Engineering PapersSearch

SEARCH · Engineering Papers

Results for “trustworthy design”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Numerical aerodynamic simulation facility preliminary study, volume 2 and appendices

Data to support results obtained in technology assessment studies are presented. Objectives, starting points, and future study tasks are outlined. Key design issues discussed in appendices include: data allocation, transposition network design, fault tolerance and trustworthiness, logic design, processing element of existing components, number of processors, the host system, alternate data base memory designs, number representation, fast div 521 instruction, architectures, and lockstep array versus synchronizable array machine comparison.

Source record

Computational Models of Trustworthiness and Trust in Autonomous Cyber-Physical-Human Systems

In this paper, we propose an approach to developing a concept of actionable trust in multi-agent,cyber-physical-human systems in safety-critical and time-critical environment of air transportation. Actionable trust requires computational models of trustworthiness and trust, for use during system design and in real time, during operations. We describe the models, examine their computability and scalability, as well as what remains to be done.

Autonomous Systems

What FM can offer DFCS design

The results of aircrafts and spacecrafts flight tests are reported. It is shown that the problems of Digital Flight Control Systems (DFCS) are the problems of systems whose complexity has exceeded the reach of the intellectual tools employed. It is also shown that intuition, experience, and techniques derived from mechanical and analog systems are insufficient for complex, integrated, digital systems. Formal Methods (FM) of computer science can offer DFCS systematic techniques for the construction of trustworthy software, including: techniques for the precise specification of requirements and the development of designs; systematic approaches to the design and structuring of distributed and concurrent systems; fault tolerance algorithms; and systematic methods of testing and analytic methods of verification.

Rushby, John

A Distributed Simulation-to-Flight Framework to Support Investigating Trust/Trustworthiness in Multi-Agent Systems

As autonomous systems continue to grow both in use and complexity, the necessity for robust and extensible simulation-to-flight frameworks is paramount for establishing an effective architecture for autonomous systems. Hardware test flights are time-consuming and cost prohibitive during early system design and development. Simulation environments can be useful tools to accelerate algorithm development and testing. However, transitions from simulation to flight (sim-to-flight) can be challenging, unless systems are designed with this transition in mind and with the necessary capabilities built into the architecture and framework. One of the objectives of Autonomy Teaming and TRAjectories for Complex Trusted Operational Reliability (ATTRACTOR) was to design and develop a distributed mixed-reality simulation environment to begin establishing a basis for certification of autonomous systems via research into trust and trustworthiness. ATTRACTOR’s objective was to construct computational concepts of trustworthiness and justifiable trust in multi-agent autonomous teams, to inform future certification of safety-critical and time-critical autonomous systems in aviation. In this paper, we present an autonomous systems architecture and development framework paired with a persistent distributed modeling and simulation (ModSim) environment for test and evaluation of autonomous systems. They were designed under ATTRACTOR in order to measure and establish trustworthiness and trust in single-and multi-agent human-machine systems whether these machines are fixed-wing general aviation, rotary-wing Unmanned Aerial Vehicles (UAVs), ground rovers, or even spacecraft. The Autonomous Entity Operational Network (AEON) framework enables autonomous system development with an easily extensible collection of libraries and plug-n-play nodes facilitated by the Data Distribution Service (DDS) communication protocol standard. The Baseline Environment for Autonomous Modeling (BEAM) simulation environment is a distributed mixed-reality Unity™-based environment built around the same DDS communication paradigm allowing for easy integration with AEON-based autonomous applications, enabling sim-to-flight with minimal configuration changes. Using AEON and BEAM, source code that runs in simulation ports directly to hardware and has successfully flown in the National Airspace System (NAS) at NASA LaRC many times over the lifetime of ATTRACTOR.

