A method and system for evaluating the residual risk of expected functional safety
Through the three-layer reception criteria and hazardous behavior probability analysis methods, the problem of evaluating the residual risk of expected functional safety of autonomous vehicles is solved, and the detailed risk assessment and operability of autonomous driving functions are achieved.
Patent Information
- Application Number
- CN202310340563.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-31
- Publication Date
- 2025-08-01
- Estimated Expiration
- 2043-03-31
AI Technical Summary
There is a lack of effective quantitative methods and guidelines in the prior art to assess the expected functional safety residual risks of autonomous vehicles, especially the risks of unknowns and uncertainties caused by system functional limitations, environmental factors and personnel misuse are not fully evaluated.
The evaluation method of three-layer reception criteria is adopted, including formulating test verification strategies, tests for known hazard scenarios, road tests or simulation tests, accident data analysis, combining ESC models and Poisson distribution to calculate the probability of hazard behavior, and establishing residual risk acceptance criteria by comparing human driver accident data.
The detailed risk assessment of the autonomous driving function is realized, the accuracy and operability of residual risk verification are improved, and the expected functional safety is at an acceptable level.
Smart Images

Figure CN116360404B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of the safety of the intended functionality of autonomous vehicles, and more particularly, to a method and system for evaluating the residual risk of the safety of the intended functionality. Background Art
[0002] The technology of autonomous driving is in the ascendant. Just meeting functional safety in the field of autonomous driving cannot fully meet the diverse and unknown requirements in actual scenarios. The safety of the intended functionality can ensure the safety of autonomous vehicles by using new methods and standard systems.
[0003] The safety of the intended functionality (SOTIF) is caused by unknown or uncertain non-system failures or human misoperations, and is characterized by unknownness and uncertainty. Its main risk sources include the limitations of system functions, environmental factors, and human misuse. The main reasons for the limitations of system functions are that the definition of system functions does not fully meet the requirements of the relevant market for system functions; insufficient consideration of relevant scenarios in the process of system design, resulting in inaccurate identification of environmental elements by the system; unreasonable design of the decision-making logic of the system, resulting in problems in system decision-making during operation; insufficient response of the actuator to system decisions, resulting in the vehicle's response not meeting the expected requirements. Environmental factors: Road conditions, things around the vehicle, and weather conditions will all affect autonomous driving. For example, special weather may affect the reliability of sensor data.
[0004] For the use of new autonomous driving technologies, an evaluation criterion needs to be established to show that the residual risk of autonomous driving functions is low enough and acceptable. Currently, there is no consensus among various vehicle manufacturers in the industry on the acceptance criteria for the residual risk of autonomous driving functions, and each vehicle manufacturer is unable to propose effective quantitative principles.
[0005] In the prior art, a quantitative evaluation method for the safety of the intended functionality of an autonomous vehicle control system is proposed, but no final risk acceptance criterion is formed. Another prior art proposes a Bayesian network analysis method for the safety of the intended functionality for system design, which gives a specific Bayesian network analysis method but does not evaluate the residual risk. Summary of the Invention
[0006] The present invention provides a method and system for evaluating the residual risk of the safety of the intended functionality, which improves the accuracy of the verification and confirmation criteria for the residual risk and has stronger operability.
[0007] To solve the above technical problems, the technical solution of the present invention is as follows:
[0008] A method for evaluating the residual risk of the safety of the intended functionality includes the following steps:
[0009] Formulate the three - layer acceptance criteria;
[0010] Formulate the test verification strategy;
[0011] Conduct tests for known hazard scenarios. When the verification of known hazard scenarios fails, conduct function improvement and optimization, and retest; when the verification of known hazard scenarios is completed and rectification passes, pass the first - layer acceptance criteria;
[0012] Conduct large - scale road tests or simulation tests, count accident data and unknown hazard scenarios in road tests or simulation tests, record the unknown hazard scenarios and return for function improvement and optimization until verification passes;
[0013] Analyze and evaluate whether the second - layer and third - layer acceptance criteria are met based on accident data analysis. If they are met, it means that the residual risk of expected functional safety is acceptable; if not, conduct function optimization and improvement, evaluate the additional test mileage required based on the accident or hazard behavior occurrence ratio combined with the current verification mileage, and after confirmation, return for large - scale road tests or simulation tests.
