Method and device for generating safety quantification target of automatic driving vehicle

Through adversarial training combined with two target generation models, the safety quantification goals of autonomous driving vehicles are optimized, and the problem of unreasonable generation results in the existing technology is solved, and the decision-making safety of autonomous driving systems is improved.

CN120207382APending Publication Date: 2025-06-27BEIJING SAIMO TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510590433.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-08
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

When existing autonomous vehicles generate safety quantification goals, it is difficult to effectively optimize the results, resulting in unreasonable decision-making and affecting road safety and traffic flow.

Method used

Through the adversarial training method, combining two target generation models (models that systematically analyze failures and functional failures), the generated safety quantization goals are optimized to ensure that the final goals are more reasonable and safe.

Benefits of technology

It improves the rationality and safety of the generation results of the safety quantification target of autonomous driving vehicles, and enhances the decision-making capabilities of autonomous driving systems in complex traffic scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120207382A_ABST
    Figure CN120207382A_ABST
Patent Text Reader

Abstract

The invention provides a method and a device for generating a safety quantification target of an automatic driving vehicle. The first target generation model generates a first initial safety quantification target when a first processing mechanism is adopted for systematic analysis faults, and the second target generation model generates a second initial safety quantification target when a second processing mechanism is adopted for functional failures; when the optimization ending condition is not met, confrontation training is carried out on the two models according to the two targets under the same evaluation dimension, and two initial safety quantification targets are regenerated by using the two trained models; and when the two regenerated targets meet an optimization ending condition, obtaining an optimal safety quantification target of the target scene according to at least one of the two regenerated targets. In this way, the generated safety quantification target is optimized through the adversarial training method, and the rationality of the safety quantification target generation result of the automatic driving vehicle can be effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of autonomous vehicle control, and in particular, to a method and device for generating safety quantification targets for autonomous vehicles. Background Art

[0002] As the future development direction of the automotive industry, intelligent driving is gradually moving from concept to reality. With the continuous evolution of autonomous driving technology, expected functional safety has become a key factor to ensure the reliable operation of intelligent driving systems. Moreover, during the driving process of autonomous vehicles, they need to independently make safety-critical decisions and estimate the impact of their behaviors on the surrounding traffic, so as to balance the safety of individuals and groups. By quantifying safety indicators, it is possible to guide autonomous vehicles to make correct decisions during operation and improve road safety and traffic flow. Therefore, formulating reasonable expected functional safety targets not only concerns the lives of users but also is an important prerequisite for the successful popularization and application of intelligent driving technology. Summary of the Invention

[0003] In view of this, the purpose of the present application is to provide a method and device for generating safety quantification targets for autonomous vehicles. By optimizing the generated safety quantification targets through an adversarial training method, the rationality of the generated results of the safety quantification targets for autonomous vehicles can be effectively improved.

[0004] The embodiment of the present application provides a method for generating safety quantification targets for autonomous vehicles. The generating method includes:

[0005] Obtain a first initial safety quantification target generated by a first target generation model when adopting a first processing mechanism for systematic analysis of faults and a second initial safety quantification target generated by a second target generation model when adopting a second processing mechanism for functional failures in the same target scenario; wherein, the first target generation model is a model for generating safety quantification targets in an autonomous driving scenario according to the initial design document of the developed autonomous driving system, and the second target generation model is a model for generating safety quantification targets in an autonomous driving scenario according to the developed autonomous driving system;

[0006] When the first initial safety quantification target and the second initial safety quantification target under the same evaluation dimension do not meet the optimization end condition of this evaluation dimension, perform adversarial training on the first target generation model and the second target generation model according to the first initial safety quantification target and the second initial safety quantification target under this evaluation dimension;

[0007] Use the adversarial-trained first target generation model to regenerate the first initial safety quantification target under this evaluation dimension, and use the adversarial-trained second target generation model to regenerate the second initial safety quantification target under this evaluation dimension;

[0008] When the regenerated first initial safety quantification target and second initial safety quantification target meet the optimization end condition of this evaluation dimension, at least one of the regenerated first initial safety quantification target and second initial safety quantification target is used to obtain the optimal safety quantification target of the target scenario under this evaluation dimension.

[0009] Optionally, the first initial safety quantification target is generated through the following steps:

[0010] Identify the scenario design elements in the initial design document of the autonomous driving system in the first target generation model;

[0011] Generate a list of elements with a compliance parameter range according to the regulatory requirements of the target area and the scenario design elements;

[0012] Determine at least one compliance score according to the driving data of the autonomous driving vehicle in the target scenario and the list of elements according to the preset score calculation rules;

[0013] When there is an abnormal score that does not meet the requirements due to a systematic analysis failure, determine the corresponding target failure type;

[0014] When the target failure type will cause a safety accident, match the corresponding first processing mechanism according to the target failure type;

[0015] Generate the corresponding first initial safety quantification target according to the first processing mechanism.

[0016] Optionally, the second initial safety quantification target is generated through the following steps:

[0017] Conduct a HARA analysis on the developed autonomous driving system used to control the movement of the autonomous driving vehicle in the target scenario;

[0018] When it is identified that the autonomous driving system has a function failure, obtain the trigger condition that causes the function failure to occur;

[0019] Determine the corresponding second processing mechanism according to the function failure and its corresponding trigger condition;

[0020] Generate the second initial safety quantification target according to the second processing mechanism.

