Drive-by-wire chassis safety guarantee method and device, electronic equipment and readable storage medium
By fusion of multi-class sensor data of the wire-controlled chassis system and multi-modal abnormality detection, combined with the safety control strategy of the redundant actuator system, the safety and reliability problems of traditional wire-controlled chassis systems under complex operating conditions are solved, and higher system reliability and safety are achieved.
Patent Information
- Application Number
- CN202510462394.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-14
- Publication Date
- 2025-06-27
AI Technical Summary
Traditional wire-controlled chassis systems are prone to functional failure due to sensor drift, communication interruption or multiple faults in complex operating conditions, and lack of safety and reliability.
By obtaining data of multiple types of vehicle sensor data for data fusion, multi-modal abnormality detection, generating fault detection results, and determining different levels of safety control strategies based on the results to control the redundant actuator system of the wire-controlled chassis.
It effectively improves the reliability and safety of the wire-controlled chassis in complex scenarios, ensuring that the vehicle can still maintain high-precision perception and safe operation in multiple failures.
Smart Images

Figure CN120207363A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the technical field of vehicle-by-wire chassis, and particularly to a method, device, electronic device and readable storage medium for ensuring the safety of a vehicle-by-wire chassis. Background Art
[0002] As a core enabling technology for autonomous driving, the vehicle-by-wire chassis is gradually changing the technical framework and market pattern of the automotive industry. By replacing traditional mechanical connections and hydraulic systems with electronic signals, the vehicle-by-wire chassis technology enables the control of the core systems of the vehicle chassis.
[0003] The core of the vehicle-by-wire chassis lies in converting the driver's operations (such as steering, braking, accelerating, etc.) into electronic signals, which are processed by an Electronic Control Unit (ECU) and transmitted to each actuator to achieve more precise and responsive vehicle control.
[0004] As the core execution system of autonomous vehicles, the safety and reliability of the vehicle-by-wire chassis are directly related to the driving safety of the vehicle. However, in complex working conditions, traditional vehicle-by-wire chassis systems are prone to functional failures due to sensor drift, communication interruption or multiple faults occurring simultaneously. Summary of the Invention
[0005] In view of this, one or more embodiments of the present disclosure provide a method, device, electronic device and readable storage medium for ensuring the safety of a vehicle-by-wire chassis, which can effectively improve the reliability and safety of the vehicle-by-wire chassis in complex scenarios.
[0006] On the one hand, the present disclosure provides a method for ensuring the safety of a vehicle-by-wire chassis, the method comprising: acquiring multi-class vehicle sensor data, performing data fusion to generate fused data; based on the fused data, performing multi-modal anomaly detection to generate a fault detection result, the fault detection result including a fault type and a fault confidence level; determining different levels of safety control strategies according to the fault detection result; and controlling the redundant actuator system of the vehicle-by-wire chassis according to the safety control strategy.
[0007] On the other hand, the present disclosure also provides a device for ensuring the safety of a vehicle-by-wire chassis, the device comprising: a data acquisition unit for acquiring multi-class vehicle sensor data, performing data fusion to generate fused data; a fault diagnosis unit for performing multi-modal anomaly detection based on the fused data to generate a fault detection result, the fault detection result including a fault type and a fault confidence level; a control arbitration unit for determining different levels of safety control strategies according to the fault detection result; and a safety control unit for controlling the redundant actuator system of the vehicle-by-wire chassis according to the safety control strategy.
[0008] On the other hand, the present disclosure also provides an electronic device, which includes a memory and a processor. The memory is used to store a computer program, and when the computer program is executed by the processor, the above-mentioned wire-controlled chassis safety guarantee method is implemented.
[0009] On the other hand, the present disclosure also provides a computer-readable storage medium, which is used to store a computer program, and when the computer program is executed by a processor, the above-mentioned wire-controlled chassis safety guarantee method is implemented.
