Control method for an autonomous vehicle

By acquiring abnormal state information of autonomous vehicles, determining the type of abnormality and its fault level, and implementing corresponding control schemes, the safety issues of autonomous vehicles in the event of a fault are solved, achieving comprehensive fault detection and timely control, and improving the safety of vehicles and passengers.

CN116331237BActive Publication Date: 2026-05-29PURPLE MOUNTAIN LAB

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
PURPLE MOUNTAIN LAB
Filing Date
2023-02-27
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

Existing autonomous vehicles lack comprehensive detection and timely safety control measures when malfunctions occur, resulting in insufficient passenger safety.

Method used

By acquiring abnormal state information of autonomous vehicles, the abnormality type and its corresponding fault level are determined, and corresponding control schemes, such as emergency braking and parking, are implemented based on the fault level to ensure the safe operation of the vehicle.

Benefits of technology

It enables comprehensive detection and timely control of malfunctions in autonomous vehicles, improving vehicle and passenger safety and enhancing the passenger experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116331237B_ABST
    Figure CN116331237B_ABST
Patent Text Reader

Abstract

The application discloses a control method of an automatic driving vehicle. The method comprises the following steps: acquiring abnormal state information of the automatic driving vehicle, wherein the abnormal state information comprises first state information for representing that a domain controller in the automatic driving vehicle is abnormal, and second state information for representing that a communication state of the automatic driving vehicle is abnormal; determining an abnormal type of the automatic driving vehicle based on the abnormal state information, wherein the abnormal type comprises a first abnormal type of the domain controller and a second abnormal type of a data transmission bus; determining a fault level corresponding to the abnormal type, wherein the fault level is used for representing an influence degree of the abnormal type on normal driving of the automatic driving vehicle; and controlling the automatic driving vehicle to run based on a preset control scheme corresponding to the fault level. The application solves the technical problem that related technologies cannot comprehensively find vehicle faults and take corresponding control measures.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of vehicle control, and more specifically, to a control method for an autonomous vehicle. Background Technology

[0002] As the real-world application scenarios of autonomous vehicles become increasingly complex, people's safety requirements for autonomous vehicles are also increasing. Currently, existing measures for degrading the operation of autonomous vehicles mainly focus on human-vehicle interaction and alarms after anomalies are detected. They do not take timely and autonomous safety measures to protect passengers and vehicles. Furthermore, they only focus on the failure of a certain module, and the measures for classifying and handling failures are too simplistic, which greatly diminishes the passenger's riding experience and may even endanger passenger safety.

[0003] There is currently no effective solution to the above problems. Summary of the Invention

[0004] This invention provides a control method for autonomous vehicles, which at least solves the technical problem that related technologies cannot fully detect vehicle faults and take corresponding control measures.

[0005] According to one aspect of the present invention, a control method for an autonomous vehicle is provided, comprising: acquiring abnormal state information of the autonomous vehicle, wherein the abnormal state information includes: first state information indicating an abnormality in the domain controller of the autonomous vehicle, and second state information indicating an abnormality in the communication state of the autonomous vehicle; determining an abnormality type of the autonomous vehicle based on the abnormal state information, wherein the abnormality type includes: a first abnormality type of the domain controller and a second abnormality type of the data transmission bus; determining a fault level corresponding to the abnormality type, wherein the fault level is used to characterize the degree of impact of the abnormality type on the normal operation of the autonomous vehicle; and controlling the operation of the autonomous vehicle based on a preset control scheme corresponding to the fault level.

[0006] Optionally, obtaining abnormal state information of the autonomous vehicle includes: in response to an abnormality in the domain controller, obtaining the current state information sent by the domain controller and the fault information of the electronic devices corresponding to the domain controller to obtain first state information; obtaining the data transmission state information of the data transmission bus to obtain second state information.

[0007] Optionally, determining the fault level corresponding to the anomaly type includes: matching the anomaly type with multiple preset anomaly types to obtain a target anomaly type that successfully matches the anomaly type; and determining the preset level corresponding to the target anomaly type as the fault level.

[0008] Optionally, in response to the failure of an exception type to match multiple preset exception types, the method further includes: obtaining the fault cause corresponding to the exception type; evaluating the fault cause to obtain the fault level corresponding to the exception type.

[0009] Optionally, based on a preset control scheme corresponding to the fault level, the operation of the autonomous vehicle is controlled, including one of the following: disconnecting the power supply to the autonomous vehicle; controlling the autonomous vehicle to perform emergency braking; controlling the autonomous vehicle to perform non-emergency braking; controlling the autonomous vehicle to pull over to the side of the road; controlling the autonomous vehicle to drive to the target stop and stop; controlling the autonomous vehicle to drive to the second stop and stop after completing the current scheduling task; controlling the speed of the autonomous vehicle to be less than a preset value; controlling the autonomous vehicle to remain stationary; controlling the autonomous vehicle to output alarm information, wherein the alarm information is used to indicate that the autonomous vehicle has malfunctioned.

[0010] Optionally, controlling the autonomous vehicle to perform emergency braking includes: acquiring first driving information of the autonomous vehicle, wherein the first driving information includes: chassis status information, vehicle positioning information, information of a first obstacle in front of the autonomous vehicle, and navigation route information; generating a future driving trajectory of the autonomous vehicle based on the first driving information and the historical planned trajectory of the autonomous vehicle; determining an emergency braking mode of the autonomous vehicle based on the first obstacle information and the vehicle driving trajectory, wherein different emergency braking modes are used to apply different braking methods to the autonomous vehicle; and controlling the autonomous vehicle to brake based on the emergency braking mode.

[0011] Optionally, based on the first obstacle information and the vehicle's driving trajectory, determining the emergency braking mode of the autonomous vehicle includes: minimizing the vehicle's driving trajectory and maximizing the deceleration of the autonomous vehicle to obtain a first emergency braking trajectory of the autonomous vehicle; obtaining the sum of the displacement of the first emergency braking trajectory and the stopping safety distance of the autonomous vehicle to obtain a preset distance; in response to the obstacle distance in the first obstacle information being greater than the preset distance, determining the emergency braking mode as the first braking mode, wherein the first braking mode is used to control the autonomous vehicle to brake according to the vehicle's driving trajectory; in response to the obstacle distance being less than or equal to the preset distance, determining the emergency braking mode as the second braking mode, wherein the second braking mode is used to control the brake pedal of the autonomous vehicle to brake at multiple different opening degrees.

[0012] Optionally, controlling the autonomous vehicle to perform non-emergency braking includes: acquiring first driving information of the autonomous vehicle, wherein the driving information includes: chassis status information, vehicle positioning information, information of a first obstacle in front of the autonomous vehicle, and navigation route information; generating a vehicle driving trajectory for the autonomous vehicle at a future time based on the first driving information and the historical planned trajectory of the autonomous vehicle; maximizing the vehicle driving trajectory and minimizing the deceleration of the autonomous vehicle to obtain a second emergency braking trajectory of the autonomous vehicle; and controlling the autonomous vehicle to brake based on the second emergency braking trajectory.

