
Advanced production systems play a vital role in modern society. Such systems are developed and industrialized over multiple years and at great expense. The complexities of these systems are exacerbated in the case of metal additive manufacturing, which involves numerous process variables and relies on various auxiliary systems. These systems generate vast amounts of data along the digital thread to produce quality components. With increased complexity comes increased risk, which in turn increases qualification and certification burdens, posing challenges to the wider adoption and industrialization of these technologies. Critical industries, including aerospace, medical, nuclear, and defense, are exploring approaches to effectively and efficiently develop and qualify these advanced manufacturing technologies, thereby providing flexibility and enhancing supply chain resilience.This research aims to demonstrate an end-to-end application of model-based systems engineering tools and techniques for the design and development of advanced production and manufacturing systems. This addresses the full lifecycle of an advanced production system to control and manage information and complexity. System levels and alternate threads are architected to facilitate flexibility and resilience. Production processes are segmented into modular production units for reuse in different production scenarios and contexts. A case study was performed for the development of a laser powder bed fusion production system for aerospace applications. The system was implemented and tested at industrial and academic facilities following a phase-based test campaign, which demonstrated its capability to produce material that conforms to material specification requirements. Industry stakeholders believe the system has verified material maturity through technology demonstration articles and provides value for future additive manufacturing industrialization undertakings.
The finalization of Systems Modeling Language Version 2 (SysML v2) represents a significant advancement for Model-based Systems Engineering (MBSE), offering a formal textual syntax and enhanced semantic precision to manage the complexity of modern systems. However, the practical utility of a new language can only be validated through rigorous application to non-trivial problems. This paper addresses the current scarcity of large-scale, public SysML v2 models by presenting a comprehensive model of the Apollo 11 mission. Using the five-layer CoSMA framework as a structuring guide, we created a detailed, multi-layered representation of this historically significant and complex system. This effort delivers two primary contributions: first, a rigorous evaluation of the expressive power and features of SysML v2 against a real-world case study; and second, the provision of a foundational, open-source artifact for the systems engineering community. The resulting model demonstrates the language's strengths in creating traceable, integrated, and verifiable system specifications. The complete Apollo 11 model is released publicly to serve as a common reference point, an educational resource, and a benchmark for the development of next-generation MBSE tools, thereby accelerating the adoption and maturation of SysML v2.
This paper addresses how to apply model-based systems engineering (MBSE) to ultrasmall planar satellites under severe power and resource constraints. PlanarSats are sub-100-gram spacecraft built as single printed-circuit boards where the same surface must host both electronics and solar cells, so power generation, geometry, and component placement are tightly coupled. Conventional MBSE with a full requirements-functional-logical-physical (RFLP) stack is often too heavy for the small, fast teams that build these missions. We propose a tailored MBSE framework that keeps compact requirements and functional view, but makes a combined Physical/Electrical view the central driver. This view uses a power-first sizing methodology based on current best estimate, maximum expected value, and maximum possible value of power, and derives an operational power envelope that links surface area, mode power, and allowable Sun incidence angles. Operational and verification views are reduced to a simple power-aware state machine and a small requirement-to-test matrix. The framework is demonstrated on a conceptual sub-100-gram, batteryless radiation-sensing PlanarSat in low Earth orbit, showing that the design remains power-positive in all planned sunlit modes while using a reduced set of MBSE artefacts maintained in a lightweight, tool-supported modeling environment. The approach is intended to help small teams retain traceability and explicit constraints for PlanarSat missions without the overhead of enterprise-scale MBSE deployment. The framework is proposed and evaluated analytically on this conceptual case study; no hardware or flight data are presented.
