Probability, statistics and uncertainty propagation
Mastery objectives
- explain quantities, units and assumptions
- repeat at least one calculation by hand
- identify uncertainty, limits and failure modes
- turn the result into a decision for a Mars architecture
1. Missions use distributions, not single magic numbers
Mass, thrust, atmospheric density, navigation error and lifetime all have dispersion. A robust design asks not only for the expected value but for the range that remains compatible with mission success.
False precision is dangerous: uncertainty describes what is known, not how many digits a screen can display.
2. Mean, variance and standard deviation
For measurements xᵢ, the arithmetic mean is x̄ = Σxᵢ/n. Variance measures spread and the standard deviation σ has the same unit as the quantity.
Five flow measurements near 10 g/s should be summarised with their spread rather than by choosing the largest value as representative.
3. Propagating uncertainty
When an output depends on several inputs, final uncertainty depends on sensitivity to each variable. Independent errors can often be combined approximately, but correlation changes the result.
Two sensors with the same calibration bias are not two independent confirmations.
4. Monte Carlo simulation
Monte Carlo draws many input combinations from their distributions and recalculates the system each time. It does not remove uncertainty; it exposes the resulting distribution.
Thousands of trials can estimate how often thermal, propellant or landing constraints are violated.
5. Conditional probability and diagnosis
Evidence changes the probability of competing hypotheses. A common alarm may be weak evidence; a second independent indicator can change the diagnosis sharply.
Bayesian reasoning helps rank hypotheses during distant anomalies, but it never replaces testing and physical understanding.
6. Distributions, risk tails and rare events
A mean value does not describe mission risk by itself. Two distributions can have the same mean while assigning very different probability to a dangerous region. For a Gaussian variable, standard deviation describes spread around the mean; for failures or extreme environmental events, asymmetric or heavy-tailed models may be more appropriate. Engineers therefore ask which part of the distribution drives the decision: nominal behavior, the 95th percentile, a credible worst case or the probability of crossing a defined threshold.
7. Updating probability when new evidence arrives
Mars decisions are sequential. Before a test, a team has an estimate of reliability; after each result, that estimate should change. Bayesian reasoning formalizes the process: a prior distribution is combined with the likelihood of new evidence to produce a posterior distribution. The method guards against two opposite mistakes, treating one successful test as proof of perfection or ignoring a large body of test evidence because an early model looked convincing.
8. Useful Monte Carlo: simulate a decision, not merely a cloud of numbers
Monte Carlo analysis draws many combinations of uncertain parameters from defined distributions. It becomes useful when several nonlinear uncertainties interact, such as mass, efficiency, duration, temperature, availability and consumption. The result is only as credible as the input distributions and correlations. One hundred thousand runs based on unjustified assumptions create a very precise error. A useful report therefore shows assumptions, sensitivity and the fraction of cases that violate a mission criterion.
Decision case: a comfortable mean can hide a dangerous tail
Assume a lander has comfortable mean propellant margin but a small fraction of simulations ends close to minimum reserve. The mean looks reassuring. Engineers therefore inspect percentiles and tail cases: if one percent of trajectories consume nearly all reserve, the decision depends on the consequence of that one percent, the credibility of the input distributions and whether an operational diversion rule can reduce exposure. A distribution is not decoration; it should lead to a design or operational decision.
9. Worked example step by step
A critical chain contains 8 independent series elements, each with a 0.995 probability of success during the relevant phase. The probability that all eight succeed is 0.995^8 ≈ 0.9607, or about 96.1%. The probability of at least one failure is therefore 1 − 0.9607 = 0.0393, or 3.93%. If the system requirement is at least 99% success, slightly improving every component may not be enough; the design may need functional redundancy or fault tolerance. The calculation shows why long series chains rapidly erode system reliability.
10. Progressive exercise
A subsystem contains five series functions at 0.998 reliability each and one redundant function made of two independent channels at 0.97. Calculate the redundant-function reliability and then the full-chain reliability. Repeat conceptually when a common-cause mechanism has a 2% probability of disabling both redundant channels together.
Detailed solution — reliability calculation
11. Reasoned solution
Two independent 0.97 branches succeed with 1 − (1 − 0.97)² = 0.9991. Five 0.998 series functions give 0.998⁵ ≈ 0.9900. The combined chain is about 0.9891 before common cause is included. A two-percent common-cause event means the redundancy cannot be credited as perfectly independent, so real reliability falls further.
12. Validation mini-project
Build a probabilistic model of one Mars operations day with at least five uncertain events, two correlations and an explicit failure criterion. Compare nominal, 95th-percentile and Monte Carlo results, then identify which uncertainty deserves the next test campaign.
Primary sources and bridges
Uncertainty foundations and statistical reasoning
This statistics module separates probability from frequency, precision from accuracy, and point estimates from uncertainty before any numerical decision is made.
Four concepts to master first
probability
Definition. Probability quantifies how plausible an event is within a stated model, from 0 to 1 or 0% to 100%.
Mission example. A 1% mission-event probability does not mean the event will occur exactly once every hundred missions.
