This presentation was given as part of the American Nuclear Society Risk-informed, Performance-based Policy and Procedures Committee (RP3C) Community of Practice (CoP). For more information on the RP3C CoP, please visit https://www.ans.org/standards/rp3c/cop/ . This presentation took place on January 27, 2023. The presentation video recording can be found online at https://youtu.be/rq4LdpfIbuI .
A Python interface is developed for the GPWR Simulator to automatically simulate cyber-spoofing of different steam generator parameters and plant operation. Specifically, steam generator water level, feedwater flowrate, steam flowrate, valve position, and steam generator controller parameters, including controller gain and time constant, can be directly attacked using command inject, denial of service, and man-in-the-middle type attacks. Plant operation can be initialized to any of the initial conditions provided by the GPWR simulator. Several different diagnostics algorithms have been implemented for anomaly detection, including physics-based diagnostics with Kalman filtering, data-driven diagnostics, noise profiling, and online sensor validation. Industry-standard safety analysis code RELAP5 is also available as a part of the toolkit. Diagnostics algorithms are analyzed based on accuracy and efficiency. Our observations indicate that physics-based diagnostics with Kalman filtering are the most robust. An experimental quantum kernel has been added to the framework for preliminary testing. Our first impressions suggest that while quantum kernels can be accurate, just like any other kernels, their applicability is problem/data dependent, and can be prone to overfitting.
Dr. Romney Duffey is an internationally recognized multi-disciplinary scientist, consultant, manager, speaker, author, and poet. Born on June 26, 1942, and educated in England, Dr. Duffey has over 50 years of unique experience in the UK, USA, and Canada on nuclear technology development, risk assessment, industrial safety, nuclear-system design, and accident analysis. As an applied physicist, his career has included a wide span of senior power-industry and government positions as researcher, executive advisor, senior manager, published author, lecturer, and consultant. Dr. Duffey is globally known as a developer of new concepts and designs with innovation advantages and market potential, for contributions to risk management and reliability applications, and to the enhancement of our understanding of the physical world. In addition to working in the USA, Canada, and the UK his international industrial, laboratory, and technical connections are worldwide.
The time required to trip a pressurized water reactor (PWR) by inserting malicious signals into its steam generator (SG) control system has been studied using the Generic PWR (GPWR) Simulator. A semi analytical model is developed to approximately reproduce the simulator response and understand the dynamics of the control unit. A series of two proportional-integral controllers determines control action according to preset constants, the readings from the feedwater level sensor, and those from feedwater and steam flowrate transmitters. It is observed that the most important factor that determines whether a trip will occur is how much additional water is added to or withheld from the SG over time compared to normal operating conditions. In order to determine the effects of control action on the SG, changes in mass inventory are considered. This approach models the SG water level as a function of mass inventory and has a backward temporal memory. A Python interface is developed for the GPWR framework to automatically simulate different spoofing scenarios and post-process the related data. We observe that the trip times predominantly depend on flow mismatch and/or level errors. Controller parameters, including the integral time and gain constants, either speed up or slow down the rate of progression to a trip set point but do not cause a trip by themselves. The reactor can trip on a high-level signal when the reading crosses above 78%, increased from its reference level of 57%, or a low-level reading when it is below 25%. The present results show roughly how long the operators would have to respond to an attack, given a specific set of spoofing signals within the issue space analyzed. We have generated a simple surface by fitting a combination of exponential functions to the data obtained from the GPWR Simulator. In general, trips on a low level have been observed to occur faster than those on a high level.Published by Elsevier Ltd.
The Nearly Autonomous Management and Control System (NAMAC) is a comprehensive control system that assists plant operations by furnishing control recommendations to operators in a broad class of situations. This study refines a NAMAC system for making reasonable recommendations during complex loss-of-flow scenarios with a validated Experimental Breeder Reactor II simulator, digital twins improved by machine-learning algorithms, a multi-attribute decision-making scheme, and a discrepancy checker for identifying unexpected recommendation effects. We assessed the performance of each NAMAC component, while we demonstrated and evaluated the capability of NAMAC in a class of loss-of-flow scenarios.
