Engineering PapersSearch

SEARCH · Engineering Papers

Results for “Safety Case Patterns”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

A Formal Basis for Safety Case Patterns

By capturing common structures of successful arguments, safety case patterns provide an approach for reusing strategies for reasoning about safety. In the current state of the practice, patterns exist as descriptive specifications with informal semantics, which not only offer little opportunity for more sophisticated usage such as automated instantiation, composition and manipulation, but also impede standardization efforts and tool interoperability. To address these concerns, this paper gives (i) a formal definition for safety case patterns, clarifying both restrictions on the usage of multiplicity and well-founded recursion in structural abstraction, (ii) formal semantics to patterns, and (iii) a generic data model and algorithm for pattern instantiation. We illustrate our contributions by application to a new pattern, the requirements breakdown pattern, which builds upon our previous work

Formal Methods

Safety Case Patterns: Theory and Applications

We develop the foundations for a theory of patterns of safety case argument structures, clarifying the concepts involved in pattern specification, including choices, labeling, and well-founded recursion. We specify six new patterns in addition to those existing in the literature. We give a generic way to specify the data required to instantiate patterns and a generic algorithm for their instantiation. This generalizes earlier work on generating argument fragments from requirements tables. We describe an implementation of these concepts in AdvoCATE, the Assurance Case Automation Toolset, showing how patterns are defined and can be instantiated. In particular, we describe how our extended notion of patterns can be specified, how they can be instantiated in an interactive manner, and, finally, how they can be automatically instantiated using our algorithm.

Safety Assurance

Evidence Arguments for Using Formal Methods in Software Certification

We describe a generic approach for automatically integrating the output generated from a formal method/tool into a software safety assurance case, as an evidence argument, by (a) encoding the underlying reasoning as a safety case pattern, and (b) instantiating it using the data produced from the method/tool. We believe this approach not only improves the trustworthiness of the evidence generated from a formal method/tool, by explicitly presenting the reasoning and mechanisms underlying its genesis, but also provides a way to gauge the suitability of the evidence in the context of the wider assurance case. We illustrate our work by application to a real example-an unmanned aircraft system- where we invoke a formal code analysis tool from its autopilot software safety case, automatically transform the verification output into an evidence argument, and then integrate it into the former.

Argumentation

A Taxonomy of Fallacies in System Safety Arguments

Safety cases are gaining acceptance as assurance vehicles for safety-related systems. A safety case documents the evidence and argument that a system is safe to operate; however, logical fallacies in the underlying argument may undermine a system s safety claims. Removing these fallacies is essential to reduce the risk of safety-related system failure. We present a taxonomy of common fallacies in safety arguments that is intended to assist safety professionals in avoiding and detecting fallacious reasoning in the arguments they develop and review. The taxonomy derives from a survey of general argument fallacies and a separate survey of fallacies in real-world safety arguments. Our taxonomy is specific to safety argumentation, and it is targeted at professionals who work with safety arguments but may lack formal training in logic or argumentation. We discuss the rationale for the selection and categorization of fallacies in the taxonomy. In addition to its applications to the development and review of safety cases, our taxonomy could also support the analysis of system failures and promote the development of more robust safety case patterns.

Greenwell, William S.

Run Time Assurance as an Alternate Concept to Contemporary Development Assurance Processes

NASA and the FAA sought industry research to identify and evaluate alternate concepts for assuring safety of airborne systems. This report documents a research effort focused on the evaluation of Run Time Assurance (RTA) as applied to a novel, airborne system architecture. The RTA pattern is applied to a case study focused on a notional integrated flight and propulsion control system for a DEP VTOL aircraft. During flight, while the high-automation algorithms are operating, the RTA system will monitor the aircraft state for any impending violation of safety requirements. When necessary, it will switch to the low-automation software to prevent such violations. Assurance practices for both baseline industry activities and the RTA approach were captured and compared to illustrate the required engineering design considerations, and possible advantages and disadvantages of each approach as part of this case study.

