Significant efforts have been recently devoted to the qualitative and quantitative evaluation of resilience in engineering systems. Current resilience evaluation methods, however, have mainly focused on business supply chains and civil infrastructure, and need to be extended for application in engineering design. A new resilience metric is proposed in this paper for the design of mechanical systems to bridge this gap, by investigating the effects of recovery activity and system failure paths on system resilience. The defined resilience metric is connected to design through time-dependent system reliability analysis. This connection enables us to design a system for a specific resilience target in the design stage. Since computationally expensive computer simulations are usually used in design, a surrogate modeling method is developed to efficiently perform time-dependent system reliability analysis. Based on the time-dependent system reliability analysis, dominant system failure paths are enumerated and then the system resilience is estimated. The connection between the proposed resilience assessment method and design is explored through sensitivity analysis and component importance measure (CIM). Two numerical examples are used to illustrate the effectiveness of the proposed resilience assessment method.

## Introduction

Resilience refers to the ability of a system to recover to its normal operating condition after occurrence of disruptive events [1]. Since the first definition in 1970s, modeling and definitions of resilience have been widely studied in ecology [2], social science [3], and economics [4].

Even though resilience has been intensively studied in the above areas, its development in engineering field is still in the early stages. Resilience assessment of engineering systems has gained increasing interest in recent years. From the perspective of definition, in 2009, the American Society of Mechanical Engineers (ASME) defined resilience as a system's ability to rapidly recover to the full function after disruption [5]; Ouyang and Wang [6] evaluated the annual resilience of a system under multihazard events; Ayyub [7] proposed a resilience metric by considering the aging effects and different types of vulnerability and recoverability scenarios. Reed et al. developed a method to evaluate the resilience of networked infrastructure [8]. Other definitions of resilience metrics have also been proposed [7], and a detailed review can be found in Ref. [9]. From the perspective of application, Yodo and Wang [10,11] assessed the resilience of an electric motor supply chain using Bayesian networks (BNs); Panteli and Mancarella assessed the resilience of electrical power infrastructure [12]; Baroud et al. [13] evaluated the resilience of an inland waterway network based on the CIM method proposed by Barker et al. [14]; and Spiegler et al. [15] estimated supply chain resilience using a control engineering approach.

The above literature reviews show that current studies of resilience in engineering system have focused on problems related to supply chains [10,11,15], waterway networks [13], power infrastructure [12], and civil infrastructure systems [6]. The developed resilience metrics are difficult to apply in engineering design. Motivated by filling the gap between resilience assessment and engineering design, the first quantitative attempt was made by Youn et al. [16] in 2011 to develop a resilience-driven design framework. After that, Mehrpouyan et al. [17] investigated the resilience of complex engineered system design by employing a graph spectral approach in the design of system architecture. The resilience design framework proposed by Youn et al. [16] was basically designed for prognostics and health management (PHM), which is associated with the detectability of failure events. In the method proposed by Mehrpouyan et al. [17], resilience is affected by the physical connections between components. In addition, Wang and Li [18,19] studied the redundancy allocation of an engineering system by considering the failure interactions; this is also related to resilience since redundancy is able to increase the reliability and decrease the vulnerability of a system.

Considering that self-healing is usually difficult for traditional mechanical systems, the recovery of mechanical systems is often achieved through repair or replacement. For different components, the recovery probability, ability, and required time are different. In this situation, according to the definition of resilience, a resilient mechanical system should be a system that has low quality loss after recovery and requires a short time to recover. Besides, there are numerous failure paths for a system with multiple components. For different failure paths, the recovery properties are different. Based on these observations, a new resilience metric is proposed in this paper. Since resilience is usually time-dependent and uncertainty is inherent in design, the proposed resilience metric is connected with design through time-dependent system reliability analysis. Time-dependent system reliability computation requires a large number of runs for realistic systems [20,21]. In this paper, a surrogate model-based method is developed to reduce the computational burden. The connection between the proposed resilience assessment and design optimization is investigated through resilience sensitivity analysis and CIM.

The contributions of this paper are thus summarized as: (1) the definition of a new resilience metric, which connects design with resilience assessment; (2) a new time-dependent system reliability analysis method for resilience assessment; (3) a strategy for the efficient evaluation of resilience based on time-dependent system reliability analysis; and (4) investigation of resilient design through sensitivity analysis and CIM.

