Security model parameterization for autonomous driving

By calculating metrics based on driving data and using multidimensional optimization techniques to determine the free parameters of the safety model for autonomous vehicles, the problem of unreasonable parameter assignment in existing technologies is solved, enabling safety verification and approval support for autonomous vehicles in different environments.

CN122138925APending Publication Date: 2026-06-02ROBERT BOSCH GMBH

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
ROBERT BOSCH GMBH
Filing Date
2024-11-06
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

The lack of effective methods in the existing technology to determine and verify the free parameters in the safety model for at least partially autonomous vehicles makes it difficult to ensure the safe and reliable operation of vehicles in road traffic.

Method used

By calculating metrics based on driving data, the free parameters of the safety model are determined using histograms and multidimensional optimization techniques. The robustness of the parameters is ensured through sensitivity analysis and cross-regional verification, and the predetermined criteria are met to guarantee safety.

Benefits of technology

It enables the reasonable assignment of free parameters, ensuring the safe operation of autonomous vehicles in different environments, providing reliable traffic safety proof, and supporting the vehicle approval process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122138925A_ABST
    Figure CN122138925A_ABST
Patent Text Reader

Abstract

A first aspect of the present disclosure relates to a computer-implemented method for parameterizing a safety model for a vehicle for at least partially autonomous driving, comprising: applying the safety model, wherein at least one metric is calculated based on at least driving data and on one or more parameters of the safety model at at least one point in time, and resulting in an evaluation result; and, matching the safety model, wherein at least one parameter of the safety model is matched based on at least the evaluation result and a predetermined criterion. A second aspect of the present disclosure relates to a computer-implemented method for validating a parameterization of a safety model for a vehicle for at least partially autonomous driving, wherein at least one parameter of the safety model has been matched, the method comprising: evaluating the at least one matched parameter of the safety model, wherein a second evaluation result is resulting.
Need to check novelty before this filing date? Find Prior Art

Description

Background Technology

[0001] The approval of at least partially autonomous vehicles, particularly highly automated driving vehicles (HAVs), requires proof of their traffic safety. A safety model contributes to this proof. This model formalizes rules by which driving behaviors, such as those of an HAV, are rated as safe or unsafe. For this purpose, assumptions are particularly needed regarding the reasonably foreseeable behaviors of other road users. The standard IEEE 2846 specifies assumptions about the parameters of such a safety model. To this end, the standard provides a non-complete list of physical parameters that should be assigned values ​​based on driving conditions and evaluated by the safety model.

[0002] However, to date, no methodology is known for properly assigning free parameters—that is, free parameters that are not pre-given by standards. What is needed here is a balance: assigning free parameters that is practical, yet also allows for smooth operation. Furthermore, a methodology for verifying the chosen values ​​is unknown.

[0003] Therefore, the problem upon which this disclosure is based is: how to determine and / or verify the free parameters of a safety model for at least partially autonomous driving of a vehicle, for safe autonomous driving. Summary of the Invention

[0004] A first general aspect of this disclosure relates to a computer-implemented method for parameterizing a safety model for at least partially autonomous driving of a vehicle. The method includes applying the safety model, wherein at least one metric is calculated at least at a time point based on driving data and one or more parameters of the safety model, and an evaluation result is obtained. The method further includes matching the safety model, wherein at least one parameter of the safety model is matched based at least on the evaluation result and a predetermined criterion. If the evaluation result does not satisfy the predetermined criterion, the matching of the safety model can be performed, for example.

[0005] A second general aspect of this disclosure relates to a method for verifying a computer implementation of a parameterized safety model for a vehicle that is at least partially autonomous, wherein at least one parameter of the safety model has been matched. The method includes evaluating at least one matched parameter of the safety model, wherein a second evaluation result is obtained. The at least one matched parameter may, for example, be matched using a method according to the first general aspect (or an embodiment thereof) for parameterizing a safety model for a vehicle that is at least partially autonomous.

[0006] A third general aspect of this disclosure relates to a computer system designed to implement a computer implementation method for parameterizing a safety model for at least partially autonomous driving, as described in the first general aspect (or its embodiments), and / or a method for verifying the parameterization of a safety model for at least partially autonomous driving, as described in the second general aspect (or its embodiments).

