提出JTA架构,系统化提升关键场景验证的可控性、可观测性与可归因性。
JTA: Joint Testability Architecture for Scenario-Based Validation of Safety-Critical Software

- 将测试场景、测试系统与被测系统统一为可分析对象,构建三维度评估框架。
- 在ArduPilot验证中发现链路丢失场景成熟,状态估计异常场景证据对齐弱。
- 提供场景契约与设计改进路径,适合自动驾驶等安全关键系统验证。
安全关键软件的验证充分性不仅取决于被测系统。关键场景需在受控条件下构建,执行证据需转化为可判别形式,异常结果须可归因于具体原因。现有测试性研究多聚焦于单一构件,缺乏对场景、测试系统与被测系统协同能力的架构支持。联合可测性架构(JTA)通过将三者视为整体分析对象,从可控性、可观测性、可隔离性三个维度建模,并通过三个领域、三条桥梁及设计-评估-优化循环组织。引入场景契约、联合能力评估、验证盲区识别和桥接导向设计动作,将能力缺口映射至控制点、证据组织与归因边界的具体改进。以ArduPilot失效保护验证为例,链路丢失场景相对成熟,而状态估计异常场景因证据对齐与归因语义较弱仍难验证。JTA并非替代现有测试或安全分析方法,而是为安全关键软件的基于场景验证提供架构基础。
原文摘要 · Abstract (English)
Validation adequacy in safety-critical software depends on more than the system under test. Critical scenarios must be constructed under controlled conditions, execution evidence must be aligned into verdict-ready form, and abnormal outcomes must be attributable to actionable causes. Existing testability research remains largely artifact-centric and offers little architectural support for reasoning about the combined capability of the scenario, the test system, and the system under test. Joint Testability Architecture (JTA) addresses this gap by treating those three elements as a single object of analysis and design. It characterizes validation capability along three dimensions--controllability, observability, and isolability--and organizes them through three domains, three bridges, and an analysis-design-evaluation-refinement loop. JTA also introduces scenario contracts, joint capability assessment, validation blind-spot identification, and bridge-oriented design actions that map capability gaps to concrete improvements in control points, evidence organization, and attribution boundaries. An illustrative analysis of ArduPilot failsafe validation shows that link-loss scenarios are comparatively mature, whereas state-estimation anomaly scenarios remain harder to validate because evidence alignment and attribution semantics are weaker. JTA is not a replacement for existing testing or safety-analysis techniques; it provides an architectural basis for modeling, designing, and assessing scenario-based validation in safety-critical software.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。