this setup, u:=ge3+p¨Ldu:=g\,e_3+ p_L^d is the common payload acceleration demand computed identically by every agent from the shared reference, and mcabm_cab is the total cable mass (the idealized massless-cable limit recovers mLum_L\,u; Section IV). This approach means there is no need for a central coordinator, for exchanging payload or cable states, for consensus protocols, or for knowing the payload mass in advance. The main contributions are: 1. A coordinator-free controller for multi-UAV cable transport that operates directly on the nonlinear manifold without linearization, requiring no payload-state, cable-state, or adaptive-parameter exchange; each agent reconstructs the payload position locally from its own cable, and the only inter-agent communication is a low-rate neighbor-position broadcast for collision avoidance. 2. Each agent estimates its effective load share (payload plus its own cable) θ^i θ_i from local cable tension and direction, with exponential convergence to a uniformly ultimately bounded neighborhood—even during near-hover conditions where classical adaptive laws fail. 3. A modular, priority-ordered safety-supervision layer that reduces the risk of cable slack, excessive cable angle, excessive tilt, swing-rate growth, and inter-agent collision. The associated input-to-state safety (ISSf) margins hold exactly under single-constraint activation, while simultaneous activation is handled by priority-ordered feasibility. Theorem 1 shows the CBF-induced force modifications keep the desired attitude within the almost-global stability region of the SO(3)SO(3) geometric attitude controller. 4. High-fidelity Drake-based simulation with bead-chain cables, onboard sensor fusion, and Dryden wind turbulence, with all loops closed through the ESKF, achieving 33.833.8 cm mean payload RMSE (2.8%2.8\% CV over 13 seeds) at low per-agent computational cost. I System Modeling The world frame W has e3e_3 upward. Rotations lie in SO(3)SO(3); the hat map (⋅)∧:ℝ3→(3)(·) :R^3→ so(3) satisfies v^w=v×w vw=v× w. Cable directions qi∈2q_i ^2 have tangent projection P(q)=I3−qq⊤P(q)=I_3-q . The system evolves on =SE(3)⏟payload×∏i=1NSE(3)×2⏟quadrotor i + cable,dim()=6+8N.Q= SE(3)_payload× _i=1^N\! SE(3)×S^2_quadrotor i + cable, (Q)=6+8N. (2) N identical quadrotors (mass mQm_Q, inertia J) obey mQp¨i m_Q p_i =−mQge3+fiRie3+Ficable+Fiwind, =-m_Qg\,e_3+f_iR_ie_3+F_i^cable+F_i^wind, (3) JΩ˙i J _i =−Ωi×JΩi+τi+τiext, =- _i× J _i+ _i+ _i^ext, (4) with kinematics R˙i=RiΩ^i R_i=R_i _i, where fif_i is scalar thrust, τi _i is control torque, FicableF_i^cable is cable tension, and FiwindF_i^wind is aerodynamic disturbance. With e3e_3 upward, gravity acts as −ge3-ge_3 on both the quadrotors and the payload. The payload (mass mLm_L, position pLp_L) satisfies mLp¨L=−mLge3+∑i=1NFiL+Fcontact+FLwindm_L p_L=-m_Lg\,e_3+ _i=1^NF_i^L+F^contact+F_L^wind, where FiLF_i^L is the cable force from the i-th rope at the payload attachment point, and FcontactF^contact denotes ground normal and Coulomb friction forces. The cable direction qi∈2q_i ^2 from payload to quadrotor evolves as q˙i=ωqi×qi q_i= _q_i× q_i with ωqi∈Tqi2 _q_i∈ T_q_iS^2. Under constraint pi=pL+RLρiL+Liqip_i=p_L+R_L _i^L+L_iq_i (ρiL _i^L: attachment offset in payload frame), swing dynamics on 2S^2 are governed by projected quadrotor acceleration and gravitational restoring torque (the singularity-free error functions parameterizing these dynamics are defined in Section I). Rigid-link cable models neglect compliance, wave propagation, and slack-to-taut transitions that significantly affect transport behavior. To capture these effects, each cable is discretized as nbn_b point-mass beads connected by nb+1n_b+1 tension-only spring-damper segments. Let b0b_0 be the quadrotor attachment, b1,…,bnbb_1,…,b_n_b the bead positions, and bnb+1b_n_b+1 the payload attachment. Each segment has rest length L0=Lrest/(nb+1)L_0=L_rest/(n_b+1), stretch Δj=∥bj−1−bj∥−L0 _j= b_j-1-b_j -L_0, and unit direction e^j=(bj−1−bj)/∥bj−1−bj∥ e_j=(b_j-1-b_j)/ b_j-1-b_j . The tension-only force law is Tj=ksΔj+cs[Δ˙j]+T_j=k_s _j+c_s[ _j]^+ when Δj>0 _j>0, and 0 when Δj≤0 _j≤ 0, where [⋅]+=max(⋅,0)[·]^+= (·,0) restricts damping to stretching. Segment stiffness derives from a maximum-stretch criterion (ϵmax=15% _ =15\%): ks=FloadLrestϵmax⋅(nb+1),cs=crefks/kref,k_s= F_loadL_rest\, _ ·(n_b+1), c_s=c_ref k_s/k_ref, (5) with Fload=mLg/NF_load=m_Lg/N and kref=300k_ref=300 N/m, cref=15c_ref=15 N⋅·s/m. Each bead (mass mb=mrope/nbm_b=m_rope/n_b, mrope=0.2m_rope=0.2 kg) obeys mbb¨j=Fj−Fj+1−mbge3m_b b_j=F_j-F_j+1-m_bg\,e_3. The model supports wave propagation (∼ksL0/mb k_sL_0/m_b), distributed inertia, and impulsive loading during slack-to-taut transitions. Each quadrotor carries an onboard sensor suite (see Table I for parameters). The IMU provides body-frame specific force a~i=Ri⊤(p¨i+ge3)+bai+nai a_i=R_i ( p_i+ge_3)+b_a_i+n_a_i and angular velocity ω~i=Ωi+bgi+ngi ω_i= _i+b_g_i+n_g_i with Gauss–Markov biases (b˙=−b/τ+η b=-b/τ+η, τ=3600τ=3600 s). The GPS provides position with dropout probability. Cable tension TiT_i is measured via a load cell, and direction qiq_i via a 2-axis encoder. Wind follows the Dryden turbulence spectrum (MIL-F-8785C) with forming filter Hα(s)=σα2V/Lα/(s+V/Lα)H_α(s)= _α 2V/L_α/(s+V/L_α) and altitude-dependent scaling σα(h)∝(h/href)1/6 _α(h) (h/h_ref)^1/6. Inter-agent spatial correlation decays as ρ(pi,pj)=exp(−∥pi−pj∥/ℓc)ρ(p_i,p_j)= (- p_i-p_j / _c) with ℓc=10 _c=10 m, so closely spaced quadrotors experience similar wind. TABLE I: Key System Parameters Parameter Symbol Value Quadrotor mass / count mQm_Q / N 1.5 kg / 3 Payload mass / radius mLm_L / rLr_L 3.0 kg / 0.15 m Formation radius rfr_f 0.6 m Beads per cable nbn_b 8 Rope mass / max stretch mropem_rope / ϵmax _ 0.2 kg / 15% IMU rate / noise fIMUf_IMU / σa _a 200 Hz / 0.0040.004 m/s2/Hz\! Hz GPS rate / noise fGPSf_GPS / σxy _xy 10 Hz / 0.02 m Baro rate / noise fbarof_baro / σw _w 25 Hz / 0.3 m Wind intensity σu,σv _u, _v / σw _w 0.5 / 0.25 m/s Simulation step Δtsim t_sim 0.2 ms I GPAC Control Architecture GPAC is a four-layer hierarchical controller assigning each physical degree of freedom to a dedicated control layer, organized by timescale (Fig. 1). Each agent i receives only: (i) a shared trajectory pd(t)p_d(t) broadcast before flight, (i) its own IMU/GPS/barometer measurements, and (i) local cable tension TiT_i and direction qiq_i. The payload position is neither measured nor broadcast; each agent reconstructs it locally from its own cable geometry (Section IV). No payload state, other cable states, or centralized coordinator is required. The control cascade requires no inter-agent state exchange; the only runtime communication is a 10 Hz neighbor-position broadcast used by the collision-avoidance barrier, and the desired heading ψd _d is part of the pre-broadcast trajectory parameters. Throughout, layer refers to the four cascade stages—L1 position/anti-swing, L2 attitude, L3 mass estimation, L4 ESO—while the ESKF sensor fusion and the priority CBF filter are supporting overlays that wrap the cascade rather than additional cascade layers. Layer 1: Position+ Anti-Swing (50 Hz)CBF Safety Filter(200 Hz)Layer 2: Attitudeon SO(3)SO(3) (200 Hz)Layer 3: MassEstimator (50 Hz)Layer 4: ESO(ω0=8 _0\!