Engineering PapersSearch

Engineering topics

Natasha Neogi

Publications and source records attributed to Natasha Neogi.

At least 19 records

NASA System-Wide Safety Wildland Firefighting Operations Workshop Report

On March 9-11, 2022, NASA’s System-Wide Safety Wildland Firefighting Operations Workshop engaged the broader wildland firefighting management ecosystem in a safety-oriented discussion via a virtual platform. This enabled a better understanding of how NASA and community expertise can be leveraged in the safe development of current and future firefighting systems and operations. The goals of the workshop were to: (1) identify and prioritize the top safety-oriented risks, gaps in capabilities, and emerging technologies to enhance wildland firefighting for both near-term and far-term concepts, with a specific focus on aviation operations and (2) engage the stakeholder community in defining emergent safety-oriented scope, roles, responsibilities, and procedures for agents undergoing increasingly complex wildland firefighting operations in information-rich, but uncertain environments. Workshop participants were solicited from wildland firefighting stakeholders across government, industry, and academia. All levels of government were engaged, as NASA sought attendees from federal, state, local, and tribal government agencies. Industry participants from traditional wildland firefighting domains such as data visualization and equipment manufacturers were invited, and corporate attendees from novel application domains such as aerial robotics and autonomous systems were present as well. The top three findings were as follows: (1) Enhancing situation awareness is a safety priority, especially in the use of aerial assets; (2) Timely access to information along with data fusion and integrated displays will enhance safety-critical decision-making both inside and outside aviation contexts; and (3) Tailorable standards and common operating pictures in the field will enhance inter-agency cooperation in the wildland firefighting lifecycle and enable the optimal use of limited resources such as aerial assets. The workshop helped inform NASA of the relevant safety-related wildland firefighting concerns and aided the broader ecosystem in understanding the potential safety-oriented role NASA might play in this community. Increased engagement with crucial governmental stakeholders (e.g., U.S. Forest Service, CAL FIRE, etc.) along with industry partners in cutting- edge information -centric domains is a fundamental next step. Additionally, the workshop findings will help define the first of a series of operationally challenging demonstrations, held in concert with strategic ecosystem partners, known as the Safety Demonstrator Series for NASA’s System-Wide Safety project. The first demonstration is set in the wildland firefighting application domain and will: (1) examine high risk operational scenarios to reduce their overall risk via services, functions or capabilities that act as risk mitigators (or transfer that risk to automated systems better able to tolerate it) and (2) explore novel tools and technologies that will enhance safety margins by enabling non-traditional or neoteric operational paradigms.

wildland firefighting

Functional Hazard Assessment for the eVTOL Aircraft Supporting Urban Air Mobility (UAM) Applications: Exploratory Demonstrations

The active development community surrounding electric vertical takeoff and landing (eVTOL) aircraft has demonstrated potential to bring new technological capabilities to market, encouraging visions of widespread and diverse Urban Air Mobility (UAM) applications. New capabilities always come with safety considerations, some familiar and others less so. OEMs who intend to obtain FAA type certification for their eVTOL designs must plan for and execute sufficient safety engineering processes to demonstrate that credible hazards associated with these eVTOL designs are adequately mitigated. This work provides an orientation for eVTOL stakeholders, especially new entrants and those in hybrid roles, to the safety and regulatory context for assuring eVTOL aircraft for UAM applications. We further present selections of functional hazard assessment (FHA) performed on a reference eVTOL concept, with process and decision narration. The exercise allows exploration of several safety considerations specific to eVTOL systems and demonstrates the FHA process together with negotiation of some of its options and variations.

Hazard Analysis

Assuring Intelligent Systems: Contingency Management for UAS

Unmanned aircraft systems (UAS) collaborate with humans to operate in diverse, safety-critical applications. However, assurance technologies need to be integrated into the design process in order to guarantee safe behavior, thereby enabling UAS operations in the National Airspace System (NAS). In this paper, formal methods are integrated with learning-enabled systems representations. The generation and representation of knowledge are captured via monadic second-order logic rules in the cognitive architecture Soar. These rules are translated into timed automata, and a proof of correctness for the translation is provided so that safety and liveness properties can be checked in the formal verification environment Uppaal. This approach is agnostic to the learning mechanism used to generate the learned rules (e.g., chunking, etc.). An example of a fault-tolerant, learning-enabled UAS deciding which of four contingency procedures to execute under a lost link scenario while overflying an urban area is used to illustrate the approach.

