Planes Without Pilots
nytimes.com
nytimes.com
Here is Patrick Smith's (formerly of Salon's Ask the Pilot column) comment from the NYT article:
>>> I'm an airline pilot, air travel blogger and author. This pilotless planes discussion is something that comes up all the time, and it never fails to raise my blood pressure.
One of the main issues is that people greatly misunderstand the capabilities of EXISTING cockpit automation, and have a vastly exaggerated sense of what it can do -- the result of articles similar to this one, which take at face value the claims of researchers, aerospace academics and tech aficionados who often have little sense of the operational realities of commercial flying.
Over and over and over we hear about how "automatic" planes are. Yet in truth flying remains a very hands-on operation subject to tremendous amounts of pilot input. It's perhaps a different KIND of input than in the old days: instead of gripping the steering yoke as would've been the case in the 1930s, you're working the various autoflight components, flight management system, etc. But the automation only does what the pilots TELL it to do: what, when, where and how. The other day I worked a flight up from the Caribbean. We had bad weather the whole way, a holding pattern, and had to fly a low-visibility Cat-2 approach. The cockpit was so busy that after we landed my voice was hoarse. Now imagine somebody dealing with the complexities of such a flight from a room thousands of miles away, with dozens of other planes stacked up.
Patrick Smith Boston
The more automation there is, the more edge cases and failure modes there will be, and another danger is the complacency it can encourage: the less often pilots have to manually fly the plane, the more likely it is they'll forget how to do it when they really need to.
How did the pilots know the system was incorrect in its assessment that the aircraft was stalling? Chances are there is some kind of electronic sensor that could provide the same information to the system.
While the pilots in the Air France plane crashed off the coast of Brazil because they trusted the instruments - the way a computer would behave, which you think is so trustworthy - there were other pilots who dealt with the same wrong sensory input and determined that the best course of action was to maintain flight principles...and not stall.
To trust in sensors and electronics in the way you describe would get a lot more people killed. I dislike this prospect very much.
they trusted the instruments - the way a computer would behave
Computers behave however we make them behave. They certainly don't need to trust the instruments if we program them not to.
And that interpretation of the Air France Flight 447 is dubious to me. The instruments told the pilots what was happening (the stalling alarm sounded for almost a full minute) and they apparently ignored it, because they didn't understood how it worked - that it would stop sounding when airspeed was low enough -, not because it was faulty.
I dislike how bad humans are already at judgement, both in cars and aircraft. The sooner we automate their jobs away, the better.
If a human can recognize bad sensor input, algorithms can as well, and those algorithms can deployed fleet-wide after a test/release cycle.
As far as I know, this crash was caused by erroneous human intervention. An (inexperienced) co-pilot was hanging on the flight joystick near constantly, unseen by the others on the flight-deck
https://en.wikipedia.org/wiki/Air_France_Flight_447#Final_re...
It is however a great goal, one which spells safer, faster, and consecutive safer technology with every step. Modern cars already has some forms of brake systems which can take control away from the driver during a crash-like situation, so the same concept for planes could be applied if it can be made safe enough. We also have kill-switches in cars which can be triggered remotely, so I could easily see a similar system be implemented which locks a plane into auto-pilot with a per-determined height and GPS direction.
Neither will replace pilots overnight, so they continue having low blood pressure and know that they still got a job tomorrow. Flying in bad weather, imperfect position technology, security, and complex traffic is going to take a long time to solve.
[0] http://www.sailingmates.com/your-gps-can-kill-you/
[1] http://www.yachting.org.au/sport-services/safety/major-incid...
Actually replacing all cars with driverless cars is a much safer bet , but the key is that they would all have to be replaced simultaneously.
There is no reason to replace every car at once, except that it would save more bad drivers from themselves.
Not quite. Too much automation leads to bored humans who aren't used to doing things themselves. If they then have to take over in an emergency, it often doesn't go well since they haven't even been practicing under normal circumstances.