Eric M. Peterson

Understanding and Verifying Neural Networks

Deep Neural Networks (DNNs) have gained immense popularity in recent times and have widespread use in applications such as image classification, sentiment analysis, speech recognition and also in safety-critical applications such as autonomous driving. However, they suffer limitations such as lack of explainability and robustness which raise safety and security concerns in their usage. Further, the complex structure and large input spaces of DNNs act as an impediment to thorough verification and testing. The SafeDNN project at the Robust Software Engineering (RSE) group at NASA aims at exploring techniques to ensure that systems that use deep neural networks are safe, robust and interpretable. In this talk, I will be presenting our technique Prophecy that automatically infers formal properties of deep neural network models. The tool extracts patterns based on neuron activations as preconditions that imply certain desirable output properties of the model. I would be highlighting case studies that use Prophecy in obtaining explanations for network decisions, understanding correct and incorrect behavior, providing formal guarantees wrt safety and robustness, and debugging neural network models. We have applied the tool on image classification networks, neural network controllers providing turn advisories in unmanned aircrafts, regression models used for autonomous center-line tracking in aircrafts and neural network object detectors

Deep Neural Networks

Supporting Crew Autonomy in Deep Space Exploration: Preliminary Onboard Capability Requirements and Proposed Research Questions. Technical Report of the Autonomous Crew Operations Technical Interchange Meeting

Communication delays are a critical challenge posed by long duration deep space exploration. Space missions historically have relied on an ever-present Mission Control Center (MCC) to direct operations in near real-time. As unanticipated anomalies that defeat fault detection and resolution systems do arise, the lack of real-time communication will significantly weaken what the MCC support represents: a reliable safety net for the flight crew through its deep and diverse areas of expertise and investigative resources. As a consequence, future space vehicles and habitats need to be equipped with capabilities to support the flight crew to operate with little or no ground support. Considerations must be given to vehicle and mission designs that will fortify the traditionally ground-centered safety net and forge new support systems, when communication delays exist. In August 2018, NASA’s Human Research Program, through its Human Factors and Behavioral Performance Element, convened a Technical Interchange Meeting (TIM) on Autonomous Crew Operations at NASA Ames Research Center. The goal of the meeting was to gather input from NASA centers, industry, academia, and branches of the Department of Defense (DoD) to address how intelligent technologies can be applied to augment onboard capabilities to support crew anomaly response. The TIM featured 24 presentations by 29 speakers and hosted a total of 59 attendees, including 43 from 5 NASA centers (Ames, Johnson, Langley, Marshall, and Jet Propulsion Lab) and 4 from the DoD (3 from Army Research Lab and 1 from Naval Postgraduate School), with remaining attendees from academia (e.g., UC Davis, CMU) and industry (e.g., IBM, Siemens). Discussions were centered around three themes: standards and guidelines, lessons learned in analog environments, and technologies. To help provide a framework for discussion, a concept matrix describing anomaly response processes was created prior to the TIM (Figure 1, page 6). The matrix captures the steps involved (monitoring and detection, diagnosis, solution development and evaluation, solution implementation and verification, resolution documentation) as well as the resources and capabilities required to support these steps (data, knowledge, analysis, synthesis, resource management). A wallpaper size printout of the matrix was utilized at the TIM to solicit attendee inputs along the three themes; the activity garnered 108 submissions of ideas. Overall, what emerged from TIM discussions was a picture of mismatch between crew anomaly response needs and support that can be provided by existing intelligent technologies. The needs are broad, spanning multiple steps and processes/resources, with many of which lacking support from existing technologies, such as knowledge management throughout the steps of problem solving (especially in resolution documentation) and manpower management. The solutions provided by existing intelligent technologies are specific to the steps/processes that they are designed to support and constrained to solving only problems similar to those that have occurred before. What is lacking from technologies is typically made up by humans, specifically their complex critical thinking, creative problem solving, and domain expertise. In the end, the TIM highlighted the pressing need to support responses to onboard anomalies during autonomous crew operations, particularly those that have eluded the system tests, inspection, and other assurance processes. Such anomalies can potentially threaten crew and vehicle safety, as well as significantly impact overall operations with additional workload. These fairly rare events are difficult to anticipate and prepare for, given the state-of-the-art in intelligent technologies. This is true even for anomalies that stem from “unknown knowns”—cases in which there is sufficient external information to characterize the problem but the overall pattern fails to be recognized by the problem solver, or in which the internal knowledge needed to solve a problem is held tacitly and potentially accessible by the problem solver but not articulated. It follows that the ability to tackle anomalies lies not only with the availability of relevant information and knowledge but also their accessibility in times of need. To that end, we propose research questions along the following three broad themes: • How intelligent technologies can help make relevant knowledge and information available? • How intelligent technologies can help make relevant knowledge and information accessible? • How intelligent technologies can help support the crew operating as a team in anomaly response processes?

