<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xml:lang="ru"><front><journal-meta><journal-id journal-id-type="publisher-id">sustain</journal-id><journal-title-group><journal-title xml:lang="ru">Надежность</journal-title><trans-title-group xml:lang="en"><trans-title>Dependability</trans-title></trans-title-group></journal-title-group><issn pub-type="ppub">1729-2646</issn><issn pub-type="epub">2500-3909</issn><publisher><publisher-name>RAMS Journal Limited liability company</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.21683/1729-2646-2021-21-2-31-37</article-id><article-id custom-type="elpub" pub-id-type="custom">sustain-419</article-id><article-categories><subj-group subj-group-type="heading"><subject>Research Article</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="ru"><subject>БЕЗОПАСНОСТЬ. УПРАВЛЕНИЕ РИСКАМИ. ТЕОРИЯ И ПРАКТИКА</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="en"><subject>SAFETY. RISK MANAGEMENT. THEORY AND PRACTICE</subject></subj-group></article-categories><title-group><article-title>О построении модели безопасности сложной автоматической системы транспортного обслуживания</article-title><trans-title-group xml:lang="en"><trans-title>Safety model construction for a complex automatic transportation system</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author" corresp="yes"><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Озеров</surname><given-names>А. В.</given-names></name><name name-style="western" xml:lang="en"><surname>Ozerov</surname><given-names>А. V.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Алексей Валерьевич Озеров – начальник Международного управления</p><p>Москва</p></bio><bio xml:lang="en"><p>Alexey V. Ozerov, Head of Department</p><p>Moscow</p></bio><xref ref-type="aff" rid="aff-1"/></contrib><contrib contrib-type="author" corresp="yes"><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Ольшанский</surname><given-names>А. М.</given-names></name><name name-style="western" xml:lang="en"><surname>Olshansky</surname><given-names>А. М.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Алексей Михайлович Ольшанский – кандидат технических наук, руководитель Центра перспективных разработок </p><p>Москва</p></bio><bio xml:lang="en"><p>Alexey M. Olshansky, Head of Centre</p><p>Moscow</p></bio><email xlink:type="simple">a.olshanskiy@vniias.ru</email><xref ref-type="aff" rid="aff-1"/></contrib></contrib-group><aff-alternatives id="aff-1"><aff xml:lang="ru">АО «НИИАС»<country>Россия</country></aff><aff xml:lang="en">JSC NIIAS<country>Russian Federation</country></aff></aff-alternatives><pub-date pub-type="collection"><year>2021</year></pub-date><pub-date pub-type="epub"><day>02</day><month>06</month><year>2021</year></pub-date><volume>21</volume><issue>2</issue><fpage>31</fpage><lpage>37</lpage><permissions><copyright-statement>Copyright &amp;#x00A9; Озеров А.В., Ольшанский А.М., 2021</copyright-statement><copyright-year>2021</copyright-year><copyright-holder xml:lang="ru">Озеров А.В., Ольшанский А.М.</copyright-holder><copyright-holder xml:lang="en">Ozerov А.V., Olshansky А.М.</copyright-holder><license license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>This work is licensed under a Creative Commons Attribution 4.0 License.</license-p></license></permissions><self-uri xlink:href="https://www.dependability.ru/jour/article/view/419">https://www.dependability.ru/jour/article/view/419</self-uri><abstract><p>Цель статьи – рассмотреть подходы к анализу модели безопасности сложных многоконтурных систем транспортного обслуживания, состоящих из не полностью контролируемых подсистем. </p><sec><title>Методы</title><p>Методы. Для описания модели безопасности используются методы системно-теоретического анализа процессов STPA и принципы, изложенные в стандарте ISO/PAS 21448:2019 (SOTIF). </p></sec><sec><title>Результаты</title><p>Результаты. В статье показаны недостатки методик локального анализа рисков FTA и FMEA и продемонстрирована необходимость более универсального подхода на основе сочетания методологии системного анализа и теории управления. Проиллюстрированы основные этапы такого анализа модели безопасности сложных систем транспортного обслуживания на примере Московского центрального кольца, обеспечивающие обратную связь для оценки безопасности планируемой структуры системы управления. Рассмотрен вариант схемы управления с виртуальной моделью в виде так называемой «контролируемой искусственной