Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Accident”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

BISON Capability, Validation and Demonstration for Reactivity-Initiated Accidents

Reactivity Initiated Accidents (RIA) are design basis accidents that could have adverse impacts on the core coolability. In the unlikely event that sufficient reactivity is inserted into the reactor core by the ejected/dropped control rod, prompt energy deposition into the fuel can occur, which when sufficiently high can lead to fuel rod failure or, at large energy deposition levels, expulsion of UO2 fragments or molten UO2 material from the fuel rod. This results in a release of fission product and fuel into the coolant and has the potential to compromise core coolability and threatening the pressure boundary of the primary coolant system. The design basis RIA is one of the industry challenging problems that the CASL aimed to address; the CASL RIA Challenge Problem Charter [1] states, ?The Pressurized Water Reactor (PWR) Rod Ejection Accident (REA) and Boiling Water Reactor (BWR) Control Rod Drop Accident (CRDA) are postulated accidents with consequences that are important to nuclear safety (fuel rod integrity and core coolability). Currently each reload core design must be analyzed to meet regulatory acceptance criteria. The goal of CASLs ModSim capability for RIA is to model the event at a higher fidelity, with validation to existing tests, to better model the transient neutronics and the progression of the fuel and cladding thermal-mechanical behavior. These improved analytical capabilities can be used to better inform reload core design, limits on fuel assembly discharge burnup, restrictions on placement of fuel in the reactor, control rod insertion limits, operating margin, and performance sensitivities.? In support of that charter, BISON, the fuel performance code has been used to demonstrate the simulation of thermal-mechanical behavior of LWR fuels during a reactivity-initiated accident. The combination of mechanical, thermal, and thermal-hydraulic phenomena all present during an RIA makes a multi-physics code such as BISON a valuable tool for modeling these scenarios. This paper will highlight many of the activities associated with BISON relevant to reactivity-initiated accident capability development and validation efforts. These efforts have been performed under both CASL and the Nuclear Energy Advanced Modeling and Simulation (NEAMS) programs.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Testing to Evaluate Processes Expected to Occur during MSR Salt Spill Accidents

Obtaining a license for a new nuclear reactor requires the identification and assessment of the potential consequences of specified accident scenarios, which are achieved using accident progression models. Those models need to be parameterized and validated using experimental data, but existing experimental data addressing processes relevant to molten salt reactor accidents are sparse. Specifically, experimental data that quantify the sensitives of important processes to the initial conditions of the spill, the ambient environment, and the containment features are needed to parameterize individual process models. Integrated experiments that simulate accident scenarios are also needed to provide data for model validation, but these experiments will require the use of proven methods to quantify the processes under evaluation. The overarching objectives of this work are to develop the methods for simulating the targeted processes, to determine the effectiveness of the methods in producing the data required for model development, to generate data that can be used to parameterize individual process models, and to provide key insights into the behavior of spilled molten salt that should be considered in models. Experimental methods were designed to quantify aspects of individual processes expected to occur during or after a molten salt spill accident that will affect the fate of spilled molten salt and the radionuclides within. These processes include 1) molten salt spreading and heat transfer, 2) molten salt flowing and freezing in tubing, 3) stainless steel corrosion kinetics in molten salt, and 4) molten salt splashing and aerosol generation. The initial tests described in this report were conducted using eutectic FLiNaK to demonstrate the test methods, the data that are generated, and the analyses of the data to derive values needed for modeling. The primary variables that were tested include initial salt temperature and the presence of volatile surrogate fission products (e.g., cesium and iodine). The developed methods are shown to be effective in quantifying the desired processes and can be applied to study more complex salt compositions of interest to molten salt reactor developers, a wide range of environmental conditions of interest to modelers, and additional variables relevant to salt spill accidents. The developed methods and insights gained from laboratory tests can also be incorporated in future large-scale integrated tests used to simulate molten salt spill accidents.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Integrated Process Testing of MSR Salt Spill Accidents

