Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Dynamic Risk Assessment”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

Quantifying the Sensitivity of Condition Incidence Parameters in the Evidence Library

One approach to quantifying spaceflight risk at NASA makes use event driven probabilistic techniques. The Medical Extensible Dynamic Probabilistic Risk Assessment Tool (MEDPRAT) is such a tool that estimates medical risk metrics via simulation and enables optimization of medical resources subject to mission constraints [1]. Previous analyses have informed medical set composition, exercise countermeasures, and water intake, where each analysis quantifies the risk associated with proposed variations in system design. As future mission profiles extend beyond Low-Earth Orbit (LEO) and lengthen in duration, understanding these risks and contributing factors is critical. MEDPRAT employs Monte Carlo sampling techniques to simulate missions and track the occurrence of medical events. These events follow fault-tree-like progressions through levels of severity and mitigation via medical treatment to many possible outcomes and these are reported throughout the mission. Making this possible, are the medical databases that contain evidence gathered by the Human Research Program (HRP). Quantifying the impact of uncertainty or variability in the input data is an important step in evaluating the credibility of modeling and simulation results. In this work, we investigate the sensitivity of medical risk metrics with respect to the condition incidence parameters within the Evidence Library (EL) [2] as the medical database input for MEDPRAT. The medical conditions, contained in the EL, are equipped with incidence rates that describe the likelihood that the condition will occur. These incidence rates reflect historical spaceflight data or when appropriate, terrestrial data. In this presentation, we will explore how uncertainty in these rates propagate to the medical risk described by MEDPRAT. These results identify the conditions and parameters with the largest contribution to medical risks.

Ian Lim↗

Dynamic HRA for FLEX

In the presentation, previous efforts for FLEX dynamic HRA, PRIMERA-HRA method and its application to an ELAP scenario are introduced.

99 GENERAL AND MISCELLANEOUS↗

AUTOMATIC GENERATION OF EVENT TREES AND FAULT TREES: A MODEL-BASED APPROACH

In the past few decades, increasing complexity in modern engineering systems has been driven by the integration of a large number of components and by the fact that the system operations involve many disciplines (e.g., thermal-hydraulics, plant operations, cyber-security). Current safety/reliability modeling approaches to such systems are labor intensive, difficult to learn, and rely heavily on simplistic Boolean logic to depict failure propagation and accident progression. While these methods serve well for simple systems (i.e., linear causal systems with limited small inter- and intra-system interactions), their results are difficult to verify when modeling complex systems (typically performed through the extensive use of modeling assumptions). The development of new methods is addressed to meet these challenges through a model-based system engineering (MBSE) lens. Under MBSE philosophy, every aspect of the system (form or function) is represented by a model that completely characterizes its architecture or behavior. MBSE approach greatly improves the management of design, analysis and verification of complex systems. An integration of Dynamic Probabilistic Risk Assessment (DPRA) methods with MBSE models is proposed to perform safety/reliability analyses of engineering systems. In particular, MBSE representation of the system (performed using Systems Modeling Language [SysML]) is coupled with DPRA methods to automatically generate event trees and fault trees.

97 - MATHEMATICS AND COMPUTING↗

Rancor-HUNTER: Using a Simulator Engine for Realistic Human Performance Modeling of Nuclear Power Operations

The Human Unimodel for Nuclear Technology to Enhance Reliability (HUNTER) is a software system to simulate human performance in support of human reliability analysis (HRA) in nuclear power plants. This paper summarizes recent work to integrate HUNTER with a plant simulator, namely the Rancor Microworld Simulator. Rancor is an offshoot of earlier work at Idaho National Laboratory (INL) to support plant modernization. The graphical software tools used to mimic digital human-system interface upgrades at INL’s Human Systems Simulation Laboratory were linked to the Rancor Microworld Simulator, an INL-developed simplified plant model. HUNTER becomes a “virtual operator” coupled to the Rancor simulator, thereby allowing a tight coupling between a digital human twin and a digital twin of the plant. Rancor-HUNTER may be run through Monte Carlo iterations across a dynamic range of performance shaping factors, thereby producing distributions of human performance in terms of procedure paths, errors instantiations, and task durations. This paper overviews the various unique features of Rancor-HUNTER and presents an example run of Rancor-HUNTER for a startup scenario.

