Health and error monitoring for sensor fusion systems

By introducing a central monitoring and error checking system in the sensor fusion system and aggregating the monitoring and error checking results of the sensor fusion system, the problem of false positive detection in the sensor fusion system is solved, and more accurate and efficient health assessment and error reporting are achieved.

CN120609397APending Publication Date: 2025-09-09NVIDIA CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510257682.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-03-08
Filing Date
2025-03-05
Publication Date
2025-09-09

AI Technical Summary

Technical Problem

Existing sensor fusion systems are prone to high-confidence false positive detections when assessing their health and reporting errors, making the systems less suitable for accurate and efficient deployment.

Method used

A central monitoring and error checking system is introduced into the sensor fusion system to generate an overall state output error signal of the system by aggregating the monitoring and error checking results in the sensor fusion system.

Benefits of technology

Improves the accuracy of detecting system errors and allows for more efficient generation of health reports, meeting functional safety requirements and ensuring that the system can accurately report errors when critical errors occur.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120609397A_ABST
    Figure CN120609397A_ABST
Patent Text Reader

Abstract

The invention discloses health and error monitoring for a sensor fusion system. In various examples, systems and methods related to health and error monitoring of sensor fusion systems are disclosed. Systems and methods for aggregating the results of monitoring and error checks in a sensor fusion system in a single checkpoint are disclosed. The processor may include one or more circuits. The one or more circuits may receive perceptual data from one or more first sensors of the machine. The one or more circuits may receive location data from one or more second sensors of the machine. The one or more circuits may generate output data by performing a fusion of at least the perceptual data and the location data. The one or more circuits may evaluate a plurality of criteria based on at least a subset of the perception data, the location data, and the output data. The one or more circuits may output an error signal according to the evaluation.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0001] Given input data from multiple sensor modalities (e.g., RADAR, camera, LiDAR, and ultrasonic), a sensor fusion system can provide an environmental description of the vehicle or machine's surroundings regarding dynamic objects (e.g., pedestrians, vehicles, machines, robots, animals, etc.) and static objects (e.g., obstacles, traffic objects, warehouse objects, road boundaries, buildings, hazards, etc.). In order for a fusion system to be considered safe, it can be compared to various functional safety requirements. An example of a functional safety requirement is to avoid reporting false positive objects with high confidence (e.g., not outputting a high confidence that an object exists when there is no actual object at the reported location). In addition, in order to provide safe and reliable output to another function or component (e.g., a consumer or downstream function or component of an autonomous or semi-autonomous machine), it is important that the fusion system can assess its health and report errors in an accurate and efficient manner. However, conventional methods for monitoring sensor fusion systems can be prone to high-confidence false positive object detections, making these systems less suitable for accurate and efficient deployment. Summary of the Invention

[0002] Embodiments of the present disclosure relate to health and error monitoring of sensor fusion systems for autonomous or semi-autonomous systems and applications. For example, systems and methods are disclosed that aggregate the results of monitoring and error checking in a sensor fusion system into a single checkpoint.

[0003] Compared to conventional systems that perform health monitoring and error checking in a discrete manner at various checkpoints in a sensor fusion system, the systems and methods according to the present disclosure perform health monitoring and error checking at a central location. As a result, the health and error checkers of current sensor fusion systems are able to perform assessments with a more comprehensive understanding of the system. The systems and methods according to the present disclosure can aggregate the results of monitoring and error checking in a sensor fusion system in a single checkpoint to output an error signal based on the aggregated overall state of the system. In this way, the system can also assess its health and report errors (for example, if a functionally critical error occurs) in an accurate and efficient manner.

[0004] At least one aspect relates to a processor. In various embodiments, the processor may include or may be one or more circuits. In various embodiments, the one or more circuits may receive sensory data from one or more first sensors of the vehicle. In various embodiments, the one or more circuits may receive positional data from one or more second sensors of the vehicle. In various embodiments, the one or more circuits may generate output data by performing a fusion of at least the sensory data and the positional data. In various embodiments, the one or more circuits may evaluate multiple criteria based on at least a subset of the sensory data, the positional data, and the output data. In various embodiments, the one or more circuits may output an error signal based on the evaluation.

[0005] In various embodiments, one or more circuits may receive the sensed data that has been monitored for a first time period. In various embodiments, one or more circuits may receive the location data that has been monitored for a second time period that is shorter than the first time period. In various embodiments, the time period during which the location data may be monitored is shorter than the time period during which the sensed data is monitored.

[0006] In various embodiments, the one or more first sensors may include or may be at least one of: a RADAR sensor, a light detection and ranging (LiDAR) sensor, an ultrasonic sensor, a stereo camera, a wide-angle camera, an infrared camera, a surround camera, a long-range camera, or a mid-range camera.

[0007] In various embodiments, the one or more circuits may detect the first object from the sensed data. The plurality of criteria corresponding to the sensed data may include or may be at least one of the following: validity of the sensed data, whether the sensed data is missing, whether the sensed data is stale, validity of a timestamp, latency of a timestamp, a position of the first object within a predetermined position range, a speed of the first object within a predetermined speed range, an acceleration of the first object within a predetermined acceleration range, a vertical position of the first object relative to the ground, a size of the first object, or a category of the first object.

[0008] In various embodiments, the one or more second sensors may include or may be at least one of: a global navigation satellite system (GNSS) sensor, or a global positioning system (GPS) sensor, an inertial measurement unit (IMU) sensor, an accelerometer, a gyroscope, a magnetic compass, a magnetometer, a microphone, a speed sensor, a vibration sensor, a steering sensor, or a brake sensor.

[0009] In various embodiments, the multiple criteria based on the location data may include or may be at least one of: validity of the data, whether the data is missing, whether the data is outdated, the speed of the vehicle is within a predetermined speed range, or the acceleration of the vehicle is within a predetermined acceleration range.

[0010] In various embodiments, the one or more circuits may detect the second object from the output data. In various embodiments, the plurality of criteria based on the output data may include or may be at least one of: whether the system time increases between fusion cycles, whether the time difference between the input modality data is greater than a threshold, whether the predicted time is greater than a threshold, whether the difference between the positions of the second objects is greater than a threshold, whether the difference between the velocities of the second objects is greater than a threshold, or whether the difference between the accelerations of the second objects is greater than a threshold.

[0011] In various embodiments, in response to the error signal, one or more circuits may perform at least one of the following operations: adjust the confidence level of the fused result, set validity information of the fused result, degrade one or more functions of the system performing the fusion, or send one or more health messages to a health server for debugging purposes.

[0012] In various embodiments, when generating output data, the one or more circuits may detect one or more fused objects by performing a fusion of at least one or more first objects with one or more second objects during a plurality of execution cycles, the one or more first objects being detected based at least on perception data from one or more first sensors of the vehicle, and the one or more second objects being detected based at least on data from one or more third sensors of the vehicle. In various embodiments, the one or more circuits may determine that the one or more first objects are invalid during the plurality of execution cycles. In various embodiments, the one or more circuits may determine a first number of cycles in which the one or more first objects are determined to be invalid. In various embodiments, the one or more circuits may determine that the one or more fused objects are invalid in response to determining that the first number of cycles is equal to a first threshold.

[0013] In various embodiments, the one or more circuits may determine that the one or more second objects are invalid during a plurality of execution cycles. In various embodiments, the one or more circuits may determine a second number of cycles during which the one or more second objects are determined to be invalid. In various embodiments, in response to determining that the second number of cycles is equal to a second threshold, the one or more circuits may determine that the one or more fused objects are invalid.

[0014] In various embodiments, one or more circuits may determine whether one or more errors occurred during a plurality of execution cycles. In various embodiments, in response to determining that one or more errors occurred during the plurality of execution cycles, the one or more circuits may determine that one or more fused objects are invalid. The one or more errors may be related to at least one of vehicle safety or execution fused functionality.

[0015] At least one aspect relates to a system that, in various embodiments, may include one or more processing units and one or more memory units. In various embodiments, the one or more memory units may store instructions that, when executed by the one or more processing units, cause the one or more processing units to perform operations comprising: receiving perception data from one or more first sensors of a vehicle. In various embodiments, the one or more processing units may receive position data from one or more second sensors of the vehicle. In various embodiments, the one or more processing units may generate output data by performing a fusion of at least the perception data and the position data. In various embodiments, the one or more processing units may evaluate multiple criteria based on at least a subset of the perception data, the position data, and the output data. In various embodiments, the one or more processing units may output an error signal based on the evaluation.

[0016] In various embodiments, one or more processing units may receive sensory data that has been monitored for a first time period. In various embodiments, one or more processing units may receive location data that has been monitored for a second time period that is shorter than the first time period. In various embodiments, the time period during which the location data may be monitored is shorter than the time period during which the sensory data is monitored.

[0017] In various embodiments, the one or more processing units may detect the first object from the perception data. In various embodiments, the plurality of criteria corresponding to the perception data may include or may be at least one of the following: validity of the perception data, whether data is missing from the perception data, whether the perception data is outdated, validity of a timestamp, latency of a timestamp, a position of the first object within a predetermined position range, a speed of the first object within a predetermined speed range, an acceleration of the first object within a predetermined acceleration range, a vertical position of the first object relative to the ground, a size of the first object, or a category of the first object.

[0018] In various embodiments, the multiple criteria based on the location data may include or may be at least one of: validity of the data, whether the data is missing, whether the data is outdated, the speed of the vehicle is within a predetermined speed range, or the acceleration of the vehicle is within a predetermined acceleration range.

[0019] In various embodiments, in response to the error signal, one or more processing units may perform at least one of the following operations: adjust the confidence level of the fused result, set validity information of the fused result, downgrade one or more functions of the system performing the fusion, or send one or more health messages to a health server for debugging purposes.

[0020] At least one aspect relates to a method. In various embodiments, the method may include receiving perception data from one or more first sensors of a vehicle. In various embodiments, the method may include receiving position data from one or more second sensors of the vehicle. In various embodiments, the method may include generating output data by performing a fusion of at least the perception data and the position data. In various embodiments, the method may include evaluating a plurality of criteria based on at least a subset of the perception data, the position data, and the output data. In various embodiments, the method may include outputting an error signal based on the evaluation.

[0021] In various embodiments, the method may include, in response to the error signal, performing at least one of the following operations: adjusting a confidence level of the fused result, setting validity information of the fused result, downgrading one or more functions of the system performing the fusion, or sending one or more health messages to a health server for debugging purposes.

[0022] In various embodiments, the processors, systems and / or methods described herein may be implemented by or may be included in at least one of: a control system for an autonomous or semi-autonomous machine; a perception system for an autonomous or semi-autonomous machine; a system for performing simulation operations; a system for performing digital twin operations; a system for performing light transport simulations; a system for performing collaborative content creation of 3D assets; a system for performing deep learning operations; a system implemented using an edge device; a system for generating or presenting at least one of virtual reality, augmented reality, or mixed reality content; a system implemented using a robot; a system for performing conversational AI operations; a system for generating synthetic data; a system comprising one or more virtual machines (VMs); a system implemented at least in part in a data center; or a system implemented at least in part using cloud computing resources. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] The present system and method for health and error monitoring of a sensor fusion system are described in detail below with reference to the accompanying drawings, in which:

[0024] Figure 1A is an illustration of an example autonomous vehicle according to some embodiments of the present disclosure;

[0025] Figure 1BAccording to some embodiments of the present disclosure Figure 1A Examples of camera positions and fields of view for autonomous vehicles;

[0026] Figure 1C According to some embodiments of the present disclosure Figure 1A a block diagram of an example system architecture for an example autonomous vehicle;

[0027] Figure 1D is a method for cloud-based servers and Figure 1A System diagram of an example of communication between autonomous vehicles;

[0028] Figure 2 is a block diagram of an example monitoring system of a sensor fusion system according to some embodiments of the present disclosure;

[0029] Figure 3-Figure 4 is a flow chart of an example process for monitoring a sensor fusion system according to some embodiments of the present disclosure;

[0030] Figure 5 is a block diagram of an example computing device suitable for implementing some embodiments of the present disclosure; and

[0031] Figure 6 is a block diagram of an example data center suitable for implementing some embodiments of the present disclosure. DETAILED DESCRIPTION

[0032] Systems and methods are disclosed related to health and error monitoring of sensor fusion systems in autonomous or semi-autonomous systems and applications. Although the present disclosure may be directed to an example autonomous or semi-autonomous vehicle or machine 100 (e.g., “vehicle 100,” “ego vehicle 100,” “machine 100,” or “ego machine 100”), its examples may be directed to a sensor fusion system in an autonomous or semi-autonomous system and application. Figure 1A-Figure 1D For example, the systems and methods described herein may be used by, but are not limited to, non-autonomous vehicles or machines, semi-autonomous vehicles or machines (e.g., in one or more adaptive driver assistance systems (ADAS)), autonomous vehicles or machines, driverless and driverless robots or robotic platforms, warehouse vehicles, off-road vehicles, vehicles coupled to one or more trailers, airships, boats, shuttles, emergency response vehicles, motorcycles, electric or motorized bicycles, aircraft, construction vehicles, submarines, drones, and / or other vehicle types. Furthermore, the systems and methods according to the present disclosure may be implemented to monitor the health and error conditions of multi-sensor fusion systems in autonomous or semi-autonomous driving and active safety systems, as well as in augmented reality, virtual reality, mixed reality, robotics, security and surveillance, autonomous or semi-autonomous machine applications, and / or any other technology space in which multi-sensor fusion systems may be used.

[0033] The present disclosure relates to systems and methods for monitoring the health and error conditions of multi-sensor fusion systems (such as, for example, autonomous driving and active safety systems). Given input data from multiple sensor modalities (e.g., RADAR, camera, LiDAR, and ultrasonic), the fusion system provides an environmental description of the vehicle's surroundings with respect to dynamic and / or static objects. In order for a fusion system to be considered safe, the fusion system can be compared to various functional safety requirements. An example of a functional safety requirement is to avoid reporting false positive objects with high confidence - for example, not outputting an object with high confidence when there is no actual object at the reported location. In addition, in order to provide safe and reliable output to another function or component (e.g., a consumer or downstream function or component of an autonomous or semi-autonomous system), it is important that the fusion system can assess its health (e.g., the presence or absence of functional reliability and / or safety of the system) and report errors in an accurate and efficient manner when functionally critical errors occur.

[0034] To address these issues, the systems and methods of the present disclosure aggregate the results of monitoring and error checking in a sensor fusion system into a single checkpoint (as a non-limiting example) to output an error signal based on the aggregated overall state of the system, rather than distributing such monitoring, error checking, and processing throughout the system. This can allow for a more comprehensive assessment of candidate errors across the entire system, which can improve the accuracy of error detection and allow for more efficient generation of health reports.

[0035] In various embodiments, a sensor fusion monitoring system (or "multi-sensor fusion (MSF) monitoring system" or "monitoring system") can provide health and safety monitoring techniques that can meet functional safety requirements (e.g., Automotive Safety Integrity Level (ASIL) B requirements). The monitoring system can provide error signals to an error handling system, which can be used to modify (e.g., limit, shut down, etc.) the functionality of the sensor fusion system or any functionality of the entire system (e.g., a system including an autonomous vehicle, server, data center, and / or the like). For example, the error handling system (or error handling node) can shut down the automatic emergency braking (AEB) functionality (or, if a critical sensor fusion error is present, modify the execution of the AEB system, such as by switching to a different AEB algorithm that does not depend on the specific input experiencing the error). The monitoring system can provide health error signals for detailed debugging of safety-critical errors. In some embodiments, the health error signal can be a brief description of the health issue. For example, the health error signal can be from a health issue that remains consistent over several cycles, or it can be provided due to the discovery of multiple health issues. In some embodiments, if a health error signal has been sent (due to some health issue), the monitoring system may perform continued error reporting even after health has been restored to avoid fluctuating error reporting behavior.

[0036] The monitoring system can provide validity information to systems downstream of the sensor fusion system so that the downstream systems can identify whether the output of the sensor fusion is reliable. In some embodiments, if a signal indicating invalid output / results from a module has been sent, the monitoring system can perform ongoing validity reporting even after the module has resumed producing reliable results.

[0037] In various embodiments, a sensor fusion system (e.g., a multi-sensor fusion (MSF) system) may include one or more perception systems, one or more ego-motion systems, and one or more sensor fusion nodes (e.g., MSF nodes, such as hardware and / or logic components communicatively coupled to various other components in the sensor fusion system architecture), each sensor fusion node including one or more sensor fusion modules (e.g., MSF modules). In various embodiments, an autonomous vehicle may include one or more MSF nodes. In various embodiments, an MSF node may correspond to one or more autonomous or semi-autonomous vehicles. In various embodiments, an MSF node (or its MSF modules) may be implemented and / or executed by hardware, firmware, and / or software in a computing device, server, or data center.

[0038] In various embodiments, each of the one or more perception systems may (1) receive data from at least one sensor (e.g., a RADAR sensor, a LiDAR sensor, an ultrasonic sensor, a stereo camera, a wide-angle camera, an infrared camera, a surround camera, a long-range camera, or a mid-range camera), (2) detect one or more objects (e.g., obstacles) from the data, and / or (3) output perception data (e.g., detected objects, states or properties of detected objects) to an MSF node (e.g., its MSF module). In various embodiments, each of the one or more ego-motion systems may (1) receive data (e.g., raw sensor data) from at least one sensor (e.g., a GNSS sensor or GPS sensor, an IMU sensor, an accelerometer, a gyroscope, a magnetic compass, a magnetometer, a microphone, a speed sensor, a vibration sensor, a steering sensor, or a brake sensor), (2) filter the data, (3) aggregate the data (e.g., aggregate raw sensor data from multiple sensors, (4) generate (or extract) ego-motion data from the data, and / or (5) output the ego-motion data to an MSF node (e.g., its MSF module). In various embodiments, an MSF module (e.g., an MSF core module of the MSF module) can receive perception data from one or more perception systems, receive ego-motion data from one or more ego-motion systems, receive node input evaluation data from a node input monitor (which will be described in the next section), perform fusion of at least the perception data and the ego-motion data, generate output data (e.g., one or more fused objects and attributes of one or more fused objects), and / or send the output data to other systems or nodes (e.g., systems or nodes that can perform localization, mapping, path planning, decision-making, or vehicle control, etc.).

[0039] In various embodiments, the MSF core module may generate one or more error signals (e.g., signals indicating a functional error or a safety-related error in an MSF core component). In various embodiments, the MSF core module may include an MSF interface, prediction and / or measurement update submodule (e.g., as described herein with respect to Figure 2 (further described herein). In various embodiments, the MSF core module can perform MSF interface, prediction, and / or measurement update functions. The MSF interface submodule can receive perception data from one or more perception systems, receive ego-motion data from one or more ego-motion systems, and / or send output data to other systems or nodes. The prediction submodule can perform prediction of the state and / or attributes of an object to perform fusion of the object with other objects. The measurement update submodule can update the measurement values ​​of an object to accurately perform prediction or fusion.

