Emergency and actuator linkage degradation method and system for autonomous work vehicle

CN122808774APending Publication Date: 2026-09-25DONGFENG COMML VEHICLE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610881514.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-17
Publication Date
2026-09-25

AI Technical Summary

Technical Problem

[0008]本发明的第一目的在于提供一种自动驾驶作业车辆的应急与执行机构联动降级方法,旨在解决现有技术在处理自动驾驶作业车辆失效应急场景时,存在的停靠位置不当、执行机构降级操作不当导致的安全问题

Benefits of technology

1、提升了应急处置的安全性。通过引入作业语义地图进行停靠决策,确保了停靠位置的合规性与安全性,避免占用作业通道或进入危险区域;通过执行机构与底盘的联动降级和显式时序对齐,确保作业车辆停稳时作业机构已处于安全锁位状态,避免引发二次事故。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122808774A_ABST
    Figure CN122808774A_ABST
Patent Text Reader

Abstract

The application discloses an emergency and actuator linkage degradation method and system of an automatic driving work vehicle, and relates to the technical field of automatic driving. The method comprises the following steps: obtaining the failure level, emergency level, current work state and actuator type of the work vehicle; performing hierarchical emergency parking decision based on the emergency level and the work semantic map containing semantic layers such as work lanes and road shoulder parking belts; generating a linkage degradation sequence for the actuator based on a three-dimensional degradation decision matrix related to the failure level, work state, actuator type and emergency level; performing explicit timing alignment on the parking remaining time and actuator degradation time consumption based on the two-dimensional orthogonal arbitration of the failure level and the emergency level; synchronously executing through an independent safety control channel, and triggering local rollback when the actuator envelope exceeds the boundary. Through the deep cooperation and timing control of the chassis and the actuator, the safety and response efficiency of emergency disposal are significantly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of autonomous driving technology for commercial vehicles, and in particular to a method and system for emergency response and actuator linkage downgrade of autonomous driving operation vehicles. Background Technology

[0002] The development of autonomous driving technology has placed extremely high demands on the safety of work vehicles. In the event of a systemic failure in a work vehicle, a minimum-risk emergency response is required. Existing technologies have disclosed various emergency handling solutions for general-purpose autonomous work vehicles, such as using general-purpose high-precision maps for route selection to achieve parallel parking, or using redundant controllers for route planning and arbitration.

[0003] However, existing emergency response solutions for autonomous work vehicles are mainly designed for passenger cars or ordinary trucks. When applied to autonomous work vehicles equipped with actuators, they have serious limitations and safety hazards. The lack of decision-making information, with emergency parking decisions relying solely on general high-precision maps and lacking an understanding of the semantics specific to operational scenarios such as "operation lanes," "roadside parking areas," and "loading and unloading areas," may lead to vehicles being parked in inappropriate or even dangerous locations, causing risks.

[0004] If the actuators malfunction, the emergency plan completely neglects the coordinated control of the actuators (such as sweeping brushes, water pumps, and grab buckets). During an emergency shutdown, the actuators may still be rotating, spraying, or in an unsafe position, which can easily lead to secondary accidents.

[0005] The lack of timing coordination means that there is no time-coordination mechanism between the parking process of the work vehicle and the safety degradation process of the actuator, which may lead to dangerous situations such as "the work vehicle has come to a complete stop but the actuator is still in a dangerous state" or "the work vehicle has stopped before the actuator has been locked".

[0006] The response strategy is simplistic and fails to comprehensively consider the failure level and urgency level of the working vehicle, resulting in a limited emergency response strategy. For example, applying excessive emergency braking when the working vehicle is still controllable, or attempting to pull over when the working vehicle is already out of control, can easily lead to safety accidents.

[0007] This application provides a method and system for emergency response and actuator linkage downgrade of autonomous driving operation vehicles, aiming to solve the above-mentioned problems. Summary of the Invention

[0008] The primary objective of this invention is to provide an emergency and actuator linkage degradation method for autonomous driving work vehicles, aiming to solve the safety problems caused by improper parking positions and improper actuator degradation operations when dealing with emergency scenarios of autonomous driving work vehicles failure in the prior art.

[0009] To achieve the above objectives, the present invention provides a method for emergency response and actuator linkage degradation of an automated driving operation vehicle, comprising: S1. Obtain the failure level L, emergency level F, current operation status S, and actuator type A of the work vehicle; S2. Based on the emergency level F and the semantic map of operations including the semantic layers of the work lane, shoulder parking strip, parking restricted area, loading / unloading / transfer area, and actuator envelope area, make emergency parking decisions; S3. Based on the three-dimensional degradation decision matrix M[L,S,A] related to the failure level L, the operation state S, and the actuator type A, and combined with the emergency level F, a linkage degradation sequence is generated for the actuators of the operation vehicle. S4. Based on the two-dimensional orthogonal arbitration of failure level L and emergency level F, perform explicit timing alignment on the remaining docking time t_stop generated by the emergency docking decision and the mechanism degradation time t_deg of the linkage degradation sequence. S5. Through a security control channel independent of the main system, docking and degradation commands are executed synchronously. When an out-of-bounds boundary is detected in the envelope area of ​​the actuator, a local priority degradation rollback is triggered to prioritize the recovery of the out-of-bounds actuator.

