Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Risk-Informed Approach”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

A Risk-Informed Approach to Trustworthiness Assessment in Digital Twins-Based Autonomous Control

In autonomous control systems, digital twins (DTs) are used to perform diagnostic and prognostic functions. The trustworthiness of these DTs is dependent on quality and coverage of the training data, model accuracy and integrity of sensor data. This work introduces a methodology to determine the trustworthiness of a DT system given faulty sensor data using a risk informed approach. Bayesian Belief Networks (BBNs) are used to propagate uncertainties and determine the probability of trustable recommendations. The decision to trust the control action provided by the DT is based on the DT output, expert opinion, and severity of problems. The performance of DTs is reliant on the data they are trained on. When they encounter out of distribution data, the trustworthiness of the recommendations decreases. To address this issue, we include an expert component that provides input on sensor degradation. For this, we utilize a generative artificial intelligence (AI) model, such as Generative Pretrained Transformer (GPT). The GPT functions as an expert with broad knowledge. The GPT is fine-tuned to understand and discriminate sensor degradation scenarios using manufactured data. This methodology is demonstrated through a case study on a Nearly Autonomous Management and Control System (NAMAC) during a steady state scenario. Various sensor degradation types with different severity levels are considered. Degraded sensor data is processed by the DT system and the fine-tuned GPT. Finally, using the BBN, we combine the GPT information and the DT output with its sources of uncertainty. This provides an output regarding the trustworthiness of the DT recommendation.

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

Risk-informed Graded Approach for Reliability and Performance Assessment of Machine Learning and Artificial Intelligence for Advanced Condition Monitoring Techniques

With the shift away from time-based maintenance and toward condition-based maintenance, and to reduce overall maintenance costs, there has been an upsurge in the usage and development of advanced condition monitoring (ACM) techniques for real-time monitoring of nuclear power plant (NPP) components. ACM is particularly useful in the development of digital twins, which are designed to predict the failure or degradation of plant components. Successful implementation of ACM requires an assessment to inform the development of a risk-informed approach to evaluate the use of ACM to meet Nuclear Regulatory Committee (NRC) regulations for in-service testing (IST) programs. This includes the monitoring and diagnostics of reactor components and systems in current, new, and advanced reactors. A key component in ACM is the usage of machine learning (ML) and artificial intelligence (AI) algorithms that can employ real-time data from instrumentation and sensors to detect and predict reactor component degradations. Such predictive capabilities enable early detection of component degradation so as to help plant personnel plan and execute necessary maintenance. For successful implementation of ML/AI in ACM such that regulatory requirements are met, a risk-informed graded approach is needed to assess the reliability and performance of ML/AI for ACM. The American Society for Mechanical Engineers (ASME) developed their Operations and Maintenance (O&M) Code to provide guidance on safe, reliable O&M of NPPs. The IST section of the O&M Code specifically establishes requirements for IST and examination to gauge operational readiness of components in water-cooled NPPs. This paper presents a state-of-the-art review of how reliability and risk assessment can be integrated with ACM to assess component performance by non-nuclear industries. This is followed by different methodologies and approaches for conducting performance and reliability assessments so as to meet IST requirements for NPP components.

97 - MATHEMATICS AND COMPUTING↗

Risk-informed Graded Approach for Reliability and Performance Assessment for Advanced Condition Monitoring Techniques

With the shift away from time-based maintenance and toward condition-based maintenance, and to reduce overall maintenance costs, there has been an upsurge in the usage and development of advanced condition monitoring (ACM) techniques for real-time monitoring of nuclear power plant (NPP) components. ACM is particularly useful in the development of digital twins, which are designed to predict the failure or degradation of plant components. Successful implementation of ACM requires an assessment to inform the development of a risk-informed approach to evaluate the use of ACM to meet Nuclear Regulatory Committee (NRC) regulations for in-service testing (IST) programs. This includes the monitoring and diagnostics of reactor components and systems in current, new, and advanced reactors. A key component in ACM is the usage of machine learning (ML) and artificial intelligence (AI) algorithms that can employ real-time data from instrumentation and sensors to detect and predict reactor component degradations. Such predictive capabilities enable early detection of component degradation so as to help plant personnel plan and execute necessary maintenance. For successful implementation of ML/AI in ACM such that regulatory requirements are met, a risk-informed graded approach is needed to assess the reliability and performance of ML/AI for ACM. The American Society for Mechanical Engineers (ASME) developed their Operations and Maintenance (O&M) Code to provide guidance on safe, reliable O&M of NPPs. The IST section of the O&M Code specifically establishes requirements for IST and examination to gauge operational readiness of components in water-cooled NPPs. This paper presents a state-of-the-art review of how reliability and risk assessment can be integrated with ACM to assess component performance by non-nuclear industries. This is followed by different methodologies and approaches for conducting performance and reliability assessments so as to meet IST requirements for NPP components.