Part of the licensing process for new nuclear reactors requires vendors to assess the potential consequences of identified accident scenarios using accident progression modeling. The accident scenario that will likely be evaluated by all molten salt reactor (MSR) developers is a spill of radionuclide-bearing fuel salt onto the reactor containment floor (i.e., a salt spill accident). The development of accident progression models requires experimental data to inform which processes to incorporate, to enable the calculation of parameters to model these processes, and to validate the model predictions. The data should quantify the sensitivities of key processes (e.g., molten salt spreading, heat transfer, containment structure corrosion, radionuclide vaporization, and aerosol generation) towards the initial conditions of the spill, the ambient environment, and the features of the containment. In addition, results from integrated process tests that quantify coupled processes are required to validate systems-level models. This report documents results from integrated process tests conducted on simulated molten salt spill accidents. The generated experimental data simultaneously quantify the heat transfer behavior of the spilled salt, compositional changes to the bulk salt, and the release of surrogate fission products from the spilled salt as aerosol particles. All tests that were conducted used FLiNaK doped with surrogate fission products, and the variables that were evaluated included the initial salt temperature and the concentration of surrogate fission products present in the salt. The major accomplishments of this work include identifying surrogate fuel salt compositions that provide insight into the dispersal behavior of radionuclides of potential significance to the source term, employing previously developed methods and measurement techniques to simultaneously measure key processes, generating data on the coupled processes of molten salt heat transfer and surrogate fission product release as aerosol particles, demonstrating new test methods for real-time monitoring of the flow rate of the spill and aerosol size quantification in an argon atmosphere, and developing a mass transfer model for cesium and iodine release from molten FLiNaK to provide insight into aerosol formation by vapor condensation. The same methodology applied herein can be employed to study different salt compositions of interest to MSR developers, different environmental conditions, and other variables that are relevant to postulated accident scenarios. The insights gained from these integrated process tests conducted at a laboratory scale will be incorporated into future integral effects tests conducted at an engineering scale.

20 FOSSIL-FUELED POWER PLANTS↗

An analysis of aircraft accidents involving fires

All U. S. Air Carrier accidents between 1963 and 1974 were studied to assess the extent of total personnel and aircraft damage which occurred in accidents and in accidents involving fire. Published accident reports and NTSB investigators' factual backup files were the primary sources of data. Although it was frequently not possible to assess the relative extent of fire-caused damage versus impact damage using the available data, the study established upper and lower bounds for deaths and damage due specifically to fire. In 12 years there were 122 accidents which involved airframe fires. Eighty-seven percent of the fires occurred after impact, and fuel leakage from ruptured tanks or severed lines was the most frequently cited cause. A cost analysis was performed for 300 serious accidents, including 92 serious accidents which involved fire. Personal injury costs were outside the scope of the cost analysis, but data on personnel injury judgements as well as settlements received from the CAB are included for reference.

Lucha, G. V.↗

An Examination of Aviation Accidents Associated with Turbulence, Wind Shear and Thunderstorm

The focal point of the study reported here was the definition and examination of turbulence, wind shear and thunderstorm in relation to aviation accidents. NASA project management desired this information regarding distinct subgroups of atmospheric hazards, in order to better focus their research portfolio. A seven category expansion of Kaplan's turbulence categories was developed, which included wake turbulence, mountain wave turbulence, clear air turbulence, cloud turbulence, convective turbulence, thunderstorm without mention of turbulence, and low altitude wind shear, microburst or turbulence (with no mention of thunderstorms).More than 800 accidents from flights based in the United States during 1987-2008 were selected from a National Transportation Safety Board (NTSB) database. Accidents were selected for inclusion in this study if turbulence, thunderstorm, wind shear or microburst was considered either a cause or a factor in the accident report, and each accident was assigned to only one hazard category. This report summarizes the differences between the categories in terms of factors such as flight operations category, aircraft engine type, the accident's geographic location and time of year, degree of injury to aircraft occupants, aircraft damage, age and certification of the pilot and the phase of flight at the time of the accident.

Evans, Joni K.↗

Changes in Frequency of the Severity and Type of Aviation Accidents (1987 to 2016)

This document reports the fourth analysis to identify the types of accidents with the greatest impact on the overall safety risk in U.S. civil aviation. The first three analyses examined accidents in 1997-20061, in 2001-20102 and in 2005-20143. The safety risks herein are defined to include four elements: (1) the number of total accidents; (2) the number of fatal accidents; (3) the number of total injuries; (4) the number of fatal injuries. Two of the previous analyses also included the number of incidents, but incident data since 2007 are difficult to separate by flight operation. Other incident details are no longer recorded as well. Due to these changes, the author’s working copy of the incident data has not been updated since 2011 (for incidents through 2010), and the incident data were not included in this analysis. Powerplant and non-powerplant system component failures were the only categories with a greater contribution to the overall safety risk from incidents than from accidents. Accident types, as well as accident rates, have been shown to vary considerably among different flight operations (e.g., large air carriers versus general aviation). For this reason, all analyses were done separately for four types of flight operations (Part 121, Scheduled Part 135, Non- Scheduled Part 135 and Part 91).

