Automatic driving method and related device
By filtering out the first target set among multiple sensor sets in the autonomous driving system and providing perceived information to the safety domain controller, the safety and reliability problems caused by sensor failure are solved, and the safe docking of the autonomous driving vehicle is achieved.
Patent Information
- Application Number
- CN202510346441.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-21
- Publication Date
- 2025-06-24
AI Technical Summary
In autonomous driving systems, sensor failures affect the safety and reliability of autonomous vehicles, and there is a lack of unified standards to solve safety-related problems.
When the sensor of the main domain controller fails, multiple sensor sets configured for the security domain controller are filtered, the first target set is filtered out, and perceived information is provided based on the set, so that the security domain controller can control the autonomous driving vehicle to perform a safe docking operation.
The safety and reliability of autonomous vehicles are improved, and the necessary perceptual information is provided to the safety domain controller through a redundant sensor collection to ensure that the vehicle can still be safely docked in the event of sensor failure.
Smart Images

Figure CN120191390A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of artificial intelligence technology, and particularly to technical fields such as autonomous driving and communication technology. Background Art
[0002] With the deep integration of artificial intelligence technology in the field of vehicle autonomous driving, a highly automated driving system endows a vehicle with the ability to automatically complete driving tasks without human intervention under specific operation settings.
[0003] Autonomous driving technology can provide users with a more comfortable travel experience. Summary of the Invention
[0004] The present disclosure provides an autonomous driving method and related devices.
[0005] According to one aspect of the present disclosure, an autonomous driving method is provided, including:
[0006] When at least one sensor of the main domain controller fails, screening out a first target set from multiple sensor sets configured for the safety domain controller;
[0007] Providing first perception information for the safety domain controller based on the sensors included in the first target set, so that the safety domain controller controls the autonomous driving vehicle to perform a safe docking operation based on the first perception information.
[0008] According to another aspect of the present disclosure, an autonomous driving device is provided, including:
[0009] A first screening module, configured to screen out a first target set from multiple sensor sets configured for the safety domain controller when at least one sensor of the main domain controller fails;
[0010] A first control module, configured to provide first perception information for the safety domain controller based on the sensors included in the first target set, so that the safety domain controller controls the autonomous driving vehicle to perform a safe docking operation based on the first perception information.
[0011] According to another aspect of the present disclosure, an electronic device is provided, including:
[0012] At least one processor; and
[0013] A memory communicatively connected to the at least one processor; wherein,
[0014] The memory stores instructions executable by the at least one processor, and when the instructions are executed by the at least one processor, the at least one processor is enabled to execute any method in the embodiments of the present disclosure.
[0015] According to another aspect of the present disclosure, there is provided a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to cause the computer to execute the method according to any one of the embodiments of the present disclosure.
[0016] According to another aspect of the present disclosure, there is provided a computer program product, including a computer program which, when executed by a processor, implements the method according to any one of the embodiments of the present disclosure.
[0017] According to another aspect of the present disclosure, there is provided a self-driving vehicle, including the electronic device described above.
[0018] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present disclosure, nor is it used to limit the scope of the present disclosure. Other features of the present disclosure will become easily understood through the following description. Description of the Drawings
[0019] The drawings are used to better understand the solution and do not constitute a limitation to the present disclosure. Among them:
[0020] Figure 1 is a schematic flowchart of a self-driving method provided according to an embodiment of the present disclosure;
[0021] Figure 2 is a schematic flowchart of the failure of a security domain controller provided according to an embodiment of the present disclosure;
[0022] Figure 3 is a schematic diagram of grouping multiple sensors provided according to an embodiment of the present disclosure;
[0023] Figure 4 is a schematic structural diagram of a self-driving device provided according to an embodiment of the present disclosure;
[0024] Figure 5 is a block diagram of an electronic device for implementing the self-driving method of the embodiments of the present disclosure. Detailed Embodiments
[0025] The following makes an explanation of the exemplary embodiments of the present disclosure in conjunction with the drawings. Various details of the embodiments of the present disclosure are included to facilitate understanding, and they should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope of the present disclosure. Similarly, for clarity and conciseness, the description below omits the description of well-known functions and structures.
[0026] The terms "first", "second", etc. in this disclosure are used to distinguish similar objects and do not necessarily describe a specific order or sequence. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, product, or apparatus that comprises a series of steps or units does not necessarily limit to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or apparatuses.
[0027] With the rapid development of artificial intelligence technology, autonomous driving systems have gradually become a research hotspot and future development direction in the transportation field. Among them, sensors, as the key components for autonomous driving vehicles to perceive the external environment, play a crucial role in autonomous driving systems.
