Skip to Content
EnergiesEnergies
  • Article
  • Open Access

28 January 2026

A Fuzzy Bayesian-Based Integrated Framework for Risk Analysis of a Dual-Cycle Liquefied Natural Gas Cold Energy Power Generation System

,
,
,
,
,
,
and
1
National & Local Joint Engineering Research Center of Harbour Oil & Gas Storage and Transportation Technology, Zhejiang Key Laboratory of Pollution Control for Port-Petrochemical Industry, Zhejiang Ocean University, Zhoushan 316022, China
2
Zhejiang Electric Power Construction Co., Ltd., Ningbo 315016, China
3
School of Civil Engineering and Geomatics, Southwest Petroleum University, Chengdu 610500, China
4
School of Economics & Management, Zhejiang Ocean University, Zhoushan 316022, China

Abstract

LNG serves as a pivotal element within integrated energy systems, especially in coastal regions where the implementation of a stable and reliable LNG cold energy power generation system significantly elevates energy efficiency. This system can effectively meet concurrent demands for cold energy utilization and electricity supply while contributing to the mitigation of carbon emissions. However, the inherent complexity of the system coupled with the scarcity of historical operational data for the novel dual-Rankine cycle process renders conventional reliability assessment methodologies inadequate. This study proposes an integrated framework utilizing fuzzy Bayesian methods to address data scarcity during the early stages of equipment deployment. A hierarchical risk factor model, incorporating process decomposition, expert evaluations, and triangular fuzzy numbers, is developed to quantify uncertainties in failure probabilities. The Bayesian network models the causal relationships among equipment failure factors, allowing for the inference of overall system reliability from individual equipment performance. Through a case study of a LNG terminal in Zhoushan, this approach integrates sensitivity analysis with forward-backward reasoning methodologies to rigorously evaluate and quantify system reliability under operational conditions. The results show that under high load conditions within the 1000 h prior to overhaul, following long-term accumulated operation, the probability of complete system shutdown in the power generation system is 3.30%, while the probability of the LNG cold energy power generation system failing to operate fully due to aging-related faults is 8.24%, demonstrating the system’s strong reliability under extreme conditions. Critical risks identified through backward inference include the seawater pump SWP1, with a posterior failure probability of 59.92% during complete shutdown, and the propane-side pump SWP3, with a posterior failure probability of 32.29% when the cold energy power generation system can only operate in a single-cycle mode. This study provides an advanced methodological framework for risk management in newly constructed LNG cold energy power generation systems, playing a crucial role in promoting sustainable, low-carbon technologies in the energy sector.

1. Introduction

Over the past decade, global LNG import and export trade has grown at an average rate of 4.6% per year, and the cryogenic exergy contained in LNG is commonly referred to as “cold energy” [1]. During regasification, recovering cold energy can improve energy utilization efficiency and enhance the economic feasibility of the LNG supply chain [2,3]. In addition to power generation, LNG cold energy has been explored for cascade utilization [4], including CO2 capture [5], air separation [6], and data center cooling [7]. With the expected continued growth in natural gas consumption and LNG storage and utilization, LNG cold energy is increasingly viewed as a valuable low-temperature energy resource that supports higher efficiency and lower emissions [8].
From an engineering perspective, cold energy is released when LNG is heated and vaporized during regasification [9]. For seawater-based regasification, approximately 810 kJ/kg of cold energy is typically discharged into seawater if not recovered [10]. Among the main utilization routes, Organic Rankine Cycle (ORC) systems play a central role as a practical energy recovery technology [11]. He et al. [12] proposed a two-stage ORC configuration based on LNG cold energy and analyzed its dynamic response, showing that LNG mass flow rate strongly influences system stability. Zhang et al. [13] developed a Genetic Algorithm (GA)-based optimization method for the Dual-Organic Rankine Cycle (DORC) LNG cold energy power generation system, achieving an improvement in power generation efficiency. These works demonstrate the technical feasibility and performance benefits of LNG cold energy recovery, but they also indicate that the system is typically multi-stage, highly coupled, and operationally sensitive.
At the same time, LNG cold energy power generation systems face non-negligible safety and reliability risks throughout operation. During transportation and transshipment, leakage risk can increase due to uncertainties in equipment condition and environmental disturbances [14]. Leakage incidents may pollute the surrounding environment and can escalate into fires and explosions, leading to major losses [15]. In addition, cold energy power generation units often co-locate with LNG storage and transportation facilities; severe accidents involving storage container failure may cause rapid LNG release and vaporization, generating flammable gas clouds that can trigger large-scale fires or explosions if not promptly controlled [16]. For ethylene–propane dual working-fluid cold energy systems, electricity generation relies on coordinated operation of booster pumps, heat exchangers, and expansion generators within multi-stage heat exchange and expansion work processes [17,18,19]. When multiple tasks occur simultaneously or operating conditions change dynamically, risk prediction and control become more difficult, and inadequate management can result in equipment damage, system shutdowns, and safety incidents [20].
Existing research has provided useful insights, yet two limitations remain prominent for reliability risk quantification in LNG cold energy power generation systems. First, many studies emphasize performance improvement and operational optimization, while system-level reliability quantification and traceable root-cause diagnosis under real operating observations are comparatively less developed for these tightly coupled cold-energy conversion chains. Second, in engineering practice, component interdependence means that a single failure can propagate and induce cascading failures, which complicates risk attribution and makes subsystem-level dominance highly state-dependent [21]. In addition, failures commonly follow a bathtub curve: early commissioning and late wear-out stages tend to exhibit higher failure rates than the stable operating stage. As a result, for newly installed or recently commissioned units, historical failure data are often scarce, incomplete, or non-stationary, which weakens the credibility of purely data-driven reliability modeling and can introduce substantial bias if traditional statistical assumptions are applied directly.
Bayesian networks provide a probabilistic framework to represent conditional dependencies and to update beliefs once evidence is observed, and Shady et al. [22] applied Bayesian optimization to operational optimization of the C3MR process to reduce energy consumption and CO2 emissions. Mun et al. [23] used Bayesian optimization in the design of liquid hydrogen cold energy recovery systems to improve recovery efficiency and reduce emissions. However, Bayesian (including dynamic Bayesian) modeling typically requires credible parameterization of conditional probability tables. When failure data are insufficient, time-varying, or unavailable for key modes, dynamic Bayesian networks alone may still be difficult to calibrate at the granularity required for reliable risk inference, even though they can represent temporal evolution conceptually.
Fuzzy comprehensive evaluation can partially address data scarcity because it allows experts to express judgments linguistically and explicitly represents ambiguity in early-stage or low-data environments. Yeo et al. [24] improved risk ranking by using fuzzy TOPSIS to reduce the subjectivity inherent in conventional FMEA; however, such multi-criteria ranking approaches are primarily prioritization tools and do not provide causal, dependency-aware posterior reasoning. Masalegooyan et al. [25] combined fuzzy sets with fault tree analysis to quantify multiple risk sources under limited data, but the results remain largely static unless coupled with an inference engine. Yu [26] incorporated advanced fuzzy sets and the CoCoSo method to improve failure-mode prioritization for LNG tank leakage, yet the method still focuses on ordering risks rather than updating probabilities under observed system evidence. Overall, fuzzy methods alone are effective for translating expert knowledge into quantitative inputs, but they are limited in modeling interdependencies and performing posterior diagnosis across system layers.
To overcome these shortcomings, fuzzy Bayesian networks (FBN) have been increasingly used to couple fuzzy expert quantification with Bayesian causal inference. Zhou et al. [27] demonstrated that fuzzy priors can be embedded into a Bayesian framework for leakage risk analysis and then updated through probabilistic inference, improving traceability from basic events to higher-level outcomes. Tian et al. [28] showed that fuzzy weighting can be integrated with Bayesian learning to enhance decision performance under uncertainty, although the focus is not on process reliability and causal propagation. Shi et al. [29] further extended this idea by introducing time factors in fuzzy dynamic Bayesian networks, enabling probability evolution modeling; nevertheless, such time-dependent models typically require more granular parameterization and are harder to calibrate credibly when failure data are sparse. Mahmood et al. [30] highlighted the practicality of expert-guided fuzzy–Bayesian frameworks for identifying dominant drivers (e.g., corrosion) in natural gas pipelines, supporting actionable maintenance decisions. Zhu et al. [31] integrated STPA/ETA with FBN to strengthen causal structure and consequence reasoning, but the resulting models can become methodologically heavy and less straightforward to reproduce for new systems. Taken together, these works indicate that fuzzy–Bayesian integration is particularly valuable when systems are highly coupled and uncertainty is high, because it combines (i) robust prior elicitation under data scarcity with (ii) dependency-aware posterior updating—capabilities that fuzzy methods or dynamic Bayesian models alone often cannot provide simultaneously. Therefore, the specific research gap addressed in this paper is the lack of a traceable and reproducible approach to quantify prior probabilities of basic events for LNG cold energy power generation systems under data scarcity, while still enabling dependency-aware posterior inference to diagnose dominant contributors under different observed operating states (e.g., shutdown versus degraded operation). This paper uniquely addresses this limitation by integrating fuzzy comprehensive evaluation with a Bayesian network mapped from fault tree logic. Expert linguistic judgments are converted into triangular fuzzy numbers and aggregated using an AHP-based expert capability weighting scheme to obtain root-node priors, and Bayesian inference is then used to propagate and update probabilities across the causal chain. Compared with dynamic Bayesian networks alone, the proposed fuzzy–Bayesian integration is superior in the early installation and commissioning phase because it provides a structured and transparent mechanism to parameterize priors from expert knowledge when historical data are insufficient, while preserving Bayesian posterior updating and sensitivity tracing for system-level diagnosis and decision support. This supports stable plant operation by enabling targeted maintenance and mitigation.
The remainder of this paper is organized as follows. Section 2 introduces the methodology, including fault tree construction, fuzzy evaluation for prior probability quantification, and Bayesian network mapping and inference. Section 3 presents the failure-risk probability calculation for the LNG cold energy power generation system. Section 4 provides reliability diagnosis and sensitivity analysis under different operating states. Section 5 concludes the study.