[0013] Optionally, controlling the autonomous vehicle to pull over includes: acquiring second driving information of the autonomous vehicle, wherein the second driving information includes lateral displacement, velocity, and acceleration; performing trajectory fitting on the autonomous vehicle based on the second driving information to obtain the motion trajectory of the autonomous vehicle; acquiring perception information of the autonomous vehicle, wherein the perception information includes second obstacle information in the lateral direction and lane line information around the autonomous vehicle; and controlling the autonomous vehicle to pull over based on the perception information and the motion trajectory.

[0014] Optionally, the above method further includes: determining a target fault level in the fault levels, wherein the target fault level is higher than other fault levels in the fault levels; obtaining a control scheme corresponding to the target fault level to obtain a preset control scheme.

[0015] According to another aspect of the present invention, a control system for an autonomous vehicle is also provided, comprising: a status data receiving module, configured to acquire abnormal status information of the autonomous vehicle, wherein the abnormal status information includes: first status information indicating an abnormality in the domain controller of the autonomous vehicle, and second status information indicating an abnormality in the communication status of the autonomous vehicle; a fault diagnosis and classification module, configured to determine the abnormality type of the autonomous vehicle based on the abnormal status information, and determine the fault level corresponding to the abnormality type, wherein the abnormality type includes: a first abnormality type of the domain controller and a second abnormality type of the data transmission bus, and the fault level is used to characterize the degree of impact of the abnormality type on the normal operation of the autonomous vehicle; and a vehicle control module, configured to control the operation of the autonomous vehicle based on a preset control scheme corresponding to the fault level.

[0016] According to another aspect of the present invention, a computer-readable storage medium is also provided, the computer-readable storage medium including a stored program, wherein, when the program is executed, it controls the device where the computer-readable storage medium is located to execute the above-described control method for an autonomous vehicle.

[0017] According to another aspect of the present invention, a processor is also provided, which is used to run a program, wherein the program executes the above-described control method for an autonomous vehicle when it runs.

[0018] In this embodiment of the invention, abnormal state information of an autonomous vehicle is acquired, and based on this information, the abnormal type of the autonomous vehicle is determined. Then, the fault level corresponding to the abnormal type is determined, and the autonomous vehicle is controlled to operate based on a preset control scheme corresponding to the fault level. It should be noted that the abnormal type includes: a first abnormal type of the domain controller and a second abnormal type of the data transmission bus. The fault level is used to characterize the degree of impact of the abnormal type on the normal operation of the autonomous vehicle. By acquiring abnormal information of the vehicle's domain controller and communication status, the abnormal type and corresponding fault level of the vehicle are determined, and a corresponding control scheme is set based on the fault level. This achieves the purpose of effectively evaluating various abnormalities found during the operation of the autonomous vehicle and taking corresponding degrading measures. This realizes the technical effect of comprehensively detecting vehicle faults and taking different control schemes for different abnormal types, thereby solving the technical problem that related technologies cannot comprehensively detect vehicle faults and take corresponding control measures. Attached Figure Description

[0019] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this application, illustrate exemplary embodiments of the invention and, together with their description, serve to explain the invention and do not constitute an undue limitation thereof. In the drawings:

[0020] Figure 1 This is a flowchart of a control method for an autonomous vehicle according to an embodiment of the present invention;

[0021] Figure 2 This is a schematic diagram of a degraded operation system for an autonomous vehicle according to an embodiment of the present invention;

[0022] Figure 3 This is a schematic diagram of a control system for an autonomous vehicle according to an embodiment of the present invention. Detailed Implementation

[0023] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0024] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0025] Example 1

[0026] According to an embodiment of the present invention, a control method for an autonomous vehicle is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.

[0027] Figure 1 This is a flowchart of a control method for an autonomous vehicle according to an embodiment of the present invention, such as... Figure 1 As shown, the method includes the following steps:

[0028] Step S102: Obtain abnormal state information of the autonomous vehicle, wherein the abnormal state information includes: first state information indicating that the domain controller in the autonomous vehicle is abnormal, and second state information indicating that the communication state of the autonomous vehicle is abnormal.

[0029] In this context, a domain controller can be a server computer that responds to secure authentication requests within a computer network domain. It is responsible for data computation and overall control functions of the key functional domains of the autonomous vehicle. The key functional domains of an autonomous vehicle are derived from its electronic and electrical architecture and include, but are not limited to, the autonomous driving domain, chassis domain, powertrain domain, body domain, and connectivity domain. The autonomous driving domain is responsible for the vehicle's autonomous driving functions. The chassis domain contains the vehicle's actuators and can provide feedback on the vehicle's driving status data to the autonomous driving system. The powertrain domain manages the vehicle's energy usage status. The body domain manages the usage status of vehicle-related components such as lights, doors, windows, and wipers. The connectivity domain enables interconnection and interoperability of information between the vehicle and the outside world, establishing comprehensive network links between the vehicle and cloud platforms, between vehicles, between vehicles and roads, between vehicles and people, and within the vehicle network. The first state information can be the domain controller's state information, and the second state information can be the vehicle communication state information.

[0030] In one alternative embodiment, the first state information can be obtained through an electronic control unit (ECU) and connected sensors, and the second state information can be obtained through data monitoring.

[0031] Step S104: Based on the abnormal state information, determine the abnormal type of the autonomous vehicle, wherein the abnormal type includes: the first abnormal type of the domain controller and the second abnormal type of the data transmission bus.

[0032] The first anomaly type can be an anomaly type of the domain controller, including but not limited to: no output data, data tampering, abnormal processing results, and other unknown anomalies. The anomaly types of the ECU and sensors are determined by the specific product repair manual. The second anomaly type can be an anomaly type of the data transmission bus, including but not limited to: communication interruption, communication delay, communication link attack, and other anomalies.

[0033] In one alternative embodiment, the first anomaly type can be determined by the ECU and the connected sensors, and the second anomaly type can be obtained by monitoring the data transmission status of the connected CAN bus network and Ethernet network, receiving network communication status information, and detecting and confirming communication status anomalies and specific anomaly types.

[0034] Step S106: Determine the fault level corresponding to the anomaly type, wherein the fault level is used to characterize the degree of impact of the anomaly type on the normal operation of the autonomous vehicle.

[0035] In one optional embodiment, a hazard analysis can be performed on the received domain controller anomalies (i.e., communication node anomalies) and data transmission status anomalies (i.e., communication status anomalies). This analysis assesses the severity of the potential consequences of the anomalies on the passenger and vehicle status. Then, a reasonable severity classification of autonomous vehicle faults is established, and a fault severity level table corresponding to the anomaly type is created to determine the fault level corresponding to the anomaly type.

