1. Introduction
Thermal pasteurization integrates food-safety requirements, product stability, quality preservation, and energy use within a single processing stage. In dairy and other heat-sensitive products, temperature control must therefore regulate not only the nominal setpoint but also exposure time, thermal overshoot, spatial uniformity, and energy demand. Recent research has addressed event-based optimization of food thermal processing [
1], energy and exergy performance in milk pasteurization [
2], advanced control of continuous-flow ohmic heating [
3], adaptive pasteurization control [
4], predictive control of extrusion [
5], and industrial drying [
6]. These applications show the value of incorporating process dynamics and operational constraints, but they represent different thermal architectures and should not be treated as interchangeable evidence.
A jacketed batch pasteurizer differs fundamentally from a continuous high-temperature short-time (HTST) line. The product remains in a stirred sanitary vessel while heat is transferred indirectly through a service jacket; there is no continuous product flow, holding tube, or dominant regenerative section. The controlled temperature therefore represents the thermal state of an accumulated product mass rather than the outlet temperature of a continuous stream. Appropriate models must account for product and jacket thermal capacities, wall and heat-loss effects, agitation, spatial temperature dispersion, actuator limits, and measurement delays. Direct transfer of continuous heat-exchanger or HTST models to this configuration may therefore produce an incorrect representation of the plant dynamics.
Thermal-system modeling increasingly combines physical balances with parameter estimation and operational data. Mechanistic and grey-box representations preserve physical interpretation and energy consistency, whereas lumped and transfer-function models facilitate identification, diagnosis, and controller synthesis [
7,
8,
9,
10]. Online estimation, Kalman-filter-based methods, reinforcement learning, fractional-order formulations, and physics-informed models have also been used to represent changing heat-transfer coefficients, uncertainty, and nonlinear thermal behavior [
11,
12,
13,
14]. For a jacketed batch system, this supports the use of a batch–jacket grey-box model as a physical plausibility layer, provided that its parameters remain admissible and are validated with data not used for estimation.
PI and PID controllers remain common industrial benchmarks because of their simplicity, low implementation cost, transparency, and operator familiarity [
15,
16]. However, fixed tuning may lead to delayed correction, overshoot, oscillation, or unnecessary energy use in processes affected by high inertia, delay, saturation, fouling, and changing heat-transfer conditions. Optimized PID, model-free, fractional-order, adaptive, neural-network-based, and uncertainty-compensation strategies have consequently been proposed for thermal systems [
17,
18,
19,
20,
21,
22]. Their adoption in food processing nevertheless requires more than improved tracking: actuator feasibility, thermal constraints, holding-time traceability, and operational stability must also be preserved.
Model predictive control (MPC) is attractive for jacketed batch pasteurization because it can anticipate thermal evolution, penalize abrupt input changes, and enforce power and temperature constraints. Its performance depends on prediction and control horizons, cost-function weights, constraint formulation, and solver feasibility [
23,
24,
25,
26,
27,
28,
29]. Autoregressive models with exogenous input (ARX) provide a compact discrete representation for this purpose because they relate current temperature to delayed inputs and past outputs. Robust, adaptive, predictive, and state-dependent ARX formulations have been reported for nonlinear or time-varying systems [
30,
31,
32,
33].
Previous pasteurization studies provide important foundations but address different process configurations. Khadir and Ringwood developed a first-principles control-oriented representation of an industrial pasteurizer assembled from plate and brazed heat exchangers [
34]. Ibarrola et al. studied predictive control of a continuous HTST process [
35], while Niamsuwan et al. evaluated multivariable MPC for milk pasteurization through simulation [
36]. Experimental comparisons of PID, MPC, and adaptive MPC have also been reported for continuous-flow ohmic heating [
3], with related predictive-control applications in extrusion [
5] and drying [
6]. These systems involve continuous transport, outlet-temperature dynamics, direct volumetric heating, or multistate flow behavior and do not directly reproduce the energy accumulation, indirect jacket transfer, agitation, spatial temperature dispersion, and batch-level replication of a closed jacketed pasteurizer.
This study develops and experimentally evaluates a traceable hybrid grey-box–ARX identification and control framework for a 250 L jacketed batch milk pasteurizer. The framework combines a batch–jacket grey-box model for physical and energy interpretation with a local ARX predictor identified in the approach and holding region. A fixed-parameter PI controller with anti-windup is compared with a nominal constrained MPC under common sampling, reference, actuator, and exclusion conditions, while supervised ARX observation, PI retuning, and adaptive MPC are evaluated separately as diagnostic, secondary, and exploratory extensions.
The contribution is methodological and experimental rather than algorithmic. The study integrates measured active electrical power, three-sensor spatial temperature supervision, formal acceptance and rejection criteria for adaptive updates, independent model-validation records, and batch-level paired controller comparisons. This design allows tracking, energy consumption, actuator saturation, feasibility, and thermal overexposure to be evaluated within a unified workflow. The conclusions are restricted to the experimentally represented operating domain and do not imply universal MPC superiority, microbiological validation, or sanitary certification.
3. Materials and Methods
The methodology was developed for a 250 L jacketed batch milk pasteurizer treated as a closed, stirred, energy-accumulating system rather than as a continuous high-temperature short-time (HTST) line. During heating and holding, the plant had no continuous product flow, holding tube, or dominant regenerative section. The workflow combined plant specifications, a batch–jacket grey-box model, and a local ARX predictor for short-horizon control. Fixed PI control, supervised adaptive extensions, and constrained MPC–ARX were evaluated under common sampling, reference, actuator, and exclusion conditions.
Manufacturer and design specifications defined the physical domain, model initialization, plausibility bounds, and operating constraints. Experimental measurements were used for parameter estimation, independent validation, controller comparison, and energy-performance calculation. Thus, specifications established admissible limits, whereas the reported results were derived from measured experimental batches.
3.1. Experimental Design and Comparative Architecture
The complete batch was the experimental unit. Time samples supported identification, prediction, controller execution, and indicator calculation but were not treated as independent statistical replications. The primary confirmatory comparison was C3–C0: nominal constrained MPC based on the fixed ARX model versus fixed-parameter PI control with anti-windup. C1 was an observation-only adaptive ARX layer, C2 was evaluated secondarily against C0, and C4 was evaluated exploratorily against C3.
All strategies used the same control period, actuator limits, reference trajectory, enabled sensors, initial-condition criteria, and scenario definitions. C4 was kept separate from the C3–C0 comparison to preserve the confirmatory role of the nominal MPC.
The C3–C0 contrast was a practical industrial benchmark, not a complexity-matched controller comparison. C0 included anti-windup, actuator saturation, input-rate limitation, and bumpless transfer; its tuning was fixed after the pilot stage. The comparison therefore quantified the incremental benefit of prediction and explicit constraint handling relative to this conventional baseline, but not superiority over gain-scheduled PI, nonlinear PID, adaptive control, nonlinear MPC, or other advanced strategies.
Table 1 summarizes the controller architecture, associated model, comparative role, and main evidence used in the study.
