Vehicle control method, device, vehicle, storage medium and program product

CN122585245APending Publication Date: 2026-08-18ZHEJIANG GEELY HLDG GRP CO LTD +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202611087193.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-21
Publication Date
2026-08-18

AI Technical Summary

Technical Problem

这种来回反复的控制冲突,不仅严重影响了用户的主观体验和满意度,在某些行车场景(例如高速公路行驶时车窗被自动打开或关闭)下,甚至可能分散驾驶员注意力或造成驾驶风险,从而影响行车安全

Benefits of technology

在本申请中,通过将用户实时手动操作的操作特征融合量化为意图强度值,并结合预设基础保护时长以及车载设备独有的设备物理因子来动态生成保护期时长,进而依据保护期内的进度区间对自动控制指令执行分级避让动作。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122585245A_ABST
    Figure CN122585245A_ABST
Patent Text Reader

Abstract

The application discloses a vehicle control method and device, a vehicle, a storage medium and a program product, and relates to the technical field of human-computer interaction. The application discloses a vehicle-mounted strategy intelligent avoidance and cooperative decision-making method based on user operation perception, which comprises the following steps: in response to a user manual operation event, operation characteristics are fused and quantified to obtain an intention intensity value; a preset basic protection time length, the intention intensity value and device physical factors are used to dynamically calculate a protection period time length, the device physical factors are composed of weighted fusion of execution delay, ergonomics sensitivity and driving safety influence parameters; when an automatic control instruction is received within the protection period, a hierarchical avoidance action is performed according to a progress interval. The application dynamically calculates the protection period by cooperating the intention intensity and the device physical characteristics, realizes the leap from a fixed cooling period to a refined flexible avoidance, effectively solves the human-vehicle mutual interference problem, and takes into account the user control sovereignty and the availability of intelligent strategies.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of human-computer interaction, and more particularly to vehicle control methods, vehicle control devices, vehicles, storage media, and computer program products. Background Technology

[0002] With the rapid development of smart cockpit technology, vehicles are gradually acquiring the ability to automatically control in-vehicle equipment (such as windows, air conditioning, seats, lights, and volume) based on scenario-based policy scripts delivered from the cloud or built into the vehicle's infotainment system. This automated control aims to improve the comfort, convenience, and safety of passengers. However, in practical applications, conflicts often arise between the automatic control of policy scripts (originating from the policy layer) and the real-time manual operation of the user (driver or passenger) on the same device, causing the so-called "human-vehicle interference" problem.

[0003] This "human-vehicle interference" manifests as follows: after a user manually adjusts a device in the car based on their own feelings or temporary needs, the executing scenario policy script may immediately modify the device's state back to the preset policy value without the user's knowledge or expectation, thus overriding the user's intention. For example, if a user manually adjusts the air conditioning temperature from 24°C to a cooler 20°C, an "energy-saving cooling" policy script will immediately activate and change the temperature back to the preset energy-saving point; or if a user opens a window to a specific position for ventilation, an "automatic window closing in rainy weather" policy will immediately force the window to close upon detecting a few raindrops. This back-and-forth control conflict not only seriously affects the user's subjective experience and satisfaction, but in certain driving scenarios (such as windows automatically opening or closing while driving on the highway), it may even distract the driver or create driving risks, thereby affecting driving safety.

[0004] The above content is only used to help understand the technical solution of this application and does not represent an admission that the above content is prior art. Summary of the Invention

[0005] The main objective of this application is to provide a vehicle control method, a vehicle control device, a vehicle, a storage medium, and a computer program product, which aims to solve the technical problem of human-vehicle interference.

[0006] To achieve the above objectives, this application proposes a vehicle control method, the vehicle control method comprising: In response to user manual operation events of in-vehicle devices, the operation characteristics of the current manual operation are fused and quantified to calculate the intent intensity value that represents the intensity of the user's operation intent. Based on the preset basic protection duration, the intent strength value, and the device physical factor corresponding to the vehicle device, the protection period duration for the automatic control command is calculated. The automatic control command is the command that the vehicle device is automatically controlled by the preset scenario strategy script after the user's manual operation event. The protection period duration is used to constrain the immediate execution of the automatic control command. When the automatic control command is received within the protection period, determine the progress interval in which the moment of receiving the automatic control command falls within the protection period; Based on the progress interval, a first execution strategy corresponding to the automatic control command is determined, and the on-board equipment is executed with reference to the first execution strategy to respond to the automatic control command.

[0007] In one embodiment, the operational features include the adjustment range of the current manual operation on the in-vehicle device, the number of historical manual operations within a preset historical time window prior to the current manual operation, and the time interval between the most recent historical manual operation and the current manual operation; the step of fusing and quantizing the operational features of the current manual operation to calculate an intent intensity value characterizing the intensity of the user's operational intent includes: The adjustment range factor is determined based on the proportion of the adjustment range to the preset maximum adjustment range of the vehicle-mounted device; Determine the operation frequency factor based on the historical number of operations; Determine the time decay factor based on the time interval; The adjustment amplitude factor, the operation frequency factor, and the time decay factor are weighted and fused to obtain the intention intensity value of the current manual operation.

[0008] In one embodiment, the step of calculating the protection period for an automatic control command based on a preset basic protection duration, the intent strength value, and the device physical factor corresponding to the on-board device includes: When the number of historical operations meets the preset exploration judgment condition, the current manual operation is determined to be in the exploration operation mode. The preset exploration judgment condition includes: the number of historical operations on the vehicle device within the preset historical time window is greater than or equal to a preset number threshold. In the exploration operation mode, the protection period duration is extended to obtain an extended protection period duration.

[0009] In one embodiment, before the step of calculating the protection period duration for the automatic control command based on the preset basic protection duration, the intent strength value, and the device physical factor corresponding to the on-board device, the method further includes: The execution latency parameter, ergonomic sensitivity parameter, and driving safety impact parameter of the vehicle-mounted device are obtained. The execution latency parameter represents the time required for the vehicle-mounted device to perform a complete action. The ergonomic sensitivity parameter represents the user's perception sensitivity to the adjustment of the vehicle-mounted device. The driving safety impact parameter represents the degree of impact of the adjustment of the vehicle-mounted device on driving safety. The execution delay parameter, the ergonomic sensitivity parameter, and the driving safety impact parameter are weighted and fused to obtain the device physical factor corresponding to the vehicle-mounted device.

[0010] In one embodiment, after determining the progress interval within the protection period when the automatic control command is received, the method further includes: Determine the urgency of the current operating scenario of the vehicle when the automatic control command is received; Based on the intent strength value and the urgency of the scenario, a collaborative decision is made to determine the second execution strategy corresponding to the automatic control command, and the vehicle-mounted device is executed a second execution action in response to the automatic control command with reference to the second execution strategy.

[0011] In one embodiment, after the step of making a collaborative decision based on the intent strength value and the scene urgency to determine the second execution strategy corresponding to the automatic control command, the method further includes: Determine whether to perform a second execution action on the on-board equipment in response to the automatic control command, referring to the second execution strategy; In the first and second execution actions, a third execution action is determined by a preset arbitration rule, and the third execution action is performed on the vehicle-mounted device.

[0012] In one embodiment, after the step of performing a first execution action in response to the automatic control command on the on-board device with reference to the first execution strategy, the method further includes: Collect user feedback data on the automatic control command, wherein the final feedback data includes at least one of the following types: acceptance type, indicating that the user accepts the execution action corresponding to the automatic control command; rejection type, indicating that the user rejects the execution action corresponding to the automatic control command; readjustment type, indicating that the user manually operates the same in-vehicle device again within the protection period; and no intervention type, indicating that the user does not intervene in the automatic execution of the automatic control command after the protection period ends. Based on the final feedback data, the basic parameters used to calculate the protection period duration are adjusted, wherein the basic parameters include at least one of the basic duration of the protection period and the fusion weight used to calculate the physical factors of the device.

[0013] Furthermore, to achieve the above objectives, this application also proposes a vehicle control device, the vehicle control device comprising: The first calculation module is used to respond to user manual operation events of the in-vehicle device, fuse and quantify the operation characteristics of the current manual operation, and calculate the intent intensity value that represents the intensity of the user's operation intent. The second calculation module is used to calculate the protection period for the automatic control command based on the preset basic protection duration, the intent strength value, and the device physical factor corresponding to the vehicle device. The automatic control command is an instruction for the vehicle device to be automatically controlled by a preset scenario strategy script after the user's manual operation event. The protection period is used to constrain the immediate execution of the automatic control command. The determination module is used to determine the progress interval within the protection period when the automatic control command is received during the protection period. The execution module is used to determine the first execution strategy corresponding to the automatic control command based on the progress interval, and to perform a first execution action on the vehicle-mounted equipment in response to the automatic control command with reference to the first execution strategy.

[0014] In addition, to achieve the above objectives, this application also proposes a vehicle comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the vehicle control method described above.

[0015] In addition, to achieve the above objectives, this application also proposes a storage medium, which is a computer-readable storage medium, on which a computer program is stored, and which, when executed by a processor, implements the steps of the vehicle control method described above.

[0016] In addition, to achieve the above objectives, this application also provides a computer program product, which includes a computer program that, when executed by a processor, implements the steps of the vehicle control method described above.

[0017] One or more technical solutions proposed in this application have at least the following technical effects: In this application, the operation characteristics of the user's real-time manual operation are quantified into an intent intensity value, and the protection period is dynamically generated by combining the preset basic protection duration and the unique physical factors of the vehicle equipment. Then, the automatic control command is executed with graded avoidance actions according to the progress interval within the protection period.

[0018] First, it significantly reduces the interference rate between people and vehicles, improving the user experience. Unlike existing technologies that use a fixed cooldown period to apply a one-size-fits-all approach to avoidance of all devices and operating scenarios, this method dynamically calculates the most reasonable protection period length based on the strength of the user's intent in a single operation (such as fine-tuning or significant adjustment) and the characteristics of the device itself. This ensures that the protection period closely matches the user's actual expectations, effectively preventing the policy script from immediately overwriting the user's just-completed operation, while also avoiding an excessively long, ineffective protection period that renders the intelligent policy function useless.

