Apparatus for risk assessment at the output of a system

The risk assessment device addresses inefficiencies in evaluating specification violations by selectively sampling high-risk inputs, reducing testing frequency and cost while improving accuracy through a multimodal optimization algorithm.

JP2026007710APending Publication Date: 2026-01-16TOYOTA JIDOSHA KK +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024107804
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-03
Publication Date
2026-01-16

AI Technical Summary

Technical Problem

Existing systems face inefficiencies in evaluating the risk of specification violations due to the rarity and minimal severity of such violations, necessitating a more focused approach to input testing to reduce the number of tests required for effective evaluation.

Method used

A risk assessment device that selectively samples input values likely to cause specification violations, calculating a risk value based on the evaluation of these inputs using a probability distribution determined by a multimodal optimization algorithm, thereby reducing the number of tests and improving accuracy.

Benefits of technology

This approach significantly reduces the frequency and cost of system testing while enhancing the accuracy of risk value estimation by focusing on inputs with high risk potential, allowing for efficient evaluation of system outputs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026007710000001_ABST
    Figure 2026007710000001_ABST
Patent Text Reader

Abstract

To save the number of times of tests by performing a test by mainly using an input value which is likely to cause a risk and evaluating the risk in a device for evaluating the risk (specification violation) of the output of a system.SOLUTION: A device gives an input value to a system to be evaluated, and calculates a value corresponding to an integral value of a multiplication value of a non-negative evaluation value and an occurrence probability of the input value giving the evaluation value as a risk value while calculating an evaluation value indicating a degree of risk on the basis of an output value and a specification. The risk value is calculated as a sum of values obtained by sampling a plurality of input values in a domain of the input values and dividing a product of a non-negative evaluation value calculated corresponding to each of the sampled input values and an occurrence probability of each of the input values by a sampling probability of each of the input values. The sampling probability of each input value is determined to be higher as the evaluation value for each input value is larger.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an apparatus for evaluating the output of any system that outputs a result in response to an input, and more particularly to an apparatus for evaluating the extent to which the output of any system may deviate from specifications (the range of outputs planned for the system). In this specification, deviation of the system output from specifications (specification violation) is referred to as "risk." [Background technology]

[0002] When a system is put into practical use, it is desirable to be able to confirm that the system's output satisfies its specifications as a quality assurance measure. For example, Non-Patent Document 1 proposes a method for achieving this, in which a system is assumed to provide output for input determined by a discrete-time or continuous-time stochastic process, and the specifications are described in temporal logic. The method uses basic Monte Carlo methods to quantify, through robust semantics, the extent to which the system's behavior satisfies its specifications, using Value at Risk (VaR) and Conditional Value-at-Risk (CVaR). [Prior art documents] [Non-patent literature]

[0003] [Non-Patent Document 1] LARS LINDEMANN, LEJUN JIANG, NIKOLAI MATNI and GEORGE J. PAPPAS, "Risk of Stochastic Systems for Temporal Logic Specifications", ACM Transactions on Embedded Computing Systems, Vol. 22, No. 3, Article 54. Publication date: April 2023. https: / / doi.org / 10.1145 / 3580490. Summary of the Invention [Problem to be solved by the invention]

[0004] To evaluate the existence or extent of specification violations (risks) in a system's output, tests are performed by providing various inputs to the system or its simulator to obtain outputs, and then evaluating whether the obtained outputs satisfy the specifications. In real-world systems, the probability of specification violations is generally low, and even if they do occur, it is implicitly expected that the severity of the violations will be minimal. For example, a lane-keeping assist system is permitted to allow a vehicle to deviate from its lane under adverse conditions, such as around sharp curves, but is expected to maintain the center of the lane as much as possible. That is, even in systems that tolerate specification violations, specification violations rarely occur. Furthermore, inputs that cause rare specification violations are rarely provided to the system, and specification violations are unlikely to occur when the system inputs are within the normal range. Therefore, in assessing system risk, testing by selectively sampling inputs that are likely to cause risks, rather than uniformly sampling all values ​​within the range of possible inputs, can reduce the number of test runs and enable more efficient system evaluation.

