Score
Designs and conducts systematic analyses of operational systems to identify and characterize hazards, failure modes, and hazardous situations and to estimate their likelihood, severity, and deployment tolerance requirements. Produces risk mappings and mitigation strategies by tracing hazards to harms, using guide-word and other hazard-analysis techniques to reveal, prioritize, and specify controls or monitoring for operational risks.
Leading AI organizations lack systematic methodologies for identifying safety risks, particularly those arising from feedback-driven and interactive failure modes; manual assessment further suffers from limited causal traceability and incompleteness. Method: This work pioneers the adaptation of System Safety Engineering’s STPA (System-Theoretic Process Analysis)—a rigorous hazard analysis framework from aviation and industrial safety—to AI systems. We construct control structure models, integrate loss scenario simulation with an AI-specific safety case framework (Korbak et al., 2025), and automatically identify Unsafe Control Actions and associated Loss Scenarios overlooked by existing threat models. Contribution/Results: The approach enables LLM-augmented, scalable analysis, significantly improving coverage, causal traceability, and robustness in hazard identification. Experimental validation demonstrates that STPA provides a verifiable, extensible, and complementary assurance mechanism for AI safety governance.
Remote Operation Centers (ROCs) face low efficiency in safety certification and lack a systematic hazard classification framework. Method: This paper proposes a hazard classification and risk assessment method selection framework based on a Generic Functional Architecture (GFA). It innovatively applies functional architecture to ROC hazard modeling for the first time, establishing a structured hazard database conceptual model. Through a three-phase process—functional decomposition, hazard mapping, and applicability analysis—the framework integrates multiple analytical techniques (e.g., HAZOP, FMEA, Bow-tie) to enable precise matching of hazard identification, classification, and assessment methods. Contribution/Results: The framework significantly enhances the systematicity and operational feasibility of ROC safety certification. It provides both theoretical foundations and practical tooling to support the International Maritime Organization (IMO) and classification societies in developing standardized ROC certification criteria.
This paper addresses the insufficient integration of early-system safety analysis with Model-Based Systems Engineering (MBSE). It comparatively evaluates three functional safety analysis methods—Failure Mode and Effects Analysis (FMEA), Functional Hazard Assessment (FHA), and Fault Feedback and Impact Propagation (FFIP)—and identifies FFIP as superior for detecting emergent behaviors, second-order effects, and fault propagation. Subsequently, it systematically reviews existing MBSE integration practices, categorizing them into four approaches: model transformation, custom algorithm development, built-in toolkits, and manual modeling. The study reveals that current integration efforts are predominantly focused on FMEA, while FHA and FFIP remain in exploratory stages, hindered by the absence of a unified framework and standardized guidelines. To bridge this gap, the paper proposes a novel, full-lifecycle safety analysis integration paradigm aligned with digital engineering transformation—enabling traceable, executable, and evolvable model-driven safety verification.
In early-stage collaborative robot task design, safety experts struggle to comprehend task logic, and risk assessment outcomes often lack practical implementability. Method: This paper proposes a model-driven risk assessment approach based on Behavior Trees (BTs)—the first application of BTs in risk assessment—enabling early risk identification, formal verification, and end-to-end traceability via visual modeling. Integrating Model-Driven Engineering (MDE) with Human Factors evaluation, the method was empirically validated by cross-functional practitioners from five industrial enterprises. Contribution/Results: The approach significantly improves risk identification completeness (+32%) and enhances collaboration efficiency between safety experts and development teams, reducing communication overhead by 41%. It establishes a novel, industrial-grade paradigm for trustworthy robotic systems that unifies modeling, analysis, and implementation within a single coherent framework.
Industrial operational technology (OT) systems—prioritizing functionality over security—are frequently misconfigured and exposed to the public Internet, posing severe cyber-physical risks. Method: We propose a comprehensive framework integrating cyberspace mapping, protocol fingerprinting, firmware version analysis, and a novel automated HMI/SCADA interface screenshot recognition technique to systematically assess global OT exposure. Our methodology correlates findings with vulnerability databases (e.g., NVD, ICS-CERT) and geolocation data across protocols, vendors, software, and regions. Contribution/Results: We identify nearly 70,000 publicly exposed OT devices, predominantly in North America and Europe; many run outdated firmware containing known critical vulnerabilities and remain unpatched for extended periods. Crucially, our interface-based analysis uncovers multiple previously undocumented unauthorized access paths—enabling the first large-scale, visually grounded quantification of real-world industrial attack surfaces and delivering actionable, operationally relevant insights for risk mitigation.
