Skip to main content

\(\textsf{PFL}\): A Probabilistic Logic for Fault Trees

  • Conference paper
  • First Online:
Formal Methods (FM 2023)


Safety-critical infrastructures must operate in a safe and reliable way. Fault tree analysis is a widespread method used for risk assessment of these systems: fault trees (FTs) are required by, e.g., the Federal Aviation Administration and the Nuclear Regulatory Commission. In spite of their popularity, little work has been done on formulating structural queries about \(\textsc {ft} \textrm{s}\) and analyzing these, e.g., when evaluating potential scenarios, and to give practitioners instruments to formulate queries on \(\textsc {ft} \textrm{s}\) in an understandable yet powerful way. In this paper, we aim to fill this gap by extending \( BFL \) [37], a logic that reasons about Boolean \(\textsc {ft} \textrm{s}\). To do so, we introduce a Probabilistic Fault tree Logic (\(\textsf{PFL}\)). \(\textsf{PFL}\) is a simple, yet expressive logic that supports easier formulation of complex scenarios and specification of FT properties that comprise probabilities. Alongside \(\textsf{PFL}\), we present \(\textsf{LangPFL}\), a domain specific language to further ease property specification. We showcase \(\textsf{PFL}\) and \(\textsf{LangPFL}\) by applying them to a COVID-19 related FT and to a FT for an oil/gas pipeline. Finally, we present theory and model checking algorithms based on binary decision diagrams (BDDs).

This work was partially funded by the NWO grant NWA.1160.18.238 (PrimaVera), and the European Union’s Horizon 2020 research and innovation programme under the Marie Skłodowska-Curie grant agreement No 101008233, and the ERC Consolidator Grant 864075 (CAESAR).

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
USD 84.99
Price excludes VAT (USA)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD 109.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

Similar content being viewed by others


  1. 1.

    When considering conditional probabilities in layer-two and layer-three formulae, we disregard the case in which \(\varPhi ^*_\textit{T} (\mu _{\overline{\rho \,}}, \phi ') = 0\).


  1. Alur, R., Courcoubetis, C., Dill, D.: Model-checking in dense real-time. Inf. Comput. 104(1), 2–34 (1993)

    Article  MathSciNet  MATH  Google Scholar 

  2. Andersen, H.R.: An introduction to binary decision diagrams. Lecture notes, available online, IT University of Copenhagen, p. 5 (1997)

    Google Scholar 

  3. Bakeli, T., Hafidi, A.A., et al.: COVID-19 infection risk management during construction activities: an approach based on fault tree analysis (FTA). J. Emerg. Manage. 18(7), 161–176 (2020)

    Article  Google Scholar 

  4. Basgöze, D., Volk, M., Katoen, J., Khan, S., Stoelinga, M.: BDDs strike back - efficient analysis of static and dynamic fault trees. In: Deshmukh, J.V., Havelund, K., Perez, I. (eds.) NFM 2022. LNCS, vol. 13260, pp. 713–732. Springer, Cham (2022).

    Chapter  Google Scholar 

  5. Ben-Ari, M.: Mathematical Logic for Computer Science. Springer, Heidelberg (2012).

    Book  MATH  Google Scholar 

  6. Bieber, P., Castel, C., Seguin, C.: Combination of fault tree analysis and model checking for safety assessment of complex system. In: Bondavalli, A., Thevenod-Fosse, P. (eds.) EDCC 2002. LNCS, vol. 2485, pp. 19–31. Springer, Heidelberg (2002).

    Chapter  Google Scholar 

  7. Bobbio, A., Egidi, L., Terruggia, R.: A methodology for qualitative/quantitative analysis of weighted attack trees. IFAC Proc. Vol. 46(22), 133–138 (2013).

    Article  Google Scholar 

  8. Boudali, H., Crouzen, P., Stoelinga, M.: Dynamic fault tree analysis using input/output interactive Markov chains. In: DSN, pp. 708–717. IEEE Computer Society (2007).