Evans, Joni K.↗

The Need for a Maximum Intensity Accident in ANS 8-Series Standards

The Y-12 National Security Complex has installed one Criticality Accident Alarm System (CAAS) under the ANS 8.3 framework as a safety significant system, and is in the process of designing, installing, and qualifying another. As a safety significant system, the Y-12 CAAS is required to demonstrate that it is able to perform its function and actuate an alarm when exposed to the radiation from both a Minimum Accident of Concern and a maximum intensity accident. The ANS 8-series standards do not present a maximum accident to be considered, nor do they specify radiation tolerance requirements for the CAAS equipment, leading CAAS vendors to potentially use other standards that provide inadequate criteria. In this paper, the historical basis and need for a maximum intensity accident in the ANS standards is discussed, the fission rate of a maximum intensity accident is proposed, and the effects of this accident on CAAS analysis and the vendor’s equipment qualification are discussed.

61 RADIATION PROTECTION AND DOSIMETRY↗

Evaluating direct vessel injection accident-event progression of AP1000 and key figures of merit to support the design and development of water-cooled small modular reactors

The passive safety systems (PSSs) within water-cooled reactors are meticulously engineered to function autonomously, requiring no external power source or manual intervention. They depend exclusively on inherent natural forces and the fundamental principles of reactor physics, such as gravity, natural convection, and phase changes, to manage, alleviate, and avert the release of radioactive materials into the environment during accident scenarios like a loss-of-coolant accident (LOCA). PSSs are already integrated into such operating commercial reactors as the Advanced Pressurized Reactor-1000 MWe (AP1000) and the Water-Water Energetic Reactor-1200 MWe (WWER-1200) are adopted in most of the upcoming small modular reactor (SMR) designs. Examples of water-cooled SMR PSSs are the passive emergency core-cooling system (ECCS), passive containment cooling system (PCCS), and passive decay-heat removal system, the designs of which vary based on reactor system-design requirements. However, understanding the accident-event progression and phases of a LOCA is pivotal for adopting a specific PSS for a new SMR design. This study covers the accident-event progression for direct vessel injection (DVI) small-break loss-of-coolant accident (SB-LOCA), associated physics phenomena, knowledge gaps, and important figures of merit (FOMs) that may need to be evaluated and assessed to validate thermal-hydraulics models with an available experimental dataset to support new SMR design and development.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Neural-based time series forecasting of loss of coolant accidents in nuclear power plants

During the last few years, deep learning in neural networks has demonstrated impressive successes in the areas of computer vision, speech and image recognition, text generation, and many others. However, sensitive engineering areas such as nuclear engineering benefited less from these efficient techniques. In this work, deep learning expert systems are utilized to model and predict time series progression of a design-basis nuclear accident, featuring a loss of coolant accident. Two major findings are accomplished in this work. First, the ability to train expert systems with high accuracy, which could help nuclear power plant operators to figure out plant responses during the accident. Second, building fast, efficient, and accurate deep models to simulate nuclear phenomena, which could be valuable to nuclear computational science. In this work, large amount of time series data is obtained from simulation tools by simulating different conditions of the base-case/nominal accident scenario. Four critical outputs/responses are monitored during the accident (e.g. temperature, pressure, break flow rate, water level). Two approaches are adopted in this work. The first approach is to use feedforward deep neural networks (DNN) to fit all time steps and outputs in a single model. The second approach is to use long short-term memory (LSTM) to fit all time steps together for each reactor response separately. Both DNN and LSTM demonstrate very good performance in predicting the test and base-case scenarios, with accuracy as low as 92% and as high as 99%, where these test scenarios are unknown to the expert systems and are not included in the model training. In addition, both approaches demonstrate a significant reduction in computational costs, as the deep expert system is able to accurately predict the accident 100,000 times faster than the original simulation tool. Given sufficient data, the methodology adopted in this study demonstrates that DNN/LSTM expert systems can be used as a decision support system to model advanced time series phenomena within nuclear power plants with high accuracy and negligible computational costs.