[0010] Optionally, the emergency stopping decision adopts an asymmetric roadside search mechanism, which, under the traffic rule of driving on the right, prioritizes searching the area to the right of the direction the work vehicle is traveling.

[0011] Alternatively, emergency docking decisions may also include: Candidate docking points are scored using a cost function J, and the weight of the cost function J increases with the failure level L according to a preset mapping relationship.

[0012] Optionally, the linkage degradation sequence adopts a three-stage timing structure of power deactivation, locking, and pressure release.

[0013] Optionally, generating the linkage degradation sequence includes tailoring the three-stage timing structure according to the emergency level F: when the emergency level F indicates emergency braking, at least the power cut-off and locking stages are retained, and the pressure release is delayed until the vehicle comes to a complete stop; when the emergency level F indicates chassis loss of control, at least the power cut-off and locking stages are forcibly executed, and remote takeover is requested.

[0014] Optionally, the three-stage timing structure sets a maximum time window for each type of actuator, wherein the total time for electric actuators does not exceed t_elec, the total time for hydraulic actuators does not exceed t_hy, the total time for pneumatic actuators does not exceed t_air, and the total degradation time t_deg for all actuators does not exceed the set threshold.

[0015] Optionally, explicit timing alignment includes: When t_deg is detected to be greater than t_stop, the adjustment strategy is executed according to the following priority: Move the docking target point downstream; Insert a deceleration and holding section into the stopping trajectory; Switch to an alternative stop location; Send an emergency deceleration request to the main controller of the work vehicle.

[0016] Optionally, the two-dimensional orthogonal arbitration also includes: Depending on the emergency level F, you can choose from three modes: semantic docking, emergency braking, or requesting remote takeover.

[0017] Optionally, when the emergency level F is chassis loss of control, the following actions shall be performed: Initiate remote takeover requests in parallel and control the actuators of the work vehicles to perform preset safety operations.

[0018] This invention provides an emergency and actuator linkage degradation system for autonomous driving work vehicles, used to implement the above method, including: The information acquisition module is used to acquire the failure level L, emergency level F, current operation status S, and actuator type A of the work vehicle; The operation semantic map module is used to store and update the operation semantic map, which includes five semantic layers: operation lane, shoulder parking strip, parking restricted area, loading / unloading / transfer area and execution agency envelope area, and provides a real-time query interface; The docking decision module is used to make emergency docking decisions based on the emergency level F and the operational semantic map, and to generate the remaining docking time t_stop; The degradation decision module is used to generate a linkage degradation sequence for the actuators of the work vehicle based on the three-dimensional degradation decision matrix M[L,S,A] related to the failure level L, the work status S, the actuator type A and the emergency level F. The timing coordination module is used for two-dimensional orthogonal arbitration based on failure level L and emergency level F, and according to explicit timing alignment rules, it coordinates the remaining docking time t_stop generated by the docking decision module and the mechanism degradation time t_deg of the linkage degradation sequence. The safety control channel is used to receive instructions from the timing coordination module, synchronously control the chassis to perform docking actions and the actuators to perform degradation actions, and trigger local priority degradation backoff when the actuator envelope area is detected to be out of bounds; the safety control channel is independent of the main system of the work vehicle.

[0019] The present invention has the following beneficial effects: 1. Improved safety in emergency response. By introducing a semantic map for parking decisions, the compliance and safety of parking locations are ensured, avoiding obstruction of work lanes or entry into dangerous areas. Through the linkage degradation of the actuator and chassis and explicit timing alignment, it is ensured that the operating mechanism is in a safe locking state when the work vehicle comes to a complete stop, preventing secondary accidents.

[0020] 2. Improved emergency response efficiency: By using a two-dimensional orthogonal arbitration of failure level L and emergency level F, the source of failure is decoupled from the controllability of the operating vehicle, enabling the adoption of the optimal response strategy based on the actual risk combination, thus avoiding response mismatch or delay.

[0021] 3. The method of this invention is not tied to a specific vehicle model. Through a configurable three-dimensional degradation decision matrix and operational semantic map, it can be adapted to different types of operational vehicles, reducing cross-vehicle adaptation costs. Furthermore, the solution covers a variety of scenarios, from controllable vehicle maneuvering to complete loss of control.

[0022] 4. Compared with existing solutions, by adopting the technology of this invention, the end-to-end delay from emergency triggering to the actuator completing the locking can be reduced from 2.5–4.0s to less than 500ms, the secondary accident rate caused by the actuator can be reduced from 18–25% to less than 2%, and the proportion of parking positions occupying the work lane can be reduced by more than 85%. Attached Figure Description

[0023] The present invention will be further described below with reference to the accompanying drawings and embodiments: Figure 1 This is a schematic diagram of the method flow of the present invention; Figure 2 This is a schematic diagram illustrating the specific process of an embodiment of the present invention; Figure 3 This is a system functional module architecture diagram according to an embodiment of the present invention; Figure 4 This is a schematic diagram of the semantic map of the operation according to an embodiment of the present invention; Figure 5 This is a schematic diagram of the hierarchical docking target point search process according to an embodiment of the present invention.

