Review on Energy Resilience

profileharsh55
Kong_et_al-2019-Risk_Analysis.pdf

Risk Analysis, Vol. 39, No. 5, 2019 DOI: 10.1111/risa.13222

Sequential Hazards Resilience of Interdependent Infrastructure System: A Case Study of Greater Toronto Area Energy Infrastructure System

Jingjing Kong,1 Slobodan P. Simonovic,1 and Chao Zhang2,∗

Coupled infrastructure systems and complicated multihazards result in a high level of com- plexity and make it difficult to assess and improve the infrastructure system resilience. With a case study of the Greater Toronto Area energy system (including electric, gas, and oil trans- mission networks), an approach to analysis of multihazard resilience of an interdependent infrastructure system is presented in the article. Integrating network theory, spatial and nu- merical analysis methods, the new approach deals with the complicated multihazard relations and complex infrastructure interdependencies as spatiotemporal impacts on infrastructure systems in order to assess the dynamic system resilience. The results confirm that the effects of sequential hazards on resilience of infrastructure (network) are more complicated than the sum of single hazards. The resilience depends on the magnitude of the hazards, their spatiotemporal relationship and dynamic combined impacts, and infrastructure interdepen- dencies. The article presents a comparison between physical and functional resilience of an electric transmission network, and finds functional resilience is always higher than physical resilience. The multiple hazards resilience evaluation approach is applicable to any type of in- frastructure and hazard and it can contribute to the improvement of infrastructure planning, design, and maintenance decision making.

KEY WORDS: Greater Toronto Area; interdependent infrastructure system; multiple hazards; re- silience

1. INTRODUCTION

Infrastructure systems, including electric power, telecommunications, natural gas and oil, trans- portation, water supply, and others, are large-scale engineered systems for the production and distri- bution of essential goods and services for society and the economy (Zio, 2016). These infrastructure systems are complex networks of interconnected

1Department of Civil and Environmental Engineering, Western University, London, ON, Canada.

2Shanghai Key Laboratory of Financial Information Technology, Shanghai University of Finance and Economics, Shanghai, China.

∗Address correspondence to Chao Zhang, Shanghai Key Labora- tory of Financial Information Technology, Shanghai University of Finance and Economics, 777 Guoding Road, Shanghai 200433, China; tel: +86-15026449812; [email protected].

functional and structural elements (Fang, Pedroni, & Zio, 2015). Small perturbation of one infrastructure system can produce cascading failures of other sys- tems and cause systemic damage to all infrastructure types (Ouyang, 2014). Mass instantaneous infras- tructure damage caused by natural hazards, such as hurricanes, earthquakes, and floods, could result in devastating, widespread, and often unpredictable impacts (Baroud, Barker, Ramirez-Marquez, & Rocco, 2015). This leads to the need for more resilient infrastructure systems, able to function in a complex and volatile environment (Hausken & He, 2014).

Resilience implies the ability of a system to withstand and return to normal condition after an internal or external disturbance (Gilbert, 2010;

1141 0272-4332/19/0100-1141$22.00/1 C© 2018 Society for Risk Analysis

1142 Kong, Simonovic, and Zhang

Hosseini, Barker, & Ramirez-Marquez, 2016). Its origins are in ecology and the work of Holling (1973). Due to the wide interest and application in various disciplines, there is neither a universal definition nor a widely accepted general quantitative approach for its assessment (Cutter et al., 2013; Zobel, 2011). Infrastructure system resilience is always seen as the ability of the interconnected and intricate infras- tructure system: (i) to resist (prevent, absorb, and withstand) any possible hazard (The infrastructure Security Partnership, 2006); (ii) to reduce the magni- tude of impact and/or duration of a disruptive event (National Infrastructure Advisory Council [NIAC], 2009); and (iii) to recover and reconstitute critical services to the public with minimum devastation (Ouyang & Wang, 2015; Simonovic & Arunkumar, 2016a). Insightful studies quantify the impacts of network topological property, response strategy, and adverse event on infrastructure system resilience (Ganin et al., 2016; Linkov et al., 2015). Accordingly, resilience is not only the measure of capacity of an infrastructure system, but also relates to the type, magnitude, and other characteristics of the disruptive event (Aerts et al., 2014; Ayyub, 2014; Oddsdóttir, Lucas, & Combaz, 2013), such as the hurricane resilience (Ouyang & Dueñas-Osorio, 2014; Ouyang & Wang, 2015; Winkler, Dueñas-Osorio, Stein, & Subramanian, 2010), seismic resilience (Shinozuka et al., 2004), and flood resilience (Simonovic, 2016; Simonovic & Arunkumar, 2016b) of infrastructure systems.

Sequential hazard resilience is of significant prac- tical value, as most world regions are subject to multiple natural and technological hazards (Ayyub, 2014; Liu, Siu, & Mitchell, 2016). Some examples in- clude: the Prince William Sound region of Alaska, USA in 1964 attacked by an earthquake and fol- lowed by landslide and tsunami (Suleimani, Hansen, & Haeussler, 2009), the Mount Pinatubo volcanic eruption that triggered an earthquake in the Philip- pines 1991, New Orleans destroyed by Hurricane Katrina and following flood in 2005, and the Japan Tohoku earthquake followed by flood and tsunami in 2011. Compared with single-hazard resilience, sequential hazard resilience of infrastructure sys- tems is more capacity oriented, and needs scenario- based, site-specific, and scope-distinct analyses. Its main objective is to synthesize impacts of multi- ple hazards on exposed spatially distributed and functionally interdependent infrastructure systems (Ouyang & Dueñas-Osorio, 2012). Sequential haz- ards impacts could be mapped onto the dynamic per-

formance of infrastructure systems (Komendantova et al., 2014).

The infrastructure system is composed of mul- tiple networked subsystems, such as power grid, water supply network, gas transmission network, and others. The failures of some system components at the local level may result in the disruptions of other components via cascading failures, and may also affect other subsystems due to their interdependen- cies (Baroud et al., 2015; Fang et al., 2015; Ouyang & Dueñas-Osorio, 2012). A quantitative infrastruc- ture resilience analysis method should incorporate the dynamic interactions of direct impacts of multiple hazards and failure propagation mech- anisms of the infrastructure system. This should provide for holistic spatiotemporal failure spread analysis and monitoring progress of restoration strat- egy implementation. However, the effects of over- lapping, sequential, and related hazards on resilience of infrastructure networks are still rarely considered and only a few approaches and studies on this topic are available. Currently, the infrastructure resilience topic is receiving significant attention in the engineer- ing field—dealing with multihazard designs. How- ever, even in this context, the number of published studies remains very low. The impacts of sequential hazards are particularly rarely addressed in the literature. There is a clear shortage of studies dealing with damage assessments of sequential hazards and/or the separation of impacts of each of the haz- ards (e.g., earthquake followed by tsunami or only earthquake).

The primary objectives of this article are: (1) to propose an approach for describing the complicated multihazard relationships and complex infrastructure interdependencies; (2) to assess and quantify multi- layer infrastructure network resilience subject to se- quential multiple hazards; and (3) to show the utility of the approach using a real case study of the Greater Toronto Area (GTA) energy infrastructure system.

The remainder of the article is organized as follows. Section 2 presents the multiple hazard resilience definition and probabilistic model derived from the single-hazard resilience and metric. In Section 3, the GTA energy infrastructure system (in- cluding electric, gas, and oil transmission networks) is used as a case study to present an application of the sequential hazard resilience assessment method. The GTA energy infrastructure system is modeled as a multilayer network, and intra- and internet- work interdependence models are constructed. Section 4 introduces a sequential hurricane and flood

Sequential Hazards Resilience of Interdependent Infrastructure System 1143

disaster scenario, analyzes their direct impacts on infrastructure and indirect failure probabilities as a consequence of various interdependences. Section 5 describes a sequential hazard resilience simula- tion procedure. Sections 6 and 7 present temporal and spatial infrastructure system performance and resilience using both physical and functional perspec- tives. Section 8 contains a discussion of single-hazard marginal impacts, cascading recovery effects, and resilience accumulative results. Conclusions are drawn in Section 9.

2. SEQUENTIAL HAZARD RESILIENCE ASSESSMENT APPROACH

The following section presents the derivation of a new sequential hazard resilience assessment approach.

2.1. Deterministic Single-Hazard Resilience Metric

Infrastructure system resilience is defined as “the ability to prepare for, and adapt to changing conditions, and withstand and recover rapidly from disruptions,” including “the ability to withstand and recover from deliberate attacks, accidents, or natu- rally occurring threats or incidents” (Office of the Press Secretary of the White House, 2013; Ouyang & Dueñas-Osorio, 2012). The original space-time dy- namic resilience measure developed by Simonovic, Peck, and Madani (2013) is adapted in this research to complex network infrastructure systems subject to multiple sequential hazards. The original definition quantifies resilience as the difference between the area under expected system performance (dot- ted line in Fig. 1) and actual system performance (solid or dashed line in Fig. 1). The mathematical representation of quantitative resilience is:

r Ai (T) = ∫ T

t OAi S PAi (t )dt∫ T

t OAi S P0(t )dt

= ∫ T

t OAi (S P0(t ) − SLAi (t ))dt∫ T

t OAi S P0(t )dt

= 1 − ∫ T

t OAi SLAi (t )dt∫ T

t OAi S P0(t )dt

, (1)

where r Ai (T) is resilience of the infrastructure system to hazard/disturbance Ai at time T, S PAi (t ) is the actual performance of a multilayer infrastructure network, S P0(t ) is the expected performance of a multilayer infrastructure network, SLAi (t ) is the sys- tem performance loss of a multilayer infrastructure

network, and t OAi is the hazard/disturbance Ai occur- rence time. Multilayer infrastructure network perfor- mance always uses a uniform measure to capture the interdependent system service level. Examples may include the proportion of surviving nodes (Ouyang & Wang, 2015; Ouyang, Dueñas-Osorio, & Min, 2012), operation rates of edges/links (Liu & Singh, 2011), or size of the largest connected component (Winkler et al., 2010). The number of customers served by the infrastructure system can also be used as the system performance measure (Poljanšek, Bono, & Gutiérrez, 2012; Reed, Kapur, & Christie, 2009).