[0021] Optionally, after obtaining the optimal safety quantification target of the target scenario under any evaluation dimension, the generation method further includes:

[0022] For any optimal safety quantization target in the target scenario, determine the test case corresponding to the optimal safety quantization target; wherein, the optimal safety quantization target is the passing condition of the test case.

[0023] Obtain the motion data generated by the autonomous driving vehicle under the test case determined by controlling through the autonomous driving system.

[0024] Determine the test result of the autonomous driving system according to the motion data.

[0025] Optionally, determine the abnormal score that does not meet the requirements due to systematic analysis failure through the following steps:

[0026] Perform weighted summation on all compliance scores to determine the comprehensive compliance score of the autonomous driving vehicle.

[0027] When the comprehensive compliance score is lower than the preset score threshold, send the relevant data corresponding to the comprehensive compliance score to the target user.

[0028] In response to the confirmation instruction of the target user, determine the abnormal score that does not meet the requirements due to systematic analysis failure.

[0029] Optionally, determine whether the first initial safety quantization target and the second initial safety quantization target in the same evaluation dimension meet the optimization end condition of the evaluation dimension through the following steps:

[0030] Determine the quantization target error in the evaluation dimension according to the first initial safety quantization target and the second initial safety quantization target in the same evaluation dimension.

[0031] When the quantization target error is within the preset error threshold range corresponding to the evaluation dimension, determine that the optimization end condition of the evaluation dimension is met; otherwise, determine that the optimization end condition of the evaluation dimension is not met.

[0032] Optionally, the matching of the corresponding first processing mechanism according to the target failure type includes:

[0033] Use the target failure type to perform mechanism lookup from the preset failure type - mechanism mapping relationship to determine the first processing mechanism corresponding to the target failure type, and perform matching processing.

[0034] An embodiment of the present application further provides a generation device for the safety quantization target of an autonomous driving vehicle, and the generation device includes:

[0035] An acquisition module, configured to acquire a first initial safety quantification target generated by a first target generation model when adopting a first processing mechanism for systematic analysis of faults, and a second initial safety quantification target generated by a second target generation model when adopting a second processing mechanism for functional failures, in the same target scenario; wherein, the first target generation model is a model for generating safety quantification targets in an autonomous driving scenario according to an initial design document of a developed autonomous driving system, and the second target generation model is a model for generating safety quantification targets in an autonomous driving scenario according to a developed autonomous driving system;

[0036] A training module, configured to, when the first initial safety quantification target and the second initial safety quantification target under the same evaluation dimension do not meet the optimization end condition of this evaluation dimension, perform adversarial training on the first target generation model and the second target generation model according to the first initial safety quantification target and the second initial safety quantification target under this evaluation dimension;

[0037] A re-generation module, configured to re-generate the first initial safety quantification target under this evaluation dimension using the first target generation model after adversarial training, and re-generate the second initial safety quantification target under this evaluation dimension using the second target generation model after adversarial training;

[0038] A determination module, configured to, when the re-generated first initial safety quantification target and the second initial safety quantification target meet the optimization end condition of this evaluation dimension, obtain the optimal safety quantification target of the target scenario under this evaluation dimension according to at least one of the re-generated first initial safety quantification target and the second initial safety quantification target.

[0039] Optionally, the generation device further includes a first generation module, and the first generation module is configured to generate the first initial safety quantification target through the following steps:

[0040] Identify the scenario design elements in the initial design document of the autonomous driving system in the first target generation model;

[0041] Generate a list of elements with a compliant parameter range according to the regulatory requirements of the target area and the scenario design elements;

[0042] Determine at least one compliance score according to the driving data of the autonomous driving vehicle in the target scenario and the list of elements, according to a preset score calculation rule;

[0043] When there is an abnormal score that does not meet the requirements due to systematic analysis of faults, determine the corresponding target fault type;

[0044] When the target fault type will cause a safety accident, match the corresponding first processing mechanism according to the target fault type;

[0045] Generate a corresponding first initial safety quantification target according to the first processing mechanism.

[0046] Optionally, the generating device further includes a second generating module, and the second generating module is configured to generate the second initial safety quantification target through the following steps:

[0047] Perform a HARA analysis on the developed autonomous driving system used to control the movement of the autonomous vehicle in the target scenario;

[0048] When it is recognized that there is a functional failure in the autonomous driving system, obtain the triggering condition that causes the occurrence of the functional failure;

[0049] Determine a corresponding second processing mechanism according to the functional failure and its corresponding triggering condition;

[0050] Generate the second initial safety quantification target according to the second processing mechanism.

[0051] Optionally, the generating device further includes a testing module, and the testing module is configured to:

[0052] After obtaining the optimal safety quantification target of the target scenario in any evaluation dimension, for any optimal safety quantification target in the target scenario, determine the test case corresponding to the optimal safety quantification target; wherein, the optimal safety quantification target is the passing condition of the test case;

[0053] Obtain the motion data generated by the autonomous vehicle under the test case determined by controlling through the autonomous driving system;

[0054] Determine the test result of the autonomous driving system according to the motion data.

