
Ensuring functional safety and cybersecurity in automotive applications is a pressing concern in nowadays. The complexity of systems with safety-critical functionalities poses a challenge for effective verification approaches to reduce the gaps between safety and cybersecurity. Semiconductors are pivotal to automated driving systems due to their role in implementing complex functionalities. Therefore, it is essential to consider both Functional Safety (FuSa) and Cybersecurity aspects when developing semiconductor devices. This paper presents a holistic approach to incorporating failure effects and modes that considers both FuSa and Cybersecurity. Additionally, it investigates the potential relationship between failures effects and/or attack effects in semiconductors and emphasizes the interplay between FuSa and cybersecurity in an analysis. By illustrating proposed co-analysis concept between these areas, this study aims to provide insights into ensuring comprehensive FuSa and Cybersecurity measures in semiconductor development for automotive applications.
Operational safety assurance for autonomous and highly automated systems is imperative due to the inherent complexities and dynamic operational environments these systems encounter. As autonomous systems evolve, ensuring their safety throughout their life-cycle becomes indispensable, not just during the deployment but also during operation. Safety assurance has evolved from traditional document-based approaches to more structured, model-driven methodologies to enhance clarity and traceability. This evolution has been driven by the need for more rigorous, repeatable, and scalable processes to ensure safety in increasingly complex systems. Traditional safety assurance methods do not adequately address the dynamic real-time challenges and changes an autonomous system might face, necessitating a more adaptive and continuous approach. This paper highlights the need for a Cumulative Operational Safety Assurance approach addressing multiple research gaps. The cumulative aspect of the approach ensures that the safety assurance case evolves continuously and incrementally with operational data, improving decision-making and system safety.
The use of unmanned aerial vehicles (UAVs) is rapidly increasing. Certain tasks necessitate the deployment of multiple UAVs for a unified mission, forming what is known as a UAV swarm. A critical factor in assessing a UAV or UAV swarm is reliability. Various mathematical models are employed to analyze reliability. For instance, Binary-State Systems (BSS) models evaluate two states: operational/functional and faulty. Some research advocates for the use of a Multi-State System (MSS) model. MSS enables the examination of more than just two states (operational and faulty), providing a more comprehensive analysis. This paper presents a comparative study on calculating the availability of a UAV swarm using both BSS and MSS models. Different UAV swarm topologies are interpreted as typical MSS structures (series, parallel, k-out-of-n) and represented by structure function. The analysis includes both homogeneous and heterogeneous UAV swarms, which can be either non-redundant or redundant hot stable systems.
The rapid development of the low-altitude economy has propelled research focus towards technology pertaining to Unmanned Aerial Vehicle (UAV) swarms. The operational environment of UAV swarms is fraught with uncertainties and risks, posing challenges to their reliable functioning and mission success rate. UAV swarms possess the resilient property due to its self-organization and self-adaptation capabilities. Resilience design and enhancement serve as an effective approach for complex network systems like UAV swarms to effectively tackle unknown risks. The foundation of resilience design and improvement lies in the utilization of scientific and rational resilience analysis methods. The current three types of system resilience analysis methods effectively address the issue of describing resilience phenomena, but they have not delved into the level of understanding the laws governing resilience in UAV swarms. In this paper, the concept of intrinsic resilience (IR) is proposed for the first time to demonstrate the inherent resilient performance of the UAV swarm itself. The IR parameters including flexibility, rebounding velocity and restoration rate are provided and a 7-tuple metric framework is established. A UAV delivery system is utilized as an example to explain and illustrate the proposed IR analysis method.
Arithmetic coding, also known as encoded or coded processing, is a software-based fault-tolerance approach that detects hardware faults at the software level by exploiting information redundancy. Existing arithmetic coding focuses on integer arithmetic. However, the increasing complexity of safety functions, e.g. from industrial robotics, requires floating-point arithmetic. This paper shows the challenges of applying existing integer codes to floating-point numbers. We identify and compare existing approaches from literature and new approaches in this paper. The comparison includes an analysis of performance, fault detection capability, hardware reliability, constraints on algorithm development, and accuracy.
Know Your Customer (KYC), which is primarily utilized by banks in the financial system, improves financial organizations' processes. The information received from the customer throughout the KYC process can be utilized to prevent fraud, money laundering, and other illegal acts. KYC processes can be carried either by individual financial institutions or through a centralized system. Aside from both of these possibilities, it is also possible to conduct KYC processes using a blockchain-based system. In this study, insurance fraud records, which insurance companies call blacklists, are carried out with blockchain technology. The solution prepared on the Ethereum network allows different insurance companies to access the network and read and write blacklist records. Keeping a blacklist record, which can be associated as a KYC process, reveals a fast, unchangeable and transparent structure between insurance companies. The study also addresses methods to mitigate a critical vulnerability in these networks where a single actor can manipulate the system through fake identities. This situation is considered as a Sybil attack. The closing remarks underlines the eagerness of emerging regulations and standards for privacy, access control, data sharing, scalability, etc.