2. Methods

The core process of this method is illustrated in Figure 1, which integrates Fault Tree Analysis (FTA), Fuzzy Comprehensive Evaluation (FCE), and Bayesian Network (BN). The process begins by constructing a fault tree to clarify the system’s failure logic and identify all basic causes. Following this, fuzzy comprehensive evaluation is applied to the basic events, incorporating expert knowledge to address uncertainty and quantify the prior probabilities of their occurrence. The next step involves mapping the fault tree structure into a Bayesian network, where the basic events serve as root nodes with assigned prior probabilities. The logical gate relationships from the fault tree are then converted into conditional probability tables for the nodes. Subsequently, probabilistic inference is performed within the Bayesian network framework to calculate the system’s failure probability (top event probability) and the posterior probabilities of key events. Finally, a sensitivity analysis is conducted to identify the critical factors.
Figure 1. Method Flow.

2.1. Fault Tree Model

Fault tree analysis is a commonly used reliability assessment method in system safety engineering [32]. It uses logical deduction to reverse-engineer the fundamental causes of system failure. As a top-down Boolean logic analysis tool, it is typically used to identify the logical relationships between potential causes or combinations of causes and the undesirable top event. The method uses a specific failure phenomenon as the top event and employs logic gate symbols to break down failure logic relations step by step, constructing a multi-level causal model from system-level failures to basic events. By identifying logical connections like AND gates and OR gates, the fault tree can clearly present the fault propagation path under the coupling effects of multiple factors [33].
In practice, fault tree analysis uses a top-down structured modeling approach, gradually decomposing system-level failure events into intermediate and basic events, with logical gates connecting events at each level [15]. The complete fault tree forms a hierarchical graphical structure, with the system’s top event at the top and the most basic failure causes at the bottom. Quantitative analysis is typically based on the assumption of event independence, using minimal cut set analysis or probabilistic calculation methods to deduce the likelihood of the top event’s occurrence, thereby identifying high-risk and weak points in the system.
Fault tree analysis has a clear logic and intuitive structure, making it suitable for fault diagnosis and risk assessment of complex systems. However, the method has certain limitations when dealing with uncertainties and dynamic behaviors between events, and it is difficult to directly characterize situations involving multi-state variables or incomplete information. Therefore, in modern engineering practice, fault tree analysis is often combined with other modeling methods to enhance the comprehensiveness and accuracy of system safety analysis.
Before constructing the fault tree, the following assumptions/simplifications were made:
  • All equipment is assumed to be in normal condition when the system starts.
  • Each event is independent in reliability modeling.
  • Upstream and downstream facilities and equipment are outside the scope of analysis.
The construction process is shown in Figure 2.
Figure 2. Example of Fault Tree Construction Process.
Independence is imposed at the basic-event level because joint failure data and correlation parameters are unavailable, and a tractable probability specification is required for fault-tree quantification and subsequent Bayesian-network parameterization. This assumption is reasonable since basic events are defined as component-level failure mechanisms, while system interactions are captured by the fault-tree logic structure rather than by correlated basic-event priors.

2.2. Fuzzy Probability

Fuzzy probability expresses the likelihood of an event occurring as a range using fuzzy numbers or membership functions, combining the ideas of fuzzy set theory and traditional probability theory. Compared to traditional precise probabilities, fuzzy probability is more suitable for describing prior information derived from expert judgment, experience estimates, or incomplete data. In fault tree analysis or Bayesian network modeling, by representing the probability of basic events as triangular fuzzy numbers or interval membership functions, uncertainty information can be retained during the logical propagation process, enabling more realistic system-level failure probability reasoning. This method not only enhances the adaptability of the model but also increases the credibility of the result interpretation, especially in early design phases or key system evaluation scenarios where data acquisition is difficult.
Experts first conduct an empirical evaluation of the basic events and categorize the evaluation results into levels, with different evaluation levels corresponding to different triangular fuzzy numbers. The Analytic Hierarchy Process (AHP) method is used to evaluate the experts. Based on the evaluation results, the experts’ professional weights (w) can be obtained. The evaluation is then converted into fuzzy probabilities according to the following formula groups:
a , b , c   =   j = 1 m w j x ij
Formula (1) represents the fuzzy number aggregation result for the root node xi based on the evaluations provided by multiple experts. The fuzzy number (a, b, c) is calculated as a weighted sum of the fuzzy numbers given by each expert. In this equation, a, b, and c are the parameters of the fuzzy number representing the root node xi which are aggregated from the individual fuzzy numbers provided by the experts. The number of experts is denoted as m, and wj is the evaluation weight assigned to each expert. The term xij represents the fuzzy number given by the j-th expert for the root node xi This weighted aggregation allows for the integration of expert knowledge and the calculation of a representative fuzzy value for the system’s evaluation.
F M = a b x a b a x d x + b c c x c b x d x a b x a b a d x + b c c x c b d x = a + b + c 3
FM—Fuzzy possibility evaluation result [30]. To maintain consistency between prior probability and fuzzy probability, an empirical formula is used to convert FM into fuzzy probability F [34]. Triangular fuzzy numbers are adopted to represent uncertainty because the judgments are elicited in a three-point form (optimistic–most likely–pessimistic), which naturally corresponds to (a, b, c). This representation is parsimonious and admits a closed-form centroid (FM = (a + b + c)/3), which facilitates the subsequent empirical mapping from FM to the fuzzy probability F and maintains consistency with the prior probability setting. In contrast, trapezoidal fuzzy numbers typically require an additional parameter to specify a plateau (core) region, which is unnecessary under the three-point elicitation scheme and may introduce extra subjectivity.
k = 2.301 × 1 F M / F M 1 / 3
F = 1 10 k         F M 0 0                   F M = 0
Fuzzy set theory [35] is used to express experts’ linguistic judgments as fuzzy possibility intervals. Because failure data are limited at the pre-commissioning stage, a literature-based empirical mapping is used to convert these fuzzy assessments into basic-event prior probabilities for the reliability analysis. The resulting priors are intended to support the initial assessment before long-term operational data become available, and they can be refined later as the system accumulates field data.
As a simple demonstration, consider the basic event “LNG pipeline blockage” evaluated under full-load conditions within the 1000 h prior to overhaul. The eight experts’ ratings are M, M, FL, VL, VL, VL, VL, and L, (a, b, c) = (0.1327, 0.2186, 0.3045). Applying the expert-weighted aggregation in Equations (1) and (2) yields FM = 0.2186, and substituting FM into Equations (3) and (4) gives F = 3.03 × 10−4, which is used as the prior probability for this basic event.