=\!8)ESKF SensorFusion (200 Hz)Quadrotori + Bead-Chain Cable + PayloadFdes,RdF_des,\,R_dfsafe,Rdsafef_safe,\,R_d^safeτi,fi _i,\,f_iθ^i θ_id^i d_ip^i,v^i p_i, v_isensorsp^i,v^i p_i, v_i Figure 1: GPAC per-agent architecture. Blue: control cascade; red: CBF overlay; teal: estimation; green: sensor fusion. Solid arrows are control/estimate signals; dashed arrows are state feedback (black) and raw sensing (gray). Each agent executes independently; only neighbor positions are broadcast at 1010\,Hz (for collision avoidance). The singularity-free error functions are defined as: eRi e_R_i =12(Rdi⊤Ri−Ri⊤Rdi)∨, = 12(R_d_i R_i-R_i R_d_i) , (6) Ψqi _q_i =1−qdi⋅qi∈[0,2], =1-q_d_i· q_i∈[0,2], (7) eqi e_q_i =P(qi)qdi∈Tqi2, =P(q_i)\,q_d_i∈ T_q_iS^2, (8) where eRie_R_i is the attitude error on SO(3)SO(3) [9], Ψqi _q_i is the cable configuration error on 2S^2 [10], and eqie_q_i is the negative gradient of Ψqi _q_i restricted to the tangent space Tqi2T_q_iS^2. These are used throughout the control and safety layers that follow. I-A Layer 1: Position Tracking and Anti-Swing Control The outermost layer (∼ 50 Hz) computes the total desired force as a sum of feedback, feedforward, cable compensation, anti-swing, and ESO terms: Fdes,i=Ffb,i+Fff,i+Fcable,i+Fswing,i+Feso,i.F_des,i=F_fb,i+F_f,i+F_cable,i+F_swing,i+F_eso,i. PID tracking feedback with per-axis anti-windup is Ffb,i=−Kpepi−Kdevi−KieIiF_fb,i=-K_p\,e_p_i-K_d\,e_v_i-K_i\,e_I_i, with gains Kp=diag(26,26,24)K_p\!=\!diag(26,26,24), Kd=diag(13,13,12)K_d\!=\!diag(13,13,12), Ki=diag(0.4,0.4,2.5)K_i\!=\!diag(0.4,0.4,2.5) (Table I). The vertical integral gain is raised so the integrator cancels the load-induced altitude deficit; the horizontal gain is kept small to avoid windup on the moving reference. Feedforward compensates gravity, the nominal trajectory, and the measured cable tension: Fff,i=mQ(adi+ge3)+Tin^iF_f,i=m_Q(a_d_i+ge_3)+T_i n_i. Cable tension compensation prevents treating cable force as disturbance: Fcable,i=κT(t)TiqiF_cable,i= _T(t)\,T_i\,q_i, where κT(t)=min(1,(t−ttaut,i)/Δramp) _T(t)= \! (1,\,(t-t_taut,i)/ _ramp ), with ttaut,it_taut,i the time cable i reaches Ti≥1.0T_i≥ 1.0 N and Δramp=2 _ramp=2 s. The ramped gain uses only measured cable force—no knowledge of mLm_L or N is required—preventing impulsive loading during the slack-to-taut transition while remaining coordinator-free. Anti-swing control suppresses pendular oscillations on 2S^2: Fswing,i=kqeqi−kωωqiF_swing,i=k_q\,e_q_i-k_ω\, _q_i, with kq=2.0k_q\!=\!2.0, kω=3.0k_ω\!=\!3.0 [10]. Here eqie_q_i Eq. (8) steers qi→qdiq_i→ q_d_i along the geodesic and ωqi∈Tqi2 _q_i∈ T_q_iS^2 is the cable angular rate, estimated from a dirty derivative of the measured cable direction. Together, these drive Ψqi _q_i monotonically toward zero in the absence of external perturbation. The ESO disturbance estimate (Layer 4) feeds forward as Feso,i=mQd^iF_eso,i=m_Q d_i. Desired rotation Rdi∈SO(3)R_d_i (3) is extracted from Fdes,iF_des,i by aligning the body z-axis with the thrust direction [9]: b3c=Fdes,i∥Fdes,i∥,b2c=b3c×b1d∥b3c×b1d∥,b1c=b2c×b3c,b_3c= F_des,i F_des,i ,\;\;b_2c= b_3c× b_1d b_3c× b_1d ,\;\;b_1c=b_2c× b_3c, (9) with b1d=[cosψd,sinψd, 0]⊤b_1d=[ _d,\, _d,\,0] setting the desired heading. The construction is well-defined provided Fdes,i≠0F_des,i≠ 0 (guaranteed by the gravity feedforward) and b3c∦b1db_3c b_1d; when ∥b3c×b1d∥ b_3c× b_1d drops below a threshold (near-vertical thrust aligned with the heading), b1db_1d is replaced by the world x-axis projected onto the plane orthogonal to b3cb_3c, keeping RdiR_d_i continuous. I-B Layer 2: Geometric Attitude Control on SO(3) The inner attitude loop (200 Hz) uses the geometric tracking controller [9]: τi=−kReRi−kΩeΩi+Ωi×JΩi, _i=-k_R\,e_R_i-k_ \,e_ _i+ _i× J _i, (10) with kR=8.0k_R\!=\!8.0, kΩ=1.5k_ \!=\!1.5, and eΩi=Ωi−Ri⊤RdiΩdie_ _i= _i-R_i R_d_i _d_i. The first two terms provide PD control on SO(3)SO(3); the third compensates gyroscopic coupling. Feedforward terms Ωi^Ri⊤RdiΩdi−Ri⊤RdiΩ˙di _iR_i R_d_i _d_i-R_i R_d_i _d_i are omitted under the assumption Ωdi≈0 _d_i≈ 0, valid when desired thrust varies slowly relative to the 200 Hz attitude bandwidth. Proposition 1 (Almost-global exponential stability [9]). Define the Lyapunov function VR=12kRΨRi+12eΩi⊤JeΩi+ceRi⊤JeΩi,V_R= 12k_R\, _R_i+ 12e_ _i J\,e_ _i+c\,e_R_i J\,e_ _i, (11) where ΨRi=12tr(I−Rdi⊤Ri) _R_i= 12tr(I-R_d_i R_i) is the attitude configuration error and c>0c>0 is sufficiently small. With ΨRi(0)<2 _R_i(0)<2: V˙R≤−λmin(W)(∥eRi∥2+∥eΩi∥2), V_R≤- _ (W) ( e_R_i ^2+ e_ _i ^2 ), (12) for a positive-definite W=W(kR,kΩ,J)W=W(k_R,k_ ,J), yielding exponential convergence on the dense open set ΨR<2⊂SO(3)\ _R<2\ (3). I-C Layers 3–4: ESO and Mass Estimator Layer 4 is a third-order Extended State Observer (ESO) per translational axis, modeling dynamics as a double integrator with lumped disturbance p¨k=b0uk+dk(t) p_k=b_0u_k+d_k(t), where uku_k is the commanded acceleration and b0=mQ/meff≈0.6b_0=m_Q/m_eff≈ 0.6 uses the load-augmented effective mass meff=mQ+mL/Nm_eff=m_Q+m_L/N: z^˙1k=z^2k+3ω0x~k,z^˙2k=z^3k+3ω02x~k+b0uk,z^˙3k=ω03x~k, z_1k= z_2k+3 _0 x_k,\;\; z_2k= z_3k+3 _0^2 x_k+b_0u_k,\;\; z_3k= _0^3 x_k, (13) with x~k=xk−z^1k x_k=x_k- z_1k and a triple pole at −ω0=−8- _0=-8 rad/s (settling ∼ 0.5 s). The disturbance estimate d^i=[z^3x,z^3y,z^3z]⊤ d_i=[ z_3x, z_3y, z_3z] is saturated to |d^i,k|≤20| d_i,k|≤ 20 m/s2 and fed forward via Feso,iF_eso,i. Under bounded d˙ d, estimation error scales as O(sup|d˙|/ω0)O( | d|/ _0) [5]. Layer 3 adaptively estimates the payload mass share θ^i≈mL/N θ_i≈ m_L/N via concurrent learning [3], providing gravity compensation