Research Project / Detail View

Modeling and assuring dependability of Systems of Systems

We study Systems of Systems (SoS — arrangements in which multiple independent systems cooperate to achieve an emergent purpose) as socio-technical systems in which autonomous actors interact, and we aim to establish engineering methods for designing their overall behavior.

Modeling and assuring dependability of Systems of Systems

Background

We treat a System of Systems (SoS) not as a mere collection of connected systems, but as a social system in which autonomous actors make decisions and interact. The behavior of such large socio-technical systems cannot be explained by checking each component in isolation.

Our goal is to build an engineering perspective that designs behavior at the whole-system level — covering not only structure and connectivity, but also the interactions, incentives, and decisions among participating actors, together with methods to explain, design, and validate the system-wide behavior we want.

The challenge

Modern systems such as automated road traffic, smart grids, smart cities, and data-sharing infrastructures are increasingly distributed systems in which multiple actors make decisions independently. Even when each actor behaves rationally, their interaction can still produce outcomes at the level of the whole system that no one intended.

  • Self-interested behavior can reduce overall efficiency, as seen in traffic congestion or peak electricity demand.
  • Unexpected interactions can destabilize the system as a whole.
  • Even when each individual subsystem is locally optimal, the overall system may still fail to function well.

Limits of Previous Research

Conventional systems engineering and System of Systems Engineering (SoSE) have achieved important results in areas such as architecture design, communication and control, and software design. However, they have not fully addressed one of the most important questions in real-world SoS: how the participating actors actually behave.

As a result, a system may be architecturally correct and implemented according to specification, yet still fail to work as intended in practice. To make SoS function in real society, it is necessary to design not only the structure of the system but also the decision-making and interaction among its actors.

What we do

Rather than controlling the system from the outside, we design it so that desirable behavior is naturally selected. Concretely, we design rules, contracts, and incentives so that even when each actor acts autonomously, the system as a whole converges to a desirable state.

This reframes SoS design: not as centralized control, but as setting the conditions under which the interaction of independent actors yields a desirable equilibrium. Treating SoS as socio-technical systems lets us extend engineering from structural design to include behavioral and institutional design.

Achievements so far

This theme grew out of resilience research on Mobility-as-a-Service: resilience analysis and design for MaaS based on enterprise architecture modeling (Reliability Engineering & System Safety, 2023), reliability analysis of digital healthcare services using semi-quantitative functional resonance analysis (Computer Systems Science and Engineering, 2023), and, more recently, a multi-agent reinforcement learning based resilience engineering method for MaaS (IEEE Transactions on Network and Service Management, 2026).

For assuring SoS as a whole, the methods have expanded from modeling to game theory: consensus-based resilience assurance (IEEE Access, 2025), an ArchiMate-based evaluation approach (Systems, 2025), and dynamic resilience analysis based on Stackelberg evolutionary games (ICSRS 2025; SoSE 2026). An empirical study treating governance as a structural design variable (SoSE 2026) marks the direction of this theme toward institutional design.

The research is also connected to public activities, including the SEAMS and TIGARS projects on assurance for automated driving and standardization work around IEC 62853, with review articles such as one on comprehensive dependability for automated driving (Journal of Society of Automotive Engineers of Japan, 2024).

Why this matters

Services that involve many organizations — transport, energy, logistics — cannot be improved by any single actor alone. As this research matures, rules and incentives can be designed so that participants cooperate naturally, and the service as a whole keeps running through disasters and failures.

Instead of someone controlling the whole, we design the conditions under which the whole moves in a desirable direction. We believe this shift in perspective offers a new tool for social systems that have grown too complex to command.

Where we are heading

The next step is to make this equilibrium-based view of SoS design concrete and to establish practical foundations for design and validation in real-world settings. Through formalization of rules and contracts in Contract Architecture Description Language (CADL), design of dynamic adaptation under autonomous actors, evaluation of system-wide dependability, and empirical studies using digital twins, we aim to develop a methodology for SoS as socio-technical system design.

  • Formalization and verification of rules and contracts: describe not only system structure but also rules and contracts, and detect contradictions or inconsistencies at design time.
  • Design of dynamic adaptation under autonomous actors: clarify mechanisms by which independently acting and learning actors can still lead the whole system toward desirable states.
  • Evaluation of system-wide dependability: assess and mitigate not only component-level correctness but also problems caused by interaction across the whole system.
Raspberry Pi Mouse simulator environment used for SoS digital twin experiments
Raspberry Pi Mouse simulator environment used in the SoSE 2026 experiment.

Future directions and example topics

Alongside the foundations described above, we work on the following kinds of topics. Students' thesis topics are usually chosen from within these directions, through discussion.

