Skip to content

Control Reconfiguration

A post-fault change to a feedback-control law or interface that lets an altered plant pursue an attainable goal.

Version
v2 · 2026-10-03 · History
Domain-specific #
13091
Domain group
Applied Sciences & Engineering
Origin domain
Engineering & Design (beyond software)
Subdomain
Control Systems → Engineering & Design (beyond software)
Aliases
Fault Tolerant Control Reconfiguration, Controller Reconfiguration

Core Idea

Control reconfiguration is a post-fault change to the effective control law or plant–controller interface within a feedback loop. A failed actuator may make the controller's intended command ineffective; a failed sensor may make its incoming measurement unreliable. Reconfiguration can update gains or controller structure while retaining physical channels, or select another active path or compensating interface, so the altered plant can meet a stated, attainable objective.[1][2][3]

The defining move is the effective control change, not any particular implementation or requirement to switch hardware channels. A virtual actuator can translate commands from an unchanged nominal controller into feasible commands for a faulty plant. A virtual sensor can supply reconstructed measurements to that controller. Another design can change post-fault inner- and outer-loop controller gains with the same physical pathways. Thus retuning is a valid variant, not a universal ingredient. Likewise, exact restoration of nominal behavior is one possible strong goal, not a guaranteed consequence. A weaker goal may be stability, bounded operation, or useful setpoint tracking under explicitly modeled faults.[1][3]

Structural Signature

Sig role-phrases:

  • Fault-altered process or signal path — A relevant plant, actuator, or sensor fault makes the former closed-loop arrangement inadequate for the chosen task. Without that post-fault mismatch, the activity is ordinary control design or planned mode switching, not this fault-driven identity.
  • Effective control change — The closed-loop law or interface changes through post-fault gains, controller structure, active measurement/actuation paths, or a virtual compensating block. An alarm without such a change is not reconfiguration.[1][3]
  • Post-change control objective — The changed loop is judged against an attainable stability or tracking requirement. Mere rewiring without a control criterion does not establish a fault-tolerant control result.[2]

Diagnosis often selects the response, but fault detection and isolation (FDI) and reconfiguration are distinguishable tasks. A separate FDI module is not a necessary structural role: the studied virtual-sensor arrangement can integrate residual generation and switching with the compensating interface. Virtual sensors, virtual actuators, controller redesign, and exact nominal recovery are likewise variants or goals rather than jointly required parts.[1]

What It Is Not

  • Not fault detection alone. Estimating that a sensor has failed may guide a switch, but the loop must actually change for reconfiguration to occur.
  • Not passive robustness. One fixed control law and interface that continue working without a post-fault change are a different fault-tolerance approach, even if they succeed.[1]
  • Not mandatory controller retuning. Virtual sensors and actuators can preserve the nominal controller while altering the interface it sees.[1]
  • Not guaranteed nominal recovery. Stability and useful degraded tracking can be the defensible target; exact matching depends on the remaining plant capabilities and model assumptions.
  • Not the live node “Reconfiguration” in discrete mathematics. That node concerns reachability among combinatorial states under local moves, not reconstructing a feedback-control loop.

Scope of Application

This pattern belongs to active fault-tolerant control of dynamic plants when a fault changes effective sensing, actuation, or plant dynamics enough to require a revised loop. Seron, De Doná, and Richter model both sensor and actuator faults in a three-reel winding machine and in interconnected liquid tanks. Their particular construction inserts fault-matched virtual interfaces around an observer-based nominal controller; the paper's boundedness and tracking conclusions apply to the faults and assumptions it explicitly considers.[1]

Osella, Haimovich, and Seron give another virtual-actuator variant under controller-driven varying sampling, with stability/tracking and reconfiguration as separate objectives. Altunkaya and colleagues instead update inner- and outer-loop flight-control gains after an actuator fault. This latter case shows why unchanged physical channels do not imply unchanged control: the effective feedback law changes. Neither study supplies an unconditional recovery guarantee for arbitrary plants.[2][3]

Clarity

“Reconfiguration” describes what control relation is altered: the effective feedback law mapping observations to commands, or the interface carrying those commands and observations between controller and plant. It does not mean that every physical wire or channel must move. A changed gain or inserted dynamic block can alter the closed-loop behavior while hardware connections remain fixed. Conversely, logging a new fault status without changing the law or interface is not enough.[3]

The distinction between the nominal controller and the effective loop is essential. A virtual actuator may hide the fault from the nominal controller by mediating its commands; the controller remains the same, yet the controller–plant system is reconfigured.[1]

Manages Complexity

The abstraction separates three questions that a vague “fault-tolerant” label merges: What fault or mismatch has occurred? What loop relation is changed? What post-change objective can still be met? That separation prevents a diagnosis success from being mistaken for a control success, and it prevents a successful controller design for one modeled fault set from becoming a claim about every outage.

