Vehicle control method, vehicle, and storage medium

By using multi-dimensional data fusion assessment and dynamic risk quantification to generate vehicle control strategies, the safety issues of vehicles in the event of sudden driver incapacitation are resolved, and safe and smooth vehicle takeover is achieved.

CN122126312APending Publication Date: 2026-06-02CHINA FAW CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHINA FAW CO LTD
Filing Date
2026-04-28
Publication Date
2026-06-02

Smart Images

  • Figure CN122126312A_ABST
    Figure CN122126312A_ABST
Patent Text Reader

Abstract

This application discloses a vehicle control method, a vehicle, and a storage medium. The method includes: acquiring object state data of a target object within the vehicle, vehicle operation data, and external environment data of the vehicle's surroundings during vehicle operation; evaluating the state of the target object based on the vehicle operation data, external environment data, and object state data to obtain a target risk quantification result, wherein the target risk quantification result describes the probability that the target object will lose control of the vehicle in its current state; generating a target control strategy based on the vehicle operation data, external environment data, and target risk quantification result, provided the target risk quantification result meets a preset risk quantification result; and controlling the vehicle based on the target control strategy. This application solves the technical problem of low security in vehicle control in related technologies.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of vehicles, in particular to a vehicle control method, a vehicle and a storage medium. BACKGROUND

[0002] The vehicle takeover method in the related art is mostly based on the determination of the driver state to determine the takeover timing, for example, by visually monitoring the head posture or the eye closure frequency, or in combination with the steering wheel torque change to evaluate the attention concentration degree, and triggering an audible and visual prompt to remind the driver to take over when an abnormality is detected. However, such a method has a response lag in the case of sudden, non-classical incapacitation scenarios, and it is difficult to complete effective identification before the driver loses control ability, thereby causing the vehicle to still be in the risk of out-of-control without takeover in the scenario of sudden incapacitation of the driver and inability to respond to the prompt, and further causing the safety of vehicle control in the related art to be low.

[0003] In view of the above problems, no effective solution has been proposed so far. SUMMARY

[0004] The embodiments of the present application provide a vehicle control method, a vehicle and a storage medium to at least solve the technical problem of low safety of vehicle control in the related art.

[0005] According to an aspect of an embodiment of the present application, a vehicle control method is provided, including: obtaining object state data of a target object in a vehicle, vehicle operation data of the vehicle and external environment data of an environment in which the vehicle is located during driving of the vehicle; performing state evaluation on the target object based on the vehicle operation data, the external environment data and the object state data to obtain a target risk quantification result of the target object, wherein the target risk quantification result is used to describe a probability that the target object loses control over the vehicle in a current state of the target object; generating a target control strategy based on the vehicle operation data, the external environment data and the target risk quantification result in a case where the target risk quantification result meets a preset risk quantification result, wherein the target control strategy is used to represent switching timing and control parameters corresponding to a plurality of takeover stages, and the plurality of takeover stages are sequentially and smoothly connected; and controlling the vehicle based on the target control strategy.

[0006] Further, performing state evaluation on the target object based on the vehicle operation data, the external environment data and the object state data to obtain a target risk quantification result includes: performing state evaluation on the target object based on the object state data to obtain an initial risk quantification result of the target object; determining a risk correction factor based on the vehicle operation data and the external environment data, wherein the risk correction factor is used to represent an external influence degree of the vehicle operation data and the external environment data on the initial risk quantification result; and correcting the initial risk quantification result based on the risk correction factor to determine the target risk quantification result.

[0007] Furthermore, the object state data includes at least two of the following: physiological state data, visual acquisition data, voice acquisition data, and active triggering data; based on the object state data, the target object's state is assessed to obtain the initial risk quantification result of the target object, including: assessing the confidence of at least two data points respectively to obtain the confidence weights corresponding to at least two data points; and weighting and fusing the at least two data points based on their corresponding confidence weights to obtain the initial risk quantification result.

[0008] Furthermore, based on vehicle operation data, external environment data, and target risk quantification results, a target control strategy is generated, including: when the target risk quantification result is greater than a first preset risk quantification result and less than a second preset risk quantification result, the first control strategy is determined as the target control strategy; when the target risk quantification result is greater than or equal to the second preset risk quantification result, a second control strategy is generated based on vehicle operation data and external environment data, and the second control strategy is determined as the target control strategy. The second preset risk quantification result is greater than the first preset risk quantification result, the risk level corresponding to the second control strategy is higher than the risk level corresponding to the first control strategy, and the second control strategy includes longitudinal control parameters corresponding to the longitudinal takeover stage in multiple takeover stages, and lateral control parameters corresponding to the lateral takeover stage in multiple takeover stages.

[0009] Furthermore, controlling the vehicle based on the target control strategy includes: when the target control strategy is the first control strategy, outputting a prompt message to the target object, wherein the prompt message is used to prompt the target object to take over the vehicle; when the target control strategy is the second control strategy, or when the target object does not take over the vehicle after the first control strategy is executed, controlling the vehicle to drive towards the target area based on longitudinal control parameters and lateral control parameters, wherein the target area is used to represent the safe parking area closest to the vehicle.

[0010] Furthermore, based on longitudinal and lateral control parameters, the vehicle is controlled to drive towards the target area, including: verifying the consistency between the second control strategy and the target risk quantification result to obtain a consistency verification result, wherein the consistency verification result is used to indicate whether the second control strategy matches the current state of the vehicle; if the consistency verification result indicates that the second control strategy matches the current state of the vehicle, the vehicle is controlled to drive towards the target area based on the longitudinal and lateral control parameters.

[0011] Furthermore, based on longitudinal and lateral control parameters, the vehicle is controlled to move towards the target area, including: determining the vehicle's current speed based on vehicle operation data; performing longitudinal control on the current speed based on the longitudinal control parameters; obtaining a local planned path for the vehicle to travel to the target area when the current speed is within a preset speed range and the vehicle's external environmental data meets the lateral takeover conditions, wherein the lateral takeover conditions are used to represent the safety conditions that the external environmental data must meet when performing lateral takeover; and performing lateral control on the vehicle based on the lateral control parameters and the local planned path to drive the vehicle towards the target area.

[0012] Furthermore, obtaining the local planned path for the vehicle to travel to the target area includes: obtaining the vehicle's current location data and the target location data of the target area; and generating the local planned path based on the current location data and the target location data.

[0013] Furthermore, after the vehicle reaches the target area, the method also includes: triggering the vehicle emergency call service and sending structured rescue data, wherein the structured rescue data includes: the vehicle's geographical location information, vehicle identification number, number of occupants in the vehicle, and event type identifier inferred by the system.

[0014] According to another aspect of the embodiments of this application, a vehicle control device is also provided, comprising: an acquisition module, configured to acquire object state data of a target object in the vehicle, vehicle operation data of the vehicle, and external environment data of the environment in which the vehicle is located during vehicle operation; an evaluation module, configured to evaluate the state of the target object based on the vehicle operation data, external environment data, and object state data, and obtain a target risk quantification result of the target object, wherein the target risk quantification result is used to describe the probability that the target object loses control of the vehicle in the current state of the target object; a generation module, configured to generate a target control strategy based on the vehicle operation data, external environment data, and target risk quantification result, provided that the target risk quantification result meets a preset risk quantification result, wherein the target control strategy is used to represent the switching timing and control parameters corresponding to multiple takeover stages, and the multiple takeover stages are smoothly connected sequentially; and a control module, configured to control the vehicle based on the target control strategy.

[0015] According to another aspect of the embodiments of this application, a vehicle is also provided, including: a memory storing an executable program; and a processor for running the program, wherein the program executes the methods in various embodiments of this application when it runs.

[0016] According to another aspect of the embodiments of this application, a computer-readable storage medium is also provided, the computer-readable storage medium including a stored executable program, wherein, when the executable program is running, it controls the device where the computer-readable storage medium is located to perform the methods of various embodiments of this application.

[0017] According to another aspect of the embodiments of this application, a computer program product is also provided, including a computer program that, when executed by a processor, implements the methods of various embodiments of this application.

