Online evaluation and guarantee method for testing confidence coefficient of semi-physical simulation system
By constructing a distributed local confidence unit and an asynchronous event capture mechanism, combined with time misalignment correlation analysis and confidence isolation and decrement chain, the problem of insufficient ability of traditional simulation systems to identify asynchronous local anomalies is solved, and accurate test reliability assessment and rapid fault location of semi-physical simulation systems are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-27
- Publication Date
- 2026-03-27
AI Technical Summary
Traditional hardware-in-the-loop (HIL) simulation systems are unable to effectively identify asynchronous local anomalies, especially short-term mutations, aperiodic disturbances, and interface drift, when faced with complex coupled structures. This leads to test results being misjudged as normal. Furthermore, they lack a quantitative expression of the confidence evolution process during operation, making it difficult to achieve early fault location and trigger response strategies.
A distributed local confidence unit is constructed, an asynchronous event capture mechanism is introduced, time misalignment correlation analysis is performed, a multi-factor confidence weakening model is designed, and a layered evaluation and chain propagation of test credibility is achieved by constructing a confidence isolation and reduction chain.
It enables accurate identification and attribution of asynchronous anomalies, enhances the testing process's ability to perceive potential risks, supports continuous quantitative tracking of system operating status and rapid identification of local anomaly locations, and improves system security.
Smart Images

Figure CN121742243A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of testing and evaluation technology, and in particular to an online assessment and assurance method for the confidence level of a hardware-in-the-loop system test. Background Technology
[0002] Hardware-in-the-loop (HIL) simulation systems, as an important means of verifying the stability, response characteristics, and boundary condition behavior of control systems, have been widely applied in high-reliability fields such as aerospace, power electronics, autonomous driving, and industrial control. These systems typically consist of model simulation units, physical interface units, and real-time control modules. By constructing a "virtual-real fusion" test environment, complex testing tasks can be completed without relying on the actual controlled object. With the increasing scale of simulation systems and the widespread adoption of multi-module heterogeneous integration, the reliability of the system's operational status has gradually become a key focus in engineering.
[0003] Traditional test result judgment mechanisms often rely on fixed indicator evaluation, output consistency comparison, or anomaly alarm rules, primarily depending on the global stability of the output or numerical deviation thresholds. However, in complex coupled structures, these mechanisms often fail to effectively identify asynchronous local anomalies. Current test systems lack the ability to respond to asynchronous behaviors without obvious amplitude characteristics, such as short-term mutations, aperiodic disturbances, and interface drift, easily leading to test results being misjudged as normal. Furthermore, existing methods often use a binary judgment of whether the test passes or fails, lacking a quantitative expression of the confidence evolution process during operation, and failing to reflect quality fluctuations or risk trends in the intermediate process. Moreover, in multi-module collaborative testing, if local anomalies do not significantly affect the final output, they are often diluted in the weighted average, making it difficult to achieve early fault location and trigger response strategies. Summary of the Invention
[0004] This invention provides an online assessment and assurance method for the confidence level of a semi-physical simulation system test. By constructing distributed local confidence units, introducing an asynchronous event capture mechanism, designing time misalignment correlation analysis, defining a multi-factor confidence weakening model, and constructing a confidence isolation and reduction chain, it ultimately achieves hierarchical assessment, chain transmission, and structured output of test confidence, effectively overcoming the limitations of existing technologies.
[0005] A method for online evaluation and assurance of confidence level in a hardware-in-the-loop simulation system includes the following steps: S1. Construct distributed local confidence units and establish asynchronous event capture clusters: Based on the module boundaries, signal flow direction and interface interaction relationship of the semi-physical simulation system, the simulation system is decomposed to generate local confidence units for independent monitoring; an asynchronous event capture cluster is set in each local confidence unit to record asynchronous abnormal events in real time and generate a local asynchronous event sequence, which serves as the basis data for subsequent confidence weakening; S2. Perform time-dislocation correlation analysis and construct local confidence weakening factors: Perform time-dislocation correlation analysis between the local asynchronous event sequence and the normal state mode of the local confidence unit to identify the asynchronous abnormal event type, including short-term noise, transient coupling, interface drift, or control lag; Based on the asynchronous abnormality type, trigger density, and cross-channel propagation trend, calculate the confidence weakening factor of each local confidence unit to reflect the true impact of the asynchronous abnormal event in the local area, and output the local confidence assessment results. S3. Construct confidence isolation and decrement chains and perform overall confidence reorganization: Construct confidence isolation and decrement chains for the confidence evaluation results of all local confidence units according to signal links and control logic to prevent asynchronous anomalies from being submerged in the overall weighted criterion; In the confidence isolation and decrement chains, based on the level, path position, and contribution of the local confidence weakening factor to the final result, perform a decremental reorganization of the overall test confidence to form an overall confidence structure that can indicate the location of local anomalies, avoid misjudging the test as passed when asynchronous anomalies exist, and generate anomaly location information and independent local confidence records for backtracking.
[0006] Optionally, the splitting specifically includes: Using the system functional modules as boundaries, the simulation model unit, hardware interface unit, and control logic unit with independent data processing capabilities are divided into independent local confidence units; Based on the signal flow direction, monitoring nodes of local confidence units are set at the data source, transmission path and response terminal; Based on the interface interaction relationship, deploy the interaction monitor of the local confidence unit at the data exchange point across units.
[0007] Optionally, the real-time recording of asynchronous exception events specifically includes: Multiple asynchronous event detectors are deployed on the critical signal path of each local confidence unit. These detectors are configured to monitor micro-duration changes, cross-sampling point drift, and aperiodic triggering responses in parallel. Establish an event timestamp sequence and associated signal identifiers to generate a local asynchronous event sequence with timestamps and event types; A circular buffer stores asynchronous events within the most recent time window, forming the underlying data queue for confidence weakening analysis.