[0040] In various embodiments, a monitoring system for monitoring an MSF system may include a node-level monitor, a module-level monitor, and an error handling system (or error handling node), wherein the node-level monitor can check higher-level signals and states (e.g., the validity of input data and / or the delay of input data) and the module-level monitor can check the internal structure of the multi-sensor fusion (MSF) process. In various embodiments, based on data output from the monitoring system, the error handling system can control the MSF system or the entire system (e.g., a system including an autonomous vehicle, a server, a data center, etc.) or shut down any function of the MSF system or the entire system. In various embodiments, the node-level monitor may include a node input monitor and / or a node output monitor. In various embodiments, the module-level monitor may include an MSF health monitor, which includes a module input monitor, an MSF core monitor, a module output monitor, and / or a state and error handler.

[0041] In various embodiments, a node input monitor may receive sensory data from one or more sensory systems, receive self-motion data from one or more self-motion systems, and perform an evaluation on the sensory data and / or self-motion data. In various embodiments, the node input monitor may generate node input evaluation data (e.g., data indicating the validity of the sensory data) or one or more error signals (e.g., signals indicating a functional error or a safety-related error of the MSF core module) based on the results of the evaluation. In various embodiments, a module input monitor may receive sensory data from one or more sensory systems, receive self-motion data from one or more self-motion systems, receive node input evaluation data from the node input monitor, perform an evaluation on the received data, generate module input evaluation data based on the results of the evaluation, and send the module input evaluation data (e.g., data indicating validity and / or error) to a status and error handler. In various embodiments, an MSF core monitor may receive one or more error signals from an MSF core module, perform an evaluation on the received one or more error signals, generate module core evaluation data based on the results of the evaluation, and send the module core evaluation data (e.g., data indicating validity and / or error) to a status and error handler. In various embodiments, a module output monitor may receive output data generated by an MSF core module, perform an evaluation on the received output data, generate module output evaluation data based on the results of the evaluation, and send the module output evaluation data (e.g., data indicating validity and / or errors) to a status and error handler. In various embodiments, a status and error handler may receive module input evaluation data (from a module input monitor), module core evaluation data (from an MSF core monitor), and / or module output evaluation data (from a module output monitor), perform an evaluation on the received evaluation data, and generate, based on the results of the evaluation: (1) validity data (e.g., validity of data associated with the MSF core module) and / or (2) a signal indicating an error and / or health of the MSF core module. In various embodiments, a node output monitor may receive output data (e.g., output data from an MSF core module), validity data (e.g., validity data from a status and error handler), and / or MSF error / health signals (e.g., MSF error or health signals from a status and error handler), perform an evaluation on the received data, and based on the results of the evaluation generate: (1) node output evaluation data (e.g., validity of fused data) and / or (2) a signal indicating an error and / or health of the MSF node.

[0042] In various embodiments, a node input monitor can evaluate or check whether the inputs to the MSF system (e.g., input data from multiple sensors, perception data, and / or ego-motion data) are missing, delayed (e.g., arriving too late), outdated (e.g., the input information has not been updated for multiple iterations), or invalid. If any of these events occurs, the node input monitor can send one or more error messages to the error handling system. The node input monitor can send information (e.g., node input evaluation data indicating the validity of the input data) to the MSF input monitor within the MSF core module and / or the MSF health monitor. Using the node input evaluation data, the MSF core module can handle degradation within the MSF system based on problems with the input data (e.g., invalid fusion output, functional degradation of the system, functional or safety-related errors, etc.). For example, if the RADAR perception data is invalid, the MSF core module can allow longer gliding of camera-only obstacles and adjust the way confidence is calculated. Input error events can also cause the obstacle fusion output to be set to invalid - either directly or after a number of cycles of consistent errors. For example, if an error occurs on the RADAR perception data (e.g., an object or obstacle detected by the RADAR) for more than a predetermined number of execution cycles (e.g., execution cycles in which fusion is performed and / or data is sampled from the sensor), the monitoring system (e.g., a node output monitor) may set (or determine or detect or evaluate) the MSF output (e.g., the fused object or obstacle) as invalid in the node output evaluation data.

[0043] In various embodiments, given a current degraded state (e.g., an invalid state of a fused output, a functionally degraded state of the system, a state associated with a functional or safety-related error, etc.), a node output monitor can obtain information about the validity of the MSF system (e.g., validity data) from a state and error handler and determine the validity of fused objects / obstacles output from the MSF system (e.g., an MSF core module). In various embodiments, a node output monitor can perform the same checks or assessments as a node input monitor, but for MSF nodes. A node output monitor can define the expected cycle frequency and latency of an MSF node and / or detect delayed or outdated nodes (e.g., whether the fused output of an MSF node is delayed by a threshold amount). The degraded state of the MSF can be determined by inspecting or evaluating the input data, output data, and / or internal processing of the MSF system (e.g., an MSF core module). The node output monitor can use these information sources to set the validity of the MSF core module as healthy (or valid, reliable, or normal) or unhealthy (or invalid, unreliable, or abnormal).

[0044] In various embodiments, the MSF health monitor can perform more detailed monitoring of dynamic MSF input data or signals, as well as monitoring for internal processing errors (e.g., internal processing errors of the MSF core module) and errors in the reported output of the MSF system (e.g., errors in the fused output of the MSF core module). The MSF health monitor can directly transmit error and health signals to a system health service (e.g., a system / node / service used to monitor and assess the status and health of an autonomous vehicle, server, or data center). Error signals can include high-level errors based on the aggregation of individual errors (e.g., grouped errors that combine different types of errors). In addition, the MSF health monitor can provide degradation status (e.g., valid or invalid, a state where the MSF system's functionality is degraded, a state related to a functional error or a safety-related error) to consumer systems (e.g., systems or nodes that can perform localization, mapping, path planning, decision-making, or vehicle control, etc.) via metadata sent on the fused obstacle output port (e.g., metadata indicating the validity of the fused object and / or the error / health status of the MSF system).

[0045] In various embodiments, a module input monitor can evaluate or check key attributes of input data (e.g., the validity of the input data) that may not be captured on the producer side (e.g., the perception system or the ego-motion system). The module input monitor can determine whether the output of the MSF system (e.g., a fused object or obstacle) is valid based on the results of the evaluation or check (e.g., the validity of the input data). Table 1 shown below describes examples of evaluations or checks performed by the module input monitor. Each evaluation or check can result in an error / health error signal (e.g., an MSF error / health signal generated by a status and error handler) with an identifier (ID) as shown in the table, which is sent to an error handling system or system health service. In various embodiments, these errors can help debug a module (e.g., an MSF core module). In various embodiments, each evaluation or check cannot send its own error signal to an error handler (e.g., a status and error handler or an error handling system or a system health service). In various embodiments, an MSF health monitor (e.g., a module input monitor, a module core monitor, a module output monitor) can determine the criticality of an error and group or aggregate the individual errors into error messages for each group based on the criticality. The error handling system can then perform functional degradation based on the grouped errors. In various embodiments, an MSF core monitor can monitor the internal processing of a sensor fusion system and perform checks, evaluations, or analyses that may not be handled by unit tests. In various embodiments, in order to provide a safe and robust fusion system, an MSF core monitor can perform checks, evaluations, or analyses (including failure mode and effects analysis (FMEA)) in which each processing step of an MSF module or system (e.g., an MSF core module) is analyzed for potential risks of violating functional safety requirements. Based on the output or results of the FMEA analysis, potential functional safety risks can be mitigated by unit testing or core monitor checks. Table 2 shown below lists examples of internal evaluations or checks in a multi-sensor fusion process (e.g., a fusion process performed by an MSF core module). Each check failure may result in an error / health error signal (e.g., an MSF error / health signal generated by the status and error handler) being sent to the error handling system or system health service. In various embodiments, the module output monitor may perform various evaluations or checks on the output generated by the sensor fusion system (e.g., a fused object or obstacle). For example, the module output monitor may perform a check on each field in the output data (e.g., a characteristic, attribute, size, position, velocity, acceleration, etc.) to see if it is within a specified range.

[0046] In various embodiments, the status and error handler can determine whether an error has occurred in an input of the MSF system, a core module of the MSF system, or an output of the MSF system, and based on the result of the determination, generate an MSF error / health signal to be sent to an error handling system, other systems / nodes, and / or a system health service. The status and error handler can determine whether the error is severe enough to disable the entire sensor fusion system (e.g., the entire MSF system) or the entire system (e.g., the entire autonomous vehicle, the entire server, or the entire data center).

[0047] In various embodiments, the monitoring system can perform module degradation based on outputs of the monitoring system. The monitoring system can have three primary outputs: (1) validity information of the fused output (e.g., fused objects or obstacles); (2) error messages indicating errors in the inputs to the MSF system, in core modules of the MSF system, or in the outputs of the MSF system; and / or (3) health messages indicating the presence or absence of reliable functionality and / or safety of the MSF system.

[0048] In various embodiments, a monitoring system (e.g., an error handling system / node or a node output monitor) can set (or provide) validity information in the fused output to inform downstream consumers whether the fused output at the current frame (e.g., the fused output at the current execution cycle) is trustworthy. The monitoring system can send error messages to a system error handling module (e.g., an error handling system) for potential functional degradation. The monitoring system can send health messages to a health service for debugging purposes.

[0049] Reference Figure 1A , Figure 1A is an example autonomous vehicle depicted as an illustrative multi-sensor system in accordance with some embodiments of the present disclosure. It should be understood that this and other arrangements described herein are set forth by way of example only. Other arrangements and elements (e.g., machines, interfaces, functions, sequences, functional groupings, etc.) may be used in addition to or in lieu of those shown, and some elements may be omitted entirely. In addition, many of the elements described herein are functional entities that may be implemented as discrete or distributed components or in conjunction with other components and implemented in any suitable combination and location. The various functions performed by the entities described herein may be performed by hardware, firmware, and / or software. For example, the various functions may be performed by a processor executing instructions stored in a memory. In some embodiments, the systems, methods, and processes described herein may be implemented using Figure 1A-Figure 1D Example of autonomous vehicle 100, Figure 5 The example computing device 500 and / or Figure 6The vehicle 100 is an example system that includes multiple sensors of different types, such as a vibration sensor 142, a RADAR sensor 160, an ultrasonic sensor 162, a LiDAR sensor 164, a stereo camera 168, a wide-angle camera 170, and an infrared camera 172. Various other embodiments of the disclosed method are not limited to vehicle systems or these specific types of sensors.

[0050] The systems and methods described herein may be used by, but are not limited to, non-autonomous vehicles or machines, semi-autonomous vehicles or machines (e.g., in one or more adaptive driver assistance systems (ADAS)), autonomous vehicles or machines, driverless and driverless robots or robotic platforms, warehouse vehicles, off-road vehicles, vehicles coupled to one or more trailers, airships, boats, shuttles, emergency response vehicles, motorcycles, electric or motorized bicycles, aircraft, engineering vehicles, submarines, drones, and / or other vehicle types. Further, the systems and methods described herein may be used for various purposes, including, by way of example and not limitation, for machine control, machine motion, machine driving, synthetic data generation, model training, perception, augmented reality, virtual reality, mixed reality, robotics, safety and surveillance, simulation and digital twins, autonomous or semi-autonomous machine applications, deep learning, environmental simulation, object or actor simulation and / or digital twins, data center processing, conversational AI, light transport simulation (e.g., ray tracing, path tracing, etc.), collaborative content creation for 3D assets, cloud computing, and / or any other suitable application.

[0051] The disclosed embodiments may be included in a variety of different systems, such as automotive systems (e.g., control systems for autonomous or semi-autonomous machines, perception systems for autonomous or semi-autonomous machines), systems implemented using robots, aerial systems, medical systems, boating systems, smart area monitoring systems, systems for performing deep learning operations, systems for performing simulation operations, systems for performing digital twin operations, systems implemented using edge devices, systems including one or more virtual machines (VMs), systems for performing synthetic data generation operations, systems implemented at least in part in a data center, systems for performing conversational AI operations, systems for hosting live streaming applications, systems for presenting one or more of virtual reality content, augmented reality content, or mixed reality content, systems for performing light transport simulations, systems for performing collaborative content creation of 3D assets, systems implemented at least in part using cloud computing resources, and / or other types of systems.

[0052] Example autonomous vehicle

[0053] Figure 1A1 is an illustration of an example autonomous vehicle 100 according to some embodiments of the present disclosure. Autonomous vehicle 100 (alternatively referred to herein as "vehicle 100") may include, but is not limited to, a passenger vehicle, such as a car, a truck, a bus, an emergency vehicle, a shuttle, an electric or motorized bicycle, a motorcycle, a fire truck, a police car, an ambulance, a boat, a construction vehicle, a submarine, a robotic vehicle, a drone, an airplane, a vehicle coupled to a trailer (e.g., a semi-trailer truck for transporting cargo), and / or other types of vehicles (e.g., unmanned and / or capable of accommodating one or more passengers). Autonomous vehicles are generally described in terms of levels of automation as defined by the National Highway Traffic Safety Administration (NHTSA), a division of the U.S. Department of Transportation, and the Society of Automotive Engineers (SAE), “Taxonomy and Definitions for Terms Related to Driving Automation Systems for On-Road Motor Vehicles” (Standard No. J3016-201506, issued on June 15, 2018, Standard No. J3016-201609, issued on September 30, 2016, and prior and future versions of such standards). The vehicle 100 is capable of implementing functionality consistent with one or more of Levels 3 through 5 of the autonomous driving levels. The vehicle 100 is capable of implementing functionality consistent with one or more of Levels 1 through 5 of the automated driving levels. For example, depending on the embodiment, the vehicle 100 may be capable of driver assistance (Level 1), partial automation (Level 2), conditional automation (Level 3), high automation (Level 4), and / or full automation (Level 5). The term "autonomy" as used herein may include any and / or all types of autonomy of 100 or other machines, such as full autonomy, high autonomy, conditional autonomy, partial autonomy, assisted autonomy, semi-autonomy, primary autonomy, or other names.

[0054] Vehicle 100 may include components such as a chassis, a body, wheels (e.g., 2, 4, 6, 8, 18, etc.), tires, axles, and other vehicle components. Vehicle 100 may include a propulsion system 150, such as an internal combustion engine, a hybrid power plant, an all-electric engine, and / or another type of propulsion system. Propulsion system 150 may be connected to a drivetrain of vehicle 100, which may include a transmission, to achieve propulsion of vehicle 100. Propulsion system 150 may be controlled in response to receiving a signal from throttle / accelerator 152.

[0055] A steering system 154, which may include a steering wheel, may be used to steer vehicle 100 (e.g., along a desired path or route) when propulsion system 150 is operating (e.g., when the vehicle is in motion). Steering system 154 may receive signals from steering actuator 156. For fully automated (Level 5) functionality, a steering wheel may be optional.

[0056] Brake sensor system 146 may be used to operate vehicle brakes in response to receiving signals from brake actuator 148 and / or brake sensors.

[0057] May include one or more CPUs, system on chip (SoC) 104 ( Figure 1C ) and / or one or more GPUs can provide signals (e.g., representing commands) to one or more components and / or systems of the vehicle 100. For example, the one or more controllers can send signals to operate the vehicle brakes via one or more brake actuators 148, to operate the steering system 154 via one or more steering actuators 156, and / or to operate the propulsion system 150 via one or more throttles / accelerators 152. The one or more controllers 136 can include one or more onboard (e.g., integrated) computing devices (e.g., supercomputers) that process sensor signals and output operating commands (e.g., signals representing commands) to enable autonomous driving and / or assist a human driver in driving the vehicle 100. The one or more controllers 136 can include a first controller 136 for autonomous driving functions, a second controller 136 for functional safety functions, a third controller 136 for artificial intelligence functions (e.g., computer vision), a fourth controller 136 for infotainment functions, a fifth controller 136 for redundancy in emergency situations, and / or other controllers. In some examples, a single controller 136 may handle two or more of the above functions, two or more controllers 136 may handle a single function, and / or any combination thereof.

[0058] The one or more controllers 136 may provide signals for controlling one or more components and / or systems of the vehicle 100 in response to sensor data (e.g., sensor inputs) received from one or more sensors. The sensor data may be received from, for example and without limitation, a global navigation satellite system (“GNSS”) sensor 158 (e.g., a global positioning system sensor), a RADAR sensor 160, an ultrasonic sensor 162, a LiDAR sensor 164, an inertial measurement unit (IMU) sensor 166 (e.g., an accelerometer, a gyroscope, a magnetic compass, a magnetometer, etc.), a microphone 196, a stereo camera 168, a wide-angle camera 170 (e.g., a fisheye camera), an infrared camera 172, a surround camera 174 (e.g., a 360-degree camera), a long-range and / or mid-range camera 198, a speed sensor 144 (e.g., for measuring the velocity of the vehicle 100), a vibration sensor 142, a steering sensor 140, a brake sensor (e.g., as part of a brake sensor system 146), and / or other sensor types.

[0059] One or more of the controllers 136 may receive input (e.g., represented by input data) from the instrument cluster 132 of the vehicle 100 and provide output (e.g., represented by output data, display data, etc.) via a human machine interface (HMI) display 134, an audible annunciator, a speaker, and / or via other components of the vehicle 100. These outputs may include information such as vehicle speed, velocity, time, map data (e.g., Figure 1C The HMI display 134 may include information such as a high-definition ("HD") map 122 of the vehicle 100, location data (e.g., the location of the vehicle 100 on the map), directions, locations of other vehicles (e.g., an occupancy grid), information about objects and states of objects as sensed by the controller 136, and the like. For example, the HMI display 134 may display information about the presence of one or more objects (e.g., street signs, warning signs, traffic light changes, etc.) and / or information about driving maneuvers that the vehicle has made, is making, or will make (e.g., changing lanes now, leaving 34B in two miles, etc.).

[0060] The vehicle 100 further includes a network interface 124 that can communicate over one or more networks using one or more wireless antennas 126 and / or a modem. For example, the network interface 124 can be capable of communicating over Long Term Evolution ("LTE"), Wideband Code Division Multiple Access ("WCDMA"), Universal Mobile Telecommunications System ("UMTS"), Global System for Mobile Communications ("GSM"), IMT-CDMA Multi-Carrier ("CDMA2000"), and the like. The one or more wireless antennas 126 can also enable communication between objects in the environment (e.g., vehicles, mobile devices, and the like) using one or more local area networks such as Bluetooth, Bluetooth Low Energy ("LE"), Z-Wave, ZigBee, and the like, and / or one or more low power wide area networks ("LPWAN") such as LoRaWAN, SigFox, and the like.

