Search NASASearch

SEARCH · Search NASA

Results for “Safety Threshold”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Airspace Safety Threshold Study: Status Update to SC-228 DAA Safety Sub-Group

Realization of the expected proliferation of Unmanned Aircraft System (UAS) operations in the National Airspace System (NAS) depends on the development and validation of performance standards for UAS Detect and Avoid (DAA) Systems. The RTCA Special Committee 228 is charged with leading the development of draft Minimum Operational Performance Standards (MOPS) for UAS DAA Systems. NASA, as a participating member of RTCA SC-228, is committed to supporting the development and validation of draft requirements as well as the safety substantiation and end-to-end assessment of DAA system performance. A recent study conducted using NASA's ACES (Airspace Concept Evaluation System) simulation capability begins to address questions surrounding the development of draft MOPS for DAA systems. ACES analyses were conducted to determine: 1) the rate at which IFR aircraft encounter other IFR and VFR aircraft, and 2) the rate at which UAS aircraft encounter VFR aircraft. Five different separation thresholds were used (two for encounter and one each for well-clear, near mid-air collision, and closest point of approach). The results will be used by SC228 to inform decisions about the safety aspect of UAS DAA systems and future requirements development and validation efforts.

Risk ratio

Investigating the Airspace Safety Threshold of the NAS

As self-separation systems are being developed for integration into the airspace, it is crucial to determine a standard that the systems must meet so that airspace safety does not degrade. To do this, the current level of safety of the NAS (National Airspace System) needs to be determined as a benchmark for comparison. This presentation is an overview of some of the ongoing work being done to evaluate the airspace as it is today. The research analyzes the distribution of encounter statistics of IFR-VFR (Instrument Flight Rules-Visual Flight Rules) traffic using unmodified historical flight data to account for mitigation effects present in the current NAS.

Airspace Encounters

Airspace Safety Threshold Study: NAS-Wide Encounter Rate Evaluation Using Historical Radar Data and ACES

Realization of the expected proliferation of Unmanned Aircraft System (UAS) operations in the National Airspace System (NAS) depends on the development and validation of performance standards for UAS Detect and Avoid (DAA) Systems. The RTCA Special Committee 228 (SC-228) is charged with leading the development of draft Minimum Operational Performance Standards (MOPS) for UAS DAA Systems. NASA, as a participating member of RTCA SC-228 is committed to supporting the development and validation of draft requirements as well as the safety substantiation and end-to-end assessment of DAA system performance. With regard to the safety aspect being studied by the SC-228 DAA Safety sub-group, NASA has conducted a study using the ACES (Airspace Concept Evaluation System) simulation capability to determine: 1) the rate at which IFR aircraft encounter other IFR and VFR aircraft, and 2) the rate at which UAS aircraft encounter VFR aircraft as well as the corresponding encounter geometries. Five different separation thresholds were used (two for encounter and one each for well-clear, near mid-air collision, and closest point of approach). The results will be used by the SC-228 DAA Safety sub-group to inform decisions about the safety aspect of UAS DAA systems and future requirements development and validation efforts.

encounter geometry

Developing Probabilistic Safety Performance Margins for Unknown and Underappreciated Risks

Probabilistic safety requirements currently formulated or proposed for space systems, nuclear reactor systems, nuclear weapon systems, and other types of systems that have a low-probability potential for high-consequence accidents depend on showing that the probability of such accidents is below a specified safety threshold or goal. Verification of compliance depends heavily upon synthetic modeling techniques such as PRA. To determine whether or not a system meets its probabilistic requirements, it is necessary to consider whether there are significant risks that are not fully considered in the PRA either because they are not known at the time or because their importance is not fully understood. The ultimate objective is to establish a reasonable margin to account for the difference between known risks and actual risks in attempting to validate compliance with a probabilistic safety threshold or goal. In this paper, we examine data accumulated over the past 60 years from the space program, from nuclear reactor experience, from aircraft systems, and from human reliability experience to formulate guidelines for estimating probabilistic margins to account for risks that are initially unknown or underappreciated. The formulation includes a review of the safety literature to identify the principal causes of such risks.