[0008] Optionally, the time misalignment correlation analysis specifically includes: A normal state mode timing template for local confidence units is established, which includes a standard signal shape, an expected response time window, and an allowable timing jitter range. A sliding time window is used to align and compare the real-time acquired local asynchronous event sequence with the normal state mode timing template. The correlation coefficient between the local asynchronous event sequence and the normal mode at different time offsets is calculated. When the maximum correlation coefficient is lower than the correlation threshold, it is determined that there is a time misalignment.
[0009] Optionally, the asynchronous exception type for identifying asynchronous exception events specifically includes: Transient spikes that are identified as having no subsequent associated events are attributed to short-term noise. The simultaneous occurrence of timing offsets in multiple associated units is attributed to transient coupling. If the drift is identified as a continuous unidirectional drift, it is attributed to interface drift. The increased response latency as the load increases is identified as being attributed to control hysteresis.
[0010] Optionally, the calculation of the confidence weakening factor for each local confidence unit specifically includes: Set a base weight for each asynchronous exception type, where the base weight for control lag is greater than that for short-time noise; A trigger density correction coefficient is introduced, which is positively correlated with the frequency of occurrence of asynchronous abnormal events per unit time; Assess cross-channel propagation trends and apply a propagation penalty factor when asynchronous abnormal events propagate along the signal link to subsequent units; A confidence weakening factor is generated by weighting the basic weights, trigger density correction coefficient, and propagation penalty factor. The confidence weakening factor is subtracted from the initial confidence baseline value to obtain the local confidence assessment result, and the local confidence assessment result is output to the reorganization stage.
[0011] Optionally, the calculation of the confidence weakening factor for each local confidence unit specifically includes: Set a base weight for each asynchronous exception type, where the base weight for control lag is greater than that for short-time noise; A trigger density correction coefficient is introduced, which is positively correlated with the frequency of occurrence of asynchronous abnormal events per unit time; Assess cross-channel propagation trends and apply a propagation penalty factor when asynchronous abnormal events propagate along the signal link to subsequent units; A confidence weakening factor is generated by weighting the basic weights, trigger density correction coefficient, and propagation penalty factor. The confidence weakening factor is subtracted from the initial confidence baseline value to obtain the local confidence assessment result, and the local confidence assessment result is output to the reorganization stage.
[0012] Optionally, the step of constructing a confidence isolation and decrement chain based on the confidence evaluation results of all local confidence units according to the signal link and control logic specifically includes: Based on the signal flow graph and control dependency of the hardware-in-the-loop simulation system, local confidence units are connected in series into a chain structure, where the output of each local confidence unit serves as the input of the next local confidence unit. By setting up isolated nodes in the chain structure, asynchronous abnormal events are prevented from being masked in the overall evaluation through weighted averaging, ensuring that the evaluation results of each local confidence unit independently affect the final credibility.
[0013] Optionally, the stepwise reorganization of the overall test credibility specifically includes: Each local confidence unit is assigned a confidence weight coefficient, which is calculated based on its hierarchical depth, its criticality in the signal path, and its contribution to the system output. A decreasing algorithm is used to apply local confidence weakening factors step by step along the confidence isolation and decreasing chain, starting from the initial overall confidence value. The weakening factors of higher-level or critical path units have higher attenuation strength. After reorganization, an overall confidence value is generated, and the confidence weight coefficient is accompanied by local anomaly markers to form an overall confidence structure that can indicate the location of anomalies.
[0014] Optionally, the generation of anomaly location information and independent local confidence records for backtracking specifically includes: When the confidence assessment result of any local confidence unit is lower than the confidence downgrade threshold, the overall test confidence is forcibly downgraded to avoid misjudgment; Record the evaluation results, weakening factors and their positions in the chain for each local confidence unit, and generate anomaly location reports and independent confidence logs for fault diagnosis and process backtracking.
[0015] The beneficial effects of this invention are: This invention constructs a local asynchronous event sequence with timestamps and type tags by deploying asynchronous event capture clusters in each local confidence unit. This enables real-time monitoring of fine-grained anomalies, including micro-duration mutations, cross-sampling point drift, and non-periodic trigger responses. It overcomes the limitations of traditional simulation systems in identifying short-term, non-periodic, and uncertain events. Furthermore, it proposes an anomaly attribution mechanism based on temporal misalignment correlation analysis. By comparing the temporal offset characteristics of abnormal events and normal state templates, it distinguishes different types of root causes, such as short-term noise, transient coupling, interface drift, and control lag, providing a precise explanatory basis for subsequent credibility assessment. This mechanism, which integrates anomaly detection and attribution, enables the system not only to identify whether anomalies exist but also to explain the source of anomalies, enhancing the testing phase's ability to perceive potential risks and develop corresponding response strategies.
[0016] This invention proposes a "confidence isolation and decreasing chain" structure. Multiple local confidence units are linked together into an ordered chain structure based on signal flow and control dependencies. A confidence isolation mechanism is introduced into the chain to prevent severe local anomalies from being masked by the overall weighted average. Furthermore, weight coefficients are set based on the hierarchical position, path criticality, and system output contribution of each unit. A decreasing algorithm is used to progressively add confidence weakening factors along the chain, constructing a gradual transition from a globally confident state to a locally risky state. This structured decreasing approach not only improves the overall assessment's responsiveness to chain-propagation risks but also realizes the transformation of confidence calculation from static weighting to dynamic transmission. It supports continuous quantitative tracking of system operating status, rapid identification of local anomaly locations, and focused attention on high-impact modules, enhancing the overall security of the system.