In a modular virtual-interface design, the previously designed controller can remain in place while a compensating sensor or actuator block changes the effective plant seen by it. This can reduce redesign burden, but moves work into model matching, switching logic, and verification of the inserted block.[1]

Abstract Reasoning

Represent the nominal loop schematically as controller \(K\) interacting with plant \(P\) through measurements \(y\) and commands \(u\). After a fault, the effective plant \(P_f\) may no longer satisfy the assumptions under which \(K\) worked. A reconfiguration \(R_f\) changes the effective connection, for example by mapping controller commands to feasible faulty-plant inputs or faulty measurements to reconstructed controller inputs. The relevant comparison is not whether \(R_f P_f\) is literally identical to \(P\), but whether the resulting closed loop meets the chosen stability and tracking conditions for the specified fault set.[1]

This reasoning also exposes a boundary. A fault estimator \(\hat f\) alone changes a belief about the plant; unless some controller gain/law, control-path choice, or compensating interface changes as a result, it has not reconfigured control. Conversely, a virtual sensor may include diagnosis internally while its output transformation performs the effective change.

Knowledge Transfer

The winding machine and tank model have different physical state variables and actuators. Both nevertheless present the same logical problem: the old controller's command/measurement relation no longer corresponds to the faulty plant, so an intervening or switched control path is used to meet an explicit post-fault target. A designer can transfer the questions about fault evidence, compensating interface, and attainable objective without copying the machine's equations into the tank system.[1]

The transfer has limits. A virtual actuator that works for one range of actuator faults does not imply spare authority for every actuator loss. A virtual sensor that reconstructs one output does not make an unobservable plant observable. Feasibility and guarantees must be re-established for the new system, not inferred from the shared abstraction.[2]

Examples

Three-reel winding machine. Seron and colleagues model a machine with unwinding, traction, and rewinding reels driven by motors. In their fault-tolerant scheme, an actuator/sensor fault alters the plant information or command effect (fault-altered process); residual-driven selection engages a matching virtual actuator and virtual sensor (effective loop change); closed-loop boundedness and setpoint tracking are checked under the paper's considered faults (post-change objective). The residual decision helps choose the path, but it is not identical to the path change.[1]

Mapped back: the motor/sensor fault supplies the trigger, the virtual interface supplies the altered feedback path, and the paper's conditional boundedness/tracking result supplies the criterion; residual diagnosis is a selection aid rather than the defining operation.

Interconnected tanks. In their two-tank model, faulty valves or level measurements alter how an unchanged nominal controller can act and observe (fault-altered process). Virtual actuator and virtual sensor signals reshape the effective input/output interface (loop change), while modeled level tracking and boundedness supply the control test (objective). The same three roles recur with hydraulic rather than reel-drive physics.[1]

Mapped back: the valve/measurement fault changes the plant or observation channel, the virtual sensor/actuator changes the loop seen by the nominal controller, and the modeled tracking/boundedness test evaluates the resulting control rather than asserting exact physical restoration.

Near miss: an alarm only. A residual crosses a threshold and a dashboard reports “sensor fault,” but the controller continues to receive that same failed measurement. The fault is identified; the effective feedback path is unchanged. This is diagnosis without control reconfiguration.

Structural Tensions

  • Reliable fault choice versus rapid switching. More discrimination can reduce the chance of choosing the wrong virtual interface, but waiting also extends operation with an inadequate loop. Diagnostic: What evidence supports the chosen fault case, how long does it take, and how is misdiagnosis handled? The Seron scheme explicitly analyzes residual-based decisions and errors in them.[1]
  • Preserving a nominal controller versus redesigning it. A virtual interface avoids replacing \(K\), but must sufficiently compensate the plant/controller mismatch; direct controller redesign has more freedom but changes more of the certified loop. Diagnostic: Can an intervening block meet the required closed-loop conditions with the available channels, or is a changed controller necessary?[1]
  • Nominal recovery versus achievable degradation. Exact response matching is attractive, but lost actuation or sensing can make it impossible. A weaker boundedness or tracking target may still be valuable. Diagnostic: Which states or outputs remain controllable and observable after the specified fault, and which guarantee has actually been proved?[1][2]

