Search NASA⌕ Search

SEARCH · Search NASA

Results for “trusted design”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Reliable Design Versus Trust

This presentation focuses on reliability and trust for the users portion of the FPGA design flow. It is assumed that the manufacturer prior to hand-off to the user tests FPGA internal components. The objective is to present the challenges of creating reliable and trusted designs. The following will be addressed: What makes a design vulnerable to functional flaws (reliability) or attackers (trust)? What are the challenges for verifying a reliable design versus a trusted design?

Field Programmable Gate Aray (FPGA)↗

Human Capabilities Assessments for Autonomous Missions: A Multi-Team Research Effort to Reduce Risk in the Human-System Integration Architecture for Future Deep-Space Missions

In future exploration missions beyond low earth-orbit, crew will have to execute complex operations and respond to off-nominal events, without real-time support from Mission Control. It is anticipated that increased reliance on automated systems, including human-centric vehicle and information architecture, will need to be designed to support the crew; increased risk to performance, health, and safety may occur if these are not implemented appropriately. The Human Factors and Behavioral Performance Element (HFBP) in the NASA Human Research Program supports research to characterize and mitigate such human health and performance risks, including the Risk of Adverse Outcome Due to Inadequate Human Systems Integration Architecture (HSIA). The HSIA risk addresses the integration of onboard capability and the crew roles and responsibilities necessary to enable the crew to respond effectively and efficiently in the increasingly autonomous mission operations environment. In 2017, HFBP released the “Human Capabilities Assessments for Autonomous Missions” (HCAAM) research topic to address HSIA related questions. HCAAM is a major NASA research effort that has assembled a multidisciplinary team from seven institutions to work closely with design and engineering efforts on research towards developing and refining human performance standards, guidelines and automation tools. The scientific focus is on quantitative assessment of human capabilities relevant to future deep-space missions during which earth/spacecraft communication is so delayed and intermittent that the crew must be able to function autonomously. The integrated strategy of the HCAAM project characterizes human capabilities and limitations related to potential performance decrements during long duration exploration mission spaceflight as relevant to both routine and complex task performance; defines system characteristics that reduce the likelihood or impact of potential decrements in human performance capabilities; performs integrated assessment of intelligent system responses within the context of an operational environment with relevant NASA tools, systems, and data structures in order to determine positive or negative interactions and validate recommended approaches; and proposes specific updates to existing standards and guidelines for inclusion in NASA handbooks for the design of future spacecraft intelligent systems that provide crew performance assessment/feedback, and to also serve as decision-support aids for the onboard crew (i.e., NASA-STD-3001, and NASA/SP-Human Integration Design Handbook (HIDH)). The scientific research vectors being addressed by the seven HCAAM teams include: - crew task performance (accuracy, efficiency) (crew + automation) - crew performance (accuracy, efficiency) - crew Situation Awareness - procedure design and multi-modal enhancement - concurrent tasking (mixed manual + some level of autonomy) - task handover - crew self-planning and time-lining - task design - trust in automation, real-time calibration - human multi-sensory feedback and guidance - human trust in on-board software-based intelligent assistants - virtual assistants The presentation will highlight plans and progress made in each of these research areas as well as the methods by which surrogate astronaut crews in the NASA JSC HERA spaceflight analog facility will function as human test subjects for all of the HCAAM research projects.

HCAAM VNSCOR↗

The Design and Evaluation of Zero Trust Architecture for Electric Vehicle Charging Infrastructure: EVs @ Scale Series on EV Charging Station Cybersecurity

