In most aircraft and certainly in jets, you have six primary instruments: airspeed indicator, attitude indicator (artificial horizon), altimeter, turn indicator, heading indicator, and a horizontal speed indicator.
The attitude, turn, and heading indicators rely on gyroscopes that are propelled by a vacuum pump and/or electric motors.
Airspeed, altimeter, and vertical speed indicators rely on a pitot-static system. The pitot tube must be exposed to the air that is uninterrupted by the plane's passage. The static port(s) must be positioned where the air is calm and undisturbed.
Each instrument of the pitot-static system relies on pressure differentials, but only the airspeed indicator is reliant on both the pitot tube and the static port. The other two instruments rely on the static port and vents or calibrated leaks.
Part of a pilot's primary training and certainly part of instrument training is in recognizing failures in this crucial system. For example, let's say you take off and your airspeed slowly drops to zero but you remain flying. There's a good chance you've got a blocked pitot tube. This is a simple example, but pilots are trained on this and other failure scenarios during primary and instrument courses. Pilots that want to die of old age train themselves beyond what's required by these courses.
At lower altitude in visual flying conditions, these failures aren't as deadly, primarily because one can still see the horizon. But high altitudes remove most of the visual cues, requiring pilots to trust the hell out of those instruments...except when they can't.
Someone else said it, but these guys lost situational awareness; I'm guessing that all of the warnings going off just overloaded them and caused them to overlook the clues that would have saved them. I've personally never flown anything bigger than a six-place Beechcraft, but I've had enough scary moments with buzzers and lights flashing to appreciate just how much pressure that situation would have caused.
Edit: This may not be the best place to add this but I don't feel like replying to several comments.
If I recall correctly, the pitot tubes on 447 were defective models known to be prone to icing. They met existing safety standards but they had still caused a number of failures other aircraft of the same model before this crash happened. The aircraft had been due for pitot replacement but Air France hadn't gotten around to it yet. The aircraft had flown directly into a thunderstorm system capable of making super cooled water which could easily overwhelm the defective pitots.
Several flight instruments rely on air pressure. If one of your pressure gauges gets blocked, you can get very misleading data.
This guy's theory as to what happened in this case is that the forward pressure tube (pitot tube) had an ice blockage, which led to a low airspeed reading. The autopilot tried to correct by accelerating the plane. Since loaded jetliners normally fly slightly nose-up to maintain altitude [1], the autopilot kept that orientation as it accelerated, which led to a climb and ultimately a stall.
When the plane stalled, it started dropping altitude rapidly -- but with a blocked pressure line, this could misleadingly report a high airspeed due to the increase in external pressure. As the pilots took over, they were (according to this guy's theory) trying to reduce airspeed by cutting the throttle and nosing up. Rather than fixing an overspeed condition, they were actually making the stall worse. They never would have realized what was happening because their instruments kept reporting overspeed.
[0] I'm not a pilot, but I worked in an aerospace museum's education department, and learned a lot from the pilots and engineers who volunteered with us.
[1] According to one of the volunteers, who was also an engineer for one of the big jetliners, loaded jetliners get about half of their lift by keeping their wings 3-6 degrees above level. The exact angle is selected based on load and airspeed; get it wrong, and you'll accidentally climb or descend.
A case of lack of situational awareness or rather faulty situational awareness brought on by a sensor failure.
Thank you.
Power + Attitude = Performance. Every PPL knows this, as did the three AF pilots that night. They deserve more credit.
We know the pilots received an audible stall warning the moment PFD's and STBY ASI failed and the A/P & A/T disengaged. That was a false stall warning, moments later they received another real stall warning.
They were flying at night entering turbulence with unreliable and conflicting data with flight control laws that went from Normal Law to Direct Law. The ASI is showing 25+ knots over the max limit while at the same time stall warning is going off. The plane is in direct law mode so any side-stick input could rip it appart.
I'm going to wait until more data is released before making a conclusion, there are too many whys.
EDIT: I should also mention that I have an MS in aeronautical engineering, and specialized in stability in control and avionics (the things that went wrong in this mishap)./EDIT
I agree 100% with the assessment that the new information does not deepen the mystery, it pretty much explains everything.
The quote from gp about lack of flight training is excessive, but it is in the right direction: those guys screwed up big time, and a big contributing factor was almost certainly inadequate training in dealing with emergencies of this nature.
They screwed up because their SA bubbles just completely collapsed because they were getting conflicting information from their instruments: simultaneous stall and overspeed warnings. Situations like that are exactly why we still need real, human pilots in these aircraft, because a properly trained crew, who truly understand the systems will be able to put together the clues to figure out what's really going on. A disproportionate amount of my training as an aviator has been dedicated to understanding all of the ways that the systems in the aircraft I fly can break. It's critical to understand not just the common failure modes, but also the interactions between them (what we call "compound emergencies"), especially when following the procedures for one emergency can exacerbate a concurrent emergency.
The thin is, in this situation they didn't even have a compound emergency: the only failure was in the pitot-static system. This is an aircraft which requires a sophisticated automated flight control system to remain stable in many flight regimes, and that automated flight control system is utterly dependent on reliably accurate data from the pitot-static system. In that context, these guys should have been drilled heavily on all the ways that the pitot-static system could fail, the manifestations of those failure modes, and how to respond to them. For example: "If you get simultaneous overspeed and stall warnings and your VSI is deeply negative, you are in a stall and need to ignore the overspeed warning and execute stall recovery procedures." Actually, when I word it that way, they shouldn't even have needed special training to figure that out: the VSI should have made it obvious.
