systems engineering//hazard analysis//fault tree analysis
Fault tree analysis is a top-down method of hazard analysis that starts from one undesired event (the **top event**: loss of thrust in flight, overpressure in a reactor) and breaks it down through logic gates into the combinations of basic failures that can cause it, and it is used in aerospace, nuclear, rail and process safety to find which combinations matter and to compute how probable the top event is. Where an FMEA asks what each part's failure does, the fault tree asks what could make this one thing happen.
Fault tree analysis is a top-down method of hazard analysis that starts from one undesired event (the top event: loss of thrust in flight, overpressure in a reactor) and breaks it down through logic gates into the combinations of basic failures that can cause it, and it is used in aerospace, nuclear, rail and process safety to find which combinations matter and to compute how probable the top event is. Where an FMEA asks what each part's failure does, the fault tree asks what could make this one thing happen.
The gates carry the logic. An OR gate fires if any input fails: a drone loses thrust on one arm if the motor fails, or its ESC fails, or the propeller breaks. An AND gate fires only if all inputs fail together: a plant loses cooling if both pumps fail. With independent basic events of probability pip_ipi, an AND multiplies and an OR, for small probabilities, very nearly adds:
PAND=∏ipi,POR=1−∏i(1−pi)≈∑ipi.P_{\text{AND}}=\prod_i p_i,\qquad P_{\text{OR}}=1-\prod_i(1-p_i)\approx\sum_i p_i .PAND=i∏pi,POR=1−i∏(1−pi)≈i∑pi.
Two pumps each unavailable 1% of the time give a cooling loss of 0.01%, a hundred times better than one pump; that number is what the redundancy buys, and the tree shows it on paper.
The tree's real output is its minimal cut sets, the smallest combinations of basic events that bring the top event about. A cut set of one is a single point of failure; a cut set of two that share a cause (both pumps on one power bus, both sensors in one connector) is a redundancy that exists only on the drawing (common-mode failure).
Its numbers inherit the independence assumption. The multiplication under an AND gate is valid only if the two failures have no common cause, and the commonest error in a fault tree is a product of small probabilities that a shared supply, a shared software version or a shared maintenance technician makes much larger. Analysts add common-cause terms explicitly for this reason.
It needs failure rates for the basic events, from field data, a Weibull distribution fitted to the plant's own records or a handbook, and its result is only as good as those rates; the tree's structure (which combinations exist) is often more valuable than its final probability.
It looks for what breaks. Hazards that arise with every part working (a controller acting on a stale value, two correct subsystems interacting badly) do not appear in it, which is the case STPA was built for; a design whose tree shows what to duplicate continues in redundancy and majority voting.