PSA truncation: small cut sets, omitted mass and convergence evidence

Evaluate what cut-set truncation removes, separate omission error from overlap approximation, and check the quantities that matter to the intended decision.

On this page

A large fault-tree or event-tree model can generate many small contributions. Truncation limits computation by retaining only contributions that meet a chosen criterion. That can be practical, but a small individual cut set does not imply a small total omitted contribution. A defensible result explains what was excluded, how the remaining logic was quantified and what evidence shows that the omission does not materially change the intended use of the model.

State exactly what is being truncated

NASA’s Fault Tree Handbook, section 6.3 discusses truncation of low-probability minimal cut sets and error bounds. A probability threshold, an event-count or order limit, and a sequence-frequency threshold are different criteria. State which object is being screened and the units of the comparison.

A cut set identifies a combination of basic events sufficient for the top event in the specified logic. Its individual probability is not automatically its unique contribution to the top-event union, because cut sets can overlap. The truncation procedure and the numerical method for combining retained sets should therefore be described separately. A threshold value without those definitions is difficult to interpret or reproduce.

See how many small contributions can matter

Consider an explicitly hypothetical partition in which a retained event has probability 0.000020 and 1,000 omitted events each have probability 0.000000010. Assume all these events are mutually exclusive. The omitted total is 0.000010, and the complete probability is 0.000030. The omitted portion is one third of the complete value, despite every excluded event being individually very small.

The example is a probability-partition illustration, not an assertion that ordinary minimal cut sets are mutually exclusive. It demonstrates the danger of judging total error from the threshold alone. If the number or structure of omitted events is unknown, the largest allowed individual contribution does not by itself bound the omitted total. The tool’s stopping rule needs a mathematical interpretation.

Use a valid union bound when exact omission is unavailable

The union bound in MIT’s probability notes states that the probability of a union cannot exceed the sum of the individual probabilities. Let R be the union of retained events and O the union of omitted events. The added probability from the omitted portion is P(O and not R), which is at most P(O), and therefore at most the sum of the omitted event probabilities.

This bound does not require independence. It does require valid probabilities for the omitted events and knowledge of the set being bounded. If all N omitted events each have probability at most τ, their union is at most min(1,Nτ). Without a justified N or an equivalent bound from the generation algorithm, reporting τ as the total error is unsupported. A broad upper bound can be valid yet too loose for the decision.

Separate overlap from truncation

Take independent basic events A, B and C with probabilities 0.010, 0.020 and 0.030. Suppose the top event is AB or AC. The two cut-set probabilities are 0.000200 and 0.000300. Their simple sum is 0.000500, but their overlap ABC has probability 0.000006. The exact top-event probability is therefore 0.000494.

A cutoff that retains only contributions at least 0.000250 keeps AC and discards AB. Its exact retained probability is 0.000300. Restoring AB adds 0.000194, rather than the full 0.000200, because the shared overlap was already covered. A calculation can therefore have both omitted-contribution error and a separate overestimate from summing overlapping retained cut sets. Those errors must not be assumed to cancel safely.

Test convergence using consistent nested calculations

In the small example, lowering the cutoff to 0.000150 retains both sets and recovers 0.000494 when the union is quantified exactly. With a fixed model, fixed probabilities, nested retained event sets and exact union calculation, adding retained events cannot decrease the retained probability. This monotonicity is a useful diagnostic, subject to those stated conditions.

Record the threshold, retained-set count, numerical result and available error bound at each stage. Keep the quantification method and input model consistent while assessing truncation. If a software option also changes success-branch treatment, approximation order or input data, a changed result cannot be attributed to the cutoff alone. Repeatability requires more than saving the displayed threshold.

The high cutoff retains AC at.000300. A lower cutoff also retains AB, raising exact union to.000494. AB has.000200 probability but .000006 overlaps the already retained AC, so newly recovered unique mass is.000194.
Original exact-union budget bars at 500,000 drawing units per probability. Teal is AC-only .000294, the 3-unit rust strip is ABC .000006, and white is AB-only .000194. Cutoffs act on individual cut-set probabilities with a retain-at-or-above rule. This independent-basic-event teaching model separates omission from overlap; ordinary cut sets are not assumed mutually exclusive. It supplies no universal cutoff or bound on unmodeled physical risks.

Check importance and comparisons, not only the total

Čepin’s truncation research abstract reports that truncation can affect importance measures and risk-informed decisions. A total top-event probability that appears stable does not ensure that every contributor ranking or change estimate is equally stable. A small omitted family can be concentrated around one component or one proposed modification.

If the intended decision compares alternatives, evaluate the difference and relevant importance measures under tighter settings as well as the two totals. Relative error can become large when the quantity of interest is a small difference between similar totals. A tolerance suitable for one headline probability is not automatically suitable for identifying the benefit of a narrowly targeted change.

Revisit screening under parameter uncertainty

A cut set screened at nominal inputs can become more important when uncertain parameters change. For example, an original product of 0.000000010 becomes 0.000001 if one factor increases one hundredfold while the other factors and model stay fixed. Whether that change is plausible depends on the input evidence; the arithmetic merely shows why nominal screening is not automatically valid throughout an uncertainty range.

If a retained cut-set list is reused for every uncertainty sample, the calculation needs evidence that omitted sets remain negligible over the relevant domain or a method that accounts for their possible contribution. Increasing the Monte Carlo sample count only refines the uncertainty calculation on the list supplied. It does not regenerate combinations that were excluded before sampling began.

Keep numerical completeness separate from model completeness

An exact calculation of the retained Boolean model can still omit a physical failure mode, wrong alignment or common dependency. Conversely, a physically appropriate model may be quantified too coarsely. Review both layers. A small numerical error bound cannot be presented as a bound on total uncertainty in the real system.

The same distinction applies to a supposedly exact alternative representation. It may calculate the probability of the supplied static logic without truncation, while the logic or input dependence assumptions remain limited. Numerical method claims should identify the model they apply to. They do not establish that a maritime scenario model includes every relevant hazard or consequence.

Report an error statement that can be assessed

A useful truncation record includes the criterion, units, model and data version, retained-set definition, overlap treatment, convergence results and any formal or empirical error evidence. Explain which result was checked: total probability, sequence frequency, ranking, sensitivity or alternative comparison. An unresolved omission bound should remain visible as a limitation.

The aim is computational efficiency with enough evidence for the intended analysis. There is no universal cutoff that makes every maritime model adequate. The threshold earns its justification through the structure of the model and the stability or bounds of the quantities being used, rather than through the number of zeros printed after the decimal point.

Sources