Risk analysis device, risk analysis method, and program
The risk analysis device automates the extraction and generation of risk scenarios using graph isomorphism, addressing the inefficiencies and biases of manual methods, thereby reducing effort and improving accuracy.
Patent Information
- Application Number
- JP2025022407
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-02-14
- Publication Date
- 2026-08-26
AI Technical Summary
Existing risk analysis methods, such as HAZOP, require significant human effort and time, are prone to human bias, and may overlook scenarios, heavily depending on the analyst's competence.
A risk analysis device and method that uses labeled directed graphs to determine subgraph isomorphism between target and scenario graphs, automating the extraction of applicable risk scenarios and generating analysis results, reducing the need for manual analysis.
Automated risk analysis reduces human effort and time required, enhances accuracy by minimizing human bias, and increases the comprehensiveness of risk scenario coverage.
Smart Images

Figure 2026136725000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to a risk analysis apparatus, a risk analysis method, and a program.
Background Art
[0002] Risk analysis may be performed for chemical plants and the like. For example, Patent Document 1 describes performing risk analysis using a method called HAZOP (Hazard And Operability Studies).
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] When performing risk analysis, it is expected that the burden on the person in charge of risk analysis can be reduced if data on risk analysis cases can be used.
[0005] An example of the object of the present disclosure is to provide a risk analysis apparatus, a risk analysis method, and a program capable of performing risk analysis using data on risk analysis cases.
Means for Solving the Problems
[0006] According to a first aspect of this disclosure, the risk analysis device includes at least a portion of a target graph, which is a labeled directed graph in which nodes represent the parts to be analyzed, the relationships between the parts to be analyzed, the relationships between the parts to be analyzed, and feature labels that include information indicating the type of part and are used for determining subgraph isomorphism; and a scenario graph, which is a labeled directed graph in which nodes represent the parts to be targeted in a risk case, the relationships between the parts to be targeted, the relationships between the parts to be targeted, the feature labels and state labels that indicate the state of the parts to be targeted, are attached to the nodes, and the device determines whether the directed graph and the feature labels are isomorphism.
[0007] According to a second aspect of this disclosure, a risk analysis method includes a computer determining whether at least a portion of a target graph, which is a labeled directed graph in which nodes represent the parts subject to risk analysis, the relationships between the parts subject to analysis, and feature labels attached to the nodes, which are labels used for determining subgraph isomorphism, and a scenario graph, which is a labeled directed graph in which nodes represent the parts subject in a risk case, the relationships between the parts subject to the case, and which are feature labels and state labels attached to the nodes, are isomorphic with respect to the directed graph and feature labels.
[0008] According to a third aspect of this disclosure, the program causes a computer to determine whether at least a portion of a target graph, which is a labeled directed graph in which nodes represent the parts subject to risk analysis, the relationships between the parts subject to analysis are represented by directed edges, and feature labels, which are labels used for determining subgraph isomorphism, are isomorphic with respect to directed graphs and feature labels, and a scenario graph, which is a labeled directed graph in which nodes represent the parts subject in a risk case, the relationships between the parts subject to the case are represented by directed edges, and feature labels, which are labels, which are labels, which are labels, which are labels, which are, the state of the parts subject to the case. [Effects of the Invention]
[0009] According to the aspects of this disclosure, risk analysis can be performed using data from risk analysis case studies. [Brief explanation of the drawing]
[0010] [Figure 1] This figure shows an example of the configuration of a risk analysis device according to the embodiment. [Figure 2] This figure shows an example of a target graph according to the embodiment. [Figure 3] This figure shows an example of a scenario graph according to the embodiment. [Figure 4] This figure shows examples of choices for element values of feature labels according to the embodiment. [Figure 5] This figure shows an example of the selection of element values for a state label according to the embodiment. [Figure 6] This figure shows an example of risk analysis results generated by the result generation unit according to the embodiment. [Figure 7] This figure shows an example of a scenario graph used by the risk analysis device according to the embodiment. [Figure 8] This figure shows an example of the procedure for the risk analysis process performed by the risk analysis device according to the embodiment. [Figure 9] This figure shows an example of a computer configuration according to the embodiment. [Modes for carrying out the invention]
[0011] The embodiments will be described below with reference to the drawings.
[0012] Figure 1 is a diagram showing an example of the configuration of a risk analysis device according to an embodiment. In the configuration shown in Figure 1, the risk analysis device 100 comprises a communication unit 110, a display unit 120, an operation input unit 130, a storage unit 180, and a processing unit 190. The processing unit 190 comprises a data acquisition unit 191, a homogeneity determination unit 192, a result generation unit 193, and a result output processing unit 194.
[0013] The risk analysis device 100 performs risk analysis. Specifically, the risk analysis device 100 extracts cases from the risk analysis cases that are applicable to the target of the risk analysis, and generates and outputs risk analysis results based on the extracted cases. The risk analysis device 100 may be configured using a computer such as a workstation (WS) or a personal computer (PC).
[0014] The subject of risk analysis performed by the risk analysis device 100 is also referred to as the risk analysis target. The risk analysis target is not limited to a specific object. For example, the risk analysis target may be equipment such as a process plant. Alternatively, the risk analysis target may be a device such as a generator. The process plant referred to here may be equipment that produces products from raw materials. For example, the risk analysis device 100 may perform risk analysis on a chemical plant, an oil refinery, a power plant, or an environmental treatment plant. The examples used by the risk analysis device 100 may be, but are not limited to, examples from past risk analyses. For example, the risk analysis device 100 may use examples of accidents that have occurred in the past.
[0015] A case of risk analysis is also referred to as a risk scenario. The object of risk analysis in a risk analysis case is also referred to as the risk scenario object. Among the risk scenarios used by the risk analysis device 100, it is preferable that there are as many cases of risk analysis for the risk scenario object of the same type as the object of risk analysis (the object for which the risk analysis device 100 performs risk analysis). The whole set of risk scenarios (the set of risk scenarios) used by the risk analysis device 100 is also referred to as a risk scenario group.