[0055] Optionally, the generating device is further configured to determine an abnormal score that does not meet the requirements due to systematic analysis failures through the following steps:

[0056] Perform a weighted sum of all compliance scores to determine the comprehensive compliance score of the autonomous vehicle;

[0057] When the comprehensive compliance score is lower than the preset score threshold, send the relevant data corresponding to the comprehensive compliance score to the target user;

[0058] In response to the confirmation instruction of the target user, determine an abnormal score that does not meet the requirements due to systematic analysis failures.

[0059] Optionally, the generating device is further configured to determine whether the first initial safety quantification target and the second initial safety quantification target under the same evaluation dimension meet the optimization end condition of this evaluation dimension through the following steps:

[0060] Determine the quantification target error under this evaluation dimension according to the first initial safety quantification target and the second initial safety quantification target under the same evaluation dimension;

[0061] When the quantification target error is within the preset error threshold range corresponding to this evaluation dimension, it is determined that the optimization end condition of this evaluation dimension is met; otherwise, it is determined that the optimization end condition of this evaluation dimension is not met.

[0062] Optionally, when the first generating module is used to match the corresponding first processing mechanism according to the target fault type, the first generating module is configured to:

[0063] Use the target fault type to perform mechanism lookup from the preset fault type - mechanism mapping relationship, determine the first processing mechanism corresponding to the target fault type, and perform matching processing.

[0064] An embodiment of this application further provides an electronic device, including: a processor, a memory, and a bus. The memory stores machine-readable instructions executable by the processor. When the electronic device runs, the processor communicates with the memory through the bus. When the machine-readable instructions are executed by the processor, the steps of the generating method as described above are executed.

[0065] An embodiment of this application further provides a computer-readable storage medium. A computer program is stored on this computer-readable storage medium. When the computer program is run by a processor, the steps of the generating method as described above are executed.

[0066] A method and apparatus for generating a safety quantification target for an autonomous vehicle provided by an embodiment of the present application. The generation method includes: obtaining, in the same target scenario, a first initial safety quantification target generated by a first target generation model for a first processing mechanism adopted for systematic analysis of faults, and a second initial safety quantification target generated by a second target generation model for a second processing mechanism adopted for functional failures; wherein, the first target generation model is a model for generating a safety quantification target in an autonomous driving scenario according to an initial design document of a developed autonomous driving system, and the second target generation model is a model for generating a safety quantification target in an autonomous driving scenario according to a developed autonomous driving system; when the first initial safety quantification target and the second initial safety quantification target under the same evaluation dimension do not meet the optimization end condition of this evaluation dimension, adversarial training is performed on the first target generation model and the second target generation model according to the first initial safety quantification target and the second initial safety quantification target under this evaluation dimension; using the adversarially trained first target generation model to regenerate the first initial safety quantification target under this evaluation dimension, and using the adversarially trained second target generation model to regenerate the second initial safety quantification target under this evaluation dimension; when the regenerated first initial safety quantification target and the second initial safety quantification target meet the optimization end condition of this evaluation dimension, at least one of the regenerated first initial safety quantification target and the second initial safety quantification target is used to obtain the optimal safety quantification target of the target scenario under this evaluation dimension.

[0067] In this way, the present application generates a safety quantification target by using two models, and performs adversarial training on the two generation models according to the generation results, so that the finally generated safety quantification target is the optimal target, thereby effectively improving the rationality of the generation result of the safety quantification target of the autonomous vehicle, and further better assisting the autonomous vehicle in autonomous driving.

[0068] In order to make the above objects, features, and advantages of the present application more obvious and understandable, the following specifically gives preferred embodiments and, in conjunction with the accompanying drawings, detailed descriptions are as follows. Description of the Drawings

[0069] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings required for the embodiments. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.

[0070] Figure 1 It is a flowchart of a method for generating a safety quantification target for an autonomous vehicle provided by an embodiment of the present application;

[0071] Figure 2 One of the schematic structural diagrams of a device for generating safety quantification targets for autonomous vehicles provided by an embodiment of the present application;

[0072] Figure 3 Another schematic structural diagram of a device for generating safety quantification targets for autonomous vehicles provided by an embodiment of the present application;

[0073] Figure 4 Schematic structural diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners

[0074] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, rather than all the embodiments. Components of the embodiments of the present application usually described and illustrated herein can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the present application that is required to be protected, but merely represents selected embodiments of the present application. Based on the embodiments of the present application, every other embodiment obtained by those skilled in the art without creative efforts belongs to the scope of protection of the present application.

[0075] As the future development direction of the automotive industry, intelligent driving is gradually moving from concept to reality. With the continuous evolution of autonomous driving technology, expected functional safety has become a key factor in ensuring the reliable operation of intelligent driving systems. Moreover, during the driving process of autonomous vehicles, they need to make safety-critical decisions independently and estimate the impact of their behaviors on the surrounding traffic, so as to balance the safety of individuals and groups. By quantifying safety indicators, it is possible to guide autonomous vehicles to make correct decisions during operation, improving road safety and traffic flow. Therefore, formulating reasonable expected functional safety goals is not only related to the safety of users' lives, but also an important prerequisite for the successful popularization and application of intelligent driving technology.

[0076] Based on this, the embodiments of the present application provide a method and device for generating safety quantification targets for autonomous vehicles. By optimizing the generated safety quantification targets through an adversarial training method, the rationality of the generation results of the safety quantification targets for autonomous vehicles can be effectively improved.

