Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Safety architecture”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

ADEPT: A Pedagogical Framework for Integrating Agentic AI with Deterministic Scientific Workflows

The integration of Large Language Models (LLMs) into scientific research promises to accelerate discovery, yet a significant gap remains between the dynamic reasoning of Artificial Intelligence (AI) agents and the static, deterministic nature of canonical scientific workflows. This paper introduces ADEPT (Agentic Discovery and Exploration Platform for Tools), a reference architecture and pedagogical framework explicitly designed to bridge this gap. ADEPT's primary mission is to provide a transparent, "glass-box" environment where researchers and engineers can learn to effectively wrap established scientific software (e.g., BLAST, Nextflow pipelines) and compose it into reliable, agent-driven workflows. We describe its modular, multi-server architecture, which leverages the Model Context Protocol (MCP) for tool serving, LangGraph for robust agentic orchestration, and a secure nsjail-based sandbox for safe code execution. By prioritizing architectural clarity, safety, and modularity, ADEPT serves as an extensible blueprint for building trustworthy AI-augmented systems and fosters the collaborative development necessary to responsibly employ agentic AI for science. We provide practical examples of how to adapt and extend this framework, highlighting its utility in workforce development and AI-readiness capabilities across research and development projects.

97 MATHEMATICS AND COMPUTING↗

Crossover as Determinant for Safety and Performance Tradeoffs in Proton Exchange Membrane Water Electrolyzers

Hydrogen (H2) crossover is a pressing challenge constraining safe and efficient operation of proton exchange membrane water electrolyzers (PEMWEs) especially amongst strides to employ thinner membranes, which enables improved energy efficiency, and elevated cathode pressures, that reduces the energy burden on downstream compressors. Here, we develop a microstructure-aware multicomponent reactive-transport framework that resolves dissolved and gaseous H2 transport pathways and mechanistically links electrode architecture to crossover related safety and performance. We show that operability is co-governed by the cathode catalyst layer (CCL) and the anode porous transport layer (APTL) which sets the H2 crossover flux and the egress capacity respectively. Elevated Pt/C ratio in the CCL suppresses crossover flux by up to 23% while a higher APTL porosity lowers H2 in O2 fraction by 0.6% in the anode effluent. We condense the findings into (cathode pressure-current density) maps overlaid with safety limits and performance targets and ultimately define two safety-performance unified metrics to gauge the size and quality of the operating window. Given the push towards higher pressure and deeper turndown for renewable integration, this study provides mechanistic design guidance to prevent crossover-induced safety risks while preserving the desired performance.

Electrolysis↗

Architecture of the personnel protection systems for Spallation Neutron Source Second Target Station

The Oak Ridge National Laboratory (ORNL) is implementing a major upgrade to the Spallation Neutron Source (SNS) facility, encompassing the addition of the Second Target Station (STS). Preliminary design reviews have been conducted on several STS Personnel Protection Systems (PPS). The reviews focused primarily on the integration with the existing SNS PPS, the new proton transport tunnel, and the target areas. Development of the PPS is ongoing, to ensure a coherent safety system with the mission of protecting users and workers from prompt radiation hazards while providing high beam availability to operations. The STS PPS element in the Integrated Control System (ICS) is a facility-wide system composed of multiple safety subsystems, including the Ring to Second Target (RTST) beam transport tunnel, Target, Bunker and Instruments. Personnel working in all these geographic areas are protected by modular reliable PPS solutions. The safety system enforces access controls, radiation monitoring, beam destination control, and application of critical device inhibit upon detection of abnormal condition. It uses well-documented processes, Common Industrial Protocol (CIP) safety, pulsed test, and redundancy to achieve the desired Safety Integrity Level (SIL). This paper gives an architectural overview of the STS PPS and a detailed safety plan for the SNS facility, addressing safety solutions and human factors.

