Multi-stage emergency method and system based on unmanned vehicle failure

By constructing a high-dimensional state space to capture the combination of fault data and implicit transmission links of autonomous vehicles, emergency strategies are generated, solving the problems of fault misjudgment and missed judgment in existing technologies, and realizing accurate fault level and emergency operation of autonomous vehicles.

CN122443489APending Publication Date: 2026-07-24GUANGDONG VOCATIONAL & TECHNICAL COLLEGE
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
GUANGDONG VOCATIONAL & TECHNICAL COLLEGE
Filing Date
2026-05-28
Publication Date
2026-07-24

AI Technical Summary

Technical Problem

Existing fault diagnosis and emergency response technologies for autonomous vehicles cannot effectively capture the implicit transmission links between faults, leading to misjudgments or omissions, which affects the accuracy of fault levels and emergency sequences.

Method used

By acquiring operational data from autonomous vehicles and external environmental data, and combining fault signals to determine multiple fault data combinations, a high-dimensional state space is constructed. This captures the spatiotemporal coupling characteristics and implicit transmission links between faults, generates emergency strategies, and performs multi-level emergency operations.

Benefits of technology

This improves the accuracy of fault levels and emergency sequences, ensuring the safe operation of autonomous vehicles in complex scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122443489A_ABST
    Figure CN122443489A_ABST
Patent Text Reader

Abstract

The application discloses a kind of based on the fault multistage emergency method and system under unmanned, the present application relates to the technical field of multistage emergency, according to the identification of multiple fault data combination to determine the corresponding fault content;Mark the current driving state of unmanned vehicle, and determine the fault matrix of unmanned vehicle in combination with each fault content, according to the iteration of the fault matrix to determine the corresponding fault event, and determine the fault level of unmanned vehicle in combination with the driving scene of unmanned vehicle, improve the accuracy of the fault level of unmanned vehicle. Multiple fault factors are dynamically matched in the emergency strategy space of unmanned vehicle to generate the emergency strategy of unmanned vehicle, determine multiple emergency projects according to the analysis of emergency strategy, and determine the emergency sequence of unmanned vehicle at the current time in combination with the driving constraint relationship of unmanned vehicle, realize the multistage emergency operation of unmanned vehicle.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the technical field of multi-level emergency response, and in particular to a multi-level emergency response method and system based on unmanned driving. Background Technology

[0002] With the rapid development of autonomous driving technology, the operational safety and reliability of autonomous vehicles in complex traffic scenarios have become a core focus of the industry. Because autonomous vehicles heavily rely on multi-source sensors, drive-by-wire chassis, and complex algorithms, they inevitably encounter system failures caused by hardware degradation, software anomalies, or extreme environmental interference during actual driving. Therefore, accurately assessing these failures and taking effective emergency interventions is crucial to ensuring the lifecycle of autonomous vehicles.

[0003] Currently, fault diagnosis and emergency response technologies for autonomous vehicles typically employ threshold triggering mechanisms based on single fault signals and preset single emergency action responses. Existing technologies largely map isolated fault signals directly to preset fault levels, failing to introduce and identify the fault content. They cannot capture the implicit transmission links between faults, making the system highly susceptible to misjudgment or omission under complex coupled fault conditions. This results in fault level classifications often being either conservative or aggressive, severely impacting the accuracy of fault levels and reducing the precision of emergency sequences. Summary of the Invention

[0004] The purpose of this invention is to overcome the shortcomings of the prior art. This invention provides a multi-level emergency response method and system for unmanned driving.

[0005] This invention provides a multi-level emergency response method for faults under autonomous driving, including:

[0006] The system acquires operational data and external environmental data of autonomous vehicles, and combines these with fault signals of the autonomous vehicles to determine multiple fault data combinations. Based on the identification of these multiple fault data combinations, the corresponding fault content is determined. The current driving state of the autonomous vehicle is marked, and the fault matrix of the autonomous vehicle is determined by combining various fault contents. The corresponding fault events are determined by iterating the fault matrix, and the fault level of the autonomous vehicle is determined by combining the driving scenario of the autonomous vehicle. Based on the tracing of the fault level, multiple fault factors are identified. These multiple fault factors are dynamically matched in the emergency strategy space of the autonomous vehicle to generate an emergency strategy for the autonomous vehicle. Different target fault levels correspond to different degradation gradient emergency strategies. Based on the analysis of the emergency strategy, multiple emergency items are identified, and the emergency sequence of the autonomous vehicle at the current moment is determined in combination with the driving constraints of the autonomous vehicle. Multi-level emergency operations of the autonomous vehicle are triggered along the emergency sequence, and fault events are gradually optimized during the driving process of the autonomous vehicle.

[0007] This invention provides a multi-level emergency response system for autonomous driving, which is applied to the aforementioned multi-level emergency response method for autonomous driving. The multi-level emergency response system for autonomous driving includes: The fault identification module is used to acquire the operating data and external environment data of the autonomous vehicle, and combine them with the fault signals of the autonomous vehicle to determine multiple fault data combinations, and determine the corresponding fault content based on the identification of multiple fault data combinations. The fault level module is used to mark the current driving state of the autonomous vehicle, determine the fault matrix of the autonomous vehicle by combining various fault contents, determine the corresponding fault events by iterating the fault matrix, and determine the fault level of the autonomous vehicle by combining the driving scenario of the autonomous vehicle. The emergency strategy module is used to identify multiple fault factors based on the traceability of the fault level. Multiple fault factors are dynamically matched in the emergency strategy space of the autonomous vehicle to generate the emergency strategy of the autonomous vehicle. Different target fault levels correspond to different degradation gradient emergency strategies. The multi-level emergency module is used to determine multiple emergency items based on the analysis of the emergency strategy, and to determine the emergency sequence of the autonomous vehicle at the current moment by combining the driving constraints of the autonomous vehicle. It triggers multi-level emergency operations of the autonomous vehicle along the emergency sequence and gradually optimizes fault events during the driving process of the autonomous vehicle.

[0008] Compared with the prior art, the beneficial effects of the present invention are: (1) Obtain the operation data and external environment data of the autonomous vehicle, and determine multiple fault data combinations based on the fault signals of the autonomous vehicle. Determine the corresponding fault content based on the identification of multiple fault data combinations; mark the current driving state of the autonomous vehicle, and determine the fault matrix of the autonomous vehicle based on each fault content. Determine the corresponding fault event based on the iteration of the fault matrix, and determine the fault level of the autonomous vehicle based on the driving scenario of the autonomous vehicle. The introduction of fault content further controls the fault matrix of the autonomous vehicle and improves the accuracy of the fault level of the autonomous vehicle.

[0009] (2) Based on the tracing of the fault level, multiple fault factors are determined. Multiple fault factors are dynamically matched in the emergency strategy space of the autonomous vehicle to generate the emergency strategy of the autonomous vehicle. Different target fault levels correspond to different degradation gradient emergency strategies. Based on the analysis of the emergency strategy, multiple emergency items are determined. Combined with the driving constraint relationship of the autonomous vehicle, the emergency sequence of the autonomous vehicle at the current moment is determined. Multi-level emergency operations of the autonomous vehicle are triggered along the emergency sequence. During the driving process of the autonomous vehicle, the fault events are gradually optimized, the emergency strategy is further controlled, and multiple emergency items and the driving constraint relationship of the autonomous vehicle are fully considered. The accuracy of the emergency sequence is improved, and multi-level emergency operations of the autonomous vehicle are realized. Attached Figure Description

[0010] Figure 1 This is a flowchart illustrating the multi-level emergency response method for faults under unmanned driving in an embodiment of the present invention. Figure 2 This is a flowchart illustrating step S11 in the multi-level emergency response method for faults based on unmanned driving in an embodiment of the present invention. Figure 3 This is a flowchart illustrating step S12 in the multi-level emergency response method for faults based on unmanned driving in an embodiment of the present invention. Figure 4 This is a flowchart illustrating step S13 in the multi-level emergency response method for faults based on unmanned driving in an embodiment of the present invention. Figure 5 This is a flowchart illustrating step S14 in the multi-level emergency response method for faults based on unmanned driving in an embodiment of the present invention. Figure 6 This is a schematic diagram of the structural composition of a multi-level emergency response system for unmanned driving in an embodiment of the present invention. Detailed Implementation

[0011] The technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention.

