Vehicle safety control method, device and equipment

By deploying vehicle control and monitoring models in intelligent connected vehicles, multi-level monitoring of driving data is achieved, solving the safety and reliability issues of intelligent connected vehicles in complex road scenarios and realizing higher vehicle control accuracy and driving safety.

CN120922155APending Publication Date: 2025-11-11GUANGZHOU XIAOPENG MOTORS TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511222438.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-28
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

Intelligent connected vehicles struggle to ensure safety and reliability in complex and ever-changing road scenarios, and existing technologies suffer from insufficient recognition of undefined scenarios or limited processing capabilities.

Method used

By deploying a vehicle control model to analyze current driving data, generating a first control command, and using a pre-trained monitoring model to perform multi-level monitoring of the first control command, assessing its reliability, and then performing safety control of the vehicle based on the monitoring results.

Benefits of technology

It improves the accuracy of vehicle control and driving safety, ensuring the safety and reliability of the vehicle under various conditions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120922155A_ABST
    Figure CN120922155A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a vehicle safety control method, device and equipment. The method comprises the steps that current driving data of a vehicle are acquired; analyzing the current driving data through a vehicle control model to obtain a first control instruction for the vehicle; the current driving data and the vehicle control instruction are analyzed through a pre-trained monitoring model, a monitoring result of the first control instruction is obtained, and the monitoring result includes that the first control instruction is reliable or unreliable; and carrying out safety control on the vehicle according to the monitoring result. The driving safety of the vehicle can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to control technology, including but not limited to a vehicle safety control method, device, and equipment. Background Technology

[0002] With the deep integration of cutting-edge technologies such as artificial intelligence, big data, and cloud computing, intelligent connected vehicles have become a core direction of global automotive industry transformation. However, when faced with complex and ever-changing road scenarios, intelligent connected vehicle control technology may suffer from insufficient recognition or limited processing capabilities for undefined scenarios, making it difficult to ensure vehicle safety and reliability under various conditions.

[0003] Therefore, there is an urgent need to develop a vehicle control system with higher safety performance to support the construction of intelligent transportation systems. Summary of the Invention

[0004] In view of this, the vehicle safety control method, apparatus, and device provided in the embodiments of this application can improve vehicle driving safety. The vehicle safety control method, apparatus, device, and storage medium provided in the embodiments of this application are implemented as follows:

[0005] In a first aspect, embodiments of this application provide a vehicle safety control method, including:

[0006] Obtain the vehicle's current driving data;

[0007] The current driving data is analyzed using a vehicle control model to obtain the first control command for the vehicle.

[0008] The current driving data and the first control command are analyzed by a pre-trained monitoring model to obtain the monitoring result of the first control command. The monitoring result includes whether the first control command is reliable or unreliable.

[0009] The vehicle is subject to safety control based on the monitoring results.

[0010] This embodiment analyzes the acquired current driving data using a deployed vehicle control model to obtain a first control command for the vehicle. A monitoring model then further monitors this first control command to determine its reliability. Based on the reliability of the first control command, further control of the vehicle is implemented. This multi-level monitoring improves the accuracy of vehicle control, thereby enhancing driving safety.

[0011] Secondly, embodiments of this application provide a vehicle safety control device, comprising:

[0012] The acquisition module is used to acquire the vehicle's current driving data;

[0013] The analysis module is used to analyze the current driving data through the vehicle control model to obtain the first control command for the vehicle;

[0014] The determination module is used to analyze the current driving data and the first control command through a pre-trained monitoring model to obtain the monitoring result of the first control command, wherein the monitoring result includes whether the first control command is reliable or unreliable.

[0015] The control module is used to perform safety control on the vehicle based on the monitoring results.

[0016] Thirdly, embodiments of this application provide a computer device, including a memory and a processor, wherein the memory stores a computer program that can run on the processor, and the processor executes the program to implement the method described in embodiments of this application. Attached Figure Description

[0017] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the specification, serve to explain the technical solutions of this application.

[0018] Figure 1 This is a schematic diagram illustrating an application scenario of the vehicle safety control method provided in the embodiments of this application;

[0019] Figure 2 A schematic diagram illustrating the implementation process of the vehicle safety control method provided in this application embodiment;

[0020] Figure 3 A schematic diagram illustrating the implementation process for determining the monitoring result of the first control command, provided in an embodiment of this application;

[0021] Figure 4 A schematic diagram illustrating the implementation process of the vehicle safety control method for data collection provided in this application embodiment;

[0022] Figure 5 A schematic diagram illustrating the training process of the vehicle control model provided in this application embodiment;

[0023] Figure 6 This is a schematic diagram of the training process for the monitoring model provided in an embodiment of this application;

[0024] Figure 7 A schematic diagram of the overall flow of the vehicle safety control method provided in the embodiments of this application;

[0025] Figure 8 This is a schematic diagram of the structure of the vehicle safety control device provided in the embodiments of this application;

[0026] Figure 9A schematic diagram of the structure of a computer device provided in an embodiment of this application. Detailed Implementation

[0027] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the specific technical solutions of this application will be further described in detail below with reference to the accompanying drawings of the embodiments of this application. The following embodiments are used to illustrate this application, but are not intended to limit the scope of this application.

[0028] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.

[0029] In the following description, references are made to “some embodiments,” which describe a subset of all possible embodiments. However, it is understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.

[0030] It should be noted that the terms "first, second, third" used in the embodiments of this application are used to distinguish similar or different objects and do not represent a specific order of objects. It can be understood that "first, second, third" can be interchanged in a specific order or sequence where permitted, so that the embodiments of this application described herein can be implemented in an order other than that illustrated or described herein.

[0031] With breakthroughs in artificial intelligence technology, intelligent connected vehicle control technology has been deeply integrated into the three core areas of intelligent connected vehicles: intelligent driving, intelligent cockpit, and vehicle-to-infrastructure (V2I) communication, driving the transformation of automobiles from "transportation tools" to "intelligent mobile terminals." However, when faced with complex and ever-changing road scenarios, intelligent connected vehicle control technology may have insufficient recognition or limited processing capabilities for undefined scenarios, making it difficult to ensure the safety and reliability of vehicles under various conditions.