[0007] A fourth aspect of this disclosure relates to a computer program designed to implement a computer implementation method for parameterizing a safety model for at least partially autonomous driving, as described in the first general aspect (or an embodiment thereof), and / or a method for verifying the parameterization of a safety model for at least partially autonomous driving, as described in the second general aspect (or an embodiment thereof).

[0008] The fifth general aspect of this disclosure relates to a computer-readable medium or signal that stores and / or contains a computer program according to the fourth general aspect (or its embodiments).

[0009] The method described in this disclosure according to the first aspect (or its implementation) aims to determine the free parameter values ​​of a safety model (e.g., according to standards) based on driving data. Driving data may, for example, be continuous operational data. The resulting safety model can at least be used as proof of the traffic safety of at least partially autonomous vehicles. Such proof is indispensable for approval arguments.

[0010] The method described in this disclosure according to the second aspect (or its embodiments) is intended to verify, for example, the free parameters found in the method according to the first aspect (or its embodiments). This verification ensures that the values ​​of the free parameters are not arbitrarily determined, but must satisfy at least one predetermined criterion, and the resulting safety model is therefore applicable to demonstrating the traffic safety of vehicles that are at least partially autonomous.

[0011] Therefore, the method according to the first aspect (or its implementation) and the method according to the second aspect (or its implementation) enable the determination of the free parameter values ​​of the safety model in a demonstrably credible manner, particularly enabling explicit assumptions about other traffic participants. This is indispensable for the approval of the demonstration.

[0012] Therefore, one objective of the method according to the first aspect (or its implementation) is to assign appropriate values ​​to the free parameters such that, on the one hand, the free parameters guarantee an acceptable level of safety, and on the other hand, the at least partially autonomous vehicle can move sufficiently progressively in road traffic. The free parameters are calibrated in a data-driven manner. For this purpose, for example, metrics are used to evaluate recorded driving data. This allows, for example, the determination of a histogram, which is now evaluated against a predefined criticality threshold. For example, it can be assessed how many interactions are critical or subcritical. Alternatively or additionally, the determined histogram can be compared with a predefined histogram. Multidimensional optimization ultimately enables the identification of appropriate combinations of parameter values ​​to meet the optimization objective. This method allows for the iterative addition of additional free parameters, for example, by adding additional relevant parameters when expanding the Operational Design Domain (ODD). Therefore, despite the increased number of parameters and the increased amount of data, the optimization problem remains manageable.

[0013] In the verification of the found parameter values ​​according to the method of the second aspect (or its implementation), two tests can be performed, for example. Sensitivity analysis can first check the robustness of the parameter values. Here, robustness means that small changes in parameter values ​​only lead to small changes in the evaluation results. This prevents the selection of parameter values ​​at the "slip point" of the metric from abruptly leading to unsafe situations due to small deviations in actual traffic. Furthermore, the safety module is evaluated, for example, on a second dataset that is unrelated to the first dataset, and the evaluation results are compared. Here, if, for example, the histograms are very different, it indicates that the first dataset does not represent the ODD well enough, and the parameters are therefore over-optimized for a specific situation.

[0014] After successful verification, a complete safety model is obtained. The advantage of this safety model is that it explicitly makes assumptions about the behavior of at least partially autonomous vehicles and other traffic participants, and formalizes "reasonably forseeable behavior" in the sense of standard IEEE 2846. Data-driven verification of the parameter values ​​provides empirical proof that these values ​​enable forward driving in practice. Finally, experts and / or licensing authorities are responsible for judging whether the values ​​are within legally acceptable limits. If these values ​​pass such an evaluation, the method can be used to contribute to the system safety argument according to SOTIF. If these values ​​do not pass such an evaluation, it can be specifically identified which assumptions are untenable, and requirements for at least partially autonomous vehicles can be derived to improve system performance. This method can also be used even when detailing the required system performance later.

[0015] The advantage of this method is that it allows for the incremental specification of one or more parameters of the safety model, thus keeping the optimization problem on which parameter matching is based manageable. For example, within an ODD such as "highway driving," there are different scenarios, such as "driving sequentially in one lane" and "driving side-by-side in multiple lanes." A small number of parameter values, such as braking deceleration and / or acceleration, can now be determined based on the recorded sequential driving. A more complex scenario, "driving side-by-side," can then be added, using the already determined parameter values, and the optimization problem only needs to be set for the newly added parameters, such as lateral acceleration and / or fluctuation ranges. Therefore, it is not necessary to re-optimize the already found parameter values. Furthermore, the optimization problem is kept small. Thus, this method enables the incremental expansion of the ODD without re-optimizing the defined parameters.