Michaelides, Tommy [ORNL] (ORCID:0000000190499869)↗

Superionic conduction in solid polymer electrolytes – decoupling ion transport from segmental relaxation

Solvent-free, solid polymer electrolytes (SPEs) are promising candidates for next-generation, electrochemical energy storage systems due to their potential to enhance safety and performance, enable flexible device architectures, and streamline manufacturing processes. Conventional SPEs suffer from limited ionic conductivity due to the strong coupling between ion transport and (generally slow) polymer segmental relaxation. The realization of superionic conduction in SPEs, in which ions move faster than the structural relaxation of the polymers, requires a shift in design principles to promote this type of decoupled ion motion. In this perspective, we discuss how polymer architecture, ion–ion correlations, and ion–polymer interactions can unlock superionic behavior. We highlight several key design features, such as crystallinity, bulky side groups, high molecular weight, and percolating ionic aggregation, with a focus on creating low-barrier transport pathways in various polymer systems. We also demonstrate opportunities to combine polymer chemistry and data science through high-throughput and automated screening approaches to reveal how phase behavior, ion dynamics, and ionic interactions govern transport, thereby potentially enabling data-driven discovery of superionic polymer electrolyte materials.

Yang, Mengying [Univ. of Delaware, Newark, DE (Uni↗

Agentic artificial intelligence for multistage physics experiments at a large-scale user facility particle accelerator

We present a language-model-driven agentic artificial intelligence (AI) system to autonomously execute multistage physics experiments on a production synchrotron light source. Implemented at the Advanced Light Source particle accelerator, the system translates natural language user prompts into structured execution plans that combine archive data retrieval, control-system channel resolution, automated script generation, controlled machine interaction, and analysis. In a representative machine physics task, we show that preparation time was reduced by 2 orders of magnitude relative to manual scripting even for a system expert, while operator-standard safety constraints were strictly upheld. Core architectural features, plan-first orchestration, bounded tool access, and dynamic capability selection, enable transparent, auditable execution with fully reproducible artifacts. These results establish a blueprint for the safe integration of agentic AI into accelerator experiments and demanding machine physics studies, as well as routine operations, with direct portability across accelerators worldwide and, more broadly, to other large-scale scientific infrastructures.

Accelerator/storage ring control systems↗

Equivariant, safe and sensitive — graph networks for new physics

This study introduces a novel Graph Neural Network (GNN) architecture that leverages infrared and collinear (IRC) safety and equivariance to enhance the analysis of collider data for Beyond the Standard Model (BSM) discoveries. By integrating equivariance in the rapidity-azimuth plane with IRC-safe principles, our model significantly reduces computational overhead while ensuring theoretical consistency in identifying BSM scenarios amidst Quantum Chromodynamics backgrounds. The proposed GNN architecture demonstrates superior performance in tagging semi-visible jets, highlighting its potential as a robust tool for advancing BSM search strategies at high-energy colliders.

72 PHYSICS OF ELEMENTARY PARTICLES AND FIELDS↗

Autonomous Fueling System for Heavy-Duty Fuel Cell Electric Trucks

The motivation for this project stemmed from the challenges associated with rapidly refueling heavy-duty hydrogen fuel cell electric trucks (FCETs). Current manual refueling processes for fast refueling involve large, heavy equipment (e.g., hoses three times heavier than standard) and pose ergonomic risks and potential for equipment damage. The goal was to develop and test an autonomous fueling system to improve ergonomics, enhance safety, increase equipment durability through design improvements, and potentially speed up the fueling process. This project aimed to add to the understanding of autonomous systems in the context of heavy-duty hydrogen refueling, evaluating the technical effectiveness of potential concepts. A successfully developed system would benefit the public by facilitating the adoption of zero-emission heavy-duty transport, reducing reliance on manual labor for a physically demanding task, and potentially improving the safety and efficiency of hydrogen refueling infrastructure. The major accomplishment during the project's active period was the completion of the system-level architecture task. This involved establishing a detailed list of system requirements covering interfaces, environmental conditions, regulatory compliance, industry standards, safety, security, performance capabilities, and optional features. Five key use cases for the autonomous system were also identified. However, due to internal restructuring at Nikola, the necessary resources could not be allocated to continue the project. Consequently, Nikola opted to discontinue the project. The award was mutually terminated by Nikola and the DOE.