[0028] There is still a lack of a unified standard on how to specifically define and solve safety-related problems from the perspective of sensors.
[0029] In view of this, the embodiments of this disclosure provide an autonomous driving method, which effectively divides sensors to improve the safety and reliability of autonomous driving vehicles. As Figure 1 shown, it mainly includes the following content:
[0030] S101, in the case that at least one sensor of the main domain controller fails, screen out the first target set from multiple sensor sets configured for the safety domain controller.
[0031] In an autonomous driving system, the main domain controller serves as the core hub of the entire vehicle control system. By receiving signals sent from various sensors of the autonomous driving vehicle, such as radar, lidar, infrared cameras, image sensors, microphones, etc., it realizes the decision-making and execution of autonomous driving. When there are hardware failures of the sensors themselves or communication failures between the sensors and the main domain controller, etc., these all belong to the sensor failures of the main domain controller.
[0032] The safety domain controller, as the name implies, is a control unit in the autonomous driving system that takes over the main domain controller and is responsible for controlling functions related to vehicle safety. Its main task is to ensure that the autonomous driving vehicle can be safely parked under the condition that the main domain controller cannot work properly for various reasons.
[0033] In the embodiments of the present disclosure, multiple sensors of an autonomous vehicle are partitioned, providing multiple sensor sets for the safety domain controller that can independently sense the surrounding environment of the autonomous vehicle. During implementation, to improve safety and reliability, each sensor set can provide the necessary sensing information required for the safety domain controller to park the vehicle. In the case where the sensors included in the main domain controller fail, a first target set can be selected from the multiple sensor sets configured for the safety domain controller to ensure that the vehicle can park safely.
[0034] The safety domain controller senses traffic elements around the autonomous vehicle by receiving information from each sensor within the first target set selected for it, and controls the autonomous vehicle to park safely in a compliant parking area.
[0035] S102, Based on the sensors included in the first target set providing first sensing information to the safety domain controller, enabling the safety domain controller to control the autonomous vehicle to perform a safe parking operation based on the first sensing information.
[0036] That is, after the first target set is selected, the safety domain controller can make driving decisions based on the first sensing information provided by each sensor in the first target set to plan and execute a driving operation for safe parking.
[0037] In the embodiments of the present disclosure, in the case where the sensors of the main domain controller fail, selecting a first target set from the multiple sensor sets configured for the safety domain controller enables the autonomous vehicle to still rely on other normally operating sensors to obtain necessary environmental sensing information, thus maintaining the safe operation of the autonomous vehicle. The multiple sensor sets provide a redundant backup sensing solution for the safety domain controller. This redundant setting can effectively improve the reliability and fault tolerance of the autonomous vehicle, reduce the safety hazards of the autonomous vehicle caused by the failure of a single sensor, and thereby improve the safety and reliability of the autonomous vehicle.
[0038] In the scenario of autonomous driving, whether the safety domain controller can obtain accurate and reliable sensing information depends to a large extent on the normal operating status of each sensor it is configured with. Therefore, to ensure that the safety domain controller can make decisions regarding vehicle safety based on effective information, the first target set can be selected from the multiple sensor sets configured for the safety domain controller based on the following steps:
[0039] Step A1, Detect the sensor status in each sensor set configured for the safety domain controller;
[0040] During implementation, the hardware functions and communication status of the sensors themselves can be detected. For example, it can be detected whether the laser emission and reception modules of the lidar are working properly, whether the scanning angle is accurate, etc.; it can be checked whether the lens of the camera is online and whether the image sensor can normally sense light and form an image, etc.
[0041] Step A2, screen the set of sensors with normal status of each sensor as the first target set.
[0042] That is, after completing the detection of the status of the sensors in each sensor set, the set in which all sensor statuses are normal can be screened out as the first target set according to the detection results.
[0043] In the embodiments of the present disclosure, by detecting and screening out the set of sensors with normal status of each sensor as the first target set, it can be ensured that the first target set configured for the safety domain controller can provide sufficient perception information to assist in driving decisions, thereby improving the reliability of the automatic docking of the autonomous vehicle, and thus ensuring the safety of the autonomous vehicle and the safety of users.
[0044] In the architecture design of the autonomous vehicle, although the execution capabilities of the safety domain controller and the main domain controller are different, in order to improve the safety of the autonomous driving system, a redundancy mechanism is also established between the safety domain controller and the main domain controller to ensure that the autonomous vehicle can still operate safely in the case of a failure of either the safety domain controller or the main domain controller. Based on the content described above, in the case of a sensor failure in the main domain controller, the sensors in the first target set screened from the multiple sensor sets configured for the safety domain controller can be used to provide the necessary first perception information for the safety domain controller. Based on this perception information, the safety domain controller can take over and guide the autonomous vehicle to perform a predetermined safe docking operation.