[0024] In the diagram: Information acquisition module 1; Dock decision module 2; Degradation decision module 3; Timing coordination module 4; Safety control channel 5; Operation semantic map module 6. Detailed Implementation

[0025] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. The described embodiments should not be regarded as limitations on this application. All other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0026] Unless otherwise defined, all technical and scientific terms used in the embodiments of this application have the same meaning as commonly understood by one of ordinary skill in the art. The terminology used in the embodiments of this application is for the purpose of describing the embodiments of this application only and is not intended to limit this application.

[0027] Before providing a further detailed description of the embodiments of this application, the nouns and terms involved in the embodiments of this application will be explained, and the nouns and terms involved in the embodiments of this application shall be interpreted as follows.

[0028] (1) Failure level L represents the level of the source and severity of failure of the autonomous driving operation vehicle. In this invention, it can be specifically divided into minor level L1, moderate level L2, severe level L3, and extreme level L4, each level corresponding to a different set of failure events. Specifically, L1 can correspond to door opening, slight abnormality of a single sensor, computing power utilization rate ≥90% and lasting ≤1s, etc.; L2 can correspond to main sensing channel failure, partial actuator failure, computing power utilization rate ≥95% and lasting ≤3s, etc.; L3 can correspond to main controller failure, severe failure of braking / steering actuators, etc.; L4 can correspond to simultaneous severe failure of braking and steering actuators, controller power supply failure, etc.

[0029] (2) The emergency level F represents the level of real-time controllability of the chassis and the urgency of stopping for the autonomous driving operation vehicle. In this invention, it can be specifically divided into controllable sidewalk F1, lane-keeping stop F2, emergency braking F3, and chassis loss of control F4. Specifically, F1 corresponds to a steering response time ≤200ms, a shoulder perception confidence level ≥0.8, and a braking deceleration ≤0.2g during deceleration; F2 corresponds to a steering response time ≤300ms, a shoulder perception confidence level between 0.6 and 0.8, and a braking deceleration ≤0.25g during deceleration; F3 corresponds to unreliable steering response and a braking deceleration ≤0.4g during deceleration; F4 corresponds to simultaneous failure of braking and steering, inability to generate a local stopping trajectory, and the need to initiate a remote takeover request to the remote platform.

[0030] (3) Operation semantic map refers to an electronic map designed specifically for autonomous driving operation vehicles, which adds operation-related semantic information layers to the traditional high-precision map. It includes at least five semantic layers: operation lane, shoulder parking strip, parking restricted area, loading / unloading / transfer area, and execution agency envelope area, providing operation scenario constraints for emergency parking decisions.

[0031] (4) Dual-dimensional orthogonal arbitration refers to a mechanism that decouples and independently evaluates the failure level determination and the real-time emergency level of the operating vehicle, and makes a comprehensive decision based on the combined state of the two. This mechanism can avoid the mismatch of response strategies caused by single-dimensional evaluation.

[0032] (5) Explicit timing alignment: This refers to a control method that ensures the remaining time t_stop of the emergency stop process of the work vehicle and the time t_deg of the linkage degradation process of the actuator meet specific timing constraints, such as t_stop ≥ t_deg. When the constraints are not met, a series of adjustment strategies are used to actively intervene to ensure that all actuator linkage mechanisms are in a safe state when the work vehicle comes to a complete stop.

[0033] Example 1 like Figure 1 and Figure 2 As shown in the figure, this application provides a method for emergency response and actuator linkage degradation of autonomous driving work vehicles. This application constructs a technical solution integrating specific semantic map decision-making, three-dimensional matrix degradation, and two-dimensional arbitration timing coordination, achieving safe, efficient, and intelligent emergency response for autonomous driving work vehicles under various failure scenarios.

[0034] The work vehicle is equipped with an emergency and actuator linkage degradation system for autonomous work vehicles. The system atomically latches the status of the work vehicle (failure level L) at the moment the emergency response is triggered, the real-time status of the work vehicle chassis (emergency level F), and the working status (S) of the work vehicle actuator, providing input for subsequent decision-making.

[0035] Specifically, the work vehicle is equipped with various sensors (such as cameras, lidar, GPS / IMU) and an onboard network (such as a CAN bus) to acquire and analyze key information such as the vehicle's failure level (L), emergency level (F), current operating status (S), and actuator type (A). When an emergency response (such as sudden braking, collision, or system failure) is triggered, the various sensors on the vehicle capture and save key vehicle status data through uninterrupted atomic operations, including vehicle speed, braking status, steering angle, sensor readings, GPS data, and system flags.

[0036] Emergency level F reflects whether the work vehicle can still reliably perform steering and braking. For example, when the work vehicle's steering response is sluggish, the emergency level is F2. Under this level, the work vehicle's braking deceleration is ≤0.2g, steering response time is ≤300ms, and shoulder perception confidence is <0.8. The work vehicle is only suitable for stopping within its own lane. When the braking system completely fails, the emergency level is F4. Under this level, the work vehicle's braking and steering fail simultaneously, and the vehicle cannot stop autonomously, requiring remote takeover.