θ^i(ge3+p¨dL) θ_i(ge_3+ p_d^L) to Layer 1. The cascade exploits timescale separation: the attitude loop (kR/J≈200k_R/J≈ 200 rad/s) is far faster than the position loop (ωp=Kp/mQ≈5 _p= K_p/m_Q≈ 5 rad/s), the ESO (ω0=8 _0=8 rad/s), and the mass adaptation (the slowest subsystem), so the attitude dynamics form the fast boundary layer. The ESO bandwidth is reduced from a higher initial setting so its disturbance estimate captures the slow exogenous wind rather than differentiating estimator noise. Singular perturbation arguments guarantee composite stability when the attitude-to-translation bandwidth ratio exceeds a computable threshold [7]. The hierarchy also provides fault containment: mass estimation errors (Layer 3) affect only feedforward in Layer 1 without corrupting attitude tracking; ESO transients are filtered before reaching attitude; CBF interventions are bounded by the tilt constraint (Section V). This modularity supports independent layer verification [8]. IV Decentralized Adaptive Estimation Figure 2: Adaptive mass estimation. Top: Measured per-quadrotor concurrent-learning estimates θ^i θ_i about the true share mL/N=1.0m_L/N=1.0 kg. Bottom: Mean across agents with ±1± 1 standard-deviation band; the buffer-driven update holds the estimate near mL/Nm_L/N (steady-state mean 1.181.18 kg) without persistent excitation. Each quadrotor runs three estimators in a downward cascade—no payload, cable, or adaptive-parameter states are exchanged: (i) ESKF for navigation, (i) geometric load-state filter, and (i) concurrent learning mass estimator. Timescale separation—navigation at 200 Hz versus load/mass estimation at 50 Hz—allows each layer to treat inputs as quasi-static, with upstream errors propagating unidirectionally, simplifying stability analysis. A 15-state ESKF [13] with δx=[δp,δv,δθ,δba,δbg]⊤∈ℝ15δ x=[δ p,\,δ v,\,δθ,\,δ b_a,\,δ b_g] ^15 fuses IMU (200 Hz) and GPS (10 Hz). Propagation uses bias-corrected specific force aW=R(q¯)(a~−ba)−ge3a_W=R( q)( a-b_a)-ge_3 and angular velocity ωc=ω~−bg _c= ω-b_g. Covariance propagation uses the error-state Jacobian: P←ΦPΦ⊤+QdP← P +Q_d. The ESKF provides (p^i,v^i,R^i)( p_i, v_i, R_i) to all downstream layers; control closes through the estimator, not ground truth. When cable i is taut, payload position is estimated geometrically: zpi=p^i−Liniz_p_i= p_i-L_i\,n_i, where ni∈2n_i ^2 points from quadrotor to payload and LiL_i is cable rest length. Each quadrotor maintains a Kalman filter with state [p^L,i⊤,v^L,i⊤]⊤∈ℝ6[ p_L,i , v_L,i ] ^6. The prediction uses a constant-velocity model with damping (βv=0.05 _v=0.05), biasing the payload velocity toward the quadrotor velocity. This value follows from the quasi-static timescale: βv=Δtest/τqs _v= t_est/ _qs where Δtest=0.02 t_est=0.02 s (50 Hz) and τqs=0.4 _qs=0.4 s is the payload pendular half-period ≈πL/g≈\!π L/g. Halving or doubling βv _v changes load RMSE by <<5% in Monte Carlo tests, confirming low sensitivity. Measurement noise is modulated by tension confidence: ξT=min(1,Ti/Tconf),Rk←Rk/(0.1+0.9ξT), _T= \! (1,\,T_i/T_conf ), R_k← R_k/(0.1+0.9\, _T), (14) with Tconf=20T_conf=20 N. When the cable is slack, measurement variance inflates, and the filter relies on prediction. An outlier gate (κν=3.0 _ν=3.0) prevents cable whip from corrupting estimates. Under Gaussian innovation, the 3σ3σ gate corresponds to a χ2(3)χ^2(3) threshold with false-rejection probability P(χ2(3)>9)=0.029P(χ^2(3)>9)=0.029; in practice, cable whip produces innovations exceeding 10σ10σ, so the gate reliably rejects corrupted measurements while passing >>97% of valid updates. With a single cable, payload position is observable only along the cable direction; the tangential component relies on a constant-velocity prediction and drifts. The resulting per-agent load estimate is therefore poor, but it is not in the tracking loop—it feeds only the mass estimator (Layer 3), which is tracking-neutral (Section VI)—so its error does not propagate to payload tracking. Fusing all N cables would recover the tangential direction but requires inter-agent communication; this distributed fusion is left to future work. From the per-cable vertical force equilibrium, each quadrotor constructs a scalar parametric model: Ticosζi⏟φi=∥ge3+a^L∥⏟Yi⋅mLN⏟θ+εi, T_i _i_ _i= g\,e_3+ a_L _Y_i· m_LN_θ+ _i, (15) where ζi=arccos(−ni,z) _i= (-n_i,z) is the cable angle from vertical, a^L a_L is payload acceleration (via numerical differentiation with low-pass filter, τf=0.1 _f=0.1 s), and εi _i captures the modeling error. Its dominant component is the cable self-weight: the load cell at the quadrotor end supports the entire cable below it, so TicosζiT_i _i also carries the cable weight in addition to the payload share. Unequal cable lengths also redistribute load across agents; this contributes to εi _i and, ultimately, to the bounded error. Although a^L a_L is differentiated from the poor single-cable load estimate, it enters only through Yi=∥ge3+a^L∥≈gY_i= g\,e_3+ a_L ≈ g, which is dominated by gravity, so that the error is masked and does not corrupt the identification. Remark 1 (Bias sources in θ θ). The dominant term is cable self-weight. Because the load cell supports the whole cable below it, TicosζiT_i _i includes the cable weight mropegm_ropeg (mrope=0.2m_rope=0.2 kg per cable) on top of the payload share. Since gravity is vertical, the full cable weight enters the vertical balance Ticosζi=(mL/N+mrope)gT_i _i=(m_L/N+m_rope)g with no cos factor, giving a payload-independent offset εicable≈mropeg≈1.96 _i^cable≈ m_ropeg≈ 1.96 N, i.e. a bias |θ~cable|≈mrope≈0.20| θ^cable|≈ m_rope≈ 0.20 kg. The observed ≈+0.18≈+0.18 kg at the nominal payload (Table IV) sits just below this because the bead chain is not perfectly vertical and carries its own dynamics, so ∼ 90% of the cable weight registers at the top load cell. Two smaller residuals remain. Cable asymmetry (Li=L¯(1+δi)L_i= L(1+ _i)) redistributes load across agents but, by vertical equilibrium, leaves the cross-agent sum ∑iTicosζi _iT_i _i fixed; it therefore affects the per-agent spread, not the mean, and is bounded by |εiasym|≤(mLg/N)|δi|tanζ¯≤1.28| _i^asym|≤(m_Lg/N)| _i| ζ≤ 1.28 N for δmax=0.19 _ =0.19. Acceleration-estimation error through the low-pass filter (τf=0.1 _f=0.1 s) contributes |εidyn|≤O(τf∥p˙L∥)≤0.4| _i^dyn|≤ O( _f p_L )≤ 0.4 N. The UUB radius |θ~|≤ε¯/Y¯| θ|≤ / Y, with Y¯=∥ge3+a^L∥≈g Y= g\,e_3+ a_L ≈ g, is dominated by the cable-weight offset; as the payload