3.2. Experimental Plant and Operating Domain
The experimental plant was a sanitary jacketed batch pasteurizer with a gross capacity of 300 L and a useful capacity of 250 L. It comprised an external service jacket, indirect electrical heating, service-fluid recirculation, and mechanical agitation. As shown in
Figure 1, the applied command drove the SCR heater, active electrical power was measured at the heater input, and heat was transferred through the service jacket to the accumulated product mass. Agitation influenced mixing, spatial temperature dispersion, and effective batch–jacket heat transfer. Product-temperature, jacket-temperature, and active-power measurements were returned to the controller and supervisory system. This architecture defined the boundaries of the batch–jacket grey-box model, ARX predictor, and MPC formulation.
Table 2 summarizes the plant specifications and operating conditions used for modeling, identification, and control.
The permissible 150–250 L fill range was not fully represented experimentally; the analyzed batches were concentrated near the nominal 250 L condition. The study therefore evaluates batch-to-batch variability near nominal fill rather than robustness across the complete equipment range.
The batch cycle comprised loading, mixing, rapid heating, approach, holding, cooling, and discharge. ARX identification and the C3–C0 evaluation were restricted to the approach and holding region, where a local predictor was considered appropriate. Rapid-heating data supported energy-balance and effective-capacity assessment, whereas cooling was treated separately because its service conditions and heat-flow direction differed from heating and holding.
All confirmatory experiments used milk and the same recipe: a 65 °C setpoint, 30 min holding period, and 63 °C minimum operational threshold. The observed batch mass, initial temperature, and agitation ranges were 242.57–270.42 kg, 17.53–24.46 °C, and 60–120 rpm, respectively. These ranges define the empirical domain; the complete fill range, alternative recipes, and other dairy formulations were not experimentally validated.
3.3. Signals, Instrumentation, and Data Acquisition
The controlled output was the mean batch temperature calculated from three valid product sensors:
Independent supervision used the minimum product temperature and the spatial temperature dispersion:
Valid holding time was accumulated only when all sensors remained valid, the minimum product temperature exceeded the required threshold, and the spatial dispersion remained within the admissible tolerance:
This criterion was used as an operational engineering indicator of time–temperature compliance. It was not interpreted as microbiological validation or sanitary certification.
The manipulated input was the normalized heating command
. However, energy calculation and energy identification were based on measured active electrical power. The command-to-thermal-power relationship was retained only as an auxiliary model:
Raw data were acquired using a common time reference at 1–2 s. Control execution, ARX prediction, RLS updating, and MPC optimization were performed at
s after causal resampling.
Table 3 summarizes the critical measured and derived signals.
Data were partitioned by batch and by block into estimation, selection, validation, and comparison subsets. Records used to tune or select models were not used as confirmatory evidence. Samples with quality flags were retained in the raw database but excluded from the affected mathematical window.
3.4. Batch–Jacket Grey-Box Model
The plant was represented by a two-state batch–jacket grey-box model describing energy accumulation in the product and effective jacket dynamics. Additional states were omitted because they were not reliably identifiable with the available sensors. The model supported parameter initialization and bounding, physical interpretation of the ARX predictor, and energy-consistency assessment.
The state vector, jacket-temperature approximation, and output were defined as
The effective thermal capacities were written as
The batch–jacket grey-box model conductance was represented as
Because the individual thermal resistances were not separately identifiable from the available measurements, was estimated as an aggregated parameter.
During heating and holding, the energy balances were
The local linear form around an operating condition was
with matrices derived from
,
,
,
, and
. First-order discretization or zero-order-hold discretization linked the physical model to the ARX representation:
Energy consistency was evaluated over each moving window using
Persistently high values were interpreted as indicators of power-measurement problems, omitted losses, incorrect effective thermal mass, or operation outside the model validity domain.
3.5. ARX Identification and Discrete-Model Validation
The ARX model was formulated in deviation variables as a local predictor for the approach and holding region:
The candidate structure was
with
For s, the candidate set comprised , , and . Candidate inputs were the normalized command and measured active electrical power . The latter was preferred because it represented the energy supplied to the process more directly, but it was used only when continuous, synchronized, and sufficiently excited. Otherwise, served as an auxiliary input, and the choice was recorded for traceability.
The parameter vector was estimated using
Weighted least squares was used when uncertainty varied across windows. Model selection combined out-of-sample performance, parsimony, discrete-time stability, multi-step and free-simulation errors, and residual autocorrelation. The response was also required to preserve a physically consistent gain sign and energy behavior. A near-unit pole was retained when it represented actual batch-energy accumulation. The nominal ARX model was fixed before controller tuning and comparative evaluation.
Model mismatch was defined as the difference between the response predicted by the fixed nominal ARX model and the measured plant response under conditions differing from those represented during identification. Anticipated sources included variations in effective thermal capacity, batch–jacket conductance, heat losses, mixing, product properties, actuator gain, sensor dynamics, effective input delay, and unmeasured disturbances. Batch-mass changes alter thermal capacity and the dominant heating dynamics, whereas recipe or composition changes may affect heat capacity, viscosity, mixing, fouling, heat transfer, and the local operating point.
Mismatch was assessed through independent one-step, multihorizon, and free-simulation errors; gain sign and stability; energy closure; and the prediction-error diagnostics of the supervised ARX–RLS observer. These criteria evaluated local adequacy for short-horizon control and were not interpreted as evidence that the same coefficients remained valid for untested batch sizes, products, or recipes.
The conservation structure can be retained for similar closed, stirred, indirectly heated jacketed vessels, but its numerical parameters are plant specific. Transfer to such equipment requires recalibration of thermal capacities, conductance, heat losses, actuator efficiency, and measurement dynamics, together with ARX re-identification. Capacity changes require reparameterization rather than proportional volume scaling because thermal mass, heat-transfer area, service circulation, and surface-to-volume ratio do not scale uniformly. Processes involving direct steam injection, spray or immersion heating, rotation, pressure-dependent operation, or continuous transport require additional balance terms and partial or complete model reconstruction.
3.6. Supervised Adaptation and Controllers
Supervised recursive least squares (RLS) was used for adaptive parameter estimation. For a regressor
, the update equations were
Raw RLS candidates were not incorporated automatically into the observer or controller. Each update passed through a sequential gate comprising data eligibility, excitation sufficiency, and model admissibility. All thresholds were calibrated from pilot-stage records and fixed before the comparative campaign.
For excitation diagnosis, regressors were normalized using pilot-stage scaling factors. Over a moving window of
samples, the normalized information matrix was calculated as
The window was considered sufficiently informative only when
where
and
denote the minimum eigenvalue and condition number, respectively. These conditions prevented updates under weak excitation or ill-conditioned regressors.
Candidate updates were evaluated only in the approach or holding region, with valid and synchronized temperature and power signals, no active alarm or mode transition, no persistent actuator saturation, acceptable spatial temperature dispersion, and energy-closure error below its prescribed limit. Failure of any eligibility or excitation condition froze adaptation and retained the previous validated parameters.
