Research Project / Detail View

Modeling and assuring dependability of Systems of Systems

We study Systems of Systems (SoS — arrangements in which multiple independent systems cooperate to achieve an emergent purpose) as socio-technical systems in which autonomous actors interact, and we aim to establish engineering methods for designing their overall behavior.

Modeling and assuring dependability of Systems of Systems

Background

We treat a System of Systems (SoS) not as a mere collection of connected systems, but as a social system in which autonomous actors make decisions and interact. The behavior of such large socio-technical systems cannot be explained by checking each component in isolation.

Our goal is to build an engineering perspective that designs behavior at the whole-system level — covering not only structure and connectivity, but also the interactions, incentives, and decisions among participating actors, together with methods to explain, design, and validate the system-wide behavior we want.

The challenge

Modern systems such as automated road traffic, smart grids, smart cities, and data-sharing infrastructures are increasingly distributed systems in which multiple actors make decisions independently. Even when each actor behaves rationally, their interaction can still produce outcomes at the level of the whole system that no one intended.

  • Self-interested behavior can reduce overall efficiency, as seen in traffic congestion or peak electricity demand.
  • Unexpected interactions can destabilize the system as a whole.
  • Even when each individual subsystem is locally optimal, the overall system may still fail to function well.

Limits of Previous Research

Conventional systems engineering and System of Systems Engineering (SoSE) have achieved important results in areas such as architecture design, communication and control, and software design. However, they have not fully addressed one of the most important questions in real-world SoS: how the participating actors actually behave.

As a result, a system may be architecturally correct and implemented according to specification, yet still fail to work as intended in practice. To make SoS function in real society, it is necessary to design not only the structure of the system but also the decision-making and interaction among its actors.

What we do

Rather than controlling the system from the outside, we design it so that desirable behavior is naturally selected. Concretely, we design rules, contracts, and incentives so that even when each actor acts autonomously, the system as a whole converges to a desirable state.

This reframes SoS design: not as centralized control, but as setting the conditions under which the interaction of independent actors yields a desirable equilibrium. Treating SoS as socio-technical systems lets us extend engineering from structural design to include behavioral and institutional design.

Achievements so far

This theme grew out of resilience research on Mobility-as-a-Service: resilience analysis and design for MaaS based on enterprise architecture modeling (Reliability Engineering & System Safety, 2023), reliability analysis of digital healthcare services using semi-quantitative functional resonance analysis (Computer Systems Science and Engineering, 2023), and, more recently, a multi-agent reinforcement learning based resilience engineering method for MaaS (IEEE Transactions on Network and Service Management, 2026).

For assuring SoS as a whole, the methods have expanded from modeling to game theory: consensus-based resilience assurance (IEEE Access, 2025), an ArchiMate-based evaluation approach (Systems, 2025), and dynamic resilience analysis based on Stackelberg evolutionary games (ICSRS 2025; SoSE 2026). An empirical study treating governance as a structural design variable (SoSE 2026) marks the direction of this theme toward institutional design.

The research is also connected to public activities, including the SEAMS and TIGARS projects on assurance for automated driving and standardization work around IEC 62853, with review articles such as one on comprehensive dependability for automated driving (Journal of Society of Automotive Engineers of Japan, 2024).

Why this matters

Services that involve many organizations — transport, energy, logistics — cannot be improved by any single actor alone. As this research matures, rules and incentives can be designed so that participants cooperate naturally, and the service as a whole keeps running through disasters and failures.

Instead of someone controlling the whole, we design the conditions under which the whole moves in a desirable direction. We believe this shift in perspective offers a new tool for social systems that have grown too complex to command.

Where we are heading

The next step is to make this equilibrium-based view of SoS design concrete and to establish practical foundations for design and validation in real-world settings. Through formalization of rules and contracts in Contract Architecture Description Language (CADL), design of dynamic adaptation under autonomous actors, evaluation of system-wide dependability, and empirical studies using digital twins, we aim to develop a methodology for SoS as socio-technical system design.

  • Formalization and verification of rules and contracts: describe not only system structure but also rules and contracts, and detect contradictions or inconsistencies at design time.
  • Design of dynamic adaptation under autonomous actors: clarify mechanisms by which independently acting and learning actors can still lead the whole system toward desirable states.
  • Evaluation of system-wide dependability: assess and mitigate not only component-level correctness but also problems caused by interaction across the whole system.
Raspberry Pi Mouse simulator environment used for SoS digital twin experiments
Raspberry Pi Mouse simulator environment used in the SoSE 2026 experiment.

Future directions and example topics

Alongside the foundations described above, we work on the following kinds of topics. Students' thesis topics are usually chosen from within these directions, through discussion.

