Risk Analysis of Instability Failure of Earth–Rock Dams Based on the Fuzzy Set Theory

: Determining the anti-sliding instability risk of earth–rock dams involves the analysis of complex uncertain factors, which are mostly regarded as random variables in traditional analysis methods. In fact, fuzziness and randomness are two inseparable uncertainty factors inﬂuencing the stability of earth–rock dams. Most previous research only focused on the randomness or the fuzziness of individual variables. Moreover, dam systems present a fuzzy transition from a stable state into a failure state. Therefore, both fuzziness and randomness of the inﬂuencing factors should be considered in the same framework, where the instability of an earth–rock dam is regarded as a mixed process. In this paper, a fuzzy risk model of instability of earth–rock dams is established by considering the randomness and fuzziness of parameters and the failure criteria comprehensively. We obtained the probability threshold of instability risk of earth–rock dams by Monte-Carlo simulation after the fuzzy parameters were transformed into interval numbers by cut set levels. By applying the proposed model to the instability analysis of the Longxingsi Reservoir, the calculation results showed that the lower limits of risk probability under different cut set levels exceeded the instability risk standard of grade C for earth–rock dams. Compared with the traditional risk determination value, the risk interval obtained with the proposed methods reﬂects different degrees of dam instability risk and can provide reference for dam structure safety assessment and management.


Introduction
The stability of earth-rock dams must be guaranteed during operation. Once a dam breaks, it will cause disastrous consequences to human life and the economy [1]. Slope instability is one of the important causes of earth-rock dams' failure [2,3]. According to statistical data, 38% of 1609 dam failure accidents occurred in 56 countries were caused by engineering structural problems, among which structural problems caused by dam slope instability failure accounted for about 40%. Earth-rock dam failure accidents caused by slope instability account for about 25% of dam failure events in China [4,5]. What makes the situation even more serious is that more than 80% of earth-rock dams built in China have reached their normal service life at present [6,7]; therefore, it is necessary to analyze the instability failure risk of earth-rock dams.
The traditional risk analysis of earth-rock dam instability is mostly based on probability theory, which mainly considers the randomness of the variables or instability criteria that affect dam stability. Based on the analysis of randomness of the variability of soil shear strength parameters, Chu et al. [8] carried out reliability analysis of earth-rock dams' slope. Combined with numerical simulation and monitoring data, Pinyol et al. [9] analyzed the risk of landslide instability of earth-rock dams caused by the change of reservoir's water level. Considering the nonlinearity of the soil failure criterion, Wang et al. [10] carried out a slope stability analysis of earth-rock dams. However, it is difficult to accurately determine the value of variables in actual projects because of the fuzziness of the soil strength parameters. In fact, the earth-rock dam is not certainly stable when the resistance is greater than the load [11], which means there is a fuzzy region of transition from the stability status to the failure status. Therefore, we introduced fuzzy methods and hybrid variations. Because the advanced fuzzy methods and hybrid variations have high requirements for the number and accuracy of parameters [12,13], their practical engineering application is limited [14,15]; therefore, we used the traditional methods.
Referring to the complex fuzzy factors in engineering systems, researchers have introduced the fuzzy set theory into the field of dam risk analysis and achieved a series of results [16]. Park et al. [17] developed a stability evaluation model of rock slope, which regards the stability evaluation process as a process of dealing with the fuzziness of data. Canal et al. [18] carried out a risk analysis of gravity dams' instability, which considered the fuzziness of monitoring data of gravity dam foundation. Haghighi et al. [19] established a risk analysis model of gravity dams' instability, in which the randomness and fuzziness of design parameters and measured data were jointly considered. These studies were often based on the analysis of a certain weak surface of the structures, and most of them only considered the fuzziness of individual variables. It is difficult to determine the shape and position of the sliding surface of an earth-rock dam, which increases the difficulty of a fuzzy analysis of the variables. Therefore, in this manuscript a fuzzy risk model corresponding to characteristics of the instability failure of earth-rock dams was established and was based on the fuzzy set theory by considering the random uncertainty of design parameters and the fuzziness of failure criteria. Furthermore, the fuzzy risk interval of earth-rock dams' instability was obtained, which provides guidance for risk management with reference to risk standards.