Eligible candidates were then required to preserve a positive and bounded static gain, satisfy the predefined discrete-time stability margin and parameter bounds, and avoid abrupt parameter changes. Parameter continuity was evaluated using
where
is the raw candidate vector. For the four-parameter ARX structure, the candidate was required to satisfy
An update was accepted only when all eligibility, excitation, conditioning, stability, gain, parameter-continuity, spatial-consistency, actuator, and energy-consistency criteria were satisfied. Otherwise, the candidate was rejected, the previous validated model was retained, and controller retuning or adaptive-MPC model replacement was not authorized.
Table 4 summarizes the complete diagnostic sequence, including the criteria, fixed thresholds, and action taken when each condition failed. Acceptance indicated numerical stability and physical admissibility, not predictive or closed-loop superiority. C1 therefore stored accepted updates in observation mode, whereas C2 and C4 could use only models that passed the complete diagnostic gate and the corresponding controller-level authorization. The fixed nominal model and controller remained available as fallback configurations.
The diagnostic gate was designed as a safety and model-admissibility filter rather than as a closed-loop performance selector. RLS minimized local one-step prediction error, whereas controller performance depended on multihorizon prediction, the MPC objective, tracking, specific energy consumption, actuator variation, and thermal overexposure. An accepted model could therefore satisfy all numerical and physical criteria yet remain inferior to the nominal predictor for receding-horizon control. Admissibility alone did not authorize model replacement, and the nominal model remained the fallback configuration.
C0 was the conventional fixed-parameter PI comparator, including saturation, input-rate limitation, bumpless transfer, and anti-windup. In incremental form,
C1 updated the ARX model in observation mode without affecting the control signal. C2 retuned the PI controller only after complete diagnostic and controller-level authorization. C3 used the fixed nominal ARX model in constrained MPC, whereas C4 used an authorized adaptive model as an exploratory extension. This separation prevented improvements caused by re-identification or additional information from being attributed solely to the control law.
The MPC prediction was written as
and the optimization problem as
subject to
Prediction horizons, control horizons, weights, constraints, scaling, and solver configuration were adjusted during the pilot stage and fixed before the confirmatory comparison.
3.7. Robustness Assessment of the Nominal Constrained MPC
The assessment examined whether C3 remained operationally adequate under model–plant mismatch. Because C3 was a nominal constrained MPC rather than a min–max, tube-based, or stochastic robust controller, the analysis was interpreted as an empirical uncertainty stress test, not as proof of robust stability or worst-case constraint satisfaction.
Two complementary assessments were conducted. First, the fixed nominal ARX model was evaluated without re-estimation across independent batches stratified by the observed batch-mass and initial-temperature ranges. Second, an offline closed-loop stress test combined structured grey-box parameter variations with data-derived ARX uncertainty, measurement uncertainty, and correlated residual disturbances.
The uncertainty set included effective batch thermal capacity, batch–jacket conductance, heat-loss contribution, actuator gain, and effective input delay. Bounds were derived, whenever possible, from independent identification and validation records, between-batch parameter variability, command-to-active-power measurements, and sensor uncertainty rather than arbitrary percentage perturbations.
Table A2 summarizes the uncertainty sources and tested bounds.
The uncertain plant was represented as
where
denotes the experimentally derived parameter set,
represents bounded measured disturbances, and
represents correlated unmodeled dynamics. The set
was constructed from independently estimated parameter variability, while residual sequences were generated through a moving-block bootstrap of independent validation residuals to preserve temporal correlation.
In every realization, the nominal ARX model, horizons, weights, scaling, constraints, solver configuration, and 5 s control period used by C3 remained unchanged. Uncertainty was applied only to the simulated plant; thus, the test evaluated model–plant mismatch rather than controller retuning or re-identification. The evaluated conditions included parameter combinations within , measured actuator-gain variability, a one-sample effective-delay variation, product-temperature measurement uncertainty, and block-resampled residual disturbances. Parameter uncertainty and external disturbances were tested separately and jointly.
Robustness was evaluated through optimizer feasibility, valid holding-condition attainment, output-constraint violation, trajectory boundedness, RMSE, IAE, specific energy consumption, actuator saturation and total variation, fallback activation, and computation time. The analysis comprised 400 closed-loop realizations: 100 nominal reference realizations, 100 with parameter uncertainty only, 100 with external disturbances only, and 100 with combined uncertainty and disturbances. Stochastic uncertainty sampling and residual resampling were performed using the fixed base random seed 20260619 with MATLAB’s R2019a Mersenne Twister generator; realization-specific seeds were derived deterministically from this base seed. The evidence was restricted to the data-derived uncertainty region and was not extrapolated to the complete fill range, alternative recipes or products, or severe sensor and actuator failures.
3.8. Comparative Protocol and Performance Indicators
The comparison used paired blocks matched by batch mass, initial temperature, agitation, jacket condition, and operating scenario. Each pair retained the same reference profile, control period, actuator limits, enabled measurements, and exclusion criteria. Initial equivalence required batch mass within the prescribed tolerance, an initial-temperature difference below 0.5 °C, and no active alarms. Controller order was balanced or randomized subject to operational restrictions. Pilot batches were used to refine the procedure, whereas confirmatory batches were not used for model retraining or controller retuning.
The campaign included at least three complete pilot blocks and five paired confirmatory blocks. Its final size considered pilot variability, the minimum engineering-relevant difference, and product availability. The complete batch was the experimental unit; temporally correlated samples were not treated as independent replications. Interrupted batches remained in the traceability record and were classified before indicator calculation.
Tracking indicators were calculated by batch as
Specific energy consumption and actuator activity were
The holding-temperature deficit was
For an indicator
in which lower values represent better performance, the paired difference in block
was
Overshoot, time outside the admissible band, saturation, MPC feasibility, computation time, fallback activations, and accepted and rejected adaptive updates were also reported.
Thermal overexposure was retained as a controller-oriented degree–time indicator:
where
is the mean product temperature and
is the control reference. With time in seconds,
has units of °C s. It measures controller-induced thermal excess and was not interpreted as microbiological lethality.
Generalized accumulated lethality was calculated conservatively from the minimum valid product-sensor temperature:
where time is expressed in minutes,
is the selected reference temperature, and
characterizes the temperature sensitivity of the target microorganism. For records sampled every
seconds,
The conventional sterilization value is the particular case
Because the treatment was conducted at pasteurization temperatures, was included only to establish the standard mathematical relationship. A microbiologically meaningful pasteurization value requires , , and values validated for the selected microorganism and milk matrix.
To establish the trajectory-level mapping, define the positive excursion above the microbiological reference as
The corresponding reference-matched degree–time integral is
and the excess equivalent lethality is
Thus, the mapping depends on the complete temperature trajectory and is not a one-to-one transformation of a scalar degree–time value. For a constant excursion
maintained for
,
and
When a validated decimal-reduction time is available, predicted microbial reduction is
No microorganism-specific log reduction was reported because and were not experimentally determined for the evaluated milk–microorganism combination.
