As the complexity of autonomous vehicles(AVs)continues to increase and artificial intelligence algorithms are becoming increasingly ubiquitous,a novel safety concern known as the safety of the intended functionality(S...As the complexity of autonomous vehicles(AVs)continues to increase and artificial intelligence algorithms are becoming increasingly ubiquitous,a novel safety concern known as the safety of the intended functionality(SOTIF)has emerged,presenting significant challenges to the widespread deployment of AVs.SOTIF focuses on issues arising from the functional insufficiencies of the AVs’intended functionality or its implementation,apart from conventional safety considerations.From the systems engineering standpoint,this study offers a comprehensive exploration of the SOTIF landscape by reviewing academic research,practical activities,challenges,and perspectives across the development,verification,validation,and operation phases.Academic research encompasses system-level SOTIF studies and algorithm-related SOTIF issues and solutions.Moreover,it encapsulates practical SOTIF activities undertaken by corporations,government entities,and academic institutions spanning international and Chinese contexts,focusing on the overarching methodologies and practices in different phases.Finally,the paper presents future challenges and outlook pertaining to the development,verification,validation,and operation phases,motivating stakeholders to address the remaining obstacles and challenges.展开更多
现有高级辅助驾驶系统(Advanced Driver Assistance Systems,ADAS)功能不断增多且系统复杂性不断提高,不可避免带来了预期功能安全(Safety of the Intended Functionality,SOTIF)问题。触发条件的识别与生成是预期功能安全活动中重要的...现有高级辅助驾驶系统(Advanced Driver Assistance Systems,ADAS)功能不断增多且系统复杂性不断提高,不可避免带来了预期功能安全(Safety of the Intended Functionality,SOTIF)问题。触发条件的识别与生成是预期功能安全活动中重要的一环,然而现有对触发条件识别仅借助系统过程理论分析方法(System Theoretic Process Analysis,STPA)进行分析,未充分考虑系统功能状态转换中存在的问题。本文以知识驱动的方式构建触发条件识别机制,将STPA及有限状态机(Finite State Machine,FSM)理论融合构建拓展型系统控制结构,针对拓展型控制架构及功能状态转换进行安全分析,根据系统存在的功能局限及人为误用,完成触发条件的识别、生成、规范化描述、分类及标签化。最后将本文提出的触发条件生成机制应用于集成式巡航辅助系统(Integrated Cruise Assistance,ICA),得到了该系统的触发条件及其分类,并将本文所提出的生成机制与现有相关触发条件生成方法进行对比分析,证明了本机制的实用性、可行性及有效性。展开更多
基于系统理论过程分析(system theory process analysis,STPA),提出了一种面向高等级自动驾驶决策系统的安全性开发方法。该方法应用在一个城市自动驾驶决策系统的原型开发阶段,通过安全分析得到系统的70个不安全控制行为。针对其中3个...基于系统理论过程分析(system theory process analysis,STPA),提出了一种面向高等级自动驾驶决策系统的安全性开发方法。该方法应用在一个城市自动驾驶决策系统的原型开发阶段,通过安全分析得到系统的70个不安全控制行为。针对其中3个功能状态,分析得到10个不安全控制行为原因,提出9个安全策略。应用其中一个典型安全策略进行系统改进,通过仿真试验对其进行了验证。试验结果表明,基于所提出方法设计的安全策略有效可行,提出的方法能够提高自动驾驶决策系统的安全性。展开更多
基金supported by the National Science Foundation of China Project(52072215,U1964203,52242213,and 52221005)National Key Research and Development(R&D)Program of China(2022YFB2503003)State Key Laboratory of Intelligent Green Vehicle and Mobility。
文摘As the complexity of autonomous vehicles(AVs)continues to increase and artificial intelligence algorithms are becoming increasingly ubiquitous,a novel safety concern known as the safety of the intended functionality(SOTIF)has emerged,presenting significant challenges to the widespread deployment of AVs.SOTIF focuses on issues arising from the functional insufficiencies of the AVs’intended functionality or its implementation,apart from conventional safety considerations.From the systems engineering standpoint,this study offers a comprehensive exploration of the SOTIF landscape by reviewing academic research,practical activities,challenges,and perspectives across the development,verification,validation,and operation phases.Academic research encompasses system-level SOTIF studies and algorithm-related SOTIF issues and solutions.Moreover,it encapsulates practical SOTIF activities undertaken by corporations,government entities,and academic institutions spanning international and Chinese contexts,focusing on the overarching methodologies and practices in different phases.Finally,the paper presents future challenges and outlook pertaining to the development,verification,validation,and operation phases,motivating stakeholders to address the remaining obstacles and challenges.
文摘现有高级辅助驾驶系统(Advanced Driver Assistance Systems,ADAS)功能不断增多且系统复杂性不断提高,不可避免带来了预期功能安全(Safety of the Intended Functionality,SOTIF)问题。触发条件的识别与生成是预期功能安全活动中重要的一环,然而现有对触发条件识别仅借助系统过程理论分析方法(System Theoretic Process Analysis,STPA)进行分析,未充分考虑系统功能状态转换中存在的问题。本文以知识驱动的方式构建触发条件识别机制,将STPA及有限状态机(Finite State Machine,FSM)理论融合构建拓展型系统控制结构,针对拓展型控制架构及功能状态转换进行安全分析,根据系统存在的功能局限及人为误用,完成触发条件的识别、生成、规范化描述、分类及标签化。最后将本文提出的触发条件生成机制应用于集成式巡航辅助系统(Integrated Cruise Assistance,ICA),得到了该系统的触发条件及其分类,并将本文所提出的生成机制与现有相关触发条件生成方法进行对比分析,证明了本机制的实用性、可行性及有效性。
文摘基于系统理论过程分析(system theory process analysis,STPA),提出了一种面向高等级自动驾驶决策系统的安全性开发方法。该方法应用在一个城市自动驾驶决策系统的原型开发阶段,通过安全分析得到系统的70个不安全控制行为。针对其中3个功能状态,分析得到10个不安全控制行为原因,提出9个安全策略。应用其中一个典型安全策略进行系统改进,通过仿真试验对其进行了验证。试验结果表明,基于所提出方法设计的安全策略有效可行,提出的方法能够提高自动驾驶决策系统的安全性。