99 - GENERAL AND MISCELLANEOUS↗

Risk-informed Graded Approach for Reliability and Performance Assessment of Sensor and Instrumentation Systems within Advanced Condition Monitoring Technologies

Advanced condition monitoring (ACM) technologies, such as digital twins, are innovative strategies designed to provide real-time health insights, including the remaining useful life of components. The primary goal of ACM is to predict and alert operators to potential functional failures before they occur. ACM systems achieve this by integrating predictive models with various sensor instrumentation, analog-to-digital converters, data warehouses, and data pre-processors. These sensor and instrumentation systems (SIS) are essential for forming a comprehensive understanding of component conditions and ensuring the predictive success of ACM programs. Introducing new technologies like ACM involves varying degrees of risk that can impact plant reliability. Therefore, risk mitigation should be commensurate with the performance and reliability of the developed technology, following a risk-informed graded approach (RIGA). Establishing a RIGA process requires a clear understanding of the hazards and reliability of all subsystems, including their interdependencies and potential impacts on the overall system. Given the critical role of SIS in ACM, this work reviews hazard identification and reliability quantification methods for SIS. It also considers these methods' implications when developing a RIGA process for ACM.

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

Hungary 908 Event - Risk Based Graded Approach to ITM

This presentation, Risk-Based, Graded Approach to Insider Threat Mitigation: Human Measures, introduces a structured framework for managing insider threat risk using internationally recognized guidance from the International Atomic Energy Agency (IAEA) Nuclear Security Series No. 8-G (Rev. 1) and the Joint Statement on Mitigating Insider Threats (INFCIRC/908). The presentation emphasizes that effective insider threat mitigation (ITM) depends on both positional controls, which manage inherent risk based on access, authority, and knowledge, and human measures, which address residual risk reflected in behavior, motivation, and reliability. Using a risk-informed and graded approach, the presentation outlines methods for identifying and prioritizing high-risk positions, applying layered organizational controls, and integrating human reliability mechanisms such as the Behavior Observation Program (BOP), Fitness-for-Duty (FFD) evaluations, Employee Assistance Programs (EAP), and Nuclear Security Culture (NSC). The human-focused portion examines behavioral and organizational indicators of opportunity, vulnerability, motivation, and crisis, demonstrating how early detection, deterrence, and response can prevent insider events. The session concludes with a case review of the Millstone Nuclear Power Station incident involving engineer George Galatis. The case illustrates how weak leadership and a poor safety culture can create conditions for failure and how a comprehensive ITM framework could have altered the outcome. The objective of this presentation is to help practitioners apply a risk-based, graded philosophy to human factors and promote a culture of accountability, communication, and resilience within nuclear organizations.

99 - GENERAL AND MISCELLANEOUS↗

Consequence analyses of sabotage-induced radiological releases in sodium-cooled fast microreactors

Analysis of three sodium-cooled fast microreactors (SFMs) with thermal powers of 10, 30, and 50 MWt showed that smaller reactors result in lower radiological consequences during a postulated sabotage-induced event because of their reduced core inventory. All SFMs used U-10Zr metal fuel enriched to 15 wt% high-assay low-enriched uranium and operated until their respective effective multiplication factor (k eff ) reduced to less than 1 or until the end of their operational lifespan. Sabotage scenarios were simulated at this point, when the fuel inventory within the core contains the highest-level of radioactivity. Radionuclide core inventories were calculated using the SCALE code at shutdown and 3 days post-shutdown. Dose consequence analyses were performed for three sabotage scenarios using the RASCAL tool. As microreactor developers plan for minimal on-site or complete off-site emergency response, it remains essential to evaluate their physical protection needs and potential hazards, including assessing postulated sabotage-induced events that could become more relevant. SFM licensees should identify a credible worst-case, major accident, estimate release source terms, and perform dose consequence analyses to evaluate site-specific physical protection measures. In conclusion, this recommendation supports a risk-informed, performance-based approach, aligning with applicable regulatory requirements, i.e., 10 CFR Parts 100 and 53 rulemaking in the United States.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Consequence analyses of sabotage-induced radiological releases in high-temperature helium-cooled prismatic microreactors