  9. Bozzano, M., Cimatti, A., Katoen, J., Nguyen, V.Y., Noll, T., Roveri, M.: Safety, dependability and performance analysis of extended AADL models. Comput. J. 54(5), 754–775 (2011).

    Article  Google Scholar 

  10. Brace, K., Rudell, R., Bryant, R.: Efficient implementation of a BDD package. In: 27th ACM/IEEE Design Automation Conference, pp. 40–45 (1990).

  11. Budde, C.E., Dehnert, C., Hahn, E.M., Hartmanns, A., Junges, S., Turrini, A.: JANI: quantitative model and tool interaction. In: Legay, A., Margaria, T. (eds.) TACAS 2017. LNCS, vol. 10206, pp. 151–168. Springer, Heidelberg (2017).

    Chapter  Google Scholar 

  12. Budde, C.E., Stoelinga, M.: Efficient algorithms for quantitative attack tree analysis. In: 2021 IEEE 34th Computer Security Foundations Symposium (CSF), pp. 1–15 (2021).

  13. Clark, P., Harrison, P., Jenkins, T., Thompson, J.A., Wojcik, R.H., et al.: Acquiring and using world knowledge using a restricted subset of English. In: Flairs Conference, pp. 506–511 (2005)

    Google Scholar 

  14. Clarke, E.M., Emerson, E.A.: Design and synthesis of synchronization skeletons using branching time temporal logic. In: Kozen, D. (ed.) Logic of Programs 1981. LNCS, vol. 131, pp. 52–71. Springer, Heidelberg (1982).

    Chapter  Google Scholar 

  15. Conrad, E., Titolo, L., Giannakopoulou, D., Pressburger, T., Dutle, A.: A compositional proof framework for FRETish requirements. In: Proceedings of the 11th ACM SIGPLAN International Conference on Certified Programs and Proofs, pp. 68–81 (2022)

    Google Scholar 

  16. Corzilius, F., Kremer, G., Junges, S., Schupp, S., Ábrahám, E.: SMT-RAT: an open source C++ toolbox for strategic and parallel SMT solving. In: Heule, M., Weaver, S. (eds.) SAT 2015. LNCS, vol. 9340, pp. 360–368. Springer, Cham (2015).

    Chapter  MATH  Google Scholar 

  17. Crapo, A., Moitra, A., McMillan, C., Russell, D.: Requirements capture and analysis in ASSERT (TM). In: 2017 IEEE 25th International Requirements Engineering Conference (RE), pp. 283–291. IEEE (2017)

    Google Scholar 

  18. Cubuktepe, M., Jansen, N., Junges, S., Katoen, J.P., Topcu, U.: Convex optimization for parameter synthesis in MDPs. IEEE Trans. Autom. Control 67, 6333–6348 (2021)

    Article  MathSciNet  Google Scholar 

  19. Déharbe, D., Shankar, S., Clarke, E.M.: Model checking VHDL with CV. In: Gopalakrishnan, G., Windley, P. (eds.) FMCAD 1998. LNCS, vol. 1522, pp. 508–514. Springer, Heidelberg (1998).

    Chapter  Google Scholar 

  20. Dutuit, Y., Rauzy, A.: A linear-time algorithm to find modules of fault trees. IEEE Trans. Reliab. 45(3), 422–425 (1996)

    Article  Google Scholar 

  21. Ericson, C.A.: Fault tree analysis. In: System Safety Conference, vol. 1, pp. 1–9 (1999)

    Google Scholar 

  22. Gainer, P., Hahn, E.M., Schewe, S.: Accelerated model checking of parametric Markov chains. In: Lahiri, S.K., Wang, C. (eds.) ATVA 2018. LNCS, vol. 11138, pp. 300–316. Springer, Cham (2018).

