Scenario intelligent driving active safety control method and system

CN122607367APending Publication Date: 2026-08-21WUHAN JIANGXIA CHUNENG AUTOMOBILE TECHNOLOGY R&D CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610886997.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-18
Publication Date
2026-08-21

AI Technical Summary

Technical Problem

[0007]有鉴于此,本申请实施例提供了一种场景智能驾驶主动安全控制方法及系统,以解决现有技术中因功能碎片化导致多类高风险场景缺乏统一处置、因单一传感器判定导致误触发干扰正常驾驶、因场景适配性差导致特殊路况下易发二次事故、以及因救援链路断裂延误救治时机的技术问题

Benefits of technology

1、本发明通过构建由感知层、决策层、执行层与联动层组成的场景风险统一处置架构,将车身失控、车辆故障、驾驶员失能、极端环境等四类十种高风险场景纳入同一决策体系,并结合多传感器交叉验证、两级预警缓冲以及驾驶员主动操控行为否决机制,在保证真实风险快速响应的同时,有效避免了因单一传感器异常或驾驶员正常动作导致的误触发问题,显著提升了极端失控场景下的甩尾、侧翻事故防控能力以及驾驶员失能场景下的碰撞事故防控能力。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122607367A_ABST
    Figure CN122607367A_ABST
Patent Text Reader

Abstract

The application provides a scene intelligent driving active safety control method and system, comprising: a perception layer collecting driver, vehicle and environment state data and verifying; a decision layer identifying four high-risk scenes of vehicle body out of control, vehicle failure, driver disability and extreme environment through multi-scene identification, hierarchical response and error-proof verification algorithm, executing differentiated strategies according to priority, reserving the highest priority of the driver, avoiding false triggering through multi-sensor cross verification and two-level early warning; an execution layer executing vehicle body stability control and emergency takeover parking; a linkage layer starting vehicle end sound and light, roadside linkage and unmanned aerial vehicle aerial rescue guidance, synchronizing position and state to an external platform. The system realizes a scene active risk avoidance, emergency takeover and automatic rescue closed loop.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of intelligent driving technology for vehicles, specifically to a method and system for active safety control of intelligent driving in various scenarios. Background Technology

[0002] With the rapid development of intelligent driving technology, a vehicle's active safety capabilities have become an important indicator for measuring the level of automotive intelligence. Currently, mainstream vehicles are widely equipped with various active safety functions such as Electronic Stability Program (ESP), Driver Monitoring System (DMS), and Automatic Emergency Braking (AEB), which have improved driving safety to a certain extent. However, existing active safety technologies still have the following significant shortcomings in practical applications: First, the problem of functional fragmentation is prominent. The ESP system mainly deals with short-term loss of vehicle posture control, the driver monitoring system can only issue fatigue or distraction warnings, and the independent emergency takeover system is usually only for single scenarios such as driver incapacitation. There is a lack of a unified coordination mechanism between the systems, which makes it impossible to provide full coverage and integrated handling for multiple high-risk scenarios such as loss of vehicle control, vehicle malfunction, driver incapacitation, and extreme environments, resulting in insufficient safety backup capabilities under complex risks.

[0003] Secondly, the risk of false triggering is high. Most emergency takeover systems rely on a single sensor (such as a steering wheel grip sensor or a DMS camera) to determine the driver's status. When the sensor malfunctions temporarily or the driver makes a normal but large movement (such as turning their head to check the rearview mirror), the system is prone to misinterpreting it as a disability and executing unnecessary takeover, interfering with normal driving and reducing the user's trust in the active safety system.

[0004] Third, they lack adaptability to different scenarios. Traditional emergency takeover solutions are typically designed for ordinary road scenarios and lack specific strategies for handling special scenarios such as highways, tunnels, underground parking lots, and extreme weather (e.g., dense fog, torrential rain). For example, they cannot accurately locate a vehicle in a tunnel without satellite navigation signals; improper parking on highways can easily lead to serious rear-end collisions; and in the case of commercial vehicles, they do not consider the needs for passenger reassurance and remote coordination, all of which could potentially lead to secondary accidents.

[0005] Finally, the rescue chain breaks down. Current solutions at best allow vehicles to pull over, but lack an effective rescue guidance mechanism afterward. Especially in remote areas, at night, in tunnels, or in areas without beacons, rescuers struggle to quickly locate the accident vehicle, and if the driver is incapacitated, they cannot actively call for help or set up warning signs, easily delaying crucial medical intervention.

[0006] In summary, how to achieve integrated active safety control with low false triggering, high scenario adaptability, and a complete rescue link while covering scenario risks is a technical problem that urgently needs to be solved in the field of intelligent driving. Summary of the Invention

[0007] In view of this, the present application provides a scenario-based intelligent driving active safety control method and system to solve the technical problems in the prior art, such as the lack of unified handling for multiple high-risk scenarios due to functional fragmentation, the mis-triggered interference with normal driving due to single sensor judgment, the susceptibility to secondary accidents in special road conditions due to poor scenario adaptability, and the delay in rescue treatment due to the breakage of rescue links.

[0008] This application proposes a scenario-based intelligent driving active safety control method, including: The system collects three types of perception data: driver status, vehicle status, and environmental status, and verifies the validity of the collected perception data to obtain valid data. The effective data is fused to identify high-risk scenarios in which the vehicle is located. These high-risk scenarios include at least two of the following: vehicle loss of control scenarios, vehicle malfunction scenarios, driver incapacitation scenarios, and extreme environment scenarios. The authenticity of the identified scenarios is cross-validated using at least two types of sensors. Control is not triggered when there is anomaly in perception data from only a single source. The priority of handling is determined based on the degree of danger of the identified scenarios, and control strategies are executed accordingly. Control strategies for scenarios with higher handling priorities are executed first, and the highest priority for driver intervention is maintained throughout the process. Control is returned when the driver's active control behavior is detected. Based on the determined handling priority and corresponding control strategy, control commands are generated to execute vehicle stability control and emergency takeover parking; After completing the emergency takeover and parking, rescue guidance will be provided, and the accident location and driver status will be synchronized to an external platform.

[0009] Furthermore, the validity verification of the collected sensing data includes: Preprocessing is performed on the data from each sensor, including unifying the acquisition frequency, aligning timestamps, filtering outliers, and filling in missing values. The validity of individual sensors is verified, and sensor data that exceeds the preset range or shows continuous no change or abrupt changes is marked as invalid and not included in subsequent identification. Consistency verification is performed on multiple sensors. When the deviation between the detection results from multiple sources representing the same state exceeds a preset deviation threshold, a majority voting mechanism is used to determine the valid data.

[0010] Furthermore, the high-risk scenarios in which the vehicle is identified include: For effective data characterizing the vehicle's motion state, when at least one of the following conditions is met, such as yaw rate, lateral acceleration, wheel speed difference between coaxial wheels, and the deviation between the expected yaw rate determined based on wheel angle and vehicle speed and the actual yaw rate of the vehicle, a preliminary judgment is triggered, and when at least two types of sensor features are abnormal at the same time, it is determined to be a vehicle loss of control scenario. For valid data characterizing the status of the power, braking, and steering systems and the longitudinal motion of the vehicle, a preliminary judgment is triggered when at least one of the following occurs: loss of power or braking response, steering system failure, or discrepancy between the actual vehicle motion and the driver's expected motion. A vehicle malfunction scenario is determined when at least two types of sensor features are abnormal at the same time. Based on valid data characterizing the driver's contact control characteristics, facial and posture characteristics, physiological characteristics, metabolic characteristics, and control behavior, a preliminary judgment is triggered when at least one of the following conditions—steering wheel grip force, consciousness state characterization parameters determined based on facial and posture characteristics, physiological indicators, cabin alcohol concentration, and continuous inactivity—reaches the corresponding preset abnormal conditions. When at least two types of sensor characteristics are abnormal at the same time, it is determined to be a driver incapacity scenario. After the preliminary judgment, the driver incapacity is confirmed by the first-level warning and the second-level warning. Based on valid data characterizing precipitation, visibility, light, and road conditions, an extreme environmental scenario is defined when at least one extreme environmental feature, such as precipitation, fog, road icing, or water accumulation, is identified and the driver does not take any corresponding action.

[0011] The preliminary judgment mentioned above refers to the initial judgment made on a scenario when one or some features characterizing a high-risk scenario reach the preset abnormal conditions. The preliminary judgment result does not directly trigger control. It must be confirmed by cross-verification of the simultaneous abnormality of features from at least two types of sensors (for driver incapacity scenarios, it must also be confirmed by the first and second level warnings) before it is determined to be a corresponding high-risk scenario and the corresponding control strategy is triggered.

[0012] Furthermore, determining the disposal priority and implementing the control strategy includes: The priority of handling is determined from high to low based on the risk level of vehicle loss of control scenarios, vehicle malfunction scenarios, driver incapacitation scenarios, and extreme environment scenarios. When multiple scenarios are identified at the same time, the control strategy for the scenario with the highest processing priority is executed first, and the control strategy for the scenario with the lowest processing priority is placed in the waiting queue. After the scenario with the highest processing priority is processed, the scenario with the lowest processing priority is re-evaluated to see if it still exists. If it does, its corresponding control strategy is executed. The control strategies for each scenario include: in the case of loss of vehicle control, direct intervention in braking, steering and power system control; in the case of vehicle malfunction, first remind the driver to take over, and intervene in control and stop the vehicle if there is no response; in the case of driver incapacitation, intervention and deceleration to pull over are performed after confirmation by the first and second level warnings; in the case of extreme environment, first remind the driver to decelerate, and intervene in controlling the vehicle speed without changing the vehicle's travel path if there is no response.

[0013] Furthermore, the vehicle stability control includes independently distributing braking force to the four wheels, correcting wheel angles, and cutting off power output. The independently distributed four-wheel braking force includes: applying braking force to the outer front wheel when oversteering, applying braking force to the inner rear wheel when understeering, and applying symmetrical braking force to both wheels when the lateral acceleration reaches a preset lateral acceleration threshold. The applied braking force is positively correlated with the yaw rate deviation and does not exceed the preset braking force upper limit. The dynamic correction of wheel angle includes: determining the correction angle based on the deviation between the current yaw rate and the target yaw rate and the angle gain coefficient adjusted with vehicle speed. The target yaw rate is the smaller of a first value determined based on vehicle speed and wheel angle and a second value determined based on road surface adhesion conditions. The correction is terminated and steering control is returned when the steering torque applied by the driver reaches a preset steering torque threshold. The power output cut-off control includes: cutting off power output when the vehicle body attitude parameters reach a preset cut-off threshold, and restoring power output after the vehicle body attitude stabilizes.

