Document
Optimal Aircraft Control Upset Recovery With and Without
Component Failures
Dean W. Sparks Daniel D. Moerder Guidance and Control Branch NASA Langley Research Center Hampton, Virginia 23 681-2199 1 Introduction 2 Vehicle Model The aircraft model which is used in this study is adapted from a 6-degree-of-freedom simulation of Langley Re- This paper treats the problem of recovering sustainable non- search Center's now-retired 737-100 research aircraft, doc- descending (safe) flight in a transport aircraft after one or umented in [1,2]. The model assumes constant mass, ro- more of its control effectors fail. Such recovery can be a tating spherical Earth, and U.S. 1976 standard atmosphere challenging goal for many transport aircraft currently in the [3] with no winds. The airframe dynamics are expressed in operational fleet for two reasons. First, they have very little body axes, and vehicle attitude is propagated using quater- redundancy in their means of generating control forces and nions.
moments. These aircraft have, as primary control surfaces, a single rudder and pairwise elevators and aileron/spoiler The vehicle's control effectors are rudder, flaps, horizon- units that provide yaw, pitch, and roll moments with suffi- tal stabilizer, elevator, aileron/spoiler, and right and left en- cient bandwidth to be used in stabilizing and maneuvering gines. The aerodynamic and thrust forces are represented the airframe. Beyond this, throttling the engines can pro- as tabular functions of these variables, along with aerody- vide additional moments, but on a much slower time scale.
namic angles and airspeed or Mach number and altitude.
Other aerodynamic surfaces, such as leading and trailing This gave roughly 90 data tables drawn from the original edge flaps, are only intended to be placed in a position and simulation software, where they were used with piecewise left, and are, hence, very slow-moving. Because of this, loss multilinear table lookups. In order to preserve differentia- of a primary control surface strongly degrades the control- bility in the optimization model, a piecewise linear-quartic lability of the vehicle, particularly when the failed effector scheme (which fits multiquartic chamfers to the multilinear becomes stuck in a non-neutral position where it exerts a interpolant near tabulated points) was employed for table disturbance moment that must be countered by the remain- lookup. This software is documented in [4]. The simulation ing operating effectors.
model additionally included dependencies on aerodynamic angle rates and load factor, but these were ignored because The second challenge in recovering safe flight is that these of their small contributions to the dynamical response.
vehicles are not agile, nor can they tolerate large acceler- ations. This is of special importance when, at the outset The aerodynamic control surfaces are represented as inte- of the recovery maneuver, the aircraft is flying toward the grators of control surface rate commands, subject to in- ground, as is frequently the case when there are major con- equality constraints on position and rate. For example, the trol hardware failures.
elevator position 8E and rate eye are related by Recovery of safe flight is examined in this paper in the con- text of trajectory optimization. For a particular transport _E : (_E (1) aircraft, and a failure scenario inspired by an historical air disaster, recovery scenari are calculated with and without subject to specified limits control surface failures, to bring the aircraft to safe flight from the adverse flight condition that it had assumed, ap- parently as a result of contact with a vortex from a larger aircraft's wake. An effort has been made to represent rel- --(_E<__E<_(YE AND 8E(V)<_SE<_8+(V) (2) evant airframe dynamics, acceleration limits, and actuator limits faithfully, since these contribute to the lack of agility and control power that plays an important role in defining where the position limits are tabular functions of airspeed.
what can be achieved with the vehicle when it is in extremis.
This pattern holds true for all control surfaces except for aileron/spoiler, whose position limitsare tabular functions we are studying the Flight 427 scenario, but applying it to a ofaltitude and Mach number, and thehorizontal stabilizer, different transport aircraft, the results are of qualitative ap- which has fixed mechanical limits. Each ofthe twoengines plicability to the Flight 427 situation.
ismodelled separately. Thrust isatabular function ofengine
Table 1 lists the vehicle state used as an initial condition for
pressure ratio, e, Mach and altitude; e itself satisfies
the study trajectories. Those quantities marked with an x in the left column were taken from [5] at the point in time where their simulation indicated that Flight 427's rudder be- came stuck at 17.6 degrees of deflection. The engine pres- = (re, (rE = ec - e ELSE (3) sure ratio values, eR and e_, were not available in [5], but 0.3 ec>_e+0.3 -0.54 ec <_ e - 0.54 could be approximated from the data in the NTSB Accident Report for this incident [6]. The other displayed quantities were fit to the dynamics of the study aircraft.
where ec is the commanded value of e.
