Search NASA⌕ Search

Engineering topics

Seydou Mbaye

Publications and source records attributed to Seydou Mbaye.

At least 19 records

Workshop on the Role of Design Assurance in System-Wide Safety’s Safety Demonstrator Series

This report summarizes a three-hour hybrid in-person/online workshop on June 7, 2024 on the topic of design assurance and the Safety Demonstrator Series (SDS), which was held at NASA Ames Research Center. The SDS provides an operational demonstration of, and recommendations for, requirements and standards necessary to monitor, assess, and mitigate risks to assure safety in disaster-oriented operations. Over sixty NASA personnel participated in the workshop. Four main topics were discussed: (1) assurance needs for the Safety Demonstrator Series, (2) assurance and the In-Time Aviation Safety Management System (IASMS), (3) in-time assurance: existing efforts and future opportunities, and (4) demonstrating assurance tools in the Safety Demonstrators. Key takeaways are as follows: 1. Design assurance tools can be used to assure an In-Time Aviation Safety Management System, the systems that comprise it, and other systems or missions. Assurance must consider both systems and components and include the interactions between elements in both a systems/aircraft context and a systems-of-systems/airspace context. 2. Design-time assurance activities can support the identification of monitors needed for operational assurance activities (i.e., the “monitor” function in the monitor-assess-mitigate paradigm at the heart of the IASMS concept). 3. A major opportunity for design-time assurance tools to contribute to the IASMS concept is to support rapid re-validation of systems. This will be particularly important for (1) supporting novel operations in the IASMS, where operational data may disprove design-time assumptions (motivating re-analysis of system safety) and (2) adapting technologies (e.g., AI/ML for autonomous operations) to new operational domains, where there may be new or different safety considerations not included in the initial scope of operations. 4. There are several design assurance tools under development in the System-Wide Safety project that can support assurance of Services, Functions, and Capabilities (SFCs) in the Safety Demonstrators. Transitioning these tools from one-off research projects into a functioning part of IASMS assurance will require closer integration between these tools. 5. It is not clear whether the role of design assurance tools is primarily as a part of IASMS architecture or as an external check on IASMS. The workshop consisted of four discussion topics initiated via four lightning talks by System-Wide Safety researchers. Discussions utilized Mural to engage both in-person and online participants in the hybrid format. Polls and surveys were also utilized to gather participant input. The workshop closed with a reflection activity for participants, as well as new ideas for collaboration and coordination of ongoing System-Wide Safety research.

design assurance↗

BERT-Based Topic Modeling and Information Retrieval to Support Fishbone Diagramming for Safe Integration of Unmanned Aircraft Systems in Wildfire Response

Recent concepts for emerging wildfire response operations have included unmanned aircraft systems (UAS) due to their increasing accessibility and capabilities. To integrate UAS into wildfire response safely, researchers have studied the use of large repositories of historic incident reports to improve the scope of root cause analysis. Recent work has emphasized applying state-of-the-art natural language processing techniques to extract useful information from these repositories. However, it has not yet been studied how these results can be interpreted and integrated into the systems engineering process. In this work, we propose a process in which Bidirectional Encoder Representations from Transformers (BERT)-based topic modeling and information retrieval are applied to a relevant set of documents in order to support the development of a fishbone diagram in a semiautomated process. High-level themes in the document set are identified using topic modeling, which are then refined and interpreted by a human analyst. Then, the themes are used to guide a finer search using information retrieval, which returns specific incident reports of relevance. This provides traceability to specific incidents as well as broader categorizations that comprise the fishbone branches. We apply the proposed process to relevant documents from NASA’s Aviation Safety Reporting System (ASRS). The proposed process is widely applicable when relevant documents are available, and the results from this study will be useful to identifying potential causes of wildfire response UAS incidents.

Hazard analysis↗

An MBSE Approach for Developing an Autonomous Rover Platform

The proliferation of increasingly autonomous systems calls for new ways to address how safety is assured. As these systems become more advanced and complex, it becomes more important to model and prototype autonomous functions at the systems level and the functions that assure they are operating safely and as expected. To that effect, researchers at the National Aeronautics and Space Administration (NASA) 's Robust Software Engineering (RSE) group are working on prototyping a Research Autonomous Vehicle, commonly referred to as R-RAV. The R-RAV is an autonomous rover platform designed to act as a case study for assured autonomy research. Moreover, an overarching goal is for the R-RAV to serve as a training ground for other mission projects. In this paper, we will detail how we have used a Model-Based Systems Engineering (MBSE) approach to model a prototype of the R-RAV and test and verify its different functionalities.