Achieving and maintaining certain quality attributes of software-intensive systems is challenging, especially when these systems undergo change. In particular, information security is more difficult to maintain and degrades more rapidly than other non-functional attributes, often with catastrophic consequences. Security patterns are a well-established method for preventing and mitigating malicious attacks or unintentional failures. However, these patterns depend on contextual factors such as attacker behaviour and run-time configurations that are not explicitly addressed at design time, but evolve along with other software components or change dynamically in production. Security issues can arise after the initial development phases if software architects do not adequately document such contextual information in their designs. Existing approaches handle security-related information during the software design phase, but fail to consider the effects of evolving system architecture and environment due to implicit assumptions. Security pattern analysis needs to incorporate such contextual information to provide accurate security predictions. In this paper, we propose a novel approach for modelling security patterns and related contextual information within software architectures. This model-based documentation facilitates the analysis of the expected functionality of applied security patterns at an architectural abstraction level. We demonstrate how these architectural improvements support the maintenance of security by enabling architects to anticipate, track, and act upon the impact of evolutionary changes on the system. To validate our modelling approach, we apply it to a common case study.
Multi-state systems (MSSs) with common bus performance sharing (CBPS) is widely exist in practical engineering. This system is a typical redundant system to ensure the reliable operation. It considers two MSSs connected via a common bus, either of which has to satisfy its own demands, then transfer performance to the other system in order to improve the whole system reliability. In this paper, a new reliability model for MSSs with CBPS is proposed. Each multi-state component has a random performance and random demand. A Markov model is established to describe the performance and demand variations. An algorithm based on the universal generating function (UGF) method is proposed to evaluate the reliability of the whole system. The sensitivity analysis of systems with a given transmission capacity is discussed. Finally, the feasibility and effectiveness of the method is illustrated by a numerical example.
With the increasing demand for road construction and limited land use on the ground, the bifurcation tunnel interchange project will become a common engineering form for future tight road networks. The safety of the branching and merging areas in tunnels should be given attention due to the influence of tunnel structures. By analyzing the driving characteristics of vehicles in the branching tunnel merging area, based on the visual distance requirements and vehicle driving characteristics of the merging area, the merging area and design reliability requirements of the branching tunnel were proposed. A reliability judgment model for the splitting impact based on the secondary deceleration theory was constructed, and reliability judgment standards for the length design of parallel deceleration lanes and direct deceleration lanes in the branching tunnel were proposed. This provides some reference and guidance for the design engineering practice and research of the branching tunnel merging area in the future.
The success of traditional fault diagnosis methods depends on obtaining a large number of training samples in the form of full faults, which may not be available in practical applications. Recent studies have shown the feasibility of constructing virtual representations reacting to fault situations by building physical models when fault samples are insufficient. In this paper, a virtual data-driven domain-based adaptive fault diagnosis method based on adaptive regularisation consistency, ARC, is proposed to ensure the consistency between the virtual and real domains. Firstly, the bearing dynamic model is constructed to obtain the simulation data, and the simulation data and the real data are input into the trained original model and the target model at the same time. The data distributions of the simulated and real samples are adaptively brought closer by adding weights to the maximum mean discrepancy (MMD); Kullback-Leibler Divergence (KLD) is used to make the feature representations extracted from the target model similar to each other and between the original model and the feature representations extracted from the target model, and regularization is used to fine-tune the feature extraction of the model. An entropy-based adaptive pseudo-labelling selection method is proposed to filter low-quality samples and prevent negative transfer. The diagnostic results of the case study show that the proposed method is able to utilize the diagnostic knowledge from the simulation data to achieve fault diagnosis of mechanical equipment and outperforms the commonly used unsupervised cross-domain fault diagnosis methods.
Strengthening the resilience of hospital systems has gained significant attention following the COVID-19 pandemic and ongoing global conflicts, which have highlighted their vulnerability to potentially disruptive events. This paper presents a novel approach to provide complete high-level overviews of hospital resilience through semi-quantitative stress tests. The paper describes the theoretical framework and a tool which facilitates its implementation. Additionally, the approach is demonstrated by using it to assess the resilience of a hospital in Lebanon. It is shown that the quantification of resilience through specific service measures enables clear identification of where changes to the hospital system can improve hospital resilience, as well as the possible magnitude of resilience improvement. The approach uses a relatively short list of indicators to help balance comprehensiveness and computational efficiency. An example of a potentially disruptive event, i.e., a stress test, is a mass casualty incident. The connection between the event and the service measures was developed semi-quantitatively using considerable information from scientific literature and expert opinion. Although the case study only consists of one stress test it demonstrates that this approach has considerable potential to provide a much-needed overview of the resilience of hospital systems and how the resilience can be best improved. Its use will provide valuable insights for both hospital managers and regulatory bodies in their discussions of how to best improve healthcare infrastructure.