42 ENGINEERING↗

MSR Salt Spill Accident Testing Using Eutectic NaCl-UCl 3

Assessing the potential consequences of identified accident scenarios is an essential part of the licensing process for a new nuclear reactor and is achieved by using accident progression models. A likely accident scenario that will be evaluated by developers of molten salt reactors (MSRs) is a spill of radionuclide-bearing fuel salt onto the reactor containment floor (i.e., a salt spill accident). Models to determine the consequences of a molten salt spill accident need to be parameterized and validated using experimental data, but little experimental effort has been dedicated to fill these data gaps to date. Specifically, data is needed to enable model development for individual processes (e.g., spreading, heat transfer, corrosion, radionuclide vaporization, and aerosol generation) that quantifies the sensitivities towards the initial conditions of the spill, the ambient environment, and the features of the containment. In addition, integrated experiments that simulate salt spill accidents will need to be conducted to provide insight into coupled processes and data for model validation, but these experiments will require the use of proven methods to quantify the processes under evaluation.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

A mechanistic model of a PWR-based nuclear power plant in response to external hazard-induced station blackout accidents

Natural hazard-induced nuclear accidents, such as the Fukushima Daiichi Accident that occurred in Japan in 2011, have significantly increased reactor safety studies in understanding nuclear power plant (NPP) responses to external hazard events such as earthquakes and floods. Natural hazards could cause the loss of offsite power in nuclear power plants, potentially leading to a Station Blackout (SBO) accident that significantly contributes to the overall risk of nuclear power plant accidents. Despite the fact that extensive research has been conducted on the station blackout accident for nuclear power plant, further understanding of these events is needed, particularly in the context of the dynamic nature of external hazards such as external flooding. This paper estimates the progression of station blackout events for a generic pressurized water reactor (PWR) in response to external flooding events. The original RELAP5-3D model of the Westinghouse four-loop design pressurized water reactor was adopted and modified to simulate the external flood-induced station blackout accident, including the short-term and long-term station blackout scenarios. A sensitivity analysis of long-term station blackout, examining reactor operation times and analyzing key parameters over time, was also conducted in this work. The results of the analyses, especially the critical timing parameters of key event sequences, provide useful insights about the time during the external flooding event, which is important for plant operators to make timely decisions to prevent potential core damage. This paper represents significant progress toward developing an integrated risk assessment framework for further identifying and assessing the effects of the critical sources of uncertainties of nuclear power plant under external hazard-induced events.

Liu, Tao↗

Analysis of Convair 990 rejected-takeoff accident with emphasis on decision making, training and procedures

This paper analyzes a NASA Convair 990 (CV-990) accident with emphasis on rejected-takeoff (RTO) decision making, training, procedures, and accident statistics. The NASA Aircraft Accident Investigation Board was somewhat perplexed that an aircraft could be destroyed as a result of blown tires during the takeoff roll. To provide a better understanding of tire failure RTO's, The Board obtained accident reports, Federal Aviation Administration (FAA) studies, and other pertinent information related to the elements of this accident. This material enhanced the analysis process and convinced the Accident Board that high-speed RTO's in transport aircraft should be given more emphasis during pilot training. Pilots should be made aware of various RTO situations and statistics with emphasis on failed-tire RTO's. This background information could enhance the split-second decision-making process that is required prior to initiating an RTO.

Batthauer, Byron E.↗

Analysis of Crew Fatigue in AIA Guantanamo Bay Aviation Accident

Flight operations can engender fatigue, which can affect flight crew performance, vigilance, and mood. The National Transportation Safety Board (NTSB) requested the NASA Fatigue Countermeasures Program to analyze crew fatigue factors in an aviation accident that occurred at Guantanamo Bay, Cuba. There are specific fatigue factors that can be considered in such investigations: cumulative sleep loss, continuous hours of wakefulness prior to the incident or accident, and the time of day at which the accident occurred. Data from the NTSB Human Performance Investigator's Factual Report, the Operations Group Chairman's Factual Report, and the Flight 808 Crew Statements were analyzed, using conservative estimates and averages to reconcile discrepancies among the sources. Analysis of these data determined the following: the entire crew displayed cumulative sleep loss, operated during an extended period of continuous wakefulness, and obtained sleep at times in opposition to the circadian disposition for sleep, and that the accident occurred in the afternoon window of physiological sleepiness. In addition to these findings, evidence that fatigue affected performance was suggested by the cockpit voice recorder (CVR) transcript as well as in the captain's testimony. Examples from the CVR showed degraded decision-making skills, fixation, and slowed responses, all of which can be affected by fatigue; also, the captain testified to feeling "lethargic and indifferent" just prior to the accident. Therefore, the sleep/wake history data supports the hypothesis that fatigue was a factor that affected crewmembers' performance. Furthermore, the examples from the CVR and the captain's testimony support the hypothesis that the fatigue had an impact on specific actions involved in the occurrence of the accident.