[0016] Because the method proposed in this disclosure allows for the advantageous matching of one or more parameters from one market to other markets (e.g., in different regions). Assume that a vehicle capable of at least partially autonomous driving has already been licensed for an ODD in one region. In this case, a safety model with specific parameter values ​​already exists, which has been evaluated on driving data in that region, resulting in a histogram of safety and / or hazard values. If comparable driving data for the same ODD in another region is now available, biases may arise in the evaluation because assumptions, for example, about the behavior of other traffic participants (reaction time, braking behavior, etc.) are no longer valid. This can now be identified, and the parameters can be matched according to the new region. The repeated evaluation should then resemble the original histogram, and approval of vehicles capable of at least partially autonomous driving can be made based on the same reasoning. This has the advantage of faster licensing in new regions and markets.

[0017] Finally, this method has the advantage that system parameters can be included in the optimization even when a pre-given criticality threshold is not met. Therefore, specific parameters of at least partially autonomous vehicles, such as reaction time or braking performance, can be identified that must be improved on the development side to achieve the desired level of safety in addition to system performance. Attached Figure Description

[0018] Figure 1a An exemplary implementation of a method for parameterizing a safety model for a vehicle that is at least partially autonomous is illustrated.

[0019] Figure 1b An exemplary implementation of a computer-based method for parameterizing a safety model for at least partially autonomous driving is illustrated, wherein an evaluation result is first evaluated, and then a safety model is matched based on the evaluation result.

[0020] Figure 1c An exemplary implementation of a computer-based method for parameterizing a safety model for at least partially autonomous driving is illustrated, wherein a distribution is calculated based on multiple metrics, and an evaluation result is evaluated, and a safety model is matched based on the evaluation result.

[0021] Figure 2 An exemplary implementation of a method for verifying a parameterized computer implementation of a safety model for a vehicle that is at least partially autonomous is illustrated.

[0022] Figure 3An exemplary implementation of a computer-based method for parameterizing and validating a safety model for a vehicle that is at least partially autonomous is illustrated. Detailed Implementation

[0023] The methods 100 and 200 presented in this disclosure aim to: how to meaningfully determine and / or verify free—i.e., not pre-given by standards—parameters for autonomous driving of a safety model for at least partially autonomous driving vehicles.

[0024] For example, the starting point is a continuous safety model, which evaluates the safety of a vehicle that is at least partially autonomous at any given time. Such a safety model must make assumptions about various physical parameters, see standard IEEE 2846. These parameters are, for example, divided into three groups. The first group includes one or more system parameters that are vehicle-specific and precisely known to the developers. Examples of such system parameters include brake pressure build-up time or the vehicle's acceleration capability. The second group includes one or more parameters whose values ​​are specified by an existing set of rules or at least can be derived from precedent. For example, a parameter in this group is, for instance, the minimum safe distance in a following situation. The third group includes one or more parameters for which no universally applicable values ​​are specified as criteria. Examples of these "free" parameters include human driver reaction time (to different events), lateral fluctuation range in straight-line driving, and braking deceleration. Methods for assigning values ​​to these free parameters and providing justification in the sense of verification according to SOTIF are unknown. The goal now is to determine meaningful values ​​for such parameters based on driving data (ground truth).

[0025] Therefore, the first step is to disclose a method in Figure 1a The method 100 illustrated in -c for parameterizing a safety model 20 for at least partially autonomous driving vehicles, particularly for highly automated driving vehicles, is described in computer implementation.

[0026] For example Figure 1aAs shown, method 100 includes: applying safety model 20 110, wherein at least one metric is calculated 111 at least at a time point based on driving data 10 and one or more parameters 30 of safety model 20, and an evaluation result is obtained. Driving data may include measured data and / or simulated data. In particular, driving data may include continuous running data, i.e., measured data and / or simulated data for long-term testing. One or more parameters 30 of safety model 20 may be predetermined and, if necessary, selected according to the corresponding driving situation. For example, the safety model is used to evaluate the acquired driving data (ground truth).

[0027] For example Figure 1a As shown, the method 100 further includes matching 120 security models 20, wherein at least one parameter of the security model is matched based on at least the evaluation results and predetermined criteria. In particular, multiple parameters of the security model can be matched here based at least on the evaluation results and predetermined criteria.

