Vehicle control method and device, vehicle, chip and storage medium

CN122808780APending Publication Date: 2026-09-25XIAOMI EV TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611141054.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-29
Publication Date
2026-09-25

AI Technical Summary

Technical Problem

相关技术中,车辆的智能驾驶系统采用单一控制器完成轨迹跟踪与稳定性控制,然而在高速、大曲率或低附着路面等极限工况下,此类系统难以兼顾通行效率与行驶安全

Benefits of technology

[0384]综上,本公开提供的技术方案,至少包括以下有益效果:1. 通过在NMPC中引入非线性轮胎模型、载荷转移、坡度、横坡、纵向力分配、轮胎附着和电机功率约束,提高高动态场景下控制命令的可实现性。2. 通过将前轴纵向力比例作为优化变量,在满足前后轴附着、电机功率和最大驱动力约束的前提下动态分配总纵向力,提高前/后轴能力利用率,并降低单轴饱和风险。3. 通过前轴纵向力比例的变化率约束和比例平顺性代价,避免前后轴扭矩分配突变,提高驱制动执行平顺性。4. 通过历史控制命令预测执行器延迟后的状态,并基于预测位姿重新采样参考轨迹,降低控制延迟引起的跟踪滞后和振荡。5. 通过根据车辆速度、规划轨迹中的动作标识和路径里程切换预测步长、权重和约束,使主控制器可适应常规、高性能和特殊路段场景。6. 通过方向盘偏置、横向速度偏置和横向误差模型偏置估计,增强实车部署中的鲁棒性。7. 通过MRA控制器将纵向速度按期望减速度预先滚动,并仅优化横向状态和转向命令,在风险接管场景下降低计算复杂度。8. 通过MRA的边界代价、侧偏代价和-相平面稳定区域代价,使车辆在减速接管过程中兼顾道路边界和横向稳定性。9. 通过异常计数、健康状态、上一帧控制命令序列的保留和多控制器仲裁,避免瞬时异常导致控制命令频繁切换,并提高系统兜底能力。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122808780A_ABST
    Figure CN122808780A_ABST
Patent Text Reader

Abstract

The disclosure provides a vehicle control method and device, a vehicle, a chip and a storage medium, and relates to the technical field of vehicles. The method comprises the following steps: acquiring a first control command sequence output by a master controller of a vehicle according to a planned trajectory, current state information, historical control commands and vehicle parameters; acquiring a second control command sequence output by a slave controller of the vehicle according to vehicle speed and yaw rate in the current state information; performing command arbitration on the first control command sequence, the second control command sequence and a third control command sequence to obtain a target control command sequence; wherein the safety risk degree of the vehicle driving according to the third control command sequence is lower than a preset risk threshold; and performing driving control on the vehicle according to the target control command sequence. Therefore, the operation safety, robustness and fault tolerance of the vehicle in complex or critical working conditions can be significantly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of vehicles, and more particularly to a vehicle control method, apparatus, vehicle, chip, and storage medium. Background Technology

[0002] With the continuous development of intelligent driving technology, vehicle control systems are becoming increasingly complex, typically involving multiple functional modules working together. In related technologies, intelligent driving systems for vehicles use a single controller to complete trajectory tracking and stability control. However, under extreme conditions such as high speeds, high curvature, or low-adhesion road surfaces, such systems struggle to balance traffic efficiency and driving safety. Summary of the Invention

[0003] This disclosure proposes a vehicle control method, apparatus, vehicle, chip, and storage medium to at least partially solve one of the technical problems in the related art.

[0004] One embodiment of this disclosure proposes a vehicle control method, comprising: acquiring a first control command sequence output by the vehicle's main controller based on a planned trajectory, current state information, historical control commands, and vehicle parameters; acquiring a second control command sequence output by the vehicle's slave controller based on the vehicle speed and yaw rate in the current state information; arbitrating the first, second, and third control command sequences to obtain a target control command sequence; wherein the safety risk level of the vehicle driving according to the third control command sequence is lower than a preset risk threshold; and performing driving control on the vehicle according to the target control command sequence.

[0005] In summary, the main controller generates a first control command sequence oriented towards task performance based on high-dimensional planned trajectory, current state information, historical control commands, and vehicle parameters, ensuring efficient and accurate trajectory tracking. A second control command sequence, oriented towards vehicle stability and safety performance, is generated from the controller based on the vehicle's current speed and yaw rate, creating heterogeneous safety redundancy for the main controller. By introducing a third control command sequence containing a fallback safety strategy and arbitrating the three, the intelligent driving system can adopt the high-performance first control command sequence output by the main controller, and seamlessly switch to the safe and stable second control command sequence output by the controller when instability risks, critical scenarios, or extreme scenarios occur, or revert to the low-risk third control command sequence. Finally, the vehicle is controlled based on the arbitration result, significantly improving the vehicle's operational safety, robustness, and fault tolerance under complex or critical conditions.

[0006] As one possible implementation, the command arbitration of the first control command sequence, the second control command sequence, and the third control command sequence includes: obtaining a threshold parameter corresponding to the path mileage of the vehicle's current driving position; wherein the threshold parameter is associated with at least one anomaly type, and the threshold parameter includes at least one of the following: lateral error threshold, heading error threshold, communication timeout threshold, and boundary margin threshold; performing anomaly detection on the vehicle's current state information based on the threshold parameter to determine the risk control state of the vehicle; and performing command arbitration on the first control command sequence, the second control command sequence, and the third control command sequence based on the risk control state and the health status of the master controller and the slave controller.

[0007] Therefore, by introducing a threshold parameter dynamically associated with the path mileage of the vehicle's current driving position, and based on this threshold parameter, anomaly detection and counting are performed on multiple dimensions such as lateral error, heading deviation, communication latency, and road boundary margin. This allows for an objective determination of whether the vehicle has entered the minimum risk control state based on the accumulated number of anomalies, thereby avoiding frequent switching of control strategies due to single instantaneous interference. Furthermore, by combining the real-time health status of the master and slave controllers, command arbitration is implemented on the first, second, and third control command sequences. This not only significantly improves the system's robustness to instantaneous anomalies and effectively suppresses control command jitter and oscillation, but also enhances the fault tolerance and safety degradation capabilities of the intelligent driving system through a closed-loop evaluation method of "anomaly counting - risk rating - health assessment - multi-source arbitration," ensuring that the vehicle always maintains a controllable and predictable low-risk operating state in various complex or critical scenarios.

[0008] As one possible implementation, the step of arbitrating the first control command sequence, the second control command sequence, and the third control command sequence based on the risk control status and the health status of the master controller and the slave controller includes: performing a validity check on the first control command sequence and the second control command sequence to obtain a validity check result; performing an availability check on the first control command sequence and the second control command sequence based on the health status of the master controller and the slave controller to obtain an availability check result; and arbitrating the first control command sequence, the second control command sequence, and the third control command sequence based on the risk control status, the validity check result, and the availability check result.

[0009] In summary, the above-mentioned command arbitration method comprehensively considers four dimensions: risk control status, health status of master / slave controllers, and command validity and availability. It not only achieves functional complementarity and safety redundancy between master and slave controllers, but also ensures that the optimal or safest control command sequence can be selected under various abnormal combinations (such as master controller failure but slave controller normal operation, or both master and slave controllers failure). This significantly improves the fault tolerance and operational continuity of the intelligent driving system.

[0010] As one possible implementation, the command arbitration of the first control command sequence, the second control command sequence, and the third control command sequence based on the risk control state, the validity check result, and the availability check result includes any one of the following: In response to the risk control state being a non-minimum risk control state, and the validity check result indicating that the first control command sequence is valid, and the availability check result indicating that the first control command sequence is available, then the first control command sequence is taken as the target control command sequence; In response to the risk control state being a non-minimum risk control state, and the validity check result indicating that the first control command sequence is invalid while the second control command sequence is valid, and the availability check result indicating that the second control command sequence is available, then the second control command sequence is taken as the target control command sequence; In response to the risk control state being a non-minimum risk control state, and the validity check result indicating that the second control command sequence is valid, and the availability check result indicating that the first control command sequence is unavailable while the second control command sequence is available, then the second control command sequence is taken as the target control command sequence. The system generates a third control command sequence. If the risk control state is at its minimum risk control state, and the validity check result indicates that the second control command is valid, and the availability check result indicates that the second control command sequence is available, then the second control command sequence is designated as the target control command sequence. If the risk control state is not at its minimum risk control state, and the validity check result indicates that both the first and second control command sequences are invalid, then the third control command sequence is designated as the target control command sequence. If the risk control state is not at its minimum risk control state, and the availability check result indicates that both the first and second control command sequences are unavailable, then the third control command sequence is designated as the target control command sequence. If the risk control state is at its minimum risk control state, and the validity check result indicates that the second control command sequence is invalid, then the third control command sequence is designated as the target control command sequence. If the risk control state is at its minimum risk control state, and the availability check result indicates that the second control command sequence is unavailable, then the third control command sequence is designated as the target control command sequence.

[0011] In summary, by setting multiple arbitration implementation paths, the intelligent driving system can prioritize traffic efficiency under non-minimum risk control conditions (using the first control command sequence output by the main controller), forcibly switch to a stability-priority control strategy under minimum risk control conditions (using the second control command sequence output by the controller or the third control command sequence as a fallback control scheme), and automatically activate the third control command sequence in the preset safety degradation mode in extreme scenarios (such as when both the main and slave controllers are abnormal). This forms a three-level control system of "high efficiency - robustness - safety net", which not only meets the performance requirements of daily driving, but also ensures that the vehicle is always in a controllable and predictable low-risk state under sudden abnormalities, thereby improving the safety of vehicle driving.

[0012] As one possible implementation, the main controller outputs the first control command sequence in the following manner: predicting the vehicle's predicted state information at the time the control command takes effect based on the historical control commands and the current state information; projecting the predicted state information onto the path coordinate system corresponding to the planned trajectory to determine the target trajectory point closest to the predicted state information from each trajectory point of the planned trajectory; resampling the planned trajectory starting from the target trajectory point to obtain a reference trajectory; and generating and outputting the first control command sequence based on the first optimization objective associated with the main controller, according to the reference trajectory, the predicted state information, the vehicle parameters, and the historical control commands.

[0013] In summary, by predicting the vehicle's state information at the moment the control command takes effect based on historical control commands and current state information, and projecting this predicted state information onto the path coordinate system of the planned trajectory to determine the nearest target trajectory point, and then resampling the original planned trajectory to generate a reference trajectory, the problem of "misalignment between the initial optimization value (or initial state) and the actual vehicle state" caused by actuator communication, calculation, and response delays can be effectively solved. Furthermore, the reference trajectory, starting with the predicted state information for local reconstruction, ensures that the trajectory context relied upon by the subsequent optimization process is highly aligned with the actual state the vehicle is about to reach. This significantly improves the foresight of trajectory tracking and the feasibility of control commands, especially in scenarios such as high-speed cornering, slopes, or changes in adhesion, avoiding the accumulation of lateral errors or steering command oscillations caused by trajectory-state mismatch.

[0014] As one possible implementation, generating the first control command sequence based on the reference trajectory, the predicted state information, the vehicle parameters, and the historical control commands includes: determining a first objective cost function corresponding to the first optimization objective based on the reference trajectory, the predicted state information, the vehicle parameters, and the historical control commands; wherein the first objective cost function uses a first state variable and a first control variable as decision variables; the first state variable is associated with the first control variable through an equality constraint defined by a nonlinear dynamic model, the nonlinear dynamic model being used to indicate the nonlinear mapping relationship between the coupled response of longitudinal and lateral forces and the vehicle motion state; under the constraints of the executable domain indicated by the objective constraint information associated with the vehicle, calculating the first control variable that can satisfy the first optimization objective indicated by the first objective cost function in the future prediction time domain, and obtaining the predicted value of the first control variable; generating the first control command sequence based on the predicted value of the first control variable.

[0015] Therefore, by constructing a first objective cost function with a nonlinear dynamic model as an equality constraint, and solving for the optimal first control variable within the feasible region defined by the vehicle's execution capability constraint, the strong coupling nonlinear relationship between longitudinal and lateral forces can be explicitly characterized. This allows for simultaneous consideration of trajectory tracking accuracy, vehicle stability, and execution feasibility during the optimization process. Compared to related technologies based on linearized models or decoupled control, this disclosure can intelligently generate physically feasible and energy-efficient control commands under extreme conditions such as cornering acceleration, emergency obstacle avoidance, or low-adhesion road surfaces. This effectively suppresses problems such as excessive sideslip angle, torque distribution imbalance, or unreachable longitudinal forces, significantly improving control robustness and safety in high-dynamic scenarios.

[0016] As one possible implementation, the step of calculating a first control variable that satisfies the first optimization objective indicated by the first target cost function within the future prediction time domain, under the constraints of the executable domain indicated by the target constraint information associated with the vehicle, and obtaining the predicted value of the first control variable, includes: determining the vehicle's driving condition information based on at least one of the planned trajectory, the path mileage of the vehicle's current driving position, and the configuration mode; determining a target driving mode from multiple driving modes based on the driving condition information; adjusting the weights of each cost function in the first target cost function and the executable boundaries of each constraint indicated by the executable domain based on the target driving mode; and calculating the first control variable that satisfies the first optimization objective indicated by the adjusted first target cost function within the future prediction time domain, under the constraints of the adjusted executable domain, and obtaining the predicted value of the first control variable.

[0017] In summary, by dynamically selecting the target driving mode based on the vehicle's current driving conditions and adjusting the weights of each cost function in the first objective cost function and the executable boundaries of each constraint in the executable domain accordingly, scenario-adaptive optimization of the control strategy can be achieved. That is, under different driving scenarios, the main controller can automatically focus on the most critical performance indicators and match the corresponding physical feasible range, thereby avoiding the "one-sided" problem caused by using fixed weights and static constraints. For example, when driving condition information indicates that the vehicle is about to enter a construction zone, narrow curve, or parking area, the main controller can switch to a "special path mode" to actively tighten the tolerance boundaries of lateral error, heading error, and vehicle sideslip angle, and shorten the prediction step size to improve path tracking accuracy and local obstacle avoidance safety. Furthermore, in low-speed scenarios (such as urban congestion), the weights of terminal error and heading error can be increased to ensure accurate stopping and lane centering. In high-speed scenarios (such as highway lane changes), the weight of lateral error can be appropriately reduced, the weights of lateral convergence speed and stability-related terms can be increased, and the rate of change constraints of some actuators can be relaxed to balance responsiveness and ride comfort. This significantly improves the adaptability, control robustness, and user experience consistency of the intelligent driving system in diverse road environments.

[0018] As one possible implementation, the predicted value satisfying the first optimization objective indicated by the first objective cost function further includes the predicted values ​​of each first state variable in the future prediction time domain; generating the first control command sequence based on the predicted values ​​of the first control variables includes: estimating the state bias of the nonlinear dynamics model based on the reference trajectory, the vehicle parameters, and the historical control commands; compensating and correcting the predicted values ​​of the first state variables using the state bias; compensating and correcting the predicted values ​​of the first control variables based on the corrected predicted values ​​of the first state variables; and generating the first control command sequence based on the compensated and corrected predicted values ​​of the first control variables.

[0019] Therefore, by estimating the state bias of the nonlinear dynamics model based on the reference trajectory, vehicle parameters, and historical control commands, and compensating and correcting the predicted value of the first state variable accordingly, and then iteratively optimizing and adjusting the predicted value of the first control variable based on this, a compensated and corrected first control command sequence is finally generated. This can achieve closed-loop compensation for the systematic deviation between the actual vehicle motion behavior and the model prediction, making the generated first control command sequence closer to the actual physical characteristics of the vehicle. It avoids control lag, tracking deviation accumulation, or stability degradation caused by model mismatch, and effectively improves vehicle control performance, especially in complex scenarios such as long time-domain prediction, low-adhesion road surfaces, or frequent lane changes.

[0020] As one possible implementation, generating the first control command sequence based on the compensated and corrected predicted value of the first control variable includes: generating a predicted trajectory for the current control cycle based on the corrected predicted value of the first state variable; determining the trajectory offset between the predicted trajectory and the reference trajectory; and generating the first control command sequence for the current control cycle based on the compensated and corrected predicted value of the first control variable in response to the trajectory offset being less than an offset threshold.

[0021] Therefore, by constructing the predicted trajectory of the current control cycle based on the predicted value of the corrected first state variable before the main controller generates the first control command sequence, and calculating the trajectory offset between it and the reference trajectory, the predicted value of the compensated and corrected first control variable is adopted as the effective output only when the trajectory offset is less than a preset offset threshold. This enables closed-loop verification of the feasibility of control commands, effectively preventing the issuance and execution of control commands that are "nominally optimal but actually deviate too much" due to factors such as model residual errors, external disturbances, or unstable optimization values. Especially in interference scenarios such as high curvature curves, sudden attachment changes, or strong crosswinds, even if the optimization solution is successful, the predicted trajectory may still deviate significantly from the expected reference trajectory due to the lack of dynamic modeling. In this case, the secondary verification of the trajectory offset can promptly intercept unreliable control commands, thereby significantly improving the safety and trajectory consistency of the control system.

[0022] As one possible implementation, the method further includes at least one of the following: in response to the absence of a predicted value that satisfies the first optimization objective, and the number of consecutive abnormal outputs by the main controller not exceeding a threshold, outputting a first control command sequence of the previous control cycle and setting the health status of the main controller to a warning; in response to the absence of a predicted value that satisfies the first optimization objective, and the number of consecutive abnormal outputs exceeding the threshold, setting the health status of the main controller to an error; wherein the health status of the main controller is used as input for the command arbitration.

[0023] Therefore, when the main controller cannot find a feasible solution that satisfies the first optimization objective, a hierarchical health status management mechanism based on the number of consecutive failures is introduced. When the number of consecutive abnormal outputs of the main controller does not exceed the limit, the valid control command sequence of the previous control cycle is maintained, and its health status is set to "warning". When the number of consecutive abnormal outputs of the main controller exceeds the limit, the health status of the main controller is set to "error". This enables dynamic evaluation and gradual degradation of the operational reliability of the main controller. On the one hand, brief output abnormalities will not immediately lead to control interruption, but will maintain stable vehicle operation and avoid control jumps by maintaining the previous valid control command sequence. On the other hand, persistent output abnormalities are identified as potential functional abnormalities, triggering an error state and serving as a key input for subsequent command arbitration. This prompts the system to switch to a slave controller or fallback control safety strategy in a timely manner. This not only enhances the fault tolerance of the main controller itself, but also provides accurate health status basis for master-slave collaborative arbitration, effectively supporting the smooth transition and safety redundancy of the entire control system under abnormal operating conditions.

[0024] As one possible implementation, the first state variable includes at least one of the following: lateral error, heading error, vehicle speed, vehicle sideslip angle, yaw rate, steering wheel angle, and steering wheel angular velocity; wherein the vehicle sideslip angle includes the front wheel sideslip angle and the rear wheel sideslip angle; and / or, the first control variable includes the target steering wheel angle, torque distribution amount, and total longitudinal force; wherein the torque distribution amount includes any one of the following: the front axle longitudinal force to be distributed to the front axle in the total longitudinal force, the rear axle longitudinal force to be distributed to the rear axle in the total longitudinal force, the proportion of the front axle longitudinal force, and the proportion of the rear axle longitudinal force.

