122
D. Krpelík et al.
might be lucky enough to encounter a helpful railroad clerk who will direct you to
an alternative connection or not.
To model such situations, the structure function might be naturally generalised to
include uncertainties about the dependencies among the states of the events in the
fault tree simply by stating the probability of the event obtaining based on the states
of the events lower in the tree hierarchy. A (graphical) tool used to depict these
models is known as the Bayesian network (BN) [5], [13, Ch. 8]. The construction
may be done by the FTA, but now we do not formulate the dependencies between
a macro-event and its causes by Boolean functions but as conditional probabilities.
This is, of course, a much more challenging task, but it also provides an advantage. It
allows us to work with a less detailed models, since we need not to advance the tree
construction up to the level in which all the relations would be deterministic, and
these conditional probabilities can be inferred by statistical methods (also by robust
statistical methods [3, Ch. 9]). Thus the main role of the FTA would be to elicit the
relevant events and the assumptions on the conditional independence. Once the BN
is constructed and the stochastic models are provided, the system reliability may
be assessed, deductively, according to the theory of probability. For
X denoting the
random vector of system components’ states:
P r(X S = 1|
X = =
x) =
y 1 ,y 2
P r(X S = 1|X A = y 1 , X B = y 2 )·
· P r(X A = y 1 , X B = y 2 |
X = =
x),
where X A , X B are the only macro-events such that the state of the system is
conditionally independent from component states given X A , X B according to our
structural assumptions.
The state of the system can be assessed recursively by marginalising over
X.
P r(X S = 1) =
x∈{0,1} N
P r(X S = 1|
X = =
x)P r(
X = =
x).
Bayesian networks can also be used to model dependencies among the component
failures, e.g. common cause failures, where some external disturbance might affect
multiple components at the same time. In such a case, component reliabilities may
be specified as conditional on the occurrence of this disturbing event, e.g.
P r(X i (t) = 1|E D (t) = 0) = R i (t)
P r(X i (t) = 1|E D (t) = 1) = 0,
for some disturbing event E D (t). In this scenario, the disturbing event would surely
render the component failed. In order to assess the overall system reliability, the
probability of occurrence of this disturbing event also has to be specified.
Précédent

- 126/568

Suivant