Implementing a zero trust architecture can significantly bolster the security of electric vehicle (EV) charging infrastructure. EV charging infrastructure includes numerous networked interfaces, each of which can present potential vulnerabilities. When these vulnerabilities are exploited, they can compromise the entire system, leading to severe operational and security risks. Zero trust is a security model that operates on the principle of "never trust, always verify," which helps manage the attack surface and limit the scope of any potential compromises. Fundamentally, this model ensures that no entity, whether inside or outside the network, is trusted by default. The design principles of zero trust include continuous verification, strict deny-by-default access controls, and micro-segmentation. Continuous verification ensures that every request is thoroughly checked, regardless of its origin. Strict access controls enforce the principle of least privilege, allowing users and devices only the minimum necessary access to perform their functions. Micro-segmentation involves dividing the network into smaller, isolated segments to prevent lateral movement in case of a breach. In the context of EV charging infrastructure, zero trust can be implemented through various strategies. For example, multi-factor authentication (MFA) can be required for engineers to access the management interfaces and control systems of charging stations. Real-time monitoring and analysis of network traffic can help detect and respond to anomalies. Systems that do not need to communicate with each other can be micro-segmented to enhance security. All communications should adhere to predefined policies to be permitted. Additionally, encrypting communications can protect sensitive information exchanged between chargers and management systems. This paper presents a zero trust architecture specifically designed for EV charging infrastructure. Implementing zero trust not only mitigates risks but also builds a resilient infrastructure capable of withstanding and quickly recovering from cyber threats. The architecture addresses six defined security objectives. A comprehensive test plan is developed to assess the architecture against these objectives, and the results of the evaluation are reported. This approach is essential for maintaining the reliability and integrity of EV charging services in an increasingly interconnected and vulnerable digital landscape. This is the first in a planned series of papers exploring the implementation of zero trust in EV charging infrastructure. Each paper will delve into different aspects and applications of zero trust, highlighting how various work processes and requirements can lead to distinct architectural designs. These architectures will be tailored to address specific security challenges and operational needs within the EV charging ecosystem, ensuring a robust and adaptable security framework.

33 ADVANCED PROPULSION SYSTEMS↗

Designing and Training for Appropriate Trust in Increasingly Autonomous Advanced Air Mobility Operations: A Mental Model Approach: Version 1

To enable effective human-autonomy teaming (HAT) in Advanced Air Mobility (AAM) operations, the current paper presents a theoretical framework to design and train for appropriate trust in automation. The novel contribution of this work resides in connecting the construct of trust to mental models and showing how this method could be used to enable emerging HAT concepts such as Adaptive Trust Calibration. To contextualize this framework, in section 2 we discuss simplified vehicle operations (SVO) and remote vehicle operations (RVO), which are leading operational concepts within AAM. In section 3 we describe our perspective on automation and increasingly autonomous systems and present a brief discussion on human-automation interaction and human-autonomy teaming. In section 4 we provide a detailed discussion on the construct of trust in automation. In section 5 we present a framework that associates mental models with trust through principles of transparent design. Finally, in section 6 we present three descriptive models for designing and training for appropriate trust in increasingly autonomous systems.

Human-Autonomy Teaming↗

"Glitch Logic" and Applications to Computing and Information Security

This paper introduces a new method of information processing in digital systems, and discusses its potential benefits to computing and information security. The new method exploits glitches caused by delays in logic circuits for carrying and processing information. Glitch processing is hidden to conventional logic analyses and undetectable by traditional reverse engineering techniques. It enables the creation of new logic design methods that allow for an additional controllable "glitch logic" processing layer embedded into a conventional synchronous digital circuits as a hidden/covert information flow channel. The combination of synchronous logic with specific glitch logic design acting as an additional computing channel reduces the number of equivalent logic designs resulting from synthesis, thus implicitly reducing the possibility of modification and/or tampering with the design. The hidden information channel produced by the glitch logic can be used: 1) for covert computing/communication, 2) to prevent reverse engineering, tampering, and alteration of design, and 3) to act as a channel for information infiltration/exfiltration and propagation of viruses/spyware/Trojan horses.

hardware vulnerabilities↗

ATS-6 - Television Relay Using Small Terminals Experiment

The Television Relay Using Small Terminals (TRUST) Experiment was designed to advance and promote the technology of broadcasting satellites. A constant envelope television FM signal was transmitted at C band to the ATS-6 earth coverage horn and retransmitted at 860 MHz through the 9-m antenna to a low-cost direct-readout ground station. The experiment demonstrated that high-quality television and audio can be received by low-cost direct-receive ground stations. Predetection bandwidths significantly less than predicted by Carson's rule can be utilized with minimal degradation of either monochrome or color pictures. Two separate techniques of dual audio channel transmission have been demonstrated to be suitable for low-cost applications.

Miller, J. E.↗

Designing a Comprehensive IDS Strategy for a Zero Trust Architecture Environment

Zero Trust Architecture or ZTA is a cybersecurity model for enterprises to structure their networked resources around to maintain total security externally and internally. In a Zero Trust environment, no part of the network is considered "trustworthy" and thus should be scrutinized and monitored extensively as is done in traditional "Trust But Verify" schemes at the network's perimeter. In this way, Zero Trust Architecture is a superior model for securing access to networked resources at the enterprise level. Fermilab, in pursuit of a better security posture, has decided to embrace this model of architecture for its network. Attaining this goal requires tremendous infrastructural, policy, and procedural adjustments that will affect all the lab's personnel and resources.

