Aviation system full life cycle risk assessment method based on triple V engineering model
By decomposing, validating, and managing uncertainties in the triple V engineering model, the systemic lack of model credibility management in aviation systems has been resolved, enabling dynamic evolution of model credibility and safety assessment throughout the entire lifecycle of aviation systems.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA AERO POLYTECH ESTAB
- Filing Date
- 2025-12-15
- Publication Date
- 2026-04-24
AI Technical Summary
Existing technologies make it difficult to systematically and quantitatively establish and maintain the credibility of computational models in the development of aviation systems. This results in a systematic deficiency and insufficient quantification capability in model credibility management, which fails to meet the ultimate safety requirements.
A method based on the triple V-engineering model is adopted, which decomposes and integrates system-level risk requirements through the outer V-engineering model, verifies and confirms and quantifies uncertainty through the middle V-engineering model, and performs life cycle evolution of uncertainty knowledge through the inner V-engineering model. Sequential Bayesian updates are used for information transmission and iteration to construct a dynamic model credibility assessment and management framework.
It enables the dynamic evolution of model credibility throughout the entire lifecycle of the aviation system, ensures that the predictive power and uncertainty of the computational model are strictly quantified, solves the problem of information silos, provides end-to-end trusted model evaluation, and supports the security evaluation of complex systems.
Smart Images

Figure CN121920190A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the fields of aviation systems engineering and computer-aided engineering, and is used for the full life cycle assurance of critical safety and complex systems such as aviation and aerospace. In particular, it relates to a method for full life cycle risk assessment of aviation systems based on the triple V engineering model. Background Technology
[0002] The development of modern aviation systems is facing unprecedented system complexity and extreme safety requirements (e.g., the probability of catastrophic failure must be lower than...). The profound changes driven by both per-flight-hour requirements and severe economic constraints have prompted the industry to shift from the traditional "manufacture-test-modify" model, which relies on physical prototypes, to a new "simulation-analysis-manufacturing" paradigm centered on modeling and simulation (M&S). In particular, "analysis-based certification" has become a critical pathway, utilizing computational simulation results as conformity verification evidence submitted to airworthiness authorities such as the Civil Aviation Administration of China (CAAC) and the Federal Aviation Administration (FAA).
[0003] However, the deep reliance on M&S introduces a fundamental technical challenge: how to systematically and quantitatively establish and maintain trust in the prediction results of safety-critical decision-making computational models, i.e., the model credibility problem. Existing technologies have significant limitations in solving this problem. Summary of the Invention
[0004] To address the shortcomings of existing technologies, this invention provides a risk assessment method for the entire lifecycle of aviation systems based on the Triple V Engineering Model. This method integrates systems engineering processes, iterative VV&UQ processes, and uncertainty knowledge management throughout the entire lifecycle. It overcomes the systemic deficiencies, insufficient quantification capabilities, and lifecycle fragmentation issues in existing technologies regarding the management of computational model credibility. This invention provides a systematic method and apparatus, called the "Triple V Engineering Model," for ensuring the entire lifecycle of complex aviation systems. The aim is to establish a clear, quantitative, traceable, and dynamically evolving framework for model credibility assessment and management.
[0005] Specifically, this invention provides a method for risk assessment of the entire life cycle of an aviation system based on a triple V engineering model, which includes: S1. Obtain system-level risk requirements for aviation systems; S2. Decompose the system-level risk requirements layer by layer according to the outer V engineering model to obtain the nodes of each level of the aviation system related to the system-level risk requirements. The levels include system level, subsystem level, component level, software module level to code unit level, and establish traceability links between nodes at each level. S3. Integrate the decomposed nodes from the bottom layer to the top layer, and use traceability links to test and verify whether they meet the design requirements of the next higher level, until the system-level design requirements are confirmed to be met. If the design requirements of each level up to the system level are met, then execute S4; otherwise, generate a corresponding level defect report and execute S2. S4. According to the mid-level V engineering model, for each node in each system level, perform verification and validation, uncertainty quantification process, and calibrate based on physical experimental data to quantitatively evaluate and ensure the credibility of the calculation model corresponding to each system level. S5. Evolution of the uncertain knowledge lifecycle according to the inner V-engineering model, including: Based on sequential Bayesian update, the posterior probability distribution generated by the system hierarchy at the lower level is used as the prior probability distribution of the system hierarchy at the upper level, and so on, to carry out cross-level transmission and iteration of uncertainty. Sequential Bayes update to: ; in, In the given data arrive Under the condition, uncertainty parameter The posterior probability distribution, In the given data arrive Under the condition, uncertainty parameter The prior probability distribution, This is new evidence; S6. Based on the system level, generate the final calculation model carrying all uncertainty information and construct a baseline digital twin of aviation system-level risk requirements; S7. Throughout the entire lifecycle of the aviation system, by tracking the status of each level of the system-level risk requirement decomposition and executing S6, the results are substituted into the baseline digital twin to conduct a full lifecycle risk assessment of the aviation system.