ABSTRACT Robustness requirements in systems engineering are frequently mis‐specified because informal notions conflate three distinct preservation concerns: preservation of required input‐output transformations, preservation of performance bounds, and preservation of mission‐level outcomes. This conflation leads to ineffective redesign when component‐level improvements fail to address coordination breakdowns, and to late discovery of failures when outcome guarantees are incorrectly inferred from verification evidence. This paper develops a formally typed framework for robustness grounded in systems theory and set‐theoretic semantics. We define functional robustness, capability robustness, and outcome robustness as distinct preservation properties, each evaluated over explicitly declared variation sets induced by system boundary and interaction structure. Robustness claims are shown to be well‐formed only when they specify what is preserved, over which operational variation, and through which boundary‐crossing interactions variation enters the system. Six theorems establish that the three robustness types are logically independent and expose common but unsound assumptions used in requirements refinement, robustness allocation, and verification reuse. A sufficiency theorem provides constructive guidance by identifying conditions under which outcome robustness can be guaranteed through jointly satisfied capability predicates, while clarifying why outcome robustness itself cannot be allocated to subsystems. The framework supports robustness‐aware requirements specification, architecture trade studies, verification planning, and failure diagnosis by making explicit whether failures arise from transformation loss, performance bound violations, or cross‐boundary coordination breakdowns, rather than treating robustness as a single undifferentiated property.
This umbrella review synthesizes findings from 79 peer‐reviewed systematic literature reviews (SLR) on digital twin (DT), a rapidly advancing technology with broad applications across various industries. By aggregating and analyzing second‐order evidence from existing SLRs, this study offers a high‐level overview of how DTs are defined, applied, and challenged across diverse industries. We identify recurring research themes, methodological inconsistencies, and sector‐specific gaps, with a particular focus on standardization, resource limitations, data quality, and system integration. Our review reveals that while DTs are widely discussed in relation to predictive maintenance, operational efficiency, and lifecycle optimization, substantial variability exists in definitions, frameworks, and implementation readiness across domains. Furthermore, underexplored areas such as user involvement, data ethics, and later lifecycle stages highlight the need for more interdisciplinary and practice‐informed approaches. By consolidating this body of knowledge, we provide strategic insights to guide future DT research and development, emphasizing the need for unified frameworks, cross‐sector knowledge transfer, and more robust evaluation of DT maturity and impact.
Medical device development remains constrained by development processes centered largely in the physical domain. These methods limited early understanding of system behavior and prolonged timelines relative to other innovation pathways. Such limitations increase prototype cycle duration and the number of iterations required to resolve design challenges. They also extend verification and validation activities. Consequently, this slows the generation of technical evidence required for regulatory submission, particularly for Class II and higher medical devices. This study presents a Model-Based Systems Engineering (MBSE) framework, which integrates digital twin capabilities, to support the development of capsule-based biomedical delivery systems as a specific use case. The framework captures system functions, requirements and behavior from empirical data. These elements are cross linked with a multi-layered digital twin model that incorporates analytical and numerical computation for higher fidelity system evaluation. Application of the framework demonstrated substantially improved traceability from high level stakeholder needs to granular Measures of Effectiveness (Moe). The framework also improved system performance, specifically the structural performance of the capsule-based biomedical delivery system increasing by 70% compared to the baseline design. Additional benefits were observed in prototype cycle efficiency, with the 30 h versus 19-week comparison suggesting an indicative acceleration of approximately two orders of magnitude. At broader development scale, the framework shows how traceable MBSE-digital twin workflows may shorten development timelines for regulated Class II medical devices. This is achieved through a reduced dependence on serial physical prototyping, faster design iteration and stronger evidence generation for verification, validation and regulatory decision making.
Systems Engineering (SE) relies on industry-academia collaboration for much of its research. Such collaborations are frequently described valuable in practice. At the same time, there is a need to align between partners to maximize the value of collaboration through acknowledging and working with nuances between parties to share and develop knowledge. At its essence, collaborative efforts might not achieve complete partner alignment to drive value if not emphasized, which could be averted with foresight and planning efforts. In the educational sciences there is a rich history of collaboration, and many models and theories for multi-stakeholder collaboration have emerged over time. In this work, we investigate the potential carry-over from educational sciences to collaboration between industry and academia in systems engineering, and discuss how an existing model of activity theory could be used to increase value in collaborative efforts between different partners. We formulate a model of activity theory applicable for systems engineering and present the Frame, Investigate, Negotiate, Do, Understand, Share (FINDUS) process to help practitioners apply the model pragmatically. The FINDUS process is presented through a set of questions that can be used as a checklist during collaboration.
