Earlier this month, the FAA's Micro Unmanned Aircraft Systems Aviation Rulemaking Committee (ARC) issued its recommendations in a final report: http://www.faa.gov/uas/publications/media/Micro-UAS-ARC-FINAL-Report.pdf
The recommendations include classifying UAVs (drones) into four categories, based on the risk that they pose to people underneath them. If the UAV fails, it will crash and could cause a serious injury.
If the mass of the UAV is less than or equal to 250 grams, then it would be in Category 1, which would have no additional restrictions (beyond those already in place).
UAVs more likely to cause a serious injury would face more restrictions. For instance, Category 2 UAVs "must maintain minimum set-off distances of 20 feet above people’s heads, or 10 feet laterally away from people, and may not operate so close to people as to create an undue hazard to those people." Category 3 UAVs would not be allowed to fly over crowds or dense concentrations of people. A Category 4 UAV, on the other hand, could do that if it complied with a documented, risk mitigation plan.
There are many interesting details about the ARC, its risk attitude, how the ARC developed its recommendations, and other factors. In particular, the ARC did not consider the likelihood of a UAV failure or the likelihood that it would hit someone if it failed; it considered only the distribution of the consequence (the chance of a serious injury) if it hit someone: "Specifically, the ARC recommends that a small UAS be permitted to conduct limited operations over people ... if that UAS presents a 30% or lower chance of causing [a serious] injury upon impact with a person."
Tuesday, April 19, 2016
Thursday, March 31, 2016
Fixing the Roof
Strong winds earlier this week in Maryland led us into two related but very different decisions.
I came home Monday afternoon to discover shingles lying next to the front door and hanging in the trees in the front yard of our house. That was unusual, and I was further surprised to learn that they came from our roof! The wind had lifted dozens from the roof on the back half of our house and blown them over the front.
After viewing the damage from the ground and reading that the weather forecast included more high winds and thunderstorms this week, we hurried to find and hire someone to repair the roof quickly.
Due to the extreme time pressure, this chaotic context (Snowden and Boone, 2007) forced us to find something that works and reestablish order (an adequate roof). We quickly searched online resources, asked friends for references, and even opened the yellow pages (we still had one from 2010) to get a list of roofers, and we called around until we had a few lined up to call back or inspect it the next morning (that took seven phone calls). Some of those who called back said that they didn't do repairs, so they were out. The first roofer who actually showed up, looked at the roof, and gave us a price got the job. It was a pure satisficing strategy - we picked the first adequate alternative. (It was quick: one roofer called later that morning and was surprised that we had already selected someone.) We had a fixed roof later that day, and we could sleep better that night.
That was the first decision. We now face a second decision: to select someone to do a roof replacement (the current roof is over 20 years old, and the shingle incident this week is a precursor to more significant problems in the future). This decision has a complicated context in which we have to get more information about the state of the roof from experts, reconcile their opinions, investigate the firms, make tradeoffs, and finally pick one.
One roof, two decisions. Both have the same problem (pick the best roofer), but the contexts, relevant attributes, and decision-making processes are very different.
Reference cited: Snowden, David J., and Mary E. Boone, “A Leader's Framework for Decision Making,” Harvard Business Review, Vol. 85, Issue 11, pages 69-76, November 2007.
I came home Monday afternoon to discover shingles lying next to the front door and hanging in the trees in the front yard of our house. That was unusual, and I was further surprised to learn that they came from our roof! The wind had lifted dozens from the roof on the back half of our house and blown them over the front.
After viewing the damage from the ground and reading that the weather forecast included more high winds and thunderstorms this week, we hurried to find and hire someone to repair the roof quickly.
