<p>This article develops and experimentally tests a supervisory risk controller used to increase the safety of drone operations. Its task is to monitor the state of the drone and environment and to use this information to automatically change safety-critical parameters in real-time during operation. </p> <p>A case study of a tethered industrial inspection drone is considered. A system theoretic process analysis (STPA) is performed to identify how the system can fail. A Dynamic Decision Network (DDN), used as an online risk model, is built based on the results of the STPA. An optimization approach is used to choose an optimal parameter configuration that ensures an acceptable risk level.</p> <p>Through experimental tests, it is demonstrated how the supervisory risk controller is able to identify the state of the drone and the environment by combining information from multiple measurements over time and how it chooses values for the maximum speed, safety distance, and maximum vertical acceleration that produces an acceptable risk level. The parameters are updated during flight based on the output from the supervisory risk controller. When no parameter set can ensure an acceptable risk level then a recommendation of aborting the mission is sent to the human operator.</p> <p>Video of the experimental results can be found at https://youtu.be/RKhG9bguRJY</p>
Autonomous transportation is an increasingly popular concept and is gradually becoming a reality. This transformation also changes the way people travel. For example, the autonomous ferry is an emerging alternative for residents living in coastal areas. To evaluate the safety of an autonomous ferry, a thorough safety review is necessary. This paper makes an initial attempt by developing a model for performing a risk assessment of collisions between an autonomous ship with manned vessels and applying this to a specific ferry operating in a canal. The safety barriers to prevent a collision are identified, as well as the respective failure modes. A Bayesian belief network is employed to model the collision and to quantitively assess the collision risk of the autonomous ferry. Relevant data are collected to perform a quantitative risk analysis. By running the model, the likelihood of a collision is calculated. A sensitivity analysis is also performed to identify the most contributing causes.
The Norwegian aquaculture industry has the potential to become the country’s leading ocean industry in the future. More than 99% of the produced biomass is Atlantic salmon and trout. Norwegian fish farming is characterised by operations that are susceptible to changing weather, wind and currents, and face challenges in terms of safety for fish, personnel, environment and material assets. Previous research and accident analyses reveal an incomplete knowledge of risk factors during aquaculture operations. In order to raise standards of safety in the workplace, operators need to be aware of the challenges to safety in their work environment. The objective of this paper is to describe and discuss the current status of the implementation of risk assessments in the Norwegian aquaculture industry, according to Norwegian legislation and compared with recommended requirements in the Norwegian standard for risk assessments (NS 5814). This standard largely follows ISO 31000 for risk management. We also propose, test and evaluate an improved approach to risk assessment that will ensure stronger operator involvement. Our findings demonstrate that there are several gaps between the current practice and the standard. At the present time, operator involvement is not sufficient according to the regulatory requirements of internal control. Although the approach improves critical steps in the risk assessment procedure, it remains to be implemented in the fish farming industry.
Maritime accident statistics are used as a key part of the IMO's formal safety assessment (FSA), a risk assessment methodology to guide policy decisions in the maritime industry.Under-reporting of maritime accidents can inhibit the accuracy of results derived from the FSA, therefore having a direct influence on maritime policy.The objective of this work is to perform comparisons between accident databases, and to investigate the degree to which underreporting is biased by factors including the type of accident, degree of severity, and ship type.This study analyzes databases of reported maritime casualties from 1) IMO GISIS, 2) IHS Fairplay, and 3) the United States Coast Guard CGMIX.The databases are subset to an eight-year period and for commercial ships greater than 100 gross tonnage (GT) to enable a direct comparison.The reporting rates for the GISIS and IHS databases are calculated for accident type, accident severity, and ship type.Results indicate that the GISIS and IHS databases contain significantly fewer non-serious accidents than serious accidents.Further biases were observed by accident and ship types.Founderings, fires / explosions, and strandings are more likely to be reported than other accident modes.Hull / machinery damage is the accident mode with the lowest reporting rate.
