Safety evaluation method of autonomous vehicle, storage medium and electronic device
By using white-box piling-in testing, the predetermined functional units of autonomous vehicles are evaluated, which solves the problem of the lack of consideration of the inherent safety of the vehicle and achieves a comprehensive and accurate safety evaluation.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- PURPLE MOUNTAIN LAB
- Filing Date
- 2023-01-18
- Publication Date
- 2026-05-29
AI Technical Summary
Existing technologies do not take into account the inherent safety of vehicles, resulting in significant limitations in the safety assessment of autonomous vehicles and a lack of objectivity in the evaluation.
The white-box piling-in test method is used to perform pre-set white-box piling-in tests on the predetermined functional units of autonomous vehicles to obtain intrinsic safety scores. Combined with the individual vehicle and cooperative safety scores, the safety of the vehicle is comprehensively evaluated.
It achieves comprehensiveness and objectivity in the safety assessment of autonomous vehicles, improves the accuracy of the evaluation, and comprehensively considers the inherent safety of the vehicle, individual vehicle safety, and collaborative safety.
Smart Images

Figure CN116109188B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of autonomous driving safety evaluation technology, and more specifically, to a safety assessment method, storage medium, and electronic device for autonomous vehicles. Background Technology
[0002] With the rapid development of technologies such as swarm intelligence, edge computing, and cloud services, vehicle-road cooperation has become an important way to achieve large-scale deployment of autonomous driving. Vehicle-road cooperation comprehensively utilizes various devices on the roadside, in-vehicle, and in the cloud, significantly improving the perception and decision-making capabilities of autonomous driving systems through collaborative perception and collaborative decision-making control, thereby reducing the cost of autonomous driving. However, the safety evaluation methods for autonomous driving in related technologies focus on evaluating the functions of a single vehicle's autonomous driving system, without considering factors such as the inherent safety of key vehicle components and intelligent collaboration, and do not address evaluation methods for vehicle-specific safety. Furthermore, for autonomous vehicles, the software code of their autonomous driving systems reaches hundreds of millions of lines, and the components come from a wide range of sources. In the open-source ecosystem and the interconnected industrial structure, system vulnerabilities cannot be thoroughly investigated, vulnerabilities and backdoors cannot be exhaustively identified, and potential random failures cannot be fully considered. For traditional internet components, these hazards are relatively controllable, but for life-or-death autonomous vehicles, a technical approach that only defends against known threats is unacceptable. Penetration testing-based security evaluations of key components are no longer comprehensive enough in the field of autonomous driving.
[0003] There is currently no effective solution to the above problems. Summary of the Invention
[0004] This invention provides a safety assessment method, storage medium, and electronic device for autonomous vehicles, to at least address the technical problem in related technologies that the failure to consider the inherent safety of vehicles leads to significant limitations in the safety assessment of autonomous vehicles and unsatisfactory objectivity.
[0005] According to one aspect of the present invention, a safety assessment method for an autonomous vehicle is provided, comprising: performing a preset white-box piling test on predetermined functional units of the autonomous vehicle to obtain an intrinsic safety score of the autonomous vehicle; obtaining a single-vehicle safety score and a collaborative safety score of the autonomous vehicle, wherein the single-vehicle safety score is used to indicate the driving safety of the autonomous vehicle in a single-vehicle driving scenario, and the collaborative safety score is used to indicate the driving safety of the autonomous vehicle in a multi-vehicle driving scenario; and obtaining a comprehensive safety score of the autonomous vehicle based on the intrinsic safety score, the single-vehicle safety score, and the collaborative safety score.
[0006] According to another aspect of the present invention, a non-volatile storage medium is provided, the non-volatile storage medium storing a plurality of instructions adapted for loading by a processor and executing any one of the safety assessment methods for autonomous vehicles described herein.
[0007] According to another aspect of the present invention, an electronic device is provided, comprising: one or more processors and a memory, the memory being used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors cause the one or more processors to implement any one of the safety assessment methods for autonomous vehicles.
[0008] In this embodiment of the invention, a white-box instrumentation testing method is employed. By performing pre-defined white-box instrumentation tests on predetermined functional units of an autonomous vehicle, the intrinsic safety score of the autonomous vehicle is obtained. The individual vehicle safety score and the collaborative safety score of the autonomous vehicle are then acquired. The individual vehicle safety score indicates the driving safety of the autonomous vehicle in a single-vehicle driving scenario, and the collaborative safety score indicates the driving safety of the autonomous vehicle in a multi-vehicle driving scenario. Based on the intrinsic safety score, the individual vehicle safety score, and the collaborative safety score, the comprehensive safety score of the autonomous vehicle is obtained. This achieves the goal of improving the comprehensiveness of the autonomous driving safety assessment by utilizing white-box instrumentation testing. It realizes the technical effect of comprehensively considering the vehicle's intrinsic safety, individual vehicle safety, and collaborative safety, thereby obtaining an objective and accurate autonomous driving safety evaluation. This solves the technical problem in related technologies where the failure to consider the vehicle's intrinsic safety leads to significant limitations in the safety assessment of autonomous vehicles and unsatisfactory objectivity. Attached Figure Description
[0009] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this application, illustrate exemplary embodiments of the invention and, together with their description, serve to explain the invention and do not constitute an undue limitation thereof. In the drawings:
[0010] Figure 1 This is a flowchart of an optional safety assessment method for autonomous vehicles provided according to an embodiment of the present invention;
[0011] Figure 2 This is a schematic diagram of an optional safety assessment method for autonomous vehicles provided according to an embodiment of the present invention;
[0012] Figure 3 This is a quantitative score curve of an optional safety assessment method for autonomous vehicles provided according to an embodiment of the present invention;
[0013] Figure 4This is a flowchart of the weight calculation for an optional safety assessment method for autonomous vehicles provided according to an embodiment of the present invention;
[0014] Figure 5 This is a schematic diagram of the importance scale of an optional safety assessment method for autonomous vehicles provided according to an embodiment of the present invention;
[0015] Figure 6 This is a schematic diagram of an optional safety assessment method for autonomous vehicles provided according to an embodiment of the present invention. Detailed Implementation
[0016] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0017] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0018] With the rapid development of technologies such as swarm intelligence, edge computing, and cloud services, vehicle-road cooperation has become an important way to achieve large-scale deployment of autonomous driving. Vehicle-road cooperation comprehensively utilizes various devices on the roadside, in-vehicle, and in the cloud, significantly improving the perception and decision-making capabilities of autonomous driving systems through collaborative perception and collaborative decision-making control. This reduces the cost of autonomous driving and fundamentally solves the technical bottlenecks encountered by single-vehicle intelligent autonomous driving, such as insufficient perception and decision-making capabilities and high sensor costs. Related research consistently identifies vehicle-road cooperation as a crucial direction for the future of autonomous driving.
[0019] Intelligent connectivity, cloud-edge-device integration, and group collaboration are the main characteristics of autonomous vehicles under vehicle-road cooperation. This extends the perception, decision-making, and execution of vehicles from a single-vehicle system to a complex cloud-edge-device integrated system. The boundary between functional safety and cybersecurity collapses, and the traditionally simple functional safety issue evolves into a generalized safety and security issue. Current autonomous driving safety evaluation methods focus on evaluating the functions of a single autonomous vehicle, without considering factors such as the inherent safety of key vehicle components and intelligent collaboration. Furthermore, for autonomous vehicles, the software code of their autonomous driving systems reaches hundreds of millions of lines, and components come from a wide range of sources. In the open-source ecosystem and the interdependent industrial structure, system vulnerabilities cannot be thoroughly investigated, vulnerabilities and backdoors cannot be exhaustively identified, and potential random failures cannot be fully considered. While these hazards are relatively controllable for traditional internet components, for life-or-death autonomous vehicles, a technical approach that only defends against known threats is unacceptable. Penetration testing-based security evaluations of key components are no longer comprehensive enough in the field of autonomous driving.
