Showing posts with label crash investigation. Show all posts
Showing posts with label crash investigation. Show all posts

Monday, June 16, 2025

Why Did Air India Flight 171 Crash?

 

That is the question that investigators will be asking in the coming days, weeks and months to come.  On Thursday June 12, a Boeing 787 Dreamliner took off from Ahmedabad in northwest India, bound for London.  On board were 242 passengers and crew.  It was a hot, clear day.  Videos taken from the ground show that after rolling down the runway, the plane "rotated" into the air (orienting flight surfaces to make the plane take off), and assumed a nose-up attitude.  But after rising for about fifteen seconds, it began to sink back toward the ground and plowed into a building housing students of a medical college.  All but one person on the plane were killed, and at least 38 people on the ground died as well.

 

This is the first fatal crash of a 787 since it was introduced in 2011.  The data recorder was recovered over the weekend, so experts have abundant information to comb through in determining what went wrong.  The formal investigation will take many weeks, but understandably, friends and relatives of the victims of the crash would like answers earlier than that.

 

Air India, the plane's operator, became a private entity only in 2022 after spending 69 years under the control of the Indian government.  An AP news report mentions that fatal crashes killing hundreds of people involved Air India equipment in 1978 and 2010.  The quality of training is always a question in accidents of this kind, and that issue will be addressed along with many others.

 

An article in the Seattle Times describes the opinions of numerous aviation experts as to what might have led to a plane crashing shortly after takeoff in this way.  While they all emphasized that everything they say is speculative at this point, they had some specific suggestions as well.

 

One noted that the appearance of dust in a video of the takeoff just before the plane becomes airborne might indicate that the pilot used up the entire runway in taking off.  This is not the usual procedure at major airports, and might have indicated issues with available engine power.

 

Several experts mentioned that the flaps may not have been in the correct position for takeoff.  Flaps are parts of the wing that can be extended downward during takeoff and landing to provide extra lift, and are routinely extended for the first few minutes of any flight.  The problem with this theory, as one expert mentioned, is that modern aircraft have alarms to alert a negligent pilot that the flaps haven't been extended, and unless there was a problem with hydraulic pressure that overwhelmed other alarms, the pilots would have noticed the issue immediately.

 

Another possibility involves an attempt to take off too soon, before the plane had enough airspeed to leave the ground safely.  Rotation, as the actions to make the plane leave the ground are called, cannot come too early, or else the plane is likely to either stall or lose altitude after an initial rise.  Stalling is an aerodynamic effect that happens when an airfoil has an excessive angle of attack to the incoming air, which no longer flows in a controlled way over the upper surface but separates from it.  The result is that lift decreases dramatically.  An airplane entering a sudden stall can appear to pitch upward and then simply drop out of the air.  While such a stall was not obvious in the videos of the flight obtained so far, something obviously caused a lack of sufficient lift that led to the crash.

 

Other more remote possibilities include engine problems that would limit the amount of thrust available below that needed for a safe takeoff.  It is possible that some systemic control issue may have limited available thrust, but there was no obvious mechanical failure of the engines before the crash, so this possibility is not a leading one.

 

In sum, initial signs are that some type of pilot error may have at least contributed to the crash:  too-early rotation, misapplication of flaps, or other more subtle mistakes.  A wide-body aircraft cannot be stopped on a dime, and once it has begun a rollout to takeoff there are not a lot of options left to the pilot should a sudden emergency occur.  A decision to abort takeoff beyond a certain point will result in overrunning the runway.  And depending on how much extra space there is at the end of the runway, an overrun can easily lead to a crash, as recently happened when Jeju Air Flight 2216 in Thailand overshot the runway and crashed into the concrete foundation of some antennas in December 2024. 

