<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Compiling Dyanamic Fault Trees into Dynamic Bayesian Nets for Reliability Analysis: the Radyban Tool</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Luigi Portinale</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Andrea Bobbio</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Daniele Codetta Raiteri</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Stefania Montani</string-name>
          <email>stefaniag@di.unipmn.it</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Dipartimento di Informatica, Universita del Piemonte Orientale Via Bellini 25g</institution>
          ,
          <addr-line>15100 Alessandria</addr-line>
          ,
          <country country="IT">ITALY</country>
        </aff>
      </contrib-group>
      <abstract>
        <p />
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>Introduction</title>
      <p>In this paper, we present Radyban
(Reliability Analysis with DYnamic BAyesian
Networks), a software tool which allows to
analyze systems modeled by means of Dynamic
Fault Trees (DFT), by relying on automatic
conversion into Dynamic Bayesian Networks
(DBN). The tools aims at providing a
familiar interface to reliability engineers, by
allowing them to model the system to be
analyzed with quite a standard formalism (i.e.
DFT) based on speci c extensions to the
well-known methodology of Fault Trees;
however, the tool also implements a modular
algorithm for automatically translating a DFT
into the corresponding DBN, without any
explicit intervention from the end user. In fact,
when the computation of speci c reliability
measures is requested, the tool exploits
classical algorithms for the inference on Dynamic
Bayesian Networks, in order to compute the
requested parameters. This is performed in
a totally transparent way to the user, who
could in principle be completely unaware of
the underlying Bayesian Network. However,
the use of DBNs allows the tool to be able
to compute measures that are not directly
computable from DFTs, but that are
naturally obtainable from DBN inference.
After having described the basic features of the
tool, we show how it operates on a real world
example and we compare the unreliability
results it generates with those returned by
other methodologies, in order to verify the
correctness and the consistency of the results
obtained.</p>
      <p>This work has been partially supported by the
EUProject Crutial IST-2004-27513.</p>
      <p>
        The modeling possibilities o ered by Fault Trees (FT),
one of the most popular techniques for
dependability analysis of large, safety critical systems, can
be extended by relying on Bayesian Networks (BN)
[
        <xref ref-type="bibr" rid="ref1 ref12 ref21 ref22 ref3">1, 3, 12, 21, 22</xref>
        ]. This formalism allows to relax some
constraints which are typical of FTs. In addition, BNs
allow to represent local dependencies and to perform
both predictive and diagnostic reasoning.
      </p>
      <p>
        In [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ], we have shown how BNs can provide a uni ed
framework in which also Dynamic Fault Trees (DFT)
[
        <xref ref-type="bibr" rid="ref6">6</xref>
        ], a rather recent extension to FTs able to treat
several types of dependencies, can be represented.
However, while reliability engineers are quite familiar with
FT-based formalisms, they are not usually comfortable
with the use of formalisms like BN and their
extensions. This is also due to the fact that, for reliability
purposes, simple and modular techniques are often
sufcient for the de nition of the required analysis
framework. Of course, a clear trade-o exists between the
simplicity of the formalism and its modeling, as well
as analysis capabilities. FTs are maybe the most
simple combinatorial formalism in reliability analysis, but
they fail in capturing important aspects like several
kind of dependencies among the system components
[
        <xref ref-type="bibr" rid="ref1 ref12 ref20">20, 1, 12</xref>
        ]. DFTs overcome some of the limitations
of standard FTs, by allowing some kind of dynamic
dependencies among components, while still o ering
a quite simple and structured framework very useful
for modeling purposes, but still quite limited from the
analysis point of view.
      </p>
      <p>
        The starting point of our work is to make available to
reliability engineers a tool where they can take
advantage of the simplicity and modularity of either plain
FTs or DFTs, by making them available at the same
time a more powerful analysis engine based on
Dynamic Bayesian Networks (DBN). In fact, the
quantitative analysis of DFTs typically requires to expand
the model in its whole state space, and to solve the
corresponding Continuous Time Markov Chain (CTMC)
[
        <xref ref-type="bibr" rid="ref6">6</xref>
        ]. Our approach is based on a translation of the DFT
into an equivalent DBN. With respect to CTMC, the
use of a DBN allows one to take advantage of the
factorization in the temporal probability model, via the
conditional independence assumptions represented in
the DBN.
