Abstract
Actuator faults are inevitable in small reverse osmosis desalination plants. It may cause energy losses and reduce the quality of the freshwater, which may endanger human life. This paper focuses on the integrated fault detection and fault-tolerant control approach. The primary motivation of this paper is to propose a novel integrated fault detection and fault-tolerant control approach. The actuator fault is estimated using the concept of parity space approach. Then the system model is updated in the fault-tolerant control block using the information of the estimated fault parameter. Moreover, the proposed approach uses the receding-horizon predictive control-bounded data uncertainties controller, which is the robust and stable variant of generalized predictive control. The remaining uncertainty caused by the model and observer is compensated by this controller. The structure of a small reverse osmosis desalination plant is deployed. In this plant, the permeate flow rate and conductivity are controlled by a retentate valve and a bypass valve, which add a small amount of inlet to the outlet. The performances of three predictive model controllers are evaluated, and a comparison is made between their computational costs, stability, and robustness. The plant is considered to be linear time-invariant and subject to model uncertainties, measurement noise, and actuator fault in the retentate valve as efficiency dropping. The results reveal the robustness of the proposed approach concerning noise and matched uncertainties as well as its accommodation to actuator fault up to 90%.
Keywords
Introduction
Due to its low cost and energy efficiency, reverse osmosis (RO) desalination system is widely used to produce potable water from brackish or seawater and wastewater in food industry, semiconductor industry, car washes, operation rooms, and municipal and agricultural applications (Rahardianto et al., 2007), especially in arid or semiarid areas with high water salinity. Based on its application, each RO desalination plant may have different characteristics and face various challenges. In a complicated and large plant, energy efficiency, performance, and reliability may be considered as control purposes (Ammous et al., 2016). However, in a small size plant, issues such as software platform for real-time control and monitoring, measurement noise, model mismatch, and actuator fault should be considered as control tasks (Jiang et al., 2017; Sánchez et al., 2005; Wade et al., 2005). In this regard, a robust fault-tolerant control (FTC) system is recommended to handle model mismatch and measurement noise. One way to deal with these problems is to design a robust controller as a passive FTC for the system subject to small ranges of uncertainties, faults, and nonlinearities (Hong Phuc et al., 2016), (Phuc et al., 2017). In many cases the fundamental of this approach is based on the robustness of model predictive control (MPC) systems (Ali et al., 2010; Wang et al., 2014). Passive FTC approaches are used in plants in which the fault significantly affects the system performance. Active fault tolerant control (AFTC) frameworks are based on fault detection and isolation (FDI) unit and reconfiguration in the controller according to fault occurrences (Kargar et al., 2014). The parity space-based fault detection technique is among the existing approaches dealing with the fault detection issues of dynamic systems, which have received much attention over the past years. Using the parity space-based approach, (Sun et al., 2018) investigated a class of discrete-time switched linear systems with dwell time constraints. Additionally, based on the parity space method, (Wu et al., 2018) investigated the problem of fault detection for the linear discrete time-varying system with multiplicative noise. On the other hand, MPCs are powerful tools to control RO desalination plants (Abbas, 2006), (Bartman et al., 2009). The AFTC –based model predictive controllers seemed to be the most functional approach to control RO desalination plants according to literature (Mcfall et al., no date), (Gambier et al., 2009, 2010).
In this work, three MPC methods, including constrained receding horizon predictive control (CRHPC) (Clarke and Scattolini, 1991), generalized predictive control (GPC) (Clarke et al., 1987a) and robust CRHPC via bounded data uncertainties (CRHPC-BDU) (Ramos et al., 2009) are employed as the control methods used in FTC structure. All three controllers are similar in the structure and differ in the stability analysis and computational cost. GPC has low computational cost but lacks stability proof. CRHPC computational cost is slightly higher but has stability proof for the nominal model. Both of the above-mentioned methods are very sensitive to model uncertainty (Manoso, 1999). CRHPC-BDU has robustness proof, but its computational cost suffers from the nonlinear system of equations solved numerically.
The structure of the work is the following, in Section 2, the model of RO desalination is presented, while the proposed control strategy is described in Section 3. Following that, Section 4 shows the simulation results, and finally, the calculations are described in Section 5.
Plant description
In general, a RO desalination plant is a multi-input multi-output (MIMO) nonlinear system where the nonlinearity is caused by the nonlinear behavior of each unit and practical challenges such as fouling, fault and model mismatch. In some works, the model of a RO system is considered nonlinear and time-invariant with respect to the membrane, and valves fouling, membrane deformations and faults (Bartman et al., 2009). If the actuator fault is regarded as a nonlinear behavior of the system, the nonlinear dynamics of the system will become very complicated. Considering cyclic washing and maintenance as routine programs for the membrane, model deviations will be small, so according to the experimental results, modeling the system as a linear time-invariant (LTI), filter fouls, and deformations as uncertainties, and actuators performance degradation as a fault is precise in practice. Accordingly, the system is controlled using LTI control strategies, which are easier to implement and have stability proof.
In this paper, a small RO desalination plant is considered as Figure 1. This system is commonly used for drinking water purification where the permeate-flow rate is controlled by the retentate control valve.