Pitfall. Do not confuse probability with certainty, frequency in a tiny sample or personal confidence.
Check that probabilities remain inside the 0–1 interval and state the model or evidence behind them.
- Evidence
- Use the defined event count or reliability model together with the exposure basis, assumptions and confidence limits supporting the probability estimate.
- Decision use
- If the estimate is too uncertain or model assumptions fail, widen the risk bound or gather more evidence before making a safety claim.
mean
Definition. The arithmetic mean adds the observations and divides by the number of observations.
Mission example. An average cabin temperature can look acceptable even while short peaks exceed a component limit.
Pitfall. A mean can hide spread, outliers, trends and multimodal behaviour.
Inspect the original series or at least range and dispersion before treating the mean as representative.
- Evidence
- Use the original measurement series and the calculated arithmetic mean so reviewers can see whether extreme readings are being hidden by averaging.
- Decision use
- If peaks or multimodal behavior matter to safety, replace the mean-only summary with limits, percentiles or separate operating states.
standard deviation
Definition. Standard deviation measures how dispersed values are around their mean in a dataset or probabilistic model.
Mission example. A sensor can have nearly zero average error yet a standard deviation large enough to make one reading unreliable.
Pitfall. Do not interpret standard deviation as a hard maximum error.
Compare the spread with the engineering tolerance and verify the distribution assumptions before using a sigma-based rule.
- Evidence
- Use the sample values, stated calculation method and resulting spread in the same physical units as the measured quantity.
- Decision use
- A larger spread can require wider margins, additional sampling or tighter process control even when the mean remains unchanged.
uncertainty
Definition. Uncertainty represents what is not known exactly about a measurement, parameter or prediction and must be propagated when quantities are combined.
Mission example. Mass, efficiency and burn duration uncertainties can turn a single propellant estimate into a range of plausible demand.
Pitfall. Reporting many decimal places does not remove uncertainty.
Carry units, source, confidence level and correlation assumptions through the calculation.
- Evidence
- Use calibration records, repeat measurements, model assumptions and the combined uncertainty interval attached to the reported value.
- Decision use
- If the uncertainty overlaps a decision limit, apply a guard band, improve the measurement or classify the result as indeterminate rather than a clean pass.
Calculation laboratory
Treat each statistical formula as a statement about evidence, not merely arithmetic. Identify the population or sample, preserve units, check the scale of the result, and ask what uncertainty or tail behavior the number hides.
Quantitative mini-lessons
Arithmetic mean
- 1 — Concrete question
- What does “mean = sum_x / n” compute in “Arithmetic mean”?
- 2 — Intuition without symbols
- The mean distributes the observed total equally across the number of measurements.
- 3 — Quantities
- mean: mean; sum_x: sum of observations; n: number of observations
- 4 — Formula
- mean = sum_x / n
- 5 — Read aloud
- Read “mean = sum_x / n” by naming every operation, subscript and grouping explicitly.
- 6 — Symbols and meaning
- mean: mean; sum_x: sum of observations; n: number of observations
- 7 — Pronunciation
- The “Read aloud” line above is the oral reference for “Arithmetic mean”. Any subscript, exponent or grouping that changes the meaning of the relation should be spoken explicitly.
- 8 — Units
- mean and observations in the same unit; n dimensionless
- 9 — Convention
- For “Arithmetic mean”, substitute values without changing the reference frame, time basis, system boundary or sign convention halfway through the calculation. Stated units: mean and observations in the same unit; n dimensionless.
- 10 — Why this operation
- In “Arithmetic mean”, division relates a quantity to a reference, duration or capacity; the denominator must belong to the same case and remain non-zero.
- 11 — Assumptions
- The relation “mean = sum_x / n” applies here only to the scenario described by the card. Inputs must be mutually consistent and satisfy the physical assumptions associated with “Arithmetic mean”.
- 12 — Unit check
- mean and observations in the same unit; n dimensionless Verify that dimensional reduction reaches the unit of the requested output.
- 13 — Numerical case
- For 18, 20, 21, 19 and 22, sum_x=100, n=5 and mean=20.
- 14 — Why the calculation works
- The numerical case applies “mean = sum_x / n” directly to the stated values. The calculation is meaningful because the quantities are substituted into the same relation before the result is interpreted for “Arithmetic mean”.
- 15 — Independent check
- Quick check: multiplying the result by the denominator should reconstruct the numerator of “Arithmetic mean” within rounding.
- 16 — Mental estimate
- Before calculating “Arithmetic mean” precisely, round the inputs to one useful digit and predict the sign and order of magnitude. The detailed result should remain consistent with that estimate.
- 17 — Interpretation
- The mean can hide spread, skew and rare events.
- 18 — What the result does not prove
- For “Arithmetic mean”, the number obtained answers only the model “mean = sum_x / n” under the stated scenario. It does not by itself validate the input data or the model outside those conditions.
- 19 — Sensitivity
- Vary one input at a time around the nominal case to identify what drives the result of “Arithmetic mean” and whether that variation can change the mission decision.
