An emergency control method, system and device for autonomous driving

By generating dynamic emergency strategies through real-time data collection and multi-sensor fusion technology, the problem of fixed emergency response plans in existing technologies has been solved, enabling new energy vehicles to handle malfunctions smoothly and safely, and improving the safety and adaptability of autonomous driving.

CN122275944APending Publication Date: 2026-06-26DONGFENG MOTOR GRP
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
DONGFENG MOTOR GRP
Filing Date
2026-04-14
Publication Date
2026-06-26

AI Technical Summary

Technical Problem

Existing emergency response solutions for autonomous driving lack dynamic adjustment capabilities and cannot adapt to the characteristics of new energy vehicles, resulting in delayed or excessive responses and making it difficult to achieve smooth and safe emergency handling.

Method used

By collecting vehicle status and environmental data in real time, dynamic emergency strategies are generated by combining fault levels and environmental parameters. Multi-sensor data fusion technology is used to obtain comprehensive environmental parameters, and the driver's response status is monitored in real time to adjust the emergency response strategy.

Benefits of technology

It enables dynamic adjustment of emergency measures, improves the safety and efficiency of emergency response, reduces the risk of secondary accidents, and enhances driving comfort and system adaptability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122275944A_ABST
    Figure CN122275944A_ABST
Patent Text Reader

Abstract

This application relates to the field of autonomous driving technology and discloses an emergency control method, system, and device for autonomous driving. The method includes: real-time collection of vehicle operating status information, determination of fault type, and assessment of fault level; collection and fusion of environmental data using multiple sensors to obtain comprehensive environmental parameters; generation of an emergency response strategy based on the fault type, level, and comprehensive environmental parameters; control of the vehicle according to the strategy and issuance of a warning to the driver; monitoring of vehicle status and driver response status, and adjusting the emergency response strategy accordingly. This application overcomes the shortcomings of fixed strategies in existing technologies by combining fault level and comprehensive environmental parameters to generate a strategy, enabling emergency measures to be dynamically adjusted according to road conditions and fault severity. Furthermore, by real-time monitoring of driver response and adjustment of the strategy, a human-machine collaborative safety redundancy is formed, effectively avoiding secondary accidents caused by driver failure to take over in time or deterioration of vehicle status, significantly improving the safety of autonomous driving.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of autonomous driving technology, specifically to an emergency control method, emergency control system, and device for autonomous driving. Background Technology

[0002] With the rapid development of the new energy vehicle industry and the increasing popularity of autonomous driving technology, vehicle safety during operation, especially the ability to handle emergencies, has become a key indicator for evaluating the performance of intelligent connected vehicles. In autonomous driving mode, the vehicle control system is highly complex. If hardware failure or software anomaly occurs and appropriate emergency measures are not taken in a timely manner, the vehicle can easily lose control. Currently, new energy vehicles are typically equipped with basic fault diagnosis systems that can trigger alarms or execute preset deceleration and stopping procedures when abnormal signals are detected, thus providing basic fault protection.

[0003] However, existing emergency response solutions for autonomous driving still have significant limitations in practical applications. On the one hand, the response strategies are relatively rigid, relying heavily on manual driver intervention or a single emergency braking mode, lacking the ability to dynamically adjust based on the severity of the fault and surrounding environmental information, resulting in delayed response or overreaction. On the other hand, existing systems often have vague assessments of fault levels, lack quantitative models, and do not fully consider environmental differences such as road type and traffic flow, making it difficult to adapt to the response characteristics of electric motors and the safety requirements of batteries in new energy vehicles.

[0004] The aforementioned deficiencies make it difficult for vehicles to achieve smooth, safe, and efficient emergency response when faced with sudden malfunctions. This not only reduces driving comfort but also increases the risk of secondary accidents, failing to meet the stringent safety requirements of high-level autonomous driving. Therefore, how to construct an emergency response system and method for sudden malfunctions in autonomous driving that is adapted to the characteristics of new energy vehicles has become an urgent technical problem to be solved. Summary of the Invention

[0005] Among the relevant technologies, emergency response solutions for autonomous driving are difficult to adapt to the characteristics of new energy vehicles and achieve stable and safe emergency response due to rigid handling strategies, lack of quantitative assessment of fault levels, and failure to dynamically adjust in conjunction with environmental information.

[0006] In a first aspect, embodiments of this application provide an emergency control method for autonomous driving, the emergency control method comprising: Real-time collection of vehicle operating status information, and determination of fault type and assessment of fault level based on the operating status information; Multiple sensors are used to collect environmental data around the vehicle in real time, and the environmental data collected by each sensor is fused to obtain comprehensive environmental parameters. Generate corresponding emergency response strategies based on fault type, fault level, and comprehensive environmental parameters; The vehicle was brought under control according to the emergency response strategy, and corresponding warning messages were issued to the driver. Monitor vehicle status and driver response status, and adjust emergency response strategies accordingly.

[0007] In conjunction with the first aspect, in one implementation, the step of fusing environmental data collected by various sensors to obtain comprehensive environmental parameters includes: The confidence level of each sensor data is determined based on the weather and vehicle driving environment type in the environmental data, and the fusion weight of each sensor is determined based on the confidence level. Data from each sensor is fused based on the fusion weights of each sensor to obtain comprehensive environmental parameters.

