System and computer readable storage medium for intervening operation of vehicle with autonomous driving capability

By interacting with autonomous vehicles through a remote operating system, analyzing vehicle status and environmental information, and providing intervention measures, the problem of remote intervention when autonomous vehicles encounter events is solved, ensuring safe vehicle operation.

CN120802936APending Publication Date: 2025-10-17MOTIONAL AD LLC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510892255.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2017-06-16
Filing Date
2018-06-13
Publication Date
2025-10-17

AI Technical Summary

Technical Problem

When an autonomous vehicle encounters an incident, existing technologies have difficulty effectively providing remote intervention to resolve the hazard or prevent the vehicle from traveling along its planned trajectory.

Method used

By interacting with the autonomous vehicle system through a remote operating system, it receives intervention requests, analyzes vehicle status and environmental information, uses machine learning algorithms to detect abnormal patterns, infers faults, and provides intervention measures, such as changing driving modes, generating new trajectories, or marking safe parking locations.

Benefits of technology

It enables rapid and effective remote intervention when autonomous vehicles encounter incidents, avoiding danger and ensuring safe driving.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120802936A_ABST
    Figure CN120802936A_ABST
Patent Text Reader

Abstract

The invention provides a system and a computer readable storage medium for intervening in operation of a vehicle with autonomous driving capability. In particular, it is determined that intervention in the operation of one or more autonomous driving capabilities of the vehicle is appropriate. Based on the determination, the person is enabled to provide information for the intervention. Interference on the operation of one or more autonomous driving capabilities of the vehicle is induced.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application of application number 201880053010.8, filed on June 13, 2018, with the title “Intervening in the operation of a vehicle with autonomous driving capabilities”. TECHNICAL FIELD

[0002] This application provides systems and computer-readable storage media for intervening in the operation of a vehicle with autonomous driving capabilities. BACKGROUND

[0003] In some cases, such as when a vehicle with autonomous driving capabilities (AV) is driving on a road and encounters an event (such as a system failure, an extreme weather condition, and a temporary detour), it can be useful to have a remotely located person provide assistance. SUMMARY

[0004] In some implementations, the technology described in this document includes a remote operations system that interacts with an AV system to address various types of events, some of which can include hazards (e.g., collisions, traffic jams, and damage) or can prevent or prohibit an AV that is part of the AV system from traveling along a planned trajectory. In some examples, to address these events, the AV system can communicate with the remote operations system, where a remote operator provides remote operations to the AV system.

[0005] In some cases, the remote operations system can include a client on the AV or associated with the AV system, and a server that is remote with respect to the AV or the AV system. In some cases, both the client and the server are on the AV. In some applications, the server and the client can be split into two different computing devices; in some cases, they can be integrated into a single computing device.

[0006] In some implementations, a function or step described as part of a remote operations client can be implemented as part of a remote operations server. Similarly, a function or step described as part of a remote operations server can be implemented as part of a remote operations client. In some cases, a function or step can be part of a remote operations server as well as part of a remote operations client.

[0007] Generally, in an aspect, a method includes: (a) determining that an intervention into operation of one or more autonomous driving capabilities of a vehicle is appropriate; (b) based on the determination, enabling a human to provide information for the intervention; and (c) causing the intervention into operation of the one or more autonomous driving capabilities of the vehicle. Determining that the intervention is appropriate can include receiving a request for the intervention. Determining that the intervention is appropriate can include receiving information about a state or environment of the vehicle or related AV system. The state or environment of the vehicle can include functionality of hardware components or software of the vehicle or AV system.

[0008] In some implementations, the information about the state or environment of the vehicle or AV system can include a signal from a hardware component or software of the vehicle or AV system. Determining that the intervention is appropriate can include analyzing the signal. Analyzing the signal can include detecting unexpected data or lack of expected data. Analyzing the signal can include evaluating a mismatch between a measured quantity and a model-estimated quantity of the hardware component or software. Analyzing the signal can include using pattern recognition to evaluate an anomalous pattern in the signal. The anomalous pattern can be learned through a machine learning algorithm. Analyzing the signal can include inferring a fault in the hardware component or software. Analyzing the signal can include detecting an unknown object present in an environment of the vehicle. Analyzing the signal can include inferring an event occurring or about to occur in an environment of the vehicle.

[0009] In some implementations, the request can include a request initiated by a remote operator. The request can include data associated with a state or environment of the vehicle or related AV system. The request can include one or more signals from one or more hardware components of the vehicle or related AV system. The request can include one or more signals from one or more software processes of the vehicle.

[0010] In some implementations, the method can include, based on the determination, causing a backup intervention into operation of the one or more autonomous driving capabilities of the vehicle. The backup intervention can include causing the vehicle or related AV system to enter a fully autonomous driving mode, a semi-autonomous driving mode, or a fully manual driving mode. The backup intervention can include causing the vehicle to operate at a reduced speed. The backup intervention can include identifying a safe parking location. The backup intervention can include generating a new trajectory to the safe parking location. The backup intervention can include invoking a backup hardware component or a backup software process. The backup intervention can include evaluating functional hardware components or software processes needed to operate the vehicle.

[0011] In some implementations, determining that an intervention is appropriate can include evaluating one or more active events associated with the vehicle or related AV system, or associated with an environment of the vehicle. Evaluating the one or more events can include merging two or more active events. Enabling the person to provide information for the intervention can include maintaining a queue based on the one or more determinations that an intervention is appropriate. Maintaining the queue can include determining a priority of the intervention based on one or more of: a decision tree, a combinatorial optimization, a machine algorithm, and past interventions. Enabling the person to provide information for the intervention can include assigning the person to provide the information based on availability of the person and one or more of: (a) time, (b) knowledge of the vehicle, (c) knowledge of the vehicle environment, or (d) language.

[0012] In some implementations, enabling the person to provide information for the intervention can include presenting an interactive interface to the person. Presenting the interactive interface can include presenting a field of view or a bird's eye view of a vision sensor of the vehicle. Presenting the interactive interface can include presenting perception information of the current or past or both. Presenting the interactive interface can include presenting trajectories of the current or past or both. Presenting the interactive interface can include presenting motion planning information of the current or past or both. Presenting the interactive interface can include presenting a system diagram of the vehicle including one or more hardware components, or one or more software processes, or both.

[0013] In some implementations, the information for the intervention can include a current location of the vehicle determined by the person. The intervention can include taking the current location identified by the person as prior knowledge and updating the current location using an inference algorithm. The intervention can include identifying a target location of the vehicle by the person. The intervention can include taking the target location identified by the person as prior knowledge and updating the target location using an inference algorithm.

[0014] In some implementations, the method can include an intervention including a trajectory found by the person. The intervention can include taking the trajectory identified by the person as prior knowledge and updating the trajectory using an inference algorithm. The intervention can include one or more trajectory sample points identified by the person. The intervention can include inferring a trajectory or a trajectory segment based on the one or more trajectory sample points. Inferring the trajectory or the trajectory segment can be based on one or more trajectory primitives. The intervention can include connecting two trajectory segments. Connecting the two trajectory segments can include smoothing the trajectory segments and smoothing a velocity profile across the trajectory segments. The intervention can include specifying one or more non-crossable road segments. The intervention can include setting a velocity profile. The intervention can include taking the velocity profile as prior knowledge and updating the velocity profile using an inference algorithm.

[0015] In some implementations, the intervention can be based on inferring a velocity distribution by a learning algorithm. The intervention can be based on inferring a steering angle by a learning algorithm. The intervention can include enabling, editing, or disabling a hardware component or a software process. The intervention can include enabling, editing, or disabling a subcomponent of a hardware component or a processing step of a software process.

[0016] In some implementations, the method can include including an intervention that overrides a travel preference or a travel rule. In some implementations, the method can include including an intervention that edits data including one or more of: a map, sensor data in the vehicle or a related AV system, trajectory data in the vehicle or a related AV system, visual data in the vehicle or a related AV system, or any past data in the vehicle or a related AV system.

[0017] In some implementations, the method can include configuring the vehicle or a related AV system based on the command. Configuring the vehicle or a related AV system based on the command can include treating the command as prior knowledge and updating the command using an inference algorithm. The command can include one or more of: a trajectory, a label, a process control, an annotation, and a machine instruction.

[0018] Generally, in an aspect, a method includes: (a) receiving an intervention request related to operation of one or more autonomous driving capabilities of a vehicle; (b) causing a human to interact with the vehicle through a communication channel; and (c) issuing an intervention to configure operation of the one or more autonomous driving capabilities of the vehicle.

[0019] In some implementations, the method can include receiving or generating or analyzing information about a state or an environment of the vehicle. The information about the state or the environment of the vehicle can include a functionality of a hardware component or a software of the vehicle. The information about the state or the environment of the vehicle can include a signal from a hardware component or a software of the vehicle. The information about the state or the environment of the vehicle can include presence of unexpected data or lack of expected data. The information about the state or the environment of the vehicle can include a mismatch between a measured quantity and a model estimated quantity of a hardware component or a software of the vehicle.

[0020] In some implementations, analyzing the information can include using pattern recognition to assess an anomalous pattern in the information. The anomalous pattern can be learned through a machine learning algorithm. Analyzing the information can include inferring a fault in a hardware component or a software. Analyzing the information can include detecting an unknown object present in an environment of the vehicle. Analyzing the information can include inferring an event that is occurring or will occur in an environment of the vehicle.

[0021] In some implementations, the intervention request can include a request initiated by a human or a second human. The intervention request can include data associated with a state or environment of the vehicle or related AV system. The intervention request can include one or more signals from one or more hardware components of the vehicle or related AV system. The intervention request can include one or more signals from one or more software processes of the vehicle.

[0022] In some implementations, determining that an intervention is appropriate can include evaluating one or more active events associated with the vehicle or related AV system, or associated with an environment of the vehicle. Evaluating the one or more events can include merging two or more active events.

[0023] In some implementations, the method can include maintaining a queue of one or more intervention requests. Maintaining the queue can include determining a priority of an intervention based on one or more of: a decision tree, a combinatorial optimization, a machine algorithm, and past interventions.

[0024] In some implementations, assigning a human to interact with the vehicle is based on availability of the human and one or more of: (a) time, (b) knowledge of the vehicle, (c) knowledge of the vehicle environment, or (d) language.

[0025] In some implementations, the method can include presenting an interaction interface to the human. Presenting the interaction interface can include presenting a field of view or a bird’s eye view of a vision sensor of the vehicle. Presenting the interaction interface can include presenting perception information of the current or past or both. Presenting the interaction interface can include presenting trajectories of the current or past or both. Presenting the interaction interface can include presenting motion planning information of the current or past or both. Presenting the interaction interface can include presenting a system diagram of the vehicle including one or more hardware components, or one or more software processes, or both.

[0026] In some implementations, the method can include an intervention that includes a current location of the vehicle determined by the human; the intervention can include treating the current location identified by the human as prior knowledge and updating the current location using an inference algorithm. The intervention can include identifying a target location of the vehicle; the intervention can include treating the identified target location as prior knowledge and updating the target location using an inference algorithm. The intervention can include a trajectory discovered by the human; the intervention can include treating the trajectory identified by the human as prior knowledge and updating the trajectory using an inference algorithm. The intervention can include one or more trajectory sample points identified by the human; the intervention can include inferring a trajectory or trajectory segment based on the one or more trajectory sample points. Inferring the trajectory or trajectory segment can be based on one or more trajectory primitives. The intervention can include connecting two trajectory segments. Connecting the two trajectory segments can include smoothing the trajectory segments and smoothing a velocity profile across the trajectory segments. In some implementations, the intervention can include specifying one or more non-navigable road segments.

[0027] In some implementations, the intervention can include setting a velocity profile; the intervention can include treating the velocity profile as prior knowledge and updating the velocity profile using an inference algorithm. The intervention can be based on inferring a velocity profile by a learning algorithm. The intervention can be based on inferring a steering angle by a learning algorithm. The intervention can include enabling, editing, or disabling a hardware component or a software process. The intervention can include enabling, editing, or disabling a subcomponent of a hardware component or a processing step of a software process.