[0016] Hereinafter, the case where the risk analysis device 100 uses a risk scenario expressed using parameters and guidewords in HAZOP will be described as an example. In the risk analysis in HAZOP, the object of risk analysis is divided into several parts, and for each part, a deviation from the steady state is assumed, and the cause of the deviation, the influence of the deviation, and the result caused by the deviation are examined. The divided part is called a study node.
[0017] When assuming a deviation, in HAZOP, "parameters" and "guidewords" are defined, and a deviation indicated by a possible combination of parameters and guidewords is assumed. As guidewords, for example, seven terms of No (none), More (increase), Less (decrease), Reverse (reverse), As Well As (excess), A part of (insufficient), and Other Than (other) are defined. Parameters are defined for each system such as a process system, an electrical system, or a mechanical system. For example, when the study node is included in the process system, terms such as flow rate, pressure, temperature, liquid level, and composition are defined as parameters. For example, when the study node is a pipe, the combination of the parameter "flow rate" and the guideword "decrease" indicates a deviation that the flow rate of the fluid flowing through the pipe is decreased from the steady state.
[0018] According to HAZOP, it is expected that potential risks can be comprehensively extracted by systematically anticipating possible abnormal conditions (deviations from the steady state). Then, it becomes possible to evaluate the extracted risks (risk assessment) and implement countermeasures against those risks (risk management).
[0019] On the other hand, HAZOP relies on manual work, requiring significant human effort and time, such as dozens of members working on a project for six months. Furthermore, drawbacks include the possibility of scenarios being overlooked due to bias when working manually, and the fact that the results heavily depend on the competence of the implementer (the person responsible for risk analysis). In response to this, the risk analysis device 100 extracts risk scenarios applicable to the risk analysis target, generates and outputs risk analysis results based on the extracted risk scenarios, allowing members performing HAZOP to refer to the risk analysis results output by the risk analysis device 100. According to the risk analysis device 100, in this respect, it is expected that the human effort and time required to perform HAZOP can be reduced.
[0020] For example, the risk analysis device 100 can extract and refer to typical risk scenarios, which is expected to reduce computation time. Furthermore, the implementer can focus on extracting risk scenarios not found in past cases or databases.
[0021] Furthermore, the risk analysis results output by the risk analysis device 100 do not require manual analysis. According to the risk analysis device 100, this also reduces the human effort and time required to perform HAZOP. Moreover, as the accumulation of risk scenarios (examples of risk analysis) progresses, the number of abnormal states (deviations from steady state) for which the risk analysis device 100 can output risk analysis results will increase, and it is expected that the human effort and time required to perform HAZOP will be further reduced.
[0022] However, the use of the risk analysis device 100 is not limited to HAZOP. The risk scenarios used by the risk analysis device 100 are not limited to those expressed using parameters and guide words in HAZOP.
[0023] The risk analysis device 100 acquires a graph showing the risk analysis target (graph representation of the risk analysis target) and a graph showing the risk scenario (graph representation of risk analysis examples). The risk analysis device 100 then extracts risk scenarios applicable to the risk analysis target by determining whether the graph showing the risk scenario (the part that will be treated as the subject of judgment) is included in the graph showing the risk analysis target.
[0024] As a result, the risk analysis device 100 can automatically extract risk scenarios applicable to the risk analysis target using a subgraph isomorphism determination algorithm. The extraction of risk scenarios and generation of risk analysis results by the risk analysis device 100 can be considered as case-based risk analysis. A graph showing the risk analysis target is also called a target graph. A graph showing risk scenarios is also called a scenario graph.
[0025] The communication unit 110 communicates with other devices. For example, the communication unit 110 may receive the target graph from another device. Alternatively, the communication unit 110 may transmit the risk analysis results generated by the risk analysis device 100 to another device.
[0026] The display unit 120 includes a display screen such as a liquid crystal panel or an LED (Light Emitting Diode) panel, and displays various images. For example, the display unit 120 may display various information related to risk analysis, such as a target graph, risk scenarios extracted by the risk analysis device 100, and risk analysis results.
[0027] The operation input unit 130 includes, for example, input devices such as a keyboard and a mouse, and accepts user operations. For example, the operation input unit 130 may accept user operations that give instructions regarding processing performed by the risk analysis device 100, such as user operations that specify the location for acquiring the target graph.
[0028] The memory unit 180 stores various types of data. For example, the memory unit 180 may store the target graph and the scenario graph. The memory unit 180 is configured using the memory devices provided by the risk analysis device 100.
[0029] The processing unit 190 controls various parts of the risk analysis device 100 to perform various processes. The functions of the processing unit 190 are performed, for example, by the CPU (Central Processing Unit) of the risk analysis device 100 reading a program from the storage unit 180 and executing it.
[0030] The data acquisition unit 191 acquires data for the risk analysis device 100 to perform risk analysis. In particular, the data acquisition unit 191 acquires the target graph and the scenario graph.
[0031] For example, if the risk analysis target is a chemical plant, a person may generate the target graph based on the P&ID (Piping & Instrumentation Diagram) of the risk analysis target. The data acquisition unit 191 may then acquire the generated target graph from a device that stores the graph via the communication unit 110. Alternatively, the data acquisition unit 191 may be configured to automatically or semi-automatically generate the target graph based on the P&ID of the risk analysis target.
[0032] Furthermore, if the risk scenario is a past HAZOP case for a chemical plant, a person may generate a scenario graph based on the P&ID of the chemical plant targeted by the HAZOP and a worksheet showing the results of the HAZOP. The data acquisition unit 191 may then acquire the generated scenario graph from a device storing the generated scenario graph via the communication unit 110. Alternatively, the data acquisition unit 191 may be configured to automatically or semi-automatically generate a target graph based on the P&ID of the chemical plant targeted by HAZOP and a worksheet showing the results of HAZOP.
[0033] The data acquisition unit 191 acquires the target graph and scenario graph, which are represented as labeled directed graphs. A labeled directed graph is also called an attributed directed graph. The labels attached to the nodes are also called the attributes of those nodes.
[0034] Figure 2 shows an example of the target graph. In the example shown in Figure 2, the target graph has four nodes, from n11 to n14, directed edges connecting the nodes, and labels assigned to each node. However, the number of nodes and edges in the target graph is not limited to a specific number.
