Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “System Resilience”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Novel Observing Strategies (NOS) and Earth System Digital Twins (ESDT) for Disaster Resilience

"Earth systems have now been observed continuously for more than 50 years, not only from space but also from airplanes, balloons and in-situ sensors. With the addition of commercial remote sensing providers, many more Internet-of-Things sensors and new NASA and international observatories being planned, these incredible amounts of data will soon be augmented by even larger amounts of diverse data and therefore will become more and more difficult to access, integrate, understand and utilize. At the same time, because of climate change and its impacts, in order to predict, manage, and mitigate the effects of extreme science events and disasters, the information produced by all of this data needs to be optimized, organized and analyzed in such a way that it can be utilized by traditional as well as many new non-traditional users. This calls for the development of observing systems that are agile, coordinated and responsive to events of interest, and for information systems to be dynamic, interactive and fast. With these objectives in mind, the Advanced Information Systems Technology (AIST) Program has been developing technologies that will allow for the development of Novel Observing Strategies (NOS) in a distributed, coordinated fashion (i.e., similar to an “Internet-of-Earth-Things”), as well as for the development of novel information systems or Earth System Digital Twins (ESDT) that will build a digital replica of the past and current states of the Earth systems, will derive forecasts of future states under nominal assumptions and will also offer the capability to investigate many hypothetical evolution scenarios under varying impact assumptions. Both NOS and ESDT will be facilitated by the unprecedented advances of Artificial Intelligence technologies, especially Machine Learning (ML), for extracting relevant information from these large amounts of data, for fusing and assimilating diverse data together and for running complex models faster. Together NOS and ESDT will help build the capabilities needed to anticipate, predict and mitigate the effects of future disasters."

Earth Science Remote Sensing; Information Systems↗

Autonomous System Technologies for Resilient Airspace Operations

Increasing autonomous systems within the aircraft cockpit begins with an effort to understand what autonomy is and developing the technology that encompasses it. Autonomy allows an agent, human or machine, to act independently within a circumscribed set of goals; delegating responsibility to the agent(s) to achieve overall system objective(s). Increasingly Autonomous Systems (IAS) are the highly sophisticated progression of current automated systems toward full autonomy. Working in concert with humans, these types of technologies are expected to improve the safety, reliability, costs, and operational efficiency of aviation. IAS implementation is imminent, which makes the development and the proper performance of such technologies, with respect to cockpit operation efficiency, the management of air traffic and data communication information, vital. A prototype IAS agent that attempts to optimize the identification and distribution of "relevant" air traffic data to be utilized by human crews during complex airspace operations has been developed.

Houston, Vincent E.↗

Role of Cyber-Physical Testing in Developing Resilient Extraterrestrial Habitats

Extraterrestrial long-term habitat systems (henceforth referred to as habitat systems) require groundbreaking technological advances to overcome the extreme demands introduced by isolation and challenging environments. A habitat system must operate as intended under continuous disruptive conditions. Designing for the demands that challenging environments will place on habitat systems (e.g., wild temperature fluctuations, galactic cosmic rays, destructive dust, meteoroid impacts, vibrations, and solar particle events) represents one of the greatest challenges in this endeavor. This engineering problem necessitates that we design and manage habitat systems to be resilient. System resilience requires a comprehensive approach that accounts for disruptions through the design process and adapts to them in operation. As the habitat system evolves—growing in physical size, complexity, population, and connectivity—and diversifies in operations, it must continue to be safe and resilient. In this endeavor, we should take advantage of lessons learned in developing civil infrastructure responsive to catastrophic natural hazards, autonomous robotics platforms, smart buildings, cyber-physical testing, complex systems, and diagnostics and prognostics for intelligent health management. This study highlights the importance of system resilience and cyber-physical testing to address the grand challenge of developing habitat systems.

Public health and safety↗

Extreme Problem Solving II: How Can 4 Astronauts do the Jobs of 80 Experts?