[0008] In conjunction with the first aspect, in one implementation, determining the fusion weights for each sensor based on confidence levels includes: According to the formula:

[0009] Calculate the first Fusion weights of various sensor data In the formula, Indicates the first The confidence level of this sensor in the current environment. This indicates the total number of sensors participating in the fusion.

[0010] In conjunction with the first aspect, in one embodiment, the method of using multiple sensors to collect environmental data around the vehicle in real time includes: using an onboard camera, millimeter-wave radar, lidar, and positioning device to collect environmental information about the vehicle.

[0011] In conjunction with the first aspect, in one implementation, determining the fault type and assessing the fault level based on the operating status information includes: Determine the current fault type of the vehicle based on the operating status information; Based on the current fault type, obtain the probability of impacting vehicle driving safety and the degree of functional failure caused by the fault; The fault level of the current fault type is assessed based on the probability of affecting vehicle driving safety and the degree of functional failure caused by the fault.

[0012] In conjunction with the first aspect, in one implementation, generating a corresponding emergency response strategy based on the fault type, fault level, and comprehensive environmental parameters includes: Generate an initial emergency strategy based on the fault type and fault level; The complexity of the current environment is analyzed based on comprehensive environmental parameters, and the initial emergency strategy is adjusted accordingly to obtain an emergency response strategy.

[0013] In conjunction with the first aspect, in one implementation, adjusting the initial emergency strategy based on the complexity of the current environment to obtain an emergency response strategy includes: If the fault level is not higher than the preset threshold and the complexity of the surrounding environment is lower than the preset value, a strategy to prompt the driver to take over the vehicle will be generated. If the fault level is higher than the preset threshold or the complexity of the surrounding environment is higher than the preset value, a strategy will be generated to automatically decelerate the vehicle, turn on the hazard warning lights, and stop in the emergency lane or a safe area.

[0014] In conjunction with the first aspect, in one implementation, after adjusting the emergency response strategy according to the vehicle status and driver response status, the method further includes: recording and saving the fault information after the vehicle is in a safe state, and uploading it to a remote platform according to the importance of the information.

[0015] Secondly, embodiments of this application provide an emergency control system for autonomous driving, comprising: The fault monitoring module is used to collect vehicle operating status information in real time, and to determine the fault type and assess the fault level based on the operating status information. The environmental perception module is used to collect environmental data around the vehicle in real time using multiple sensors, and to fuse the environmental data collected by each sensor to obtain comprehensive environmental parameters. The emergency decision-making module is used to generate corresponding emergency response strategies based on the fault type, fault level, and comprehensive environmental parameters. The vehicle control module is used to control the vehicle according to the emergency response strategy; The human-machine interaction module is used to issue corresponding warning information to the driver. The human-machine interaction module is also used to monitor the vehicle status and the driver's response status, and adjust the emergency response strategy according to the vehicle status and the driver's response status.

[0016] Thirdly, embodiments of this application provide an emergency control device for autonomous driving, the emergency control device for autonomous driving including a processor, a memory, and an emergency control program for autonomous driving stored in the memory and executable by the processor, wherein when the emergency control program for autonomous driving is executed by the processor, it implements the steps of the emergency control method for autonomous driving as described in any of the above claims.

[0017] The beneficial effects of the technical solutions provided in this application include: This application overcomes the shortcomings of fixed strategies in existing technologies by combining fault levels with comprehensive environmental parameters to generate strategies, enabling emergency measures to be dynamically adjusted according to road conditions and fault severity. Furthermore, by monitoring driver response in real time and adjusting strategies accordingly, a human-machine collaborative safety redundancy is formed, avoiding secondary accidents caused by driver failure to take over in time or deterioration of vehicle condition. Attached Figure Description

[0018] Figure 1 This is a detailed flowchart illustrating an embodiment of the emergency control method of this application; Figure 2 This is a diagram illustrating the architecture of the emergency control system in this application. Figure 3 This is a flowchart illustrating the emergency control method of this application; Figure 4 This is a schematic diagram of the hardware structure of the emergency control equipment involved in the embodiments of this application. Detailed Implementation

[0019] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present application.

[0020] Among the relevant technologies, emergency response solutions for autonomous driving are difficult to adapt to the characteristics of new energy vehicles and achieve stable and safe emergency response due to rigid handling strategies, lack of quantitative assessment of fault levels, and failure to dynamically adjust in conjunction with environmental information.

[0021] In a first aspect, embodiments of this application provide an emergency control method for autonomous driving, the emergency control method comprising: Step S1: Collect vehicle operating status information in real time, and determine the fault type and assess the fault level based on the operating status information.

[0022] Specifically, step S1 includes: Step S1a: Collect hardware operating parameters and software operating status data of the autonomous driving system.

[0023] Specifically, the fault detection sensor unit is deployed in key parts of the vehicle's autonomous driving system, including but not limited to the autonomous driving controller, sensor interface, actuator drive circuit, etc., to continuously collect hardware operating parameters (such as processor temperature, memory usage, sensor power supply voltage, etc.) and software operating status data (such as algorithm iteration cycle, data transmission delay, decision output frequency, etc.).