MBSE↗

A Model-Based Systems Engineering Evaluation of the Evolution to an In-Time Aviation Safety Management System

In 2018, as result of a recommendation from the National Academies, NASA began to prototype an In-Time Aviation Safety Management System (IASMS). The purpose of the IASMS is to enable innovative aviation operations and greater heterogeneity of the overall National Airspace (NAS) by automating much of the safety monitoring, assessment, and risk and hazard mitigation function present in today’s Safety Management Systems (SMS). NASA has worked together with early industry collaborators to understand how such a system might work and has published several early Concepts of Operation (ConOps) and other technical memoranda that illustrate the primary considerations for selected aviation domains. The shift from an SMS to an IASMS is predicated on several assumptions, including: 1.) automating safety functions will decrease the amount of time necessary for risk and hazard identification and analysis, making it more likely that safety concerns are understood ‘in-time’ to mitigate them, and 2.) an IASMS will allow easier tailoring of safety management processes to the particular risks and hazards inherent to that aviation operation. In this paper, we begin to validate these assumptions through the use of Model-Based Systems Engineering (MBSE).

IASMS↗

A Model-Based Systems Engineering Evaluation of the Evolution to an In-Time Aviation Safety Management System

In 2018, as result of a recommendation from the National Academies, NASA began to prototype an In-Time Aviation Safety Management System(IASMS). The purpose of the IASMS is to enable innovative aviation operations and greater heterogeneity of the overall National Airspace (NAS) by automating much of the safety monitoring, assessment, and risk and hazard mitigation functionspresent in today’s Safety Management Systems (SMS). NASA has worked together with early industry collaborators to understand how such a system might work and has published several early Concepts of Operation (ConOps) and other technical memoranda that illustrate the primary considerations for selected aviation domains. The shift from an SMS to an IASMS is predicated on several assumptions, including: 1.) automating safety functions will decrease the amount of time necessary for risk and hazard identification and analysis, making it more likely that safety concerns are understood ‘in-time’ to mitigate them, and 2.) an IASMS will allow easier tailoring of safety management processes to the particular risks and hazards inherent to that aviation operation. In this paper, we begin to validate these assumptions through the use of Model-Based Systems Engineering (MBSE).

In-time Aviation Safety Management System↗

Analysis of Input from Wildfire Incident Experts to Identify Key Risks and Hazards in Wildfire Emergency Response

The United States Department of Agriculture (USDA) describes wildland fires as, “a force of nature that can be nearly as impossible to prevent, and as difficult to control, as hurricanes, tornadoes and floods.” Existing challenges in managing wildland fires often put first responders’ lives at risk. The emergence of drones and their capabilities to supplement human efforts could alleviate some, if not all, of those risks that first responders face during wildfire management efforts. However, the process of adding drones to wildfire response has come with its own challenges as well. NASA’s System-Wide Safety Project is working towards overcoming these challenges to enable routine transfer of risk from responders to aviation assets. The concept of operations and model-based systems engineering (MBSE) effort for this shift is underway. To inform and to validate the MBSE effort, we delivered a questionnaire to wildland firefighting experts on the hazards they currently face. This questionnaire has given us insight and a better understanding of the challenges related to the use of drones from a first responder’s point of view. We are using this information to better address responders’ concerns, develop a safety management system, and eliminate the roadblocks that prevent the use of drones in wildfire management.

Wildfire↗

BERT-based Topic Modeling and Information Retrieval to Support Fishbone Diagramming for Safe Integration of Unmanned Aircraft Systems in Wildfire Response

Recent concepts for emerging wildfire response operations have included unmanned aircraft systems (UAS) due to their increasing accessibility and capabilities. To integrate UAS into wildfire response safely, researchers have studied the use of large repositories of historic incident reports to improve the scope of root cause analysis. Recent work has emphasized applying state-of-the-art natural language processing techniques to extract useful information from these repositories. However, it has not yet been studied how these results can be interpreted and integrated into the systems engineering process. In this work, we propose a process in which Bidirectional Encoder Representations from Transformers (BERT)-based topic modeling and information retrieval are applied to a relevant set of documents in order to support the development of a fishbone diagram in a semiautomated process. High-level themes in the document set are identified using topic modeling, which are then refined and interpreted by a human analyst. Then, the themes are used to guide a finer search using information retrieval, which returns specific incident reports of relevance. This provides traceability to specific incidents as well as broader categorizations that comprise the fishbone branches. We apply the proposed process to relevant documents from NASA’s Aviation Safety Reporting System (ASRS). The proposed process is widely applicable when relevant documents are available, and the results from this study will be useful to identifying potential causes of wildfire response UAS incidents.

