A Hybrid Approach for Evaluating Faulty Behavior Risk of High-Risk Operations Using ANP and Evidence Theory

Hydropower project construction is a high-risk operation, where accidents occur frequently. Moreover, the factors leading to accidents are often human factors, so safety evaluation of these factors for the hydropower projects’ work system is very significant. TheHuman Factors Analysis and Classification System (HFACS) framework is applied to build evaluation system. In the evaluation process, correlation analysis is used to form the intercriteria analysis matrix that helps the decision makers to build impact relation matrix. Factor weights are calculated by the Analytic Network Process (ANP). In the index value determination step, the evidence theory is used to eliminate the conflicts of three decision makers and the index values are then calculated. The faulty behavior risk (FBR) assessment value is finally obtained. The proposed method is practical and its applicability is proved by an example.


Introduction
Hydropower construction has the characteristics of a complex construction environment, including outdoor work, construction difficulties, a broad range of cross operations, and labor-intensive tasks.On the other hand, it is characterized by lower safety management levels and, more commonly, a lack of safety supervision and personnel training.It is obvious that there are many unsafe factors in the process of hydropower construction, and many accidents occurred frequently.Huang et al. [1] counted fire, transportation, and coal mine accidents between the years 2001-2011 in China and pointed out that human factors, including a lack of training, supervision, and management, job skills, and unsafe behavior of the operators, accounted for 88% of accident rates.Sovacool [2] assessed the social and economic costs of major accidents in the coal, oil, natural gas, hydroelectric, and renewable and nuclear sectors from 1907 to 2007.He pointed out that 94 percent of reported fatalities occurred at hydroelectric facilities.Therefore, building the quantitative model to evaluate the impact and consequences of human factors in high-risk operations' accidents are very important.
The Human Factors Analysis and Classification System (HFACS) is an investigation framework that utilizes a systematic approach.HFACS is a commonly utilized tool, whose primary application is investigating human contributions to aviation accidents.After further research, HFACS has been systematically and thoroughly applied in all types of accident evaluation and research.The system has been employed to maritime accidents, railway accidents, mining accidents, and hydropower projects [3][4][5][6][7].These studies reveal that the HFACS framework for the description of accident risk factors has a high degree of reliability.
The traditional HFACS index system [3,6,8] only considers the impact of a one-way relationship between adjacent levels, which makes expressing the relationship of interdependence between all levels of factors difficult.Chi-square and Fisher's test have been used to analyze HFACS category links between adjacent categories [9], but only the adjacent levels' relationships were analyzed, and the relationship was unidirectional; namely, it described how factors in the upper (organizational) levels in the framework affect categories in the lower (operational) levels; to determine dependencies between factors more accurately, Liu and Lai [10], in their study, proposed the use of statistical methods for analysis of data on accidents.The only drawback is also that the above articles analyze the relationship between adjacent levels of the factors, without any cross-level relationship investigation.Hydropower engineering has complex operating conditions and interaction between factors; changes in one factor may affect another one.Therefore, it is necessary to analyze the relationship and the effect size between all the factors, both in adjacent level and in nonadjacent level.In this paper, the interaction between different factors was analyzed quantitatively using statistical methods, including the  2 (chisquare) test, Lambda, and Tau-y measurements based on the HFACS framework, which was useful for the experts to make interaction decision.