[0012] Please see Figures 1 to 6 A multi-level emergency response method for faults under autonomous driving is proposed and applied to multi-level emergency scenarios. The multi-level emergency response method for faults under autonomous driving includes: Step S11: Obtain the operating data and external environment data of the autonomous vehicle, and combine them with the fault signals of the autonomous vehicle to determine multiple fault data combinations, and determine the corresponding fault content based on the identification of multiple fault data combinations. Step S12: Mark the current driving state of the autonomous vehicle, and determine the fault matrix of the autonomous vehicle in combination with each fault content. Determine the corresponding fault event based on the iteration of the fault matrix, and determine the fault level of the autonomous vehicle in combination with the driving scenario of the autonomous vehicle. Step S13: Based on the tracing of the fault level, multiple fault factors are determined. These multiple fault factors are dynamically matched in the emergency strategy space of the autonomous vehicle to generate an emergency strategy for the autonomous vehicle. Different target fault levels correspond to different degradation gradient emergency strategies. Step S14: Based on the analysis of the emergency strategy, determine multiple emergency items, and combine the driving constraints of the autonomous vehicle to determine the emergency sequence of the autonomous vehicle at the current moment. Trigger multi-level emergency operations of the autonomous vehicle along the emergency sequence, and gradually optimize the fault events during the driving process of the autonomous vehicle.

[0013] refer to Figure 2 In step S11, the specific steps are as follows: S111: When the autonomous vehicle is driving in autonomous driving mode, the autonomous vehicle's operation data is acquired. At the same time, the external environment data of the human-driven vehicle is collected through the autonomous vehicle's external sensing array, and combined with the autonomous vehicle's operation data for spatiotemporal alignment to map to a high-dimensional state space. S112: In this high-dimensional state space, fault signals of autonomous vehicles are collected in real time. Multiple fault markers are determined based on the analysis of the fault signals. Cross-domain feature extraction is performed by combining the autonomous vehicle's operating data and external environment data to determine multiple fault data combinations that characterize different failure mechanisms. Correlation topology identification is performed on multiple fault data combinations to capture the spatiotemporal coupling characteristics and implicit transmission links between each fault data combination, thereby determining the fault content that characterizes the essential causes and manifestations of the fault.

[0014] In the embodiments of this application, when the autonomous vehicle is driving in an autonomous driving mode, the autonomous vehicle's operating data is acquired. At the same time, the external environment data of the autonomous vehicle is collected by the external sensing array of the autonomous vehicle and combined with the autonomous vehicle's operating data for spatiotemporal alignment to map to a high-dimensional state space, thus introducing a high-dimensional state space.

[0015] At this time, while the autonomous vehicle is driving in autonomous driving mode, the vehicle's operation data is acquired in real time through the vehicle bus network. The operation data includes at least chassis drive-by-wire execution feedback data, powertrain status data, and vehicle posture data. Simultaneously, the external environment data of the autonomous vehicle is collected through the vehicle's external perception array, which includes heterogeneous active and passive sensors. The external environment data includes at least three-dimensional point cloud cluster data, two-dimensional image pixel matrix, and target-level heading trajectory data. At this stage, the operation data and the external environment data are input to the data preprocessing module in parallel in an asynchronous manner and at different frequencies to form a raw multimodal data stream.

[0016] After acquiring the raw multimodal data stream, spatiotemporal alignment is performed by combining it with the operational data of the autonomous vehicle. In the temporal alignment dimension, the timestamps of each data frame in the operational data and external environment data are extracted based on the unified system clock of the autonomous vehicle. Then, based on linear interpolation or frequency synchronization algorithms, the low-frequency operational data is aligned to the time series of the high-frequency external environment data to eliminate time delay distortion caused by differences in data acquisition cycles. In the spatial alignment dimension, the vehicle dynamic pose information in the operational data is extracted and combined with the calibration extrinsic parameters of each sensor in the external sensing array to construct a spatial coordinate transformation matrix. Each external environment data is projected from its respective sensor coordinate system to the vehicle coordinate system with the rear axle center as the origin to eliminate relative pose deviations during vehicle movement, thereby completing the spatiotemporal reference unification of multi-source data.

[0017] After completing the spatiotemporal alignment, the aligned time-series operational data sequence and the spatial environment data sequence are concatenated and mapped at the feature level to a high-dimensional state space. At this point, a pre-defined convolutional neural network is used to extract semantic feature vectors from the spatial environment data, and a recurrent neural network is used to extract dynamic change feature vectors from the time-series operational data. The semantic feature vectors and dynamic change feature vectors are concatenated into tensors, and then nonlinearly mapped to a high-dimensional manifold space of a pre-defined dimension through a fully connected mapping layer to generate a high-dimensional state feature matrix. Each state vector in the high-dimensional state space not only encodes the current instantaneous operational parameters and external environment parameters of the autonomous vehicle, but also implicitly encodes the spatiotemporal coupling relationship between operation and environment, thus providing a complete data representation foundation for subsequent cross-domain feature extraction of fault signals.

[0018] Specifically, regarding the driverless car, it is equipped with a drive-by-wire chassis, lidar, millimeter-wave radar, and multi-view cameras. The driverless car was cruising at 80 km / h in driverless mode on the highway when it suddenly encountered heavy rain and crosswinds, and there was a localized flooded section of the road ahead.

[0019] The autonomous vehicle acquires real-time operational data via the chassis CAN bus, including current speed (80 km / h), steering wheel angle (0 degrees), yaw rate (0.5 degrees / second), and brake hydraulic pressure (1 MPa). Simultaneously, the vehicle's external sensing array operates in sync: lidar collects dense water reflection point cloud data 20 meters ahead, millimeter-wave radar acquires distance and speed data of heavy trucks in the same lane ahead, and the forward-facing camera captures blurred rainy-day images under the high-speed swaying of the windshield wipers. This heterogeneous data is input in parallel to the autonomous vehicle's central computing platform at different frequencies, such as 100Hz for CAN data, 10Hz for radar data, and 30Hz for image data.

[0020] The central computing platform of the autonomous vehicle initiates spatiotemporal alignment. In the time dimension, based on the system's master clock, the 100Hz chassis yaw rate data is precisely anchored to the timestamps of the 10Hz LiDAR point cloud and the 30Hz camera image through an interpolation algorithm, ensuring that the "0.5 degrees / second yaw angle" and the "water accumulation reflection point cloud" are physical states reflected at the same absolute moment. In the spatial dimension, using the pose operation data calculated in real time by the autonomous vehicle and the sensor extrinsic parameter calibration matrix, the position of the heavy truck in the millimeter-wave radar coordinate system and the position of the water accumulation in the LiDAR coordinate system are uniformly transformed to the rear axle center coordinate system of the autonomous vehicle, eliminating the perception blind spot offset caused by the vibration of the autonomous vehicle body.

[0021] Autonomous vehicles map spatiotemporally aligned data to a high-dimensional state space. They extract environmental semantic feature vectors of "low-adhesion road surface and water splash occlusion" from rainy day images and water accumulation point clouds through convolutional networks. At the same time, they extract chassis operation dynamic feature vectors of "vehicle speed maintaining high-frequency weak oscillations and continuous small-range shifts in yaw rate" through recurrent networks. These two types of vectors are then mapped through tensor concatenation and fully connected layers to generate a state feature matrix for the current moment in the high-dimensional state space of the autonomous vehicle. This matrix not only contains explicit information such as "water accumulation and heavy trucks ahead" but also encodes the implicit correlation of "the physical coupling tendency between the vehicle's weak yaw and the reflection of water on the road surface" in the dimensional space.

[0022] Furthermore, in this high-dimensional state space, fault signals of the autonomous vehicle are collected in real time. Based on the analysis of these fault signals, multiple fault markers are determined. Cross-domain feature extraction is performed by combining the autonomous vehicle's operating data and external environmental data to determine multiple fault data combinations that characterize different failure mechanisms. Correlation topology identification is performed on multiple fault data combinations to capture the spatiotemporal coupling characteristics and implicit transmission links between each fault data combination. This allows for the determination of fault content that characterizes the essential causes and manifestations of the fault. This comprehensive approach considers the spatiotemporal coupling characteristics and implicit transmission links between various fault data combinations, ensuring the accuracy of the fault content that characterizes the essential causes and manifestations of the fault.

