On Abstractions and Simplifications in the Design of Human-Automation Interfaces

On Abstractions and Simplifications in the Design of Human-Automation Interfaces
复制标题

人机界面设计中的抽象和简化

DOI:
--
复制
发表时间:
2002
期刊:
--
影响因子:
--
通讯作者:
A. Degani
A. Degani
中科院分区:
--
文献类型:
--
作者:
M. Heymann;A. Degani

文献摘要

被引文献

相似文献

摘要本报告从一个正式的角度阐述了人机交互的设计,它侧重于界面的信息内容,而不是图形用户界面的设计。它还涉及向用户提供信息的问题(例如,用户手册、培训材料和所有其他资源)。在本报告中,我们提出了一种生成界面和用户手册的形式化程序。这一过程遵循两个标准:第一,界面必须正确,即通过给定的界面,用户将能够正确地操作指定的任务。其次,界面应该简洁。报告讨论了这一办法的基本概念和正式方法。文中用两个例子说明了该方法。这种构造界面的算法可以实现自动化,并初步开发了实现该算法的软件系统。人类与自动化的互动广为流传,几乎我们生活的方方面面都涉及到计算机系统、信息系统、机器和设备。这些机器很复杂,由许多状态、事件、参数和协议组成。然而,用户看到的唯一面孔是界面:总是对机器底层行为的(高度)简化描述。这不是巧合,否则用户将受到巨大的不必要的复杂性的影响。例如,以消费电子产品为例,使用户界面和相关的用户手册尽可能高效、简单和简洁正成为营销的当务之急,而不再仅仅是工程和人为因素的理想。随着消费设备变得越来越复杂和多功能,就有了一个互惠的驱动装置,使它们更简单、更容易使用(因此更有市场价值)。在当今的大多数自动化系统中,人是监督者。用户与系统或工具交互以实现某些操作任务(Parsuramann等人,2000年)。这些任务或任务规范可能涉及执行特定的动作序列(例如,设置医用辐射机的程序)、监视机器的模式改变(例如,飞机自动着陆)或防止机器达到指定的非法状态(例如,跳闸电网)。为了达到任务规格,需要向用户提供有关机器行为的信息。在大多数情况下,该信息是通过界面和相关的用户手册和其他培训材料来提供的。自然,为了使用户能够正确可靠地与机器交互以实现任务规范,提供给用户的信息必须首先是正确的。例如,如果一架客机的飞行员没有足够的信息来解决模式转换问题,并决定在进入自动驾驶仪的命令后,飞机将进入“爬升”模式还是“水平飞行”模式,那么可以说提供给飞行员的信息不充分。保证正确交互所需的有效信息的一个可靠方法是向用户提供机器行为的全部细节。这样,原则上用户可以始终正确可靠地跟踪机器的状态。但这样大量的细节也有明显的缺点:界面的大小和用户手册的重量将是巨大的,用户的负担无法理解和管理。实际上,界面和相关的用户手册总是对机器行为的简化或抽象描述。任何接口都不能提供对机器基本行为的完整描述。因此,自动化系统的设计者主要关心的是确保这些抽象的接口和手册确实是足够和正确的。目前,这项评估是以临时方式进行的。它通常涉及昂贵的模拟和广泛的测试,在航空航天和医疗设备等行业,它还涉及复杂的认证程序(例如,见联邦航空条例25.1329和相关咨询通告)。然而,尽管设计团队和认证官员尽了最大努力,在航空(雅培、斯洛特和斯廷森,1996)、海事(国家运输安全委员会,1997)、医疗(Leveson,1995,见附录A--Therac-25事故)和汽车系统中已报告了许多涉及不正确接口的事件和事故
Summary This report addresses the design of human-automation interaction from a formal perspectivethat focuses on the information content of theinterface, rather than the design of the graphicaluser interface. It also addresses the issue of theinformation provided to the user (e.g., user-manuals, training material, and all otherresources). In this report, we propose a formalprocedure for generating interfaces and user-manuals. The procedure is guided by two criteria:First, the interface must be correct, that is, withthe given interface the user will be able toperform the specified tasks correctly. Second, theinterface should be succinct. The report discussesthe underlying concepts and the formal methodsfor this approach. Two examples are used toillustrate the procedure. The algorithm forconstructing interfaces can be automated, and apreliminary software system for itsimplementation has been developed. Introduction Human interaction with automation is sowidespread that almost every aspect of our livesinvolves computer systems, information systems,machines, and devices. These machines arecomplex and are composed of many states,events, parameters and protocols. Yet, the onlyface the user sees is the interface: always a(highly) reduced description of the underlyingbehavior of the machine. This is no coincidence,because otherwise the user would be subjected toenormous unnecessary complexity. Consider, forexample, consumer electronics where making theuser-interfaces and associated user-manuals asefficient, simple, and succinct as possible isbecoming a marketing imperative, and no longeris just an engineering and human factors ideal. Asconsumer devices get increasingly complex andmultifunctional, there is a reciprocal drive torender them simpler and easier to use (andthereby more marketable).In the majority of today's automated systems, thehuman is the supervisor. Users interact withsystems or tools to achieve certain operationaltasks (Parsuramann et al., 2000). These tasks, ortask specifications, may involve the execution ofspecific sequences of actions (e.g., a procedurefor setting up a medical radiation machine),monitoring a machine's mode changes (e.g., anautomatic landing of an aircraft), or preventing amachine from reaching specified illegal states(e.g., tripping a power grid). To achieve thesetask specifications, the user is provided withinformation about the behavior of the machine. Inmost cases, this information is provided by meansof an interface and associated user-0aanuals andother training material.Naturally, for the user to be able to interact withthe machine correctly and reliably so as toachieve the task specification, the informationprovided to the user must first and foremost becorrect. For example, if the pilot of an airlinerhas insufficient information to resolve a modetransition and to decide whether, after entering acommand to the autopilot, the aircraft will enter"climb" mode or "level-flight" mode, then onecan say that the information provided to the pilotis inadequate. One sure way to guaranteesufficient information for correct interaction is toprovide the user with the full detail of themachine behavior. This way the user can, inprinciple, always track the status of the machinecorrectly and reliably. But this amount of detailhas an obvious downside too; the size ofinterfaces and weight of user manuals will behuge, and the burden on the userincomprehensible and unmanageable.In practice, the interface and related user manualsare always a reduced, or abstracted, description ofthe machine's behavior. No interface provides acomplete description of the underlying behaviorof the machine. Therefore, a major concern ofdesigners of automated systems is to make surethat these abstracted interfaces and manuals areindeed adequate and correct. Currently, thisevaluation is performed in an ad hoc fashion. Itusually involves costly simulations and extensivetesting, and in industries such as aerospace andmedical equipment, it also involves complicatedcertification procedures (see for example FederalAviation Regulation 25.1329 and associatedAdvisory Circular). Yet, despite the best effortsby design teams and certification officials,numerous incidents and accidents involvingincorrect interfaces have been reported in aviation(Abbott, Slotte, and Stimson, 1996), maritime(National Transportation Safety Board, 1997),medical (Leveson, 1995 see Appendix A --theTherac-25 accidents), and automotive systems