Knowledge / Risk and reliability
FTA probabilities: rare-event approximation and overlapping cut sets
Compare exact unions, rare-event sums and probability bounds using two overlapping cut sets, including a case where small cut-set probabilities still mislead.
On this page
Adding minimal-cut-set probabilities is convenient, but the sum counts a state more than once when several cut sets are simultaneously true. The resulting error is controlled by overlap, not by the number of decimal places shown in the answer. A maritime fault tree can therefore produce a very small but materially biased result if one rare shared event sits inside several apparently separate failure paths.
Write the union before selecting an approximation
Let a hypothetical cooling-loss event be T = AB OR AC. A is an upstream isolation failure, while B and C represent two separately modeled downstream conditions. The minimal cut sets are K1={A,B} and K2={A,C}. Their intersection is ABC. Probability theory gives P(T)=P(AB)+P(AC)−P(ABC), without any independence assumption.
The NASA handbook presents set-based probability evaluation. Here the numerical example is independently constructed. It describes one defined mission or demand, so every input and output is dimensionless. An annual initiating frequency cannot be inserted into this equation in place of P(A) without first constructing a compatible time or event model.
Calculate the small-overlap case exactly
Assume A, B and C are independent, with probabilities 0.02, 0.03 and 0.04. Then P(AB)=0.0006, P(AC)=0.0008 and P(ABC)=0.000024. The exact top-event probability is 0.001376. Summing the two cut sets gives 0.0014, an absolute overestimate of 0.000024.
Relative to the exact result, the error is 0.000024/0.001376 ≈ 1.74%. Relative to the sum it is about 1.71%; always state the denominator when reporting a percentage error. The equivalent factored calculation is 0.02 × [1−(1−0.03)(1−0.04)]. Agreement between the inclusion–exclusion and factored forms provides an elementary calculation check.
Small cut-set probabilities do not guarantee small error
Now retain the same logic but use independent probabilities P(A)=0.001 and P(B)=P(C)=0.8. Each cut set has probability only 0.0008. Nevertheless, their intersection has probability 0.00064. The exact union is 0.00096, whereas the rare-event sum is 0.0016: a 66.7% overestimate relative to the exact value.
The rare A event gates both routes, so whenever one route is present the other is quite likely too. The cut sets are dependent even though their constituent basic events were stipulated independent. This constructed counterexample shows why a universal rule based only on every cut set being below a fixed small threshold is insufficient. Inspect the shared-event structure and actual intersection terms.
Use bounds with their correct meaning
For any collection of events, the union probability is no larger than the sum of their probabilities and no larger than one. It is at least the largest individual probability. Thus max P(Ki) ≤ P(T) ≤ min[1, ΣP(Ki)]. These bounds do not need independence, but they do require correctly evaluated individual cut-set probabilities.
Subtracting all pairwise intersections from the sum gives a second-order Bonferroni lower bound. With two sets this is exact; with more sets, triple intersections and higher terms remain. A negative lower bound can be replaced by zero, but its looseness is information: the chosen approximation is then not resolving the probability well enough for a sharp decision.
Do not mistake independent events for exclusive events
Independent events can occur together. Mutually exclusive events cannot. If B and C were alternative operating modes that could never coexist within the modeled observation, P(BC) would be zero and their union would be an exact sum. Treating those modes as independent would invent an impossible overlap. Conversely, separate equipment names do not establish either independence or exclusivity.
A useful check asks what one recorded demand could look like. Can the same demand satisfy both AB and AC? If yes, it belongs to their intersection. If failure records assign one primary cause to an event that had several contributing causes, the database may appear exclusive while the physical states are not. Quantification should follow the actual event definition.
A dependency error can overwhelm an approximation error
The product P(AB)=P(A)P(B) was justified only by the stated independence assumption. In general P(AB)=P(A)P(B|A). A shared flood, common electrical supply or maintenance state can make the conditional failure probability very different from the marginal value. Calling the subsequent union sum conservative does not correct an underestimated cut-set product.