  • Describing rules and contracts in the Contract Architecture Description Language (CADL) and verifying them at design time
  • Dynamic resilience analysis of SoS based on Stackelberg and evolutionary games
  • Empirical studies of governance as a design variable: trade-offs between performance and autonomy
  • Building SoS experiment environments with digital twins, such as robot simulators
  • Case studies of real services: MaaS, airports, disaster response, and hazardous-material transport

Overview articles to read first

These overview articles, written in Japanese, are an easier entry point than the research papers below.

  • Comprehensive Dependability for Automated Driving: Lessons from the PEGASUS Project and Level-4 Automated Driving Services (in Japanese)

    Yutaka Matsubara, Journal of Society of Automotive Engineers of Japan, Jan. 2024 Special Issue on Innovation Governance.

Software and projects for this theme

Papers and articles related to this project

View all publications
  • 2026

    A Multi-Agent Reinforcement Learning Based Resilience Engineering Method for Mobility-as-a-Service

    Zhengshu Zhou, Weijie Yu, Tingting Zhao, Qian Long, Yutaka Matsubara, Hiroaki Takada

    IEEE Transactions on Network and Service Management, Vol.23, pp.2135-2148

    This paper proposes a method that uses multi-agent reinforcement learning to improve the resilience of Mobility-as-a-Service, so that transport services can keep working when disruptions occur. Each agent learns through trial and error how to adjust operations, and together they restore service when parts of the network fail. This helps transport operators prepare for disruptions such as accidents or outages.

    Link

  • 2026

    A System-of-Systems Resilience Analysis Framework Based on Stackelberg Evolution Game

    Huanjun Zhang, Yutaka Matsubara

    21st International Conference on System of Systems Engineering (SoSE 2026), Kongsberg, Norway, Jun.-Jul. 2026

    This paper proposes a framework that analyzes the resilience of a system of systems using a Stackelberg evolution game, a model of leader-follower strategic interaction. A leading constituent moves first and the others adapt, and analyzing this interaction shows how cooperation and self-interest shape recovery from disruptions. The framework helps designers anticipate how an SoS behaves under stress.

    Link

  • 2026

    Governance as a Structural Design Variable: An Empirical Study of Performance-Autonomy Value Spaces in Systems of Systems

    Chihiro Shimoyama, Yutaka Matsubara

    21st International Conference on System of Systems Engineering (SoSE 2026), Kongsberg, Norway, Jun.-Jul. 2026

    This paper empirically studies how governance choices in a system of systems shape the trade-off between overall performance and the autonomy of member systems. Stronger central control tends to raise overall performance but reduces each member's freedom, and the study maps this value space through experiments. The results help architects choose a governance style deliberately rather than by default.

    Link

  • 2025

    ArchiMate-Based System of Systems Resilience Evaluation Approach

    Huanjun Zhang, Yutaka Matsubara

    Systems, Vol.13, Issue 5

    This paper proposes a way to evaluate the resilience of a system of systems using ArchiMate, a standard enterprise architecture modeling language. Describing the member systems and their dependencies as a model makes it possible to estimate how failures propagate and how well services recover. This gives designers a common notation for discussing resilience.

    Link

  • 2025

    Consensus Based Resilience Assurance for System of Systems

    Huanjun Zhang, Yutaka Matsubara

    IEEE Access, Vol.13, pp.20203-20217

    This paper proposes a consensus-based process in which the stakeholders of a system of systems agree on how much resilience is enough and how to assure it. Because no single organization controls an SoS, resilience targets must be negotiated rather than imposed, and the paper turns that negotiation into a structured process. This helps independently managed systems cooperate toward dependable services.

    Link

  • 2025

    A Decision Support Scheme for Safe and Efficient Transportation of Hazardous Materials

    Zhengshu Zhou, Yutaka Matsubara, Hiroaki Takada

    IEEE Transactions on Intelligent Transportation Systems, Vol.26, Issue 1, pp.309-322

    This paper proposes a decision support scheme that helps plan hazardous material transportation routes considering both safety and efficiency. Candidate routes and plans are compared from both risk and cost viewpoints, and the trade-offs are presented to decision makers. This supports realistic planning where safety and economics must be balanced.

    Link

  • 2025

    A Dynamic Resilience Research for Acknowledged System-of-systems Based on a Stackelberg Evolutionary Game

    Huanjun Zhang, Yutaka Matsubara

    The 9th International Conference on System Reliability and Safety (ICSRS 2025), Italy, Nov 2025

    This paper studies the dynamic resilience of an acknowledged system of systems using a Stackelberg evolutionary game model. The game captures how a coordinating leader and independent constituents adjust their strategies over time after disruptions. This dynamic view complements resilience assessments that only look at a single point in time.

