Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “TRUST”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Trust in Collaborative Automation in High Stakes Software Engineering Work

The amount of autonomy in software engineering tools is increasing as developers build increasingly complex systems. Research in other domains shows that too much or too little trust in autonomous tools can have negative consequences, but we are not aware of any study that has investigated trust in autonomous tools in the highly interactive context of a software engineering workplace. We present the results of a ten week ethnographic case study of engineers collaborating with autonomous tools to write flight software at a large national space exploration organization to support high stakes missions. We find that trust in an autonomous software engineering tool in this setting was influenced by four main factors: the tool’s transparency, social context, an organization’s associated processes, and its usability. We outline theoretical implications for future research into trust in autonomous software engineering tools, and practical implications for tool designers and organizations conducting high stakes work with autonomous tools.

Davidoff, Scott↗

The Influence of Viability, Independence, and Self-Governance on Trust and Public Acceptance of Uncrewed Air Vehicle Operations

Trust is expected to be a critical construct that drives successful use of advanced air mobility (AAM) technologies. As yet, though, the role of trust in human-autonomy interaction is underexplored. Kaber (2018) argues that autonomy requires the highest level of three independent dimensions -- viability, independence, and self-governance. The present study examined whether trust varies across the three dimensions of autonomy under varying levels of risk. Participants in the high-risk group read a series of vignettes on a drone that delivers medical supplies over a city where the current study was conducted. Participants in the low-risk group read a series of vignettes on a drone that delivers fast food over a fictitious city. Each vignette described a drone that is either autonomous (i.e., possesses all dimensions) or automated (i.e., one of the dimensions is compromised). Results imply that the three dimensions of autonomy do not equally influence human-technology trust and behavior.

Advanced Air Mobility↗

Space ROS TOFU: Flying Space ROS with Containerized Hybrid Trust

Space ROS is a distribution of Robot Operating System 2 (ROS2) targeting the specific requirements of flight software and spaceborne robotics while maintaining the flexibility that has made ROS indispensible for robotics research and industrial system integration. With Space ROS, a project can leverage the existing ROS2 ecosystem to reduce redundant development while tackling increasingly complex demands for on-device intelligence; however, there is no substitute for flight heritage to combat the risk-aversion common to spaceflight projects, and Space ROS has yet to fly. To break the collective-action standoff and gain valuable flight experience, the Distributed Spacecraft Autonomy (DSA) team at NASA Ames Research Center developed Opportunistic Software Experiments for Spacecraft Autonomy Testbeds (OSE-SAT) architecture, utilizing containerization to execute lower-trust software under traditionally verified heritage flight software for demonstration on-orbit. OSE-SAT leverages a hybrid-trust model where flexible, complex components like Space ROS can run without risk to the host spacecraft while providing validated feedback to a highly scrutinized, trusted core. We leverage this testbed to demonstrate Space ROS in flight, building heritage, and experience for projects with "Trust On First Use" (TOFU) requirements for flight heritage. We present a Space ROS component for OSE-SAT, lessons learned integrating Space ROS into a flight software stack, and the results of the first known use of Space ROS in orbit.

small satellites↗

Computational Models of Trustworthiness and Trust in Autonomous Cyber-Physical-Human Systems

In this paper, we propose an approach to developing a concept of actionable trust in multi-agent,cyber-physical-human systems in safety-critical and time-critical environment of air transportation. Actionable trust requires computational models of trustworthiness and trust, for use during system design and in real time, during operations. We describe the models, examine their computability and scalability, as well as what remains to be done.

Autonomous Systems↗

Zero-Trust Architecture for Autonomous Edge Computing

We are at the apex of an aviation revolution where autonomy will play a central role in enabling complex, multi-agent systems to communicate, interact, and collaborate on a myriad of applications spanning autonomous swarms to wild-fire management. Autonomy is not an absolute but rather a spectrum ranging from a system requiring significant human intervention to one requiring little to none [1]. For example, the extreme, in the case of an autonomous aircraft, is one that operates independently in the airspace interacting with all other elements (air traffic controllers, other pilots) as if it were a human pilot. Critical to this vision is an architecture that enables autonomous agents to interact with minimal latency. Edge computing is an emerging architecture where compute and storage is pushed to the ‘edge’ of the network in order to minimize the round-trip time from agent to resource thereby mitigating the latency associated with cloud-only based approaches. Additionally, services can generate massive amounts of data (e.g., video feeds), which may require analysis in near real-time. Moving this data to the cloud for further processing may not be feasible due to latency, bandwidth, and cost. Privacy, security, and reliability can also be improved by edge computing architectures. However, this geo-distributed and dynamic* architecture complicates the establishment of unambiguous network security boundaries and can lead to vulnerabilities including man in the middle attacks, replay attacks, physical security breaches of edge nodes, signal interception, etc. This motivates the need for zero-trust architectures [2–4] which de-emphasize the notion of static network perimeters and, as the name implies, do not instill any innate trust in any particular agent. It is required that all agents must be authorized and approved in every transaction. In this paper, we present a zero-trust architecture suitable for edge-computing applications that demand significant low-latency, security, privacy, and reliability.