[0014] Furthermore, the emergency takeover shutdown includes: Based on environmental perception data, the system plans parking routes and performs smooth deceleration, lane changing, and parking operations, with the deceleration acceleration not exceeding the preset deceleration limit. Before executing control actions, the driver's active control behavior is intercepted and verified. When active control behavior is detected, the control action is terminated and control is returned. The interception and verification does not repeat the scene authenticity judgment. For different high-risk scenarios, corresponding emergency takeover and parking strategies are implemented: In the case of loss of vehicle control, vehicle stability control is first implemented, and control is returned or taken over again depending on the driver's condition after the vehicle attitude is stabilized; in the case of vehicle failure, residual power or braking capacity is used to decelerate and pull over to the side of the road; in the case of driver incapacitation, after confirmation by the first and second level warnings, the driver takes over and pulls over to the side of the road; in extreme environment scenarios, after two level warnings, the vehicle speed is reduced to below the preset safe speed and the vehicle is kept in the lane until visibility is restored or the driver takes over.

[0015] Furthermore, the process of providing rescue guidance and synchronizing the accident location and driver status to an external platform includes: Rescue guidance is provided through a combination of vehicle-mounted audio and visual warnings and roadside equipment. The accident location and driver status will be synchronized to emergency contacts, the alarm platform, and the operation platform.

[0016] Furthermore, it also includes: Identify special driving scenarios based on at least one of high-precision maps, satellite navigation signal status, vehicle speed and road speed limits, and operating signs. The special driving scenarios include at least one of highway scenarios, urban core area scenarios, underground space or tunnel scenarios where satellite navigation signals are missing, and operating vehicle scenarios. During emergency takeover parking, corresponding parking strategies are executed for the identified special driving scenarios. The parking strategies include at least one of limiting the parking area, adjusting the parking position or target, and pushing early warning information or vehicle location information through roadside equipment or venue management platform.

[0017] A scenario-based intelligent driving active safety control system, the system comprising a perception layer, a decision-making layer, an execution layer, and a linkage layer; The perception layer is used to collect three types of perception data: driver status, vehicle status, and environmental status. The validity of the collected perception data is verified to obtain valid data, and the valid data is output to the decision layer. The decision-making layer is used to fuse the effective data and identify high-risk scenarios in which the vehicle is located. The high-risk scenarios include at least two of the following: vehicle loss of control scenarios, vehicle malfunction scenarios, driver incapacitation scenarios, and extreme environment scenarios. The decision-making layer cross-verifies the authenticity of the identified scenarios using at least two types of sensors, and does not trigger control when there is an anomaly in perception data from only a single source. The decision-making layer determines the handling priority and executes control strategies based on the degree of danger of the identified scenarios, with priority given to control strategies for scenarios with higher handling priority. The highest priority for driver intervention is maintained throughout the process, and control is returned when the driver's active control behavior is detected. The execution layer is used to perform vehicle stability control and emergency takeover parking according to the control commands generated by the decision layer; The linkage layer is used to guide rescue efforts after the execution layer completes emergency takeover and parking, and to synchronize the accident location and driver status to an external platform.

[0018] Furthermore, the perception layer includes a driver state perception component, a vehicle state perception component, and an environment perception component. The driver state perception component is used to collect the driver's contact control characteristics, facial and posture characteristics, physiological characteristics, and metabolic characteristics. The vehicle state perception component is used to collect vehicle posture, collision, wheel speed, tire pressure, and the working status of the power system, braking system and steering system. The environmental perception component is used to collect information on road conditions, obstacles, precipitation, light, and visibility in front of and around the vehicle.

[0019] Compared with the prior art, the present invention has the following beneficial effects: 1. This invention constructs a unified scenario risk handling architecture consisting of a perception layer, a decision-making layer, an execution layer, and a linkage layer. It incorporates ten high-risk scenarios across four categories, including vehicle loss of control, vehicle malfunction, driver incapacity, and extreme environments, into the same decision-making system. By combining multi-sensor cross-verification, two-level early warning buffering, and a driver active control behavior veto mechanism, it ensures rapid response to real risks while effectively avoiding false triggering caused by a single sensor malfunction or normal driver actions. This significantly improves the ability to prevent skidding and rollover accidents in extreme loss of control scenarios and the ability to prevent collision accidents in driver incapacity scenarios.

[0020] 2. This invention comprehensively solves the pain points of traditional solutions in handling situations where there is no satellite signal, complex road conditions, nighttime, or remote road sections by providing customized handling strategies for special scenarios such as highways, tunnels, underground parking lots, urban core areas, and commercial vehicles, as well as rescue guidance mechanisms such as vehicle-mounted audio and visual warnings, roadside equipment linkage guidance, and vehicle-mounted drone aerial guidance. It significantly shortens the rescue and positioning time after an accident, reduces the incidence of secondary accidents caused by improper placement of warning signs or the inability of rescue personnel to arrive quickly, and realizes a closed-loop handling from proactive risk avoidance and emergency takeover to automatic rescue. Attached Figure Description

[0021] To more clearly illustrate the technical solutions in the embodiments of this application, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0022] Figure 1 This is a flowchart of a scenario-based intelligent driving active safety control method provided in an embodiment of the present invention; Figure 2 This is a diagram illustrating the architecture of an intelligent driving active safety control system for specific scenarios, as provided in an embodiment of the present invention. Figure 3 This is a schematic diagram illustrating the principle of data acquisition and validity verification at the perception layer, provided in an embodiment of the present invention. Figure 4 This is a logic diagram of linkage-layer rescue guidance and special scenario handling provided in an embodiment of the present invention; Figure 5 The following is a logic diagram of hierarchical response and priority superposition for the decision-making level provided in the embodiments of the present invention; Figure 6 The present invention provides a logic diagram for the distribution of braking force and steering correction in the vehicle body control module. Detailed Implementation

[0023] In the following description, specific details such as particular system architectures and techniques are set forth for illustrative purposes and not for limitation, in order to provide a thorough understanding of the embodiments of this application. However, those skilled in the art will understand that this application may also be implemented in other embodiments without these specific details. In other instances, detailed descriptions of well-known systems, apparatuses, circuits, and methods have been omitted so as not to obscure the description of this application with unnecessary detail.

[0024] This invention provides a scenario-based intelligent driving active safety control system and method, which is particularly suitable for passenger cars, operating vehicles and commercial vehicles equipped with L2 and above intelligent driving functions, and can also be extended to other vehicle active safety control fields that require unified handling of risks in multiple scenarios and high-reliability emergency takeover.

[0025] In actual driving, vehicle active safety systems have long faced the severe challenge of lacking a unified handling mechanism for four high-risk scenarios caused by functional fragmentation: loss of vehicle control, vehicle malfunction, driver incapacitation, and extreme environments. Because a single sensor determines the driver's state, the false trigger rate remains high even with sensor malfunction or normal driver actions, severely interfering with normal driving. Due to poor scenario adaptability, they cannot handle special road conditions such as highways, tunnels, underground parking lots, and severe weather, making it difficult to control the secondary accident rate. Furthermore, existing solutions only terminate after parking on the side of the road, lacking a rescue link, making it difficult for rescue personnel to quickly locate the vehicle in remote areas or at night, delaying crucial rescue opportunities. In traditional solutions, ESP and DMS operate independently, simply stacking multiple sensors without establishing a cross-validation mechanism, making them prone to misjudgments due to single-path anomalies. Offline rule calibration relies on extensive real-vehicle road testing, unable to respond online to different driver behaviors and dynamic environmental changes. Conventional open-loop control systems lack the highest priority rejection capability for driver intervention and cannot coordinate with roadside equipment, drones, etc., to guide rescue efforts. The aforementioned shortcomings make it difficult for existing technologies to meet the four core requirements of scene coverage accuracy, false trigger suppression capability, special scene adaptation depth and rescue link integrity in real driving environments with multiple concurrent risks and frequent special scenarios. As a result, the overall vehicle active safety protection capability and user experience are difficult to further improve.

[0026] This invention introduces multimodal fusion perception and multi-scene recognition algorithms, utilizing at least two types of sensors to cross-verify scene authenticity and establish an error-prevention verification mechanism to ensure priority for driver-initiated actions. Based on risk level quantification priority, a graded response decision algorithm is designed to execute customized handling strategies for special scenarios such as highways, tunnels, urban core areas, and commercial vehicles. Furthermore, it integrates vehicle-mounted audio-visual warnings, roadside equipment guidance, and vehicle-mounted drone aerial guidance to construct a rescue mechanism. This forms a comprehensive scene-based proactive safety control technology system integrating full-domain perception, graded decision-making, error-prevention execution, and three-dimensional rescue. The technical solution provided by this invention will be described in detail below with reference to specific embodiments.

[0027] Example 1 This embodiment provides a scenario-based intelligent driving active safety control method, applied to the unified handling of various high-risk scenarios during vehicle operation, such as vehicle loss of control, vehicle malfunction, driver incapacitation, and extreme environments. The overall process of this method is as follows: Figure 1 As shown, the process includes, in sequence, sensing and data acquisition and validity verification, multimodal fusion and scene recognition, hierarchical decision-making and response, execution control, and rescue coordination. The following is a detailed explanation with reference to the accompanying drawings.

[0028] In application, collecting three types of perception data—driver status, vehicle status, and environmental status—is the foundation of the entire method's information acquisition. Driver status refers to the driver's actual physical and operational condition during driving, including whether they are conscious and maintain effective control of the vehicle. The purpose of collecting this status is to determine if the driver can continue to perform driving tasks. Vehicle status refers to the vehicle's posture during driving and the health of its key systems. The purpose of collecting this status is to promptly detect whether the vehicle is on the verge of loss of control or malfunction. Environmental status refers to the road, weather, and obstacle conditions around the vehicle. The purpose of collecting this status is to determine whether external conditions pose a driving risk. Validity verification involves evaluating the authenticity and reliability of data from each sensor, eliminating erroneous data caused by sensor malfunctions or interference. Only data that passes validity verification is included in subsequent identification, ensuring that subsequent judgments are based on reliable information.