D'Antonio, Lucas↗

Trustworthiness and Trust: Identifying Factors that Drive Successful Human-AI Interaction in Nuclear Power Plant Applications

Emerging technologies such as artificial intelligence (AI) and machine learning (ML) are rapidly evolving and considered a promising tool for efficient and continued safe operations of the U.S. nuclear power plants (NPPs). Emerging AI techniques like large language models (LLMs) are one such technology that may support personnel at existing NPPs perform work more efficiently. For example, operators may query the current operational status of a power plant via a chat interface leveraging LLMs to access plant-related information in an interactive manner rather than manually collecting various sensor data for tasks such as surveillances or completing work orders. This is a fundamental shift in the way operators currently perform their tasks today. The literature of human-automation interaction indicates that trust is a crucial factor that drives successful interaction between a human operator and an automated system, like an AI-infused NPP application. This work presents the results of a literature review on key factors that relate to trust in AI/LLM technologies for NPP applications. The relevant literature of human factors and cognitive engineering has identified various factors related to trust including trustworthiness, performance characteristics, operator skill and perceived risk. This preliminary literature review will guide development and evaluation of models involving the identified factors influencing trust in AI and develop a framework for human-centered design for interface between humans and AI. By addressing trust, this work supports developing a technical basis for designing key characteristics of AI/LLM to support calibrated trust, which will ultimately support wide-scale adoption of AI/LLM technologies, as well as ensure safe, effective, and reliable use.

99 - GENERAL AND MISCELLANEOUS↗

CAHS: Context-Aware Homology Search

Protein homology search is foundational to bioinformatics: it supports annotation transfer, structure/function inference, and evolutionary analysis over rapidly expanding sequence repositories (e.g., UniProtKB). Profile hidden Markov models (pHMMs), as implemented in HMMER, remain the most widely trusted approach because they provide statistically calibrated E-values; however, their gap behavior is fixed once a profile is trained, despite biological evidence that insertion/deletion tolerance varies across flexible loops and intrinsically disordered regions. We present CAHS (Context-Aware Homology Search), a lightweight query-time adapter for pHMM search that incorporates learned and biologically motivated signals without changing HMMER's downstream search pipeline or its calibrated E-value reporting. Given a query sequence, CAHS computes per-residue representations from a protein language model and a disorder predictor, maps these to profile coordinates, and modulates only match-state transition rows (gap-open and gap-extension probabilities) while preserving Plan7 constraints. We comprehensively evaluate CAHS across six structurally diverse protein families and multi-domain architectures against a 570k-sequence target corpus. CAHS expands detection capability, retrieving thousands of additional remote homologs at relaxed thresholds by maintaining alignment quality through flexible regions. For multi-domain proteins, context-aware modulation resolves 94% of fragmented alignments. Crucially, CAHS preserves hit-set invariance at stringent operating points (E<10-10), demonstrating increased statistical confidence without inflating false positives. Furthermore, sharper statistical distinction between homologs and background noise during early filter stages yields up to a 3.87× acceleration in end-to-end wall-clock time on high-performance computing clusters. Overall, CAHS illustrates a practical AI-for-science design pattern: augmenting a trusted probabilistic model with query-specific learned signals to improve interpretable, reproducible inference in data-rich biology.

Bhattaram, Swethasree [Georgia Institute of Techno↗

Adaptive Sampling-Based Bi-Fidelity Stochastic Trust Region Method for Stochastic Derivative-Free Optimization

Bi-fidelity stochastic optimization has gained increasing attention as an efficient approach to reduce computational costs by leveraging a low-fidelity (LF) model to optimize an expensive high-fidelity (HF) objective. In this paper, we propose ASTRO-BFDF, an adaptive sampling trust-region method specifically designed for unconstrained bi-fidelity stochastic derivative-free optimization problems. In ASTRO-BFDF, the LF function serves two purposes: (i) to identify better iterates for the HF function when the optimization process indicates a high correlation between them and (ii) to reduce the variance of the HF function estimates using bi-fidelity Monte Carlo (BFMC). The algorithm dynamically determines sample sizes while adaptively choosing between crude Monte Carlo and BFMC to balance the trade-off between optimization and sampling errors. We prove that the iterates generated by ASTRO-BFDF converge to a first-order stationary point almost surely. Additionally, we demonstrate the effectiveness of the proposed algorithm through numerical experiments on synthetic benchmarks and simulation optimization problems involving discrete event systems.