[0077] Please refer to Figure 1 , Figure 1 which is a flowchart of a method for generating safety quantification targets for autonomous vehicles provided by an embodiment of the present application. As shown in Figure 1 , the generation method provided by the embodiments of the present application includes:

[0078] S101. Obtain a first initial safety quantification target generated by a first target generation model when adopting a first processing mechanism for systematic analysis of faults and a second initial safety quantification target generated by a second target generation model when adopting a second processing mechanism for functional failures in the same target scenario.

[0079] S102. When the first initial safety quantification target and the second initial safety quantification target under the same evaluation dimension do not meet the optimization end condition of this evaluation dimension, perform adversarial training on the first target generation model and the second target generation model according to the first initial safety quantification target and the second initial safety quantification target under this evaluation dimension.

[0080] S103. Use the adversarially trained first target generation model to regenerate the first initial safety quantification target under this evaluation dimension, and use the adversarially trained second target generation model to regenerate the second initial safety quantification target under this evaluation dimension;

[0081] S104. When the regenerated first initial safety quantification target and second initial safety quantification target meet the optimization end condition of this evaluation dimension, obtain the optimal safety quantification target of the target scenario under this evaluation dimension according to at least one of the regenerated first initial safety quantification target and second initial safety quantification target.

[0082] The following is an explanation of the exemplary steps of the embodiments of the present application:

[0083] Regarding step S101, the first target generation model is a model that generates safety quantification targets in an autonomous driving scenario according to the initial design document of the developed autonomous driving system, and the second target generation model is a model that generates safety quantification targets in an autonomous driving scenario according to the developed autonomous driving system.

[0084] In this step, for any target scenario, obtain at least one first initial safety quantification target generated by the first target generation model and at least one second initial safety quantification target generated by the second target generation model in this target scenario.

[0085] Here, the first initial safety quantification target is a quantification target determined according to the first processing mechanism adopted when the first target generation model discovers a systematic analysis fault and adopts the first processing mechanism to process the systematic analysis fault when the autonomous driving vehicle moves or simulates in this target scenario.

[0086] The second initial safety quantification target is the quantification target determined according to the second processing mechanism adopted when the second target generation model discovers a functional failure during the movement or simulation of the autonomous vehicle in the target scenario and processes the functional failure using the second processing mechanism.

[0087] Among them, the target scenario is pre-determined, and specifically may include road feature data, environmental feature data, self-vehicle feature data, other reference object data, etc. And each type of data can be further divided into other data with multiple levels of tags. For example, please refer to Table 1, which is a reference table of scenario data information provided in this application.

[0088] Table 1:

[0089]

[0090] In an implementation manner provided in this application, the first initial safety quantification target is generated through the following steps:

[0091] S11. Identify the scenario design elements in the initial design document of the autonomous driving system in the first target generation model.

[0092] S12. Generate a list of elements with a compliant parameter range according to the regulatory requirements of the target area and the scenario design elements.

[0093] S13. Determine at least one compliance score according to the driving data of the autonomous vehicle in the target scenario and the list of elements according to the preset score calculation rules.

[0094] S14. When there is an abnormal score that does not meet the requirements due to a systematic analysis failure, determine the corresponding target failure type.

[0095] S15. When the target failure type may cause a safety accident, match the corresponding first processing mechanism according to the target failure type.

[0096] S16. Generate the corresponding first initial safety quantification target according to the first processing mechanism.

[0097] Regarding step S11, this step specifically includes: obtaining the initial design document of the developed autonomous driving system, performing format conversion processing on the initial design document to become machine language; then identifying the scenario design elements in the initial design document converted into machine language to determine at least one scenario design element.

[0098] Here, generally, multiple scenario design elements can be determined. For example, the scenario design elements may include the geographical location where the autonomous vehicle operates, road type, traffic conditions, environmental conditions, time range, speed range, infrastructure status, operation restrictions, etc.

[0099] For step S12, this step may specifically include: in response to a selection instruction for the target area, obtaining the laws, regulations, and safety requirements related to traffic in the target area; then, according to the obtained laws, regulations, and safety requirements, extracting data according to the scenario design elements to obtain a list of elements with a compliant parameter range.

[0100] For example, when the laws and regulations in the target area stipulate that on a highway, the maximum speed of a vehicle cannot exceed 120 km / h, then the road type in the determined list of elements is a highway and the speed range is below 120 km / h.

[0101] For step S13, the driving data of the autonomous vehicle in the target scenario may specifically be: the data generated by the actual driving of the autonomous vehicle in the target scenario, or the data generated by simulating the driving of the autonomous vehicle in the target scenario.

[0102] Here, each compliance score may correspond to a score calculation rule. For example, the compliance scores may include: speed compliance score, time compliance score, weather compliance score, etc.

[0103] The score calculation rule may specifically include:

[0104] Degree of compliance score = (number of compliant regulations / total number of relevant regulations) * 100%;

[0105] Speed compliance score = (duration of the compliant speed interval / total operation duration) * 100%;

[0106] Time compliance score = (number of times the time is within the compliant range / total number of monitoring times) * 100%;

[0107] Weather compliance score = (number of times the weather is within the compliant range / total number of monitoring times) * 100%;

[0108] In addition, multi-level evaluation indicators may also be used in the score calculation rule, and the number of each evaluation indicator may be multiple. For example, the evaluation indicators used for speed compliance scoring may be divided into 4 first-level indicators, 35 second-level indicators, and 140 third-level indicators, and can also be further split into 4th level or more. All indicators are weighted and averaged.