[0029] In application, fusing validated sensing data involves combining information from different types of sensors according to a unified temporal and spatial reference to form a holistic understanding of the current driving situation. This aims to overcome the limitations of single-sensor information. Identifying high-risk scenarios involves extracting features that characterize dangerous situations from the fusion results and comparing them with preset feature templates to determine whether the vehicle is in at least two of the four high-risk scenarios: vehicle control failure, vehicle malfunction, driver incapacitation, and extreme environment. Cross-validating the authenticity of the identified scenario using at least two types of sensors means that the scenario is confirmed only when two or more independent sensors point to the same conclusion. Control is not triggered when sensing data from a single source is abnormal, thus avoiding malfunctions caused by individual device failures. Determining the priority of handling based on the severity of the identified scenario means determining the order of handling multiple risks, prioritizing control strategies for scenarios with higher priority. Maintaining the highest priority for driver intervention throughout the process means that regardless of the system's actions, the driver's active operation always has the final say, and control is immediately returned upon detecting active driver intervention.

[0030] In application, the execution of vehicle stability control and emergency takeover stopping based on control commands generated according to the determined handling priorities and corresponding control strategies are the action links of the method. Vehicle stability control refers to adjusting braking, steering, and power to restore the vehicle to a stable driving state when the vehicle's posture becomes abnormal, with the aim of preventing the vehicle from fishtailing, understeer, or rolling over. Emergency takeover stopping refers to the system taking over operation and safely stopping the vehicle when the driver is no longer able to drive, with the aim of preventing accidents even when the driver is incapacitated. The execution links only act upon receiving the corresponding control commands, thus ensuring that the actions are based on consistent and reliable judgment.

[0031] In application, after emergency takeover and parking, providing rescue guidance and synchronizing the accident location and driver status to an external platform are the follow-up and external coordination aspects of the method. Rescue guidance refers to alerting surrounding road users through various means after the vehicle has come to a stop, helping rescue forces locate the vehicle as quickly as possible. Its purpose is to reduce the risk of secondary accidents and shorten rescue arrival time. Synchronizing the accident location and driver status to an external platform involves sending the precise location of the vehicle and the driver's current physical condition to the party capable of organizing rescue. Its purpose is to ensure timely dispatch of rescue resources, thereby extending safety protection from pre-accident avoidance to post-accident rescue.

[0032] Specifically, during an actual driving process, this method continuously collects driver operation and body data, vehicle posture and system status data, as well as surrounding road and weather data. Each data point is validated before being sent to the identification stage. This method fuses these data according to a unified benchmark, extracts scene features, and compares them one by one with feature templates. If the current data falls within the feature range of a dangerous situation, it calls at least two independent types of sensors for cross-validation to confirm its authenticity, thereby determining which of the four high-risk scenarios it belongs to. Based on this, the method determines the priority of handling and prioritizes high-risk scenarios. Before taking action, it checks again whether the driver has engaged in any active control behavior. If so, control is immediately returned to the driver; if only a single source of perception data reports an anomaly, no action is taken. Once intervention is confirmed, the method sends control commands to the execution stage, which performs vehicle stability control or emergency takeover. After the vehicle comes to a stop, rescue guidance is initiated, and the accident location and driver status are synchronized to an external platform, thus completing a closed loop from perception to handling to rescue.

[0033] The three types of perception data can be collected using various independent sensors distributed throughout the cockpit and vehicle body, or by a unified system controller aggregating existing status information from each electronic control unit. Cross-verification of the scenario's realism can be achieved by cross-checking the same physical quantity using two independent sensors, or by cross-checking the logical relationships between different physical quantities. Synchronization of the accident location and driver status to an external platform can be achieved through real-time uploading via cellular mobile networks, or by targeted transmission via the vehicle's emergency call device.

[0034] By sequentially linking and connecting the five stages of perception, fusion recognition, hierarchical decision-making, execution control, and synchronized rescue into a complete closed loop, the previously independent vehicle stability, status monitoring, and emergency response systems can work collaboratively around a unified judgment. By verifying the driver's active control behavior before any action is taken and always maintaining its highest intervention priority, the system can intervene decisively in truly dangerous situations without interfering with normal driver operations. By uniformly identifying four types of high-risk scenarios and handling them according to priority, conflicting responses will not occur when multiple dangers occur simultaneously. By immediately switching to rescue guidance and information synchronization after the vehicle comes to a stop, safety protection extends from proactive risk avoidance to post-incident rescue, thus forming a comprehensive safety net for all driving risks in various scenarios.

[0035] As an optional embodiment, such as Figure 3As shown, the validity verification of the perceived data includes data preprocessing, single-sensor verification, and multi-sensor consistency verification: preprocessing unifies the acquisition frequency of data from each sensor, performs timestamp alignment, filters outliers, and completes missing values; single-sensor verification detects whether the output is within the preset range, whether there is a constant output for a continuous number of cycles, or a sudden jump, and marks abnormal data as invalid; multi-sensor consistency verification uses majority voting when the deviation from multiple sources exceeds the threshold. When the deviation between the steering wheel angle and the image recognition wheel angle is too large, the one with the smaller deviation from the bus steering command is taken as valid data.

[0036] In applications, preprocessing for validating the collected sensing data involves standardizing the acquisition frequency of each sensor to a preset frequency, and performing timestamp alignment, outlier filtering, and missing value completion on all data. Acquisition frequency refers to the number of times a sensor outputs data per unit of time. Standardizing the acquisition frequency of each sensor to a preset frequency ensures that data from different devices have a consistent rhythm, facilitating subsequent processing based on the same time reference. Timestamp alignment involves marking the generation time of each data point and grouping data from different sensors at the same time together, aiming to eliminate misalignments caused by different acquisition times. Outlier filtering removes data points that significantly deviate from the reasonable range, preventing individual erroneous data from interfering with judgment. Missing value completion involves appropriately filling in occasionally missing data according to its preceding and following values, aiming to maintain the continuity and integrity of the data sequence.

[0037] In applications, validating the data of a single sensor involves checking whether the sensor output falls within a preset range and whether there is any unchanging or abrupt change for a preset number of cycles. Abnormal sensor data is marked as invalid and excluded from subsequent identification. The preset range refers to the numerical interval within which a sensor's output should fall under normal operating conditions; output exceeding this range often indicates a malfunction in the device itself. Unchanging for a preset number of cycles means the sensor output remains unchanged for several consecutive acquisition cycles, typically indicating a device malfunction or signal interruption. Abrupt changes refer to drastic jumps in output between adjacent cycles that defy physical laws, usually indicating interference with the device. Once these conditions are detected, the sensor data is marked as invalid, preventing it from participating in subsequent scene identification and thus eliminating erroneous information at its source.

[0038] In applications, consistency verification of multiple sensors refers to using a majority voting mechanism to determine valid data when the deviation between detection results from multiple sources representing the same state exceeds a preset deviation threshold. Multiple sources representing the same state refer to multiple measurement results of the same physical quantity given by different devices; a deviation exceeding the preset deviation threshold indicates undue discrepancy between these results. The majority voting mechanism selects the set of results that are closest to each other and constitute a majority as the reliable result, aiming to obtain correct values ​​even when individual devices malfunction. When the deviation between the steering wheel angle and the wheel rotation angle from image recognition exceeds a preset matching deviation threshold, the smaller deviation between these two values ​​and the steering command output from the bus is taken as valid data. The steering command output from the bus refers to the steering control signal on the vehicle's internal network reflecting driving intentions. Using this as a reference, it is possible to determine which of the two—the steering wheel angle and the wheel rotation angle from image recognition—is closer to the actual steering, thus selecting the more reliable value.

[0039] Specifically, before the data enters the recognition stage, this method first unifies the data from various devices to a preset acquisition frequency and aligns them according to timestamps. Then, it filters out obviously erroneous values ​​and fills in occasional missing data, ensuring consistency in data rhythm and completeness. Next, this method checks each sensor individually; any output that exceeds limits, remains stagnant for extended periods, or exhibits unreasonable jumps is marked as invalid and rejected. Finally, this method compares multiple results for the same physical quantity. When their discrepancies are too large, the result with the most similar values ​​is taken as the valid one. For critical quantities such as steering wheel angle and wheel rotation angle, the steering command on the bus is further introduced as a reference, and the result closest to this command is taken as valid data. After these three processes, the data entering the recognition stage is both consistent and reliable, providing a prerequisite for accurately judging dangerous scenarios.

[0040] Missing values ​​can be filled in using a linear transition based on adjacent data, or by predicting the trend of the physical quantity. For the selection of multiple results for the same physical quantity, majority voting or a third-party reference signal can be used for comparison. Timestamp alignment can be achieved by using a unified hardware clock to label each data stream, or by compensating for data acquisition delays.

[0041] Preprocessing ensures data from different devices are synchronized in terms of rhythm and timing, preventing misalignment and misreading caused by inconsistent acquisition paces. Single-sensor data validity verification promptly eliminates erroneous data from faulty devices, preventing incorrect information from entering subsequent judgments. Multi-sensor consistency verification, supplemented by bus-based steering commands, allows for the selection of reliable values ​​even if individual devices malfunction, significantly reducing the possibility of misjudgment at the source. This provides data-level support for the system to refrain from hasty action when sensing data from a single source is abnormal.

[0042] As an optional embodiment, identifying vehicle body loss of control scenarios and vehicle malfunction scenarios includes: triggering an initial judgment based on vehicle motion state data (yaw rate, lateral acceleration, coaxial wheel speed difference, steering wheel angle and actual yaw matching deviation), determining vehicle body loss of control when at least two types of sensor features are abnormal at the same time, and distinguishing oversteering, understeering, tire blowout loss of control and road slippage according to feature combinations; triggering an initial judgment based on power, braking, steering system status and vehicle longitudinal motion data (accelerator pedal opening and output torque, brake pedal opening and braking pressure, steering torque feedback and fault code, actual acceleration and expected acceleration deviation), and determining vehicle malfunction scenarios when at least two types of sensor features are abnormal at the same time.