- 20 — Guided and autonomous exercises
Guided exercise. sum_x=240 and n=8.
Detailed guided correction — open after trying
sum_x=240 and n=8. mean=30.
Autonomous exercise. sum_x=91 and n=7.
Autonomous correction — open after trying
sum_x=91 and n=7. mean=13.
- 21 — Mission decision
- Always pair it with a spread indicator and sample context.
Population variance
- 1 — Concrete question
- What does “var = sum_sq / n” compute in “Population variance”?
- 2 — Intuition without symbols
- Variance measures spread by averaging squared deviations around the mean.
- 3 — Quantities
- var: variance; sum_sq: sum of squared deviations from the mean; n: number of observations
- 4 — Formula
- var = sum_sq / n
- 5 — Read aloud
- Read “var = sum_sq / n” by naming every operation, subscript and grouping explicitly.
- 6 — Symbols and meaning
- var: variance; sum_sq: sum of squared deviations from the mean; n: number of observations
- 7 — Pronunciation
- The “Read aloud” line above is the oral reference for “Population variance”. Any subscript, exponent or grouping that changes the meaning of the relation should be spoken explicitly.
- 8 — Units
- var in squared observation units; n dimensionless
- 9 — Convention
- For “Population variance”, substitute values without changing the reference frame, time basis, system boundary or sign convention halfway through the calculation. Stated units: var in squared observation units; n dimensionless.
- 10 — Why this operation
- In “Population variance”, division relates a quantity to a reference, duration or capacity; the denominator must belong to the same case and remain non-zero.
- 11 — Assumptions
- The relation “var = sum_sq / n” applies here only to the scenario described by the card. Inputs must be mutually consistent and satisfy the physical assumptions associated with “Population variance”.
- 12 — Unit check
- var in squared observation units; n dimensionless Verify that dimensional reduction reaches the unit of the requested output.
- 13 — Numerical case
- If sum_sq=20 and n=5, var=4.
- 14 — Why the calculation works
- The numerical case applies “var = sum_sq / n” directly to the stated values. The calculation is meaningful because the quantities are substituted into the same relation before the result is interpreted for “Population variance”.
- 15 — Independent check
- Quick check: multiplying the result by the denominator should reconstruct the numerator of “Population variance” within rounding.
- 16 — Mental estimate
- Before calculating “Population variance” precisely, round the inputs to one useful digit and predict the sign and order of magnitude. The detailed result should remain consistent with that estimate.
- 17 — Interpretation
- For a sample estimating a population, the denominator may become n−1 depending on the estimator.
- 18 — What the result does not prove
- For “Population variance”, the number obtained answers only the model “var = sum_sq / n” under the stated scenario. It does not by itself validate the input data or the model outside those conditions.
- 19 — Sensitivity
- Vary one input at a time around the nominal case to identify what drives the result of “Population variance” and whether that variation can change the mission decision.
- 20 — Guided and autonomous exercises
Guided exercise. sum_sq=45 and n=9.
Detailed guided correction — open after trying
sum_sq=45 and n=9. var=5.
Autonomous exercise. sum_sq=12 and n=6.
Autonomous correction — open after trying
sum_sq=12 and n=6. var=2.
- 21 — Mission decision
- State explicitly whether the data are a population or sample before comparing variances.
Standard deviation
- 1 — Concrete question
- What does “std = sqrt(var)” compute in “Standard deviation”?
- 2 — Intuition without symbols
- The square root returns variance spread to the physical unit of the data.
- 3 — Quantities
- std: standard deviation; var: variance
- 4 — Formula
- std = sqrt(var)
- 5 — Read aloud
- Read “std = sqrt(var)” by naming every operation, subscript and grouping explicitly.
- 6 — Symbols and meaning
- std: standard deviation; var: variance
- 7 — Pronunciation
- The “Read aloud” line above is the oral reference for “Standard deviation”. Any subscript, exponent or grouping that changes the meaning of the relation should be spoken explicitly.
- 8 — Units
- std in the observation unit; var in squared units
- 9 — Convention
- For “Standard deviation”, substitute values without changing the reference frame, time basis, system boundary or sign convention halfway through the calculation. Stated units: std in the observation unit; var in squared units.
- 10 — Why this operation
- In “Standard deviation”, the square root brings a quadratic quantity back to the scale of the requested quantity; the combined terms must follow the model assumptions.
- 11 — Assumptions
- The relation “std = sqrt(var)” applies here only to the scenario described by the card. Inputs must be mutually consistent and satisfy the physical assumptions associated with “Standard deviation”.
- 12 — Unit check
- std in the observation unit; var in squared units Verify that dimensional reduction reaches the unit of the requested output.
- 13 — Numerical case
- With var=4, std=sqrt(4)=2.
- 14 — Why the calculation works
- The numerical case applies “std = sqrt(var)” directly to the stated values. The calculation is meaningful because the quantities are substituted into the same relation before the result is interpreted for “Standard deviation”.
- 15 — Independent check
- Quick check: squaring the result should reconstruct the expected quadratic quantity in “Standard deviation”.