After determining the evaluation index system based on the HFACS framework, the next step is to select evaluation methods.Marhavilas et al. [11] reviewed relevant scientific papers published on six representative scientific journals covering the decade 2000-2009.Major risk analysis and assessment methods were analyzed and classified and risk analysis assessment techniques were classified into three categories: (a) qualitative, (b) quantitative, and (c) hybrid, which is a combination of qualitative and quantitative techniques.Qualitative evaluation methods require evaluators with relevant knowledge and experience; quantitative evaluation methods require large amounts of safety data.A simple qualitative analysis is more subjective and it is difficult to apply consistently when it comes to multilayer evaluation, while incomplete data inhibits the effective application and testing of quantitative safety evaluation methods [12].Therefore, qualitative and quantitative methods for analysis and evaluation should be combined, to compensate for their respective defects.Hybrid evaluation methods normally include neural networks, grey correlation method, and analytic network processes (ANP).
Neural networks seldom reflect the relationship between factors clearly and a reasonable neural network structure is difficult to achieve [13].The grey correlation method mainly deals with poor, incomplete, and uncertain data that is designated as "grey" and is mainly used in solving multicharacteristic optimization problems in manufacturing processes [14].The ANP method has a robust ability to deal with the relationships between different factors not only in adjacent level but also in cross-level in the HFACS framework.The environment of hydropower construction is very complex and there exists cross influence between many factors.With some conditions, accidents occur because many factors are coupled with each other and long-term effect [7].The relationship of these factors can be represented by a network where nodes correspond to the levels or components.The ANP method is the more general form of AHP which allows feedback and dependence between and among the decisionmaking criteria and the alternatives and thus enables more accurate modeling of complex decision environments [15].For the evaluation system of complex high-risk construction, the ANP method has been utilized in the evaluation of occupational hazards' risks, environmental impact risks, equipment management risk, and hydropower construction risk by, for example, Huang et al. [16], Zhou et al. [7], and Nilashi et al. [17], and reasonable safety evaluation results were obtained.
The evaluation of the safety situation of high-risk operations often relies on the opinions of the experts obtained through questionnaires and sample data; however these data are, in many cases, incomplete and uncertain and are affected by subjective factors, which make safety evaluation results inaccurate.In order to deal with the uncertain problems in the mathematical models for multicriteria and multiobjective applications, there are some references which we can refer to [17].The Dempster-Shafer (DS) evidence theory is a way to deal with uncertainty, the applications of which have received considerable attention both on a theoretical and on a practical level, with some interesting findings [18,19].Evidence theory can assess and process the information from expert advisors, questionnaires, and other ways and solve the problem of information uncertainty in the process of data integration.Curcurù et al. [20] pointed out that analyzing and evaluating accidents are very difficult due to the shortage and fuzziness of data, and evidence theory can be used to resolve uncertainty and reduce the bias of expert opinion.
Zhang et al. [21] proposed a new model based on Analytical Hierarchy Process (AHP) and Dempster-Shafer (DS) evidence theory for the assessment of E-Commerce security.However, as Su et al. [22] pointed out, when experts offer different risk assessment factor values, different pieces of evidence may be contradictory and cannot be directly used in Dempster-Shafer's evidence fusion rules; they will need to be modified.Guo and Li [23] proposed a combination rule based on the strategy of cross-merging between evidences in order to eliminate the problem of conflicting evidence and made the final combination results more succinct, reasonable, and effective.
In consideration of subjectivity and the conflicting evidence of the decision makers (DMs), a multicriteria risk assessment model is proposed.In this paper, the HFACS framework is first established.The statistic associations are then calculated by chi-square test, Lambda, and Tau-y correlation coefficient method.The goal of safety assessment is to obtain the intercriteria evaluation, which includes the process of defining the criteria weights and the aggregation of the utility (index) values related to each criterion.The ANP method is used for consideration of the interdependences between the factors in the four HFACS levels; the index values are given by three DMs based on some principle.The data from different DMs conflicts, the evidence theory, which is used to eliminate the conflict, makes data fusion and the final index value available.

