Showing posts with label system safety. Show all posts
Showing posts with label system safety. Show all posts

Wednesday, June 2, 2010

NYTimes discusses "nuking the well", studies were done decades ago

I just read NYTimes article about the discussion to use underground nuclear explosion to seal the oil leak in the Gulf of Mexico http://www.nytimes.com/2010/06/03/us/03nuke.html?hp. The idea may sound crazy, but experiments were conducted in 1970s in the USSR. The places are called Lira and Azgir nuclear testing sites in Western Kazakhstan, you can read more on  http://www.nnc.kz/en/about/activity/radioecology.html .

Kazakhstan's National Nuclear Center continues environmental monitoring of the sites.  I am not an expert in this field, but from what I understand an underground nuclear explosion creates a sealed cavity that serves as a container, which keeps natural gas and condensate form leaking into the ground. I have thought about this project when InnoCentive announced its  "Emergency Response 2.0 : Solutions to Respond to Oil Spill in the Gulf of Mexico" on https://gw.innocentive.com/ar/challenge/overview/9383447 .

At that time I thought it could be nearly impossible to place a nuclear device 1 km deep into the water and further into the seabed. But I guess, some of the scientists that were involved with the project decided to give the idea a shot, literally. I knew that both underwater and underground tests were routinely done in the past (see http://alturl.com/v7x6 ), but combining two in one could be a real challenge.

I agree with NYTimes that such risky idea is cannot be seriously considered.  However, as crazy as the idea sounds, the fact that it got front page coverage in NYTimes (!!!"...What about nuking the well?") suggests that both BP and the Federal government are running out of serious options. Or perhaps, public opinion is being prepared for an option that includes conventional explosion to stop the spill, which looks much more acceptable vis-a-vie a nuclear option.

Here is an abstract from the paper called Reduction of Risks from Lira Underground Nuclear Facilities at Karachaganak Oil-and-Gas Complex published by National Nuclear Center researchers in 2008:

"T. I. Ageyeva2, A. Zh. Tuleushev2 and V. V. Podenezhko2
(2) Institute of Nuclear Physics, Almaty, Kazakhstan
The theme of this article is the investigations of radioactive contamination within and around underground cavities created by underground nuclear detonations performed in connection with the operation of oil and gas condensate fields. Underground storages of gas condensate are not maintained for a long time. The results from the large-scale complex indicate the absence of a real threat from nuclear objects on the environment. However, there is a potential danger connected with possible changes in the geological environment containing the underground storages of condensates. The pressure created in the cavities is the controlling parameter of the conditions in the cavities. Laboratory investigations of a condensate from the underground cavities confirm the absence of caesium-137 and strontium-90 and the presence of tritium. The strategy of closing off the cavities with the application of filling the cavity space with loose or helium materials is designed. The basic objective of the subsequent works is to decrease the environmental risks associated with oil-and-gas operations and underground storage of condensates.

Keywords  cavities - underground nuclear detonations - condensate storage - LIRA - Kazakhstan"

Source: http://www.springerlink.com/content/r3w0jgvmx87tv332/

Tuesday, June 1, 2010

Realpolitik of the Blame Game

After BP’s numerous failed attempts to stop oil contamination in the Gulf of Mexico its corporate image is in ruins.  As BP’s public image reached its saturation limits for criticism, the political debate redirects public attention from the oil company to the Federal government.  With the accident rolling into its sixth week, the Obama administration is forced to answer  “Who is to blame?” and “What to do?” In short, political pressure and public anger demand swift satisfaction.

In this respect, Obama's decision to begin criminal investigations into the Deepwater Horizon explosion and the oil spill may give such satisfaction. Unfortunately, it is short-lived and may prove counterproductive in the long-run. Criminal inquiries into the cause of the oil spill is likely to narrow down the scope of post-mortem analysis to near physical and temporal proximity of the accident. In other words, the investigation will focus on people who made decisions as the accident emerged.

After the Exxon Valdes accident, the public was given a scapegoat, Capitan Hazelwood, who was singlehandedly blamed to cause the accident. Although, he was later cleared of the charge being drunk at the time of the accident, he had never cleared his name from the stigma of causing of the biggest oil spill in US history (until current accident).   There were more systemic problems such as functional and interoperable navigation systems on board the ship and on the shore of Alaska, the culture of tolerance to safety problems among the oil executives and public official, etc. However,  systemic factors tend to “spread the blame” and lack the luxury of targeted blame, thus satisfaction of punishment.  Simple and straightforward causes are always easier to describe and accept. I hope to be wrong, but it is likely that we can expect several Capitan Hazelwoods from BP and its subcontractors who could be “scarified” to satisfy public outcry.  However, it is unlikely that such narrow view can help us understand the complexity of the accident.

It is in our human nature to go back in time and look for a single event, which could have prevented to the catastrophe from happening.  The bigger the accident, the stronger is our temptation to reverse time. Inability to reverse the situation results in anger, dissatisfaction and need for revenge. These emotions have to be channeled one way or the other. What make the case with the oil spill unique is the fact that the public is given a rare opportunity to be part of the accident as it emerges.  The public feels helpless to reverse time and to contain the accident. Old and new media channels enables people to get first-hand accounts of the environmental impact on the ocean's seabed, the coast and wildlife. As the result, it is natural for people to ask who is in charge and who is to blame. If those who are in charge do not act swiftly and find those who are to blame, the public could blame those who are in charge.  If those who were in charge yesterday do not blame those who are in charge today, then those who were in charge yesterday are to get blamed themselves and vice versa. The same is true with BP and its numerous subcontractors.

Unfortunately realpolitik of the blame game creates an environment in which each player is concerned with own political and legal liabilities. Criminal inquiry adds more gasoline to the flame.  Starting the investigation before accident’s containment is almost like investigating causes of an air crash with airplane still in the air. Perhaps, such approach could give unique perspective, but more likely it will downgrade itself to simplified description of immediate events with operators and decision makers who were unfortunate enough to be in close proximity as the accident emerged.

Wednesday, May 26, 2010

"The Logic Of Failure: Recognizing And Avoiding Error In Complex Situations"

Great book written in 1989 by West German Professor Dorner. This is a good introduction into System dynamics and System thinking. The book gives several mental models of how people "attack" complex problems and why they often fail. Dorner describes several psychological experiments that help to differentiate "bad decision maker" from "good decision makers," as well as mental traps that lead to failures. Based on this analysis he presents his model of decomposition and planning. At the end of the book Dorner quotes Clausewitz that "...War is not an infinite mass of minor events... War consists rather of single, great, decisive actions, each of which needs to be handled individually." Such "strategic thinking" requires far greater expenditure of mental energy argues Dorner.

Dorner ends his book with the thought that "...If we cannot form a picture of a temporal configuration, we cannot adjust our thinking and actions to take that temporal pattern into account... We human being are creature of the present. But the world today must learn to think in temporal configuration."

The book is easy to read and comprehend. I gave it to my 15 years old son to read it. Hopefully he will use my advise to read it earlier in his life.

"The Field Guide to Understanding Human Error" by Sidney Dekker

I met Professor Dekker couple of weeks ago during his visit to Engineering System Division at MIT.

He is definitely one of the most intelligent and sharp thinking persons I have ever met. I was impressed with his clarity and speed of thought. I could catch with his speed of thinking only after he made an iterative loop in his argument.

There are two major themes that are reflected throughout his book. First is that human error is not the cause but a symptom of a trouble. Accepting this notion is first step towards New view of human error, which can never be the conclusion of an investigation, but rather its starting point. Understanding error means reconstructing the context in which such decision was made. "Human error problem is an organizational problem.  This means that understanding human error hinges in understanding the organizational context in which people work."

People tend to react post factum and backwardly reconstruct sequence of events in a linear manner.  In the aftermath of an accident, one can easily list logical arguments how and why people should have foreseen and prevented the upcoming events. We easily judge people, who failed to take proper actions. We focus on their personal shortcomings such as absence of proper training and experience, health conditions and hours of proper sleep, etc.  We usually tend to focus our attention on people who happened to be closest to the accident in term of time and space.

Second theme of the book is forward looking metal model, which focuses on preventing accidents in the future rather than analyzing the accident with a hindsight bias. Hindsight gives the investigators better and more complete information in comparison to people who made the decision prior to the failure.  It provides with facts that become midpoints in the linear logic flow that the investigator reconstructs. As we walk backwards, each facts is perceive not as an "intersection point" with a list of equally valid choices, but rather as point of the process when/where incorrect decision was recorded. Hindsight bias exaggerates the importance of the recorded facts versus other events that are not directly related to the specific accident.

The author compares three accident models (1) the sequence-of-event, (2) the epidemiological model and (3) the system model. He argues that the latter is a holistic approach that looks at accidents as emerging form interactions between system components and processes, rather than failures within them.

Dekker warns against "quick fixes" and misuse of technical labels, which do not describe the gap between reality and our judgments, whereas "safety improvements come from organizations monitoring and understanding the gap between procedures and practice." He concludes that "a safety culture is a culture that allow the boss to hear bad news."

Thursday, February 18, 2010

How Safe Is Safe Enough?

Safety is a public good because the “consumption” or enjoyment of safety by one individual does not diminish the “availability” of safety for other individuals (assuming that the value of each human life is equal to the value of any other human life).  Government is elected by citizens of the society and is given official authority to enforce rules and regulations. Thus the government is given official power through enforcement of laws and regulations to maintain safety for the benefit of all citizens within its jurisdiction.  Magnitude of an accident (and its consequences) may affect each and every individual in the society or a random group of individuals. Theoretically, it is in general interest of all citizens to oblige with the rules and maintain safety.  In reality, “the picture” has many conflicting nuances.

As individuals we react to immediate pain.  Pain simplifies our point of view and helps us to survive (Minsky, 1985). Pain is build-in alarm system that informs human brain about immediate threats to its body’s existence.  As humans we tend to react to most immediate threats. When threats (and/or health hazards) are remote in terms of time and impact – such as smoking, breathing poisonous air, eating trans-fat food, etc – our reaction is not as swift or as rational.

A societal equivalent of human pain is loss of human life.  As a community or a society, people tend to react to accidents that involve loss of human lives with great attention.  The risks that are not visible or well understood do not get public attention until fatal accident actually takes place. As individuals, human society in general does not have high attention to threats and problems that are far in time and space.

Nothing can be valued more than human life. However, there is a distinction between the value of an exiting human life and the value of a deceased human being.  The later case was a substitute for blood feud or what is called vendetta, where attaching price to diseased life was the way to avoid further bloodshed. In fact this approach has been considered as more civilized conflict resolution for centuries (what is know as blood money). The moral line is drawn between the world of alive and the world of deceased. Those who attempt to take “the price tag” from the world of deceased and use it in our world make rational analysis, which is immoral at the same time.

In my point of view, there are two important trends worth noticing:

(1) As human society become more dependent on complex systems, there seems to be slow convergence of system safety and public health. It is clear that the fundamental of two fields is the same – the value of human life. However, it is not clear whether such oversimplified approach can be beneficial to either system safety or public health. This is just an intuitive feeling which I hope to understand during the course.

(2) Availability of information and its widespread and fast dissemination leads to greater public awareness. Easily available instruments and tools (email, matlab, google earth, skype, youtube, simple chemical tests and pH strips, individual radioactivity sensors, etc) lead to increased role of individuals in dealing with safety, which in turn influence behavior of governments and corporations. Availability of information also builds much richer postmortem picture of an accident and different accident scenarios, where ordinary citizens are able to question and challenge official reports and causes of an accident.

The simplest answer to the question “who should be responsibility for risk management?” is government and its regulatory agencies.  However, we know that the government agencies are managed and run by individuals. These individuals, as many of us, can manage only a certain level of complexity. There is no guarantee that they can integrate all the pieces together and maintain public safety all the time.

I think (“which implies that I do not as yet know so”), since safety is a public good, it has to be collective responsibility of each and every citizen in the society to think in cohesive and responsible when it comes to safety.

The role of the legal system depends on the end–result that society expects from its courts.  There must be a reason why the US legal system adopted the civil (tort) approach towards safety hazards (besides obvious corporate interests). It is my understanding that such approach was in part chosen to shift attention from responsibility of individuals to corporate responsibility, and eventually to accidents/hazards causes. It is difficult to judge if the system is functioning effectively or not since we have no information how many accidents/hazards were prevented just by potential possibility and danger of civil litigation.  We can only see the cases that are floating on the surface, in which corporations are using complex legal procedures to avoid, mitigate or postpone expensive settlements.

Criminal charges, on the other hand shift the focus from the accident to particular individual responsibility. It is often the case where both the government (which could be under public pressure) and the public itself are eager to “teach a lesson”. The expectation is shifted from understanding wholesale list of accident’s causes to finding specific “target” or “villain”.  Other potential “targets” are giving limited information about the accident reinforcing the initial bias, redirecting the blame and sacrificing the least protected “target.”

In the case of tainted milk, the Chinese government decided to teach a lesson. Three individuals were sentenced to death and 21 others, “mostly dairy producers and middlemen, were given terms ranging from two years to life in prison” (http://www.nytimes.com/2009/01/22/world/asia/22iht-milk.3.19601372.html).  Such lesson is likely to influence behavior of Chinese businessmen and even prevent potential food poisoning. One can argue that the trial may bring limited benefits to the society, even if it does not address the structural problem of food safety.

Here I would like to address the issue of Human error and Learning from Mistakes described (Flatch et al.). I think that we need to decouple <understanding the accident> from <learning from the accident>. I argue that it could be possible to learn from an accident even if complete description of an accident is not determined and vice versa. In any of the four options, the end result of the accident is the same.


















Learning form an accidentFailing to learn from an accident
Understanding the accidentXX
Failing to understand the accidentXX

So in the case of tainted milk, even if full picture of the food safety hazard has not been found or at least publicly recognized (i.e. export of the poisoned food products), there is still a possibility that appropriate lessons are learned. In the case of uncontrolled acceleration (Audi, Toyota, GM), even if the cause(s) of the fault(s) was known, the management has not learned the lesson.

This takes us back to individual reaction to physical pain.  Perhaps criminal prosecution of individual executives (in this case imprisonment) could be more effective approach in achieving public safety at the cost of objective accident investigation.

The biggest doubt here is that by focusing on individual responsibility we do not solve the challenges of potential accidents, which could be greater in power and magnitude as our society becomes more complex and interdependent.

Wednesday, November 11, 2009

Thoughts on STAMP (Systems-Theoretic Accident Model and Processes)

New Accident Model for Engineering Safer Systems (Leveson, http://sunnyday.mit.edu/16.355/)




Symptom – “something that indicates the existence of something else”, Webster dictionary http://www.merriam-webster.com/dictionary/Symptom



It is my understanding that STAMP focuses on “constraints necessary to limit system behavior to safe changes and adaptations” (p.12). The model briefly touches upon a symptom as “the process leading to an accident (loss event)... described in terms of an adaptive feedback function that fails to maintain safety as performance changes over time to meet a complex set of goals and values” (p.26).

Reading this article I kept asking myself if complex systems are just “complex and often imperfect human artifact”, could one characterize symptoms of upcoming accidents? In other words, if we can classify accident factors (p.21), can we characterize accident symptoms?

The article briefly mentions that “proximity” to systems has changed over time (p. 14). In the past, operators had direct access to their systems and were able to get “direct physical feedback” from the system. More experienced operators could have indentified changes in the system’s behavior or “feel” erroneous symptoms (or what is called “detect maladaptive changes” p.26).  Such ability usually came from “gut feeling” or intuition, which in reality was based on previous experience and undocumented assumptions.

Modern complex systems do not give us luxury of “feeling” the system. Moreover, post-mortem accident investigation may not reveal the symptoms that operators failed to recognize before that accident. Available factual data may not necessarily lead us to the correct interpretation of that data (p.26). But we may assume that such symptoms are usually non-linear, dynamics (with feedback loops) and adaptive to the environment.

It might sound as gross generalization, but I argue that STAMP should not only help to control the “beast”, but also explain “why and when the beast wants to get out from the cage”.  I will take a risk of classifying such symptoms into three categories:

(1) external symptoms: symptoms that emerge as the result of external socio-technical environment (including change and adaptation of new safety constrains) that forces the system to adapt and lead to maladaptive changes. This can be categorized as expected and inevitable results if and when erroneous processes influence the system and its environment.

(2) interface symptoms: symptoms that emerge as the result of interaction between the system and its operator, the system and other systems. This is the closest we can get to the old way “feeling the vibration” the system and being able to get feedback from it.

(3) internal behavioral symptoms: unintended or unforeseen symptoms that can be best identified by the designer or peer-reviewers of the system. My intuition, tells me that this is the most difficult symptom to indentify and categorize (and decompose), which can be done only through extensive testing of the system.