At some point, it's probably best to take the human out of the loop entirely (even in emergencies), but where that point is will depend not only on the task at hand, but also on the individual human.
I expect we're at the point where a computer can do a better job than a mediocre pilot.
For example, see Air France 447. It looks like it would have ended well if the pilots had ignored the emergency and let the autopilot deal with it. It also would have been fine if the pilots knew how to fly the plane with the automation turned off.
Sounds like lots of points of potential human error.
A lot of people are citing the frozen AOA sensors on the Airbus flight a few years ago as a reason that even a perfect AI would make mistakes, but why did that particular sensor cause the autopilot to drastically change approach? Shouldn't inputs from GPS, Altimeter, and gyroscopic sensors contraindicate the external AOA sensors?
What information did the pilots have that the computer system didn't to let them know to change the behavior? We all know about situations where the pilots intervened to prevent an issue, but are there opposing situations where the sensors indicated an issue that the pilots couldn't observe and they made an error?
What are the hard problems that are really stopping complete automation versus the problems that we have right now due to not expecting complete automation?
Humans are inherently more error prone than computers, once properly programmed and designed. AI and machines might not be better now, but they will be eventually. And the only way to get there is to start small and work our way up.
In my opinion, right now we're at the limit of safety provided by letting humans run things. We can't really make those systems more safe than they are right now. We need a paradigm shift.
Letting computers run the show is uncharted territory. Right now, AI pilots/drivers are in their infancy. Comparing an infant to a mature system is a short sighted comparison. You need to take the long view- what would these systems look like after a decade or two of iteration?
It's like not anyone is saying we should do this RIGHT NOW WITH NO GOING BACK! Of course not. Let's try it in drones. Let's try it in cargo planes. Let's try it in military planes. If it ever seems like it won't work, we can always change course.
But not even wanting to try??? Come on, that isn't in our DNA.
And therein lies the problem. HN commenters know how fragile technology is.
True, more or less.
> We need a paradigm shift.
Really? Perfect safety is a pipe dream, and the rule of diminishing returns applies here as everywhere else.
Compared to modern aviation, the early days were just chock-full of accidents and incidents, because we hadn't encountered the 90% cases in order to solve them. Happily, we've solved those cases and more, which is how we come to have the luxury of confusing edge and corner cases, like deliberate CFIT (e.g. Germanwings 9525), with major safety issues.
Introducing full-on, pilotless cockpit automation is going to have the same high incident rate that early aviation did, for the same reasons -- we just don't know enough about the problem domain to account for the 90% cases, so we're going to have to see them fall out of the sky and hit the ground before we know how to solve them.
And, of course, there's also the fact that pilotless aviation can't actually solve all the edge and corner cases of piloted aviation, but only some of them. It'd make deliberate CFIT a thing of the past, sure! But deliberate CFIT, and things like it, aren't the only reasons why a commercial aircraft falls out of the sky. Sometimes it's maintenance error; sometimes it's equipment failure; sometimes we don't even know what happened. Pilotless aviation won't address all of these cases.
Eventually, I don't doubt, we would achieve the same excellent safety record with pilotless aircraft that we see right now with piloted ones. The question boils down to whether, in order to address a subset of the corner cases in piloted aviation, it's worth accepting the costly process of working out the 90% cases in pilotless aviation. I really do not think it's Luddism to regard the tradeoff there as not worth making.
For computers, the same isn't true, because you can inject a recorder between its sensors and its "brain" and then disconnect the sensors wholesale and feed input data directly using just software.
Let me put it this way: How about frame the comment around UAVs / drones - once the genuis-level programmers and designers can get a drone carry a raw chicken egg from Atlanta to Boston without breaking it, then we can talk about what long-view implications might be.
I mean, there have been decades of development trying to advance safety. People are already trying. It's not being a Luddite to put forward that the human brain is still a better pilot than a program.