The relationship in Equations (33)–(37) applies only when degree–time exposure and equivalent lethality are calculated from the same temperature trajectory, reference temperature, and time unit. Therefore, the reported controller-oriented , based on mean product temperature and the control reference, cannot be converted directly into or a target-specific pasteurization value.
3.9. Statistical Analysis, Uncertainty, and Validity Domain
All performance indicators were calculated separately for each complete batch. Time samples were used to compute batch-level RMSE, IAE, specific energy consumption, overshoot, actuator saturation and activity, time outside the admissible band, and thermal overexposure but were not treated as independent statistical observations. Statistical inference was therefore conducted at the paired-block level.
For each of the five confirmatory blocks
, the paired difference for indicator
was defined as
Negative values favored C3 for indicators in which lower values represented better performance. RMSE was treated as the principal quadratic tracking indicator, IAE as a complementary accumulated-error measure, and specific energy consumption as the principal energy-performance outcome. Because RMSE and IAE were derived from the same temperature-error trajectory, they were not interpreted as statistically independent evidence.
For each indicator, the analysis reported the controller-specific mean and standard deviation, the mean and standard deviation of the paired differences, relative percentage change, a 95% confidence interval for the mean paired difference, and a small-sample-corrected paired standardized effect size. Confidence intervals were calculated from the five paired differences using the Student’s distribution. The effect-size sign followed the definition of ; therefore, negative values favored C3.
The paired differences were examined using individual paired-block and quantile–quantile plots. Given the limited number of blocks, formal normality testing was not used as the sole basis for selecting the inferential procedure. A paired-samples -test evaluated the mean difference, and an exact paired nonparametric test was included as a sensitivity analysis. When multiple indicators were tested within the same comparison, -values were adjusted using the Holm procedure. The results were interpreted jointly through confidence intervals, effect magnitude, directional consistency across blocks, and the minimum engineering-relevant difference rather than statistical significance alone.
The secondary C2–C0 and exploratory C4–C3 comparisons were analyzed separately from the primary C3–C0 contrast. Their interpretation emphasized the magnitude and direction of the changes and the associated tracking, energy, and actuator trade-offs rather than dichotomous significance decisions.
Measurement-uncertainty sources included product-temperature sensors, active-power measurements, batch mass, temporal resampling, and estimated model parameters. These sources were considered when interpreting the derived indicators and delimiting the validity domain; no quantitative combined-uncertainty claim was made without a complete metrological uncertainty budget. The findings were not extrapolated beyond the experimentally represented ranges of batch volume, agitation, heating power, product type, service conditions, and dynamic region.
4. Results
4.1. Experimental Campaign and Traceability
The campaign comprised 54 batches: 12 for model identification, selection, and validation; 12 for pilot-stage procedure refinement; and 30 for controller comparison, divided equally among the confirmatory C3–C0, secondary C2–C0, and exploratory C4–C3 contrasts. This partition prevented records used for model development or procedural refinement from being reused as confirmatory evidence.
Table 5 summarizes campaign traceability. The batches averaged
min, with a mass of
kg and an initial temperature of 20.99 ± 1.90 °C. Batch masses remained concentrated near the nominal fill condition rather than covering the full permissible 150–250 L range; consequently, the campaign does not support comparisons among low-, intermediate-, and high-fill levels. After causal preprocessing,
of samples remained valid for identification and controller evaluation.
All batches achieved 30 min of valid holding under the operational criterion defined in the protocol. This result confirms compliance with the evaluated time–temperature condition but does not constitute microbiological validation or replace food-safety testing.
Block equivalence was maintained through matched conditions of batch mass, initial temperature, agitation, and drift scenario. The nominal model was identified and validated before the comparison baseline was fixed, after which the controllers were evaluated without retraining, retuning, or treating temporally correlated samples as independent replications. This preserves the evidential separation required in the revised experimental design.
4.2. Grey-Box Model, Nominal ARX, and Multihorizon Prediction
The batch–jacket grey-box model yielded an effective product thermal capacity of
MJ/K and an effective jacket capacity of
MJ/K (
Table 6). The nominal conductance reference was
W/K, and mean electrical consumption was
kWh per batch. The relative energy-closure error was
, ranging from 0.189 to 0.291. This discrepancy reflects unresolved heat losses, effective metallic thermal storage, and simplifications of the two-state representation. Accordingly, the grey-box model was used for physical interpretation, parameter initialization, and plausibility bounds rather than as a high-fidelity simulator.
ARX identification was restricted to the approach and holding region. Among 27 candidate structures with and , the selected model had , , and . It retained discrete-time stability, a positive static gain of 0.0813, and a one-step validation RMSE of 0.0499 °C. The RMSE increased to 0.350 °C at 24 steps, corresponding to 120 s, and to 1.413 °C in free simulation, indicating progressive error accumulation outside measurement-corrected short-horizon prediction. The nominal ARX model was therefore suitable for local receding-horizon control but not for extrapolation across the complete batch cycle or untested operating modes.
Table 6 and
Figure 2 provide partial operational support for H1: the hybrid framework combined physical interpretation and plausibility bounds with a stable, parsimonious, and locally predictive ARX model. However, it was not evaluated as a complete model of every batch mode or against all possible modeling alternatives; its validity remains restricted to the experimentally represented region.
4.3. Within-Domain Model-Mismatch Assessment
To examine whether nominal-model performance was concentrated in a narrow batch condition, the independent validation records were stratified according to batch mass and initial temperature. Batch mass was classified as lower, nominal, or higher relative to the campaign distribution, using predefined limits established before calculating the prediction indicators. Initial temperature was similarly divided into lower and higher thermal-load conditions. The nominal ARX coefficients were not re-estimated within these strata.
Table 7 reports 1-step RMSE, 24-step RMSE, free-simulation RMSE, and the sign and stability of the nominal model across the observed operating strata. This analysis evaluates whether the fixed predictor retained acceptable local performance under the batch-to-batch variability represented in the campaign. It does not extend the empirical validity of the model beyond the observed mass, temperature, agitation, product, or recipe ranges.
4.4. Robustness Assessment Under Parameter Uncertainty and External Disturbances
The offline stress test evaluated whether C3 remained operationally adequate under model–plant mismatch. Unlike the within-domain assessment in
Section 4.3, which used variability observed in experimental batches, this analysis introduced parameter uncertainty, measurement uncertainty, effective-delay variation, actuator-gain variability, and temporally correlated residual disturbances. Because C3 is a nominal constrained MPC, the assessment was interpreted as an empirical stress test rather than as proof of robust stability or guaranteed constraint satisfaction.
A total of 400 closed-loop Monte Carlo realizations were generated using MATLAB’s Mersenne Twister pseudorandom-number generator and a fixed base seed of 20260619. The realizations were equally divided into four groups of 100 runs: nominal reference, parameter uncertainty only, external disturbances only, and combined parameter uncertainty and external disturbances. The uncertainty sources and bounds are reported in
Table A2.