In Fig. 1, the width of a red arrow displays the duration of the disturbance. Typical dynamic infrastructure performance can be divided into three phases: disaster prevention, damage and propaga- tion, evolution and recovery (Baroud et al., 2015; Baroud, Ramirez-Marquez, Barker, & Rocco, 2014; Poljanšek et al., 2012). Based on the resilience model derived by the Multidisciplinary Center for Earth- quake Engineering Research (Bruneau et al., 2003), the system resilience is a function of system performance and system adaptive capacity. System adaptive capacity determines the shape of the perfor- mance curve in Fig. 1, and can be described using four features of the graph: robustness, redundancy, re- sourcefulness, and rapidity. Robustness refers to the ability of a system to withstand a given level of stress without suffering degradation or loss of function— minimum level of performance after the system disturbance. It is computed as the ratio of minimum number of operational elements after multiple dis- turbances to the total number of elements in the net- work. Redundancy, represented by the slope of the descending segment of the graph, describes the al- ternative functions and designs for the system to op- erate (e.g., existence of parallel transmission lines). Therefore, there is a close functional link between redundancy and robustness (NIAC, 2009). Resource- fulness is the capacity to develop and implement mitigation and response strategies for recovery from a specific disturbance and is represented by the slope of the ascending segment of the graph in Fig. 1. It is a function of restoration strategies, and can be calcu- lated as the difference between system performance with and without restoration strategy. Rapidity is measured by the time necessary for the infrastruc- ture system to recover to normal operational level. It is worth mentioning that performance metrics used should be based on the research focus and available data.

1144 Kong, Simonovic, and Zhang

Fig. 1. Typical interdependent infrastruc- ture system performance under a single hazard/disturbance Ai.

2.2. Probabilistic Sequential Hazard Resilience Metric

Multiple hazard/disturbance refers to a situation when hazards of different kinds or magnitudes occur at the same time or, more often, follow one another with damaging force. Examples include floods in the midst of drought, or hurricane followed by landslides and floods (Gill & Malamud, 2015; Kappes, Keiler, Elverfeldt, & Glade, 2012) and similar occurrences. With their diverse intensity, return periods, im- pacts, and uncertain relationships, multiple hazards may have complex impacts and create unexpected threats very different from those caused by a single hazard/disturbance (Carpignano, Golia, Di Mauro, Bouchon, & Nordvik, 2009; Kappes et al., 2012; Ouyang & Dueñas-Osorio, 2012). Multihazard re- silience is the dynamic nonlinear superposition of a single hazard’s spatiotemporal impacts on a complex infrastructure system.

Sequence is a typical temporal relation of mul- tiple hazards. Sequential hazards resilience of an infrastructure system is generally analyzed individ- ually with the assumption of later events occurring after full system recovery from the previous one, which means the later hazard happens after t REAi in Fig. 1. Then infrastructure system performance and resilience can be calculated as single-hazard resilience at different time periods, and evaluated individually (Liu et al., 2016).

In reality, very often there is not enough time or resources for full infrastructure system recovery from the previous hazard before the later one occurs. The impact of one hazard on the physical infrastruc- ture could increase the vulnerability to secondary

or future hazard events, therefore potentially am- plifying the effects of secondary or future hazards. For example, an earthquake may weaken bridges, making them more susceptible to collapse in the event of another earthquake, if the repairs are not completed before the follow-up events. In this situ- ation, infrastructure damaged by the earlier hazard could not be repaired as planned and can be de- stroyed by a later hazard. Therefore, infrastructure resilience is not an integration of individual hazards resilience at different times—it is a result of multiple hazard impacts’ interaction on the infrastructure system. The later hazard may happen during the “damage and propagation phase” or the “evolution and recovery phase” and therefore could result in different system performance considering hazard interactions and infrastructure interdependences.

In the situation of the later hazard occurrence during the former hazard’s damage and propagation phase, the infrastructure system would be attacked by two hazards simultaneously or sequentially with- out repair. The response of a single infrastructure system under the interaction of two hazards would be more complex, resulting in, for example, a fragility curve of a bridge under simultaneous or sequential impacts of hurricane and earthquake. The infras- tructure system performance would be more compli- cated considering infrastructure interdependences, as shown in Fig. 2. However, robustness of the infras- tructure system under the two hazards is lower than the robustness under the single hazard. Resourceful- ness and rapidity are also different from that of a sin- gle hazard with the same available repair resources.

In the situation of the later hazard occurrence during the former hazard’s evolution and recovery

Sequential Hazards Resilience of Interdependent Infrastructure System 1145

Fig. 2. Typical infrastructure system performance under two concurrent hazards.

Fig. 3. Typical infrastructure system performance under two sequential hazards.

phase, the infrastructure system would be attacked by two hazards sequentially with partial repair only. The whole system performance of the infrastructure system can be divided into two phases, shown in Fig. 3. The system performance evolution curve in each phase has a shape very different from the shape of the performance curve under a single hazard.

Expanding on the deterministic resilience model in Equation (1) and system performance under se- quential hazards relationship (Figs. 2 and 3), sequen- tial hazard resilience could be expressed as:

r A1 ,..., Am (T) =

∫ T t OA1

S P(t )dt

∫ T t OA1

S P0(t )dt = ∑m

i =1 ∫ t ∗Ai

t OAi

S P(t )dt

∫ T t OA1

S P0(t )dt

= 1 − ∑m

i =1 ∫ t ∗Ai

t OAi

SL(t )dt

∫ T t OA1

S P0(t )dt , (2)

where r A1,..., Am (T) is multihazards resilience of a mul- tilayer infrastructure network at T. Notation for haz-

ards is A1, . . . , Am(m ≥ 2) with subscripts of haz- ards being in order of precedence. The t OAi is the occurrence of hazard Ai , t ∗Ai = min{t REAi , t Ai +1 , T}. With S P(t ) approaching 1 and T approaching in- finity, the resilience r A1,..., Am (T) will approach the value 1.

A vulnerability function (fragility curve) of infrastructure system (suggested by general agree- ment in multirisk analysis) (Baroud et al., 2014; Bruneau et al., 2003) assumes that the state of an infrastructure system is random, and therefore the actual system performance (S P(t )) and system loss (SL(t )) of a multilayer infrastructure network are also of stochastic nature. The multihazard resilience in this case can be seen as an expected value, and Equation (2) can be modified as:

r A1,..., Am (T) = ∑m

i =1 ∫ t ∗Ai

t OAi

E (S P(t )) dt

∫ T t OA1

E (S P0(t ))dt

1146 Kong, Simonovic, and Zhang

= 1 − ∑m

i =1 ∫ t ∗Ai

t OAi

E (SL(t )) dt

∫ T t OA1

E (S P0(t ))dt

= 1 − ∑m

i =1 ∫ t ∗Ai

t OAi

∑N u=1 Pu (t )

N dt

∫ T t OA1

∑N u=1 (1−P Eu (t ))

N dt , (3)

where E(S P(t )) is the expected value of actual performance of a multilayer infrastructure network. E(S P0(t )) is the expected value of expected system performance. E(SL(t )) is the expected value of expected multilayer infrastructure network loss. N is the size of the multilayer infrastructure network. Pu is the damage probability of uth individual in- frastructure component. P Eu is the expected damage of uth individual infrastructure component, which always equals 0 without any damage. Accordingly, features (robustness, resourcefulness, rapidity) of multihazards resilience are also the corresponding expected values.

In reality, infrastructure systems always have backup facilities, “slack” resources, redundancy, or structure modularity (Nan & Sansavini, 2017), so the function loss would not be the same as physical damages (Reed, Wang, Kapur, & Zheng, 2016). The normal way to analyze functional resilience of multihazards is to measure the importance of infras- tructure (Iu) with corresponding metrics. Examples may include use of operation facilities for system technical performance, population served, economic benefits of industry supported, or unaffected seg- ments of society (Larocca, Johansson, Hassel, & Guikema, 2015). Then the multihazard functional resilience can be expressed as:

r A1,..., AmF (T) = ∑m

i =1 ∫ t ∗Ai

t OAi

E (S P(t )) dt

∫ T t OA1

E (S P0(t ))dt

= 1 − ∑m

i =1 ∫ t ∗Ai

t OAi

E (SL(t )) dt

∫ T t OA1

E (S P0(t ))dt

= 1 − ∑m

i =1 ∫ t ∗Ai

t OAi

∑N u=1 Pu (t )Iu

N dt

∫ T t OA1

∑N u=1 (1−P Eu (t ))Iu

N dt . (4)

The main features of multihazard functional re- silience (robustness, resourcefulness, and rapidity) will change with change in the functional importance of infrastructures.

2.3. Sequential Hazard Resilience Assessment Methodology

To obtain the value of variables in Equations (3) or (4), a multiple hazard resilience assessment methodology of interdependent infrastructure sys- tems is developed by integrating all the analytical definitions introduced in the previous section. The implementation of the methodology contains three steps. The first step involves interdependent in- frastructure system modeling with network theory and geographical information systems (GIS) for processing spatial data, which includes (i) a single type of internally interdependent infrastructure; and (ii) multiple types of externally interdependent infrastructures. The second step involves develop- ment of a multiple hazard relationship model and assessment of direct impacts on individual infras- tructure components with statistical fragility curves. The diverse combined impacts of multiple hazards on the infrastructure system require temporal and spatial decompositions of relationships. Inductive generalization is used to construct the multiple hazards relationship analysis framework. The third step includes assessment of indirect impacts as a con- sequence of infrastructure interdependencies, and calculation of spatiotemporal system resilience using Monte Carlo simulation. The methodology frame- work and implementation process are illustrated in Fig. 4 for an example of energy infrastructure.

The utility of this assessment framework is speci- fied in the following sections with the GTA energy in- frastructure system. First, the GTA electric, gas, and oil transmission networks are modeled using network theory and GIS, including their operation mech- anisms and topology-based interdependent mech- anisms. Second, a sequential hurricane and flood scenario is modeled, especially their temporal and spatial relationship. Combined with the damage probability functions for each infrastructure type un- der separate hurricane and flood events, the direct damage probability of individual infrastructure com- ponents is estimated. At last, by integrating the joint restoration strategy (see Subsection 5.1) and all the above models, GTA interdependent infrastructure system resilience is analyzed by Monte Carlo simu- lation.

3. MULTILAYER INTERDEPENDENT INFRASTRUCTURE NETWORK

This section presents an interdependent in- frastructure system model of the GTA energy

Sequential Hazards Resilience of Interdependent Infrastructure System 1147

Fig. 4. Assessment framework for sequential hazards resilience of interdependent infrastructure system.

infrastructure system. All the data used in this study are in the public domain, provided by the owners of the infrastructure. To validate the data, maps and reports available from the infrastructure owners, in- cluding the independent electricity system operator (IESO), Hydro One, the Canadian Association of Petroleum Producers (CAPP), and the Canadian Energy Pipeline Association (CEPA) are used together with the CanVec data. CanVec is a digital cartographic reference product of Natural Resources Canada (NRCan) combining the National Topo- graphic Data Base, the Mapping the North process conducted by the Canada Center for Mapping and Earth Observation, the Atlas of Canada data, the GeoBase initiative, and available satellite imagery.