The remainder of the paper is organized as follows: Section 2 provides background concepts on resilience and time-dependent reliability analysis. Section 3 presents the proposed resilience assessment method. Two numerical examples are used to illustrate the proposed method in Sec. 4. Concluding remarks are provided in Sec. 5.

## Background

In this section, we first briefly review two resilience metrics that have a qualitative connection to design. After that, we summarize the concept of time-dependent reliability analysis.

### Resilience of an Engineering System.

Figure 1 illustrates a generalized representation of system resilience, which consists of three key elements, namely, reliability, vulnerability, and recoverability.

The *reliability* element is associated with the probability that the system performs satisfactorily in the presence of disruptive events. It can be time-independent or time-dependent. High reliability implies low probability of performing unsatisfactorily. However, high reliability requires large initial investment. The *vulnerability* element describes the degraded performance of the system after disruptive events. If a disruption occurs, a system with higher vulnerability will have a more severe failure consequence than a system with lower vulnerability. The *recoverability* element quantifies how quickly and how well a system can recover to its normal state after disruption. Inspired by the three elements of system resilience, various models and definitions of resilience have been proposed in recent years. Two representative definitions are the resilience metrics proposed by Youn et al. [16] and Ayyub [7]. (It should also be noted that *robustness* is an element overlapping between reliability and vulnerability).

where $Esf$ is system failure event, $Ecd$ is correct diagnosis, $Ecp$ is correct prognosis, $Emr$ is mitigation/recovery event, $PDiag$ is the probability of correct diagnosis [22], $PProg$ is the probability of correct prognosis [23], and $PCorr$ is the probability of correct recovery.

The resilience metric proposed in Eqs. (1) and (2) focuses on the restoration of the system using PHM methods. In order to increase the resilience of a system, the resilience design problem finally becomes a sensor network design problem, which is associated with the probability of correct diagnosis and prognosis. However, the resilience metric given in Eq. (2) does not include the vulnerability element in Fig. 1. For example, for two systems with identical reliability and $PDiagPProgPCorr$, it is apparent that the system with lower vulnerability has a higher resilience. But Eq. (2) fails to represent this situation.

where $Tin$ is the time instant of failure initialization, $Tf$ is the time to failure, $Tr$ is the time to recovery, $F$ is the failure profile, $Re$ is the recovery profile, $\Delta Tf$ is the duration of failure, and $\Delta Tr$ is the duration of recovery. $F$ measures the robustness and redundancy, and $Re$ measures the resourcefulness and rapidity. As shown in Fig. 2, three failure events and six recovery events have been considered in Ayyub's resilience metric [7].

All the three elements of the original resilience definition in Fig. 1 have been included in the metric defined in Eq. (3). A review of other alternative definitions and metrics of system resilience is available in Ref. [9]. From the literature review, it is found that most of current definitions of resilience metrics have not been explicitly connected to engineering design. The purpose of this paper is to develop a resilience metric that can be quantitatively connected to time-dependent reliability analysis and design optimization. In Secs. 2.2 and 3, we first briefly introduce the concept of time-dependent reliability analysis and then propose a new resilience metric to connect engineering design with resilience.

### Time-Dependent Reliability Analysis.

where $Pr{\u22c5}$ is probability, “$\u2200$” means “for all”, and $[0,\u2009t]$ is the time duration of interest. The corresponding time-dependent failure probability is given by $pf(0,\u2009t)=1\u2212R(0,\u2009t)$.

Time-dependent reliability analysis has been intensively studied during the past years [25]. The efforts in time-dependent reliability analysis have led to a group of time-dependent reliability analysis methods, such as the upcrossing rate methods [26], surrogate model-based methods [27,28], sampling-based approaches [24], and composite limit-state function methods [29]. Next, we develop the proposed approach to perform resilience assessment based on time-dependent reliability analysis.

## Resilience Assessment Based on Time-Dependent System Reliability Analysis

In this section, we first propose a new resilience metric for an engineering system. After that, we discuss in detail how to evaluate the resilience based on this metric.

### New Definition of Resilience Metric.

Considering the fact that Youn's resilience metric [16] can effectively represent resilience in terms of probability, we propose a new resilience metric by extending Youn's resilience metric [16] to incorporate vulnerability and the effect of uncertainty in recoverability.