99 - GENERAL AND MISCELLANEOUS↗

Event-modeled Risk Assessment Using Linked Diagrams

Event Modeling Risk Assessment using Linked Diagrams (EMRALD) is a software tool developed at INL for researching the capabilities of dynamic PRA (Probabilistic Risk Assessment). In order to promote the effective use of dynamic PRA by the general community, EMRALD focuses on the following key aspects: Simplifying the modeling process by providing a structure that corresponds to traditional PRA modeling methods Providing a user interface (UI) that makes it easy for the user to model and visualize complex interactions Allowing the user to couple with other analysis applications such as physics based simulations. This includes one-way communication for most applications and two-way loose coupling for customizable applications Providing the sequence and timing of events that lead to the specified outcomes when calculating results Traditional aspects of components with basic events, fault trees, and event trees are all captured in a dynamic framework of state diagrams, which are displayed.

Prescott, SteveR↗

Data Mining of Historical Human Data to Assess the Risk of Injury due to Dynamic Loads

The NASA Occupant Protection Group is charged with ensuring crewmembers are protected during all dynamic phases of spaceflight. Previous work with outside experts has led to the development of a definition of acceptable risk (DAR) for space capsule vehicles. The DAR defines allowable probability rates for various categories of injuries. An important question is how to validate these probabilities for a given vehicle. One approach is to impact test human volunteers under projected nominal landing loads. The main drawback is the large number of subject tests required to attain a reasonable level of confidence that the injury probability rates would meet those outlined in the DAR. An alternative is to mine existing databases containing human responses to impact. Testing an anthropomorphic test device (ATD) at the same human‐exposure levels could yield a range of ATD responses that would meet DAR. As one aspect of future vehicle validation, the ATD could be tested in the vehicle's seat and suit configuration at nominal landing loads and compared with the ATD responses supported by the human data set. This approach could reduce the number of human‐volunteer tests NASA would need to conduct to validate that a vehicle meets occupant protection standards. METHODS: The U.S. Air Force has recorded hundreds of human responses to frontal, lateral, and spinal impacts at many acceleration levels and pulse durations. All of this data are stored on the Collaborative Biomechanics Data Network (CBDN), which is maintained by the Wright Patterson Air Force Base (WPAFB). The test device for human occupant restraint (THOR) ATD was impact tested on WPAFB's horizontal impulse accelerator (HIA) matching human‐volunteer exposures on the HIA to 5 frontal and 3 spinal loading conditions. No human injuries occurred as a result of these impact conditions. Peak THOR response variables for neck axial tension and compression, and thoracic‐spine axial compression were collected. Maximal chest deflection was determined from motion capture video of the impact test. HIC‐ 15 and BRIC were calculated from head acceleration responses. Given the number of human subjects for each test condition a confidence interval of injury probability will be obtained. RESULTS: Results will be discussed in terms of injury‐risk probability estimates based on the human data set evaluated. Also, gaps in the data set will be identified. These gaps could be one of two types. One is areas where additional THOR testing would increase the comparable human data set, thereby improving confidence in the injury probability rate. The other is where additional human testing would assist in obtaining information on other acceleration levels or directions. DISCUSSION: The historical human data showed validity of the THOR ATD for supplemental testing. The historical human data are limited in scope, however. Further data are needed to characterize the effects of sex, age, anthropometry, and deconditioning due to spaceflight on risk of injury

Wells, Jesica↗

Risk Identification and Visualization in a Concurrent Engineering Team Environment

Incorporating risk assessment into the dynamic environment of a concurrent engineering team requires rapid response and adaptation. Generating consistent risk lists with inputs from all the relevant subsystems and presenting the results clearly to the stakeholders in a concurrent engineering environment is difficult because of the speed with which decisions are made. In this paper we describe the various approaches and techniques that have been explored for the point designs of JPL's Team X and the Trade Space Studies of the Rapid Mission Architecture Team. The paper will also focus on the issues of the misuse of categorical and ordinal data that keep arising within current engineering risk approaches and also in the applied risk literature.

Risk Scoring↗

Performing Numerical Analysis of Cybersecurity Options Using Dynamic Risk Analysis Tool EMRALD