[0019] Secondly, this method achieves reliable quantification and precise avoidance of user operation intentions. Each manual user operation is calculated using a multi-dimensional feature fusion approach, incorporating adjustment magnitude, operation frequency, and operation duration to determine a precise intent strength value. This strength metric fully reflects the intensity of the user's underlying intent: minor, temporary adjustments (such as volume tweaks) produce only weak intent strength, with a short protection period, allowing for rapid policy recovery; while repeated exploratory adjustments or significant preference adjustments produce stronger intent strength, extending the protection period and fully respecting the depth of user operations. This positive correlation between intent quantification and avoidance duration ensures interpretability and high accuracy in avoidance decisions.

[0020] Finally, differentiated adaptation to the physical characteristics of different devices enables refined obstacle avoidance management. This method introduces device physical factors (covering execution latency, ergonomic sensitivity, and driving safety impact coefficients), abstracting the cognitive / physical costs to users from adjusting different devices into calculable numerical parameters. Therefore, users can clearly perceive that for devices like car windows, which are deeply related to safety and highly sensitive to users, the system provides a longer protection period, fully respecting the user's control over these core devices; while for devices with low sensitivity and low safety impact, such as volume and ambient lighting, the protection period is shorter, and the strategy function can still be used frequently. This method of differentiated obstacle avoidance at the device level is a newly introduced technical approach, fundamentally solving the shortcomings of existing technologies that use a single cooling-off period and cannot adapt to multiple types of devices. Attached Figure Description

[0021] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0022] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0023] Figure 1 This is a first flowchart illustrating the first embodiment of the vehicle control method of this application; Figure 2 This is a second flowchart illustrating the first embodiment of the vehicle control method of this application; Figure 3 This is a third flowchart provided for the first embodiment of the vehicle control method of this application; Figure 4 This is a schematic diagram of the fourth process provided in the first embodiment of the vehicle control method of this application; Figure 5 This is a fifth flowchart illustrating the first embodiment of the vehicle control method of this application; Figure 6 This is a sixth flowchart provided for the first embodiment of the vehicle control method of this application; Figure 7 This is a seventh flowchart illustrating the first embodiment of the vehicle control method of this application; Figure 8 This is a schematic diagram of the module structure of the vehicle control device according to an embodiment of this application; Figure 9 This is a schematic diagram of the equipment structure of the hardware operating environment involved in the vehicle control method in the embodiments of this application.

[0024] The purpose, features, and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0025] It should be understood that the specific embodiments described herein are merely illustrative of the technical solutions of this application and are not intended to limit this application.

[0026] To better understand the technical solution of this application, a detailed description will be provided below in conjunction with the accompanying drawings and specific implementation methods.

[0027] Currently, to address the issue of "human-vehicle interference," existing technologies primarily employ a fixed cooling-off period (or cooling window) approach. For example, background technology document CN112757922A discloses a method that implements a fixed-duration cooling-off window for strategy execution based on vehicle status (such as vehicle speed, gear position, energy management status, etc.), during which automatic strategy execution is prohibited. This method adjusts the priority of strategy execution based on vehicle status, mitigating the conflict to some extent.

[0028] However, the aforementioned existing technologies have obvious technical defects, specifically: First, existing systems cannot accurately perceive and quantify users' real-time operational intentions. They typically only record the final state value of the device, failing to effectively distinguish whether a change in device state originates from "the user's physical manual operation" (e.g., triggered by a touchscreen, physical button, or voice command) or "automatic adjustments by the policy engine." Without clearly identifying the source of the operation, it's impossible to accurately determine when protection needs to be activated for the user's actual actions. Furthermore, current technology lacks pattern recognition for users performing multiple operations within a short period (e.g., repeatedly fine-tuning to find the optimal value within a 5-minute window), and it cannot quantify and integrate multi-dimensional features such as adjustment magnitude, operation frequency, and operation novelty to form a separate quantifiable "intent strength" indicator. Therefore, it cannot accurately reflect the strength of the user's underlying intentions.

[0029] Second, the strategy execution avoidance mechanism adopts a fixed, one-size-fits-all cooling-off period. The existing solution uses a preset, fixed cooling-off period (e.g., uniformly set at 5 minutes), which does not dynamically change based on the intensity of the user's single operation intention. More importantly, this fixed cooling-off period completely ignores the physical characteristics and operational attributes of the controlled device itself. The physical execution latency of different devices such as car windows, air conditioning temperature, and volume, the user's ergonomic sensitivity, and the impact of device state changes on driving safety all have fundamental differences. Using a uniform, fixed cooling-off period to constrain the strategy execution of all devices is imprecise and unreasonable. This leads to an excessively long protection period on devices where users expect quick policy effects (such as volume adjustment), resulting in a degraded intelligent experience; while on devices where users are deeply involved, an excessively short protection period leads to frequent conflicts. Statistics show that the user intervention rate is over 40% when the policy overrides the user's manual adjustment.

[0030] Third, there is a lack of tiered response and collaborative decision-making capabilities based on the urgency of the scenario. When faced with a policy request, the existing solution either completely prohibits execution during the cooling-off period or directly enforces it after the cooling-off period, lacking an intermediate state. It cannot collaboratively judge the "urgency level of the current scenario" (e.g., an emergency scenario involving highway driving safety vs. a comfort scenario involving adjusting ambient lighting) and the "strength of the user's intent" in a two-dimensional decision matrix. In particular, the solution lacks a safety emergency coverage mechanism to, in the event of a critical situation endangering driving safety (e.g., windows unexpectedly fully open while driving at high speed), bypass the user's protection period restrictions in a justified and restrained manner, at least informing them of the risk in the form of a strong reminder, forming a safety-first control loop.

[0031] Fourth, the avoidance parameters are statically fixed and lack adaptive learning based on user feedback. The cooldown period length and related parameters in existing solutions are all static preset values, and they do not undergo online, device-level adjustments and optimizations based on actual user feedback such as acceptance or rejection of strategy suggestions, or readjustments during the protection period. This prevents the system from gradually evolving to a parameter state that best balances avoidance effectiveness and intelligence based on the actual usage habits of the user group.

[0032] In summary, existing technologies lack an intelligent obstacle avoidance method capable of accurately quantifying and perceiving user operational intentions, dynamically generating protection periods based on device physical characteristics, and making decisions in conjunction with the urgency of the scenario. In particular, they lack a mechanism for safely overriding avoidance rules in emergency safety scenarios. This is the fundamental reason why the current "human-vehicle interference" problem is difficult to solve effectively. Therefore, how to provide a more intelligent, refined, and safe in-vehicle strategy avoidance and collaborative decision-making method has become an urgent technical problem to be solved.

[0033] The main solution to this problem, according to the embodiments of this application, is: In this embodiment, for ease of description, the following description uses the vehicle control unit as the executing entity.

[0034] Existing technologies, when dealing with conflicts between automated policy script control and real-time manual user operations, typically employ a fixed-duration cooling-off period to intercept policy execution in a "one-size-fits-all" manner. This approach completely ignores the varying strengths of the true intent behind a single user action and fails to differentiate between the fundamental differences in physical execution latency, ergonomic sensitivity, and driving safety impacts of various in-vehicle devices. Consequently, frequent instances of human-vehicle interference arise where a user's recently completed manual adjustment is incorrectly overwritten by policy errors, resulting in an excessively high rate of user manual intervention.

[0035] This application provides a solution that enables the vehicle control unit to obtain an intent strength value that truly reflects the strength of the user's operational intent by fusing and quantifying the operational characteristics of the user's manual operation. Based on this intent strength value and the device physical factors that cover the physical characteristics of the device, a differentiated protection period is dynamically calculated for each user operation. Then, within different progress intervals of the protection period, graded and adaptive avoidance actions are executed on the automatic control commands of the strategy. This achieves a leap from fixed-duration indiscriminate interception to refined and flexible avoidance based on the coordination of intent strength and device physical characteristics. While ensuring the user's control sovereignty, the availability of the vehicle's intelligent strategy is maximized, and the human-vehicle interference rate is significantly reduced.

[0036] It should be noted that the executing entity in this embodiment can be a computing service device with data processing, network communication, and program execution functions, such as a tablet computer, personal computer, or mobile phone, or an electronic device or vehicle capable of performing the above functions. The following description uses a vehicle as an example to illustrate this embodiment and the subsequent embodiments.

[0037] Based on this, embodiments of this application provide a vehicle control method, referring to... Figure 1 , Figure 1 This is a flowchart illustrating the first embodiment of the vehicle control method of this application.

[0038] In this embodiment, the vehicle control method includes steps S10 to S40: Step S10: In response to the user manual operation event of the vehicle device, the operation characteristics of the current manual operation are fused and quantified to calculate the intent intensity value that represents the intensity of the user's operation intent. First, identify the source of device status change events. When a device status change is detected, check the change source label. If the source is a direct user interaction method such as HMI touch, physical button, or voice command, then mark the operation as a user manual operation event; if the source is a policy engine call or system initialization, then this step is not triggered.

[0039] For identified user manual operation events, their operation features are extracted, specifically including three dimensions: adjustment magnitude features, operation frequency features, and operation timeliness features. In terms of adjustment magnitude, the adjustment ratio of the state difference before and after the current operation to the device's preset maximum adjustment range is calculated, and the adjustment is divided into three levels: fine adjustment, medium adjustment, and large adjustment based on this ratio. In terms of operation frequency, the number of historical user manual operations on the vehicle-mounted device within a preset historical time window including the current operation time is counted. In terms of operation timeliness, the time interval between the current operation time and the most recent historical user manual operation time is obtained, and a timeliness decay factor is calculated based on this time interval.

