Security risk assessment method, device and electronic equipment
By generating and simulating derived road test data during autonomous driving, the problem of accuracy in risk level assessment in autonomous driving has been solved, a unified and objective risk assessment standard has been achieved, and the safety and optimization efficiency of autonomous driving have been improved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING QINGZHOUZHIHANG INTELLIGENT TECH CO LTD
- Filing Date
- 2025-12-31
- Publication Date
- 2026-05-26
AI Technical Summary
In actual road tests of autonomous driving, existing technologies struggle to establish unified and objective risk level assessment standards, resulting in low accuracy in identifying road test risk states and low efficiency in manual analysis, making it difficult to cover all possible risk situations and affecting the safety and optimization efficiency of autonomous driving.
By generating multiple derived road test data of target safety events during autonomous driving, simulating the derived road test data, and assessing the risk level of target safety events based on the simulation results, a unified and objective risk level assessment standard is formed, thereby achieving automated risk level assessment and improving accuracy.
It has achieved automated and objective risk level assessment, improved the accuracy of risk levels, ensured that high-risk issues are addressed first, and enhanced the safety and optimization efficiency of autonomous driving.
Smart Images

Figure CN122085960A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of intelligent driving technology, and in particular to a safety risk assessment method, device and electronic device. Background Technology
[0002] In real-world road tests of autonomous vehicles, planning and control issues will inevitably arise. Accurately identifying the risk status of these issues is crucial for the orderly optimization of autonomous driving. Currently, the risk status of problems encountered in road tests relies primarily on the subjective experience of test engineers. However, different test engineers may have significantly different risk perceptions of the same problem, making it difficult to establish a unified and objective evaluation standard and reducing the accuracy of identifying the risk status of road test problems. Summary of the Invention
[0003] This application provides a security risk assessment method, apparatus, and electronic device to alleviate or solve one or more technical problems existing in the prior art.
[0004] In a first aspect, embodiments of this application provide a security risk assessment method, including: Based on the original road test data corresponding to the target safety event, multiple derived road test data are generated. The target safety event is any one of at least one safety event that occurs during the autonomous driving process of the vehicle. Simulations are performed on the multiple derived road test data to obtain multiple simulation results. Each simulation result is used to characterize the correlation information between the corresponding derived road test data and the target security event. Based on the multiple simulation results, assess the risk level of the target security event.
[0005] Secondly, embodiments of this application provide a security risk assessment device, including: The generation module is used to generate multiple derived road test data based on the original road test data corresponding to the target safety event, wherein the target safety event is any one of at least one safety event that occurs during the autonomous driving process of the vehicle. The simulation module is used to simulate the multiple derived road test data respectively to obtain multiple simulation results. Any simulation result is used to characterize the correlation information between the corresponding derived road test data and the target security event. An evaluation module is used to assess the risk level of the target security event based on the multiple simulation results.
[0006] Thirdly, embodiments of this application provide an electronic device, including a memory, a processor, and a computer program stored in the memory, wherein the processor implements any of the methods of embodiments of this application when executing the computer program.
[0007] Fourthly, embodiments of this application provide a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the method of any one of the embodiments of this application.
[0008] Fifthly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements any of the methods described in the embodiments of this application.
[0009] The technical solution provided in this application generates multiple derived road test data of target safety events occurring during autonomous driving, simulates the derived road test data, and determines the risk level of the target safety events based on the simulation results. This not only establishes a unified and objective risk level assessment standard, achieving automated risk level assessment, but also, by generalizing road test data, allows for a more in-depth risk level assessment, avoiding the limitations of single road test data and thus improving the accuracy of the assessed risk levels. Furthermore, based on this accurate risk level, when optimizing various problems arising in autonomous driving, it ensures that high-risk issues are addressed first, thereby improving the safety of autonomous driving.
[0010] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application, it can be implemented according to the contents of the specification. In order to make the above and other objects, features and advantages of this application more obvious and understandable, specific embodiments of this application are given below. Attached Figure Description
[0011] In the accompanying drawings, unless otherwise specified, the same reference numerals throughout the various drawings denote the same or similar parts or elements. These drawings are not necessarily drawn to scale. It should be understood that these drawings depict only some embodiments according to this application and should not be construed as limiting the scope of this application.
[0012] Figure 1 A flowchart of the security risk assessment method provided in an embodiment of this application is shown; Figure 2 A schematic diagram of the security risk assessment method provided in an embodiment of this application is shown; Figure 3 A schematic diagram of the modules of the security risk assessment device according to an embodiment of this application is shown; Figure 4 A block diagram of an electronic device provided in an embodiment of this application is shown. Detailed Implementation
[0013] In the following description, only certain exemplary embodiments are briefly described. As those skilled in the art will recognize, the described embodiments can be modified in various ways without departing from the concept or scope of this application. Therefore, the drawings and description are considered to be exemplary in nature and not restrictive.
[0014] First, the terms used in the embodiments of this application are explained as follows: Lane longitudinal distance: The relative distance between an obstacle and an autonomous vehicle in the longitudinal direction of the lane. The longitudinal direction is defined by the center line of the lane in which the autonomous vehicle is located, and the lateral direction is defined by the direction perpendicular to the lane.
[0015] Minimum collision distance (min_dis): This refers to the closest distance between an autonomous vehicle and an obstacle during simulation, serving as a quantifiable indicator of potential risk. A smaller minimum collision distance indicates that the vehicle is closer to the obstacle.
