Paper deep dive
Engagement-Zone-Aware Input-Constrained Guidance for Safe Target Interception in Contested Environments
Praveen Kumar Ranjan, Abhinav Sinha, Yongcan Cao
Intelligence
Status: succeeded | Model: google/gemini-3.1-flash-lite-preview | Prompt: intel-v1 | Confidence: 95%
Last extracted: 3/26/2026, 1:27:44 AM
Summary
This paper presents an engagement-zone-aware (EZ-aware) guidance framework for an attacker to intercept a target in contested environments with multiple defenders. By modeling defender-induced engagement zones and incorporating input saturation dynamics, the authors develop a smooth switching guidance strategy that ensures safety and target interception while reducing the conservatism of traditional maximum-range-based methods.
Entities (5)
Relation Signals (3)
Attacker → avoids → Engagement Zone (EZ)
confidence 95% · the attacker must guarantee EZ avoidance by ensuring that its trajectory remains outside the engagement zone
Defender → defines → Engagement Zone (EZ)
confidence 95% · The EZ of a defender is defined as the subset of the attacker’s state space from which the defender’s engagement capability guarantees interception
Attacker → intercepts → Target
confidence 95% · The objective is to design a nonlinear guidance law that enables the attacker to intercept a stationary target
Cypher Suggestions (0)
No Cypher suggestions yet.
Abstract
Abstract:We address target interception in contested environments in the presence of multiple defenders whose interception capability is limited by finite ranges. Conventional methods typically impose conservative stand-off constraints based on maximum engagement distance and neglect the interceptors' actuator limitations. Instead, we formulate safety constraints using defender-induced engagement zones. To account for actuator limits, the vehicle model is augmented with input saturation dynamics. A time-varying safe-set tightening parameter is introduced to compensate for transient constraint violations induced by actuator dynamics. To ensure scalable safety enforcement in multi-defender scenarios, a smooth aggregate safety function is constructed using a log-sum-exp operator combining individual threat measures associated with each defender's capability. A smooth switching guidance strategy is then developed to coordinate interception and safety objectives. The attacker pursues the target when sufficiently distant from threat boundaries and progressively activates evasive motion as the EZ boundaries are approached. The resulting controller relies only on relative measurements and does not require knowledge of defender control inputs, thus facilitating a fully distributed and scalable implementation. Rigorous analysis provides sufficient conditions guaranteeing target interception, practical safety with respect to all defender engagement zones, and satisfaction of actuator bounds. An input-constrained guidance law based on conservative stand-off distance is also developed to quantify the conservatism of maximum-range-based safety formulations. Simulations with stationary and maneuvering defenders demonstrate that the proposed formulation yields shorter interception paths and reduced interception time compared with conventional methods while maintaining safety throughout the engagement.
Tags
Links
- Source: https://arxiv.org/abs/2603.23649v1
- Canonical: https://arxiv.org/abs/2603.23649v1
Trouble viewing inline? Open PDF directly →
Full Text
100,769 characters extracted from source content.
Expand or collapse full text
Engagement-Zone-Aware Input-Constrained Guidance for Safe Target Interception in Contested Environments Praveen Kumar Ranjan 111Postdoctoral Fellow, email: praveen.ranjan@my.utsa.edu, Member AIAA Abhinav Sinha 222Assistant Professor, email: abhinav.sinha@uc.edu ‡ Corresponding author, Senior Member AIAA. Yongcan Cao 333Professor, email: yongcan.cao@utsa.edu, Senior Member AIAA. Abstract This paper addresses target interception in contested, GPS-denied environments in the presence of multiple moving defenders whose interception capability is limited by finite engagement ranges. Conventional methods typically impose conservative stand-off constraints based solely on maximum engagement distance and neglect the actuator limitations of the interceptor. Instead, we formulate safety constraints using defender-induced engagement zones (EZs), defined as regions of the attacker’s state space from which capture becomes inevitable under the defenders’ current engagement capability. To explicitly account for actuator limits, the nonholonomic vehicle model is augmented with symmetric input saturation dynamics. A time-varying safe-set tightening parameter is introduced to compensate for transient constraint violations induced by actuator dynamics. To ensure scalable safety enforcement in multi-defender scenarios, a smooth aggregate safety function is constructed using a log-sum-exp (soft-minimum) operator that combines individual threat measures associated with each defender’s engagement capability. A smooth switching guidance strategy is then developed to coordinate interception and safety objectives. The attacker pursues the target when sufficiently distant from threat boundaries and progressively activates evasive motion as the EZ boundaries are approached. The resulting controller relies only on relative measurements and does not require knowledge of defender control inputs, thus facilitating a fully distributed and scalable implementation. Lyapunov-based analysis provides sufficient conditions guaranteeing target interception, practical safety with respect to all defender engagement zones, and satisfaction of actuator bounds. An input-constrained guidance law based on conservative stand-off distance is also developed to quantify the conservatism of maximum-range-based safety formulations. Simulation studies with stationary and maneuvering defenders demonstrate that the proposed EZ-aware formulation yields shorter interception paths and reduced interception time compared with conventional maximum-range-based safety methods while maintaining safety throughout the engagement. 1 Introduction The growing need for autonomous systems operating in contested environments necessitates guidance strategies that ensure both survivability and mission accomplishment [doi:10.2514/1.37030, doi:10.2514/1.G007057, doi:10.2514/1.G003157, 10634571, 10660561, 10839025]. Applications such as target interception, air defense, and precision strike missions place requirements on guidance strategies in addition to ensuring negligible miss distance. Such requirements have been addressed in the form of terminal constraints, e.g., impact time (see [9000526, doi:10.2514/1.G005367, doi:10.2514/1.G005180] and references therein). However, in many settings, the pursuer must often breach defended regions to engage with the target and function under strict sensing and maneuvering limitations. A fundamental abstraction for analyzing these interactions is the Target–Attacker–Defender (TAD) engagement, where a pursuer (or attacker) attempts to reach a target while one or more defenders employ interception strategies to neutralize the attacker [sinha2022three, 9274339]. While defender–target cooperation [7171913, 9274339, Casbeer2018, sinha2022three, doi:10.2514/6.2010-7876, doi:10.2514/1.58566] has been the primary focus in most prior studies of TAD games, only limited attention has been given to strategies from the attacker’s perspective. In [doi:10.2514/6.2025-1902], the authors presented a pursuit strategy under an adversarial environment by leveraging reinforcement learning and data-driven methodologies. The three-agent pursuit-evasion dynamics is further investigated in [doi:10.2514/1.61832], where differential game formulations are employed to derive sufficient conditions for the attacker to strike the target while avoiding interception by the defenders. The authors in [SUN20192337] designed guidance laws to steer the attacker to a defender-safe boundary and then maintain a critical miss distance, establishing attacker-win conditions under linearized game dynamics without requiring knowledge of the target/defender’s control efforts. In [doi:10.2514/1.51611], a linear quadratic differential game was used to derive cooperative pursuit–evasion strategies, including the homing interceptor’s optimal pursuit and evasion policy. The authors in [QI20171958] utilized a three-player bounded-control game to design an attacker strategy that guarantees a miss distance from the defender by avoiding the infeasible zero effort miss region and establishes sufficient conditions for the attacker’s success. It is worth mentioning that most of the safety constraints in interception and pursuit-evasion problems are typically enforced via feasibility constraints, e.g., minimum distance from obstacle or threat region, and ad-hoc actuator limits during implementation. As a result, such considerations do not explicitly characterize the effective input bounds for safety preservation. For example, the authors in [doi:10.2514/1.G003223] developed an intercept-angle target interception law for a multiple-obstacle environment by enforcing safety constraints through minimum-distance constraints within an optimal guidance formulation. In [8263864], a multiple TAD differential game was studied, where target safety is ensured through optimal defender-attacker pairing strategies and feedback control laws derived from double-integrator dynamics. Other works have addressed safety via input constraints. In [RUSNAK20119349], the control effort of the players is penalized in a TAD game through quadratic costs, resulting in the bounds appearing as part of the optimization objective rather than as explicit safety constraints. In [11288066], guidance law was developed for impact-time interception that explicitly accounts for seeker field of view constraints and actuator bounds by incorporating an input affine saturation model. In [doi:10.2514/1.47276], the authors developed a multi-model adaptive estimator-guidance framework utilizing model-dependent gains to account for actuator saturation and target maneuver uncertainty. The authors in [ranjan2025incp] developed an input-constrained guidance law for an attacker in a multiple static defender threat environment using a discontinuous switching function. A time-constrained target-intercept guidance strategy was developed in [doi:10.2514/6.2026-0121] to lead an attacker toward a target while avoiding multiple obstacles of varying sizes. Most of the above-mentioned works require complete knowledge of the defender’s strategy to guarantee the attackers’ escape and employ simplified vehicle models (e.g., linearized dynamics). This assumption may be impractical in realistic scenarios, especially those involving multiple defenders with range and maneuverability constraints. A more practical approach is to design the intercept guidance strategy using geometric threat sets rather than exact defender threat predictions. An