Search NASA⌕ Search

SEARCH · Search NASA

Results for “Software Safety”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

JUSTIFI: Software for Improving Performance Objectives via Energy Efficiency

With growing energy supply concerns and rising costs, energy efficiency is a critical component of industrial energy resilience and competitiveness by directly reducing energy operating costs. Energy efficiency projects in manufacturing also yield valuable benefits to other key metrics, such as improved quality, reduced maintenance costs, improved safety, decreased pollution, and enhanced productivity. However, it is difficult to receive approval for energy efficiency projects, so implementation rates are low, even when meeting capital project payback period criteria. The inclusion and quantification of non-energy benefits (NEBs) in the decision-making process for energy efficiency projects can improve the overall financial payback period while demonstrating a positive impact on the firm's key performance metrics and business strategy. Despite their significant financial and strategic value, NEBs are rarely factored into decision-making due to lack of tools to effectively identify and quantify them. Therefore, a comprehensive and integrative approach is needed for the rapidly evolving energy landscape. To address these challenges, through funding from U.S. Department of Energy, our new assessment methodology integrates common continuous improvement six sigma concepts, such as the DMAIC process, and a protocol of guiding questions, into energy efficiency assessments to identify NEBs. We have also developed open-source software, JUSTIFI, to guide users through this process, data collection, and quantification. It is designed to be used concurrently with DOE energy system analysis software suite, MEASUR. Our methodology and tools inform energy assessors, firm engineering, decision makers, and workforce seeking to increase energy resilience and to maximize benefits aligned with performance metrics.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

JUSTIFI: Software for Improving Performance Objectives via Energy Efficiency

With growing energy supply concerns and rising costs, energy efficiency is a critical component of industrial energy resilience and competitiveness by directly reducing energy operating costs. Energy efficiency projects in manufacturing also yield valuable benefits to other key metrics, such as improved quality, reduced maintenance costs, improved safety, decreased pollution, and enhanced productivity. However, it is difficult to receive approval for energy efficiency projects, so implementation rates are low, even when meeting capital project payback period criteria. The inclusion and quantification of non-energy benefits (NEBs) in the decision-making process for energy efficiency projects can improve the overall financial payback period while demonstrating a positive impact on the firm's key performance metrics and business strategy. Despite their significant financial and strategic value, NEBs are rarely factored into decision-making due to lack of tools to effectively identify and quantify them. Therefore, a comprehensive and integrative approach is needed for the rapidly evolving energy landscape. To address these challenges, through funding from U.S. Department of Energy, our new assessment methodology integrates common continuous improvement six sigma concepts, such as the DMAIC process, and a protocol of guiding questions, into energy efficiency assessments to identify NEBs. We have also developed open-source software, JUSTIFI, to guide users through this process, data collection, and quantification. It is designed to be used concurrently with DOE energy system analysis software suite, MEASUR. Our methodology and tools inform energy assessors, firm engineering, decision makers, and workforce seeking to increase energy resilience and to maximize benefits aligned with performance metrics.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Adaptive Protection and Validated Models to Enable Deployment of High Penetrations of Solar PV (PV-MOD)

