A control method and device for a full-time active safety automatic emergency braking system

By using a unified risk fusion model and graded failure protection for the all-time active safety automatic emergency braking system, the problems of false triggering and communication jitter during the switchover between automatic driving and manual takeover are solved, achieving safe and reliable control handover and system availability, and reducing the risk of work interruption.

CN122300552APending Publication Date: 2026-06-30QINGDAO PORT INT FREIGHT & LOGISTICS CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
QINGDAO PORT INT FREIGHT & LOGISTICS CO LTD
Filing Date
2026-04-29
Publication Date
2026-06-30

AI Technical Summary

Technical Problem

Existing automatic emergency braking systems are prone to false triggering, conflict judgment, and repeated triggering during the transition between automatic driving and manual takeover. Furthermore, their failure protection is insufficient during communication jitter, leading to safety blind spots and operational interruptions.

Method used

The system employs a full-time active safety automatic emergency braking system, which calculates risk levels through a unified risk fusion model, generates graded safety control commands, and combines independent safety control signal links and graded failure protection to ensure safe and reliable switching of control under different takeover states.

Benefits of technology

This reduces the risk of false triggering and conflict determination during the transition between autonomous driving and manual takeover, ensures the availability and safety of the system during communication jitter, reduces work interruptions, and improves the overall reliability and safety of the automatic emergency braking system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122300552A_ABST
    Figure CN122300552A_ABST
Patent Text Reader

Abstract

This invention belongs to the field of vehicle braking control and autonomous driving control technology, and relates to a control method and device for a full-time active safety automatic emergency braking system. The method includes: collecting environmental perception, vehicle operating status, takeover status, boundary constraints, and FAS-AEB system health data, performing time alignment and validity checks; calculating risk fusion values ​​using a unified risk fusion model and mapping them to risk levels; generating graded safety control commands based on risk levels, and generating control switching commands based on risk fusion values; periodically sending safety status identifiers through an independent safety link; continuously monitoring anomalies, triggering graded failure protection based on anomaly duration, and restoring and re-looping in reverse order after anomaly resolution. This invention achieves continuous online active safety throughout the entire process of autonomous driving, local takeover, and remote takeover, reducing the risk of collisions during takeover, operational interruptions caused by single emergency stops, and the insufficient availability of single-level failure protection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of vehicle braking control and autonomous driving control technology, specifically relating to a control method and device for a full-time active safety automatic emergency braking system. Background Technology

[0002] With the advancement of autonomous driving applications in closed or semi-closed environments such as ports, mining areas, and industrial parks, vehicles frequently switch between autonomous driving, local manual takeover, and remote takeover during actual operations. In existing technologies, manual control usually dominates the takeover phase, resulting in the weakening or bypassing of the Automatic Emergency Braking (AEB) function, creating a safety blind spot during the takeover period.

[0003] Existing AEB (Automatic Emergency Braking) solutions typically employ a single trigger logic, meaning an immediate stop is triggered upon reaching a threshold. This approach is prone to false triggering in low-speed, precise displacement and confined work areas, causing work interruptions and making it difficult to balance safety and efficiency.

[0004] Furthermore, obstacle triggering and electronic fence triggering are still determined independently and in parallel in many systems, lacking a unified risk fusion decision, which easily leads to conflicting judgments and repeated triggering. In terms of failure handling, the common "timeout triggers vehicle control" is a single-level protection strategy, which is insufficient in the face of short-term communication jitter.

[0005] In view of this, it is very necessary to provide a control method and device for a full-time active safety automatic emergency braking system to solve the above-mentioned defects in the prior art. Summary of the Invention

[0006] The purpose of this invention is to address the shortcomings of the existing technology, such as the tendency to generate false triggers and operation interruptions when using a single trigger logic, the tendency to generate conflict judgments and repeated triggers when using independent parallel judgments, and the low availability of failure handling during short-term communication jitter. The invention provides a control method and device for designing a full-time active safety automatic emergency braking system to solve the above-mentioned technical problems.

[0007] To achieve the above objectives, the present invention provides the following technical solution: A control method for a full-time active safety automatic emergency braking system includes the following steps: Step S1: Collect environmental perception data, vehicle operating status data, takeover status data, boundary constraint data, and FAS-AEB (Full-time Active Safety Autonomous Emergency Braking) system health data; perform time alignment, validity checks, and data preprocessing on the raw data; Step S2: Construct risk features based on the collected data and perform feature preprocessing to obtain standardized feature components; based on the standardized feature components, use a unified risk fusion model to calculate the risk fusion value, and perform time smoothing and risk level mapping on the risk value to output the risk level; Step S3: Generate graded safety control instructions based on the risk level and send them to the vehicle actuators to perform corresponding vehicle control operations; generate control status switching instructions based on the risk fusion value and send them to the control status machine to switch the takeover status. Step S4: Generate a safety status identifier based on the risk level, control status, and vehicle control operation; establish an independent safety control signal link, and periodically send the safety status identifier through the independent safety control signal link, while simultaneously sending it to multiple receiving ends; wherein, the multiple receiving ends include: the vehicle-side safety monitoring module of the FAS-AEB system, the local manual driver's console operation end, and the remote monitoring center server end; Step S5: Each receiving end receives the security status identifier; continuously monitors the communication status, the status of each module in the FAS-AEB system, and policy conflicts, and monitors the reception of the security status identifier by each receiving end; if an anomaly is detected, the hierarchical failure protection is triggered according to the duration of the anomaly; when the anomaly is resolved, the hierarchical failure protection is exited and steps S1 to S4 are executed again in a loop; if no anomaly is detected, steps S1 to S4 are executed continuously in a loop.

[0008] Preferably, step S1 specifically includes: Step S11: Collect environmental perception data, vehicle operating status data, takeover status data, boundary constraint data, and FAS-AEB system health data at fixed intervals; The environmental perception data includes: obstacle type, obstacle location, and obstacle speed; Vehicle operating status data includes: vehicle speed, gear, braking status, and steering control status; Takeover status data includes: autonomous driving status, local manual takeover status, and remote takeover status; Boundary constraint data includes: electronic fence boundary distance, area attributes, operation scenario identifiers, and scenario parameters; among them, the electronic fence boundary distance is the shortest distance between the vehicle and the boundary, area attributes include high-risk areas, operation areas, etc., operation scenario identifiers include ports, mining areas, industrial parks, etc., and scenario parameters include area risk level, operation mode, etc. FAS-AEB system health data includes: module operating status, communication quality, and signal keep-alive status; Step S12: To avoid misjudgment caused by time mismatch of multi-source data, perform timestamp alignment and timeout removal on the collected data; Step S13: Perform a validity check on the raw data. The validity check includes: checking for null and outlier values, checking the physical rationality of coordinates and velocity, and checking the gear position. Step S14: Perform standardization processing on the data that passes the inspection to form a unified input vector.

[0009] This step can achieve the following technical effects: Ensuring the temporal consistency and physical rationality of multi-source input data provides standardized and alignable input features for subsequent risk fusion calculations, reducing the risk of misjudgment due to data anomalies or mismatches.