[0109] Suppose we need to calculate the compliance score of the speed of an autonomous vehicle. We can use the following formula:

[0110] Compliance Speed Interval Score (CVS) = (T_compliant / T_total) * 100%

[0111] Where: T_compliant is the total time that the autonomous vehicle travels within the compliance speed interval. T_total is the total time that the autonomous vehicle travels.

[0112] If laws and regulations stipulate that on a highway in a certain country, the maximum speed of a vehicle cannot exceed 120 km / h, we can further refine the calculation:

[0113] CVS = (T_compliant_120 / T_total) * 100%

[0114] Here, T_compliant_120 is the time that the autonomous vehicle travels within the interval where the speed does not exceed 120 km / h.

[0115] Composite Compliance Score (CCS) = Σ(Wi * Si) / ΣWi

[0116] Where: Wi is the weight of the i-th indicator, indicating the importance of this indicator among all indicators. Si is the specific score of the i-th indicator. Σ represents the summation symbol, summing over all indicators.

[0117] Regarding step S14, in an implementation manner provided by the present application, the following steps are used to determine the abnormal scores that do not meet the requirements due to systematic analysis failures:

[0118] S21. Perform a weighted sum of all compliance scores to determine the composite compliance score of the autonomous vehicle.

[0119] S22. When the composite compliance score is lower than the preset score threshold, send the relevant data corresponding to the composite compliance score to the target user.

[0120] S23. In response to the confirmation instruction of the target user, determine the abnormal scores that do not meet the requirements due to systematic analysis failures.

[0121] Regarding step S21, this step includes obtaining all compliance scores and their respective weight coefficients, and then performing a weighted calculation using their respective weight coefficients and all compliance scores to obtain the composite compliance score of the autonomous vehicle.

[0122] Regarding step S22, the preset score threshold is a pre-determined value, and the preset score thresholds for different scenarios and different autonomous vehicles may be different.

[0123] The target user is a user with relevant professional knowledge.

[0124] Regarding step S23, the confirmation instruction is an instruction for the target user to confirm the existence of a systematic analysis failure.

[0125] Continuing with step S14, the determination of the corresponding target failure type specifically includes: the first target generation model performs a failure mode analysis to determine the target failure type.

[0126] Exemplarily, the target failure type may include: systematic failure, random hardware failure, insufficient function, and improper operation.

[0127] Regarding step S15, the corresponding relationship between the failure type and whether a safety accident is caused is determined in advance.

[0128] In an implementation manner provided by the present application, the matching of the corresponding first processing mechanism according to the target failure type includes: using the target failure type to perform a mechanism search from a preset failure type - mechanism mapping relationship, determining the first processing mechanism corresponding to the target failure type, and performing a matching process.

[0129] Regarding step S16, this step specifically may include: extracting quantization indexes for the first processing mechanism, and generating a corresponding first initial safety quantization target according to the extracted quantization indexes.

[0130] Continuing with step S101, in an implementation manner provided by the present application, the second initial safety quantization target is generated through the following steps:

[0131] S31. Perform a HARA analysis on the developed autonomous driving system used to control the target autonomous vehicle to move in the target scenario.

[0132] S32. When it is recognized that there is a functional failure in the autonomous driving system, obtain the triggering condition that causes the occurrence of this functional failure.

[0133] S33. Determine a corresponding second processing mechanism according to the functional failure and its corresponding triggering condition.

[0134] S34. Generate the second initial safety quantization target according to the second processing mechanism.

[0135] Regarding step S31, the HARA analysis is a hazard analysis and risk assessment analysis. This step is to identify potential hazards and risks in the system, evaluate their impact on system safety, and provide a basis for formulating subsequent processing mechanisms.

[0136] For step S33, the second processing mechanism may include optimization algorithms, enhancing data processing capabilities, introducing new security technologies, etc.

[0137] For step S34, this step may specifically include: processing the autonomous driving system according to the second processing mechanism, and obtaining a second initial safety quantification target based on the processed autonomous driving system.

[0138] For step S102, in an implementation provided by the present application, it is determined whether the first initial safety quantification target and the second initial safety quantification target under the same evaluation dimension meet the optimization end condition of this evaluation dimension through the following steps: determining the quantification target error under this evaluation dimension according to the first initial safety quantification target and the second initial safety quantification target under the same evaluation dimension; when the quantification target error is within the preset error threshold range corresponding to this evaluation dimension, it is determined that the optimization end condition of this evaluation dimension is met, otherwise, it is determined that the optimization end condition of this evaluation dimension is not met.

[0139] Continuing with step S102, the adversarial training process of the two models is described through the following example:

[0140] Suppose the first initial safety quantification target generated by the first target generation model is S1, and the second initial safety quantification target generated by the second target generation model is S2.

[0141] The goal of adversarial training is to find an optimal safety quantification target S, which can be achieved by minimizing the difference between the outputs of the two models. The objective function can be expressed as:

[0142] L(S) = α·L1(S, S1) + β·L2(S, S2)

[0143] where L is the total loss, L1 and L2 are the loss functions of the first target generation model and the second target generation model respectively, and α and β are weight coefficients.