Strategies for securing digital instrumentation and control (I&C) systems within the nuclear industry are provided by multiple standards and guidance documents.However, since selection and use of security controls outlined in these documents are frequently only considered during or after installation, there are often limitations on their use, such as technological constraints related to design or operation.Furthermore, alternative controls intended to provide the same or similar security countermeasure as the primary control may also be infeasible at these stages, leaving the I&C system vulnerable to cyber-attacks.The limitations associated with 'bolting on' security controls late in the systems engineering lifecycle can be reduced by integrating Cyber-Informed Engineering (CIE) into the process.This paper evaluates the use of CIE during the high-level design stage of a hydrogen generation project where heat and electricity are provided by a nuclear power plant.Applying CIE to this project highlighted potential cyber vulnerabilities of the initial design, leading to recommendations for process flow and I&C system design modifications to reduce, and at times eliminate, the risk from both deliberate and unintentional cyber incidents.
This paper develops a Nearly Autonomous Management and Control (NAMAC) system for advanced reactors. The development process of NAMAC is characterized by a three layer-layer architecture: knowledge base, the Digital Twin (DT) developmental layer, and the NAMAC operational layer. The DT is described as a knowledge acquisition system from the knowledge base for intended uses in the NAMAC system. A set of DTs with different functions is developed with acceptable performance and assembled according to the NAMAC operational workflow to furnish recommendations to operators. To demonstrate the capability of the NAMAC system, a case study is designed, where a baseline NAMAC is implemented for operating a simulator of the Experimental Breeder Reactor II during a single loss of flow accident. When NAMAC is operated in the training domain, it can provide reasonable recommendations that prevent the peak fuel centerline temperature from exceeding a safety criterion.
The document is the Final Technical Report for the Nuclear Energy University Program’s Integrated Research Project (IRP) on “Development and Application of a Data-Driven Methodology for Validation of Risk-Informed Safety Margin Characterization (RISMC) Models”. The project goal is to develop and demonstrate a data-driven methodology for validation of advanced computer models used in nuclear power plant safety analysis. Specifically, the advanced computer models are those in the toolkit developed to support risk-informed safety margin characterization (RISMC), an integrated deterministic/probabilistic safety analysis methodology developed in the Department of Energy’s Light Water Reactor Sustainability (LWR-S) program.
A new generation of dynamic methods has started receiving attention for nuclear reactor probabilistic risk assessment (PRA). These methods, which are commonly referred to as dynamic PRA (DPRA) methodologies, directly employ system simulators to evaluate the impact of timing and sequencing of events (e.g., failure of components) on accident progression. Compared to classical PRA (CPRA) methods, which are based on static Boolean logic structures such as fault trees and event trees (ETs), DPRA methods can provide valuable insights from an accident management perspective. However, as of today this class of methods has received limited attention in practical applications. One factor is DPRA research and development has progressed mostly as an alternative to state-of-practice CPRA methods (i.e., disconnected from currently employed PRA methods). This disconnect is addressed in this paper by presenting several algorithms that can be employed to bridge the gap between CPRA and DPRA. First, algorithms designed to identify differences between CPRA and DPRA results are presented. The identification process compares the CPRA ET sequence or the minimal cut sets (MCSs) obtained by CPRA with the set of transients simulated by the DPRA. If inconsistencies are observed, solutions are provided to incorporate these differences back into the CPRA by employing DPRA to inform existing CPRA. We performed this incorporation either probabilistically (e.g., by updating MCS probability) or topologically (by adding new branching conditions or sequences in the ET).