    Link

  • 2025

    Improving Airport Baggage Handling System Efficiency with Simulation-Based Design

    Chenda Siv, Yutaka Matsubara, Hiroaki Takada

    2nd IEOM World Congress on Industrial Engineering and Operations Management, Canada, Oct 2025

    This paper uses simulation-based design to analyze and improve the efficiency of an airport baggage handling system. A simulation model of the conveying and sorting process reproduces congestion, letting designers compare layouts and operating policies. Improvement ideas can thus be tried without stopping the real large-scale facility.

  • 2025

    Co-evolution Guidebook (HMCES Guidebook)

    Daichi Mizuguchi, Akihisa Morikawa, Yutaka Matsubara, Kiyoshi Fujiwara

    HMCES Project

    Link

  • 2025

    Kyoshinka Guidebook

    Daichi Mizuguchi, Akihisa Morikawa, Yutaka Matsubara, Kiyoshi Fujiwara

    HMCES Project

    Link

  • 2025

    Enhancing Human-Robot Collaboration through Existing Guidelines: A Case Study Approach

    Yutaka Matsubara, Akihisa Morikawa, Daichi Mizuguchi, Kiyoshi Fujiwara

    HMCES Project

    Link

  • 2024

    Comprehensive Dependability for Automated Driving: Lessons from the PEGASUS Project and Level-4 Automated Driving Services

    Yutaka Matsubara

    Journal of Society of Automotive Engineers of Japan, Jan. 2024 Special Issue on Innovation Governance

    A review article discussing how to assure the overall dependability of automated driving, drawing lessons from Germany's PEGASUS project and Level-4 driving services. It looks at both the technical side, such as scenario-based testing, and the societal side, such as rules and governance for operating services. Readers get a broad picture of what dependable automated driving actually requires.

  • 2024

    AI2X Co-evolution Guidebook and Case Study for Human-centered AI Framework

    Akihisa Morikawa, Yutaka Matsubara, Daichi Mizuguchi, Kiyoshi Fujiwara

    SAFECOMP 2024 Position Paper, Florence, Sep 2024

    This position paper introduces a guidebook and case study from the AI2X co-evolution project, which aims at human-centered frameworks where AI and society develop together. The guidebook distills how organizations can introduce AI while keeping humans central, and the case study shows the ideas applied in practice. It follows up the project introduction presented at SAFECOMP 2023.

    Link

  • 2024

    Reaching Consensus on System-of-systems Resilience Assurance: A Case of Mobility as a Service

    Huanjun Zhang, Yutaka Matsubara, Hiroaki Takada

    SASSUR 2024 at SAFECOMP 2024, LNCS Vol.14989, pp.200-212, Florence, Sep 2024

    This paper proposes a process for stakeholders to reach consensus on resilience assurance of a system of systems, using Mobility-as-a-Service as a case study. The process makes each stakeholder's assumptions and requirements explicit and reconciles them step by step into an agreed argument. It focuses on inter-organizational agreement, not just technology.

    Link

  • 2023

    Resilience Analysis and Design for Mobility-as-a-Service Based on Enterprise Architecture Modeling

    Zhengshu Zhou, Yutaka Matsubara, Hiroaki Takada

    Reliability Engineering & System Safety, Vol.229

    This paper proposes an enterprise-architecture-based method to analyze and design the resilience of Mobility-as-a-Service systems. The service is modeled as a whole, covering not only IT systems but also the organizations and business processes around them, so weak points can be found across the entire structure. This supports designing transport services that keep running through failures.

    Link

  • 2023

    Developing Reliable Digital Healthcare Service Using Semi-Quantitative Functional Resonance Analysis

    Zhengshu Zhou, Yutaka Matsubara, Hiroaki Takada

    Computer Systems Science and Engineering, Vol.45, No.1, pp.35-50

    This paper applies a semi-quantitative version of FRAM, a method for analyzing how everyday performance variability interacts, to improve the reliability of digital healthcare services. Assigning rough numeric scores to how much each activity varies helps identify where small everyday variations can combine into service failures. This is useful for services where people, devices, and software work closely together.

    Link

  • 2023

    A Quantitative Approach for System of Systems’ Resilience Analyzing Based on ArchiMate

    Huanjun Zhang, Yutaka Matsubara, Hiroaki Takada

    DECSoS 2023 at SAFECOMP 2023, LNCS Vol.14489, pp.47-60, Toulouse, Sep 2023

    This paper proposes a quantitative method for analyzing the resilience of a system of systems based on ArchiMate architecture models. Assigning quantitative measures to model elements lets designers compare where reinforcement improves resilience most. This supports spending limited resources where they matter.

