1. Introduction
Maglev trains represent a new type of urban rail transit system, and their systems’ safety and reliability are of great significance for ensuring the safety of people’s lives and property, directly influencing the sustainable development of maglev transportation commercialization. As train equipment becomes increasingly information-based and complex, there are higher demands for risk analysis concerning maglev trains. Against the backdrop of rising issues in safety-related fields, finding the weak links in the system through risk analysis and conducting qualitative and quantitative analysis on them is becoming more and more important.
Risk analysis technology originated from the demand for system safety theory and engineering applications in the U.S. military industry, leading to its rapid development and emergence as a new discipline, which is a branch of systems engineering. Currently, different countries adopt various standards for safety management in urban rail transit systems. To unify the management standards among its member states, the European Union has established safety management specifications for urban rail transit systems, which have become a major global reference. Japan, which initially did not adopt the RAMS standards but maintained a high level of rail system safety, transformed IEC61508 into the national standard JIS-C-0508 after the widespread international acceptance of the RAMS concept [
1]. Additionally, Japan developed the “Technical Guidelines for the Safety of Train Security Control Systems” based on its domestic context. South Korea has developed an urban rail transit operation safety risk assessment system (KRRI), consisting of four subsystems including accident analysis.
Muttram R.I. conducted research on railway safety risks by analyzing potential safety risk factors using fault tree analysis. Based on this analysis, he developed a railway safety risk assessment model and conducted detailed model analysis, providing strategies to mitigate railway safety risks [
2]. Jafarian E., Rezvani M.A., and others studied the causes of train derailment, employing fuzzy set theory to construct an analysis model. They identified six major categories of risk factors and, using the model, assessed and determined the root causes of train derailments [
3]. Chris J. Baker focused on assessing risks in urban rail transit, categorizing risk factors and utilizing expert scoring to determine the weights of these factors. The model developed in this study is highly targeted, enhancing the objectivity and accuracy of the risk assessment results [
4]. M. Bulakh, A. Okorokov, D. Baranovskyi, and others built a railway traffic risk assessment system based on the current state of railway accidents. Their study classified operational risks according to their nature, discussing general, local, and technical risks in detail, and proposed targeted risk mitigation measures [
5]. Aleksandar Blagojevic, Sandra Kasalica, and others used the entropy weighting method to develop a safety risk assessment model for urban rail transit. Through this model, they identified evaluation indicators, assigned weights to these indicators, and employed fuzzy comprehensive evaluation to process the data, providing valuable insights for railway system safety assessments [
6].
In summary, the formulation and optimization methods of risk assessment strategies are among the keys to improving the safety of railway equipment. This paper conducts a risk analysis of the levitation system, explores the theory of multi-attribute decision-making, establishes new risk evaluation indicators using triangular fuzzy numbers, and determines the risk levels of levitation system failures. These efforts provide direction for the implementation of train maintenance work.
  2. Maglev Train Suspension System
  2.1. Structure Principle of Suspension System
A maglev train is supported by five independent bogies. The car body is mounted on the bogies through a secondary suspension system composed of air springs and dampers [
7]. Each bogie relies on eight levitation electromagnets to generate an attractive force against the track, supporting the train body and maintaining a fixed gap with the track, embracing it without mechanical contact, as shown in 
Figure 1.
Each bogie of the magnetic levitation train is further divided into two suspension modules: left and right. Each module includes four electromagnets corresponding to one suspension control system [
8,
9]. Thus, a single bogie includes two independent suspension control systems, and the entire train comprises a total of ten suspension control systems. Each suspension control system (referred to as a suspension unit) operates by controlling two levitation electromagnets to achieve suspension for one module. The suspension control system mainly consists of suspension sensors (position, acceleration, and current sensors), a suspension controller, a power chopper, and auxiliary devices such as a control power supply, as shown in 
Figure 2.
  2.2. Levitation System Control Mode
The suspension control methods include module suspension mode and single-point suspension mode. The module suspension mode is the fundamental mode of suspension control [
10]. It treats the module as a complete controlled object and incorporates the state information from both endpoints into the control algorithm in real-time, actively suppressing the mutual influence between the two ends. As a result, previously unknown coupling information becomes measurable and controllable state variables within the system, thereby eliminating the impact of coupling on system performance. The single-point suspension system relies on the compression or extension of coil springs to absorb impacts, with shock absorbers dissipating the vibrational energy of the springs. The lower control arm transmits forces and moments, guiding the wheel to follow a specific trajectory, thereby ensuring driving stability and handling [
11]. However, compared to the modular suspension system, its handling and driving stability are inferior. Therefore, this paper adopts the module suspension mode.