Cyberattacks can have many different attack paths, durations, and goals. There are also many different mitigation options involving hardware, software, and/or humans. Considering a cyber threat should involve defense-in-depth methods and a quantitative or numerical evaluation of overall effectiveness against dynamic, time-dependent attacks to make cost and risk-informed decisions. Typical cyberattack modeling methods only provide a qualitative evaluation. The main areas of cybersecurity are confidentiality, integrity, and availability. For companies with cyber-physical systems such as advanced nuclear reactors, cyber-related safety is a requirement set by North American Electric Reliability and the U.S. Nuclear Regulatory Commission. They are also concerned about availability or reliability as a business case. As cyber threats are evolving to a business-for-hire structure, more attacks may focus on disrupting business success and reliability, causing financial and economic stability risk. Companies want to know business reliability and recovery from those threats, and that requires modeling physical behavior of the targets. Dynamic-state-based and Markov-based modeling provides a method for better cyber scenario modeling with different tools having issues such as state-base explosion. Dynamic modeling enables time and conditional features not found in other numerical evaluation methods. EMRALD (Event Modeling Risk Assessment using Lined Diagrams) is a dynamic risk analysis modeling and simulation tool and has features that reduce modeling issues. It has been used to model different time-dependent events including plant behavior and operator procedures. As a general modeling tool, EMRALD can also be used to model cyberattack scenarios with varying mitigation options and quantify effectiveness, producing numerical data for risk-informed decisions. This paper uses EMRALD to demonstrate that dynamic numerical risk analysis can be used for cyber threat modeling to provide insights for design decision-making and optimize defense strategies. Keywords: cyber modeling; cyber-physical systems; numerical cyber modeling

97 - MATHEMATICS AND COMPUTING↗

Dynamic Positioning System (DPS) Risk Analysis Using Probabilistic Risk Assessment (PRA)

The National Aeronautics and Space Administration (NASA) Safety & Mission Assurance (S&MA) directorate at the Johnson Space Center (JSC) has applied its knowledge and experience with Probabilistic Risk Assessment (PRA) to projects in industries ranging from spacecraft to nuclear power plants. PRA is a comprehensive and structured process for analyzing risk in complex engineered systems and/or processes. The PRA process enables the user to identify potential risk contributors such as, hardware and software failure, human error, and external events. Recent developments in the oil and gas industry have presented opportunities for NASA to lend their PRA expertise to both ongoing and developmental projects within the industry. This paper provides an overview of the PRA process and demonstrates how this process was applied in estimating the probability that a Mobile Offshore Drilling Unit (MODU) operating in the Gulf of Mexico and equipped with a generically configured Dynamic Positioning System (DPS) loses location and needs to initiate an emergency disconnect. The PRA described in this paper is intended to be generic such that the vessel meets the general requirements of an International Maritime Organization (IMO) Maritime Safety Committee (MSC)/Circ. 645 Class 3 dynamically positioned vessel. The results of this analysis are not intended to be applied to any specific drilling vessel, although provisions were made to allow the analysis to be configured to a specific vessel if required.

Thigpen, Eric B.↗

Dynamic Positioning System (DPS) Risk Analysis Using Probabilistic Risk Assessment (PRA)

The National Aeronautics and Space Administration (NASA) Safety & Mission Assurance (S&MA) directorate at the Johnson Space Center (JSC) has applied its knowledge and experience with Probabilistic Risk Assessment (PRA) to projects in industries ranging from spacecraft to nuclear power plants. PRA is a comprehensive and structured process for analyzing risk in complex engineered systems and/or processes. The PRA process enables the user to identify potential risk contributors such as, hardware and software failure, human error, and external events. Recent developments in the oil and gas industry have presented opportunities for NASA to lend their PRA expertise to both ongoing and developmental projects within the industry. This paper provides an overview of the PRA process and demonstrates how this process was applied in estimating the probability that a Mobile Offshore Drilling Unit (MODU) operating in the Gulf of Mexico and equipped with a generically configured Dynamic Positioning System (DPS) loses location and needs to initiate an emergency disconnect. The PRA described in this paper is intended to be generic such that the vessel meets the general requirements of an International Maritime Organization (IMO) Maritime Safety Committee (MSC)/Circ. 645 Class 3 dynamically positioned vessel. The results of this analysis are not intended to be applied to any specific drilling vessel, although provisions were made to allow the analysis to be configured to a specific vessel if required.

Thigpen, Eric B.↗

PSA 2025 DPRA for Cyber Optimization

Cyberattacks can have many different attack paths, durations, and goals. There are also many different mitigation options involving hardware, software, and/or humans. Evaluating defense options should include quantitative evaluation of overall effectiveness to make cost and risk-informed decisions. Typical cyberattack modeling methods only provide a qualitative evaluation and have difficulty with time dependent scenarios. The main areas of cybersecurity are confidentiality, integrity, and availability. For companies with cyber-physical systems such as advanced nuclear reactors, cyber-related integrity is a requirement set by the U.S. Nuclear Regulatory Commission. But companies are also concerned about availability or reliability as a business case. As cyber threats are evolving to a business-for-hire structure, more attacks focus on disrupting business success and reliability, causing financial and economic stability risk. Companies want reliability analysis while optimizing cost, which requires more than safety modeling methods. Dynamic-state-based and Markov-based modeling provides a method for better cyber scenario modeling with timing and conditional features not found in other numerical evaluation methods. EMRALD (Event Modeling Risk Assessment using Lined Diagrams) is a dynamic risk analysis modeling and simulation tool and has features that reduce modeling issues such as state-base explosion found in Markov-based tools. It has been used to model different time-dependent events including plant behavior and operator procedures. As a general modeling tool, EMRALD can also be used to model cyberattack scenarios with varying mitigation options and quantify effectiveness, producing numerical data for risk-informed decisions. This paper uses EMRALD to demonstrate that dynamic risk analysis can be used for cyber threat modeling to provide insights for design decision-making and optimize defense strategies.