  • Describing rules and contracts in the Contract Architecture Description Language (CADL) and verifying them at design time
  • Dynamic resilience analysis of SoS based on Stackelberg and evolutionary games
  • Empirical studies of governance as a design variable: trade-offs between performance and autonomy
  • Building SoS experiment environments with digital twins, such as robot simulators
  • Case studies of real services: MaaS, airports, disaster response, and hazardous-material transport

Overview articles to read first

These overview articles, written in Japanese, are an easier entry point than the research papers below.

  • Comprehensive Dependability for Automated Driving: Lessons from the PEGASUS Project and Level-4 Automated Driving Services (in Japanese)

    Yutaka Matsubara, Journal of Society of Automotive Engineers of Japan, Jan. 2024 Special Issue on Innovation Governance.

Software and projects for this theme

Papers and articles related to this project

View all publications
  • 2026

    A Multi-Agent Reinforcement Learning Based Resilience Engineering Method for Mobility-as-a-Service

    Zhengshu Zhou, Weijie Yu, Tingting Zhao, Qian Long, Yutaka Matsubara, Hiroaki Takada

    IEEE Transactions on Network and Service Management, Vol.23, pp.2135-2148

    Link

  • 2026

    A System-of-Systems Resilience Analysis Framework Based on Stackelberg Evolution Game

    Huanjun Zhang, Yutaka Matsubara

    21st International Conference on System of Systems Engineering (SoSE 2026), Kongsberg, Norway, Jun.-Jul. 2026

    To appear.

  • 2026

    Governance as a Structural Design Variable: An Empirical Study of Performance-Autonomy Value Spaces in Systems of Systems

    Chihiro Shimoyama, Yutaka Matsubara

    21st International Conference on System of Systems Engineering (SoSE 2026), Kongsberg, Norway, Jun.-Jul. 2026

    To appear.

  • 2025

    ArchiMate-Based System of Systems Resilience Evaluation Approach

    Huanjun Zhang, Yutaka Matsubara

    Systems, Vol.13, Issue 5

    Link

  • 2025

    Consensus Based Resilience Assurance for System of Systems

    Huanjun Zhang, Yutaka Matsubara

    IEEE Access, Vol.13, pp.20203-20217

    Link

  • 2025

    A Decision Support Scheme for Safe and Efficient Transportation of Hazardous Materials

    Zhengshu Zhou, Yutaka Matsubara, Hiroaki Takada

    IEEE Transactions on Intelligent Transportation Systems, Vol.26, Issue 1, pp.309-322

    Link

  • 2025

    A Dynamic Resilience Research for Acknowledged System-of-systems Based on a Stackelberg Evolutionary Game

    Huanjun Zhang, Yutaka Matsubara

    The 9th International Conference on System Reliability and Safety (ICSRS 2025), Italy, Nov 2025

    Link

  • 2025

    Improving Airport Baggage Handling System Efficiency with Simulation-Based Design

    Chenda Siv, Yutaka Matsubara, Hiroaki Takada

    2nd IEOM World Congress on Industrial Engineering and Operations Management, Canada, Oct 2025

  • 2025

    Co-evolution Guidebook (HMCES Guidebook)

    Daichi Mizuguchi, Akihisa Morikawa, Yutaka Matsubara, Kiyoshi Fujiwara

    HMCES Project

    Link

  • 2025

    Kyoshinka Guidebook

    Daichi Mizuguchi, Akihisa Morikawa, Yutaka Matsubara, Kiyoshi Fujiwara

    HMCES Project

    Link

  • 2025

    Enhancing Human-Robot Collaboration through Existing Guidelines: A Case Study Approach

    Yutaka Matsubara, Akihisa Morikawa, Daichi Mizuguchi, Kiyoshi Fujiwara

    HMCES Project

    Link

  • 2024

    Comprehensive Dependability for Automated Driving: Lessons from the PEGASUS Project and Level-4 Automated Driving Services

    Yutaka Matsubara

    Journal of Society of Automotive Engineers of Japan, Jan. 2024 Special Issue on Innovation Governance

  • 2024

    AI2X Co-evolution Guidebook and Case Study for Human-centered AI Framework

    Akihisa Morikawa, Yutaka Matsubara, Daichi Mizuguchi, Kiyoshi Fujiwara

    SAFECOMP 2024 Position Paper, Florence, Sep 2024

    Link

  • 2024

    Reaching Consensus on System-of-systems Resilience Assurance: A Case of Mobility as a Service

    Huanjun Zhang, Yutaka Matsubara, Hiroaki Takada

    SASSUR 2024 at SAFECOMP 2024, LNCS Vol.14989, pp.200-212, Florence, Sep 2024

    Link

  • 2023

    Resilience Analysis and Design for Mobility-as-a-Service Based on Enterprise Architecture Modeling