[0010] Preferably, step S2 specifically includes: Step S21: Construct risk features based on the collected data. Risk features include: distance features, speed features, boundary features, vehicle speed features, state features, and scene features. Among them, distance features The relative distance between the vehicle and the obstacle is calculated based on the Euclidean distance between the obstacle's position and the vehicle's position. velocity characteristics The relative approach speed between the vehicle and the obstacle, based on the obstacle's speed. With the speed of the vehicle The relative approximation velocities between them are calculated as follows: The calculation method in the same direction is... The opposite calculation method is ; Boundary features The distance between the vehicle and the electronic fence boundary is calculated based on the shortest straight-line distance between the vehicle's position and the electronic fence boundary. Vehicle speed characteristics The vehicle's current speed is read from the vehicle's operating status data; State characteristics Read from the takeover status data, including: autonomous driving status, local manual takeover status, and remote takeover status; Scene features For scene parameters; Step S22 involves performing feature preprocessing operations on the risk features to verify their validity and normalize them, resulting in standardized feature components: , , , , , in, This is a numerical constraint function that limits the output to between 0 and 1, taking the boundary value if the value exceeds the range. As a distance risk component, As a speed risk component, As a component of boundary risk, As a state risk component, Assign risk components to the scenario; To preset a safe distance threshold, To set a preset distance threshold, Distance features; To preset a low threshold for relative velocity, To preset a high threshold for relative velocity, It is a speed characteristic; To preset the boundary safety threshold, To preset the boundary critical threshold, Boundary features; The mapping function from the takeover state to the state risk component. State characteristics; This is the mapping function from scene parameters to scene risk components. For scene features; Step S23: Calculate the risk fusion value using a unified risk fusion model based on each standardized feature component; Step S24: To reduce the risk fusion value jump caused by sensor jitter, the risk fusion value is smoothed by first-order low-pass filtering. Step S25: Map the smoothed risk fusion values ​​to risk levels and output the risk levels:

[0011] in, , , The preset risk level threshold, and Level 0 corresponds to no risk or very low risk; Level 1 corresponds to low risk; Level 2 corresponds to medium risk; Level 3 corresponds to high risk.

[0012] This step can achieve the following technical effects: By constructing multi-dimensional risk features including distance, speed, boundary, pattern, and scene, and performing normalization, weighted fusion, and coupling compensation, the system achieves the effect of uniformly quantizing multi-source heterogeneous inputs into risk values ​​in the range of 0 to 1 and mapping them to discrete levels, thus solving the conflict judgment problem caused by the independent parallel triggering of obstacles and electronic fences.

[0013] Preferably, step S23 specifically includes: Step S231, calculate the original risk fusion value :

[0014] in, The weights are relative distances. As relative velocity weights, For boundary distance weights, As for vehicle mode weights, These are the scene weight coefficients, and the sum of all weights is 1. As a distance risk component, As a speed risk component, As a component of boundary risk, As a state risk component, Assign risk components to the scenario; Step S232: Add a coupling compensation term to the original risk fusion value to obtain the risk fusion value. :

[0015] in, This is the approach speed-distance coupling compensation coefficient; This is the boundary risk compensation coefficient.

[0016] This step can achieve the following technical effects: By adding a proximity velocity-distance coupling compensation term and a boundary risk compensation term to the weighted summation, risk gain correction is achieved for near-distance high-speed approach and near-boundary conditions, thereby improving the evaluation accuracy of the unified risk fusion model in extreme scenarios.

[0017] Preferably, in step S3, a graded safety control command is generated based on the risk level and sent to the vehicle actuator to perform the corresponding vehicle control operation, specifically including: If the risk level is Level 0, a "no braking control" command is generated, and the vehicle actuators drive normally without performing vehicle control operations. If the risk level is Level 1, a "speed limit control" command is generated, and the vehicle actuators perform the operation: reduce the vehicle's maximum permissible speed; If the risk level is Level 2, a "deceleration control" command is generated, and the vehicle actuator performs the operation: reducing the speed according to the preset deceleration curve; If the risk level is Level 3, an "emergency braking control" command is generated, and the vehicle actuators perform the operation: triggering rapid braking; Within the same control cycle, the above vehicle control actions are executed mutually exclusively, and follow the principle of higher-level actions covering lower-level actions.

[0018] This step can achieve the following technical effects: By mapping risk levels to a three-level progressive action chain of speed limit, deceleration, and emergency braking, and following the principle of higher levels covering lower levels, the traditional single emergency stop is replaced by graded intervention, reducing work interruptions caused by accidental triggering while ensuring safety.

[0019] Preferably, step S3 involves generating a control state switching instruction based on the risk fusion value and sending it to the control state machine to perform a takeover state switching, specifically including: Preset anti-shake design: takeover threshold With backoff threshold Separate settings, and ; If the risk fusion value is greater than or equal to the takeover threshold If the command is executed, a "Enter Safe Takeover State" instruction will be generated, the control state machine will switch to the safe takeover state, and the FAS-AEB system will actively take over vehicle control. If the risk fusion value is less than the takeover threshold And greater than the backoff threshold Then maintain normal control status; If the risk fusion value remains below the backoff threshold And the duration exceeds the stable time window If so, a "Enter recovery rollback state" instruction is generated, the control state machine switches to rollback state, and control is gradually handed over to the original control subject, gradually restoring the normal control state. If the risk fusion value remains below the backoff threshold However, the duration did not exceed the stable time window. If so, the current takeover status will remain and the timer will continue; In the normal control state, the vehicle is under the normal control of the current operating entity; the operating entities include: autonomous driving, local manual takeover, and remote takeover.

[0020] This step can achieve the following technical effects: By adopting a joint judgment mechanism that separates the takeover threshold and the rollback threshold and combines them with a stable time window, the effect of suppressing the frequent switching and jittering of control under boundary conditions is achieved. This balances the timeliness of takeover and the stability of recovery, and reduces control conflicts and repeated triggering.

[0021] Preferably, the security status indicator in step S4 includes: FAS-AEB system heartbeat flag, risk fusion value, risk level, current control status, current security control action, and timestamp.

[0022] This step can achieve the following technical effects: By periodically sending a security status identifier containing a heartbeat flag, risk value, and control status to multiple receivers through an independent security control signal link, an independent and secure communication channel is provided for all-time security monitoring and keep-alive detection, supporting the reliable triggering of graded failure protection.

[0023] Preferably, step S5 specifically includes: Step S51, continuously check for the following abnormalities: If any of the multiple receivers fails to receive a security status indicator within a preset timeout threshold; If any module in the FAS-AEB system times out without outputting, outputs an invalid value, or fails a self-test; Policy conflicts may occur, such as contradictions between security control instructions and temporary adjustment constraints, mismatch between control status and instruction source, and receiving mutually exclusive execution instructions within the same cycle. Step S52: If any of the above abnormal situations occur within the preset timeout threshold, the graded failure protection is triggered according to the duration of the abnormality. When the abnormality is detected to be resolved, the graded failure protection is exited and steps S1 to S4 are executed again in a loop. If no of the above abnormalities occur within the preset timeout threshold, steps S1 to S4 are executed continuously in a loop. The graded failure protection includes: If the anomaly lasts for less than 500ms, it is a short-term anomaly, which will trigger "speed limit protection" to restrict the maximum speed of the vehicle and suppress the growth of risk. If the duration of the abnormality is greater than or equal to 500ms and less than 2s, the "slow stop protection" will be triggered, and the vehicle will decelerate smoothly to a stop according to the preset deceleration curve. If the anomaly lasts for more than 2 seconds, the "vehicle control restriction protection" will be triggered, prohibiting the vehicle from moving and requiring manual intervention to restore it. When the abnormality is detected and resolved, the system recovers step by step in the opposite direction of the triggering sequence: first, the vehicle control protection is deactivated, then the slow stop protection is deactivated, and finally the speed limit protection is deactivated, until the normal control state is restored, thus avoiding secondary risks caused by the transition recovery.

[0024] This step can achieve the following technical effects: By triggering speed limits, slow stops, and vehicle control restrictions based on short-term, medium-term, and long-term anomalies respectively, and restoring them in reverse order, the system achieves vehicle controllability during short-term anomalies such as communication jitter and ensures safe parking during continuous anomalies, thus solving the problem of insufficient availability of the single-level "vehicle control restriction upon timeout" scheme.

