Engineering PapersSearch

Engineering topics

Spirkovska, Lilly

Publications and source records attributed to Spirkovska, Lilly.

At least 19 records

Architecture and Information Requirements to Assess and Predict Flight Safety Risks During Highly Autonomous Urban Flight Operations

As aviation adopts new and increasingly complex operational paradigms, vehicle types, and technologies to broaden airspace capability and efficiency, maintaining a safe system will require recognition and timely mitigation of new safety issues as they emerge and before significant consequences occur. A shift toward a more predictive risk mitigation capability becomes critical to meet this challenge. In-time safety assurance comprises monitoring, assessment, and mitigation functions that proactively reduce risk in complex operational environments where the interplay of hazards may not be known (and therefore not accounted for) during design. These functions can also help to understand and predict emergent effects caused by the increased use of automation or autonomous functions that may exhibit unexpected non-deterministic behaviors. The envisioned monitoring and assessment functions can look for precursors, anomalies, and trends (PATs) by applying model-based and data-driven methods. Outputs would then drive downstream mitigation(s) if needed to reduce risk. These mitigations may be accomplished using traditional design revision processes or via operational (and sometimes automated) mechanisms. The latter refers to the ‘in-time’ aspect of the system concept. This report comprises architecture and information requirements and considerations toward enabling such a capability within the domain of low altitude highly autonomous urban flight operations. This domain may span, for example, public-use surveillance missions flown by small unmanned aircraft (e.g., infrastructure inspection, facility management, emergency response, law enforcement, and/or security) to transportation missions flown by larger aircraft that may carry passengers or deliver products. Caveat: Any stated requirements in this report should be considered initial requirements that are intended to drive research and development (R&D). These initial requirements are likely to evolve based on R&D findings, refinement of operational concepts, industry advances, and new industry or regulatory policies or standards related to safety assurance.

Young, Steven

Real-Time Monitoring and Prediction of Airspace Safety

The U.S. National Airspace System (NAS) has reached an extremely high level of safety in recent years. However, it will only become more difficult to maintain the current level of safety with the forecasted increase in operations, and so the FAA has been making revolutionary changes to the NAS to both expand capacity and ensure safety. Our work complements these efforts by developing a novel model-based framework for real-time monitoring and prediction of the safety of the NAS. Our framework is divided into two parts: (offline) safety analysis and modeling part, and a real-time (online) monitoring and prediction of safety. The goal of the safety analysis task is to identify hazards to flight (distilled from several national databases) and to codify these hazards within our framework such that we can monitor and predict them. From these we define safety metrics that can be monitored and predicted using dynamic models of airspace operations, aircraft, and weather, along with a rigorous, mathematical treatment of uncertainty. We demonstrate our overall approach and highlight the advantages of this approach over the current state-of-the-art through simulated scenarios.

safety metrics

A Markov Decision Process Framework for Optimal Airport Reconfiguration

The airport runway configuration is defined as a combination set of runways for arrivals and departures used at a point during operation of the airport. An optimal configuration of these runways depends on a number of factors, including traffic demand, wind magnitude and direction, other adverse weather conditions, and noise restrictions, among others. Based on the current state of these factors and predictions of traffic demand and weather conditions, runway configuration changes are made and coordinated between tower controller, other air traffic control facilities, pilots, and ground personnel. Reconfigurations can be quite disruptive to airport operations; minimizing their frequency and scheduling them well in advance is essential for mitigating some of the added workload for controllers and pilots. Unfortunately, deciding on an appropriate time to change is challenging for human decision makers. Not only do multiple factors need to be evaluated, but the uncertainty in their forecasts must also be considered. Previous optimization methods, such as mixed linear integer programming, have been proposed. Although these methods can reason over a large set of variables, they do not systematically handle the uncertainty associated with weather movement, traffic demands, and other variables. In this work, we introduce a Markov Decision Process (MDP)-based decision making framework which can reason effectively over the inherent uncertainties and make optimal decisions on if/when to change the airport configuration. In a prototype implementation, we present a single runway with three aircraft and utilize knowledge of the forecasted wind speed and direction to determine whether to keep or change the current runway configuration. Our aim through this work is to present a framework for airport reconfiguration which can be scalable to additional aircraft, multiple runways, and various input parameters. This technique will optimize the airport reconfiguration procedure by providing a proactive approach, optimizing not just at the next optimal opportunity for a reconfiguration based on varying atmospheric and traffic conditions in the terminal airspace, but also anticipating future necessary reconfigurations. This will eliminate the inefficiencies of frequent changes currently associated with runway reconfiguration procedures.