[0028] The evaluation results specifically include at least one metric calculated at at least one time point. Therefore, the evaluation results here include at least one metric value. The metric value may be, but does not necessarily have to be, multidimensional.

[0029] For example, a safety model can exist in the form of a continuous metric that covers the subjective and / or objective hazard of the driving situation at each point in time, and optionally also the degree of causation caused by the at least partially autonomous driving of the vehicle. The safety model contains parameters regarding the systemic behavior of the vehicle and the behavior of other road users. Parameters not pre-given by official documents, standards, or legislation can be referred to as free parameters.

[0030] For example Figure 1b As illustrated in -c, matching the security model 20 120 at least based on the evaluation results and predetermined criteria (or method 100) may include evaluating the evaluation results 121 at least based on the predetermined criteria, wherein an evaluation result is obtained. Matching the security model 20 120 at least based on the evaluation results and predetermined criteria may further include matching the security model 20 122 at least based on the evaluation results, wherein at least one parameter of the security model is matched.

[0031] The matching of the security model 120 can be performed, for example, when the evaluation result does not meet a predetermined criterion. Alternatively or additionally, the matching of the security model 120 can be performed, for example, when the evaluation result is negative if necessary. This is in Figure 3 The example provided illustrates this, where “nOK” represents “not OK” and indicates a negative evaluation result.

[0032] In any case, the security model, and in particular at least one parameter of the security model, can be matched 120 such that the evaluation results obtained by reapplying the security model meet predetermined criteria, i.e., leading to a positive evaluation result when necessary. This is in Figure 3 It is also illustrated by way of example that method 100 ends only when the evaluation result is positive (i.e., "OK").

[0033] The predetermined criterion can be designed to match at least one parameter such that the at least one parameter ensures an acceptable level of safety while simultaneously allowing the vehicle to move sufficiently forward in road traffic. In particular, the at least one parameter can be matched such that it is both physically possible and reasonable, and that the violation rate obtained when evaluating the assessment results is sufficiently low.

[0034] A safety model may include code that can be parameterized by one or more parameters, or may be parameterizable code, wherein the code is designed to assess the degree to which the vehicle's driving behavior is safe. This code may be implementable. Applying a safety model may include implementing parameterizable and, in particular, parameterized code.

[0035] At least one parameter of the safety model (of which the safety model is matched) can encode assumptions about the predictable behavior of other traffic participants. For example, at least one parameter 30 may initially be a literature value and / or an empirical value (i.e., prior to matching via method 100). Alternatively or additionally, at least one parameter 30 may initially be estimated. In particular, at least one parameter of the safety model may be a free parameter. The initial necessary assignment of multiple free parameters can be performed using values ​​from the literature, empirical values ​​(best guesses), and / or estimates.

[0036] On the other hand, at least one parameter can also be a vehicle system parameter. This allows for the identification, for example, of vehicle parameters that must be improved to achieve the desired level of safety. For instance, vehicle system parameters can relate to vehicle performance, such as maximum deceleration.

[0037] If multiple parameters of a safety model are matched, it is possible to match not only one or more parameters that encode assumptions about the expected behavior of one or more other traffic participants, but also one or more system parameters of the vehicle.

[0038] At least one metric can be one-dimensional. Alternatively, at least one metric can be multi-dimensional. Instead of a multi-dimensional quantity, multiple one-dimensional quantities can also be computed.

[0039] This metric can also be (quasi)continuous. Here, the metric is calculated at each (discrete) time point based on driving data 10 and one or more parameters.

[0040] For example, at least one metric may include the urgency of the vehicle's driving situation. The urgency may be subjective and / or objective. Where necessary, a multidimensional quantity may include a component corresponding to the (subjective and / or objective) urgency of the vehicle's driving situation. Alternatively or additionally, at least one metric may include the degree of causation of the urgency of the vehicle's driving situation. Where necessary, a multidimensional quantity may include a component (or additional components) corresponding to the degree of causation of the urgency of the vehicle's driving situation.

[0041] like Figure 1c As illustrated in the diagram, when the 110 safety model is applied at multiple points in time, the 112 metric can be calculated based at least on driving data 10 and one or more parameters based on the safety model, resulting in multiple metric values. The metric values ​​can be, but do not necessarily have to be, multidimensional.