Proactive Network Maintenance (PNM) is a cornerstone for cable network reliability. Accurate fault detection and diagnosis of faults in hybrid-fiber coaxial (HFC) networks are significant for providing customers high service quality, optimizing network operations and minimizing related costs. Fault detection and diagnosis in this industry has been widely explored via labeling and data-driven techniques. Yet, academic contributions lack of studies focusing on cable network fault diagnosis via Full-Band Capture (FBC) downstream data analysis. Another criticality in the field is the absence of ground truth and expertise uncertainty around the correct fault labeling of raw impaired data. With basic expertise knowledge about the fault types and driven by the assumption of single cable modem (CM) signal representative of a single fault state, this paper offers a fault diagnosis scheme using FBC downstream data. At first, a data matrix is constructed by concatenating 78 distinct features computed for a series of empirical sliding windows and steps. Next, we apply augmentation techniques to balance the classes considering different augmentation ratios. Following, we employ Pearson Correlation for the reduction of highly correlated features and Genetic Algorithm (GA) for the final feature selection. Random Forest is used as surrogate model in GA. Through different experimental runs, our approach shows high classification accuracy across nine classes of network fault states, establishing a foundation for state-of-the-art diagnosis results in the field.
Telecommunication Networks (TLCNs) enable the control of Cyber-Physical Systems (CPSs). Reliable End-to-End (E2E) communication among TLCN devices is fundamental to prevent CPS failures. Simulating the complex underlying phenomena that cause E2E communication failure, such as transmission delays and package dropouts, might be computationally expensive, challenging the reliability assessment of E2E communication. To tackle this issue, we reframe the E2E communication as a classification problem to streamline its reliability assessment. We use Gradient Boosting (GB) as an example of an off-the-shelf classifier that can be tailored to the purpose of estimating the E2E communication success or failure, without relying on the long-running simulation of the information processing through the nodes of a TLCN embedded into a CPS. The CPS considered as case study is an Integrated Power and Telecommunication Network (IP&TLCN) system.
TheRail Data Network (RDN) is the communication infrastructure deployed along the rail tracks, which enables the exchange of information between all the components in the railway infrastructure. The RDN in modern railway trans-portation systems is critical in ensuring operational safety and efficiency. Combining a nation's RDN and Core Network (CN) via strategically placed interconnection links into a unified optical communication infrastructure has been proposed as a promising solution to ensure throughput and latency requirements of Digital Rail Operation (DRO) and Passenger Connectivity (PC). However, the cost of renting, configuring, and operating all possible interconnection links is too high. Furthermore, there are no guidelines on the appropriate number of interconnection links required to maintain an acceptable level of robustness in the combined network. In this work, we aim to provide guidelines to the Rail Operator (RO) on choosing the interconnection links to minimize the cost of the interconnection links while guaranteeing and maintaining acceptable robustness in the combined network. Robustness surfaces are used to analyze and compare different combined network cases differing on the interconnection links for the German inter-city railway. The main findings reveal that the proposed interconnection of the RDN and CN improves the robustness to nearly the maximum achievable while reducing 75% of the costs for the German inter-city railway.
Field Development Planning (FDP) for oil and gas (O&G) recovery projects requires strategic well placement and infrastructure design to maximize hydrocarbon extraction. This work presents a Deep Reinforcement Learning (DRL) framework based on Deep Q-Networks (DQN) for the optimization of drilling scheduling. Different sets of parameters describing the reservoir characteristics are considered for the definition of the state space and the parameter combination providing the largest profit over the entire lifetime of the oil project is identified. The proposed framework is validated considering a synthetic case study that emulates the complexity of the drilling scheduling problem in real-world scenarios.
The co-engineering of safety and security in modern systems is a complex endeavor that requires the combined consideration of these qualities and their interactions. This is problematic in existing approaches as they focus mostly on a single quality and hence hinder the explicit consideration and analysis of the interactions. In addition to the technical complex-ity, human factors and social constructs lead to socio-technical challenges in the co-engineering, that can potentially result in unsafe and insecure systems. This research aims to simplify the identification and management of socio-technical challenges in safety and security co-engineering of complex, safety-critical systems. This research proposes a tool-based solution using ontologies and knowledge bases to facilitate knowledge exchange among stakeholders. The proposed tool-based solution improves upon the existing manual identification and management of socio-technical gaps. As a start, the research focuses on the challenges imposed by the different models, engineering views and analysis techniques used by safety and security domains, which convey actionable information to the stakeholders from other domains. To validate the usefulness of the proposed ontological approach, a proof-of-concept was created using the data flow diagram model of an existing Industry 4.0 use case and its threat risk analysis. The created domain ontology leveraged the security model and threat analysis, and was able to identify certain socio-technical gaps in the existing security threat modelling and analysis. The gaps identified were in regard to the modeling choices made during the analysis, the engineering rigor adopted to protect the most critical elements identified during the analysis and avoiding confusions when communicating the results of the analysis. Thus, the potential of the ontological approach to enhance understanding and communication within the security team, as well as between the safety and security teams, was demonstrated.