engagement zone (EZ) defines the set of attacker-relative states from which a defender can guarantee interception, assuming the attacker does not change course. Several studies have explored modeling engagement or capture zones under different structural constraints (e.g., static obstacles [OYLER20161], constrained environments [ZHOU201664], and visibility [IBRAGIMOV1998187]). An alternate relevant formulation involves modeling the defenders as range-limited, where each defender can travel only up to a maximum range, as considered in [10365808, doi:10.2514/1.I011394, doi:10.2514/1.I011593]. These modeling approaches offer ways to encode threat geometry, which helps develop safety-aware guidance strategies in constrained environments. Unlike static safety margins or fixed threat envelopes, EZs are dynamic, geometry-dependent, and can be analytically characterized. This formulation incorporates key factors such as velocity ratios, turning constraints, and capture radii. Therefore, incorporating EZ information into guidance design enables more accurate identification of the safe maneuvering region to reduce conservatism and improve interception efficiency in a contested environment. Moreover, the analytical characterization of the EZs allows for the safety to be evaluated directly from engagement geometry, circumventing the need for repeated optimization steps typically required in constrained optimal control or model predictive control approaches. Additionally, practical interceptor systems operate under input constraints, and neglecting these constraints may result in infeasible guidance commands that compromise safety during the engagement. However, most existing approaches rely on computationally expensive, optimization-based methods that use global information and do not explicitly guarantee safety or input constraint satisfaction. Despite substantial progress in characterizing EZs and capture regions, most methods rely on online optimization that treats EZs and input bounds as constraints, leading to significant computational overhead and limiting their applicability in fast, decentralized, and resource-constrained environments, especially when multiple defenders are present. Motivated by these limitations, we develop an engagement-zone-aware guidance framework for the attacker that explicitly incorporates input constraints while ensuring safety with respect to defender-induced threats. To the best of our knowledge, this is the first work that systematically integrates analytic EZ characterization with input-constrained feedback design for safe target interception in a contested environment. The main contributions of this work are summarized below. First, we develop a nonlinear switching guidance strategy using only relative measurements that enables the attacker to intercept a target in the presence of multiple moving defender threats while ensuring safety and satisfying input constraints. Unlike optimization-based or differential game approaches, the proposed strategy relies on analytical safety characterization and provides the guidance law in a feedback form to enable computationally efficient real-time implementation. Second, the safety guarantees in our proposed design are twofold– (i) safety with respect to defender-induced threats, and (i) safety ensuring permissible bounded control input while maintaining safety or stability. Our work aggregates individual defender EZ-based threats via a smooth log-sum-exp approximation to account for multiple defenders. Therefore, our method reduces the conservatism associated with prior methods that rely on fixed stand-off distances to enable efficient interception in contested environments. Third, the proposed design provides safety guarantees by augmenting the engagement kinematics with a smooth symmetric input saturation model and proposing a safe-set tightening parameter that shrinks the safe set to enable the vehicle to preemptively apply deceleration when heading towards EZs. Unlike prior methods that treat actuator limits only as feasibility constraints or ignore their impact on safety, the proposed approach explicitly integrates input constraints into the safety-critical guidance design. Moreover, we provide analytical guarantees on safety and interception performance under bounded control inputs. Fourth, we also develop a guidance strategy based on conservative stand-off distance constraints and contrast it with the engagement zone formulation for further insights. In both scenarios, we establish theoretical guarantees showing that the proposed strategies preserve safety with respect to all defender engagement zones while satisfying input constraints. 2 Preliminaries and Problem Formulation This section formulates the attacker-defender-target engagement kinematics in relative coordinates, incorporating bounded-rate dynamics for the control input. We then characterize the defender-induced EZs and formulate the control objectives for the attacker to intercept the target while maintaining safety from the defenders. 2.1 Vehicles’ Relative Kinematics Model Consider a multi-agent engagement scenario consisting of a mobile attacker A, n moving defenders denoted by the set =D1,D2,…,DnD=\D_1,D_2,…,D_n\, and a stationary target T, as illustrated in Figure˜1. Each defender is equipped with an interception capability that can only reach a finite distance from its instantaneous position. This maximum engagement distance is represented by the dotted black circles centered at each defender in Figure˜1. Figure 1: Attacker-Target-Defender engagement geometry. The attacker and the defenders are modeled as nonholonomic vehicles moving at constant speed. Their kinematics in the inertial frame are described by x˙i=vicosγi,y˙i=visinγi,γ˙i=aivi, x_i=v_i _i, y_i=v_i _i, γ_i= a_iv_i, (1) where the subscript i denotes the attacker (i=Ai=A) or the jjth defender (i=Dji=D_j) with j∈j , [xi,yi]⊤∈ℝ2[x_i,y_i] ^2 denotes the vehicle position, vi>0v_i>0 denotes the vehicle speed, γi∈(0,2π] _i∈(0,2π] denotes the vehicle heading angle and aia_i denotes the lateral acceleration that is the only control input to the vehicle model. This vehicle model captures the motion of turn-constrained platforms such as fixed-wing aircraft, missiles, and underwater vehicles that maneuver through lateral forces (e.g., lift or side force). To explicitly account for bounded control inputs, we augment the attacker dynamics with a smooth symmetric input-saturation model [kumar2025provably], a˙A=[1−(aAamax)n]aAc−p1aA, a_A= [1- ( a_Aa_ )^n ]a_A^c-p_1a_A, (2) where n=2n=2, p1∈ℝ>0p_1 _>0 denote constants, and aAca_A^c denotes the commanded lateral acceleration, which is the pseudo control input for the augmented system incorporating the above saturation model. Remark 1. From (2), it follows that when |aA|→amax|a_A|→ a_ , a˙A→−p1aA, a_A→-p_1a_A, and when |aA|→−amax|a_A|→-a_ , a˙A→p1aA, a_A→ p_1a_A, which implies that aAa_A will decrease if aA→amaxa_A→ a_ and aAa_A will increase if aA→−amaxa_A→-a_ . Therefore, the above saturation model ensures that aAa_A remains bounded as |aA|<amax|a_A|<a_ . Thus, we augment the saturation model in (2) with the kinematics (6)-(7) and will design aAca_A^c, which will automatically ensure that aAa_A remains within the permissible limits. To facilitate guidance design with only relative information, we transform the given motion model into relative polar coordinates. This transformation helps us to reduce the dimensionality of the problem and the complexity of the control, while offering intuitive geometric information on the attacker’s motion relative to the target and the defenders. Based on the inertial positions, the relative distance rAj∈ℝ≥0r_Aj _≥ 0 and the line-of-sight (LOS) angle θAj∈[0,2π) _Aj∈[0,2π) between the attacker and the jjth agent (defenders or target) are defined as, rAj=(xj−xA)2+(yj−YA)2,θAj=tan−1(yj−yAxj−xA), r_Aj= (x_j-x_A )^2+ (y_j-Y_A )^2,~ _Aj= ^-1 ( y_j-y_Ax_j-x_A ), (3) where the subscript j∈∪Tj ∪\T\ and the LOS is measured from the attacker to the jjth vehicle. Additionally, we define the attacker’s lead angle as the angle subtended by the attacker’s velocity to the respective LOS to defenders or target, and is given by, σAj=γA−θAj,∀j∈∪T, _Aj= _A- _Aj,~∀\;j ∪\T\, (4) such that σAj∈(−π,π] _Aj∈(-π,π]. Similarly, we define the defender’s lead angle with respect to the attacker as, σjA=γj−θAj,∀j∈, _jA= _j- _Aj,~∀ j , (5) representing the angle subtended by the defender’s velocity vector with respect to the LOS angle from the attacker to the defender. Based on the above-defined relative variables, we can express the relative motion kinematics between the attacker and the j th agent as, r˙Aj r_Aj =vjcosσjA−vAcosσAj =v_j _jA-v_A _Aj (6) rAjθ˙Aj r_Aj θ_Aj =vjsinσjA−vAsinσAj,∀j∈∪T, =v_j _jA-v_A _Aj,\;∀\;j ∪\T\, (7) using (1), (3), (4) and (5). The relative formulation simplifies the representation of the attacker’s motion and plays a crucial role in characterizing threat regions posed by the defenders. 2.2 Defender-induced Engagement Zones (EZs) In this work, each defender is modeled as a mobile platform, such as an aircraft equipped with interception capabilities (e.g., turret-mounted systems or missiles). The instantaneous position of the defender is treated as the origin from which this capability can be deployed. The objective is to design a guidance strategy that enables the attacker to remain safe from defenders by identifying and avoiding regions of the state space where interception becomes unavoidable under the current control policy. These regions are referred to as EZs. Definition 1 (Engagement Zone (EZ)). The EZ of a defender is defined as the subset of the attacker’s state space from which the defender’s engagement capability guarantees interception, assuming the attacker continues with its current heading and control strategy. Remark 2. Therefore, EZ characterizes the region in the attacker’s configuration space where it is at risk of being intercepted by the defenders without altering its trajectory. In the relative polar coordinate frame centered at the defender’s point of origin, the engagement boundary represents the outermost surface of the EZ, beyond which the attacker remains safe but crossing which guarantees interception if it maintains its current trajectory. For the fast defenders DiD_i, with speed ratio μi=vAvDi∈(0,1) _i= v_Av_D_i∈(0,1), the boundary of its EZ is analytically characterized as ρi(σAi)=μiRi[cosσAi+cos2σAi−1+(Ri+ci)2μi2Ri2],∀i∈, _i( _Ai)= _iR_i [ _Ai+ ^2 _Ai-1+ (R_i+c_i)^2 _i^2R_i^2 ],\;∀\;i , (8) where ρi _i denotes the critical radial distance from a defender’s point of origin, RiR_i denotes the maximum engagement range, and cic_i denotes the capture radius. (a) Safe region with EZ considerations. (b) Comparison of EZ for different Attacker headings. Figure 2: Illustration of EZ for single defender ([xD,yD]⊤=[0 0]⊤[x_D,y_D] =[0\;0] with RD=1R_D=1 m and cD=0.25c_D=0.25m). Figure˜2(a) illustrates the engagement boundary for a single defender when the attacker