3.1. GTA Energy Infrastructure Spatial Network

The GTA is the most populated metropolitan area in Canada, and is defined as the central City of Toronto and its four surrounding regional munic- ipalities: Durham, Halton, Peel, and York. In this article, electric, gas, and oil transmission networks of the GTA are taken for the implementation of the proposed approach. The GTA electric transmission network is built from the CanVec data (NRCan, 2014), IESO (IESO, 2014), and Hydro One reports (Hydro One Networks Inc., 2012). The GTA gas and oil transmission networks are built from the CanVec data (NRCan, 2014) and CEPA maps (CAPP, 2014; CEPA, 2014). The GTA three-layer energy infrastructure spatial network is illustrated in Fig. 5.

GTA electric transmission network refers to the bulk power system of GTA, including the generation and transmission stations and power lines. There are three types of power plants in GTA: nuclear, gas-fired, and solar power stations; three types of transmission lines with different voltage—500 kV, 230 kV, and 115 kV. The GTAA Cogeneration Plant is not considered here as its capacity is only 90 MW and its primary role is to provide power to the Toronto Pearson International Airport. There are no gas or oil production facilities in GTA. Therefore, the gas and oil transmission networks contain only transmission facilities: compressor stations, meter stations, pump stations, and pipelines. Due to limited data availability, no information on the capacity of gas and oil facilities is provided here. GTA energy infrastructure system information is provided in Table I.

3.2. Infrastructure Interdependence Models

Individual infrastructure systems consist of numerous and distributed components. Damage to several components or localized impact of natural or manmade disasters could cause whole system failure (Buldyrev, Parshani, Paul, Stanley, & Havlin, 2010). In addition, the small failures of a few components could propagate to other infrastructure, and result in a large disaster to society and the economy. There- fore, cascading failures need to be addressed in the analyses of infrastructure system resilience and risk. Based on the three-layer GTA energy infrastructure network, two types of interdependences need to

1148 Kong, Simonovic, and Zhang

Fig. 5. GTA three-layer energy infrastructure spatial network.

Table I. GTA Three-Layer Energy Infrastructure Spatial Network Information

Infrastructure Components Number Infrastructure Components Number

Electric Transmission Network Gas Transmission Network Power generation Nuclear 2 Compressor stations 2

Gas-fired 6 Meter stations 15 Transmission stations 500 kV 4 Pipelines 22

230 kV 43 115 kV 26 Oil Transmission Network

Power line 500 kV 13 Pumping stations 4 230 kV 64 Meter stations 1 115 kV 30 Pipelines 6

be considered: intranetwork (within a layer) and internetwork (between the layers) failure propaga- tion mechanisms. Intranetwork interdependence is always modeled as an operation mechanism for one type of infrastructure. Some examples include the Motter-Lai (ML) model (Crucitti, Latora, & Mar- chiori, 2004; Fang et al., 2015; Motter & Lai, 2002) of power grid failure propagation, the pipeline flow model of a gas system (Ouyang, Hong, Mao, Yu, & Qi, 2009), and so on. Internetwork interdependence focuses on the physical and functional interaction between different types of infrastructure, which includes topology-based or flow-based methods (Ouyang, 2014).

There are three types of infrastructure in the GTA energy infrastructure system: electric, gas, and oil transmission networks. For the electric transmis- sion network, the ML model is a prominent approach used to analyze cascading failures. In this model, nodes are differentiated as generators NG (electricity

generating plants) and loads NL(substations). All nodes are interconnected by a set of edges represent- ing power lines. The load of each substation node is defined as the number of most efficient paths from generation to substations that pass through that sub- station node (Goh, Kahng, & Kim, 2001). Each sub- station node u is characterized by initial load Lu(0), real load Lu(t ), and maximum load Cu = Lu(0) × t p, where constant t p is a tolerance parameter. Path efficiency euv (t ) is the maximum value of efficiency of all paths connecting node u and v, representing relative link capacity. Efficiency of zth path ezuv (t ) is calculated as the reciprocal of sum of reciprocals of edge efficiency in the path. The initial value of each edge efficiency is set to 1 following the recommen- dation from published studies (Goh et al., 2001). It is assumed that electricity is flowing between any pair of generator nodes and substation nodes through the most efficient path. An initial breakdown of edges surrounding a node causes power to be redistributed

Sequential Hazards Resilience of Interdependent Infrastructure System 1149

in the network, reflected by changes in the most efficient paths and, consequently, changes in the load at each node. Some nodes are then forced to operate above capacity (being overloaded), represented by decreases in efficiency of the edges of that node:

euv (t + 1) =⎧⎨ ⎩

euv (0) else euv (0) min(

Lu (0) Lu (t )

, Lv (0) Lv (t )

) if Lu(0) < Lu(t ) ≤ Cu. 0 if Lu(t ) > Cu

(5)

The substation fails when its path efficiency equals 0. The failed substations would change the path efficiency of other substation nodes, and indeed change the electric transmission path in the network. Convergence in this iterative process occurs when the node states become stable. If we assume that the maximum load of every substation node in the network is the same, then the performance P(t ) of the electric power network can be computed as the fraction of available substation nodes. Here, t p is set to 2 (Johansson & Hassel, 2010).

As the sizes of gas and oil transmission networks are small, their intranetwork interdependence is modeled using a topology-based model. This article assumes that gas is transported from compressor stations to meter stations, and oil is transported from pump stations to meter stations.

The topology-based model is used for internet- work interdependence among the three types of in- frastructure systems here. This article assumes that gas-fired power plants require gas to keep normal operation, and all types of gas and oil nodes re- quire electricity to keep their normal operation. As the networks considered are all limited to the ma- jor transmission systems, internetwork links are not illustrated in Fig. 5 but are defined as follows: (i) gas- fired electric plants are supported by the nearest gas meter stations through gas transmission pipelines; (ii) gas and oil nodes are powered by the nearest elec- tric transmission substations through power lines; and (iii) buffering is introduced as a popular emer- gency preparedness strategy that makes the infras- tructure interdependence less tight. Each gas-fired electric plant has buffers in the form of gas stock. The compressor stations, pumping stations, and me- ter stations of gas and oil transmission networks have buffers in the form of standby power generators. Buffers of the above infrastructure are measured in units of time and all are assumed to be equal to one-

time step (two hours). Nodes would be nonopera- tional in the case of malfunction of supporting nodes or destroyed connecting edges.

3.3. Physical and Functional Resilience Metric

Different aspects of infrastructure performance could be measured by using different units. To an- alyze details of the infrastructure dynamic evolution process, in this article the interdependent infrastruc- ture system’s physical and functional resilience are evaluated, respectively, which means different Iu in Equation (4). For physical resilience, Iu of each node in the multilayer infrastructure network is calculated using its capacity. Then physical system performance is measured by the expected value of the proportion of weighted operational nodes. For example, the electric transmission substations’ weight is calculated proportional to their voltage.

For functional resilience, Iu of each node in the multilayer infrastructure network is calculated using the number of customers being served. Then functional system performance is measured by the expected value of the impacted population. As electric infrastructure is seen as the most important in the energy infrastructure system, population unaffected by electric loss is used as a measure of functional system performance here. Considering that the electric substations with larger than 500 kV capacity always function as the hub substations, the population of GTA is allocated to a particular electric substation with 115 kV and 230 kV using the Thiessen polygons (Fig. 6). The Thiessen polygons define areas of influence around each of a set of points whose boundaries define the area that is clos- est to a given point relative to its neighbors. So each single polygon can be considered as the area served by one transmission station. GTA population and the dissemination area boundaries data are obtained from the Canadian Census Analyser (2011).

4. SEQUENTIAL HAZARDS SCENARIO AND ITS IMPACTS

This section describes a sequential hurricane- flood scenario used for GTA case study resilience analyses.

4.1. Sequential Hurricane and Flood Scenario

The sequential hurricane and flood scenario is modeled based on the record of Hurricane Hazel,

1150 Kong, Simonovic, and Zhang

Fig. 6. Population supported by electric transmission substa- tions in GTA.

which was followed by a flood and struck Toronto on October 15, 1954. The path of Hurricane Hazel (Hurricane Hazel Storm Story Map) is downloaded from the NOAA GeoPlatform. Information about the hurricane, storm surge, and flood impacts is from government websites: Hurricane Hazel: 60th Anniversary and Environment and Climate Change Canada.

The records of the Canadian Disaster Database (Public Safety Canada, 2015) show that Hurricane Hazel followed by flood killed 81 people and left 1,896 families homeless. The record rainfall that the storm brought was unable to infiltrate the ground because the above-average rainfall in the preceding month had already saturated the soil. Most of the rain simply ran off the surface into rivers and creeks, rapidly filling them to capacity and beyond. One estimate of runoff was that 90% of the precipitation ran off the land directly into rivers, raising the water level by 6–8 m (Environment and Climate Change Canada [ECCCan], 2015).

This disaster caused by the combined impact of hurricane and flood is taken as the prototype disaster scenario for implementation of the methodology developed in this article. Based on the historical records, the hurricane lasted for 24 hours with rain- fall, then the flood occurred. This means the flood occurred during the damage and propagation phase, or evolution and recovery phase, of the hurricane, dependent on the restoration starting time. Since the whole GTA area was affected by the hurricane, and only infrastructure located within the river basins was impacted by the flooding, there was a spatial overlap between the two hazards.

Based on the Saffir-Simpson Hurricane Wind Scale (The Saffir-Simpson Team, 2012), only hur- ricanes above category 3 (wind speed higher than 110 mph) usually cause flooding. The following assumptions are included in the GTA case study: (i) Hurricane Hazel was assumed to be a category 3 hur- ricane with gust wind speed of 120 mph, weakening to 40 mph after 24 hours; (ii) the hurricane path is the same as the path of Hurricane Hazel as retrieved from the ArcGIS web resources (Tam, 2015); (iii) the area 50 km from the hurricane path was impacted by the hurricane with the same wind speed (Rogers et al., 2013; Willoughby, 2007); and (iv) the impacted area of GTA is divided into four zones (with dif- ferent hurricane occurrence time) perpendicular to the hurricane path, and attacked successively from south to north. Fig. 7 shows the spatial distribution of combined hurricane and flood impacts.

According to the flood classification of the National Weather Service Alaska-Pacific River Forecast Center, the flood following Hurricane Hazel is categorized as a major flooding event. As GTA is dissected by rivers and streams, infrastruc- ture affected by the flood is also along rivers and streams. Based on the flood plain map of Toronto and Region (Toronto and Region Conservation Authority [TRCA], 2012) and Flood Vulnerable Area Clusters of GTA (TRCA, 2014), the most impacted areas include Holland Marsh, Humber River basin, Woodbridge, Thistletown, Raymore Drive, Mount Dennis, Long Branch, and Don River basin, and the flood depth in these areas exceeds 10 ft (ECCCan, 2015). Combining the records of Hurricane Hazel impacts, hurricane occurrence time,

Sequential Hazards Resilience of Interdependent Infrastructure System 1151

Fig. 7. Sequential hurricane and flood im- pacts on GTA.

and the distance from the hurricane path, the flooded areas are identified and shown in Fig. 7. There are only a limited number of infrastructure elements impacted directly (two power generating stations, six transmission substations, one submarine powerline, and one submarine gas transmission pipeline).