zero trust↗

The Impact of Trust on Organization Commitment

As the global economy continues to spawn competitive forces, organizations have sought to become more competitive by cutting costs, eliminating non-value added work, and using more automation. Jobs have become broader and more flexible leading to a leaner workforce with higher-level knowledge and skills and more responsibility for day-to-day decisions. More than ever, organizations depend on employees as the innovators and designers of products and processes and as a source of strategic advantage. Therefore employee commitment among knowledge workers is needed to maintain organizational viability. It would seem that stronger relationships due to greater dependency, involvement, and investment would develop between employers and high-technology workers resulting in more committed employees. However, the opposite has been evidenced as key knowledge workers are changing jobs frequently. This may be due to a perceived lack of commitment by management to its employees. The notion of exchange may dominate the development of organizational commitment whereby an individual decides what to give a firm (commitment, extra effort, better performance, etc.) based on what the firm gives them (e.g., trust and security). It is the relationship between an employee's organizational commitment and the responding level of trust in the organization that is examined in this paper. An experiment is described that will seek to identify this relationship. Preliminary results are expected to show a positive relationship whereby employee commitment is positively correlated with organizational trust.

Robinson, Kimberly↗

Toward Justifiable Trust in Autonomous Systems Incorporating Human Knowledge in Autonomous Systems through Machine Learning

Trust in Autonomous Systems is largely about humans trusting the decisions made by autonomous systems. This trust can be increased through learning from domain experts. In particular, autonomous systems can learn offline from past mission operations before conducting any operations of its own. Additionally, autonomous systems can learn online by obtaining human feedback during operations. We will discuss several classes of machine learning methods and our application of them to autonomous systems. The first class of methods is anomaly detection, which uses operations data to identify examples of anomalous operations. The second class of methods is inverse reinforcement learning, also known as apprenticeship learning, that takes past operations data as input and yields a controller that is able to duplicate the operations described by the data. The third class is active learning, which identifies examples on which the model is most uncertain and requests domain expert feedback.

Oza, Nikunj C.↗

Effects of Autonomous sUAS Separation Methods on Subjective Workload, Situation Awareness, and Trust

The Unmanned Aircraft System (UAS) Traffic Management (UTM) concept was designed to support autonomous small UAS operations at a large-scale and without direct human intervention. However, human-autonomy interactions will be impacted by situation awareness, workload, and trust in the autonomy. Method: Nine participants monitored live small UAS operations in a representative UTM system during a series of traffic conflict scenarios and then provided subjective responses regarding situation awareness, workload, and trust in the autonomous separation method. The study employed a 3 (Separation Method: Autonomous Sense and Avoid, Geofence, Manual) × 2 (Incursion: High, Medium) within subjects design. Results: Situation awareness ratings for both autonomous separation methods were significantly lower than the manual condition. An interaction indicated differential workload ratings for the Autonomous Sense and Avoid separation ratings. Trust ratings significantly dropped when the Geofencing separation method failed. Conclusion: Subjective responses of remote operators in the UTM system are affected by the vehicle separation methods. Operators’ understanding of decisions made by the autonomous systems onboard the vehicle likely influence this effect

UAS↗

TRUST, Trustworthiness and EOSDIS

In recent years there has been considerable attention by the international scientific research and applications community to ensure high quality of data and information management. The terms FAIR (Findable, Accessible, Interoperable, Reusable) data, TRUST (Transparency, Responsibility, User Community, Sustainability, and Technology) principles, and CARE (Collective Benefit, Authority to Control, Responsibility, and Ethics) principles have come into vogue during the last decade. NASA has been managing data and information for over 60 years. NASA’s Earth Observing System Data and Information System (EOSDIS) has been in operation for over 25 years, managing most of NASA’s Earth science data. Trustworthiness is a goal that NASA has always strived to achieve or exceed, because it: enables the success of any NASA science mission; inspires general science research and applications; justifies the cost of operations; contributes to the value of NASA’s Open Data Policy; and influences the long term, historical view for the data collection. Given the recent growth of interest in TRUST principles, it is useful to assess and show how NASA’s attention to trustworthiness maps into those principles. This presentation addresses shows how the various steps that have been taken by the Earth Science Data and Information System (ESDIS) Project in the implementation and evolution of EOSDIS map into the TRUST principles.