[0045] Correspondingly, in the case of a failure of the safety domain controller, the safe docking operation of the autonomous vehicle can be completed based on the steps shown in Figure 2 including:
[0046] S201, in the case of a failure of the safety domain controller, screen out multiple normally working sensors to obtain a second target set.
[0047] For example, in the case of a failure of the safety domain controller, the second target set can be screened out from the multiple sensor sets configured for the safety domain controller.
[0048] The same as the screening method of the first target set, the sensors that can best meet the current requirements can be screened out from the multiple sensor sets configured for the safety domain controller as the second target set.
[0049] Among them, a plurality of sensor sets configured for the safety domain controller can cover all sensors in the autonomous driving vehicle. Among them, the situation where all the plurality of sensor sets configured for the safety domain controller fail hardly exists. By configuring a plurality of sensor sets, a redundancy mechanism is provided to improve the high availability of screening out a suitable second target set.
[0050] Of course, during implementation, according to the requirements for safely docking the autonomous driving vehicle, the requirements may include the required sensor types and the sensing ranges of each type of sensor. Based on these requirements, a plurality of normally operating sensors that meet the requirements can be screened out from the autonomous driving vehicle to obtain a second target set.
[0051] S202, based on the sensors included in the second target set, provide second sensing information for the main domain controller, so that the main domain controller takes over the work of the safety domain controller and controls the autonomous driving vehicle to perform a safe docking operation based on the second sensing information.
[0052] That is, after screening out the second target set, by integrating the data provided by each sensor in the second target set, second sensing information is formed. The second sensing information is used to describe the information of the vehicle's surrounding environment and its own state. So that the main domain controller can take over the work of the safety domain controller and control the speed and / or driving direction of the autonomous driving vehicle based on the second sensing information until it stops safely.
[0053] In the embodiments of the present disclosure, in the case where a problem occurs with the sensors in the safety domain controller, the main domain controller takes over the safety operation of the safety domain controller, so that the main domain controller of the autonomous driving vehicle can still rely on other normally operating sensors to replace the failed sensors in the safety domain controller to obtain the necessary environmental information, thereby maintaining the safe operation of the autonomous driving vehicle, and thus improving the safety and reliability of the autonomous driving vehicle.
[0054] In the embodiments of the present disclosure, to improve the safety of the autonomous driving vehicle and achieve redundant sensor configuration, a plurality of sensors of the autonomous driving vehicle can be divided into a plurality of sensor groups, and each sensor set includes at least one sensor group.
[0055] During implementation, all the sensors of the autonomous driving vehicle can be divided into a plurality of sensor groups according to the sensor type and / or the coverage area. Among them, different sensor groups are responsible for sensing different sensing directions of the autonomous driving vehicle, so that each sensor group collects information corresponding to its respective sensing direction. For example, according to the sensing direction, it can be divided into a vehicle front sensor group, such as Figure 3 G1 and G2 in; a rear sensor group, such as Figure 3 G3 and G4 in. Figure 3 shows the approximate positions of the sensors relative to the autonomous driving vehicle. Among them:
[0056] The sensor group G1 includes: lidar 2, radar 8, radar 9, image sensors 11, and image sensors 12;
[0057] The sensor group G2 includes: lidar 1, infrared camera 1, radar 3, and image sensors 2, image sensors 3, image sensors 4, image sensors 5, image sensors 6, and image sensors 7;
[0058] The sensor group G3 includes: microphone 2, infrared camera 2, radars 4, 5, 6, 7, and image sensors 8, 9, 10;
[0059] The sensor group G4 includes: microphone 1, image sensor 1, radars 1, 2.
[0060] Of course, it can be understood that the embodiments of the present disclosure are only Figure 3 exemplarily illustrated. During implementation, the number of sensor groups and the sensors included in each sensor group can be flexibly divided. Each sensor is responsible for a different sensing direction.
[0061] By dividing multiple sensors into multiple sensor groups based on the sensing direction and ensuring that each group corresponds to its own sensing direction, the sensors in the same group can provide signals in the sensing direction they are responsible for for driving decisions. When redundant sensor groups are provided in the same sensing direction (such as Figure 3 G1 and G2 shown), the safety of autonomous driving can be further improved.
[0062] In the case of a failure of a certain sensor in the sensor group in any sensing direction, switching from the main domain controller to the safety domain controller, the safety domain controller has redundant multiple sensor sets, and can quickly find an alternative sensor in the remaining sensor groups in that sensing direction to ensure the safety and stability of the autonomous driving vehicle and improve the reliability and redundancy of the autonomous driving vehicle.