[0025] Preferably, the control method for the all-time active safety automatic emergency braking system further includes a controlled temporary adjustment strategy, specifically including: A temporary adjustment request is initiated by the local manual driving console. The system sequentially performs permission authentication verification, time constraint verification, area constraint verification, and speed constraint verification. Once all verifications pass, the temporary adjustment of the safety control strategy is allowed. Full-time active safety control will be forcibly restored when any of the following conditions are met: the preset time limit is reached, the vehicle crosses the boundary, the vehicle exceeds the speed limit, a high-risk event is detected, or a restoration command is received. During the execution of the controlled temporary adjustment strategy, steps S1 to S4 are continuously executed in a loop to maintain risk assessment and alarm output; The permission authentication verification includes: whether the local manual control console has the authorization permission to adjust the temporary policy. When the permission level of the control console is not lower than the preset adjustment permission threshold, the verification passes. The time constraint verification includes: verifying whether the temporary adjustment duration of the request is within the maximum duration allowed by the system. If the request duration exceeds the upper limit, the verification fails and the adjustment request is rejected; if the request duration does not exceed the upper limit, the verification passes and the adjustment request is allowed. The area constraint verification includes: determining whether the current location of the vehicle allows for temporary strategy adjustments based on the electronic fence information; allowing adjustment requests and passing the verification only within preset adjustable areas, such as low-speed operation areas and specific loading and unloading areas; if the vehicle is in a high-risk area, the adjustment request is rejected and the verification fails, such as intersections, narrow passages, and densely populated pedestrian areas. The speed constraint verification includes: verifying whether the vehicle's current speed is within the allowable speed range, and allowing the adjustment request and passing the verification only when the vehicle speed is lower than a preset low speed threshold. The high-risk events include: a risk fusion value greater than or equal to the takeover threshold, a risk level reaching Level 3, emergency braking control under graded safety control being implemented, or boundary distance... Less than the preset boundary critical threshold wait.

[0026] This step can achieve the following technical effects: By implementing four-fold constraint verification based on permissions, timeliness, region, and speed, and by maintaining continuous online risk assessment and multi-condition triggering for forced recovery during the adjustment period, it is possible to temporarily relax safety control strategies in low-speed, precision operation scenarios, and also avoid long-term protection failures caused by human error.

[0027] Preferably, the control method for the all-time active safety automatic emergency braking system further includes optimizing the weight parameters in the unified risk fusion model using an adaptive weight learning mechanism, specifically including: Establish a sliding window buffer to store historical risk assessment samples, with each sample containing a historical risk fusion value. Risk level result label and scene parameters Where i is the time step index and the scene parameter Scenario parameters in the unified risk fusion model correspond; Construct the loss function L(w): , in, This represents the penalty coefficient for missed detections, where a real event occurs but the risk fusion value is low. This is the penalty coefficient for false alarms; there are no real events, but the risk fusion value is high. is the regularization coefficient, which determines the degree to which the constraint weights deviate from their initial values; This is the initial weight vector; To optimize weights; According to The target risk value mapped is derived retrospectively from actual results; it is a "label" pre-set by engineers based on experience or statistical data, used for training the model. The mapping relationship expression is: ; by For a period of time, the weight vector is updated using gradient descent and an adaptive learning rate strategy; The updated weights are subjected to normalization constraints, non-negativity constraints, change magnitude constraints, and exponential smoothing. When the false alarm rate or false negative rate exceeds the preset threshold, it will revert to the previous stable weight combination. The false positive rate refers to the proportion of samples whose output risk level reaches the intervention threshold when no dangerous event occurs, while the false negative rate refers to the proportion of samples whose output risk level is lower than the intervention threshold when a dangerous event occurs.

[0028] This step can achieve the following technical effects: By sampling historical samples through a sliding window, constructing an asymmetric loss function for gradient updates, and implementing weight constraints and anomaly backoff, the system achieves online optimization of cross-scenario risk fusion weights, reducing the risk of false triggering and missed detection in long-term operation and improving model robustness.

[0029] In addition, the present invention also provides a control device for a full-time active safety automatic emergency braking system, comprising: an information acquisition unit, a risk fusion assessment unit, a hierarchical safety control and state switching unit, an independent safety control signal unit, an anomaly monitoring and hierarchical failure protection unit, a controlled temporary strategy management unit, and a weight optimization unit; The information acquisition unit specifically includes: Collect environmental perception data, vehicle operating status data, takeover status data, boundary constraint data, and FAS-AEB system health data; perform time alignment, validity checks, and data preprocessing on the raw data; The risk fusion assessment unit specifically includes: Risk features are constructed based on the collected data and preprocessed to obtain standardized feature components. Based on the standardized feature components, a unified risk fusion model is used to calculate the risk fusion value, and the risk value is then smoothed over time and mapped to the risk level to output the risk level. The hierarchical security control and state switching unit specifically includes: Based on the risk level, a graded safety control instruction is generated and sent to the vehicle actuator to perform the corresponding vehicle control operation; based on the risk fusion value, a control status switching instruction is generated and sent to the control status machine to switch the takeover status. The independent safety control signal unit specifically includes: A safety status identifier is generated based on the risk level, control status, and vehicle control operation. An independent safety control signal link is established, and the safety status identifier is periodically sent through this link, simultaneously to multiple receiving ends. These multiple receiving ends include: the vehicle-side safety monitoring module of the FAS-AEB system, the local manual driver's console, and the remote monitoring center server. The safety status identifier includes: the FAS-AEB system heartbeat flag, risk fusion value, risk level, current control status, current vehicle control operation, and timestamp. The anomaly monitoring and graded failure protection unit specifically includes: Each receiving end receives a security status identifier; it continuously monitors the communication status, the status of each module in the FAS-AEB system, and policy conflicts, and monitors the reception of security status identifiers by each receiving end; if an anomaly is detected, it triggers graded failure protection based on the duration of the anomaly; when the anomaly is resolved, it exits graded failure protection and restarts the loop, executing the contents of the information acquisition unit, risk fusion assessment unit, graded security control and state switching unit, and independent security control signal unit in sequence; if no anomaly is detected, it continues to loop and execute the contents of the information acquisition unit, risk fusion assessment unit, graded security control and state switching unit, and independent security control signal unit in sequence. The controlled temporary policy management unit specifically includes: A temporary adjustment request is initiated by the local manual driving console. The system sequentially performs permission authentication verification, time constraint verification, area constraint verification, and speed constraint verification. Once all verifications pass, the temporary adjustment of the safety control strategy is allowed. Full-time active safety control will be forcibly restored when any of the following conditions are met: the preset time limit is reached, the vehicle crosses the boundary, the vehicle exceeds the speed limit, a high-risk event is detected, or a restoration command is received. During the execution of the controlled temporary adjustment strategy, the contents of the information collection unit, risk fusion assessment unit, hierarchical security control and state switching unit, and independent security control signal unit are continuously cyclically and sequentially executed to maintain risk assessment and alarm output. The weight optimization unit specifically includes: Establish a sliding window buffer to store historical risk assessment samples, with each sample containing a historical risk fusion value. Risk level result label and scene parameters Where i is the time step index and the scene parameter Scenario parameters in the unified risk fusion model correspond; Construct the loss function L(w): , in, This represents the penalty coefficient for missed detections, where a real event occurs but the risk fusion value is low. This is the penalty coefficient for false alarms; there are no real events, but the risk fusion value is high. is the regularization coefficient, which determines the degree to which the constraint weights deviate from their initial values; This is the initial weight vector; To optimize weights; According to The target risk value mapped is derived retrospectively from actual results; it is a "label" pre-set by engineers based on experience or statistical data, used for training the model. The mapping relationship expression is: ; by For a period of time, the weight vector is updated using gradient descent and an adaptive learning rate strategy; The updated weights are subjected to normalization constraints, non-negativity constraints, change magnitude constraints, and exponential smoothing. When the false alarm rate or false negative rate exceeds the preset threshold, it will revert to the previous stable weight combination. The false positive rate refers to the proportion of samples whose output risk level reaches the intervention threshold when no dangerous event occurs, while the false negative rate refers to the proportion of samples whose output risk level is lower than the intervention threshold when a dangerous event occurs.