[0037] After acquiring the status information of the work vehicle, the system enters the emergency docking decision-making phase. Emergency docking decisions are tiered based on the emergency level F: when F is F1 or F2, the system queries the operational semantic map in real time and searches for candidate docking points; when F is F3, the system skips semantic search and directly generates an emergency braking trajectory; when F is F4, the system skips local docking decisions and requests remote takeover. The system makes emergency docking decisions based on an operational semantic map customized for the work vehicle. Unlike general high-precision maps that only contain road geometry information, this operational semantic map contains information crucial to the operational scenario.

[0038] like Figure 4 As shown, the operational semantic map comprises five semantic layers: operational lane (A), road shoulder parking area (B), restricted parking area (C), loading / unloading / transfer area (D), and actuator envelope area (E). By utilizing these layers, the system avoids selecting parking points that obstruct operational routes, conflict with operational personnel, or cannot accommodate actuators. This improves the rationality and safety of parking locations, preventing secondary congestion and associated safety risks.

[0039] Subsequently, the system generates a coordinated degradation sequence for the actuators of the work vehicle in parallel. A preset three-dimensional degradation decision matrix M[L,S,A] is queried, using the acquired failure level L, work state S, and actuator type A as indices, to output an optimal degradation operation sequence for the current specific complex scenario. Furthermore, the generation of the coordinated degradation sequence also incorporates an emergency level F for pruning; for example, when F is F3, both power failure and locking are retained, while when F is F4, at least power failure and locking are executed.

[0040] For example, when the actuator of the work vehicle is a grab bucket, for scenarios such as "L2 level perception failure," "S2 operation in progress," and "A is a grab bucket," the matrix outputs a sequence of first "locking" and then "slowly releasing pressure." Specifically, the moving joints of the grab bucket are first locked mechanically or hydraulically, and then the remaining pressure in the hydraulic system is gradually released to prevent residual pressure from pushing the cylinder and causing the grab bucket to move suddenly due to rapid pressure release. By generating a linkage degradation sequence, precise operation of the actuator can be achieved, reducing safety risks.

[0041] After generating the emergency docking decision and the linkage degradation sequence, the system performs explicit timing alignment on both. Specifically, based on the two-dimensional orthogonal arbitration of the failure level L and the emergency level F, the system performs timing alignment on the remaining docking time t_stop generated by the emergency docking decision and the time t_deg consumed by the actuator degradation calculated by the linkage degradation sequence.

[0042] If the system calculates that the time t_deg required for actuator degradation is greater than the remaining time t_stop for the work vehicle to dock, the system will adjust the work vehicle's docking plan to extend t_stop until the timing constraints are met. This ensures that the timing of the work vehicle's docking and the actuator degradation process is synchronized, preventing the actuator from remaining in a dangerous moving state after the work vehicle has come to a complete stop, thus improving safety.

[0043] The dual-dimensional orthogonal arbitration mechanism separates the failure level (L) and emergency level (F) of the work vehicle, enabling the system to make a more reasonable response. Specifically, if the failure level is L2 and the emergency level is F1, it means the work vehicle is currently under control, and the system will control the vehicle to pull over. If the failure level is L2 and the emergency level is F4, it means the work vehicle is out of control, and the system will request remote takeover. Through the dual-dimensional orthogonal arbitration mechanism, the system will not ignore the controllable state of the work vehicle simply because the failure level (L) is low, thus avoiding safety risks.

[0044] Combination Figure 1 and Figure 2 As shown, the system synchronously executes vehicle docking and actuator degradation through an independent safety channel. During emergency docking decisions and linked degradation sequences, the system continuously monitors the state of the actuator's envelope area E. If the system detects that the actual physical envelope of the actuator (i.e., the vehicle's tools, such as an extended sweeping brush or robotic arm) exceeds the predetermined safety boundary due to changes in the vehicle's posture or uneven road surface (e.g., encroaching on adjacent lanes or touching roadside obstacles), a local priority degradation rollback sub-process is immediately triggered. This sub-process causes the vehicle to pause its current docking and issues a highest-priority command to retract the out-of-bounds actuator back into the safety envelope. After the actuator is retracted into the safety envelope, the system resumes control of the vehicle's docking. This avoids potential risks in complex dynamic environments and further improves safety.

[0045] In a preferred embodiment, to improve the efficiency and safety of emergency stopping decisions, the system employs an asymmetric roadside search mechanism. Specifically, in areas following right-hand traffic rules, the system prioritizes searching for available stopping areas on the right side of the vehicle's direction of travel, such as the shoulder stopping zone B. Only after a left-hand area is explicitly marked as "allowing temporary stopping" in the operational semantic map and undergoes safety verification (e.g., assessing the risk of oncoming or adjacent lane traffic flow) will that left-hand area be included in the candidate stopping point list. This avoids operational vehicles performing complex and high-risk continuous left-hand lane changes in emergency situations, reducing the probability of accidents and improving safety.