[0010] The technical solutions provided by one or more embodiments of the present disclosure can ensure the high-precision perception ability of the vehicle and its wire-controlled chassis even when a single or some sensors fail by obtaining multi-type vehicle sensor data. Based on the fused data, multi-modal fault detection can be performed to accurately identify various types of vehicle fault problems. According to the fault detection results, different levels of safety control strategies can be determined for the wire-controlled chassis, and multiple safety guarantee solutions can be provided for vehicle operation. The redundant actuator system of the wire-controlled chassis ensures that different levels of safety control strategies can be effectively executed, improving the safety and reliability of the wire-controlled chassis. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] The features and advantages of the embodiments of the present disclosure will be more clearly understood by referring to the accompanying drawings. The drawings are schematic and should not be construed as imposing any limitation on the present disclosure. In the drawings:
[0012] Figure 1 A schematic diagram of the steps of the wire-controlled chassis safety guarantee method in one embodiment of the present disclosure is shown;
[0013] Figure 2 A schematic diagram of the flow of the federated Kalman filter algorithm in one embodiment of the present disclosure is shown;
[0014] Figure 3 A schematic diagram of the structure of the temporal convolutional network model in one embodiment of the present disclosure is shown;
[0015] Figure 4 A schematic diagram of the trigger process of different levels of safety control strategies in one embodiment of the present disclosure is shown;
[0016] Figure 5 A schematic diagram of the functional modules of the wire-controlled chassis safety guarantee device in one embodiment of the present disclosure is shown;
[0017] Figure 6 A schematic diagram of the structure of the electronic device in one embodiment of the present disclosure is shown. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0018] To make the objectives, technical solutions, and advantages of the embodiments of the present disclosure clearer, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present disclosure. Apparently, the described embodiments are some, but not all, of the embodiments of the present disclosure. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present disclosure without creative efforts shall fall within the protection scope of the present disclosure.
[0019] Please refer to Figure 1 , a wire-controlled chassis safety guarantee method provided by an embodiment of the present disclosure may include the following multiple steps.
[0020] S1: Obtain multi-class vehicle sensor data, perform data fusion, and generate fusion data.
[0021] In this embodiment, the vehicle may integrate multiple types of sensors (including IMU, wheel speed sensors, lidar, cameras, etc.), which can form sensor heterogeneous redundancy. Even if a single or some sensors fail, the high-precision perception ability of the vehicle and the vehicle's wire control system can still be maintained through cross-verification of vehicle sensor data and intelligent compensation algorithms. The multi-class vehicle sensor data can be collected in chronological order.
[0022] In a practical application example, three groups of IMUs (Inertial Measuring Unit) can be arranged and installed at the front, middle, and rear of the wire-controlled chassis respectively. The sampling frequency of the IMU can be set to 200Hz; dual-redundant wheel speed sensors can be arranged, adopting a heterogeneous design of magnetoelectric and Hall types respectively to avoid common cause failures of the same type of wheel speed sensors; a group of optical steering angle sensors with a resolution of up to 0.1° can also be arranged, and its anti-electromagnetic interference ability can be better than that of traditional potentiometer sensors.
[0023] It should be noted that most of the sensors in this embodiment can adopt redundant design and heterogeneous design to ensure the effectiveness of vehicle sensor data. Since the optical steering angle sensor has strong anti-interference ability and low failure rate, redundant design can be considered not to be carried out to reduce costs. Moreover, the steering angle information of the optical steering angle sensor can be cross-verified through sensors such as IMU and wheel speed to achieve soft redundancy, which is also one of the considerations for not carrying out hardware redundant design for it.
[0024] In this embodiment, various vehicle sensor data can be fused through a data fusion algorithm, such as the Federated Fusion Algorithm, so as to improve the subsequent data processing efficiency and fault detection efficiency.
[0025] In some embodiments, the federated Kalman filter algorithm can be adopted to perform weighted fusion on multi-class vehicle sensor data. The fusion weights can be determined according to the real-time confidence of the vehicle sensor data.
[0026] By adopting the federated Kalman filter algorithm, during the data fusion process, the accuracy, signal-to-noise ratio, and delay characteristics of various sensors can be comprehensively considered to optimize the allocation of fusion weights, thereby enhancing the adaptability and response speed to various sudden faults in the by-wire chassis system. The federated Kalman filter is a distributed filtering framework. A Kalman filter is run for each sensor or sensor subsystem to process and estimate local data. Then, these local estimation results are integrated through weighted averaging or other fusion methods to obtain a more accurate global estimate.