Benjamin N Kelley

Build-up Approach to Updating the Mock Quiet Spike(TradeMark) Beam Model

A crucial part of aircraft design is ensuring that the required margin for flutter is satisfied. A trustworthy flutter analysis, which begins by possessing an accurate dynamics model, is necessary for this task. Traditionally, a model was updated manually by fine tuning specific stiffness parameters until the analytical results matched test data. This is a time consuming iterative process. NASA Dryden Flight Research Center has developed a mode matching code to execute this process in a more efficient manner. Recently, this code was implemented in the F-15B/Quiet Spike(TradeMark) (Gulfstream Aerospace Corporation, Savannah, Georgia) model update. A build-up approach requiring several ground vibration test configurations and a series of model updates was implemented in order to determine the connection stiffness between aircraft and test article. The mode matching code successfully updated various models for the F-15B/Quiet Spike(TradeMark) project to within 1 percent error in frequency and the modal assurance criteria values ranged from 88.51-99.42 percent.

Herrera, Claudia Y.

Build-up Approach to Updating the Mock Quiet Spike(TM)Beam Model

A crucial part of aircraft design is ensuring that the required margin for flutter is satisfied. A trustworthy flutter analysis, which begins by possessing an accurate dynamics model, is necessary for this task. Traditionally, a model was updated manually by fine tuning specific stiffness parameters until the analytical results matched test data. This is a time consuming iterative process. The NASA Dryden Flight Research Center has developed a mode matching code to execute this process in a more efficient manner. Recently, this code was implemented in the F-15B/Quiet Spike (Gulfstream Aerospace Corporation, Savannah, Georgia) model update. A build-up approach requiring several ground vibration test configurations and a series of model updates was implemented to determine the connection stiffness between aircraft and test article. The mode matching code successfully updated various models for the F-15B/Quiet Spike project to within 1 percent error in frequency and the modal assurance criteria values ranged from 88.51-99.42 percent.

Herrera, Claudia Y.

Reducing Risk of InSight Surface Operations Through High-Fidelity Command Sequence Modeling

Simulating spacecraft behavior is crucial for the success of deep space missions, and failure to do so may result in damages to or the loss of the spacecraft. Many previous deep space missions have made use of ground-simulation of sequenced commanding, at speeds far greater than real time, to predict spacecraft state over time through the execution of onboard sequences. This type of modeling can be done at any fidelity, and most missions have opted to decrease fidelity to reduce cost and complexity. However, NASA’s Interior Exploration using Seismic Investigations, Geodesy and Heat Transport (InSight) mission expanded the scope of ground modeling considerably, which has led to numerous benefits over past implementations. This paper will discuss the process and products that InSight created, as well as the lessons learned from successfully operating the spacecraft on Mars. InSight is the first JPL mission to expand the scope of ground modeling to include the uplink of files from Earth to the spacecraft, rather than making the simplification that any command sequences already exist onboard the spacecraft. The advantages of modeling the uplink of files are numerous. First, it allows for accurate modeling of the onboard filesystem of the spacecraft at all points in time, meaning that all file loads and deletions throughout the mission are modeled at the exact moment they are predicted to actually happen. Second, operators can be more certain that dependencies between sequences are not broken due to the dynamic nature of the filesystem as files are deleted, copied, and uplinked. Lastly, spacecraft filesystem tracking allows for management of sequences prior to uplink, limiting the uplink to only new sequences. The onboard filesystem model became crucial to mission success, emphasizing the importance of investing in accurate models before the need for them arises. During daily tactical operations of a spacecraft on Mars, a model is only useful if the results can be interpreted quickly. In this fast-paced environment, it is essential that command products are modeled and reviewed, errors are found and diagnosed, and new command products are redelivered, remodeled, re-reviewed in a timely manner. It is impossible to review the entire model and therefore the results of the model must be condensed and presented in a fashion that is intuitive, easy-to-navigate, complete, and trustworthy. InSight developed a number of innovative sequence review products that are designed to provide operators with the information required to quickly assess the validity of command products and diagnose potential issues. Together, these products provide a complete, yet succinct picture of the command and sequence model to the operators and facilitate a quick assessment of all sequence command products. This paper will cover planning and sequencing innovations made during InSight surface operations, and will compare the tools, processes, and results to those on other missions. Additionally, the paper will cover the flexible, yet robust nature of the planning and sequencing system architecture and how that flexibility allowed for rapid development and response to the unpredictability of Mars.