- 16 — Mental estimate
- Before calculating “Standard deviation” precisely, round the inputs to one useful digit and predict the sign and order of magnitude. The detailed result should remain consistent with that estimate.
- 17 — Interpretation
- Standard deviation alone does not describe distribution shape or rare tails.
- 18 — What the result does not prove
- For “Standard deviation”, the number obtained answers only the model “std = sqrt(var)” under the stated scenario. It does not by itself validate the input data or the model outside those conditions.
- 19 — Sensitivity
- Vary one input at a time around the nominal case to identify what drives the result of “Standard deviation” and whether that variation can change the mission decision.
- 20 — Guided and autonomous exercises
Guided exercise. var=9.
Detailed guided correction — open after trying
var=9. std=3.
Autonomous exercise. var=2.25.
Autonomous correction — open after trying
var=2.25. std=1.5.
- 21 — Mission decision
- Inspect histogram, quantiles and distribution assumptions for risk decisions.
Standard error of the mean
- 1 — Concrete question
- What does “stderr = std / sqrt(n)” compute in “Standard error of the mean”?
- 2 — Intuition without symbols
- With independent observations, uncertainty on the mean decreases with the square root of sample size.
- 3 — Quantities
- stderr: standard error; std: observation standard deviation; n: number of observations
- 4 — Formula
- stderr = std / sqrt(n)
- 5 — Read aloud
- Read “stderr = std / sqrt(n)” by naming every operation, subscript and grouping explicitly.
- 6 — Symbols and meaning
- stderr: standard error; std: observation standard deviation; n: number of observations
- 7 — Pronunciation
- The “Read aloud” line above is the oral reference for “Standard error of the mean”. Any subscript, exponent or grouping that changes the meaning of the relation should be spoken explicitly.
- 8 — Units
- stderr and std in the same unit; n dimensionless
- 9 — Convention
- For “Standard error of the mean”, substitute values without changing the reference frame, time basis, system boundary or sign convention halfway through the calculation. Stated units: stderr and std in the same unit; n dimensionless.
- 10 — Why this operation
- In “Standard error of the mean”, the square root brings a quadratic quantity back to the scale of the requested quantity; the combined terms must follow the model assumptions.
- 11 — Assumptions
- The relation “stderr = std / sqrt(n)” applies here only to the scenario described by the card. Inputs must be mutually consistent and satisfy the physical assumptions associated with “Standard error of the mean”.
- 12 — Unit check
- stderr and std in the same unit; n dimensionless Verify that dimensional reduction reaches the unit of the requested output.
- 13 — Numerical case
- With std=6 and n=36, stderr=6/6=1.
- 14 — Why the calculation works
- The numerical case applies “stderr = std / sqrt(n)” directly to the stated values. The calculation is meaningful because the quantities are substituted into the same relation before the result is interpreted for “Standard error of the mean”.
- 15 — Independent check
- Quick check: squaring the result should reconstruct the expected quadratic quantity in “Standard error of the mean”.
- 16 — Mental estimate
- Before calculating “Standard error of the mean” precisely, round the inputs to one useful digit and predict the sign and order of magnitude. The detailed result should remain consistent with that estimate.
- 17 — Interpretation
- The formula assumes independent relevant sampling; more biased data does not remove bias.
- 18 — What the result does not prove
- For “Standard error of the mean”, the number obtained answers only the model “stderr = std / sqrt(n)” under the stated scenario. It does not by itself validate the input data or the model outside those conditions.
- 19 — Sensitivity
- Vary one input at a time around the nominal case to identify what drives the result of “Standard error of the mean” and whether that variation can change the mission decision.
- 20 — Guided and autonomous exercises
Guided exercise. std=10 and n=25.
Detailed guided correction — open after trying
std=10 and n=25. stderr=2.
Autonomous exercise. std=4 and n=16.
Autonomous correction — open after trying
std=4 and n=16. stderr=1.
- 21 — Mission decision
- Increase n only when new observations add genuinely independent information.
RSS propagation of three uncertainties
- 1 — Concrete question
- What does “u_rss = sqrt(u1^2 + u2^2 + u3^2)” compute in “RSS propagation of three uncertainties”?
- 2 — Intuition without symbols
- Quadratic combination represents independent contributions that may act in different directions.
- 3 — Quantities
- u_rss: combined uncertainty; u1: first contribution; u2: second; u3: third
- 4 — Formula
- u_rss = sqrt(u1^2 + u2^2 + u3^2)
- 5 — Read aloud
- Read “u_rss = sqrt(u1^2 + u2^2 + u3^2)” by naming every operation, subscript and grouping explicitly.
- 6 — Symbols and meaning
- u_rss: combined uncertainty; u1: first contribution; u2: second; u3: third
- 7 — Pronunciation
- The “Read aloud” line above is the oral reference for “RSS propagation of three uncertainties”. Any subscript, exponent or grouping that changes the meaning of the relation should be spoken explicitly.