[0014] Preferably, the analysis and evaluation of whether the second - layer acceptance criteria are met based on accident data analysis are specifically as follows:
[0015] Obtain the safety goals of autonomous driving through hazard analysis, thus obtaining the vehicle - level hazard behaviors that violate the safety goals. Obtain the conditional probability of the occurrence of vehicle - level hazard behaviors according to the ESC model, calculate the acceptance criteria corresponding to the vehicle - level hazard behaviors. When the test results of vehicle - level hazard behaviors meet the acceptance criteria of vehicle - level hazard behaviors, pass the second - layer acceptance criteria.
[0016] Preferably, the vehicle - level hazard behaviors that violate the safety goals include:
[0017] Loss of vehicle lateral control, unexpected vehicle lateral control, excessive vehicle lateral control, insufficient vehicle lateral control, loss of vehicle acceleration control, unexpected vehicle acceleration control, excessive vehicle acceleration control, insufficient vehicle acceleration control, loss of vehicle deceleration control, unexpected vehicle deceleration, excessive vehicle deceleration control, insufficient vehicle deceleration control.
[0018] Preferably, in the ESC model, E represents exposure, S represents severity, and C represents controllability, specifically:
[0019] For each hazard event, estimate the exposure probability of each operating scenario based on the determined reasons, and assign a probability level of E0, E1, E2, E3, or E4 to the exposure probability. Among the levels from E1 to E4, the probability difference between two adjacent E levels is an order of magnitude. The classification of E is described and graded as follows: E0 means impossible to occur; E1 means very low probability of occurrence; E2 means low probability of occurrence; E3 means medium probability of occurrence; E4 means high probability of occurrence;
[0020] For each hazard event, estimate the severity probability of potential harm based on the determined reasons, and assign a severity level of S0, S1, S2, or S3 to the severity probability. Among the levels from S1 to S3, the probability difference between two adjacent S levels is an order of magnitude. The classification of S is described and graded as follows: S0 means no harm; S1 means mild and moderate harm; S2 means severe and life-threatening harm but with a possibility of survival; S3 means life-threatening harm and fatal harm with uncertain survival;
[0021] For each hazard event, estimate the controllability probability of the hazard event for the driver or other persons in the operating scenario based on a determined reason, and assign a controllability level of C0, C1, C2, or C3 to the controllability probability. Among the levels from C1 to C3, the probability difference between two adjacent C levels is an order of magnitude. The classification of C is described and graded as follows: C0 means controllable; C1 means simply controllable; C2 means generally controllable; C3 means difficult to control or uncontrollable.
[0022] Preferably, the conditional probability of the occurrence of the vehicle hazard behavior obtained according to the ESC model is used to calculate the acceptance criterion corresponding to the vehicle hazard behavior, specifically:
[0023] According to the relevant parameters involved in the hazard scenario, establish an exposure model P EA , and establish a controllability model M AC , and obtain the conditional probability P AC that M is controllable through simulation and sampling surveys of drivers CA , and obtain the probability P CA of an accident occurring under the conditional probability P SC ;
[0024] Obtain the traffic accident incidence rate A h of human drivers corresponding to the hazard behavior in the hazard scenario through statistical data
[0025] Calculate the tolerable ratio R A of the hazard behavior
[0026] Use the Poisson distribution to describe the number of hazard behavior times caused by the autonomous driving function in the real scenario, and obtain the verification target of the hazard behavior, that is, the acceptance criterion corresponding to the hazard behavior.
[0027] Preferably, the M is obtained through simulation and sampling survey of drivers AC is the controllable conditional probability P CA , specifically:
[0028] Under the scenario of a set of determined relevant parameters, let M drivers of different ages and genders conduct tests, where the age group conforms to the normal distribution; obtained according to the control passing rate of the drivers in this scenario, if N people pass successfully, then the controllable conditional probability P in this scenario CA = N / M.
[0029] Preferably, calculate the tolerated ratio R of the hazard behavior A , specifically:
[0030]
[0031] Preferably, the use of the Poisson distribution to describe the number of hazard behavior times caused by the autonomous driving function in the real scenario and obtain the verification target of the hazard behavior is specifically:
[0032] The probability function of the Poisson distribution is:
[0033]
[0034] In the formula, P(X=k) represents the probability that the hazard behavior event occurs k times, λ is the average number of occurrences of the hazard behavior event per unit mileage or unit time; k is the number of occurrences of the hazard behavior event;
[0035] The obtained verification target of the hazard behavior is:
[0036] τ A = -ln(1-α) / R A
[0037] In the formula, α is the confidence level.