[0028] In some implementations, the intervention can include overriding a travel preference or a travel rule. The intervention can include editing data including one or more of: a map, sensor data in the vehicle, trajectory data in the vehicle, vision data in the vehicle, or any past data in the vehicle. Configuring operation of one or more autonomous driving capabilities can include treating the intervention as prior knowledge and updating the intervention using an inference algorithm for the purpose of the configuration. The intervention can include one or more of: a trajectory, a label, a process control, an annotation, and a machine instruction.

[0029] Generally, in an aspect, an implementation includes a vehicle having autonomous driving capabilities, and the vehicle includes (a) steering, acceleration, and deceleration devices that are responsive to control signals from a driving control system to autonomously drive the vehicle on a road network; (b) a monitoring element on the vehicle that generates an intervention request for the vehicle to participate in an intervention by a human, and (c) a communication element that receives a command from the human and provides the command to the driving control system for the steering, acceleration, and deceleration devices to maneuver the vehicle to a target location.

[0030] In some implementations, the vehicle can include a processor that receives information about a state or an environment of the vehicle to determine that an intervention is appropriate. The state or the environment of the vehicle can include a functionality of a hardware component or software of the vehicle. The information about the state or the environment of the vehicle can include a signal from a hardware component or software of the vehicle.

[0031] In some implementations, the vehicle can include determining that an intervention is appropriate by analyzing a signal. Analyzing the signal can include detecting unexpected data or lack of expected data. Analyzing the signal can include evaluating a mismatch between a measured quantity and a model-estimated quantity of a hardware component or software. Analyzing the signal can include evaluating an anomalous pattern in the signal using pattern recognition. The anomalous pattern can be learned from a machine learning algorithm. Analyzing the signal can include inferring a fault in a hardware component or software. Analyzing the signal can include detecting an unknown object present in an environment of the vehicle. Analyzing the signal can include inferring an event that is occurring or will occur in an environment of the vehicle.

[0032] In some implementations, the request can include a request initiated by a remote operator. The request can include data associated with a state or environment of the vehicle. The request can include one or more signals from one or more hardware components of the vehicle. The request can include one or more signals from one or more software processes of the vehicle.

[0033] In some implementations, the vehicle can include a processor that causes a backup intervention in the driving control system. The backup intervention can include causing the vehicle to enter a fully autonomous driving mode, a semi-autonomous driving mode, or a fully manual driving mode. The backup intervention can include causing the vehicle to operate at a reduced speed. The backup intervention can include identifying a safe parking location. The backup intervention can include generating a new trajectory to the safe parking location. The backup intervention can include invoking a backup hardware component or a backup software process. The backup intervention can include evaluating functional hardware components or software processes required to operate the vehicle.

[0034] In some implementations, the vehicle can include a processor that evaluates one or more active events associated with processing or an environment of the vehicle. Evaluating the one or more active events can include merging two or more active events.

[0035] In some implementations, the vehicle can include a processor that enables a person to provide information for an intervention includes maintaining a queue based on one or more determinations that the intervention is appropriate. Maintaining the queue can include determining a priority of the intervention based on one or more of: a decision tree, a combinatorial optimization, a machine algorithm, and past interventions. Enabling the person to provide the information for the intervention can include assigning the person providing the information based on availability of the person and one or more of: (a) time, (b) knowledge of the vehicle, (c) knowledge of the vehicle environment, or (d) language. Enabling the person to provide the information for the intervention can include presenting an interactive interface to the person. Presenting the interactive interface can include presenting a field of view or a bird’s eye view of a visual sensor of the vehicle. Presenting the interactive interface can include presenting perception information that is current or past or both. Presenting the interactive interface can include presenting trajectories that are current or past or both. Presenting the interactive interface can include presenting motion planning information that is current or past or both. Presenting the interactive interface can include presenting a system diagram of the vehicle that includes one or more hardware components, or one or more software processes, or both.

[0036] In some implementations, the intervention can include a current location of the vehicle determined by the person. The intervention can include treating the current location identified by the person as prior knowledge and updating the current location using an inference algorithm.

[0037] In some implementations, the intervention can be based on a target location of the vehicle identified by the person. The intervention can include treating the target location identified by the person as prior knowledge and updating the target location using an inference algorithm.

[0038] In some implementations, the intervention can include a trajectory found by a human. The intervention can include treating the trajectory identified by the human as prior knowledge and updating the trajectory using an inference algorithm.

[0039] In some implementations, the intervention can include one or more trajectory sample points identified by a human. The intervention can include inferring a trajectory or trajectory segment based on the one or more trajectory sample points. Inferring the trajectory or trajectory segment can be based on one or more trajectory primitives. The intervention can include connecting two trajectory segments. Connecting the two trajectory segments can include smoothing the trajectory segments and smoothing a velocity profile across the trajectory segments.

[0040] In some implementations, the intervention can include specifying one or more non-crossable road segments. The intervention can include setting a velocity profile. The intervention can include treating the velocity profile as prior knowledge and updating the velocity profile using an inference algorithm. The intervention can be based on inferring the velocity profile by a learning algorithm. The intervention can be based on inferring a steering angle by a learning algorithm. The intervention can include enabling, editing, or disabling a hardware component or a software process. The intervention can include enabling, editing, or disabling a subcomponent of a hardware component or a processing step of a software process. The intervention can include overriding a travel preference or a travel rule. The intervention can include editing data including one or more of: a map, sensor data, trajectory data, vision data, or any past data.

[0041] In some implementations, a vehicle can include a processor that configures the vehicle or a related AV system based on a command. Configuring the vehicle or the related AV system based on the command can include treating the command as prior knowledge and updating the command using an inference algorithm. The command can include one or more of: a trajectory, a label, a process control, an annotation, and a machine instruction.

[0042] In another aspect, an implementation includes an apparatus comprising: (a) a processor configured to (1) receive an intervention request related to operation of a vehicle, and (2) extract motion information or perception information from the intervention request; and (b) a display configured to (1) display the motion information or the perception information, and (2) allow a user to interact with the operation of the vehicle.

[0043] In some implementations, the intervention can include a request initiated by a remote operator. The intervention request can include data associated with a state or an environment of the vehicle or a related AV system. The intervention request can include one or more signals from one or more hardware components of the vehicle or the related AV system. The intervention request can include one or more signals from one or more software processes of the vehicle.

[0044] In some implementations, the display can be configured to present an interactive interface including a field of view or a bird’s eye view of the vehicle’s vision sensors. The display can be configured to present an interactive interface including perception information of the current or past or both. The display can be configured to present an interactive interface including trajectories of the current or past or both. The display can be configured to present an interactive interface including motion planning information of the current or past or both. The display can be configured to present an interactive interface including a system diagram of the vehicle, the system diagram including one or more hardware components, or one or more software processes, or both.

[0045] In some implementations, the apparatus can include a processor that converts one or more interactions from a user into an intervention for operation of the vehicle. The one or more interactions can include a current location of the vehicle determined by the user; the processor can treat the current location identified by the user as prior knowledge and use an inference algorithm to generate an updated current location as the intervention. The one or more interactions can include a target location of the vehicle identified by the user; the processor can treat the target location as prior knowledge and use an inference algorithm to generate an updated target location as the intervention. The one or more interactions can include a trajectory identified by the user; the processor can treat the trajectory as prior knowledge and use an inference algorithm to generate an updated trajectory as the intervention. The one or more interactions include one or more trajectory sample points identified by the user; the processor can infer a trajectory or a trajectory segment based on the one or more trajectory sample points. The processor can infer a trajectory or a trajectory segment based on one or more trajectory primitives. The processor can connect two trajectory segments. Connecting two trajectory segments can include smoothing the trajectory segments and smoothing a velocity profile across the trajectory segments. The one or more interactions can include specifying one or more non-crossable road segments. The one or more interactions can include setting a velocity profile. The processor can treat the velocity profile as prior knowledge and use an inference algorithm to generate an updated velocity profile as the intervention. The processor can infer a velocity profile through a learning algorithm, and the velocity profile can be included in the intervention. The processor can infer a steering angle through a learning algorithm, and the steering angle can be included in the intervention. The one or more interactions or the intervention can include enabling, editing, or disabling a hardware component or a software process. The one or more interactions or the intervention can include enabling, editing, or disabling a subcomponent of a hardware component or a step of a software process. The one or more interactions or the intervention can include overriding a travel preference or a travel rule. The one or more interactions or the intervention can include editing data including one or more of: a map, sensor data in the vehicle or a related AV system, trajectory data in the vehicle or a related AV system, vision data in the vehicle or a related AV system, or any past data in the vehicle or a related AV system. The intervention can include one or more of: a trajectory, a label, a process control, an annotation, and a machine instruction.

[0046] Generally, in an aspect, a method includes: (a) causing a vehicle to drive in an autonomous mode on a roadway, the vehicle including one or more autonomous driving capabilities; (b) receiving an intervention regarding operation of the one or more autonomous driving capabilities, and (c) analyzing the intervention and configuring one or more hardware components or one or more software processes of the vehicle.

[0047] In some implementations, the intervention can include a current location of the vehicle; analyzing the intervention can include treating the current location in the intervention as prior knowledge and updating the current location using an inference algorithm. The intervention can include a target location; analyzing the intervention can include treating the target location in the intervention as prior knowledge and updating the target location using an inference algorithm. The intervention can include a trajectory; analyzing the intervention can include treating the trajectory in the intervention as prior knowledge and updating the trajectory using an inference algorithm. The intervention can include one or more trajectory sample points; analyzing the intervention can include treating the one or more trajectory sample points as prior knowledge and updating the one or more trajectory sample points using an inference algorithm. Analyzing the intervention can include inferring a trajectory or a trajectory segment based on the one or more trajectory sample points. Inferring the trajectory or the trajectory segment can be based on one or more trajectory primitives. Inferring the trajectory or the trajectory segment can include connecting two trajectory segments. Connecting the two trajectory segments can include smoothing the trajectory segments and smoothing a velocity profile across the trajectory segments. The intervention can include specifying one or more non-crossable road segments. The intervention can include inferring or setting a velocity profile. Analyzing the intervention can include treating the velocity profile as prior knowledge and updating the velocity profile using an inference algorithm. Analyzing the intervention can include inferring the velocity profile by a learning algorithm. Analyzing the intervention can include inferring a steering angle by a learning algorithm. Analyzing the intervention can include enabling, editing, or disabling a hardware component or a software process. Analyzing the intervention can include enabling, editing, or disabling a subcomponent of a hardware component or a processing step of a software process. The intervention can include overriding a travel preference or a travel rule. The intervention can include editing data including one or more of: a map, sensor data in the vehicle or a related AV system, trajectory data in the vehicle or the related AV system, vision data in the vehicle or the related AV system, or any past data in the vehicle or the related AV system.

[0048] Generally, in an aspect, a method includes: (a) receiving machine-readable instructions from a remote operator regarding operation of a vehicle; and (b) configuring the vehicle to execute the machine-readable instructions. The vehicle can include one or more autonomous driving capabilities. The machine-readable instructions can represent one or more of: a current location, a target location, one or more trajectories, one or more trajectory sample points, one or more velocity profiles, or one or more impassable road segments. The machine-readable instructions can include enabling, editing, or disabling hardware components or software processes. The machine-readable instructions can include enabling, editing, or disabling subcomponents of hardware components or processing steps of software processes. The machine-readable instructions can include overriding travel preferences or travel rules. The intervention can include editing data including one or more of: a map, sensor data in the vehicle or related AV systems, trajectory data in the vehicle or related AV systems, visual data in the vehicle or related AV systems, or any past data in the vehicle or related AV systems.

[0049] These and other aspects, features, and implementations can each be explained in terms of methods, apparatus, systems, components, program products, methods of doing business, means for performing functions, and in other ways.

[0050] These and other aspects, features, and implementations can be discerned from the following description of certain exemplary implementations, which are provided by way of example in accordance with the rights claimed. BRIEF DESCRIPTION OF DRAWINGS

[0051] Figure 1 is a block diagram of an AV system.

[0052] Figure 2A and Figure 2B shows an example of a remote operation system.

[0053] Figure 3A and Figure 3B shows an example of a remote operation client.

[0054] Figure 4A and Figure 4B shows an example of a remote operation flowchart.