[0006] Preferably, the outer V-engineering model includes a process for decomposing system-level functions and physical design into nodes at each level, and integrating, testing, and verifying the decomposed nodes at each level.
[0007] Preferably, the mid-level V-engineering model includes a process of modeling and verifying each node, uncertainty propagation, physical testing, validation, and Bayesian calibration.
[0008] Preferably, the inner-layer V-engineering model includes a process based on the calibration in the middle-layer V-engineering model flow, which transmits uncertainty between layers and realizes a systematic iterative combination process.
[0009] Preferably, the nodes at each level of the aviation system in S2 include hardware nodes and software nodes.
[0010] Preferably, step S4, according to the mid-level V engineering model, performs verification and confirmation, uncertainty quantification processes for each node in each system level, and calibrates based on physical experimental data to quantitatively evaluate and ensure the credibility of the computational model corresponding to each system level, including: S41. Model and verify each node in each system level; S42. Based on prior knowledge of input uncertainty, predict the probability distribution of the model output; S43. Conduct physical experiments and obtain physical observation data with measurement uncertainties; S44. Compare the model prediction data with the physical observation data to determine if there is a data bias. If yes, proceed to S46; otherwise, proceed to S45. S45. Directly use the prior probability distribution as the posterior probability distribution. S46. By executing the Bayesian model, the prior probability distribution is updated to the posterior probability distribution based on the likelihood function derived from physical observation data and biases, and the prediction model is calibrated to improve the reliability of the calculation models at each level of the system.
[0011] Preferably, the model verification in S41 includes: generating a systematically encrypted discretized grid result based on the computational model, and calculating the grid convergence index GCI.
[0012] Preferably, the propagation in S42 includes: obtaining the output result based on the initial prior knowledge through model simulation, constructing a chaotic polynomial expansion PCE surrogate model, and then performing Monte Carlo sampling on the PCE surrogate model to obtain a prior probabilistic prediction.
[0013] Preferably, the baseline digital twin in S6 is constructed by the final computational model and its associated set of final posterior probability distributions managed by the inner V-engineering model.
[0014] Compared with the prior art, the beneficial effects of the present invention are as follows: 1. This invention innovatively provides a recursive, nested, iterative feedback nonlinear triple V-engineering model structure. The outer V-engineering model defines which system levels and node objects in the aviation system require credibility assessment, providing context and objectives for the activities of the middle and inner V-engineering layers. The middle V-engineering model ensures that the computational model used at any level is not a "black box," but a "white box" whose predictive capabilities, limitations, and uncertainties have been rigorously quantified. The inner V-engineering model ensures that information along the entire reasoning chain, from the uncertainty of a functional component to the final probabilistic assessment of the overall aircraft safety, is continuous, consistent, and constantly increasing. This makes model credibility no longer a static, one-time assessment, but a dynamic, evolving entity that accumulates information, thus providing robust risk assessment services for the entire lifecycle of the aviation system.
[0015] 2. Based on sequential Bayesian updates, this invention constructs an end-to-end "digital thread" of uncertain knowledge from design, analysis, experimentation, manufacturing to operation and maintenance through an inner V-engineering model. This provides a fundamental solution to the "information silo" problem that has long plagued the development of complex systems and lays the foundation for realizing a truly reliable digital twin based on a trustworthy model. Attached Figure Description
[0016] Figure 1 The flowchart shows the aviation system full life cycle risk assessment method based on the triple V engineering model of this invention. Figure 2 This is a schematic diagram of a triple V engineering model according to an embodiment of the present invention; Figure 3 This is a Bayesian calibration result diagram of the EHA parameters of an electro-hydraulic servo actuator according to an embodiment of the present invention; Figure 4 This is a dynamic evolution diagram of the damping coefficient of the electro-hydraulic servo actuator EHA according to an embodiment of the present invention.
[0017] Key reference numerals: 100, Outer V-engineering model; 200, Middle V-engineering model; 300, Inner V-engineering model. Detailed Implementation
[0018] The following is with reference to the appendix. Figure 1-4 The embodiments of the present invention will be described.
