Airborne system cascade failure analysis method based on model

By building an airborne system model for cascade failure and using the DWNodeRank algorithm, the problem of low accuracy of cascade failure analysis in the existing technology is solved, and more accurate failure propagation paths and path combination analysis is achieved.

CN120145552APending Publication Date: 2025-06-13NANJING UNIV OF AERONAUTICS & ASTRONAUTICS
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510222804.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-27
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

The existing cascade failure analysis methods of airborne systems fail to effectively consider the impact of system status and path combination, resulting in low analysis accuracy.

Method used

The model-based cascade failure analysis method of airborne system is adopted to construct a cascade failure-oriented airborne system model, including nominal model and fault propagation model, and the consistency of the model is verified by XML information extraction technology and graph isomorphic methods, and the fault propagation intensity and probability are calculated by the DWNodeRank algorithm.

Benefits of technology

The accuracy of cascade failure analysis is improved, and the fault propagation path and path combination can be more accurately identified during the system cascade failure process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120145552A_ABST
    Figure CN120145552A_ABST
Patent Text Reader

Abstract

The invention is applicable to the technical field of system analysis, and provides a model-based airborne system cascade failure analysis method, which comprises the following steps of: constructing a cascade failure-oriented airborne system model based on AADL and instantiating the cascade failure-oriented airborne system model to obtain an aaxl2 file, then, the XML technology is used for extracting components of all levels, the connection relation between the components and fault propagation information from an aaxl2 file to construct a cascade propagation model, system topological parameters are used for defining fault propagation strength between the components in the airborne system and inputting the fault propagation strength into a DWNodeRank algorithm, the fault influence degree between the components is output, the fault propagation probability between the components is solved in combination with the failure rate of the components, and the fault propagation probability between the components is calculated. And representing the fault influence degree as a component importance degree, taking a component fault greater than a preset threshold value as a cascade failure initial condition, and solving a fault propagation path and a fault propagation path combination which cause a system cascade failure process by using a cascade propagation model through a fault propagation path analysis algorithm. Therefore, the accuracy of cascade failure analysis can be improved through the method.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the technical field of system analysis, and particularly relates to a model-based cascading failure analysis method for airborne systems. Background Art

[0002] The functions of modern civil aircraft airborne systems are becoming increasingly diverse, and the structures are becoming more complex. They are composed of mechanical, electronic, electrical, and hydraulic units, including flight control systems, environmental control systems, and power systems, etc., with high integration and complexity. A certain function of the system is often realized by multiple components working together, and a certain component is also involved in realizing multiple functions at the same time, showing high integration. Without the help of analysis tools, it is very difficult to determine the operating state, failure mode, and failure impact of the system, and it is impossible to verify the safety of the system only through testing methods, showing complexity.

[0003] Due to the interaction relationship between components of the airborne system, a component failure will iteratively affect the failures of other components with interaction relationships, resulting in system function failures and even system failures, that is, cascading failures occur. Analyzing the cascading failure phenomenon of the system helps to deepen the understanding of the system failure behavior. The cascading failure analysis methods include analysis methods based on probability models and analysis methods based on complex networks. However, the above methods do not consider the influence of the system state and path combination, resulting in the problem of low accuracy of cascading failure analysis. Summary of the Invention

[0004] The embodiments of this application provide a model-based cascading failure analysis method for airborne systems, which can solve the problem that the current analysis methods do not consider the influence of the system state and path combination, resulting in low accuracy of cascading failure analysis.

[0005] In a first aspect, an embodiment of the present application provides a model-based cascading failure analysis method for an airborne system, including the following steps: S1: Construct an airborne system model for cascading failure based on the architecture design modeling language AADL. The system model includes a nominal model and a fault propagation model; S2: Instantiate the system model in S1 to obtain an instantiated aaxl2 file; S3: Use XML information extraction technology to extract components at each level, connection relationships between components, and fault propagation information from the instantiated aaxl2 file, and use them to construct an airborne system cascading propagation model. Verify the consistency between the AADL model and the cascading propagation model based on the graph isomorphism method; S4: According to the airborne system cascading propagation model in S3, define the fault propagation intensity between components inside the airborne system using system topology parameters, and use the fault propagation intensity as the input of the DWNodeRank algorithm to output the fault influence degree between components. Combine the component failure rate to solve the fault propagation probability between components; S5: Represent the fault influence degree in S4 as the component importance, use the component failure with the component importance greater than the preset threshold as the initial condition of cascading failure, and use the airborne system cascading propagation model in S3 to solve the fault propagation path and the combination of fault propagation paths that cause system failure during the system cascading failure process through the fault propagation path analysis algorithm.

[0006] In a possible implementation manner of the first aspect, the above step S1 includes:

[0007] When the system model is a nominal model, divide the system model into a system level, a function level, and a component level. Represent the components at each level of the system model through predefined components of the AADL model, and then declare the sub-components and connection interaction relationships of each component to complete the construction of the nominal model;

[0008] When the system model is a fault propagation model, describe the fault propagation influence between components, the influence of component faults on functions, and the influence of function faults on the system state by declaring the fault propagation behavior, component error behavior, and composite error behavior of each component to complete the construction of the fault propagation model.

[0009] Optionally, in another possible implementation manner of the first aspect, the elements of the airborne system cascading propagation model in the above step S3 include component layer nodes B = {b 1 , b 2 ,..., b n}, function layer nodes F = {f 1 , f 2 ,..., f m}, and system layer nodes S = {s 1 , s 2 ,…, s k};

[0010] Component layer node connection matrix Mbb As follows:

[0011]

[0012] Wherein takes values of 0 or 1. When , it indicates that system component i connects or propagates an error to component j; when , it indicates that there is no interaction between component i and component j;

[0013] Component layer - Function layer connection matrix M fb As follows:

[0014]

[0015] Wherein takes values of logical words "and" and "or". When and , it indicates that when components j and j + 1 fail, system function i fails; when , it indicates that when component j fails, function i fails;

[0016] Function layer - System layer connection matrix M sf As follows:

[0017]

[0018] Among them, takes values of 0 or 1. When , it indicates that system component i connects or propagates an error to component j; when , it indicates that there is no interaction between component i and component j.

[0019] Optionally, in another possible implementation manner of the first aspect, the process of constructing the cascading propagation model based on XML information extraction in the above step S3 includes:

[0020] Using the Python ElementTree module to extract the system - level components, function - level components, component - level components, the connection relationships between components, and the fault propagation information from the aaxl2 file, and then constructing the cascading propagation model according to the mapping relationship between the AADL model and the cascading propagation model;

[0021] Construct the component layer nodes of the cascade propagation model by extracting component-level components, and construct the connection matrix of the component layer nodes of the cascade propagation model by extracting the connection relationships and fault propagation relationships among component-level components; extract the function layer nodes of the component-level component cascade propagation model, and extract the state transition logic in the composite error behavior of the function-level components to construct the component layer-function layer connection matrix; extract the system layer nodes of the system-level component error state component cascade propagation model, and extract the state transition logic in the composite error behavior of the system-level components to construct the function layer-system layer connection matrix.

[0022] Optionally, in another possible implementation manner of the first aspect, the verification of the consistency between the AADL model and the cascade propagation model based on the graph isomorphism method in the above step S3 includes:

[0023] Convert the component layer, function layer components, and system error states in the AADL model into nodes, convert the data interaction and fault impacts between component-level components into edges of the nodes, and convert the fault impacts between function-level and system-level components into edges to obtain the AADL graph model;

[0024] Convert the nodes at all levels of the cascade propagation model into nodes, and convert the connection relationships between the nodes into edges to obtain the cascade propagation graph model;

[0025] Take the AADL graph model and the cascade propagation graph model as the input of the VF2 algorithm, and determine whether the two graph models are isomorphic by comparing the nodes of the two graph models.

[0026] Optionally, in another possible implementation manner of the first aspect, the definition of the fault propagation intensity between components in the above step S4 is as follows:

[0027]

[0028] where L dout is the out-degree centrality of the node, and L b is the betweenness centrality of the node.