[0055] Figure 5 shows an example of a remote operation server.

[0056] Figures 6-12 shows an example of a remote operation interface. DETAILED DESCRIPTION

[0057] The term "autonomous driving capability" is used broadly to include any function, feature, or facility that can participate in driving of an AV, e.g., other than by human manipulation of a steering wheel, throttle, brakes, or other physical controls of the AV.

[0058] The term "remote operation" is used broadly to include, for example, any instruction, guidance, command, request, order, indication, or other control of or interaction with the autonomous driving capabilities of an AV or AV system sent to the AV or AV system over a communication channel (e.g., wireless or wired). The term "remote operation command" is sometimes used interchangeably with "remote operation" in this document. Remote operation is an example of intervention.

[0059] The term "remote operator" is used broadly to include, for example, any person or any software process or hardware device or any combination thereof that originates, causes, or otherwise is the source of a remote operation. The remote operator can be located locally to the AV or AV system (e.g., occupying the AV, located next to the AV, or one or more steps away from the AV) or remotely from the AV or AV system (e.g., at least 1, 2, 3, 4, 5, 10, 20, 30, 40, 50, 100, 200, 300, 400, 500, 600, 700, 900, or 1000 meters away from the AV).

[0060] The term "remote operation event" is used broadly to include, for example, any occurrence, action, situation, event, or other circumstance for which a remote operation is appropriate, useful, desirable, or necessary.

[0061] The term "remote operation request" is used broadly to include, for example, any communication from the AV or AV system to the remote operator or other part of the remote operation system related to the remote operation.

[0062] The term "tele-interact" or "tele-interaction" is used broadly to include, for example, any virtual interaction between the remote operator and a hardware component or software process of the AV or AV system.

[0063] The term "standby operation" is used broadly to include, for example, any manner, form, or method of action, performance, or activity of the autonomous driving capabilities of the AV following a remote operation request and prior to or concurrent with the corresponding remote operation being received and executed by the AV system.

[0064] The term "trajectory" is used broadly to include, for example, any path or route from one location to another; for example, a path from a pickup location to a drop-off location.

[0065] The term "target" or "target location" is used broadly to include, for example, a location to be reached by the AV, including, for example, a temporary drop-off location, a final drop-off location, or a destination.

[0066] This document describes technologies applicable to any vehicle with one or more autonomous driving capabilities, including fully autonomous vehicles, highly autonomous vehicles, and conditionally autonomous vehicles, such as vehicles referred to as Level 5, Level 4, and Level 3, respectively (see SAE International's standard J3016: Taxonomy and Definitions of Terms Relating to Automated Driving Systems for Road-Based Motor Vehicles, which is incorporated herein by reference in its entirety for more details on the classification of vehicle autonomy). A vehicle with autonomous driving capabilities may attempt to control the steering or speed of the vehicle. The technologies described in this document can be applied to partially autonomous vehicles and driver-assisted vehicles, such as so-called Level 2 and Level 1 vehicles (see SAE International's standard J3016: Taxonomy and Definitions of Terms Relating to Automated Driving Systems for Road-Based Motor Vehicles). One or more of the Level 1, Level 2, Level 3, Level 4, and Level 5 vehicle systems may automate certain vehicle operations (e.g., steering, braking, and map usage) under certain driving conditions based on analysis of sensor inputs. The technologies described in this document can benefit vehicles of any level, ranging from fully autonomous vehicles to manually operated vehicles.

[0067] AV system

[0068] like Figure 1 As shown in FIG, a typical activity of an AV 10 is to safely and reliably drive autonomously, partially manually, or both, through an environment 12 to a destination 14 while avoiding vehicles, pedestrians, cyclists, and other obstacles 16 and obeying the rules of the road (e.g., operating rules or driving preferences). Features, functions, and facilities of an AV or AV system that enable an AV to perform autonomous driving are generally referred to as autonomous driving capabilities.

[0069] The driving of an AV is typically supported by an array of technologies 18 and 20 (e.g., hardware, software, and stored and real-time data), which this document collectively refers to (along with the AV 10) as an AV system 22. In some implementations, one, some, or all of the technologies are located on the AV. In some cases, one, some, or all of the technologies are located at another location, such as at a server (e.g., in a cloud computing infrastructure). Components of the AV system may include one, more, or all of the following (among others).

[0070] 1. Memory 32, which is used to store machine instructions and various types of data.

[0071] 2. One or more sensors 24 for measuring or inferring or both the state and condition of the AV, such as its position, linear and angular velocity and acceleration, and heading (i.e., the direction of the front end of the AV). For example, such sensors can include, but are not limited to: a GPS; an inertial measurement unit that measures both vehicle linear acceleration and angular rate; individual wheel speed sensors for measuring or estimating individual wheel slip rates; individual wheel brake pressure or brake torque sensors; engine torque or individual wheel torque sensors; and steering wheel angle and angular rate sensors.

[0072] 3. One or more sensors 26 for sensing or measuring properties of the AV's environment. For example, such sensors can include, but are not limited to: lidar; radar; monocular or stereo video cameras in the visible, infrared, and / or thermal light spectrum; ultrasonic sensors; time-of-flight (TOF) depth sensors; speed sensors; and temperature and rain sensors.

[0073] 4. One or more devices 28 for communicating measured or inferred or both properties of other vehicles' state and condition, such as position, linear and angular velocity, linear and angular acceleration, and linear and angular heading. These devices include vehicle-to-vehicle (V2V) and vehicle-to-infrastructure (V2I) communication devices, as well as devices for wireless communication over point-to-point or ad hoc networks or both. Devices can communicate across the electromagnetic spectrum (including radio and optical communications) or other media (e.g., acoustic communication).

[0074] 5. One or more data sources 30 for providing historical or real-time or predicted information about the environment 12, or a combination of any two or more of them, including, for example, traffic congestion updates and weather conditions. Such data can be stored on a memory storage unit 32 on the AV or communicated to the AV from a remote database 34 via wireless communication.

[0075] 6. One or more data sources 36 for providing digital road map data extracted from a GIS database, potentially including one or more of: high precision maps of road geometry properties, maps describing road network connectivity properties, maps describing road physical properties such as traffic speed, traffic volume, number of vehicle and bicycle lanes, lane width, lane traffic direction or lane marking type and location or combinations thereof, and maps describing spatial locations of road features such as crosswalks, traffic signs or various types of other travel signals. Such data can be stored on a memory storage unit 32 on the AV, or transmitted to the AV from a remotely located database over wireless communication, or a combination of both.

[0076] 7. One or more data sources 38 for providing historical information about driving properties (e.g., typical speed and acceleration profiles) of vehicles that have previously traveled along local road segments at similar times of day. Such data can be stored on a memory storage unit 32 on the AV, or transmitted to the AV from a remotely located database 34 over wireless communication, or a combination of both.

[0077] 8. One or more computing devices 40 located on the AV for executing algorithms (e.g., processes 42) for generating control actions online (i.e., in real time on the vehicle) based on both real-time sensor data and a priori information, allowing the AV to perform its autonomous driving capabilities.

[0078] 9. One or more interface devices 44 (e.g., displays, mice, tracking points, keyboards, touch screens, speakers, biometric readers, and gesture readers) coupled to the computing devices 40 for providing various types of information and alerts to users (e.g., occupants or remote users) of the AV as well as receiving input from users of the AV. The coupling can be wireless or wired. Any two or more of the interface devices can be integrated into a single one.

[0079] 10. One or more communication interfaces 46 (e.g., wired, wireless, WiMAX, Wi-Fi, Bluetooth, satellite, cellular, optical, near field or radio, or combinations thereof) for transmitting data from remotely located databases 34 to the AV, transmitting sensor data or data related to driving performance to remotely located databases 34, or transmitting communications related to remote operation.

[0080] 11. Functional devices 48 of the AV equipped to receive commands from the computer devices 40 for driving (e.g., steering, accelerating, decelerating, gear selection) and for auxiliary functions (e.g., turn signal activation) and act in accordance with the commands.

[0081] Teleoperation system

[0082] A teleoperation system (which can be remote, local, or a combination thereof to an AV or AV system) can enable a teleoperator to interact with an AV system (e.g., provide commands, visualize driving conditions, and investigate functionality of hardware components or software processes) via a communication channel. The interaction can help the AV system respond adequately to various events.

[0083] Figure 2A An exemplary architecture of a teleoperation system is shown. The teleoperation system 290 can include the following elements (as well as other elements):

[0084] • A teleoperation client 201 (e.g., hardware, software, firmware, or a combination of two or more thereof) that is typically installed on an AV 200 of an AV system 292. The teleoperation client 201 can interact with components of the AV system 292 (e.g., sensors 203, communication devices 204, user interface devices, memory 206, controllers 207, or functional devices, or a combination thereof), e.g., send and receive information and commands. The teleoperation client 201 can communicate with a teleoperation server 210 through a communication interface 204 (which can be at least partially wireless).

[0085] • The teleoperation server 210 can be located in the AV 200 or in a remote location, e.g., at least 0.1, 1, 2, 3, 4, 5, 10, 20, 30, 40, 50, 100, 200, 300, 400, 500, 600, 700, 900, or 1000 meters from the AV 200. The teleoperation server 210 communicates with the teleoperation client 201 using a communication interface 204. In some implementations, the teleoperation server 210 can communicate with multiple teleoperation clients simultaneously; for example, the teleoperation server 210 communicates with another teleoperation client 251 of another AV 250 that is part of another AV system 294. The clients 201 and 251 can communicate with one or more data sources 220 (e.g., a central server 222, remote sensors 224, and remote databases 226, or a combination thereof) to collect data (e.g., road networks, maps, weather, and traffic) to enable autonomous driving capabilities. The teleoperation server 210 can also communicate with the remote data sources 220 for teleoperation of the AV system 292 or 294, or both.

[0086] A user interface 212 presented by the teleoperation server 210 is used by a human teleoperator 214 to participate in the remote operation of the AV system 200. In some cases, the interface 212 can present to the teleoperator 214 what the AV system 200 has sensed or is currently sensing. This presentation can be based on real sensor signals or simulations. In some implementations, the user interface 212 can be replaced by an automated intervention process 211, which makes any decisions on behalf of the teleoperator 214.

[0087] See also Figure 2B In some implementations, the teleoperation client 201 can communicate with two or more teleoperation servers 231 and 232, where the servers transmit and aggregate various information for a single teleoperation operator 214 to conduct a teleoperation session on a user interface 212. In some cases, the teleoperation client 201 can communicate with two or more teleoperation servers (e.g., 231 and 233), which present separate user interfaces (e.g., 212 and 216) to different teleoperators (e.g., 214 and 218), thereby allowing two or more teleoperators (e.g., 214 and 218) to participate in a teleoperation session together. In some cases, automation processes 211 and 215 can automate teleoperation on behalf of the interfaces (e.g., 212 and 216) and the teleoperators (e.g., 214 and 218).

[0088] Figure 3A An exemplary flow chart of a remote operation system 290 is shown. Figure 3B An exemplary architecture of the remote operation client 201 is shown, which may be software loaded on a memory 322 and executed by a processor 320, or may be hardware including one or more of the following: a data bus 310, a processor 320, a memory 322, a database 324, and a communication interface 326. Figure 3A , under initial conditions 301, the AV system operates in a fully autonomous mode (i.e., driving without manual assistance). In step 302, a monitoring process ( Figure 3B In step 303, based on the generated remote operation event, the event processing process ( Figure 3BThe remote operation request can include information about the AV system (e.g., planned trajectory, perceived environment, vehicle components, or a combination thereof, etc.). Meanwhile, the AV system can implement a fallback operation 307 while waiting for a remote operation to be issued by a remote operator.

[0089] In step 304, the remote operator accepts the remote operation request and engages in the remote interaction. The remote interaction can vary; for example, the remote operation server can recommend possible remote operations to the remote operator through an interface, and the remote operator can select one or more of the recommended remote operations and cause the remote operations to be sent to the AV system. In some implementations, the remote operation server presents the environment of the AV system to the remote operator through a user interface, and the remote operator is able to see the environment to select the best remote operation. In some cases, the remote operator can enter computer code as a remote operation. In some examples, the remote operator uses the interface to draw a recommended trajectory for the AV to follow along which to continue driving of the AV.