    Chapter  Google Scholar 

  23. Giannakopoulou, D., Mavridou, A., Rhein, J., Pressburger, T., Schumann, J., Shi, N.: Formal requirements elicitation with FRET. In: International Working Conference on Requirements Engineering: Foundation for Software Quality (REFSQ-2020). No. ARC-E-DAA-TN77785 (2020)

    Google Scholar 

  24. Hahn, E.M., Han, T., Zhang, L.: Synthesis for PCTL in parametric Markov decision processes. In: Bobaru, M., Havelund, K., Holzmann, G.J., Joshi, R. (eds.) NFM 2011. LNCS, vol. 6617, pp. 146–161. Springer, Heidelberg (2011).

    Chapter  Google Scholar 

  25. Hansen, K.M., Ravn, A.P., Stavridou, V.: From safety analysis to software requirements. IEEE Trans. Software Eng. 24(7), 573–584 (1998)

    Article  Google Scholar 

  26. Hansson, H., Jonsson, B.: A logic for reasoning about time and reliability. Formal Aspects Comput. 6(5), 512–535 (1994).

    Article  MATH  Google Scholar 

  27. Hermanns, H., Krämer, J., Krčál, J., Stoelinga, M.: The value of attack-defence diagrams. In: Piessens, F., Viganò, L. (eds.) POST 2016. LNCS, vol. 9635, pp. 163–185. Springer, Heidelberg (2016).

    Chapter  Google Scholar 

  28. International Standardization Organization: ISO/DIS 26262: Road vehicles, functional safety (2018).

  29. Jimenez-Roa, L., Heskes, T., Tinga, T., Stoelinga, M.: Automatic inference of fault tree models via multi-objective evolutionary algorithms. IEEE Trans. Dependable Secure Comput., 1–12 (2021).

  30. Junges, S., et al.: Parameter synthesis for Markov models. arXiv preprint arXiv:1903.07993 (2019)

  31. Katoen, J.P.: The probabilistic model checking landscape. In: Proceedings of the 31st Annual ACM/IEEE Symposium on Logic in Computer Science, pp. 31–45 (2016)

    Google Scholar 

  32. Kumar, R., Stoelinga, M.: Quantitative security and safety analysis with attack-fault trees. In: Proceedings of the 18th IEEE International Symposium on High Assurance Systems Engineering (HASE 2017), pp. 25–32. HASE, IEEE, USA (2017).

  33. Kwiatkowska, M., Norman, G., Parker, D.: PRISM 4.0: verification of probabilistic real-time systems. In: Gopalakrishnan, G., Qadeer, S. (eds.) CAV 2011. LNCS, vol. 6806, pp. 585–591. Springer, Heidelberg (2011).

    Chapter  Google Scholar 

  34. Moszkowski, B.: A temporal logic for multi-level reasoning about hardware. Technical report, STANFORD UNIV CA (1982)

    Google Scholar 

  35. Nauta, M., Bucur, D., Stoelinga, M.: LIFT: learning fault trees from observational data. In: McIver, A., Horvath, A. (eds.) QEST 2018. LNCS, vol. 11024, pp. 306–322. Springer, Cham (2018).

    Chapter  Google Scholar 

  36. Nicoletti, S., Hahn, E., Stoelinga, M.: A logic to reason about fault trees. Interview Report.

  37. Nicoletti, S., Hahn, E., Stoelinga, M.: BFL: a logic to reason about fault trees. In: (DSN), pp. 441–452. IEEE/EUCA (2022).

  38. Ognjanovic, Z.: Discrete linear-time probabilistic logics: completeness, decidability and complexity. J. Log. Comput. 16(2), 257–285 (2006).

    Article  MathSciNet  MATH  Google Scholar 

  39. Pease, A., Murray, W.: An English to logic translator for ontology-based knowledge representation languages. In: 2003 Proceedings of the International Conference on Natural Language Processing and Knowledge Engineering, pp. 777–783. IEEE (2003)

    Google Scholar 

  40. Pnueli, A.: The temporal logic of programs. In: 18th Annual Symposium on Foundations of Computer Science, Providence, Rhode Island, USA, 31 October–1 November 1977, pp. 46–57. IEEE Computer Society (1977).