For example, if P(A)=0.02 and P(B|A)=0.20, the AB probability is 0.004. Using a marginal P(B)=0.03 would give 0.0006 if independence were assumed, underestimating that path by more than sixfold. This separate teaching case cannot be combined with the previous independent model without redefining its joint distribution.
Distinguish mathematical error from input uncertainty
An exact Boolean probability can still depend on poorly known failure rates. Removing overlap error improves the calculation, not the evidence behind the inputs. Keep three uncertainties visible: whether the logic is adequate, whether the joint probabilities are supported, and whether the numerical solution approximates that chosen model sufficiently well.
Suppose an internal decision threshold for the first invented case lies between 0.001376 and 0.0014. The approximation could change the classification, even though its percentage error is small. This does not establish that the exact number is suitable for approval: plausible input ranges may be much wider. Compare the uncertainty interval and the calculation bounds with the criterion together.
Choose a solver and verify its settings
A binary decision diagram or other exact method can avoid explicit expansion of every overlap, subject to the probabilities and dependencies it supports. A cut-set engine may instead use a sum, inclusion–exclusion bounds or truncation. The SAPHIRE technical-reference summary identifies probability algorithms and importance evaluation as distinct documented capabilities; a software label alone does not identify the selected calculation.
Record the solver version, quantification option, cutoff and dependency treatment. Reproduce a small known case before trusting a large model. If the software returns 0.0014 for the first example, it may be faithfully executing a sum approximation rather than malfunctioning. The analyst still owns the choice and its suitability for the decision.
Check a three-cut-set union without dropping the final term
For another original example, let T=AB OR AC OR BC with the first case's independent values a=0.02, b=0.03 and c=0.04. The sum of cut-set probabilities is 0.0006+0.0008+0.0012=0.0026. Each of the three pairwise intersections equals ABC, and the triple intersection also equals ABC. Inclusion–exclusion therefore gives Q=ab+ac+bc−2abc=0.002552.
Subtracting the three pairwise intersections but forgetting the triple intersection would give 0.002528. That is a lower bound, not the exact answer. The same ABC state was originally counted three times, then removed three times, so it must be restored once. Following the count of one concrete state is often clearer than manipulating a long alternating series mechanically. A numerical solver should reproduce this small test before its overlap settings are trusted on a larger tree.
Separate a missing path from a discarded probability term
A solver's reported truncation error concerns paths represented in the input model but omitted from numerical evaluation. It cannot bound a common-cause path that was never modeled. Similarly, an exact answer under independence is not an exact answer for a dependent physical system. The word exact should always be followed mentally by “for this specified model.”
When a calculation changes after review, state whether the change came from improved arithmetic, revised data or new causal structure. Those explanations lead to different next steps. More precise arithmetic may settle an overlap issue; a newly identified shared utility may require reviewing many related trees. Keeping the causes of revision separate makes the numerical result easier to use and prevents a solver accuracy claim from becoming a claim of complete engineering knowledge.
Report the overlap that matters
A useful result states the mission boundary, exact or approximate method, largest shared-event groups, probability bounds and sensitivity to uncertain inputs. Report absolute and relative error separately. Do not label the sum a complete safety margin: it is only an upper bound for the correctly specified union of the correctly specified cut sets.
For a ship study, the practical implication may be that several apparent causes are one common-support problem. Solving the overlap correctly then changes both the number and the interpretation of priorities. These examples illustrate probability accounting; they neither assign real marine component probabilities nor define an acceptable level of navigational, personnel or environmental risk.
Sources
- Fault Tree Handbook with Aerospace Applications · NASA · Source check date: 2026-10-06
- SAPHIRE technical reference, NUREG/CR-6952 Volume 2 public abstract · US Nuclear Regulatory Commission / Idaho National Laboratory · Source check date: 2026-10-06