[0061] Figure 1B According to some embodiments of the present disclosure, Figure 1A An example of camera positions and fields of view for autonomous vehicle 100 is shown. The cameras and respective fields of view are an example embodiment and are not intended to be limiting. For example, additional and / or alternative cameras may be included and / or the cameras may be located at different locations on vehicle 100.

[0062] The camera type used for the camera may include, but is not limited to, a digital camera that may be suitable for use with components and / or systems of the vehicle 100. The camera may operate at Automotive Safety Integrity Level (ASIL) B and / or at another ASIL. The camera type may have any image capture rate, such as 60 frames per second (fps), 120fps, 240fps, and the like, depending on the implementation. The camera may be capable of using a rolling shutter, a global shutter, another type of shutter, or a combination thereof. In some examples, the color filter array may include a red-white-white-white (RCCC) color filter array, a red-white-white-blue (RCCB) color filter array, a red-blue-green-white (RBGC) color filter array, a Foveon X3 color filter array, a Bayer sensor (RGGB) color filter array, a monochrome sensor color filter array, and / or another type of color filter array. In some embodiments, a clear pixel camera such as a camera with an RCCC, RCCB, and / or RBGC color filter array may be used in an effort to improve light sensitivity.

[0063] In some examples, one or more of the cameras can be used to perform advanced driver assistance system (ADAS) functions (e.g., as part of a redundant or fail-safe design). For example, a multi-function monocular camera can be installed to provide functions including lane departure warning, traffic sign assistance, and intelligent headlight control. One or more of the cameras (e.g., all of the cameras) can simultaneously record and provide image data (e.g., video).

[0064] One or more of the cameras can be mounted in a mounting assembly, such as a custom-designed (three-dimensional ("3D") printed) assembly, to cut out stray light and reflections from within the car (e.g., reflections from the dashboard reflected in the windshield mirror) that might interfere with the camera's ability to capture image data. With respect to the wing mirror mounting assembly, the wing mirror assembly can be custom 3D printed so that the camera mounting plate matches the shape of the wing mirror. In some examples, one or more cameras can be integrated into the wing mirror. For side-view cameras, one or more cameras can also be integrated into the four pillars at each corner of the cabin.

[0065] A camera with a field of view that includes a portion of the environment in front of the vehicle 100 (e.g., a front-facing camera) can be used for surround vision to help identify the forward path and obstacles, as well as assist in providing information critical to generating an occupancy grid and / or determining a preferred vehicle path with the help of one or more controllers 136 and / or control SoCs. The front-facing camera can be used to perform many of the same ADAS functions as LiDAR, including emergency braking, pedestrian detection, and collision avoidance. The front-facing camera can also be used for ADAS functions and systems, including lane departure warning ("LDW"), autonomous cruise control (ACC), and / or other functions such as traffic sign recognition.

[0066] A variety of cameras may be used in the front-facing configuration, including, for example, a monocular camera platform including a complementary metal oxide semiconductor ("CMOS") color imager. Another example may be a wide-angle camera 170, which may be used to sense objects entering the field of view from the periphery (e.g., pedestrians, intersection traffic, or bicycles). Although Figure 1B The figure shows only one wide-angle camera, but there can be any number (including zero) of wide-angle cameras 170 on the vehicle 100. In addition, any number of long-range cameras 198 (e.g., a pair of long-range stereo cameras) can be used for depth-based object detection, especially for objects for which neural networks have not yet been trained. Long-range cameras 198 can also be used for object detection and classification and basic object tracking.

[0067] Any number of stereo cameras 168 may also be included in the front configuration. In at least one embodiment. One or more of the stereo cameras 168 may include an integrated control unit including a scalable processing unit that may provide a multi-core microprocessor and programmable logic ("FPGA") with an integrated controller area network ("CAN") or Ethernet interface on a single chip. Such a unit may be used to generate a 3D map of the vehicle's environment, including distance estimates for all points in the image. Alternative stereo cameras 168 may include a compact stereo vision sensor that may include two camera lenses (one on the left and one on the right) and an image processing chip that may measure the distance from the vehicle to a target object and use the generated information (e.g., metadata) to activate autonomous emergency braking and lane departure warning features. Other types of stereo cameras 168 may be used in addition to or alternatively to those described herein.

[0068] Cameras with a field of view that includes portions of the environment to the sides of the vehicle 100 (e.g., side view cameras) can be used for surround vision, providing information used to create and update occupancy grids and generate side impact collision warnings. For example, surround cameras 174 (e.g., Figure 1B Four surround cameras 174 (shown in FIG. 1 ) can be positioned on the vehicle 100. The surround cameras 174 can include wide-angle cameras 170, fisheye cameras, 360-degree cameras, and / or the like. For example, four fisheye cameras can be positioned on the front, rear, and sides of the vehicle. In an alternative arrangement, the vehicle can utilize three surround cameras 174 (e.g., left, right, and rear) and can utilize one or more other cameras (e.g., a forward-facing camera) as a fourth surround-view camera.

[0069] A camera having a field of view that includes a portion of the environment behind the vehicle 100 (e.g., a rearview camera) can be used to assist with parking, surround view, rear collision warning, and creating and updating occupancy grids. A variety of cameras can be used, including but not limited to cameras that are also suitable as front-facing cameras as described herein (e.g., long-range and / or mid-range cameras 198, stereo cameras 168, infrared cameras 172, etc.).

[0070] Figure 1C According to some embodiments of the present disclosure, Figure 1A1 is a block diagram of an example system architecture for an example autonomous vehicle 100. It should be understood that this arrangement and other arrangements described herein are set forth merely as examples. Other arrangements and elements (e.g., machines, interfaces, functions, sequences, functional groupings, etc.) may be used in addition to or in place of those shown, and some elements may be omitted entirely. Further, many of the elements described herein are functional entities that may be implemented as discrete or distributed components or in conjunction with other components, and in any appropriate combination and location. The various functions described herein as being performed by entities may be implemented by hardware, firmware, and / or software. For example, the various functions may be implemented by a processor executing instructions stored in memory.

[0071] Figure 1C Each of the components, features, and systems of the vehicle 100 is illustrated as being connected via a bus 102. The bus 102 may include a controller area network (CAN) data interface (alternatively referred to herein as a "CAN bus"). The CAN may be a network internal to the vehicle 100 that assists in controlling various features and functions of the vehicle 100, such as actuation of brakes, acceleration, braking, steering, windshield wipers, and the like. The CAN bus may be configured to have tens or even hundreds of nodes, each with its own unique identifier (e.g., a CAN ID). The CAN bus may be read to find steering wheel angle, ground speed, engine revolutions per minute (RPM), button positions, and / or other vehicle status indicators. The CAN bus may be ASIL B compliant.

[0072] Although bus 102 is described here as a CAN bus, this is not intended to be limiting. For example, FlexRay and / or Ethernet may be used in addition to or in lieu of a CAN bus. Furthermore, although bus 102 is represented by a single line, this is not intended to be limiting. For example, there may be any number of buses 102, which may include one or more CAN buses, one or more FlexRay buses, one or more Ethernet buses, and / or one or more other types of buses using different protocols. In some examples, two or more buses 102 may be used to perform different functions and / or may be used for redundancy. For example, a first bus 102 may be used for collision avoidance functionality, and a second bus 102 may be used for drive control. In any example, each bus 102 may communicate with any component of vehicle 100, and two or more buses 102 may communicate with the same component. In some examples, each SoC 104, each controller 136, and / or each computer within the vehicle may have access to the same input data (e.g., input from sensors on vehicle 100) and may be connected to a common bus such as a CAN bus.

[0073] The vehicle 100 may include one or more controllers 136, such as those described herein. Figure 1A The controller 136 may be used for a variety of functions. The controller 136 may be coupled to any other various components and systems of the vehicle 100 and may be used for control of the vehicle 100, artificial intelligence of the vehicle 100, infotainment for the vehicle 100, and / or the like.

[0074] The vehicle 100 may include one or more system-on-chips (SoCs) 104. The SoCs 104 may include a CPU 106, a GPU 108, a processor 110, a cache 112, an accelerator 114, a data store 116, and / or other components and features not shown. The SoCs 104 may be used to control the vehicle 100 in a variety of platforms and systems. For example, the one or more SoCs 104 may be combined with an HD map 122 in a system (e.g., a system of the vehicle 100), which may be downloaded from one or more servers (e.g., a server) via a network interface 124. Figure 1D One or more servers 178) obtain map refreshes and / or updates.

[0075] The CPU 106 may include a CPU cluster or CPU complex (alternatively, referred to herein as a "CCPLEX"). The CPU 106 may include multiple cores and / or L2 caches. For example, in some embodiments, the CPU 106 may include eight cores in a coherent multiprocessor configuration. In some embodiments, the CPU 106 may include four dual-core clusters, each with a dedicated L2 cache (e.g., a 2MB L2 cache). The CPU 106 (e.g., CCPLEX) may be configured to support simultaneous cluster operations such that any combination of CPU 106 clusters can be active at any given time.

[0076] The CPU 106 may implement power management capabilities including one or more of the following features: each hardware block may be automatically clock gated when idle to conserve dynamic power; each core clock may be gated when the core is not actively executing instructions due to the execution of WFI / WFE instructions; each core may be independently power gated; each core cluster may be independently clock gated when all cores are clock gated or power gated; and / or each core cluster may be independently power gated when all cores are power gated. The CPU 106 may further implement an enhanced algorithm for managing power states, in which allowed power states and expected wakeup times are specified, and hardware / microcode determines the optimal power state to enter for the core, cluster, and CCPLEX. The processing core may support a simplified power state entry sequence in software, with this work being offloaded to the microcode.

[0077] The GPU 108 may include an integrated GPU (alternatively referred to herein as an "iGPU"). The GPU 108 may be programmable and efficient for parallel workloads. In some examples, the GPU 108 may use an enhanced tensor instruction set. The GPU 108 may include one or more streaming microprocessors, each of which may include an L1 cache (e.g., an L1 cache with at least 96KB of storage capacity), and two or more of these streaming microprocessors may share an L2 cache (e.g., an L2 cache with 512KB of storage capacity). In some embodiments, the GPU 108 may include at least eight streaming microprocessors. The GPU 108 may use a computing application programming interface (API). In addition, the GPU 108 may use one or more parallel computing platforms and / or programming models (e.g., NVIDIA's CUDA).

[0078] In the case of automotive and embedded use, GPU 108 can be power optimized to achieve optimal performance. For example, GPU 108 can be manufactured on fin field effect transistors (FinFETs). However, this is not intended to be limiting, and GPU 108 can be manufactured using other semiconductor manufacturing processes. Each streaming microprocessor can merge several mixed precision processing cores divided into multiple blocks. For example and without limitation, 64 PF32 cores and 32 PF64 cores can be divided into four processing blocks. In such an example, each processing block can be allocated 16 FP32 cores, 8 FP64 cores, 16 INT32 cores, two mixed precision NVIDIA tensor cores for deep learning matrix arithmetic, L0 instruction cache, warp scheduler, dispatch unit and / or 64KB register file. In addition, the streaming microprocessor may include independent parallel integer and floating point data paths to provide efficient execution of workloads using a mix of computation and addressing calculations. The streaming microprocessor may include independent thread scheduling capabilities to allow for finer-grained synchronization and collaboration between parallel threads. A streaming microprocessor may include a combined L1 data cache and shared memory unit to increase performance while simplifying programming.

[0079] GPU 108 can include high bandwidth memory (HBM) and / or a 16GB HBM2 memory subsystem that provides a peak memory bandwidth of approximately 900 GB / s in some examples. In some examples, synchronous graphics random access memory (SGRAM), such as fifth generation graphics double data rate synchronous random access memory (GDDR5), can be used in addition to or in lieu of HBM memory.

[0080] The GPU 108 may include unified memory technology that includes access counters to allow memory pages to be more accurately migrated to the processor that accesses them most frequently, thereby improving the efficiency of memory ranges shared between processors. In some examples, address translation services (ATS) support may be used to allow the GPU 108 to directly access the CPU 106 page tables. In such an example, when the GPU 108 memory management unit (MMU) experiences a miss, an address translation request may be transmitted to the CPU 106. In response, the CPU 106 may look up the virtual-to-physical mapping for the address in its page table and transmit the translation back to the GPU 108. In this way, unified memory technology may allow a single unified virtual address space to be used for memory of both the CPU 106 and the GPU 108, thereby simplifying GPU 108 programming and porting of applications to the GPU 108.

[0081] Additionally, GPU 108 may include access counters that can track how often GPU 108 accesses the memory of other processors. Access counters can help ensure that memory pages are moved to the physical memory of the processor that accesses them most frequently.

[0082] SoC 104 may include any number of caches 112, including those described herein. For example, cache 112 may include an L3 cache available to both CPU 106 and GPU 108 (e.g., connected to both CPU 106 and GPU 108). Cache 112 may include a write-back cache that may track the state of lines, for example, using a cache coherence protocol (e.g., MEI, MESI, MSI, etc.). Depending on the implementation, the L3 cache may include 4MB or more, although smaller cache sizes may also be used.

[0083] The SoC 104 may include one or more arithmetic logic units (ALUs) that may be used to perform processing for any of a variety of tasks or operations related to the vehicle 100, such as processing a DNN. Furthermore, the SoC 104 may include a floating point unit (FPU) or other math coprocessor or digital coprocessor type for performing mathematical operations within the system. For example, the SoC 104 may include one or more FPUs integrated as execution units within the CPU 106 and / or GPU 108.

[0084] SoC 104 may include one or more accelerators 114 (e.g., hardware accelerators, software accelerators, or a combination thereof). For example, SoC 104 may include a hardware acceleration cluster, which may include optimized hardware accelerators and / or large on-chip memory. The large on-chip memory (e.g., 4MB SRAM) may enable the hardware acceleration cluster to accelerate neural networks and other calculations. The hardware acceleration cluster may be used to supplement GPU 108 and offload some tasks of GPU 108 (e.g., freeing up more cycles of GPU 108 for performing other tasks). As an example, accelerator 114 may be used for targeted workloads (e.g., perception, convolutional neural networks (CNNs), etc.) that are stable enough to easily control acceleration. When used herein, the term "CNN" may include all types of CNNs, including region-based or regional convolutional neural networks (RCNNs) and fast RCNNs (e.g., for object detection).

[0085] The accelerator 114 (e.g., a hardware acceleration cluster) may include a deep learning accelerator (DLA). The DLA may include one or more tensor processing units (TPUs) that can be configured to provide an additional 10 trillion operations per second for deep learning applications and reasoning. The TPU may be an accelerator configured to perform image processing functions (e.g., for CNN, RCNN, etc.) and optimized for performing image processing functions. The DLA may be further optimized for a specific set of neural network types and floating-point operations and reasoning. The design of the DLA may provide higher performance per millimeter than a general-purpose GPU and far exceed the performance of the CPU. The TPU may perform several functions, including a single-instance convolution function, support for INT8, INT16, and FP16 data types for both features and weights, and post-processor functions.

[0086] DLA can quickly and efficiently execute neural networks, particularly CNNs, on processed or unprocessed data for any of a wide variety of functions, such as, but not limited to: CNNs for object recognition and detection using data from camera sensors; CNNs for distance estimation using data from camera sensors; CNNs for emergency vehicle detection and recognition and detection using data from microphones; CNNs for facial recognition and vehicle owner identification using data from camera sensors; and / or CNNs for safety and / or security-related events.

[0087] The DLA can perform any function of the GPU 108, and by using an inference accelerator, for example, the designer can target any function to either the DLA or the GPU 108. For example, the designer can focus the processing of CNNs and floating-point operations on the DLA and leave other functions to the GPU 108 and / or other accelerators 114.

[0088] The accelerator 114 (e.g., a hardware acceleration cluster) may include a programmable vision accelerator (PVA), which may be alternatively referred to herein as a computer vision accelerator. The PVA may be designed and configured to accelerate computer vision algorithms for advanced driver assistance systems (ADAS), autonomous driving, and / or augmented reality (AR) and / or virtual reality (VR) applications. The PVA may provide a balance between performance and flexibility. For example, each PVA may include, for example and without limitation, any number of reduced instruction set computer (RISC) cores, direct memory access (DMA), and / or any number of vector processors.

[0089] The RISC core can interact with an image sensor (e.g., an image sensor of any camera described herein), an image signal processor, and / or the like. Each of these RISC cores can include any amount of memory. Depending on the implementation, the RISC core can use any of a number of protocols. In some examples, the RISC core can execute a real-time operating system (RTOS). The RISC core can be implemented using one or more integrated circuit devices, application specific integrated circuits (ASICs), and / or storage devices. For example, the RISC core can include an instruction cache and / or tightly coupled RAM.

[0090] The DMA may enable components of the PVA to access system memory independently of the CPU 106. The DMA may support any number of features used to provide optimizations for the PVA, including, but not limited to, support for multi-dimensional addressing and / or circular addressing. In some examples, the DMA may support addressing in up to six or more dimensions, which may include block width, block height, block depth, horizontal block stride, vertical block stride, and / or depth stride.

[0091] A vector processor can be a programmable processor that can be designed to efficiently and flexibly execute programming for computer vision algorithms and provide signal processing capabilities. In some examples, the PVA can include a PVA core and two vector processing subsystem partitions. The PVA core can include a processor subsystem, one or more DMA engines (e.g., two DMA engines), and / or other peripherals. The vector processing subsystem can operate as the main processing engine of the PVA and can include a vector processing unit (VPU), an instruction cache, and / or a vector memory (e.g., VMEM). The VPU core can include a digital signal processor, such as, for example, a single instruction multiple data (SIMD), a very long instruction word (VLIW) digital signal processor. The combination of SIMD and VLIW can enhance throughput and speed.

[0092] Each of the vector processors can include an instruction cache and can be coupled to dedicated memory. As a result, in some examples, each of the vector processors can be configured to execute independently of the other vector processors. In other examples, the vector processors included in a particular PVA can be configured to employ data parallelism. For example, in some embodiments, multiple vector processors included in a single PVA can execute the same computer vision algorithm, but on different regions of an image. In other examples, the vector processors included in a particular PVA can execute different computer vision algorithms simultaneously on the same image, or even execute different algorithms on sequence images or portions of images. Among other things, any number of PVAs can be included in a hardware acceleration cluster, and any number of vector processors can be included in each of these PVAs. In addition, the PVAs can include additional error correction code (ECC) memory to enhance overall system security.