The impacts of hurricane and flood on the GTA three-layer energy network have three parts: direct damage as hurricane and flood, indirect damage as intranetwork connection, and indirect damage as in- ternetwork interdependence. The direct impacts on individual infrastructure components are calculated as discussed in Subsections 4.2 and 4.3. Combining the direct impacts, indirect impacts on individual infrastructure as intranetwork interdependence are analyzed with the operation model of single networks introduced in Subsection 3.2. Then indirect impacts on individual infrastructure as internetwork interdependence are analyzed with the topology- based model described above. The dynamic impacts of hurricane and flood on the GTA three-layer energy network are simulated as shown in Fig. 8.

4.2. Single-Hazard Impacts on Infrastructure

Infrastructure component direct failure proba- bilities under a single hazard can be computed by their fragility models under different hazards. The in- dividual infrastructure component vulnerability data under hurricane and flood are all from the published papers, reports, and HAZUS-MH platform.

In the case of a hurricane and power grid, power plants are mostly insensitive to structural hurri- cane damage and therefore their fragilities are not

considered. The fragilities of transmission substa- tions and transmission lines are estimated based on the work of Ouyang and Dueñas-Osorio (2012). The damage probability of substations is represented via log-normal fragility curves. These curves generate the probability of damage for a given wind gust speed (ws ) while taking into account the local terrain and structural characteristics of the substation under consideration. The general form of the fragility curve is given as follows (Ouyang & Dueñas-Osorio, 2014; Federal Emergency Management Agency [FEMA], 2016):

Ptr ans sub,u,l ( D ≥ dul |Ws = xu)

= ∫ xu

0

1√ 2π σul w

exp

( −(ln w − μul )2

2σ 2

) dw. (6)

These curves generate four probabilities for the uth transmission station with different damage lev- els. l refers to the damage level of an infrastructure. It can be low, moderate, severe, or total. Moderate level is used in this work. Ptr ans sub,u,l is the uth electric transmission substation moderate damage probability of exceedance given wind speed xu at the substation site, calculated using the fragility curve corresponding to the terrain near the substation. The parameters μul and σ represent the logarith- mic mean and standard deviation of the pertinent fragility curve. Fragility curves for each type of modeled terrain and building type are taken from a HAZUS-MH technical report.

Transmission lines consist of transmission sup- port structures, conductors, and various pieces of hardware. Due to design requirements (Scawthorn

1152 Kong, Simonovic, and Zhang

Fig. 8. Simulation procedure of GTA infrastructure system resilience under sequential hurricane and flood.

et al., 2006), the fragility of a transmission line under wind load (without considering debris impacts) is mainly determined by the failures of towers. The number of towers along a line is computed as the line length divided by the average span between two adjacent towers, which is set as 0.30 km based on the regional utility data. Based on the investigations by Quanta Technology (2008), the failure probability of the uth transmission support structure can be approximated by an exponential function under a given wind speed xu,

Ptr ans t ower,u (Ws = xu) = min {

2 × 10−7e0.0834xu , 1 }

. (7)

For the gas system subject to a hurricane, un- derground pipelines are mostly invulnerable to wind hazards, and only the gas node failures are consid- ered. The damage probabilities of compressor sta- tions, pumping stations, and meter stations are also calculated using Equation (7).

Underground cables and pipelines might be de- stroyed by the storm surge. The uth underground ca- ble or pipeline damage probability can be approx- imated as functions of hurricane and flood severity (Quanta Technology, 2008),

Punder li ne,u = [a + b( H − S)] × I ( H − S) , (8) where Punder li ne,u is the uth underground facility’s damage probability for given hurricane and storm surge categories. H is the hurricane category (1)–(5), S is the storm surge zone category (1)–(5). a and b are tuning parameters, and equal to 0.08 and 0.28, re- spectively, as the type of infrastructure analyzed is cable (Quanta Technology, 2008). I( H − S) is an in- dicator function showing whether the area is affected by an incoming hurricane, and equals 1 if H − S ≥ 0, else equals 0.

For the flood impacts on the power grid, trans- mission support structures are considered as safe, and only electric node failures are included in

Sequential Hazards Resilience of Interdependent Infrastructure System 1153

the model. For gas and oil networks, all kinds of components could be affected by flooding. HAZUS (FEMA, 2016) provides the infrastructure failure probability under flood within specific areas. In accordance with the hurricane data, the relationship between infrastructure damage probability and flood depth is based on the data from the United States. Two damage levels are considered: low and high. The high damage probabilities with 10 ft flood depth are: 0.30 for power plants, 0.15 for transmission substa- tions, and 0.40 for compressor, pumping, and meter stations of both gas and oil transmission networks.

4.3. Sequential Hazard Impacts on Infrastructure

Damage probability functions discussed in the previous section are for separate hazards, hurricane or flood. Based on the temporal and spatial relation- ships of the two hazards, their impacts on infrastruc- ture are not independent. Damage probabilities of infrastructure should be calculated according to their location and hazard occurrence time.

During t = 1 to t = 12, the hurricane affected the whole GTA, all infrastructure would be dam- aged with specific probability Ptu ( H), which can be calculated by Equations (6) and (7) except the un- derground pipelines.

From t = 13 flooding begins to affect areas along rivers and streams of GTA. Only infras- tructure located in these areas would be directly impacted by the flood. The damage probability of infrastructure only directly affected by the flood (submarine pipelines) Ptu (F ) can be calculated using Equation (8). Other flooded infrastructure damage probability can be calculated by:

Ptu (F |H) = Ptu (F ) + η(1 − Ptu (F )) Ptu ( H), (9) where η is a restoration parameter, which could be 0 or 1. As gust wind speed occurs at t = 1, there may be some time to restore hurricane damaged infrastruc- ture. With limited resources, parts of the hurricane damaged infrastructure might be recovered. For this infrastructure, η = 0, and its damage probability un- der the flood would be Ptu (F ). For other infrastruc- ture affected by hurricane and flood without restora- tion, η = 1. In addition, the infrastructure not located in the blue areas in Fig. 7 would not be damaged by flooding due to its location.

Based on the intranetwork and internetwork fail- ure interdependence models discussed in Subsection 3.2, infrastructure may also be nonoperational due to interdependences. As the function of arcs is deter-

mined by their connecting nodes, there is no undi- rected arcs failure; only nodes would be nonopera- tional when they lose the connection with the source nodes.

5. SEQUENTIAL HAZARD RESILIENCE SIMULATION

5.1. Joint Restoration Model of Interdependent Infrastructure System

Return to initial level of performance after the disturbance is the critical characteristic of system resilience, which is illustrated as the raising limb of the system performance curve shown in Figs. 1–3. There is emerging literature studying the restoration processes of infrastructure systems. Most of the published research deals with the optimization of postdisaster individual infrastructure system restora- tion, applying a variety of modeling approaches and focusing on different aspects of the restoration strat- egy. Examples include: minimization of the power system’s restoration time under hurricane event (Liu, Davidson, & Apanasovich, 2007; Nateghi, Guikema, & Quiring, 2011), maximization of power system resilience with different operations models (Fang et al., 2015), maximization of performance and minimization of a telecommunication system cost (Zobel, 2011), maximization of resource efficiency in spatially distributed networks (Hausken & He, 2014; Hosseini et al., 2016), and others. The joint restoration strategy work mostly considers single- layer infrastructure network resilience. Restoration strategies are always focused on the repair order of damaged system components or the addition of new components. The main questions are where and how to allocate limited repair resources.

In this study, the resilience of a multilayer in- frastructure network is introduced as an objective that can be implemented in the assessment of vari- ous recovery strategies. So analytically, the objective of restoration is set to maximize the resilience of a multilayer infrastructure network during a selected duration, which can be expressed as:

max r A1,..., An (t ∗), (10a)

s.t.

⎧⎪⎪⎨ ⎪⎪⎩

∑ u

RNu(t ) ≤ CRN(t ) ∑

u

T Nu(t ) ≤ CT N(t ) , (10b)

1154 Kong, Simonovic, and Zhang

where r A1,..., An (t ∗) is the multiple hazard A1, . . . , An (n ≥ 2) expected resilience value during [t OA1 , t ∗], t ∗ is the specific time set for resilience assessment, t OA1 is the beginning time of the first hazard A1, RNu de- notes physical resources needed to repair the dam- age of the uth individual infrastructure component at t (t < t ∗) , CRN(t ) denotes physical resources avail- able at t (t < t ∗) , T Nu(t ) is the time needed to re- pair the damaged uth individual infrastructure com- ponent at t (t < t ∗) , and CT N(t ) is the total time available at t step, which can be measured as t ∗ − t .

The formulated restoration model (Equations (10a) and (10b)) is not easy to solve with standard optimization techniques, as the dynamic spatial impacts of hazards on infrastructures and fail- ure propagation within and across networks are nonlinear and of a high level of complexity. The evo- lutionary programming methods like, for example, the genetic algorithm (GA) proposed by Ouyang and Wang (2015) can be used here.

5.2. Sequential Hazard Resilience Simulation Process

System resilience analysis shows expected infras- tructure system response to component fragilities and interaction of hazards and their intensities. The Monte Carlo method is used for simulation of dam- age propagation due to its ability to include complex phenomena like cascading failures in the model (Hernandez-Fajardo & Duenas-Osorio, 2013). As multiple hazards might occur at different times, the simulation process could be divided into several phases to integrate components damage probabilities calculation and their cascading failure effects. Every phase starts with a hazard occurrence, and includes direct hazards impact evolution, intranetwork fail- ure propagation analysis, and internetwork failure propagation analysis, as shown in Fig. 8. In this case, the simulation progress is divided into two phases. The first phase is focused on infrastructure network performance subject to hurricane. The second phase combines the flood impacts on the infrastructure system.

In this simulation, delivery time of electric, gas, and oil is set to be equal to one time step (two hours). Buffers usually have limited capacity in terms of the time, and are usually incorporated as a time delay be- tween the node failure and its dependency loss. Here, we set every node to have a backup of two hours.

To develop the restoration strategy at the components level, that is, determine the restoration

sequence of damaged components at each time step, the following assumptions are added to the restora- tion model list: (i) restoration begins at the time step when component failure occurs or later; (ii) damaged component can recover to normal function in one time step with restoration; and (iii) at most two dam- aged components can be restored in one time step with resource constraints. With gusting wind speeds occurring at t = 1, there are 11 time steps before the flooding begins. After the wind speed weakens below a specific threshold, the restoration can begin. In our case this moment is at t = 8. So, two restoration strategies with different starting times would be used in the simulation. One is a two-phase strategy, restoration from t = 8 to t = 12 and then starting at t = 18 after the flooding ends. The other is a one-phase strategy, starting at t = 18 after both hazards end. The final simulation results are averaged over 100 runs.