[0019] To address the aforementioned technical problems, this invention provides a "Triple V" engineering model structure that deeply integrates, nests, and synergizes systems engineering, model quality assurance, and knowledge evolution theory. For example... Figure 2As shown, the "Triple V" engineering model structure consists of three logically nested "V"-shaped processes. The outer V engineering model 100 represents the system engineering process, from the left-wing requirement decomposition to the right-wing integration confirmation. The middle V engineering model 200 represents the VV&UQ iterative loop executed at each level (such as the component level). The inner V engineering model 300 represents the lifeline of uncertain knowledge; its left wing represents the refinement of knowledge through data fusion, and its right wing represents the aggregation of knowledge through system integration. The core information flow represents how posterior knowledge becomes new prior knowledge, driving the evolution of the entire model's cognitive capabilities.
[0020] Its internal logic, principles and methods, model structure and innovative features are explained in detail below: I. Outer V-layer Engineering Model 100 (System Engineering Skeleton): Principles and Logic: As the macro-level process framework for the entire development activity, the left wing of the outer V-engineering model represents the decomposition process of functional and physical design, breaking down the top-level system requirements (such as aircraft range and safety indicators) into subsystems, components, and even software modules and code design specifications. The right wing of the outer V-engineering model represents the integration, testing, and verification process, integrating the implemented lower-level components step by step and verifying whether they meet the design requirements of the next higher level through testing, ultimately confirming at the system level whether they meet the top-level requirements.
[0021] Function: The outer V-engineering model 100 defines the "field" and "rhythm" of development assurance activities. It specifies at which development stage and for which system level object a credibility assessment is required. It provides context and objectives for the activities of the middle V-engineering model 200 and the inner V-engineering model 300.
[0022] II. Mid-level V-engineering Model 200 (Model Credibility Engine): Principles and Logic: This layer is the core engine ensuring the quality of the model itself. Its essence is to execute evidence-based scientific induction and deduction loops at each system level. For each node of the outer layer V engineering model 100 (such as "component design"), the middle layer V executes a complete closed-loop process, including: Modeling & Verification: The deductive process involves building a computational model based on physical laws and design knowledge, and verifying the model to ensure that it can accurately solve its mathematical equations.
[0023] Uncertainty propagation (UQ Propagation): A deductive process that predicts the probability space of the model output based on prior knowledge of the uncertainty of the input.
[0024] Physical Experimentation: The observation process that obtains data about the real behavior of the physical world, which involves measurement uncertainty.
[0025] Validation & Bayesian Calibration: This inductive process compares model predictions with physical observations. If discrepancies exist, Bayesian inference is used to "learn" from the observational data, updating the model parameters and completing a cognitive iteration.
[0026] Function: The mid-level V-engineering model 200 is a key component of "trust injection". It ensures that the computational model used at any level is not a "black box", but a "white box" whose predictive power, limitations and uncertainties have been rigorously quantitatively evaluated.
[0027] III. Inner Layer V Engineering Model 300 (Uncertainty Knowledge Evolution Bus): Principles and Logic: This layer is the most theoretically innovative part of this invention. Its core principle is to ontologically view probability distributions as a computable, transferable, and evolvable representation of knowledge states. It constructs an "uncertainty knowledge bus" that spans the entire lifecycle, including: The inner V-engineering model's left wing (Knowledge Refinement) represents the entropy reduction process of knowledge states over time or a logical sequence. Each successful calibration of the middle-layer V-engineering model 200 signifies a reduction in cognitive uncertainty within the system using new information (physical experimental data), manifested as a narrowing of the probability distribution (i.e., a reduction in variance).
[0028] The right wing of the inner V-engineering model (Knowledge Aggregation) represents the process of knowledge combination and propagation at the system level. The refined posterior probability distributions of the lower-level components are passed as input to the models of the upper-level subsystems. Through methods such as Bayesian networks, they are systematically combined to achieve the "fidelity-preserving" transmission of uncertainty between levels.
[0029] The core mechanism of the system is sequential Bayesian update: ; This expression is the mathematical engine of the inner V-layer evolution, which formally defines the iterative process of knowledge: the posterior knowledge at the current moment. It is derived from the knowledge of the previous moment. (As a current priori) and new evidence It was decided jointly.
[0030] Function: The inner V layer is the carrier of the "trust chain." It ensures that information along the entire reasoning chain, from the uncertainty of a single functional component to the final probabilistic assessment of the safety of the entire aircraft, is continuous, consistent, and constantly increasing. This makes the model's credibility no longer a static, one-off assessment, but a dynamic, evolving entity that changes with the accumulation of information.
