Event Tree Reliability Analysis of Safety-Critical Systems Using Theorem Proving
Bibliographic record
Abstract
Event tree (ET) analysis is widely used as a forward deductive safety analysis technique for decision-making at the design stage of safety-critical systems, such as smart power grids. An ET is a schematic diagram representing all possible complete/partial reliability and failure consequence events in a system so that one of these events can occur. In this article, we propose to use formal techniques based on theorem proving for the formal modeling and step-analysis of ET diagrams. To this end, we develop a formalization in higher order logic enabling the mathematical modeling of the graphical diagrams of ETs and the formal analysis of system-level failure/reliability. We propose new mathematical ET probabilistic formulations, based on a genericlist-datatype, which are capable of analyzing large scale ETs that consist of$\mathcal {N}$multistatesystem components and enable the formal ET probabilistic analysis for any given probabilistic distribution. We demonstrate the practical effectiveness of the proposed ET formalization by performing the formal reliability analysis of a standard IEEE 118-bus electrical power grid system and also formally determine its reliability indices, such as system/customer average interruption frequency and duration (SAIFI, SAIDI, and CAIDI). To assess the accuracy of our proposed approach, we compare our formal ET analysis results for the grid with those obtained by MATLAB Monte Carlo simulation, the commercial Isograph software as well as manual paper-and-pencil analysis.
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame machine prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. The Gemma side is a direct model label for every work in the frame, read from the title-only record. The Codex side is a classifier learned from the 10,348 direct Codex labels and calibrated to design-weighted sample rates; fields without enough sample support carry no Codex call. Candidate is the union of the two sides; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels.
Distilled classifier scores by category (both heads)
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.005 | 0.017 |
| Meta-epidemiology (narrow) | 0.001 | 0.000 |
| Meta-epidemiology (broad) | 0.001 | 0.002 |
| Bibliometrics | 0.002 | 0.001 |
| Science and technology studies | 0.001 | 0.002 |
| Scholarly communication | 0.002 | 0.003 |
| Open science | 0.002 | 0.001 |
| Research integrity | 0.001 | 0.001 |
| Insufficient payload (model declined to judge) | 0.003 | 0.001 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; a candidate call from one source (direct Gemma or distilled Codex), not a consensus.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".