So, because a human brain is better now, we should ignore the possibilities of any other path? We should simply give up working on flying/driving AI because in its current state, in its infancy, it isn't as good? That is an absurd view and that is what I would describe as Luddite.
Your quip just inspired a wonderfully bad story idea: North Korean agents steal a DNA sample from Elon Musk, and infuse their leader with his DNA. In a short time, changing him into Kim Jong Elon. North Korea becomes a futuristic place with Hyperloops and self driving cars. But is this shiny new wonderland all that it's cracked up to be? (Finally, a story so implausible, even Seth Rogen wouldn't open the script!)
Why would you even make this software accessible from the ground?
On the plane, you replace the pilot with software that does the pilot's job. Built into it, you have a bunch of rules, such as don't fly out of range of a place to land, don't fly into terrain, don't fly into other aircraft, etc.. All these safety rules are fixed and can only be modified by engineers on the ground.
The only orders that the plane receives from the ground are fly from here, to there at altitude X. If terrorists hack air traffic control and send all aircraft out to sea, the planes will detect they don't have sufficient fuel for the journey, and will turn back. If the planes detect they're flying too close to other aircraft, they will turn away. All terrorists would be able to do in this situation, is cost a lot of time and money.
[1] http://en.wikipedia.org/wiki/American_Airlines_Flight_587
Don't some pilots carry guns?
100 ways to kill someone with a ballpoint pen?
http://www.al-vimh.net/2011/05/100-ways-to-kill-with-a-ballp...
Why do you assume that the requirements for the software will be set by safety-minded engineers, rather than by politicians?
I can also think of attack vectors even with your constraints. Tell all planes in a region to fly to a particular airport. Each plane individually calculates that it has enough fuel, so does so. But this doesn't account for the overloaded airport. Even with fuel contingency to fly to a nearby backup airport, I'm sure there's a number beyond which this will not be possible (since all available backup airports would get overloaded too, etc).
Redundancy.
If something goes wrong with your software, you want a backup. So you either keep a pilot in the cockpit like the article mentions, or you give up all hope of recovering from the unexpected technical malfunction. The problem is, the wort case scenarios where there's value in having both a pilot and co-pilot on-board likely cannot be programmed against. Sully did a great job landing in the Hudson river, but he had a co-pilot's help. Would a solo pilot unaccustomed to doing much in the cockpit have been as successful alone? Impossible to day.
And if the aircraft detects something is wrong, it could alert the ground, and then it could be flown remotely by a specially trained group of pilots and engineers who do nothing but practice controlling aircraft in trouble, or actually fly aircraft that are in trouble.
True for Airbus, (mostly) not for Boeing -- the first Boeing product with FBW is the 777, and it goes well out of its way to provide control feedback similar to a non-FBW system.
And FBW equipment is hardly a panacea. You might consider looking closely at Air France 447, which crashed with the loss of all souls aboard as a direct result of its FBW system not providing realistic feedback. In a non-FBW aircraft, or even in a 777, it would not have been possible for an inexperienced copilot to stall the aircraft all the way from cruise altitude to impact, without anyone else in the cockpit being aware of what was going on.
Remote control isn't a panacea, either. What happens when that system is also compromised by whatever mishap has the aircraft in trouble to begin with? With a pilot on board, it's possible at least some of those aboard the aircraft might survive. With an empty cockpit and an R/C remote, everyone on board is almost certainly going to die.
Also, you want somebody to talk to ATC, reroute the plane when the weather changes, guide it in land, etc. Computers are still not good enough on those tasks.
I get the impression that we'll be swapping low frequency incidents that kill hundreds with even lower frequency incidents that kill magnitudes more instead. But the frequency will be so low that we'll pretend it doesn't exist and slowly cut down on safeguards and failsafe mechanisms until the first corresponding catastrophic incident occurs.
if they wanted to kill more people the plane would never leave the ground, likely you don't need a plane at all, those luggage areas are very crowded at peak hours
You could have this. But what are the chances that this will happen in practice, instead of a general reduction in this kind of measure in the interests of cost-cutting? Humans are notoriously bad in assessing risk for unlikely events. If an accident hasn't happened, then this tends to become a justification to compromise and cut costs even when the sample size is too small.