[0036] Specifically, the fault levels may include, but are not limited to, nine fault levels from E0 to E8. Among them, E0 is the highest fault level, E8 is the lowest fault level, and so on for intermediate levels.

[0037] Step S108: Control the operation of the autonomous vehicle based on the preset control scheme corresponding to the fault level.

[0038] The preset control scheme can be pre-set. For different fault levels received, the corresponding vehicle control method is invoked based on the vehicle's current status and information about obstacles in front of the vehicle.

[0039] Specifically, when the fault level is E0, the vehicle is considered uncontrollable and the danger is unavoidable. The only course of action is to disconnect the power supply to the autonomous vehicle by cutting off the high voltage to minimize the impact on people and the vehicle. When the fault level is E1, a collision is considered unavoidable or at the critical point, but the vehicle is controllable. The most urgent braking control method must be used to stop the vehicle to minimize the impact on people and the vehicle or to avoid a collision altogether. When the fault level is E2, the vehicle is considered controllable, and while collision conditions exist, they can be avoided. Non-emergency braking can be used to control the vehicle's braking, avoiding a collision and improving passenger comfort during braking. When the fault level is E3, the vehicle is considered not capable of autonomous driving. Continuing to drive may trigger a collision. The vehicle should be pulled over and driven only after the anomaly is resolved. When the fault level is E4, the vehicle is considered capable of short-term autonomous driving, but a collision may occur after a certain period. The nearest parking spot should be found. When the fault level is E5, the vehicle can be considered to have short-term autonomous driving capabilities, but after a certain period, a collision may be triggered. Furthermore, due to its own task scheduling issues, the vehicle cannot immediately adopt a parking method other than the currently planned task. In this case, the vehicle needs to complete the current scheduling task, such as picking up or dropping off passengers, loading or unloading goods, or leaving the task point, and then find the nearest parking point, safely arriving at that point and braking to a stop. When the fault level is E6, the vehicle can be considered to have autonomous driving capabilities and no collision conditions exist. However, due to special driving scenario limitations, the vehicle speed needs to be limited to a certain value. In this case, the vehicle should be controlled to travel at the limited speed value. When the fault level is E7, the vehicle is considered to be stationary and there is an anomaly. In this case, the vehicle's autonomous driving function needs to be locked, and the vehicle should remain stationary until the anomaly is resolved before the vehicle is unlocked. When the fault level is E8, the existing anomaly has no impact on the vehicle's current operating status; only an alarm is issued.

[0040] In this embodiment of the invention, abnormal state information of an autonomous vehicle is acquired, and based on this information, the abnormal type of the autonomous vehicle is determined. Then, the fault level corresponding to the abnormal type is determined, and the autonomous vehicle is controlled to operate based on a preset control scheme corresponding to the fault level. It should be noted that the abnormal type includes: a first abnormal type of the domain controller and a second abnormal type of the data transmission bus. The fault level is used to characterize the degree of impact of the abnormal type on the normal operation of the autonomous vehicle. By acquiring abnormal information of the vehicle's domain controller and communication status, the abnormal type and corresponding fault level of the vehicle are determined, and a corresponding control scheme is set based on the fault level. This achieves the purpose of effectively evaluating various abnormalities found during the operation of the autonomous vehicle and taking corresponding degrading measures. This realizes the technical effect of comprehensively detecting vehicle faults and taking different control schemes for different abnormal types, thereby solving the technical problem that related technologies cannot comprehensively detect vehicle faults and take corresponding control measures.

[0041] Optionally, obtaining abnormal state information of the autonomous vehicle includes: in response to an abnormality in the domain controller, obtaining the current state information sent by the domain controller and the fault information of the electronic devices corresponding to the domain controller to obtain first state information; obtaining the data transmission state information of the data transmission bus to obtain second state information.

[0042] The current status information can be the status information of the domain controller during its current operation, the fault information of electronic devices can include but is not limited to the fault location and fault severity, and the data transmission status information can include but is not limited to normal and abnormal.

[0043] In one alternative embodiment, the current status information sent by the domain controller can be obtained through the ECU and connected sensors, and the data transmission status information of the data transmission bus can be obtained through data monitoring.

[0044] Optionally, determining the fault level corresponding to the anomaly type includes: matching the anomaly type with multiple preset anomaly types to obtain a target anomaly type that successfully matches the anomaly type; and determining the preset level corresponding to the target anomaly type as the fault level.

[0045] Among them, the preset abnormality type can be any type of abnormality that the vehicle has been preset in advance, the target abnormality type can be a preset abnormality type that matches the current abnormality type of the vehicle, and the preset level can be a preset fault level, which can be represented by nine fault levels from E0 to E8.

[0046] In one optional embodiment, the anomaly type can be matched with multiple preset anomaly types by keyword comparison to obtain the target anomaly type that successfully matches the anomaly type. The preset level corresponding to the target anomaly type can be determined as the fault level by looking up a table.

[0047] Specifically, based on the acquired first and second state information, a fault severity level table is formed after assessing the degree of fault danger, and an abnormal alarm message is sent to the vehicle terminal. The severity level of any known abnormalities subsequently discovered can be obtained by directly looking up the table.

[0048] Optionally, in response to the failure of an exception type to match multiple preset exception types, the method further includes: obtaining the fault cause corresponding to the exception type; evaluating the fault cause to obtain the fault level corresponding to the exception type.

[0049] Among them, the cause of the malfunction can be any factor that leads to the vehicle malfunction.

[0050] Understandably, when an unknown anomaly occurs in a vehicle, the severity level of the fault is assessed based on the fault location and description, matched with the existing fault severity level, and then the anomaly of this type and the corresponding fault level are added to the aforementioned fault severity level table.

[0051] Optionally, the above method further includes: determining a target fault level in the fault levels, wherein the target fault level is higher than other fault levels in the fault levels; obtaining a control scheme corresponding to the target fault level to obtain a preset control scheme.

[0052] The target fault level can be the level corresponding to the fault currently occurring in the vehicle.

[0053] Specifically, as shown in step S108, different fault levels correspond to different control schemes.

[0054] Optionally, based on a preset control scheme corresponding to the fault level, the operation of the autonomous vehicle is controlled, including one of the following: disconnecting the power supply to the autonomous vehicle; controlling the autonomous vehicle to perform emergency braking; controlling the autonomous vehicle to perform non-emergency braking; controlling the autonomous vehicle to pull over to the side of the road; controlling the autonomous vehicle to drive to the target stop and stop; controlling the autonomous vehicle to drive to the second stop and stop after completing the current scheduling task; controlling the speed of the autonomous vehicle to be less than a preset value; controlling the autonomous vehicle to remain stationary; controlling the autonomous vehicle to output alarm information, wherein the alarm information is used to indicate that the autonomous vehicle has malfunctioned.