08 HYDROGEN↗

Elastic Stochastic Full Waveform Inversion (eSFWI)

This collaboration between Lawrence Livermore National Security, LLC (LLNS) as manager and operator of Lawrence Livermore National Laboratory (LLNL) and Chevron USA Inc., acting through its Chevron Technical Center division, aimed at developing next-generation computational methods for the Elastic Stochastic Full Waveform Inversion (eSFWI). Seismic imaging is heavily used in the oil and gas industry for identifying and operating subsurface reservoirs. Improved seismic imaging methods can improve productivity, lower costs, and improve operational and environmental safety. This CRADA demonstrated that new high-performance computing (HPC) architectures being rolled out over the next five years can enable unprecedented seismic imaging resolution when using eSFWI techniques to process active seismic data. An open-source computational mini-application was developed, capable of demonstrating near-peak performance for eSFWI algorithms on CPU and GPU enabled HPC platforms. Performance was demonstrated on LLNL HPC systems such as Lassen, as well as on Chevron systems. This project benefited Chevron USA Inc. by demonstrating the potential computational efficiency of their full waveform inversion capabilities used to characterize oil/gas reservoirs, which in turn benefits the public through potential increases in capabilities to perform analysis of leasing sites.

04 OIL SHALES AND TAR SANDS↗

Proposed Classifications of Remote Operations for Nuclear Reactors Based on Physical and Cybersecurity Considerations

The incorporation of remote operations into reactor operations is a topic of high interest among advanced and small modular reactor (A/SMR) vendors, with some considering it essential to the success of their business models. However, remote operations are a concept novel to the nuclear industry. While various technical aspects of remote operations have been explored, a significant gap remains in understanding the security implications of integrating remote operations into reactor designs, particularly concerning the security requirements for remote-operations facilities and infrastructure. This report aims to address this gap by first defining classes of remote operation based on the extent of remote access to reactor control systems and grounded in the existing regulatory framework with compatible terminology. Secondly, the report outlines the physical and cybersecurity requirements applicable to remote-operations facilities and infrastructure at each defined class. These requirements are based on existing licensing frameworks provided by 10 Code of Federal Regulations (CFR) Part 50 and 10 CFR Part 52, as well as the upcoming A/SMR licensing framework in the proposed Part 53. The assessment focuses specifically on security regulations, such as 10 CFR Part 73, which includes provisions for both cybersecurity (§ 73.54) and physical security (§ 73.55). This report proposes five classes of remote reactor operations. Class 1 involves remote monitoring only, with no control over reactor systems. Class 2 allows for the remote issuance of allowlisted commands to the reactor facility. Class 3 extends control to non-safety-significant, non-safety-related, or not important to safety systems and equipment. Class 4 permits remote control of safety-significant systems. Finally, Class 5 allows remote control of safety-related systems. It is important to note that these classes were defined purely with functionality in mind, without considering the practicality or feasibility of implementation for each class under current or upcoming regulatory guidance. The intention behind this approach is to enable an assessment of which security requirements apply to each class, allowing readers to evaluate the implementation possibilities for their specific use cases. Following the definition of remote-operation classes, the report assesses the specific physical and cybersecurity requirements applicable to the remote-operations facility and infrastructure within each defined class. This includes defining the types and locations of operators that are possible at each class of operation and, based on operator type and location, as well as functionality within each class, outlining the physical and cybersecurity requirements. By detailing the security requirements by class, the report provides readers with the information needed to determine the type of security program they may need to implement for their desired concept of operation. The next contribution of this report was to assess the practicality of implementing each proposed class of remote operations based upon the security requirement assessment. In short, three of the five proposed remote-operation classes were found to possibly have a practical path forward to implementation under the U.S. regulatory framework. Class 1 remote operations are currently in use in the U.S. while Class 2 and 3 remote operations may be logistically possible to implement under the U.S. regulatory framework. The final two Classes, 4 and 5, would likely be logistically difficult, if not infeasible to implement within the current U.S. physical- and cybersecurity regulatory framework. Given the results of the feasibility assessment, an example architecture is proposed for both Class 2, remote allowlisted commands, and Class 3, remote control of non-safety systems as well as security implication assessments of each architecture. These example implementations are not meant to be prescriptive in terms of how Class 2 or Class 3 remote operations should be deployed; instead, they are intended to be informative to stakeholders on how Class 2 or Class 3 could potentially be applied in order to inform their system design. An example architecture for Class 1 remote monitoring was not provided as Class 1 in already in use in U.S. nuclear operations. Example architectures for Class 4 and Class 5 were not provided due to their assessment of being likely infeasible to implement. The final contribution is an assessment of the physical- and cybersecurity implications of introducing autonomous operations into an A/SMR. What was found was that the security implications can be separated into two cases. Autonomous operations supported by SSCs located only at the reactor site, and autonomous operations supported by SSCs outside of the reactor site. For the first case, the introduction of autonomous systems will likely not change the facility’s requirement to comply with existing cyber and physical security regulation

