Search NASASearch

SEARCH · Search NASA

Results for “Software trust”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

The Essence of Cryptol: A Denotational Cryptol Interpreter in Coq for Foundational Assurances for Quantum Resistant Cryptosystems

Systems of the utmost consequence need a means to establish authenticity of software and data. Cryptosystems implement authentication, but can be vulnerable to cryptographic and implementation attacks. With the threat of quantum cryptographic attacks, “post-quantum” cryptosystems (PQCs) must be henceforth used in these systems. However, the new cryptography needs new ways to, rigorously and machine-checkably, prove systems free of vulnerabilities. We propose a retargetable capability to rapidly instantiate proven correct postquantum cryptosystems through novel proof-carrying synthesis and proof-automation technique, extending those proven successful on existing systems. This capability is crucial to meeting the cryptographic requirements for future high-consequence systems. Since specifications for high consequence cryptography are presently captured in a domain specific language known as Cryptol. While this can enable convenient fully automated reasoning about Cryptol specificaitons and implementations via the Software Analysis Workbench (SAW), Cryptol has expressivity gaps, so that cryptosystems with probabilistic programming features like Falcon cannot be fully expressed in the language. Moreover, SAW’s automation fails for programs and specificaitons with inductive and recursive structure, as in the Sphincs+ PQC. Finally, Cryptol and SAW together represent some 200,000 lines of unverified Haskell, so that the any guarantees about high consequence cryptography are presently contingent on a large, unverified, yet trusted computing base. The first step of the larger project of agile, assured crpytography is therefore to provide a formal, mechanized semantics for Cryptol, so that the specifications expressed by cryptographers in Cryptol can be reasoned about and compiled into performant implementations with a foundational, machine checkable certificate of correctness. This report describes our work on this first step, culminating in the design of a certified denotational interpreter, in Coq, for core Cryptol.

97 MATHEMATICS AND COMPUTING

Teamwork for Oversight of Processes and Systems (TOPS). Implementation guide for TOPS version 2.0, 10 August 1992

As the nation redefines priorities to deal with a rapidly changing world order, both government and industry require new approaches for oversight of management systems, particularly for high technology products. Declining defense budgets will lead to significant reductions in government contract management personnel. Concurrently, defense contractors are reducing administrative and overhead staffing to control costs. These combined pressures require bold approaches for the oversight of management systems. In the Spring of 1991, the DPRO and TRW created a Process Action Team (PAT) to jointly prepare a Performance Based Management (PBM) system titled Teamwork for Oversight of Processes and Systems (TOPS). The primary goal is implementation of a performance based management system based on objective data to review critical TRW processes with an emphasis on continuous improvement. The processes are: Finance and Business Systems, Engineering and Manufacturing Systems, Quality Assurance, and Software Systems. The team established a number of goals: delivery of quality products to contractual terms and conditions; ensure that TRW management systems meet government guidance and good business practices; use of objective data to measure critical processes; elimination of wasteful/duplicative reviews and audits; emphasis on teamwork--all efforts must be perceived to add value by both sides and decisions are made by consensus; and synergy and the creation of a strong working trust between TRW and the DPRO. TOPS permits the adjustment of oversight resources when conditions change or when TRW systems performance indicate either an increase or decrease in surveillance is appropriate. Monthly Contractor Performance Assessments (CPA) are derived from a summary of supporting system level and process-level ratings obtained from objective process-level data. Tiered, objective, data-driven metrics are highly successful in achieving a cooperative and effective method of measuring performance. The teamwork-based culture developed by TOPS proved an unequaled success in removing adversarial relationships and creating an atmosphere of continuous improvement in quality processes at TRW. The new working relationship does not decrease the responsibility or authority of the DPRO to ensure contract compliance and it permits both parties to work more effectively to improve total quality and reduce cost. By emphasizing teamwork in developing a stronger approach to efficient management of the defense industrial base TOPS is a singular success.