[0025] Therefore, by specifying the first state variable as key kinematic and dynamic quantities including lateral error, heading error, vehicle speed, front / rear wheel slip angle, yaw rate, steering wheel angle and its rate of change, and defining the first control variable as executable physical quantities such as the target steering wheel angle, total longitudinal force and the distribution of front / rear axle longitudinal forces, it is possible to achieve refined modeling and precise control of the vehicle's longitudinal and lateral coupled motion. Introducing the front / rear wheel slip angle as a state variable allows the main controller to directly sense and constrain whether the tire's working point is close to the adhesion limit, while designing the torque distribution as a proportional or axle-part force facilitates seamless integration with four-wheel drive or distributed drive chassis actuators. This targeted selection of state and control variables not only enhances the physical interpretability of the optimization problem but also ensures that the generated first control command sequence has high-precision tracking capability and strong environmental adaptability on actual vehicles, making it particularly suitable for scenarios with stringent requirements for tire utilization efficiency and dynamic balance, such as track driving, slippery surfaces, or high-curvature curves.

[0026] As one possible implementation, the first objective cost function is determined based on at least one of the following cost functions: a state tracking cost function, determined based on the lateral error, heading error, and speed error in the first state variables, and the front axle longitudinal force proportional tracking error determined based on the torque distribution amount in the first control variables; a comfort cost function, determined based on the rate of change between two consecutively determined first control variables; a tire slip cost function, determined based on the front wheel slip angle and rear wheel slip angle in the first state variables; a road boundary intrusion cost function, determined based on the lateral error and error boundary value in the first state variables; and a super slip cost function, determined based on the vehicle slip angle determined by the first state variables and the vehicle parameters... The extreme sideslip angle is determined by the tire model; the lateral convergence speed cost function is determined based on the lateral error and expected lateral convergence speed in the first state variable; the reference steering and reference longitudinal force cost function is determined based on the deviation between the reference steering and reference longitudinal force at each trajectory point in the reference trajectory and the first control variable; the preview time cost function is determined based on the deviation between the predicted driving time and the target preview time under the target driving mode; wherein, the predicted driving time is the time required for the vehicle to travel the path distance corresponding to the future predicted time domain, determined based on the first state variable and the first control variable; the target preview time is the expected driving time for the vehicle to travel the path distance under the target driving mode.

[0027] In summary, the state tracking cost function ensures the vehicle accurately follows the reference trajectory in terms of lateral position, heading, and speed; the comfort cost function suppresses high-frequency jitter in control commands, improving passenger experience; the tire slip / over-slip cost function explicitly constrains the front and rear wheel operating points away from the adhesion limit, preventing vehicle instability; the road boundary intrusion cost function actively avoids the risk of exceeding road boundaries; the lateral convergence speed cost function accelerates error decay, improving cornering responsiveness; and the reference steering and reference longitudinal force cost functions ensure the control output aligns with the planning intent. Figure 1 The anticipation time cost function enables the vehicle to adaptively adjust its driving rhythm under different driving modes, achieving on-demand time control. The fusion design of the above multi-dimensional cost functions allows the main controller to meet high-precision tracking requirements while also ensuring safety, comfort, and consistency in driving style under complex operating conditions, significantly outperforming traditional optimization methods that only focus on a single performance indicator.

[0028] As one possible implementation, the target constraint information includes at least one of the following constraints: initial state constraints, used to instruct the first target cost function to determine each first control variable based on the predicted state information; equality constraints defined by the nonlinear dynamic model; rate of change constraint of the target steering wheel angle; rate of change constraint of longitudinal force; rate of change constraint of the proportion of front axle longitudinal force; constraint that both the front axle longitudinal force and the rear axle longitudinal force do not exceed the tire adhesion capacity; constraint that the product of the total longitudinal force and the vehicle speed does not exceed the total vehicle motor power; constraint that the product of the front axle longitudinal force and the vehicle speed does not exceed the front axle motor power; constraint that the product of the rear axle longitudinal force and the vehicle speed does not exceed the rear axle motor power; constraint that the front axle driving force does not exceed the maximum front axle driving force; constraint that the rear axle driving force does not exceed the maximum rear axle driving force.

[0029] Therefore, by introducing multiple physical constraints covering initial state, nonlinear dynamics, actuator rate of change, tire adhesion, and motor power limitations into the optimization problem, it can be ensured that the first control command sequence generated by the main controller is not only mathematically optimal but also fully executable in a real vehicle: the initial state constraint ensures that optimization starts from predicted state information, avoiding state jumps; the equation constraint of the nonlinear dynamics model accurately characterizes the longitudinal and lateral coupled motion; the rate of change constraints of steering wheel angle, longitudinal force, and torque distribution ratio effectively suppress actuator saturation and mechanical shock; the adhesion constraint based on the tire model prevents the front and rear axle driving braking forces from exceeding the friction circle boundary; and the power constraints of the whole vehicle and axle motors ensure that the control commands do not exceed the upper limit of the electric drive system's capabilities in high-speed or steep gradient scenarios. These constraints together constitute a compact and realistic "executable domain," avoiding problems such as command unreachability, tire slippage, or power interruption caused by ignoring the physical limits of actuators in related technologies, greatly improving the control reliability and system robustness in high-dynamic driving scenarios.

[0030] As one possible implementation, the slave controller outputs the second control command sequence in the following manner: in response to the vehicle meeting a set abnormal triggering condition, it determines the desired deceleration of the vehicle based on the vehicle speed and the yaw rate; it determines the speed sequence and path mileage sequence in the future prediction time domain based on the vehicle speed, the desired deceleration, and the prediction step time; and it generates and outputs the second control command sequence based on the speed sequence, the path mileage sequence, the road boundary information of the vehicle's travel path, and the planned trajectory, according to a second optimization objective associated with the slave controller.

[0031] Therefore, when the vehicle meets the set abnormal triggering conditions, the slave controller dynamically calculates the expected deceleration based on the vehicle speed and yaw rate, and generates the speed sequence and path mileage sequence in the future prediction time domain based on the forward extrapolation. Then, combined with the road boundary information and planned trajectory of the vehicle's driving road, a second control command sequence is generated. This enables the construction of a lightweight and highly reliable control benchmark with safe deceleration, path maintenance and boundary avoidance as the core objectives in abnormal or emergency scenarios. It significantly improves the system's real-time response speed, control continuity and autonomous backup capability in emergency conditions, and effectively suppresses the risk of overstepping, skidding or loss of control caused by control deficiency or inaccurate commands.

[0032] As one possible implementation, the step of generating and outputting the second control command sequence based on the second optimization objective associated with the slave controller, according to the speed sequence, the path mileage sequence, the road boundary information of the vehicle's travel path, and the planned trajectory, includes: determining a second objective cost function corresponding to the second optimization objective based on the speed sequence, the path mileage sequence, the road boundary information, and the planned trajectory; wherein the second objective cost function uses a second state variable and a second control variable as decision variables; the second state variable is associated with the second control variable through a lateral dynamics model; the lateral dynamics model is used to indicate the nonlinear mapping relationship between the tire lateral force response and the vehicle yaw motion state; under the constraints of the lateral dynamics model, calculating the second control variable that can satisfy the second optimization objective indicated by the second objective cost function in the future prediction time domain, and obtaining the predicted value of the second control variable; generating and outputting the second control command sequence for the current control cycle based on the predicted value of the second control variable.

[0033] Therefore, by constructing a second objective cost function constrained by a lateral dynamics model, and coupling the second state variable and the second control variable through a nonlinear mapping relationship between tire lateral force and yaw motion, the controller can achieve fine-grained control of vehicle lateral stability under limited information conditions. Compared with methods based on linear bicycle models or open-loop braking strategies in related technologies, this nonlinear optimization framework can more realistically reflect the tire's response characteristics in the extreme adhesion region. In scenarios such as cornering deceleration, obstacle avoidance, or low-adhesion road surfaces, it generates control commands that take into account road boundary constraints, trajectory feasibility, and yaw stability, thereby maximizing vehicle controllability while ensuring safety.

[0034] As one possible implementation, the step of generating and outputting the second control command sequence based on the second optimization objective associated with the slave controller, according to the speed sequence, the path mileage sequence, the road boundary information of the vehicle's travel route, and the planned trajectory, further includes: in response to the absence of a predicted value that satisfies the second optimization objective, and the number of consecutive abnormal outputs by the slave controller not exceeding a threshold, outputting the second control command sequence of the previous control cycle.

[0035] Therefore, when the controller fails to find a feasible solution that satisfies the second optimization objective, if the number of consecutive abnormal outputs from the controller does not exceed a set threshold, the valid second control command sequence from the previous control cycle is used. This effectively suppresses the interruption or jump of control commands caused by the failure of instantaneous numerical solution, ensuring the continuity and smoothness of the controller output. It also avoids unnecessary vehicle dynamic disturbances caused by brief calculation abnormalities in emergency situations, thus enhancing the robustness and reliability of the safety redundancy system.

[0036] As one possible implementation, the second objective cost function is determined based on at least one of the following cost functions: a lateral error and heading error tracking cost function, determined based on the lateral error and heading error in the second state variables; a boundary cost function, determined based on the lateral error and error boundary; a front and rear wheel sideslip cost function, determined based on the front wheel sideslip angle and rear wheel sideslip angle in the second state variables; a phase plane stability region cost function, determined based on the deviations between the yaw rate, front wheel sideslip angle, and rear wheel sideslip angle in the second state variables and the phase plane stability region; and a steering balance cost function. The compliance cost function is determined based on the steering wheel angle and steering wheel angular velocity in the second control variables, as well as the steering wheel command changes between adjacent sampling points in the future prediction time domain and the steering wheel command changes between the current control cycle and the previous control cycle; wherein, the method for determining the phase plane stable region includes any one of the following: determining the phase plane stable region based on the vehicle's maximum lateral acceleration and rear wheel limit sideslip angle; determining the phase plane stable region based on the vehicle's sideslip angle and yaw rate; determining the phase plane stable region based on the vehicle's lateral acceleration and yaw rate.

[0037] In summary, by constructing the second objective cost function as a weighted combination of multiple dimensions, including lateral error / heading error tracking, road boundary constraints, front and rear wheel slip angle limits, phase plane stability region deviation, and steering smoothness, the slave controller can still generate safe control commands that take into account trajectory keeping, vehicle dynamic stability, and execution comfort, even when relying only on limited state information such as vehicle speed and yaw rate. Among these features, the lateral and heading error tracking cost functions ensure the vehicle stays as close as possible to the planned trajectory; the boundary cost function actively suppresses the risk of the vehicle approaching or exceeding the road boundary; the front and rear wheel yaw cost functions explicitly constrain the tire operating point away from the adhesion limit, preventing instability caused by excessive yaw; the introduction of a phase plane stability region cost function based on yaw rate, front / rear wheel yaw angle, or lateral acceleration allows the slave controller to directly assess whether the vehicle state is in the theoretical phase plane stability region and actively drive the system back to the stability region during optimization, thereby effectively preventing nonlinear instability phenomena such as fishtailing and oversteering in high-risk scenarios such as cornering deceleration and emergency obstacle avoidance; and the steering smoothness cost function, through joint penalties on steering wheel angle, speed, and their temporal rate of change, significantly suppresses high-frequency jitter and step jumps in control commands, improving ride comfort and reducing actuator wear. Thus, the slave controller not only possesses strong robust safety fallback capabilities but also maintains high control quality under abnormal operating conditions.

[0038] As one possible implementation, the second state variable includes at least one of the following: lateral error, heading error, vehicle sideslip angle, yaw rate, steering wheel angle, and steering wheel angular velocity; wherein the vehicle sideslip angle includes the front wheel sideslip angle and the rear wheel sideslip angle; and / or, the second control variable includes the target steering wheel angle.

[0039] Therefore, by optimizing the controller's variables, including lateral error, heading error, sideslip angle, yaw rate, steering wheel angle, steering wheel angular velocity, and target steering wheel angle, instead of simultaneously optimizing longitudinal forces (such as total longitudinal force, front axle longitudinal force, rear axle longitudinal force, front axle longitudinal force ratio, and rear axle longitudinal force ratio), the optimization scale can be reduced and the real-time performance of risk takeover can be improved.

[0040] As one possible implementation, generating a second control command sequence for the current control cycle based on the predicted value of the second control variable includes: determining the total longitudinal force of the vehicle based on the expected deceleration and the vehicle model in the vehicle parameters; and generating the second control command sequence for the current control cycle based on the predicted value of the second control variable and the total longitudinal force.

[0041] Therefore, by limiting the second control variable to include only the target steering wheel angle, and no longer jointly optimizing longitudinal control variables such as total longitudinal force and torque distribution between the front and rear axles, the controller significantly reduces the dimensionality of decision variables and the complexity of the solution problem. Based on this, the required total longitudinal force is directly calculated analytically using the determined desired deceleration and the vehicle model. This analytical result is then fused with the optimized predicted value of the target steering wheel angle to generate the second control command sequence for the current control cycle. This achieves a decoupled and collaborative mechanism between high-precision optimization of lateral control and rapid analysis of longitudinal control. On the one hand, it retains the ability to optimize the steering wheel angle, ensuring active control of path tracking and yaw stability even in emergency scenarios. On the other hand, it avoids time-consuming iterative solutions to nonlinear longitudinal distribution problems during time-critical risk takeover processes, significantly shortening the generation delay of control commands and improving the real-time response of the system. This satisfies both safe deceleration requirements and maintains necessary lateral guidance capabilities, effectively balancing computational efficiency, control performance, and functional safety, providing a highly reliable, low-latency, and safe redundant execution path for intelligent driving systems.

[0042] As one possible implementation, the abnormal triggering conditions include at least one of the following: the main controller outputs an abnormality; the distance between the vehicle and the road boundary is less than a set distance; the vehicle communication is abnormal; the vehicle is in a minimum risk control state; the tracking error of the vehicle on the planned trajectory exceeds a set error threshold.

[0043] Therefore, by explicitly defining abnormal triggering conditions as including risk situations such as abnormal output of the main controller, vehicle approaching the road boundary, communication abnormality, being in a minimum risk control state, or exceeding the trajectory tracking error limit, it can be ensured that the slave controller can be activated in a timely manner in critical scenarios where safety intervention is most needed. These abnormal triggering conditions cover potential abnormal modes in multiple dimensions such as perception, planning, control, communication, and vehicle-environment interaction, making the activation of the slave controller highly situation-aware and proactive, significantly improving the timing rationality of the slave controller's response, thereby ensuring both safety and system operating efficiency.

[0044] As one possible implementation, determining the desired deceleration of the vehicle based on the vehicle speed and the yaw rate includes any one of the following: determining the desired deceleration of the vehicle based on the vehicle speed, the yaw rate, and configuration parameters; wherein the configuration parameters are used to indicate the maximum lateral acceleration and maximum longitudinal acceleration associated with the wheels; determining the road curvature of the road on which the vehicle is currently traveling and the boundary distance between the vehicle and the road boundary, and determining the desired deceleration of the vehicle based on multiple of the vehicle speed, yaw rate, lateral error, road curvature, and boundary distance; wherein the lateral error is determined based on the current state information and the planned trajectory.

[0045] Therefore, different methods can be used to calculate the vehicle's expected deceleration, which can improve the flexibility and applicability of this method.

[0046] As one possible implementation, the generation of the third control command sequence includes: in response to the vehicle meeting a set second abnormal triggering condition, determining the desired total braking torque of the vehicle based on the vehicle speed, the yaw rate, and the vehicle mass; determining the vehicle motor torque and the hydraulic braking torque of the braking control system based on the total braking torque; determining the target steering wheel angle based on the angular error between the yaw rate and the desired yaw rate; and generating the third control command sequence based on the target steering wheel angle, the vehicle motor torque, and the hydraulic braking torque.

[0047] Therefore, when the vehicle meets the set second abnormal triggering condition, the desired total braking torque of the vehicle is determined based on the vehicle speed, yaw rate, and vehicle mass. The total braking torque is then broken down into the vehicle motor torque and hydraulic braking torque. The target steering angle is obtained based on the yaw rate error, and finally, a third control command sequence is generated. This enables coordinated control of vehicle power and steering under emergency abnormal conditions, ensuring sufficient deceleration capability while reserving adjustment space for yaw stability control in advance. This avoids saturation or insufficient response of a single control source, ensuring the feasibility of vehicle control under abnormal conditions.

[0048] As one possible implementation, generating the third control command sequence based on the target steering wheel angle, the vehicle motor torque, and the hydraulic braking torque includes: obtaining a set front axle longitudinal force ratio; wherein the front axle longitudinal force ratio is the ratio of the front axle longitudinal force to the total longitudinal force of the vehicle; distributing the vehicle motor torque according to the front axle longitudinal force ratio to obtain the front axle motor torque distributed to the front axle of the vehicle and the rear axle motor torque distributed to the rear axle of the vehicle; and generating the third control command sequence based on the target steering wheel angle, the front axle motor torque, the rear axle motor torque, and the hydraulic braking torque.

[0049] Therefore, by introducing a strategy of proportionally distributing the longitudinal force of the front axle to the torque of the front / rear axle motors, the axle load matching distribution of braking torque can be achieved. Combined with the target steering angle to generate a third control command sequence, the braking force distribution can be adapted to the current lateral motion state of the vehicle, making full use of the friction adhesion limits of each axle, avoiding the vehicle from sideslipping and becoming unstable due to a single axle reaching its friction limit first. At the same time, the steering adjustment and braking distribution can work together to better stabilize the yaw rate during forced braking with large deceleration, and enhance the lateral stability of the braking process.

[0050] As one possible implementation, determining the desired total braking torque of the vehicle based on the vehicle speed, the yaw rate, and the vehicle mass includes: determining the actual lateral acceleration of the vehicle based on the vehicle speed and the yaw rate; determining the desired longitudinal deceleration of the vehicle based on the lateral acceleration, the maximum permissible lateral acceleration of the vehicle, and the maximum longitudinal acceleration; and determining the desired total braking torque of the vehicle based on the longitudinal deceleration, the vehicle mass, and the vehicle speed.

[0051] Therefore, based on the vehicle's speed and yaw rate, the actual lateral acceleration of the vehicle is derived. Then, combined with the maximum permissible lateral / longitudinal acceleration, the desired longitudinal deceleration is obtained. Finally, based on this longitudinal deceleration, vehicle mass, and speed, the total braking torque is calculated. This allows for dynamic matching of the total braking force under friction limit constraints. It ensures sufficient deceleration to meet emergency braking requirements without causing sideslip and loss of control due to the total braking torque exceeding the tire adhesion limit. The total braking torque requirement is always generated in accordance with the vehicle's current stability boundary, satisfying the vehicle control objective of ensuring braking stability within the friction limit.

[0052] As one possible implementation, determining the target steering wheel angle based on the angular error between the yaw rate and the desired yaw rate includes: determining an open-loop transfer function from the steering wheel angle to the yaw rate; wherein the open-loop transfer function indicates the transfer relationship between the steering wheel angle and the yaw rate; determining an adjustment controller and corresponding adjustment parameters based on the open-loop transfer function; wherein the adjustment controller establishes a mapping relationship between the angular error between the yaw rate and the desired yaw rate and the target steering wheel angle; and determining the target steering wheel angle based on the angular error between the vehicle's actual yaw rate and the desired yaw rate, as well as the adjustment controller and the adjustment parameters.

[0053] In summary, a control controller was designed based on the open-loop transfer function from steering wheel angle to yaw rate. Then, a strategy was developed to solve for the target steering wheel angle through the yaw rate error. This established a precise mapping relationship for closed-loop stabilization of yaw rate. The steering angle can be corrected in real time for the angular deviation between the actual yaw rate and the desired yaw rate. Compared with open-loop adjustment with fixed parameters, the response is more accurate and the anti-disturbance capability is stronger. It can effectively suppress yaw disturbances caused by load transfer and changes in road surface adhesion during forced deceleration, and prevent the vehicle from skidding and losing control.