We start to explain the proposed new resilience metric by investigating the resilience of a specific system without considering uncertainty. For a specific system, as shown in Fig. 3, consider a certain quantity of interest (QoI). The QoI can be system performance, economic value of the system, or other quantities. Suppose the QoI decreases over time from its original state $Q0$, and at a certain time instant $tf$, the QoI suddenly decreases from $Q(tf)$ to $Qe<Q0$ (QoI after failure) due to disturbance or failure of the system. The quality loss due to the disturbance is $Qloss=Q(tf)\u2212Qe$. After the disturbance, the recovery starts to be active. Recovery has three elements: (1) can the system function be recovered or not, (2) how much can it be recovered, and (3) how long does it take to recover. If the system can be recovered, the recovery activity is performed immediately, and the system recovers to $Qr\u2264Q0$ without taking any time (immediate recovery), the recovered QoI is then $Qrecover=Qr\u2212Qe$. If it takes some time for the system to recover (normal recovery) and the system is recovered at time instant $tr$, the recovered QoI is then $Qrecover=Qr\u2212Qe\u2212Q\xaf(tr\u2212tf)$, where $Q\xaf$ is the average quality loss during recovery used to account for the required effort for recovery.

where $Irecover=0$ means the system function cannot be recovered, $Irecover=1$ indicates the system function can be recovered, $Q(t)$ is the QoI at time instant *t,*$v(tf)=Q(tf)/Q0$*,*$vr=Qr/Q0$, $ve=Qe/Q0$, and $v\xaf=Q\xaf/Q0$ are the remaining performance ratio at $tf$ before disturbance, recovery ratio, the remaining performance ratio after disturbance, and average performance loss ratio per unit time during recovery process, respectively. $tr=tf$ corresponds to the situation of immediate recovery. The three elements of recovery are represented as $Irecover$, $vr$, and $(tr\u2212tf)$ in the above equation.

where $Pre=Pr{Recovery|\u2009Esf}$ is the probability of recovery given that the component is failed, which is a probabilistic form of $Irecover$ defined in Eq. (5), $(\Psi \u0303(t)|Recovery,\u2009Esf)$ is the resilience given that the component is failed and can be recovered, $\u222b0t\u222b\tau tftf,tr(\tau ,\zeta )[vr\u2212ve\u2212v\xaf(\zeta \u2212\tau )/v(\tau )\u2212ve]d\zeta d\tau $ is the expected resilience by considering the uncertainty in $tf$ and $tr$, and $ftf,tr(\tau ,\zeta )$ is the joint probability density function (PDF) of $tf$ and $tr$. The distribution of $tf$ can be obtained using the time-dependent system reliability analysis method presented in Sec. 3.2.

in which $R(0,\u2009t)$ is the time-dependent reliability of the component.

*sake of illustration and explanation*, in Secs. 3.2 to 3.4, we assume that $v(tf)=Q(tf)/Q0=1$ (i.e., no performance degradation if there is no failure). Equation (8) can then be rewritten as

in which $\Delta t=\u222b0t\u222b\tau tftf,tr(\tau ,\zeta )(\zeta \u2212\tau )d\zeta d\tau $ is the expected recovery time.

Since $Qe<Q0$ and $Qr\u2264Q0$, we have $ve<1$ and $vr\u22641$. $R(0,\u2009t)$, $ve$ and $v\xaf$ may be affected by the redundancy of a system since redundancy will reduce the QoI losses due to failure and during recovery. In this paper, the resilience metric is proposed without considering the effect of redundancy. Redundancy can be considered in the proposed resilience metric by studying its effect on $R(0,\u2009t)$, $ve$, and $v\xaf$ in future. Analysis of Eq. (9) shows that: (i) when the component is completely reliable ($R(0,\u2009t)=1$), the resilience is also unity; (ii) when the reliability is zero ($R(0,\u2009t)=0$), $\Psi (t)$ is governed by the recovery probability ($Pre$), recovery time ($\Delta t$), recovery ratio ($vr$), and vulnerability which is represented as the remaining performance ratio after failure ($ve$); (iii) when the recovery ratio is unity ($vr=1$) and reliability is zero, $\Psi (t)$ is mainly affected by the recovery time ($\Delta t$).