[0035] Figure 3 shows an example of a scenario graph. In the example shown in Figure 3, the scenario graph has three nodes, n21 to n23, directed edges connecting the nodes, and labels assigned to each node. However, the number of nodes and edges in a scenario graph is not limited to a specific number.
[0036] Each node in the target graph represents a study node, which is a segment of the risk analysis target. Each node in the scenario graph represents a study node, which is a segment of the risk scenario target (the target of risk analysis in the risk scenario). The study node targeted for risk analysis is also referred to as the analysis portion. The study node targeted for risk scenarios is also referred to as the case study portion.
[0037] The target graph may include nodes that represent the operating environment of the risk analysis target, such as nodes representing the atmosphere. This allows the graph to represent the exchange of substances, energy, etc., between the risk analysis target and its surroundings (operating environment), such as the intake of air by the risk analysis target and the release of exhaust gases from the risk analysis target into the atmosphere. If the nodes of the target graph are limited to only those representing the part of the risk analysis target, the nodes representing the operating environment of the risk analysis target may be considered as interfaces between the risk analysis target and its surroundings, such as vents. The scenario graph may also include nodes that indicate the operating environment for the risk scenario.
[0038] The granularity at which the risk analysis target is divided when generating the target graph is not limited to a specific level. For example, one study node may represent one piece of equipment, or a component of an equipment. Alternatively, one study node may represent a combination of multiple pieces of equipment. Furthermore, as mentioned above, piping may also be treated as study nodes, and piping may also be represented as nodes. For example, sections of a piping path where the same cause results in the same effect may be shown as a single node.
[0039] Here, it is also possible to represent piping with edges. In this case, labels could be attached to the edges to represent the state of the piping, such as the state of the fluid flowing through it. However, when labels are attached to edges, there is a possibility that edges that need to indicate a state, such as piping, and edges that do not need to indicate a state, such as the junction of two study nodes, will be mixed together. In that case, in order to generate risk analysis results, it will be necessary to determine whether or not a state is indicated on the edge, and in this respect, the burden of generating risk analysis results will increase. In contrast, the risk analysis device 100 can achieve uniformity by not labeling the edges, thus reducing the load on the risk analysis device 100.
[0040] It is preferable that the scenario graph used by the risk analysis device 100 includes as many scenario graphs as possible that are divided using the same division rules as those used for dividing the risk analysis target. If the division rules for the target graph and the scenario graph differ, the scenario graph is considered to be inapplicable to the target graph. In this context, the applicability of a scenario graph to a target graph can be understood as meaning that the risk scenarios represented by that scenario graph are applicable to the subject of risk analysis.
[0041] In both the target graph and the scenario graph, each directed edge represents a physical connection between study nodes. For example, the direction of each edge may indicate the direction of material movement (the direction in which the material is transported) assumed during the design of the risk analysis target or risk scenario target. Directed edges can be considered to represent causal relationships (causal relationships of state changes between study nodes).
[0042] The labels assigned to each node include feature labels, which are used for determining subgraph isomorphism, and state labels, which are used to indicate the results of the risk analysis. Feature labels contain information indicating the type of study node (the part targeted for risk analysis) to which the node to which the feature label is attached represents. Feature labels may also be represented as integer vectors, with identification numbers indicating the type of study node, etc. The number of elements in a feature label is not limited to a specific number. For example, the number of elements in an integer vector representing a feature label is not limited to a specific number.
[0043] A state label contains information indicating the state of the study node represented by the node to which it is assigned. The state label may also be represented as an integer vector, where the state of the study node is indicated by an identification number. The number of elements in a state label is not limited to a specific number. For example, the number of elements in an integer vector representing a state label is not limited to a specific number.
[0044] Representing feature labels and state labels as integer vectors allows for a relatively small amount of memory capacity to be required to store the labels. Furthermore, representing feature labels as integer vectors also reduces the computational load required to determine whether feature labels are identical or not.
[0045] The information shown in the feature labels is also called the node's feature, or simply the feature. State labels are also called node labels. The information shown in the feature labels can be considered as examples of explanatory variables, and the information shown in the state labels can be considered as examples of the dependent variable. In other words, the risk analysis device 100 can be seen as using the information shown in the feature labels to calculate the information to be shown in the state labels.
[0046] The data acquisition unit 191 acquires one or more scenario graphs. The entire set of scenario graphs acquired by the data acquisition unit 191 is also called a scenario graph group. A set of scenario graphs can be understood as a representation of a set of risk scenarios in the form of a collection of graphs. In other words, a set of scenario graphs can be understood as a collection of scenario graphs that represent each risk scenario included in the set of risk scenarios.
[0047] The isomorphism determination unit 192 determines whether the target graph and the scenario graph are subgraph isomorphic. Specifically, the isomorphism determination unit 192 determines whether a subgraph of the target graph and one scenario graph are isomorphic with respect to directed graphs and feature labels. Here, the subgraph of the target graph may be the target graph itself (the entire target graph). In other words, the isomorphism determination unit 192 determines whether at least a part of the target graph and the scenario graph are isomorphic. The isomorphism determination unit 192 extracts scenario graphs from the group of scenario graphs that it determines to be identical in type to a subgraph of the target graph, as scenario graphs applicable to the target graph.
[0048] In this context, the fact that a subgraph of the target graph and a single scenario graph are isomorphic with respect to directed graphs and feature labels means that Condition 1. Among the subgraphs of the target graph, there is a subgraph that is isomorphic to the scenario graph as a directed graph, and, Condition 2. In any pair of nodes that are isomorphically matched in Condition 1 above, the feature labels of the nodes in the target graph and the feature labels of the nodes in the scenario graph are the same. That is the case.
[0049] For example, in determining partial isomorphism between the target graph shown in Figure 2 and the scenario graph shown in Figure 3, the subgraphs of the target graph consisting of nodes n12, n13, and n14, the edges from node n12 to n13, and the edges from node n13 to n14, and the scenario graph are isomorphic as directed graphs (condition 1 above). Furthermore, the feature labels are the same for all pairs: node n12 and node n21, node n13 and node n22, and node n14 and node n23 (condition 2 above). Therefore, the isomorphism determination unit 192 extracts the scenario graph shown in Figure 3 as a scenario graph applicable to the subgraphs of the target graph, specifically nodes n12, n13, and n14, and the edges from node n12 to n13 and from node n13 to n14.