[0023] At this point, in this high-dimensional state space, fault signals broadcast by the underlying actuators and sensors of the autonomous vehicle are collected in real time. The fault signals are parsed according to a unified diagnostic protocol to extract fault identifiers and state bits, thereby identifying multiple explicit fault markers. Using the fault markers as query indexes, the operating data feature vectors and external environment data feature vectors that overlap with the fault markers in time are retrieved in the high-dimensional state space. An attention mechanism-driven cross-domain feature extraction operation is performed to concatenate and reassign the weights of heterogeneous fault markers, operating status features, and environmental constraint features using tensors. Redundant information from false alarms of a single sensor is extracted, thereby identifying multiple fault data combinations that characterize different failure mechanisms.

[0024] After identifying multiple fault data combinations, an association topology graph is constructed using each fault data combination as a node and the temporal sequence and logical causal relationship between the fault data combinations as directed edges. By inputting the association topology graph into a spatiotemporal graph neural network, message passing and aggregation iterations of node features are performed along the directed edges to identify the temporal trigger sequence and the mutual influence weights between multiple fault data combinations, thereby capturing the spatiotemporal coupling characteristics between each fault data combination. Simultaneously, based on the spatiotemporal coupling characteristics, intermediate hidden nodes that do not have direct explicit fault labels but cause resonance of multiple node features are located in the association topology graph, and the directed path from the initial node through the hidden node to the end node is traced to capture the implicit transmission link.

[0025] After capturing the implicit transmission links, reverse tracing and forward traversal operations are performed on the associated topology graph. At this time, in the associated topology graph, the root node with an in-degree of zero and the earliest triggering time is determined, and the combination of fault data corresponding to the root node is defined as the essential cause of the fault. At the same time, the leaf node with an out-degree greater than a preset threshold and located at the end of the transmission link is determined, and the combination of fault data corresponding to the leaf node is defined as the fault manifestation. The essential cause of the fault and the fault manifestation are encapsulated in a structured way to determine the fault content that represents the complete evolution logic of the fault, so as to provide accurate input parameters for the subsequent iteration of the fault matrix.

[0026] Specifically, the central computing platform of the autonomous vehicle monitors the underlying signals in real time in a high-dimensional state space. At this time, it collects fault signals such as a broken pulse signal from the left front wheel speed sensor and a low contrast fault signal from the front-view camera. After parsing using a unified diagnostic protocol, it identifies two fault markers: "transient loss of left front wheel speed signal" and "degradation due to visual obstruction in front." Using these two fault markers as indexes, the system extracts "operational data" (such as minor oscillations in steering wheel angle and weak fluctuations in brake hydraulic pressure) and "external loop" within the same time window in the high-dimensional state space. The system uses environmental data, such as lidar detecting high-reflectivity water accumulation points on the road ahead and millimeter-wave radar detecting lateral crosswind disturbance vectors. Through cross-domain feature extraction, the system strongly correlates "wheel speed signal loss" with "water accumulation points and splashing water" features, and strongly correlates "visual occlusion degradation" with "heavy rain and crosswind disturbance" features. This filters out the possibility of occasional false alarms from the sensors themselves and identifies two fault data combinations: combination one is "physical loss of wheel speed sensor lock caused by water splashing" and combination two is "deterioration of visual perception link signal-to-noise ratio caused by heavy rain and crosswind".

[0027] The autonomous vehicle combines the above fault data to construct an associated topology graph, in which "heavy rain, crosswinds and water accumulation environment" serves as the environmental background node, and "deterioration of signal-to-noise ratio of visual perception link" and "physical loss of wheel speed sensor lock" serve as parallel execution and perception nodes. Through the message passing mechanism of spatiotemporal graph neural network, the system identifies the spatiotemporal coupling characteristics: that is, crosswinds cause the autonomous vehicle to deviate laterally, which in turn requires the front wheels to apply a larger steering angle to maintain the lane, and at this time the front wheels happen to drive into the water accumulation area.

[0028] The accumulated water not only obscured the view, but also caused the tires to hydroplane, which caused the wheel speed sensor tooth ring to be instantly covered by a water film (wheel speed loss). As a result, the system captured an implicit transmission link: extreme weather disturbance: crosswind + heavy rain > increased need for vehicle lateral offset correction > vehicle driving into deep water area induces hydroplane > perception degradation and wheel speed loss occur simultaneously. Among them, "extreme weather environment induces hydroplane" becomes the implicit transmission key node without explicit DTC code.

[0029] The autonomous vehicle traces and traverses the aforementioned topology graph. Through reverse tracing, it identifies the root node with zero in-degree as "extreme weather and road conditions of heavy rain, crosswinds, and water accumulation," which is the essential cause of the fault. This indicates that the fault is not a permanent damage to the vehicle's internal hardware, but rather that the external environment exceeds the physical working boundaries of the sensors and actuators. Through forward traversal, it identifies leaf nodes with extremely high out-degree as "limited intervention of the ESP system due to unreliable wheel speed signals" and "reduced confidence in tracking the target ahead due to visual degradation," which are the manifestations of the fault. The system encapsulates the essential cause and manifestation of the fault, determining the complete fault content as: "Instantaneous degradation of the perception-execution dual domain and risk of hydroplaning caused by heavy rain, crosswinds, and water accumulation." This fault content accurately reveals the deep physical crisis behind the surface sensor alarm.

[0030] refer to Figure 3 In step S12, the specific steps are as follows: S121: Real-time monitoring of autonomous vehicles, acquisition of multiple current driving data of autonomous vehicles in different dimensions, determination of the current driving status of autonomous vehicles based on the identification of multiple current driving data, and tensor splicing in multi-dimensional feature space in combination with various fault contents to construct a fault matrix representing the full-dimensional fault state. S122: Perform multi-level iterations on the fault matrix and predict the driving failure path of the autonomous vehicle during the iteration process. By tracing along the driving failure path, multiple driving failure contents are identified. At the same time, the driving scenario of the autonomous vehicle is obtained, and a corresponding fault framework is constructed by combining multiple driving failure contents. Furthermore, fault pre-simulation is carried out by combining the driving conflict situation of the autonomous vehicle, thereby determining the fault level of the autonomous vehicle.

[0031] In the embodiments of this application, the autonomous vehicle is monitored in real time, and multiple current driving data of the autonomous vehicle in different dimensions are obtained. The current driving state of the autonomous vehicle is determined based on the identification of multiple current driving data. Tensor splicing is performed in a multi-dimensional feature space in combination with various fault contents to construct a fault matrix representing the full-dimensional fault state. This takes into account the overall consideration of multiple current driving data and ensures the accuracy of the current driving state of the autonomous vehicle.

[0032] At this time, the autonomous vehicle is monitored in real time. Multiple current driving data of the autonomous vehicle in different dimensions are obtained through the chassis dynamometer bus, inertial measurement unit and positioning module. The different dimensions include at least longitudinal dynamic dimension, lateral dynamic dimension and kinematic attitude dimension. The multiple current driving data are analyzed and thresholded, or the current driving data is input into a pre-trained state classification model to identify the dynamic boundary and trajectory maintenance capability of the autonomous vehicle at the current moment, so as to determine the current driving state of the autonomous vehicle. The current driving state includes, but is not limited to, stable cruise state, extreme lateral slip state and instability critical state.

[0033] The current driving state and the various fault contents identified in the previous steps are subjected to feature embedding operations, and they are mapped to a preset multi-dimensional feature space. At this time, for the current driving state, its continuous dynamic parameter feature vector is extracted; for each fault content, its fault semantic feature vector containing the discrete identifier of the essential cause and the continuous distribution of the manifestation is extracted. Through the feature mapping network, the heterogeneous driving state features and fault semantic features are transformed into isomorphic feature vectors with a unified dimension and numerical distribution range, so as to eliminate the interference of different physical dimensions on the subsequent matrix construction.

[0034] In the multidimensional feature space, the isomorphized current driving state feature vector and each fault content feature vector are concatenated using a tensor concatenation operation. Then, using the current driving state feature vector as the basic tensor axis, each fault content feature vector is concatenated and fused along the orthogonal latent feature dimensions. This results in the concatenated tensor encoding not only the vehicle's current absolute motion state but also embedding the activation weights and deterioration gradients of each fault under the current motion state. The concatenated higher-order tensor is the fault matrix representing the full-dimensional fault state. Each element in this fault matrix reflects the degree of risk accumulation under the interaction of a specific driving state dimension and a specific fault mechanism dimension, thus providing structured data support for subsequent iteration of the fault matrix and determination of the fault level.