Human activities, institutional practices, and technical processes often depend on the correct functioning of software systems operating in a context that continuously changes. This is challenging because typical software systems are rigid and cannot easily adapt to changing environments. We call a (software) system "context-aware" if it can sense changes in its context and adapt its behavior in a way that is relevant to a particular context situation, as opposed to rigid systems that cannot easily adapt to the changing environment. As studied before, this may concern adapting to changes in the situation of the user, to changes in the operation of the system itself, and to changes in relevant external factors, such as public values, regulations, and norms. Reflecting context awareness in the software specification process is essential, but it still lacks a formal specification. Aiming at bridging this gap, the current paper proposes a conceptual model for the three viewpoints, assuming a holistic approach that asks for addressing trade-offs. The analysis will be illustrated with several examples. Future research focuses on managing these trade-offs and orchestration-driven approaches.
Mission Engineering is maturing as a Systems Engineering discipline, yet adoption of its common frameworks remains stratified. This study examines whether selective adoption is observable across ME scholarship and develops a framework to address identified barriers. We analyze 42 self-identifying ME publications (2014-2025) using a 24-term rubric derived from Department of War guidance, constructing lexical similarity networks, coauthorship maps, and coherence baselines to test predictions from Kuhn's paradigm competition against Rogers' diffusion of innovations. Results show a binary stratification between papers engaging with Mission Engineering Guide (MEG)-coined terminology and those that do not (Cohen's d = 1.93), with no meaningful community modularity detected across 102 community detection runs (max Q = 0.212 < 0.30). Non-engaged papers are terminologically indistinguishable from random subsets, supporting Rogers' single-framework diffusion model and indicating that adoption barriers arise from implementation friction rather than competing theoretical alternatives. These findings identify process complexity, limited trialability, and weak interpersonal collaboration as likely barriers. In response, we present a formalized ten-step ME process with modular, artifact-producing steps and explicit mathematical specifications spanning operational, functional, capability, and system domains. This enables independent execution, reproducible evaluation, and standardized outputs, increasing trialability, reducing integration complexity, and supporting interoperability and broader adoption.
As nuclear fusion progresses from experimental research toward integrated power plant design, plasma control systems must operate within increasingly complex architectural, operational, and lifecycle constraints. This paper examines plasma vertical and radial position control from a model-based systems engineering perspective, aiming to complement established control design practices by making system boundaries, interfaces, and dependencies explicit. Rather than proposing new control laws, the study focuses on how sensing, estimation, actuation, and constraint handling are organised and coordinated within the plasma position-control function. Using SysML with the MagicGrid framework, we use model-based systems engineering tools to make explicit the traceability from stakeholder value propositions and plant-level operating objectives to tokamak subsystem functions and the plasma position-control capability. This decomposition exposes dependencies across sensing, reconstruction, actuation, power delivery, and protection that can affect integration, extensibility, and fault tolerance. The analysis highlights how assumptions and interface couplings that are often implicit in conventional control workflows become increasingly important at system scale. The proposed framework is intended as a conceptual and organizational aid for fusion power-plant programmes such as STEP Fusion (Spherical Tokamak for Energy Production), where physics assumptions, control requirements, subsystem interfaces, and plant architectures must be refined together under design uncertainty.
