Risk analysis method for civil aircraft cockpit human-machine system based on node resilience assessment
By building a functional network model of the human-machine system of the civil aircraft cockpit and using the SIR infectious disease model to simulate risk transmission, the risk analysis problems in complex tasks in the civil aircraft cockpit are solved, and the system's safety and recovery capabilities are improved.
Patent Information
- Application Number
- CN202410594756.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-14
- Publication Date
- 2025-08-26
- Estimated Expiration
- 2044-05-14
AI Technical Summary
The prior art is difficult to effectively analyze the risk factors and the impact of quantitative risks on system performance in the civil aircraft cockpit human-machine system, and there is a lack of quantitative analysis methods.
The method based on node elasticity assessment is adopted, and the civil aircraft cockpit control program is decomposed through hierarchical task analysis method and functional resonance analysis, a functional network model of the human-machine system is constructed, the transmission rate, infection rate and recovery rate are calculated, and the risk transmission process is simulated using the SIR infectious disease model to analyze the elasticity of key nodes.
Quantitative analysis of human-machine system risk events in civil aircraft cockpits has been realized, the system's safety and risk resistance have been improved, and the system's recovery ability has been enhanced.
Smart Images

Figure CN118568930B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of complex human-machine system risk analysis, and specifically relates to a civil aircraft cockpit human-machine system risk analysis method based on node elasticity assessment. Background Art
[0002] Risk analysis is the process of understanding the risks inherent in a system, estimating the probability of risk events occurring, and the severity of potential harm and loss. Risk analysis techniques can be categorized into qualitative and quantitative methods. Qualitative analysis involves non-quantitative analysis of the factors influencing risk events in the civil aviation system, making a perceptual judgment about whether a risk event will occur. Quantitative analysis, based on qualitative analysis, applies mathematical methods to analyze the relationship between system risk events and influencing factors, providing a quantitative description of the risk event. While qualitative analysis has matured, it cannot adapt to the increasing complexity of risks in intelligent human-machine systems. Quantitative analysis methods are less mature and lack effective technical means to quantify the dynamic spread of risk and the extent of its impact. Summary of the Invention
[0003] Purpose of the invention: In order to overcome the deficiencies in the existing technology, a risk analysis method for the human-machine system in the cockpit of a civil aircraft is provided based on node elasticity assessment. Risk events and the degree of damage to the system caused by the risk are analyzed in a complex human-machine system, and targeted measures are taken for risk events. This is of great significance to improving the robustness, safety and resilience of the intelligent interactive human-machine system in the cockpit of future civil aircraft.
[0004] Technical Solution: To achieve the above objectives, the present invention provides a civil aircraft cockpit human-machine system risk analysis method based on node resilience assessment, comprising the following steps:
[0005] S1: Analyze flight crew operational tasks during typical flight phases;
[0006] S2: Analyze and decompose the cockpit human-machine system functions based on the functional resonance analysis method, and screen out the main functional units of the human-machine system;
[0007] S3: Analyze the output characteristics of the function, consider the internal and external influencing factors of the function, obtain the function failure link, and build a risk propagation network model for the human-machine system;
[0008] S4: Calculate the propagation index of each node in the risk propagation network of the human-machine system;
[0009] S5: Based on a node elasticity evaluation method, the node elasticity value is calculated through a random simulation method to analyze the key nodes of the human-machine system.
[0010] Furthermore, the step S1 specifically includes:
[0011] A1: Select a specific flight phase and analyze the main objectives of the flight mission;
[0012] A2: Decompose the main goal into multiple sub-goals within the constraints and assumptions, and then break down the operational tasks or actions under each sub-goal;
[0013] A3: Draw an HTA diagram of the flight operation sequence guided by the main target, and clarify the order of actions and the subordinate relationships of the actions.
[0014] Furthermore, the step S2 specifically includes:
[0015] B1: Decompose the task process into multiple human, technical and organizational functions;
[0016] B2: Construct a functional network model of the human-machine system, where nodes are decomposed functions and nodes are connected based on functional relationships such as "output-input", "output-prerequisite", "output-resource", "output-time" and "output-control".
[0017] Furthermore, each function in step B1 consists of six aspects: input, premise, resource, time, control and output.