[0029] Optionally, in another possible implementation manner of the first aspect, taking the fault propagation intensity as the input of the DWNodeRank algorithm and outputting the fault impact degree between components in the above step S4 includes:

[0030] Normalize the fault propagation intensity matrix, and use the vector (1 / n)e T to replace the rows that are all 0 in the normalized fault propagation intensity matrix to obtain the probability transition matrix, where n is the dimension of the matrix;

[0031] Construct the DWNodeRank matrix A according to the probability transition matrix and the preset damping factor; use the out-degree centrality of the node as the initial vector, and determine the fault impact degree of the component layer nodes of the cascade propagation model by iteratively obtaining the stationary distribution of the matrix A.

[0032] Optionally, in another possible implementation of the first aspect, the fault propagation probability in step S4 above is defined as follows:

[0033]

[0034] Pr(ij) = λ i A(e i→j )

[0035] where A i and A j are the fault influence degrees of nodes i and j respectively, and A(e i→j ) represents the fault influence degree of the connection edge between the two nodes, and λ i is the failure rate of node i.

[0036] Optionally, in another possible implementation of the first aspect, the implementation process of the fault propagation path analysis algorithm in step S5 above is as follows:

[0037] Using the node influence degree as the importance value, select the nodes with importance values greater than the preset threshold as the starting nodes for cascading failure analysis, and use the starting nodes, cascading propagation model, given propagation order, and path probability requirements as the input of the fault propagation path analysis algorithm;

[0038] Obtain the fault paths after the first fault propagation according to the starting nodes and the component layer node matrix. For each fault propagation path, judge the influence of the path on the system function according to the function layer-component layer connection matrix, and judge the influence of the path on the system state according to the system layer-function layer connection matrix, obtain all single fault paths that cause system failure, and calculate the path propagation probability, and retain the fault propagation paths that meet the preset probability requirements;

[0039] For path combinations, after excluding the single paths that will cause system failure, permute and combine the remaining paths, identify the path combinations that will cause system failure according to the function layer-component layer connection matrix and the system layer-function layer connection matrix, and calculate the propagation probability of the path combinations, and retain the fault propagation path combinations that meet the preset probability requirements;

[0040] If the fault propagation order does not reach the preset given value, start from the last node of the current path and continue the next-order fault propagation and path analysis until the specified propagation order is reached, and output the fault propagation paths and fault propagation path combinations that cause all system failures.

[0041] Beneficial effects: In the technical solution of the present application, first, an airborne system model for cascading failure is constructed based on the architecture design modeling language AADL. The system model includes a nominal model and a fault propagation model. The system model is instantiated to obtain an instantiated aaxl2 file. The XML information extraction technology is used to extract components at each level, the connection relationships between components, and fault propagation information from the instantiated aaxl2 file, which are used to construct an airborne system cascading propagation model. Then, the consistency between the AADL model and the cascading propagation model is verified based on the graph isomorphism method. Next, according to the airborne system cascading propagation model, the fault propagation intensity between components inside the airborne system is defined using system topology parameters, and the fault propagation intensity is used as the input of the DWNodeRank algorithm to output the fault influence degree between components. The fault propagation probability between components is solved by combining the component failure rate. Finally, the fault influence degree is expressed as the component importance, and the component failures with component importance greater than the preset threshold are used as the initial conditions for cascading failure. Using the airborne system cascading propagation model and through the fault propagation path analysis algorithm, the fault propagation paths and combinations of fault propagation paths that lead to system failure during the system cascading failure process are solved. Thus, the accuracy of cascading failure analysis can be improved through the above method. Description of the Drawings

[0042] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0043] Figure 1 It is a schematic flowchart of a model-based cascading failure analysis method for an airborne system provided by an embodiment of the present application;

[0044] Figure 2 It is a system modeling architecture diagram provided by an embodiment of the present application;

[0045] Figure 3 It is a cascading propagation model diagram provided by an embodiment of the present application;

[0046] Figure 4 It is an algorithm diagram of the VF2 algorithm provided by an embodiment of the present application;

[0047] Figure 5 It is a flowchart of the DWNodeRank algorithm provided by an embodiment of the present application;

[0048] Figure 6 It is a flowchart of the fault propagation path analysis algorithm provided by an embodiment of the present application;

[0049] Figure 7It is the architecture diagram of the flight control system of a certain type of aircraft provided by an embodiment of the present application;

[0050] Figure 8 It is the nominal model diagram of the flight control system provided by an embodiment of the present application;

[0051] Figure 9 It is the fault propagation model diagram of the left aileron sensor assembly provided by an embodiment of the present application;

[0052] Figure 10 It is the fault propagation model diagram of the left aileron control system provided by an embodiment of the present application;

[0053] Figure 11 It is the sub-component relationship matrix diagram provided by an embodiment of the present application;

[0054] Figure 12 It is the component layer node connection matrix diagram provided by an embodiment of the present application;

[0055] Figure 13 It is the component layer - function layer connection matrix diagram provided by an embodiment of the present application;

[0056] Figure 14 It is the function layer - system layer connection matrix diagram provided by an embodiment of the present application;

[0057] Figure 15 It is the cascade propagation model diagram of the flight control system of a certain type of aircraft provided by an embodiment of the present application;

[0058] Figure 16 It is the AADL model abstraction diagram of the flight control system provided by an embodiment of the present application;

[0059] Figure 17 It is the cascade propagation model abstraction diagram of the flight control system provided by an embodiment of the present application. Detailed implementation manners

[0060] In the following description, for the purpose of illustration rather than limitation, specific details such as specific system structures, technologies, etc. are put forward to thoroughly understand the embodiments of the present application. However, those skilled in the art should clearly understand that the present application can also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid unnecessary details from interfering with the description of the present application.

[0061] It should be understood that when used in the specification of the present application and the appended claims, the term "comprising" indicates the presence of the described features, wholes, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or their combinations.

[0062] It should also be understood that the term "and / or" as used in the specification of this application and the appended claims refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations.

[0063] As used in the specification of this application and the appended claims, the term "if" may be construed, depending on the context, as "when", "once", "in response to determining", or "in response to detecting". Similarly, the phrases "if determined" or "if [the described condition or event] is detected" may be construed, depending on the context, to mean "once determined", "in response to determining", "once [the described condition or event] is detected", or "in response to detecting [the described condition or event]".

[0064] In addition, in the description of the specification of this application and the appended claims, the terms "first", "second", "third", etc. are used only for distinguishing descriptions and should not be construed as indicating or implying relative importance.

[0065] Reference to "one embodiment" or "some embodiments" or the like described in the specification of this application means that a specific feature, structure, or characteristic described in connection with that embodiment is included in one or more embodiments of this application. Thus, statements such as "in one embodiment", "in some embodiments", "in other some embodiments", "in still other embodiments", etc. that appear in different places in this specification do not necessarily all refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in another way. The terms "comprising", "including", "having", and their variants all mean "including but not limited to", unless otherwise specifically emphasized in another way.

[0066] The method for analyzing cascading failures of a model-based airborne system provided by this application will be described in detail below with reference to the accompanying drawings.

[0067] Figure 1 The flowchart of a method for analyzing cascading failures of a model-based airborne system provided by an embodiment of this application is shown.

[0068] As Figure 1 shown, the method for analyzing cascading failures of a model-based airborne system includes the following steps:

[0069] S1: Construct an airborne system model for cascading failures based on the architecture design modeling language AADL. The system model includes a nominal model and a fault propagation model.

[0070] Further, in the embodiment of this application, the above step S1 includes:

[0071] S101: When the system model is a nominal model, divide the system model into a system level, a function level, and a component level. Represent the components at each level of the system model through the predefined components of the AADL model, and then declare the sub-components and connection interaction relationships of each component to complete the construction of the nominal model;

[0072] S102: When the system model is a fault propagation model, describe the fault propagation impact between components, the impact of component faults on functions, and the impact of function faults on the system state by declaring the fault propagation behavior, component error behavior, and composite error behavior of each component to complete the construction of the fault propagation model.

[0073] In an embodiment of the present application, to analyze the cascading failure of the system, the established model needs to include system architecture information and fault propagation information between components. The airborne system model for cascading failure includes two parts:

[0074] (1) Construction of the airborne system nominal model for cascading failure. Since AADL modeling has a high degree of freedom, to standardize the modeling project and at the same time consider the information required by the model, an airborne system model architecture is proposed as Figure 2 shown, dividing the system components into a system level, a function level, and a component level.