The system structure of the module suspension control scheme is illustrated in 
Figure 3. The suspension controller adjusts the suspension gap at both ends of the module based on the gap, current, and acceleration at ends A and B, along with the control objectives [
12,
13].
  2.3. Suspension System Hierarchy
Based on the composition and structure of the suspension system, as well as the requirements for fault analysis, the hierarchical structure of the suspension system, which is divided into three levels, has been established, as shown in 
Figure 4.
In this hierarchy, the suspension system constitutes the top level, while the power supply system, actuators, sensors, suspension controllers, and suspension train control system comprise the middle level. The bottom level consists of the lowest tier [
14].
  2.4. Fault Analysis of Maglev Train Suspension System
For the levitation control system, there are three possible states. First, normal levitation, in which a levitation gap of 9 mm is maintained between the electromagnet and the magnetic pole surface of the track. Second, system failure occurs when the levitation point drops onto the track sliding surface. Third, system failure occurs when the levitation electromagnet adheres to the magnetic pole surface of the track. As for the levitation guidance system, when the vehicle makes a turn or is affected by cross-winds and undergoes lateral displacement, guidance control is required. Its states mainly include normal guidance or insufficient guidance force [
15].
In the risk analysis process of the magnetic levitation train system, it is crucial to identify and analyze potential hazardous states and their impacts. Below is a detailed description of the potential hazardous states of the train suspension system, including the causes that lead to these hazardous states, their potential impacts, and corresponding prevention and improvement measures. The results of the fault impact analysis for the suspension system are as follows [
16,
17,
18,
19]:
① Fault of suspension drop point
Fault of suspension drop point refers to a situation where, during the operation of a train, the levitation system suddenly loses its supporting force on the train, causing an interruption in the levitated state between the train and the track and resulting in a momentary sinking of the train or contact with the track. Suspension drop points may arise from failures in the controller, sensors, chopper, power supply, or electromagnets. These failures can lead to train line interruptions or service outages. To address this, measures such as implementing redundant configurations for suspension points, installing slider devices at each suspension point and adding hydraulic support wheel devices next to the sliders are employed. These measures ensure that even if some suspension points fail, the train can still glide stably along the track.
② Failure of suspension coupling vibration
There is an interaction between the train levitation system and other components of the vehicle (such as the car body and bogie). When the vibration frequencies triggered by this interaction exhibit abnormal coupling, a levitation-coupling vibration fault will occur. Suspension drop points may occur due to failures in the controller, sensors, chopper, power supply, or electromagnets, all of which can lead to interruptions in train service or line outages. To mitigate this risk, measures such as employing redundant configurations for suspension points, installing slider devices at each suspension point, and adding hydraulic support wheel devices next to the sliders are implemented. These measures ensure that even if some suspension points fail, the train can continue to glide stably along the track.
③ Failure of suspension magnet adhesion.
The levitation-adhesion failure means that, under certain conditions, the attractive force generated by the train levitation system is excessively large, resulting in an extremely small distance between the train and the track. In severe cases, the train adheres tightly to the track, rendering normal levitated operation impossible. This can trigger a series of serious consequences, including long-term disruption of the line, prolonged suspension of service, severe damage to the maglev train, potential risks of passenger injuries caused by unstable operation, and even possible train derailment and major accidents. To address the issue of suspension magnet adhesion failures, measures include designing hybrid redundant controllers that combine digital and analog systems to ensure the suspension control output signal can be interrupted in the event of adhesion. Additionally, installing copper alloy protrusions on the magnetic pole surface of the electromagnet is recommended to reduce the suspension force and friction coefficient during adhesion. This enables the electromagnet to slide along the track, thereby enhancing the safety and reliability of the system.
④ Suspension controller fire failure
When problems such as short-circuits, over-loads, and poor heat dissipation occur in the internal electronic components and circuits of the levitation controller, a fire may be triggered. The potential hazardous state of fire in the suspension controller is primarily caused by overheating of the electromagnet and excessive temperatures in the rectifier cabinet. These conditions can lead to damage to the electromagnet and rectifier cabinet, resulting in failure to perform the suspension function and ultimately causing service interruptions. To prevent and mitigate such risks, measures include conducting regular inspections of the equipment, controlling the current flowing through the electromagnet, and enhancing cooling systems along with implementing rational thermal design.
