Method and device for evaluating safety of adaptive cruise anticipatory function in cornering scenario
By constructing a safety test and evaluation method for the expected functions of adaptive cruise control in a curve scenario, and using simulation software and cost functions to conduct safety risk assessment, the problem of lack of quantitative evaluation in existing technologies is solved, thus ensuring the safety of autonomous vehicles.
Patent Information
- Application Number
- CN202411115785.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-14
- Publication Date
- 2025-11-21
- Estimated Expiration
- 2044-08-14
AI Technical Summary
Existing technologies lack quantitative evaluation standards for the expected functional safety of adaptive cruise control systems in curve scenarios, making it impossible to effectively identify and analyze potential risks, resulting in safety hazards for autonomous vehicles in complex traffic environments.
This paper provides a safety test and evaluation method for the expected function of adaptive cruise control in a curve scenario. By acquiring unsafe control behaviors, constructing causal scenarios, using simulation software to construct test scenarios, designing cost functions to score safety risks, and determining the safety evaluation results.
It enables quantitative safety risk assessment of adaptive cruise control systems in curve scenarios, identifies potential hazards, verifies and assesses unknown risks, and ensures the expected functional safety of autonomous vehicles.
Smart Images

Figure CN119126741B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of intended function safety testing, in particular to a self-adaptive cruise intended function safety testing evaluation method and device under a curve scenario. BACKGROUND
[0002] With the development of automatic driving technology from L2 to L3 and higher levels, the complexity and integration of vehicle functions have significantly improved. This requires the system not only to run stably under normal conditions, but also to have high adaptability and robustness in complex and variable traffic environments. Intended function safety is proposed to address new challenges that may arise during this technical leap. SOTIF (Safety of The Intended Functionality) mainly aims to solve vehicle hazard events caused by non-vehicle function failures, thereby focusing on avoiding potential safety accidents caused by design defects or performance limitations.
[0003] However, in the current academic research on intended function safety, most of the research focuses on qualitative research, analyzing the scenarios in which intended function safety problems may occur or the functions that cause intended function safety problems. There is a lack of quantitative analysis, i.e., pointing out quantitative evaluation standards in the statistical sense. The self-adaptive cruise system function module is an important part of ADAS (Advanced Driver Assistance System), and it has attracted the attention of many scholars because of its wide application prospects in actual production and life. The main function of ACC (Adaptive Cruise Control) can be defined as controlling the throttle opening and brake pressure of the ego vehicle based on maintaining a certain following distance and relative speed, thereby achieving automatic following.
[0004] Due to the inability of autonomous vehicles to ensure the realization of adaptive cruise control functions under the influence of complex traffic conditions and environments, the following situations may occur under a curve scenario: ACC function failure, leading to collisions of the controlled vehicle; the vehicle fails to change lanes on time, resulting in a collision; the vehicle fails to respond to lane change instructions, causing a rear-end collision; the ego vehicle's acceleration and deceleration exceeds the safety threshold (passenger comfort threshold, vehicle safety threshold), affecting passenger experience; unintended ACC caused by passenger error, resulting in a collision with the front vehicle. There are also some unpredictable emergencies that may pose risks to the intended function safety of autonomous vehicles. Accurate and reliable verification of the risk level of the cause scenario, as well as verification and evaluation of unknown risks and final confirmation of the intended function safety of autonomous vehicles, are currently the problems to be solved. SUMMARY
[0005] To solve the technical problem of how to identify, analyze and quantify the expected functional safety problems that adaptive cruise control system may face in curved driving, the embodiment of the present application provides a kind of adaptive cruise expected functional safety test evaluation method and device under curved road scene.The technical solution is as follows:
[0006] In one aspect, a kind of adaptive cruise expected functional safety test evaluation method under curved road scene is provided, the method is realized by expected functional safety test evaluation equipment, the method includes:
[0007] S1, the unsafe control behavior of automatic driving vehicle under curved road scene is acquired.
[0008] S2, according to unsafe control behavior, cause scene is constructed, and then expected functional safety demand is obtained.
[0009] S3, based on expected functional safety demand, simulation test scene of vehicle adaptive cruise is constructed in simulation software and is tested, and test result is obtained.
[0010] S4, according to test result, safety evaluation dimension index and the weight coefficient of safety evaluation dimension index are determined.
[0011] S5, design cost function, according to safety evaluation dimension index, the weight coefficient of safety evaluation dimension index and cost function, safety risk level score result is obtained.
[0012] S6, according to safety risk level score result, the expected functional safety test evaluation result of adaptive cruise under curved road scene is obtained.
[0013] Optionally, the unsafe control behavior of automatic driving vehicle under curved road scene in S1 is acquired, including:
[0014] S11, by the system theory process analysis of adaptive cruise ACC system, safety constraint and whole vehicle level hazard event are determined.
[0015] S12, according to safety constraint and whole vehicle level hazard event, whole vehicle level safety target is designed.
[0016] S13, according to whole vehicle level hazard event and whole vehicle level safety target, the unsafe control behavior of automatic driving vehicle under curved road scene is obtained.
[0017] Optionally, the whole vehicle level hazard event in S11 includes:
[0018] ACC function failure, controlled vehicle collision.
[0019] Lane change is not carried out in time, and vehicle collision occurs.
[0020] Not responding to lane change instruction, rear-end collision.
