Vehicle SOTIF scene library construction method
By building and optimizing the SOTIF scenario library for commercial vehicles, the problem of the difficulty in covering the performance boundaries unique to commercial vehicles in existing technologies has been solved, realizing systematic and automated expected functional safety testing, and improving the efficiency and coverage of the discovery of unknown safety risks.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-29
- Publication Date
- 2026-04-07
AI Technical Summary
Existing technologies are unable to systematically cover and characterize the unique performance boundaries and functions of commercial vehicles, making it impossible to effectively construct boundary danger scenarios that can trigger SOTIF hazards, and making it difficult to fully explore and evaluate the unknown unsafe areas within the operational design domain of commercial vehicle autonomous driving systems.
A vehicle SOTIF scene library is constructed. By constructing original scenes, classifying, labeling, calibrating and standardizing the format, standard scene data is generated. An optimization algorithm is used to perform iterative search in the parameter space to converge and generate boundary hazard scenes, which are then imported into the SOTIF scene library. An evaluation index system is established for testing and verification.
It enables systematic, automated, and targeted functional safety testing of commercial vehicle autonomous driving systems, fills the technical gap in building a dedicated scenario library, improves the efficiency and coverage of discovering unknown safety risks, and changes the passive testing mode that relies on human experience.
Smart Images

Figure CN121808631A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of automotive testing technology, specifically relating to a method for constructing a vehicle SOTIF scenario library. Background Technology
[0002] In the field of Safety for Expected Functions (SOTIF) for Automated Driving, building a test scenario library that can fully expose system performance limitations and unknown risks is fundamental for safety assessment and verification. Existing technologies already include several general scenario library construction schemes for intelligent driving, such as the method for building an intelligent driving scenario library disclosed in patent document CN114647583A, which achieves structured management of scenarios by hierarchically encoding elements such as roads, traffic, and the environment.
[0003] However, this approach has certain shortcomings. Specifically, for commercial vehicles with larger mass, longer size, and longer braking distance, their typical operating conditions, such as long-distance high-speed driving, heavy-load uphill and downhill driving, platooning, and the special risks they face, such as trailer swaying and driver fatigue over long periods, differ significantly from those of conventional passenger vehicles, such as five-seater sedans. This is especially true for commercial vehicles with driver assistance or autonomous driving functions, which are highly dependent on sensors and algorithms. Current general scenario libraries are insufficient to systematically cover and characterize the unique performance boundaries and functions of these commercial vehicles, making it impossible to effectively construct boundary danger scenarios that can trigger SOTIF hazards. Consequently, it is difficult to fully explore and effectively evaluate the unknown unsafe areas within the operational design domain of commercial vehicle autonomous driving systems. Summary of the Invention
[0004] The purpose of this invention is to propose a method for constructing a vehicle SOTIF scene library to solve the problems in the prior art.
[0005] Therefore, the present invention provides a method for constructing a vehicle SOTIF scene library, including: Construct the original scene; The original scenarios are categorized according to test categories, wherein the test categories include at least a variety of restricted scenarios; The categorized scenarios are labeled, and the labels include at least the triggering conditions for specific scenario conditions that indicate the occurrence of dangerous behaviors, and the scope of the autonomous driving system software and hardware modules that are functionally deficient due to the triggering conditions. The scenes are calibrated and characterized as either static scenes containing static environmental information or dynamic scenes containing dynamic interaction sequences. The calibrated static and dynamic scenes are further processed for format standardization to generate corresponding standard scene data. The parameters of the basic scenarios in the standard scenario data are generalized to obtain the parameter space of the logical scenarios. An optimization algorithm is then used to iteratively search the parameter space. Guided by the scenario hazard assessment function, the boundary hazard scenarios used to test the capability boundary of the system are converged and generated, and then imported into the SOTIF scenario library.
[0006] In some embodiments, it also includes: An evaluation index system is established to conduct expected functional safety tests and verifications of the autonomous driving functions of commercial vehicles based on the aforementioned boundary hazardous scenarios.