On past and present space missions, resilience is largely dependent on the problem-solving expertise of flight controllers at Mission Control on the ground. Missions to Mars will instead experience long communication delays and blackouts that require a small crew to detect, diagnose, and respond to critical events with only intermittent and limited real-time ground support. Our 2021 SpaceCHI paper “Extreme Problem Solving: The New Challenges of Deep Space Exploration” introduced the paradigm shift of increasingly Earth-independent mission operations and identified the capabilities that are not currently available on-board but will be needed to enable safe exploration beyond low-Earth orbit [1]. This paper investigates how the ground team achieves resilience today to inform what will be needed to achieve human-systems resilience on future long duration exploration missions – how can a crew of four generalists achieve the same outcomes as a team of 80+ experts? An actual ISS anomaly is analyzed and then reimagined under Mars transit conditions, to reveal critical decision-points and the onboard capabilities that will be needed for successful resolution. This paper also presents criteria for what makes urgent, unanticipated events so challenging to resolve.

human-systems integration architecture↗

Collaborative Communications Between a Human and a Resilient Safety Support System

Successful introductory UAM integration into the NAS will be contingent on resilient safety systems that support reduced-crew flight operations. In this paper, we present a system that performs three functions: 1) monitors an operator’s physiological state; 2) assesses when the operator is experiencing anomalous states; and 3) mitigates risks by a combination of dynamic, context-based unilateral or collaborative dynamic function allocation of operational tasks. The monitoring process receives high data-rate sensor values from eye-tracking and electrocardiogram sensors. The assessment process takes these values and performs a classification that was developed using machine learning algorithms. The mitigation process invokes a collaboration protocol called DFACC to which, based on context, performs vehicle operations that the operator would otherwise routinely execute. This system has been demonstrated in a UAM flight simulator for an operator incapacitation scenario. The methods and initial results as well as relevant UAM and AAM scenarios will be described.

Advanced Air Mobility,↗

Collaborative Communications Between A Human and A Resilient Safety Support System

Successful introductory UAM integration into the NAS will be contingent on resilient safety systems that support reduced-crew flight operations. In this paper, we present a system that performs three functions: 1) monitors an operator’s physiological state; 2) assesses when the operator is experiencing anomalous states; and 3) mitigates risks by a combination of dynamic, context-based unilateral or collaborative dynamic function allocation of operational tasks. The monitoring process receives high data-rate sensor values from eye-tracking and electrocardiogram sensors. The assessment process takes these values and performs a classification that was developed using machine learning algorithms. The mitigation process invokes a collaboration protocol called DFACCto which, based on context, performs vehicle operations that the operator would otherwise routinely execute. This system has been demonstrated in a UAM flight simulator for an operator incapacitation scenario. The methods and initial results as well as relevant UAM and AAM scenarios will be described.

Advanced air mobility↗

Playing a 3-Stringed Violin: Innovation via the Joint Evolution of People, Process, and Knowledge Management System

Users continuously evaluate the value and performance of their Knowledge Management Systems (KMS). As suggested by a punctuated socio-technical system process model, today's success can quickly become tomorrow's failure should the KMS fail to meet evolving needs and expectations. The more deeply a tool is embedded in the actual work process, the more vulnerable it is to emergent changes and perturbations. This paper uses the metaphor of a "3-stringed violin" to explore how differing levels of user knowledge about tools and processes can lead to system perturbations and how the active involvement of other actors can dampen the impact of perturbations, i.e., help the system survive the operational equivalent of a broken string. Recommendations suggest ways to increase system resiliency and contribute to incremental innovation.

Socio-technical systems↗

Medical System Requirements Development for Lunar Operations

The major health hazards of spaceflight include higher levels of damaging radiation, altered gravity, extended periods of isolation and confinement, a closed and potentially hostile living environment, and the stress associated with being a long distance from Earth. As we increase the duration of lunar stays with foreseeable communication latencies and disruptions, there will be a progressive need for crew to maintain their own health and independently respond to critical medical events. The Exploration Medical Capability element of the NASA Human Research Program is developing a set of Medical System requirements for lunar transit and surface operations. These requirements specify the capabilities, processes and procedures of a habitat Medical System needed for a range of conditions known to occur during spaceflight. Requirement text is written so as not to constrain innovative design solutions necessary for a resilient system. The requirement set includes attributes and functions the Medical System imposes on eight additional habitat systems. A key property of the Medical System is the provision of medical knowledge that will be stored, updated, analyzed, and secured within a Habitat Data System. A Task Performance Support System will aid in medical data acquisition and interpretation, crew training, medical condition prevention, diagnosis and treatment, provide interactive procedures, and track medical inventory. A Wellness System will focus on the provision of countermeasures to prevent, mitigate or treat adverse physical and behavioral health effects while the Medical System recommends adjustments to these countermeasures to maintain crew health. An Environmental Monitoring System will share out-of-bounds readings of air and water quality, acoustics, and radiation exposure levels with the Medical System to help identify issues before they affect crew health and performance. A Communications System will provide secured and private consultations between crew and the ground medical team and their loved ones on Earth. The Medical System also imposes requirements on a Research & Testbed System, fostering advanced medical science such as human research. A Waste Management System provides biohazard waste containment and waste disposal options (recycle and reuse). An Extravehicular Activity System supports crew health during lunar surface activities. And finally, a Maintenance Support System ensures that medical equipment is performing as expected. These requirements are being specifically developed for lunar surface operations but could help to identify Medical System requirements for any space habitat (e.g., I-Hab, commercial endeavors, etc.).