[0031] As attached Figure 1 As shown, as one aspect of the present invention, the present invention provides a method for risk assessment of the entire life cycle of an aviation system based on a triple V engineering model, which includes: S1. Obtain system-level risk requirements for the aviation system.
[0032] System-level risk requirements for aviation systems form the cornerstone of the entire safety engineering process. They define the top-level safety objectives that the system must meet within acceptable risk levels. These requirements are not arbitrary but are based on industry standards (such as DO-178C, DO-254, ARP4761, ARP4754), regulations (such as FAR / CS 25), and the internal safety policies of airlines / manufacturers.
[0033] For example, the system-level risk requirements of an aviation system can be considered as top-level safety objectives: this is the highest-level and most macro-level risk requirement, usually directly associated with "catastrophic" accidents. It sets the tone for the safety design of the entire system. Catastrophic accident probability requirements: this is the most well-known risk requirement. For civil transport aircraft, it is typically required that: "The probability of any single system or combination of events that could lead to catastrophic failure must be less than 10 per hour." -9 "Catastrophic: refers to an accident that results in an aircraft crash and multiple deaths. 10" -9 / hour: This number is known as the "one billionth of an hour" standard and is the gold standard in the field of aviation safety.
[0034] S2. Decompose the system-level risk requirements layer by layer according to the outer V engineering model to obtain the nodes of each level of the aviation system related to the system-level risk requirements. The levels include system level, subsystem level, component level, software module level to code unit level, and establish traceability links between each level.
[0035] Following the decomposition process of the functional and physical design represented by the left wing 110 in the outer V engineering model flow, the top-level system-level risk requirements (such as the aircraft's range and safety indicators) are decomposed layer by layer. For example, the aforementioned system-level safety objectives (top-level objectives) can be decomposed into specific systems at lower and even lower levels to achieve them. For instance, "The probability of a catastrophic accident caused by the failure of the flight control system must be less than 10." -9 / hour. "The probability of a catastrophic accident caused by a serious misleading navigation system must be less than 10."-9 / hour. "Then it is deciphered to the specific systems at the lower level to implement it, to obtain the nodes (including hardware nodes and software nodes) of each level of the aviation system related to system-level risk requirements. The levels include system level, subsystem level, component level, software module level to code unit level, and a traceability link is established between each level.
[0036] S3. Integrate the decomposed nodes from the bottom layer to the top layer, and use traceability links to test and verify whether they meet the design requirements of the next higher level, until the system-level design requirements are confirmed to be met. If the design requirements of each level up to the system level are met, then execute S4; otherwise, generate a corresponding level defect report and execute S2.
[0037] Following the integration, testing, and verification process represented by the right wing in the outer V-engineering model flow, the underlying components or software code that have achieved hierarchical decomposition are integrated level by level, and traceability links are used to verify whether they meet the design requirements of the next higher level through testing. Finally, at the system level, it is confirmed whether they meet the top-level requirements.
[0038] If the design requirements at each level up to the system level are met, proceed to step S4 to move down the hierarchy. Otherwise, generate a defect report for the corresponding level, identify the problem based on the defect report, and then re-execute S2 to perform system classification until a classification result that meets the design requirements at each level up to the system level is obtained.
[0039] S4. Following the mid-level V-engineering model, for each node in each system level, perform verification and validation (V&V) and uncertainty quantification (UQ) processes, and calibrate based on physical experimental data to quantitatively evaluate and ensure the reliability of the computational models corresponding to each system level. Specifically, this includes: S41. Model and verify each node in each system level.
[0040] Based on physical laws and design knowledge, a computational model is established for each node in each system level. For each node's computational model, model verification is performed to ensure that the model can accurately solve its mathematical equations, thereby quantifying its numerical error. If the error is large, the model is modified.
[0041] The model validation includes: generating systematically encrypted discretized grid results based on the computational model, and calculating the grid convergence index GCI.
[0042] S42. Based on prior knowledge of input uncertainty, predict the probability distribution of the model output.
[0043] Given a set of prior probability distributions containing uncertainty, a computational model is used to propagate the data to generate a prior probabilistic prediction that focuses on the output.
[0044] The propagation process includes: obtaining output results based on initial prior knowledge through model simulation, constructing a chaotic polynomial expansion PCE surrogate model, and then performing Monte Carlo sampling on the PCE surrogate model to obtain prior probabilistic predictions.
[0045] It also includes: calculating the global sensitivity index from the coefficients of the PCE surrogate model, identifying the uncertain inputs that contribute the most to the variance of prior probabilistic predictions, and giving them priority consideration.