[0017] This invention constructs a multi-factor joint confidence weakening model by integrating the basic weight of anomaly types, the trigger density correction coefficient per unit time, and the cross-channel propagation penalty factor. This model can dynamically adjust the actual impact of each anomaly event on local confidence. In particular, the trigger density coefficient enables the system to weight and amplify situations where anomalies occur frequently, while the propagation penalty factor enhances the structural consideration of anomaly propagation paths. Overall, this forms a dual-dimensional characterization of both the intensity of the anomaly itself and the depth of its system impact. Compared to traditional schemes that count events or uniformly deduct points, this invention offers advantages such as stratified anomaly severity, modelable propagation, and continuously adjustable confidence changes. Attached Figure Description
[0018] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only for this invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0019] Figure 1 This is a schematic diagram of the method flow according to an embodiment of the present invention; Figure 2 This is a schematic diagram illustrating the construction of confidence isolation and decreasing chains and the overall confidence reorganization in an embodiment of the present invention. Detailed Implementation
[0020] The present invention will now be described in detail with reference to the accompanying drawings and specific embodiments. For some well-known technologies, those skilled in the art may also use other alternative methods to implement the invention. Moreover, the accompanying drawings are only for more specific description of the embodiments and are not intended to specifically limit the present invention.
[0021] like Figures 1-2 As shown, an online assessment and assurance method for the test confidence of a hardware-in-the-loop simulation system includes the following steps: S1. Construct distributed local confidence units and establish asynchronous event capture clusters: Based on the module boundaries, signal flow and interface interaction relationships of the semi-physical simulation system, the simulation system is split to generate local confidence units for independent monitoring; an asynchronous event capture cluster is set up in each local confidence unit to record asynchronous abnormal events in real time and generate a local asynchronous event sequence, which serves as the basis data for subsequent confidence weakening.
[0022] Based on the module boundaries, signal flow, and interface interaction relationships of the hardware-in-the-loop simulation system, the simulation system is decomposed, specifically including: 1. Module Boundary Division: Using system functional modules as boundaries, units with independent data processing capabilities are divided into independent local confidence units, specifically including: Simulation model unit (simulation node that performs physical modeling and dynamic solving); Hardware interface unit (A / D, D / A conversion module); Control logic unit (FPGA, DSP, etc., which implements the calculation module of control law).
[0023] 2. Signal Flow Direction Layout: Based on the signal flow direction, monitoring nodes for local confidence units will be set up at the following key locations: Data source (external stimulus, sensor input); Data transmission path (bus, signal chain); Response terminal (drive module, control actuator output).
[0024] 3. Interface Interaction Deployment: Based on the interface interaction relationship between modules, deploy local confidence unit interaction monitors at cross-unit data exchange points to capture asynchronous interaction characteristics and abnormal triggering behaviors between units.
[0025] Within each local confidence unit, an asynchronous event capturing cluster is set up, specifically including: 1. Asynchronous Event Detector Deployment: Deploy multiple asynchronous event detectors on the critical signal paths of each local confidence unit, configured to monitor the following three types of typical asynchronous abnormal events in parallel: First, micro-duration mutations: these occur instantaneously and last for a duration shorter than the sampling period. Abnormal signal spikes. The monitoring method is as follows: Interpolate auxiliary sampling points (midpoint interpolation) between every two adjacent sampling points: ; If the actual sampled values show: ; Furthermore, this peak value only lasts for less than one sampling period. If so, it is determined to be a micro-duration mutation. The threshold for the amplitude of the sudden change can be empirically set at 3 to 5 times the standard deviation of the signal. This represents the interpolation point signal value, located between adjacent sampling points. For the first The signal value at each sampling point.
[0026] Second, cross-sampling-point drift: Unexpected smooth drift occurs between consecutive sampling points, manifested as a change in the first-order derivative. The monitoring method is as follows: Calculate the first-order difference (approximate derivative) of the signal: ; Multiple consecutive (3-5) sampling points satisfy That is, it is judged as drift across sampling points. This is the drift rate threshold (the maximum permissible offset per unit time). Indicates the first The signal difference at each point represents the approximate derivative.
[0027] Third, non-periodic trigger response: If the occurrence time of the signal response event deviates too much from the set period T, determine whether the trigger is premature or delayed. This results in abnormal response delays or premature responses. The monitoring methods are as follows: Record the sequence of actual occurrence times of response events Theoretical time is ; Calculate time deviation: ; If it exists: And it continues to appear If this occurs more than once, it will be marked as an abnormal non-periodic trigger response. To set the desired period, Trigger time deviation threshold ( (10-20%) The minimum number of consecutive anomalies is recommended, with a value of ≥3.
[0028] In a hardware-in-the-loop simulation system, critical signal paths refer to those signal channels that directly affect the system's operating state, control logic closed loop, and interaction stability, including: Control command path: Control signals output from the control logic unit (FPGA or emulation controller) to the actuator; Sensor feedback path: The data channel that collects data from analog or physical sensors and inputs it into the simulation calculation module, such as position sensors, current sampling, and pressure feedback signals.
[0029] Interface input / output path: The data exchange path between the A / D and D / A conversion modules and the simulation model in a hardware-in-the-loop interface. It is often used to bridge the gap between analog hardware input and the simulation model.
[0030] If these paths experience asynchronous anomalies, it will directly affect the reliability of the simulation results, and therefore they are designated as critical signal paths.
[0031] 2. Construction of Local Asynchronous Event Sequences: For each event Record it when it occurs: ;in Indicates the first Each asynchronous exception event includes a timestamp, signal identifier, and event type. Indicates the timestamp of the event. This represents the corresponding signal path identifier. Indicates the event type label. All events constitute a local asynchronous event sequence: .