[0032] In view of this, embodiments of this application provide a vehicle safety control method. This method analyzes the acquired current driving data through a deployed vehicle control model to obtain a first control command for the vehicle. The first control command is then further monitored by a monitoring model to determine its reliability. Based on the reliability of the first control command, the vehicle is controlled further. Thus, through multi-level monitoring, the accuracy of vehicle control can be improved, thereby enhancing vehicle driving safety.

[0033] Figure 1 This is a schematic diagram illustrating an application scenario of the vehicle safety control method provided in the embodiments of this application. For example... Figure 1As shown, the vehicle safety control method provided in this application embodiment can be applied to vehicle 11. Vehicle 11 can communicate with server 12 through a communication network.

[0034] For example, the vehicle-to-everything (V2N) infotainment system on vehicle 11 communicates with server 12 using communication standards such as V2N (vehicle-to-network), Wi-Fi, and / or 5G networks, enabling server 12 to provide data transmission capabilities for vehicle 11. For instance, vehicle 11 is equipped with an in-vehicle Wi-Fi device, which has already established a communication connection with server 12. The V2N infotainment system and the in-vehicle Wi-Fi device establish a communication connection based on the WLAN protocol, thereby enabling the V2N infotainment system to establish a communication connection with server 12 through the in-vehicle Wi-Fi device. As another example, the V2N infotainment system has 5G communication capabilities, and establishes a communication connection with the server based on a 5G mobile network. The specific communication method between the V2N infotainment system and the server is not limited in this application.

[0035] In some possible embodiments, the vehicle 11 can collect data containing map elements along the route (such as obstacles, parking spaces, driving lanes, signs, etc.) through sensors such as cameras and lidar during operation. The vehicle 11 can process the collected data to obtain map data using the computing resources of its in-vehicle system. The vehicle 11 can also send the collected data to the server 12 through a communication connection, which is not limited.

[0036] Figure 2 This is a schematic diagram illustrating the implementation flow of the vehicle safety control method provided in an embodiment of this application. Figure 2 As shown, the method may include the following steps 201 to 203:

[0037] Step 201: Obtain the vehicle's current driving data.

[0038] In this embodiment of the application, the type of current driving data of the vehicle is not limited. For example, the current driving data of the vehicle may include vehicle status data and sensor data collected during the current driving process.

[0039] The vehicle status data may include real-time vehicle speed, acceleration changes, and precise steering angle, which provide feedback on the vehicle's driving status. The sensor data may include data collected by various sensors deployed on the vehicle, such as road images captured by cameras and distance information detected by millimeter-wave radar.

[0040] In this embodiment of the application, there is no limitation on the acquisition duration of the vehicle's current driving data. For example, it may be to acquire the vehicle's current driving data during a one-minute driving process, or to acquire the vehicle's current driving data during a 30-second driving process, etc.

[0041] Step 202: Analyze the current driving data using the vehicle control model to obtain the first control command for the vehicle.

[0042] In this application embodiment, the type of vehicle control model is not limited. For example, the vehicle control model may be a neural network model, a predictive control model, etc.

[0043] For example, the predictive control model can output a corresponding first control command to the vehicle based on the distance between the vehicle and the vehicle in front, pedestrian information on the road, etc. The first control command may be acceleration, deceleration, parking on the side of the road, braking, steering operation, maintaining the current speed and driving normally, etc.

[0044] In some embodiments, when analyzing current driving data, the vehicle control model may also determine the first control command based on stored historical driving data, such as comparing the current driving data with multiple stored historical driving data, and taking the control command corresponding to the historical driving data with the highest similarity as the first control command.

[0045] Step 203: Analyze the current driving data and the first control command using a pre-trained monitoring model to obtain the monitoring results of the first control command. The monitoring results include whether the first control command is reliable or unreliable.

[0046] In the embodiments of this application, the specific type of monitoring model is not limited. For example, the monitoring model may include a neural network model or a composite model. The monitoring model can be used to evaluate whether the first monitoring instruction is reliable.

[0047] In some embodiments, steps 301 to 302 may be performed to determine the monitoring result of the first control command:

[0048] Step 301: Obtain the vehicle's current driving scenario, which includes environmental information and road information.

[0049] Understandably, when assessing the reliability of vehicle control commands, focusing solely on a single or a few data types, such as relying solely on sensor data, may result in insufficient accuracy in the assessment.

[0050] Based on this, in this embodiment of the application, the current driving scenario of the vehicle can also be obtained, which includes environmental information of the vehicle and road information of the vehicle.

[0051] It should be noted that the driving scenarios in this application embodiment are more specific scenarios. For example, the highway scenario is decomposed into multiple specific scenarios such as the number of lanes, traffic flow, and weather conditions, while the urban road scenario is decomposed into multiple specific scenarios such as intersection type, pedestrian density, and traffic light status.

[0052] For example, taking a complex intersection scenario as an example, it is necessary to consider scenario elements such as traffic signs and markings, and the distribution of pedestrians and vehicles at the intersection. If the road scenario is a highway scenario, the road information in this scenario includes the number of lanes, traffic flow, etc., and the environmental information includes weather conditions, etc.

[0053] Step 302: Input the current driving data, the current driving scenario, and the first control command into the pre-trained monitoring model to obtain the monitoring results of the first control command.

[0054] Here, when determining the monitoring result for the first control command based on the pre-trained monitoring model, it is done according to the vehicle's current driving data, the vehicle's current driving scenario, and the specific content of the first control command. It is evident that this monitoring model comprehensively considers multiple factors when determining the monitoring result for the first control command, thereby improving the accuracy of the reliability assessment of the control command.

[0055] In some embodiments, step 302 can be achieved by performing steps 403 to 405 as follows.

[0056] Step 204: Implement safety controls on the vehicle based on the monitoring results.

[0057] In this embodiment of the application, after obtaining the monitoring results of the first control command through the monitoring model, the vehicle can be safely controlled based on whether the first control command is reliable.

[0058] In this way, multi-level monitoring can improve the accuracy of vehicle control and thus enhance vehicle driving safety.

[0059] Understandably, when vehicle control and monitoring models are in use, the hardware involved may experience functional safety faults, such as sensor malfunctions or computing unit anomalies. These hardware failures can affect the normal operation of the vehicle control and monitoring models, causing the monitoring methods to fail. If the vehicle continues to be controlled based on the evaluation results of the model after the fault occurs, it could potentially lead to a safety accident.