[0144] The loss function is a measure of the difference between the outputs of the two models.

[0145]

[0146]

[0147] S i is the i-th element of the optimal safety quantification target, S 1i and S 2i are the i-th elements output by the first target generation model and the second target generation model respectively, and n is the total number of elements.

[0148] Use principal security parameter analysis for dimensionality reduction and extraction of key security indicators.

[0149]

[0150] η is the learning rate, is the dimension of the loss function L with respect to S.

[0151] During the adversarial training process, mainly adjust the weight coefficients α and β to balance the influence of the two models, and supplement the learning rate through expert experience and previous engineering experience. In this way, the adversarial training of the two models is completed.

[0152] For step S103, this step may specifically include using the first target generation model after adversarial training to regenerate the first initial safety quantization target corresponding to this evaluation dimension in the target scenario, and using the second target generation model after adversarial training to regenerate the second initial safety quantization target corresponding to this evaluation dimension in the target scenario.

[0153] For step S104, in this step, the judgment condition for the optimization end condition is the same as that in step S102, which will not be elaborated here.

[0154] Here, any target scenario can determine at least one optimal safety quantization target.

[0155] Among them, when obtaining the optimal safety quantization target of the target scenario in this evaluation dimension according to at least one of the regenerated first initial safety quantization target and the second initial safety quantization target, specifically, it may be: determining the first initial safety quantization target as the optimal safety quantization target of the target scenario in this evaluation dimension, or determining the second initial safety quantization target as the optimal safety quantization target of the target scenario in this evaluation dimension, or determining the mean value of the first initial safety quantization target and the second initial safety quantization target as the optimal safety quantization target of the target scenario in this evaluation dimension. Which specific method to adopt can be adaptively selected according to the actual application scenario.

[0156] In addition, in another implementation manner provided in the present application, after obtaining the optimal safety quantization target of the target scenario in any evaluation dimension, the generation method further includes: for any optimal safety quantization target in the target scenario, determining the test case corresponding to this optimal safety quantization target; obtaining the motion data generated by the autonomous driving vehicle under this test case determined by controlling through the autonomous driving system; determining the test result of the autonomous driving system according to the motion data.

[0157] In this example, this optimal safety quantization target is the passing condition of this test case.

[0158] Determining the test result of the autonomous driving system according to the motion data includes: when the motion data meets the optimal safety quantification target, it represents that the test passes; otherwise, it is determined that the test fails.

[0159] In this way, the present application generates safety quantification targets by using two models, and performs adversarial training on the two generation models according to the generation results, so that the finally generated safety quantification target is the optimal target, thereby effectively improving the rationality of the safety quantification target generation result of the autonomous driving vehicle, and further better assisting the autonomous driving vehicle to perform autonomous driving.

[0160] Based on the same inventive concept, an embodiment of the present application also provides a generation device corresponding to the generation method. Since the principle of solving problems by the device in the embodiment of the present application is similar to the above-mentioned generation method in the embodiment of the present application, the implementation of the device can refer to the implementation of the method, and the repeated parts will not be described again.

[0161] Please refer to Figure 2 、 Figure 3 , Figure 2 which is one of the structural schematic diagrams of a generation device for safety quantification targets of an autonomous driving vehicle provided by an embodiment of the present application. Figure 3 which is the second structural schematic diagram of a generation device for safety quantification targets of an autonomous driving vehicle provided by an embodiment of the present application. As Figure 2 shown in

[0162] An acquisition module 210, configured to acquire, in the same target scenario, a first initial safety quantification target generated by a first target generation model when adopting a first processing mechanism for systematic analysis of faults, and a second initial safety quantification target generated by a second target generation model when adopting a second processing mechanism for functional failures; wherein, the first target generation model is a model for generating safety quantification targets in an autonomous driving scenario according to the initial design document of the developed autonomous driving system, and the second target generation model is a model for generating safety quantification targets in an autonomous driving scenario according to the developed autonomous driving system;

[0163] A training module 220, configured to perform adversarial training on the first target generation model and the second target generation model according to the first initial safety quantification target and the second initial safety quantification target in the same evaluation dimension when the first initial safety quantification target and the second initial safety quantification target in the same evaluation dimension do not meet the optimization end condition of the evaluation dimension;

[0164] A regeneration module 230, configured to regenerate the first initial safety quantization target in this evaluation dimension by using the first target generation model after adversarial training, and regenerate the second initial safety quantization target in this evaluation dimension by using the second target generation model after adversarial training;

[0165] A determination module 240, configured to, when the regenerated first initial safety quantization target and the second initial safety quantization target meet the optimization end condition of this evaluation dimension, obtain the optimal safety quantization target of the target scenario in this evaluation dimension according to at least one of the regenerated first initial safety quantization target and the second initial safety quantization target.

[0166] Optionally, as Figure 3 shown, the generating device 200 further includes a first generating module 250, and the first generating module 250 is configured to generate the first initial safety quantization target through the following steps:

[0167] Identify the scenario design elements in the initial design document of the autonomous driving system in the first target generation model;

[0168] Generate a list of elements with a compliance parameter range according to the regulatory requirements of the target area and the scenario design elements;

[0169] Determine at least one compliance score according to the driving data of the autonomous driving vehicle in the target scenario and the list of elements according to a preset score calculation rule;

[0170] When there is an abnormal score that does not meet the requirements due to a systematic analysis failure, determine the corresponding target failure type;

[0171] When the target failure type may cause a safety accident, match the corresponding first processing mechanism according to the target failure type;

[0172] Generate the corresponding first initial safety quantization target according to the first processing mechanism.