[0046] In a preferred embodiment, the system uses a cost function in the emergency docking decision. All candidate stops are scored. For example... Figure 5 As shown, the cost function It is a mathematical model for multi-objective optimization, and its calculation formula can be expressed as: ; in, This indicates the path length from the work vehicle to the parking point. Indicates the smoothness of the trajectory. This indicates the risk of the implementing agency colliding with the environment. This indicates the impact of stopping behavior on traffic flow. This indicates the confidence level that the stop is reachable.

[0047] Cost function The weights are dynamically adjusted according to a preset mapping relationship as the failure level L increases. For example, when the failure level changes from L1 to L3, the risk of collision with the actuator increases. Related weights , and reachability confidence Related weights This will significantly increase safety. This mechanism allows the system to prioritize safer stopping points, even if they are not the fastest to reach, when the failure level L of the operating vehicle is high, thus improving safety.

[0048] In a preferred embodiment, the linkage degradation sequence adopts a three-stage timing structure of power cut-off, locking, and pressure release. The three-stage timing structure defines a standard safe operating procedure for different types of actuators (electric, hydraulic, and pneumatic driven).

[0049] The first stage, "power cut-off," involves quickly disconnecting the power source from the actuator. The second stage, "locking," refers to fixing the actuator in its current position or a preset safe position using mechanical or hydraulic locking devices to prevent accidental movement due to gravity or inertia. The third stage, "pressure release," for hydraulic or pneumatic systems, safely releases residual pressure in the pipeline to prevent high-pressure liquid jetting during subsequent maintenance or rescue.

[0050] By setting strict time windows for the above three stages, the entire actuator degradation time can be determined, providing a reliable time base t_deg for explicit timing alignment and improving the reliability and security of emergency response. Optional three-stage mandatory timing windows are available: Electric mechanism: power failure ≤10ms, lock position ≤50ms, pressure release ≤150ms, total time ≤t_elec; Hydraulic mechanism: power cut-off ≤15ms, locking ≤100ms, pressure release ≤200ms, total time ≤t_hy; Pneumatic mechanism: power cut-off ≤ 10ms, lock-in ≤ 80ms, pressure release ≤ 180ms, total time ≤ t_air; In this embodiment, t_elec=210ms, t_hy=315ms, t_air=270ms, and the total degradation time for all mechanisms is t_deg≤500ms.

[0051] Preferably, the system dynamically trims the above three-stage timing structure according to the emergency level F. The specific method is as follows: When the emergency level is F1 or F2, the working vehicle has sufficient time and controllable braking capability, so it retains the complete three-stage sequence of power cut-off, locking and pressure release to ensure that the actuator is fully in a safe state during the docking process.

[0052] When the emergency level is F3, the braking time for the work vehicle is relatively tight. The system only executes two sequences: "power cut-off" and "lock-in," prioritizing the prevention of the actuator from continuing to move or falling. The "pressure release" is then executed only after the work vehicle has come to a complete stop. This ensures that the actuator will not cause a secondary accident during emergency braking and also avoids consuming valuable braking time by executing the "pressure release" action.

[0053] When the emergency level is F4, the system will at least enforce "power cut-off" and "lock-in". If the upper structure control channel is still available, the system will initiate a constrained "best effort upper structure safety" process in parallel. This process will perform limited retraction or locking actions on the actuator at a speed not exceeding 0.5 m / s and within the safety envelope, without blocking the initiation of remote takeover requests.

[0054] Through the aforementioned sequence pruning mechanism based on the F-level, the system can dynamically balance the integrity and timeliness of the downgrade operation under different levels of urgency, ensuring that safety is prioritized in the most critical moments while avoiding unnecessary delays, thus achieving deep adaptation between the downgrade strategy and the emergency level F of the work vehicle.

[0055] On the other hand, by adopting a three-stage sequence of power cut-off, locking, and pressure release, actuators of different types and manufacturers can be managed uniformly and reliably, improving the reliability and predictability of degradation operations and achieving accurate calculation of t_deg.

[0056] In a preferred embodiment, the system specifies the specific execution strategy for explicit timing alignment. For example... Figure 5 As shown, when the timing coordination module detects that the calculated mechanism degradation time t_deg is greater than the remaining docking time t_stop, that is, the end point of the work vehicle docking process in the initial state is earlier than the end point of the mechanism degradation process, the system will execute the adjustment strategy according to the following priority to extend the docking time of the work vehicle, so as to buy enough time for the safe shutdown of the actuator and improve safety.

[0057] The priority of the adjustment strategy is as follows: The stopping point is shifted downstream along the direction of the working vehicle's travel by a certain distance, thereby naturally extending the stopping trajectory and time; Insert one or more deceleration and holding sections into the planned stopping trajectory, that is, the working vehicle coasts at a very low speed or stays stationary for a short time to "wait" for the actuator to complete the degradation; Abandon the current best stop and switch to an alternative stop that is slightly lower in rating but is farther away or easier to reach; An emergency deceleration request is sent directly to the main controller or power system of the work vehicle to forcibly extend the stopping time t_stop by reducing the vehicle speed.