  41. Raskin, J.F.: Logics, automata and classical theories for deciding real time. Ph.D. thesis, Facultés universitaires Notre-Dame de la Paix, Namur (1999)

    Google Scholar 

  42. Rauzy, A.: New algorithms for fault trees analysis. Reliab. Eng. Syst. Saf. 40(3), 203–211 (1993).

    Article  MathSciNet  Google Scholar 

  43. Ruijters, E., Stoelinga, M.: Fault tree analysis: a survey of the state-of-the-art in modeling, analysis and tools. Comput. Sci. Rev. 15–16, 29–62 (2015).

    Article  MathSciNet  MATH  Google Scholar 

  44. Schneier, B.: Attack trees. Dr. Dobb’s J. 24(12), 21–29 (1999)

    Google Scholar 

  45. Stamatelatos, M., Vesely, W., Dugan, J., Fragola, J., Minarick, J., Railsback, J.: Fault tree handbook with aerospace applications. Prepared for NASA Office of Safety and Mission Assurance (2002)

    Google Scholar 

  46. Thums, A., Schellhorn, G.: Model checking FTA. In: Araki, K., Gnesi, S., Mandrioli, D. (eds.) FME 2003. LNCS, vol. 2805, pp. 739–757. Springer, Heidelberg (2003).

    Chapter  Google Scholar 

  47. Volk, M., Junges, S., Katoen, J.: Fast dynamic fault tree analysis by model checking techniques. IEEE Trans. Ind. Inform. 14(1), 370–379 (2018).

    Article  Google Scholar 

  48. Walker, M.D.: Pandora: a logic for the qualitative analysis of temporal fault trees. Ph.D. thesis, The University of Hull (2009)

    Google Scholar 

  49. White, C., Schwitter, R.: An update on PENG light. In: Proceedings of the Australasian Language Technology Association Workshop 2009, pp. 80–88 (2009)

    Google Scholar 

  50. Yuhua, D., Datao, Y.: Estimation of failure probability of oil and gas transmission pipelines by fuzzy fault tree analysis. J. Loss Prev. Process Ind. 18(2), 83–88 (2005)

    Article  Google Scholar 

Download references

Author information

Authors and Affiliations


Corresponding author

Correspondence to Stefano M. Nicoletti .

Editor information

Editors and Affiliations


A Appendix: Algorithms and Additional Definitions for Layer One Formulae

Following, operations between \(\textsc {bdd} \textrm{s}\) are represented by bold operands e.g., \(\boldsymbol{\wedge }, \boldsymbol{\vee } \). Algorithms to conduct these operations on \(\textsc {bdd} \textrm{s}\) can be found in [2, 5]. Given a set of variables \(\texttt{V} = \{v_1, \ldots ,v_n\}\), existential quantification (needed to translate part of the semantics of \(\textrm{MCS}\) operator) can be defined as follows: \(\boldsymbol{\exists } v . \boldsymbol{\textrm{B}} = \textsc {Restrict}(\boldsymbol{\textrm{B}},v, 0) \boldsymbol{\vee } \textsc {Restrict}(\boldsymbol{\textrm{B}},v, 1)\); \(\boldsymbol{\exists } V . \boldsymbol{\textrm{B}} = \boldsymbol{\exists } v_1. \boldsymbol{\exists } v_2 . \,\ldots \, \boldsymbol{\exists } v_n . \boldsymbol{\textrm{B}} \).

