Aircraft AI/ML Control with Deterministic Output Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional safety-critical algorithms in aerospace applications are deterministic, leading to complex verification efforts and high costs, making it challenging to deploy real-time artificial intelligence and machine learning systems on aircraft.

Innovation Solution

A real-time AI/ML system that combines a non-deterministic AI/ML module with a deterministic module, where the deterministic module checks the AI/ML output against boundary conditions, reverse-computed inputs, or command limits to ensure safety and certification compliance, allowing the use of unqualified AI/ML models.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If deterministic algorithms are used for safety-critical aerospace applications, then certification compliance is achieved, but verification complexity and costs increase significantly

Engineering Contradiction:
Improvecertification complianceVSAvoidverification complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the algorithm into two distinct modules: a non-deterministic AI/ML module for primary processing and a deterministic module for verification. This segmentation allows each module to be optimized independently, with the deterministic module handling only boundary condition checks rather than full algorithm verification, thereby reducing overall verification complexity while maintaining certification compliance.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The deterministic module acts as an intermediary between the AI/ML module and the certification requirements. It provides a verifiable layer that checks boundary conditions and ensures deterministic behavior where needed, serving as a mediator that enables certification without requiring full verification of the complex AI/ML algorithms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If non-deterministic AI/ML models are used, then algorithm flexibility and intelligence improve, but certification compliance becomes difficult

Engineering Contradiction:
Improvealgorithm flexibilityVSAvoidcertification compliance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system separates the flexible AI/ML processing from the certification-critical functions by creating distinct modules. The AI/ML module can use sophisticated non-deterministic algorithms for adaptability, while the deterministic module handles certification-compliant operations, allowing each to operate in its optimal regime without compromising the other.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The deterministic module serves as an intermediary that bridges the gap between non-deterministic AI/ML models and certification requirements. It provides a verifiable interface that ensures certification compliance while allowing the AI/ML module to maintain its flexibility and intelligence through non-deterministic processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If full verification of AI/ML algorithms is performed, then certification compliance is achieved, but development costs increase to half of total costs

Engineering Contradiction:
Improvecertification complianceVSAvoiddevelopment costs
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system extracts the verification function from the main AI/ML algorithm by implementing a separate deterministic module that handles only boundary condition checks. This extraction reduces the verification scope and associated costs while maintaining sufficient certification compliance, avoiding the need to verify the entire complex AI/ML system.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of performing full verification of the AI/ML algorithm, the system applies partial verification through the deterministic module that checks only critical boundary conditions. This partial action approach provides sufficient certification compliance without incurring the prohibitive costs of complete algorithm verification.

Inventive Principle:
Principle #16Partial or excessive action

4Reliability

If deterministic models are used throughout, then certification compliance is ensured, but system intelligence and adaptability are reduced

Engineering Contradiction:
Improvecertification complianceVSAvoidsystem intelligence
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments functionality to assign different characteristics to different modules: the AI/ML module provides intelligence and adaptability through non-deterministic processing, while the deterministic module ensures certification compliance. This segmentation allows the system to achieve both intelligence and compliance without compromising either.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP4209850A1Real-time artificial intelligence and/or machine learning (ai/ML) systems
Publication Date: 2023.07.12 HAMILTON SUNDSTRAND CORP
  • EP4209850A1 patent drawingFigure 1~2
  • EP4209850A1 patent drawingFigure 3
  • EP4209850A1 patent drawing

AI summary

A real-time artificial intelligence and/or machine learning (AI/ML) system (100) for an aircraft can include an AI/NΠ, module (101) configured to receive one or more inputs (103) and to calculate an AI/NΠ, control output (105). The AI/NΠ, module (101) can include a nondeterministic model for processing the inputs (103) and outputting the AI/ML control output (105). The system (100) can include a deterministic module (107) configured to receive one or more inputs and the AI/NΠ, control output (105) from the AI/NΠ, module (101). The deterministic module (107) can include a deterministic model for processing the inputs (103) and/or AI/ML control output (105) to calculate a deterministic condition. The deterministic module (107) can be configured to check the AI/ML control output (105) against the deterministic condition to determine whether to output the AI/ML, control output (105).