[0063] After dividing the multiple sensors of the autonomous driving vehicle into multiple sensor groups, the sensor groups can be freely combined into sensor sets. Each sensor set includes at least one sensor group. For example, the sensor set {G1} only contains the sensor group G1; the sensor set {G1, G2, G3} can contain three sensor groups, namely the sensor group G1, the sensor group G2, and the sensor group G3. During implementation, the configuration of the sensor groups and sets can be flexibly divided according to the actual vehicle situation. As long as redundant multiple sensor sets can be provided for the safety domain controller and each sensor set can provide necessary safety sensing information to the safety domain controller.
[0064] It can be understood that the main domain controller is responsible for the operation of the entire vehicle and requires comprehensive environmental perception capabilities. Therefore, the main domain controller should be equipped with all types of sensors to achieve complex autonomous driving tasks. The safety domain controller focuses on providing basic safety guarantees, especially in emergency situations. Its sensor configuration should be concentrated on areas and functions that are crucial for safety. Thus, the number of sensors included in each sensor set within the safety domain controller is less than that of the main domain controller.
[0065] As Figure 3 shown, the sensor set configured for the main domain controller is {G1, G2, G3}, while the safety domain can include four sensor sets, namely {G1, G3}, {G1, G4}, {G2, G3}, {G2, G4}, thereby achieving four redundant sensor set configurations. In the case of any sensor failure in the main domain controller, basically one of these four sensor sets can always provide a perception signal for the safety domain controller to use.
[0066] In the embodiments of the present disclosure, by grouping the sensors, even if the sensors in a certain group fail or are interfered with, other groups can still continue to provide necessary perception information to ensure that the vehicle can maintain safe operation. Different groups can cover different functional requirements. If one group fails, the data of other groups can help the autonomous driving vehicle make correct decisions, and can reduce the impact of a single failure point on the safety of the entire autonomous driving system. And the number of sensors included in each sensor set within the safety domain controller is less than that of the main domain controller, which can ensure that the safety domain controller can include the minimum necessary sensor set, reduce the complexity of signal processing of the safety domain controller, and increase the reliability of the autonomous driving system.
[0067] In the embodiments of the present disclosure, each sensor group corresponds to a hub respectively, which is responsible for receiving signals from multiple sensors, sorting and processing them, and then forwarding them to the corresponding controller to facilitate the management and optimization of data transmission. Among them, the functions of each sensor group corresponding to the hub are as follows:
[0068] Each sensor group of the main domain controller sends the perception signal to the main domain controller through the corresponding hub;
[0069] Each sensor group of the safety domain controller sends the perception signal to the safety domain controller through the corresponding hub.
[0070] In the embodiments of the present disclosure, by using the hub to group the sensors, the modularity and maintainability of the system are improved, providing a basic guarantee for dividing multiple sensor sets for the main domain controller and the safety domain controller.
[0071] In addition, when any hub fails, it can also be understood that the sensors in the hub malfunction, thus triggering a safety operation. That is, when any hub fails, the operation of the main domain controller will stop, a first target set will be selected from the slave safety domain controllers, and the first perception information will be provided for the safety domain controller based on the sensors included in the first target set, so that the safety domain controller controls the autonomous vehicle to perform a safe parking operation based on the first perception information.
[0072] In the embodiments of the present disclosure, to improve the flexibility and security of grouping, multiple sensors of an autonomous vehicle are divided into multiple perception regions based on power supply requirements, and each perception region is powered separately; each sensor group includes at least one perception region.
[0073] That is, different types of sensors have different power supply requirements due to factors such as their working principles and performance requirements. According to these different power supply requirements, all the sensors on the autonomous vehicle can be divided into multiple perception regions, and each perception region is powered separately.
[0074] Among them, each sensor group includes at least one perception region. The sensor groups are divided based on factors such as the type, function, and location of the sensors, while the perception regions are divided based on power supply requirements. As Figure 3 shown, in the direction between the rear and the front of the vehicle, the sensors in the autonomous vehicle can be divided into two layers, upper and lower. In the upper layer distribution, the front sensor group G2 of the autonomous vehicle includes the front lidar 1, infrared camera 1, radar 3, and image sensors 2, 3, 4, 5, 6, 7.
[0075] Among them:
[0076] The lidar 1 and the image sensors 2 and 3 on both sides of the autonomous vehicle form a perception region, as Figure 3 shown as U2 in the figure;
[0077] The infrared camera 1, radar 3, and image sensors 4, 5, 6, 7 form another perception region, as Figure 3 shown as U3 in the figure.