[0055] The target stop can be the stop closest to the current vehicle. The current dispatch task can include, but is not limited to, picking up or dropping off passengers, loading or unloading goods, or leaving the task point. The second stop can be the stop closest to the vehicle after completing the current dispatch task. The preset value can be the vehicle speed limited by special scenarios.

[0056] In an optional embodiment, the vehicle can be controlled by a vehicle control device to execute the above control scheme. Alarm information can be fed back to the user via an audio feedback device. The audio feedback device can be understood as any device capable of providing audio feedback, such as a horn or other device equipped with a horn. The normal passage notification fed back by the audio feedback device can be a semantically meaningful sound or a non-semantic, identifiable sound. For example, a normal vehicle status notification is a single "beep," and an abnormal vehicle status notification is three "beep beep beep" sounds.

[0057] Specifically, as described in step S108, the above control schemes correspond to nine fault levels, from E0 to E8.

[0058] Optionally, controlling the autonomous vehicle to perform emergency braking includes: acquiring first driving information of the autonomous vehicle, wherein the driving information includes: chassis status information, vehicle positioning information, information of a first obstacle in front of the autonomous vehicle, and navigation route information; generating the vehicle's driving trajectory at a future time based on the first driving information and the autonomous vehicle's historical planned trajectory; determining the emergency braking mode of the autonomous vehicle based on the first obstacle information and the vehicle's driving trajectory, wherein different emergency braking modes are used to apply different braking methods to the autonomous vehicle; and controlling the autonomous vehicle to brake based on the emergency braking mode.

[0059] Among them, chassis status information can be normal or abnormal, vehicle positioning information can be the vehicle's current specific location, first obstacle information can be the perceived obstacle information in front of the vehicle, navigation route information can be the specific route of vehicle navigation, historical planning trajectory can be the vehicle's historical braking planning trajectory, and emergency braking mode can be the method of controlling the vehicle to perform emergency braking.

[0060] In one alternative embodiment, the initial driving information of the autonomous vehicle can be obtained through devices such as sensors and positioning systems.

[0061] Specifically, the system generates the vehicle's trajectory for future moments, including establishing a vehicle braking trajectory planning method, i.e., the trajectory planning module of the vehicle degraded operation system. Based on chassis status information, vehicle positioning information, perceived obstacle information, and navigation route information, and combined with the vehicle's historical planned trajectory, the system periodically generates the vehicle's braking trajectory in a forward-predicted state. It creates a data receiving and processing timer for the planning module and a vehicle driving path reference line generator, and starts the corresponding processing threads. Based on the received braking signal, it calls the scene planner for processing. The scene planner receives external chassis status information, vehicle positioning information, perceived obstacle information, and navigation route information, processes them, and updates the vehicle status information, perception fusion information, and navigation route information. If a new navigation route exists, it calls the map data interface to obtain high-precision map data within a certain range in front of and behind the vehicle, including road information, lane information, intersections, traffic lights, pedestrian crossings, speed limit signs, no-stopping signs, etc., and generates a set of reference lines for vehicle driving based on this local high-precision map data. If no new navigation route exists, the road map data is updated based on the vehicle's forward direction planned by the reference line generator and a certain range of straight paths behind the vehicle, and a simplified vehicle driving reference line is generated accordingly. Based on the vehicle's current state and historical planned trajectories, and considering the vehicle's control delay, the pre-control state of the vehicle is predicted and updated, serving as the starting point for trajectory planning. This planned starting point is then stitched together with the vehicle's previous planned trajectory to ensure the continuity of the overall planned trajectory and the smoothness of vehicle control. Based on the vehicle's current state, information about obstacles ahead, the previous frame's planned trajectory information, and the trajectory planning starting point, the trajectory planning method is called to generate the vehicle's displacement and velocity data along each reference line by traversing the reference line set. The vehicle's displacement data along the reference lines is planned by projecting the planned starting point onto the corresponding reference line using internal coordinates, and then using linear interpolation at certain intervals to extract and convert path points on the reference lines as displacement data points.

[0062] Optionally, based on the first obstacle information and the vehicle's driving trajectory, determining the emergency braking mode of the autonomous vehicle includes: minimizing the vehicle's driving trajectory and maximizing the deceleration of the autonomous vehicle to obtain a first emergency braking trajectory of the autonomous vehicle; obtaining the sum of the displacement of the first emergency braking trajectory and the stopping safety distance of the autonomous vehicle to obtain a preset distance; in response to the obstacle distance in the first obstacle information being greater than the preset distance, determining the emergency braking mode as the first braking mode, wherein the first braking mode is used to control the autonomous vehicle to brake according to the vehicle's driving trajectory; in response to the obstacle distance being less than or equal to the preset distance, determining the emergency braking mode as the second braking mode, wherein the second braking mode is used to control the brake pedal of the autonomous vehicle to brake at multiple different opening degrees.

[0063] The first emergency braking trajectory can be the braking trajectory after the vehicle's driving trajectory and deceleration have been replanned, and the preset distance can be understood as the maximum distance between the vehicle and the obstacle after the vehicle has come to a smooth stop based on the calculated braking trajectory.

[0064] Specifically, determining the emergency braking mode for an autonomous vehicle can include: planning the vehicle's speed data along a reference line, first determining whether replanning the speed data is needed based on the projection of the planned starting point onto the planned trajectory in the previous frame. If the remaining distance from the projection point to the end point of the planned trajectory... Less than the distance from the vehicle to the first obstacle in front Subtract the safe stopping distance from the obstacle after the vehicle stops. ,Right now If the speed data is correct, there is no need to replan the speed data; the speed data from the previous frame of the planned trajectory can be used, with adjustments made to the relative distance between the speed data and the planning starting point. Otherwise, the speed data should be replanned starting from the planning starting point, following a three-segment S-shaped braking curve. The state transitions to a state where the deceleration decreases uniformly. State, rate of change of deceleration Where s, v, and a are the vehicle's displacement, velocity, and acceleration state values, The initial braking speed, This represents the distance the vehicle traveled after the first phase ended. This represents the vehicle's speed after the first phase ends. This represents the maximum deceleration reached by the vehicle after the first stage, and it is a positive value. It then transitions to uniform deceleration. status, in which This represents the distance the vehicle traveled after the second phase ended. This represents the vehicle's speed after the second stage ends. Finally, it transitions to a speed that increases uniformly with deceleration. State, rate of change of deceleration ,in This represents the distance the vehicle travels after the third stage, which is the final distance the vehicle travels along the planned trajectory. In these three stages... Given a known quantity, we can obtain and Constraint relationships, among which , The maximum deceleration value is not greater than the maximum deceleration value in the vehicle's throttle / brake calibration. Combined with the vehicle's motion process, the vehicle's velocity data along the reference line is finally established, including time-domain state information such as time, displacement, velocity, acceleration, and jerk during the vehicle's motion process. The displacement data and velocity data of the vehicle along the corresponding reference line are linearly estimated at fixed time intervals to finally form the vehicle's driving trajectory along the corresponding reference line.