Methodology
The risk hierarchy model is first established by studying the risk factors and the way they influence each other.Then the relationship between the factors is analyzed.The evaluation model is built using the method of ANP and then evidence theory.Therefore, the evaluation process of this study involves six stages, as shown in Figure 1.These steps will be described in detail below.

Evaluation Index System Framework. The Human Factors
Analysis and Classification System (HFACS) framework is the analysis of the experience summary and extraction of hundreds of flight accident reports.It is an artificial factor analysis tool which is widely applied in aviation safety incidents.We use the theory of HFACS combined with hydropower plant construction accident data recorded over the years along with questionnaires to build a safety evaluation index system.The broad structure of HFACS includes four main levels of investigation: unsafe acts, preconditions for unsafe acts, unsafe supervision, and organizational influences.While using the HFACS framework, we considered the characteristics of hydropower plant construction accidents to adjust the model, in combination with other reference works [24,25] We built the safety evaluation index system framework as shown in Table 1.

Evaluation
Processes.The DMs are safety managers, construction managers, or supervisory engineers with adequate experience, and they are experts in hydropower construction.The stakeholders are site workers and safety analysts.Before we conduct the evaluation, some assumptions should be clarified: (H1) Assume that the DM preferences fit the axiomatic structure required by multiattribute utility theory.
(H2) In the evaluation framework, assume that one factor can affect other factors that located no matter in the same level or the adjacent level or the nonadjacent level.For example, the factor "organization structure and responsibility" (in level one) can affect the factor "team management" (in level three), the safety management institution, and safety staffs, which can determine the team leader and who is the person responsible for construction.
(H3) In the evaluation framework, the factors in lower level do not affect the higher one, which fits in with the hypothesis of HFACS framework.
Step 1 (correlation analysis of factors).Quantitative analysis, that is, the correlation coefficient calculation, can be performed to establish the interaction relationship between different factors in the HFACS.Correlation analysis closely reflects the degree of correlation between the variables by means of the correlation coefficient value.First, the  2 (chisquare) test [26] is used to test for independence, where we assume that  0 represents the hypothesis that hydropower operations' risk factors of HFACS are independent of each other; this assumption states that the risk factors of HFACS are dependent on and correlated to each other.By calculating the chi-square statistic using the chi-square distribution and appropriate  1 degrees of freedom, the significance level for  0 was chosen as  = 0.05, and we obtained  2  = 3.84 [27,28].When the actual value  2 is greater than the calculated value  2  , we reject the hypothesis  0 and accept  1 , which means that factors are dependent on each other.Using the dependent factors, the Lambda and Tau-y measurement methods were applied in the correlation analysis to further calculate the extent of mutual influence and obtain the mutual influence relationship matrix   of the index factors.B3 Risk monitoring Hazard identification and safety evaluation for dangerous facilities or sites; register and archive for identified major hazards in time; taking measures to monitor major hazards; identification and appropriate control measures of existing equipment failure and error operation; planned control on change of institution, personnel, process, equipment, operating process, and environment that is permanent or temporary change.
B4 Emergency rescue Emergency management organization and emergency rescue team; complete emergency plan for safety production accidents; emergency facilities, equipment, supplies, and emergency drill.

B5 Accident treatment
Deal with the accident in a timely manner; report the accident in time and save the accident evidence.
C Preconditions for unsafe acts C1 Operating environment Included are both the operational setting (e.g., weather, altitude, and terrain) and the ambient environment, such as heat, vibration, lighting, and toxins.C2 Technical measurements Safety warning signs and safety colors complying with the requirements on equipment or workplace; safety protection measures; safety equipment and safety facilities; safety technical disclosure; compiling operating procedures instruction; the construction safety technology solutions.
C3 Team management Preshift meeting; predicting dangerous activities; smooth communication of personnel information (including safety management personnel, technical personnel and workers); inappropriate assignment of team members, insufficient number of team members, lack of team leader, and poor teamwork; inappropriate operation plan to the actual conditions.
C4 Poor personal basic situation Pathological conditions such as medical illness, physical trauma, and physical fatigue for individuals; worker's safety awareness; personal preparation of workers (including adequate rest, sufficient training, and proper medication).

C5 Occupational health
Timely treatment of occupational diseases.
C6 Mechanical equipment Performance and maintenance; temporary power in accordance with the provisions to construction safety; the design of equipment and controls, display/interface characteristics, checklist layouts, task factors, and automation.

C7 Material
Material certificate and material testing; control material production, transport, and stacking.
D Unsafe acts of operators D1 Perception and decision errors Workers' sense of physical environment and technological environment is inconsistent with reality (as visual illusion); misdiagnosed emergency and wrong response to emergency, wrong plan due to exceeding ability, improper operation and maintenance procedure, poor decision, and so forth.