[0046] S43. Conduct physical experiments on real-world physical behaviors and obtain physical observation data with measurement uncertainties.
[0047] S44. Compare the model prediction data with the physical observation data to determine if there is a data bias. If yes, proceed to S46; otherwise, proceed to S45.
[0048] S45. Use the prior probability distribution directly as the posterior probability distribution.
[0049] S46. By executing the Bayesian model, the prior probability distribution is updated to the posterior probability distribution based on the likelihood function derived from physical observation data and biases, and the prediction model is calibrated to improve the reliability of the calculation models at each level of the system.
[0050] The Bayesian model used is a Markov Chain Monte Carlo (MCMC) algorithm. The MCMC algorithm is employed for posterior sampling, updating the prior distribution of parameters to the posterior distribution. Physical experimental data is used to quantitatively reduce the cognitive uncertainty in the computational model, achieving the "knowledge refinement" defined by the subsequent inner V-model.
[0051] S5. Evolution of the uncertain knowledge lifecycle according to the inner V-engineering model, including: The process involves executing an inner-layer uncertainty evolution V-model representing the lifecycle evolution of uncertain knowledge. Based on sequential Bayesian updates, the posterior probability distribution generated at the lower-level system hierarchy is used as the prior probability distribution at the next higher-level system hierarchy, and so on, to perform cross-level transmission and iteration of uncertainty.
[0052] Sequential Bayes update to: ; in, For the posterior knowledge at the current moment (given data) arrive Under the condition, parameters (posterior probability distribution) Prior knowledge at the current moment (given data) arrive Under the condition, parameters (the prior probability distribution) This is new evidence.
[0053] Sequential Bayesian update is the mathematical engine for the evolution of the inner V-engineering model process. It formally defines the iterative process of knowledge: the posterior knowledge at the current time step. It is derived from the knowledge of the previous moment. (As a current priori) and new evidence This is a joint decision. The inner V-engineering model process is the carrier of the "trust chain." It ensures that the information along the entire reasoning chain is continuous, consistent, and constantly increasing, from the uncertainty of a single functional component to the final probabilistic assessment of the safety of the entire aircraft. This makes the model's credibility no longer a static, one-off assessment, but a dynamic, evolving entity that changes with the accumulation of information.
[0054] S6. Based on the system level, generate the final calculation model carrying all uncertainty information and construct a baseline digital twin of aviation system-level risk requirements.
[0055] Based on the top-level system-level generation of the final computational model (whose credibility has been guaranteed by the nested execution of steps S5 and S6 above), this final full-aircraft computational model, which has been fully verified by the "triple V" method and carries all uncertainty information, together with its associated set of final posterior probability distributions managed by the inner V model, constitutes the baseline digital twin of the complex aviation system.
[0056] S7. Throughout the entire lifecycle of the aviation system, by tracking the status of each level of the system-level risk requirement decomposition and executing S6, the results are substituted into the baseline digital twin to conduct a full lifecycle risk assessment of the aviation system.
[0057] Throughout the entire lifecycle of an aviation system, multiple sensors fixed to the complex system track the status of each level of system-level risk requirement decomposition, receive operational data streams, execute dynamic model update algorithms, and continuously update the posterior probability distribution in the inner V-model. This synchronizes the final computational model with the physical instance, and the results are then substituted into the baseline digital twin for a full lifecycle risk assessment of the aviation system. The dynamic model update algorithm is implemented using a particle filter.
[0058] As another embodiment, the method of the present invention is applied to the development assurance and full life-cycle risk assessment process of the active gust load alleviation (GLA) function in a novel, highly redundant fly-by-wire flight control system (FCS), including: P1, Risk requirements for obtaining the active gust mitigation function of the aircraft's fly-by-wire flight control system (equivalent to S1 above).
[0059] The Quantity of Interest (QoI) is defined as a key airworthiness compliance requirement: "When an aircraft encounters a '1-cos' vertical gust as defined by airworthiness regulations, its maximum bending moment at the wing root must be guaranteed." Exceeding the final design limit load ( The probability of ) is lower than . P2. Execution of the first phase: definition and planning of the outer V-layer engineering model (equivalent to S2-S3 above).
[0060] Based on the outer V model 100, the FCS system is decomposed into multiple levels from top to bottom, and a bottom-up integration and verification path is planned.
[0061] Level 1: System level (six-degree-of-freedom full-machine nonlinear simulation model).
[0062] Level 2: Component level (simulation models of electro-hydraulic servo actuators (EHA), sensors, control law algorithm modules, etc.).