Rosekind, Mark R.↗

Accident Precursor Analysis and Management: Reducing Technological Risk Through Diligence

Almost every year there is at least one technological disaster that highlights the challenge of managing technological risk. On February 1, 2003, the space shuttle Columbia and her crew were lost during reentry into the atmosphere. In the summer of 2003, there was a blackout that left millions of people in the northeast United States without electricity. Forensic analyses, congressional hearings, investigations by scientific boards and panels, and journalistic and academic research have yielded a wealth of information about the events that led up to each disaster, and questions have arisen. Why were the events that led to the accident not recognized as harbingers? Why were risk-reducing steps not taken? This line of questioning is based on the assumption that signals before an accident can and should be recognized. To examine the validity of this assumption, the National Academy of Engineering (NAE) undertook the Accident Precursors Project in February 2003. The project was overseen by a committee of experts from the safety and risk-sciences communities. Rather than examining a single accident or incident, the committee decided to investigate how different organizations anticipate and assess the likelihood of accidents from accident precursors. The project culminated in a workshop held in Washington, D.C., in July 2003. This report includes the papers presented at the workshop, as well as findings and recommendations based on the workshop results and committee discussions. The papers describe precursor strategies in aviation, the chemical industry, health care, nuclear power and security operations. In addition to current practices, they also address some areas for future research.

Phimister, James R.↗

NASA Structural Analysis Report on the American Airlines Flight 587 Accident - Local Analysis of the Right Rear Lug

A detailed finite element analysis of the right rear lug of the American Airlines Flight 587 - Airbus A300-600R was performed as part of the National Transportation Safety Board s failure investigation of the accident that occurred on November 12, 2001. The loads experienced by the right rear lug are evaluated using global models of the vertical tail, local models near the right rear lug, and a global-local analysis procedure. The right rear lug was analyzed using two modeling approaches. In the first approach, solid-shell type modeling is used, and in the second approach, layered-shell type modeling is used. The solid-shell and the layered-shell modeling approaches were used in progressive failure analyses (PFA) to determine the load, mode, and location of failure in the right rear lug under loading representative of an Airbus certification test conducted in 1985 (the 1985-certification test). Both analyses were in excellent agreement with each other on the predicted failure loads, failure mode, and location of failure. The solid-shell type modeling was then used to analyze both a subcomponent test conducted by Airbus in 2003 (the 2003-subcomponent test) and the accident condition. Excellent agreement was observed between the analyses and the observed failures in both cases. From the analyses conducted and presented in this paper, the following conclusions were drawn. The moment, Mx (moment about the fuselage longitudinal axis), has significant effect on the failure load of the lugs. Higher absolute values of Mx give lower failure loads. The predicted load, mode, and location of the failure of the 1985-certification test, 2003-subcomponent test, and the accident condition are in very good agreement. This agreement suggests that the 1985-certification and 2003- subcomponent tests represent the accident condition accurately. The failure mode of the right rear lug for the 1985-certification test, 2003-subcomponent test, and the accident load case is identified as a cleavage-type failure. For the accident case, the predicted failure load for the right rear lug from the PFA is greater than 1.98 times the limit load of the lugs. I.

Raju, Ivatury S↗

Causal Factors and Adverse Events of Aviation Accidents and Incidents Related to Integrated Vehicle Health Management

Causal factors in aviation accidents and incidents related to system/component failure/malfunction (SCFM) were examined for Federal Aviation Regulation Parts 121 and 135 operations to establish future requirements for the NASA Aviation Safety Program s Integrated Vehicle Health Management (IVHM) Project. Data analyzed includes National Transportation Safety Board (NSTB) accident data (1988 to 2003), Federal Aviation Administration (FAA) incident data (1988 to 2003), and Aviation Safety Reporting System (ASRS) incident data (1993 to 2008). Failure modes and effects analyses were examined to identify possible modes of SCFM. A table of potential adverse conditions was developed to help evaluate IVHM research technologies. Tables present details of specific SCFM for the incidents and accidents. Of the 370 NTSB accidents affected by SCFM, 48 percent involved the engine or fuel system, and 31 percent involved landing gear or hydraulic failure and malfunctions. A total of 35 percent of all SCFM accidents were caused by improper maintenance. Of the 7732 FAA database incidents affected by SCFM, 33 percent involved landing gear or hydraulics, and 33 percent involved the engine and fuel system. The most frequent SCFM found in ASRS were turbine engine, pressurization system, hydraulic main system, flight management system/flight management computer, and engine. Because the IVHM Project does not address maintenance issues, and landing gear and hydraulic systems accidents are usually not fatal, the focus of research should be those SCFMs that occur in the engine/fuel and flight control/structures systems as well as power systems.