D2 Skill-based errors
Wrong operations, omitted step in procedure, and poor technique.
D3 Violation operations Operation and maintenance not in accordance with the standards, not qualified for mission, failure to properly prepare for work, speeding, and so forth.
Step 2 (determining the ANP model of network structure).The typical structure of ANP is established under the condition that the interaction relationship between index factors is known.The first step is to establish the control layer, determine the decision-making goals, and define decision criteria.Then, the relative weight of each decision goal can be acquired using the ANP method.The next step is to construct a network layer and classify and identify each element set and finally analyze the interaction relationships within the network structure.The network structure model is shown in Figure 2. As shown in Figure 2, the arrow represents the relationship between the indicators.The network layer is composed of the evaluation indices, which shows that nonindependent network layer elements have a mutual influence on the network structure. Step Here the column vectors of   are the sorted vectors of the elements  1 , . . .,    .The table represents the impact of cluster's elements on the elements   , . . .,    of the cluster   ; if the elements of the cluster   are not affected by the elements of the cluster   , then   = 0. Thus, we finally obtain the supermatrix  under the criterion of   : Step 4 (establishing ANP weighted supermatrix If the clusters have nothing to do with   , then its corresponding sorted vector components can be set to zero, and so we obtain the weighting matrix: The elements in the  supermatrix are now weighted and we obtain  = (  ), in which where  is the weighted supermatrix and the sum of its columns is 1.Such matrices are called column random matrices.
Step 5 (calculating weights).Let us assume that   is an element in the weighted supermatrix  reflecting the onestep priority from element  to element .The priority from  to  can be used to also obtain ∑  =1     , which is called the two-step priority, and it denotes an element of  2 .In the case of  2 , the columns are still normalized.For  ∞ = lim →∞   , the th column of  ∞ is just the limit of the corresponding ordering vector of the elements under the   network layer for the element .Finally, the relative ordering vector is the weight   of the risk factor under the   criterion.Step 6 (combining evidence theory). = ∑  =1     [29,30] declares that the above work just completed the calculation of weights   in the formula; the next job is to compute evaluation index value   . stands for the faulty behavior risk (FBR) value of the high-risk operations system and   stands for the evaluation index value of each factor in the HFACS framework.For each factor, we can obtain some evidence and calculate the corresponding evaluation index value   by using the evidence theory.Finally, we can decide on subsequent measures based on the FBR value obtained for this particular high-risk operations system.
The evidence theory method is used to fuse the evidence based on the results of safety inspection.Evidence theory method can be understood as a quantitative description of the effects of all evidence on one or more hypotheses.In cases where the evidence is incompletely conflicting, one can obtain the trust function for the combination results of multievidence through this method.A specific method for calculating the trust function is described by where Θ is a frame of discernment.There are two elements {, } under Θ; their corresponding basic trust distribution functions are  1 and  2 , with focal elements, respectively,   and   .In (7), the degree of the conflict of the combination of evidence can be described by , where  = ∑   ∩  =0  1 (  ) ⋅  2 (  ) ≺ 1, which is called the conflict coefficient.The coefficient of 1/(1 − ) can be used as a normalization factor.
If more evidences are combined, one may apply the DS combination method of (7), to combine all evidence in a pairwise manner.
The combination rule of DS cannot be used when there is a conflict between evidences, so the original evidence theory should be modified so that application in this paper's methods allows us to deal with conflicting evidence [23].
Then, the similarity coefficient between evidence  1 and  2 can be expressed as For the set of collected evidences, whose number in the system is , the above formula can be used to calculate the similarity coefficient between each pair of  1 and  2 , forming the similarity matrix, which can be expressed in the form Then, we obtain the matrix SM of similarity degree, whose matrix elements are  between the evidences, and use it to define the support degree sup(  ) of all the evidence; that is, the support degree of the body   in the designated evidence system is [31]  The support degree of the evidence   is normalized.We obtain the credibility weight of evidence   as follows: After the acquisition of credibility weights of each evidence, the weighted average for the basic trust distribution of evidence is calculated: Using the classical Dempster-Shafer combination rule to combine   () ( = 1, 2, . . ., ), the final weighted evaluation values   are acquired by the weighted average of the combination results.
Step 7 (index scores and measures).The modified evidence theory model is mainly to eliminate the conflict that different DMs have different assessments on one factor.For intracriteria evaluation of any factor, a logistic function should be found for the safety attributes.A linear function is used to model the safety rate instead of an exponential function.First, the linguistic variables set which consists of five judgment levels is set by referring other works [32,33].And then, based on the principle of Likert scale [34] and other references [24], and to have a better distinction degree, a 1-9 value scale is given to the linguistic variables.The "medium (M)" variable corresponds to an average value of 5, while the corresponding values for "low (L)" and "high (H)" are 3 and 7, respectively.The complete list of variables and corresponding average values are shown in Table 2.
We calculate the faulty behavior risk (FBR) of the working system by using the index weights and linguistic values.The intercriteria evaluation includes the process of defining the criteria weights by means of an elicitation procedure.This process and the meaning of the criteria weights depend on the type of method.Specifically, the corresponding index evaluation weight   calculated by the ANP method and evaluation index value   computed by the evidence theory method are multiplied and then summed; that is,  = ∑  =1     (  ∈ (0, 1),   ∈ (1, 9)).In this manner, we obtain an overall FBR value of the system.The FBR value of the system is only a numerical result without knowing how well or bad the system is; thus the result degree should be established to give a clear result.From the value of   and   , it can be determined that the FBR range from 0 to 9. The risk will be increased in a nonlinear way with the value increasing and we can classify them in an equidistance division way.At the same time, we can get the fact from other studies [35,36] that the FBR will be major risks if their score exceeds 40% of the total score.On the other hand, the effective measures should be taken when the FBR is in major level and the major level score value interval should be expanded to take measures timely.Therefore, based on the requirement of safety management, experience of experts, and other references [36], the FBR value will divide into four degrees.
(1) If the system's  ≥ 4, there are major risks involved in the operation of the system.Work should cease and be redesigned and fault rectifying should take place and the system should be reevaluated until the new risk assessment values meet the requirements.
(2) If 4 >  ≥ 2, there are some risks involved in the operation of the system.The system's managers or administrators should take corrective and preventive measures and reevaluate after the rectification of the problems.
(3) If 2 >  ≥ 1, there are a few risks involved in the operation of the system but cannot be ignored.The administrators should take corrective action and issue a rectification notice.
(4) If  < 1, the construction or operation of the highrisk system is safe.