Due to the computational complexity, a dif- ferential evolution algorithm proposed by Zhang, Kong, and Simonovic (2018) is used to solve the optimal solution to a joint restoration model of an in- terdependent infrastructure system in Subsection 5.1 by applying GA. The search procedure is performed following three steps.

The first step is code design. Suppose the restora- tion activities begin at t0, and express a restoration sequence by a genotype, which is a 0–1 variable ma- trix G = [gut ]U×CI N . U represents the number of dam- aged infrastructure components. CI N = t ∗−t0 repre- sents the total time available at t0. t ∗ is the specific time set for resilience assessment. If the uth damaged infrastructure component is restored at t0 + t , gut = 1; else, gut = 0. According to above assumptions (i)– (iii), matrix G is subject to the following constraints:

⎧⎪⎪⎪⎪⎪⎨ ⎪⎪⎪⎪⎪⎩

U∑ u=1

gut ≤ 2, (t = 1, 2, 3, . . . , CI N)

U∑ u=1

CI N∑ t =1

gut ≤ U. (11)

Comprehensively considering convergence speed and the variety of individuals, some geno- types of initial individuals are chosen from feasible solutions, the others are randomly generated.

The second step is the fitness value computa- tion. Each genotype corresponds to a restoration se- quence. The fitness value of each genotype is the re- silience of infrastructure systems at time t ∗ with the restoration sequence. For genotypes that do not meet

Sequential Hazards Resilience of Interdependent Infrastructure System 1155

constraint (11), a small enough number is used as a penalty for an unacceptable solution.

The third step is rules for selection, cross-over, mutation, and stopping. The roulette method, two- point cross-over, and random mutation are chosen as rules for the selection, cross-over, and mutation. There are two rules for stopping: one is the num- ber of maximum generations, and the other is the convergence of the optimal fitness value between generations. When the algorithm stops, the genotype corresponding to the maximum fitness value is the optimal restoration strategy.

6. GTA ENERGY INFRASTRUCTURE SYSTEM PHYSICAL RESILIENCE

6.1. Infrastructure Physical Performance Spatial Analysis

GTA three-layer energy infrastructure network resilience is a measure of dynamic performance of all the components together. With the interdependence among infrastructure components, multihazards would have significant diverse impacts on the mul- tilayer network. Electric transmission network, gas transmission network, and oil transmission network performance at six time points subject to different hazards are shown in Fig. 9. The six time points are selected as the hazard occurrence time, one time step after hazard occurrence time, the time when systems resilience returns to a new stable state after the first hazard, the second hazard occurrence time, the time when systems resilience returns to a new stable state after the second hazard, and the time when all nodes recover to normal state.

As shown in Fig. 9, different hazards’ impact on the multilayer infrastructure network have notable dynamic spatial features. Combined with disaster scenario in Fig. 7, it is easy to know the directly damaged infrastructures by the hazards at different times, and easy to identify the indirectly failed infrastructures. For example, comparing the figures at t = 1 and figures at t = 2 in Fig. 9, the number of infrastructures with damage probability larger than 0 are not only located in the area where hurricane occurs at t = 2. These infrastructures are failed due to their interdependence on the damaged infras- tructures. In Fig. 9(a), only a few infrastructures impacted by the flood directly are of darker color, and the failures do not spread through the whole multilayer infrastructure network. In Figs. 9(b)– (d), from t = 1 to t = 8, damage probabilities of

infrastructure components are the same, and the failures propagate with the hurricane path. From t = 9, the infrastructure performances in the last three rows of Fig. 9 begin to be different. In the case of a single hurricane, infrastructure component damage probabilities turn out to be smaller and smaller with restoration strategies beginning at t = 8. But for the multilayer infrastructure network subject to sequential hurricane and flood, their performances are worse at t = 19 than t = 13 after the flood impact whether there is in-between restoration or not.

Damage probabilities of infrastructure compo- nents under sequential hurricane and flood hazards are not always smaller or bigger than the sum of single hurricane and flood impacts in Fig. 9. After the end of both hazards at t = 19, the damage probability of almost all the infrastructures increases (nodes turn darker in Figs. 9(b) and (d)), not only the infrastruc- tures directly affected by the flood. In the power grid, electric transmission substations (red nodes) near the power generation stations affected directly by the flood are always more sensitive to flooding, which can be observed from the comparison of Figs. 9(b) and (d) at t = 19. The electric transmission substations far from the flood impacted areas, located in the south- western and northeastern parts of GTA, are always more robust to flooding. The results echo previous research on spatially localized impacts on interde- pendent networks (Berezin, Bashan, Danziger, Li, & Havlin, 2015). Also, the hub electric substations with more connections, such as the 500 kV substations and 230 kV substations linking with 115 kV substations, are more susceptible to the undirected influence. In the gas transmission network, there are two notable features at t = 19. One is that the number of dark blue nodes in Fig. 9(d) is larger than the number in Fig. 9(b), similar to the power grid. The other is that the 14 dark blue nodes in Fig. 9(d) are not localized but scattered throughout the network. The reason might be that the number of gas infrastructure ele- ments is small and not clustered in space. The only gas infrastructure elements impacted by flooding indirectly are the underwater pipelines from a gas meter station to the Portlands Energy Center (which is a 550-MW natural gas electrical generating station on the Toronto waterfront). This would increase the damage probability of the power plant and related substations. In the oil transmission network at t = 19 in Fig. 9(d), all the nodes are darker when compared to Fig. 9(b), though no direct flood impacts are present. All impacts on gas and oil transmission

1156 Kong, Simonovic, and Zhang

(a)

(b)

Fig. 9. Spatial physical performance of GTA three-layer energy infrastructure network under different hazard scenarios. (a) Components performance under the flood with one-phase restoration strategy starting at t = 7. (b) Components performance under the hurricane and flood with one-phase restoration strategy starting at t = 8. (c) Components performance under the sequential hurricane and flood with one-phase restoration strategy starting at t = 19. (d) Components performance under the sequential hurricane and flood with two-phase restoration strategy starting at t = 8 and t = 19, respectively.

networks are due to their dependence on electric power.

The restoration strategy and its implementation starting time also play an important role in infras- tructure components performance. It is worth noting that restoration strategies implemented with two

scenarios (sequential hurricane and flood without in-between restoration, and sequential hurricane and flood with in-between restoration) have the same system resilience maximum objective, boundary conditions, and algorithm. The only difference is the strategy implementation starting time. In Fig. 9(c),

Sequential Hazards Resilience of Interdependent Infrastructure System 1157

(c)

(d)

Fig. 9. Continued.

the restoration strategy implementation starts from t = 19 after all hazards end. In Fig. 9(d), the im- plementation is in two-stages starting after the end of each hazard. The first stage lasts from t = 8 to t = 12, and the second from t = 19 until all infras- tructure recovery. Comparison of Figs. 9(c) and (d) shows that (i) at t = 8 (when the flood starts), only

the directly affected Portlands Energy Center and connected substations damage probability increases; (ii) at t = 13, more nodes in Fig. 9(c) turn lighter than in Fig. 9(d); (iii) at t = 19 (when the flood ends) and t = 25, the difference between the two figures is more obvious: the damage probability of infrastructures with two-phase restoration strategy is

1158 Kong, Simonovic, and Zhang

Fig. 10. GTA three-layer infrastructure network dynamic physical resilience. pr is physical resilience of the GTA three-layer energy infras- tructure network. Blue line pr F −7 is physical resilience of GTA multilayer energy infrastructure network under the flood with one-phase restoration strategy starting at t = 7. Yellow line pr H−8 is physical resilience of GTA multilayer energy infrastructure network under the hurricane with one-phase restoration strategy starting at t = 8. Pink line pr H,F −19 is physical resilience of GTA multilayer energy infrastruc- ture network under sequential hurricane and flood with one-phase restoration strategy starting at t = 19. Green line pr H−8,F −19 is physical resilience of GTA multilayer energy infrastructure network under sequential hurricane and flood with two-phase restoration strategy with starting time at t = 8 and t = 19, respectively.

much smaller than that with one-phase restoration strategy.

6.2. Dynamic Infrastructure System Physical Resilience

The infrastructure system dynamic physical resilience subject to different hazards is shown in Fig. 10 for the multilayer infrastructure net- work structure, disaster scenario parameters, and simulation procedures that maximize the whole infrastructure system physical resilience.

According to Fig. 10, different from static re- silience, dynamic resilience fluctuates nonlinearly with the hazards occurrence, infrastructure interac- tion, and infrastructure restoration. Single-layer and multilayer infrastructure network physical resilience subject to multiple hazards is not equal to the sum of the single-hazard resilience. Infrastructure system

physical resilience to sequential hurricane and flood hazards with in-between restoration (from t = 8 to t = 12) pr H−8,F −19 (green line) is larger than the sum of single hurricane (blue line) and flood resilience (yel- low line): pr H−8 + pr F −7 − 1 before t = 13 for elec- tric transmission network, t = 13 for gas transmission network, t = 15 for oil transmission network, t = 14 for multilayer network, and smaller after that time.

Though subject to the same sequential hurricane and flood, single-layer and multilayer infrastructure network physical resilience are different due to the different start of restoration time. Generally, the earlier the start of restoration, the higher system resilience. According to Fig. 10, the infrastruc- ture system resilience with in-between restoration pr H−8,F −19 (green line) is always larger than the system resilience without in-between restoration pr H,F −19 (pink line). The in-between restora- tion not only influences system resilience during

Sequential Hazards Resilience of Interdependent Infrastructure System 1159

Fig. 11. Spatial functional impacts of GTA three-layer energy infrastructure network under different hazards scenarios. (a) Population impacted under the flood with one-phase restoration strategy starting at t = 7. (b) Population impacted under the hurricane with one-phase restoration strategy starting at t = 8. (c) Population impacted under the sequential hurricane and flood with one-phase restoration strategy starting at t = 19. (d) Population impacted under the sequential hurricane and flood with two-phase restoration strategy starting at t = 8 and t = 19, respectively.

corresponding repair time (from t = 8 to t = 12), but also impacts the follow-up system resilience (after t = 12). This is the positive effect of in- terdependence. Damage probabilities of repaired infrastructure decline and lead to the decline of damage probabilities of dependent infrastructure elements. The differences between the impacts of two restoration strategies are more obvious in the electric transmission network.