[0007] In some embodiments, the original scenario includes a commercial vehicle SOTIF base scenario built based on experience and a hazardous scenario collected from the actual vehicle within the vehicle's autonomous driving function ODD.
[0008] In some embodiments, the various restricted scenarios include: Expected functional safety testing scenarios for commercial vehicles under limitations in perception capabilities; and Commercial vehicle expected functional safety testing scenarios under the limitations of decision-making algorithms; and Commercial vehicle expected functional safety testing scenarios under the limitations of control algorithms; and Expected functional safety testing scenarios for commercial vehicles under communication function limitations; and Testing scenarios for expected functional safety of commercial vehicles under limitations of human-computer interaction functions.
[0009] In some embodiments, during the labeling of categorized scenes, the triggering conditions are associated with the scopes, and each triggering condition is configured with a scope that can affect it.
[0010] In some embodiments, the labels of the triggering conditions include a multi-level system, wherein the first level system includes at least one or more of environmental perception, map positioning, decision planning, control execution, V2X communication, and human-computer interaction; The second-level system includes at least one or more of the following: sensor installation location issues, sensor functional limitations, sensor surface issues, data quality issues, and target recognition issues; The scope of application includes at least one or more of the following: sensor hardware, controller, actuator, communication unit, human-machine interface, and sensing algorithm, positioning algorithm, decision planning algorithm, or control algorithm running thereon.
[0011] In some embodiments, the static scene includes a multi-layer model, which includes at least a road structure layer, a road infrastructure layer, a temporary road and facility alteration layer, a traffic participant layer, a natural environment layer, and a communication state layer, wherein each layer includes key information and feature information of the model scene. The dynamic scene includes at least the location and motion information of vehicles or other traffic participants.
[0012] In some embodiments, the step of employing an optimization algorithm to iteratively search the parameter space, guided by a scenario hazard assessment function, to converge and generate boundary hazard scenarios for testing the system capability boundary includes: Define a model for assessing the level of danger in autonomous driving scenarios; Assign corresponding weights to multiple evaluation variables of the model, wherein the evaluation variables include at least one or more of obstacle distance, TTC, speed difference, road conditions, weather conditions, and traffic flow; Based on the current weight combination, calculate the danger score for each scenario in the scenario library; The weights are adjusted to generate neighboring solutions, and a new weight combination that improves the scene hazard score is selected as the current solution. Repeat the iterative optimization steps until the preset termination condition is met, and then determine the high-risk scoring scenarios selected under the final weight combination as boundary danger scenarios.
[0013] In some embodiments, the evaluation index system includes short-term indicators and long-term indicators; The short-term indicators include at least the horizontal and vertical safety clearances, the expansion time interval, and the potential expansion severity index; The long-term metrics include at least the percentage of safe time, the number of takeover requests triggered, and the total number of lane departure warnings triggered.
[0014] In some embodiments, the further format standardization processing of the calibrated static scene and the dynamic scene includes: After performing at least outlier analysis, interpolation, filtering, and curvature continuity operations on the CSV files corresponding to the static and dynamic scenes, an OPENX file is generated.
[0015] Beneficial effects: This invention provides a systematic, automated, and clearly defined method for testing and verifying the Safety in Expected Functional Components (SOTIF) of commercial vehicles in the field of autonomous driving. It not only fills the technological gap in building a dedicated scenario library tailored to the specific characteristics and complexity of commercial vehicles, but more importantly, it changes the traditional passive testing model that relies on human experience, has fragmented test cases, and struggles to cover long-term risks. Through a structured tagging system, it achieves precise management and root cause tracing of massive scenarios. Through intelligent optimized search, it can proactively and efficiently uncover critical and dangerous operating conditions affecting system performance. Attached Figure Description
[0016] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0017] Figure 1 This is a flowchart illustrating the method for constructing a vehicle SOTIF scene library provided by the present invention.
[0018] Figure 2 The overall flowchart of the vehicle SOTIF scene library construction method provided by the present invention is shown.
