'I’ve become isolated': the aftermath of near-doomed QF72
smh.com.au
smh.com.au
Pilots properly responded with thrust reduction to decrease engine stress, but unknown to them, the MD-81 had been fitted with Automatic Thrust Restoration[2] that kept increasing thrust to maintain normal climb setting. Increased thrust led to surging of the left engine too, until both engines failed at 78 seconds.
The aircraft crashed into a field and broke into three parts (everyone survived).[3]
Post-crash analysis determined that reduced thrust would have kept both engines operational, and maintained thrust would've lead to failure of only the right engine, which would have allowed to keep flying and perform a safe landing. ATR increased thrust and caused both engines to fail.
Captain of the flight retired from flying, saying that he lost trust in airplanes.
[1] https://en.wikipedia.org/wiki/Scandinavian_Airlines_Flight_7...
[2] https://patents.justia.com/patent/4662171
[3] https://i.imgur.com/k4q0WMm.png and https://i.imgur.com/KzPNhsU.jpg
Airline fatalities decreased 10-fold in the last 30 years, while total miles travelled increased by the same factor. Flying today is 100x safer now, and I don't quite understand peoples' fetish with human control.
Airline travel certainly has become safer, at least on a per-mile basis, but 100x safer? That's fantasy.
1. https://en.wikipedia.org/wiki/Aviation_accidents_and_inciden... 2. https://www.bts.gov/content/us-passenger-miles
https://en.wikipedia.org/wiki/Aviation_safety#/media/File:19...
In any case, the larger point should be undeniably clear. Air travel is getting safer and safer.
Tesla has some of these things. It beeps at you when it detects you are about to hit cars in front of you. If you are in traffic and it doesn't see that your lane will be going around say a stopped car in a different lane in traffic you can easily override it. Similarly for the driver can override the autopilot, and because it has a kind of tactile feeling when you use the steering wheel to override the self-driving. Still it's far far from perfect, current evidence being the front end crashes into immobile barriers. But they have these notions built in of feedback, control, override. I expect every self-driving vehicle has something different in how they handle these things. Eventually we'll have standards across car lines. I bet planes are all different with all those amazingly huge number of controls the pilot has to understand.
Furthermore, you don't know that it's software that's improving the safety of flights, it could be changes in procedures and training.
"For a pilot, loss of control is the ultimate threat. It's our job to control the aircraft, and if computers and their software, by design, can remove that functionality from the pilot, then nothing good is going to come out of that."
I've flown an F-16 where the fly by wire system won't let you over G the jet. So, I think some level of automation is good in that regard. But, it's very subtle and you feel in control at all times. I would never fly an aircraft that would actively take over control of the aircraft... because the automation messes up all the time.
- Horrible examples of automation going wrong, hard to design and failing easily.
- Autonomous app-based air taxis are coming together with automated urban air traffic control (Uber and others). Market estimated to be worth €1.5 trillion by Morgan Stanley analysis.
What's your take?
Maybe some kind of augmented reality that lets you land in true 0 visibility, or automation that lets us reduce spacing on approach. Think things that improve safety, reliability, and ops tempo, therefore profits.
But, the stakes are just too high to ever remove a human override, though, imo.
Even if a pilot is not completely useless and we value a human life at infinity, at some point having a pilot on board is not worth it. If a pilot can save the plane in less than 1/<number of passengers and non-pilot crew> of situations that would have ended in a fatal crash without them, we lose more pilots than we save non-pilots.
Also, it's possible that an autopilot can handle a situation but the pilot erroneously overrides it and crashes.
Those are a bad idea, independent of automation. At least until 100% of our energy is carbon-free.
And they're generally not going to land on rooftops either. A roof has to be designed with a helipad from the start. It's tough to retrofit one later due to structural issues, and use of roof space for antennas and machinery.
In my eyes the problem isn't so much that the systems are overly invasive, it's more that the failure modes of automation aren't well understood or signalled and cannot always be remedied.
Should I read this to mean you don't support AGCAS?
I think this is part of the reason people who like free software defend it almost religiously: they understand the dangerous of the authors and users of software being legally segregated.
Yes, aviation-ignorant editor, he really did mean to write attitude before you changed it to altitude.
Apt and ironic, given the circumstances
And the loss is the direct result of badly designed and badly implemented software automation.
Yet, software continues to eat everything, and large swaths of the industry praise a "move fast and break things" attitude about it. Even life-critical industries consider it OK to make airframe changes rendering a passenger aircraft unstable in parts of the performance envelope and patch it over with software supposedly compensating for those new flight characteristics, dependent on a single faulty sensor and no input sanity checking. After 346 people die in two incidents, they reconsider, only after forced by regulators.
This <it'll be OK, just patch it> attitude needs to be eradicated.