[0060] Based on this, in some embodiments, a first diagnostic result of whether the acquisition module is working properly, and a second diagnostic result of whether the control model and the monitoring model are working properly can also be obtained. The acquisition module is used to collect the vehicle's current driving data and current driving scenario; and to perform safety control on the vehicle based on the first diagnostic result, the second diagnostic result and the monitoring result.

[0061] In other words, the first diagnostic result is used to diagnose whether the hardware involved in the vehicle control model and monitoring model is functioning properly, that is, whether the data acquisition model used to collect the vehicle's current driving data and the current driving scenario is working properly. The second diagnostic result includes whether the control model and monitoring model are operating normally, that is, the second diagnostic result can include the following situations: both the control model and monitoring model are operating normally; neither the control model nor the monitoring model is operating normally; the control model is operating normally but the monitoring model is not operating normally; and the control model is not operating normally but the monitoring model is operating normally.

[0062] In this application embodiment, the implementation method of performing safety control on the vehicle based on the first diagnostic result, the second diagnostic result, and the monitoring result is not limited.

[0063] For example, if both the first and second diagnostic results are normal and the monitoring result indicates that the first control command is reliable, the vehicle can be safely controlled according to the first control command.

[0064] That is, if the data collection model used to collect the current driving data and the current driving scenario of the vehicle can work normally, the control model and the monitoring model can both work normally, and the first control command issued by the vehicle is a reliable command, then the vehicle can be safely controlled according to the first control command.

[0065] If both the first and second diagnostic results are normal, and the monitoring result indicates that the first control command is unreliable, the vehicle will be controlled for safety according to the preset control rules.

[0066] That is, if the data collection model used to collect the current driving data and current driving scenario of the vehicle can work normally, and the control model and monitoring model can both work normally, then it is further determined whether the first control command issued by the vehicle is reliable. If the first control command is unreliable, the vehicle can be controlled safely according to the preset control rules, rather than according to the first control command.

[0067] If the first or second diagnostic result is abnormal, the vehicle will be subject to safety control according to preset control rules.

[0068] That is, if the data acquisition model used to collect the current driving data and current driving scenario of the vehicle may be faulty, or if one or both of the control model and monitoring model cannot operate normally, the vehicle can be safely controlled according to preset control rules.

[0069] The preset control rules include actions such as pulling over to the side of the road, maintaining the current speed, and keeping a safe following distance. Of course, preset control rules may also include other control commands, and there are no restrictions on this.

[0070] In this embodiment, a deployed vehicle control model analyzes the acquired current driving data to obtain a first control command for the vehicle. This first control command is then further monitored by a monitoring model to determine its reliability. Based on the reliability of the first control command, the vehicle is controlled further. This multi-level monitoring improves the accuracy of vehicle control, thereby enhancing driving safety.

[0071] Figure 4 This is a schematic diagram illustrating the implementation flow of the vehicle safety control method provided in an embodiment of this application. Figure 4 As shown, the method may include the following steps 401 to 406:

[0072] Step 401: Obtain the vehicle's current driving data and the vehicle's current driving scenario, which includes environmental information and road information.

[0073] Here, the method of implementing step 401 is the same as the method of implementing steps 201 and 301 in the above embodiments, and will not be described again here.

[0074] Step 402: Analyze the current driving data using the vehicle control model to obtain the first control command for the vehicle.

[0075] Here, the method of implementing step 402 is the same as the method of implementing step 202 in the above embodiment, and will not be described again here.

[0076] Step 403: Input the current driving data and the current driving scenario into the first sub-model of the pre-trained monitoring model to obtain the first confidence level of the first control command.

[0077] Understandably, simply using rule-based matching or statistical analysis methods cannot flexibly adapt to the changing combinations of factors such as road conditions, weather, and traffic when faced with complex and ever-changing real-world road scenarios. For example, in the event of sudden road construction, relying on pre-set simple rules cannot accurately determine the rationality of the generated control commands. Statistical analysis methods, on the other hand, primarily evaluate models based on the statistical characteristics of historical data, lacking a deep understanding and reasoning ability for real-time dynamic scenarios.

[0078] Therefore, a more flexible and accurate monitoring model is needed to further evaluate the rationality of the generated control commands in order to ensure the safety of vehicle operation.

[0079] In the embodiments of this application, the type of pre-trained monitoring model is not limited. For example, in some embodiments, the pre-trained monitoring model includes a first sub-model, a second sub-model, and a fusion model, wherein the first sub-model, the second sub-model, and the fusion model are connected sequentially.

[0080] In this way, after obtaining the vehicle's current driving data and current driving scenario, the current driving data and current driving scenario can be input into the first sub-model of the pre-trained monitoring model. The first sub-model can analyze the current driving data and current driving scenario based on preset rules to determine the first confidence level corresponding to the first control command. The first confidence level is used to characterize whether the first control command is reliable.

[0081] The higher the confidence level, the higher the reliability of the control command.

[0082] In the embodiments of this application, the type of the first sub-model is not limited, such as the first sub-model being a decision tree algorithm model.

[0083] Step 404: Input the current driving data, historical driving data and the second control command into the second sub-model of the pre-trained monitoring model to obtain the second confidence level of the first control command. The historical driving scenario corresponding to the historical driving data is the same as the current driving scenario, and the second control command is the control command corresponding to the historical driving data.

[0084] In this embodiment, a historical driving scenario identical to the current driving scenario can first be searched in the database to obtain a second control command corresponding to the historical driving scenario. This second control command is a highly reliable control command, obtained by analyzing historical driving data under the historical driving scenario within a historical time period. Thus, the current driving data, historical driving data, and the second control command can be input into the second sub-model of a pre-trained monitoring model. Based on the above information, the second sub-model can determine the second confidence level corresponding to the first control command. This second confidence level is used to characterize whether the first control command is reliable.

[0085] The higher the confidence level, the higher the reliability of the control command.

[0086] In the embodiments of this application, the type of the second sub-model is not limited, such as the second sub-model being a Bayesian algorithm model.

[0087] Step 405: The first confidence level and the second confidence level are fused using the fusion model in the pre-trained monitoring model to obtain the monitoring result of the first control command.