[0020] To address the aforementioned problems, this invention provides a method embodiment for safety assessment of autonomous vehicles. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0021] Figure 1 This is a flowchart of an optional safety assessment method for autonomous vehicles according to an embodiment of the present invention, such as... Figure 1 As shown, the method includes the following steps:
[0022] Step S102: Perform a pre-set white-box piling test on the predetermined functional units of the autonomous vehicle to obtain the intrinsic safety score of the autonomous vehicle.
[0023] It is understandable that, because related technologies often rely on defined input / output interfaces and testing and evaluation according to defined inputs and steps, system vulnerabilities cannot be thoroughly investigated, vulnerabilities and backdoors cannot be exhaustively identified, and potential random failures cannot be fully considered. Technical approaches that only defend against known threats are incomplete evaluation methods. This invention introduces a white-box instrumentation testing method to test predetermined functional units of autonomous vehicles. Since some connected functional units in a vehicle have a decisive impact on the intrinsic safety of autonomous vehicles, an intrinsic safety score can be obtained by testing and evaluating the key units.
[0024] Optionally, the aforementioned predefined functional units may be an airbag controller unit (ACU) and a vehicle connectivity system (T-BOX).
[0025] In an optional embodiment, the above-mentioned white-box instrumentation test of predetermined functional units of the autonomous vehicle to obtain the intrinsic safety score of the autonomous vehicle includes: determining multi-level predetermined indicators for the predetermined functional units, wherein the multi-level predetermined indicators include: a primary indicator and a secondary indicator corresponding to the primary indicator, the primary indicator being a superior indicator of the secondary indicator; performing the white-box instrumentation test on the predetermined functional units of the autonomous vehicle to obtain the secondary indicator score of the secondary indicator of the predetermined functional units, wherein the secondary indicator score of the secondary indicator of the predetermined functional units is a quantitative score obtained by the predetermined functional units based on the secondary indicator test; obtaining the secondary weights corresponding to the secondary indicators and obtaining the primary weights corresponding to the primary indicators; obtaining the primary indicator score of the primary indicator of the predetermined functional units based on the secondary weights and the secondary indicator scores of the secondary indicators of the predetermined functional units; and determining the intrinsic safety score of the autonomous vehicle based on the primary indicator score of the primary indicator of the predetermined functional units.
[0026] It is understandable that a multi-level predetermined indicator system is established, where primary and secondary indicators have a corresponding relationship, and primary indicators are the superior indicators of their corresponding secondary indicators, which are considered sub-indicators of primary indicators. To enhance the perception of inherent vehicle safety, white-box interpolation tests are conducted on predetermined functional units of autonomous vehicles. These predetermined functional units can be considered units that have a key impact on autonomous driving, resulting in secondary indicator scores for each predetermined functional unit. Primary and secondary indicators have different levels of importance; primary indicators correspond to primary weights, and secondary indicators correspond to secondary weights. The secondary weights, along with the secondary indicator scores of the predetermined functional units, yield the primary indicator scores for the primary indicators of those predetermined functional units. In other words, the primary indicator score is obtained based on the secondary weights and the secondary indicator scores of the predetermined functional units. Based on the primary indicator scores of the predetermined functional units, the inherent safety score of the autonomous vehicle is determined.
[0027] Optionally, intermediate indicators may exist between the primary and secondary indicators in the aforementioned multi-level predetermined indicators. For example, there may be a sequence from higher-level indicators to lower-level indicators, following the order of primary indicator, corresponding intermediate indicator, and corresponding secondary indicator. The intermediate indicators may be of one or more levels.
[0028] In an optional embodiment, the above-mentioned white-box instrumentation test on the predetermined functional unit of the autonomous vehicle to obtain the secondary index score of the predetermined functional unit includes: performing white-box instrumentation test on the predetermined functional unit of the autonomous vehicle to obtain the qualitative evaluation level, attack time, disturbance frequency, and detection time of the predetermined functional unit, wherein the qualitative evaluation level is obtained by qualitatively classifying the impact of the white-box instrumentation test on the predetermined functional unit, and the attack time is the time it takes for the predetermined functional unit to be successfully attacked by the white-box instrumentation test. The disturbance frequency is the frequency at which the predetermined functional unit is disturbed by the white-box instrumentation test, and the detection duration is the duration for which the predetermined functional unit detects the attack from the white-box instrumentation test. Using the Euclidean distance method, the attack duration, the disturbance frequency, and the detection duration are normalized to obtain a normalized result. Based on the normalized result, the qualitative evaluation level is adjusted to obtain an adjusted qualitative evaluation level. Based on the adjusted qualitative evaluation level and the corresponding quantitative value, the secondary indicator score of the predetermined functional unit's secondary indicator is determined.
[0029] It is understandable that, for objective evaluation and comprehensive score calculation of multiple indicators, it is necessary to quantify the scores of the secondary indicators of the predetermined functional units. White-box instrumentation tests are performed on the predetermined functional units of the autonomous vehicle to obtain the qualitative evaluation level, attack time, disturbance frequency, and detection time of the predetermined functional units. The Euclidean distance method is used to perform a first normalization process on the attack time, disturbance frequency, and detection time to obtain the normalized results. The qualitative evaluation level is adjusted based on the normalized results; in other words, the qualitative evaluation level is adjusted based on the attack time, disturbance frequency, and detection time to obtain the adjusted qualitative evaluation level. Based on the adjusted qualitative evaluation level, the corresponding quantitative value is determined. The adjusted qualitative evaluation level and its corresponding quantitative value can be considered as a continuous quantification process of qualitative indicators, converting them into secondary indicator scores (e.g., numerical results from 0 to 100), which are then determined as the secondary indicator scores of the predetermined functional units. The above processing objectively processes the results of white-box instrumentation tests, which helps to obtain objectively quantified scores for the secondary indicators of the predetermined functional units.
[0030] In one optional embodiment, obtaining the secondary weights corresponding to the secondary indicators includes: determining multiple similar test units of the same type as the predetermined functional units; and obtaining the secondary weights corresponding to the secondary indicators based on the similar test scores of the multiple similar test units.
[0031] It is understandable that multiple similar test units are beneficial for representing typical faults that are prone to occur in similar functional units. This allows for the identification of multiple similar test units of the same type as the predetermined functional units, thereby characterizing and determining the importance of secondary indicators. Based on the similar test scores of the secondary indicators corresponding to multiple similar test units, the secondary weights corresponding to the secondary indicators are obtained. Through this process, it can be understood that by increasing the quantity of test units, problems that are prone to occur in similar functions can be represented. Using multiple similar test units to obtain the common characteristics of the predetermined functional units helps to obtain more accurate secondary weights corresponding to the secondary indicators.
[0032] In an optional embodiment, obtaining the primary weight corresponding to the primary indicator includes: obtaining the primary weight corresponding to the primary indicator based on the secondary weight and the similar test scores of the secondary indicators corresponding to the multiple similar test units.
[0033] It is understandable that, based on the secondary weights, the scores of similar tests for secondary indicators corresponding to multiple similar test units can yield the primary weights for the primary indicators. Primary indicators correspond to secondary indicators; the more important the secondary indicator, the higher its weight, and consequently, the greater the importance of the primary indicator. This process helps improve the objectivity and accuracy of the primary weights corresponding to the primary indicators.