[0042] The method 100 may include removing temporal correlations between the 114 or more metrics. This could be done, for example, by removing the temporal information for each metric. Alternatively, metrics could be aggregated to eliminate their temporal correlations. The aggregation of metrics could occur within a fixed time window and / or through interactions with other traffic participants by a vehicle that is at least partially autonomous.

[0043] This method 100 (or as) Figure 1c As illustrated in the diagram, applying the 110 security model may include calculating a distribution 113 based on multiple metrics, particularly an empirical distribution function and / or histogram. The evaluation results may include this distribution.

[0044] Evaluating the 121 assessment results based at least on predetermined criteria may include evaluating the distribution in light of a predetermined criticality threshold 40. Here, for example, the violation rate may be calculated and evaluated as the share of driving situations above the predetermined criticality threshold. Alternatively or additionally, evaluating the 121 assessment results based at least on predetermined criteria may include evaluating the distribution in light of a predetermined reference distribution (e.g., in light of a reference histogram).

[0045] For example, evaluating driving data from at least partially autonomous vehicles can yield a histogram of safety (or criticality) values ​​and a violation rate, i.e., the share of driving situations where the safety level is below a pre-defined threshold (or the criticality level is above a given threshold). Now, by means of, for example, multidimensional, iterative optimization, specified parameter values ​​can be matched such that these values ​​are physically possible and reasonable, and also comply with the pre-defined threshold.

[0046] In addition, disclosures such as Figure 2 The method 200, illustratively illustrated, is for verifying a parameterized computer implementation of a safety model for at least partially autonomous driving vehicles, particularly for highly automated driving vehicles, wherein optionally, at least one parameter of the safety model has been matched. The method 200 includes evaluating 210 at least one matched parameter or multiple matched parameters (or more generally: parameters of the safety model) of the safety model, wherein a second evaluation result is obtained.

[0047] At least one matched parameter may be, but does not necessarily have to be, matched according to method 100, which is used to parameterize a safety model for at least partially autonomous vehicles, particularly highly automated driving vehicles. Therefore, method 200 may be a continuation of method 100. However, on the other hand, method 200 does not necessarily have to be implemented following method 100. For example, at least one parameter of the safety model may have been matched outside of method 100, and then method 200 may be implemented independently of method 100. The initial assignment of one or more parameters may already be a match of one or more parameters, which can be verified by method 200.

[0048] The evaluation of at least one matched parameter (or more generally, the parameters of the safety model) of the safety model can be based on a sensitivity analysis of the safety model in view of the at least one matched parameter. A second evaluation result can be positive at least when the assessment of the safety model changes only slightly with small variations in at least one matched parameter of the safety model. In this case, at least one matched parameter of the safety model is "robust". For example, the found parameter values ​​can be subjected to sensitivity analysis to rule out situations where small deviations from the assumptions result in disproportionately fewer cases being classified as critical. If the sensitivity analysis concludes that one or more matched parameters are not robust to small variations, then either the safety model is unsuitable and / or the developed driving function is not suitable for traffic. In this case, the safety model and / or the developed driving function can be improved.

[0049] Alternatively or additionally, evaluating at least one matched parameter (or more generally, the parameters of the safety model) of safety model 210 may include applying the matched safety model 212 to additional driving data 11, resulting in a further evaluation. The additional driving data may also include measured data and / or simulated data. In particular, the additional driving data may include continuous operating data, i.e., measured data and / or simulated data for long-term testing. The additional driving data 11 must be different from driving data 10, i.e., it must be other driving data. For example, driving data 10 and additional driving data 11 must also include (or contain) the same and / or similar ODD elements. Alternatively or additionally, driving data 10 and additional driving data 11 must also include (or contain) similar and / or the same driving scenarios. The second evaluation result can be, for example, positive, at least when the evaluation result is sufficiently consistent with the additional evaluation result. Based on the additional driving data 11, it can be evaluated whether the safety model and parameters are sufficiently generally effective. For example, this only makes sense for the same Operational Design Domain (ODD), or it does not allow the addition of new ODD elements that the security model cannot yet evaluate.

[0050] If necessary, the evaluation result can be positive, for example, if a small change in at least one matched parameter of the safety model results in only a minor change in the assessment of the safety model, and if the assessment result is sufficiently consistent with other assessment results. Statistical tests can be used in this analysis, for example.