[0021] The acceleration or deceleration of the ego vehicle exceeds a safety threshold.
[0022] The passenger mis-touches, leading to unexpected ACC and collision with the front vehicle.
[0023] Optionally, in S2, the cause scene is constructed according to the unsafe control behavior, and then the expected functional safety requirement is obtained, including:
[0024] In S21, the trigger condition and performance limitation are constructed for each unsafe control behavior, and the cause scene is constructed according to the unsafe control behavior, the trigger condition and the performance limitation.
[0025] In S22, the expected functional safety requirement is obtained according to the cause scene and the vehicle-level safety target.
[0026] Optionally, in S3, the simulation test scene of the vehicle adaptive cruise is constructed in the simulation software and tested based on the expected functional safety requirement, and the test result is obtained, including:
[0027] In the simulation software, the vehicle dynamics model is created based on the expected functional safety requirement, the controller control decision algorithm is added, the vehicle driving lane environment is added, and the adaptive cruise simulation test experiment is performed on the simulated vehicle, and the test result is obtained.
[0028] Optionally, the calculation method of the safety risk level score result in S5 is shown in the following formula (1):
[0029] (1)
[0030] In the formula, represents the safety risk level score result of the ACC system in the current simulation test scene under the current evaluation standard, represents the number of cumulative hazard behaviors, represents the weighted weight value of a certain type of cumulative hazard behavior, represents the risk coefficient of a certain type of cumulative hazard behavior, represents the number of event hazard behaviors, represents the weighted weight value of a certain type of event hazard behavior, represents the risk coefficient of a certain type of event hazard behavior, represents the risk coefficient of a certain type of cumulative hazard behavior, represents the critical risk coefficient of a certain type of cumulative hazard behavior, represents the risk coefficient of a certain type of event hazard behavior, represents the critical risk coefficient of a certain type of event hazard behavior.
[0031] In another aspect, a device for evaluating the safety of adaptive cruise control in a curved road scenario is provided. The device is applied to a method for evaluating the safety of adaptive cruise control in a curved road scenario. The device comprises:
[0032] An obtaining module is configured to obtain unsafe control behaviors of an autonomous vehicle in a curved road scenario.
[0033] A constructing module is configured to construct a cause scenario based on the unsafe control behaviors, and further obtain expected functional safety requirements.
[0034] A testing module is configured to construct a simulation test scenario of vehicle adaptive cruise control in simulation software based on the expected functional safety requirements, and perform testing to obtain a test result.
[0035] A determining module is configured to determine safety evaluation dimension indicators and weight coefficients of the safety evaluation dimension indicators based on the test result.
[0036] A designing module is configured to design a cost function, and obtain a safety risk level score result based on the safety evaluation dimension indicators, the weight coefficients of the safety evaluation dimension indicators, and the cost function.
[0037] An outputting module is configured to obtain an evaluation result of the expected functional safety of adaptive cruise control in a curved road scenario based on the safety risk level score result.
[0038] Optionally, the obtaining module is further configured to:
[0039] S11, determine safety constraints and vehicle-level hazard events by analyzing the system theory process of an adaptive cruise control ACC system.
[0040] S12, design a vehicle-level safety target based on the safety constraints and the vehicle-level hazard events.
[0041] S13, obtain unsafe control behaviors of an autonomous vehicle in a curved road scenario based on the vehicle-level hazard events and the vehicle-level safety target.
[0042] Optionally, the vehicle-level hazard events include:
[0043] ACC function failure, collision of the controlled vehicle.
[0044] Failure to change lanes on time, collision of the vehicle.
[0045] Failure to respond to lane change instructions, rear-end collision.
[0046] Self-vehicle acceleration and deceleration exceeds a safety threshold.
[0047] Passenger accidental touch leading to unexpected ACC, collision with the front vehicle.
[0048] Optionally, the constructing module is further used for:
[0049] S21, constructing a triggering condition and a performance limitation for each unsafe control behavior, and constructing a causation scene according to the unsafe control behavior, the triggering condition and the performance limitation.
[0050] S22, obtaining an expected functional safety requirement according to the causation scene and a vehicle-level safety target.
[0051] Optionally, the testing module is further used for:
[0052] Based on the expected functional safety requirement, a vehicle dynamics model is created in simulation software, a controller control decision algorithm is added, a vehicle driving lane environment is added, and a self-adaptive cruise simulation test experiment is performed on a simulated vehicle to obtain a test result.
[0053] Optionally, a calculation method of the safety risk level score result is shown in the following formula (1):
[0054] (1)
[0055] In the formula, ACC represents an ACC system, score represents a safety risk level score result of the ACC system in a current simulation test scene under a current scoring standard, N represents a number of cumulative hazard behaviors, w represents a weighted weight value of a certain type of cumulative hazard behavior, r represents a risk coefficient of the certain type of cumulative hazard behavior, M represents a number of event hazard behaviors, m represents a weighted weight value of a certain type of event hazard behavior, s represents a risk coefficient of the certain type of event hazard behavior, a represents a dangerous coefficient of the cumulative hazard behavior, b represents a critical dangerous coefficient of the cumulative hazard behavior, c represents a dangerous coefficient of the event hazard behavior, and d represents a critical dangerous coefficient of the event hazard behavior.