1.1 A.1 Translating FTs to BDDs

\( \varPsi _{FT} \) is defined as follows:

Definition 7

The translation function of a FT T is a function \( \varPsi _{FT_{\textit{T}}} :\texttt{E} \rightarrow \texttt{BDD} \) that takes as input an element \(e\in \texttt{E} \). With \(e'\in ch (e)\), we can define \( \varPsi _{FT_{\textit{T}}} \):

$$\begin{aligned} \varPsi _{FT_{\textit{T}}} (e)=&{\left\{ \begin{array}{ll} \overline{\boldsymbol{\textrm{B}}}(e) &{} \!\!\!\!\text {if}~e\in \texttt{BE} \\ {\boldsymbol{\bigvee }} \varPsi _{FT_{\textit{T}}} (e') &{} \!\!\!\!\text {if}~e\in \texttt{IE} ~\text {and}~t(e)=\texttt{OR} \\ {\boldsymbol{\bigwedge }} \varPsi _{FT_{\textit{T}}} (e') &{} \!\!\!\!\text {if}~e\in \texttt{IE} ~\text {and}~t(e)=\texttt{AND} \\ \underset{n_1<\ldots <n_k}{\underset{n_1,\ldots ,n_k}{\boldsymbol{\bigvee }}} \underset{i=1}{\overset{k}{\boldsymbol{\bigwedge }}} \varPsi _{FT_{\textit{T}}} (e'_{n_{i}}) &{} \!\!\!\!\text {if}~e\in \texttt{IE} ~\text {and}~t(e){=}\texttt{VOT} (k/N)\\ \end{array}\right. } \end{aligned}$$

where \(\overline{\boldsymbol{\textrm{B}}}(v)\) is a BDD with a single node in which \( Low (v)=\mathtt {{0}}\) and \( High (v)=\mathtt {{1}}\).

1.2 A.2 Algorithm 5: Translating FTs/Formulae to BDDs

Following, the recursion scheme taken from [37] to translate \(\textsc {ft} \textrm{s}\) and layer one formulae is presented.

figure t

where \(\underline{\boldsymbol{\textrm{B}}} _\textit{T} (\phi )[\texttt{V} \curvearrowright \mathtt {V'} ]\) indicates the \(\textsc {bdd}\) \(\underline{\boldsymbol{\textrm{B}}} _\textit{T} (\phi )\) in which every variable \(v_k\in \texttt{V} \) is renamed to its primed \(v'_k\in \mathtt {V'} \).

1.3 A.3 Algorithm 6: Model Checking \(\textsf{PFL}\) over a FT and a \(\overline{b\,}\)

Overview. As per [37], given a specific vector \(\overline{b}\), a \(\textsc {ft}\) \(\textit{T} \) and a layer one formula \(\phi \), this algorithm showcases how to check if \(\overline{b\,}, \textit{T} \models \phi \). To do so, we translate the given formula to a \(\textsc {bdd}\) and then we walk down the \(\textsc {bdd}\) from the root node following truth assignments given in the specific vector \(\overline{b\,}\).

figure u

Algorithm 6. Algorithm 6 shows an algorithm to check whether \(\overline{b\,},\textit{T} \models \phi \), given a status vector \(\overline{b\,}\), a \(\textsc {ft}\) \(\textit{T} \) and a formula \(\phi \). A \(\textsc {bdd}\) for the formula \(\phi \) is computed with regard to the structure function of the given \(\textsc {ft}\) \(\textit{T} \) i.e., we compute \(\underline{\boldsymbol{\textrm{B}}} _\textit{T} (\phi )\) as per Algorithm 5. Subsequently, the algorithm walks down the \(\textsc {bdd}\) following the Boolean assignments given in \(\overline{b\,}\): if the i-th element of \(\overline{b\,}\) is set to 0 then the next node in the path will be given by \( Low (w_i)\), if it is set to 1 then the next node will be \( High (w_i)\). When the algorithm reaches a terminal node it returns True if its value is one - i.e., if \(\overline{b\,},\textit{T} \models \phi \) - and False otherwise.

1.4 A.4 Algorithm 7: Computing all Satisfying Vectors

Overview. Given a \(\textsc {ft}\) \(\textit{T} \) and a formula \(\phi \), we now want to compute all vectors \(\overline{b}\) such that \(\overline{b\,}, \textit{T} \models \phi \). In this scenario no Boolean vector is given. Thus, we need to construct the \(\textsc {bdd}\) for the given formula and then collect every path that leads to the terminal \(\mathtt {{1}}\) to compute all satisfying vectors \({\llbracket {\overline{b\,}}\rrbracket }_\textit{T} \) for the given formula.