2.3. Bayesian Network

Bayesian networks [36] are graphical techniques used to describe probabilistic information and reasoning between variables. They can handle the fuzziness and uncertainty of information. A Bayesian network consists of nodes, directed arcs, and conditional probability tables, and is a graph-based model based on probability theory used to represent conditional dependencies between variables. It has two main components:
  • Directed Acyclic Graph (DAG): Each node in the graph represents a random variable, and the edges represent the dependencies between variables.
  • Conditional Probability Distribution (CPD): Each node is associated with a conditional probability table (CPT) that characterizes the probability distribution of the variable given the values of its parent nodes.
In reliability analysis of complex systems, fault trees are a commonly used analysis tool, describing causal relationships between various events using logic gates. However, traditional fault trees rely solely on deterministic logic, which struggles to handle uncertainty issues common in real engineering applications and cannot support backward reasoning. To improve the expressiveness and reasoning capabilities of the model, the fault tree can be converted into a Bayesian network [37], thereby representing dependencies between variables probabilistically.
Basic events serve as independent nodes with assigned prior probabilities; intermediate and top events are modeled with conditional probability tables based on the logic gate structure. Common AND, OR, and NOT gates can be expressed directly through deterministic probability tables to represent their causal logic, or uncertain factors such as incomplete failures or redundant failures can be introduced to build more flexible probability models.
Bayesian networks support bidirectional reasoning, allowing for the prediction of system failure probabilities based on component states, as well as the ability to trace back to the most likely causes after a system failure occurs [38]. Furthermore, the model can integrate observational data for dynamic updates, making it suitable for system diagnostics, operational monitoring, and preventive maintenance. In this way, the original structure of the fault tree is preserved, while improving the accuracy and intelligence level of the system modeling. For a given event A, the probability of event B occurring can be calculated. Based on the fault tree structure in Figure 2, a Bayesian network can be constructed as shown in Figure 3.
Figure 3. Fault Tree Mapped to Bayesian Network. (a) AND Gate; (b) OR Gate.
After the fault tree has been successfully mapped to a Bayesian network, Bayesian inference can be applied to quantitatively analyze the causal relationships between fault events. Bayes’ Theorem provides a systematic way to update the probability of a target event based on new evidence. It is expressed as follows:
P B A = P B P A | B P A
Formula (5) expresses Bayes’ Theorem, where P(B|A) represents the posterior probability of event B occurring given that event A has occurred. The prior probability of event B is denoted by P(B), while P(A|B) is the likelihood of event A occurring, assuming event B has happened. P(A) represents the prior probability of event A, independent of event B. This formula shows how to update the probability of B in light of the occurrence of event A, which is central to statistical inference and decision-making under uncertainty.
In the context of fault diagnosis, event A may represent an observed failure in a component or subsystem, while event B could denote a potential root cause or a system-level fault. By applying Bayes’ Theorem, we can infer the probability of the root cause (B) based on observed evidence (A), thereby supporting more accurate fault isolation.
Based on Equation (5) and the AND-gate logic shown in Figure 3a, the occurrence mechanism and probability expression of event QSW1 can be derived step by step. First, an AND gate represents a “simultaneous occurrence” logic: the output event occurs only when all input events occur. As indicated by the AND-gate structure for QSW1 in Figure 3a, QSW1 is not triggered by a single failure but results from the concurrent failures of ECSW, PCSW, SWP2, and SWP3. Therefore, the occurrence condition of QSW1 can be written as ECSW ∩ PCSW ∩ SWP2 ∩ SWP3.
Next, translating this logical condition into a probabilistic form, the probability of QSW1 is the joint probability that all four input events occur simultaneously, i.e., P(QSW1) = P(ECSW ∩ PCSW ∩ SWP2 ∩ SWP3).
This step directly maps the fault-tree AND-gate structure to its corresponding probabilistic expression.
Finally, according to the AND-gate rule in Equation (5), and under the assumption that the input basic events are mutually independent (or approximately independent), the joint probability can be factorized into the product of the individual probabilities, yieldingP(QSW1) = P(ECSW)·P(PCSW)·P(SWP2)·P(SWP3).
Thus, once the prior probabilities of ECSW, PCSW, SWP2, and SWP3 are obtained, the probability of the intermediate event QSW1 can be calculated by multiplying these terms and then used as an input for subsequent upper-level inference and system risk evaluation.

3. Risk Probability Calculation of LNG Cold Energy Power Generation System

Accurately calculating risk probabilities is crucial for ensuring the safe and efficient operation of LNG cold energy power generation systems. Identifying potential faults, their likelihood, and impacts provides the foundation for robust risk management strategies. This section conducts a comprehensive fault analysis to establish a clear understanding of system vulnerabilities and their associated probabilities.

3.1. Fault Analysis of LNG Cold Energy Power Generation System

To effectively manage the risks inherent in LNG cold energy power generation, a thorough fault analysis is essential. This analysis involves a systematic assessment of individual system components to identify potential failure points, determine their causes, and evaluate their potential impacts on system performance and safety.

3.1.1. LNG Cold Energy Power Generation System

The Zhoushan LNG cold energy power generation system achieves cold energy cascade recovery through an ethylene-propane dual-cycle system. The process flow is as follows: after liquefied natural gas (LNG) is pressurized by a booster pump, it enters the evaporator for reheating and vaporization. The released cold energy is initially recovered by the ethylene working fluid. The vaporized natural gas then enters the temperature-rise heat exchanger, where it exchanges heat with the propane working fluid for secondary heat exchange, completing the staged use of cold energy in different temperature zones. Subsequently, the natural gas is further reheated in the seawater heat exchanger to meet the pipeline transportation temperature requirement, and finally transported to the downstream pipeline. The system operates through the collaboration of two Rankine cycles, driving the expansion generator set to generate electricity [19]. The major equipment and main process flow of the system are shown in Figure 4.
Figure 4. LNG Cold Energy Power Generation System Schematic Diagram.
Given the complexity of the system’s process flow, strong equipment coupling, and the potential risk of cold energy recovery interruptions or natural gas transportation blockages due to failures, it is essential to perform a quantitative assessment of the potential risks. Since the facility lacks long-term operational data, this study employs fault tree analysis to construct a system failure logic model. Expert experience is used to quantify the occurrence probabilities of abnormal basic events for key equipment such as the booster pump, heat exchangers, and generator sets, and Bayesian networks are combined to calculate the system-level failure probability. Sensitivity analysis is conducted to identify the key equipment’s risk contribution, providing a theoretical basis for optimizing operation and maintenance strategies.