[0056] On the other hand, an expected functional safety test evaluation device is provided, and the device includes a processor and a memory. The memory stores computer readable instructions which, when executed by the processor, implement any one of the above methods for adaptive cruise expected functional safety test evaluation under a curve scene.
[0057] In another aspect, a computer-readable storage medium is provided, the storage medium having stored therein at least one instruction, the at least one instruction being loaded and executed by a processor to implement any one of the above adaptive cruise prospective function safety test evaluation methods in a curve scenario.
[0058] The technical solution provided by the embodiment of the present application has at least the following beneficial effects:
[0059] In the embodiment of the present application, an expected function safety test evaluation method for adaptive cruise in a curve scenario of an autonomous vehicle is designed. After the safety constraints and the vehicle-level safety target are determined, the dangerous trigger events are analyzed to obtain the expected function safety requirements under the control module. A simulation test scenario based on the expected function content of adaptive cruise in a curve scenario is constructed by using a simulation software. The safety evaluation dimension index is determined by evaluating the trigger events and risk events in the ACC system, and the evaluation index is weighted. The safety risk level of adaptive cruise in a curve scenario is quantitatively analyzed by using the designed cost function, so as to determine the safety of the current scenario. The risk score of the expected function safety events of adaptive cruise in a curve scenario is determined by using the present application, so as to determine the importance of the test evaluation, verify the unknown risks, and finally form the test evaluation method for the expected function safety of adaptive cruise in a curve scenario of an autonomous vehicle. BRIEF DESCRIPTION OF DRAWINGS
[0060] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0061] Figure 1 is a flow chart of an expected function safety test evaluation method for adaptive cruise in a curve scenario provided by the embodiment of the present application;
[0062] Figure 2 is a block diagram of an expected function safety test evaluation device for adaptive cruise in a curve scenario provided by the embodiment of the present application;
[0063] Figure 3 is a structural schematic diagram of an expected function safety test evaluation device provided by the embodiment of the present application. DETAILED DESCRIPTION
[0064] The technical solutions in the present application will be described below with reference to the drawings.
[0065] In the embodiments of the present application, the words such as "exemplary", "for example", etc. are used to represent an example, illustration or description. Any embodiment or design scheme described as "exemplary" in the present application should not be interpreted as more preferred or more advantageous than other embodiments or design schemes. Rather, the word "exemplary" is intended to present the concept in a specific manner. In addition, in the embodiments of the present application, the meaning expressed by "and / or" can be both, or can be one of the two.
[0066] In the embodiments of the present application, "image" and "picture" can be used interchangeably at times, and it should be pointed out that the meanings expressed are consistent when the distinction is not emphasized. "Of", "corresponding" and "corresponding" can be used interchangeably at times, and it should be pointed out that the meanings expressed are consistent when the distinction is not emphasized.
[0067] In the embodiments of the present application, sometimes the subscript such as W1 can be written in the form of non-subscript such as W1, and the meanings expressed are consistent when the distinction is not emphasized.
[0068] In order to make the technical problems, technical schemes and advantages to be solved by the present application more clear, the following will be described in detail in combination with the drawings and specific embodiments.
[0069] The embodiments of the present application provide a self-adaptive cruise expected function safety test evaluation method in a curve scenario, which can be realized by an expected function safety test evaluation device. The expected function safety test evaluation device can be a terminal or a server. As shown in the flow chart of the self-adaptive cruise expected function safety test evaluation method in a curve scenario, the processing flow of the method can include the following steps: Figure 1
[0070] S1, obtaining an unsafe control behavior of an automatic driving vehicle in a curve scenario.
[0071] In a feasible implementation manner, on the basis of STPA (System Theoretic Process Analysis) of the ACC system, a curve causation scenario is selected, and a related requirement for function improvement is proposed.
[0072] Optionally, the above step S1 can include the following steps S11-S13:
[0073] S11, determining safety constraints and vehicle-level hazard events by performing system theoretic process analysis on the adaptive cruise ACC system.
[0074] The vehicle-level hazard events can include: ACC function failure, collision of the controlled vehicle; lane change not in time, vehicle collision; no response to lane change instruction, rear-end collision; self-vehicle acceleration and deceleration exceeding a safety threshold; passenger mis-touch leading to unexpected ACC, and collision with a front vehicle.
[0075] S12, designing a vehicle-level safety target according to the safety constraints and the vehicle-level hazard events.
[0076] S13, obtaining unsafe control behaviors of the autonomous vehicle in a curve scene according to the vehicle-level hazard events and the vehicle-level safety target.
[0077] In a feasible implementation, on the basis of system theory process analysis of the ACC system, a curve causation scene is selected, and related requirements for function improvement are proposed. In order to obtain the SOTIF requirements of the ACC system, system theory process analysis method needs to be used to analyze each step. First, safety constraints are determined, and all possible vehicle-level hazard events are analyzed. Second, main vehicle-level hazard events are divided, and vehicle-level safety targets involved in subsequent analysis are determined, and finally expected functional safety requirements under the control module can be obtained.
[0078] Further, the STPA method can analyze any loss (life loss, property loss, and vehicle loss) that is unacceptable to the relevant participants. For the ACC system, the following four can be defined:
[0079] L-1: personal injury (including the driver and traffic scene participants);
[0080] L-2: vehicle damage (including the vehicle and other vehicles);
[0081] L-3: traffic task failure;
[0082] L-4: environmental damage.