[0065] Based on the planned trajectory of the corresponding reference lines, a trajectory evaluation equation and a comprehensive cost function are established by considering the curvature change of the trajectory curve, lateral offset, distance from obstacles, and degree of deviation from the reference lines. The total cost value of each reference line trajectory is calculated, and the reference line trajectory with the smallest cost value is selected as the final vehicle driving trajectory. The relative time of the trajectory is corrected by combining the current timestamp information, and the trajectory data is released periodically.

[0066] A braking control method for the vehicle along the planned trajectory is established, which is the control module of the vehicle degraded operation system. Based on the generated vehicle driving trajectory, combined with chassis status information, vehicle positioning information, and vehicle throttle / brake calibration information, lateral and longitudinal control commands are periodically generated to control the vehicle to brake along the planned trajectory;

[0067] A vehicle lateral control method based on a linear quadratic optimal control algorithm is established. The vehicle dynamics equations are established based on the vehicle's overall parameters and longitudinal velocity. The coefficient matrices A and B in the state equations are solved, and the continuous state equations are discretized. A linear quadratic regulator (LQR) objective function is established based on the state matrices A and B. Through iterative optimization, the objective function achieves the required iterative accuracy, yielding the optimal state feedback matrix K. The vehicle's state parameters at the pre-aiming time point are predicted in advance, taking into account the vehicle's state and planned trajectory information. The predicted state is compared with the current state to obtain the lateral control error and the curvature information of the pre-aiming point. The optimal state feedback matrix, along with the overall vehicle parameter information and the pre-aiming point curvature information, is used to calculate the feedforward control output to eliminate steady-state errors. Based on the previously calculated state feedback matrix, lateral control error, and feedforward control output, the final control output steering angle is calculated. According to the chassis control protocol, this steering command is periodically sent to the vehicle chassis to control the vehicle's steering process.

[0068] A vehicle longitudinal control method based on the proportional, integral, and derivative (PID) control algorithm for dual-loop deviation is established.

[0069] Establish the underlying logic of PID control, calculate the PID control output according to the PID discretization calculation formula, initialize the position PID and speed PID parameters according to the control module configuration information, and load the throttle / brake calibration table, which is obtained by conducting longitudinal dynamic calibration tests on a specific vehicle in advance.

[0070] A control module timer is established to periodically receive external chassis status information, vehicle positioning information, and trajectory planning information, and performs data verification and reception timeout handling. Based on the received chassis status and vehicle positioning information, the vehicle status data is updated. According to the initial braking speed of the planned trajectory, a PID parameter interpolation table is consulted to set the position PID and speed PID control parameters for a specific initial braking speed, thus obtaining the optimal control parameters for different initial braking speeds. This PID parameter interpolation table is obtained by pre-tuning the position PID and speed PID for a specific vehicle at different initial braking speeds. With a certain lead-in time, combined with vehicle status and planned trajectory information, the vehicle's state parameters are predicted in advance after the lead-in time. The predicted vehicle state is compared with the current state to obtain the longitudinal control error. This error value is used to calculate and output the acceleration control output value through the position PID and speed PID, and then undergoes acceleration slope compensation and control dead zone acceleration correction to obtain the final acceleration output. The corresponding throttle / brake command value is obtained by consulting the throttle / brake calibration table, and a unique brake or throttle opening is obtained after throttle / brake singularity processing. Finally, according to the chassis control protocol, this opening command is periodically sent to the vehicle chassis to control the vehicle's longitudinal acceleration or deceleration process.

[0071] Establish a segmented pressure-based braking control method. When the distance to the first obstacle in front of the vehicle is less than the limit braking distance... When a safe parking distance is added, the maximum opening type of emergency braking is used to stop the vehicle. Current vehicle speed Let g be the coefficient of friction, and g be the acceleration due to gravity. When the distance to the obstacle is greater than the distance required for a smooth stop plus the safe stopping distance, a smaller brake opening is used for smooth braking. When the distance to the obstacle is greater than the maximum braking distance plus the safe stopping distance but less than the smooth stopping distance plus the safe stopping distance, a time-to-collision (TTC) graded braking system based on a time-to-ground safety distance model is used, i.e., when... At that time, there was no action. At this time, apply partial braking by adjusting the brake opening to a suitable degree. Full braking with maximum braking opening is initiated at this time, where T = (d - d0) / V, d is the distance to the obstacle, d0 is the safe stopping distance, and V is the vehicle speed. , The vehicle's smooth braking opening value and partial braking opening value were obtained from actual vehicle testing.

[0072] An emergency braking vehicle control method is established. First, the planning module outputs the final emergency braking trajectory based on constraints of maximizing braking deceleration and minimizing the planned trajectory displacement. Then, the distance between the vehicle and the obstacle ahead is determined. Parking safety distance and the final displacement of the planned trajectory during emergency braking (i.e., the distance required for a smooth stop as mentioned above) relationship, if If the emergency braking fails, the control module will use emergency braking to stop the vehicle according to the planned trajectory; otherwise, segmented pressure-type emergency braking will be used.

[0073] Optionally, controlling the autonomous vehicle to perform non-emergency braking includes: acquiring first driving information of the autonomous vehicle, wherein the driving information includes: chassis status information, vehicle positioning information, information of a first obstacle in front of the autonomous vehicle, and navigation route information; generating a vehicle driving trajectory for the autonomous vehicle at a future time based on the first driving information and the historical planned trajectory of the autonomous vehicle; maximizing the vehicle driving trajectory and minimizing the deceleration of the autonomous vehicle to obtain a second emergency braking trajectory of the autonomous vehicle; and controlling the autonomous vehicle to brake based on the second emergency braking trajectory.

[0074] Among them, chassis status information can be normal or abnormal, vehicle positioning information can be the vehicle's current specific positioning, first obstacle information can be the perceived obstacle information in front of the vehicle, navigation route information can be the specific route of vehicle navigation, historical planning trajectory can be the vehicle's historical braking planning trajectory, emergency braking mode can be the way to control the vehicle to perform emergency braking, and second emergency braking trajectory can be the braking trajectory after replanning the vehicle's driving trajectory and deceleration.

[0075] In one alternative embodiment, the initial driving information of the autonomous vehicle can be obtained through devices such as sensors and positioning systems.

[0076] Specifically, controlling an autonomous vehicle to perform non-emergency braking can include: first, the planning module outputs the final emergency braking planning trajectory with the constraints of maximizing the planned trajectory displacement and minimizing the braking deceleration value; then, the control module controls the vehicle to perform non-emergency braking along the planned trajectory.