[0093] The accelerator 114 (e.g., a hardware acceleration cluster) may include an on-chip computer vision network and SRAM to provide high bandwidth, low latency SRAM for the accelerator 114. In some examples, the on-chip memory may include at least 4MB of SRAM consisting of, for example and without limitation, eight field-configurable memory blocks that can be accessed by both the PVA and the DLA. Each pair of memory blocks may include an advanced peripheral bus (APB) interface, configuration circuitry, a controller, and a multiplexer. Any type of memory may be used. The PVA and DLA may access the memory via a backbone that provides high-speed memory access to the PVA and DLA. The backbone may include an on-chip computer vision network that interconnects the PVA and DLA to the memory (e.g., using APB).

[0094] The on-chip computer vision network can include an interface that ensures that both the PVA and DLA provide ready and valid signals before transmitting any control signals / addresses / data. Such an interface can provide separate phases and separate channels for transmitting control signals / addresses / data, as well as burst-based communication for continuous data transmission. This type of interface can comply with ISO 26262 or IEC 61508 standards, but other standards and protocols can also be used.

[0095] In some examples, SoC 104 may include a real-time ray tracing hardware accelerator, such as that described in U.S. patent application Ser. No. 16 / 101,232, filed on Aug. 10, 2018. The real-time ray tracing hardware accelerator may be used to quickly and efficiently determine the position and extent of objects (e.g., within a world model) in order to generate real-time visual simulations for use in RADAR signal interpretation, for sound propagation synthesis and / or analysis, for SONAR system simulation, for general wave propagation simulation, for comparison with LiDAR data for positioning and / or other functions, and / or for other uses. In some embodiments, one or more tree traversal units (TTUs) may be used to perform one or more ray tracing related operations.

[0096] The accelerator 114 (e.g., a hardware accelerator cluster) has a wide range of uses in autonomous driving. The PVA can be a programmable vision accelerator that can be used in key processing stages in ADAS and autonomous vehicles. The capabilities of the PVA are a good match for algorithmic domains that require predictable processing, low power, and low latency. In other words, the PVA performs well on semi-intensive or intensive rule computations, and even on small data sets that require predictable runtimes with low latency and low power. Therefore, in the context of platforms for autonomous vehicles, the PVA is designed to run classic computer vision algorithms because they are efficient at object detection and integer math operations.

[0097] For example, according to one embodiment of the technology, PVA is used to perform computer stereo vision. In some examples, a semi-global matching-based algorithm can be used, but this is not intended to be limiting. Many applications for Level 3-5 autonomous driving require on-the-fly motion estimation / stereo matching (e.g., structure from motion, pedestrian recognition, lane detection, etc.). PVA can perform computer stereo vision functions on input from two monocular cameras.

[0098] In some examples, PVA can be used to perform dense optical flow, for example by processing raw RADAR data (e.g., using a 4D Fast Fourier Transform) to provide processed RADAR. In other examples, PVA is used for time-of-flight depth processing, for example by processing raw time-of-flight data to provide processed time-of-flight data.

[0099] The DLA can be used to run any type of network to enhance control and driving safety, including, for example, a neural network that outputs a confidence measure for each object detection. Such confidence values ​​can be interpreted as probabilities, or as providing a relative "weight" of each detection compared to other detections. This confidence value enables the system to make further decisions about which detections should be considered true positives versus false positives. For example, the system can set a threshold for confidence and only consider detections that exceed the threshold as true positives. In an automatic emergency braking (AEB) system, a false positive detection could cause the vehicle to automatically apply emergency braking, which is clearly undesirable. Therefore, only the most confident detections should be considered triggers for AEB. The DLA can run a neural network to regress the confidence value. This neural network can take as its input at least some subset of parameters, such as bounding box dimensions, a ground plane estimate obtained (e.g., from another subsystem), inertial measurement unit (IMU) sensor 166 output related to the vehicle 100's orientation and distance, and 3D position estimates of objects obtained from the neural network and / or other sensors (e.g., LiDAR sensor 164 or RADAR sensor 160).

[0100] SoC 104 may include one or more data stores 116 (e.g., memory). Data stores 116 may be on-chip memory of SoC 104 that may store neural networks to be executed on the GPU and / or DLA. In some examples, data stores 116 may be large enough to store multiple instances of the neural network for redundancy and safety. Data stores 116 may include an L2 or L3 cache 112. References to data stores 116 may include references to memory associated with the PVA, DLA, and / or other accelerators 114 as described herein.

[0101] SoC 104 may include one or more processors 110 (e.g., embedded processors). Processor 110 may include a boot and power management processor, which may be a dedicated processor and subsystem for handling boot power and management functions and related safety implementations. The boot and power management processor may be part of the SoC 104 boot sequence and may provide runtime power management services. The boot power and management processor may provide clock and voltage programming, auxiliary system low power state transitions, SoC 104 thermal and temperature sensor management, and / or SoC 104 power state management. Each temperature sensor may be implemented as a ring oscillator whose output frequency is proportional to temperature, and SoC 104 may use the ring oscillator to detect the temperature of CPU 106, GPU 108, and / or accelerator 114. If it is determined that the temperature exceeds a threshold, the boot and power management processor may enter a temperature fault routine and place SoC 104 in a lower power state and / or place vehicle 100 in a driver safety parking mode (e.g., to safely park vehicle 100).

[0102] The processor 110 may further include a set of embedded processors that may function as an audio processing engine. The audio processing engine may be an audio subsystem that allows for full hardware support for multi-channel audio through multiple interfaces and a wide range of flexible audio I / O interfaces. In some examples, the audio processing engine is a dedicated processor core having a digital signal processor with dedicated RAM.

[0103] The processor 110 may further include an always-on processor engine that may provide the necessary hardware features to support low-power sensor management and wake-up use cases. The always-on processor engine may include a processor core, tightly coupled RAM, supporting peripherals (e.g., timers and interrupt controllers), various I / O controller peripherals, and routing logic.

[0104] Processor 110 may further include a safety cluster engine, which includes a dedicated processor subsystem that handles safety management of automotive applications. The safety cluster engine may include two or more processor cores, tightly coupled RAM, supporting peripherals (such as timers, interrupt controllers, etc.), and / or routing logic. In safety mode, the two or more cores may operate in lockstep mode and function as a single core with comparison logic to detect any differences between their operations.

[0105] Processor 110 may further include a real-time camera engine, which may include a dedicated processor subsystem for handling real-time camera management.

[0106] The processor 110 may further include a high dynamic range signal processor, which may include an image signal processor, which is a hardware engine that is part of a camera processing pipeline.

[0107] The processor 110 may include a video image compositer, which may be a processing block (e.g., implemented on a microprocessor) that implements the video post-processing functions required by the video playback application to produce the final image for the player window. The video image compositer may perform lens distortion correction for the wide-angle camera 170, the surround camera 174, and / or for the in-cab monitoring camera sensor. The in-cab monitoring camera sensor is preferably monitored by a neural network running on another instance of the advanced SoC, configured to recognize in-cab events and respond accordingly. The in-cab system may perform lip reading to activate mobile phone service and place calls, dictate emails, change vehicle destinations, activate or change the vehicle's infotainment system and settings, or provide voice-activated web surfing. Certain functions are only available to the driver when the vehicle is operating in autonomous mode and are disabled in other circumstances.

[0108] The video image compositer can include enhanced temporal noise reduction for both spatial and temporal noise reduction. For example, in the presence of motion in the video, the noise reduction appropriately weights spatial information and downweights information provided by neighboring frames. In the case where an image or portion of an image does not include motion, the temporal noise reduction performed by the video image compositer can use information from previous images to reduce noise in the current image.

[0109] The video image compositor can also be configured to perform stereo rectification on the input stereo footage frames. The video image compositor can further be used for user interface composition when the operating system desktop is in use and the GPU 108 does not need to continuously render new surfaces. Even when the GPU 108 is powered on and active for 3D rendering, the video image compositor can be used to offload the GPU 108 to improve performance and responsiveness.

[0110] SoC 104 may further include a mobile industry processor interface (MIPI) camera serial interface, a high-speed interface for receiving video and input from a camera, and / or a video input block that may be used for camera and related pixel input functions. SoC 104 may further include an input / output controller that may be controlled by software and may be used to receive I / O signals that are not assigned to a specific role.

[0111] The SoC 104 may further include a wide range of peripheral interfaces to enable communication with peripherals, audio codecs, power management, and / or other devices. The SoC 104 may be used to process data from cameras (connected via Gigabit multimedia serial links and Ethernet), sensors (e.g., LiDAR sensor 164, RADAR sensor 160, etc., which may be connected via Ethernet), data from the bus 102 (e.g., vehicle 100 speed, steering wheel position, etc.), and data from the GNSS sensor 158 (connected via Ethernet or a CAN bus). The SoC 104 may further include dedicated high-performance mass storage controllers, which may include their own DMA engines and which may be used to free the CPU 106 from routine data management tasks.

[0112] SoC 104 can be an end-to-end platform with a flexible architecture that spans Levels 3-5 of automation, providing a comprehensive functional safety architecture that leverages and efficiently uses computer vision and ADAS technologies for diversity and redundancy, along with deep learning tools to provide a platform for a flexible and reliable driving software stack. SoC 104 can be faster, more reliable, and even more energy- and space-efficient than conventional systems. For example, when combined with CPU 106, GPU 108, and data storage 116, accelerator 114 can provide a fast and efficient platform for Levels 3-5 autonomous vehicles.

[0113] This technology therefore provides capabilities and functionality that cannot be achieved with conventional systems. For example, computer vision algorithms can be executed on CPUs, which can be configured using high-level programming languages ​​such as the C programming language to execute a wide variety of processing algorithms across a wide variety of visual data. However, CPUs often fail to meet the performance requirements of many computer vision applications, such as those related to execution time and power consumption. In particular, many CPUs are unable to execute complex object detection algorithms in real time, a requirement for in-vehicle ADAS applications and practical Level 3-5 autonomous vehicles.

[0114] In contrast to conventional systems, by providing a CPU complex, a GPU complex, and a hardware acceleration cluster, the technology described herein allows for multiple neural networks to be executed simultaneously and / or sequentially, and the results to be combined to achieve Level 3-5 autonomous driving capabilities. For example, a CNN executed on a DLA or dGPU (e.g., GPU 120) can include text and word recognition, allowing the supercomputer to read and understand traffic signs, including signs for which a neural network has not been specifically trained. The DLA can further include a neural network capable of recognizing, interpreting, and providing semantic understanding of the signs, and passing that semantic understanding to a path planning module running on the CPU complex.

[0115] As another example, as required for Level 3, 4, or 5 driving, multiple neural networks can run simultaneously. For example, a warning sign consisting of "Caution: Flashing lights indicate icing conditions" along with a light can be interpreted by several neural networks, either independently or collectively. The sign itself can be identified as a traffic sign by a first neural network deployed (e.g., a trained neural network), and the text "Flashing lights indicate icing conditions" can be interpreted by a second neural network deployed, which informs the vehicle's path planning software (preferably executing on a CPU complex) that icing conditions exist when the flashing lights are detected. The flashing lights can be identified by operating a third neural network deployed over multiple frames, which informs the vehicle's path planning software of the presence (or absence) of the flashing lights. All three neural networks can run simultaneously, for example, within the DLA and / or on GPU 108.

[0116] In some examples, a CNN for facial recognition and owner recognition can use data from a camera sensor to identify the presence of an authorized driver and / or owner of the vehicle 100. An always-on sensor processing engine can be used to unlock the vehicle and turn on the lights when the owner approaches the driver's door, and in security mode, disable the vehicle when the owner leaves the vehicle. In this way, the SoC 104 provides security against theft and / or carjacking.

[0117] In another example, a CNN for emergency vehicle detection and identification can use data from microphone 196 to detect and identify emergency vehicle sirens. In contrast to conventional systems that use general classifiers to detect sirens and manually extract features, SoC 104 uses CNNs to classify environmental and urban sounds and to classify visual data. In a preferred embodiment, the CNN running on the DLA is trained to identify the relative closing speed of emergency vehicles (for example, by using the Doppler effect). The CNN can also be trained to identify emergency vehicles specific to the local area in which the vehicle is operating, as identified by the GNSS sensor 158. Thus, for example, when operating in Europe, the CNN will seek to detect European sirens, and when in the United States, the CNN will seek to identify only North American sirens. Once an emergency vehicle is detected, with the assistance of the ultrasonic sensor 162, the control program can be used to execute emergency vehicle safety routines, slowing the vehicle, pulling to the side of the road, stopping the vehicle, and / or idling the vehicle until the emergency vehicle passes.

[0118] The vehicle may include a CPU 118 (e.g., a discrete CPU or dCPU) that may be coupled to the SoC 104 via a high-speed interconnect (e.g., PCIe). The CPU 118 may include, for example, an X86 processor. The CPU 118 may be used to perform any of a variety of functions, including, for example, arbitrating potentially inconsistent results between ADAS sensors and the SoC 104, and / or monitoring the status and health of the controller 136 and / or the infotainment SoC 130.

[0119] The vehicle 100 may include a GPU 120 (e.g., a discrete GPU or dGPU) that may be coupled to the SoC 104 via a high-speed interconnect (e.g., NVIDIA's NVLINK). The GPU 120 may provide additional artificial intelligence functionality, for example, by executing redundant and / or different neural networks, and may be used to train and / or update the neural network based on input (e.g., sensor data) from sensors of the vehicle 100.

[0120] The vehicle 100 may further include a network interface 124, which may include one or more wireless antennas 126 (e.g., one or more wireless antennas for different communication protocols, such as a cellular antenna, a Bluetooth antenna, etc.). The network interface 124 can be used to enable wireless connections to the cloud (e.g., to a server 178 and / or other network devices), to other vehicles, and / or to computing devices (e.g., a passenger's client device) via the Internet. To communicate with other vehicles, a direct link can be established between the two vehicles, and / or an indirect link can be established (e.g., across a network and through the Internet). The direct link can be provided using a vehicle-to-vehicle communication link. The vehicle-to-vehicle communication link can provide the vehicle 100 with information about vehicles approaching the vehicle 100 (e.g., vehicles in front of, to the sides of, and / or behind the vehicle 100). This functionality can be part of the cooperative adaptive cruise control functionality of the vehicle 100.

[0121] The network interface 124 may include a SoC that provides modulation and demodulation functions and enables the controller 136 to communicate over a wireless network. The network interface 124 may include an RF front-end for up-conversion from baseband to RF and down-conversion from RF to baseband. The frequency conversion may be performed by well-known processes and / or may be performed using a super-heterodyne process. In some examples, the RF front-end functionality may be provided by a separate chip. The network interface may include wireless functionality for communicating over LTE, WCDMA, UMTS, GSM, CDMA2000, Bluetooth, Bluetooth LE, Wi-Fi, Z-wave, ZigBee, LoRaWAN, and / or other wireless protocols.

[0122] The vehicle 100 may further include data storage 128, which may include off-chip storage (e.g., outside the SoC 104). The data storage 128 may include one or more storage elements, including RAM, SRAM, DRAM, VRAM, flash memory, a hard disk, and / or other components and / or devices that can store at least one bit of data.

[0123] The vehicle 100 may further include a GNSS sensor 158. The GNSS sensor 158 (e.g., GPS, assisted GPS sensor, differential GPS (DGPS) sensor, etc.) is used to assist with mapping, perception, occupancy grid generation, and / or path planning functions. Any number of GNSS sensors 158 may be used, including, for example and without limitation, GPS using a USB connector with an Ethernet to serial (RS-232) bridge.

[0124] The vehicle 100 may further include a RADAR sensor 160. The RADAR sensor 160 may be used by the vehicle 100 for remote vehicle detection even in darkness and / or in adverse weather conditions. The RADAR functional safety level may be ASIL B. The RADAR sensor 160 may use CAN and / or bus 102 (e.g., to transmit data generated by the RADAR sensor 160) for control and access to object tracking data, and in some examples access Ethernet to access raw data. A variety of RADAR sensor types may be used. For example and without limitation, the RADAR sensor 160 may be suitable for front, rear, and side RADAR use. In some examples, a pulsed Doppler RADAR sensor is used.

[0125] The RADAR sensor 160 can include different configurations, such as long-range with a narrow field of view, short-range with a wide field of view, short-range side coverage, and so on. In some examples, long-range RADAR can be used for adaptive cruise control functions. The long-range RADAR system can provide a wide field of view (e.g., within 250m) achieved through two or more independent browsing. The RADAR sensor 160 can help distinguish between static objects and moving objects and can be used by the ADAS system for emergency braking assistance and forward collision warning. The long-range RADAR sensor may include a single-station multimode RADAR with multiple (e.g., six or more) fixed RADAR antennas and high-speed CAN and FlexRay interfaces. In the example with six antennas, the central four antennas can create a focused beam pattern that is designed to record the surroundings of the vehicle 100 at a higher rate with minimal traffic interference from adjacent lanes. The other two antennas can expand the field of view, making it possible to quickly detect vehicles entering or leaving the lane of the vehicle 100.

[0126] As an example, a medium-range RADAR system may include a range of up to 160m (front) or 80m (rear) and a field of view of up to 42 degrees (front) or 150 degrees (rear). A short-range RADAR system may include, but is not limited to, a RADAR sensor designed to be mounted on both ends of the rear bumper. When mounted on both ends of the rear bumper, such a RADAR sensor system can create two beams that continuously monitor the blind spots behind and beside the vehicle.

[0127] Short-range RADAR systems can be used in ADAS systems for blind spot detection and / or lane change assistance.

[0128] The vehicle 100 may further include ultrasonic sensors 162. The ultrasonic sensors 162, which may be located on the front, rear, and / or sides of the vehicle 100, may be used for parking assistance and / or for creating and updating an occupancy grid. A variety of ultrasonic sensors 162 may be used, and different ultrasonic sensors 162 may be used for different detection ranges (e.g., 2.5 m, 4 m). The ultrasonic sensors 162 may operate at functional safety level ASIL B.

[0129] The vehicle 100 may include a LiDAR sensor 164. The LiDAR sensor 164 may be used for object and pedestrian detection, emergency braking, collision avoidance, and / or other functions. The LiDAR sensor 164 may be ASIL B functional safety level. In some examples, the vehicle 100 may include multiple LiDAR sensors 164 (e.g., two, four, six, etc.) that may use Ethernet (e.g., to provide data to a Gigabit Ethernet switch).

[0130] In some examples, the LiDAR sensor 164 may be capable of providing a list of objects and their distances for a 360-degree field of view. Commercially available LiDAR sensors 164 may have, for example, an advertised range of approximately 100 meters, an accuracy of 2-3 cm, and support for 100 Mbps Ethernet connections. In some examples, one or more non-obtrusive LiDAR sensors 164 may be used. In such examples, the LiDAR sensor 164 may be implemented as a small device that can be embedded in the front, back, sides, and / or corners of the vehicle 100. In such examples, the LiDAR sensor 164 may provide a field of view of up to 120 degrees horizontally and 35 degrees vertically, with a range of 200 meters, even for low-reflectivity objects. The front-mounted LiDAR sensor 164 may be configured for a horizontal field of view between 45 and 135 degrees.