[0078] Both of these two perception regions U2 and U3 are included in the front sensor group G2 of the autonomous vehicle.
[0079] It can also be as Figure 3 shown that the rear sensor group G4 of the autonomous vehicle only includes one perception region U1. The perception region U1 can include the microphone 1, image sensor 1, radar 1, and radar 2.
[0080] Based on a similar partitioning principle, such as Figure 3 shown, the front sensor group G1 of the autonomous vehicle only contains one sensing area D3. The sensing area D3 may include lidar 2, radar 8, radar 9, and image sensors 11 and 12.
[0081] The rear sensor group G3 of the autonomous vehicle may include two sensing areas, namely sensing area D1 and sensing area D2. The sensing area D1 may include radar 4, radar 5, and image sensor 8; the sensing area D2 may include microphone 2, infrared camera 2, image sensors 9 and 10, radar 6, and radar 7.
[0082] Among them, the viewing angles of the image sensors in different sensing areas can be flexibly determined. For example, for the sensing areas U1 and D1 at the rear of the autonomous vehicle, the viewing angle of the image sensor 1 in the sensing area U1 can be 170°, while the viewing angle of the image sensor 8 in the sensing area D1 can be 30°.
[0083] In specific implementation, the partitioning of the sensing areas and the setting of the viewing angle range of the image sensors can be determined according to actual requirements, and the present disclosure implementation does not limit this.
[0084] In the embodiments of the present disclosure, by partitioning the sensors into different sensing areas according to power supply requirements, even if a certain power supply fails, the sensors in other areas can still work normally, enhancing the redundancy and reliability of the system. Different types of sensors may have different power consumption characteristics. Reasonably partitioning the sensing areas helps to optimize energy use while reducing the complexity of sensor wiring. At the same time, independent sensing areas can provide a basis for partitioning sensor groups.
[0085] In the embodiments of the present disclosure, different sensing areas can be partitioned based on the vehicle structure. For example Figure 3 divides the vehicle into front, middle, and rear sensing areas. Among them, each sensing area has a corresponding redundant configuration. For example, U1 and D1 are redundant with each other, U2 and D2 are redundant with each other, and U3 and D3 are redundant with each other.
[0086] During implementation, the partitioning of the sensing areas should meet at least one of the following conditions:
[0087] (1) At most a specified number of infrared cameras are set in the same sensing area;
[0088] As Figure 3 shown, at most one infrared camera 1 is included in the sensing area U3; at most one infrared camera 2 is included in the sensing area D2. By restricting the number of infrared cameras in the same sensing area, the cost can be effectively controlled, and sufficient information can be obtained to support the autonomous driving requirements.
[0089] (2) At most a specified number of lidar sensors are set within the same sensing area;
[0090] For example, Figure 3 As shown, there is at most one lidar sensor 1 in the sensing area U2; there is at most one lidar sensor 2 in the sensing area D3. Since the cost of lidar sensors themselves is relatively high, restricting the number within the same sensing area can effectively control costs and provide sufficient information to support the requirements of autonomous driving.
[0091] (3) At most a specified number of microphones are set within the same sensing area;
[0092] For example, Figure 3 As shown, at most one microphone is set in the sensing area U1, which can provide sufficient information for autonomous driving while effectively controlling costs.
[0093] (4) Multiple image sensors are divided into different sensing areas;
[0094] For example, Figure 3 As shown, the sensing area U1 contains the image sensor 1 in the rear sensing direction of the autonomous vehicle; the sensing area U2 contains the image sensors 2 and 3 on the left and right sides of the autonomous vehicle; the sensing area U3 contains the image sensors 6 and 7 in the front of the autonomous vehicle and the image sensors 4 and 5 on both sides. Dividing multiple image sensors into different sensing areas can ensure comprehensive and almost blind-spot-free environmental perception of the autonomous vehicle, avoiding the situation where data is overly concentrated in some areas while causing insufficient perception in other areas. And it can achieve sensor redundancy backup for different sensing areas.
[0095] (5) Multiple radar sensors are divided into different sensing areas;
[0096] For example, Figure 3 As shown, the sensing area D1 contains the left rear radar 4 and the right rear radar 5 of the autonomous vehicle; the sensing area D2 contains the left side radar 6 and the right side radar 7 of the autonomous vehicle; the sensing area D3 contains the left front radar 8 and the right front radar 9 of the autonomous vehicle. The division of each radar sensor into different sensing areas is also for achieving all-round and targeted environmental perception. By dividing them into different sensing areas, the functional advantages of each radar in the corresponding sensing area can be better exerted.