Or sensors that aren't unreliable pieces of junk. I'll fly with a computer that has accurate SA over a human that doesn't, any day of the week.
to OP:
For example: "If you get simultaneous overspeed and stall warnings and your VSI is deeply negative, you are in a stall and need to ignore the overspeed warning and execute stall recovery procedures." Actually, when I word it that way, they shouldn't even have needed special training to figure that out: the VSI should have made it obvious.
wow, and how were they supposed to know that VSI is reliable?
but it is in the right direction: those guys screwed up big time, and a big contributing factor was almost certainly inadequate training in dealing with emergencies of this nature.
I think you're too early to jump onto conclusions based solely on impartial and interim report.
You're not alone though - seems that opinion of internet experts is divided between putting full blame on pilots or putting full blame on sensors.
I think actual situation was a bit more complex than that.
Anyway, the computer had reported loss of reliable airspeed so they should have ignored all instruments that use airspeed and fly on what's left. There are procedures for this kind of failure. It looks like they didn't follow them.
Nova did a program on this. It's on netflix. http://www.netflix.com/WiMovie/70148706 They showed the correct solution was to fly the plane based on angle of attack and throttle settings. You don't need airspeed to keep the plane in the air long enough to figure something else out.
Not really confirmed.
Even that post says (read carefully):
The attitude, turn, and heading indicators rely on gyroscopes that are propelled by a vacuum pump and/or electric motors.
Airspeed, altimeter, and _vertical speed indicators_ rely on a pitot-static system. The pitot tube must be exposed to the air that is uninterrupted by the plane's passage. The static port(s) must be positioned where the air is calm and undisturbed.
I actually blame both: if the sensors hadn't broken, the mishap would not have occurred. However, even once the sensors broke, if the pilots had better SA, they still could have prevented the mishap. Even then, I don't blame the pilots so much as the training system that failed to prepare them for this situation, given what I already mentioned about how reliant these aircraft are on their pitot-static systems.
There is always a possibility that sensors will fail. Unless you have enough redundancy in your sensors to employ a voting system (not always practical, sometimes not even possible), computers are still no good at handling such failures. A properly trained human has a pretty good chance of maintaining SA when sensors fail. A computer, not so much. In fact, given the definition of SA, I'm not entirely convinced that any computer currently in existences is truly capable of having SA at all (which is what I was trying to get at in my previous reply).
BTW, I imagine a pitot tube placed on the body of the engine would not need extra heating and would be very unlikely to ice. You can even place it inside the exhaust and compensate the reading for engine flow.
We have to figure out what went wrong, what mistakes the crew made in order to prevent future accidents like this.
And I, coming from a third-world country, take offense at your statement. Pilots here endure very thorough training. One would have to be a lunatic to trust his nephew to a flying computer. The pilot must always know what's going on.
And that brings the main point: people die when the machine surprises its operator. "Smart" planes have become so smart pilots have trouble understanding what they are doing under all that software. And that's assuming the software is not buggy and they didn't got a very unfortunate NullPointException in the worst possible moment.
Ever hit the wrong key in emacs and wondered why it was suddenly responding differently? Imagine that happening at 38k feet, at night in a thunderstorm.
My doctoral work was exactly in this field. Mode awareness, transitions awareness and autoflight understanding, especially in rare flight configurations, is a deep problem that needs to be tamed.
More info in my dissertation (never though I'd write that on HN!): http://dspace.mit.edu/handle/1721.1/9172
My opinion is that requiring mode awareness is a big chunk of overhead. It should be eliminated wherever possible.
Removing that restriction allows anything to happen at any time. This is believed to be more complex to model.
Think of modes as a mechanism to prune a decision tree.
Pivot tubes are 'tubes' located away from the body of the airplane for the reason that they get away from the boundary airflow to give accurate airspeed readings. Attempting to 'compensate' for other factors just introduces more uncertainty, which is exactly what you don't want when you're 5 knots above stall.
Let's imagine a plane starting take-off roll. Engines are spinning up to full throttle (99-100% of thrust), but airframe just started to accelerate slowly. Compensating for anything is pretty useless in this case - airflow trough the engines is even higher than during cruise, but airflow around wings is quite minimal.
There are such things in the engines! They're used to feed the data about engine performance to FADECs (http://en.wikipedia.org/wiki/FADEC) and the crew.
But they're totally useless for airspeed calculation! Bear in mind that air flowing trough and around the engine has totally different dynamics than the air passing around the rest of the airframe. Well, that's kind of the point of the engine - to create thrust, isn't it? That's why airspeed, altitude and AoA sensors actually have to be placed further away from the engines - so that they give as accurate picture as possible.
I don't mean using it as a primary source for airspeed data, but backups in case other sources show weird or no data. The data that comes from those sensors already enters the cockpit, so it would make sense to use it.
But yes, I think the conclusion after AF447 investigation is completed will be that some kind of back-up speed indicator is needed beyond pitot tubes.
http://en.wikipedia.org/wiki/List_of_accidents_and_incidents...
perhaps you can show at least ONE incident that happened because "third world pilots rely too much on autopilot"? I'm genuinely interested, 'cause I'm aviation enthusiast and haven't heard of any.
Compare the sound of the engines as picked up by the front microphones and the rear microphones, and figure out how far behind the latter is shifted in time compared to the former. The faster the plane is going relative to the air, the shorter that time should be.
If the engine sound is too uniform to provide any way to match up the sound as recorded from the two locations, some kind of sound source could be added.
But microphones ARE measuring pressure!
Basically you propose the same method for measuring airspeed, except less precise and as prone to disturbances by external objects (like ice).