Reveley, Mary S.↗

NASA Accident Precursor Analysis Handbook, Version 1.0

Catastrophic accidents are usually preceded by precursory events that, although observable, are not recognized as harbingers of a tragedy until after the fact. In the nuclear industry, the Three Mile Island accident was preceded by at least two events portending the potential for severe consequences from an underappreciated causal mechanism. Anomalies whose failure mechanisms were integral to the losses of Space Transportation Systems (STS) Challenger and Columbia had been occurring within the STS fleet prior to those accidents. Both the Rogers Commission Report and the Columbia Accident Investigation Board report found that processes in place at the time did not respond to the prior anomalies in a way that shed light on their true risk implications. This includes the concern that, in the words of the NASA Aerospace Safety Advisory Panel (ASAP), "no process addresses the need to update a hazard analysis when anomalies occur" At a broader level, the ASAP noted in 2007 that NASA "could better gauge the likelihood of losses by developing leading indicators, rather than continue to depend on lagging indicators". These observations suggest a need to revalidate prior assumptions and conclusions of existing safety (and reliability) analyses, as well as to consider the potential for previously unrecognized accident scenarios, when unexpected or otherwise undesired behaviors of the system are observed. This need is also discussed in NASA's system safety handbook, which advocates a view of safety assurance as driving a program to take steps that are necessary to establish and maintain a valid and credible argument for the safety of its missions. It is the premise of this handbook that making cases for safety more experience-based allows NASA to be better informed about the safety performance of its systems, and will ultimately help it to manage safety in a more effective manner. The APA process described in this handbook provides a systematic means of analyzing candidate accident precursors by evaluating anomaly occurrences for their system safety implications and, through both analytical and deliberative methods used to project to other circumstances, identifying those that portend more serious consequences to come if effective corrective action is not taken. APA builds upon existing safety analysis processes currently in practice within NASA, leveraging their results to provide an improved understanding of overall system risk. As such, APA represents an important dimension of safety evaluation; as operational experience is acquired, precursor information is generated such that it can be fed back into system safety analyses to risk-inform safety improvements. Importantly, APA utilizes anomaly data to predict risk whereas standard reliability and PRA approaches utilize failure data which often is limited and rare.

Groen, Frank↗

Preliminary Analysis of Aircraft Loss of Control Accidents: Worst Case Precursor Combinations and Temporal Sequencing

Aircraft loss of control (LOC) is a leading cause of fatal accidents across all transport airplane and operational classes, and can result from a wide spectrum of hazards, often occurring in combination. Technologies developed for LOC prevention and recovery must therefore be effective under a wide variety of conditions and uncertainties, including multiple hazards, and their validation must provide a means of assessing system effectiveness and coverage of these hazards. This requires the definition of a comprehensive set of LOC test scenarios based on accident and incident data as well as future risks. This paper defines a comprehensive set of accidents and incidents over a recent 15 year period, and presents preliminary analysis results to identify worst-case combinations of causal and contributing factors (i.e., accident precursors) and how they sequence in time. Such analyses can provide insight in developing effective solutions for LOC, and form the basis for developing test scenarios that can be used in evaluating them. Preliminary findings based on the results of this paper indicate that system failures or malfunctions, crew actions or inactions, vehicle impairment conditions, and vehicle upsets contributed the most to accidents and fatalities, followed by inclement weather or atmospheric disturbances and poor visibility. Follow-on research will include finalizing the analysis through a team consensus process, defining future risks, and developing a comprehensive set of test scenarios with correlation to the accidents, incidents, and future risks. Since enhanced engineering simulations are required for batch and piloted evaluations under realistic LOC precursor conditions, these test scenarios can also serve as a high-level requirement for defining the engineering simulation enhancements needed for generating them.

Belcastro, Christine M.↗