[0083] Based on the analysis of the ACC function, the vehicle-level hazard events shown in Table 1 below can be obtained.
[0084] Table 1
[0085]
[0086] In combination with the contents analyzed in Table 1 above, the vehicle-level safety targets shown in Table 2 can be listed. In subsequent analysis, the following targets need to be met at all times to prevent the occurrence of danger.
[0087] Table 2
[0088]
[0089] UCA (Unsafety Control Action) refers to a control action that can lead to a vehicle-level hazard event in a certain special scenario. Generally, the source of the behavior, the control action that leads to it, or the corresponding guide words, and the hazards caused by the behavior are listed. Analogous to the guide words given in the hazard and operability analysis theory, and according to the vehicle control action, the following aspects can be analyzed:
[0090] G-1: need but not provided;
[0091] G-2: not needed, but provided;
[0092] G-3: need, but control signal is too large / small;
[0093] G-4: need, but the timing of providing the control signal is incorrect.
[0094] By integrating the ACC system architecture analyzed above and the events that can occur during driving that can lead to failure of the vehicle driving task, the following Table 3 shows the ACC system unsafe control behaviors.
[0095] Table 3
[0096]
[0097] S2, according to the unsafe control behavior, build the cause scene, and then get the expected functional safety requirement.
[0098] In a feasible implementation, the potential dangerous behavior of adaptive cruise control in a curve scenario is identified, and the expected functional safety problem of adaptive cruise control in a curve scenario is analyzed.
[0099] Optionally, the above step S2 can include the following steps S21-S22:
[0100] S21, for each unsafe control behavior, build the trigger condition and performance limitation, and according to the unsafe control behavior, the trigger condition and the performance limitation, build the cause scene.
[0101] S22, according to the cause scene and the vehicle-level safety target, get the expected functional safety requirement.
[0102] In a feasible implementation, the vehicle driving environment simulates the road scene of the real road condition, which shows the geometric structure, physical properties and dynamic behavior characteristics of the road elements, aiming to provide a highly simulated driving environment.
[0103] Further, when step S2 is performed, firstly, diversified test scenarios are identified and defined according to the detailed analysis result of step S1. Then, for each test scenario, its key parameters, such as road geometry, traffic flow, weather condition, etc., are extracted, and the final test scenario is determined in combination with external environment and vehicle control.
[0104] The trigger scenario generally includes a trigger condition and a performance limitation. The trigger condition or the performance limitation alone does not cause the generation of unsafe control behavior when acting on the ego vehicle. Only when both of them occur at the same time, a function deficiency is caused, and thus the generation of unsafe control behavior is caused. The cause scenario is shown in Table 4:
[0105] Table 4
[0106]
[0107] The ACC module SOTIF requirement focuses on the decision control module of the ACC system, and adopts a function improvement method to broaden the application scenarios of the traditional control strategy, and thus realizes the expected functional safety goal of the whole vehicle. The ACC system SOTIF requirement is shown in Table 5:
[0108] Table 5
[0109]
[0110] S3, based on the expected functional safety requirement, a simulation test scenario of the vehicle adaptive cruise is constructed in the simulation software and tested, and a test result is obtained.
[0111] Specifically, constructing the simulation test scenario of the vehicle adaptive cruise in the simulation software and testing can include: creating a vehicle dynamics model in the simulation software, adding a controller control decision algorithm, adding a vehicle driving lane environment, and performing adaptive cruise simulation test experiment on the simulated vehicle to obtain a test result.
[0112] In a feasible implementation manner, after analyzing the trigger event of the adaptive cruise in the curve scenario, the test of the autonomous vehicle is performed for the specific trigger event, and the test specifically includes the following steps:
[0113] (1) analyzing and identifying the trigger event to obtain different test scenarios, and determining a final test scenario.
[0114] When the final test scenario is determined, the key parameters in different test scenarios are extracted, and the distribution range of the key parameters is given by a real data or theoretical analysis method, and thus the final test scenario is obtained in combination with external environment, vehicle control, etc.
[0115] (2) constructing an autonomous vehicle simulation test scenario in simulation software.
[0116] In the vehicle development process, Simulink is often used in conjunction with vehicle dynamics simulation software such as Carsim. Carsim focuses on the simulation of vehicle dynamics, while Simulink provides a powerful modeling and simulation environment. Through joint simulation, comprehensive simulation and analysis of vehicle power, stability, braking and other performance can be achieved, providing strong support for vehicle design and control system optimization. The simulation software specifically uses Carsim and Simulink software.
[0117] The steps for building an autonomous vehicle simulation test scene mainly include the following steps:
[0118] B1 Establish an autonomous vehicle dynamics model in the simulation software Carsim
[0119] B2 Add the same control decision algorithm as the real vehicle in the simulation software Simulink.
[0120] Import the adaptive cruise control decision algorithm into the simulation environment, send data to the built vehicle dynamics module, and control the vehicle to drive normally in the simulation environment.
[0121] B3 Add vehicle driving environment in the simulation software Carsim.
[0122] According to the real vehicle driving environment, add the corresponding road scene, i.e. the curve scene, in the simulation software. The road scene is used to simulate the geometric characteristics, physical characteristics and behavior characteristics of the road scene elements in the real environment.
