Counterfactual Execution Trace Analysis for Malfunction Root Cause Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In complex systems with multiple hardware and software components, identifying the cause of malfunction is challenging due to over-estimation of failure influence and unsuitability for real-time systems, particularly in schemes like the 'general trace-based framework of logical causality' which is complex and prone to over-estimation.

Innovation Solution

A method that involves obtaining execution traces, calculating unaffected trace prefixes, and generating a counterfactual model to determine necessary or sufficient causality by verifying compliance with global system properties, using finite state automaton models for specification and extension models.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If the general trace-based framework of logical causality is used to determine component causality, then a systematic approach to analyzing malfunctions is provided, but the calculation complexity increases and over-estimation of failure influence occurs

Engineering Contradiction:
Improvecausality determination accuracyVSAvoidcalculation complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the system into multiple components and analyzes their execution traces independently. By dividing the global property violation analysis into component-level trace examinations, the calculation complexity is reduced while maintaining causality determination accuracy through systematic comparison of individual component behaviors against their specifications.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts and removes faulty events from execution traces to create cleaned versions for comparison. By taking out the problematic events that cause property violations and analyzing the remaining trace structure, the method avoids over-estimation of failure influence while maintaining systematic analysis capability.

Inventive Principle:
Principle #2Taking out (Extraction)

2Measurement precision

If the general trace-based framework of logical causality is used, then a comprehensive analysis scheme is provided, but it is not suitable for real-time systems due to computational overhead

Engineering Contradiction:
Improvecausality analysis completenessVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-processing execution traces to identify and mark faulty events before the actual causality analysis. By preparing cleaned traces and component behavior profiles in advance, the method reduces the computational overhead during real-time analysis, making it suitable for real-time systems while maintaining comprehensive analysis capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies partial action by focusing analysis only on components whose execution traces exhibit non-compliance with specifications. Instead of analyzing all components equally, the method concentrates computational resources on the subset of components that actually contributed to the property violation, reducing overall analysis time while maintaining completeness for faulty components.

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If multiple components are analyzed for malfunction causes, then comprehensive coverage is achieved, but the difficulty of identifying actual cause components increases

Engineering Contradiction:
Improvecausality identification accuracyVSAvoidcause identification difficulty
Core Design Contradiction:
Measurement precisionVSDifficulty of detecting and measuring

Solution Approach 1:

The patent uses feedback by comparing each component's execution trace against its specification and using the results to determine causality. The analysis feeds back information about which components violated which properties, allowing systematic identification of actual cause components among multiple faulty components through iterative verification and elimination.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary element in the form of cleaned execution traces that serve as mediators between the raw execution data and the causality determination. By using these intermediate processed traces that have had faulty events removed, the method simplifies the detection and measurement of actual cause components by providing a clearer basis for comparison and analysis.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10437656B2Method for automatically determining causes of the malfunction of a system made up of a plurality of hardware or software components
Publication Date: 2019.10.08 INRIA INSTITUT NATIONAL DE RECHERCHE EN INFORMATIQUE ET EN AUTOMATIQUE
  • US10437656B2 patent drawing
  • US10437656B2 patent drawing
  • US10437656B2 patent drawing

AI summary

The invention relates to a method for automatically determining necessary or sufficient cause of a malfunction of a system made up of a plurality of hardware or software components. The method comprises, from the obtaining (22) of an execution trace including a sequence of events observed during the execution of the system, obtaining a tested subset of components comprising at least one component in which the execution trace has (24) at least one non-conformity with the specification of correct operation of said component and a subset of components processed in accordance with said tested subset of components; for a processed subset of components, a calculation, for each of the components of the system, of a prefix of an execution trace not affected by events that do not conform with the specification observed for the components of the processed subset of components, the determination of a counterfactual execution model of the processed subset making it possible to generate all of the possible behaviors, starting with the unaffected prefixes, in the absence of a malfunction of the components of the processed subset of components and the determination (28, 30) of the necessary or sufficient cause of the components of the subset of components tested for the malfunction of the system in accordance with the verification that said counterfactual model of the processed subset of components complies with said global property of the system.