[0090] Based on the remote interaction, the remote operator can issue an appropriate remote operation, which is then processed by the remote operation processing process (336 in FIG. 3) against the remote operation. In step 305, the remote operation processing process sends the remote operation to the AV system to affect the autonomous driving capabilities of the AV. In step 306, the remote operation ends once the AV system completes execution of the remote operation or aborts the remote operation, or the remote operation is terminated by the remote operator. The AV system can return to the autonomous mode 301, and the AV system listens for another remote operation event. Figure 3B

[0091] Remote operation client

[0092] Figure 4A ​An exemplary flow chart for a remote operation client 201 is shown. In some implementations, the remote operation client 201 may be integrated as part of the AV system 410. In some examples, the remote operation client 201 is distinct from the AV system 410 and maintains communication with the AV system 410. In some instances, the remote operation client 201 may include an AV system monitoring process 420, a remote operation event handling process 430, and a remote operation command handling process 440. The AV system monitoring process 420 may access system information and data 412 for analysis. The analysis results may generate remote events 422 to the remote event handling process 430. The remote operation event handling process 430 may send a remote operation request 434 to the remote operation server 450 and a backup request 432 to the remote operation command handling process 440. In some implementations, the remote operation server 450 may present a user interface 460 for a remote operator 470 to remotely interact with the AV system 410. In response to actions by the remote operator through the user interface, the remote operation server may issue a remote operation command 452 that expresses the remote operation in a form used by the remote operation command processing process 440. The remote operation command processing process 440 converts the remote operation command into an AV system command 442 expressed in a form useful to the AV system 410 and sends the command to the AV system.

[0093] AV system monitoring process. The AV system monitoring process 420 can receive system information and data 412 to monitor the operating state of the AV system 410 (e.g., speed, acceleration, steering, data communication, perception, and trajectory planning). The operating state can be based on directly reading the output of the hardware components or software processes of the AV system 410, or both, or based on indirectly inferring (e.g., computationally or statistically) the output, such as by measuring associated quantities, or both. In some implementations, the AV system monitoring process 420 can derive information from the operating state (e.g., calculating statistics or comparing the monitored conditions with knowledge in a database). Based on the monitored operating state, the derived information, or both, the monitoring process 420 can determine a teleoperation event 422 for which a teleoperation 452 should be generated.

[0094] When the AV system 22( Figure 1 A remote action event ( Figure 4AExamples include: a malfunctioning brake; a tire blowout; a visual sensor's field of view being obstructed; a visual sensor's frame rate falling below a threshold; the AV system's movement not matching the current steering angle, throttle level, brake level, or a combination thereof; faulty software code; a signal strength decrease; a noise level increase; an unknown object perceived in the AV system's environment; a motion planning process failing to find a trajectory toward a goal due to a planning error; a data source (e.g., a database, a sensor, and a map data source) being inaccessible; or a combination thereof.

[0095] In some implementations, a remote operation event (422) can be triggered at an event or upon a request. Examples include: a detour, a protest, a fire, an accident, a flood, a fallen tree or rock, a medical emergency, a police request, a request by an occupant in the AV (e.g., a passenger not liking the AV system's driving behavior), a request by an AV user (e.g., a package sender using the AV system to transport a package wanting to change a new trajectory or a destination), or initiated by a remote operator, or a combination thereof. Figure 4A

[0096] The remote operation event (422) generated by the AV system monitoring process (420) can include one or more of the following pieces of information:

[0097] 1. One or more outputs from hardware components or software processes of the AV system (410), such as a video stream from a camera, a signal from a sensor (e.g., lidar and radar), a tracked object from a perception system, a dynamic quantity (e.g., speed and direction) of the AV system, a throttle level, a brake level, or a trajectory identified by a motion planning process, or a combination thereof.

[0098] 2. A status of hardware components and / or software processes of the AV system (410), such as a malfunction of a sensor operation, a heavy load in a motion planning process, a long queue, or a long time in a decision process. The status information can be used to determine an applicable remote operation.

[0099] ​3. Relationships between measurements and estimates or thresholds. For example, the number of feasible trajectories toward a goal is less than a threshold (e.g., 1, 2, 3, 4, 5, or 10). The number of unknown objects perceived in the environment near the AV system is greater than a threshold (e.g., 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, or 10). The confidence in a variable (e.g., signal strength, velocity, direction, data rate, distance to a perceived object, or geolocated position) falls below a certain threshold (e.g., 100%, 95%, 90%, 85%, 80%, 75%, 70%, 65%, 60%, 55%, or 50%). The deviation of a measured quantity from an estimate exceeds a threshold (e.g., at least 1%, 2%, 3%, 4%, 5%, 10%, 15%, 20%, 25%, 30%, 35%, 40%, 45%, or 50%). The deviation can be set deterministically or the deviation can be inferred probabilistically by machine learning methods.

[0100] 4. Lack of certain data from the AV system 410 or other data sources or both, such as map data, sensor data, connectivity data, GPS data, infrastructure data, or vehicle-to-vehicle data.

[0101] 5. Presence of certain data from the AV system 410 or other data sources or both, such as unexpected occupants in the AV, unexpected logins in the AV system, or unexpected data injected in the AV system 410.

[0102] 6. Presence of a request, such as a request for remote operation assistance by an occupant of the AV or a user of the AV system 410.

[0103] 7. Dangerous conditions in the AV system 410 or in the environment of the AV system 410. Examples include a fire, a flat tire, a bomb.

[0104] 8. Known facts about the AV system 410 or the environment of the AV system 410. Examples include: any objects perceived in the past or current environment of the AV system 410; any past, current, or future rules of travel; any past, current, or future trajectories; construction zones; and lane changes.

[0105] 9. Unidentifiable items. Examples include: the AV system 410 is unable to identify an object detected in the past or current environment of the AV system 410; the AV system 410 is unable to interpret any past, current, or future rules of travel; unable to plan any past, current, or future trajectories; and obstacles on a road segment (e.g., construction zones and detours).

[0106] There are explicit information that suggest the occurrence of an event that can not be based on information from the AV system 410 but can be inferred. For example, in some implementations, the AV system monitoring process 420 can determine or infer a failure in the AV system 410 through pattern recognition. For example, one or more signal values received from the AV system 410 that deviate from a specified pattern can be determined as a system failure. Patterns can be hand-crafted from data or derived via machine learning methods, such as reinforcement learning or deep learning.

[0107] In some implementations, the AV system monitoring process 420 can detect a failure in the AV system 410 through model-based methods. A model of the monitored hardware components or software processes is constructed, and past inputs or past measurements are used to estimate the current state of the model. When a measurement associated with the current state deviates from its estimate, a system failure can occur. For example, the dynamics of the AV with respect to throttle and steering commands are described in a dynamics model, and the monitoring process 420 uses the dynamics model to estimate the dynamics at time t based on the throttle and steering commands at time t-1. When the measured dynamics at time t deviates from the estimated dynamics by at least 1%, 2%, 3%, 4%, 5%, 10%, 15%, 20%, 25%, 30%, 35%, 40%, 45%, or 50%, the monitoring process 420 determines a system failure. The model can be hand-designed or identified using system identification methods, or can be learned using machine learning methods, e.g., neural networks.

[0108] Figure 4B Examples of remote operation events triggered by data from various data sources and their relevance to remote operations are shown, as follows.

[0109] 1. Data from sensors on the AV (481). For example, no images can be sent from a certain vision sensor during a certain time period, which indicates that the vision sensor is no longer functional. This can impact the AV system’s ability to avoid obstacles or park for obstacles in the vision sensor’s field of view.

[0110] 2. Data from sensors external to the AV, e.g., data from other vehicles and infrastructure (482). For example, the AV system can receive a notification from a nearby emergency vehicle and be expected to yield to the emergency vehicle. A remote operator can assist the AV system in finding a suitable parking location at the roadside.

[0111] 3. Data from maps, databases, and other data sources (483). For example, the AV system may have arrived at a dedicated teleoperation zone marked on a map, e.g., an area where the AV system is required to comply with teleoperation from a teleoperation system. The AV system should find a suitable parking location and wait for teleoperation.

[0112] 4. Data from the AV system's perception process (484). For example, the perception process may detect an unknown object on the AV's planned trajectory. The AV system may stop for the object and wait for the remote operator's assistance to classify the object.

[0113] 5. Data from the AV system's motion planning process (485). For example, the motion planning process may not have been able to find a feasible trajectory to the target within a certain amount of time. The remote operator can manually assign a trajectory to move the AV system forward to the target.

[0114] 6. Data from the AV system's control process (486). For example, the AV system's controller may have experienced a fault that renders the AV system undriveable. The remote operator can notify emergency service providers to tow the AV.

[0115] 7. Data from government agencies. For example, data from the police department may show that a road is closed.

[0116] 8. Data mismatch: For example, the perceived road segment differs from the information provided by the map.

[0117] Remote operation event processing process. See again Figure 4A After remote operation event handling process 430 receives remote operation event 422, it can use remote operation event 422 or system information and data 412 or both to derive important characteristics (e.g., safety, fault), which can be included in remote operation request 434. Examples of important characteristics are as follows.

[0118] 1. The current operational state of a hardware component or software process of the AV system 410, which can be a binary metric (eg, indicating active or inactive), a categorical metric, or a numerical scale, or a combination thereof.

[0119] 2. Active teleoperation events, which include a list of teleoperation events for which a teleoperation is being requested or is being handled under a teleoperation, or both. For example, the motion planning process of the AV system 410 can fail to find a feasible trajectory to the goal, and has generated a first teleoperation event. While waiting for a response to the request from the teleoperator, the AV system can perceive the arrival of an ambulance, and generate a second teleoperation event that triggers a second teleoperation request to the teleoperator to instruct the AV system how to yield to the ambulance. The first and second teleoperation events can be placed in the active teleoperation events list 436. The first and second teleoperation events can be merged because they have a similar cause: the motion planning process failed. In other words, when two or more teleoperation events 422 are generated, the teleoperation event handling process 430 can merge some of the teleoperation events 422. The advantage of merging is to let the teleoperator 470 handle similar teleoperation events together.

[0120] 3. Perception data about the environment near the AV system 410, e.g., obstacles perceived by the perception process or video streams from cameras.

[0121] The teleoperation event handling process 430 can generate a fallback request 432 and send it to the teleoperation command handling process 440. The fallback request 432 specifies one or more fallback operations for the AV system 410 to implement in response to the teleoperation event 422 while waiting for one or more teleoperations 452. Examples of fallback operations are described below.

[0122] 1. The AV system can remain in a fully autonomous driving mode, or can allow or request human assistance in a semi-autonomous driving mode or take over driving in a fully manual driving mode (i.e., a mode in which no autonomous driving capability is active).

[0123] 2. The AV system can maintain a nominal (e.g., current) speed or reduce the driving speed.

[0124] 3. The AV system can continue to follow the current trajectory toward the goal. In some cases, the AV system can plan a new trajectory from its current location to a safe parking location (e.g., a parking lot, an empty space on the side of the road, an emergency lane, a shoulder, a green space, and an AV service center). The AV system can maneuver the AV along the new trajectory, which has the ability to stop to avoid traffic congestion or an accident or a collision with an object (e.g., another vehicle or a pedestrian). (Additional information about such maneuvering can be found in U.S. Patent Application Serial No. 15 / 477,833, filed April 3, 2017, and incorporated by reference herein).

[0125] 4. An AV system can invoke a backup system. For example, a cellular communication system can have failed and a satellite communication system can be invoked; a high resolution sensor can have failed and a low resolution sensor can be invoked, where the sensors can include radar, lidar, camera, or video recorder; a remote database (e.g., map data) can have become inaccessible in real time and an on-board database can be invoked for this purpose.

[0126] 5. An AV system can apply a driving model trained in past conditions (e.g., geographic region, daytime, nighttime, and rush hour) to new conditions. For example, a driving model created based on the environment in town A can be applied to driving in town B; a driving model created based on daytime can be applied to driving at night or nighttime.