      </p>
      <p>The tool we have implemented is called Radyban
(Reliability Analysis with DYnamic BAyesian Networks)
and allows the design of the reliability model through
a graphical interface where the analyst can access and
exploit all the familiar modeling constructs of DFTs;
the resulting model is then compiled into an equivalent
DBN and the analysis is performed in a transparent
way to user, who has just to specify the desired type
of analysis algorithm.
2</p>
    </sec>
    <sec id="sec-2">
      <title>Dynamic Fault Trees</title>
      <p>
        Fault Trees allow one to represent the combination of
elementary causes that lead to the occurrence of an
undesired catastrophic event named the Top Event (TE)
[
        <xref ref-type="bibr" rid="ref1 ref12">1, 12</xref>
        ]. By specifying failure probabilities on the
basic components of the modeled system (the elementary
causes of the TE, also called basic events), the whole
system unreliability (probability of the TE) at a given
mission time can be computed.
      </p>
      <p>
        In recent years, an e ort has been documented in the
literature, aimed at increasing the modeling power of
FT by including new primitive gates, able to
accommodate complex kinds dependencies. This augmented
FT language is referred to by the authors as Dynamic
FT [
        <xref ref-type="bibr" rid="ref13 ref6">6, 13</xref>
        ]. DFT introduce four basic (dynamic) gates:
the warm spare (WSP), the sequence enforcing (SEQ),
the probabilistic dependency (PDEP) and the priority
AND (PAND).
      </p>
      <p>A WSP dynamic gate models one primary
component that can be substituted by one or more backups
(spares), with the same functionality (see Fig. 2(a),
where spares are identi ed by \circle-headed" arcs).
The WSP gate fails if its primary fails and all of its
spares have failed or are unavailable (a spare is
unavailable if it is shared and being used by another spare
gate). Spares can fail even while they are dormant,
but the failure rate of an unpowered (i. e. dormant)
spare is lower than the failure rate of the
corresponding powered one. More precisely, being the failure
rate of a powered spare, the failure rate of the
unpowered spare is , with 0 1 called the dormancy
factor. Spares are more properly called \hot" if = 1
and \cold" if = 0.</p>
      <p>A SEQ gate forces its inputs to fail in a particular
order: when a SEQ is found in a DFT, it never happens
WSP
P
FDEP
A
(b)
T</p>
      <p>B</p>
      <p>PAND
A</p>
      <p>
        B
(c)
that the failure sequence takes place in di erent orders.
SEQ gates can be modeled as a special case of a cold
spare [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ], so they will not be considered any more in
the following1.
      </p>
      <p>In the FDEP gate (Fig. 2(b)), one trigger event T
(connected with a dashed arc in the gure) causes other
dependent components to become unusable or
inaccessible. In particular, when the trigger event occurs,
the dependent components fail with pd = 1; the
separate failure of a dependent component, on the other
hand, has no e ect on the trigger event. FDEP has
also a non-dependent output, that simply re ects the
status of the trigger event and is called dummy output
(i. e. not used in the analysis).</p>
      <p>We have generalized the FDEP by de ning a new
gate, called probabilistic dependency (PDEP). In the
PDEP, the probability of failure of dependent
components, given that the trigger has failed, is pd 1.
Finally, the PAND gate reaches a failure state if and
only if all of its input components have failed in a
preassigned order (from left to right in graphical
notation). While the SEQ gate allows the events to occur
only in a preassigned order and states that a di erent
failure sequence can never take place, the PAND does
not force such a strong assumption: it simply detects
the failure order and fails just in one case (in Fig. 2(c)
a failure occurs i A fails before B, but B may fail
before A without producing a failure in G).
3</p>
    </sec>
    <sec id="sec-3">
      <title>Dynamic Bayesian Networks</title>
      <p>
        DBNs [
        <xref ref-type="bibr" rid="ref16 ref18 ref5">5, 18, 16</xref>
        ] extend the BN formalism by
providing an explicit discrete temporal dimension. The
standard DBN representation model adopts a discrete
time approach, where several time slices are explicited,
togheter with information about transitions from a
time slice to the next ones. When the Markov
assump1The conceptual di erence between the two kind of
gates is that the inputs to a SEQ do not need to be a
component and its set of spares, but can be components
covering any kind of function in the FT.
tion holds (and in particular when we are dealing with
a rst order Markov process) the future slice at time
t + ( being the so called discretization step
usually assumed to be 1) is conditionally independent of
the past ones given the present slice at time t [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ]. In
this case, it is su cient to represent two consecutive
time slices called the anterior and the ulterior layer.