maintains a constant heading γA=0∘ _A=0 , where it is observed that the EZ shifts left relative to the defender’s maximum engagement radius, which creates a region within the nominal range where the attacker can remain safe. This observation highlights that using the maximum engagement radius as the engagement boundary is overly conservative, as it unnecessarily restricts feasible attacker trajectories and can lead to longer paths and increased interception time. More generally, the position of the engagement zone depends on the lead angle between the attacker and the defender. As the attacker’s strategy changes, the engagement boundary shifts accordingly, and causes the safe region within the maximum engagement radius to move in different directions, as illustrated in Figure˜2(b). Figure 3: Engagement boundary relative to the maximum range. Based on the above properties, we can define the region of state space inside each defender’s maximum engagement range as ℰMR=(rAi,θAi,σAi)∈ℝ≥0×[0,2π)×(−π,π]∣rAi≤Ri+ci,i∈. ^MR= \ (r_Ai, _Ai, _Ai ) _≥ 0×[0,2π)×(-π,π]\, r_Ai≤ R_i+c_i,i \. (9) The expression in (9) implies that remaining outside the set ℰMRE^MR enables the attacker to conservatively maintain safety by remaining outside the maximum engagement radius of all the defenders. In contrast, based on Definition˜1, the EZ of a defender DiD_i with respect to the attacker is defined as ℰ:=(rAi,θAi,σAi)∈ℝ≥0×[0,2π)×(−π,π]|rAi≤ρi(σADi),i∈. := \ (r_Ai, _Ai, _Ai ) _≥ 0×[0,2π)×(-π,π]\, |\,r_Ai≤ _i( _AD_i),i \. (10) Crossing this EZ boundary places the attacker within the defender’s guaranteed capture region. Therefore, the engagement boundary accounts for relative engagement geometry, including velocity ratio and maneuvering capabilities, providing an accurate characterization of the defender’s capture region. Additionally, employing EZ-based capture region allows the attacker to exploit maneuvering regions that would otherwise be deemed unsafe under conservative formulations. To better clarify the different regions of state-space, Figure˜3 illustrates different regions around the defender for the current relative side bearing angle of the attacker (according to its current strategy). The dotted black circle of radius Ri+ciR_i+c_i represents the maximum defender range that represents the conservative stand-off safety constraint. The purple colored circle represents the EZ boundary, inside which the attacker’s capture is guaranteed. It is important to note that the sets ℰE and ℰMRE^MR generally overlap but do not coincide. While ℰMRE^MR remains fixed with respect to the defender, the set ℰE is subject to change as the attacker maneuvers around the defender. 2.3 Design of the Control Objectives The objective of this paper is to design a nonlinear guidance law that enables the attacker to intercept a stationary target while remaining safe from threats posed by multiple moving defenders and respecting bounds on the attacker’s lateral acceleration. Achieving this objective requires the attacker to satisfy three coupled requirements. First, the guidance law must ensure target interception by asymptotically reducing the relative distance between the attacker and the target to zero, i.e., limt→∞rAT(t)=0. _t→∞r_AT(t)=0. (11) Second, the attacker must guarantee EZ avoidance by ensuring that its trajectory remains outside the engagement zone of every defender at all times. Formally, this requires (rAi,θAi,σAi)∉ℰi,∀t≥0 (r_Ai, _Ai, _Ai) _i,~∀~t≥ 0 (12) which is equivalently expressed as maintaining rAi>ρir_Ai> _i for each defender. Additionally, we design the attacker’s strategy to guarantee conservative safety by ensuring the attacker remains outside the defender’s maximum engagement range. Such a design forms our baseline approach for comparison and is formally given as (rAi,θAi,σAi)∉ℰMR,∀t≥0 (r_Ai, _Ai, _A_i) ^MR,~∀ t≥ 0 (13) that will enable the attacker to maintain rAi>Ri+ci,∀i∈r_Ai>R_i+c_i,\;∀\;i . Third, the guidance strategy must satisfy actuator constraints by explicitly enforcing bounds on the attacker’s lateral acceleration during design. This requirement is expressed as |aA(t)|≤aAmax,∀t≥0, |a_A(t) |≤ a_A ,~∀ t≥ 0, (14) where aAmax>0a_A >0 denotes the prescribed symmetric bound on the attacker’s lateral acceleration. 3 Engagement-Zone-Aware Input-Constrained Intercept Guidance Design In this section, we develop the nonlinear guidance law for the attacker to intercept the target while preventing neutralization from the defender-induced EZs, while also accounting for physical limits on the attacker’s lateral acceleration. We first formulate the safety conditions that ensure the attacker remains outside the regions reachable by the defenders’ maximum engagement range, by modeling unsafe regions as time-varying EZ boundaries rather than fixed standoff radii. Using these safety conditions, we construct an aggregate safety measure that combines the effects of all defender-induced EZs and includes a tunable parameter that controls how strongly multiple EZs contribute to the overall safety measure. Finally, we design a smooth switching guidance law for the attacker in the presence of multiple defenders that guarantees both the target interception and avoidance of defender EZs under the attacker’s input constraints. To incorporate the defender-induced EZs in the control design, we define a safety function for the attacker with respect to each EZ as bi=rADi−ρi,i∈, b_i=r_AD_i- _i,\;i , (15) which depends on the attacker’s position and velocity, yielding a characterization of the safe state-space based on the attacker’s current strategy (heading angle). Note that bi>0b_i>0 represents the scenarios when the attacker is outside the ith defender’s EZ, that is, rADi>ρir_AD_i> _i. On the other hand, bi≤0b_i≤ 0 indicates scenarios when the attacker is present inside the ith defender’s EZ, implying that interception by the defender’s deployed capability is guaranteed. Therefore, maintaining safety requires bi>0b_i>0 for all defender-induced EZs. Accordingly, the safe set for the attacker can be defined as ≔(xA,yA,γA)∈ℝ2×[0,2π)|bi>0∀i∈. \\,(x_A,y_A, _A) ^2×[0,2π)\; |\;b_i>0\;∀\;i \, \. (16) To ensure the safety of the attacker (forward invariance of set C), it is necessary to characterize how each safety function evolves along the system trajectories. Therefore, differentiating bib_i with respect to time and using the relative kinematics model, we obtain the dynamics of the safety function as b˙i b_i =vicosσiA−vAcosσAi+∇ρivisinσiArAi−∇ρivAsinσAirAi−∇ρiaAvA, =v_i _iA-v_A _Ai+∇ _i v_i _iAr_Ai-∇ _i v_A _Air_Ai-∇ _i a_Av_A, (17) where ∇ρi∇ _i denotes the gradient of engagement boundary of the iith defender, computed using (8), as ∇ρi=−μiRisinσADi[1+cosσADicos2σADi−1+(Ri+ci)2μi2Ri2]. ∇ _i=- _iR_i _AD_i [1+ _AD_i ^2 _AD_i-1+ (R_i+c_i)^2 _i^2R_i^2 ]. (18) From the expression of b˙i b_i, it can be observed that aAa_A has relative degree one with respect to the safety constraint bib_i. To account for multiple EZs, we aggregate the safety function for all the EZs using the log-sum-exp (soft-minimum) operator, h=−βlog(∑i∈e−bi/β), h=-β ( _i e^-b_i/β ), (19) where β∈ℝ>0β _>0 is a user-defined constant that determines how closely h approximates the minimum values of individual safety functions. Remark 3. The safety aggregation function in (19) satisfies mini∈bi−βlogn≤h≤mini∈bi, _i b_i-β n≤ h≤ _i b_i, (20) where n denotes the number of defenders. The upper bound implies that if h>0h>0, then mini∈bi>0 _i b_i>0, which ensures bi>0b_i>0 for all EZs (the attacker remains outside every defender’s EZ). If all bi>0b_i>0, then h is guaranteed to be positive if, mini∈bi>βlnn, _i b_i>β n, which provides a design condition on the smoothing parameter β, obtained from the lower bound of h in (20). Particularly, choosing β sufficiently small makes h a close approximation of minibi _ib_i (or closest engagement boundary to the attacker), thereby tightening the equivalence between the condition h>0h>0 and the requirement bi>0∀i∈b_i>0~∀~i . On the other hand, selecting larger values of β allows the aggregation to account for the combined effect of multiple EZs, rather than focusing solely on the nearest one. We can now define the safe set associated with the aggregated safety function as h≔(xA,yA,γA)∈ℝ2×[0,2π)|h>0. _h \(x_A,y_A, _A) ^2×[0,2π)\; |h>0 \. (21) When the smoothing parameter β→0β→ 0, h≈C_h closely approximates the point-wise minimum of the individual margins. However, when β is finite, the aggregation provides an inner approximation of the true safe set, that is, h⊂C_h . Figure 4: Variation of the safety function boundary (h=0)(h=0) for different choices of the parameter β. Figure˜4 compares the boundary defined by h=0h=0 for two defenders under different values of the parameter β for a fixed attacker’s heading angle, where it can be observed that for small values of β, the aggregated safety function closely approximates the pointwise minimum of the individual safety functions. As a result, the overall unsafe region is essentially formed by the simple union of the individual EZs, producing a sharp concave notch between the two EZs. In practice, such a concave region may cause the attacker to enter unsafe regions, as it may not possess sufficient control authority to avoid it. In contrast, larger values of β yield a smoother aggregation that results in a safety boundary that blends the influence of both EZs and eliminates the concave notch to produce a more regular and maneuverable safety region. Additionally, since h aggregates the individual safety margins through a smooth log-sum-exp map, its time derivative is a weighted combination of the individual safety functions’ rates, given as h˙ h =∑i∈e−bi/β∑i∈e−bi/βb˙i=∑i∈wib˙i = _i e^-b_i/β _i e^-b_i/β b_i= _i w_i b_i =∑i∈wi(vicosσiA+vi∇ρirAisinσiA−vAcosσAi−vA∇ρirAisinσAi)⏟fh−∑i∈wi∇ρi⏟ghaAvA, = _i w_i (v_i _iA+ v_i∇ _ir_Ai _iA-v_A _Ai- v_A∇ _ir_Ai _Ai )_f_h- _i w_i∇ _i_g_h a_Av_A, (22) obtained by differentiating (19) with respect to time, where ∑i∈wi=1 _i w_i=1 with wi≥0w_i≥ 0. It can be observed from the above equation that aAa_A also has relative degree one with respect to the aggregated safety function h. In this work, we explicitly account for the smooth lateral acceleration saturation model (2), making the commanded acceleration aACa_A^C the control input to be designed. Consequently, an ideal design enforcing h>0h>0 would require regulating h¨ h, which depends on the attacker’s dynamics as well as on the defender’s (typically unknown) maneuvering strategy. This could be verified by taking the derivative of h˙ h as in (22) with respect to time, where both aACa_A^C and ai,i∈a_i,\;i explicitly appear, confirming that h has relative degree two with respect to aACa_A^C. To circumvent these issues and retain implementability under input constraints, we introduce a tightening parameter Δ>0 >0 and require the attacker to maintain h≥Δh≥ instead of h>0h>0. This margin ensures that the attacker remains sufficiently far from every defender’s EZ, thereby preserving enough