grows the cables run more vertical and the residual fraction shrinks, so the net per-agent bias falls from +0.18+0.18 to +0.02+0.02 kg across mL∈3,6,9m_L∈\3,6,9\ kg (Table IV). The regressor Eq. (15) formalizes the implicit coordination stated in Eq. (1). With feedforward Fff,i=θ^i⋅uF_f,i= θ_i· u where u:=ge3+p¨Ldu:=g\,e_3+ p_L^d, each estimate converges to the effective per-agent share including its own cable, θ^i→mL/N+mrope θ_i→ m_L/N+m_rope, so the total feedforward ∑i=1NFff,i _i=1^NF_f,i converges to (mL+Nmrope)u(m_L+Nm_rope)\,u, the total weight the team must support. Including the cable mass in the identified load is in fact correct for feedforward, since the quadrotors lift the cables as well as the payload. No agent requires knowledge of N or mLm_L; each estimates its share from local cable measurements, and summation yields correct collective compensation. This holds because the regressor YiY_i and control u derive from the same shared trajectory, ensuring scalar parametric consistency across agents. Remark 2 (Trajectory synchronization). Since the trajectory is a polynomial stored locally and evaluated analytically, agents compute u identically up to floating-point precision (∼10−15 \!10^-15 relative error). Any clock offset Δt t introduces feedforward error bounded by ∥∂u/∂t∥Δt ∂ u/∂ t t. The concurrent-learning update augments gradient descent with stored data: θ^˙i=−γYisproj−γρ∑j=1MiYj(Yjθ^i−φj) θ_i=-γ\,Y_i\,s_proj-γρ _j=1^M_iY_j(Y_j θ_i- _j), where γ=0.5γ=0.5, ρ=0.5ρ=0.5, and sproj=si⊤nis_proj=s_i n_i projects sliding variable si=e˙L,i+λeL,is_i= e_L,i+λ e_L,i (λ=1.0λ=1.0) onto cable direction [3]. The first term drives online gradient descent; the second replays stored pairs (Yj,φj)j=1Mi\(Y_j, _j)\_j=1^M_i. The history buffer holds up to M¯=50 M=50 points, admitting samples only when excitation exceeds Ymin=0.5Y_ =0.5 m/s2 and the regressor differs from the buffer mean by δY=0.1 _Y=0.1, ensuring diversity. Estimates are projected to [θmin,θmax]=[0.1,50.0][ _ , _ ]=[0.1,50.0] kg. Proposition 2 (Finite-excitation convergence). If the history stack contains at least one informative sample, ΣY=1M∑jYj2>0 _Y= 1M _jY_j^2>0, the parameter error decays exponentially at rate γρ∑jYj2=γρMΣYγρ _jY_j^2=γρ M _Y: |θ~(t)|≤|θ~(0)|exp(−γρ(∑jYj2)t) θ(t) ≤ θ(0) \! (-γρ( _jY_j^2)\,t ), without persistent excitation of the online trajectory. With bounded modeling error |εi|≤ε¯| _i|≤ , convergence is uniformly ultimately bounded: |θ~|≤ε¯/Y¯| θ|≤ / Y, where Y¯=ΣY Y= _Y is the RMS regressor magnitude (consistent with Remark 1). Proof. Neglecting the online term (rendered nonpositive by projection onto [θmin,θmax][ _ , _ ] [4]) and substituting φj=Yjθ+εj _j=Y_jθ+ _j, the replay term gives θ~˙=−γρ(∑jYj2)θ~+γρ∑jYjεj θ=-γρ( _jY_j^2)\, θ+γρ _jY_j _j. With Vθ=12θ~2V_θ= 12 θ^2, V˙θ=−γρ(∑jYj2)θ~2+γρθ~∑jYjεj V_θ=-γρ( _jY_j^2) θ^2+γρ\, θ _jY_j _j. In the noise-free case Grönwall’s inequality yields exponential convergence at rate γρ∑jYj2γρ _jY_j^2; bounded ε leaves a residual set of radius |θ~|≤|∑jYjεj|/∑jYj2≤ε¯/Y¯| θ|≤| _jY_j _j|/ _jY_j^2≤ / Y (for Yj≈Y¯Y_j≈ Y). Empirically, taut-cable samples accumulated during flight hold the estimate within ≈±0.15≈± 0.15 kg of the effective share (Section VI). ∎ Remark 3 (Closed-loop estimation–control interaction). Proposition 2 treats the regressor as exogenous. In closed loop, θ^i θ_i enters the feedforward Fff,i=θ^iuF_f,i= θ_iu and so shapes the tracking error eL,ie_L,i and, in turn, the cable measurements feeding the estimator. A representative gain chain at the steady-state offset θ~≈0.19 θ≈ 0.19 kg (∥u∥≤11.8 u ≤ 11.8 m/s2, kp,min=6k_p, =6, L≈1L≈ 1 m): a tracking offset ≲θ~∥u∥/kp,min≈0.37 θ u /k_p, ≈ 0.37 m, a cable-angle offset ≈0.37≈ 0.37 rad, and a regressor perturbation ≈0.37Ti≈4.5≈ 0.37\,T_i≈ 4.5 N—which exceeds the modeling residual ε¯≈2.0 ≈ 2.0 N. We therefore explicitly do not claim the closed-loop coupling is absorbed within ε¯ . (This conservatively counts the cable-weight offset as fed-back error; since the estimator converges to the effective share, that offset is in fact compensated, and the residual coupling is smaller.) A rigorous certificate (a contraction condition γθγp<1 _θ _p<1 on the estimation–tracking interconnection) is left to future work; empirically, the loop is stable across all tested seeds, team sizes, and payloads (Tables IV, VIII). V CBF Safety Filter Figure 3: Top: Tension margin (distance to TminT_ ) for all cables. Middle: Cable angle margin (distance to ζmax=34.4∘ _ =34.4 ); shaded regions indicate CBF activation during aggressive cornering. Bottom: Tilt margin, held at the limit. Orange regions denote constraint activation. Figure 4: Top: Cable angle from vertical for each cable, with the CBF limit ζmax=34.4∘ _ =34.4 ; this relative-degree-two output exceeds the limit during aggressive cornering. Bottom: Quadrotor tilt angle with limit ϕmax=28.6∘ _ =28.6 ; the filter holds it at the limit. A modular, priority-ordered CBF-inspired layer supervises operational constraints via minimal post-processing, modifying GPAC output only when necessary and reducing constraint violations rather than strictly enforcing them. Each barrier function corresponds to a transport hazard from Section I, providing runtime safety supervision within the designed safety envelopes. The safety filter operates on the force fi∈ℝ3f_i ^3 from Layer 1. Abstracting translational dynamics Eq. (3) as mQp¨i=fi+wi(t)m_Q p_i=f_i+w_i(t) (affine in control, with lumped disturbance wiw_i from ESO), five barrier functions encode the safe set k=x∣hk(x)≥0C_k=\x h_k(x)≥ 0\: hTlow h_T^low =Ti−Tmin,hTup=Tmax−Ti =T_i-T_ ,\;\;h_T^up=T_ -T_i (tautness), (tautness), (16) hζ h_ζ =cosζi−cosζmax = _i- _ (cable angle), (cable angle), (17) hω h_ω =ωmax2−∥ωqi∥2 = _ ^2- _q_i ^2 (swing rate), (swing rate), (18) htilt h_tilt =cosϕi−cosϕmax = _i- _ (vehicle tilt), (vehicle tilt), (19) hcol h_col =∥pi−pj∥2−dmin2 = p_i-p_j ^2-d_ ^2 (collision), (collision), (20) with Tmin=2T_ \!=\!2 N, Tmax=60T_ \!=\!60 N, ζmax=0.6 _ \!=\!0.6 rad (34.4∘34.4 ), ωmax=1.5 _ \!=\!1.5 rad/s, ϕmax=0.5 _ \!=\!0.5 rad (28.6∘28.6 ), dmin=0.8d_ \!