4.7 Article

Using model checking to help discover mode confusions and other automation surprises

Journal

RELIABILITY ENGINEERING & SYSTEM SAFETY
Volume 75, Issue 2, Pages 167-177

Publisher

ELSEVIER SCI LTD
DOI: 10.1016/S0951-8320(01)00092-8

Keywords

automation surprise; mode confusion; model checking; formal methods; mental model; human-computer interaction

Ask authors/readers for more resources

Automation surprises occur when an automated system behaves differently than its operator expects. If the actual system behavior and the operator's 'mental model' are both described as finite state transition systems, then mechanized techniques known as 'model checking' can be used automatically to discover any scenarios that cause the behaviors of the two descriptions to diverge from one another. These scenarios identify potential surprises and pinpoint areas where design changes, or revisions to training materials or procedures, should be considered. The mental models can be suggested by human factors experts, or can be derived from training materials, or can express simple requirements for 'consistent' behavior. The approach is demonstrated by applying the Muro state exploration system to a 'kill-the-capture' surprise in the MD-88 autopilot. This approach does not supplant the contributions of those working in human factors and aviation psychology, but rather provides them with a tool to examine properties of their models using mechanized calculation. These calculations can be used to explore the consequences of alternative designs and cues, and of systematic operator error, and to assess the cognitive complexity of designs. The description of model checking is tutorial and is hoped to be accessible to those from the human factors community to whom this technology may be new. (C) 2002 Published by Elsevier Science Ltd.

Authors

I am an author on this paper
Click your name to claim this paper and add it to your profile.

Reviews

Primary Rating

4.7
Not enough ratings

Secondary Ratings

Novelty
-
Significance
-
Scientific rigor
-
Rate this paper

Recommended

No Data Available
No Data Available