autonomous crew operations

Case Study: Analysis of Autonomous Center line Tracking Neural Networks

Deep neural networks have gained widespread usage in a number of applications. However, limitations such as lack of explainability and robustness inhibit building trust in their behavior, which is crucial in safety critical applications such as autonomous driving. Therefore, techniques which aid in understanding and providing guarantees for neural network behavior are the need of the hour. In this paper, we present a case study applying a recently proposed technique, Prophecy, to analyze the behavior of a neural network model, provided by our industry partner and used for autonomous guiding of airplanes on taxi runways. This regression model takes as input an image of the runway and produces two outputs, cross-track error and heading error, which represent the position of the plane relative to the center line. We use the Prophecy tool to extract neuron activation patterns for the correctness and safety properties of the model. We show the use of these patterns to identify features of the input that explain correct and incorrect behavior. We also use the patterns to provide guarantees of consistent behavior. We explore a novel idea of using sequences of images (instead of single images) to obtain good explanations and identify regions of consistent behavior.

Deep Neural Networks

Identification of vortex-induced clear-air turbulence using airline flight records

The nature and cause of clear-air turbulence is being investigated, in cooperation with the National Transportation Safety Board, using the flight records available from airline encounters with severe turbulence. This paper presents two case studies of severe turbulence which indicate that the airplanes involved encountered vortex arrays which were generated by destabilized wind-shear layers near the tropopause. In order to identify and analyze vortex patterns (i.e., vortex strength, size, and spacings), potential-flow models of vortex arrays were developed that describe reasonably well the wind patterns derived from the airliner flight records. The results of this analysis indicate that in the two cases studied, the vortex cores had diameters in the range of 900 to 1,200 ft with tangential velocities in the range of 70 to 85 ft/sec. This study presents the first identification and analysis of vortex arrays from airline flight data. The results are compared with theoretical predictions and previous observations.

Parks, E. K.

Development and Execution of the RUNSAFE Runway Safety Bayesian Belief Network Model

One focus area of the National Aeronautics and Space Administration (NASA) is to improve aviation safety. Runway safety is one such thrust of investigation and research. The two primary components of this runway safety research are in runway incursion (RI) and runway excursion (RE) events. These are adverse ground-based aviation incidents that endanger crew, passengers, aircraft and perhaps other nearby people or property. A runway incursion is the incorrect presence of an aircraft, vehicle or person on the protected area of a surface designated for the landing and take-off of aircraft; one class of RI events simultaneously involves two aircraft, such as one aircraft incorrectly landing on a runway while another aircraft is taking off from the same runway. A runway excursion is an incident involving only a single aircraft defined as a veer-off or overrun off the runway surface. Within the scope of this effort at NASA Langley Research Center (LaRC), generic RI, RE and combined (RI plus RE, or RUNSAFE) event models have each been developed and implemented as a Bayesian Belief Network (BBN). Descriptions of runway safety issues from the literature searches have been used to develop the BBN models. Numerous considerations surrounding the process of developing the event models have been documented in this report. The event models were then thoroughly reviewed by a Subject Matter Expert (SME) panel through multiple knowledge elicitation sessions. Numerous improvements to the model structure (definitions, node names, node states and the connecting link topology) were made by the SME panel. Sample executions of the final RUNSAFE model have been presented herein for baseline and worst-case scenarios. Finally, a parameter sensitivity analysis for a given scenario was performed to show the risk drivers. The NASA and LaRC research in runway safety event modeling through the use of BBN technology is important for several reasons. These include: 1) providing a means to clearly understand the cause and effect patterns leading to safety issues, incidents and accidents, 2) enabling the prioritization of specialty areas needing more attention to improve aviation safety, and 3) enabling the identification of gaps within NASA's Aviation Safety funding portfolio