[0018] According to another aspect of the embodiments of this application, a computer program product is also provided, including a non-volatile computer-readable storage medium storing a computer program that, when executed by a processor, implements the methods in various embodiments of this application.

[0019] According to another aspect of the embodiments of this application, a computer program is also provided, which, when executed by a processor, implements the methods of the various embodiments of this application.

[0020] In this application embodiment, a vehicle control method is proposed. During vehicle operation, the method first acquires object state data of a target object within the vehicle, vehicle operation data, and external environment data of the vehicle's surroundings. Next, based on the vehicle operation data, external environment data, and object state data, a state assessment of the target object is performed to obtain the probability that the target object will lose control of the vehicle in the current state, i.e., the target risk quantification result. Then, if the target risk quantification result meets a preset risk quantification result, a target control strategy including multiple takeover phases is generated based on the vehicle operation data, external environment data, and target risk quantification result. Finally, the vehicle is controlled based on the target control strategy. This application adopts a multi-dimensional data fusion-driven dynamic risk quantification and phased smooth control collaborative mechanism. By jointly modeling object state data, vehicle operation data and external environment data, it outputs continuous target risk quantification results, effectively improving the accuracy of risk quantification. On this basis, it dynamically generates a progressive target control strategy that includes multiple takeover stages, ensuring a smooth and controllable handover process. This achieves the technical objective of proactively intervening before the target object loses its controllability and accurately matching the intensity of intervention with the needs of the scenario. Thus, it realizes the technical effect of closed-loop control from passive early warning to proactive, safe and smooth takeover, thereby solving the technical problem of low vehicle control safety in related technologies. Attached Figure Description

[0021] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:

[0022] Figure 1 This is a flowchart of a vehicle control method according to an embodiment of this application;

[0023] Figure 2 This is a flowchart of an optional vehicle control method according to an embodiment of this application;

[0024] Figure 3 This is a flowchart of a multimodal fusion perception of a target object state according to an embodiment of this application;

[0025] Figure 4 This is a flowchart of intelligent takeover and path decision-making according to an embodiment of this application;

[0026] Figure 5 This is a flowchart of an emergency call service for a vehicle according to an embodiment of this application;

[0027] Figure 6 This is a schematic diagram of a vehicle control device according to an embodiment of this application. Detailed Implementation

[0028] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.

[0029] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0030] According to an embodiment of this application, an embodiment of a vehicle control method is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.

[0031] Figure 1 This is a flowchart of a vehicle control method according to an embodiment of this application, such as... Figure 1As shown, the method includes the following steps:

[0032] Step S102: During the vehicle driving process, obtain the object state data of the target object in the vehicle, the vehicle operation data of the vehicle, and the external environment data of the environment where the vehicle is located.

[0033] The above-mentioned vehicle may refer to a vehicle with active control capabilities. The vehicle types may include, but are not limited to, electric vehicles, fuel vehicles, and hybrid vehicles, etc. The specific vehicle type needs to be determined according to the actual situation. The above-mentioned vehicle can be used as the execution carrier of this application, carrying all the hardware and software systems for perception, decision-making, control, and communication; the operation state of the vehicle and the environmental interaction information can be used to provide the physical basis and real-time feedback for the generation of risk assessment and control strategies.

[0034] The above-mentioned target object may refer to the person responsible for vehicle control. The target object may be the core object of the risk assessment of this application. The system continuously monitors the state of the target object to determine whether it has the ability to continuously, effectively, and safely control the vehicle, thereby triggering a takeover decision. The change in the state of the target object is the only trigger basis for "active takeover" in this application.

[0035] The above-mentioned object state data may refer to the multi-modal perception data directly collected from the target object, reflecting its physiological, behavioral, and interaction intentions. The object state data may include, but are not limited to, physiological state data, visual acquisition data, voice acquisition data, and active trigger data, etc. The specific object state data needs to be determined according to the actual situation. The object state data can be used as the primary input source for risk assessment, directly reflecting whether the state of the target object is abnormal. The quality and fusion accuracy of the object state data can be used to determine whether the system can identify potential incapability risks in advance before the driver causes the vehicle to lose control.

[0036] The above-mentioned vehicle operation data may refer to the parameter set that is real-time collected by on-vehicle sensors during the vehicle driving process, reflecting its own dynamic state and system performance. The vehicle operation data may include, but are not limited to, vehicle speed, steering angle, gear position, acceleration, deceleration, and vehicle load data, etc. The specific vehicle operation data needs to be determined according to the actual control requirements. The vehicle operation data can be used to provide the vehicle state context for risk assessment, to judge whether "under the current vehicle condition, the driver's incapability has constituted a real threat", and as the execution constraint condition for the generation of control strategies.

[0037] The above external environment data may refer to the static and dynamic information of the road environment where the vehicle is located, reflecting the constraint conditions and feasibility of the external traffic scenario for the vehicle's safe takeover, and is used to evaluate "whether it is suitable to perform a takeover action in the current environment". The external environment data may include, but is not limited to, high-precision map road types, vehicle density in adjacent lanes, lighting conditions, etc. The specific external environment data needs to be determined according to the actual situation. The external environment data can be used to prevent the system from forcibly performing actions in an inappropriate takeover environment (such as changing lanes in a tunnel or stopping on the main highway of a high-speed road), avoiding secondary accidents, and is a prerequisite for achieving safe takeover.

[0038] In an optional embodiment, during the vehicle's driving process, object state data of a target object is acquired, including at least two non-redundant perception data among physiological signals, visual behavior signals, and voice signals. Vehicle operation data of the vehicle is synchronously collected, covering dynamic parameters such as vehicle speed, steering angle, acceleration, gear position, and load. External environment data is acquired, including road type, lane line status, road surface adhesion coefficient, traffic flow density, distribution of surrounding obstacles, and high-precision map information, forming a multi-source spatio-temporal synchronous input for risk assessment and control decision-making.

[0039] Exemplarily, during the vehicle's driving process, physiological signals of the target object are collected through bioelectric sensors integrated in the steering wheel, seat, and cabin, combined with visual perception of eye movements, head postures, and facial expressions by an in-vehicle camera, and voice features and abnormal audio are acquired through a microphone array, jointly constituting the object state data of the target object. Vehicle operation data such as vehicle speed, steering angle, acceleration, gear position, and load is synchronously obtained from the Controller Area Network (abbreviated as CAN) / Local Interconnect Network (abbreviated as LIN) of the vehicle controller and the inertial measurement unit. At the same time, by integrating high-precision maps, Global Positioning System (abbreviated as GPS) positioning, millimeter-wave radar, cameras, and Vehicle-to-Everything (abbreviated as V2X) communication modules, road type, lane line status, road surface adhesion coefficient, traffic flow density, distribution of surrounding obstacles, and traffic constraint information are obtained in real time, forming complete external environment data. Optionally, the three types of data are input to the risk assessment module after spatio-temporal synchronization processing, providing a global perception input for subsequent dynamic takeover decisions.

[0040] Step S104, based on the vehicle operation data, external environment data, and object state data, perform a state assessment on the target object to obtain a target risk quantification result of the target object, where the target risk quantification result is used to describe the probability that the target object loses control of the vehicle in the current state of the target object.

[0041] The aforementioned state assessment can refer to the calculation process of establishing a unified multi-dimensional assessment model by integrating multi-source heterogeneous input data (object state data of the target object, vehicle operation data, and environmental data of the external environment) to quantitatively judge whether the target object currently has the ability to continuously, effectively, and safely control the vehicle.

[0042] The aforementioned target risk quantification result can refer to a continuous numerical output. The target risk quantification result can be used to represent the probability that, at the current moment, the target object loses all or part of its control over the vehicle due to physiological, behavioral, or consciousness abnormalities. The target risk quantification result takes the value of a closed interval [0, 1] or [0, 100], with higher values ​​indicating a greater probability of incapacitation. The target risk quantification result can be used to transform fuzzy driver state abnormalities into calculable, comparable, and gradable mathematical quantities. It drives the dynamic selection and parameter adjustment of control strategies in progressive takeover protocols; achieving a linear mapping between risk level and response intensity, ensuring the predictability and safety of system behavior.

