MADE Module Guides > Modeling Redundancy
4 Redundancy in Response Simulation
The system response to redundancy during failure can be simulated through failure injection and response simulation in the MADE model. Using response simulation shows the effects of a failure in the system (strength of response and how the response propagates). A system model in MADE can be modified to identify the effects that a redundant arrangement has in the system.
Figure 8 ("Response Simulation Redundancy process"): Step 1 (Analysis Options) → Step 2 (Feedback) → Step 3 (Fault Injection) → Step 4 (Step Table) → Step 5 (Response Simulation).
4.1 Analysis Options (Step 1)
Before beginning failure injection and response simulation, the appropriate analysis options should first be selected. The analysis options for response simulation (FCM) are in Project Preferences and are saved on a project-specific basis. These preferences allow the user to set threshold type & values to refine the response of the system to what is expected.
To access and set analysis options:
- Select Preference → Project Preferences from the main menu
- Select FCM Analysis from the dialog menu (left side)
- Set the Threshold Options, Threshold Constant (only applicable for Sigmoid Thresholds), FCM Simulation & Step Limiter options
Figure 9 shows the "FCM Analysis" preferences page: Threshold Type radio options (Bivalent, Trivalent, Bivalent Sigmoid [value 4.0], Trivalent Sigmoid [selected, value 1.0], No Threshold [Max 1, Min -1]) each with an Evaluate button; FCM Simulation section: Perturbed Value = 1.00, Perturbed Response Margin (%) = 1.00, "Apply Step Limit (No. of Steps)" checkbox (unchecked, default 20); Restore Defaults / Apply / Apply and Close / Cancel buttons.
4.1.1 Threshold Options (Step 1.1)
The threshold options determine the method of analysis that is used to evaluate the responses from a component. As the output of a component is perturbed high or low by a certain amount (dependent on input flows and strengths) the threshold options dictate the resultant output perturbation.
Selecting the appropriate threshold options is fundamental to achieving the correct results; the threshold options should be decided on depending on the analysis required. If a detailed response is required, then a sigmoid threshold should normally be used.
Table 1: Threshold types
| Method | Description | Range | Comments |
|---|---|---|---|
| Bivalent | A simple form of thresholding that only measures 0 and +1 responses. Does not allow negative perturbations. | 0, 1 | Appropriate for simple analysis where only unidirectional perturbations occur. |
| Trivalent | A simple form of thresholding that measures -1, 0 and +1 responses. Trivalent can detect high and low failures but does not provide much detail in each perturbation. | -1, 0, 1 | Appropriate for simple analysis where bi-directional perturbations occur. |
| Trivalent Sigmoid | A detailed threshold that uses a trivalent sigmoid (based on a sigmoid value) between the range of -1 and +1. The trivalent sigmoid can display detailed responses for both the high and low range. | -1 to 1 | Appropriate for detailed analysis where bi-directional perturbations occur. |
4.1.2 Threshold Constant (Step 1.2)
The threshold constant is used to adjust the sigmoid value for trivalent sigmoid threshold options. Editing the value of the sigmoid allows for a finely tuned response to be examined, to display the effects of damping or other expected phenomena accurately.
- Enter a value to change the sigmoid, or
- Select Evaluate to open a dialog with a graphical representation of the sigmoid
The evaluation dialog (Figure 12, "Trivalent sigmoid chart and threshold slider") displays the curve of the sigmoid for the calculations, with natural values on the x-axis and the threshold values on the y-axis (shown ranging x = -2.0 to 2.0, y = -1.0 to 1.0, with reference lines at 0.762/-0.762 for a Sigmoid Threshold of 1.0). The sigmoid graph can be modified using the sigmoid value to change the effects of thresholding.
To change the sigmoid threshold:
- Drag the sigmoid threshold slider
- Select OK when thresholding seems adequate
Response simulation is a cyclic process that requires an engineer to engage with the model and match the responses to the expected response based on experience. This process often involves troubleshooting various responses and refining the response. Considering the qualitative approach behind FCM, it is the general trend of the response that is important.
4.1.3 Threshold Constant (Step 1.3)
This section consists of two settings used in FCM simulation: Amplitude & Perturbed Response Margin (%).