[0040] Furthermore, the aforementioned multi-dimensional operational features are fused and quantified to obtain an intent intensity value that characterizes the strength of the current user's operational intent. Specifically, an adjustment amplitude factor is determined based on the level of the adjustment ratio, an operation frequency factor is determined based on the number of historical user manual operations, and a time-effect decay factor is determined based on the time interval. The adjustment amplitude factor, operation frequency factor, and time-effect decay factor are then weighted and summed, and the weighted result is constrained to a preset numerical range to obtain the intent intensity value. The larger the adjustment amplitude, the more frequent the operation within the preset historical time window, and the closer the last operation, the higher the intent intensity value, indicating a stronger current user intent and a desire for the system to avoid automatic policy intervention for a longer period.

[0041] Furthermore, the process of fusing and quantifying operational features also includes identifying the type of user's operational intent. Specifically, when the number of manual operations performed by the user within the preset historical time window reaches or exceeds a preset exploration threshold, the user is determined to be in an exploration operation mode of repeatedly adjusting the device to find the optimal value. In this mode, the user's operational intent is more explicit and intense, and accordingly, the protection period will be adaptively extended to fully ensure the continuity of the user's operation during the exploration process.

[0042] In one feasible implementation, refer to Figure 2 Step S10 may include steps A11 to A14: Step A11: Determine the adjustment range factor based on the proportion of the adjustment range to the preset maximum adjustment range of the vehicle-mounted equipment; Step A12: Determine the operation frequency factor based on the historical number of operations; Step A13: Determine the time decay factor based on the time interval; Step A14: Weighted fusion of adjustment amplitude factor, operation frequency factor and time decay factor to obtain the intention intensity value of the current manual operation.

[0043] First, calculate the adjustment range of the vehicle-mounted device caused by the user's manual operation, i.e., the absolute difference in the device's state value before and after the operation. Obtain the preset maximum adjustment range corresponding to the vehicle-mounted device, and calculate the proportion of the adjustment range to the preset maximum adjustment range to obtain the adjustment ratio. Determine the corresponding adjustment range factor based on the numerical range of the adjustment ratio. For example, the adjustment ratio can be divided into three intervals: when the adjustment ratio is less than the first amplitude threshold (e.g., 10%), it is determined to be a fine-tuning operation, indicating that the user has only made a small correction to the device state, and the adjustment intention is relatively weak. In this case, the adjustment range factor takes a low value (e.g., 0.2); when the adjustment ratio is between the first amplitude threshold and the second amplitude threshold (e.g., 30%), it is determined to be a medium-tuning operation, indicating that the user has made a certain degree of state adjustment, and the adjustment intention is moderate. In this case, the adjustment range factor takes a middle value (e.g., 0.5); when the adjustment ratio reaches or exceeds the second amplitude threshold, it is determined to be a large-scale adjustment operation, indicating that the user has made a significant change to the device state, and the adjustment intention is strong. In this case, the adjustment range factor takes a high value (e.g., 1.0). Through the above hierarchical mapping, the continuous operational amplitude is transformed into discrete amplitude contribution components that reflect the strength of the intention.

[0044] Secondly, the number of times the user manually operated the vehicle device within a preset historical time window prior to the current manual operation is counted. The preset historical time window is a time interval extending backwards for a preset duration (e.g., 300 seconds) from the current operation time. The device operation logs recorded within this time window are iterated through, and operation records where the operation originates from user manual operation and the target device is the current vehicle device are selected. The number of these records is counted to obtain the historical operation count. Based on the historical operation count, an operation frequency factor is calculated. For example, the historical operation count can be compared with a preset reference operation count threshold (e.g., 3 times). If the historical operation count has reached or exceeded this threshold, it indicates that the user repeatedly operated the device within this time period, resulting in a high operation frequency and a significant intention accumulation effect; in this case, the operation frequency factor can be set to its upper limit (e.g., 1.0). If the historical operation count has not reached this threshold, the operation frequency factor is determined according to the ratio of the historical operation count to the reference operation count threshold. Therefore, the more frequent the operation within the preset time window, the larger the operation frequency factor, and the higher its contribution to the intention intensity value.

[0045] Next, obtain the time interval between the current manual operation and the most recent historical user manual operation. If the current operation is the first operation within a preset historical time window, the time interval can be the window duration or a preset maximum value. Based on the time interval, calculate the time decay factor. For example, an exponential decay function can be used to calculate the time decay factor, and the decay rate is controlled by a preset decay coefficient (e.g., a decay coefficient of 0.1), so that the closer the historical operation is to the current operation, the stronger its timeliness and the greater its reference value for judging the current intention. When the time interval is zero (i.e., the current operation has just occurred), the time decay factor is at its maximum value (e.g., 1.0); as the time interval increases, the time decay factor decreases exponentially, reflecting the gradual weakening of the timeliness of the user's operation intention.

[0046] Finally, the calculated adjustment amplitude factor, operation frequency factor, and time decay factor are weighted and fused to obtain the current manual operation intent intensity value. For example, the fusion weights of the three can be preset (e.g., amplitude weight 0.4, frequency weight 0.3, time decay weight 0.3). Each factor is multiplied by its corresponding weight and then summed to obtain the comprehensive intent intensity value. The comprehensive intent intensity value is further constrained to a preset intent intensity value range (e.g., [0.1, 1.0]). If the calculated result is lower than the lower limit of the range, the lower limit value is used; if it is higher than the upper limit, the upper limit value is used, ensuring that the intent intensity value is always within a reasonable range. A higher intent intensity value indicates a stronger user's current operational intent, suggesting that the system should maintain respect for the device's state for a longer period, avoiding interference from automatic control strategies.

[0047] Step S20: Based on the preset basic protection duration, intent strength value and the device physical factor corresponding to the vehicle device, calculate the protection period duration for the automatic control command. The automatic control command is the command that the preset scenario strategy script automatically controls the vehicle device after the user's manual operation event. The protection period duration is used to constrain the immediate execution of the automatic control command. Before calculating the protection period duration, the device physical factors corresponding to the vehicle-mounted device are first obtained. These physical factors are comprehensive quantitative indicators characterizing the physical operation characteristics of the device, obtained by weighted fusion of execution latency parameters, ergonomic sensitivity parameters, and driving safety impact parameters. Specifically, the execution latency parameter reflects the time required for the vehicle-mounted device to perform a complete adjustment action; devices with slower execution require more time for the user to perceive and confirm the adjustment effect after operation. The ergonomic sensitivity parameter reflects the user's perceptual sensitivity and operational engagement when adjusting the device; devices with higher sensitivity reflect stronger personal preferences embodied in each user adjustment and are less likely to be quickly overridden by the strategy. The driving safety impact parameter reflects the degree of impact of the device's state adjustment on driving safety; devices with greater safety impact should have more user control over their state. The above three parameters are weighted and summed according to preset weights to obtain the device physical factors corresponding to the vehicle-mounted device. Meanwhile, the driving safety impact parameters are also dynamically selected based on the current dynamic state of the vehicle. For example, when the vehicle speed exceeds a preset threshold, the driving safety impact parameters of window-type devices are set to a higher value to reflect the higher requirements for the control safety of the device in high-speed scenarios.

[0048] After obtaining the device's physical factors, the protection period duration is dynamically calculated based on a preset basic protection duration, the intent strength value, and the device's physical factors, combined with the preset basic protection duration. Specifically, the basic protection duration, the intent strength value, and the device's physical factors are multiplied to obtain an initial protection period duration, which is then constrained to a preset duration range to finally obtain the protection period duration. Thus, the stronger the intent, the more sensitive the device, and the greater the impact on driving safety, the longer the calculated protection period duration; conversely, the shorter the protection period duration.

[0049] Furthermore, the calculation of the protection period duration also includes an adaptive fine-tuning step based on the user's operational intent. Specifically, when the user is determined to be in exploratory operation mode based on the characteristics of the current manual operation, it indicates that the user is repeatedly adjusting to find the optimal state value of the device. In this case, more comprehensive protection should be provided, and therefore the calculated protection period duration is extended. When it is determined that the user is making significant adjustments, indicating a long-term preference, the protection period duration is also appropriately extended accordingly. In this way, the protection period duration ultimately achieves three-dimensional dynamic adaptation with the user's operational intent, the device's physical characteristics, and the vehicle's real-time status, overcoming the limitations of the fixed cooling period in existing technologies.

[0050] In one feasible implementation, refer to Figure 3 Step S20 may include steps B11 to B12: Step B11: When the number of historical operations meets the preset exploration judgment conditions, the current manual operation is determined to be in the exploration operation mode. The preset exploration judgment conditions include: the number of historical operations on the vehicle device within the preset historical time window is greater than or equal to the preset number threshold. Step B12: In the exploration operation mode, the protection period duration is extended to obtain the extended protection period duration.

[0051] After calculating the intent strength value and before determining the final protection period duration, a step of determining the user's operation mode is included. Specifically, the number of historical operations on the in-vehicle device, statistically obtained within the preset historical time window, is obtained and compared with a preset threshold number. The preset threshold number is a critical value used to distinguish between normal adjustment behavior and exploratory adjustment behavior. For example, the preset threshold number can be set to 3 times. When the number of historical operations is greater than or equal to the preset threshold number, it indicates that the user has repeatedly and repeatedly manually adjusted the in-vehicle device within the preset historical time window. This is not a one-time temporary correction, but a continuous attempt to find the optimal state value or the most comfortable setting point of the device. This type of operation behavior has clear exploratory and repeated trial and error characteristics, so the current manual operation is determined to be in exploratory operation mode. When the number of historical operations is less than the preset threshold number, it indicates that the user's operation on the device is sporadic adjustment, which is determined to be a non-exploratory operation mode, and the protection period duration can be calculated according to the conventional process.