[0030] The beneficial effects of this invention are as follows: Firstly, addressing the problem of existing solutions where a single emergency stop is easily triggered and leads to work interruptions, it reduces work interruptions while ensuring safety by adopting tiered safety control and progressive intervention instead of direct emergency stops. Secondly, addressing the issue of conflicting judgments arising from the independent parallel execution of obstacle triggering and electronic fence triggering, it calculates risk values ​​using a unified risk fusion model and uses this single risk source to simultaneously drive tiered safety control commands and control status switching commands, reducing the risk of inconsistency between the action chain and the control chain. Thirdly, addressing the insufficient availability of single-level failure protection, it improves system availability while ensuring a safety baseline by executing tiered failure protection based on the duration of the anomaly and restoring it in reverse order after the anomaly is resolved. Fourthly, addressing the issue of AEB being easily bypassed and creating safety blind spots during the takeover phase, it reduces the collision risk during the takeover phase by keeping AEB online throughout the entire process of autonomous driving, local takeover, and remote takeover.

[0031] Therefore, it is evident that the present invention has outstanding substantive features and significant progress compared with the prior art, and the beneficial effects of its implementation are also obvious. Attached Figure Description

[0032] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0033] Figure 1 This is a flowchart of a control method for a full-time active safety automatic emergency braking system provided by the present invention.

[0034] Figure 2 This is the risk triggering and control flowchart provided by the present invention.

[0035] Figure 3 This is a flowchart of hierarchical control and failure protection provided by the present invention.

[0036] Figure 4 This is a flowchart of the joint determination of control state machine with dual threshold and stable time window provided by the present invention.

[0037] Figure 5 This is a closed-loop flowchart of the adaptive weight learning mechanism provided by the present invention.

[0038] Figure 6 This is a flowchart of controlled temporary strategy adjustment and automatic recovery provided by the present invention.

[0039] Figure 7This is a schematic diagram of the control device for a full-time active safety automatic emergency braking system provided by the present invention.

[0040] Among them, 1-information acquisition unit, 2-risk fusion assessment unit, 3-hierarchical security control and state switching unit, 4-independent security control signal unit, 5-anomaly monitoring and hierarchical failure protection unit, 6-controlled temporary strategy management unit, and 7-weight optimization unit. Detailed Implementation

[0041] The present invention will now be described in detail with reference to the accompanying drawings and specific embodiments. The following embodiments are explanations of the present invention, but the present invention is not limited to the following implementation methods.

[0042] Example 1: like Figure 1 and Figure 2 As shown in the figure, the control method of a full-time active safety automatic emergency braking system provided in this embodiment includes the following steps: Step S1: Collect environmental perception data, vehicle operating status data, takeover status data, boundary constraint data, and FAS-AEB system health data; perform time alignment, validity checks, and data preprocessing on the raw data; Step S1 specifically includes: Step S11: Collect environmental perception data, vehicle operating status data, takeover status data, boundary constraint data, and FAS-AEB system health data at fixed intervals; The environmental perception data includes: obstacle type, obstacle location, and obstacle speed; Vehicle operating status data includes: vehicle speed, gear, braking status, and steering control status; Takeover status data includes: autonomous driving status, local manual takeover status, and remote takeover status; Boundary constraint data includes: electronic fence boundary distance, area attributes, operation scenario identifiers, and scenario parameters; among them, the electronic fence boundary distance is the shortest distance between the vehicle and the boundary, area attributes include high-risk areas, operation areas, etc., operation scenario identifiers include ports, mining areas, industrial parks, etc., and scenario parameters include area risk level, operation mode, etc. FAS-AEB system health data includes: module operating status, communication quality, and signal keep-alive status; Step S12: To avoid misjudgment caused by time mismatch of multi-source data, perform timestamp alignment and timeout removal on the collected data; Step S13: Perform a validity check on the raw data. The validity check includes: checking for null and outlier values, checking the physical rationality of coordinates and velocity, and checking the gear position. Step S14: Perform standardization processing on the data that passes the inspection to form a unified input vector.

[0043] This step can achieve the following technical effects: Ensuring the temporal consistency and physical rationality of multi-source input data provides standardized and alignable input features for subsequent risk fusion calculations, reducing the risk of misjudgment due to data anomalies or mismatches.

[0044] Step S2: Construct risk features based on the collected data and perform feature preprocessing to obtain standardized feature components; based on the standardized feature components, use a unified risk fusion model to calculate the risk fusion value, and perform time smoothing and risk level mapping on the risk value to output the risk level; Step S2 specifically includes: Step S21: Construct risk features based on the collected data. Risk features include: distance features, speed features, boundary features, vehicle speed features, state features, and scene features. Among them, distance features The relative distance between the vehicle and the obstacle is calculated based on the Euclidean distance between the obstacle's position and the vehicle's position. velocity characteristics The relative approach speed between the vehicle and the obstacle, based on the obstacle's speed. With the speed of the vehicle The relative approximation velocities between them are calculated as follows: The calculation method in the same direction is... The opposite calculation method is ; Boundary features The distance between the vehicle and the electronic fence boundary is calculated based on the shortest straight-line distance between the vehicle's position and the electronic fence boundary. Vehicle speed characteristics The vehicle's current speed is read from the vehicle's operating status data; State characteristics Read from the takeover status data, including: autonomous driving status, local manual takeover status, and remote takeover status; Scene features For scene parameters; Step S22: Perform validity verification and normalization on the risk features to obtain standardized feature components: , , , , , in, This is a numerical constraint function that limits the output to between 0 and 1, taking the boundary value if the value exceeds the range. As a distance risk component, The lower the value, the closer the distance and the higher the risk; As a speed risk component, A larger value indicates a faster approximation speed and a higher risk. As a component of boundary risk, The higher the value, the greater the risk as it approaches the electronic fence boundary; As a state risk component, The value represents the difference in risk sensitivity under different takeover conditions; Assess the risk level of a given scenario. Characterizes risk bias under different operational areas or scenario parameters; The preset distance safety threshold; This is a preset distance threshold. A low threshold for relative velocity is preset; A high threshold for relative velocity is preset; Preset boundary safety threshold; The preset boundary critical threshold; The mapping function from the takeover state to the state risk component; This is a mapping function from scene parameters to scene risk components; Step S23: Calculate the risk fusion value using a unified risk fusion model based on each standardized feature component; Step S24: To reduce the jumps in risk fusion values ​​caused by sensor jitter, the risk fusion values ​​are smoothed using a first-order low-pass filter. , in, This is a smoothing coefficient, with a value ranging from 0 to 1. The current time is the smoothed risk fusion value. This is the smoothed risk value from the previous time step. This represents the risk fusion value calculated using the unified risk fusion model at the current moment. Step S25: Map the smoothed risk fusion values ​​to risk levels and output the risk levels:

[0045] in, , , The preset risk level threshold, and Level 0 corresponds to no risk or very low risk; Level 1 corresponds to low risk; Level 2 corresponds to medium risk; Level 3 corresponds to high risk.

[0046] This step can achieve the following technical effects: By constructing multi-dimensional risk features including distance, speed, boundary, pattern, and scene, and performing normalization, weighted fusion, and coupling compensation, the system achieves the effect of uniformly quantizing multi-source heterogeneous inputs into risk values ​​in the range of 0 to 1 and mapping them to discrete levels, thus solving the conflict judgment problem caused by the independent parallel triggering of obstacles and electronic fences.