[0024] Furthermore, after collecting hardware operating parameters and software operating status data, data preprocessing is required, including outlier removal, data smoothing, and standardization.

[0025] Step S1b: Determine the fault type and assess the fault level based on the operating status information.

[0026] Specifically, step S1b includes: Step A: Determine the current fault type of the vehicle based on the operating status information.

[0027] It is worth noting that the current fault type judgment rules cover common fault modes, such as sensor data loss, communication interruption, abnormal algorithm exit, and actuator unresponsiveness.

[0028] Step B: Based on the current fault type, obtain the probability of affecting vehicle driving safety and the degree of functional failure caused by the fault.

[0029] Step C: Assess the fault level of the current fault type based on the probability of affecting vehicle driving safety and the degree of functional failure caused by the fault.

[0030] Specifically, the fault level is calculated using the following formula to achieve a quantitative assessment of the fault level:

[0031] In the formula, This indicates the fault level, with a value ranging from 0 to 10. The higher the value, the more serious the threat the fault poses to vehicle driving safety. This represents the probability that a malfunction will affect the vehicle's driving safety, and its value ranges from 0 to 1. This indicates the degree of functional failure caused by the fault, with a value ranging from 0 to 1. and Let be the weighting coefficient, satisfying ,in The value range is 0.6-0.8. The value range is 0.2-0.4.

[0032] In some specific embodiments, sensor data drift faults The value can be 0.7, while the screen display malfunction... The value can be 0.2; while completely losing steering control The value is 1.0, and only a non-critical sensor has failed. The value can be 0.3. Furthermore, The value is 0.7. The value is 0.3 because in autonomous driving safety assessments, the probability of a malfunction usually has a slightly greater impact on safety than the degree of functional failure.

[0033] It is worth noting that the formula in step C above transforms the qualitative description of the fault into a quantitative level assessment, providing a clear quantitative basis for the formulation of subsequent emergency strategies.

[0034] This application provides a specific embodiment in which, when the system detects that the lidar data is completely lost, The value is 0.8 (high security risk probability). A value of 0.9 (severe functional failure) can be used to calculate the fault level using a formula. Due to the fault level The value of is in the range of 0-10, therefore a linear mapping is performed in actual calculations to obtain . This is classified as a severe fault.

[0035] Step S2: Use multiple sensors to collect environmental data around the vehicle in real time, and fuse the environmental data collected by each sensor to obtain comprehensive environmental parameters.

[0036] Specifically, step S2 includes: Step S2a: Collect vehicle environmental information using vehicle-mounted cameras, millimeter-wave radar, lidar, and positioning devices.

[0037] Optionally, the positioning device may be a combination of GNSS and IMU positioning.

[0038] Specifically, vehicle-mounted cameras are mainly used to identify visual information such as traffic lights, lane lines, traffic signs, and pedestrians; millimeter-wave radar has strong adaptability to adverse weather conditions and is mainly used to detect the speed and distance of vehicles and obstacles at a distance; lidar can generate high-precision three-dimensional point clouds, providing accurate three-dimensional structures of the surrounding environment; and high-precision positioning units are used to determine the precise position of the vehicle in a high-precision map, with an error controllable within 0.5 meters.

[0039] Understandably, cameras provide texture and color information, radar provides distance and speed information, and positioning devices provide absolute position information; the combination of multiple sensors eliminates the blind spots of a single sensor. The complementarity of multi-source heterogeneous data can construct more accurate 3D environment models, providing high-precision data support for path planning and obstacle avoidance in emergency strategies.

[0040] Step S2b: Determine the confidence level of each sensor data based on the weather and vehicle driving environment types in the environmental data, and determine the fusion weight of each sensor based on the confidence level.

[0041] Understandably, a higher confidence level indicates that the sensor's data is more reliable in the current environment. For example, in a clear, unobstructed environment, the confidence level of the camera... The value might be 0.9, while its confidence level is lower during heavy rain. The value may drop to 0.3.

[0042] Step S2c: Based on the fusion weights of each sensor, the data from each sensor are fused to obtain comprehensive environmental parameters.

[0043] Specifically, according to the formula:

[0044] Calculate the first Fusion weights of various sensor data In the formula, Indicates the first The confidence level of this sensor in the current environment. This indicates the total number of sensors participating in the fusion.

[0045] Furthermore, if vehicle-mounted cameras, millimeter-wave radar, lidar, and positioning devices are used to collect vehicle environmental information, then n=4 (i.e., cameras, millimeter-wave radar, lidar, and positioning devices). It is understandable that the above step S2c uses weighted fusion technology, which can dynamically allocate weights according to the performance of different sensors in the current environment, so as to ensure that the fusion result is closer to the real environment.

[0046] In some specific embodiments, in foggy weather, the lidar's... millimeter-wave radar The camera High-precision positioning Then the sum of the total confidence levels is Therefore, the fusion weight of lidar millimeter-wave radar The camera Weight of positioning device .

[0047] It is worth noting that this weighting allocation allows lidar and high-precision positioning data, which perform better in foggy weather, to occupy a larger proportion in environmental modeling, thereby improving the accuracy of environmental perception.