[0075] Then use AADL components to describe system components, functions, and the system, corresponding to component-level components, function-level components, and system-level components in the system model architecture respectively. The AADL components and their meanings are shown in Table 1 below:

[0076] Table 1 AADL Components and Their Meanings

[0077]

[0078] For the system itself, it can be represented by the "system" or "abstract" component; for system functions, it can be represented by the "system" or "abstract" component; for system components, appropriate components can be selected according to the component functions. The "device" component can be selected for sensor components, and the "memory" component can be selected for memories.

[0079] Then declare the hierarchy of each component to declare the system architecture, that is, declare that the function-level components in the airborne system are the sub-components of the system-level components, and the component-level components are the sub-components of the function-level components.

[0080] Finally, declare the connection relationships between components to describe the information propagation behaviors such as data transmission between components inside the system. Complete the components of the airborne system nominal model for cascading failure.

[0081] (2) Construction of a system fault propagation model for cascading failures. By constructing an airborne system error annex library, the fault propagation types between system components and the error behavior state machines of components at all levels can be declared. The error behavior state machines can declare the error states, error events, and state transitions due to error events of components at all levels. The declaration format for error types is "ErrorName:type;", and the declaration formats for error events, error states, and state transitions in the error behavior state machines are: "EventName:error event;", "StateName:state;", "TrasitionName:State1-[errorevent]->State2;" respectively.

[0082] For component-level components, such components only have two states: normal and faulty states. For function-level components, they have two states: normal and function-faulty states. For system-level components, multiple error states can be defined.

[0083] In the "propagationpaths" module of the function-level component, the fault propagation between component-level components is declared to describe the fault propagation behavior between component-level components. The declaration format is "PathName:SubcomponentA.InputPort1->SubcomponentB.OutputPort2;".

[0084] By constructing composite error behaviors, the mapping from the failure modes of system subsystems to the error states of the system itself can be defined in the "composite errorbehavior" module of the component fault propagation model. Since only components with sub-components have composite error behaviors, in the airborne system AADL model, only system-level components and function-level components have composite error behaviors. In system-level components, by declaring the state transitions of the system when a single function fails or a combination of multiple functions fails in the system, the impact of system function failures on the system is described. In function-level components, by declaring the state transitions of the function component when a single component fails or a combination of multiple components fails in the function component, the impact of component failures on the system function is described. The declaration format for composite error behaviors is: "[LogicalWord{Subcomponents.State}]->State;", and the logical words used include: AND logic (And) and voting logic (Ormore), and the voting logic is represented by "1Ormore" for OR logic.

[0085] For functional-level components, they also have two states. When a state transition occurs, it can only change from the normal state to the faulty state. However, the state of a functional-level component is only related to the combination of the states of its sub-components, and there is no error event that causes a functional failure. Therefore, the functional component fault propagation model includes composite error behavior, declaring that a fault in a sub-component within a functional component leads to a fault in the functional-level component.

[0086] In addition, in a functional-level component, the propagation path of an error can be declared through the error propagation path. Therefore, the error behavior of a functional component also includes error propagation behavior, declaring the fault influence relationship between its sub-components.

[0087] For system-level components, there are multiple failure states, and the specific state they are in is only related to the combination of the states of functional-level components. Therefore, the system-level component fault propagation model only includes composite error behavior, declaring that a fault in a functional-level component leads to a change in the system state.

[0088] S2: Instantiate the system model in S1 to obtain an instantiated aaxl2 file.

[0089] In an embodiment of the present application, for the instantiated aaxl2 file, the AADL model is built in a package. So the top-level node is Package, ownClassifier represents a component, subcomponent represents a sub-component declaration, ownPortConnection represents a port connection declaration, ownAnnexSubclause represents an annex declaration. The annex declaration includes state transitions (transition), error propagations (propagations), error states (states), property declarations (properties), etc. The descriptions of each node in the aaxl2 file are shown in Table 2.

[0090] Table 2 Description of the aaxl2 file node information

[0091]

[0092] S3: Use XML information extraction technology to extract components at each level, the connection relationships between components, and fault propagation information from the instantiated aaxl2 file, for constructing an airborne system cascading propagation model, and verify the consistency of the AADL model and the cascading propagation model based on the graph isomorphism method.

[0093] Further, in an embodiment of the present application, the elements of the airborne system cascading propagation model in step S3 above include component layer nodes B = {b 1 , b 2 ,..., b n}, functional layer nodes F = {f 1 , f 2,..., f m} and the system layer nodes S = {s 1 , s 2 ,…, s k};

[0094] Component layer node connection matrix M bb is as follows:

[0095]

[0096] where takes a value of 0 or 1. When , it means that system component i connects or propagates an error to component j; when , it means that there is no interaction between component i and component j;

[0097] Component layer - function layer connection matrix M fb is as follows:

[0098]

[0099] where takes values of logical words "and" and "or". When and , it means that when components j and j + 1 fail, system function i fails; when , it means that when component j fails, function i fails;

[0100] Function layer - system layer connection matrix M sf is as follows:

[0101]

[0102] where, takes a value of 0 or 1. When , it means that system component i connects or propagates an error to component j; when , it means that there is no interaction between component i and component j.

[0103] Furthermore, in another embodiment of the present application, the process of constructing the cascade propagation model based on XML information extraction in step S3 includes:

[0104] Using the Python ElementTree module to extract the system - level components, function - level components, component - level components, the connection relationships between components, and the fault propagation information from the aaxl2 file, and then constructing the cascade propagation model according to the mapping relationship between the AADL model and the cascade propagation model;

[0105] Construct the component layer nodes of the cascading propagation model by extracting component-level components, and extract the connection relationships and fault propagation relationships between component-level components to construct the connection matrix of the component layer nodes of the cascading propagation model; extract the function-level components of the component cascading propagation model's function layer nodes, and extract the state transition logic in the composite error behavior of the function-level components to construct the component layer - function layer connection matrix; extract the error state of the system-level components of the component cascading propagation model's system layer nodes, and extract the state transition logic in the composite error behavior of the system-level components to construct the function layer - system layer connection matrix.

[0106] In an embodiment of the present application, the AADL model information is extracted based on the XML information extraction method to construct an airborne system cascading propagation model. The cascading propagation model is as Figure 3 shown. The element mapping relationship between the AADL model and the cascading propagation model is shown in Table 3. The specific construction process includes: constructing the component layer of the cascading propagation model, constructing the function layer of the cascading propagation model, and constructing the system layer of the cascading propagation model.

[0107] Table 3 Element mapping relationship between AADL model and cascading propagation model

[0108]

[0109] (1) First, determine all components of the AADL model. The components in the AADL model can be divided into two categories: component types and implementation types. A component can define multiple implementation types, but can only uniquely define one component type. Therefore, by determining all component types in the AADL model, all components in the model can be determined. The types and names of each component are declared in the attributes of the "classifier" node. By extracting the attributes of the "classifier" node, the types of each component can be determined. By extracting the components of the component type, all components in the model can be determined.

[0110] After determining all components in the AADL model, determine the hierarchy of each component by judging whether a component is a sub-component of other components. According to the information of the "ownedSystemSubcomponent" node in the AADL model, the component without sub-components is a component-level component, the component with component-level components as sub-components is a function-level component, and the component with function-level components as sub-components is a system-level component. Among them, the component-level component corresponds to the component layer node.

[0111] Establish a connection matrix C, which is a zero matrix with the dimension of the number of component-level components. The connection information between component-level components is included in the functional components. Extract the information of the "ownedPortConnection" node in the functional-level components, and determine the source sub-component and target sub-component of the connection between components through the sub-nodes "source" and "destination". Then set the corresponding element in the connection matrix C to 1. After traversing all the functional-level components, the connection matrix C is obtained.

[0112] Establish a fault propagation matrix F, which is a zero matrix with the dimension of the number of component-level components. The fault propagation information between component-level components is included in the functional components. Extract the information of the "paths" node in the functional-level components, and determine the source sub-component and target sub-component of the fault propagation between components through the sub-nodes "source" and "target". Then set the corresponding element in the fault propagation matrix F to 1. After traversing all the functional-level components, the fault propagation matrix F is obtained.