[0032] 3. Basic data queue caching mechanism: Store in a circular buffer to cache the most recent window. Internal event data: Used to support subsequent confidence weakening analysis and time-dislocation correlation processing. This refers to the current moment.
[0033] S2. Perform time-dislocation correlation analysis and construct local confidence weakening factors: Perform time-dislocation correlation analysis between the local asynchronous event sequence and the normal state mode of the local confidence unit to identify the asynchronous abnormal event type, including short-term noise, transient coupling, interface drift, or control lag; Based on the asynchronous abnormality type, trigger density, and cross-channel propagation trend, calculate the confidence weakening factor of each local confidence unit to reflect the true impact of the asynchronous abnormal event in the local area, and output the local confidence assessment results.
[0034] Specifically, it includes: S21, Temporal Dislocation Correlation Analysis: This involves performing temporal dislocation correlation analysis between the local asynchronous event sequence and the normal state pattern of its local confidence unit. Specifically, this includes: S211, Construct a normal state mode timing template for local confidence units. It includes: Standard signal form ; Expected response time window ; Allowable timing jitter range .
[0035] S11 constructs a normal state mode timing template to perform time alignment analysis on the actual asynchronous events of local confidence units, thereby determining whether there is a timing misalignment in the current system and further identifying the root cause of the anomaly. When the hardware-in-the-loop simulation system is running, each local confidence unit will generate a series of asynchronous events, such as mutations, drifts, or aperiodic responses. To determine whether these events are abnormal, a normal reference template must be used for comparison. Therefore, a normal state mode timing template needs to be pre-established for each local confidence unit. This template can be understood as the benchmark for the event timing and signal behavior that the unit should have under ideal conditions. During system operation, the asynchronous event sequence acquired in real time is aligned with this template, and the time matching degree of the two is compared by sliding comparison. By calculating the correlation, it is assessed whether the current state deviates from the normal rhythm. If the correlation after alignment is lower than a set threshold, a timing misalignment can be considered to exist, thereby triggering further anomaly identification mechanisms, such as determining whether it is short-term noise, coupling disturbance, or control lag.
[0036] The construction of a normal state mode timing template for a local confidence unit can be summarized in the following three steps: 1. Collect normal state data: During the system debugging phase or long-term operation, select a period marked as having no abnormalities and collect the key signal outputs and event trigger records of the local confidence unit.
[0037] 2. Extract template features: Based on the collected data above, the following key content is extracted: The change curve of key signals under normal conditions serves as the standard signal form. The typical time delay range from signal input to response is defined as the expected response time window; The slight advance or delay tolerance of the signal response under normal fluctuations is set as the allowable timing jitter range.
[0038] 3. Encapsulate as a template structure: The above three elements are uniformly encapsulated as a time-series template object for quick matching and sliding alignment during subsequent comparative analysis.
[0039] The normal state mode timing template includes the following: 1. Standard signal form: This refers to the waveform, amplitude variation trend, periodicity, etc. of a signal within a certain time range under ideal conditions. For example, analog signals should show a linear increase, and digital signals should switch at regular intervals.
[0040] 2. Expected response time window: This refers to the allowable time range between the occurrence of an excitation and the triggering of a response. For example, after a control command is issued, the response should occur between 100ms and 150ms.
[0041] 3. Allowable timing jitter range: Considering the existence of minor disturbances in the actual system, a certain range of advance or delay in response time is allowed, ±10ms, to avoid normal minor fluctuations being misjudged as abnormal.
[0042] S212, Sliding window alignment comparison: In actual operation, a local confidence unit may generate some asynchronous abnormal events at different times, such as signal drift, control delay, and sudden spikes. To determine whether these abnormalities have truly affected the reliability of the system, a reference standard for normal behavior is needed.
[0043] Therefore, each of the aforementioned local confidence units is pre-set with a normal state mode timing template, indicating how the signal should change, within what time window the event should occur, and the permissible range of advance or delay under anomaly-free conditions. During simulation, the system continuously collects the sequence of currently occurring asynchronous events and gradually aligns this real-time sequence with the pre-set template using a sliding time window. After each alignment, the time consistency (correlation) of the two is calculated. If, at any time offset, the two cannot match well, it indicates that the current state has deviated from the normal operating rhythm, i.e., a time misalignment exists. Once a time misalignment is confirmed, the misalignment characteristics are analyzed to further determine the type of problem (short-term noise, interface drift, control lag), providing a basis for subsequent reliability assessment.
[0044] Specifically, this includes using a sliding time window to process real-time partially asynchronous event sequences. Align with the normal mode template and set the window length to [value]. For each time offset ,Compare: ;in Offset The correlation coefficient is shown below.
[0045] That is, at a time offset of Under the condition of real-time asynchronous event sequence With normal timing template The correlation coefficient between them is used to quantify the degree of time alignment between them. Indicates the current local confidence unit at time [time]. The observed sequence of asynchronous events includes event occurrence time, event type, etc. This indicates shifting the entire normal state timing template forward or backward. The new sequence obtained after time is used for alignment and comparison with real-time events, corr This indicates the statistical correlation (correlation coefficient) between two time series, using the Pearson correlation coefficient as a measure of time similarity. Through continuous adjustment... And recalculate This allows us to find the optimal time offset for aligning two sequences. If all offsets are... All are below the set threshold If this is true, it means that the current state of the local unit deviates significantly from the expected state, i.e., a time misalignment has occurred.