The above model of a DBN is usually called 2TBN
(two time-slice Temporal Bayesian Network)[
        <xref ref-type="bibr" rid="ref16 ref4">16, 4</xref>
        ]. A
DBN (2TBN) is in canonical form if the anterior layer
contains only variables having in uence on the same
variable or on another variable at the ulterior level.
Given a DBN in canonical form, inter-slice edges
connecting a variable in the anterior layer to the same
variable in the ulterior layer are called temporal arcs;
in other words, a temporal arcs connect variable Xit
to variable Xit+ (being Xit the copy of variable Xi at
time t). Radyban explicitly uses the notion of
temporal arc in its representation.
      </p>
      <p>Concerning the analysis of a DBN, di erent kinds of
inference algorithms are available. In particular, let
Xt be a set of variables at time t and ya:b any stream
of observation from time point a to time point b (i.e. a
set of instantiated variables Yij with a j b). The
following tasks can be performed over a DBN:
Prediction: computing P (X t+hjy1:t) for some
horizon h &gt; 0, i.e. predicting a future state
taking into consideration the observation up to now;
this task is called ltering or monitoring if h = 0.
Smoothing: computing P (X t ljy1:t) for some
l &lt; t, i.e. estimating what happened l steps in
the past given all the evidence (observations) up
to now.</p>
      <p>
        Di erent algorithms, either exact or approximate
can be exploited in order to implement the above
tasks. In the Radyban tool, the user can select
either the ltering/prediction or the smoothing task,
and for each given task she/he may choose between
using a Junction Tree (JT) inference [
        <xref ref-type="bibr" rid="ref10 ref16">10, 16</xref>
        ] or
the Boyen-Koller (BK) algorithm [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ], a
parameterized inference algorithm that, depending on the
parameters provided (disjoint sets of variables called
clusters), may return exact as well as approximate
results. Such algorithms have been implemented
by resorting to Intel PNL (Probabilistic Networks
Library), a set of open-source C++ libraries,
(http://www.intel.com/research/mrl/pnl), to
which we have provided some minor adjustments.
DFT editor
DFT.xml
      </p>
      <p>DBN.xml
DFT2DBN
DBN solver</p>
      <p>DBN.xml
Results</p>
      <p>Results</p>
      <p>The Radyban tool</p>
      <sec id="sec-3-1">
        <title>Tool functionalities</title>
        <p>The main features of Radyban allow the user to: (1)
edit a dynamic fault tree and (2) automatically
compile a DFT into the corresponding DBN, on which both
predictive and diagnostic inference can then be drawn.
This is the modality designed for reliability engineers
who are not familiar with BN-based formalism and
who want to take advantage of a DFT-based model
interface augmented with the whole analysis power of
DBNs. However, the tool also allows the possibility of
directly editing a (D)BN and then draw inferences on
it; of course this modality has to be followed only by
users having the necessary background on (D)BNs2.
The tool architecture is depicted in Fig. 2.