[0051] For example Figure 2 As shown, methods 100 and 200 may include a check 220: whether the second evaluation result is positive or negative. If the second evaluation result is positive, at least one matched parameter (and therefore the safety model) can be considered validated in this respect. Specifically, if the second evaluation result is positive, methods 100 and 200 may include using the safety model as proof in the approval process (Freigabeprozess) of at least partially autonomous vehicles 230. If the second evaluation result is negative, a weakness analysis 240 can be performed, for example. Figure 2 In the middle, weakness analysis 240 can also be performed after the arrow "nOK". If at least one matched parameter of the safety model (and therefore the safety model) can be verified, the safety model can be considered as a contribution to the proof of vehicle traffic safety. If at least one matched parameter of the safety model (and therefore the safety model) cannot be verified, the safety model and / or the vehicle must be changed (improved).

[0052] If the second evaluation result is positive, then methods 100 and 200 can output: at least one matched parameter (or multiple matched parameters) of the security model can be verified. Alternatively or additionally, if the second evaluation result is negative, then methods 100 and 200 can output: at least one matched parameter (or multiple matched parameters) of the security model cannot be verified.

[0053] Figure 3 An embodiment is shown in which method 200 is executed following method 100. First, in method 100, driving data 10, a safety model 20, and initial parameter values ​​30 of the safety model are provided to method 100. With the initial assignment of the parameter values, the safety model 20 can be implemented on the driving data 10. Here, multiple metrics 111, 112 can be calculated, for example, considering the urgency and / or causal relationship of the driving situation. In step 114, the temporal correlation between the metrics can be eliminated. For example, these metrics can represent evaluation results, which can be evaluated in step 121. For this purpose, a distribution can be calculated based on multiple metrics, which is then evaluated based on a predetermined urgency threshold 40 and / or a predetermined reference distribution 41, also provided to method 100. A quality function can also be used for this purpose. For example, the violation rate can be calculated and evaluated as the share of driving situations above the predetermined urgency threshold, where the quality is sufficiently high if the violation rate is sufficiently low. If sufficient quality is not yet achieved, at least one parameter of safety models 120 and 122 can be matched, meaning one or more parameter values ​​of the safety model can be optimized. If sufficient quality is achieved, the parameters of the safety model can be validated. This can include sensitivity analysis 211 and / or applying the matched safety model 212 to additional driving data 11 provided to method 200, yielding additional evaluation results. If sensitivity analysis 211 concludes that the (matched) parameters are sufficiently robust, a positive second evaluation result can be output or supported. Otherwise, a negative second evaluation result can be output. If the evaluation result is sufficiently consistent with the additional evaluation result, a positive second evaluation result can be output or supported. Otherwise, a negative second evaluation result can also be output. In step 220, it can now be checked whether the second evaluation result is positive. In this case, the safety model can be used as evidence in at least part of the vehicle approval process. If the second evaluation result is negative, weakness analysis 240 can be performed, for example. Here, for example, the safety model and / or the developed driving functions must be improved.

[0054] Furthermore, a computer system is disclosed, designed to implement a method 100 for parameterizing a safety model for at least partially autonomous vehicles, particularly for highly automated driving vehicles. Alternatively or additionally, the computer system may be designed to implement a method 200 for verifying the parameterization of a computer implementation of a safety model for at least partially autonomous vehicles, particularly for highly automated driving vehicles. In particular, the computer system may be designed to implement method 100 for parameterizing a safety model for at least partially autonomous vehicles (e.g., for highly automated driving vehicles) and—for example, subsequently—implement method 200 for verifying the parameterization of a safety model for at least partially autonomous vehicles (e.g., for highly automated driving vehicles). The computer system may include a processor and / or working memory.

[0055] Furthermore, a computer program is disclosed, designed to implement a method 100 for parameterizing a safety model for at least partially autonomous vehicles, particularly for highly automated driving vehicles. Alternatively or additionally, the computer program may be designed to implement a method 200 for verifying the parameterization of a computer implementation of a safety model for at least partially autonomous vehicles, particularly for highly automated driving vehicles. In particular, the computer program may be designed to implement method 100 for parameterizing a safety model for at least partially autonomous vehicles (e.g., for highly automated driving vehicles) and—for example, subsequently—implement method 200 for verifying the parameterization of a safety model for at least partially autonomous vehicles (e.g., for highly automated driving vehicles). The computer program may exist, for example, in an interpretable form or in a compiled form. The computer program may (also in part) be loaded into the computer's RAM for execution, for example, as a sequence of bits or bytes.