[0077] Optionally, controlling the autonomous vehicle to pull over includes: acquiring second driving information of the autonomous vehicle, wherein the second driving information includes lateral displacement, velocity, and acceleration; performing trajectory fitting on the autonomous vehicle based on the second driving information to obtain the motion trajectory of the autonomous vehicle; acquiring perception information of the autonomous vehicle, wherein the perception information includes second obstacle information in the lateral direction and lane line information around the autonomous vehicle; and controlling the autonomous vehicle to pull over based on the perception information and the motion trajectory.

[0078] The second obstacle information can be the location and size of the obstacle perceived by the vehicle in the lateral direction, and the lane line information can be the number and specific location of the lane lines.

[0079] In one alternative embodiment, second driving information of the autonomous vehicle can be obtained through displacement sensors, velocity sensors, and acceleration sensors.

[0080] Specifically, controlling an autonomous vehicle to pull over to the side of the road can include: a planning module, based on the vehicle's kinematics model, determining the initial and final states of the vehicle performing the pull-over task in the Frenet coordinate system—namely, its lateral and longitudinal displacements, velocities, and accelerations—and fitting its longitudinal trajectory using a fifth-order polynomial. and lateral trajectory The longitudinal trajectory It is a function of time, a horizontal trajectory. It is a function of longitudinal displacement, which is determined by the vehicle's kinematic model. Then the lateral trajectory is transformed. a function of time Thus, the lateral and longitudinal time-domain motion trajectories of the vehicle are obtained;

[0081] The lateral and longitudinal controllers of the control module are invoked to control the vehicle to park along the planned trajectory. During this process, obstacle information on the side where the vehicle is parked needs to be taken into account. If there are no obstacles on the side where the vehicle is parked within the lateral trajectory range, the vehicle is controlled to drive along the planned trajectory. If there are obstacles, the Time-to-Traffic (TTC) value between the obstacle and the lateral trajectory control point is calculated using a time-distance-based safe distance model. If the TTC value is greater than the relative time to the lateral trajectory control point, the vehicle is controlled to drive along the planned trajectory normally. If the TTC value is less than or equal to the relative time to the lateral trajectory control point and the trend of change is gradually decreasing, the lateral controller sends a lane-keeping signal.

[0082] Upon receiving the lane keeping signal, the planning module actively requests lane centerline information at a certain distance before and after the current vehicle's lane from the high-precision map data service. If the request fails, the lane centerline information is generated from the left and right lane lines perceived by the vehicle. Using this lane centerline information as a reference line, a constant-speed driving trajectory is generated along this reference line, and the control module simultaneously controls the vehicle to travel along this trajectory.

[0083] When the TTC value of the obstacle on the side of the road perceived by the vehicle is greater than a certain threshold and the trend of change is gradually increasing, the vehicle will re-execute the task of parking on the side of the road.

[0084] Specifically, the above method also includes: a vehicle control method for parking at the nearest station. The planning module first obtains the nearest necessary point on the navigation route to the vehicle's current position as the endpoint of this planning. If there is no necessary point, the endpoint of the navigation route is used as the endpoint of the planned trajectory. Based on this, a parking trajectory near the nearest necessary point is established, and then the control module controls the vehicle to brake along this trajectory.

[0085] Establish a vehicle control method for stopping after completing the current scheduling task. First, obtain the execution status of the current planning task from the planning module. If the task is still in progress, the control module controls the vehicle to drive along the planned trajectory of the current planning task. If the planning module has completed the current task, the planning module plans the vehicle's braking trajectory using the untraveled route along a fixed distance of the navigation route as a reference line. Then, the control module controls the vehicle to brake along this trajectory.

[0086] Establish a speed-limited vehicle control method. Speed-limited driving considers the speed control of the vehicle under normal driving conditions along the navigation route. That is, the speed value of the vehicle along the reference line in the planning module is changed to a constant value, the displacement increases uniformly with time, and the acceleration and jerk are both zero. The planning module outputs the uniform motion trajectory of the vehicle along the navigation route, and then the control module controls the vehicle to drive along the planned trajectory at a limited speed.

[0087] Establish a vehicle control method that keeps the vehicle stationary while waiting. When the vehicle is stationary, if an anomaly is detected by the system status monitoring, the vehicle's driving mode is locked to emergency mode, and the vehicle is in a parked and locked state. When the system anomaly disappears, the vehicle is unlocked.

[0088] An intermediate state machine is established for vehicle mode task switching. When the autonomous driving system detects an anomaly and degrades, this state machine selects the appropriate vehicle control method based on the severity of the fault to brake and stop the vehicle. Simultaneously, during the execution of a vehicle control task, if a more severe anomaly occurs requiring a more urgent vehicle control task, this state machine switches tasks, calls the matching trajectory planning method and vehicle control method, generates autonomous driving control commands, and sends them to the vehicle chassis to control the vehicle to perform the corresponding actions.

[0089] Figure 2 This is a schematic diagram of a degraded operation system for an autonomous vehicle according to an embodiment of the present invention, such as... Figure 2As shown, the device mainly includes: a status data receiving module, used to acquire status information of key domain controllers connected to the system, status information of ECUs belonging to the domain controllers, status information of sensors belonging to the domain controllers, and data bus communication status information. The module prioritizes acquiring the status information of key domain controllers and bus communication. Only when a key domain controller malfunctions will it receive and filter the status information of the ECUs and connected sensors under the malfunctioning domain controller. Domain controller status malfunctions include ECU failures and sensor failures, while bus communication status malfunctions include communication terminal issues, communication delays, and network attacks.

[0090] The fault diagnosis and grading module is used to assess and grade the severity of faults based on the specific anomaly type of each critical domain controller or the data bus communication anomaly type, outputting the highest fault severity level and the corresponding fault code. When assessing and grading faults in critical domain controllers, the operating status of their redundant backup domain controllers is also considered. Only when all controllers in a corresponding functional domain exhibit anomalies will the fault severity be assessed as high; otherwise, the fault severity is low. Fault levels are divided into nine levels, from E0 to E8.

[0091] The vehicle control module is used to execute specific vehicle control methods and fault alarm methods based on the highest fault severity level and fault code output by the fault diagnosis and grading module, combined with the autonomous driving vehicle degraded operation strategy, to generate vehicle control commands, send them to the vehicle drive-by-wire chassis, and control the vehicle to perform corresponding actions, including emergency braking (graded pressure emergency braking and emergency braking along the planned trajectory) through the task state machine, non-emergency braking, parking on the side of the road, parking at the nearest station, parking after completing the current scheduling task, speed-limited driving, maintaining the parking state, and fault-only prompting. Then, the lateral controller and longitudinal controller of the trajectory planner control the vehicle drive-by-wire chassis.

[0092] Example 2

[0093] According to another aspect of the present invention, a control system for an autonomous vehicle is also provided. This system can execute the control method for the autonomous vehicle in Embodiment 1 above. The specific implementation scheme and application scenario in this embodiment are the same as those in Embodiment 1 above, and will not be repeated here.