Strand, Albert A.

Human-Autonomy Teaming: Supporting Dynamically Adjustable Collaboration

This presentation is a technical update for the NATO-STO HFM-247 working group. Our progress on four goals will be discussed. For Goal 1, a conceptual model of HAT is presented. HAT looks to make automation act as more of a teammate, by having it communicate with human operators in a more human, goal-directed, manner which provides transparency into the reasoning behind automated recommendations and actions. This, in turn, permits more trust in the automation when it is appropriate, and less when it is not, allowing a more targeted supervision of automated functions. For Goal 2, we wanted to test these concepts and principles. We present findings from a recent simulation and describe two in progress. Goal 3 was to develop pattern(s) of HAT solution(s). These were originally presented at HCII 2016 and are reviewed. Goal 4 is to develop a re-usable HAT software agent. This is an ongoing effort to be delivered October 2017.

Human-Autonomy Teaming

Homotopy Solver

This software implements parallel versions of an interior-point solver, based on the publicly available ipopt solver. Here we have full control over the linear solver and our algorithm is fully parallel thus enabling scalability to large-scale optimization problems. This package also has a parallel implementation of a homotopy solver developed under the scalable methods for contact LDRD project 23-ERD-017. This solver is an mfem-based implementation of algorithm described in ``A filter trust-region Newton continuation method for nonlinear complementarity problems''. Cosmin G. Petra, Nai-Yuan Chiang, Jingyi Wang, Tucker Hartland, and Michael Puso (submitted), LLNL-JRNL-869761.

Hartland, Tucker [Lawrence Livermore National Labo

Hardware Fuzzing with An Emulator

Bugs in digital logic have led to some significant security vulnerabilities. Hardware bugs are particularly troublesome since they cannot be easily patched. Additionally, if the bug is in the root of trust, all trust built upon it can be vulnerable. Traditional testing either require a deep knowledge of the system, creative attack vectors and lots of human interaction. This is not scalable as there are very few engineers that can wear the hat of a designer, a verification engineer, and a cybersecurity expert. Hardware fuzzing is a relatively new research area in dynamic hardware testing. It has proven to be an effective method for discovering bugs, unexpected behaviors, and security vulnerabilities in software. While hardware fuzzing is new to the hardware domain, it has a strong track record in software testing. Fuzzing is a testing technique that randomly mutates the input data to uncover bugs or vulnerabilities in the design. It is especially good at finding corner cases that test engineers can not envision. Another advantage over other dynamic testing techniques is that, if done well, deep knowledge of the design is not required. Additionally, fuzzing scales well. If the system is set up correctly, it can run unsupervised for weeks if necessary. In this work, we propose using hardware fuzzing to improve the input vector generation for an information flow tracking tool. To get reasonable throughput of test vectors, an emulator is targeted as the execution platform. Efficient emulator execution has some specific requirements.

42 ENGINEERING

CASIS Fact Sheet: Hardware and Facilities

Vencore is a proven information solutions, engineering, and analytics company that helps our customers solve their most complex challenges. For more than 40 years, we have designed, developed and delivered mission-critical solutions as our customers' trusted partner. The Engineering Services Contract, or ESC, provides engineering and design services to the NASA organizations engaged in development of new technologies at the Kennedy Space Center. Vencore is the ESC prime contractor, with teammates that include Stinger Ghaffarian Technologies, Sierra Lobo, Nelson Engineering, EASi, and Craig Technologies. The Vencore team designs and develops systems and equipment to be used for the processing of space launch vehicles, spacecraft, and payloads. We perform flight systems engineering for spaceflight hardware and software; develop technologies that serve NASA's mission requirements and operations needs for the future. Our Flight Payload Support (FPS) team at Kennedy Space Center (KSC) provides engineering, development, and certification services as well as payload integration and management services to NASA and commercial customers. Our main objective is to assist principal investigators (PIs) integrate their science experiments into payload hardware for research aboard the International Space Station (ISS), commercial spacecraft, suborbital vehicles, parabolic flight aircrafts, and ground-based studies. Vencore's FPS team is AS9100 certified and a recognized implementation partner for the Center for Advancement of Science in Space (CASIS

Solomon, Michael R.