Here, this study analyzes the radiological dose consequences of sabotage-induced accidents at three high-temperature helium-cooled prismatic microreactors (HTPMs) with thermal power ratings of 1, 10, and 50 MWt. Each HTPM employs uranium oxycarbide tristructural isotropic fuel enriched to 19.75 wt% high-assay low-enriched uranium. Simulations were conducted to estimate reactor core inventory at the point of fuel discharge––when the effective multiplication factor reduced to less than 1––representing peak radionuclide inventory. Postulated sabotage scenarios leading to reactor shutdown were analyzed at two intervals: immediately post-shutdown (0 h) and 3 days after shutdown using the SCALE code for radionuclide inventories and the RASCAL tool for dose consequences. Results show that although HTPMs benefit from inherent safety features and robust fuel design, radiological consequences scale with reactor power because of increased source term inventories. Smaller microreactors exhibited proportionally lower dose consequences. To support the economic and regulatory feasibility of microreactor deployment, this study emphasizes the value of a risk-informed, performance-based approach, as supported by regulations like 10 CFR Parts 100 and 53 in the United States. Microreactor developers should perform site-specific assessments of potential sabotage or low-probability, high-consequence events, especially when considering minimal on-site or full off-site emergency response.

Consequence↗

Radiological Releases from Novel Fuel Forms in Advanced Reactors During Severe Accidents for Consequence Analyses

Various advanced reactor developers are exploring the potential for reductions in the size of physical security forces and emergency planning zones. These reductions are based on robust fuel forms and inherently safe reactor designs. However, such reductions in physical protection measures could increase the risk of sabotage. To assess the possibility of reducing these measures, sabotage-induced radiological consequence analyses were carried out. These analyses considered accident scenarios that were beyond design basis accidents and overly conservative (Shah, 2025a; Shah, 2025b; Shah and Hartanto, 2026), yielding very large release fractions. These fractions, which can be used to evaluate physical protection and emergency planning requirements, have been crudely determined and applied as demonstrations for a sodium-cooled fast reactor (SFR) (Shah and Hartanto, 2025a), a high-temperature gas-cooled reactor (HTGR) (Shah and Hartanto, 2025b), a heat pipe–cooled reactor (HPR) (Shah and Hartanto, 2025c), and a molten salt–cooled reactor (MSR) (Shah et al., 2026). A Sandia National Laboratories (SNL) team used MELCOR—a fully integrated severe accident analysis code—to demonstrate the code’s capability to analyze advanced (i.e., not light water–cooled) reactors (including a fluoride salt–cooled high-temperature reactor [FHR]) and calculate radiological releases to the environment during severe accidents (Wagner et al., 2022a, 2022b, 2022c, 2023a, and 2023b). Although the analyses were carried out to demonstrate MELCOR’s growing capability, the release source terms were estimated for advanced reactors, providing valuable insights into the accident progression and radiological releases. These findings from prior SNL studies, including estimated source terms and related sensitivity studies, were leveraged to derive source terms for postulated sabotage-induced accidents. Insights from these sensitivity studies informed the scaling of SNL’s estimated source terms for the defined accident scenarios. The derived release fractions for the severe accident scenarios for the respective reactor designs can be used to perform more nuanced dose consequence analyses to evaluate the reactors’ physical protection and emergency planning zone requirements. These analyses are in accordance with the risk-informed, performance-based approach proposed under 10 CFR Part 53. This study builds on the prior source term analyses and associated sensitivity studies by SNL to derive time-dependent and design-informed release fractions. Section 2 describes the diverse advanced reactor designs analyzed by the SNL team. Section 3 discusses the severe accident analyses, the release fractions calculated, and the limitations and assumptions of the demonstration project. Section 4 presents the release percentages derived for the hypothetical sabotage-induced severe accidents at the advanced reactors. Section 5 summarizes the study’s findings and conclusions.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Defensive Cybersecurity Architecture Design Using Force-on-Force Cyber-Physical Modeling