[0019] Figure 3 The diagram shows the operational scenario of the commercial vehicle autonomous driving function, which is based on the vehicle SOTIF scene library construction method provided by this invention.
[0020] Figure 4 This is a classification diagram of trigger condition tags for the SOTIF scene library provided by the present invention.
[0021] Figure 5 This is a classification diagram of trigger condition tags for the SOTIF scene library provided by the present invention.
[0022] Figure 6 The present invention provides a six-layer model diagram of the expected functional safety scenarios for commercial vehicles.
[0023] Figure 7 The scene calibration flowchart provided by this invention.
[0024] Figure 8 This is a schematic diagram illustrating the format conversion of the scenario in this invention. Detailed Implementation
[0025] The invention will be more readily understood by referring to the following detailed description of preferred embodiments and included examples. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. In case of conflict, the definitions in this specification shall prevail.
[0026] like Figure 1-8 As shown, a method for constructing a vehicle SOTIF scene library includes: Constructing original scenarios. This process leverages expert experience and reasoning analysis to study the elements of expected functional safety scenarios, constructing scenarios that could potentially trigger SOTIF problems. Simultaneously, by screening typical scenarios from the expected functional safety scenario library, typical scenarios are selected to expand the SOTIF basic scenarios. Furthermore, real-vehicle testing is conducted within the Operational Design Domain (ODD), i.e., acquiring actual hazardous scenarios from the vehicle's sensors to expand the SOTIF basic scenarios. Constructing original scenarios ensures a high degree of relevance between hazardous scenarios and reality, giving the scenario library practical significance and value for test vehicles.
[0027] The original scenarios are classified according to test categories, wherein the test categories include at least a variety of restricted scenarios, including restricted perception scenarios, restricted decision-making and planning scenarios, restricted control execution scenarios, restricted communication scenarios, and restricted human-computer interaction scenarios, wherein restricted human-computer interaction scenarios are restricted scenarios under human error.
[0028] The categorized scenarios are labeled, with each label including at least a triggering condition characterizing the specific scenario conditions under which dangerous behavior occurs, and a scope characterizing the autonomous driving system's hardware and software modules that are functionally deficient due to the triggering condition. Specifically, each scenario's label includes at least two parts: a triggering condition and a scope. The triggering condition collectively describes the scenario conditions that lead to dangerous behavior; for example, heavy rain causing water droplets to form on a camera lens. The scope explicitly identifies the specific hardware and software modules of the system that are functionally deficient due to this condition; for example, a forward-looking camera or a visual perception algorithm. Labeling allows for a precise mapping of the risk causes in dangerous scenarios to the system's weaknesses, enabling accurate retrieval of corresponding dangerous scenarios from a scenario database for subsequent analysis.
[0029] Scenes are calibrated and characterized as either static scenes containing static environmental information or dynamic scenes containing dynamic interaction sequences. Static scenes describe fixed information such as roads, traffic facilities, and weather, while dynamic scenes describe the movement sequences of dynamic elements such as vehicles and pedestrians.
[0030] The calibrated static and dynamic scenes undergo further format standardization processing to generate corresponding standard scene data. For example, this data can be converted into industry-standard formats commonly used in various fields, such as OpenDRIVE for describing static roads and OpenSCENARIO for describing dynamic behavior. This format standardization process ensures the compatibility and reproducible applicability of the scene data across different toolchains.
[0031] The basic scenarios in the standard scenario data are generalized to obtain the parameter space of logical scenarios. An optimization algorithm is then used to iteratively search this parameter space, guided by a scenario hazard assessment function, to converge and generate boundary hazard scenarios for testing the system's capability limits. These boundary hazard scenarios are then imported into the SOTIF scenario library. Specifically, based on these standard-format basic scenarios, key parameters such as vehicle speed, distance, and visibility are adjusted to form a broad logical scenario parameter space. Within this space, optimization methods such as hill climbing are used, guided by a hazard assessment function that integrates factors such as distance and speed difference, to iteratively search and ultimately converge to generate a series of boundary hazard scenarios that challenge the system's capability limits. These are then imported into the final SOTIF scenario library. Parameter generalization expands the theoretical scope of test coverage. The optimization algorithm, based on a preset hazard assessment model, performs targeted iterative calculations within this range, continuously adjusting scenario parameters, and ultimately selecting parameter combinations that optimize the assessment function value. These combinations correspond to boundary hazard scenarios with high testing value, while useless hazard scenarios are excluded.