Green, Lawrence L.

Eddy covariance towers as sentinels of abnormal radioactive material releases

Ensuring accurate detection and attribution of abnormal releases of radioactive material is critical for protecting human health and safety. Most commonly, such detection is accomplished via active monitoring approaches involving the collection of physical samples. Further, this is labor intensive and limits the temporal and spatial resolution of any detected events to a relatively coarse level. As an alternative first step towards passive monitoring, we developed an approach using eddy flux tower data records to identify signals from a known abnormal release and quantify the extent to which that signal also occurs at other times in the data record. Through two case studies, one of which targeted the Fukushima nuclear disaster and the other targeting an abnormal release event at a radioisotope production facility in Fleurus, Belgium, we tested our approach and identified several potential heretofore unidentified abnormal events that were consistent with atmospheric circulation patterns and/or wind direction from known release sites. Because our approach is relatively simple and is resistant to systematic errors in the observational record, it has broad applicability beyond specific constituents and ecosystem types to identify a wide variety of limited-duration anomalies in flux tower data to ensure human health and industrial safety.

54 ENVIRONMENTAL SCIENCES

Flight Motor Set 360L003 (STS-29R)

The redesigned solid rocket motor (RSRM) flight set 360L003 was launched on March 13, 1989 as part of NASA space shuttle mission STS-29R. As was the case with flight sets 360L001 and 360L002 (STS-26R and STS-27R), both motors (360L003A and 360L003B) performed in an excellent manner. Evaluation of the ground environment instrumentation measurements verified thermal model analysis data and showed agreement with predicted environmental effects. The right-hand aft field joint primary heater failed during the countdown; the secondary heater was activated and performed as designed. All other field joint heaters and aft skirt thermal conditioning systems had no anomalies. Shuttle thermal imager infrared readings compared favorably with measured ground environment instrumentation data. No thermal launch commit criteria violations occurred at any time. Evaluation of the development flight instrumentation showed exceptional propulsion performance. All ballistic parameters closely matched the predicted values and were well within the required specification levels. Girth and biaxial strain gage measurements compared closely with corresponding gages on previous flight motors, static tests, and with preflight predictions. Adequate safety factors were verified. (Some ignition transient spiking was noted in a few girth gages; the spiking was determined not to be representative of actual case behavior, but an instrumentation phenomena.) The accelerometers again measured high vibration amplitude levels during the ignition transient and the reentry Max Q phases. Postflight inspection showed that all combustion gas was contained by the insulation in the field and case-to-nozzle joints. No anomalous insulation erosion patterns were found, and the seals that did directly contain motor pressure showed no heat effects, erosion, or blowby. All anomalies identified were a result of splashdown damage, with the exception of fretting in the case field joint interference (nonsealing) surfaces and a prelaunch field joint heater failure. The disposition of all anomalies and the complete results are reported.

Riehr, Glen A.

