Robust navigation in changing marine environments requires autonomous systems capable of perceiving, reasoning, and acting under uncertainty. This study introduces a hybrid risk-aware navigation architecture that integrates probabilistic modeling of obstacles along the vehicle path with smooth trajectory optimization for autonomous surface vessels. The system constructs probabilistic risk maps that capture both obstacle proximity and the behavior of dynamic objects. A risk-biased Rapidly Exploring Random Tree (RRT) planner leverages these maps to generate collision-free paths, which are subsequently refined using B-spline algorithms to ensure trajectory continuity. Three distinct RRT* rewiring modes are implemented based on the cost function: minimizing the path length, minimizing risk, and optimizing a combination of the path length and total risk. The framework is evaluated in experimental scenarios containing both static and dynamic obstacles. The results demonstrate the system's ability to navigate safely, maintain smooth trajectories, and dynamically adapt to changing environmental risks. Compared with conventional LIDAR or vision-only navigation approaches, the proposed method shows improvements in operational safety and autonomy, establishing it as a promising solution for risk-aware autonomous vehicle missions in uncertain and dynamic environments.
This study uses comparative life cycle assessment to compare the life cycle impacts of three power systems for a 10.5-m Norwegian gillnet fishing vessel: a conventional diesel-mechanical (DMS), a diesel-battery parallel hybrid (PHS), and a hydrogen fuel cell-battery series hybrid (SHS) system. Results show that direct emissions are dominated by combustion-related impacts, while component manufacturing drives toxicity and resource categories. The PHS reduces global warming potential (GWP) by 28%, and the SHS by up to 91% compared to the DMS when powered by low-carbon electricity and green hydrogen from electrolysis in Norway. However, both alternatives shift burdens towards manufacturing-related impact categories. Sensitivity analysis highlights the critical role of electricity and hydrogen supply pathways: fossil-based inputs can erase benefits, while localised low-carbon electrolysis enables slight improvements. The findings stress that battery and fuel cell systems can reduce fishing vessel emissions meaningfully only when coupled with clean energy supply chains.
With increasing autonomy in systems, the role of software becomes more prominent as it overtakes human operator functions. The software in autonomy differs from automation with respect to functionality, implementation, and complexity, and software failures contribute to system and operational risk. Such failures, however, are often not sufficiently catered for in current risk assessments and mitigation processes, as they are challenging to identify and quantify, in particular, in the early conceptual design phase. Software reliability is not the same as software safety, as the latter encompasses the context and use of the software, as well as interactions and potential cascading failures to hardware, humans, and the environment. It is also difficult to investigate cascading effects on the system that may follow from software failures. The objective of this paper is to propose a novel classification taxonomy to support a more thorough identification of software failures for systems with different degrees of autonomy, as well as for software implementation techniques. The risk from software is interwoven into the design, development, validation, and verification processes, impacting safe operation. The proposed taxonomy can be used iteratively from the early design phase as the detailed design concepts evolve. The level of abstraction for system and software functions decreases with the design and development process. The validation and verification processes must ensure the software’s safety and reliability on different system abstraction levels. The software taxonomy in this paper includes relevant causes, consequences, and process relationships, and has been created based on existing industry classifications, research, and system models. A case study applying the taxonomy to navigation and collision avoidance functions on the subsystem level of a Maritime Autonomous Surface Ship (MASS) is performed. Software properties extracted from existing systems and knowledge are transformed into a functional model. Each software failure is then described in the context of the system level valid for the design, development, validation, and verification processes for MASS. The overall outcome of the paper may contribute to the safer design of systems through enhanced identification of potential hazards and software failures, leading to improved risk assessments and, as such, a better basis for defining more efficient safety requirements for autonomous systems from the early system development. Even though the paper exemplifies the taxonomy and classification by focusing on MASS, the work has relevance to other types of software-intensive systems.