Remote Sensing↗

An Extended Case Study Methoology for Investigating Influence of Cultural, Organizational, and Automation Factors on Human-Automation Trust

This paper discusses a case study that examined the influence of cultural, organizational and automation capability upon human trust in, and reliance on, automation. In particular, this paper focuses on the design and application of an extended case study methodology, and on the foundational lessons revealed by it. Experimental test pilots involved in the research and development of the US Air Forces newly developed Automatic Ground Collision Avoidance System served as the context for this examination. An eclectic, multi-pronged approach was designed to conduct this case study, and proved effective in addressing the challenges associated with the cases politically sensitive and military environment. Key results indicate that the system design was in alignment with pilot culture and organizational mission, indicating the potential for appropriate trust development in operational pilots. These include the low-vulnerabilityhigh risk nature of the pilot profession, automation transparency and suspicion, system reputation, and the setup of and communications among organizations involved in the system development.

automation suspicion↗

Influence of Cultural, Organizational, and Automation Capability on Human Automation Trust: A Case Study of Auto-GCAS Experimental Test Pilots

This paper discusses a case study that examined the influence of cultural, organizational and automation capability upon human trust in, and reliance on, automation. In particular, this paper focuses on the design and application of an extended case study methodology, and on the foundational lessons revealed by it. Experimental test pilots involved in the research and development of the US Air Force's newly developed Automatic Ground Collision Avoidance System served as the context for this examination. An eclectic, multi-pronged approach was designed to conduct this case study, and proved effective in addressing the challenges associated with the case's politically sensitive and military environment. Key results indicate that the system design was in alignment with pilot culture and organizational mission, indicating the potential for appropriate trust development in operational pilots. These include the low-vulnerability/ high risk nature of the pilot profession, automation transparency and suspicion, system reputation, and the setup of and communications among organizations involved in the system development.

trust↗

Verification of Triple Modular Redundancy (TMR) Insertion for Reliable and Trusted Systems

We propose a method for TMR insertion verification that satisfies the process for reliable and trusted systems. If a system is expected to be protected using TMR, improper insertion can jeopardize the reliability and security of the system. Due to the complexity of the verification process, there are currently no available techniques that can provide complete and reliable confirmation of TMR insertion. This manuscript addresses the challenge of confirming that TMR has been inserted without corruption of functionality and with correct application of the expected TMR topology. The proposed verification method combines the usage of existing formal analysis tools with a novel search-detect-and-verify tool. Field programmable gate array (FPGA),Triple Modular Redundancy (TMR),Verification, Trust, Reliability,

Trust↗

An Experimental Study of the Effect of Transparency on Pilot Trust in the Emergency Landing Planner

This experimental study examined the effects of transparency (operationalized as increasing levels of explanation) on pilot trust of an automated emergency landing planner. A low-fidelity study was conducted where commercial pilots (N12) interacted with simulated recommendations from NASA's Emergency Landing Planner (ELP). These recommendations varied in their associated levels of transparency. Results indicated that trust in the ELP was influenced by the level of transparency within the human-machine interface of the ELP.

transparency↗

Zero Trust and Identity Access Management in Support of Service-Based Urban Air Mobility Applications

Urban Air Mobility environments will contain of a collection of service-based services, which will be typically hosted within cloud infrastructures. The underlying data for these UAM services will need to be secured. One approach to securing these UAM services would be to leverage the Zero Trust framework, that focuses on securing services and associated data, instead of securing the network. An early step in moving towards a Zero Trust framework is to standardize identity access manage support for an ever-widening set of services, where users must explicitly be granted access to each service.

UAM↗

Trusted Autonomy for Space Flight Systems

NASA has long supported research on intelligent control technologies that could allow space systems to operate autonomously or with reduced human supervision. Proposed uses range from automated control of entire space vehicles to mobile robots that assist or substitute for astronauts to vehicle systems such as life support that interact with other systems in complex ways and require constant vigilance. The potential for pervasive use of such technology to extend the kinds of missions that are possible in practice is well understood, as is its potential to radically improve the robustness, safety and productivity of diverse mission systems. Despite its acknowledged potential, intelligent control capabilities are rarely used in space flight systems. Perhaps the most famous example of intelligent control on a spacecraft is the Remote Agent system flown on the Deep Space One mission (1998 - 2001). However, even in this case, the role of the intelligent control element, originally intended to have full control of the spacecraft for the duration of the mission, was reduced to having partial control for a two-week non-critical period. Even this level of mission acceptance was exceptional. In most cases, mission managers consider intelligent control systems an unacceptable source of risk and elect not to fly them. Overall, the technology is not trusted. From the standpoint of those who need to decide whether to incorporate this technology, lack of trust is easy to understand. Intelligent high-level control means allowing software io make decisions that are too complex for conventional software. The decision-making behavior of these systems is often hard to understand and inspect, and thus hard to evaluate. Moreover, such software is typically designed and implemented either as a research product or custom-built for a particular mission. In the former case, software quality is unlikely to be adequate for flight qualification and the functionality provided by the system is likely driven largely by the need to publish innovative work. In the latter case, the mission represents the first use of the system, a risky proposition even for relatively simple software.