[0048] In some preferred embodiments, based on the fused sensor data, the environmental perception module constructs a three-dimensional environmental model within a 50-meter radius around the vehicle. This model includes road boundaries, lane line positions, the positions and speeds of surrounding vehicles, and the positions of pedestrians and other obstacles, and is updated at a frequency of 10Hz to ensure that the emergency decision-making module can obtain real-time environmental information.

[0049] Step S3: Generate corresponding emergency response strategies based on the fault type, fault level, and comprehensive environmental parameters.

[0050] The above step S3 specifically includes: Step S3a: Generate an initial emergency strategy based on the fault type and fault level.

[0051] In some embodiments, the initial emergency strategy includes: for a serious fault of "brake actuator failure" and L=8.7, the initial preset plan may be "immediately turn on the hazard warning lights, gradually decelerate to 20km / h, and plan to stop in the nearest emergency lane".

[0052] It should be noted that the initial handling strategies are extracted from a pre-established emergency strategy database under different combinations of fault types (such as sensor faults, computing unit faults, actuator faults, etc.), different fault levels (0-10 levels), and different environmental conditions (such as highways, urban roads, congested road sections, open road sections, etc.).

[0053] Step S3b: Analyze the complexity of the current environment based on comprehensive environmental parameters, and adjust the initial emergency strategy according to the complexity of the current environment to obtain an emergency response strategy.

[0054] Understandably, incorporating environmental complexity into strategy generation allows the same fault to trigger different handling solutions under different road conditions (such as highways vs. residential roads), significantly improving the system's adaptability to different scenarios. First, a baseline solution is determined based on the fault, and then fine-tuned based on the environment. This approach ensures the basic principles of fault handling while also taking into account the specificities of the external environment, reducing the risk of decision-making conflicts.

[0055] Step S3b specifically includes: Step A: Assess the current environmental complexity based on the 3D environment model and determine the environmental complexity score. .

[0056] Step B: In practical applications, the preset scheme needs to be dynamically adjusted according to the actual situation. The adjustment coefficient is calculated using the following formula:

[0057] In the formula, Indicates the strategy adjustment coefficient; The environmental complexity factor ranges from 0.1 to 0.5. In this embodiment... ; This represents an environmental complexity score, ranging from 0 to 10. A higher score indicates a more complex environment. For example, the environmental complexity of a highway emergency lane... The value could be 2, while at urban intersections during peak hours... The value may be 9. If the current environment is during peak hours on a main urban road (…), Then the adjustment coefficient At this time, the original deceleration time will be shortened, and the steering action will be more cautious to avoid affecting other vehicles.

[0058] Understandably, the aforementioned strategy adjustment coefficients allow the system to modify the preset emergency strategy based on the complexity of the environment, making the emergency response more closely aligned with the actual scenario. The final generated emergency response strategy includes specific control parameters, such as target vehicle speed, deceleration acceleration, steering angle, and stopping position.

[0059] In one specific embodiment of this application: the initial emergency strategy for severe faults ( The proposed strategy is to reduce the vehicle speed to 30 km / h within 10 seconds. The specific modified strategy is as follows: Scenario 1: If the fault level is not higher than the preset threshold (e.g., fault level) If the fault is minor and the complexity of the surrounding environment is lower than the preset value (e.g., few vehicles and empty roads), a strategy will be generated to prompt the driver to take over the vehicle. Scenario 2: If the fault level is higher than the preset threshold (e.g., fault level...) If the fault is classified as moderate to severe or the complexity of the surrounding environment is higher than the preset value (such as heavy traffic or narrow roads), a strategy will be generated to automatically decelerate the vehicle, turn on the hazard warning lights, and stop in the emergency lane or a safe area.

[0060] Furthermore, when generating an automatic deceleration strategy, the acceleration for automatic deceleration is calculated using the following formula:

[0061] In the formula, Expresses deceleration and acceleration (unit: (take positive values). This represents the safety factor, which ranges from 1.2 to 1.5. In this embodiment... This is used to deal with possible emergencies; Indicates the vehicle's current speed (unit: ); Indicates the safe distance from obstacles ahead (unit: The above environmental parameters are derived from the comprehensive environmental information provided in the preceding steps.

[0062] In the specific embodiment of the above deceleration control, if the vehicle's current speed (72km / h) Safe distance from the obstacle ahead Then deceleration This acceleration ensures that the vehicle can decelerate to a safe speed within 50 meters without losing control due to excessive deceleration.

[0063] Step S4: Take control of the vehicle according to the emergency response strategy and issue corresponding warning information to the driver.

[0064] In some implementations, after an emergency response strategy is generated, it is immediately translated into specific control commands to control the vehicle's power system, braking system, and steering system.

[0065] Specifically, based on the deceleration and acceleration in the strategy It sends a braking command to the braking system and a power cut-off command to the power system, causing the vehicle to decelerate at a predetermined acceleration. Based on the steering angle in the strategy, it sends a steering command to the steering system, causing the vehicle to gradually move towards the emergency lane.

[0066] Furthermore, while controlling the vehicle, the human-machine interaction module initiates a driver warning process, sending warning information to the driver through various means such as vision, hearing, and touch.

[0067] In some alternative implementations, the warning intensity is determined by the following formula:

[0068] In the formula, I represents the warning intensity, which ranges from 0 to 10. The larger the value, the stronger the warning. This indicates the weight of the fault level's impact, with a value ranging from 0.5 to 0.7. In this embodiment... 0.6; L is the fault level (0-10) defined above; T represents the estimated time required for driver takeover (unit: s, value range: 0-10).