Due to the extreme time pressure, this chaotic context (Snowden and Boone, 2007) forced us to find something that works and reestablish order (an adequate roof). We quickly searched online resources, asked friends for references, and even opened the yellow pages (we still had one from 2010) to get a list of roofers, and we called around until we had a few lined up to call back or inspect it the next morning (that took seven phone calls). Some of those who called back said that they didn't do repairs, so they were out. The first roofer who actually showed up, looked at the roof, and gave us a price got the job. It was a pure satisficing strategy - we picked the first adequate alternative. (It was quick: one roofer called later that morning and was surprised that we had already selected someone.) We had a fixed roof later that day, and we could sleep better that night.
That was the first decision. We now face a second decision: to select someone to do a roof replacement (the current roof is over 20 years old, and the shingle incident this week is a precursor to more significant problems in the future). This decision has a complicated context in which we have to get more information about the state of the roof from experts, reconcile their opinions, investigate the firms, make tradeoffs, and finally pick one.
One roof, two decisions. Both have the same problem (pick the best roofer), but the contexts, relevant attributes, and decision-making processes are very different.
Reference cited: Snowden, David J., and Mary E. Boone, “A Leader's Framework for Decision Making,” Harvard Business Review, Vol. 85, Issue 11, pages 69-76, November 2007.
Tuesday, January 26, 2016
Preparing for Disasters
The blizzard last weekend provided plenty examples of risk management: people in the path of the storm bought food and batteries, refueled their cars and trucks, and got ready to spend some time at home.
One cannot prevent a natural disaster, but one can try to prevent some of the potential problems that it could cause. In New York City, the preparations included a sufficiently large force to clear streets (4,600 workers and more than 2,000 pieces of equipment, according to The Washington Post) and specific actions just before the storm (closing the transit system, which prevented buses from getting stuck in the snow and blocking snowplows).
On the other side of the country, officials are making contingency plans for a much worse disaster: an earthquake and tsunami in the Pacific Northwest that could kill thousands, leave many homeless, and disrupt the economy. Oregon’s response plan, called the Cascadia Playbook, describes the system for moving personnel, equipment, and supplies into the area after the disaster and setting up medical facilities and shelters for the homeless.
In both cases, officials have used previous failures to make better plans. In the 2010 Snowmageddon storms, the New York transit system stayed open, which led to stranded buses; this time they closed it. The 2011 Japanese tsunami gave planners in the Pacific Northwest the opportunity to consider more accurately what would be needed.
Links:
Story about Washington, D.C., and New York City:
https://www.washingtonpost.com/local/after-a-wild-winter-weekend-a-difficult-commute-awaits/2016/01/24/3c987ebe-c302-11e5-b933-31c93021392a_story.html
Story about planning in the Pacific Northwest:
https://www.washingtonpost.com/national/health-science/is-a-massive-earthquaketsunami-overdo-along-the-northern-west-coast/2016/01/25/b423740c-bfce-11e5-bcda-62a36b394160_story.html
Photos from Washington: https://www.washingtonpost.com/local/time-to-pick-up-the-pieces-after-major-dc-area-snowstorm/2016/01/24/889fa7b4-c2c2-11e5-8965-0607e0e265ce_gallery.html?hpid=hp_no-name_photo-story-b%3Ahomepage%2Fstory
One cannot prevent a natural disaster, but one can try to prevent some of the potential problems that it could cause. In New York City, the preparations included a sufficiently large force to clear streets (4,600 workers and more than 2,000 pieces of equipment, according to The Washington Post) and specific actions just before the storm (closing the transit system, which prevented buses from getting stuck in the snow and blocking snowplows).
On the other side of the country, officials are making contingency plans for a much worse disaster: an earthquake and tsunami in the Pacific Northwest that could kill thousands, leave many homeless, and disrupt the economy. Oregon’s response plan, called the Cascadia Playbook, describes the system for moving personnel, equipment, and supplies into the area after the disaster and setting up medical facilities and shelters for the homeless.
In both cases, officials have used previous failures to make better plans. In the 2010 Snowmageddon storms, the New York transit system stayed open, which led to stranded buses; this time they closed it. The 2011 Japanese tsunami gave planners in the Pacific Northwest the opportunity to consider more accurately what would be needed.