[0038] Preferably, the evaluation of whether the third-layer acceptance criterion is met according to the accident data analysis is specifically:
[0039] Compare the accident statistics of human drivers in the same ODD scenario of the intelligent driving function. When the ratio of accidents of the intelligent driving function is not higher than the ratio of accidents of human drivers in the same ODD scenario of the intelligent driving function, the third-layer acceptance criterion is passed.
[0040] The present invention also provides an expected functional safety residual risk assessment system, which applies the above-mentioned expected functional safety residual risk assessment method, including:
[0041] A criterion formulation module, which is used to formulate a three-layer acceptance criterion;
[0042] A verification strategy formulation module, which is used to formulate a test verification strategy;
[0043] A scenario test module, which is used to conduct known hazard scenario tests. When the known hazard scenario verification fails, function improvement and optimization are carried out and the test is retaken; when the known hazard scenario verification is completed and rectified successfully, it passes the first-layer acceptance criterion;
[0044] A road test or simulation test module, which is used to conduct large-scale road tests or simulation tests, count accident data and unknown hazard scenarios in the road test or simulation test, record the unknown hazard scenarios and return them to the scenario test module for function improvement and optimization until the verification passes;
[0045] An analysis and evaluation module, which is used to analyze and evaluate whether the second-layer and third-layer acceptance criteria are met based on the accident data. If they are met, it means that the expected functional safety residual risk is acceptable; if not, function optimization and improvement are carried out, and the additional test mileage to be added is evaluated according to the accident or hazard behavior occurrence ratio combined with the current verification mileage. After confirmation, it returns to conduct large-scale road tests or simulation tests.
[0046] Compared with the prior art, the beneficial effects of the technical solution of the present invention are:
[0047] By analyzing the intelligent driving function and ODD, and combining with the SOTIF 21448 standard, the present invention finally obtains a quantifiable three-layer residual risk acceptance criterion. The first-layer criterion is based on the SOTIF standard, that is, all known hazard scenarios should be tested and pass the test after optimization and improvement. The second-layer criterion is derived from the corresponding acceptance criteria for different autonomous driving hazard behaviors. When the test results meet the acceptance criteria for the corresponding hazard behaviors, the second layer is considered to pass. The third-layer criterion is the overall acceptance criterion. By comparing the human driver accident statistics data in the same intelligent driving function ODD scenario, according to the GAMAB criterion, that is, the residual risk of any new system is not higher than that of the existing system with similar functions or hazards, the overall acceptance criterion for the intelligent driving function is obtained. If all three layers of criteria pass, it can be considered that the expected functional safety residual risk of the intelligent driving function is low enough. This method refines the residual risk acceptance criteria for different autonomous driving behaviors through the detailed classification of autonomous driving functions and ODD, improves the accuracy of the verification and confirmation criteria for residual risks, and has stronger operability. Description of the Drawings
[0048] Figure 1 This is a schematic diagram of the method flow of the present invention.
[0049] Figure 2 This is a schematic diagram of the corresponding scenario A of the hazard behavior provided by the embodiment.
[0050] Figure 3 This is a schematic diagram of the system module of the present invention. Detailed implementation manners
[0051] The attached drawings are only for illustrative purposes and should not be construed as a limitation to this patent;
[0052] To better illustrate this embodiment, some components in the attached drawings are omitted, enlarged or reduced, which do not represent the dimensions of the actual product;
[0053] For those skilled in the art, it is understandable that some well-known structures and their descriptions in the attached drawings may be omitted.
[0054] The technical solution of the present invention will be further described below in conjunction with the attached drawings and embodiments.
[0055] This embodiment provides a method for evaluating the residual risk of expected functional safety, as Figure 1 shown, including the following steps:
[0056] Formulate a three-layer acceptance criterion;
[0057] Formulate a test and verification strategy;
[0058] Conduct tests on known hazard scenarios. When the verification of the known hazard scenarios fails, conduct function improvement and optimization and retest; when the verification of the known hazard scenarios is completed and the rectification is passed, pass the first-layer acceptance criterion;
[0059] Conduct large-scale road tests or simulation tests, count the accident data and unknown hazard scenarios in the road tests or simulation tests, record the unknown hazard scenarios and return for function improvement and optimization until the verification is passed;
[0060] Analyze and evaluate based on the accident data whether the second-layer and third-layer acceptance criteria are met. If they are met, it means that the residual risk of the expected functional safety is acceptable; if not, conduct function optimization and improvement, evaluate the additional test mileage required based on the accident or hazard behavior occurrence ratio combined with the current verification mileage, and after confirmation, return for large-scale road tests or simulation tests.