technology↗

Risk-Significant Adverse Condition Awareness Strengthens Assurance of Fault Management Systems

As spaceflight systems increase in complexity, Fault Management (FM) systems are ranked high in risk-based assessment of software criticality, emphasizing the importance of establishing highly competent domain expertise to provide assurance. Adverse conditions (ACs) and specific vulnerabilities encountered by safety- and mission-critical software systems have been identified through efforts to reduce the risk posture of software-intensive NASA missions. Acknowledgement of potential off-nominal conditions and analysis to determine software system resiliency are important aspects of hazard analysis and FM. A key component of assuring FM is an assessment of how well software addresses susceptibility to failure through consideration of ACs. Focus on significant risk predicted through experienced analysis conducted at the NASA Independent Verification Validation (IVV) Program enables the scoping of effective assurance strategies with regard to overall asset protection of complex spaceflight as well as ground systems. Research efforts sponsored by NASA's Office of Safety and Mission Assurance defined terminology, categorized data fields, and designed a baseline repository that centralizes and compiles a comprehensive listing of ACs and correlated data relevant across many NASA missions. This prototype tool helps projects improve analysis by tracking ACs and allowing queries based on project, mission type, domaincomponent, causal fault, and other key characteristics. Vulnerability in off-nominal situations, architectural design weaknesses, and unexpected or undesirable system behaviors in reaction to faults are curtailed with the awareness of ACs and risk-significant scenarios modeled for analysts through this database. Integration within the Enterprise Architecture at NASA IVV enables interfacing with other tools and datasets, technical support, and accessibility across the Agency. This paper discusses the development of an improved workflow process utilizing this database for adaptive, risk-informed FM assurance that critical software systems will safely and securely protect against faults and respond to ACs in order to achieve successful missions.

Fault management↗

Risk-Significant Adverse Condition Awareness Strengthens Assurance of Fault Management Systems

As spaceflight systems increase in complexity, Fault Management (FM) systems are ranked high in risk-based assessment of software criticality, emphasizing the importance of establishing highly competent domain expertise to provide assurance. Adverse conditions (ACs) and specific vulnerabilities encountered by safety- and mission-critical software systems have been identified through efforts to reduce the risk posture of software-intensive NASA missions. Acknowledgement of potential off-nominal conditions and analysis to determine software system resiliency are important aspects of hazard analysis and FM. A key component of assuring FM is an assessment of how well software addresses susceptibility to failure through consideration of ACs. Focus on significant risk predicted through experienced analysis conducted at the NASA Independent Verification & Validation (IV&V) Program enables the scoping of effective assurance strategies with regard to overall asset protection of complex spaceflight as well as ground systems. Research efforts sponsored by NASAs Office of Safety and Mission Assurance (OSMA) defined terminology, categorized data fields, and designed a baseline repository that centralizes and compiles a comprehensive listing of ACs and correlated data relevant across many NASA missions. This prototype tool helps projects improve analysis by tracking ACs and allowing queries based on project, mission type, domain/component, causal fault, and other key characteristics. Vulnerability in off-nominal situations, architectural design weaknesses, and unexpected or undesirable system behaviors in reaction to faults are curtailed with the awareness of ACs and risk-significant scenarios modeled for analysts through this database. Integration within the Enterprise Architecture at NASA IV&V enables interfacing with other tools and datasets, technical support, and accessibility across the Agency. This paper discusses the development of an improved workflow process utilizing this database for adaptive, risk-informed FM assurance that critical software systems will safely and securely protect against faults and respond to ACs in order to achieve successful missions.