[0034] In an optional embodiment, obtaining the secondary weights corresponding to the secondary indicators based on the similar test scores of the secondary indicators corresponding to the plurality of similar test units includes: obtaining the secondary coefficient of variation corresponding to the secondary indicators based on the similar test scores of the secondary indicators corresponding to the plurality of similar test units; and performing a second normalization process on the secondary coefficient of variation to obtain the secondary weights of the secondary indicators.
[0035] Understandably, to reduce the influence of similar test scores on secondary indicators, dimensionless processing is performed to obtain the secondary coefficient of variation. A second normalization process is then applied to the secondary coefficient of variation to obtain the secondary weights of the secondary indicators.
[0036] In an optional embodiment, obtaining the primary weight corresponding to the primary indicator based on the secondary weight and the similar test scores of the secondary indicators corresponding to the plurality of similar test units includes: obtaining the primary coefficient of variation corresponding to the primary indicator based on the secondary weight and the similar test scores of the secondary indicators corresponding to the plurality of similar test units; and performing a third normalization process on the primary coefficient of variation to obtain the primary weight of the primary indicator.
[0037] Understandably, to mitigate the risk of increased importance of primary indicators due to a large number of secondary indicators, which could lead to decreased objectivity and accuracy in security assessments, it is necessary to derive primary weights for primary indicators based on secondary weights. Based on these secondary weights and the test scores of similar secondary indicators for multiple similar test units, the primary coefficient of variation for each primary indicator is obtained. A third normalization process is then applied to the primary coefficient of variation to obtain the primary weight for each primary indicator.
[0038] Optionally, the above-mentioned first-level coefficient of variation can be obtained in various ways. For example, the test scores of the secondary indicators corresponding to multiple similar test units can be weighted using a linear weighting method to obtain the first-level evaluation matrix of the first-level indicator. Based on the matrix elements in the first-level evaluation matrix, the mean and standard deviation of the matrix elements in the first-level evaluation matrix can be obtained, and then the first-level weight of the first-level indicator can be obtained.
[0039] Step S104: Obtain the single-vehicle safety score and the collaborative safety score of the aforementioned autonomous vehicle. The single-vehicle safety score is used to indicate the driving safety of the aforementioned autonomous vehicle in a single-vehicle driving scenario, and the collaborative safety score is used to indicate the driving safety of the aforementioned autonomous vehicle in a multi-vehicle driving scenario.
[0040] Understandably, in order to conduct a comprehensive evaluation based on autonomous driving scenarios and obtain the vehicle's intrinsic safety score, it is also necessary to obtain the single-vehicle safety score of the autonomous vehicle in a single-vehicle driving scenario, as well as the collaborative safety score of the autonomous vehicle in a multi-vehicle driving scenario.
[0041] In an optional embodiment, obtaining the single-vehicle safety score of the autonomous vehicle includes: obtaining a simulation test score of the autonomous vehicle based on the accident frequency corresponding to a plurality of preset simulation test scenarios and the scenario weight corresponding to the plurality of simulation test scenarios, wherein the simulation test scenarios are used to test the frequency of natural driving accidents occurring in the autonomous vehicle; obtaining a field test score of the autonomous vehicle based on the perception ability score of the autonomous vehicle for site recognition and the response ability score of the autonomous vehicle for road conditions, wherein the perception ability score is used to characterize the accuracy and recognition time of the autonomous vehicle for site recognition, and the response ability score is used to characterize the autonomous vehicle's ability to change its driving state in response to different road conditions; obtaining a driving test score of the autonomous vehicle based on the number of times the autonomous vehicle was taken over and the driving acceleration of the autonomous vehicle, wherein the number of times the autonomous vehicle was taken over by human intervention; and obtaining the single-vehicle safety score of the autonomous vehicle based on the simulation test score, the field test score, and the driving test score.
[0042] It is understandable that the individual safety score of an autonomous vehicle is composed of multiple aspects. First, based on the accident frequencies corresponding to multiple preset simulation test scenarios and the corresponding scenario weights, the simulation test score of the autonomous vehicle is obtained. It should be noted that the simulation test scenarios are used to test the frequency of natural driving accidents involving autonomous vehicles, that is, the frequency of accidents caused without external influence. Next, based on the autonomous vehicle's perception ability score for site recognition and its response ability score for road conditions, the site test score of the autonomous vehicle is obtained. The perception ability score is used to characterize the accuracy and recognition time of the autonomous vehicle's site recognition, and the response ability score is used to characterize the autonomous vehicle's ability to change its driving state in response to different road conditions. Finally, based on the number of times the autonomous vehicle intervenes and its driving acceleration, the driving test score of the autonomous vehicle is obtained. The number of times the driver intervenes, to a certain extent, characterizes the driver's level of information about the autonomous driving system, representing the number of times the autonomous vehicle is manually taken over. Based on the simulation test score, site test score, and driving test score, the individual safety score of the autonomous vehicle is obtained. The above processing methods evaluate the safety of autonomous vehicles in single-vehicle scenarios from three aspects: simulation test score, field test score, and driving test score, which helps to improve the comprehensiveness of the overall safety score.
[0043] Optionally, there are multiple ways to obtain simulation test scores. For example, the simulation test scores can be obtained by using the scene weights corresponding to the autonomous vehicle in multiple simulation test scenarios and then summing the accident frequencies corresponding to the multiple simulation test scenarios.
[0044] Optionally, there are multiple ways to obtain the field test score of the above-mentioned autonomous vehicle. For example, the field test score of the autonomous vehicle can be obtained by weighted summing of the above-mentioned perception ability score and the above-mentioned response ability score.
[0045] Optionally, there are several ways to obtain the above driving test scores. For example, because open road testing requires autonomous vehicles to have a high level of safety, it is generally difficult to use accident rates to evaluate the safety of autonomous driving. However, the speed of vehicle state changes is often linked to safety and reflects the smoothness of autonomous driving. Generally speaking, large accelerations and rotational speeds often occur on the verge of traffic accidents. From the perspective of passengers, high lateral accelerations, braking accelerations, and rotational speeds not only reduce passenger comfort but also make passengers worry about the safety of the vehicle. Therefore, the driving acceleration of autonomous vehicles can be used to evaluate vehicle safety. In addition, the number of times a safety driver intervenes during vehicle operation can also reflect the safety of autonomous vehicles. By counting the number of times a safety driver intervenes, and using a deduction principle to deduct points according to the proportion of each situation occurring at a certain driving time and mileage, the driving test score of the autonomous vehicle can be obtained.
[0046] In one optional embodiment, obtaining the cooperative safety score of the autonomous vehicle includes: determining a preset vehicle-road cooperative decision-making scenario; obtaining the single-vehicle accident rate and single-vehicle traffic efficiency of the autonomous vehicle in the preset single-vehicle scenario, and the cooperative accident rate and cooperative traffic efficiency of the autonomous vehicle in the vehicle-road cooperative decision-making scenario; and obtaining the cooperative safety score of the autonomous vehicle based on the single-vehicle accident rate, the single-vehicle traffic efficiency, the cooperative accident rate, and the cooperative traffic efficiency.
[0047] It is understandable that the cooperative safety score of autonomous vehicles is composed of multiple aspects. First, a pre-defined vehicle-to-infrastructure (V2I) decision-making scenario is established. Aside from single-vehicle scenarios, V2I occurs more frequently in autonomous driving in practical applications, requiring vehicles to possess the ability to safely navigate multi-vehicle situations. The single-vehicle accident rate and single-vehicle traffic efficiency of autonomous vehicles in the pre-defined single-vehicle scenario, as well as the cooperative accident rate and cooperative traffic efficiency of autonomous vehicles in the V2I decision-making scenario, are obtained. It should be noted that using the single-vehicle accident rate and single-vehicle traffic efficiency as the basis for comparison of the cooperative accident rate and cooperative traffic efficiency, and eliminating the influence of single-vehicle safety, can more accurately characterize the impact of V2I capabilities. Then, based on the single-vehicle accident rate, single-vehicle traffic efficiency, cooperative accident rate, and cooperative traffic efficiency, the cooperative safety score of the autonomous vehicle is obtained.