Uncertain Factors Affecting the Stability of Earth-Rock Dams
When the sliding moment L acting on an earth-rock dam exceeds its anti-sliding moment R, the earth-rock dam will be unstable according to the traditional analysis. However, in the engineering field, there are serious cognitive uncertainties about the factors affecting the sliding moment and anti-sliding moment of earth-rock dams, which are embodied in the following three aspects.

•
Uncertainty of human factors Although human factors are difficult to evaluate directly and quantitatively in risk analysis, they must be considered in engineering risk assessment. From 1954 to 2018, dam failure accidents caused by human factors accounted for 4.83% in China and were mainly related to management errors [20,21]. In 1993, the dam failure of the Gouhou Reservoir in Qinghai, China, killed more than 340 people [22]. The accident investigation showed that defects caused by human management errors in the process of design and construction of the dam were one of the main factors of the accident.

•
Uncertainty of the calculation model The uncertainty of a risk calculation model for earth-rock dams needs to be analyzed. Firstly, a simulation model used to calculate the structural stability of an earth-rock dam is only an approximation of the prototype. Secondly, the selected simulation model is only one of the calculation models. Thirdly, inappropriate analysis models may be selected due to the uncertainty of the concept. For example, the Bishop method considers the interaction between soil strips, while the Swedish method does not. If different models are selected in the design of an earth-rock dam, the safety factor is also different, resulting in different Water 2021, 13, 3088 3 of 13 errors. Lastly, unpredictable potential anomalies increase the uncertainty of using models to represent real engineering systems [23].

Uncertainty of parameters
The uncertainty of parameters is mainly caused by statistical errors and variability and represents most of the uncertainty in the analysis [24]. In practice, the instability failure of an earth-rock dam is influenced by many uncertain factors such as water level, material parameters, structure size, and so on. At present, water levels and material parameters are the two most remarkable factors in the stability reliability analysis of earth-rock dams [25].
(a) During the rise and drawdown of a reservoir's water level, the soil undergoes the process of mutual transformation between saturation and unsaturation, which further affects the soil strength and local pore water pressure, as well as the stability of the earthrock dam. The water level is a random variable, whose uncertainty can be described with a probability curve of the water level [26,27]. When analyzing the distribution of the reservoir's water level, the distribution profile can be regarded as a reasonable approximation of the probability curve of the reservoir's water level.
(b) The material parameters that affect the stability of an earth-rock dam mainly include soil cohesion c, internal friction angle ϕ, and bulk density γ. The accurate values of the material parameters for a certain zone are uncertain due to the variability of the soil properties in the time-space domain. Furthermore, the uncertainty of the material parameters can be caused by the test process and the difference between test and actual conditions in laboratory tests or field experiments [28].
In the instability analysis of earth-rock dams, the influence of the variability of γ, which can be regarded as a fixed value, is less significant than that of the physical and mechanical parameters c and ϕ [29]. The variation coefficients of the internal friction angle ϕ and the cohesion c can be determined through tests and statistical analysis of practical engineering samplings.