In every realization, C3 retained the same nominal ARX model, prediction and control horizons, objective-function weights, scaling, actuator and output constraints, solver configuration, and 5 s control period used in the experimental comparison. No online re-identification, retuning, or adaptation was permitted; uncertainty and disturbances were applied only to the simulated plant. The test therefore evaluated tolerance to model–plant mismatch rather than controller reconfiguration.
Table 8 summarizes the resulting closed-loop feasibility, holding-condition attainment, temperature-constraint violation, tracking performance, specific energy consumption, actuator saturation, and fallback behavior for each scenario group.
Across all realizations, the optimization remained feasible at 100.0% of the control instants, and the valid holding condition was achieved in 100.0% of the realizations. Under parameter uncertainty alone, mean RMSE increased from 1.451 °C in the nominal condition to 1.650 °C, while specific energy consumption increased from 0.08956 to 0.09592 kWh/kg. External disturbances produced a mean RMSE of 1.454 °C, indicating only a minor deterioration relative to the nominal reference. The combined uncertainty-and-disturbance scenarios produced a mean RMSE of 1.615 °C and a maximum temperature violation of 1.823 °C. Nevertheless, all simulated trajectories remained bounded, and fallback activation occurred in 0 of the 400 realizations.
The observed changes were physically consistent with variations in effective batch thermal capacity, effective delay, and actuator gain, although the available results do not provide a source-by-source sensitivity ranking. Variations in effective batch thermal capacity primarily altered the heating rate and dominant time constant, whereas effective-delay variation affected the timing of anticipatory power reduction near the holding region. Actuator-gain variability changed the thermal power delivered relative to the MPC command. Correlated residual disturbances produced only small mean changes in tracking, as indicated by the increase in RMSE from 1.451 to 1.454 °C and a maximum temperature violation of 0.038 °C, without a meaningful increase in specific energy consumption. These effects were reflected mainly in RMSE, maximum temperature violation, and specific energy consumption.
Across the complete stress test, the largest observed RMSE was 3.678 °C, whereas the largest observed temperature violation was 2.552 °C. Despite these extrema, C3 maintained optimizer feasibility and bounded trajectories, achieved the valid holding condition, avoided actuator saturation, and did not activate the fallback controller. Because the available summary does not establish that the largest RMSE and largest temperature violation occurred in the same realization, they are interpreted as the worst observed metric values rather than as the results of a uniquely identified worst-case trajectory. These extrema define the practical boundary of the evaluated uncertainty region and indicate that constraint tightening or an explicitly robust MPC formulation would be required before extending operation beyond it.
Overall, C3 tolerated the parameter and disturbance variability represented by the data-derived uncertainty set without loss of optimizer feasibility, trajectory divergence, or failure to attain the valid holding condition. However, these results do not establish robust stability or worst-case constraint satisfaction outside that set. The evidence is therefore restricted to near-nominal fill conditions, the installed sensing and actuation chain, and the 65 °C/30 min milk recipe. Other fill levels, formulations, thermal recipes, severe faults, or substantially different heat-transfer conditions require additional experimental validation or an MPC formulation with explicit uncertainty propagation and constraint tightening.
4.5. Adaptive Observer C1
C1 operated as a parallel ARX–RLS observer without modifying the applied power or control law. Its purpose was to separate online parameter estimation from controller-induced performance changes and to screen candidate models before their possible authorization for use by C2 or C4.
A candidate update was accepted only when it satisfied the complete diagnostic framework defined in
Table 4, including data eligibility, excitation, numerical conditioning, dynamic stability, physical gain, parameter continuity, spatial consistency, actuator condition, and energy consistency. If any criterion failed, the candidate was rejected, and the previously validated parameter vector was retained. Accordingly, the number of accepted updates indicates numerical and physical admissibility but does not demonstrate predictive or closed-loop superiority over the nominal ARX model.
As shown in
Table 9, all final accepted models remained stable under every control base. However, C1 did not reduce predictive RMSE relative to the nominal ARX model in any case. Under C0, RMSE increased from 0.0579 to 0.0920 °C, whereas under C2 it increased from 0.0554 to 0.0820 °C. The differences were smaller under the predictive controllers: RMSE increased from 0.0382 to 0.0405 °C under C3 and from 0.0361 to 0.0418 °C under C4. These results indicate that the fixed nominal ARX model was already informative within the evaluated operating domain and that recursive updating introduced no systematic predictive benefit.
C0- and C2-based operation produced lower acceptance rates and more rejected updates than C3- and C4-based operation. Under C0 and C2, persistent actuator saturation was the dominant first failed diagnostic gate, whereas under C3 and C4 the physical-gain criterion was the dominant rejection cause. This distinction suggests that the admissibility of recursive updates depended not only on the estimator but also on the closed-loop operating conditions generated by the underlying controller.
Figure 3 compares the nominal and adaptive prediction errors, the supervised evolution of the estimated static gain, and the cumulative accepted and rejected update events. Although all final accepted models satisfied the prescribed stability requirements, the C1 RMSE remained above the corresponding nominal-model RMSE for every control base. C1 therefore supported the supervisory component of H3 by demonstrating stable, traceable, and selective update screening, but it did not support the proposition that online adaptation necessarily improves prediction under the limited drift represented in the campaign. The findings confirm that model admissibility is a necessary safety condition but not evidence of predictive or closed-loop benefit.
4.6. Temporal Comparison Between C0 and C3
Figure 4 presents a representative block from the confirmatory comparison. C0 reached the holding region with greater overshoot and a more prolonged subsequent thermal excursion. In contrast, C3 reduced power before reaching the setpoint and maintained the product temperature within a narrower band during the holding stage. This visual difference is consistent with the purpose of MPC: to use the fixed nominal ARX model to anticipate the effect of heating power, respect constraints, and avoid delayed corrective actions.
The actuator signal complements the thermal interpretation. C0 maintained high saturation during an important fraction of the batch and then required an abrupt corrective action. C3 applied a progressive power reduction, sustained low levels during holding, and avoided persistent saturation. The improvement did not arise from re-identifying the model during the comparison; the model used by C3 was the previously selected nominal ARX model with fixed parameters. Therefore, the representative block confirms the methodological separation among identification, tuning, and comparison.
4.7. Overall Performance Indicators
Table 10 summarizes the mean performance indicators for batches not used for identification. These values are descriptive; confirmatory interpretation is reserved for paired block differences. C0 registered a mean RMSE of 3.207 °C, IAE of 8886 °C s, specific energy consumption of 0.0926 kWh/kg, and saturation of 45.51%. C3 reduced these values to 1.235 °C, 1025 °C s, 0.0834 kWh/kg, and 0% saturation. The simultaneous reduction in tracking error, overshoot, specific energy consumption, and saturation constitutes the clearest descriptive evidence in favor of C3.