[0043] In application, identifying vehicle loss of control scenarios relies on valid data characterizing the vehicle's motion state. This data includes yaw rate, lateral acceleration, wheel speeds of all four wheels, wheel slip angle, and steering wheel angle. Yaw rate refers to the speed at which the vehicle rotates around its vertical axis; lateral acceleration refers to the acceleration experienced by the vehicle in the left-right direction; and wheel slip angle is the angle between the actual direction of wheel travel and its orientation. These quantities collectively reflect whether the vehicle has deviated from the driver's intended trajectory. An initial judgment is triggered when any of the following conditions are met: the vehicle's yaw rate reaches a preset yaw rate threshold; the lateral acceleration reaches a preset lateral acceleration threshold; the wheel speed difference between wheels on the same axle reaches a preset wheel speed difference threshold; or the matching deviation between the steering wheel angle and the vehicle's actual yaw rate exceeds a preset matching deviation threshold. An initial judgment indicates that the system initially suspects the vehicle may be out of control but has not yet confirmed it. To prevent false positives, a vehicle loss of control scenario is only determined when at least two types of sensor features are simultaneously abnormal. The system further identifies the type of loss of control based on feature combinations. Oversteering is characterized by an unexpected yaw rate, excessive lateral acceleration, and a rear wheel slip angle greater than the front wheel slip angle. Understeering is characterized by an unexpected yaw rate, excessive lateral acceleration, and a front wheel slip angle greater than the rear wheel slip angle. Tire blowout loss of control is characterized by a sudden drop in wheel speed, a sudden change in yaw rate, and a sudden change in lateral acceleration. Road slippage is characterized by fluctuations in wheel speed differences exceeding a preset fluctuation threshold and persistently excessive lateral acceleration. The above initial judgment is triggered by several conditions in a logical OR relationship. Therefore, even if the matching deviation exceeds the threshold but the yaw rate is still below the threshold, the initial judgment can still be triggered. The yaw rate lower than expected in understeering and the yaw rate threshold condition in the initial judgment belong to two separate stages: type differentiation and initial judgment triggering, and are not contradictory.

[0044] In application, vehicle fault scenario identification utilizes effective data characterizing the power, braking, and steering system states, as well as the vehicle's longitudinal motion. This data includes powertrain output torque, braking system pressure, steering system torque feedback, bus fault codes, actual vehicle acceleration, accelerator pedal opening, and brake pedal opening. Accelerator pedal opening refers to the degree to which the driver depresses the accelerator; brake pedal opening refers to the degree to which the driver depresses the brake pedal; torque feedback refers to the force returned by the steering system to the steering wheel; and fault codes refer to codes reported by the vehicle's internal network indicating an abnormality in a certain system. Initial judgment is triggered when any of the following conditions are met: accelerator pedal opening reaches a preset threshold but powertrain output torque is zero for a preset duration; brake pedal opening reaches a preset threshold but braking system pressure does not exceed a preset braking pressure threshold for a preset duration; steering torque feedback is abnormal and a steering system fault code is output via the bus; or the deviation between the actual vehicle acceleration and the expected acceleration determined based on driver operation exceeds a preset acceleration deviation threshold for a preset duration. These scenarios correspond to power loss, braking failure, steering failure, and a significant discrepancy between vehicle response and driver intent, respectively. Similarly, to prevent false alarms, a vehicle malfunction scenario is only determined when at least two types of sensor features are abnormal at the same time.

[0045] Specifically, when a vehicle suddenly swerves after running over a foreign object, its yaw rate and lateral acceleration may simultaneously exceed their respective thresholds. The system triggers an initial assessment based on this and checks for the presence of a second type of abnormal feature. Once confirmed, it is classified as a loss-of-control scenario. Further analysis, such as the relationship between the rear and front wheel slip angles, determines whether it is oversteer or another type. Similarly, if the driver has deeply pressed the accelerator but the powertrain output torque remains zero for an extended period, the system triggers an initial vehicle fault assessment and checks for simultaneous abnormalities in braking or steering, along with corresponding fault codes. Once confirmed, it is classified as a vehicle fault scenario. Throughout the entire identification process, the system consistently adheres to the condition of simultaneous anomalies in at least two types of sensor features as the confirmation criterion, thus capturing genuine hazards while avoiding being misled by individual abnormal data.

[0046] The yaw rate can be obtained using the angular velocity measuring element in the vehicle attitude sensor, or by combining the wheel speed difference with the vehicle speed for calculation. Whether power is actually being output can be determined by reading the output torque of the powertrain, or by comparing the relationship between the accelerator pedal opening and the actual vehicle acceleration. Whether braking is properly established can be determined by reading the brake system pressure, or by comparing the relationship between the brake pedal opening and the vehicle deceleration.

[0047] By comprehensively judging multiple characteristics such as yaw rate, lateral acceleration, wheel speed difference, and the matching deviation between steering wheel angle and actual yaw, and adhering to the principle of confirming only when at least two types of characteristics are abnormal simultaneously, the identification of vehicle control loss is both sensitive and robust, effectively suppressing false alarms while ensuring that no real loss of control is missed. By further distinguishing between loss of control types such as oversteer, understeer, tire blowout loss of control, and road slippage, the system can match different stabilization measures for loss of control caused by different reasons. By jointly judging the working data and fault codes of the three major systems of power, braking, and steering, and using the deviation between the actual vehicle response and the driver's intention as evidence, vehicle faults can be accurately and timely identified, buying time for timely intervention and safe stopping.

[0048] As an optional embodiment, identifying driver incapacity scenarios and extreme environment scenarios includes: triggering an initial judgment based on driver contact control characteristics, facial and posture characteristics, physiological characteristics, metabolic characteristics, and control behavior data; determining driver incapacity when at least two types of sensor characteristics are abnormal simultaneously; and triggering a first-level warning after the initial judgment; confirming incapacity and completing a second-level warning if there is no effective operation within a preset time; and triggering an initial judgment based on precipitation intensity, visibility, light intensity, lateral acceleration, and driver operation data; determining an extreme environment scenario when abnormal environmental characteristics are detected simultaneously and the driver does not perform corresponding operations.

[0049] In application, identifying driver incapacity scenarios relies on valid data characterizing the driver's contact and control features, facial and postural features, physiological features, metabolic features, and control behaviors. These quantities reflect the driver's remaining driving ability from five perspectives: grip strength, facial state, physiological rhythm, alcohol content, and operational actions. An initial judgment is triggered when any of the following conditions are met: steering wheel grip strength is below a preset grip strength threshold for a preset duration; the driver is detected as unconscious (eyes closed, face down, or head tilted) for a preset duration; heart rate is below a preset lower threshold or above a preset upper threshold for a preset duration; cabin alcohol concentration reaches a preset alcohol concentration threshold; or there is a continuous preset duration without any pedal or steering wheel operation. To prevent false judgments, a driver incapacity scenario is only determined when at least two types of sensor features are simultaneously abnormal. After the initial judgment, the system triggers an alert for a first-level warning. The purpose of the first-level warning is to awaken the driver, who may only be briefly distracted or drowsy. If no effective operation is performed within the preset duration, driver incapacity is confirmed, triggering a second-level warning. The purpose of the two-level warning is to give conscious drivers time to react and to avoid taking over the reins of drivers who are not actually incapacitated.

[0050] In application, identifying extreme environmental scenarios relies on valid data characterizing precipitation intensity, visibility, light intensity, vehicle speed, lateral vehicle motion, and driver actions. Visibility refers to the distance that can be clearly seen ahead under current conditions, while fog refers to dense fog patches appearing locally. These quantities collectively reflect whether the external environment has deteriorated to the point of endangering driving safety. An initial judgment is triggered when any of the following conditions are met: precipitation reaches a preset precipitation level and visibility is below a preset visibility threshold; light intensity drops sharply and fog features are detected, and visibility is below the preset visibility threshold; or road icing or water accumulation is detected and lateral acceleration fluctuations exceed a preset fluctuation threshold. Unlike the aforementioned scenarios, the confirmation condition for extreme environmental scenarios is the simultaneous detection of abnormal environmental characteristics and the driver's lack of corresponding action. In other words, an extreme environmental scenario is only determined when the external environment is indeed deteriorating and the driver fails to take appropriate measures such as slowing down. This approach captures the actual danger while respecting the driver's normal response.

[0051] Specifically, when a driver suddenly falls ill and takes their hands off the steering wheel, their grip strength will fall below a threshold for a period of time. Simultaneously, the in-cabin camera may detect head movement or closed eyes. The simultaneous abnormality of these two characteristics causes the system to determine that the driver is incapacitated. The system then issues a first-level warning. If the driver does not react within a specified time, incapacity is confirmed, and a second-level warning is issued. Similarly, when a vehicle enters a foggy area, the light sensor detects a sudden drop in light, and the image identifies fog with visibility below a threshold. If the driver does not take any action such as slowing down, the system determines that an extreme environmental scenario has been entered. In both of these types of identification, the system uses the common indication of multiple features as a basis and sets up a two-level warning buffer for suspected incapacity situations, thus achieving a balance between accuracy and reliability.

[0052] The driver's physiological state can be acquired using heart rate and respiration sensors embedded in the seat, or data from wearable physiological monitoring devices. The assessment of a driver's unconscious state can be done using camera image recognition of closed eyes, face down, and head tilt, or by combining this with behavioral assessments of prolonged periods without pedal or steering wheel operation. Visibility can be determined using camera analysis of the clarity of the image ahead, or by combining readings from rainfall and light sensors.

[0053] By characterizing the driver's state from five perspectives—grip strength, facial expression, circadian rhythm, alcohol content, and operational actions—and adhering to a requirement that at least two of these characteristics be abnormal simultaneously before determining incapacity, the system can promptly detect when a driver has truly lost their ability to drive, while avoiding misjudging brief moments of distraction as incapacity. By establishing a two-level warning buffer before confirming incapacity, the system provides conscious drivers with ample opportunity to react and take over, minimizing unnecessary intervention. By setting the confirmation conditions for extreme environments to be met simultaneously with abnormal environmental characteristics and the driver's lack of corresponding action, the system only intervenes when there is a clear external danger and the driver has not yet responded, ensuring safety in adverse weather conditions without disrupting the driver's normal driving.

[0054] As an optional embodiment, such as Figure 5 As shown, determining the priority of handling and executing control strategies includes: ranking the handling priorities from high to low according to the risk level of vehicle loss of control, vehicle malfunction, driver incapacity, and extreme environment; when multiple scenarios are identified simultaneously, the scenario with the highest priority is executed first, and the others are placed in a waiting queue. After the high-priority scenario is handled, it is re-evaluated and executed; combined with the priority superposition mechanism in high-speed scenarios (the overall priority of each scenario is increased, and vehicle loss of control directly triggers the highest level response); based on the principle of minimizing control intervention and maximizing risk reduction, the maximum intervention strategy is selected for vehicle loss of control, the medium intervention strategy is selected for vehicle malfunction, the low intervention and gradual sideline strategy is selected for driver incapacity, and the early warning priority strategy is selected for extreme environment.

[0055] In application, determining the priority of responses involves ranking the risk levels of vehicle loss of control scenarios, vehicle malfunction scenarios, driver incapacitation scenarios, and extreme environment scenarios from highest to lowest, and then assigning corresponding response priorities. Risk level refers to the likelihood and urgency of a scenario causing serious consequences if it occurs, while response priority refers to the order in which the system handles multiple scenarios simultaneously. Vehicle loss of control is placed at the highest level because it leaves the shortest time for response and has the most severe consequences. The order is vehicle malfunction, driver incapacitation, and extreme environment. This ranking aims to address the most dangerous and urgent situations first when resources and time are limited.