[0046] S213, Misalignment Detection: In a partial confidence unit, to determine whether there is a temporal anomaly, i.e., misalignment, in the currently occurring asynchronous event sequence, the real-time acquired event sequence is compared with the normal state timing template of that unit. Since events may not occur exactly at the expected time points, the system uses a sliding time alignment method, shifting the template forward and backward by multiple offsets along the time axis. Each time the sequence is shifted, the correlation coefficient between the real-time event sequence and the template at the current time is recalculated. This refers to the degree of similarity between the two objects in their current time-aligned state. After multiple slides, the maximum correlation value under all offsets is recorded. This is equivalent to finding the alignment state that best approximates normal behavior.
[0047] If the maximum correlation value is still very low (i.e., no sliding method can align well), it means that the current event sequence has deviated significantly from the normal pattern, which can be judged as a time misalignment. This usually means that control lag, interface drift or other problems that affect the reliability of simulation may have occurred.
[0048] Specifically as follows: Find the maximum relevance: ; If the following conditions are met: Then it is determined that there is a time misalignment in the current local confidence unit. This is the correlation threshold used to determine whether a time misalignment exists. When the maximum correlation coefficient is below this threshold, a significant misalignment is considered to exist between the local asynchronous event sequence and the normal template, making alignment impossible through any time offset. The system should mark this period as abnormal. The correlation threshold is set between 0.6 and 0.8. If the system has a low tolerance for misalignment, 0.8 (high sensitivity) is used; if noise exists or the template is loose, it can be relaxed to 0.6 (low false alarm rate). Alternatively, the maximum correlation distribution of each local unit can be calculated over multiple normal operating cycles, and its lowest steady-state correlation lower limit can be used as a reference. For example, if 95% of the correlations in 100 normal cycles are higher than 0.78, it can be set to 0.75.
[0049] S214, Based on the misalignment characteristic pattern, the causes of the abnormal events are attributed as follows: If an event manifests as a transient spike with no subsequent associated events and a very short duration, lasting only one sampling period or less, it is attributed to short-time noise. If multiple associated units exhibit timing shifts within a neighboring time period, i.e., within the same time window, multiple different local confidence units exhibit similar types of misalignment events, and there is a signal dependency or synchronization control logic between the associated units, with no obvious continuity but the triggering exhibits obvious transient diffusion, then it is attributed to transient coupling. If asynchronous events occur continuously, and the signal time or amplitude gradually deviates, with all misalignments in the same direction, exhibiting a unidirectional drift trend, then it is attributed to interface drift. If the response event is delayed, and the delay increases with the increase of system load, and the causal relationship between the control output delay and the input excitation is stable, then it is attributed to control hysteresis.
[0050] The aforementioned associated units refer to local confidence units that have a direct dependency relationship in signal flow, control logic, or data interaction.
[0051] S22, Confidence weakening factor construction: Based on the identified asynchronous anomaly types, trigger density, and cross-channel propagation trends, a local confidence weakening factor is calculated, specifically including: S221, Basic Weights for Asynchronous Exception Types: Based on different types of asynchronous exception events, the impact on the system's test reliability is quantitatively differentiated, thereby constructing a differentiated confidence weakening weight model. Not all exceptions have an equivalent impact on the system. Some exceptions, such as control lag, directly interfere with core control logic, causing significant errors, while others, such as short-term noise, may only be external jitter or non-persistent disturbances, having a smaller impact on the overall system reliability. Therefore, a basic severity weight needs to be assigned to different exception types as a key component of the subsequent confidence weakening factor calculation, reflecting differentiated treatment and precise assessment. Specifically, basic weights are assigned to each type of exception based on factors such as sustainability, systemicity, and scope of impact. : The control lag weight is greater than the short-time noise.
[0052] Control lag: This is a systemic structural problem. The delay will worsen with increasing load and is prone to feedback misalignment and closed-loop instability. Therefore, it is given the highest weight, and this invention can take 1.0.
[0053] Interface drift: manifested as persistent misalignment or clock skew, which may be caused by hardware and software interface synchronization errors, data update lag, etc. It has a significant impact on time-sensitive simulations and has the second highest weight. In this invention, it can be taken as 0.8.
[0054] Transient coupling: Although it has the disturbance characteristics of multiple units responding simultaneously, most of them are short-term bursts and non-persistent. They belong to the category of repairable disturbance problems and have a moderate weight. In this invention, a weight of 0.6 can be used.
[0055] Short-term noise: mostly physical interference, electromagnetic jitter or occasional sampling errors, usually not persistent, can be eliminated by filtering or sliding window processing, so it is given the lowest weight, which can be 0.3 in this invention.
[0056] S222, Trigger Density Correction Coefficient: After identifying asynchronous abnormal events and completing preliminary attribution classification, it is also necessary to determine the frequency of these abnormal events, that is, how many times they occur per unit time. The logic is simple: if the same type of abnormality occurs repeatedly within a time period, it obviously indicates that the system has been subjected to more serious interference, and its weakening of the system's confidence should be greater. Therefore, the variable of trigger density correction coefficient is introduced to quantify the occurrence frequency of abnormal events as a weighting factor and participate in the calculation of the final confidence weakening value. This correction coefficient is proportional to the number of events per unit time (i.e., trigger density). In other words: the more frequent the abnormality, the more the confidence score is deducted; the fewer the abnormalities, the negligible the impact.
[0057] Specifically, it includes: Calculate the trigger density, which is the number of events per unit time: ; The number of abnormal events within a time window The number of asynchronous exception events detected internally; Calculate the trigger density correction factor: ; The density mapping function will trigger the density mapping to a correction coefficient. Use a monotonically increasing function, i.e., a linear form: ; This represents the linear amplification factor, controlling the rate of increase of the correction coefficient with density variation. Its value ranges from 0.05 to 0.2, and the optimal range is determined through experimental calibration. hour, This can be set as an upper limit. Alternatively, a piecewise threshold function can be used, which sets a safe density range, and increases the weight directly when the range is exceeded. .