[0016] Minimum collision time (min_ttc): refers to the minimum predicted collision time between an autonomous vehicle and an obstacle based on the current speed and trajectory. Minimum collision time = With the rapid development of autonomous driving technology, safety has become a core focus of the industry. In real-world road tests, autonomous vehicles encounter planning and control (PNC) issues, such as path selection, inappropriate following distance, abrupt steering or braking, and poor speed control. Accurately identifying and assessing the potential safety risks associated with these issues is crucial for guiding algorithm development, optimizing test resource allocation, and accelerating autonomous driving iteration. Currently, the risk status of problems in road tests relies primarily on the subjective experience of test or development engineers. However, different engineers may have significantly different risk perceptions of the same problem, making it difficult to establish a unified and objective evaluation standard and reducing the accuracy of identifying the risk status of road test problems. Given the large number of road test problems, manual analysis also suffers from low efficiency. Furthermore, due to the lack of objective risk quantification indicators, deciding which PNC problems to prioritize relies solely on keywords describing the severity of the problem, resulting in low accuracy. Alternatively, additional time is required for manual analysis, reducing optimization efficiency. Moreover, due to limitations imposed by time, cost, regulations, and safety in actual testing, it is difficult to cover all possible risk scenarios, limiting the depth of risk assessment.
[0017] In view of this, embodiments of this application provide a safety risk assessment method, apparatus, and electronic device, aiming to form a unified and objective risk level assessment standard and improve the accuracy of the risk level obtained from the assessment. The following is a detailed description.
[0018] It should be noted that the application examples provided in this application are for ease of understanding, and this application does not specifically limit the application of the technical solutions. Furthermore, the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. The collection, use, and processing of related data must comply with the relevant laws, regulations, and standards of the relevant countries and regions, and corresponding operation entry points are provided for users to choose to authorize or refuse.
[0019] The technical solution of this application and how it solves the aforementioned technical problems are described in detail below with specific embodiments. The listed specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will be described in detail below with reference to the accompanying drawings.
[0020] Figure 1 A flowchart of the security risk assessment method provided in an embodiment of this application is shown. Figure 1 The method shown can be executed by an evaluation device, which can be a mobile phone, tablet, desktop computer, laptop, vehicle terminal, or other terminal device, or a physical server, cloud server performing cloud computing, etc. Figure 1 As shown, the method may include steps S101, S102 and S103.
[0021] Step S101: Generate multiple derived road test data based on the original road test data corresponding to the target safety event. The target safety event is any one of the at least one safety events that occur during the autonomous driving process of the vehicle.
[0022] In some implementations, during real-world road tests of autonomous driving, vehicles can collect full road test data using onboard data acquisition devices (such as cameras and sensors). This is done to improve the efficiency of risk level assessment and cover as many risk scenarios as possible. Figure 2As shown, the original road test data corresponding to the target safety event can be extracted from the full road test data, and multiple derived road test data can be generated based on the original road test data corresponding to the target safety event. The target safety event is triggered by an autonomous vehicle and an obstacle; the target safety event can be a collision, sudden braking, etc., and the obstacle can be a motor vehicle, a non-motor vehicle, a pedestrian, etc. The original road test data can be video data and point cloud data within a preset time period before and after the trigger time of the target safety event. In some implementations, the trigger time of the target safety event can be used as a reference to extract 10 seconds of video data and point cloud data (5 seconds before and 5 seconds after) to obtain the original road test data corresponding to the target safety event. For example, if the trigger time of the target safety event is the 10th second, then the video data and point cloud data from the 5th to the 15th second can be extracted to obtain the original road test data corresponding to the target safety event.
[0023] Step S102: Simulate multiple derived road test data separately to obtain multiple simulation results. Any simulation result is used to characterize the correlation information between the corresponding derived road test data and the target safety event.
[0024] In some implementations, each derived road test data can be sequentially input into the simulation platform for simulation to obtain the corresponding simulation results.
[0025] In other implementations, a distributed simulation platform can be pre-deployed, and multiple derived road test data sets can be input into the distributed simulation platform for parallel simulation to obtain multiple simulation results. Alternatively, the multiple derived road test data sets can be divided into multiple datasets, and each derived road test data set in each dataset can be sequentially input into the distributed simulation platform for parallel simulation to obtain simulation results corresponding to each derived road test data set in the dataset.
[0026] Step S103: Based on multiple simulation results, assess the risk level of the target security event.
[0027] The risk level of a target security event can be determined by evaluating multiple simulation results based on a pre-defined assessment strategy. The risk levels can be categorized from lowest to highest, including low, medium, and high, or level one, two, three, and four. The method for classifying risk levels can be customized as needed in practical applications.
[0028] The technical solution provided in this application generates multiple derived road test data of target safety events occurring during autonomous driving, simulates the derived road test data, and determines the risk level of the target safety events based on the simulation results. This not only establishes a unified and objective risk level assessment standard, achieving automated risk level assessment, but also, by generalizing road test data, allows for a more in-depth risk level assessment, avoiding the limitations of single road test data and thus improving the accuracy of the assessed risk levels. Furthermore, based on this accurate risk level, when optimizing various problems arising in autonomous driving, it ensures that high-risk issues are addressed first, thereby improving the safety of autonomous driving.