This article develops and experimentally tests a supervisory risk controller used to increase the safety of drone operations. Its task is to monitor the state of the drone and environment and to use this information to automatically change safety-critical parameters in real-time during operation. A case study of a tethered industrial inspection drone is considered. A system theoretic process analysis (STPA) is performed to identify how the system can fail. A Dynamic Decision Network (DDN), used as an online risk model, is built based on the results of the STPA. An optimization approach is used to choose an optimal parameter configuration that ensures an acceptable risk level. Through experimental tests, it is demonstrated how the supervisory risk controller is able to identify the state of the drone and the environment by combining information from multiple measurements over time and how it chooses values for the maximum speed, safety distance, and maximum vertical acceleration that produces an acceptable risk level. The parameters are updated during flight based on the output from the supervisory risk controller. When no parameter set can ensure an acceptable risk level then a recommendation of aborting the mission is sent to the human operator. Video of the experimental results can be found at https://youtu.be/RKhG9bguRJY
This paper presents the novel concept called supervisory risk control (SRC) which provides risk-based rationality improving the safety and intelligence of autonomous systems. Autonomous cyber-physical systems enable new and challenging types of transport, efficient mapping and monitoring of oceans and land, and inspections and interventions of structures, with less dependence on human operators. More autonomous functionality may improve operational efficiency, but society and authorities are reluctant to approve highly autonomous systems due to uncertainties related to safe performances. The SRC concept therefore implements online risk assessment and modeling into control system algorithms. This enables the systems to assess the risk level and make decisions based on perception, comprehension, and projection of future operational risk scenarios (i.e., “risk-based rationality”), which today primarily is done by a human operator. In addition to presenting the concept, the paper gives results from development, simulation, and field experiments related to SRC. The research results show the feasibility of including risk aspects more extensively in the control systems than existing solutions, e.g., for machinery systems and navigation of autonomous ships. The paper also pinpoints the future research and development needs. The main application area so far is autonomous marine and maritime systems and operations, although the results are relevant across domains for improved system safety, integrity, and reduced accident risk.
Understanding risk-influencing factors (RIFs) associated with the occurrence of maritime accidents is important to prevent their future occurrence, identify high-risk ships, and properly influence policy. However, current methods often suffer from selection bias or do not account for variations in ship exposure, leading to biased or incomplete assessments. This study addresses these gaps by incorporating AIS-derived activity metrics as offset variables in regression analysis. This transformation of the dependent variable leads to the analysis of accident rates. The method is applied to ship losses of command (i.e., loss of propulsion, loss of electrical power, or loss of directional control / steering) by cargo ships in Norwegian waters from 2017 to 2021. Significant variables influencing the rate of loss of command include ship’s flag state, ship manager domicile, number of inspection deficiencies, propulsion redundancy, and the use of a single fuel onboard. Inspection deficiencies and sailing with a flag of convenience are associated with increased rates. Sailing with a Norwegian ship manager, propulsion redundancy, and a single fuel type onboard are associated with decreased rates. Incorporating measures of ship activity as exposure significantly improves the overall model fit, leading to better identification of RIFs associated with the occurrence of ship losses of command. Sensitivity analyses using sailed distance as exposure and the Cox proportional hazards model demonstrate overall robustness. The results are beneficial for identifying high-risk ships from the perspective of vessel traffic management and can be used for decision-making. The method has promising potential for the future analysis of RIFs associated with other types of maritime accidents.
The rapid development of Maritime Autonomous Surface Ships (MASS) marks a significant leap towards enhanced efficiency and safety in the maritime industry. In this context, a transition process between modes of operation (MoO) is crucial for maintaining navigational safety and operational effectiveness. These transitions, however, may introduce complex functional couplings that generate performance fluctuations, posing new challenges for navigation safety. Despite increasing focus on MASS safety, current research lacks a systematic approach to identify coupling risks during MoO transitions. To fill this gap, this study presents a four-step quantitative framework that integrates Sequentially Timed Events Plotting, the Functional Resonance Analysis Method and Monte Carlo simulations. The framework identifies key functions and their interrelations during MoO transitions, quantifies the performance variability in the couplings, and pinpoints high-risk couplings and resonance paths. A case study focusing on a MASS encountering fishing vessels without Automatic Identification System data is presented to illustrate the framework's application. The results reveal high-risk resonance paths involving situational awareness of the autonomous navigation system, ship-to-shore data transmission, and decision-making by seafarers on board and remote operators. Twelve measures are proposed, including AI-driven monitoring, multi-sensor fusion, and adaptive communication protocols to mitigate operational risks to ensure safe MoO transitions.