IV&V↗

The Human Challenges of Remotely Piloted Aircraft Systems

Remotely Piloted Aircraft (RPA) range from small electric quadcopters that are flown close to the ground within visual range of the operator, to larger systems capable of extended flight in airspace shared with conventional aircraft. Before RPA can operate routinely and safely in civilian airspace, we need to understand the unique human factors associated with these aircraft. RPA pilots participated in focus groups where they were asked to recall critical incidents that either presented a threat to safety, or highlighted a case where the pilot contributed to system resilience or mission success. Ninety incidents were gathered from focus-groups. Human factor issues included the impact of reduced sensory cues, traffic separation in the absence of an out-the-window view, control latencies, vigilance during monotonous and ultra-long endurance flights, control station design considerations, transfer of control between control stations, the management of lost link procedures, and decision-making during emergencies. Some of these concerns have received significant attention in the literature, or are analogous to human factors of manned aircraft. Although many of the reported incidents were related to pilot error, the participants also provided examples of the positive contribution that humans make to the operation of highly-automated systems.

Hobbs, Alan↗

Human Factors of Remotely Piloted Aircraft Systems: Lessons from Incident Reports

An exploratory study is being conducted to examine the feasibility of collecting voluntary critical incident reports from RPAS pilots. Twenty-three experienced RPAS pilots volunteered to participate in focus groups in which they described critical incidents from their own experience. Participants were asked to recall (1) incidents that revealed a system flaw, or (2) highlighted a case where the human operator contributed to system resilience or mission success. Participants were asked to only report incidents that could be included in a public document. A total of 90 incidents were reported. Human factor issues included the impact of reduced sensory cues, traffic separation in the absence of an out-the-window view, control latencies, vigilance during monotonous and ultra-long endurance flights, control station design considerations, transfer of control between control stations, the management of lost link procedures, and decision-making during emergencies.

human factors↗

The Cognitive Challenges of Flying a Remotely Piloted Aircraft

A large variety of Remotely Piloted Aircraft (RPA) designs are currently in production or in development. These aircraft range from small electric quadcopters that are flown close to the ground within visual range of the operator, to larger systems capable of extended flight in airspace shared with conventional aircraft. Before RPA can operate routinely and safely in civilian airspace, we need to understand the unique human factors associated with these aircraft. The task of flying an RPA in civilian airspace involves challenges common to the operation of other highly-automated systems, but also introduces new considerations for pilot perception, decision-making, and action execution. RPA pilots participated in focus groups where they were asked to recall critical incidents that either presented a threat to safety, or highlighted a case where the pilot contributed to system resilience or mission success. Ninety incidents were gathered from focus-groups. Human factor issues included the impact of reduced sensory cues, traffic separation in the absence of an out-the-window view, control latencies, vigilance during monotonous and ultra-long endurance flights, control station design considerations, transfer of control between control stations, the management of lost link procedures, and decision-making during emergencies. Some of these concerns have received significant attention in the literature, or are analogous to human factors of manned aircraft. The presentation will focus on issues that are poorly understood, and have not yet been the subject of extensive human factors study. Although many of the reported incidents were related to pilot error, the participants also provided examples of the positive contribution that humans make to the operation of highly-automated systems.