- 8 — Units
- all uncertainties in the same unit
- 9 — Convention
- For “RSS propagation of three uncertainties”, substitute values without changing the reference frame, time basis, system boundary or sign convention halfway through the calculation. Stated units: all uncertainties in the same unit.
- 10 — Why this operation
- In “RSS propagation of three uncertainties”, the square root brings a quadratic quantity back to the scale of the requested quantity; the combined terms must follow the model assumptions.
- 11 — Assumptions
- The relation “u_rss = sqrt(u1^2 + u2^2 + u3^2)” applies here only to the scenario described by the card. Inputs must be mutually consistent and satisfy the physical assumptions associated with “RSS propagation of three uncertainties”.
- 12 — Unit check
- all uncertainties in the same unit Verify that dimensional reduction reaches the unit of the requested output.
- 13 — Numerical case
- With u1=0.20 mm, u2=0.15 mm, u3=0.10 mm, u_rss≈0.2693 mm.
- 14 — Why the calculation works
- The numerical case applies “u_rss = sqrt(u1^2 + u2^2 + u3^2)” directly to the stated values. The calculation is meaningful because the quantities are substituted into the same relation before the result is interpreted for “RSS propagation of three uncertainties”.
- 15 — Independent check
- Quick check: squaring the result should reconstruct the expected quadratic quantity in “RSS propagation of three uncertainties”.
- 16 — Mental estimate
- Before calculating “RSS propagation of three uncertainties” precisely, round the inputs to one useful digit and predict the sign and order of magnitude. The detailed result should remain consistent with that estimate.
- 17 — Interpretation
- Correlation requires covariance terms; simple RSS may then under- or over-estimate uncertainty.
- 18 — What the result does not prove
- For “RSS propagation of three uncertainties”, the number obtained answers only the model “u_rss = sqrt(u1^2 + u2^2 + u3^2)” under the stated scenario. It does not by itself validate the input data or the model outside those conditions.
- 19 — Sensitivity
- Vary one input at a time around the nominal case to identify what drives the result of “RSS propagation of three uncertainties” and whether that variation can change the mission decision.
- 20 — Guided and autonomous exercises
Guided exercise. u1=3, u2=4, u3=0.
Detailed guided correction — open after trying
u1=3, u2=4, u3=0. u_rss=5.
Autonomous exercise. u1=1, u2=2, u3=2.
Autonomous correction — open after trying
u1=1, u2=2, u3=2. u_rss=3.
- 21 — Mission decision
- Document correlations and common sources before closing an uncertainty budget.
Empirical Monte Carlo probability
- 1 — Concrete question
- What does “p_event = N_event / N_total” compute in “Empirical Monte Carlo probability”?
- 2 — Intuition without symbols
- Observed frequency over many simulations estimates event probability under the sampled model.
- 3 — Quantities
- p_event: estimated probability; N_event: simulations with event; N_total: total simulations
- 4 — Formula
- p_event = N_event / N_total
- 5 — Read aloud
- Read “p_event = N_event / N_total” by naming every operation, subscript and grouping explicitly.
- 6 — Symbols and meaning
- p_event: estimated probability; N_event: simulations with event; N_total: total simulations
- 7 — Pronunciation
- The “Read aloud” line above is the oral reference for “Empirical Monte Carlo probability”. Any subscript, exponent or grouping that changes the meaning of the relation should be spoken explicitly.
- 8 — Units
- counts dimensionless; p_event dimensionless
- 9 — Convention
- For “Empirical Monte Carlo probability”, substitute values without changing the reference frame, time basis, system boundary or sign convention halfway through the calculation. Stated units: counts dimensionless; p_event dimensionless.
- 10 — Why this operation
- In “Empirical Monte Carlo probability”, division relates a quantity to a reference, duration or capacity; the denominator must belong to the same case and remain non-zero.
- 11 — Assumptions
- The relation “p_event = N_event / N_total” applies here only to the scenario described by the card. Inputs must be mutually consistent and satisfy the physical assumptions associated with “Empirical Monte Carlo probability”.
- 12 — Unit check
- counts dimensionless; p_event dimensionless Verify that dimensional reduction reaches the unit of the requested output.
- 13 — Numerical case
- With N_event=37 and N_total=1,000, p_event=0.037=3.7%.
- 14 — Why the calculation works
- The numerical case applies “p_event = N_event / N_total” directly to the stated values. The calculation is meaningful because the quantities are substituted into the same relation before the result is interpreted for “Empirical Monte Carlo probability”.
- 15 — Independent check
- Quick check: multiplying the result by the denominator should reconstruct the numerator of “Empirical Monte Carlo probability” within rounding.
- 16 — Mental estimate
- Before calculating “Empirical Monte Carlo probability” precisely, round the inputs to one useful digit and predict the sign and order of magnitude. The detailed result should remain consistent with that estimate.
- 17 — Interpretation
- A Monte Carlo frequency is reliable only if input distributions and sample size adequately cover the phenomenon.
- 18 — What the result does not prove
- For “Empirical Monte Carlo probability”, the number obtained answers only the model “p_event = N_event / N_total” under the stated scenario. It does not by itself validate the input data or the model outside those conditions.