The availability and validation of various PV models in commercial tools differ, with some models not yet thoroughly validated for advanced inverter functionalities and reliable performance under weak system conditions. Many existing models do not fully incorporate new inverter control functions, which can affect system stability. The increasing deployment of solar PV and other inverter-based resources (IBRs), including distributed energy resources (DERs), is influencing the reliable operation of protection schemes in distribution systems and microgrids. Emerging adaptive protection schemes (APS) offer new opportunities for protecting these systems during varying configurations and DER operating conditions, though their demonstration and validation remain limited. Adaptive protection schemes face similar challenges, as they are typically designed for specific configurations. There is a growing need for tools and methodologies to streamline the deployment of adaptive protection for safe and reliable DER integration. The project main objective was to develop and validate high-fidelity generic models of solar PV facilities for stability, protection, EMT, and QSTS analyses. This objective was achieved, and these models can now be integrated into commercial software tools, enabling utilities, vendors, and developers to study high-penetration PV systems more confidently. The project also demonstrated advanced applications of these models, including the design and deployment of adaptive protection schemes in high-penetration field applications and microgrids, supporting grid safety and reliability. Several milestones were reached by the end of the project. A sophisticated inverter test plan was developed, and inverters representative of the North American marketplace were selected. EPRI and NREL tested various inverters, conforming to IEEE standards. Improvements were made to existing generic models of IBR units, IBR plants, and aggregated feeders for various analyses. The first generic electromagnetic transient (EMT) model for a solar PV plant was developed, conforming to IEEE Std 2800™-2022 and validated against laboratory measurements of a 2.2 MVA large-scale battery energy storage system (BESS) inverter. That model was then used to produce reference responses illustrating examples of validated and verified IBR plant models that pass or fail tests for technical minimum capability and performance as specified in the IEEE standard. The developed, tested, and validated generic models can be used for transmission planning, stability assessments, expansion planning, and evaluating potential future IBR interconnection requirements. They can also support interconnection screens and conformity assessments of IBR plants, including solar PV. The project significantly contributed to the ongoing standardization and model-based representation and verification of IBR responses. The project further addressed challenges of common distribution protection schemes with increasing deployment of DER by developing, validating, and demonstrating adaptive protection schemes (APS) that can improve the reliable and safe integration of DER into distribution systems. New APS were designed using improved DER models for three common distribution systems: a radial feeder, a meshed network, and a microgrid. Modeling and hardware-in-the-loop (HIL) testing of the APS were conducted, successfully showing their effectiveness and selectivity. Proof-of-concept field demonstration was achieved for two APS, i.e., one on a radial feeder and another one in a microgrid. Field demonstration could not be achieved for the APS on a meshed network, primarily due apprehension of one utility partner and also due to limited access to the protective algorithms in the network protectors. Guidelines developed from the lessons learned in the project lay out the general process followed in the design, installation, and commissioning of APS for various distribution systems. Distribution utility partners’ apprehension about field demonstration of the new APS were addressed—with varying success—by taking a stepped risk-management approach of modeling of a wide range of sensitivities first, performing in-depth proof-of-concept testing in the laboratory including HIL next, and finally deliberately implementing and commissioning the actual protection equipment and algorithms into parts of—or in parallel operation to—the three real distribution systems. Future work should include pilot projects that further show the acceptable performance of the developed APS before these schemes be rolled out more widely. Inclusion of both utility and original equipment manufacturers (OEMs) in future projects could increase chances of successful field demonstration. Despite challenges in achieving the field demonstration goal of the project for all three APS, the research significantly contributed to the innovation of adaptive protection solutions for scalable and reliable DER integration into distribution systems. This project significantly enhances the understanding of the impact of using appropriate inverter models on distribution and transmission (T&D) systems. By addressing the limitations of existing generic models, the project introduces high-fidelity models for stability, protection, electromagnetic transient (EMT), and quasi-static time series (QSTS) analyses. These models, integrated into commercial software tools, enable utilities, vendors, and developers to confidently study high-penetration PV systems. The project also demonstrates advanced applications, including adaptive protection schemes (APS) for distribution systems and microgrids, ensuring grid safety and reliability. The technical effectiveness and economic feasibility of the methods are evident through the development and validation of sophisticated inverter test plans and the selection of representative inverters. Testing by EPRI and NREL on retail, commercial, and utility-scale inverters, conforming to IEEE standards, underscores the robustness of the models. Improvements to existing generic models for various analyses further enhance their validity and applicability. The project also identifies gaps in common distribution protection schemes and designed new APS using improved DER models, demonstrating their effectiveness through modeling and hardware-in-the-loop (HIL) testing. The project’s benefits to the public are manifold. By advancing the standardization and model-based representation of IBR response, it supports transmission planning, stability assessments, and future IBR interconnection requirements. The generic models can facilitate better communication between transmission planners and developers, supporting expected IBR plant capability and performance. Additionally, the development of APS for radial feeders, meshed networks, and microgrids supports the integration of distributed energy resources (DERs) into distribution systems, enhancing grid reliability and safety. The project’s emphasis on thorough testing and simplicity in design ensures practical and scalable solutions for DER integration.