[0058] S223, Cross-channel propagation penalty factor: When an asynchronous anomaly occurs in a local confidence unit, the system checks whether the anomaly propagates downstream along the signal chain, control chain, or data chain. If multiple subsequent units show similar misaligned responses at close range, it indicates that the anomaly is not only local but also has a chain reaction capability. To quantify this impact, a cross-channel propagation penalty factor is introduced. , which represents the range and depth of the anomaly's propagation in space. The deeper the propagation and the more units it affects, the heavier the penalty and the greater the weakening of the overall credibility. This penalty factor is designed to be proportional to the number of propagation path levels L, that is, the more levels of units the propagation involves, the higher the penalty.
[0059] Specifically: If the event continues to propagate along the signal link to downstream units, a penalty factor is applied: This formula means that, based on a base penalty value of 1, a fixed propagation level penalty coefficient is added for each propagation level. The final The overall multiplicative weights of the confidence-weakening factors will reflect the propagational impact of this anomaly. The number of unit levels traversed by the abnormal propagation, that is, which downstream unit level the current abnormal event affects from the source unit.
[0060] The propagation level penalty coefficient ranges from 0.2 to 0.5. For high-security systems, such as flight control, it can be set to 0.5, while for low-sensitivity scenarios, such as logistics simulation, it can be set to 0.2. The core purpose of this part is to identify asynchronous abnormal events that propagate along the signal link between multiple local confidence units and impose more severe penalties to reflect their cascading impact on the overall system reliability. This design prevents the following misjudgment scenarios: that is, although an anomaly may not seem serious within a single unit, it propagates layer by layer to multiple downstream modules, affecting the overall response logic of the system. Without penalties, its risk would be underestimated.
[0061] S224, the confidence weakening factor is obtained by integrating the three influencing factors to generate a numerical confidence weakening factor D, which represents the actual degree of damage to the confidence caused by the abnormal behavior of the local confidence unit. ;in This represents the confidence weakening factor of the local confidence unit.
[0062] S225, Based on the calculated confidence weakening factor D, the initial confidence level of this local unit. Subtract points to obtain the actual credibility value at the current time point; The initial confidence baseline value is set as follows: ; The local confidence level is: The result is passed as output to the overall credibility reorganization stage.
[0063] If D=0, it means there is no weakening, and the confidence level remains at 1; If D=0.2, then the credibility of the current unit is 0.8, indicating that there is a certain risk. If D ≥ 0.5, it indicates that the unit is seriously abnormal and its reliability has fallen below the critical value for reliable operation.
[0064] S3. Construct confidence isolation and decrement chains and perform overall confidence reorganization: Construct confidence isolation and decrement chains for the confidence evaluation results of all local confidence units according to signal links and control logic to prevent asynchronous anomalies from being submerged in the overall weighted criterion; In the confidence isolation and decrement chains, based on the level, path position, and contribution of the local confidence weakening factor to the final result, perform a decremental reorganization of the overall test confidence to form an overall confidence structure that can indicate the location of local anomalies, avoid misjudging the test as passed when asynchronous anomalies exist, and generate anomaly location information and independent local confidence records for backtracking.
[0065] Specifically, it includes: S31, Construct a confidence isolation and decreasing chain: S311, Confidence chain structure construction: In a complex hardware-in-the-loop simulation system, there are multiple independent yet interdependent modules, such as controllers, signal interfaces, motor models, and sensor feedback. These modules form causal relationships or chain dependencies through signal connections, control logic, or physical feedback. That is, the output of an upstream module often affects the behavior of a downstream module. In this structure, if one module malfunctions, this malfunction may infect downstream modules, causing them to exhibit indirect malfunctions. Without organizing these modules according to signal and logic order, it is impossible to determine whether a particular malfunction is the root cause or a consequence. Therefore, based on the signal flow graph and control dependencies of the hardware-in-the-loop simulation system, all local confidence units are chained together into a directed chain structure: ;in, This represents the system's starting module, such as external inputs or control command sources. These are the final output modules, such as physical feedback and response actuators. This represents the entire confidence chain. For the first A local confidence unit Indicates signal from Flow direction This means that the output of the current cell is the input of the next cell.
[0066] S312, Setting Isolation Nodes: In a hardware-in-the-loop simulation system composed of multiple modules, directly weighting or merging the confidence results of all modules can lead to a problem: some modules may exhibit severe anomalies, but because most modules function normally, the overall average remains high, masking these local anomalies and causing the system to mistakenly register the test as passed. Therefore, in the chain structure, an isolation mechanism is implemented to ensure that local confidence levels are not masked during the overall weighted averaging process. An independent confidence evaluation channel is maintained for each unit, and the following expression is constructed for each local unit. Calculate its credibility separately: Among them, the difference For the first The credibility of a local unit Set the global initial confidence level to 1. This is the confidence weakening factor for that unit. This means that even if only one module is anomalous, its weakening factor... This will also directly affect the reliability of the module itself. It will not be averaged out. Subsequent overall credibility assessments can decrease layer by layer, rather than being uniformly merged. Through this independent assessment mechanism, the system can adjust the overall credibility result step by step according to the credibility of each module, thus forming a decreasing chain, rather than a rough average, which makes it easier to accurately locate the source of the anomaly.