[0088] Here, the confidence level of the first control command can be comprehensively analyzed through a fusion model to determine the total confidence level of the first control command, and the monitoring result of the first control command can be determined based on the total confidence level.

[0089] For example, the first control instruction may be determined to be an unreliable instruction if the total confidence level is less than the confidence level threshold, and the first control instruction may be determined to be a reliable instruction if the total confidence level is greater than or equal to the confidence level threshold.

[0090] By implementing this embodiment, the monitoring model combines indicators such as the accuracy of control commands, response time, and decision stability under different scenarios to assign corresponding weights to sub-models and calculate a comprehensive quantitative score to evaluate the performance of the vehicle control model. This makes the evaluation of the vehicle control model more scientific and accurate, and provides more targeted data support for algorithm optimization and model improvement.

[0091] It should be noted that the vehicle control model and the pre-trained monitoring model can be sent to the vehicle by the server, and the vehicle can deploy them in a controller that meets safety requirements.

[0092] Here, the server can first train the monitoring model and the vehicle control model, and then distribute the vehicle control model and the pre-trained monitoring model to the vehicle for use.

[0093] It should be noted that the vehicle can also receive updated vehicle control models and updated monitoring models sent by the server according to preset sending rules, which include real-time sending or periodic sending.

[0094] In other words, when the server updates the vehicle control model and monitoring model to obtain the updated vehicle control model and monitoring model, the server can also send the updated vehicle control model and monitoring model to the vehicle in real time. Alternatively, it can choose to send the updated monitoring model to the vehicle periodically. The period can be once a week, and the updated version of the vehicle control model or monitoring model can be detected and sent. Or, it can be queried and sent according to other periods. This application embodiment does not limit this.

[0095] In this way, the vehicle control model in the vehicle and the monitoring model in the server are synchronized. When the server updates and improves the monitoring model and the vehicle control model, the vehicle side can synchronize these optimized structures in a timely manner, so that the model can be continuously optimized according to the actual scenario and data.

[0096] For example, the server-side optimizes the visual recognition and decision-making algorithms of the vehicle control model for frequent road flooding scenarios during heavy rain, thereby improving the model's ability to cope. In this way, because the various models on the vehicle side are updated in a timely manner, when encountering such scenarios in actual driving, the new algorithm model can be used for evaluation, thus improving the accuracy of the evaluation results and providing reliable assurance for safe vehicle operation.

[0097] In some embodiments, in order to obtain a vehicle control model and a monitoring model, the vehicle may send a request message to the server, the request message being used to request the deployment of the vehicle control model and the monitoring model; the vehicle receives the vehicle control model and the pre-trained monitoring model sent by the server, the pre-trained monitoring model being matched with the version of the vehicle control model.

[0098] In other words, the capabilities of the vehicle control model and the monitoring model deployed in the vehicle are matched; that is, when the vehicle control model is updated, the monitoring model is also updated accordingly. This allows the vehicle control model and the monitoring model to complement each other, avoiding inaccurate evaluation of control commands caused by incompatibility between the new version of the vehicle control model and the old version of the monitoring model, or between the old version of the vehicle control model and the new version of the monitoring model.

[0099] Step 406: Implement safety controls on the vehicle based on the monitoring results.

[0100] Here, the method of controlling the vehicle based on the monitoring results is the same as step 204 in the above embodiment, and will not be repeated here.

[0101] In this embodiment, a deployed vehicle control model analyzes the acquired current driving data to obtain a first control command for the vehicle. This first control command is then further monitored by a monitoring model to determine its reliability. Based on the reliability of the first control command, the vehicle is controlled further. This multi-level monitoring improves the accuracy of vehicle control, thereby enhancing driving safety.

[0102] It should be noted that the vehicle control model and monitoring model used in actual applications are pre-trained. The training process of the vehicle control model and monitoring model is described in detail below.

[0103] The vehicle control model can be trained by executing steps 501 to 503.

[0104] Step 501: Obtain the first training dataset, which includes multiple historical driving scenarios, vehicle driving data and initial control commands corresponding to each historical driving scenario.

[0105] Here, there are no restrictions on how the first training dataset is obtained. For example, the first training dataset can be generated based on the HARA (Hazard Analysis and Risk Assessment) method and an existing scenario library.

[0106] Here, historical driving scenarios are more specific. For example, highway scenarios are broken down into multiple specific scenarios such as the number of lanes, traffic flow, and weather conditions, while urban road scenarios are broken down into multiple specific scenarios such as intersection type, pedestrian density, and traffic light status.

[0107] The first training dataset may include multiple historical driving scenarios, each of which is associated with and stored along with its corresponding vehicle driving data and initial control commands. The initial control commands are determined based on the vehicle driving data within that historical driving scenario, and these initial control commands are reliable control commands.

[0108] Step 502: Input multiple historical driving scenarios and the vehicle driving data corresponding to each historical driving scenario into the preset control model to obtain the training control command corresponding to each historical driving scenario.

[0109] Here, a preset control model is used to analyze the vehicle control commands corresponding to each historical driving scenario to determine the training control commands corresponding to that historical driving scenario. Understandably, these training control commands may be reliable or unreliable.

[0110] Step 503: Based on the initial control command and the training control command, iteratively train the preset control model to obtain the vehicle control model.

[0111] Here, the preset control model can be corrected based on the difference between the initial control command and the training control command. Iterative training of the preset control model can be achieved by using the difference in commands corresponding to multiple historical driving scenarios, thereby obtaining the vehicle control model.

[0112] By implementing this embodiment, the preset control model is trained using a more specific training dataset to obtain a vehicle control model, which enables the generated vehicle control model to be more accurate in determining the vehicle's control commands.

[0113] The training of the monitoring model can be achieved by executing steps 601 to 602.

[0114] Step 601: Obtain the second training dataset. The second training dataset includes multiple training subsets. Each training subset includes historical driving scenarios, historical driving data of vehicles under historical driving scenarios, and historical control commands corresponding to historical driving scenarios. The historical control commands are obtained by the vehicle control model from the analysis of historical driving scenarios.

[0115] Here, there are no restrictions on how the second training dataset is obtained. For example, the second training dataset can be generated based on the Hazard Analysis and Risk Assessment (HARA) method and an existing scenario library.