Safety Performance Margin

NASA System Safety Handbook: System Safety Framework and Concepts for Implementation - Volume 1

System safety assessment is defined in NPR 8715.3C, NASA General Safety Program Requirements as a disciplined, systematic approach to the analysis of risks resulting from hazards that can affect humans, the environment, and mission assets. Achievement of the highest practicable degree of system safety is one of NASA's highest priorities. Traditionally, system safety assessment at NASA and elsewhere has focused on the application of a set of safety analysis tools to identify safety risks and formulate effective controls.1 Familiar tools used for this purpose include various forms of hazard analyses, failure modes and effects analyses, and probabilistic safety assessment (commonly also referred to as probabilistic risk assessment (PRA)). In the past, it has been assumed that to show that a system is safe, it is sufficient to provide assurance that the process for identifying the hazards has been as comprehensive as possible and that each identified hazard has one or more associated controls. The NASA Aerospace Safety Advisory Panel (ASAP) has made several statements in its annual reports supporting a more holistic approach. In 2006, it recommended that "... a comprehensive risk assessment, communication and acceptance process be implemented to ensure that overall launch risk is considered in an integrated and consistent manner." In 2009, it advocated for "... a process for using a risk-informed design approach to produce a design that is optimally and sufficiently safe." As a rationale for the latter advocacy, it stated that "... the ASAP applauds switching to a performance-based approach because it emphasizes early risk identification to guide designs, thus enabling creative design approaches that might be more efficient, safer, or both." For purposes of this preface, it is worth mentioning three areas where the handbook emphasizes a more holistic type of thinking. First, the handbook takes the position that it is important to not just focus on risk on an individual basis but to consider measures of aggregate safety risk and to ensure wherever possible that there be quantitative measures for evaluating how effective the controls are in reducing these aggregate risks. The term aggregate risk, when used in this handbook, refers to the accumulation of risks from individual scenarios that lead to a shortfall in safety performance at a high level: e.g., an excessively high probability of loss of crew, loss of mission, planetary contamination, etc. Without aggregated quantitative measures such as these, it is not reasonable to expect that safety has been optimized with respect to other technical and programmatic objectives. At the same time, it is fully recognized that not all sources of risk are amenable to precise quantitative analysis and that the use of qualitative approaches and bounding estimates may be appropriate for those risk sources. Second, the handbook stresses the necessity of developing confidence that the controls derived for the purpose of achieving system safety not only handle risks that have been identified and properly characterized but also provide a general, more holistic means for protecting against unidentified or uncharacterized risks. For example, while it is not possible to be assured that all credible causes of risk have been identified, there are defenses that can provide protection against broad categories of risks and thereby increase the chances that individual causes are contained. Third, the handbook strives at all times to treat uncertainties as an integral aspect of risk and as a part of making decisions. The term "uncertainty" here does not refer to an actuarial type of data analysis, but rather to a characterization of our state of knowledge regarding results from logical and physical models that approximate reality. Uncertainty analysis finds how the output parameters of the models are related to plausible variations in the input parameters and in the modeling assumptions. The evaluation of unrtainties represents a method of probabilistic thinking wherein the analyst and decision makers recognize possible outcomes other than the outcome perceived to be "most likely." Without this type of analysis, it is not possible to determine the worth of an analysis product as a basis for making decisions related to safety and mission success. In line with these considerations the handbook does not take a hazard-analysis-centric approach to system safety. Hazard analysis remains a useful tool to facilitate brainstorming but does not substitute for a more holistic approach geared to a comprehensive identification and understanding of individual risk issues and their contributions to aggregate safety risks. The handbook strives to emphasize the importance of identifying the most critical scenarios that contribute to the risk of not meeting the agreed-upon safety objectives and requirements using all appropriate tools (including but not limited to hazard analysis). Thereafter, emphasis shifts to identifying the risk drivers that cause these scenarios to be critical and ensuring that there are controls directed toward preventing or mitigating the risk drivers. To address these and other areas, the handbook advocates a proactive, analytic-deliberative, risk-informed approach to system safety, enabling the integration of system safety activities with systems engineering and risk management processes. It emphasizes how one can systematically provide the necessary evidence to substantiate the claim that a system is safe to within an acceptable risk tolerance, and that safety has been achieved in a cost-effective manner. The methodology discussed in this handbook is part of a systems engineering process and is intended to be integral to the system safety practices being conducted by the NASA safety and mission assurance and systems engineering organizations. The handbook posits that to conclude that a system is adequately safe, it is necessary to consider a set of safety claims that derive from the safety objectives of the organization. The safety claims are developed from a hierarchy of safety objectives and are therefore hierarchical themselves. Assurance that all the claims are true within acceptable risk tolerance limits implies that all of the safety objectives have been satisfied, and therefore that the system is safe. The acceptable risk tolerance limits are provided by the authority who must make the decision whether or not to proceed to the next step in the life cycle. These tolerances are therefore referred to as the decision maker's risk tolerances. In general, the safety claims address two fundamental facets of safety: 1) whether required safety thresholds or goals have been achieved, and 2) whether the safety risk is as low as possible within reasonable impacts on cost, schedule, and performance. The latter facet includes consideration of controls that are collective in nature (i.e., apply generically to broad categories of risks) and thereby provide protection against unidentified or uncharacterized risks.