14 SOLAR ENERGY↗

Hazards and Probabilistic Risk Assessments of Advanced Nuclear Reactors Coupled with Industrial Facilities

This report provides a roadmap and tool kit for site specific risk assessments across a broad range of industrial customers co-located with advanced nuclear power plants (ANPP) that are not currently built and operating in the U.S. This report builds upon the body of work sponsored by the Department of Energy (DOE) Integrated Energy Systems Pathway that has produced industrial requirements studies and techno-economic assessments on the topics of feasibility of ANPP supported industrial processes. This report also leverages the DOE Light Water Reactor Sustainability (LWRS) program that has presented hazards assessment and generic probabilistic risk assessments (PRAs) for the addition of a heat extraction system (HES) to light-water reactors (LWRs) co-located with hydrogen production facilities. Many of the hazard assessments and risk assessments performed for the LWRS report are agnostic to whether the nuclear reactor is an ANPP or were adapted to the ANPP focus. The report performs hazards assessments to include industrial facilities: an oil refinery, a methanol plant, a synthetic fuel (synfuel) plant, the production of synthetic gas (syngas) as part of the methanol and synfuel plants, wood pulp and paper mills, and hydrogen production. Hydrogen production facilities are assessed in depth through prior reports in the LWRS program and the results are leveraged in this report. All these facilities are specified through industrial process and requirements research performed by national laboratories, universities, and interaction with industry. Many of the processes used in this report are pre-conceptual designs to use for decarbonization of the current technology facilities. A process of failure modes and effects analysis (what can go wrong) and accidentology (what has historically gone wrong) was used to determine the hazards presented to the nuclear power plant by the addition of the HES and the industrial customer. Chemical properties of feedstocks and products are summarized as part of the hazards assessment. Example analysis procedures are provided for each of the hazard types identified. These deterministic analyses can be used to assess adherence to licensing criteria. They can also be used to meet other safety goals like protection of the public, workers, or industrial facility equipment. A modular high temperature gas-cooled reactor (MHTGR) PRA only existing on paper was modeled and verified in modern PRA software. This will provide a tool for representative ANPP probabilistic analyses for future research.

10 SYNTHETIC FUELS↗

Transition of SRT Source Term Software to Modern Version Control System to Enable More Efficient Verification, Validation, and User Engagement

The Simplified Radionuclide Transport (SRT) code assists in reactor design and licensing by providing a detailed analysis of radionuclide transport under specific transient scenarios. This analysis is essential for ensuring that reactors meet safety and regulatory standards before they are authorized to operate. Mechanistic source term analysis, which involves a realistic evaluation of radionuclide behavior from the source to the environment, is a key component of this process. It provides a comprehensive understanding of potential release scenarios, supporting the development of robust safety measures.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Code Coverage Status of the ARC Code PERSENT

The Argonne Reactor Code (ARC) software system supports users in their fast reactor design goals by providing neutronic, thermal-hydraulic, and structural analysis capabilities. PERSENT fulfills the role of generating reactivity coefficients for a given time point of a REBUS calculation usable in a point kinetics based safety analysis capability. PERSENT also provides a sensitivity coefficient capability on eigenvalue, reactivity worth, and several other key coefficients that are used in the follow-on safety analysis. Given a co-variance matrix, PERSENT can carry out the uncertainty quantification to indicate the amount of error in the reactivity coefficients derived from the errors in the cross section measurements. With continued improvement of computational resources, many of the geometry modeling capabilities in DIF3D that were primarily used in low order schemes are not really needed anymore. Today, the diffusion and transport capabilities of DIF3D-VARIANT are primarily used in the reactor design process with some scattered usage of DIF3D-FD and DIF3D-Nodal. PERSENT is part of the ARC code system and is built around DIF3D-VARIANT and the flux solution it provides. The purpose of the present work is to identify a set of test problems for PERSENT and assess the code coverage of PERSENT for those test problems. PERSENT treats the DIF3D executable as an external executable and thus the code coverage considerations only need to focus on the PERSENT source code and only a fraction of the connected modules in the existing ARC software library. The goal is to document what parts of the existing PERSENT code are touched by the set of test problems and which are not. Because the verification work done on PERSENT was focused on the most common uses of PERSENT for fast reactor analysis, the code coverage assessment of those capabilities is the highest priority. This will ensure that nothing is being missed by the existing verification test problems that users of PERSENT rely upon. The code coverage analysis of PERSENT was performed with the Code Coverage Tool of the Intel Fortran compiler which requires modifications to the compilation of PERSENT. The detailed coverage tables are given for each submodule of PERSENT. Most of the uncovered parts/files could be easily ignored because they are either for error message and debugging output or not needed by PERSENT today. Only a few uncovered parts of PERSENT deserve extending the verification test suite.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Development and Validation of a Probabilistic Risk Assessment Model for a Generic Modular High Temperature Gas-Cooled Reactor