[0018] Furthermore, the step S3 specifically includes:
[0019] C1: Analyze the output characteristics of the function and explain the risk output of the function from the perspective of time and accuracy;
[0020] C2: Analyze the internal and external factors affecting the function;
[0021] C3: Obtain function failure links based on the function’s risk output and influencing factors;
[0022] C4: Construct a risk propagation network model G(N,V) for the human-machine system, where N is the network node set and V is the network edge set; the influencing factors and the risk output of each function are regarded as nodes N. i , i=1,2,...,n, and regard the failed link as node N i With node N j Directed connections between .
[0023] Furthermore, the transmission index in step S4 includes transmission rate, infection rate and recovery rate indicators, and the specific calculation method includes the following steps:
[0024] D1: Based on cognitive reliability and error analysis methods, risk events are divided into 13 human failure modes and 2 system function failure modes;
[0025] D2: Define the node states of the human-machine system risk propagation network into three categories: risk-uninfected state, risk-infected state, and risk-recovered state; calculate the infection rate β, propagation rate ε, and recovery rate γ in the human-machine system risk propagation network model;
[0026] The calculation of infection rate β includes: giving a basic value of failure probability based on statistics; setting common performance conditions according to the situational environment of each event; and correcting the failure probability;
[0027] The calculation of the transmission rate ε involves dividing the connections between nodes into four categories: "human→human", "machine→human", "human→machine", and "machine→machine"; calculating the failure probability of each connection separately, using the same calculation steps as the infection rate;
[0028] The recovery rate γ is calculated by the following formula:
[0029] γ=1-(1-(1-P(A)(1-P(B)(1-P(C)))
[0030] Among them, A is the failure event of the diagnosis link, B is the failure event of the verification link, and C is the failure event of the system self-correction link.
[0031] Furthermore, the step S5 specifically includes:
[0032] E1: Based on the random simulation method, the initial risk node is first selected from the node set, and then according to the SIR epidemic model mechanism, the node is traversed and calculated whether it is infected or recovered;
[0033] E2: Define the performance indicator of the risk propagation network model as the ratio of the number of uninfected nodes to the total number of nodes, and record the changes in network performance after each simulation;
[0034] E3: Calculates node elasticity metrics based on performance changes. The formula is as follows:
[0035]
[0036] Among them, Q is the system performance metric, Q max is the initial performance value, Q min is the minimum performance value, t s is the moment when performance loss occurs, t m is the moment when the performance reaches its minimum, t e It is the moment when the system performance returns to its original state;
[0037] E4: Sort nodes based on node elasticity calculation results and analyze human-machine system risk events.
[0038] Furthermore, the mechanism of the SIR epidemic model in step E1 is:
[0039] The risk propagation of human-machine systems based on the SIR infectious disease model divides nodes into three states: risk-free state, risk-infected state, and risk-recovered state. The risk-free state is the state where the risk has not yet occurred; the risk-infected state is when the node is occupied by the risk and can spread the risk to other nodes; the risk-recovered state is when the system and the crew identify, communicate, and control the risk, and can restore other nodes.
[0040] The SIR epidemic model has the following assumptions: (1) the total number of nodes always remains a constant; (2) all nodes are infectious, denoted as the infection rate β; (3) the connections between nodes have different degrees of influence on the infection, denoted as the transmission rate ε; (4) at each moment, an infected node has a probability of recovering from the infected state, denoted as the recovery rate γ.
[0041] The calculation method for whether a node is infected or recovered is:
[0042] In a risk propagation process, let the event of infection risk of node j in the human-machine system network G(N,V) be I, and the infection rate of node j be β j , the probability of risk recovery is γ, then the probability of event I occurring is:
[0043]
[0044] Among them, Ω is the parent node set of the current node j, ε ij is the risk transmission rate between nodes i and j;
[0045] If the recovery event of node j is L, then the probability of event L occurring is:
[0046] P j (L) = γ
[0047] The method of the present invention generally includes: for civil aircraft cockpit control procedures in typical flight phases, decomposing civil aircraft cockpit control procedures based on hierarchical task analysis method and functional resonance analysis method, and constructing a human-machine system functional network model; considering the risk events of functional output from the perspective of accuracy and timeliness of functional output in the human-machine system functional network model, and integrating the internal and external influencing factors of the function to construct a human-machine system risk propagation network model; calculating the propagation rate, infection rate and recovery rate of nodes in the human-machine system risk propagation network model based on cognitive reliability and error analysis methods; using a node elasticity assessment method, simulating the dynamic propagation process of risk in the human-machine system based on the SIR infectious disease model, calculating the elasticity of each node in the human-machine system risk propagation network model through a random simulation method, and analyzing the key links of the human-machine system.