Analysis of the Study.
The following is a frequency table of index factors causing accidents based on 186 construction accident cases of the Three Gorges project, the Xiluodu project, and several other large domestic hydropower projects.What is more, the percentage showing the degree to which each factor is present for the 186 construction accident cases is shown in Table 3.
As outlined in Table 3, the "B1 education and training," "C4 personal basic situation," and "B2 safety supervision, inspection, and acceptance" constitute a large percentage of the factors leading to accidents.It is thus obvious that the occurrence frequency of these factors is higher in cases of accidents; "B5 accident report, investigation, and treatment," "C5 occupational health," and "B4 emergency rescue" have a smaller proportion, less than 5%.The data presented above are just the frequency results, without considering any mutual influence relationship between the factors.
Statistical methods were used for data correlation analysis, using SPSS software to calculate the chi-square values of any two factors among the operation safety high-risk index framework, to determine possible independence between factors and further obtain the Lambda and Tau-y correlation coefficient between the index factors.The correlation coefficients were calculated according to the first step in the evaluation process and are shown in Table 4.
We can see from Table 4 that the values of  (x-y) range from 0 to 0.455, where a larger value of  (x-y) indicates a Correlation analysis results are auxiliary information for the DMs to build impact relation matrix.First we selected three DMs with adequate working experience from the site construction; they were competent at this job.The basic information of the three DMs is presented in Table 5.
The three DMs are discussed together based on the correlation coefficient in Table 4. Considering the value interval of  (x-y), the experts divide the relationship into four grades (0, 1, 2, and 3).The number zero means no influence between factors with the condition that  is zero and hence the relationship is marked with "0," the number one is representative of a small influence, the number two means that one of the factors affects the other moderately, and the number three indicates a strong effect.With the assumption of H1, H2, and H3, three experts conduct agreement of every two factors and all results are presented in Table 6.
Table 6 shows the calculated impact strength relation matrix obtained through the Lambda correlation coefficient  (x-y) and of the accident cases by experts.Clearly, the sums of the rows and columns indicate how much a factor affects other factors (the higher the sum is, the more important that factor is).We can see that Table 6 is not symmetric along the diagonal, suggesting that there is no causality between factors and that the relationship may be bidirectional.
We can get the mutual influence structure of the index factors by associating the Lambda correlation coefficient between the factors with the impact strength relation matrix, shown in Figure 3, in which dashed arrows are representative of a small influence, thin arrows show moderate influence, and thick arrows represent strong influence.For factor in upper level, it is clearly observed that the degree of influence on other factors far outweighs the other factors that affect them.The factor "C4 personal basic situation" is affected by other factors mostly and the factor "A1 organization structure and responsibility" affect other factors mostly, and the main reason is that organization structure and responsibility in the highest level and personal basic situation can be easily affected by many other factors.Strengthening the management of certain factors in the system would have a very important impact on the safety of the entire construction system.For example, "C4 personal basic situation," "C3 team management," "D3 violation operations," and "C2 technical measurements" are largely affected by other factors, and their impact on the system's safety is large and cannot be ignored.