[0113] Add matrix C and F and then normalize the matrix to obtain the component layer connection matrix.

[0114] (2) The functional-level components correspond to the nodes in the functional layer. Determine the composite error behavior of the functional-level components, that is, extract the statement of the "ownedAnnexSubclause" node. Determine the fault conversion logic by judging whether there are logical keywords "And" and "Ormore" in the composite error behavior, which can be divided into:

[0115] When there is the keyword "AND", by extracting the characters between the keyword "AND" and ".", the components involved in the sentence and the logical composite error behavior code can be determined. Set the corresponding element in the functional layer-component layer connection matrix to the logical word "AND".

[0116] When there is the keyword "ORMORE", by extracting the characters between the keyword "(", ",", and ".", the components involved in the voting logic composite error behavior of this sentence can be determined. Set the corresponding element in the functional layer-component layer connection matrix to the logical word "OR".

[0117] If there is no state transition logic keyword, it means that there is only one component involved in the composite error behavior of this sentence. Therefore, the component involved can be determined through the keyword ".". Set the corresponding element in the functional layer-component layer connection matrix to the logical word "OR".

[0118] (3) Since the states of system-level components are related to functional components, all the converted states in the composite error behavior of system-level components are extracted, that is, the nodes of the system layer of the cascade propagation model are determined. The declarations of the "ownedAnnexSubclause" nodes are extracted. The fault conversion logic is determined by judging whether there are logical keywords "And" and "Oomore" in the composite error behavior, which can be divided into:

[0119] When there is a keyword "And", by extracting the characters between the keyword "And" and ".", the components involved in the sentence and the logical composite error behavior code can be determined. The corresponding element in the system layer-functional layer connection matrix is set to the logical word "And".

[0120] When there is a keyword "Oomore", by extracting the characters between the keyword "(", ",", and ".", the components involved in the voting logic composite error behavior of this sentence can be determined. The corresponding element in the system layer-functional layer connection matrix is set to the logical word "Or".

[0121] If there is no state transition logic keyword, it means that there is only one component involved in the composite error behavior of this sentence. Therefore, the component involved can be determined by the keyword ".". The corresponding element in the system layer-functional layer connection matrix is set to the logical word "OR".

[0122] Furthermore, in another embodiment of the present application, the verification of the consistency between the AADL model and the cascade propagation model based on the graph isomorphism method in the above step S3 includes:

[0123] The components, functional components, and system error states in the AADL model are converted into nodes, the data interaction and fault effects between component-level components are converted into edges of the nodes, and the fault effects between functional-level and system-level components are converted into edges, obtaining the AADL graph model;

[0124] The nodes at all levels of the cascade propagation model are converted into nodes, and the connection relationships between the nodes are converted into edges, obtaining the cascade propagation graph model;

[0125] The AADL graph model and the cascade propagation graph model are used as the input of the VF2 algorithm, and by comparing the nodes of the two graph models, it is judged whether the two graph models are isomorphic.

[0126] In the embodiments of the present application, components, functional components, and system error states in the AADL model are abstracted as nodes, data interactions and fault impacts between component-level components are abstracted as edges of nodes, and fault impacts between functional-level and system-level components are abstracted as edges, obtaining an AADL graph model; nodes at all levels of the cascade propagation model are abstracted as nodes, and the connection relationships between nodes are abstracted as edges, obtaining a cascade propagation graph model; the AADL graph model and the cascade propagation graph model are used as inputs to the VF2 algorithm. By comparing the nodes of the two graph models, it is determined whether the two graph models are isomorphic. The VF2 algorithm is as Figure 4 shown.

[0127] S4: According to the airborne system cascade propagation model in S3, use system topology parameters to define the fault propagation intensity between components in the airborne system, and use the fault propagation intensity as the input of the DWNodeRank algorithm to output the fault impact degree between components, and combine the component failure rate to solve the fault propagation probability between components.

[0128] Further, in the embodiments of the present application, the definition of the fault propagation intensity between components in the above step S4 is as follows:

[0129]

[0130] where L dout is the out-degree centrality of the node, and L b is the betweenness centrality of the node.

[0131] Further, in the embodiments of the present application, using the fault propagation intensity as the input of the DWNodeRank algorithm in the above step S4 and outputting the fault impact degree between components includes:

[0132] Normalize the fault propagation intensity matrix, and use the vector (1 / n)e T to replace the rows that are all 0 in the normalized fault propagation intensity matrix to obtain a probability transition matrix, where n is the dimension of the matrix;

[0133] According to the probability transition matrix and a preset damping factor, construct the DWNodeRank matrix A; use the out-degree centrality of the node as the initial vector, and determine the fault impact degree of the nodes in the component layer of the cascade propagation model by iteratively obtaining the stationary distribution of the matrix A.

[0134] Further, in the embodiments of the present application, the definition of the fault propagation probability in the above step S4 is as follows:

[0135]

[0136] Pr(ij) = λ i A(e i→j )

[0137] where Ai and A j are the failure impact degrees of nodes i and j respectively. A(e i→j ) represents the failure impact degree of the connection edge between two nodes, and λ i is the failure rate of node i.

[0138] In an embodiment of the present application, the failure propagation intensity is defined as the cost for a node in the network to propagate a failure to other nodes. The greater the failure propagation intensity, the stronger the ability of the node to propagate a failure in the network. The out-degree centrality and betweenness centrality of a node are both related to the influence of the node in the network and are important factors for analyzing the degree of influence of a node failure on other nodes. The present application comprehensively considers the out-degree centrality and betweenness centrality of nodes in the network to define the failure propagation intensity of a node, representing the magnitude of the ability of a node in the network to propagate a failure. The expression is as follows:

[0139]

[0140] Among them, L dout is the out-degree centrality of the node, and L b is the betweenness centrality of the node. The propagation intensity of the connection edge between nodes is related to the failure propagation intensities of the two nodes. The failure propagation intensity of the edge is calculated through a coupling degree function, and the expression is as follows:

[0141]

[0142] Representing the failure propagation ability of a node through the failure influence propagation intensity does not comprehensively consider the mutual influence between nodes. The influence of a node will be updated according to the failure propagation ability of the connected nodes. The influence of the node is corrected through the DWNodeRank algorithm. The DWNodeRank algorithm process is as Figure 5 shown, and the specific steps are as follows:

[0143] (1) Calculate the propagation matrix H. H is used to describe the propagation relationship of a directed weighted network with n nodes. The elements in the matrix represent the failure propagation intensity between two nodes, and it is expressed as:

[0144] H = (h ij ) n×n

[0145] where the subscripts i and j represent the node numbers, n is the number of nodes in the network, and h ij represents the propagation intensity between nodes i and j.

[0146] (2) Calculate the transition matrix P. Divide the first row of the propagation matrix by the sum of the non-zero vectors in this row to obtain the normalized matrix P, and it is expressed as:

[0147]

[0148] (3) Process the dangling nodes. If a node i in the network has no connections pointing to other nodes, that is, no outgoing edges, it means that all values in the i-th row of the network's propagation matrix are 0. Such a node is a dangling node. Use the vector (1 / n)e T to replace the row with all elements being 0 in the matrix to process the dangling nodes in the transition matrix P:

[0149]

[0150] where η is a Boolean vector indicating whether a node is a dangling node. Being equal to 0 means the node v i is not a dangling node, and being equal to 1 means the node v i is a dangling node.

[0151] (4) Calculate the DWNodeRank matrix A:

[0152]

[0153] where α is the damping factor, and (P′) T represents the transpose of the matrix P′.

[0154] (5) Solve for the DWNodeRank value.