[0048] Beneficial effects: Compared with the existing technology, the present invention can analyze risk events and the degree of damage to the system in complex human-machine systems, solving the problems of existing civil aircraft cockpit human-machine systems that are difficult to analyze risk factors in complex task processes and difficult to quantify the impact of risks on the performance of human-machine systems. The present invention is of great significance and value in improving the safety, risk resistance and recovery capabilities of future intelligent aircraft cockpit human-machine systems. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] Figure 1 It is the overall flow chart of the present invention;
[0050] Figure 2 This is an HTA analysis diagram for the takeoff phase in an embodiment of the present invention;
[0051] Figure 3 This is a functional network diagram of the human-machine system during the takeoff phase in an embodiment of the present invention;
[0052] Figure 4 This is a risk propagation network diagram for the takeoff stage in an embodiment of the present invention. DETAILED DESCRIPTION
[0053] The present invention is further illustrated below with reference to the accompanying drawings and specific embodiments. It should be understood that these embodiments are only used to illustrate the present invention and are not used to limit the scope of the present invention. After reading the present invention, modifications of various equivalent forms of the present invention made by those skilled in the art all fall within the scope defined by the claims attached to this application.
[0054] like Figure 1 As shown, the present invention provides a civil aircraft cockpit human-machine system risk analysis method based on node resilience assessment. In this embodiment, taking the A320 aircraft takeoff phase flight mission as an example, the method of the present invention is implemented, specifically including the following steps:
[0055] Step (1): Analyze the flight crew's operational tasks during the takeoff phase. The specific steps are as follows:
[0056] Step (1.1): Select the takeoff phase and analyze the main objectives of the flight mission;
[0057] Step (1.2): Decompose the main goal into multiple sub-goals within the constraints and assumptions, and break down the operational tasks or actions under each goal. The constraints and assumptions include: controlling the number of sub-goals to an appropriate level; the decomposition results can fully describe the system without being too complex. The mission objectives of the takeoff phase are shown in Table 1;
[0058] Table 1 Mission objectives for the takeoff phase
[0059]
[0060] Step (1.3): Draw the HTA diagram of the flight operation sequence guided by the main target, clarify the order of actions and the subordinate relationship of actions, such as Figure 2 shown.
[0061] Step (2): Analyze and decompose the cockpit human-machine system functions based on the functional resonance analysis method to screen out the main functional units of the human-machine system. The functional resonance analysis method is used to construct the interaction between system functions, consider the human, material, and organizational factors behind the risk, and reveal the nonlinear coupling relationship between functions. It includes four steps: identifying and describing functions, determining the change output of functions, determining the coupling relationship between functions, and analyzing the results.
[0062] The specific steps are as follows:
[0063] Step (2.1): Decompose the task process into multiple human, technical, and organizational functions. Each function consists of six aspects: input, premise, resource, time, control, and output. Some functional descriptions are shown in Table 2.
[0064] Table 2 Description of some functions of the human-machine system during takeoff
[0065]
[0066] Step (2.2): Construct a functional network model of the human-machine system. The nodes are the decomposed functions, and the nodes are connected based on the relationships of "output-input", "output-prerequisite", "output-resource", "output-time" and "output-control". Figure 3 shown. Figure 3 In the figure, red nodes are the start and end nodes, white nodes are the manipulation behavior nodes, gray nodes are the thinking behavior nodes including observation, judgment and thinking, and blue nodes are the system components or system states related to human-computer interaction.