No abstract is provided for this article.
Petroleum exploration and production in the Barents Sea is a controversial topic. The Goliat field outside the northern coast of Norway will be the first offshore oil development in this region, with planned production start in 2013–2014. Avoiding major accidents at Goliat is critical; not only to reduce the risks to human lives and the environment, but also to gain political acceptance. Providing early warnings of major accidents for Goliat is one of the main objectives of the research project ‘Building Safety’. The objective of this paper is to describe the development of early warnings in the form of indicators. In addition, the paper includes an overview of current status of early warnings of accidents in other major hazard industries; the nuclear power industry, the chemical process industry, and aviation. Experiences from these industries, including lessons learned from recent major accidents, have been used as important input to the development of early warning indicators.
In this chapter, definitions of important terms related to online probabilistic risk assessmentOnline probabilistic risk assessment are clarified (Sect. 2.1). In Sect. 2.2, dynamic, real-time, and online risk assessmentsOnline risk assessment are defined. In Sect. 2.3, methods for online risk assessmentOnline risk assessment such as hazard identificationHazard identification, event sequence diagramsEvent sequence diagram (ESDs), fault tree analysisFault tree analysis (FTA), and hybrid methodsHybrid method are presented. In addition, in this subsection, the online risk assessmentOnline risk assessment methodology for autonomousAutonomous systems is more clarified by applying the method in a case studyCase study. In Sect. 2.4, methods for dynamic probabilistic risk assessmentDynamic probabilistic risk assessment of complex systemsComplex systems including dynamic event sequence diagramsDynamic event sequence diagrams (DESDs), Markov chainsMarkov chain, dynamic fault treesDynamic fault tree, and dynamic Bayesian networksDynamic bayesian network are presented and discussed. Finally, in Sect. 2.5, the challengesChallenges of available methods are discussed; and possible solutions to overcome these challengesChallenges are proposed. Integrating predictive and optimizationOptimization algorithmsAlgorithm, as well as simulation, with risk assessmentRisk assessment may result in more powerful risk assessmentRisk assessment methods for complex systemsComplex systems.
With increasing autonomy in systems, the role of software becomes more prominent as it overtakes human operator functions. The software in autonomy differs from automation with respect to functionality, implementation, and complexity, and software failures contribute to system and operational risk. Such failures, however, are often not sufficiently catered for in current risk assessments and mitigation processes, as they are challenging to identify and quantify, in particular, in the early conceptual design phase. Software reliability is not the same as software safety, as the latter encompasses the context and use of the software, as well as interactions and potential cascading failures to hardware, humans, and the environment. It is also difficult to investigate cascading effects on the system that may follow from software failures. The objective of this paper is to propose a novel classification taxonomy to support a more thorough identification of software failures for systems with different degrees of autonomy, as well as for software implementation techniques. The risk from software is interwoven into the design, development, validation, and verification processes, impacting safe operation. The proposed taxonomy can be used iteratively from the early design phase as the detailed design concepts evolve. The level of abstraction for system and software functions decreases with the design and development process. The validation and verification processes must ensure the software’s safety and reliability on different system abstraction levels. The software taxonomy in this paper includes relevant causes, consequences, and process relationships, and has been created based on existing industry classifications, research, and system models. A case study applying the taxonomy to navigation and collision avoidance functions on the subsystem level of a Maritime Autonomous Surface Ship (MASS) is performed. Software properties extracted from existing systems and knowledge are transformed into a functional model. Each software failure is then described in the context of the system level valid for the design, development, validation, and verification processes for MASS. The overall outcome of the paper may contribute to the safer design of systems through enhanced identification of potential hazards and software failures, leading to improved risk assessments and, as such, a better basis for defining more efficient safety requirements for autonomous systems from the early system development. Even though the paper exemplifies the taxonomy and classification by focusing on MASS, the work has relevance to other types of software-intensive systems.