97 - MATHEMATICS AND COMPUTING↗

System risk quantification and decision making support using functional modeling and dynamic Bayesian network

Risk-informed decision-making requires a probabilistic assessment of the likelihood of success of control action, given the system status. This paper presents a systematic state transition modeling approach integrating dynamic probabilistic risk assessment with a decision-making process using a dynamic Bayesian network (DBN) coupled with functional modeling. A functional model designed with multilevel flow modeling (MFM) technique was used to build a system state structure inferred by energy, mass, and information flow so that one can verify the developed model with respect to system functionality. The MFM model represents the causal relationship among the nodes, which captures the structure of process parameters and control units. Each node may have multiple possible states, and the DBN structured by the MFM model represents the time-domain transitions among the defined states. Furthermore, the MFM-DBN integrated state transition modeling is a white-box approach that allows one to draw the system's risk profile by updating the system states and supports the decisions probabilistically with physical inference. An example of a simple heating system has been used to illustrate this process, including decision-making support based on quantitative risk profile. For demonstrating its applicability to a complex system operational decision making, a case study of station blackout accident scenario leading to the seal loss of coolant accident in a nuclear power plant is presented. The proposed approach effectively provided the risk profile along time for each option so that the operators can make the best decision, which minimizes the plant risk.

42 ENGINEERING↗

Integrating static PRA information with risk informed safety margin characterization (RISMC) simulation methods

The overall objective of the project was to develop a computationally feasible and user-friendly mechanized process to integrate traditional probabilistic risk assessment (PRA) and dynamic PRA (DPRA) results. Starting with the systematic identification of items in an existing PRA that need dynamic augmentation, the project used a generic 4-loop pressurized reactor (PWR) and 3-loop PWR as example plants. Station blackout (SBO) and large break loss of coolant accident SBLOCA) were selected as the example initiating events. Using the traditional event-tree (ET)/fault-tree (FT) methodology augmented by dynamic evet tree approach, the potential consequences of the initiating events were simulated with RELAP-3D and MELCOR/RASCAL codes to cover Level 1 through Level 3 of PRA. RAVEN and ADAPT software were used to generate Level 1 simulations with RELAP-3D and Level 2/3 simulations with MELCOR (Level 2)/RASCAL (Level 3), respectively. Example branching conditions (BCs) for SBO included AC power recovery time, valve repair failure time, reactor coolant pump leak time/break size and emergency power supply duration to a total of 9. Example BCs for LOCA included off-site power recovery time, diesel generator power recovery time, auxiliary feed water system operation time, safety relief valve failure to open upon demand, reactor coolant pump seal break time and size to a total of 21. Each RELAP-3D simulation (9,587 scenarios) was labelled OK or Core Damage based on the maximum allowed peak clad temperature (2,100oF). Each MELCOR simulation (4610 scenarios) was labeled as Bin over 10rem or Bin 0-10rem based on the dose at the site boundary. The scenarios were clustered based on the criteria above using the mean shift methodology. Classical PRA (CPRA) and DPRA results were compared to identify the ET sequences that need DPRA augmentation. Several approaches were proposed for the incorporation of these sequences into CPRA using clustering with the mean shift methodology, restructuring the CPRA ETs by adding new BCs/sequences, and using the concept of a limit surface. Procedures for decision making regarding the possible consequences of an initiating event (e.g. core damage or not, site evacuation or not) were developed using a convolutional neural network (CNN), a recurrent neural network (RNN) and a transformer neural network (TNN). The project has led to two PhD degrees, three archival journal papers and five refereed conference proceedings.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Engineering Risk Assessment of Space Thruster Challenge Problem

The Engineering Risk Assessment (ERA) team at NASA Ames Research Center utilizes dynamic models with linked physics-of-failure analyses to produce quantitative risk assessments of space exploration missions. This paper applies the ERA approach to the baseline and extended versions of the PSAM Space Thruster Challenge Problem, which investigates mission risk for a deep space ion propulsion system with time-varying thruster requirements and operations schedules. The dynamic mission is modeled using a combination of discrete and continuous-time reliability elements within the commercially available GoldSim software. Loss-of-mission (LOM) probability results are generated via Monte Carlo sampling performed by the integrated model. Model convergence studies are presented to illustrate the sensitivity of integrated LOM results to the number of Monte Carlo trials. A deterministic risk model was also built for the three baseline and extended missions using the Ames Reliability Tool (ART), and results are compared to the simulation results to evaluate the relative importance of mission dynamics. The ART model did a reasonable job of matching the simulation models for the baseline case, while a hybrid approach using offline dynamic models was required for the extended missions. This study highlighted that state-of-the-art techniques can adequately adapt to a range of dynamic problems.

