On Abstractions and Simplifications in the Design of Human-Automation Interfaces
On Abstractions and Simplifications in the Design of Human-Automation Interfaces
复制标题
人机界面设计中的抽象和简化
DOI:
--
复制
发表时间:
2002
期刊:
影响因子:
--
通讯作者:
A. Degani
中科院分区:
文献类型:
--
作者:
M. Heymann;A. Degani
Summary This report addresses the design of human-automation interaction from a formal perspectivethat focuses on the information content of theinterface, rather than the design of the graphicaluser interface. It also addresses the issue of theinformation provided to the user (e.g., user-manuals, training material, and all otherresources). In this report, we propose a formalprocedure for generating interfaces and user-manuals. The procedure is guided by two criteria:First, the interface must be correct, that is, withthe given interface the user will be able toperform the specified tasks correctly. Second, theinterface should be succinct. The report discussesthe underlying concepts and the formal methodsfor this approach. Two examples are used toillustrate the procedure. The algorithm forconstructing interfaces can be automated, and apreliminary software system for itsimplementation has been developed. Introduction Human interaction with automation is sowidespread that almost every aspect of our livesinvolves computer systems, information systems,machines, and devices. These machines arecomplex and are composed of many states,events, parameters and protocols. Yet, the onlyface the user sees is the interface: always a(highly) reduced description of the underlyingbehavior of the machine. This is no coincidence,because otherwise the user would be subjected toenormous unnecessary complexity. Consider, forexample, consumer electronics where making theuser-interfaces and associated user-manuals asefficient, simple, and succinct as possible isbecoming a marketing imperative, and no longeris just an engineering and human factors ideal. Asconsumer devices get increasingly complex andmultifunctional, there is a reciprocal drive torender them simpler and easier to use (andthereby more marketable).In the majority of today's automated systems, thehuman is the supervisor. Users interact withsystems or tools to achieve certain operationaltasks (Parsuramann et al., 2000). These tasks, ortask specifications, may involve the execution ofspecific sequences of actions (e.g., a procedurefor setting up a medical radiation machine),monitoring a machine's mode changes (e.g., anautomatic landing of an aircraft), or preventing amachine from reaching specified illegal states(e.g., tripping a power grid). To achieve thesetask specifications, the user is provided withinformation about the behavior of the machine. Inmost cases, this information is provided by meansof an interface and associated user-0aanuals andother training material.Naturally, for the user to be able to interact withthe machine correctly and reliably so as toachieve the task specification, the informationprovided to the user must first and foremost becorrect. For example, if the pilot of an airlinerhas insufficient information to resolve a modetransition and to decide whether, after entering acommand to the autopilot, the aircraft will enter"climb" mode or "level-flight" mode, then onecan say that the information provided to the pilotis inadequate. One sure way to guaranteesufficient information for correct interaction is toprovide the user with the full detail of themachine behavior. This way the user can, inprinciple, always track the status of the machinecorrectly and reliably. But this amount of detailhas an obvious downside too; the size ofinterfaces and weight of user manuals will behuge, and the burden on the userincomprehensible and unmanageable.In practice, the interface and related user manualsare always a reduced, or abstracted, description ofthe machine's behavior. No interface provides acomplete description of the underlying behaviorof the machine. Therefore, a major concern ofdesigners of automated systems is to make surethat these abstracted interfaces and manuals areindeed adequate and correct. Currently, thisevaluation is performed in an ad hoc fashion. Itusually involves costly simulations and extensivetesting, and in industries such as aerospace andmedical equipment, it also involves complicatedcertification procedures (see for example FederalAviation Regulation 25.1329 and associatedAdvisory Circular). Yet, despite the best effortsby design teams and certification officials,numerous incidents and accidents involvingincorrect interfaces have been reported in aviation(Abbott, Slotte, and Stimson, 1996), maritime(National Transportation Safety Board, 1997),medical (Leveson, 1995 see Appendix A --theTherac-25 accidents), and automotive systems