AdaNET prototype library administration manual

The functions of the AdaNET Prototype Library of Reusable Software Parts is described. Adopted from the Navy Research Laboratory's Reusability Guidebook (V.5.0), this is a working document, customized for use the the AdaNET Project. Within this document, the term part is used to denote the smallest unit controlled by a library and retrievable from it. A part may have several constituents, which may not be individually tracked. Presented are the types of parts which may be stored in the library and the relationships among those parts; a concept of trust indicators which provide measures of confidence that a user of a previously developed part may reasonably apply to a part for a new application; search and retrieval, configuration management, and communications among those who interact with the AdaNET Prototype Library; and the AdaNET Prototype, described from the perspective of its three major users: the part reuser and retriever, the part submitter, and the librarian and/or administrator.

Hanley, Lionel

Development and Deployment of Robonaut 2 to the International Space Station

The development of the Robonaut 2 (R2) system was a joint endeavor with NASA and General Motors, producing robots strong enough to do work, yet safe enough to be trusted to work near humans. To date two R2 units have been produced, designated as R2A and R2B. This follows more than a decade of work on the Robonaut 1 units that produced advances in dexterity, tele-presence, remote supervision across time delay, combining mobility with manipulation, human-robot interaction, force control and autonomous grasping. Design challenges for the R2 included higher speed, smaller packaging, more dexterous fingers, more sensitive perception, soft drivetrain design, and the overall implementation of a system software approach for human safety, At the time of this writing the R2B unit was poised for launch to the International Space Station (ISS) aboard STS-133. R2 will be the first humanoid robot in space, and is arguably the most sophisticated robot in the world, bringing NASA into the 21st century as the world's leader in this field. Joining the other robots already on ISS, the station is now an exciting lab for robot experiments and utilization. A particular challenge for this project has been the design and certification of the robot and its software for work near humans. The 3 layer software systems will be described, and the path to ISS certification will be reviewed. R2 will go through a series of ISS checkout tests during 2011. A taskboard was shipped with the robot that will be used to compare R2B's dexterous manipulation in zero gravity with the ground robot s ability to handle similar objects in Earth s gravity. R2's taskboard has panels with increasingly difficult tasks, starting with switches, progressing to connectors and eventually handling softgoods. The taskboard is modular, and new interfaces and experiments will be built up using equipment already on ISS. Since the objective is to test R2 performing tasks with human interfaces, hardware abounds on ISS and the crew will be involved to help select tasks that are dull, dirty or dangerous. Future plans for R2 include a series of upgrades, evolving from static IVA (Intravehicular Activity) operations, to mobile IVA, then EVA (Extravehicular Activity).

Ambrose, Robert O.

Southwest Water Resources: Monitoring Surface Water Extents of Remote Stock Ponds in the Southwestern United States Using Earth Observing Systems for Enhanced Water Resources Management

Due to increasingly frequent and severe drought conditions in the southwestern US, land managers and livestock producers need to monitor stock ponds with increasing regularity. The ability to assess stock pond water levels with Earth observing satellite systems would enhance monitoring efforts of partners at the US Forest Service, Arizona Department of Game and Fish, and the Diablo Trust. This study employed Landsat 8 Operational Land Imager (OLI), Sentinel-1 C-band Synthetic Aperture Radar (C-SAR), and Sentinel-2 Multispectral Instrument (MSI) to monitor surface water extent for hundreds of critical stock ponds in Arizona. Using methods adapted from previously developed image processing workflows, this project conducted a time-series analysis to capture seasonal and interannual variations in surface water area between 2013 to 2021. In addition, end users can monitor the surface water extent of stock ponds through the developed Google Earth Engine software tool called Surface Water Identification and Forecasting Tool (SWIFT). SWIFT incorporates the Automated Water Extraction Index, Modified Normalized Difference Water Index, and Tasseled Cap-Wetness Index for optical imagery and the incidence angle, VV and VH polarization bands for Sentinel-1 imagery to detect small water bodies in the study area with an overall accuracy range of 88-93%. These tools will empower our partners to monitor the extents of water in their stock ponds remotely, enabling them to develop data-informed and sustainable management solutions for decades to come.