Structural–Framed Character

Evaluative weight. Post-fault performance is judged against an engineering target; “acceptable” is not a universal mathematical constant. Human-practice bound. Engineers declare fault classes and control objectives, while feedback dynamics and system constraints determine what a revised law can achieve.[1][2]

Institutional origin. Fault-tolerant control research supplies virtual-actuator and gain-update schemes, but neither one scheme nor one aircraft application defines reconfiguration. Vocabulary travel. Changed effective control and feedback are portable within controlled plants; state-space matrices, observers and sample periods are technical realizations.[1][3]

Import versus recognition. A new system qualifies when a fault prompts a change to the effective plant–controller connection or law and a post-change objective is checked. An organization merely revising its plan after a problem borrows the word. Its character: mixed-framed—a structural feedback modification under task-specific safety and performance criteria.

Structural Core vs. Domain Accent

Portable skeleton. Live Feedback is the staged prerequisite: measured outputs affect control input in the relation being changed. The edge is composition/presupposes, not strict subsumption, because reconfiguration is a post-fault change to a controller or interface, not itself a feedback loop.[1]

Domain-bound mechanism. A fault creates a mismatch; an effective law or plant–controller connection changes and the resulting control objective is checked. State-space matrices, virtual sensors/actuators, gain updates and invariant-set proofs make particular schemes testable but are not jointly required of every reconfiguration.[1][2][3]

Why not prime. Feedback itself transfers broadly, but a generic post-crisis policy revision lacks a controlled plant, measured-output loop and declared post-change control target. Fault Tolerance may be the desired result, not the identity. This remains a control-engineering intervention grounded in a live Feedback prerequisite.

This entry presupposes Feedback. Control reconfiguration changes an effective feedback-control law or interface and structurally presupposes feedback.

Relationships to Other Abstractions

Local relationship map for Control ReconfigurationParents appear above the current abstraction, mutual partners to the right, and children below. Node labels state whether each abstraction is prime or domain-specific; colors identify relation types.ControlReconfigurationDOMAINPrime abstraction: Feedback — presupposesFeedbackPRIME

Current abstraction Control Reconfiguration Domain-specific

Parents (1) — more general patterns this builds on

  • Control Reconfiguration presupposes Feedback Prime

    Control reconfiguration changes an effective feedback-control law or interface and structurally presupposes feedback.

    Condition / exception structural_prerequisite

Hierarchy path (1) — routes to 1 parentless root

Neighborhood in Abstraction Space

Control Reconfiguration sits in a sparse region of the domain-specific corpus (82nd percentile for distinctiveness): few abstractions share its structure, so a faithful description tends to retrieve it precisely.

Family — Unclustered & Miscellaneous (2551 abstractions)

Nearest neighbors

Computed from structural-signature embeddings · 2026-10-08

Not to Be Confused With

An unchanged robust controller may deliver fault tolerance without reconfiguration. Fault detection may tell the supervisor what happened without modifying the control law. The terminology of fault Accommodation and Reconfiguration overlaps in some literature: a post-fault gain change can satisfy this entry's test even if every physical signal channel is unchanged. The criterion is an altered effective closed-loop law or interface, not a rigid vocabulary boundary. Finally, the word “reconfiguration” in a combinatorial reachability problem has a different bearer and failure boundary.

References

[1] María M. Seron, José A. De Doná, and Jan H. Richter, "Integrated sensor and actuator fault-tolerant control", International Journal of Control 86(4), 689–708 (2013), DOI 10.1080/00207179.2012.757653. Author-uploaded full text directly checked, especially Introduction on FDI versus reconfiguration and unchanged nominal controller, and application sections on winding machine and interconnected tanks. Guarantees are explicitly model- and fault-set-conditional. registry ↩a ↩b ↩c ↩d ↩e ↩f ↩g ↩h ↩i ↩j ↩k ↩l ↩m ↩n ↩o ↩p ↩q ↩r ↩s ↩t

[2] Esteban N. Osella, Hernan Haimovich, and María M. Seron, "Fault-tolerant control under controller-driven sampling using virtual actuator strategy" (2013), original-research author abstract directly checked for virtual-actuator engagement, separate objectives, and conditional preservation of stability/tracking. registry ↩a ↩b ↩c ↩d ↩e ↩f ↩g

[3] Ege C. Altunkaya, Akin Catak, Emre Koyuncu, and Ibrahim Ozkol, "Innovative Gain Reconfiguration for Active Fault-Tolerant Flight Control: Balance of Stability and Agility" (2024), original-research author abstract directly checked for fault-conditioned inner- and outer-loop gain updates. registry ↩a ↩b ↩c ↩d ↩e ↩f ↩g