Thus far, the ailerons and spoilers have been referred to as a Table 1. USAir 427 adverse flight conditions.
single unit. This is because, on the study aircraft, hardware x Altitude 5500 ft linkages couple their motion. In particular, the right spoiler x Total velocity 315 ft/sec deflection is related to aileron deflection 8A by X-body velocity 306.22 ft/sec Y-body velocity 54.15 ft/sec Z-body velocity -28.14 ft/sec (4) 8xR = max {0, 32 x Roll angle -75 deg x Pitch angle -22 deg x Yaw angle 25 deg where 8A and 8xR are expressed in degrees. The left spoiler Roll rate -4.69 deg/sec mirrors this, deflecting when the aileron deflection is nega- Pitch rate 8.59 deg/sec tive. This relationship is not differentiable and, so, should Yaw rate -12.60 deg/sec confidently be expected to cause difficulty in optimiza- x Vertical acceleration 2.0 g tion computations which require a guarantee of adequate x Longitudinal acceleration -0.35 g smoothness for convergence. The aileron/spoiler linkage is e_, eR 1.64 modelled smoothly by driving the spoiler deflections from the aileron rate command CYA, modified by a squashing func- tion on 8A. Again, for the right spoiler, These quantities were imposed as initial conditions on the trajectories discussed in the next section. Not shown are control surface initial conditions that were defined as a re- 32 1 (5) gxR = T_cYA1 + exp{25 - 208A} sult of the acceleration terms in Table 1.
The trajectory optimization results in the following section It should be noted that the vehicle model from [ 1,2] included were obtained by approximating the solution of the plant a number of logical branches in which calculated quan- equations by collocation, using a midpoint Euler discretiza- tities changed discretely as vehicle states passed thresh- tion formula that provides 2hal-order accuracy, with equally olds. These were carried into the optimization model, but spaced integration intervals. The optimization computa- smoothed using appropriately defined squashing functions.
tions were carried out using the SNOPT 5.3 [7] nonlin- ear programming code. Gradients of dynamics and con- straints were supplied to SNOPT analytically, and were ob- 3 Trajectory Optimization Formulation tained by applying the ADIFOR 2.1 [8] FORTRAN differ- entiation package to the source code that defines the plant In September 1994, a Boeing 737-300 aircraft, USAir Flight model, constraints, and cost function. The organization of 427, crashed on approach to Pittsburgh after encountering the various elements of this trajectory optimization prob- the vortex wake field of a passing 727 aircraft. Results from lem, including discretization, constraints, boundary condi- a simulation study of this 737, reconstructed from the re- tions, cost function, ADIFOR-generated gradients, and the covered flight data, indicated that the crash may have been call to SNOPT is managed by MADS4.3 [9], a FORTRAN due to adverse yaw moments caused by a stuck rudder [5].
90/77 code developed at Langley Research Center.
This specific aircraft incident was selected as the testcase for the work reported in this paper. It should be noted that the The key performance issue in recovery of safe flight is to USAir 427 aircraft was a 737-300, rather then the uniquely recover while losing as little altitude as possible in order short-bodied Langley 737-100 used in this study. The "300" to avoid ground contact and without violating airframe is larger all around, with more powerful engines. Because and crew safety acceleration placards. This certainly makes a solution for the stuck rudder case in which the ailerons
selection ofthe cost function simple; i.e.maximize terminal
altitude. Since the aircraft isinitially traveling downward, a and spoilers are linked, and which satisfies the placards in
nonpositive altitude rate Table 2. This difficulty highlights the importance of los-
ing a control effector in an aircraft with negligible control redundancy.
h_<O (6) Figures 1-9 display features of the recovery trajectories for the no-failure cases, computed using 40 integration inter- is imposed throughout the trajectory, in order to assure a vals. The solid lines correspond to independent spoilers meaningful solution. After the solution is obtained, it is and the dash-dotted lines to coupled aileron/spoilers. The verified that (6) is never an active constraint on the solution.
dashed lines, on the control surface histories, are their posi- The acceleration placards constraining the recovery trajec- tion limits. The maneuver is short in duration, lasting less tories are given in Table 2.