3.1.2. Fault Tree Analysis of LNG Cold Energy Power Generation Unit

Based on the LNG cold energy power generation system process flow shown in Figure 4, this study constructs the LNG cold energy power generation system fault tree model, as shown in Figure 5. The system is first divided into four subsystems: LNG, seawater, ethylene, and propane, according to the working fluid supply. Then, the combinations of faults in different subsystems lead to different power generation states, dividing the system into two fault states: shutdown (S) and partial operation (H). This technique supports both quantitative risk assessment based on probabilistic data and qualitative identification of key fault nodes. The equipment failures within different subsystems are further detailed into equipment-level fault trees, as shown in Figure 6, Figure 7, Figure 8 and Figure 9.
Figure 5. LNG Cold Energy Power Generation System Fault Tree Model.
Figure 6. LNG System Fault Subtree.
Figure 7. Ethylene System Fault Subtree.
Figure 8. Propane System Fault Subtree.
Figure 9. Fault Subtrees of Seawater Supply System: (a) LNG Side of Seawater Supply System (b) Ethylene Side of Seawater Supply System (c) Propane Side of Seawater Supply System.
Figure 6 illustrates the fault subtree of the LNG system, clearly depicting the logical relationships between various equipment and their failures within the subsystem. This subsystem is mainly composed of pipelines and heat exchangers, with the equipment connected in series through the pipelines. Therefore, once a failure occurs in any equipment, it may trigger a chain reaction, potentially causing a failure in the entire system or even leading to a shutdown.
Figure 7 and Figure 8 respectively display the fault subtrees of the ethylene system and the propane system. Both systems consist of buffer tanks, pipelines, heat exchangers, booster pumps, and core power generation devices, with a closed-loop structure. In these systems, the booster pump is designed with a dual-pump parallel configuration, and it is only considered a pump failure when both pumps fail simultaneously.
Figure 9 illustrates the seawater supply system, which uses seawater as the medium to provide heat sources for the LNG, ethylene, and propane systems. The three supply lines have the same structure, consisting of identical types of equipment, and operate independently.
The specific fault events, or basic events, for the same type of equipment are further subdivided. The fault subtree diagrams for the main equipment, such as pump sets, generator sets, pipelines, heat exchangers, valves, and buffer tanks, are shown in Figure 10, Figure 11 and Figure 12.
Figure 10. Pump Set Fault Subtree Schematic.
Figure 11. Generator Set Fault Subtree Schematic.
Figure 12. Pipelines (a), Heat Exchangers (b), Valves (c), and Buffer Tanks (d) Fault Subtree Schematic.
Common failure types for pump sets include clogging, leakage, vibration, overload, and control faults. Among these, leakage can be further divided into seal failure, internal corrosion leakage, and external corrosion leakage. Mechanical vibration is typically caused by bearing deformation or improper design and installation. Control faults fall under electrical failures and are mainly manifested as signal distortion and circuit disconnection.
Figure 11 shows the core equipment in the cryogenic power generation system— the generator set. Common failures of the generator set include mechanical and electrical failures. Mechanical failures manifest as leakage and vibration. Leakage typically occurs at sealing points or due to equipment corrosion, while vibration is caused by bearing deformation or rotor failure. Electrical failures include rectifier damage, poor brush contact, voltage regulator failure, and other power generation-related faults. Control-related failures mainly arise from sensor or controller malfunctions, affecting the stability of the power generation process. Additionally, insulation failure is also a significant electrical fault that impacts the normal operation of the generator set.
The pipeline, heat exchanger, valve, buffer tank, and other equipment shown in Figure 12 are relatively static devices, and their failure modes are mainly focused on two issues: clogging and leakage. Among these, pipeline failures are particularly prominent. Common leakage locations in pipelines include flange connections and the pipe body itself. Leakage in the pipe body is typically caused by internal or external corrosion [39], and design defects or improper installation may also lead to leakage issues.
Based on the failure data, the corresponding underlying and intermediate events of the fault subtree can be traced back to Table 1. These events are classified according to the equipment and medium. For example, heat exchanger failures are associated with three failure mechanisms such as X6 clogging and A2 leakage. All underlying event numbers and their equipment affiliations strictly correspond to the statistical results in the table, forming a complete failure causal chain network.
Table 1. Equipment Number and Fault Event Number.
Here, aging is embedded at the basic-event level during the elicitation of fuzzy prior probabilities. The 225 basic events extracted from the fault tree represent concrete, component-specific failure modes (e.g., pump-set degradation, heat-exchanger fouling, pipeline corrosion/leakage, and generator-set malfunction) and are linked to identifiable equipment items (including 21 pipeline types, 7 pumps, and 6 heat exchangers) via a standardized coding scheme. To maintain transparency despite the large number of events, the basic events are further organized by subsystem and, critically, by working medium/operating environment (e.g., LNG-side cryogenic loop, seawater supply loop, ethylene loop, and propane loop), so that each event can be traced along the path “medium/subsystem–equipment–failure mode” and remains an actionable engineering object. Importantly, the 225 events are not assumed to be equally credible or assigned a uniform likelihood; instead, the medium-based categorization is also used in the probability elicitation stage to avoid a one-size-fits-all assumption. Different media imply different dominant degradation mechanisms and baseline probability levels—for example, seawater-side components are more exposed to corrosion, fouling, and intensified mechanical wear, whereas LNG-side components are dominated by low-temperature brittleness, sealing degradation, and thermal-stress-related failures under cryogenic and high-pressure conditions; the ethylene and propane loops exhibit distinct degradation characteristics associated with their own media properties and operating envelopes. Because each basic event is defined to reflect the failure likelihood of its corresponding component under the considered operating period, the effect of equipment aging is inherently included in the event definition and is therefore directly assessed by experts when assigning linguistic ratings and the associated triangular fuzzy numbers. In other words, experts do not evaluate “aging” as a separate variable; instead, they provide an overall judgment of each basic event that already accounts for age-related degradation mechanisms relevant to that component. The resulting fuzzy probabilities thus represent age-inclusive and medium-differentiated priors for the root nodes, which are subsequently used as traceable quantitative inputs for the fuzzy evaluation and mapped into Bayesian network node dependencies for probabilistic reasoning.

3.1.3. Fault Tree Mapping to Bayesian Network

The conversion is based on the relationship between the two models, where events in the fault tree correspond to nodes in the Bayesian network. The failure probability of basic events is converted into the prior probability of the root nodes, and AND/OR gate relationships are transformed into directed arcs. Based on the fault tree structure shown in Figure 5, the conversion results are shown in Figure 13 and Figure 14. Bayesian inference and probability updating are implemented in the GeNle Academic Version 5.0.4830.0 software platform.
Figure 13. Bayesian Network Mapping of LNG Cold Energy Power Generation System Fault Tree.
Figure 14. Schematic Diagram of Fault Tree to Bayesian Network Mapping for Different Equipment. (a) Heat Ex-changer; (b) Pipelines; (c) Buffer Tank; (d) Pump Set; (e) Valve; (f) Generator Set.
In the Bayesian network at the equipment level in Figure 13, it can be observed that the subsystems are relatively independent of each other, but there is an intersection at the heat exchanger equipment. Once a heat exchanger fails, it may simultaneously affect two or more subsystems. For example, the failure of heat exchanger E0502 will directly cause the simultaneous shutdown of the LNG, ethylene, and propane subsystems, making it an important risk point for system-level failure.
The Bayesian network structures of different devices in Figure 14 are relatively simple. Compared to static equipment such as pipelines, buffer tanks, valves, and heat exchangers, pumps and generator sets are more complex due to the inclusion of moving parts, leading to more intricate network branching structures. Based on the previous fault tree analysis, it can be observed that the failure modes of the overall system are primarily in series, while the pump sets exhibit a parallel structure.

3.2. Fuzzy Comprehensive Evaluation Based on Expert Scoring

In the process of fuzzy comprehensive evaluation, scientifically and reasonably determining the weights of evaluation indices is a critical issue. In this section, the Analytic Hierarchy Process (AHP) is first applied to establish an expert capability evaluation index system. By combining expert scoring with calculated weights, it provides a more objective and effective foundation for the subsequent fuzzy comprehensive evaluation.

3.2.1. Establishing Expert Capability Evaluation Index System Based on AHP Method

AHP (Analytic Hierarchy Process) is a structured method used for multi-criteria decision-making. It helps decision-makers make more scientific and rational decisions by breaking down complex problems into multiple hierarchical factors, allowing for trade-offs and selections between various options and criteria [40]. For the relevant experts, an expert capability evaluation index system is established based on their education, professional title, and years of work experience, as shown in Figure 15. Using AHP, different levels of judgment matrices are constructed, and scoring is done using the scaling method. The largest eigenvalue and eigenvector of each judgment matrix are then calculated. After consistency testing, the normalized eigenvector is used as the weight, assigning each expert an appropriate evaluation weight.
Figure 15. Schematic of Expert Capability Evaluation Index System.
Based on the previous paragraph, and in conjunction with the experts’ basic information provided in Table 2, the expert calibration is carried out through the AHP consistency check of the judgment matrices. The consistency ratios of the matrices in Table 3, Table 4, Table 5 and Table 6 are 0.0462, 0.0167, 0.0070, and 0.0128, all below 0.1, indicating that the experts’ judgments are sufficiently consistent and no further correction is needed. In addition, experts’ opinions are not assumed to have equal weights. Expert weights are derived from the validated judgment matrices by obtaining the corresponding weight vectors at each level and then aggregating them in a hierarchical, top-down manner according to the criteria in Figure 15, resulting in the final expert weight vector reported in Table 7.
Table 2. Experts’ Information.
Table 3. Criteria Layer Judgment Matrix.
Table 4. Judgment Matrix under the Influence of Education Level.
Table 5. Judgment Matrix under the Influence of Professional Title.
Table 6. Judgment Matrix under the Influence of Years of Work Experience.
Table 7. Expert Weights.
Finally, the weights of the eight experts are calculated step by step in a top-down manner, and the results are reported in Table 7. Based on the matrices in Table 3, Table 4, Table 5 and Table 6, the corresponding weight vectors are obtained as follows: Table 3: (0.1396, 0.3325, 0.5278); Table 4: (0.2570, 0.2570, 0.2570, 0.0692, 0.0303, 0.0692, 0.0303, 0.0303); Table 5: (0.0945, 0.4183, 0.0945, 0.0945, 0.0242, 0.0945, 0.0851, 0.0945); and Table 6: (0.0236, 0.0709, 0.0477, 0.1059, 0.1572, 0.0327, 0.2307, 0.3313). Following the criteria in Figure 15, the expert weight vector in Table 7 is calculated as (0.07975, 0.21238, 0.09247, 0.09697, 0.09524, 0.05834, 0.15428, 0.21051).
After renormalizing the rounded weights to ensure a unit sum (original sum = 0.99994), the weight range is 0.05834–0.21239 (max/min = 3.64). The cumulative shares of the largest 2, 3, and 4 weights are 0.42292, 0.57720, and 0.67418, respectively, indicating that influence is not excessively concentrated. In addition, the Herfindahl–Hirschman index equals 0.15003 (effective number of experts = 6.67), the normalized Shannon entropy equals 0.95377, and the Gini coefficient equals 0.23992. These results collectively indicate a moderately concentrated yet balanced weighting structure, implying that the aggregated failure-probability results are not driven by any single expert and that any ranking fluctuations, if present, are likely limited to near-tie cases.