[0123] (3) In the simulation test scene of the autonomous vehicle on the curve, the simulated adaptive cruise control system of the autonomous vehicle is tested.
[0124] S4, according to the test results, determine the safety evaluation dimension index and the weight coefficient of the safety evaluation dimension index.
[0125] S5, design a cost function, and according to the safety evaluation dimension index, the weight coefficient of the safety evaluation dimension index and the cost function, obtain the safety risk level score result.
[0126] In a feasible implementation manner, the evaluation index and the weight coefficient of the evaluation index are determined, and the safety risk level of the adaptive cruise on the curve scene is quantitatively analyzed through the designed cost function.
[0127] Specifically, according to the function definition of the ACC system and the function standard specification specified by the national standard GB / T 20608-2006 for the ACC system, the expected function safety evaluation dimensions shown in Table 6 can be extracted.
[0128] Table 6
[0129]
[0130] An evaluation system framework is built. According to the function definition of the ACC system, the expected function safety evaluation dimensions shown in Table 7 can be extracted. If it is proved that the control algorithm proposed in the application has safety, not only the current driving task can be completed smoothly under the corresponding cause scene, and the safety of the passengers is guaranteed, but also the vehicle always maintains a reasonable longitudinal and lateral safety state with the front vehicle during driving, and the vehicle is provided with a control signal meeting the design expectation.
[0131] Table 7
[0132]
[0133] The number starting with CHA represents the cumulative hazard behavior, and the weight coefficient needs to be based on the importance and acceptance of the SOTIF for the ACC function to improve the index. The weight corresponding to the safety-related index will be higher. The number starting with EHA corresponds to the event hazard behavior, which proves that the control algorithm has a huge security vulnerability if it occurs, which is completely unacceptable in the design process, so the corresponding weight is the largest.
[0134] The results of different control algorithms are calculated by designing a cost function, and the safety risk level score in the connection scene is shown in Table 8:
[0135] Table 8
[0136]
[0137] Alternatively, the calculation method of the safety risk level score result in S5 is shown in the following formula (1):
[0138] (1)
[0139] In the formula, represents the risk score of the running result of the ACC system in the current simulation test scene under the current scoring standard. If the calculated value is higher, it can be considered that the expected function safety problem of the current control algorithm in the current running test scene has not been solved, there is a great security risk, and it is easy to cause the driving task to fail, in other words, it proves that the function improvement goal of the control module has not been achieved. Correspondingly, the lower the value is, the more the safety of the vehicle in the current scene can be guaranteed, and respectively correspond to the weighted weight of a certain cumulative hazard behavior and event hazard behavior; and respectively correspond to the risk coefficients of the above two behaviors.
[0140] S6、According to the safety risk level score result, an expected function safety test evaluation result of adaptive cruise under the curve scene is obtained.
[0141] In an available implementation, the expected function safety of the vehicle adaptive cruise is evaluated and analyzed to form a test evaluation system.
[0142] The above calculation result is analyzed to determine the risk level of different dangerous behaviors under the curve scene. A low score indicates a higher expected function safety level of the system, and a high score indicates a higher risk. By verifying the unknown risk of the expected function safety of the autonomous vehicle, the rationality of the existing risk can be determined. When a dangerous event occurs in the scene test process, the risk rationalization can be verified by quantitative evaluation of the test result, the expected function safety of the autonomous vehicle is determined, and a set of test evaluation processes is formed.
[0143] In the embodiment of the application, an expected function safety test evaluation method for adaptive cruise of an autonomous vehicle under a curve scene is designed. After the safety constraints and the vehicle-level safety target are determined, the dangerous trigger events are analyzed to obtain the expected function safety requirements under the control module. A simulation test scene based on the expected function content of adaptive cruise under the curve scene is constructed by using simulation software. The safety evaluation dimension index is determined by evaluating the trigger events and risk events in the ACC system, and the evaluation index is weighted. The safety risk level of adaptive cruise under the curve scene is quantitatively analyzed by using the designed cost function, so as to determine the safety of the current scene. The risk score of the expected function safety event of adaptive cruise under the curve scene is determined by using the application, so as to determine the importance of the test evaluation, verify the unknown risk, and finally form the expected function safety test evaluation method for adaptive cruise of an autonomous vehicle under a curve scene.
[0144] Figure 2 is a block diagram of an adaptive cruise expected function safety test evaluation device under a curve scene according to an exemplary embodiment. The device is used for adaptive cruise expected function safety test evaluation method under a curve scene. Referring to Figure 2 The device includes an acquisition module 310, a construction module 320, a test module 330, a determination module 340, a design module 350, and an output module 360. Among them:
[0145] The acquisition module 310 is used for acquiring an unsafe control behavior of an autonomous vehicle under a curve scene.
[0146] The construction module 320 is used for constructing a cause scene according to the unsafe control behavior, and obtaining the expected function safety requirement.
[0147] The test module 330 is configured to construct a simulation test scene of vehicle adaptive cruise in simulation software based on the expected functional safety requirement, and perform testing to obtain a test result.
[0148] The determination module 340 is configured to determine a safety evaluation dimension index and a weight coefficient of the safety evaluation dimension index according to the test result.
[0149] The design module 350 is configured to design a cost function, and obtain a safety risk level score result according to the safety evaluation dimension index, the weight coefficient of the safety evaluation dimension index, and the cost function.