[0069] It should be noted that the T-value is determined based on driver status monitoring (such as eye tracking, steering wheel touch sensing, etc.). If the driver is detected looking at the road ahead, the T-value may be 3; if the driver is detected looking at a mobile phone, the T-value may be 8.

[0070] It is worth noting that the above optional implementation method can dynamically adjust the warning intensity according to the severity of the fault and the urgency of the driver taking over, ensuring that the driver can perceive and respond to the fault situation in a timely manner.

[0071] For example, in one specific embodiment, for a serious fault with L=8.7, if the driver is looking at a mobile phone (T=8), the warning intensity is... This is a high-intensity warning. At this time, the system will simultaneously activate visual (flashing red fault icon and text prompt on the display), audible (high-frequency alarm sound + voice "Emergency fault, please take over the vehicle immediately!"), and tactile (violent steering wheel vibration + continuous seat vibration) warning methods; if the driver is looking ahead (T=3), then... This is a medium-to-high intensity warning, which may only activate visual and auditory warnings, while the intensity of tactile warnings is reduced.

[0072] Step S5: Monitor the vehicle status and driver response status, and adjust the emergency response strategy according to the vehicle status and driver response status.

[0073] Specifically, during the execution of emergency response strategies by the vehicle, the system continuously monitors the vehicle's status (such as speed, acceleration, and position) and the driver's response (such as whether the driver touches the steering wheel, presses the brake pedal, or the accelerator pedal), and dynamically adjusts the emergency response strategies based on the monitoring results.

[0074] Preferably, if the system detects that the driver is beginning to take over vehicle control, the control authority of the autonomous driving system is gradually reduced.

[0075] Specifically, the methods for monitoring driver response include: detecting whether the driver applies steering force using a steering wheel torque sensor, detecting whether the driver presses the brake or accelerator pedal using a pedal displacement sensor, and detecting whether the driver is looking ahead using a camera. When the system detects that the driver begins to take over the vehicle (such as applying steering force or pressing the pedal), the system gradually reduces the control authority of the autonomous driving system. The authority decay is calculated using the following formula:

[0076] In the formula, R represents the autonomous driving control authority at time t, with a value range of 0-1, where 1 represents full control and 0 represents complete release; Indicates initial control permissions, with a value of 1; This represents the attenuation coefficient, with a value ranging from 0.1 to 0.3. In this embodiment... =0.2; t represents the time after the driver takes over (unit: s).

[0077] It is worth noting that by gradually adjusting control permissions as described above, a smooth transition of autonomous driving permissions can be achieved, avoiding sudden changes in vehicle control that could lead to danger.

[0078] In one specific embodiment, when the driver takes over the vehicle at time t=0, the control authority at time t=1s... This means the system still retains 81.9% control; at t=3s, The system and the driver each control approximately half of the permissions; at t=10s, The system retains only 13.5% control permissions; at t=20s, The system essentially releases control completely, allowing the driver to take full control.

[0079] It should be noted that throughout the process, the system continuously assesses whether the vehicle is in a safe state (e.g., the vehicle has come to a complete stop in the emergency lane, hazard warning lights are on, and a safe distance is maintained from other vehicles). If the vehicle is in a safe state, the emergency response process ends; if the vehicle is not in a safe state, the emergency strategy continues to be adjusted until the vehicle is safe.

[0080] Step S6: Record and upload fault information.

[0081] Step S6 specifically includes: Step S6a: Once the vehicle is in a safe state, the system automatically initiates the fault information recording process. The recorded information includes: fault occurrence time (accurate to milliseconds), fault type, fault level, vehicle speed and location at the time of the fault, specific details of the emergency response strategy, changes in vehicle status during the emergency response process, and driver response status.

[0082] Furthermore, this information is first stored in the vehicle's onboard storage unit (such as a solid-state drive), and then selectively uploaded to the remote monitoring platform based on the importance of the information. The storage priority of the information is calculated using the following formula:

[0083] In the formula, P_s represents the information storage priority, with a value range of 0-10, and the larger the value, the higher the priority; This indicates the weight of the fault level's impact, with a value ranging from 0.7 to 0.9. In this embodiment... =0.8; L is the fault level (0-10) defined above; F represents the rarity of the fault, with a value range of 0-10. The larger the value, the rarer the fault. This value is determined based on the statistics of the historical fault database. For example, the common sensor data drift fault has F=2, while the rare controller chip damage fault has F=9.

[0084] Understandably, the aforementioned priority quantification can be used to determine the storage and uploading priorities of different fault information, ensuring that important information is saved and uploaded first, and providing data support for subsequent fault analysis and system optimization.

[0085] In one specific embodiment of this application, for rare severe faults where L=8.7 and F=9, the storage priority is... For high-priority faults, all information about the fault will be fully stored and immediately uploaded to the remote platform; for common minor faults with L=2 and F=3, This is a low-priority item, and its information is only stored in the vehicle unit and uploaded when the vehicle enters maintenance mode.