[0050] The isomorphism determination unit 192 may perform the determination of condition 1 above using an existing subgraph isomorphism determination algorithm (for example, a known subgraph isomorphism determination algorithm). In the example in Figure 2, the value of each element of the state label in the target graph is "-1". The value "-1" of the state label element indicates a missing value (invalid value). The isomorphism determination unit 192 treats the label element value "-1" as a wildcard and excludes it from the determination of label identity. Alternatively, the isomorphism determination unit 192 may exclude state labels from the identity determination regardless of the value of the state labels of the nodes in the target graph. In this case, for example, the nodes in the target graph do not need to have state labels.
[0051] The result generation unit 193 generates risk analysis results by referring to the target graph and the scenario graph extracted by the isomorphism determination unit 192. In particular, the result generation unit 193 generates risk analysis result data that shows the type of part indicated by the feature labels of the nodes in the subgraph of the target graph (type of study node) and the state of the part indicated by the state labels of the nodes in the scenario graph (state of study node) among the subgraph of the target graph and the scenario graph which have been determined to be isomorphic.
[0052] Specifically, the result generation unit 193 generates a scenario in which, if an abnormal state (deviation from the steady state) indicated by the state label of the corresponding node in the scenario graph occurs at the study node indicated by the upstream node of the path in the target graph, an effect indicated by the state label of the corresponding node in the scenario graph occurs at the study node indicated by the downstream node of the path in the target graph.
[0053] In this context, a path in the target graph is formed when two or more nodes in the target graph are connected in series by directed edges. In this context, the scenarios in the risk analysis results refer to information that shows the events expected to occur in the subject of the risk analysis, and the events that are expected to result from those events.
[0054] Figure 4 shows examples of choice of element values for feature labels. Figure 4 shows an example where the risk analysis target is a chemical plant. In the example in Figure 4, the correspondence between the element values of the feature label and the identification number is shown in the form of a conversion table. The data showing the correspondence between the element values of the feature label and the identification number is also called feature label conversion data.
[0055] In the example shown in Figure 4, the feature label conversion data includes fields for "Number," "Process Component," and "Flammable / Ignitive Gas." However, the data used by the risk analysis device 100 as feature labels is not limited to a specific type of data (data on a specific item). For example, the data items of the feature labels may include design information for the risk analysis target, such as design pressure or design temperature. The items shown in the feature label conversion data can also be various items depending on the data items shown in the feature labels.
[0056] The columns for "Process Components" and "Flammable Gases" show the options for element values for that item. The numbers in parentheses to the left of each item name indicate the position of that item's element in the feature label. In the example in Figure 4, the feature label has two elements.
[0057] The "Number" field displays an integer used as an identification number. The element values for both "Process Components" and "Flammable / Ignitive Gases" are represented by the identification numbers shown on the same row. For example, the value "External Environment" for "Process Component" is represented by identification number "0". The value "Shut-off Valve (Manual)" for "Process Component" is represented by identification number "1".
[0058] The value for "Process Component" indicates the type of study node. The value for "flammable / ignitable gas" indicates whether the gas contained in the study node (for example, the gas flowing through the study node, or the gas stored in the study node) is flammable or ignitable.
[0059] The memory unit 180 may store the feature label conversion data illustrated in Figure 4. The result generation unit 193 may then obtain information about the study nodes included in the scenario by converting the identification numbers included in the feature labels using the feature label conversion data when generating the risk analysis results.
[0060] In the example in Figure 4, when the study node is a valve, the type of study node is indicated by the function of the valve, such as "shut-off valve (manual)", "shut-off valve (automatic)", and "self-acting valve". By classifying valves according to their function in this way, it is expected that the efficiency of risk analysis will improve.
[0061] Here, let's consider a case where "risk" is calculated in risk analysis using the impact and frequency of the occurrence of a given scenario. In this case, when calculating the frequency, failure frequency data of the faulty equipment is used, but it is thought that the frequency (frequency of scenario occurrence) will differ depending on the function of the valve, such as whether the valve is automatic or manual. It is conceivable to distinguish between automatic and manual valves when calculating the risk, but in this case, the task of classifying the valves will be required when calculating the frequency.
[0062] In contrast, as shown in the example in Figure 4, by pre-classifying valves by function using feature labels and feature label conversion data, it becomes unnecessary to perform valve classification work when conducting risk analysis. In this respect, the efficiency of risk analysis can be improved.
[0063] Furthermore, HAZOP involves referencing information on whether a valve is malfunctioning or not, making it possible to perform HAZOP even if the valves are not classified. However, engineers performing HAZOP possess knowledge of the operation and risk of malfunctions associated with each type of valve, and may feel uncomfortable handling various types of valves without distinction. In contrast, as shown in the example in Figure 4, the valves are classified using feature labels and feature label conversion data, which is expected to allow engineers to perform HAZOP without feeling any discomfort.
[0064] Furthermore, classifying valves by function is expected to improve work efficiency in post-process risk analysis. Post-process, in this context, refers to the work performed by the risk analysis implementer to interpret the risk analysis results from the risk analysis device 100 and to confirm whether the accident scenarios are actually plausible. In post-process, for example, the validity of the risk analysis results is determined, and safety measures are planned based on the risk analysis results. Generally, risk is calculated using the impact and frequency of the relevant scenario, and failure frequency data for faulty equipment is used when calculating the frequency of the relevant scenario. Since the failure frequency differs depending on whether the valve is automatic or manual, etc., it is expected that distinguishing and documenting the valves will reduce the burden on implementers in the post-processing stage.
[0065] Classifying valves by function is one example of a method for classifying process components. The method of classifying process components handled by the risk analysis device 100 is not limited to any particular method.
[0066] Figure 5 shows an example of the choice of element values for state labels. Figure 5 shows an example where the risk analysis target is a chemical plant. In the example in Figure 5, the correspondence between the selected element values of the state label and the identification number is shown in the form of a conversion table. The data showing the correspondence between the selected element values of the state label and the identification number is also called state label conversion data.