[0032] Ultimately, through the above technical solutions, a SOTIF test scenario library can be constructed that is customized for commercial vehicles with autonomous driving functions, has a clear structure, and can be efficiently managed and applied. This scenario library can systematically find and generate dangerous test cases that are most likely to expose the performance boundaries of the autonomous driving system of commercial vehicles from a massive number of parameter combinations, thereby significantly improving the efficiency and coverage of discovering unknown safety risks and providing direct evidence for targeted testing verification and system improvement.
[0033] In one embodiment, the system further includes establishing an evaluation index system for conducting expected functional safety tests and verifications of the autonomous driving functions of commercial vehicles based on the boundary hazard scenarios. Specifically, as shown below... Figure 2 As shown, standardized evaluation indicators are used to verify the expected functional safety of autonomous driving functions in commercial vehicles by incorporating them into the expected functional safety scenario library. In some embodiments, the evaluation indicators in the expected functional safety scenario library are divided into short-term evaluation indicators and long-term evaluation indicators. Short-term indicators can directly provide evaluation results after a single scenario test of the autonomous driving function of the commercial vehicle. Long-term indicators require the completion of multiple scenario tests to provide a comprehensive evaluation result of the super cruise function of the commercial vehicle.
[0034] The short-term indicators include lateral and longitudinal safety clearance, TTC (Traffic Transmission Control), and the potential collision severity index. The long-term indicators are the percentage of safe time, the number of takeover requests triggered, and the total number of lane departure warnings triggered.
[0035] For example, the lateral and longitudinal safety clearance is specifically explained. The lateral and longitudinal safety clearance index is based on the RSS model and the requirements for maintaining lateral and longitudinal vehicle clearance at different vehicle speeds. The RSS model determines a minimum safety distance by calculating the distance, speed, reaction time, and braking capacity between the vehicles in front and behind.
[0036] The minimum longitudinal safety distance is:
[0037] V f V is the speed of the vehicle in front. r Given the following vehicle's speed, reaction time ρ, and minimum braking acceleration a... min,brake Maximum braking acceleration a max,brake And the maximum acceleration a max,accel .
[0038] The minimum safe distance laterally is:
[0039] μ is a non-negative minimum lateral safety distance parameter, and v1 and v2 are the lateral velocities of vehicle 1 and vehicle 2, respectively.
[0040] and These are the maximum lateral accelerations of vehicles 1 and 2 after a reaction time ρ. lateral velocity, It is the minimum lateral braking acceleration.
[0041] Regarding the Time-to-Collision (TCC) explanation, TTC refers to the time it takes for a vehicle to reach the vehicle in front (or an obstacle) at its current speed. The specific formula is as follows:
[0042] Where d is the relative distance between the two vehicles, v rel This is the relative speed between the two vehicles, which is the speed of the rear vehicle minus the speed of the front vehicle. If the front vehicle is stationary, it is the speed of the rear vehicle itself, and the unit is seconds.
[0043] The Potential Collision Severity Index (PCSI) is explained below. It is used to assess the potential severity of a collision when it is unavoidable. Its specific formula is as follows:
[0044] Where W1i is the heading angle and position weight between the vehicle and the i-th other vehicle; W2i is the relative speed weight between the vehicle and the i-th other vehicle. It is a function of severity; Let be the collision angle between the vehicle and the i-th other vehicle.
[0045] In summary, during the testing and verification of vehicles in the expected functional safety scenario library, short-term indicators are used to evaluate SOTIF performance issues during the functional development phase of commercial vehicles, while long-term indicators are used to evaluate SOTIF performance during the operation phase of commercial vehicles.