[0054] As one possible implementation, the second abnormal triggering condition includes at least one of the following: the main controller outputs an abnormality; the slave controller outputs an abnormality; the vehicle's planning module malfunctions; wherein the planning module is used to output the planned trajectory; and the vehicle is in a minimum risk control state.

[0055] Therefore, by explicitly defining the second abnormal triggering condition as including risk situations such as abnormal output of the main controller, abnormal output of the slave controller, the vehicle being in a minimum risk control state, and abnormal planning module, it can be ensured that the fallback controller can be activated in a timely manner under abnormal conditions that require the most safety intervention, providing lateral stability protection and emergency deceleration and stopping capability for the vehicle, and significantly improving the robustness of the vehicle control system and driving safety.

[0056] Another embodiment of this disclosure proposes a vehicle control device, comprising: a first acquisition module, configured to acquire a first control command sequence output by the vehicle's main controller based on a planned trajectory, current state information, historical control commands, and vehicle parameters; a second acquisition module, configured to acquire a second control command sequence output by the vehicle's slave controller based on the vehicle speed and yaw rate in the current state information; an arbitration module, configured to arbitrate the first control command sequence, the second control command sequence, and the third control command sequence to obtain a target control command sequence; wherein the safety risk level of the vehicle driving according to the third control command sequence is lower than a preset risk threshold; and a control module, configured to perform driving control on the vehicle according to the target control command sequence.

[0057] In summary, by generating a first control command sequence based on high-dimensional planned trajectory, current state information, historical control commands, and vehicle parameters, the main controller ensures efficient and accurate trajectory tracking. A second control command sequence, based on vehicle speed and yaw rate, is generated to enhance vehicle stability and safety, creating heterogeneous safety redundancy for the main controller. Introducing a third control command sequence with a fallback safety strategy and arbitrating the three sequences allows the intelligent driving system to adopt the high-performance first control command sequence from the main controller while seamlessly switching to the safe and stable second control command sequence or reverting to the low-risk third control command sequence in the event of instability risks, critical scenarios, or extreme situations. Finally, vehicle control is implemented based on the arbitration result, significantly improving the vehicle's operational safety, robustness, and fault tolerance under complex or critical conditions.

[0058] As one possible implementation, the arbitration module is configured to: obtain a threshold parameter corresponding to the path mileage of the vehicle's current driving position; wherein the threshold parameter is associated with at least one anomaly type, and the threshold parameter includes at least one of the following: lateral error threshold, heading error threshold, communication timeout threshold, and boundary margin threshold; perform anomaly detection on the vehicle's current state information based on the threshold parameter to determine the risk control state of the vehicle; and arbitrate commands for the first control command sequence, the second control command sequence, and the third control command sequence based on the risk control state, the health status of the master controller, and the slave controller.

[0059] Therefore, by introducing a threshold parameter dynamically associated with the path mileage of the vehicle's current driving position, and based on this threshold parameter, anomaly detection and counting are performed on multiple dimensions such as lateral error, heading deviation, communication latency, and road boundary margin. This allows for an objective determination of whether the vehicle has entered the minimum risk control state based on the accumulated number of anomalies, thereby avoiding frequent switching of control strategies due to single instantaneous interference. Furthermore, by combining the real-time health status of the master and slave controllers, command arbitration is implemented on the first, second, and third control command sequences. This not only significantly improves the robustness of the intelligent driving system to instantaneous anomalies and effectively suppresses the jitter and oscillation of control commands, but also greatly enhances the fault tolerance and safety degradation capabilities of the intelligent driving system through the closed-loop logic of "anomaly counting - risk rating - health assessment - multi-source arbitration," ensuring that the vehicle always maintains a controllable and predictable low-risk operating state in various complex or critical scenarios.

[0060] As one possible implementation, the arbitration module is configured to: perform validity checks on the first control command sequence and the second control command sequence to obtain validity check results; perform availability checks on the first control command sequence and the second control command sequence based on the health status of the master controller and the slave controller to obtain availability check results; and arbitrate commands on the first control command sequence, the second control command sequence, and the third control command sequence according to the risk control status, the validity check results, and the availability check results.

[0061] Therefore, the above-mentioned command arbitration method comprehensively considers four dimensions: risk control status, health status of master / slave controllers, and command validity and availability. It not only achieves functional complementarity and safety redundancy between master and slave controllers, but also ensures that the optimal or safest control command sequence can be selected under various abnormal combinations (such as master controller failure but slave controller normal operation, or both master and slave controllers failure). This significantly improves the fault tolerance and operational continuity of the intelligent driving system.

[0062] As one possible implementation, the first acquisition module is configured to: predict the predicted state information of the vehicle at the effective time of the control command based on the historical control commands and the current state information; project the predicted state information onto the path coordinate system corresponding to the planned trajectory to determine the target trajectory point closest to the predicted state information from each trajectory point of the planned trajectory; resample the planned trajectory starting from the target trajectory point to obtain a reference trajectory; and generate and output the first control command sequence based on the first optimization objective associated with the main controller, according to the reference trajectory, the predicted state information, the vehicle parameters, and the historical control commands.

[0063] Therefore, by predicting the vehicle's state information at the moment the control command takes effect based on historical control commands and current state information, and projecting this predicted state information onto the path coordinate system of the planned trajectory to determine the nearest target trajectory point, and then resampling the original planned trajectory to generate a reference trajectory, the problem of "misalignment between the initial optimization value (or initial state) and the actual vehicle state" caused by actuator communication, calculation, and response delays can be effectively solved. Among them, the reference trajectory is partially reconstructed starting from the predicted state information, which can ensure that the trajectory context on which the subsequent optimization process depends is highly aligned with the actual state that the vehicle is about to reach. This significantly improves the foresight of trajectory tracking and the feasibility of control commands, especially in dynamic scenarios such as high-speed cornering, slopes, or changes in adhesion, avoiding the accumulation of lateral errors or oscillations in steering commands caused by trajectory-state mismatch.

[0064] As one possible implementation, the first acquisition module is configured to: determine a first objective cost function corresponding to the first optimization objective based on the reference trajectory, the predicted state information, the vehicle parameters, and the historical control commands; wherein the first objective cost function uses a first state variable and a first control variable as decision variables; the first state variable is associated with the first control variable through an equality constraint defined by a nonlinear dynamic model, the nonlinear dynamic model being used to indicate the nonlinear mapping relationship between the coupled response of longitudinal and lateral forces and the vehicle motion state; under the constraints of the executable domain indicated by the objective constraint information associated with the vehicle, calculate the first control variable that can satisfy the first optimization objective indicated by the first objective cost function in the future prediction time domain, and obtain the predicted value of the first control variable; and generate the first control command sequence based on the predicted value of the first control variable.

[0065] Therefore, by constructing a first objective cost function with a nonlinear dynamic model as an equality constraint, and solving for the optimal first control variable within the feasible region defined by the vehicle's execution capability constraint, the strong coupling nonlinear relationship between longitudinal and lateral forces can be explicitly characterized. This allows for simultaneous consideration of trajectory tracking accuracy, vehicle stability, and execution feasibility during the optimization process. Compared to related technologies based on linearized models or decoupled control, this disclosure can intelligently generate physically feasible and energy-efficient control commands under extreme conditions such as cornering acceleration, emergency obstacle avoidance, or low-adhesion road surfaces. This effectively suppresses problems such as excessive sideslip angle, torque distribution imbalance, or unreachable longitudinal forces, significantly improving control robustness and safety in high-dynamic scenarios.

[0066] As one possible implementation, the second acquisition module is configured to: in response to the vehicle meeting a set first abnormal triggering condition, determine the expected deceleration of the vehicle based on the vehicle speed and the yaw rate; determine the speed sequence and path mileage sequence in the future prediction time domain based on the vehicle speed, the expected deceleration, and the prediction step time; and generate and output the second control command sequence based on a second optimization objective associated with the slave controller, according to the speed sequence, the path mileage sequence, the road boundary information of the vehicle's travel path, and the planned trajectory.

[0067] Therefore, when the vehicle meets the set abnormal triggering conditions, the slave controller dynamically calculates the expected deceleration based on the vehicle speed and yaw rate, and generates the speed sequence and path mileage sequence in the future prediction time domain based on the forward extrapolation. Then, combined with the road boundary information and planned trajectory of the vehicle's driving road, a second control command sequence is generated. This enables the construction of a lightweight and highly reliable control benchmark with safe deceleration, path maintenance and boundary avoidance as the core objectives in abnormal or emergency scenarios. It significantly improves the system's real-time response speed, control continuity and autonomous backup capability in emergency conditions, and effectively suppresses the risk of overstepping, skidding or loss of control caused by control deficiency or inaccurate commands.

[0068] As one possible implementation, the second acquisition module is configured to: determine a second objective cost function corresponding to the second optimization objective based on the speed sequence, the path mileage sequence, the road boundary information, and the planned trajectory; wherein the second objective cost function uses a second state variable and a second control variable as decision variables; the second state variable is associated with the second control variable through a lateral dynamics model; the lateral dynamics model is used to indicate the nonlinear mapping relationship between the tire lateral force response and the vehicle yaw motion state; under the constraints of the lateral dynamics model, calculate the second control variable that can satisfy the second optimization objective indicated by the second objective cost function in the future prediction time domain, and obtain the predicted value of the second control variable; generate a second control command sequence for the current control cycle based on the predicted value of the second control variable, and output it.

[0069] Therefore, by constructing a second objective cost function constrained by a lateral dynamics model, and coupling the second state variable and the second control variable through a nonlinear mapping relationship between tire lateral force and yaw motion, the controller can achieve fine-grained control of vehicle lateral stability under limited information conditions. Compared with related technologies based on linear bicycle models or open-loop braking strategies, this nonlinear optimization framework can more realistically reflect the tire's response characteristics in the extreme adhesion region. In scenarios such as cornering deceleration, obstacle avoidance, or low-adhesion road surfaces, it generates control commands that take into account road boundary constraints, trajectory feasibility, and yaw stability, thereby maximizing vehicle controllability while ensuring safety.

[0070] As one possible implementation, the third control command sequence is obtained through a third acquisition module, wherein the third acquisition module is configured to: in response to the vehicle meeting a set second abnormal triggering condition, determine the desired total braking torque of the vehicle based on the vehicle speed, the yaw rate, and the vehicle mass; determine the vehicle motor torque and the hydraulic braking torque of the braking control system based on the total braking torque; determine the target steering wheel angle based on the angular error between the yaw rate and the desired yaw rate; and generate the third control command sequence based on the target steering wheel angle, the vehicle motor torque, and the hydraulic braking torque.

[0071] Therefore, when the vehicle meets the set second abnormal triggering condition, the desired total braking torque of the vehicle is determined based on the vehicle speed, yaw rate, and vehicle mass. The total braking torque is then broken down into the vehicle motor torque and hydraulic braking torque. The target steering angle is obtained based on the yaw rate error, and finally, a third control command sequence is generated. This enables coordinated control of vehicle power and steering under emergency abnormal conditions, ensuring sufficient deceleration capability while reserving adjustment space for yaw stability control in advance. This avoids saturation or insufficient response of a single control source, ensuring the feasibility of vehicle control under abnormal conditions.

[0072] As one possible implementation, the third acquisition module is configured to: determine the open-loop transfer function from the steering wheel angle to the yaw rate; wherein the open-loop transfer function indicates the transfer relationship between the steering wheel angle and the yaw rate; determine an adjustment controller and corresponding adjustment parameters based on the open-loop transfer function; wherein the adjustment controller is configured to establish a mapping relationship between the angle error between the yaw rate and the desired yaw rate and the target steering wheel angle; and determine the target steering wheel angle based on the angle error between the actual yaw rate and the desired yaw rate of the vehicle, as well as the adjustment controller and the adjustment parameters.

[0073] Therefore, an adjustment controller is designed based on the open-loop transfer function from steering wheel angle to yaw rate. Then, a strategy of solving the target steering wheel angle through yaw rate error is established to establish a precise mapping relationship for closed-loop stabilization of yaw rate. This can correct the steering angle in real time based on the angle deviation between the actual yaw rate and the desired yaw rate of the vehicle. Compared with open-loop adjustment with fixed parameters, it has a more accurate response and stronger anti-disturbance capability. It can effectively suppress yaw disturbances caused by load transfer and changes in road surface adhesion during forced deceleration, and avoid vehicle sideslip and loss of control.

[0074] Another aspect of this disclosure provides a vehicle, including: a processor; a memory for storing processor-executable instructions; wherein the processor is configured to implement the vehicle control method as described in the preceding aspect.

[0075] In another aspect of this disclosure, a chip is provided that includes an interface circuit and a processing circuit coupled to each other, the interface circuit being used to input or output signals, and the processing circuit being configured to perform the vehicle control method as described in the preceding aspect.

[0076] In another aspect, this disclosure provides a non-transitory computer-readable storage medium having stored computer program instructions thereon, which, when executed by a processor, implement the vehicle control method as described in the foregoing aspect.

[0077] Another aspect of this disclosure provides a computer program product having a computer program stored thereon, which, when executed by a processor, implements the vehicle control method as described in the foregoing aspect.

[0078] Additional aspects and advantages of this disclosure will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of this disclosure. Attached Figure Description

[0079] The above and / or additional aspects and advantages of this disclosure will become apparent and readily understood from the following description of the embodiments taken in conjunction with the accompanying drawings, in which: Figure 1 A schematic flowchart of a vehicle control method provided for an exemplary embodiment of the present disclosure; Figure 2 A schematic flowchart of another vehicle control method provided for an exemplary embodiment of this disclosure; Figure 3 A schematic flowchart of yet another vehicle control method provided for an exemplary embodiment of this disclosure; Figure 4 A schematic flowchart of another vehicle control method provided for an exemplary embodiment of the present disclosure; Figure 5A schematic flowchart of another vehicle control method provided for an exemplary embodiment of this disclosure; Figure 6 A schematic flowchart of another vehicle control method provided for an exemplary embodiment of this disclosure; Figure 7 A schematic flowchart of yet another vehicle control method provided for an exemplary embodiment of this disclosure; Figure 8 A schematic flowchart of another vehicle control method provided for an exemplary embodiment of this disclosure; Figure 9 A schematic flowchart of another vehicle control method provided for an exemplary embodiment of the present disclosure; Figure 10 A schematic flowchart of yet another vehicle control method provided for an exemplary embodiment of this disclosure; Figure 11 A schematic flowchart of another vehicle control method provided for an exemplary embodiment of this disclosure; Figure 12 A schematic diagram of the structure of a vehicle control device provided for an exemplary embodiment of the present disclosure; Figure 13 A block diagram illustrating a vehicle according to an exemplary embodiment; Figure 14 This is a schematic diagram of the structure of a chip proposed as an exemplary embodiment of the present disclosure. Detailed Implementation

[0080] Embodiments of this disclosure are described in detail below, examples of which are illustrated in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and intended to explain this disclosure, and should not be construed as limiting this disclosure.

[0081] It should be noted that the acquisition, storage, use, and processing of data in this disclosed technical solution comply with the provisions of relevant laws and regulations and do not violate public order and good morals.

[0082] It should also be noted that all data processed in this disclosure is data that has been explicitly authorized by the user or relevant party, and has been de-identified or anonymized before collection and use, and does not contain any personally identifiable information or user privacy content; all data is used only for vehicle control purposes, ensuring that data security and user privacy rights are fully protected while achieving technical effects.

[0083] In view of at least one of the problems existing in the above-mentioned related technologies, this disclosure proposes a vehicle control method, device, vehicle, chip and storage medium.

[0084] The vehicle control method, apparatus, vehicle, chip, and storage medium of this disclosure are described below with reference to the accompanying drawings.

[0085] Figure 1 A schematic flowchart of a vehicle control method provided for an exemplary embodiment of this disclosure.

[0086] It should be noted that the vehicle control method of this disclosure can be applied to a vehicle control device. In some possible embodiments, the vehicle control device can be configured in a vehicle to enable the vehicle to perform vehicle control functions. Additionally, in some possible embodiments, the vehicle control device can also be software within the vehicle.

[0087] The vehicle can be a hybrid vehicle, a non-hybrid vehicle, an electric vehicle, a fuel cell vehicle, or other types of vehicles; the vehicle can be a driver-assisted vehicle, a semi-driver-assisted vehicle, or a non-driver-assisted vehicle. Driver-assisted driving refers to technologies that use sensors, algorithms, and artificial intelligence to perceive the vehicle's environment, make decisions, plan strategies, and execute control commands to assist drivers in driving more safely and efficiently.

[0088] like Figure 1 As shown, the vehicle control method may include the following steps S101 to S104: Step S101: Obtain the first control command sequence output by the vehicle's main controller based on the planned trajectory, current status information, historical control commands, and vehicle parameters.

[0089] The planned trajectory can be a sequence of desired travel paths output by the vehicle's planning module, containing multiple trajectory points. Each trajectory point has corresponding path mileage, location, road topology information, and dynamic reference information, including but not limited to: heading, longitudinal velocity, lateral velocity, curvature, yaw rate, tire angle, longitudinal acceleration, road boundary, gradient, and cross slope. The path mileage indicates the cumulative distance from the trajectory point along the planned path to the starting point of the journey.

[0090] The current status information includes, but is not limited to: measurement status (such as inertial measurement unit (IMU) data, wheel speed, etc.), positioning status, chassis status (such as suspension height, braking pressure, etc.). For example, the current status information includes, but is not limited to: lateral error, heading error, vehicle speed, vehicle sideslip angle (including front wheel sideslip angle and rear wheel sideslip angle), yaw rate, steering wheel angle, steering wheel angular velocity, etc.

[0091] Among them, the historical control commands include, but are not limited to: historical steering commands, historical total longitudinal force commands, historical front axle torque ratio commands (or historical front axle longitudinal force ratio commands), etc., where the front axle torque ratio refers to the ratio of the front axle drive torque to the total drive torque, and the front axle longitudinal force ratio is the ratio of the front axle longitudinal force to the total longitudinal force of the vehicle.

[0092] The vehicle parameters include, but are not limited to, physical characteristics such as wheelbase, center of gravity position, vehicle mass (i.e., vehicle weight), moment of inertia, tire model parameters, steering ratio, steering actuator dynamic parameters, vehicle width, maximum power, and tire adhesion parameters. For example, vehicle parameters can be determined based on vehicle type.

[0093] The first control command sequence includes multiple control quantities, including but not limited to: the target steering wheel angle. Torque distribution, total longitudinal force F L The torque distribution includes any one of the following: the front axle longitudinal force to be distributed to the front axle out of the total longitudinal force; the rear axle longitudinal force to be distributed to the rear axle out of the total longitudinal force; and the proportion of the front axle longitudinal force. 2. Rear axle longitudinal force ratio. The front axle longitudinal force ratio is the ratio of the front axle longitudinal force to the total longitudinal force of the vehicle; the rear axle longitudinal force ratio is the ratio of the rear axle longitudinal force to the total longitudinal force of the vehicle.

[0094] As one possible implementation, the vehicle's main controller can generate a first control command sequence based on its preset first optimization objective, by combining the planned trajectory, current status information, historical control commands, and vehicle parameters.

[0095] Step S102: Obtain the second control command sequence output by the vehicle's slave controller based on the vehicle speed and yaw rate in the current status information.

[0096] The second control command sequence includes multiple control quantities, including but not limited to: the target steering wheel angle. And total longitudinal force.

[0097] As one possible implementation, the vehicle's slave controller can generate a second control command sequence based on its preset second optimization objective, combining the vehicle's current speed and yaw rate. Optionally, the slave controller can generate the second control command sequence based on the second optimization objective, combining vehicle speed, yaw rate, road boundary information of the vehicle's travel path, and planned trajectory.