[0005] In view of the above circumstances, a main object of the present invention is to reduce the number of tests in an apparatus that performs tests to provide various inputs to a system and obtain outputs to evaluate the risk of the output (violation of specifications), by conducting tests that focus on values ​​that are likely to cause risk as inputs to the system and evaluating the risk. [Means for solving the problem]

[0006] According to the present invention, the above problem is solved by providing a risk assessment device for a system, comprising: specification setting means configured to set specifications for the output of the system to be evaluated; an evaluation value calculation means configured to calculate an evaluation value representing the degree of risk based on the input values ​​to the system and the specifications of the output values; a risk value calculation means configured to sample the input values ​​and calculate a risk value using the evaluation value calculated from the sampled input values ​​by the evaluation value calculation means; an input value sampling probability determination means configured to determine a sampling probability, which is the probability that the input value is sampled, according to a predetermined condition; Including, The object of the present invention is achieved by an apparatus in which the risk value calculation means is configured to calculate a risk value based on the evaluation value calculated corresponding to each of the input values, the occurrence probability of each of the sampled input values, the sampling probability of each of the input values, and the number of samples of the input values. Note that the apparatus of the present invention can be realized by operation in accordance with a program of any computer device. In addition, the "evaluation value calculation means" may be configured to provide an input value to the system, obtain an output value of the system in response to the input, and calculate an evaluation value representing the degree of risk based on the output value and the specifications. The "risk value calculation means" may be configured to sample a plurality of input values ​​in the domain of input values ​​of the system, and use the evaluation value calculated from the sampled input values ​​by the evaluation value calculation means to calculate, as a risk value, a value equivalent to the integral of the product of a non-negative value among the evaluation values ​​and the probability of occurrence of the input value that gives that evaluation value. The "input value sampling probability determination means" may be configured to determine the sampling probability, which is the probability that each input value will be sampled in sampling the multiple input values ​​from the domain of input values ​​of the system when calculating the risk value in the risk value calculation means, so that the sampling probability becomes higher the larger the evaluation value calculated from the input value (predetermined condition). The "risk value calculation means" may be configured to sample the plurality of input values ​​within the domain of the input values ​​according to the sampling probability, and calculate, as the risk value, a value obtained by dividing the product of the evaluation value calculated corresponding to each of the plurality of sampled input values ​​for which the evaluation value is non-negative by the probability of occurrence of each of the plurality of sampled input values ​​that give each of the non-negative evaluation values ​​by the sampling probability of each of the plurality of sampled input values ​​that give each of the non-negative evaluation values, and then dividing the sum of the values ​​obtained by dividing the sum by the total number of samples.

[0007] In the above configuration, the "system" to be evaluated may be any system that generates an output for an input, such as a system composed of real machinery or equipment, or a simulation that virtually realizes the input and output of the machinery or equipment using a computer or other device. The "system output specifications" refer to the conditions that the system's output must satisfy, typically expressed as a normal output range or any condition that the range must satisfy. As already mentioned, "risk" refers to deviation from the output specifications, i.e., a violation of the specifications. The "evaluation value" represents the degree of risk of the output value obtained from each input value. The greater the deviation of the output value from the boundary of the specification range, the larger the positive value. When the output value satisfies the specification, the value is calculated to be negative (0 at the boundary of the specification). As will be explained in the following embodiment section, the evaluation value may be a value obtained by inverting the sign of a robust value defined based on the difference between the system output and the boundary of the specification. The robustness value increases as the output value is less likely to deviate from the specification boundary, i.e., as the output value moves further away from the specification boundary toward the inside of the specification range. The more the output value deviates from the specification boundary, the more negative the value becomes. When the output is consistent with the boundary, the robustness value may be defined as 0. That is, the evaluation value is defined to increase as the output value deviates from the specification boundary to the outside of the specification range, corresponding to the increased risk to system stability and goal achievement. The "risk value" is defined as a value equivalent to the integral of the product of a non-negative evaluation value and the probability of occurrence of an input value that gives that evaluation value within the input value's domain (the range of possible input values). That is, the risk value increases as the frequency and degree of deviation of the output value from the specification increase in a system. Therefore, the risk value can be used as an index to evaluate the degree of deviation of the system's output from the specification based on the magnitude and frequency of the deviation.