[0048] Optionally, the above-mentioned vehicle-road cooperative decision-making scenarios can be various, such as: designing scenarios such as beyond-line-of-sight following, lane change conflict, unprotected left turn, pedestrian intrusion warning, oncoming vehicle warning, safe passage through intersections based on traffic light cooperative perception, accidents ahead, sudden avoidance by the vehicle in front while following, non-motorized vehicle violation, cooperative perception of events in tunnels, and multi-vehicle cooperative decision-making and control, as preset vehicle-road cooperative decision-making scenarios.
[0049] Step S106: Based on the aforementioned intrinsic safety score, the aforementioned single-vehicle safety score, and the aforementioned collaborative safety score, the comprehensive safety score of the aforementioned autonomous vehicle is obtained.
[0050] It is understandable that combining intrinsic safety scores, individual vehicle safety scores, and collaborative safety scores to obtain a comprehensive safety score for autonomous vehicles would help improve the overall comprehensiveness of the safety score.
[0051] In one optional embodiment, the comprehensive safety score of the autonomous vehicle is obtained based on the intrinsic safety score, the single-vehicle safety score, and the cooperative safety score, including: determining a first weight corresponding to the intrinsic safety score, a second weight corresponding to the single-vehicle safety score, and a third weight corresponding to the cooperative safety score; and obtaining the comprehensive safety score of the autonomous vehicle based on the intrinsic safety score, the first weight, the single-vehicle safety score, the second weight, the cooperative safety score, and the third weight.
[0052] It is understandable that a weighting method is used to flexibly represent the importance of intrinsic safety score, individual vehicle safety score, and collaborative safety score. A first weight corresponding to the intrinsic safety score, a second weight corresponding to the individual vehicle safety score, and a third weight corresponding to the collaborative safety score are determined. Based on the intrinsic safety score, the first weight, the individual vehicle safety score, the second weight, the collaborative safety score, and the third weight, the comprehensive safety score of the autonomous vehicle is calculated.
[0053] Through the above steps S102 to S106, the goal of improving the comprehensiveness of the safety assessment of autonomous driving can be achieved by using white-box piling tests. This achieves the technical effect of comprehensively considering the inherent safety of the vehicle, individual vehicle safety, and collaborative safety, thereby obtaining an objective and accurate autonomous driving safety assessment. This solves the technical problem in related technologies where the inherent safety of the vehicle is not taken into consideration, resulting in a large limitation in the safety assessment of autonomous vehicles and an unsatisfactory objectivity.
[0054] Based on the above embodiments and optional embodiments, the present invention proposes an optional implementation method. Figure 2 This is a schematic diagram of an optional safety assessment method for autonomous vehicles provided according to an embodiment of the present invention. The following is a detailed description of steps S1 to S6.
[0055] Step S1: Obtain the vehicle's intrinsic security score. Traditional critical component security testing primarily relies on defined input / output interfaces, conducting tests and evaluations according to predetermined inputs and steps. These methods can effectively prevent known security threats, such as common cyberattacks, and detect the patching of known backdoors and vulnerabilities. However, for autonomous vehicles, the software code of their autonomous driving systems reaches hundreds of millions of lines, and components come from various domestic and international parts manufacturers. In the open-source ecosystem and highly interactive industrial structure, system vulnerabilities cannot be thoroughly investigated, vulnerabilities and backdoors cannot be exhaustively listed, and potential random failures cannot be fully considered. For traditional internet components, these hazards are relatively controllable, but for life-or-death autonomous vehicles, a technical approach that only defends against known threats is unacceptable. Critical component security evaluations based on penetration testing are no longer comprehensive enough in the field of autonomous driving. Therefore, a white-box instrumentation testing method is adopted to obtain the vehicle's intrinsic security score, as detailed in the following sub-steps.
[0056] Step S101: Determine the evaluation targets. The airbag controller unit (ACU) and the vehicle connectivity system (T-BOX) are the most critical systems for the safety of intelligent connected vehicles. The autonomous driving system is the brain of the intelligent connected vehicle, responsible for perceiving the vehicle's surrounding environment, predicting behavior, planning paths, speed planning, and motion control. The vehicle connectivity system is the nerve center of the intelligent connected vehicle, responsible for vehicle-to-vehicle, vehicle-to-infrastructure, and vehicle-to-cloud communication, as well as remote vehicle monitoring, remote control, and remote diagnostics. Therefore, the ACU and T-BOX have a crucial impact on the inherent safety of the vehicle.
[0057] Step S102: Establish an indicator system and determine the primary and secondary indicators corresponding to the vehicle's ACU and T-BOX, respectively. From the perspective of intrinsic safety, establish indicator systems for T-BOX and ACU separately.
[0058] Based on the hardware and software composition of the T-BOX system, the T-BOX security evaluation is divided into four parts: hardware security, system software security, application software security, and communication security.
[0059] Based on the security threats and specific functional modules faced by the four parts of hardware, system software, application software and communication, the evaluation influencing factors are classified and the primary indicators for T-BOX are determined. The secondary indicators corresponding to the primary indicators of T-BOX are as follows. Table 1 is a schematic diagram of the T-BOX intrinsic security indicator system.
[0060] Table 1
[0061]
[0062]
[0063] Among them, CAN (Controller Area Network) bus is one of the most widely used fieldbuses in vehicles. LIN (Local Interconnect Network) bus is a low-cost serial communication network defined for vehicle distributed electronic systems. It complements other multiplexed networks in vehicles, such as Controller Area Networks, and is suitable for applications that do not have high requirements for network bandwidth, performance, or fault tolerance. WLAN (Wireless Local Area Network) is used to form a network system for mutual communication and resource sharing. GPS (Global Positioning System) is a high-precision positioning and navigation system.
[0064] Based on the hardware and software composition of the autonomous driving system (ACU), the safety evaluation of the autonomous driving system is divided into five parts: computing unit safety, perception sensor safety, operating system safety, application software safety, and communication security.
[0065] Based on the security threats and specific functional modules faced by the five parts of computing unit, sensing sensor, operating system, application software and communication, the evaluation influencing factors are classified and the primary and secondary indicators for ACU are determined as follows. Table 2 is the ACU intrinsic security indicator system.
[0066] Table 2
[0067]
[0068]
[0069]
[0070] The difference between the indicator systems in Tables 1 and 2 above and general evaluation systems in related technologies lies in the fact that general evaluations utilize fixed external interfaces of the vehicle to launch attacks and assess security levels by observing system responses. This primarily reflects the system's ability to block and isolate external attacks, representing an "external" security protection capability and an assessment of the effectiveness of defenses against known vulnerabilities / backdoors. In contrast, the white-box instrumentation testing method, by pre-setting vulnerabilities and backdoors within the vehicle system to trigger various attacks and even random failures, simulates situations where core modules of the system malfunction for various reasons. Observing the vehicle's response assesses its security level, reflecting the vehicle's intrinsic security capabilities—its internal ability to cope with attacks and failures, including unpredictable random failures and network attacks based on unknown vulnerabilities / backdoors. The intrinsic security score obtained through the white-box instrumentation test has a broader coverage than general evaluation scores in related technologies, taking into account unknown factors. It offers better evaluation capabilities and results for autonomous driving safety issues that are closely related to driver safety.