[0056] In application, when multiple scenarios are identified simultaneously, the control strategies for scenarios with higher priority are executed first, while the control strategies for scenarios with lower priority are placed in a waiting queue. After the high-priority scenarios are handled, the system re-evaluates whether the low-priority scenarios still exist. If they do, their corresponding control strategies are executed. The waiting queue refers to a queuing mechanism that temporarily suspends unexecuted handling tasks. The purpose of the re-evaluation is to avoid taking unnecessary actions on low-priority hazards that have already disappeared after high-priority scenarios have been handled. The system also incorporates a priority stacking mechanism for special scenarios. In highway scenarios, the overall handling priority of each scenario is increased, and the highest level of response is directly triggered for vehicle loss of control scenarios. The purpose of priority stacking is to improve the decisiveness of handling situations, given the more serious consequences on highways.

[0057] In application, control strategies for each scenario are selected based on the principle of minimizing control intervention and maximizing risk reduction. Control intervention refers to the degree to which the system intervenes in vehicle control. This principle means that intervention should be minimized to reduce the impact on normal driving, while still mitigating risks. The vehicle loss-of-control scenario has the highest risk level and the shortest time window for the accident; therefore, a maximum intervention strategy is selected, directly intervening in braking, steering, and powertrain control, prioritizing vehicle stability. The vehicle malfunction scenario has a moderate accident time window; therefore, a medium intervention strategy is selected, first alerting the driver to take over, and intervening to ensure safe stopping of the vehicle if there is no response. The driver incapacitation scenario has a longer accident time window; therefore, a low intervention strategy is selected, intervening after confirmation by the first and second level warnings, and prioritizing a gentle deceleration and sidewalk strategy to avoid rear-end collisions. The extreme environment scenario has the longest accident time window; therefore, a warning-priority strategy is selected, first alerting the driver to slow down, and intervening to control the vehicle speed without changing the vehicle's path if there is no response.

[0058] Specifically, when the system simultaneously identifies both driver incapacity and extreme environment scenarios on ordinary roads, the method prioritizes handling driver incapacity scenarios, placing extreme environment scenarios in a waiting queue. Only after the vehicle has been safely taken over is the system assessed for the persistence of severe weather. If it remains, the system continues to control the vehicle speed according to the extreme environment strategy. When the vehicle is traveling on a highway, the overall priority for each scenario is increased. Upon detecting loss of control, the system immediately triggers the highest level of response, intervening with maximum intervention in braking, steering, and power to stabilize the vehicle. For different scenarios, the system employs strategies ranging from direct full intervention to intervention after warning, gradual pull-to-the-side movement after warning, and speed control only when necessary, based on the level of intervention from strongest to weakest. This approach mitigates risks while minimizing disruption to the driver.

[0059] In handling multiple concurrent scenarios, the order of response can be determined using a fixed priority queue sorted by risk level, or a priority queue dynamically adjusted based on the length of the accident occurrence time window. Driver alerts can be delivered via voice announcements, or through a multi-channel approach combining instrument panel displays and steering wheel vibrations. Priority stacking for special scenarios can involve either increasing the overall priority of all scenarios or directly assigning a specific scenario as the highest response priority.

[0060] By prioritizing four scenarios according to their risk level from highest to lowest and determining the order of response accordingly, the system ensures that it always addresses the most urgent and serious situations first when multiple dangers coexist, avoiding neglecting any one aspect. Through a waiting queue and a post-response reassessment mechanism, low-priority dangers are neither overlooked nor unnecessarily addressed. By prioritizing all scenarios on highways and directly triggering the highest response for loss of vehicle control, the system enhances its decisiveness, particularly considering the more severe consequences of high-speed driving. Through a differentiated strategy that minimizes intervention while maximizing risk reduction, the system applies appropriate intervention to each scenario, effectively mitigating risks while minimizing the impact on the driver's normal driving.

[0061] As an optional embodiment, the vehicle stability control includes: independently distributing four-wheel braking force (applying braking force opposite to the yaw direction to the outer front wheel during oversteering, with the braking force positively correlated with the yaw rate deviation and not exceeding a preset upper limit, and the gradient not exceeding a preset upper limit; applying assist yaw torque to the inner rear wheel and reducing the front wheel braking force distribution during understeering; symmetrical braking when lateral acceleration reaches a threshold); dynamically correcting the steering angle (determining the expected corrected steering angle based on the yaw rate deviation and the angle gain coefficient dynamically adjusted with vehicle speed, the target yaw rate being the smaller of the product of vehicle speed and steering angle divided by wheelbase and the product of road friction coefficient and gravitational acceleration divided by vehicle speed, the correction angle and rate being constrained by upper limits, and immediately terminating correction and returning control when the driver's steering torque reaches a threshold); and power output cut-off control (immediately cutting off power when the yaw rate or lateral acceleration reaches a cut-off threshold when the vehicle loses control, with cut-off priority higher than understeering in oversteering scenarios, and gradually restoring power after the attitude stabilizes, with the recovery rate not exceeding an upper limit).

[0062] In application, independently distributed four-wheel braking force refers to applying different amounts of braking force to each of the four wheels to generate a torque that returns the vehicle to center. When oversteer is detected, braking force is applied to the outer front wheel to generate a torque opposite to the yaw direction, suppressing further yaw. The applied braking force is dynamically determined according to the following relationship: The applied braking force is positively correlated with the yaw rate deviation; that is, the greater the yaw rate deviation, the greater the applied braking force. Furthermore, the applied braking force does not exceed the preset braking force upper limit, and the application gradient of the braking force on one side does not exceed the preset gradient upper limit. This is to prevent sudden changes in braking force that could lead to further loss of vehicle control. When understeer is detected, braking force is applied to the inner rear wheel to generate an assist yaw moment, improving steering response, while simultaneously reducing the braking force distribution ratio between the two front wheels. When the lateral acceleration reaches a preset lateral acceleration threshold, symmetrical braking force is applied to both wheels to reduce vehicle speed and maintain left-right braking force balance, avoiding the generation of additional yaw moment.

[0063] In application, dynamic wheel steering angle correction refers to determining the expected correction angle based on the deviation between the current yaw rate and the target yaw rate, and a steering angle gain coefficient that dynamically adjusts with vehicle speed, satisfying the following relationship: in, To correct the turning angle as expected; The target yaw rate (take the smaller of the two); This is the actual yaw rate; This is the steering angle gain coefficient, which is dynamically adjusted according to vehicle speed. The higher the vehicle speed, the smaller the value.

[0064] The target yaw rate refers to the ideal yaw rate that a vehicle should have under the current vehicle speed and steering conditions. Its value is the smaller of the following two values, satisfying the following relationship: in, Vehicle speed; For the wheel's turning angle; This refers to the wheelbase; The coefficient of friction of the road surface; This is the acceleration due to gravity.

[0065] The goal of choosing the smaller value is to both follow the driver's intentions and not exceed the limits provided by the road surface adhesion. The expected correction angle is positively correlated with the difference between the current yaw rate and the target yaw rate, and the higher the vehicle speed, the smaller the value of the angle gain coefficient, thus avoiding overcorrection at high speeds. The single correction angle does not exceed the preset upper limit, and the correction rate does not exceed the preset upper limit, in order to make the correction smooth. During the correction process, the driver's steering torque is monitored in real time. When the steering torque applied by the driver reaches the preset steering torque threshold, the correction is immediately terminated and steering control is returned.

[0066] In application, power output cut-off control refers to immediately cutting off power output when the yaw rate or lateral acceleration reaches a preset cut-off threshold in a vehicle loss-of-control scenario. The purpose is to quickly remove driving force to facilitate attitude recovery when the vehicle is severely unstable. Power cut-off is prioritized over understeer in oversteer scenarios because oversteer is more likely to cause a skid and has more severe consequences. After the vehicle attitude stabilizes, i.e., when the yaw rate and lateral acceleration are below the preset yaw rate threshold and remain below the preset lateral acceleration threshold for a preset duration, power output is gradually restored, with the power restoration rate not exceeding the preset upper limit. This aims to prevent a sudden increase in power from causing the vehicle to lose control again.

[0067] Specifically, when the vehicle experiences a fishtail (oversteer), braking force is applied to the outer front wheel. The magnitude of this braking force increases with the yaw rate deviation according to the aforementioned relationship, and is constrained by an upper limit and gradient, thereby generating a torque opposite to the yaw direction to pull the vehicle back. Simultaneously, the system calculates the expected correction angle according to the aforementioned relationship and smoothly corrects the wheel steering angle. If the yaw rate or lateral acceleration has exceeded the cutoff threshold, power output is immediately cut off. After the vehicle's attitude stabilizes and remains stable for a sufficient period, the system gradually restores power at a limited rate. If the driver actively applies a sufficiently large steering torque during this process, the system immediately terminates the correction and returns steering control to the driver, ensuring that the driver's actions always take precedence.

[0068] The independent application of braking force to individual wheels can be achieved using a hydraulic adjustment unit within the vehicle's electronic stability system, or through an electronically controlled braking actuator. Correction of wheel steering angle can be achieved by applying additional steering angle through an electric power steering system, or by directly adjusting the steering angle using a steer-by-wire mechanism. The cutting off and restoration of power output can be achieved by adjusting engine fuel injection and ignition, or by limiting the output torque of the drive motor.

[0069] By applying calculated braking forces, constrained by upper limits and gradients, to the outer front wheel or the inner rear wheel, a properly oriented and appropriately sized self-aligning torque is generated, effectively suppressing fishtailing and understeer and preventing rollover. Wheel steering angles are corrected based on the difference between the target yaw rate and the current yaw rate, combined with a gain coefficient that decreases with vehicle speed. This correction follows driving intentions without exceeding road surface adhesion limits and avoids over-correction at high speeds. Power is cut off in cases of severe instability and gradually restored after stabilization, preventing the driving force from contributing to the loss of control and avoiding secondary loss of control caused by sudden power return. Real-time monitoring of the driver's steering torque ensures that the driver can regain control at any time.