[0029] To maximize coverage of potential boundary conditions and extreme cases of the target security event, in some implementations, generating multiple derived road test data based on the original road test data corresponding to the target security event may include: determining multiple offset parameter combinations based on the original road test data; and using the multiple offset parameter combinations to offset the original road test data to obtain multiple derived road test data.
[0030] This process involves determining multiple offset parameter combinations based on the original road test data. These combinations may include: extracting event parameters of the target safety event from the original road test data, including the trigger time of the target safety event, the longitudinal relative distance between the vehicle and the obstacle when the target safety event is triggered, and the lane information corresponding to the target safety event. The trigger time is offset according to a preset time offset step and time offset range to obtain multiple offset times; the longitudinal relative distance is offset according to a preset distance offset step, a preset distance offset range, and lane information to obtain at least one offset distance; and multiple offset times, multiple offset distances, and preset speed transformation factors are combined to obtain multiple offset parameter combinations, where each offset parameter combination includes offset time, offset distance, and speed transformation factor.
[0031] In some implementations, video data and point cloud data from the original road test data can be analyzed to identify the obstacle that triggered the target safety event, as well as the trigger time of the target safety event, the longitudinal relative distance between the autonomous vehicle and the obstacle when the target safety event is triggered, the reference position of the obstacle when the target safety event is triggered, lane information, etc., which are used as event parameters of the target safety event. The trigger time in the event parameters is offset within a preset time offset step size, resulting in multiple offset times. The longitudinal relative distance is sequentially offset according to a preset distance offset step size to obtain the corresponding offset distance. Based on the lane width in the lane information, it is determined whether the obstacle has left the lane at this offset distance. If it has left the lane, the distance offset stops. If it has not left the lane and the offset distance is within the distance offset range, the longitudinal relative distance is continuously offset sequentially according to the preset distance offset step size until the obstacle leaves the lane or the offset distance is no longer within the distance offset range, at which point the longitudinal relative distance offset stops, resulting in at least one offset distance. Furthermore, the offset time, offset distance, and velocity transformation factor are used as offset dimensions respectively. A three-dimensional matrix is constructed for multiple offset times, at least one offset distance, and multiple preset velocity transformation factors. Each row and each column in the three-dimensional matrix is used as a combination of offset parameters. That is, any combination of offset parameters includes offset time, offset distance, and velocity transformation factor.
[0032] For example, the triggering time of the target security event At the 10th second, the longitudinal relative distance *s* is 0 meters (i.e., a collision occurs). The time offset step is 0.5 seconds, with a time offset range of [-2 seconds, 2 seconds]. The distance offset step is 0.5 meters, with a distance offset range of [-5 meters, 5 meters]. The lane width is 7 meters, the obstacle's moving speed is 4 meters per second, and there are multiple preset speed transformation factors *k* = [0.8, 0.85, 0.9, 0.95, 1.05, 1.1, 1.15, 1.2]. Therefore, multiple offset times can be obtained. =[t-2, t-1.5, t-1, t-0.5, t+0.5, t+1, t+1.5, t+2]= [8, 8.5, 9, 9.5, 10.5, 11, 11.5, 12]. At least one offset distance. =[s-5, s-4.5, s-4…s+4, s+4.5, s+5]=[-5, -4.5, -4…4, 4.5, 5]. This results in 8 offset times, 20 offset distances, and 8 velocity transformation factors, totaling 8*20*8=1280 combinations of offset parameters.
[0033] Therefore, by using the event parameters of the target security event as a benchmark to determine the offset parameters of different offset dimensions (i.e., offset time, offset distance, and velocity transformation factor), and combining the offset parameters of different offset dimensions to obtain multiple offset parameter combinations, the potential boundary conditions and extreme situations of the target security event can be maximized when performing data offset based on the offset parameter combinations, thereby improving the accuracy of risk level assessment.
[0034] In some implementations, the aforementioned method of offsetting the original road test data using multiple offset parameter combinations to obtain multiple derived road test data may include: extracting vehicle driving data and the original movement trajectory of obstacles from the original road test data; offsetting the original movement trajectory using any offset parameter combination to obtain a derived movement trajectory; and determining the driving data and the derived movement trajectory as derived road test data.
[0035] Specifically, video and point cloud data from the original road test data can be analyzed to obtain driving data such as the position, speed, and acceleration of the autonomous vehicle, as well as multiple original trajectory points of obstacles in the target safety event, as the original movement trajectories of the obstacles. Each offset parameter combination is used to offset the original movement trajectory, resulting in a corresponding derived movement trajectory. The vehicle's driving data is then combined with each derived movement trajectory to obtain derived road test data. In other words, there is a one-to-one correspondence between offset parameter combinations and derived movement trajectories, and also a one-to-one correspondence between offset parameter combinations and derived road test data. Continuing the previous example, with 1280 offset parameter combinations, there are 1280 derived movement trajectories and 1280 derived road test data.
[0036] Each original trajectory point can include the current time, current movement speed, and current position. Position can be represented using two-dimensional coordinates, i.e., x-axis and y-axis. The time unit is seconds, meaning the obstacle's movement speed and position are extracted per second to obtain each original trajectory point. Any original trajectory point can be denoted as (…). ), where i is an integer from 1 to T, Let i be the total duration of the original road test data, for example, T=10, then i=1,2,3…9,10.