[0008] According to its definition, the above-mentioned "risk value" is obtained by integrating the product of a non-negative evaluation value and the probability of occurrence of an input value that gives that evaluation value over the domain of input values. However, the form of the evaluation value function for an input value is generally unknown (the probability of occurrence of an input value is assumed to be set or obtainable as appropriate). In such cases, one method for calculating the risk value is to provide input values ​​appropriately sampled within the domain of input values ​​to the system to obtain an evaluation value, and then calculate (estimate) the value by integrating the product of multiplying a non-negative evaluation value among those evaluation values ​​by its occurrence probability (the probability of occurrence of the input value). As mentioned above, in general, in a system, it is assumed that the output satisfies specifications over most of the domain of input values, and that input values ​​that cause risk are rare. In other words, even if input values ​​are sampled evenly across the entire domain of input values ​​to calculate the evaluation value, most of the input values ​​will not contribute to the risk value, and the calculation of the evaluation value will be ineffective. Furthermore, for the range of input values ​​where the evaluation value is non-negative and contributes to the calculation of the risk value, increasing the number of samples in the range where the contribution to the risk value is large, i.e., the range where the magnitude of the non-negative evaluation value is large, is expected to improve the accuracy of risk value estimation.

[0009] Therefore, in the device of the present invention, as described above, risk values ​​are estimated through sampling of input values. First, while the evaluation value calculation means calculates the evaluation values ​​as described above, the input value sampling probability determination means searches for input values ​​in the system's input value domain that produce non-negative evaluation values, and determines the sampling probability of each input value when sampling the input values ​​in the risk value calculation means so that the sampling probability for each input value increases as the evaluation value calculated for that input value increases. The risk value is then calculated by sampling a plurality of input values ​​within the input value domain according to their sampling probabilities, and, in accordance with the theory of importance sampling, dividing the product of the evaluation value calculated for each of the plurality of sampled input values ​​and the probability of occurrence of each of the input values ​​that give each of the evaluation values ​​by the sampling probability for each of the plurality of sampled input values, and then dividing the sum of the resulting values ​​by the number of sampled input values. [According to the theory of importance sampling, if S(x) is a function of random variable x and the joint density function p(x) when the sampling probability q(x)=0, then the integral of the product of S(x)·p(x)=0 is given by Σ{S(x)·p(x) / q(x)} / N. Here, Σ is the sum and N is the number of samples.] [Usually, input values ​​with a negative evaluation value have a sampling probability of 0, and are expected not to be sampled when calculating the risk value.]

[0010] According to the above-described configuration of the device of the present invention, when calculating a risk value by sampling input values, it is possible to calculate an evaluation value by selectively sampling input values ​​that have a high evaluation value and contribute greatly to the risk value, rather than sampling input values ​​evenly across the entire domain of input values ​​and calculating an evaluation value. This significantly reduces the system testing load required to calculate the evaluation value, and makes it possible to reduce the time, cost, and labor required for risk evaluation. It is also expected that the accuracy of the risk value estimated by sampling will be improved.

[0011] In the above-described apparatus of the present invention, the specifications to be satisfied by the system output may generally be ranges or values ​​that change over time, and therefore the specifications may be described by signal temporal logic. In this case, the evaluation value may be an index value that represents the degree of deviation of the system output value from the specifications over time.

