MADE Module Guides > Failure Simulation and Responses
6 Worked Example
Using an example model, the following section will go through the user workflow (see failure-simulation-responses-guide-editors-and-review-workflow.md) to examine simulation of failures for the model. For this example, it is assumed that the model has been completed.
6.1 Step 1: Run Response Simulation
The system being used is a Power Generation subsystem of a Vehicle System. There are two main levels of indenture (LOI): the Power Generation subsystem, and the Diesel Engine subsystem within Power Generation. The model uses a trivalent sigmoid threshold and there are non-zero initial values for the input flow properties into the system (this is done for this example in order to better display an example of a model that requires multiple steps to find an initial equilibrium).
Figure 3 ("First LOI of the Model") shows: IN → {Liquid, Gas, Electrical} → Fuel Tank (Liquid) / Control Unit (Continuous) → Diesel Engine (Mechanical - rotational) → OUT, under Mission Profile "Regular Trip", End Effect Item "Vehicle System" — with warning icons on Control Unit and Diesel Engine.
Figure 4 ("Second LOI of the Model") shows the Diesel Engine internal structure: IN → {Liquid, Gas, Electrical, Continuous} → Air Filter (Gas) / Lift Pump → Primary Fuel Filter → Secondary Fuel Filter (Liquid, warning icon) → Injector Pump (Liquid) → Engine (Mechanical - rotational) → OUT, with Coupling 1 feeding back Mechanical-rotational to Lift Pump, and Governor providing Mechanical-linear from Continuous input.
Without injecting a failure, the Liquid Dynamic Pressure Response Simulation from the Injector Pump is selected from the right-click context menu. The resulting graph (Figure 5) shows that the initial value of the Dynamic Pressure was zero; this was increased due to the initial values of the flow properties at the input of the system. The simulation runs until an equilibrium can be found — for the Injector Pump's Dynamic Pressure this equilibrium value is 0.666. This value does not have a quantitative meaning in relation to the system; it simply represents a steady value that will serve as a nominal value of operation.
6.2 Step 2: Step Through Simulation Whilst Viewing Step Table
There have still not been any failures introduced to the model. To examine what is happening during the initial simulation to an equilibrium (which will be the nominal state of the system), use the FCM stepping buttons in the toolbar to step through the FCM simulation. This displays, in stepped order on the MADE system model, the order in which changes occur to the flow properties in the model due to the initial values on the input flow properties.
Figure 6 shows the system model mid-simulation with per-step deltas overlaid on each item (e.g. Air Filter "↓1", Engine "↓2"/"↓3", Coupling 1 "Angular v... ↓3", Lift Pump "↓4", Primary/Secondary Fuel Filter "↓5"/"↓6", Injector Pump "↓3"), with a "Functional Perturbation: Refine Gas Mass flow rate (Air Filter)" banner and FCM stepping toolbar buttons highlighted.
The step table presents each item and their flow properties as a row. The column headed with "i" presents the initial values of all the flow properties at the beginning of simulation; each further column displays the values of the flow properties at that step. Equilibrium is reached when the entire set of values repeats itself, with the final column headed with "=" presenting the equilibrium values of all flow properties. It is from this equilibrium that a failure will be injected and to which the system's response to failure will be compared.
Figure 7 ("Step Table for the Model Without a Failure Injected") shows the full step table for the Diesel Engine, columns 1–11 plus "=" (equilibrium), rows for Air Filter (Gas flow rate → 0.462), Control Unit (Continuous Amplitude → 0.245), Coupling 1 (Mechanical - r... → 0.0), Diesel Engine (Mechanical - r... Torque → 0.876), Engine (Mechanical - r... Torque → 0.876), Fuel Tank (Liquid Static pr... → 0.462), Governor (Mechanical - li... velocity → 0.632), Injector Pump (Liquid Dynami... pressure → 0.876; note: this is the row referenced/plotted as the response simulation graph in Step 1, though the guide's final equilibrium value stated in the graph is 0.666 — see note below), Lift Pump (Liquid Flow rate → 0.432), Power Generation (Mechanical - r... → 0.876), Primary Fuel Filter (Liquid Flow rate → 0.407), Secondary Fuel Filter (Liquid Flow rate → 0.386), and three Vehicle System rows (Electrical Voltage → 0.5, Liquid Flow rate → 0.5, Mechanical - r... → 0.876, Gas Mass flow r... → 0.5).
(Note on source fidelity: the guide's Figure 5 response-simulation graph for Injector Pump Dynamic Pressure settles at 0.666, while the Figure 7 step-table equilibrium column shows 0.876 for what appears to correspond to the same or a related Injector Pump flow. This is reproduced as printed in the source guide — the discrepancy may reflect that Figure 7's table was generated from a slightly different simulation run/model state than Figure 5's graph, or that Dynamic pressure and Dynamic Pressure's related Torque/rotational row are distinct flow properties. Treat the individual figures' values as authoritative for their own context rather than cross-reconciling them.)
6.3 Step 3: View Final Values
As noted, the equilibrium values are represented in both the response simulation graph and the step table. In reality, they are alternate views of the same information. The response simulation graph is a graphical display of one or several flow properties plotted over the course of the simulation. The step table displays all flow properties at the one time in their own rows.