[0052] Furthermore, when the current manual operation is determined to be in exploration mode, the protection period duration is extended. Specifically, firstly, based on a preset basic protection period, the intent intensity value, and the device physical factor, and combined with the preset basic protection period, an initial protection period duration is obtained using conventional calculation methods. Then, the initial protection period duration is multiplied by a preset exploration extension coefficient, which is a value greater than 1 (exemplarily, it can be set to 1.5), to obtain the extended protection period duration. This extension process significantly increases the protection period based on the conventional calculation result, fully matching the user's need for continuous operation over a long period while exploring the device's optimal state.

[0053] The rationale for extending the protection period is as follows: Compared to a single temporary adjustment or a single significant preference adjustment, users in exploration mode are experiencing a complete behavioral loop—that is, through multiple attempts, observing the subjective feelings after each adjustment, and further approaching the target value. During this process, any automatic control commands from preset scenario strategy scripts may interrupt the user's exploration rhythm, forcing the user to restart the adjustment process and generating a stronger sense of frustration. Therefore, in exploration mode, a longer protection period than in normal operation should be provided to ensure that the system maintains a sufficient avoidance stance until the user finds a satisfactory state, preventing automatic strategies from interfering with the user's exploration behavior chain.

[0054] After completing the exploration mode determination and protection period extension processing, the extended protection period, along with other possible duration adjustment results in this field, is constrained to a preset duration range (e.g., [60 seconds, 1800 seconds]) to prevent insufficient protection due to an excessively short protection period, or prolonged failure of the strategy's intelligent function due to an excessively long protection period. The final constrained duration is the final protection period for subsequent automatic control commands triggered by the current user manual operation event.

[0055] Through the above methods, this embodiment achieves accurate identification of the user's repeated adjustment and exploration behavior, and accordingly extends the protection period. This makes the protection period not only related to the intensity of the single operation intention and the physical characteristics of the device, but also matched with the user's operation behavior pattern, further improving the intelligence and humanization of the avoidance mechanism.

[0056] In one feasible implementation, refer to Figure 4 Steps C11-C12 may be included before step S20: Step C11: Obtain the execution delay parameter, ergonomic sensitivity parameter, and driving safety impact parameter of the vehicle-mounted device. The execution delay parameter represents the time required for the vehicle-mounted device to perform a complete action, the ergonomic sensitivity parameter represents the user's sensitivity to the adjustment of the vehicle-mounted device, and the driving safety impact parameter represents the degree of impact of the adjustment of the vehicle-mounted device on driving safety. Step C12 involves weighted fusion of execution delay parameters, ergonomic sensitivity parameters, and driving safety impact parameters to obtain the device physical factors corresponding to the vehicle-mounted equipment.

[0057] Before calculating the protection period based on the preset basic protection duration, intent strength value, and device physical factors, it is necessary to first construct the corresponding device physical factors for each vehicle-mounted device. The device physical factor is a quantitative indicator that comprehensively reflects the physical operation characteristics of the device, and its construction process includes two stages: parameter acquisition and weighted fusion.

[0058] During the parameter acquisition phase, for the vehicle-mounted equipment whose physical factors need to be constructed, the execution latency parameters, ergonomic sensitivity parameters, and driving safety impact parameters are acquired respectively.

[0059] The execution delay parameter characterizes the time required for the vehicle-mounted device to complete a full action from receiving a control command. Execution delays vary significantly among different vehicle-mounted devices. For example, it takes several seconds for a window to go from fully closed to fully open, while volume adjustment is almost instantaneous. For devices with longer execution delays, users need time to observe and perceive the adjustment effect after manual adjustment. If the automatic control command overrides the effect before it is fully realized, the user will not be able to accurately judge whether the manual operation achieved the expected goal, easily leading to repeated adjustments. Therefore, devices with longer execution delays should receive a correspondingly longer protection period. To facilitate weighted fusion calculations, the actual execution delays of each device can be normalized to obtain a normalized execution delay parameter, with a value range of [0, 1]. A larger value indicates slower execution.

[0060] The ergonomic sensitivity parameter characterizes the user's perceptual sensitivity and operational engagement when adjusting the in-vehicle device. The cognitive and physical costs of adjusting different devices vary. For example, fine-tuning the window position involves the user's perceived ventilation and field of vision, leading to a high level of subjective perception and engagement. In contrast, adjusting ambient lighting color is more driven by aesthetic preference, resulting in relatively lower perceptual sensitivity. Devices with higher ergonomic sensitivity reflect stronger personal preferences and usage habits in each adjustment, making them less susceptible to rapid overriding by automatic control strategies. For instance, ergonomic sensitivity parameters can be preset for each in-vehicle device, ranging from [0, 1]. Higher values ​​indicate greater user sensitivity and operational engagement with the device.

[0061] The driving safety impact parameters characterize the degree to which adjustments to the on-board equipment affect driving safety. The impact of changes in the states of different devices on driving safety varies fundamentally. For example, in high-speed driving scenarios, significantly opening windows can significantly increase wind noise, affect vehicle stability, and distract the driver, resulting in a high safety impact coefficient; while adjustments to volume or ambient lighting have a relatively small impact on driving safety. For devices with a greater impact on driving safety, the final decision-making power regarding their states should be more delegated to the user, and the threshold for automatic system intervention should be correspondingly raised. For example, driving safety impact parameters can be preset for each on-board device under different vehicle dynamic states, with values ​​ranging from [0, 1]. A larger value indicates a more significant impact of the device's adjustment on driving safety.

[0062] Furthermore, the driving safety impact parameters are dynamically selected based on the vehicle's current dynamic state. Specifically, for the same onboard device, two preset values ​​can be used: driving safety impact parameters for low-speed conditions and driving safety impact parameters for high-speed conditions. When the vehicle speed exceeds a preset speed threshold (e.g., 80 km / h), the driving safety impact parameters for high-speed conditions are used; when the vehicle speed is lower than or equal to the preset speed threshold, the driving safety impact parameters for low-speed conditions are used. Taking a car window as an example, at low speeds, the impact of opening the window on driving safety is relatively limited, and the driving safety impact parameter can be set to a lower value (e.g., 0.3); at high speeds, opening the window will significantly affect driving stability and the in-vehicle environment, and the driving safety impact parameter will be set to a higher value (e.g., 0.9). Through this dynamic selection, the device's physical factors can reflect changes in the vehicle's operating environment in real time, thereby affecting the calculation results of the subsequent protection period duration.

[0063] In the weighted fusion stage, the obtained execution latency parameters, ergonomic sensitivity parameters, and driving safety impact parameters are weighted and fused to obtain the device physical factor corresponding to the vehicle-mounted device. For example, corresponding fusion weights can be preset for the above three parameters (e.g., execution latency weight 0.3, ergonomic sensitivity weight 0.4, driving safety impact weight 0.3), and the sum of the three weights is 1. Multiplying each parameter by its corresponding weight and summing the results yields the device physical factor of the vehicle-mounted device in its current state. A larger device physical factor indicates that the overall physical characteristics of the device determine that it requires a longer strategy avoidance time after manual user operation; a smaller value indicates that the physical characteristics of the device are more suitable for rapid strategy recovery of automatic control.

[0064] In this embodiment, the device physical factors integrate physical characteristics of three dimensions: execution latency, ergonomic sensitivity, and driving safety impact. Compared with the existing technology that only uses a single fixed cooling period or simple sensitivity label, it can more comprehensively and accurately characterize the overall cost to the user and vehicle of adjusting the vehicle device once, laying the foundation for subsequent implementation of device-level differentiated protection period calculation.

[0065] Step S30: When an automatic control command is received within the protection period, determine the progress interval in which the moment the automatic control command is received is within the protection period. When an automatic control command for the same in-vehicle device is received after a user manual operation event, triggered by a preset scenario strategy script, the system first checks whether the in-vehicle device is currently within its protection period. Specifically, the system maintains the protection period status of each in-vehicle device, which includes at least the protection period start time and the total protection period duration. If the current time exceeds the sum of the protection period start time and the total protection period duration, the protection period is determined to have ended; if the current time is still within this time range, the in-vehicle device is determined to be currently within its protection period.

[0066] If the system is determined to be within the protection period, the progress position of the moment the automatic control command was received within the protection period duration is further calculated. Specifically, the elapsed duration of the protection period is determined based on the time difference between the current moment and the start time of the protection period, and the proportion of the elapsed duration to the total protection period duration is calculated to obtain the protection period progress value. The protection period progress value ranges from 0% to 100%, where 0% indicates the protection period has just begun and 100% indicates the protection period is about to end.

[0067] Then, the protection period progress value is compared with multiple preset progress thresholds to determine the current progress interval. The progress interval is divided into several progressively increasing intervals based on the protection period progress value, for example: a first progress interval, corresponding to a protection period progress value between 0% and the first threshold; a second progress interval, corresponding to a protection period progress value between the first and second thresholds; and a third progress interval, corresponding to a protection period progress value between the second threshold and 100%. Different progress intervals correspond to different levels of restriction on the subsequent execution of the automatic control command. The earlier the protection period progress, the closer it is to the user's most recent manual operation, and the stronger the user's current need for protection, thus the stricter the restriction on the automatic control command. The later the protection period progress, the less impact the user's operation has, and the more relaxed the restriction on the automatic control command, until normal execution resumes after the protection period ends. This segmented and progressive approach achieves a flexible avoidance effect where the protection intensity decreases smoothly over time, avoiding the disjointed experience problem caused by complete prohibition during the cooling-off period and immediate release after the cooling-off period in existing technologies.

[0068] Step S40: Determine the first execution strategy corresponding to the automatic control command based on the progress interval, and perform the first execution action of the on-board equipment in response to the automatic control command with reference to the first execution strategy.

[0069] After determining the progress interval at which the automatic control command is received, a first execution strategy corresponding to the automatic control command is determined based on the preset mapping relationship between progress intervals and execution strategies. This mapping relationship defines a progressively increasing degree of restriction on the automatic control command by the execution strategy, from strict to lenient, as the protection period progress value increases.