[0012] In the above-described configuration of the present invention, the input value sampling probability determination means may be configured to determine the sampling probability of each input value according to a multimodal optimization algorithm. Here, the multimodal optimization algorithm is a continuous optimization algorithm based on CMA-ES (Covariance Matrix Adaptation Evolution Strategy). In short, in the present invention, a process of selecting a plurality of input value points so that the density of selected points centered on a certain point within the entire domain of input values ​​forms a Gaussian distribution, calculating evaluation values, selecting input value points that give the top few of the evaluation values, selecting a plurality of input values ​​so that the density of selected points forms a Gaussian distribution centered on the selected input value point, calculating evaluation values, and selecting input value points that give the top few of the evaluation values, and repeating this process until an appropriately set condition, for example, the distribution of selected points within the domain of input values, converges. Then, within the domain of the input values, several point distributions are formed that follow Gaussian distributions with a high density of points selected around points that give high evaluation values, and these Gaussian distributions are combined to form a mixed Gaussian distribution, which is then normalized to form a probability density distribution representing the sampling probability. Note that, prior to combining the Gaussian distributions, point distributions in which the number of non-negative evaluation values ​​is less than an appropriately set proportion may be excluded.

[0013] Furthermore, in the above-described configuration of the device of the present invention, in the process of determining the sampling probability of each input value in the input value sampling probability determination means, evaluation values ​​are calculated at selected points of the input value within the domain of the input value. Therefore, if previously calculated evaluation values ​​are used in the risk value calculation process in the risk value calculation means, this is advantageous in that the input / output processing load or test load of the system can be further reduced. In this regard, in the process of determining the sampling probability of each input value, the higher the sampling probability of the input value, the more evaluation values ​​corresponding to the input value are calculated at various points. In this case, in the risk value calculation process in the risk value calculation means, the evaluation values ​​calculated for each of the multiple sampled input values ​​are obtained by using the previously calculated evaluation values ​​corresponding to input values ​​sampled with equal probability from among the points for which evaluation values ​​are calculated by the input value sampling probability determination means. This allows evaluation values ​​corresponding to input values ​​sampled according to the sampling probability to be obtained.

[0014] In the calculation of risk values ​​in the device of the present invention, it is expected that the more sampling times, the closer the calculated risk value will be to its true value (the integral of the product of a non-negative evaluation value and the occurrence probability of the input value that gives that evaluation value). Therefore, the process of sampling multiple input values ​​to calculate a risk value may be configured to be repeated until a predetermined condition that is set appropriately is satisfied. Specifically, the predetermined condition may be that the risk value is sampled a minimum number of times or more until a predetermined convergence condition is satisfied, or until the number of samplings reaches a maximum number of times that is set appropriately. [Effects of the Invention]

[0015] Thus, with the device of the present invention, in order to evaluate the risk of a system, tests are performed in which various inputs are applied to the system to obtain outputs, and when a risk value is calculated from the relationship between the output values ​​and specifications, input / output processing of the system is performed by narrowing down the input values ​​to those with a high degree of risk, which is expected to significantly reduce the frequency of performing input / output tests of the system, more efficiently reduce costs and labor, and improve the accuracy of risk value estimation. The configuration of the device of the present invention may be used to evaluate either an actual system or a simulated system.

[0016] Other objects and advantages of the present invention will become apparent from the following description of preferred embodiments of the invention. [Brief explanation of the drawings]

[0017] [Figure 1] Fig. 1(A) is a diagram schematically illustrating a computer in which a risk assessment device according to this embodiment is realized, and Fig. 1(B) is a diagram in the form of a block diagram illustrating the configuration of the risk assessment device according to this embodiment. [Figure 2] Fig. 2(A) is a diagram showing a distribution of evaluation values ​​calculated by the risk assessment device according to this embodiment. Fig. 2(B) is a diagram showing a domain of input values, showing sampling points in the case of uniform sampling and input value points that give local maximum evaluation values. Fig. 2(C) is a diagram showing a domain of input values, showing input value points that give local maximum evaluation values ​​and sampling points in the case of sampling in the vicinity. [Figure 3] Figures 3(A) to 3(D) are schematic diagrams illustrating the process of determining points to select input values ​​according to a multimodal optimization algorithm in the device of this embodiment. Figure 3(E) is a schematic diagram illustrating the process of forming a mixed Gaussian distribution by combining Gaussian distributions of selected points obtained according to the multimodal optimization algorithm in the device of this embodiment. [Figure 4] FIG. 4 is a block diagram showing the configuration of a risk assessment device according to another aspect of this embodiment. [Explanation of symbols]

[0018] 1...Computer main body, 2...Computer terminal, 3...Monitor, 4...Keyboard, mouse (input device) BEST MODE FOR CARRYING OUT THE INVENTION

[0019] The present invention will now be described in detail with reference to some preferred embodiments thereof with reference to the accompanying drawings, in which like reference numerals indicate like parts.