Algorithm 7. To achieve the desired outcome we will construct the \(\textsc {bdd}\) \(\underline{\boldsymbol{\textrm{B}}} _\textit{T} (\phi )\) for the given formula following Algorithm 5. Then, the algorithm will walk down the \(\textsc {bdd}\) and store all the paths that lead to the terminal node \(\mathtt {{1}}\). These paths represent all the status vectors that satisfy our formula \(\phi \). The value for the elements of each vector is set to 0 or 1 if the stored path follows respectively the low or high edge of the collected elements of the \(\textsc {bdd}\). After computing the \(\textsc {bdd}\) for a given \(\phi \), AllSat [2] will achieve the desired outcome. This algorithm returns exactly all the satisfying assignments for a given \(\textsc {bdd}\), i.e., in our case, all the Boolean vectors that satisfy our formula.

B Appendix: Proofs

1.1 B.1 Proof for Theorem 1


For a layer one formula \(\phi \) and \(\overline{\rho \,}\in B\), one can express

$$\begin{aligned} \varPhi ^*_\textit{T} (\mu _{\overline{\rho \,}},\phi ) = \sum _{\begin{array}{c} b \in \mathbb {B}^n:\\ \varPhi _T(b,\phi ) = \mathtt {{1}} \end{array}} \prod _{i=1}^n \rho _i^{b_i}(1-\rho _i)^{1-b_i}. \end{aligned}$$

This is a polynomial in the n variables \(\rho _i\). Each summand has degree 1 in each \(\rho _i\), hence \(\varPhi ^*_\textit{T} (\mu _{\overline{\rho \,}},\phi )\) can be written as

$$\begin{aligned} \varPhi ^*_\textit{T} (\mu _{\overline{\rho \,}},\phi ) = \sum _{w \in \{0,1\}^n} c^h_w \prod _{i=1}^n \rho _i^{w_i} \end{aligned}$$

for some constants \(c^h_w \in \mathbb {R}\). Now fix an i, and let \(\phi ,\phi '\) be two Boolean formulae; then we can write \(\frac{\varPhi ^*_\textit{T} (\mu _{\overline{\rho \,}},\phi \wedge \phi ')}{\varPhi ^*_\textit{T} (\mu _{\overline{\rho \,}},\phi ')} = \frac{A\rho _i + B}{C\rho _i + D}\) for some polynomials ABCD in the variables \(\rho _1,\ldots ,\rho _{i-1},\rho _{i+1},\ldots ,\rho _n\). In particular, we have

$$\begin{aligned} \frac{\partial }{\partial \rho _i}\frac{\varPhi ^*_\textit{T} (\mu _{\overline{\rho \,}},\phi \wedge \phi ')}{\varPhi ^*_\textit{T} (\mu _{\overline{\rho \,}},\phi ')} = \frac{AD-BC}{(C\rho _i + D)^2}. \end{aligned}$$

The sign of this partial derivative does not depend on the value of \(\rho _i\). In particular, when all other \(\rho _{i'}\) are fixed, this expression is maximized on an interval when \(\rho _i\) is at one of the boundary points of that interval.

Now let us return to the setting of the Theorem; we will prove it for the maximum only as the minimum is proved analogously. Let Let \(B = \prod _i [l_i,u_i]\) and let \(\overline{\rho \,}\in \prod _i [l_i^{-1},l_i^{+}]\); our aim is to find a vertex \(\overline{\rho \,}'\) such that \(\frac{\varPhi ^*_\textit{T} (\mu _{\overline{\rho \,}},\phi \wedge \phi ')}{\varPhi ^*_\textit{T} (\mu _{\overline{\rho \,}},\phi ')} \le \frac{\varPhi ^*_\textit{T} (\mu _{\overline{\rho \,}'},\phi \wedge \phi ')}{\varPhi ^*_\textit{T} (\mu _{\overline{\rho \,}'},\phi ')}\). To do so, we construct a sequence \(\overline{\rho \,}_0,\overline{\rho \,}_1,\ldots ,\overline{\rho \,}_n\) with the following properties:

  1. 1.