- 19 — Sensitivity
- Vary one input at a time around the nominal case to identify what drives the result of “Empirical Monte Carlo probability” and whether that variation can change the mission decision.
- 20 — Guided and autonomous exercises
Guided exercise. N_event=25 and N_total=500.
Detailed guided correction — open after trying
N_event=25 and N_total=500. p_event=0.05=5%.
Autonomous exercise. N_event=3 and N_total=10,000.
Autonomous correction — open after trying
N_event=3 and N_total=10,000. p_event=0.0003=0.03%.
- 21 — Mission decision
- Increase samples or use dedicated methods for extremely rare events.
Bayesian update
- 1 — Concrete question
- What does “p_A_given_B = p_B_given_A×p_A / p_B” compute in “Bayesian update”?
- 2 — Intuition without symbols
- Bayes reweights a hypothesis by combining its prior probability with the likelihood of new evidence.
- 3 — Quantities
- p_A_given_B: probability of A given B; p_B_given_A: probability of B if A is true; p_A: prior probability of A; p_B: total probability of B
- 4 — Formula
- p_A_given_B = p_B_given_A×p_A / p_B
- 5 — Read aloud
- Read “p_A_given_B = p_B_given_A×p_A / p_B” by naming every operation, subscript and grouping explicitly.
- 6 — Symbols and meaning
- p_A_given_B: probability of A given B; p_B_given_A: probability of B if A is true; p_A: prior probability of A; p_B: total probability of B
- 7 — Pronunciation
- The “Read aloud” line above is the oral reference for “Bayesian update”. Any subscript, exponent or grouping that changes the meaning of the relation should be spoken explicitly.
- 8 — Units
- all probabilities dimensionless between zero and one
- 9 — Convention
- For “Bayesian update”, substitute values without changing the reference frame, time basis, system boundary or sign convention halfway through the calculation. Stated units: all probabilities dimensionless between zero and one.
- 10 — Why this operation
- In “Bayesian update”, division relates a quantity to a reference, duration or capacity; the denominator must belong to the same case and remain non-zero.
- 11 — Assumptions
- The relation “p_A_given_B = p_B_given_A×p_A / p_B” applies here only to the scenario described by the card. Inputs must be mutually consistent and satisfy the physical assumptions associated with “Bayesian update”.
- 12 — Unit check
- all probabilities dimensionless between zero and one Verify that dimensional reduction reaches the unit of the requested output.
- 13 — Numerical case
- With p_B_given_A=0.9, p_A=0.1 and p_B=0.18, p_A_given_B=0.9×0.1/0.18=0.5.
- 14 — Why the calculation works
- The numerical case applies “p_A_given_B = p_B_given_A×p_A / p_B” directly to the stated values. The calculation is meaningful because the quantities are substituted into the same relation before the result is interpreted for “Bayesian update”.
- 15 — Independent check
- Quick check: multiplying the result by the denominator should reconstruct the numerator of “Bayesian update” within rounding.
- 16 — Mental estimate
- Before calculating “Bayesian update” precisely, round the inputs to one useful digit and predict the sign and order of magnitude. The detailed result should remain consistent with that estimate.
- 17 — Interpretation
- A poor prior or likelihood estimate yields a misleading update despite correct arithmetic.
- 18 — What the result does not prove
- For “Bayesian update”, the number obtained answers only the model “p_A_given_B = p_B_given_A×p_A / p_B” under the stated scenario. It does not by itself validate the input data or the model outside those conditions.
- 19 — Sensitivity
- Vary one input at a time around the nominal case to identify what drives the result of “Bayesian update” and whether that variation can change the mission decision.
- 20 — Guided and autonomous exercises
Guided exercise. p_B_given_A=0.8, p_A=0.2 and p_B=0.32.
Detailed guided correction — open after trying
p_B_given_A=0.8, p_A=0.2 and p_B=0.32. p_A_given_B=0.16/0.32=0.5.
Autonomous exercise. p_B_given_A=0.6, p_A=0.1 and p_B=0.20.
Autonomous correction — open after trying
p_B_given_A=0.6, p_A=0.1 and p_B=0.20. p_A_given_B=0.06/0.20=0.30.
- 21 — Mission decision
- Document probability assumptions before using the result for diagnosis or technical decisions.
Mission reasoning
Probability is a model, not a prophecy
Mission risk numbers come from assumptions, test history, reliability data or expert models. A probability is therefore conditional on what was included. “One percent” for a valve failure under laboratory conditions cannot automatically be reused for dusty Mars operation. Good engineering records the population, exposure time and confidence behind the number before it enters a decision tree.
Statistics preserve the shape of evidence
Averages are useful summaries but cannot replace distributions. Telemetry may show the same mean temperature for two systems while one is stable and the other oscillates across safe limits. Range, quantiles, standard deviation and time plots reveal different failure risks. Engineers choose a statistic because it answers a question, not because it is familiar.