7. GTA ENERGY INFRASTRUCTURE SYSTEM FUNCTIONAL RESILIENCE

7.1. Infrastructure Functional Performance Spatial Analysis

The impacted population of each electric trans- mission substation supported area is used for analy- sis of spatial features of functional dynamic resilience (see Fig. 11). For comparison, the six time points for presentation of spatial functional resilience analyses are the same as those used in the analyses of physical resilience.

As shown in Fig. 11, the structural/physical im- portance of an infrastructure does not always keep in accord with its social influence. The impacted popu-

lation is larger in the GTA periphery than in central areas. This might be because substations located at the edge usually support a larger area and population than those in central areas.

In Fig. 11(a), the impacted population of all the areas is less than 100,000, as the flood only attacks several electric infrastructure elements and has little impact on the whole infrastructure system. In Figs. 11(b)–(d), from t = 1 to t = 8, the impacted pop- ulation in each area is nearly the same, and failures propagate also by the hurricane path. From t = 9, the impacted population in each area is different, and the flood impacts on population are more obvious, which echos the functional resilience curve decrease after the flood in Fig. 12. Comparing the difference between impacted population at t = 13 and t = 19 subject to sequential hurricane and flood (Figs. 11(c) and (d)), the flood impacted areas (blue color in Fig. 4) would not have a dramatic functional loss, but impacted population located at the edge areas increases sharply.

Time of implementation of restoration strategy also has a significant impact on system resilience. There are only two restoration strategies consid- ered in this work with the same system resilience maximization objective, boundary conditions, and

1160 Kong, Simonovic, and Zhang

Fig. 12. GTA electric transmission network dynamic functional and physical resilience. f r is functional resilience of GTA elec- tric transmission network. pr is physical resilience of GTA elec- tric transmission network. Dark blue line f r F −7 is functional re- silience of GTA electric transmission network under the flood with one-phase restoration strategy starting at t = 7. Light blue line pr F −7 is physical resilience of GTA electric transmission net- work under the flood with one-phase restoration strategy starting at t = 7. Dark yellow line f r H−8 is functional resilience of GTA electric transmission network under the hurricane with one-phase restoration strategy starting at t = 8. Light yellow line pr H−8 is physical resilience of GTA electric transmission network under the hurricane with one-phase restoration strategy starting at t = 8. Dark red line f r H,F −19 is functional resilience of GTA electric transmission network under sequential hurricane and flood with one-phase restoration strategy starting at t = 19. Light red line pr H,F −19 physical resilience of GTA electric transmission network under sequential hurricane and flood with one-phase restoration strategy starting at t = 19. Dark green line f r H−8,F −19 is func- tional resilience of GTA electric transmission network under se- quential hurricane and flood with two-phase restoration strategy with starting time at t = 8 and t = 19, respectively. Light green line pr H−8,F −19 is physical resilience of GTA electric transmission net- work under sequential hurricane and flood with two-phase restora- tion strategy with starting time at t = 8 and t = 19, respectively.

calculation algorithm—the only difference is in the strategy implementation starting time. In Fig. 11(c) the restoration strategy starts from t = 19 after all hazards end. In Fig. 11(d), a two-stage strategy is implemented after the end of each hazard. The first stage lasts from t = 8 to t = 12, and the second from t = 19 until all infrastructure recovery. Comparison of the impacted population at t = 25 of Figs. 11(c) and (d) shows that the latter, with in-between restoration, is smaller than the former, without in- between restoration. The reason for the difference could be that the interdependence among diverse in-

frastructures aggravates the failures and restoration effects.

7.2. Dynamic Infrastructure System Functional Resilience

GTA three-layer infrastructure network func- tional performance is measured by the ratio of electric transmission substation served population to the total population served. The system functional resilience shows the service recovery capacity of the multilayer infrastructure network. As electric energy is the most important for people, GTA power grid dynamic functional resilience is chosen to repre- sent the whole infrastructure system’s functional resilience. Based on the transmission substations’ damage probabilities and their supporting popu- lation, infrastructure system functional resilience is shown in Fig. 12. In the figure, dark color lines denote functional resilience, and light color lines denote physical resilience.

According to Fig. 12, functional resilience is always larger than the corresponding physical re- silience, and shows more obvious decrease after the second hazard. There are possibly two explanations for that. First is that multiple redundancy paths exist between electric transmission substations and power generating stations. Then some of the components experiencing physical failure would not experience the functional loss. Also, each component restora- tion might decrease the damage probability of sev- eral infrastructure elements. The two effects could be strengthened by the interdependence among infrastructure elements. The second reason could be unequal population and substation distributions. Though substation capacities are used as their weight to calculate the system resilience, the population they serve is usually not in proportion to their capacity.

Contrary to the physical resilience of the power grid subject to multiple hazards, its functional re- silience f r H,F (dark green line in Fig. 12) and f r H,( R),F (dark red line in Fig. 12) is always smaller than the sum of single hurricane and flood resilience ( f r H + f r F − 1; dark blue line and dark orange line in Fig. 12) before t = 6 subject to sequential hurricane and flood with in-between restoration, and before t = 12 subject to sequential hurricane and flood without in-between restoration.

The positive effects of restoration strategy are more obvious in functional resilience. Comparison of the functional resilience subject to sequential hurri- cane and flood without in-between restoration (light

Sequential Hazards Resilience of Interdependent Infrastructure System 1161

Fig. 13. Resilience profiles for different magnitude of hazards.

green line in Fig. 12) and functional resilience subject to sequential hurricane and flood with in-between restoration (light red line in Fig. 12) shows that the latter is always larger. Also, the difference be- tween functional resilience of multiple hazards is also larger than the corresponding physical resilience (dark green line and dark red line in Fig. 12).

GTA results show that the rapidity of all single- and three-layer networks is less than 36 time steps (72 hours). But the physical and functional resilience of single-layer and multilayer infrastructure net- works are not equal to, but approach the value of, 1 at t = 40 according to Figs. 7–10. This is because the resilience metric (Equation (4)) is an accumulative ratio of unaffected area to the expected area. It is not a measure of the system state, but of service capacity during a time period. Therefore, this ratio can be used to assess the system service provision capacity during a period of time, which is the basic meaning of resilience. This might be another reason for the

functional resilience being higher than the physical resilience in Fig. 12.

8. DISCUSSION

The multiple hazards spatiotemporal impacts on interdependent infrastructure system resilience are a complex process. The key reasons are interactions of infrastructure interdependences, combined impacts of single hazards, and diverse restoration strategies.

8.1. Single-Hazard Marginal Impacts The single-hazard impacts on physical and

functional resilience do not only depend on their spatiotemporal characteristics or relationships with other hazards, but also on the intensity of the hazard. According to Figs. 9 and 11, flooding of lower magnitude (affecting 10 nodes and edges) only increases the damage probability of infrastructure

1162 Kong, Simonovic, and Zhang

Fig. 14. Resilience profiles for different time interval of hazards.

located in, or near, the floodplain areas, although infrastructure interdependence is considered in the model. Similarly, there is a small decrease in the resilience curves in Figs. 10 and 12, especially in the electric transmission network and multilayer energy infrastructure network. The small size of gas and oil transmission networks is the reason for their more significant decrease in resilience after the flood.

The small marginal effects of the flood may be explained by the fact that: (i) the direct flood impacts on infrastructure components are small in Equation (9), that is, damage probabilities of infras- tructures subject to flooding are all smaller than 0.3 except two submarine transmission lines; (ii) there exist redundant paths connecting every load node with multiple source nodes (Fig. 5)—networks with more redundant topology structure would reduce the flood impacts, as the load nodes have a higher chance of connecting with a source node; and (iii) there is a slight increase of path efficiency.

The hurricane marginal effects are not as small as the flooding effects, as shown in Figs. 9(b) and

11(b), and by the red line in Figs. 10 and 12. Basi- cally, the magnitude of the hazard is the determining factor. The high gust wind speed through the whole GTA causes large infrastructure damage probability and, indeed, a sharp decrease of the resilience curves. Based on the Saffir-Simpson Hurricane Wind Scale, only hurricanes above category 3 (wind speed higher than 110 mph) usually cause flooding; category 5 is the highest category for hurricanes with wind speed 157 mph or higher. The hurricane list in Subsection 4.1 is with wind speed (ws ) of 120 mph, so we make the ws change from 110 mph to 160 mph with 10 mph as the interval. According to the record and available HAZUS data, the flood list in Subsection 4.1 is with the highest flood depth (more than 10 ft), so the mag- nitude of flood does not change. GTA three-layer energy infrastructure network resilience is simulated with only the hurricane wind speed changed and the other original values remain unchanged (Fig. 13).

According to Fig. 13, with the same spatiotem- poral relationships of sequential hurricane and flood, GTA three-layer energy infrastructure network

Sequential Hazards Resilience of Interdependent Infrastructure System 1163

Fig. 15. Resilience profiles for different spatial overlap area of hazards.

physical resilience and electric transmission network functional resilience change with the different mag- nitude of hurricane. The higher the wind speed, the lower is system resilience. Moreover, the higher the wind speed, the more significant the resilience de- crease. Meanwhile, the rule is more marked with functional resilience than physical resilience, as the distances between two adjacent lines in Figs. 13(c) and (d) are bigger than those in Figs. 13(a) and (b). Comparing Figs. 13(a) and (b), the two-phase restoration strategy is always better than the one- phase restoration strategy, especially in the situation with smaller wind speed, and so is the functional re- silience. In addition, resilience with wind speed of 110 mph is significantly bigger than the resilience with higher wind speed. The result is consistent with the fact that hurricanes with wind speed higher than 110 mph (category 3) are major hurricanes because of their potential for significant damage.

8.2. Cascading Failure and Recovery Effects

Infrastructure system restoration strategy is a complicated problem, and is getting more and more attention. The main reason is the cascading recovery effect as a consequence of infrastructure interdepen- dence, which is obvious in simulation results.

The slopes of multilayer infrastructure network resilience curves in Fig. 10 (dark blue and red lines) are always larger than 2 of 103 (number of restora- tion nodes/number of all nodes). As demonstrated in Fig. 10, all the single-layer and multilayer infras- tructure network resilience with two-phase restora- tion strategy are drastically higher than those with one-phase restoration strategy.

The cascading recovery effects in the electric transmission network are particularly apparent. The electric transmission network resilience curve with two-phase restoration strategy (red line in Fig. 10

1164 Kong, Simonovic, and Zhang

Fig. 16. Resilience profiles for different resource constraints.

and pink line in Fig. 12) drops a bit after the flood, but clearly shows a rising tendency. Since the flood impacts are small, cascading recovery effects are the main reason for this behavior.

Cascading recovery effects can also be illustrated from the temporal and spatial dimensions with the sensitive analysis of time interval and overlap area of hurricane and flood.