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

Linking DSC/TGA to Cell Levels: Energetics, Evolved Gases, and Thermal Safety of NMC811‐Graphite Micro‐Cell

Thermochemical characterization of battery materials links intrinsic material properties to decomposition pathways, heat generation, and gas evolution that govern performance and safety. Despite extensive work on NMC811-Graphite, variability across partial configurations and the limited adoption of micro-cell architectures (cathode+anode+electrolyte+separator) hinder robust cell-scale interpretation. Accordingly, this work establishes a bottom-up, component-resolved methodology integrating DSC/TGA, evolved gas analysis (EGA), and in situ XRD to link decomposition pathways and energy release across partial and micro-cell configurations, providing a transferable assessment of safety and stability in emerging chemistries. In separator-free configurations, the gas–solid reaction between cathode-evolved O 2 and anode-leached Li dominates the net heat release (1139 J g −1 ). In contrast, in the micro-cell configuration, the separator hinders O 2 transport and alters the timing and pathways of other reactions, and reduces the net energy release to 618 J g −1 . Energy release was organized into defined temperature windows that provide a framework for a thermodynamic model combining quantified gas evolution with selected decomposition pathways and effective reaction enthalpies to estimate net specific energy release, with agreement between DSC and cell-level tests. Ex situ XPS of heat-treated samples extends post-mortem analysis to thermal-abuse regimes, supporting key pathway elements.

25 ENERGY STORAGE↗

Integrating Cybersecurity Risk Assessment with Process Safety in Chemical Process Industries

This dissertation bridges the gap between industrial cybersecurity and traditional process safety by introducing an integrated Cyber-LOPA framework that combines the Purdue Enterprise Reference Architecture, Cyber Kill Chain, and CVSS v4.0 metrics. Demonstrated on a High-Density Polyethylene slurry process, the work illustrates how cyber threats targeting automation systems can bypass physical protection layers, proving the necessity of unified risk assessments to prevent cyber-induced physical incidents in chemical manufacturing plants.

Cyber-LOPA (CLOPA)↗

Decayheatml

This code is designed to predict and analyze the decay heat generated in molten salt reactors (MSRs) using a hybrid approach that combines machine learning and segmented polynomial fitting. The accurate prediction of decay heat is essential for reactor safety and the optimization of spent fuel storage. The code operates through several key components: 1) Data Architecture: It incorporates a modular data architecture that handles various MSR-specific operational parameters such as power density, humidity content, and air ingress. These parameters are sampled using Sobol sequences to ensure comprehensive coverage of operational uncertainties. 2) Machine Learning Framework: The code employs a diverse set of machine learning models, including polynomial regression, decision trees, random forests, gradient boosting, support vector regression, k-nearest neighbors, multi-layer perceptrons, and symbolic regression. These models are trained to predict decay heat over a wide temporal range, from immediate shutdown up to 10,000 years. 3) Region-Optimized Training: The temporal domain is divided into multiple regions, each modeled separately to capture distinct decay heat characteristics across different time scales. This approach significantly improves the accuracy and interpretability of predictions. 4) Segmented Polynomial Interpretation (SPI): The SPI method translates machine learning predictions into piecewise polynomial equations. These equations are physically interpretable and can be directly integrated into existing engineering workflows and safety analyses. 5) Front-End Interfaces: The code includes both a Jupyter notebook interface for research development and a Streamlit web application for operational deployment. These interfaces allow users to interactively explore decay heat predictions, adjust operational parameters, and visualize results in real-time. 6) Applications: The framework supports various applications, including safety system validation and spent fuel container optimization. It enables real-time evaluation of worst-case decay heat scenarios, informing the design of passive safety systems and optimizing container designs for long-term storage. Overall, this code provides a robust, accurate, and user-friendly tool for predicting decay heat in MSRs, enhancing reactor safety, and optimizing spent fuel management.