  3. Risk Analysis Method Based on Fuzzy Multi-Attribute Decision Theory
By analyzing the failure mode and effects analysis (FMEA) method for assessing the risk of suspension system failures, it was found that this approach has several limitations: ① The use of expert scoring to determine indicator values introduces a strong degree of subjectivity into the assessment results; ② The integer values assigned to each indicator do not adequately express situations that fall between two levels; ③ Treating all indicator values equally fails to reflect the varying impacts of different evaluation indicators on the assessment results. These shortcomings significantly affect the accuracy and objectivity of the evaluation outcomes. Therefore, this study introduces the concepts of the entropy weight method and triangular fuzzy numbers from the perspective of fuzzy decision-making, proposing a risk assessment method for suspension systems based on fuzzy multi-attribute decision theory [
20].
  3.1. Principle of Multi-Attribute Decision-Making
Multiple Attribute Decision-Making (MADM) is an important component of modern decision science, with a wide range of theoretical and practical applications in various fields, including engineering design, economics, management, and military operations. Its essence lies in utilizing existing decision information to rank a limited set of alternatives and select the best option through a defined method. MADM is primarily composed of two parts: ① Acquisition of decision information: Decision information generally includes two aspects: attribute weights and attribute values. Attribute values can be represented in three forms: real numbers, interval numbers, and fuzzy linguistic terms; ② Decision-making: This typically involves aggregating decision information in a specific manner to rank the alternatives and identify the optimal solution. This process generally includes three aspects: normalization (standardization) of the decision matrix, determination of attribute weights, and comprehensive ranking of alternatives [
21,
22,
23,
24]. The decision-making process is typically illustrated as shown in 
Figure 5.
- (1)
- Establishment of an Index System 
The risk assessment indicators are a systematic structure constructed using systems theory methods, consisting of a series of related indicators that reflect various aspects of the evaluation object to achieve the evaluation purpose. The evaluation indicators serve as the carrier of the risk assessment content and represent the external manifestation of the risk evaluation content. Scientifically and reasonably determining the evaluation indicators can not only encompass all factors reflecting the risk assessment as much as possible but also ensure the objectivity and comprehensiveness of the risk assessment while maintaining the simplicity of the evaluation indicators and the practicality of the evaluation methods.
- (2)
- Determination of Attribute Weights 
In general, an index system contains more than one evaluation index, and different evaluation indexes reflect different aspects of decision-making information. Therefore, the importance of different evaluation indexes with respect to decision-making information also varies. To reflect the importance of evaluation indexes, weights are usually used, that is, the more important an index is, the larger the corresponding weight value. The methods for determining attribute weights mainly fall into two categories: subjective weighting methods and objective weighting methods.
Subjective Weighting Methods: This kind of method is based on the preference information given by decision-makers or the weights of attributes directly given by decision-makers. Most of them use qualitative methods of comprehensive scoring to determine weights, such as the point-estimate value method, the judgment matrix method, the comparison matrix method, and the Fuzzy subset method. These methods are characterized by being highly influenced by the subjectivity of decision-makers, having poor transparency and reproducibility in the evaluation process, and being simple in calculation.
Objective Weighting Methods: This method is based on objective information such as the decision-making matrix, that is, weights are determined according to the correlation between index data or the degree of variation in each index value. It does not contain human subjective factors, such as the principal component analysis method, the entropy weight method, and the factor analysis method. These methods are characterized by not depending on the subjective attitude of decision-makers, having strong transparency and reproducibility in the evaluation process, and having a relatively complex calculation process.
- (3)
- Decision-Making Methods 
After normalizing the decision matrix and determining the attribute weights, it is necessary to perform a comprehensive ranking or selection of the alternatives, referred to as comprehensive evaluation. Multi-attribute (multi-index) comprehensive evaluation involves synthesizing multiple indicator evaluation values into a single overall evaluation value using certain mathematical models (or algorithms). Common comprehensive evaluation methods include simple linear weighting, ideal point method, analytic hierarchy process (AHP), and gray relational analysis, among others.
  3.2. Multi-Attribute Decision Index System
- (1)
- Determination of Evaluation Indicators 
Determine the severity of hazards (S), the probability of hazard occurrence (P), and the detectability of hazards (D) as value indicators.
- (2)
- Fuzzification of Index Values 
Due to the strong subjectivity of the severity, probability of hazard occurrence, and detectability indicators determined by expert scoring, triangular fuzzy numbers will be used to blur the values of these indicators, aiming to minimize the impact of various uncertain factors on the indicator values. If the fuzzy number 
F in the real number domain is determined by (
), the membership function is defined as follows:
Then, 
F is referred to as a triangular fuzzy number, denoted as 
, as shown in 
Figure 6. Here, 
 and 
, with 
a and b representing the lower and upper bounds, respectively, indicating the degree of fuzziness. The larger the difference 
, the stronger the degree of fuzziness. When 
, 
F is a regular real number.