[0067] Step (3): Analyze the output characteristics of the function, consider the internal and external influencing factors of the function, obtain the function failure link, and build the human-machine system risk propagation network model. The specific steps are as follows:
[0068] Step (3.1): Analyze the output characteristics of the function and describe the risk output of the function from the perspective of time and accuracy, as shown in Table 3;
[0069] Table 3 Human-machine system functional risk output
[0070]
[0071]
[0072]
[0073] Step (3.2): Analyze the internal and external influencing factors of the function, as shown in Table 4;
[0074] Table 4 Factors affecting the function of human-machine system
[0075]
[0076]
[0077] Step (3.3): Obtain functional failure links based on the risk outputs and influencing factors of the function. If there is a physical connection relationship between the risk outputs, such as mechanical, electrical, or information transmission, or a logical connection relationship such as operating procedures or environmental impact, between the risk outputs and the influencing factors, then a functional failure link is considered to exist between the two. The results are shown in Table 5. In the table, a failure link is defined as the event on the left affecting the event on the right. The internal influencing factors are numbered starting with "I" and the external influencing factors are numbered starting with "O". The functional risk output number includes the function number and the output number of the current function.
[0078] Table 5 Human-machine system function failure links
[0079]
[0080]
[0081]
[0082] Step (3.4): Construct the risk propagation network model G(N,V) of the human-machine system, where N is the network node set and V is the network edge set, as follows: Figure 4 As shown, the influencing factors and the risk output of each function are regarded as nodes N i , i=1,2,...,n, and regard the failed link as node N i With node N j Directed connections between .
[0083] Step (4): Define the node states of the human-machine system risk propagation network into three categories: risk-uninfected state, risk-infected state, and risk-recovered state; calculate the propagation rate, infection rate, and recovery rate indicators of each node in the human-machine system risk propagation network. The specific steps are as follows:
[0084] Step (4.1): Based on the cognitive reliability and error analysis method, risk events are divided into 13 human failure modes and 2 system function failure modes, as shown in Table 6;
[0085] Table 6 Basic values of failure modes and failure probabilities of human-machine system functions
[0086]
[0087]
[0088] Step (4.2): Calculate the infection rate β, transmission rate ε and recovery rate γ in the human-machine system risk propagation network model;
[0089] The calculation of infection rate β includes: giving a basic value of failure probability based on statistics; setting common performance conditions according to the situational environment of each event; and correcting the failure probability;
[0090] The infection rate β is calculated by the following formula:
[0091] β=CPC·p
[0092] Where CPC is the CPC impact value, and p is the basic failure probability of the failure mode included in the change output. The infection rate of the change output is obtained by correcting the basic failure probability using the CPC impact value.
[0093] The infection rates of some nodes are shown in Table 7;
[0094] Table 7 Infection rates of some nodes in the human-machine system risk propagation network model
[0095]
[0096]
[0097] The calculation of the propagation rate ε involves classifying the connections between nodes into four categories: "human→human", "machine→human", "human→machine", and "machine→machine". The formula for calculating the propagation rate ε is as follows:
[0098] ε=CPC·p
[0099] The failure probability of each connection is calculated separately, and the calculation results are shown in Table 8.
[0100] Table 8 Directed connection propagation rate of human-machine system
[0101]
[0102] The recovery rate γ is calculated by the following formula:
[0103] γ=1-(1-(1-P(A)(1-P(B)(1-P(C)))
[0104] Wherein, A is the diagnosis link failure event, B is the verification link failure event, and C is the system self-correction link failure event. In this embodiment, the calculation result is γ=0.2884.
[0105] Step (5): Based on a node elasticity evaluation method, the node elasticity value is calculated by a random simulation method to analyze the key nodes of the human-machine system. The specific steps are as follows:
[0106] Step (5.1): Based on the random simulation method, first select the initial risk node from the node set, and then traverse and calculate whether the node is infected or recovered according to the SIR epidemic model mechanism;
[0107] The risk propagation of human-machine systems based on the SIR infectious disease model divides nodes into three states: risk-free state, risk-infected state, and risk-recovered state. The risk-free state is the state where the risk has not yet occurred; the risk-infected state is when the node is occupied by the risk and can spread the risk to other nodes; the risk-recovered state is when the system and the crew identify, communicate, and control the risk, and can restore other nodes.
[0108] The SIR epidemic model has the following assumptions: (1) the total number of nodes always remains a constant; (2) all nodes are infectious, denoted as the infection rate β; (3) the connections between nodes have different degrees of influence on the infection, denoted as the transmission rate ε; (4) at each moment, an infected node has a probability of recovering from the infected state, denoted as the recovery rate γ.