[0037] Therefore, by using combinations of offset parameters to offset the original movement trajectory of the obstacle, a derived movement trajectory is obtained, which in turn yields derived road test data. This allows the derived road test data to maximize coverage of the boundary conditions and extreme situations that may occur in the target safety event, thereby improving the accuracy of subsequent risk level assessments.
[0038] To ensure the effectiveness of the simulation, in some implementations, the aforementioned method of offsetting the original movement trajectory using a combination of offset parameters to obtain a derived movement trajectory may include: dividing the original movement trajectory into a first sub-movement trajectory and a second sub-movement trajectory according to a division rule, wherein the start time of the second sub-movement trajectory is earlier than the trigger time of the target security event; for any original trajectory point in the second sub-movement trajectory, if the current time of the original trajectory point is different from the trigger time, offsetting the original trajectory point using a combination of offset parameters to obtain a derived trajectory point; and splicing the derived trajectory points corresponding to the first sub-movement trajectory, the second sub-movement trajectory, and the original trajectory point containing the trigger time in chronological order to obtain the derived movement trajectory.
[0039] In some implementations, the division rule may be to subtract the trigger time from a preset duration to obtain the division time. The original movement trajectory is divided into a first sub-movement trajectory and a second sub-movement trajectory according to the division time. For any original trajectory point in the second sub-movement trajectory, it is determined whether the current time of that original trajectory point is the same as the trigger time. If they are different, the original trajectory point is offset using a combination of offset parameters to obtain a derived trajectory point. Given the derived trajectory points of all original trajectory points except those containing the trigger time, the first sub-movement trajectory, each derived trajectory point, and the original trajectory point containing the trigger time are processed in chronological order from front to back.
[0040] For example, with a preset duration of 2 seconds and a trigger time of 10 seconds, the original road test data is a 10-second video from 5 seconds to 15 seconds. The obstacle's movement speed and position per second are extracted to obtain the original trajectory points. Therefore, the obstacle's original movement trajectory is the 10-second movement trajectory from 5 seconds to 15 seconds. When dividing the original movement trajectory, 10-2=8 can be used, that is, the 8th second is used as the division time (which can also be called the offset reference point or generalization reference point). This yields the first sub-movement trajectory from 5 seconds to 7 seconds and the second sub-movement trajectory from 8 seconds to 15 seconds. The second sub-movement trajectory includes 8 original trajectory points. The original trajectory point corresponding to 10 seconds does not need to be offset, and the original trajectory points corresponding to 8 seconds, 9 seconds, and 11 seconds to 15 seconds are offset to obtain derived trajectory points. And in chronological order, the first sub-trajectory, the derived trajectory points at the 8th and 9th seconds, the original trajectory point at the 10th second, and the derived trajectory points from the 11th to the 15th seconds are spliced together to obtain the derived trajectory.
[0041] Therefore, by dividing the original movement trajectory into a first sub-trajectory and a second sub-trajectory, and offsetting the original trajectory points in the second sub-trajectory, the derived movement trajectory maintains consistency with the initial one in the open-loop phase. This not only avoids the discontinuity of the obstacle's state (such as a bicycle suddenly jumping), but also reproduces real problems and efficiently explores boundary conditions.
[0042] As mentioned earlier, any original trajectory point includes the current time, current speed, and current position (i.e., the current x-coordinate and current y-coordinate). The position of the obstacle when the safety event is triggered is used as the reference position, and the event parameters may also include this reference position. Accordingly, the aforementioned offsetting of the original trajectory point using a combination of offset parameters to obtain a derived trajectory point may include: offsetting the current time of the original trajectory point using the offset time in the offset parameter combination to obtain a derived time; if the current moving speed of the original trajectory point is greater than a preset speed, offsetting the current moving speed of the original trajectory point using a speed transformation factor in the offset parameter combination to obtain a derived speed; offsetting the current position of the original trajectory point using the offset distance, speed transformation factor, and reference position in the offset parameter combination to obtain a derived position; and determining the derived time, derived speed, and derived position as the derived trajectory point corresponding to the original trajectory point. For example, the preset speed is 3 meters per second.
[0043] In some implementations, for any original trajectory point in the second sub-trajectory, if the current time at that original trajectory point differs from the trigger time, the current time at that original trajectory point can be added to the offset time in the offset parameter combination, and the result can be determined as the derived time. The current movement speed at that original trajectory point is multiplied by the speed transformation factor in the offset parameter combination, and the result can be determined as the derived speed. An intermediate position is determined based on the speed transformation factor corresponding to the offset parameter combination, the current position, and the reference position. The ordinate of this intermediate position is then offset according to the offset distance to obtain the derived position. The derived time, derived speed, and derived position are then determined as the derived trajectory point corresponding to that original trajectory point.
[0044] In some implementations, the abscissa of the intermediate position can be determined according to the following formula one, based on the velocity transformation factor corresponding to the offset parameter combination and the abscissa of the reference position; and the ordinate of the intermediate position can be determined according to the following formula two, based on the velocity transformation factor corresponding to the offset parameter combination and the ordinate of the reference position.
[0045] Formula 1: ; Formula 2: ; in, It is the x-coordinate of the current position. It is the y-coordinate of the current position. It is the x-coordinate of the reference position. It is the ordinate of the reference position. This refers to the velocity transformation factor in the currently used combination of offset parameters. The x-coordinate of the middle position. Let i be the ordinate of the middle position. The time in T excluding the trigger time, To divide the time, T is the total duration of the original road test data. Continuing with the example above, i is any time from the 8th second, 9th second, 11th second to the 15th second.