4.2</p>
      </sec>
      <sec id="sec-3-2">
        <title>Graphical interface description</title>
        <p>Modeling the failure mode of a system as a DBN might
be complicated for the user, while drawing the DFT
model and generating automatically the corresponding
DBN, is sometimes more practical. In this way, the
DFT becomes a high level formalism allowing the user
to express in a straightforward way the relations
between the components of the system, whose modeling
in terms of DBN primitives would be less comfortable.</p>
        <p>2At the current stage, the graphical interface does not
allow the user to access the DBN produced by the
compilation of a DFT (that can however be edited in XML form);
we are currently working in order to allow this possibility
as well.</p>
        <p>The DFT editor allows the modeler to resort to
standard DFT constructs (i.e. boolean and dynamic
gates), as well as to specify additional properties
(allowed by our tool) for the analysis. In fact, the user
may indicate which events will be queried and which
events have been observed (true or false) at a given
time point. Another extension on which we are
working on is to allow the possibility of the so called Repair
Box, i.e. a gate modeling the repair (through a
suitable repair rate) of components: at the current stage
only the repair of basic events (i.e. elementary system
components) is allowed.</p>
        <p>The user can also specify the analysis time step k, as
well as the mission time T and the inference algorithm
to be adopted on the corresponding DBN for the
required analysis (i.e. the analysis must be performed
from time 0 to time T every k instants). This
information is directly inherited by the corresponding DBN
when translation is required. In this way, the DFT
is exploited as an easy and well known formalism, to
which the user is typically already familiar, through
which all the needed data for DBN inference can be
given in input.</p>
        <p>Particularly important from the quantitative analysis
point of view is another parameter that the user can
set on the DFT: the discretization step . Since DBN
is a discrete time formalism, a suitable discretization
step must be de ned in case failure speci cation on the
system components are given in a continuous way. Let
us suppose that a basic component C is characterized
by an exponential failure rate C : given a
discretization step , we can characterize the failure probability
of C as</p>
        <sec id="sec-3-2-1">
          <title>P [C failed at tjC working at (t )] = 1</title>
          <p>e C
In terms of the corresponding DBN, represents the
amount of time separating the anterior layer from the
ulterior layer. This di ers from the model usually
adopted in the reliability analysis of a DFT which is
usually a CTMC. The results provided by a CTMC are
in fact slightly di erent. As a matter of fact, the two
models are not exactly equivalent, since in a CTMC
transitions occur in a continuous fashion.</p>
          <p>There is a trade-o between the approximation
provided by discretization and the computational e ort
needed for the analysis: smaller is the
discretization step, more accurate are the results obtained
(and closer to the continuous case computation), but
greater is the time horizon required for the analysis
(and thus the computation time). In fact, if failure
rates are given as f ault=hour and we set a mission
time of T hours, a discretization step = 1h will
require analysis up to step t = T , while a discretization
step = 10h will only require analysis up to step
t = T =10 (since each step will count as 10 time units);
this fact, in DBN inference, will result in a speed up
of the result computation, because a smaller number
of time slices have to be considered (i.e. a time slice
in the latter case approximate 10 slices in the former).
Fig. 3 shows a screenshot of the graphical interface of
our tool. It is mainly composed by three windows;
the Main window allows the user to draw the DFT
model, while in the window named Property Page, it
is possible to set the attributes of the node currently
selected in the main window. From the Execute menu
of the Main window, the user can run the conversion
and the analysis of the DFT model. At the end of
such process, the obtained results are displayed in the
window called Solver Execution.
4.3</p>
        </sec>
      </sec>
      <sec id="sec-3-3">
        <title>Compiling DFT into DBN</title>
        <p>
          The gates of a DFT can be individually compiled into
corresponding DBN fragments (see [
          <xref ref-type="bibr" rid="ref1 ref14">1, 14</xref>
          ] for the
technical details); however, each single fragment has then
to be combined with each others, in order to produce
the compiled DBN corresponding to the input DFT.
From the structural point of view, combining di erent
fragments is trivial; just overlaps nodes corresponding
to the same variable in di erent fragments. Fig. 4(a)
shows an example of structural combination of the
subnets of a WSP gate with one primary component P ,
one spare B and a PDEP with a component T
triggering B. The WSP DBN fragment is shown in the lower
part of Fig. 4(a), while the PDEP DBN fragment is
shown in the upper part of Fig. 4(a).
        </p>
        <p>
          While the structural combination is relatively
simple (the common part is the one concerning
temporal copies of variable B), the quantitative combination
of the conditional probabilities (i.e. the generation of
the CPTs relative to the combined structure) may be
rather problematic. The problem stands in the fact
that the structural combination will introduce new
dependencies when overlapping nodes; the question is
whether there exists a method of quantifying such
dependencies in a modular way, by combining the CPTs
of the original fragments, under a set of reasonable
assumptions. This is a well studied issue in BN theory
under the name of \causal" or \conditional
independence" [
          <xref ref-type="bibr" rid="ref17 ref9">9, 17</xref>
          ]. The main point refers to the possibility
of avoiding a complete CPT speci cation for a given
node, when the number of the parents is too large for a
reasonable assessment. Common for these approaches
is the realization that all parameters are required if we
do not make additional assumptions. However, if the
domain experts are able to identify, e.g., functional
relations, then this should be taken into consideration.