3.2.2. Expert Scoring and Fuzzy Evaluation Quantification

The probability of basic events occurring corresponds to different fuzzy numbers, and the associated membership functions also vary. In fuzzy theory, the occurrence of basic events has a certain degree of uncertainty. Therefore, using fuzzy numbers to describe the probability of event occurrence can better express this uncertainty. During the construction of fuzzy numbers, uncertain probability values are typically converted into fuzzy numbers based on expert experience or qualitative descriptions. These fuzzy numbers will have different membership functions under different conditions, reflecting the degree of fuzziness or credibility of a particular event’s occurrence.
In practical applications, especially in the evaluation of root node failures, experts’ qualitative language descriptions are often expressed as fuzzy judgments. To handle these fuzzy judgments, these qualitative descriptions are typically transformed into triangular fuzzy numbers [41]. Triangular fuzzy numbers can be described by a simple set of parameters, usually a small value, the most likely value, and a large value, which can accurately represent the expert’s qualitative evaluation.
According to the correspondence between qualitative language and triangular fuzzy numbers in Table 8, the mapping relationship between these qualitative languages and triangular fuzzy numbers is clarified. Through this transformation, fuzzy number operations can be used for more precise calculations, while effectively addressing and evaluating the root node failure probabilities with greater uncertainty, thus providing more reliable information support for decision-making.
Table 8. The Relationship Between Qualitative Language and Triangular Fuzzy Numbers.

3.3. Failure Risk Probability Calculation

To accurately assess failure risks, it is essential to quantify the probabilities associated with potential risk factors. In this section, we begin by calculating the prior probabilities of root nodes, which serve as fundamental inputs for the comprehensive failure risk probability calculation.
In practice, system failure rates typically follow a bathtub-shaped curve, with higher failure rates at the initial and late stages and a relatively low failure rate during the stable operating period. Early failures are often attributed to commissioning, debugging, and run-in effects, after which the system enters a normal operating stage with reduced and relatively stable failures. As the system approaches the scheduled inspection/overhaul interval, failures become more frequent and tend to increase. The maintenance cycle of the system considered in this study is one year; therefore, experts evaluate the basic events after 10.5 months of accumulated operation (7560 h). In this study, the shutdown-state and partial-operation-state proportions are defined with respect to a fixed late-cycle observation window, specified as the last 1000 operating hours of the annual maintenance cycle. Moreover, reliability-related operating states and performance accounting in this study follow IEEE Std 762-2023 to ensure consistent acceptance assessment [42]. The corresponding outage/derating accounting conventions are aligned with the NERC GADS Data Reporting Instructions (Appendix F) [43]. In conjunction with the original design requirements and with reference to NERC’s State of Reliability 2024, the acceptance criteria are set such that the shutdown-state proportion shall not exceed 5% and the partial-operation-state proportion shall not exceed 10%; compliance with these thresholds indicates that the system meets the acceptance requirements [44].

3.3.1. Calculation of Root Node Prior Probability

Taking the basic event “LNG pipeline blockage” as an example, the eight experts’ qualitative linguistic assessments of its prior probability are, in order, M, M, FL, VL, VL, VL, VL, and L. According to the linguistic-term–to–triangular-fuzzy-number mapping adopted in this study, these assessments are converted into the corresponding triangular fuzzy numbers: (0.35, 0.50, 0.65), (0.35, 0.50, 0.65), (0.17, 0.27, 0.37), (0, 0.05, 0.10), (0, 0.05, 0.10), (0, 0.05, 0.10), (0, 0.05, 0.10), and (0.07, 0.13, 0.19). At this point, the qualitative judgments have been quantified, providing the inputs required for the subsequent calculations.
Next, the expert weight vector given in Table 7 is used to aggregate the eight triangular fuzzy numbers via Equation (1). Specifically, let the weight of expert i be wi and the corresponding triangular fuzzy number be (a, b, c). The aggregated fuzzy number is denoted as (a, b, c), where a, b, and c are obtained by weighted synthesis of the lower, modal, and upper values across all experts. Substituting the weight vector and the eight triangular fuzzy numbers into Equation (1) yields the aggregated fuzzy number (a, b, c) = (0.1327, 0.2186, 0.3045).
After obtaining (a, b, c), Equation (2) is applied to compute the fuzzy possibility evaluation result FM. Substituting (a, b, c) = (0.1327, 0.2186, 0.3045) into Equation (2) gives FM = 0.218646. This value represents the possibility level of the basic event after synthesizing the experts’ opinions with their respective weights.
Finally, to obtain a probability value suitable for subsequent probabilistic reasoning, FM is mapped to the fuzzy probability using Equations (3) and (4). Substituting FM into Equations (3) and (4) results in a fuzzy probability of F = 3.03 × 10−4 for the occurrence of the basic event “LNG pipeline blockage,” which is then taken as the prior probability of this node. The same procedure is applied to the remaining root nodes, and the resulting prior probabilities are summarized in Table 9.
Table 9. Root Node Prior Probability.

3.3.2. System Operation Failure Risk Calculation

By integrating prior probabilities and conditional probability parameters into the Bayesian network model and performing probabilistic inference calculations, the results show that under high load conditions within the 1000 h prior to the overhaul, following long-term accumulated operation, the probability of the “complete shutdown” (S) event is 3.30%, while the probability of the “partial operation” (H) state occurring is 8.24%. The probability distribution of operational states is shown in Figure 16.
Figure 16. System State Probability Distribution.
The calculation results indicate that the system faces significant performance degradation risks during continuous operation, with the probability of partial operation as a transitional stage being notably higher than that of complete shutdown. Therefore, a preventive maintenance mechanism should be established, proactively triggering the partial operation mode to perform online diagnostics and repairs for the shutdown units. This strategy can improve the overall system reliability and effectively ensure the continuous and stable operation of industrial processes.