Really? From every account I've read, it depended entirely upon a single flight attitude sensor, and did no sanity checking whatsoever against other data, sensors, or inputs. There was an extra-cost-option for a second AOA sensor and an obscure cockpit light that would tell when the two AOA sensors disagreed, but those were not installed in either of the crashed airplanes.
It seems at the very least, such a critical system should have three primary sensors with full algorithms to check for disagreement, plus checking against the artificial horizon display inputs, airspeed, throttle, etc. to determine if they were actually in the part of the envelope where the MCAS would be useful.
So, unless it there are a number of checks & features that have been written in no account I've read, it's really bad design -- software.
Moreover, they could have decided to NOT design the airframe so that it would have deadly characteristics requiring a software patch to hide.
Again, really bad design - airframe.
Or, they could have decided that this is a potential critical and deadly failure mode which properly required extra training and a new Type Rating for pilots to fly the new aircraft. But instead they decided to try to bury it in the same type and an hour of iPad training, so that their airline customers would see the a lower overall cost of the new model.
Again, really bad design -- process.
Perhaps you can point me to some documentation I'm missing here, but this is what I've consistently gathered from the substantial number of articles I've read.
The reason Qantas Flight 72 only nose-dived twice, if I'm understanding the incident report correctly, is that each nose-dive caused the internal monitoring to fail and that part of the flight control computer responsible to be faulted out for the rest of the flight. After the second nose dive, all three of the primary flight computers had faulted, disabling the affected flight control features.
I hit a dog with my car and had flashbacks and intrusive thoughts about it for about three weeks.
"One thing is certain: the computers blocked my control inputs. For a pilot, loss of control is the ultimate threat. It's our job to control the aircraft, and if computers and their software, by design, can remove that functionality from the pilot, then nothing good is going to come out of that."
This is not real supervision, automatic systems must be designed to relinquish control before the situation is dangerous.
https://en.wikipedia.org/wiki/XL_Airways_Germany_Flight_888T
which reads like something right out of Perrow's "Normal Accidents" book in that it was an incredible confluence of hardware and human failures.
The regulators were trying to test the envelope protection system under stressful conditions and it turned out that the AoA vanes were non-functioning which contributed to the crash.
Thus it is relevant to the later 737 MAX crashes.
It is a "normal accident" because of the human factors: e.g. no flight plan filed because it was a test flight, regulators ordering the pilots to defy the air traffic controllers, regulators ordering pilots to go forward with a test they didn't want to do... And on top of it all a maintenance error.
Of course for every QF72 there are probably a bunch of injuries and deaths attributed to pilot error, which is why the computers are there, but at some point there has to be a middle ground. If you defer control to the computers in all situations, what's the point of the pilots?
If these computers and their software are smart enough to make life critical decisions, why can't they make the most important decision of all: should I stop?
For example, a sudden encounter with wind shear might push an otherwise well-trimmed aircraft into just that kind of move, and the FBW computer would be expected to compensate.
In this case, the "eyes and ears" of flight computers failed in ways that were unknown to designers and thus bypassed safety measures against their failure.
There was still an extremely competent ready and able pilot at the helm who should've been able to disengage the auto-pilot features of a plane with faulty sensors, take control and land safely but couldn't. Seems like ridiculous failure mode to be honest.
It also did give control back to the pilots: after the second nose-down, the control law reverted as designed to 'alternate' (a degraded state) which removed the part of the envelope protection causing the nose downs. And the pilots also correctly switched to the backup ADIRU, which disconnected the faulty data from (most of) the aircraft's systems.
For me, the interesting part of the article is the severe consequences for the pilot's mental health. A serious, but non-catastrophic problem occurs, and is skillfully dealt with by the crew (whose training is designed for exactly this). There are a number of injuries, but none are life-threatening. But the pilot's sense of responsibility, the feeling that it could all have been much worse, and a loss of faith in the aircraft, results in long term disability despite the 'successful' result.
"I've learnt from these events, but none have generated the body response or trauma that this one has on October 7, 2008. This scenario involving computers, denial of control and potential mass casualties is at a different level. It seems we've survived a science-fiction scenario, a No Man's Land of automation failure on an unprecedented scale."
Also, the Airbus autopilot could be disabled. The 737 MAX MCAS system couldn't be; all they could disable was all electronic control over the trim motors, which shut off MCAS but also shut off the system they needed to be able to recover the trim entirely.
Is it a Similar situation to coal and nuclear power? Better the devil you know.
It's important to not place faith in things.
In the more recent cases, with 100% death counts, I read unsubtle accusations at third world pilots not knowing how to fly planes
At the end of the article it mentions that the article is mostly an extract from the Caption's book. Which is coming out in roughly two weeks time.