[0046] Furthermore, the ordinate of the intermediate position is offset according to the offset distance to obtain the derived position. This can be achieved by adding the offset distance to the ordinate of the intermediate position to obtain a new ordinate, and then determining the position corresponding to the ordinate of the intermediate position and the ordinate of the derived position as the derived position.
[0047] In other words, the derived trajectory point can be represented as ( ),in, , , These are the offset time, offset distance, and velocity transformation factor in the currently used offset parameter combination. Indicates the current movement speed.
[0048] In other implementations, the offset speed can be determined based on the speed transformation factor in the currently used offset parameter combination and the current moving speed of the obstacle, and the derived speed can be obtained by adding the current moving speed to the offset speed. Specifically, the offset speed can be determined according to Formula 3 below, based on the speed transformation factor in the currently used offset parameter combination and the current moving speed of the obstacle.
[0049] Formula 3: ,in, This refers to the velocity transformation factor in the currently used combination of offset parameters. Indicates the offset speed. This represents the current movement speed. Correspondingly, the derived trajectory point can be represented as ( ).
[0050] Therefore, for each original trajectory point in the second sub-trajectory that is not at the reference position, the offset (or perturbation, generalization) is performed using the currently used offset parameter combination to obtain the corresponding derived trajectory points. This can maximize the coverage of the boundary conditions and extreme situations that may occur in the target security event, thereby improving the accuracy of subsequent risk level assessment.
[0051] In some implementations, the aforementioned assessment of the risk level of a target security event based on multiple simulation results may include: scoring multiple simulation results according to a preset scoring strategy to obtain a target risk score for the target security event; and obtaining the risk level corresponding to the target risk score from the correspondence between risk scores and risk levels, and using it as the risk level of the target security event.
[0052] The process of scoring multiple simulation results according to a preset scoring strategy to obtain a target risk score for the target safety event may include: for any simulation result, if the associated information represented by the simulation result is not empty, determining the collision score corresponding to the simulation result based on the associated information, whereby the collision score is used to represent the probability of a collision between a vehicle and an obstacle; for the offset parameter combination corresponding to the simulation result, determining the offset weight corresponding to the simulation result based on the parameter values and preset weights of each parameter in the offset parameter combination, whereby the offset weight is used to represent the degree of difference between the corresponding derived road test data and the original road test data; and determining the target risk score for the target safety event based on the collision scores and offset weights corresponding to the multiple simulation results respectively.
[0053] In some implementations, simulation results may include correlation information between the corresponding derived road test data and the target safety event. During the simulation, if an obstacle creates an exit path or collides with other traffic participants, it indicates that the corresponding derived road test data is unreasonable. In this case, the correlation information in the simulation result can be empty, and the simulation result does not participate in the score calculation. If the obstacle collides with the autonomous vehicle, the correlation information in the simulation result may include information such as the relative collision angle and relative collision speed, and this simulation result participates in the score calculation. If the obstacle does not collide with the autonomous vehicle, the correlation information in the simulation result may include information such as the minimum collision distance and minimum collision time, and this simulation result participates in the score calculation. That is, when there are M derived road test data, the number of simulation results participating in the score calculation can be less than M, where M is a positive integer. Since each derived road test data is simulated separately, therefore... Figure 2 As shown, each derived road test data can be regarded as a different simulation scenario. If the simulation scenario is unreasonable (i.e., the correlation information in the simulation result is empty), the corresponding simulation result will not participate in the score calculation. If the simulation scenario is reasonable (i.e., the correlation information in the simulation result is not empty), the corresponding simulation result will participate in the score calculation.
[0054] Correspondingly, if the correlation information represented by the simulation result is not empty, the collision score corresponding to the simulation result can be determined based on the correlation information according to the following formula four.
[0055] Formula 4: ,in, Represents the collision score. This indicates the relative collision speed in the associated information. This indicates the relative collision angle in the associated information. This indicates the weight corresponding to the preset obstacle type. The obstacle type can include motor vehicles, non-motor vehicles, pedestrians, etc. This represents the weight corresponding to the preset minimum collision distance. This represents the weight corresponding to the preset minimum collision time. Indicates the minimum collision distance. This represents the minimum collision time.
[0056] Understandably, when the simulation results do not include some parameters from Formula 4, the corresponding parameters will be 0. For example, during the simulation, if an obstacle collides with the autonomous vehicle, the associated information includes the relative collision angle and relative collision speed; in this case, the minimum collision distance and minimum collision time are both zero. If the obstacle does not collide with the autonomous vehicle, the associated information includes the minimum collision distance and minimum collision time; in this case, the relative collision angle and relative collision speed are both zero.
[0057] In some implementations, the offset parameter combination can be denoted as [offset time, offset distance, velocity transformation factor], where offset time is the first parameter, offset distance is the second parameter, and velocity transformation factor is the third parameter. The parameter value corresponding to any parameter in the offset parameter combination includes an original value and a derived value. That is, for the offset time (parameter) in the offset parameter combination, its corresponding parameter value includes the current time (original value) and the derived time (derived value); for the offset distance (parameter) in the offset parameter combination, its corresponding parameter value includes the current position (original value) and the derived position (derived value); for the velocity transformation factor (parameter) in the offset parameter combination, its corresponding parameter value includes the current moving speed (original value) and the derived speed (derived value). Furthermore, a weight is preset for each parameter. Correspondingly, the aforementioned determination of the offset weight corresponding to the simulation result based on the parameter values and preset weights of each parameter in the offset parameter combination can include: determining the offset weight corresponding to the simulation result according to the following formula five, based on the parameter values and preset weights of each parameter in the offset parameter combination.