[0035] Specifically, the autonomous vehicle's central computing platform monitors the vehicle in real time, acquiring current driving data from different dimensions through the chassis CAN bus, IMU, and wheel speed sensors: the longitudinal dynamics dimension shows a current speed of 80 km / h and an acceleration of -0.5 m / s², with slight braking; the lateral dynamics dimension shows a steering wheel angle of 3 degrees and a yaw rate of 1.5 degrees / second, with slight deviation due to crosswinds; and the kinematic attitude dimension shows a body roll angle of 0.8 degrees. The system identifies the above data and determines that although the vehicle is experiencing lateral external disturbances, the tire slip angle remains within the linear range and has not exceeded the adhesion limit, thus determining the current driving state of the autonomous vehicle as "stable cruise state under crosswind disturbance".

[0036] The system maps the aforementioned "stable cruise state affected by crosswind disturbance" with the "fault content" determined in the preceding S112 step, namely the risk of instantaneous degradation of the perception-execution dual domain and hydroplaning loss of control induced by heavy rain, crosswinds and water accumulation environment, into a multi-dimensional feature space. The system extracts continuous parameters such as lateral offset rate and longitudinal deceleration in the current driving state to construct a driving state feature vector. At the same time, it extracts "water depth index", "wheel speed signal frame loss rate" and "visual signal-to-noise ratio reduction value" in the fault content to construct a fault semantic feature vector. Through the feature embedding network, the offset rate and frame loss rate, which have completely different physical meanings, are mapped into isomorphic distribution vectors in the same high-dimensional feature space, so that the two have computable numerical distance and inner product semantics.

[0037] The autonomous vehicle performs tensor splicing in a high-dimensional feature space. The system uses the feature vector of "stable cruise state under crosswind disturbance" as the row tensor basis and the fault feature vector of "instantaneous degradation in perception-execution dual domain" as the column tensor extension, and performs tensor concatenation along the feature channel dimension. The fault matrix generated after splicing not only records "vehicle speed of 80km / h" and "wheel speed frame loss" separately, but also calculates and encodes the joint feature of "the risk weight index of hydroplaning runaway caused by wheel speed frame loss increases exponentially in the matrix cross elements" in the driving state of "driving state of 80km / h high speed with 1.5 degrees / second yaw". This full-dimensional fault matrix intuitively reflects that although the current driving state is still stable, the system is in an extremely dangerous critical state under the cross action of "specific fault content: hydroplaning / signal loss".

[0038] Furthermore, the fault matrix is ​​iterated at multiple levels, and the driving failure path of the autonomous vehicle is predicted during the iteration process. Multiple driving failure contents are identified by tracing along the driving failure path. At the same time, the driving scenario of the autonomous vehicle is obtained, and a corresponding fault framework is constructed by combining multiple driving failure contents. Fault pre-simulation is further combined with the driving conflict situation of the autonomous vehicle to determine the fault level of the autonomous vehicle. By introducing fault contents, the fault matrix of the autonomous vehicle is further controlled, and the accuracy of the fault level of the autonomous vehicle is improved.

[0039] At this point, the fault matrix is ​​iterated through multiple levels. The fault matrix is ​​then input into a preset dynamic evolution model, with the fault matrix at the current moment as the initial state. Combining the dynamic boundary constraints of the autonomous vehicle and the deterioration gradients of each fault, forward extrapolation is performed according to a preset time step. In each iteration, the cumulative risk value of each element in the fault matrix is ​​updated, and the evolution trajectory of elements whose risk values ​​exceed the safety threshold is extracted. Thus, the temporal evolution sequence of the autonomous vehicle from the current state to the completely out-of-control state is predicted in the multi-dimensional state space. This sequence is the driving failure path of the autonomous vehicle.

[0040] By tracing back along the failure path, the node features that play a dominant role in the evolution of the failure path are extracted. Then, starting from the final loss of control node, the matrix element with the largest risk increment in each iteration is retrieved in reverse along the iteration time axis. The dynamic dimension and failure mechanism dimension corresponding to the element are analyzed to determine the multiple driving failure contents that the autonomous vehicle will trigger in sequence during the deterioration along the failure path. The driving failure contents include, but are not limited to, loss of lateral trajectory maintenance capability, reduction of longitudinal braking performance and tendency of attitude instability and rollover.

[0041] Real-time acquisition of high-precision map data and perception fusion results of autonomous vehicles is used to determine the driving scenario of autonomous vehicles. The driving scenario includes at least road topology, traffic flow density, and meteorological road surface adhesion coefficient. The boundary constraints of the driving scenario are structured and mapped with multiple driving failures to construct a corresponding fault framework. In the fault framework, each element of the driving scenario is used as the environmental boundary, and the driving failures are used as endogenous risk variables. The interference relationship between the environmental boundary and the endogenous risk variables is established, that is, the deterioration acceleration effect or the blocking effect of a specific failure in a specific scenario is defined.

[0042] Under the constraints of the fault framework, fault simulation is performed in conjunction with the driving conflict situation of autonomous vehicles. At this time, driving failure content is superimposed on the current driving scenario. Through game theory or multi-agent interaction model, the dynamic game process between autonomous vehicles and surrounding traffic participants under failure intervention is simulated. The difference between the dynamic margin required for the vehicle to avoid risks and the actual available margin of the vehicle is quantified to generate a conflict situation deterioration index. According to the preset threshold range of the conflict situation deterioration index, the fault level of autonomous vehicles is determined. The fault level increases progressively with the increase of the conflict situation deterioration index.

[0043] Specifically, the autonomous vehicle's central computing platform iterates through multiple levels on the fault matrix generated in the preliminary steps, which includes a surge in hydroplaning risk. The system uses the fault matrix with the current vehicle speed of 80 km / h and a yaw rate of 1.5 degrees / second as the initial state, and combines it with the physical constraint of a sharp decrease in the adhesion coefficient on the waterlogged road surface, performing forward extrapolation in 100-millisecond time steps. During the iteration process, the system predicts that if the current steering and braking inputs are maintained, the tire slip angle will exceed the linear range after 300 milliseconds, the front wheels will completely lose lateral grip after 600 milliseconds, and the vehicle will enter an uncontrollable rotational state after 900 milliseconds. This temporal state sequence consisting of "small offset > sideslip > rotational loss of control" is the driving failure path of the autonomous vehicle under the current operating conditions.

[0044] The system traces back along the aforementioned driving failure path; starting from the final "rotational loss of control" node, it determines that "the front wheels lose lateral grip" at 600 milliseconds is the direct disaster node, "the tire slip angle exceeds the linear range" at 300 milliseconds is the deterioration acceleration node, and "the ESP system cannot actively intervene due to loss of wheel speed signal" at 0 milliseconds is the underlying trigger node; thus, the system determines that the autonomous vehicle will trigger multiple driving failures in sequence along this path as follows: "loss of active yaw damping suppression capability", "loss of front axle trajectory maintenance capability", and "complete instability of vehicle dynamic attitude".

[0045] The system acquires real-time driving scenarios of autonomous vehicles: "Highway main road: no escape lane", "Heavy truck on the right: limited lateral space", and low-adhesion road surface in heavy rain. The system integrates the above driving scenarios with the identified driving failure content to construct a fault framework. In this framework, "environmental boundary conditions: heavy truck on the right" and "intrinsic risk: loss of front axle trajectory holding capability" form a fatal interference - that is, "the presence of the heavy truck on the right deprives the vehicle of the lateral fault tolerance space required when it sideslips", while "the low-adhesion road surface blocks the possibility of avoiding the heavy truck by accelerating or making an emergency lane change".

[0046] Within the aforementioned fault framework, the system conducts fault simulations based on driving conflict scenarios. It simulates an autonomous vehicle experiencing front axle sideslip failure, where its rightward veer will result in a side collision with a heavy truck after 1.2 seconds. The system calculates that the lateral acceleration required for the autonomous vehicle to avoid this collision is 0.8g, but the physical limits of the current flooded road surface can only provide 0.3g of lateral force, resulting in a significant difference in dynamic margin and a conflict situation deterioration index reaching an extremely high risk threshold. Based on this simulation result, the system determines that although the vehicle has not yet physically sideslipped, it is already on an irreversible collision deterioration path. Therefore, it decisively classifies the autonomous vehicle's fault level as the highest level, such as L1 lethal, providing a crucial basis for immediately triggering the highest degrading gradient "emergency strategy, such as emergency pullover."