[0043] In one optional embodiment, based on vehicle operation data, external environment data, and object state data, a comprehensive analysis of the target object's physiological, behavioral, and interactive states is performed. Combined with vehicle dynamic characteristics and surrounding traffic environment constraints, a continuous numerical target risk quantification result is calculated. This target risk quantification result characterizes the probability that the target object will lose effective control of the vehicle in its current state, and is used to quantify the real-time risk level of driver incapacity, rather than a binary judgment. This process collaboratively models driver state, vehicle dynamics, and road scenarios, enabling risk assessment to possess environmental adaptability and contextual awareness, improving the early detection, accuracy, and reliability of incapacity identification, and providing accurate, continuous, and interpretable decision-making basis for subsequent graded response and smooth takeover.

[0044] Step S106: If the target risk quantification result meets the preset risk quantification result, a target control strategy is generated based on vehicle operation data, external environment data and target risk quantification result. The target control strategy is used to represent the switching timing and control parameters corresponding to multiple takeover stages, and the multiple takeover stages are smoothly connected in sequence.

[0045] The aforementioned preset risk quantification result can refer to a pre-defined continuous threshold boundary used to trigger the generation of control strategies. The preset risk quantification result can include, but is not limited to, single-threshold modes, multi-level threshold modes, and dynamic threshold modes. Among these, the multi-level threshold mode can include, but is not limited to, a first preset risk quantification result, a second preset risk quantification result, etc. The specific preset risk quantification result needs to be determined according to actual needs. The preset risk quantification result can be used as a decision-making trigger threshold for switching from a monitoring state to an active intervention state, ensuring that the control handover process is initiated only when the risk reaches an acceptable takeover threshold, avoiding frequent interventions caused by low-risk disturbances.

[0046] The aforementioned target control strategy refers to a sequence of control commands with temporal constraints and parameter continuity, generated based on current vehicle operating data, external environment data, and target risk quantification results. The target control strategy may include, but is not limited to, switching timing, control parameters, constraints, and output formats; the specific target control strategy needs to be determined based on the actual situation. The target control strategy can be used to guide the vehicle to achieve a smooth and safe transition of control during multiple takeover phases.

[0047] The aforementioned multiple takeover phases refer to several consecutive, non-overlapping control sub-phases during the transfer of vehicle control from the target object to the driving system, divided according to functional decoupling and temporal priority. These multiple takeover phases may include, but are not limited to, longitudinal takeover phases, lateral takeover phases, and safe stopping phases; the specific multiple takeover phases need to be determined based on the actual situation. Multiple takeover phases can be used to achieve safety, comfort, and predictability in the transfer of control, avoiding system coupling oscillations caused by simultaneous takeover of longitudinal and lateral control; by executing in stages, the instantaneous pressure on the bandwidth and actuator response speed of the drive-by-wire system is reduced, improving system robustness and user trust.

[0048] In one optional embodiment, when the target risk quantification result meets the preset risk quantification result, a target control strategy is dynamically generated based on vehicle operation data, external environment data, and the target risk quantification result. This target control strategy defines the switching timing and corresponding control parameters for multiple takeover phases. Each phase is triggered in an orderly manner according to the risk level and environmental constraints, with the longitudinal takeover phase taking precedence over the lateral takeover phase, to achieve a smooth transition of control parameters, avoid abrupt command changes, and ensure the continuity and stability of the vehicle's dynamic response. The above process realizes the evolution of control handover from abrupt switching to a gradual, phased, and parameter-continuous evolution, reducing occupant discomfort and the risk of secondary collisions during the takeover process, improving the predictability and safety of the system response, and ensuring that the control behavior always conforms to the vehicle dynamic boundaries and traffic rule constraints.

[0049] Step S108: Control the vehicle based on the target control strategy.

[0050] In one optional embodiment, based on the takeover phase switching timing defined by the target control strategy and continuously changing control parameters, longitudinal deceleration, lateral path guidance, and safe stopping operations are sequentially performed on the vehicle. The control quantities at each stage are smoothly interpolated over time to ensure that the dynamic response is stepless and oscillating, achieving a passive and seamless transfer of control from the target object to the system. The above process follows a preset control sequence and environmental constraints, enabling the vehicle to complete stable and compliant takeover behavior without human intervention, effectively avoiding dangerous actions such as sudden braking and sharp turns, and improving the safety, comfort, and repeatability of the takeover process.

[0051] In this application embodiment, a vehicle control method is proposed. During vehicle operation, the method first acquires object state data of a target object within the vehicle, vehicle operation data, and external environment data of the vehicle's surroundings. Next, based on the vehicle operation data, external environment data, and object state data, a state assessment of the target object is performed to obtain the probability that the target object will lose control of the vehicle in the current state, i.e., the target risk quantification result. Then, if the target risk quantification result meets a preset risk quantification result, a target control strategy including multiple takeover phases is generated based on the vehicle operation data, external environment data, and target risk quantification result. Finally, the vehicle is controlled based on the target control strategy. This application adopts a multi-dimensional data fusion-driven dynamic risk quantification and phased smooth control collaborative mechanism. By jointly modeling object state data, vehicle operation data and external environment data, it outputs continuous target risk quantification results, effectively improving the accuracy of risk quantification. On this basis, it dynamically generates a progressive target control strategy that includes multiple takeover stages, ensuring a smooth and controllable handover process. This achieves the technical objective of proactively intervening before the target object loses its controllability and accurately matching the intensity of intervention with the needs of the scenario. Thus, it realizes the technical effect of closed-loop control from passive early warning to proactive, safe and smooth takeover, thereby solving the technical problem of low vehicle control safety in related technologies.

[0052] Optionally, based on vehicle operation data, external environment data, and object status data, a status assessment of the target object is performed to obtain the target risk quantification result of the target object, including: performing a status assessment of the target object based on the object status data to obtain an initial risk quantification result of the target object; determining a risk correction factor based on vehicle operation data and external environment data, wherein the risk correction factor is used to represent the degree of external influence of vehicle operation data and external environment data on the initial risk quantification result; and correcting the initial risk quantification result based on the risk correction factor to determine the target risk quantification result.

[0053] The aforementioned initial risk quantification result can refer to a basic probability value independently calculated based on the object's state data, reflecting only the degree of abnormality in the target object's own state. The initial risk quantification result can be used as a starting point for risk assessment, providing a direct, endogenous basis for judging the driver's incapacity state, and is used to capture potential loss of control risks caused by intrinsic factors such as fatigue, sudden illness, or distraction.

[0054] The aforementioned risk correction factors can refer to dynamic correction coefficients calculated from vehicle operating data (such as vehicle speed, steering angle, acceleration, and gear position) and external environmental data (such as road type, weather, lighting, lane line clarity, and distance between adjacent vehicles). Risk correction factors may include, but are not limited to, vehicle speed correction factors, environmental complexity correction factors, vehicle dynamics state correction factors, and multi-factor fusion corrections. Specific risk correction factors need to be determined based on the actual situation. Risk correction factors can be used to eliminate the interference of environmental and vehicle conditions on human factor judgments, achieve decoupled assessment of human factor risk and situational operability, and ensure that a high response is triggered only when "human incapacity + environmental vulnerability" occurs.

[0055] In one optional embodiment, firstly, the target object is assessed based on its state data to obtain an initial risk quantification result characterizing its own disability probability; then, by combining vehicle operation data and external environmental data, a risk correction factor reflecting the amplification or inhibition effect of both on human-caused risks is calculated; furthermore, this risk correction factor is applied to the initial risk quantification result through multiplicative correction to generate the final target risk quantification result. The above process achieves decoupled assessment and dynamic fusion of intrinsic human-caused risks and external situational influences, avoiding false triggering due to environmental safety (such as low-speed parking) or response delay due to high-risk environments (such as high-speed curves), improving the accuracy of risk judgment, scenario adaptability, and anti-interference capability, and providing a more semantically consistent and engineering-practical quantitative basis for the reliable triggering of subsequent control strategies.