C2 showed a slight RMSE reduction relative to C0, but it did not sustain an overall improvement. Its IAE, specific energy consumption, and
were higher than those of C0, suggesting that supervised PI self-tuning did not transform the process response robustly enough under slow drift. C4 showed the lowest descriptive RMSE, 1.227 °C, and the lowest descriptive IAE, 1005 °C s; however, its specific energy consumption and
were higher than those of C3, as shown in
Table 10 and
Figure 5. This difference is important for H5: the adaptive extension may marginally improve tracking, but it introduces additional actuator activity and should not be presented as conclusively superior.
4.8. Paired Confirmatory Comparison C3-C0
The confirmatory analysis used five matched blocks, each contributing one batch-level observation for C3 and one for C0. Thus, inference was based on five paired differences rather than on the temporal samples recorded during controller execution.
Table 11 reports controller-specific variability, paired differences, relative changes, 95% confidence intervals, small-sample-corrected paired effect sizes, Holm-adjusted
-values, and directional consistency across blocks.
C3 reduced RMSE by 1.959 °C, IAE by 7801 °C s, and specific energy consumption by 0.0081 kWh/kg, corresponding to relative reductions of 61.3%, 88.3%, and 8.6%, respectively. All five paired blocks favored C3 for RMSE and IAE, and all five blocks also favored C3 for specific energy consumption. The energy outcome showed greater relative between-block variability than the tracking indicators. Because RMSE and IAE originated from the same error trajectory, IAE was treated as complementary accumulated-error evidence rather than as an independent confirmation. Overall, the improved temperature regulation was not achieved through greater specific energy use.
Additional engineering indicators are reported in
Table A1. Relative to C0, C3 reduced actuator total variation by 64.9%, overshoot by 97.0%, time outside the admissible band by 86.7%, and thermal overexposure by 99.6%, while eliminating persistent actuator saturation. The optimization remained feasible at all evaluated control instants.
Thermal overexposure was not interpreted as microbiological equivalent lethality. The reported values of 4738 °C s for C0 and 21 °C s for C3 represent mean-temperature degree–time exposure above the control reference. Their difference of 4717 °C s indicates substantially lower controller-induced thermal excess, but it cannot be converted uniquely into , which depends exponentially on the complete temperature trajectory. Moreover, is referenced to 121.1 °C with °C and is not the appropriate primary microbiological measure for the evaluated 65 °C pasteurization treatment. Target-specific pasteurization values would require validated - and -values and were not used as confirmatory evidence.
Figure 6 shows the paired-block results for RMSE, IAE, and specific energy consumption. The tracking improvement was directionally consistent and was not attributable to a single batch, whereas specific energy consumption exhibited greater dispersion while retaining a mean difference favoring C3. The paired design preserved correspondence between batches operated under matched conditions.
4.9. Secondary and Exploratory Comparisons
C2 and C4 addressed different contrasts and were therefore not combined into a single controller ranking. C2 was compared with C0 as a secondary evaluation of supervised PI retuning, whereas C4 was compared with C3 as an exploratory evaluation of adaptive versus nominal MPC. No paired C2–C3 inference was made.
Table 12 summarizes the direction and interpretation of the changes in RMSE, IAE, and specific energy consumption for both contrasts.
Relative to C0, C2 reduced RMSE by 0.0388 °C and saturation by 3.64 percentage points but increased IAE, specific energy consumption, and actuator activity. H3 therefore received partial support: supervised adaptation improved selected tracking and saturation indicators but did not provide an overall performance improvement under drift. The C1 results further showed that online updating requires supervision and rejection of inadmissible parameter estimates.
C4 marginally reduced RMSE and IAE relative to C3 while maintaining feasibility and computation time compatible with the control period. However, it increased specific energy consumption, , and thermal overexposure. C4 therefore did not provide a sufficiently balanced advantage to replace C3. Instead, the results support authorizing MPC adaptation only when its predictive or tracking benefit exceeds the associated increases in energy use and actuator activity.
4.10. Hypothesis Synthesis and Validity Domain
Table 13 synthesizes the hypothesis decisions within the experimentally represented domain. H1 received partial operational support because the hybrid framework combined physical plausibility with a stable, parsimonious, positive-gain ARX predictor, although energy closure was incomplete and alternative model architectures were not exhaustively compared. H2 was supported by the confirmatory C3–C0 results. H3–H5 received partial support because adaptation improved selected indicators but did not provide a consistently superior tracking–energy–actuator trade-off.
Overall, C3 was the preferred nominal predictive strategy for the evaluated pasteurizer, whereas C2 and C4 remained conditional supervised extensions rather than automatic replacements. These conclusions are limited to batches near the nominal fill condition, the installed sensing and actuation architecture, and the 65 °C/30 min milk recipe. Transfer to routine industrial operation requires further validation across broader operating conditions, including sensor and power-system behavior and direct product-quality and microbiological measurements. The operational holding criterion should not be interpreted as microbiological validation or sanitary certification.
5. Discussion
The findings support a process-specific identification–control workflow for a closed, stirred, energy-accumulating pasteurizer. The batch–jacket grey-box model and local ARX predictor played complementary roles, while the nominal constrained MPC–ARX improved tracking, energy use, actuator behavior, and thermal exposure relative to the fixed-parameter PI benchmark. These conclusions apply only to the experimentally represented domain and do not imply universal controller superiority, microbiological validation, or sanitary certification [
37,
38].
5.1. Interpretation of the Hybrid Grey-Box–ARX Framework
The batch–jacket grey-box model served as a physical and energy-plausibility layer rather than as a high-fidelity simulator. Its estimated thermal capacities and conductance provided interpretable initialization and validation bounds, whereas the relative energy-closure error of 0.234 ± 0.032 reflected unresolved heat losses, metallic thermal storage, power uncertainty, and simplified jacket dynamics. This use is consistent with hybrid approaches that preserve physical structure while estimating plant-specific thermal behavior from data [
8,
10,
14].
The selected ARX model (
,
, and
) was stable, parsimonious, and characterized by positive static gain. Its validation RMSE increased from 0.0499 °C at one step to 0.350 °C at 120 s and 1.413 °C in free simulation. Thus, it was adequate for measurement-corrected receding-horizon prediction in the approach and holding region, but not for the complete batch cycle, rapid heating, cooling, or untested operating modes [
30,
32,
33]. The hybrid framework therefore combined physical interpretability with local predictive capacity without claiming that either model reproduced all plant dynamics.
5.2. Control Performance, Literature Positioning, and Benchmark Scope
In the five paired blocks, C3 reduced RMSE by 1.959 °C, IAE by 7801 °C s, specific energy consumption by 0.0081 kWh/kg, and actuator saturation by 44.46 percentage points relative to C0. Overshoot, time outside the admissible band, actuator activity, and thermal overexposure were also reduced. Because tracking improved while energy use and actuator effort decreased, the benefit was not obtained through more aggressive heating. Rather, the predictor allowed earlier power reduction near the setpoint and limited delayed corrective action in the high-inertia batch.