[0047] Step S23 specifically includes: Step S231, calculate the original risk fusion value :

[0048] in, The relative distance weight is 0.35. The relative velocity weight is 0.25. This is the boundary distance weight, with a value of 0.2. This represents the vehicle mode weight, with a value of 0.12. This is the scene weight coefficient, with a value of 0.08, and the sum of all weights is 1; As a distance risk component, As a speed risk component, As a component of boundary risk, As a state risk component, Assign risk components to the scenario; Step S232, based on the original risk fusion value By adding a coupling compensation term, the risk fusion value is obtained. :

[0049] in, This is the approach speed-distance coupling compensation coefficient; This is the boundary risk compensation coefficient.

[0050] This step can achieve the following technical effects: By adding a proximity velocity-distance coupling compensation term and a boundary risk compensation term to the weighted summation, risk gain correction is achieved for near-distance high-speed approach and near-boundary conditions, thereby improving the evaluation accuracy of the unified risk fusion model in extreme scenarios.

[0051] Step S3: Generate graded safety control instructions based on the risk level and send them to the vehicle actuators to perform corresponding vehicle control operations; generate control status switching instructions based on the risk fusion value and send them to the control status machine to switch the takeover status. In step S3, a graded safety control command is generated based on the risk level and sent to the vehicle actuator to perform the corresponding vehicle control operation, specifically including: If the risk level is Level 0, a "no braking control" command is generated, and the vehicle actuators drive normally without performing vehicle control operations. If the risk level is Level 1, a "speed limit control" command is generated, and the vehicle actuators perform the operation: reduce the vehicle's maximum permissible speed; If the risk level is Level 2, a "deceleration control" command is generated, and the vehicle actuator performs the operation: reducing the speed according to the preset deceleration curve; If the risk level is Level 3, an "emergency braking control" command is generated, and the vehicle actuators perform the operation: triggering rapid braking; Within the same control cycle, the above vehicle control actions are executed mutually exclusively, and follow the principle of higher-level actions covering lower-level actions.

[0052] This step can achieve the following technical effects: By mapping risk levels to a three-level progressive action chain of speed limit, deceleration, and emergency braking, and following the principle of higher levels covering lower levels, the traditional single emergency stop is replaced by graded intervention, reducing work interruptions caused by accidental triggering while ensuring safety.

[0053] In step S3, a control state switching instruction is generated based on the risk fusion value and sent to the control state machine to perform a takeover state switching. Specifically, this includes: Preset anti-shake design: such as Figure 4 As shown, the takeover threshold With backoff threshold Separate settings, and Stable time window The value range is set to 1s to 3s; If the risk fusion value is greater than or equal to the takeover threshold If the command is executed, a "Enter Safe Takeover State" instruction will be generated, the control state machine will switch to the safe takeover state, and the FAS-AEB system will actively take over vehicle control. If the risk fusion value is less than the takeover threshold And greater than the backoff threshold Then maintain normal control status; If the risk fusion value remains below the backoff threshold And the duration exceeds the stable time window If so, a "Enter recovery rollback state" instruction is generated, the control state machine switches to rollback state, and control is gradually handed over to the original control subject, gradually restoring the normal control state. If the risk fusion value remains below the backoff threshold However, the duration did not exceed the stable time window. If so, the current takeover status will remain and the timer will continue; In the normal control state, the vehicle is under the normal control of the current operating entity; the operating entities include: autonomous driving, local manual takeover, and remote takeover.

[0054] This step can achieve the following technical effects: By adopting a joint judgment mechanism that separates the takeover threshold and the rollback threshold and combines them with a stable time window, the effect of suppressing the frequent switching and jittering of control under boundary conditions is achieved. This balances the timeliness of takeover and the stability of recovery, and reduces control conflicts and repeated triggering.

[0055] Step S4: Generate a safety status identifier based on the risk level, control status, and vehicle control operation; establish an independent safety control signal link, and periodically send the safety status identifier through the independent safety control signal link, while simultaneously sending it to multiple receiving ends; wherein, the multiple receiving ends include: the vehicle-side safety monitoring module of the FAS-AEB system, the local manual driver's console operation end, and the remote monitoring center server end; The security status indicator in step S4 includes: FAS-AEB system heartbeat flag, risk fusion value, risk level, current control status, current safety control action, and timestamp; This step can achieve the following technical effects: By periodically sending a security status identifier containing a heartbeat flag, risk value, and control status to multiple receivers through an independent security control signal link, an independent and secure communication channel is provided for all-time security monitoring and keep-alive detection, supporting the reliable triggering of graded failure protection.

[0056] Step S5: Each receiving end receives the security status identifier; continuously monitors the communication status, the status of each module in the FAS-AEB system, and policy conflicts, and monitors the reception of the security status identifier by each receiving end; if an anomaly is detected, the hierarchical failure protection is triggered according to the duration of the anomaly; when the anomaly is resolved, the hierarchical failure protection is exited and steps S1 to S4 are executed again in a loop; if no anomaly is detected, steps S1 to S4 are executed continuously in a loop. like Figure 3 As shown, step S5 specifically includes: Step S51, continuously check for the following abnormalities: If any of the multiple receivers fails to receive a security status indicator within a preset timeout threshold; If any module in the FAS-AEB system times out without outputting, outputs an invalid value, or fails a self-test; Policy conflicts may occur, such as contradictions between security control instructions and temporary adjustment constraints, mismatch between control status and instruction source, and receiving mutually exclusive execution instructions within the same cycle. Step S52: If any of the above abnormal situations occur within the preset timeout threshold, the graded failure protection is triggered according to the duration of the abnormality. When the abnormality is detected to be resolved, the graded failure protection is exited and steps S1 to S4 are executed again in a loop. If no of the above abnormalities occur within the preset timeout threshold, steps S1 to S4 are executed continuously in a loop. like Figure 3 As shown, the graded failure protection includes: If the anomaly lasts for less than 500ms, it is a short-term anomaly, which will trigger "speed limit protection" to restrict the maximum speed of the vehicle and suppress the growth of risk. If the duration of the abnormality is greater than or equal to 500ms and less than 2s, the "slow stop protection" will be triggered, and the vehicle will decelerate smoothly to a stop according to the preset deceleration curve. If the anomaly lasts for more than 2 seconds, the "vehicle control restriction protection" will be triggered, prohibiting the vehicle from moving and requiring manual intervention to restore it. When the abnormality is detected and resolved, the system recovers step by step in the opposite direction of the triggering sequence: first, the vehicle control protection is deactivated, then the slow stop protection is deactivated, and finally the speed limit protection is deactivated, until the normal control state is restored, thus avoiding secondary risks caused by the transition recovery.

[0057] This step can achieve the following technical effects: By triggering speed limits, slow stops, and vehicle control restrictions based on short-term, medium-term, and long-term anomalies respectively, and restoring them in reverse order, the system achieves vehicle controllability during short-term anomalies such as communication jitter and ensures safe parking during continuous anomalies, thus solving the problem of insufficient availability of the single-level "vehicle control restriction upon timeout" scheme.