[0058] By implementing the adjustment strategy, the stopping time of the adjusted work vehicles is extended to ensure that t_stop > t_deg.

[0059] In a preferred embodiment, the system further refines the function of two-dimensional orthogonal arbitration. In addition to arbitration for timing alignment, it also executes different emergency response modes based on the urgency level F. Specifically, the system switches between the following three modes depending on the F value: When F is F1 or F2, it indicates that the chassis of the work vehicle has good controllability, and the "execute semantic docking" mode, which includes complete semantic search and fine-grained trajectory planning, is selected. When F is F3, it indicates that the steering ability of the work vehicle is unreliable but the braking is still effective. The system will abandon the search for complex stopping points and switch to the "execute emergency braking" mode to stop the work vehicle in the current lane as quickly as possible. When F is F4, indicating that the chassis of the work vehicle has completely lost control, the system will determine that local safety cannot be guaranteed and switch to the "request remote takeover" mode.

[0060] Based on the emergency level of the work vehicle, different emergency response modes are selected to ensure that the emergency strategy matches the actual status of the work vehicle.

[0061] Preferably, when the emergency level F is determined to be F4, the system will initiate two independent tasks in parallel. On the one hand, the system sends a remote takeover request to the remote monitoring center and establishes a communication and control link between the work vehicle and the remote driver as soon as possible. On the other hand, the system performs a preset, constrained best-effort safety operation on the actuator. This operation retracts or locks the actuator at a speed not exceeding 0.5 m / s and within the safety envelope, and converges to the minimum safe state when the operation times out or the risk increases.

[0062] Therefore, while awaiting remote assistance, the work vehicle itself will degrade its actuators by slowly retracting its robotic arm or closing valves. These two tasks are executed in parallel without blocking each other. This parallel processing ensures that requests for remote takeover are not delayed, while maximizing control of local risks while awaiting remote assistance.

[0063] Example 2 Please see Figure 3 This application embodiment also provides an emergency and actuator linkage degradation system for autonomous driving operation vehicles. This system is the physical carrier for implementing the above method, including an information acquisition module 1, a parking decision module 2, a degradation decision module 3, a timing coordination module 4, and a safety control channel 5.

[0064] The information acquisition module 1 acquires and parses key information such as the failure level L, emergency level F, current operating status S, and actuator type A of the operating vehicle from various sensors (such as cameras, lidar, GPS / IMU) and vehicle network (such as CAN bus) of the operating vehicle.

[0065] The stopping decision module 2, based on the information provided by the information acquisition module 1, queries the operation semantic map stored in the operation semantic module 6 in real time to make emergency stopping decisions, plan the stopping trajectory, and calculate the expected remaining stopping time t_stop. The operation semantic map stored in the operation semantic module 6 can be updated and upgraded.

[0066] The degradation decision module 3 receives information from the information acquisition module 1, and generates a linkage degradation sequence containing specific operation steps and time estimates for the actuator of the work vehicle by querying the three-dimensional degradation decision matrix M[L,S,A] stored in the system, and calculates the total time t_deg of the sequence.

[0067] The timing coordination module 4, based on L×F dual-dimensional arbitration logic, performs dual-dimensional orthogonal arbitration on the failure level L and the emergency level F. According to explicit timing alignment rules, it coordinates the remaining docking time t_stop generated by the docking decision module 2 and the mechanism degradation time t_deg generated by the degradation decision module. Finally, through the safety control channel 5, it sends control commands to the work vehicle to simultaneously control the docking of the work vehicle and the degradation of the actuator. The safety control channel 5 is independent of the main system, directly controlling the chassis and actuator of the work vehicle, possessing single-point fault tolerance, and is responsible for detecting actuator envelope out-of-bounds errors and triggering local priority degradation rollback.

[0068] Preferably, the timing coordination module 4 is also used to execute non-blocking parallel processing logic when the emergency level F is detected to be F4. The timing coordination module 4 simultaneously performs the following actions: immediately initiating a remote takeover request; and sending instructions to the controller of the actuator through the safety control channel to control it to perform preset safety operations. Therefore, it ensures that even in the most extreme circumstances, while issuing a remote distress signal, degraded control of the actuator is simultaneously implemented, further improving safety.

[0069] To illustrate the technical solution of the present invention more specifically, it will be described below in conjunction with specific application scenarios.

[0070] Scenario 1: A minor malfunction occurs in the park's autonomous sweeper truck late at night (L1+F1). An autonomous sweeper truck (model KT1E) is performing routine sweeping operations along the rightmost lane on a three-lane one-way road in the park. The actuators include sweeping brushes, a water pump, a telescopic mechanism, and a vacuum pump. The current operating status is S2 (operating), the vehicle speed is 12 km / h, and the actuator envelope extends outward by 0.6 m.

[0071] At a certain moment, the door of the work vehicle was unexpectedly opened. The information acquisition module captured the event and confirmed it as a valid failure after 25ms, classifying it as failure level L1. At the same time, the information acquisition module detected a steering response time of 150ms and a shoulder perception confidence level as high as 0.95, meeting the threshold for emergency level F1, and thus classifying the emergency level as F1.