hazard analysis↗

From BERTopic to SysML: Informing Model-Based Failure Analysis With Natural Language Processing for Complex Aerospace Systems

The development of emerging complex aerospace systems will require new approaches for capturing safety incident scenarios as early as possible in the design phase. However, for novel systems, relevant data available is limited. In this work, we propose a framework informing model-based mission assurance activities with historical incident reports, lessons learned, or other relevant engineering documents using natural language processing. In doing so, we investigate whether there is useful information in data sets that are relevant, if not identical, to the system under design and whether, through rigorous systems engineering practice, this information can be effectively leveraged through model-based failure analysis. In a worked case study, we apply state-of-the-art topic modeling techniques to two data sets, a mission relevant data set and a system relevant data set. The sets of topics are merged and interpreted to form a preliminary list of failure topics that can be used to inform the identification of off-nominal modes in the model-based failure modes and effects analysis development. Once data from the system in operation is available, it can be used to update the topics identified. By extracting information about likely failures from relevant historical data sets and utilizing model-based mission assurance to ensure relevance and rigor, unanticipated failures can be reduced, and projects can more effectively learn from past missions.

Failure Analysis↗

From BERTopic to SysML: Informing Model-Based Failure Analysis With Natural Language Processing for Complex Aerospace Systems

The development of emerging complex aerospace systems will require new approaches for capturing safety incident scenarios as early as possible in the design phase. However, for novel systems, relevant data available is limited. In this work, we propose a framework informing model-based mission assurance activities with historical incident reports, lessons learned, or other relevant engineering documents using natural language processing. In doing so, we investigate whether there is useful information in data sets that are relevant, if not identical, to the system under design and whether, through rigorous systems engineering practice, this information can be effectively leveraged through model-based failure analysis. In a worked case study, we apply state-of-the-art topic modeling techniques to two data sets, a mission relevant data set and a system relevant data set. The sets of topics are merged and interpreted to form a preliminary list of failure topics that can be used to inform the identification of off-nominal modes in the model-based failure modes and effects analysis development. Once data from the system in operation is available, it can be used to update the topics identified. By extracting information about likely failures from relevant historical data sets and utilizing model-based mission assurance to ensure relevance and rigor, unanticipated failures can be reduced, and projects can more effectively learn from past missions.

Failure Analysis↗

BERT-based Topic Modeling and Information Retrieval to Support Fishbone Diagramming for Safe Integration of Unmanned Aircraft Systems in Wildfire Response

Recent concepts for emerging wildfire response operations have included unmanned aircraft systems (UAS) due to their increasing accessibility and capabilities. To integrate UAS into wildfire response safely, researchers have studied the use of large repositories of historic incident reports to improve the scope of root cause analysis. Recent work has emphasized applying state-of-the-art natural language processing techniques to extract useful information from these repositories. However, it has not yet been studied how these results can be interpreted and integrated into the systems engineering process. In this work, we propose a process in which Bidirectional Encoder Representations from Transformers (BERT)-based topic modeling and information retrieval are applied to a relevant set of documents in order to support the development of a fishbone diagram in a semiautomated process. High-level themes in the document set are identified using topic modeling, which are then refined and interpreted by a human analyst. Then, the themes are used to guide a finer search using information retrieval, which returns specific incident reports of relevance. This provides traceability to specific incidents as well as broader categorizations that comprise the fishbone branches. We apply the proposed process to relevant documents from NASA’s Aviation Safety Reporting System (ASRS). The proposed process is widely applicable when relevant documents are available, and the results from this study will be useful to identifying potential causes of wildfire response UAS incidents.

hazard analysis↗

Defining A Modelling Language to Support Functional Hazard Assessment

Functional Hazard Assessment (FHA) is a key early-stage engineering process that supports the incorporation of safety in design by identifying the high-level functional hazards the system may encounter. While many FHA-like methodologies have been proposed in the design engineering literature, many of these methodologies have had difficulty becoming accepted industry practice. Industry standards, on the other hand, either provide too little recommendation on how to represent the function of the system to perform FHA, or rely on existing design artefacts which insufficiently support the goals of the process. This paper presents some of the problems with current modeling languages (both proposed and used) for FHA which limit the scope, expressiveness, flexibility, and precision of the analysis. It then outlines desirable principles an FHA-supporting analysis language should embody, and introduces the Functional Reasoning Design Language (FRDL), a formal modeling language for describing the functional elements of a system and their interactions, which aims to satisfy these principles. To demonstrate the use of this language, the modeling and hazard analysis of a disaster response drone is presented. While this case study is limited in scope, it highlights how FRDL can represent system function while reducing the ambiguity present in typical FHA-supporting functional modeling languages