[0071] Step S103, Qualitative evaluation of indicators. A backdoor is implanted into the system using a white-box instrumentation method. After the backdoor is triggered, it can simulate the T-BOX displaying the various indicators in Table 1 and the ACU displaying the various indicators in Table 2. Based on the vehicle response, the degree of impact on the system and the attack time t are qualitatively recorded. c Disturbance frequency p and system detection time t f The system detection time mentioned above refers to the duration after the vehicle detects that it has been attacked.
[0072] Unlike quantifiable metrics such as braking distance and response time, the pre-defined functional units of a vehicle (e.g., ACU and T-BOX) can only be qualitatively evaluated based on the degree of impact when subjected to cyberattacks or malfunctions. These can be categorized as excellent, good, fair, or poor, specifically: unaffected (A), minor disturbances (B), single effective attack (C), and continuous effective attacks (D). Minor disturbances refer to a preset number of disturbances. Effective attacks refer to cyberattacks.
[0073] And it can be based on the attack time t c Disturbance frequency p h and system discovery time t f Secondary factors are used to qualitatively classify intermediate levels such as A-, B+ / B-, C+ / C-, and D+. The specific method is as follows:
[0074] The attack time t c Disturbance frequency p h and system discovery time t f Perform dimensionless normalization to obtain the attack time after dimensionless normalization. Perturbation frequency after dimensionless normalization System discovery time after dimensionless normalization Among them, t c The bigger The closer p approaches 0, the better. h smaller The closer t is to 0, the better. f smaller The closer it gets to 0, the better the orientation of inherent vehicle safety is t. c The larger p h The smaller t f The smaller.
[0075] Calculate the vehicle's preset functional units. The Euclidean distance from the origin is expressed as Where s is the Euclidean distance. When s < 1 / 3, a "+" is obtained on top of the original level; when s > 2 / 3, a "-" is obtained on top of the original level, with the highest being A and the lowest being D. Using the above method, the qualitative evaluation level is adjusted based on the normalization result to obtain the adjusted qualitative evaluation level.
[0076] Step S104: Determine the scores of the secondary indicators for the predetermined functional units. The evaluation levels A, A-, B+, B, B-, C+, C, C-, D+, and D are assigned the values 10, 9, 8, 7, 6, 5, 4, 3, 2, and 1, respectively. To quantify the secondary indicators in Tables 1 and 2, the following mathematical expression 1 is preferably used for score calculation:
[0077]
[0078] Wherein, α, β, a, and b are preset parameters, obtained by calculation based on typical values, as follows: When the secondary indicator is rated A, the quantitative value f(10) = 100 is set; when the secondary indicator is rated B, the quantitative value f(7) = 80 is set; when the secondary indicator is rated D, the quantitative value f(1) = 1 is set, and obtained by calculation:
[0079]
[0080] By substituting the set quantitative values corresponding to the secondary indicators into mathematical expression 1, the secondary indicator scores of the predetermined functional units can be obtained.
[0081] In another quantification method, Figure 3 This is a quantitative score curve graph of an optional safety assessment method for autonomous vehicles provided according to an embodiment of the present invention. It can also be obtained by searching... Figure 3 The preset curve in the curve is used to obtain the secondary index score of the secondary index of the predetermined functional unit.
[0082] Step S105: Based on the indicator system (primary and secondary indicators), the scores of secondary indicators and primary indicators, determine the intrinsic safety score of the autonomous vehicle.
[0083] This implementation proposes a comprehensive score calculation method based on a multi-level index system using the coefficient of variation. Figure 4 This is a flowchart illustrating the weight calculation process of an optional safety assessment method for autonomous vehicles according to an embodiment of the present invention, specifically the weighting process. Figure 4 As shown, weights are assigned based on the variability of the difficulty in achieving the characteristic indicators. Weights are assigned to each level of indicators through partitioned calculation and a progressively weighted approach. The comprehensive score for each level is calculated using nonlinear weighting and linear weighting methods based on the independence or dependency relationship between the indicators. This effectively avoids the influence of subjective factors in expert decision-making and analytic hierarchy process (AHP), while also addressing the problem that the traditional coefficient of variation method is only applicable to single-level indicator systems. It also avoids the unreasonable influence of the number of second-level indicators on the weight of first-level indicators. The specific steps are as follows:
[0084] n T-BOX functional units of the same type as those in autonomous vehicles, and m ACU functional units of the same type as those in autonomous vehicles, are used as multiple similar test units. Using the typical n T-BOX functional units and m ACU functional units, tests are conducted item by item according to the secondary indicators in Tables 1 and 2. The similar test score for the T-BOX is obtained, denoted as p. Based on the number of secondary indicators for the T-BOX in Table 1, there are a total of 19, so p = 19. The similar test score for the ACU is obtained, denoted as q. Based on the number of secondary indicators for the ACU in Table 2, there are a total of 31, so q = 31. The secondary evaluation matrix X2 for the T-BOX and the secondary evaluation matrix Y2 for the ACU are formed as follows:
[0085]
[0086] Where, x np y is the p-th secondary indicator of the nth T-BOX functional unit. mp This is the qth secondary indicator of the m-th ACU functional unit.
[0087] Calculate the mean and standard deviation of the matrix elements (i.e., scores of similar tests) in X2 and Y2 respectively:
[0088]
[0089] Where i is the identifier of the functional unit (including the T-BOX functional unit and the ACU functional unit), j is the secondary indicator identifier of the T-BOX functional unit, j = 1, 2, ..., p, and k is the secondary indicator identifier of the ACU, k = 1, 2, ..., q. s is the mean score of similar tests for the secondary indicators of T-BOX. xj The standard deviation of the test scores for the T-BOX functional unit is given. s is the average score of similar tests for the secondary indicators of the ACU functional unit. yk s is the standard deviation of the scores of similar tests for the k-th secondary indicator of the ACU functional unit. xj Let be the standard deviation of the scores of similar tests for the j-th secondary indicator of the T-BOX functional unit.
[0090] Calculate the second-order coefficient of variation for each of the second-order indicators sequentially:
[0091] Among them, v xj Let v be the coefficient of variation of the j-th secondary index of the T-BOX functional unit. yk is the second-order coefficient of variation of the k-th second-order index of the ACU functional unit.
[0092] Taking autonomous driving systems as an example, the primary indicators such as computing units, perception sensors, operating systems, application software, and communication systems are interdependent in the entire autonomous driving system, while the secondary indicators are relatively independent, making it unsuitable to directly obtain weights using traditional normalization methods. Furthermore, some primary indicators may contain more secondary indicators, but this does not necessarily mean that the primary indicator is more important.
[0093] Using the second-order coefficient of variation of the T-BOX functional unit, the second-order indicators under the first-order indicators of the T-BOX functional unit are normalized sequentially to obtain the second-order weights of the T-BOX functional unit as follows:
[0094]
[0095]
[0096]
[0097]
[0098] Among them, v xj Let v be the coefficient of variation of the j-th secondary index of the T-BOX functional unit. x1 v x2 v x3 v x4 w represents the second-order coefficient of variation for the first to fourth second-order indicators of the T-BOX functional unit. x1 For the first group of secondary weights of the T-BOX functional unit, v x5 v x6 v x7 v x8w represents the second-order coefficient of variation for the 5th to 8th second-order indicators of the T-BOX functional unit. x2 For the second group of secondary weights of the T-BOX functional unit, v x9 v x10 v x11 v x12 w represents the second-order coefficient of variation for the 9th to 12th second-order indicators of the T-BOX functional unit. x3 For the third group of secondary weights of the T-BOX functional unit, v x13 v x14 ......v x19 w represents the second-order coefficient of variation for the 13th to 19th second-order indicators of the T-BOX functional unit. x4 This is the fourth group of secondary weights for the T-BOX functional unit.
[0099] It should be noted that the above w x1 w x2 w x3 w x4 The four sets of secondary weights are based on the four parts of hardware security, system software security, application software security and communication security of the T-BOX functional unit shown in Table 1.