control authority to maneuver away even under bounded control inputs. To this end, the resulting tightened safe set is defined as Δ≔(xA,yA,γA)∈ℝ2×[0,2π)|h>Δ,Δ>0. _ \(x_A,y_A, _A) ^2×[0,2π)\; |h> ,\; >0 \. (23) which, by construction, satisfies Δ⊂h⊂ℰ.C_ _h ⊂E. To enable only the minimum necessary tightening of the safety constraint, we propose a time-varying parameter, Δ(t)≔max0,1p1[|gh(t)|amaxvA−fh(t)], (t) \0, 1p_1 [|g_h(t)| a_ v_A-f_h(t) ] \, (24) based on the worst-case evolution of safety boundaries under all admissible inputs. From (22), the worst-case instantaneous rate of decrease of h over all admissible accelerations is given by, h˙min(t) h_ (t) =min|aA|≤amaxfh(t)−gh(t)aAvA=fh(t)−|gh(t)|amaxvA, = _|a_A|≤ a_ \f_h(t)-g_h(t) a_Av_A \=f_h(t)-|g_h(t)|\, a_ v_A, (25) since for gh(t)>0g_h(t)>0 and gh(t)<0g_h(t)<0 the choices aA=amaxa_A=a_ and aA=−amaxa_A=-a_ , respectively, yield the largest negative contribution to h˙ h to produce the maximum possible decrease in the safety measure h. Additionally, from (2), a local approximation of the actuator response time under worst-case remaining control authority can be obtained as τresp=1p1, _resp= 1p_1, (26) since a˙A≈aAC−p1aA a_A≈ a_A^C-p_1a_A near saturation boundaries. This implies that p1p_1 represents the actuator’s effective response speed and τresp _resp represents the characteristic time required for the actual acceleration to track the commanded input aACa_A^C. Lemma 1 (Safety Tightening Buffer). Consider the dynamics of the safety constraint (22) and the designed tightening parameter as in (24). Then, for any h(t0)>Δ(t0),∀t0≥0h(t_0)> (t_0),∀ t_0≥ 0, the safety constraint remains non-negative over the response window [t0,t0+τresp][t_0,t_0+ _resp] for all admissible control inputs, that is, h(t)>0,∀t∈[t0,t0+τresp]. h(t)>0,\;∀ t∈[t_0,t_0+ _resp]. (27) Proof. From (25), it is evident that h˙(t)≥h˙min h(t)≥ h_ , which implies that the instantaneous decrease in h is lower bounded by worst case decrement h˙min h_ . On integrating the above inequality, we obtain h(t)≥h(t0)+∫t0th˙min(s)s,t∈[t0,t0+τresp]. h(t)≥ h(t_0)+ _t_0^t h_ (s)ds,~~t∈[t_0,t_0+ _resp]. (28) Since h˙min(s)≥h˙min(t0) h_ (s)≥ h_ (t_0) for all s∈[t0,t0+τresp]s∈[t_0,t_0+ _resp], we can simplify the above expression to obtain a conservative linear extrapolation safety function h(t)≥h(t0)+(t−t0)h˙min(t0),t∈[t0,t0+τresp], h(t)\;≥\;h(t_0)+(t-t_0)\, h_ (t_0),~~t∈[t_0,t_0+ _resp], (29) over a short interval of length τresp _resp. If h˙min(t0)≥0 h_ (t_0)≥ 0, then h(t)≥h(t0)≥0h(t)≥ h(t_0)≥ 0 on [t0,t0+τresp][t_0,t_0+ _resp] which implies that h(t)h(t) remains non-negative over the finite response window. However, when h˙min(t0)≤0 h_ (t_0)≤ 0, we have h(t0+τresp)≥h(t0)+τresph˙min(t0) h(t_0+ _resp)≥ h(t_0)+ _resp h_ (t_0) (30) using (29). The above expression can be rewritten using h(t0)>Δ(t0)h(t_0)> (t_0) as h(t)≥Δ(t0)+τresph˙min(t0), h(t)≥ (t_0)+ _resp h_ (t_0), (31) which provides the condition on the Δ(t) (t) as proposed in (24) to ensure h(t)>0h(t)>0. This concludes the proof. ∎ Figure 5: Variation of the safety function boundary with tightening parameter Δ . Figure˜5 compares the engagement boundary under different tightening strategies of the aggregate safety function with two defenders at a constant attacker’s heading (γA=0∘ _A=0 ). The red solid line represents the nominal engagement boundary corresponding to zero tightening corresponding to Δ(t)=0 (t)=0, while the green dotted line represents the engagement boundary under a constant tightening margin corresponding to Δ(t)=0.1 (t)=0.1 that uniformly enlarges the unsafe region in all directions relative to the nominal case. In comparison, the proposed state-dependent tightening parameter expands the nominal unsafe region non-uniformly as depicted by the blue dotted boundary. Specifically, the unsafe set is enlarged on the left side of the nominal engagement boundary, while no expansion occurs on the right side. This asymmetry is consistent with the attacker’s heading γA=0∘ _A=0 since when approaching from the left, the nominal engagement boundary lies on a collision trajectory that necessitates tightening. However, the same heading cannot drive the attacker into the EZ for positions to the right of the nominal boundary and therefore does not require any expansion of the engagement boundary. Remark 4. Since the proposed tightening function Δ(t) (t) in (24) utilizes smooth functions fhf_h and ghg_h that are dependent on the relative kinematics and vehicle states, the time derivative of the tightening function is bounded, that is, |Δ˙(t)|<LΔ| (t)|<L_ , for some finite constant LΔL_ >0. Up to this point, the safety constraints have been characterized, and a tightening mechanism has been introduced to enlarge the effective unsafe set, ensuring that worst-case system behavior cannot drive the attacker into the actual EZs. In the considered problem, the attacker must simultaneously pursue target interception while avoiding safety violations, which naturally introduces competing objectives. To address this, we develop a switching condition and a corresponding guidance law that allow the attacker to transition between target-interception and EZ-avoidance modes. The proposed lateral acceleration component that steers the attacker away from all defender-induced engagement zones is given by aAb=vAKs(h−Δ)−vA∑i∈wi(vicosσiA+vi∇ρirAisinσiA−vAcosσAi−vA∇ρirAisinσAi)∑i∈wi∇ρi, a_A^b= v_AK_s (h- )-v_A _i w_i (v_i _iA+ v_i∇ _ir_Ai _iA-v_A _Ai- v_A∇ _ir_Ai _Ai ) _i w_i∇ _i, (32) where KsK_s denotes the controller gain to be designed. This component is obtained by imposing h˙=−Ks(h−Δ(t)) h=-K_s (h- (t) ) that guarantees forward invariance of the tightened safe set ΔC_ , thus ensuring that the attacker remains outside all defender-induced EZs while the safety margin decays in a controlled manner. For target interception, we propose the attacker’s lateral acceleration component as aAT=−KIvAσAT−vA2sinσATrAT, a_A^T=-K_Iv_A _AT- v_A^2 _ATr_AT, (33) where KIK_I is the controller gain for interception to be designed. The above component of the lateral acceleration is obtained by ensuring σ˙AT=−K1σAT σ_AT=-K_1 _AT, which aligns the attacker’s velocity along the attacker-to-target LOS in order to steer the attacker towards the target. This results in pure pursuit behavior, which is sufficient to guarantee interception of a stationary target. To determine when the attacker may violate the safety constraint, we define the boundary based on the aggregate safety function rate as ψ(aA)=fh+ghaAvA+αh(h−Δ)=0, ψ(a_A)=f_h+g_h a_Av_A+ _h(h- )=0, (34) where αh(⋅) _h(·) is an extended class-K function444An extended class-K function is a continuous and strictly increasing function ϕ:(−ℓ1,ℓ2)→ℝφ:(- _1, _2) satisfying ϕ(0)=0φ(0)=0, where ℓ1,ℓ2>0 _1, _2>0. Unlike a standard class-K function, whose domain is [0,∞)[0,∞), an extended class-K function is defined on an interval containing the origin and therefore permits negative arguments.. The first two terms in (34) correspond to h˙(aA) h(a_A), which represent how aAa_A influences the instantaneous rate of change of the safety function. The last term is always a positive quantity that acts as a corrective barrier, preventing the safety function from decreasing too rapidly. Therefore, the ψ(aA)=0ψ(a_A)=0 represents the boundary at which the evolution of the safety function exactly balances the barrier correction term. Consequently, ψ(aA)>0ψ(a_A)>0 indicates that the attacker’s applied lateral acceleration satisfies the safety constraint, whereas ψ(aA)≤0ψ(a_A)≤ 0 indicates that the applied control input would lead to violation of the safe set. In this work, we select αh=Ks(h−Δ) _h=K_s (h- ), consistent with the safety feedback term in (32), so that purely applying this term ensures that the tightened safety condition is never violated. To handle the trade-off between safety and target-interception, we blend aAba_A^b and aATa_A^T via a switching function/convex combination of the form aAd=α(ψ(aAT))aAb+(1−α(ψ(aAT)))aAT, a_A^d=α (ψ (a_A^T ) )a_A^b+ (1-α (ψ (a_A^T ) ) )a_A^T, (35) where α:ℝ→[0,1]α:R→[0,1] is a continuous, locally Lipschitz, and monotonically decreasing switching function. Thus there exists ε>0 >0 such that α(ψ(aAT))=1,ifψ(aAT)≤0,0,ifψ(aAT)≥ε. α (ψ (a_A^T ) )= cases1,&if\;ψ (a_A^T )≤ 0,\\ 0,&if\;ψ (a_A^T )≥ cases. (36) For brevity, we denote ψ≔ψ(aAT)ψ ψ (a_A^T ) and α≔α(ψ(aAT))α α (ψ (a_A^T ) ), representing ψ evaluated at aATa_A^T and α evaluated at ψ, respectively, unless otherwise stated. Therefore, based on the switching strategy in (36), the attacker’s state-space can be divided into three regions, as presented in Table˜1. Region Mode Condition on α Guidance Law Interpretation I Pure target interception α=0α=0 aAd=aATa_A^d=a_A^T The attacker is sufficiently far from all engagement zones; the guidance law focuses entirely on target interception. I Pure EZ avoidance α=1α=1 aAd=aAba_A^d=a_A^b The attacker is near an engagement boundary; the safety component is fully activated to prevent entry into the engagement zone. I Blended mode 0<α<10<α<1 aAd=(1−α)aAT+αaAba_A^d=(1-α)a_A^T+α a_A^b Both interception and safety terms contribute to the commanded acceleration. This region represents the transition between interception and safety dominance, where α varies continuously due to its locally Lipschitz and nonincreasing properties. Table 1: Operating regions of the proposed guidance law. Assumption 1. The time derivative of α is uniformly bounded, that is, there exists Lα>0L_α>0 such that |α˙|<Lα∀t≥0| α|<L_α~∀~t≥ 0, ensuring smooth transition between various guidance modes. Lemma 2. The switching condition in (36) defines the boundary ψ(aAT)=0ψ(a_A^T)=0, which identifies the region beyond which applying only the target-interception lateral acceleration in (33) may compromise safety. This condition, therefore, characterizes the threshold beyond which the desired lateral acceleration aAda_A^d can potentially violate the tightened safety requirement h(t)>Δ(t)h(t)> (t). Proof. Using (22), we obtain the dynamics of the aggregated safety function at aA=aTa_A=a_T as h˙(aT)=fh+ghaTvA. h(a_T)=f_h+g_h a_Tv_A. (37) To guarantee that h˙(aT) h(a_T) above does not violate the tightened safety condition, one must ensure the condition, h˙(aT)+αh(h−Δ)=ψ(aAT)=fh+ghaTvA+αh(h−Δ)≥0, h(a_T)+ _h(h- )=ψ(a_A^T)=f_h+g_h a_Tv_A+ _h(h- )≥ 0, (38) which on comparison with (34) provides the switching boundary ψ(aT)=0ψ(a_T)=0 as presented in (36). Moreover, it is important to note that aAba_A^b satisfies ψ(aAb)=0ψ(a_A^b)=0 by construction, obtained by ensuring h˙=−Ks(h−Δ(t)) h=-K_s (h- (t) ). Since ψ is affine in aAa_A, the proposed blended control in (35) will result in ψ(aAd)=(1−α)ψ(aT),∀α∈[0,1]. ψ(a_A^d)= (1-α )ψ(a_T),\;∀\;α∈[0,1]. (39) Using the above expression, we can analyze the safety condition in the three regions of the state-space. In Region I, when ψ(aAT)>ϵψ(a_A^T)>ε, we have α=0α=0 and therefore ψ(aAd)=ψ(aAT)ψ(a_A^d)=ψ(a_A^T). Since ψ(aAT)≥0ψ(a_A^T)≥ 0, it follows that ψ(aAd)≥0ψ(a_A^d)≥ 0, ensuring