4. Risk Analysis of LNG Cold Energy Power Generation System

In this study, the system state is denoted as PS, with PS = S representing complete shutdown and PS = H representing partial operation (degraded operation). Accordingly, deterministic evidence in diagnostic inference is imposed as P(PS = S) = 1 or P(PS = H) = 1, and the posterior probabilities of subsystem nodes are updated via backward (diagnostic) belief propagation. In addition, risk acceptance is defined in terms of the predicted reliability-state proportions over the considered maintenance stage: the shutdown-state probability should satisfy P(PS = S) ≤ 5%, and the partial-operation probability should satisfy P(PS = H) ≤ 10%. These criteria provide an explicit, operation-oriented benchmark for judging whether the assessed risk level is acceptable and for linking posterior diagnosis to maintenance prioritization.
Data analysis (Table 10 and Figure 17) shows that when the system is in a complete shutdown state, the posterior failure probability of SWP1 increases from its prior value to 59.92%, and LNGS increases to 34.84%. In the partial operation state, the posterior probability of SWP3 jumps to 32.29%. This difference in probability sensitivity reveals the differentiated impact of failure modes in different subsystems: failures in the LNG supply and seawater supply on the LNG side have a decisive impact on the overall complete shutdown risk, while the seawater supply on the ethylene and propane sides primarily affects the system’s degraded operation capability.
Table 10. Subsystem Prior Probability and Posterior Probability under Different States Table.
Figure 17. Subsystem Prior Probability and Posterior Probability under Different States.
SWP1 and the propane-side seawater pump dominate the inferred system failure be-cause the LNG cold-energy power system is fundamentally constrained by the continuity of LNG-side heat exchange. The reported system-state probabilities (shutdown = 3.30% and partial operation = 8.24%) are evaluated over a fixed observation window: the last 1000 operating hours within a maintenance interval. As indicated by the system structure in Figure 4, the core function is the transfer of LNG cold energy through the heat-exchange chain; once LNG supply is disturbed or interrupted, the plant cannot maintain the required thermal balance and protection logic drives the system directly into a complete shutdown. In this chain, the seawater supply on the LNG side (driven by SWP1) is a hard enabling condition for stable heat exchange: loss of SWP1 effectively removes the primary heat sink/source needed to sustain LNG vaporization/heat-transfer requirements, so the shutdown state becomes highly informative evidence for SWP1-related failure. This is exactly what the posterior inference reflects: under the complete shutdown observation, SWP1’s posterior probability rises sharply to 59.92%. This value is a diagnostic posterior conditioned on the shutdown observation, rather than a reliability metric of SWP1. Meanwhile LNG supply-related causes (LNGS) also increase to 34.84%, confirming that failures in LNG supply and LNG-side seawater supply are decisive drivers of full shutdown risk. In addition to the structural “must-have” role of sea-water pumps, seawater service conditions are inherently harsh; corrosion, fouling, and intensified mechanical wear under continuous operation increase the likelihood of pump and pipeline failures, which further amplifies their dominance in the posterior diagnosis.
By contrast, the ethylene and propane subsystems mainly play supporting roles in heat transfer and energy conversion rather than acting as the primary constraint of LNG cold-energy availability. Their working media are generally less corrosive than seawater, and many of their faults manifest as performance degradation rather than an immediate loss of the system’s funda-mental heat-exchange capability. Consequently, when the system is observed in a partial-operation (degraded) state, the posterior probability concentrates on the component that most directly limits the degraded operating pathway—namely the propane-side seawater pump (SWP3), whose posterior jumps to 32.29%. This value should be interpreted as a diagnostic posterior conditioned on the degraded-state observation. Physically, this aligns with the operational flexibility of the plant: if one conversion/transfer branch fails, the remaining branch may still sustain low-power operation while maintenance or replacement is per-formed, but failure of the key seawater pump serving that branch becomes the bottleneck that determines whether the system can continue in a degraded mode. This subsystem-dependent sensitivity explains why SWP1 (LNG-side seawater supply) dominates complete shutdown, whereas the propane-side pump is most influential for degraded operation capability.
Based on the backward inference results, it is recommended to prioritize the monitoring of subsystems with a posterior probability increase greater than 30%. This bidirectional probability inference method enables backward tracing from system failure phenomena to root causes, providing a quantitative analysis tool for optimizing the reliability of cryogenic power generation systems.
The sensitivity analysis in Figure 18 and Figure 19 quantifies how uncertainty in basic-event parameters propagates to the system-state probabilities. For the complete shutdown state PS = S, the current value is P(PS = S) = 0.0329899 and the reachable range is 0.032546 to 0.0334339. The absolute bandwidth is 0.0008879, about 2.69% relative to the current value. The highest sensitivity is associated with X41, which corresponds to valve V1 leakage. Its local derivative is a = 0.97145, showing an almost one-to-one propagation from the leakage-probability variation to the shutdown probability near the operating point. When X41 varies from 0.004113 to 0.005027, P(PS = S) changes by 0.0008879. Equivalently, a 10% change around the current parameter value 0.00457 induces an approximately 0.000444 change in P(PS = S), which is about 1.35% relative. Other highly ranked sensitivities under PS = S are mainly related to LNG-side flow-continuity constraints, including pipeline corrosion leakage parameters such as X27 and X28, pipeline flange leaks such as X2, X10, and X18, pipeline blockage such as X25, and SWP1 seal and corrosion-related failures such as X30 and X32. These results support a quantified maintenance rule: if the uncertainty of the V1 leakage parameter is reduced from 10% to 5% by intensified inspection or online monitoring, the induced uncertainty in P(PS = S) is approximately halved from about 0.000444 to about 0.000222. Similar uncertainty-reduction actions should target the LNG-side critical pipelines and the SWP1-related failure modes identified above.
Figure 18. Sensitivity Analysis when the Operating State is S (Complete Shutdown).
Figure 19. Sensitivity Analysis when the Operating State is H (Partial Operation).
For the partial-operation state PS = H, the current value is P(PS = H) = 0.0824321 and the reachable range is 0.0820443 to 0.0828199. The absolute bandwidth is 0.0007756, about 0.94% relative. The dominant sensitivities concentrate on ethylene and propane side valve leakage parameters, specifically V3 leakage X220 and V2 leakage X198. Their derivatives are a = 0.84858 and a = 0.831988, respectively. A 10% change around 0.00457 produces an approximately 0.000388 change in P(PS = H), about 0.47% relative. Additional contributors include downstream pipeline corrosion leakage parameters, notably X194, X201, X216, and X223 for internal corrosion leaks and X202, X217, and X224 for external corrosion leaks, as well as generator-set seal-failure leakage X96. Maintenance implications under PS = H can therefore be quantified as prioritizing valve seal and leakage trending for V2 and V3, together with corrosion control for the downstream pipelines, because reducing uncertainty in these parameters yields the largest measurable reduction in the predicted partial-operation probability.

5. Conclusions

By integrating fuzzy comprehensive evaluation with the Analytic Hierarchy Process (AHP), this study develops a fuzzy Bayesian risk assessment model and constructs a multi-level reliability evaluation framework for LNG cold-energy power generation systems. The model combines a fault tree (four subsystems, 21 equipment types, and 225 basic events) with expert-based fuzzy quantification of basic-event probabilities, and then maps the fault tree to a Bayesian network to enable probabilistic updating and dynamic inference. Typical prior probabilities include LNG pipeline blockage (2.89 × 10−4) and seawater valve leakage (4.57 × 10−3), which are assigned to the corresponding root nodes.
Reliability-state evaluation shows that, for a fixed late-cycle observation window defined as the last 1000 operating hours immediately preceding the scheduled overhaul within the one-year maintenance interval, the predicted probabilities of complete shutdown and partial operation are 3.30% and 8.24%, respectively. The low shutdown probability indicates that the system’s logical structure and redundancy effectively reduce the likelihood of immediate collapse, whereas the higher partial-operation probability suggests that performance degradation is more likely to accumulate before a catastrophic failure occurs. Considering the bathtub-shaped evolution of failure rates over the life cycle, experts assessed basic events at 10.5 months of operation for the one-year maintenance interval analyzed in this work. This assessment provides the basic-event priors used to evaluate system reliability states over the final 1000 operating hours leading up to overhaul.
Posterior (backward) inference identifies the components most likely responsible for abnormal system states and supports maintenance prioritization. Under the complete-shutdown state, the posterior failure probability of the seawater supply system pump SWP1 increases to 59.92%, indicating that shutdown is largely driven by SWP1-related failure modes. Under the partial-operation state, the posterior failure probability of the propane-side pump SWP3 rises to 32.29%, implying that partial operation is more strongly associated with propane-side capacity degradation than with a complete loss of seawater supply. Accordingly, components with posterior probabilities above 30% are recommended as priority inspection targets, highlighting SWP1 (59.92%) and SWP3 (32.29%) for state-specific diagnostics and preventive actions.
Sensitivity analysis further reveals the basic events that most strongly influence the top-event probability. The seawater valve V1 exhibits the highest sensitivity, with failure risk increasing nonlinearly once the critical coefficient exceeds 0.83, consistent with threshold-like escalation typical of chloride-induced pitting corrosion. In contrast, the propane valve V3 shows a smaller sensitivity increase (2.1%) but a broader response bandwidth (18.7%), suggesting a more gradual degradation mechanism (e.g., seal wear and thermal cycling) that affects reliability across a wider operating range.
These results yield actionable maintenance guidance and explicit risk acceptance criteria. SWP1 should be the primary diagnostic focus when shutdown is suspected, while SWP3 should be prioritized under partial-operation conditions. For V1, enhanced monitoring and more frequent leakage inspection should be initiated as operating conditions approach the critical coefficient of 0.83 to avoid rapid risk escalation. For V3, continuous leakage trending and seal-condition monitoring are recommended over purely threshold-based alarms. The proposed acceptance criteria require the shutdown proportion to remain below 5% and the partial-operation proportion below 10%. Under the evaluated high-load condition, the predicted shutdown probability (3.30%) and partial-operation probability (8.24%) both satisfy these limits, indicating acceptable risk at the assessed maintenance stage. In addition, introducing parallel valves can reduce the influence of single-valve leakage on the top event by distributing the flow-control function, thereby improving robustness against shutdown and supporting stable partial-load operation.