8.2.1. Sensitivity Analysis of Time Interval of Hazards

The temporal relationship of hazards are a tradi- tional and hot topic of multihazards resilience or risk analysis. Occurrence time order is always used to describe the temporal relationship of multihazards. However, the effects of time interval of hazards’ occurrence time on system resilience has never been analyzed. For the sequential hazards scenario list in Subsection 4.1, a 24-hour interval (12 time steps

in Figs. 9–12) exists between hurricane and flood occurrence time. As the fragility curves of individual infrastructure components under simultaneous hurricane and flood are not available, we set the time interval between hurricane and flood from 4 to 24 with four time steps as intervals. This means that the flood starts at t = 13, 17, 21, 25, 29, 33, and 37, respectively. Then one-phase restoration strategy starts at the end of the flood, two-phase restoration strategy starts at the end of the hurricane. GTA energy infrastructure network resilience is simulated with only the time interval between hurricane and flood being changed (Fig. 14).

According to Fig. 14, though the magnitude and impact areas of hurricane and flood are constant, GTA three-layer energy infrastructure network physical resilience and electric transmission network functional resilience change with the different time intervals between the two hazards. Comparing Figs. 14(a) and (b), the advantage of two-phase

Sequential Hazards Resilience of Interdependent Infrastructure System 1165

restoration becomes more and more obvious as the time interval increases. For the one-phase restoration strategy, physical and functional resilience both de- crease as the time interval increases. This is because of the failure cascading within the network. For the two-phase restoration strategy, physical and func- tional resilience both increase as the time interval increases. Though only two individual infrastructure components can be restored at each time step, the restoration cascading recovery effects of the first- phase restoration lead to quick resilience increase.

8.2.2. Sensitivity Analysis of Spatial Overlap of Hazards

The spatial relationship of hazards does not receive much attention and is always neglected in the existing research. For the distributed infrastructure system, hazards with different spatial relationship could impact different infrastructure components and cause distinct results. Area of overlap can be used to measure the spatial relationship of hazards. Here, we set the area of overlap of hurricane and flood in the disaster scenario in Subsection 4.1 as 1 (the area of blue areas in Fig. 7). Then we enlarged the radius of the area by a factor of 1, 2, 3, 4, and 5, respectively. GTA three-layer energy infrastructure network resilience is simulated with only the spatial overlap between hurricane and flood being changed (Fig. 15).

According to Fig. 15, though the magnitude and impact areas of hurricane and flood are constant, GTA three-layer energy infrastructure network re- silience changes with the different spatial overlap of the two hazards. The bigger the spatial overlap, the smaller the system resilience. Moreover, comparing Figs. 15(a) and (b), the bigger the spatial overlap, the smaller the difference between the physical resilience with one-phase restoration strategy and two-phase restoration strategy. In addition, the physical re- silience and functional resilience change not so much as the change of spatial overlap area. This is because the increased individual infrastructure components due to overlap area enlargement are more concen- trated. Even without the enlargement of overlap area, the damage probability of increased individual infrastructure components would be impacted by their near directly damaged individual infrastruc- ture components. Also, they could be impacted by their near infrastructures’ recovery. Besides, the flood attacking area takes a very small proportion of GTA area, even for the radius of the overlap

area of hazards scaled up to six times. Therefore, the small damage of infrastructures within similar spatial areas would not decrease system resilience dramatically.

It is worth noting that restoration strategy imple- mentation is aiming at multilayer network resilience maximization with a limit of two units of resources at one step. All the single-layer network resilience would be a bit smaller than the optimal ones.

8.3. Restoration Resource Limits

Disaster scenario, infrastructure system, and restoration strategy together shape the system resilience curve. Disaster is always force majeure, and infrastructure system cannot be changed during a short time. Restoration strategy is always deter- mined by the number of available resource. As the constraint for restoration strategy in the research, two units is the original value. Here, we simulate GTA three-layer energy infrastructure network re- silience with only the number of available resources changed (Fig. 16).

According to Fig. 16, GTA three-layer energy infrastructure network resilience changes with the different resource constraints. The more resources, the bigger is resilience. Moreover, the increase of resilience is slower with the resource increase. Based on the Figs. 16(a) and (b), the difference in re- silience with larger than four units of resource is not so obvious, and marginally decreases. Comparing Figs. 16(c) and (d), resilience with two-phase restora- tion strategy is significant bigger than resilience with one-phase restoration strategy. The difference is bigger when there are more resources available. So for the GTA energy infrastructure system, the num- ber of resources for four individual infrastructure components’ recovery during four hours is essential for resilience improvement.

In addition, with the same resource constraint, dynamic resilience would be different with a different recovery focus, such as maximizing resilience during the specific time period, speeding the system recov- ery to an acceptable level, or minimizing system soci- ety losses, etc.

9. CONCLUSION

Although multihazard analyses are commonly restricted to qualitative and semiquantitative ap- proaches, this article introduces a quantitative prob- abilistic multihazard resilience analysis method of

1166 Kong, Simonovic, and Zhang

an infrastructure system as an extension of resilience approaches to catastrophe risk management of in- frastructure systems. This method integrates infras- tructure interdependence, multihazard relationships, dynamic resilience metric, and restoration strategy model through network theory and simulation. It can be used not only to study multihazard resilience, but also multihazard risk analysis of systems-of-systems.

With the GTA energy infrastructure system case study, the simulation results show that the multi- hazard resilience is always different from the sum of single-hazard resilience. Infrastructure system resilience is sensitive to the hazard strength and choice of restoration strategy. Though cascading fail- ures could exacerbate impacts of single hazards, the cascading recovery effects could lower the impacts of hazards on system resilience. In the article, only a fixed amount of restoration resources are available, and assumed to have the same effectiveness in restoring different infrastructures. With sector-based operation and maintenance, a holistic method of optimal infrastructure system resilience provides for more systemic thinking and better choice of disaster recovery strategies at all levels (community, region or the country). So, the resilience model is highly recommended for planning and distribution of restoration resources.

Finally, actual infrastructure systems are of high complexity. The case study simplifies the real infras- tructure system structure and its failure propagation mechanism. However, it is very clear that the frame- work can be easily extended to evaluate system re- silience with more detailed infrastructure operation models. With the availability of more empirical data than what were available for this study, the method provided in this article can be more accurately veri- fied in future research.

ACKNOWLEDGMENTS

This research was supported by the Natural Sci- ences and Engineering Research Council of Canada (NSERC), the Institute of Catastrophic Loss Re- duction (ICLR), and funded by Chaucer PLC, the Natural Science Foundation of China under Grant 71704111.

REFERENCES

Aerts, J. C., Botzen, W. J., Emanuel, K., Lin, N., Moel, H. D., & Michel-kerjan, E. O. (2014). Evaluating flood resilience strate- gies for coastal megacities. Science, 344(6183), 473–475.

Ayyub, B. M. (2014). Systems resilience for multihazard environ- ments: Definition, metrics, and valuation for decision making. Risk Analysis, 34(2), 340–355.

Baroud, H., Barker, K., Ramirez-Marquez, J. E., & Rocco, C. M. (2015). Inherent costs and interdependent impacts of infras- tructure network resilience. Risk Analysis, 35(4), 642–662.

Baroud, H., Ramirez-Marquez, J. E., Barker, K., & Rocco, C. M. (2014). Stochastic measures of network resilience: Applications to waterway commodity flows. Risk Analysis, 34(7), 1317–1335.

Berezin, Y., Bashan, A., Danziger, M. M., Li, D., & Havlin, S. (2015). Localized attacks on spatially embedded net- works with dependencies. Scientific Reports, 5. https://doi.org/ 10.1038/srep08934

Bruneau, M., Chang, S., Eguchi, R., Lee, G., O’Rourke, T., Rein- horn, A., . . . Winterfeldt, D. V. (2003). A framework to quan- titatively assess and enhance the seismic resilience of commu- nities. Earthquake Spectra, 19, 733–752.

Buldyrev, S. V., Parshani, R., Paul, G., Stanley, H. E., & Havlin, S. (2010). Catastrophic cascade of failures in interdependent net- works. Nature, 464(7291), 1025–1028.

Canadian Association of Petroleum Producers (CAPP). (2014). Canadian Energy Pipeline Association liquids and natural gas pipelines maps [data file]. Retrieved from CAPP web- site: https://www.capp.ca/canadian-oil-and-natural-gas/infra structure-and-transportation/pipelines.

Canadian Census Analyser (CHASS). (2011). Canadian Cen- sus Data [data file]. Retrieved from CHASS website: https://dc.chass.utoronto.ca/census/.

Canadian Energy Pipeline Association (CEPA). (2014). About pipelines map [data file]. Retrieved from CEPA website: https://aboutpipelinesmap.com/#/.

Carpignano, A., Golia, E., Di Mauro, C., Bouchon, S., & Nordvik, J.-P. (2009). A methodological approach for the definition of multi-risk maps at regional level: First application. Journal of Risk Research, 12, 513–534.

Crucitti, P., Latora, V., & Marchiori, M. (2004). Model for cas- cading failures in complex networks. Physical Review E, 69(4). https://doi.org/10.1103/PhysRevE.69.045104

Cutter, S. L., Ahearn, J. A., Amadei, B., Crawford P., Eide E. A., & Galloway, G. E., . . . Zoback, M. L. (2013). Disaster re- silience: A national imperative. Environment Science & Policy for Sustainable Development, 55(2), 25–29.

Environment and Climate Change Canada (ECCCan). (2015). Hurricane Hazel [data file]. Retrieved from ECCCan web- site: https://www.ec.gc.ca/ouragans-hurricanes/default.asp?lang =En&n=4343267B-1.

Fang, Y., Pedroni, N., & Zio, E. (2015). Optimization of cascade- resilient electrical infrastructures and its validation by power flow modeling. Risk Analysis, 35(4), 594–607.

Federal Emergency Management Agency (FEMA). (2016). HAZUS-MH3.1. Retrieved from https://www.fema.gov/hazus- software.

Ganin, A. A., Massaro, E., Gutfraind, A., Steen, N., Keisler, J. M., Kott, A., . . . Linkov, I. (2016). Operational re- silience: Concepts, design and analysis. Scientific Reports, 6. https://doi.org/10.1038/srep19540

Gilbert, G. W. (2010). Disaster resilience: A guide to the literature. NIST Special Publication #1117. Retrieved Au- gust 2, 2016, from https://nvlpubs.nist.gov/nistpubs/Legacy/SP/ nistspecialpublication1117.pdf.

Gill, J. C., & Malamud, B. D. (2015). Reviewing and visualizing the interactions of natural hazards. Reviews of Geophysics, 52(4), 680–722.

Goh, K. I., Kahng, B., & Kim, D. (2001). Universal behavior of load distribution in scale-free networks. Physical Review Let- ters, 87(27). https://doi.org.10.1103/PhysRevLett.87.278701

Hausken, K., & He, F. (2014). On the effectiveness of secu- rity countermeasures for critical infrastructures. Risk Analysis, 36(4), 711–726.