[0020] Computer equipment configuration The risk assessment device for a system according to this embodiment may be realized by the operation of a computer program on a computer device 1, as illustrated in FIG. 1(A), of a type commonly used in this field. The computer device 1 is typically equipped with a CPU, a memory storing various programs for executing calculations, a storage device M having a work memory and a data memory used during calculations, and a computer terminal device 2 having a monitor 3 for displaying and outputting instructions from the implementer to the computer device 1, calculation results, and other information, and an input device 4 such as a keyboard and a mouse. Various simulation results may be displayed on the monitor 3, etc. Each component of the risk assessment device illustrated in FIG. 1(B) below is realized by the operation of the computer device 1 according to the program. When a system operation test is obtained by simulation, input / output operations of the system may be performed on the computer device 1 (or may be performed on a separate computer device). When a system operation test is performed on an actual device, an I / O device (not shown) for communicating input / output with the system may be connected to the computer device 1.

[0021] Risk assessment device configuration In the risk assessment device at the output of the system according to this embodiment, as shown in Figure 1(B), a specification setting unit C, an assessment value calculation unit E, an input value sampling probability determination unit D, and a risk value calculation unit R are provided.

[0022] More specifically, the evaluation value calculation unit E is configured to provide an input i to the system S, obtain its output o, and calculate an "evaluation value," which is an index representing the degree of risk of the system's output value corresponding to a certain input value, i.e., the degree of deviation from the specification sp, based on the output o and the specification sp that the system's output value must satisfy, as set by the specification setting unit C. The input value sampling probability determination unit D is configured to issue instructions ci to the evaluation value calculation unit E to provide various input values ​​i to the system S, calculate evaluation values ​​es corresponding to the input values, detect input values ​​that give non-negative evaluation values ​​in the input value domain, and determine the sampling probability (sampling probability) q(x) of each input value when sampling input values ​​from the input value domain when calculating the risk value (described below). The sampling probability of each input value is determined to be higher the higher the evaluation value obtained from the evaluation value calculation unit E for each input value in the distribution ds (the sampling probability of an input value that gives a zero or negative evaluation value is expected to be zero or lower). The risk value calculation unit R is configured to sample multiple input values ​​i from the input value domain in accordance with the sampling probability q(x) for each input value determined in the distribution ds by the input value sampling probability determination unit D, issue an instruction ciq to the evaluation value calculation unit E to provide those input values ​​i to the system S, calculate an evaluation value es corresponding to the input value, and calculate a risk value r in the manner described below using the obtained evaluation value es(x) and the occurrence probability p(x) of the input value that provides it. Note that the occurrence probability p(x) of the input value is set or obtained in any manner by the input value occurrence probability determination unit P, as mentioned in the Summary of the Invention section. The calculated risk value r may be displayed in any manner, for example, on the monitor 3.

[0023] Activation of risk assessment device (a) Overview In the system risk assessment device according to this embodiment, various input values ​​are applied to the system to be assessed (either a real system or a simulation thereof) to perform tests to obtain output values. The greater the frequency and degree of deviation of the output value from the specifications, the greater the "risk value" calculated, and the greater the degree and frequency of deviation of the system's output from the specifications are assessed. Specifically, as mentioned in the "Summary of the Invention" section, this risk value is defined as a value equivalent to the integral of the product of a non-negative evaluation value in the domain of input values ​​and the probability of occurrence of the input value that gives that evaluation value. Here, the "evaluation value" is an index value that represents the degree of risk of the output value obtained from each input value. The greater the deviation of the system's output value from the specification boundary, the greater the positive value. When the output satisfies the specifications, the "evaluation value" is calculated to be a negative value. For example, as shown in FIG. 2A, in the input value domain (x1, x2), the evaluation value es for the input value is calculated so that the greater the deviation of the output value from the specification, the larger the positive value, and a distribution of the magnitude of the evaluation value es is formed in the input value domain (x1, x2). The probability of occurrence of the input value can be determined or obtained as appropriate. The risk value is the product of the non-negative part of the evaluation value es as shown in FIG. 2A and the probability of occurrence of each input value, integrated over the input value domain (x1, x2). Therefore, if the function that assigns an evaluation value to an input value is known for the system being evaluated, the risk value can be calculated by integrating the product of the evaluation value and the probability of occurrence of the input value.