[0155] The core formula of the DWNodeRank algorithm is used to solve the DWNodeRank value, quantifying the node influence degree with specific scores. When the number of nodes is small, it can be solved by solving the system of equations. However, in actual operations, due to the large number of nodes, it cannot be obtained by the analytical method. The stationary distribution of the matrix A can be obtained through the idea of power method iteration. The solution process is as follows:

[0156] The matrix A has a real eigenvalue with a value of 1, and the eigenvector corresponding to this eigenvalue is the stationary distribution of the matrix. Initialize the iteration vector x to represent the initial DWNodeRank values of each node. Since the purpose of this part of the research is to obtain the influence of each node on other nodes, the out-degree centrality value of each node is taken as the initial value of the vector x, that is, x i takes the value of v i the out-degree centrality value of the node. Then calculate r = Ax through the power method iteration process. When the difference in the norms of the two vectors x and r is less than the specified value, at this time x is the stationary distribution of the matrix, otherwise continue the iteration to solve.

[0157] After the iteration ends, the operation result represents the node fault influence degree value. The greater the influence degree, the stronger the ability of the node fault to affect other nodes. The node influence degree combines with the node failure rate to define the node fault propagation probability as follows:

[0158]

[0159] Pr(ij) = λ i A(e i→j )

[0160] where, Ai and A j are the fault influence degrees of nodes i and j respectively, and A(e i→j ) represents the fault influence degree of the connecting edge between the two nodes, and λ i is the failure rate of node i.

[0161] S5: Represent the fault influence degree in S4 as the component importance, take the component faults with component importance greater than the preset threshold as the initial conditions of cascading failure, and use the on-board system cascading propagation model in S3. Through the fault propagation path analysis algorithm, solve the fault propagation paths and the combinations of fault propagation paths that lead to system failure in the process of system cascading failure.

[0162] Further, in an embodiment of the present application, the implementation process of the fault propagation path analysis algorithm in the above step S5 is as follows:

[0163] S501: Take the node influence degree as the importance value, select the nodes with importance value greater than the preset threshold as the starting nodes for cascading failure analysis, and use the starting nodes, cascading propagation model, given propagation order, and path probability requirement as the input of the fault propagation path analysis algorithm;

[0164] S502: Obtain the fault paths after the first fault propagation according to the starting nodes and the component layer node matrix. For each fault propagation path, judge the influence of the path on the system function according to the function layer-component layer connection matrix, and judge the influence of the path on the system state according to the system layer-function layer connection matrix, obtain all single fault paths that lead to system failure, and calculate the path propagation probability, and retain the fault propagation paths that meet the preset probability requirement;

[0165] S503: For the path combinations, after excluding the single paths that will lead to system failure, arrange and combine the remaining paths, identify the path combinations that will lead to system failure according to the function layer-component layer connection matrix and the system layer-function layer connection matrix, and calculate the propagation probability of the path combinations, and retain the fault propagation path combinations that meet the preset probability requirement;

[0166] S504: If the fault propagation order has not reached the preset given value, start from the last node of the current path and continue the next-order fault propagation and path analysis until the specified propagation order is reached, and output the fault propagation paths and the combinations of fault propagation paths that lead to all system failures.

[0167] In an embodiment of the present application, when a component with a great influence in the system fails, it may have a greater scope of fault impact and is more likely to cause the system to fail. Therefore, the present application uses the influence degree of a node as the importance value of the node, and believes that a node with a greater influence degree, that is, a node with great influence, has a higher importance in the system. And sort the importance of nodes according to the influence of the nodes, take the failure of nodes with higher importance in the network as the initial state of cascading failure, and use it as the input of the fault propagation path analysis algorithm proposed in the present application.

[0168] The input of the fault propagation path analysis algorithm includes: a cascading propagation model, a propagation order, a path probability requirement, and a starting node. The algorithm flow chart is as Figure 6 shown, and mainly includes the following steps:

[0169] Step 1: Generate the fault path and the scope of fault impact after the first fault propagation according to the neighbor nodes of the starting node.

[0170] According to the starting node and the component layer node connection matrix M bb of the cascading propagation model, the neighbor nodes of the node in the component layer can be obtained. The starting node and the neighbor nodes are combined respectively to obtain the propagation path and the scope of fault impact of the first propagation, that is, the initial node propagates the fault to all its neighbor nodes respectively. For example, if the initial fault node is i and the node has two neighbor nodes j and k, two fault propagation paths can be obtained: i→j, i→k, and the scope of fault impact is: j and k. For the generated paths, judge the impact of a single path or a combination of paths on the function layer nodes.

[0171] Step 2: Judge whether there is a single path in the fault path that causes functional failure or system failure. If there is a path, it is necessary to judge whether the path meets the probability requirement. Then obtain the combination of fault propagation paths that can cause functional failure or system failure, and judge whether the combination of paths meets the probability requirement. Output the path or combination of paths that cause functional failure or system failure and meet the probability requirement, and the current scope of fault impact.

[0172] Before considering the impact of the path on the system function or system state, it is first necessary to judge the impact of component failure on the function and the impact of functional failure on the system state according to the cascading propagation model. According to the function layer-component layer node connection matrix M fb of the cascading propagation model, the set of fault components corresponding to a certain functional failure in the system can be determined M fb The logical words in include "and" and "or". According to M fbIn the row vector, extract the elements with the same logical word to obtain a component failure set in the case of a functional failure. When multiple elements in the row vector are "and", it means that when the components corresponding to these elements are all faulty, the corresponding functional component failure can determine a component failure set. When k elements are "or", it means that the failure of one of these components can lead to a functional failure, and k component failure sets can be obtained. For example, in M fb In the row vector corresponding to function f, the i-th and j-th elements are both "and", and the m-th and n-th elements are both "or". It can be obtained that three component failure sets lead to the failure of function f, namely {i, j}, {m} and {n}. Similarly, when judging the impact of functional failure on the system state, the function layer-system layer connection matrix M in the cascade propagation model is used. sf By analyzing the elements with the same logical words in the row vector, the set of fault functions corresponding to the corresponding system failure state can be obtained.

[0173] When considering the impact of a single path, if the component layer node set that causes the function i failure is is the set of nodes on the kth path A subset of Then this path will cause function i to fail. By judging the impact of all the first generated paths on all functions, the set of fault functions at the end of the first propagation can be obtained. Similarly, if the fault function list of the current cascade failure process contains all the fault functions corresponding to a certain system failure state, the system will be in this failure state. Considering the fault function list caused by each path, all single fault paths that will cause system failure or functional failure at the end of the first propagation can be identified, and then the probability of each fault propagation path can be calculated. If the probability requirement is met, the path is output.

[0174] When considering the impact of path combination on the system, the path that has caused the system to be in a faulty state is not considered, and the remaining paths are arranged and combined to obtain the component layer node set under the path combination. Compare the component layer fault node set when each functional layer node fails If the intersection of the component layer node set under the path combination and the component layer fault node set when the function layer node fails is the component layer fault node set when the function layer node fails, and there is a path in the combined path whose last node is in the component layer fault node set when the function layer node fails, then Then the path combination will cause the corresponding function to fail. Obtain the failed function and the path combination that causes the path failure. Then determine whether the fault function list corresponding to the system failure state is a subset of the current fault function list. Determine the system failure state, identify the path combination that affects the system state, calculate the probability of the path combination, and output the path combination and fault impact range that meet the probability requirements.

[0175] When the failure probability of the control system is less than 10 -8 , as the failure propagates, the failure probability will decrease step by step, and the system is considered a safe system. Therefore, for a single failure propagation path or a combination of paths, this application ignores the influence of paths with a probability less than the set probability threshold and focuses on paths with a probability greater than the probability threshold. The path probability threshold of this application is 10 -8 , that is, the probabilities of the failure propagation paths output in the path analysis process are all greater than 10 -8 . The calculation method of the path probability is as follows:

[0176] (1) For a single path, the probability of the path can be obtained through the failure propagation probability between the nodes in the path, expressed as:

[0177]

[0178] Among them, γ represents the number of edges in the path, and P k (e i→j ) is the failure propagation probability of an edge in the path.

[0179] (2) For a combination of paths, since there must be a last node of one path in the set of component layer nodes that affect the function, the combination paths are divided into two categories: complete paths and incomplete paths. For complete paths, the calculation method of the single path propagation probability is used. For incomplete paths, the path needs to be intercepted, and the probability of the path from the starting node to the node in the set of component layer nodes that affect the function is calculated, and then the probabilities of the two paths are multiplied, which is the propagation probability of the combination path, expressed as:

[0180]

[0181] Among them, P Lcomplete represents the complete path probability, and γ 1 is the number of edges in the complete path. P Lincomplete represents the probability of the incomplete path, and γ 2 is the number of edges in the incomplete path.