Hazard Assessment↗

A Grounded Theory of UAS Reported Accidents

Context: The manufacture and operation of sUAS are not as regulated as today’s commercial operation, and their widespread use introduces new risks and hazards to the general public. Aim: Our intent is to understand the various processes that prevent or portend sUAS incidents or accidents and the influence that pilots’ expectations and training have on these processes. Method: We use classic grounded theory on sUAS reported accidents (and incidents). Results: We identified three categories, Control Interference, Reviewing and Reporting, which describe various processes surrounding UAS accidents based on the dataset analyzed. Conclusion: The use of grounded theory can offer a different perspective in the analysis of UAS accidents. In addition, the traceability between data sources and the method results facilitate result validation, and navigation. While the results are preliminary, the concepts can be expanded through the use of other accident datasets or used as basis for UAS accident surveys.

Carlos Paradis↗

Evaluating Faulty State Occurrence in Wildfire UAS Missions Using Markov Chains

As autonomous technology advances, unmanned aircraft systems are increasingly integrated into emergency response missions, such as wildfire response. These systems must be be safe with less risk than non-autonomous counter parts, yet quantifying the risk associated with present-day and future systems conventionally relies solely on expert opinion and little data. Instead, combining narrative mishap reports with probabilistic analysis can provide a method for evolutionary and timely risk analysis. In this paper, we present a framework for a data-driven probabilistic risk assessment style analysis, where hazard events and rates originate from documented UAS mishaps. The framework is applied to a UAS mapping mission in wildfire response, including a fault tree analysis, event tree analysis, and probabilistic analysis using Markov Chains. The analysis provides an enumeration of hazards in the system, hazard events that can lead to faults, the probability of a mission experiencing any fault, the probability of experiencing a specific fault, and the expected time spent until faulty states occur in present-day operations.

risk analysis↗

Evaluating Faulty State Occurrence in Wildfire UAS Missions Using Markov Chains

As autonomous technology advances, unmanned aircraft systems are increasingly integrated into emergency response missions, such as wildfire response. These systems must be be safe with less risk than non-autonomous counter parts, yet quantifying the risk associated with present-day and future systems conventionally relies solely on expert opinion and little data. Instead, combining narrative mishap reports with probabilistic analysis can provide a method for evolutionary and timely risk analysis. In this paper, we present a framework for a data-driven probabilistic risk assessment style analysis, where hazard events and rates originate from documented UAS mishaps. The framework is applied to a UAS mapping mission in wildfire response, including a fault tree analysis, event tree analysis, and probabilistic analysis using Markov Chains. The analysis provides an enumeration of hazards in the system, hazard events that can lead to faults, the probability of a mission experiencing any fault, the probability of experiencing a specific fault, and the expected time spent until faulty states occur in present-day operations.

risk analysis↗

A Grounded Theory of UAS Reported Accidents

Context: The manufacture and operation of sUAS are not as regulated as today’s commercial operation, and their widespread use introduces new risks and hazards to the general public. Aim: Our intent is to understand the various processes that prevent or portend sUAS incidents or accidents and the influence that pilots’ expectations and training have on these processes. Method: We use classic grounded theory on sUAS reported accidents (and incidents). Results: We identified three categories, Control Interference, Reviewing and Reporting, which describe various processes surrounding UAS accidents based on the dataset analyzed. Conclusion: The use of grounded theory can offer a different perspective in the analysis of UAS accidents. In addition, the traceability between data sources and the method results facilitate result validation, and navigation. While the results are preliminary, the concepts can be expanded through the use of other accident datasets or used as basis for UAS accident surveys.

Carlos Paradis↗

Defining A Modelling Language to Support Functional Hazard Assessment

Functional Hazard Assessment (FHA) is a key early-stage engineering process that supports the incorporation of safety in design by identifying the high-level functional hazards the system may encounter. While many FHA-like methodologies have been proposed in the design engineering literature, many of these methodologies have had difficulty becoming accepted industry practice. Industry standards, on the other hand, either provide little recommendation on how to represent the function of the system to perform FHA, or rely on readily-available models with little justification in design theory. This paper presents some of the problems with current modelling languages used for FHA which limit the scope, expressiveness, flexibility, and precision of the analysis, as well as desirable principles an FHA-supporting analysis language should embody. It further introduces the Functional Reasoning Design Language (FRDL), a formal modelling language for describing the functional behaviors of a system and their interactions which satisfies these principles. To demonstrate the use of this language, the modelling and hazard analysis of a disaster response drone is presented.

safety analysis↗