The safety goals adopted by the U.S. Nuclear Regulatory Commission (NRC) consist of two qualitative safety goals backed up by two quantitative health objectives (QHOs). The QHOs establish risk limits for severe accidents in terms of their radiological consequences to affected individuals, in particular, the average individual health risks of early fatality and latent cancers from radiation exposure of members of the public living in the vicinity of a nuclear power plant. This paper is devoted to a reexamination of the coverage of the current safety goals as they constrain (or fail to constrain) the total (radiological and nonradiological) risk posed by nuclear power plant operation. Specifically, we suggest the need to address societal consequences. By societal consequences, we mean measures of consequences that reflect the number of people affected and the offsite effects both radiological and nonradiological, not just the individual risks. Recent Level 3 probabilistic risk assessments suggest that given a high likelihood of evacuation of the close-in population before any release occurs the current QHOs are satisfied by large margins, and the experience of an actual severe accident at Fukushima showed that actual human health effects from released radiation were not the dominant consequences, as there were no early fatalities and no measurable increases expected in cancer rates above the baseline rates in the Japanese population. Hence, regardless of accident probability, Fukushima-type accidents with evacuation would satisfy the NRC's health-related safety goals. However, there were very significant societal costs in that large numbers of people were relocated for long periods and there was substantial property damage and community disruption along with the costs of recovery and decontamination. We argue that, in addition to the risks addressed in the current safety goals, societal risk should also be considered. This paper discusses specific possibilities for a goal and an associated quantitative objective.
Current system thermal-hydraulic codes have limited credibility in simulating real plant conditions, especially when the geometry and boundary conditions are extrapolated beyond the range of test facilities. This paper proposes a data-driven approach, Feature Similarity Measurement FFSM), to establish a technical basis to overcome these difficulties by exploring local patterns using machine learning. The underlying local patterns in multiscale data are represented by a set of physical features that embody the information from a physical system of interest, empirical correlations, and the effect of mesh size. After performing a limited number of high-fidelity numerical simulations and a sufficient amount of fast-running coarse-mesh simulations, an error database is built, and deep learning is applied to construct and explore the relationship between the local physical features and simulation errors. Case studies based on mixed convection have been designed for demonstrating the capability of data-driven models in bridging global scale gaps.
Despite the progress in high performance computing, Computational Fluid Dynamics (CFD) simulations are still computationally expensive for many practical engineering applications such as simulating large computational domains and highly turbulent flows. One of the major reasons of the high expense of CFD is the need for a fine grid to resolve phenomena at the relevant scale, and obtain a grid-independent solution. The fine grid requirements often drive the computational time step size down, which makes long transient problems prohibitively expensive. In the research presented, the feasibility of a Coarse Grid CFD (CG-CFD) approach is investigated by utilizing Machine Learning (ML) algorithms. Relying on coarse grids increases the discretization error. Hence, a method is suggested to produce a surrogate model that predicts the CG-CFD local errors to correct the variables of interest. Given high-fidelity data, a surrogate model is trained to predict the CG-CFD local errors as a function of the coarse grid local features. ML regression algorithms are utilized to construct a surrogate model that relates the local error and the coarse grid features. This method is applied to a three-dimensional flow in a lid driven cubic cavity domain. The performance of the method was assessed by training the surrogate model on the flow full field spatial data and tested on new data (from flows of different Reynolds number and/or computed by different grid sizes). The proposed method maximizes the benefit of the available data and shows potential for a good predictive capability.
Probabilistic risk assessment (PRA) based on event- and fault-tree analyses has long been a popular and powerful technique for formulating system- and plant-level risk scenarios in high-hazard facilities [1]. Event- and fault-tree-based PRA is commonly performed in the nuclear industry using tools like Systems Analysis Programs for Hands-on Integrity Reliability Evaluation (SAPHIRE) [2] or the Computer Aided Fault Tree Analysis System (CAFTA) [3]. Often, the goal of a PRA effort is to assess the risk of events having high consequences to the public or the environment. In such a case, the fault-tree and event-tree analyses in a PRA mostly focus on initiating events and system and component failures that would result in such consequences. However, a much broader spectrum of consequences is possible in principle from cyber-attack: a computer system could be exposed to an attack that could lead to disruption, financial loss or other damage to the system and its organization. It is not only a major threat for businesses, but has recently impacted infrastructure utilities. In a nuclear power plant, the potential consequences of cyber-attack may range from an inconvenience to unplanned reactor shutdowns or to plant damage, or (in principle) worse; but the low-consequence end of this accident spectrum is not typically addressed using PRA models. Hence it is important to understand better, and minimize the risk of, cyber-attacks in nuclear power plants. The proven fault-tree analysis methodology holds a strong promise of a comprehensive, robust, scalable, and efficient assessment of cyber-attack scenarios in NPPs. This paper presents a fault-tree based formulation for a cyber-attack scenario in a water flow-loop comprised of flow controllers and pumps, controlled via manual controls, wired signals and wireless signals that is susceptible to a cyber-attack. The fault-tree analysis technique is applied to a variety of cyber-attacks that may result in system failure. The analysis provides a comprehensive picture of the attack scenarios and an exhaustive list of attack pathways that are critical for causing system failure, paving the way for formulating strategies of performing cyber-attack prevention analysis.