[0027] In a practical application example, the fusion weights of the federated Kalman filter algorithm are determined by the following formula:
[0028]
[0029] Where, is the error variance of the i-th sensor at time k, and this error variance can be calculated in real time by the sliding window method. n is the total number of sensors participating in data fusion, and W i,k is the fusion weight of the i-th sensor.
[0030] In a practical application example, please refer to Figure 2 , the process of fusing multi-class vehicle sensor data using the federated Kalman filter algorithm can include: obtaining the original vehicle sensor data; calculating the real-time variance of each vehicle sensor data; dynamically allocating weights for each vehicle sensor data according to the real-time variance; and using the dynamically allocated fusion weights to perform weighted fusion on multi-class vehicle sensor data.
[0031] S2: Based on the fusion data, perform multi-modal anomaly detection to generate a fault detection result, where the fault detection result includes a fault type and a fault confidence level.
[0032] In this embodiment, based on the fusion data, multi-modal fault detection can be performed to accurately identify various types of vehicle fault problems and by-wire chassis system fault problems. Multi-modal fault detection can be achieved through one or more techniques such as machine learning, deep learning, signal processing, and fault tree analysis. The fault confidence level in the fault detection result can indicate the possibility of each fault occurring, and the value can range from 0 to 1. In particular, a fault confidence level of 0 means completely uncertain, that is, there is no evidence indicating the existence of a certain fault; a fault confidence level of 1 means completely certain, that is, there is sufficient evidence indicating the existence of a certain fault.
[0033] In some embodiments, a Temporal Convolutional Network (TCN) model can be utilized to perform multi-modal anomaly detection on the fused data. The TCN model can include multiple dilated convolutional layers. The dilation coefficients of the multiple dilated convolutional layers can grow exponentially. The number of output channels of each dilated convolutional layer can be equal.
[0034] Specifically, introducing an intelligent fault detection model based on the Temporal Convolutional Network can achieve efficient and low-latency fault prediction and identification. The Temporal Convolutional Network can learn temporal features based on historical data, quickly classify potential fault patterns, and combine an adaptive anomaly threshold adjustment mechanism to dynamically optimize the detection strategy and reduce false alarms and missed detections. Compared with traditional rule-based threshold detection methods, using the TCN model for multi-modal anomaly detection can more accurately identify complex and multi-modal faults, improve the detection accuracy, and reduce the misjudgment rate.
[0035] One of the core features of the Temporal Convolutional Network is Dilated Convolution. The dilation coefficient of the dilated convolution determines the interval between each element in the convolutional kernel of the Temporal Convolutional Network. For example, when the dilation coefficient is 1, the elements in the convolutional kernel are continuous; when the dilation coefficient is 2, there is a gap of one position between the elements in the convolutional kernel. In the Temporal Convolutional Network of this embodiment, the dilation coefficient can be set to grow exponentially (such as 1, 2, 4, 8), which can gradually expand the receptive field of the network. On the basis of not increasing too much computational complexity, the Temporal Convolutional Network can capture feature dependencies within a longer time range.
[0036] The number of output channels of each dilated convolutional layer is equal, which can maintain the network structure consistency of the Temporal Convolutional Network, facilitating design and implementation. At the same time, fixing the number of channels also helps with the number of parameters and computational complexity of the Temporal Convolutional Network model, avoiding overfitting caused by too many channels.
[0037] The Temporal Convolutional Network can output the fault confidence through the Sigmoid activation function and classify the fault types (such as sensor failure, actuator jamming, etc.).
[0038] In a practical application example, the TCN model includes 4 dilated convolutional layers with dilation coefficients of 1, 2, 4, and 8 respectively, and the number of output channels of each dilated convolutional layer is 64.
[0039] In a practical application example, please refer to Figure 3, the convolutional kernel of a temporal convolutional network model has a size of 3 and includes 3 dilated convolutional layers. The dilation coefficients of each dilated convolutional layer are 1, 2, and 4 respectively, and the number of output channels of each dilated convolutional layer is 64. This temporal convolutional network model can process the fused data of three channels simultaneously in each operation, and the fused data of each channel can contain 64 time steps of data volume.