In recent years, especially in Europe, cloud-based railway signalling systems are becoming practical. These systems centrally control field equipment (such as signals and switches) from a central unit located remotely via a network, rather than being installed at the field equipment's location. To achieve a highly available and cost-effective cloud-based railway signalling system, a COTS (Commercial-Off- The-Shelf) based cloud railway signalling system have been proposed, which implements the central unit with cost-effective and high-performance COTS hardware. Railway signalling systems require high levels of safety and reliability. For safety, it is required that the occurrence of hazardous failures leading to train derailments or collisions be once every 10,000 to 100,000 years. Regarding reliability, it is required to maintain adequate availability of the system during the mission time (approximately 20 hours) and to avoid emergency stops as much as possible to ensure safety. This study discusses countermeasures against non-human-induced failures and human-induced failures, which are challenges for the aforementioned system. For non-human-induced failures, we focus on transmission interruptions lasting several seconds in the message transmission path between the central unit and the field terminals connected near each field equipment. For human-induced failures, we focus on the compromise of less than the majority of the multiplexed central units. We then propose countermeasures for these challenges. Next, we construct a Markov model to describe system behavior in various scenarios: normal conditions, transmission interruption, compromise, and simultaneous transmission interruption and compromise. Furthermore, based on these models, we analytically evaluate the reliability and safety of the proposed countermeasures.
Global surrogate model is used to replace complex spatial systems for reliability analysis, performance evaluation and optimization, which requires sufficient samples. To reduce the overhead of expensive simulation experiments with high fidelity, a batch adaptive sampling method that synthesizes the informativeness and diversity of samples is proposed. Support vector-enhanced batch adaptive sampling (SV-BAS) method utilizes the properties of support vector machines to add sampling points in batches using a hybrid sampling strategy that combines local exploration and global exploitation. Utilizing the pipeline principle of support vectors, the support vectors are first filtered using a low-precision support vector machine. Then, a high-precision support vector machine is used to compute the predicted errors of support vectors with no computational cost, which is used for local exploration. The sparsity of support vectors and the sampling center method based on the distance criterion are used to ensure the diversity of sample points in the batch sampling. The performance of the proposed method is verified by the simulations using six numerical functions with varying features and dimensions. The results show that compared with other single-sample adaptive sampling methods, the proposed algorithm performs better in terms of model accuracy as well as sampling efficiency. Further, the proposed algorithm is used for remote sensing satellite effectiveness assessment and has good application prospects.
A method used for fault management and localization in military systems is presented. Fault localization, the process of determining the approximate location of a fault, is a key component of this method. The method utilizes the fault propagation behaviour of the system and power supply interfaces within the system items for fault isolation purposes. Fault isolation, which involves determining the location of a fault to the extent necessary to effect repair, is crucial for effective maintenance. In addition to this, special fault scenarios are introduced to the fault management algorithm to handle various system fault evaluation scenarios. The fault diagnosis findings, the faulty items and derived Built-in tests (BIT) results, of the algorithm are demonstrated on user interface for the maintenance personnel or operator to initiate appropriate corrective actions.
This study investigates the evaluation of the representativeness of datasets in autonomous driving systems using statistical distance metrics. Eight different datasets, created in the Carla simulation environment, cover various driving conditions, including normal and impaired lighting scenarios, alternative routes, and challenging conditions such as power outages. The datasets were designed to represent similar routes under different conditions. Various distance metrics- Wasserstein, Kuiper, Anderson-Darling, Chernoff, DTS, and CVM-were applied to measure pairwise dataset distances. We anticipated that the dataset for a given route under ideal conditions would exhibit a large distance measure (of any of the listed distance measures) compared to the same route under impaired conditions (e.g., a power failure at the streetlights). However, we were particularly interested in whether a measurable jump at a (potential threshold) value could be recognized even with a smaller drop in dataset condition quality. The results of the study show that a normalization of these distance measures enables precise divergence comparisons and the determination of meaningful threshold values. This in turn means that normalized deviation measures can effectively identify deviations in real time, hence contributing to the development and monitoring of more reliable autonomous driving models.