Intelligent Systems

Decentralized Control Synthesis for Air Traffic Management in Urban Air Mobility

Urban air mobility (UAM) refers to air transportation services within an urban area, often in an on-demand fashion. We study air traffic management (ATM) for vehicles in a UAM fleet, while guaranteeing system safety requirements such as traffic separation. Existing ATM methods for unmanned aerial systems, such as UAS traffic management, utilize alternative approaches which do not provide strict safety guarantees. No established infrastructure exists for providing ATM at scale for UAM. We provide a decentralized, hierarchical approach for UAM ATM that allows for scalability to high traffic densities as well as providing theoretical guarantees of correctness with respect to user-provided safety specifications. Our main contributions are two-fold. First, we propose a novel UAM ATM architecture that divides the control authority between vertihubs that are each in charge of all UAM vehicles in their local airspace. Each vertihub also contains a number of vertiports that are in charge of UAM vehicle takeoffs and landings. The resulting architecture is decentralized and hierarchical, which not only enables scalability, but also robustness in the event of any individual vertihub or vertiport no longer being operational. Second, we provide a contract-based correct-by-construction reactive synthesis approach that provably guarantees safety properties with respect to user-provided specifications in linear temporal logic. We demonstrate the approach on large-volume UAM air traffic data.

Urban Air Mobility

Creating Formal Characterizations ofRoutine Contingency Management inCommercial Aviation

Traditional approaches to safety management focus on collection of data describing unwanted states (i.e., accidents and incidents) and analysis of undesired behaviors (i.e., faults and errors) that precede those states. Thus, in the traditional view of safety, safety is both defined and measured by its absence, namely the lack of safety. In extremely high confidence systems like commercial air transport, however, opportunities to measure the absence of safety are relatively rare. Ironically, a critical barrier to measuring safety and the impact of mitigation strategies in commercial aviation is the lack of opportunities for measurement.

Intelligent Contingency Management,

Creating Formal Characterizations of Routine Contingency Management in Commercial Aviation

The identification, modelling, and analysis of root causes of accidents and incidents dominate conventional safety management approaches. However, the effect of humans’ safety-producing behavior on the overall resilience of the system is often neglected. Additionally, emerging aviation markets are giving rise to concepts of operation, such as urban air mobility and optionally piloted air cargo operations, that are leading to a shift in locus of control between humans and automation. Without an understanding of the human contribution to safety, it is difficult to assess the effects of these novel role allocations on overall system safety. In this work, safety-producing behaviors are identified and abstracted into resilient performance strategies. Production rules that encapsulate these strategies are then generated and classified in the Soar cognitive architecture. The strategies are then applied to a remotely-operated air cargo example to demonstrate how safe learning is facilitated. The learned rules and strategies are then formally verified.

Safety Critical Systems

Minimum-Violation Traffic Management for Urban Air Mobility

Urban air mobility (UAM) refers to air transportation services in and over an urban area and has the potential to revolutionize mobility solutions. However, due to the projected scale of operations, current air traffic management (ATM) techniques are not viable. Increasingly autonomous systems are a pathway to accelerate the realization of UAM operations but must be fielded safely and efficiently. The heavily regulated, safety critical nature of aviation may lead to multiple, competing safety constraints that can be traded off based on the operational context. In this paper, we design a framework which allows for the scalable planning of a UAM ATM system. We formalize safety oriented constraints derived from FAA regulations by encoding them as temporal logic formulae. We then propose a method for UAM ATM that is both scalable and minimally violates the temporal logic constraints. Numerical results show that the runtime for our proposed algorithm is suitable for very large problems and is backed by theoretical guarantees of correctness with respect to given temporal logic constraints.