[0058] This embodiment provides a control method for a full-time active safety automatic emergency braking system, which further includes a controlled temporary adjustment strategy, specifically including: like Figure 6 As shown, a temporary adjustment request is initiated by the local manual driving console, and permission authentication verification, time constraint verification, area constraint verification, and speed constraint verification are executed in sequence. After all verifications pass, the temporary adjustment of the safety control strategy is allowed. When any of the following conditions occur, full-time active safety control will be forcibly restored: the preset time limit is reached, the vehicle crosses the boundary, the vehicle exceeds the speed limit, a high-risk event is detected, or a restoration command is received. During the execution of the controlled temporary adjustment strategy, steps S1 to S4 are continuously executed in a loop to maintain risk assessment and alarm output; The permission authentication verification includes: whether the local manual control console has the authorization permission to adjust the temporary policy. When the permission level of the control console is not lower than the preset adjustment permission threshold, the verification passes. The timeliness constraint verification includes: verifying whether the temporary adjustment duration of the request is within the maximum duration allowed by the system. The maximum duration of a single temporary policy adjustment is 5 to 15 minutes. If the request duration exceeds the maximum, the verification fails and the adjustment request is rejected; if the request duration does not exceed the maximum, the verification passes and the adjustment request is allowed. The area constraint verification includes: determining whether the current location of the vehicle allows for temporary strategy adjustments based on the electronic fence information; allowing adjustment requests and passing the verification only within preset adjustable areas, such as low-speed operation areas and specific loading and unloading areas; if the vehicle is in a high-risk area, the adjustment request is rejected and the verification fails, such as intersections, narrow passages, and densely populated pedestrian areas. The speed constraint verification includes: verifying whether the vehicle's current speed is within the allowable speed range, and allowing temporary adjustments only when the vehicle speed is below 5km / h, and passing the verification. The high-risk events include: a risk fusion value greater than or equal to the takeover threshold, a risk level reaching Level 3, emergency braking control under graded safety control being implemented, or boundary distance... Less than the preset boundary critical threshold wait.

[0059] This step can achieve the following technical effects: By implementing four-fold constraint verification based on permissions, timeliness, region, and speed, and by maintaining continuous online risk assessment and multi-condition triggering for forced recovery during the adjustment period, it is possible to temporarily relax safety control strategies in low-speed, precision operation scenarios, and also avoid long-term protection failures caused by human error.

[0060] This embodiment provides a control method for a full-time active safety automatic emergency braking system, which further includes optimizing the weight parameters in the unified risk fusion model using an adaptive weight learning mechanism, specifically including: like Figure 5 As shown, a sliding window buffer is established to store historical risk assessment samples, with each sample containing a historical risk fusion value. Risk level result label and scene parameters Where i is the time step index and the scene parameter Scenario parameters in the unified risk fusion model correspond; Construct the loss function L(w): , in, This represents the penalty coefficient for missed detections, where a real event occurs but the risk fusion value is low. This is the penalty coefficient for false alarms; there are no real events, but the risk fusion value is high. is the regularization coefficient, which determines the degree to which the constraint weights deviate from their initial values; This is the initial weight vector; To optimize weights; According to The target risk value mapped is derived retrospectively from actual results; it is a "label" pre-set by engineers based on experience or statistical data, used for training the model. The mapping relationship expression is: ; by For a given period, the weight vector is updated using gradient descent: , in, This is the updated weight vector; The weight vector before the update; η The learning rate is calculated using an adaptive learning rate strategy: ; in, The initial learning rate is set to 0.05. The attenuation amount is set to 0.02; This refers to the number of times the system runs. The updated weights are subjected to normalization constraints, non-negativity constraints, change magnitude constraints, and exponential smoothing. The normalization constraint expression is as follows: ; The expression for the nonnegativity constraint is: ; The expression for the constraint on the magnitude of change is: ; The exponential smoothing expression is as follows: ; When the false alarm rate or false negative rate exceeds the preset threshold, it will revert to the previous stable weight combination. The false positive rate refers to the proportion of samples whose output risk level reaches the intervention threshold when no dangerous event occurs, while the false negative rate refers to the proportion of samples whose output risk level is lower than the intervention threshold when a dangerous event occurs.

[0061] This step can achieve the following technical effects: By sampling historical samples through a sliding window, constructing an asymmetric loss function for gradient updates, and implementing weight constraints and anomaly backoff, the system achieves online optimization of cross-scenario risk fusion weights, reducing the risk of false triggering and missed detection in long-term operation and improving model robustness.

[0062] Example 2: like Figure 7 As shown, this embodiment provides a control device for a full-time active safety automatic emergency braking system, including: an information acquisition unit 1, a risk fusion assessment unit 2, a hierarchical safety control and state switching unit 3, an independent safety control signal unit 4, an anomaly monitoring and hierarchical failure protection unit 5, a controlled temporary strategy management unit 6, and a weight optimization unit 7. The information acquisition unit 1 specifically includes: Collect environmental perception data, vehicle operating status data, takeover status data, boundary constraint data, and FAS-AEB system health data; perform time alignment, validity checks, and data preprocessing on the raw data; The risk fusion assessment unit 2 specifically includes: Risk features are constructed based on the collected data and preprocessed to obtain standardized feature components. Based on the standardized feature components, a unified risk fusion model is used to calculate the risk fusion value, and the risk value is then smoothed over time and mapped to the risk level to output the risk level. The hierarchical security control and state switching unit 3 specifically includes: Based on the risk level, a graded safety control instruction is generated and sent to the vehicle actuator to perform the corresponding vehicle control operation; based on the risk fusion value, a control status switching instruction is generated and sent to the control status machine to switch the takeover status. The independent safety control signal unit 4 specifically includes: A safety status identifier is generated based on the risk level, control status, and vehicle control operation. An independent safety control signal link is established, and the safety status identifier is periodically sent through this link, simultaneously to multiple receiving ends. These multiple receiving ends include: the vehicle-side safety monitoring module of the FAS-AEB system, the local manual driver's console, and the remote monitoring center server. The safety status identifier includes: the FAS-AEB system heartbeat flag, risk fusion value, risk level, current control status, current vehicle control operation, and timestamp. The anomaly monitoring and graded failure protection unit 5 specifically includes: Each receiving end receives a security status identifier; it continuously monitors the communication status, the status of each module in the FAS-AEB system, and policy conflicts, and monitors the reception of security status identifiers by each receiving end; if an anomaly is detected, it triggers graded failure protection based on the duration of the anomaly; when the anomaly is resolved, it exits graded failure protection and restarts the loop, executing the contents of information acquisition unit 1, risk fusion assessment unit 2, graded security control and state switching unit 3, and independent security control signal unit 4 in sequence; if no anomaly is detected, it continues to loop and execute the contents of information acquisition unit 1, risk fusion assessment unit 2, graded security control and state switching unit 3, and independent security control signal unit 4 in sequence. The controlled temporary policy management unit 6 specifically includes: A temporary adjustment request is initiated by the local manual driving console. The system sequentially performs permission authentication verification, time constraint verification, area constraint verification, and speed constraint verification. Once all verifications pass, the temporary adjustment of the safety control strategy is allowed. Full-time active safety control will be forcibly restored when any of the following conditions are met: the preset time limit is reached, the vehicle crosses the boundary, the vehicle exceeds the speed limit, a high-risk event is detected, or a restoration command is received. During the execution of the controlled temporary adjustment strategy, the contents of information collection unit 1, risk fusion assessment unit 2, hierarchical security control and state switching unit 3, and independent security control signal unit 4 are continuously cyclically and sequentially executed to maintain risk assessment and alarm output. The weight optimization unit 7 specifically includes: Establish a sliding window buffer to store historical risk assessment samples, with each sample containing a historical risk fusion value. Risk level result label and scene parameters Where i is the time step index and the scene parameter Scenario parameters in the unified risk fusion model correspond; Construct the loss function L(w): , in, This represents the penalty coefficient for missed detections, where a real event occurs but the risk fusion value is low. This is the penalty coefficient for false alarms; there are no real events, but the risk fusion value is high. is the regularization coefficient, which determines the degree to which the constraint weights deviate from their initial values; This is the initial weight vector; To optimize weights; According to The target risk value mapped is derived retrospectively from actual results; it is a "label" pre-set by engineers based on experience or statistical data, used for training the model. The mapping relationship expression is: ; by For a period of time, the weight vector is updated using gradient descent and an adaptive learning rate strategy; The updated weights are subjected to normalization constraints, non-negativity constraints, change magnitude constraints, and exponential smoothing. When the false alarm rate or false negative rate exceeds the preset threshold, it will revert to the previous stable weight combination. The false positive rate refers to the proportion of samples whose output risk level reaches the intervention threshold when no dangerous event occurs, while the false negative rate refers to the proportion of samples whose output risk level is lower than the intervention threshold when a dangerous event occurs.