[0131] In some examples, LiDAR technologies such as 3D flash LiDAR may also be used. 3D flash LiDAR uses flashes of laser as an emission source to illuminate the vehicle's surroundings up to about 200 m. The flash LiDAR unit includes a receiver that records the laser pulse transmission time and the reflected light on each pixel, which in turn corresponds to the range from the vehicle to the object. Flash LiDAR can allow a highly accurate and distortion-free image of the surrounding environment to be generated with each laser flash. In some examples, four flash LiDAR sensors can be deployed, one on each side of the vehicle 100. Available 3D flash LiDAR systems include solid-state 3D staring array LiDAR cameras (e.g., non-browsing LiDAR devices) with no moving parts other than a fan. The flash LiDAR device can use 5 nanosecond Class I (eye-safe) laser pulses per frame and can capture the reflected laser light in the form of a 3D range point cloud and co-registered intensity data. By using flash LiDAR, and because flash LiDAR is a solid-state device with no moving parts, the LiDAR sensor 164 may be less susceptible to motion blur, vibration, and / or shock.

[0132] The vehicle may further include an IMU sensor 166. In some examples, the IMU sensor 166 may be located at the center of the rear axle of the vehicle 100. The IMU sensor 166 may include, for example and without limitation, an accelerometer, a magnetometer, a gyroscope, a magnetic compass, and / or other sensor types. In some examples, such as in a six-axis application, the IMU sensor 166 may include an accelerometer and a gyroscope, while in a nine-axis application, the IMU sensor 166 may include an accelerometer, a gyroscope, and a magnetometer.

[0133] In some embodiments, the IMU sensor 166 can be implemented as a miniature, high-performance GPS-assisted inertial navigation system (GPS / INS) that combines micro-electromechanical systems (MEMS) inertial sensors, a high-sensitivity GPS receiver, and advanced Kalman filtering algorithms to provide estimates of position, velocity, and attitude. Thus, in some examples, the IMU sensor 166 can enable the vehicle 100 to estimate heading without requiring input from a magnetic sensor by directly observing and correlating velocity changes from the GPS to the IMU sensor 166. In some examples, the IMU sensor 166 and the GNSS sensor 158 can be combined into a single integrated unit.

[0134] The vehicle may include microphones 196 positioned in and / or around the vehicle 100. The microphones 196 may be used for, among other things, emergency vehicle detection and identification.

[0135] The vehicle may further include any number of camera types, including stereo cameras 168, wide angle cameras 170, infrared cameras 172, surround cameras 174, long and / or medium range cameras 198, and / or other camera types. These cameras may be used to capture image data around the entire periphery of the vehicle 100. The type of camera used depends on the implementation and the requirements of the vehicle 100, and any combination of camera types may be used to provide the necessary coverage around the vehicle 100. Additionally, the number of cameras may vary depending on the implementation. For example, the vehicle may include six cameras, seven cameras, ten cameras, twelve cameras, and / or another number of cameras. As an example and not limitation, the cameras may support Gigabit Multimedia Serial Link (GMSL) and / or Gigabit Ethernet. Each of the cameras described herein may include a 10GbE compliant Ethernet port. Figure 1A and Figure 1B Described in more detail.

[0136] Vehicle 100 may further include a vibration sensor 142. Vibration sensor 142 can measure vibrations of vehicle components, such as axles. For example, changes in vibration can indicate changes in the road surface. In another example, when two or more vibration sensors 142 are used, the difference between the vibrations can be used to determine friction or slippage of the road surface (e.g., when there is a vibration difference between a powered axle and a freely rotating axle).

[0137] The vehicle 100 may include an ADAS system 138. In some examples, the ADAS system 138 may include a SoC. The ADAS system 138 may include autonomous / adaptive / automatic cruise control (ACC), cooperative adaptive cruise control (CACC), forward collision warning (FCW), automatic emergency braking (AEB), lane departure warning (LDW), lane keeping assist (LKA), blind spot warning (BSW), rear cross traffic warning (RCTW), collision warning system (CWS), lane centering (LC), and / or other features and functions.

[0138] The ACC system may utilize RADAR sensors 160, LIDAR sensors 164, and / or cameras. The ACC system may include longitudinal ACC and / or lateral ACC. Longitudinal ACC monitors and controls the distance to the vehicle immediately in front of vehicle 100, automatically adjusting the vehicle speed to maintain a safe distance from the vehicle ahead. Lateral ACC maintains distance and, when necessary, recommends lane changes for vehicle 100. Lateral ACC is related to other ADAS applications such as LCA and CWS.

[0139] CACC uses information from other vehicles, which may be received from other vehicles indirectly via a wireless link or via a network connection (e.g., via the Internet) via the network interface 124 and / or wireless antenna 126. A direct link may be provided by a vehicle-to-vehicle (V2V) communication link, while an indirect link may be an infrastructure-to-vehicle (I2V) communication link. Typically, the V2V communication concept provides information about the vehicle immediately ahead (e.g., the vehicle immediately ahead of the vehicle 100 and in the same lane as it), while the I2V communication concept provides information about traffic further ahead. A CACC system may include either or both I2V and V2V information sources. Given information about the vehicle ahead of the vehicle 100, CACC may be more reliable, and it has the potential to improve the smoothness of traffic flow and reduce road congestion.

[0140] The FCW system is designed to alert the driver to hazards so that the driver can take corrective action. The FCW system uses a front-facing camera and / or RADAR sensor 160 coupled to a dedicated processor, DSP, FPGA, and / or ASIC, which is electrically coupled to driver feedback such as a display, speaker, and / or vibrating component. The FCW system can provide warnings in the form of, for example, audible, visual warnings, vibrations, and / or rapid brake pulses.

[0141] The AEB system detects an impending forward collision with another vehicle or other object and can automatically apply the brakes if the driver does not take corrective action within specified time or distance parameters. The AEB system may use a front-facing camera and / or RADAR sensor 160 coupled to a dedicated processor, DSP, FPGA and / or ASIC. When the AEB system detects a hazard, it typically first alerts the driver to take corrective action to avoid the collision, and if the driver does not take corrective action, the AEB system may automatically apply the brakes in an effort to prevent or at least mitigate the effects of the predicted collision. The AEB system may include technologies such as dynamic brake support and / or collision approach braking.

[0142] The LDW system provides visual, audible, and / or tactile warnings, such as steering wheel or seat vibrations, to alert the driver when the vehicle 100 crosses a lane marking. When the driver indicates an intention to leave the lane by activating a turn signal, the LDW system is deactivated. The LDW system may utilize a front-facing camera coupled to a dedicated processor, DSP, FPGA, and / or ASIC that is electrically coupled to driver feedback such as a display, speaker, and / or vibration components.

[0143] The LKA system is a variation of the LDW system. If the vehicle 100 begins to leave its lane, the LKA system provides steering input or braking to correct the vehicle 100.

[0144] The BSW system detects and warns the driver of vehicles in the car's blind spot. The BSW system can provide visual, audible, and / or tactile alerts to indicate that merging or changing lanes is unsafe. The system can provide additional warnings when the driver uses a turn signal. The BSW system can use one or more rear-facing cameras and / or one or more RADAR sensors 160 coupled to a dedicated processor, DSP, FPGA, and / or ASIC (which is electrically coupled to driver feedback, such as a display, speaker, and / or vibration component).

[0145] The RCTW system can provide visual, audible, and / or tactile notifications when an object is detected outside the range of the rear-mounted camera while the vehicle 100 is in reverse. Some RCTW systems include AEB to ensure that the vehicle brakes are applied to avoid a collision. The RCTW system can use one or more rear-mounted RADAR sensors 160 coupled to a dedicated processor, DSP, FPGA, and / or ASIC that is electrically coupled to driver feedback such as a display, speaker, and / or vibration component.

[0146] Conventional ADAS systems can be prone to false positive results, which can be annoying and distracting to the driver, but are typically not catastrophic because the ADAS system alerts the driver and allows the driver to decide whether a safety condition actually exists and act accordingly. However, in the autonomous vehicle 100, in the event of conflicting results, the vehicle 100 itself must decide whether to heed the results from the primary computer or the auxiliary computer (e.g., the first controller 136 or the second controller 136). For example, in some embodiments, the ADAS system 138 can be a backup and / or auxiliary computer for providing perception information to the backup computer rationality module. The backup computer rationality monitor can run redundant and diverse software on hardware components to detect failures in perception and dynamic driving tasks. The output from the ADAS system 138 can be provided to the supervisory MCU. If the outputs from the primary and auxiliary computers conflict, the supervisory MCU must determine how to reconcile the conflict to ensure safe operation.

[0147] In some examples, the primary computer can be configured to provide a confidence score to the supervisory MCU, indicating the primary computer's confidence in the selected result. If the confidence score exceeds a threshold, the supervisory MCU can follow the primary computer's direction, regardless of whether the secondary computer provides conflicting or inconsistent results. In the event that the confidence score does not meet the threshold and the primary and secondary computers indicate different results (e.g., a conflict), the supervisory MCU can arbitrate between these computers to determine the appropriate result.

[0148] The supervisory MCU can be configured to run a neural network that is trained and configured to determine, based on outputs from the primary and secondary computers, conditions under which the secondary computer provides a false alarm. Thus, the neural network in the supervisory MCU can learn when the output of the secondary computer can be trusted and when it cannot. For example, when the secondary computer is a RADAR-based FCW system, the neural network in the supervisory MCU can learn when the FCW system is identifying a metal object that is not actually a danger, such as a drain grate or manhole cover that triggers an alarm. Similarly, when the secondary computer is a camera-based LDW system, the neural network in the supervisory MCU can learn to disregard the LDW when a cyclist or pedestrian is present and lane departure is actually the safest strategy. In embodiments that include a neural network running on the supervisory MCU, the supervisory MCU can include at least one of a DLA or a GPU suitable for running the neural network with associated memory. In a preferred embodiment, the supervisory MCU can include and / or be included as a component of the SoC 104.

[0149] In other examples, the ADAS system 138 may include an auxiliary computer that uses traditional computer vision rules to perform ADAS functions. In this way, the auxiliary computer can use classic computer vision rules (if-then), and the presence of a neural network in the supervisory MCU can improve reliability, safety, and performance. For example, diverse implementations and intentional non-identity make the entire system more fault-tolerant, especially with respect to failures caused by software (or software-hardware interface) functions. For example, if there is a software vulnerability or bug in the software running on the main computer and the non-identical software code running on the auxiliary computer provides the same overall result, the supervisory MCU can be more confident that the overall result is correct and that the vulnerability in the software or hardware on the main computer did not cause a substantial error.

[0150] In some examples, the output of the ADAS system 138 can be fed into the primary computer's perception block and / or the primary computer's dynamic driving task block. For example, if the ADAS system 138 indicates a forward collision warning due to an object immediately ahead, the perception block can use this information when identifying the object. In other examples, the secondary computer can have its own neural network that is trained and thus reduces the risk of false positives as described herein.

[0151] The vehicle 100 may further include an infotainment SoC 130 (e.g., an in-vehicle infotainment system (IVI)). Although illustrated and described as an SoC, the infotainment system may not be an SoC and may include two or more separate components. The infotainment SoC 130 may include a combination of hardware and software that can be used to provide audio (e.g., music, personal digital assistant, navigation instructions, news, radio, etc.), video (e.g., TV, movies, streaming, etc.), phone (e.g., hands-free calling), network connectivity (e.g., LTE, Wi-Fi, etc.), and / or information services (e.g., a navigation system, rear parking assistance, radio data system, vehicle-related information such as fuel level, total distance covered, brake fuel level, oil level, door open / closed, air filter information, etc.) to the vehicle 100. For example, the infotainment SoC 130 may include a radio, a disc player, a navigation system, a video player, USB and Bluetooth connectivity, an onboard computer, in-vehicle entertainment, Wi-Fi, steering wheel audio controls, hands-free voice controls, a head-up display (HUD), an HMI display 134, a telematics device, a control panel (e.g., for controlling and / or interacting with various components, features, and / or systems), and / or other components. The infotainment SoC 130 may further be used to provide information (e.g., visual and / or auditory) to a user of the vehicle, such as information from an ADAS system 138, autonomous driving information such as planned vehicle maneuvers, trajectories, surrounding environment information (e.g., intersection information, vehicle information, road information, etc.), and / or other information.

[0152] The infotainment SoC 130 may include GPU functionality. The infotainment SoC 130 may communicate with other devices, systems, and / or components of the vehicle 100 via a bus 102 (e.g., a CAN bus, Ethernet, etc.). In some examples, the infotainment SoC 130 may be coupled to a supervisory MCU so that in the event of a failure of a primary controller 136 (e.g., a primary and / or backup computer of the vehicle 100), the infotainment system's GPU may perform some self-driving functions. In such an example, the infotainment SoC 130 may place the vehicle 100 in a driver-safe parking mode as described herein.

[0153] The vehicle 100 may further include an instrument cluster 132 (e.g., a digital instrument panel, an electronic instrument cluster, a digital instrument panel, etc.). The instrument cluster 132 may include a controller and / or a supercomputer (e.g., a separate controller or a supercomputer). The instrument cluster 132 may include a set of instruments, such as a speedometer, fuel level, oil pressure, a tachometer, an odometer, a turn indicator, a shift position indicator, a seat belt warning light, a parking brake warning light, an engine check light, airbag (SRS) system information, lighting controls, safety system controls, navigation information, etc. In some examples, information may be displayed and / or shared between the infotainment SoC 130 and the instrument cluster 132. In other words, the instrument cluster 132 may be included as part of the infotainment SoC 130, or vice versa.

[0154] Figure 1D For cloud-based servers and Figure 1A 180 ). FIG. 176 is a system diagram illustrating communication between an example autonomous vehicle 100 and a server 178 . System 176 may include a server 178 , a network 190 , and a vehicle including vehicle 100 . Server 178 may include multiple GPUs 184 (A)-184 (H) (collectively referred to herein as GPUs 184 ), PCIe switches 182 (A)-182 (H) (collectively referred to herein as PCIe switches 182 ), and / or CPUs 180 (A)-180 (B) (collectively referred to herein as CPUs 180 ). GPUs 184 , CPUs 180 , and PCIe switches may be interconnected with a high-speed interconnect and / or PCIe connection 186 , such as, for example and without limitation, an NVLink interface 188 developed by NVIDIA. In some examples, GPUs 184 are connected via NVLink and / or NVSwitch SoC, and GPUs 184 and PCIe switches 182 are connected via a PCIe interconnect. Although eight GPUs 184 , two CPUs 180 , and two PCIe switches are illustrated, this is not intended to be limiting. Depending on the implementation, each of the servers 178 can include any number of GPUs 184, CPUs 180, and / or PCIe switches. For example, each of the servers 178 can include eight, sixteen, thirty-two, and / or more GPUs 184.

[0155] Server 178 can receive image data from a vehicle via network 190, the image data representing images showing unexpected or changed road conditions, such as recently begun road construction. Server 178 can transmit neural network 192, updated neural network 192, and / or map information 194, including information about traffic and road conditions, via network 190 and to the vehicle. Updates to map information 194 can include updates to HD map 122, such as information about construction sites, potholes, curves, flooding, or other obstacles. In some examples, neural network 192, updated neural network 192, and / or map information 194 can be generated from new training and / or data received from any number of vehicles in the environment and / or based on experience from training performed at a data center (e.g., using server 178 and / or other servers).

[0156] Server 178 can be used to train a machine learning model (e.g., a neural network) based on training data. The training data can be generated by the vehicle and / or can be generated in simulation (e.g., using a game engine). In some examples, the training data is labeled (e.g., in cases where the neural network benefits from supervised learning) and / or undergoes other preprocessing, while in other examples, the training data is not labeled and / or preprocessed (e.g., in cases where the neural network does not require supervised learning). Training can be performed according to any one or more classes of machine learning techniques, including but not limited to the following: supervised training, semi-supervised training, unsupervised training, self-learning, reinforcement learning, federated learning, transfer learning, feature learning (including principal component and cluster analysis), multilinear subspace learning, manifold learning, representation learning (including alternative dictionary learning), rule-based machine learning, anomaly detection, and any variants or combinations thereof. Once the machine learning model is trained, the machine learning model can be used by the vehicle (e.g., transmitted to the vehicle via network 190), and / or the machine learning model can be used by server 178 to remotely monitor the vehicle.

[0157] In some examples, server 178 can receive data from the vehicle and apply the data to the latest real-time neural network for real-time intelligent reasoning. Server 178 can include a deep learning supercomputer and / or a dedicated AI computer powered by GPU 184, such as the DGX and DGX Station machines developed by NVIDIA. However, in some examples, server 178 can include the deep learning infrastructure of a data center using only CPU power.

[0158] The deep learning infrastructure of server 178 may be capable of rapid real-time inference and may use this capability to assess and verify the health of the processors, software, and / or associated hardware in vehicle 100. For example, the deep learning infrastructure may receive periodic updates from vehicle 100, such as an image sequence and / or objects that vehicle 100 has located within the image sequence (e.g., via computer vision and / or other machine learning object classification techniques). The deep learning infrastructure may run its own neural network to identify objects and compare them to those identified by vehicle 100, and if the results do not match and the infrastructure concludes that the AI ​​in vehicle 100 has malfunctioned, server 178 may transmit a signal to vehicle 100 instructing the vehicle's 100 fail-safe computer to take control, notify passengers, and complete a safe parking maneuver.

[0159] For inference, server 178 may include a GPU 184 and one or more programmable inference accelerators (e.g., NVIDIA's TensorRT 3). The combination of GPU-powered servers and inference acceleration can enable real-time responses. In other examples, such as where performance is less important, CPU, FPGA, and other processor-powered servers can be used for inference.

[0160] Figure 2 is a block diagram of an example system for monitoring a sensor fusion system (e.g., sensor fusion monitoring system 200) according to some embodiments of the present disclosure. The sensor fusion monitoring system 200 (or "multi-sensor fusion (MSF) monitoring system" or "monitoring system") can provide health and safety monitoring technology that can meet functional safety requirements (e.g., ASILB, ASIL D, etc.). The monitoring system 200 can provide an error signal to an error handling system (e.g., error handling system 290), which can be used to shut down functions of the sensor fusion system (e.g., MSF system) or any functions of the entire system (e.g., a system including the autonomous vehicle 100, server 178, data center 600, etc.). For example, if a critical sensor fusion error exists, the error handling system 290 can shut down the automatic emergency braking (AEB) function. The monitoring system 200 can provide a health error signal (e.g., MSF error / health signal 283) for detailed debugging of safety-critical errors. The monitoring system 200 can provide validity information to systems downstream of the sensor fusion system (e.g., systems or nodes that can perform positioning, mapping, path planning, decision-making, or vehicle control, etc.) so that the downstream system can identify whether the output of the sensor fusion is reliable.