[0024] However, since the function that assigns an evaluation value to the input value of the system is usually unknown, in the device of this embodiment, input values ​​at several points within the domain of the input values ​​are sampled, and the risk value is estimated and calculated using the evaluation values ​​obtained from the sampled input values. In this regard, as shown in Figure 2(B) as an example, when the evaluation value of point M in the domain of the input values ​​(x1, x2) is high, if sampling points s are selected evenly throughout the entire domain of the input values ​​(x1, x2) and evaluation values ​​are calculated at those sampling points, the evaluation values ​​of most points s other than those near point M will not be used in calculating the risk value and will be wasted. Therefore, in this embodiment, instead of sampling input values ​​evenly within the domain of input values, as shown in Fig. 2(C), the input values ​​are sampled so that the greater the contribution to the risk value, i.e., the greater the magnitude of the non-negative evaluation value (near point M with a high evaluation value), the more points s are sampled within the domain of input values, and the evaluation value obtained from the sampled input values ​​is used to calculate the risk value (although not shown, sampled points may also be selected from around points with moderately high evaluation values. The number of samples is smaller around points with low evaluation values). For this reason, in the device of this embodiment, the input value sampling probability determination unit D determines the sampling probability of each input value in sampling input values ​​from the domain of input values ​​so that the greater the contribution of each input value to the risk value, i.e., the higher the evaluation value obtained from each input value, the higher the sampling probability. As already mentioned, this configuration makes it possible to calculate the evaluation value by selectively sampling input values ​​that have a high contribution to the risk value, thereby significantly reducing the input / output processing load on the system required to calculate the evaluation value, and is expected to reduce the time, cost, or effort required to evaluate risk while also improving the accuracy of the risk value estimated by sampling.

[0025] (b) Specifications for the system output value The specifications for the system's output, i.e., the conditions that the system's output must satisfy, are typically expressed as a range of valid outputs or any condition that the range must satisfy. In this regard, since the system's output typically changes dynamically, the specifications may be set using signal temporal logic. In this case, the boundaries that the output must satisfy in the specifications may change over time.

[0026] (c) Calculation of evaluation value The evaluation value may be calculated in any manner so that the greater the deviation of the system output value from the specification boundary, the greater the positive value it takes. In this regard, typically, the evaluation value es may be, for example, the inverse of the sign of the robustness value ρ of the output value in the system: es=-ρ. Here, the robustness value ρ may be generally defined as a value that becomes positive as the output becomes less likely to deviate from the specification boundary. For example, if the specification for the output value v(t) that changes over time is 0≦v(t) <vo In this case, the robust value ρ may be defined as the smaller of the difference between the output value v and the boundary value closest to it (vo-v(t)) and (v(t)-0). When the specifications are given as a combination of conditions φ1, φ2, ..., the robust value at time t is determined as follows using the robust values ​​ρ(φ1,t), ρ(φ2,t) ... of the conditions φ1, φ2, ... When the specification is φ1∧φ2: min{ρ(φ1,t),ρ(φ2,t)} If the specification is that the condition φ1 always holds in time interval I: inf t′∈t+I ρ(φ1,t') (infρ(φ1,t') is the lower bound of ρ(φ1)) If the specification is that the condition φ1 holds at least once in time interval I:supρ t′∈t+I (φ1,t') (supρ(φ1,t') is the upper bound of ρ(φ1)) If the specification is that condition φ1 is true in time interval I, and condition φ2 is true until condition φ1 is true, then:sup min{ρ(φ1),inf t′∈t+I ρ(φ2,t')}