In the rapidly evolving field of artificial intelligence (AI), large language model s (LLMs) have demonstrated impressive capabilities in generating natural language. However, their proficiency in specialized domains, particularly in the field of systems engineering (SE), remains less explored and unquantified. This paper introduces SysEngBench, a novel benchmark specifically designed to evaluate LLMs in the context of SE concepts and applications. SysEngBench encompasses a comprehensive set of tasks derived from core SE processes, including requirements analysis, system architecture design, risk management, and stakeholder communication, to provide an assessment of language model abilities.Our evaluation of leading LLMs using SysEngBench reveals a strong correlation between model scale and performance, with state-of-the-art models like GPT-4o and Claude 3.5 Sonnet achieving near-human-level accuracy (above 95%) across multiple categories. Smaller models like Llama-3.2 1B exhibit significantly higher defect densities and lower accuracy scores, highlighting their limitations in handling SE tasks. However, Pareto analysis demonstrates that while larger models generally outperform smaller ones, some mid-sized models like Phi-3.5-mini-instruct achieve competitive accuracy with significantly lower computational requirements. These findings suggest pathways for practitioners and future research, particularly in optimizing smaller models for domain-specific reasoning through fine-tuning or knowledge integration. SysEngBench provides a systematic approach to assessing AI's impact on SE, offering insights into the trade-offs between model efficiency and accuracy. By establishing a benchmark for LLM evaluation in this domain, we provide a cohesive, extensible, and effective method to refine AI's role in the SE discipline.
The Common Vulnerabilities and Exposures (CVE) Program's mission is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities. A cybersecurity practitioner who suspects a software, hardware, or service vulnerability, can initiate a CVE-ID Requesting process, as defined by MITRE. This process is cumbersome, as it is entirely textual and evolvable, making it prone to incomplete description and misinterpretations. To automate and streamline the process, we developed a model of this process using Object-Process Methodology (OPM ISO 19450:2024). The model features computational capabilities, enabling practitioners to feed a textual description of the potential vulnerability they wish to report for CVE-ID Requesting. In response, the system provides all matching CVE Numbering Authority (CNA) instances in a descending relevance order. A survey that evaluates the effectiveness of this model-based approach has shown that it formally explicates the CVE-ID Requesting process and automates it. This greatly alleviates the task of determining what CNA is best suitable for examining the potential CVE for which a number is sought. Beyond streamlining and automating the process, this work demonstrates the benefits of adopting an approach to cybersecurity that standardizes and formulates global cybersecurity processes and systems. The approach facilitates the way professionals navigate their way in the complex, evolving web of hardware and software vulnerabilities.
As Large Language Models (LLMs) are increasingly deployed within the systems engineering domain, optimizing these models to balance performance accuracy and cost for given computational resources becomes essential. One process for finding the right balance is quantization, a process that involves converting model parameters from higher precision formats to lower precision formats. This empirical study investigates the impact of quantization at varying levels, including 4, 8, and 16-bit floating-point on LLM performance and cost within systems engineering problem contexts.The benchmark for systems engineering tasks, SysEngBench, is used to evaluate LLM performance. It is tailored to systems engineering domain knowledge and is mapped to the INCOSE Systems Engineering Handbook and IEEE 15288 System Life Cycle Processes, covering concepts across requirements, architecture, model-based systems engineering, technical management processes, and specialty engineering activities. By examining accuracy loss across quantization levels, insights can be gleaned into scenarios where lower bit quantization provides resource efficiency gains with minimal impact on accuracy, as well as scenarios where higher bit quantization levels are paramount for maintaining high fidelity responses. Analysis on quantization levels versus accuracy and model size, together with inferencing computing costs, indicates distinct trade-offs that can guide practitioners. These cost efficiency trade-offs help in selecting appropriate quantization levels to balance desired performance, cost, and resource requirements, which is particularly useful for model deployment in computation-constrained environments.