[0097] (6) Multiple lidar sensors are divided into different sensing areas.
[0098] For example, Figure 3As shown in the figure, in the sensing area D3 and the sensing area U2, each contains a lidar. The lidars in different sensing areas are divided into different sensor groups, which can achieve redundant backup of the lidars and make full use of the information they sense to improve the safety and reliability of the autonomous driving system.
[0099] In the embodiments of the present disclosure, based on the different functions of different sensors and combined with the power supply requirements, multiple sensors are divided into multiple sensing areas, and it is ensured that the number and / or type of sensors in each sensing area meet the specified conditions. While improving the reliability and redundancy of the autonomous driving system, it can also optimize energy management. Further improving the safety performance and user experience of the entire autonomous driving system.
[0100] Based on the content described above, after dividing the multiple sensors of the autonomous driving vehicle into multiple sensor groups, the reliability of each sensor group can be calculated based on the reliability of each sensor, as well as the reliability of the main domain controller and the safety domain controller including different sensor groups, to verify that the autonomous driving method provided in the embodiments of the present disclosure can improve the safety of the autonomous driving vehicle.
[0101] Take Figure 3 the divided sensor groups as an example. The reliability of the image sensor is represented by r(V); the reliability of the lidar is represented by r(L); the reliability of the radar is represented by r(R); the reliability of the infrared camera is represented by r(L); the reliability of the microphone is represented by r(A); the reliability of the hub corresponding to each sensor group is represented by r(H).
[0102] Then the reliability of the sensor group G1 can be calculated based on formula (1):
[0103] Group1r(G1) = r(V) 2 *r(L)*r(R) 2 *r(H) (1)
[0104] In formula (1), Group1r(G1) is used to represent the reliability of the sensor group G1, where r(V) 2 represents the product of the reliabilities of the two image sensors included in the sensor group G1; r(R) 2 represents the product of the reliabilities of the two radars included in the sensor group G1.
[0105] Similarly, the reliability of the sensor group G2 can be calculated based on formula (2):
[0106] Group2r(G2) = r(V) 6 *r(L)*r(R)*r(I)*r(H) (2)
[0107] The reliability of sensor group G3 can be calculated based on formula (3):
[0108] Group3r(G3) = r(V) * r(R) 2 * r(I) * r(A) * r(H) (3)
[0109] The reliability of sensor group G4 can be calculated based on formula (4):
[0110] Group4r(G4) = r(V) * r(R) 2 * r(A) * r(H) (4)
[0111] In the case where sensor groups G1, G2, and G3 are sensors of the primary domain controller, the reliability of the sensors of the primary domain controller can be calculated based on formula (5):
[0112] r(M) = r(G1) * r(G2) * r(G3) (5)
[0113] where r(M) represents the reliability of the sensors of the primary domain controller.
[0114] In the case where the sets of sensor groups {G1, G3}, {G1, G4}, {G2, G3}, and {G2, G4} are sensors of the security domain controller, the reliability of the sensors of the security domain controller can be calculated based on formula (6):
[0115] r(S) = 1 - (1 - r(G1) * r(G3)) * (1 - r(G2) * r(G4)) * (1 -
[0116] r(G1) * r(G4)) * (1 - r(G2) * r(G3)) (6)
[0117] where r(S) represents the reliability of the sensors of the security domain controller.
[0118] From the calculation results based on the above formulas, it can be obtained that r(S) is much greater than r(M).
[0119] Exemplarily, based on the specific reliability values of individual sensors (not listed in the table), the calculation results of the reliability of sensor groups and the final autonomous driving system can be as shown in Table 1:
[0120] Table 1
[0121]
[0122] As shown in Table 1, if only the grouped sensors are combined for use in the sensors of the main domain controller or the sensors of the safety domain controller, the reliability of the autonomous vehicle will decrease accordingly as the number of sensor groups increases. After multiple sensors configured for the safety domain controller are aggregated, the reliability of the autonomous vehicle is much greater than that of only having the sensors of the main domain controller. Therefore, the autonomous driving method provided by the embodiments of the present disclosure can effectively improve the safety of the autonomous vehicle.
[0123] Based on the same technical concept, the embodiments of the present disclosure further provide an autonomous driving device 400, as Figure 4 shown, including:
[0124] A first screening module 401, configured to screen out a first target set from multiple sensor sets configured for the safety domain controller when at least one sensor of the main domain controller fails;
[0125] A first control module 402, configured to provide first perception information for the safety domain controller based on the sensors included in the first target set, so that the safety domain controller controls the autonomous vehicle to perform a safe docking operation based on the first perception information.