Urban Air Mobility

Assured Contingency Landing Management for Advanced Air Mobility

Advanced Air Mobility (AAM) is quickly developing as a new air transportation system that moves people and packages in the regions previously not / less served by the current aviation systems. Such AAM must operate safely despite the potential to encounter hazards and experience anomalies and failures in-flight. It becomes especially important to have systematic auto-mitigation strategies to perform safe contingency actions in AAM flight operations, as pilots have limited Situational Awareness (SA) and limited time to make prompt decisions when encountering failures/anomalies in high-density low altitude airspace. This paper presents Assured Contingency Landing Management (ACLM) with an online landing strategy selection to decide between the following three options when a contingency landing is required: (1) Return-to-launch landing site, (2) Land immediately at a nearby clear but unprepared site, (3) Land at a prepared landing site from the approximate footprint. Our presented algorithm shows a real-time auto-mitigation loop with multiple threads that run simultaneously to check controllability, reachability, and intermediate decisions to hold/ loiter or continue the flight plan as the landing strategy solution is being computed. Case study simulation is demonstrated with the safety-critical propulsion system and battery system and shows how different failure scenarios impact the landing strategy selection.

Autonomous Mitigation

Establishing the Assurance Efficacy of Automated Risk Mitigation Strategies

Verification and validation of increasingly autonomous aviation systems is a major challenge. Traditional techniques for the assurance of high-confidence, safety-critical systems are not equipped to handle the complexity, uncertainty, and lack of predictability inherent in non-deterministic systems. Techniques such as run time monitoring, formal methods, and testing and simulation have been applied to some effect, but it is difficult to properly assess the success of such measures. The authors propose the concept of Assurance Efficacy to address this gap. Assurance Efficacy is seen as a parameter, criteria, or perspective by which to evaluate, identify and explore safety risk mitigation strategies and operational assurance architectures. Validation of the utility of this concept through flight testing is a first step in determining its potential role in assessing the overall safety of complex, increasingly autonomous systems that cannot be fully assured in the design phase.

system safety

A High-Performance Computing GNSS-aware Path Planning Algorithm for Safe Urban Flight Operations

The emergence and development of advanced technologies and vehicle types have created a growing demand for new forms of flight operations. These new and increasingly complex operational paradigms, such as Advanced and Urban Air Mobility (AAM/UAM), present regulatory authorities and the aviation community with several design-and-implementation challenges – particularly for highly autonomous vehicles. An overarching and daunting task is to develop protocols that can integrate these operations without compromising safety or disrupting traditional airspace operations. A shift toward a more predictive, autonomous, risk mitigation capability becomes critical to meet this challenge. This paper proposes and evaluates a computationally-efficient path planning approach to perform pre-flight planning and autonomous in-flight re-routing to minimize exposures to selected hazards. In our evaluation, hazards associated with degraded and missing critical GPS navigation data are considered. In this paper, we first present a high-performance computing path planning approach based on an adapted Bellman-Ford algorithm, developed in the CUDA programming language. Using the adapted path planning algorithm, we test this algorithm when encountering issues with GPS quality, and deliver an implementation that can produce flight paths that minimize exposure to risks, while maintaining a low computational burden. In our evaluation, the computation of periodic and aperiodic path updates are evaluated, prioritizing specific events as triggers for updates, based on changes to satellite availability. These critical events can lead to significant exposure to navigational hazards if not dealt with correctly.

GNSS

A High-Performance Computing GNSS-aware Path Planning Algorithm for Safe Urban Flight Operations

The emergence and development of advanced technologies and vehicle types have created a growing demand for new forms of flight operations. These new and increasingly complex operational paradigms, such as Advanced and Urban Air Mobility (AAM/UAM), present regulatory authorities and the aviation community with several design-and-implementation challenges – particularly for highly autonomous vehicles. An overarching and daunting task is to develop protocols that can integrate these operations without compromising safety or disrupting traditional airspace operations. A shift toward a more predictive, autonomous, risk mitigation capability becomes critical to meet this challenge. This paper proposes and evaluates a computationally-efficient path planning approach to perform pre-flight planning and autonomous in-flight re-routing to minimize exposures to selected hazards. In our evaluation, hazards associated with degraded and missing critical GPS navigation data are considered. In this paper, we first present a high-performance computing path planning approach based on an adapted Bellman-Ford algorithm, developed in the CUDA programming language. Using the adapted path planning algorithm, we test this algorithm when encountering issues with GPS quality, and deliver an implementation that can produce flight paths that minimize exposure to risks, while maintaining a low computational burden. In our evaluation, the computation of periodic and aperiodic path updates are evaluated, prioritizing specific events as triggers for updates, based on changes to satellite availability. These critical events can lead to significant exposure to navigational hazards if not dealt with correctly.

GNSS