The schematic of the process with control loops.
A laboratory size of the plant was identified and experimented by Gambieret al. (2010). A bypass line was installed on the system to control permeate conductivity by mixing the inlet water with the outlet water from the filter. In the operation point of 250 l/h for the brine water, 0.02 l/h for bypass, 250 l/h for outlet flow rates and 425 µS/cm for permeate conductivity, a dynamic LTI state-space model is identified where this operation point is set by 50% opening of both control valves. The mathematical equations describing the plant are as follows
where
Moreover, unstructured uncertainties
The parameters of the model are taken from Gambier et al. (2010) and are shown in Table 1 with 0.015s for sample time. The inputs and outputs of the system are described in Figure 2.
Model parameters.

System inputs and outputs description.
Actuator fault on the retentate valve is much more statically common than sensors and other valve faults because of fouling caused by brine water.
Control strategy
One of the advantages of MPC systems is the capability of online handling the circumstances where system changes, and the system model follows the change. It is the fundamental advantage of model predictive-based FTC with a multi-model control strategy because, in this strategy, the system must operate smoothly during model switching. In Figure 3, the block diagram of the proposed control strategy is depicted. The proposed FDI block uses the parity space approach to detect and estimate the fault parameter. The information of the estimated fault parameter is sent to the FTC block. Depending on the estimated fault parameter value, which is provided by the FDI block, the planner unit decides which controller should be used, and the proposed FTC strategy switches between the suitable controllers and reconfigures the controller. In other words, the planner selects the appropriate model/controller pair subject to the estimated fault parameter value. This procedure is similar to fault accommodation using MPC methods (Boskovic and Mehra, 2002; Qu et al., 2016). The robustness of this method is guaranteed if each controller performs robustly.

Model predictive-based FTC with the multi-model control strategy.
The main idea of this work originates from the fact that model switching by MPC structure causes no bump in the system behavior (Clarke et al., 1987b). Therefore, the multi-model strategy can be applied to accommodate with a fault for the class of faults that can be modeled as a sudden parameter change in the LTI system. The critical part of this strategy is to estimate the fault as soon as possible to update the model where model mismatch does not exceed robustness bound. The model mismatch is caused not only by fault estimation error but also model uncertainty. Moreover, fault detection and estimation are affected by the model uncertainty and measurement noise. In fault accommodating context, the main issue is that the system remains stable after a fault whether fault diagnosis is accurate or not. The effect of actuator fault is formulated in the system dynamics as follows
where
where
Although it seems that (5) limits the fault structure in the system, efficiency dropping is a common phenomenon for the actuators in practice. Efficiency dropping is in the class of actuator faults that can be modeled as change in the model parameter. In detail, using (5) in (4) and some simplifications, the dynamic equations of the system could be written as follows
where
where
where
(1) Assumptions 1 and 2 hold.
(2) The system remains controllable.
(3) The input matrix of the system is updated by the
By substituting
The practical perspective of this proposition shall be ensured by adopting a robust controller satisfying Assumption 2 and fault detection, isolation, and estimation unit satisfying Assumption 1. The dynamics of transient response is under the effect of the bump, which is due to the performance of the fault detection system and the controller switching. Although the fault estimation unit satisfies Assumption 1, the transient response for
In (12) the term
where
So, after the fault detection and if the system remains controllable, the FTC block uses the model (14). With a few changes, the free-response prediction
Parity space method is adopted for fault detection (Gertler, 1997), which is presented in Appendix 1 in detail. In general, the parity space fault detection scheme is generating the residual signal which is compared with the threshold. The system is detected to be faulty if the norm of the residual exceeds the threshold. The magnitude of the residual signal is related to the amount of a fault (
Based on the description given above, the proposed approach in this paper can be summarized as follows:
(1) The actuator fault occurs at the sample time
(2) The information of the estimated fault parameter is sent to the FTC block. The FTC block uses the model (14) and reconfigures the controller. Actually, the matrix B and the uncertainty
Simulation results
The formulations of GPC, CRHPC, and CRHPC-BDU are detailed in Appendix 2. The parameters of these controllers for the RO desalination plant are adjusted by Table 2. To have a fair comparison, the similar parameters are set equal.
Controller’s parameters.
The bound of uncertainties, mentioned in (3), are considered as follows
The measurement noise, mentioned in (2), is considered white noise with power 0.05. Inputs and outputs in Figure 2 show that the three controllers are capable in the presence of the noise and uncertainties.
The noiseless nominal system converges for faults up to nearly

System response in the presence of noise when

System response when
The fault occurrence after

The inputs and outputs of the noiseless nominal system for
The first major variation of residual signal is considered as a fault detection variable mentioned in Table 3. The nominal noiseless system is simulated under four states of fault, which are demonstrated in Figure 7. These states are used to specify the switching threshold parameter, that is, the exposed values on Y (Figure 7) are considered as thresholds for the planner (Figure 3) to choose the nearest model to the system.
Fragmentation of fault based on the nominal model and noiseless model outputs.