Weight Calculation.
The core work in ANP application is to calculate the weighted supermatrix and the limits of the supermatrix through the index factors influence relationship matrix built using the ANP network hierarchy, which is a very complex calculation process.In order to achieve this, the realization of the ANP model and the calculation of weights were done on the ANP professional software Super Decisions (SD) platform.We obtained the weights of each index factor affecting the safety of high-risk operations through SD software based on (2), (3), and (5) and compared them to the weighted value based on the recorder accident cases, and the results are presented in Table 7.
As is shown in Table 7, the three factors of largest weight according to accident cases' statistics are "B1 education and training," "C4 personal basic situation," and "B2 safety supervision, inspection, and acceptance," because of the higher frequency of these factors in accident cases.The corresponding results obtained through the ANP model were "C4 personnel basic situation," "D2 skill-based errors," and "D3 violation operations," and the weight of "B1 education and training" was ranked seventh.The weight of "C4 personnel basic situation" has the highest value, which is expected because of the mutual influence between the corresponding elements in calculating ANP weights; "D3 violation operations" is the most direct manifestation of the cause of accidents, considering its impact on various other factors, so its weight becomes large.The original larger weights of "B2 safety supervision, inspection, and acceptance," "B3 risk monitoring," "C1 operating environment," and so forth have lower rankings, and the original factor weights that were ranked relatively low, for example, "A2 safety investment," "A3 safety laws and regulations," and "D1 perception and decision errors" were increased, meaning they have a stronger effect.These changes in the weight values demonstrate that taking into account the relationship between the factors has a significant impact on the evaluation results.There are complex dependencies and feedback relationships between index factors in high-risk operation systems; the results that take into account the relationship between the factors  Mathematical Problems in Engineering are more consistent with the actual situation and the ANP approach more objectively reflects the complex relationship between the relevant factors.

Index Value
Calculation.This paper takes a single work system as an example for risk assessment.First, the nonconformance rate of the safety index is calculated for the entire construction process by checking each safety indicator using the method of a safety checklist.Second, a score of the index is obtained according to the statistical results of safety indicators obtained through the safety checklists.Scoring rules have a 9-point scale in Table 2 where the lowest score is 1, indicating the lowest possible risk coefficient, and the maximum score is 9, indicating a higher risk coefficient of the index.If the nonconformance rate is 0, this indicates that all the test items are in line with regulations, having the lowest possible risk coefficient and giving a score of 1.The results were given by three DMs using the safety checklist method shown in Table 8.The three investigations are the same person as the three experts in Section 3.1.The three DMs were independently assessed for the particular work system; due to the fact that each investigator had their own knowledge background, engineering experience and subjective awareness, and other differences, the results are not the same.The three assessment results were used for the application of the evidence theory method.
In Table 8, there are some conflicts to be found.For the first and second expert, "B3 risk monitoring," "C1 operating environment," "C2 technical measurements," "C5 occupational health," and "D1 perception and decision errors" got different scores.It indicates that both experts have different risk attitude on these five factors.For the first and third investigator, they have different assessments on eleven factors, such as A3, B1, B2, B3, C1, and C3; totally 61% factors have different scores.The second and third expert also give different scores to ten factors.In an overall view, there are only five factors which have the same scores from three experts and only account for 28% in the all eighteen factors.Thus, due to the different background of three experts, their conflicts are obvious and should be taken into consideration.
In order to give a detailed procedure of the conflict degree calculation, factor A3 is selected as an example.In this factor, the index scores only three possible numbers 2, 3, or 4; thus Θ consists of three elements 2, 3, and 4.There are three pieces of evidence from three experts  1 (2) = 0.