Links:
Story about Washington, D.C., and New York City:
https://www.washingtonpost.com/local/after-a-wild-winter-weekend-a-difficult-commute-awaits/2016/01/24/3c987ebe-c302-11e5-b933-31c93021392a_story.html
Story about planning in the Pacific Northwest:
https://www.washingtonpost.com/national/health-science/is-a-massive-earthquaketsunami-overdo-along-the-northern-west-coast/2016/01/25/b423740c-bfce-11e5-bcda-62a36b394160_story.html
Photos from Washington: https://www.washingtonpost.com/local/time-to-pick-up-the-pieces-after-major-dc-area-snowstorm/2016/01/24/889fa7b4-c2c2-11e5-8965-0607e0e265ce_gallery.html?hpid=hp_no-name_photo-story-b%3Ahomepage%2Fstory
Monday, January 4, 2016
Keeping a Pipeline Safe
The risk associated with the 62-year-old pipelines under the Straits of Mackinac in northern Michigan was the subject of an article by Steve Friess in The Washington Post on Sunday.
After a different Enbridge pipeline in Michigan failed in 2010 and released about 20,000 barrels of oil, the state appointed a task force to study the oil pipelines throughout Michigan, include those under the Straits of Mackinac. The task force report made four recommendations about the Straits pipelines and nine others for the whole state. The task force recommended that the Straits pipelines should not transport heavy crude oil. Enbridge has stated that the pipelines carry only light crude oil and light synthetic crude and natural gas liquids, including propane. See, for instance, its Operational Reliability Plan. The Enbridge website has more information about the pipelines and their plans to keep it safe; see http://www.enbridgeus.com/Line-5.aspx
Everyone agrees that a failure of the Straits pipelines could cause severe environmental damage.
Enbridge, of course, also has a financial risk; they would lose revenue if the pipeline fails and has to be shutdown. An Enbridge spokesperson stated, “Every day we’re out repairing pipelines and shutting down due to release, we’re not moving product. It’s in our interest as a pipeline company to keep it in the pipe.”
The Michigan Petroleum Pipeline Task Force website also has some interesting documents about the pipeline construction, including the 1953 engineering analysis (http://michigan.gov/documents/deq/Appendix_A.2_493980_7.pdf), which describes the selection of the location, the construction of the pipeline, and the analysis of the stresses involved. In general, it is a good example of risk assessment and mitigation. It acknowledges both the environmental and financial risks. The pipeline elsewhere in Michigan has only one pipe, but two pipelines were used at the Straits, "for purposes of extra flexibility, extra strength, and a greater factor of safety against possible damage," according to this report. If there are two pipes, then a leak in one pipe should release less oil, and the other pipe can continue to operate, which minimizes the financial and operational disruptions. The report mentions the hazard from a ship's anchor and describes why this is unlikely in general and how the pipeline design will reduce this risk. It also mentions that "any possible contamination of the waters caused by oil spillage from the pipeline crossing is considered remote in comparison to the amount and possibility of spillage from oil tankers."
This last point remains extremely relevant: given that people in Michigan use oil from Canada, all of the transportation options have risks, which the task force report acknowledged.
For example, trains transporting oil had accidents in Quebec and Virginia.
After a different Enbridge pipeline in Michigan failed in 2010 and released about 20,000 barrels of oil, the state appointed a task force to study the oil pipelines throughout Michigan, include those under the Straits of Mackinac. The task force report made four recommendations about the Straits pipelines and nine others for the whole state. The task force recommended that the Straits pipelines should not transport heavy crude oil. Enbridge has stated that the pipelines carry only light crude oil and light synthetic crude and natural gas liquids, including propane. See, for instance, its Operational Reliability Plan. The Enbridge website has more information about the pipelines and their plans to keep it safe; see http://www.enbridgeus.com/Line-5.aspx
Everyone agrees that a failure of the Straits pipelines could cause severe environmental damage.