[0063] Level 3: Hardware-in-the-Loop (HIL) and Flight Control Hydraulic System Integrated Test Bench (connecting the physical flight control computer to the simulation environment).
[0064] Level 4: Flight Test Level (Final Physical System Validation).
[0065] For each level, a detailed VV&UQ plan was developed, which clarified the required computational models, physical experiments, and credibility assessment criteria.
[0066] P3. Execute the second stage: nested execution of the middle-layer V-engineering model and the inner-layer V-engineering model (equivalent to S4 above). Taking the EHA model of a level 2 component-level electro-hydraulic servo actuator as an example: Objective: To quantitatively evaluate the numerical errors (e.g., output force, response time, output shaft displacement, etc.) of the solver in the Simulink model of the electro-hydraulic servo actuator (EHA).
[0067] Procedure: The grid convergence exponential (GCI) method was used to evaluate the accuracy and reliability of the computational results. The actuator's response time to a step command was selected as the core output of interest (QoI). This includes: Systematic discretization: Three sets of systematically encrypted time steps are used. , , (Encryption ratio r = 2); Data acquisition: Obtain three response time simulation results ( ): 26.02 ms, 25.40 ms, 25.15 ms.
[0068] Detailed derivation: Calculation of convergence order: ; Calculate GCI: ; Conclusion: The numerical error of the response time with a 1ms step is 0.84%, which is negligible compared to the expected physical uncertainty. The solution is verified. If the numerical error exceeds 5%, it proves that the model's solution accuracy is insufficient and needs improvement.
[0069] Uncertainty propagation and prior prediction: Objective: To predict the range of uncertainty in EHA bandwidth performance prior to physical testing.
[0070] The process includes: Uncertainty Representation (Inner Layer V Starting Point): Identify key input uncertainties to form initial prior knowledge of the inner layer V(300): The following example uses two aspects of uncertainty: Hydraulic oil bulk modulus (Chance and uncertainty); Servo valve opening area error (Cognitive uncertainty); Construction of a Chaotic Polynomial Expansion (PCE) Proxy Model: Based on 100 high-fidelity Simulink runpoints, constructing an EHA bandwidth with respect to ( , The PCE proxy model. Proxy model input: hydraulic oil bulk modulus. and servo valve opening area error ; Proxy model output: EHA bandwidth.
[0071] UQ propagation: Execution on the PCE agent model Sub-Markov chain Monte Carlo MCMC sampling (uncertain bandwidth) yields a prior probabilistic prediction of the bandwidth: mean = 20.51 Hz, 95% confidence interval = [17.53 Hz, 23.49 Hz].
[0072] Sensitivity analysis: The Sobol index was calculated from the PCE coefficients, and a global sensitivity analysis was conducted, revealing... It contributes 71% to the bandwidth variance. It is 26%.
[0073] This result guides engineers to prioritize the control of the bulk modulus of hydraulic oil, which involves controlling the temperature, pressure, and air content of the hydraulic oil.
[0074] Bayesian model calibration: Objective: To integrate physical experimental data, reduce model cognitive uncertainty, and complete the closed loop of the mid-level V engineering model 200.
[0075] The process includes: Physical test: The average bandwidth measured by the EHA bench test is Hz, measurement uncertainty Hz.
[0076] Bayesian model calibration: using the parameters determined in the preceding steps Prior probability distributions serve as initial knowledge, based on experimental data. As new evidence, construct the likelihood function: ; In the formula, Indicates that under given parameters and Under these conditions, experimental observation data The probability distribution; Indicates by and The established PCE agent model, The variance of the observed noise.
[0077] The MCMC algorithm is used for posterior sampling to update the prior distribution of parameters to the posterior distribution. Physical experimental data is used to quantitatively reduce the cognitive uncertainty in the computational model, achieving the "knowledge refinement" defined by the subsequent inner V model.
[0078] Results analysis: Posterior distribution: such as Figure 3 As shown in the figure, this illustrates the impact of the key uncertainty parameter "servo valve opening area error" in the EHA model. "The results of Bayesian calibration are shown. The horizontal axis represents the parameter value (%), and the vertical axis represents the probability density. The blue dashed area represents the broad prior distribution (uniform distribution U(-5%, +5%)) based on the design tolerance setting, reflecting the very limited knowledge of this parameter before the physical experiment. The red solid area represents the posterior distribution obtained after integrating data from 10 bench tests. It can be seen that the peak of the posterior distribution is concentrated around +3.1%, and the distribution range is significantly narrowed, indicating that the physical test data greatly refined the knowledge of this parameter, and the cognitive uncertainty was significantly reduced." The posterior distribution exhibits a significant change in convergence compared to its broad uniform prior distribution.