[0100] The secondary weights of the ACU functional unit are obtained as follows:
[0101]
[0102]
[0103]
[0104]
[0105]
[0106] Among them, v yk v is the second-order coefficient of variation of the k-th second-order index of the ACU functional unit. y1 v y2 v y3 v y4 w represents the second-order coefficient of variation for the first to fourth second-order indicators of the ACU functional unit. y1 For the first group of secondary weights of the ACU functional unit, v y5 v y6 ......v x10 w represents the second-order coefficient of variation for the 5th to 10th second-order indicators of the ACU functional unit. y2 For the second group of secondary weights of the ACU functional unit, v y11v y12 v y13 v y14 w represents the second-order coefficient of variation for the 11th to 14th second-order indicators of the ACU functional unit. y3 For the third group of secondary weights of the ACU functional unit, v y15 v y16 ......v y26 w represents the second-order coefficient of variation for the 15th to 26th second-order indicators of the ACU functional unit. y4 For the fourth group of secondary weights of the ACU functional unit, v y27 v y28 ......v y31 w represents the second-order coefficient of variation for the 27th to 31st second-order indicators of the ACU functional unit. y5 This is the 5th secondary weight of the ACU functional unit.
[0107] It should be noted that the above w y1 w y2 w y3 w y4 w y5 The five secondary weights are based on the five parts of the ACU functional unit shown in Table 2: computing unit security, sensing sensor security, operating system security, application software security, and communication security.
[0108] Based on the secondary weights of the T-BOX functional unit and the ACU functional unit, a linear weighting method is used to comprehensively weight the scores of the secondary indicators, forming the primary evaluation matrix X1 of the T-BOX functional unit and the primary evaluation matrix Y1 of the ACU functional unit as follows:
[0109]
[0110] Where, x n4 For the four primary indicators of the nth T-BOX functional unit, y m5 These are the five primary indicators for the m-th ACU functional unit. It should be noted that the four primary indicators for the T-BOX functional unit are shown in Table 1, and the five primary indicators for the ACU functional unit are shown in Table 2.
[0111] Calculate the mean and standard deviation of the matrix elements in X1 and Y1 respectively.
[0112]
[0113] Where i is the identifier of the functional unit (including the T-BOX functional unit and the ACU functional unit), r is the first-level indicator identifier of the T-BOX functional unit, r = 1, 2, 3, 4, and t is the first-level indicator identifier of the ACU functional unit, t = 1, 2, 3, 4, 5. The average of the first-level indicators of the T-BOX functional unit, s xr The standard deviation of the T-BOX functional units. s represents the mean of the first-level indicators of the ACU functional unit. yt Let s be the standard deviation of the t-th primary index of the ACU functional unit. xr denoted as the standard deviation of the r-th primary index of the T-BOX functional unit, where n is the number of T-BOX functional units and m is the number of ACU functional units.
[0114] Calculate the first-level coefficient of variation for the first-level indicators of the T-BOX functional unit and the first-level coefficient of variation for the first-level indicators of the ACU functional unit in sequence:
[0115]
[0116] Among them, v xr v is the first-level coefficient of variation of the r-th first-level index of the T-BOX functional unit. yt Let be the first-level coefficient of variation of the t-th first-level index of the ACU functional unit.
[0117] The coefficients of variation of the first-level indicators of the T-BOX functional unit are normalized to obtain the first-level weights W of the first-level indicators of the T-BOX functional unit. x The first-level coefficient of variation of the first-level indicators of the ACU functional unit is normalized to obtain the first-level weight W of the first-level indicators of the ACU functional unit. y :
[0118]
[0119]
[0120] The T-BOX functional unit and ACU functional unit of the autonomous vehicle under test are tested to obtain the secondary index scores of each secondary index of the T-BOX functional unit. The scores of the secondary indicators for each secondary indicator of the ACU functional unit.
[0121] The first-level weights of the T-BOX functional unit and the ACU functional unit are calculated using the second-level weights, S. x1 To S x4 S represents the scores of the four primary indicators for T-BOX. y1 To Sy4 The scores for the five primary indicators of ACU are as follows.
[0122]
[0123]
[0124]
[0125] Considering the dependencies between primary indicators, the functional unit score S of the T-BOX functional unit is calculated using a nonlinear weighting method based on the primary weights. T-BOX , and the functional unit score S of the ACU functional unit ACU
[0126]
[0127] In the formula, S xr The first-level indicator score and S for the T-BOX functional unit yt W is the primary performance indicator score for the ACU functional unit. xr The primary indicator weight W for the T-BOX functional unit x The r-th element in W yt The first-level indicator weight W of the ACU functional unit y The t-th element in.
[0128] The intrinsic safety level score of the vehicle is obtained by averaging the functional unit scores of the T-BOX and ACU. T-BOX +S ACU ) / 2.
[0129] Step S2: Obtain the bicycle safety score. The following sub-steps will provide a detailed explanation:
[0130] Step S201: Determine the simulation test score.
[0131] Based on the simulation test scenario set, there are a total of M scenarios. Simulation tests were conducted separately, the accident rate under each scenario was statistically analyzed, and scores were calculated. The score calculation formula is as follows:
[0132]
[0133] Where x is the independent variable representing the accident rate obtained from the simulation test, p0 is the natural driving accident rate, and the unit is p0 km / time or p0 hour / time, and e is the identifier of the simulation test scenario.
[0134] For N vehicles Test C dThis serves as the test identifier; the score S is recorded after the test is completed. ed_simu The subscript ed indicates the score of the d-th vehicle in the e-th scenario, and simu indicates the simulation test result;
[0135] Determine the scenario weight set based on the importance of each scenario and its frequency of occurrence in natural driving. The scores of the vehicle in each scenario are weighted and summed, w e_simu We assign weights to the vehicle in the e-th scenario and obtain the total score in the simulation test.
[0136] Step S202: Determine the field test score. The field test evaluation mainly includes two parts: perception ability test and execution ability test. The perception ability test includes traffic signs, traffic markings, traffic lights, traffic control gestures, vehicle recognition, pedestrian recognition, obstacle recognition, etc. The recognition accuracy rate and recognition time of each test vehicle are statistically analyzed based on the actual field test results. For example, 100 points are set for a recognition accuracy rate of 100% and a recognition time of 0 seconds, and 80 points are set for the average recognition accuracy rate and recognition time of a human driver. The perception ability score is calculated using a comprehensive weighted method.
[0137] In performance capability testing, it's difficult to directly quantify driving performance using a mathematical formula. Therefore, a manual scoring method can be used to assess responsiveness to various traffic signs, driving ability on curves and turns, reversing and parking skills, U-turn skills, and emergency response capabilities. The average of the scores from all experts is then calculated to obtain the final performance capability score. Finally, the perception and performance capability scores are weighted and summed to obtain the course test score S. field .
[0138] Step S203: Determine the driving test score. Because open road testing requires autonomous vehicles to have a high level of safety, it is generally difficult to evaluate the safety of autonomous driving using accident rates. However, the speed of vehicle state changes is often linked to safety and reflects the smoothness of autonomous driving. Generally, large accelerations and rotational speeds often occur on the verge of traffic accidents. From the perspective of passengers, high lateral accelerations, braking accelerations, and rotational speeds not only reduce passenger comfort but also make passengers worry about vehicle safety. Therefore, these factors can be used to evaluate vehicle safety. Furthermore, the number of times human intervention is required during vehicle operation can also reflect the safety of the autonomous vehicle.