[0182] Step 3: Determine whether the cascade propagation order has been reached. If not, perform the next-order failure propagation. If it has been reached, stop the search.

[0183] Step 4: According to the neighbor nodes of the termination node of the failure propagation path in the previous order, obtain the failure propagation path of this order and add the neighbor nodes of the path termination node to the failure influence range, and return to Step 2.

[0184] The model-based cascading failure analysis method provided by this application first constructs an airborne system model for cascading failure based on the architecture design modeling language AADL. The system model includes a nominal model and a fault propagation model. The system model is instantiated to obtain an instantiated aaxl2 file. Using XML information extraction technology, the components at each level, the connection relationships between components, and the fault propagation information are extracted from the instantiated aaxl2 file to construct an airborne system cascading propagation model. Then, based on the graph isomorphism method, the consistency between the AADL model and the cascading propagation model is verified. Next, according to the airborne system cascading propagation model, the fault propagation intensity between components inside the airborne system is defined using system topology parameters, and the fault propagation intensity is used as the input of the DWNodeRank algorithm to output the fault influence degree between components. The fault propagation probability between components is solved by combining the component failure rate. Finally, the fault influence degree is expressed as the component importance, and the component failures with component importance greater than the preset threshold are used as the initial conditions for cascading failure. Using the airborne system cascading propagation model and through the fault propagation path analysis algorithm, the fault propagation paths and combinations of fault propagation paths that cause system failure during the system cascading failure process are solved. Thus, the accuracy of cascading failure analysis can be improved through the above method.

[0185] The following takes the flight control system of a certain type of aircraft as an example to illustrate the analysis method provided by this application.

[0186] The architecture of the flight control system of a certain type of aircraft is as Figure 7 shown. The flight control system is a typical safety-critical system. The failure of this system or partial functional faults will have a serious impact on the flight safety of the aircraft. This type of flight control system consists of a flight control computer system, a control surface drive mechanism, a sensor system, and control surfaces. Its main function is to collect the instructions issued by the pilot and the input signals of the sensors during flight. After being processed by the flight control computer, it actuates the control surfaces through the control surface drive mechanism. The flight control computer subsystem of the flight control system has a dual-redundancy architecture and is composed of two identical primary flight computers (PFCs). The architectures of the two computers are basically the same. They receive sensor data, perform command calculations and outputs, and thus control the flight attitude of the aircraft. The control surface drive mechanism includes a left aileron actuator (LAA), a right aileron actuator (RAA), and a rudder actuator (RA). Its main function is to drive the corresponding control surfaces to actuate. The sensor system includes a right aileron position sensor (RAPS), a left aileron position sensor (LAPS), and a rudder position sensor (RPS). Its main function is to collect the angle information of each control surface. The inertial measurement unit (IMU) is used to calculate the angle change of the aircraft. The control surfaces of the aircraft include a left aileron (Left_aileron), a right aileron (Right_aileron), and a rudder (Rudder).

[0187] The corresponding relationship between AADL components and components of a certain type of flight control system is shown in Table 4:

[0188] Table 4 Components of the flight control system corresponding to components

[0189]

[0190] After establishing the mapping relationship between AADL components and system components, functions, and systems, it is necessary to establish the connection relationship of the components, that is, to declare the transmission direction of data in the system. Taking the left aileron control function in the system as an example, the connection relationship among its seven sub-components is as follows: LAPS is connected to the LA_angle_d port of PFC1 through the port LA_angle_d, indicating that the left aileron sensor transmits the measured left aileron angle information to the first flight control computer. In addition to the first flight control computer, the left aileron sensor data is also transmitted to the IMU and the second flight control computer. The two flight control computers are also connected through data ports to compare the data of the two computers. After receiving the sensor data and IMU data, the two flight control computers transmit the processed data to the first flap drive mechanism and the second flap drive mechanism respectively, that is, the roll_command1 port of PFC1 is connected to the roll_command1 port of LAA1, and the roll_command2 port of PFC2 is connected to the roll_command2 port of LAA2. LAA1 and LAA2 transmit data to the left aileron Left_aileron through their output ports.

[0191] Similarly, by establishing the connection relationship among the sub-components of the right aileron control function and the rudder control function, the nominal model of the flight control system can be obtained, as Figure 8 shown.

[0192] Taking the left aileron sensor as an example, the method for constructing the fault propagation model of component-level components is described, as Figure 9 shown. First, the error behavior state machine comp of the component-level component is called. In the error propagation behavior (error propagations module), it is declared that the component will transmit the propagation error Fault_p through its data output port LA_angle_d. In the component error behavior, the error event failure that causes the component state transition due to its own error is defined. When the error event occurs, the component state will change from working to failed, as shown in the "transitions" module. In the "propagation" module of the component error behavior, it is declared that the error will be propagated through the output data port only when the component is in the failed state.

[0193] Taking the left aileron control system as an example, the method for constructing the fault propagation model of function-level components is described, asFigure 10 As shown. The function - level component calls the Function error behavior state machine. In its composite error behavior, it is declared that when the left aileron component (left_aileron) fails, the function component will transition from the normal (working) state to the malfunction state, as shown in the "state" module in "composite error propagation". In the error path declaration, the error propagation path between sub - components is declared. As shown in path1, it is declared that the error will propagate from LAA2 to left_aileron, that is, the failure of the No. 2 left aileron drive mechanism will affect the left aileron.

[0194] The component error behavior state machine called by the system component is PFCS. In its composite error behavior, when the function component Ru_control fails (in the malfunction state), the system is in the turn_hard state, indicating that when the rudder control function fails, the flight control system has difficulty turning. When the LA_control and RA_control functions fail simultaneously, the system is in the tumbling_hard state, indicating that when the left and right aileron control functions fail, the system has difficulty tumbling.

[0195] To construct the component layer of the cascade propagation model, it is first necessary to determine the component - layer nodes. By extracting all components in the AADL model and judging whether they are sub - components of other components, the levels of each component can be determined. The components are divided into: system - level components, function - level components, and component - level components. Among them, the component - level components correspond to the component - layer nodes of the cascade propagation model. A total of 19 components are extracted from the example object AADL model. According to the sub - component declarations of each component in the model, the sub - component relationship matrix S is extracted as Figure 11 shown.

[0196] Table 5 AADL components at all levels

[0197]

[0198] By extracting the connection relationships and fault propagation information of component - level components, after summing and normalizing the component connection matrix and the fault propagation matrix, the component - layer node connection matrix is obtained as Figure 12 shown.

[0199] Extracting the composite error behavior of each function component can determine the impact of component - level component failures on function - level components, that is, obtaining the impact of component - layer nodes on function - layer nodes in the cascade propagation model. The function - layer - component - layer connection matrix is as Figure 13 shown.

[0200] In the cascade propagation model, the nodes at the system layer represent the state of the system. By extracting the composite error behaviors of system components, the impact of faults in functional-level components on the system state can be determined, and the components at the system layer of the cascade propagation model and the system-layer to functional-layer connection matrix can be obtained as Figure 14 shown.

[0201] The cascade propagation model of a certain type of flight control system is obtained as Figure 15 shown.

[0202] The steps to abstract the AADL model of the flight control system into a graph model are as follows:

[0203] (1) Abstract the components in the AADL model into nodes in the graph model, and add connection edges between the nodes according to the connection and fault propagation relationships between the nodes at the component layer.

[0204] (2) According to the mapping rules from the AADL model to the cascade propagation model, add functional-level components as nodes in the graph model, and abstract the influence relationship between the functional-level components and the component-level components into connection edges.

[0205] (3) Add system-level components in the graph model, and abstract the influence relationship into edges according to the influence relationship between the functional components and the system components, to obtain the abstract graph model as Figure 16 shown. Abstract the nodes at each layer in the cascade propagation model into nodes in the graph model, and abstract the connection edges between the nodes into the edges of the graph model, to obtain the abstract graph model as Figure 17 shown.