[0070] Specifically, when the progress interval is the first progress interval, it indicates that the time since the user's most recent manual operation is relatively short, and the user's control over the vehicle-mounted device is still in a stage of strong protection needs. At this time, the first execution strategy is determined to be a complete avoidance strategy, that is, the automatic control command is not executed, nor is any prompt or disturbance issued to the user, so as to fully respect the user's just completed control intention. When the progress interval is the second progress interval, it indicates that the immediate impact of the user's operation has weakened, but a certain degree of avoidance is still required. At this time, the first execution strategy is determined to be a silent recording strategy, that is, the automatic control command is not executed for the time being, but it is recorded in the system log for subsequent data analysis and strategy optimization. This process is imperceptible to the user. When the progress interval is the third progress interval, it indicates that the impact of the user's operation has further weakened, and the protection period is about to end. It is appropriate to convey strategy suggestions to the user. At this time, the first execution strategy is determined to be a flexible suggestion strategy, that is, the suggested content corresponding to the automatic control command is presented to the user in a gentle interactive way (such as voice prompts or information pop-ups), and the user decides whether to adopt and execute it. The system does not force execution.

[0071] When the progress interval is the protection period progress value, which has reached or exceeded 100%, that is, the protection period has ended, the first execution strategy is determined to be the normal execution strategy, that is, the automatic control command is directly executed, and the automatic control function of the on-board equipment by the scene strategy script is restored.

[0072] After determining the first execution strategy, the corresponding first execution action is performed on the in-vehicle device in accordance with the first execution strategy. If it is a complete avoidance strategy, the automatic control command is discarded and no device control action is performed; if it is a silent recording strategy, the request content of the automatic control command is cached in the local or cloud log storage area and no control signal is sent to the in-vehicle device; if it is a flexible suggestion strategy, the in-vehicle human-machine interface is invoked to send a suggestion notification to the user through at least one method such as voice broadcast or pop-up window on the central control screen, and the user's response to the suggestion notification is listened to; if it is a normal execution strategy, the automatic control command is converted into a device control signal and sent to the in-vehicle device for execution.

[0073] By implementing the aforementioned tiered execution method based on the protection period's progress intervals, a gradual avoidance and recovery mechanism is achieved, progressing from complete interception to silent transition, then to flexible interaction, and finally to normal execution of automatic control commands. Compared to the abrupt switching method in existing technologies, which involves absolute prohibition during the cooling-off period and immediate execution upon its expiration, the tiered and gradual strategy execution provided in this step ensures that users experience a smooth and natural intelligent service recovery process after operating the device, rather than an abrupt policy rebound. This achieves a refined balance between protecting user control and maintaining intelligent policy functionality.

[0074] In one feasible implementation, refer to Figure 5 Step S30 may be followed by steps D11 to D13: Step D11: Determine the urgency of the current operating scenario of the vehicle when the automatic control command is received; Step D12: Based on the intent strength value and the urgency of the scenario, a collaborative decision is made to determine the second execution strategy corresponding to the automatic control command; Step D13: Refer to the second execution strategy to perform the second execution action of the automatic control command on the on-board equipment.

[0075] After determining the progress interval within the protection period at which the automatic control command is received, this method further includes introducing a scenario-based collaborative decision-making mechanism to compensate for the potential neglect of scenario safety requirements when relying solely on the protection period progress for avoidance decisions. To this end, the scenario urgency of the vehicle's current operating scenario at the time the automatic control command is received is first determined. The scenario urgency is an indicator used to measure the urgency of the scenario strategy that triggered the automatic control command in terms of both safety and timeliness. For example, the urgency of a scenario can be divided into multiple levels: when the automatic control command involves scenarios related to driving safety, such as a window opening unexpectedly while driving at high speed, a window left open in the rain, or a child safety lock not engaged, the scenario urgency is determined to be at the emergency level; when the automatic control command involves scenarios related to driving comfort, such as suggesting turning on the air conditioner when the interior temperature is too high or switching to recirculation mode when the air quality is poor, the scenario urgency is determined to be at a higher level; when the automatic control command involves scenarios related to energy saving or convenience, such as suggesting turning off the air conditioner to save energy when the car is parked, the scenario urgency is determined to be at a medium level; when the automatic control command involves scenarios related to atmosphere or personalization, such as automatically turning on ambient lighting upon arriving home, the scenario urgency is determined to be at a lower level. The determination of the scenario urgency can be based on a comprehensive analysis of the vehicle's current dynamic state data (such as vehicle speed and gear), environmental sensor data (such as rain sensor and temperature sensor), and the preset urgency label carried by the automatic control command.

[0076] After determining the urgency of the scenario, a collaborative decision is made based on the intent strength value and the scenario urgency to determine the second execution strategy corresponding to the automatic control command. The core of this collaborative decision is based on a preset two-dimensional decision mapping relationship. This mapping relationship uses scenario urgency as the first dimension and the strength of the user's intent reflected by the intent strength value as the second dimension. Different combinations of dimensions correspond to different second execution strategies. Specifically, firstly, the strength of the user's current intent is determined based on the intent strength value. When the intent strength value exceeds a preset intent strength threshold (e.g., 0.6), the user's current operation intent is determined to be a strong intent; otherwise, it is determined to be a weak intent.

[0077] Furthermore, based on the combination of scenario urgency and intent strength, the preset two-dimensional decision mapping relationship is queried to obtain the second execution strategy. For example, the two-dimensional decision mapping relationship can be set as follows: when the scenario urgency is at the urgency level and the user intent is weak, it indicates that the current scenario strategy involving security risks requires immediate response, while the user's recent operational intent towards the device is relatively weak. In this case, the second execution strategy is determined to be a direct execution strategy, that is, the automatic control command directly controls the in-vehicle device to ensure driving safety as a priority; when the scenario urgency is at the urgency level and the user intent is strong, it indicates that security needs conflict with the user's strong operational intent. In this case, the second execution strategy is determined to be a strong reminder strategy, that is, using a multi-channel interaction method (such as... (At least two of the following: voice broadcast, pop-up prompts, and seat vibration) will be used to issue a prominent safety reminder to the user, allowing the user to make a final decision after being aware of the risks. When the urgency level of the scenario is high, regardless of the strength of the user's intention, the second execution strategy will be a flexible suggestion strategy, which will make suggestions to the user in a gentle manner and fully respect the user's right to choose. When the urgency level of the scenario is medium or low, if the user's intention is strong, the second execution strategy will be a complete avoidance strategy. If the user's intention is weak, a flexible suggestion strategy or a complete avoidance strategy may be adopted as appropriate, with priority given to ensuring the user's operating experience.

[0078] After determining the second execution strategy, the vehicle-mounted device performs a second execution action in response to the automatic control command, referring to the second execution strategy. If the second execution strategy is a direct execution strategy, the automatic control command is converted into a device control signal and sent to the vehicle-mounted device for execution; if it is a strong reminder strategy, multiple in-vehicle human-machine interaction channels are invoked to issue a prominent safety warning notification to the user, and the user's response to the notification is monitored to determine whether to execute it subsequently; if it is a flexible suggestion strategy, suggestions are provided to the user in a single or gentle combination of voice or pop-up windows; if it is a complete avoidance strategy, the automatic control command is not executed and the user is not disturbed.

[0079] By introducing a collaborative decision-making mechanism that combines scenario urgency with user intent strength, this embodiment achieves deeper decision-making capabilities based on scenario security and user intent, beyond simply avoiding situations within the protection period time dimension. Especially in security emergency scenarios, the collaborative decision-making mechanism can effectively supplement or even reasonably cover avoidance decisions that solely rely on the progress of the protection period, preventing delays in security response due to mechanically adhering to protection period rules, and achieving an orderly balance between security priority and the protection of user control sovereignty.

[0080] In one feasible implementation, refer to Figure 6 Step D12 may be followed by steps E11 to E12: Step E11: Determine the second execution action to be performed on the on-board equipment in response to the automatic control command, referring to the second execution strategy; In step E12, during the first and second execution actions, a third execution action is determined by a preset arbitration rule, and the third execution action is performed on the vehicle-mounted equipment.

[0081] In this method, for the same automatic control command, there may be two parallel decision paths: one is the first execution action determined based on the protection period progress interval, targeting the protection period dimension; the other is the second execution action determined based on the collaborative decision of scenario urgency and user intent intensity, targeting the scenario dimension. To avoid conflicts or execution contradictions between the two decision paths, a unified arbitration mechanism needs to be introduced between them to determine the single execution action ultimately issued to the vehicle-mounted equipment.

[0082] Specifically, after determining the first and second execution actions respectively, a third execution action is determined by comprehensively arbitrating the two actions using preset arbitration rules. The core principle of the preset arbitration rules is: while ensuring driving safety as the priority, the need to protect the user's control sovereignty is also taken into account, and a conservative approach is taken to comprehensively weigh the execution actions from different decision-making sources.

[0083] An exemplary implementation of the arbitration rule is as follows: First, it is determined whether the urgency of the scenario corresponding to the current automatic control command belongs to the preset highest urgency level (i.e., the urgency level). If the scenario urgency is the urgency level, it indicates that the current automatic control command involves an emergency scenario related to driving safety, and safety considerations have the highest priority. In this case, the arbitration rule directly determines the second execution action as the third execution action, that is, based on the collaborative decision-making result at the scenario level. This means that even if the protection period is in its early stages and the first execution action is a strongly restrictive action such as complete avoidance or silent recording, as long as the current scenario involves an emergency driving safety situation, the arbitration result can still be upgraded to actions such as strong reminders or direct execution to ensure that safety-related policies can reach the user or vehicle execution layer in a timely manner, achieving emergency safety coverage.