[0109] In a risk propagation process, let the event of infection risk of node j in the human-machine system network G(N,V) be I, and the infection rate of node j be β j , the probability of risk recovery is γ. Then the probability of event I occurring is:
[0110]
[0111] Where Ω is the parent node set of the current node j, ε ij is the risk transmission rate between nodes i and j.
[0112] If the recovery event of node j is L, then the probability of event L occurring is:
[0113] P j (L) = γ
[0114] Step (5.2): Define the performance indicator of the risk propagation network model as the ratio of the number of uninfected nodes to the total number of nodes, and record the changes in network performance after each simulation;
[0115] Step (5.3): Calculate the node elasticity metric based on the performance change. The formula is as follows:
[0116]
[0117] Among them, Q is the system performance metric, Q max is the initial performance value, Q minis the minimum performance value, t s is the moment when performance loss occurs, t m is the moment when the performance reaches its minimum, t e It is the moment when the system performance returns to its original state;
[0118] Step (5.4): Sort the nodes according to the node elasticity calculation results. The results are shown in Table 9.
[0119] Table 9 Average node elasticity and ranking
[0120]
[0121]
[0122] Analyzing risk events reveals that node I6 has the highest average resilience. I6 represents "pilot fatigue," a key component of the system structure and significantly impacts other nodes. Furthermore, N23.c represents "difficulty viewing the PFD," I7 represents "eye fatigue," N9.c represents "delayed groundspeed / airspeed judgment," and N9.b represents "incorrect groundspeed / airspeed judgment." Human error accounts for four of these five nodes, with N23.c also being closely related to pilot visual load and information processing. Overall, among the risk nodes, equipment risks account for approximately 51%, human errors for approximately 40%, and environmental and social risks for approximately 9%. Equipment risks are typically associated with flight control and information transmission, while operational errors also account for a high proportion of human errors.
[0123] Overall, the pilot's physiological and psychological condition is more critical. The other non-human error risks ranked at the top are all related to the pilot's information acquisition. The reason may be that the pilot relies mainly on the visual channel to obtain navigation information, which is visually demanding and prone to risks. The frequency of "human-machine" risks related to flight control is higher in the nodes ranked lower. In order to improve the robustness and resilience of the human-machine system, corresponding risk prevention strategies are proposed. In order to address the problem of high pilot fatigue that easily leads to risks, the pilot's current status can be monitored through real-time analysis of physiological data such as facial movement fatigue analysis or eye movement electromyography. To solve the problem of high visual load for pilots during flight, multi-channel fusion human-machine interaction technology can be used to balance the load, or the visualization of navigation information can be improved to make important information easy to obtain.
Claims
1. A civil aircraft cockpit human-machine system risk analysis method based on node resilience assessment, characterized by: The steps include: S1: Analyze flight crew operational tasks during typical flight phases; S2: Analyze and decompose the cockpit human-machine system functions based on the functional resonance analysis method, and screen out the main functional units of the human-machine system; S3: Analyze the output characteristics of the function, consider the internal and external influencing factors of the function, obtain the function failure link, and build a risk propagation network model for the human-machine system; S4: Calculate the propagation index of each node in the risk propagation network of the human-machine system; S5: Based on a node resilience assessment method, node resilience values are calculated using a random simulation method to analyze key nodes in the human-machine system; Step S5 specifically includes: E1: Based on the random simulation method, the initial risk node is first selected from the node set, and then according to the SIR epidemic model mechanism, the node is traversed and calculated whether it is infected or recovered; E2: Define the performance indicator of the risk propagation network model as the ratio of the number of uninfected nodes to the total number of nodes, and record the changes in network performance after each simulation; E3: Calculates node elasticity metrics based on performance changes. The formula is as follows: Among them, Q is the system performance metric, Q max is the initial performance value, t s is the moment when performance loss occurs, t m is the moment when the performance reaches its minimum, t e It is the moment when the system performance returns to its original state; E4: Sort nodes based on node elasticity calculation results and analyze human-machine system risk events; The mechanism of the SIR epidemic model in step E1 is: The risk propagation of human-machine systems based on the SIR infectious disease model divides nodes into three states: risk-free state, risk-infected state, and risk-recovered state. The risk-free state is the state where the risk has not yet occurred; the risk-infected state is when the node is occupied by the risk and can spread the risk to other nodes; the risk-recovered state is when the system and the crew identify, communicate, and control the risk, and can enable other nodes to recover. The SIR epidemic model has the following assumptions: (1) the total number of nodes always remains a constant; (2) all nodes are infectious, denoted by the infection rate β; (3) the connections between nodes have different degrees of influence on the infection, denoted by the transmission rate ε; (4) at each moment, the infected node has a probability of recovering from the infected state, denoted by the recovery rate γ; The calculation method for whether the node is infected or recovered in step E1 is: In a risk propagation process, let the event of infection risk of node j in the human-machine system network G(N,V) be I, and the infection rate of node j be β j , the probability of risk recovery is γ, then the probability of event I occurring is: Among them, Ω is the parent node set of the current node j, ε ij is the risk transmission rate between nodes i and j; If the recovery event of node j is L, then the probability of event L occurring is: P j (L)=γ.