Retamales, Mauricio Eduardo Tano [Idaho National L↗

Interplay of intercalation dynamics and lithium plating in monolithic and architectured graphite anodes during fast charging

Fast charging of high-capacity anodes is challenging due to lithium plating reactions, which lead to poor cycling performance and safety concerns. Thus, accurate predictions of plating onset and an understanding of this electrochemical process are crucial for robust battery design. However, the most commonly used models, based on porous electrode theory (e.g., the pseudo-2D model), are notoriously difficult to calibrate due to their complexity, limiting their predictive power. This work studies the process of lithium plating during fast charging of (small-particle) graphite half-cells by measuring local reaction progression and plating behavior using optical operando techniques. These experiments employ a realistic 1D graphite electrode geometry with commercially-relevant mass loading charged at fast charge rates. It is demonstrated that the local reaction progression and plating onset can not only be predicted accurately with a p2D numerical model, but that these processes follow a simple scaling law. Remarkably, the entire reaction histories of different electrodes charged at different rates (e.g., 160 μm thickness at 0.5C, 111 μm at 1C or 66 μm at 4C) were observed to have self-similar intercalation profiles. It is demonstrated that plating onset is in turn governed by the reaction profile which explains why both processes exhibit the same scaling behavior. Finally, operando measurements of local reaction dynamics are conducted for the first time in electrodes with channeled architectures, quantitatively determining how channels affect reaction uniformity and plating onset. Together, these results reveal underlying simplicity in the complex electrochemical environment of fast charging and lithium plating, improving understanding of this process. These fundamental insights are broadly applicable for design processes, modeling and experimental evaluation of lithium ion batteries.

25 ENERGY STORAGE↗

ObstacleSense: Low-Power Neuromorphic Vision for Corridor Obstacle Awareness in Low-Level ADAS

The automotive industry’s pursuit of Level 5 autonomy is constrained by substantial perception-compute power requirements, often reaching 1, 000 + watts in full autonomy stacks. Reducing this energy burden requires rethinking perception not only at the high-end autonomy level, but also at the foundational Advanced Driver Assistance Systems (ADAS) level where low-power, safety-critical sensing can have broad impact. Neuromorphic vision provides a promising starting point: HD Dynamic Vision Sensors (DVS) can operate below 100 mW at the sensor level by reporting only asynchronous brightness changes. However, low-power sensing alone is insufficient if downstream perception reintroduces dense, energy-intensive computation. In particular, many event-driven object-detection pipelines still rely on CNN backbones, while purely spiking alternatives often trade away accuracy or ignore deployment constraints. We introduce ObstacleSense, a highly compact, CNN-free hybrid ANN–SNN framework for Level 0–1 forward-corridor obstacle awareness. Instead of performing full-scene object detection with a convolutional feature backbone, ObstacleSense targets the safety-critical question of whether the ego corridor is occupied and how far the nearest obstacle is. The architecture combines polarity-conditioned event encoding, lightweight temporal spiking dynamics, axial spatial mixing, and coarse-to-fine range estimation within a regular fixed-grid compute pattern. This design avoids the dense CNN backbone commonly used in event-based detection while maintaining a small state footprint suitable for eventual small-FPGA deployment. Before hardware mapping, we evaluate the software implementation using a model-side power proxy derived from MACs, weight and activation traffic, and spiking state updates under shared FP16 assumptions. On simulated CARLA event corpora, the deployment-oriented model achieves 0.9464 objectness F1, 0.9978 grid-level mAP, and 0.8987 m distance Mean Absolute Error at an estimated 1.92 mW proxy cost, while maintaining performance on unseen generalization test sequences.

Johnson-Scott, Zac [ORNL]↗

Initial Feasibility Assessment and Broader Strategy Development for Fiber Integration via Advanced Manufacturing

Structural health monitoring is critical for ensuring the operational safety and cost-competitiveness of the developing advanced reactor designs. The extreme operational envelopes of these advanced architectures, having operating temperatures ranging 400°C–1,000°C and heightened displacement damage doses, render conventional commercially available piezoelectric transducers and resistive strain gauges unviable. Optical fiber sensors present an attractive solution for advanced radiation-hardened instrumentation due to their high thermal stability and distributed sensing capabilities. However, their deployment in embedded applications can be hindered by the severe thermomechanical strain driven by the coefficient of thermal expansion mismatch between fused silica glass and structural metal alloys like stainless steel (e.g., SS316L).

36 MATERIALS SCIENCE↗

Microsphere LiMn 0.6 Fe 0.4 PO 4 /C cathode with unique rod-like secondary architecture for high energy lithium ion batteries

LiMn x Fe 1-x PO 4 /C is considered a promising next-generation cathode material with significant commercial potential, inheriting the safety of LiFePO 4 while offering higher energy densities. However, the extremely low conductivity and the Jahn-Teller effect induced by Mn 3+ limit its practical capacity and rate performance. Effective modifications can be achieved through particle nanonization and uniform carbon coating. Here, in this work, we synthesized microspherical LiMn 0.6 Fe 0.4 PO 4 /C cathode materials using a hydrothermal method combined with spray drying carbon coating. The cathode material exhibits a microsphere structure composed of aggregated nanorods with a uniform 3 nm carbon coating, showing good dispersibility, small specific surface area and high tap density. In-situ diffraction analysis showed that expanding the single-phase solid solution region during (de)lithiation can reduce the energy barrier for electron transport, improve the kinetics of the (dis)charge process, and enhance both cycling and rate performance. The initial capacity at 0.1C can reach 155 mAh/g, and the capacity remains at 133.5 mAh/g with a retention rate of 97.1 % after 300 cycles. The synergistic effect of particle nanonization and uniform carbon coating endows the LiMn x Fe 1-x PO 4 /C material with excellent electrochemical performance.

25 ENERGY STORAGE↗

Development and Implementation of a New AI-Based Tool to Support Fast Reactor Software Model Generation and Validation

This report summarizes FY26 work to develop Maggie, an artificial intelligence-based assistant designed to support software model generation and validation activities for fast reactor analysis codes. The project established a modular, code-agnostic software architecture that separates reusable agent capabilities from code-specific knowledge and tools, with initial implementation focused on the FRP-supported fast reactor safety analysis code SAS4A/SASSYS1 (SAS). A curated SAS-specific knowledge base was assembled from the code manual, training materials, historical analysis reports, and representative input files, and was integrated through retrieval-augmented generation to ground Maggie’s responses in authoritative sources. Maggie was deployed on the internal Argonne network, where it demonstrated practical user-facing capability as a chatbot for answering natural language questions about SAS and retrieving relevant technical information. Demonstration cases also showed that Maggie can generate useful snippets of SAS input for selected modeling tasks, while highlighting current limitations in reliability and consistency for more complex input generation tasks. Overall, the FY26 effort established the technical foundation for an AI-assisted capability intended to improve the efficiency, consistency, and accessibility of fast reactor software model development at Argonne and, with further improvements, to support eventual use by the broader fast reactor community, including industry users of FRP-supported analysis tools.

Thomas, Rachel [Argonne National Laboratory (ANL),↗

Provable Repair of Vision Transformers

Vision Transformers have emerged as state-of-the-art image recognition tools, but may still exhibit incorrect behavior. Incorrect image recognition can have disastrous consequences in safety-critical real-world applications such as self-driving automobiles. In this paper, we present Provable Repair of Vision Transformers (PRoViT), a provable repair approach that guarantees the correct classification of images in a repair set for a given Vision Transformer without modifying its architecture. PRoViT avoids negatively affecting correctly classified images (drawdown) by minimizing the changes made to the Vision Transformer’s parameters and original output. Here, we observe that for Vision Transformers, unlike for other architectures such as ResNet or VGG, editing just the parameters in the last layer achieves correctness guarantees and very low drawdown. We introduce a novel method for editing these last-layer parameters that enables PRoViT to efficiently repair state-of-the-art Vision Transformers for thousands of images, far exceeding the capabilities of prior provable repair approaches.

97 MATHEMATICS AND COMPUTING↗