Freed, Michael↗

Trusted Communication: Utilizing Speech Communication to Enhance Human-Machine Teaming Success

An area of increasing interest for the next generation of aircraft is autonomy and the integration of increasingly autonomous systems into the national airspace. Such an integration requires humans to work closely with autonomous systems, forming teams. Our hypothesis is that a team composed of both humans and autonomous systems will operate better than either entity alone. We have existing procedures for certifying pilots to operate in the national airspace and are currently working on methods for validating the function of autonomous systems, however we have no method in place for assessing the interaction of these two disparate systems. Communication is one avenue. This paper will examine the use of language as a metric for ascertaining human-machine teaming effectiveness. A proof-of-concept of the application of two communication-based analysis techniques, Linguistic Inquiry and Word Count (LIWC) and Latent Semantic Analysis (LSA), for the prediction of success in human/chatbot teaming was conducted. By running these analyses over data from the 2014 and 2015 Loebner Prize competitions of human/chatbot teaming, numerical scores were obtained that can be associated with scores provided by human judges during the competition. Correlating their LIWC and LSA data with the scores provided by the judges, and using linear regression over this correlation, formulae were obtained that predict the score of human/chatbot interaction. These formulae were tested over the 2013 Loebner Prize transcripts, determining that, though there was strong correlation between predicted and actual scores, the predictive success of this method was not strong. However, with specialized topic spaces and lexica, as well as larger data sets, the predictive power of these metrics will improve. Given the importance of providing metrics for human-machine system team success and given the promise shown by the communication-basedLIWCand LSAmethods, continuing research in this area is necessary. After examining the potential for using communication and spoken language as a metric for the success of human/autonomous system teaming, this paper then examines aspects inherent to communication systems that may contribute to unreliability and reduced trust. Modern natural language processing tools rely on deep learning algorithms to create language rules that produce accurate results, but these rules are uninterpretable. The resulting blackbox system lacks transparency necessary for full validation and complete trust. Additionally, speech-based interfaces pose other difficulties to developing coordinated teamwork between humans and autonomous systems. Human communication is infrequently limited to speech only, instead usually relying on a combination of verbal, gestural, and general body language communication. Reducing an analysis of team effectiveness to a study of spoken language alone is problematic as it leaves these other equally important forms of communication out. This paper will examine these problems and the general deficiencies in speech-based metrics for human-machine teaming.

E L Meszaros↗

ATTRACTOR: Autonomy Teaming and TRAjectories for Complex Trusted Operational Reliability

Autonomous systems (AS) are crucial to realizing the vision of new, complex transportation modes, such as advanced air mobility (AAM) and urban air mobility (UAM). A chief barrier to induction of AS into aviation is insufficient understanding of AS reliability in time-critical and safety-critical environments—an obstacle to certification. ATTRACTOR is aimed at building a basis for certification of classes of autonomous cyber-physical-human systems (CPHS) via establishing metrics and models of trustworthiness and trust in multi-agent team interactions, analyzable trajectories, explainability of computational algorithms (explainable artificial intelligence, or XAI), and persistent modeling and simulation, in the context of missions planning and operation. By “building a basis for certification,” we mean acquiring an understanding of when a system is trustworthy and developing computable means to estimate trustworthiness and trust in order to eventually inform functional requirements that contribute to certification. The outcomes are applicable not just to aviation but to all domains that rely on autonomous systems.

Autonomy↗

Recommendations to Advance Space Trusted Autonomy

The interagency Space Science and Technology Partnership Forum was established in2015 to identify synergistic efforts and technologies across the U.S. government. While the various space agencies of the U.S. government have distinctly different visions for future operational space systems, all share important foundational common needs. These needs, combined with the maturation of autonomous technology and the prospect of leveraging autonomous systems to address those needs, have led each agency to consider how and when to to implement increasing levels of autonomy in their space systems, and how to determine the trustworthiness of an autonomous system. The Partnership facilitated dialogue among the partners, collected and analyzed data on current and desired future levels of capability, and identified gaps to motivate three recommendations that can be addressed within the Partnership community. These recommendations address the need for more robust documenting and socializing of anomalies in space system operations; the need to expand communication and trust within the community of developers, operators, and end users; and the need for a safe development and testing environment for maturing and demonstrating future autonomous space systems. These recommendations will facilitate both near-term programmatic actions and long-term steps for implementing enduring progress towards enabling space trusted autonomy.

Christopher A Jones↗