Sequential Hazards Resilience of Interdependent Infrastructure System 1167

Hernandez-Fajardo, I., & Duenas-Osorio, L. (2013). Probabilistic study of cascading failures in complex interdependent; lifeline systems. Reliability Engineering & System Safety, 111(2), 260– 272.

Holling, C. S. (1973). Resilience and stability of ecological systems. Annual Review of Ecology & Systematics, 4(4), 1–23.

Hosseini, S., Barker, K., & Ramirez-Marquez, J. E. (2016). A re- view of definitions and measures of system resilience. Reliability Engineering & System Safety, 145, 47–61.

Hydro One Networks Inc. (2012). Transmission system: South- ern Ontario. Retrieved from https://www.hydroone.com/ RegulatoryAffairs/Documents/EB-2012-0031/Exhibit%20A/ A-07-01.pdf.

Johansson, J., & Hassel, H. (2010). An approach for modeling interdependent infrastructures in the context of vulnerability analysis. Reliability Engineering & System Safety, 95(12), 1335– 1344.

Kappes, M. S., Keiler, M., Elverfeldt, K. V., & Glade, T. (2012). Challenges of analyzing multi-hazard risk: A review. Natural Hazards, 64(2), 1925–1958.

Komendantova, N., Mrzyglocki, R., Mignan, A., Khazai, B., Wenzel, F., Patt, A., & Fleming, K. (2014). Multi-hazard and multi-risk decision-support tools as a part of participa- tory risk governance: Feedback from civil protection stake- holders. International Journal of Disaster Risk Reduction, 8, 50–67.

Larocca, S., Johansson, J., Hassel, H., & Guikema, S. (2015). Topological performance measures as surrogates for physical flow models for risk and vulnerability analysis for electric power systems. Risk Analysis, 35(4), 608–623.

Linkov, I., Bridges, T., Creutzig, F., Decker, J., Foxlent, C., Kröger, W., . . . Thiel-Clemen, T. (2015). Changing the resilience paradigm. Nature Climate Change, 4(6), 407– 409.

Liu, B., Siu, Y. L., & Mitchell, G. (2016). Hazard inter- action analysis for multi-hazard risk assessment: A sys- tematic classification based on hazard-forming environment. Natural Hazards and Earth System Sciences, 16(2), 629– 642.

Liu, H., Davidson, R. A., & Apanasovich, T. V. (2007). Statistical forecasting of electric power restoration times in hurricanes and ice storms. IEEE Transactions on Power Systems, 22(4), 2270– 2279.

Liu, Y., & Singh, C. (2011). A methodology for evaluation of hurricane impact on composite power system reliability. IEEE Transactions on Power Systems, 26(1), 145–152.

Motter, A. E., & Lai, Y. C. (2002). Cascade-based attacks on complex networks. Physical Review E, 66(2). https://doi. org/10.1103/PhysRevE.66.065102

Nan, C., & Sansavini, G. (2017). A quantitative method for as- sessing resilience of interdependent infrastructures. Reliability Engineering & System Safety, 157, 35–53.

Nateghi, R., Guikema, S. D., & Quiring, S. M. (2011). Comparison and validation of statistical methods for predicting power out- age durations in the event of hurricanes. Risk Analysis, 31(12), 1897–1906.

National Infrastructure Advisory Council (NIAC). (2009). Critical infrastructure resilience: Final report and recommen- dations. Retrieved from https://www.dhs.gov/sites/default/files/ publications/niac-critical-infrastructure-resilience-final-report- 09-08-09-508.pdf.

Natural Resources Canada (NRCan). (2014). Can- vec 50K ON Res MGT [data file]. Retrieved from Natural Resource Canada website: https://ftp.geogratis.gc.ca/pub/ nrcan_rncan/vector/canvec/fgdb/Res_MGT/.

Oddsdóttir, F., Lucas, B., & Combaz, É. (2013). Measuring disaster resilience. Retrieved from https://www.gsdrc.org/docs/ open/hdq1045.pdf.

Office of the Press Secretary of the White House. (2013). Presi- dential policy directive 21: Critical infrastructure security and re- silience. Retrieved from https://www.whitehouse.gov/the-press- office/2013/02/12/presidential-policy-directive-critical-infra- structure-security-and-resil.

Ouyang, M. (2014). Review on modeling and simulation of inter- dependent critical infrastructure systems. Reliability Engineer- ing & System Safety, 121(1), 43–60.

Ouyang, M., & Dueñas-Osorio, L. (2012). Time-dependent re- silience assessment and improvement of urban infrastructure systems. Chaos: An Interdisciplinary Journal of Nonlinear Sci- ence, 22(3). https://doi.org/10.1063/1.4737204

Ouyang, M., & Dueñas-Osorio, L. (2014). Multi-dimensional hur- ricane resilience assessment of electric power systems. Struc- tural Safety, 48, 15–24.

Ouyang, M., Dueñas-Osorio, L., & Min, X. (2012). A three-stage resilience analysis framework for urban infrastructure systems. Structural Safety, 36(2), 23–31.

Ouyang, M., Hong, L., Mao, Z., Yu, M, & Qi, F. (2009). A method- ological approach to analyze vulnerability of interdependent in- frastructures. Simulation Modelling Practice & Theory, 17(5), 817–828.

Ouyang, M., & Wang, Z. (2015). Resilience assessment of interde- pendent infrastructure systems: With a focus on joint restora- tion modeling and analysis. Reliability Engineering & System Safety, 141, 74–82.

Poljanšek, K., Bono, F., & Gutiérrez, E. (2012). Seismic risk as- sessment of interdependent critical infrastructure systems: The case of European gas and electricity networks. Earthquake En- gineering & Structural Dynamics, 41(1), 61–79.

Public Safety Canada (PSCan). (2015). The Canadian Dis- aster Database [data file]. Retrieved from PSCan website: https://www.publicsafety.gc.ca/cnt/rsrcs/cndn-dsstr-dtbs/index- eng.aspx.

Quanta Technology. (2008). Undergrounding assessment phase 3 final report: Ex ante cost and benefit modeling. Retrieved Au- gust 2, 2016, from https://woodpoles.org/portals/2/documents/ UndergroundingAssessment_P3.pdf.

Reed, D. A., Kapur, K. C., & Christie, R. D. (2009). Methodology for assessing the resilience of networked infrastructure. IEEE Systems Journal, 3(2), 174–180.

Reed, D., Wang, S., Kapur, K., & Zheng, C. (2016). Systems- based approach to interdependent electric power delivery and telecommunications infrastructure resilience subject to weather-related hazards. Journal of Structural Engineering, 142(8), C4015011.

Rogers, R., Aberson, S., Aksoy, A., Annane, B., Black, M., Cione, J., . . . Zhang, X. (2013). NOAA’s hurricane intensity forecast- ing experiment: A progress report. Bulletin of the American Me- teorological Society, 94(6), 859–882.

Scawthorn, C., Flores, P., Blais, N., Seligson, H., Tate, E., Chang, S., & Lawrence, M. (2006). HAZUS-MH flood loss estimation methodology. II. Damage and loss assessment. Natural Hazards Review, 7(2), 72–81.

Shinozuka, M., Chang, S. E., Cheng, T. C., Feng, M., O’Rourke, T. D., Saadeghvaziri, M. A., . . . Shi, P. (2004). Resilience of integrated power and water systems. In MCEER (Ed.), Research progress & accomplishments 2003–2004 (pp. 65–86). Retrieved August 2, 2016, from https://ubir.buffalo.edu/xmlui/handle/10477/631.

Simonovic, S. P. (2016). From flood risk management to quan- titative flood disaster resilience: A paradigm shift. Inter- national Journal of Safety and Security Engineering, 6(2), 85–95.

Simonovic, S. P., & Arunkumar, R. (2016a). Quantification of resilience to water scarcity, a dynamic measure in time and space. International Association of Hydrological Sciences, 373, 13–17.

1168 Kong, Simonovic, and Zhang

Simonovic, S. P., & Arunkumar, R. (2016b). Comparison of static and dynamic resilience for a multipurpose reservoir operation. Water Resources Research, 52(11), 8630–8649.

Simonovic, S. P., Peck, A., & Madani, K. (2013). Dynamic re- silience to climate change caused natural disasters in coastal megacities quantification framework. British Journal of Envi- ronment & Climate Change, 3(3), 378–401.

Suleimani, E., Hansen, R., & Haeussler, P. J. (2009). Numerical study of tsunami generated by multiple submarine slope fail- ures in Resurrection Bay, Alaska, during the M W, 9.2 1964 earthquake. Pure & Applied Geophysics, 166(1), 131–152.

Tam, J. (2015). Hurricane Hazel path [data file]. Re- trieved from ArcGIS website: https://www.arcgis.com/ home/item.html?id=871c5504798b4a62a45ab98348c72014.

The Independent Electricity System Operator (IESO). (2014). Map of Ontario’s electricity system [data file]. Retrieved from IESO website: https://www.ieso.ca/Power-Data/Supply- Overview/Ontario-System-Maps.

The Infrastructure Security Partnership. (2006). Regional disaster resilience: A guide for developing an action plan. Reston,VA: American Society of Civil Engineers.

The Saffir-Simpson Team. (2012). The Saffir-Simpson Hur- ricane Wind Scale. Retrieved from https://www.nhc.noaa. gov/pdf/sshws.pdf.

Toronto and Region Conservation Authority (TRCA). (2012). Flood plain mapping [data file]. Retrieved from TRCA web- site: https://trca.ca/conservation/flood-risk-management/flood- plain-management/.

Toronto and Region Conservation Authority (TRCA). (2014). City of Toronto emergency plan risk specific plan: Flooding. Retrieved from https://www1.toronto.ca/ city_of_toronto/office_of_emergency_management/files/pdf/ flood_rsp.pdf.

Willoughby, H. E. (2007). Forecasting hurricane intensity and im- pacts. Science, 315(5816), 1232–1233.

Winkler, J., Dueñas-Osorio, L., Stein, R., & Subramanian, D. (2010). Performance assessment of topologically diverse power systems subjected to hurricane events. Reliability Engineering & System Safety, 95(4), 323–336.

Zhang, C., Kong, J., & Simonovic, S. P. (2018). Modeling joint restoration strategies for interdependent infrastructure sys- tems. Plos One, 13(4), e0195727.

Zio, E. (2016). Challenges in the vulnerability and risk analysis of critical infrastructures. Reliability Engineering & System Safety, 152, 137–150.

Zobel, C. W. (2011). Representing perceived tradeoffs in defin- ing disaster resilience. Decision Support Systems, 50(2), 394– 403.