(13)
It is clear that the third expert is in conflict with factor A3 by the first and second expert, and the conflict degree of the first expert and the third expert is the same as that of the second expert and the third expert 1 (  ) ⋅  2 (  ) = 0.2 × 0.5 + 0.2 × 0.5 + 0.8 × 0 + 0.8 × 0.5 + 0 × 0 + 0 × 0.5 = 0.6.

(14)
The conflict coefficient is 0.6, which indicates that the conflict is obvious.
By combining the evidence of the three experts' score results in Table 8 using ( 7)- (11) and then calculating all the safety evaluation scores of the work system, combined with the weight of each index, we finally obtain the risk value of the entire work system.Each index score value is shown in Table 9.
We then come to the following conclusions combined with the results in Tables 8 and 9: (1) The index with a score higher than 4 points is "D3 violation operations" out of the 18 safety evaluation indicators of the work system.During construction inspection, a number of test results are unqualified and are closely related to unsafe behavior and violation operations by the staff, which may lead to accidents directly.Therefore, the violation operations should be given high priority, and through strengthening education and training, safety supervision and team management, and other measures, we can reduce the number of occurring personnel violation operations.
(2) Safety evaluation index scores above 3 points but less than 4 points are those for "A3 safety laws and regulations," "B1 education and training," "C1 operating environment," "C4 personal basic situation," and "C7 material."There was a big discrepancy in "C4 personal basic situation" between the results of the experts, but it was less pronounced in constructionrelated check items and has little impact on system security.The other four items should be given great importance by the relevant departments and the necessary measures should be taken.We should improve safety management systems for construction work, strengthen the construction personnel safety education and training, improve safety awareness of construction workers, and promote a culture of safe construction, and the disposal of construction materials should be regulated in order to avoid safety risks and ensure the smooth and safe construction in high-risk environments.(3) A score greater than 1 point but less than 3 points was obtained for seven factors, that is, "B2 safety supervision, inspection, and acceptance," "B3 risk monitoring," "C2 technical measurements," "C3 team management," "C5 occupational health," "C6 mechanical equipment," and "D1 perception and decision errors."Although they must not be ignored, these indicators are not the most serious.Decision makers should take further safety measures to reduce the possibility of accidents caused by these factors.
(4) The remaining five indicators are fully satisfied and have a score of 1 point, indicating that all the test items are in line with regulations, having the lowest possible risk coefficient.Scientific decision-making should be summarized timely and good at keeping the advantages of safety management, find deficiencies in high-risk operations, and improve as soon as possible.
To obtain the FBR value of the hydropower construction system, we multiply the score value of each indicator by the corresponding weight and sum them.The total value obtained for this system is 2.668, calculated as follows: The total safety assessment score is 2.668 points for the entire process of the work system, according to the seventh step of the evaluation process, indicating that the whole project can proceed with construction, while correcting shortcomings and then supervising and timely inspecting the rectification work until the indicators are fully up to standards.Violation operations ranked third in the normalized weights of ANP ranking, which shows that they have a large probability of occurrence, as it is the most direct manifestation that caused the accidents, and its index score value based on evidence theory is 4.276.Its importance has been verified and must be given high priority in construction safety.What is more, it is closely connected with other factors and thus could be strengthened through education and training, safety supervision, team management, and other measures to reduce the occurrence of personnel violation operations."A1 organizational structure and responsibility," "A2 safety investment," "B4 emergency rescue," "B5 accident reporting, investigation, and treatment," and "D2 skill-based errors" have an index value (i.e., risk) of 1, which is the lowest risk at management level, and the corresponding weights are relatively small, declaring that the impact of these factors for accidents is relatively small but cannot be ignored.The weighting ranking and index scores of other factors are placed in the middle, which means that managers should take further relevant safety measures to reduce accidents which may happen due to these indicators, although these indicators are not the most serious.
This paper introduced a statistical correlation analysis method on the basis of HFACS index system and obtained relationships between all the factors, which is more realistic and reasonable and offers more advantages than conventional single-layer influence relations.This combination of the statistical calculations after accidents happened (i.e., ANP weight calculation) and management level assessment results before the accidents (i.e., synthesis of evidence theory based on safety checklist) is effective and reasonable and can provide accurate guidance for managers to take actions for mitigation of the high-risk conditions in operations and to improve safety.