Currently, nuclear power plant physical security systems are highly dependent on air-gaps as a protective measure against cyber-threats. Cyber-physical threats become more likely as advanced cyber-threat capabilities to jump air-gaps transition into common use. Defending against the emerging threat of cyber-enabled physical intrusions is poorly understood. The consequence of these cyber-physical attacks has no quantitative analysis method to inform risk-informed, performance-based cybersecurity approaches. By modifying the physical security simulation tool Dante, cyber-physical threat consequence was able to be analyzed on a notional facility. The results of this analysis are used to design a Defensive Cybersecurity Architecture (DCSA) for the physical security system to produce example resilience measures for this notional facility. A DCSA defines security levels to provide a graded approach for defending plant functions, and security zones for trusted communication between systems. This approach can be applied to real world systems to produce physical protection systems and response measures that are resilient to cyber-physical threats.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Diversion Path Analysis: A Proposed Methodology to Develop an MC&A Approach for Liquid-Fueled Molten Salt Reactors

Nuclear material control and accounting (MC&A) is a critical element of both the US Nuclear Regulatory Commission (NRC) and US Department of Energy (DOE)’s domestic safeguards and security requirements. NRC licensees are required, under Title 10 of the Code of Federal Regulations (10 CFR) Part 74 to establish and maintain an MC&A program that captures and records the quantities and locations of special nuclear material (SNM) at the facility. Along with physical protection, MC&A is a key element of domestic nuclear material safeguards that enables the NRC to ensure that SNM is controlled and accounted for. SNM, per 10 CFR Part 74, refers to plutonium, 233 U, and uranium enriched in the isotope 233 U or 235 U, but does not include source material. Periodic physical inventories, coupled with material balance evaluations, are effective and demonstrated tools to account for and detect theft or diversion of SNM in facilities containing SNM in bulk material form (i.e., not in discrete, countable items). Historically in the United States, these types of facilities have included fuel fabrication, conversion, and enrichment facilities. In comparison, reactors have relied on item counting of assemblies and control of SNM while in containment (e.g., a sealed reactor pressure vessel) because, to date, reactor fuel has been in item form. In liquid-fueled molten salt reactors (MSRs), unlike traditional light water reactors (LWRs) or bulk facilities, bulk SNM quantities can change significantly during operation as a result of depletion and transmutation. This introduces challenges to the use of traditional periodic physical inventories and material balance evaluations to detect theft or diversion of SNM in reactors that use SNM in bulk material form. Liquid-fueled (i.e., salt-fueled) MSR facilities are MSRs that use SNM within a salt eutectic as the fuel. The SNM is in a bulk material form any time it is outside of fresh or spent fuel storage containers. Some examples of when SNM will be in bulk form in the facility are during addition of fuel to the reactor system, while fuel is circulating in operation, and while fuel is in a drain tank. Periodic physical inventories and material balance evaluations can likely be effectively applied to many portions of an MSR facility, including all areas where depletion and transmutation are not significantly changing the quantities of SNM within the control area. Within an MSR facility, this would include fresh fuel receipt and loading, waste streams that may contain SNM, irradiated fuel storage outside of the reactor core, and any irradiated fuel processing that may happen after SNM has been removed from the reactor. All of these process steps could rely on measurements of SNM quantities compared with documented inventories. Any discrepancies from predicted (i.e., book) inventories and measured inventories could be quantified as inventory differences, consistent with traditional MC&A guidance from the NRC (e.g., in NUREG-1065 Revision 2, NUREG-2159 Revision 1, and RG 5.29 Revision 2). Within the reactor system, additions and removals to the book inventory include depletion of the SNM (e.g., fission of 235 U), which complicates the use of physical inventories. SNM control, however, can also likely be effectively applied to detect theft of SNM throughout a liquid-fueled MSR facility. To complement these approaches, prior technical reports have identified that a diversion path analysis may be a useful, risk-informed, and performance-based tool to determine suitable elements of an MC&A approach for the reactor system within a liquid-fueled MSR facility.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Regulatory Considerations for Domestic Reprocessing Facility Physical Security