[0067] S32, Overall credibility of decreasing recombination: S321, Assigning Confidence Weighting Coefficients: In a hardware-in-the-loop simulation system, not all modules are equally important. Some modules are located downstream of the final output, and their output directly affects the system's final judgment. Some modules, although upstream, are at critical branch points or the core of decision-making logic. Some modules, while not playing a control role, have outputs that are crucial for the system's pass / fail decision. Therefore, this scheme assigns a confidence weighting coefficient to each local confidence unit based on its structural location and functional role. To ensure that the reliability calculation considers not only whether an anomaly occurred, but also where the anomaly occurred. That is, for each local unit... Weighting coefficients for each allocation This value takes into account all factors. ;in, This indicates the depth of the cell hierarchy (distance from the output). This indicates the degree of criticality in the path. For example, a disruptive node indicates whether the unit is the only node or bottleneck in a critical path. For instance, if its disconnection would prevent the entire signal chain from transmitting, its criticality would be higher. This represents the weight of a unit's contribution to the final system output, such as the influence path strength. It indicates the degree to which the unit's output affects the overall system result, such as whether it is a feedback signal in the control loop or participates in the final index judgment. Weighting function. The function is decreasing, meaning the closer the downstream unit is to the output, the greater its impact. This allows us to map these three factors to a single weight value. Weighting function First, let's set the three input parameters... , , Normalize to the [0,1] interval to eliminate differences in units and scale: Hierarchical Depth With the maximum number of levels Based on this, the normalization depth is defined as: The deeper the level, The higher the value, the closer it is to the output terminal; critical : Static scoring method is used to set: Non-critical nodes: 0; Alternative branch nodes: 0.5; The only critical node: 1; Contribution The weighting is set according to the proportion of this unit in the final output calculation. For example, if its proportion in the output is 20%, then... .
[0068] Then, the three factors are weighted and combined to form the final weight coefficient.
[0069] S322, Decreasing Combination Algorithm: The initial overall credibility is set as follows: This indicates that the system is in a completely trustworthy initial state. Weakening operations are performed sequentially along the confidence chain: starting from the first module, the impact of the anomaly is subtracted layer by layer. Each module has two key indicators, including its confidence weakening factor Di and its weight coefficient. Multiplying the two together yields the current module's deduction for overall credibility, expressed as: Repeat the above process until all modules have been traversed. After the last module has been calculated, the final overall confidence score is obtained. This value represents the overall test confidence level that the system can maintain after considering the effects of all local anomalies. This section describes how to apply the confidence-weakening information of multiple local confidence units to the overall system step by step, according to their order and importance in the signal chain, to finally arrive at an overall test confidence level value; in other words, this is a process of deducting points layer by layer, starting from the initial state of the system where everything is considered normal (confidence level is 1), and then deducting points step by step according to the degree of anomaly and weight of each module, until finally forming an overall confidence level evaluation.
[0070] The reason for using a decreasing approach instead of a one-time weighted average is that the hardware-in-the-loop simulation system has a causal sequence. An abnormality in one module may affect the next module. If a weighted average is used, the seemingly normal modules in the later modules will mask the problematic modules in the earlier modules, which is easy to misjudge. Using a gradually decreasing approach is closer to the real process of signal propagation and fault transmission, and is also more conducive to risk accumulation analysis.
[0071] S323, Structured Anomaly Marking Output: After the entire confidence chain calculation is completed, the evaluation result of each local confidence unit (i.e., the confidence level of that module) is compared with a set confidence downgrade threshold. If the confidence level of a module is lower than this threshold, it means that the module is no longer trustworthy and needs to be marked separately. Furthermore, the entire system should enter a downgrade process or fail the test. Therefore, information on all modules below the threshold is extracted to form an anomaly localization report, where each record contains: Module Number ; Its confidence weakening factor ; Its weight in the chain ; Its final local credibility ; The following structured results are output: ;in, This represents a collection of anomaly location reports. This is the credibility downgrade threshold; if any If this happens, the overall credibility will be forcibly downgraded.
[0072] This Treat it as an anomaly log or risk report for: Show which cells the anomaly occurred in; Assistance engineers in locating the root cause; In a test automation system, trigger an alarm or switch to fail-safe mode.
[0073] Credibility downgrade threshold This threshold serves as a boundary for judging whether local confidence is still acceptable. In many security-related systems, a confidence level below 70% is generally considered too risky and lacks stability guarantees. Setting it too high can cause the system to become overly sensitive to minor disturbances; setting it too low will tolerate too many potential risks. A value of 0.7 represents a trade-off between risk identification and fault tolerance. In a model with an initial value of 1 and progressively decreasing confidence, most minor anomalies will only weaken the confidence level to the 0.8–0.95 range. Only when there are more serious problems will it fall below 0.7. Therefore, 0.7 is used as the threshold.
[0074] This invention encompasses any substitutions, modifications, equivalent methods, and solutions made within the spirit and scope of this invention. To provide the public with a thorough understanding of this invention, specific details are described in detail in the following preferred embodiments; however, those skilled in the art will fully understand the invention even without these details. Furthermore, to avoid unnecessary misunderstanding of the essence of this invention, well-known methods, processes, procedures, components, and circuits are not described in detail.
[0075] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A method for online evaluation and assurance of confidence level in a hardware-in-the-loop simulation system, characterized in that, Includes the following steps: S1. Based on the module boundaries, signal flow direction and interface interaction relationship of the semi-physical simulation system, the simulation system is decomposed to generate local confidence units for independent monitoring; an asynchronous event capture cluster is set in each local confidence unit to record asynchronous abnormal events in real time and generate a local asynchronous event sequence, which serves as the basis data for subsequent confidence weakening; S2. Perform time misalignment correlation analysis on the local asynchronous event sequence and the normal state mode of the local confidence unit to identify the asynchronous abnormal event type, including short-term noise, transient coupling, interface drift or control lag; based on the asynchronous abnormality type, trigger density and cross-channel propagation trend, calculate the confidence weakening factor of each local confidence unit to reflect the true impact of the asynchronous abnormal event in the local area, and output the local confidence assessment result. S3. Construct a confidence isolation and decrement chain for the confidence evaluation results of all local confidence units according to the signal link and control logic to prevent asynchronous anomalies from being submerged in the overall weighted criterion. In the confidence isolation and decrement chain, the overall test confidence is reorganized in a decremental manner according to the level, path position and contribution of the local confidence weakening factor to the final result, forming an overall confidence structure that can indicate the location of local anomalies, avoiding misjudging the test as passed when asynchronous anomalies exist, and generating anomaly location information and independent local confidence records for backtracking.