[0086] Secondly, embodiments of this application also provide an emergency control system for autonomous driving, comprising: a fault monitoring module, an environmental perception module, an emergency decision-making module, a vehicle control module, and a human-machine interaction module; wherein, The system comprises the following modules: a fault monitoring module, which collects real-time vehicle operating status information and determines the fault type and severity based on this information; an environmental perception module, which uses multiple sensors to collect real-time environmental data around the vehicle and fuses the data to obtain comprehensive environmental parameters; an emergency decision-making module, which generates corresponding emergency response strategies based on the fault type, fault severity, and comprehensive environmental parameters; a vehicle control module, which controls the vehicle according to the emergency response strategies; and a human-machine interaction module, which issues corresponding warning messages to the driver, monitors vehicle status and driver response status, and adjusts the emergency response strategies accordingly.

[0087] In some optional implementations, to achieve a quantitative assessment of the fault level, the fault monitoring module uses the following formula to calculate the fault level:

[0088] In the formula, This indicates the fault level, with a value ranging from 0 to 10. The higher the value, the more serious the threat the fault poses to vehicle driving safety. This represents the probability that a malfunction will affect the vehicle's driving safety, and its value ranges from 0 to 1. This indicates the degree of functional failure caused by the fault, with a value ranging from 0 to 1. and Let be the weighting coefficient, satisfying .

[0089] Understandably, in autonomous driving safety assessments, the probability of a malfunction typically has a slightly greater impact on safety than the degree of functional failure. Therefore, The value range is 0.6-0.8. The value range is 0.2-0.4. In the above implementation method, the qualitative fault description is transformed into a quantitative level assessment, providing a clear quantitative basis for the formulation of subsequent emergency strategies.

[0090] In some alternative implementations, the environmental perception module integrates multiple sensors such as vehicle-mounted cameras, millimeter-wave radar, lidar, and high-precision positioning units (such as GNSS+IMU combined positioning).

[0091] Understandably, vehicle cameras are mainly used to identify visual information such as traffic lights, lane lines, traffic signs, and pedestrians; millimeter-wave radar has strong adaptability to adverse weather conditions and is mainly used to detect the speed and distance of vehicles and obstacles at a distance; lidar can generate high-precision three-dimensional point clouds, providing accurate three-dimensional structure of the surrounding environment; and high-precision positioning units are used to determine the precise position of the vehicle in a high-precision map, with an error controllable within 0.5 meters.

[0092] Preferably, to improve the accuracy and reliability of environmental perception, the environmental perception module adopts multi-sensor data fusion technology, and the fusion weight of different sensor data is calculated by the following formula:

[0093] In the formula, Indicates the first The fusion weights of various sensor data; Indicates the first The confidence level of a sensor under the current environment, ranging from 0 to 1. A higher value indicates that the sensor's data is more reliable under the current environment. For example, in a clear, unobstructed environment, the confidence level of a camera... The value may be 0.9, but under heavy rain conditions... The value may drop to 0.3; This represents the total number of sensors participating in the fusion, in this embodiment. (i.e., cameras, millimeter-wave radar, lidar, and high-precision positioning units).

[0094] It is understandable that by calculating fusion weights, the performance of different sensors in the current environment can be dynamically assigned weights to ensure that the fusion result is closer to the real environment.

[0095] In some preferred embodiments, the module has a built-in emergency strategy database, which stores a large number of preset emergency response plans. These plans are based on a large number of traffic accident cases, simulation test data and expert experience, and cover response strategies under different fault types (such as sensor faults, computing unit faults, actuator faults, etc.), different fault levels (0-10 levels) and different environmental conditions (such as highways, urban roads, congested road sections, open road sections, etc.).

[0096] In practical applications, the emergency decision-making module does not simply invoke preset plans, but can dynamically adjust the preset plans according to the actual situation. The adjustment coefficient is calculated using the following formula:

[0097] In the formula, K represents the strategy adjustment coefficient; The environmental complexity factor ranges from 0.1 to 0.5. In this embodiment... =0.3; D represents the environmental complexity score, with a value range of 0-10. The larger the value, the more complex the environment. For example, the D value of a highway emergency lane may be 2, while the D value of an urban intersection during peak hours may be 9.

[0098] Furthermore, the vehicle control module communicates directly with the underlying control systems of new energy vehicles (such as Electronic Stability Program (ESP), Electronic Brakeforce Distribution (EBD), and Electric Power Steering (EPS),) and can send control commands such as acceleration, deceleration, steering, and activation of hazard warning lights. For example, when the emergency decision module decides to park the vehicle in the emergency lane, the vehicle control module first calculates the target path, then controls the steering wheel through the EPS system, and simultaneously controls the vehicle to decelerate through the braking system, maintaining the vehicle's stable movement within the lane throughout the process.

[0099] Optionally, the human-machine interface module supports multiple warning methods, including visual, auditory, and tactile warnings, which can be used in combination depending on the fault situation. Visual warnings are implemented through the vehicle's central display screen and instrument panel, displaying text and icon information such as fault type and suggested operations; auditory warnings are implemented through the vehicle's speakers, emitting alarm sounds or voice prompts of different frequencies and rhythms; tactile warnings are implemented through the steering wheel vibration motor and seat vibration module, conveying urgency information through different vibration modes.