[0067] In the example shown in Figure 5, the status label conversion data includes fields for "Number," "Guide Word," "Causative Device," "Failure Mode," "Device Affected," and "Impact Mode." However, the data used by the risk analysis device 100 as state labels is not limited to a specific type of data (data of a specific item). The items shown in the state label conversion data can also be various items depending on the items of the data shown in the state label.
[0068] The columns for "Guide Word," "Causative Device," "Failure Mode," "Device Affected," and "Impact Mode" show the options for element values for that item. The number in parentheses to the left of each item name indicates the position of that element in the feature label. In the example in Figure 5, the state label has five elements.
[0069] The "Number" field displays an integer used as an identification number. The element values for each of the following items—"Guide Word," "Causative Device," "Failure Mode," "Device Affected by the Effect," and "Effect Mode"—are all represented by the identification number shown on the same row. For example, a "guide word" value of "none" is represented by identification number "0". A "guide word" value of "No-Flow" is represented by identification number "1".
[0070] The "guide word" value indicates the combination of parameters and guide words in HAZOP. In other words, the "guide word" value indicates what is assumed to be the deviation from the steady state. The value for "Causative Device" indicates whether or not the study node is a causative device. A study node being a causative device means that it can be the starting point for a deviation from the steady state in the risk analysis target. The "failure mode" value indicates the cause of the deviation from the steady state. The value for "Equipment where impact manifests" indicates whether or not a study node is an equipment where impact manifests. A study node being an equipment where impact manifests means that the deviation from the steady state at that study node can manifest as an anomaly in the risk analysis target (for example, an accident in the risk analysis target). The "mode of impact" indicates the type of anomaly that may manifest as an anomaly in the risk analysis target.
[0071] The memory unit 180 may store state label conversion data as illustrated in Figure 5. The result generation unit 193 may then convert the identification number shown in the state label using the state label conversion data when generating the risk analysis results, thereby obtaining information such as the assumed state of the study node included in the scenario.
[0072] Figure 6 shows an example of the risk analysis results generated by the result generation unit 193. The information showing the risk analysis results is also referred to as a worksheet. In the example in Figure 6, the worksheet is presented as tabular data containing the following items: "Reference Scenario," "Guide Word," "Causative Device," "Failure Mode," "Scenario," "Devices Affected," and "Impact Mode."
[0073] In the example in Figure 6, each row in the table shows the impact that occurs in the study node corresponding to the affected device when a deviation from the steady state occurs in the study node corresponding to the causative device within the risk analysis target. The information showing the impact of a deviation from the steady state in the causative device on the affected device, as shown in each row of the table in the example in Figure 6, is also referred to as an individual scenario in the risk analysis results, or simply an individual scenario.
[0074] Figure 7 shows an example of a scenario graph used by the risk analysis device 100. The scenario graph in Figure 7 is a labeled directed graph in which N nodes, from node n30-1 to 30-N, are connected in series by directed edges to form a single path. Here, N is an integer N≧2, representing the number of nodes included in the scenario graph. The scenario graph in Figure 3 corresponds to the example of the scenario graph in Figure 7 where N=3.
[0075] In the example in Figure 7, node n30-1 indicates the study node corresponding to the faulty device. The node indicating the faulty device is also referred to as the upstream node. Node n30-N indicates a study node corresponding to the equipment where the impact is evident. A node indicating a study node corresponding to the equipment where the impact is evident is also referred to as the downstream node. When generating individual scenarios, the result generation unit 193 reads information about the deviation from the steady state assumed for the study node corresponding to the causative device from the state label of the upstream node. The result generation unit 193 also reads information about the impact that is likely to occur for the study node corresponding to the device where the impact is manifested, from the state label of the downstream node.
[0076] In the following description of the process by which the result generation unit 193 generates individual scenarios, it is assumed that the subgraph of the target graph and the scenario graph are determined to be of the same type. Furthermore, the result generation unit 193 writes each of the generated scenarios to a worksheet (an empty row).
[0077] Among the nodes in the subgraph of the target graph, the node that corresponds to the upstream node of the scenario graph in the subgraph isomorphism is also referred to as the upstream node of the subgraph of the target graph. The upstream node of the subgraph of the target graph is thought to represent the study node corresponding to the causative equipment in the risk analysis.
[0078] Among the nodes in the subgraph of the target graph, the node that corresponds to the furthest downstream node of the scenario graph in the subgraph isomorphism is also referred to as the furthest downstream node of the subgraph of the target graph. The furthest downstream node of the subgraph of the target graph is thought to represent a study node that corresponds to the instrument where the impact of the risk analysis is manifested.
[0079] In the worksheet in Figure 6, the "Reference Scenario" column shows the name (data file name) of the risk scenario from which each individual scenario was generated. When the result generation unit 193 writes each individual scenario to the worksheet, it writes the data file name of the referenced risk scenario as the value of "Reference Scenario".
[0080] The "Guide Word" column shows the content assumed to be a deviation from the steady state. When the result generation unit 193 writes individual scenarios to the worksheet, it reads the identification number of the "Guide Word" in the state label of the upstream node of the scenario graph. The result generation unit 193 then converts the read identification number into a string (the name of the guide word option) by referring to the state label conversion data. The result generation unit 193 then writes the obtained string as the value of the "Guide Word" in each scenario of the worksheet.
[0081] The "Causative Device" column shows the name of the causative study node in each scenario. For example, each node in the target graph is labeled with the name of the study node it represents, in addition to the feature label and state label. When the result generation unit 193 writes each scenario to the worksheet, it writes the name of the study node labeled on the uppermost node of the subgraph of the target graph as the value of "Causative Device".
[0082] The "Failure Mode" column indicates the cause of the deviation from the steady state, as shown in the "Guide Word" column. When the result generation unit 193 writes each scenario to the worksheet, it reads the identification number of the "Failure Mode" in the state label of the uppermost node of the subgraph of the target graph. The result generation unit 193 then converts the read identification number into a string (the name of the failure mode option) by referring to the state label conversion data. The result generation unit 193 then writes the obtained string as the "Failure Mode" value for each scenario in the worksheet.