Dezfuli, Homayoon

Detecting Risk and Anomalies in Airplane Dynamics Through Entropic Analysis of Time Series Data

Despite recent efforts to move away from traditional threshold exceedance detection methods for aircraft state monitoring, modern aircraft still rely on safety thresholds to communicate to pilots the identification of an anomaly in the aircraft when a threshold is surpassed. Current anomaly detection methods mainly depend on uninterpretable machine learning models to learn complex patterns and relationships contained in the time series data of aircraft. Although these methods are capable of identifying known anomalies, their deficiency in interpretability presents a challenge when translating them to different aircraft. To overcome this deficiency, entropic analysis of aircraft dynamics seeks to characterize the complexity, or lack thereof, of the aircraft dynamics prior to the development of a risk scenario. This complexity characterization provides a more straightforward summary of state changes in the dynamics of flight variables. To build a foundation for entropic analysis, we analyzed the complexity of unstable approaches, an anomalous event present in many of today’s aviation accidents. The analysis revealed a statistically significant difference in the complexity distribution of flight variables under a stable approach versus an unstable approach. These differences in complexity were especially notable minutes before an approach was identified as unstable. Moreover, the multiscale entropic analysis revealed the presence of signal complexity at multiple time scales across multiple time windows before landing. By capturing state changes and corrections in the aircraft dynamics using entropy, advanced, yet still interpretable, sensor systems based on entropic frameworks from this study can be constructed in the future using classical machine learning approaches.

Risk detection

Piloted Well Clear Performance Evaluation of Detect and Avoid Systems with Suggestive Guidance