[0027] (d) Determining the sampling probability of the input values As described above, in this embodiment, when calculating a risk value, the number of points at which input values ​​are sampled within the domain of input values ​​is determined to be greater in regions with higher evaluation values. To this end, the input value sampling probability determination unit D may be configured in any manner to determine a distribution of sampling probabilities (probabilities of sampling for calculating a risk value) that increase in accordance with the magnitude of the evaluation value of the input value within the domain of input values.

[0028] One specific example of determining the sampling probability of the input values ​​is a method using a multimodal optimization algorithm, as described below. More specifically, first, an evaluation value es is calculated for each input value of points appropriately (usually randomly) selected within the domain of the input values ​​(FIG. 3(A)). Here, the top several points with high evaluation values ​​are selected, and a selection probability distribution is determined so that the frequency qs of the next selection follows a Gaussian distribution, centered on these selected points (FIG. 3(B)). Next, an evaluation value es is calculated for each input value of a point S selected according to the selection probability (FIG. 3(C)). Here, the top several points with high evaluation values ​​are again selected, and a selection probability distribution is determined so that the frequency qs of the next selection follows a Gaussian distribution, centered on these selected points (FIG. 3(D)). Then, an evaluation value es is calculated for each input value of the selected points according to the selection probability. Selecting points according to the selection probability, calculating evaluation values ​​for the input values ​​of the selected points, selecting the top few calculated evaluation values, determining a selection probability distribution centered on the selected points so that the frequency of subsequent selection follows a Gaussian distribution, and selecting points according to the selection probability. Repeating this process results in multiple point distributions with Gaussian selection frequencies centered on points with high evaluation values ​​within the domain of input values. Each selection probability distribution is then multiplied by a weight proportional to its evaluation value, resulting in multiple distributions with higher selection frequencies for higher evaluation values. Adding these multiple distributions together produces a single Gaussian mixture distribution representing the overall distribution of selection frequencies. Distributions with a non-negative evaluation value that is less than a predetermined percentage may be excluded from the combined distribution. Then, normalizing the combined Gaussian mixture distribution so that its integral is 1 results in a distribution ds of sampling probability q(x) with higher selection frequencies for higher evaluation values ​​(Figure 3(E)). Here, the shape of the distribution of the sampling probability is expected to match the shape of the distribution of the non-negative part of the evaluation value.

[0029] (e) Calculation of risk value As described above, the risk value is calculated in the risk value calculation unit R by sampling multiple input values ​​x from the domain of input values ​​in accordance with the sampling probability q(x) for each input value determined by the input value sampling probability determination unit D, and then having the evaluation value calculation unit E calculate evaluation values ​​es(x) from those input values ​​x, using the obtained evaluation values ​​es(x) and the occurrence probability p(x) of the input values ​​that give those evaluation values. In this regard, as described in the Summary of the Invention, according to the theory of importance sampling, when the input values ​​x are sampled in the domain of input values ​​with a sampling probability q(x) in the input value domain, the estimated value re of the value r obtained by integrating the product of a non-negative evaluation value es(x) and the occurrence probability p(x) of the input value that gives that evaluation value is given by the sum of the values ​​obtained by dividing the product of the evaluation value es(x) and the occurrence probability p(x) of each of the input values ​​x that give each of those evaluation values ​​by the sampling probability q(x) of each of the multiple input values, and then dividing this sum by the number of input values ​​sampled N: re=Σ{es(x)·p(x) / q(x)} / N Thus, the above re is estimated as the risk value used for system evaluation in the device of this embodiment.

[0030] When estimating a risk value through sampling of input values ​​from a domain of input values ​​as described above, the estimation accuracy increases with the number of samples. Therefore, the process of calculating the risk value through sampling of the input values ​​described above may be configured to be repeated until a predetermined condition, which is set as appropriate, is satisfied. Specifically, the predetermined condition may be repeated an appropriate minimum number of times until the risk value satisfies a predetermined convergence condition, or until the number of samplings reaches an appropriate maximum number of times.