This study looks to develop and validate a probabilistic risk assessment (PRA) model for the modular high temperature gas-cooled reactor (MHTGR) using INL’s Systems Analysis Programs for Hands-on Integrated Reliability Evaluations (SAPHIRE) software. Validation against a General Atomics design involves matching event and fault trees to historical frequencies, with a goal of under 15% difference. The research aims to deliver a reliable PRA model to assess the safety of MHTGRs for use within high-temperature industrial applications.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Synthesis of Correct Digital Controller Models from Specifications by Model Transformation (21-0320)

The design of high consequence controllers (in weapons systems, autonomy, etc.) that do what they are supposed to do is a significant challenge. Testing simply does not come close to meeting the requirements for assurance. Today circuit designers at Sandia (and elsewhere) typically capture the core behavior of their components using state models in tools such as STATEFLOW. They then check that their models meet certain requirements (e.g. “The system bus must not deadlock” or “both traffic lights at an intersection must not be green at the same time”) using tools called model checkers. If the model checker returns “yes” then the property is guaranteed to be satisfied by the model. However, there are several drawbacks to this industry practice: (1) there is a lot of detail to get right, this is particularly challenging when there are multiple components requiring complex coordination (2) any errors returned by the model checker have to be traced back through the design and fixed, necessitating rework, (3) there are severe scalability problems with this approach, particularly when dealing with concurrency. All this places high demands on the designers who now face not only an accelerated schedule but also controllers of increasing complexity. This report describes a new and fundamentally different approach to the construction of safety-critical digital controllers. Instead of directly constructing a complete model and then trying to verify it, the designer can start with an initial abstract (think “sketch”) model plus the requirements, from which a correct concrete model is automatically synthesized. There is no need for post-hoc verification of required functional properties. Having tool to carry this out will significantly impact the nation’s ability to ensure the safety of high-consequence digital systems. The approach has been implemented in a prototype tool, along with a suite of examples, including ones that reflect actual problems faced by designers. Our approach operates on a variant of Statecharts developed at Sandia called Qspecs. Statecharts are a widely used formalism for developing concurrent reactive systems, supporting scalability through allowing state models containing composite states, which are the serial or parallel composition of substates which can themselves contain statecharts. Statecharts enable an incremental style of development, in which states are progressively refined to incorporate greater detail in an incremental model of software development. Our approach formulates a set of constraints from the structure of the models and the requirements and propagates these constraints to a fixpoint. The solution to the constraints is an inductive invariant along with guards on the transitions. We also show how our approach extends to implementation refinement, decomposition, composition, and elaboration. We currently handle safety requirements written in LTL (Linear Temporal Logic)

42 ENGINEERING↗

Nuclear Safety [Vol. 35, No. 1, January-June 1994]