[0046] In one embodiment, the various restricted scenarios include: This section describes expected functional safety test scenarios for commercial vehicles under perception limitations. Specifically, it examines situations where the perception system fails to correctly identify hazards due to sensor performance limitations, blind spots, or misunderstandings. The test considers road and environmental factors within these scenarios to assess the safe driving capabilities of the commercial vehicle's autonomous driving system under these limitations. Examples include changes in environmental factors such as lighting, rainfall, snowfall, or alterations to the surface material or color of objects. The test evaluates the safe driving capabilities of the commercial vehicle's autonomous driving system under different scenarios. This section describes a test scenario for the expected functional safety of commercial vehicles under the limitations of decision-making algorithms. Specifically, it tests the adaptability of the autonomous driving system's decision-making function to different traffic conditions or surrounding environments by combining road geographical factors with the vehicle's own and target vehicle's position and behavior, as well as factors such as the movement state of traffic participants and traffic light status. For example, it simulates vehicle movement or traffic behavior in an environment, such as forced lane changes, overtaking, and sudden braking, creating emergency situations to test the adaptability of the autonomous driving system's decision-making function. This section describes a test scenario for the expected functional safety of commercial vehicles under the limitations of their control algorithms. Specifically, it examines factors affecting control, including vehicle and driving environment conditions such as vehicle status and road conditions, to test the effectiveness of the control algorithm in the commercial vehicle's autonomous driving system. These factors include vehicle weight, strong winds, road friction, and road incline. This involves testing expected functional safety scenarios for commercial vehicles under communication limitations. Specifically, it tests the information communication latency, packet loss rate, and other parameters of the positioning device simulation model within a simulation scenario library environment to assess the safe driving capabilities of the commercial vehicle's autonomous driving system under different environments and operating conditions. The expected functional safety test scenario for commercial vehicles under the limitations of human-computer interaction functions, namely the expected functional safety test scenario for commercial vehicles under human error, uses driver-in-the-loop simulation technology and other methods to implement input behaviors such as driver error, delayed operation, and inability to operate, to test the safe driving capability of the commercial vehicle's autonomous driving system under human error.
[0047] By systematically categorizing the original scenarios according to five functional limitations—perception, decision-making, control, communication, and human-machine interaction—the commercial vehicle SOTIF scenario library is transformed from a disorganized collection of scenarios into a systematic testing tool with clear objectives, a rigorous structure, and ease of management and application. This not only ensures the comprehensiveness and representativeness of the scenario library's content but, more importantly, aligns the entire process of scenario generation, management, and application with the fundamental goal of conducting in-depth, quantitative safety assessments of autonomous driving systems, significantly improving the efficiency and effectiveness of expected functional safety development and verification.
[0048] like Figures 3-5 As shown, in one embodiment, during the labeling of categorized scenarios, the triggering conditions are associated with the scopes, and each triggering condition is configured with a scope that can influence it. Here, a triggering condition refers to a specific scenario condition that causes the autonomous driving system to exhibit dangerous behavior, such as adverse environmental conditions or special target object characteristics. When the autonomous driving system has certain functional deficiencies and performance limitations, under the influence of the triggering conditions, the system will deviate from its expected behavior, leading to harm. The scope of the triggering conditions encompasses both the software and hardware components of the autonomous driving system. When functional deficiencies at the vehicle level are triggered by the triggering conditions, harmful behavior will result.
[0049] In such Figure 3 As shown, within the operating range of the commercial vehicle autonomous driving function, the operating scenarios include provincial highways, service areas, intersections (traffic lights), and highways (toll stations, ramps, and main highways). Analysis reveals functional deficiencies and triggering conditions that lead to potential hazards. These triggering conditions are the sources of SOTIF hazards. By overlaying triggering conditions onto the basic scenarios, key scenarios with SOTIF challenges are constructed.