*A*and

*B*. Similarly, a parallel or combined system can also be decomposed into mutually exclusive failure paths. Based on the mutually exclusive failure paths, Eq. (9) is rewritten as

*i*occurs, $Pr{EFSi|Esf}$ is the probability that the system fails through failure path

*i*, $Pr{Recovery|EFSi,\u2009Esf}$ is the probability that the system recovers from failure path

*i*, $Nf$ is the total number of mutually exclusive failure paths, $\psi i$ is the system's resilience to the

*i*th system failure path, and $FS,i(0,\u2009t)$ and $\psi i$ are given by

in which $vr,i$, $ve,i$, and $\Delta ti$ are the recovery ratio to the system initial performance $Q0$, remaining ratio to $Q0$, and the expected required recovery time of the *i*th failure path.

*i*be $nf(i)$, we have

in which $Pre(k)$ is the recovery probability of the *k*th component, $Findexi$ is the vector of failed component indices of the *i*th system failure path, $vr(k)$ is the recovery ratio to $Q0$ of the *k*th component, $\Delta t(k)$ is the expected required recovery time of the *k*th component, and $ve(k)$ is the quality remaining ratio to $Q0$ of the *k*th component. Note that $vr(k)$, $\Delta t(k)$, and $ve(k)$ are used as constants for a component *k* in this paper for the sake of illustration. They can also be treated as random. $Pre(i)$ and the quality recovery ratios and times can be obtained from the failure modes and effects analysis (FMEA) for the system. Besides, $Pre(k)$ can be expressed as $Pre(k)=PDiag(k)PProg(k)PCorr(k)$ to connect the proposed resilience metric with the metric given in Eq. (2).

Equation (17) indicates that four main elements are required to evaluate the resilience of a system. The four elements are (i) reliability of the system, (ii) probability of having different system failure paths, (iii) probability of recovery of different system failure paths from failure, and (iv) QoI loss due to different system failure paths.

It can be seen from Eq. (10) that the proposed resilience metric has a form similar to Youn's resilience metric [16] as presented in Eq. (2). However, there are mainly three differences between Eqs. (2) and (17): (i) the resilience is expressed as a time-dependent function in Eq. (17) while Eq. (2) is time-independent; (ii) The term $PDiagPProgPCorr$ given in Eq. (2) is combined into one term $Pre$ in Eq. (17) and is expanded into $\u2211i=1Nf[FS,i(0,\u2009t)(\u220fj=1nf(i)Pre(Findexi(j)))]$ by investigating the effects of different mutually exclusive system failure paths; and (iii) Eq. (17) has an extra term $(vr,i\u2212ve,i\u2212v\xaf\Delta ti)/(1\u2212ve,i)$ to include the vulnerability element within resilience assessment. Besides, the investigation of effects of different failure paths on the probability of recovery also incorporates vulnerability into resilience evaluation.

The resilience defined in Eq. (17) is bounded in the interval [0,1], with 1 indicating high resilience of the system and 0 indicating low resilience. Before applying the proposed new resilience metric to engineering design, there are three main challenges that need to be solved.

- (1)
Computationally expensive simulation models are usually used to predict the system response. Since time-dependent system reliability analysis is required in Eq. (17), how to efficiently estimate $Rs(0,\u2009t)$ and $FS,i(0,\u2009t)$, $i=1,\u20092,\u2009\cdots ,\u2009Nf$ over $[0,\u2009t]$ is the first challenge.

- (2)
A system with multiple components may have many mutually exclusive failure paths, which are required in the proposed resilience assessment. How to efficiently enumerate these mutually exclusive system failure paths is the second challenge.

- (3)
Given the resilience metric defined in Eq. (17), how to efficiently perform resilience assessment and how to connect the resilience analysis with design is the third challenge.

In this paper, a new time-dependent system reliability analysis method is developed to address the first challenge. Based on the system reliability analysis method, the second and third challenges are solved as well.