[0098] The second optimization objective adopted by the slave controller differs from the first optimization objective adopted by the master controller. The first optimization objective focuses on global task performance (such as efficient traffic flow), while the latter focuses on local dynamic safety (such as preventing skidding, loss of control, and preventing vehicles from crossing road boundaries). For example, the master controller's first optimization objective might be: maximizing traffic efficiency while meeting safety constraints; the slave controller's second optimization objective might be: achieving safe deceleration or braking while maintaining vehicle dynamic stability. It should be noted that the examples of optimization objectives adopted by the master / slave controllers are merely illustrative, and this disclosure is not limited to these examples. The optimization objectives of the master / slave controllers can be set based on actual application requirements.

[0099] Step S103: Perform command arbitration on the first control command sequence, the second control command sequence, and the third control command sequence to obtain the target control command sequence.

[0100] Among them, the safety risks of the vehicle when it is traveling according to the third control command sequence are lower than the preset risk threshold. For example, when the vehicle is traveling according to the third control command sequence, the vehicle can safely stop without losing lateral stability.

[0101] As one possible implementation, the third control command sequence can be a pre-configured fallback safety control sequence designed to put the vehicle into a low-risk operating state, ensuring that the vehicle maintains basic safety even if both the master and slave controllers fail or their outputs are unreliable. For example, the third control command sequence may include conservative commands such as applying fixed braking force, maintaining zero steering angle, and activating the electronic parking brake, ensuring that the safety risk of the vehicle driving according to this third control command sequence is below a preset risk threshold.

[0102] As another possible implementation, the third control command sequence can be a control command sequence generated by the emergency brake controller (or underbody controller, chassis feedback controller) in the vehicle based on the vehicle's chassis controller area network (CAN) signals (such as vehicle speed, chassis yaw rate, and actual steering wheel angle). This ensures that even if both the master and slave controllers fail or their outputs are unreliable, the vehicle can still reduce its speed without losing lateral stability, and after low speed or stopping, it can cooperate with the existing electronic parking brake (EPB) / parking gear (P gear) request logic to complete the parking hold.

[0103] In this embodiment of the disclosure, command arbitration can be performed on the first control command sequence, the second control command sequence, and the third control command sequence to obtain a target control command sequence. For example, a valid and usable control command sequence from the first, second, and third control command sequences can be used as the target control command sequence.

[0104] Step S104: Perform driving control on the vehicle according to the target control command sequence.

[0105] In this embodiment of the disclosure, vehicle driving control can be performed based on each control quantity in the target control command sequence. For example, each control quantity in the target control command sequence can be sent to the corresponding actuator (such as a steering motor, electric braking system, four-wheel drive torque distribution unit, etc.) to achieve precise control of the vehicle's motion state and ensure that it safely, stably, and efficiently tracks the planned trajectory.

[0106] The vehicle control method of this disclosure generates a first control command sequence oriented towards task performance through the main controller based on high-dimensional planned trajectory, current state information, historical control commands, and vehicle parameters, ensuring efficient and accurate trajectory tracking. It generates a second control command sequence oriented towards vehicle stability and safety performance from the controller, depending on the vehicle's current speed and yaw rate, forming a heterogeneous safety redundancy for the main controller. By introducing a third control command sequence containing a fallback safety strategy and arbitrating the three, the intelligent driving system can adopt the high-performance first control command sequence output by the main controller, and seamlessly switch to the safe and stable second control command sequence output by the controller when instability risks, critical scenarios, or extreme scenarios occur, or revert to the low-risk third control command sequence. Finally, the vehicle is controlled according to the arbitration result, significantly improving the vehicle's operational safety, robustness, and fault tolerance under complex or critical conditions.

[0107] As one possible implementation method, Figure 2 This is a schematic flowchart illustrating another vehicle control method provided as an exemplary embodiment of the present disclosure. It should be noted that this vehicle control method can be executed alone, or it can be executed together with any embodiment of the present disclosure or any possible implementation thereof, or it can be executed together with any technical solution in related technologies. The embodiments of the present disclosure do not impose any limitations on this.

[0108] like Figure 2 As shown, the vehicle control method may include the following steps S201 to S206: Step S201: Obtain the first control command sequence output by the vehicle's main controller based on the planned trajectory, current status information, historical control commands, and vehicle parameters.

[0109] Step S202: Obtain the second control command sequence output by the vehicle's slave controller based on the vehicle speed and yaw rate in the current status information.

[0110] It should be noted that the explanation of step S201 can be found in the relevant description in any embodiment of this disclosure, and will not be repeated here.

[0111] Step S203: Obtain the threshold parameter corresponding to the path mileage of the vehicle's current driving position; wherein, the threshold parameter is associated with at least one anomaly type, and the threshold parameter includes at least one of the following: lateral error threshold, heading error threshold, communication timeout threshold, and boundary margin threshold.

[0112] The path mileage at the vehicle's current location indicates the cumulative distance traveled from the current location along the planned path to the starting point of the journey. Anomalies include, but are not limited to: communication anomalies (or communication link anomalies), vehicle crossing / approaching road boundaries, trajectory tracking deviation anomalies, and vehicle dynamic instability anomalies.

[0113] As one possible implementation, a correspondence between different path mileages and threshold parameters can be set (e.g., the correspondence can be stored in the form of a lookup table or piecewise function). Thus, in this disclosure, the above correspondence can be queried based on the path mileage of the vehicle's current driving location to determine the threshold parameter corresponding to that path mileage.

[0114] Step S204: Based on the threshold parameter, perform anomaly detection on the current status information of the vehicle to determine the risk control status of the vehicle.

[0115] The risk control status includes Minimum Risk Action (MRA) status and non-MRA status.

[0116] As one possible implementation, anomaly detection can be performed on the current state information of the vehicle based on a threshold parameter to determine the number of times at least one type of anomaly is detected, and the risk control status of the vehicle can be determined based on the number of times at least one type of anomaly is detected.

[0117] For example, if the lateral error indicated by the current state information exceeds the lateral error threshold in the threshold parameters, the number of abnormalities for trajectory tracking deviation can be incremented by one; if the heading error indicated by the current state information exceeds the heading error threshold in the threshold parameters, the number of abnormalities for trajectory tracking deviation can be incremented by one; if the communication delay indicated by the current state information exceeds the communication timeout threshold in the threshold parameters, the number of abnormalities for communication can be incremented by one; if it is determined from the current state information that the vehicle is approaching or crossing the road boundary, the number of abnormalities for the vehicle crossing / approaching the road boundary can be incremented by one.

[0118] For example, if the number of anomalies of any anomaly type exceeds the threshold associated with that anomaly type, the vehicle's risk control status can be determined to be MRA (Missing Risk Management) status; if the number of anomalies of all anomaly types does not exceed the threshold associated with their respective anomaly types, the vehicle's risk control status can be determined to be non-MRA status. The thresholds associated with different anomaly types may be the same or different, and this embodiment does not impose any limitations on this.

[0119] Step S205: Based on the risk control status and the health status of the master controller and slave controller, the first control command sequence, the second control command sequence, and the third control command sequence are arbitrated to obtain the target control command sequence.

[0120] Health status is a discrete state identifier used to characterize the current operational reliability and functional availability of the corresponding controller. It serves as a key input for command arbitration, determining whether to adopt the control command sequence output by the corresponding controller. For example, health status includes normal, warning (e.g., the controller exhibits a tolerable anomaly for a period of time but has not yet lost its basic functions), and error (e.g., the controller has experienced a persistent or severe anomaly).

[0121] For example, when the risk control state is not MRA and the master controller's health state is not faulty, the first control command sequence can be used as the target control command sequence. When the risk control state is not MRA and the master controller's health state is faulty, and the slave controller's health state is not faulty, the second control command sequence can be used as the target control command sequence. When the risk control state is not MRA and both the master and slave controllers' health states are faulty, the third control command sequence can be used as the target control command sequence. When the risk control state is MRA and the slave controller's health state is not faulty, the second control command sequence can be used as the target control command sequence. When the risk control state is MRA and the slave controller's health state is faulty, the third control command sequence can be used as the target control command sequence.

[0122] In any embodiment of this disclosure, the command arbitration method may be as follows: performing a validity check on the first control command sequence and the second control command sequence to obtain a validity check result; performing an availability check on the first control command sequence and the second control command sequence based on the health status of the master controller and the slave controller to obtain an availability check result; and arbitrating the first control command sequence, the second control command sequence, and the third control command sequence according to the risk control status, the validity check result, and the availability check result.

[0123] The validity checks include, but are not limited to, at least one of the following: whether the command is empty or whether the command has timed out.

[0124] The validity check result indicates whether the first control command sequence and the second control command sequence are valid. For example, if the first control command sequence is not empty and the command has not timed out, the first control command sequence is determined to be valid; if there is an empty value in the first control command sequence, and / or the first control command sequence has timed out, the first control command sequence is determined to be invalid. Similarly, the validity of the second control command sequence can be determined.

[0125] The availability check result is used to indicate whether the first control command sequence and the second control command sequence are available. For example, if the health status of the master controller is not erroneous, the first control command sequence is determined to be available, while if the health status of the master controller is erroneous, the first control command sequence is determined to be unavailable. Similarly, if the health status of the slave controller is not erroneous, the second control command sequence is determined to be available, while if the health status of the slave controller is erroneous, the second control command sequence is determined to be unavailable.

[0126] Understandably, the above-mentioned command arbitration method comprehensively considers four dimensions: risk control status, health status of master / slave controllers, and command validity and availability. It not only achieves functional complementarity and safety redundancy between master and slave controllers, but also ensures that the optimal or safest control command sequence can be selected under various abnormal combinations (such as master controller failure but slave controller normal operation, or both master and slave controllers failure). This significantly improves the fault tolerance and operational continuity of the intelligent driving system.

[0127] As a first possible implementation, when the risk control state is a non-minimum risk control MRA state, and the validity check result indicates that the first control command sequence is valid, and the availability check result indicates that the first control command sequence is available, the first control command sequence can be used as the target control command sequence.

[0128] As a second possible implementation, when the risk control status is not MRA status, and the validity check result indicates that the first control command sequence is invalid while the second control command sequence is valid, and the availability check result indicates that the second control command sequence is available, the second control command sequence can be used as the target control command sequence.

[0129] As a third possible implementation, when the risk control status is not MRA status, the validity check result indicates that the second control command sequence is valid, and the availability check result indicates that the first control command sequence is unavailable while the second control command sequence is available, the second control command sequence can be used as the target control command sequence.

[0130] As a fourth possible implementation, when the risk control status is MRA status, the validity check result indicates that the second control command is valid, and the availability check result indicates that the second control command sequence is available, the second control command sequence can be used as the target control command sequence.

[0131] As a fifth possible implementation, when the risk control status is not MRA and the validity check results indicate that both the first and second control command sequences are invalid, the third control command sequence can be used as the target control command sequence.

[0132] As a sixth possible implementation, when the risk control status is not MRA and the availability check results indicate that both the first and second control command sequences are unavailable, the third control command sequence can be used as the target control command sequence.

[0133] As a seventh possible implementation, when the risk control status is MRA and the validity check result indicates that the second control command sequence is invalid, the third control command sequence can be used as the target control command sequence.

[0134] As an eighth possible implementation, if the risk control status is MRA and the availability check result indicates that the second control command sequence is unavailable, the third control command sequence can be used as the target control command sequence.

[0135] In summary, by setting multiple arbitration implementation paths, the intelligent driving system can prioritize traffic efficiency in non-MRA states (using the first control command sequence output by the main controller), forcibly switch to a stability-priority control strategy in MRA states (using the second control command sequence output by the controller or the third control command sequence as a fallback control scheme), and automatically activate the third control command sequence in the preset safety degradation mode in extreme scenarios (such as when both the main and slave controllers are abnormal). This forms a three-level control system of "high efficiency - robustness - safety net", which not only meets the performance requirements of daily driving, but also ensures that the vehicle is always in a controllable and predictable low-risk state under sudden abnormalities, thereby improving the safety of vehicle driving.

[0136] In any embodiment of this disclosure, in the event of an anomaly in the vehicle's planning module, a third control command sequence can be used as the target control command sequence; wherein, the planning module is used to output the planned trajectory. That is, this disclosure considers that when the planning module malfunctions, the master / slave controllers cannot generate a reliable control command sequence due to a lack of valid planned trajectory input. Even if the master / slave controllers are in normal health, their output may still pose a safety hazard. Therefore, this disclosure can proactively identify the upstream fault of the planning module failure and directly switch to the third control command sequence accordingly, avoiding vehicle loss of control due to reliance on invalid planning.

[0137] Step S206: Perform driving control on the vehicle according to the target control command sequence.

[0138] It should be noted that the explanation of step S206 can be found in the relevant description in any embodiment of this disclosure, and will not be repeated here.

[0139] The vehicle control method of this disclosure introduces a threshold parameter dynamically associated with the path mileage of the vehicle's current driving position. Based on this threshold parameter, it performs anomaly detection and counting on multiple dimensions of states such as lateral error, heading deviation, communication delay, and road boundary margin. It can objectively determine whether the vehicle has entered the minimum risk control (MRA) state based on the accumulated number of anomalies, thereby avoiding frequent switching of control strategies due to single instantaneous interference. On this basis, combined with the real-time health status of the master controller and slave controller, command arbitration is performed on the first control command sequence, the second control command sequence, and the third control command sequence. This not only significantly improves the robustness of the system to instantaneous anomalies and effectively suppresses the jitter and oscillation of control commands, but also enhances the fault tolerance and safety degradation capabilities of the intelligent driving system through a closed-loop evaluation method of "anomaly counting - risk rating - health assessment - multi-source arbitration". This ensures that the vehicle always maintains a controllable and predictable low-risk operating state in various complex or critical scenarios.

[0140] In related technologies, intelligent driving vehicles, operating in high-dynamic scenarios such as high speeds, sharp curves, gradient changes, near adhesion limits, or on racetracks, need to simultaneously meet requirements for trajectory tracking accuracy, vehicle stability, tire adhesion margin, longitudinal drive and braking force constraints, front and rear axle torque distribution capabilities, and actuator response constraints. Traditional linear control or low-order vehicle model control methods often struggle to simultaneously handle tire nonlinearity, longitudinal and lateral coupling, path boundary constraints, differences in front and rear axle drive and braking capabilities, and actuator delays. This can easily lead to problems such as increased lateral error, excessive vehicle sideslip angle, steering command jitter, unreasonable front and rear axle torque distribution, or unrealizable longitudinal forces in curves or forced-motion scenarios. Furthermore, considering the communication, computation, steering, and drive / braking control response delays of vehicle actuators, directly using the current measured state as the initial optimization value may result in a misalignment between the optimized trajectory and the actual vehicle state.

[0141] To address at least one of the aforementioned problems, this disclosure also proposes a vehicle control method. Figure 3 This is a schematic flowchart illustrating another vehicle control method provided as an exemplary embodiment of the present disclosure. It should be noted that this vehicle control method can be executed alone, or it can be executed together with any embodiment of the present disclosure or any possible implementation thereof, or it can be executed together with any technical solution in related technologies. The embodiments of the present disclosure do not impose any limitations on this.

[0142] like Figure 3 As shown, based on any embodiment of this disclosure, the main controller may output a first control command sequence using the following steps S301 to S304: Step S301: Based on the vehicle's historical control commands and current status information, predict the vehicle's predicted status information at the time the control command takes effect.

[0143] It should be noted that the explanations of historical control commands and current status information in the foregoing embodiments also apply to this embodiment, and will not be repeated here.

[0144] The control command effective time refers to the time when the vehicle control command takes effect. Predicted state information indicates the vehicle state at the time the control command takes effect, including the predicted pose.

[0145] As one possible implementation, the main controller can employ deep learning, reinforcement learning, or machine learning techniques from the field of artificial intelligence to predict the vehicle's state information after delay compensation at the time the control command takes effect, based on the vehicle's historical control commands and current state information. For example, a trained deep learning model can be used to predict the vehicle's state information after delay compensation at the time the control command takes effect, based on the vehicle's historical control commands and current state information. The deep learning model has learned the mapping relationship between the input data (historical control commands and current state information) and the output data (predicted state information).

[0146] As another possible implementation, the main controller can input current state information, historical control commands, and reference road topology information into the nonlinear dynamic model, and integrate forward over a fixed sampling time to obtain the predicted state information after delay compensation. Delay compensation can be achieved using Euler integration, trapezoidal integration, or fourth-order Runge-Kutta integration.

[0147] Step S302: Project the predicted state information onto the path coordinate system corresponding to the planned trajectory to determine the target trajectory point closest to the predicted state information from each trajectory point of the planned trajectory.

[0148] The path coordinate system can be the DL coordinate system in the trajectory planning context, where the D (longitudinal, Along-track or Down-track) axis is along the trajectory tangent (longitudinal / heading) and the L (lateral, Lateral) axis is perpendicular to the trajectory normal (lateral / side deviation).

[0149] As an example, the main controller can calculate the predicted centroid pose based on the path mileage, lateral error, and heading error corresponding to the predicted state information. Based on the predicted centroid pose, the controller can determine the projection point of the predicted state information onto the path coordinate system, thereby identifying the target trajectory point closest to the projection point from among the trajectory points of the planned trajectory.

[0150] Step S303: Starting from the target trajectory point, resample the planned trajectory to obtain the reference trajectory.

[0151] In this embodiment of the disclosure, the planned trajectory is resampled using the target trajectory point as the new trajectory starting point to obtain a reference trajectory.

[0152] Step S304: Based on the first optimization objective associated with the main controller, generate a first control command sequence according to the reference trajectory, predicted state information, vehicle parameters and historical control commands, and output it.

[0153] The explanations of vehicle parameters in the aforementioned embodiments also apply to this embodiment, and will not be repeated here.

[0154] The first optimization objective focuses on global task performance (such as efficient passage). For example, the first optimization objective is to maximize passage efficiency while satisfying security constraints.

[0155] In this embodiment of the disclosure, the main controller can generate a first control command sequence based on its own associated first optimization objective, according to the reference trajectory, predicted state information, vehicle parameters and historical control commands, and output it.

[0156] The vehicle control method of this disclosure predicts the vehicle's state information at the moment the control command takes effect based on historical control commands and current state information, and projects this predicted state information onto the path coordinate system of the planned trajectory to determine the nearest target trajectory point. Based on this, the original planned trajectory is resampled to generate a reference trajectory. This effectively solves the problem of "misalignment between the initial optimization value (or initial state) and the actual vehicle state" caused by actuator communication, calculation, and response delays. The reference trajectory is partially reconstructed starting from the predicted state information, which ensures that the trajectory context on which the subsequent optimization process depends is highly aligned with the actual state that the vehicle is about to reach. This significantly improves the foresight of trajectory tracking and the feasibility of control commands, especially in scenarios such as high-speed cornering, slopes, or changes in adhesion, avoiding the accumulation of lateral errors or oscillations in steering commands caused by trajectory-state mismatch.

[0157] As one possible implementation method, Figure 4 This is a schematic flowchart illustrating another vehicle control method provided as an exemplary embodiment of the present disclosure. It should be noted that this vehicle control method can be executed alone, or it can be executed together with any embodiment of the present disclosure or possible implementations thereof, or it can be executed together with any technical solution in related technologies. The embodiments of the present disclosure do not impose any limitations on this.

[0158] like Figure 4 As shown, based on any embodiment of this disclosure, the main controller may output a first control command sequence using the following steps S401 to S406: Step S401: Based on the vehicle's historical control commands and current status information, predict the vehicle's predicted status information at the time the control command takes effect.

