The Human Factor – the 2009 crash of Air France Flight 447
vanityfair.com
vanityfair.com
[1] http://www.bea.aero/en/enquetes/flight.af.447/rapport.final....
A video from CBS shows a very eye-opening demonstration of tactile feedback the mechanical linkage can provide. It's a feedback loop that the non-flying pilot can't ignore.
http://youtu.be/kERSSRJant0?t=3m9s
However, it doesn't mean there aren't other pilots who prefer fly-by-wire joysticks and can list (safety) advantages over mechanical linkages.
Remember that it's easy to criticize such decisions in hindsight, but the decision was taken for a reason, and approved by government agencies at the time.
Averaging inputs in this way interferes with that in such an obvious fashion that it's really inexcusable. I really don't believe this is purely a hindsight thing. Sure, they made this decision for a reason and it was approved my government agencies at the time. However, that doesn't mean I can't think those reasons don't override the fundamental principle of always knowing who's in control of the airplane, and that the government agencies were wrong to approve it.
This crash is fairly amazing in how basic a failure it was. The two main things that went wrong (confusion over who was controlling the airplane, and not putting the nose down in a stall) are both extremely basic things. It's the computing equivalent of not checking to see if your machine is plugged in, except that people die because you forget to check.
It seems that training was deficient when it came to the basics, and I also think that the non-linked averaged controls are completely inexcusable and should be eliminated.
1. Have a switch that determines "who is flying the airplane" i.e. which controls are active
2. Implement some kind of feedback even if it's not direct mechanical such as moving both joysticks with a little bit of servo force: not enough to overpower one's hand but enough for the non-flying folks in the cockpit to see
3. Have an "averaging error" sound, light up, whatever if the two joysticks have inputs which are too far from one another to make sense. This isn't great because you still have to pick one joystick to have priority and that might be non-intuitive to pilots
Ultimately I think the biggest problem with the Airbus design is that it adds an extra level of indirection between pilot's inputs and airplane course. In most aircraft if you let the controls return to "neutral" the airplane will slowly return to neutral as well. In an Airbus if you let the controls return to neutral the airplane just continues to do whatever it was you were doing; if you're climbing it continues to climb; turning it continues to turn; etc.
http://www.apollosoftware.com/products/flybywire/flybywire_e...
It seems to me that this is how the problem occurred; someone yanked back on the joystick and nobody else noticed it and then it returned to neutral. But the airplane continued to try and hold attitude up. In a Boeing airplane that wouldn't be a few seconds of joystick back, it'd be a continuous holding of the yoke towards the pilots making it very obvious what was happening.
The pilots shouldn't have an integrator between them and the airplane because it makes the airplane handle in very non-intuitive ways to the first 80 or so years of aviation as well as basically all the smaller planes that pilots train on prior to flying big jets.
Now, there's no reason you can't have a full fly-by-wire system with all the conveniences and safety advantages that implies along with such a system. The two controls could be mechanically linked before feeding into the system, or they could be completely mechanically independent and then use a force feedback system to link the electronically.
There are interesting arguments on both sides of the Airbus fly-by-wire system, but it's ultimately a separate question.
Certifying and retrofitting force feedback controls on existing Airbus planes will be very expensive, and since the current safety record is so good, it's probably not going to happen unless another accident happens attributable to the same design decision.
AFAIK they could see how the controls were manipulated on the FDR, and I think both pilots actually applied nose-up inputs for some time.
Although the failure was basic, and they certainly lacked hands-on high altitude flying experience, you have to consider that the situation they got themselves into became very confusing, to the point where they likely didn't trust any instruments or warnings they got.
The right initial reaction to the situation would _not_ have been to push the nose down, but to add power and a _slight_ nose up input.
However, pulling back on the stick would have been safe to do in normal law, so I think it's very likely that the most inexperienced pilot thought he still had stall protection, and that combined with control inputs that would only be appropriate in lower speed settings caused the initial sequence of events.
Where it becomes completely ridiculous is when they're losing altitude at a rapid rate despite having the stick pulled all the way back. You are stalling. That should have been abundantly clear at that point. And then, when stalling, holding the stick back is the last thing you want to do.
Given the confusion and sensor trouble, stalling the plane is understandable. Keeping it stalled all the way down to the ocean is what is crazy. Designing the control system so that one pilot can't even know that the other pilot is keeping the plane stalled is likewise crazy.
The fact that the stall warning stopped due to low airspeed and came on again when they pushed the nose forward (because airspeeds became available again and the stall warning started working) only made the problem worse, and can explain why they completely lost the trust in the instruments.
In the end, there's a host of factors and bad design decisions that led up to the accident, and on top of that poor high altitude training.
That in itself doesn't explain the averaging design choice, but it does explain why they decided on the particular fly-by-wire design they have, where in normal law the stick inputs don't have a 1-to-1 correspondance with control surface deflections (like you have on a small airplane for instance).