[0150] The output module 360 is configured to obtain an expected functional safety test evaluation result of adaptive cruise in a curve scene according to the safety risk level score result.
[0151] Optionally, the acquisition module 310 is further configured to:
[0152] S11, determine safety constraints and vehicle-level hazard events by performing system theory process analysis on the adaptive cruise ACC system.
[0153] S12, design a vehicle-level safety target according to the safety constraints and the vehicle-level hazard events.
[0154] S13, obtain an unsafe control behavior of the autonomous vehicle in the curve scene according to the vehicle-level hazard events and the vehicle-level safety target.
[0155] Optionally, the vehicle-level hazard events include:
[0156] ACC function failure, collision of the controlled vehicle.
[0157] Failure to change lanes in time, collision of the vehicle.
[0158] Failure to respond to a lane change instruction, rear-end collision.
[0159] The acceleration or deceleration of the ego vehicle exceeds a safety threshold.
[0160] Passenger accidental touch leading to unexpected ACC, collision with a front vehicle.
[0161] Optionally, the construction module 320 is further configured to:
[0162] S21, construct a trigger condition and a performance limitation for each unsafe control behavior, and construct a causation scene according to the unsafe control behavior, the trigger condition, and the performance limitation.
[0163] S22, obtain an expected functional safety requirement according to the causation scene and the vehicle-level safety target.
[0164] Optionally, the test module 330 is further used for:
[0165] Based on the expected functional safety requirement, a vehicle dynamics model is created in simulation software, a controller control decision algorithm is added, a vehicle lane environment is added, and a self-adaptive cruise simulation test experiment is performed on the simulated vehicle to obtain a test result.
[0166] Optionally, the calculation method of the safety risk level score result is shown in the following formula (1):
[0167] (1)
[0168] In the formula, represents a safety risk level score result of the ACC system in the current simulation test scene under the current scoring standard, represents the number of cumulative hazard behaviors, represents a weighted weight value of a certain type of cumulative hazard behavior, represents a risk coefficient of a certain type of cumulative hazard behavior, represents the number of event hazard behaviors, represents a weighted weight value of a certain type of event hazard behavior, represents a risk coefficient of a certain type of event hazard behavior, represents a risk coefficient of a cumulative hazard behavior, represents a critical risk coefficient of a cumulative hazard behavior, represents a risk coefficient of an event hazard behavior, represents a critical risk coefficient of an event hazard behavior.
[0169] In the embodiment of the application, an expected functional safety test evaluation method for adaptive cruise of an autonomous vehicle in a curve scene is designed. After safety constraints and vehicle-level safety targets are determined, a risk triggering event is analyzed to obtain an expected functional safety requirement of the control module. A simulation test scene based on the expected functional content of adaptive cruise in a curve scene is constructed by using simulation software. Safety evaluation dimension indexes are determined by evaluating triggering events and risk events in the ACC system, and the evaluation indexes are assigned weights. The safety risk level of adaptive cruise in a curve scene is quantitatively analyzed by using a designed cost function, so as to determine the safety of the current scene. The risk score of the expected functional safety event of adaptive cruise in a curve scene is determined by using the application, so as to determine the importance of the test evaluation, verify unknown risks, and finally form an expected functional safety test evaluation method for adaptive cruise of an autonomous vehicle in a curve scene.
[0170] Figure 3 is a structural schematic diagram of an expected functional safety test evaluation device provided by the embodiment of the application, as Figure 3As shown, the expected function safety test evaluation device can include the above-mentioned Figure 3 The adaptive cruise expected function safety test evaluation device under the curve scenario. Optionally, the expected function safety test evaluation device 410 can include a first processor 2001.
[0171] Optionally, the expected function safety test evaluation device 410 can also include a memory 2002 and a transceiver 2003.
[0172] Wherein, the first processor 2001 is connected with the memory 2002 and the transceiver 2003, such as can pass through the communication bus.
[0173] The following will be described in detail Figure 3 The specific introduction of each component of the expected function safety test evaluation device 410:
[0174] Wherein, the first processor 2001 is the control center of the expected function safety test evaluation device 410, which can be a processor or a plurality of processing elements. For example, the first processor 2001 is one or more central processing units (CPU), which can also be an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application, such as one or more microprocessors (digital signal processor, DSP), or one or more field programmable gate arrays (FPGA).
[0175] Optionally, the first processor 2001 can execute various functions of the expected function safety test evaluation device 410 by running or executing software programs stored in the memory 2002 and calling data stored in the memory 2002.
[0176] In a specific implementation, as an embodiment, the first processor 2001 can include one or more CPUs, such as the CPU0 and CPU1 shown in Figure 3
[0177] In a specific implementation, as an embodiment, the expected function safety test evaluation device 410 can also include a plurality of processors, such as the CPU0 and CPU1 shown in Figure 3 The first processor 2001 and the second processor 2004 shown in the foregoing embodiments can be implemented by using a single-CPU or a multi-CPU. The processor herein can refer to one or more devices, circuits, and / or processing cores for processing data (for example, computer program instructions).
[0178] The memory 2002 is configured to store a software program for implementing the scheme of the present application, and the first processor 2001 is configured to control the execution of the software program. For details, refer to the method embodiments described above, which will not be repeated here.
