Functional Failure Mode, Effects and Criticality Analysis of Spacecraft Autonomous Collision Avoidance Systems
This study presents a qualitative Functional Failure Mode, Effects and Criticality Analysis of spacecraft autonomous collision avoidance systems, identifying 127 failure modes and prioritizing high-risk scenarios related to decision-making, data integrity, and resource management to propose targeted risk mitigation strategies.
Original paper licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
The sky above Earth is no longer empty. It is filled with a growing cloud of human-made objects, ranging from active satellites and rocket stages to tiny fragments of debris left behind by collisions and breakups. While the largest pieces can be tracked from the ground, millions of smaller fragments remain invisible to sensors yet travel at speeds fast enough to destroy a spacecraft on impact. To stay safe, satellites must constantly watch for these potential collisions. Traditionally, this has been a job for people on the ground: they track the objects, calculate the risk, decide if a satellite needs to move, and then send a command to fire its engines. But as space becomes more crowded and communication delays increase, waiting for a human to make every decision is becoming too slow. This has led to the development of autonomous systems, where the satellite itself must sense the danger, decide to move, and execute the maneuver without waiting for instructions from Earth.
The challenge with giving a satellite this much power is that it creates a complex chain of dependencies. If the satellite's sensors give a wrong reading, if its computer misinterprets the data, or if its engines fail to fire correctly, the result could be a catastrophic collision or a wasted maneuver that puts the satellite in a worse position. A new study by researchers from universities in France, Germany, and the United States examines exactly how these autonomous systems can fail. Instead of looking at a single piece of hardware, the team mapped out the entire process, from the moment ground stations first spot a potential threat to the moment the satellite confirms it has moved to safety. They treated the system not as a single machine, but as a distributed network of functions involving ground tracking, data exchange, onboard computing, and propulsion.
The researchers applied a rigorous safety analysis method to a representative design of such a system. They broke the operation down into thirty-four distinct functions, such as receiving tracking data, calculating the probability of a collision, planning a new path, and firing the thrusters. For each function, they asked a simple but critical question: how could this step go wrong? They identified 127 different ways the system could fail. These failures ranged from the ground station sending data too late, to the satellite's computer misreading a sensor, to the engines firing in the wrong direction or not at all. The team then evaluated the consequences of each failure. They looked at how likely each error was to happen, how hard it would be to detect before it caused harm, and how severe the outcome would be if it did occur.
The analysis revealed that the most dangerous failures are often the ones that go unnoticed. The highest-risk scenario identified was a "false negative" decision, where the satellite's computer correctly sees a threat but decides not to act, leaving the spacecraft on a collision course. This was followed closely by errors in validating incoming data, where the system accepts bad information as if it were true, or miscalculates the probability of a crash. The study found that time is just as critical as accuracy; even if the data is correct, if it arrives after the decision window has closed, the system is effectively blind. The researchers also found that the system is highly sensitive to the integrity of information. If the source of the data is unclear, if the units of measurement are mismatched, or if the time stamps are wrong, the entire decision-making process can collapse.
One of the most significant findings is that the safety of an autonomous system depends less on the perfection of its onboard software and more on the reliability of the information flowing through it. A physically healthy satellite can still make a fatal error if it is fed incorrect data from the ground or if it fails to verify that its engines actually moved it to the new position. The study highlights that the system must be designed to handle uncertainty conservatively. It cannot simply assume that a lack of a warning means safety, nor can it blindly trust every piece of data it receives. The researchers suggest that future systems need diverse sources of information, strict checks on data age and quality, and independent ways to verify that a maneuver was successful. They also emphasize the need for clear rules on who is in charge—the ground or the satellite—and how to handle situations where communication is lost.
The researchers did not claim to have solved the problem of space safety, nor did they provide a final checklist for every satellite. Instead, they provided a detailed map of where the risks lie in the current approach to autonomous collision avoidance. Their work shows that while giving satellites the ability to act on their own is necessary for the future of spaceflight, it introduces a new set of vulnerabilities that must be managed with extreme care. The study concludes that safety cannot be achieved by relying on a single algorithm or a single sensor. It requires a system that constantly checks its own work, validates the information it receives, and has a clear plan for what to do when things go wrong. As the number of objects in orbit continues to grow, understanding these failure modes is the first step toward ensuring that the satellites we rely on can survive in an increasingly crowded sky.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.