The residual signal generated by parity fault detector,
In Table 3, four operating models are considered for the system. As noise and uncertainty cause some error (

The residual signal for the system in the presence of noise and fault when
Although the proposed approach selects the estimated fault parameter from the predefined set and it may not be accreted estimation, the fault detection approach is fast and the remaining uncertainty caused by the model and observer is compensated by the proposed controller.
The planner (Figure 3) follows the following procedure. Initially, the model is set as the nominal. The residual signal generated by FDI is monitored and if its variation for one sample exceeds 0.5 and reaches lower than 1.5 (like Figure 7 b) the model changes to Model 2. For variations between 1.5 and 2.4, and variations greater than 2.4, the model changes to Model 3 and Model 4, respectively.
The proposed method claims that the system can tolerate the fault up to 90% efficiency dropping in the retentate valve. To show this assertion, the system is examined for the marginal values of faults as displayed in Table 3, subject to the noise and uncertainties. The behavior of the inputs and outputs of the system for the marginal cases in the presence of noise and when the actuator fault has occurred at the time of

System response in the presence of noise when the actuator fault

System response in the presence of noise. The actuator fault

System response in the presence of noise. The actuator fault

System response in the presence of noise. The actuator fault
Figure 13 shows the output error for the scenario, which is considered in Figure 12. The error is the difference between the setpoint and the system output. As can be seen, the permeate flow presents a steady-state error in the presence of the fault. However, the conductivity steady-state error is nearly zero for all three cases. It is shown that the quality of freshwater is maintained even in the presence of the fault. But the permeate flow steady-state error for CRHPC-BDU is more than CRHPC and GPC. Considering higher values for uncertainties result in more robust but less accurate output responses (Ramos et al. 2009) and this is why the steady-state error in CRHPC-BDU is more than CRHPC and GPC.

Output error in the presence of noise. The actuator fault
In all simulations cases, when a fault occurs, a deviation in the input and output signals appears, but the system converges to reference signal with a bias due to model mismatch and fluctuations due to measurement noise. The horizon parameters are big enough to satisfy the stability of the constraints of CRHPC. Therefore, the calculated control inputs in each sample are close to the control signal of GPC and the inputs and outputs are close consequently. The CRHPC-BDU is more conservative due to robustness constraints that cause slower convergence. It also suffers from bigger tracking bias. These cons for CRHPC-BDU are in exchange for robustness guaranty unlike numerical robustness of GPC and CRHPC (Appendix 2).
Conclusion
In this paper, the integrated fault detection and FTC approach for a RO desalination unit is presented. The actuator fault is estimated using the parity space approach. Then the system model is updated in the FTC block by applying the estimated fault parameter. The proposed approach uses the CRHPC-BDU controller, which is the robust and stable variant of GPC. Moreover, the outputs of GPC and CRHPC are examined to compare with the proposed approach. Four sets of parameters are used for four models concerning the minimum robustness bound of MPC. The results show that multiple-model MPC control successfully accommodates the system under actuator fault and uncertainty and the goals of the designed control system are achieved.
Footnotes
Appendix 1
The FDI unit implemented by the parity space method is reviewed here. Consider the state space representation of discrete time LTI system
where the pair
with a more compressed form as
where the involving parameters are defined as
Equation (A4), known as parity relation, describes the inputs-outputs relation based on the states in the past. For
The number of rows of
Therefore, if
and the residual signal is generated as follows
Now, consider the following parameters for a fault
With similar calculations, the more general form of (A4) is as follows
Using a vector of parity space yields
The residual signal is only under the effect of the fault. Indeed, considering the model uncertainties, disturbances and noises add some terms in the residual signal but (A8) ensures that the residual signal is isolated from the system dynamics.
Appendix 2
GPC, CRHPC, and CRHPC-BDU are very similar in the strategy and notation. Consider CARIMA representation of MIMO plant
Where
Where
Declaration of conflicting interests
The author(s) declared no potential conflicts of interest with respect to the research, authorship, and/or publication of this article.
Funding
The author(s) received no financial support for the research, authorship, and/or publication of this article.