=\!0.8 m. Cable angle is denoted ζi _i to distinguish it from the adaptive parameter θ=mL/Nθ=m_L/N (Section IV). The first two barriers maintain cable tension within [Tmin,Tmax][T_ ,T_ ]; hζh_ζ and hωh_ω limit cable angle and swing rate; htilth_tilt bounds vehicle roll/pitch; and hcolh_col prevents inter-agent collision. Since cos(⋅) (·) is monotonically decreasing on [0,π][0,π], the safe conditions ζi≤ζmax _i≤ _ and ϕi≤ϕmax _i≤ _ are equivalent to hζ≥0h_ζ≥ 0 and htilt≥0h_tilt≥ 0, respectively. For collision Eq. (20), the second derivative involves both fif_i and fjf_j. In the decentralized setting, agent i treats neighbor acceleration as a bounded disturbance and enforces a conservative one-sided HOCBF using only its own force, with the disturbance absorbed into the ISSf margin. Tautness barriers Eq. (16) are relative-degree-one. Cable angle, tilt, and collision are relative-degree-two, handled via HOCBFs [19, 1]: defining ψ1=h˙+α1h _1= h+ _1h, the constraint ψ˙1+α2ψ1≥0 ψ_1+ _2 _1≥ 0 becomes relative-degree-one in control, with the safe set ψ1≥0∩h≥0\ _1≥ 0\∩\h≥ 0\ forward-invariant. These relative degrees are computed on the force-affine surrogate mQp¨i=fi+wim_Q p_i=f_i+w_i; in the bead-chain plant, tension and cable angle additionally depend on cable stretch, bead dynamics, and slack-to-taut transitions, so the barriers are designed on the surrogate and the high-fidelity simulation evaluates robustness to this model mismatch. V-A Priority-Ordered Safety Projection with Conditional ISSf Margins The idealized filter is the QP solved at each control cycle: fsafe=argminf,δ∥f−fnom∥2+λ∑jδj2 f_safe= argmin_f,\,δ\; f-f_nom ^2+λ\! _j\! _j^2 (21) s.t.Bj(x,f)≥−μj−δj, \;\;s.t.\;\;B_j(x,f)≥- _j- _j, where BjB_j is the control-affine constraint function for barrier j: h˙j+αjhj h_j+ _jh_j for the relative-degree-one tautness barriers, and the HOCBF form ψ˙1,j+α2,jψ1,j ψ_1,j+ _2,j _1,j (with ψ1,j=h˙j+α1,jhj _1,j= h_j+ _1,jh_j) for the relative-degree-two angle, tilt, and collision barriers. With λ=100λ=100 penalizing relaxation, and since hard forward invariance of h≥0\h≥ 0\ is unrealistic under disturbances, we use Input-to-State Safety (ISSf), coupling the robustness margin to the ESO estimate; i.e., Bj≥−μbase−κd∥d^i∥B_j≥- _base- _d d_i , with μbase=2.0 _base=2.0, κd=1.5 _d=1.5. When the ESO reports large disturbances, the margin grows, and the filter activates earlier. For a relative-degree-one barrier the steady-state violation bound is hj(t)≥−(μbase+κdd¯)/αjh_j(t)≥-( _base+ _d d)/ _j The implementation in this paper uses sequential gradient projection with priority ordering (tautness> angle> tilt> swing> collision) rather than a full QP. This approximation equals Eq. (21) when at most one constraint is active—typical, as the filter is transparent in nominal flight and engages only near a constraint boundary during aggressive cornering. The formal ISSf bound on hj(t)h_j(t) therefore holds under single-constraint activation; under simultaneous multi-constraint activation, only priority-ordered feasibility is ensured. The priority ordering reflects failure severity: tautness ranks highest because cable slack causes immediate loss of controllability, while the inter-agent clearance is held at ≥0.67≥ 0.67 m against the dmin=0.8d_ =0.8 m bound. Slack variables δj _j ensure lower-priority constraints degrade gracefully. Per-agent cost is O(Nc)O(N_c) with Nc=6N_c=6 constraints (∼ 1200 FLOPs/cycle). The safety filter modifies force direction, changing the desired rotation RdR_d. A critical requirement is that this perturbation not exit the geometric controller’s stability region. Theorem 1 (Safety–attitude compatibility). While the tilt barrier Eq. (19) is active it constrains the safe thrust direction to the cone ϕi≤ϕmax=0.5 _i≤ _ =0.5 rad, so the safe desired attitude lies within ϕmax _ of the hover attitude: ΨR(I,Rdsafe)=1−cosϕi≤1−cosϕmax≈0.12, _R(I,R_d^safe)=1- _i≤ 1- _ ≈ 0.12, (22) (≤0.15≤ 0.15 even at the worst observed tilt of 32∘32 ). The CBF-modified attitude reference, therefore, stays deep within the hover neighborhood—far from the antipodal configuration (ΨR=2 _R=2) that bounds the geometric controller’s almost-global basin (Proposition 1)—so the safety filter cannot drive the desired attitude toward the controller’s stability boundary. Proof. The tilt barrier htilt=cosϕi−cosϕmax≥0h_tilt= _i- _ ≥ 0 constrains the safe thrust direction b3c=fsafe/∥fsafe∥b_3c=f_safe/ f_safe Eq. (9) to ϕi≤ϕmax _i≤ _ . Since RdsafeR_d^safe aligns b3cb_3c with the body z-axis, its geodesic distance from the hover attitude I (where b3=e3b_3=e_3) is exactly ϕi _i, giving ΨR(I,Rdsafe)=1−cosϕi≤1−cosϕmax _R(I,R_d^safe)=1- _i≤ 1- _ . This bound holds whenever the tilt barrier is active—the regime in which the filter modifies the attitude reference. ∎ Remark 4 (Actual attitude). Theorem 1 bounds the desired reference, not the actual attitude RiR_i. The geometric controller (Proposition 1) drives Ri→RdsafeR_i→ R_d^safe exponentially from any error ΨR(Ri,Rdsafe)<2 _R(R_i,R_d^safe)<2; because the reference stays within 0.120.12 of hover and the attitude loop is fast (200200 Hz, ∼ 5 ms settling, Remark 5), the tracking error remains well inside the basin in simulation. We do not claim exponential tracking of the time-varying safe reference in the presence of the omitted angular-rate feedforward. Remark 5 (Timescale separation). Compatibility relies on three timescales: fast attitude (kR/J≈200k_R/J≈ 200 rad/s, settling 5 ms), medium safety filter (Butterworth cutoff 2π×15≈942π× 15≈ 94 rad/s), and slow position/cable dynamics (g/L≈3 g/L≈ 3 rad/s). The attitude-to-CBF bandwidth ratio 200/94≈2.1200/94≈ 2.1 is moderate. Classical singular perturbation [7, Ch. 11] typically requires this ratio to be much greater than one. Instead, we rely on a practical composability argument. The attitude settling time ( 5 ms) is less than the CBF Butterworth delay ( 11 ms). This guarantees the attitude controller resolves any step change in RdsafeR_d^safe within one safety filter cycle. Butterworth rate-limiting ensures ∥R˙dsafe∥≤2πfc⋅2ϕmax R_d^safe ≤ 2π f_c· 2 _ . Thus, the Ωdi≈0 _d_i≈ 0 simplification in Eq. (10) remains valid. The stronger separation ωatt/ωpos≈200/3≈67 _att/ _pos≈ 200/3≈ 67 does satisfy formal singular perturbation, ensuring the position-attitude cascade is stable. The CBF operates within this well-separated hierarchy. VI Simulation Results We validated GPAC using a Drake-based [16] multibody simulation, with parameters listed in Table I. The physics engine runs at 5000 Hz using a semi-implicit Euler method, and cable vibrations (around 55 Hz) are resolved with 90 times oversampling. The cable rest lengths are asymmetric ([0.994, 1.155, 0.952] m for the baseline seed), showing up to 19% variation. The multi-rate timing