Calculation Model of Fuzzy Risk
We define the sliding moment and the anti-sliding moment as L and R, respectively. The value of R is closely related to the change of the upstream water level and the saturation line of the dam body. The value of L is mainly related to the variability of the soil parameters. The traditional instability risk model of earth-rock dams is shown as Equation (1) [30]: where f R,L (r,l) is the joint probability density function of L and R. Because the sliding moment and anti-sliding moment are relatively independent when the shape and position of the sliding surface associated with instability failure of an earth-rock dam is certain, the risk model can be expressed as Equation (2).
The conditional probability density function of the sliding moment and upstream water level is shown in Equation (3).
where f (l/h) is the conditional probability density function of the sliding moment (L) under a certain water level h, and f H (h) is the probability density function of the upstream water level of the dam.
According to the full probability formula, Equation (4) can be derived as: the instability failure risk model of earth-rock dams can be expressed as Equation (5): where F L (h) is the probability that the sliding moment is greater than the anti-sliding moment under a certain water level h.
Considering the fuzziness of random variables and failure criteria, as well as the uncertainty of human factors and the calculation model for earth-rock dams, the concept of membership function in the fuzzy set theory is introduced to describe the uncertainty of the instability process of earth-rock dams [31]. If the anti-sliding moment R, sliding moment L, and the failure criterion are taken as fuzzy random variables, the fuzzy risk model of instability failure of earth-rock dams is represented by Equation (6): where µ Z ∈ [0,1] is the membership degree of the system state variable Z to the fuzzy event of instability failure, and µ R and µ L ∈ [0,1] are membership functions of ® and (L), respectively [27]. According to Equation (5), Equation (6) can be transformed into Equation (7): When the fuzziness of R, L, and failure criteria are not taken into account, that is, µ R (r) = µ L (l) = µ Z (r,l) = 1, Equation (7) can be transformed into Equation (5), which is consistent with the traditional risk calculation model. The fuzzy risk model constructed with Equation (7) is compatible with the risk model not considering fuzziness, but the latter is a special case of the former.

Method for Eliminating Fuzziness
According to Equation (7), it is necessary to calculate the fuzzy risk with fuzzy variables and membership functions through integration, in which the determination of membership functions is very difficult. According to the concept of level cut set in the fuzzy set theory, a fuzzy set can be transformed into a classical set [32]. After the fuzzy variables are converted into interval numbers, the traditional risk calculation method can be used to solve the fuzzy risk model.
Assuming that the average range of the design parameters is [a, b], the fuzzy parameter interval can be obtained by introducing the level cut set α (α ∈ [0,1]), as shown in Equation (8): where k = (b − a)/2, which reflects the fuzzy boundary range of the average value of the design parameters. According to the actual situation of the project, it is generally taken as k = 10% × [(b + a)/2]; α is the boundary variable of the fuzzy state and has a corresponding fuzzy range for each value in [0,1], indicating the fuzzy degree of the design parameter values. The greater the value of α is, the narrower the range is. When α = 1, the fuzzy interval reaches a point in which the fuzziness of the design parameters is not considered. By introducing the level cut set α (α ∈ [0,1]), the fuzzy interval of the failure criterion can also be obtained, as shown in Equation (9): where δ represents the maximum allowable margin of limit state, which shall be determined according to the actual engineering situation and management situation by experts during the calculation. When α = 1, the failure criterion is determined. Combining Equations (8) and (9) to eliminate the fuzziness of the design parameters and criteria, fuzzy intervals can be given by: The limit state equation shown in Equation (1) is transformed into: According to Equation (7), Equations (13) and (14) can be converted into Equations (15) and (16): The fuzzy risk interval is written as follows: are the lower and upper limits of fuzzy risk probability, respectively.
After the fuzziness is eliminated, . The upper and lower limits of the fuzzy risk interval can be calculated by using traditional risk calculation methods. Different values in the interval represent different degrees of fuzzy risk, which is more reasonable than the single value of traditional risk determination.

Fuzzy Risk Calculation
Due to the difficulty in solving the integral expression of the fuzzy risk calculation model, the discrete numerical integration method is used to calculate the fuzzy risk probability [33]. Assuming the lowest and highest water levels of reservoir operation in the actual project are H 1 and H 2 , respectively, the range of the water level H is from H 1 to H 2 . Thus, Equation (7) can be converted into Equations (18) and (19) according to Equations (15) and (16): where F L (h i ) is the probability of instability failure of the earth-rock dam when the given water level interval is h i , ∆F H h i is the interval frequency of the reservoir water level, and n is the number of divided intervals of the reservoir water level.

