Murphi busts an altitude: a Murphi analysis of an automation surprise

E. Palmer
{"title":"Murphi busts an altitude: a Murphi analysis of an automation surprise","authors":"E. Palmer","doi":"10.1109/DASC.1999.863726","DOIUrl":null,"url":null,"abstract":"In training and during operations, users of automatic systems form expectations of how automatic systems respond to their control inputs and to environmental disturbances. These expectations form the basis for what can called the operator's \"mental model\" of the system. An \"automation surprise\" is said to occur when the automation behaves in a manner different from what the operator expects. A requirement for a properly functioning human-machine system is that the human operator have good situation awareness. A key component of an operator's situation awareness is knowing how the machine will behave in the near future. Automation surprises are situations in which this system requirement has failed. In this paper, the modeling language-Murphi-is used to model and analyze an automation surprise in which a flight crew, using the autopilot, climbs above their cleared altitude during a full mission flight simulation. Murphi is a system description language and model checker developed by software engineers to formally evaluate behavioral requirements for concurrent software processes A rule-based model of the autopilot system and the pilot was developed. Murphi was then used to automatically check the validity of the above requirement for a model of the pilot-autopilot-aircraft system. The requirement failed for the same sequence of human and machine events that were recorded in the altitude bust incident. The Murphi model was then modified to explore possible procedural and mode logic fixes to reduce the likelihood of this type of breakdown in the human-machine system.","PeriodicalId":269139,"journal":{"name":"Gateway to the New Millennium. 18th Digital Avionics Systems Conference. Proceedings (Cat. No.99CH37033)","volume":"18 3 Suppl 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"1999-10-24","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"9","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Gateway to the New Millennium. 18th Digital Avionics Systems Conference. Proceedings (Cat. No.99CH37033)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/DASC.1999.863726","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 9

Abstract

In training and during operations, users of automatic systems form expectations of how automatic systems respond to their control inputs and to environmental disturbances. These expectations form the basis for what can called the operator's "mental model" of the system. An "automation surprise" is said to occur when the automation behaves in a manner different from what the operator expects. A requirement for a properly functioning human-machine system is that the human operator have good situation awareness. A key component of an operator's situation awareness is knowing how the machine will behave in the near future. Automation surprises are situations in which this system requirement has failed. In this paper, the modeling language-Murphi-is used to model and analyze an automation surprise in which a flight crew, using the autopilot, climbs above their cleared altitude during a full mission flight simulation. Murphi is a system description language and model checker developed by software engineers to formally evaluate behavioral requirements for concurrent software processes A rule-based model of the autopilot system and the pilot was developed. Murphi was then used to automatically check the validity of the above requirement for a model of the pilot-autopilot-aircraft system. The requirement failed for the same sequence of human and machine events that were recorded in the altitude bust incident. The Murphi model was then modified to explore possible procedural and mode logic fixes to reduce the likelihood of this type of breakdown in the human-machine system.
墨菲打破了一个高度:对自动化意外的墨菲分析
在培训和操作期间,自动系统的用户形成了对自动系统如何响应其控制输入和环境干扰的期望。这些期望构成了操作员对系统的“心智模型”的基础。所谓的“自动化意外”是指当自动化的行为方式与操作人员的预期不同时发生的。一个正常运行的人机系统的要求是人类操作员具有良好的态势感知能力。操作员的情况意识的一个关键组成部分是知道机器在不久的将来会如何表现。自动化意外是系统需求失败的情况。本文采用建模语言murphy对全任务飞行仿真中机组人员使用自动驾驶仪爬升到允许高度以上的自动化意外事件进行建模和分析。Murphi是由软件工程师开发的一种系统描述语言和模型检查器,用于形式化地评估并发软件过程的行为需求。然后使用Murphi来自动检查上述要求对驾驶员-自动驾驶-飞机系统模型的有效性。在高空爆炸事件中记录的人类和机器事件的相同序列的要求失败了。然后修改了Murphi模型,以探索可能的程序和模式逻辑修复,以减少人机系统中这种类型故障的可能性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信