is set to match the GPAC layer structure. The simulation environment includes Dryden wind and a full sensor suite. All control loops are closed using the ESKF rather than ground truth, ensuring sensor-in-the-loop realism. The principal controller, estimator, and CBF parameters are listed in Table I; the complete parameter set, the waypoint trajectory, and the per-seed randomization are released with the open-source implementation.111Anonymized for review; the repository and commit hash will be provided in the camera-ready version. We report the 33D payload-position RMSE against the piecewise-linear load reference over the post-pickup window t≥2t≥ 2 s, as the mean ± standard deviation (and coefficient of variation, CV) over the Monte-Carlo seeds. TABLE I: Principal GPAC controller, ESO, concurrent-learning (CL), and CBF parameters. The full set is in the open-source implementation. Param. Value Param. Value kpxy,kdxyk_p^xy,k_d^xy 26, 1326,\,13 kpz,kdzk_p^z,k_d^z 24, 1224,\,12 kixy,kizk_i^xy,k_i^z 0.4, 2.50.4,\,2.5 ϕmax _ 0.50.5 rad kq,kωk_q,k_ω (swing) 2.0, 3.02.0,\,3.0 kR,kΩk_R,k_ (att.) 8.0, 1.58.0,\,1.5 ωo,b0 _o,b_0 (ESO) 88 rad/s, 0.60.6 τESO _ESO 0.10.1 s γ,ργ,ρ (CL) 0.5, 0.50.5,\,0.5 buffer M¯ M 5050 αT,αζ _T, _ζ (CBF) 1.5, 1.01.5,\,1.0 αϕ,αc _φ, _c 2.0, 5.02.0,\,5.0 dmind_ 0.80.8 m broadcast 1010 Hz The overall 3D RMSE is 33.6 cm for the baseline seed (4.8% of the workspace diagonal and within one cable length); a 13-seed Monte Carlo gives a mean of 33.8 cm with a 2.8% coefficient of variation, so performance is essentially seed-invariant. This is achieved with all control and estimation loops closed through the ESKF (no ground-truth feedback), under wind disturbance and 19% cable asymmetry. The horizontal and vertical channels contribute comparably (22.3 and 25.1 cm): the payload trails and swings as the formation drags it through the figure-eight, while the vertical error is concentrated in the pickup transient before the altitude integrator settles. The largest excursions occur during the figure-eight cornering, where the payload pendulum is most excited. Figure 5: 3D trajectory of the load and the quadcopters. The max velocity of the load is 1 m/s. TABLE I: Payload tracking errors (cm) for the baseline seed; the 13-seed Monte-Carlo mean is 33.8±0.933.8± 0.9 cm (2.8% CV). Horiz. Vert. 3D Phase RMSE Max RMSE Max RMSE Max Ascent (2–6 s) 15.9 42.3 47.1 60.1 49.8 61.0 Fig-8 right (7–20 s) 26.6 65.9 16.8 41.2 31.5 73.2 Fig-8 left (24–36 s) 20.7 38.1 21.2 29.2 29.6 45.2 Descent (39–43 s) 14.2 30.2 24.2 33.1 28.1 38.3 Post-descent (43–50 s) 6.7 11.7 29.0 33.7 29.8 33.7 Overall 22.3 72.2 25.1 60.1 33.6 74.5 Figure 6: Payload tracking error. Top: 3D error (RMSE 33.6 cm); peaks during aggressive cornering. Bottom: Components. The horizontal and vertical channels contribute comparably; the vertical error is concentrated in the pickup transient. Figure 7: Estimation performance. Top: ESKF error (5.0 cm RMSE). Middle: Decentralized load estimate, limited by single-cable observability. Bottom: Per-quadrotor concurrent-learning mass estimates fluctuating about mL/N=1.0m_L/N=1.0 kg (steady-state mean 1.181.18 kg). Table I breaks the baseline-seed error down by phase. The horizontal channel is tightest during the post-descent hover (6.7 cm) and largest through the figure-eight (26.6 cm) as the formation drags the payload through the corners. The vertical error is dominated by the ascent phase (47.1 cm), the slack-to-taut pickup transient before the altitude integrator cancels the load-induced deficit; in steady cruise, it settles to roughly 17–24 cm. The ESKF gives a quadrotor position RMSE of about 5.0 cm, near the GPS noise floor, with errors increasing during cornering. Low variance across Monte Carlo seeds indicates that ESKF accuracy depends on sensor noise rather than cable geometry. The decentralized single-cable load-position estimate is poor (RMSE ≈2.5≈ 2.5 m, Fig. 7), dominated by the unobservable tangential direction, with a step near t≈30t≈ 30 s when the figure-eight reverses and the tangential offset flips sign. Crucially, this estimate feeds only the tracking-neutral mass estimator and not the position loop, so it does not affect payload tracking (33.833.8 cm); recovering the tangential direction via distributed multi-cable fusion is left to future work. The concurrent-learning estimator admits taut-cable regressor samples into a fixed buffer and keeps the per-agent mass share close to the true mL/N=1.0m_L/N=1.0 kg throughout the flight (Fig. 2), with a steady-state mean of 1.181.18 kg and a 0.010.01 kg spread across seeds; the buffer-driven update provides this without persistent excitation. The impact of removing it is quantified in Table V. To separate the estimator’s identification role from any tracking role, we sweep the payload over mL∈3,6,9m_L∈\3,6,9\ kg (per-agent share 1.01.0–3.03.0 kg, N=3N=3), running each case with the adaptive feedforward active (full) and disabled (no-CL); Table IV reports both. Two facts emerge. First, the estimate recovers the true share across the full 3×3× range, with an absolute bias that stays within the Remark 1 bound ε¯/Y¯≈0.2 / Y≈ 0.2 kg and shrinks with load (+0.18+0.18 down to +0.02+0.02 kg): as the share grows the cables run more vertical and the additive modeling residual becomes a smaller fraction of TicosζiT_i _i. Second, the tracking RMSE is statistically identical with and without the adaptive feedforward at every mass—the per-axis altitude integrator absorbs the static-load deficit regardless of which feedforward supplies it. The mass-share estimate is therefore an identification mechanism—the quantity that enables implicit coordination Eq. (1) without communication—rather than a tracking gain. TABLE IV: Mass-share identification across a 3×3× payload sweep (N=3N=3, 3 seeds each). θ θ tracks the true share mL/Nm_L/N with absolute bias within the Remark 1 bound (ε¯/Y¯≈0.2 / Y≈ 0.2 kg); tracking RMSE is unchanged whether the estimate drives the feedforward (full) or not (no-CL). m_L Share θ Bias RMSE full RMSE no-CL (kg) (kg) (kg) (kg) (cm) (cm) 3 1.0 1.18±0.041.18± 0.04 +0.18+0.18 31.6±1.431.6± 1.4 32.0±1.732.0± 1.7 6 2.0 2.11±0.092.11± 0.09 +0.11+0.11 30.7±0.430.7± 0.4 31.4±0.631.4± 0.6 9 3.0 3.02±0.113.02± 0.11 +0.02+0.02 33.3±0.433.3± 0.4 33.4±0.133.4± 0.1 Table VII shows the hazard-to-mitigation mapping and the measured constraint performance, and makes explicit which constraints are