[0040] In some embodiments, a fixed-point quantization method can be adopted to train the temporal convolutional network model. In this way, the computational efficiency of the temporal convolutional network model on some embedded systems (such as FPGA) can be improved. Preferably, an 8-bit fixed-point quantization method (linearly mapping floating-point values to the 8-bit integer range through a scaling factor and a zero point) is used to train the temporal convolutional network model to compress the model's computational amount, so that the inference latency of this temporal convolutional network model running on FPGA can be less than 2 ms.
[0041] In some actual application scenarios, to reduce the computational amount and improve the inference speed, the temporal convolutional network model can also be pruned and optimized and lightweight deployed. For example, 50% channel pruning is performed on the temporal convolutional network model to reduce redundant calculations and improve the operating efficiency on embedded systems. Another example is that by combining with the NEON instruction set of ARM Cortex-A55, lightweight deployment of the temporal convolutional network model can accelerate the matrix calculations involved in the model and reduce the inference time by 30%.
[0042] In some embodiments, data augmentation can be performed on the fused data to simulate various fault scenarios and obtain sample fault data. Using the sample fault data, the temporal convolutional network model can be trained or optimized to improve the model's robustness. Data augmentation of the fused data includes, but is not limited to, simulating signal loss, signal drift, and noise mutation. For example, randomly deleting some time step data to simulate a sudden interruption of the sensor; adding linear / nonlinear offsets (such as slow cumulative deviation) to simulate sensor aging or temperature drift; superimposing Gaussian noise (steady interference) or impulse noise (burst spikes) to simulate environmental interference; data truncation to simulate communication packet loss; temporal misalignment to simulate clock asynchronization; range overrun to simulate sensor saturation.
[0043] In some embodiments, the temporal convolutional network model can also perform online learning and adaptive update. For example, adopting a sliding window mechanism to update the model parameters every 1000 samples; based on an unsupervised learning-based adaptive tuning method (such as PCA dimensionality reduction and clustering analysis), dynamically adjusting the anomaly detection threshold of the model; combining with the vehicle's historical data to autonomously adjust the fault discrimination criteria of the model in different environments (such as rainy days, ice and snow roads).
[0044] S3: Determine different levels of safety control strategies according to the fault detection results.
[0045] In this embodiment, according to the fault detection result, different levels of safety control strategies can be determined for the by-wire chassis, and multiple safety guarantee schemes can be flexibly provided for the by-wire chassis. For example, when a minor fault (such as sensor drift) is detected, the safety control strategy can be to automatically perform software compensation on the processed data of the by-wire chassis system; when the detected fault intensifies (such as actuator abnormality), the safety control strategy can be to trigger the backup actuator in the redundant actuator system to perform seamless switching between actuators to ensure that the vehicle can still drive safely; in the case of a serious fault (such as the failure of the core braking system), the safety control strategy can be to enter the emergency fault tolerance mode, take active degradation measures on the by-wire chassis system, or make an emergency stop to ensure driving safety.
[0046] In some embodiments, according to the fault type and the fault confidence level, a fault item and the item confidence level corresponding to each fault item are determined; based on the fault item and the item confidence level, a health score of the by-wire chassis is determined; according to the comparison result between the health score and multiple health thresholds, different levels of the safety control strategy are determined.
[0047] When a fault occurs in the by-wire chassis system or the vehicle body, according to the health score, a quantitative evaluation criterion for the dangerous scenario can be provided, which is beneficial to implementing appropriate safety control strategies. The specific implementation of the health score can be achieved through a preset calculation formula or a calculation model.
[0048] In a practical application example, the scoring mechanism of a health score calculation model is implemented through the following formula.
[0049]
[0050] Among them, Health Score is the health score, C f,i is the confidence level of different fault modes, ω i is the corresponding weight of different fault modes, and the weight value is set according to the actual influence degree of each type of fault mode. In particular, the weights of various fault modes can be set to be the same, and the health score can be simplified into the following form.