[0058] Formula 5: ,in, This represents the preset weight of the j-th parameter. This represents the original value corresponding to the j-th parameter. This represents the derived value corresponding to the j-th parameter. This represents the offset weight corresponding to the offset parameter combination. The larger the offset weight, the smaller the difference between the corresponding derived road test data and the original road test data. j can be any value from 1, 2, and 3. That is, when j=1, it represents the first parameter in the offset parameter combination; when j=2, it represents the second parameter in the offset parameter combination; and when j=3, it represents the third parameter in the offset parameter combination.
[0059] In some implementations, determining the target risk score of a target safety event based on the collision scores and offset weights corresponding to multiple simulation results may include: determining the target risk score of a target safety event based on the collision scores and offset weights corresponding to multiple simulation results according to Formula Six below.
[0060] Formula Six: ,in, Indicates the target risk score. Indicates the first The offset weights corresponding to each simulation result Indicates the first The collision score corresponding to each simulation result The integer N represents the total number of simulation results used in the calculation.
[0061] Therefore, by determining the collision score and offset weight corresponding to the simulation results, and determining the target risk score of the target safety event based on the collision score and offset weight, the risk level of the target safety event is determined based on the target risk score, thus forming a unified and objective risk level assessment standard, which can improve the accuracy of the determined risk level.
[0062] It should be noted that the process of determining the target risk score is not limited to the above description. When the differences between the derived road test data are small, the offset weight can be omitted, and the average score of the collision scores corresponding to each simulation result can be directly used as the target risk score.
[0063] In some implementations, the aforementioned correspondence between risk scores and risk levels may be a correspondence between risk score intervals and risk levels. Accordingly, obtaining the risk level corresponding to the target risk score from the aforementioned correspondence between risk scores and risk levels and using it as the risk level of the target security event may include: determining a target risk score interval containing the target risk score, and determining the risk level corresponding to the target risk score interval as the risk level of the target security event.
[0064] In some implementations, a pre-set Corresponding to high risk, Corresponding to medium risk, The risk levels are categorized as follows: Low risk. High risk indicates a collision hazard regardless of whether the drift is aggressive or conservative, requiring close monitoring and limited remediation. Medium risk indicates significant safety hazards or frequent violations; a collision risk only arises with more aggressive drifts, while conservative drifts do not pose a collision hazard. Low risk indicates comfort zone issues or minor violations; no collision risk occurs regardless of whether the drift is aggressive or conservative. This level has a lower priority.
[0065] Therefore, by determining the risk level of a target safety event based on its target risk score, a unified and objective risk level assessment standard is established, and the accuracy of the determined risk level is improved. This risk level can then drive the allocation of R&D resources, improve R&D efficiency, prioritize the resolution of high-risk issues, and thus ensure the safety of autonomous driving.
[0066] Corresponding to the application scenarios and methods provided in the embodiments of this application, the embodiments of this application also provide a security risk assessment device, which can be applied to the aforementioned assessment equipment, such as... Figure 3 As shown, the device includes: The generation module 301 is used to generate multiple derived road test data based on the original road test data corresponding to the target safety event, wherein the target safety event is any one of at least one safety event that occurs during the autonomous driving process of the vehicle. Simulation module 302 is used to simulate the multiple derived road test data respectively to obtain multiple simulation results. Any simulation result is used to characterize the correlation information between the corresponding derived road test data and the target security event. The evaluation module 303 is used to evaluate the risk level of the target security event based on the multiple simulation results.
[0067] In some implementations, the generation module 301 is specifically used for: Based on the original road test data, determine multiple combinations of offset parameters; The original road test data is offset by using the combination of multiple offset parameters to obtain multiple derived road test data.
[0068] In some implementations, the target safety event is triggered by the vehicle and the obstacle, and the generation module 301 is further specifically used for: The event parameters of the target safety event are extracted from the original road test data. The event parameters include the trigger time of the target safety event, the longitudinal relative distance between the vehicle and the obstacle when the target safety event is triggered, and the lane information corresponding to the target safety event. The trigger time is offset according to the preset time offset step and time offset range to obtain multiple offset times; Based on a preset distance offset step size, a preset distance offset range, and the lane width, the longitudinal relative distance is offset to obtain at least one offset distance; The multiple offset times, the at least one offset distance, and the preset multiple velocity transformation factors are combined to obtain multiple offset parameter combinations, each of which includes offset time, offset distance, and velocity transformation factor.
[0069] In some implementations, the generation module 301 is further specifically used for: Extract the vehicle's driving data and the original movement trajectory of the obstacles from the original road test data; For any combination of offset parameters, the original movement trajectory is offset using the combination of offset parameters to obtain a derived movement trajectory; The driving data and the derived movement trajectory are determined as the derived road test data.
[0070] In some implementations, any original trajectory point in the original movement trajectory includes the current time, and the generation module 301 is further specifically used for: According to the division rules, the original movement trajectory is divided into a first sub-movement trajectory and a second sub-movement trajectory, wherein the start time of the second sub-movement trajectory is earlier than the trigger time; For any original trajectory point in the second sub-movement trajectory, if the current time of the original trajectory point is different from the trigger time, the original trajectory point is offset using the offset parameter combination to obtain a derived trajectory point; The derived movement trajectories are obtained by splicing together the first sub-movement trajectory, the derived trajectory points corresponding to the second sub-movement trajectory, and the original trajectory points containing the trigger time, in chronological order.
