Cockpit crisis
www2.macleans.ca
www2.macleans.ca
One of the more dangerous things when operating a vehicle is cognitive overload; when shit goes wrong, a bunch of stuff tends to get dumped on you and you can't think fast enough to catch up. A way to let the airplane worry about itself for a minute while the pilots can catch up seems to be a decent way to address this side effect of being a conscious being instead of an automaton.
The jab about the unreliability of computers is just that; avionics software is on a much slower release schedule and has a much more fixed set of inputs than a web browser, allowing for a more thorough (or even formal) analysis of its behavior.
> “People say it’s impossible to stall an Airbus, right? It has stall-protection systems and it won’t allow you to exceed the maximum angle of attack where a stall would occur,” argues Paul Strachan, an Air Canada pilot who is the head of the company’s pilots’ union. “But that’s not true. If there’s ice on the wing, that whole detection system isn’t accurate to begin with. I would be pretty hesitant to get on a plane with no pilot.”
Flight control systems can be built to compensate for all sorts of failures[1] that would pose grave difficulty for human pilots, but nobody's really advocating for completely-autonomous passenger planes. The problem right now is that the autonomous systems to reduce pilot workload and improve safety have failure modes that tend to overload the pilots with information. A working, reliable "panic button" would definitely help pilots get back in front of the plane in an emergency situation, but so would fixing the information overload to allow pilots to prioritize important issues (pitot freezing up, speed indicators unreliable) over side effects (unreliable stall warning, alternate law activation).
I don't think it was confidence, just a semi-reflexive action (if too low, pull up) when there wasn't enough thrust or lift to manage that.
If the training was such that the appropriate response to any cognitive overload/panic situation was to mash the panic button and reason things out, it would save lives.
Even with only a few alarms, it's easy for inexperienced people to get panicked about something. But the claims of Sullenberger, the pilot who landed the plane in the Hudson river, are sobering.
http://www.businessinsider.com/capt-sullenberger-stop-cuttin...
That used to be true, and may be right now, but the trend is towards airlines accepting simulator time in lieu. The trouble with that is that simulators are subject to the same problem as any other complex input device: if you haven't foreseen the problem beforehand, you don't program the simulator to model it, and the pilot isn't trained to handle it. Experience can help that simulator time can't.
The recent high-pressure turbine blade failure on Qantas is a case in point where the pilots were overwhelmed with page after page of error faults, 145 of them if I remember correctly. If they hadn't been very fortunate to have two other senior captains in the cockpit with them, they would have had a great deal of trouble dealing with the information flow.
Personally, as a light aircraft pilot myself, I would not be comfortable with young airline pilots with only simulator experience. At least one of them needs to have a few thousand hours of hands-on-stick experience.
Worst case, add power, level out, and hopefully you'll be stable for a few minutes while the pilots catch up to the airplane.
That said, I'm not an aeronautical or control systems engineer, so this is just speculation.
Once you get to airliner altitudes (say, FL350 and above), the plane does not really want to fly anymore; there is only a narrow band of throttle / pitch inputs that will result in stable flight. You can see this in your favorite flight sim: take a Cessna 172 up to 4000ft and try crashing it. Turn off the engine, cross the controls, and pull the nose up until it stalls. Then release all the controls, and the thing goes back to flying normally with no input from you (and without an engine). Then try this again at 13,500ft in a thunderstorm and see what happens. You can even have engine power. The plane behaves very differently at its service ceiling.
Airspeed data is critical, which is why there were three redundant airspeed systems. Turns out, it wasn't enough.
At one point, they were at full thrust, nose-up, and climbing, yet in the heat of a storm of warnings, they failed to recognize that the airframe, engines, wings were all performing exactly as designed, aside from a panicking computer.
At that point they had completely lost situational awareness, and held the plane nose-up and falling until it contacted the water. If they had been able to 'step back' and look at the wider situation, they almost certainly should have been able to guesstimate some power settings, trim appropriately to lower the nose to recover to a normal flight attitude and hang on until they could trouble-shoot the frozen pitot tubes that had caused the air data computers to lose airspeed info.
Unfortunately, in a failure scenario, your most obvious sign of trouble is usually not a clear an unambiguous warning, but a perplexing disagreement between various data.
Your problem is 1) identifying this state 2) identifying a corrective / maintenance action and 3) executing on this. Hopefully before you run into a failure-to-maintain-sufficient-altitude or failure-to-maintain-core-integrity, or other appropriate sustainable operational mode.
Complex situation is complex.
Seems to me a fatal design flaw bordering on ridiculous, to create a user interface that is not displaying this critical piece of information.
> In the case of Flight 447, Air France’s pilots’ union has pointed a finger at Airbus by suggesting that the stall warning system on the A330 likely contributed to the doomed flight crew’s confusion by sounding only intermittently even though the plane remained in a stall the whole time.
> In the Air France crash, for example, investigators noted that the plane’s critical angle of attack “was not directly displayed to the pilots” [...]
Not only were they overloaded with useless noise, but critical information was either delivered in a confusing way, by design, or hidden from view...
They need UX people, badly.
Planes crash when a lot of things go wrong at once. In the case of the Colgan Air crash, the problem was not the stall. The problem was that the pilots were sleepy, confused, and under-trained. The stall was too much for them because they were in a state where they could panic, and they didn't have the training to stop panicing and start flying the plane. So they randomly poked the controls, and that didn't save the plane.
Take two training pilots on a full 8 hour's sleep, and the stall probably wouldn't have even happened. If it did, a "whoa" would have been exchanged and they might have gone around for another landing approach. But I don't think it would be a big deal, it's just some randomness that is par for the course when you are trying to float twenty tons of metal through the air.
It's like long division in multivar class. Some people can do it again given time but most people wouldn't be able to divide 1345 into 26 right off the bat.
To me, it seems ridiculous that pilots are unable to remember this stuff. Really. To recover from a stall, you ease down on the stick and alternatively apply power. Barring a deep-stall condition, it's really that simple. They even teach you that the most basic error in a stall condition is to pull back on the stick in a panic-stricken attempt at forcing the plane to gain altitude. I'm stupefied at these reports.
The systems were "reporting" alternating stall and overspeed warnings. So you have one system telling you to pull up to slow down and then another saying you are about to stall, the stall readings are invalid...the computer gives up and says you're on your own.
BTW, the AOA screen is not even visible, it's buried in a submenu of the main screen.
There were even situations where pushing forward was the wrong thing to do (although no longer, thank goodness). The 727 could enter a situation where the elevator itself was stalled from the main wing stall.
Modern heavies are about systems management and cockpit procedures. As someone below points out, if one system is telling you to pull up from overspeed, and another is telling you to push forward from stall, which do you believe? And, more importantly, how quickly can you trouble-shoot to find the correct action?
http://www.usatoday.com/news/washington/2009-05-13-buffalo-c...
I see this as a reoccurring theme in the next 100 years as we get self driving cars, automated food processing, intelligent machines automating everything. We gotta deal with this in a smart way, require by law "Kill computer" switch accessible and known by all operators, to get the computer to stop demanding its own way and just do what the human tells it to do.
Though we can't say we weren't warned, Hal saying he can't jeopardize the mission to Wall-E auto computer demanding it's own way over the will of the captain. Is there even a solution to this problem or are we doomed to be pets one day?