Cloutier, Kyle

A Distributed Simulation-to-Flight Framework to Support Investigating Trust/Trustworthiness in Multi-Agent Systems

As autonomous systems continue to grow both in use and complexity, the necessity for robust and extensible simulation-to-flight methods is paramount for establishing an effective architecture for autonomous systems. A fundamental objective of the ATTRACTOR (Autonomy Teaming and TRAjectories for Complex Trusted Operational Reliability) project was to design and develop a distributed mixed-reality simulation environment to begin establishing a basis for certification of autonomous systems via research into trust and trustworthiness. In this paper, we present an autonomous systems architecture and development framework paired with a persistent distributed modeling and simulation environment for test and evaluation of autonomous systems. The Autonomous Entity Operations Network (AEON) framework enables autonomous system development with an easily extensible collection of libraries and plug-n-play nodes facilitated by the Data Distribution Service (DDS) communication protocol standard. The Baseline Environment for Autonomous Modeling (BEAM) simulation environment is a distributed mixed-reality Unity™-based environment built around the same DDS communication paradigm allowing for easy integration with AEON-based autonomous applications. They were designed under ATTRACTOR in order to measure and establish trustworthiness and trust in single- and multi-agent human-machine systems whether these machines are fixed-wing general aviation, rotary-wing Unmanned Aerial Vehicles (UAVs), ground rovers, or even spacecraft. Together AEON and BEAM enable sim-to-flight with minimal configuration changes. By using AEON and BEAM, source code that runs in simulation ports directly to hardware and has successfully flown in the lab and in the National Airspace System (NAS) at NASA LaRC many times over the lifetime of ATTRACTOR.

Benjamin N Kelley

A Distributed Simulation-to-Flight Framework to Support Investigating Trust/Trustworthiness in Multi-Agent Systems

As autonomous systems continue to grow both in use and complexity, the necessity for robust and extensible simulation-to-flight methods is paramount for establishing an effective architecture for autonomous systems. A fundamental objective of the ATTRACTOR (Autonomy Teaming and TRAjectories for Complex Trusted Operational Reliability) project was to design and develop a distributed mixed-reality simulation environment to begin establishing a basis for certification of autonomous systems via research into trust and trustworthiness. In this paper, we present an autonomous systems architecture and development framework paired with a persistent distributed modeling and simulation environment for test and evaluation of autonomous systems. The Autonomous Entity Operations Network (AEON) framework enables autonomous system development with an easily extensible collection of libraries and plug-n-play nodes facilitated by the Data Distribution Service (DDS) communication protocol standard. The Baseline Environment for Autonomous Modeling (BEAM) simulation environment is a distributed mixed-reality Unity™-based environment built around the same DDS communication paradigm allowing for easy integration with AEON-based autonomous applications. They were designed under ATTRACTOR in order to measure and establish trustworthiness and trust in single- and multi-agent human-machine systems whether these machines are fixed-wing general aviation, rotary-wing Unmanned Aerial Vehicles (UAVs), ground rovers, or even spacecraft. Together AEON and BEAM enable sim-to-flight with minimal configuration changes. By using AEON and BEAM, source code that runs in simulation ports directly to hardware and has successfully flown in the lab and in the National Airspace System (NAS) at NASA LaRC many times over the lifetime of ATTRACTOR.

Benjamin N Kelley

Intercomparison of the LASCO-C2, SECCHI-COR1, SECCHI-COR2, and Mk4 Coronagraphs

In order to assess the reliability and consistency of white-light coronagraph measurements, we report on quantitative comparisons between polarized brightness [pB] and total brightness [B] images taken by the following white-light coronagraphs: LASCO-C2 on SOHO, SECCHI-COR1 and -COR2 on STEREO, and the ground-based MLSO-Mk4. The data for this comparison were taken on 16 April 2007, when both STEREO spacecraft were within 3.1 deg. of Earth’s heliographic longitude, affording essentially the same view of the Sun for all of the instruments. Due to the difficulties of estimating stray-light backgrounds in COR1 and COR2, only Mk4 and C2 produce reliable coronal-hole values (but not at overlapping heights), and these cannot be validated without rocket flights or ground-based eclipse measurements. Generally, the agreement between all of the instruments’ pB values is within the uncertainties in bright streamer structures, implying that measurements of bright CMEs also should be trustworthy. Dominant sources of uncertainty and stray light are discussed, as is the design of future coronagraphs from the perspective of the experiences with these instruments.