The solution of ∆F
According to the probability curve of water level, the corresponding probability value between the two water levels can be found. Reservoir regulation can be carried out by a probability algorithm, through which the reservoir storage probability curve can be divided into several sections. Taking the water level at the end of the section as the initial water level for regulation, the flood evolution of each frequency layer can be determined. Eventually, the water level probability curve can be obtained by probability combination [34]. By statistical analysis of long-term monitoring data, the distribution pattern of the reservoir water level can also be obtained, which can be regarded as a reasonable approximation of the probability curve of the water level [35].

2.
The solution of The instability risk of an earth-rock dam under a certain reservoir water level is related to the location of the sliding surface [36]. In order to obtain the maximum value of F L (h i ), the minimum safety factor K min of dam instability under a certain water level should be determined firstly. Secondly, the most dangerous sliding surface corresponding to the minimum safety factor is considered to calculate the sliding force and anti-sliding force of the most dangerous sliding surface by using the limit equilibrium method. Finally, the maximum value of F L (h i ) can be obtained by substituting the limit state equation of dam slope stability.

3.
Limit state equation According to the traditional stability analysis method [37], the safety factor K can be expressed as: where (w i ) 1 is the weight of the soil strip when calculating the sliding moment, (w i ) 2 is the weight of the soil strip when calculating the anti-sliding moment, α i is the angle between each block and the center line of the sliding arc, ϕ i and c i are effective shear strength indexes, and l i is the bottom arc length of each block. The limit state equation of earth-rock dam stability is as follows: The probability interval of instability risk of an earth-rock dam under a certain water level can be calculated by the Monte-Carlo method. The calculation flow chart is shown in Figure 1.

Risk Standard for Instability Failure of Earth-Rock Dams
Risk analysis research all over the world generally attach importance to risk probability analysis. However, due to the inconsistence of the evaluation systems in different countries, a unified risk standard has not yet been established [38]. According to the Guidelines for Safety Evaluation of Reservoir Dams issued by China, Jiang et al. [39] provided different risk probability thresholds for earth-rock dams based on the calculation of reliability analysis. The risk rate thresholds P fa and P fb for a certain variation range were set as reasonable risk standards: when P < P fa , the security level is grade A, which indicates the safety state; when P fa ≤ P < P fb , the security level is grade B, which indicates the basic safety state; when P ≥ P fb , the security level is grade C, which indicates an unsafety state. The risk rate thresholds under different conditions are shown in Table 1.

Risk Standard for Instability Failure of Earth-Rock Dams
Risk analysis research all over the world generally attach importance to risk probability analysis. However, due to the inconsistence of the evaluation systems in different countries, a unified risk standard has not yet been established [38]. According to the Guidelines for Safety Evaluation of Reservoir Dams issued by China, Jiang et al. [39] provided different risk probability thresholds for earth-rock dams based on the calculation of reliability analysis. The risk rate thresholds Pfa and Pfb for a certain variation range were set as reasonable risk standards: when P < Pfa, the security level is grade A, which indicates the safety state; when Pfa ≤ P < Pfb, the security level is grade B, which indicates the basic safety state; when P ≥ Pfb, the security level is grade C, which indicates an unsafety state. The risk rate thresholds under different conditions are shown in Table 1. Table 1. Risk thresholds of instability failure for earth-rock dams [39].

Case Study: The Longxingsi Reservoir
The Longxingsi Reservoir dam is located in Henan Province, China. After decades of operation, the downstream slope of the dam presents an obvious uplift and deformation. Therefore, the Dam Safety Management Center of the Ministry of Water Resources of

Case Study: The Longxingsi Reservoir
The Longxingsi Reservoir dam is located in Henan Province, China. After decades of operation, the downstream slope of the dam presents an obvious uplift and deformation. Therefore, the Dam Safety Management Center of the Ministry of Water Resources of China carried out a safety appraisal of the dam and evaluated the safety grade of the dam structure in 2007. According to the calculation parameters provided by the safety appraisal report, the fuzzy analysis of the instability failure risk of the earth-rock dam was carried out using the model and method proposed in this manuscript.