97 MATHEMATICS AND COMPUTING↗

LC-Opt: Benchmarking Reinforcement Learning and Agentic AI for End-to-End Liquid Cooling Optimization in Data Centers

Liquid cooling is critical for thermal management in high-density data centers with the rising AI workloads. However, machine learning-based controllers are essential to unlock greater energy efficiency and reliability, promoting sustainability. We present LC-Opt, a Sustainable Liquid Cooling (LC) benchmark environment, for reinforcement learning (RL) control strategies in energy-efficient liquid cooling of high-performance computing (HPC) systems. Built on the baseline of a high-fidelity digital twin of Oak Ridge National Lab's Frontier Supercomputer cooling system, LC-Opt provides detailed Modelica-based end-to-end models spanning site-level cooling towers to data center cabinets and server blade groups. RL agents optimize critical thermal controls like liquid supply temperature, flow rate, and granular valve actuation at the IT cabinet level, as well as cooling tower (CT) setpoints through a Gymnasium interface, with dynamic changes in workloads. This environment creates a multi-objective real-time optimization challenge balancing local thermal regulation and global energy efficiency, and also supports additional components like a heat recovery unit (HRU). We benchmark centralized and decentralized multi-agent RL approaches, demonstrate policy distillation into decision and regression trees for interpretable control, and explore LLM-based methods that explain control actions in natural language through an agentic mesh architecture designed to foster user trust and simplify system management. LC-Opt democratizes access to detailed, customizable liquid cooling models, enabling the ML community, operators, and vendors to develop sustainable data center liquid cooling control solutions.

Naug, Avisek [Hewlett Packard Enterprise]↗

A Distributed Simulation-to-Flight Framework to Support Investigating Trust/Trustworthiness in Multi-Agent Systems

As autonomous systems continue to grow both in use and complexity, the necessity for robust and extensible simulation-to-flight methods is paramount for establishing an effective architecture for autonomous systems. A fundamental objective of the ATTRACTOR (Autonomy Teaming and TRAjectories for Complex Trusted Operational Reliability) project was to design and develop a distributed mixed-reality simulation environment to begin establishing a basis for certification of autonomous systems via research into trust and trustworthiness. In this paper, we present an autonomous systems architecture and development framework paired with a persistent distributed modeling and simulation environment for test and evaluation of autonomous systems. The Autonomous Entity Operations Network (AEON) framework enables autonomous system development with an easily extensible collection of libraries and plug-n-play nodes facilitated by the Data Distribution Service (DDS) communication protocol standard. The Baseline Environment for Autonomous Modeling (BEAM) simulation environment is a distributed mixed-reality Unity™-based environment built around the same DDS communication paradigm allowing for easy integration with AEON-based autonomous applications. They were designed under ATTRACTOR in order to measure and establish trustworthiness and trust in single- and multi-agent human-machine systems whether these machines are fixed-wing general aviation, rotary-wing Unmanned Aerial Vehicles (UAVs), ground rovers, or even spacecraft. Together AEON and BEAM enable sim-to-flight with minimal configuration changes. By using AEON and BEAM, source code that runs in simulation ports directly to hardware and has successfully flown in the lab and in the National Airspace System (NAS) at NASA LaRC many times over the lifetime of ATTRACTOR.

Benjamin N Kelley↗

A Distributed Simulation-to-Flight Framework to Support Investigating Trust/Trustworthiness in Multi-Agent Systems

As autonomous systems continue to grow both in use and complexity, the necessity for robust and extensible simulation-to-flight methods is paramount for establishing an effective architecture for autonomous systems. A fundamental objective of the ATTRACTOR (Autonomy Teaming and TRAjectories for Complex Trusted Operational Reliability) project was to design and develop a distributed mixed-reality simulation environment to begin establishing a basis for certification of autonomous systems via research into trust and trustworthiness. In this paper, we present an autonomous systems architecture and development framework paired with a persistent distributed modeling and simulation environment for test and evaluation of autonomous systems. The Autonomous Entity Operations Network (AEON) framework enables autonomous system development with an easily extensible collection of libraries and plug-n-play nodes facilitated by the Data Distribution Service (DDS) communication protocol standard. The Baseline Environment for Autonomous Modeling (BEAM) simulation environment is a distributed mixed-reality Unity™-based environment built around the same DDS communication paradigm allowing for easy integration with AEON-based autonomous applications. They were designed under ATTRACTOR in order to measure and establish trustworthiness and trust in single- and multi-agent human-machine systems whether these machines are fixed-wing general aviation, rotary-wing Unmanned Aerial Vehicles (UAVs), ground rovers, or even spacecraft. Together AEON and BEAM enable sim-to-flight with minimal configuration changes. By using AEON and BEAM, source code that runs in simulation ports directly to hardware and has successfully flown in the lab and in the National Airspace System (NAS) at NASA LaRC many times over the lifetime of ATTRACTOR.