U.S. advanced non-light-water reactor vendors may pursue collocated on-site reprocessing activities. Therefore, these facilities are likely to possess formula quantities, or Category I quantities, of special nuclear material (SNM) during normal operations. The U.S. Nuclear Regulatory Commission (U.S. NRC) has yet to formally establish a regulatory framework for commercial reprocessing. While Category I requirements would explicitly not apply in this circumstance under current regulatory requirements, regulatory certainty does not exist. A novel framework should be developed to ensure public health and safety while also risk-informing the physical security requirements. This report reviews the relevant background of related rulemaking activities and proposes risk-informed physical protection requirements to satisfy these objectives. Insights from NRC security-related rulemaking activities provide a substantial technical basis to approach potential establishment of physical security requirements for reprocessing facilities. If a licensee can provide justification that the material satisfies a sufficient self-protecting radiation dose threshold, the material may not be subject to theft or diversion requirements and only potential sabotage requirements would apply. Furthermore, if the material can be justified to be moderately dilute, a set of risk-informed requirements could provide adequate protection of public health and safety. A revised performance objective for prevention of theft of moderately dilute Category I SNM may be detection to allow prompt recovery by a local law enforcement agency. However, a significant caveat to the proposed categorization scheme is the unknown integration of radiological sabotage with requirements for the protection against theft. Future licensees should consult with the NRC regarding treatment of this regulatory topic. Additionally, the self-protecting radiation dose threshold (either the existing or a proposed future threshold) would need to be considered. An integrated approach may apply graded potential requirements for protection against the design basis threat of radiological sabotage currently applicable to commercial nuclear power plants and Category I SNM facilities defined within 10 CFR 73.1(a).

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Development of a Digital Twin for Hydrogen Dispersion and Safety Assessment in an Electrolyzer Based Hydrogen Production Facility

Digital twin models are virtual representations of physical systems that use real-time data to simulate and optimize performance. This study presents the development and initial implementation of a digital twin (DT) for the electrolyzer-based hydrogen production facility at NREL's Advanced Research on Integrated Energy Systems (ARIES), focused on enhancing safety and optimizing sensor placement through physics-based simulations and metadata integration. The DT incorporates detailed facility-specific information, including component layout, leak locations, and controlled release parameters, to model hydrogen dispersion under varying environmental conditions. Using steady-state computational fluid dynamics (CFD) simulations informed by real meteorological data, such as wind speed, direction, and vertical wind profiles, the DT enables visualization of hydrogen plume behavior and spatial concentration distributions. Comparative analysis between high and low wind speed scenarios illustrates the significant influence of wind dynamics on plume shape and extent, with horizontal momentum dominating dispersion at higher speeds, while buoyancy effects become more prominent under low wind conditions. These simulations generate a rich dataset embedded within the DT, allowing users to assess potential leak outcomes and identify optimal sensor locations based on concentration thresholds. The model supports scenario-based analysis to guide safety strategies and equipment deployment for open-area hydrogen infrastructure. The digital twin thus serves as a dynamic platform for virtual prototyping, providing predictive insight into hydrogen behavior and enhancing risk-informed decision-making. This initial phase establishes a validated foundation for future integration of transient, uncontrolled leak scenarios and real-time sensor feedback, positioning the DT as a critical tool for safety design, operational planning, and adaptive monitoring in hydrogen systems. Overall, the approach demonstrates the value of combining environmental data with digital simulations to inform safer and more efficient deployment of hydrogen technologies.

08 HYDROGEN↗

Development of a Digital Twin for Hydrogen Dispersion and Safety Assessment in an Electrolyzer-Based Hydrogen Production Facility: Preprint

Digital twin models are virtual representations of physical systems that use real-time data to simulate and optimize performance. This study presents the development and initial implementation of a digital twin (DT) for the electrolyzer-based hydrogen production facility at the National Renewable Energy Laboratory (NREL)'s Advanced Research on Integrated Energy Systems (ARIES), focused on enhancing safety and optimizing sensor placement through physics-based simulations and metadata integration. The DT incorporates detailed facility-specific information, including component layout, leak locations, and controlled release parameters, to model hydrogen dispersion under varying environmental conditions. Using steady-state computational fluid dynamics (CFD) simulations informed by real meteorological data, such as wind speed, direction, and vertical wind profiles, the DT enables visualization of hydrogen plume behavior and spatial concentration distributions. Comparative analysis between high and low wind speed scenarios illustrates the significant influence of wind dynamics on plume shape and extent, with horizontal momentum dominating dispersion at higher speeds, while buoyancy effects become more prominent under low wind conditions. These simulations generate a rich dataset embedded within the DT, allowing users to assess potential leak outcomes and identify optimal sensor locations based on concentration thresholds. The model supports scenario-based analysis to guide safety strategies and equipment deployment for open-area hydrogen infrastructure. The digital twin thus serves as a dynamic platform for virtual prototyping, providing predictive insight into hydrogen behavior and enhancing risk-informed decision-making. This initial phase establishes a validated foundation for future integration of transient, uncontrolled leak scenarios and real-time sensor feedback, positioning the DT as a critical tool for safety design, operational planning, and adaptive monitoring in hydrogen systems. Overall, the approach demonstrates the value of combining environmental data with digital simulations to inform safer and more efficient deployment of hydrogen technologies.