[0061] The specific method for analyzing and evaluating based on the accident data whether the second-layer acceptance criterion is met is as follows:
[0062] The safety objectives of autonomous driving are obtained through hazard analysis, and then the vehicle hazards that violate the safety objectives are obtained. According to the ESC model, the conditional probability of the occurrence of vehicle hazards is obtained, and the acceptance criteria corresponding to the vehicle hazards are calculated. When the test results of the vehicle hazards meet the acceptance criteria of the vehicle hazards, the second-layer acceptance criteria are passed.
[0063] The vehicle hazards that violate the safety objectives include:
[0064] Loss of vehicle lateral control, unexpected vehicle lateral control, excessive vehicle lateral control, insufficient vehicle lateral control, loss of vehicle acceleration control, unexpected vehicle acceleration control, excessive vehicle acceleration control, insufficient vehicle acceleration control, loss of vehicle deceleration control, unexpected vehicle deceleration, excessive vehicle deceleration control, insufficient vehicle deceleration control.
[0065] The occurrence of an unsafe control behavior does not necessarily mean the occurrence of a hazard. Therefore, it is necessary to obtain the probability P of the occurrence of the above unsafe behaviors and causing personal injuries within the ODD of intelligent driving through statistics or simulation.
[0066] In the ESC model, the calculation of the probability P can be considered from three aspects: E (exposure), S (severity), and C (controllability). According to the requirements of the national functional safety standard "GB T 34590.3-2022 Road Vehicles - Functional Safety - Part 3: Concept Phase": For each hazard event, estimate the exposure probability of each operating scenario based on certain reasons, and assign a probability level of E0, E1, E2, E3, or E4 to the exposure probability. Among the levels from E1 to E4, the probability difference between two adjacent E levels is an order of magnitude. The classification of E is described and graded as follows: E0 means impossible to occur; E1 means very low probability of occurrence; E2 means low probability of occurrence; E3 means medium probability of occurrence; E4 means high probability of occurrence;
[0067] For each hazard event, estimate the severity probability of potential injuries based on certain reasons, and assign a severity level of S0, S1, S2, or S3 to the severity probability. Among the levels from S1 to S3, the probability difference between two adjacent S levels is an order of magnitude. The classification of S is described and graded as follows: S0 means no injury; S1 means mild and moderate injuries; S2 means severe and life-threatening injuries but with a possibility of survival; S3 means life-threatening injuries and fatal injuries with uncertain survival;
[0068] For each hazard event, estimate the controllable probability of the driver or other personnel in the operating scenario for the hazard event based on a definite reason, and assign a controllability level of C0, C1, C2, or C3 to the controllable probability. Among the levels from C1 to C3, the probability difference between two adjacent C levels is an order of magnitude. The classification of C is described and graded as follows: C0 means controllable; C1 means simply controllable; C2 means generally controllable; C3 means difficult to control or uncontrollable.
[0069] In this embodiment, it is preliminarily determined that the probabilities corresponding to the E, S, and C levels are defined as follows: P E1 = 0.001, P E2= 0.01, P E3 = 0.1, P E4 = 1; P S1 = 0.01, P S2 = 0.1, P S3 = 1; P C1 = 0.01, P C2 = 0.1, P C3 = 1; The following takes an example of an expected functional safety hazard scenario: When driving in L2-level assisted driving in the urban area and passing through an intersection, a pedestrian passes through the zebra crossing. Due to missed target recognition, there is a missed braking and collision with the pedestrian, causing injury. The description of the exposure degree of the scenario: Driving on urban roads, passing through an intersection, and the scenario of a pedestrian passing through the zebra crossing occurs every day, which is a high-probability scenario. Therefore, the exposure degree is E4, then P E4 = 1; The description of the hazard degree: According to the speed limit, the L2 driving assistance function will pass through the zebra crossing at a speed of 30 km / h. When colliding with a pedestrian, it will cause life-threatening injuries to the pedestrian. Therefore, the hazard degree is S3, then P S3 = 1, meaning that each collision will cause injuries at the S3 level; The description of controllability: The L2-level driving assistance function requires the driver to be in the loop. For this scenario, it is generally controllable by the driver. Therefore, the controllability is C2, then P C2 = 0.1, meaning that 90% of the drivers can control it. The relevant probabilities can be adjusted according to the specific trigger conditions of the expected functional safety. For example, if it is found through SOTIF analysis that the camera has a defect in missing the recognition of pedestrians wearing white clothes, then the trigger condition is that a pedestrian wearing white clothes passes through the zebra crossing. The exposure degree of the scenario of a pedestrian passing through the zebra crossing is E4, but the exposure degree of the scenario of a pedestrian wearing white clothes passing through the zebra crossing is E3.