[0127] 6. An AV system can not be allowed to perform certain travel preferences. For example, a backup operation can not allow the AV system to pass another vehicle.

[0128] In some implementations, the backup request 432 can specify, for example, one or more of the following (as well as a wide variety of other actions and operations and combinations thereof): remain autonomous traversing the currently planned trajectory; change the goal to the AV service center and re-plan the trajectory to the new goal based on autonomous driving; autonomously follow the current trajectory at a lower speed; re-plan the trajectory to stop at the nearest location where it is safe to stop; or autonomously slow down until stopping.

[0129] Each backup operation can have two main attributes: one or more required system processes (e.g., minimum required on-board processes) and a cost of the backup operation (e.g., a computed cost). Examples of system processes include maneuvering, data communication, database access, motion planning, perception or sensing, or combinations thereof. The cost represents how much the backup operation deviates from the nominal autonomous driving mode. For example, a fault-free AV system can drive at a nominal speed (e.g., 40 mph); a backup request to remain autonomous traversing the currently planned trajectory at a reduced speed (e.g., 20 mph) when a faulted process occurs can not require invoking a motion planning process, but can require at least perception and sensing processes so that the AV system can avoid hitting an object. The cost of this example can include how much the speed is reduced compared to the nominal speed of the AV system that is normally driving on the same road; and how much the perception accuracy will be sacrificed by the AV system in performing the perception and sensing processes without invoking the motion planning process.

[0130] The cost of the backup operation can be described, for example, in terms of the backup operation, the remote operation event, and the current operating state of the AV system. When the backup request specifies two or more backup operations, the cost of each backup operation will be added or weighted summed. The selection of one or more appropriate backup operations can be based on priority. Some implementations can utilize a decision tree to determine the hierarchy of the selection. In some implementations, one or more appropriate backup operations to be included in the backup request can be selected based on solving a combinatorial optimization problem. Some implementations of the selection can be based on a machine learning approach in which the best backup operation or set of best backup operations is inferred from a database. The database can include past selections in various remote operation events.

[0131] When a remote operation event is received, the remote operation event handling process 430 can initialize a list of backup operations from which to select and remove backup operations that cannot invoke required system processes or whose cost exceeds a threshold or both. When two or more backup operations remain on the list, the one with the lowest cost can be selected. For example, a first backup operation in which the AV system will traverse a new trajectory to a safe parking location can require the processes of induction, perception, motion planning, and maneuvering to function. A second backup operation in which the AV system immediately begins to decelerate along an existing trajectory until stopping can require only the maneuvering process to be operational. If all required processes of both backup operations remain functional, their costs are compared to determine which backup operation should be executed. If the motion planning process of the AV system fails, the second backup operation will be selected because the first backup operation is infeasible.

[0132] The remote operation event handling process 430 can send a remote operation request 434 to the remote operation server 420. When the remote operation request 434 arrives at the remote operation server 450, the server can place the remote operation request 434 in a queue 451 for assignment of an available human remote operator 470. When the assigned remote operator 470 becomes available, the remote operator 470 is presented with the remote operation request 434 on a remote operation interface 460. The assignment of the remote operator 470 to the remote operation request 434 can be based on one or more of: time (e.g., peak or off-peak hours, season, day and night), knowledge or experience with the vehicle (e.g., vehicle make and model), or knowledge or experience with the vehicle’s neighborhood environment (e.g., country, state, city, town, street, and landmarks), and language to be used (e.g., verbal communication can be used between the remote operator and the user of the AV system; a series of texts can be presented to the user of the AV system).

[0133] The teleoperation request 434 can include one or more of the following: relevant information about AV system failures or other conditions, AV system information and data 412, teleoperation events 422, important features, current active teleoperation events, one or more teleoperations, and data of the AV system associated with each active teleoperation event.

[0134] The teleoperation event processing process 430 can initialize a list of potential teleoperations on the client or the server 450 or both. Each potential teleoperation is associated with one or more (e.g., required) hardware components or software processes or both. Potential teleoperations with unmet requirements can be removed from the list. For example, on the teleoperation server 450, the teleoperator 470 can teleinteract with the AV system 410 through the teleoperation system and issue teleoperation commands 452 including a new trajectory (which can require a maneuvering process and a perception process operable) that enables the AV system 410 to travel along the specified trajectory without hitting any objects. The remaining potential teleoperations on the list can be ranked based on the following: the ease of teleinteracting with the AV system 410 for the teleoperator 470 with respect to the current active teleoperation events. The teleinteraction ranks higher for which more active teleoperation events can be handled.

[0135] The teleoperator 470 can view the information on the interface 460 and issue one or more teleoperation commands 452. The teleoperation commands 452 can be expressed at one or more levels. For example, high-level commands can be expressed in spoken natural language or written natural language, or both, such as “turn right, go straight, and make a U-turn.” Mid-level commands can be expressed as alphanumeric strings, such as “a001, b005, a003,” where a001 is a code for turning right, b005 for going straight, and a003 for making a U-turn. Low-level commands can be expressed as machine instructions, such as,

[0136]

[0137]

[0138] Regardless of the level, the teleoperation commands 452 can include a description of the behavior of the AV system 410 or include one or more steps to be performed by the AV system 410, or both. When the teleoperation command processing process 440 receives the teleoperation commands 452, it converts the teleoperation commands 452 into AV system commands 442 for controlling and maneuvering the AV system.

[0139] AV system commands 442 typically include machine instructions expressed, for example, in assembly language or low-level language (e.g., C / C++). When remote operation commands 452 are expressed in a high-level language such as a natural language, remote operation command processing process 440 can convert remote operation commands 452 to machine instructions for AV system 410.

[0140] Remote operation command processing process. Remote operation command processing process 440 processes the backup request from remote operation event processing process 430 based on one or more remote operation events 422, remote operation commands 452 issued by remote operator 470 via remote operation interface 460, or both. In some implementations, there can be a discrepancy (e.g., a conflict) between backup request 432 and remote operation commands 452. For example, backup request 432 can require AV system 410 to operate along an existing trajectory at a reduced speed, but at the same time, teleoperation command 452 can require AV system 410 to operate along a new trajectory at a nominal speed. Thus, remote operation command processing process 440 must reconcile the discrepancy to ensure that AV system 410 drives safely during the transition between backup operation and remote operation.

[0141] In some implementations, remote operator 470 can initiate remote interaction without backup request 434 being generated. Remote operator 470 can independently initiate remote operation commands 452 to remote operation command processing process 440. For example, weather conditions can change from sunny to snowing, and despite AV system monitoring process 420 not having generated any teleoperation event 422 in response to the weather change, remote operator can request AV system 410 to drive back to an AV service center.

[0142] Remote operation command processing process 440 receives remote operation commands 452 issued by remote operator 470 through remote operation interface 460 and converts remote operation commands 452 to one or more AV system commands 442. AV system commands 442 are then sent to respective hardware components or software processes of AV system 410.

[0143] Remote operation server

[0144] In Figure 4A In some implementations, remote operation system 400 includes a remote operation server 450 that can present interface 460 to allow remote operator 470 to remotely interact with AV system 410 through the remote operation system. Remote operation system 400 enables different types of remote interactions for remote operator 470 to interact with AV system 410 and influence the behavior of the AV system, e.g., influence one or more of the autonomous driving capabilities.

[0145] When the teleoperation server 450 receives a teleoperation request 434, the teleoperation server 450 analyzes the teleoperation request 434 and associated data, such as relevant information of system failure, system information and data 412, teleoperation events 422, important features, current active teleoperation events, data of one or more teleoperations or AV systems associated with each active teleoperation event, or a combination thereof. The teleoperation server 450 can present corresponding information to the teleoperator 470.

[0146] Figure 5 An exemplary architecture of a teleoperation server 501 is shown, which can include software loaded on a memory 520 executed by a processor 522, or can be hardware including one or more of the following: a data bus 510, a processor 520, a memory 522, a database 524, and a communication interface 526.

[0147] When a teleoperation request arrives at the communication interface 526 of the teleoperation server, the teleoperation request can be handled by a queuing process 532. In some implementations, the queuing process 532 can consider a first-in-first-out approach. In some cases, the queuing process 532 can evaluate the urgency of the teleoperation request and subsequently prioritize handling of urgent teleoperation requests. Urgency level can be associated with safety. For example, an event of an AV system on fire can be placed with a high urgency level; an occurrence of a flat tire of an AV system parked in a safe place can be placed with a low urgency level.

[0148] Prioritizing teleoperation requests can utilize a decision tree to determine a hierarchy of existing teleoperation requests. In some implementations, the priority can be based on solving a combinatorial optimization problem. Some implementations of priority can be based on a machine learning method that analyzes a database; for example, the database can include past teleoperation requests.

[0149] The teleoperation server 501 can include an interface manager 534 that presents content to the teleoperator for a teleinteraction session. The teleoperator can conduct a teleinteraction regarding trajectory planning, in which one or more trajectory primitives are used based on a primitive adjustment process 536 (details of which will be described below). When the teleoperator views the relevant information, he can issue teleoperation commands. The teleoperation server can include a teleoperation command publisher 538 to transmit the commands to a teleoperation command handling process of the teleoperation client. In some implementations, the teleoperation command publisher 538 can convert the teleoperation commands into suitable machine instructions, such as alphanumeric strings or computer code.

[0150] The teleinteraction between the teleoperator and the AV system can rely on interface devices. For example, Figure 6The device 600 is shown, which a remote operator can utilize to select what information to display (e.g., perception 612, motion plan 614, or AV system interaction 616, or a combination thereof). In this example, the remote operator can select perception information 612, and the interface 610 can show the field of view from a vision sensor of the AV system. In some cases, the interface 650 can show a bird’s eye view of the vision sensor. Some implementations can include both the field of view and the bird’s eye view. The field of view or the bird’s eye view can be the view currently experienced by the AV system, or a snapshot of the past, or both. The perception information can include map information. The perception information can be an image or a video showing a 2D or 3D view. When presenting a video, the interfaces 610 and 650 can include a navigation bar 618 to allow the remote operator to control the video. In some implementations, the perception information can include processed data; for example, image segmentation, perceived objects in the vision data, objects detected but not recognized in the vision data.

[0151] For example, Figure 7 The device 700 is shown, which a remote operator utilizes to select motion plan information 712 to display on the interface 710. In some implementations, the interface 710 can show a map, a trajectory of the AV, a geographic location of the AV, or a direction of the AV, or a combination thereof. The trajectory can be a current trajectory 730 of the AV at the current time, or can be a snapshot of the past, or a combination thereof. The perception information can be an image or a video showing a 2D or 3D view. When presenting a video, the interfaces 710 and 750 can include navigation bars 720 and 722, respectively. For example, the interface 710 shows the current trajectory 730, but the remote operator can rewind the display of the trajectory by moving the navigation bar 720 to a past time point 722 shown in the interface 750.

[0152] Referring to Figure 2A The remote operation data associated with the remote operation request can be stored by the AV system in a remote database 226, and the remote operation server 210 retrieves the remote operation data from the database 226. In some implementations, the remote operation data can be transmitted by the AV system to the remote operation server along with the remote operation request.

[0153] Remote interaction with the AV system. The remote operation server can enable the remote operator to interact with hardware components or software processes of the AV system, for example, one or more of the autonomous driving capabilities. Different types of remote interactions are allowed. For example, remote interactions about localization help the AV system identify the location of the AV system when the on-board localization process fails; remote interactions about trajectory help the AV system identify a new trajectory or update an existing trajectory; remote interactions about annotations help the AV system identify perceived objects. Many other examples exist.

[0154] Remote interaction regarding localization. When a localization component on the AV system (i.e., a process that determines the geographic location of the AV) fails, a remote operation event is generated for the failed localization. A remote operator can invoke remote interaction regarding localization of the AV system, which directs the AV system to re-localize itself. For example, Figure 8 A scenario is shown in which the AV system is unable to localize itself and sends a remote operation request to a remote operator. For example, the remote operation server presents an interface 810 to the remote operator and allows the remote operator to activate AV system remote interaction 812. The remote operation request can be transmitted with perception data regarding the environment near the AV system, and the interface 810 displays a field of view 814. The remote operator can view the environment and map data and determine the location of the AV system on the map data. The interface 810 can change to interface 850 during the remote interaction and display an overhead view 854 on the map data, and the remote operator can place the location of the AV system at a waypoint 852.