Rainey Aberle

Fit2Fly: A Proof of Concept for Testing the Commercial Feasibility of Unmanned Aerial System Operations

As autonomous Unmanned Aerial Systems (UAS) become more prevalent, improvements in airworthiness assessments, data security, establishing vehicle trust, and more will become necessary to make fleet operations of these systems routine. Currently, these are verified for every UAS vehicle through a time-intensive manual inspection performed by human individuals. This process becomes infeasible when introduced into large-scale operations, so the Fit2Fly project is attempting to address these concerns. Fit2Fly is a multi-year project with a large scope, so we chose to narrow our focus to building a proof-of-concept feasibility simulation in tandem with physical UAS demonstration. This work resulted in a software simulation capable of running asynchronous commercial operations with persistent data modeling in coordination with several autonomous drones using integrated radio and GPS configurations.

Ryan Bonk

Goal Structuring Notation in a Radiation Hardening Assurance Case for COTS-Based Spacecraft

A systematic approach is presented to constructing a radiation assurance case using Goal Structuring Notation (GSN) for spacecraft containing COTS parts. The GSN paradigm is applied to an SRAM single-event upset experiment board designed to fly on a CubeSat in January 2017. A custom software language for development of a GSN assurance case is under development at Vanderbilt. Construction of a radiation assurance case without use of hardened parts or extensive radiation testing is discussed.

Radiation Effects Modeling (REM)

Usability Evaluation of Fleet Management Interface for High Density Vertiplex Environments

To meet the rising demand for an Advanced Air Mobility (i.e. urban and rural unmanned aircraft systems) ecosystem, NASA Aeronautics Research Mission Directorate (ARMD) is hosting a series of simulations and flight tests under the High Density Vertiplex sub-project (HDV). HDV aims to develop an integrated automation architecture to support terminal area flight operations. The HDV simulations and flight tests address safety, integration, and operational challenges, while integrated systems and software demonstrate design readiness, robustness, and interoperability. During the initial HDV simulation in 2021, a prototype traffic management tool developed by NASA called Fleet Management Interface (FMI) was tested. FMI was designed to introduce an advanced level of human-automation interaction to aid both Ground Control Station Operators (GCSOs) and Fleet Managers (FMs) in remotely managing flights under their ownership. In a human-in-the-loop simulation, a usability study was conducted with FMI to identify optimal approaches for displaying information for human operators using subjective measures of usability, workload, situation awareness, risk, and trust, along with qualitative feedback. This study consisted of task analysis in which GCSO and FM subjects used an Urban Air Mobility (UAM) environment to develop and execute a plan for two different traffic scenarios of remotely controlled vehicles. In each scenario, a controlled vehicle completed a takeoff, active flight, and landing sequence while automated traffic flew in the background at a rate of 20 operations per hour. In the first scenario, the controlled vehicle flew a nominal route with takeoff and landing at the same vertiport. In the second scenario, the controlled vehicle started on the nominal route, then diverted to an unplanned location mid-flight. Results showed that self-reported performance, usability, trust, and situation awareness ratings of FMI were moderately to strongly high. There were small differences between scenarios, with Scenario 2 being perceived as more unstable, complex, variable, risky, and potentially harmful than Scenario 1. Furthermore, participants described improvements that could be made to create a better user experience. For example, users would like greater configurability of the interface based on their personal information requirements, and they would like the opportunity to review routes before assigning them. The results from this study will inform future development of the FMI with the end goal of creating a reference automation tool for airspace management procedures in AAM. The FMI could be introduced as a potential way to reduce dependency on traditional air navigation services through increased automation in high density vertiplex environments.