[0126] In some embodiments, it further includes:
[0127] A second screening module, configured to screen out multiple normally operating sensors to obtain a second target set when the safety domain controller fails;
[0128] A second control module, configured to provide second perception information for the main domain controller based on the sensors included in the second target set, so that the main domain controller takes over the work of the safety domain controller and controls the autonomous vehicle to perform a safe docking operation based on the second perception information.
[0129] In some embodiments, multiple sensors of the autonomous vehicle are divided into multiple sensor groups, and each sensor set includes at least one sensor group;
[0130] The number of sensors included in each sensor set configured for the safety domain controller is less than the number of sensors of the main domain controller.
[0131] In some embodiments, each sensor group corresponds to a hub;
[0132] Each sensor group of the main domain controller sends a perception signal to the main domain controller through the corresponding hub;
[0133] Each sensor group of the safety domain controller sends a perception signal to the safety domain controller through the corresponding hub.
[0134] In some embodiments, an autonomous vehicle is divided into multiple sensing directions, and each sensor group corresponds to its respective sensing direction.
[0135] In some embodiments, multiple sensors of an autonomous vehicle are divided into multiple sensing regions based on power supply requirements, and each sensing region is powered separately; each sensor group includes at least one sensing region.
[0136] In some embodiments, the sensing region satisfies at least one of the following conditions:
[0137] At most a specified number of infrared cameras are arranged in the same sensing region;
[0138] At most a specified number of lidars are arranged in the same sensing region;
[0139] At most a specified number of microphones are arranged in the same sensing region;
[0140] Multiple image sensors are divided into different sensing regions;
[0141] Multiple radar sensors are divided into different sensing regions;
[0142] Multiple lidars are divided into different sensing regions.
[0143] In some embodiments, the first screening module further includes:
[0144] A detection subunit, configured to detect the sensor states in each sensor set configured for the safety domain controller;
[0145] A screening subunit, configured to screen the sensor sets with normal sensor states as the first target set.
[0146] For the specific functions and examples of the modules and sub-modules of the device according to the embodiments of the present disclosure, reference may be made to the relevant descriptions of the corresponding steps in the above method embodiments, which will not be elaborated herein.
[0147] In the technical solution of the present disclosure, the acquisition, storage, and application of the user's personal information involved all comply with the provisions of relevant laws and regulations and do not violate public order and good customs.
[0148] According to the embodiments of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium, and a computer program product.
[0149] Figure 5FIG. 0 shows a schematic block diagram of an example electronic device 500 that may be used to implement embodiments of the present disclosure. The electronic device is intended to represent various forms of digital computers, such as, a laptop computer, a desktop computer, a workbench, a personal digital assistant, a server, a blade server, a mainframe computer, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as, a personal digital assistant, a cellular phone, a smart phone, a wearable device, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are only examples and are not intended to limit the implementation of the present disclosure described and / or claimed herein.
[0150] As Figure 5 shown, the device 500 includes a computing unit 501 that may perform various appropriate actions and processes in accordance with a computer program stored in a read-only memory (ROM) 502 or a computer program loaded from a storage unit 508 into a random access memory (RAM) 503. In the RAM 503, various programs and data required for the operation of the device 500 may also be stored. The computing unit 501, the ROM 502, and the RAM 503 are connected to each other via a bus 504. An input / output (I / O) interface 505 is also connected to the bus 504.
[0151] A plurality of components in the device 500 are connected to the I / O interface 505, including: an input unit 506, such as a keyboard, a mouse, etc.; an output unit 507, such as various types of displays, speakers, etc.; a storage unit 508, such as a magnetic disk, an optical disk, etc.; and a communication unit 509, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 509 allows the device 500 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0152] The computing unit 501 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 501 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 501 executes the various methods and processes described above, such as the autonomous driving method. For example, in some embodiments, the autonomous driving method can be implemented as a computer software program that is tangibly contained in a machine-readable medium, such as the storage unit 508. In some embodiments, part or all of the computer program can be loaded and / or installed onto the device 500 via the ROM 502 and / or the communication unit 509. When the computer program is loaded into the RAM 503 and executed by the computing unit 501, one or more steps of the autonomous driving method described above can be executed. Alternatively, in other embodiments, the computing unit 501 can be configured to execute the autonomous driving method in any other suitable way (e.g., by means of firmware).
[0153] Various embodiments of the systems and techniques described above in this document can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGA), application-specific integrated circuits (ASIC), application-specific standard products (ASSP), system-on-a-chip systems (SOC), complex programmable logic devices (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special-purpose or general-purpose programmable processor, and can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0154] The program code for implementing the methods of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to the processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing devices, such that when the program codes are executed by the processor or controller, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The program codes can be executed entirely on the machine, partially on the machine, executed partially on the machine as an independent software package and partially on a remote machine, or executed entirely on a remote machine or server.