Regulations to establish operational and performance requirements for unmanned aircraft systems (UAS) are being developed by a consortium of government, industry and academic institutions (RTCA, 2013). Those requirements will apply to the new detect-and-avoid (DAA) systems and other equipment necessary to integrate UAS with the United States (U.S) National Airspace System (NAS) and will be determined according to their contribution to the overall safety case. That safety case requires demonstration that DAA-equipped UAS collectively operating in the NAS meet an airspace safety threshold (AST). Several key gaps must be closed in order to link equipment requirements to an airspace safety case. Foremost among these is calculation of the systems risk ratio, the degree to which a particular system mitigates violation of an aircraft separation standard (FAA, 2013). The risk ratio of a DAA system, in combination with risk ratios of other collision mitigation mechanisms, will determine the overall safety of the airspace measured in terms of the number of collisions per flight hour. It is not known what the effectiveness is of a pilot-in-the-loop DAA system or even what parameters of the DAA system most improve the pilots ability to maintain separation. The relationship between the DAA system design and the overall effectiveness of the DAA system that includes the pilot, expressed as a risk ratio, must be determined before DAA operational and performance requirements can be finalized. Much research has been devoted to integrating UAS into non-segregated airspace (Dalamagkidis, 2009, Ostwald, 2007, Gillian, 2012, Hesselink, 2011, Santiago, 2015, Rorie 2015 and 2016). Several traffic displays intended for use as part of a DAA system have gone through human-in-the-loop simulation and flight-testing. Most of these evaluations were part of development programs to produce a deployable system, so it is unclear how to generalize particular aspects of those designs to general requirements for future traffic displays (Calhoun, 2014). Other displays have undergone testing to collect data that may generalize to new displays, but have not been evaluated in the context of the development of an overall safety case for UAS equipped with DAA systems in the NAS (Bell, 2012). Other research efforts focus on DAA surveillance performance and separation standards. Together with this work, they are expected to facilitate validation of the airspace safety case (Park, 2014 and Johnson, 2015). The contribution of the present work is to quantify the effectiveness of the pilot-automation system to remain well clear as a function of display features and surveillance sensor error. This quantification will help enable selection of a minimum set of DAA design features that meets the AST, a set that may not be unique for all UAS platforms. A second objective is to collect and analyze pilot performance parameters that will improve the modeling of overall DAA system performance in non-human-in-the-loop simulations. Simulating the DAA-equipped UAS in such batch experiments will allow investigation of a much larger number of encounters than is possible in human simulations. This capability is necessary to demonstrate that a particular set of DAA requirements meets the AST under all foreseeable operational conditions.

detect and avoid

Conflict Alerts for Aircraft Conducting Visual Approaches

It is common for aircraft to conduct visual and instrument final approaches to a single runway or multiple parallel runways. Useful, nonexcessive safety alerts on aircraft conducting visual approaches are helpful to air traffic controllers, though pilots are responsible for separation with the preceding aircraft. A variety of visual approaches to various runway configurations are studied, and a set of safety alert thresholds is proposed. Fast-time simulations with recorded real-world air traffic data of mostly visual approach flights are performed on a prototype tactical separation assurance system for terminal airspace. Alerts are generated -- with both the standard separation thresholds and the proposed safety alert thresholds -- and compared with those from the Conflict Alert (CA) functionality in the Standard Terminal Automation Replacement System (STARS). The results show that the number of Mode-C Intruder alerts generated was reduced 76% as compared to STARS CA. The nuisance alerts generated by assuming visual to be instrument approaches was reduced by 92% when the proposed safety alert thresholds were used and visual approaches were assumed.A set of safety alert thresholds, which allow safety alerts to be provided to the controllers for aircraft conductingvisual approaches to a single runway or multiple parallel runways, has been proposed based on input from SubjectMatter Experts as well as visual approach procedures and common practices. The goal is to maximize the thresholdswithin the guidance of the procedures and common practices and to minimize the number of nuisance alerts and totalnumber of alerts with the support of flight intent information. Tests have been performed using a recently developedprototype tactical separation assurance system for terminal airspace, called Terminal Tactical Separation-AssuredFlight Environment (T-TSAFE). The input was a full day of air traffic data from Dallas/Fort Worth (DFW) TRACONwith most arriving flights conducting visual approaches. The results compare favorably with those of the ConflictAlert (CA) functionality of the Standard Terminal Automation Replacement System (STARS).When fast-time simulation experiment was performed using T-TSAFE with all arriving flights assumed to conductinstrument approaches, the expected large number of separation alerts were observed. When compared with STARSCA, the conflict pairs common to both T-TSAFE and STARS CA was only 21% of the total STARS CA alerts. As aresult, the nuisance-alert rate for STARS CA was estimated to be about 70%, which is comparable to a similar previously estimation of 80% nuisance-alert rate for CARTS (Common Automated Radar Terminal System) CA. The Mode-CIntruder (MCI) alerts were also reduced by 76% as compared to STARS CA.Examination of the common conflict pairs between T-TSAFE and STARS CA shows that they are valid separationconflicts with good alert lead times for T-TSAFE. However, many of them would still be considered nuisance alertsif the aircraft were conducting visual approaches. This was confirmed by another visual approach fast-time simulationT-TSAFE experiment, in which all DFW arriving flights were assumed to be on visual approaches and our proposedsafety alert thresholds were used and tested. The result of the experiment showed that the number of non-MCI alertswas less by 92% as compared to the number when all DFW arrivals were assumed to be conducting instrumentapproaches. The common conflict pairs involving aircraft conducting visual approaches to parallel runways werereduced by 93% as well. Thus, the flight intent information and the safety alert thresholds are effective in reducingnuisance alerts.T-TSAFE can thus provide separation and safety conflict alerts seamlessly in the real-world environment of mixedterminal operations with arriving flights of both visual and instrument approaches. Compared with STARS CA, TTSAFEhas fewer false alerts, larger alert lead time, and larger alert thresholds. While the nuisance alerts are reducedsignificantly with the safety alert thresholds, further work is needed to study if the alert lead time for safety alerts issufficient.