2. The method for risk analysis of a civil aircraft cockpit human-machine system based on node resilience assessment according to claim 1, characterized in that: The step S1 specifically includes: A1: Select a specific flight phase and analyze the main objectives of the flight mission; A2: Decompose the main goal into multiple sub-goals within the constraints and assumptions, and then break down the operational tasks or actions under each sub-goal; A3: Draw an HTA diagram of the flight operation sequence guided by the main target, and clarify the order of actions and the subordinate relationships of the actions.
3. The method for risk analysis of a civil aircraft cockpit human-machine system based on node resilience assessment according to claim 1, characterized in that: The functional resonance analysis method in step S2 includes four steps: identifying and describing functions, determining the change output of functions, determining the coupling relationship between functions, and analyzing the results.
4. The method for risk analysis of a civil aircraft cockpit human-machine system based on node resilience assessment according to claim 3 is characterized in that: The step S2 specifically includes: B1: Decompose the task process into multiple human, technical and organizational functions; B2: Construct a functional network model of the human-machine system, where nodes are decomposed functions and nodes are connected based on functional relationships.
5. The method for risk analysis of a civil aircraft cockpit human-machine system based on node resilience assessment according to claim 4 is characterized in that: Each function in step B1 consists of six aspects: input, premise, resource, time, control and output.
6. The method for risk analysis of a civil aircraft cockpit human-machine system based on node resilience assessment according to claim 1, characterized in that: The step S3 specifically includes: C1: Analyze the output characteristics of the function and explain the risk output of the function from the perspective of time and accuracy; C2: Analyze the internal and external factors affecting the function; C3: Obtain function failure links based on the function’s risk output and influencing factors; C4: Construct a risk propagation network model G(N,V) for the human-machine system, where N is the network node set and V is the network edge set; the influencing factors and the risk output of each function are regarded as nodes N. i , i=1,2,...,n, and regard the failed link as node N i With node N j Directed connections between .
7. The method for risk analysis of a civil aircraft cockpit human-machine system based on node resilience assessment according to claim 1, characterized in that: The transmission index in step S4 includes transmission rate, infection rate and recovery rate indicators, and the specific calculation method includes the following steps: D1: Based on cognitive reliability and error analysis methods, risk events are divided into 13 human failure modes and 2 system function failure modes; D2: Define the states of nodes in the risk propagation network of the human-machine system into three categories: risk-uninfected state, risk-infected state, and risk-recovered state; Calculate the infection rate β, transmission rate ε and recovery rate γ in the risk propagation network model of human-machine system; The calculation of the infection rate β includes: providing a basic value of the failure probability based on statistics; setting common performance conditions based on the situational environment of each event; and correcting the failure probability. The infection rate β is calculated using the following formula: β=CPC·p Where CPC is the CPC impact value, and p is the basic failure probability of the failure mode included in the change output. The infection rate of the change output is obtained by correcting the basic failure probability using the CPC impact value. The calculation of the transmission rate ε involves classifying the connections between nodes into four categories: "human→human", "machine→human", "human→machine", and "machine→machine". The failure probability of each connection is calculated separately, using the same calculation steps as the infection rate. The formula for calculating the transmission rate ε is as follows: ε=CPC·p The recovery rate γ is calculated by the following formula: γ=1-(1-(1-P(A)(1-P(B)(1-P(C))) Among them, A is the failure event of the diagnosis link, B is the failure event of the verification link, and C is the failure event of the system self-correction link.