strictly held and which are only reduced. The tension filter maintains positive cable tension in steady flight (per-cable mean 1313–1717 N), with brief slack-side excursions to ≈0.7≈ 0.7 N (below Tmin=2T_ =2 N) in the worst seed during the most aggressive cornering. The collision barrier, fed a 1010 Hz neighbor-position broadcast, keeps the inter-agent clearance at 0.850.85 m on average, with a worst-case 0.670.67 m that dips just below the dmin=0.8d_ =0.8 m bound; the cable swing rate stays strictly within its 1.51.5 rad/s bound (1.31.3 rad/s observed). The quadrotor tilt rides its 28.6∘28.6 cone and slightly exceeds it under load (mean 29∘29 , worst 32∘32 ). The most-exceeded constraint is the cable angle, which reaches 48∘48 (limit 34.4∘34.4 ) during aggressive cornering, as the force-level filter has limited single-step authority over this relative-degree-two output. In summary, the filter holds the swing rate strictly and keeps tension, clearance, and tilt near their bounds with brief excursions, but does not strictly enforce the cable angle; reducing these residual violations—e.g. with explicit higher-order barriers on the swing and cable-angle dynamics—is left to future work. Table V isolates each layer’s contribution with every loop closed through the estimator. The ESO disturbance feedforward is the dominant tracking benefit: removing it more than doubles the RMSE (+110%+110\%) and lets the cable angle reach 68∘68 , since the formation no longer rejects the Dryden wind. The CBF improves tracking by 19%19\% and enforces the safety constraints—removing it both raises the error and collapses the worst-case inter-agent clearance to 0.320.32 m, confirming that the barrier, not the tracking controller, produces the separation. The concurrent-learning feedforward is near-neutral for tracking (+0%+0\%): as the mass sweep (Table IV) confirms, the per-axis altitude integrator absorbs the static-load deficit at every payload, so the adaptive estimate’s role is the explicit per-agent mass share (Fig. 2) that enables implicit coordination, rather than a tracking gain. We note that the ESO is driven by a low-pass-filtered position estimate at a reduced observer bandwidth (ωo=8 _o=8 rad/s); a higher bandwidth on the raw estimate instead differentiates measurement noise into the disturbance channel and erodes the very benefit the ablation reports. TABLE V: Ablation results: payload tracking RMSE (cm). Configuration RMSE Max Angle Full GPAC (baseline) 33.6 — 49∘ No concurrent learning 33.6 ++0% 50∘ No ESO feedforward 70.6 ++110% 68∘ No CBF safety filter 40.1 ++19% 46∘ TABLE VI: Cable tension statistics (N) during steady-state flight. Asymmetric cable lengths produce unequal load sharing. Cable L_i (m) Mean Std Min Max 0 0.994 16.0 3.4 5.4 29.4 1 1.155 13.2 4.2 1.9 26.9 2 0.952 17.1 3.4 5.9 31.9 Figure 8: Cable tensions. Asymmetric lengths yield unequal load sharing, accommodated without coordination. TABLE VII: Hazard-to-mitigation mapping with constraint limits and measured performance. Hazard Mitigation Limit Observed Mass unknown CL estimation — θ^=1.18±0.01 θ\!=\!1.18\!±\!0.01 kg Wind disturbance ESO feedfwd — +110%+110\% w/o (Tab. V) Cable slack CBF tension [2, 60] N min ≈0.7≈ 0.7 N (worst) Cable angle CBF + anti-swing 34.4∘34.4 48∘48 Excessive tilt CBF tilt 28.6∘28.6 29∘29 Swing rate CBF swing 1.5 rad/s 1.3 rad/s Collision CBF separation 0.8 m ≥0.67≥ 0.67 m Sensor noise ESKF fusion — 5.0 cm RMSE VI-A Team-Size Scaling To test team-size invariance directly, we run the identical per-agent stack—no gains, geometry, or trajectory retuned—for N∈2,…,6N∈\2,…,6\, holding the per-agent share constant at mL/N=1.0m_L/N=1.0 kg (i.e. mL=Nm_L=N kg) so that team size is decoupled from per-agent load. Each entry is a 3-seed mean (Table VIII). TABLE VIII: Team-size scaling at constant per-agent share (mL/N=1.0m_L/N=1.0 kg). Identical per-agent controller; 3 seeds each. The nominal adjacent-agent spacing 2rsin(π/N)2r (π/N) at the fixed formation radius r=0.6r=0.6 m is the geometric driver of the N≥5N\!≥\!5 degradation. N RMSE (cm) Clear. (m) Tilt θ (kg) Spacing (m) 2 32.6±1.532.6± 1.5 0.960.96 28.8∘28.8 1.211.21 1.201.20 3 31.6±1.431.6± 1.4 0.870.87 29.7∘29.7 1.181.18 1.041.04 4 31.2±1.431.2± 1.4 0.490.49 30.3∘30.3 1.271.27 0.850.85 5 51.5±1.351.5± 1.3 0.210.21 37.0∘37.0 1.091.09 0.710.71 6 62.0±3.362.0± 3.3 0.120.12 39.5∘39.5 1.141.14 0.600.60 For N∈2,3,4N∈\2,3,4\ the payload RMSE is flat at 3131–3333 cm and the per-agent mass-share estimate tracks its 1.01.0 kg target (within the same ∼ 20%20\% bias seen at N=3N=3): the identical local control law is structurally reusable across team size, and tracking performance is team-size-invariant. Safety margins, however, degrade earlier than tracking, and the controller’s reusability should not be read as safe scaling. The collision clearance stays above dmin=0.8d_ =0.8 m only for N≤3N≤ 3 (0.870.87 m at N=3N=3); by N=4N=4 it has already fallen to 0.490.49 m, and the quadrotor tilt sits marginally above the nominal 28.6∘28.6 cone at every N (consistent with the baseline result, where the tilt rides its limit). The cause is formation geometry, not the control law: with a fixed radius r=0.6r=0.6 m the nominal adjacent-agent spacing 2rsin(π/N)2r (π/N) shrinks monotonically (1.041.04 m at N=3N=3, 0.850.85 at N=4N=4, 0.710.71 at N=5N=5, 0.600.60 at N=6N=6), and the realized clearance falls faster still as the loaded agents lean inward, so the collision filter is increasingly asked to maintain a separation the formation cannot geometrically provide and instead trades it for tilt. By N≥5N≥ 5 the nominal spacing itself drops below dmind_ and tracking collapses. Restoring clearance requires scaling r with N, which for the fixed 11 m cable length splays the cables past the angle limit ζmax=34.4∘ _ =34.4 ; larger teams therefore require proportionally longer cables. In short, the per-agent controller scales without modification, but the fixed-radius formation provides reliable inter-agent clearance only up to N=3N=3 (worst-case 0.670.67 m even there); beyond that, the formation radius and cable length—not the controller—set the practical team-size ceiling. VII Conclusion This paper presented GPAC, a four-layer hierarchical controller for decentralized cooperative aerial transport on SE(3)×(2)NSE(3)×(S^2)^N. The architecture’s central property is that each quadrotor runs an identical control stack using only local sensors and its