[0056] Optionally, the object status data includes at least two of the following: physiological status data, visual acquisition data, voice acquisition data, and active triggering data; the object status is assessed based on the object status data to obtain the initial risk quantification result of the object, including: assessing the confidence of at least two data points respectively to obtain the confidence weights corresponding to at least two data points; and weighting and fusing the at least two data points based on their corresponding confidence weights to obtain the initial risk quantification result.

[0057] The aforementioned physiological state data can refer to bioelectrical signals or physiological parameters directly related to the physiological functions of the target subject. Physiological state data may include, but is not limited to, heart rate variability, skin conductance, electromyography (EMG) signals, blood oxygen saturation, and micro-changes in electroencephalography (EEG). Specific physiological state data needs to be determined based on the actual situation. Physiological state data can provide objective and difficult-to-fake indicators of disability, and can be used to identify sudden physiological events (such as arrhythmia, respiratory arrest, and sudden drop in blood pressure), serving as a core basis for assessing the disability risk of the target subject.

[0058] The aforementioned visual acquisition data can refer to the sequence of images of the target object's face and head. Visual acquisition data may include, but is not limited to, eyelid closure duration and frequency, head posture angle, pupil diameter change rate, facial muscle movements, and the percentage of time the gaze deviates from the center of the road. Specific visual acquisition data needs to be determined based on the actual situation. Visual acquisition data can be used to provide high spatiotemporal resolution behavioral representations to identify visually observable abnormal behavioral patterns such as distraction, fatigue, and loss of consciousness.

[0059] The aforementioned voice acquisition data refers to the voice signal of the target object. Voice acquisition data may include, but is not limited to, abnormal sound intensity, slowed speech rate, unclear pronunciation, increased pause frequency, and keyword recognition. The specific voice acquisition data needs to be determined based on the actual acquisition situation. Voice acquisition data can be used to supplement the identification of confusion, language impairment, or requests for help, especially providing auxiliary judgment when visual or physiological data is limited.

[0060] The aforementioned proactive triggering data can refer to explicit intervention signals generated by physical or touch input devices actively operated by the target object. Proactive triggering data can be used to directly express their subjective desire for assistance. Proactive triggering data can be used as a high-confidence deterministic input, serving as a decisive triggering basis when uncertainty exists in any other modality, thus avoiding delays caused by system hesitation.

[0061] The aforementioned active triggering data may include, but is not limited to, pressing the dedicated emergency button on the steering wheel, pressing and holding the "Help" icon on the central control screen, or stepping on an unconventional brake pedal (such as dual-pedal linkage). The specific active triggering data needs to be determined based on the actual situation and is not limited here.

[0062] The aforementioned confidence assessment refers to the quantitative evaluation of the reliability level of each object's state data under the current acquisition environment and sensor operating conditions. Confidence assessment can be used to suppress invalid or false alarm inputs caused by sensor malfunctions, interference, or abnormal operating conditions (such as strong light obscuring the camera or electromagnetic interference affecting heart rate detection), ensuring the stability of the fusion results.

[0063] The aforementioned confidence weights can refer to the dynamic proportional coefficients assigned to each object's state data during the weighted fusion process. Confidence weights can be used to control the influence of a certain data on the final risk value, achieving adaptive data fusion. When the confidence of a certain modality decreases, its weight is automatically reduced to improve system robustness; and its dominant role is strengthened when a high-confidence modality appears.

[0064] The aforementioned weighted fusion can refer to the process of linearly or non-linearly combining at least two object state data with their corresponding confidence weights to output a single continuous value as the initial risk quantification result.

[0065] In one optional embodiment, based on at least two items from the object state data—physiological state data, visual acquisition data, voice acquisition data, or actively triggered data—a confidence assessment is performed on each data item to generate a corresponding dynamic confidence weight, reflecting the reliability of each modality under the current acquisition conditions. Subsequently, the original risk features are weighted and fused according to the confidence weights to output a single, continuous initial risk quantification result. This process, through a confidence-driven adaptive weighting mechanism, effectively suppresses misjudgments caused by sensor interference, environmental anomalies, or signal failures, enhances the collaborative reliability of multimodal data in high-noise, low-signal-to-noise-ratio scenarios, and achieves stable, interpretable, and highly fault-tolerant assessment of driver disability status without introducing complex deep learning models, thereby improving the accuracy and engineering practicality of the initial risk quantification result.

[0066] Optionally, a target control strategy is generated based on vehicle operation data, external environment data, and target risk quantification results. This includes: determining a first control strategy as the target control strategy when the target risk quantification result is greater than a first preset risk quantification result and less than a second preset risk quantification result; and generating a second control strategy based on vehicle operation data and external environment data when the target risk quantification result is greater than or equal to the second preset risk quantification result, and determining the second control strategy as the target control strategy. The second preset risk quantification result is greater than the first preset risk quantification result, the risk level corresponding to the second control strategy is higher than the risk level corresponding to the first control strategy, and the second control strategy includes longitudinal control parameters corresponding to the longitudinal takeover stage in multiple takeover stages, and lateral control parameters corresponding to the lateral takeover stage in multiple takeover stages.

[0067] The aforementioned first preset risk quantification result can refer to a pre-defined low threshold boundary used to initiate a basic takeover response. The first preset risk quantification result can be used as the activation threshold for triggering the first control strategy, ensuring that a mild, low-intrusion intervention is initiated before the risk reaches a severe level, achieving early response and smooth transition of the risk, and avoiding delays that could lead to a deterioration of the situation.

[0068] The aforementioned second preset risk quantification result can refer to a pre-defined high threshold boundary that is higher than the first preset risk quantification result. This second preset risk quantification result can serve as a decision watershed for triggering the second control strategy, ensuring that when the risk reaches a critical point that endangers safety, the system quickly switches to a high response level and initiates a complete takeover process, including lateral control, to achieve life safety assurance.

[0069] The aforementioned first control strategy can refer to the basic takeover control sequence activated when the target risk quantification result falls between the first and second preset risk quantification results. This first control strategy can be used to alert the driver to take over during a moderate risk phase, thereby achieving risk buffering.

[0070] The aforementioned second control strategy can refer to a comprehensive takeover control sequence activated when the target risk quantification result reaches or exceeds a second preset risk quantification result, encompassing complete coordinated actions of vertical and horizontal control. This second control strategy can be used to achieve proactive, safe, and closed-loop vehicle control takeover in high-risk scenarios, completing the entire process of deceleration, lane changing, and route guidance to a safe stopping point, ensuring the feasibility and safety of the final stop.

[0071] The aforementioned longitudinal takeover phase refers to the priority control sub-phase executed during the takeover process, focusing on the vehicle's longitudinal dynamics (acceleration / deceleration). Its purpose is to reduce vehicle speed to a safe range, creating preconditions for lateral control. The longitudinal takeover phase can be used to reduce kinetic energy risks and eliminate the direct threat of rear-end collisions or loss of control; it is the primary safety prerequisite for all takeover procedures.

[0072] The aforementioned longitudinal control parameters refer to continuous adjustment quantities used to control the longitudinal dynamics of the vehicle, generated by the second control strategy. These longitudinal control parameters may include, but are not limited to, target deceleration values, rate of change of deceleration, target vehicle speed threshold, and braking pressure slope; the specific longitudinal control parameters need to be determined based on actual conditions. These longitudinal control parameters can be used to achieve gradual, non-abrupt adjustment of vehicle speed, ensuring ride comfort and maintaining a safe following distance.

[0073] The aforementioned lateral takeover phase refers to a control sub-phase initiated after longitudinal control has stabilized, targeting the vehicle's lateral dynamics (steering / trajectory tracking), and used to guide the vehicle to a safe parking area. The lateral takeover phase enables lane changes and path convergence, completing a smooth transition from the current driving trajectory to the target parking point, and is a key link in achieving a "safe parking" closed loop.

[0074] The aforementioned lateral control parameters refer to continuous adjustment quantities used to control the lateral dynamics of the vehicle, generated by the second control strategy. Lateral control parameters may include, but are not limited to, target lateral acceleration, steering angular velocity, path curvature radius, lane change trajectory type, etc., and the specific lateral control parameters need to be determined based on actual conditions. Lateral control parameters can be used to achieve smooth, safe lane changes and path tracking that comply with road constraints, avoiding sharp turns, skidding, or lane departure.