нейронной сети». </p></sec><sec><title>Выводы</title><p>Выводы. В настоящее время активно тестируются системы беспилотного управления (без машиниста) на железнодорожном транспорте, которые имеют в своем составе модули автоматического обнаружения препятствий, использующие методы машинного обучения. Введение последних в контур управления крайне усложняет задачу анализа рисков и угроз и оценку безопасности таких систем с помощью традиционных методов построения деревьев ошибок и анализа отказов и их последствий FTA и FMEA. При построении модели безопасности столь сложных многоконтурных систем транспортного обслуживания, состоящих из не полностью контролируемых подсистем, в которых используются методы машинного обучения с не до конца предсказуемым поведением, требуется применение системного подхода для анализа небезопасных сценариев с формированием библиотеки сценариев и формализацией описания модели угроз, в том числе на границах различных контуров управления, в целях сокращения области неизвестных небезопасных сценариев для проектируемых систем беспилотного транспортного обслуживания.</p></sec></abstract><trans-abstract xml:lang="en"><p>The Aim of the paper is to consider approaches to the analysis of a safety model of complex multi-loop transportation systems comprising not completely supervised subsystems. </p><sec><title>Method</title><p>Method. For the description of a safety model, the paper uses systems theoretic process analysis (STPA) methods and the principles specified in ISO/PAS 21448:2019 (SOTIF). </p></sec><sec><title>Result</title><p>Result. The paper shows drawbacks of the FTA and FMEA local risk analysis methods and demonstrates a demand for some universal approach based on the combination of STPA and control theory. It gives an overview of the major stages of such analysis for the safety model of complex transportation systems exemplified by the Moscow Central Circle, which provide a feedback for safety evaluation of a transport control system under development. The paper analyzes the feasibility of using a virtual model for control purposes in the form of a so-called “supervised artificial neural network”.</p></sec><sec><title>Conclusion</title><p>Conclusion. Today, railways are actively testing autonomous systems (with no driver onboard) that apply as their subsystems automatic perception modules using machine learning. The introduction of the latter into the control loop complicates the task of hazard analysis and safety evaluation of such systems using conventional FTA and FMEA methods. The construction of a safety model of such complex multi-loop transportation systems comprising not completely supervised subsystems that use machine learning methods with not completely predictable behavior requires the application of a systems approach to the analysis of unsafe scenarios along with the compilation of a scenario library and the formalization of a hazard model’s description, pertaining to the boundaries of various control loops as well, in order to reduce the regions of unknown unsafe scenarios for autonomous transportation systems under development.</p></sec></trans-abstract><kwd-group xml:lang="ru"><kwd>железнодорожный транспорт</kwd><kwd>беспилотное управление</kwd><kwd>модель безопасности</kwd><kwd>метод STPA</kwd><kwd>машинное обучение</kwd><kwd>искусственная нейронная сеть (ИНС)</kwd></kwd-group><kwd-group xml:lang="en"><kwd>railway transport</kwd><kwd>autonomy</kwd><kwd>safety model</kwd><kwd>STPA</kwd><kwd>machine learning</kwd><kwd>artificial neural network (ANN)</kwd></kwd-group></article-meta></front><back><ref-list><title>References</title><ref id="cit1"><label>1</label><citation-alternatives><mixed-citation xml:lang="ru">World Report on Metro Automation. URL: https://www. uitp.org/publications/world-report-on-metro-automation/</mixed-citation><mixed-citation xml:lang="en">https://www.uitp.org/publications/world-report-onmetro-automation/.</mixed-citation></citation-alternatives></ref><ref id="cit2"><label>2</label><citation-alternatives><mixed-citation xml:lang="ru">IEC 26690:2014. Railway applications – Urban guided transport management and command/control systems – Part 1: System principles and fundamental concepts.</mixed-citation><mixed-citation xml:lang="en">IEC 26690:2014. Railway applications – Urban guided transport management and command/control systems – Part 1: System principles and fundamental concepts.