08 HYDROGEN↗

Developing a Process for Collaboration-Based Siting of a Federal Consolidated Interim Storage Facility in the United States: Learning from Communities Living with Legacy Waste

In June of 2023, the U.S. Department of Energy (DOE), Office of Nuclear Energy (NE) announced the selection of its Collaboration-Based Siting (CBS) Consortia, a group of 12 awardees, including the Consortium for Risk Evaluation with Stakeholder Participation (CRESP) (led by Vanderbilt University) to assist DOE-NE with the development of its process for siting a federal consolidated interim storage facility (FCISF) for spent nuclear fuel (SNF) storage. At this time, DOE NE is not soliciting interested host communities, rather the CBS Consortia are tasked with in-depth engagement, mutual learning, and capacity building to provide DOE NE with feedback on the CBS process. CRESP’s objective is to engage communities in two regions (the Pacific Northwest and the Southeast) with sites currently storing defense- and research-related SNF to foster learning concerning the best and worst practices in community participation in risk-informed decision making. This includes learning from existing structures for public input in radioactive waste management decision making [e.g. citizen advisory boards (CABs)] and other local parties about how to build and sustain trust among the parties. CRESP has been working to engage stakeholders and Tribes surrounding two DOE sites historically differing in receptiveness to engaging with DOE and trusting in DOE to accomplish its missions. CRESP’s approach to date has consisted of (1) engaging voluntarily members and former members of the DOE Office of Environmental Management’s CABs to develop a mutual understanding of their perspectives, values, and experiences related to risk and participatory decision making; (2) engaging members of those communities that would likely be part of any radioactive waste management discussions and who may provide valuable feedback for the development of the CBS process; and in the longer term, (3) engaging communities to foster knowledge sharing on understanding and definitions of risk and how risk is factored into community decision making. Our emphasis is to identify opportunities for improving risk communication frameworks, strategies, and decision making. The selection of a future FCISF site is likely to result in the creation of a structure similar to a CAB composed of members of the local community. We anticipate that these insights can help DOE NE learn from existing participatory risk communication structures in place at sites storing defenseor research-related SNF to understand best practices for fostering enduring and participatory relationships with future CABs. Within this paper, we (1) describe CRESP’s overall approach to assisting DOE NE with maturing the CBS process; (2) present a summary of preliminary phase 1 project results, including the development of a body of knowledge (describing available resources to support community engagement, risk communica tion, and participatory decision making) and community ecosystem information (leveraging demographic, social, economic, and environmental attribute mapping and advanced sentiment analysis of social media data); and (3) based on these results, provide observations for future research opportunities to support the development of CBS processes for radioactive waste management facilities, generally.

collaboration-based siting↗

Templates for Risk Informed Assurance with Curvature Embeddings (TRACE)

We investigate recovery of geometric structure from networks embedded in manifolds with spatially varying curvature, extending the constant-curvature framework of Lubold et al. (2023). Our work supports cascade risk assessment in critical infrastructure through the Templates for Risk-informed Assurance with Curvature Embeddings (TRACE) framework. Simulations on a bi-modal Gaussian surface show that constant-curvature methods yield weighted averages shaped by clique patterns, while hierarchical clustering identifies distinct regimes. Localized estimation, however, reveals boundary contamination in transitional regions. To address heterogeneity, we develop distance metrics for graphs with edge and node features, proving their metric validity, and validate them via deterministic graph generation from canonical tilings. We further propose a diffusion-based anomaly detection approach that treats networks as glued manifolds, using curvature discontinuities to detect structural anomalies. Employing the carré-du-champ operator and scalar curvature, we achieve robust anomaly discrimination, demonstrated on the Singapore Water Treatment (SWaT) dataset with joint network-traffic and sensor features. Integration with TRACE reveals how curvature shapes cascade dynamics: positive curvature impedes, while negative curvature accelerates propagation. This geometric perspective provides interpretable risk metrics and visualization tools for critical infrastructure managers. While full validation remains ongoing, our contributions establish a rigorous foundation for geometric analysis of network resilience and cascade vulnerability.