### Time-Dependent System Reliability Analysis.

Time-dependent system reliability analysis provides $R(0,\u2009t)$ and $FS,i(0,\u2009t)$, $i=1,\u20092,\u2009\cdots ,\u2009Nf$, required in Eq. (17). During the past decades, only a few methods have been reported for time-dependent *system* reliability analysis [20,31,32]. Most of the reported system reliability analysis methods rely on the first-order reliability method (FORM). In this paper, to remove the limitation of FORM and yet be computationally efficient, a recently developed single-loop Kriging (SILK) surrogate modeling method is employed and extended for time-dependent system reliability analysis [33]. Note that failure sequences and brittle failure events [34] are important issues for time-dependent system reliability analysis. In the case of ductile failures, the overall system limit state is not affected by the sequence of component failures [35]. However, in the case of brittle failures, the failure of a component changes the limit state functions of the other components; as a result, the overall system limit state is dependent on the failure sequence [35]. Consider a two-bar system with brittle failures as shown in Fig. 4. Two failure sequences are possible (as in Fig. 4(c)), and the corresponding reliability block diagram (RBD) is shown in Fig. 4(d) [36]. The time-dependent system reliability method discussed in this paper is applicable when the sequences are identified and the RBD is available. In large systems with multiple components, dominant failure sequences may need to be identified using a branch-and-bound technique [34] or adaptive sampling [34].

where “$\u222a$” is “union,” “$\u2229$” is “intersection,” and $gi(X,\u2009Y(\tau i),\u2009\tau i)$ is the limit-state function of the *i*th component.

In the context of surrogate model-based reliability analysis, methods have been proposed to construct a single extreme value surrogate model for system reliability analysis [37,38]. The extreme value surrogate model may be highly nonlinear. In this situation, building surrogate models for individual limit state functions is a promising way. In this paper, we therefore build a surrogate model for each individual limit state function and the SILK method is employed for the surrogate modeling. The original SILK method only focused on the estimation of $pf(0,\u2009t)$, which is point estimation. For different time intervals, surrogate models need to be constructed repeatedly to obtain the failure probability up to $[0,\u2009t]$. In this section, we first briefly review the SILK method. Based on that, we modify the original SILK method to efficiently estimate $pf(0,\u2009\tau ),\u2009\tau \u2208[0,\u2009t]$ and $FS,i(0,\u2009\tau ),\u2009\tau \u2208[0,\u2009t]$, $i=1,\u20092,\u2009\cdots ,\u2009Nf$. By doing so, we can evaluate the resilience up to $[0,\u2009t]$ with just one surrogate model.

#### A Brief Review of SILK.

where $N(\u22c5,\u2009\u22c5)$ stands for normal distribution, $g\u0302(x(i),\u2009y(i)(t(j)),\u2009t(j))$ and $\sigma g\u03022(x(i),\u2009y(i)(t(j)),\u2009t(j))$ are mean and variance of the prediction, which are obtained from Kriging surrogate model [39], and $y(i)(t(j))$ is the *i*th trajectory of $Y(t)$ at time instant $t(j)$.

A detailed description of SILK is available in Ref. [33].

#### Time-Dependent System Reliability Analysis Based on SILK.

As discussed above, the original SILK method only focuses on estimating $pf(0,\u2009t)$ instead of $pf(0,\u2009\tau ),\u2009\tau \u2208[0,\u2009t]$. In order to accurately estimate $pf(0,\u2009\tau ),\u2009\tau \u2208[0,\u2009t]$, the first-passage boundary needs to be accurately modeled in the surrogate model $G\u0302=g\u0302(X,\u2009Y,\u2009t)$. It also implies that for every trajectory of the response function, the sign of points close to the first-passage point as shown in Fig. 5 needs to be accurately classified.

*k*th realization of the system over time interval $[0,\u2009\tau ],\u2009\tau \u2264t$ is given by [20]:

where $IB(k,\u2009\tau )$ is the system failure indicator for the *k*th realization of the system with $IB(k,\u2009\tau )>0$ indicating failure and $IB(k,\u2009\tau )=0$ indicating success, $Is,i(k,\u2009\tau )$ is the failure indicator of the *i*th component over time interval $[0,\u2009\tau ],\u2009\tau \u2264t$, and $Is,i(k,\u2009\tau )=1$ indicates failure and $Is,i(k,\u2009\tau )=0$ indicates success.

For a combined series and parallel system, the system Boolean function is defined according to the system topology based on Eqs. (33) and (34). For instance, for the *k*th realization of a combined system as shown in Fig. 6, the Boolean function is defined as

where $Isys(IB(k,\u2009\tau ))=1$, if $IB(k,\u2009\tau )>0$ and $Isys(IB(k,\u2009\tau ))=0,\u2009otherwise$.