[0116] Here, historical driving scenarios are further broken down into more specific scenarios. For example, highway scenarios are broken down into multiple specific scenarios such as the number of lanes, traffic flow, and weather conditions, while urban road scenarios are broken down into multiple specific scenarios such as intersection type, pedestrian density, and traffic light status.

[0117] The second training dataset may include multiple training subsets. Each training subset includes a historical driving scenario, historical driving data of the vehicle corresponding to that historical driving scenario, and historical control commands corresponding to that historical driving scenario. The historical control commands are control commands determined by the vehicle control model based on the vehicle's historical driving data under that historical driving scenario. In other words, these historical control commands may be reliable or unreliable.

[0118] Step 602: Input each training subset in the second training dataset into the monitoring model, and iteratively train the monitoring model to obtain the pre-trained monitoring model.

[0119] In the embodiments of this application, the type of monitoring model is not limited. For example, in some embodiments, the monitoring model includes a first sub-model, a second sub-model, and a fusion model, wherein the first sub-model, the second sub-model, and the fusion model are connected sequentially.

[0120] There are no restrictions on the type of the first sub-model; for example, the first sub-model can be a decision tree algorithm model. Similarly, there are no restrictions on the type of the second sub-model; for example, the second sub-model can be a Bayesian algorithm model.

[0121] In this way, the monitoring model can be iteratively trained based on each training subset to obtain a pre-trained monitoring model.

[0122] For example, a training subset can be input into the decision tree algorithm model and the Bayesian algorithm model for iterative training to obtain a trained monitoring model. The output of this monitoring model is the reliability of the historical control commands output by the vehicle control model under historical driving scenarios and historical driving data.

[0123] Here, we employ decision tree and Bayesian algorithms as the core to construct a logical decision tree structure. The decision tree algorithm model can make hierarchical decisions based on different scenarios and vehicle driving data, while the Bayesian algorithm model evaluates the model's reliability from a probabilistic perspective. The combination of the two provides powerful analytical capabilities for the monitoring model.

[0124] The following describes an exemplary application of the embodiments of this application in a real-world application scenario.

[0125] Figure 7 The overall flow of the vehicle safety control method provided in the embodiments of this application is as follows. Figure 7 As shown, the method includes the following:

[0126] (1) Build a monitoring model on the server side and realize the synchronization of vehicle and server models.

[0127] Step 1: Based on HARA and existing scene libraries, a scene definition method is used to structure scene elements and identify specific scene elements, providing basic data support for subsequent model training and optimization. For example, highway scenes are decomposed into multiple element modules such as the number of lanes, traffic flow, and weather conditions, while urban road scenes are decomposed into element modules such as intersection type, pedestrian density, and traffic light status.

[0128] Step 2: Iteratively train the vehicle control model based on the scenario library (first training dataset and second training dataset), and export vehicle control commands, which are then input into the monitoring model. This monitoring model uses deterministic algorithms such as decision trees and Bayesian algorithms. The decision tree classifies and makes decisions on the input data based on pre-defined detailed rules and conditions for different road scenarios and vehicle states. The Bayesian algorithm statistically analyzes the prior probability of the correctness of the vehicle control commands output by the vehicle control model under different scenario elements and vehicle states based on historical data, and updates the posterior probability based on new data. It then scores the capability of the vehicle control model using deep cross-analysis. The inputs are structured driving scenarios, vehicle driving data, and vehicle control commands; the output is the credibility of the cloud-based AI model.

[0129] (2) Deploy and use vehicle control and monitoring models on the vehicle side.

[0130] Step 1: When the iterative optimization of the vehicle control model on the server side is pushed to the vehicle, the monitoring model will also be pushed to the vehicle simultaneously to ensure that the capabilities of the vehicle control model and the monitoring model are matched. The vehicle control model receives the model iterated from the server and outputs the corresponding vehicle control instructions according to the current road scenario input to achieve autonomous driving or other functions. The monitoring model is deployed in the vehicle safety monitoring module, which is a controller that meets safety requirements.

[0131] Step 2: The monitoring model receives the current driving scenario, vehicle driving data, and control commands generated by the vehicle control model. This monitoring model uses algorithms such as decision trees to analyze this data, evaluate the reliability of the control commands, and determine the current credibility of the vehicle control model.

[0132] The hardware safety monitoring module monitors the hardware-related functional safety faults involved in the input and output of the vehicle control model, such as sensor failures and computing unit anomalies, and ensures the normal operation of the monitoring model to prevent the entire system from failing due to hardware problems.

[0133] Step 3: Based on the reliability level of the control commands derived from the monitoring model and the fault diagnosis results of the hardware safety monitoring module, comprehensively determine the current safe state of the vehicle. Specific measures include reminding the driver to take over the vehicle, downgrading the operating mode, or exiting the operation of the AI ​​model to ensure driving safety.

[0134] Implementing this embodiment offers several advantages. First, by utilizing multi-dimensional data and deterministic algorithms, the reliability of the vehicle control model can be more accurately assessed, and potential model problems can be identified in a timely manner, providing a more reliable guarantee for the safe operation of intelligent connected vehicles. Second, the deep application of decision tree algorithms and the collaborative iteration between the server and the vehicle enable the monitoring model to keep pace with changes in the actual scenario and the needs of model optimization, better adapting to complex and ever-changing road environments. Third, it allows the vehicle to take timely and effective countermeasures when faced with anomalies in the vehicle control model, such as warning the driver and switching control strategies, greatly improving the driving safety of intelligent connected vehicles.

[0135] The server can train the vehicle control model and monitoring model in the following ways.

[0136] The server collects road scene data, including but not limited to traffic signs, road markings, vehicle behavior, and pedestrian actions, to build an initial road scene database. This database is used to train the vehicle control model, generating the vehicle control model and its control commands for each scene within the database. Simultaneously, the existing scene database is structured by analyzing scene elements (e.g., road environment, weather, vehicle status). The structured driving scenes and corresponding vehicle control commands are then input into decision tree and Bayesian algorithms for iterative training. This yields a pre-trained monitoring model. The algorithm's output represents the reliability of the vehicle control commands generated by the model under the current driving data and the current scene.

[0137] When the vehicle control model is deployed on the vehicle side, the monitoring model is also deployed on the vehicle's controller (MCU).