These findings complement MPC studies in continuous HTST pasteurization, plate-heat-exchanger plants, and simulation-based multivariable milk pasteurization [
34,
35,
36], as well as applications to continuous-flow ohmic heating, extrusion, and drying [
3,
5,
6]. Those systems involve continuous transport, outlet-temperature dynamics, direct heating, or multistate flow behavior. The present contribution is therefore methodological and process-specific: it integrates a batch-specific physical layer, a locally validated ARX predictor, measured active power, three-sensor spatial supervision, explicit adaptive-update gates, and paired batch-level evaluation. It does not propose a new general MPC algorithm.
The C3–C0 comparison was an industrial benchmark rather than a complexity-matched contest. C0 included anti-windup, saturation, input-rate limitation, and bumpless transfer, and both controllers used the same reference, sensors, control period, actuator limits, and paired-block protocol. The results therefore quantify the incremental benefit of prediction and explicit constraint handling over this fixed-parameter PI baseline, but not superiority over gain-scheduled PI, nonlinear PID, robust MPC, or nonlinear MPC.
NMPC could extend the validity domain by representing temperature- and mode-dependent dynamics, but it would require an independently validated nonlinear model, state or disturbance estimation, repeated numerical integration, and nonlinear optimization. It may also be more sensitive to initialization, solver tolerances, model mismatch, and fallback design. By contrast, C3 solved a quadratic program in approximately 6.4 ms within a 5 s control period. A fair future comparison should evaluate PI, gain-scheduled or nonlinear PI, linear MPC, and NMPC under common batches, constraints, objectives, measurements, and fallback rules, while reporting calibration effort, feasibility, computation time, and mismatch sensitivity.
5.3. Interpretation and Limits of Supervised Adaptation
The adaptive strategies addressed different contrasts: C2 was evaluated against C0, whereas C4 was evaluated against C3. Neither provided a sufficiently balanced improvement to replace nominal MPC. C1 further showed that all final accepted models remained stable, although adaptive prediction RMSE exceeded that of the nominal ARX model for every control base. Model admissibility and performance benefit were therefore distinct outcomes.
Several mechanisms explain this result. First, the nominal model already had low local prediction error and the campaign represented limited drift, so any reduction in bias may have been smaller than the additional variance introduced by RLS. Second, closed-loop regulation, actuator constraints, and operation near the holding setpoint reduced persistent excitation and increased regressor correlation. Third, RLS minimized one-step error, whereas controller performance depended on multihorizon prediction, batch-level tracking, energy use, actuator activity, and thermal overexposure. Sensor noise, spatial variation, correlated residuals, and unmodeled jacket dynamics could therefore appear as parameter drift [
44].
These mechanisms affected C2 and C4 differently. In C2, changes in estimated gain or dynamics altered PI tuning, producing a slight RMSE and saturation improvement but higher IAE, energy use, and actuator activity. In C4, parameter updates changed the prediction matrices and power sequence; RMSE and IAE improved marginally, but specific energy consumption, actuator variation, and thermal overexposure increased. Thus, adaptation was not uniformly detrimental, but its tracking benefit did not compensate for the wider operational trade-offs [
32,
33,
45].
The supervisory gate rejected invalid, insufficiently excited, ill-conditioned, unstable, physically inadmissible, discontinuous, saturated, spatially inconsistent, or energy-inconsistent updates. It was a safety and model-admissibility filter, not a prospective performance selector. Future authorization should therefore add persistent-mismatch detection, a minimum dwell time, recent-window multihorizon validation, and a performance gate based on a tracking–energy–actuator criterion. Until such conditions are demonstrated, C1 should remain an observer and C3 the default controller.
The fixed-dimensional ARX update also cannot separate slow physical drift from nonlinear or temporally correlated residual dynamics. Hierarchical adaptive estimation and congealed neural-network structures offer conceptual alternatives by separating slowly varying uncertainty from nonlinear residual compensation [
49,
50,
51]. However, their direct application would require a new process model, stability and constraint analysis, additional sensing or state estimation, computational verification, and independent experiments; they motivate future development rather than validate the present ARX–RLS implementation.
5.4. Energy Use, Thermal Exposure, and Industrial Relevance
The simultaneous reductions in error, specific energy consumption, saturation, and actuator activity indicate that C3 used thermal energy more selectively. At the mean batch mass of 257.29 kg, the measured reduction of 0.0081 kWh/kg corresponds to approximately 2.08 kWh per batch. Lower total variation and elimination of persistent saturation may also reduce unnecessary switching and improve power-use traceability.
Thermal overexposure and microbial lethality must nevertheless remain distinct. The former is a linear degree–time measure above the controller reference, whereas equivalent lethality weights the complete temperature trajectory exponentially using a target-specific reference temperature and -value. Consequently, the 99.6% reduction in thermal overexposure cannot be converted through a universal factor into an equivalent reduction in lethality or microbial log reduction. The reported indicator was also based on mean product temperature, while conservative lethality assessment requires a validated cold-point trajectory.
Likewise,
is referenced to 121.1 °C with
°C and is principally a sterilization metric, not the appropriate primary microbiological criterion for the evaluated 65 °C milk treatment. A target-specific pasteurization value requires validated
- and
-values, an appropriate reference temperature, and cold-point verification. The observed reduction should therefore be interpreted as lower controller-induced thermal excess, with possible energy and quality implications, not as evidence of microbial safety or sanitary certification [
2,
37].
Using the illustrative Quito energy-charge range, the measured reduction represents approximately USD 0.13–0.27 per batch and USD 131–274 over 1000 equivalent batches; the corresponding avoided emissions are approximately 0.70 kg CO
2-eq per batch and 0.70 t CO
2-eq over 1000 batches [
52,
53]. These are order-of-magnitude scenarios, not validated scale-up or life-cycle results. Actual benefits depend on tariff and demand charges, production frequency, geometry, heating efficiency, utility integration, capital and maintenance requirements, and preservation of the specific reduction at larger scale.
5.5. Robustness, Transferability, and Validity Limits
Within the observed batch-mass and initial-temperature strata, the fixed nominal predictor retained stable, positive-gain behavior and comparable 1-step and 24-step accuracy without re-estimation. Errors increased in free simulation, confirming that mismatch accumulated without measurement correction. The offline stress test extended this assessment by applying data-derived parameter, actuator-gain, delay, measurement, and correlated-residual uncertainty only to the simulated plant while retaining the C3 model and tuning.
Across 400 realizations, optimization remained feasible at all control instants, holding was achieved in all realizations, trajectories remained bounded, and neither saturation nor fallback activation occurred. Mean RMSE increased from 1.451 °C nominally to 1.650 °C under parameter uncertainty and 1.615 °C under combined uncertainty and disturbances; external disturbances alone produced only a small change to 1.454 °C. Parameter uncertainty therefore had the larger aggregate effect, although the design did not support ranking individual uncertainty sources. Receding-horizon feedback and input constraints plausibly limited error accumulation but could not compensate indefinitely for large gain or delay errors, severe disturbances, or operation outside the locally identified region.