Enbridge, of course, also has a financial risk; they would lose revenue if the pipeline fails and has to be shutdown. An Enbridge spokesperson stated, “Every day we’re out repairing pipelines and shutting down due to release, we’re not moving product. It’s in our interest as a pipeline company to keep it in the pipe.”
The Michigan Petroleum Pipeline Task Force website also has some interesting documents about the pipeline construction, including the 1953 engineering analysis (http://michigan.gov/documents/deq/Appendix_A.2_493980_7.pdf), which describes the selection of the location, the construction of the pipeline, and the analysis of the stresses involved. In general, it is a good example of risk assessment and mitigation. It acknowledges both the environmental and financial risks. The pipeline elsewhere in Michigan has only one pipe, but two pipelines were used at the Straits, "for purposes of extra flexibility, extra strength, and a greater factor of safety against possible damage," according to this report. If there are two pipes, then a leak in one pipe should release less oil, and the other pipe can continue to operate, which minimizes the financial and operational disruptions. The report mentions the hazard from a ship's anchor and describes why this is unlikely in general and how the pipeline design will reduce this risk. It also mentions that "any possible contamination of the waters caused by oil spillage from the pipeline crossing is considered remote in comparison to the amount and possibility of spillage from oil tankers."
This last point remains extremely relevant: given that people in Michigan use oil from Canada, all of the transportation options have risks, which the task force report acknowledged.
For example, trains transporting oil had accidents in Quebec and Virginia.
Wednesday, December 30, 2015
Turn around don't drown video
Monday, December 21, 2015
Is a Self-Driving Car Safe?
Matt McFarland's article about the safety of robots, drones, and self-driving cars highlights the need for testing of all types: software tests, hardware tests, simulations, and operations on test tracks and real roads.
As the article mentions, the big question: how can one know if the robotic system is safe?
Safety must be relative to an acceptable risk threshold, and setting that threshold will be an important conversation. Testing will have to show that the likelihood of an accident is sufficiently low and that the damage, if an accident occurs, is acceptably low.
In their draft requirements, the California Department of Motor Vehicles suggested that a third-party testing organization should verify that the vehicle is safe.
Links:
https://www.washingtonpost.com/news/innovations/wp/2015/12/18/the-billion-dollar-robot-question-how-can-we-make-sure-theyre-safe/
http://www.dmv.ca.gov/portal/dmv/detail/pubs/newsrel/newsrel15/2015_63
As the article mentions, the big question: how can one know if the robotic system is safe?
Safety must be relative to an acceptable risk threshold, and setting that threshold will be an important conversation. Testing will have to show that the likelihood of an accident is sufficiently low and that the damage, if an accident occurs, is acceptably low.
In their draft requirements, the California Department of Motor Vehicles suggested that a third-party testing organization should verify that the vehicle is safe.
Links:
https://www.washingtonpost.com/news/innovations/wp/2015/12/18/the-billion-dollar-robot-question-how-can-we-make-sure-theyre-safe/
http://www.dmv.ca.gov/portal/dmv/detail/pubs/newsrel/newsrel15/2015_63
Monday, November 30, 2015
How to plan a test
Testing generates information that can be used to make a decision. Testing can occur at any stage in the development of a product or system; it can test a specific attribute or overall performance; it can test a component, a subsystem, a system, or a system-of-systems.
Planning a test requires making crucial decisions: Which item to test? Which test to perform? How many tests to perform?
The test plan determines the value of the information gathered and the time and cost of testing. In general the key tradeoff is that gathering more valuable information requires more time and cost.
My students and I have developed some techniques for making test planning decisions.
