Simulation Credibility
Turn simulation results into safety evidence: the platforms, the questions they can answer, the verification and validation chain behind a claim, and the argument an assessor actually buys.
- Chapters
- 13
- Chapters
- XiL platforms
- 6
- XiL platforms
- Credibility factors
- 8
- Credibility factors
- Pitfall patterns
- 7
- Pitfall patterns
- 01The Evidence Question
- 02The XiL Ladder
- 03Intended Use & Credibility Goals
- 04Verifying & Validating the Model
- 05Calibration Without Circular Evidence
Why it pays for itself
The argument nobody hands you, built link by link
Recognised test environments are not a credibility case. Intended use, verification, validation, calibration discipline, uncertainty, correlation, coverage, fault fidelity, tool confidence and reproducibility are assembled into one chain whose weakest link sets the claim.
Platform choice tied to the claim, not to a fidelity ranking
A matrix of what is real, emulated, modelled or absent per loop element, so a test strategy is written from which elements the claim leans on rather than from the assumption that one platform is stronger than another.
Coverage and weight stated honestly
The strongest claim each campaign type actually supports, the three gaps between a modelled parameter space and reality, and the discounts a result takes for credibility shortfall and for extrapolation beyond its validated domain.
What you’ll be able to do
Match the Platform to the Claim
Choose between model, software, processor, hardware, driver and vehicle in the loop on the basis of which loop elements the claim leans on, and say so explicitly in the verification strategy.
Write the Question Before the Campaign
Fix the question of interest, the context of use, the validity domain and the acceptance thresholds in advance, so a campaign cannot quietly define them after the results exist.
Keep Calibration and Validation Apart
Partition data before fitting, track parameter provenance, and recognise when a retune has just expired every validation result obtained with the previous parameters.
Report Distributions, Not Point Values
Quantify and propagate input uncertainty, rank the contributors, and refuse a pass verdict for a distribution that straddles the limit however comfortable its mean looks.
State Coverage Claims Honestly
Name the denominator behind any coverage number, attach the sampling scheme and exposure assumptions to it, and keep the scenario catalog under the governance an evidence artifact needs.
Assemble a Defensible Argument
Bind correlation, calibration provenance, convergence, campaign logs, uncertainty reports, tool confidence and the configuration manifest into one structured argument whose gaps are visible as gaps.
Chapter by chapter
- 01
The Evidence Question
Why simulation became load-bearing, and the distinction the rest of the guide turns on: a result is a number a computer produced, while evidence is that number plus a documented reason to believe it says something true about the real vehicle.
- The statistical wall, computed live
- The credibility chain behind one claim
- Where published standards leave the argument to you
- 02
The XiL Ladder
Six platforms that each make different things real, laid out as a matrix rather than a fidelity ranking. Read it row-wise and the surprise appears: the plant stays modelled all the way through hardware-in-the-loop, and is often simpler there.
- What is real, emulated, modelled or absent
- The real-time contract and frame overruns
- Injection points, and what a digital twin is not
- 03
Intended Use & Credibility Goals
A model is credible for a question, not in general. Write the question of interest and the context of use first, scale rigor to how much of the decision rests on the model, and name the validity domain before anyone asks a question outside it.
- Risk-scaled rigor tiers
- Validity domain and the extrapolation temptation
- A factor vocabulary for stating credibility goals
- 04
Verifying & Validating the Model
Two distinct ways to be wrong: solving the equations badly, and solving the wrong equations well. Code verification, solution verification through convergence studies, solver choice as a modelling decision, and why validating an unverified model invites compensation.
- Three artifacts, three checks
- Step size, stability and silent distortion
- Stiffness, event detection and their blind spots
- 05
Calibration Without Circular Evidence
Tuning a model on the very tests later claimed as validation proves that the optimizer converged. The chapter draws the circular flow honestly, prices the partitioned alternative, and adds the trap that survives perfect data discipline.
- Calibration error against held-out error
- The partition has a shelf life
- Identifiability, and why parameters travel
- 06
Uncertainty & Sensitivity
A result offered as evidence is a distribution plus a statement of what that distribution includes. Two kinds of not knowing, propagation through the model, sensitivity ranking that names where measurement money should go, and comparing distributions rather than points.
- Aleatory, epistemic, parameter, model form
- Tornado screening and its blind spot
- Margin is not margin until uncertainty is subtracted
- 07
Correlation to Physical Tests
Physical measurements anchor the whole virtual edifice, but matching peaks is not correlation. Decomposed agreement ratings, the two models that hit the same peak by opposite mechanisms, and how to spend a scarce test budget.
- Corridor, phase, magnitude and slope
- Right answer for the wrong reason
- Correlation evidence ages, so script the rerun
- 08
Scenario & Parameter Coverage
Coverage of what, sampled how, and what could still be hiding between the samples? The functional, logical and concrete ladder, four sampling strategies against a hidden failure region, and the strongest honest claim each campaign type supports.
- Claims made at the top, tests run at the bottom
- Grid, random, stratified and adaptive search
- The scenario catalog as an evidence artifact
- 09
Fault Injection Fidelity
A plant model calibrated on healthy data has no validation evidence about its behaviour with a jammed valve. The chapter asks, per fault class, on which platform the physics is actually present, and measures the timing chain where the real scheduling lives.
- Fault class against platform, cell by cell
- Detection interval plus reaction against the budget
- What a sampled frame simply cannot see
- 10
Qualifying the Toolchain
Every box in the virtual test stack is a software tool in the Part 8 sense, including the script that decides pass or fail. Tool confidence addresses malfunction; a qualified solver running an invalid model produces results that are precise, repeatable and false.
- Walking the stack, tool by tool
- Tool correctness against model validity
- The post-processing blind spot
- 11
Configuration & Reproducibility
Every claim quietly assumes a fixed object. A manifest that resolves model, parameters, scenarios, solver settings, seeds, tools, environment and scoring script to exact versions is what answers the assessor question about rerunning tonight.
- Which claims survive your pinning discipline
- Non-determinism you did not order
- A change-impact table with the reruns it triggers
- 12
Weighing the Evidence
From a pile of artifacts to an argument: a goal structure where every solution node is an artifact the earlier chapters produced, the division of labor between virtual breadth and physical anchoring, and the discounts that decide what a result may weigh.
- Each leg carries an assessor question
- Credibility shortfall and extrapolation discounts
- The claims-limits list, stated before the assessor does
- 13
A Worked Credibility Argument
One driver assistance function, one campaign, every chapter in its place: the question and domain written first, a correlation gate that no campaign may pass without, the evidence built in order, and a claim that states its residuals.
- Sixteen weeks, three worlds, one gate
- Weakest-link credibility scoring
- Seven pitfalls and the question that catches each
Who this guide is for
- Verification and validation leads deciding how much of a safety argument simulation may carry
- Simulation and model engineers whose results are cited in a safety case
- HIL and test bench owners defending timing and fault injection evidence
- Automated driving teams running large scenario campaigns and reporting coverage
- Functional safety managers and assessors probing the seam between tool confidence and model validity
Frequently Asked Questions
Common questions about Simulation Credibility
Start the course today
A free account unlocks one full concept guide, 3 work product templates, 1 guided process, the Markov simulator, and 5 practice exams per month. The Pro and Expert plans unlock more of the 77-guide library. No credit card required.