Author Contributions

Conceptualization, Y.Z., Y.H. and B.W.; methodology, G.Q., Y.W. and C.G.; software, C.G.; validation, C.F. and R.L.; formal analysis, Y.Z. and B.W.; investigation, Y.H.; resources, B.W.; data curation, C.F. and Y.Z.; writing—original draft preparation, Y.Z.; writing—review and editing, Y.H., G.Q., Y.W., C.G., C.F., R.L. and B.W.; funding acquisition, R.L. and B.W. All authors have read and agreed to the published version of the manuscript.

Funding

This research was funded by the “Pioneer” and “Leading Goose” R&D Program of Zhejiang, grant number 2023C04048.

Data Availability Statement

The original contributions presented in this study are included in the article. Further inquiries can be directed to the corresponding authors.

Conflicts of Interest

Author Yungen He was employed by the Zhejiang Electric Power Construction Co., Ltd. Author Rongsheng Lin was employed by the Jurong Energy (XINJIANG) Co., Ltd. The remaining authors declare that the research was conducted in the absence of any commercial or financial relationships that could be construed as a potential conflict of interest.

Abbreviations

The following abbreviations are used in this manuscript:
AHPAnalytic Hierarchy Process
BCNNBayesian Convolutional Neural Networks
BNBayesian Network
CoCoSoCombined Compromise Solution
CPDConditional Probability Distribution
CPTConditional Probability Table
DAGDirected Acyclic Graph
DSW1Complete System Shutdown: Outage scenario caused by the failure of two systems
DSW2Partial System Operation: Partial operation scenario caused by the failure of two systems
ECSWSystem failure: Ethylene Cracking System
ETAEvent Tree Analysis
FAHPFuzzy Analytic Hierarchy Process
FBNFuzzy Bayesian networks
FCEFuzzy Comprehensive Evaluation
FDBNFuzzy Dynamic Bayesian Networks
FTAFault Tree Analysis
HOperating status: Partial System Operation
LNGLiquefied Natural Gas
LNGSSystem failure: LNG System
ORCOrganic Rankine Cycle
PCSWSystem failure: Propane Cycle System
PSOperating status: Power Generation System
QSW1Complete System Shutdown: Outage scenario caused by the failure of all four systems
SOperating status: Complete System Shutdown
SSW1Complete System Shutdown: Outage scenario caused by a single system failure
SSW2Partial System Operation: Partial operation scenario caused by the failure of a single system
STPASystem Theory Process Analysis
SWP1System failure: Failure on the LNG side of the seawater supply system
SWP2System failure: Failure on the ethylene side of the seawater supply system
SWP3System failure: Failure on the propane side of the seawater supply system
TSW1Complete System Shutdown: Outage scenario caused by the failure of three systems