[0051]
[0052] In some embodiments, if the health score is less than or equal to the first threshold and greater than the second threshold, a first-level fault tolerance strategy is triggered, and the first-level fault tolerance strategy is used to reduce the system power of the current actuator system. In this scenario, it can indicate that there is a minor abnormality in the by-wire chassis system, and relevant personnel can be warned, and some operations such as speed limiting, power reduction, and software compensation data can also be performed on the actuator.
[0053] In some embodiments, if the health score is less than or equal to a second threshold and greater than a third threshold, a secondary fault tolerance strategy is triggered, and the secondary fault tolerance strategy is used to activate the backup actuator system. In this scenario, it can indicate that there is an obvious abnormality in the drive-by-wire chassis system, and it is necessary to activate the backup actuator in the redundant actuator system (for example, switch from the main steering motor to the standby motor).
[0054] In some embodiments, if the health score is less than or equal to the third threshold, a tertiary fault tolerance strategy is triggered, and the tertiary fault tolerance strategy is used to force a safe stop. In this scenario, it can indicate that there is a serious fault in the drive-by-wire chassis system, and the backup actuator of the redundant actuator system may also malfunction, and it is necessary to enter the forced stop operation in the safe mode.
[0055] It should be noted that the above first threshold is obviously greater than the second threshold, and the second threshold is obviously greater than the third threshold. In addition, the safety control strategy may not be limited to a three-level arrangement. In some application scenarios with tight computing resources and device resources, only a two-level safety control strategy may be arranged. And in application scenarios with abundant computing resources and device resources, a safety control strategy of four levels or more may be arranged. When the level of the safety control strategy is not three levels, multiple threshold trigger intervals need to be set accordingly.
[0056] In a practical application example, please refer to Figure 4 , the first threshold can be taken as 0.8, the second threshold can be taken as 0.5, and the third threshold can be taken as 0.3. When the health score is between 0.5 and 0.8, a primary fault tolerance strategy is triggered to indicate speed limitation of the current actuator; when the health score is between 0.3 and 0.5, a secondary fault tolerance strategy is triggered to indicate activation of the backup actuator; when the health score is below 0.3, a tertiary fault tolerance strategy is triggered to indicate forced safe stop.
[0057] S4: Control the redundant actuator system of the drive-by-wire chassis according to the safety control strategy.
[0058] In this embodiment, the construction of the redundant actuator system ensures that different levels of safety control strategies can be effectively executed, improving the safety and reliability of the steer-by-wire chassis, and thus ensuring vehicle safety and passenger safety. The redundant actuator system may include a redundant electro-hydraulic braking system, which is mainly used for vehicle deceleration and stopping. The redundant actuator system may include a redundant steer-by-wire system, which mainly realizes wheel steering. The redundant actuator system may include a redundant drive-by-wire system, which is mainly used to control the power output of the vehicle. The redundant actuator system may include a redundant electronically controlled suspension system, which mainly provides better vehicle stability and a more comfortable riding experience. The redundant actuator system may have redundant deployment of the throttle pedal actuator and the Electric Parking Brake (EPB).
[0059] In a practical application example, under the instruction of the safety control strategy, the switching logic of the redundant actuator system or the redundant actuator is as follows: when there is a minor fault (such as the sensor error is greater than the preset value), software compensation for the actuator function is triggered (such as filtering, deviation correction); when there is a medium fault (such as abnormal main actuator current), switching to the standby actuator is triggered; when there is a severe fault (such as the backup actuator also fails), then a safe stop is triggered.
[0060] In some embodiments, the redundant actuator system includes a redundant steer-by-wire system and a redundant electro-hydraulic braking system.
[0061] Specifically, the steer-by-wire system can control the vehicle driving direction, and the electro-hydraulic braking system can control the vehicle driving speed. These are two key factors during vehicle driving, so redundant design is particularly needed to ensure driving safety.
[0062] In a practical application example, the redundant steer-by-wire system is a Dual-Motor Steering system. Specifically, the Dual-Motor Steering system adopts a master-slave motor cooperative control strategy. When the main motor is operating normally, the slave motor is in a low-power standby mode. When the main motor has an abnormality (such as overheating, stalling), it automatically switches to the slave motor. The Adaptive Fault-Tolerant Control (AFCC) algorithm is used to dynamically adjust the torque of the slave motor during the switching process to avoid instantaneous jitter.