[0173] Optionally, the generating device 200 further includes a second generating module 260, and the second generating module 260 is configured to generate the second initial safety quantization target through the following steps:

[0174] Perform a HARA analysis on the developed autonomous driving system used to control the movement of the autonomous driving vehicle in the target scenario;

[0175] When it is identified that the autonomous driving system has a function failure, obtain the trigger condition that causes the function failure to occur;

[0176] Determine the corresponding second processing mechanism according to the function failure and its corresponding trigger condition;

[0177] Generate the second initial safety quantization target according to the second processing mechanism.

[0178] Optionally, the generating device 200 further includes a testing module 270, and the testing module 270 is configured to:

[0179] After obtaining the optimal safety quantization target of the target scenario under any evaluation dimension, for any optimal safety quantization target under the target scenario, determine the test case corresponding to this optimal safety quantization target; wherein, this optimal safety quantization target is the passing condition of this test case;

[0180] Obtain the motion data generated by the autonomous vehicle under the test case determined by controlling through the autonomous driving system;

[0181] Determine the test result of the autonomous driving system according to the motion data.

[0182] Optionally, the generating device 200 is further configured to determine the abnormal scores that do not meet the requirements due to systematic analysis failures through the following steps:

[0183] Perform a weighted sum of all compliance scores to determine the comprehensive compliance score of the autonomous vehicle;

[0184] When the comprehensive compliance score is lower than the preset score threshold, send the relevant data corresponding to the comprehensive compliance score to the target user;

[0185] In response to the confirmation instruction of the target user, determine the abnormal scores that do not meet the requirements due to systematic analysis failures.

[0186] Optionally, the generating device 200 is further configured to determine whether the first initial safety quantization target and the second initial safety quantization target under the same evaluation dimension meet the optimization end condition of this evaluation dimension through the following steps:

[0187] Determine the quantization target error under this evaluation dimension according to the first initial safety quantization target and the second initial safety quantization target under the same evaluation dimension;

[0188] When the quantization target error is within the preset error threshold range corresponding to this evaluation dimension, determine that the optimization end condition of this evaluation dimension is met, otherwise, determine that the optimization end condition of this evaluation dimension is not met.

[0189] Optionally, when the first generating module 250 is used to match the corresponding first processing mechanism according to the target failure type, the first generating module 250 is configured to:

[0190] Use the target fault type to look up the mechanism from the preset fault type - mechanism mapping relationship, determine the first processing mechanism corresponding to the target fault type, and perform matching processing.

[0191] Please refer to Figure 4 , Figure 4 which is a schematic structural diagram of an electronic device provided by an embodiment of the present application. As Figure 4 shown in, the electronic device 400 includes a processor 410, a memory 420, and a bus 430.

[0192] The memory 420 stores machine-readable instructions executable by the processor 410. When the electronic device 400 runs, the processor 410 communicates with the memory 420 through the bus 430. When the machine-readable instructions are executed by the processor 410, the steps of the generation method in the method embodiment as described above can be executed. The specific implementation manner can refer to the method embodiment and will not be elaborated here. Figure 1 shown, and will not be elaborated here.

[0193] An embodiment of the present application further provides a computer-readable storage medium. A computer program is stored on the computer-readable storage medium. When the computer program is run by a processor, the steps of the generation method in the method embodiment as described above can be executed. The specific implementation manner can refer to the method embodiment and will not be elaborated here. Figure 1 shown, and will not be elaborated here.

[0194] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated here.

[0195] In several embodiments provided by the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. The device embodiments described above are only illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For another example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the couplings, direct couplings, or communication connections shown or discussed with each other can be through some communication interfaces. The indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.

[0196] The units described as separate components may or may not be physically separated. The components shown as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0197] In addition, in each embodiment of the present application, each functional unit can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit.

[0198] If the above-mentioned function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a non-volatile computer-readable storage medium executable by a processor. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs.

[0199] Finally, it should be noted that the above-described embodiments are only specific implementation manners of the present application, used to illustrate the technical solutions of the present application, rather than limiting them. The protection scope of the present application is not limited thereto. Although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: any person skilled in the art within the technical scope disclosed in the present application can still modify the technical solutions described in the foregoing embodiments, or can easily think of changes, or perform equivalent replacements on some of the technical features; and these modifications, changes, or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method for generating a safety quantitative target for an autonomous driving vehicle, characterized in that: The generation method comprises: Obtaining, in the same target scenario, a first initial safety quantitative target generated by a first target generation model for a first processing mechanism adopted for a systematic analysis of a fault, and a second initial safety quantitative target generated by a second target generation model for a second processing mechanism adopted for a functional failure; wherein the first target generation model is a model for generating safety quantitative targets in an autonomous driving scenario based on an initial design document of a developed autonomous driving system, and the second target generation model is a model for generating safety quantitative targets in an autonomous driving scenario based on a developed autonomous driving system; When the first initial safety quantization target and the second initial safety quantization target under the same evaluation dimension do not meet the optimization end condition of the evaluation dimension, performing adversarial training on the first target generation model and the second target generation model according to the first initial safety quantization target and the second initial safety quantization target under the evaluation dimension; Regenerate a first initial safety quantization target under the evaluation dimension using the first target generation model after adversarial training, and regenerate a second initial safety quantization target under the evaluation dimension using the second target generation model after adversarial training; When the regenerated first initial safety quantification target and the second initial safety quantification target meet the optimization end condition of the evaluation dimension, the optimal safety quantification target of the target scenario under the evaluation dimension is obtained according to at least one of the regenerated first initial safety quantification target and the second initial safety quantification target.