References

  1. Liu, H.; Tang, L.; Dou, Z.; Wang, S.; Yu, D. Optimizing integrated hydrogen liquefaction with LNG cold energy: A thermoeconomic assessment, comparative analysis, and feasibility study with emphasis on composite curves and uncertainty scrutiny. Energy 2025, 315, 134416. [Google Scholar] [CrossRef] [Scilit]
  2. Zhao, W.; Wang, B.; Bei, Y.; Peng, L.; Tao, H.; Varbanov, P.S.; Friedler, F. Multi-period natural gas pipeline scheduling optimisation integrated with LNG cold energy cascade utilisation. Sustain. Energy Technol. Assess. 2025, 83, 104577. [Google Scholar] [CrossRef] [Scilit]
  3. You, J.; Xiao, R.; Alotaibi, M.A.; Chauhdary, S.T.; Ji, T. Integrating an innovative geothermal-driven multigeneration approach and LNG cold energy utilization process for sustainable energy supply, producing hydrogen, power, heating, and cooling. Process Saf. Environ. Prot. 2025, 196, 106904. [Google Scholar] [CrossRef] [Scilit]
  4. Ji, M.; Zhao, Y.; Li, Z.; Han, D.; Wang, B.; Pan, T.; Chen, Y.; Yang, X. Investigation of the cascade utilization of LNG cold energy using total site heat integration method. Therm. Sci. Eng. Prog. 2025, 67, 104209. [Google Scholar] [CrossRef] [Scilit]
  5. Yin, L.; Ju, Y.; Lin, Q. An integrated solution of energy storage and CO2 reduction: Trans-critical CO2 energy storage system combining carbon capture with LNG cold energy. J. Clean. Prod. 2024, 482, 144228. [Google Scholar] [CrossRef] [Scilit]
  6. Li, R.; Xu, C.; Dai, T.; Xu, H.; Xin, T. Thermodynamic analysis and optimization of a novel semi-closed supercritical CO2 power cycle integrated with an air separation unit incorporating LNG cold energy utilization. Energy 2025, 332, 137183. [Google Scholar] [CrossRef] [Scilit]
  7. Mehrenjani, J.R.; Shirzad, A.; Adouli, A.; Gharehghani, A. Data-driven optimization of two novel geothermal-powered systems integrating LNG regasification with thermoelectric generation for eco-friendly seawater desalination and data center cooling. Energy 2024, 313, 133846. [Google Scholar] [CrossRef] [Scilit]
  8. Wan, T.; Zhou, W.; Bai, B.; Zhang, P. Evaluations of energy, exergy, and economic (3E) on a liquefied natural gas (LNG) cold energy utilization system. Int. J. Hydrogen Energy 2024, 65, 308–318. [Google Scholar] [CrossRef] [Scilit]
  9. Li, R.; Tang, F.; Pan, J.; Cao, Q.; Hu, T.; Wang, K. Energy integration of LNG cold energy power generation and liquefied air energy storage: Process design, optimization and analysis. Energy 2025, 321, 135513. [Google Scholar] [CrossRef] [Scilit]
  10. Chen, X.; Yue, J.; Fu, L.; Zhang, M.; Tang, M.; Feng, J.; Shen, B. Green hydrogen production and liquefaction using offshore wind power, liquid air, and LNG cold energy. J. Clean. Prod. 2023, 423, 138653. [Google Scholar] [CrossRef] [Scilit]
  11. Wang, F.; Li, P.; Gai, L.; Chen, Y.; Zhu, B.; Chen, X.; Tao, H.; Varbanov, P.S.; Sher, F.; Wang, B. Enhancing the efficiency of power generation through the utilisation of LNG cold energy by a dual-fluid condensation Rankine cycle system. Energy 2024, 305, 132113. [Google Scholar] [CrossRef] [Scilit]
  12. He, T.; Ma, J.; Mao, N.; Qi, M.; Jin, T. Exploring the stability and dynamic responses of dual-stage series ORC using LNG cold energy for sustainable power generation. Appl. Energy 2024, 372, 123735. [Google Scholar] [CrossRef] [Scilit]
  13. Zhang, Y.; Lin, R.; Wang, F.; Wang, B.; Zhuang, Y.; Liew, P.Y.; Tao, H.; Yan, Y.; Gai, L. Optimization of Dual-Organic Rankine Cycle for LNG wide temperature range cold energy utilization based on Genetic Algorithm. Energy 2025, 341, 139484. [Google Scholar] [CrossRef] [Scilit]
  14. Aneziris, O.; Koromila, I.; Nivolianitou, Z. A systematic literature review on LNG safety at ports. Saf. Sci. 2020, 124, 104595. [Google Scholar] [CrossRef] [Scilit]
  15. Kang, J.; Lv, K.; Sun, Y.; Li, M. Predictive risk assessment framework for leakage accident of offshore LNG transfer system. Expert Syst. Appl. 2025, 271, 126580. [Google Scholar] [CrossRef] [Scilit]
  16. Depken, J.; Simon-Schultz, M.; Baetcke, L.; Ehlers, S. Comparing the safety of bunkering LH2 and LNG using quantitative risk assessment with a focus on ignition hazards. Int. J. Hydrogen Energy 2024, 83, 1243–1250. [Google Scholar] [CrossRef] [Scilit]
  17. Shao, Y.L.; Soh, K.Y.; Wan, Y.D.; Huang, Z.F.; Islam, M.R.; Chua, K.J. Multi-objective optimization of a cryogenic cold energy recovery system for LNG regasification. Energy Convers. Manag. 2021, 244, 114524. [Google Scholar] [CrossRef] [Scilit]
  18. Li, Y.; Liu, Y.; Zhang, G.; Yang, Y. Thermodynamic analysis of a novel combined cooling and power system utilizing liquefied natural gas (LNG) cryogenic energy and low-temperature waste heat. Energy 2020, 199, 117479. [Google Scholar] [CrossRef] [Scilit]
  19. Franco, A.; Giovannini, C. Optimal design of direct expansion systems for electricity production by LNG cold energy recovery. Energy 2023, 280, 128173. [Google Scholar] [CrossRef] [Scilit]
  20. Miętkiewicz, R. LNG supplies’ security with autonomous maritime systems at terminals’ areas. Saf. Sci. 2021, 142, 105397. [Google Scholar] [CrossRef] [Scilit]
  21. Qi, M.; Park, J.; Kim, J.; Lee, I.; Moon, I. Advanced integration of LNG regasification power plant with liquid air energy storage: Enhancements in flexibility, safety, and power generation. Appl. Energy 2020, 269, 115049. [Google Scholar] [CrossRef] [Scilit]
  22. Shady, R.; Ahmed, S.F.; Sleiti, A.K. Operation optimization of propane pre-cooled mixed refrigerant LNG Process: A novel integration of knowledge-based and constrained Bayesian optimization approaches. Chem. Eng. Sci. 2024, 300, 120560. [Google Scholar] [CrossRef] [Scilit]
  23. Mun, H.; Lee, I. Liquid hydrogen cold energy recovery to enhance sustainability: Optimal design of dual-stage power generation cycles. Energy 2023, 284, 129229. [Google Scholar] [CrossRef] [Scilit]
  24. Yeo, S.; Jeong, B.; Lee, W.-J. Improved formal safety assessment methodology using fuzzy TOPSIS for LPG-fueled marine engine system. Ocean Eng. 2023, 269, 113536. [Google Scholar] [CrossRef] [Scilit]
  25. Masalegooyan, Z.; Piadeh, F.; Behzadian, K. A comprehensive framework for risk probability assessment of landfill fire incidents using fuzzy fault tree analysis. Process Saf. Environ. Prot. 2022, 163, 679–693. [Google Scholar] [CrossRef] [Scilit]
  26. Yu, J.; Ding, H.; Yu, Y.; Wu, S.; Zeng, Q.; Xu, Y. Risk assessment of liquefied natural gas storage tank leakage using failure mode and effects analysis with Fermatean fuzzy sets and CoCoSo method. Appl. Soft Comput. 2024, 154, 111334. [Google Scholar] [CrossRef] [Scilit]
  27. Zhou, Q.-Y.; Li, B.; Lu, Y.; Chen, J.; Shu, C.-M.; Bi, M.-S. Dynamic risk analysis of oil depot storage tank failure using a fuzzy Bayesian network model. Process Saf. Environ. Prot. 2023, 173, 800–811. [Google Scholar] [CrossRef] [Scilit]
  28. Tian, R.; Yang, S.; Wang, C.; Ma, Z.; Kang, C. Medicine-Shelf matching strategy based on Bayesian convolutional neural network with fuzzy analytic hierarchy process. Expert Syst. Appl. 2023, 231, 120814. [Google Scholar] [CrossRef] [Scilit]
  29. Shi, M.; Zhang, J.; Lang, X.; You, Q.; Jing, Y.; Huang, D.; Dai, H.; Kang, J. Dynamic risk evaluation of hydrogen station leakage based on fuzzy dynamic Bayesian network. Int. J. Hydrogen Energy 2024, 50, 1131–1145. [Google Scholar] [CrossRef] [Scilit]
  30. Mahmood, Y.; Chen, J.; Yodo, N.; Huang, Y. Optimizing natural gas pipeline risk assessment using hybrid fuzzy Bayesian networks and expert elicitation for effective decision-making strategies. Gas Sci. Eng. 2024, 125, 205283. [Google Scholar] [CrossRef] [Scilit]
  31. Zhu, T.; Meng, C.; Han, X.; Wang, Y.; Dang, J.; Chen, H.; Qi, M.; Zhao, D. A risk assessment framework for water electrolysis systems: Mapping System Theoretic Process Analysis (STPA) and Event Tree Analysis (ETA) into Fuzzy Bayesian Networks (FBN). Process Saf. Environ. Prot. 2025, 194, 306–323. [Google Scholar] [CrossRef] [Scilit]
  32. Shalev, D.M.; Tiran, J. Condition-based fault tree analysis (CBFTA): A new method for improved fault tree analysis (FTA), reliability and safety calculations. Reliab. Eng. Syst. Saf. 2007, 92, 1231–1241. [Google Scholar] [CrossRef] [Scilit]
  33. Cheng, S.R.; Lin, B.; Hsu, B.M.; Shu, M.H. Fault-tree analysis for liquefied natural gas terminal emergency shutdown system. Expert Syst. Appl. 2009, 36, 11918–11924. [Google Scholar] [CrossRef] [Scilit]
  34. Onisawa, T. An approach to human reliability in man-machine systems using error possibility. Fuzzy Sets Syst. 1988, 27, 87–103. [Google Scholar] [CrossRef] [Scilit]
  35. Karimi, I.; Hüllermeier, E. Risk assessment system of natural hazards: A new approach based on fuzzy probability. Fuzzy Sets Syst. 2007, 158, 987–999. [Google Scholar] [CrossRef] [Scilit]
  36. Machado, P.G.; de Oliveira Ribeiro, C.; do Nascimento, C.A.O. Risk analysis in energy projects using Bayesian networks: A systematic review. Energy Strategy Rev. 2023, 47, 101097. [Google Scholar] [CrossRef] [Scilit]
  37. Wang, L.; Huang, Y.; Wang, Y.; Gu, B.; Li, B.; Fang, D. Comprehensive lifecycle safety risk assessment for construction robotics using TS fault tree analysis and Bayesian network. Autom. Constr. 2025, 172, 106041. [Google Scholar] [CrossRef] [Scilit]
  38. Khakzad, N.; Khan, F.; Amyotte, P. Safety analysis in process facilities: Comparison of fault tree and Bayesian network approaches. Reliab. Eng. Syst. Saf. 2011, 96, 925–932. [Google Scholar] [CrossRef] [Scilit]
  39. Qu, Z.; Jiang, X.; Zou, X.; Yue, X.; Xing, Y.; Zhu, J.; Zhang, L. An active learning framework assisted development of corrosion risk assessment strategies for offshore pipelines. Process Saf. Environ. Prot. 2024, 192, 738–749. [Google Scholar] [CrossRef] [Scilit]
  40. Zhong, C.; Yang, Q.; Liang, J.; Ma, H. Fuzzy comprehensive evaluation with AHP and entropy methods and health risk assessment of groundwater in Yinchuan Basin, northwest China. Environ. Res. 2022, 204, 111956. [Google Scholar] [CrossRef] [Scilit]
  41. Guan, X.; Yu, F.; Xu, H.; Li, C.; Guan, Y. Flood risk assessment of urban metro system using random forest algorithm and triangular fuzzy number based analytical hierarchy process approach. Sustain. Cities Soc. 2024, 109, 105546. [Google Scholar] [CrossRef] [Scilit]
  42. IEEE Std 762-2023; IEEE Standard Definitions for Use in Reporting Electric Generating Unit Reliability, Availability, and Productivity. IEEE Standards Association: Piscataway, NJ, USA, 2023. Available online: https://standards.ieee.org/ieee/762/6856/ (accessed on 20 January 2026).
  43. North American Electric Reliability Corporation (NERC). Appendix F: Performance Indexes and Equations. In GADS Data Reporting Instructions; North American Electric Reliability Corporation (NERC): Atlanta, Georgia, 2025; Available online: https://studylib.es/doc/9543360/appendix-f-equations-2023-dri (accessed on 20 January 2026).
  44. North American Electric Reliability Corporation (NERC). State of Reliability 2024: Technical Assessment of 2023 Bulk Power System Performance; North American Electric Reliability Corporation (NERC): Atlanta, Georgia, 2024; Available online: https://www.nerc.com/pa/RAPA/PA/Performance%20Analysis%20DL/NERC_SOR_2024_Technical_Assessment.pdf (accessed on 20 January 2026).
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.

Article Metrics

Citations

Article Access Statistics

Multiple requests from the same IP address are counted as one view.