A good example of where, even the highest level of automation in an aircraft, failed to assist in an emergency was Qantas Flight 32 [1]. A physical failure on the plane caused sensor and control failures, something rendering AI almost completely useless. Admittedly, humans can also have failures and this has lead to many crashes before, however humans have also used exemplary skill, experience, and abstract problem solving to correct mechanical failures in aeroplanes countless other times.
If the AI would crash the plane one time in a thousand, and the pilot would intentionally crash the plane one time in a million, then this system reduces risk to one in a billion.
It helps against terrorists too. They have to disable almost the entire crew at once, or they'll have a nice leisurely ride to a waiting SWAT team.
But I'd be happy relying on the steep odds against hardware failure happening on the same flight as human attack, as long as we can keep those variables reasonably independent.
...and no reason not to murder the entire passsenger load on the way there, save possibly to have hostages once the aircraft's on the ground. I really don't think you have thought this all the way through.
It's also a better situation by far than letting them crash the plane into a building, and if the system is known to exist it's a deterrent against hijacking planes in the first place. And if there's a struggle on board, it's less likely that the struggle will cause a crash.
Schrecklichkeit, maybe?
Technically it's already possible. It's a lot easier than autonomous cars, as all the technology is already in place and less other human-beings that could interfere the system. In a few years, commercial airplanes will probably be like the US combat drones that fly autonomously in Middle East/Africa while being supervised from Las Vegas.
But you are right, that with AI other issues surface. An accident of the A320 in late 2014:
On 5 November 2014, Lufthansa Flight 1829, an Airbus A321 was flying from Bilbao to Munich when the aircraft, while on autopilot, lowered the nose into a descent reaching 4000 fpm. The uncommanded pitch-down was caused by two angle of attack sensors that were jammed in their positions, causing the fly by wire protection to believe the aircraft entered a stall while it climbed through FL310. The Alpha Protection activated, forcing the aircraft to pitch down, which could not be corrected even by full stick input. The crew disconnected the related Air Data Units and were able to recover the aircraft. The event was also reported in the German press several days before the Germanwings crash. The German BFU (Aircraft Accident Investigation Bureau) reported on the incident on 17 March 2015 in a Bulletin publishing the flight data recorder and pitch control data in English and German. As a result of this incident an Airworthiness Directive made mandatory the Aircraft Flight Manual amended by the procedure the manufacturer had described in the FOT and the OEB and a subsequent information of flight crews prior to the next flight. EASA issued a similar Airworthiness Directive for the aircraft types A330/340. -- http://en.wikipedia.org/wiki/Accidents_and_incidents_involvi...
At first the Germanwings Flight 9525 sounded very similary to the Lufthansa Flight 1829. There were speculation that the same issue happened again, but then they found the voice recorder (co-pilot...). Germanwings Flight 9525 was an Airbus A320-200: http://en.wikipedia.org/wiki/Germanwings_Flight_9525
"In this scenario, a ground controller might operate as a dispatcher managing a dozen or more flights simultaneously. It would be possible for the ground controller to 'beam' into individual planes when needed and to land a plane remotely in the event that the pilot became incapacitated — or worse."
As I currently understand the procedures, the pilot and co-pilot of commercial aircraft alternate responsibility for the aircraft during their work-day. For example, if the pilot takes off on one flight, the co-pilot will perform the take-off on the next.
Removing the co-pilot from that alternation would significantly increase the workload of the pilot.
I can understand the point, but I don´t see that happening in some decades. Airplanes have a problem that automatic cars or trains don't have, you can not failsafe them with a "STOP EVERYTHING NOW & HERE" system. In a case of fire or any other big emergency or computer failure, you simply perform an emergency stop to a side and you are out of your self driving car in 10 sec (the worst could be that your bricked car is now creating a traffic jam), unfortunately that's not the case with an A320.