Nuclear Safety is a review journal that covers significant developments in the field of nuclear safety. Its scope includes the analysis and control of hazards associated with nuclear energy, operations involving fissionable materials, and the products of nuclear fission and their effects on the environment. Primary emphasis is on safety in reactor design, construction, and operation; however, the safety aspects of the entire fuel cycle, including fuel fabrication, spent-fuel processing, nuclear waste disposal, handling of radioisotopes, and environmental effects of these operations, are also treated. Table of Contents for this issue follows. THE CHERNOBYL ACCIDENT: 1 Chernobyl Accident Management Actions, A. R Sich; GENERAL SAFETY CONSIDERATIONS: 25 The IAEA-ASSET Approach to Avoiding Accidents is to Recognize the Precursors to Prevent Incidents, F. Reisch; ACCIDENT ANALYSIS: 36 A Review of the Available Information on the Triggering Stage of a Steam Explosion, D. F. Fletcher; 58 Analysis and Modeling of Flow-Blockage-Induced Steam Explosion Events in the High-Flux Isotope Reactor, R. P. Taleyarkhan, V. Georgevich, C. W. Nestor, U. Gat, B. L. Lepard, D. H. Cook, J. Freels, S. J. Chang, C. Luttrell, R. C. Gwaltney, and J. Kirkpatrick; 74 An Analysis of Disassembling the Radial Reflector of a Thermionic Space Nuclear Reactor Power System, M. S. El-Genk and D. V. Paramonov; CONTROL AND INSTRUMENTATION: 86 Standards for High-Integrity Software, D. R. Wallace, D. R. Kuhn, L M. Ippolito, and L. Beltracchi; DESIGN FEATURES: 98 Adoption of New Design Features for the Next Generation Nuclear Power Reactors, L. S. Tong; 114 Review of Nuclear Piping Seismic Design Requirements, G. C. Slagis and S. E. Moore; ENVIRONMENTAL EFFECTS: 128 PC-Based Probabilistic Safety Assessment Study for a Geological Waste Repository Placed in a Bedded Salt Formation, S. A. Khan; OPERATING EXPERIENCES: 142 Managing Aging in Nuclear Power Plants: Insights from NRC’s Maintenance Team Inspection Reports, A. Fresco and M. Subudhi; 150 Reactor Shutdown Experience, Compiled by J. W. Cletcher; 153 Selected Safety-Related Events, Compiled by G. A. Murphy; RECENT DEVELOPMENTS: 158 Reports, Standards, and Safety Guides, D. S. Queener; 168 Proposed Rule Changes as of Dec. 31, 1993; ANNOUNCEMENTS: 177 Symposium on Radioactive and Mixed Waste—Risk as a Basis for Waste Classification; 177 1995 Incineration Conference 178 Ninth Power Plant Dynamics Control and Testing Symposium; 174 The Authors

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Nuclear Safety [Vol. 35, No. 1, January-June 1994]

Nuclear Safety is a review journal that covers significant developments in the field of nuclear safety. Its scope includes the analysis and control of hazards associated with nuclear energy, operations involving fissionable materials, and the products of nuclear fission and their effects on the environment. Primary emphasis is on safety in reactor design, construction, and operation; however, the safety aspects of the entire fuel cycle, including fuel fabrication, spent-fuel processing, nuclear waste disposal, handling of radioisotopes, and environmental effects of these operations, are also treated. Table of Contents for this issue follows. GENERAL SAFETY CONSIDERATIONS: THE CHERNOBYL ACCIDENT: 1 Chernobyl Accident Management Actions, A. R Sich 25 The IAEA-ASSET Approach to Avoiding Accidents is to Recognize the Precursors to Prevent Incidents, F. Reisch; ACCIDENT ANALYSIS: 36 A Review of the Available Information on the Triggering Stage of a Steam Explosion, D. F. Fletcher; 58 Analysis and Modeling of Flow-Blockage-Induced Steam Explosion Events in the High-Flux Isotope Reactor, R. P. Taleyarkhan, V. Georgevich, C. W. Nestor, U. Gat, B. L. Lepard, D. H. Cook, J. Freels, S. J. Chang, C. Luttrell, R. C. Gwaltney, and J. Kirkpatrick; 74 An Analysis of Disassembling the Radial Reflector of a Thermionic Space Nuclear Reactor Power System, M. S. El-Genk and D. V. Paramonov; CONTROL AND INSTRUMENTATION: 86 Standards for High-Integrity Software, D. R. Wallace, D. R. Kuhn, L M. Ippolito, and L. Beltracchi; DESIGN FEATURES: 98 Adoption of New Design Features for the Next Generation Nuclear Power Reactors, L. S. Tong; 114 Review of Nuclear Piping Seismic Design Requirements, G. C. Slagis and S. E. Moore; ENVIRONMENTAL EFFECTS: 128 PC-Based Probabilistic Safety Assessment Study for a Geological Waste Repository Placed in a Bedded Salt Formation, S. A. Khan; OPERATING EXPERIENCES: 142 Managing Aging in Nuclear Power Plants: Insights from NRC’s Maintenance Team Inspection Reports, A. Fresco and M. Subudhi; 150 Reactor Shutdown Experience, Compiled by J. W. Cletcher; 153 Selected Safety-Related Events, Compiled by G. A. Murphy; RECENT DEVELOPMENTS: 158 Reports, Standards, and Safety Guides, D. S. Queener; 168 Proposed Rule Changes as of Dec. 31, 1993; ANNOUNCEMENTS: 177 Symposium on Radioactive and Mixed Waste—Risk as a Basis for Waste Classification; 177 1995 Incineration Conference 178 Ninth Power Plant Dynamics Control and Testing Symposium; 174 The Authors