[0079] Detailed derivation: Posterior statistic: derived from MCMC sample analysis The posterior mean is +3.1%, and the 95% confidence interval is [+0.7%, +5.5%].
[0080] Uncertainty reduction rate: .
[0081] Conclusion: Cognitive uncertainty was significantly reduced. This calibrated EHA model and its more accurate posterior parameter distribution represent a successful evolution of knowledge.
[0082] P4. Execution of the third stage: stepwise aggregation of uncertainty (equivalent to S5 above).
[0083] The credible models of all components (such as EHA) in Level 2 are integrated into the full-machine simulation model of Level 1. The inner layer V here represents crucial knowledge transfer: the posterior of Level 2 becomes the prior of the analysis in Level 1. Using Bayesian network technology, all the uncertainties refined at the lower levels are systematically and correlatedly propagated to the top-level QoI (wing root moment). (That is, the uncertainties of relevant lower-level nodes are iteratively improved, integrated, and extrapolated to the top-level system level).
[0084] P5. Perform the fourth phase: system-level verification and certification assurance (equivalent to S6 above).
[0085] System verification: The probabilistic predictions of the integrated model were finally verified with the test data of the HIL and flight control hydraulic system integrated test bench. The deviation was within the joint uncertainty range, and the verification was successful.
[0086] Authentication Analysis: Perform simulation and calculate Because the probability is lower than As required by law, GLA functionality is certified.
[0087] Baseline Digital Twin: This final full-aircraft model, which has been fully validated using the "Triple V" method and carries all uncertainty information, along with its associated set of final posterior probability distributions managed by the inner V model, is archived as the baseline digital twin of the aircraft (AC001).
[0088] P6. Execution of Phase 5: In-service Operation and Dynamic Evolution (equivalent to S7 above).
[0089] Two years after aircraft AC001 entered service, the Health Monitoring System (HUMS) detected that its aileron response was systematically slower than when it left the factory.
[0090] Dynamic model update: Objective: To quantitatively infer the physical causes of performance degradation.
[0091] Process: The equivalent damping coefficient inside the EHA As hidden health conditions to be tracked. Including: Initialization: A particle filter is used to initialize 1000 particles, whose distribution follows... Posterior distribution at the time of manufacture .
[0092] Sequential update: Using the actual response time obtained from HUMS after each flight cycle as the observation data, the particle weights are continuously updated and resampled.
[0093] Results Analysis: After data fusion over thousands of flight cycles, the particle distribution in the particle filter tends to stabilize. For the converged particle set (representative...) The mean of the set of possible values is obtained by statistical calculation. Standard deviation The distribution is as follows: Figure 4 As shown in the figure, this diagram illustrates the use of a particle filter to dynamically track the "equivalent damping coefficient"—a parameter representing the internal health status of an in-service EHA actuator. The evolution process of "". The horizontal axis represents the flight cycle (time), and the vertical axis represents the evolution process of "". The parameter values are shown in the figure. The figure illustrates the values for three time slices. Probability distribution. At t = 0 (factory condition), the distribution is relatively wide, reflecting initial uncertainty. As service data is continuously incorporated, the distribution begins to drift towards higher values at t = 2000 cycles. By t = 4000 cycles, the distribution has significantly migrated and converged to a new state centered at 1.15, accurately quantifying the "personalized" degradation of the component, clearly distinct from the initial state.
[0094] Conclusion: The knowledge of the inner V layer was successfully updated dynamically. It can be quantitatively inferred that the EHA of this specific aircraft has experienced approximately 15% performance degradation.
[0095] Predictive maintenance decisions include: The updated By incorporating digital twins and reassessing the risks, we discovered... It has risen to Based on this, the system automatically triggered a predictive maintenance instruction, suggesting that the specific actuator be inspected in the near future, thus realizing the transformation from passive maintenance to intelligent predictive maintenance.
[0096] This example demonstrates in detail how the method of the present invention systematically builds model credibility and dynamically integrates it throughout the entire lifecycle of design, certification, and operation of complex aerospace systems, demonstrating significant innovation and industrial applicability.
[0097] The embodiments described above are merely preferred embodiments of the present invention and are not intended to limit the scope of the present invention. Various modifications and improvements made by those skilled in the art to the technical solutions of the present invention without departing from the spirit of the present invention should fall within the protection scope defined by the claims of the present invention.