[0139] Based on human comfort and safety requirements when driving a vehicle, comfort, confidence, and panic zones were established for longitudinal acceleration / deceleration, lateral acceleration / deceleration, rotational speed, and driving speed. The time taken for acceleration, rotational speed, and speed to fall within each zone during road testing was recorded, as were the number of interventions. Points were deducted according to a deduction principle based on the proportion of each situation occurring within a given driving time and mileage, resulting in a driving test score S. road Table 3 illustrates the division of comfort, confidence, and panic zones. As shown in Table 3, based on general human perception, five sets of boundary values are set for longitudinal acceleration, longitudinal deceleration, lateral acceleration, lateral deceleration, and driving speed.
[0140] Table 3
[0141]
[0142] Figure 6 This is a schematic diagram of an optional safety assessment method for autonomous vehicles provided according to an embodiment of the present invention, such as... Figure 6 As shown in Table 3 and a lmax These are the comfort zone boundary, confidence zone boundary, and maximum achievable longitudinal acceleration boundary, respectively. and a lmin These are the comfort zone boundary, confidence zone boundary, and maximum achievable longitudinal deceleration boundary, respectively. and a cmax These are the comfort zone boundary, confidence zone boundary, and maximum reachable boundary for lateral acceleration, respectively. and a cmin These represent the comfort zone boundary, confidence zone boundary, and maximum achievable longitudinal deceleration boundary, respectively. lim and V max These are the road speed limit and the maximum achievable speed, respectively, with the subscript numbers used to distinguish between different sections.
[0143] Step S204: Since the simulation test score, track test score, and driving test score have different focuses, a weakness in any one of them may compromise the safety of the autonomous vehicle. Therefore, the root-finding method is used to calculate the comprehensive score, i.e., the mathematical expression of the single-vehicle safety score S2 is:
[0144] Step S3: Determine the collaborative safety score. After vehicle-to-infrastructure (V2I) cooperation, the autonomous driving system gains many unique capabilities not found in single-vehicle systems, such as target perception from a global perspective, multi-vehicle collaborative perception, collaborative decision-making, and collaborative passage. Therefore, it is necessary to evaluate some capabilities unique to the advantageous scenarios of V2I cooperation. The following sub-steps will provide a detailed explanation.
[0145] Step S301: Design scenarios such as beyond-line-of-sight following, lane change conflict, unprotected left turn, pedestrian intrusion warning, oncoming vehicle warning, safe passage through intersections based on traffic light cooperative perception, accidents ahead, sudden avoidance by the vehicle in front while following, non-motorized vehicle violation, cooperative perception of events in tunnels, and multi-vehicle cooperative decision control as preset vehicle-road cooperative decision scenarios.
[0146] Step S302: Conduct comparative tests of vehicle-road cooperation and single-vehicle autonomous driving, and statistically analyze accident rates and traffic efficiency in different scenarios.
[0147] Step S303: Based on the data collected from natural driving in the single-vehicle scenario, calculate the single-vehicle accident rate and single-vehicle traffic efficiency. The score is calculated based on the two factors of cooperative accident rate and cooperative traffic efficiency, using the following formula:
[0148] s 3_e =0.8×s 3_e_acc +0.2×s 3_e_eff
[0149] Among them, s 3_e_acc Let s be the collaborative accident rate in the e-th scenario. 3_e_eff The collaborative traffic efficiency in the e-th scenario is scored as follows: if the capability fails to improve, 0 points are awarded; if the capability reaches the level of natural driving, 80 points are awarded; and if the capability reaches the ideal optimal solution, 100 points are awarded.
[0150] Step S304: Referencing the single-vehicle accident rate and single-vehicle traffic efficiency of natural driving, calculate the improvement level of safety performance of vehicle-road cooperation compared to single-vehicle autonomous driving capability.
[0151] Step S305: Calculate the score based on the improvement level of autonomous driving capabilities after vehicle-road cooperation, obtaining the cooperative accident rate and cooperative traffic efficiency. Among them, the accident rate accounts for 80% of the score, and the traffic efficiency accounts for 20%. If the capability fails to improve or declines, 0 points are awarded; reaching the natural driving level in a single-vehicle scenario earns 80 points; and reaching the ideal optimal solution earns 100 points.
[0152] Step S306: The scores are weighted and summed based on the importance of each scenario to obtain the cooperative safety score S3 of the autonomous vehicle.
[0153] Step S4: Evaluate the vehicle's ability to protect occupants using traditional vehicle collision safety evaluation methods, and calculate the collision safety score S4.
[0154] Step S5: Customize the score. Based on the user's understanding and needs regarding security, other security evaluation indicators can be added to calculate the custom score S. N .
[0155] Step S6: Calculate the overall safety score of the autonomous vehicle using the 1-9 scale method.
[0156] Step S601: Using the intrinsic safety score, single-vehicle safety score, cooperative safety score, collision safety score, and custom score obtained from steps S1 to S5 as five elements, a judgment matrix B is established by assigning values to these elements based on their relative importance. Figure 5 This is an important scale diagram of an optional safety assessment method for autonomous vehicles provided according to an embodiment of the present invention, such as... Figure 5 As shown, the 1-9 scale indicates that the two elements being compared are equally important to extremely important.
[0157]
[0158] Define b gh Let g be the element in the g-th row and h-th column of matrix B, representing the importance of the g-th element relative to the h-th element, and v be the number of elements, obtained through steps S1 to S5, where v = 5.
[0159] Step S602: Determine the weights of the elements using the summation method. Summation by row:
[0160]
[0161] The weights of each element are calculated by normalizing the element weights. Where v h is an intermediate variable, and h is the feature identifier.
[0162] Step S603: The intrinsic safety score, single-vehicle safety score, cooperative safety score, collision safety score, and custom score obtained from steps S1 to S5 are weighted and summed to calculate the comprehensive safety score S of the autonomous vehicle. all Establish mathematical expression as
[0163] The above optional implementation methods achieve at least the following effects: In view of the expanded scope of safety issues of autonomous vehicles after vehicle-road cooperation, and the fact that related methods are often limited to evaluating autonomous "single vehicles", this patent analyzes various factors affecting the safety of autonomous vehicles in vehicle-road cooperation, considers the impact of other safety factors such as the intrinsic safety of key components, i.e., predetermined functional units, single vehicle safety, cooperative safety, and collision safety on vehicle safety, and proposes a multi-level index system scoring calculation method based on the coefficient of variation. At the same time, it comprehensively utilizes evaluation algorithms such as hierarchical analysis and importance scaling to provide a more comprehensive and objective safety evaluation method for vehicle-road cooperation.
[0164] This invention provides a non-volatile storage medium storing a program that, when executed by a processor, implements a safety assessment method for autonomous vehicles.
[0165] This invention provides an electronic device including a processor, a memory, and a program stored in the memory and executable on the processor. When the processor executes the program, it performs the following steps: performing a preset white-box instrumentation test on predetermined functional units of an autonomous vehicle to obtain an intrinsic safety score for the autonomous vehicle; obtaining a single-vehicle safety score and a collaborative safety score for the autonomous vehicle, wherein the single-vehicle safety score indicates the driving safety of the autonomous vehicle in a single-vehicle driving scenario, and the collaborative safety score indicates the driving safety of the autonomous vehicle in a multi-vehicle driving scenario; and obtaining a comprehensive safety score for the autonomous vehicle based on the intrinsic safety score, the single-vehicle safety score, and the collaborative safety score. The device described herein may be a server, a PC, etc.
[0166] The present invention also provides a computer program product, which, when executed on a data processing device, is suitable for executing an initialization program having the following method steps: performing a preset white-box instrumentation test on predetermined functional units of an autonomous vehicle to obtain an intrinsic safety score of the autonomous vehicle; obtaining a single-vehicle safety score and a collaborative safety score of the autonomous vehicle, wherein the single-vehicle safety score is used to indicate the driving safety of the autonomous vehicle in a single-vehicle driving scenario, and the collaborative safety score is used to indicate the driving safety of the autonomous vehicle in a multi-vehicle driving scenario; and obtaining a comprehensive safety score of the autonomous vehicle based on the intrinsic safety score, the single-vehicle safety score, and the collaborative safety score.