remote pilot station↗

A Prognostics Framework Development for Swarm Satellite Formations

Prognostics is the science of predicting the failure(s) of a component or a system and understanding how the performance will change in the event of a failure or degradation mechanism. With accurate predictions of possible failures, autonomous mitigative actions can be taken to correct/repair any issues or alert human operators of a failure threshold exceedance requiring condition-based maintenance. Although there is extensive research on failure predictions for a component or a system, there are significantly more opportunities to foray into failure predictions and prognostics for a system of systems such as an airspace consisting of multiple aircraft, a fleet of unmanned aerial vehicles, and a swarm of intelligent satellite systems. Failure prediction and mitigation are particularly important in autonomous systems such as satellite swarm systems that need effective resource management and minimal human interactions. Based on NASA's decadal survey, there is a clear need to prioritize the development of satellite swarm technology for studies of space physics and Earth science. The science community will propose future missions that return in-situ measurements from a 3-D (three-dimensional) volume of space, with relative spacecraft motion and inter-satellite baselines controlled according to the mission objectives. For such multi-spacecraft missions, it is required that ground operations resources do not scale with the number of satellites, thus compromising the swarm or leading to inefficiencies in resource allocation. Swarms of tens or hundreds of small satellites will require autonomy in attitude control, navigation and failure. Although significant research has been conducted in the areas of autonomous formation flying algorithms, less attention has been given to the development of resilient systems robust to failures.The focus of this research paper is the integration of model-based prognostics into the swarm dynamics control and decision-making algorithms. We simulate swarm management strategies for a subsystem failure to demonstrate the importance of failure predictions by comparing two cases: (i) no health information is provided to the system and utilized in the decision-making process and (2) system health information is obtained using prognostics and employed by the control system. One example scenario presented is for the GPS (Global Positioning System) system of an individual satellite to perform off-nominally due to increasing estimated error. In this scenario, the keep-out zone for that satellite would become more conservative, thereby decreasing the risk of collision. This is achieved via tuning the individual artificial repulsive functions assigned to each satellite.This paper is structured as follows. First we provide an overview of current swarm technology development, where we specifically use the term swarm to define multiple satellites flying in formation in similar orbits, with cross-link communication and station-keeping capabilities. Second, we give an introduction to the Swarm Orbital Dynamics Advisor (SODA), a tool that accepts high-level configuration commands and provides the orbital maneuvers required to achieve the prescribed formation configuration. Third, we provide the details of the model-based prognostics algorithm implementation in SODA. Finally, we present different case studies for potential component/subsystem failures and the swarm responses based with and without failure prediction information.

prognostics↗

C2-Related Incidents Reported by UAS Pilots

It has been estimated that aviation accidents are typically preceded by numerous minor incidents arising from the same causal factors that ultimately produced the accident. Accident databases provide in-depth information on a relatively small number of occurrences, however incident databases have the potential to provide insights into the human factors of Remotely Piloted Aircraft System (RPAS) operations based on a larger volume of less-detailed reports. Currently, there is a lack of incident data dealing with the human factors of unmanned aircraft systems. An exploratory study is being conducted to examine the feasibility of collecting voluntary critical incident reports from RPAS pilots. Twenty-three experienced RPAS pilots volunteered to participate in focus groups in which they described critical incidents from their own experience. Participants were asked to recall (1) incidents that revealed a system flaw, or (2) highlighted a case where the human operator contributed to system resilience or mission success. Participants were asked to only report incidents that could be included in a public document. During each focus group session, a note taker produced a de-identified written record of the incident narratives. At the end of the session, participants reviewed each written incident report, and made edits and corrections as necessary. The incidents were later analyzed to identify contributing factors, with a focus on design issues that either hindered or assisted the pilot during the events. A total of 90 incidents were reported. This presentation focuses on incidents that involved the management of the command and control (C2) link. The identified issues include loss of link, interference from undesired transmissions, voice latency, accidental control transfer, and the use of the lost link timer, or lost link OK features.

unmanned aircraft systems↗

Pilot Critical Incident Reports as a Means to Identify Human Factors of Remotely Piloted Aircraft

It has been estimated that aviation accidents are typically preceded by numerous minor incidents arising from the same causal factors that ultimately produced the accident. Accident databases provide in-depth information on a relatively small number of occurrences, however incident databases have the potential to provide insights into the human factors of Remotely Piloted Aircraft System (RPAS) operations based on a larger volume of less-detailed reports. Currently, there is a lack of incident data dealing with the human factors of unmanned aircraft systems. An exploratory study is being conducted to examine the feasibility of collecting voluntary critical incident reports from RPAS pilots. Twenty-three experienced RPAS pilots volunteered to participate in focus groups in which they described critical incidents from their own experience. Participants were asked to recall (1) incidents that revealed a system flaw, or (2) highlighted a case where the human operator contributed to system resilience or mission success. Participants were asked to only report incidents that could be included in a public document. During each focus group session, a note taker produced a de-identified written record of the incident narratives. At the end of the session, participants reviewed each written incident report, and made edits and corrections as necessary. The incidents were later analyzed to identify contributing factors, with a focus on design issues that either hindered or assisted the pilot during the events. A total of 90 incidents were reported. Human factor issues included the impact of reduced sensory cues, traffic separation in the absence of an out-the-window view, control latencies, vigilance during monotonous and ultra-long endurance flights, control station design considerations, transfer of control between control stations, the management of lost link procedures, and decision-making during emergencies. Pilots participated willingly and enthusiastically in the study, and generally had little difficulty recalling critical incidents. The results suggest that pilot interviews can be a productive method of gathering information on incidents that might not otherwise be reported. Some of the issues described in the reports have received significant attention in the literature, or are analogous to human factors of manned aircraft. In other cases, incident reports involved human factors that are poorly understood, and have not yet been the subject of extensive study. Although many of the reported incidents were related to pilot error, the participants also provided examples of the positive contribution that humans make to the operation of highly-automated systems.