[0063] It should be noted that the present disclosure has designed some specific technical means to ensure that the switching time between the main motor and the auxiliary motor can be less than 5 ms. These specific technical means include: the auxiliary motor maintains a low-current pre-excitation (such as micro-power-on of the coil) during standby to avoid complete power-off and reduce start-up delay; a dual independent drive circuit is adopted, the power supplies of the main and auxiliary motors are separated, and the power supply is instantaneously switched through a high-speed solid-state relay during switching; the AFCC algorithm preloads the parameters of the auxiliary motor and dynamically adjusts the torque output during switching to eliminate jitter without re-initialization; the FPGA monitors the status of the main motor in real time, and the fault signal transmission delay is less than 1 ms to ensure a quick trigger of the switching process.
[0064] In a practical application example, the redundant wire-controlled braking system is a dual Electronic Hydraulic Brake (EHB) system. Specifically, the dual Electronic Hydraulic Brake system adopts dual redundant brake pumps. When the main pump fails, the standby pump can seamlessly take over. It has an intelligent degradation function. If the fault is minor, the braking torque of the main pump is reduced to avoid abrupt braking and affecting driving stability. It has a complete backup capability. If the main braking system fails, the electronic parking system can take over the braking task.
[0065] The wire-controlled chassis safety guarantee method provided by an embodiment of the present disclosure can be executed in a computer environment with an FPGA and an ARM dual-processor architecture. Among them, the FPGA processor is responsible for real-time sensing data processing and the execution of safety control strategies; the ARM processor is responsible for communicating with the upper computer and receiving control instructions from the upper computer. Inside the FPGA processor, a fault detection model can be integrated to infer potential fault points and calculate the health score of the wire-controlled chassis.
[0066] The technical solutions provided by one or more embodiments of the present disclosure ensure high-precision perception capabilities of the vehicle and its wire-controlled chassis even when a single or some sensors fail by acquiring multi-type vehicle sensor data. Based on the fused data, multi-modal fault detection can be performed to accurately identify various types of vehicle fault problems. According to the fault detection results, different levels of safety control strategies can be determined for the wire-controlled chassis, and multiple safety guarantee solutions can be provided for vehicle operation. The redundant actuator system of the wire-controlled chassis ensures that different levels of safety control strategies can be effectively executed, improving the safety and reliability of the wire-controlled chassis.
[0067] The technical solutions provided by one or more embodiments of the present disclosure combine a sensor redundancy architecture and a heterogeneous architecture, a federated fusion algorithm, TCN real-time fault diagnosis, and a dynamic fault tolerance control strategy, effectively solving the problems of long response delay and insufficient fault tolerance of traditional wire-controlled chassis systems in multi-modal fault scenarios, and greatly improving the safety and reliability of wire-controlled chassis systems in extreme working conditions, long-term operation, and high-dynamic environments.
[0068] The wire-controlled chassis safety guarantee method provided by one or more embodiments of the present disclosure is applicable to autonomous vehicles at L4 level and above. Especially in scenarios such as complex urban roads, unmanned mining areas, and automated transportation in smart ports, it can provide stable and reliable vehicle safety guarantee.
[0069] Please refer to Figure 5 , the present disclosure also provides a wire-controlled chassis safety guarantee device, and the device includes:
[0070] A data acquisition unit 100, configured to acquire various types of vehicle sensor data, perform data fusion, and generate fusion data;
[0071] A fault diagnosis unit 200, configured to perform multi-modal anomaly detection based on the fusion data, and generate a fault detection result, where the fault detection result includes a fault type and a fault confidence level;
[0072] A control arbitration unit 300, configured to determine safety control strategies at different levels according to the fault detection result;
[0073] A safety control unit 400, configured to control the redundant actuator system of the wire-controlled chassis according to the safety control strategy.
[0074] In one embodiment, the data acquisition unit 100 is specifically configured to perform weighted fusion on the vehicle sensor data by using a federated Kalman filtering algorithm, and the fusion weight is determined according to the real-time confidence level of the vehicle sensor data.