Current decision making regarding whether to abort a high-risk aquaculture operation in a Norwegian fish farm is mainly experience-driven. The on-site personnel decides whether to start/delay/abort operations primarily based on their subjective judgement about whether they can handle the situation. The risk is considered implicitly as "gut feelings". There are no explicit operational limits nor a structured process to derive these for high-risk operations. In this research, a predefine safety-critical attributes have been identified from major accident scenarios to guide machine learning process to define operational limits based on multi-source data. Bayesian network, Tree Augmented Naïve Bayes (TAN) search algorithms were selected to build up prediction model so that operational limits upon a given condition can be decided. The paper concludes that machine learning techniques have great potential to be used to support safe decision-making in high-risk aquaculture operation, and the risk-based operational limits facilitates better understanding of operational context, and comprehension of the meaning of several deviations which may indicate a dangerous situation.
Enabling higher levels of autonomy requires an increased ability to identify and handle internal faults and unforeseen changes in the environment. This work presents an approach to improve this ability for a robotic system executing a series of independent tasks, such as inspection, sampling, or intervention, at different locations. A dynamic decision network (DDN) is used to infer the presence of internal faults and the state of the environment by fusing information over time. This knowledge is used to make risk-informed decisions enabling the system to proactively avoid failure and to minimize the consequence of faults. Past states are evaluated with new information to identify and counteract previous sub-optimal actions. A case study on an inspection drone tasked with contact-based ultrasound inspection is presented. The case study successfully demonstrates the proposed capabilities while minimizing time use and maximizing mission completion.
Autonomous marine systems may switch between various operational modes with different levels of autonomy (LoA), due to a rapidly changing environment and the complex nature of tasks. The dynamic autonomy brings an additional layer of complexity to ensuring safe marine operations, but this functionality is not sufficiently considered in current risk analysis methods. Hence, this paper proposes an approach to hazard identification based on the system theoretic process analysis (STPA) that includes unsafe transitions between different LoA in systems. A case study of a remotely operated vehicle (ROV) with four operational modes with different LoAs is used to illustrate the approach. The results show that the proposed approach contributes to: 1) communicating a shift of responsibilities among human operator and system controller in different operational modes by specifying how the allocation of the responsibility between human operators and the controller changes, and what updated process model of the operator and the controller are to ensure a successful transition; 2) refining safety constraints to be more concrete to improve system design, and operational procedures and 3) identifying triggering events for marine system modes' transitions to handle environmental interaction systematically and sufficiently.
No abstract is provided for this article.
No abstract is provided for this article.
The fish farming industry is one of the industries in Norway with the highest occupational fatality and injury rate. Despite the serious health, safety, and environmental issues in the industry, little is done to measure changes in safety over time beyond the traditional Lost Time Injury (LTI) registrations. In this article the objective is twofold; (i) to propose a framework for developing safety indicators based on Systems-Theoretic Process Analysis (STPA), and (ii) to apply the framework to find indicators relevant for hazards in operations where subcontractors participate. STPA uses a hierarchical portrayal of the system in focus, in contrast to sequential models, and views safety as a control problem. It is believed that a systemic approach to indicator development better captures the complex safety challenges in aquaculture. Thirteen indicators are identified within areas such as maintenance, training, and planning. The indicators identified may function as a basis for decisions and actions that must be undertaken to ensure safe operations.
Failures of critical infrastructures can represent a threat both to people, economy and societal functions and to national security. So, thorough risk analyses of infrastructures are required to reduce the probability and mitigate the consequences of failures. The interdependencies between infrastructures can be strong, but are seldom accounted for in current analyses. This chapter presents a method for assessing these interdependencies and also provides an example. The analysis is part of an overall cross-sector risk and vulnerability analysis (RVA), see Chap. 3.
This chapter presents three case studies in the data leakage domain and the methods proposed and evaluated for mitigating the threat of data leakage. The case studies are: detecting an insider attempting to misuse and leak data stored in a database system; using honeytokens to detect insider threats; and detecting leakage through email.