Tang, Huabin

Assessment of Some IASMS-relevant Data Sources for Aviation Safety

An In-time Aviation Safety Management System (IASMS) [1,2] is a set of services, functions, and capabilities (SFCs) necessary for monitoring known hazards and emergent risks, assessing safety data for anomalies, precursors, and trends, mitigating hazards that reach safety thresholds, and assuring efficacy of controls in mitigating hazards. An IASMS will continually monitor the NAS to collect data on the status of aircraft, air traffic management systems, weather, and airports. Within the NASA Aeronautics Research Mission Directorate (ARMD) System-Wide Safety (SWS) project’s technical challenge called In-time Aviation Safety Management Systems (IASMS) for Commercial Aviation Operations, which we often refer to as Technical Challenge 6 (TC-6), we have performed an assessment of several aviation data sources we have found that are relevant to assessing the safety of the National Airspace System (NAS) in the context of an IASMS. This assessment includes understanding the nature of the data themselves and using some data analytics tools on these data to show how they can be used to identify potential safety issues. We also describe how the data and analytics are part of a system that can allow for other data and analytics to be performed and for the results to be visualized for use by appropriate operators to identify potential safety issues and develop mitigations. This report is a step toward the ultimate goal of TC-6, which is to develop a prototype IASMS system that demonstrates the potential of an IASMS and inspire operators to build analogous systems to make the best possible use of the significant investments that they make in collecting, storing, and managingdata related to their operations.

aviation safety

Extravehicular Activity on the Lunar Surface: Mapping Mitigation Risk Consequence for Crew Needing Assistance or Rescue

Extravehicular activity (EVA) on the lunar surface presents unique risks to crew with possibility for injury. Without appropriate assistance or rescue capability, inability to nominally ambulate and return to a lander, especially during early Artemis missions, could have catastrophic consequences. Mapping likelihood and consequence safety risk associated with identified injury scenarios establishes a baseline from which to assess potential mitigation solutions to ensure crew health and safety. Causes leading to the need for incapacitated crew rescue (ICR) during EVA on the lunar surface were previously identified and classified using an ICR/Acute Injury scenario spectrum. Severe scenarios are those when the affected astronaut requires either partial or full continuous assistance from the rescuer. Evaluation of these continual reliance conditions included calculating event probabilities (likelihoods) associated with an early Artemis mission and mapping them to established Exploration System Directorate (ESD) probability thresholds; safety consequences were analyzed and correlated to defined ESD personnel safety categories. These resulting likelihood and consequence values served as a baseline for assessing risk reduction of three mitigation capabilities: crew assistance (rescuer crew) only, walking assist devices, and a wheeled transport device. Of the twenty-five continual reliance conditions, ten were evaluated as “catastrophic” (Level 5, loss of life) during EVA on the lunar surface with probabilities ranging from moderate to very low during an early Artemis mission. Crew assistance only and walking assist devices showed similar potential for risk reduction, with four of the ten causes decreasing to Level 4. A wheeled transport device further increased risk reduction with six of the ten conditions decreasing to Level 4. Given the catastrophic consequence of several identified conditions, assessments should be performed to determine the feasibility of mitigation capabilities. It is currently unknown whether a rescuer astronaut could effectively provide continuous assistance to enable both crew to return safely to the lander from the standpoint of both suit geometry and human performance. Although resulting in an increase in resources, providing a wheeled transport provides the highest risk reduction potential, and walking assist devices may have prevention as well as mitigation benefits.

