Knowledge / Risk and reliability
FTA minimal cut sets: reducing logic without losing failure paths
Reduce a fault tree with repeated events, prove minimality and use counterexamples to distinguish a compact expression from a complete engineering model.
On this page
A minimal cut set is a smallest sufficient combination of basic failures for a defined top event. Smallest means that no member can be removed while retaining sufficiency; it does not mean the combination has the fewest members among every possible route. For ship systems, the useful result is often the discovery that apparent redundancy still shares one vulnerable support. Boolean reduction exposes that structure, but it cannot discover a failure mechanism that the original model omitted.
Define the function before reducing the tree
Consider an invented seawater service with two delivery trains. Either train can supply the entire required flow at the specified head during one demand. Let A mean local failure of train 1 and B local failure of train 2. Let C mean loss of a common electrical supply, which defeats both trains. Let D mean blockage of an alternative shared delivery arrangement that matters only when train 1 is unavailable. These are deliberately simplified event definitions, not a description of an installed system.
The assumed top-event logic is T = (A OR C) AND (B OR C), OR (A AND D). Parentheses are essential: the first branch is simultaneous loss of the two delivery trains, and the second is the separately stipulated A-and-D failure path. If the actual piping does not support that second path, the equation must change before any algebra begins. The NRC handbook provides the underlying cut-set and Boolean framework.
Expand first, then apply absorption
Use + for OR and juxtaposition for AND. Distributing the first branch gives AB + AC + BC + CC. A repeated occurrence of C is the same event, so CC = C. Absorption then gives C + AC = C and C + BC = C. Including the second branch leaves T = C + AB + AD, or equivalently C + A(B + D).
These are identities in event logic. They do not require independent failures, small probabilities or a numerical failure-rate database. The expression is true for exactly the same assignments of A, B, C and D as the original tree. Probability assumptions enter later. Replacing CC with C² would confuse an event appearing twice with two independent events that happen to share a label.
Prove each minimal cut set
The minimal cut sets are {C}, {A,B} and {A,D}. C alone makes T true. A and B together also make it true when C and D are false, but neither A alone nor B alone does so. The same removal test applies to {A,D}. There is no requirement that all minimal sets have equal size; a one-event set can coexist with two-event sets.
The combination {A,B,D} is a cut set, but not minimal, because it contains {A,B} and {A,D}. Removing this redundant description does not remove an accident possibility. The state A=B=D=true is still included in both retained sufficient paths. Minimal-set reduction removes duplicated logical descriptions, not the physical failures represented by those descriptions.
Check equivalence with concrete states
Four binary events generate 2⁴ = 16 possible assignments. Evaluate the original and reduced expression for all sixteen; their results must match. Useful hand checks include C=true with every other event false, A=true alone, B=D=true with A=C=false, and A=D=true with B=C=false. The respective top-event results are true, false, false and true.
Exhaustive comparison verifies algebra for this small model. It does not establish that two trains really have sufficient capacity or that the chosen failure definitions cover flooding, maintenance and fire. Keep these two checks separate: equivalence is a property of equations, while model adequacy is a property of the relationship between those equations and the engineering question.
Maintain one identity for one event
A common supply failure drawn on two branches must retain one identifier. Giving it identifiers C1 and C2 solely because it appears twice creates fictional independence during later quantification. Conversely, merging two genuinely different failures into C may create a fictional single-point weakness. Event identity should follow the physical mechanism, location, mission and failure mode.
The same pump failing to start and failing after an hour of running are not automatically the same event. A valve failing closed and failing open can be incompatible states under a defined observation, while failures occurring at different times need a temporal model. A naming dictionary should resolve those distinctions before a software package merges repeated symbols.
Use the result to question redundancy
The singleton {C} says that local improvements to A or B cannot eliminate every modeled failure route. It directs attention to the common supply, but does not prove that duplicating electrical hardware is the best intervention. A new supply could still share cooling, switchboard space, protective logic or a maintenance error with the old one. Proposed changes require a revised physical model.
The shared A in {A,B} and {A,D} also matters. Improving A affects two routes, but the magnitude of the benefit depends on probabilities and dependencies. Merely counting how often a component appears in cut sets is not a defensible risk ranking. A rare three-event set can matter less than a frequent two-event set, or vice versa.
Keep probability and truncation outside the proof
After the logical result is established, cut-set probabilities can be calculated using an appropriate joint model. AB and AD overlap when A, B and D occur together. Their probabilities cannot generally be added as though they describe separate populations. Reduction has removed logical supersets, but it has not made the remaining minimal sets mutually exclusive.
Large models often discard sets below a probability cutoff. That is a numerical approximation, not Boolean absorption. Record the threshold and show that discarded contributions cannot change the decision materially. A minimal cut set with many members is not automatically negligible, especially when those members share a cause or an operating condition.
Understand where a static cut set stops helping
An ordinary coherent fault tree treats failures as conditions that can only make the top event more likely when introduced. If success of one item can itself create a hazard, or a protective action must occur before another event, simple positive-event reduction may not capture the question. Complemented events, state models or sequence analysis can be necessary.
For example, loss of both running pumps at the end of a mission differs from failure to maintain uninterrupted cooling throughout that mission. A spare starting late may satisfy an eventual running-state test while violating continuity. Neither a short cut-set list nor a matching truth table repairs an incorrect top-event time boundary.
Derive the gate from capacity, not the equipment count
A useful boundary challenge is a three-pump arrangement. If any one pump supplies the required function, service is lost only when all three are unavailable: the local failure expression is XYZ. If two pumps are required simultaneously to meet the same duty, any pair of failures is sufficient, giving XY OR XZ OR YZ. The equipment count is unchanged, but the minimal cut sets and their orders are different.
Write the flow and head requirement that determines which case applies. A pump that supplies enough volume at one head may be insufficient at another; degraded performance can therefore be a failure of the required function without being a complete mechanical stoppage. Do not infer a gate from a drawing that simply shows three parallel symbols. Capacity, common routing and operating state establish the logic. This check is especially useful when a model is copied from a similar vessel whose duty or piping resistance differs.
Preserve a reason for every excluded path
An excluded event should have a reason tied to the scope: it may be physically impossible in the defined configuration, outside the stated mission or handled in another linked model. “Not previously observed” is a data statement and does not itself establish impossibility. Likewise, an undeveloped event is a known modeling boundary, not an event with zero probability.
Review exclusions after a change in capacity, supply arrangement or maintenance practice. A path that was impossible with a permanently disconnected branch can become credible after a temporary connection is introduced. Keep the exclusion rationale close to the event dictionary so a later analyst can see which physical facts supported the reduced tree. Algebra preserves the logic that was supplied; it cannot preserve a rationale that was never recorded.
Deliver a reduction another analyst can reproduce
Retain the top-event wording, event dictionary, original expression, reduction steps and final sets. Include the capacity and operating-state assumptions that make each AND gate appropriate. The NASA handbook discusses alternative qualitative representations, including binary decision diagrams; a compact representation is useful only when its event semantics remain traceable.
A good review asks for a counterexample: a credible system state that fails the real function while making the modeled top event false. Finding one means the model needs extension. Failing to find one is useful evidence, not proof of completeness. The example here teaches algebra and interpretation; it supplies no vessel reliability estimate or approval to remove a protective feature.
Sources
- Fault Tree Handbook, NUREG-0492 · US Nuclear Regulatory Commission · Source check date: 2026-10-06
- Fault Tree Handbook with Aerospace Applications · NASA · Source check date: 2026-10-06