[0050] By tagging the scenario library, the trigger conditions of each autonomous driving system are systematically categorized and tagged. The trigger condition tags are divided into multiple layers according to different granularities and requirements, and combined according to the combination of trigger source and scope. Figure 4 The scenario library categorizes trigger condition labels. Specifically, SOTIF scenario trigger condition labels include environmental perception, decision planning, control execution, map positioning, and vehicle communication / human-machine interaction. Each SOTIF scenario trigger condition consists of a trigger mechanism, a trigger source, and a scope. The trigger mechanism comprises three levels of the trigger condition label. The trigger source refers to the various elements in the aforementioned six-layer scenario architecture, while the scope refers to the hardware and software that constitute each system.
[0051] For example, the basic triggering conditions and scope labels for hazardous scenarios during the operation of some commercial vehicle autonomous driving functions are explained. The triggering conditions include two layers. The first layer includes environmental perception. The second layer, corresponding to environmental perception, includes sensor installation location issues, sensor functional limitations, sensor surface issues, data quality issues, and target recognition issues. The scope of environmental perception is defined as camera / LiDAR / ultrasonic radar / millimeter-wave radar / rain sensor / perception detection and segmentation algorithm. In another example, the first layer is map localization, and the corresponding second layer includes GNSS issues, SLAM (visual / LiDAR) issues, and high-precision map issues. The corresponding scope is defined as GNSS / IMU / HDMAP / domain controller ADU / SLAM algorithm. In another example, the first layer is decision planning, and the corresponding second layer includes complex traffic participants and complex road conditions. The corresponding scope is defined as domain controller ADU / SOC / decision planning algorithm. In yet another example, the first layer is control execution, and the corresponding second layer includes road geometry, road surface conditions, tire status, vehicle external forces, and powertrain system. The corresponding scope is defined as EPS / braking system EBS / control execution algorithm. In another example, the first layer is V2X communication, and the corresponding second layer involves signal source issues, transmission process issues, and reception issues, with the corresponding scope being OBU / RSU / V2X / H2PU. In yet another example, the first layer is human-machine interaction, and the corresponding second layer involves driver issues and remote operation platooning issues, with the scope being HMI / TPMS / HOD / DMS.
[0052] By labeling triggering conditions and scopes, the causal relationships of risks implicit in scenarios can be made explicit, ensuring that each scenario corresponds to a clear combination of risk causes and system vulnerabilities. This allows a massive number of test scenarios to be accurately retrieved, filtered, and categorized based on their fundamental technical attributes, thereby greatly improving the usability of the scenario library and the targeting of testing. In subsequent test analysis, engineers can quickly pinpoint the root cause of problems, whether it stems from specific environmental interference, specific algorithm modules, or specific hardware interfaces, significantly accelerating the diagnosis and remediation of security issues.
[0053] like Figure 6 As shown, in one embodiment, the static scene description is based on a six-layer scene model, namely the road structure layer, road infrastructure layer, temporary road and facility alteration layer, traffic participants layer, natural environment layer, and communication state layer. It records key information and features of the scene and describes the elements that can reflect the expected functional safety features and value of the scene in turn.
[0054] Dynamic scenes utilize the OpenScenario standard to describe vehicle poses, including vehicle position, trajectory, speed, acceleration, and the posture types, position information, and motion information of other traffic participants. It supports scene story creation and global traffic light logic configuration.
[0055] like Figure 7 As shown, scene calibration is performed using a combination of automatic calibration software and manual correction. Specifically, based on the calibration specifications, namely the types of static and dynamic scenes, the automatic calibration software automatically calibrates the pre-generated target list. If there are omissions or errors, manual correction can be used to form the final target list. Finally, the final target list, i.e. the calibration index list, is imported into the SOTIF scene. For calibrated scenes, if scene changes occur, the above calibration process can be repeated.
[0056] like Figure 8 As shown, in one embodiment, the scene format is converted to the OPEN series format. Specifically, to achieve continuous and shared testing scene operation, its format is converted to the OPENX standard series. After performing outlier analysis, interpolation, filtering, curvature continuity, and other operations on the scene data in the specified format, a simulation scene based on OpenDRIVE and OpenSCENARIO is generated.