safety. In Region I, the safety component (32) is fully active. When ψ(aAT)≤0ψ(a_A^T)≤ 0 and α=1α=1, we obtain ψ(aAd)=0ψ(a_A^d)=0. In Region I, when 0<ψ(aAT)<ϵ0<ψ(a_A^T)<ε, we have 0<α<10<α<1. Using (39), it follows that ψ(aAd)>0ψ(a_A^d)>0 since ψ(aAT)>0ψ(a_A^T)>0. Therefore, ensuring ψ(aAT)≥0ψ(a_A^T)≥ 0 is sufficient to guarantee safety ψ(aAd)≥0ψ(a_A^d)≥ 0 across all three regions. Under this condition, ψ(aAT)≥0ψ(a_A^T)≥ 0 implies that the aggregate safety function has a nonnegative rate of change, so the safety margin h−Δh- is nondecreasing and the constraint h>Δh> is preserved. On the other hand, when ψ(aAT)<0ψ(a_A^T)<0, the aggregate safety function decreases, which may drive h to Δ in finite time and violate the safety condition h(t)>Δh(t)> . This concludes the proof. ∎ To account for the lateral acceleration dynamics and the constraints in the permissible limits, we define the tracking error between the actual and the desired lateral acceleration as, z=aA−aAd, z=a_A-a_A^d, (40) representing the offset between the actual and the desired values while representing more realistic dynamics. Driving this tracking error to zero, that is, limt→∞z→0 _t→∞z→ 0, ensures that the attacker accurately follows the desired guidance strategy in (35). To ensure this, we design the commanded lateral acceleration for the attacker as aAc= a_A^c= p1aA+a˙Ad+(α−1)σATvA+α(h−Δ)fhvA−Kaz1−(aAamax)n, p_1a_A+ a_A^d+(α-1) _ATv_A+α (h- ) f_hv_A-K_az1- ( a_Aa_ )^n, (41) where Ka∈ℝ>0K_a _>0 is the controller gain. The first two terms in the numerator of aAca_A^c compensate for the lateral acceleration dynamics and the time variation in the desired lateral acceleration. The third and fourth terms capture the contributions from the interception and safety guidance objectives blended via the switching function and represent the backstepping terms from the recursion. The last term in the numerator aAca_A^c represents the corrective input that drives the acceleration tracking error to zero. Theorem 1. Consider the target–attacker–defender relative kinematics (6)–(7) with the input saturation model (2). Suppose the attacker’s commanded lateral acceleration is given by (41), with the resulting actual lateral acceleration governed by (35). Then the attacker intercepts the target while remaining outside the defenders’ engagement boundaries and respecting the actuator bounds, provided the controller gains satisfy KI>supα∈(0,1)2vA+ϵσ+Lα2(Ri+Ci)(1−α)2+w1,Ks>supα∈(0,1)ϵh+ϵΔ+Lα2α2+w1, K_I> _α∈(0,1) 2v_A+ _σ+L_α2 (R_i+C_i )(1-α)^2+w_1,\;K_s> _α∈(0,1) _h+ _ +L_α2α^2+w_1, (42) where ϵσ>0,ϵh>0,ϵΔ>0 _σ>0, _h>0, _ >0 and w1>0w_1>0 are constants. Proof. Consider the candidate for the Lyapunov function V1=12(1−α)σAT2+12α(h−Δ(t))2. V_1= 12 (1-α ) _AT^2+ 12α (h- (t ) )^2. (43) Differentiating V1V_1 with respect to time and using (17) and (22), we obtain, V˙1= V_1= (1−α)σATσ˙AT+α(h−Δ)(h˙−Δ˙(t))+α˙2((h−Δ(t))2−σAT2) (1-α) _AT σ_AT+α (h- ) ( h- (t) )+ α2 ( (h- (t) )^2- _AT^2 ) = = (1−α)σAT(aAdvA+vArATsinσAT)+α(h−Δ)(fh+ghaAdvA)+((1−α)σATvA+α(h−Δ(t))fhvA)z (1-α ) _AT ( a_A^dv_A+ v_Ar_AT _AT )+α (h- ) (f_h+g_h a_A^dv_A )+ ((1-α) _ATv_A+α (h- (t) ) f_hv_A )z −α(h−Δ)Δ˙(t)+α˙2((h−Δ(t))2−σAT2) -α (h- ) (t)+ α2 ( (h- (t) )^2- _AT^2 ) (44) using aA=z+aAda_A=z+a_A^d from (40). On substituting the desired lateral acceleration (35) in the above equation, we obtain V˙1= V_1= −(1−α)2KIσAT2−α2Ks(h−Δ(t))2+((1−α)σATvA+α(h−Δ(t))fhvA)z -(1-α)^2K_I _AT^2-α^2K_s (h- (t) )^2+ ((1-α) _ATv_A+α (h- (t) ) f_hv_A )z +α(1−α)[σAT(aAb+vArATsinσAT)+(h−Δ)(fh+ghvAaAT)]−α(h−Δ)Δ˙(t) +α(1-α) [ _AT (a_A^b+ v_Ar_AT _AT )+ (h- ) (f_h+ g_hv_Aa_A^T ) ]-α (h- ) (t) +α˙2((h−Δ(t))2−σAT2). + α2 ( (h- (t) )^2- _AT^2 ). (45) To explicitly account for the actuator dynamics introduced by the saturation model in (2), we augment the Lyapunov function with an additional term that captures the acceleration tracking error, V=V1+V2V=V_1+V_2, where V2=z2/2V_2=z^2/2. On differentiating V with respect to time and using (2), (45), we obtain V˙= V= V˙1+V˙2=V1˙+zz˙=V1˙+z(a˙A−a˙Ad) V_1+ V_2= V_1+z z= V_1+z ( a_A- a_A^d ) = = −(1−α)2K1σAT2−α2Ks(h−Δ(t))2+((1−α)σATvA+α(h−Δ(t))fhvA)z -(1-α)^2K_1 _AT^2-α^2K_s (h- (t) )^2+ ((1-α) _ATv_A+α (h- (t) ) f_hv_A )z +α(1−α)[σAT(aAb+vArATsinσAT)+(h−Δ)(fh+ghvAaAT)]−α(h−Δ)Δ˙(t) +α(1-α) [ _AT (a_A^b+ v_Ar_AT _AT )+ (h- ) (f_h+ g_hv_Aa_A^T ) ]-α (h- ) (t) +α˙2((h−Δ(t))2−σAT2)+[[1−(aAamax)n]aAc−p1aA−a˙Ad]z. + α2 ( (h- (t) )^2- _AT^2 )+ [ [1- ( a_Aa_ )^n ]a_A^c-p_1a_A- a_A^d ]z. (46) Choosing the commanded acceleration proposed in (41) renders the derivative of the Lyapunov function candidate as V˙= V= −(1−α)2KIσAT2−α2Ks(h−Δ(t))2−Kaz2+α˙2((h−Δ(t))2−σAT2)−α(h−Δ)Δ˙(t) -(1-α)^2K_I _AT^2-α^2K_s (h- (t) )^2-K_az^2+ α2 ( (h- (t) )^2- _AT^2 )-α (h- ) (t) +α(1−α)[σAT(aAb+vArATsinσAT)+(h−Δ)(fh+ghvAaAT)]. +α(1-α) [ _AT (a_A^b+ v_Ar_AT _AT )+ (h- ) (f_h+ g_hv_Aa_A^T ) ]. (47) We analyze the safety guarantees and stability of the proposed guidance law (41) by partitioning the state-space into three distinct regions according to the switching function in (36). In Region I (pure target interception mode), α=0α=0 and ψ(aAT)≥ϵψ(a_A^T)≥ε, which implies the target interception term aATa_A^T is purely activated in aAda_A^d. Under such a condition α˙=0 α=0, α(1−α)=0α (1-α )=0 and Δ˙=0 =0 renders the Lyapunov derivative as V˙=−KIσAT2−Kaz2<0,∀(σAT,z)∈ℝ2∖(0,0), V=-K_I _AT^2-K_az^2<0,\;∀\;( _AT,z) ^2 (0,0), (48) if K1>0K_1>0 and Ka>0K_a>0. This implies that both σAT _AT and z converge asymptotically to zero. The term σAT→0 _AT→ 0 implies the attacker aligns its heading along the LOS to the target, resulting in r˙AT=−vA<0 r_AT=-v_A<0, and guaranteeing monotonic range reduction similar to pure-pursuit guidance. In addition, z→0z→ 0 results in the attacker perfectly tracking the desired acceleration, that is, aA=aAd=aATa_A=a_A^d=a_A^T. In Region I (pure EZ avoidance mode), ψ(aAT)≤0ψ(a_A^T)≤ 0 and α=1α=1, and only the safety component aAba_A^b is fully active in the desired acceleration aAda_A^d. Since under such conditions α˙=0 α=0 and α(1−α)=0α (1-α )=0, the Lyapunov derivative in (47) simplifies to V˙=−Ks(h−Δ(t))2−Kaz2−(h−Δ)Δ˙(t)≤−Ks2(h−Δ)2−Kaz2+LΔ22Ks V=-K_s (h- (t ) )^2-K_az^2- (h- ) (t)≤- K_s2 (h- )^2-K_az^2+ L_ ^22K_s (49) following Remark˜4. It follows from the above expression that if Ks>0K_s>0 and Ka>0K_a>0, then decrement of V is guaranteed outside the compact set ΩII≔(h−Δ,z)∈ℝ2|Ks2(h−Δ)2+Kaz2≤LΔ22Ks. _I \(h- ,z) ^2 | K_s2 (h- )^2+K_az^2≤ L_ ^22K_s \. Therefore, h−Δh- and z are uniformly ultimately bounded in Region I with the ultimate performance bounds given as |h−Δ|≤LΔKs|h- |≤ L_ K_s and |z|≤LΔ22K2Ka|z|≤ L_ ^22K_2K_a. This results in h→Δ+ϵ1h→ + _1 and z→ϵ2z→ _2, where the residual errors ϵ1 _1 and ϵ2 _2 are bounded by the ultimate performance limits as derived above and can be made arbitrarily small by a suitable choice of the design parameters. This implies that in Region I, the guidance law prioritizes safety and steers the attacker toward a small neighborhood of the tightened safe set. Similarly, the attacker’s lateral acceleration remains within a small neighborhood of the desired acceleration, that is, aA→aAd+ϵ2a_A→ a_A^d+ _2. In Region I (blended mode), 0<ψ(aAT)<ϵ0<ψ(a_A^T)<ε, 0<α<10<α<1, such that a convex combination of aAba_A^b and aATa_A^T is active in aAda_A^d, which on following Remark˜4 and ˜1, simplifies the Lyapunov derivative in (47) to V˙2≤ V_2≤ −[(1−α)2KI−(vArAT+ϵσ2)−Lα2]σAT2−[α2Ks−ϵh+ϵΔ+Lα2](h−Δ(t))2−Kaz2 - [(1-α)^2K_I- ( v_Ar_AT+ _σ2 )- L_α2 ] _AT^2- [α^2K_s- _h+ _ +L_α2 ] (h- (t) )^2-K_az^2 +12ϵσ|aAb|2+12ϵh|ϕ|2+12ϵΔLΔ, + 12 _σ|a_A^b|^2+ 12 _h|φ|^2+ 12 _ L_ , (50) where ϕ=fh+ghvAaATφ=f_h+ g_hv_Aa_A^T. The above expression provides the sufficient condition as presented in (42) on the gains (after substituting rAT≥Ri+cir_AT≥ R_i+c_i, since in Region I, interception cannot occur and therefore rATr_AT is bounded away from zero) to ensure that the first two terms in the above expression are always negative definite, yielding V˙= V= −w1σAT2−w1(h−Δ)2−Kaz2+d¯, -w_1 _AT^2-w_1 (h- )^2-K_az^2+ d, (51) where d¯=12ϵσ|aAb|2+12ϵh|ϕ|2+12ϵΔ|Δ˙| d= 12 _σ|a_A^b|^2+ 12 _h|φ|^2+ 12 _ | | denotes the upper bound on the residual terms. It follows from the above expression that the Lyapunov function candidate V decreases outside the compact set ΩIII≔(σAT,h−Δ,z)∈ℝ3|w1σAT2+w2(h−Δ)2+Kaz2≤d¯, _I \( _AT,h- ,z) ^3 |w_1 _AT^2+w_2 (h- )^2+K_az^2≤ d \, with ultimate performance bounds, |σAT|,|h−Δ|≤d¯w1| _AT|,|h- |≤ dw_1 and |z|≤d¯Ka|z|≤ dK_a. This implies that in Region I, σAT→ϵ3 _AT→ _3, h→Δ+ϵ4h→ + _4 and z→ϵ5z→ _5, where ϵ3,ϵ4 _3, _4 and ϵ5 _5 are positive constants. This results in the attacker maintaining a bounded LOS misalignment σAT↛0 _AT → 0 within a bounded neighborhood of the tightened safety boundary, while the attacker’s lateral acceleration tracks the desired acceleration up to a bounded residual error aA→aAd+ϵ5a_A→ a_A^d+ _5. Combining the analyses across the three regions establishes the desired safety and convergence properties. In Region I, the closed-loop dynamics are asymptotically stable to guarantee target interception. In Regions I and I, the Lyapunov derivative is negative outside compact sets, implying uniform ultimate boundedness of σAT,h−Δ(t) _AT,h- (t) and z. As a consequence, the attacker remains within a bounded neighborhood of the tightened safety boundary while never penetrating the defender-induced EZs, and ensuring that its lateral acceleration tracks the desired values up to a bounded residual error. Moreover, the smooth saturation dynamics in (2) ensure that the actual control input aAa_A remains within the admissible limits for all time. Therefore, under the gain conditions in (42), the proposed guidance law guarantees target interception, practical safety from the defenders, while respecting the constraints on the attacker’s control inputs. This completes the proof. ∎ Remark 5. The ultimate bounds derived in Regions I and I can be made smaller by choosing high values of the gains K1K_1, KSK_S, and KaK_a, improving the uniform ultimate boundedness performance and shrinking the invariant compact sets. Particularly, increasing KsK_s reduces the steady-state deviation of h−Δh- from zero, and larger KaK_a decreases the residual acceleration tracking error z. However, excessively large gains may amplify high-amplitude oscillations, leading to degraded performance. Therefore, the gains must be selected to balance tight ultimate bounds with acceptable transient smoothness and actuator limitations. Remark 6. From Theorem˜1, it is evident that both the actual lateral acceleration aAa_A and the acceleration tracking error z are uniformly ultimately bounded. Since aAd=aA+za_A^d=a_A+z, it follows that the desired lateral acceleration aAda_A^d is also bounded. As a consequence, the desired lateral acceleration remains physically realizable, and the derivative a˙Ad a_A^d associated with the proposed control in (41) remains bounded. This ensures that all internal signals in the backstepping-based command law are well-defined and prevents