[0100] In some optional implementations, the emergency control system for autonomous driving further includes a communication module. This module employs 4G / 5G wireless communication technology and is primarily used for information exchange with a remote monitoring platform in the event of a sudden malfunction. On one hand, this module sends fault information (including fault type, fault level, and time of occurrence), vehicle location information, and vehicle status data to the remote monitoring platform. On the other hand, this module can receive emergency guidance instructions issued by the remote monitoring platform, such as remote assistance in planning parking routes.

[0101] Preferably, to ensure priority transmission of critical information, the communication module uses the following formula to determine communication priority:

[0102] In the formula, This indicates the communication priority, with a value ranging from 0 to 10. The larger the value, the higher the priority. This indicates the weight of the fault level's impact, with a value ranging from 0.6 to 0.8. In this embodiment... ; The fault levels (0-10) defined above; This indicates the level of danger of the vehicle's current location, with a value ranging from 0 to 10. A higher value indicates a more dangerous location, such as the center of a highway. The value is 9, while the parking lot The value is 1.

[0103] It is worth noting that once the communication module determines the priority, it can ensure that high-priority information occupies communication resources first.

[0104] In one specific embodiment, when a vehicle experiences a serious malfunction in the middle of a highway ( , When ), communication priority This is the highest priority, and the communication module will prioritize transmitting this fault information; if the vehicle experiences a minor fault in the parking lot ( , ),but This is a low-priority signal, and information transmission can wait until communication resources are idle.

[0105] The functions of each module in the above-mentioned emergency control system for autonomous driving correspond to the steps in the above-mentioned emergency control method embodiment, and their functions and implementation processes will not be described in detail here.

[0106] Thirdly, embodiments of this application provide an emergency control device, which can be a personal computer (PC), laptop computer, server, or other device with data processing capabilities.

[0107] Reference Figure 4 , Figure 4 This is a schematic diagram of the hardware structure of the emergency control device involved in the embodiments of this application. In the embodiments of this application, the emergency control device may include a processor, a memory, a communication interface, and a communication bus.

[0108] The communication bus can be of any type and is used to interconnect the processor, memory, and communication interface.

[0109] Communication interfaces include input / output (I / O) interfaces, physical interfaces, and logical interfaces used to interconnect devices within the emergency control equipment, as well as interfaces used to interconnect the emergency control equipment with other devices (such as other computing devices or user equipment). Physical interfaces can be Ethernet interfaces, fiber optic interfaces, ATM interfaces, etc.; user equipment can be displays, keyboards, etc.

[0110] Memory can be various types of storage media, such as random access memory (RAM), read-only memory (ROM), non-volatile RAM (NVRAM), flash memory, optical storage, hard disk, programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), etc.

[0111] The processor can be a general-purpose processor, which can call the emergency control program stored in the memory and execute the emergency control method provided in the embodiments of this application. For example, the general-purpose processor can be a central processing unit (CPU). The method executed when the emergency control program is called can be referred to in the various embodiments of the emergency control method of this application, and will not be repeated here.

[0112] Those skilled in the art will understand that Figure 4 The hardware structure shown does not constitute a limitation of this application and may include more or fewer components than shown, or combine certain components, or have different component arrangements.

[0113] Fourthly, embodiments of this application also provide a computer-readable storage medium.

[0114] The present application has an emergency control program stored on a computer-readable storage medium, wherein when the emergency control program is executed by a processor, it implements the steps of the emergency control method described above.

[0115] The method implemented when the emergency control procedure is executed can be referred to in the various embodiments of the emergency control method of this application, and will not be repeated here.

[0116] In summary, this invention eliminates the lag and subjective bias of traditional handling methods through the millisecond-level response and quantitative evaluation mechanism of the fault monitoring module, ensuring accurate matching between fault response levels and safety threats, and reducing accident risks from the source. It overcomes the unreliability of single-sensor data in complex environments by utilizing multi-sensor fusion technology, providing precise environmental support for emergency decision-making. The dynamic adjustment mechanism enables intelligent and personalized emergency strategies, adapting to different road scenarios and traffic conditions, minimizing interference with traffic flow while ensuring safety. Combined with a graded warning system for driver status and a smooth transition mechanism for control permissions, it effectively avoids secondary accidents caused by abrupt human-machine interaction, improving human-machine collaboration efficiency and driving comfort. Furthermore, the priority-based information management system optimizes data storage and transmission resources, supports system iterative optimization, and balances safety and energy efficiency for new energy vehicles, comprehensively improving the safety, intelligence, scenario adaptability, and reliability of emergency handling for sudden faults in autonomous driving.

[0117] It should be noted that the sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0118] The terms "comprising" and "having," and any variations thereof, in the specification, claims, and accompanying drawings of this application are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to such process, method, product, or apparatus. The terms "first," "second," and "third," etc., are used to distinguish different objects, etc., and do not indicate a sequence, nor do they limit "first," "second," and "third" to different types.

[0119] In the description of the embodiments of this application, terms such as "exemplary," "for example," or "for instance" are used to indicate examples, illustrations, or explanations. Any embodiment or design described as "exemplary," "for example," or "for instance" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or designs. Specifically, the use of terms such as "exemplary," "for example," or "for instance" is intended to present the relevant concepts in a concrete manner.