[0063] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. The methods disclosed in the embodiments are described simply because they correspond to the systems disclosed in the embodiments; relevant details can be found in the method section.

[0064] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.

[0065] In the embodiments provided by this invention, it should be understood that the disclosed systems, methods, and approaches can be implemented in other ways. For example, the system embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between systems or units may be electrical, mechanical, or other forms.

[0066] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0067] In addition, the functional modules in the various embodiments of the present invention can be integrated into one processing unit, or each module can exist physically separately, or two or more modules can be integrated into one unit.

[0068] Similarly, in the various embodiments of the present invention, each processing unit can be integrated into a functional module, or each processing unit can exist physically, or two or more processing units can be integrated into a functional module.

[0069] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.

[0070] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0071] The above-disclosed embodiments are merely preferred embodiments of the present invention, but the present invention is not limited thereto. Any non-creative changes that can be conceived by those skilled in the art, as well as any improvements and modifications made without departing from the principles of the present invention, should fall within the protection scope of the present invention.

Claims

1. A control method for a full-time active safety automatic emergency braking system, characterized in that, Includes the following steps: Step S1: Collect environmental perception data, vehicle operating status data, takeover status data, boundary constraint data, and FAS-AEB system health data; perform time alignment, validity checks, and data preprocessing on the raw data; Step S2: Construct risk features based on the collected data and perform feature preprocessing to obtain standardized feature components; Based on standardized feature components, a unified risk fusion model is used to calculate the risk fusion value, and the risk value is smoothed over time and mapped to the risk level to output the risk level. Step S3: Generate graded safety control instructions based on the risk level and send them to the vehicle actuators to perform the corresponding vehicle control operations; Based on the risk fusion value, a control state switching instruction is generated and sent to the control state machine to perform a takeover state switching. Step S4: Generate a safety status identifier based on the risk level, control status, and vehicle control operation. An independent safety control signal link is established, and a safety status identifier is periodically sent to multiple receiving ends through this link. These multiple receiving ends include: the vehicle-side safety monitoring module of the FAS-AEB system, the local manual driver's console, and the remote monitoring center server. The safety status identifier includes: the FAS-AEB system heartbeat flag, risk fusion value, risk level, current control status, current vehicle control operation, and timestamp. Step S5: Each receiving end receives the security status identifier; continuously monitors the communication status, the status of each module in the FAS-AEB system, and policy conflicts, and monitors the reception of the security status identifier by each receiving end; if an anomaly is detected, the hierarchical failure protection is triggered according to the duration of the anomaly; when the anomaly is resolved, the hierarchical failure protection is exited and steps S1 to S4 are executed again in a loop; if no anomaly is detected, steps S1 to S4 are executed continuously in a loop.

2. The control method for a full-time active safety automatic emergency braking system according to claim 1, characterized in that, Step S1 specifically includes: Step S11: Collect environmental perception data, vehicle operating status data, takeover status data, boundary constraint data, and FAS-AEB system health data at fixed intervals; The environmental perception data includes: obstacle type, obstacle location, and obstacle speed; Vehicle operating status data includes: vehicle speed, gear, braking status, and steering control status; Takeover status data includes: autonomous driving status, local manual takeover status, and remote takeover status; Boundary constraint data includes: electronic fence boundary distance, area attributes, operation scenario identifiers, and scenario parameters; among them, the electronic fence boundary distance is the shortest distance between the vehicle and the boundary, area attributes include high-risk areas and operation areas, operation scenario identifiers include ports, mining areas, and industrial parks, and scenario parameters include area risk level and operation mode. FAS-AEB system health data includes: module operating status, communication quality, and signal keep-alive status; Step S12: Perform timestamp alignment and timeout removal on the collected data; Step S13: Perform a validity check on the raw data. The validity check includes: checking for null and outlier values, checking the physical rationality of coordinates and velocity, and checking the gear position. Step S14: Perform standardization processing on the data that passes the inspection.

3. The control method for a full-time active safety automatic emergency braking system according to claim 1, characterized in that, Step S2 specifically includes: Step S21: Construct risk features based on the collected data. Risk features include: distance features, speed features, boundary features, vehicle speed features, state features, and scene features. Among them, distance features The relative distance between the vehicle and the obstacle is calculated based on the Euclidean distance between the obstacle's position and the vehicle's position. velocity characteristics The relative approach speed between the vehicle and the obstacle, based on the obstacle's speed. With the speed of the vehicle The relative approximation velocities between them are calculated as follows: The calculation method in the same direction is... The opposite calculation method is ; Boundary features The distance between the vehicle and the electronic fence boundary is calculated based on the shortest straight-line distance between the vehicle's position and the electronic fence boundary. Vehicle speed characteristics The vehicle's current speed is read from the vehicle's operating status data; State characteristics Read from the takeover status data, including: autonomous driving status, local manual takeover status, and remote takeover status; Scene features For scene parameters; Step S22 involves performing feature preprocessing operations on the risk features to verify their validity and normalize them, resulting in standardized feature components: , , , , , in, This is a numerical constraint function that limits the output to between 0 and 1, taking the boundary value if it exceeds the range. As a distance risk component, As a speed risk component, As a component of boundary risk, As a state risk component, Assign risk components to the scenario; To preset a safe distance threshold, To set a preset distance threshold, Distance features; To preset a low threshold for relative velocity, To preset a high threshold for relative velocity, It is a velocity characteristic; To preset the boundary safety threshold, To preset the boundary critical threshold, Boundary features; The mapping function from the takeover state to the state risk component. State characteristics; This is the mapping function from scene parameters to scene risk components. For scene features; Step S23: Calculate the risk fusion value using a unified risk fusion model based on each standardized feature component; Step S24: Smooth the risk fusion value using a first-order low-pass filter; Step S25: Map the smoothed risk fusion values ​​to risk levels and output the risk levels: in, , , The preset risk level threshold, and Level 0 corresponds to no risk or very low risk; Level 1 corresponds to low risk; Level 2 corresponds to medium risk; Level 3 corresponds to high risk.

4. The control method for a full-time active safety automatic emergency braking system according to claim 3, characterized in that, Step S23 specifically includes: Step S231, calculate the original risk fusion value : in, The weights are relative distances. As relative velocity weights, For boundary distance weights, As for vehicle mode weights, These are the scene weight coefficients, and the sum of all weights is 1. As a distance risk component, As a speed risk component, As a component of boundary risk, As a state risk component, Assign risk components to the scenario; Step S232: Add a coupling compensation term to the original risk fusion value to obtain the risk fusion value. : in, This is the proximity speed-distance coupling compensation coefficient; This is the boundary risk compensation coefficient.

5. The control method for a full-time active safety automatic emergency braking system according to claim 1, characterized in that, In step S3, a graded safety control command is generated based on the risk level and sent to the vehicle actuator to perform the corresponding vehicle control operation, specifically including: If the risk level is Level 0, a "no braking control" command is generated, and the vehicle actuators drive normally without performing vehicle control operations. If the risk level is Level 1, a "speed limit control" command is generated, and the vehicle actuators perform the operation: reduce the vehicle's maximum permissible speed; If the risk level is Level 2, a "deceleration control" command is generated, and the vehicle actuator performs the operation: reducing the speed according to the preset deceleration curve; If the risk level is Level 3, an "emergency braking control" command is generated, and the vehicle actuators perform the operation: triggering rapid braking; Within the same control cycle, the above vehicle control actions are executed mutually exclusively, and follow the principle of higher-level actions covering lower-level actions.