[0084] If the scenario urgency level is not considered emergency, meaning the current automatic control command does not involve a safety emergency, the arbitration rules adopt a conservative approach to comprehensively consider the first and second execution actions. Specifically, the degree of restriction imposed on the automatic control command by the first and second execution actions is compared, and the execution action with the higher degree of restriction and less user intrusion is selected as the third execution action. The degree of restriction of the execution actions, from highest to lowest, is as follows: complete avoidance (no execution, no disturbance) > silent recording (no execution, no disturbance, but background recording) > flexible suggestion (gentle prompt left to the user) > strong reminder (multi-channel prominent reminder) > direct execution (forced execution). For example, if the first execution action is complete avoidance and the second execution action is a flexible suggestion, then after arbitration, complete avoidance is selected as the third execution action to fully respect the user's control sovereignty protection needs reflected in the protection period; if the first execution action is a flexible suggestion and the second execution action is complete avoidance, then complete avoidance is also selected. This conservative approach ensures that, in non-emergency scenarios, the execution of automatic control commands never exceeds the upper limits allowed by the protection period mechanism and the collaborative decision-making mechanism.

[0085] After determining the third execution action according to the aforementioned arbitration rules, the third execution action is taken as the final decision result and executed on the vehicle-mounted device. If the third execution action is direct execution, a control signal is sent to the vehicle-mounted device; if it is a strong reminder, a warning is issued to the user through the multi-channel human-machine interface; if it is a gentle suggestion, a suggestion is made to the user in a mild manner; if it is silent recording, the instruction information is written to the log storage area without disturbing the user; if it is complete avoidance, the automatic control instruction is discarded without any processing.

[0086] Through the aforementioned arbitration mechanism, this method systematically integrates the first execution action based on the progress of the protection period with the second execution action based on collaborative decision-making based on scenario urgency and intent strength, forming a unified final execution decision. This arbitration mechanism ensures, on the one hand, that in security emergency scenarios, the collaborative decision-making result effectively covers the avoidance restrictions of the protection period, prioritizing safety; on the other hand, it ensures that in non-emergency scenarios, the protection period mechanism and the collaborative decision-making mechanism mutually check and balance each other, safeguarding the user's control experience with more conservative actions, thereby achieving an optimized balance between security, intelligence, and user experience.

[0087] In one feasible implementation, refer to Figure 7 Step S40 may be followed by steps F11-F12: Step F11: Collect the user's final feedback data on the automatic control command. The final feedback data includes at least one of the following types: acceptance type, indicating that the user accepts the execution action corresponding to the automatic control command; rejection type, indicating that the user rejects the execution action corresponding to the automatic control command; readjustment type, indicating that the user manually operates the same on-board device again within the protection period; and no intervention type, indicating that the user does not intervene in the automatic execution of the automatic control command after the protection period ends. Step F12: Based on the final feedback data, adjust the basic parameters used to calculate the protection period duration. The basic parameters include at least one of the basic duration of the protection period and the fusion weight used to calculate the physical factors of the equipment.

[0088] After the on-board equipment performs the first execution action in response to the automatic control command according to the first execution strategy, the method also includes a closed-loop learning mechanism for feedback collection and parameter adaptive adjustment, so that the calculation parameters of the protection period duration can be continuously optimized with user feedback in actual use, gradually approaching the best avoidance effect.

[0089] During the feedback collection phase, the system automatically monitors and collects the user's final feedback data on the automatic control commands and their execution actions. This final feedback data is categorized into several types based on the user's different response behaviors: The first type is the acceptance type, which indicates that the user accepts the execution action corresponding to the automatic control command. This type of feedback can be identified in the following ways: when the system issues a strategy suggestion to the user in a flexible manner, and the user does not reject the suggestion within a preset observation time window, it can be regarded as the user's tacit acceptance; or when the system issues a suggestion in a flexible manner, the user actively confirms the adoption of the suggestion through voice command or touch operation.

[0090] The second type is the rejection type, which indicates that the user rejects the execution action corresponding to the automatic control command. This type of feedback can be identified in the following ways: when the system issues a strategy suggestion to the user in a flexible manner, the user actively closes the suggestion pop-up, explicitly rejects it with a voice command, or manually adjusts the device status to a direction inconsistent with the suggestion within a preset observation time window.

[0091] The third type is the readjustment type, which indicates that the user manually operates the same in-vehicle device again within the protection period. This type of feedback can be identified as follows: if a new user manual operation event is detected from the in-vehicle device before the current protection period has ended, it indicates that the user is still not satisfied with the current device status, and the protection period triggered by the previous operation may not be sufficient to meet the user's continuous control needs for the device, requiring further strengthening of protection.

[0092] The fourth type is the non-intervention type, which indicates that when the preset scenario strategy script executes automatic control commands on the vehicle-mounted device after the protection period ends, the user does not perform any intervention operations on the automatic execution. This type of feedback can be identified as follows: after the protection period ends, the automatic control commands are normally issued to the device for execution, and no new user manual operation events are detected for the device within the preset observation time window. This indicates that the user has no objection to the execution result of the automatic control commands, and the current protection period may be too long for the device, with room for optimization by appropriately shortening it.

[0093] The aforementioned types of final feedback data are continuously recorded and stored, and can be aggregated and summarized according to a preset statistical period (for example, 7 days) to form feedback statistics data for parameter adjustment.

[0094] During the parameter adaptive adjustment phase, based on the collected final feedback data, the fundamental parameters used to calculate the protection period duration are adjusted. These fundamental parameters include at least one of the following: the basic protection period duration and the fusion weights used to calculate the equipment physical factors. The specific adjustment method is as follows: Regarding the adjustment of the base duration: The global readjustment rate is calculated by statistically analyzing the ratio of readjustment type feedback data from all devices within a preset statistical period to the total feedback data. When the global readjustment rate exceeds a first adjustment threshold (e.g., 0.25), it indicates that the current base duration is generally too short, and users generally make readjustments during the protection period. Therefore, the base duration needs to be appropriately extended. In this case, the base duration is multiplied by an increase factor greater than 1 (e.g., 1.1), and the result is constrained to within the preset upper limit of the base duration. When the global readjustment rate is lower than a second adjustment threshold (e.g., 0.10), it indicates that the current base duration is generally too long, and users generally do not intervene in policy execution after the protection period ends, resulting in unnecessary restrictions on the policy's intelligent functions. In this case, the base duration is multiplied by a decrease factor less than 1 (e.g., 0.95), and the result is constrained to above the preset lower limit of the base duration. When the global readjustment rate is between the first and second adjustment thresholds, the current base duration remains unchanged.

[0095] The adjustment of the fusion weights for the physical factors of the equipment: The fusion weights include the weights of the execution delay parameter, the ergonomic sensitivity parameter, and the driving safety impact parameter, and the sum of the three is always 1. The core logic for adjusting the fusion weights based on the final feedback data is as follows: A high readjustment rate indicates that the current protection period parameters are insufficient to protect the equipment, and the ergonomic sensitivity component and the safety impact component should be strengthened to improve the comprehensive value of the physical factors of the equipment, thereby extending the protection period; a high non-intervention rate indicates that the current protection period parameters may be too restrictive to the equipment, and the above components can be appropriately weakened. Specifically, when the readjustment type feedback ratio of a certain equipment exceeds the preset readjustment threshold within the preset statistical period, the weights of the ergonomic sensitivity parameter and the driving safety impact parameter are multiplied by an increment coefficient greater than 1, and then the three are normalized to restore the sum to 1; when the non-intervention type feedback ratio of a certain equipment exceeds the preset non-intervention threshold, the above two weights are multiplied by a reduction coefficient less than 1, and the same normalization process is performed.

[0096] Through the aforementioned feedback collection and parameter adaptive adjustment mechanism, the basic parameters of the protection period duration are optimized online in a closed loop based on actual user feedback. The periodic parameter adjustments ensure that, as system runtime accumulates, the combined weights of the basic duration and device physical factors gradually converge to an optimal value that aligns with the actual operating habits of the user group, thus continuously improving the accuracy of the avoidance strategy over time.

[0097] It should be noted that the aforementioned final feedback data collection and parameter adjustment process only maintains statistical data by device bucket, and does not construct or rely on any user behavior profiles by individual user bucket. The base duration and the fusion weight are global or device-level shared parameters, and their adjustment is based on aggregated feedback data of user groups, decoupled from the specific user's identity. This design enables this method to achieve adaptive optimization while effectively avoiding overlap with other technical solutions such as user profile construction, maintaining clear boundaries of the technical solutions.

[0098] In a typical driving scenario, a user is driving in the city. As the weather warms up, the user wants to open the car windows to a comfortable position that ensures ventilation without excessive wind noise. The user first uses the physical buttons on the door to adjust the window from completely closed to about 30% opening. After a short while, feeling that the airflow is insufficient, the user then uses the buttons again to adjust the window opening to about 60%. After another short period of testing, feeling that the wind noise is too loud, the user uses the buttons a third time to adjust the window back to about 45% opening, finally finding the position satisfactory.

[0099] The vehicle control unit detected the three device status change events mentioned above. Source identification confirmed that all three operations originated from physical button triggers and were marked as user manual operation events. At each operation, the system calculated the proportion of the adjustment range to the window's preset maximum adjustment range. All three adjustments were at the medium or large adjustment level, corresponding to relatively high adjustment range factor values. Simultaneously, a 5-minute time window was traced back from the current operation time to count the historical number of user manual operations on the window within that window. The third operation had a historical operation count of 3.

[0100] During the third operation, the system fused and quantified the operation features: the adjustment amplitude factor was set to 0.5 (medium adjustment), the operation frequency factor was set to the upper limit of 1.0 because the number of historical operations reached 3 and the ratio to the preset reference threshold of 3 was 1; and the time decay factor was set to 1.0 because the operation had just occurred. The weighted summation according to the fusion weights was: 0.4×0.5 + 0.3×1.0 + 0.3×1.0 =0.2 + 0.3 + 0.3 = 0.8, and the intent intensity value was obtained after constraints: 0.8.