Conclusions
In this paper, a theoretical study combined with the ANP method and evidence theory is carried out in the context of hydropower engineering safety construction issues.The difference from most current methods is that the hybrid approach presented solves the problem of dependence on incomplete data.This way, we fully utilize even uncertain or imprecise factors in our process.In addition, the proposed approach has advantages over ANP on the number of comparisons and consistency checks, as it can properly deal with quantitative and uncertain factors, which cannot be solved by the traditional method.Therefore, meaningful results for solving the uncertainty problem can be obtained, which are in accordance with common practices for guiding safety assessments and analyzing risk factors.
The Human Factor Analysis and Classification System (HFACS) is applied in this study of the evaluation problem of human factors in high-risk operations.Then, the interaction between different factors was analyzed quantitatively using statistical methods, including the  2 (chi-square) test, Lambda, and Tau-y measurements.These statistical methods are introduced to solve the defects of the one-way relationship between the adjacent levels faced in previous studies.
The method not only is concerned about mutual influence between factors on all levels, but also takes into account the strength of the relationship, which could not be reflected using previous methods.They turned out to be effective methods to deal with the set of influence factors in the system.In addition, the ANP model's data inputs rely on expert scoring used in the traditional ANP method, which leads to the comparison results of the index factors being too subjective.Moreover, the various DMs' knowledge and experience are different and the inconsistency of the results cannot reflect the actual situation presented using the weighted average.In order to solve the above problems, Lambda correlation coefficient results of statistical method are introduced into the construction of the ANP nonweighted matrix.A combination of statistical methods and ANP methods provides a suitable approach for solving the problems of calculating weights.
The limitation of this work is the bias with three DMs, and it is better to use group decision-making method by more DMs.

Figure 2 :
Figure 2: The hydropower project operations risk assessment model based on ANP.

Figure 3 :First
Figure 3: Mutual influence structure of the index factors.

Table 1 :
Factors description of proposed HFACS index framework.Formal process by which the vision of an organization is carried out like operations, procedures, and oversight, among others, including safety production laws, regulations, and other standards.
B2 Safety supervision, inspection, and acceptance Safety troubleshooting program with a clear investigation of the purpose, scope, methods, and requirements; safety oversight (including all production and business related sites, environment, personnel, equipment, facilities, and activities) and methods; negligence of duty, failure to provide guidance of equipment maintenance, failure to provide skill and safety training and training track qualifications, failure to check the qualification of equipment, failure to identify existing equipment failure and error operation, and failure to initiate corrective action; regulators authorized unqualified staff for duty; authorized mission not in accordance with regulations; failure to enforce rules and regulations.
3 (establishing the ANP supermatrix).Let us assume that there are  criteria, denoted as  1 , . . .,   , independent of each other, in the ANP control layer.Under the control layer, we have a total of  clusters in the network layer, denoted as  1 , . . .,   , where each cluster   is made up by the elements  1 , . . .,   are obtained by the eigenvalue method.We denote   as ,  = 1, . .., .Control layer criteria   ( = 1, . .., ) are the first level of criteria, and the elements   ( = 1, . ..,   ) in the cluster   are the second level of criteria.The influence of the elements of cluster   on the element   is compared indirectly with each other; that is, the degree of the occurring probability of a risk factor affected by other risk factors is compared.Then we can get a comparison matrix:   1 ,  2 , . . .,    Normalized eigenvector  1 ).The supermatrix  is composed of  supermatrices. is also the total number of criteria and under each criterion we have a corresponding supermatrix.These matrices are nonnegative, while the subblock   of the supermatrices is column normalized, whereas the supermatrix  is not.Taking   as the criterion, the importance of each cluster under   is compared against the criterion ( = 1, . . ., )    1 , . . .,   Normalized eigenvector vector  1  1 . . . . . . = 1, . . .,  . . .

Table 2 :
Linguistic values and numbers.

Table 3 :
Classification statistics of each index factor.
stronger correlation between  and , whereas the values of  (x-y) are mostly distributed in the range of 0.05 ∼ 0.2.

Table 4 :
Intercriteria analysis matrix obtained by correlation coefficient.

Table 5 :
The basic information of three experts.

Table 8 :
Index score results of the three experts.

Table 9 :
Index score results calculated using the evidence theory.