Challenges for automated driving for humans and technology
Technological Issues:
sensing and interpreting environment
predicting behavior of other road users
safe and efficient decisions
Acceptance of customers:
concerns about safety, reliability, and loss of control
Provide proof of safety:
nearly impossible to validate the safety
large number of miles required
Approaches to provide proof of safety
Scenario Based Testing
Decomposition Approach
Road Categorization Approach
Modular Safety Approval
Silent Testing
Scenario Based Testing (SBT)
identify critical situations to reduce testing effort
addition to SBT
identify test cases from relevant scenarios
combine redundand cases
identify requirements for each road
group road sections with similar requirements
compare requirements and capabilities
focus on microscopic requirements
Behavioral Safety
Current Validation Processes
General Approach:
Analysis funds on assumtions and simplifications
impact on behavior is unknown
ISO 26262: functional safety on system level
Defining Particular Pass-/Fail-Criteria
Change of one module doesn’t require verification of other modules
Driver drives in real world with active perception
automation runs in parallel, not controlling actuators
Behavior Semantic Scenery Description (BSSD)
Demands based on scenery and traffic rules
Requirements:
Description must represent behavior space of motor vehicle
behavior description must be semantic
description must be the same for different scenery sections with same behavior requirement
Example:
Boundaries
Reservation / Priority
Where do priority participants come from?
Speed Limit
Overtake permission
System Theoretic Process Analysis (STPA)
Each interface in control circuit sends control actions
Identify unsafe control actions by defining hazards due to
▪ Not providing control action
▪ Providing control action
▪ Incorrect Timing / Order
▪ Control Action stopped too soon / applied too long
Fault tree analysis
Analyze Fault by breaking down violation into possible faults
Safety Goal Violation
Causal Factors on different levels
Causal Factors on Modular Level
Risk Evaluation
Risk must not be higher than the status quo
Approval Trap
More testing km needed than possible
Last changeda year ago