amplification of high-frequency dynamics in the closed-loop system. Remark 7. It is important to emphasize that both the desired acceleration (35) and the commanded acceleration (41) rely only on relative information and do not require the information of control input of other agents. Compared to prior approaches, the proposed method yields a fully distributed, scalable method for practical multi-agent engagement scenarios, robust to communication-induced anomalies or adversarial information constraints, even when inter-agent communication is limited or unreliable. Furthermore, the independence from adversarial control inputs ensures robustness to changes in defender strategies (as well as to the number of defenders), eliminating the need to retune or restructure the attacker’s guidance law. 4 Maximum Engagement-Range-based Input-Constrained Intercept Guidance Design In this section, we design the guidance law for the attacker that enforces safety through a fixed stand-off distance equal to the defender’s maximum engagement range constraint Ri+ciR_i+c_i while ensuring prescribed control input bounds. Such a design provides a baseline for comparison with the proposed EZ-based safety constraints. In contrast to prior works [doi:10.2514/1.37030, doi:10.2514/1.G003157, 10839025, doi:10.2514/1.G003223, doi:10.2514/6.2026-0121] that employ similar range-based safety constraints but neglect actuator limits, the baseline design explicitly incorporates input bounds to enable a fair comparison. For notational convenience, we adopt the same variables used in the EZ-based formulation and denote them with the superscript (⋅)MR(·)^MR to represent the quantities associated with the maximum engagement-range-based formulation. The goal here is to design the attacker’s guidance strategy to satisfy (13) such that it maintains a position outside the defender’s maximum range. Under such considerations, the conservative safety and the aggregated conservative safety function are given by biMR=rAi−Ri−ci,hMR=−βlog(∑i∈e−btMR/β),∀i∈, b_i^MR=r_Ai-R_i-c_i,\;\;h^MR=-β ( _i e^-b_t^MR/β ),\;∀\;i , (52) where β>0β>0 is a constant. From the above safety measure, biMR≥0b_i^MR≥ 0 represents the scenarios when the attacker is outside the iith defender’s maximum engagement range, that is, rADi>Ri+cir_AD_i>R_i+c_i. In comparison, biMR≤0b_i^MR≤ 0 indicates scenarios when the attacker is inside the iith defender’s maximum engagement range. Additionally, similar to Remark˜3, hMRh^MR aggregates the safety measure from all the defenders using a log-sum-exp operator (soft-min) function, with the parameter β governing how strongly the aggregated function emphasizes the most critical defender. Therefore, we can define the safe set that encompasses the region outside the maximum engagement range of all the defenders as hMR≔(xA,yA,γA)∈ℝ2×[0,2π)|hMR>0. _h^MR \(x_A,y_A, _A) ^2×[0,2π)\; |~h^MR>0 \. (53) Thus, remaining outside the above set, that is, hMR>0h^MR>0, guarantees that biMR>0,∀i∈b_i^MR>0,∀\ i , using inferences from Remark˜3. On differentiating hMRh^MR with respect to time and using (6), we obtain the dynamics of the aggregate conservative safety measure as h˙MR h^MR =∑i∈wiMRr˙Ai=∑i∈wiMR(vicosσiA−vAcosσAi) = _i w_i^MR r_Ai= _i w_i^MR (v_i _iA-v_A _Ai ) (54) where wiMR=e−biMR/β∑i∈e−biMR/βw_i^MR= e^-b_i^MR/β _i e^-b_i^MR/β denotes the normalized soft-min weight associated with each defender. One can observe from (54) that the first derivative of the conservative safety function depends only on the relative velocity between the attacker and the defenders. Since the attacker’s lateral acceleration does not appear explicitly in h˙MR h^MR, we further differentiate h˙MR h^MR with respect to time to obtain h¨MR h^MR =1β((h˙MR)2−∑i∈wiMR(b˙iMR)2)+∑i∈wiMR(−aisinσiA+rAiθ˙Ai2)⏟fhMR+(∑i∈wisinσAi)⏟ghMRaA, = 1β (( h^MR)^2- _i w_i^MR( b_i^MR)^2 )+ _i w_i^MR (-a_i _iA+r_Ai θ_Ai^2 )_f_h^MR+ ( _i w_i _Ai )_g_h^MRa_A, (55) using (6) and (7). The drift and input coupling terms in (55) are shown in underbraces. It is important to observe the above expression that the attacker’s lateral acceleration has a relative degree of two with respect to the conservative safety constraint hMRh^MR. Ensuring forward invariance of the set hMRC_h^MR ensures safety by forcing the attacker to remain outside the maximum engagement range of all defenders. Since hMRh^MR has a relative degree of two, we introduce an auxiliary function to enable the higher-order control barrier function-based design, given as ψ1MR(x)=h˙MR(x)+α1(hMR(x))=h˙MR(x)+K1MRhMR, _1^MR(x)= h^MR(x)+ _1\! (h^MR(x) )= h^MR(x)+K_1^MRh^MR, (56) where α1(⋅) _1(·) is an extended class-K function. In this work, we utilize a linear class-K function of the form α1(hMR)=K1MRhMR _1 (h^MR )=K_1^MRh^MR, where K1MR>0K_1^MR>0 . The auxiliary function (56) incorporates both the conservative safety function and its derivative to enable the enforcement of the safety constraints for relative-degree-two systems. The admissible set corresponding to the auxiliary constraint is defined as 1MR=x∈ℝn∣ψ1MR(x)≥0. _1^MR= \x ^n _1^MR(x)≥ 0 \. (57) It follows that enforcing the forward invariance of the sets 1MRC_1^MR will ensure the forward invariance of the set hMRC_h^MR, thus guaranteeing that the attacker maintains a conservative safety constraint throughout its maneuver. To retain implementability under input constraints, we introduce a tightening parameter ΔMR>0 ^MR>0 and ensure safety by satisfying ψ1MR>ΔMR _1^MR> ^MR instead of ψ1MR>0 _1^MR>0. This tightening contracts the nominal safe set and introduces a safety buffer that preserves forward invariance of the conservative safety constraint despite bounded control authority. This tightening parameter is given as ΔMR(t)≔max0,1p1[|ghMR|amax−fhMR−K1MRh˙MR], ^MR(t) \0, 1p_1 [|g_h^MR|\,a_ -f_h^MR-K_1^MR h^MR ] \, (58) where fh,ghf_h,g_h are defined in (55). As a consequence, we can define the tightened conservative safe set as ΔMR=x∈ℝn∣ψ1MR(x)≥ΔMR. _ ^MR= \x ^n _1^MR(x)≥ ^MR \. (59) Hence, ensuring forward invariance to the set ΔMRC_ ^MR will ensure attacker safety at all times, since, by construction, ΔMR⊂1MR⊂hMR⊂ℰMRC_ ^MR _1^MR _h^MR ^MR. Remark 8. Similar to Lemma˜1, we can show that the tightening parameter (58) is designed to counteract the worst-case decrease of the auxiliary barrier function ψ1MR _1^MR over the actuator response interval. In particular, the term |ghMR|amax|g_h^MR|a_ captures the largest possible adverse contribution of the bounded lateral acceleration to the safety dynamics, whereas the terms fhMRf_h^MR and K1MRh˙MRK_1^MR h^MR arise from the safety function dynamics in (55) and (56). By scaling this worst-case decrease over the actuator response interval 1/p11/p_1, the tightening parameter ΔMR(t) ^MR(t) provides the minimum safety buffer required to maintain feasibility of the safety constraint despite bounded control authority We now introduce a lateral acceleration component for the attacker that enforces safety under the conservative formulation, given by aAbMR=∑i∈wiMR((r˙Ai) 2β+aisinσiA−rAiθ˙Ai2)−(h˙MR)2β−K1MRh˙MR−K2MR(ψ1MR−ΔMR)∑i∈wiMRsinσAi, a_A^b^MR= _i w_i^MR ( ( r_Ai)^\,2β+a_i _iA-r_Ai θ_Ai^2 )- ( h^MR)^2β-K_1^MR h^MR-K_2^MR ( _1^MR- ^MR ) _i w_i^MR _Ai, (60) where K1MR>0K_1^MR>0 and K2MR>0K_2^MR>0 are controller gains. The above lateral acceleration component (60) is obtained by imposing the higher-order control barrier function condition, ψ˙1MR(x)+α2(ψ1MR−ΔMR)≥0, ψ_1^MR (x )+ _2 (ψ_1^MR- ^MR )≥ 0, (61) which ensures that the set 1MRC_1^MR is forward-invariant, allowing the attacker to remain outside the defenders’ maximum range. The target-interception component remains unchanged from the EZ-based safety formulation in Section˜3. Using (33) and (60), the overall desired lateral acceleration is constructed as a convex combination of the target-interception and maximum-range avoidance components, given by aAdMR=αMRaAbMR+(1−α)aAT, a_A^d^MR=α^MRa_A^b^MR+ (1-α )a_A^T, (62) where αMRα^MR denotes a scalar continuous and monotonically decreasing switching function α(ψ)MR=1,ifψMR(aAT)≤0,0,ifψMR(aAT)≥ε. α(ψ)^MR= cases1,&if\;ψ^MR(a_A^T)≤ 0,\\ 0,&if\;ψ^MR(a_A^T)≥ cases. (63) Remark 9. Similar to Lemma˜2, it can be shown that the above switching condition leads to the boundary ψ(aAT)MR=h˙c 2β+∑i∈wi(−r˙Ai 2β−aisinσiA+rAiθ˙Ai2+sinσAi)aAT+K1MRh˙MR+K2MR(ψ1MR−ΔMR)=0, ψ(a_A^T)^MR= h_c^\,2β+ _i w_i (- r_Ai^\,2β-a_i _iA+r_Ai θ_Ai^2+ _Ai )a_A^T+K_1^MR h^MR+K_2^MR ( _1^MR- _MR )=0, (64) such that ensuring ψ(aAT)MR≥0ψ(a_A^T)^MR≥ 0 is equivalent to ensuring safety, that is, ψ(aAd)≥0ψ(a_A^d)≥ 0. This boundary characterizes the influence of the relative attacker-defender motion on the behavior of the conservative safety function. In particular, the first three terms in the above boundary expression denote h˙(aAT)MR h(a_A^T)^MR, while the last two terms are positive constants to ensure the control barrier function condition (61). To account for input constraints using the saturation model in (2), we define the tracking error between the actual and the desired acceleration as zMR=aAMR−aAdMR, z^MR=a_A^MR-a_A^d^MR, (65) which, in a way, represents the mismatch between the inner and outer control loops. Accordingly, the commanded lateral acceleration for the attacker is designed to achieve target interception while ensuring that it remains outside the defenders’ maximum engagement range, and is given by aAcMR=p1aAMR+(a˙Ad)MR+(1−αMR)σATvA+αMRψ1MRghMR−KaMR(zMR)1−(aAMRamax)n, a_A^c^MR= p_1a_A^MR+ ( a_A^d )^MR+ (1-α^MR ) _ATv_A+α^MR _1^MRg_h^MR-K_a^MR (z^MR )1- ( a_A^MRa_ )^n, (66) where KaMR>0K_a^MR>0 is a gain and ΔMR(t) ^MR(t) denotes the time-varying tightening term introduced to compensate for the transient effect of the bounded actuator dynamics. The first two terms in (66) compensate for the actuator dynamics and the time variation of the desired acceleration. The next two terms in (66) arise from the recursive backstepping design corresponding to the interception and conservative safety objectives. The last term in (66) is a robust corrective action that drives the acceleration tracking error to zero. Theorem 2. Consider the target–attacker–defender relative kinematics (6)–(7) with the input saturation model (2). Suppose the attacker’s commanded lateral acceleration is given by (66), with the resulting actual lateral acceleration governed by (62). Then the attacker intercepts the target while remaining outside the defenders’ conservative maximum range boundaries and respecting the actuator bounds, provided the controller gains satisfy KI> K_I> supαMR∈(0,1)2vA+ϵσMR+LαMR2(Ri+ci)(1−αMR)2+w2, _α^MR∈(0,1) 2v_A+ _σ^MR+L_α^MR2 (R_i+c_i )(1-α^MR)^2+w_2, (67) K2MR> K_2^MR> supαMR∈(0,1)ϵhMR+ϵΔMR+LαMR2(αMR)2+w2, _α^MR∈(0,1) _h^MR+ _ ^MR+L_α^MR2 (α^MR )^2+w_2, (68) K1MR>0K_1^MR>0 and Ka>0K_a>0, where ϵσMR>0,ϵhMR>0,ϵΔMR>0 _σ^MR>0, _h^MR>0, _ ^MR>0 and w2>0w_2>0 are constants. Proof. Consider the Lyapunov function candidate associated with the target-interception and conservative-safety objectives, V1MR=12(1−αMR)σAT2+12αMR(ψ1MR−ΔMR)2+12zMR. V_1^MR= 12 (1-α^MR ) _AT^2+ 12α^MR ( _1^MR- ^MR )^2+ 12z^MR. (69) Differentiating V1MRV_1^MR with respect to time and using (2), (55), (56) and the relationship aAMR=zMR+(aAd)MRa_A^MR=z^MR+ (a_A^d )^MR, we obtain the dynamics of the Lyapunov candidate V1MRV_1^MR along the closed-loop trajectories as V˙1MR= V_1^MR= (1−αMR)σATσ˙AT+αMR(ψ1MR−ΔMR)(h¨MR+K1MRh˙MR)−αMR(ψ1MR−ΔMR)Δ˙MR (1-α^MR) _AT σ_AT+α^MR ( _1^MR- ^MR ) ( h^MR+K_1^MR h^MR )-α^MR ( _1^MR- ^MR ) ^MR +α˙MR2((ψ1MR)2−σAT2)+zMRz˙MR + α^MR2 ( ( _1^MR )^2- _AT^2 )+z^MR z^MR = = (1−αMR)σAT(aAdvA+vArATsinσAT)+αMR(ψ1MR−ΔMR)(fhMR+ghMRaAd+K1MRh˙MR) (1-α^MR) _AT ( a_A^dv_A+ v_Ar_AT _AT )+α^MR ( _1^MR- ^MR ) (f_h^MR+g_h^MRa_A^d+K_1^MR h^MR ) −αMR(ψ1MR−ΔMR)Δ˙MR+α˙MR2((ψ1MR)2−σAT2) -α^MR ( _1^MR- ^MR ) ^MR+ α^MR2 ( ( _1^MR )^2- _AT^2 ) +[(1−αMR)σATvA+αMRψ1MRghMR+[1−(aAamax)n](aAc)MR−p1aAMR−(a˙Ad)MR]zMR. + [ (1-α^MR ) _ATv_A+α^MR _1^MRg_h^MR+ [1- ( a_Aa_ )^n ] (a_A^c )^MR-p_1a_A^MR- ( a_A^d )^MR ]z^MR. (70) Now, using the proposed desired lateral acceleration (62) and the proposed commanded lateral acceleration (66), we can simplify the above equation to V˙1MR= V_1^MR= −(1−αMR)2KIσAT2−(αMR)2K2MR(ψ1MR)2−KaMR(zMR)2−αMR(ψ1MR−ΔMR)Δ˙MR - (1-α^MR )^2K_I _AT^2- (α^MR )^2K_2^MR ( _1^MR )^2-K_a^MR (z^MR )^2-α^MR ( _1^MR- ^MR ) ^MR +α(1−α)[σAT(aAb+vArATsinσAT)+ψ1MR(fhMR+ghMRaAT)]+α˙MR2((ψ1MR)2−σAT2). +α(1-α) [ _AT (a_A^b+ v_Ar_AT _AT )+ _1^MR (f_h^MR+g_h^MRa_A^T ) ]+ α^MR2 ( ( _1^MR )^2- _AT^2 ). (71) We now analyze the dynamics of the Lyapunov function candidate in the three regions of the state space, according to the switching condition (63). In Region I (pure target interception mode), αMR=0α^MR=0 and ψMR(aAT)≥ϵψ^MR(a_A^T)≥ε, which implies the target interception term aATa_A^T is purely activated in (aAd)MR (a_A^d )^MR. Under such a condition α˙MR=0 α^MR=0, and αMR(1−αMR)=0α^MR (1-α^MR )=0, which renders V˙1MR=−KIσAT2−KaMR(zMR)2<0,∀(σAT,zMR)∈ℝ2∖(0,0), V_1^MR=-K_I _AT^2-K_a^MR (z^MR )^2<0,\;∀\;( _AT,z^MR) ^2 (0,0), (72) if the controller gains are selected as KI>0K_I>0 and KaMR>0K_a^MR>0. This implies that both σAT _AT and zMRz^MR converge asymptotically to zero. This aligns the attacker’s heading angle along the LOS to the target, yielding r˙AT=−vA<0 r_AT=-v_A<0 and guaranteeing monotonic range. Also, the attacker will perfectly track the desired acceleration, that is, aA=aAdMR=aATa_A=a_A^d^MR=a_A^T, since limt→∞zMR→0 _t→∞z^MR→ 0. In Region I (pure maximum-engagement-range avoidance mode), ψMR(aAT)≤0ψ^MR(a_A^T)≤ 0 and αMR=1α^MR=1, resulting in the safety component (aAb)MR (a_A^b )^MR to be fully active in the desired acceleration (aAd)MR (a_A^d )^MR. Such a condition renders V˙1MR= V_1^MR= −K2MR(ψ1MR−ΔMR)2−KaMR(zMR)2−αMR(ψ1MR−ΔMR)Δ˙MR -K_2^MR ( _1^MR- ^MR )^2-K_a^MR (z^MR )^2-α^MR ( _1^MR- ^MR ) ^MR ≤ ≤ −K2MR2(ψ1MR−ΔMR)2−KaMR(zMR)2+LΔMR2K2MR - K_2^MR2 ( _1^MR- ^MR )^2-K_a^MR (z^MR )^2+ L_ ^MR2K_2^MR (73) since α˙MR=0 α^MR=0 and αMR(1−αMR)=0α^MR (1-α^MR )=0. It follows from the above expression that if K2MR>0K_2^MR>0 and Ka>0K_a>0, then V˙1MR<0 V_1^MR<0 outside the compact set ΩIIMR≔(ψ1MR−ΔMR,zMR)∈ℝ2|K2MR2(ψ1MR−Δ)2+KaMR(zMR)2≤(LΔMR)22K2MR. _I^MR \( _1^MR- ^MR,z^MR) ^2 | K_2^MR2 ( _1^MR- )^2+K_a^MR (z^MR )^2≤ (L_ ^MR )^22K_2^MR \. Therefore, ψ1MR−Δ _1^MR- and zMRz^MR are uniformly ultimately bounded in Region I with the ultimate performance bounds given as |ψ1MR−ΔMR|≤LΔMRK2MR,|zMR|≤(LΔMR)22K2MRKaMR.| _1^MR- ^MR|≤ L_ ^MRK_2^MR,~~|z^MR|≤ (L_ ^MR )^22K_2^MRK_a^MR. This results in ψ1MR→ΔMR+ϵ1MR _1^MR→ ^MR+ _1^MR and z→ϵ2MRz→ _2^MR, where the residual errors ϵ1 _1 and ϵ2 _2 are bounded by the ultimate performance limits as derived above and can be made arbitrarily small. Since ψ1MR=h˙MR+K1MRhMR _1^MR= h^MR+K_1^MRh^MR, we have h˙MR+K1MRhMR→ΔMR+ϵ1 h^MR+K_1^MRh^MR→ ^MR+ _1. In steady state, when h˙MR→0 h^MR→ 0, hMRh^MR converges to a non-negative value, that is, hMR→ΔMR+ϵ1MRK1MR≥0h^MR→ ^MR+ _1^MRK_1^MR≥ 0, ensuring that the safety is maintained asymptotically. Therefore, this implies that in Region I, the guidance law prioritizes safety and steers the attacker toward the boundary of the conservative safe set 1MRC_1^MR. Additionally, zMR→0z^MR→ 0 asymptotically, resulting in the attacker being able to perfectly track the desired lateral acceleration, that is, aA→aAda_A→ a_A^d. In Region I (blended mode), 0<ψMR(aAT)<ϵMR0<ψ^MR(a_A^T)<ε^MR, 0<αMR<10<α^MR<1, such that a convex combination of aAba_A^b and aATa_A^T is active in aAda_A^d, and simplifies (71) to V˙1MR≤ V_1^MR≤ −[(1−α)2KI−14(vArAT+ϵσMR2)−LαMR2]σAT2−[α2K2MR−ϵhMR+ϵΔMR8+LαMR2](ψ1MR−ΔMR)2 - [(1-α)^2K_I- 14 ( v_Ar_AT+ _σ^MR2 )- L_α^MR2 ] _AT^2- [α^2K_2^MR- _h^MR+ _ ^MR8+ L_α^MR2 ] ( _1^MR- ^MR )^2 −KaMR(zMR)2+|(aAb)MR|28ϵσ+|ϕMR|28ϵhMR+LΔMR2ϵΔMR, -K_a^MR (z^MR )^2+ | (a_A^b )^MR |^28 _σ+ |φ^MR |^28 _h^MR+ L_ ^MR2 _ ^MR, (74) where ϕMR=fhMR+ghMRaATφ^MR=f_h^MR+g_h^MRa_A^T. The above expression provides the sufficient condition as presented in (68) on the gains (after substituting rAT≥Ri+cir_AT≥ R_i+c_i, since in Region I, interception cannot occur and therefore rATr_AT is bounded away from zero) to ensure that the first two terms in the above expression are always negative definite, yielding V˙1MR= V_1^MR= −w2σAT2−w2(ψ1MR−ΔMR)2−KaMR(zMR)2+d¯MR -w_2 _AT^2-w_2 ( _1^MR- ^MR )^2-K_a^MR (z^MR )^2+ d^MR (75) where d¯MR=|(aAb)MR|28ϵσ+|ϕ|28ϵhMR+LΔMR2ϵΔMR d^MR= | (a_A^b )^MR |^28 _σ+ |φ|^28 _h^MR+ L_ ^MR2 _ ^MR denotes the upper bound on the residual terms. It follows from the above expression that the V˙1MR V_1^MR decreases outside the compact set ΩIIIMR≔(σAT,ψ1MR,zMR)∈ℝ3|w2σAT2+w2(ψ1MR−ΔMR)2+KaMR(zMR)2≤d¯MR _I^MR \( _AT, _1^MR,z^MR) ^3 |w_2 _AT^2+w_2 ( _1^MR- ^MR )^2+K_a^MR (z^MR )^2≤ d^MR \ with ultimate performance bounds, |σAT|,|ψ1MR−ΔMR|≤d¯MRw2| _AT|, | _1^MR- ^MR |≤ d^MRw_2 and |zMR|≤d¯MRKaMR |z^MR |≤ d^MRK_a^MR. This implies that in Region I, σAT→ϵ3MR _AT→ _3^MR, ψ1MR→ΔMR+ϵ4MR _1^MR→ ^MR+ _4^MR and z→ϵ5MRz→ _5^MR, where ϵ3MR,ϵ4MR _3^MR, _4^MR and ϵ5MR _5^MR are positive constants. Consequently, the attacker maintains a bounded LOS misalignment, σAT↛0 _AT → 0, within a bounded neighborhood of the tightened safety boundary, while its lateral acceleration tracks the desired acceleration up to a bounded residual error, aA→aAdMR+ϵ5a_A→a_A^d^MR+ _5. Therefore, the attacker remains outside the maximum engagement range of all the defenders, preserving safety at all times. When the attacker’s state lies in Region I, it is away from the defender’s threat, and the attacker prioritizes target interception. While in Regions I and I, the attacker prioritizes safety. In addition, the smooth saturation dynamics in (2) ensures that the actual control input aAa_A remains within the admissible limits for all time. Therefore, the proposed guidance law guarantees target interception, practical safety from the defenders, while respecting the constraints on the attacker’s control inputs. This completes the proof. ∎ Remark 10. It is essential to note that in comparison to EZ-based design, the maximum engagement range-based design relies on the knowledge of the defender’s control actions (see (60) and (64)). This dependency introduces a significant information requirement and limits the applicability of range-based safety formulations in scenarios where defender strategies are unknown, uncertain, or dynamically changing. Since the conservative safety function has a relative degree of two with respect to the attacker’s lateral acceleration, the resulting design relies on a higher-order control barrier function formulation, which requires additional modeling information and a more complex controller structure. In contrast, the earlier proposed EZ-based approach leads to a simpler first-order control barrier function design. While both approaches guarantee the safety of the attacker under bounded control inputs, they differ in their operational behavior. In the maximum engagement-range-based formulation, the attacker maintains a conservative distance and never enters the defenders’ engagement range. On the other hand, the EZ-based strategy allows the attacker to penetrate the defenders’ engagement range intelligently while ensuring the attacker cannot be neutralized by remaining outside the EZ. Thus, the maximum engagement-range-based formulation provides a conservative safety baseline, whereas the EZ-based design enables more aggressive yet provably safe interception strategies. 5 Simulation results We now present simulation results demonstrating the efficacy of the proposed EZ-based and maximum engagement-range-based methods across varying numbers of defenders and defense strategies. For all simulation results, the attacker moves at a constant speed vA=1m/sv_A=1\,m/s, and the controller gains for the EZ-based design are selected as KI=0.7K_I=0.7 for target interception, K2=0.9K_2=0.9 for EZ avoidance, and Ka=0.9K_a=0.9. The controller gains for the maximum engagement-range-based design are chosen as K1MR=1.8K_1^MR=1.8, K2MR=1.5K_2^MR=1.5, and KaMR=15K_a^MR=15. Moreover, the safety aggregation parameters are selected as β=0.5β=0.5 and βMR=0.9β^MR=0.9 in the two cases. Each defender moves at a speed ratio of μi=0.7 _i=0.7 relative to the attacker, has engagement range Ri=1.5mR_i=1.5\,m, and a capture radius ri=0.5mr_i=0.5\,m resulting in maximum engagement radius of 2m2m. In the trajectory plots that follow, star-shaped markers denote the initial positions of the agents, while hollow circular markers represent their locations at intermediary times. Additionally, in the following figures, (⋅)EZ (· )^EZ represents variables associated with EZ-based design, while (⋅)MR (· )^MR represents those for maximum engagement-range-based design. To better visualize the agents’ trajectories, we also provide animations for all the following results at https://youtu.be/5DsaCRfdgmc. (a) Attacker’s trajectories. (b) Attacker-to-target distance and bearing angle. (c) Control inputs (EZ formulation). (d) Control inputs (maximum range formulation). (e) Evolution of safety functions. (f) EZ penetration. Figure 6: Target interception by avoiding two stationary defenders. (a) Attacker’s trajectories. (b) Attacker-to-target distance and bearing angle. (c) Control inputs (EZ formulation). (d) Control inputs (maximum range formulation). (e) Evolution of safety functions. (f) EZ penetration. Figure 7: Comparison of attacker performance with three moving defenders. (a) Attacker’s trajectories. (b) Attacker-to-target distance and bearing angle. (c) Control inputs (EZ formulation). (d) Control inputs (maximum range formulation). (e) Evolution of safety functions. (f) EZ penetration. Figure 8: Comparison of attacker performance with six moving defenders. (a) Two stationary defenders. (b) Three moving defenders. (c) Six moving defenders. Figure 9: Comparison of the tightening parameter variation. 