[0031] Configuration and operation of a modified risk assessment device In the configuration of the device of this embodiment described above, the input value sampling probability determination unit D calculates an evaluation value in the process of determining the sampling probability of the input value. Therefore, in another aspect of the device of this embodiment, the risk value calculation unit R may be configured to calculate the risk value using the evaluation value already calculated by the input value sampling probability determination unit D. In this configuration, as shown in FIG. 4, the risk value calculation unit R calculates the risk value by referring to the calculated evaluation value es together with the sampling probability q(x) from the input value sampling probability determination unit D.

[0032] In operation, the central point of the multiple Gaussian distributions forming the Gaussian mixture distribution formed by the input value sampling probability determination unit D is sampled with a probability corresponding to the magnitude of the evaluation value. Since many points are selected in the region with large evaluation values ​​to calculate the evaluation value, the above sampling corresponds to sampling any point from among the points for which evaluation values ​​have been calculated with equal probability. Similarly, the expected value obtained by dividing the product of the evaluation value es(x) at the sampled point and the occurrence probability p(x) of the input value that gives that evaluation value by the sampling probability q(x) at that point is the estimated risk value. Note that, in this case, the estimation accuracy increases with the number of samples. Therefore, the process of calculating the risk value through input value sampling may be repeated until a predetermined condition is satisfied. This configuration eliminates the need to calculate the evaluation value during the risk value calculation process, advantageously further reducing the input / output processing load of the system.

[0033] Thus, according to the device of this embodiment, when a test is performed in which various inputs are given to the system and an output is obtained to evaluate the risk of the system, the input / output processing of the system is executed by narrowing it down to input values ​​that pose a high degree of risk, so it is expected that a more accurate evaluation can be achieved with a smaller system input / output execution load.

[0034] The above description has been made in relation to the embodiments of the present invention, but it will be apparent that many modifications and changes will be readily apparent to those skilled in the art, and the present invention is not limited to the above-described exemplary embodiments, but can be applied to various devices without departing from the concept of the present invention.

Claims

1. A risk assessment device for a system, comprising: specification setting means configured to set specifications for the output of the system to be evaluated; an evaluation value calculation means configured to calculate an evaluation value representing the degree of risk based on the input values ​​to the system and the specifications of the output values; a risk value calculation means configured to sample the input values ​​and calculate a risk value using the evaluation value calculated from the sampled input values ​​by the evaluation value calculation means; an input value sampling probability determination means configured to determine a sampling probability, which is the probability that the input value is sampled, according to a predetermined condition; Including, The risk value calculation means is configured to calculate a risk value based on the evaluation value calculated corresponding to each of the input values, the occurrence probability of each of the sampled input values, the sampling probability of each of the input values, and the number of samples of the input values.

2. 2. The apparatus of claim 1, wherein the specification is described by signal-time temporal logic, and the evaluation value is an index value representing the degree of deviation of the output value of the system from the specification over time.

3. 2. The apparatus of claim 1, wherein said input value sampling probability determining means is configured to determine said sampling probability for each of said input values ​​according to a multimodal optimization algorithm.

4. 2. An apparatus according to claim 1, wherein, in the process of determining the sampling probability of each of the input values ​​in the input value sampling probability determination means, the evaluation value corresponding to the input value is calculated at more points in an area where the sampling probability of the input value is higher, and in the process of calculating the risk value in the risk value calculation means, the evaluation value calculated corresponding to each of the input values ​​among the plurality of sampled input values ​​for which the evaluation value is non-negative is an evaluation value that has already been calculated corresponding to the input value at a point sampled with equal probability from the sampling points for which the evaluation value was calculated by the input value sampling probability determination means.

5. 2. The apparatus of claim 1, wherein the risk value calculation means is configured to repeat the process of sampling the plurality of input values ​​and calculating the risk value until the calculated risk value satisfies a predetermined condition.