[0161] In short, the monitoring system 200 may include or be coupled to any one of one or more perception systems 210-1, ..., 210-k (hereinafter referred to as perception systems 210), one or more ego-motion systems 212, and one or more sensor fusion nodes (e.g., MSF nodes 220). The MSF nodes 220 may include one or more sensor fusion modules (e.g., MSF modules 240). In various embodiments, an autonomous vehicle may include one or more MSF nodes. In various embodiments, an MSF node may correspond to one or more autonomous vehicles. In various embodiments, the MSF nodes 220 (or their MSF modules 240) may be implemented and / or executed by hardware, firmware, and / or software in a computing device (e.g., computing device 500), a server (e.g., server 178), or a data center (e.g., data center 600).

[0162] Reference Figure 2 , any one or more perception systems 210 may (1) include at least one sensor and / or receive data from at least one sensor (e.g., a RADAR sensor, a LiDAR sensor, an ultrasonic sensor, a stereo camera, a wide-angle camera, an infrared camera, a surround camera, a long-range camera, or a mid-range camera), (2) detect one or more objects (e.g., obstacles) from the data, and / or (3) output perception data (e.g., detected objects, states or attributes of detected objects) to the MSF node 220 (or its MSF module 240). In various embodiments, each of the one or more ego-motion systems 212 may (1) include at least one sensor and / or receive data (e.g., raw sensor data) from at least one sensor (e.g., a GNSS sensor, a GPS sensor, an IMU sensor, an accelerometer, a gyroscope, a magnetic compass, a magnetometer, a microphone, a speed sensor, a vibration sensor, a steering sensor, or a brake sensor), (2) filter the data, (3) aggregate the data (e.g., aggregate raw sensor data from multiple sensors), (4) generate (or extract) ego-motion data from the data, and / or (5) output the ego-motion data to the MSF node 220 (e.g., its MSF module 240).

[0163] The MSF module 240 (e.g., the MSF core module 250 of the MSF module 240) may receive sensory data 211-1, ..., 211-k (hereinafter referred to as sensory data 211) from the corresponding sensory system 210, may receive ego-motion data 213 from the corresponding motion system 212, and / or may receive node input evaluation data 235 (described below) from the node input monitor 230. The MSF module 240 may perform a fusion of the sensory data and the ego-motion data to generate output data 253 (e.g., representations of one or more fused objects and attributes of one or more fused objects). For example, the MSF module 240 may use the sensory data and the ego-motion data to generate output data 253 indicating at least one of the (relative or absolute) position, velocity, acceleration, Doppler, color, and / or transparency of one or more detected objects, including, but not limited to, weighting based on the sensory data and the ego-motion data. The MSF module 240 may transmit the output data 253 to other systems or nodes 295 (e.g., systems or nodes that may perform localization, mapping, path planning, decision-making, or vehicle control, etc.).

[0164] The MSF core module 250 may generate one or more error signals 251-1, ..., 251-m (hereinafter referred to as error signals 251). The MSF core module 250 may generate the error signals 251 to indicate, for example, but not limited to, a functional error or a safety-related error in the MSF core module 250. As further described herein, the MSF core module 250 may generate the error signals 251 in response to an evaluation of data received from the sensor and / or perception system 210.

[0165] The MSF core module 250 may include modules (or submodules) for an MSF interface 252, a prediction 254, and / or a measurement update 256. The MSF interface 252 may receive sensory data from the perception system 210, may receive ego-motion data (e.g., position data) from one or more ego-motion systems 212, and / or may send output data 253 to other systems or nodes 295. In some embodiments, the MSF interface may receive data from sensors and schedule the order in which input data is processed in a fusion module (e.g., an MSF module). In some embodiments, the MSF interface may include a sub-block (e.g., a sub-module) called a scheduler (not shown) that performs scheduling operations. In some embodiments, the MSF interface may include a track management sub-block (not shown).

[0166] The prediction module 254 may perform prediction of the state and / or attributes of an object to perform fusion of the object with other objects. The measurement update module 256 may update the measurement value of the object to accurately perform prediction or fusion.

[0167] Further references Figure 2 , the monitoring system 200 for monitoring the MSF system may include one or more or various combinations of node-level monitors 230, 270, module-level monitors 260, and an error handling system 290 (or error handling node). The node-level monitors 230, 270 may check higher-level signals and states, such as input data validity and / or input data delay. For example, node-level signals and states may have a relatively higher level than module-level signals and states. On the other hand, the module-level monitor 260 may check lower-level signals and states, such as the internal structure of a multi-sensor fusion (MSF) process. Based on the data output from the monitoring system 200, the error handling system 290 may control the MSF system or the entire system (e.g., a system including the autonomous vehicle 100, the server 178, the data center 600, etc.), or shut down any function of the MSF system or the entire system.

[0168] Node-level monitors may include node input monitors 230 and / or node output monitors 270. Module-level monitors may include MSF health monitors 260, which include module input monitors 262, MSF core monitors 264, module output monitors 266, and / or status and error handlers 280.

[0169] The node input monitor 230 can evaluate received input data (e.g., input data received from the systems 210 and 212 to be used by the MSF node 220 for sensor fusion operations) to perform error detection and / or health assessment on the received input data. For example, the node input monitor 230 can receive perception data 211 from the corresponding perception system 210 and can receive ego-motion data 213 from the corresponding ego-motion system 212, and can perform an assessment on the perception data 211 and / or the ego-motion data 212. The node input monitor 230 can generate node input assessment data 235 (e.g., data indicating the validity of the perception data) or one or more error signals 237 (e.g., signals indicating a functional error or a safety-related error of the MSF core module) based on the results of the assessment.

[0170] The module input monitor 262 can evaluate or check key attributes of input data (e.g., perception data 211, ego-motion data 213), and can determine whether the output 253 of the MSF system (e.g., fused objects or obstacles) is valid based on the results of the evaluation or checking (e.g., the validity of the input data). The module input monitor 262 can receive perception data 211 from the corresponding perception system 210, receive ego-motion data 213 from the corresponding ego-motion system 212, and receive node input evaluation data 235 from the node input monitor 230, perform an evaluation on the received data, generate module input evaluation data 263 based on the results of the evaluation, and send the module input evaluation data 263 (e.g., data indicating validity and / or errors) to the status and error processor 280.

[0171] The MSF core monitor 264 can monitor the internal processing of the sensor fusion system (e.g., the internal processing of the MSF core module 250) and can perform checks, evaluations, or analyses that may not be handled by the unit tests. The MSF core monitor 264 can receive error signals 251 from the MSF core module 250, perform an evaluation on one or more received error signals, generate module core evaluation data 265 based on the results of the evaluation, and send the module core evaluation data 265 (e.g., data indicating validity and / or errors) to the status and error handler 280.

[0172] The module output monitor 266 may perform various evaluations or checks on the output 253 (e.g., a fused object or obstacle) generated by the sensor fusion system. The module output monitor 266 may receive the output data 253 generated by the MSF core module 250, may perform an evaluation on the received output data, may generate module output evaluation data 267 based on the results of the evaluation, and may send the module output evaluation data 267 (e.g., data indicating validity and / or errors) to the status and error handler 280.

[0173] The status and error processor 280 can determine whether an error has occurred in the inputs of the MSF system (e.g., the sensory data 211, the ego-motion data 213), the core module 250 of the MSF system, or the outputs 253 of the MSF system. The status and error processor 280 can receive module input evaluation data 263 (from the module input monitor 262), module core evaluation data 265 (from the MSF core monitor 264), and / or module output evaluation data 267 (from the module output monitor 266), can perform an evaluation on the received evaluation data 263, 265, 267, and can generate, based on the results of the evaluation: (1) validity data 281 (e.g., the validity of data related to the MSF core module 250) and / or (2) a signal 283 indicating an error and / or health of the MSF core module. The node output monitor 270 can receive output data 253 (e.g., output data 253 from the MSF core module 250), validity data 281 (e.g., validity data 281 from the status and error processor 280), and / or MSF error / health signals 283 (e.g., MSF error or health signals 283 from the status and error processor 280), can perform an evaluation on the received data, and can generate, based on the results of the evaluation: (1) node output evaluation data 271 (e.g., data indicating the validity of the fused data) and / or (2) a signal 272 indicating an error and / or health of the MSF node 220.

[0174] Further references Figure 2, the node input monitor 230 can evaluate or check whether the inputs of the MSF system (e.g., input data from multiple sensors, perception data 211 and / or ego-motion data 213) are missing, delayed (e.g., arriving too late), outdated (e.g., the input information has not been updated in multiple iterations), or invalid. If any of these events occurs, the node input monitor 230 can send one or more error messages 237 to the error handling system 290. The node input monitor 230 can send information (e.g., node input evaluation data 235 regarding the validity of the input data) to the MSF core module 250 and / or the MSF input monitor 262 within the MSF health monitor 260. Using the node input evaluation data 235, the MSF core module 250 can handle degradations within the MSF system (e.g., invalidity of fusion output, degradation of system functionality, functional or safety-related errors, etc.) based on problems with the input data (as indicated in the node input evaluation data 235). For example, if the RADAR perception data is invalid, the MSF core module 250 can allow a longer slide of the camera-only obstacle (e.g., allowing more camera-only data samples to be detected until a system-level error is detected) and adjust how the confidence is calculated. Input error events can also cause the obstacle fusion output to be set to invalid - either directly or after a number of cycles of consistent errors. For example, if an error occurs on the RADAR perception data (e.g., an object or obstacle detected by the RADAR) for more than a predetermined number of execution cycles (e.g., the execution cycles in which the fusion is performed), the monitoring system (e.g., the node output monitor 270) can set (or determine or detect or evaluate) the MSF output (e.g., the fused object or obstacle) as invalid in the node output evaluation data 271.

[0175] refer to Figure 2Given a current degraded state (e.g., a state where the fused output is invalid, a state where system functionality is degraded, a state associated with a functional or safety-related error, etc.), the node output monitor 270 can obtain information about the validity of the MSF system (e.g., MSF health assessment data 281) from the state and error processor 280 and determine the validity 271 of the fused objects / obstacles output from the MSF system (e.g., from the MSF core module). In various embodiments, the node output monitor 270 can perform the same checks or assessments as the node input monitor 230, but for the MSF node 220. The node output monitor 270 can define the expected cycle frequency and latency of the MSF node 220 and / or detect delayed or outdated nodes (e.g., whether the fused output of the MSF node 200 is delayed or outdated). The degraded state of the MSF can be determined by inspecting or evaluating the input data, output data, and / or internal processing of the MSF system (e.g., the MSF core module 250). The node output monitor 270 may use these information sources to set the validity 271 of the MSF core module as healthy (or valid or reliable or normal) or unhealthy (or invalid or unreliable or abnormal).

[0176] Further references Figure 2 , the MSF health monitor 260 can monitor dynamic MSF input data or signals (e.g., perception data 211, ego-motion data 213), as well as internal processing errors (e.g., internal processing errors of the MSF core module 250) and errors in the reported output of the MSF system (e.g., errors in the fused output 253 from the MSF core module 250). The MSF health monitor 260 can transmit error and health signals 283 directly to a system health service (not shown). For example, the system health service can be a system / node / service used to monitor and assess the status and health of an autonomous vehicle, server, or data center. Error and health signals 283 can include high-level errors based on the aggregation of individual errors (e.g., grouping errors that combine different types of errors). In addition, the MSF health monitor 260 can provide degradation status (e.g., valid or invalid, a state where the MSF system's functionality is degraded, a state related to a functional error or a safety-related error) to a consumer system 295 (e.g., a system or node that can perform localization, mapping, path planning, decision-making, or vehicle control) via metadata sent on a fused obstacle output port. For example, validity data 281 may contain metadata indicating the validity of a fusion object, and error and health signals 283 may contain metadata indicating the error / health status of the MSF system.

[0177] Further references Figure 2Module input monitor 262 can evaluate or check attributes of input data (e.g., input data validity); in some cases, these attributes may not be individually detected as erroneous or invalid on the producer side (e.g., perception system 210 or ego-motion system 212). Module input monitor 262 can determine whether the MSF system output 253 (e.g., a fused object or obstacle) is valid based on the results of the evaluation or check (e.g., input data validity). Table 1 below describes examples of evaluations or checks performed by module input monitor 262. Each evaluation or check can result in an error / health error signal (e.g., MSF error / health signal 283 generated by status and error handler 280) with an ID as shown in the table, which is sent to error handling system 290 or system health service (not shown). These errors resulting from the evaluation or check can help debug modules (e.g., MSF core module 250). In various embodiments, each evaluation or check performed by module input monitor 262 cannot send its own error signal to an error handler (e.g., status and error handler 280, error handling system 290, or system health service). In various embodiments, the MSF health monitor 260 (e.g., module input monitor 262, module core monitor 264, module output monitor 266) can determine the criticality of the errors and group or aggregate the errors into error messages based on the criticality. The error handling system 290 can then perform functional degradation based on the grouped errors.

[0178]

[0179]

[0180]

[0181] Table 1. Examples of evaluations or checks performed by module input monitors

[0182] In various embodiments, the evaluation or inspection of RADAR or camera as shown in Table 1 can be applied to other perception sensors, such as LiDAR sensors, ultrasonic sensors, stereo cameras, wide-angle cameras, infrared cameras, surround cameras, long-range cameras, or medium-range cameras. In various embodiments, the evaluation or inspection of RADAR or camera as shown in Table 1 can be applied to other ego-motion sensors, such as GNSS sensors or GPS sensors, IMU sensors, accelerometers, gyroscopes, magnetic compasses, magnetometers, microphones, speed sensors, vibration sensors, steering sensors, or brake sensors.

[0183] The MSF core monitor 264 can monitor the internal processing of the sensor fusion system (e.g., the internal processing of the MSF core module 250) and can perform checks, evaluations, or analyses that may not be handled by unit tests. To provide a safe and robust fusion system, the MSF core monitor 250 can perform checks, evaluations, or analyses, including a failure mode and effects analysis (FMEA), in which each step of the processing of an MSF module or system (e.g., the MSF core module 250) is analyzed for potential risks of violating functional safety requirements. Based on the output or results of the FMEA analysis, potential functional safety risks can be mitigated by unit tests or core monitor checks. Table 2, shown below, lists examples of internal evaluations or checks within a multi-sensor fusion process (e.g., the fusion process performed by the MSF core module 250). Each failed check can result in an error / health error signal (e.g., an MSF error / health signal 283 generated by the status and error handler 280) being sent to the error handling system 290 or a system health service (not shown).

[0184]

[0185]

[0186] Table 2. Examples of inspections or assessments for the MSF core modules

[0187] Further references Figure 2 , module output monitor 266 can perform various evaluations or checks on the output 253 (e.g., fused objects or obstacles) generated by the sensor fusion system. For example, module output monitor 266 can perform checks on each field (e.g., characteristics, attributes, size, position, velocity, acceleration, etc.) in the output data 253 to check whether it is within a specified range. Status and error handler 280 can determine whether an error has occurred in the input of the MSF system (e.g., perception data 211, ego-motion data 213), the core module 250 of the MSF system, or the output 253 of the MSF system, and can generate an MSF error / health signal 283 based on the result of the determination to be sent to the error handling system 290, other systems / nodes 295, and / or a system health service (not shown). Status and error handler 280 can determine whether the error is severe enough to invalidate the entire sensor fusion system (e.g., the entire MSF system) or the entire system (e.g., the entire autonomous vehicle 100, the entire server 178, or the entire data center 600).

[0188] Further references Figure 2, the monitoring system 200 can perform module degradation based on the outputs of the monitoring system (e.g., MSF error signal 237, MSF error / health signal 283, MSF error signal 272, fusion object validity 271). The monitoring system can have three main outputs: (1) validity information of the fused output (e.g., fusion object or obstacle); (2) error messages indicating errors in the inputs of the MSF system, the core modules of the MSF system, or the outputs of the MSF system; and / or (3) health messages indicating the presence or absence of reliable functionality and / or safety of the MSF system. The monitoring system 200 (e.g., the error handling system / node 290 or the node output monitor 270) can set (or provide) validity information in the fused output for downstream consumers (e.g., other systems / nodes 295) to inform whether the fused output 253 at the current frame (e.g., the fused output at the current execution cycle) meets the criteria to be trusted. Monitoring system 200 can send error messages (e.g., MSF error signal 237, MSF error / health signal 283, MSF error signal 272) to a system error handling module (e.g., error handling system 290) for potential functional degradation. Monitoring system 200 can send health messages (e.g., MSF error / health signal 283) to a health service for debugging purposes.

[0189] Figure 3 is a flow chart of an example process 300 for monitoring a sensor fusion system according to some embodiments of the present disclosure. Each block of the process 300 described herein comprises a computational process that may be performed using any combination of hardware, firmware, and / or software. For example, the various functions may be performed by a processor executing instructions stored in a memory. The process 300 may be embodied as computer usable instructions stored on a computer storage medium. The process 300 may be provided by a standalone application, a service or a hosted service (standalone or in combination with another hosted service), or a plug-in to another product, to name a few. The process 300 may be provided using a software package that is compatible with the system. Figure 1A-Figure 1D Example of autonomous vehicle 100, Figure 5 An example computing device 500, Figure 6 Example data center 600 and / or Figure 2 The process 300 may be performed by similar components, features, and / or functionality to the example sensor fusion monitoring system 200. However, the process 300 may additionally or alternatively be performed by any one system or any combination of systems, including but not limited to the systems described herein.

[0190] In various embodiments, a system (e.g., example autonomous vehicle 100, example computing device 500, example data center 600, example sensor fusion monitoring system 200, MSF system) can detect one or more fused objects by performing fusion of at least one or more first objects and one or more second objects during a plurality of execution cycles. The one or more first objects can be detected based at least on perception data (e.g., perception data 211-1) from one or more first sensors (e.g., RADAR) of the vehicle and / or position data (e.g., self-motion data 213) from one or more second sensors (e.g., ego-motion sensors) of the vehicle. The one or more second objects can be detected based at least on perception data (e.g., perception data 211-2) from one or more third sensors (e.g., cameras) of the vehicle and / or position data (e.g., self-motion data 213) from one or more third sensors of the vehicle.