[0101] At the same time, the system determines that the number of historical operations within the 5-minute window has reached the preset exploration threshold of 3 times, confirming that the user is currently in exploration operation mode, that is, the user is trying to find the best position of the car window by repeatedly adjusting.

[0102] Then, the system obtains the device physical factor corresponding to the window. The window's execution latency parameter (normalized) is 1.0, the ergonomic sensitivity is 0.9, the current vehicle speed is low-speed urban driving (not exceeding 80km / h), and the driving safety impact parameter is set to low speed 0.3. Weighted fusion is performed according to preset default weights (execution latency weight 0.3, ergonomic sensitivity weight 0.4, driving safety impact weight 0.3): 0.3×1.0 + 0.4×0.9 + 0.3×0.3 = 0.3 + 0.36 + 0.09 = 0.75, resulting in a device physical factor of approximately 0.75.

[0103] Based on an intent strength value of 0.8, a device physical factor of 0.75, and a preset basic protection duration of 300 seconds, the initial protection period is calculated as: 300 × 0.8 × 0.75 = 180 seconds. Since the user is determined to be in exploration mode, the protection period is extended by multiplying it by an exploration extension coefficient of 1.5: 180 × 1.5 = 270 seconds. After constraining the result to the interval [60, 1800] seconds, the final protection period is 270 seconds (i.e., 4.5 minutes). The system establishes the protection period status for this window, with the protection period starting at the completion time of the third operation, and the initial avoidance level being complete avoidance.

[0104] Approximately one minute after the protection period is established (protection period progress approximately 22%, within the first progress range of 0%-50%), the preset "automatic window closing in rain" scenario strategy script detects sporadic raindrops and triggers a closing command for the window. Upon receiving this automatic control command, the system checks if the window is currently within the protection period, calculates the protection period progress to approximately 22%, and identifies it as the first progress range. Based on the mapping relationship, the first execution strategy corresponding to the first progress range is a complete avoidance strategy, and the first action is to discard the command and not execute the window closing action.

[0105] Simultaneously, the system assesses the urgency of the current scenario. Although rain is detected, the rain sensor reading is only 0.3 (light rain level), which has not yet reached the safety urgency threshold, thus classifying the scenario urgency as high. Combining this with an intent strength value of 0.8 (greater than 0.6, considered a strong intent), the collaborative decision matrix is ​​queried. When the scenario urgency is high and the intent is strong, the corresponding second execution strategy is a gentle suggestion strategy, and the second execution action is to gently suggest the user close the window.

[0106] Since the scenario's urgency level is not considered urgent, the arbitration rules adopt a conservative approach. Comparing the first action (complete avoidance) and the second action (flexible suggestion), complete avoidance imposes a higher degree of restriction. Therefore, after arbitration, complete avoidance was selected as the third action, and the system ultimately does not execute the window-closing action, thus avoiding disruption to the user.

[0107] Subsequently, approximately 4 minutes after the protection period was established (protection period progress approximately 89%, within the third progress range of 80%-100%), the rain sensor reading rose to 0.6 (moderate rain level). The vehicle was currently traveling at low speed in urban areas, and the "automatic window closing in rainy weather" strategy was triggered again. At this point, the first execution strategy corresponding to the third progress range of the protection period was a flexible recommendation strategy. Simultaneously, the increased rainfall caused the scenario's urgency level to escalate from a higher level, and the second execution strategy determined by the collaborative decision-making process remained a flexible recommendation strategy. After arbitration, the final action was a flexible recommendation. The system issued a prompt to the user via a pop-up window on the central control screen and voice announcement: "Increased rainfall detected; it is recommended to close the windows." The user decides whether to accept this recommendation based on their current experience.

[0108] As demonstrated in the above typical scenarios, this method accurately identifies the user's exploratory operation mode during repeated exploration and adjustments of the car windows, automatically extending the protection period. In the initial protection phase (light rain), it completely avoids policy intervention; in the later protection phase (heavy rain), it only gently suggests solutions to the user. Throughout the process, there is no instance of policy-mandated window closure interrupting the user's exploration behavior, causing interference between the user and the vehicle. Furthermore, if the vehicle enters a highway (speed exceeding 100km / h), the system classifies "high-speed window open" as an emergency scenario. Even in the initial protection phase, the collaborative decision-making safety emergency coverage mechanism bypasses the protection period limit and issues a strong reminder to the user, ensuring driving safety.

[0109] In this scenario, the user did not subsequently reject the "close windows in the rain" suggestion. After the protection period ended, the system collected feedback data of the non-intervention type. This data was then incorporated into the parameter adaptive adjustment of the preset statistical period to optimize the protection period calculation parameters of vehicle window devices.

[0110] It should be noted that the above examples are only for understanding this application and do not constitute a limitation on the vehicle control method of this application. Any simple modifications based on this technical concept are within the protection scope of this application.

[0111] This application also provides a vehicle control device, please refer to... Figure 8 The vehicle control device includes: The first calculation module 10 is used to respond to user manual operation events of the vehicle-mounted device, fuse and quantify the operation characteristics of the current manual operation, and calculate the intent intensity value that represents the intensity of the user's operation intent. The second calculation module 20 is used to calculate the protection period for the automatic control command based on the preset basic protection duration, the intent strength value and the device physical factor corresponding to the vehicle device. The automatic control command is the command for the vehicle device to be automatically controlled by the preset scenario strategy script after the user manual operation event. The protection period is used to constrain the immediate execution of the automatic control command. The determination module 30 is used to determine the progress interval in which the automatic control command is received within the protection period when the automatic control command is received within the protection period. The execution module 40 is used to determine the first execution strategy corresponding to the automatic control command based on the progress interval, and to perform a first execution action on the vehicle-mounted device in response to the automatic control command with reference to the first execution strategy.

[0112] In one embodiment, the operational features include the adjustment range of the current manual operation on the vehicle-mounted device, the number of historical manual operations within a preset historical time window prior to the current manual operation, and the time interval between the most recent historical manual operation and the current manual operation; the first calculation module 10 is further configured to: The adjustment range factor is determined based on the proportion of the adjustment range to the preset maximum adjustment range of the vehicle-mounted device; Determine the operation frequency factor based on the historical number of operations; Determine the time decay factor based on the time interval; The adjustment amplitude factor, the operation frequency factor, and the time decay factor are weighted and fused to obtain the intention intensity value of the current manual operation.

[0113] In one embodiment, the second computing module 20 is further configured to: When the number of historical operations meets the preset exploration judgment condition, the current manual operation is determined to be in the exploration operation mode. The preset exploration judgment condition includes: the number of historical operations on the vehicle device within the preset historical time window is greater than or equal to a preset number threshold. In the exploration operation mode, the protection period duration is extended to obtain an extended protection period duration.

[0114] In one embodiment, the vehicle control device further includes a fifth module for: Before the step of calculating the protection period for automatic control commands based on the preset basic protection duration, the intent strength value, and the device physical factor corresponding to the on-board equipment: The execution latency parameter, ergonomic sensitivity parameter, and driving safety impact parameter of the vehicle-mounted device are obtained. The execution latency parameter represents the time required for the vehicle-mounted device to perform a complete action. The ergonomic sensitivity parameter represents the user's perception sensitivity to the adjustment of the vehicle-mounted device. The driving safety impact parameter represents the degree of impact of the adjustment of the vehicle-mounted device on driving safety. The execution delay parameter, the ergonomic sensitivity parameter, and the driving safety impact parameter are weighted and fused to obtain the device physical factor corresponding to the vehicle-mounted device.

[0115] In one embodiment, the vehicle control device further includes a sixth module for: After the step of determining the progress interval within the protection period where the automatic control command is received when it is received within the protection period: Determine the urgency of the current operating scenario of the vehicle when the automatic control command is received; Based on the intent strength value and the urgency of the scenario, a collaborative decision is made to determine the second execution strategy corresponding to the automatic control command; The vehicle-mounted equipment performs a second execution action in response to the automatic control command, referring to the second execution strategy.

[0116] In one embodiment, the sixth module is further configured to: After the step of making a collaborative decision based on the intent strength value and the scene urgency to determine the second execution strategy corresponding to the automatic control command: Determine whether to perform a second execution action on the on-board equipment in response to the automatic control command, referring to the second execution strategy; In the first and second execution actions, a third execution action is determined by a preset arbitration rule, and the third execution action is performed on the vehicle-mounted device.

[0117] In one embodiment, the vehicle control device further includes a sixth module for: After the step of performing the first execution action of the on-board device in response to the automatic control command with reference to the first execution strategy: Collect user feedback data on the automatic control command, wherein the final feedback data includes at least one of the following types: acceptance type, indicating that the user accepts the execution action corresponding to the automatic control command; rejection type, indicating that the user rejects the execution action corresponding to the automatic control command; readjustment type, indicating that the user manually operates the same in-vehicle device again within the protection period; and no intervention type, indicating that the user does not intervene in the automatic execution of the automatic control command after the protection period ends. Based on the final feedback data, the basic parameters used to calculate the protection period duration are adjusted, wherein the basic parameters include at least one of the basic duration of the protection period and the fusion weight used to calculate the physical factors of the device.

[0118] The vehicle control device provided in this application, employing the vehicle control method in the above embodiments, can solve the technical problem of human-vehicle interference. Compared with the prior art, the beneficial effects of the vehicle control device provided in this application are the same as those of the vehicle control method provided in the above embodiments, and other technical features in the vehicle control device are the same as those disclosed in the methods of the above embodiments, and will not be repeated here.

[0119] This application provides a vehicle, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, which are executed by the at least one processor to enable the at least one processor to perform the vehicle control method in Embodiment 1 above.

[0120] The following is for reference. Figure 9 The diagram illustrates a structural schematic of a vehicle suitable for implementing embodiments of this application. The vehicle in these embodiments may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions), PMPs (Portable Media Players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 9 The vehicle shown is merely an example and should not be construed as limiting the functionality and scope of use of the embodiments of this application.