runway reconfiguration

Identification of Safety Metrics for Airport Surface Operations

A large fraction of safety incidents occurs on the ground during airport surface operations. Although these incidents are mostly non-fatal with a few exceptions, they are high profile incidents that remain a source of concern for the National Transportation Safety Board (NTSB), the Federal Aviation Administration (FAA), major airlines, and other stakeholders of the National Airspace System (NAS). These incidents have historically been mitigated by implementing changes to regulations, policies, and procedures over time. This approach has minimized but not eliminated the risk of occurrences. It is thus important to develop integrated techniques to assess, model, and prevent these incidents by analyzing the risk and likelihood of occurrence and communicating results of the analysis to decision-making personnel who can mitigate and prevent incidents in real time. The research presented in this report builds on prior work of researchers at the NASA Ames Research Center who developed an automated framework, Real-Time Safety Monitoring (RTSM), to enable monitoring and prediction of the safety of the NAS. In the RTSM framework, hazards to flight are translated to safety metrics such as wake vortex encounters or loss of separation, that can be modeled and analyzed offline and also predicted and monitored in real time (online). The intent of this report is to integrate predictable incidents that occur during surface and ground operations into the safety portfolio of the RTSM project by (i) identifying suitable information sources from which ground incidents can be studied, (ii) developing safety metrics correlated with surface operations, and (iii) recommending suitable data sources that can be quantified and used for the computation of pertinent safety metrics.

ground operations

Dynamic Routing of Aircraft in the Presence of Adverse Weather Using a POMDP Framework

Each year weather-related airline delays result in hundreds of millions of dollars in additional fuel burn, maintenance, and lost revenue, not to mention passenger inconvenience. The current approaches for aircraft route planning in the presence of adverse weather still mainly rely on deterministic methods. In contrast, this work aims to deal with the problem using a Partially Observable Markov Decision Processes (POMDPs) framework, which allows for reasoning over uncertainty (including uncertainty in weather evolution over time) and results in solutions that are more robust to disruptions. The POMDP-based decision support system is demonstrated on several scenarios involving convective weather cells and is benchmarked against a deterministic planning system with functionality similar to those currently in use or under development.

Decision making

Real-Time Prediction of Safety Margins in the National Airspace

Underlying all operations in the National Airspace System (NAS) is the concept of safety. Safety, as defined by acceptable levels of risk, is to be maintained at all times. The real-time safety monitoring (RTSM) framework is under development to provide an automated system to quantify safety in the NAS, estimate the current level of safety, and predict the future evolution of safety and the occurrence of events that pose an increased risk to flights so that these occurrences can be managed strategically rather than mitigated reactively. This paper presents the mathematical framework, the models, and the monitoring and prediction algorithms used to achieve this. RTSM computes safety as expressed through a set of safety margins based on user-defined safety metrics, thresolds, and events. Sources of uncertainty are modeled and propagated through the predictions in order to compute the probabilistic evolution of safety and the probability of events that introduce increased risk to operations. A prototype implementation is discussed and results demonstrating feasibility are presented. The results highlight the kinds of predictions that can be computed and the fidelity that is currently achieved.

national airspace system

Real Time Safety Monitoring: Concept for Supporting Safe Flight Operations

A number of organizations are working on processes, procedures, regulations, and technologies to maintain or improve the safety of the National Airspace System (NAS). In this paper, we describe a Real Time Safety Monitoring (RTSM) system that benefits from these efforts to define a set of safety metrics that are automatically monitored in real-time. In addition to providing information about current potentially adverse conditions to a variety of users, from those who need a broad overview of a day's flight operations to those who need to decide on a control tactic to employ in the next five minutes, the RTSM system predicts conditions within a specified prediction horizon. Its intelligent interface alerts the user, presenting the information as appropriate considering the current context and circumstances. We illustrate the system concept with five conceptual use cases, describing which safety metrics may be of the most interest to five user groups and suggesting a multi-modal display format. We posit that having access to information about adverse conditions in time to make efficient preemptive decisions without sacrificing safety will improve the already high level of safety and aid in the expansion planned for the NAS under the Next Generation Air Transportation System (NextGen).

safety

Initial Demonstration of the Real-Time Safety Monitoring Framework for the National Airspace System Using Flight Data