[0075] In one optional embodiment, when the target risk quantification result is higher than the first preset risk quantification result but lower than the second preset risk quantification result, the first control strategy is determined as the target control strategy. When the target risk quantification result reaches or exceeds the second preset risk quantification result, a second control strategy, including longitudinal and lateral coordinated control, is dynamically generated based on vehicle operation data and external environment data. The second preset risk quantification result is higher than the first preset risk quantification result, and the risk response level corresponding to the second control strategy is higher than that of the first control strategy. The second control strategy clearly distinguishes between the longitudinal takeover phase and the lateral takeover phase, and configures corresponding longitudinal and lateral control parameters respectively, achieving a response mechanism where the control intensity increases with the risk level gradient and the action sequence is strictly step-by-step. The above process adaptively selects the control level according to the risk level. Under medium risk, only the first control strategy is executed to avoid excessive intervention. Under high risk, longitudinal deceleration and lateral path guidance are coordinated to ensure that the takeover behavior unfolds orderly within the safety boundary, improving the accuracy, safety, and environmental adaptability of the system response, while ensuring the predictability of control actions and passenger comfort.

[0076] Optionally, controlling the vehicle based on a target control strategy includes: when the target control strategy is a first control strategy, outputting a prompt message to the target object, wherein the prompt message is used to prompt the target object to take over the vehicle; when the target control strategy is a second control strategy, or when the target object does not take over the vehicle after the first control strategy is executed, controlling the vehicle to drive towards a target area based on longitudinal control parameters and lateral control parameters, wherein the target area is used to represent the safe parking area closest to the vehicle.

[0077] The aforementioned prompt message refers to the human-machine interaction warning signal output by the system to the target object when the target control strategy is the primary control strategy. This prompt message can be used to provide a final opportunity for manual intervention during medium-risk phases. Without taking over control, it awakens or reminds the driver through a strong sensing signal, preventing premature system intervention and reflecting the safety design principle of "human-centric, machine-assisted."

[0078] For example, the types of prompts may include, but are not limited to: visual prompts: a flashing red icon or text prompt (such as "Please take over immediately") displayed on the dashboard or head-up display (HUD); auditory prompts: repeated voice announcements (such as "An abnormal state has been detected; please resume driving immediately") at a frequency of ≥2 times / second, with a volume higher than ambient noise; tactile prompts: vibration of the steering wheel or seat (frequency 5–15Hz, amplitude ≤0.3g), duration ≤10 seconds, to avoid overstimulation; and combined prompts: simultaneous triggering of visual, auditory, and tactile prompts to ensure perception under different attentional states. The above values ​​are for illustrative purposes only; specific values ​​need to be determined based on actual needs.

[0079] The aforementioned target area can refer to the nearest parking area that complies with traffic regulations and physical safety conditions, dynamically calculated based on the vehicle's current location, real-time environmental data, and high-precision map information. The target area can serve as the endpoint for automatic vehicle parking after the second control strategy is activated or the first control strategy fails. The target area provides a spatial endpoint for the second control strategy, ensuring that after longitudinal deceleration and lateral guidance, the vehicle can safely and compliantly park at a location with the lowest risk of secondary accidents, thus achieving a closed loop of "control-parking-risk avoidance."

[0080] In one optional embodiment, when the target control strategy is the first control strategy, a prompt message is output to the target object to remind it to regain control of the vehicle; when the target control strategy is the second control strategy, or when the target object does not respond to the takeover request after the first control strategy is executed, the vehicle is driven along the planned path to the parking area closest to the current location that meets traffic regulations and safety conditions, i.e., the target area, based on the longitudinal control parameters and lateral control parameters. This process retains the priority of human intervention through prompt messages, and automatically executes phased, constrained longitudinal deceleration and lateral guidance when no response is received, achieving a seamless transition from warning to safe stopping. This effectively reduces the risk of loss of control due to driver incapacity and improves the safety, compliance, and execution reliability of the system in graded response scenarios.

[0081] Optionally, controlling the vehicle to drive towards the target area based on longitudinal control parameters and lateral control parameters includes: verifying the consistency between the second control strategy and the target risk quantification result to obtain a consistency verification result, wherein the consistency verification result is used to indicate whether the second control strategy matches the current state of the vehicle; if the consistency verification result indicates that the second control strategy matches the current state of the vehicle, controlling the vehicle to drive towards the target area based on the longitudinal control parameters and lateral control parameters.

[0082] The aforementioned consistency verification can refer to the process of comparing and calculating the logical and physical constraints between the target risk quantification results and the second control strategy to determine whether the strategy can be implemented safely and compliantly.

[0083] For example, consistency verification may include, but is not limited to, the following: Dynamic consistency verification: comparing the vehicle's current speed, lateral acceleration, and steering angle with the initial state required by the second control strategy to see if they are within the allowable tolerance range; Environmental consistency verification: verifying whether the target path area still has passable conditions (e.g., whether there are obstacles in adjacent lanes, whether lane lines are clear, and whether the gradient exceeds the limit); Rule consistency verification: verifying whether the strategy action violates traffic rules (e.g., initiating a lane change in a prohibited lane change area or entering a non-stop zone); Logical consistency verification: verifying whether there are internal conflicts or conflicts with preset safety rules in the strategy instruction sequence through formal methods (e.g., Answer Set Programming, or ASP). The above consistency verification is only an example, and the specific consistency verification needs to be determined according to the actual situation.

[0084] The aforementioned consistency verification result can refer to the binary status identifier output by the consistency verification process. The consistency verification result may include, but is not limited to, matching (i.e., all verification items meet the preset constraints and the strategy can be executed safely); and non-matching (i.e., at least one verification item violates the constraints and the strategy cannot be executed). The specific consistency verification result needs to be determined based on the actual situation. The consistency verification result can be used to clearly characterize whether the second control strategy is consistent with the current vehicle state and environmental conditions in terms of safety, compliance, and executableness.

[0085] In one optional embodiment, after the second control strategy is generated, a logical consistency verification is performed on the decision intent corresponding to the second control strategy and the target risk quantification result. A consistency verification result indicating whether the strategy matches the actual vehicle state is output. Only when the consistency verification result is a match is the vehicle driven towards the target area based on the longitudinal and lateral control parameters. This ensures that high-risk takeover actions are feasible under real-world constraints, thereby avoiding the risk of loss of control due to misjudgment of the state or sudden environmental changes, and improving the reliability, safety, and verifiability of control decisions.

[0086] Optionally, the vehicle is controlled to move toward the target area based on longitudinal control parameters and lateral control parameters, including: determining the vehicle's current speed based on vehicle operation data; performing longitudinal control on the current speed based on the longitudinal control parameters; obtaining a locally planned path for the vehicle to move to the target area when the current speed is within a preset speed range and the vehicle's external environmental data meets the lateral takeover conditions, wherein the lateral takeover conditions are used to represent the safety conditions that the external environmental data must meet when performing lateral takeover; and performing lateral control on the vehicle based on the lateral control parameters and the locally planned path to drive the vehicle toward the target area.

[0087] The aforementioned current vehicle speed refers to the instantaneous speed of the vehicle calculated in real time based on vehicle operation data. It serves as feedback input for longitudinal control. The current vehicle speed can be used to determine whether the precondition for initiating lateral control is met, ensuring that lateral control is only activated after the speed drops to a safe threshold, thus avoiding dynamic instability caused by lane changes at high speeds.

[0088] The aforementioned preset speed range refers to a closed interval consisting of the upper and lower speed limits set for initiating lateral control intervention. The preset speed range can be pre-calibrated by vehicle dynamics safety boundaries and traffic scenario constraints. The preset speed range can be used as a timing switching threshold between longitudinal and lateral control, ensuring that lateral actions are only performed after sufficient kinetic energy reduction and vehicle stability enhancement, thereby reducing the risk of rollover, skidding, or collision.