cable, yet the collective system achieves coordinated payload transport with subsystem-level stability guarantees and priority-ordered safety supervision. No knowledge of the team size N or payload mass mLm_L is required; no payload, cable, or adaptive states are exchanged between agents—each reconstructs the payload position locally from its own cable—and the only inter-agent communication is a low-rate neighbor-position broadcast for collision avoidance. The hazard-oriented decomposition—each layer targeting a specific failure mode (Table VII)—enables three properties that are individually well-studied but rarely combined: geometric manifold-based stability, decentralized adaptive learning, and runtime safety supervision. Hierarchical timescale separation limits cross-layer fault propagation, the absence of a central coordinator removes that single point of failure, and the per-agent control law is structurally reusable across team sizes (Table VIII). High-fidelity simulation with flexible cables, onboard sensor fusion, and wind turbulence—with every loop closed through the ESKF—confirms the architecture operates closed-loop at low per-agent computational cost, achieving a 33.8 cm mean payload-tracking RMSE while maintaining positive cable tension (except brief slack-side excursions), the inter-agent clearance above 0.670.67 m at N=3N=3, the swing rate within bounds, and the tilt at its limit. Two constraints are not strictly enforced: the cable angle, a relative-degree-two output, is briefly exceeded during aggressive cornering, and the inter-agent clearance degrades as team size grows at fixed formation radius (Section VI). Bounding the cable angle with a higher-order barrier on the swing dynamics, and scaling the formation geometry with N, are left to future work. The present results are simulation-only, making hardware flight experiments the immediate next step. Two architectural limitations motivate further algorithmic development: the decentralized single-cable load-position estimate is limited by observability (though it lies outside the tracking loop and thus does not affect payload tracking), and the sequential CBF projection guarantees only priority-ordered feasibility—rather than full ISSf—when multiple constraints activate simultaneously. Accordingly, future work targets distributed consensus-based estimation to recover the unobservable tangential direction while preserving communication efficiency. References [1] A. D. Ames, S. Coogan, M. Egerstedt, G. Notomista, K. Sreenath, and P. Tabuada (2019) Control barrier functions: theory and applications. In Proc. European Control Conf. (ECC), p. 3420–3431. External Links: Document Cited by: §I, §V. [2] A. D. Ames, X. Xu, J. W. Grizzle, and P. Tabuada (2017) Control barrier function based quadratic programs for safety critical systems. IEEE Trans. Autom. Control 62 (8), p. 3861–3876. External Links: Document Cited by: §I. [3] G. Chowdhary and E. Johnson (2010) Concurrent learning for convergence in adaptive control without persistency of excitation. In Proc. IEEE Conf. Decision Control (CDC), p. 3674–3679. External Links: Document Cited by: §I, §I-C, §IV. [4] G. Chowdhary, M. Muhlegg, J. P. How, and F. Holzapfel (2013) Concurrent learning adaptive control of linear systems with exponentially convergent bounds. Int. J. Adaptive Control Signal Process. 27 (4), p. 280–301. External Links: Document Cited by: §I, §IV. [5] B. Guo and Z. Zhao (2013) Active disturbance rejection control for nonlinear systems: an introduction. John Wiley & Sons. External Links: Document Cited by: §I-C. [6] H. Hajieghrary, D. Kularatne, and M. A. Hsieh (2018) Differential geometric approach to trajectory planning: cooperative transport by a team of autonomous marine vehicles. In 2018 Annual American Control Conference (ACC), p. 858–863. External Links: Document Cited by: §I. [7] H. K. Khalil (2002) Nonlinear systems. 3rd edition, Prentice Hall. Cited by: §I-C, Remark 5. [8] P. Koopman and M. Wagner (2017) Challenges in autonomous vehicle safety assurance. IEEE Intelligent Transportation Systems Magazine 9 (1), p. 4–18. Cited by: §I, §I-C. [9] T. Lee, M. Leok, and N. H. McClamroch (2010) Geometric tracking control of a quadrotor UAV on SE(3). In Proc. IEEE Conf. Decision Control (CDC), p. 5420–5425. External Links: Document Cited by: §I, §I-A, §I-B, §I, Proposition 1. [10] T. Lee (2018) Geometric control of quadrotor UAVs transporting a cable-suspended rigid body. IEEE Trans. Control Syst. Technol. 26 (1), p. 255–264. External Links: Document Cited by: §I, §I-A, §I. [11] N. Leveson (2011) Engineering a safer world: systems thinking applied to safety. MIT Press. Cited by: §I. [12] M. Sharma and S. Sundaram (2023) A geometric control approach for multi-UAV cooperative payload transfer. Nonlinear Dynamics 111, p. 10077–10096. External Links: Document Cited by: §I. [13] J. Solà (2017) Quaternion kinematics for the error-state Kalman filter. arXiv preprint arXiv:1711.02508. Cited by: §I, §IV. [14] K. Sreenath, T. Lee, and V. Kumar (2013) Geometric control and differential flatness of a quadrotor UAV with a cable-suspended load. In Proc. IEEE Conf. Decision Control (CDC), p. 2269–2274. External Links: Document Cited by: §I. [15] S. Sun, X. Wang, D. Sanalitro, A. Franchi, M. Tognon, and J. Alonso-Mora (2025) Agile and cooperative aerial manipulation of a cable-suspended load. Science Robotics. Note: arXiv:2501.18802 External Links: Document Cited by: §I. [16] R. Tedrake and the Drake Development Team (2024) Drake: model-based design and verification for robotics. Note: Available at https://drake.mit.edu External Links: Link Cited by: §VI. [17] B. Wang, R. Huang, and L. Zhao (2024) Auto-multilift: distributed learning and control for cooperative load transportation with quadrotors. Note: arXiv:2406.04858 Cited by: §I. [18] P. Williams (2009) Dynamics of towed payload system using multiple aerodynamic surfaces. In Proc. AIAA Guidance, Navigation, and Control Conf., External Links: Document Cited by: §I. [19] W. Xiao, C. Belta, and C. G. Cassandras (2022) High-order control barrier functions. IEEE Trans. Autom. Control 67 (7), p. 3655–3662. External Links: Document Cited by: §V. [20] B. Yang and L. Xie (2025) Robust safe control for nonlinear quadrotor with a cable-suspended payload systems via control barrier function and disturbance estimator. Control Engineering Practice 156, p. 106158. External Links: Document Cited by: §I.