 

The alternative of taking off and trying to stay in the air may not be successful either, unless sufficient thrust can be applied to gain sufficient altitude.  Although no expert mentioned the following possibility and there may be good reasons for that, perhaps there was an issue with brakes not being fully released on the landing-gear wheels.  This would slow down the plane considerably, and the unusual nature of the problem might not give the pilots time enough to figure out what was happening. 

 

Modern jetliners are exceedingly complicated machines, and the more parts there are in a system, the more combinations of things can happen to cause difficulties.  The fact that there have so far been no calls to ground the entire fleet of 787 Dreamliners indicates that the consensus of experts is that a fundamental issue with the plane itself is probably not at fault. 

 

Once the flight-recorder data has been studied, we will know a great deal more about things such as flap and engine settings, precise timing of control actions, and other matters that are now a subject of speculation.  It is entirely possible that the accident happened due to a combination of minor mechanical problems and poor training or execution by the flight crew.  Many major tragedies in technology occur because a number of problems, each of which could be overcome by itself, combine to cause a system failure.

 

Our sympathies are with those who lost loved ones in the air or on the ground.  And I hope that whatever lessons we learn from this catastrophe will improve training and design efforts to make these the last fatalities involving a 787 in a long time.

 

Sources:  I referred to AP articles at https://apnews.com/article/air-india-survivor-crash-boeing-e88b0ba404100049ee730d5714de4c67 and https://apnews.com/article/india-plane-crash-what-to-know-4e99be1a0ed106d2f57b92f4cc398a6c, a Seattle Times article at https://www.seattletimes.com/business/boeing-aerospace/what-will-investigators-be-looking-for-in-air-india-crash-data/, and the Wikipedia articles on Air India and Air India Flight 171.

Monday, April 08, 2019

Boeing Confirms Software At Fault In Ethiopian Crash


Last Thursday, Apr. 4, Ethiopian Transport Minister Dagmawit Moges released a preliminary report into the crash of an Ethiopian Airlines Boeing 737 Max 8 outside Addis Ababa last month, killing all 157 people on board.  Cockpit voice recordings and data from the flight recorder make it very clear that, as Boeing CEO Dennis A. Muilenberg admitted regarding both this crash and that of an Indonesian Lion Air flight last fall, "it's apparent that in both flights the Maneuvering Characteristics Augmentation System, known as MCAS, activated in response to erroneous angle of attack information."  Boeing is currently scrambling to fix both that software problem and another minor one uncovered recently, but as of now, no 737 Max 8s are flying in the U. S. or much of anywhere else.  And the FBI is reportedly investigating how Boeing certified the plane.

When we blogged about the Ethiopian crash three weeks ago, there were significant questions as to whether the MCAS alone was at fault, or whether pilot errors contributed to the crash.  But according to a summary published in the Washington Post, Minister Moges said that the pilots did everything recommended by the manufacturer to disable the MCAS, which was repeatedly attempting to point the plane's nose downward in response to the single faulty angle-of-attack sensor output.  But their efforts proved futile, and the plane eventually keeled over into a 40-degree dive and crashed into the ground at more than 500 mph. 

Our sympathy is with those who lost relatives and loved ones in both crashes.  Similar words were spoken by CEO Muilenberg, on whose head lies the ultimate responsibility for fixing these problems.  In doing so, he and his underlings will be dealing with how to smoothly integrate control of life-critical systems when both humans and what amounts to artificial intelligence are involved.

This is not a new problem, but it has transformed so much over the years that it seems new. 

I once toured a museum near Lowell, Massachusetts which preserved a good number of the original pieces of machinery used in one of the many water-powered textile mills that used to dot the landscape in the early 1800s.  Attached to their main water turbine was a large, complicated system of gears, flywheels, springs, levers, and so on which turned out to be the speed regulator for the mill.  As looms were cut in and out of the belt-and-shaft power distribution system, the load would vary, but it was important to keep the speed of the mill's shafts as constant as possible.  The complicated piece of machinery I saw turned out to be a sophisticated control system that kept the wheels turning at the same rate to within a few percent, despite wide variations in load.