[0070] The conditional probability of the occurrence of the vehicle's hazard behavior obtained according to the ESC model is used to calculate the acceptance criterion corresponding to the vehicle's hazard behavior, specifically:
[0071] According to the relevant parameters involved in the hazard scenario, establish an exposure degree model P through traffic big data analysis EA, and establish a controllability model M AC , and obtain M through simulation and sampling surveys of drivers AC The conditional probability P for being controllable CA , and obtain the probability P of an accident occurring under the conditional probability P CA ; SC ;
[0072] Obtain the traffic accident incidence rate A of human drivers' corresponding hazardous behaviors in a hazardous scenario through statistical data h ;
[0073] Calculate the tolerated ratio R of hazardous behaviors A ;
[0074] Use the Poisson distribution to describe the number of hazardous behavior times caused by the autonomous driving function in the real scenario, and obtain the verification target of the hazardous behavior, that is, the acceptance criterion corresponding to the hazardous behavior
[0075] The M obtained through simulation and sampling surveys of drivers AC The conditional probability P for being controllable CA , specifically:
[0076] In a scenario with a set of determined relevant parameters, let M drivers of different ages and genders be tested, where the age group conforms to a normal distribution; obtained according to the control passing rate of the drivers in this scenario, let N people pass successfully, then the conditional probability P for being controllable in this scenario CA = N / M
[0077] Calculate the tolerated ratio R of hazardous behaviors A , specifically:
[0078]
[0079] The Poisson distribution is suitable for describing the number of random events occurring per unit time (or space). According to the ISO 21448 standard, the number of hazardous behavior events caused by the autonomous driving function in the real scenario can also be described by the Poisson distribution law. The use of the Poisson distribution to describe the number of hazardous behavior times caused by the autonomous driving function in the real scenario and obtain the verification target of the hazardous behavior is specifically:
[0080] The probability function of the Poisson distribution is:
[0081]
[0082] In the formula, P(X = k) represents the probability that the hazardous behavior event occurs k times, λ is the average number of occurrences of the hazardous behavior event per unit mileage or unit time; k is the number of occurrences of the hazardous behavior event
[0083] The verification objective of the harmful behavior is as follows:
[0084] τ A =-ln(1-α) / R A
[0085] In the formula, α is the confidence level.
[0086] A typical scenario A that can be used to calculate the probability can be described as follows: The vehicle is driving on a highway using the ADAS function, following the vehicle in front at high speed. When the vehicle in front decelerates, the vehicle unexpectedly accelerates due to a related item failure, resulting in a rear-end collision with the vehicle in front on the highway, as Figure 2 shown.