[0070] As an optional implementation, emergency takeover parking includes: planning the optimal parking path based on environmental perception data, performing smooth deceleration, safe lane changing, and parking at the side of the road, with the deceleration acceleration not exceeding a preset deceleration limit; after receiving the control command but before actually executing the action, performing a final interception verification of the driver's active control behavior (any active operation such as pressing the pedal, turning the steering wheel, or pressing the cancel button will immediately terminate control and return control), this interception verification does not repeat the scenario authenticity judgment; special scenario takeover logic: in the case of vehicle loss of control, immediately intervene to stabilize the vehicle, after the attitude is stabilized, detect the driver's status, if there is active control, return control, if there is no response, press the driver's button. In cases of driver incapacity, the system intervenes automatically. In the event of vehicle malfunction, the warning lights are activated and a reminder to pull over is given. If there is no response within a preset time, the system automatically takes over, using residual power or braking to slow down and pull over. If normal braking is not possible, the system uses intermittent braking and downshifting to bring the vehicle to a stop. After stopping, an alarm and rescue guidance are triggered. In the event of driver incapacity, the system takes over after two levels of warnings without response. It prioritizes driving in the side lane, dynamically avoids surrounding vehicles, searches for a safe area, and smoothly pulls over to the side of the road. After stopping, an alarm and rescue guidance are automatically triggered. In extreme environmental scenarios, the system takes over after two levels of warnings without feedback. It gradually reduces the vehicle speed to below the preset safe speed and maintains lane driving while activating fog lights and warning lights until visibility is restored or the driver takes over.

[0071] In this application, the first step in emergency takeover parking is to plan the optimal parking path based on environmental perception data, performing smooth deceleration, safe lane changing, and pulling over to the side of the road. The deceleration acceleration must not exceed a preset deceleration limit to avoid rear-end collisions. The optimal parking path refers to the trajectory that safely and smoothly guides the vehicle to the parking position under current road and surrounding vehicle conditions. The purpose of planning this path is to ensure a smooth and controllable takeover process. Smooth deceleration refers to gradually reducing the vehicle speed with a gentle deceleration; safe lane changing refers to changing lanes after confirming the feasibility of adjacent lanes; and pulling over to the side of the road refers to parking the vehicle in a safe area on the side of the road. Limiting the deceleration acceleration within the preset deceleration limit allows following vehicles sufficient time to react, thus avoiding rear-end collisions. In this embodiment, the preset deceleration limit is set to 2 m / s². 2 That is, the deceleration during emergency takeover and parking should not exceed 2 m / s². 2 .

[0072] In application, a final interception and verification is performed on the driver's active control behavior after receiving the control command and before the actual execution of the control action. If any active operation is detected, such as pressing the pedal, turning the steering wheel, or pressing the cancel button, the control action is immediately terminated and feedback indicates that control has been returned. Active control behavior refers to the driver's conscious actions in operating the vehicle. The purpose of this verification is to immediately return the vehicle to the driver once they indicate that they still have the ability to control it. This interception and verification does not repeat the scenario authenticity judgment, but directly executes the action based on the already passed cross-verification results. Thus, together with the preceding global judgment, it forms a fault-prevention mechanism that connects judgment and interception, avoiding both lag in judgment at a single stage and preventing functional duplication.

[0073] In the application, different takeover control logics are executed for different scenarios. In the case of vehicle loss of control, immediate intervention is implemented to execute vehicle stability control. After the vehicle's attitude stabilizes, the driver's status is detected. If the driver actively engages in control, control is returned; otherwise, the takeover process for driver incapacity scenarios is followed. In the case of vehicle malfunction, warning lights are activated to remind the driver to pull over. If there is no response within a preset time, automatic takeover is initiated, using residual power or braking capacity to gradually decelerate and pull over. If normal braking is not possible, intermittent braking and downshifting are used to achieve a stop. After stopping, an alarm and rescue guidance process is triggered. In the case of driver incapacity, takeover is initiated after confirmation of the first and second level warnings and no response. Prioritizing the outermost lane and dynamically avoiding surrounding vehicles, a safe area is searched for to achieve a smooth pullover. After stopping, an alarm and rescue guidance process is automatically triggered. In extreme environment scenarios, automatic takeover is initiated after two level warnings and no feedback. The vehicle speed is gradually reduced to below a preset safe speed while maintaining lane position, while fog lights and warning lights are activated until visibility is restored or the driver takes over. In this embodiment, the preset safe vehicle speed in extreme environmental scenarios is 40 km / h, meaning the vehicle speed is gradually reduced to below 40 km / h. Similarly, in scenarios where the driver is disabled, the deceleration for a smooth stop at the side of the road does not exceed 2 m / s². 2 .

[0074] Specifically, when a vehicle experiences a power system malfunction such as engine stalling, this method first activates the warning lights and alerts the driver to pull over. If the driver does not respond within a specified time, an optimal parking path is planned based on environmental perception data. The system then uses residual power or braking capacity to smoothly decelerate at a speed not exceeding a preset deceleration limit, and safely changes lanes if necessary, ultimately pulling over to the side of the road. If normal braking is no longer possible, the system uses intermittent braking and downshifting to achieve a complete stop. Once the vehicle comes to a stop, an alarm and emergency assistance guidance are triggered. Throughout the takeover process, this method continuously monitors the driver's actions, such as pressing the pedals, turning the steering wheel, and pressing the cancel button. If any active operation is detected, control is immediately returned to the driver. Furthermore, the system adheres to the principle of not taking action only when there is abnormal perception data from a single source and cross-verification by at least two types of sensors, thus ensuring a secure and accurate takeover.

[0075] The optimal parking path can be planned using trajectory planning based on the fusion of forward-facing millimeter-wave radar and camera perception, or by combining high-precision maps with predictions of surrounding vehicle movement. When normal braking fails, deceleration can be achieved through intermittent braking combined with downshifting, or by using the drive motor to recover energy for braking. The detection of driver's active control behavior can be achieved by directly collecting pedal and steering wheel movements, or by listening to the cancel button signal.

[0076] By limiting deceleration to a low level and planning the optimal stopping path, the emergency takeover ensures its own safety while providing ample reaction time for following vehicles, significantly reducing the risk of rear-end collisions. By verifying the driver's active control behavior before taking action and adhering to a single-source perception data anomaly-free approach and cross-verification with at least two types of sensors, the system never oversteps its authority when the driver is still capable and avoids accidental takeover in case of occasional device malfunctions. Through the design of seamless takeover logic for vehicle loss of control, vehicle malfunction, driver incapacitation, and extreme environments, the system can adopt the most appropriate stopping and protection methods based on the characteristics of each scenario, ensuring that all types of dangers are properly handled.

[0077] As an optional embodiment, such as Figure 4As shown, the linkage layer guides rescue efforts and synchronizes accident location and driver status, including: providing rescue guidance through vehicle-mounted audio-visual warnings and roadside equipment linkage; synchronizing accident location and driver status to emergency contacts, alarm platforms, and the operation platform to achieve unified dispatch of rescue resources; special scenario strategies: in highway scenarios, after taking over, prioritize parking in the emergency lane; if there is no emergency lane, maintain the current lane and reduce speed to below the preset safe speed, and push warning information to the preset range of road sections behind via roadside equipment; in urban core area scenarios, prioritize parking on auxiliary roads or temporary parking spaces, prohibit parking on main roads, intersections, and bus stop areas, and automatically synchronize the vehicle location to the surrounding traffic management platform after parking; in underground space or tunnel scenarios, achieve positioning through visual SLAM, find the nearest safe area to park along the driving direction after taking over, and push the precise location to the location management system through the vehicle positioning module and link broadcasts and indicator lights to guide rescue; in the scenario of commercial vehicles, after the driver becomes incapacitated, implement graded response for safe parking, and simultaneously push alarm information to the operation platform, which then remotely communicates with passengers via voice, reassures them, and guides them to assist in confirming the safety status.

[0078] In this application, rescue guidance is achieved through a combination of vehicle-mounted audio-visual warnings and roadside equipment. Vehicle-mounted audio-visual warnings rely on the vehicle's own lights and sounds to alert the surrounding area, while roadside equipment uses facilities along the road to issue alerts to relevant areas. These two methods complement each other, working from near to far, to ensure that all road users and rescue personnel can quickly detect the accident. The rescue guidance is activated immediately after the vehicle comes to a complete stop, thus alerting those behind and in the surrounding area at the first opportunity and reducing the risk of secondary accidents.

[0079] In this application, the accident location and driver status are synchronized with emergency contacts, the alarm platform, and the operations platform to achieve unified dispatch of rescue resources. Accident location refers to the precise location of the vehicle after it comes to a stop, and driver status refers to the driver's current physical and mental condition. Synchronizing these two pieces of information with multiple parties capable of organizing rescue aims to enable coordinated responses from medical and traffic management forces, thereby shortening rescue arrival time. In this embodiment, the alarm platform includes both the 110 (police) and 120 (ambulance) alarm platforms.

[0080] In application, corresponding control strategies are implemented for specific driving scenarios during emergency takeover and parking. On highways, after takeover, the vehicle prioritizes parking in the emergency lane. If no emergency lane is available, it maintains its current lane and decelerates to below a preset safe speed. Simultaneously, roadside equipment pushes warning information to a preset range of road sections to alert following vehicles to avoid the area. In urban core areas, after takeover, the vehicle prioritizes parking on auxiliary roads or temporary parking spaces, prohibiting parking on main roads, intersections, and bus stop areas. After parking, the vehicle's location is automatically synchronized to the surrounding traffic management platform for nearby law enforcement or rescue forces to be dispatched. In underground spaces or tunnels where satellite navigation signals are lacking, positioning is achieved through visual synchronous positioning and mapping. After takeover, the vehicle searches for the nearest safe area to park along the driving direction. After parking, the onboard positioning module pushes the precise location to the location management system and triggers broadcasts and indicator lights to guide rescue personnel. In commercial vehicles, if the driver becomes incapacitated, scene recognition and tiered response are implemented for safe parking. Alarm information is simultaneously pushed to the operating platform, which remotely communicates with passengers to reassure them and guide them to assist in confirming the safety situation. In this embodiment, the preset safe speed in the highway scenario is 30 km / h, that is, when there is no emergency lane, the speed is reduced to below 30 km / h, and the preset range of road sections for pushing the warning to the rear is a road section 5 kilometers behind. The vehicle positioning module is a vehicle ultra-wideband positioning module.

[0081] Specifically, once a vehicle completes emergency takeover and comes to a complete stop on a highway, it first alerts nearby vehicles with onboard audio and visual warnings. Then, roadside equipment pushes warning information to a pre-defined area behind the vehicle to alert distant vehicles to avoid the area. Simultaneously, the accident location and driver status are synchronized with emergency contacts, the alarm platform, and the operations platform. If the accident occurs in a tunnel where satellite signals are unavailable, the vehicle uses visual synchronous positioning and mapping to determine its location and stops nearby. The onboard positioning module then reports the precise location to the site management system and triggers broadcasts and indicator lights to guide rescue personnel to the scene quickly. If the vehicle is a commercial vehicle and the driver is incapacitated, the operations platform remotely communicates with passengers during the tiered parking process to reassure them and guide them to assist in confirming the safety situation.

