发表机构
Beihang University(北京航空航天大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究提出JTA架构,将场景、测试系统与被测系统整合分析,通过多维度表征验证能力并引入相关方法,经ArduPilot失效保护验证示例分析,为安全关键软件场景化验证提供架构基础。
AI 中文摘要
安全关键软件的验证充分性不仅取决于被测系统,还需在受控条件下构建关键场景、将执行证据整理为可直接判定的形式,且异常结果必须能归因于可操作的原因。现有可测试性研究大多以工件为中心,几乎未为场景、测试系统与被测系统的组合能力推理提供架构支持。联合可测试性架构(JTA)将这三者视为单一分析与设计对象,沿可控性、可观测性、可隔离性三个维度表征验证能力,通过三个领域、三个桥梁及分析-设计-评估-优化循环对其进行组织。JTA还引入了场景契约、联合能力评估、验证盲区识别及面向桥梁的设计动作,将能力缺口映射为控制点、证据组织及归因边界的具体改进。对ArduPilot失效保护验证的示例分析显示,链路丢失场景的验证成熟度相对较高,而状态估计异常场景因证据对齐与归因语义较弱,验证难度更大。JTA并非替代现有测试或安全分析技术,而是为安全关键软件的场景化验证提供建模、设计与评估的架构基础。
英文摘要
Validation adequacy in safety-critical software depends on more than the system under test. Critical scenarios must be constructed under controlled conditions, execution evidence must be aligned into verdict-ready form, and abnormal outcomes must be attributable to actionable causes. Existing testability research remains largely artifact-centric and offers little architectural support for reasoning about the combined capability of the scenario, the test system, and the system under test. Joint Testability Architecture (JTA) addresses this gap by treating those three elements as a single object of analysis and design. It characterizes validation capability along three dimensions--controllability, observability, and isolability--and organizes them through three domains, three bridges, and an analysis-design-evaluation-refinement loop. JTA also introduces scenario contracts, joint capability assessment, validation blind-spot identification, and bridge-oriented design actions that map capability gaps to concrete improvements in control points, evidence organization, and attribution boundaries. An illustrative analysis of ArduPilot failsafe validation shows that link-loss scenarios are comparatively mature, whereas state-estimation anomaly scenarios remain harder to validate because evidence alignment and attribution semantics are weaker. JTA is not a replacement for existing testing or safety-analysis techniques; it provides an architectural basis for modeling, designing, and assessing scenario-based validation in safety-critical software.
CommentsAccepted by QRS 2026