[0047] refer to Figure 4 In step S13, the specific steps are as follows: S131: The fault level is traced back in reverse, and multiple fault factors that induce the fault are identified by combining the causal analysis mechanism during the tracing process. These multiple fault factors are input into the emergency strategy space of the autonomous vehicle, so as to perform Pareto optimization among driving safety, traffic efficiency and passenger comfort to generate the emergency strategy of the autonomous vehicle. S132: Map different target fault levels to different degradation gradients. The degradation gradients are divided according to the autonomous driving capabilities of the autonomous vehicle. At the same time, high-level faults correspond to high degradation gradient strategies that strip away perception redundancy and execution redundancy, while low-level faults correspond to low degradation gradient strategies that only restrict the operating domain.

[0048] In the embodiments of this application, the fault level is traced back, and multiple fault factors that induce the fault are determined by combining the causal analysis mechanism during the tracing process. These multiple fault factors are input into the emergency strategy space of the autonomous vehicle, thereby performing Pareto optimization among driving safety, traffic efficiency and passenger comfort to generate the emergency strategy of the autonomous vehicle. This approach is compatible with the overall consideration of the fault level and ensures the accuracy of the multiple fault factors that induce the fault.

[0049] At this point, the fault level is traced backwards, following the fault framework and failure path constructed in the previous steps, and the root node and intermediate propagation nodes that triggered the fault level are retrieved from top to bottom. During the tracing process, a causal analysis mechanism is introduced. At this point, by calculating the attribution weight of each node feature to the fault level output, the contribution of each potential trigger to the final high-risk situation is quantified, the pseudo-correlation features caused by multi-source data coupling are stripped away, and the driving variables with real physical causal relationships are extracted, thereby identifying multiple fault factors that induce the fault. The fault factors include at least environmental boundary mutation factors, actuator physical limit overrun factors, and sensor information source degradation factors.

[0050] Multiple identified fault factors are feature-encoded to form a fault factor vector, which is then input into the autonomous vehicle's pre-defined emergency strategy space. The emergency strategy space is a strategy pool composed of multiple "basic emergency behavior primitives, such as deceleration, lane change, pulling over, and activating hazard lights," and is divided into multiple subspaces according to the degradation gradient. After inputting the fault factor vector, the matching degree between the vector and the triggering conditions of each emergency strategy in the strategy pool is calculated to activate the corresponding set of candidate emergency strategies, and the execution constraint boundaries of each candidate strategy under the current vehicle state are extracted.

[0051] In the candidate emergency strategy set, a multi-objective optimization model is constructed, taking into account the current dynamic state of the autonomous vehicle and external environmental constraints, with driving safety, traffic efficiency, and passenger comfort as evaluation indicators. For each strategy in the candidate strategy set, its safety risk margin, speed interference gradient to traffic flow, and passenger impact index caused by acceleration are quantified during the execution cycle. Pareto optimization is performed in the multi-objective optimization model. At this point, under the premise of ensuring that the driving safety risk margin does not exceed the fatal threshold, a non-dominated solution set that compromises traffic efficiency loss and passenger comfort is sought. The strategy with the minimum comprehensive evaluation cost function is selected from the non-dominated solution set, thereby generating the emergency strategy of the autonomous vehicle.

[0052] Specifically, the autonomous vehicle's central computing platform reverse-engineers the L1 (lethal) fault level determined in the preceding steps; along the fault simulation path of "collision with heavy truck", the system uses a causal analysis mechanism to calculate the weight of deteriorating nodes; the system removes the pseudo-correlated factor of "brief camera obstruction" because it does not directly cause loss of control, extracts the core attribution variables that cause L1 level faults, and identifies multiple fault factors that induce the fault as follows: Factor 1 "deprivation of lateral avoidance space caused by heavy truck on the right: sudden change in environmental boundary", Factor 2 "loss of front wheel hydroplaning lateral force caused by deep water accumulation: exceeding the physical limit of actuator", and Factor 3 "abnormal wheel speed signal leads to suppression of active intervention of ESP system: degradation of perception source".

[0053] The system encodes the three fault factors mentioned above as vectors [lateral space deprivation, lateral force loss, ESP suppression] and inputs them into the emergency strategy space of the autonomous vehicle. In the strategy pool, this vector triggers a set of candidate strategies with high degradation gradients, specifically activating three candidate strategies: Strategy A "emergency braking (triggering AEB) and stopping in the current lane", Strategy B "large-angle turn and lane change to the left overtaking lane", and Strategy C "linear deceleration while using redundant steering motors for fine-tuning and correction, and slowly changing lanes to the right emergency lane". The system also extracts the current execution constraint boundary: the adhesion coefficient of the waterlogged road surface is extremely low, and large-angle turns or sudden braking will trigger physical loss of control.

[0054] The autonomous vehicle performs Pareto optimization on the three candidate strategies mentioned above. For "Strategy A: Emergency Braking," its safety margin is compromised due to the possibility of rear-end collisions, severely impacting traffic efficiency and causing significant passenger impact and poor comfort. For "Strategy B: Large-Angle Lane Change," lateral force is lost on flooded roads, directly exceeding the lethal safety risk threshold. For "Strategy C: Linear Deceleration and Fine-Tuning Lane Change," it uses redundant steering motors with high-frequency micro-vibration to counteract hydroplaning, maintaining a safety risk margin above the critical value and addressing left-side traffic issues. With less flow interference and a smooth acceleration curve, passenger comfort is high. The system solves the problem in a multi-objective optimization model. Strategy B is eliminated, and strategies A and C form a Pareto non-dominated solution set. Since strategy C achieves the optimal trade-off between traffic efficiency and passenger comfort above the safety baseline, its comprehensive evaluation cost function is minimized. Finally, the system establishes strategy C as the final emergency strategy for the autonomous vehicle, namely, "linearly decelerating at a deceleration of -1.5 m / s², activating hazard lights, and flexibly changing lanes to the right into the emergency lane with a very small steering angle."

[0055] Furthermore, different target fault levels are mapped to different degradation gradients. The degradation gradients are divided according to the autonomous driving capabilities of the autonomous vehicle. At the same time, high-level faults correspond to high degradation gradient strategies that strip away perception redundancy and execution redundancy, while low-level faults correspond to low degradation gradient strategies that only restrict the operating domain. A low degradation gradient strategy that only restricts the operating domain is introduced for low-level faults.

[0056] At this point, different target fault levels are mapped to different degradation gradients. Based on the autonomous driving capability level of the autonomous vehicle, the degradation gradient is divided into at least three steps from high to low. The first degradation gradient corresponds to the full-function operating domain, which only limits the maximum vehicle speed or following distance. The second degradation gradient corresponds to the perception degradation operating domain, which removes some heterogeneous perception redundancy, switches to a heterogeneous incomplete perception mode, and simultaneously narrows the weather and road condition boundaries of the Operation Design Domain (ODD). The third degradation gradient corresponds to the minimum risk operating domain, which removes all perception redundancy and execution redundancy, and forces a degradation to a safety net control mode based on the underlying redundant actuators. The degradation gradient and the fault level are positively correlated. The higher the fault level, the larger the mapped degradation gradient, and the more stringent the system redundancy and operational freedom are removed.

[0057] When a high-level fault is identified, it is mapped to the third degradation gradient, and a high degradation gradient strategy is generated. Under this gradient, since the system determines that the vehicle faces an extreme risk of loss of control or collision, it is necessary to take aggressive degradation measures that strip away perception redundancy and execution redundancy. At this time, in the perception dimension, the main perception link that has failed or severely degraded is cut off, and non-failed "heterogeneous single-source perception data, such as relying solely on millimeter-wave radar or high-precision map priors" is forcibly called to estimate the minimum risk trajectory. In the execution dimension, the "main execution channel" that has exceeded the physical limit, such as the main braking system or main steering motor, is shielded, and the physically isolated "redundant execution channel, such as the electronic parking brake system or backup steering motor" is forcibly activated. At the cost of sacrificing the smoothness of normal driving and the completeness of functions, the underlying control to avoid fatal collisions is obtained, and emergency strategies such as emergency parking or extremely low-speed crawling are generated.

[0058] When a low-level fault is detected, it is mapped to the first or second degradation gradient, and a low degradation gradient strategy is generated. Under this gradient, the system determines that the vehicle still has complete dynamic control capabilities and core perception capabilities, with only local performance degradation. At this time, there is no need to strip away hardware-level redundancy; the operating domain is restricted only through algorithm-level constraints. For example, in the perception dimension, all heterogeneous fusion mechanisms are retained, but the confidence weight of degraded sensors is reduced. In the execution dimension, the main execution channel is retained, and the maximum longitudinal acceleration and maximum lateral acceleration thresholds of the vehicle are reduced only through the limiting operation of the dynamic controller. Conservative operating strategies such as speed-limited cruise, prohibition of autonomous lane changes, or increased following distance are generated to maximize traffic efficiency and passenger comfort while ensuring absolute safety.