Propagating uncertainty
When a result depends on uncertain inputs, the output also has uncertainty. A first check can vary one parameter at a time to see sensitivity. More formal work may use linear uncertainty propagation, covariance matrices or Monte Carlo simulation. Correlation matters: two errors that move together cannot be treated as independent simply because they came from different columns in a spreadsheet.
Decision thresholds under uncertainty
A threshold should include measurement uncertainty and consequence. If a pressure reading is 0.1 kPa below an abort limit but sensor uncertainty is ±0.3 kPa, treating the nominal number as exact is unsafe. Operations can use guard bands, repeated measurements or an independent sensor. The right response depends on both uncertainty magnitude and the cost of a wrong decision.
Statistics practice — calculate and interpret before checking the worked answer
Exercise A — Probability interpretation
A failure probability is estimated at 0.02 per mission. Explain two statements that would be incorrect interpretations of this value.
Detailed correction — Exercise A
It is incorrect to claim that the failure must happen exactly twice in 100 missions or that any particular mission is 98% “safe” in an absolute sense. The estimate belongs to a model and evidence set; independence, operating conditions and uncertainty around the estimate must be stated.
State explicitly that 0.02 is a modelled mission probability, not a schedule predicting exactly two failures per hundred missions and not a complete statement of mission safety.
Exercise B — Mean and excursion
Five readings are 18, 20, 21, 19 and 32 °C. Compute the mean and explain why it may be a poor safety summary.
Detailed correction — Exercise B
The sum is 110 °C, so the mean is 22 °C. The 32 °C excursion may violate a component limit even though the average appears moderate. A safety review must retain the peak and time history.
After calculating the mean, compare it with the individual readings and note the 32 °C excursion; a central value that hides a potentially hazardous extreme is a poor safety summary.
Exercise C — Spread reasoning
Two sensors have the same zero mean error, but sensor A has much smaller dispersion than sensor B. Which sensor gives more precise individual readings, assuming both are unbiased?
Detailed correction — Exercise C
Sensor A. Equal mean error says their biases are similar, but smaller standard deviation means individual readings are clustered more tightly around the truth under the stated model.
When comparing sensors, separate bias from dispersion: equal zero mean error does not make their uncertainty equal, and the narrower distribution provides the more precise measurement.
Exercise D — Uncertainty propagation
A consumption estimate depends on crew size and daily use. Crew size is exact for the scenario, but daily use is uncertain by ±10%. What happens to the total consumption uncertainty if all days use the same uncertain rate?
Detailed correction — Exercise D
The total scales with the same uncertain rate, so the relative uncertainty remains about ±10% when crew size and duration are treated as exact. It would be wrong to reduce the uncertainty by averaging days if the same systematic rate uncertainty affects every day.
Propagate only the uncertain inputs that matter to the consumption result; a fixed crew size and uncertain daily use should not be treated as if they contribute the same uncertainty.
Exercise E — Threshold decision
A measured quantity is 9.9 against a limit of 10.0, with measurement uncertainty ±0.3. Should the team call the condition unquestionably below the limit?
Detailed correction — Exercise E
No. The uncertainty interval overlaps and exceeds the limit. The team should apply the predefined guard band, obtain an independent or repeated measurement, or move to the safer operational state according to consequence and procedure.
Compare the 9.9 reading, its ±0.3 uncertainty and the 10.0 limit together; when the uncertainty band crosses the limit, the team cannot honestly claim a clean pass without a guard-band rule.
Interactive beginner glossary
Use the interactive terms to build a precise language for uncertain evidence. Each definition should tell you what a statistic means, what it does not mean, and when it can mislead a mission decision.
- probability — Probability quantifies how plausible an event is within a stated model, from 0 for impossible to 1 for certain. It is meaningful only when the event and assumptions are defined.
- event — An event is a specified outcome or set of outcomes whose occurrence can be counted or assigned a probability, such as a valve failing during a mission phase.
- frequency — Frequency is the observed number or proportion of occurrences in a dataset or time interval. It is empirical evidence, not automatically the true probability of future events.
- sample — A sample is the finite set of observations actually collected from a larger population or process. Conclusions from it depend on how representative and sufficiently large it is.
- population — A population is the full set of items, people, missions or possible observations about which a statistical statement is intended to apply.
- mean — The arithmetic mean is the sum of the observed values divided by their number. It is useful for central tendency but can be strongly influenced by extreme values.
- median — The median is the middle value after sorting observations. Half the observations lie on each side, making it less sensitive to extreme outliers than the mean.
- outlier — An outlier is an observation unusually far from the rest. It may be a real rare event, a different operating condition or a measurement problem and should be investigated, not automatically deleted.
- range — The range is the interval from the minimum to the maximum observed value. It gives a simple spread measure but says little about how values are distributed inside the interval.
- variance — Variance is the mean squared deviation from the mean. Squaring keeps positive and negative deviations from cancelling and gives greater weight to large departures.
- standard deviation — Standard deviation is the square root of variance and describes typical spread around the mean in the same units as the measured quantity.
- distribution — A probability distribution describes how probability or frequency is allocated across possible values of a variable. Its shape matters for tails, thresholds and risk.