Coronagraph

A Persistent Simulation Environment for Autonomous Systems

The age of Autonomous Unmanned Aircraft Systems (AUAS) is creating new challenges for the accreditation and certification requiring new standards, policies and procedures that sanction whether a UAS is safe to fly. Establishing a basis for certification of autonomous systems via research into trust and trustworthiness is the focus of Autonomy Teaming and TRAjectories for Complex Trusted Operational Reliability (ATTRACTOR), a new NASA Convergent Aeronautics Solution (CAS) project. Simulation Environments to test and evaluate AUAS decision making may be a low-cost solution to help certify that various AUAS systems are trustworthy enough to be allowed to fly in current general and commercial aviation airspace. NASA is working to build a peer-to-peer persistent simulation (P3 Sim) environment. The P3 Sim will be a Massively Multiplayer Online (MMO) environment were AUAS avatars can interact with a complex dynamic environment and each other. The focus of the effort is to provide AUAS researchers a low-cost intuitive testing environment that will aid training for and assessment of decisions made by autonomous systems such as AUAS. This presentation focuses on the design approach and challenges faced in development of the P3 Sim Environment is support of investigating trustworthiness of autonomous systems.

Kelley, Benjamin N.

A Modular, Portable Model of Image Fidelity

There is a persistent need for a trustworthy model of perceptual image fidelity, especially in applications such as image compression and display design. A fidelity model provides a measure of the visual discriminability of two images. Ahumada has previously shown that the existing fidelity models may be categorized according to their inclusion of various canonical properties, such as a contrast sensitivity function, spatial frequency channels, etc. This suggests that research would be aided by the availability of a modular model, in which these components could be easily inserted or removed. A further impediment to research in this area has been that most models are written in low-level languages and are consequently large, non-portable, and difficult to understand, modify, and maintain. We therefore believe research would also be aided by models written in high-level languages. To serve both of these purposes, and to honor our conference host for his lifetime dedication to the problem of image quality. Global brightness and its effect on perceptual image quality. We offer a modular model written in the high-level language Mathematica. We will demonstrate this model and show how it may be modified.

Watson, Andrew B.

ATTRACTOR: Toward Trustworthy and Trusted Autonomous Systems

The question of what it means and what it takes for an autonomous system to consider another autonomous system justifiably trustworthy must be addressed by all who seek to integrate intelligent machine agents into real-world operations. A satisfactory answer to this question is an essential component in accepting autonomous machine decision-making in safety-critical and time-critical environments, such as aviation. Historically, simulation platforms for test and evaluation of complex systems have proven to be effective in assessing performance and contributing to decisions on the fitness of systems to operate in current general and commercial aviation airspace. Moreover, simulations have informed the definition of safety-critical constraints. However, as machine systems progressively take on responsibilities for decision-making traditionally supplied by humans, simulations require enhancement. Mixed reality simulation that integrates real-world platforms and data or high-fidelity simulation data in a sim-to-flight paradigm provides insight into agent interaction and the rationale behind autonomous agent decision-making as well as the capacity for seamless integrated implementation, testing, and operation of systems. Strong simulation capabilities are especially important in the presence of algorithms that hold great promise in decision-making yet increase the uncertainty in the system. Autonomy Teaming and TRAjectories for Complex Trusted Operational Reliability (ATTRACTOR) is a subproject of NASA’s Convergent Aeronautics Solutions (CAS) Project. ATTRACTOR’s objective is to build a basis for understanding trust and trustworthiness in multi-agent autonomous teams, and thus to inform future certification of safety-critical and time-critical autonomous systems in aviation. Because the concepts of trust and trustworthiness must be addressed in a context, ATTRACTOR has chosen Search and Rescue (SAR) in dynamic and unstructured environments, with emphasis on search, as its design reference mission (DRM). During dynamic planning and execution of trajectory-based operations, autonomous agents determine their trajectories given an assigned mission or missions and call for assistance from an appropriate teammate when needed. This experience along with the attendant human-machine and machine-machine interactions, serve as a platform for developing approaches to identifying and measuring trustworthiness and increasing trust. In this paper, we give an overview of some of ATTRACTOR’s research and development activities, findings, and ongoing work.

ATTRACTOR

Analyzing Natural Language Context in Human-Machine Teaming using Supervised Machine Learning

Building a foundation for trustworthiness and trust verification in multi-asset teaming is the research challenge of Autonomy Teaming and TRAjectories for Complex Trusted Operational Reliability (ATTRACTOR). The Design Reference Mission (DRM) for ATTRACTOR is a search and rescue mission objective governed by a multi-member team consisting of human and machine operators. A crucial component to the effort is the communication between humans and autonomous agents throughout both planning and execution stages of the mission. Intuitive communication methods and modalities are posited as critical enablers for certifying trust and trustworthiness. This paper reports on the data collection and analysis conducted in support of the Human Informed Natural-language GANs Evaluation (HINGE)project to attain explainable and trusted communication between human-machine assets. Two identically curated image description datasets were acquired for HINGE, both consisting of two unique input modalities (typed vs. verbal) and retrieved in two distinct contexts (general vs. specific). The gathered datasets were assessed and compared using Parts-of-Speech (POS)features, sentence similarity metrics, and linguistic analysis. Then, the datasets were modeled and tested separately and in combination with one another using machine learning algorithms. The comparison and testing results reveal a superior dataset, by which a preferred context and input is understood, for generating image representations of missing persons using a Generative Adversarial Network (GAN).

Bryan A Barrows

Survey of lift-fan aerodynamic technology

Representatives of NASA Ames Research Center asked that a summary of technology appropriate for lift-fan powered short takeoff/vertical landing (STOVL) aircraft be prepared so that new programs could more easily benefit from past research efforts. This paper represents one of six prepared for that purpose. The authors have conducted or supervised the conduct of research on lift-fan powered STOVL designs and some of their important components for decades. This paper will first address aerodynamic modeling requirements for experimental programs to assure realistic, trustworthy results. It will next summarize the results or efforts to develop satisfactory specialized STOVL components such as inlets and flow deflectors. It will also discuss problems with operation near the ground, aerodynamics while under lift-fan power, and aerodynamic prediction techniques. Finally, results of studies to reduce lift-fan noise will be presented. The paper will emphasize results from large scale experiments, where available, for reasons that will be brought out in the discussion. Some work with lift-engine powered STOVL aircraft is also applicable to lift-fan technology and will be presented herein. Small-scale data will be used where necessary to fill gaps.

Hickey, David H.

Trustworthy Autonomy for Gateway Vehicle System Manager

This webinar will present techniques for achieving trusted autonomous operations that are being pioneered on the NASA Lunar Gateway Vehicle System Manager (VSM). The challenges of achieving trusted autonomy faced by the VSM project are similar to challenges in underwater autonomous systems. The webinar will describe the overall approach to verification and present in detail the use of design-time (development) assume-guarantee contracts using model checking and runtime (operational) assume-guarantee contracts. The webinar will conclude with a summary of lessons learned to date and future challenges.

Assume-guarantee contracts

Metrics and Benchmarks for Visualization

What is a "good" visualization? How can the quality of a visualization be measured? How can one tell whether one visualization is "better" than another? I claim that the true quality of a visualization can only be measured in the context of a particular purpose. The same image generated from the same data may be excellent for one purpose and abysmal for another. A good measure of visualization quality will correspond to the performance of users in accomplishing the intended purpose, so the "gold standard" is user testing. As a user of visualization software (or at least a consultant to such users) I don't expect visualization software to have been tested in this way for every possible use. In fact, scientific visualization (as distinct from more "production oriented" uses of visualization) will continually encounter new data, new questions and new purposes; user testing can never keep up. User need software they can trust, and advice on appropriate visualizations of particular purposes. Considering the following four processes, and their impact on visualization trustworthiness, reveals important work needed to create worthwhile metrics and benchmarks for visualization. These four processes are (1) complete system testing (user-in-loop), (2) software testing, (3) software design and (4) information dissemination. Additional information is contained in the original extended abstract.

Uselton, Samuel P.

Analytic Verification of Flight Software

In the realm of space exploration, the biggest obstacle to widespread application of autonomy in flight software is not technical feasibility; it is doubt about its trustworthiness as a replacement for human-in-the-loop decision-making.

model