[0059] Specifically, the autonomous vehicle's central computing platform, based on its hardware architecture, pre-constructs a degradation gradient system corresponding to the fault level. The first degradation gradient corresponds to "limiting vehicle speed and following distance," the second degradation gradient corresponds to "disabling visual main perception and relying on radar for degraded driving," and the third degradation gradient corresponds to "disabling main braking / main steering and activating redundant chassis hardwired control." The system sets L3 minor faults to be mapped to the first degradation gradient, L2 serious faults to the second degradation gradient, and "L1 fatal faults, hydroplaning loss of control risk" determined in the preliminary steps are directly mapped to the third degradation gradient, establishing the principle that the deeper the degradation, the more thorough the capability deprivation.

[0060] For the currently identified L1-level fatal faults in autonomous vehicles, the system maps them to the third degradation gradient and generates a high degradation gradient strategy. Since the water accumulation has caused the front wheels to hydroplan and the wheel speed signal to be abnormal, the ESP main braking intervention logic is blocked, and the system decisively executes redundancy deprivation. In the perception dimension, the system cuts off the front-view camera with a very low signal-to-noise ratio due to the rain and the lidar interfered with by the splashing water, retaining only the millimeter-wave radar with strong penetration to detect the distance to the heavy truck in front, and calling the lane line prior of the high-precision map to calculate the blind spot trajectory. In the execution dimension, the system abandons the attempt to maintain the lane by relying on front wheel steering and conventional hydraulic braking, deprives the main execution channel, and instead activates the backup redundancy channel—using rear wheel steer-by-wire or through "asymmetrical braking of the left and right wheels, using the still normal rear wheel speed sensors and calipers" to generate yaw moment, while simultaneously pulling up the electronic parking brake (EPB) to reduce speed. This strategy completely deprives the smooth redundancy of normal autonomous driving, and forcibly pulls the autonomous vehicle out of the edge of loss of control with extreme dynamic intervention.

[0061] In contrast, if an autonomous vehicle experiences only a wiper sensor malfunction in the same rainy road section, such as a low-level L3 malfunction, the system maps it to the first degradation gradient and generates a low-degradation gradient strategy. In this case, the system does not need to strip away any perception and execution redundancy; vision, radar, and lidar still maintain fully fused perception, and the main braking and main steering channels function normally. The system only restricts the operating domain at the algorithm level, forcibly limiting the maximum cruising speed from 80 km / h to 60 km / h and increasing the following distance from 1.5 seconds to 3.0 seconds, prohibiting autonomous overtaking and lane changing. The autonomous vehicle continues to cruise smoothly within the restricted operating domain without triggering underlying redundant emergency mechanisms, thus ensuring safety while avoiding unnecessary traffic efficiency losses and passenger panic.

[0062] refer to Figure 5 In step S14, the specific steps are as follows: S141: Semantic parsing of emergency strategies and extraction of multiple emergency items by combining action decoupling mechanism. Cross-matching of multiple emergency items with multiple current driving data of autonomous vehicles in different dimensions. And temporal arrangement by combining the driving constraint relationship of autonomous vehicles, thereby determining the emergency sequence of autonomous vehicles at the current moment. S142: Trigger multi-level emergency operations of the autonomous vehicle sequentially along the timeline of the emergency sequence, and introduce an online reinforcement learning mechanism during the driving process of the autonomous vehicle. Use the actual execution feedback of the multi-level emergency operations as reward and punishment signals to adaptively correct fault events, thereby gradually optimizing fault events during the driving process of the autonomous vehicle.

[0063] In the embodiments of this application, the emergency strategy is semantically parsed, and multiple emergency items are extracted by combining the action decoupling mechanism. The multiple emergency items are cross-matched with multiple current driving data of the autonomous vehicle in different dimensions, and the driving constraints of the autonomous vehicle are combined with temporal arrangement to determine the emergency sequence of the autonomous vehicle at the current moment. This takes into account the overall consideration of the driving constraints of the autonomous vehicle and ensures the accuracy of the emergency sequence of the autonomous vehicle at the current moment.

[0064] At this point, the emergency strategy is semantically parsed to extract macroscopic semantic tags representing the strategy intent, and these macroscopic semantic tags are input into a preset action decoupling mechanism. The action decoupling mechanism, based on vehicle dynamics and actuator physical boundaries, decomposes the macroscopic strategy intent into indivisible atomic operation instructions, thereby extracting multiple emergency items. Each emergency item includes a specific control object, target parameters, and execution mode. For example, the "pull over" strategy intent is decoupled into multiple independent emergency items such as "activate hazard warning lights," "linearly reduce longitudinal acceleration," "asynchronously apply yaw moment," and "anchor the vehicle at the target position."

[0065] The system acquires multiple current driving data of the autonomous vehicle in real time across different dimensions, including at least longitudinal kinematics, lateral dynamics, and chassis pose. Multiple emergency items are extracted and cross-matched with the current driving data. The target parameters of the emergency items are compared with the measured values ​​of the corresponding dimensions in the current driving data. The system calculates the dynamic control margin and actuator availability margin required for each emergency item to transition from the current state to the target state. Through cross-matching, conflicting items that are physically impossible to execute due to limitations in the current driving state (such as tire adhesion reaching its limit) are eliminated. The control gain of executable items is adaptively calibrated to ensure that the control commands of each emergency item do not exceed the current vehicle dynamic stability boundary.

[0066] The driving constraints of the autonomous vehicle are obtained, including at least "mandatory traffic regulations, such as the requirement to activate the turn signal for a specified duration before changing lanes," "physical prior constraints of the actuators, such as the pressure build-up delay of the braking system," and "vehicle kinematic coherence constraints, such as the dynamic decoupling requirement of decelerating before turning." These driving constraints are used as the construction rules for a directed acyclic graph (DAG). Multiple emergency items after cross-matching are used as nodes, and the triggering order and time delay determined by the constraints are used as directed edges. Topological sorting is then performed. During the sorting process, the logical preconditions between nodes are strictly verified to eliminate circular dependencies and conflicting edges. This arranges the discrete emergency items into a continuous execution flow that strictly follows temporal logic and physical laws, ultimately determining the emergency sequence of the autonomous vehicle at the current moment.

[0067] Specifically, the autonomous vehicle's central computing platform performs semantic analysis on the high-degradation gradient emergency strategy generated in the previous steps, which involves "using redundant actuators to linearly decelerate and flexibly change lanes to the emergency lane." The system identifies the macro-intention of this strategy as "safely avoiding a heavy truck ahead and pulling over to the side of the road on a low-adhesion, waterlogged surface." It then activates the action decoupling mechanism, breaking down this macro-intention into four independent atomized emergency items: Item 1 "Activate hazard warning flashers: hazard lights," Item 2 "Set the longitudinal target deceleration calculated based on millimeter-wave radar and high-precision maps to -1.5 m / s²," Item 3 "Use redundant rear-wheel steering or asymmetric braking to generate a weak yaw rate of 0.5 degrees / second," and Item 4 "Trigger EPB caliper parking when the vehicle speed drops to 20 km / h."

[0068] The autonomous vehicle acquires real-time driving data: longitudinal speed 80km / h, current yaw rate 1.5 degrees / second, front wheel steering angle 3 degrees, and estimated road adhesion coefficient 0.3. The system cross-matches the above emergency items with the driving data. For item two, the system compares the target deceleration of -1.5m / s² with the low adhesion coefficient of 0.3 and calculates that conventional hydraulic braking may trigger ABS anti-lock braking and fail to build up pressure linearly. Therefore, the execution mode of item two is adaptively corrected to "adopting a combined deceleration mode of rear axle regenerative braking + light hydraulic braking". For item three, the system determines that the front wheels are already at the hydroplaning critical point. If the front wheel steering angle is further increased, it will inevitably lose control. Therefore, it is confirmed that item three must be decoupled from front wheel steering dependence and matched to an executable scheme of "relying only on the difference in braking torque between the left and right wheels to generate yaw". This eliminates physically infeasible actions and completes the dynamic calibration of control parameters.