[0071] In some implementations, the event parameters also include the reference position of the obstacle when the safety event is triggered, and any original trajectory point also includes the current moving speed and current position. The generation module 301 is further specifically used for: Using the offset time in the offset parameter combination, the current time in the original trajectory point is offset to obtain the derived time; If the current moving speed at the original trajectory point is greater than the preset speed, the current moving speed at the original trajectory point is offset using the speed transformation factor in the offset parameter combination to obtain the derived speed; Using the offset distance, the velocity transformation factor, and the reference position in the offset parameter combination, the current position of the original trajectory point is offset to obtain the derived position; The derived time, the derived speed, and the derived position are determined as the derived trajectory points corresponding to the original trajectory points.
[0072] In some implementations, the evaluation module 303 is specifically used for: The multiple simulation results are scored according to a preset scoring strategy to obtain the target risk score of the target security event; From the correspondence between risk scores and risk levels, the risk level corresponding to the target risk score is obtained and used as the risk level of the target security event.
[0073] In some implementations, the evaluation module 303 is further specifically used for: For any simulation result, if the associated information represented by the simulation result is not empty, the collision score corresponding to the simulation result is determined according to the associated information. The collision score is used to represent the probability of the vehicle colliding with the obstacle. For the offset parameter combination corresponding to the simulation result, the offset weight corresponding to the simulation result is determined according to the parameter value and preset weight of each parameter in the offset parameter combination. The offset weight is used to characterize the degree of difference between the corresponding derived road test data and the original road test data. The target risk score of the target safety event is determined based on the collision scores and offset weights corresponding to the multiple simulation results.
[0074] The functions of each module in the devices of this application embodiment can be found in the corresponding descriptions of the methods described above, and they have corresponding beneficial effects, which will not be repeated here. Furthermore, the device embodiments described above are merely illustrative. The modules described as separate components may or may not be physically separate. The components illustrated as modules may or may not be physical modules; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this application solution according to actual needs.
[0075] Figure 4 This is a block diagram of an electronic device used to implement embodiments of this application. For example... Figure 4As shown, the electronic device includes a memory 401 and a processor 402. The memory 401 stores a computer program that can run on the processor 402. When the processor 402 executes the computer program, it implements the method described in the above embodiments. The number of memories 401 and processors 402 can be one or more. In a specific implementation, the electronic device may also include a communication interface 403 for communicating with external devices and performing data exchange and transmission.
[0076] In practical implementation, if the memory 401, processor 402, and communication interface 403 are implemented independently, they can be interconnected via a bus to communicate with each other. This bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. This bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 4 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.
[0077] Optionally, in a specific implementation, if the memory 401, processor 402 and communication interface 403 are integrated on a single chip, the memory 401, processor 402 and communication interface 403 can communicate with each other through an internal interface.
[0078] This application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the method provided in this application.
[0079] This application provides a computer program product, including a computer program that, when executed by a processor, implements the method provided in this application.
[0080] This application also provides a chip, which includes a processor for calling and executing instructions stored in a memory, causing a communication device with the chip installed to perform the method provided in this application.
[0081] This application also provides a chip, including: an input interface, an output interface, a processor, and a memory. The input interface, output interface, processor, and memory are connected through an internal connection path. The processor is used to execute code in the memory. When the code is executed, the processor is used to execute the method provided in the application embodiment.
[0082] It should be understood that the aforementioned processor can be a Central Processing Unit (CPU), or other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. General-purpose processors can be microprocessors or any conventional processor. It is worth noting that the processor can be a processor supporting Advanced Reduced Instruction Set Machines (ARM) architecture.
[0083] Further, optionally, the aforementioned memory may include read-only memory and random access memory. The memory may be volatile memory or non-volatile memory, or may include both. Non-volatile memory may include read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory may include random access memory (RAM), which serves as an external cache. By way of example, but not limitation, many forms of RAM are available. Examples include Static Random Access Memory (SRAM), Dynamic Random Access Memory (DRAM), Synchronous DRAM (SDRAM), Double Data Rate SDRAM (DDR SDRAM), Enhanced Synchronous DRAM (ESDRAM), Sync Link DRAM (SLDRAM), and Direct Rambus RAM (DR RAM).
[0084] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. A computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions according to this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another.
[0085] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of this application. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of those different embodiments or examples.
[0086] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this application, "a plurality of" means two or more, unless otherwise explicitly specified.
[0087] Any process or method described in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of code comprising one or more executable instructions for implementing a particular logical function or process. Furthermore, the scope of the preferred embodiments of this application includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order depending on the functionality involved.
[0088] The logic and / or steps described in the flowchart or otherwise herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus or device (such as a computer-based system, a processor-included system or other system that can fetch and execute instructions from, an instruction execution system, apparatus or device).
[0089] It should be understood that various parts of this application can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented using software or firmware stored in memory and executed by a suitable instruction execution system. All or part of the steps of the methods in the above embodiments can be implemented by a program instructing related hardware, the program being stored in a computer-readable storage medium, which, when executed, includes one or a combination of the steps of the method embodiments.