[0089] The aforementioned lateral takeover conditions refer to a set of safety constraints that the external environmental data must satisfy to determine whether lateral control is permitted. Lateral takeover conditions may include, but are not limited to, adjacent lane accessibility, lane line identifiability, road type legality, curvature and slope constraints, and traffic rule compliance. Specific lateral takeover conditions need to be determined based on the actual situation. Lateral takeover conditions are used to ensure that lateral actions (such as lane changes and path deviations) are physically feasible and traffic compliant in both spatial and temporal dimensions, preventing steering near obstacles, in areas with missing lanes, or in areas prohibited by rules.

[0090] The aforementioned local planning path refers to a continuous, smoothly curvatured two-dimensional trajectory segment that conforms to dynamic constraints, generated by the path planning module based on the vehicle's current position, target area coordinates, and real-time environmental data after the lateral takeover conditions are met. Local planning path types can include, but are not limited to, cubic spline curves, Bézier curves, and polynomial interpolation trajectories; the specific local planning path needs to be determined according to actual requirements. Local planning paths can be used to transform the abstract spatial location of the "target area" into an executable sequence of control commands, ensuring safe, comfortable, and conflict-free path convergence for lateral control within a limited space.

[0091] In one optional embodiment, firstly, the current vehicle speed is acquired in real time based on vehicle operation data, and longitudinal dynamic control is implemented according to longitudinal control parameters. When the current vehicle speed falls within a preset speed range and the external environmental data simultaneously meets the lateral intervention conditions required for lateral intervention, a local planned path pointing to the target area is generated. Finally, lateral dynamic control is executed based on the lateral control parameters and the local planned path, enabling the vehicle to smoothly transition to the target area. This process ensures the kinetic safety of lateral intervention timing through speed range limitations, guarantees the compliance and spatial feasibility of steering actions through multi-dimensional environmental constraints, and achieves precise trajectory guidance through a smooth local path. This effectively avoids the risk of loss of control caused by lateral intervention at high speeds, and improves the temporal rationality, environmental adaptability, and execution safety of the control sequence.

[0092] Optionally, obtaining the local planned path for the vehicle to travel to the target area includes: obtaining the vehicle's current location data and the target location data of the target area; and generating the local planned path based on the current location data and the target location data.

[0093] The aforementioned current location data can refer to the three-dimensional geometric information representing the instantaneous spatial coordinates of the vehicle in the global coordinate system, output in real time by the vehicle positioning system. Current location data may include, but is not limited to, location coordinates, accuracy level, and information update frequency; the specific current location data needs to be determined based on actual requirements. Current location data can be used as a starting point reference for local path planning, ensuring that path generation is based on the vehicle's actual spatial state and avoiding path deviation, collisions, or deviations from the target area due to positioning errors.

[0094] The aforementioned target location data can refer to the precise spatial coordinates of the final safe stopping point that the vehicle needs to reach in the global coordinate system. This target location data can be used as the endpoint target for local path planning, providing a clear spatial convergence direction for lateral control and ensuring that the vehicle ultimately stops at a compliant, statically safe location with no risk of secondary collision.

[0095] In one optional embodiment, firstly, the vehicle's current location data and the target location data of the target area are acquired. Both are determined based on high-precision positioning and map semantic information, representing the vehicle's current spatial coordinates and the coordinates of a safe stopping point after rule verification, respectively. Then, based on the spatial relationship between the two in a unified coordinate system, a local planning path that satisfies dynamic constraints, has continuous curvature, and is conflict-free is generated to guide the vehicle smoothly from its current location to the target location. This process, through precise spatial start and end point constraints, ensures that the generated path has real-world adaptability and termination accuracy, avoiding deviations, oscillations, or stopping failures caused by positioning ambiguity or target generalization, thereby improving the accuracy, safety, and trajectory reproducibility of control execution.

[0096] Optionally, after the vehicle drives to the target area, the method further includes: triggering the vehicle emergency call service and sending structured rescue data, wherein the structured rescue data includes: the vehicle's geographical location information, vehicle identification number, number of occupants in the vehicle, and event type identifier inferred by the system.

[0097] The aforementioned structured rescue data refers to a set of structured information that conforms to the emergency call service (eCall) standard, automatically generated and encapsulated by the system after the vehicle has come to a complete stop. Structured rescue data may include, but is not limited to, geographic location information, vehicle identification number, number of occupants, and event type identifiers; the specific structured rescue data needs to be determined based on actual needs. Structured rescue data can be used to achieve seamless information connection from in-vehicle autonomous safety response to external professional rescue, ensuring that rescue organizations can quickly obtain accurate vehicle location, identity, and event nature without human intervention, shortening response time and improving the efficiency of life-saving treatment.

[0098] The Vehicle Identification Number (VIN) mentioned above refers to a unique alphanumeric code for each vehicle, used to identify its manufacturer, model, year of manufacture, and unique serial number throughout its entire lifecycle. The VIN serves as legal identification for roadside assistance centers, facilitating quick retrieval of vehicle registration information, brand and model, safety features (such as airbag configuration), and historical maintenance records, thus aiding in the accurate matching of rescue resources and the tracing of accident liability.

[0099] The event type identifier mentioned above can be a standardized code or enumerated value that characterizes the nature of this emergency. The event type identifier can be used to initially describe the event category to the rescue center.

[0100] The event type identifiers mentioned above may include, but are not limited to: 0x01: Sudden health problems of the driver (such as myocardial infarction or fainting), inferred from a combination of abnormal physiological signals and behavioral incapacity; 0x02: Sudden health problems of occupants (such as child suffocation or elderly fainting), detected by cabin sensors as abnormal vital signs of non-drivers; 0x03: The driver actively triggers a distress call, confirmed manually by the driver pressing a button; 0x04: System self-check anomalies leading to forced docking, such as sensor failure or communication interruption; 0x05: Unknown events, unable to be clearly categorized, only marked "Emergency docking, cause under investigation." The above event type identifiers are for illustrative purposes only; specific event type identifiers need to be determined based on the actual situation.

[0101] In one optional embodiment, after the vehicle arrives at the target area and comes to a stop, the vehicle emergency call service (eCall) is automatically triggered, and structured rescue data containing vehicle geolocation information, vehicle identification number (VIN), number of occupants in the vehicle, and event type identifiers generated by the system based on multimodal perception is sent. This ensures that rescue organizations can obtain accurate location coordinates, unique vehicle identity, occupant size, and event nature classification without human intervention, achieving seamless information connection from autonomous vehicle parking to external professional rescue, improving the accuracy, timeliness, and resource matching efficiency of emergency response, and avoiding rescue delays and misjudgments caused by ambiguous or missing information.

[0102] In one alternative embodiment, Figure 2 This is a flowchart of an optional vehicle control method according to an embodiment of this application, such as... Figure 2 As shown, after the system powers on and performs a self-test, the method continuously uses multimodal sensing to perceive the driver's state and the vehicle environment, and assesses the risk level. If the risk level is low, multimodal sensing continues. If the risk level is medium, a tiered warning is activated to prompt the driver to take over, and it is determined whether the driver responds in a timely manner. If the driver responds in a timely manner, multimodal sensing continues; if the driver does not respond in a timely manner, an intelligent takeover decision is generated. If the risk level is high, an intelligent takeover decision is generated directly, a progressive takeover protocol is executed, a route is planned to a safe stopping point, the vehicle is brought to a safe stop, and an emergency call is automatically activated to send location and event information. Finally, the process ends, and the system waits for rescue.

[0103] The above process achieves differentiated response strategies through multi-level risk assessment. Low-risk scenarios involve continuous monitoring to avoid false triggering; medium-risk scenarios initiate tiered early warnings while retaining a window for manual takeover; and high-risk scenarios directly trigger intelligent takeover and a safe closed-loop handling system. This improves the system's response timeliness and control safety in scenarios where the driver is disabled, ensuring smooth stopping and automatic distress calls without relying on human intervention. It effectively constructs a full-chain life safety guarantee mechanism from perception and decision-making to execution, enhancing the reliability of the intelligent driving system and user trust.