This can be explained by considering a structural
transformation called divorcing [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ]; it essentially
consists in factorizing the assessment of the CPT of a
given node with a large number of parents, by adding
new parent nodes representing a set of the original
parents and by considering their combination as a
\noisy" (probabilistic) functional relation. An
example is shown in Fig. 4(b), where parent nodes of node
B(t + ) in Fig. 4(a) are \divorced" by creating new
parents B0(t + ) and B"(t + ). Conceptually, node
B0(t + ) represents the combination of nodes B(t)
and T (t + ), while node B"(t + ) is the
combination of B(t) and P (t). A way of implementing this
consists in setting 4 values for nodes B0(t + ) and
B"(t + ) such that for example B0(t + ) = \00"
i B(t) = 0 ^ T (t + ) = 0, B0(t + ) = \01" i
B(t) = 0 ^ T (t + ) = 1 and so on. Node Bf (t + )
implements the noisy relation used for integrating the
original CPTs and determined by the underlying
assumptions we want to make.
        </p>
        <p>
          A typical example of such assumptions is the
classical \noisy-OR". Noisy-OR implies the independence
of the causes that inhibit the presence of a given
consequence and has a cumulative e ect over the
consequence (the probability of having the consequence
when more than one cause is present is higher than
the consequence's probability when each cause is
singularly present) [
          <xref ref-type="bibr" rid="ref10 ref19">10, 19</xref>
          ].
        </p>
        <p>For instance, let us suppose that in the example of
Fig. 4(a), we quantify P [B = 1jT = 1] = pd = 0:8,
= 0:5, = 0:1, e 1 and e 1 ,
in the hypothesis that the failure rate is su ciently
t
T
B
P
(a)
t+Δ
PDEP dbn
T
P</p>
        <p>B</p>
        <p>WSP
WSP dbn
structural
divorcing on B
B(t+Δ)
t
T
P
(b)
t+Δ
PDEP dbn
T
B’
P</p>
        <p>B"</p>
        <p>WSP
WSP dbn</p>
        <p>
          Bf
small [
          <xref ref-type="bibr" rid="ref22">22</xref>
          ] and = 1 (as usual 0 = working and
1 = f ailed). With a noisy-OR interaction we could
compute for example
It is worth remarking that, in order to compute the
CPT produced by combining di erent fragments on
common variables, there is no need to make explicit
the divorcing structure of Fig. 4(b); once the modeler
has decided the suitable noisy functional relation for
components shared across di erent gates, this can be
directly applied to the structure of Fig. 4(a). In the
S
current example, our tool will in fact directly produce
the structure of Fig. 4(a)3.
5
        </p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>An example</title>
      <p>
        The example we report is inspired from [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ] and
represents an Active Heat Rejection System (AHRS). The
block scheme of the AHRS's architecture is depicted
in Fig. 5; such system is composed by two redundant
thermal rejection units A and B, each one possessing
a primary component (A1 and B1 respectively) and
a cold spare (A2 and B2 respectively). A1 and B2
are powered by a common source P 1, which acts as
a trigger in a FDEP gate, in which A1 and B2 are
the dependent components. Similarly, B1 and A2 are
powered by P 2. An extra stand-by cold spare unit (S)
is shared between the two thermal rejection units A
and B, and is powered (and potentially triggered) by
the source P 3. The time to fail of any component in
the system is a random variable ruled by the negative
exponential distribution; Tab. 1 shows the exponential
failure rate of every component.
After the conversion of the DFT in a DBN, we can
perform the analysis of the latter by means of our tool.
Tab. 2 shows the unreliability of the system versus
the mission time varying between 0 and 100 hours,
with di erent discretization steps ( = 1h; 0:5h; 0:05h
respectively, in columns 2, 3 and 4). To perform
such a computation, we just used a ltering task by
querying node TE without providing any observation
stream; in other words we performed standard
prediction. The obtained results have been successfully
3At the current stage the tool implements, in addition
to noisy-OR, another kind of interaction called MSP (Most
Severe Prevailing) corresponding to the situation where,
given a set of potential causes of an e ect, the most severe
cause prevails over the others (see [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ] for more details).