[0083] The column for "Equipment where the impact manifests" shows the name of the study node on the side where the impact occurs in each scenario. For example, each node in the target graph is labeled with the name of the study node it represents, in addition to the feature label and state label. When the result generation unit 193 writes each scenario to the worksheet, it writes the name of the study node labeled on the downstream node of the subgraph of the target graph as the value of "Equipment where the impact manifests".
[0084] The "Influence Mode" column indicates the types of anomalies that may manifest in each scenario. When the result generation unit 193 writes each scenario to the worksheet, it reads the identification number of the "Influence Mode" in the state label of the downstream node of the scenario graph. The result generation unit 193 then converts the read identification number into a string (the name of the influence mode selection) by referring to the state label conversion data. The result generation unit 193 then writes the obtained string as the "Influence Mode" value for each scenario in the worksheet.
[0085] In the "Scenario" column, each scenario is described in text. The result generation unit 193 takes the values for "Cause Equipment," "Failure Mode," "Effective Equipment," and "Impact Mode" into a template that reads, "Due to the (Failure Mode) of (Cause Equipment), (Impact Mode) occurs in (Effective Equipment)," and generates text that represents each scenario. The result generation unit 193 then writes the generated text as the value for "Scenario."
[0086] The result output processing unit 194 outputs the worksheet generated by the result generation unit 193. The method by which the result output processing unit 194 outputs the worksheet is not limited to a specific method. For example, the result output processing unit 194 may transmit the worksheet to another device via the communication unit 110. Alternatively, in addition to transmitting the worksheet, the result output processing unit 194 may display the worksheet on the display unit 120. Alternatively, the result output processing unit 194 may output the worksheet to the storage unit 180 in addition to outputting the worksheet to the outside of the risk analysis device 100 (sending or displaying the worksheet).
[0087] Figure 8 shows an example of the procedure for the risk analysis process performed by the risk analysis device 100. In the process shown in Figure 8, the data acquisition unit 191 acquires the target graph and the scenario graph group (step S101).
[0088] Next, the processing unit 190 starts a loop L11 that processes each scenario included in the group of scenario graphs obtained in step S101 (step S102). The scenario graph that is the target of processing in loop L11 is also called the target scenario graph. In the processing of loop L11, the isomorphism determination unit 192 performs a subgraph isomorphism determination between the target graph and the processing target scenario graph, and extracts all subgraphs of the target graph that are isomorphic with respect to the processing target scenario graph, directed graph and feature labels (step S103).
[0089] Next, the processing unit 190 starts a loop L12 that processes each subgraph obtained in step S103 (step S104). The subgraph being processed in loop L12 is also called the processed subgraph.
[0090] In the processing of loop L12, the result generation unit 193 generates individual scenarios based on the processing target subgraph and the processing target scenario graph and writes them to the worksheet (step S105). The result generation unit 193 generates individual scenarios in which, if a deviation from the steady state occurs, as shown at the upstream node of the processing target scenario graph, an effect occurs at the study node targeted for risk analysis, as shown at the upstream node of the processing target scenario graph, as shown at the downstream node of the processing target subgraph, as well as at the study node targeted for risk analysis, as shown at the downstream node of the processing target scenario graph.
[0091] Next, the processing unit 190 performs termination processing for loop L12 (step S106). Specifically, the processing unit 190 determines whether or not loop L12 processing has been performed on all subgraphs obtained in step S103. If it determines that there are still subgraphs that have not been processed by loop L12, the processing unit 190 continues to process loop L12 on the unprocessed subgraphs. On the other hand, if it determines that loop L12 processing has been performed on all subgraphs obtained in step S103, the processing unit 190 terminates loop L12.
[0092] If loop L12 is completed, the processing unit 190 performs termination processing for loop L11 (step S107). Specifically, the processing unit 190 determines whether or not loop L11 processing has been performed for all scenarios included in the scenario graph group obtained in step S101. If it determines that there are still scenarios for which loop L11 processing has not been performed, the processing unit 190 continues to process loop L11 for the unprocessed scenarios. On the other hand, if it determines that loop L11 processing has been performed for all scenarios included in the scenario graph group obtained in step S101, the processing unit 190 terminates loop L11.
[0093] When the processing unit 190 completes loop L11, the result output processing unit 194 outputs the worksheet generated by the result generation unit 193 (step S108). After step S108, the risk analysis device 100 completes the process shown in Figure 8.
[0094] Next, we will describe the experiment involving the risk analysis device 100. A risk analysis device 100 was tested for operation at a hydrogen refueling station. For the operational verification, a dataset was prepared in which HAZOP worksheets for 29 hydrogen compressor / accumulator units were plotted as scenario graphs. The guided worksheets were "no flow rate" and "increased utilization." By applying the risk analysis device 100 to the prepared dataset, we were able to identify 254 scenarios (individual scenarios), confirming the effectiveness of the risk analysis device 100.
[0095] As described above, the isomorphism determination unit 192 determines whether at least a part of the target graph and the scenario graph are isomorphic with respect to directed graphs and feature labels. The target graph is a labeled directed graph in which the analysis target portion, which is the part subject to risk analysis, is represented by nodes, the relationships between the analysis target portions are represented by directed edges, and feature labels are attached to the nodes. Feature labels are labels that include information indicating the type of portion and are used for subgraph isomorphism determination. The scenario graph is a labeled directed graph in which the case target portion, which is the part subject to risk in a case, is represented by nodes, the relationships between the case target portions are represented by directed edges, and feature labels and state labels are attached to the nodes. State labels are labels that indicate the state of the case target portion.
[0096] The risk analysis device 100 allows risk analysis to be performed using data from risk analysis cases. In particular, the risk analysis device 100 can automatically extract cases (risk scenarios) applicable to the target of risk analysis (risk analysis target) using subgraph isomorphism determination. In this respect, the risk analysis device 100 is expected to reduce the human effort and time required to perform risk analysis.
[0097] Furthermore, the risk analysis device 100 can use existing subgraph isomorphism determination algorithms to extract cases applicable to the risk analysis target. In this respect, the risk analysis device 100 is expected to reduce the human effort and time required to design the device.