[0191] Reference Figure 3 In process 300, at block B302, during a plurality of execution cycles, a system (e.g., perception system 210-1) may detect one or more first objects based on perception data (e.g., perception data 211-1) from one or more first sensors (e.g., RADAR). In various embodiments, a system (e.g., node input monitor 230) may determine that the one or more first objects are invalid. In various embodiments, the system (e.g., node input monitor 230) may report that the one or more first objects are invalid to another module or system (e.g., MSF core module 250, MSF health monitor 260, node output monitor 270, error handling system 290, system 295 external to MSF node 220).

[0192] At block B304, the system (e.g., node input monitor 230, module input monitor 262) may determine a first number of cycles during which the one or more first objects are determined to be invalid. In various embodiments, in response to determining that the first number of cycles is equal to a first threshold (e.g., determining that the one or more first objects remain invalid for x number of cycles, where x is a predetermined positive integer), the system may determine that the one or more fused objects are invalid and proceed to block B306.

[0193] At block B306 , in response to determining that the first number of cycles is equal to the first threshold, the system (e.g., node output monitor 270 ) may determine that one or more fused objects are invalid and / or generate a signal (e.g., signal 271 ) indicating that one or more fused objects are invalid.

[0194] At block B308, during a plurality of execution cycles, the system (e.g., perception system 210-2) may detect one or more second objects based on data from one or more third sensors (e.g., cameras). In various embodiments, the system (e.g., node input monitor 230) may determine that the one or more second objects are invalid. In various embodiments, the system (e.g., node input monitor 230) may report that the one or more second objects are invalid to another module or system (e.g., MSF health monitor 260, node output monitor 270, system 295 external to MSF node 220).

[0195] At block B310, the system (e.g., node input monitor 230, module input monitor 262) may determine a second number of cycles during which one or more second objects are determined to be invalid. In various embodiments, in response to determining that the second number of cycles is equal to a second threshold (e.g., determining that one or more second objects remain invalid for y number of cycles, where y is a predetermined positive integer and y may be different from x), the system may determine that the one or more fused objects are invalid and proceed to block B306. At block B306, in response to determining that the second number of cycles is equal to the second threshold, the system (e.g., node output monitor 270) may determine that the one or more fused objects are invalid and / or generate a signal (e.g., signal 271) indicating that the one or more fused objects are invalid.

[0196] At block B312, during a plurality of execution cycles, the system (e.g., node input monitor 230, module input monitor 262) may determine that the state of the vehicle (e.g., the state of the vehicle's motion) is invalid based on data from one or more second sensors (e.g., ego-motion sensors). In various embodiments, the system may report that the state is invalid to another module or system (e.g., MSF core module 250, MSF health monitor 260, node output monitor 270, error handling system 290, system 295 external to MSF node 220). At block B306, in response to reporting that the state is invalid, the system may determine that one or more fused objects are invalid and / or generate a signal (e.g., signal 271) indicating that the one or more fused objects are invalid.

[0197] At blocks B314 to B320, the system may determine whether one or more errors (e.g., missing, delayed, and / or outdated data or objects) occurred (or were reported) during the plurality of execution cycles. The one or more errors (e.g., MSF error signal 237, MSF error / health signal 283, MSF error signal 272) may be related to at least one of vehicle safety or execution fusion functionality. At block B306, in response to determining that one or more errors occurred (or were reported) during the plurality of execution cycles, the system (e.g., node output monitor 270) may determine that one or more fused objects are invalid and / or may generate a signal (e.g., signal 271) indicating that one or more fused objects are invalid.

[0198] At block B314 , the system (eg, MSF core module 250 , core monitor 264 ) may determine that one or more processing errors from the sensor fusion core module (eg, error signals 251 from the MSF core module 250 ) occurred during the plurality of execution cycles.

[0199] At block B316 , the system (eg, status and error handler 280 ) may determine that one or more errors (eg, one or more errors 265 ) were reported from the sensor fusion core monitor (eg, MSF core monitor 264 ) during a plurality of execution cycles.

[0200] At block B318 , the system (e.g., status and error processor 280 ) may determine that one or more errors (e.g., one or more errors 267 ) were reported from the sensor fusion output monitor (e.g., MSF output monitor 266 ) during a plurality of execution cycles.

[0201] At block B320, the system (e.g., error handling system 290) may determine that one or more errors (e.g., one or more errors 272) related to staleness (e.g., information about an input or object has not been updated in several iterations or cycles) were reported from a node output monitor (e.g., MSF node monitor 270) during multiple execution cycles.

[0202] Figure 4is a flow chart of an example process 400 for monitoring a sensor fusion system according to some embodiments of the present disclosure. Each block of the process 400 described herein comprises a computational process that may be performed using any combination of hardware, firmware, and / or software. For example, the various functions may be performed by a processor executing instructions stored in a memory. The process 400 may be embodied as computer usable instructions stored on a computer storage medium. The process 400 may be provided by a standalone application, a service, or a hosted service (standalone or in combination with another hosted service), or a plug-in to another product, to name a few. The process 400 may be provided using a software package that is compatible with the system. Figure 1A-Figure 1D Example of autonomous vehicle 100, Figure 5 An example computing device 500, Figure 6 Example data center 600 and / or Figure 2 The process 400 may be performed by components, features, and / or functionality similar to the example sensor fusion monitoring system 200. However, the process 400 may additionally or alternatively be performed by any one system or any combination of systems, including but not limited to the systems described herein.

[0203] Reference Figure 4 In process 400, at block B402, a system (e.g., example autonomous vehicle 100, example computing device 500, example data center 600, example sensor fusion monitoring system 200, example MSF system) may receive perception data (e.g., perception data 211-1) from one or more first sensors (e.g., RADAR) of a vehicle (e.g., autonomous vehicle 200). In various embodiments, the one or more first sensors may include or may be at least one of a RADAR sensor, a LiDAR sensor, an ultrasonic sensor, a stereo camera, a wide-angle camera, an infrared camera, a surround camera, a long-range camera, or a mid-range camera. In various embodiments, the system (e.g., example MSF system) may detect a first object from the perception data (e.g., perception data 211-1).

[0204] At block B404, the system may receive position data (e.g., ego-motion data 213) from one or more second sensors of the vehicle (e.g., ego-motion sensors). In various embodiments, the one or more second sensors may include or may be at least one of a GNSS sensor, a GPS sensor, an IMU sensor, an accelerometer, a gyroscope, a magnetic compass, a magnetometer, a microphone, a speed sensor, a vibration sensor, a steering sensor, or a brake sensor.

[0205] At block B406, the system (e.g., an MSF system) may generate output data (e.g., fused output data 253) by performing a fusion of at least the sensory data (e.g., sensory data 211-1) and the positional data (e.g., ego-motion data 213). In various embodiments, the system may receive sensory data (e.g., RADAR sensory data) that has been monitored for a first time period. In various embodiments, the system may receive positional data (e.g., ego-motion data) that has been monitored for a second time period that is shorter than the first time period. In various embodiments, the time period for which the positional data may be monitored is shorter than the time period for which the sensory data is monitored. For example, the sensory data from the accelerometer may be monitored once per second, while the positional data from the RADAR sensor may be monitored every 20 seconds.

[0206] At block B408, the system (e.g., node input monitor 230, module input monitor 262, module output monitor 266, status and error processor 280, node output monitor 270) may evaluate a plurality of criteria based on at least a subset of the sensory data (e.g., sensory data 211), position data (e.g., ego-motion data 213), and output data (e.g., fused output data 253). In various embodiments, the plurality of criteria corresponding to the sensory data may include or may be at least one of the validity of the sensory data, whether data is missing from the sensory data, whether the sensory data is outdated, the validity of the timestamp, the latency of the timestamp, the position of the first object within a predetermined position range, the speed of the first object within a predetermined speed range, the acceleration of the first object within a predetermined acceleration range, the vertical position of the first object relative to the ground, the size of the first object, or the category of the first object (see Table 1). In various embodiments, the plurality of criteria based on the position data may include or may be at least one of the validity of the data, whether data is missing, whether data is outdated, the speed of the vehicle within a predetermined speed range, or the acceleration of the vehicle within a predetermined acceleration range (see Table 1).

[0207] In various embodiments, a system (e.g., an example MSF system) can detect a second object (e.g., a fused object or an obstacle) from the output data (e.g., the fused output data 253). In various embodiments, the plurality of criteria based on the output data can include or can be at least one of: whether the system time increases between fusion cycles, whether the time difference between the input modality data is greater than a threshold, whether the predicted time is greater than a threshold, whether the gap between the positions of the second object is greater than a threshold, whether the gap between the velocities of the second object is greater than a threshold, or whether the gap between the accelerations of the second object is greater than a threshold (see Table 2).

[0208] At block B410, the system (e.g., monitoring system 200) may output an error signal (e.g., MSF error signal 237, MSF error / health signal 283, MSF error signal 272, validity data 271) based on the evaluation. In various embodiments, in response to the error signal, the system (e.g., MSF core module 250, error handling system 290) may perform at least one of the following operations: adjust the confidence level of the fusion result (e.g., increase or decrease the confidence level of the fusion output or fusion object 253), set validity information of the fusion result (e.g., validity data 271), degrade one or more functions of the system performing the fusion (e.g., MSF core module 250 may degrade one or more functions related to the fusion based on the error message), or send one or more health messages (e.g., MSF error / health signal 283) to a health server for debugging purposes.

[0209] In various embodiments, the processors, systems and / or methods described herein may be implemented by or may be included in at least one of: a control system for an autonomous or semi-autonomous machine; a perception system for an autonomous or semi-autonomous machine; a system for performing simulation operations; a system for performing digital twin operations; a system for performing light transport simulations; a system for performing collaborative content creation of 3D assets; a system for performing deep learning operations; a system implemented using an edge device; a system for generating or presenting at least one of virtual reality, augmented reality, or mixed reality content; a system implemented using a robot; a system for performing conversational AI operations; a system for generating synthetic data; a system comprising one or more virtual machines (VMs); a system implemented at least in part in a data center; a system implementing one or more language models (such as, one or more large language models (LLMs)); a system for performing generative AI operations; or a system implemented at least in part using cloud computing resources.

[0210] Example computing device

[0211] Figure 5FIG2 is a block diagram of an example computing device 500 suitable for implementing some embodiments of the present disclosure. Computing device 500 may include an interconnect system 502 that directly or indirectly couples the following devices: memory 504, one or more central processing units (CPUs) 506, one or more graphics processing units (GPUs) 508, a communication interface 510, input / output (I / O) ports 512, I / O components 514, a power supply 516, one or more presentation components 518 (e.g., a display), and one or more logic units 520. In at least one embodiment, computing device 500 may include one or more virtual machines (VMs), and / or any of its components may include virtual components (e.g., virtual hardware components). For non-limiting example, one or more GPUs 508 may include one or more vGPUs, one or more CPUs 506 may include one or more vCPUs, and / or one or more logic units 520 may include one or more virtual logic units. Thus, computing device 500 may include discrete components (eg, a complete GPU dedicated to computing device 500 ), virtual components (eg, a portion of a GPU dedicated to computing device 500 ), or a combination thereof.

[0212] although Figure 5 The various blocks of are shown as being connected via an interconnect system 502 having wires, but this is not intended to be limiting and is provided for clarity only. For example, in some embodiments, a presentation component 518 such as a display device may be considered an I / O component 514 (e.g., if the display is a touch screen). As another example, the CPU 506 and / or the GPU 508 may include memory (e.g., memory 504 may represent a storage device in addition to the memory of the GPU 508, the CPU 506, and / or the other components). In other words, Figure 5 The term computing device is illustrative only. No distinction is made between categories such as "workstation," "server," "laptop," "desktop," "tablet," "client device," "mobile device," "handheld device," "game console," "electronic control unit (ECU)," "virtual reality system," and / or other device or system types, as all are considered within the Figure 5 within the range of computing devices.

[0213] The interconnection system 502 can represent one or more links or buses, such as an address bus, a data bus, a control bus, or a combination thereof. The interconnection system 502 can include one or more links or bus types, such as an industry standard architecture (ISA) bus, an extended industry standard architecture (EISA) bus, a video electronics standard association (VESA) bus, a peripheral component interconnect (PCI) bus, a peripheral component interconnect express (PCIe) bus, and / or another type of bus or link. In some embodiments, there is a direct connection between components. As an example, the CPU 506 can be directly connected to the memory 504. In addition, the CPU 506 can be directly connected to the GPU 508. In the case where there is a direct or point-to-point connection between components, the interconnection system 502 can include a PCIe link to perform the connection. In these examples, it is not necessary to include a PCI bus in the computing device 500.

[0214] Memory 504 may include any of a variety of computer-readable media. Computer-readable media can be any available media that can be accessed by computing device 500. Computer-readable media can include volatile and non-volatile media and removable and non-removable media. By way of example and not limitation, computer-readable media can include computer storage media and communication media.

[0215] Computer storage media may include volatile and non-volatile media and / or removable and non-removable media implemented in any method or technology for storing information such as computer-readable instructions, data structures, program modules, and / or other data types. For example, memory 504 may store computer-readable instructions (e.g., representing programs and / or program elements, such as an operating system). Computer storage media may include, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technology, CD-ROM, digital versatile disks (DVD) or other optical disk storage devices, magnetic cassettes, magnetic tape, magnetic disk storage devices or other magnetic storage devices, or any other medium that can be used to store the desired information and that can be accessed by computing device 500. As used herein, computer storage media does not include signals themselves.

[0216] Computer storage media may embody computer-readable instructions, data structures, program modules, and / or other data types in a modulated data signal such as a carrier wave or other transmission mechanism, and include any information delivery media. The term "modulated data signal" may refer to a signal that has one or more of its characteristics set or changed in such a manner as to encode information into the signal. By way of example and not limitation, computer storage media may include wired media such as a wired network or a direct wired connection, and wireless media such as acoustic, RF, infrared, and other wireless media. Any combination of the above should also be included within the scope of computer-readable media.

[0217] The CPU 506 can be configured to execute at least some of the computer-readable instructions to control one or more components of the computing device 500 to perform one or more of the methods and / or processes described herein. Each of the CPUs 506 can include one or more cores (e.g., one, two, four, eight, twenty-eight, seventy-two, etc.) capable of processing a large number of software threads simultaneously. The CPU 506 can include any type of processor and can include different types of processors, depending on the type of computing device 500 implemented (e.g., a processor with fewer cores for mobile devices and a processor with more cores for servers). For example, depending on the type of computing device 500, the processor can be an Advanced RISC (ARM) processor implemented using Reduced Instruction Set Computing (RISC) or an x86 processor implemented using Complex Instruction Set Computing (CISC). The computing device 500 can also include one or more CPUs 506 in addition to one or more microprocessors or supplementary coprocessors such as math coprocessors.

[0218] In addition to or in place of the CPU 506, the GPU 508 may also be configured to execute at least some computer-readable instructions to control one or more components of the computing device 500 to perform one or more of the methods and / or processes described herein. One or more GPUs 508 may be integrated GPUs (e.g., with one or more CPUs 506) and / or one or more GPUs 508 may be discrete GPUs. In embodiments, one or more GPUs 508 may be coprocessors for one or more CPUs 506. The computing device 500 may use the GPU 508 to render graphics (e.g., 3D graphics) or perform general-purpose computing. For example, the GPU 508 may be used for general-purpose computing on a GPU (GPGPU). The GPU 508 may include hundreds or thousands of cores capable of processing hundreds or thousands of software threads simultaneously. The GPU 508 may generate pixel data for outputting an image in response to a rendering command (e.g., a rendering command received from the CPU 506 via a host interface). The GPU 508 may include graphics memory such as display memory for storing pixel data or any other suitable data (e.g., GPGPU data). Display memory can be included as part of memory 504. GPU 508 can include two or more GPUs operating in parallel (e.g., via a link). The link can connect the GPUs directly (e.g., using NVLINK) or through a switch (e.g., using NVSwitch). When combined, each GPU 508 can generate pixel data or GPGPU data for different portions or different outputs (e.g., a first GPU for a first image and a second GPU for a second image). Each GPU can include its own memory or can share memory with other GPUs.

[0219] In addition to or in lieu of the CPU 506 and / or GPU 508, the logic unit 520 may be configured to execute at least some computer-readable instructions to control one or more components of the computing device 500 to perform one or more methods and / or processes described herein. In embodiments, the CPU 506, GPU 508, and / or logic unit 520 may perform any combination of methods, processes, and / or portions thereof, either separately or in conjunction. The one or more logic units 520 may be part of and / or integrated within the one or more CPUs 506 and / or the one or more GPUs 508 and / or the one or more logic units 520 may be discrete components of or otherwise external to the CPU 506 and / or GPU 508. In embodiments, the one or more logic units 520 may be processors of the one or more CPUs 506 and / or the one or more GPUs 508.

[0220] Examples of logic unit 520 include one or more processing cores and / or components thereof, such as a data processing unit (DPU), a tensor core (TC), a tensor processing unit (TPU), a pixel vision core (PVC), a vision processing unit (VPU), a graphics processing cluster (GPC), a texture processing cluster (TPC), a streaming multiprocessor (SM), a tree traversal unit (TTU), an artificial intelligence accelerator (AIA), a deep learning accelerator (DLA), an arithmetic logic unit (ALU), an application-specific integrated circuit (ASIC), a floating point unit (FPU), an input / output (I / O) element, a peripheral component interconnect (PCI) or a peripheral component interconnect express (PCIe) element, etc.

[0221] The communication interface 510 may include one or more receivers, transmitters, and / or transceivers that enable the computing device 500 to communicate with other computing devices via an electronic communication network, including wired and / or wireless communications. The communication interface 510 may include components and functionality that enable communication over any of a number of different networks, such as wireless networks (e.g., Wi-Fi, Z-Wave, Bluetooth, Bluetooth LE, ZigBee, etc.), wired networks (e.g., communicating over Ethernet or InfiniBand), low-power wide-area networks (e.g., LoRaWAN, SigFox, etc.), and / or the Internet. In one or more embodiments, the logic unit 520 and / or the communication interface 510 may include one or more data processing units (DPUs) to transmit data received over the network and / or through the interconnect system 502 directly to one or more GPUs 508 (e.g., memory in a GPU 508).

[0222] The I / O ports 512 can enable the computing device 500 to be logically coupled to other devices including I / O components 514, presentation components 518, and / or other components, some of which can be built into (e.g., integrated into) the computing device 500. Illustrative I / O components 514 include a microphone, a mouse, a keyboard, a joystick, a game pad, a game controller, a satellite dish, a browser, a printer, a wireless device, and the like. The I / O components 514 can provide a natural user interface (NUI) that processes user-generated mid-air gestures, voice, or other physiological input. In some instances, the input can be transmitted to an appropriate network element for further processing. The NUI can implement any combination of voice recognition, stylus recognition, facial recognition, biometric recognition, gesture recognition on and adjacent to the screen, mid-air gestures, head and eye tracking, and touch recognition associated with the display of the computing device 500 (described in more detail below). The computing device 500 can include a depth camera such as a stereo camera system, an infrared camera system, an RGB camera system, touch screen technology, and combinations thereof for gesture detection and recognition. Additionally, computing device 500 may include an accelerometer or gyroscope to enable motion detection (e.g., as part of an inertial measurement unit (IMU)). In some examples, the output of the accelerometer or gyroscope may be used by computing device 500 to render immersive augmented or virtual reality.

