control//fault diagnosis//fault
A fault is an unpermitted deviation of at least one property of a system from its acceptable condition (a pressure sensor reading 0.3 bar high, a motor delivering 20 % less thrust) while the system still performs its function, only worse; the word exists so that engineers can name what fault diagnosis looks for before anything breaks. A **failure** is the loss of the ability to perform the function: the drone falls, the pump stops pumping. These are the definitions of the IFAC diagnosis community, and every plant has its own dialect for them.
A fault is an unpermitted deviation of at least one property of a system from its acceptable condition (a pressure sensor reading 0.3 bar high, a motor delivering 20 % less thrust) while the system still performs its function, only worse; the word exists so that engineers can name what fault diagnosis looks for before anything breaks. A failure is the loss of the ability to perform the function: the drone falls, the pump stops pumping. These are the definitions of the IFAC diagnosis community, and every plant has its own dialect for them.
All of diagnosis lives in the gap between the two. The earlier the fault is seen, the more options remain: order the spare part, wait for Sunday's planned stop, reduce the load, land at the next field. Once the failure arrives the only option left is repair.
A tyre losing pressure slowly is a fault; the blowout on the motorway is the failure.
The car drives normally the whole time in between, a little heavier on fuel, and the pressure warning exists to make that interval usable.
Faults are classified three ways, and each classification changes the tool:
By where they occur: in a sensor (bias, drift, a frozen value), in an actuator (a weak motor, a sticking valve) or in the process itself (a leak, a worn impeller, a fouled heat exchanger).
By their shape in time: abrupt (a step, a cable snapping), incipient (a slow drift from wear, fouling or ageing) and intermittent (a loose connector that comes and goes, the workshop's nightmare because it never reproduces on the bench). An abrupt fault suits a detection threshold, an incipient one needs accumulated evidence (CUSUM) or a trend on a health indicator, an intermittent one needs events counted over weeks with timestamps.
By how they enter the model of the system, added to a signal or changing its dynamics (fault model).
A fault masked by redundancy is still a fault. A failed channel in a triplex system changes nothing visible, and unless something detects it the system flies on with less redundancy than its designers counted on; such latent faults are why redundant systems run self-tests.
In software dependability the vocabulary differs: a fault (a bug) causes an error (a wrong internal state) that may lead to a failure. The control sense used here puts the deviation in the physical system.
A fault with intent is an attack: someone alters measurements, commands or code and, if competent, makes sure the detector stays quiet (cyber-physical security).