[0098] Furthermore, the risk analysis device 100 can compensate for individual differences in case extraction, such as differences in experience, by automatically extracting cases. It is expected that even people with little experience in case extraction can use the risk analysis device 100 to extract cases with relatively high accuracy. Furthermore, the risk analysis device 100 is expected to reduce human error in risk analysis by automatically extracting cases.
[0099] Furthermore, according to the risk analysis device 100, the process of extracting cases is not a black box compared to when a machine learning model is used to extract cases. In this respect, the risk analysis device 100 offers high explainability of the case extraction results.
[0100] Furthermore, in both the target graph and the scenario graph, piping is represented by nodes. Here, it is also conceivable to represent the piping with edges. In this case, labels could be attached to the edges to represent the state of the piping, such as the state of the fluid flowing through it. However, when labels are attached to the edges, there is a possibility that edges that need to indicate a state, such as piping, and edges that do not need to indicate a state, such as the interface between two study nodes, will be mixed together. In that case, the result generation unit 193 will need to determine whether or not a state is indicated on the edge, and in this respect, the load on the result generation unit 193 will increase. In contrast, the risk analysis device 100 can achieve uniformity by not labeling the edges, thereby relatively reducing the load on the result generation unit 193.
[0101] Furthermore, the risk analysis device 100 can extract applicable cases (risk scenarios) to the subject of risk analysis (risk analysis target) based on the similarity of fluid characteristics such as the flammability of the fluid in the piping. In this respect, the risk analysis device 100 can extract applicable cases to the subject of risk analysis with relatively high accuracy. In other words, it is expected that the risk analysis device 100 can extract scenarios that are more similar to the subject of risk analysis.
[0102] Furthermore, the result generation unit 193 generates a worksheet (risk analysis results) showing the type of part indicated by the feature label and the state of the part indicated by the state label for the nodes of the scenario graph that have been determined to be identical in type to at least a part of the target graph. The risk analysis device 100 can automatically generate risk analysis results, and in this respect, it is expected to reduce the human effort and time required to perform risk analysis.
[0103] Furthermore, the risk analysis device 100 automatically generates risk analysis results, thus compensating for individual differences in the generation of risk analysis results, such as differences in experience. It is expected that even people with little experience in generating risk analysis results can use the risk analysis device 100 to generate risk analysis results with relatively high accuracy. Furthermore, the risk analysis device 100 is expected to reduce human error in risk analysis by automatically generating risk analysis results.
[0104] Furthermore, the risk analysis device 100 allows for risk analysis using a database of scenario graphs that visualize the results of past risk analyses and the tacit knowledge of skilled engineers in graph format. In this respect, the risk analysis device 100 enables the effective utilization and transmission of knowledge related to risk analysis.
[0105] Furthermore, with the risk analysis device 100, the process of extracting cases is not a black box compared to when risk analysis results are generated using a machine learning model. In this respect, the risk analysis device 100 offers high explainability of risk analysis results.
[0106] Furthermore, a single scenario graph consists of two or more nodes connected in series by directed edges, forming a single directed path. According to the risk analysis device 100, the load on the isomorphism determination unit 192 is relatively small because the structure of the scenario graph is relatively simple. Furthermore, the risk analysis device 100 only needs to generate scenarios (individual scenarios) where there is no merging or branching of influences between study nodes, resulting in a relatively small load on the result generation unit 193. It is also expected that the scenarios generated by the result generation unit 193 will be easier for users to understand.
[0107] Furthermore, the result generation unit 193 generates data indicating that when the state indicated by the state label of the upstream node in the directed path formed by the scenario graph occurs, the effect indicated by the state label of the downstream node occurs. According to the risk analysis device 100, the result generation unit 193 only needs to refer to the nodes at both ends of the scenario graph and does not need to refer to the intermediate nodes. In this respect, the risk analysis device 100 can reduce the load on the result generation unit 193 relatively. Furthermore, according to the risk analysis device 100, the scenarios (individual scenarios) generated by the result generation unit 193 are relatively simple, and it is expected that people who refer to the scenarios generated by the result generation unit 193 will be able to easily understand the scenarios.
[0108] Figure 9 shows an example of a computer configuration according to this embodiment. In the configuration shown in Figure 9, the computer 700 comprises a CPU 710, a main memory 720, an auxiliary memory 730, an interface 740, and a non-volatile recording medium 750.
[0109] The risk analysis device 100 described above may be implemented in a computer 700. In that case, the operation of the processing unit 190 and each of its parts is stored in auxiliary storage device 730 in the form of a program. The CPU 710 reads the program from auxiliary storage device 730, loads it into main memory 720, and executes the above processing according to the program.
[0110] Furthermore, the CPU 710 reserves a memory area in the main memory 720 corresponding to the memory unit 180 according to the program. Communication between the communication unit 110 and other devices is performed by the interface 740 having a communication function and performing communication according to the control of the CPU 710. The display unit 120 performs the display by having an interface 740 that has a display device and displaying various images according to the control of the CPU 710. The acceptance of user operations by the operation input unit 130 is performed when the interface 740, which has input devices such as a keyboard and mouse, accepts user operations and outputs information indicating the accepted user operations to the CPU 710.
[0111] One or more of the above-mentioned programs may be recorded on the non-volatile recording medium 750. In this case, the interface 740 may read the program from the non-volatile recording medium 750. The CPU 710 may then either directly execute the program read by the interface 740, or temporarily save it in the main memory 720 or auxiliary memory 730 before executing it.
[0112] Alternatively, a program to implement all or part of the functions of the risk analysis device 100 may be recorded on a computer-readable recording medium, and the program recorded on this recording medium may be loaded into a computer system and executed to perform the processing of each part. The term "computer system" here includes hardware such as the OS (Operating System) and peripheral devices. Furthermore, "computer-readable recording media" refers to portable media such as flexible disks, magneto-optical disks, ROMs (Read Only Memory), CD-ROMs (Compact Disc Read Only Memory), and storage devices such as hard disks built into computer systems. The above-mentioned program may be intended to implement only a part of the functions described above, and may also be able to implement the above-mentioned functions in combination with programs already recorded in the computer system.