than 5 seconds, and loses roughly 400 feet in altitude. It is also somewhat extreme, as can be seen from the accel- Table 2. Acceleration Placards ration and euler angle plots. Unsurprisingly, allowing the spoilers to move independently enhances the performance; Z-body acceleration +/- 2g in this case, by roughly 6%. Note that, the flaps are ag- Y-body acceleration +/- 1.5g gressively used, decreasing 12and enhancing lift. This turns Y-body acceleration rate +/- 2g/sec out to be very important to recovering the vehicle. We have not been successful in computing a no-failure recovery ma- Having defined cost function, initial conditions, and plac- neuver that satisfied acceleration placards with realistically ard constraints, there remains termination of the recovery coupled aileron/spoiler, without using flaps. Interestingly, it maneuver. Because of the degraded controllability of an looks as though the pilot could simply turn them on, then aircraft with control effector failures, it may be difficult or off at the outset of the maneuver, freeing his or her hands to impossible to bring the aircraft to a steady trim condition; wrestle with the yoke and throttles. This may, on examina- furthermore, even if trimmed flight is possible, it may occur tion of further upset scenari, generalize to a trainable pilot after the minimum altitude in the recovery trajectory has action for recovering control.
passed. Therefore, the terminal condition for these trajecto- ries was selected as Figures 10-19 display corresponding data for recovery (with independent spoilers) for the same initial conditions, but in- cluding a rudder hardover failure. Two trajectories are pre- sented. The optimized trajectory for maximizing altitude 17 2 0 resulted in undesirable responses in the accelerations (Fig- _ _< 0 (7) ures 14 and 15). In order to determine the importance of
h:°/ oo __ o
these extraneous-looking temporal features, the trajectory was recalculated, adding a integral penalty on the sum of the squared control surface rates, scaled by 10 2. This was seen to have a fairly negligible effect on performance. In the where % 0, and 0 are the euler angles. In other words, the Figures, the dash-dotted lines depict response without the aircraft has stopped descending, and has a non-negative en- control rate penalty and the solid lines are the response with ergy rate. If the airframe is rotating, it is rotating back to it. Additionally, obeying the trajectory optimization rule of a centered position. This appears to ensure that the aircraft thumb that it is easier to solve a problem where the plant can be flown from the terminal point of the recovery maneu- can meet the constraints easily than one where it can not, ver without losing more altitude.
the object of the optimization problem was inverted from maximizing final altitude for a fixed rudder deflection to maximizing constant rudder deflection for a fixed final al- 4 Upset Recovery titude. This permitted variation of the rudder setting during the iterations, and dramatically eased the solution process.
In this section, two main scenari are considered. First, re- For an altitude loss of 4190 It, the maximized rudder de- covery from the initial conditions of Table 1 with minimum flection without the control rate penalty was 17.61 deg., and altitude loss is calculated with a healthy set of control effec- with it was 17.54 deg.; both of which correspond well to tors, to serve as an ideal baseline against which to consider 17.6 deg at which the data in Table 1 were drawn.
the case of the rudder hardover suggested by [5]. In analyz- ing the "healthy" case we, in fact, consider two subscenari The Figures show a trajectory that is startlingly different recovery with the ailerons and spoilers linked using (5), from the no-fail case on several counts. First, the trajec- and again, allowing the spoilers to operate independently of tory duration is an order of magnitude larger. As can be the ailerons. This was done because, at the time of writing, seen from Figure 10, after the initial altitude loss, there is the authors are still wrestling with the problem of obtaining a leg where altitude is almost unchanged for the rest of the 7. Gill, P.E., et. al., User_' GuideJor SNOPT 5.3." A trajectory. This occurs shortly after 20 sec, and the change FORTRAN Package Jor Large-Scale Nonlinear Pro- can be seen in the euler angle histories, as the aircraft labo- gramming, May 20, 1998.
riously brings itself to a sustainable attitude. Although the 8. Bischof, C., et. at., ADIFOR 2.0 Users' Guide (Re- aircaft speed is slowing down during the latter portion of the vision D), Mathematical, Information, and Computa- maneuver, the terminal l_ value is slightly positive, thus sat- tional Sciences Division, U.S. Department of Energy, isfying the terminal energy rate condition. During the whole Technical Memorandum No. 192, June 1998.
of the maneuver, the vehicle wallows, with oscillating nor- mal and side accelerations of smaller magnitude than was 9. Moerder, D.D. and Khong, T.H., MADS 4.3 Users' seen in the no-fail case, consistent with the reduced avail- Guide, November 2000, Draft Report - to be pub- ability of control authority. It is interesting to note that there lished.
is almost no use of the flaps in this case. Instead, the inde- pendence of the spoilers is exploited, bringing them both up Independent Spoilers, Coupled Spoilers early on in the trajectory to accomplish the braking function.