C3 remains a nominal MPC: it does not use invariant tubes, min–max optimization, chance constraints, or formal uncertainty propagation. The findings demonstrate empirical tolerance within the observed and data-derived uncertainty region, not robust stability or guaranteed worst-case constraint satisfaction. Explicit guarantees would require, for example, constraint tightening, disturbance-state augmentation, gain-scheduled predictors, or tube-based, min–max, or stochastic MPC.
Transferability applies to the workflow rather than to the identified parameters. For a similar closed, stirred, indirectly heated jacketed vessel, the conservation structure may be retained, but thermal capacities, conductance, heat losses, actuator mapping, delay, sensor dynamics, ARX coefficients, constraints, and tuning must be recalibrated and independently validated. Capacity changes require reparameterization rather than proportional scaling because thermal mass, heat-transfer area, surface-to-volume ratio, circulation, and actuator effectiveness do not scale uniformly. Direct-steam, spray, immersion, rotating, pressurized, or continuous systems require partial or complete reconstruction of the physical and predictive models.
Table A4 summarizes the relative engineering effort; monetary costs and person-hours were not measured.
The principal validity limitation is that batches were concentrated near nominal fill and all confirmatory comparisons used milk with the 65 °C/30 min recipe. The study did not cover the complete 150–250 L range, other recipes or formulations, severe faults, or substantially altered heat transfer, and the local predictor should not be extrapolated to rapid heating, cooling, or transitions. Statistical generalization is also restricted by five paired confirmatory blocks, although treating the batch as the experimental unit avoided temporal pseudoreplication. Finally, the benchmark was not complexity matched, and no direct microbiological, sensory, physicochemical, or nutritional validation was performed. These restrictions delimit, but do not invalidate, the within-domain comparison.
5.6. Practical Implications and Future Work
Implementation should follow a staged sequence: verify instrumentation, active power, synchronization, agitation, and spatial uniformity; calibrate the batch–jacket grey-box model as a plausibility layer; identify and independently validate the local ARX predictor under safe excitation; and evaluate controllers under common references, constraints, sampling, sensors, and exclusion rules. Within the validated domain, C3 should remain the primary predictive strategy, with C1 operating as an observation layer before any adaptive controller is authorized.
Future blocked campaigns should cover predefined fill levels, initial temperatures, product-specific recipes, agitation and heat-transfer degradation, sensor and actuator uncertainty, and longer operation. They should combine model-validation, feasibility, tracking, energy, actuator, spatial-uniformity, microbiological, product-quality, and metrological outcomes. Broader operation could then be assigned to a common model, gain-scheduled local models, supervised re-identification, or an explicitly robust controller.
Further work should also compare linear MPC with gain-scheduled PI and NMPC under common experimental conditions and conduct plant-specific techno-economic and environmental assessment. A longer-term extension is a hierarchical robust adaptive architecture combining nominal MPC, supervised estimation of slow physical drift, bounded residual-dynamics compensation, independent safety and performance authorization, and fallback control [
49,
50]. Such an architecture requires process-specific stability analysis, explicit constraint treatment, computational verification, and experimental validation.
6. Conclusions
This study developed and experimentally evaluated a traceable hybrid grey-box–ARX identification and constrained-control workflow for a 250 L jacketed batch milk pasteurizer. The plant was treated as a closed, stirred, energy-accumulating batch system rather than as a continuous HTST process. This distinction determined the model structure, signal selection, interpretation of thermal holding, and use of the complete batch—not temporally correlated samples—as the experimental and statistical unit.
The batch–jacket grey-box model and local ARX predictor served complementary purposes. The grey-box model provided physical interpretation, energy-consistency bounds, and parameter initialization, whereas the selected , , and ARX structure supplied a stable, parsimonious, positive-gain predictor for the approach and holding region. Its low one-step error supported receding-horizon control, while the increase in multihorizon and free-simulation errors confirmed that the model should not be extrapolated to the complete batch cycle, rapid transitions, cooling, or untested operating modes.
In five paired confirmatory blocks, C3, the nominal constrained MPC–ARX strategy, improved performance relative to the fixed-parameter PI controller with anti-windup. C3 reduced RMSE by 1.959 °C, IAE by 7801 °C s, and specific energy consumption by 0.0081 kWh/kg. It also reduced overshoot, time outside the admissible band, actuator activity, saturation, and thermal overexposure. Optimization remained feasible at all evaluated experimental control instants, with a mean solution time of approximately 6.4 ms within the 5 s control period. C3 was therefore the preferred predictive strategy within the evaluated domain. This conclusion is restricted to the fixed-parameter PI benchmark used in the paired campaign and does not establish superiority over gain-scheduled PI, nonlinear control, robust MPC, or NMPC.
Supervised adaptation provided diagnostic and exploratory value but did not establish an overall advantage over the nominal model and controller. C1 screened ARX–RLS updates for data eligibility, excitation, conditioning, stability, physical admissibility, parameter continuity, and energy consistency, yet accepted updates did not systematically improve prediction. C2 and C4 produced limited improvements in selected tracking indicators but introduced unfavorable trade-offs in accumulated error, energy use, actuator activity, or thermal overexposure. Adaptation should therefore remain a conditional extension rather than an automatic replacement for C3. Under the limited drift and closed-loop excitation represented in the campaign, the potential reduction in model bias was insufficient to offset estimation variability and the propagation of parameter changes into controller behavior.
The within-domain assessment and data-derived stress test provided additional evidence that C3 tolerated the represented parameter, actuator-gain, delay, measurement, and correlated-disturbance variations while maintaining feasible and bounded closed-loop operation and attaining the valid holding condition. However, C3 remains a nominal MPC; these results demonstrate empirical tolerance to model–plant mismatch within the evaluated uncertainty region, not formal robust stability or guaranteed worst-case constraint satisfaction. Likewise, the reduction in degree–time thermal overexposure indicates lower controller-induced thermal excess but is not equivalent to a reduction in accumulated microbial lethality. Target-specific lethality requires a validated cold-point trajectory and appropriate reference-temperature, -value, and -value information. No microbial log-reduction, -based sterilization, product-quality, or sanitary-certification claim is therefore inferred.
The conclusions are limited to the evaluated pasteurizer, batches concentrated near nominal fill, the installed sensing and actuation chain, and the 65 °C/30 min milk recipe. The complete 150–250 L fill range, alternative products and recipes, severe faults, and substantially different heat-transfer conditions were not experimentally validated. Transferability consequently applies to the workflow rather than to direct reuse of plant-specific parameters: similar jacketed vessels require parameter recalibration, ARX re-identification, controller retuning, robustness assessment, and independent closed-loop validation, whereas different heating or transport architectures require partial or complete model reconstruction. Future blocked campaigns should extend validation across predefined fill levels, recipes, disturbances, and longer operating periods; incorporate direct microbiological and product-quality measurements; compare linear MPC with gain-scheduled PI and NMPC under common conditions; and conduct plant-specific techno-economic and environmental assessments. More advanced hierarchical or neural robust adaptive structures should be considered only after process-specific stability, constraint, computational, and experimental validation.