vertiplex

Usability Evaluation of Fleet Management Interface for High Density Vertiplex Environments

To meet the rising demand for an Advanced Air Mobility (AAM) (i.e. urban and rural unmanned aircraft systems) ecosystem, the NASA Aeronautics Research Mission Directorate (ARMD) is hosting a series of simulations and flight tests under the High Density Vertiplex sub-project (HDV) to prototype and study the effectiveness AAM capabilities under various operational contexts. HDV aims to develop an integrated automation architecture to support terminal area flight operations. The HDV simulations and flight tests address safety, integration, and operational challenges, while integrated systems and software demonstrate design readiness, robustness, and interoperability. During the initial HDV simulation in 2021, a prototype traffic management tool developed by NASA called the Fleet Management Interface (FMI) was tested. FMI was designed to introduce an advanced level of human-automation interaction to aid both Ground Control Station Operators (GCSOs) and Fleet Managers (FMs) in remotely managing flights under their ownership. In a human-in-the-loop simulation, a usability study was conducted with the FMI to identify optimal approaches for displaying information to human operators using subjective measures of usability, workload, situation awareness, risk, and trust, along with qualitative feedback. This study consisted of task analysis in which GCSO and FM subjects used an Urban Air Mobility (UAM) environment to develop and execute a plan for two different traffic scenarios of remotely controlled vehicles. In each scenario, a remotely controlled vehicle completed a takeoff, active flight, and landing sequence while simulated traffic flew in the background at a rate of 20 operations per hour. In the first scenario, the controlled vehicle flew a nominal route with takeoff and landing at the same vertiport. In the second scenario, the controlled vehicle started on the nominal route, then diverted to an unplanned location mid-flight. Results showed that self- reported performance, usability, trust, and situation awareness ratings of FMI were moderately to strongly high. There were small differences between scenarios, with Scenario 2 being perceived as more unstable, complex, variable, risky, and potentially harmful than Scenario 1. Furthermore, participants described improvements that could be made to create a better user experience. For example, users suggested customizable interfaces to accommodate information display preferences, and the ability to review routes before assigning them. The results from this study will inform future development of the FMI with the end goal of creating a reference automation tool for airspace management procedures in AAM. The FMI could serve to reduce dependency on traditional air navigation services through increased automation in high density vertiplex environments.

Fleet manager

Evaluation of a Dispatcher's Route Optimization Decision Aid to Avoid Aviation Weather Hazards

This document describes the results and analysis of the formal evaluation plan for the Honeywell software tool developed under the NASA AWIN (Aviation Weather Information) 'Weather Avoidance using Route Optimization as a Decision Aid' project. The software tool aims to provide airline dispatchers with a decision aid for selecting optimal routes that avoid weather and other hazards. This evaluation compares and contrasts route selection performance with the AWIN tool to that of subjects using a more traditional dispatcher environment. The evaluation assesses gains in safety, in fuel efficiency of planned routes, and in time efficiency in the pre-flight dispatch process through the use of the AWIN decision aid. In addition, we are interested in how this AWIN tool affects constructs that can be related to performance. The construct of Situation Awareness (SA), workload, trust in an information system, and operator acceptance are assessed using established scales, where these exist, as well as through the evaluation of questionnaire responses and subject comments. The intention of the experiment is to set up a simulated operations area for the dispatchers to work in. They will be given scenarios in which they are presented with stored company routes for a particular city-pair and aircraft type. A diverse set of external weather information sources is represented by a stand-alone display (MOCK), containing the actual historical weather data typically used by dispatchers. There is also the possibility of presenting selected weather data on the route visualization tool. The company routes have not been modified to avoid the weather except in the case of one additional route generated by the Honeywell prototype flight planning system. The dispatcher will be required to choose the most appropriate and efficient flight plan route in the displayed weather conditions. The route may be modified manually or may be chosen from those automatically displayed.