By implementing a similar procedure, we can also estimate $FS,i(0,\u2009t)$, $i=1,\u20092,\u2009\cdots ,\u2009Nf$. However, there is a challenge that the number of failure scenarios (i.e., $Nf$) will increase exponentially with the number of components. This makes it almost impossible to get all $FS,i(0,\u2009t)$, $i=1,\u20092,\u2009\cdots ,\u2009Nf$. In Sec. 3.3, we will discuss how to perform resilience assessment by overcoming this challenge.

### Resilience Assessment.

According to the resilience metric defined in Eq. (17), the first step of resilience assessment is to identify all the mutually exclusive system failure paths. A possible way of achieving this purpose is to use the binary decision diagram (BDD)-based method as presented in Ref. [40]. From the BDD, the mutually exclusive failure paths can be identified efficiently. However, for some failure paths, there are still a lot of possible failure paths. In the proposed resilience metric, all the failure paths need to be identified. This is not practical for a system with a large number of components even if the BDD-based method [40] is employed.

where $nf,i$ is the number of failed system realizations through the *i*th system failure path, and $If,i(j,\u2009\tau )$ is the failure indicator function of the *i*th failure path at the *j*th random realization.

where $a\xaf(j)=\u2211i=1NfIf,i(j,\u2009\tau )ai$.

in which $Ffail(j)(k),\u2009k=1,\u2009\cdots ,\u2009nfail(j)$ is the vector of failed component indices and $nfail(j)$ is the number of failed components in the *j*th failed random realization. Note that failure indicator and failed indices are discussed at the component level in this paper, the failure indicators of component-level failure modes need to be converted into failure indicator of components if a component has multiple failure modes.

### Resilience Sensitivity Analysis and CIM.

In this section, the relationship between design variables and the proposed resilience metric is investigated through resilience sensitivity analysis and CIM.

#### Resilience Sensitivity Analysis.

where $z$ is a realization of random variables $Z$, $IS(z,\u2009t)$ is the system failure indicator over $[0,\u2009t]$, $fZ(z,\u2009\mu )$ is the joint PDF of $Z$ under given $\mu $, $If,i(z,\u2009t)$ is the failure indicator of the *i*th system failure path over $[0,\u2009t]$, and $\Omega S$ and $\Omega Si$ are failure domains of the system and the *i*th system failure path, respectively.

in which $\mu Yi(t)$ and $\sigma Yi(t)$ are the mean and standard deviation of $Yi(t)$, $\xi j$, $j=1,\u20092,\u2009\cdots ,\u2009ne$ are independent random variables, $\lambda j$ and $fj(t)$ are the eigenvalues and eigenvectors of the covariance function of $Yi(t)$, and $ne$ is the number of eigenvectors used to represent the stochastic process.

in which $\sigma i$ is the standard deviation of the normal random variable.

where $a\xaf(j)$ is given in Eq. (40).

#### Resilience CIM.

*i*on the resilience of the system. Since the proposed resilience metric includes two parts: reliability and restoration as shown in Eq. (17), the resilience CIM is defined as

where $\Delta \Psi is(t)$ is the resilience difference given that component *i* is safe and $\Delta \Psi ir(t)$ is the resilience difference given that the recoverability of component *i* is one.

Based on the resilience CIM, the importance of each component to the resilience of the system can be analyzed. In design for resilience, we could allocate different resilience levels to different components based on the CIM [44].

## Numerical Examples

In this section, a roller clutch without brittle failure events and a cantilever beam-bar system with brittle failure events are used to demonstrate the proposed resilience assessment method.

### A Roller Clutch.

An automotive roller clutch as shown in Fig. 7 is adopted from Ref. [29] as our first example. For proper operation of the clutch, three performance functions, namely, contact angle, torque capacity, and hoop stress, need to be verified during the clutch design. A proper contact angle ensures that the clutch will not be scraped. A requirement of torque avoids the situation that the clutch is locked. The hoop stress requirement guarantees the fatigue life of the cage [29]. The clutch will fail if any of the three requirements cannot be satisfied.

in which $L=80\u2009mm$, $\sigma c=3790\u2009MPa$, $c1=0.25\pi E/2(1\u22120.292)$, and $\sigma c=207\u2009GPa$.