    Zhengshu Zhou, Yutaka Matsubara, Hiroaki Takada

    Reliability Engineering & System Safety, Vol.229

    Link

  • 2023

    Developing Reliable Digital Healthcare Service Using Semi-Quantitative Functional Resonance Analysis

    Zhengshu Zhou, Yutaka Matsubara, Hiroaki Takada

    Computer Systems Science and Engineering, Vol.45, No.1, pp.35-50

    Link

  • 2023

    A Quantitative Approach for System of Systems’ Resilience Analyzing Based on ArchiMate

    Huanjun Zhang, Yutaka Matsubara, Hiroaki Takada

    DECSoS 2023 at SAFECOMP 2023, LNCS Vol.14489, pp.47-60, Toulouse, Sep 2023

  • 2023

    Toward Human-centered AI Framework: An Introduction to AI2X Co-evolution Project

    Yutaka Matsubara, Akihisa Morikawa, Daichi Mizuguchi, Kiyoshi Fujiwara

    SAFECOMP 2023 Position Paper, Toulouse, Sep 2023

    Link

  • 2023

    Enhancing Stakeholder Consensus in the Construction of System of Systems Resilience using Assurance Case

    Huanjun Zhang, Yutaka Matsubara, Hiroaki Takada

    DSW 2023, University of Tsukuba

    Link

  • 2021

    Resilience Engineering Method for Improving Reliability of MaaS

    Zhengshu Zhou, Yutaka Matsubara, Hiroaki Takada

    DSW 2021

    Best Presentation Award.

    Link

  • 2021

    Best Presentation Award for Resilience Engineering Method for Improving Reliability of MaaS

    Zhengshu Zhou, Yutaka Matsubara, Hiroaki Takada

    DSW 2021

  • 2020

    CASE Revolution and Cybersecurity in the Automotive Domain

    Yutaka Matsubara, Ryo Kurachi, Hiroaki Takada

    IPSJ Magazine, Vol.61, No.4, pp.338-343

  • 2020

    Towards Identifying and Closing Gaps in Assurance of Autonomous Road Vehicles: Technical Notes Part 2

    Robin Bloomfield, Gareth Fletcher, Heidy Khlaaf, Philippa Ryan, Shuji Kinoshita, Yoshiki Kinoshita, Makoto Takeyama, Yutaka Matsubara, Peter Popov, Kazuki Imai, Yoshinori Tsutake

    TIGARS Project

    Link

  • 2020

    Towards Identifying and Closing Gaps in Assurance of Autonomous Road Vehicles: Technical Notes Part 1

    Robin Bloomfield, Gareth Fletcher, Heidy Khlaaf, Philippa Ryan, Shuji Kinoshita, Yoshiki Kinoshita, Makoto Takeyama, Yutaka Matsubara, Peter Popov, Kazuki Imai, Yoshinori Tsutake

    TIGARS Project

    Link

  • 2019

    Resilience Analysis Method Based on Open System Dependability

    Yoshinari Toda, Yutaka Matsubara, Hiroaki Takada

    DSW 2019, Tokyo

    Link

  • 2018

    Trends and Prospects in Safety and Security for Connected Cars and Society

    Yutaka Matsubara, Ryo Kurachi, Hiroaki Takada

    Jidosha Gijutsu, Vol.72, No.5, pp.87-93

  • 2017

    Trends and Prospects in Automotive Safety and Security Toward Autonomous Driving

    Yutaka Matsubara, Ryo Kurachi, Hiroaki Takada

    IPSJ Magazine, Vol.58, No.11

Other main research projects

01 Real-time performance assurance in high-performance embedded systems

Trust in a single computer

Real-time performance assurance in high-performance embedded systems

We study how to keep mixed-criticality systems fast, predictable, and safe even when many applications share CPUs, memory, storage, and networks.

Open this project

02 IoTxWeb3: lifecycle management and data sharing for Internet of Things (IoT) devices

Trust in connected devices

IoTxWeb3: lifecycle management and data sharing for Internet of Things (IoT) devices

We combine Internet of Things (IoT) devices with blockchain and smart contracts so that device permissions, data sharing, and lifecycle management can be handled in a transparent way.

Open this project

03 Verifying and explaining trust: fuzzing, formal methods, and assurance cases

Cross-cutting theme

Verifying and explaining trust: fuzzing, formal methods, and assurance cases

Across all three pillars, we develop techniques for checking whether a system actually deserves trust and for explaining why — fuzzing for concurrent software, formal verification, security analysis, and assurance cases.

Open this project