Safety is a crucial factor in the design and operation of autonomous ships. With the development of electrified autonomy, monitoring battery systems is essential, as their possible failures impact the propulsion of autonomous ships and can cause power-system blackouts. Therefore, real-time risk monitoring must be included in the overall control architecture of autonomous ships to keep supervisors in remote control centres aware of the real-time risk status. This study proposes a method for the real-time risk monitoring of battery systems based on risk indicator data. The proposed method combines risk analysis models, inconsistency, and correlation analysis to evaluate the real-time risk of battery systems and diagnose any aged or abnormal battery cells. The method is applied to a pilot all-electric autonomous passenger ferry milliAmpere 2. Results indicate that the onboard battery system operated normally despite the inconsistency of two battery modules at the beginning of the service. Two battery cells were diagnosed to have caused this inconsistency, which could substantially shorten the life of the other batteries in the same battery modules and even lead to their failure. Real data from milliAmpere 2 validate the proposed method, showing promising potential for real-time risk monitoring of battery systems.
The demand for autonomous robotic solutions capable of operating in complex and dangerous environments - such as those found in inspection and maintenance (I&M) operations - is growing. However, the success of autonomous system deployments relies heavily on their actual and human-perceived safety. Current AI-based predictions often lack robust uncertainty handling, which could lead to catastrophic outcomes. In the SAFESUB project, we address this gap by developing a framework for reliable uncertainty estimation and control throughout a sensing, perception, and control pipeline for autonomous uncrewed underwater vehicle (UUV) interventions. In this paper, we present the overall SAFESUB concept, detail relevant opportunities (use cases) and research challenges for future autonomous UUV intervention in I&M operations, and outline our preliminary results and next steps for the SAFESUB concept components: 1) A novel 3D underwater camera system with built-in uncertainty estimation of sensor data, 2) a basis for perception for 6-DOF pose estimation and corresponding uncertainty, and 3) an uncertainty-aware UUV intervention architecture designed for risk reduction in operations. The components are under development, and details will be shared in subsequent component-specific papers as the purpose of this paper is to give a project-wide overview and promptly share the SAFESUB concept. The paper also explores the state of the art on underwater sensing, perception, and intervention techniques, and provides a categorization of UUV operation concepts.
Vessel losses of command (e.g., propulsion, electrical power, or steering failure) can serve as the initiating event for significant maritime accidents, such as grounding. It is therefore important to estimate the frequency of such events for navigational risk assessments. Despite the existence of previous studies, new data have become available that may reveal more precise and useful information for risk estimations and accident prevention. This paper analyzes two databases of vessel losses of command within Norway’s economic exclusive area over a five year period. The study utilizes a novel database of incidents observed by the Norwegian Coastal Administration’s (NCA) Vessel Traffic Services (VTS), in addition to incidents reported to IHS Markit over the same five year period. Automatic identification system (AIS) data is used to construct activity metrics of vessel activity, which are used to compute vessel loss of command incidence rates for ship types. To account for under-reporting, capture–recapture methods are used to calculate adjusted incidence-rates. The duration of each incident is recorded and used to construct distributions of repair times. Probabilities of towing and anchoring are computed for ship types and incident location. The results indicate that previous studies may have underestimated the incidence of vessel loss of command. Using the best-case scenario, cargo ships and tankers suffer losses of command more frequently than other ship types. Significant under-reporting of losses of command was observed in the IHS Markit database.
Autonomous ships require remote supervision from a human operator to ensure safety. However, there are knowledge gaps concerning human factor influences on remote supervisory control. We investigate the influence of five factors on remote supervisory control during simulated intervention scenarios: (i) Skillset, represented by gamers and navigators; (ii) Monitoring Time, represented by either 5 or 30 min of passive monitoring; (iii) Number of Vessels, represented by either one or three vessels; (iv) Available Time, represented by 20- or 60-s critical time windows; (v) Decision Support System (DSS), represented by availability of a DSS. The experiment was a randomized factorial design where participants (n = 32) completed two interventions: first a handover (automation detects a critical event and hands over control) and then a takeover (operator detects a critical event and takes over control). We observed: (i) gamers and navigators both demonstrated transferrable skillsets, but neither group excelled over the other; (ii) monitoring time affected boredom, but this translated to minor performance effects. Moreover, performance was reduced under conditions of (iii) supervising three vessels, (iv) low time availability, and (v) unavailable DSS. These outcomes contribute to the empirical basis for assessing maritime human factors in remotely controlled and autonomous ship design.