550C 540C ,d IJ-530 c 5 Conclusions _-,520C Recovery of safe flight for a particular aircraft, in a specific 510C initial adverse condition has been examined, with and with- out a specific control failure. It was seen that under optimal 50( 28 0.29 0.3 0.31 0.32 0.33 circumstances, the adverse vehicle state could be corrected Mach Number with little altitude loss. In addition, a control failure which proved fatal in practice was corrected, assuming indepen- Figure 1: No Failure Mach Number vs. Altitude.
dently acting spoilers. Generalizing these results to a com- prehensive set of upset scenari will be time consuming, but Independent Spoilers, Coupled Spoilers could offer valuable heuristic piloting insights.
2c c 6 References _-2c 1.
TCV/User Oriented FORTRAN ProgramJbr the B 73 7 o -4C Six DOF Dynamic Model, Sperry Systems Manage- -6C ment, Report No. SP-710-021, March 1981.
-8C 2.
Goodwin, A.E., NASA 515 Flight Control System Tim_ R_c Description RSFS Aircraft, Boeing Commercial Air- plane Co., Report No. D6-34279, Vol. 1-2, Sept.
Figure 2: No Failure Roll Angle.
1976.
3.
U.S. Standard Atmosphere, 1976, NOAA, NASA, Independent Spoilers, Coupled Spoilers 2C USAF, Oct. 1976.
1C 4.
Moerder, D.D. Linear-Quartic Chamfer Splines for Efficient Smooth Modelling of Tabular Data, NASA c TM to be published.
-1C a. -2C 5.
Parks, E.K., et. al., "Reconstruction of the 1994 Pitts- burgh Airplane Accident Using a Computer Simula- -3C tion", AIAA Journal of Aircraft, Vol. 35, No. 5, Sept.
-4C 2 4 6 - Oct. 1998, pp. 665-670.
Tim,_ _,_," 6.
Uncontrolled Descent and Collision with Terrain, Figure 3: No Failure Pitch Angle.
USAIR Flight 427, Boeing 737-300, N513AU Near Aliquippa, Pennsylvania, September 8, 1994, Na- tional Transportation Safety Board, NTSB/AAR- 99/01, Mar. 1999.
Independent Spoilers, -.- Coupled Spoilers Independent Spoilers, -.- Coupled Spoilers
40 I
_3o m i _20 >'10 -0 1 2 3 4 Tim_ £_c
Oo
2 4 6 Tim_ R_c Figure 8: No Failure Right Spoiler.
Figure 4: No Failure Yaw Angle.
Independent Spoilers, -.- Coupled Spoilers Independent Spoilers, -.- Coupled Spoilers a _20 < 0 10 _--- o
2 3
z_ 2 Tim_ R_c -3 _: 0 1 2 3 4 Figure 9: No Failure Flaps.
Tim_ R_c Figure 5: No Failure Normal Acceleration.
Wilh Penalty, No Penalty 600C 500C Independent Spoilers, -.- Coupled Spoilers I'& 400 c _.3ooc 200C _o 100 0.3 0.4 0.5 Mach Number -1 Figure 10: Stuck Rudder Altitude vs. Mach.
-20 1 2 3 4 Tim_ £_c Wi_ Penal_, No Penal_ 4O Figure 6: No Failure Side Acceleration.
2O _-20 Independent Spoilers, Coupled Spoilers Ez -40 -60 -80 Vim*,s**.
20 40 60 Figure 7: No Failure Aileron.
Figure 11: Stuck Rudder Roll Angle.
Wilh Penalty, No Penalty With Penalty, No Penalty 10 3O 2O 6 lO _-10 _-20 " -30 >L ................................
-40 -20 -30 -500 20 40 60 10 20 30 40 Tim_ R_r Tim_ R_t- Figure 12: Stuck Rudder Pitch Angle. Figure 16: Stuck Rudder Aileron.
With Penalty, No Penalty Wilh Penalty, No Penalty 4o 3O 2O " 10 >" 0 -10 -200 20 40 60 00 10 20 30 40 Tim_ R_c Tim_ R_c Figure 13: Stuck Rudder Yaw Angle.
Figure 17: Stuck Rudder Right Spoiler.
With Penalty, No Penalty With Penalty, No Penalty 40[ ,, _2 i i!
< 0 .._ &20 E-1 o Z -2 "_10 -3 0 10 20 30 0_ 4O 10 20 30 Tim_ R_c Timo_ Ro_c Figure 14: Stuck Rudder Normal Acceleration.
Figure 18: Stuck Rudder Left Spoiler.
With Penalty, No Penalty With Penalty, No Penalty 3o ............................
42o I:1 _o EIO -1 -2 10 20 30 40 10 20 30 4O Tim_ R_c Timo_ Ro_c Figure 15: Stuck Rudder Side Acceleration. Figure 19: Stuck Rudder Flaps.