Amplitude is a variable added to or subtracted from the Functional Flow Property value at the time of perturbation when conducting a FCM Response Simulation.
Perturbed Response Margin is the threshold applied to determine whether a component response (transient, steady state) has deviated from nominal. The margin is calculated as a percentage of the nominal response value at the same time step.
The last property of the analysis requires adjusting the step settings for the response simulation. These settings control the duration or length over which the analysis is observed. Having a low step size may lead to an incomplete representation of the response, while a large step size may include unnecessary sections of response (e.g. sections of a response that have reached equilibrium). The ideal step size will depend on the size of the model, the complexity of functional connections and the requirements of the response for the users.
Note: By default, No Limit is selected for the step limit. Users may deselect this to impose a limitation to the number of steps experienced in the step table. This is best used with the No Threshold option.
To set a Step Limit:
- Select the Apply Step Limit checkbox
- Enter a value for the required step size
4.2 Feedback Connection (Step 2)
A redundancy can be modelled by creating a feedback flow in the MADE system model. Feedback is used to relate the response from one item to its redundant counterpart(s). Creating the feedback connection that establishes redundancy in a model is important since it displays the effects of the redundancy in the system model.
In this example, we will consider a simple active redundancy between two generators in an electrical model. The redundancy flow will be connected from the output of one generator subsystem to the input of the other, and vice-versa. With these connections, when one subsystem fails, the response is detected by the other subsystem and compensated by it. It is important not to forget to change the strength and polarity of the feedback so that it causes the required response — in this model a negative polarity and maximum strength will compensate for the other component.
To form a feedback in a model:
- Select the feedback connection icon (↓F) in the icon toolbar
- Click-and-drag from the output of subsystem 1 into the input of subsystem 2
- Verify/Change the causal strength to maximum (10)
- Repeat as necessary for subsystem 2 into subsystem 1
Figure 14 shows the "Diesel Engine" system model with dashed F- feedback connections between the Governor/Injector Pump area, and the Properties viewer for the "Mechanical - rotational -> Mechanical - rotational" connection: Source/Target = Mechanical - rotational, Function = Regulate, Polarity = Negative (selected), Acausal unchecked, Causal Strength = 10.00 (maximum).
4.3 Failure Injection (Step 3)
Failure injection is used to inject a failure into the system model, so that the responses to that failure can be seen throughout the system. The effects of the failure may be examined at once or 'stepped' through by using the step table.
Injecting a failure follows the process of introducing a failure/failures to an item (or set of items) to investigate the distribution of failure responses throughout the entire system. Before propagating a failure, it needs to be injected. This can be performed by locating the appropriate item and accessing the right-click menu.
Note: In the generation of FMEA/FMECA reports, all possible failures in the model are automatically injected to determine and record their impacts on the system.
To introduce a failure injection into the system model:
- Right-click an item and select Failure Injection → [Flow Property] → [Failure Response] (Perturb by value allows users to choose the magnitude of the failure — this is applicable for sigmoid thresholds)
- Verify that the injected failure is displayed at the top-left corner of the system model editor
- Repeat as necessary for multiple failure injections
Figure 15 shows the "Diesel Engine" system model with a failure being injected on the "Lift Pump" item via right-click: System Model, Failure Diagram, Functions, Hazard Diagram, Maintenance Actions, Cut/Copy/Paste/Delete, Zoom In/Out, End Effect Item, Fault Tree, Response Paths, Hazard Path Analysis, Propagate All..., Override Failure Diagram, Failure Injection → Liquid Flow rate → Up / Down, Response Simulation.
4.4 Using the Step Table Viewer (Step 4)
Once the required failures have been injected, the response may be viewed on the system model and step table viewer. Depending on user preference, the response can be traced step-by-step through the system or simply displayed all at once to view the distribution.
The controls for the stepping process are in the icon toolbar (top right): Run, Sequential Step, Sequential Reset, Reset, Clear (five icons).
4.4.1 Run (Step to Equilibrium) (Step 4.1)
Selecting the run icon will display all steps until equilibrium (or a step limit) is achieved. This method displays the same information on the system model as Sequential Stepping but displays all steps at once. This is useful for users who simply need to verify the end response, rather than trace it.