In the above time-dependent failure probability expressions, $pf1(0,\u2009t)$ and $pf2(0,\u2009t)$ are related to the contact angle, $pf3(0,\u2009t)$ is related to the torque capacity, and $pf4(0,\u2009t)$ is related to the cage stress. Table 2 gives the random variables of the roller clutch example. The QoI of the clutch is torque. There are three types of components: roller ($pf1(0,\u2009t)$ and $pf2(0,\u2009t)$), hub ($pf3(0,\u2009t)$), and cage ($pf4(0,\u2009t)$). The average quality loss rate ($v\xaf=Q\xaf/Q0$) during revoery is assumed to be $0.2/year$. Table 3 gives the assumed data of the three types of components for the resilience assessment of the roller clutch.

Following the procedure given in Table 1, we first construct surrogate models for the limit-state functions given in Eqs. (56)–(59) using the modified SILK method. Table 4 gives the number of function evaluations (NOF) required for each limit-state function.

Figure 8 plots the comparison of time-dependent system failure probability obtained from the modified SILK with Kriging surrogate model and MCS. It shows that the modified SILK method can accurately estimate the time-dependent system failure probability. We then perform resilience assessment for the roller clutch. Figure 9 gives the resilience of the roller clutch over 20 years. Along with the resilience curve, we also plot two realizations of the system performance curves with failure events. In each individual realization, the system performance is recovered to a particular value after failure due to the recovery activity. Comparing Figs. 8 and 9, it can be found that considering the recovery activity has increased the resilience of the system.

We also perform resilience sensitivity analysis for the mean values of $Dout$, $Din0$, $DH0$, and $d0$ and resilience CIM using the method presented in Sec. 3.4. Figures 10 and 11 plot the results of resilience sensitivity analysis and CIM over different time intervals. The results show that the resilience is the most sensivity to the mean of $d0$. With the increase of time duration, sensivities of $Dout$, $DH0$, and $d0$ are getting close to each other. The results of CIM analysis indicate that component 1 (roller) is the most important for the clutch resilience.

### A Cantilever Beam-Bar System.

A cantilever beam-bar system as shown in Fig. 12 is modified from Refs. [36,40] as our second example. There are three components in the system including (1) bar, (2) beam, and (3) joint at the fixed point. The RBD which defines the failure of the system is also given in Fig. 12. There are brittle failure events in this example. The failure of component 3 (i.e., joint at the fixed point) will change the limit state function of components 1 and 2. Meanwhile, the failure of the bar will trigger the change in limit state function of component 3.

Table 5 gives the random variables and stochastic load process of the cantilever beam-bar system. The QoI of this example is the cost of the system. Table 6 gives the assumed recovery data of the three components for the resilience assessment of the cantilever beam-bar system. The average quality loss rate ($v\xaf=Q\xaf/Q0$) during revoery is $0.6/year$. In this example, the load $F(t)$ is modeled as a stationary Gaussian stochastic process and the correlation of the stochastic process is given by

Equations (61)–(65) show that each component has two-stage failure paths. Based on the relationship between the trigger events and the resulted failure modes, the RBD as shown in Fig. 12 is modified as Fig. 13, which is the same as that presented in Refs. [36,40].

Based on the modified RBD, we perform time-dependent system reliability analysis and resilience assessment for the system. Figure 14 gives the resilience of the system over twenty years. Figure 15 presents the CIM analysis results.

The result illustrates that the resilience decreases with time and component 2 (Beam) and 3 (Joint) are more important than component 1 (Bar) for the system resilience.

## Conclusion

A new resilience metric is proposed in this paper in order to connect resilience assessment to engineering design, by investigating the effects of failure, recovery, and the system failure paths on system resilience. The proposed resilience metric is expressed as a function of time-dependent system failure paths, reliability, and recovery probability. This builds a bridge between design and the resilience metric. A new time-dependent system reliability analysis method is presented to efficiently evaluate system resilience based on the proposed resilience metric. Resilience sensitivity analysis and CIM are also discussed based on the proposed metric to study the connection between resilience and design. Two numerical examples illustrate the effectiveness of the proposed method.

In the proposed resilience metric, the recovery probability of a component is assumed to be constant. In reality, the recovery probability may be random as well. How to integrate the health monitoring system into the proposed resilience metric needs to be investigated in the future. Other future needs include considering redundancy [18] among components in the system resilience assessment, accounting for the interdependency between different components and multiple failure sequences, considering different types of recovery scenarios, and learning the interdependence between components using BNs.

## Acknowledgment

The research reported in this paper was supported by the Air Force Office of Scientific Research (Grant No. FA9550-15-1-0018, Technical Monitor: Dr. David Stargel). The support is gratefully acknowledged.