5.1 Target Interception avoiding Stationary Defenders In the first set of results (see Figure˜6), we consider two stationary defenders, located at ([xD1,yD1]⊤=[0,0.6]m([x_D_1,y_D_1] =[0,0.6]m, [xD2,yD2]⊤=[0,−0.6]m[x_D_2,y_D_2] =[0,-0.6]m. The attacker starts at ([xA,yA]⊤=[0,−10]m([x_A,y_A] =[0,-10]m with a heading angle of γA=0∘ _A=0 , such that the initial LOS from attacker to the target intersects with the overlapping region between the engagement range of the defenders. The trajectory for both methods is compared in Figure˜6(a), where the dotted circles centered at the respective defender’s position represent the maximum engagement radius of the defender. Both approaches achieve successful target interception. However, the EZ-based approach enables the attacker to enter the defenders’ maximum range, potentially allowing it to take a shorter path. In comparison, maximum engagement-range-based design forces the attacker to remain conservatively outside the defender’s maximum effective range, resulting in a longer path to intercept the target. This observation is verified by comparing the target relative variables, as shown in Figure˜6(b). EZ-based design takes less time for the relative attacker-target range to converge to zero than the maximum engagement-range formulation. In general, the relative range to the target decreases over time and eventually converges to zero, indicating successful interception. The lead angle of the attacker relative to the target, denoted by σAT _AT, also shows convergent behavior, that is, approaching zero nominally but temporarily deviating when the attacker executes avoidance maneuvers near the EZ. Figures˜6(c) and 6(d) presents the attacker’s control input profiles for both methods, illustrating the lateral acceleration converging to the desired lateral acceleration without violating the prescribed bounds. The third and fourth subplots in Figures˜6(c) and 6(d) compare the components of the desired lateral acceleration, demonstrating switching between target-seeking and safety-preserving modes and showing smooth transitions at different time instants depending on the perceived threat from nearby defenders. Figure˜6(e) depicts the profiles of the safety constraint variables for both methods, where the aggregate safety function and the safety function remain strictly positive throughout the engagement, guaranteeing safety for the attacker at all times. However, it is worth mentioning that these variables have different physical interpretations across the two approaches. In the maximum engagement-range-based design, safety corresponds to strictly keeping the attacker outside each defender’s maximum engagement range, whereas EZ-based safety is defined with respect to an EZ, which captures the coupled geometric and dynamic interaction between the attacker and the defenders. Finally, we compare the relative distances between the attacker and the defenders in Figure˜6(f), where the dotted black line represents the defender’s maximum range. The EZ-based design profile is shown in a solid line, while the maximum engagement-range-based design is shown in dotted lines. One can observe that the attacker’s distance falls below the black dotted line at times when the attacker is within a defender’s engagement range. In the maximum engagement range-based design, the relative attacker-defender distance never falls below the defender engagement range, clearly demonstrating the conservatism of such an approach. 5.2 Target Interception avoiding Moving Defenders We now present results for moving defenders (n=3n=3 and n=6n=6), where the defenders adopt an aggressive stance and utilize pure pursuit to intercept the attacker by executing the lateral acceleration aDi=−KIvi(γi−θiA)+vivAsin(γA−θiA)riA−vi2sin(γi−θiA)riA,∀i∈, a_D_i=-K_Iv_i ( _i- _iA )+ v_iv_A ( _A- _iA )r_iA- v_i^2 ( _i- _iA )r_iA,\;∀\;i , (76) where θiA _iA denotes the LOS angle from the iith defender to the attacker. In the results presented in Figure˜7, three defenders are initially positioned at ([xD1,yD1]⊤=[2.5, 2.5]m([x_D_1,y_D_1] =[2.5,\,2.5]m , [xD2,yD2]⊤=[−2, 4.4]m[x_D_2,y_D_2] =[-2,\,4.4]m , and [xD3,yD3]⊤=[−2.9, 2.2]m[x_D_3,y_D_3] =[-2.9,\,2.2]m, respectively. In the results presented in Figure˜8, first three defenders start as the same position as in the n=3n=3 case, while the remaining defenders start at, ([xD4,yD4]⊤=[3,−2]m([x_D_4,y_D_4] =[3,\,-2]m , [xD5,yD5]⊤=[−2.6,−1]m[x_D_5,y_D_5] =[-2.6,\,-1]m , and [xD6,yD6]⊤=[0,−2]m[x_D_6,y_D_6] =[0,\,-2]m, respectively. All defenders are assumed to be homogeneous in their capabilities, similar to the stationary defender case. Figures˜7(a) and 8(a) illustrate the trajectory for the defenders and the attacker for both approaches, where the defenders can be seen to be moving closer to intercept the target following the control law presented in (76). One can observe that, following the EZ-based approach, the attacker takes a shorter path to intercept the target by penetrating the defender’s engagement range, while the maximum engagement-range-based approach takes a longer route to comply with the strict requirement of fully avoiding a defender’s range. The relative variables are compared in Figures˜7(b) and 8(b), which shows the relative range and the bearing angles eventually converging to zero, with the convergence time difference between the methods increasing in the moving case compared to the stationary defenders scenario. However, between 5−12sec5-12sec, the relative variable profiles can be seen temporarily moving away from zero, corresponding to times when the attacker executes an evasive maneuver to avoid an EZ or a maximum engagement range. The safety constraints profiles are depicted in Figures˜7(e) and 8(e). For both methods and both scenarios, the safety functions remain strictly positive, ensuring the attacker’s safety against the defender’s threat. The subplots Figures˜7(c), 7(d), 8(c) and 8(d) compare the different components of the attacker’s lateral acceleration in the moving defender scenario. These profiles illustrate switching between the target-seeking and safety-preserving modes, with the control input dynamically adapting to the defenders’ time-varying positions. Smooth transitions between these modes can be observed at different time instants as the attacker adjusts its maneuvering strategy in response to the evolving threat posed by the moving defenders. The comparison of the attacker-defender distance is presented in Figures˜7(f) and 8(f), which demonstrates that the engagement-range-based method may temporarily lead the attacker into the defenders’ engagement range without being unsafe, while the maximum engagement-range-based approach strictly prevents such an entry by forcing a conservative distance constraint. Finally, we compare the tightening parameter profiles for both methods across all scenarios, as illustrated in Figure˜9. It is observed that the tightening parameter assumes relatively larger values during the initial phase of the engagement and gradually decreases as the engagement progresses. This happens since during the initial phases, the attacker encounters the unsafe regions head-on and demands higher values of the tightening parameter. As the engagement proceeds, the attacker performs evasive maneuvers and progressively avoids the defenders’ threatening regions. Consequently, the attacker eventually aligns with the target along a relatively unobstructed LOS. Under such conditions, the safety constraint becomes less restrictive, and the required tightening margin decreases accordingly. As a result, the tightening parameter gradually converges toward zero at the end of the engagement, indicating that no additional safety margin is required to maintain safe operation. Furthermore, the tightening parameter remains strictly positive and evolves smoothly throughout the entire engagement for all scenarios, which ensures continuous enforcement of the safety constraints without introducing discontinuous variations in the control behavior. Table 2: Comparison of target interception time. Simulation Scenario Proposed Method Conservative safety constraint Noramlized Savings (%\%) Static defenders (n=2n=2) 15.52 s 15.97 s 2.82 Moving defenders (n=3n=3) 18.91 s 22.08 s 14.36 Moving defenders (n=6n=6) 21.42 s 26.82 s 20.13 Table˜2 compares the interception times achieved by the EZ-based and maximum engagement-range-based formulations for defenders. The EZ-based approach yields a modest reduction in interception time for static defenders (2.82%) and a substantially larger reduction for moving defenders (14.36% and 20.13%), compared to the maximum engagement-range formulation. The relatively smaller improvement in the stationary defender case arises because the defenders do not actively maneuver, leading to a largely static threat region in which both methods produce similar avoidance behavior. In contrast, when defenders are moving, the threat geometry evolves dynamically, which makes conservative distance-based constraints more restrictive. Under such conditions, the EZ-aware formulation more effectively captures the coupled kinematic and dynamic interaction between the attacker and defenders, allowing the attacker to exploit favorable engagement configurations while still maintaining safety guarantees. Consequently, the attacker can maneuver more efficiently around the defenders and maintain a more direct path toward the target, resulting in a shorter interception time. These results highlight the advantage of incorporating EZ-aware safety constraints, particularly in dynamic multi-defender scenarios where threat regions evolve over time. 6 Conclusions In this work, we designed nonlinear guidance laws for an attacker to safely intercept a target while avoiding capture by the defenders and respecting the physical bounds on the attacker’s lateral acceleration. In the first approach, the defender-induced regions where attacker interception by defenders is guaranteed were modeled as Engagement Zones (EZs) and directly incorporated into the guidance design. In the second approach, we design the safety constraints to ensure that the attacker remains outside the maximum engagement range of the defenders. To ensure the designs respect the control input bounds, we also incorporate a smooth saturation model and introduce a tightening parameter to shrink the respective safe set and ensure permissible control input values. Further, a smooth minimum (log-sum-exp) function was adopted to aggregate risks across multiple zones into a unified safety measure. Stability analysis under a continuous switching function established safe-set invariance near EZs and asymptotic target interception when away from the EZs or maximum engagement range, all while respecting input bounds. Numerical simulations with multiple defenders validated the approach across diverse initial conditions, including challenging configurations with overlapping zones and concave notches. The results show that the proposed EZ-aware safety formulation enables less conservative maneuvering compared with traditional range-based safety constraints, which allows the attacker to exploit favorable engagement geometries while maintaining provable safety and achieving reduced interception times. References