[0206] Taking the graph model abstracted from the AADL model and the graph model abstracted from the cascade propagation model as the input of the graph isomorphism verification algorithm, it can be verified that the two graph models are isomorphic, and then it is proved that the process of converting from the source AADL model of the flight control system to the cascade propagation model is correct, and it is verified that the AADL model is consistent with the converted cascade propagation model and there is no information omission.

[0207] The component layer of the cascade propagation model constitutes a topological network model, and the topological parameters of each node are shown in Table 6:

[0208] Table 6 Network topological parameters of the component layer of the cascade propagation model

[0209]

[0210] According to the coupling degree function, the fault propagation intensity matrix Pd between each node in the network can be calculated. Taking the matrix Pd as the input of the DWNodeRank algorithm, the DWNodeRank matrix A is obtained as follows:

[0211]

[0212] Taking the out-degree centrality of the nodes as the initial vector, the initial vector is as follows: [0.214 0.214 0.214 0.142 0.286 0.286 0.071 0.071 0.071 0.071 0.071 0.071 0 0 0]

[0214] Taking the damping coefficient as 0.85, the influence degrees of each node are calculated as shown in Table 7:

[0215] Table 7 Influence Degrees of Nodes in the Component Layer of the Cascade Propagation Model

[0216]

[0217] As can be seen from Table 7, nodes PFC1 and PFC2 have the highest influence degrees. When these nodes fail, they are more likely to affect other nodes. Followed by the IMU node, the nodes with the weakest influence degrees include: LEFT_Aileron, RIGHT_Aileron, RUDDER, LAPS, RAPS, and RPS. In the flight control system, the flight control computer is the core component, which is responsible for receiving IMU information and the rudder surface position information of the rudder surface sensor, combining the input signals of the pilot's joystick and pedals, and calculating control commands for the rudder surface drive mechanism. If the flight control computer fails, it will affect multiple components in the system, so the flight control computer has a relatively large influence degree. Similarly, in the network of the component layer of the cascade propagation model, each rudder surface only receives information from the rudder surface drive mechanism and has no outgoing edges connected to other components, so each rudder surface has the smallest influence degree.

[0218] Table 8 Influence Degrees and Failure Rates of Nodes in the Component Layer

[0219]

[0220] Set the failure rates of the nodes as shown in Table 8. Combining the influence degree values and failure rates of the nodes, calculate the failure propagation probability values of each connection edge in the component layer, and obtain the failure propagation probability matrix Pr as follows. The nodes represented by the row vectors and column vectors in matrix Pr are the same as those in matrix A of DWNodeRank.

[0221]

[0222] According to the influence degrees of each component, the importance degrees and their rankings of each component in the flight control system are shown in the table. Among the nodes in the component layer of the cascade propagation model, the importance degrees of the nodes are divided into four categories. Among them, PFC1 and PFC2 have the highest importance degrees, followed by IMU. The importance degrees of LAPS, RAPS, and RPS are the third level. The importance degrees of the nodes such as LAA1 and LAA2 representing the rudder surface drive mechanism and rudders such as Left_aileron are the lowest.

[0223] This application takes the nodes PFC1 and PFC2 with the highest importance and the failure of the IMU component with the second highest importance as the initial state of cascading failure. Through the above-mentioned fault propagation path analysis algorithm, the system cascading effect is analyzed, and the single paths and path combinations that cause system failure are respectively identified when the failures of PFC1, PFC2, and IMU nodes are used as the initial states.

[0224] (1) Analysis of the impact of system cascading failure when PFC1 fails

[0225] Set the order of analyzing the fault propagation path to 2. When the PFC1 node fails, the neighbor nodes of PFC1 include: PFC2, LAA1, RAA1, and RA1. The first-stage propagation paths are shown in Table 9.

[0226] Table 9 First-order fault propagation paths when PFC1 fails

[0227]

[0228] According to the component-layer - function-layer connection matrix M fb and the function-layer - system-layer connection matrix M sf , the function-layer node fault conditions and system-layer node conditions can be obtained, as shown in Table 10. For example, the LA_control function failure may be caused by two situations: the simultaneous failure of LAA1 and LAA2, or the failure of Left_aileron. In the first-order fault propagation paths, no single path or path combination will cause the system's functional failure, so there is no single path or path combination that causes system failure, and no first-order fault paths need to be output. The list of first-order affected nodes in cascading failure, that is, the first-order fault influence range when PFC1 fails is: PFC2, LAA1, RAA1, and RA1.

[0229] Table 10 Conditions for functional failure and system failure

[0230]

[0231] Taking the neighbor nodes of the last node in the first-order propagation path as the propagation target nodes, the second-order propagation paths are identified as shown in Table 11.

[0232] Table 11 Second-order fault propagation paths when PFC1 fails

[0233]

[0234] Considering the impact of a single path on the function, there are three paths that will cause functional-layer node failures, and the probabilities of the corresponding propagation paths are shown in the table. Since the probability threshold is set to 10 -8 , that is, greater than the probability 10 -8All paths are dangerous paths. Therefore, for the path "PFC1→RA1→Rudder", this path will cause the function Ru_control to fail, and at the same time the system is in the failure state turn_hard, with a probability of 2.06×10 -8 , which meets the probability requirement, so this path is a dangerous path of the system. The paths "PFC1→RAA1→Right_aileron" and "PFC1→LAA1→Left_aileron" will not cause the system to be in a failure state. When the two paths are combined, the system will be in the failure state tumbling_hard, but they will respectively cause the functions RA_control and LA_control to fail. These two paths are also regarded as the output of dangerous paths in the system. For second-order fault propagation paths, only the dangerous paths are output.

[0235] Considering path combinations again, since path 6 can respectively cause the function Ru_control to fail and the system to be in a failure state, this path is not considered repeatedly in combination with other paths. Some combination cases among the remaining paths are shown in Table 12. When path 1 and path 4 are combined, when path 1 propagates the fault to LAA2, previously, LAA1 has failed. Therefore, the combination of the two paths can cause the function LA_control to fail. Similarly, when path 2 and path 5 are combined, it will cause the function RA_control to fail. The probabilities of both path combinations are 1.115×10 -13 , neither of which meets the probability requirement, so the danger of the combined path can be ignored and the path combination cases do not need to be output. When path 4 and path 5 are combined, the functions RA_control and LA_control fail simultaneously, and the system is in the failure state tumbling_hard, but the fault probability is less than the probability threshold, so it is not output either. Similarly, the combination of paths 1, 2, 4, and 5 is not output due to the too small probability.

[0236] When PFC1 fails, the scope of second-order fault impact is: PFC2, LAA1, RAA1, RA1, LAA2, RAA2, RA2, Left_aileron, Right_aileron, and Rudder.

[0237] Table 12 Fault Propagation Path Combinations when PFC1 Fails

[0238]

[0239] (2) Analysis of the Impact of Cascading Failure of the System when PFC2 Fails

[0240] When the important node PFC2 fails, the fault propagation paths in the system are shown in Table 13. After the first-order propagation ends, there is no single path or combination of paths that causes system functional failure or system failure. The fault influence scope is: PFC1, LAA2, RAA2, and RA2.

[0241] Table 13 Fault Propagation Paths when PFC2 Fails

[0242]

[0243] After the second-order propagation ends, it is identified that the path "PFC2→RA2→Rudder" will cause the system Ru_control function to fail, resulting in the system being in the turn_hard state. At the same time, the path probability is 1.97×10 -8 , which is greater than the probability requirement and is a dangerous path of the system. The path "PFC2→LAA2→Left_aileron" will not cause the system to be in a fault state, but will cause the system LA_control function to fail and is a dangerous path of the system. Similarly, the path "PFC2→RAA2→Right_aileron" will not cause the system to be in a fault state, but will cause the system RA_control function to fail and is also a dangerous path of the system. When considering the influence of a single path, only the identified dangerous paths are output.

[0244] All first-order path combinations with PFC2 failure as the initial condition will not affect the state of the system or function. Some cases of the second-order path combinations are shown in Table 14, which is similar to the fault path combinations with PFC1 failure as the initial state. All combinations are not output because the path probabilities are less than the probability threshold. The second-order fault influence scope is: PFC1, LAA1, RAA1, RA1, LAA2, RAA2, RA2, Left_aileron, Right_aileron, and Rudder.