This study addresses the functional safety risks of infrastructure-enabled autonomous vehicle yard systems (IX-DA) operating without human intervention by systematically applying, for the first time, the Hazard Analysis and Risk Assessment (HARA) methodology from ISO 26262 to closed-area, infrastructure-dominated scenarios. The authors identify eight categories of hazardous events and derive six corresponding safety goals, proposing a dynamic ASIL downgrade strategy based on operational speed: high-speed loss-of-control scenarios require compliance with ASIL C, whereas low-speed controlled operations may be downgraded to QM. By integrating a standards-compliant HARA process, system architecture decomposition, and multi-scenario risk evaluation, this approach offers a feasible pathway for the phased safety deployment of IX-DA systems.
This study addresses the challenge of analyzing complex, multidimensional safety risks in aviation systems, which traditional functional hazard analysis methods struggle to capture comprehensively. To overcome this limitation, the authors propose a novel, traceable, and structured approach for generating hypothetical hazard scenarios using large language models (LLMs). The method automatically constructs coherent hazard narratives from NASA Aviation Safety Reporting System (ASRS) reports and evaluates their plausibility through historical co-occurrence evidence. Innovatively integrating evolutionary abduction with a hybrid generation mechanism—combining zero-shot and few-shot prompting alongside optional fine-tuning—the framework employs evolutionary algorithms to optimize both structural validity and narrative consistency. Experimental results demonstrate that this hybrid strategy significantly enhances the realism, logical correctness, and diversity of generated scenarios, outperforming approaches based on single-generation paradigms.
This study addresses critical limitations in current AI risk assessment methodologies, which often misapply traditional safety frameworks, leading to incomplete risk coverage and erroneous safety conclusions due to terminological imprecision and inadequate contextual fit. To overcome these issues, this work proposes the first end-to-end risk assessment framework that extends the concept of Operational Design Domain (ODD)—originally developed for autonomous vehicles—to general-purpose AI systems. By explicitly defining the intended operating conditions of AI systems, the framework establishes well-demarcated safety boundaries. It integrates principles from systems safety engineering, cybersecurity, and AI governance, harmonizing technical, societal, and ethical dimensions into a unified, rigorous terminology and a structured evaluation process. The resulting methodology offers a comprehensive risk assessment tool applicable across diverse AI domains, significantly enhancing developers’ and auditors’ ability to understand, validate, and credibly substantiate safety claims—thereby avoiding misleading assurances of security.
This study addresses the lack of a systematic framework for identifying critical input variables and conducting sensitivity analysis under uncertainty in complex simulations, particularly in military decision-making contexts. The authors propose a unified sensitivity analysis framework that integrates local and global methods—including variance-based, derivative-based, screening, and uncertainty quantification techniques—and strategically maps these approaches to specific decision objectives such as factor prioritization, fixing, variance reduction, and mapping. Innovatively, the framework introduces a “sensitivity audit” mechanism to enhance traceability of model assumptions and promote responsible model usage. By providing a structured guide for high-dimensional, complex simulation systems, this work significantly improves model interpretability, transparency, and the credibility of decisions derived from such models.
This study addresses the challenge of managing residual risks that cannot be fully eliminated, noting that existing qualitative analyses lack actionable dynamic management mechanisms. To bridge this gap, the authors propose formalizing the Bowtie risk diagram as a directed acyclic graph (DAG) capable of supporting Bayesian inference and causal intervention. By incorporating safety-state semantics and explicit intervention nodes, and integrating expert probability assessments with do-calculus, the framework enables risks to be observable, quantifiable, and intervenable. The work introduces Realtime Risk Studio—a modeling tool—and Probability Capture—a method for eliciting probabilistic judgments—to construct, for the first time, an executable real-time risk reasoning model. Validation in an instant payment gateway scenario demonstrates the efficacy of transforming Bowtie diagrams into DAGs, fusing noisy expert probabilities, and performing “What-if” causal intervention analyses.