unmanned aircraft systems↗

Automated Target Planning for FUSE Using the SOVA Algorithm

The SOVA algorithm was originally developed under the Resilient Systems and Operations Project of the Engineering for Complex Systems Program from NASA s Aerospace Technology Enterprise as a conceptual framework to support real-time autonomous system mission and contingency management. The algorithm and its software implementation were formulated for generic application to autonomous flight vehicle systems, and its efficacy was demonstrated by simulation within the problem domain of Unmanned Aerial Vehicle autonomous flight management. The approach itself is based upon the precept that autonomous decision making for a very complex system can be made tractable by distillation of the system state to a manageable set of strategic objectives (e.g. maintain power margin, maintain mission timeline, and et cetera), which if attended to, will result in a favorable outcome. From any given starting point, the attainability of the end-states resulting from a set of candidate decisions is assessed by propagating a system model forward in time while qualitatively mapping simulated states into margins on strategic objectives using fuzzy inference systems. The expected return value of each candidate decision is evaluated as the product of the assigned value of the end-state with the assessed attainability of the end-state. The candidate decision yielding the highest expected return value is selected for implementation; thus, the approach provides a software framework for intelligent autonomous risk management. The name adopted for the technique incorporates its essential elements: Strategic Objective Valuation and Attainability (SOVA). Maximum value of the approach is realized for systems where human intervention is unavailable in the timeframe within which critical control decisions must be made. The Far Ultraviolet Spectroscopic Explorer (FUSE) satellite, launched in 1999, has been collecting science data for eight years.[1] At its beginning of life, FUSE had six gyros in two IRUs and four reaction wheels. Over time through various failures, the satellite has been left with one reaction wheel on the vehicle skew axis and two gyros. To remain operational, a control scheme has been implemented using the magnetic torque rods and the remaining momentum wheel.[2] As a consequence, there are attitude regions where there is insufficient torque authority to overcome environmental disturbances (e.g. gravity gradient torques). The situation is further complicated by the fact that these attitude regions shift inertially with time as the spacecraft moves through earth s magnetic field during the course of its orbit. Under these conditions, the burden of planning targets and target-to-target slew maneuvers has increased significantly since the beginning of the mission.[3] Individual targets must be selected so that the magnetic field remains roughly aligned with the skew wheel axis to provide enough control authority to the other two orthogonal axes. If the field moves too far away from the skew axis, the lack of control authority allows environmental torques to pull the satellite away from the target and can potentially cause it to tumble. Slew maneuver planning must factor the stability of targets at the beginning and end, and the torque authority at all points along the slew. Due to the time varying magnetic field geometry relative to any two inertial targets, small modifications in slew maneuver timing can make large differences in the achievability of a maneuver.

Heatwole, Scott↗

Identification of Human Factors in Unmanned Aviation Via Pilot Incident Reports

There is a need for incident data relevant to the operation of civilian unmanned aircraft systems (UAS) in the National Air Space (NAS). Currently, very limited incident and accident data are available from military sources, and the tightly-restricted civilian UAS industry has produced very few incident reports that could shed light on design issues relevant to human factors. An exploratory study is being conducted to examine the feasibility of collecting voluntary critical incident reports from UAS pilots, and using the information to identify areas where human factors guidelines will be of assistance. Experienced UAS pilots are participating in small focus groups in which they are prompted to describe critical incidents that either reveal a system flaw, or highlight a case where the human operator contributed to system resilience or mission success. The de-identified incidents are being analyzed to identify contributing factors, with a focus on design issues that either hindered or assisted the pilot in dealing with the incident. Preliminary findings will be described.

human factors↗