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Democratizing uncertainty quantification

Uncertainty Quantification (UQ) is vital to safety-critical model-based analyses, but the widespread adoption of sophisticated UQ methods is limited by technical complexity. In this paper, we introduce UM-Bridge (the UQ and Modeling Bridge), a high-level abstraction and software protocol that facilitates universal interoperability of UQ software with simulation codes. It breaks down the technical complexity of advanced UQ applications and enables separation of concerns between experts. UM-Bridge democratizes UQ by allowing effective interdisciplinary collaboration, accelerating the development of advanced UQ methods, and making it easy to perform UQ analyses from prototype to High Performance Computing (HPC) scale. In addition, we present a library of ready-to-run UQ benchmark problems, all easily accessible through UM-Bridge. These benchmarks support UQ methodology research, enabling reproducible performance comparisons. We demonstrate UM-Bridge with several scientific applications, harnessing HPC resources even using UQ codes not designed with HPC support.

Benchmarks↗

SSR APPLIED – Automated Power Plants: Intelligent, Efficient and Digitised (V.2)

This report describes work undertaken during the SSR APPLIED project. The focus of the project has been on the development of digital twins to de-risk licensing of improved operating and maintenance practices. The operation of a bespoke flowing separate effects molten salt loop at ANL, with realistic temperature gradients, will provide invaluable data for computer codes validation. Three digital twins of aspects of the SSR-W have been successfully developed using ANL expertise and software. These digital twins have demonstrated optimization of the fuel cycle, the ability to model transients using an integrated coupled neutronic – thermal-hydraulic model with a model of the fuel expansion feedback so important to the inherent safety of the SSR-W. Advanced machine learning techniques have been developed and demonstrated for optimization of heat exchanger operation and maintenance.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

SAM: A Modern System Code for Advanced Non-LWR Safety Analysis

The System Analysis Module (SAM), developed at Argonne National Laboratory and by collaborators at other organizations, is for advanced non–light water reactor safety analysis. SAM aims to provide fast-running, modest-fidelity, whole-plant transient analysis capabilities that are essential for fast-turnaround design scoping and engineering analyses of advanced reactor concepts. To facilitate code development, SAM utilizes the MOOSE object-oriented application framework, its underlying finite element library, and linear and nonlinear solvers to leverage modern advanced software environments and numerical methods. SAM aims to solve tightly coupled physical phenomena, including fission reaction, heat transfer, fluid dynamics, and thermal-mechanical responses in advanced reactor structures, systems, and components with high accuracy and efficiency. Finally, this paper gives an overview of the SAM code development, including goals and functional requirements, physical models, current capabilities, verification and validation, software quality assurance, and examples of simulations for advanced nuclear reactor applications.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Data-Conforming Data-Driven Control: Avoiding Premature Generalizations Beyond Data

Data-driven and adaptive control approaches face the problem of introducing sudden distributional shifts beyond the distribution of data encountered during learning. Therefore, they are prone to invalidating the very assumptions used in their own construction. This is due to the linearity of the underlying system, inherently assumed and formulated in most data-driven control approaches, which may falsely generalize the behavior of the system beyond the behavior experienced in the data. This article seeks to mitigate these problems by enforcing consistency of the newly designed closed-loop systems with data and slowing down any distributional shifts in the joint state-input space. This is achieved through incorporating affine regularization terms and linear matrix inequality constraints to data-driven approaches, resulting in convex semi-definite programs that can be efficiently solved by standard software packages. We discuss the optimality conditions of these programs and then conclude this article with a numerical example that further highlights the problem of premature generalization beyond data and shows the effectiveness of our proposed approaches in enhancing the safety of data-driven control methods.