Dorneich, Michael C.

Crew Performance Support System to Aid in Anomaly Resolution: Concept of Operations

As missions progress into deep space, communication delays and disruptions will disenable the crew’s reliance on Earth experts. There are also limitations in the amount of data that can be downlinked to the ground. It is prudent to assume that critical, complex vehicle or habitat sub-systems will malfunction at a time when a lunar or Mars’ crew cannot rely on the Earth-Support team to detect, diagnose and resolve the problem and it is impractical to expect a small crew to step-in with the same level of expertise as 50+ authorities. The crew will need novel processes and advanced technological support to independently identify and resolve safety- and time-critical anomalies. That a self-reliant crew is unable to respond appropriately to time-critical anomalies is a significant risk to crew safety and mission success. This risk is driven by several factors; novel and unanticipated anomalies would not have been trained pre-flight, the crew could forget their pre-flight training or spaceflight stressors could impair the crew’s problem-solving ability. At last year’s IWS, Beard reported that a single spaceflight stressor (elevated CO2) could undermine the crew’s ability to independently respond to emergencies. Concept of Operations (ConOps) provide a common view of future system functions to all stakeholders. For the current project, a ConOps was developed that describes the operational processes, practices and capabilities needed by a crew of astronauts on deep space missions to autonomously respond to anticipated and unanticipated anomalies. It is crucial to recognize that, as of August 2018 existing technologies are unable to effectively support crew anomaly response to unanticipated events. “Intelligent technology” has not reached a maturity level that permits generalizing a solution to novel situations. For example, to train intelligent technology requires volumes of data that do not exist. The complexities involved in a manned mission to Mars cannot be compared to sending rovers to Mars using scripted software. This ConOps proposes a Crew Performance Support System (CPSS) that will push NASA and its industry partners toward what will be required for a safe and successful manned mission to Mars. Anomaly resolution during a deep space mission will take place within a dynamic, or changing, context. The figure to the left shows five broad contextual variables: the organizational culture, mission context, system characteristics, team characteristics and individual characteristics. The yellow arrow indicates that spaceflight and task-related stressors can affect system, team and individual crewmember characteristics and therefore anomaly response potential. The figure depicts a protective umbrella of Human-System Integration (HSI) principles that should be instituted during CPSS development including a balanced workload, shared situation awareness and building an appropriate level of trust in the automation. The figure also depicts two interrelated and cooperative components, an HSI Data System and other Enabling Capabilities will be required to support crew anomaly response and Earth-Support situation awareness. As we journey from ISS to Gateway to Mars, multiple, simultaneous and integrated research and development efforts (i.e., support systems co-evolution) must be implemented to meet the problem-solving challenges a self-reliant crew will face on a Mars’ mission. The crossovers between the capabilities are just as important as the discrete capabilities themselves. As the capabilities mature, the lines between the support subdomains will blur and an integrated system will emerge. The ConOps summarizes current knowledge about how highly trained people solve anomalies in safety- and time-critical situations, describes a group of capabilities that could help to reduce the extant risk and documents requirements levied on additional systems that provides critical inputs to the CPSS. Scenarios are used to promote a shared understanding of processes, practices and technological goals needed for safe and productive manned missions beyond LEO.