  • 2023

    Toward Human-centered AI Framework: An Introduction to AI2X Co-evolution Project

    Yutaka Matsubara, Akihisa Morikawa, Daichi Mizuguchi, Kiyoshi Fujiwara

    SAFECOMP 2023 Position Paper, Toulouse, Sep 2023

    This position paper introduces the AI2X co-evolution project, which explores frameworks for human-centered AI in society. It outlines why AI systems and the society using them must adapt to each other, and sets out the project's research agenda. The paper positions the challenges of deploying AI safely in society.

    Link

  • 2023

    Enhancing Stakeholder Consensus in the Construction of System of Systems Resilience using Assurance Case

    Huanjun Zhang, Yutaka Matsubara, Hiroaki Takada

    DSW 2023, University of Tsukuba

    Link

  • 2021

    Resilience Engineering Method for Improving Reliability of MaaS

    Zhengshu Zhou, Yutaka Matsubara, Hiroaki Takada

    DSW 2021

    Best Presentation Award.

    Link

  • 2021

    Best Presentation Award for Resilience Engineering Method for Improving Reliability of MaaS

    Zhengshu Zhou, Yutaka Matsubara, Hiroaki Takada

    DSW 2021

  • 2020

    CASE Revolution and Cybersecurity in the Automotive Domain

    Yutaka Matsubara, Ryo Kurachi, Hiroaki Takada

    IPSJ Magazine, Vol.61, No.4, pp.338-343

    A review article on how the CASE trend (Connected, Autonomous, Shared, Electric) changes cybersecurity requirements for vehicles. As cars connect to networks and receive software updates remotely, attackers gain new entry points, so defenses must span the whole lifecycle from development to operation. The article summarizes these shifts for readers outside the automotive field.

  • 2020

    Towards Identifying and Closing Gaps in Assurance of Autonomous Road Vehicles: Technical Notes Part 2

    Robin Bloomfield, Gareth Fletcher, Heidy Khlaaf, Philippa Ryan, Shuji Kinoshita, Yoshiki Kinoshita, Makoto Takeyama, Yutaka Matsubara, Peter Popov, Kazuki Imai, Yoshinori Tsutake

    TIGARS Project

    Link

  • 2020

    Towards Identifying and Closing Gaps in Assurance of Autonomous Road Vehicles: Technical Notes Part 1

    Robin Bloomfield, Gareth Fletcher, Heidy Khlaaf, Philippa Ryan, Shuji Kinoshita, Yoshiki Kinoshita, Makoto Takeyama, Yutaka Matsubara, Peter Popov, Kazuki Imai, Yoshinori Tsutake

    TIGARS Project

    Link

  • 2019

    Resilience Analysis Method Based on Open System Dependability

    Yoshinari Toda, Yutaka Matsubara, Hiroaki Takada

    DSW 2019, Tokyo

    Link

  • 2018

    Trends and Prospects in Safety and Security for Connected Cars and Society

    Yutaka Matsubara, Ryo Kurachi, Hiroaki Takada

    Jidosha Gijutsu, Vol.72, No.5, pp.87-93

    A review article surveying safety and security trends for connected cars and the surrounding connected society. It explains why safety, which protects people from failures, and security, which protects systems from attacks, must be considered together once vehicles are networked. Related standards and research directions are also introduced.

  • 2017

    Trends and Prospects in Automotive Safety and Security Toward Autonomous Driving

    Yutaka Matsubara, Ryo Kurachi, Hiroaki Takada

    IPSJ Magazine, Vol.58, No.11

    A review article surveying automotive safety and security technologies needed to realize autonomous driving. It explains how safety design against failures and defenses against cyber attacks influence each other, and why both are prerequisites for self-driving cars. The article suits readers who want an overview before studying individual technologies.

Other main research projects

01 Real-time performance assurance in high-performance embedded systems

Trust in a single computer

Real-time performance assurance in high-performance embedded systems

We study how to keep mixed-criticality systems fast, predictable, and safe even when many applications share CPUs, memory, storage, and networks.

Open this project

02 IoTxWeb3: lifecycle management and data sharing for Internet of Things (IoT) devices

Trust in connected devices

IoTxWeb3: lifecycle management and data sharing for Internet of Things (IoT) devices

We combine Internet of Things (IoT) devices with blockchain and smart contracts so that device permissions, data sharing, and lifecycle management can be handled in a transparent way.

Open this project

03 Verifying and explaining trust: fuzzing, formal methods, and assurance cases

Cross-cutting theme

Verifying and explaining trust: fuzzing, formal methods, and assurance cases

Across all three pillars, we develop techniques for checking whether a system actually deserves trust and for explaining why — fuzzing for concurrent software, formal verification, security analysis, and assurance cases.

Open this project