I'm sure that from time to time the thing might malfunction, and in that case a human operator would have to intervene, shutting it down if it started to go too fast, for example, or if continued operation endangered someone caught in a belt, say.  So humans have been learning to get along with autonomous machinery for almost two hundred years.

The difference now is that in transportation systems (autonomous cars, airplanes), timing is critical.  And because cars and planes travel into novel situations, not all of which can be anticipated by software engineers, conditions can arise which make it hard or impossible for the humans who are ultimately responsible for the safety of the craft to respond.  That increasingly seems to be what happened to Ethiopian Air Flight 302, as evidenced by the black-box data clearly showing only one angle-of-attack sensor to be transmitting flawed data. 

Such issues have happened numerous times with the limited number of autonomous cars that have been fielded in recent years.  We know of at least two fatalities associated with them, and there have probably been many more near-misses or non-fatal accidents as well. 

But even a severe car wreck can kill at most a few people.  Commercial airliners are in a differenc category altogether.  They are operated by (mostly) seasoned professionals who should be able to trust that if they follow the procedures recommended by the manufacturer (in this case, Boeing), they will be able to deal with almost any imaginable contingency, even something like a stray plastic bag jamming an angle-of-attack sensor (this is my imagination working, but something had to make it give an erroneous reading).  In the case of the Ethiopian crash, the implied promise was broken.  The pilots did what they were told would disable the MCAS, but it didn't disable, and with disastrous results.

It is unusual for a criminal investigation to be aimed at the civilian U. S. aircraft industry, whose safety record has been achieved under mostly cooperative conditions between the Federal Aviation Administration and the firms who make and fly the planes.  Obviously it is too soon to speculate about what, if anything, will turn up from such an investigation.  In teaching my engineering classes, I sometimes ask if anyone has encountered on-the-job situations whose ethics could be questioned.  And I have heard several stories about how inspection or test records were falsified in order to pass along defective products.  So such things do happen, but one hopes that in a firm with a reputation such as Boeing's, incidents like this are rare. 

The marketplace has ways of punishing firms for bad behavior which are not just, perhaps, but nonetheless effective.  With the growth of Airbus, Boeing knows it has a formidable rival for commercial aircraft, and any company with millions of dollars' worth of capital sitting idly on the ground as the 737 Max 8s wait for properly vetted software upgrades is bound to be having second thoughts about going with Boeing the next time they need some planes.  I would not want to be one of the software engineers or managers dealing with this problem, as the reputation of the company may be hinging on the timeliness and effectiveness of the fixes they will come up with. 

Boeing has been reasonably transparent about this problem so far, and I hope they continue to be up-front and frank with customers, regulators, investigators, and the public about the progress they make toward fixing these software issues.  People have been learning to get along with smart machines for centuries now, and I am confident that engineers can overcome this issue as well.  But it will take a lot of work and continued vigilance to keep something like it from happening in the future.

Sources:  The Washington Post carried the story "Additional software problem detected in Boeing 737 Max flight control system, officials say," on Apr. 4 at https://www.washingtonpost.com/world/africa/ethiopia-says-pilots-performed-boeings-recommendations-to-stop-doomed-aircraft-from-diving-urges-review-of-737-max-flight-control-system/2019/04/04/3a125942-4fec-11e9-bdb7-44f948cc0605_story.html.  I also consulted a  Seattle Times article at https://www.seattletimes.com/business/boeing-aerospace/fbi-joining-criminal-investigation-into-certification-of-boeing-737-max/ and the original report from the Transport Ministry of Ethiopia, which the Washington Post currently has at https://www.washingtonpost.com/context/ethiopia-aircraft-accident-investigation-preliminary-report/?noteId=6375a995-4d9f-4543-bc1e-12666dfe2869&questionId=7ad6fc9d-5427-415d-b719-34ad0b3fecfd&utm_term=.55ff25187605.