Based on the representation of the membership function for triangular fuzzy numbers, and considering the characteristics of the three indicators, severity of failure, probability of occurrence, and detectability, the membership functions used to blur each indicator value are determined as shown in 
Figure 7.
- (3)
- Normalization and Weighting of Indicators 
1. Normalization Process: Since decision attributes reflect different aspects of the decision-making process and generally lack commensurability, meaning that each attribute does not have a unified measurement standard, making direct comparison difficult, it is typically necessary to normalize the decision matrix to eliminate the influence of differing dimensions, magnitudes, and attribute types on the decision results. Essentially, this involves using an appropriate mathematical transformation to convert the attribute values, which have various dimensions and properties, into “quantified values” that can be integrated for analysis [
20].
Commonly used normalization methods for evaluation indicators primarily include the vector normalization method and the proportional transformation method:
① Vector Normalization Method: This method is suitable for normalizing cases where all evaluation indicators share the same vector units, but the measurement scales of different evaluation indicators are unequal. The calculation formula is as follows:
In the formula,  represents the normalized result, and  is an element of the decision matrix which corresponds to the value of the j-th evaluation indicator for the i-th failure mode in the decision matrix, and m is the total number of failure modes.
② Proportional Transformation Method: This method has two different transformation approaches, which are as follows:
In the formula, , .
When the evaluation indicators are expressed as fuzzy numbers, the conversion formula for the indicator values is modified as follows. Let there be 
n fuzzy evaluation indicator values, where 
, and let these be represented as triangular fuzzy numbers, denoted by 
. The calculation formula for normalization is given by the following:
In the formula, 
 is the normalized results of the fuzzy evaluation indicators 
.
2. Weighting Approach:
To represent the importance of each evaluation indicator in the assessment results, the fuzzy indicator values are generally processed through a weighted approach. The calculation formula is shown as Equation (6).
In the equation,  represents the weighted outcome of the fuzzy evaluation indicators ;  represents the elements in the fuzzy decision matrix, which correspond to the fuzzy value of the j-th evaluation indicator for the i-th fault mode; and  represents the weight of the j-th evaluation indicator.
  3.3. Determination of Multiple Attribute Indicators
In the process of project evaluation or decision-making, weights are often used to represent the relative importance of each evaluation indicator (or each objective or attribute). To reasonably determine the relative importance of each evaluation indicator, this paper employs the entropy weight method to objectively establish their weights based on the quantity and quality of information contained in each indicator.
The concept of entropy originates from thermodynamics and was later introduced into the field of information by C.E. Shannon, who broadened its meaning. Specifically, entropy is a function of the state of a material system that represents the level of disorder within the system and serves as a measure of its randomness. The entropy weights derived from calculations of the evaluation matrix, used as weights, do not reflect the actual significance of a specific indicator in decision-making or evaluation problems. Instead, they indicate the relative intensity of competition among indicators under the given conditions of determined values for various evaluation indicators in the evaluated set. From an informational perspective, they represent the extent to which the indicator provides useful information for the problem at hand [
25].
In an evaluation problem with m evaluation indicators and n evaluated objects, the entropy of the 
j-th evaluation indicator is defined as follows:
In this context,  represents the entropy of the j-th evaluation indicator; , , ,  denotes the elements in the decision matrix, which correspond to the value of the j-th evaluation indicator for the i-th fault mode.
The entropy weight of the 
j-th evaluation indicator is given by the following:
        where 
 is the entropy of the 
j-th evaluation indicator, and 
m is the number of evaluation indicators.
Once the evaluation objects are determined, the evaluation indicators can be adjusted and modified based on the entropy weights to facilitate more accurate and reliable evaluations. Additionally, the entropy weights can be used to adjust the precision of certain indicator evaluation values, and if necessary, the evaluation values and their precision can be redefined [
20].
  3.4. Multi-Attribute Risk Decision-Making
The ideal solution method is an effective multi-attribute decision-making approach. The fundamental idea of this method is to utilize the concepts of ideal and negative ideal solutions in multi-objective decision-making problems. This is achieved by constructing the ideal and negative ideal solutions for the problem and using the proximity to find the ideal solution and the distance from the negative ideal solution as the basis for evaluating each object. In this context, the fuzzy ideal solution is composed of the maximum values of the fuzzy indicator values for each attribute, while the fuzzy negative ideal solution consists of the minimum values of the fuzzy indicator values for each attribute. The Hamming distance is employed to measure the differences between the decision alternatives and the fuzzy ideal and fuzzy negative ideal solutions. The basic steps are as follows [
26,
27,
28]:
① First, identify the alternatives to be evaluated (fault modes) and the evaluation indicators (attributes), and construct the decision matrix based on expert scoring:
In the formula, D represents the decision matrix;  is the value corresponding to the j-th evaluation indicator for the i-th fault mode, where n is the number of alternatives to be evaluated and m is the number of evaluation indicators (attributes).