[0138] In this way, during the driving process, the vehicle control model outputs corresponding control commands, such as steering angle and speed adjustment, based on the input environmental perception data and through internal calculation and reasoning, in order to achieve autonomous driving or assisted driving functions.

[0139] The monitoring model synchronously reads the environmental elements of the vehicle control model, the output commands of the autonomous driving algorithm, and the current driving status of the vehicle, and outputs the confidence value of the control commands. The confidence value ranges from 0 to 1, with a higher value indicating a more reliable control command.

[0140] The hardware safety monitoring module monitors the hardware-related functional safety faults involved in the input and output of the vehicle control model, such as camera delay, lag, and computing unit abnormalities, and ensures the normal operation of the monitoring model to prevent the entire system from failing due to hardware problems.

[0141] For example, in a large city with heavy traffic, a vehicle is traveling on a busy downtown street. It is during the morning rush hour on a weekday, and the road is congested with traffic, pedestrians are crossing frequently, traffic lights are flashing alternately, and it is drizzling, making the road surface slippery. Based on this environmental data and vehicle status data, the vehicle control model generates a series of vehicle control commands, such as maintaining the current speed, maintaining a safe distance from the vehicle in front, and preparing to deal with possible pedestrians crossing the road.

[0142] The decision tree algorithm in the monitoring model analyzes the input data according to preset rules. It first determines that the current location is a congested urban area with light rain. Based on the road speed limit and the deceleration status of vehicles ahead, it evaluates the rationality of the vehicle control model's speed-maintaining command. The Bayesian algorithm in the monitoring model, on the other hand, uses historical data to determine the prior probability that the vehicle control command issued by the vehicle control model is correct under similar weather and traffic conditions. The posterior probability is updated by incorporating new input data. The results of both algorithms are combined, and a quantitative evaluation is performed from multiple dimensions, including control command accuracy, response time, and decision stability. The final quantitative score for the vehicle control command in the current scenario is 75 points (out of 100), slightly below the preset safety threshold of 80 points. Therefore, the vehicle enters a degraded operating state (speed is not allowed to exceed 30 km / h).

[0143] In related technologies, vehicle control models often rely on single or limited data types when generating vehicle control commands, such as environmental data collected solely from sensors. This solution, however, comprehensively integrates driving scenarios (such as road signs, markings, and the status of other vehicles and pedestrians), vehicle driving data (such as vehicle speed, acceleration, steering angle, and braking status), and vehicle control commands (acceleration, deceleration, and steering commands). This comprehensive data acquisition provides a richer and more complete information foundation for the monitoring model to assess the reliability of control commands.

[0144] Existing technologies employ simple rule-matching algorithms, which struggle to adapt to complex and ever-changing road scenarios. This solution utilizes decision trees and Bayesian algorithms as its core, constructing a logical decision tree structure. Decision trees enable hierarchical decision-making based on different scenarios and vehicle states, while Bayesian algorithms evaluate model reliability from a probabilistic perspective. The combination of these two approaches provides the algorithm with powerful analytical capabilities.

[0145] In related technologies, there is a lack of collaboration between the vehicle and the server, and the vehicle-side algorithms are mostly static. This invention achieves collaborative iteration between the server and the vehicle-side algorithms. The server uses a scenario definition method to modularize the elements of the model training scenario library, and combines the actual operating data uploaded by the vehicle with the control commands generated by the vehicle control model to iteratively optimize the monitoring model. The optimized monitoring model is then synchronized to the vehicle, enabling the model to continuously optimize based on the actual scenario and data.

[0146] Current technologies for assessing the safety of vehicle control models are mostly qualitative, lacking quantitative evaluation methods and making it difficult to accurately measure the model's performance in different scenarios. This solution constructs a quantitative evaluation system to quantitatively analyze multiple key indicators of the vehicle control model. For example, based on the calculation results of decision trees and Bayesian algorithms, combined with indicators such as the accuracy of control commands, response time, and decision stability in different scenarios, appropriate weights are assigned to calculate a comprehensive quantitative score to evaluate the vehicle control model's performance. This makes the evaluation of vehicle control models more scientific and accurate, providing more targeted data support for algorithm optimization and model improvement.

[0147] It should be understood that although the steps in the above flowcharts are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the above flowcharts may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.

[0148] Based on the foregoing embodiments, this application provides a vehicle safety control device, which includes various modules and units included in each module, and can be implemented by a processor; of course, it can also be implemented by specific logic circuits; in the implementation process, the processor can be a central processing unit (CPU), microprocessor (MPU), digital signal processor (DSP) or field programmable gate array (FPGA), etc.

[0149] Figure 8 This is a schematic diagram of the structure of the vehicle safety control device provided in the embodiments of this application, as shown below. Figure 8 As shown, the device 800 includes an acquisition module 801, an analysis module 802, a determination module 803, and a control module 804, wherein:

[0150] The acquisition module 801 is used to acquire the vehicle's current driving data;

[0151] Analysis module 802 is used to analyze the current driving data through the vehicle control model to obtain the first control command for the vehicle;

[0152] The determination module 803 is used to analyze the current driving data and the first control command through a pre-trained monitoring model to obtain the monitoring result of the first control command. The monitoring result includes whether the first control command is reliable or unreliable.

[0153] The control module 804 is used to perform safety control on the vehicle based on the monitoring results.

[0154] In some embodiments, the acquisition module 801 is further configured to acquire the current driving scenario of the vehicle, the current driving scenario including environmental information and road information;

[0155] The analysis module 802 is specifically used to input the current driving data, the current driving scenario, and the first control command into the pre-trained monitoring model to obtain the monitoring results of the first control command.

[0156] In some embodiments, the monitoring model includes a first sub-model, a second sub-model, and a fusion model, and the analysis module 802 includes a first analysis sub-module, a second analysis sub-module, and a fusion module;

[0157] The first analysis submodule is used to input the current driving data and the current driving scenario into the first sub-model to obtain the first confidence level of the first control command;

[0158] The second analysis submodule is used to input the current driving data, historical driving data and the second control command into the second sub-model, and obtain the second confidence level of the first control command based on it. The historical driving scenario corresponding to the historical driving data is the same as the current driving scenario, and the second control command is the control command corresponding to the historical driving data.

[0159] The fusion module is used to fuse the first confidence level and the second confidence level through the fusion model to obtain the monitoring result of the first control command.