Which facility to use? In some cases, a system (such as a military vehicle) needs to be used in an operational environment, but there are no existing test facilities like that environment. Instead of building a new test facility, one could use a combination of existing facilities to replicate the new operational environment. We developed an optimization model to find the test plan that used the best combination of existing facilities examples. For military vehicle applications, it specified the time and number of miles that the test vehicles should run on each existing test facility. Reference: http://www.isr.umd.edu/~jwh2/papers/IEST.pdf
Which configuration to test? A system-of-systems (SoS) consists of relatively independent systems. For example, a missile defense systems has control stations, radar locations, and rocket launchers. If the reliability of the SoS is unknown because the reliability of the systems is unknown, then testing is needed, but testing a full-scale configuration is expensive. We developed a simulation technique to predict the results of tests with smaller configurations under different scenarios and estimate the expected error of the tests. With this information, the test planning decision-makers could evaluate the tradeoffs of cost and expected error and determine the best test configuration. Reference: http://www.isr.umd.edu/~jwh2/papers/Tamburello-Herrmann-JRR-2015.pdf
Which attribute to measure (test)? In a multiattribute decision making situation, measurements of the attributes are valuable for knowing which alternative is best. If these measurements have error and the total budget for measurements is limited, then it is crucial to measure the attributes in a way that provides the most valuable information and increases the likelihood of selecting the truly best alternative. We developed and tested rules for determining which attributes should be measured how many times and showed that better rules can significantly increase this likelihood. Reference: http://www.isr.umd.edu/~jwh2/papers/Leber-Herrmann-ISERC-2015.pdf
Which test to perform? Demonstrating the reliability of a complicated system (such as a liquid rocket engine) requires testing the system and its components and subsystems. These tests and the associated hardware are expensive and require time at scarce test facilities. We developed a multi-objective test plan optimization approach to determine the best test plan that meets the demonstrated reliability. Reference: http://www.isr.umd.edu/~jwh2/papers/Strunz-Herrmann-CEAS-Space-2011.pdf
Planning a test requires making crucial decisions: Which item to test? Which test to perform? How many tests to perform?
The test plan determines the value of the information gathered and the time and cost of testing. In general the key tradeoff is that gathering more valuable information requires more time and cost.
My students and I have developed some techniques for making test planning decisions.
Which facility to use? In some cases, a system (such as a military vehicle) needs to be used in an operational environment, but there are no existing test facilities like that environment. Instead of building a new test facility, one could use a combination of existing facilities to replicate the new operational environment. We developed an optimization model to find the test plan that used the best combination of existing facilities examples. For military vehicle applications, it specified the time and number of miles that the test vehicles should run on each existing test facility. Reference: http://www.isr.umd.edu/~jwh2/papers/IEST.pdf
Which configuration to test? A system-of-systems (SoS) consists of relatively independent systems. For example, a missile defense systems has control stations, radar locations, and rocket launchers. If the reliability of the SoS is unknown because the reliability of the systems is unknown, then testing is needed, but testing a full-scale configuration is expensive. We developed a simulation technique to predict the results of tests with smaller configurations under different scenarios and estimate the expected error of the tests. With this information, the test planning decision-makers could evaluate the tradeoffs of cost and expected error and determine the best test configuration. Reference: http://www.isr.umd.edu/~jwh2/papers/Tamburello-Herrmann-JRR-2015.pdf
Which attribute to measure (test)? In a multiattribute decision making situation, measurements of the attributes are valuable for knowing which alternative is best. If these measurements have error and the total budget for measurements is limited, then it is crucial to measure the attributes in a way that provides the most valuable information and increases the likelihood of selecting the truly best alternative. We developed and tested rules for determining which attributes should be measured how many times and showed that better rules can significantly increase this likelihood. Reference: http://www.isr.umd.edu/~jwh2/papers/Leber-Herrmann-ISERC-2015.pdf
Which test to perform? Demonstrating the reliability of a complicated system (such as a liquid rocket engine) requires testing the system and its components and subsystems. These tests and the associated hardware are expensive and require time at scarce test facilities. We developed a multi-objective test plan optimization approach to determine the best test plan that meets the demonstrated reliability. Reference: http://www.isr.umd.edu/~jwh2/papers/Strunz-Herrmann-CEAS-Space-2011.pdf
Subscribe to:
Posts (Atom)