    \(\overline{\rho \,}_0 = \overline{\rho \,}\);

  2. 2.

    \(\frac{\varPhi ^*_\textit{T} (\mu _{\overline{\rho \,}_i},\phi \wedge \phi ')}{\varPhi ^*_\textit{T} (\mu _{\overline{\rho \,}_i},\phi ')} \le \frac{\varPhi ^*_\textit{T} (\mu _{\overline{\rho \,}_{i+1}},\phi \wedge \phi ')}{\varPhi ^*_\textit{T} (\mu _{\overline{\rho \,}_{i+1}},\phi ')}\) for \(i < n\);

  3. 3.

    \(\rho _{i,i'} \in \{l_{i'},u_{i'}\}\) for \(i' \le i \le n\).

This ensures that \(\overline{\rho \,}' := \overline{\rho \,}_n\) has the required property. We define each \(\overline{\rho \,}_{i}\) from \(\overline{\rho \,}_{i-1}\) as follows: define \(\overline{\rho \,}_{i}^-,\overline{\rho \,}_i^+ \in [l_i,u_i]\) by

$$\begin{aligned} \overline{\rho \,}_{i,i'}^{\bullet } = {\left\{ \begin{array}{ll} l_i,&{} \text { if }\bullet = -\text { and }i'= i,\\ u_i,&{} \text { if }\bullet = +\text { and }i'= i,\\ \rho _{i-1,i'},&{} \text { if }i' \ne i. \end{array}\right. } \end{aligned}$$

By the discussion following (3), one has \(\frac{\varPhi ^*_\textit{T} (\mu _{\overline{\rho \,}_{i}},\phi \wedge \phi ')}{\varPhi ^*_\textit{T} (\mu _{\overline{\rho \,}_{i}},\phi ')} \le \max \left\{ \frac{\varPhi ^*_\textit{T} (\mu _{\overline{\rho \,}_{i+1}^-},\phi \wedge \phi ')}{\varPhi ^*_\textit{T} (\mu _{\overline{\rho \,}_{i+1}^-},\phi ')},\frac{\varPhi ^*_\textit{T} (\mu _{\overline{\rho \,}_{i+1}^+},\phi \wedge \phi ')}{\varPhi ^*_\textit{T} (\mu _{\overline{\rho \,}_{i+1}^+},\phi ')}\right\} \). Take \(\overline{\rho \,}_{i+1} \in \{\overline{\rho \,}^-_{i+1}\), \(\overline{\rho \,}^+_{i+1}\}\) to maximize \(\frac{\varPhi ^*_\textit{T} (\mu _{\overline{\rho \,}_{i+1}},\phi \wedge \phi ')}{\varPhi ^*_\textit{T} (\mu _{\overline{\rho \,}_{i+1}},\phi ')}\), then this satisfies conditions 1–3 above.

Rights and permissions

Reprints and permissions

Copyright information

© 2023 The Author(s), under exclusive license to Springer Nature Switzerland AG

About this paper

Check for updates. Verify currency and authenticity via CrossMark

Cite this paper

Nicoletti, S.M., Lopuhaä-Zwakenberg, M., Hahn, E.M., Stoelinga, M. (2023). \(\textsf{PFL}\): A Probabilistic Logic for Fault Trees. In: Chechik, M., Katoen, JP., Leucker, M. (eds) Formal Methods. FM 2023. Lecture Notes in Computer Science, vol 14000. Springer, Cham.

Download citation

  • DOI:

  • Published:

  • Publisher Name: Springer, Cham

  • Print ISBN: 978-3-031-27480-0

  • Online ISBN: 978-3-031-27481-7

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics