Vehicle expected function safety data driven closed-loop solving method, system and equipment and storage medium
By collecting and analyzing data from actual hazardous events through vehicle sensing systems, multi-dimensional optimization solutions are developed, which solves the problem of insufficient vehicle functionality in existing technologies that cannot respond quickly. This enables continuous optimization of vehicle functional modules and full lifecycle functional safety management, thereby improving the stability and safety of intelligent driving systems.
Patent Information
- Application Number
- CN202510913622.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-03
- Publication Date
- 2025-10-17
AI Technical Summary
Existing technologies lack data-driven, closed-loop solutions for anticipated functional safety issues that address actual hazardous events. This results in vehicles being unable to quickly and accurately analyze and respond to risks caused by functional deficiencies or improper use during actual operation, making it difficult to prevent the recurrence of the same or similar hazardous events.
By collecting driving data before and after hazardous events through vehicle sensing systems, preprocessing and functional deviation analysis are performed to formulate multi-dimensional system optimization plans. Combined with simulation and real vehicle testing verification, a data-driven closed-loop optimization process is established to achieve continuous optimization and risk assessment of vehicle functional modules.
It has improved the stability and robustness of vehicle functional modules in high-risk scenarios, and built a functional safety management platform covering the entire life cycle to ensure the long-term safety of intelligent driving systems in changing scenarios.
Smart Images

Figure CN120806628A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of vehicle intended function safety, in particular to a vehicle intended function safety data-driven closed-loop solution method, system, device and storage medium. BACKGROUND
[0002] In recent years, with the rapid development of intelligent networking and automatic driving technology, vehicle function safety has become an important prerequisite for ensuring system reliability and passenger safety. Traditional safety problem solving solutions are mostly from static design and single safety perspective. Based on the method of pre-design modeling and assumption scenario deduction, it is difficult to discover and effectively respond to unknown safety problems in the system running process. Especially in the field of vehicle intended function safety, it is difficult to completely predict and avoid the risks caused by insufficient functions or improper use in the design stage, which leads to the inability to quickly and accurately analyze and respond to the harm events that occur in the actual operation stage, and there is a problem of fragmentation between design, testing and operation stages.
[0003] In particular, in the actual running process of the vehicle, the actual harm events that have occurred have passively exposed the defects and deficiencies in the original design of the system that have not been considered, but the existing technology lacks a data-driven closed-loop analysis method for these actual harm events, making it difficult to effectively analyze and optimize the system by using the actual running data to analyze the insufficient functions in depth, which may cause the same or similar harm events to occur repeatedly.
[0004] In the prior art, Chinese patent document CN117726208A discloses an "intended function safety analysis method and system for an intelligent driving system of an automobile", which adopts a system theory process analysis method to construct a whole vehicle level function control architecture for vehicle intended function safety analysis; adopts a hazard and operability analysis method to identify hazards and determine harm events corresponding to the whole vehicle running environment; and for possible harm events, defines safety measures corresponding to each component or software based on the whole vehicle level function control structure; collects running data of the vehicle in the running scene, and stores the running data in the scene library after labeling; and tests and verifies each component or software that has defined safety measures in a simulation or actual road environment. However, this technical solution relies on a scene library driven function verification means, and evaluates the function applicability and potential risk prediction through pre-defined working conditions, which seriously depends on the exhaustiveness and rationality assumption of the scene in the design stage, and is difficult to cover new combination risks that occur in complex dynamic environments, and lacks response capability for function problems exposed by the deployed system in actual operation.
[0005] In summary, the prior art lacks a data-driven closed-loop intended function safety problem solving method for actual harm events. SUMMARY
[0006] The present application solves the technical problem that the prior art lacks a data-driven closed-loop expected functional safety problem solving method for actual harm events.
[0007] The vehicle expected functional safety data-driven closed-loop solving method provided by the present application comprises the following steps: Step 1, collecting driving data before and after a harm event of a vehicle through a vehicle sensing system, and pre-processing to obtain pre-processed driving data; Step 2, performing functional deviation analysis and trigger condition induction on the pre-processed driving data respectively; Step 3, based on the results of functional deviation analysis and trigger condition induction, formulating a multi-dimensional system optimization scheme to optimize the vehicle functional module, to obtain an optimized vehicle functional module; Step 4, when a harm event occurs to the vehicle, performing steps 1-3 to analyze the driving data before and after the harm event, when the optimized vehicle functional module makes an unacceptable expected response, obtaining the residual risk of unacceptable expected response, and when the optimized vehicle functional module makes an acceptable expected response, designing a verification and confirmation strategy to evaluate the residual risk of different scenarios, to obtain the residual risk of acceptable expected response; Step 5, based on the residual risk of unacceptable expected response and the residual risk of acceptable expected response in step 4, updating the multi-dimensional system optimization scheme, re-optimizing the vehicle functional module, performing harm identification and risk assessment on the re-optimized vehicle functional module, and when the harm identification and risk assessment results are acceptable, the vehicle is put into operation, and when the harm identification and risk assessment results are unacceptable, steps 2-3 are performed.
[0008] Further, in the embodiment of the present application, the vehicle sensing system in step 1 comprises a millimeter wave radar, a laser radar, a camera, an inertial navigation sensor, a wheel speed sensor and a GPS positioning module.
[0009] Further, in the embodiment of the present application, the driving data before and after the harm event of the vehicle in step 1 comprises vehicle driving state, vehicle position, vehicle speed, vehicle acceleration, vehicle steering angle, vehicle surrounding environment condition, vehicle driving road state and vehicle surrounding traffic participant behavior.
[0010] Further, in the embodiment of the present application, the pre-processing in step 1 is specifically: data cleaning is performed on the driving data before and after the harm event of the vehicle, the time sequence of the driving data after data cleaning is aligned, feature extraction is performed on the driving data after time sequence alignment, the extracted driving data features are classified, and pre-processed driving data is obtained.
[0011] Further, in the embodiment of the present application, the function deviation analysis and trigger condition induction in step 2 are specifically as follows: Based on the design document, function requirement specification and control strategy definition of the vehicle function module, the function response standard that the vehicle function module should have when the hazard event occurs is determined, the reason why the vehicle function module does not achieve the function response standard is analyzed, and the trigger condition when the vehicle function module does not achieve the function response standard is induced.
[0012] Further, in the embodiment of the present application, the multi-dimensional system optimization scheme in step 3 is specifically as follows: The vehicle function module is optimized in multiple dimensions from the aspects of vehicle hardware configuration, perception strategy, decision control logic and human-computer interaction mechanism.
[0013] Further, in the embodiment of the present application, the design verification and confirmation strategy evaluation of residual risks in different scenarios in step 4 are specifically as follows: For known scenarios, the vehicle is simulated and tested, and the simulation test results and the real vehicle test results are cross-verified to obtain the residual risks of the known scenarios. For unknown scenarios, potential function deviations and trigger conditions are identified through a data-driven method to obtain the residual risks of the unknown scenarios.
[0014] The vehicle expected function safety data-driven closed-loop solution system provided by the present application comprises the following modules: A preprocessing module acquires driving data before and after a vehicle hazard event through a vehicle sensing system, and pre-processes the driving data to obtain pre-processed driving data. An analysis and induction module performs function deviation analysis and trigger condition induction on the pre-processed driving data. An optimization module formulates a multi-dimensional system optimization scheme to optimize the vehicle function module based on the function deviation analysis and trigger condition induction results, and obtains an optimized vehicle function module. An evaluation module performs back-filling analysis on the driving data before and after a vehicle hazard event based on the preprocessing module, the analysis and induction module and the optimization module when the vehicle hazard event occurs, obtains residual risks of unacceptable expected responses when the optimized vehicle function module makes unacceptable expected responses, and obtains residual risks of acceptable expected responses when the optimized vehicle function module makes acceptable expected responses. A continuous optimization module updates the multi-dimensional system optimization scheme based on the residual risk of unacceptable expected response and the residual risk of acceptable expected response, re-optimizes the vehicle function module, performs hazard identification and risk assessment on the re-optimized vehicle function module, and puts the vehicle into operation when the hazard identification and risk assessment results are acceptable, and executes the analysis induction module and the optimization module when the hazard identification and risk assessment results are unacceptable.
[0015] The electronic device comprises a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory realize mutual communication through the communication bus. The memory is used for storing a computer program. The processor is used for executing the program stored on the memory to realize the vehicle expected function safety data-driven closed-loop solution method.
[0016] The computer readable storage medium stores a computer program, and the computer program is executed by the processor to realize the vehicle expected function safety data-driven closed-loop solution method.
[0017] The present application solves the technical problem that the prior art lacks a data-driven closed-loop expected function safety problem solving method for actual hazard events. Specific beneficial effects include: The application provides a vehicle expected function safety data-driven closed-loop solution method, restarts an expected function safety process based on a real harm event actually occurring in vehicle operation, and restores a system perception, decision-making and control link step by step through data backfill analysis, so that problems can be quickly identified and root causes can be accurately located. Vehicle driving data before and after a harm event is collected by a vehicle sensing system, preprocessed, and subjected to function deviation analysis and trigger condition induction, so that lengthy risk hypothesis deduction is avoided, and the timeliness and pertinence of problem identification are improved. A multi-dimensional system optimization scheme is formulated based on a real harm event, combined with trigger conditions and function failure performances backtracked from the preprocessed driving data, and the multi-dimensional system optimization scheme is optimized in a targeted manner from a perception algorithm, human-computer interaction logic to a control strategy through a corresponding relationship of 'event-defect-optimization', so that the stability and robustness of a vehicle function module in a typical high-risk scene can be significantly improved. The application constructs a function safety data management platform covering the whole life cycle of a vehicle, realizes unified modeling and dynamic linkage from function requirements, verification data to actual operation performance, and when a vehicle harm event occurs and an optimized vehicle function module makes an unacceptable expected response, the residual risk of a scene corresponding to the harm event is evaluated, the analysis and optimization process can be automatically restarted, the vehicle function module is adaptively evolved, and the long-term safety of an intelligent driving system in a variable scene is ensured. The application starts from a harm event actually occurring in actual operation, extracts and backfills vehicle operation data, locates the root cause of harm occurrence, identifies the deviation and deficiency of a vehicle function module in actual working conditions, formulates a targeted multi-dimensional system optimization scheme and verification strategy, constructs a complete whole life cycle closed-loop management system, and fundamentally improves the continuous effectiveness of vehicle expected function safety. BRIEF DESCRIPTION OF DRAWINGS
[0018] The above and / or additional aspects and advantages of the application will become apparent and be readily understood from the following description, taken in conjunction with the drawings, in which: Figure 1 is a vehicle expected function safety data-driven closed-loop solution method flowchart of the first embodiment. DETAILED DESCRIPTION
[0019] Various embodiments of the application will be described in detail below with reference to the drawings. The embodiments described by reference to the drawings are exemplary and are intended to explain the application, and cannot be understood as limiting the application.
[0020] Embodiment I. The vehicle expected function safety data-driven closed-loop solution method described in the embodiment comprises the following steps: Step 1: collecting driving data of the vehicle before and after the hazardous event occurs through the vehicle sensor system and preprocessing the data to obtain preprocessed driving data; Step 2: Perform functional deviation analysis and trigger condition summary on the pre-processed driving data; Step 3: Based on the functional deviation analysis and trigger condition summary results, a multi-dimensional system optimization plan is formulated to optimize the vehicle functional modules to obtain the optimized vehicle functional modules; Step 4: When a hazardous event occurs, execute steps 1 to 3 to perform a re-injection analysis on the vehicle's driving data before and after the hazardous event. If the optimized vehicle functional module makes an unacceptable expected response, the residual risk of the unacceptable expected response is obtained. If the optimized vehicle functional module makes an acceptable expected response, the design verification and validation strategy evaluates the residual risk of different scenarios to obtain the residual risk of the acceptable expected response. Step 5: Based on the residual risk of unacceptable expected reactions and the residual risk of acceptable expected reactions described in step 4, update the multi-dimensional system optimization plan, re-optimize the vehicle functional modules, and perform hazard identification and risk assessment on the re-optimized vehicle functional modules. When the hazard identification and risk assessment results are acceptable, the vehicle is put into operation. When the hazard identification and risk assessment results are unacceptable, execute steps 2 to 3.
[0021] In this embodiment, the vehicle sensing system in step 1 includes a millimeter wave radar, a laser radar, a camera, an inertial navigation sensor, a wheel speed sensor and a GPS positioning module.
[0022] In this embodiment, the driving data of the vehicle in step 1 before and after the hazardous event occurs includes the vehicle's driving status, vehicle position, vehicle speed, vehicle acceleration, vehicle steering angle, vehicle surrounding environment conditions, vehicle driving road conditions and the behavior of traffic participants around the vehicle.
[0023] In this embodiment, the pre-processing in step 1 is specifically as follows: The driving data before and after the vehicle hazardous incident is cleaned, the time series of the cleaned driving data is aligned, the features of the time series aligned driving data are extracted, and the extracted driving data features are classified to obtain the preprocessed driving data.
[0024] In this embodiment, the functional deviation analysis and triggering conditions in step 2 are summarized as follows: Based on the design document, functional requirement specification and control strategy definition of the vehicle function module, the functional response standard that the vehicle function module should have when a hazard event occurs is determined, the reason why the vehicle function module does not achieve the functional response standard is analyzed, and the trigger condition when the vehicle function module does not achieve the functional response standard is summarized.
[0025] In the embodiment, the multi-dimensional system optimization scheme in step 3 is specifically: The vehicle function module is optimized in multiple dimensions from the aspects of vehicle hardware configuration, perception strategy, decision control logic and human-computer interaction mechanism.
[0026] In the embodiment, the design verification and confirmation strategy evaluates the residual risk of different scenarios in step 4, which is specifically: For known scenarios, simulation testing and real vehicle testing are performed on the vehicle, and the simulation test results and real vehicle test results are cross-verified to obtain the residual risk of known scenarios. For unknown scenarios, the corresponding functional deviation and trigger condition are identified through a data-driven method to obtain the residual risk of unknown scenarios.
[0027] The prior art lacks a data-driven closed-loop expected functional safety problem solving method for actual hazard events.
[0028] To solve the above technical problems, the embodiment provides a vehicle expected functional safety data-driven closed-loop solving method, which specifically includes the following steps: Step 1, collect the driving data before and after the vehicle hazard event through the vehicle sensing system, and pre-process the driving data before and after the vehicle hazard event, clean the driving data, align the time sequence of the driving data after cleaning, extract the features of the driving data after time sequence alignment, classify the extracted driving data features, and obtain the pre-processed driving data.
[0029] When a hazard event occurs during vehicle operation, such as collision, emergency braking, out-of-control abnormal event, etc., the driving data before and after the vehicle hazard event is quickly marked and stored. The driving data before and after the vehicle hazard event is mainly collected by the vehicle sensing system, including millimeter wave radar, laser radar, camera, inertial navigation sensor, wheel speed sensor, GPS positioning module, etc., which collects the driving data of vehicle driving state, position, speed, acceleration, steering angle, environmental conditions, road conditions, surrounding traffic participant behavior, etc.
[0030] Firstly, the collected driving data is cleaned, including removing missing values, outliers, and noise data, and aligning the time stamps of different sensor driving data to ensure data synchronization. At the same time, feature extraction is performed, including vehicle kinematic features, environmental features, and behavior features, etc. Vehicle kinematic features include speed change and trajectory curve, etc. Environmental features include weather, lighting, and road conditions, etc. Behavior features include driver behavior patterns. Subsequently, the driving data of different scenarios is classified preliminarily, laying a foundation for subsequent data closed-loop feedback analysis.
[0031] Step 2, functional deviation analysis and trigger condition induction are performed on the preprocessed driving data. Based on the design documents, functional requirement specifications and control strategy definitions of vehicle functional modules, the functional response standards that vehicle functional modules should have when a hazard event occurs are determined. The reasons for the vehicle functional modules not achieving the functional response standards are analyzed, and the trigger conditions when the vehicle functional modules do not achieve the functional response standards are induced. When a hazard event occurs, all hazard events will be standardized and recorded, and the original driving data within a certain time range before and after the hazard event will be extracted, and the unified processing and time alignment of multi-source data will be completed. Data types include but are not limited to sensor information, vehicle state parameters, environmental conditions, and driver operations, etc. Sensor information includes millimeter wave radar, camera, and laser radar, etc. Vehicle state parameters include speed, acceleration, and steering wheel angle, etc. Environmental conditions include lighting, weather, and road conditions, etc. Driver operations include braking, steering, and takeover, etc.
[0032] Unlike traditional expected functional safety analysis methods that start with risk prediction, this embodiment innovatively takes real hazard events that have occurred in the actual operation of the vehicle as the starting point. After each actual hazard event occurs, such as collision, emergency braking failure, lane deviation without correction, etc., it is indicated that the vehicle functional module has failed to complete its expected function in a specific scenario. Since the hazard event has already occurred, the existence of risk has become a fact. Therefore, this embodiment no longer performs traditional hazard identification and evaluation steps, but takes real hazard events as the starting point to carry out data-driven vehicle functional module behavior reproduction and deviation positioning analysis, providing reliable basis for subsequent functional deficiency and system optimization work.
[0033] The root cause of the vehicle functional module failing to perform the expected function according to the design requirements is identified as the target, and system-level functional deviation analysis and trigger condition induction are carried out. This analysis process is based on the running state of the vehicle functional module in the actual event, combined with design specifications and running data for structured attribution.
[0034] 1. Based on the vehicle function module design document, function requirement specification and control strategy definition, the function response standards that the vehicle function module should have in the corresponding scene of the occurred hazard event are determined, including the expected behavior logic of the activation timing, trigger threshold, execution strategy, etc. in the perception, decision, control stages. Taking this as the reference framework, the actual performance of the vehicle function module in the data of the driving vehicle in the aspects of perception identification, behavior decision, control execution, etc. is analyzed, and the response delay, interruption, misjudgment or non-triggering, etc. in the function link are analyzed, and the system level attribution points of the function not implemented or function failure are accurately located.
[0035] 2. The conditions for the occurrence of function not implemented are classified and analyzed in combination with the environmental variables, running state and vehicle function module response data in various function failure events. The specific analysis dimensions include but are not limited to: light, weather, road type, vehicle speed, target object type, relative distance, driver operation behavior, etc. By comparing the common conditions presented by multiple similar events, the high-frequency trigger factors leading to the function failure of the vehicle function module can be summarized to provide support for the identification of the boundaries and function application domain of the vehicle function module. The analysis results will be output in a structured manner to form a hazard event corresponding function deviation and typical trigger condition summary table, which records the core function defects, deviation performance and typical trigger conditions exposed by each vehicle function module in actual operation. Table 1 is an example of hazard event corresponding function deviation analysis and typical trigger condition summary.
[0036] Table 1
[0037] Step 3, based on the function deviation analysis and trigger condition summary results, a multi-dimensional system optimization scheme is developed to optimize the vehicle function module, and an optimized vehicle function module is obtained; After the function deficiency and its trigger conditions corresponding to the actual hazard events in step 2 are determined, this step will develop a multi-dimensional system optimization scheme, including optimization from multiple dimensions such as hardware configuration, perception strategy, decision control logic, human-machine interaction mechanism, etc. For the hazard event example in step 2, the corresponding specific system optimization details are as follows: Table 2
[0038] Step 4, the effectiveness, stability and coverage of the multi-dimensional system optimization scheme are evaluated, the known scene and unknown scene are differentiated for evaluation, and a residual risk identification and analysis mechanism is introduced in the long-term running process of the vehicle function module, to realize the full-chain closed-loop confirmation of the safety performance of the vehicle function module.
[0039] When a hazardous event occurs to the vehicle, the driving data before and after the hazardous event is fed back for analysis based on the methods described in steps 1 to 3. When the optimized vehicle functional module makes an unacceptable expected response, the residual risk of the unacceptable expected response is obtained. When the optimized vehicle functional module makes an acceptable expected response, the design verification and confirmation strategy evaluates the residual risks of different scenarios and obtains the residual risk of an acceptable expected response.
[0040] 1. In terms of known scenario assessment, the vehicle is subjected to simulation tests and actual vehicle tests, and the simulation test results and actual vehicle test results are cross-validated to obtain the residual risk of the known scenario. The hazardous events identified in step 2 are imported into the simulation platform to reproduce the scenario simulation. For each optimization item, the versions of the vehicle functional module before and after optimization are tested simultaneously to compare the differences in the behavioral performance of the vehicle functional module in perception, decision-making, control, human-computer interaction and other aspects. The quantitative indicators of the simulation test results include recognition rate, false alarm rate, control response delay, path deviation, risk event triggering frequency, etc. After the simulation test is passed, the actual vehicle test phase is entered. Combined with the operating design conditions and design domain, coverage tests are carried out in closed roads and actual traffic scenarios. Multi-source data including system response logs, driver behavior, environmental status, etc. are collected and cross-validated with the simulation test results to ensure the effectiveness and consistency of the optimization measures under real operating conditions.
[0041] If the risk of the known scenario is found to be small enough after testing and the expected functional safety is achieved, the vehicle can continue to be put into operation. If the risk of the known scenario is found to be not small enough after testing, or the risk of the known scenario is small enough but the expected functional safety is not achieved, the corresponding known scenario is judged to have residual risk, and the residual risk of the known scenario is obtained.
[0042] 2. For unknown scenarios, the corresponding functional deviations and triggering conditions are identified through data-driven methods to obtain the residual risks of the unknown scenarios. After the vehicle functional module is deployed, a long-term operation data monitoring mechanism will be enabled to continuously collect and dynamically screen global driving data. The data-driven method will be used to identify unforeseen potential functional boundaries or behavioral deviations, that is, the functional deviations and triggering conditions corresponding to unknown scenarios. These newly triggered unknown scenarios will be analyzed for feedback and residual risk assessment and verification. The vehicle functional module will trigger a rapid closed-loop mechanism of "optimization-verification-re-monitoring" based on the newly triggered unknown scenarios, dynamically update the vehicle functional module behavior model and triggering rules, and achieve continuous expansion of the functional boundaries of the vehicle functional module and iterative improvement of safety.
[0043] If the possibility of unknown scenarios that can cause harmful behaviors is small enough after the residual risk assessment verification, and the expected functional safety is achieved, the vehicle can continue to run, if the possibility of unknown scenarios that can cause harmful behaviors is not small enough after the residual risk assessment verification, or the possibility of unknown scenarios that can cause harmful behaviors is small enough after the residual risk assessment verification but the expected functional safety is not achieved, it is judged that the corresponding unknown scenario has residual risk, and the residual risk of the unknown scenario is obtained.
[0044] Step 5, based on the residual risk of unacceptable expected reaction and the residual risk of acceptable expected reaction described in step 4, update the multi-dimensional system optimization scheme, re-optimize the vehicle function module, re-specify the design and definition of the vehicle function module, and perform hazard identification and risk assessment on the re-optimized vehicle function module. When the hazard identification and risk assessment result is acceptable, the vehicle is put into operation, and when the hazard identification and risk assessment result is unacceptable, steps 2-3 are performed.
[0045] The risk assessment principle is as follows: two indexes of S (severity) and C (controllability) are used for risk level evaluation to determine whether the risk is acceptable. If the severity and controllability are both greater than 0, it is determined that the hazard event is unacceptable risk; if either the severity or the controllability is 0, it is determined that the risk is acceptable risk.
[0046] A long-term real-time data collection platform is established to continuously record the real-time running state of the vehicle, the behavior of the driver, the environmental characteristics and the road conditions through the vehicle-mounted sensor system, and a vehicle long-term running data database is constructed. When the system monitors a new hazard event, data backfilling closed-loop analysis is immediately started to quickly diagnose the problem root and trigger condition, and the corresponding vehicle function module is optimized according to the residual risk optimization. The updated optimization measures are quickly deployed through remote technology. The performance of the vehicle under different environmental conditions is continuously tracked, and the optimization scheme is continuously improved to evaluate the long-term effectiveness and stability of the scheme.
[0047] Periodic historical data analysis and summary are performed to realize continuous accumulation of safety experience and stable improvement of system performance, and to complete long-term data-driven dynamic optimization closed loop.
[0048] A functional safety data management platform covering the entire vehicle life cycle is established to uniformly store and dynamically manage safety-related data generated by the vehicle at each stage, including but not limited to functional requirements and control strategy documents at the design stage, test conditions and result data at the simulation and real vehicle verification stage, driving logs, system state information, driver interaction behavior, actual hazard event records and backfilling analysis results collected at the running stage. The functional safety data management platform supports unified modeling and structured archiving of data, realizes cross-domain traceability and interconnectivity of driving data at different stages, and provides a complete data basis for system-level safety management.
[0049] The embodiment collects vehicle driving data in real time through a vehicle-mounted sensor system, automatically marks and extracts event-related data when a safety hazard event occurs in actual operation, such as collision, misrecognition, non-capturing, etc., performs data backfill analysis, locates specific links where the system function does not achieve as expected, identifies functional deficiencies and triggering conditions, and establishes a structured attribution model. Based on the backfill analysis results, corresponding software and hardware optimization schemes are developed, including perception algorithms, human-machine interaction logic, control strategies, etc.; through high-risk simulation scenarios and real vehicle verification processes, double-channel verification is carried out, and verification indicators include recognition rate, control delay, and false trigger rate, etc., and a residual risk identification mechanism is introduced to monitor and dynamically correct unknown boundaries after optimization. Through continuous data backfill analysis, residual risk identification and optimization verification processes, problems found in the running phase are quickly fed back to the system design and control logic update link to realize real-time evolution management of functional safety. A risk monitoring and response system covering the whole chain of "design-verification-deployment-operation-feedback" is formed, which not only enables the system to achieve closed-loop solutions for known problems, but also has the ability to continuously absorb and respond to unknown risks, supporting the realization of long-term stable expected functional safety of intelligent driving systems in complex dynamic environments.
[0050] A long-term operation monitoring and life cycle data management platform supporting systematic evolution is constructed, which can realize unified modeling and through management of functional safety data in each stage from design, testing to deployment and operation; combined with the newly identified problems in the operation data, the functional safety analysis process is restarted, and dynamic feedback is given to the design stage to realize continuous expansion of system function boundary and evolution of safety capability, ensuring the expected functional safety of vehicles throughout the entire use cycle.
[0051] Embodiment two. The vehicle expected functional safety data-driven closed-loop solution system described in the embodiment includes the following modules: A preprocessing module collects vehicle driving data before and after a hazard event occurs through a vehicle sensor system and pre-processes the data to obtain pre-processed driving data; An analysis and induction module performs functional deviation analysis and triggering condition induction on the pre-processed driving data; An optimization module develops multi-dimensional system optimization schemes based on the results of functional deviation analysis and triggering condition induction to optimize vehicle function modules, and obtains optimized vehicle function modules; An evaluation module, when a vehicle hazard event occurs, based on the preprocessing module, analysis induction module and optimization module, the driving data before and after the vehicle hazard event is backfilled and analyzed, when the optimized vehicle function module makes an unacceptable expected response, the residual risk of the unacceptable expected response is obtained, when the optimized vehicle function module makes an acceptable expected response, the residual risk of the acceptable expected response is obtained by designing verification and confirmation strategy to evaluate the residual risk of different scenarios. A continuous optimization module, based on the residual risk of the unacceptable expected response and the residual risk of the acceptable expected response of the evaluation module, updates the multi-dimensional system optimization scheme, re-optimizes the vehicle function module, and performs hazard identification and risk assessment on the re-optimized vehicle function module, when the hazard identification and risk assessment result is acceptable, the vehicle is put into operation, when the hazard identification and risk assessment result is unacceptable, the analysis induction module and the optimization module are executed.
[0052] Embodiment three. An electronic device, comprising a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other through the communication bus. The memory is used to store a computer program. The processor is used to execute the program stored on the memory, and realizes the vehicle expected function safety data-driven closed-loop solution method of embodiment one.
[0053] Embodiment four. The computer readable storage medium of the embodiment, the computer readable storage medium stores a computer program, and the computer program is executed by the processor to realize the vehicle expected function safety data-driven closed-loop solution method of embodiment one.
[0054] The vehicle expected function safety data-driven closed-loop solution method, system, device and storage medium are described in detail above. The principle and implementation of the present application are described in this paper by applying specific examples. The above examples are only used to help understand the method and its core idea; at the same time, for those skilled in the art, according to the idea of the present application, the specific implementation and application range will be changed; in view of the above, the content of the specification should not be understood as the limitation of the present application.
Claims
1. A data-driven closed-loop solution for vehicle expected functional safety, characterized by: The following steps are involved: Step 1: collecting driving data of the vehicle before and after the hazardous event occurs through the vehicle sensor system and preprocessing the data to obtain preprocessed driving data; Step 2: Perform functional deviation analysis and trigger condition summary on the pre-processed driving data; Step 3: Based on the functional deviation analysis and trigger condition summary results, a multi-dimensional system optimization plan is formulated to optimize the vehicle functional modules to obtain the optimized vehicle functional modules; Step 4: When a hazardous event occurs, execute steps 1 to 3 to perform a re-injection analysis on the vehicle's driving data before and after the hazardous event. If the optimized vehicle functional module makes an unacceptable expected response, the residual risk of the unacceptable expected response is obtained. If the optimized vehicle functional module makes an acceptable expected response, the design verification and validation strategy evaluates the residual risk of different scenarios to obtain the residual risk of the acceptable expected response. Step 5: Based on the residual risk of unacceptable expected reactions and the residual risk of acceptable expected reactions described in step 4, update the multi-dimensional system optimization plan, re-optimize the vehicle functional modules, and perform hazard identification and risk assessment on the re-optimized vehicle functional modules. When the hazard identification and risk assessment results are acceptable, the vehicle is put into operation. When the hazard identification and risk assessment results are unacceptable, execute steps 2 to 3.
2. The data-driven closed-loop solution for vehicle expected functional safety according to claim 1 is characterized in that: The vehicle sensing system in step 1 includes a millimeter-wave radar, a laser radar, a camera, an inertial navigation sensor, a wheel speed sensor, and a GPS positioning module.
3. The data-driven closed-loop solution for vehicle expected functional safety according to claim 1 is characterized in that: The driving data of the vehicle before and after the hazardous event in step 1 includes the vehicle's driving state, vehicle position, vehicle speed, vehicle acceleration, vehicle steering angle, vehicle surrounding environment conditions, vehicle driving road conditions and the behavior of traffic participants around the vehicle.
4. The data-driven closed-loop solution for vehicle expected functional safety according to claim 1, characterized in that: The pre-processing in step 1 is specifically as follows: The driving data before and after the vehicle hazardous incident is cleaned, the time series of the cleaned driving data is aligned, the features of the time series aligned driving data are extracted, and the extracted driving data features are classified to obtain the preprocessed driving data.
5. The data-driven closed-loop solution for vehicle expected functional safety according to claim 1, characterized in that: The functional deviation analysis and triggering conditions in step 2 are summarized as follows: Based on the design documents, functional requirement specifications and control strategy definitions of the vehicle functional modules, the functional response standards that the vehicle functional modules should have when a hazardous incident occurs are clarified, the reasons why the vehicle functional modules fail to achieve the functional response standards are analyzed, and the triggering conditions when the vehicle functional modules fail to achieve the functional response standards are summarized.
6. The data-driven closed-loop solution for vehicle expected functional safety according to claim 1, characterized in that: The multi-dimensional system optimization solution in step 3 is specifically as follows: The vehicle functional modules are optimized in multiple dimensions from the aspects of vehicle hardware configuration, perception strategy, decision-making control logic and human-computer interaction mechanism.
7. The data-driven closed-loop solution for vehicle expected functional safety according to claim 1, characterized in that: The design verification and validation strategy in step 4 above assesses the residual risk for different scenarios, specifically: For known scenarios, the vehicle is tested in simulation and on-site, and the simulation and on-site test results are cross-validated to obtain the residual risk of the known scenario; For unknown scenarios, potential functional deviations and trigger conditions are identified through data-driven methods to obtain the residual risks of unknown scenarios.
8. Vehicle expected functional safety data-driven closed-loop solution system, characterized by: Includes the following modules: A preprocessing module collects driving data before and after a hazardous event occurs through a vehicle sensor system and performs preprocessing to obtain preprocessed driving data; The analysis and summarization module performs functional deviation analysis and trigger condition summary on the pre-processed driving data; The optimization module formulates a multi-dimensional system optimization plan based on the functional deviation analysis and trigger condition summary results to optimize the vehicle functional modules and obtain the optimized vehicle functional modules; The evaluation module, when a hazardous event occurs, performs a re-injection analysis of the vehicle's driving data before and after the hazardous event based on the pre-processing module, the analysis and induction module, and the optimization module. If the optimized vehicle functional module makes an unacceptable expected response, the residual risk of the unacceptable expected response is obtained. If the optimized vehicle functional module makes an acceptable expected response, a verification and confirmation strategy is designed to evaluate the residual risk of different scenarios and obtain the residual risk of an acceptable expected response. The continuous optimization module updates the multi-dimensional system optimization plan based on the residual risk of unacceptable expected reactions and the residual risk of acceptable expected reactions described in the evaluation module, re-optimizes the vehicle functional modules, and performs hazard identification and risk assessment on the re-optimized vehicle functional modules. When the hazard identification and risk assessment results are acceptable, the vehicle is put into operation. When the hazard identification and risk assessment results are unacceptable, the analysis and induction module and the optimization module are executed.
9. An electronic device, characterized in that: It includes a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other via the communication bus; Memory for storing computer programs; The processor is configured to implement the data-driven closed-loop solution for vehicle expected functional safety as described in any one of claims 1 to 7 when executing the program stored in the memory.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the vehicle expected functional safety data-driven closed-loop solution according to any one of claims 1 to 7.
Citation Information
Patent Citations
Predicted function safety analysis method and system for automobile intelligent driving system
CN117726208A
Cited By
Auxiliary driving optimization method based on expected function safety risk assessment
CN121734377A
Assisted driving optimization method based on expected functional safety risk assessment
CN121734377B