[0087] Based on parameters such as the following distance, deceleration of the vehicle in front, unexpected acceleration, and relative speed between the two vehicles, a model is established to further obtain the probability distribution. As Figure 2 shown: Vehicle No. 1 is the own vehicle, with a vehicle speed of V1 and an acceleration of a1; Vehicle No. 2 has a vehicle speed of V2 and an acceleration of a2; the distance between the two vehicles is d. Through big data analysis of traffic scenarios, an exposure P EA related to (V1, V2, a1, a2, d) is established, and a controllability model M AC is established. Further, through simulation and sampling surveys of drivers, the conditional probability P AC that M CA is controllable is obtained. Specifically, in a set of scenarios with a determined (V1, V2, a1, a2, d), for example, let 100 drivers of different ages (following a normal distribution) and genders conduct tests. According to the control passing rate of the drivers in this scenario, if only 5 out of 100 people succeed in passing, the probability P CA that this scenario is controllable is 0.05. Further, according to the magnitude of the relative speed of the collision (calculated from V1, V2, a1, a2, d), the probability P CA of an accident occurring under the conditional probability is obtained. SC
[0088] The traffic accident incidence rate A of human drivers rear-ending the vehicle in front on the highway in scenario A is obtained through statistical data. h For the calculation of A h , it can be calculated according to statistical data: For example, in the region of the product target market, the total driving mileage of local human drivers on the highway per year is M A , among which the number of rear-end collision accidents on the highway is H A . Further, (times / km);
[0089] The tolerated ratio of rear-ending the vehicle in front on the highway is the average number of occurrences of harmful behavior events per unit mileage (or unit time);
[0090] The verification target for rear-ending the vehicle in front at high speed is τ A =-ln(1-α) / R A , where α is the confidence level. That is to say, if there is no rear-ending of the vehicle in front within τ A mileage, it proves that the expected functional safety problem causing this hazard behavior passes the second-layer acceptance criterion.
[0091] Similarly, for other hazard behaviors such as side collisions and running off the ramp, as well as the corresponding expected functional safety problems, this method can also be used for calculation. That is, different P values can be obtained according to the relevant parameters involved in the hazard scenario (such as speed, acceleration, steering wheel angle, distance from the lane line and guardrail, etc.). E 、P S 、P C probabilities, and then the acceptance criteria for different hazard behaviors can be calculated according to the formula in the above steps. If all hazard behaviors pass the second-layer acceptance criterion, it proves that the overall passes the second-layer acceptance criterion.
[0092] The evaluation of whether the third-layer acceptance criterion is met based on accident data analysis is as follows:
[0093] By comparing the accident statistics of human drivers in the same ODD scenario of the intelligent driving function, when the accident rate of the intelligent driving function is not higher than the accident rate of human drivers in the same ODD scenario of the intelligent driving function, it passes the third-layer acceptance criterion.
[0094] The third-layer acceptance criterion is the overall acceptance criterion based on the ODD, that is, the accident rate of the intelligent driving function is not higher than the accident rate of human drivers within the ODD range corresponding to the intelligent driving function.
[0095] First, find the accident data of human drivers within the corresponding ODD range according to the ODD range of different intelligent driving functions. Further, by analogy with the accident rate of human drivers, the allowable accident rate of intelligent driving is obtained. The following example is provided in this embodiment:
[0096] The accident rates of human drivers in urban driving and highway driving are different. Correspondingly, the verification targets and acceptance criteria for intelligent driving functions in urban areas and highway intelligent driving functions are also different. Taking the high-speed cruise assist driving function with a limited vehicle speed as an example: Define the driving ODD H as follows: 1. The vehicle speed range is 0-60 km / h; 2. There are no pedestrians or bicycles on the road; 3. The road is a highway or expressway, and there is a separation guardrail or green belt between the oncoming lanes of the road.
[0097] Obtain the accident statistics of human drivers corresponding to the above intelligent driving scenarios: A h-hw : The accident incidence rate (times / km) of human drivers in driving scenario H.
[0098] M hw <60: The total mileage of vehicles driving at a speed lower than 60 km / h on highways / expressways in the target market in the previous year.
[0099] H hw <60: The total number of traffic accidents of vehicles driving at a speed lower than 60 km / h on highways / expressways in the target market in the previous year.
[0100] Then A can be calculated h-hw :
[0101]
[0102] The verification target corresponding to ODD H is obtained as τ h-hw = -ln(1 - α) / A h-hw In the formula, α is the confidence level. That is to say, if no accident occurs within τ h-hw mileage, it proves that the third - layer acceptance criterion is passed.
[0103] If all the above three - layer acceptance criteria are passed, it means that the residual risk of expected functional safety is low enough to be accepted.