This paper presents a method for developing and testing a risk-based control system, as a first step towards including the human supervisor explicitly in the design of the system. The result is a control system with improved decision-making capabilities compared to existing control systems. The methodology presented in the paper uses the Systems Theoretic Process Analysis (STPA) to analyse the risks of an autonomous ship within its concept of operations (CONOPS), and a Human-STPA (H-STPA) is used to analyse human responsibilities and involvement. The STPA results are then used to construct a Bayesian belief network (BBN)-based risk model to assess the operational risk of the ship. This is represented as a risk cost, describing the expected cost of consequences caused by potential hazardous events. This cost is combined with fuel costs, operations costs, and the potential loss of income if new missions are not undertaken using a supervisory risk controller (SRC). The SRC is capable of making decisions about how the ship should be safely operated and notifies the human supervisor in due time when it is necessary for them to take control. The last part of the methodology presented in this paper is testing the control system using a set of verification objectives based on results from the STPA and H-STPA. A case study involving an autonomous cargo ship with a human supervisor located in a remote operation center (ROC) is included; it shows that the proposed control system can operate the ship safely in different conditions and situations. By designing the SRC to notify the human supervisor before it reaches its operational limit, the ship is able to operate in a wider range of conditions compared to when just the autonomous control system is in charge. Hence, the proposed methodology shows promising results and provides useful insights related to shared control for autonomous ships.
The decarbonization of the shipping industry is a hot topic and new emission reduction goals, regulations, and initiatives all over the world underline its importance. These goals apply to the ocean going fleet, as well as coastal shipping and fisheries. Both academia and industry, work on the development and testing of new technologies to reach emission reduction targets. Besides technical feasibility and economic viability, the safety of new power and propulsion systems must be considered in this process. In this paper, the Systems Theoretic Process Analysis (STPA) method is used for hazard identification and comparison of two alternative hybrid power and propulsion systems for a small-scall fishing vessel. The assessment method allows for identifying focus areas for hazard reduction in a systematic manner. System safety requirements derived from the assessment can be considered when designing power and propulsion systems. Based on the results, a discussion of the method and the usefulness of the results is given. The main findings are that the assessment provides valuable insights into the hazards introduced by new power and propulsion systems in a qualitative manner. For a quantification of the risk, further work and an extension of the assessment are needed. The STPA results show that especially the control of the power sources and their interactions internally and externally with the consumer side are crucial. Therefore, special attention should be given to the design of the automated control system, feedback system, and user interaction with the system.
With higher autonomy in maritime systems, tasks and responsibilities are moved from the human operator to software, increasing the complexity and the importance of safe and reliable functionality. Software failures, however, may be introduced from the early life cycle phases intentionally or unintentionally, and these must therefore be mitigated by safe and secure design approaches. A challenge is that existing methods are not particularly well-suited for analyzing software risks. Thus, the objective of this paper is to propose a systematic and efficient software failure identification approach by extending the Systems-Theoretic Process Analysis (STPA) with a software failure taxonomy and the System Modeling Language (SysML). This enables the control structure in STPA to cover both the dynamic and static aspects of the software functions. Combined with an implementation platform independent questionnaire, this gives a more systematic and guided search for potential software failures than existing approaches. To demonstrate the proposed approach, a case study on a ferry's navigation system that operates in manual control or semi-autonomous mode is performed. In the case study, the focus is on creating an avoidance map data structure, including both moving and static obstacles to be avoided by the ferry, and the subsequent process of collision risk warning calculation. Software failures are identified and evaluated in collision scenarios where the ferry operates under foggy conditions. The paper shows that the proposed systematic approach provides an improved process for identifying and analyzing critical software failures. This facilitates enhanced risk mitigation in the design and testing phases contributing to autonomous systems' safety and security.