Goto

Collaborating Authors

 safety concept


Safety integrity framework for automated driving

arXiv.org Artificial Intelligence

This paper describes the comprehensive safety framework th at underpinned the development, release process, and regulatory approval of BMW's first SAE Level 3 Au tomated Driving System. The framework combines established qualitative and quantitative me thods from the fields of Systems Engineering, Engineering Risk Analysis, Bayesian Data Analysis, Design of Experiments, and Statistical Learning in a novel manner. The approach systematically minimizes the r isks associated with hardware and software faults, performance limitations, and insufficient specifica tions to an acceptable level that achieves a Positive Risk Balance. At the core of the framework is the system atic identification and quantification of uncertainties associated with hazard scenarios and the red undantly designed system based on designed experiments, field data, and expert knowledge. The residual risk of the system is then estimated through Stochastic Simulation and evaluated by Sensitivity Analys is. By integrating these advanced analytical techniques into the V-Model, the framework fulfills, unifies, and complements existing automotive safety standards. It therefore provides a comprehensive, rigorou s, and transparent safety assurance process for the development and deployment of Automated Driving System s.


Connected Dependability Cage Approach for Safe Automated Driving

arXiv.org Artificial Intelligence

Automated driving systems can be helpful in a wide range of societal challenges, e.g., mobility-on-demand and transportation logistics for last-mile delivery, by aiding the vehicle driver or taking over the responsibility for the dynamic driving task partially or completely. Ensuring the safety of automated driving systems is no trivial task, even more so for those systems of SAE Level 3 or above. To achieve this, mechanisms are needed that can continuously monitor the system's operating conditions, also denoted as the system's operational design domain. This paper presents a safety concept for automated driving systems which uses a combination of onboard runtime monitoring via connected dependability cage and off-board runtime monitoring via a remote command control center, to continuously monitor the system's ODD. On one side, the connected dependability cage fulfills a double functionality: (1) to monitor continuously the operational design domain of the automated driving system, and (2) to transfer the responsibility in a smooth and safe manner between the automated driving system and the off-board remote safety driver, who is present in the remote command control center. On the other side, the remote command control center enables the remote safety driver the monitoring and takeover of the vehicle's control. We evaluate our safety concept for automated driving systems in a lab environment and on a test field track and report on results and lessons learned.


Learning Autonomous Vehicle Safety Concepts from Demonstrations

arXiv.org Artificial Intelligence

Abstract-- Evaluating the safety of an autonomous vehicle (AV) depends on the behavior of surrounding agents which can be heavily influenced by factors such as environmental context and informally-defined driving etiquette. A key challenge is in determining a minimum set of assumptions on what constitutes reasonable foreseeable behaviors of other road users for the development of AV safety models and techniques. In this paper, we propose a data-driven AV safety design methodology that first learns "reasonable" behavioral assumptions from data, and then synthesizes an AV safety concept using these Figure 1: Evaluating the safety of an autonomous vehicle (AV) learned behavioral assumptions. We borrow techniques from depends on what constitutes as reasonable foreseeable behaviors of control theory, namely high order control barrier functions other road users. For example, determining whether the autonomous and Hamilton-Jacobi reachability, to provide inductive bias car (blue) is currently in a safe state depends on how the human to aid interpretability, verifiability, and tractability of our driver (red) may behave (e.g., speed up or swerve away).