</mixed-citation></citation-alternatives></ref><ref id="cit3"><label>3</label><citation-alternatives><mixed-citation xml:lang="ru">Шубинский И.Б., Шебе Х., Розенберг Е.Н. О функциональной безопасности сложной технической системы управления с цифровыми двойниками // Надежность. 2021. № 1. С. 38-44.</mixed-citation><mixed-citation xml:lang="en">Shubinsky I.B., Schäbe H., Rozenberg E.N. On the functional safety of a complex technical control system with digital twins. Dependability 2021; 1:38-44.</mixed-citation></citation-alternatives></ref><ref id="cit4"><label>4</label><citation-alternatives><mixed-citation xml:lang="ru">Qi Y., Cao Y., Sun Y. Safety analysis on typical scenarios of GTCS based on STAMP and STPA // IOP Conference Series: Materials Science and Engineering. IOP Publishing, 2020. Т. 768. № 4. P. 042042.</mixed-citation><mixed-citation xml:lang="en">Qi Y., Cao Y., Sun Y. Safety analysis on typical scenarios of GTCS based on STAMP and STPA. IOP Conference Series: Materials Science and Engineering 2020;768(4):042042.</mixed-citation></citation-alternatives></ref><ref id="cit5"><label>5</label><citation-alternatives><mixed-citation xml:lang="ru">Leveson N.G., A systems-theoretic approach to safety in software-intensive systems // IEEE Transactions on Dependable and Secure Computing. 2004. Vol. 1. No. 1 P. 66-86.</mixed-citation><mixed-citation xml:lang="en">Leveson N.G. A systems-theoretic approach to safety in software-intensive systems. IEEE</mixed-citation></citation-alternatives></ref><ref id="cit6"><label>6</label><citation-alternatives><mixed-citation xml:lang="ru">Chaima Bensaci, Youcef Zennir, Denis Pomorski. A Comparative Study of STPA Hierarchical Structures in Risk Analysis: The case of a Complex Multi-Robot Mobile System. // European Conference on Electrical Engineering &amp; Computer Science, EECS 2018, Dec 2018, Bern, Switzerland.</mixed-citation><mixed-citation xml:lang="en">Transactions on Dependable and Secure Computing 2004;1(1):66-86.</mixed-citation></citation-alternatives></ref><ref id="cit7"><label>7</label><citation-alternatives><mixed-citation xml:lang="ru">ISO/PAS 21448:2019 (SOTIF). Road Vehicles – Safety of the Intended Function.</mixed-citation><mixed-citation xml:lang="en">Bensaci C., Zennir Y., Pomorski D. A Comparative Study of STPA Hierarchical Structures in Risk Analysis: The case of a Complex Multi-Robot Mobile System. European Conference on Electrical Engineering &amp; Computer Science. Bern (Switzerland); 2018.</mixed-citation></citation-alternatives></ref><ref id="cit8"><label>8</label><citation-alternatives><mixed-citation xml:lang="ru">Попов П.А. Развитие отечественных и зарубежных беспилотных технологий // Автоматика, связь, информатика. 2020. № 9. C. 6-12.</mixed-citation><mixed-citation xml:lang="en">ISO/PAS 21448:2019 (SOTIF). Road Vehicles – Safety of the Intended Function.</mixed-citation></citation-alternatives></ref><ref id="cit9"><label>9</label><citation-alternatives><mixed-citation xml:lang="ru">Арнольд В.И. «Жесткие» и «мягкие» математические модели. М.: Издательство МЦНМО, 2004. 32 с.</mixed-citation><mixed-citation xml:lang="en">Popov P.A. [Development of Russian and foreign driverless operation technology]. Automation, Communica‑ tion and Informatics 2020;9:6-12. (in Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit10"><label>10</label><citation-alternatives><mixed-citation xml:lang="ru">Yan F., Zhang S., Tang T. Autonomous Train Operational Safety assurance by Accidental Scenarios Searching // 2019 IEEE Intelligent Transportation Systems Conference (ITSC). IEEE, 2019. P. 3488-3495.</mixed-citation><mixed-citation xml:lang="en">Arnold V.I. “Hard” and “soft” mathematical models. MTSNMO Publishing house; 2004. (in Russ.).</mixed-citation></citation-alternatives></ref><ref id="cit11"><label>11</label><citation-alternatives><mixed-citation xml:lang="ru">Yan F., Zhang S., Tang T. Autonomous Train Operational Safety assurance by Accidental Scenarios Searching. IEEE Intelligent Transportation Systems Conference. IEEE; 2019. P. 3488-3495.</mixed-citation><mixed-citation xml:lang="en">Yan F., Zhang S., Tang T. Autonomous Train Operational Safety assurance by Accidental Scenarios Searching. IEEE Intelligent Transportation Systems Conference. IEEE; 2019. P. 3488-3495.</mixed-citation></citation-alternatives></ref></ref-list><fn-group><fn fn-type="conflict"><p>The authors declare that there are no conflicts of interest present.</p></fn></fn-group></back></article>