A1
      </p>
      <p>A2
B1</p>
      <p>B2
AFailure</p>
      <p>
        BFailure
veri ed by comparison with the results returned by
other tools on the same DFT model. Such tools are
DRPFTproc [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ] (based on modularization [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ] and
conversion to Stochastic Petri Nets of dynamic gates) and
Galileo [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ] (based on modularization, Binary Decision
Diagrams (BDD) and CTMCs). Last two columns
of tab. 2 reports also the results obtained using such
tools. It is easy to verify that, as the discretization
step is reduced, Radyban results become closer and
closer to the results obtained by means of the other
tools, thus con rming the claim that, in this example,
the only source of approximation in using DBNs is due
to discretization. Moreover, as already mentioned, a
trade-o between computation time and result
precision exists: if approximated results are su cient, a
quicker DBN inference can be obtained by choosing a
relatively large discretization step.
      </p>
      <sec id="sec-4-1">
        <title>Component A1 A2 B1</title>
        <p>B2</p>
        <p>S
P1, P2, P3
DBN also o er additional analysis capabilities with
respect to Markov models and Petri Nets:
smoothing inference allows to rebuild the past history of the
system, given a stream of observations. As an
example, we have considered a situation in which the
overall system was observed as operational at time
t = 10h and t = 20h, while it was observed to be
failed (T E = true) at t = 60h. By applying a
smoothing algorithm, Radyban was able to provide
the probabilities of failure of the system in the time
span 20h t 60h (see table 3). For example, we
can state that, by knowing that the system was
certainly operational at t = 20h and was certainly failed
at t = 60h, the probability that it was already failed
at t = 50h is about 0:4%. This suggest that a very
unlikely event has occurred, because just 10 hours before
the observation of the failure, the system was almost
de nitely operational.</p>
        <p>We feel that the approch implemented in the tool can
be a step forward in making available formalisms based
on Bayesian nets to the reliability community, without
asking reliability practitioners to renounce to their
familiar constructs like those used in FT or DFT. In
the future, we plan to extend the tool capabilities, by
adding ad hoc structures to the DFT, which can then
be naturally characterized in the corresponding DBN:
for example, we will allow the insertion of multi-valued
nodes, the modeling of complex repair policies and the
speci cation of conditional dependencies among basic
events.</p>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>A.</given-names>
            <surname>Bobbio</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Portinale</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Minichino</surname>
          </string-name>
          , and
          <string-name>
            <given-names>E.</given-names>
            <surname>Ciancamerla</surname>
          </string-name>
          .
          <article-title>Improving the analysis of dependable systems by mapping fault trees into bayesian networks</article-title>
          .
          <source>Reliability Engineering and System Safety</source>
          ,
          <volume>71</volume>
          :
          <fpage>249</fpage>
          {
          <fpage>260</fpage>
          ,
          <year>2001</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>A.</given-names>
            <surname>Bobbio</surname>
          </string-name>
          and
          <string-name>
            <given-names>D. Codetta</given-names>
            <surname>Raiteri</surname>
          </string-name>
          .
          <article-title>Parametric fault-trees with dynamic gates and repair boxes</article-title>
          .
          <source>In Proceedings Reliability and Maintainability Symposium RAMS2004</source>
          , pages
          <fpage>101</fpage>
          {
          <fpage>106</fpage>
          , Los Angeles, USA,
          <year>2004</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>H.</given-names>
            <surname>Boudali</surname>
          </string-name>
          and
          <string-name>
            <given-names>J.</given-names>
            <surname>Bechta-Dugan</surname>
          </string-name>
          .
          <article-title>A new bayesian network approach to solve dynamic fault trees</article-title>
          .
          <source>In Proceedings Reliability and Maintainability Symposium RAMS2005</source>
          , pages
          <fpage>451</fpage>
          {
          <fpage>456</fpage>
          ,
          <year>2005</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>X.</given-names>
            <surname>Boyen</surname>
          </string-name>
          and
          <string-name>
            <given-names>D.</given-names>
            <surname>Koller</surname>
          </string-name>
          .
          <article-title>Tractable inference for complex stochastic processes</article-title>
          .