As new operational paradigms and additional aircraft are being introduced into the National Airspace System (NAS), maintaining safety in such a rapidly growing environment becomes more challenging. It is therefore desirable to have an automated framework to provide an overview of the current safety of the airspace at different levels of granularity, as well an understanding of how the state of the safety will evolve into the future given the anticipated flight plans, weather forecast, predicted health of assets in the airspace, and so on. Towards this end, as part of our earlier work, we formulated the Real-Time Safety Monitoring (RTSM) framework for monitoring and predicting the state of safety and to predict unsafe events. In our previous work, the RTSM framework was demonstrated in simulation on three different constructed scenarios. In this paper, we further develop the framework and demonstrate it on real flight data from multiple data sources. Specifically, the flight data is obtained through the Shadow Mode Assessment using Realistic Technologies for the National Airspace System (SMART-NAS) Testbed that serves as a central point of collection, integration, and access of information from these different data sources. By testing and evaluating using real-world scenarios, we may accelerate the acceptance of the RTSM framework towards deployment. In this paper we demonstrate the framework's capability to not only estimate the state of safety in the NAS, but predict the time and location of unsafe events such as a loss of separation between two aircraft, or an aircraft encountering convective weather. The experimental results highlight the capability of the approach, and the kind of information that can be provided to operators to improve their situational awareness in the context of safety.

Real-time Safety Monitoring

From Diagnosis to Action: An Automated Failure Advisor for Human Deep Space Missions

The major goal of current space system development at NASA is to enable human travel to deep space locations such as Mars and asteroids. At that distance, round trip communication with ground operators may take close to an hour, thus it becomes unfeasible to seek ground operator advice for problems that require immediate attention, either for crew safety or for activities that need to be performed at specific times for the attainment of scientific results. To achieve this goal, major reliance will need to be placed on automation systems capable of aiding the crew in detecting and diagnosing failures, assessing consequences of these failures, and providing guidance in repair activities that may be required. We report here on the most current step in the continuing development of such a system, and that is the addition of a Failure Response Advisor. In simple terms, we have a system in place the Advanced Caution and Warning System (ACAWS) to tell us what happened (failure diagnosis) and what happened because that happened (failure effects). The Failure Response Advisor will tell us what to do about it, how long until something must be done and why its important that something be done and will begin to approach the complex reasoning that is generally required for an optimal approach to automated system health management. This advice is based on the criticality and various timing elements, such as durations of activities and of component repairs, failure effects delay, and other factors. The failure advice is provided to operators (crew and mission controllers) together with the diagnostic and effects information. The operators also have the option to drill down for more information about the failure and the reasons for any suggested priorities.

spacecraft health maintenance

Determining Mission Effects of Equipment Failures

NASA plans call for long duration deep space missions with human crews. Because of light-time delay and other considerations, increased autonomy is needed. Crews on next-generation missions will likely be small, perhaps with as few as four members. A small crew is not likely to possess the full range of expertise needed to deal with unexpected failures and anomalies. Applied artificial intelligence technologies have developed decision support tools with the potential to fill the gap, but these tools need to be integrated to provide a smooth operational capability. In this paper we describe such an integration involving anomaly detection, diagnosis, system effect propagation, and plan repair.

Morris, Paul

Putting Integrated Systems Health Management Capabilities to Work: Development of an Advanced Caution and Warning System for Next-Generation Crewed Spacecraft Missions

Integrated System Health Management (ISHM) technologies have advanced to the point where they can provide significant automated assistance with real-time fault detection, diagnosis, guided troubleshooting, and failure consequence assessment. To exploit these capabilities in actual operational environments, however, ISHM information must be integrated into operational concepts and associated information displays in ways that enable human operators to process and understand the ISHM system information rapidly and effectively. In this paper, we explore these design issues in the context of an advanced caution and warning system (ACAWS) for next-generation crewed spacecraft missions. User interface concepts for depicting failure diagnoses, failure effects, redundancy loss, "what-if" failure analysis scenarios, and resolution of ambiguity groups are discussed and illustrated.

integrated system management

Advanced Caution and Warning System, Final Report - 2011

The work described in this report is a continuation of the ACAWS work funded in fiscal year (FY) 2010 under the Exploration Technology Development Program (ETDP), Integrated Systems Health Management (ISHM) project. In FY 2010, we developed requirements for an ACAWS system and vetted the requirements with potential users via a concept demonstration system. In FY 2011, we developed a working prototype of aspects of that concept, with placeholders for technologies to be fully developed in future phases of the project. The objective is to develop general capability to assist operators with system health monitoring and failure diagnosis. Moreover, ACAWS was integrated with the Discrete Controls (DC) task of the Autonomous Systems and Avionics (ASA) project. The primary objective of DC is to demonstrate an electronic and interactive procedure display environment and multiple levels of automation (automatic execution by computer, execution by computer if the operator consents, and manual execution by the operator).