2. The method for online evaluation and assurance of confidence level in a hardware-in-the-loop simulation system according to claim 1, characterized in that, The splitting specifically includes: Using the system functional modules as boundaries, the simulation model unit, hardware interface unit, and control logic unit with independent data processing capabilities are divided into independent local confidence units; Based on the signal flow direction, monitoring nodes of local confidence units are set at the data source, transmission path and response terminal; Based on the interface interaction relationship, deploy the interaction monitor of the local confidence unit at the data exchange point across units.
3. The method for online evaluation and assurance of confidence level in a hardware-in-the-loop simulation system according to claim 1, characterized in that, The real-time recording of asynchronous exception events specifically includes: Multiple asynchronous event detectors are deployed on the critical signal path of each local confidence unit. These detectors are configured to monitor micro-duration changes, cross-sampling point drift, and aperiodic triggering responses in parallel. Establish an event timestamp sequence and associated signal identifiers to generate a local asynchronous event sequence with timestamps and event types; A circular buffer stores asynchronous events within the most recent time window, forming the underlying data queue for confidence weakening analysis.
4. The method for online evaluation and assurance of confidence level in a hardware-in-the-loop simulation system according to claim 1, characterized in that, The time misalignment correlation analysis specifically includes: A normal state mode timing template for local confidence units is established, which includes a standard signal shape, an expected response time window, and an allowable timing jitter range. A sliding time window is used to align and compare the real-time acquired local asynchronous event sequence with the normal state mode timing template. The correlation coefficient between the local asynchronous event sequence and the normal mode at different time offsets is calculated. When the maximum correlation coefficient is lower than the correlation threshold, it is determined that there is a time misalignment.
5. The online assessment and assurance method for the test confidence of a semi-physical simulation system according to claim 4, characterized in that, The specific asynchronous exception types for identifying asynchronous exception events include: Transient spikes that are identified as having no subsequent associated events are attributed to short-term noise. The simultaneous occurrence of timing offsets in multiple associated units is attributed to transient coupling. If the drift is identified as a continuous unidirectional drift, it is attributed to interface drift. The increased response latency as the load increases is identified as being attributed to control hysteresis.
6. The online assessment and assurance method for the test confidence of a semi-physical simulation system according to claim 5, characterized in that, The calculation of the confidence weakening factor for each local confidence unit specifically includes: Set a base weight for each asynchronous exception type, where the base weight for control lag is greater than that for short-time noise; A trigger density correction coefficient is introduced, which is positively correlated with the frequency of occurrence of asynchronous abnormal events per unit time; Assess cross-channel propagation trends and apply a propagation penalty factor when asynchronous abnormal events propagate along the signal link to subsequent units; A confidence weakening factor is generated by weighting the basic weights, trigger density correction coefficient, and propagation penalty factor. The confidence weakening factor is subtracted from the initial confidence baseline value to obtain the local confidence assessment result, and the local confidence assessment result is output to the reorganization stage.
7. The online assessment and assurance method for the test confidence of a semi-physical simulation system according to claim 6, characterized in that, The trigger density correction coefficient specifically includes: first, counting the number of anomalies within a certain time window, then dividing by the time length to obtain the trigger density. The higher the trigger density, the denser the anomalies. The density is mapped to a correction coefficient through a monotonically increasing function to increase the penalty weight for frequent anomalies. The propagation penalty factor identifies asynchronous anomaly events that spread along the signal link between multiple local confidence units and imposes penalties.
8. The online assessment and assurance method for the test confidence of a semi-physical simulation system according to claim 1, characterized in that, The construction of a confidence isolation and decrement chain based on the confidence evaluation results of all local confidence units according to the signal link and control logic specifically includes: Based on the signal flow graph and control dependency of the hardware-in-the-loop simulation system, local confidence units are connected in series into a chain structure, where the output of each local confidence unit serves as the input of the next local confidence unit. By setting up isolated nodes in the chain structure, asynchronous abnormal events are prevented from being masked in the overall evaluation through weighted averaging, ensuring that the evaluation results of each local confidence unit independently affect the final credibility.
9. The online assessment and assurance method for the test confidence of a semi-physical simulation system according to claim 8, characterized in that, The specific steps of reorganizing the overall test credibility in a decreasing manner include: Each local confidence unit is assigned a confidence weight coefficient, which is calculated based on its hierarchical depth, its criticality in the signal path, and its contribution to the system output. A decreasing algorithm is used to apply local confidence weakening factors step by step along the confidence isolation and decreasing chain, starting from the initial overall confidence value. The weakening factors of higher-level or critical path units have higher attenuation strength. After reorganization, an overall confidence value is generated, and the confidence weight coefficient is accompanied by local anomaly markers to form an overall confidence structure that can indicate the location of anomalies.
10. The online assessment and assurance method for the test confidence of a semi-physical simulation system according to claim 9, characterized in that, The generation of anomaly location information and independent local confidence records for backtracking specifically includes: When the confidence assessment result of any local confidence unit is lower than the confidence downgrade threshold, the overall test confidence is forcibly downgraded to avoid misjudgment; Record the evaluation results, weakening factors and their positions in the chain for each local confidence unit, and generate anomaly location reports and independent confidence logs for fault diagnosis and process backtracking.