          <source>In Proceedings UAI</source>
          <year>1988</year>
          , pages
          <fpage>33</fpage>
          {
          <fpage>42</fpage>
          ,
          <year>1998</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>T.</given-names>
            <surname>Dean</surname>
          </string-name>
          and
          <string-name>
            <given-names>K.</given-names>
            <surname>Kanazawa</surname>
          </string-name>
          .
          <article-title>A model for reasoning about persistence and causation</article-title>
          .
          <source>Computational Intelligence</source>
          ,
          <volume>5</volume>
          (
          <issue>3</issue>
          ):
          <volume>142</volume>
          {
          <fpage>150</fpage>
          ,
          <year>1989</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>J. Bechta</given-names>
            <surname>Dugan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.J.</given-names>
            <surname>Bavuso</surname>
          </string-name>
          , and
          <string-name>
            <given-names>M.A.</given-names>
            <surname>Boyd</surname>
          </string-name>
          .
          <article-title>Dynamic fault-tree models for fault-tolerant computer systems</article-title>
          .
          <source>IEEE Transactions on Reliability</source>
          ,
          <volume>41</volume>
          :
          <fpage>363</fpage>
          {
          <fpage>377</fpage>
          ,
          <year>1992</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>J. Bechta</given-names>
            <surname>Dugan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.J.</given-names>
            <surname>Sullivan</surname>
          </string-name>
          , and
          <string-name>
            <given-names>D.</given-names>
            <surname>Coppit</surname>
          </string-name>
          .
          <article-title>Developing a low-cost high-quality software tool for dynamic fault-tree analysis</article-title>
          .
          <source>IEEE Transactions on Reliability</source>
          ,
          <volume>49</volume>
          (
          <issue>1</issue>
          ):
          <volume>49</volume>
          {
          <fpage>59</fpage>
          ,
          <year>2000</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>R.</given-names>
            <surname>Gulati</surname>
          </string-name>
          and
          <string-name>
            <given-names>J.</given-names>
            <surname>Bechta-Dugan</surname>
          </string-name>
          .
          <article-title>A modular approach for analyzing static and dynamic fault trees</article-title>
          .
          <source>In Proceedings Reliability and Maintainability Symposium RAMS1997</source>
          , pages
          <fpage>1</fpage>
          <issue>{7</issue>
          ,
          <year>1997</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>D.</given-names>
            <surname>Heckerman</surname>
          </string-name>
          and
          <string-name>
            <given-names>J.S.</given-names>
            <surname>Breese</surname>
          </string-name>
          .
          <article-title>Causal independence for probability assessment and inference using bayesian networks</article-title>
          .
          <source>IEEE Transactions on Systems, Man and Cybernetics</source>
          ,
          <volume>26</volume>
          (
          <issue>6</issue>
          ):
          <volume>826</volume>
          {
          <fpage>831</fpage>
          ,
          <year>1996</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>F.V.</given-names>
            <surname>Jensen</surname>
          </string-name>
          .
          <source>Bayesian Networks and Decision Graphs</source>
          . Springer,
          <year>2001</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>U.</given-names>
            <surname>Kjaerul</surname>
          </string-name>
          .
          <article-title>dhugin: a computational system for dynamic time-sliced bayesian networks</article-title>
          .
          <source>International Journal of Forecasting</source>
          ,
          <volume>11</volume>
          :
          <fpage>89</fpage>
          {
          <fpage>101</fpage>
          ,
          <year>1995</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>H.</given-names>
            <surname>Langseth</surname>
          </string-name>
          and
          <string-name>
            <given-names>L.</given-names>
            <surname>Portinale</surname>
          </string-name>
          .
          <article-title>Bayesian networks in reliability</article-title>
          .
          <source>Reliability Engineering and System Safety</source>
          ,
          <volume>92</volume>
          (
          <issue>1</issue>
          ):
          <volume>92</volume>
          {
          <fpage>108</fpage>
          ,
          <year>2007</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>R.</given-names>
            <surname>Manian</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.W.</given-names>
            <surname>Coppit</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.J.</given-names>
            <surname>Sullivan</surname>
          </string-name>
          , and
          <string-name>
            <given-names>J.B.</given-names>
            <surname>Dugan</surname>
          </string-name>
          .
          <article-title>Bridging the gap between systems and dynamic fault tree models</article-title>
          .