[0104] Figure 3 This is a flowchart of a multimodal fusion perception process for the state of a target object according to an embodiment of this application, such as... Figure 3As shown, the process begins with parallel acquisition of raw signals: visual signals are acquired via a camera, physiological signals via a steering wheel sensor / wearable device, behavioral signals via a steering wheel angle sensor / grip force sensor, and active signals via an emergency call button. Next, preprocessing and feature extraction are performed on these multi-source signals: facial feature analysis is performed on the visual signals to obtain eyelid, gaze, and head posture features; physiological indicators are calculated from the physiological signals to obtain heart rate, heart rate variability, and other indicators; and operational behavior analysis is performed on the behavioral signals to obtain the frequency and intensity of abnormal operations. Then, the obtained features, indicators, and active signals are weighted and fused together; finally, the driver's state score and confidence level are output.

[0105] The above process involves parallel acquisition of multimodal raw signals from vision, physiology, behavior, and active triggering, followed by targeted preprocessing and feature extraction to achieve a comprehensive and high-dimensional characterization of the driver's state. Then, through weighted fusion of multi-source features, the overall state score and confidence level are comprehensively evaluated, improving the accuracy and robustness of anomaly identification. This effectively suppresses the risk of missed detection caused by false alarms or failures of a single sensor, providing reliable, quantifiable, and interpretable input for subsequent risk decisions and enhancing the system's perception reliability and decision-making safety in complex driving scenarios.

[0106] Figure 4 This is a flowchart of an intelligent takeover and path decision-making process according to an embodiment of this application, such as... Figure 4 As shown, the core decision-making steps of this process after receiving the takeover command are safety and smoothness. In this process, firstly, the vehicle status (vehicle speed, position) is queried, and the environmental perception (lane lines, traffic flow, obstacles) is scanned. At the same time, a high-precision map is retrieved (to find a safe parking area). Next, a "safe parking corridor" (target point and path) is generated; the trajectory is decomposed into longitudinal / lateral control sub-targets; the smooth control curve (speed, acceleration, steering angle) is calculated; and finally, the control command is output to the drive-by-wire actuator.

[0107] Specifically, upon receiving the takeover command, the system first queries the vehicle's current status (including speed, position, and heading angle), simultaneously scans environmental perception data (lane lines, distances to vehicles ahead and behind, and dynamic obstacles), and retrieves high-precision maps to identify compliant and sufficiently spacious safe parking areas. Based on this information, a "safe parking corridor" is generated from the starting point to the target parking point. This corridor meets road regulations, dynamic feasibility, and obstacle avoidance requirements, and is decomposed into longitudinal deceleration control sub-objectives and lateral path guidance sub-objectives. Subsequently, the acceleration and steering angle change rates are dynamically adjusted according to the risk level, and a trajectory planning algorithm with continuous curvature and smooth acceleration is used to generate control curves, ensuring that the longitudinal deceleration does not exceed the comfort threshold and the lateral steering angle change rate meets the vehicle's dynamic limits. Finally, the generated precise speed, acceleration, and steering angle command sequence is output to the brake-by-wire, drive-by-wire, and steering-by-wire actuators, achieving a gradual and shock-free transfer of control.

[0108] This process constructs a safety corridor by integrating real-time status, environmental perception, and high-precision maps. It achieves coordinated decoupling of longitudinal and lateral control through smooth trajectory decomposition and dynamic parameter adjustment, improving the stability, comfort, and safety of the takeover process. It avoids dangerous actions such as sudden braking and sudden turns, effectively reducing the risk of secondary accidents. At the same time, it ensures that the vehicle is accurately parked in the compliant area, laying a reliable physical foundation for subsequent automatic alarm and rescue response.

[0109] Figure 5 This is a flowchart of a vehicle emergency call service according to an embodiment of this application. Figure 5 This demonstrates how the system performs external communication and information transmission after the vehicle has come to a complete stop. For example... Figure 5 As shown, once the vehicle has come to a safe stop, the emergency communication protocol is activated. First, it automatically dials an emergency number, or it can send standardized data packets in parallel. After dialing the emergency number, it uses voice synthesis to broadcast key information (location, event). Then, it confirms whether the call was successfully connected. If connected, the line remains open until the rescue personnel confirm, and communication is complete, waiting for interaction. If the call is not connected or the signal is weak, the backup plan is activated, attempting to broadcast a request for help via V2X, or sending an SMS / application push to the preset emergency contact. After completing the above backup plan, communication is complete, waiting for interaction.

[0110] Specifically, once the vehicle has come to a safe stop, the emergency communication protocol is immediately activated. It prioritizes automatically dialing the emergency call service (eCall) via the cellular network and simultaneously sends a structured rescue data packet conforming to preset standards, including the vehicle's precise geographical location, VIN code, number of occupants, and an event type identifier inferred by the system. After the voice call is established, the voice synthesis module clearly broadcasts the core information, ensuring the rescue center receives crucial information in real time. The call connection status is continuously monitored. If successfully connected, the channel remains open until the rescuer confirms receipt of the information, entering a waiting interactive state. If the initial call fails, an alternative communication mechanism is automatically activated. This involves broadcasting a request for help to nearby vehicles or roadside units via V2X to achieve relay forwarding, or sending a text message and mobile application notification containing location and event summary to preset emergency contacts. All communication paths are executed in priority order until any channel successfully transmits information, at which point retrying terminates and the system enters a waiting interactive state. This process utilizes a primary and backup multi-channel redundant communication architecture to ensure effective delivery of emergency information even under extreme conditions such as no cellular network coverage, weak signal, or network congestion. This greatly improves the reliability and coverage of rescue response, avoids rescue delays caused by communication interruptions, and builds a truly uninterrupted closed loop for life safety protection.

[0111] According to the embodiments of this application, an embodiment of a vehicle control device is provided. It should be noted that the device can be used to execute the above-described vehicle control method. The specific implementation methods and application scenarios are the same as those of the above-described method, and will not be repeated here.

[0112] Figure 6 This is a schematic diagram of a vehicle control device according to an embodiment of this application, such as... Figure 6 As shown, the device includes: an acquisition module 602, an evaluation module 604, a generation module 606, and a control module 608.

[0113] The acquisition module 602 is used to acquire object state data of the target object in the vehicle, vehicle operation data, and external environment data of the vehicle's environment during vehicle operation. The evaluation module 604 is used to evaluate the state of the target object based on the vehicle operation data, external environment data, and object state data to obtain the target risk quantification result of the target object. The target risk quantification result describes the probability that the target object will lose control of the vehicle in its current state. The generation module 606 is used to generate a target control strategy based on the vehicle operation data, external environment data, and target risk quantification result, provided that the target risk quantification result meets the preset risk quantification result. The target control strategy represents the switching timing and control parameters corresponding to multiple takeover stages, and the multiple takeover stages are smoothly connected sequentially. The control module 608 is used to control the vehicle based on the target control strategy.

[0114] Optionally, the evaluation module is used to evaluate the status of the target object based on the object status data to obtain the initial risk quantification result of the target object; determine the risk correction factor based on vehicle operation data and external environment data, wherein the risk correction factor is used to represent the degree of external influence of vehicle operation data and external environment data on the initial risk quantification result; and correct the initial risk quantification result based on the risk correction factor to determine the target risk quantification result.

[0115] Optionally, the object status data includes at least two of the following: physiological status data, visual acquisition data, voice acquisition data, and active triggering data; the evaluation module is also used to evaluate the confidence of at least two of the data respectively to obtain the confidence weights corresponding to at least two of the data; based on the confidence weights corresponding to at least two of the data, the at least two of the data are weighted and fused to obtain the initial risk quantification result.

[0116] Optionally, the generation module is used to determine the first control strategy as the target control strategy when the target risk quantification result is greater than the first preset risk quantification result and less than the second preset risk quantification result; and to generate a second control strategy based on vehicle operation data and external environment data when the target risk quantification result is greater than or equal to the second preset risk quantification result, and to determine the second control strategy as the target control strategy. The second preset risk quantification result is greater than the first preset risk quantification result, the risk level corresponding to the second control strategy is higher than the risk level corresponding to the first control strategy, and the second control strategy includes longitudinal control parameters corresponding to the longitudinal takeover stage in multiple takeover stages, and lateral control parameters corresponding to the lateral takeover stage in multiple takeover stages.