[0072] The parking decision module receives inputs from L1 and F1 levels, determines that the current working vehicle still possesses full roadside parking capability, and should perform a semantic parking maneuver. Therefore, it reads data from the operational semantic map. Referring to Table 1, based on the F1 level, the system activates an asymmetric roadside search mechanism: prioritizing the search for suitable roadside parking areas on the right side of the driving direction, and by default not moving to the left. The search results show that there is a suitable roadside parking area on the right shoulder with ID SH1048 18m downstream of the current rightmost working lane, which the system identifies as the preferred parking point.

[0073] Table 1

[0074] To avoid performing high-risk left lane changes in emergency situations, the system no longer searches for candidate points on the left. Subsequently, based on the cost function... Rate this stop. Refer to Table 2. , , , as well as Weights are assigned according to L1 level. Set the weight to 1.2. Set to 0.8, the final calculation yields This stop point was selected as the optimal stop point. Lightweight MPC generates a smooth stopping trajectory with a lateral deviation of only 7cm, a maximum longitudinal deceleration of 0.28g, and an estimated remaining stopping time of t_stop=9.0s.

[0075] Table 2

[0076] Meanwhile, the degradation decision module receives inputs from L1, S2, and the actuator set A = {sweeping brush, water pump, telescopic mechanism, sewage pump}, and queries the three-dimensional degradation decision matrix M[L1,S2,A_i]. Referring to Table 3, the matrix outputs a three-stage sequence of "power off, lock, and pressure release" for the actuators: sweeping brush total time 235ms, water pump 190ms, telescopic mechanism 200ms, sewage pump 250ms. Taking the maximum value, the total degradation time of the mechanism is t_deg = 250ms.

[0077] Table 3

[0078] Subsequently, the timing coordination module compared t_stop=9.0s with t_deg=250ms and found that t_deg was much smaller than t_stop, satisfying the timing constraints and requiring no adjustment. The safety control channel simultaneously issued stopping trajectory and degradation sequence instructions. Ultimately, the work vehicle completed locking of all actuators within 250ms after triggering and stopped on the right shoulder after 9.0s, with the actuator envelope remaining within its bounds throughout the entire process. Within 1 second of the work vehicle coming to a complete stop, hazard lights, emergency broadcasts, and alarm notifications were automatically triggered, completing a safe and efficient emergency response.

[0079] Scenario 2: The same sweeper truck experiences a perception failure in the early morning (L2+F2) The same autonomous sweeper truck was operating on the same one-way three-lane park road in the early morning, with a small number of other vehicles operating in the other two lanes. The actuator remained unchanged, the operating status was still S2 (operating), the vehicle speed was 10km / h, and the actuator envelope was expanded by 0.55m.

[0080] At a certain moment, the lidar in the main sensing channel of the work vehicle became contaminated, causing the shoulder boundary confidence level to drop to 0.55. The information acquisition module confirmed the failure after 50ms, and the system rated it as a failure level L2. The information acquisition module also learned that the steering response time had increased to 220ms, and the shoulder sensing confidence level had fallen below 0.6. Therefore, the emergency level was rated as F2, requiring the vehicle to stop in this lane.

[0081] Referring to Table 4, the current emergency level is F2. The working vehicle no longer meets the conditions for safely pulling over; therefore, it must not initiate a search for stopping on the shoulder, nor change lanes to the left or pull over to the left. The stopping decision module skips the search of the shoulder stopping strip and the left-hand candidate area, locking onto a suitable deceleration stopping strip within 15 to 60 meters downstream of the current rightmost lane. The search finds a comfortable stopping strip with ID DL308. The cost function... Because L2 level will weight collision risk Increased to 1.5, reachability confidence weight Upgraded to 1.0, final rating The system plans a stopping trajectory within this lane, with a maximum longitudinal deceleration of 0.18g and an estimated remaining stopping time of t_stop=5.6s. It does not encroach on the left lane.

[0082] Table 4

[0083] Referring to Table 5, the degradation decision module queries the M[L2,S2,A_i] matrix. The total time for the sweeping brush is 247ms, the water pump is 199ms, the telescopic mechanism is 210ms, and the sewage pump is 257ms. Taking the maximum value, we get t_deg=257ms.

[0084] The timing coordination module comparison revealed that t_deg=257ms is less than t_stop=5.6s, satisfying the timing constraints. The safety control channel synchronously issued the parking trajectory and degradation command. Ultimately, the work vehicle completed the locking of all actuators within 257ms and stopped at the designated parking strip within the current lane after 5.6s. Throughout the process, it did not straddle lane markings, did not collide with other work vehicles, and the actuator envelope did not exceed the boundary. The system reported an alarm. Because the work vehicle did not attempt to change lanes to the left or move to the side, a lateral collision was avoided under conditions of low perception confidence, ensuring safety.