[0104] Another embodiment provides an expected functional safety residual risk assessment system, as Figure 3 shown. The assessment system applies the above - mentioned expected functional safety residual risk assessment method, including:
[0105] A criterion - setting module, which is used to set three - layer acceptance criteria;
[0106] A verification - strategy - setting module, which is used to set test verification strategies;
[0107] A scenario - testing module, which is used to conduct known - hazard scenario tests. When the known - hazard scenario verification fails, function improvement and optimization are carried out, and the test is retested; when the known - hazard scenario verification is completed and the rectification is passed, the first - layer acceptance criterion is passed;
[0108] A road - test or simulation - test module, which is used to conduct large - scale road tests or simulation tests, count accident data and unknown - hazard scenarios in the road tests or simulation tests, record the unknown - hazard scenarios and return them to the scenario - testing module for function improvement and optimization until the verification is passed;
[0109] An analysis and evaluation module is configured to analyze and evaluate whether the second-level acceptance criterion and the third-level acceptance criterion are met based on accident data. If they are met, it indicates that the residual risk of expected functional safety is acceptable; if not, functional optimization and improvement are carried out. The additional test mileage required is evaluated based on the accident or hazard behavior occurrence ratio in combination with the current verification mileage. After confirmation, it returns to conduct large-scale road tests or simulation tests.
[0110] The same or similar reference numerals correspond to the same or similar components;
[0111] The terms describing the positional relationship in the drawings are for illustrative purposes only and should not be construed as a limitation of this patent;
[0112] Obviously, the above embodiments of the present invention are merely examples for clearly illustrating the present invention and are not intended to limit the implementation manners of the present invention. For those of ordinary skill in the art, other different forms of changes or modifications can be made based on the above description. It is not necessary and impossible to enumerate all the implementation manners here. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the present invention shall be included in the protection scope of the claims of the present invention.
Claims
1. A method for evaluating the residual risk of expected functional safety, characterized in that, It includes the following steps: Formulate three - layer acceptance criteria; Formulate test verification strategies; Conduct known - hazard scenario tests. When the known - hazard scenario verification fails, conduct function improvement and optimization, and retest; When the known - hazard scenario verification is completed and rectification passes, pass the first - layer acceptance criteria; Conduct large - scale road tests or simulation tests, count accident data and unknown - hazard scenarios in the road tests or simulation tests, record the unknown - hazard scenarios and return for function improvement and optimization until the verification passes; Analyze and evaluate based on accident data whether the second - layer and third - layer acceptance criteria are met. If they are met, it means the residual risk of the expected functional safety is acceptable; if not, conduct function optimization and improvement, evaluate the additional test mileage required based on the accident or hazard behavior occurrence ratio combined with the current verification mileage, and after confirmation, return for large - scale road tests or simulation tests; The analysis and evaluation based on accident data to determine whether the second - layer acceptance criteria are met is specifically as follows: Obtain the safety goals of autonomous driving through hazard analysis, thus obtaining the vehicle - level hazard behaviors that violate the safety goals. Obtain the conditional probability of the vehicle - level hazard behaviors occurring according to the ESC model, calculate the acceptance criteria corresponding to the vehicle - level hazard behaviors. When the test results of the vehicle - level hazard behaviors meet the acceptance criteria of the vehicle - level hazard behaviors, pass the second - layer acceptance criteria; The obtaining of the conditional probability of the vehicle - level hazard behaviors occurring according to the ESC model and the calculation of the acceptance criteria corresponding to the vehicle - level hazard behaviors are specifically as follows: Based on the relevant parameters involved in the hazard scenario, an exposure model P is established through traffic big data analysis EA , and a controllability model M is established AC . The conditional probability P that M is controllable is obtained through simulation and sampling surveys of drivers AC , and the probability P of an accident occurring under the conditional probability P is obtained CA ; CA SC ; Obtain the traffic accident incidence rate A of corresponding hazard behaviors of human drivers in hazard scenarios through statistical data h ; Calculate the tolerated ratio R of the harmful act A ; Use the Poisson distribution to describe the number of hazard behavior times caused by the autonomous driving function in the real scenario, and obtain the verification goal of the hazard behavior, which is the acceptance criteria corresponding to the hazard behavior; The analysis and evaluation based on accident data to determine whether the third - layer acceptance criteria are met is specifically as follows: Compare the accident statistics of human drivers in the same ODD scenario of the intelligent driving function. When the accident ratio of the intelligent driving function is not higher than that of human drivers in the same ODD scenario of the intelligent driving function, pass the third - layer acceptance criteria.