[0117] Optionally, the control module is used to output a prompt message to the target object when the target control strategy is the first control strategy, wherein the prompt message is used to prompt the target object to take over the vehicle; when the target control strategy is the second control strategy, or when the target object does not take over the vehicle after the first control strategy is executed, the control module controls the vehicle to drive towards the target area based on the longitudinal control parameters and the lateral control parameters, wherein the target area is used to represent the safe parking area closest to the vehicle.

[0118] Optionally, the control module is also used to verify the consistency between the second control strategy and the target risk quantification result, and obtain a consistency verification result, wherein the consistency verification result is used to indicate whether the second control strategy matches the current state of the vehicle; if the consistency verification result indicates that the second control strategy matches the current state of the vehicle, the vehicle is controlled to drive towards the target area based on the longitudinal control parameters and the lateral control parameters.

[0119] Optionally, the control module is also used to determine the current vehicle speed based on vehicle operation data; to perform longitudinal control on the current vehicle speed based on longitudinal control parameters; to obtain a local planned path for the vehicle to travel to the target area when the current vehicle speed is within a preset speed range and the vehicle's external environment data meets the lateral takeover conditions, wherein the lateral takeover conditions are used to represent the safety conditions that the external environment data needs to meet when performing lateral takeover; and to perform lateral control on the vehicle based on the lateral control parameters and the local planned path, so that the vehicle travels to the target area.

[0120] Optionally, the control module is also used to acquire the vehicle's current location data and the target location data of the target area; and to generate a local planning path based on the current location data and the target location data.

[0121] Optionally, after the vehicle reaches the target area, the device is also used to trigger the vehicle emergency call service and send structured rescue data, which includes: the vehicle's geographical location information, vehicle identification number, number of occupants in the vehicle, and event type identifier inferred by the system.

[0122] Embodiments of this application also provide a vehicle, including: a memory storing an executable program; and a processor for running the program, wherein the program executes the methods described in various embodiments of this application when it runs.

[0123] Embodiments of this application also provide a computer-readable storage medium including a stored executable program, wherein, when the executable program is running, it controls the device where the computer-readable storage medium is located to perform the methods of various embodiments of this application.

[0124] Embodiments of this application also provide a computer program product, including a computer program that, when executed by a processor, implements the methods of various embodiments of this application.

[0125] Embodiments of this application also provide a computer program product, including a non-volatile computer-readable storage medium for storing a computer program that, when executed by a processor, implements the methods in various embodiments of this application.

[0126] Embodiments of this application also provide a computer program that, when executed by a processor, implements the methods described in the various embodiments of this application.

[0127] In the above embodiments of this application, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0128] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For instance, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.

[0129] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0130] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0131] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.

[0132] The above description is only a preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.

Claims

1. A vehicle control method, characterized in that, include: During vehicle operation, acquire object state data of target objects in the vehicle, vehicle operation data of the vehicle, and external environment data of the environment in which the vehicle is located. Based on the vehicle operation data, the external environment data, and the object status data, the target object is evaluated to obtain the target risk quantification result, wherein the target risk quantification result is used to describe the probability that the target object loses control of the vehicle in the current state of the target object; If the target risk quantification result meets the preset risk quantification result, a target control strategy is generated based on the vehicle operation data, the external environment data and the target risk quantification result. The target control strategy is used to represent the switching timing and control parameters corresponding to multiple takeover stages, and the multiple takeover stages are smoothly connected in sequence. The vehicle is controlled based on the target control strategy.

2. The vehicle control method according to claim 1, characterized in that, Based on the vehicle operation data, the external environment data, and the object status data, a status assessment is performed on the target object to obtain a quantitative result of the target risk, including: Based on the object state data, the target object is evaluated to obtain the initial risk quantification result of the target object; Based on the vehicle operation data and the external environment data, a risk correction factor is determined, wherein the risk correction factor is used to represent the degree of external influence of the vehicle operation data and the external environment data on the initial risk quantification result; The initial risk quantification result is corrected based on the risk correction factor to determine the target risk quantification result.

3. The vehicle control method according to claim 2, characterized in that, The object state data includes at least two of the following: physiological state data, visual acquisition data, voice acquisition data, and active triggering data; based on the object state data, a state assessment of the target object is performed to obtain an initial risk quantification result for the target object, including: Confidence assessments are performed on each of the at least two data points to obtain the confidence weights corresponding to the at least two data points; Based on the confidence weights corresponding to the at least two data points, the at least two data points are weighted and fused to obtain the initial risk quantification result.

4. The vehicle control method according to claim 1, characterized in that, Based on the vehicle operation data, the external environment data, and the target risk quantification results, a target control strategy is generated, including: If the target risk quantification result is greater than the first preset risk quantification result and less than the second preset risk quantification result, the first control strategy is determined as the target control strategy. When the target risk quantification result is greater than or equal to the second preset risk quantification result, a second control strategy is generated based on the vehicle operation data and the external environment data, and the second control strategy is determined as the target control strategy. The second preset risk quantification result is greater than the first preset risk quantification result, the risk level corresponding to the second control strategy is higher than the risk level corresponding to the first control strategy, and the second control strategy includes longitudinal control parameters corresponding to the longitudinal takeover stage among the multiple takeover stages, and lateral control parameters corresponding to the lateral takeover stage among the multiple takeover stages.

5. The vehicle control method according to any one of claims 1 to 4, characterized in that, Controlling the vehicle based on the target control strategy includes: When the target control strategy is the first control strategy, a prompt message is output to the target object, wherein the prompt message is used to prompt the target object to take over the vehicle; When the target control strategy is the second control strategy, or when the target object does not take over the vehicle after the first control strategy is executed, the vehicle is controlled to drive towards the target area based on longitudinal control parameters and lateral control parameters, wherein the target area is used to represent the safe parking area closest to the vehicle.

6. The vehicle control method according to claim 5, characterized in that, Based on the longitudinal control parameters and the lateral control parameters, controlling the vehicle to drive towards the target area includes: The consistency verification between the second control strategy and the target risk quantification result is performed to obtain a consistency verification result, wherein the consistency verification result is used to indicate whether the second control strategy matches the current state of the vehicle; If the consistency verification result shows that the second control strategy matches the current state of the vehicle, the vehicle is controlled to drive towards the target area based on the longitudinal control parameters and the lateral control parameters.

7. The vehicle control method according to claim 5, characterized in that, Based on longitudinal and lateral control parameters, the vehicle is controlled to move toward the target area, including: The current speed of the vehicle is determined based on the vehicle operation data; The current vehicle speed is longitudinally controlled based on the aforementioned longitudinal control parameters; When the current vehicle speed is within a preset speed range and the external environment data of the vehicle meets the lateral takeover conditions, a local planned path for the vehicle to travel to the target area is obtained. The lateral takeover conditions are used to represent the safety conditions that the external environment data needs to meet when performing a lateral takeover. Based on the lateral control parameters and the local planning path, the vehicle is laterally controlled to drive towards the target area.

8. The vehicle control method according to claim 7, characterized in that, Obtaining the local planned path of the vehicle to the target area includes: Obtain the current location data of the vehicle and the target location data of the target area; The local planning path is generated based on the current location data and the target location data.

9. The vehicle control method according to claim 7, characterized in that, After the vehicle drives to the target area, the method further includes: The vehicle emergency call service is triggered, and structured rescue data is sent, which includes: the vehicle's geographical location information, vehicle identification number, number of occupants in the vehicle, and event type identifier inferred by the system.

10. A vehicle, characterized in that, include: Memory, which stores executable programs; A processor for running the program, wherein the program, when running, performs the method according to any one of claims 1 to 9.

11. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored executable program, wherein, when the executable program is executed, it controls the device on which the storage medium is located to perform the method according to any one of claims 1 to 9.

12. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method according to any one of claims 1 to 9.