Benjamin N Kelley↗

A Distributed Simulation-to-Flight Framework to Support Investigating Trust/Trustworthiness in Multi-Agent Systems

As autonomous systems continue to grow both in use and complexity, the necessity for robust and extensible simulation-to-flight frameworks is paramount for establishing an effective architecture for autonomous systems. Hardware test flights are time-consuming and cost prohibitive during early system design and development. Simulation environments can be useful tools to accelerate algorithm development and testing. However, transitions from simulation to flight (sim-to-flight) can be challenging, unless systems are designed with this transition in mind and with the necessary capabilities built into the architecture and framework. One of the objectives of Autonomy Teaming and TRAjectories for Complex Trusted Operational Reliability (ATTRACTOR) was to design and develop a distributed mixed-reality simulation environment to begin establishing a basis for certification of autonomous systems via research into trust and trustworthiness. ATTRACTOR’s objective was to construct computational concepts of trustworthiness and justifiable trust in multi-agent autonomous teams, to inform future certification of safety-critical and time-critical autonomous systems in aviation. In this paper, we present an autonomous systems architecture and development framework paired with a persistent distributed modeling and simulation (ModSim) environment for test and evaluation of autonomous systems. They were designed under ATTRACTOR in order to measure and establish trustworthiness and trust in single-and multi-agent human-machine systems whether these machines are fixed-wing general aviation, rotary-wing Unmanned Aerial Vehicles (UAVs), ground rovers, or even spacecraft. The Autonomous Entity Operational Network (AEON) framework enables autonomous system development with an easily extensible collection of libraries and plug-n-play nodes facilitated by the Data Distribution Service (DDS) communication protocol standard. The Baseline Environment for Autonomous Modeling (BEAM) simulation environment is a distributed mixed-reality Unity™-based environment built around the same DDS communication paradigm allowing for easy integration with AEON-based autonomous applications, enabling sim-to-flight with minimal configuration changes. Using AEON and BEAM, source code that runs in simulation ports directly to hardware and has successfully flown in the National Airspace System (NAS) at NASA LaRC many times over the lifetime of ATTRACTOR.

Benjamin N Kelley↗

Experimental Study of Collision Detection Schema Used by Pilots During Closely Spaced Parallel Approaches

An experimental flight simulator study was conducted to examine the mental alerting logic and thresholds used by subjects to issue an alert and execute an avoidance maneuver. Subjects flew a series of autopilot landing approaches with traffic on a closely-spaced parallel approach; during some runs, the traffic would deviate towards the subject and the subject was to indicate the point when they recognized the potential traffic conflict, and then indicate a direction of flight for an avoidance maneuver. A variety of subjects, including graduate students, general aviation pilots and airline pilots, were tested. Five traffic displays were evaluated, with a moving map TCAS-type traffic display as a baseline. A side-task created both high and low workload situations. Subjects appeared to use the lateral deviation of the intruder aircraft from its approach path as the criteria for an alert regardless of the display available. However, with displays showing heading and/or trend information, their alerting thresholds were significantly lowered. This type of range-only schema still resulted in many near misses, as a high convergence rate was often established by the time of the subject's alert. Therefore, the properties of the intruder's trajectory had the greatest effect on the resultant near miss rate; no display system reliably caused alerts timely enough for certain collision avoidance. Subjects' performance dropped significantly on a side-task while they analyzed the need for an alert, showing alert generation can be a high workload situation at critical times. No variation was found between subjects with and with out piloting experience. These results suggest the design of automatic alerting systems should take into account the range-type alerting schema used by the human, such that the rationale for the automatic alert should be obvious to, and trusted by, the operator. Although careful display design may help generate pilot/automation trust, issues such as user non-conformance to automatically generated commands can remain a possibility.

Pritchett, Amy R.↗

Computational Models of Trustworthiness and Trust in Autonomous Cyber-Physical-Human Systems

In this paper, we propose an approach to developing a concept of actionable trust in multi-agent,cyber-physical-human systems in safety-critical and time-critical environment of air transportation. Actionable trust requires computational models of trustworthiness and trust, for use during system design and in real time, during operations. We describe the models, examine their computability and scalability, as well as what remains to be done.

Autonomous Systems↗