2. The expected functional safety residual risk assessment method according to claim 1, wherein, The vehicle - level hazard behaviors that violate the safety goals include: Loss of vehicle lateral control, unexpected vehicle lateral control, excessive vehicle lateral control, insufficient vehicle lateral control, loss of vehicle acceleration control, unexpected vehicle acceleration control, excessive vehicle acceleration control, insufficient vehicle acceleration control, loss of vehicle deceleration control, unexpected vehicle deceleration, excessive vehicle deceleration control, insufficient vehicle deceleration control.
3. The expected functional safety residual risk assessment method according to claim 2, wherein In the ESC model, E represents exposure, S represents severity, and C represents controllability. Specifically: For each hazard event, estimate the exposure probability of each operating scenario based on the determined reasons, and assign a probability level of E0, E1, E2, E3, or E4 to the exposure probability. Among the levels from E1 to E4, the probability difference between two adjacent E levels is one order of magnitude. The classification of E is described and graded as follows: E0 means impossible to occur; E1 means very low probability of occurrence; E2 means low probability of occurrence; E3 means medium probability of occurrence; E4 means high probability of occurrence; For each hazard event, estimate the severe probability of potential harm based on the determined reasons, and assign a severity level of S0, S1, S2, or S3 to the severe probability. Among the levels from S1 to S3, the probability difference between two adjacent S levels is an order of magnitude. The classification of S is described and graded as follows: S0 represents no harm; S1 represents mild and moderate harm; S2 represents severe and life-threatening harm, but there is a possibility of survival; S3 represents life-threatening harm and fatal harm with uncertain survival. For each hazard event, estimate the controllable probability of the driver or other persons in the operating scenario for the hazard event based on a determined reason, and assign a controllability level of C0, C1, C2, or C3 to the controllable probability. Among the levels from C1 to C3, the probability difference between two adjacent C levels is an order of magnitude. The classification of C is described and graded as follows: C0 represents controllable; C1 represents simply controllable; C2 represents generally controllable; C3 represents difficult to control or uncontrollable.
4. The expected functional safety residual risk assessment method according to claim 3, wherein The M obtained through simulation and sampling surveys of drivers AC is the controllable conditional probability P CA , specifically: Under the scenario of a set of determined relevant parameters, let M drivers of different ages and genders be tested, where the age range conforms to a normal distribution; obtained according to the control passing rate of the drivers in this scenario, if N people pass successfully, then the conditional probability P that can be controlled in this scenario CA = N / M.
5. The expected functional safety residual risk assessment method according to claim 3, characterized in that Calculate the tolerated ratio R of the harmful act A , specifically as follows:
6. The expected functional safety residual risk assessment method according to claim 3, characterized in that Describing the number of hazard behavior times caused by the autonomous driving function in the real scenario using the Poisson distribution, and obtaining the verification target of the hazard behavior, specifically: The probability function of the Poisson distribution is: In the formula, P(X = k) represents the probability that the hazard behavior event occurs k times, λ is the average number of occurrences of the hazard behavior event per unit mileage or unit time; k is the number of occurrences of the hazard behavior event; The obtained verification target of the hazard behavior is: τ A = -ln(1 - α) / R A In the formula, α is the confidence level.
7. A system for evaluating the residual risk of expected functional safety, characterized in that, The evaluation system applies the expected functional safety residual risk assessment method described in any one of claims 1 to 6, including: A criterion formulation module, which is used to formulate a three-layer acceptance criterion; A verification strategy formulation module, which is used to formulate a test verification strategy; A scenario test module, which is used to conduct known hazard scenario tests. When the known hazard scenario verification fails, conduct function improvement and optimization, and retest; when the known hazard scenario verification is completed and rectified and passed, pass the first-layer acceptance criterion; A road test or simulation test module, which is used to conduct large-scale road tests or simulation tests, count the accident data and unknown hazard scenarios in the road test or simulation test, record the unknown hazard scenarios and return them to the scenario test module for function improvement and optimization until the verification is passed; An analysis and evaluation module, which is used to analyze and evaluate whether the second-layer acceptance criterion and the third-layer acceptance criterion are met based on the accident data. If they are met, it means that the expected functional safety residual risk is acceptable; if not, conduct function optimization and improvement, evaluate the additional test mileage required based on the accident or hazard behavior occurrence ratio combined with the current verification mileage, and after confirmation, return to conduct large-scale road tests or simulation tests.
Citation Information
Patent Citations
Method for carrying out hazard assessment by risk analysis on road vehicle speediness
CN108510185A