[0057] Static scene format standards include OpenDRIVE, OpenCRG, RoadXML, and OSM. Dynamic scene format standards include OpenSCENARIO.
[0058] In one embodiment, the step of employing an optimization algorithm to iteratively search the parameter space, guided by a scenario hazard assessment function, to converge and generate boundary hazard scenarios for testing the system's capability boundaries and remove useless scenarios includes: The SOTIF logical scenario is obtained by overlaying trigger conditions onto a basic scenario. Based on the parameter space definition of the scenario (logical scenario), a boundary scenario optimization generation method is used to generalize the scenario and construct boundary scenarios. In the parameter space of the logical scenario, an optimization algorithm is used to quickly and accurately converge to the global optimum to find edge cases. The interaction of vehicles in the scenario is described as an optimization problem. Through optimization iteration, the deviation between the scenario collision risk and the expected collision risk is continuously reduced, and finally, a boundary scenario that can test the unknown and unsafe limits of vehicle capabilities is obtained. The parameter weights of the edge cases are calculated to expand the test range that generates dangerous parameters, thereby generating and filtering more SOTIF dangerous scenarios.
[0059] The hill-climbing algorithm used for screening hazardous scenes in the SOTIF scene library is a heuristic algorithm commonly used to find optimal solutions to problems. It continuously adjusts the current solution in an attempt to gradually reach the optimal solution. Its core idea is to start from an initial solution and gradually approach a local optimum until no better solution can be found. Using the hill-climbing algorithm to screen hazardous boundary scenes for autonomous driving is an attempt to combine local search and optimization ideas. A specific example is given below: Define a model for assessing the hazard level of autonomous driving scenarios. Specifically, define a model for evaluating the hazard level of autonomous driving scenarios. The model is based on multiple assessment variables, such as obstacle distance, TTC (Total Traffic Trouble), speed difference, road conditions, weather conditions, and traffic flow. Each assessment variable is assigned a weight, and the combination of these weights determines the overall hazard score of the scenario.
[0060]
[0061] Where f(x) represents the level of danger in the scenario, M represents the number of all evaluation variables in the scenario, and A i Let be the influence weight of the i-th evaluation variable in the scenario.
[0062] Then, the parameters are initialized; specifically, the weights of each factor are randomly generated or initialized based on empirical knowledge. The expected functional safety library scenario for commercial vehicles, built as described above, is also used.
[0063] Based on the current weight combination, calculate the danger score of each scene in the scene library, and identify the scenes with the highest scores as potential dangerous scenes. Then adjust the weight A. i To generate neighboring solutions, re-evaluate the hazard score f(x) for all scenarios for each neighboring solution. Select the neighboring solution that results in the highest average hazard score (or the largest number of hazardous scenarios) as the new current solution.
[0064] Repeat the iterative optimization steps described above until a preset termination condition is met, such as reaching a preset number of iterations and the risk score no longer significantly improving. When the algorithm terminates, the current weight A... i The combination will be the optimal solution for all weight combinations, at which point weight A i The combined scenario sequence represents a set of scenarios with a high degree of danger. Using this set of weights, the scenario library is re-evaluated to obtain the final expected functional safety scenario library for commercial vehicles.
[0065] Finally, it should be noted that the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A method for constructing a vehicle SOTIF scene library, characterized in that, include: Construct the original scene; The original scenarios are categorized according to test categories, wherein the test categories include at least a variety of restricted scenarios; The categorized scenarios are labeled, and the labels include at least the triggering conditions for specific scenario conditions that indicate the occurrence of dangerous behaviors, and the scope of the autonomous driving system software and hardware modules that are functionally deficient due to the triggering conditions. The scenes are calibrated and characterized as either static scenes containing static environmental information or dynamic scenes containing dynamic interaction sequences. The calibrated static and dynamic scenes are further processed for format standardization to generate corresponding standard scene data. The parameters of the basic scenarios in the standard scenario data are generalized to obtain the parameter space of the logical scenarios. An optimization algorithm is then used to iteratively search the parameter space. Guided by the scenario hazard assessment function, the boundary hazard scenarios used to test the capability boundary of the system are converged and generated, and then imported into the SOTIF scenario library.