[0113] Although the present disclosure has been described above with reference to embodiments, the present disclosure is not limited to the embodiments described above. Various modifications to the structure and details of the present disclosure are possible, as can be understood by those skilled in the art within the scope of the present disclosure. Furthermore, the embodiments described above may be combined with other embodiments as appropriate.
[0114] Some or all of the above embodiments may also be described as follows, but are not limited to these.
[0115] (Note 1) An isomorphism determination unit determines whether a directed graph and its feature labels are isomorphic with respect to at least a portion of a target graph, which is a labeled directed graph in which the analysis target portion, which is the part of the risk analysis, is shown by nodes, the relationships between the analysis target portion, is shown by directed edges, and feature labels, which are labels used for determining subgraph isomorphism and include information indicating the type of portion, are attached to the nodes; and a scenario graph is a labeled directed graph in which the case target portion, which is the part of the risk case, is shown by nodes, the relationships between the case target portion, is shown by directed edges, and the feature labels and state labels, which are labels indicating the state of the case target portion, are attached to the nodes. A risk analysis device equipped with the following features.
[0116] (Note 2) In both the aforementioned target graph and the aforementioned scenario graph, the piping is indicated by nodes. The risk analysis device described in Appendix 1.
[0117] (Note 3) A result generation unit generates data indicating the type of portion of the node in the target graph indicated by the feature label and the state of the portion of the node in the scenario graph indicated by the state label, from at least a portion of the target graph determined to be of the same type and the scenario graph. A risk analysis device as described in Appendix 1 or Appendix 2, comprising the above.
[0118] (Note 4) One of the aforementioned scenario graphs is one in which two or more nodes are connected in series by directed edges to form a directed path. The risk analysis device described in Appendix 3.
[0119] (Note 5) The result generation unit generates data indicating that when the state indicated by the state label of the upstream node in the directed path occurs among the nodes at both ends of the scenario graph, the effect indicated by the state label of the downstream node occurs. The risk analysis device described in Appendix 4.
[0120] (Note 6) Computers At least a portion of a target graph is a labeled directed graph in which nodes represent the parts subject to risk analysis, directed edges represent the relationships between the target parts, and feature labels, which are labels used for determining subgraph isomorphism and include information indicating the type of part, are attached to the nodes. The scenario graph is a labeled directed graph in which nodes represent the parts subject to risk in a case, directed edges represent the relationships between the case parts, and feature labels, which are labels indicating the state of the case parts, are attached to the nodes. The system determines whether the directed graph and the feature labels are isomorphic. A risk analysis method that includes the following.
[0121] (Note 7) On the computer, The process involves determining whether at least a portion of a target graph, which is a labeled directed graph in which the analysis target portion (the part subject to risk analysis) is represented by nodes, the relationships between the analysis target portion are represented by directed edges, and feature labels, which are labels used for determining subgraph isomorphism and include information indicating the type of portion, are isomorphic with respect to the directed graph and feature labels, and whether a scenario graph, which is a labeled directed graph in which the case target portion (the part subject in a risk case) is represented by nodes, the relationships between the case target portion are represented by directed edges, and the feature labels and state labels, which are labels indicating the state of the case target portion, are isomorphic with respect to the directed graph and feature labels. A program that executes the command. [Explanation of Symbols]
[0122] 100 Risk Analysis Device 110 Communications Department 120 Display section 130 Operation Input Section 180 Storage section 190 Processing Unit 191 Data Acquisition Unit 192 Isomorphism Determination Department 193 Result generation section 194 Result Output Processing Unit
Claims
1. An isomorphism determination unit determines whether a directed graph and its feature labels are isomorphic with respect to at least a portion of a target graph, which is a labeled directed graph in which the analysis target portion, which is the part of the risk analysis, is shown by nodes, the relationships between the analysis target portion, is shown by directed edges, and feature labels, which are labels used for determining subgraph isomorphism and include information indicating the type of portion, are attached to the nodes; and a scenario graph is a labeled directed graph in which the case target portion, which is the part of the risk case, is shown by nodes, the relationships between the case target portion, is shown by directed edges, and the feature labels and state labels, which are labels indicating the state of the case target portion, are attached to the nodes. A risk analysis device equipped with the following features.
2. In both the aforementioned target graph and the aforementioned scenario graph, the piping is indicated by nodes. The risk analysis device according to claim 1.
3. A result generation unit generates data indicating the type of portion of the node in the target graph indicated by the feature label and the state of the portion of the node in the scenario graph indicated by the state label, from at least a portion of the target graph determined to be of the same type and the scenario graph. A risk analysis device according to claim 1 or claim 2, comprising:
4. One of the aforementioned scenario graphs is one in which two or more nodes are connected in series by directed edges to form a directed path. The risk analysis device according to claim 3.
5. The result generation unit generates data indicating that when the state indicated by the state label of the upstream node in the directed path occurs among the nodes at both ends of the scenario graph, the effect indicated by the state label of the downstream node occurs. The risk analysis device according to claim 4.
6. Computers At least a portion of a target graph is a labeled directed graph in which nodes represent the parts subject to risk analysis, directed edges represent the relationships between the target parts, and feature labels, which are labels used for determining subgraph isomorphism and include information indicating the type of part, are attached to the nodes. The scenario graph is a labeled directed graph in which nodes represent the parts subject to risk in a case, directed edges represent the relationships between the case parts, and feature labels, which are labels indicating the state of the case parts, are attached to the nodes. The system determines whether the directed graph and the feature labels are isomorphic. A risk analysis method that includes the following.
7. On the computer, The process involves determining whether at least a portion of a target graph, which is a labeled directed graph in which the analysis target portion (the part subject to risk analysis) is represented by nodes, the relationships between the analysis target portion are represented by directed edges, and feature labels, which are labels used for determining subgraph isomorphism and include information indicating the type of portion, are isomorphic with respect to the directed graph and feature labels, and whether a scenario graph, which is a labeled directed graph in which the case target portion (the part subject in a risk case) is represented by nodes, the relationships between the case target portion are represented by directed edges, and the feature labels and state labels, which are labels indicating the state of the case target portion, are isomorphic with respect to the directed graph and feature labels. A program that executes the command.
Citation Information
Patent Citations
Safety management method for plant facility
JP2009122737A