[0160] In some embodiments, the acquisition module 801 is further configured to acquire a first diagnostic result of whether the acquisition module is working properly, and a second diagnostic result of whether the control model and the monitoring model are working properly, wherein the acquisition module is configured to acquire the current driving data of the vehicle;

[0161] The control module 804 is specifically used to perform safety control on the vehicle based on the first diagnostic result, the second diagnostic result, and the monitoring result.

[0162] In some embodiments, the control module 804 is further configured to perform safety control on the vehicle according to the first control command when both the first diagnostic result and the second diagnostic result are normal and the monitoring result indicates that the first control command is reliable;

[0163] If both the first and second diagnostic results are normal, and the monitoring result indicates that the first control command is unreliable, the vehicle will be subject to safety control according to preset control rules.

[0164] If either the first or second diagnostic result is abnormal, the vehicle is subjected to safety control according to the preset control rules.

[0165] In some embodiments, the preset control rules include pulling over to the side of the road, maintaining the current speed, and maintaining a safe following distance.

[0166] In some embodiments, the apparatus further includes a receiving module;

[0167] The receiving module is used to receive the vehicle control model and the pre-trained monitoring model sent by the server.

[0168] The vehicle control model is obtained by the server training a preset control model based on a first training dataset. The first training dataset includes multiple historical driving scenarios and vehicle driving data corresponding to each historical driving scenario. The pre-trained monitoring model is obtained by the server training a monitoring model based on an acquired second training dataset. The second training dataset includes multiple historical driving scenario information, historical driving data of the vehicle under each historical driving scenario, and historical control commands corresponding to each historical driving scenario. The historical control commands are obtained by the vehicle control model from analyzing the historical driving scenarios.

[0169] In some embodiments, the apparatus further includes a training module;

[0170] The acquisition module 801 is also used to acquire a first training dataset, which includes multiple historical driving scenarios, vehicle driving data and initial control commands corresponding to each historical driving scenario;

[0171] The training module is used to input the multiple historical driving scenarios and the vehicle driving data corresponding to each historical driving scenario into the preset control model to obtain the training control command corresponding to each historical driving scenario.

[0172] The vehicle control model is obtained by iteratively training the preset control model according to the initial control command and the training control command.

[0173] In some embodiments, the acquisition module 801 is further configured to acquire a second training dataset, which includes multiple training subsets. Each training subset includes a historical driving scenario, historical driving data of the vehicle under the historical driving scenario, and historical control instructions corresponding to the historical driving scenario. The historical control instructions are obtained by the vehicle control model from the analysis of the historical driving scenario.

[0174] The training module is used to input each training subset in the second training dataset into the monitoring model, and to iteratively train the monitoring model to obtain a pre-trained monitoring model.

[0175] In some embodiments, the receiving module is further configured to receive the updated monitoring model sent by the server according to a preset sending rule, wherein the preset sending rule includes real-time sending or periodic sending.

[0176] In some embodiments, the apparatus further includes a request module;

[0177] The request module is used to send request information to the server, and the request information is used to request the deployment of the vehicle control model and the monitoring model;

[0178] The receiving module is also used to receive the vehicle control model and the pre-trained monitoring model sent by the server, wherein the pre-trained monitoring model is matched with the version of the vehicle control model.

[0179] The descriptions of the above device embodiments are similar to those of the above method embodiments, and have similar beneficial effects. For technical details not disclosed in the device embodiments of this application, please refer to the descriptions of the method embodiments of this application for understanding.

[0180] It should be noted that, in the embodiments of this application... Figure 8The module division of the vehicle safety control device shown is illustrative and represents only one logical functional division; in actual implementation, other division methods may be used. Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, exist as separate physical units, or be integrated into one unit by two or more units. The integrated units can be implemented in hardware, as software functional units, or a combination of both.

[0181] It should be noted that, in the embodiments of this application, if the above-described methods are implemented as software functional modules and sold or used as independent products, they can also be stored in a computer-readable storage medium. Based on this understanding, the technical solutions of the embodiments of this application, or the parts that contribute to related technologies, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause an electronic device to execute all or part of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), magnetic disks, or optical disks. Thus, the embodiments of this application are not limited to any specific hardware and software combination.

[0182] This application provides a computer device, which may be a server, and its internal structure diagram may be as follows: Figure 9 As shown, the computer device includes a processor, memory, and a network interface connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and a database. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The database stores data. The network interface communicates with external terminals via a network connection. When the computer program is executed by the processor, it implements the methods described above.

[0183] This application provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the steps of the method provided in the above embodiments.

[0184] This application provides a computer program product containing instructions that, when run on a computer, cause the computer to perform the steps in the method provided in the above-described method embodiments.

[0185] Those skilled in the art will understand that Figure 9The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0186] In one embodiment, the vehicle safety control device provided in this application can be implemented as a computer program, and the computer program can be implemented in the form of, for example, Figure 9 The device operates on the computer device shown. The memory of the computer device can store the various program modules that make up the above-described apparatus. The computer program, composed of the various program modules, causes the processor to execute the steps of the methods in the various embodiments of this application described in this specification.

[0187] It should be noted that the descriptions of the storage medium and device embodiments above are similar to the descriptions of the method embodiments above, and have similar beneficial effects. For technical details not disclosed in the storage medium, storage medium, and device embodiments of this application, please refer to the descriptions of the method embodiments of this application for understanding.

[0188] It should be understood that the phrases "one embodiment," "an embodiment," or "some embodiments" mentioned throughout the specification mean that a specific feature, structure, or characteristic related to an embodiment is included in at least one embodiment of this application. Therefore, "in one embodiment," "in one embodiment," or "in some embodiments" appearing throughout the specification do not necessarily refer to the same embodiment. Furthermore, these specific features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. It should be understood that in the various embodiments of this application, the sequence numbers of the above-described processes do not imply a sequential order of execution; the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application. The sequence numbers of the above-described embodiments are merely for descriptive purposes and do not represent the superiority or inferiority of the embodiments. The descriptions of the various embodiments above tend to emphasize the differences between the various embodiments; their similarities or commonalities can be referred to mutually, and for the sake of brevity, they will not be repeated here.