② The elements of D are subjected to fuzzification to obtain the fuzzy indicator values , represented as triangular fuzzy numbers, denoted as ,, .
③ Normalize  according to Equation (4).
④ The weights of the evaluation indicators (entropy weights) are obtained from Equation (8). Then, the fuzzy indicator value matrix is weighted to obtain the fuzzy weighted matrix.
⑤ The fuzzy ideal solution 
 and the fuzzy negative ideal solution 
 are determined from Equation (10).
The optimal vector  is the maximum value of each evaluation indicator in the normalized vector, corresponding to the fuzzy maximum value of the fuzzy weighted indicator for attribute . The worst vector  is the minimum value of each evaluation indicator in the normalized vector, corresponding to the fuzzy minimum value of the fuzzy weighted indicator for attribute j.
⑥ Calculate 
 and 
, 
 and 
, 
 and 
, 
 and 
 the Hamming distance according to Equation (11).
⑦ Identify the differences  between Scheme  and Scheme  .
Differences 
 between Scheme 
 and Scheme 
: 
⑧ Determine the relative closeness 
 of the scheme 
 to the fuzzy ideal solution 
. 
⑨ Rank the risk priority of failure modes according to the magnitude of the relative closeness D value.
  4. Fuzzy Multi-Attribute Risk Analysis of Maglev Train Suspension System
This section analyzes the power supply system in the suspension system as an example. Among the 12 fault modes of the power supply system, 6 are selected for discussion. The fault modes, along with their severity, probability of occurrence, and detectability, are presented in the table below [
29,
30,
31,
32]:
If the Risk Priority Number (RPN) from 
Table 1 is used for evaluation, the risk assessment results are as follows: A4 = A6 > A1 = A3 = A5 > A2. The risk associated with the abnormal output of the 110 V DC converter is the same as that of the 330 V DC converter’s abnormal output. Additionally, the risk of internal short circuits in the 110 V and 330 V batteries is equal to that of the malfunctioning surge suppression circuit of the 330 V DC converter, which has the highest risk value. Since the weights of the various indicators differ, the risk weight of fault modes with higher severity should outweigh those of other indicators. Moreover, the risks of different fault modes cannot be identical; therefore, the results mentioned above may slightly deviate from the actual situation.
To accurately assess the risk levels of various faults, a risk assessment method based on fuzzy multi-attribute decision-making is employed to reevaluate the failure risks of the power supply system as follows:
- (1)
- From the FMEA results presented in  Table 1- , three evaluation criteria (Severity, Occurrence, and Detectability) and six fault modes (A1 to A6) can be established, leading to the development of a multi-objective decision matrix  D- : 
- (2)
- The decision matrix  D-  can be fuzzified based on the data presented in  Table 1- : 
- (3)
- Normalization can be performed according to Equation (4), yielding the following results: 
- (4)
- The entropy and entropy weights of the  j- -th evaluation criterion can be obtained from Equations (7) and (8), as shown in  Table 2- : 
- (5)
- The fuzzy decision weight matrix is obtained by weighting the fuzzy indicator matrix according to Equation (6). 
- (6)
- The fuzzy ideal solution and fuzzy negative ideal solution are determined according to Equation (10): 
- (7)
- The Hamming distance between the alternative solutions and the ideal solution is calculated using Equation (11), as shown in  Table 3- . 
- (8)
- Calculate the differences between the fuzzy ideal solution and the fuzzy anti-ideal solution using Equation (12). Then, determine the relative proximity of each scheme to the fuzzy ideal solution using Equation (13). The results are shown in  Table 4- . 
- (9)
- The risk priority ranking is conducted based on the proximity, and the results are as follows: 
According to the above analysis results, the failure risk of the surge suppression circuit is the highest, while that of the input filter circuit is the lowest. The risk of battery short-circuit is higher than that of output failure. This is mainly because during the risk assessment process, not only is the severity of the failure considered, but also the failure occurrence rate. Generally speaking, the occurrence rate of output failure is higher than that of battery short-circuit.
Therefore, by introducing triangular fuzzy numbers to fuzzify the three risk assessment indicators, namely severity, detectability, and occurrence degree, the influence of some factors on the assessment results is eliminated. The determination of the weights of each assessment indicator effectively solves the problem of low accuracy of the assessment results caused by treating assessment indicators equally.