Hence I'd say this is much more a design issue than it is pilot error, as both senior pilots were advising the right course but the interface design allowed the inexperienced pilot to silently override control. Yes, this junior pilot probably had too little training and reacted terribly; but what's the point of having multiple pilots if they apparently don't add any additional safety because coordination amongst them has to rely on non-technical means instead of being facilitated by intuitive interface design? Where's the iPhone revolution in planes?
That's funny. I thought it was because they don't get sufficient stall training. The input blending would certainly be a contributing factor, but they would have made it if the guy did exactly nothing instead of the wrong thing. This goes along with my feeling about the SF accident where the (was it Korean?) pilots don't generally fly planes but rely on the automation.
The pilots got plenty of stall training, but mostly in take-off / landing scenarios (which is realistically when you're most likely to experience a stall).
This is a bit douchy, no? Or is it common practice?
My point is that if we let teenagers drive fully automated cars,they might find themselves in a truly critical situation they will not be able to get out of, due to their lack of experience and training. People will then say - if they were experienced drivers, and if not for all this automation, they would be able to get out of this situation. Because that's exactly what this article is saying - if the aircraft wasn't as automated, and the pilots had a lot more experience actually flying, they would have realised that the plane was, in fact, stalling, and maybe would have saved it. That does not change the fact that automation, overall, saves more lives than it takes.
Also, don't forget that you can't have redundant systems for everything, unless you want to be driving a tank. Imagine driving an automatic car and then some bird poo falls on the laser-sensor and the car literally can't see anymore(I am exaggerating, but the car can surely be blinded by something, the laser sensor on top can become dirty or damaged). The best it could do is apply full breaking force,but if you are on a motorway and there is an 18-wheeler behind you it could be a fatal idea. Again - the autopilot can't continue, it has to give control back to the driver - and the driver might crash the car if they are not experienced enough.
Further, these airplanes are kept fairly widely separated in altitude and the skies are rather sparse, so collisions are something to be avoided but it's not all that hard.
In a car though, the safety margins are much, much lower. Because there are vehicles everywhere the time to collision is probably measured in milliseconds rather than minutes. Because there are no redundant systems to ensure safety once the car "realizes" it can't control itself anymore you're prettymuch hosed. Are any of the regulations on self-driving cars taking this into account and at least mandating that the control system has sufficient battery back-up for it to at least TRY and gracefully de-energize the vehicle?
Once cars become self-driving you can't really rely on humans to suddenly jump in and take the wheel and save the day. They're going to be asleep or not paying attention or watching a movie or whatever. And if they are going to be required to watch the road paying 100% attention to what they car is doing, what's the advantage of having the car drive itself? You're in a constant battle of "what's the car going to do?!" which is actually more tiring than just driving it yourself.
An easy solution might require that self-driving cars only self-drive in lanes which are adjacent to a shoulder of sufficient width giving the car an out that requires only minimal controls, so basically far-right or far-left lanes on a freeway.
A self-driving car might also need to have multiple, redundant regenerative braking systems so that it can power itself enough to power the controls to safely guide the car to a stop. But then it also needs multiple control systems so that if one of those fails, the car isn't out of control.
The economics of having an autopilot on an airliner (which costs many millions of dollars) and a car (95% of which cost less than $100k) are really, really different.
But in this one specific area, of how to handle failures and returning control to the human, I think cars have the advantage. It just doesn't compensate for all the other places where a car autopilot is vastly more difficult.
I guess my assumption on when the car tells a human being to take control are in a few circumstances:
1. it loses the ability to control a driving input that ostensibly the driver still has the ability to control (steering servo fails)
2. it loses the ability to control a driving input that the driver also can't control (tire blowout)
3. it doesn't know what to do or can't make a decision so the driver is the tiebreaker (crash imminent, road disappears, brand new road with no map data, etc)
4. it loses a sensor input completely or starts getting data that it considers garbage and thus can't safely operate the vehicle (LIDAR or camera fails)
5. loss of power so that autopilot just straight up fails
I could probably think of some more scenarios but the point isn't to be exhaustive but illustrative.
So in some of these circumstances the car does have an opportunity to pull over and wake the driver up and say "hey you need to drive now" but in others, it's going to be split second.
If ALL the car failure modes resulted in the car pulling over and the driver taking back over at his/her leisure then I would 100% agree with you. But there clearly are failure modes where the driver is going to get put back in the control loop with little/no warning and be asked to make a decision perhaps faster than they can wake up and/or process the scene and catch up enough to decide well.
So basically what you have to do is make some kind of guarantee about "the car will never ask the driver to take over with less than 60 seconds of notice" or something like that. But the hardware cost to enable you to make that kind of guarantee is substantial; sensors, battery backups, autopilot systems, actuators, etc all in triplicate. And I don't know that you can do with just two because in the situation where you go from two to one you don't have any kind of ability to determine if one of the pieces of software is malfunctioning due to memory corruption.