[0159] Step S402: Project the predicted state information onto the path coordinate system corresponding to the planned trajectory to determine the target trajectory point closest to the predicted state information from each trajectory point of the planned trajectory.

[0160] Step S403: Starting from the target trajectory point, resample the planned trajectory to obtain the reference trajectory.

[0161] It should be noted that the explanations of steps S401 to S403 can be found in the relevant descriptions in any embodiment of this disclosure, and will not be repeated here.

[0162] Step S404: Based on the reference trajectory, predicted state information, vehicle parameters, and historical control commands, determine the first objective cost function corresponding to the first optimization objective of the main controller; wherein the first objective cost function uses the first state variable and the first control variable as decision variables.

[0163] It should be noted that in related technologies, trajectory tracking control focuses more on lateral and heading errors, while insufficiently considering the effects of tire slip angle, longitudinal and lateral adhesion distribution, motor power, slope, and cross slope. Furthermore, for vehicles with front and rear axle drive or regenerative braking capabilities, these technologies only optimize the total longitudinal force without optimizing the front / rear axle longitudinal force ratio, which may lead to excessive power or torque of a single axle motor or failure to fully utilize the front and rear axle adhesion margin.

[0164] To address the aforementioned issues, the first state variable in this disclosure refers to a physical quantity used to describe the vehicle's motion state in the future prediction time domain. It reflects the vehicle's current and short-term future dynamic behavior, including but not limited to at least one of the following: lateral error e y Heading error Vehicle speed v, vehicle slip angle yaw rate Steering wheel angle Steering wheel angular velocity etc.; among which, the vehicle slip angle includes the front wheel slip angle and the rear wheel slip angle.

[0165] The first control variable refers to the amount of execution instructions that the main controller can actively adjust during the optimization process to drive the vehicle to evolve towards the desired state. This includes, but is not limited to, the target steering wheel angle. Torque distribution, total longitudinal force F LThe torque distribution includes, but is not limited to, any one of the following: the front axle longitudinal force to be distributed to the front axle out of the total longitudinal force, the rear axle longitudinal force to be distributed to the rear axle out of the total longitudinal force, and the proportion of the front axle longitudinal force. Rear axle longitudinal force ratio (1- Among them, the front axle longitudinal force ratio is the ratio of the front axle longitudinal force to the total longitudinal force of the vehicle, and the rear axle longitudinal force ratio is the ratio of the rear axle longitudinal force to the total longitudinal force of the vehicle.

[0166] Understandably, by specifying the first state variable as key kinematic and dynamic quantities, including lateral error, heading error, vehicle speed, front / rear wheel slip angle, yaw rate, steering wheel angle and its rate of change, and defining the first control variable as executable physical quantities such as the target steering wheel angle, total longitudinal force, and the distribution of front / rear axle longitudinal forces, it is possible to achieve refined modeling and precise control of the vehicle's longitudinal and lateral coupled motion. Introducing the front / rear wheel slip angle as a state variable allows the main controller to directly sense and constrain whether the tire's working point is close to the adhesion limit. Designing the torque distribution as a proportional or axle-part force facilitates seamless integration with four-wheel drive or distributed drive chassis actuators. This targeted selection of state and control variables not only enhances the physical interpretability of the optimization problem but also ensures that the generated first control command sequence possesses high-precision tracking capabilities and strong environmental adaptability on actual vehicles, making it particularly suitable for scenarios with stringent requirements for tire utilization efficiency and dynamic balance, such as track driving, slippery surfaces, or high-curvature curves.

[0167] In this embodiment of the disclosure, the main controller can integrate the first optimization objective, reference trajectory, predicted state information, vehicle parameters, and historical control commands to determine the first objective cost function corresponding to the first optimization objective. The first objective cost function uses a first state variable and a first control variable as decision variables. The first state variable is associated with the first control variable through an equality constraint defined by a nonlinear dynamic model. The nonlinear dynamic model is used to indicate the nonlinear mapping relationship between the coupled response of longitudinal and lateral forces and the vehicle motion state.

[0168] In any embodiment of this disclosure, the nonlinear dynamics model can comprehensively consider the following factors: the evolution of lateral error, heading error, velocity, sideslip angle, yaw rate, and steering actuator state based on the center of mass; second-order dynamics of the steering actuator, calculating the velocity change of the steering wheel angle based on the difference between the target steering wheel angle and the actual steering wheel angle; calculation of front / rear wheel lateral forces based on the tire magic formula, wherein the vehicle sideslip angle (or tire sideslip angle) can be determined by velocity, sideslip angle, yaw rate, and front wheel angle; and the ratio of front axle longitudinal forces. The total longitudinal force is decomposed into front axle longitudinal force and rear axle longitudinal force. The front and rear axle longitudinal forces are involved in the calculation of tire lateral force, normal load, yaw moment, and longitudinal acceleration. In scenarios requiring a fixed ratio, the following can also be used: The constraints are calibrated values; the effects of slope, cross slope, air resistance, rolling resistance, tire normal load transfer, and vehicle maximum power on dynamics and constraints; the steering transmission ratio coefficient is adjusted based on curvature and truncated by upper and lower limits to adapt to the mapping of steering wheel angle and tire angle under different curvature scenarios.

[0169] In any embodiment of this disclosure, the first objective cost function may be determined according to at least one of the following cost functions: The first term is the state tracking cost function, which is jointly determined based on the lateral error, heading error, and speed error in the first state variables, as well as the front axle longitudinal force proportional tracking error determined based on the torque distribution in the first control variable. For example, the state tracking cost function is determined based on the lateral error, heading error, speed error, and front axle proportional tracking error. The lateral error and heading error can employ a quadratic cost with exponential modulation, giving different penalty characteristics to small and large error regions. The front axle proportional tracking error can guide the front axle longitudinal force proportion in braking or energy recovery scenarios. Approaching the desired braking distribution.

[0170] The second term is the comfort cost function, which is determined based on the rate of change between two consecutive solutions (or determinations) of the first control variable. For example, the comfort cost function is determined based on the rate of change of steering command, the rate of change of total longitudinal force, and the rate of change of the front axle longitudinal force ratio between consecutive control points, and the weight of the steering command rate of change can vary with the fourth power of the speed.

[0171] The third term is the tire side slip cost function, which is determined based on the front and rear wheel side slip angles in the first state variable. This tire side slip cost function is used to suppress excessive front / rear wheel side slip angles.

[0172] The fourth item is the road boundary intrusion cost function, which is determined based on the lateral error and error boundary values ​​in the first state variable. This cost function is used to add a penalty when the lateral error exceeds the left and right boundaries of the error boundary values.

[0173] The fifth item is the over-slip cost function, which is determined jointly by the vehicle slip angle (or tire slip angle) determined by the first state variable and the limit slip angle determined by the tire model in the vehicle parameters. The over-slip cost function is used to add a penalty when the vehicle slip angle exceeds the limit slip angle obtained from the tire model.

[0174] The sixth item is the lateral convergence speed cost function, which is determined based on the lateral error in the first state variable and the desired lateral convergence speed. Specifically, the lateral convergence speed cost function is used to provide the desired lateral convergence speed when the lateral error exceeds a set threshold.

[0175] The seventh item is the reference steering and reference longitudinal force cost function, which is determined based on the deviation between the reference steering and reference longitudinal force at each trajectory point in the reference trajectory and the first control variable. The reference steering and reference longitudinal force cost function is used to reduce the deviation between the optimized first control variable and the corresponding control quantity in the reference trajectory.

[0176] The eighth item is the aiming time cost function, which is determined based on the deviation between the predicted travel time and the target aiming time under the target driving mode. The predicted travel time is the time required for the vehicle to traverse the path distance corresponding to the future predicted time domain, determined based on the first state variable and the first control variable. The target aiming time is the expected travel time for the vehicle to traverse the path distance under the target driving mode. The target driving mode includes, but is not limited to, racing mode.

[0177] That is, the aiming time cost function is used to encourage vehicles to travel the above path distance in a shorter time under the target driving mode.

[0178] In summary, the state tracking cost function ensures the vehicle accurately follows the reference trajectory in terms of lateral position, heading, and speed; the comfort cost function suppresses high-frequency jitter in control commands, improving passenger experience; the tire slip / over-slip cost function explicitly constrains the front and rear wheel operating points away from the adhesion limit, preventing vehicle instability; the road boundary intrusion cost function actively avoids the risk of exceeding road boundaries; the lateral convergence speed cost function accelerates error decay, improving cornering responsiveness; and the reference steering and reference longitudinal force cost functions ensure the control output aligns with the planning intent. Figure 1 The anticipation time cost function enables the vehicle to adaptively adjust its driving rhythm under different driving modes, achieving on-demand time control. The fusion design of the above multi-dimensional cost functions allows the main controller to meet high-precision tracking requirements while also ensuring safety, comfort, and consistency in driving style under complex operating conditions, significantly outperforming traditional optimization methods that only focus on a single performance indicator.

[0179] Step S405: Under the constraints of the executable domain indicated by the target constraint information associated with the vehicle, calculate the first control variable that can satisfy the first optimization objective indicated by the first target cost function in the future prediction time domain, and obtain the predicted value of the first control variable.

[0180] The target constraint information is used to constrain the values ​​of the first state variable and the first control variable in the first target cost function. For example, the target constraint information includes, but is not limited to, at least one of the following constraints: initial state constraints (used to instruct the first target cost function to solve for (or determine) each first control variable based on the predicted state information), equality constraints defined by the nonlinear dynamics model (such as equality constraints of a nonlinear dynamics model based on trapezoidal integrals), constraints on the rate of change of the target steering wheel angle, constraints on the rate of change of longitudinal force, constraints on the rate of change of the proportion of front axle longitudinal force, constraints that neither the front axle longitudinal force nor the rear axle longitudinal force exceeds the tire adhesion capacity, constraints that the product of the total longitudinal force and the vehicle speed does not exceed the total vehicle motor power, constraints that the product of the front axle longitudinal force and the vehicle speed does not exceed the front axle motor power, constraints that the product of the rear axle longitudinal force and the vehicle speed does not exceed the rear axle motor power, constraints that the front axle driving force does not exceed the maximum front axle driving force, and constraints that the rear axle driving force does not exceed the maximum rear axle driving force.

[0181] Among them, the upper and lower limits indicated by the rate of change constraint of the target steering angle can be dynamically contracted according to the reference steering, the currently predicted longitudinal force and vehicle speed, so that the lateral input is more in line with the vehicle's capability boundary.

[0182] Understandably, by introducing multiple physical constraints into the optimization problem, including those covering initial state, nonlinear dynamics, actuator rate of change, tire adhesion, and motor power limitations, it can be ensured that the first control command sequence generated by the main controller is not only mathematically optimal but also fully executable in a real vehicle: initial state constraints ensure that optimization starts from predicted state information, avoiding state jumps; the equality constraints of the nonlinear dynamics model accurately characterize the longitudinal and lateral coupled motion; the rate of change constraints of steering wheel angle, longitudinal force, and torque distribution ratio effectively suppress actuator saturation and mechanical shock; the adhesion constraint based on the tire model prevents the front and rear axle driving braking forces from exceeding the friction circle boundary; and the vehicle and axle motor power constraints ensure that control commands do not exceed the upper limit of the electric drive system's capabilities in high-speed or steep gradient scenarios. These constraints together constitute a compact and realistic "executable domain," avoiding problems such as command unreachability, tire slippage, or power interruption caused by ignoring the physical limits of actuators in related technologies, greatly improving the control reliability and system robustness in high-dynamic driving scenarios.

[0183] The executable domain refers to the set of all feasible control inputs that satisfy the vehicle's physical characteristics and operational safety requirements, as defined by the target constraint information. For example, the executable domain is the legal space in which the first control variable and the first state variable can take values ​​within the predicted state information and future prediction time domain, while simultaneously satisfying conditions such as the nonlinear dynamics model, actuator capability limitations, tire adhesion boundaries, drive / brake distribution constraints, and feasible road areas.

[0184] In this embodiment of the disclosure, the main controller can solve the first objective cost function based on the executable domain indicated by the target constraint information associated with the vehicle, so as to calculate the predicted values ​​of each first control variable in the future prediction time domain.

[0185] Step S406: Generate a first control command sequence based on the predicted value of the first control variable and output it.

[0186] In this embodiment of the disclosure, the main controller can generate a first control command sequence based on the predicted value of the first control variable, that is, each control quantity in the first control command sequence is generated based on the predicted value of the first control variable.

[0187] The vehicle control method of this disclosure constructs a first objective cost function constrained by a nonlinear dynamic model and solves for the optimal first control variable within the feasible region defined by the vehicle's execution capability constraints. This method can explicitly characterize the strong coupling nonlinear relationship between longitudinal and lateral forces, thereby simultaneously considering trajectory tracking accuracy, vehicle stability, and execution feasibility during the optimization process. Compared with related technologies based on linearized models or decoupled control, this disclosure can generate physically realizable and energy-efficient control commands under extreme conditions such as cornering acceleration, emergency obstacle avoidance, or low-adhesion road surfaces. It effectively suppresses problems such as excessive sideslip angle, torque distribution imbalance, or unreachable longitudinal force, significantly improving control robustness and safety in high-dynamic scenarios.

[0188] As one possible implementation method, Figure 5 This is a flowchart illustrating another vehicle control method provided as an exemplary embodiment of the present disclosure. It should be noted that this vehicle control method can be executed alone, or it can be executed together with any embodiment of the present disclosure or any possible implementation thereof, or it can be executed together with any technical solution in related technologies. The embodiments of the present disclosure do not impose any limitations on this.

[0189] like Figure 5 As shown, based on any embodiment of this disclosure, the main controller may output a first control command sequence using the following steps S501 to S508: Step S501: Based on the vehicle's historical control commands and current status information, predict the vehicle's predicted status information at the time the control command takes effect.

[0190] Step S502: Project the predicted state information onto the path coordinate system corresponding to the planned trajectory to determine the target trajectory point closest to the predicted state information from each trajectory point of the planned trajectory.

[0191] Step S503: Starting from the target trajectory point, resample the planned trajectory to obtain the reference trajectory.

[0192] Step S504: Based on the reference trajectory, predicted state information, vehicle parameters, and historical control commands, determine the first objective cost function corresponding to the first optimization objective; wherein, the first objective cost function uses the first state variable and the first control variable as decision variables.

[0193] In this process, the first state variable is associated with the first control variable through an equality constraint defined by the nonlinear dynamic model. The nonlinear dynamic model is used to indicate the nonlinear mapping relationship between the coupled response of longitudinal and lateral forces and the vehicle's motion state. It should be noted that explanations of steps S501 to S504 can be found in the relevant descriptions in any embodiment of this disclosure, and will not be repeated here.

[0194] Step S505: Determine the vehicle's driving condition information based on at least one of the planned trajectory, the path mileage of the vehicle's current driving location, and the configuration mode, and determine the target driving mode from multiple driving modes based on the vehicle's driving condition information.

[0195] The driving condition information includes, but is not limited to: action markers in the planned trajectory, path mileage or configuration mode of the vehicle's current driving position, etc.; wherein, the configuration mode refers to the control strategy marker actively set by the user, system or external command to indicate the current operating scenario of the vehicle or the driving preference specified by the user, such as closed test track mode, track racing mode, urban commuting mode, energy saving priority mode, etc.

[0196] The target driving modes include, but are not limited to: normal mode, special path mode and racing mode. Different target driving modes correspond to different weight configurations and constraint tightness of the cost function.

[0197] In this embodiment of the disclosure, the main controller can determine the vehicle's driving condition information based on at least one of the planned trajectory, the path mileage of the vehicle's current driving location, and the configuration mode, and determine the target driving mode that matches the driving condition information from a variety of driving modes.

[0198] Step S506: Based on the target driving mode, adjust the weights of each cost function in the first target cost function and the executable boundaries of each constraint indicated by the executable domain.

[0199] Among them, the executable domain is the executable domain indicated by the target constraint information associated with the vehicle.

[0200] In this embodiment, the main controller can adjust the weights of each cost function in the first target cost function and the executable boundaries of each constraint indicated by the executable domain, based on the weight configuration and constraint tightness of the cost function corresponding to the target driving mode. For example, when the action marker in the planned trajectory indicates that the vehicle has entered a special area, the main controller can switch to a special path mode and change parameters such as lateral error, heading error, vehicle sideslip angle (or tire sideslip angle), and prediction step size. When the vehicle is in low-speed and high-speed scenarios, the main controller can change the weights of lateral error, heading error, and terminal error (i.e., endpoint error) through speed interpolation to avoid the problem that a single weight cannot adequately address both stability and sensitivity across the entire speed domain.

[0201] Step S507: Under the constraints of the adjusted executable domain, calculate the first control variable that can satisfy the first optimization objective indicated by the adjusted first objective cost function in the future prediction time domain, and obtain the predicted value of the first control variable.

[0202] In this embodiment of the disclosure, the main controller can solve the adjusted first objective cost function based on the adjusted executable domain to obtain the predicted values ​​of each first control variable in the future prediction time domain.

[0203] Step S508: Generate a first control command sequence based on the predicted value of the first control variable and output it.

[0204] It should be noted that the explanation of step S508 can be found in the relevant description in any embodiment of this disclosure, and will not be repeated here.

[0205] The vehicle control method of this disclosure can achieve scenario-adaptive optimization of the control strategy by dynamically selecting the target driving mode according to the current driving condition information of the vehicle, and adjusting the weights of each cost function in the first target cost function and the executable boundaries of each constraint in the executable domain accordingly. That is, under different driving scenarios, the main controller can focus on the most critical performance indicators and match the corresponding physical feasible range, thereby avoiding the "one-sided" problem caused by using fixed weights and static constraints. For example, when driving condition information indicates that the vehicle is about to enter a construction zone, narrow curve, or parking area, the main controller can switch to a "special path mode" to actively tighten the tolerance boundaries of lateral error, heading error, and vehicle sideslip angle, and shorten the prediction step size to improve path tracking accuracy and local obstacle avoidance safety. Furthermore, in low-speed scenarios (such as urban congestion), the weights of terminal error and heading error can be increased to ensure accurate stopping and lane centering. In high-speed scenarios (such as highway lane changes), the weight of lateral error can be appropriately reduced, the weights of lateral convergence speed and stability-related terms can be increased, and the rate of change constraints of some actuators can be relaxed to balance responsiveness and ride comfort. This significantly improves the adaptability, control robustness, and user experience consistency of the intelligent driving system in diverse road environments.

[0206] As one possible implementation method, Figure 6 This is a schematic flowchart illustrating another vehicle control method provided as an exemplary embodiment of the present disclosure. It should be noted that this vehicle control method can be executed alone, or it can be executed together with any embodiment of the present disclosure or any possible implementation thereof, or it can be executed together with any technical solution in related technologies. The embodiments of the present disclosure do not impose any limitations on this.

[0207] like Figure 6 As shown, based on any embodiment of this disclosure, the main controller may output a first control command sequence using the following steps S601 to S609: Step S601: Based on the vehicle's historical control commands and current status information, predict the vehicle's predicted status information at the time the control command takes effect.

[0208] Step S602: Project the predicted state information onto the path coordinate system corresponding to the planned trajectory to determine the target trajectory point closest to the predicted state information from each trajectory point of the planned trajectory.

[0209] Step S603: Starting from the target trajectory point, resample the planned trajectory to obtain the reference trajectory.

[0210] Step S604: Based on the reference trajectory, predicted state information, vehicle parameters, and historical control commands, determine the first objective cost function corresponding to the first optimization objective; wherein, the first objective cost function uses the first state variable and the first control variable as decision variables.