Assessment↗

New Approach Methodology for Assessing Inhalation Risks of a Contact Respiratory Cytotoxicant: Computational Fluid Dynamics-Based Aerosol Dosimetry Modeling for Cross-Species and In Vitro Comparisons

Regulatory agencies are considering alternative approaches to assessing inhalation toxicity that utilizes in vitro studies with human cells and in silico modeling in lieu of additional animal studies. In support of this goal, computational fluid-particle dynamics models were developed to estimate site-specific deposition of inhaled aerosols containing the fungicide, chlorothalonil, in the rat and human for comparisons to prior rat inhalation studies and new human in vitro studies. Under bioassay conditions, the deposition was predicted to be greatest at the front of the rat nose followed by the anterior transitional epithelium and larynx corresponding to regions most sensitive to local contact irritation and cytotoxicity. For humans, simulations of aerosol deposition covering potential occupational or residential exposures (1–50 µm diameter) were conducted using nasal and oral breathing. Aerosols in the 1–5 µm range readily penetrated the deep region of the human lung following both oral and nasal breathing. Under actual use conditions (aerosol formulations >10 µm), the majority of deposited doses were in the upper conducting airways. Beyond the nose or mouth, the greatest deposition in the pharynx, larynx, trachea, and bronchi was predicted for aerosols in the 10–20 µm size range. Only small amounts of aerosols >20 µm penetrated past the pharyngeal region. Using the ICRP clearance model, local retained tissue dose metrics including maximal concentrations and areas under the curve were calculated for each airway region following repeated occupational exposures. These results are directly comparable with benchmark doses from in vitro toxicity studies in human cells leading to estimated human equivalent concentrations that reduce the reliance on animals for risk assessments.

63 RADIATION, THERMAL, AND OTHER ENVIRON. POLLUTAN↗

Tactical Analysis for Calculating Contextual Risk at Boundaries: Summary of Laboratory Directed Research & Development Effort

The Tactical Analysis for Calculating Contextual Risk at Boundaries (TACCRAB) tool is an innovative digital twin (DT) platform and automated risk algorithm designed to transform operational decision-making in structured screening environments, with an initial focus on Southern Border Land Ports of Entry (POEs). The invention provides integration points for advanced artificial intelligence, predictive modeling, and real-time data analysis to produce a comprehensive risk management tool that enables proactive, data-informed security strategies. The core inventive features of TACCRAB center on its unique risk algorithm, which dynamically calculates contextual risk by synthesizing historical data, near real-time streaming data from the checkpoints themselves, and AI-generated predictions. Unlike traditional risk assessment methods, TACCRAB utilizes a DT to provide comprehensive operational insights, allowing stakeholders to visualize, simulate, and optimize checkpoint configurations with unprecedented speed and contextual awareness. TACCRAB's key innovation lies in its ability to combine multiple complex inputs - including technology detection probabilities, resource availability, screening pathway characteristics, and threat actor behavioral patterns - into a unified risk calculation and update these inputs based on changing operational and environmental conditions. By leveraging a DT that continuously updates and learns from linked data, TACCRAB can suggest adaptive mitigation strategies that minimize risk while maintaining operational efficiency. Particularly novel is the platform's approach to decision support, which goes beyond static risk assessment. The DT provides dynamic metrics such as wait times, resource allocation effectiveness, and potential emerging threat scenarios, enabling users to view sophisticated, relevant what-if simulations and optimize checkpoint operations in near real-time. The system's architecture allows for generalized application across different screening environments, such as secure facilities, ports of entry, and soft targets, making it a versatile tool for security and operational management. The invention distinguishes itself through its comprehensive integration of predictive modeling, AI-driven pattern discovery, and user-friendly interface design. By combining these elements, TACCRAB transforms complex risk data into actionable insights, supporting decision-makers at various organizational levels - from booth agents making split-second screening decisions to checkpoint managers optimizing the day's resource allocation to strategic planners managing long-term investments.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