lunar surface

Probability of Obstacle Collision for UAVs in Presence of Wind

For incorporation of unmanned aerial vehicles into the National Airspace, ensuring safety of the airspace including the vehicles, people, and property on the ground is of utmost importance. One of the safety-critical factors for unmanned aviation flights is the risk of deviating from a planned trajectory resulting in a variety of hazards, including potential loss of separation between vehicle and obstacles or unexpected battery energy consumption. Off-nominal conditions introduced by component failures, degraded controllability and environmental disturbances such as wind gusts can lead to unacceptable unexpected deviations from the flight trajectory. It is essential to accurately model such effects on the flight trajectory while computing safety thresholds such as minimum separation from surrounding obstacles, available battery resource to complete the mission or determining delay in the expected time of arrival of flights. In this paper, a tool is presented based on Gaussian Process Regression for wind representation over a pre-defined trajectory for fast, yet approximated, in-time evaluation of possible trajectory deviations caused by wind gusts. The deviation in the planned trajectory caused by wind is further simulated utilizing a 6 degrees-of-freedom (DOF) UAV trajectory simulator comprising of a rotorcraft lumped-mass model with LQRI controller. Both steady-state wind and wind gust effects are investigated. The probability of collision with obstacle is computed and demonstrated on real flight data from experimental flights of an octocopter at NASA Langley Research Center in the presence of simulated obstacles and wind conditions. Effect of varying wind conditions and varying UAV airspeed is further demonstrated on experimental flights in the presence of wind measured by ground based weather service stations. The proposed approach would eventually benefit timely mitigation of current and future safety-critical events in autonomous systems by enabling risk-informed decision making.

Portia Banerjee

A Full-scale Demonstration of Pressurized Water Reactor Core Design Optimization using Multi-Cycle Optimization Methodology

The U.S. nuclear sector encounters a difficulty in upholding essential safety standards while also securing economic viability for continued operation. Safety stands as a pivotal factor across all facets of operations within light-water reactor nuclear power plants. Achieving economic feasibility alongside safety can be facilitated through the utilization of a risk-informed framework, exemplified by the ongoing development within the Risk-Informed Systems Analysis Pathway under the auspices of the U.S. Department of Energy's LWRS Program. This initiative advocates for a diverse array of research and development endeavors aimed at optimizing both safety and economic efficacy within nuclear power plants, particularly pertinent as many plants contemplate second license renewals. The Risk-Informed Systems Analysis Pathway has two main goals: deploy methodologies and technologies that better represent safety margins and cost and safety factors and develop advanced applications that enable cost-effective plant operation. This report assesses the potential for resolving multi-cycle plant reload challenges through real-world scenarios utilizing the Plant ReLoad Optimization (PRLO) framework. This framework offers reactor core design developers analytic tools of reactor safety and fuel performance with the assistance of artificial intelligence (AI) to enhance core design solutions. Multi-objective genetic algorithm alongside acceleration techniques is explored as an enabling technology for improving fuel efficiency while upholding safety thresholds. The demonstration of multi-cycle core design optimization is performed. This report investigates the practical application of the PRLO platform in addressing real-world core design challenges, supporting AI efforts, and contrasting outcomes with those derived from heuristic or conventional algorithms.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS

Exploration of Near-Term Potential Routes and Procedures for Urban Air Mobility

Urban air mobility is gaining interest as the need for On Demand Mobility in today's congested traffic is becoming high in metropolitan areas. Urban Air Mobility (UAM) is envisioned as a concept to transport passengers and cargo safely and efficiently using innovative aircraft in the urban areas. It is expected to improve mobility for the general public, decongest road traffic, reduce transport time and reduce the strain on existing public transport networks. There exist several challenges to Urban Air Mobility (UAM) such as integration of procedures with airspace and the airport, noise levels that are acceptable to the general public, public safety, public acceptance, vehicle certification, and more. Most of the research in the United States and European skies (DLR - German Aerospace Center) related to urban areas has focused on small UAS (Unmanned Aircraft Systems) flights (NASA's UTM (UAS Traffic Management) research) and their integration with the airspace and building safe operations in densely populated areas. Previous studies on UAM have focused on fast time simulations of the routes that are separated via a separation service and network of routes. Similarly, research in Europe has focused on the approach profile for these innovative aircraft, vertiports and battery life among others. UAM as a part of the On-Demand Mobility effort has provided some guidelines for operations as shown below: Does not require additional ATC (Air Traffic Control) infrastructure; Does not impose additional workload on ATC; Does not restrict operations of traditional airspace users; Will meet appropriate safety thresholds and requirements; Will prioritize operational scalability; Will allow flexibility where possible and structure where necessary. This paper explores potential routes and procedures in a Human-In-The-Loop (HITL) experiment that could be applied in the near-term to allow integration of UAM flights into the airspace as well as a large airport. The airspace that was explored was Dallas Fort Worth (DFW) airspace managed by the DFW East Tower in South Flow only. In addition, Dallas Love Field (DAL) and Addison (ADS) airspace were also part of the testbed. The initial set of routes investigated in this study were published helicopter routes in the DFW area. Figure 1 shows class B airspace in DFW area and the origin/destination city pairs where UAM flights flew along with helicopter routes shown in blue. The research focused on exploring procedures for integrating UAM flights into Class Bravo and Class Delta airspace. Three different communication procedures, evaluated with three different levels of UAM traffic, are shown in Table 1. The current day routes were evaluated with current day communication procedures were explored as the first condition. The current day routes were also evaluated in the second condition with reduced communications, which was assumed due to the presence of a Letter Of Agreement (LOA). The purpose of the LOA was to reduce the verbiage associated with pilots getting clearance to Class B airspace from the controllers, pre-assigning beacons codes to the UAM flights, separate routes by assigning altitudes and speeds to flights going in any one direction. Flights were expected to automatically change frequency when exiting Class B airspace, thus transition points for entry and exit points were also specified in the LOA.

Urban Air Mobility

Deep Learning-Based Negotiation Strategy Selection for Cooperative Conflict Resolution in Urban Air Mobility

This paper presents a collaborative conflict resolution technique using deep neural network-based intelligent search of the solution space. This approach offers a rapid convergence to a mutually acceptable solution for real-time conflict resolution, suitable for urban air mobility operations. Furthermore, the presented technique allows operational flexibility to the urban air mobility agents where these agents can collaboratively devise the solution via integrative negotiation, based on their local utility functions, as long as such a solution does not violate the global safety thresholds. The presented machine-to-machine negotiation method is built on our prior work on holistic assessment of the airspace and potential conflict detection implemented at-the-edge, onboard the unmanned aircraft systems. This paper extends the prior work to augment decision-making at-the-edge, thereby, promising a true distributed control architecture for urban air mobility. In this approach, each agent (a) builds a potential in-flight conflict map, (b) identifies the conflicting agents, (c) dynamically prepares a list of alternatives based on its current utility functions, (d) negotiates with the conflicting agents to pick one of these alternatives, and (e) implements the negotiated alternative to mutually resolve the conflict. Note that such an approach does not require a contingency plan to be made pre-flight, as the conflict resolution strategies are decided and negotiated in real time based on the present state of the agent. The contingency plan, if available, can serve as an input to the real-time conflict resolution strategy formulation, and also can be used as a fallback plan in case the negotiation fails and the impacted agents need to switch to a rule-based/supervisory resolution mode from the discussed distributed resolution mode. The presented collaborative negotiation-based conflict resolution technique incorporates a time-dependent reward function to catalyze collaborative resolution by incentivizing the agents with local and global rewards beneficial to their business operations.

