SearcharxivSearch

arXiv subjects

Jens Braband

Publications and source records attributed to Jens Braband.

9 recordsLinked to original sources

A Semi-quantitative Covid-19 Individual Risk Model

This paper introduces a new basic risk model that could also be utilized by Covid-19 warning apps a priori, before an action is performed. Today the common warning apps estimate risk a posteriori and give no advice on particular scenarios. The new model also has the advantage that the individual risks behind the decision-making process would be uniform (in contrast to some current regulations) and it could help to understand the risks better and could also help to reduce risks a priori. It could be easily implemented on a single app screen, needing only some individual preferences to be set and a handful of adjustments to the particular scenario that shall be assessed. The disadvantage as of any simplified semi-quantitative risk models is that calibration is not easy (as some calibration points may even contradict) and that cumulative effects are hard to integrate e. g. the joint effect of combined scenarios. But, in principle calibration is feasible and it may be a good decision to calibrate the model conservatively.

cs.SI

Risk Model of German Corona Warning App - Reloaded

In this paper we discuss the risk model of the German Corona Warning App (CWA) in two versions. Both are based on a general semi-quantitative risk approach that is not state of the art anymore and for some application domains even deprecated. However, it turns out that the CWA uses a much more limited model, that does not even assess risk, but relies only on one parameter, a weighted exposure time. It is shown that the CWA grossly underestimates even this parameter and so may reassure the users wrongly. As the CWA also has other systematic limitations and shortcomings it is advised not to rely on its results but rather on Covid testing and vaccination.

cs.SI

Statistical Assessment of Safety Levels of Railway Operators

Recently the European Union Agency for Railways (ERA) has received a mandate for 'the development of common safety methods for assessing the safety level and the safety performance of railway operators at national and Union level'. Currently, several methods are under development. It is of interest how a possible candidate would behave and what would be the advantages and disadvantages of a particular method. In this paper, we study a version of the procedure. On the one hand side we analyze it based on the theory of mathematical statistics. As a result, we present a statistically efficient method the rate-ratio test based on a quantity that has smaller variance than the quantity handled by the ERA. Then, we support the theoretical results with the help of a simple simulation study in order to estimate failure probabilities of the first and second kinds. We construct such alternative distributions which the decision procedure cannot distinguish. We will show that the use of procedures that are optimal in the sense of mathematical statistics combined with the use of a characteristics that has small spread, here the number of accidents, is advantageous.

stat.AP

Application of the Cox Regression Model for Analysis of Railway Safety Performance

The assessment of in-service safety performance is an important task, not only in railways. For example it is important to identify deviations early, in particular possible deterioration of safety performance, so that corrective actions can be applied early. On the other hand the assessment should be fair and objective and rely on sound and proven statistical methods. A popular means for this task is trend analysis. This paper defines a model for trend analysis and compares different approaches, e. g. classical and Bayes approaches, on real data. The examples show that in particular for small sample sizes, e. g. when railway operators shall be assessed, the Bayesian prior may influence the results significantly.

stat.AP

On Safety Assessment of Artificial Intelligence

In this paper we discuss how systems with Artificial Intelligence (AI) can undergo safety assessment. This is relevant, if AI is used in safety related applications. Taking a deeper look into AI models, we show, that many models of artificial intelligence, in particular machine learning, are statistical models. Safety assessment would then have t o concentrate on the model that is used in AI, besides the normal assessment procedure. Part of the budget of dangerous random failures for the relevant safety integrity level needs to be used for the probabilistic faulty behavior of the AI system. We demonstrate our thoughts with a simple example and propose a research challenge that may be decisive for the use of AI in safety related systems.

cs.AI

Towards an IT Security Risk Assessment Framework for Railway Automation

Some recent incidents have shown that possibly the vulnerability of IT systems in railway automation has been underestimated. Fortunately, so far, almost only denial-of-service attacks were successful, but due to several trends, such as the use of commercial IT and communication systems or privatization, the threat potential could increase in the near future. However, up to now, no harmonized IT security risk assessment framework for railway automation exists. This paper defines an IT security risk assessment framework which aims to separate IT security and safety requirements as well as certification processes as far as possible. It builds on the well-known safety and approval processes from IEC 62425 and integrates IT security requirements based on the ISA99/IEC62443 standard series. While the detailed results are related to railway automation the general concepts are also applicable to other safety-critical application areas.

cs.CR

Why 2 times 2 ain't necessarily 4 - at least not in IT security risk assessment

Recently, a novel approach towards semi-quantitative IT security risk assessment has been proposed in the draft IEC 62443-3-2. This approach is analyzed from several different angles, e.g. embedding into the overall standard series, semantic and methodological aspects. As a result, several systematic flaws in the approach are exposed. As a way forward, an alternative approach is proposed which blends together semi-quantitative risk assessment as well as threat and risk analysis.

cs.CR

Basic requirements for proven-in-use arguments

Proven-in-use arguments are needed when pre-developed products with an in-service history are to be used in different environments than those they were originally developed for. A product may include software modules or may be stand-alone integrated hardware and software modules.The topic itself is not new, but most recent approaches have been based on elementary probability such as urn models which lead to very restrictive requirements for the system or software to which it has been applied. The aim of this paper is to base the argumentation on a general probabilistic model based on Grigelionis or Palm Khintchine theorems, so that the results can be applied to a very general class of products without unnecessary limitations. The advantage of such an approach is also that the same requirements hold for a broad class of products.

cs.SE

Propagation of Uncertainty in Risk Analysis and Safety Integrity Level Composition

In many risk analyses the results are only given as mean values and often the input data are also mean values. However the required accuracy of the result is often an interval of values e. g. for the derivation of a Safety Integrity Level (SIL). In this paper we reason what should be the accuracy of the input data of risk analyses if a particular certainty of the result is demanded. Also the backside of the coin, the SIL composition is discussed. The results show that common methods for risk analysis are faulty and that SIL allocation by a kind of SIL calculus seems infeasible without additional requirements on the composed components. A justification of a common practice for parameter scaling in well-constructed semi-quantitative risk analysis is also provided.

stat.OT