          <source>In Proceedings IEEE Annual Reliability and Maintainability Symposium</source>
          , pages
          <volume>105</volume>
          {
          <fpage>111</fpage>
          . IEEE Computer Society Press, Washington, DC,
          <year>1999</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>S.</given-names>
            <surname>Montani</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Portinale</surname>
          </string-name>
          ,
          <article-title>and</article-title>
          <string-name>
            <given-names>A.</given-names>
            <surname>Bobbio</surname>
          </string-name>
          .
          <article-title>Dynamic bayesian networks for modeling advanced fault tree features in dependability analysis</article-title>
          .
          <source>In Proc. ESREL</source>
          <year>2005</year>
          ,
          <string-name>
            <given-names>Tri</given-names>
            <surname>City</surname>
          </string-name>
          , pages
          <volume>1414</volume>
          {
          <fpage>1422</fpage>
          ,
          <year>2005</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>S.</given-names>
            <surname>Montani</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Portinale</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Bobbio</surname>
          </string-name>
          , and
          <string-name>
            <surname>D.</surname>
          </string-name>
          Codetta-Raiteri.
          <article-title>RADYBAN: a tool for reliability analysis of dynamic fault trees through conversion into dynamic bayesian networks</article-title>
          .
          <source>Reliability Engineering and System Safety</source>
          , in press,
          <year>2007</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>K.</given-names>
            <surname>Murphy</surname>
          </string-name>
          .
          <article-title>Dynamic Bayesian Networks: Representation, Inference and Learning</article-title>
          .
          <source>PhD Thesis</source>
          , UC Berkley,
          <year>2002</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <surname>D. Poole N.L. Zhang.</surname>
          </string-name>
          <article-title>Exploiting causal independence in Bayesian network inference</article-title>
          .
          <source>Journal of Arti cal Intelligence Research</source>
          ,
          <volume>5</volume>
          :
          <fpage>301</fpage>
          {
          <fpage>328</fpage>
          ,
          <year>1996</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>P.</given-names>
            <surname>Dagum</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Galper</surname>
          </string-name>
          , and
          <string-name>
            <given-names>E.</given-names>
            <surname>Horwitz</surname>
          </string-name>
          .
          <article-title>Dynamic network models for forecasting</article-title>
          .
          <source>In Proc. UAI'92</source>
          , pages
          <fpage>41</fpage>
          {
          <fpage>48</fpage>
          ,
          <year>1992</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>J.</given-names>
            <surname>Pearl</surname>
          </string-name>
          .
          <article-title>Probabilistic Reasoning in Intelligent Systems</article-title>
          . Morgan Kaufmann,
          <year>1989</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <given-names>L.</given-names>
            <surname>Portinale</surname>
          </string-name>
          and
          <string-name>
            <given-names>A.</given-names>
            <surname>Bobbio</surname>
          </string-name>
          .
          <article-title>Bayesian networks for dependability analysis: an application to digital control reliability</article-title>
          .
          <source>In 15-th Conference Uncertainty in Arti cial Intelligence</source>
          , UAI-
          <volume>99</volume>
          , pages
          <fpage>551</fpage>
          {
          <fpage>558</fpage>
          ,
          <year>1999</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <given-names>J.G.</given-names>
            <surname>Torres-Toledano</surname>
          </string-name>
          and
          <string-name>
            <given-names>L.E.</given-names>
            <surname>Sucar</surname>
          </string-name>
          .
          <article-title>Bayesian networks for reliability analysis of complex systems</article-title>
          .
          <source>In Lecture Notes in Arti cial Intelligence</source>
          , volume
          <volume>1484</volume>
          , pages
          <fpage>195</fpage>
          {
          <fpage>206</fpage>
          . Springer Verlag, Berlin,
          <year>1998</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <given-names>P.</given-names>
            <surname>Weber</surname>
          </string-name>
          and
          <string-name>
            <surname>L.</surname>
          </string-name>
          <article-title>Jou e. Reliability modelling with dynamic bayesian networks</article-title>
          .
          <source>In SafeProcess</source>
          <year>2003</year>
          ,
          <source>5th IFAC Symposium on Fault Detection, Supervision and Safety of Technical Processes</source>
          , Washington DC,
          <year>2003</year>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>