Comprehensive Forced Response Analysis of J2X Turbine Bladed-Discs with 360 Degree Variation in CFD Loading

The temporal frequency content of the dynamic pressure predicted by a 360 degree computational fluid dynamics (CFD) analysis of a turbine flow field provides indicators of forcing function excitation frequencies (e.g., multiples of blade pass frequency) for turbine components. For the Pratt and Whitney Rocketdyne J-2X engine turbopumps, Campbell diagrams generated using these forcing function frequencies and the results of NASTRAN modal analyses show a number of components with modes in the engine operating range. As a consequence, forced response and static analyses are required for the prediction of combined stress, high cycle fatigue safety factors (HCFSF). Cyclically symmetric structural models have been used to analyze turbine vane and blade rows, not only in modal analyses, but also in forced response and static analyses. Due to the tortuous flow pattern in the turbine, dynamic pressure loading is not cyclically symmetric. Furthermore, CFD analyses predict dynamic pressure waves caused by adjacent and non-adjacent blade/vane rows upstream and downstream of the row analyzed. A MATLAB script has been written to calculate displacements due to the complex cyclically asymmetric dynamic pressure components predicted by CFD analysis, for all grids in a blade/vane row, at a chosen turbopump running speed. The MATLAB displacements are then read into NASTRAN, and dynamic stresses are calculated, including an adjustment for possible mistuning. In a cyclically symmetric NASTRAN static analysis, static stresses due to centrifugal, thermal, and pressure loading at the mode running speed are calculated. MATLAB is used to generate the HCFSF at each grid in the blade/vane row. When compared to an approach assuming cyclic symmetry in the dynamic flow field, the current approach provides better assurance that the worst case safety factor has been identified. An extended example for a J-2X turbopump component is provided.

Elrod, David

Data Interfaces for Automated Vehicle Services - A Municipality Perspective

As Automated Vehicle (AV) services proliferate, data sharing between AV operators and municipal agents is assuming greater importance. Information on the dynamic nature of the road system such as incidents to avoid, weather hazards (such as flooding), construction and detours, as well as active safety concerns (e.g. - riots) is important for AV operators. Such information cannot be directly sensed from a vehicle's sensor array, but instead must be communicated in a timely and trustworthy channel. Municipalities are interested in pushing this information to AV operators to support emergency response efforts, reduce traffic in construction zones, and generally improve operation of the system. Similarly, information on vehicle safety such as disengagements, as well as critical information on the use of roadway system (trips, origin and destination patterns) are important performance factors for municipalities to understand utilization and plan for appropriate infrastructure. As mobility shifts to on-demand options, the need for safe and coordinated pick-up and drop-off zones will increase (potentially reducing parking needs). For all of these reasons, communication flows between AV operators and municipalities are becoming increasingly important. This paper investigates the functions, emerging practices and protocols for sharing of such critical data, and identifies gaps in and challenges in existing practices. Additionally, case studies are used to highlight the impacts of data sharing between AV operators and municipalities.

29 ENERGY PLANNING, POLICY, AND ECONOMY

An Approach to V&V of Embedded Adaptive Systems

Rigorous Verification and Validation (V&V) techniques are essential for high assurance systems. Lately, the performance of some of these systems is enhanced by embedded adaptive components in order to cope with environmental changes. Although the ability of adapting is appealing, it actually poses a problem in terms of V&V. Since uncertainties induced by environmental changes have a significant impact on system behavior, the applicability of conventional V&V techniques is limited. In safety-critical applications such as flight control system, the mechanisms of change must be observed, diagnosed, accommodated and well understood prior to deployment. In this paper, we propose a non-conventional V&V approach suitable for online adaptive systems. We apply our approach to an intelligent flight control system that employs a particular type of Neural Networks (NN) as the adaptive learning paradigm. Presented methodology consists of a novelty detection technique and online stability monitoring tools. The novelty detection technique is based on Support Vector Data Description that detects novel (abnormal) data patterns. The Online Stability Monitoring tools based on Lyapunov's Stability Theory detect unstable learning behavior in neural networks. Cases studies based on a high fidelity simulator of NASA's Intelligent Flight Control System demonstrate a successful application of the presented V&V methodology. ,

Liu, Yan

Hierarchical Mixture of Experts for Advanced Air Mobility Flight Phase Classification