6.4 Step 4: Inject a Failure and Step Through Simulation
Failures are injected into the system by perturbing or adjusting a modelling variable. In the case of FCM simulation the variable that is perturbed is a flow property in the model. For Bond Graph simulation, the variable perturbed is a Bond variable itself, like amplitude or damping.
A failure is injected using the right-click context menu and then the failure can be stepped through (if it is FCM). Similar to initially stepping through the simulation, stepping through the failure simulation takes the previously found equilibrium values and injects a constant perturbation; each step seen in the step table represents one step of the simulation beyond the equilibrium. The simulation continues until a new equilibrium (also known as steady state) is reached, signifying the steady state response of the system to the failure. In this example a low failure has been injected into the outflow of the Secondary Fuel Filter.
Figure 8 ("Failure Simulation Stepped Through") shows the system model with the "Functional Perturbation: Refine Liquid Flow rate (Secondary Fuel Filter)" banner, and per-item step-counters showing "15" steps so far: Air Filter (15, green/nominal), Lift Pump (15), Primary Fuel Filter (15), Secondary Fuel Filter (↓15, red/failed-low), Injector Pump (15), Engine (↓15, ↓15 — both outputs showing the propagated low failure), under Mission Profile "New Group", End Effect Item "Power Generation".
The step table produced once a failure simulation has been run appears very similar to the previous step table, however it is truncated in the sense that the pre-failure simulation steps are not included. The step table presents the previously found equilibrium values as the initial values for the new failure analysis (in the "i" column), with simulation steps presented until the final steady state is reached (final values presented in the "=" column).
Figure 9 ("Step Table for a Failure Simulation") shows the Diesel Engine step table, columns 1–14 plus "=", with the Secondary Fuel Filter row dropping to a final equilibrium of -0.532 and the Injector Pump Liquid Dynamic pressure row settling at 0.426 (down from its earlier nominal 0.462/0.632-range values), while Air Filter, Control Unit, Lift Pump, Primary Fuel Filter, and the Vehicle System Electrical Voltage/Gas rows remain unaffected at their prior nominal values (0.462, 0.245, 0.432, 0.407, 0.5, 0.5 respectively). Diesel Engine and Engine rows both settle at 0.71 (up from their prior nominal near-0 initial values in this truncated view), and Power Generation settles at 0.71 as well.
6.5 Step 5: Check Response Simulation
Again, the response simulation graph can be opened, and it will display the same information as the step table. The graph, when a failure has been injected, is now split into two segments: the first portion shows the simulation's initial run to equilibrium (with the point at which the failure is injected marked as "FAILURE ACTIVATION"), and the second portion shows the rest of the simulation as the model finds a final steady state response to the failure.
Figure 10 ("Response Simulation of a Failure") shows the Injector Pump's Liquid Dynamic pressure graph: rising from 0 to ~0.9 by step ~5, holding flat through the "FAILURE ACTIVATION" marker (around step 13), then dropping after failure injection to settle at a final steady-state value of 0.426 by around step 20 onward.
6.6 Step 6: Response Direction
Using the response simulation graph (or the step table) the final steady state value is compared to the initial equilibrium value. A response direction for each flow property is derived by finding whether the steady state value is greater than, lower than, or within a similar range of the equilibrium value:
- If steady state > equilibrium → the failure response is considered high
- If steady state < equilibrium → the response is considered low
- If steady state is within a range (as defined by the Perturbed Response Margin in the preferences) → the response is considered nominal (no change)
It is these response "statements" (high/low/nominal) that are the major inputs into failure-based analyses such as FMEA and PHM.
6.7 Step 7: View the Propagation Table
The propagation table presents all failures in the system and the results of their simulations. For example, the failure injected above was a low failure of the Secondary Fuel Filter. As established during the above failure simulation work-through, it was found that when the Secondary Fuel Filter fails low, the Injector Pump shows a low failure response. This is supported by the propagation table.
The propagation table is the final major output of failure simulation, and it is the propagation table's information that is used in related failure analyses.
Figure 11 ("Propagation Table as the Final Output of Failure Simulation") shows the "Propagation Table - FCM" viewer: header reads "Detectable Failures: 83% | Threshold Type: Trivalent Sigmoid | Criticality Threshold Type: N/A | Generated: 12:04:33 PM". Rows list each Component/Flow Property (e.g. Air Filter/Mass flow rate (Gas), Control Unit/Amplitude (Contin...), Coupling 1/Angular velocity, Diesel Engine/Torque, Engine/Torque, Fuel Tank/Static pressure, Governor/Linear velocity, Injector Pump/Dynamic pressure, Lift Pump/Flow rate, Power Generation/Torque, Primary Fuel Filter/Flow rate, Secondary Fuel Filter/Flow rate) each showing a "Failure" column (mostly "Low", one "Dec..." truncated) and per-downstream-component columns (Air Fil..., Cont..., Cou..., Diese..., Engin..., Fuel..., Gove..., Inject..., Lift P..., Powe..., Prim..., Seco...) populated with "Low" markers showing which downstream items also register a Low response for each row's originating failure.
Source: Local MADE 3.9.1 installation: com.phm.made.help.plugin/documents/help/pdf/Failure Simulation and Responses.pdf · retrieved 2026-07-09