[0211] The first state variable is associated with the first control variable through the equality constraints defined by the nonlinear dynamic model. The nonlinear dynamic model is used to indicate the nonlinear mapping relationship between the coupled response of longitudinal and lateral forces and the vehicle motion state.

[0212] It should be noted that the explanations of steps S601 to S604 can be found in the relevant descriptions in any embodiment of this disclosure, and will not be repeated here.

[0213] Step S605: Under the constraints of the executable domain indicated by the target constraint information associated with the vehicle, calculate the first control variable and the first state variable that can satisfy the first optimization objective indicated by the first objective cost function in the future prediction time domain, and obtain the predicted values ​​of the first control variable and the first state variable.

[0214] It should be noted that the explanation of the target constraint information can be found in the relevant description in any embodiment of this disclosure, and will not be repeated here.

[0215] In this embodiment of the disclosure, the main controller can solve the first objective cost function based on the executable domain indicated by the target constraint information associated with the vehicle, so as to obtain the predicted values ​​of each first control variable and each first state variable in the future prediction time domain.

[0216] Step S606: Estimate the state bias of the nonlinear dynamics model based on the reference trajectory, vehicle parameters and historical control commands.

[0217] For example, in order to improve vehicle robustness, the main controller can estimate the lateral velocity offset, steering wheel zero offset, steering wheel angular velocity, and lateral error model offset based on the reference trajectory, vehicle parameters, and historical control commands.

[0218] Among them, the steering wheel zero-position offset / steering wheel angular velocity offset estimation is activated when the reference yaw rate is small and the lateral error exceeds the set threshold, and the offset value is updated through exponential filtering to ultimately limit it within the preset range.

[0219] Among them, the lateral velocity offset estimation is activated when each trajectory point in the reference trajectory is approximately straight, in order to reduce the impact of lateral velocity measurement error on the side slip angle estimation.

[0220] Among them, the lateral error model bias is used to correct the lateral error variation term in the vehicle model, so that the systematic error between the actual vehicle and the model prediction is compensated.

[0221] Step S607: Use the state bias to compensate and correct the predicted value of the first state variable.

[0222] In this embodiment of the disclosure, the main controller can use the state bias of the nonlinear dynamic model to compensate and correct the predicted value of the corresponding first state variable. For example, the steering wheel angular velocity bias can be used to compensate and correct the predicted value of the steering wheel angular velocity in the first state variable.

[0223] Step S608: Based on the corrected predicted value of the first state variable, compensate and correct the predicted value of the first control variable.

[0224] In this embodiment of the disclosure, the main controller can determine the predicted value of the first control variable after compensation correction based on the predicted value of the first state variable and the nonlinear dynamic model.

[0225] Step S609: Generate and output the first control command sequence based on the predicted value of the first control variable after compensation and correction.

[0226] In this embodiment of the disclosure, the main controller can generate a first control command sequence based on the predicted value of the first control variable after compensation and correction. That is, each control quantity in the first control command sequence is generated based on the predicted value of the first control variable after compensation and correction.

[0227] In any embodiment of this disclosure, the first control command sequence is generated in the following manner: the main controller can generate the predicted trajectory of the current control cycle (or the current frame) based on the predicted value of the corrected first state variable, calculate the trajectory offset between the predicted trajectory and the reference trajectory, and determine whether the trajectory offset is less than a set offset threshold. If so, i.e. the trajectory offset is less than the offset threshold, the main controller can generate the first control command sequence of the current control cycle based on the predicted value of the corrected first control variable. If not, the main controller output is determined to be abnormal. In this case, it is not necessary to generate the first control command sequence of the current control cycle based on the predicted value of the corrected first control variable.

[0228] It should be understood that by constructing the predicted trajectory of the current control cycle based on the predicted value of the corrected first state variable before the main controller generates the first control command sequence, and calculating the trajectory offset between it and the reference trajectory, the predicted value of the compensated and corrected first control variable is adopted as the effective output only when the trajectory offset is less than a preset offset threshold. This can achieve closed-loop verification of the feasibility of the control command, effectively preventing the issuance and execution of control commands that are "nominally optimal but actually deviate too much" due to factors such as model residual errors, external disturbances, or unstable optimization values. Especially in interference scenarios such as high curvature curves, abrupt attachment changes, or strong crosswinds, even if the optimization solution is successful, the predicted trajectory may still deviate significantly from the expected reference trajectory due to the lack of dynamic modeling. In this case, the secondary verification of the trajectory offset can promptly intercept unreliable control commands, thereby significantly improving the safety and trajectory consistency of the control system.

[0229] In any embodiment of this disclosure, if there is no predicted value that satisfies the first optimization objective (i.e., the first objective cost function fails to be solved), and the number of consecutive abnormal outputs by the main controller does not exceed a set threshold, the main controller may output the first control command sequence of the previous control cycle and set the health status of the main controller to a warning. The health status of the main controller serves as input for command arbitration.

[0230] Among them, the output anomalies of the main controller include, but are not limited to: failure to solve the first objective cost function, anomalies in the control command sequence output by the main controller, and the trajectory offset solved by the main controller exceeding the offset threshold; among them, anomalies in the control command sequence include: the presence of null values ​​or abnormal values ​​in the control command sequence.

[0231] In any embodiment of this disclosure, if there is no predicted value that satisfies the first optimization objective (i.e., the first objective cost function fails to be solved), and the number of consecutive abnormal outputs of the main controller exceeds a set threshold, the health status of the main controller can be set to error; wherein, the health status of the main controller is used as input for command arbitration.

[0232] Understandably, by introducing a hierarchical health status management mechanism based on the number of consecutive failures when the main controller cannot find a feasible solution that satisfies the first optimization objective—when the number of consecutive abnormal outputs of the main controller does not exceed the limit, the valid control command sequence of the previous control cycle is maintained, and its health status is set to "warning"; while when the number of consecutive abnormal outputs of the main controller exceeds the limit, the health status of the main controller is set to "error"—dynamic assessment and gradual degradation of the operational reliability of the main controller can be achieved. On the one hand, brief output abnormalities will not immediately lead to control interruption, but will maintain stable vehicle operation and avoid control jumps by maintaining the previous valid control command sequence. On the other hand, persistent output abnormalities are identified as potential functional abnormalities, triggering an error state and serving as a key input for subsequent command arbitration, prompting the system to switch to a slave controller or fallback control safety strategy in a timely manner. This not only enhances the fault tolerance of the main controller itself, but also provides accurate health status basis for master-slave collaborative arbitration, effectively supporting the smooth transition and safety redundancy of the entire control system under abnormal operating conditions.

[0233] The vehicle control method of this disclosure estimates the state bias of the nonlinear dynamic model (such as yaw rate bias, steering wheel zero-position offset, lateral error model deviation, etc.) based on the reference trajectory, vehicle parameters, and historical control commands. Based on this, the predicted value of the first state variable is compensated and corrected. Then, based on this, the predicted value of the first control variable is iteratively optimized and adjusted. Finally, a compensated and corrected first control command sequence is generated. This method can achieve closed-loop compensation for the systematic deviation between the actual vehicle motion behavior and the model prediction. This makes the generated first control command sequence closer to the actual physical characteristics of the vehicle and avoids problems such as control lag, tracking deviation accumulation, or stability degradation caused by model mismatch. It effectively improves vehicle control performance, especially in complex scenarios such as long time domain prediction, low-adhesion road surfaces, or frequent lane changes.

[0234] As one possible implementation method, Figure 7 This is a schematic flowchart illustrating another vehicle control method provided as an exemplary embodiment of the present disclosure. It should be noted that this vehicle control method can be executed alone, or it can be executed together with any embodiment of the present disclosure or any possible implementation thereof, or it can be executed together with any technical solution in related technologies. The embodiments of the present disclosure do not impose any limitations on this.

[0235] like Figure 7 As shown, based on any embodiment of this disclosure, the controller can output a second control command sequence using the following steps S701 to S703: Step S701: In response to the vehicle meeting the set first abnormal triggering condition, the desired deceleration of the vehicle is determined based on the vehicle speed and yaw rate in the vehicle's current state information.

[0236] The first abnormal triggering condition is a pre-set abnormal condition that may trigger the vehicle to enter the risk control state. For example, the first abnormal triggering condition includes, but is not limited to, at least one of the following conditions: abnormal output of the main controller, the distance between the vehicle and the road boundary is less than the set distance, abnormal vehicle communication, the vehicle is in the minimum risk control (MRA) state, and the tracking error of the vehicle on the planned trajectory exceeds the set error threshold.

[0237] Among them, the distance between the vehicle and the road boundary is less than the set distance, which means that the vehicle approaches or crosses the road boundary.

[0238] The method for determining the MRA state is, for example, as follows: obtaining a threshold parameter corresponding to the path mileage of the vehicle's current driving location, and performing anomaly detection on the vehicle's current state information based on the threshold parameter to determine the number of times at least one anomaly type is detected. Therefore, based on the number of anomalies for each anomaly type, it can be determined whether the vehicle is in an MRA state. The implementation principle can be found in the relevant descriptions in the above embodiments, and will not be repeated here.

[0239] In summary, by explicitly defining the first abnormal trigger condition as including risky situations such as abnormal output of the main controller, vehicle approaching the road boundary, communication abnormality, being in MRA state, or exceeding the trajectory tracking error limit, it can be ensured that the slave controller can be activated in a timely manner in critical scenarios where safety intervention is most needed. These abnormal trigger conditions cover potential abnormal modes in multiple dimensions such as perception, planning, control, communication, and vehicle-environment interaction, making the activation of the slave controller highly context-aware and proactive, significantly improving the timing rationality of the slave controller's response, thereby ensuring both safety and system operating efficiency.

[0240] The desired deceleration refers to the vehicle's desired longitudinal deceleration.

[0241] As one possible implementation method, the desired deceleration can be determined, for example, by determining the vehicle's desired deceleration based on the vehicle's current speed, yaw rate, and configuration parameters; wherein the configuration parameters indicate the maximum lateral acceleration and maximum longitudinal acceleration associated with the wheels.

[0242] As an example, the controller can adjust the vehicle's speed based on its current speed v and yaw rate. Calculate the desired deceleration a using configuration parameters. des For example, |v can be obtained from the controller The desired deceleration is obtained by using a linear model and upper and lower limit truncation as the risk intensity input. For example, the controller can determine the vehicle's actual lateral acceleration based on the vehicle's current speed and yaw rate, and then determine the vehicle's desired deceleration (i.e., the desired longitudinal deceleration) based on the lateral acceleration, the vehicle's maximum permissible lateral acceleration, and the maximum longitudinal acceleration. For instance, the controller can calculate the desired deceleration Ax using the following formula: (1) in, For maximum lateral acceleration, For minimum lateral acceleration, For the maximum longitudinal acceleration, |v | represents the estimated lateral acceleration of the current vehicle; eps is a set minimum value, used as a protection term to prevent the denominator from being zero.

[0243] As another possible implementation, the desired deceleration can be determined as follows: The road curvature of the current travel path and the boundary distance between the vehicle and the road boundary are determined. The desired deceleration is then determined based on multiple factors, including the vehicle's current speed, yaw rate, lateral error, road curvature, and boundary distance. The lateral error is determined based on the vehicle's current state information and the planned trajectory. In other words, in this disclosure, the desired deceleration can be determined by the vehicle's current speed, yaw rate, lateral error, road curvature, boundary distance, or a combination thereof.

[0244] In summary, different methods can be used to calculate the expected deceleration of a vehicle, which can improve the flexibility and applicability of this method.

[0245] Step S702: Determine the speed sequence and path mileage sequence in the future prediction time domain based on vehicle speed, expected deceleration and prediction step time.

[0246] In this embodiment of the disclosure, the speed sequence in the future prediction time domain can be calculated based on the vehicle's current speed, expected deceleration and prediction step time, and a path mileage sequence can be generated based on the speed sequence and prediction step time.

[0247] For example, the first velocity v(0) in the velocity sequence is calculated as follows: v(0) = max(v current ,v min ); The calculation method for non-first velocities v(k+1) in a velocity sequence is, for example: v(k+1) = max(v min , v(k)+ a des Ts); The first path mileage s(0) in the path mileage sequence is calculated, for example, as: s(0) = s current ; The calculation method for the non-first path mileage s(k+1) in the path mileage sequence is, for example: s(k+1) = s(k) + Ts v(k); Among them, v current This refers to the vehicle's current speed, v min This refers to the set minimum vehicle speed; s current Ts refers to the path mileage of the vehicle's current location, Ts refers to the prediction step time, and k is a natural number.

[0248] Understandably, the above calculation method allows the controller to inherently include a deceleration intention when taking over a risk, while retaining the ability to anticipate information such as the curvature, boundaries, and slope of the future path.

[0249] Step S703: Based on the second optimization objective associated with the slave controller, a second control command sequence is generated and output according to the speed sequence, path mileage sequence, road boundary information of the vehicle's travel route, and planned trajectory.

[0250] The second optimization objective focuses on local dynamic safety (such as preventing skidding, preventing loss of control, and preventing the vehicle from crossing the road boundary). For example, the second optimization objective could be: to achieve safe deceleration or braking while maintaining the dynamic stability of the vehicle body.

[0251] Among these, road boundary information refers to the left and right boundary data of the current driving lane or drivable area perceived by the vehicle's relevant perception modules. This includes, but is not limited to, lane line positions, curbs, guardrails, obstacle edges, or road geometric constraint information provided by high-precision maps. The aforementioned perception modules include, but are not limited to, sensor systems such as cameras, millimeter-wave radar, lidar, and high-precision positioning.

[0252] In this embodiment of the disclosure, the slave controller can generate and output a second control command sequence based on its own second optimization objective, according to the speed sequence, path mileage sequence, road boundary information of the vehicle's travel path, and planned trajectory. For example, the slave controller can generate and output a second control command sequence based on its own second optimization objective, by comprehensively considering the speed sequence, path mileage sequence, current state information, vehicle parameters, road boundary information of the vehicle's travel path, and planned trajectory.

[0253] The vehicle control method of this disclosure, when the vehicle meets the set first abnormal triggering condition, the slave controller dynamically calculates the expected deceleration based on the vehicle's current speed and yaw rate, and generates a speed sequence and path mileage sequence in the future prediction time domain based on forward extrapolation. Then, it generates a second control command sequence by combining the road boundary information and planned trajectory of the vehicle's driving road. This can realize the construction of a lightweight and highly reliable control benchmark with safe deceleration, path maintenance and boundary avoidance as the core objectives in abnormal or emergency scenarios. It significantly improves the system's response speed, real-time performance, control continuity and autonomous backup capability in emergency situations, and effectively suppresses the risk of overstepping boundaries, skidding or loss of control caused by control loss or inaccurate commands.

[0254] As one possible implementation method, Figure 8 This is a flowchart illustrating another vehicle control method provided as an exemplary embodiment of the present disclosure. It should be noted that this vehicle control method can be executed alone, or it can be executed together with any embodiment of the present disclosure or any possible implementation thereof, or it can be executed together with any technical solution in related technologies. The embodiments of the present disclosure do not impose any limitations on this.

[0255] like Figure 8 As shown, based on any embodiment of this disclosure, the controller can output a second control command sequence using the following steps S801 to S805: Step S801: In response to the vehicle meeting the set first abnormal triggering condition, the desired deceleration of the vehicle is determined based on the vehicle speed and yaw rate in the vehicle's current state information.

[0256] Step S802: Determine the speed sequence and path mileage sequence in the future prediction time domain based on vehicle speed, expected deceleration and prediction step time.

[0257] It should be noted that the explanations of steps S801 to S802 can be found in the relevant descriptions in any embodiment of this disclosure, and will not be repeated here.

[0258] Step S803: Based on the speed sequence, path mileage sequence, road boundary information, and planned trajectory, determine the second objective cost function corresponding to the second optimization objective; wherein, the second objective cost function uses the second state variable and the second control variable as decision variables.

[0259] The second state variable refers to a physical quantity used to describe the vehicle's motion state in the future prediction time domain. It reflects the vehicle's current and short-term future dynamic behavior, including but not limited to at least one of the following: lateral error e y Heading error Vehicle side slip angle yaw rate Steering wheel angle Steering wheel angular velocity Among them, the vehicle slip angle includes the front wheel slip angle and the rear wheel slip angle, etc.

[0260] The second control variable refers to the amount of execution instructions that the controller can actively adjust during the optimization process, used to drive the vehicle to evolve towards the desired state, including but not limited to the target steering wheel angle. .

[0261] Understandably, optimizing the controller's variables, including lateral error, heading error, sideslip angle, yaw rate, steering wheel angle, steering wheel angular velocity, and target steering wheel angle, instead of simultaneously optimizing longitudinal forces (such as total longitudinal force, front axle longitudinal force, rear axle longitudinal force, front axle longitudinal force ratio, and rear axle longitudinal force ratio), can reduce the optimization scale and improve the real-time performance of risk takeover.

[0262] The second state variable is associated with the second control variable through a lateral dynamics model. This lateral dynamics model indicates the nonlinear mapping between the tire lateral force response and the vehicle yaw motion state, such as front / rear wheel slip angle → lateral force → yaw moment → rate of change of each state variable. For example, the lateral dynamics model can use a reference speed as a known parameter to calculate the front / rear wheel slip angle, front / rear wheel lateral force, resultant lateral force, yaw moment, and the rate of change of lateral error, heading error, slip angle, yaw rate, and steering actuator state with respect to path distance.

[0263] In this embodiment of the disclosure, the slave controller can integrate its own second optimization objective, speed sequence, path mileage sequence, road boundary information, and planned trajectory to determine the second objective cost function corresponding to the second optimization objective. For example, the slave controller can integrate its own second optimization objective, speed sequence, path mileage sequence, current state information, vehicle parameters, road boundary information of the vehicle's travel path, and planned trajectory to determine the second objective cost function corresponding to the second optimization objective.

[0264] In any embodiment of this disclosure, the second objective cost function may be determined according to at least one of the following cost functions: The first term is the lateral error and heading error tracking cost function, which is determined based on the lateral error and heading error in the second state variables. For example, the lateral error and heading error tracking cost function can employ a nonlinear quadratic penalty with a critical threshold to increase the weight of the regression trajectory under large error conditions.

[0265] The second term is the boundary cost function, which is determined based on the lateral error and error boundaries in the second state variable. For example, the boundary cost function is used to increase the penalty through a smoothing function when the lateral error exceeds the left and right error boundaries, thus causing the optimized trajectory to move away from the road boundaries.

[0266] The third term is the front and rear wheel slip cost function, which is determined based on the front and rear wheel slip angles in the second state variables. For example, the front and rear wheel slip cost function is used to suppress excessive vehicle slip angles (or tire slip angles) and improve stability during low-risk takeover processes.

[0267] The fourth item is the phase plane stable region cost function, which is determined based on the deviations between the yaw rate, front wheel sideslip angle, and rear wheel sideslip angle in the second state variables and the phase plane stable region.

[0268] The determination of the phase-plane stable region includes any of the following methods: determining the phase-plane stable region based on the vehicle's maximum lateral acceleration and the rear wheel's limiting sideslip angle; determining the phase-plane stable region based on the vehicle's sideslip angle and yaw rate; or determining the phase-plane stable region based on the vehicle's lateral acceleration and yaw rate. For example, the phase-plane stable region cost function is used to penalize excessive yaw rate and excessive combined sideslip angle.

[0269] For example, the cost function of the stable region of the phase plane It can be calculated in the following way: (2) in, This refers to the maximum yaw rate, where, , This refers to the maximum lateral acceleration; 1 refers to the rear wheel limit slip angle, which represents the maximum slip angle that the tire can withstand under the adhesion limit; Lr refers to the distance from the vehicle's center of gravity to the rear axle, which is one of the vehicle parameters used to describe the influence of the front and rear axle distribution on yaw motion; softplus refers to the soft positive function.