Accreditation of United States Government (USG) Information Systems (IS) is required to assure their function and security before delivery to the operational environment. However, in many cases, the baseline document-based accreditation processes are sources of cost and schedule overruns. This results in delays in providing critical information or functionality to USG stakeholders and users. A more modern approach, leveraging Digital Engineering (DE) and using Model-Based Systems Engineering (MBSE) practices, has the potential to reduce cost and risk of schedule overrun. This paper investigates the costs and benefits of the application of MBSE to the default document-centric Authorization to Operate (ATO) process. The ATO is a required accreditation process for all USG IS that seek to run in an operational environment. This research builds formal SysML models of the ATO, NIST Risk Management Framework, and a representative IS (a cloud-native asset management application). These models and their interactions are then assessed relative to default document-centric processes for their ability to quantitatively improve the results of the accreditation process, specifically by (1) improving the identification and resolution of inconsistencies in requirements management, (2) improving the schedule and cost for accreditation through parameterization and automatic generation of required documentation directly from SysML models. The results illustrate that an MBSE-enabled ATO process has significant benefits in identifying and addressing common ATO errors in requirements validation. Problems with inconsistencies, mislabeled requirements, erroneous "copy and paste," and errors in requirements traceability that are ubiquitous in document-centric ATO artifacts are driven to zero under the model-based ATO process due to the error-checking tools included in modern MBSE software. Improvements in the accreditation schedule and effort were found in the model-based ATO process because of the reuse of security controls, and the large degree of automatic generation of ATO artifacts. Publicly available security control models for > 1000 NIST SP800- 53 Revision security controls were developed and demonstrated, and 20 of the 41 ATO documents/artifacts generally required for accreditation or systems development of the representative IS were demonstrated to be parametrically definable and auto-generatable using tools available in modern MBSE software packages. Discussion focuses on the costs and benefits of this model-driven approach for contemporary and future USG IS. This work is novel in that the artifacts of a model-based ATO have not previously been developed, and that the costs and benefits of model-driven accreditation have not been previously asserted, investigated or analyzed.
Heterogeneous AI accelerators solve the fundamental problem of limited compute capacity and rigid pricing by enabling access to diverse computational resource pools with varying cost-performance characteristics. This mirrors federated cloud computing paradigms where resource pooling across providers optimizes utilization and cost. We present an SE framework for adaptive orchestration using hierarchical decomposition, standardized interfaces, and model-based engineering. Our approach integrates INCOSE lifecycle processes with evolutionary architecture patterns to manage technical complexity while enabling stakeholder value. Empirical validation achieves 70% cost reduction and 99.95% availability, demonstrating how SE principles enable sustainable heterogeneous AI systems.
This paper proposes an MBSE-based visual dynamic reliability analysis method for complex equipment systems to address the limited coupling between system modeling and visualization simulation and the inability of static fault trees to reflect real time damage evolution during mission execution. The method builds a real time bidirectional data loop among the system modeling tool, the visualization simulation environment, and dynamic fault tree analysis, enabling dynamic mapping and synchronous updating of fault probabilities from simulation damage data. Using an armed helicopter as a case study, a data interaction platform integrating UE5, Simulink, and the system modeling tool is developed, and 100 independent dynamic simulation runs are conducted together with a comparison against static fault tree analysis. The results indicate that the proposed method effectively captures the dynamic evolution of top-event probability under the present damage scenarios, while providing real time responsiveness and scenario awareness for dynamic reliability assessment. The method provides support for early-stage scheme comparison and preliminary safety evaluation of complex equipment systems.SIGNIFICANCE AND PRACTITIONER POINTS For researchers, this study tightly couples SysML system models, dynamic fault trees, and UE5-based 3D simulation twins. By establishing a real time bidirectional data loop, it enables real time system reliability analysis through visual simulation. This research offers novel approaches for researchers in two aspects: data acquisition methods for reliability analysis and the implementation of dynamic fault trees.