[0075] In one embodiment, the fusion weight is determined by the following formula:
[0076]
[0077] where W i,k is the fusion weight of the i-th sensor, is the error variance of the i-th sensor at the k-th moment, and the error variance is calculated in real time by a sliding window method, and n is the total number of sensors participating in data fusion.
[0078] In one embodiment, the fault diagnosis unit 200 is specifically configured to perform multi-modal anomaly detection on the fusion data by using a temporal convolutional network model, and the temporal convolutional network model includes a plurality of dilated convolutional layers, the dilation coefficients of the plurality of dilated convolutional layers increase exponentially, and the number of output channels of each dilated convolutional layer is equal.
[0079] In one embodiment, the control arbitration unit 300 is specifically configured to determine a fault item and the item confidence corresponding to each fault item according to the fault type and the fault confidence; determine the health score of the by-wire chassis based on the fault item and the item confidence; and determine different levels of safety control strategies according to the comparison result between the health score and multiple health thresholds.
[0080] In one embodiment, the determining different levels of safety control strategies according to the comparison result between the health score and multiple health thresholds includes at least one of the following: if the health score is less than or equal to the first threshold and greater than the second threshold, trigger a primary fault tolerance strategy, where the primary fault tolerance strategy is used to reduce the system power of the current actuator system; if the health score is less than or equal to the second threshold and greater than the third threshold, trigger a secondary fault tolerance strategy, where the secondary fault tolerance strategy is used to activate the backup actuator system; if the health score is less than or equal to the third threshold, trigger a tertiary fault tolerance strategy, where the tertiary fault tolerance strategy is used to force a safe stop; where the first threshold is greater than the second threshold, and the second threshold is greater than the third threshold.
[0081] In one embodiment, the redundant actuator system includes a redundant by-wire steering system and a redundant by-wire braking system.
[0082] Each unit illustrated in the above embodiments can be specifically implemented by a computer chip or by a product with a certain function. A typical implementation device is a computer. Specifically, the computer can be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.
[0083] For convenience of description, the above devices are described by dividing them into various units according to their functions. Of course, when implementing the present application, the functions of each unit can be implemented in the same or multiple software and / or hardware.
[0084] Please refer to Figure 6 , the present disclosure also provides an electronic device, where the electronic device includes a memory and a processor, the memory is used to store a computer program, and when the computer program is executed by the processor, the above-described by-wire chassis safety guarantee method is implemented.
[0085] The present disclosure also provides a computer-readable storage medium, where the computer-readable storage medium is used to store a computer program, and when the computer program is executed by a processor, the above-described by-wire chassis safety guarantee method is implemented.
[0086] Among them, the processor can be a Central Processing Unit (CPU). The processor can also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc., or a combination of the above types of chips.
[0087] As a non-transitory computer-readable storage medium, the memory can be used to store non-transitory software programs, non-transitory computer-executable programs, and modules, such as the program instructions / modules corresponding to the methods in the embodiments of the present disclosure. By running the non-transitory software programs, instructions, and modules stored in the memory, the processor can execute various functional applications and data processing of the processor, that is, implement the methods in the above method embodiments.
[0088] The memory can include a program storage area and a data storage area. Among them, the program storage area can store an operating system and application programs required for at least one function; the data storage area can store data created by the processor, etc. In addition, the memory can include high-speed random access memory, and can also include non-transitory memory, such as at least one magnetic disk storage device, flash memory device, or other non-transitory solid-state storage devices. In some embodiments, the memory may optionally include a memory remotely set relative to the processor, and these remote memories can be connected to the processor through a network. Examples of the above networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.
[0089] Those skilled in the art can understand that to implement all or part of the processes in the above method embodiments, it can be completed by instructing relevant hardware through a computer program. The program can be stored in a computer-readable storage medium, and when the program is executed, it can include the processes of the above method embodiments. Among them, the storage medium can be a magnetic disk, optical disk, Read-Only Memory (ROM), Random Access Memory (RAM), Flash Memory, Hard Disk Drive (abbreviation: HDD), or Solid-State Drive (SSD), etc.; the storage medium can also include a combination of the above types of memories.