2. The generation method according to claim 1, characterized in that: The first initial safety quantitative target is generated by the following steps: Identifying scenario design elements in an initial design document for an autonomous driving system in a first objective generation model; Generate a list of elements with compliance parameter ranges based on the regulatory requirements of the target area and the scenario design elements described; Determine at least one compliance score according to a preset score calculation rule based on the driving data of the autonomous driving vehicle in the target scenario and the list of elements; When there is an abnormal score that does not meet the requirements due to a systematic analysis failure, determine the corresponding target failure type; When the target fault type may cause a safety accident, matching a corresponding first processing mechanism according to the target fault type; According to the first processing mechanism, a corresponding first initial safety quantification target is generated.

3. The generation method according to claim 1, characterized in that: The second initial safety quantitative target is generated by the following steps: Conduct HARA analysis on the developed autonomous driving system used to control the movement of the autonomous vehicle in the target scenario; When a functional failure of the autonomous driving system is identified, obtaining a trigger condition causing the functional failure to occur; Determine a corresponding second processing mechanism according to the functional failure situation and its corresponding trigger condition; The second initial safety quantitative target is generated according to the second processing mechanism.

4. The generation method according to claim 1, characterized in that: After obtaining the optimal safety quantification target of the target scenario under any evaluation dimension, the generation method further includes: For any optimal safety quantification target under the target scenario, determine a test case corresponding to the optimal safety quantification target; wherein the optimal safety quantification target is a passing condition for the test case; Acquiring motion data generated by the autonomous driving vehicle determined by control of the autonomous driving system under the test case; A test result of the autonomous driving system is determined based on the motion data.

5. The generation method according to claim 2, characterized in that: Use the following steps to determine if there are undesirable anomaly scores due to systematic analysis failures: Taking a weighted sum of all compliance scores to determine a comprehensive compliance score of the autonomous driving vehicle; When the comprehensive compliance score is lower than a preset score threshold, relevant data corresponding to the comprehensive compliance score is sent to the target user; In response to a confirmation instruction from the target user, it is determined that there is an abnormal score that does not meet the requirements due to a systematic analysis failure.

6. The generation method according to claim 2, characterized in that: Determine whether the first initial safety quantitative target and the second initial safety quantitative target under the same evaluation dimension meet the optimization end condition of the evaluation dimension by the following steps: Determine a quantitative target error under the same evaluation dimension according to a first initial safety quantitative target and a second initial safety quantitative target under the same evaluation dimension; When the quantized target error is within the preset error threshold range corresponding to the evaluation dimension, it is determined that the optimization end condition of the evaluation dimension is met; otherwise, it is determined that the optimization end condition of the evaluation dimension is not met.

7. The generation method according to claim 2, characterized in that: The matching of the first processing mechanism corresponding to the target fault type includes: The target fault type is used to perform a mechanism search from a preset fault type-mechanism mapping relationship, determine a first processing mechanism corresponding to the target fault type, and perform matching processing.

8. A device for generating a safety quantitative target for an autonomous driving vehicle, characterized in that: The generating device comprises: An acquisition module, used to acquire, under the same target scenario, a first initial safety quantitative target generated by a first target generation model when a first processing mechanism is adopted for a systematic analysis of a fault, and a second initial safety quantitative target generated by a second target generation model when a second processing mechanism is adopted for a functional failure; wherein the first target generation model is a model for generating safety quantitative targets in an autonomous driving scenario based on an initial design document of a developed autonomous driving system, and the second target generation model is a model for generating safety quantitative targets in an autonomous driving scenario based on a developed autonomous driving system; a training module, configured to perform adversarial training on the first target generation model and the second target generation model according to the first initial safety quantification target and the second initial safety quantification target under the same evaluation dimension when the first initial safety quantification target and the second initial safety quantification target under the same evaluation dimension do not meet the optimization end condition of the evaluation dimension; A regeneration module, used to regenerate a first initial safety quantization target under the evaluation dimension using the first target generation model after adversarial training, and to regenerate a second initial safety quantization target under the evaluation dimension using the second target generation model after adversarial training; A determination module is used to obtain the optimal safety quantitative target of the target scenario under the evaluation dimension according to at least one of the regenerated first initial safety quantification target and the second initial safety quantification target when the regenerated first initial safety quantification target and the second initial safety quantification target meet the optimization end condition of the evaluation dimension.

9. An electronic device, characterized in that: include: A processor, a memory and a bus, wherein the memory stores machine-readable instructions executable by the processor, and when the electronic device is running, the processor and the memory communicate through the bus, and the machine-readable instructions are executed by the processor to execute the steps of the generation method as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the generation method according to any one of claims 1 to 7 are executed.