Architecture development using model-based systems engineering (MBSE) brings the benefits of efficient and less error-prone development for complex products. However, today, many enterprises' existing infrastructures, such as requirements and processes, are not compatible with MBSE technologies. During the migration from such a non-MBSE environment to an MBSE paradigm, many challenges arise and cause significant modeling difficulties. Dealing with them incorrectly, beyond errors and usability problems, will at least cause prohibitive costs that are likely to lead to program failures and prevent the adoption of MBSE. In this paper, these severe challenges are described, and the methods and strategies for MBSE architecture development for a partially built product are developed. Specifically, an algorithm is devised to find the minimum number of requirements to support the modeling of a specific safety case, a functional element, or a system component. In addition, a strategy and a process are developed to architect the MBSE architecture in an efficient way. With results from a case study of an airplane electrical power system, it is shown that the speed of modeling is significantly improved. This largely increases the chances of meeting early-stage schedules and avoiding program failures, which can enable further motivation for migrating toward MBSE in the enterprise.
Safety challenges in automated transport systems create the need for a strong design and safety coupling. In this regard, the second version of the Systems Modeling Language (SysML v2) offers new integration opportunities with extensibility features such as libraries. Due to the novelty of SysML v2, safety libraries have not yet been sufficiently explored. Hence, this article investigates the integration of the System Theoretic Process Analysis (STPA) into SysML v2. STPA was selected because of its system-theoretic foundation and suitability for analyzing complex transport systems. Results reveal opportunities (e.g., library managers), current limitations (e.g., tool maturity), and future work (e.g., standards) for SysML v2 safety extensions.
In response to the growing need for reconfigurable systems in dynamic operational environments, this paper presents a model-based modular and reconfigurable architecture design approach that integrates Model-Based Systems Engineering (MBSE) method with modular decomposition. The method centers on a service-driven Function-Mode-Component (FMC) model constructed using the Department of Defense Architecture Framework (DoDAF), explicitly linking functional behaviors, operational modes, and physical components. To address hidden reconfiguration constraints, a design matrix and state-space analysis framework are introduced, identifying conflicts arising from shared components, sequential dependencies, and concurrent operations. Coupled with a multi-criteria modular decomposition strategy that accounts for reconfiguration constraints, the approach generates cohesive, low-coupling modules while quantitatively evaluating alternative decompositions. A missile launch system case study demonstrates the method's capability to guide modular decomposition, uncover infeasible reconfiguration paths, and provide feedback to update DoDAF models, supporting iterative model-based architecture design.Significance and Practitioner Points For Researchers: This study bridges a gap between model-based systems engineering (MBSE) and modular design by introducing a novel Function-Mode-Component (FMC) modeling framework. Based on MBSE models using Department of Defense Architecture Framework (DoDAF), the proposed approach explicitly links functional behaviors, operational modes, and physical components while accounting for hidden reconfiguration constraints such as shared resource dependencies and sequential/concurrent operation conflicts. The case study demonstrates how this framework enables quantitative evaluation of alternative modular architectures, identification of infeasible transition paths, and feedback-driven improvement of architecture models. Researchers can leverage this methodology to explore the trade-offs between functional cohesion, modularity, and structural integration, and to extend reconfiguration-aware design principles to complex cyber-physical systems and service-driven System-of-Systems.
Artificial intelligence (AI) is rapidly changing the world, from completely controlling routine or mundane tasks like text and image generation, to powering advanced algorithms that control critical systems. The recent advances in generative AI quickly overwhelmed multiple industries from education to finance as first adopters rushed (and continue to rush) to take advantage of the technology. The expanding AI ecosystem presents novel risks and ethical challenges that must be handled to ensure that technology is leveraged fairly and ethically. There are intertwined risks and ethical challenges stemming from the stochastic nature of AI (i.e., intrinsic risks), as well as from specific applications (i.e., extrinsic risks). Appropriately regulating AI requires a systems-approach to develop an integrated solution to these dependent challenges. Thus far, however, questions of risk, ethics and regulation appear to occupy separate spaces. This article reviews the risks and ethical implications of AI and proposes a system-level approach to integrating ethics and regulation for the nascent industry.