Spirkovska, Lilly

Advanced Caution and Warning System

The current focus of ACAWS is on the needs of the flight controllers. The onboard crew in low-Earth orbit has some of those same needs. Moreover, for future deep-space missions, the crew will need to accomplish many tasks autonomously due to communication time delays. Although we are focusing on flight controller needs, ACAWS technologies can be reused for on-board application, perhaps with a different level of detail and different display formats or interaction methods. We expect that providing similar tools to the flight controllers and the crew could enable more effective and efficient collaboration as well as heightened situational awareness.

Spirkovska, Lilly

General Purpose Data-Driven Online System Health Monitoring with Applications to Space Operations

Modern space transportation and ground support system designs are becoming increasingly sophisticated and complex. Determining the health state of these systems using traditional parameter limit checking, or model-based or rule-based methods is becoming more difficult as the number of sensors and component interactions grows. Data-driven monitoring techniques have been developed to address these issues by analyzing system operations data to automatically characterize normal system behavior. System health can be monitored by comparing real-time operating data with these nominal characterizations, providing detection of anomalous data signatures indicative of system faults, failures, or precursors of significant failures. The Inductive Monitoring System (IMS) is a general purpose, data-driven system health monitoring software tool that has been successfully applied to several aerospace applications and is under evaluation for anomaly detection in vehicle and ground equipment for next generation launch systems. After an introduction to IMS application development, we discuss these NASA online monitoring applications, including the integration of IMS with complementary model-based and rule-based methods. Although the examples presented in this paper are from space operations applications, IMS is a general-purpose health-monitoring tool that is also applicable to power generation and transmission system monitoring.

Iverson, David L.

Anomaly Detection for Next-Generation Space Launch Ground Operations

NASA is developing new capabilities that will enable future human exploration missions while reducing mission risk and cost. The Fault Detection, Isolation, and Recovery (FDIR) project aims to demonstrate the utility of integrated vehicle health management (IVHM) tools in the domain of ground support equipment (GSE) to be used for the next generation launch vehicles. In addition to demonstrating the utility of IVHM tools for GSE, FDIR aims to mature promising tools for use on future missions and document the level of effort - and hence cost - required to implement an application with each selected tool. One of the FDIR capabilities is anomaly detection, i.e., detecting off-nominal behavior. The tool we selected for this task uses a data-driven approach. Unlike rule-based and model-based systems that require manual extraction of system knowledge, data-driven systems take a radically different approach to reasoning. At the basic level, they start with data that represent nominal functioning of the system and automatically learn expected system behavior. The behavior is encoded in a knowledge base that represents "in-family" system operations. During real-time system monitoring or during post-flight analysis, incoming data is compared to that nominal system operating behavior knowledge base; a distance representing deviation from nominal is computed, providing a measure of how far "out of family" current behavior is. We describe the selected tool for FDIR anomaly detection - Inductive Monitoring System (IMS), how it fits into the FDIR architecture, the operations concept for the GSE anomaly monitoring, and some preliminary results of applying IMS to a Space Shuttle GSE anomaly.

Spirkovska, Lilly

Usage of Fault Detection Isolation & Recovery (FDIR) in Constellation (CxP) Launch Operations

This paper will explore the usage of Fault Detection Isolation & Recovery (FDIR) in the Constellation Exploration Program (CxP), in particular Launch Operations at Kennedy Space Center (KSC). NASA's Exploration Technology Development Program (ETDP) is currently funding a project that is developing a prototype FDIR to demonstrate the feasibility of incorporating FDIR into the CxP Ground Operations Launch Control System (LCS). An architecture that supports multiple FDIR tools has been formulated that will support integration into the CxP Ground Operation's Launch Control System (LCS). In addition, tools have been selected that provide fault detection, fault isolation, and anomaly detection along with integration between Flight and Ground elements.

Ferrell, Rob

Operator Performance Evaluation of Fault Management Interfaces for Next-Generation Spacecraft

In the cockpit of the NASA's next generation of spacecraft, most of vehicle commanding will be carried out via electronic interfaces instead of hard cockpit switches. Checklists will be also displayed and completed on electronic procedure viewers rather than from paper. Transitioning to electronic cockpit interfaces opens up opportunities for more automated assistance, including automated root-cause diagnosis capability. The paper reports an empirical study evaluating two potential concepts for fault management interfaces incorporating two different levels of automation. The operator performance benefits produced by automation were assessed. Also, some design recommendations for spacecraft fault management interfaces are discussed.

Hayashi, Miwa