A dual redundant control system whose fault-tolerant policy is capable
of removing the failed controller is proposed. The heuristics of dete
cting failures of a controller and changing the time weight take the f
orm of a set of linguistic decision rules in fuzzy logic. This detecti
on method based on performance measure enables the detection of a fail
ed controller without relying on mathematical model and failure assump
tions. It can handle gradually degrading failures as well as catastrop
hic failures by introducing the concept of failure measure and time we
ight. The failed controller is smoothly removed by reducing the time w
eight of the failed controller.