[0121] like Figure 9 As shown, the vehicle may include a processing unit 1001 (e.g., a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to a program stored in a read-only memory 1002 or a program loaded from a storage device 1003 into a random access memory 1004. The random access memory 1004 also stores various programs and data required for vehicle operation. The processing unit 1001, the read-only memory 1002, and the random access memory 1004 are interconnected via a bus 1005. An input / output interface 1006 is also connected to the bus. Typically, the following systems can be connected to the input / output interface 1006: input devices 1007 including, for example, a touchscreen, touchpad, keyboard, mouse, image sensor, microphone, accelerometer, gyroscope, etc.; output devices 1008 including, for example, a liquid crystal display (LCD), speaker, vibrator, etc.; storage devices 1003 including, for example, magnetic tape, hard disk, etc.; and communication devices 1009. The communication device 1009 allows the vehicle to communicate wirelessly or wiredly with other devices to exchange data. Although the diagram shows vehicles with various systems, it should be understood that it is not required to implement or have all of the systems shown. More or fewer systems may be implemented alternatively.

[0122] Specifically, according to the embodiments disclosed in this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments disclosed in this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device, or installed from storage device 1003, or installed from read-only memory 1002. When the computer program is executed by processing device 1001, it performs the functions defined in the methods of the embodiments disclosed in this application.

[0123] The vehicle provided in this application, employing the vehicle control method described in the above embodiments, can solve the technical problem of human-vehicle interference. Compared with the prior art, the beneficial effects of the vehicle provided in this application are the same as those of the vehicle control method provided in the above embodiments, and other technical features of the vehicle are the same as those disclosed in the method of the previous embodiment, and will not be repeated here.

[0124] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any suitable manner in one or more embodiments or examples.

[0125] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

[0126] This application provides a computer-readable storage medium having computer-readable program instructions (i.e., a computer program) stored thereon, the computer-readable program instructions being used to execute the vehicle control method in the above embodiments.

[0127] The computer-readable storage medium provided in this application may be, for example, a USB flash drive, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems or devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system or device. The program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.

[0128] The aforementioned computer-readable storage medium may be included in the vehicle or may exist independently and not installed in the vehicle.

[0129] The aforementioned computer-readable storage medium carries one or more programs. When these programs are executed by a vehicle, the vehicle: responds to a user manual operation event from an onboard device by fusing and quantifying the operational characteristics of the current manual operation to calculate an intent intensity value representing the intensity of the user's operational intent; calculates a protection period for an automatic control command based on a preset basic protection duration, the intent intensity value, and the device physical factor corresponding to the onboard device, wherein the automatic control command is an instruction for automatically controlling the onboard device by a preset scenario strategy script after the user manual operation event, and the protection period is used to constrain the immediate execution of the automatic control command; when the automatic control command is received within the protection period, the vehicle determines the progress interval in which the moment of receiving the automatic control command falls within the protection period; determines a first execution strategy corresponding to the automatic control command based on the progress interval, and performs a first execution action in response to the automatic control command on the onboard device with reference to the first execution strategy.

[0130] Computer program code for performing the operations of this application can be written in one or more programming languages ​​or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, and C++, and conventional procedural programming languages ​​such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a Local Area Network (LAN) or a Wide Area Network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0131] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0132] The modules described in the embodiments of this application can be implemented in software or hardware. The names of the modules do not necessarily limit the functionality of the unit itself.

[0133] The readable storage medium provided in this application is a computer-readable storage medium that stores computer-readable program instructions (i.e., a computer program) for executing the above-described vehicle control method, thereby solving the technical problem of human-vehicle interference. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided in this application are the same as those of the vehicle control method provided in the above embodiments, and will not be repeated here.

[0134] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the vehicle control method described above.

[0135] The computer program product provided in this application can solve the technical problem of human-vehicle interference. Compared with the prior art, the beneficial effects of the computer program product provided in this application are the same as those of the vehicle control method provided in the above embodiments, and will not be repeated here.

[0136] The above description is only a part of the embodiments of this application and does not limit the patent scope of this application. All equivalent structural transformations made under the technical concept of this application and using the contents of the specification and drawings of this application, or direct / indirect applications in other related technical fields, are included in the patent protection scope of this application.

Claims

1. A vehicle control method, characterized in that, The vehicle control method includes: In response to user manual operation events of in-vehicle devices, the operation characteristics of the current manual operation are fused and quantified to calculate the intent intensity value that represents the intensity of the user's operation intent. Based on the preset basic protection duration, the intent strength value, and the device physical factor corresponding to the vehicle device, the protection period duration for the automatic control command is calculated. The automatic control command is the command that the vehicle device is automatically controlled by the preset scenario strategy script after the user's manual operation event. The protection period duration is used to constrain the immediate execution of the automatic control command. When the automatic control command is received within the protection period, determine the progress interval in which the moment of receiving the automatic control command falls within the protection period; Based on the progress interval, a first execution strategy corresponding to the automatic control command is determined, and the on-board equipment is executed with reference to the first execution strategy to respond to the automatic control command.

2. The vehicle control method as described in claim 1, characterized in that, The operational features include the adjustment range of the current manual operation on the vehicle-mounted device, the number of historical manual operations within a preset historical time window before the current manual operation, and the time interval between the most recent historical manual operation and the current manual operation; the step of fusing and quantifying the operational features of the current manual operation to calculate the intent intensity value representing the intensity of the user's operational intent includes: The adjustment range factor is determined based on the proportion of the adjustment range to the preset maximum adjustment range of the vehicle-mounted device; Determine the operation frequency factor based on the historical number of operations; Determine the time decay factor based on the time interval; The adjustment amplitude factor, the operation frequency factor, and the time decay factor are weighted and fused to obtain the intention intensity value of the current manual operation.

3. The vehicle control method as described in claim 2, characterized in that, The step of calculating the protection period for automatic control commands based on a preset basic protection duration, the intent strength value, and the device physical factor corresponding to the on-board equipment includes: When the number of historical operations meets the preset exploration judgment condition, the current manual operation is determined to be in the exploration operation mode. The preset exploration judgment condition includes: the number of historical operations on the vehicle device within the preset historical time window is greater than or equal to a preset number threshold. In the exploration operation mode, the protection period duration is extended to obtain an extended protection period duration.

4. The vehicle control method as described in claim 1, characterized in that, Before the step of calculating the protection period for the automatic control command based on the preset basic protection duration, the intent strength value, and the device physical factor corresponding to the on-board equipment, the method further includes: The execution latency parameter, ergonomic sensitivity parameter, and driving safety impact parameter of the vehicle-mounted device are obtained. The execution latency parameter represents the time required for the vehicle-mounted device to perform a complete action. The ergonomic sensitivity parameter represents the user's perception sensitivity to the adjustment of the vehicle-mounted device. The driving safety impact parameter represents the degree of impact of the adjustment of the vehicle-mounted device on driving safety. The execution delay parameter, the ergonomic sensitivity parameter, and the driving safety impact parameter are weighted and fused to obtain the device physical factor corresponding to the vehicle-mounted device.

5. The vehicle control method as described in claim 1, characterized in that, After determining the progress interval within the protection period where the automatic control command is received when it is received within the protection period, the method further includes: Determine the urgency of the current operating scenario of the vehicle when the automatic control command is received; Based on the intent strength value and the urgency of the scenario, a collaborative decision is made to determine the second execution strategy corresponding to the automatic control command; The vehicle-mounted equipment performs a second execution action in response to the automatic control command, referring to the second execution strategy.

6. The vehicle control method as described in claim 5, characterized in that, After the step of making a collaborative decision based on the intent strength value and the scene urgency to determine the second execution strategy corresponding to the automatic control command, the method further includes: Determine whether to perform a second execution action on the on-board equipment in response to the automatic control command, referring to the second execution strategy; In the first and second execution actions, a third execution action is determined by a preset arbitration rule, and the third execution action is performed on the vehicle-mounted device.

7. The vehicle control method as described in claim 1, characterized in that, After the step of performing a first execution action in response to the automatic control command on the on-board equipment with reference to the first execution strategy, the method further includes: Collect user feedback data on the automatic control command, wherein the final feedback data includes at least one of the following types: acceptance type, indicating that the user accepts the execution action corresponding to the automatic control command; rejection type, indicating that the user rejects the execution action corresponding to the automatic control command; readjustment type, indicating that the user manually operates the same in-vehicle device again within the protection period; and no intervention type, indicating that the user does not intervene in the automatic execution of the automatic control command after the protection period ends. Based on the final feedback data, the basic parameters used to calculate the protection period duration are adjusted, wherein the basic parameters include at least one of the basic duration of the protection period and the fusion weight used to calculate the physical factors of the device.

8. A vehicle control device, characterized in that, The vehicle control device includes: The first calculation module is used to respond to user manual operation events of the in-vehicle device, fuse and quantify the operation characteristics of the current manual operation, and calculate the intent intensity value that represents the intensity of the user's operation intent. The second calculation module is used to calculate the protection period for the automatic control command based on the preset basic protection duration, the intent strength value, and the device physical factor corresponding to the vehicle device. The automatic control command is an instruction for the vehicle device to be automatically controlled by a preset scenario strategy script after the user's manual operation event. The protection period is used to constrain the immediate execution of the automatic control command. The determination module is used to determine the progress interval within the protection period when the automatic control command is received during the protection period. The execution module is used to determine the first execution strategy corresponding to the automatic control command based on the progress interval, and to perform a first execution action on the vehicle-mounted equipment in response to the automatic control command with reference to the first execution strategy.

9. A vehicle, characterized in that, The vehicle includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the vehicle control method as described in any one of claims 1 to 7.

10. A storage medium, characterized in that, The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, it implements the steps of the vehicle control method as described in any one of claims 1 to 7.

11. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the steps of the vehicle control method as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Hybrid power energy management method and system for vehicle fuel cell

    CN112757922A