Over the past decades, several computer codes have been developed for simulation and analysis of thermal-hydraulics and system response in nuclear reactors under operating, abnormal transient, and accident conditions. However, simulation errors and uncertainties still inevitably exist even while these codes have been extensively assessed and used. In this work, a data-driven framework (Optimal Mesh/Model Information System, OMIS) is formulated and demonstrated to estimate simulation error and suggest optimal selection of computational mesh size (i.e., nodalization) and constitutive correlations (e.g., wall functions and turbulence models) for low-fidelity, coarse-mesh thermal-hydraulic simulation, in order to achieve accuracy comparable to that of high-fidelity simulation. Using results from high-fidelity simulations and experimental data with many fast-running low-fidelity simulations, an error database is built and used to train a machine learning model that can determine the relationship between local simulation error and local physical features. This machine learning model is then used to generate insight and help correct low-fidelity simulations for similar physical conditions. The OMIS framework is designed as a modularized six-step procedure and accomplished with state-of-the-art methods and algorithms. A mixed-convection case study was performed to illustrate the entire framework.
This report documents the activities performed during the FY2018 for the DOE Light Water Reactor Sustainability (LWRS) Program, Risk-Informed System Analysis (RISA) Pathway, Enhanced Resilient Plant (ERP) Systems research. The purpose of the RISA Pathway research and development is to support plant owner-operator decisions with the aim to improve the economics, reliability, and maintain the high levels of safety of current nuclear power plants over periods of extended plant operations. The concept of ERP refers to the combinations of Accident Tolerant Fuel (ATF), optimal use of Diverse and Flexible Coping Strategy (FLEX), enhancements to plant components and systems, and the incorporation of augmented or new passive cooling systems, as well as improved fuel cycle efficiency. The objective of the ERP research effort is to use the RISA methods and toolkit in industry applications, including methods development and early demonstration of technologies, in order to enhance existing reactors safety features (both active and passive) and to substantially reduce operating costs through risk-informed approaches to plant design modifications to the plant and their characterization. There are two main focus areas in FY2018 for the ERP R&D efforts. One is to evaluate the risk impact brought by the ATF designs and FLEX in the selected accident scenarios. The other is to investigate various approaches to accomplish the ERP research objective, i.e., use RISA methods and toolkit to enhance existing reactors safety features and reduce plant operating costs.
The U.S. Nuclear Regulatory Commission (NRC) is considering a rulemaking that would revise requirements in 10 CFR 50.46 [also known as the emergency core cooling system (ECCS) rule]. Experimental work sponsored by the NRC suggested that the current regulatory acceptance criteria on ECCS performance during design-basis accidents are actually nonconservative for higher-burnup fuel, that embrittlement mechanisms not contemplated in the original criteria exist, and that the 17% limit on oxidation is not adequate to preserve the level of ductility that the NRC originally deemed to be warranted for adequate protection. The new rule imposes new acceptance criteria and is expected to be in effect within this decade. An implementation plan was developed that will give individual plants up to 7 years with which to comply once the rule is amended, depending on the status of each plant's analysis of record, the effort involved, and existing analytical margin to the limits.The proposed rule may challenge U.S. light water reactor fleet operational flexibility and economics. Within the U. S. Department of Energy Light Water Reactor Sustainability Program, the Idaho National Laboratory is pursuing an initiative that is focused on industry applications using Risk-Informed Safety Margin Characterization (RISMC) tools and methods applied to issues that are of current interest to the operating fleet. The mission of RISMC is to provide cost-beneficial approaches to safety analysis by leveraging modern methods, augmented tools (a combination of existing and new), and repurposed data (existing, but used in a new way).