Advanced Air Mobility (AAM) and Urban Air Mobility (UAM) operations will have numerous vehicles and aircraft flying in the airspace, which poses safety and security concerns. Commercial airlines utilize Air Traffic Management (ATM) and Air Traffic Control (ATC) for real-time monitoring, surveillance, traffic coordination, and rerouting to maintain safe and efficient flight patterns. Transferring ATM and ATC architectures to AAM/UAM will be difficult to implement since AAM/UAM aircraft fly at lower altitudes, have more static and dynamic obstacles, operate in highly dense environments, and have several more aircraft to monitor for a given volume of the national airspace (NAS). Automatic flight phase classification will enhance efficiencies of ATM/ATC-like architectures for AAM/UAM. Classifying the main flight phases (takeoff, climb, cruise, descent, and landing) provides insight to ensure safe operations, provide situational awareness of the NAS, and monitor flights in case there are any emergencies. Typical flight phase classification methods are all-or-nothing, which will not capture or accurately classify the transitions between flight phases. Utilizing hierarchical mixture of experts (HME) provides a flight phase classification solution that includes transitions between the flight phases by assigning weights based on ground-based distributed sensor readings from cameras and radar. Adding the transitions between flight phases increases the fidelity of flight phase classification and provides deeper insight for flight phase classification by leveraging distributed sensing concepts.

distributed sensing

Decomposition-Based Failure Mode Identification Method for Risk-Free Design of Large Systems

When designing products, it is crucial to assure failure and risk-free operation in the intended operating environment. Failures are typically studied and eliminated as much as possible during the early stages of design. The few failures that go undetected result in unacceptable damage and losses in high-risk applications where public safety is of concern. Published NASA and NTSB accident reports point to a variety of components identified as sources of failures in the reported cases. In previous work, data from these reports were processed and placed in matrix form for all the system components and failure modes encountered, and then manipulated using matrix methods to determine similarities between the different components and failure modes. In this paper, these matrices are represented in the form of a linear combination of failures modes, mathematically formed using Principal Components Analysis (PCA) decomposition. The PCA decomposition results in a low-dimensionality representation of all failure modes and components of interest, represented in a transformed coordinate system. Such a representation opens the way for efficient pattern analysis and prediction of failure modes with highest potential risks on the final product, rather than making decisions based on the large space of component and failure mode data. The mathematics of the proposed method are explained first using a simple example problem. The method is then applied to component failure data gathered from helicopter, accident reports to demonstrate its potential.

Tumer, Irem Y.

Psychophysiological Sensing and State Classification for Attention Management in Commercial Aviation

Attention-related human performance limiting states (AHPLS) can cause pilots to lose airplane state awareness (ASA), and their detection is important to improving commercial aviation safety. The Commercial Aviation Safety Team found that the majority of recent international commercial aviation accidents attributable to loss of control inflight involved flight crew loss of airplane state awareness, and that distraction of various forms was involved in all of them. Research on AHPLS, including channelized attention, diverted attention, startle / surprise, and confirmation bias, has been recommended in a Safety Enhancement (SE) entitled "Training for Attention Management." To accomplish the detection of such cognitive and psychophysiological states, a broad suite of sensors has been implemented to simultaneously measure their physiological markers during high fidelity flight simulation human subject studies. Pilot participants were asked to perform benchmark tasks and experimental flight scenarios designed to induce AHPLS. Pattern classification was employed to distinguish the AHPLS induced by the benchmark tasks. Unimodal classification using pre-processed electroencephalography (EEG) signals as input features to extreme gradient boosting, random forest and deep neural network multiclass classifiers was implemented. Multi-modal classification using galvanic skin response (GSR) in addition to the same EEG signals and using the same types of classifiers produced increased accuracy with respect to the unimodal case (90 percent vs. 86 percent), although only via the deep neural network classifier. These initial results are a first step toward the goal of demonstrating simultaneous real time classification of multiple states using multiple sensing modalities in high-fidelity flight simulators. This detection is intended to support and inform training methods under development to mitigate the loss of ASA and thus reduce accidents and incidents.

Harrivel, Angela R.