[0082] The synchronization of accident location data to external platforms can be achieved via cellular mobile networks or vehicle-mounted satellite communication links. For areas with missing satellite signals, location can be achieved through visual simultaneous localization and mapping, or by combining ultra-wideband ranging. Warnings to vehicles behind can be provided by roadside equipment pushing information to a pre-defined road segment, or by continuous audio-visual warnings from vehicles.

[0083] By using vehicle-mounted audio and visual aids, along with roadside equipment, to guide rescue efforts from near to far, accident warnings cover a range from the vicinity of the vehicle to more distant road sections, enabling nearby vehicles and rescue forces to detect the accident as quickly as possible. By synchronizing the accident location and driver status with emergency contacts, alarm platforms, and operational platforms, rescue resources can be dispatched uniformly and promptly. Through strategies such as prioritizing emergency lane stops and sending warnings to rearwards for highways, urban core areas, underground spaces or tunnels, and for commercial vehicles, avoiding main roads and intersections while notifying traffic management platforms, accurately reporting locations in areas with weak satellite signals using visual positioning, and alerting operational platforms and reassuring passengers, traditional solutions are effectively addressed in these special scenarios.

[0084] As an optional extension, the linkage layer also includes vehicle-mounted drone rescue guidance. After emergency takeover and parking, the system can automatically release the vehicle-mounted drone. The drone is equipped with a flashing light and a positioning beacon, and carries a foldable triangular warning sign that can be electromagnetically grasped. The drone automatically flies along the emergency lane to about 100 meters behind the vehicle, places the warning sign on the road, and then returns to hover near the vehicle, continuously issuing warnings to vehicles behind via the flashing light and positioning beacon. Through drone aerial guidance, the effective distance limitation of vehicle-mounted audio and visual warnings can be overcome, allowing for earlier warnings to vehicles behind from a greater distance, further reducing the risk of secondary accidents.

[0085] Example 2 This embodiment provides a scenario-based intelligent driving active safety control system for executing the scenario-based intelligent driving active safety control method of Embodiment 1. The system integrates a perception layer, a decision-making layer, an execution layer, and a linkage layer. The core system architecture is as follows: Figure 2 As shown, a closed loop of proactive risk avoidance, emergency takeover, and automatic rescue under scenario risks is achieved. The following describes each layer and its composition. The specific identification, control, and handling logic executed by each layer is the same as in Example 1 and will not be repeated.

[0086] In application, the perception layer collects three types of perception data: driver status, vehicle status, and environmental status. It verifies the validity of the collected perception data and outputs the verified data to the decision layer. The perception layer is the foundation for the entire system's information acquisition; the three types of data it collects reflect whether the driver can continue driving, whether the vehicle is on the verge of loss of control or malfunction, and whether external conditions pose a driving risk. After collecting data, the perception layer does not use it directly. Instead, it first verifies the authenticity and reliability of each data point, eliminating erroneous data caused by device failure or interference. Only data that passes the validity verification is output to the decision layer, ensuring that subsequent judgments are based on reliable information.

[0087] In application, the decision layer is used to fuse validated perception data and identify high-risk scenarios where the vehicle is located. High-risk scenarios include at least two of the following: vehicle loss of control scenarios, vehicle malfunction scenarios, driver incapacitation scenarios, and extreme environment scenarios. The decision layer is the system's judgment and command component. It fuses information from different types of sensors according to a unified benchmark to form a holistic understanding, then extracts features and compares them with templates to determine whether the vehicle is currently in a certain type of danger. The decision layer cross-validates the authenticity of the identified scenario using at least two types of sensors, and does not trigger control if perception data from only a single source is abnormal. The decision layer determines the priority of action based on the degree of danger of the identified scenario, prioritizing control strategies for scenarios with higher priority, and retaining the highest priority for driver intervention throughout the process. Control is immediately returned upon detecting active driver control behavior.

[0088] In application, the execution layer is used to perform vehicle stability control and emergency takeover stopping based on the control commands output by the decision-making layer. The execution layer is the action part of the system. Vehicle stability control refers to adjusting braking, steering, and power to return the vehicle to a stable driving state to prevent fishtailing, understeer, or rollover when the vehicle's posture becomes abnormal. Emergency takeover stopping refers to the system taking over operation and safely stopping the vehicle when the driver is no longer able to drive. The execution layer only acts after receiving commands from the decision-making layer, thus ensuring that the actions are based on a unified judgment.

[0089] In application, the linkage layer is used to guide rescue efforts after the execution layer completes emergency takeover and parking, and to synchronize the accident location and driver status to an external platform. The linkage layer is the system's aftermath and external coordination part. It alerts surrounding traffic participants in various ways and helps rescue forces locate the vehicle as quickly as possible. At the same time, it sends the vehicle's precise location and the driver's current physical condition to the party capable of organizing rescue, thereby reducing the risk of secondary accidents and shortening rescue arrival time.

[0090] Specifically, during an actual driving process, the perception layer continuously collects driver operation and body data, vehicle posture and system status data, as well as surrounding road and weather data. Each data point is validated before being sent to the decision layer. The decision layer integrates this data according to a unified benchmark, extracts scene features, and compares them one by one with templates. Once the current data falls within the characteristic range of a dangerous situation, it calls at least two independent types of sensors for cross-validation to confirm its authenticity, thereby determining which of the four high-risk scenarios it belongs to. Based on this, the decision layer determines the priority of handling and prioritizes high-risk scenarios. Before taking action, it checks whether the driver has engaged in any active control behavior; if so, control is immediately returned to the driver. If only a single source of perception data reports an anomaly, no action is taken. After confirming the need for intervention, the decision layer sends control commands to the execution layer, which executes vehicle stability control or emergency takeover to stop the vehicle. Once the vehicle has come to a complete stop, the linkage layer immediately provides rescue guidance and synchronizes the accident location and driver status to an external platform, thus completing a closed loop from perception to handling to rescue.

[0091] The three types of perception data can be collected using various independent sensors distributed throughout the cockpit and vehicle body, or by a unified system controller aggregating existing status information from each electronic control unit. Cross-verification of the scenario's realism can be achieved by cross-checking the same physical quantity using two independent sensors, or by cross-checking the logical relationships between different physical quantities. Synchronization of the accident location and driver status to an external platform can be achieved through real-time uploading via cellular mobile networks, or by targeted transmission via the vehicle's emergency call device.

[0092] Through a four-layered interconnection of perception, decision-making, execution, and coordination, information collection, judgment, action, and aftermath are clearly divided and linked into a unified whole. This allows the previously independent vehicle stability, status monitoring, and emergency response to work collaboratively around a single judgment. By having the decision-making layer verify the driver's active control behavior before taking action and always retaining the driver's highest intervention authority, the system can decisively intervene in truly dangerous situations without interfering with the driver's normal operation. By uniformly identifying four types of high-risk scenarios and handling them according to priority, conflicting responses will not occur when multiple dangers occur simultaneously. Once the vehicle has come to a complete stop, the system immediately transitions to rescue guidance and information synchronization, extending safety protection from proactive risk avoidance to post-accident rescue.

[0093] As an optional embodiment, such as Figure 6As shown, the perception layer includes a driver state perception component, a vehicle state perception component, and an environmental perception component: the driver state perception component collects the driver's contact control characteristics, facial and posture characteristics, physiological characteristics, and metabolic characteristics to perform multi-dimensional cross-verification of the driver's state; the vehicle state perception component collects vehicle posture, collision, wheel speed, tire pressure, and the working status of the power system, braking system, and steering system to monitor the vehicle posture and vehicle health status in real time; the environmental perception component collects information on road conditions, obstacles, precipitation, light, and visibility in front and around the vehicle to identify environmental information such as surrounding road conditions, obstacles, extreme weather, and water accumulation or icy road surfaces.

[0094] In application, the driver state perception component collects the driver's tactile control characteristics, facial and posture characteristics, physiological characteristics, and metabolic characteristics to perform multi-dimensional cross-validation of the driver's state. Tactile control characteristics refer to the driver's grip strength on the steering wheel, used to determine if the driver's hands are still effectively controlling the steering wheel. Facial and posture characteristics refer to the driver's eyes, facial orientation, and head posture, used to determine if the driver is conscious and focused on the road ahead. Physiological characteristics refer to the driver's heart rate and breathing rhythm, used to detect signs of sudden illness from a physiological perspective. Metabolic characteristics refer to the alcohol content in the vehicle's air, used to detect potential intoxication. Combining information from these four levels avoids drawing incomplete conclusions based on only one type of information.

[0095] In application, the vehicle state perception component collects data on vehicle attitude, collision status, wheel speed, tire pressure, and the operational status of the powertrain, braking, and steering systems to monitor vehicle attitude and overall vehicle health in real time. Vehicle attitude is used to detect deviations from normal driving posture; collision status is used to promptly identify impact events; wheel speed is used to detect abnormal wheel rotation; tire pressure is used to detect potential hazards such as tire blowouts; and the operational status of the powertrain, braking, and steering systems is used to assess the normal functioning of these three critical systems. These multiple aspects collectively cover the vehicle's health status, enabling early and comprehensive detection of loss of control and malfunctions.

[0096] In applications, environmental perception components collect information on road conditions, obstacles, precipitation, lighting, and visibility ahead and in the surrounding area to identify environmental information such as road conditions, obstacles, extreme weather, and waterlogged or icy surfaces. Road conditions and obstacles ahead and in the surrounding area are used to identify lanes and targets ahead; precipitation is used to determine if there is severe weather such as heavy rain; lighting is used to detect sudden changes in lighting when entering tunnels or encountering fog; and visibility is used to measure the distance that can be seen clearly ahead under current conditions. All of this information collectively characterizes the external environment, providing a basis for judging whether external conditions pose a driving risk.

[0097] Specifically, during driving, the driver state perception component simultaneously collects driver information from four perspectives: grip strength, facial expression, physiological rhythm, and alcohol content. The vehicle state perception component collects data on vehicle posture, collision status, wheel speed, tire pressure, and the operation of the power, braking, and steering systems. The environmental perception component collects data on targets ahead, surrounding images, precipitation intensity, and light intensity. These three components work in parallel, continuously providing the system with raw information from the driver, vehicle, and environment. When an anomaly occurs in any aspect, multiple devices within the corresponding component simultaneously reflect the anomaly from different angles, thus providing conditions for subsequent cross-validation.