[0094] Figure 3 This is a schematic diagram of a control system for an autonomous vehicle according to an embodiment of the present invention, such as... Figure 3As shown, the system includes: a status data receiving module 302, used to acquire abnormal status information of the autonomous vehicle, wherein the abnormal status information includes: first status information indicating that the domain controller in the autonomous vehicle is abnormal, and second status information indicating that the communication status of the autonomous vehicle is abnormal; a fault diagnosis and classification module 304, used to determine the abnormal type of the autonomous vehicle based on the abnormal status information, and determine the fault level corresponding to the abnormal type, wherein the abnormal type includes: a first abnormal type of the domain controller and a second abnormal type of the data transmission bus, and the fault level is used to characterize the degree of impact of the abnormal type on the normal operation of the autonomous vehicle; and a vehicle control module 306, used to control the operation of the autonomous vehicle based on a preset control scheme corresponding to the fault level.

[0095] The status data receiving module 302 includes: a first acquisition unit, used to acquire the current status information sent by the domain controller and the fault information of the electronic device corresponding to the domain controller in response to an anomaly of the domain controller, and obtain the first status information; and a second acquisition unit, used to acquire the data transmission status information of the data transmission bus, and obtain the second status information.

[0096] The fault diagnosis and classification module 304 includes: a type matching unit, used to match the abnormal type with multiple preset abnormal types to obtain the target abnormal type that successfully matches the abnormal type; and a level determination unit, used to determine the preset level corresponding to the target abnormal type as the fault level.

[0097] In response to the failure of an exception type to match multiple preset exception types, the fault diagnosis and classification module 304 further includes: a cause acquisition unit, used to acquire the fault cause corresponding to the exception type; and a fault evaluation unit, used to evaluate the fault cause and obtain the fault level corresponding to the exception type.

[0098] The vehicle control module 306 includes: a power control unit for controlling the disconnection of the power supply to the autonomous vehicle; a first brake control unit for controlling the autonomous vehicle to perform emergency braking; a second brake control unit for controlling the autonomous vehicle to perform non-emergency braking; a first parking control unit for controlling the autonomous vehicle to pull over to the side of the road; a second parking control unit for controlling the autonomous vehicle to drive to the target parking point and stop; a third parking control unit for controlling the autonomous vehicle to drive to the second parking point and stop after completing the current scheduling task; a speed control unit for controlling the speed of the autonomous vehicle to be less than a preset value; a vehicle status control unit for controlling the autonomous vehicle to remain stationary; and an information output unit for controlling the autonomous vehicle to output alarm information, wherein the alarm information is used to indicate that the autonomous vehicle has malfunctioned.

[0099] The first braking control unit includes: a first acquisition subunit, used to acquire first driving information of the autonomous vehicle, wherein the first driving information includes: chassis status information, vehicle positioning information, information of a first obstacle located in front of the autonomous vehicle, and navigation route information; a first generation subunit, used to generate the vehicle driving trajectory of the autonomous vehicle at a future time based on the first driving information and the historical planned trajectory of the autonomous vehicle; a mode determination subunit, used to determine the emergency braking mode of the autonomous vehicle based on the first obstacle information and the vehicle driving trajectory, wherein different emergency braking modes are used to brake the autonomous vehicle using different braking methods; and a first control subunit, used to control the autonomous vehicle to brake based on the emergency braking mode.

[0100] The mode determination subunit can be implemented through the following steps: minimizing the vehicle's driving trajectory and maximizing the deceleration of the autonomous vehicle to obtain the first emergency braking trajectory of the autonomous vehicle; obtaining the sum of the displacement of the first emergency braking trajectory and the stopping safety distance of the autonomous vehicle to obtain a preset distance; in response to the obstacle distance in the first obstacle information being greater than the preset distance, determining the emergency braking mode as the first braking mode, wherein the first braking mode is used to control the autonomous vehicle to brake according to the vehicle's driving trajectory; in response to the obstacle distance being less than or equal to the preset distance, determining the emergency braking mode as the second braking mode, wherein the second braking mode is used to control the brake pedal of the autonomous vehicle to brake at multiple different opening degrees.

[0101] The second braking control unit includes: a second acquisition subunit for acquiring first driving information of the autonomous vehicle, wherein the driving information includes: chassis status information, vehicle positioning information, information of a first obstacle located in front of the autonomous vehicle, and navigation route information; a second generation subunit for generating the vehicle's driving trajectory at a future time based on the first driving information and the autonomous vehicle's historical planned trajectory; a first trajectory acquisition subunit for maximizing the vehicle's driving trajectory and minimizing the deceleration of the autonomous vehicle to obtain a second emergency braking trajectory of the autonomous vehicle; and a second control subunit for controlling the autonomous vehicle to brake based on the second emergency braking trajectory.

[0102] The first parking control unit includes: a fourth acquisition subunit for acquiring second driving information of the autonomous vehicle, wherein the second driving information includes lateral displacement, velocity, and acceleration; a second trajectory acquisition subunit for fitting the trajectory of the autonomous vehicle based on the second driving information to obtain the motion trajectory of the autonomous vehicle; a perception information acquisition subunit for acquiring perception information of the autonomous vehicle, wherein the perception information includes second obstacle information in the lateral direction and lane line information around the autonomous vehicle; and a third control subunit for controlling the autonomous vehicle to pull over to the side of the road based on the perception information and the motion trajectory.

[0103] The above-mentioned device further includes: a level determination module, used to determine a target fault level in the fault levels, wherein the target fault level is higher than other fault levels in the fault levels; and a scheme acquisition module, used to acquire the control scheme corresponding to the target fault level and obtain a preset control scheme.

[0104] Example 3

[0105] According to another aspect of the present invention, a computer-readable storage medium is also provided, the computer-readable storage medium including a stored program, wherein, when the program is executed, it controls the device where the computer-readable storage medium is located to execute the above-described control method for an autonomous vehicle.

[0106] Example 4

[0107] According to another aspect of the present invention, a processor is also provided, which is used to run a program, wherein the program executes the above-described control method for an autonomous vehicle when it runs.

[0108] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0109] In the above embodiments of the present invention, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0110] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For instance, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.

[0111] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0112] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0113] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.

