Risk analysis of gravity dam instability using credibility theory Monte Carlo simulation model

Risk analysis of gravity dam stability involves complicated uncertainty in many design parameters and measured data. Stability failure risk ratio described jointly by probability and possibility has deficiency in characterization of influence of fuzzy factors and representation of the likelihood of risk occurrence in practical engineering. In this article, credibility theory is applied into stability failure risk analysis of gravity dam. Stability of gravity dam is viewed as a hybrid event considering both fuzziness and randomness of failure criterion, design parameters and measured data. Credibility distribution function is conducted as a novel way to represent uncertainty of influence factors of gravity dam stability. And combining with Monte Carlo simulation, corresponding calculation method and procedure are proposed. Based on a dam section, a detailed application of the modeling approach on risk calculation of both dam foundation and double sliding surfaces is provided. The results show that, the present method is feasible to be applied on analysis of stability failure risk for gravity dams. The risk assessment obtained can reflect influence of both sorts of uncertainty, and is suitable as an index value.

). Corresponding models have been established to consider both randomness and fuzziness of influence factors. However, in current studies, fuzziness and randomness of factors influencing gravity dam stability are studied separately, which makes the gained risk assessments are described jointly by probability measure and possibility measure. For example, a certain failure risk probability interval is [R L ,R U ] with possibility α = 0.5. Given that probability and possibility are independent, this description fails to synthetically reflect the contribution of fuzzy factors to risk assessments, and is difficult to clearly characterize the likelihood of risk occurrence in practical engineering.
Actually, fuzziness and randomness of influence factors have no essential difference in stability failure risk analysis of gravity dam. They shall be processed in the same frame. Therefore, this article views gravity dam anti-sliding stability failure as a hybrid event, uses credibility theory (Liu 2006) to consider both randomness and fuzziness of failure criterion, design parameters and measured data simultaneously and establishes credibility stability failure risk analysis model of gravity dam to objectively reflect both sorts of uncertainty. Combining present analysis model with Monte Carlo simulation, calculation method and procedure are proposed to analyze the risk of anti-sliding stability of gravity dam.

Instability credibility risk ratio of gravity dam
Instability risk calculation of gravity dam based on Monte Carlo simulation can be divided into four steps: (1) determine the instability model function of gravity dam; (2) identify and quantify uncertainty of model factors; (3) simulate; (4) analyze results and calculate instability risk ratio.

Instability risk calculation mode of gravity dam
Gravity dam instability is regarded as a random fuzzy event. Fuzziness in the calculation model comes from model factors and failure criterion. There will be three conditions: failure criterion is determined while the model contains both random and fuzzy factors; failure criterion is fuzzy and the model contains random factors only; failure criterion is fuzzy and the model contains both random and fuzzy factors.
Stability state function of gravity dam is expressed by Z and fuzzy failure criterion is expressed by credibility density distribution function η(Z). Then, credibility risk ratio model considering both fuzzy failure criterion and fuzzy model factors is: where ϕ(Z) is credibility density distribution function of state function and η(Z) is credibility failure criterion. Through appropriate conversion, failure probability model under rest two conditions can be gained as following: (1) State function is random fuzzy variable and failure criterion is expressed by the limit state function. In other words, when Z < K , the structure failed and the failure crite- Then, the credibility risk ratio is degraded into: The state function contains random variables only and the failure criterion is fuzzy. According to the integrated chance theorem Ch{Θ × Y } = Pr{Y }, the credibility risk ratio degraded into: where f (Z) is random distribution density function of the state function. Failure risk ratio is a real number expressed by credibility distribution.
Since credibility failure criterion distribution function is often sectionally derivable and derived functions are sectionally continuous, it can get from partial integration of Eq. (1): where a and b are lower and upper limits of fuzzy interval of failure criterion. Derived function of η(Z) is continuous in the interval [a, b]. When Z < a, η(Z) = 1. When Z > a, η(Z) = 0.

Instability model function of gravity dam
Functional status of structure generally can be expressed by performance function: where X i (i = 1, 2, . . . , n) is actions that could influence the structure and environmental influence as well as performance and geometric parameters of materials and rock soils.
For the simplest situation, Eq. (5) can be rewritten into: where R is resistance of structure and S is load effect of structure. Main variables of instability risk ratio of gravity dam foundation include upstream and downstream water levels H 1 and H 2 , silt elevation H 3 , uplift pressure reduction coefficient α 1 and α 2 , shearing friction coefficient f ′ and cohesion c ′ of the contact surface between dam concrete and dam foundation, volume weight of concrete γ c and dam profile size, and the force condition is shown in Fig. 1. Shearing strength state function is: In Fig. 1, W 1 , W 2 , W 3 are upstream vertical water pressure, dead weight of dam block and downstream vertical water pressure respectively. P 1 , P 2 and P 3 are respectively upstream horizontal water pressure, downstream horizontal water pressure and horizontal silt pressure. U is uplift pressure. The calculation expressions of these forces can be derived as follows: where γ c , γ w and γ s are unit weight of concrete, water and silt respectively. During deep anti-sliding stability analysis of both surfaces of gravity dam, a deep weak structural surface AB is chosen (Fig. 2), which is called the main slip surface. BC is an assistant plane of fracture. Stresses on ABD are dam weight (W ), total horizontal load of dam (H), dead load of block ABC (G 1 ), uplift pressure of AB (U 1 ), seepage pressure on the ABC-BCD interface (U 3 ), acting force between sliding blocks (Q). Stresses in BCD include opposite acting force (Q), seepage pressure (U 3 ), dead load of block BCD (G 2 ), and uplift pressure of BC (U 2 ).
Shearing strength of ABD is: Shearing strength of BCD is:

Fig. 1 Anti-sliding stability analysis of gravity dam foundation
where A 1 is area of structural surface AB and A 2 is area of assistant plane of fracture BC. The calculation expressions can be derived as follows: For the loading condition shown in Fig. 2, W and P are the same as previously mentioned. The calculation expressions of the rest can be derived as: where b is width of dam block.
According to equal safety coefficient method, when ABC and BCD reach the limit state at the same time, the double sliding surface model will surface buckling failure. In other words, the limit state function meets Z = Z 1 = Z 2 . Based on this implicit function, thrust Q and the limit state function value Z can be calculated.

Risk identification of model factors
Uncertainty of model factors has to be analyzed when discussing instability process of gravity dam using the opinion of mixed uncertainty. Gravity dam, a complicated structural system, will suffer various concentrated forces and distributed forces (e.g. dead load, hydraulic pressure and seepage pressure of dam foundation) during construction and operation. Man causes of gravity dam instability include flood, earthquakes, seepage of dam foundation, material aging, and so on. The following text analyzes uncertainty of water level and material parameters.
Water level is a random variable. Upstream water level is related with pondage, reservoir inflow and discharge flow, while downstream water level is mainly influenced by discharge flow. Reservoir inflow is affected by rainfall and shows high uncertainty. Discharge flow is controlled by hydraulic parameters and also shows certain uncertainty. Additionally, hydrometry has system and observation errors, which shows some uncertainty. Dam water level during the service period is estimated through statistical analysis of complete monitoring sequences, which could use the classic frequency approach to process it uncertainty. Upstream and downstream water levels can be viewed as random variables (Salmon and Hartford 1995) which obey a certain probability distribution.
Material parameters involved in the instability risk analysis of gravity dam include volume weights of dam and rocks as well as shearing friction coefficient and cohesion of dam foundation and slip surface. Volume weight of dam concrete was determined by test. Sample size met requirement of statistical analysis and was treated as a random variable. Uncertainty of mechanical parameters of rocks in dam foundation includes: (1) uncertainty of engineering geological investigation; (2) uncertainty of engineering geological rock group and rock structure. Fuzziness of mechanical parameters of rocks, statistical variables that combines survey crew experiences and rock grouping, has more important significance.

Uncertainty of failure criterion
Buckling failure of gravity dam is a progressive force when the yield range expands from local to global. Some artificial influences exist in understanding the failure criterion (Ma and Wu 2001). According to limit equilibrium state method, failure state of sliding surface is divided clearly by the limit state function Z = K . When safety coefficient of the sliding surface reaches a specific value K , the whole system reaches the ultimate equilibrium state. However, fuzzy number is more practical to express the progressive process. When considering fuzzy failure criterion, fuzzy limit state of the structure is possibility distribution that obeys to a certain membership function. For example, the membership distribution function µ(Z) is a symmetric triangular distribution: According to definitions of credibility measure and credibility distribution, credibility distribution density function corresponding to the possibility distribution of failure criterion is: The symmetric triangular distributed fuzzy failure criterion is turned into lower semitrapezoid distributed credibility distribution. This distribution converts from possibility distribution interval into a univalent function of credibility measure about limit state. Since credibility under limit state drops significantly with the increase of state function Z, this paper employed the following distribution form: where coefficients a, b and k could be determined according to requirements on security level of different buildings and corresponding standards based on expert experiences and information entropy method (Shlyakhtenko 2005;Su et al. 2009) (Figs. 3, 4, 5).