[0179] Alternatively, the memory 2002 can be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disk storage, a magneto-optical disk, a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer, but is not limited to this. The memory 2002 can be integrated with the first processor 2001 or exist independently, and is coupled to the first processor 2001 through an interface circuit (not shown in the foregoing embodiments) of the expected functional safety test evaluation device 410. The embodiments of the present application are not limited in this regard. Figure 3
[0180] The transceiver 2003 is configured to communicate with a network device or a terminal device.
[0181] Alternatively, the transceiver 2003 can include a receiver and a transmitter (not shown separately in the foregoing embodiments). The receiver is configured to implement the receiving function, and the transmitter is configured to implement the transmitting function. Figure 3
[0182] Alternatively, the transceiver 2003 can be integrated with the first processor 2001 or exist independently, and is coupled to the first processor 2001 through an interface circuit (not shown in the foregoing embodiments) of the expected functional safety test evaluation device 410. The embodiments of the present application are not limited in this regard. Figure 3
[0183] It should be noted that, Figure 3 The structure of the expected function safety test evaluation device 410 shown in the figure does not constitute a limitation on the router, and the actual knowledge structure recognition device can include more or fewer components than the figure, or combine certain components, or different component arrangements.
[0184] In addition, the technical effects of the expected function safety test evaluation device 410 can refer to the technical effects of the adaptive cruise expected function safety test evaluation method in the curve scenario described in the above method embodiments, which will not be described here.
[0185] It should be understood that the first processor 2001 in the embodiments of the present application can be a central processing unit (CPU), and the processor can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), ready programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc.
[0186] It should also be understood that the memory in the embodiments of the present application can be volatile or nonvolatile memory, or can include both volatile and nonvolatile memory. The nonvolatile memory can be read-only memory (ROM), programmable ROM (PROM), erasable PROM (EPROM), electrically EPROM (EEPROM), or flash memory. The volatile memory can be random access memory (RAM) used as external cache. By way of example, and not limitation, many forms of random access memory (RAM) are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0187] The above-described embodiments can be implemented in whole or in part by software, hardware (such as a circuit), firmware, or any combination thereof. When implemented in software, the above-described embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present application are wholly or partially generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instructions can be transferred from one website, computer, server, or data center to another website, computer, server, or data center through a wired (such as infrared, wireless, microwave, etc.) manner. The computer-readable storage medium can be any available medium accessible by a computer or a data storage device such as a server, data center, etc. containing one or more available medium collections. The available medium can be a magnetic medium (such as a floppy disk, a hard disk, a magnetic tape), an optical medium (such as a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state disk.
[0188] It should be understood that the term "and / or" herein merely describes an association relationship of associated objects, which means that there can be three relationships, for example, A and / or B can represent three cases of A alone, A and B together, and B alone, where A and B can be singular or plural. In addition, the character " / " herein generally represents an "or" relationship between the front and rear associated objects, but can also represent an "and / or" relationship, which can be understood in the context before and after.
[0189] In the present application, "at least one" means one or more, and "multiple" means two or more. "At least one of the following" or the like means any combination of the items, including any combination of single or multiple items. For example, at least one of a, b, or c can represent a, b, c, a-b, a-c, b-c, or a-b-c, where a, b, and c can be single or multiple.
[0190] It should be understood that in various embodiments of the present application, the size of the sequence number of the above-described processes does not mean the order of execution, and the execution order of the processes should be determined by their functions and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0191] Those skilled in the art can clearly understand that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0192] Those skilled in the art can clearly understand that, for the convenience and brevity of the description, the specific working processes of the devices, apparatuses and units described above can refer to the corresponding processes in the foregoing method embodiments, which will not be repeated here.
[0193] In several embodiments provided by the present application, it should be understood that the disclosed devices, apparatuses and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely schematic, for example, the division of the units is only a logical function division, and actual implementation can have another division manner, for example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.
[0194] The units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, that is, they can be located in one place, or can be distributed on multiple network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment scheme.
[0195] In addition, each functional unit in each embodiment of the present application can be integrated into a processing unit, or each unit can exist physically independently, or two or more units can be integrated into one unit.
[0196] If the functions are realized in the form of software function units and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application or the parts of the present application that essentially contribute to the prior art or the parts of the technical solutions can be embodied in the form of software products. The computer software product is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in the various embodiments of the present application. The aforementioned storage medium includes a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media that can store program codes.