[0270] The fifth item, the steering smoothness cost function, is determined based on the steering wheel angle and steering wheel angular velocity in the second control variables, as well as the changes in steering wheel commands between adjacent sampling points in the future prediction time domain, and the changes in steering wheel commands between the current control cycle (or the current frame) and the previous control cycle (or the previous frame).

[0271] In summary, by constructing the second objective cost function as a weighted combination of multiple dimensions, including lateral error / heading error tracking, road boundary constraints, front and rear wheel slip angle limits, phase plane stability region deviation, and steering smoothness, the slave controller can still generate safe control commands that take into account trajectory keeping, vehicle dynamic stability, and execution comfort, even when relying only on limited state information such as vehicle speed and yaw rate. Among these features, the lateral and heading error tracking cost functions ensure the vehicle stays as close as possible to the planned trajectory; the boundary cost function actively suppresses the risk of the vehicle approaching or exceeding the road boundary; the front and rear wheel yaw cost functions explicitly constrain the tire operating point away from the adhesion limit, preventing instability caused by excessive yaw; the introduction of a phase plane stability region cost function based on yaw rate, front / rear wheel yaw angle, or lateral acceleration allows the slave controller to directly assess whether the vehicle state is in the theoretical phase plane stability region and actively drive the system back to the stability region during optimization, thereby effectively preventing nonlinear instability phenomena such as fishtailing and oversteering in high-risk scenarios such as cornering deceleration and emergency obstacle avoidance; and the steering smoothness cost function, through joint penalties on steering wheel angle, speed, and their temporal rate of change, significantly suppresses high-frequency jitter and step jumps in control commands, improving ride comfort and reducing actuator wear. Thus, the slave controller not only possesses strong robust safety fallback capabilities but also maintains high control quality under abnormal operating conditions.

[0272] Step S804: Under the constraints of the transverse dynamics model, calculate the second control variable that can satisfy the second optimization objective indicated by the second objective cost function in the future prediction time domain, and obtain the predicted value of the second control variable.

[0273] In this embodiment of the disclosure, the second objective cost function can be solved based on the transverse dynamics model to obtain the predicted value of the second control variable in the future prediction time domain.

[0274] Step S805: Generate and output the second control command sequence for the current control cycle based on the predicted value of the second control variable.

[0275] In this embodiment of the disclosure, the controller can generate a second control command sequence based on the predicted value of the second control variable, that is, the control quantity in the second control command sequence is generated based on the predicted value of the second control variable.

[0276] The vehicle control method of this disclosure constructs a second objective cost function constrained by a lateral dynamics model and couples and optimizes the second state variable and the second control variable through a nonlinear mapping relationship between tire lateral force and yaw motion. This enables the controller to achieve fine-grained control of the vehicle's lateral stability under limited information conditions. Compared with methods based on linear bicycle models or open-loop braking strategies in related technologies, this nonlinear optimization framework can more realistically reflect the tire's response characteristics in the extreme adhesion region. In scenarios such as cornering deceleration, obstacle avoidance, or low-adhesion road surfaces, it generates control commands that take into account road boundary constraints, trajectory feasibility, and yaw stability, thereby maximizing vehicle controllability while ensuring safety.

[0277] As one possible implementation method, Figure 9 This is a schematic flowchart illustrating another vehicle control method provided as an exemplary embodiment of the present disclosure. It should be noted that this vehicle control method can be executed alone, or it can be executed together with any embodiment of the present disclosure or possible implementations thereof, or it can be executed together with any technical solution in related technologies. The embodiments of the present disclosure do not impose any limitations on this.

[0278] like Figure 9 As shown, based on any embodiment of this disclosure, the controller can output a second control command sequence using the following steps S901 to S908: Step S901: In response to the vehicle meeting the set first abnormal triggering condition, the desired deceleration of the vehicle is determined based on the vehicle speed and yaw rate in the vehicle's current state information.

[0279] Step S902: Determine the speed sequence and path mileage sequence in the future prediction time domain based on vehicle speed, expected deceleration and prediction step time.

[0280] Step S903: Based on the speed sequence, path mileage sequence, road boundary information, and planned trajectory, determine the second objective cost function corresponding to the second optimization objective; wherein, the second objective cost function uses the second state variable and the second control variable as decision variables.

[0281] The second state variable is associated with the second control variable through a lateral dynamics model; the lateral dynamics model is used to indicate the nonlinear mapping relationship between the tire lateral force response and the vehicle yaw motion state.

[0282] Step S904: Under the constraints of the transverse dynamics model, calculate the second control variable that can satisfy the second optimization objective indicated by the second objective cost function in the future prediction time domain.

[0283] In this embodiment of the disclosure, the controller can solve the second objective cost function based on the transverse dynamics model. If the solution is successful, step S905 can be executed; if the solution fails, step S906 can be executed.

[0284] It should be noted that steps S905 and S906 are two parallel possible implementations, and either one can be selected for execution.

[0285] Step S905: Based on the predicted value of the determined second control variable, generate and output the second control command sequence for the current control cycle.

[0286] It should be noted that the explanation of steps S901 to S905 can be found in the relevant description in any embodiment of this disclosure, and will not be repeated here.

[0287] In step S906, in response to the absence of a predicted value that satisfies the second optimization objective, it is determined whether the number of consecutive abnormal outputs from the controller has not exceeded the number threshold. If yes, step S907 is executed; otherwise, step S908 is executed.

[0288] Among them, the output anomalies from the controller include, but are not limited to: failure to solve the second objective cost function, anomalies in the control command sequence output from the controller, and exceeding the limit of the trajectory offset solved by the controller; among them, anomalies in the control command sequence include: the presence of null values ​​or outlier values ​​in the control command sequence.

[0289] The trajectory offset exceeding the limit obtained from the controller means that: based on the predicted value of the second state variable obtained from solving the second objective cost function, a predicted trajectory is generated, and the trajectory offset between the predicted trajectory and the planned trajectory is determined, and the trajectory offset is greater than or equal to the offset threshold.

[0290] It should be noted that steps S907 and S908 are two parallel possible implementations, and either one can be selected for execution.

[0291] Step S907: Output the second control command sequence of the previous control cycle.

[0292] In this embodiment of the disclosure, if there is no predicted value that satisfies the second optimization objective (i.e., the second objective cost function fails to be solved), it can be determined whether the number of consecutive abnormal outputs from the controller has not exceeded the set number threshold. If so, the controller can output the second control command sequence of the previous control cycle (i.e., the previous frame).

[0293] Step S908 sets the health state of the controller to error; wherein the health state of the controller is used as input for command arbitration.

[0294] In this embodiment of the disclosure, if there is no predicted value that satisfies the second optimization objective (i.e., the second objective cost function fails to be solved), it can be determined whether the number of consecutive abnormal outputs from the controller has not exceeded the set number threshold. If not, i.e., the number of consecutive abnormal outputs from the controller exceeds the number threshold, the health status of the controller is set to error. The health status of the controller is used as the input for command arbitration.

[0295] In summary, if the slave controller fails to find a feasible solution that satisfies the second optimization objective, and the number of consecutive abnormal outputs by the slave controller exceeds a set threshold, its health status is set to error. This health status is then used as a key input for command arbitration, enabling the command arbitration side to switch to the third control command sequence in a timely manner, thus preventing the system from falling into an uncontrolled state when both the master and slave controllers fail.

[0296] It should be noted that in controlled driving scenarios such as closed tracks, there are fewer disturbances or traffic participants in the driving environment, and additional safety monitoring measures (such as remote emergency stop and fence protection) are usually provided. The system can allow brief output anomalies while ensuring overall safety, maintaining vehicle stability through a sequence of control commands from historical control cycles. Only when there are multiple consecutive output anomalies is the system considered to have failed, and the health state of the slave controller is set to error. This avoids unnecessary control switching due to instantaneous numerical disturbances and improves the continuity of the driving process. Therefore, in one embodiment of this disclosure, steps S907 and S908 can be executed in controlled driving scenarios such as closed tracks. However, in non-closed road driving scenarios (such as public roads, urban roads, or highways), due to the complex vehicle operating environment, diverse traffic participants, and higher safety risks, the control system needs to have the highest level of response determinism and fault sensitivity. Any output anomaly from the slave controller may jeopardize driving safety; therefore, its health state can be directly set to error instead of using a fault-tolerance strategy based on the accumulation of consecutive anomalies.

[0297] The vehicle control method of this disclosure, when the controller fails to find a feasible solution that satisfies the second optimization objective, if the number of consecutive abnormal outputs from the controller does not exceed a set threshold, then the valid second control command sequence of the previous control cycle is used. This effectively suppresses the interruption or jump of control commands caused by the failure of instantaneous numerical solution, ensures the continuity and smoothness of the controller output, avoids unnecessary vehicle dynamic disturbances caused by brief calculation abnormalities in emergency conditions, and enhances the robustness and reliability of the safety redundancy system.

[0298] As one possible implementation method, Figure 10This is a schematic flowchart illustrating another vehicle control method provided as an exemplary embodiment of the present disclosure. It should be noted that this vehicle control method can be executed alone, or it can be executed together with any embodiment of the present disclosure or any possible implementation thereof, or it can be executed together with any technical solution in related technologies. The embodiments of the present disclosure do not impose any limitations on this.

[0299] like Figure 10 As shown, based on any embodiment of this disclosure, the controller can output a second control command sequence by performing the following steps S1001 to S1006: Step S1001: In response to the vehicle meeting the set first abnormal triggering condition, the desired deceleration of the vehicle is determined based on the vehicle speed and yaw rate in the vehicle's current state information.

[0300] Step S1002: Determine the speed sequence and path mileage sequence in the future prediction time domain based on vehicle speed, expected deceleration and prediction step time.

[0301] Step S1003: Based on the speed sequence, path mileage sequence, road boundary information, and planned trajectory, determine the second objective cost function corresponding to the second optimization objective; wherein, the second objective cost function uses the second state variable and the second control variable as decision variables, and the second control variable includes the steering wheel target angle.

[0302] The second state variable is associated with the second control variable through a lateral dynamics model; the lateral dynamics model is used to indicate the nonlinear mapping relationship between the tire lateral force response and the vehicle yaw motion state.

[0303] Step S1004: Under the constraints of the transverse dynamics model, calculate the second control variable that can satisfy the second optimization objective indicated by the second objective cost function in the future prediction time domain, and obtain the predicted value of the second control variable.

[0304] It should be noted that the explanation of steps S1001 to S1004 can be found in the relevant description in any embodiment of this disclosure, and will not be repeated here.

[0305] Step S1005: Determine the total longitudinal force of the vehicle based on the desired deceleration and the vehicle model in the vehicle parameters.

[0306] The vehicle model includes parameters such as vehicle mass (i.e., vehicle weight, hereinafter referred to as vehicle mass), wheelbase, moment of inertia, and tire lateral stiffness.

[0307] In this embodiment of the disclosure, the controller can estimate the total longitudinal force of the vehicle based on the vehicle's desired deceleration and the vehicle model in the vehicle parameters.

[0308] As one possible implementation, the controller can determine the vehicle's desired total braking torque based on the vehicle's current speed v, desired deceleration Ax, and vehicle mass in the vehicle model, and convert the total braking torque into total longitudinal force based on the conversion relationship between torque and force.

[0309] For example, the total braking torque can be calculated from the controller using the following formula: (3) in, Rw is the amplitude of the total braking torque, m is the tire rolling radius, and m is the vehicle's curb weight (referred to as vehicle mass in this disclosure). rho1, rho2, and rho3 are the fitting coefficients of the skid resistance model, where rho1 corresponds to rolling resistance, rho2 corresponds to the first-order term of wind resistance, and rho3 corresponds to the second-order term of wind resistance. Overall, rho1 represents the skid resistance at the vehicle speed. This represents the final total braking torque; where the total braking torque can be negative.

[0310] Step S1006: Generate the second control command sequence for the current control cycle based on the predicted value of the second control variable and the total longitudinal force.

[0311] In this embodiment of the disclosure, the controller can generate a second control command sequence based on the predicted value of the second control variable (i.e., the target steering wheel angle) and the total longitudinal force.

[0312] The vehicle control method of this disclosure significantly reduces the decision variable dimension and solution complexity of the optimization problem by limiting the second control variable to only the target steering wheel angle, and no longer jointly optimizing longitudinal control variables such as total longitudinal force and torque distribution between the front and rear axles. Based on this, the required total longitudinal force is directly calculated analytically based on the determined desired deceleration and vehicle model, and the analytical result is fused with the predicted value of the optimized target steering wheel angle to generate the second control command sequence of the current control cycle. This achieves a decoupled and coordinated mechanism of high-precision optimization of lateral control and rapid analysis of longitudinal control. On the one hand, it retains the ability to optimize the steering wheel angle, ensuring that path tracking and yaw stability can still be actively controlled in emergency scenarios. On the other hand, it avoids time-consuming iterative solutions to nonlinear longitudinal distribution problems in time-sensitive risk takeover processes, greatly shortens the generation delay of control commands, and improves the real-time response of the system. It meets the requirements of safe deceleration while maintaining the necessary lateral guidance capability, effectively balancing computational efficiency, control performance, and functional safety, and providing a highly reliable, low-latency, safe, redundant execution path for intelligent driving systems.

[0313] As one possible implementation method, Figure 11This is a flowchart illustrating another vehicle control method provided as an exemplary embodiment of the present disclosure. It should be noted that this vehicle control method can be executed alone, or it can be executed together with any embodiment of the present disclosure or any possible implementation thereof, or it can be executed together with any technical solution in related technologies. The embodiments of the present disclosure do not impose any limitations on this.

[0314] like Figure 11 As shown, based on any embodiment of this disclosure, the third control command sequence can be generated by the fallback controller using the following steps S1101 to S1104: Step S1101: In response to the vehicle meeting the set second abnormal triggering condition, determine the vehicle's desired total braking torque based on the vehicle speed, yaw rate, and vehicle mass.

[0315] The second abnormal triggering condition is a pre-set abnormal condition that may trigger the vehicle to enter the risk control state. For example, the second abnormal triggering condition includes, but is not limited to, at least one of the following: abnormal output from the main controller, abnormal output from the slave controller, abnormal vehicle planning module, or the vehicle being in the minimum risk control (MRA) state. The planning module is used to output the planned trajectory.

[0316] The method for determining the MRA state is, for example, as follows: obtaining a threshold parameter corresponding to the path mileage of the vehicle's current driving location, and performing anomaly detection on the vehicle's current state information based on the threshold parameter to determine the number of times at least one anomaly type is detected. Therefore, based on the number of anomalies for each anomaly type, it can be determined whether the vehicle is in an MRA state. The implementation principle can be found in the relevant descriptions in the above embodiments, and will not be repeated here.

[0317] In summary, by explicitly defining the second abnormal trigger condition as including risky situations such as abnormal output of the main controller, abnormal output of the slave controller, the vehicle being in MRA state, and abnormal planning module, it can be ensured that the fallback controller can be activated in a timely manner under abnormal conditions that require the most safety intervention, providing lateral stability protection and emergency deceleration and stopping capability for the vehicle, and significantly improving the robustness of the vehicle control system and driving safety.

[0318] In this embodiment of the disclosure, when the vehicle meets the set second abnormal triggering condition, the bottom-line controller can determine the vehicle's desired total braking torque based on the vehicle's current speed, yaw rate, and vehicle mass.

[0319] In any embodiment of this disclosure, the total braking torque is determined, for example, by the following method: The underbody controller first determines the actual lateral acceleration of the vehicle based on the vehicle speed and yaw rate, and then determines the desired longitudinal deceleration of the vehicle based on the lateral acceleration, the maximum permissible lateral acceleration, and the maximum longitudinal acceleration. For example, longitudinal control is performed based on a rhomboid constraint of lateral and longitudinal friction, wherein the formula for calculating the desired longitudinal deceleration is as shown in formula (1) above. Then, the desired total braking torque of the vehicle is determined based on the longitudinal deceleration, vehicle mass, and vehicle speed. For example, the underbody controller can use formula (3) above to calculate the total braking torque.

[0320] In summary, the actual lateral acceleration of the vehicle is derived based on its speed and yaw rate. Then, the desired longitudinal deceleration is obtained by combining this with the maximum permissible lateral / longitudinal acceleration. Finally, based on this longitudinal deceleration, vehicle mass, and speed, the total braking torque is calculated. This allows for dynamic matching of the total braking force under friction limit constraints. This ensures sufficient deceleration to meet emergency braking requirements without causing sideslip or loss of control due to the total braking torque exceeding the tire adhesion limit. The total braking torque requirement is always generated in accordance with the vehicle's current stability boundary, thus satisfying the vehicle control objective of ensuring braking stability within the friction limit.

[0321] Step S1102: Determine the vehicle motor torque and the hydraulic braking torque of the braking control system based on the total braking torque.

[0322] In this embodiment of the disclosure, the bottom-line controller can distribute the total braking torque to obtain the vehicle motor torque and the hydraulic braking torque of the braking control system.

[0323] For example, the underbody controller can use the following formula to calculate the vehicle motor torque and hydraulic braking torque: (4) in, This refers to the torque of the vehicle's motor. For hydraulic braking torque, the clamp is used to limit the torque to [T]. min The range of values ​​for [Nm, 0Nm]; T min It means The minimum torque value, which takes a negative value. It should be noted that this disclosure refers to T... min The specific value is not limited and can be configured based on actual application needs. The minimum torque value.

[0324] Step S1103: Determine the target steering wheel angle based on the angular error between the yaw speed and the desired yaw speed.

[0325] The desired yaw rate is a pre-set, relatively small yaw rate; for example, the desired yaw rate is 0.

[0326] In this embodiment of the disclosure, the bottom-up controller can determine the target steering wheel angle by combining the angular error between the yaw rate and the set desired yaw rate.

[0327] In any embodiment of this disclosure, the method for determining the target steering wheel angle is, for example, as follows: the bottom-up controller can determine the open-loop transfer function from the steering wheel angle to the yaw rate; wherein, the open-loop transfer function is used to indicate the transfer relationship between the steering wheel angle and the yaw rate; based on the open-loop transfer function, an adjustment controller and corresponding adjustment parameters are determined; wherein, the adjustment controller is used to establish a mapping relationship between the angle error between the yaw rate and the desired yaw rate and the target steering wheel angle; based on the angle error between the actual yaw rate of the vehicle and the desired yaw rate, as well as the adjustment controller and adjustment parameters, the target steering wheel angle is determined. The adjustment controller includes, but is not limited to, a proportional-integral (PI) controller and a proportional-integral-derivative (PID) controller. Taking a PI controller as an example, the adjustment parameters include proportional gain and integral gain.

[0328] As an example, taking a PI controller as the regulating controller, the fallback controller can calculate the target steering wheel angle in the following way: The lateral control objective of the overriding controller is not to continue tracking the planned trajectory, but to stabilize the yaw rate during forced movement. The overriding controller can employ the following steady-state model of the front wheel turning to yaw rate with an understeer coefficient: (5) Where y is the yaw rate of the vehicle. denoted as front wheel steering angle; K(v) is the steady-state gain, which is related to vehicle speed v; L is the vehicle wheelbase; and Kc is the understeer coefficient, which characterizes the vehicle's steering characteristics.

[0329] Considering the hysteresis of the Electric Power Steering (EPS) system, the EPS actuator can be modeled using the following formula: (6) Formula (6) models the steering wheel angle to the front wheel angle as a first-order inertial element. , These are the Laplace transforms of the front wheel angle and the steering wheel angle, respectively. The set scaling factor; The inertial time constant of EPS represents the hysteresis characteristics of the actuator, and the model is approximated as a first-order inertial element.

