Automatic driving system fault processing method and device, equipment and storage medium

By monitoring communication status information, judging faults and triggering safety modes, and using backup links and historical data to control vehicles, the problem of low security in the prior art autonomous driving system when communication is abnormal is solved, and stable operation and safe exit in the case of failure are achieved.

CN120573128AActive Publication Date: 2025-09-02FOSS (HANGZHOU) INTELLIGENT TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510651594.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-20
Publication Date
2025-09-02
Estimated Expiration
2045-05-20

AI Technical Summary

Technical Problem

Existing autonomous driving systems are difficult to quickly trigger the safety mode when communication is abnormal, resulting in low system security, especially inability to respond in time when hardware failure or software is stuck, which may cause the vehicle to deviate from the expected path or get out of control.

Method used

By monitoring communication status information, the system failure is judged, the safety mode is triggered, and the backup link perception information and historical data are used to generate vehicle control instructions to ensure the continuity of vehicle control and exit the safety mode when the driver takes over.

Benefits of technology

Improves the robustness and safety of the autonomous driving system in the event of abnormal communication, ensuring that the vehicle can operate stably in the event of failure and safely exit the safety mode when the driver takes over.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120573128A_ABST
    Figure CN120573128A_ABST
Patent Text Reader

Abstract

The invention discloses an automatic driving system fault processing method, apparatus and device, and a storage medium. The method comprises the steps of determining whether an automatic driving system has a fault based on communication state information; when the automatic driving system has a fault, triggering a safety mode of the automatic driving system, and after entering the safety mode, determining whether backup link sensing information exists or not; if the backup link sensing information exists, using the backup link sensing information and the historical sensing data to generate a vehicle control instruction, and obtaining current state information of the vehicle; and a vehicle control mode is determined according to the current state information, and in the process of executing the vehicle control instruction based on the vehicle control mode, if the driver takes over the vehicle, the safety mode is quitted. The safety mode is quickly triggered when the communication is abnormal, the vehicle control is maintained by using the backup link sensing information and the historical sensing data, and the safety mode is quitted when the driver takes over the vehicle, so that the robustness and the safety of the automatic driving system are effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of autonomous driving technology, and in particular to a method, device, equipment, and storage medium for handling faults in an autonomous driving system. Background Art

[0002] With the rapid development of autonomous driving technology, advanced driver assistance features (such as Highway Assist (HWA)) are becoming increasingly common in mass-produced vehicles. These systems typically rely on the collaborative work of multiple chips or cores, achieving sensor data fusion, planning and control, and vehicle execution through real-time cross-chip or cross-core communication. For example, in existing technologies, the previous generation of domain controllers achieved target fusion and planning and control through Ethernet communication between the MCU and the SOC chip. However, the new generation of domain controllers achieves collaborative perception and decision-making through the division of labor among multiple cores within a single chip.

[0003] However, this type of distributed architecture faces significant safety challenges in complex scenarios. When cross-chip or cross-core communication is interrupted due to hardware failure, software jamming, or short-term interruptions (such as a 3-second Ethernet heartbeat interruption), the system may not be able to detect or respond in time. For example, in a mass-produced vehicle case, the interruption of communication between the MCU and the SOC caused the fusion module to lose target information. The system misjudged that there was no car in front and accelerated, ultimately causing a collision. Although existing technologies trigger functional degradation through diagnostic trouble codes (DTCs), the delayed reporting of DTCs (such as reaching a 3-second threshold) causes the function to enter an unexpected control state before degradation. Moreover, in dynamic scenarios such as lane changes or vehicle posture tilt, if communication is interrupted or the module is jammed, it is difficult for the existing system to coordinate cross-lane trajectory planning and control, which may cause the vehicle to deviate from the expected path or lose control.

[0004] Therefore, there is an urgent need for a fault handling method for autonomous driving systems that can quickly trigger a safety mode when communication anomalies occur and use backup data or historical data to maintain vehicle control, thereby improving the robustness and safety of the autonomous driving system. Summary of the Invention

[0005] The main purpose of the present invention is to provide a method, device, equipment and storage medium for handling faults of an autonomous driving system, aiming to solve the technical problem in the prior art that the autonomous driving system has difficulty maintaining short-term vehicle control capabilities when communication is abnormal, resulting in low safety of the autonomous driving system.

[0006] To achieve the above objectives, the present invention provides a method for handling faults in an autonomous driving system, the method comprising the following steps:

[0007] Determine whether the autonomous driving system has a fault based on communication status information;

[0008] When a fault occurs in the autonomous driving system, triggering a safety mode of the autonomous driving system, and determining whether backup link perception information exists after entering the safety mode;

[0009] If there is backup link perception information, the backup link perception information and historical perception data are used to generate a vehicle control instruction and obtain the current state information of the vehicle;

[0010] A vehicle control mode is determined according to the current state information, and in the process of executing the vehicle control instruction based on the vehicle control mode, if the driver takes over the vehicle, the safety mode is exited.

[0011] Optionally, the step of determining whether the automatic driving system has a fault based on the communication status information includes:

[0012] Acquire communication status information, wherein the communication status information is update status information of the perception fusion information and the heartbeat packet information;

[0013] Determine, based on the update status information, whether the perception fusion information has not been updated continuously to reach the first preset frame or whether the heartbeat packet information has not been updated continuously to reach the second preset frame, and obtain a determination result;

[0014] Determine whether the automatic driving system has a fault based on the judgment result.

[0015] Optionally, after the step of determining whether the automatic driving system has a fault according to the judgment result, the method further includes:

[0016] If the judgment result is that the perception fusion information has not been continuously updated to reach the first preset frame or the heartbeat packet information has not been continuously updated to reach the second preset frame, it indicates that there is a fault in the automatic driving system.

[0017] Optionally, after the step of triggering a safety mode of the autonomous driving system when a fault occurs in the autonomous driving system and determining whether backup link perception information exists after entering the safety mode, the method further includes:

[0018] If there is no backup link perception information, the historical perception data is used to generate vehicle control instructions and obtain the current status information of the vehicle;

[0019] The step of determining the vehicle control mode according to the current state information and exiting the safety mode if the driver takes over the vehicle during the process of executing the vehicle control instruction based on the vehicle control mode is performed.

[0020] Optionally, the step of triggering a safety mode of the autonomous driving system when a fault occurs in the autonomous driving system, and determining whether backup link perception information exists after entering the safety mode, includes:

[0021] When there is a fault in the autonomous driving system, triggering a safety mode of the autonomous driving system;

[0022] After the automatic driving system enters the safety mode, issuing a flag corresponding to the safety mode;

[0023] Acquire historical perception data and determine whether there is backup link perception information, wherein the historical perception data is sensor data for a preset time period before the fault occurs.

[0024] Optionally, the step of determining the vehicle control mode according to the current state information and exiting the safety mode if the driver takes over the vehicle during the process of executing the vehicle control instruction based on the vehicle control mode includes:

[0025] Determining a vehicle control mode based on the current state information, wherein the vehicle control mode includes a lane control mode and a cross-lane control mode;

[0026] When the vehicle control mode is the lane control mode, determining a vehicle control time threshold based on the current environment information and the current state information, and generating a vehicle takeover prompt message through the automatic driving system to remind the driver;

[0027] During the process of executing the vehicle control instruction based on the lane control method, if the vehicle control time does not exceed the vehicle control time threshold and the driver receives the vehicle takeover prompt information and takes over the vehicle, the safety mode is exited.

[0028] Optionally, after the step of determining the vehicle control method based on the current state information, the method further includes:

[0029] When the vehicle control mode is a cross-lane control mode, determining whether the automatic driving system can generate a trajectory for the vehicle to return to its own lane during the lane change process;

[0030] If the autonomous driving system cannot generate a trajectory for the vehicle to return to its own lane during the lane change, the vehicle is controlled to change lanes to the target lane based on the cross-lane control method, and a vehicle takeover prompt message is generated by the autonomous driving system to alert the driver;

[0031] During the process of executing the vehicle control instruction based on the cross-lane vehicle control method, if the driver receives the vehicle takeover prompt information and takes over the vehicle, the safety mode is exited.

[0032] In addition, to achieve the above-mentioned purpose, the present invention also provides a fault handling device for an automatic driving system, the device comprising:

[0033] A fault judgment module is used to judge whether there is a fault in the automatic driving system based on the communication status information;

[0034] a safety trigger module, configured to trigger a safety mode of the autonomous driving system when a fault occurs in the autonomous driving system, and determine whether backup link perception information exists after entering the safety mode;

[0035] An information acquisition module, configured to generate a vehicle control instruction using the backup link perception information and historical perception data if there is backup link perception information, and to obtain the current status information of the vehicle;

[0036] The vehicle control module is used to determine a vehicle control mode according to the current state information, and to exit the safety mode if the driver takes over the vehicle during the process of executing the vehicle control instruction based on the vehicle control mode.

[0037] In addition, to achieve the above-mentioned purpose, the present invention also proposes an autonomous driving system fault handling device, which includes: a memory, a processor, and an autonomous driving system fault handling program stored on the memory and runnable on the processor, and the autonomous driving system fault handling program is configured to implement the steps of the autonomous driving system fault handling method described above.

[0038] In addition, to achieve the above-mentioned purpose, the present invention also proposes a storage medium, on which an autonomous driving system fault handling program is stored. When the autonomous driving system fault handling program is executed by a processor, the steps of the autonomous driving system fault handling method described above are implemented.

[0039] The present invention discloses a method for judging whether an automatic driving system has a fault based on communication status information; when a fault occurs in the automatic driving system, triggering a safety mode of the automatic driving system, and after entering the safety mode, determining whether there is backup link perception information; if there is backup link perception information, generating a vehicle control instruction using the backup link perception information and historical perception data, and obtaining the current status information of the vehicle; determining a vehicle control method based on the current status information, and in the process of executing the vehicle control instruction based on the vehicle control method, exiting the safety mode if the driver takes over the vehicle. Since the present invention quickly triggers the safety mode when communication is abnormal, uses the backup link perception information and historical perception data to maintain vehicle control, and exits the safety mode when the driver takes over the vehicle, compared to the prior art, the present invention effectively improves the robustness and safety of the automatic driving system when communication is abnormal. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] Figure 1 This is a flowchart of a first embodiment of a method for handling a fault in an autonomous driving system according to the present invention;

[0041] Figure 2 This is a schematic diagram of the internal links of the previous generation domain controller and the new generation domain controller;

[0042] Figure 3 This is a schematic diagram of a specific workflow for troubleshooting of the autonomous driving system of the present invention;

[0043] Figure 4 This is a flowchart of a second embodiment of a method for troubleshooting an autonomous driving system according to the present invention;

[0044] Figure 5 Schematic diagram of the safety response mechanism of the autonomous driving system of the present invention in the event of communication interruption or system hang;

[0045] Figure 6 This is a flowchart of a third embodiment of a method for troubleshooting an autonomous driving system according to the present invention;

[0046] Figure 7 This is a structural block diagram of a first embodiment of a fault handling device for an automatic driving system according to the present invention;

[0047] Figure 8 It is a structural diagram of an automatic driving system fault handling device in a hardware operating environment involved in an embodiment of the present invention.

[0048] The purpose, features and advantages of the present invention will be further described with reference to the accompanying drawings and in conjunction with the embodiments. DETAILED DESCRIPTION

[0049] It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0050] The embodiment of the present invention provides a method for handling faults in an automatic driving system. Figure 1 , Figure 1 2 is a flow chart of a first embodiment of a method for troubleshooting an autonomous driving system according to the present invention.

[0051] In this embodiment, the automatic driving system fault handling method includes steps S10 to S40:

[0052] Step S10: Determine whether there is a fault in the automatic driving system based on the communication status information.

[0053] It should be noted that the execution subject of this embodiment can be a computer server device used in vehicle control, which has data processing, network communication, and program execution functions. The computer server device can be located in the vehicle. The computer service device can be a server, a computer, an onboard mobile device, or an electronic device capable of performing the above functions, such as an autonomous driving system fault handling device. The following uses the autonomous driving system fault handling device as an example to illustrate this embodiment and the following embodiments.

[0054] It should be explained that the above-mentioned communication status information can be cross-chip or cross-core communication status information, and can be update information of perception fusion information and heartbeat packet information, wherein the perception fusion information can be fusion information of multiple sensors, and the heartbeat packet information can be a custom data packet used to maintain connection and status monitoring in the network communication of the autonomous driving system.

[0055] refer to Figure 2 , Figure 2 This diagram illustrates the internal links between the previous-generation and new-generation domain controllers. In the previous-generation domain controller's internal links, the system-on-chip (SoC) chip fuses front and corner radar information (i.e., environmental information in front of and to the sides of the vehicle detected by the radar sensors) with forward-view information from the vision processing chip (i.e., visual information in front of the vehicle), a process known as sensor data fusion (SDF). The MCU chip then handles sensor fusion (SF), path planning, control, and arbitration between different systems. Heartbeat packets are used for system health monitoring, and DTCs (diagnostic trouble codes) are used for fault diagnosis and reporting. In short, the previous-generation domain controller completes target fusion and planning control through Ethernet communication between the MCU and SoC. In the new-generation domain controller's internal links, visual information is first collected. The first core then performs target fusion (SDF), SF fusion, and driving planning, responsible for target fusion, sensor fusion, and driving path planning. The second core then performs SF fusion, partial L2 planning, control, and arbitration, responsible for sensor fusion, partial L2 autonomous driving planning and control, and system arbitration. In short, the new-generation domain controller achieves collaborative perception and decision-making through multi-core division of labor. Therefore, when cross-chip or cross-core communication is interrupted due to hardware failure, software freeze or short-term interruption (such as Ethernet heartbeat interruption for 3 seconds), the autonomous driving system may not be able to detect or respond in time.

[0056] In a specific implementation, cross-chip or cross-core communication status information can be monitored, and the communication status information (i.e., the update status information of the perception fusion information and the heartbeat packet information) can be used to determine whether the autonomous driving system has a fault. Cross-chip or cross-core communication status information can also be monitored, and the communication status information can be combined with the DTC (diagnostic fault code) information to determine whether the autonomous driving system has a fault.

[0057] Step S20: When a fault occurs in the autonomous driving system, a safety mode of the autonomous driving system is triggered, and after entering the safety mode, it is determined whether there is backup link perception information.

[0058] It should be understood that the safety mode of an autonomous driving system is a comprehensive system designed to ensure that the vehicle can operate safely and reliably without human intervention.

[0059] It should be explained that backup link perception information refers to the perception data obtained by the autonomous driving system automatically switching to the backup communication link or backup sensor when the main communication link or main sensor link fails (such as communication interruption or sensor failure). These data are used to maintain the system's perception capability when the main link fails, ensuring the continuity and safety of vehicle control.

[0060] In a specific implementation, when a fault occurs in the autonomous driving system, the safety mode of the autonomous driving system is triggered; after the autonomous driving system enters the safety mode, a flag corresponding to the safety mode is issued; historical perception data is obtained, and it is determined whether there is backup link perception information, the historical perception data being sensor data for a preset time period before the fault occurs.

[0061] Step S30: If there is backup link perception information, the backup link perception information and historical perception data are used to generate a vehicle control instruction, and the current state information of the vehicle is obtained.

[0062] It should be understood that if there is no backup link perception information, the historical perception data is used to generate vehicle control and obtain the current status information of the vehicle.

[0063] It can be understood that vehicle control instructions refer to vehicle control commands generated by the autonomous driving system based on perception data, planning algorithms and current vehicle status, which are used to control the vehicle's acceleration, deceleration, steering and other behaviors.

[0064] It should be noted that the current state information of the vehicle may include the vehicle's lane position, driving direction, target trajectory, etc.

[0065] Step S40: determining a vehicle control mode according to the current state information, and exiting the safety mode if the driver takes over the vehicle during the process of executing the vehicle control instruction based on the vehicle control mode.

[0066] It should be noted that the vehicle control methods include lane control and cross-lane control. These two vehicle control methods have different control logic and objectives in safety mode to ensure safety in different scenarios.

[0067] It should be explained that positive acceleration requests are not allowed in the current lane control mode; if there is a deceleration request when using the backup link perception information to control the vehicle, the deceleration request will be executed; the current lane control mode has a maximum control time, which is determined by the lane line length, vehicle speed, specific scenario, etc.; during the current lane control process, the system needs to immediately remind the driver to take over the vehicle; during the current lane control process, if the driver takes over the vehicle, the safety mode will exit.

[0068] Positive acceleration requests are not allowed in cross-lane control mode; if there is a deceleration request when using backup link perception information to control the vehicle, the deceleration request will be executed; during the lane change process, if the system can plan a trajectory to return to the current lane, the vehicle will return to the current lane; during the lane change process, if the system cannot plan a trajectory to the current lane, the vehicle will continue to change lanes to the target lane; the system needs to immediately remind the driver to take over the vehicle; during the cross-lane control process, if the driver takes over the vehicle, the safety mode will exit.

[0069] For example, reference Figure 3 , Figure 3 This is a specific workflow diagram for fault handling of the automatic driving system of the present invention. First, it is determined whether the safety mode is triggered; if the safety mode is not triggered, the system operates normally; if the safety mode is triggered, it is determined whether there is backup link perception information (i.e., backup link perception data); if there is backup link perception information, the backup link perception information and historical perception data are used to control the vehicle, and it is determined whether the vehicle is in a lane-changing state; if the vehicle is in a lane-changing state, the cross-lane control mode is selected; if the vehicle is not in a lane-changing state, the current lane control mode is selected; then after the driver takes over the vehicle, the safety mode is exited (i.e., function exit); if there is no backup link perception information, the historical perception data is used to control the vehicle, and it is determined whether the vehicle is in a lane-changing state; if the vehicle is in a lane-changing state, the cross-lane control mode is selected; if the vehicle is not in a lane-changing state, the current lane control mode is selected; then after the driver takes over the vehicle, the safety mode is exited (i.e., function exit).

[0070] This embodiment discloses determining whether an autonomous driving system has a fault based on communication status information; when a fault occurs in the autonomous driving system, triggering the safety mode of the autonomous driving system, and after entering the safety mode, determining whether there is backup link perception information; if there is backup link perception information, generating a vehicle control instruction using the backup link perception information and historical perception data, and obtaining the current status information of the vehicle; determining a vehicle control method based on the current status information, and exiting the safety mode if the driver takes over the vehicle during the process of executing the vehicle control instruction based on the vehicle control method. Since this embodiment quickly triggers the safety mode when communication is abnormal, uses the backup link perception information and historical perception data to maintain vehicle control, and exits the safety mode when the driver takes over the vehicle, compared to the existing technology, this embodiment effectively improves the robustness and safety of the autonomous driving system when communication is abnormal.

[0071] refer to Figure 4 , Figure 4 2 is a flow chart of a second embodiment of a method for troubleshooting an autonomous driving system according to the present invention.

[0072] Based on the first embodiment above, in this embodiment, step S10 includes steps S101 to S103:

[0073] Step S101: Acquire communication status information, where the communication status information is update status information of perception fusion information and heartbeat packet information.

[0074] Step S102: determining, based on the update status information, whether the perception fusion information has not been updated continuously to reach the first preset frame or whether the heartbeat packet information has not been updated continuously to reach the second preset frame, and obtaining a determination result.

[0075] Step S103: Determine whether the automatic driving system has a fault based on the judgment result.

[0076] In a specific implementation, if the judgment result is that the perception fusion information has not been continuously updated to reach the first preset frame or the heartbeat packet information has not been continuously updated to reach the second preset frame, it indicates that there is a fault in the autonomous driving system.

[0077] For example, reference Figure 5 , Figure 5 This is a schematic diagram of the safety response mechanism of the autonomous driving system of the present invention in the event of a communication interruption or system freeze. In the figure, time T1 is the actual moment when the communication interruption or module freeze occurs. At this time, the system may detect that the fused data (i.e., perception fusion data) is not updating or that the heartbeat packet (i.e., heartbeat packet information) is interrupted. If the fused data is not updated for n1 frames (i.e., the first preset frame) or the transmission control heartbeat packet is not updated for n2 frames (i.e., the second preset frame), the safety mode triggering condition is met and safe mode is entered. Before time T1 (i.e., before the safety mode flag is issued), the system records a period of perception data (i.e., historical perception data, such as lane markings and target vehicle position) to maintain vehicle control capabilities in safe mode. Time T2 is the moment when the system detects a communication interruption or module freeze and triggers safe mode. At this point, the system determines whether to enter safe mode based on preset conditions (e.g., no update of n1 frames of fused data or no update of n2 frames of heartbeat packets). The exit time of safe mode can be dynamically determined based on specific operating conditions (e.g., lane length, vehicle speed, driver takeover status, etc.). When the driver takes over or communication is restored, the system exits safe mode and vehicle control commands become invalid. In safe mode, the system will not accelerate; it will control the vehicle using backup link perception data or partially valid sensor data; it will control the vehicle using historical perception information; and the exit time depends on the specific operating conditions.

[0078] It should be understood that the first preset frame and the second preset frame may be user-defined, and this embodiment does not limit this.

[0079] This embodiment discloses obtaining communication status information, wherein the communication status information is update status information of perception fusion information and heartbeat packet information; determining whether the perception fusion information has not been continuously updated to reach a first preset frame or whether the heartbeat packet information has not been continuously updated to reach a second preset frame based on the update status information, and obtaining a judgment result; and determining whether the autonomous driving system has a fault based on the judgment result. Because the present invention determines whether the autonomous driving system has a fault by determining whether the perception fusion information has not been continuously updated to reach a first preset frame or whether the heartbeat packet information has not been continuously updated to reach a second preset frame, compared to the prior art, the present invention can quickly determine whether the system has a fault when communication is abnormal, thereby quickly triggering a safety mode, further improving the safety of the autonomous driving system.

[0080] refer to Figure 6 , Figure 6 2 is a flow chart of a third embodiment of a method for troubleshooting an autonomous driving system according to the present invention.

[0081] Based on the above embodiments, in this embodiment, step S40 includes steps S401 to S403:

[0082] Step S401: Determine a vehicle control mode based on the current state information, where the vehicle control mode includes a lane control mode and a cross-lane control mode.

[0083] In a specific implementation, it is possible to determine whether the current vehicle state is a lane keeping state or a lane changing state based on the current state information; if the current vehicle state is a lane keeping state, the vehicle control in this lane is maintained, that is, the vehicle control mode is the vehicle control mode in this lane; if the current vehicle state is a lane changing state, the vehicle control mode is determined based on the lane changing sub-state.

[0084] It should be noted that the lane change sub-states include Stage 0, Stage 1, and Stage 2. Stage 0 is the lane change waiting state, Stage 1 is the state where the lane change has begun but the vehicle does not have the right of way in the target lane and can safely and comfortably plan a trajectory back to the original lane, and Stage 2 is the state where the vehicle already has the right of way in the target lane or can no longer safely and comfortably return to the original lane.

[0085] In the specific implementation, when the vehicle is in the Stage 0 state, the lane change is canceled and the vehicle is controlled according to the control method of the lane; when the vehicle is in the Stage 1 state, the lane change is canceled, and the vehicle first drives along the trajectory returning to the center of the lane (that is, the vehicle is controlled according to the cross-lane control method), and then the vehicle is controlled according to the control method of the lane; when the vehicle is in the Stage 2 state, the lane change is continued according to the lane change trajectory (that is, the vehicle is controlled according to the cross-lane control method). After the lane change is completed and the vehicle reaches the target lane, the vehicle is controlled according to the control method of the lane.

[0086] It should be understood that when the vehicle is in stage 1, it will continue to plan its return path. If a comfortable trajectory back to the current lane can be planned while satisfying lateral acceleration comfort, the planning is considered successful. If the planned return path would invade the target lane of the lane change, the vehicle is considered to have the right of way in the target lane, i.e., it is in stage 2.

[0087] Step S402: When the vehicle control mode is the lane control mode, a vehicle control time threshold is determined based on the current environment information and the current state information, and a vehicle takeover prompt message is generated through the automatic driving system to remind the driver.

[0088] Step S403: During the process of executing the vehicle control instruction based on the lane control mode, if the vehicle control time does not exceed the vehicle control time threshold and the driver receives the vehicle takeover prompt information and takes over the vehicle, exit the safety mode.

[0089] It should be noted that the above-mentioned vehicle control time threshold can be determined based on factors such as lane line length, vehicle speed, current specific scenario, etc. The current environmental information can include lane line length and current specific scenario.

[0090] In a specific implementation, after step S401, steps S404 to S406 are further included:

[0091] Step S404: When the vehicle control mode is a cross-lane vehicle control mode, determine whether the automatic driving system can generate a trajectory for the vehicle to return to the lane during the lane change process.

[0092] Step S405: If the automatic driving system cannot generate a trajectory for the vehicle to return to the current lane during the lane change process, the vehicle is controlled to change lanes to the target lane based on the cross-lane vehicle control method, and the automatic driving system generates a vehicle takeover prompt message to remind the driver.

[0093] It should be noted that if the automatic driving system can generate a trajectory for the vehicle to return to its lane during the lane change process, the vehicle will be controlled to return to its lane based on the cross-lane control method.

[0094] Step S406: During the process of executing the vehicle control instruction based on the cross-lane vehicle control method, if the driver receives the vehicle takeover prompt information and takes over the vehicle, the safety mode is exited.

[0095] This embodiment discloses determining a vehicle control mode based on the current state information, wherein the vehicle control mode includes a lane control mode and a cross-lane control mode; when the vehicle control mode is the lane control mode, a vehicle control time threshold is determined based on the current environment information and the current state information, and a vehicle takeover prompt message is generated by the automatic driving system to remind the driver; during the process of executing the vehicle control command based on the lane control mode, if the vehicle control time does not exceed the vehicle control time threshold and the driver receives the vehicle takeover prompt message and takes over the vehicle, the safety mode is exited. Since this embodiment determines the vehicle control mode based on the current state information, and when the vehicle control mode is the lane control mode, a vehicle control time threshold is determined based on the current environment information and the current state information, and if the vehicle control time does not exceed the vehicle control time threshold and the driver receives the vehicle takeover prompt message and takes over the vehicle, the safety mode is exited, compared to the prior art, this embodiment dynamically adjusts the vehicle control command by distinguishing the current state of the vehicle, ensuring that the vehicle can still drive safely in fault conditions such as communication interruption or module jamming.

[0096] In addition, an embodiment of the present invention also proposes a storage medium, on which an autonomous driving system fault handling program is stored. When the autonomous driving system fault handling program is executed by a processor, the steps of the autonomous driving system fault handling method described above are implemented.

[0097] Reference Figure 7 , Figure 7 This is a structural block diagram of the first embodiment of the automatic driving system fault handling device of the present invention.

[0098] like Figure 7 As shown, the automatic driving system fault handling device proposed in an embodiment of the present invention includes: a fault judgment module 701, a safety trigger module 702, an information acquisition module 703 and a vehicle control module 704.

[0099] The fault judgment module 701 is used to judge whether there is a fault in the automatic driving system based on the communication status information.

[0100] The safety trigger module 702 is used to trigger the safety mode of the autonomous driving system when a fault occurs in the autonomous driving system, and to determine whether there is backup link perception information after entering the safety mode.

[0101] The information acquisition module 703 is configured to generate a vehicle control instruction using the backup link perception information and historical perception data if there is backup link perception information, and to acquire the current state information of the vehicle.

[0102] The vehicle control module 704 is configured to determine a vehicle control mode according to the current state information, and to exit the safety mode if the driver takes over the vehicle during the process of executing the vehicle control instruction based on the vehicle control mode.

[0103] The safety trigger module 702 is also used to generate a vehicle control instruction using historical perception data if there is no backup link perception information, and obtain the current status information of the vehicle; execute the step of determining the vehicle control method based on the current status information, and in the process of executing the vehicle control instruction based on the vehicle control method, if the driver takes over the vehicle, exit the safety mode.

[0104] The safety trigger module 702 is also used to trigger the safety mode of the autonomous driving system when a fault occurs in the autonomous driving system; after the autonomous driving system enters the safety mode, it sends a flag corresponding to the safety mode; obtains historical perception data and determines whether there is backup link perception information, the historical perception data being sensor data for a preset time period before the fault occurs.

[0105] The embodiment of the present device discloses determining whether an automatic driving system has a fault based on communication status information; when a fault exists in the automatic driving system, triggering the safety mode of the automatic driving system, and after entering the safety mode, determining whether there is backup link perception information; if there is backup link perception information, generating a vehicle control instruction using the backup link perception information and historical perception data, and obtaining the current status information of the vehicle; determining a vehicle control method based on the current status information, and in the process of executing the vehicle control instruction based on the vehicle control method, exiting the safety mode if the driver takes over the vehicle. Since the embodiment of the present device quickly triggers the safety mode when communication is abnormal, uses the backup link perception information and historical perception data to maintain vehicle control, and exits the safety mode when the driver takes over the vehicle, compared to the prior art, the embodiment of the present device effectively improves the robustness and safety of the automatic driving system when communication is abnormal.

[0106] Based on the first embodiment of the automatic driving system fault handling device of the present invention, a second embodiment of the automatic driving system fault handling device of the present invention is proposed.

[0107] In this embodiment, the fault judgment module 701 is also used to obtain communication status information, where the communication status information is update status information of perception fusion information and heartbeat packet information; based on the update status information, it is determined whether the perception fusion information has not been continuously updated to reach the first preset frame or whether the heartbeat packet information has not been continuously updated to reach the second preset frame to obtain a judgment result; and based on the judgment result, it is determined whether the automatic driving system has a fault.

[0108] The fault judgment module 701 is also used to indicate that there is a fault in the automatic driving system if the judgment result is that the perception fusion information has not been continuously updated to reach the first preset frame or the heartbeat packet information has not been continuously updated to reach the second preset frame.

[0109] Other embodiments or specific implementations of the automatic driving system fault handling device of the present invention can refer to the above-mentioned method embodiments and will not be repeated here.

[0110] The present application provides an autonomous driving system fault handling device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the autonomous driving system fault handling method in the above-mentioned embodiment one.

[0111] Reference below Figure 8 , which shows a schematic diagram of the structure of an autonomous driving system fault handling device suitable for implementing an embodiment of the present application. The autonomous driving system fault handling device in the embodiment of the present application may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions), PMPs (Portable Media Players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 8 The autonomous driving system fault handling device shown is merely an example and should not impose any limitations on the functions and scope of use of the embodiments of the present application.

[0112] like Figure 8As shown, the autonomous driving system fault handling device may include a processing device 1001 (e.g., a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes based on programs stored in a read-only memory 1002 or programs loaded from a storage device 1003 into a random access memory 1004. Random access memory 1004 also stores various programs and data required for the operation of the autonomous driving system fault handling device. Processing device 1001, read-only memory 1002, and random access memory 1004 are interconnected via a bus 1005. An input / output interface 1006 is also connected to the bus. Typically, the following systems can be connected to the input / output interface 1006: an input device 1007 including, for example, a touchscreen, touchpad, keyboard, mouse, image sensor, microphone, accelerometer, gyroscope, etc.; an output device 1008 including, for example, a liquid crystal display (LCD), speaker, vibrator, etc.; a storage device 1003 including, for example, a magnetic tape, hard disk, etc.; and a communication device 1009. The communication device 1009 can allow the autonomous driving system fault handling device to communicate with other devices wirelessly or by wire to exchange data. Although the figure shows the autonomous driving system fault handling device with various systems, it should be understood that it is not required to implement or include all of the illustrated systems. More or fewer systems may alternatively be implemented or included.

[0113] In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in the present application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program comprising program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via a communication device, or installed from a storage device 1003, or installed from a read-only memory 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the method of the embodiment disclosed in the present application are performed.

[0114] The autonomous driving system fault handling device provided in this application, which utilizes the autonomous driving system fault handling method described in the aforementioned embodiment, can address the prior art technical problem of autonomous driving systems struggling to maintain short-term vehicle control when communication anomalies occur, resulting in lower safety. Compared to the prior art, the autonomous driving system fault handling device provided in this application achieves the same beneficial effects as the autonomous driving system fault handling method described in the aforementioned embodiment. Other technical features of the autonomous driving system fault handling device are the same as those disclosed in the aforementioned embodiment and are not further elaborated here.

[0115] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any one or more embodiments or examples in a suitable manner.

[0116] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

[0117] It should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or system comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or system. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or system comprising the element.

[0118] The serial numbers of the above embodiments of the present invention are for description only and do not represent the advantages or disadvantages of the embodiments.

[0119] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better embodiment. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as read-only memory / random access memory, magnetic disk, optical disk), and includes a number of instructions for enabling a terminal device (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in each embodiment of the present invention.

[0120] The above are only preferred embodiments of the present invention and are not intended to limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made using the contents of the present invention description and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.

Claims

1. A method for handling faults in an automatic driving system, characterized in that: The method comprises: Determine whether the autonomous driving system has a fault based on communication status information; When a fault occurs in the autonomous driving system, triggering a safety mode of the autonomous driving system, and determining whether backup link perception information exists after entering the safety mode; If there is backup link perception information, the backup link perception information and historical perception data are used to generate a vehicle control instruction and obtain the current state information of the vehicle; A vehicle control mode is determined according to the current state information, and in the process of executing the vehicle control instruction based on the vehicle control mode, if the driver takes over the vehicle, the safety mode is exited.