[0155] Information identifying the location of the waypoint 852 is transmitted back to the AV system within the remote operation command. In some implementations, the waypoint 852 identified by the remote operator can be treated as a deterministic command by the remote operation command processing process. Thus, the motion planning process can resume with the waypoint 852 treated as a starting location and search for an optimal trajectory toward the original goal.

[0156] In some implementations, the waypoint 852 can be treated as a non-deterministic location, and the remote operation command processing process can use probabilistic inference to identify a true geographic location on the map data. For example, the waypoint 852 can be treated as prior knowledge, and conditional probabilities regarding the prior knowledge can be computed to infer a true geographic location of the AV system. In some cases, the conditional probabilities can take into account other information including one or more of: perception data of the past or present or both, trajectory data of the past or present or both, map data, sensing data from on-board sensors, sensing data from off-board sensors, and data from external data sources.

[0157] Remote interaction regarding motion planning. When a motion planning process on the AV system fails, a remote operation event can be generated for the failed motion planning process. A remote operator can invoke remote interaction for motion planning of the AV system, which directs the AV system to identify a trajectory.

[0158] For example, Figure 9Scenarios are shown in which the AV system cannot identify a sufficient trajectory and a remote operation request is sent to a remote operator. For example, the remote operation server presents an interface 910 to the remote operator and allows the remote operator to activate AV system remote interaction 912. The remote operation request is transmitted with, for example, AV geographic location or map data or both. In some applications, data about the environment near the AV system can be transmitted with the remote operation request.

[0159] Interface 910 can display a map surrounding AV 930 and a goal 932. The remote operator can review the associated data and determine (e.g., draw) a new trajectory for AV system 930 on the map. Interface 910 can switch to another interface 950 during the remote interaction session and show the new trajectory 952 on the map data. The remote operation command can include the new trajectory and can be sent to the remote operation command processing process on the AV system.

[0160] In some implementations, the remote operator provides one or more seeds 920 of possible trajectories and generates a new trajectory 952 on interface 950. The seeds can be points or trajectory segments. The remote operation command can include the one or more seeds, the new trajectory, or both, and be sent to the remote operation command processing process on the AV system.

[0161] During the remote interaction session, the remote operator can interact with the motion planning process of the AV system. The remote operator can perform one or more of the following:

[0162] • Issue a new goal. The motion planning process then uses map data to build a trajectory through the road network from the AV's current location to the new goal.

[0163] • Issue a series of goals to be traversed in sequence. For example, Figure 10 A remote operator is shown specifying goals 1010, 1020, 1030, and 1040 in a remote interaction session. The motion planning process of the AV system then builds a trajectory with segments 1012, 1022, 1032, and 1042 that starts from its current location and then traverses the series of goals in sequence.

[0164] • Specify one or more road segments of the road network as non-traversable. For example, the motion planning process can then check the current trajectory and check whether the current trajectory traverses any non-traversable road segments of the road network. If so, re-plan the trajectory to avoid the non-traversable road segments. The specification can be integrated into the map, for example, by editing annotations on the map or drawing new road segments or both.

[0165] • Override travel preferences or travel rules. In some implementations, certain events can cause the AV system to get stuck if the AV system keeps executing its travel preferences or travel rules, and a remote operator can issue a teleoperation command to override the travel preferences or travel rules. For example, an unusual event (e.g., a fire, a protest, an ambulance, construction, a detour, or a marathon race) can occur on the road the AV system is driving on, and a remote operator can command the AV system to bypass the unusual event by executing a lane change to drive on the opposite lane. For example, there can be an object (e.g., a beach ball) blocking the road, but the AV system cannot identify what the object is and can decide to stay put without hitting the object; a remote operation system can be invoked, and after seeing the object via the remote operation system, the remote operator can issue a command to hit the object in order to get the AV system to continue driving.

[0166] In some implementations, the remote interaction can specify one or more of the following elements. The specification can be determined by the remote operator or derived by computation or both.

[0167] • A location (including orientation) of the AV system. In some cases, a series of locations are described, and a transition between two consecutive locations can be added.

[0168] • A speed profile that describes a preferred speed of the AV system over a segment of the trajectory or the entire trajectory. The preferred speed can be specified as a single value, an upper limit, a lower limit, or a range or combination thereof.

[0169] • Attributes of a segment of the trajectory or the entire trajectory. Examples of attributes include one or more of the following: tracking errors, confidence intervals, whether or not modifications by the AV system's motion planning process are allowed or disallowed, and additional data to be considered by the AV system (e.g., updated software processes, software patches, remote databases, areas on the map, updated maps, sensors in the infrastructure, detour information, fire reports, events on the road network, and data sources from government agencies).

[0170] The interface for remote interaction regarding a trajectory can rely on trajectory primitives for the remote operator to generate or manipulate the trajectory. See Figure 11 , the interface can display one or more trajectory primitives: a left turn 1101, a left lane shift 1102, a straight ahead 1103, a straight back, a right lane shift 1104, a right turn 1105, a U-turn left, a U-turn right, parallel parking or no parking, and perpendicular parking or no parking, or combinations thereof, to name a few. The remote operator can select one or more trajectory primitives to generate or manipulate the trajectory. For example, from the following primitives, a trajectory can be assembled by the interface 1100: a lane shift to right 1122, a straight ahead 1124, a right turn 1126, and a straight ahead 1128.

[0171] A primitive can have a set of parameters that can be adjusted by a remote operator. Examples of parameters include one or more of the following: segment length, speed of the AV system upon entering the primitive, speed of the AV system driving along the primitive, AV speed upon reaching the end of the primitive, lane changes allowed or prohibited, radii of turns (e.g., left, right, and U-turns), difference between start and end locations (including orientation) of a turn, maximum allowed yaw rate of the AV during traversal of the primitive, and end location of the primitive.

[0172] Referring to Figure 5 , the remote operation server 501 can include a primitive adjustment process 536 to handle parameters across primitives. When a particular parameter is set by a remote operator, the primitive adjustment process 536 can ensure that other parameters are automatically modified to be compatible with the current adjustment. For example, when a remote operator is configuring the maximum allowed yaw rate, the primitive adjustment process can automatically modify the entry and exit speeds of the primitive to ensure that the maximum allowed yaw rate is not exceeded. In some cases, the speeds of two connected primitives can be different, e.g., the first primitive can be set to 60 mph and the second primitive can be set to 35 mph; since the AV cannot immediately reduce the speed from 60 mph to 35 mph, the primitive adjustment process can computationally smooth the speed between the two primitives.

[0173] In some implementations, after a first primitive is selected and set by a remote operator, the primitive adjustment process 536 can recommend options of feasible primitives that can be connected with the first primitive. When a second primitive is determined to be connected with the first primitive, the default parameter values of the second primitive can be automatically inferred by the primitive adjustment process 536 to ensure compatibility (e.g., speed, location, and turn) across the connected primitives.

[0174] The primitive adjustment process 536 can utilize other data sources, such as map data, to appropriately set default values of parameters. For example, the entry or exit speed of a primitive can be set according to the speed limit of the road where the AV system is located; the default lateral offset of a lane change maneuver can be automatically set according to the width of the lane where the AV is currently driving.

[0175] Referring to Figure 5 , the remote operation server 501 can include a remote operation command publisher 538 to handle remote operation commands generated by a remote interaction session. The remote operation command publisher 538 can convert the remote operation commands into appropriate machine instructions, such as alphanumeric strings or computer code. The remote operation commands generated by a remote interaction session can include any remote interaction activities that occur during the session. Referring to Figure 4AWhen the remote operation command processing process 440 in the AV system 410 receives a remote operation command 452, the remote operation command processing process 440 can generate, edit, and act upon the remote operation command. In some cases, the remote operation command 452 can include a trajectory, and the remote operation command processing process can treat the trajectory as deterministic or non-deterministic or both, and subsequently execute the trajectory. When the remote operation command processing process 440 treats a trajectory (or a portion of a trajectory) as non-deterministic, editing the trajectory (or the portion of the trajectory) can be based on probabilistic reasoning that takes into account other information including one or more of: past or current or both perception data, past or current or both trajectory data, map data, sensing data from on-board sensors, sensing data from off-board sensors, and data from external data sources.

[0176] In some implementations, the remote operation command processing process 440 can infer missing information. For example, the remote operation command 452 can have specified a pair of locations (including directions) at two locations, but a connecting trajectory from one location to another location can be missing from the remote operation command. The remote operation command processing process 440 can generate a feasible connecting trajectory from one location to another location by itself or by invoking a motion planning process. Inferring missing trajectories can be performed using a rule-based system that, for example, converts a position difference between two locations into a smooth trajectory. Inferring missing trajectories can be considered as an optimization problem where the variables are the intermediate locations between a given pair of locations, and a cost function can be defined as the position difference between the intermediate locations; for example, the cost function can be the sum of squares of the position differences. Minimizing the cost function will result in the best trajectory, which will ensure that the resulting transition presents a smooth and gradual change in driving direction.

[0177] In some implementations, the remote operation command 452 can include a trajectory without a speed profile, and the remote operation command processing process 440 can generate a speed profile that results in a safe traversing trajectory by itself or by invoking a motion planning process by taking into account data from other data sources such as positions and speeds of other objects (e.g., vehicles and pedestrians) from a perception process and road information from a map. The speed profile can be derived through dynamic programming where speed constraints are propagated backward from the end of the trajectory to the beginning of the trajectory according to safety and comfort constraints.

[0178] Remote interaction regarding hardware components or software processes. When a remote operation request arrives at the remote operation server, the remote operator can invoke remote interaction regarding hardware components or software processes (e.g., autonomous driving capabilities) of the AV system. For example, Figure 12The following scenario is shown: a teleoperations server presents an interface 1200 to a teleoperator and allows the teleoperator to activate AV system remote interaction to remotely handle hardware components or software processes (e.g., autonomous driving capabilities) of the AV system. The teleoperator can select a process (e.g., motion planning process 1202 or perception process 1204) and then disable or enable the process. In some cases, the interface 1200 can allow the teleoperator to edit the functionality of the process. In some cases, the interface 1200 can allow the teleoperator to view, create, change, edit, delete, import, or export data entries in an on-board database 1206.

[0179] In some implementations, the interface 1200 can allow the teleoperator to zoom into a software process for editing one or more internal steps or to zoom into a hardware component for editing one or more subcomponents. For example, the teleoperator can select the perception process 1204 and internal steps (e.g., segmentation 1222, object detection 1224, and object recognition and classification 1226) can be displayed. The teleoperator can select a step to view, create, change, edit, delete, enable, disable, invoke, or ignore the parameters or algorithms of the step.

[0180] In some implementations, the interface 1200 can display sensors (e.g., lidar 1232 or vision sensors 1234) of the AV system. In some cases, the interface 1200 can allow the teleoperator to view, edit, enable, or disable the functionality and parameters of the sensors. In some cases, the interface 1200 can allow the teleoperator to view, create, change, edit, delete, enable, disable, invoke, or ignore data acquired from the sensors.

[0181] Generally, in an aspect, a method can include determining that intervention into operation of one or more autonomous driving capabilities of a vehicle is appropriate, enabling a human to provide information for the intervention based on the determination, and causing intervention into operation of the one or more autonomous driving capabilities of the vehicle. Determining that intervention is appropriate can include receiving a request for intervention. Determining that intervention is appropriate can include receiving information about a state or environment of the vehicle or related AV system. The state or environment of the vehicle can include functionality of hardware components or software of the vehicle or AV system.

[0182] In some implementations, the information about the state or environment of the vehicle or AV system can include a signal from a hardware component or software of the vehicle or AV system. Determining that intervention is appropriate can include analyzing the signal to detect presence of unexpected data or lack of expected data. Analyzing the signal can include evaluating a mismatch between a measured quantity of the hardware component or software and a model estimated quantity. Analyzing the signal can include using pattern recognition to evaluate an anomalous pattern in the signal. The anomalous pattern is learned by a machine learning algorithm. Analyzing the signal can include inferring a fault in the hardware component or software. Analyzing the signal can include detecting an unknown object present in the environment of the vehicle or related AV system. Analyzing the signal can include inferring an event occurring or about to occur in the environment of the vehicle or related AV system.