[0120] In the description of the embodiments of this application, unless otherwise stated, " / " means "or". For example, A / B can mean A or B. The "and / or" in the text is merely a description of the relationship between related objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist simultaneously, and B exists alone. In addition, in the description of the embodiments of this application, "multiple" means two or more.

[0121] In some processes described in the embodiments of this application, multiple operations or steps are included in a specific order. However, it should be understood that these operations or steps may not be executed in the order they appear in the embodiments of this application, or they may be executed in parallel. The sequence number of the operation is only used to distinguish different operations, and the sequence number itself does not represent any execution order. In addition, these processes may include more or fewer operations, and these operations or steps may be executed sequentially or in parallel, and these operations or steps may be combined.

[0122] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above, and includes several instructions to cause a terminal device to execute the methods described in the various embodiments of this application.

[0123] The above are merely preferred embodiments of this application and do not limit the patent scope of this application. Any equivalent structural or procedural transformations made using the content of this application's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of this application.

Claims

1. An emergency control method for automatic driving, characterized by, The emergency control method comprises: Real-time collection of vehicle running state information, and determination of a fault type and assessment of a fault level according to the running state information; Real-time collection of environmental data around the vehicle by using multiple sensors, data fusion of the environmental data collected by each sensor to obtain comprehensive environmental parameters; Generation of a corresponding emergency disposal strategy according to the fault type, the fault level and the comprehensive environmental parameters; Control of the vehicle according to the emergency disposal strategy, and issuance of corresponding warning information to the driver; Monitoring of the vehicle state and the driver response state, and adjustment of the emergency disposal strategy according to the vehicle state and the driver response state.

2. The emergency control method of claim 1, wherein, The data fusion of the environmental data collected by each sensor to obtain comprehensive environmental parameters comprises: Determination of the confidence of each kind of sensor data based on the weather and the vehicle driving environment type in the environmental data, and determination of the fusion weight of each kind of sensor based on the confidence; Data fusion of each kind of sensor data based on the fusion weight of each kind of sensor to obtain comprehensive environmental parameters.

3. The emergency control method according to claim 2, characterized by, The determination of the fusion weight of each kind of sensor based on the confidence comprises: According to the formula: Computing a fusion weight for sensor data , wherein , wherein represents a confidence level of the i-th sensor under the current environment, represents a confidence level of the i-th sensor under the current environment, represents a total number of sensors participating in the fusion.

4. The emergency control method of claim 1, wherein, The real-time collection of environmental data around the vehicle by using multiple sensors comprises: collection of environmental information of the vehicle by using a vehicle-mounted camera, a millimeter wave radar, a laser radar and a positioning device.

5. The emergency control method of claim 1, wherein, The determination of a fault type and assessment of a fault level according to the running state information comprises: Determination of the current fault type of the vehicle according to the running state information; Obtaining of the influence probability of vehicle driving safety and the functional failure degree caused by the fault according to the current fault type; Assessment of the fault level of the current fault type according to the influence probability of vehicle driving safety and the functional failure degree caused by the fault.

6. The emergency control method of claim 1, wherein, The generation of a corresponding emergency disposal strategy according to the fault type, the fault level and the comprehensive environmental parameters comprises: Generation of an initial emergency strategy according to the fault type and the fault level; Analysis of the complexity of the current environment according to the comprehensive environmental parameters, and adjustment of the initial emergency strategy according to the complexity of the current environment to obtain the emergency disposal strategy.

7. The emergency control method of claim 6, wherein, The adjustment of the initial emergency strategy according to the complexity of the current environment to obtain the emergency disposal strategy comprises: If the fault level is not higher than a preset threshold and the complexity of the surrounding environment is lower than a preset value, a strategy of prompting the driver to take over the vehicle is generated; If the fault level is higher than the preset threshold or the complexity of the surrounding environment is higher than the preset value, a strategy of automatic deceleration of the vehicle, turning on of a danger warning lamp and parking of the vehicle to an emergency lane or a safe area is generated.

8. The emergency control method of claim 1, wherein, After the adjustment of the emergency disposal strategy according to the vehicle state and the driver response state, the method further comprises: after the vehicle is in a safe state, recording and saving of fault information, and uploading of the information to a remote platform according to the importance of the information.

9. An emergency control system for autonomous driving, characterized in that Comprise: A fault monitoring module for real-time collection of vehicle running state information, and determination of a fault type and assessment of a fault level according to the running state information; An environmental perception module for real-time collection of environmental data around the vehicle by using multiple sensors, data fusion of the environmental data collected by each sensor to obtain comprehensive environmental parameters; An emergency decision module for generation of a corresponding emergency disposal strategy according to the fault type, the fault level and the comprehensive environmental parameters; A vehicle control module is configured to control the vehicle according to the emergency handling strategy; A human-computer interaction module is configured to send corresponding warning information to the driver, and the human-computer interaction module is further configured to monitor a vehicle state and a driver response state, and adjust the emergency handling strategy according to the vehicle state and the driver response state.

10. An emergency control device for automatic driving, characterized by The emergency control device for autonomous driving comprises a processor, a memory, and an emergency control program for autonomous driving stored in the memory and executable by the processor, wherein the emergency control program for autonomous driving, when executed by the processor, implements the steps of the emergency control method for autonomous driving according to any one of claims 1 to 8.