[0245] Table 14 Fault Propagation Path Combinations when PFC2 Fails

[0246]

[0247] (3) Analysis of the Influence of System Cascade Failure when IMU Fails

[0248] When the IMU fails, the identified fault propagation paths in the system are shown in Table 15.

[0249] Table 15 Fault Propagation Paths when IMU Fails

[0250]

[0251] When the first-order fault propagation ends and the second-order fault propagation ends, there is no single path that can lead to system functional failure and system failure. However, during the second-order fault propagation, the combination of some fault propagation paths will lead to system functional failure, thus affecting the system state. The path combination is shown in Table 16. For example, the combination of the second-order paths "IMU→PFC1→LAA1" and "IMU→PFC2→LAA2" can lead to the failure of the function LA_control, but the occurrence probability of the combined path is 8.21×10 -17 , which is less than the probability threshold, so it can be ignored. Similarly, the combination of the paths "IMU→PFC1→RAA1" and "IMU→PFC2→RAA2" will lead to the failure of the function RA_control, and the combination of the paths "IMU→PFC1→RA1" and "IMU→PFC2→RA2" will lead to the failure of the function Ru_control, and even cause the system to be in the turn_hard state. However, due to its occurrence probability being less than the probability threshold, the harm of this path combination can be ignored. The scope of the second-order fault impact is: PFC1, PFC2, LAA1, LAA2, RAA1, RAA2, RA1 and RA2.

[0252] Table 16 Fault Propagation Path Combinations when IMU Fails

[0253]

[0254] It should be understood that the magnitudes of the sequence numbers of the steps in the above embodiments do not imply the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0255] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.

Claims

1. A model-based airborne system cascading failure analysis method, characterized in that: include: S1: Building an airborne system model for cascading failures based on the architecture design modeling language AADL, the system model includes a nominal model and a fault propagation model; S2: Instantiate the system model in S1 to obtain the instantiation aaxl2 file; S3: Using XML information extraction technology, extract components at each level, connection relationships between components, and fault propagation information from the instantiated aaxl2 file to build an airborne system cascade propagation model. Verify the consistency of the AADL model and the cascade propagation model based on the graph isomorphism method. S4: According to the airborne system cascade propagation model in S3, the system topology parameters are used to define the fault propagation strength between components in the airborne system, and the fault propagation strength is used as the input of the DWNodeRank algorithm to output the fault impact between components. The fault propagation probability between components is solved in combination with the component failure rate. S5: The fault impact in S4 is expressed as component importance, and the component failure with component importance greater than the preset threshold is used as the initial condition of cascading failure. The airborne system cascade propagation model in S3 is used to solve the fault propagation path and fault propagation path combination that lead to system failure in the system cascade failure process through the fault propagation path analysis algorithm.

2. The model-based airborne system cascading failure analysis method according to claim 1, characterized in that: The step S1 comprises: When the system model is a nominal model, the system model is divided into system level, function level and component level, and the components of each level of the system model are represented by predefined components of the AADL model, and then the subcomponents and connection interaction relationships of each component are declared to complete the construction of the nominal model; When the system model is a fault propagation model, the fault propagation behavior, component error behavior and compound error behavior of each component are declared to describe the impact of fault propagation between components, the impact of component failure on function and the impact of functional failure on system status, so as to complete the construction of the fault propagation model.

3. The model-based airborne system cascading failure analysis according to claim 1, characterized in that: The elements of the airborne system cascade propagation model in step S3 include component layer nodes B = {b1, b2, ..., b n }、Functional layer node F={f1,f2,...,f m } and system layer nodes S = {s1, s2, ..., s k }; Component layer node connection matrix M bb as follows: in The value is 0 or 1. When , it means that the system component i connects or transmits the propagation error to component j; when When , it means there is no interaction between component i and component j; Component layer-function layer connection matrix M fb as follows: in The value is "and" and "or" logical words. and When , it means that when components j and j+1 fail, system function i fails; when When , it means that function i fails when component j fails; Functional layer-system layer connection matrix M sf as follows: in, The value is 0 or 1. When , it means that the system component i connects or transmits the propagation error to component j; when , it means there is no interaction between component i and component j.

4. The model-based airborne system cascading failure analysis according to claim 1, characterized in that: The process of constructing the cascade propagation model based on XML information extraction in step S3 includes: The Python ElementTree module is used to extract the AADL model system-level components, function-level components, component-level components, the connection relationship between each component, and the fault propagation information from the aaxl2 file, and then the cascade propagation model is constructed according to the mapping relationship between the AADL model and the cascade propagation model; The component-level nodes of the cascade propagation model are constructed by extracting component-level components, and the connection relationship and fault propagation relationship between component-level components are extracted to construct the component-level node connection matrix of the cascade propagation model; the functional-level nodes of the component cascade propagation model of functional-level components are extracted, and the state transition logic in the composite error behavior of functional-level components is extracted to construct the component-level-function layer connection matrix; the system-level nodes of the error-state component cascade propagation model of system-level components are extracted, and the state transition logic in the composite error behavior of system-level components is extracted to construct the function-level-system layer connection matrix.

5. The model-based airborne system cascading failure analysis according to claim 1, characterized in that: The step S3 verifies the consistency of the AADL model and the cascade propagation model based on the graph isomorphism method, including: The component layer, functional layer components and system error states in the AADL model are converted into nodes, the data interaction and fault impact between component-level components are converted into edges of nodes, and the fault impact between functional-level and system-level components are converted into edges to obtain an AADL graph model; The nodes at all levels of the cascade propagation model are converted into nodes, and the connection relationship between nodes is converted into edges to obtain a cascade propagation graph model; The AADL graph model and the cascade propagation graph model are used as the input of the VF2 algorithm. By comparing the nodes of the two graph models, it is determined whether the two graph models are isomorphic.

6. The model-based airborne system cascading failure analysis according to claim 1, characterized in that: The fault propagation intensity between components in step S4 is defined as follows: Among them, L dout is the out-degree centrality of the node, L b is the betweenness centrality of the node.

7. The model-based airborne system cascading failure analysis according to claim 1, characterized in that: In step S4, the fault propagation intensity is used as the input of the DWNodeRank algorithm to output the impact of faults between components, including: Normalize the fault propagation intensity matrix and use the vector (1 / n)e T Replace the rows with all zeros in the normalized fault propagation intensity matrix to obtain the probability transfer matrix, where n is the dimension of the matrix; According to the probability transfer matrix and the preset damping factor, the DWNodeRank matrix A is constructed. The node out-degree centrality is used as the initial vector, and the stable distribution of the matrix A is obtained through iteration to determine the impact of component layer node failures in the cascade propagation model.

8. The model-based airborne system cascading failure analysis according to claim 1, characterized in that: The fault propagation probability in step S4 is defined as follows: Among them, A i and A j The failure impact of nodes i and j, A(e i→j ) represents the fault impact of the edge between two nodes, λ i is the failure rate of node i.

9. The model-based airborne system cascading failure analysis according to claim 1, characterized in that: The implementation process of the fault propagation path analysis algorithm in step S5 is as follows: Taking the node influence as the importance value, the node with the importance value greater than the preset threshold is selected as the starting node of the cascading failure analysis, and the starting node, cascade propagation model, given propagation order and path probability requirement are used as the input of the fault propagation path analysis algorithm; The fault path after the first fault propagation is obtained according to the starting node and component layer node matrix. For each fault propagation path, the impact of the path on the system function is determined according to the function layer-component layer connection matrix, and the impact of the path on the system state is determined according to the system layer-function layer connection matrix. All single-challenge fault paths that cause system failure are obtained, and the path propagation probability is calculated, and the fault propagation paths that meet the preset probability requirements are retained; For path combinations, after excluding the single path that will cause system failure, the remaining paths are arranged and combined, and the path combinations that will cause system failure are identified according to the function layer-component layer connection matrix and the system layer-function layer connection matrix, and the propagation probability of the path combination is calculated, and the fault propagation path combinations that meet the preset probability requirements are retained; If the fault propagation order does not reach the preset given value, the next order fault propagation and path analysis will continue starting from the last node of the current path until the specified propagation order is reached, and the fault propagation path and fault propagation path combination that cause all system failures will be output.