[0183] In some implementations, the request can include a request initiated by a remote operator over a wireless communication channel. The request can include data associated with the state or environment of the vehicle or related AV system. The request can include one or more signals from one or more hardware components or one or more software processes of the vehicle or related AV system.

[0184] In some implementations, based on the determination, causing a backup intervention to an operation of one or more autonomous driving capabilities of the vehicle. The backup intervention can include causing the vehicle or related AV system to enter a fully autonomous driving mode, a semi-autonomous driving mode, or a fully manual driving mode. The backup intervention can include causing the vehicle to operate at a reduced speed. The backup intervention can include identifying a safe parking location. The backup intervention can include generating a new trajectory to the safe parking location. The backup intervention can include invoking a backup hardware component or a backup software process. The backup intervention can include evaluating functional hardware components or functional software processes required to operate the vehicle.

[0185] In some implementations, determining that intervention is appropriate can include evaluating one or more active events associated with the vehicle or related AV system, or associated with an environment of the vehicle or related AV system. Evaluating the one or more events can include merging two or more active events. Enabling a human to provide information for intervention can include maintaining a queue based on one or more determinations that intervention is appropriate. Maintaining the queue can include determining a priority of the intervention based on one or more of the following: a decision tree, a combinatorial optimization, a machine algorithm, and past interventions.

[0186] In some implementations, enabling the person to provide information for the intervention can include assigning the person to provide the information based on the person's availability and one or more of: (a) time, (b) knowledge of the vehicle, (c) knowledge of the vehicle's environment, or (d) language. Enabling the person to provide information for the intervention can include presenting an interactive interface. Presenting the interactive interface can include presenting a field of view or a bird's eye view of a vision sensor of the vehicle. Presenting the interactive interface can include presenting perception information that is current or past or both. Presenting the interactive interface can include presenting trajectories that are current or past or both. Presenting the interactive interface can include presenting motion planning information that is current or past or both. Presenting the interactive interface can include presenting a system diagram of the vehicle that includes one or more hardware components, or one or more software processes, or both. The information for the intervention can include a current location of the vehicle determined by the person, and the intervention can include taking the current location as prior knowledge and updating the current location using an inference algorithm. The intervention is based on a target location of the vehicle identified by the person, and the intervention can include taking the target location as prior knowledge and updating the target location using an inference algorithm. The intervention can include a trajectory discovered by the person, and the intervention can include taking the trajectory as prior knowledge and updating the trajectory using an inference algorithm. The intervention can include one or more trajectory sample points identified by the person, and the intervention can include inferring a trajectory or a trajectory segment based on the one or more trajectory sample points.

[0187] In some implementations, inferring the trajectory or the trajectory segment is based on one or more trajectory primitives. The intervention can include connecting two trajectory segments. Connecting the two trajectory segments can include smoothing the trajectory segments and smoothing a velocity profile across the trajectory segments.

[0188] In some implementations, the intervention can include specifying one or more non- traversable road segments. The intervention can include setting a velocity profile by the person, and the intervention can include taking the velocity profile as prior knowledge and updating the velocity profile using an inference algorithm. The intervention is based on inferring a velocity profile by a learning algorithm. The intervention is based on inferring a turning angle by a learning algorithm. The intervention can include enabling, editing, or disabling a hardware component or a software process. The intervention can include enabling, editing, or disabling a subcomponent of a hardware component or a processing step of a software process. The intervention can include overriding a travel preference or a travel rule. The intervention can include editing data that includes one or more of: a map, sensor data in the vehicle or a related AV system, trajectory data in the vehicle or a related AV system, vision data in the vehicle or a related AV system, or any past data in the vehicle or a related AV system. Configuring the vehicle or a related AV system based on the command includes taking the command as prior knowledge and updating the command using an inference algorithm.

[0189] Generally, in an aspect, an implementation includes a method that includes: (a) receiving an intervention request related to operation of one or more autonomous driving capabilities of a vehicle; (b) causing a human to interact with the vehicle through a communication channel; and (c) issuing an intervention to configure operation of the one or more autonomous driving capabilities of the vehicle.

[0190] In some implementations, the method can include receiving or generating or analyzing information about a state or environment of the vehicle. The information about the state or environment of the vehicle can include functionality of hardware components or software of the vehicle. The information about the state or environment of the vehicle can include signals from hardware components or software of the vehicle. The information about the state or environment of the vehicle can include presence of unexpected data or lack of expected data. The information about the state or environment of the vehicle can include a mismatch between a measured quantity and a model estimated quantity of a hardware component or software of the vehicle. Analyzing the information can include using pattern recognition to assess abnormal patterns in the information. Learning abnormal patterns through a machine learning algorithm. Analyzing the information can include inferring a fault in a hardware component or software. Analyzing the information can include detecting an unknown object present in an environment of the vehicle. Analyzing the information can include inferring an event occurring or about to occur in an environment of the vehicle. The intervention request can include data associated with a state or environment of the vehicle or related AV system. The intervention request can include one or more signals from one or more hardware components or one or more software processes of the vehicle or related AV system.

[0191] In some implementations, the method includes maintaining a queue of one or more intervention requests. Maintaining the queue can include determining a priority of an intervention based on one or more of: a decision tree, combinatorial optimization, a machine algorithm, and past interventions. Assigning a human to interact with the vehicle based on availability of the human and one or more of: (a) time, (b) knowledge of the vehicle, (c) knowledge of an environment of the vehicle, or (d) language. Presenting an interaction interface that includes a field of view or a bird's eye view of a vision sensor of the vehicle. Presenting an interaction interface that includes perception information of the current or past or both. Presenting an interaction interface that includes trajectories of the current or past or both. Presenting an interaction interface that includes motion planning information of the current or past or both. Presenting an interaction interface that includes presenting a system diagram of the vehicle that includes one or more hardware components, or one or more software processes, or both.

[0192] In some implementations, the intervention can include a current location of the vehicle identified by the human, and the intervention can include treating the current location identified by the human as prior knowledge and updating the current location using an inference algorithm. The intervention can include a target location discovered by the human, and the intervention can include treating the target location identified by the human as prior knowledge and updating the target location using an inference algorithm. The intervention can include a trajectory identified by the human, and the intervention can include treating the trajectory identified by the human as prior knowledge and updating the trajectory using an inference algorithm. The intervention can include one or more trajectory sample points identified by the human, and the intervention can include inferring a trajectory or trajectory segment based on the one or more trajectory sample points. Inferring the trajectory or trajectory segment is based on one or more trajectory primitives. The intervention can include connecting two trajectory segments, connecting the two trajectory segments including smoothing the trajectory segments and smoothing a velocity profile across the trajectory segments. The intervention can include specifying one or more non-crossable road segments.

[0193] In some implementations, the intervention can include setting a velocity profile, and the intervention can include treating the velocity profile as prior knowledge and updating the velocity profile using an inference algorithm. The intervention is based on inferring the velocity profile by a learning algorithm. The intervention is based on inferring a turning angle by a learning algorithm. The intervention can include enabling, editing, or disabling a hardware component or a software process. The intervention can include enabling, editing, or disabling a subcomponent of a hardware component or a processing step of a software process. The intervention can include overriding a travel preference or a travel rule. The intervention can include editing data including one or more of: a map, sensor data in the vehicle, trajectory data in the vehicle, visual data in the vehicle, or any past data in the vehicle.

[0194] Generally, in an aspect, an implementation includes a vehicle having autonomous driving capability and including (a) steering, acceleration, and deceleration equipment that are responsive to control signals from a driving control system to autonomously drive the vehicle on a road network, (b) a monitoring element on the vehicle that generates an intervention request for engaging the vehicle in an intervention interaction with a human, and (c) a communication element that receives an intervention from the human that is to be implemented by the driving control system by issuing control signals to the steering, acceleration, and deceleration equipment to cause the vehicle to maneuver to a target location.

[0195] In some implementations, a processor receives information about a state or environment of a vehicle to determine that an intervention is appropriate. The state or environment of the vehicle can include functionality of hardware components or software processes of the vehicle. The information about the state or environment of the vehicle can include signals from the hardware components or software processes of the vehicle. Determining that the intervention is appropriate can include using pattern recognition to assess anomalous patterns in the signals. The anomalous patterns are learned through a machine learning algorithm. Determining that the intervention is appropriate can include detecting that there is unexpected data or a lack of expected data. Determining that the intervention is appropriate can include assessing a mismatch between a measured quantity and a model estimated quantity of a hardware component or software process. Determining that the intervention is appropriate can include inferring a fault in a hardware component or software process. Determining that the intervention is appropriate can include detecting an unknown object present in an environment of the vehicle. Determining that the intervention is appropriate can include inferring an event occurring or about to occur in an environment of the vehicle. The intervention request can include data associated with the state or environment of the vehicle. The intervention request can include one or more signals from one or more hardware components or one or more software processes of the vehicle. A processor causes a backup intervention in a drive control system. The backup intervention can include causing the vehicle to enter a fully autonomous driving mode, a semi-autonomous driving mode, or a fully manual driving mode. The backup intervention can include causing the vehicle to operate at a reduced speed. The backup intervention can include identifying a safe parking location and generating a new trajectory to the safe parking location. The backup intervention can include invoking a backup hardware component or a backup software process. The backup intervention can include assessing functional hardware components or functional software processes needed to operate the vehicle.

[0196] In some implementations, a processor evaluates one or more active intervention requests associated with a vehicle or with an environment of a vehicle. Evaluating the one or more active events can include merging two or more intervention requests. Evaluating the one or more active events can include prioritizing the intervention requests using one or more of the following: a decision tree, a combinatorial optimization, a machine algorithm, and past interventions. A processor that treats a current location specified in an intervention as prior knowledge and uses an inference algorithm to update the current location. A processor that treats a target location specified in an intervention as prior knowledge and uses an inference algorithm to update the target location. A processor that treats a trajectory specified in an intervention as prior knowledge and uses an inference algorithm to update the trajectory. A processor that treats one or more trajectory sample points specified in an intervention as prior knowledge and uses an inference algorithm to update the one or more trajectory sample points. A processor that infers a trajectory or a trajectory segment based on one or more trajectory sample points. Inferring the trajectory or the trajectory segment is based on one or more trajectory primitives. A processor that connects two trajectory segments, which can include smoothing the trajectory segments and smoothing a velocity profile across the trajectory segments. An intervention can include specifying one or more non-crossable road segments. A processor that treats a velocity profile specified in an intervention as prior knowledge and uses an inference algorithm to update the velocity profile.

[0197] In some implementations, a processor executes an intervention to enable, edit, or disable a hardware component or a software process. A processor that executes an intervention to override a travel preference or a travel rule. A processor that executes an intervention to edit data, which includes one or more of the following: a map, sensor data, trajectory data, vision data, or any past data.

[0198] Generally, in an aspect, an implementation includes an apparatus that includes: (a) a processor configured to (1) receive an intervention request related to an operation of a vehicle, and (2) extract motion information or perception information, or both, from the intervention request; and (b) a display configured to (1) display the motion information or the perception information, and (2) allow a user to interact with the operation of the vehicle and record one or more interactions.

[0199] In some implementations, the intervention request can include data associated with a state or an environment of the vehicle or related AV system. The intervention request can include one or more signals from one or more hardware components or one or more software processes of the vehicle or related AV system. The display is configured to present an interactive interface that includes a field of view or a bird’s eye view of a vision sensor of the vehicle. The display is configured to present an interactive interface that includes perception information that is current or past or both. The display is configured to present an interactive interface that includes a trajectory that is current or past or both. The display is configured to present an interactive interface that includes motion planning information that is current or past or both. The display is configured to present an interactive interface that includes a system diagram of the vehicle that includes one or more hardware components, or one or more software processes, or both. A processor that converts the interaction into an intervention for operation of the vehicle.