[0189] In this article, the term "and / or" is merely a description of the relationship between related objects, indicating that there can be three kinds of relationships. For example, object A and / or object B can represent three situations: object A exists alone, object A and object B exist simultaneously, and object B exists alone.

[0190] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0191] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. The embodiments described above are merely illustrative. For example, the division of modules is only a logical functional division, and in actual implementation, there may be other division methods, such as: multiple modules or components can be combined, or integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the various components shown or discussed can be through some interfaces, and the indirect coupling or communication connection between devices or modules can be electrical, mechanical, or other forms.

[0192] The modules described above as separate components may or may not be physically separate. The components shown as modules may or may not be physical modules. They may be located in one place or distributed across multiple network units. Some or all of the modules may be selected to achieve the purpose of this embodiment according to actual needs.

[0193] In addition, each functional module in the various embodiments of this application can be integrated into one processing unit, or each module can be a separate unit, or two or more modules can be integrated into one unit; the integrated modules can be implemented in hardware or in the form of hardware plus software functional units.

[0194] Those skilled in the art will understand that all or part of the steps of the above method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps of the above method embodiments. The aforementioned storage medium includes various media that can store program code, such as mobile storage devices, read-only memory (ROM), magnetic disks, or optical disks.

[0195] Alternatively, if the integrated units described above are implemented as software functional modules and sold or used as independent products, they can also be stored in a computer-readable storage medium. Based on this understanding, the technical solutions of the embodiments of this application, or the parts that contribute to related technologies, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause an electronic device to execute all or part of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as mobile storage devices, ROMs, magnetic disks, or optical disks.

[0196] The methods disclosed in the several method embodiments provided in this application can be arbitrarily combined without conflict to obtain new method embodiments.

[0197] The features disclosed in the several product embodiments provided in this application can be arbitrarily combined without conflict to obtain new product embodiments.

[0198] The features disclosed in the several method or device embodiments provided in this application can be arbitrarily combined without conflict to obtain new method or device embodiments.

[0199] The above description is merely an embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A vehicle safety control method, characterized in that, The method includes: Obtain the vehicle's current driving data; The current driving data is analyzed using a vehicle control model to obtain the first control command for the vehicle. The current driving data and the first control command are analyzed by a pre-trained monitoring model to obtain the monitoring result of the first control command. The monitoring result includes whether the first control command is reliable or unreliable. The vehicle is subject to safety control based on the monitoring results.

2. The method according to claim 1, characterized in that, The step of analyzing the current driving data and the first control command using a pre-trained monitoring model to obtain the monitoring results for the first control command includes: The current driving scenario of the vehicle is obtained, including environmental information and road information; The current driving data, the current driving scenario, and the first control command are input into the pre-trained monitoring model to obtain the monitoring results of the first control command.

3. The method according to claim 2, characterized in that, The monitoring model includes a first sub-model, a second sub-model, and a fusion model. The step of inputting the current driving data, the current driving scenario, and the first control command into the pre-trained monitoring model to obtain the monitoring result for the first control command includes: The current driving data and the current driving scenario are input into the first sub-model to obtain the first confidence level of the first control command; The current driving data, historical driving data, and second control command are input into the second sub-model to obtain the second confidence level of the first control command. The historical driving scenario corresponding to the historical driving data is the same as the current driving scenario, and the second control command is the control command corresponding to the historical driving data. The first confidence level and the second confidence level are fused using the fusion model to obtain the monitoring result of the first control command.

4. The method according to claim 2, characterized in that, The step of performing safety control on the vehicle based on the monitoring results includes: The system acquires a first diagnostic result indicating whether the acquisition module is functioning correctly, and a second diagnostic result indicating whether the control model and the monitoring model are functioning correctly. The acquisition module is used to acquire the vehicle's current driving data and current driving scenario. Based on the first diagnostic result, the second diagnostic result, and the monitoring result, the vehicle is subjected to safety control.

5. The method according to claim 4, characterized in that, The step of performing safety control on the vehicle based on the first diagnostic result, the second diagnostic result, and the monitoring result includes: If both the first and second diagnostic results are normal, and the monitoring result indicates that the first control command is reliable, then the vehicle is subjected to safety control according to the first control command. If both the first and second diagnostic results are normal, and the monitoring result indicates that the first control command is unreliable, the vehicle will be subject to safety control according to preset control rules. If either the first or second diagnostic result is abnormal, the vehicle is subjected to safety control according to the preset control rules.

6. The method according to claim 1, characterized in that, Before acquiring the vehicle's current driving data, the method further includes: Receive the vehicle control model and the pre-trained monitoring model sent by the server; The vehicle control model is obtained by the server training a preset control model based on a first training dataset. The first training dataset includes multiple historical driving scenarios and vehicle driving data corresponding to each historical driving scenario. The pre-trained monitoring model is obtained by the server training a monitoring model based on an acquired second training dataset. The second training dataset includes multiple historical driving scenario information, historical driving data of the vehicle under each historical driving scenario, and historical control commands corresponding to each historical driving scenario. The historical control commands are obtained by the vehicle control model from analyzing the historical driving scenarios.

7. The method according to claim 6, characterized in that, After receiving the vehicle control model and the pre-trained monitoring model from the receiving server, the method further includes: The system receives updated vehicle control models and updated monitoring models sent by the server according to preset sending rules, which include real-time sending or periodic sending.

8. The method according to claim 6, characterized in that, The vehicle control model and the pre-trained monitoring model sent by the receiving server include: Send a request message to the server, the request message being used to request the deployment of a vehicle control model and a monitoring model; The system receives the vehicle control model and the pre-trained monitoring model sent by the server, wherein the pre-trained monitoring model is matched with the version of the vehicle control model.

9. A vehicle safety control device, characterized in that, include: The acquisition module is used to acquire the vehicle's current driving data; The analysis module is used to analyze the current driving data through the vehicle control model to obtain the first control command for the vehicle; The determination module is used to analyze the current driving data and the first control command through a pre-trained monitoring model to obtain the monitoring result of the first control command, wherein the monitoring result includes whether the first control command is reliable or unreliable. The control module is used to perform safety control on the vehicle based on the monitoring results.

10. A computer device comprising a memory and a processor, the memory storing a computer program executable on the processor, characterized in that, When the processor executes the program, it implements the steps of the method according to any one of claims 1 to 8.