2. The method for constructing a vehicle SOTIF scene library according to claim 1, characterized in that, Also includes; An evaluation index system is established to conduct expected functional safety tests and verifications of the autonomous driving functions of commercial vehicles based on the aforementioned boundary hazardous scenarios.
3. The method for constructing a vehicle SOTIF scene library according to claim 1, characterized in that, The original scenarios include the SOTIF basic scenario for commercial vehicles built based on experience and the hazardous scenarios collected from actual vehicles within the ODD of the vehicle's autonomous driving function.
4. The method for constructing a vehicle SOTIF scene library according to claim 1, characterized in that, The various restricted scenarios include: Expected functional safety testing scenarios for commercial vehicles under limitations in perception capabilities; and Commercial vehicle expected functional safety testing scenarios under the limitations of decision-making algorithms; and Commercial vehicle expected functional safety testing scenarios under the limitations of control algorithms; and Expected functional safety testing scenarios for commercial vehicles under communication function limitations; and Testing scenarios for expected functional safety of commercial vehicles under limitations of human-computer interaction functions.
5. The method for constructing a vehicle SOTIF scene library according to claim 1, characterized in that, In the process of labeling the categorized scenes, the triggering conditions are associated with the scopes, and each triggering condition is configured with a scope that can affect it.
6. The SOTIF scene library construction method according to claim 1, characterized in that, The triggering condition labels include multiple hierarchical systems, wherein the first level system includes at least one or more of the following: environmental perception, map positioning, decision planning, control execution, V2X communication, and human-computer interaction; The second-level system includes at least one or more of the following: sensor installation location issues, sensor functional limitations, sensor surface issues, data quality issues, and target recognition issues; The third-level system includes multiple domains, which include at least sensor hardware, controllers, actuators, communication units, human-machine interfaces, and one or more of the sensing algorithms, positioning algorithms, decision planning algorithms, or control algorithms running on them.
7. The SOTIF scene library construction method according to claim 1, characterized in that, The static scene includes a multi-layer model, which includes at least a road structure layer, a road infrastructure layer, a temporary alteration layer of roads and facilities, a traffic participant layer, a natural environment layer, and a communication status layer. Each layer of the model includes key information and feature information of the model scene. The dynamic scene includes at least the location and motion information of vehicles or other traffic participants.
8. The SOTIF scene library construction method according to claim 1, characterized in that, The optimization algorithm iteratively searches the parameter space, guided by the scenario hazard assessment function, to converge and generate boundary hazard scenarios for testing the system's capability boundaries, including: Define a model for assessing the level of danger in autonomous driving scenarios; Assign corresponding weights to multiple evaluation variables of the model, wherein the evaluation variables include at least one or more of obstacle distance, TTC, speed difference, road conditions, weather conditions, and traffic flow; Based on the current weight combination, calculate the danger score for each scenario in the scenario library; The weights are adjusted to generate neighboring solutions, and a new weight combination that improves the scene hazard score is selected as the current solution. Repeat the iterative optimization steps until the preset termination condition is met, and then determine the high-risk scoring scenarios selected under the final weight combination as boundary danger scenarios.
9. The SOTIF scene library construction method according to claim 2, characterized in that, The evaluation index system includes short-term and long-term indicators; The short-term indicators include at least the horizontal and vertical safety clearances, the expansion time interval, and the potential expansion severity index; The long-term metrics include at least the percentage of safe time, the number of takeover requests triggered, and the total number of lane departure warnings triggered.
10. The SOTIF scene library construction method according to claim 1, characterized in that, The format standardization process for the calibrated static and dynamic scenes includes: After performing at least outlier analysis, interpolation, filtering, and curvature continuity operations on the CSV files corresponding to the static and dynamic scenes, an OPENX file is generated.
Citation Information
Patent Citations
Method for building intelligent driving scene library
CN114647583A