[0085] Table 5

[0086] The application scenarios of this invention are not limited to the aforementioned sweeping and washing vehicles; it is also applicable to automated grab trucks, automated guided vehicles, and automated combine harvesters. Its operational semantic map includes dedicated layers for container yards, quay crane operation areas, charging areas, field boundaries, harvested areas, and unloading points. By replacing the operational semantic map and the three-dimensional degradation decision matrix M[L,S,A], the core framework of this invention can be quickly and cost-effectively adapted to various types of automated driving vehicles.

[0087] The above embodiments are merely preferred technical solutions of the present invention and should not be considered as limitations on the present invention. The scope of protection of the present invention should be limited to the technical solutions described in the claims, including equivalent substitutions of the technical features described in the claims. That is, equivalent substitutions and improvements within this scope are also within the scope of protection of the present invention.

Claims

1. A method for emergency response and actuator linkage degradation of an automated driving operation vehicle, characterized in that, Includes the following steps: S1. Obtain the failure level L, emergency level F, current operation status S, and actuator type A of the work vehicle; S2. Based on the emergency level F and the semantic map of operations including the semantic layers of the work lane, shoulder parking strip, parking restricted area, loading / unloading / transfer area and actuator envelope area, make emergency parking decisions; S3. Based on the three-dimensional degradation decision matrix M[L,S,A] related to the failure level L, the operation state S, and the actuator type A, and combined with the emergency level F, a linkage degradation sequence is generated for the actuators of the operation vehicle. S4. Based on the two-dimensional orthogonal arbitration of failure level L and emergency level F, perform explicit timing alignment on the remaining docking time t_stop generated by the emergency docking decision and the mechanism degradation time t_deg of the linkage degradation sequence. S5. Through a security control channel independent of the main system, docking and degradation commands are executed synchronously. When an out-of-bounds boundary is detected in the envelope area of ​​the actuator, a local priority degradation rollback is triggered to prioritize the recovery of the out-of-bounds actuator.

2. The method according to claim 1, characterized in that, The emergency stopping decision adopts an asymmetric roadside search mechanism. Under the traffic rule of driving on the right, the area to the right of the direction of travel of the operation vehicle is searched by default.

3. The method according to claim 2, characterized in that, Emergency docking decisions also include: Candidate docking points are scored using a cost function J, and the weight of the cost function J increases with the failure level L according to a preset mapping relationship.

4. The method according to claim 1, characterized in that, The linkage degradation sequence adopts a three-stage timing structure of power deactivation, locking, and pressure release.

5. The method according to claim 4, characterized in that, The generation of the linkage degradation sequence includes tailoring the three-stage timing structure according to the emergency level F: when the emergency level F indicates emergency braking, at least the power cut-off and locking stages are retained, and the pressure release is delayed until the vehicle comes to a complete stop; when the emergency level F indicates chassis loss of control, at least the power cut-off and locking stages are forcibly executed, and remote takeover is requested.

6. The method according to claim 5, characterized in that, The three-stage timing structure sets a maximum time window for each type of actuator. The total time for electric actuators does not exceed t_elec, the total time for hydraulic actuators does not exceed t_hy, the total time for pneumatic actuators does not exceed t_air, and the total degradation time t_deg for all actuators does not exceed the set threshold.

7. The method according to claim 1, characterized in that, Explicit timing alignment includes: When t_deg is detected to be greater than t_stop, the adjustment strategy is executed according to the following priority: Move the docking target point downstream; Insert a deceleration and holding section into the stopping trajectory; Switch to an alternative stop location; Send an emergency deceleration request to the main controller of the work vehicle.

8. The method according to claim 1, characterized in that, Two-dimensional orthogonal arbitration also includes: Depending on the emergency level F, you can choose from three modes: semantic docking, emergency braking, or requesting remote takeover.

9. The method according to claim 8, characterized in that, When the emergency level F indicates chassis loss of control, perform the following actions: Initiate remote takeover requests in parallel and control the actuators of the work vehicles to perform preset safety operations.

10. An emergency response and actuator linkage degradation system for an autonomous driving operation vehicle, characterized in that, include: The information acquisition module is used to acquire the failure level L, emergency level F, current operation status S, and actuator type A of the work vehicle; The Operation Semantic Map module is used to store and update the operation semantic map, which includes semantic layers of operation lanes, shoulder parking strips, parking restricted areas, loading / unloading / transfer areas and actuator envelope areas, and provides a real-time query interface; The docking decision module is used to make emergency docking decisions based on the emergency level F and the operational semantic map, and to generate the remaining docking time t_stop; The degradation decision module is used to generate a linkage degradation sequence for the actuators of the work vehicle based on the three-dimensional degradation decision matrix M[L,S,A] related to the failure level L, the work state S, and the actuator type A. The timing coordination module is used for two-dimensional orthogonal arbitration based on failure level L and emergency level F, and according to explicit timing alignment rules, it coordinates the remaining docking time t_stop generated by the docking decision module and the mechanism degradation time t_deg of the linkage degradation sequence. The safety control channel is used to receive instructions from the timing coordination module, synchronously control the chassis to perform docking actions and the actuators to perform degradation actions, and trigger local priority degradation backoff when the actuator envelope area is detected to be out of bounds; the safety control channel is independent of the main system of the work vehicle.