[0200] In some implementations, the interaction can include specifying a current location of the vehicle, and the processor takes the current location as prior knowledge and uses an inference algorithm to generate an updated current location as the intervention. The interaction can include specifying a target location, and the processor takes the target location as prior knowledge and uses an inference algorithm to generate an updated target location as the intervention. The interaction can include specifying a trajectory, and the processor takes the trajectory as prior knowledge and uses an inference algorithm to generate an updated trajectory as the intervention. The interaction can include specifying one or more trajectory sample points, and the processor infers a trajectory or a trajectory segment based on the one or more trajectory sample points. The inferred trajectory or trajectory segment is based on one or more trajectory primitives. The inferred trajectory can include connecting two trajectory segments, the connecting including smoothing the trajectory segments and smoothing a velocity profile across the trajectory segments.

[0201] In some implementations, the interaction can include specifying one or more non-crossable road segments. In some implementations, the interaction can include setting a velocity profile, and the processor takes the velocity profile as prior knowledge and uses an inference algorithm to generate an updated velocity profile as the intervention. A processor that infers a velocity profile through a learning algorithm and includes the velocity profile in the intervention. A processor that infers a steering angle through a learning algorithm and includes the steering angle in the intervention. The intervention can include enabling, editing, or disabling a hardware component or a software process. The intervention can include overriding a travel preference or a travel rule. The intervention can include editing data that includes one or more of the following: a map, sensor data in the vehicle or related AV system, trajectory data in the vehicle or related AV system, vision data in the vehicle or related AV system, or any past data in the vehicle or related AV system. The intervention can include one or more of the following: a trajectory, a label, a process control, an annotation, and a machine instruction.

[0202] Generally, in an aspect, implementations include a method that includes causing a vehicle to drive in an autonomous mode on a roadway, the vehicle including one or more autonomous driving capabilities, receiving an intervention regarding operation of the one or more autonomous driving capabilities, and analyzing the intervention and configuring one or more hardware components or one or more software processes of the vehicle based on the intervention.

[0203] In some implementations, the intervention can include a current location of the vehicle. Analyzing the intervention can include treating the current location in the intervention as prior knowledge and updating the current location using an inference algorithm. The intervention can include a target location of the vehicle. Analyzing the intervention can include treating the target location in the intervention as prior knowledge and updating the target location using an inference algorithm. The intervention can include a trajectory of the vehicle. Analyzing the intervention can include treating the trajectory in the intervention as prior knowledge and updating the trajectory using an inference algorithm. The intervention can include one or more trajectory sample points of the vehicle. Analyzing the intervention can include treating the one or more trajectory sample points as prior knowledge and updating the one or more trajectory sample points using an inference algorithm. Analyzing the intervention can include inferring a trajectory or a trajectory segment based on the one or more trajectory sample points. Inferring the trajectory or the trajectory segment is based on one or more trajectory primitives. Inferring the trajectory or the trajectory segment can include connecting two shorter trajectory segments, which can include smoothing the shorter trajectory segments and smoothing a velocity profile across the shorter trajectory segments.

[0204] In some implementations, the intervention can include specifying one or more non- traversable road segments. The intervention can include setting a velocity profile. Analyzing the intervention can include treating the velocity profile as prior knowledge and updating the velocity profile using an inference algorithm.

[0205] In some implementations, wherein analyzing the intervention can include inferring a velocity profile by a learning algorithm. Analyzing the intervention can include inferring a steering angle by a learning algorithm. Analyzing the intervention can include enabling, editing, or disabling a hardware component or a software process. Analyzing the intervention can include enabling, editing, or disabling a subcomponent of a hardware component or a processing step of a software process. The intervention can include overriding a travel preference or a travel rule. The intervention can include editing data including one or more of: a map, sensor data in the vehicle or a related AV system, trajectory data in the vehicle or the related AV system, vision data in the vehicle or the related AV system, or any past data in the vehicle or the related AV system.

[0206] Generally, in an aspect, implementations include a method that includes receiving machine-readable instructions from a remote operator regarding operation of a vehicle; and configuring the vehicle to execute the machine-readable instructions.

[0207] In some implementations, the vehicle can include one or more autonomous driving capabilities. The machine-readable instructions represent a current location. The machine-readable instructions represent a target location. The machine-readable instructions represent one or more trajectories. The machine-readable instructions represent one or more trajectory sample points. The machine-readable instructions represent one or more speed profiles. The machine-readable instructions represent one or more impassable road segments. The machine-readable instructions include enabling, editing, or disabling a hardware component or a software process. The machine-readable instructions include enabling, editing, or disabling a processing step of a subcomponent of a hardware component or a software process. The machine-readable instructions include overriding a travel preference or a travel rule. The machine-readable instructions include editing data including one or more of: a map, sensor data in the vehicle or a related AV system, trajectory data in the vehicle or a related AV system, visual data in the vehicle or a related AV system, or any past data in the vehicle or a related AV system.

[0208] Although the description in this document has described implementations in which the remote operator is a human, the remote operator functionality can be performed partially or completely automatically.

[0209] Other implementations are within the scope of the claims.

[0210] CROSS-REFERENCE TO RELATED APPLICATIONS

[0211] This application claims the benefit of U.S. Application Serial No. 15 / 624,780, filed June 16, 2017, U.S. Application Serial No. 15 / 624,802, filed June 16, 2017, U.S. Application Serial No. 15 / 624,819, filed June 16, 2017, U.S. Application Serial No. 15 / 624,838, filed June 16, 2017, U.S. Application Serial No. 15 / 624,839, filed June 16, 2017, and U.S. Application Serial No. 15 / 624,857, filed June 16, 2017, the disclosure of each of the above applications is hereby incorporated by reference in its entirety.

Claims

1. A system comprising: one or more processors; as well as A non-transitory computer-readable storage medium storing instructions that, when executed by the one or more processors, cause the one or more processors to: receiving an intervention request from a vehicle; Treating the current position of the vehicle as a non-deterministic position with conditional probability; identifying a geographic location of the vehicle based on probabilistic reasoning using the conditional probabilities; as well as Intervening in the operation of the autonomous driving capabilities of the vehicle.

2. The system according to claim 1, wherein: The instructions causing the one or more processors to receive the request cause the one or more processors to: Information related to a status or environment of the vehicle or an associated AV system is received, the status or environment of the vehicle including functionality of hardware components or software of the vehicle or the AV system.

3. The system according to claim 1, wherein: The instructions further cause the one or more processors to analyze the request to detect the presence of unexpected data or the absence of expected data, and wherein the instructions causing the one or more processors to analyze the request cause the one or more processors to: assessing a mismatch between a measured quantity and a model estimated quantity of a hardware component or software of the vehicle; or Pattern recognition is used to evaluate the requests for unusual patterns.

4. The system according to claim 3, wherein: Analyzing the request further includes at least one of the following: inferring a fault in said hardware component or said software; Detecting unknown objects in the environment of the vehicle or associated AV system; and Inferring events that are occurring or will occur in the environment of the vehicle or associated AV system.

5. The system according to claim 1, wherein The instructions further cause the one or more processors to implement a backup intervention for operation of the autonomous driving capability of the vehicle, and wherein the backup intervention includes at least one of: Placing the vehicle or associated AV system into a fully autonomous driving mode, a semi-autonomous driving mode, or a fully manual driving mode; and The vehicle is operated at a reduced speed.

6. The system according to claim 5, wherein: The backup intervention includes at least one of the following: Mark safe parking locations; generating a new trajectory to the safe parking position; Invoking an alternate hardware component or an alternate software process; and Evaluate functional hardware components or functional software processes required to operate the vehicle.

7. The system according to claim 1, wherein: Intervention of the vehicle's autonomous driving capabilities includes at least one of the following: evaluating one or more active events associated with the vehicle or associated AV system, or associated with an environment of the vehicle or associated AV system; presenting a field of view or a bird's-eye view of a visual sensor of the vehicle; as well as Presenting an interactive interface includes presenting a current track, a past track, or both.

8. The system according to claim 1, wherein: Intervention of the vehicle's autonomous driving capabilities includes at least one of the following: treating the current location as prior knowledge and using an inference algorithm to identify the geographic location; inferring one or more trajectory segments based on the one or more trajectory primitives; as well as The trajectory segments are connected by smoothing the velocity profile across the trajectory segments.

9. The system according to claim 1, wherein: Intervention of the vehicle's autonomous driving capabilities includes at least one of the following: Designate one or more non-traversable road sections; Inferring steering angles through learning algorithms; and A process step that enables, edits, or disables a subcomponent of a hardware component or a software process.

10. The system according to claim 1, wherein: Intervening in the autonomous driving capabilities of the vehicle includes editing data, wherein the data includes at least one of: a map, sensor data in the vehicle or an associated AV system, trajectory data in the vehicle or an associated AV system, visual data in the vehicle or an associated AV system, or any past data in the vehicle or an associated AV system.

11. A non-transitory computer-readable storage medium storing instructions that, when executed by one or more processors, cause the one or more processors to: receiving an intervention request from a vehicle; Treating the current position of the vehicle as a non-deterministic position with conditional probability; identifying a geographic location of the vehicle based on probabilistic reasoning using the conditional probabilities; and Intervening in the operation of the autonomous driving capabilities of the vehicle.

12. The non-transitory computer-readable storage medium of claim 11, wherein: Receiving the request includes receiving information related to a status or environment of the vehicle or an associated AV system, including functionality of hardware components or software of the vehicle or the AV system.

13. The non-transitory computer-readable storage medium of claim 11, wherein: The instructions further cause the one or more processors to analyze the request to detect the presence of unexpected data or the absence of expected data, and wherein analyzing the request comprises at least one of: assessing a mismatch between a measured quantity and a model estimated quantity of a hardware component or software of the vehicle; or Pattern recognition is used to evaluate the requests for unusual patterns.

14. The non-transitory computer-readable storage medium of claim 13, wherein: Analyzing the request further includes at least one of the following: inferring a fault in said hardware component or said software; Detecting unknown objects in the environment of the vehicle or associated AV system; and Inferring events that are occurring or will occur in the environment of the vehicle or associated AV system.

15. The non-transitory computer-readable storage medium of claim 11, wherein: The instructions further cause the one or more processors to implement a backup intervention for operation of the autonomous driving capability of the vehicle, and wherein the backup intervention includes at least one of: Placing the vehicle or associated AV system into a fully autonomous driving mode, a semi-autonomous driving mode, or a fully manual driving mode; and The vehicle is operated at a reduced speed.

16. The non-transitory computer-readable storage medium of claim 15, wherein: The backup intervention includes at least one of the following: Mark safe parking locations; generating a new trajectory to the safe parking position; Invoking an alternate hardware component or an alternate software process; and Evaluate functional hardware components or functional software processes required to operate the vehicle.

17. The non-transitory computer-readable storage medium of claim 11, wherein: Intervention of the vehicle's autonomous driving capabilities includes at least one of the following: evaluating one or more active events associated with the vehicle or associated AV system, or associated with an environment of the vehicle or associated AV system; presenting a field of view or a bird's-eye view of a visual sensor of the vehicle; as well as Presenting an interactive interface includes presenting a current track, a past track, or both.

18. The non-transitory computer-readable storage medium of claim 11, wherein: Intervention of the vehicle's autonomous driving capabilities includes at least one of the following: treating the current location as prior knowledge and using an inference algorithm to identify the geographic location; inferring one or more trajectory segments based on the one or more trajectory primitives; as well as The trajectory segments are connected by smoothing the velocity profile across the trajectory segments.

19. The non-transitory computer-readable storage medium of claim 11, wherein: Intervention of the vehicle's autonomous driving capabilities includes at least one of the following: Designate one or more non-traversable road sections; Inferring steering angles through learning algorithms; and A process step that enables, edits, or disables a subcomponent of a hardware component or a software process.

20. The non-transitory computer-readable storage medium of claim 11, wherein: Intervening in the autonomous driving capabilities of the vehicle includes editing data, wherein the data includes at least one of: a map, sensor data in the vehicle or an associated AV system, trajectory data in the vehicle or an associated AV system, visual data in the vehicle or an associated AV system, or any past data in the vehicle or an associated AV system.

Citation Information

Patent Citations

  • Processing a request signal regarding operation of an autonomous vehicle

    US11377108B2