Claims
1. A method for risk assessment of the entire life cycle of an aviation system based on a triple V engineering model, characterized in that, It includes: S1. Obtain system-level risk requirements for aviation systems; S2. Decompose the system-level risk requirements layer by layer according to the outer V engineering model to obtain the nodes of each level of the aviation system related to the system-level risk requirements. The levels include system level, subsystem level, component level, software module level to code unit level, and establish traceability links between nodes at each level. S3. Integrate the decomposed nodes from the bottom layer to the top layer, and use traceability links to test and verify whether they meet the design requirements of the next higher level, until the system-level design requirements are confirmed to be met. If the design requirements of each level up to the system level are met, then execute S4; otherwise, generate a corresponding level defect report and execute S2. S4. According to the mid-level V engineering model, for each node in each system level, perform verification and validation, uncertainty quantification process, and calibrate based on physical experimental data to quantitatively evaluate and ensure the credibility of the calculation model corresponding to each system level. S5. Evolution of the uncertain knowledge lifecycle according to the inner V-engineering model, including: Based on sequential Bayesian update, the posterior probability distribution generated by the system hierarchy at the lower level is used as the prior probability distribution of the system hierarchy at the upper level, and so on, to carry out cross-level transmission and iteration of uncertainty. Sequential Bayes update to: ; in, In the given data arrive Under the condition, uncertainty parameter The posterior probability distribution, In the given data arrive Under the condition, uncertainty parameter The prior probability distribution, This is new evidence; S6. Based on the system level, generate the final calculation model carrying all uncertainty information and construct a baseline digital twin of aviation system-level risk requirements; S7. Throughout the entire lifecycle of the aviation system, by tracking the status of each level of the system-level risk requirement decomposition and executing S6, the results are substituted into the baseline digital twin to conduct a full lifecycle risk assessment of the aviation system.
2. The method for risk assessment of the entire life cycle of aviation systems based on the triple V engineering model according to claim 1, characterized in that, The outer V-engineering model includes the process of decomposing system-level functions and physical design into nodes at each level, and integrating, testing, and verifying the decomposed nodes at each level.
3. The method for risk assessment of the entire life cycle of aviation systems based on the triple V-engineering model according to claim 1, characterized in that, The mid-level V-engineering model includes modeling and verification of each node, uncertainty propagation, physical testing, confirmation, and Bayesian calibration processes.
4. The method for risk assessment of the entire life cycle of aviation systems based on the triple V-engineering model according to claim 1, characterized in that, The inner-layer V-engineering model includes a process based on the calibration in the middle-layer V-engineering model flow, which transmits uncertainty between layers and realizes a systematic iterative combination process.
5. The method for risk assessment of the entire life cycle of aviation systems based on the triple V-engineering model according to claim 1, characterized in that, The nodes at each level of the aviation system in S2 include hardware nodes and software nodes.
6. The method for risk assessment of the entire life cycle of aviation systems based on the triple V-engineering model according to claim 1, characterized in that, S4, according to the mid-level V engineering model, performs verification and validation, uncertainty quantification processes for each node in each system level, and calibrates based on physical experimental data to quantitatively evaluate and ensure the credibility of the computational model corresponding to each system level, including: S41. Model and verify each node in each system level; S42. Based on prior knowledge of input uncertainty, predict the probability distribution of the model output; S43. Conduct physical experiments and obtain physical observation data with measurement uncertainties; S44. Compare the model prediction data with the physical observation data to determine if there is a data bias. If yes, proceed to S46; otherwise, proceed to S45. S45. Directly use the prior probability distribution as the posterior probability distribution. S46. By executing the Bayesian model, the prior probability distribution is updated to the posterior probability distribution based on the likelihood function derived from physical observation data and biases, and the prediction model is calibrated to improve the reliability of the calculation models at each level of the system.
7. The method for risk assessment of the entire life cycle of aviation systems based on the triple V-engineering model according to claim 6, characterized in that, The model verification in S41 includes: generating a systematically encrypted discretized grid result based on the computational model, and calculating the grid convergence index GCI.
8. The method for risk assessment of the entire life cycle of aviation systems based on the triple V engineering model according to claim 6, characterized in that, The propagation in S42 includes: obtaining the output result based on the initial prior knowledge through model simulation, constructing a chaotic polynomial expansion PCE surrogate model, and then performing Monte Carlo sampling on the PCE surrogate model to obtain the prior probabilistic prediction.
9. The method for risk assessment of the entire life cycle of aviation systems based on the triple V engineering model according to claim 1, characterized in that, The baseline digital twin in S6 is constructed by the final computational model and its associated set of final posterior probability distributions managed by the inner V-engineering model.