Basic Data
In order to analyze the stability of the dam, a survey section was arranged at a weak interlayer in the dam body during safety evaluation, and indoor tests were carried out by using borehole and shaft sampling. According to the test results of soil sampling, the physical and mechanical indexes of several samples were analyzed comprehensively to determine the calculation parameters. The results are shown in Table 2. Since the weight of variable uncertainty cannot be determined on a temporal basis, it is recommended to consider the uncertainty of the variables equally [40]. The variation coefficient of cohesion c and internal friction angle ϕ could be determined by statistical analysis of the sampling test results. The distribution form of the parameters is shown in Table 3. The normal water level of the Longxingsi reservoir is 279.0 m, the design flood level is 284.41 m, and the check flood level is 286.8 m. According to the water level monitoring data of the reservoir dam operation collected in more than 40 years, the water level of the reservoir basically obeys a normal distribution. The frequency value of each reservoir water level interval could be obtained through statistical analysis, as shown in Table 4.

Calculation of
GeoStudio is a slope stability analysis software based on the limit equilibrium method and the numerical analysis method [41]. It is widely used for its ability of accurately and quickly determining the minimum safety factor and the most dangerous slip surface of a slope [42]. There are many contact surfaces where sliding instability may occur under a certain water level condition. According to the water level interval set in Table 4, the position of the sliding arc surface with the minimum safety factor and the corresponding safety factor K min are obtained by using the slope stability calculation module of GeoStudio calculation software. Then, the sliding force and anti-sliding force at this position are calculated by using the model proposed in this paper, and the probability value of dam slope instability risk is calculated by a Monte Carlo simulation. Different water levels correspond to different dangerous sliding arc surfaces; the minimum safety factors are shown in Table 5. X 0 and Y 0 are the center coordinates of the most dangerous slip surface, and R is the corresponding radius.

Fuzzy Risk Calculation
The fuzzy risk of stability failure of the earth-rock dam was calculated by Equation (18) and Equation (19). Taking α = 0.5 as an example, the calculation results are shown in Table 6: Table 6. Fuzzy risk probability value under all water levels of the reservoir (α = 0.5).

Reservoir Water
Level (m) The risks under different cut-off levels are shown in Table 7 and Figure 2:

Discussion
(1) According to Figure 2, the range of fuzzy risk value is the greatest when the level cut set α = 0. When α = 1.0, the determined probability value of instability risk is 2.67 × 10 −3 , which is consistent with the risk rate calculated by the traditional reliability method. Therefore, the results of the risk fuzzy analysis based on the fuzzy set theory include the result of the traditional reliability method, but are more comprehensive, as shown in Figure 2. (2) The different interval values in Table 7 represent different degrees of fuzzy risk; in addition, the risk interval values from the lower limit to the upper limit indicate the gradual process of dam instability risk transition. The fuzzy risk interval when α = 0.5, indicating that the fuzziness of each design parameter was considered equally, was selected as the risk of downstream dam slope instability failure. The risk interval was [2.72 × 10 −3 , 3.14 × 10 −3 ], and the average value was 2.93 × 10 −3 . From the perspective of engineering risk, the risk probability of the earth-rock dam changes relatively little in this risk interval. Referring to the corresponding risk standards, the upper and lower limits of the interval can provide reference for further risk assessment.
(3) Referring to the risk standard shown in Table 1, the upper and lower limits of the fuzzy risk interval when α = 0.5 were all greater than Pfb, indicating that the risk of stability failure of the dam is appreciable. According to the Guideline of Dam Safety Evaluation SL258-2017 [43], the stability of the dam structure is evaluated as grade C, which indicates reinforcement measures are necessary. This result is consistent with the conclusion drawn by experts on the stability of the dam structure, which verifies the rationality of the fuzzy risk model of instability of earth-rock dams. Compared with the deterministic risk probability obtained by the traditional method, a risk interval of values was obtained by considering the fuzziness of the variables, which reflects the actual situation of the dam more comprehensively.
(4) It should be pointed out that the upper and lower limits of the risk interval may fall into different levels of risk standards. In order to evaluate the dam safety level, the risk interval under the appropriate cut-off level needs to be selected; this is an advantage