Although the price of doing all this is going down drastically I suspect that it'll be a while before people are willing to pay enough to get the kind of redundancy they have in airplanes.
So what am I missing? I'm really curious.
For example, when the airspeed data was lost, the Airbus had to fall back to an alternate behavior which is part of what confused the pilots. In a car, you could skip that fallback and just go straight to "pull over and stop," but the airplane has to keep trying somehow. Similarly, the angle of attack went beyond the range the designers had anticipated, and the computer assumed that it was a bad reading. But it kept going, because it had to. In a car, if there's a bad reading, it can again just go straight to "pull over and stop".
Big failures will always mean big problems, but what's striking about AF447 is that it was such small failures. And when it comes to small failures, I think a car is in a much better position to deal with it because it can just cut the gordian knot.
I think the disconnect is that I see that sensor as hugely important. If you were in a car and it lost the ability to sense speed via the speedometer, how would it pull over and stop? How would it know how quickly to steer towards the shoulder? How would it know when it had stopped?
When airline autopilots were developed you didn't have a dozen ways to sense speed. With a car you have the speedometer, GPS, probably some kind of estimates from LIDAR and vision, and the ability to integrate output from the accelerometers and feed all those into a kalman filter to make a really good model for the car's speed even if the more accurate methods fail. Certainly there are good odds it could perform well enough to move the car to the shoulder.
I guess I am less worried about those kinds of more minor failures and more worried about the kinds where humans are suddenly thrust back into the loop. On airplanes the pilots nearly always have a way to control the plane and plenty of time to react since they've got 5-30 minutes worth of glide.
In a car when something goes wrong you might well have vehicles on either side, in front and behind if it's heavy traffic. And in that case if the car finds itself asking for a human driver very suddenly who has to start making very good decisions faster than a human is capable of.
In my mind the "you can always pull over and stop" only works if you're assuming that the car is driving on an immaculately paved stretch of nearly or completely empty road.
This documentary about AF Flight 447 is the best I found so far: https://www.youtube.com/watch?v=TsgyBqlFixo
...including the last words of the pilots.
There is no (central) display indicating the current position of both control sticks.
There is no redundant system allowing the pilots to see their speed, even if the method used is inaccurate it would still be better than nothing (GPS, heated pitot tubes, ...) Same for the altimeter.
Flight recorders aren't designed to float and broadcast their position, or at least release a small beacon that would give rescue teams a general idea about where to search.
They are not designed to float, because there is no guarantee that the flight recorder will separate from the rest of the wreckage, but most importantly because accidents at cruise altitude are incredibly rare, it's the safest time of the flight - and you are very unlikely to be over the ocean in any other mode of flight. Even with airports close to the sea, a crash few km from the shore would not be difficult to locate.
And flight recorders have auxiliary batteries and actually broadcast their location for a month after the crash - the problem here was that no one had an idea where the plane crashed, something that's very,very improbable in its own right.
Off topic but how does the airplane know it's stalling if the airspeed indicators are not working?
Edit: Reading through the official investigation document:
"The angle of attack is the parameter that allows the stall warning to be triggered; if the angle of attack values become invalid, the warning stops. "
So like said in another comment - even with no valid speed values, the angle of attack can trigger a stall warning.
But apparently the airplane can still fly for a short time even at this crazily large angle. Therefore when the pilot did the right thing to reduce the angle, he triggered the stall warning again and completely got confused. I think this is a major design flaw in Airbus's system.
It raises an interesting point about instrumentation - it's easy to make a display that looks like a gauge, a needle, or whatever. But if the system behind the display can have some knowledge of whether it's getting good data or not, then really there is (at least) another dimension to the information. How do we represent that so that operators can make sound judgements in unfortunate circumstances?
As sibling replies mention, angle of attack is the key indicator. There's a critical angle where you're stalled if you go beyond it, and not stalled below it, regardless of airspeed.
The A330 has vanes which measure the airflow direction
http://aviation.stackexchange.com/questions/2094/how-does-an...
Light aircraft usually just have a metal flap on the leading wing edge which blows upward if the plane is angled up too much.
Edit: Having read the stackexchange explanation I think there is a big part of the reason for the crash right there. The warning system was operated by the computer taking data from the vanes and air speed indicators which gave weird results which surely confused the crew. Had the plane had a basic metal flap with switch and buzzer the crash may not have happened.
Also, the 330 is not equipped with pitot heaters? The military aircraft (simulators) that I've messed with will start to complain if you don't have the pitot heaters on, well before you ever leave the ground.
To me, as an experienced pilot, that says it all.
http://www.amazon.com/Field-Guide-Understanding-Human-Error/...
Fantastic read about the futility of placing blame on a single human in a catastrophe like this. It makes a strong case for why more automation often causes more work. Definitely worth checking out, Etsy has applied it to their engineering work by using it to facilitate blameless post mortems:
The automation may have created new dangers, but it probably reduced more common errors.