[0197] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical range disclosed by the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A method for testing and evaluating the expected functional safety of adaptive cruise control in a curve scenario, characterized in that, The method includes: S1. Acquire unsafe control behaviors of autonomous vehicles in curve scenarios; S2. Based on the unsafe control behavior, construct the causative scenario, and then obtain the expected functional safety requirements; S3. Based on the expected functional safety requirements, construct a simulation test scenario for vehicle adaptive cruise control in simulation software and conduct the test to obtain the test results; S3 includes: Different test scenarios are obtained by analyzing and identifying triggering events, and the final test scenario is determined; a simulation test scenario for autonomous vehicles is constructed in simulation software; and a scenario simulation test experiment is conducted on the simulated autonomous vehicle adaptive cruise system in the autonomous vehicle curve simulation test scenario. S4. Based on the test results, determine the safety evaluation dimension indicators and the weight coefficients of the safety evaluation dimension indicators; S5. Design a cost function, and obtain the safety risk level score based on the safety evaluation dimension indicators, the weight coefficients of the safety evaluation dimension indicators, and the cost function. S6. Based on the safety risk level score, obtain the expected functional safety test evaluation results of adaptive cruise control in the curve scenario; The calculation method for the safety risk level score in S5 is shown in the following formula (1): In the formula, S s This represents the safety risk level score of the ACC system under the current scoring criteria in the current simulation test scenario, n. CHA ω represents the cumulative number of harmful behaviors. CHA c represents the weighted value of a certain cumulative harmful behavior. CHA (q CHA ) represents the risk coefficient of a certain type of cumulative harmful behavior, n EHA ω represents the number of harmful behaviors in the event category. EHA c represents the weighted value of a certain type of harmful behavior. EHA (q EHA ) represents the risk coefficient of a certain type of harmful behavior, q CHA lim represents the risk factor of cumulative harmful behaviors. CHA q represents the critical risk coefficient for cumulative harmful behaviors. EHA lim represents the risk factor of an event-type harmful behavior. EHA This represents the critical risk coefficient for event-type harmful behaviors.
2. The method for testing and evaluating the expected functional safety of adaptive cruise control in a curve scenario according to claim 1, characterized in that, The acquisition of unsafe control behaviors of autonomous vehicles in curve scenarios in S1 includes: S11. By conducting a system theoretical process analysis of the Adaptive Cruise Control (ACC) system, safety constraints and vehicle-level hazard events are determined. S12. Based on the aforementioned safety constraints and vehicle-level hazard events, design vehicle-level safety objectives; S13. Based on the vehicle-level hazard events and vehicle-level safety objectives, obtain the unsafe control behaviors of autonomous vehicles in curve scenarios.
3. The method for testing and evaluating the expected functional safety of adaptive cruise control in a curve scenario according to claim 2, characterized in that, The vehicle-level hazard events in S11 include: ACC function failed, and the controlled vehicle was involved in a collision; Failure to change lanes in a timely manner resulted in a collision. The vehicle failed to respond to the lane change instruction, resulting in a rear-end collision. The vehicle's acceleration and deceleration exceeded the safety threshold; An occupant accidentally activated the ACC (Adaptive Cruise Control) system, resulting in an unexpected collision with the vehicle in front.
4. The method for testing and evaluating the expected functional safety of adaptive cruise control in a curve scenario according to claim 1, characterized in that, The step S2 involves constructing a causative scenario based on the unsafe control behavior, thereby obtaining the expected functional safety requirements, including: S21. For each unsafe control behavior, construct triggering conditions and performance limitations, and construct the causative scenario based on the unsafe control behavior, triggering conditions, and performance limitations. S22. Based on the causative scenario and the vehicle-level safety objectives, the expected functional safety requirements are obtained.
5. The method for testing and evaluating the expected functional safety of adaptive cruise control in a curve scenario according to claim 1, characterized in that, In step S3, based on the expected functional safety requirements, a simulation test scenario for vehicle adaptive cruise control is constructed in simulation software and tested to obtain test results, including: Based on the expected functional safety requirements, a vehicle dynamics model was created in the simulation software, a controller control decision algorithm was added, the vehicle driving environment was added, and an adaptive cruise simulation test was conducted on the simulated vehicle to obtain the test results.
6. A device for testing and evaluating the expected functional safety of adaptive cruise control in a curve scenario, wherein the device is used to implement the method for testing and evaluating the expected functional safety of adaptive cruise control in a curve scenario as described in any one of claims 1-5, characterized in that... The device includes: The acquisition module is used to acquire unsafe control behaviors of autonomous vehicles in curve scenarios. The construction module is used to construct the causal scenario based on the unsafe control behavior, thereby obtaining the expected functional safety requirements; The testing module is used to construct a simulation test scenario for vehicle adaptive cruise control in simulation software based on the expected functional safety requirements and conduct tests to obtain test results. The determination module is used to determine the security evaluation dimension indicators and the weight coefficients of the security evaluation dimension indicators based on the test results. The design module is used to design the cost function and obtain the safety risk level score result based on the safety evaluation dimension indicators, the weight coefficients of the safety evaluation dimension indicators and the cost function. The output module is used to obtain the expected functional safety test evaluation results of adaptive cruise control in a curve scenario based on the safety risk level score results.
7. The adaptive cruise control expected function safety test and evaluation device in a curve scenario according to claim 6, characterized in that, The acquisition module is used for: S11. By conducting a system theoretical process analysis of the Adaptive Cruise Control (ACC) system, safety constraints and vehicle-level hazard events are determined. S12. Based on the aforementioned safety constraints and vehicle-level hazard events, design vehicle-level safety objectives; S13. Based on the vehicle-level hazard events and vehicle-level safety objectives, obtain the unsafe control behaviors of autonomous vehicles in curve scenarios.
8. A device for testing and evaluating expected functional safety, characterized in that, The expected functional safety testing and evaluation equipment includes: processor; A memory storing computer-readable instructions that, when executed by the processor, implement the method as described in any one of claims 1 to 5.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium contains program code that can be invoked by a processor to execute the method as described in any one of claims 1 to 5.
Citation Information
Patent Citations
Expected function safety test evaluation method for automatic driving vehicle error / missing identification
CN112711260A