[0223] The power supply 516 may include a hardwired power supply, a battery power supply, or a combination thereof. The power supply 516 may provide power to the computing device 500 to enable the components of the computing device 500 to operate.

[0224] The presentation component 518 may include a display (e.g., a monitor, a touch screen, a television screen, a head-up display (HUD), other display types, or a combination thereof), speakers, and / or other presentation components. The presentation component 518 may receive data from other components (e.g., the GPU 508, the CPU 506, the DPU, etc.) and output the data (e.g., as images, video, sound, etc.).

[0225] Sample Data Center

[0226] Figure 6 An example data center 600 is shown, which may be used in at least one embodiment of the present disclosure. The data center 600 may include a data center infrastructure layer 610, a framework layer 620, a software layer 630, and an application layer 640.

[0227] like Figure 6As shown, the data center infrastructure layer 610 may include a resource coordinator 612, grouped computing resources 614, and node computing resources ("node CRs") 616(1)-616(N), where "N" represents any complete positive integer. In at least one embodiment, the node CRs 616(1)-616(N) may include, but are not limited to, any number of central processing units (CPUs) or other processors (including DPUs, accelerators, field programmable gate arrays (FPGAs), graphics processors or graphics processing units (GPUs), etc.), memory devices (e.g., dynamic read-only memory), storage devices (e.g., solid-state drives or disk drives), network input / output (NW I / O) devices, network switches, virtual machines (VMs), power modules, and cooling modules. In some embodiments, one or more of the node CRs 616(1)-616(N) may correspond to a server having one or more of the above-mentioned computing resources. Furthermore, in some embodiments, node CRs 616 ( 1 )- 616 (N) may include one or more virtual components, such as vGPUs, vCPUs, etc., and / or one or more of node CRs 616 ( 1 )- 616 (N) may correspond to virtual machines (VMs).

[0228] In at least one embodiment, the grouped computing resources 614 may include separate groups (not shown) of node CR616 housed in one or more racks, or many racks (also not shown) housed in data centers at various geographic locations. The separate groups of node CR616 within the grouped computing resources 614 may include computing, networking, memory, or storage resources that can be configured or allocated to support groupings of one or more workloads. In at least one embodiment, several node CR616 comprising CPUs, GPUs, DPUs, and / or other processors may be grouped in one or more racks to provide computing resources to support one or more workloads. One or more racks may also include any number of power modules, cooling modules, and / or network switches in any combination.

[0229] Resource coordinator 612 may configure or otherwise control one or more node CRs 616(1)-616(N) and / or grouped computing resources 614. In at least one embodiment, resource coordinator 612 may comprise a software design infrastructure (SDI) management entity for data center 600. Resource coordinator 612 may comprise hardware, software, or some combination thereof.

[0230] In at least one embodiment, Figure 6As shown, the framework layer 620 may include a job scheduler 633, a configuration manager 634, a resource manager 636, and a distributed file system 638. The framework layer 620 may include a framework that supports the software 632 of the software layer 630 and / or one or more applications 642 of the application layer 640. The software 632 or the application 642 may include web-based service software or applications, such as those provided by Amazon Web Services, Google Cloud, and Microsoft Azure. The framework layer 620 may be, but is not limited to, a free and open source software network application framework, such as Apache Spark, which can utilize the distributed file system 638 for large-scale data processing (e.g., "big data"). TM (hereinafter referred to as "Spark"). In at least one embodiment, the job scheduler 633 may include a Spark driver to facilitate scheduling of workloads supported by the various layers of the data center 600. In at least one embodiment, the configuration manager 634 may be capable of configuring the various layers, such as the software layer 630 and the framework layer 620 including Spark and a distributed file system 638 for supporting large-scale data processing. The resource manager 636 may be capable of managing the mapping or allocation of clustered or grouped computing resources to support the distributed file system 638 and the job scheduler 633. In at least one embodiment, the clustered or grouped computing resources may include the grouped computing resources 614 at the data center infrastructure layer 610. The resource manager 636 may coordinate with the resource coordinator 612 to manage these mapped or allocated computing resources.

[0231] In at least one embodiment, the software 632 included in the software layer 630 may include software used by at least a portion of the node CRs 616(1)-616(N), the grouped computing resources 614, and / or the distributed file system 638 of the framework layer 620. The one or more types of software may include, but are not limited to, Internet web page search software, email virus scanning software, database software, and streaming video content software.

[0232] In at least one embodiment, the one or more applications 642 included in the application layer 640 may include one or more types of applications used by at least a portion of the node CRs 616(1)-616(N), the grouped computing resources 614, and / or the distributed file system 638 of the framework layer 620. The one or more types of applications may include, but are not limited to, any number of genomics applications, cognitive computing, and machine learning applications, including training or inference software, machine learning framework software (e.g., PyTorch, TensorFlow, Caffe, etc.), and / or other machine learning applications used in conjunction with one or more embodiments.

[0233] In at least one embodiment, any of configuration manager 634, resource manager 636, and resource coordinator 612 can implement any number and type of self-modification actions based on any number and type of data acquired in any technically feasible manner. The self-modification actions can relieve a data center operator of data center 600 from making potentially poor configuration decisions and can avoid underutilized and / or poorly performing portions of the data center.

[0234] The data center 600 may include tools, services, software, or other resources for training one or more machine learning models or using one or more machine learning models to predict or infer information according to one or more embodiments described herein. For example, a machine learning model may be trained by calculating weight parameters according to a neural network architecture using the software and computing resources described above with respect to the data center 600. In at least one embodiment, using the weight parameters calculated using one or more training techniques, the resources described above with respect to the data center 600 may be used to infer or predict information using a trained machine learning model corresponding to one or more neural networks, such as, but not limited to, those described herein.

[0235] In at least one embodiment, the data center 600 may use a CPU, an application-specific integrated circuit (ASIC), a GPU, an FPGA, and / or other hardware (or corresponding virtual computing resources) to perform training and / or reasoning using the aforementioned resources. In addition, one or more of the software and / or hardware resources described above may be configured as a service to allow users to train or perform information reasoning, such as image recognition, speech recognition, or other artificial intelligence services.

[0236] Sample network environment

[0237] A network environment suitable for implementing embodiments of the present disclosure may include one or more client devices, servers, network attached storage (NAS), other backend devices, and / or other device types. The client devices, servers, and / or other device types (e.g., each device) may be configured to: Figure 5 The backend device 600 may be implemented on one or more instances of the computing device 500—for example, each device may include similar components, features, and / or functionality of the computing device 500. In addition, in the case of implementing a backend device (e.g., a server, NAS, etc.), the backend device may be included as part of the data center 600, an example of which is described herein with respect to Figure 6 Describe in more detail.

[0238] The components of the network environment can communicate with each other through the network, which can be wired, wireless, or both. The network can include multiple networks, or a network of networks. For example, the network can include one or more wide area networks (WANs), one or more local area networks (LANs), one or more public networks (e.g., the Internet and / or the Public Switched Telephone Network (PSTN)), and / or one or more private networks. In the case where the network includes a wireless telecommunications network, components such as base stations, communication towers, or even access points (and other components) can provide wireless connections.

[0239] Compatible network environments may include one or more peer-to-peer network environments (in which case the server may not be included in the network environment), and one or more client-server network environments (in which case one or more servers may be included in the network environment). In a peer-to-peer network environment, the functionality described herein with respect to the server may be implemented on any number of client devices.

[0240] In at least one embodiment, the network environment may include one or more cloud-based network environments, distributed computing environments, combinations thereof, and the like. The cloud-based network environment may include a framework layer, a job scheduler, a resource manager, and a distributed file system implemented on one or more servers, which may include one or more core network servers and / or edge servers. The framework layer may include a framework for supporting software at the software layer and / or one or more applications at the application layer. The software or application may include network-based service software or application programs, respectively. In an embodiment, one or more client devices may use network-based service software or application programs (e.g., by accessing the service software and / or application programs via one or more application programming interfaces (APIs)). The framework layer may be, but is not limited to, a type of free and open source software network application framework that may, for example, use a distributed file system for large-scale data processing (e.g., "big data").

[0241] A cloud-based network environment can provide cloud computing and / or cloud storage that performs any combination of the computing and / or data storage functions described herein (or one or more portions thereof). Any of these various functions can be distributed across multiple locations from a central or core server (e.g., one or more data centers that can be distributed across a state, region, country, global, etc.). If the connection to the user (e.g., client device) is relatively close to an edge server, the core server can assign at least a portion of the functionality to the edge server. A cloud-based network environment can be private (e.g., limited to a single organization), public (e.g., available to many organizations), and / or a combination thereof (e.g., a hybrid cloud environment).

[0242] Client devices may include Figure 5 The client device 500 may be embodied as a personal computer (PC), a laptop computer, a mobile device, a smartphone, a tablet computer, a smartwatch, a wearable computer, a personal digital assistant (PDA), an MP3 player, a virtual reality head-mounted display, a global positioning system (GPS) or device, a video player, a camera, a surveillance device or system, a vehicle, a watercraft, an aircraft, a virtual machine, a drone, a robot, a handheld communication device, a hospital device, a gaming device or system, an entertainment system, an in-vehicle computer system, an embedded system controller, a remote control, an appliance, a consumer electronic device, a workstation, an edge device, any combination of these described devices, or any other suitable device.

[0243] The present disclosure can be described in the general context of machine-usable instructions or computer code executed by a computer or other machine such as a personal digital assistant or other handheld device, including computer-executable instructions such as program modules. Generally, program modules including routines, programs, objects, components, data structures, etc. refer to code that performs a specific task or implements a specific abstract data type. The present disclosure can be practiced in a variety of system configurations, including handheld devices, consumer electronics, general-purpose computers, more specialized computing devices, etc. The present disclosure can also be practiced in a distributed computing environment where tasks are performed by remote processing devices linked through a communication network.

[0244] As used herein, the statement "and / or" with respect to two or more elements should be interpreted as referring to only one element or combination of elements. For example, "element A, element B and / or element C" may include only element A, only element B, only element C, element A and element B, element A and element C, element B and element C, or elements A, B and C. In addition, "at least one of element A or element B" may include at least one of element A, at least one of element B, or at least one of element A and at least one of element B. Further, "at least one of element A and element B" may include at least one of element A, at least one of element B, or at least one of element A and at least one of element B.

[0245] The subject matter of the present disclosure is described in detail herein to meet statutory requirements. However, the description itself is not intended to limit the scope of the present disclosure. On the contrary, the inventors have contemplated that the claimed subject matter may also be embodied in other ways to include steps that are different from the steps described herein in conjunction with other current or future technologies, or combinations of similar steps. Moreover, although the terms "step" and / or "block" may be used herein to imply different elements of the method employed, these terms should not be interpreted as implying any particular order among or between the various steps disclosed herein, unless the order of the steps is explicitly described.

Claims

1. One or more processors, including: One or more circuits for: receiving sensory data obtained using one or more first sensors of the machine; receiving position data obtained using one or more second sensors of the machine; generating output data at least in part by performing a fusion of at least the sensory data and the position data; evaluating a plurality of criteria based on at least a subset of the sensory data, the positional data, and the output data; as well as An error signal is output as a function of the evaluation. 2 . The one or more processors of claim 1 , wherein the time period over which the position data is monitored is shorter than the time period over which the sensory data is monitored.

3. The one or more processors of claim 1 , wherein the one or more first sensors comprise at least one of a RADAR sensor, a light detection and ranging (LiDAR) sensor, an ultrasonic sensor, a stereo camera, a wide-angle camera, an infrared camera, a surround camera, a long-range camera, or a mid-range camera.

4. The one or more processors of claim 1 , wherein: The one or more circuits are configured to detect a first object from the sensory data; as well as The multiple criteria corresponding to the perception data include at least one of the following: validity of the perception data, whether data is missing in the perception data, whether the perception data is outdated, validity of a timestamp, delay of a timestamp, the position of the first object is within a predetermined position range, the speed of the first object is within a predetermined speed range, the acceleration of the first object is within a predetermined acceleration range, the vertical position of the first object relative to the ground, the size of the first object, or the category of the first object.

5. The one or more processors of claim 1 , wherein the one or more second sensors comprise at least one of a global navigation satellite system (GNSS) sensor, or a global positioning system (GPS) sensor, an inertial measurement unit (IMU) sensor, an accelerometer, a gyroscope, a magnetic compass, a magnetometer, a microphone, a speed sensor, a vibration sensor, a steering sensor, or a brake sensor.

6. One or more processors as described in claim 1, wherein the multiple criteria based on the position data include at least one of the following: validity of the data, whether the data is missing, whether the data is out of date, the speed of the machine is within a predetermined speed range, or the acceleration of the machine is within a predetermined acceleration range.

7. The one or more processors of claim 1 , wherein: the one or more circuits being configured to detect a first object from the output data; as well as The multiple criteria based on the output data include at least one of: whether the system time increases between fusion cycles, whether the time difference between the input modality data is greater than a threshold, whether the prediction time is greater than a threshold, whether the difference between the positions of the first objects is greater than a threshold, whether the difference between the velocities of the first objects is greater than a threshold, or whether the difference between the accelerations of the first objects is greater than a threshold.

8. The one or more processors of claim 1 , wherein in response to the error signal, the one or more circuits are configured to perform at least one of the following operations: adjusting a confidence level of the fused result; Setting validity information of the result of the fusion; degrading one or more functions of a system performing the fusion; or Sends one or more health messages to a health server for debugging purposes.

9. The one or more processors of claim 1 , wherein the output data is generated at least in part by: detecting one or more fused objects by performing a fusion of at least one or more first objects detected based at least on the perception data from one or more first sensors of a machine and one or more second objects detected based at least on data from one or more third sensors of the machine during a plurality of execution cycles; during the plurality of execution cycles, determining that the one or more first objects are invalid; determining a first number of periods during which the one or more first objects are determined to be invalid; as well as In response to determining that the first number of cycles is equal to a first threshold, the one or more fused objects are determined to be invalid.

10. The one or more processors of claim 9, wherein the one or more circuits are configured to: during the plurality of execution cycles, determining that the one or more second objects are invalid; determining a second number of cycles during which the one or more second objects are determined to be invalid; and In response to determining that the second number of cycles is equal to a second threshold, the one or more fused objects are determined to be invalid.

11. The one or more processors of claim 9, wherein the one or more circuits are configured to: determining whether one or more errors occurred during the plurality of execution cycles; and In response to determining that one or more errors occurred during the plurality of execution cycles, determining that the one or more fused objects are invalid, The one or more errors are related to at least one of vehicle safety or performing the fused function.

12. The one or more processors of claim 1 , wherein the one or more processors are included in at least one of: control systems for autonomous or semi-autonomous machines; Perception systems for autonomous or semi-autonomous machines; a system for performing one or more simulation operations; a system for performing one or more digital twin operations; a system for performing light transport simulations; A system for performing collaborative content creation of 3D assets; a system for performing one or more deep learning operations; a system for generating or presenting at least one of augmented reality content, virtual reality content, or mixed reality content; a system for hosting one or more live streaming applications; Systems implemented using edge devices; Systems implemented using robots; A system for performing one or more conversational AI operations; A system implementing one or more large language models (LLMs); A system implementing one or more language models; A system for performing one or more generative AI operations; Systems for generating synthetic data; A system comprising one or more virtual machines VM; A system implemented at least in part in a data center; or A system implemented at least in part using cloud computing resources.

13. A system comprising: One or more processors configured to perform operations comprising: receiving sensory data from one or more first sensors of the machine; receiving position data from one or more second sensors of the machine; generating output data by performing a fusion of at least the sensory data and the position data; evaluating a plurality of criteria based on at least a subset of the sensory data, the positional data, and the output data; and An error signal is outputted as a function of the evaluation.

14. The system of claim 13, wherein the time period over which the position data is monitored is shorter than the time period over which the sensory data is monitored.

15. The system of claim 13, wherein: The operations further include: detecting a first object from the perception data; and The multiple criteria corresponding to the perception data include at least one of the following: validity of the perception data, whether data is missing in the perception data, whether the perception data is outdated, validity of a timestamp, delay of a timestamp, the position of the first object is within a predetermined position range, the speed of the first object is within a predetermined speed range, the acceleration of the first object is within a predetermined acceleration range, the vertical position of the first object relative to the ground, the size of the first object, or the category of the first object.

16. The system of claim 13, wherein the plurality of criteria based on the position data include at least one of: validity of data, whether data is missing, whether data is outdated, whether the speed of the machine is within a predetermined speed range, or whether the acceleration of the machine is within a predetermined acceleration range.

17. The system of claim 13, wherein in response to the error signal, the operations further comprise: adjusting a confidence level of the fused result; Setting validity information of the result of the fusion; degrading one or more functions of a system performing the fusion; or Sends one or more health messages to a health server for debugging purposes.

18. The system of claim 13, wherein the system is included in at least one of: control systems for autonomous or semi-autonomous machines; Perception systems for autonomous or semi-autonomous machines; a system for performing one or more simulation operations; a system for performing one or more digital twin operations; a system for performing light transport simulations; A system for performing collaborative content creation of 3D assets; a system for performing one or more deep learning operations; a system for generating or presenting at least one of augmented reality content, virtual reality content, or mixed reality content; a system for hosting one or more live streaming applications; Systems implemented using edge devices; Systems implemented using robots; A system for performing one or more conversational AI operations; A system implementing one or more large language models (LLMs); A system implementing one or more language models; A system for performing one or more generative AI operations; Systems for generating synthetic data; A system comprising one or more virtual machines VM; A system implemented at least in part in a data center; or A system implemented at least in part using cloud computing resources.

19. A method comprising: receiving sensory data from one or more first sensors of the machine; receiving position data from one or more second sensors of the machine; generating output data by performing a fusion of at least the sensory data and the position data; evaluating a plurality of criteria based on at least a subset of the sensory data, the positional data, and the output data; as well as An error signal is outputted as a function of the evaluation.

20. The method of claim 19, further comprising: In response to the error signal, perform at least one of the following operations: adjusting a confidence level of the fused result; Setting validity information of the result of the fusion; degrading one or more functions of a system performing the fusion; or Sends one or more health messages to a health server for debugging purposes.

Citation Information

Patent Citations

  • Method for programmable timeouts of tree traversal mechanisms in hardware

    US10885698B2