[0069] The system incorporates driving constraints to sequence the above items. Based on mandatory traffic regulations, item one must be executed at least 3 seconds earlier than item three. Based on vehicle kinematic continuity constraints, under high-speed and low-adhesion conditions at 80 km / h, longitudinal deceleration (item two) must be established first to shift the vehicle load forward and increase rear wheel grip before yaw moment (item three) can be safely applied for lane changing. Based on actuator physical prior constraints, item four (EPB parking) can only intervene after the longitudinal vehicle speed is below 20 km / h (the result of item two). The system generates the final emergency sequence through topological sorting: [T0 time: Trigger item 1: Turn on hazard lights] > [T0 to T3 time: Trigger item 2: Linear deceleration, vehicle speed decreases from 80km / h] > [T3 time: Meet the regulatory light delay constraint, trigger item 3: Apply slight yaw lane change] > [Tx time: Vehicle speed decreases to 20km / h, trigger item 4: EPB anchoring parking]. This emergency sequence ensures that under extreme instability boundaries, the actuators of the autonomous vehicle have strict logic, compliant timing, and do not conflict with each other, allowing it to smoothly enter the emergency lane.

[0070] Furthermore, multi-level emergency operations of the autonomous vehicle are triggered sequentially along the timeline of the emergency sequence. An online reinforcement learning mechanism is introduced during the driving process of the autonomous vehicle. The actual execution feedback of the multi-level emergency operations is used as a reward and punishment signal to adaptively correct fault events. This gradually optimizes fault events during the driving process of the autonomous vehicle. At the same time, the emergency strategy is further controlled, and the driving constraints of multiple emergency items and the autonomous vehicle are fully considered, which improves the accuracy of the emergency sequence and realizes multi-level emergency operations of the autonomous vehicle.

[0071] At this point, multi-level emergency operations of the autonomous vehicle are triggered sequentially along the timeline of the emergency sequence. Using the preset timestamps of each discrete emergency item in the emergency sequence as a synchronization benchmark, the current system time is monitored through real-time interruption or time polling mechanisms. When the system time reaches the trigger timestamp of a certain emergency item, the central computing platform sends control commands to the corresponding underlying drive-by-wire actuators, while continuously monitoring the execution state machine of the commands. During the execution of the current level of emergency operation, the triggering conditions for the next level of emergency operation are pre-locked, thereby achieving a smooth relay and seamless transition of multi-level emergency operations in the time dimension, ensuring the continuity of the vehicle's dynamic response.

[0072] An online reinforcement learning mechanism is introduced during the driving process of an autonomous vehicle to collect real-time feedback data on the actual execution of multi-level emergency operations. This feedback data includes the deviation between the actual output of the actuator and the command target, the rate of change of vehicle state parameters, and the evolution trend of external environmental risk indicators. The actual feedback data is mapped to a preset reward and punishment function to calculate the immediate reward and punishment signal for the current emergency operation. If the actual feedback indicates that the vehicle dynamics are stabilizing and the risk indicators are decreasing, a positive reward signal is generated. If the feedback indicates that the actuator response is lagging, the vehicle attitude is diverging, or it is approaching the physical boundary, a negative punishment signal is generated. The reward and punishment signals quantitatively evaluate the effectiveness of the current emergency operation in eliminating the risk of failure.

[0073] Using reward and penalty signals as the driving force for gradient updates, the fault events identified in the previous steps are adaptively corrected. At this point, the implicit feature parameters representing the degree of fault deterioration and evolution trend in the fault events are used as the weights of the policy to be optimized in reinforcement learning. The policy gradient is calculated using the reward and penalty signals, and the implicit feature parameters are updated in reverse along the gradient direction. When a negative penalty signal is received, the weights of the fault evolution path that leads to attitude divergence are suppressed, and the intensity of subsequent emergency operations that have not been triggered is adjusted accordingly. When a positive reward signal is received, the weights of the current fault state transition that tends to be stable are enhanced, and even the intervention magnitude of subsequent emergency operations is reduced. Through the above continuous online iteration and parameter updates during the driving process, the fault event model gradually approaches the real physical evolution law, thereby realizing the adaptive correction and gradual optimization of fault events during the driving process of autonomous vehicles.

[0074] Specifically, the central computing platform of the autonomous vehicle triggers multiple levels of emergency operations sequentially along the emergency sequence timeline generated by the preceding steps. At time T0, the system triggers the first-level operation, "activating the hazard warning lights and initiating linear deceleration with a target deceleration of -1.5 m / s²", and the underlying brake-by-wire system begins to build up pressure. At time T3, the system confirms that the deceleration operation has taken effect and meets the lighting timing constraints, triggering the second-level operation, "applying a slight yaw rate to change lanes to the right", and the rear-wheel redundant steering mechanism or asymmetric braking system begins to intervene. At the subsequent time Tx, it prepares to trigger the third-level operation, "EPB parking when the vehicle speed drops to 20 km / h". Each level of operation is strictly relayed along the timeline, avoiding the chassis control logic confusion caused by multiple concurrent commands.

[0075] During the aforementioned driving process, the autonomous vehicle employs an online reinforcement learning mechanism to construct reward and penalty signals. When performing the second-level operation, "applying a slight yaw lane change," the system collects real-time feedback on the actual execution: it discovers that due to the deeper water than initially estimated, the rear wheels also exhibit slight hydroplaning, resulting in an actual yaw rate of only 0.2 degrees / second, significantly lower than the target of 0.5 degrees / second, and the vehicle's center of gravity sideslip angle begins to slowly diverge. Based on this, the reward and penalty function calculates the current instantaneous reward and penalty signal as a strong negative penalty, such as -1.5, indicating that the current lane change action failed to effectively correct the trajectory and worsened stability. Conversely, if the vehicle accurately tracks the 0.5 degrees / second yaw and the sideslip angle converges during the lane change, a positive reward is output, such as +0.8.

[0076] The autonomous vehicle uses this strong negative penalty signal as a driving force to adaptively correct the "fault event" model determined in the previous steps, namely "front wheel hydroplaning leading to loss of lateral force accompanied by ESP suppression". Through policy gradient backpropagation, the system identifies that the weight parameters of "road adhesion coefficient estimate (0.3)" and "rear wheel grip margin" in the fault event model are overly optimistic. Based on this, the system corrects the fault event online, reducing the road adhesion coefficient weight to 0.2 and changing the fault evolution trend from "linear deterioration" to "exponential deterioration". In response to this optimized fault event, the system immediately adaptively adjusted the third-level operation that had not yet been triggered: abandoning the original conservative plan of "reducing to 20km / h before parking", it instead intervened in advance with EPB (electronic parking brake) to anchor when the vehicle speed dropped to 35km / h, and stopped any subsequent lane change fine-tuning actions. Through this online learning and correction during the driving process, the autonomous vehicle effectively curbed the divergence trend caused by rear wheel hydroslip, and finally safely stopped in the emergency lane under the corrected fault cognition framework, realizing the gradual optimization and closed-loop convergence of the fault event in dynamic evolution.

[0077] Please see Figure 6The multi-level emergency response system based on autonomous driving is applied to the aforementioned multi-level emergency response method based on autonomous driving; the multi-level emergency response system based on autonomous driving includes: The fault identification module 21 is used to acquire the operating data and external environment data of the autonomous vehicle, and combine the fault signals of the autonomous vehicle to determine multiple fault data combinations, and determine the corresponding fault content based on the identification of multiple fault data combinations. The fault level module 22 is used to mark the current driving state of the autonomous vehicle, determine the fault matrix of the autonomous vehicle in combination with various fault contents, determine the corresponding fault events based on the iteration of the fault matrix, and determine the fault level of the autonomous vehicle in combination with the driving scenario of the autonomous vehicle. Emergency strategy module 23 is used to determine multiple fault factors based on the traceability of the fault level. Multiple fault factors are dynamically matched in the emergency strategy space of the autonomous vehicle to generate an emergency strategy for the autonomous vehicle. Different target fault levels correspond to different degradation gradient emergency strategies. The multi-level emergency module 24 is used to determine multiple emergency items based on the analysis of the emergency strategy, and to determine the emergency sequence of the autonomous vehicle at the current moment in combination with the driving constraints of the autonomous vehicle. It triggers multi-level emergency operations of the autonomous vehicle along the emergency sequence and gradually optimizes fault events during the driving process of the autonomous vehicle.

[0078] It should be noted that although multiple modules are mentioned in the detailed description above, this division is not mandatory; in fact, according to the embodiments of this disclosure, the features and functions of two or more modules or described above can be embodied in one module; conversely, the features and functions of one module described above can be further divided into multiple modules to be embodied.