Discussion
(1) According to Figure 2, the range of fuzzy risk value is the greatest when the level cut set α = 0. When α = 1.0, the determined probability value of instability risk is 2.67 × 10 −3 , which is consistent with the risk rate calculated by the traditional reliability method. Therefore, the results of the risk fuzzy analysis based on the fuzzy set theory include the result of the traditional reliability method, but are more comprehensive, as shown in Figure 2.
(2) The different interval values in Table 7 represent different degrees of fuzzy risk; in addition, the risk interval values from the lower limit to the upper limit indicate the gradual process of dam instability risk transition. The fuzzy risk interval when α = 0.5, indicating that the fuzziness of each design parameter was considered equally, was selected as the risk of downstream dam slope instability failure. The risk interval was [2.72 × 10 −3 , 3.14 × 10 −3 ], and the average value was 2.93 × 10 −3 . From the perspective of engineering risk, the risk probability of the earth-rock dam changes relatively little in this risk interval. Referring to the corresponding risk standards, the upper and lower limits of the interval can provide reference for further risk assessment.
(3) Referring to the risk standard shown in Table 1, the upper and lower limits of the fuzzy risk interval when α = 0.5 were all greater than P fb , indicating that the risk of stability failure of the dam is appreciable. According to the Guideline of Dam Safety Evaluation SL258-2017 [43], the stability of the dam structure is evaluated as grade C, which indicates reinforcement measures are necessary. This result is consistent with the conclusion drawn by experts on the stability of the dam structure, which verifies the rationality of the fuzzy risk model of instability of earth-rock dams. Compared with the deterministic risk probability obtained by the traditional method, a risk interval of values was obtained by considering the fuzziness of the variables, which reflects the actual situation of the dam more comprehensively.
(4) It should be pointed out that the upper and lower limits of the risk interval may fall into different levels of risk standards. In order to evaluate the dam safety level, the risk interval under the appropriate cut-off level needs to be selected; this is an advantage that allows directly judging the dam safety level, in contrast with the traditional risk determination value. In addition, the analysis model can be further optimized to quantitatively estimate the degree of influence of the uncertainty of each factor, so as to improve the accuracy of the evaluation.

Conclusions
Most of the traditional risk analysis methods only consider the randomness of the factors which affect the stability of earth-rock dams. However, due to the complexity of factors influencing the stability risk of a dam, the fuzziness of various factors should be considered. In this paper, a fuzzy risk model of instability failure of earth-rock dams based on the fuzzy set theory was established through comprehensively considering the randomness and fuzziness of the risk factors. The fuzzy variable was transformed into an interval number by the use of the level cut set, then the Monte-Carlo method was employed to calculate the risk probability. Based on the risk analysis of instability failure of the Longxingsi reservoir dam, both the upper and the lower limits of the risk probability were found to be on the dangerous side. The safety assessment evaluated the dam structure stability as grade C, which is consistent with the conclusion of the dam safety appraisal. The parameters used in this method are in good agreement with those of the traditional methods. Solving the model does not present significantly increased difficulties to researchers investigating the cracking and failure risk of traditional earth-rock dams. Compared with the risk value determined by the traditional risk analysis method, the risk interval value obtained by this method is more in line with engineering practice and provides a new possibility for risk assessment by relevant scholars and government departments, as well as reference and support for dam risk management.