- normal distribution — A normal distribution is a symmetric, single-peaked model defined by a mean and standard deviation. It is useful for many aggregated errors but should not be assumed without evidence.
- quantile — A quantile is a value below which a stated fraction of the distribution lies. The 95th percentile, for example, has 95% of values at or below it.
- uncertainty — Uncertainty describes what is not known exactly about a measurement, parameter or prediction and should be represented with an interval, distribution or other stated bound.
- measurement uncertainty — Measurement uncertainty quantifies the range of values reasonably compatible with a measurement after accounting for instrument resolution, calibration, environment and other error sources.
- systematic error — Systematic error is a repeatable offset or distortion that pushes measurements in a consistent direction, often because of calibration, modelling or installation bias.
- random error — Random error produces unpredictable measurement-to-measurement variation. Repetition can characterize its spread, but averaging does not remove a persistent systematic bias.
- bias — Bias is a systematic tendency for an estimate or measurement to be displaced from the true or reference value in one direction.
- precision — Precision describes how closely repeated measurements agree with one another. A system can be very precise yet inaccurate if all measurements share the same bias.
- accuracy — Accuracy describes closeness to the true or accepted reference value. It depends on both random scatter and systematic error.
- confidence interval — A confidence interval is a range produced by a statistical procedure intended to cover an unknown parameter at a stated long-run rate under the model assumptions.
- correlation — Correlation describes how two quantities vary together. Correlation can reveal a relationship but does not by itself prove that one variable causes the other.
- covariance — Covariance measures joint variation of two quantities, including whether they tend to increase together or in opposite directions. Its magnitude depends on their units.
- independence — Two events or variables are independent when knowing the outcome of one does not change the probability distribution of the other under the stated model.
- Monte Carlo — Monte Carlo simulation repeatedly evaluates a model using many sampled input values so the resulting spread of outcomes can reveal uncertainty, tails and failure probabilities.
- sensitivity — Sensitivity measures how much an output changes when an input or assumption changes. It helps identify which uncertainties or design parameters dominate a decision.
- guard band — A guard band is an intentional safety offset between an operational or acceptance threshold and the true limit, allowing for uncertainty, drift and measurement error.
- threshold — A threshold is a declared boundary at which a decision or system response changes, such as warning, rejection, abort or entry into safe mode.
- risk — Risk combines the possibility of an unwanted event with the severity of its consequences. A low-probability event can still be important when consequences are catastrophic.
Operational depth: from calculation to mission decision
Choosing the statistic that matches the question
Different statistics answer different questions. The mean estimates a central value, the maximum reveals an extreme, a percentile describes the upper part of a distribution, and standard deviation summarises spread under particular assumptions. In Mars operations, the “right” statistic depends on consequence. Average cabin temperature may matter for energy budgeting, while the maximum component temperature matters for survival. A good report therefore names the decision first and selects the statistic second, rather than presenting one convenient number as a universal summary.
Small samples and false confidence
Space missions often have little directly comparable data. Ten successful cycles do not prove a failure probability is tiny; they merely show that failure was not observed in that small exposure. Confidence intervals and Bayesian reasoning can express this limitation, but the key operational lesson is simpler: absence of observed failure is not the same as proof of negligible risk. Engineers should preserve uncertainty explicitly and seek additional evidence from physics, component tests, analogous systems and accelerated testing where justified.
Correlation changes propagation
Uncertainty propagation becomes dangerous when dependencies are ignored. Two temperature sensors mounted together can share the same thermal bias. Two software estimates can depend on the same upstream measurement. Treating those errors as independent would exaggerate the benefit of averaging or fusion. Covariance records how uncertainties move together. Before combining estimates, teams should ask which errors share environment, calibration, model assumptions or source data. Independence is a claim that needs evidence, not a default spreadsheet setting.
Monte Carlo as a scenario generator
Monte Carlo simulation repeatedly samples uncertain inputs and runs the model to produce a distribution of outcomes. It is useful when relationships are nonlinear or thresholds make simple linear propagation misleading. Yet Monte Carlo does not rescue bad input assumptions. Thousands of runs with unrealistic distributions merely create precise-looking nonsense. Each input distribution should be tied to evidence, bounded by physics and reviewed for correlation. The output should then be interpreted in mission terms such as probability of violating a limit or expected reserve margin.
Decision-making with guard bands
Guard bands create operational space between a measured value and a hard limit. They account for measurement uncertainty, latency and the consequence of crossing the limit before action takes effect. A pressure system may trigger intervention before the structural or physiological limit itself. The width of the band should come from uncertainty and response dynamics, not an arbitrary percentage. This approach turns statistical understanding into action rules that crews can execute quickly under stress.
Operational review checklist
Before accepting a statistical result, identify the data source, sample size, units, assumptions and relevant uncertainty. Compare the computed value with the raw observations and state what decision threshold or risk judgment it informs.
Plan for uncertainty that does not behave nominally: outliers, bias, non-normal tails, weak samples or correlated failures can invalidate a neat calculation. The robust answer explains how the decision changes when those assumptions fail.