97 MATHEMATICS AND COMPUTING↗

Risk assessment of wellbore leakage during underground hydrogen storage

The expansion of renewable energy sources would require large-scale energy storage options to overcome the intermittent nature of these sources. Underground hydrogen storage (UHS) in depleted hydrocarbon reservoirs offers a scalable and practical energy storage solution. These reservoirs are chosen for their availability and large capacity, but the unique properties of hydrogen raise concerns about potential leakage pathways, particularly through wellbores. In this study, we develop and apply, for the first time, reduced-order models (ROMs) specifically designed for efficient leakage risk prediction in UHS systems operating in depleted hydrocarbon reservoirs. Using 3,000 high-fidelity simulation scenarios, we examine the influence of 11 key parameters, including reservoir and aquifer depths, wellbore permeability and porosity, initial saturations of water, oil and gas fractions (hydrogen, light, intermediate, and heavy hydrocarbons), reservoir pressure multiplier, and the aquifer-to-reservoir volume ratio, to simulate leakage behavior over a 1,000-year timescale. We train ROMs using a two-step classification-regression approach, achieving R 2 values exceeding 99 % across all targets. These ROMs effectively capture the leakage evolution and identify critical controls of leakage, guiding the design of mitigation strategies. Results indicate that gas leakage occurs in about 27 % of scenarios as early as five years post-operation, reaching volumes of up to 106 ft3. Oil leakage is less frequent (~17 %) and typically begins decades later. Our findings also show that hydrogen often migrates first, owing to its smaller molecular size and higher buoyancy, followed by heavier hydrocarbons. Over time, these heavier components contribute significantly to the total leaked volume, reinforcing the need for targeted monitoring and remediation strategies. Our analysis highlights that deeper storage reservoirs, shallower aquifers, and low-permeability wellbores significantly reduce leakage risks. In conclusion, this work offers a robust framework for risk-informed UHS deployment, supporting energy security through reliable large-scale hydrogen storage while safeguarding environmental integrity.

08 HYDROGEN↗

ARCADE Analysis Methods & Validation Pathway

The Advanced Reactor Cyber Analysis and Development Environment (ARCADE) provides an automated analysis system which supports risk-informed performance based (RIPB) evaluations of nuclear control systems. Every possible cyber threat which could lead to consequence is identified by simulating the unsafe control action sequences which transform digital harm into physical harm. Eliminating the simulation of complex digital cyber attack chains cuts out unnecessary computational overhead and focuses directly on the physics of cyber-physical attacks. This focus enables designers to make informed decisions which can entirely eliminate categories of cyber threats against advanced reactors through the physical nature of the plant design. This narrowing of cyber threat against nuclear power plants through the physics of the system is intended to make any remaining threat management and cost efficient. This is the goal of the Tiered Cyber Analysis (TCA) outlined in NRC Draft Regulation Guide (RG) 5.96, which provides a RIPB cybersecurity approach for new reactors. ARCADE has been custom developed to meet the demands of the rigorous analysis required in Tier 1 of the TCA, which forms the foundation of the TCA process. Currently, ARCADE is still under development, but has made significant leaps in capability. A pilot analysis on the opensource Asherah simulator was performed which demonstrated key functionality goals. The next stage of ARCADE development involves improvements to the applications which support the analysis system, and enabling the analysis system to utilize the full suite of unsafe control action simulations. Since the analysis method’s core functions are complete, validation of the analysis method will be started concurrent to the next development stages. The automated analysis ARCADE will provide can radically change the cybersecurity design process for advanced reactors, reducing the cost of security implementation while enhancing cyber resilience. The pathway for ARCADE’s development to this goal has become much clearer. The majority of technical hurdles have been cleared, and the remaining development needs have been solidified. ARCADE is now capable of assisting the advanced reactor design process and directly support advanced reactor industry RIPB practices.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