Random fuzzy simulation
In credibility stability failure analysis model of gravity dam, some variables (H 1 , H 2 , γ c , α 2 ) were vested with a random distribution and others , α, U 1 , U 2 , U 3 were given with a possibility distribution. If the model contains k random variables (X 1 , X 2 , . . . , X k ) and n − k fuzzy variables X k+1 , X k+2 , . . . , X n . Since all fuzzy input variables are expressed in a fuzzy set, model function was simulated firstly under possibility measure. Then, simulated results were converted into expression of credibility distribution (Baudrit et al. 2005). Considering independent random factors and fuzzy factors in the model, the random fuzzy response of the random fuzzy limit state function of gravity dam is gained through mixed algorithm (Baudrit et al. 2006), which is based on Monte Carlo simulation (Altarejos-García et al. 2012): 1. Generate a random number in [0, 1] to every random variable. The variable value which takes this random number as the probability distribution is used as one sample p x 1 , p x 2 , . . . , p x k i . 2. Choose one α-cut and the membership function of the jth sampling is recorded as µ j . 3. Generate maximum and minimum of the response function under this horizontal cut set, u ij and l ij . 4. Choose another α-cut and repeat Step 2 and Step 3. 5. Choose another random probability distribution sequence and repeat Step 2-4.
For any random sample, the random fuzzy response expressed in membership function is gained through maximum and minimum values of fuzzy response. In other words, for the ith (i = 1, 2, . . . , N ) random sample p x 1 , p x 2 , . . . , p x k i with a membership of µ Z j j = 1, 2, . . . q , fuzzy response of state function is expressed as an interval l ij , u ij . Therefore, there are a total of N × q fuzzy intervals. Based on this random fuzzy response and definition of credibility measure, random fuzzy distribution Φ i (Z) under the ith sample expressed in credibility distribution can be gained as (Li and Liu 2009a): where, M i is arbitrary model function value under the ith random sample, i = 1, 2, . . . , N (Fig. 6). where n(Z) is random sample size smaller than Z, N is total random samples, A is arbitrary interval of state function value and y is credibility value of the interval A. The overall instability risk ratio of gravity dam can be known by bringing CDF into Eqs.
(2)-(4). When failure criterion is determined and the model function contains both random and fuzzy variables, risk ratio P is calculated from Eq. (2). When the failure criterion is fuzzy and the model function only contain random variables, risk ratio P is calculated from Eq. (3). When the failure criterion is fuzzy and the model function contains both random and fuzzy variables, the overall risk ratio is calculated from Eq. (4). Risk ratios are all determinate real number on an interval [0, 1] (Fig. 7).

Basic parameters
A serving gravity dam was chosen as the research object. It is a first-grade structure with 100 years of design reference period. The crest elevation, maximum height, normal pool level and level of dead water are 384, 162, 173 and 370 m, respectively. The downstream water level is basically stable. The upstream face above the 295 m elevation is straight and the rest dam body has 1:0.2 slope. The downstream face is vertical and crest width is 12 m. It was constructed on poor rock mass. There's deep bed rock and the dam foundation has high permeable rate. Two heavy curtains were set on upstream and downstream

Result analysis
Random fuzzy responses of the dam foundation surface instability model and T2-5 deep instability model are shown in Figs. 9 and 10.
Membership function of fuzzy failure state was determined. Considering grade and design specifications of architecture, parameters were determined 2.61, 3.08 and 1.05, respectively. Results are shown in Table 3. CDF of anti-sliding stability state function of dam foundation and deep layers is shown in Fig. 11. It can be seen from calculated results that instability risk ratios of both dam foundation and deep layer are smaller than the acceptable 1 × 10 −4 . Deep T 3 2-3 , JC2-6 and JC2-7   high fuzzy uncertainty, thus resulting in its high risk ratio although it is deeply buried. The most dangerous sliding surface is on JC2-4, with a risk ratio as high as 6.61 × 10 −5 . This is caused by its low angle and small burial depth as well as the giant upstream sliding block.   Fig. 11 Cumulative distribution of anti-sliding instability probability, a JC2-4, b dam foundation To analyze effect of fuzzy factor f and c change on risk ratio Pr, sensitivity analysis was implemented by using the following method. Firstly, calculate risk ratio under different variances of f while distribution of c and mean of f are fixed. Draw the curve Pr ∼ V f . Similarly, draw curve Pr ∼ V c . Results of sensitivity analysis of stability failure risk assessment of dam foundation are shown in Fig. 12. When variance of fuzzy variable increases, risk ratio of the system increases. This conforms to the general rule.

Conclusions
Stability failure of gravity dam involves complicated uncertainty. In this article, after adequately considering uncertainty of various factors, a method to analyze stability failure risk of gravity dam and corresponding calculation procedure are proposed. Conclusions are drawn as follows.
To overcome the deficiency of existing risk analysis method that considers randomness and fuzziness separately, this article applies the credibility theory into dam failure and establishes a credibility stability failure risk analysis model of gravity dam to integrate randomness and fuzziness together. Based on Monte Carlo simulation, a mixed algorithm is combined with post-processing of credibility risk analysis mode. And general calculating method is adopted. Stability failure of gravity dam are viewed as hybrid events. Inputs of this calculating method are a series of probability distribution and fuzzy sets. By introducing credibility measure, fuzziness in hybrid variables is mapped from possibility space into the probability space, so risk ratio obtained is represented by a determinate real number.
The example demonstrates that the present method is effective for providing decision support to safety assessment of fuzzy stability of gravity dam. Sensibility analysis results show that credibility risk ratio can sensitively reflect variance change of fuzzy factors. Risk ratio described by credibility measure reflects both randomness and fuzziness and agrees with description habit of traditional probability risk ratio. If there are indexes and standards on credibility risk ratio, credibility theory could become an effective representation tool of fuzzy-random stability failure risk analysis of gravity dam.