[0090] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other, and the differences between each embodiment and other embodiments are emphasized. In particular, for the embodiments of the apparatus, device, and storage medium, since they are basically similar to the method embodiments, the description is relatively simple, and reference can be made to the corresponding parts of the method embodiments for relevant content.
[0091] The above description is only for the embodiments of the present application and is not intended to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.
[0092] Although the embodiments of the present disclosure have been described in conjunction with the accompanying drawings, those skilled in the art can make various modifications and variations without departing from the spirit and scope of the present disclosure, and such modifications and variations fall within the scope defined by the appended claims.
Claims
1. A method for ensuring safety of a wire-controlled chassis, characterized in that: The method comprises: Acquire multiple types of vehicle sensor data, perform data fusion, and generate fused data; Based on the fused data, multimodal anomaly detection is performed to generate a fault detection result, wherein the fault detection result includes a fault type and a fault confidence level; Determining safety control strategies of different levels according to the fault detection results; According to the safety control strategy, a redundant actuator system of the drive-by-wire chassis is controlled.
2. The method according to claim 1, characterized in that The data fusion comprises: The vehicle sensor data is weightedly fused by using a federated Kalman filter algorithm, and the fusion weight is determined according to the real-time confidence of the vehicle sensor data.
3. The method according to claim 2, characterized in that The fusion weight is determined by the following formula: Among them, W i,k is the fusion weight of the i-th sensor, is the error variance of the ith sensor at time k, and the error variance is calculated in real time by the sliding window method, and n is the total number of sensors involved in data fusion.
4. The method according to claim 1, characterized in that: The performing multimodal anomaly detection based on the fused data includes: Multimodal anomaly detection is performed on the fused data using a temporal convolutional network model, wherein the temporal convolutional network model comprises a plurality of dilated convolutional layers, the dilation coefficients of the plurality of dilated convolutional layers increase exponentially, and the number of output channels of each of the dilated convolutional layers is equal.
5. The method according to claim 1, characterized in that Determining different levels of safety control strategies according to the fault detection result includes: Determine the fault item and the item confidence corresponding to each of the fault items according to the fault type and the fault confidence; Determining a health score based on the faulty item and the item confidence; The security control strategies at different levels are determined according to the comparison results of the health score and multiple health thresholds.
6. The method according to claim 5, characterized in that Determining the security control strategies at different levels according to the comparison results between the health score and the multiple health thresholds includes at least one of the following: If the health score is less than or equal to the first threshold and greater than the second threshold, a first-level fault-tolerant strategy is triggered, and the first-level fault-tolerant strategy is used to reduce the system power of the current actuator system; If the health score is less than or equal to the second threshold and greater than the third threshold, a secondary fault tolerance strategy is triggered, and the secondary fault tolerance strategy is used to activate the backup executor system; If the health score is less than or equal to a third threshold, a third-level fault-tolerant strategy is triggered, and the third-level fault-tolerant strategy is used to force safe parking; The first threshold is greater than the second threshold, and the second threshold is greater than the third threshold.
7. The method according to claim 1, characterized in that The redundant actuator system includes a redundant steer-by-wire system and a redundant brake-by-wire system.
8. A wire-controlled chassis safety device, characterized in that: The device comprises: A data acquisition unit, used to acquire multiple types of vehicle sensor data, perform data fusion, and generate fused data; A fault diagnosis unit, configured to perform multimodal anomaly detection based on the fused data and generate a fault detection result, wherein the fault detection result includes a fault type and a fault confidence level; A control arbitration unit, used to determine safety control strategies of different levels according to the fault detection result; A safety control unit is used to control the redundant actuator system of the drive-by-wire chassis according to the safety control strategy.
9. An electronic device, characterized in that: The electronic device comprises a memory and a processor, wherein the memory is used to store a computer program, and when the computer program is executed by the processor, the method according to any one of claims 1 to 7 is implemented.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium is used to store a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.
Citation Information
Cited By
Robot multi-joint permanent magnet synchronous motor linkage control method, device and system
CN120638906A
Method, device and system for linkage control of multi-joint permanent magnet synchronous motors in robots
CN120638906B
Vehicle control method, intelligent cabin and vehicle
CN120986324A
Vehicle control method, intelligent cockpit and vehicle
CN120986324B