Figure 17 ("Step to equilibrium") shows a "Single Line Electrical Diagram" model — a redundant dual-generator electrical system (Generator Room 8 / 9, feeding 8GT-SWG / 9GT-SWG via a Generator Controller, through Transformers 8GTA-XF-1 / 9GTA-XF-1, Isolators 1/2, Wires 1/2, into a 132kV BUS, then Isolator 3, 132kV Overhead Line, Line Trap, Wire 3, and two output Transformers VT8-9/VT-10) — after running to equilibrium following a "Connect 11.5kV OUT Voltage (8GT-SWG)" failure injection: per-item step-count deltas shown (e.g. Transformer 8GTA-XF-1 ↓7/↓8, Isolator 1/Wire 1 ↓5/↓10, 132kV BUS ↓17/↑17, Isolator 3 ↓18, Transformer VT8-9 ↓18/↓19/↓19/↓23/↓23/↓22, 9GT-SWG/Isolator 2/Wire 2 showing ↑ (up) responses ↑10/↑11/↑12/↑13, Line Trap/Wire 3 ↓19/↓20, 132kV Overhead Line ↓21/↓24), with F- feedback lines shown between Generator Room 8/9 and their respective switchgear.
4.4.2 Sequential Stepping (Step 4.2)
To view the system response for a failure on a step-by-step basis, the sequential step icon should be used. This method is useful for tracing specific paths through the system and for tracking the order of the steps. The user can roll over each step on the system model to identify a response during a specific time-step.
Figure 18 shows the same Single Line Electrical Diagram after a single sequential step: only the 8GT-SWG item shows a step-1 delta (↓1), with all downstream items still at their nominal (unperturbed) state — illustrating how sequential stepping reveals the failure propagating one hop at a time.
4.4.3 Sequentially Resetting the Step Table (Step 4.3)
If a single, sequential step needs to be reset, this is achieved using the sequential reset icon. This is useful for resetting the individual responses, so that stepping can be restarted.
4.4.4 Resetting the Step Table (Step 4.4)
If the system model needs to be reset i.e. remove all failure responses while retaining the initial failure injection, then the step table can be reset using the reset icon. This is useful for resetting the entire response, so that stepping can be restarted.
4.4.5 Clearing the Step Table (Step 4.5)
In a similar manner to resetting the step table, users may also delete the response and failure injection to begin a new failure injection. This method removes the response from the system model and removes the injected failures.
To clear the step table: In the main toolbar select 'Clear the Step Table'.
4.5 Using the Response Simulation Viewer (Step 5)
After failure injection and stepping has been performed, the next step is to investigate the response graphically by viewing the response charts. Selecting the response simulation for a component allows MADE to open the response that was viewed in the stepping table. The response simulation allows users to graph the results of various items and investigate their effects over the time-steps simulated.
The user can view the effects of the redundancy throughout the system by displaying response graphs of various items in response to a failure. A representation of redundancy in the form of a flow output returning to nominal can be visualized and exported.
To access the response simulation viewer:
- Inject a failure and run the simulation to equilibrium
- Right-click an item and select Response Simulation → [Flow Property]
- View the response graph in the response simulation viewer
- Repeat as necessary or select other flows to display their simulation responses in the chart
Figure 19 shows the "FCM Response Simulation - Vehicle System" viewer with Lift Pump's "Liquid Flow rate" checked/selected in the tree (Driveline, Power Generation > Control Unit, Diesel Engine > Air Filter, Coupling 1, Engine, Governor, Injector Pump, Lift Pump [Liquid Flow rate], Primary Fuel Filter, Secondary Fuel Filter, Mechanical - rotational Torque; Fuel Tank; Vehicle; Mechanical - rotational Angular velocity), plotted graph dropping from 0 after "FAILURE ACTIVATION" and settling at a final steady-state value of -0.813.
Source: Local MADE 3.9.1 installation: com.phm.made.help.plugin/documents/help/pdf/Modeling Redundancy Guide.pdf · retrieved 2026-07-09