[0098] The detection of driver grip strength can be achieved using a pressure-sensitive film placed on the inner rim of the steering wheel, or by using a strain gauge to measure minute deformations on the steering wheel. The acquisition of the driver's facial and head posture can be achieved using an infrared imaging device, or by using a depth imaging device combined with dot-matrix projection. The detection of targets ahead can be achieved using a ranging and velocimetry device that emits electromagnetic waves and receives the echoes, or by fusing the data with images to jointly determine the target's distance and speed.

[0099] By assigning driver, vehicle, and environment data to three separate sets of sensing components, each with its own focus, and with multiple devices operating from different physical angles covering each aspect, the failure or disturbance of any single device ensures that monitoring capability for that aspect is not lost. By characterizing driver status through four dimensions—grip strength, facial expression, circadian rhythm, and alcohol content—the assessment of driver incapacity no longer relies on a single clue, significantly improving the reliability of the judgment. By covering vehicle status with multiple aspects such as posture, collision, wheel speed, tire pressure, and power, braking, and steering, vehicle loss of control and malfunctions can be detected early and comprehensively, laying a solid data foundation for accurate identification of dangerous scenarios.

[0100] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.

Claims

1. A scenario-based intelligent driving active safety control method, characterized in that, include: The system collects three types of perception data: driver status, vehicle status, and environmental status, and verifies the validity of the collected perception data to obtain valid data. The effective data is fused to identify high-risk scenarios in which the vehicle is located. These high-risk scenarios include at least two of the following: vehicle loss of control scenarios, vehicle malfunction scenarios, driver incapacitation scenarios, and extreme environment scenarios. The authenticity of the identified scenarios is cross-validated using at least two types of sensors. Control is not triggered when there is anomaly in perception data from only a single source. The priority of handling is determined based on the degree of danger of the identified scenarios, and control strategies are executed accordingly. Control strategies for scenarios with higher handling priorities are executed first, and the highest priority for driver intervention is maintained throughout the process. Control is returned when the driver's active control behavior is detected. Based on the determined handling priority and corresponding control strategy, control commands are generated to execute vehicle stability control and emergency takeover parking; After completing the emergency takeover and parking, rescue guidance will be provided, and the accident location and driver status will be synchronized to an external platform.

2. The scenario-based intelligent driving active safety control method according to claim 1, characterized in that, The validity verification of the collected sensing data includes: Preprocessing is performed on the data from each sensor, including unifying the acquisition frequency, aligning timestamps, filtering outliers, and filling in missing values. The validity of individual sensors is verified, and sensor data that exceeds the preset range or shows continuous no change or abrupt changes is marked as invalid and not included in subsequent identification. Consistency verification is performed on multiple sensors. When the deviation between the detection results from multiple sources representing the same state exceeds a preset deviation threshold, a majority voting mechanism is used to determine the valid data.

3. The scenario-based intelligent driving active safety control method according to claim 1, characterized in that, The high-risk scenarios in which the vehicle is identified include: For effective data characterizing the vehicle's motion state, when at least one of the following conditions is met, such as yaw rate, lateral acceleration, wheel speed difference between coaxial wheels, and the deviation between the expected yaw rate determined based on wheel angle and vehicle speed and the actual yaw rate of the vehicle, a preliminary judgment is triggered, and when at least two types of sensor features are abnormal at the same time, it is determined to be a vehicle loss of control scenario. For valid data characterizing the status of the power, braking, and steering systems and the longitudinal motion of the vehicle, a preliminary judgment is triggered when at least one of the following occurs: loss of power or braking response, steering system failure, or discrepancy between the actual vehicle motion and the driver's expected motion. A vehicle malfunction scenario is determined when at least two types of sensor features are abnormal at the same time. Based on valid data characterizing the driver's contact control characteristics, facial and posture characteristics, physiological characteristics, metabolic characteristics, and control behavior, a preliminary judgment is triggered when at least one of the following conditions—steering wheel grip force, consciousness state characterization parameters determined based on facial and posture characteristics, physiological indicators, cabin alcohol concentration, and continuous inactivity—reaches the corresponding preset abnormal conditions. When at least two types of sensor characteristics are abnormal at the same time, it is determined to be a driver incapacity scenario. After the preliminary judgment, the driver incapacity is confirmed by the first-level warning and the second-level warning. Based on valid data characterizing precipitation, visibility, light, and road conditions, an extreme environmental scenario is defined when at least one extreme environmental feature, such as precipitation, fog, road icing, or water accumulation, is identified and the driver does not take any corresponding action.

4. The scenario-based intelligent driving active safety control method according to claim 3, characterized in that, The process of determining the priority of actions and implementing control strategies includes: The priority of handling is determined from high to low based on the risk level of vehicle loss of control scenarios, vehicle malfunction scenarios, driver incapacitation scenarios, and extreme environment scenarios. When multiple scenarios are identified at the same time, the control strategy for the scenario with the highest processing priority is executed first, and the control strategy for the scenario with the lowest processing priority is placed in the waiting queue. After the scenario with the highest processing priority is processed, the scenario with the lowest processing priority is re-evaluated to see if it still exists. If it does, its corresponding control strategy is executed. The control strategies for each scenario include: in the case of loss of vehicle control, direct intervention in braking, steering and power system control; in the case of vehicle malfunction, first remind the driver to take over, and intervene in control and stop the vehicle if there is no response; in the case of driver incapacitation, intervention and deceleration to pull over are performed after confirmation by the first and second level warnings; in the case of extreme environment, first remind the driver to decelerate, and intervene in controlling the vehicle speed without changing the vehicle's travel path if there is no response.

5. The scenario-based intelligent driving active safety control method according to claim 4, characterized in that, The vehicle stability control includes independently distributing braking force to the four wheels, correcting wheel angle, and cutting off power output; The independently distributed four-wheel braking force includes: applying braking force to the outer front wheel when oversteering, applying braking force to the inner rear wheel when understeering, and applying symmetrical braking force to both wheels when the lateral acceleration reaches a preset lateral acceleration threshold. The applied braking force is positively correlated with the yaw rate deviation and does not exceed the preset braking force upper limit. The dynamic correction of wheel angle includes: determining the correction angle based on the deviation between the current yaw rate and the target yaw rate and the angle gain coefficient adjusted with vehicle speed. The target yaw rate is the smaller of a first value determined based on vehicle speed and wheel angle and a second value determined based on road surface adhesion conditions. The correction is terminated and steering control is returned when the steering torque applied by the driver reaches a preset steering torque threshold. The power output cut-off control includes: cutting off power output when the vehicle body attitude parameters reach a preset cut-off threshold, and restoring power output after the vehicle body attitude stabilizes.

6. The scenario-based intelligent driving active safety control method according to claim 3, characterized in that, The emergency takeover shutdown includes: Based on environmental perception data, the system plans parking routes and performs smooth deceleration, lane changing, and parking operations, with the deceleration acceleration not exceeding the preset deceleration limit. Before executing control actions, the driver's active control behavior is intercepted and verified. When active control behavior is detected, the control action is terminated and control is returned. The interception and verification does not repeat the scene authenticity judgment. For different high-risk scenarios, corresponding emergency takeover and parking strategies are implemented: In the case of loss of vehicle control, vehicle stability control is first implemented, and control is returned or taken over again depending on the driver's condition after the vehicle attitude is stabilized; in the case of vehicle failure, residual power or braking capacity is used to decelerate and pull over to the side of the road; in the case of driver incapacitation, after confirmation by the first and second level warnings, the driver takes over and pulls over to the side of the road; in extreme environment scenarios, after two level warnings, the vehicle speed is reduced to below the preset safe speed and the vehicle is kept in the lane until visibility is restored or the driver takes over.

7. The scenario-based intelligent driving active safety control method according to claim 1, characterized in that, The process of providing rescue guidance and synchronizing the accident location and driver status to an external platform includes: Rescue guidance is provided through a combination of vehicle-mounted audio and visual warnings and roadside equipment. The accident location and driver status will be synchronized with emergency contacts, the alarm platform, and the operation platform.

8. The scenario-based intelligent driving active safety control method according to claim 6, characterized in that, Also includes: Identify special driving scenarios based on at least one of high-precision maps, satellite navigation signal status, vehicle speed and road speed limits, and operating signs. The special driving scenarios include at least one of highway scenarios, urban core area scenarios, underground space or tunnel scenarios where satellite navigation signals are missing, and operating vehicle scenarios. During emergency takeover parking, corresponding parking strategies are executed for the identified special driving scenarios. The parking strategies include at least one of limiting the parking area, adjusting the parking position or target, and pushing early warning information or vehicle location information through roadside equipment or venue management platform.

9. A scenario-based intelligent driving active safety control system, characterized in that, The system includes a perception layer, a decision-making layer, an execution layer, and a linkage layer; The perception layer is used to collect three types of perception data: driver status, vehicle status, and environmental status. The validity of the collected perception data is verified to obtain valid data, and the valid data is output to the decision layer. The decision-making layer is used to fuse the effective data and identify high-risk scenarios in which the vehicle is located. The high-risk scenarios include at least two of the following: vehicle loss of control scenarios, vehicle malfunction scenarios, driver incapacitation scenarios, and extreme environment scenarios. The decision-making layer cross-verifies the authenticity of the identified scenarios using at least two types of sensors, and does not trigger control when there is an anomaly in perception data from only a single source. The decision-making layer determines the handling priority and executes control strategies based on the degree of danger of the identified scenarios, with priority given to control strategies for scenarios with higher handling priority. The highest priority for driver intervention is maintained throughout the process, and control is returned when the driver's active control behavior is detected. The execution layer is used to perform vehicle stability control and emergency takeover parking according to the control commands generated by the decision layer; The linkage layer is used to guide rescue efforts after the execution layer completes emergency takeover and parking, and to synchronize the accident location and driver status to an external platform.

10. The scenario-based intelligent driving active safety control system according to claim 9, characterized in that, The perception layer includes a driver state perception component, a vehicle state perception component, and an environment perception component. The driver state perception component is used to collect the driver's contact control characteristics, facial and posture characteristics, physiological characteristics, and metabolic characteristics. The vehicle state perception component is used to collect vehicle posture, collision, wheel speed, tire pressure, and the working status of the power system, braking system and steering system. The environmental perception component is used to collect information on road conditions, obstacles, precipitation, light, and visibility in front of and around the vehicle.