97 MATHEMATICS AND COMPUTING↗

Large-scale Hydrogen Storage Risk Assessment

This project investigated risks involved in deploying a large-scale hydrogen storage system at the Port of Seattle (hereafter, the Port) for its on-terminal and maritime applications in an urban industrial setting. Alongside, the project attempted to address some of the barriers to risk assessment such as need for an exact system design for a systematic investigation, direct access to surrounding communities to gauge their perceptions, and an integrated software required to undertake a full-fledged risk assessment. These barriers were overcome using illustrative reference station designs, engaging with community-facing agencies through Port support, and pooling national laboratory capabilities available for risk assessments. The project identified relevant public safety risk metrics, compared various hydrogen carriers, engaged with community-facing agencies, and explored potential gaps in existing safety codes and standards. The primary impacts of this project include the development of risk assessment guidance for ports and utilities, informing them of the trade-offs in the choice of hydrogen carriers, and the ability to increase public capacity for dialog and engagement. This paves the way toward decarbonization of the Port activities, bringing about awareness around jobs in the market for risk assessments, and the need to ramp up community engagement long before any hydrogen system deployment is undertaken.

08 HYDROGEN↗

Formal Methods for Provably Secure Software and Firmware

This project addresses a gap observed in verifying the programming in embedded devices used in international arms control: namely verifying that embedded programming in an arms control device does exactly what it is supposed to do, no more and no less, every time without fail, and without disclosing unauthorized information accidentally or intentionally. In critical military, aerospace, and industrial safety systems this problem is sometimes addressed using formal methods (FM). This multi-year project seeks to identify formal methods toolsets useable in arms control regimes, with emphasis on applicability, ease of use, long term availability, and support.

formal methods, Arms Control Verification↗

ADEPT: A Pedagogical Framework for Integrating Agentic AI with Deterministic Scientific Workflows

The integration of Large Language Models (LLMs) into scientific research promises to accelerate discovery, yet a significant gap remains between the dynamic reasoning of Artificial Intelligence (AI) agents and the static, deterministic nature of canonical scientific workflows. This paper introduces ADEPT (Agentic Discovery and Exploration Platform for Tools), a reference architecture and pedagogical framework explicitly designed to bridge this gap. ADEPT's primary mission is to provide a transparent, "glass-box" environment where researchers and engineers can learn to effectively wrap established scientific software (e.g., BLAST, Nextflow pipelines) and compose it into reliable, agent-driven workflows. We describe its modular, multi-server architecture, which leverages the Model Context Protocol (MCP) for tool serving, LangGraph for robust agentic orchestration, and a secure nsjail-based sandbox for safe code execution. By prioritizing architectural clarity, safety, and modularity, ADEPT serves as an extensible blueprint for building trustworthy AI-augmented systems and fosters the collaborative development necessary to responsibly employ agentic AI for science. We provide practical examples of how to adapt and extend this framework, highlighting its utility in workforce development and AI-readiness capabilities across research and development projects.

97 MATHEMATICS AND COMPUTING↗

STAT7 v2.0 User Guide

The STAT7 software was developed to perform steady-state, single-phase thermal hydraulics analysis of plate-fueled reactors based on statistical propagation of uncertainties. Application of the software includes non-power research and test reactor analysis, and it has been used for the conversion to low- enriched uranium fuel of U.S. High Performance Research Reactors such as the Massachusetts Institute of Technology Research Reactor. Since it can be necessary to repeat reactor safety analysis, such as during fuel reloading, STAT7 accommodates flexibility in analyzing many practical aspects of reactor fuel management. STAT7 uses a Monte Carlo approach to model uncertainty in common fuel fabrication parameters and other key reactor operating parameters required for reactor thermal hydraulics analysis. These safety calculations are ultimately intended to protect against high fuel plate temperatures due to critical heat flux, or onset of flow instability. STAT7 supports water properties based on the IAPWS-IF97 functions (The International Association for the Properties of Water and Steam Industrial Formulation 1997 for the Thermodynamic Properties of Water and Steam) in addition to fitted functions. STAT7 predicts axial profiles of fuel, cladding, and coolant temperature along a lateral stripe that runs the full length of the fuel plate from the bottom to the top. STAT7 can simultaneously analyze every axial node in each lateral stripe of all fuel plates and coolant channels in every fuel element of an entire reactor core. Power splits are calculated for each axial node of each plate to determine how much of the power goes out each face of the plate. In a single execution, STAT7 can be used to perform full core analysis by analyzing the margin to onset of nucleate boiling and onset of flow instability for each axial node of each stripe of each plate of each fuel element in the core.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