[0090] Furthermore, the functional units in the various embodiments of this application can be integrated into a processing module, or each unit can exist physically separately, or two or more units can be integrated into a module. The integrated module can be implemented in hardware or as a software functional module. If the integrated module is implemented as a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. This storage medium can be a read-only memory, a disk, or an optical disk, etc.
[0091] The above description is merely an exemplary embodiment of this application, but the scope of protection of this application is not limited thereto. Any person skilled in the art can easily conceive of various variations or substitutions within the technical scope described in this application, and these should all be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A method of security risk assessment, characterized by, The method comprises: generating a plurality of derived road test data according to original road test data corresponding to a target safety event, the target safety event being any one of at least one safety event occurring in the automatic driving process of a vehicle; performing simulation on the plurality of derived road test data respectively to obtain a plurality of simulation results, any simulation result being used to represent the association information between the corresponding derived road test data and the target safety event; evaluating the risk level of the target safety event according to the plurality of simulation results.
2. The method of claim 1, wherein, The method comprises: determining a plurality of offset parameter combinations according to the original road test data; offsetting the original road test data using the plurality of offset parameter combinations respectively to obtain a plurality of derived road test data.
3. The method of claim 2, wherein, The target safety event is triggered by the vehicle and an obstacle, and the method comprises: extracting event parameters of the target safety event from the original road test data, the event parameters comprising a trigger time of the target safety event, a longitudinal relative distance between the vehicle and the obstacle when the target safety event is triggered, and lane information corresponding to the target safety event; offsetting the trigger time according to a preset time offset step and a time offset range to obtain a plurality of offset times; offsetting the longitudinal relative distance according to a preset distance offset step, a preset distance offset range and the lane information to obtain at least one offset distance; combining the plurality of offset times, the at least one offset distance and a plurality of preset speed transformation factors to obtain a plurality of offset parameter combinations, any offset parameter combination comprising an offset time, an offset distance and a speed transformation factor.
4. The method of claim 2, wherein, The method comprises: extracting driving data of the vehicle and an original moving track of the obstacle from the original road test data; for any offset parameter combination, offsetting the original moving track using the offset parameter combination to obtain a derived moving track; determining the driving data and the derived moving track as the derived road test data.
5. The method of claim 4, wherein, Any original track point in the original moving track comprises a current time, and the method comprises: dividing the original moving track into a first sub-moving track and a second sub-moving track according to a division rule, the starting time of the second sub-moving track being earlier than the trigger time; for any original track point in the second sub-moving track, offsetting the original track point using the offset parameter combination in the case that the current time in the original track point is different from the trigger time to obtain a derived track point; splicing the first sub-moving track, the second sub-moving track, the derived track points corresponding to the first sub-moving track and the second sub-moving track, and the original track point containing the trigger time in the order of time to obtain a derived moving track.
6. The method of claim 5, wherein, The event parameter further comprises a reference position of the obstacle when triggering the safety event, any original trajectory point further comprises a current moving speed and a current position, the offsetting the original trajectory point by using the offset parameter combination comprises: offsetting a current time in the original trajectory point by using an offset time in the offset parameter combination to obtain a derived time; in a case that the current moving speed in the original trajectory point is greater than a preset speed, offsetting the current moving speed in the original trajectory point by using a speed transformation factor in the offset parameter combination to obtain a derived speed; offsetting the current position in the original trajectory point by using an offset distance in the offset parameter combination, the speed transformation factor and the reference position to obtain a derived position; determining the derived time, the derived speed and the derived position as a derived trajectory point corresponding to the original trajectory point.
7. The method according to any one of claims 2 to 6, characterized in that, The risk level of the target safety event is evaluated according to the plurality of simulation results, comprising: scoring the plurality of simulation results according to a preset scoring strategy to obtain a target risk score of the target safety event; obtaining a risk level corresponding to the target risk score from a corresponding relationship between risk scores and risk levels and taking the risk level as the risk level of the target safety event.
8. The method of claim 7, wherein, The target risk score of the target safety event is obtained by scoring the plurality of simulation results according to a preset scoring strategy, comprising: for any simulation result, determining a collision score corresponding to the simulation result according to associated information represented by the simulation result in a case that the associated information is not empty, the collision score being used to represent a probability of a collision event between the vehicle and the obstacle; for the offset parameter combination corresponding to the simulation result, determining an offset weight corresponding to the simulation result according to parameter values corresponding to parameters in the offset parameter combination and preset weights, the offset weight being used to represent a difference degree between corresponding derived road test data and the original road test data; determining the target risk score of the target safety event according to collision scores and offset weights respectively corresponding to the plurality of simulation results.
9. A security risk assessment apparatus, characterized by, comprising: a generation module configured to generate a plurality of derived road test data according to original road test data corresponding to a target safety event, the target safety event being any one of at least one safety event occurring to a vehicle in an automatic driving process; a simulation module configured to simulate the plurality of derived road test data respectively to obtain a plurality of simulation results, any simulation result being used to represent associated information between corresponding derived road test data and the target safety event; an evaluation module configured to evaluate a risk level of the target safety event according to the plurality of simulation results.
10. An electronic device, comprising: comprising a memory, a processor and a computer program stored in the memory and executable on the processor, the processor executing the program to implement the method of any one of claims 1-8. comprising a memory, a processor and a computer program stored in the memory and executable on the processor, the processor executing the program to implement the method of any one of claims 1-8.