6. The control method for a full-time active safety automatic emergency braking system according to claim 1, characterized in that, In step S3, a control state switching instruction is generated based on the risk fusion value and sent to the control state machine to perform a takeover state switching. Specifically, this includes: Preset anti-shake design: takeover threshold With backoff threshold Separate settings, and ; If the risk fusion value is greater than or equal to the takeover threshold If the command is executed, a "Enter Safe Takeover State" instruction will be generated, the control state machine will switch to the safe takeover state, and the FAS-AEB system will actively take over vehicle control. If the risk fusion value is less than the takeover threshold And greater than the backoff threshold Then maintain normal control status; If the risk fusion value remains below the backoff threshold And the duration exceeds the stable time window If so, a "Enter recovery rollback state" instruction is generated, the control state machine switches to rollback state, and control is gradually handed over to the original control subject, gradually restoring the normal control state. If the risk fusion value remains below the backoff threshold However, the duration did not exceed the stable time window. If so, the current takeover status will remain and the timer will continue; In the normal control state, the vehicle is under the normal control of the current operating entity; the operating entities include: autonomous driving, local manual takeover, and remote takeover.

7. The control method for a full-time active safety automatic emergency braking system according to claim 1, characterized in that, Step S5 specifically includes: Step S51, continuously check for the following abnormalities: If any of the multiple receivers fails to receive a security status indicator within a preset timeout threshold; If any module in the FAS-AEB system times out without outputting, outputs an invalid value, or fails a self-test; The following situations may occur: contradictions between security control instructions and temporary adjustment constraints; mismatch between control status and instruction source; and policy conflicts arising from receiving mutually exclusive execution instructions within the same cycle. Step S52: If any of the above abnormal situations occur within the preset timeout threshold, the graded failure protection is triggered according to the duration of the abnormality. When the abnormality is detected to be resolved, the graded failure protection is exited and steps S1 to S4 are executed again in a loop. If no of the above abnormalities occur within the preset timeout threshold, steps S1 to S4 are executed continuously in a loop. The graded failure protection includes: If the anomaly lasts for less than 500ms, the "speed limit protection" will be triggered, limiting the vehicle's maximum permissible speed. If the duration of the abnormality is greater than or equal to 500ms and less than 2s, the "slow stop protection" will be triggered, and the vehicle will decelerate smoothly to a stop according to the preset deceleration curve. If the anomaly lasts for more than 2 seconds, the "vehicle control restriction protection" will be triggered, prohibiting vehicle movement and requiring manual intervention to restore the vehicle. When the abnormality is detected and resolved, the system recovers step by step in the reverse order of the triggering sequence: first, the vehicle control protection is deactivated, then the slow stop protection is deactivated, and finally the speed limit protection is deactivated, until the normal control state is restored.

8. The control method for a full-time active safety automatic emergency braking system according to claim 1, characterized in that, This also includes controlled temporary adjustment strategies, specifically including: A temporary adjustment request is initiated by the local human operator console. The system sequentially performs permission authentication verification, time constraint verification, area constraint verification, and speed constraint verification. Once all verifications are passed, the temporary adjustment of the safety policy is allowed. Full-time active safety control will be forcibly restored when any of the following conditions are met: the time limit is reached, the vehicle crosses the boundary, the vehicle exceeds the speed limit, a high-risk event is detected, or a restoration command is received. During the execution of the controlled temporary adjustment strategy, steps S1 to S4 are continuously executed in a loop to maintain risk assessment and alarm output; The permission authentication verification includes: whether the local manual control console has the authorization permission to adjust the temporary policy. When the permission level of the control console is not lower than the preset adjustment permission threshold, the verification passes. The time constraint verification includes: verifying whether the temporary adjustment duration of the request is within the maximum duration allowed by the system. If the request duration exceeds the upper limit, the verification fails and the adjustment request is rejected; if the request duration does not exceed the upper limit, the verification passes and the adjustment request is allowed. The area constraint verification includes: determining whether the current location of the vehicle allows for temporary policy adjustments based on the electronic fence information; allowing adjustment requests and passing the verification only within the preset adjustable area; and rejecting adjustment requests and failing the verification if the vehicle is in a high-risk area. The speed constraint verification includes: verifying whether the vehicle's current speed is within the allowable speed range, and allowing the adjustment request and passing the verification only when the vehicle speed is lower than a preset low speed threshold. The high-risk events include: a risk fusion value greater than or equal to the takeover threshold, a risk level reaching Level 3, emergency braking control under graded safety control being implemented, or boundary distance... Less than the preset boundary critical threshold .

9. The control method for a full-time active safety automatic emergency braking system according to claim 1, characterized in that, It also includes optimizing the weight parameters in the unified risk fusion model using an adaptive weight learning mechanism, specifically including: Establish a sliding window buffer to store historical risk assessment samples, with each sample containing a historical risk fusion value. Risk level result label and scene parameters Where i is the time step index and the scene parameter Scenario parameters in the unified risk fusion model correspond; Construct the loss function L(w): , in, This is the penalty coefficient for missed detection; This is the penalty coefficient for false alarms; is the regularization coefficient, which determines the degree to which the constraint weights deviate from their initial values; This is the initial weight vector; To optimize weights; According to The target risk value being mapped, and the mapping relationship expression are as follows: ; by For a period of time, the weight vector is updated using gradient descent and an adaptive learning rate strategy; The updated weights are subjected to normalization constraints, non-negativity constraints, change magnitude constraints, and exponential smoothing. When the false alarm rate or false negative rate exceeds the preset threshold, it will revert to the previous stable weight combination. The false positive rate refers to the proportion of samples whose output risk level reaches the intervention threshold when no dangerous event occurs, while the false negative rate refers to the proportion of samples whose output risk level is lower than the intervention threshold when a dangerous event occurs.

10. A control device for a full-time active safety automatic emergency braking system, characterized in that, include: Information acquisition unit, risk fusion assessment unit, hierarchical security control and state switching unit, independent security control signal unit, anomaly monitoring and hierarchical failure protection unit, controlled temporary strategy management unit, weight optimization unit; The information acquisition unit specifically includes: Collect environmental perception data, vehicle operating status data, takeover status data, boundary constraint data, and FAS-AEB system health data; perform time alignment, validity checks, and data preprocessing on the raw data; The risk fusion assessment unit specifically includes: Risk features are constructed based on the collected data and preprocessed to obtain standardized feature components. Based on the standardized feature components, a unified risk fusion model is used to calculate the risk fusion value, and the risk value is then smoothed over time and mapped to the risk level to output the risk level. The hierarchical security control and state switching unit specifically includes: Based on the risk level, a graded safety control instruction is generated and sent to the vehicle actuator to perform the corresponding vehicle control operation; based on the risk fusion value, a control status switching instruction is generated and sent to the control status machine to switch the takeover status. The independent safety control signal unit specifically includes: A safety status identifier is generated based on the risk level, control status, and vehicle control operation. An independent safety control signal link is established, and the safety status identifier is periodically sent through this link, simultaneously to multiple receiving ends. These multiple receiving ends include: the vehicle-side safety monitoring module of the FAS-AEB system, the local manual driver's console, and the remote monitoring center server. The safety status identifier includes: the FAS-AEB system heartbeat flag, risk fusion value, risk level, current control status, current vehicle control operation, and timestamp. The anomaly monitoring and graded failure protection unit specifically includes: Each receiving end receives a security status identifier; it continuously monitors the communication status, the status of each module in the FAS-AEB system, and policy conflicts, and monitors the reception of security status identifiers by each receiving end; if an anomaly is detected, it triggers graded failure protection based on the duration of the anomaly; when the anomaly is resolved, it exits graded failure protection and restarts the loop, executing the contents of the information acquisition unit, risk fusion assessment unit, graded security control and state switching unit, and independent security control signal unit in sequence; if no anomaly is detected, it continues to loop and execute the contents of the information acquisition unit, risk fusion assessment unit, graded security control and state switching unit, and independent security control signal unit in sequence.