2. The automatic driving system fault handling method according to claim 1, wherein: The step of determining whether the automatic driving system has a fault based on the communication status information includes: Acquire communication status information, wherein the communication status information is update status information of the perception fusion information and the heartbeat packet information; Determine, based on the update status information, whether the perception fusion information has not been updated continuously to reach the first preset frame or whether the heartbeat packet information has not been updated continuously to reach the second preset frame, and obtain a determination result; Determine whether the automatic driving system has a fault based on the judgment result.

3. The automatic driving system fault handling method according to claim 2, wherein: After the step of determining whether the automatic driving system has a fault according to the determination result, the method further includes: If the judgment result is that the perception fusion information has not been continuously updated to reach the first preset frame or the heartbeat packet information has not been continuously updated to reach the second preset frame, it indicates that there is a fault in the automatic driving system.

4. The automatic driving system fault handling method according to claim 1, wherein: After the step of triggering the safety mode of the autonomous driving system when a fault occurs in the autonomous driving system and determining whether backup link perception information exists after entering the safety mode, the method further includes: If there is no backup link perception information, the historical perception data is used to generate vehicle control instructions and obtain the current status information of the vehicle; The step of determining the vehicle control mode according to the current state information and exiting the safety mode if the driver takes over the vehicle during the process of executing the vehicle control instruction based on the vehicle control mode is performed.

5. The automatic driving system fault handling method according to claim 1, wherein: The step of triggering a safety mode of the autonomous driving system when a fault occurs in the autonomous driving system, and determining whether backup link perception information exists after entering the safety mode, includes: When there is a fault in the autonomous driving system, triggering a safety mode of the autonomous driving system; After the automatic driving system enters the safety mode, issuing a flag corresponding to the safety mode; Acquire historical perception data and determine whether there is backup link perception information, wherein the historical perception data is sensor data for a preset time period before the fault occurs.

6. The automatic driving system fault handling method according to claim 1, wherein: The step of determining the vehicle control mode according to the current state information and exiting the safety mode if the driver takes over the vehicle during the process of executing the vehicle control instruction based on the vehicle control mode includes: Determining a vehicle control mode based on the current state information, wherein the vehicle control mode includes a lane control mode and a cross-lane control mode; When the vehicle control mode is the lane control mode, determining a vehicle control time threshold based on the current environment information and the current state information, and generating a vehicle takeover prompt message through the automatic driving system to remind the driver; During the process of executing the vehicle control instruction based on the lane control method, if the vehicle control time does not exceed the vehicle control time threshold and the driver receives the vehicle takeover prompt information and takes over the vehicle, the safety mode is exited.

7. The automatic driving system fault handling method according to claim 6, characterized in that: After the step of determining the vehicle control mode based on the current state information, the method further includes: When the vehicle control mode is a cross-lane control mode, determining whether the automatic driving system can generate a trajectory for the vehicle to return to its own lane during the lane change process; If the autonomous driving system cannot generate a trajectory for the vehicle to return to its own lane during the lane change, the vehicle is controlled to change lanes to the target lane based on the cross-lane control method, and a vehicle takeover prompt message is generated by the autonomous driving system to alert the driver; During the process of executing the vehicle control instruction based on the cross-lane vehicle control method, if the driver receives the vehicle takeover prompt information and takes over the vehicle, the safety mode is exited.

8. An automatic driving system fault handling device, characterized in that: The device comprises: A fault judgment module is used to judge whether there is a fault in the automatic driving system based on the communication status information; a safety trigger module, configured to trigger a safety mode of the autonomous driving system when a fault occurs in the autonomous driving system, and determine whether backup link perception information exists after entering the safety mode; An information acquisition module, configured to generate a vehicle control instruction using the backup link perception information and historical perception data if there is backup link perception information, and to obtain the current status information of the vehicle; The vehicle control module is used to determine a vehicle control mode according to the current state information, and to exit the safety mode if the driver takes over the vehicle during the process of executing the vehicle control instruction based on the vehicle control mode.

9. An automatic driving system fault handling device, characterized in that: The device includes: a memory, a processor, and an autonomous driving system fault handling program stored in the memory and executable on the processor, wherein the autonomous driving system fault handling program is configured to implement the steps of the autonomous driving system fault handling method according to any one of claims 1 to 7.

10. A storage medium, characterized in that: The storage medium stores an autonomous driving system fault handling program, which, when executed by the processor, implements the steps of the autonomous driving system fault handling method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Vehicle control method and device based on automatic driving, equipment and medium

    CN109606385A

  • Intelligent fault classification method and system for automatic driving vehicle

    CN111028384A

  • Automatic driving redundancy control system and method

    CN113247022A

  • Automobile automatic driving assistance method and system

    CN113928336A

  • Automatic driving perception redundancy control method and device, equipment and storage medium

    CN117842076A