[0167] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0168] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0169] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0170] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0171] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0172] Memory may include non-persistent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0173] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0174] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
[0175] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0176] The above are merely embodiments of the present invention and are not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principle of the present invention should be included within the scope of the claims of the present invention.
Claims
1. A safety assessment method for autonomous vehicles, characterized in that, include: Pre-defined white-box piling tests are performed on predetermined functional units of autonomous vehicles to obtain the intrinsic safety score of the autonomous vehicle. The predetermined functional units include the airbag control unit and the vehicle network system. The intrinsic safety score reflects the intrinsic safety capability of the autonomous vehicle, which is the ability to internally cope with attacks and failures, including unpredictable random failures and network attacks based on unknown vulnerabilities / backdoors. Obtain the single-vehicle safety score and the collaborative safety score of the autonomous vehicle, wherein the single-vehicle safety score is used to indicate the driving safety of the autonomous vehicle in a single-vehicle driving scenario, and the collaborative safety score is used to indicate the driving safety of the autonomous vehicle in a multi-vehicle driving scenario. Based on the intrinsic safety score, the individual vehicle safety score, and the collaborative safety score, the comprehensive safety score of the autonomous vehicle is obtained. The process of obtaining the individual safety score of the autonomous vehicle includes: obtaining a simulation test score for the autonomous vehicle based on the accident frequency corresponding to multiple preset simulation test scenarios and the scenario weights corresponding to the multiple simulation test scenarios, wherein the simulation test scenarios are used to test the frequency of natural driving accidents occurring in the autonomous vehicle; obtaining a field test score for the autonomous vehicle based on the perception ability score for site recognition and the response ability score for road conditions, wherein the perception ability score is used to characterize the accuracy and recognition time of the autonomous vehicle's site recognition, and the response ability score is used to characterize the autonomous vehicle's ability to change its driving state in response to different road conditions; obtaining a driving test score for the autonomous vehicle based on the number of times the autonomous vehicle was taken over and the driving acceleration of the autonomous vehicle, wherein the number of times the autonomous vehicle was taken over by a human; and obtaining the individual safety score of the autonomous vehicle based on the simulation test score, the field test score, and the driving test score. The method of obtaining the cooperative safety score of the autonomous vehicle includes: determining a preset vehicle-road cooperative decision-making scenario; obtaining the single-vehicle accident rate and single-vehicle traffic efficiency of the autonomous vehicle in the preset single-vehicle scenario, and the cooperative accident rate and cooperative traffic efficiency of the autonomous vehicle in the vehicle-road cooperative decision-making scenario; and obtaining the cooperative safety score of the autonomous vehicle based on the single-vehicle accident rate, the single-vehicle traffic efficiency, the cooperative accident rate, and the cooperative traffic efficiency.
2. The method according to claim 1, characterized in that, The process of performing pre-defined white-box instrumentation tests on predetermined functional units of the autonomous vehicle to obtain an intrinsic safety score for the autonomous vehicle includes: Determine the multi-level predetermined indicators for the predetermined functional unit, wherein the multi-level predetermined indicators include: a primary indicator and a secondary indicator corresponding to the primary indicator, wherein the primary indicator is the superior indicator of the secondary indicator; The predetermined functional units of the autonomous vehicle are subjected to white-box piling tests to obtain the secondary index scores of the secondary indexes of the predetermined functional units, wherein the secondary index scores of the secondary indexes of the predetermined functional units are the quantitative scores obtained by the predetermined functional units based on the secondary index tests. Obtain the secondary weights corresponding to the secondary indicators, and obtain the primary weights corresponding to the primary indicators; Based on the secondary weights and the secondary index scores of the secondary indicators of the predetermined functional units, the primary index scores of the primary indicators of the predetermined functional units are obtained. The intrinsic safety score of the autonomous vehicle is determined based on the primary index score of the primary index of the predetermined functional unit.
3. The method according to claim 2, characterized in that, The white-box instrumentation test is performed on the predetermined functional units of the autonomous vehicle to obtain the secondary indicator scores of the secondary indicators of the predetermined functional units, including: White-box instrumentation testing is performed on the predetermined functional units of the autonomous vehicle to obtain the qualitative evaluation level, attack time, disturbance frequency, and detection time of the predetermined functional units. The qualitative evaluation level is obtained by qualitatively classifying the impact of the white-box instrumentation test on the predetermined functional units. The attack time is the time it takes for the predetermined functional units to be successfully attacked by the white-box instrumentation test. The disturbance frequency is the frequency of disturbances generated by the white-box instrumentation test on the predetermined functional units. The detection time is the time it takes for the predetermined functional units to detect the attack of the white-box instrumentation test. Using the Euclidean distance method, the attack time, the perturbation frequency, and the detection time are subjected to a first normalization process to obtain a normalized result. The qualitative evaluation level is adjusted based on the normalization result to obtain the adjusted qualitative evaluation level. Based on the adjusted qualitative evaluation level and the corresponding quantitative value, the secondary indicator score of the secondary indicator of the predetermined functional unit is determined.
4. The method according to claim 2, characterized in that, The step of obtaining the secondary weights corresponding to the secondary indicators includes: Identify multiple similar test units of the same type as the predetermined functional unit; Based on the scores of the secondary indicators corresponding to the multiple similar test units, the secondary weights corresponding to the secondary indicators are obtained.
5. The method according to claim 4, characterized in that, Obtaining the first-level weight corresponding to the first-level indicator includes: Based on the secondary weights and the scores of the secondary indicators corresponding to the multiple similar test units, the primary weights corresponding to the primary indicators are obtained.
6. The method according to claim 4, characterized in that, The step of obtaining the secondary weights corresponding to the secondary indicators based on the scores of the secondary indicators corresponding to the multiple similar test units includes: Based on the similar test scores of the secondary indicators corresponding to the multiple similar test units, the secondary coefficient of variation corresponding to the secondary indicators is obtained. The second-order coefficient of variation is subjected to a second normalization process to obtain the second-order weights of the second-order indicators.
7. The method according to claim 5, characterized in that, The step of obtaining the primary weight corresponding to the primary indicator based on the secondary weight and the similar test scores of the secondary indicators corresponding to the multiple similar test units includes: Based on the secondary weights and the scores of the secondary indicators corresponding to the multiple similar test units, the primary coefficient of variation corresponding to the primary indicator is obtained. The first-level coefficient of variation is subjected to a third normalization process to obtain the first-level weight of the first-level index.
8. The method according to any one of claims 1 to 7, characterized in that, Based on the intrinsic safety score, the individual vehicle safety score, and the cooperative safety score, the comprehensive safety score of the autonomous vehicle is obtained, including: Determine the first weight corresponding to the intrinsic security score, the second weight corresponding to the single vehicle security score, and the third weight corresponding to the collaborative security score; Based on the intrinsic safety score, the first weight, the single-vehicle safety score, the second weight, the collaborative safety score, and the third weight, the comprehensive safety score of the autonomous vehicle is obtained.
9. A non-volatile storage medium, characterized in that, The non-volatile storage medium stores multiple instructions adapted for loading and execution by a processor of the safety assessment method for autonomous vehicles according to any one of claims 1 to 8.
10. An electronic device, characterized in that, include: One or more processors and a memory, the memory being used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors cause the one or more processors to implement the safety assessment method for an autonomous vehicle according to any one of claims 1 to 8.