[0056] Furthermore, a computer-readable medium or signal storing and / or containing a computer program is disclosed. This medium may include, for example, one of RAM, ROM, EPROM, HDD, SSD, etc., on or within which the signal is stored.

Claims

1. A computer-implemented method (100) for parameterizing a safety model (20) of a vehicle for at least partially autonomous driving, the method comprising: - Apply (110) the safety model (20), wherein at least one metric is calculated (111) at least at a time point based on driving data (10) and one or more parameters based on the safety model (20), and an evaluation result is obtained; - Match (120) the security model (20), wherein at least one parameter of the security model is matched based on the evaluation results and predetermined criteria; Optionally, if the evaluation result does not meet the predetermined criterion, the security model is matched (120).

2. The method (100) according to claim 1, wherein matching (120) the security model (20) based at least on the evaluation result and the predetermined criterion comprises: - The evaluation result (121) is evaluated at least based on the predetermined criterion, wherein the evaluation result is obtained; - At least based on the evaluation results, match (122) the security model (20).

3. The method (100) according to claim 1 or 2, wherein at least one parameter of the security model is matched (120) such that the evaluation result obtained by reapplying the security model satisfies the predetermined criterion.

4. The method (100) according to any one of the preceding claims, wherein the safety model includes code that can be parameterized by the one or more parameters, the code being designed to assess the degree to which the driving behavior of the vehicle is safe.

5. The method (100) according to any one of the preceding claims, wherein at least one parameter of the safety model encodes assumptions about the expected behavior of other traffic participants.

6. The method (100) according to any one of the preceding claims, wherein the at least one metric includes the degree of causation of the driving situation of the vehicle and / or the driving situation of the vehicle.

7. The method (100) according to any one of the preceding claims, wherein when the safety model (110) is applied at multiple time points, the metric (112) is calculated at least based on the driving data (10) and one or more parameters based on the safety model, wherein multiple metric values ​​are obtained.

8. The method (100) according to claim 7, comprising: - Calculate the distribution based on the multiple metrics (113); The evaluation results (121) based at least on the predetermined criterion include: evaluating the distribution in view of a predetermined critical threshold (40), optionally wherein the violation rate is calculated and evaluated as the share of driving situations above the predetermined critical threshold, and / or wherein the evaluation results (121) based at least on the predetermined criterion include: evaluating the distribution in view of a predetermined reference distribution (41).

9. A method (200) for verifying a computer implementation of a parameterization of a safety model for at least partially autonomous driving of a vehicle, wherein at least one parameter of the safety model has been matched, the method comprising: - Evaluate at least one matched parameter of the security model described in (210), wherein a second evaluation result is obtained; Optionally, the at least one matched parameter has been matched (120) according to a computer-implemented method for parameterizing a safety model for at least partially autonomous driving vehicles, as described in any of the preceding claims.

10. The method (100, 200) according to claim 9, wherein the evaluation (210) of at least one matched parameter of the security model is based on a sensitivity analysis (211) of the security model in view of the at least one matched parameter, and the second evaluation result is positive at least when the evaluation of the security model changes only slightly in the event of a small change in the at least one matched parameter of the security model.

11. The method (100, 200) according to claim 9 or 10, wherein evaluating (210) at least one matched parameter of the safety model comprises applying (212) the matched safety model to additional driving data (11), wherein additional evaluation results are obtained, and the second evaluation result is positive at least when the evaluation results are sufficiently consistent with the additional evaluation results.

12. The method (100, 200) according to any one of claims 9 to 11, comprising: - Check (220) whether the second evaluation result is positive or negative; - If the second evaluation result is positive, the safety model described in (230) shall be used as proof in the approval process for vehicles that are at least partially autonomous.

13. A computer system designed for: - Implement the computer-implemented method (100) for parameterizing a safety model for at least partially autonomous driving of a vehicle according to any one of claims 1 to 8, and / or - Implement a computer implementation of a parameterization of a safety model for a vehicle used for at least partially autonomous driving, according to any one of claims 9 to 12 (200).

14. A computer program designed to perform: - A computer-implemented method (100) for parameterizing a safety model for at least partially autonomous driving of a vehicle, according to any one of claims 1 to 8; and / or - A method (200) for verifying a computer implementation of a parameterization of a safety model for a vehicle used for at least partially autonomous driving, according to any one of claims 9 to 12.

15. A computer-readable medium or signal that stores and / or contains a computer program according to claim 14.