[0114] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. A control method for an autonomous vehicle, characterized in that, include: Obtain abnormal state information of the autonomous vehicle, wherein the abnormal state information includes: first state information indicating that the domain controller in the autonomous vehicle is abnormal, and second state information indicating that the communication state of the autonomous vehicle is abnormal. Based on the abnormal state information, the abnormal type of the autonomous vehicle is determined, wherein the abnormal type includes: a first abnormal type of the domain controller and a second abnormal type of the data transmission bus; Determine the fault level corresponding to the anomaly type, wherein the fault level is used to characterize the degree of impact of the anomaly type on the normal operation of the autonomous vehicle, and the fault level is determined by comparing the anomaly type with preset anomaly types using keywords, and / or by evaluating the fault cause of the anomaly type. Based on the preset control scheme corresponding to the fault level, the autonomous vehicle is controlled to operate; The method further includes: when the preset control scheme corresponding to the fault level is to control the autonomous vehicle to perform emergency braking, acquiring first driving information of the autonomous vehicle, wherein the first driving information includes: chassis status information, vehicle positioning information, information of a first obstacle located in front of the autonomous vehicle, and navigation route information; generating a vehicle driving trajectory of the autonomous vehicle at a future time based on the first driving information and the historical planned trajectory of the autonomous vehicle, wherein the historical planned trajectory is the historical braking planned trajectory of the autonomous vehicle; minimizing the vehicle driving trajectory and maximizing the deceleration of the autonomous vehicle to obtain a first emergency braking trajectory of the autonomous vehicle; obtaining the sum of the displacement of the first emergency braking trajectory and the stopping safety distance of the autonomous vehicle to obtain a preset distance; in response to the obstacle distance in the first obstacle information being greater than the preset distance, determining the emergency braking mode as a first braking mode, wherein the first braking mode is used to control the autonomous vehicle to brake according to the vehicle driving trajectory; in response to the obstacle distance being less than or equal to the preset distance, determining the emergency braking mode as a second braking mode, wherein the second braking mode is used to control the brake pedal of the autonomous vehicle to brake at multiple different opening degrees.

2. The method according to claim 1, characterized in that, Obtaining abnormal state information of the autonomous vehicle includes: In response to an anomaly in the domain controller, the system obtains the current status information sent by the domain controller and the fault information of the electronic devices corresponding to the domain controller to obtain the first status information. Obtain the data transmission status information of the data transmission bus to obtain the second status information.

3. The method according to claim 1, characterized in that, Determining the fault level corresponding to the anomaly type includes: The anomaly type is matched with multiple preset anomaly types to obtain the target anomaly type that successfully matches the anomaly type. The preset level corresponding to the target anomaly type is determined as the fault level.

4. The method according to claim 3, characterized in that, In response to the failure of the exception type to match multiple preset exception types, the method further includes: Obtain the cause of the fault corresponding to the aforementioned exception type; The cause of the fault is evaluated to obtain the fault level corresponding to the abnormality type.

5. The method according to claim 1, characterized in that, The method further includes: Determine a target fault level among the fault levels, wherein the target fault level is higher than the other fault levels among the fault levels; Obtain the control scheme corresponding to the target fault level to obtain the preset control scheme.

6. The method according to claim 1, characterized in that, Based on the preset control scheme corresponding to the fault level, the autonomous vehicle is controlled to operate, including one of the following: Disconnect the power supply to the autonomous vehicle; Control the autonomous vehicle to perform emergency braking; Control the autonomous vehicle to perform non-emergency braking; Control the autonomous vehicle to pull over to the side of the road; Control the autonomous vehicle to drive to the target parking point and stop; After the autonomous vehicle completes the current scheduling task, it will drive to the second stop and park. The speed of the autonomous vehicle is controlled to be less than a preset value; Control the autonomous vehicle to remain stationary; The autonomous vehicle is controlled to output alarm information, wherein the alarm information is used to indicate that the autonomous vehicle has encountered an anomaly.

7. The method according to claim 6, characterized in that, Controlling the autonomous vehicle to perform non-emergency braking includes: The first driving information of the autonomous vehicle is obtained, wherein the driving information includes: chassis status information, vehicle positioning information, information of the first obstacle located in front of the autonomous vehicle, and navigation route information; Based on the first driving information and the historical planned trajectory of the autonomous vehicle, the vehicle driving trajectory of the autonomous vehicle at future moments is generated; The second emergency braking trajectory of the autonomous vehicle is obtained by maximizing the vehicle's driving trajectory and minimizing the deceleration of the autonomous vehicle. Based on the second emergency braking trajectory, the autonomous vehicle is controlled to brake.

8. The method according to claim 6, characterized in that, Controlling the autonomous vehicle to pull over includes: The second driving information of the autonomous vehicle is obtained, wherein the second driving information includes: lateral displacement, velocity and acceleration; Based on the second driving information, the trajectory of the autonomous vehicle is fitted to obtain the motion trajectory of the autonomous vehicle. The perception information of the autonomous vehicle is acquired, wherein the perception information includes: information on a second obstacle in the lateral direction, and lane line information around the autonomous vehicle; Based on the perceived information and the motion trajectory, the autonomous vehicle is controlled to pull over to the side of the road.

9. A control system for an autonomous vehicle, characterized in that, include: A status data receiving module is used to acquire abnormal status information of the autonomous vehicle, wherein the abnormal status information includes: first status information indicating that the domain controller in the autonomous vehicle is abnormal, and second status information indicating that the communication status of the autonomous vehicle is abnormal. The fault diagnosis and classification module is used to determine the abnormal type of the autonomous vehicle based on the abnormal state information, and to determine the fault level corresponding to the abnormal type. The abnormal type includes a first abnormal type of the domain controller and a second abnormal type of the data transmission bus. The fault level is used to characterize the degree of impact of the abnormal type on the normal operation of the autonomous vehicle. The fault level is determined by comparing the abnormal type with preset abnormal types using keywords, and / or by evaluating the fault cause of the abnormal type. The vehicle control module is used to control the operation of the autonomous vehicle based on a preset control scheme corresponding to the fault level. The system is further configured to: acquire first driving information of the autonomous vehicle when the preset control scheme corresponding to the fault level is to control the autonomous vehicle to perform emergency braking; acquire first driving information of the autonomous vehicle, wherein the first driving information includes: chassis status information, vehicle positioning information, information of a first obstacle located in front of the autonomous vehicle, and navigation route information; generate a future driving trajectory of the autonomous vehicle based on the first driving information and the historical planned trajectory of the autonomous vehicle, wherein the historical planned trajectory is the historical braking planned trajectory of the autonomous vehicle; minimize the driving trajectory and maximize the deceleration of the autonomous vehicle to obtain a first emergency braking trajectory of the autonomous vehicle; acquire the sum of the displacement of the first emergency braking trajectory and the stopping safety distance of the autonomous vehicle to obtain a preset distance; determine the emergency braking mode as a first braking mode in response to the obstacle distance in the first obstacle information being greater than the preset distance, wherein the first braking mode is used to control the autonomous vehicle to brake according to the driving trajectory; and determine the emergency braking mode as a second braking mode in response to the obstacle distance being less than or equal to the preset distance, wherein the second braking mode is used to control the brake pedal of the autonomous vehicle to brake at multiple different opening degrees.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored program, wherein, when the program is executed, it controls the device on which the computer-readable storage medium is located to perform the method according to any one of claims 1 to 8.

11. A processor, characterized in that, The processor is used to run a program, wherein the program, when running, performs the method according to any one of claims 1 to 8.