发表机构
Naval Postgraduate School(美国海军研究生院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文提出脆弱性空间理论,将风险分析三元组重新定义为脆弱性空间,区分风险、可靠性、对抗性和安全性四种视角,并论证单一视角无法全面揭示系统脆弱性,风险决策需权衡其他视角。
AI 中文摘要
自20世纪80年代以来,工程系统的风险分析一直基于情景集合$\mathcal{S}$、可能性$L$和后果$C$的三元组来定义,其中$Risk = (\mathcal{S},L,C)$。我们认为,仅将这一三元组等同于风险是不充分的,且可能具有误导性。相反,我们将此三元组定义为脆弱性空间$\mathcal{V} = (\mathcal{S},L,C)$,只有当人们对可能性和后果做出特定解释时,它才成为风险。在此,解释具有数学意义,并定义了一个将系统脆弱性数据元素映射到某一视角的映射。形式上,我们将脆弱性视角定义为对可能性和后果数据的特定解释选择,该选择允许定义和分析脆弱性分析度量。我们认为风险只是$\mathcal{V}$的四种常见视角之一,并从数学上论证为何每种视角都应保持为独立概念。首先,我们展示了将$C$解释为集值函数会产生可靠性度量,而非风险度量。然后,我们展示了通过可能性理论对$L$的解释将产生不同于风险的对抗性和安全性度量。这一新的理论框架阐明了风险、可靠性、对抗性和安全性视角之间的概念、数学和实践差异——这四种常见的工程系统分析在文献中经常被混淆。我们理论的一个结果是,没有任何单一视角能揭示工程系统的所有脆弱性,这表明通过风险分析进行决策可能会不可避免地产生来自其他脆弱性视角的、未被充分认识的权衡取舍。
英文摘要
Since the 1980s, risk analysis for engineering systems has been defined based on a tuple of scenarios, $\mathcal{S}$, likelihoods, $L$, and consequences, $C$, where $Risk = (\mathcal{S},L,C)$. We argue that equating this triplet with risk alone is insufficient and potentially misleading. Instead, we define this tuple as a vulnerability space $\mathcal{V} = (\mathcal{S},L,C)$, which becomes risk only when one makes specific interpretations of likelihood and consequence. Here, an interpretation has mathematical meaning, and defines a map that assigns data elements about system vulnerability to a perspective. Formally, we define a vulnerability perspective as a specific choice of interpretations of likelihood and consequence data that allows vulnerability analysis measures to be defined and analyzed. We argue that risk is only one of four common perspectives on $\mathcal{V}$ and demonstrate mathematically why each perspective should remain a distinct concept. First, we show how interpretation of $C$ as a set-valued function produces reliability measures, not risk measures. Then, we show how interpretation of $L$ via possibility theory will produce adversarial and safety measures distinct from risk. This new theoretical framework clarifies the conceptual, mathematical, and practical differences between risk, reliability, adversarial, and safety perspectives---four common engineering system analyses often conflated in the literature. A consequence of our theory is that no single perspective will reveal all vulnerabilities of an engineering system, suggesting decision-making via risk analysis may incur unavoidable and underappreciated tradeoffs from other vulnerability perspectives.
Comments18 pages, 1 figure, 10 tables