[0155] In the context of this disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0156] In order to provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, speech input, or tactile input).
[0157] The systems and techniques described herein can be implemented in a computing system including backend components (e.g., as a data server), or a computing system including middleware components (e.g., an application server), or a computing system including frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system including any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of a communication network include: a local area network (LAN), a wide area network (WAN), and the Internet.
[0158] A computer system can include a client and a server. The client and the server are generally far apart from each other and typically interact through a communication network. The relationship of the client and the server is generated by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, can also be a server of a distributed system, or a server incorporating a blockchain.
[0159] Based on the foregoing electronic device, the present disclosure further provides a vehicle, which may include the electronic device, and may further include a communication component, a display screen for implementing a human-machine interface, an information collection device for collecting surrounding environment information, etc. The communication component, the display screen, and the information collection device are communicatively connected to the electronic device.
[0160] According to an embodiment of the present disclosure, the electronic device may be integrally integrated with the communication component, the display screen, and the information collection device, or may be separately provided from the communication component, the display screen, and the information collection device.
[0161] It should be understood that various forms of the processes shown above may be used, steps may be reordered, added, or deleted. For example, the steps described in the present disclosure may be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in the present disclosure can be achieved, and no limitation is made herein.
[0162] The above specific embodiments do not constitute a limitation on the protection scope of the present disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the principles of the present disclosure shall be included within the protection scope of the present disclosure.
Claims
1. An automatic driving method, comprising: In the event that at least one sensor of the primary domain controller fails, a first target set is selected from a plurality of sensor sets configured for the security domain controller; Based on the sensors included in the first target set, first perception information is provided to the safety domain controller, so that the safety domain controller controls the autonomous driving vehicle to perform a safe parking operation based on the first perception information.
2. The method according to claim 1, further comprising: In the case of a security domain controller failure, multiple sensors that are working normally are screened out to obtain a second target set; Based on the sensors included in the second target set, second perception information is provided to the primary domain controller so that the primary domain controller takes over the work of the security domain controller and controls the autonomous driving vehicle to perform a safe parking operation based on the second perception information.
3. The method according to claim 1 or 2, wherein: The multiple sensors of the autonomous driving vehicle are divided into multiple sensor groups, each sensor set including at least one sensor group; The number of sensors included in each sensor set configured for the security domain controller is smaller than the number of sensors for the primary domain controller.
4. The method according to claim 3, wherein: Each sensor group corresponds to a hub; Each sensor group of the primary domain controller sends a sensing signal to the primary domain controller through a corresponding hub; Each sensor group of the security domain controller sends a sensing signal to the security domain controller through a corresponding hub.
5. The method according to claim 3, wherein: The autonomous driving vehicle is divided into multiple perception directions, and each sensor group corresponds to its own perception direction.
6. The method according to claim 3, wherein: The multiple sensors of the autonomous driving vehicle are divided into multiple sensing areas based on power supply requirements, and each sensing area is powered separately; each sensor group includes at least one sensing area.
7. The method according to claim 6, wherein: The sensing area meets at least one of the following conditions: A maximum of a specified number of infrared cameras can be set in the same sensing area; At most a specified number of laser radars can be set in the same sensing area; At most a specified number of microphones can be set in the same sensing area; Multiple image sensors are divided into different sensing areas; Multiple radar sensors are divided into different perception areas; Multiple lidars are divided into different perception areas.
8. The method according to any one of claims 1 to 7, wherein: The step of selecting a first target set from a plurality of sensor sets configured for the security domain controller includes: detecting the status of sensors in each sensor set configured for the security domain controller; A sensor set in which each sensor is in a normal state is selected as the first target set.
9. An automatic driving device, comprising: A first screening module, configured to screen out a first target set from a plurality of sensor sets configured for a security domain controller when at least one sensor of the primary domain controller fails; The first control module is used to provide first perception information to the safety domain controller based on the sensors included in the first target set, so that the safety domain controller controls the autonomous driving vehicle to perform a safe parking operation based on the first perception information.
10. An electronic device, comprising: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 8.
11. A non-transitory computer-readable storage medium storing computer instructions, wherein: The computer instructions are used to cause the computer to execute the method according to any one of claims 1-8.
12. A computer program product, comprising a computer program, which, when executed by a processor, implements the method according to any one of claims 1 to 8.
13. An autonomous driving vehicle comprising the electronic device described in claim 10.