HSIA risk

Visualizing and analyzing 3D biomolecular structures using Mol* at RCSB.org: Influenza A H5N1 virus proteome case study

The easiest and often most useful way to work with experimentally determined or computationally predicted structures of biomolecules is by viewing their three-dimensional (3D) shapes using a molecular visualization tool. Mol* was collaboratively developed by RCSB Protein Data Bank (RCSB PDB, RCSB.org) and Protein Data Bank in Europe (PDBe, PDBe.org) as an open-source, web-based, 3D visualization software suite for examination and analyses of biostructures. It is capable of displaying atomic coordinates and related experimental data of biomolecular structures together with a variety of annotations, facilitating basic and applied research, training, education, and information dissemination. Across RCSB.org, the RCSB PDB research-focused web portal, Mol* has been implemented to support single-mouse-click atomic-level visualization of biomolecules (e.g., proteins, nucleic acids, carbohydrates) with bound cofactors, small-molecule ligands, ions, water molecules, or other macromolecules. RCSB.org Mol* can seamlessly display 3D structures from various sources, allowing structure interrogation, superimposition, and comparison. Using influenza A H5N1 virus as a topical case study of an important pathogen, we exemplify how Mol* has been embedded within various RCSB.org tools—allowing users to view polymer sequence and structure-based annotations integrated from trusted bioinformatics data resources, assess patterns and trends in groups of structures, and view structures of any size and compositional complexity. In addition to being linked to every experimentally determined biostructure and Computed Structure Model made available at RCSB.org, Standalone Mol* is freely available for visualizing any atomic-level or multi-scale biostructure at rcsb.org/3d-view.

3D biostructure

ReMU: regional minimal updating for model-based derivative-free optimization

Derivative-free optimization (DFO) problems are optimization problems where derivative information is unavailable or extremely difficult to obtain. Model-based DFO solvers have been applied extensively in scientific computing. Powell's NEWUOA (2004) [Powell, The NEWUOA software for unconstrained optimization without derivatives, in Large-Scale Nonlinear Optimization, Nonconvex Optimization and its Applications Vol. 83, G. Di Pillo and M. Roma, eds., Springer, 2006, pp. 255–297] and Wild's POUNDerS (2014) [Wild, Solving derivative-free nonlinear least squares problems with POUNDERS, in Advances and Trends in Optimization with Engineering Applications, T. Terlaky, M.F. Anjos, and S. Ahmed, eds., SIAM, 2017, pp. 529–540] explore the numerical power of the minimal norm Hessian (MNH) model for DFO and contributed to the open discussion on building better models with fewer data to achieve faster numerical convergence. Another decade later, we propose the regional minimal updating (ReMU) models, and extend the previous models into a broader class, including the H 2 norm models [Xie and Yuan, Least H 2 norm updating of quadratic interpolation models for derivative-free trust-region algorithms, IMA J. Numer. Anal. 46 (2025), pp. 21–50]. This paper shows motivation behind ReMU models, computational details, theoretical and numerical results on particular extreme points and the barycentre of ReMU's weight coefficient region, and the associated KKT matrix error and distance. Novel metrics, such as the truncated Newton step error, are proposed to numerically understand the new models' properties. A new algorithmic strategy, based on iteratively adjusting the ReMU model type, is also proposed, and shows numerical advantages by combining and switching between the barycentric model and the classic least Frobenius norm model in an online fashion.

derivative-free trust-region methods

Verification of Autonomous Systems for Space Applications

Autonomous software, especially if it is based on model, can play an important role in future space applications. For example, it can help streamline ground operations, or, assist in autonomous rendezvous and docking operations, or even, help recover from problems (e.g., planners can be used to explore the space of recovery actions for a power subsystem and implement a solution without (or with minimal) human intervention). In general, the exploration capabilities of model-based systems give them great flexibility. Unfortunately, it also makes them unpredictable to our human eyes, both in terms of their execution and their verification. The traditional verification techniques are inadequate for these systems since they are mostly based on testing, which implies a very limited exploration of their behavioral space. In our work, we explore how advanced V&V techniques, such as static analysis, model checking, and compositional verification, can be used to gain trust in model-based systems. We also describe how synthesis can be used in the context of system reconfiguration and in the context of verification.

Brat, G.