It´s true that we don´t manually fly the airplane most of the time, and that 80 or 90% of flights are mostly routine that could be automatized somehow. But there are certain days, certain flights, certain airports (and this can be the same Airport that yesterday was perfectly standard) were you need to make decisions that a computer can not make. When you start encountering big thunderstorms in the radar, and not a possible way out, short final wind-shear or other limit edge operation, strange behavior or malfunction of the on board computers, systems or instruments, corrupted or missing navigation or performance data (or flying to Russia were you can not trust , in other words, unexpected situations were there are not clear rules to apply, just your experience an understanding of the basics, and a bit of that Capt. Kirk essence somebody named in other comment.
You need a really powerful and independent AI to face the fuzzy decisions that need to be made in a weekly basis. This AI needs to have independent control over the flight computers and controls, independent artificial vision, independent navigation skills not related to the normal rute computer, and a way to know when to skip safety rules completely.
If you try to substitute it with a simple AI, you end with problems like the one that didn't make the general media but could have ended with a Lufthansa crashing on the Pyrenees this last November, if it hadn't been pilot intervention ( http://www.pprune.org/rumours-news/558483-iced-aoa-sensors-s... ). The failure was of a system that exists purely to prevent pilot error. This system almost sent the A320 in to the ground. Just because the pilots were at the cabin and disconnected the air data computers a tragedy was averted.
Unfortunately this happens often enough, but doesn't make the news. The A320 model is 30 years old, it had at the beginning a number of fatal accidents due to the same computers that were intended to improve safety (like http://en.wikipedia.org/wiki/Air_France_Flight_296 or http://en.wikipedia.org/wiki/Air_Inter_Flight_148 ), but we are still dealing with automatic errors like the one of the Lufthansa ( the angle of attack fins get locked and the computers think that you are in a stall, the auto correct the stall with a dive that you can not correct manually, you need to disconnect 2 of the 3 air data computers to disable this saving behavior). Of course there is also a whole lot of money to be lost in sales if a model is declared dangerous, so complex accidents tend to be attributed mainly to the pilots, after all they can no longer give their opinion after the crash.
If something, the tendency has gone too far in to automatizing the flight. Flying manually tends to be less and less part of the requirements of big carriers, getting to a dangerous point: in some countries in Asia piloting skills are almost non existent (Korea, Vietnam, China). In China for example (at least in a couple of Airlines where a number of friends are flying) flight officers are not even allowed to land or take off the airplane, that means that if the captain has a heart attack there is a hight probability of the plane crashing. Once this flight officers are promoted to captain, they'll have almost no manual skills for flying the airplane.
This doesn't mean that safety systems are not useful or necessary, they really are, and they must be improved and to help the safety of the operation, but they can not be an end in themselves.
Returning to making a plane pilot free, you may remove humans from the inside of the plane, but they are going to be designed, build, programed, operated and maintained by humans in a human environment. I don´t see how you are going to get rid of the human error factor any time soon even if you had the perfect AI right now. Remotely controlling or even assisting pilots is a big no no, way too easy to perform a huge attack of docens of planes at a time, using just a laptop and some human engineering.
This is hyperbole, automation that is being discussed is about how we can design a system that would in these circumstances. Retrofitting planes probably isn't going to work. However a whole new approach to sensors and global communications might provide the added information that's required for automated flights.
Each pilot that has commented seems to be against automation, just because their current work practices are too complex. However that is an engineering problem. Hacking a set of planes to crash is an engineering problem. Its not one that is going to be solved tomorrow, but perhaps in 10 to 15 years when a new generation of planes comes along.
My biggest beef isn't with flight automation but with trains. Surely that's the lowest hanging fruit on the automation tree and we seem to be aiming for the hardest with personal cars and commercial planes.
Queue handwringing pilots complaining that they cannot possible be replaced...