Advanced Air Mobility

MSL Telecom Automated Anomaly Detection

The Mars Science Laboratory (MSL) Telecom Operations Team at the Jet Propulsion Laboratory (JPL) has implemented a machine learning system in order to automate the anomaly detection process as a part of daily operations. Machine learning enables reliable detection of anomalies in Telecom-related telemetry and automated reporting of Telecom subsystem status, resulting in an 90% reduction in team workload and improved anomaly detection reliability. At present, machine learning methods are used to detect: 1. Anomalous long-term trends in telemetry data 2. Anomalous time-domain evolution of telemetry values Both types of anomalies pose their own unique challenges that are addressed in different ways. In the first case, long term trending of daily minima, maximum, and mean telemetry values in temperatures, currents, voltages, and radio frequency (RF) power levels is used in addition to hard threshold safety checks to look for changes in long-term equipment health and performance. Long-term trending methods allow for ordinary seasonal variations in these quantities caused by temperature changes over the course of the Martian year while allowing operators to determine whether current performance remains in line with historical values from previous years. Changes in long-term trends can provide important insights into the health and status of the rover's on-board systems as well as valuable early warning if subtle degradation begins to take hold. But while trending of daily statistics is valuable, it does not detect anomalies in the short-term time evolution of data over the course of minutes or hours during a day, and this task is handled with short-term shape analysis. Principal components analysis (PCA) has been found to provide robust detection of short-term anomalies, and several examples of the use of PCA to detect actual anomalous events will be provided here. In using PCA, we use both the percentage of explained variance and also a log likelihood test on the PCA expansion coefficients to flag telemetry data for human review. Previous work in the field of spacecraft anomaly detection includes [1] for MSL and [2] for some other JPL missions.

Mukai, Ryan

Space station crew safety: Human factors interaction model

A model of the various human factors issues and interactions that might affect crew safety is developed. The first step addressed systematically the central question: How is this space station different from all other spacecraft? A wide range of possible issue was identified and researched. Five major topics of human factors issues that interacted with crew safety resulted: Protocols, Critical Habitability, Work Related Issues, Crew Incapacitation and Personal Choice. Second, an interaction model was developed that would show some degree of cause and effect between objective environmental or operational conditions and the creation of potential safety hazards. The intermediary steps between these two extremes of causality were the effects on human performance and the results of degraded performance. The model contains three milestones: stressor, human performance (degraded) and safety hazard threshold. Between these milestones are two countermeasure intervention points. The first opportunity for intervention is the countermeasure against stress. If this countermeasure fails, performance degrades. The second opportunity for intervention is the countermeasure against error. If this second countermeasure fails, the threshold of a potential safety hazard may be crossed.

Cohen, M. M.

Space Station crew safety - Human factors model

A model of the various human factors issues and interactions that might affect crew safety is developed. The first step addressed systematically the central question: How is this Space Station different from all other spacecraft? A wide range of possible issue was identified and researched. Five major topics of human factors issues that interacted with crew safety resulted: Protocols, Critical Habitability, Work Related Issues, Crew Incapacitation and Personal Choice. Second, an interaction model was developed that would show some degree of cause and effect between objective environmental or operational conditions and the creation of potential safety hazards. The intermediary steps between these two extremes of causality were the effects on human performance and the results of degraded performance. The model contains three milestones: stressor, human performance (degraded) and safety hazard threshold. Between these milestones are two countermeasure intervention points. The first opportunity for intervention is the countermeasure against stress. If this countermeasure fails, performance degrades. The second opportunity for intervention is the countermeasure against error. If this second countermeasure fails, the threshold of a potential safety hazard may be crossed.

Cohen, M. M.