[0079] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the disclosure herein; this application is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein; the specification and embodiments are to be considered exemplary only.

[0080] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A multi-level emergency response method for faults under autonomous driving, characterized in that, include: The system acquires operational data and external environmental data of autonomous vehicles, and combines these with fault signals of the autonomous vehicles to determine multiple fault data combinations. Based on the identification of these multiple fault data combinations, the corresponding fault content is determined. The current driving state of the autonomous vehicle is marked, and the fault matrix of the autonomous vehicle is determined by combining various fault contents. The corresponding fault events are determined by iterating the fault matrix, and the fault level of the autonomous vehicle is determined by combining the driving scenario of the autonomous vehicle. Based on the tracing of the fault level, multiple fault factors are identified. These multiple fault factors are dynamically matched in the emergency strategy space of the autonomous vehicle to generate an emergency strategy for the autonomous vehicle. Different target fault levels correspond to different degradation gradient emergency strategies. Based on the analysis of the emergency strategy, multiple emergency items are identified, and the emergency sequence of the autonomous vehicle at the current moment is determined in combination with the driving constraints of the autonomous vehicle. Multi-level emergency operations of the autonomous vehicle are triggered along the emergency sequence, and fault events are gradually optimized during the driving process of the autonomous vehicle.

2. The multi-level emergency response method for unmanned driving based on claim 1, characterized in that, The process of acquiring operational data and external environmental data of the autonomous vehicle, and combining this data with fault signals from the autonomous vehicle to determine multiple fault data combinations, and then determining the corresponding fault content based on the identification of these multiple fault data combinations, includes: While the autonomous vehicle is driving in autonomous driving mode, the system acquires the vehicle's operational data. At the same time, the system collects the external environment data of the human-driven vehicle through the vehicle's external sensing array. The data is then combined with the autonomous vehicle's operational data for spatiotemporal alignment to map it to a high-dimensional state space.

3. The multi-level emergency response method for unmanned driving based on claim 2, characterized in that, The process of acquiring operational data and external environmental data of the autonomous vehicle, and determining multiple fault data combinations based on the fault signals of the autonomous vehicle, and determining the corresponding fault content based on the identification of multiple fault data combinations, further includes: In this high-dimensional state space, fault signals of autonomous vehicles are collected in real time. Multiple fault markers are determined based on the analysis of these fault signals. Cross-domain feature extraction is performed by combining the autonomous vehicle's operating data and external environmental data to determine multiple fault data combinations that characterize different failure mechanisms. Correlation topology identification is performed on multiple fault data combinations to capture the spatiotemporal coupling characteristics and implicit transmission links between each fault data combination, thereby determining the fault content that characterizes the essential causes and manifestations of the fault.

4. The multi-level emergency response method for unmanned driving based on claim 1, characterized in that, The system marks the current driving state of the autonomous vehicle and determines a fault matrix for the autonomous vehicle by combining various fault contents. It then determines the corresponding fault events based on the iteration of this fault matrix and determines the fault level of the autonomous vehicle by combining the driving scenario of the autonomous vehicle, including: Real-time monitoring of autonomous vehicles is conducted to acquire multiple current driving data points of the autonomous vehicles in different dimensions. The current driving status of the autonomous vehicles is determined based on the identification of multiple current driving data points. Furthermore, tensor splicing is performed in a multi-dimensional feature space in combination with various fault contents to construct a fault matrix that represents the full-dimensional fault status.

5. The multi-level emergency response method for unmanned driving based on claim 4, characterized in that, The process of marking the current driving state of the autonomous vehicle, determining a fault matrix for the autonomous vehicle based on various fault contents, determining corresponding fault events based on the iteration of the fault matrix, and determining the fault level of the autonomous vehicle based on the driving scenario of the autonomous vehicle also includes: The fault matrix is ​​iterated at multiple levels, and the driving failure path of the autonomous vehicle is predicted during the iteration process. Multiple driving failure contents are identified by tracing along the driving failure path. At the same time, the driving scenario of the autonomous vehicle is obtained, and a corresponding fault framework is constructed by combining multiple driving failure contents. Furthermore, fault pre-simulation is carried out by combining the driving conflict situation of the autonomous vehicle, so as to determine the fault level of the autonomous vehicle.

6. The multi-level emergency response method for unmanned driving based on claim 1, characterized in that, The process involves identifying multiple fault factors based on the fault level, and dynamically matching these factors within the autonomous vehicle's emergency strategy space to generate an emergency strategy for the vehicle. Different target fault levels correspond to different degradation gradients in the emergency strategy, including: The fault level is traced back, and multiple fault factors that induce the fault are identified by combining the causal analysis mechanism during the tracing process. These multiple fault factors are input into the emergency strategy space of the autonomous vehicle, so as to perform Pareto optimization among driving safety, traffic efficiency and passenger comfort to generate the emergency strategy of the autonomous vehicle.

7. The multi-level emergency response method for unmanned driving based on claim 6, characterized in that, The process of identifying multiple fault factors based on the fault level, dynamically matching these factors within the autonomous vehicle's emergency strategy space to generate an emergency strategy for the autonomous vehicle, wherein different target fault levels correspond to different degradation gradients in the emergency strategy, further includes: Different target fault levels are mapped to different degradation gradients. The degradation gradients are divided according to the autonomous driving capabilities of autonomous vehicles. At the same time, high-level faults correspond to high degradation gradient strategies that strip away perception and execution redundancy, while low-level faults correspond to low degradation gradient strategies that only restrict the operating domain.

8. The multi-level emergency response method for unmanned driving based on claim 1, characterized in that, The process involves determining multiple emergency items based on the analysis of the emergency strategy, and combining this with the driving constraints of the autonomous vehicle to determine the emergency sequence for the autonomous vehicle at the current moment. Multi-level emergency operations of the autonomous vehicle are triggered along this emergency sequence, and fault events are progressively optimized during the autonomous vehicle's driving process, including: Semantic parsing of emergency strategies is performed, and multiple emergency items are extracted by combining action decoupling mechanism. These emergency items are cross-matched with multiple current driving data of autonomous vehicles in different dimensions, and time sequence arrangement is performed in combination with the driving constraints of autonomous vehicles to determine the emergency sequence of autonomous vehicles at the current moment.

9. The multi-level emergency response method for unmanned driving based on claim 8, characterized in that, The process of determining multiple emergency items based on the analysis of the emergency strategy, determining the emergency sequence of the autonomous vehicle at the current moment by combining the driving constraints of the autonomous vehicle, triggering multi-level emergency operations of the autonomous vehicle along the emergency sequence, and gradually optimizing fault events during the driving process of the autonomous vehicle also includes: The autonomous vehicle's multi-level emergency operations are triggered sequentially along the timeline of the emergency sequence. An online reinforcement learning mechanism is introduced during the autonomous vehicle's driving process. The actual execution feedback of the multi-level emergency operations is used as a reward and punishment signal to adaptively correct fault events, thereby gradually optimizing fault events during the autonomous vehicle's driving process.

10. A multi-level emergency response system for unmanned driving, characterized in that, The multi-level emergency response system based on unmanned driving is applied to the multi-level emergency response method based on unmanned driving as described in any one of claims 1-9; The multi-level emergency response system based on autonomous driving includes: The fault identification module is used to acquire the operating data and external environment data of the autonomous vehicle, and combine them with the fault signals of the autonomous vehicle to determine multiple fault data combinations, and determine the corresponding fault content based on the identification of multiple fault data combinations. The fault level module is used to mark the current driving state of the autonomous vehicle, determine the fault matrix of the autonomous vehicle by combining various fault contents, determine the corresponding fault events by iterating the fault matrix, and determine the fault level of the autonomous vehicle by combining the driving scenario of the autonomous vehicle. The emergency strategy module is used to identify multiple fault factors based on the traceability of the fault level. Multiple fault factors are dynamically matched in the emergency strategy space of the autonomous vehicle to generate the emergency strategy of the autonomous vehicle. Different target fault levels correspond to different degradation gradient emergency strategies. The multi-level emergency module is used to determine multiple emergency items based on the analysis of the emergency strategy, and to determine the emergency sequence of the autonomous vehicle at the current moment by combining the driving constraints of the autonomous vehicle. It triggers multi-level emergency operations of the autonomous vehicle along the emergency sequence and gradually optimizes fault events during the driving process of the autonomous vehicle.