[0330] In this disclosure, the open-loop transfer function from steering wheel angle to yaw rate can be generated by combining formulas (5) and (6): (7) Subsequently, based on the internal model control method shown in formula (8), the controller shown in formula (8) can be equivalent to the PI controller shown in formula (9) below: (8) (9) Where C(s) is the controller transfer function, Kp is the proportional gain, Ki is the integral gain, and Ti is the integral time constant. Let F(s) be the time constant of the low-pass filter in the internal model controller, used to adjust the controller's response speed. Further: K(v) is truncated to [v...] based on the vehicle speed. min ,v max Within the corresponding reasonable available range, avoid abnormal gain.

[0331] Assuming the desired yaw rate of the fallback controller is 0, then the angle error is: The steering wheel command can consist of a proportional term and an integral term. Through speed-related steering wheel angle constraints, steering wheel angular velocity constraints, integral decay, and anti-windup mechanisms, the target steering wheel angle in the steering wheel command can be obtained.

[0332] In this disclosure, the yaw rate stability control based on the internal model control equivalent PI and the integral anti-saturation mechanism can be used to construct a closed-loop error with a target of zero based on the chassis yaw rate. The target steering angle is generated by the equivalent PI controller, and the steering wheel command is limited by the vehicle speed related constraints, integral decay and integral anti-saturation mechanism to improve the lateral stability during forced movement.

[0333] In summary, a control controller was designed based on the open-loop transfer function from steering wheel angle to yaw rate. Then, a strategy was developed to solve for the target steering wheel angle through the yaw rate error. This established a precise mapping relationship for closed-loop stabilization of yaw rate. The steering angle can be corrected in real time for the angular deviation between the actual yaw rate and the desired yaw rate. Compared with open-loop adjustment with fixed parameters, the response is more accurate and the anti-disturbance capability is stronger. It can effectively suppress yaw disturbances caused by load transfer and changes in road surface adhesion during forced deceleration, and prevent the vehicle from skidding and losing control.

[0334] Step S1104: Generate a third control command sequence based on the target steering wheel angle, vehicle motor torque, and hydraulic braking torque.

[0335] As one possible implementation, the fallback controller can directly generate a third control command sequence based on the target steering wheel angle, vehicle motor torque, and hydraulic braking torque. That is, the third control command sequence only contains the three control quantities: the target steering wheel angle, vehicle motor torque, and hydraulic braking torque.

[0336] As another possible implementation, the fallback controller can also indirectly generate a third control command sequence based on the target steering wheel angle, the vehicle motor torque, and the hydraulic braking torque. For example, the fallback controller can obtain a set front axle longitudinal force ratio and, based on this ratio, distribute the vehicle motor torque to obtain the front axle motor torque allocated to the front axle and the rear axle motor torque allocated to the rear axle. Thus, in this disclosure, a third control command sequence can be generated based on the target steering wheel angle, the front axle motor torque, the rear axle motor torque, and the hydraulic braking torque. Here, the front axle longitudinal force ratio is the ratio of the front axle longitudinal force to the total longitudinal force of the vehicle; the front axle motor torque equals the total vehicle motor torque. Front axle longitudinal force ratio; Rear axle motor torque = Total vehicle motor torque - Front axle motor torque.

[0337] Understandably, by introducing a strategy of proportionally distributing the longitudinal force of the front axle to the torque of the front / rear axle motors, the axle load matching distribution of braking torque can be achieved. Combined with the target steering wheel angle to generate a third control command sequence, the braking force distribution can be adapted to the current lateral motion state of the vehicle, making full use of the friction adhesion limits of each axle, avoiding the vehicle from sideslipping and becoming unstable due to a single axle reaching its friction limit first. At the same time, the steering adjustment and braking distribution can work together to better stabilize the yaw rate during forced braking with large deceleration, thereby enhancing the lateral stability of the braking process.

[0338] The vehicle control method of this disclosure determines the desired total braking torque of the vehicle based on the vehicle speed, yaw rate, and vehicle mass when the vehicle meets the set second abnormal triggering condition. The total braking torque is then broken down into the vehicle motor torque and hydraulic braking torque. The target steering angle is obtained based on the yaw rate error, and a third control command sequence is generated accordingly. This enables coordinated control of vehicle power and steering under emergency abnormal conditions, ensuring sufficient deceleration capability while reserving adjustment space for yaw stability control in advance. It avoids saturation or insufficient response of a single control source, ensuring the feasibility of vehicle control under abnormal conditions.

[0339] In any embodiment of this disclosure, nonlinear model predictive control (NMPC) and minimum risk action (MRA) can be used in conjunction in intelligent driving or track driving scenarios to achieve high-dynamic trajectory tracking, actuator delay compensation, vehicle stability constraints, and risk takeover in abnormal states. Under normal conditions, the main controller (hereinafter referred to as the NMPC controller) generates a control command sequence that considers lateral and longitudinal dynamics, tire constraints, and actuator constraints. However, in cases of main controller malfunction, planning anomaly, tracking error anomaly, boundary anomaly, or communication anomaly, the slave controller (hereinafter referred to as the MRA controller or MRA2 controller) generates a low-risk control command sequence aimed at deceleration and lateral stability, and the final control command sequence is selected through arbitration logic. This disclosure addresses at least the following technical problems: improving the tracking accuracy of high-dynamic trajectories; compensating for actuator and communication delays; maintaining vehicle stability under conditions of tire nonlinearity, slope, lateral gradient, and longitudinal-lateral coupling; quickly entering a low-risk trajectory in abnormal states; avoiding direct loss of control when the main and slave controllers output abnormalities; and reducing the computational complexity of the slave controller.

[0340] For example, the vehicle control scheme provided in this disclosure mainly includes the following steps: 1. Obtain the vehicle's current status information, historical control commands, planned trajectory, vehicle type, and the enabling, planning, and functional status of intelligent driving functions.

[0341] 2. Select the corresponding vehicle parameters according to the vehicle type, including but not limited to: wheelbase, center of gravity position, mass, moment of inertia, tire model parameters, steering ratio, steering actuator dynamic parameters, vehicle width, maximum power and tire adhesion parameters.

[0342] 3. Convert the vehicle pose from rear axle coordinates to centroid coordinates in the current state information, and project the vehicle's current state information onto the path coordinate system corresponding to the planned trajectory / reference trajectory to obtain the lateral error, heading error, speed, sideslip angle, yaw rate, turning angle and turning rate, etc.

[0343] 4. Based on the historical steering command, historical total longitudinal force command and historical front axle torque ratio command in the historical control commands, the vehicle state information after actuator delay (referred to as predicted state information in this disclosure) is predicted through a nonlinear dynamic model, and the predicted pose in the predicted state information is used to resample the reference trajectory.

[0344] 5. Under normal control conditions, the main controller constructs an NMPC optimization problem, taking lateral error, heading error, speed error, steering smoothness, longitudinal force smoothness, smoothness of the front / rear axle longitudinal force ratio, tire slip angle, road boundary intrusion, over-slip, lateral convergence speed, reference control input and aiming time as comprehensive costs, and using nonlinear dynamics model, steering rate, longitudinal force change rate, front axle longitudinal force ratio change rate, tire adhesion, vehicle motor power, front and rear axle motor power and front and rear axle maximum driving force as constraints, to solve the control command sequence in the future prediction time domain (referred to as the first control command sequence in this disclosure).

[0345] 6. In the risk takeover state, the MRA optimization problem is constructed by the slave controller, and the vehicle speed is rolled according to the desired deceleration and the spatial sampling sequence (referred to as the path mileage sequence in this disclosure). Only the lateral state and steering control commands are optimized, and boundary costs, tire side slip costs, phase plane stable region costs and steering comfort costs are added. The risk avoidance control sequence in the deceleration state is output (referred to as the second control command sequence in this disclosure).

[0346] 7. Based on the output status of the main controller, the output status of the slave controller, the planning status, the vehicle risk status, and whether the control command sequence has timed out, enter command arbitration and select the first control command sequence of NMPC, the second control command sequence of MRA2, or the fallback control command sequence of the fallback controller (or MRA3 controller) (referred to as the third control command sequence in this disclosure).

[0347] 8. If the optimization solution of the current frame is successful and the trajectory is not deviated, the control command sequence of the current frame solution is issued and saved as a hot start for the next frame; if the short-term solution is abnormal, the control command sequence available in the previous frame is issued; if the number of consecutive abnormalities exceeds the threshold, the error status is reported to trigger risk takeover or exit the vehicle's intelligent control function.

[0348] To achieve the above steps, the specific implementation principles of the master controller and slave controller will be explained in detail below.

[0349] I. Key Modules and Implementation Methods 1.1 Input State and Reference Trajectory Construction The main controller takes the vehicle's current state information (including measurement state, positioning state, and chassis state), the planned trajectory, and the control command sequence from the previous control cycle as input. Each trajectory point in the planned trajectory contains information such as path mileage, position, heading, longitudinal velocity, lateral velocity, curvature, yaw rate, tire angle, longitudinal acceleration, road boundary, slope, and cross slope. Optionally, some fields in the planned trajectory can be reused as slope or cross slope data, or uniformly represented as road topology information and dynamic reference information attached to the planned trajectory.

[0350] The main controller first selects the rear axle coordinates based on whether the vehicle is in simulation mode, or translates from the rear axle coordinates along the vehicle's heading to the center of mass coordinates. Then, it finds the perpendicular from the vehicle's center of mass to the reference curve in the planned trajectory, and uses the perpendicular distance as the starting point of the predicted trajectory. It then interpolates the planned trajectory to obtain the reference position, heading, speed, sideslip reference, curvature, slope, cross slope, boundary, reference steering, and longitudinal force of each sampling point in the future prediction time domain, which is referred to as the reference trajectory in this disclosure.

[0351] The lateral error is represented by the signed distance from the vehicle's center of mass to the foot of the reference trajectory, with its sign determined by the vehicle's position relative to the reference velocity direction. The heading error is represented by the wrap angle between the vehicle's velocity direction and the reference velocity direction, ensuring that the model still models errors in the vehicle's velocity direction even in scenarios with a reference yaw velocity.

[0352] 1.2 NMPC Controller The NMPC controller is used for normal or high-performance trajectory tracking scenarios. Its optimization variables include lateral error, heading error, speed, vehicle sideslip angle, yaw rate, steering wheel angle, and steering wheel angular velocity within the prediction interval, as well as control inputs such as the steering wheel target angle, the ratio of total longitudinal force to front axle longitudinal force. .in, This can represent the proportion of the total driving or braking longitudinal force distributed to the front axle, while the proportion of the longitudinal force to the rear axle is 1- .

[0353] The NMPC controller uses path mileage as the main discrete independent variable, and vehicle dynamics are discretized with respect to path distance. The prediction step size can be obtained by multiplying the vehicle speed by the prediction sampling time, or a fixed spatial step size can be used in specific modes. The step size can be adjusted after preset segments based on path mileage to take into account both high-speed long preview and fine control of special road sections.

[0354] 1.3 Cost Function and Constraints of NMPC Controller The objective cost function of NMPC consists of the following multiple cost functions: First, the state tracking cost function includes lateral error, heading error, velocity error, and optional front axle longitudinal force proportional tracking error. The lateral and heading errors can employ a quadratic cost with exponential modulation, giving different penalty characteristics to large and small error regions. The front axle longitudinal force proportional tracking error can guide braking or energy recovery scenarios. Approaching the desired braking distribution.

[0355] Secondly, the comfort cost function includes the rate of change of steering command between continuous control points, the rate of change of total longitudinal force, and the rate of change of the proportion of front axle longitudinal force, and can make the weight of the steering change rate change change vary with the fourth power of speed.

[0356] Third, the tire side slip cost function is used to suppress excessive front / rear wheel side slip angles.

[0357] Fourth, the road boundary intrusion cost function is used to increase the penalty when the lateral error exceeds the left and right boundaries.

[0358] Fifth, the over-slip cost function is used to add a penalty when the vehicle slip angle (or tire slip angle) exceeds the limit slip angle obtained from the tire model.

[0359] Sixth, the lateral convergence speed cost function is used to give the expected lateral convergence speed when the lateral error exceeds a threshold.

[0360] Seventh, reference steering and reference longitudinal force cost functions are used to reduce the deviation from the planned reference control quantities.

[0361] Eighth, the aiming time cost, used to encourage vehicles to cover the predicted distance in a shorter time in racing mode.

[0362] The constraints of NMPC include: initial state constraints, equality constraints of the nonlinear dynamic model based on trapezoidal integrals, rate of change constraints of the target steering angle, rate of change constraints of total longitudinal force, rate of change constraints of the longitudinal force ratio of the front axle, constraints that the longitudinal forces of the front and rear wheels do not exceed the tire adhesion capacity, constraints that the product of total longitudinal force and speed does not exceed the vehicle motor power, constraints that the product of the longitudinal forces of the front and rear axles and speeds does not exceed the corresponding axle motor power, and constraints that the driving forces of the front and rear axles do not exceed the corresponding axle maximum driving force.

[0363] 1.4 Optimization of front and rear axle torque distribution In a preferred embodiment, the NMPC controller proportionalizes the front axle longitudinal force. It is incorporated into the optimization problem as an independent control input.

[0364] The NMPC controller calculates the front axle longitudinal force ratio of the previous control cycle based on the current or historical front and rear motor torques, and uses this ratio as a reference for the rate of change constraint and comfort cost function of the first optimization point. If historical control commands are available, the historical front axle longitudinal force ratio also participates in actuator delay prediction. Therefore, the main controller outputs not only the total longitudinal force but also the front / rear axle longitudinal force ratio, enabling downstream actuators to send front axle torque ratio requests to the vehicle power control unit.

[0365] This torque distribution optimization can handle both driving and braking scenarios simultaneously. For any predicted point, the main controller will adjust the total longitudinal force F... L Distributed as longitudinal force to the front axle and rear axle longitudinal force Both are used for tire lateral force calculation, yaw moment calculation, adhesion constraints, motor power constraints, and single-axle maximum driving force constraints. For vehicles or modes that require maintaining a fixed front axle longitudinal force ratio, this can be configured to... The upper and lower limits are both set to the preset front axle longitudinal force ratio, thus being compatible with both fixed and variable distribution implementation methods.

[0366] 1.5 Mode Switching and Parameter Adaptation The NMPC controller supports multiple control modes (or driving modes), such as normal mode, special path mode, and racing mode. The main controller can select different weights and constraints based on motion markers in the planned trajectory, the path mileage of the vehicle's current position, or the configuration mode. When motion markers in the planned trajectory indicate that the vehicle has entered a special area, the main controller can switch to special path mode and change parameters such as lateral error, heading error, tire slip angle, and prediction step size. For low-speed and racing scenarios, the weights of lateral error, heading error, and terminal error (i.e., endpoint error) can be changed through speed interpolation to avoid the problem that a single weight cannot adequately balance stability and sensitivity across the entire speed domain.

[0367] 1.6 Actuator Delay Compensation and Reference Trajectory Resampling The controller stores a sequence of historical control commands, including steering wheel commands, total longitudinal force commands, and front axle longitudinal force proportional commands. It interpolates these commands based on their issuance time and the start time of the current frame to obtain a sequence of historical control commands corresponding to the delay time window. If delay prediction is enabled and the vehicle is in autonomous driving mode, the main controller inputs the current state information, each historical control command from the historical command sequence, and reference road topology information into the nonlinear dynamics model. It then integrates forward over a fixed sampling time to obtain the delayed-compensated predicted state information. After obtaining the predicted state information, the main controller back-calculates the predicted centroid pose based on the path mileage, lateral error, and heading error corresponding to the predicted state information, and reconstructs the reference trajectory using this predicted centroid pose as the new trajectory starting point. This ensures that the initial state of the optimization problem is more consistent with the actual activation time of the vehicle actuators, reducing tracking lag or oscillations caused by control delays.

[0368] 1.7 State Bias Estimation and Model Error Compensation To improve robustness in real-world driving, the main controller estimates lateral velocity offset, steering wheel zero-position offset, steering wheel angular velocity, and lateral error model offset. Steering wheel zero-position offset / steering wheel angular velocity offset estimation is activated when the reference yaw rate is low and the lateral error exceeds a threshold, and the offset values ​​are updated using exponential filtering to ultimately limit them within a preset range. Lateral velocity offset estimation is activated when each trajectory point in the reference trajectory is approximately straight, to reduce the impact of lateral velocity measurement errors on sideslip angle estimation. The lateral error model offset is used to correct for lateral error variations in the vehicle model, compensating for systematic errors between the actual vehicle and model predictions.

[0369] 1.8 Hot Start, Anomaly Counting, and Health Status Management After successful optimization, the main controller saves the optimized variables and the optimal control command sequence as initial values ​​for the next frame's warm-start. If the current frame's solution is successful and the trajectory does not deviate significantly, the current solution is published. If the current frame's solution fails but the main controller's consecutive anomaly count does not exceed a threshold, the optimal control command sequence from the previous frame is published, and the main controller's health status is set to warning. If the consecutive anomaly count exceeds the threshold, the main controller's health status is set to error, allowing the upper-level arbitration logic to switch risk takeover or fallback control. Trajectory deviation judgment can be achieved using a weighted sum of the absolute values ​​of the lateral errors within the prediction interval, with the threshold dynamically adjusted based on the current lateral error.

[0370] II. MRA Risk Takeover Control Plan 2.1 MRA Controller Positioning The MRA controller generates minimum risk control commands when the main controller output is abnormal, the vehicle tracking error is abnormal, the vehicle approaches or crosses the road boundary, the communication link is abnormal, the planning state is abnormal, or the vehicle is already in MRA state. Compared with the NMPC controller, the MRA controller reduces the optimization dimensionality. Instead of simultaneously optimizing longitudinal force, it generates a desired longitudinal deceleration (denoted as desired deceleration in this disclosure) based on vehicle speed, yaw rate, and configuration parameters, and uses this desired deceleration to roll out the speed and path sampling points within the prediction interval. The optimization variables of the MRA controller include lateral error, heading error, vehicle sideslip angle, yaw rate, steering wheel angle, steering wheel angular velocity, and target steering wheel angle.

[0371] 2.2. Velocity and Spatial Sampling Construction The MRA controller uses vehicle speed v and yaw rate as the basis. And the configuration model calculates the expected deceleration a des For example, |v The desired deceleration is obtained by using a linear model and upper / lower bounds as input for risk intensity. Then, the velocity and path mileage are recursively calculated over a prediction step time Ts.

[0372] 2.3 Cost Function of MRA Controller The cost function of the MRA controller includes the following components: a lateral error and heading error tracking cost function, employing a nonlinear quadratic penalty with a critical threshold to increase the weight of the regression trajectory under large error conditions; a boundary cost function, which increases the penalty through a smoothing function when the lateral error exceeds the left and right boundaries, causing the optimized trajectory to move away from the road boundaries; a front and rear wheel sideslip cost function, which suppresses excessive tire sideslip angles and improves stability during low-risk takeovers; and a phase plane stability region cost, constructed based on the maximum lateral acceleration and the rear wheel extreme sideslip angle. - In the stable region, penalties are imposed for exceeding limits on yaw rate and combined sideslip angle. The steering smoothness cost function constrains steering wheel command variations between adjacent sampling points and between the current frame, with weights varying with velocity.

[0373] 2.4 Vehicle Dynamics Model of MRA Controller The MRA controller employs a simplified but still nonlinear lateral dynamics model of tire lateral forces. This model uses a reference speed as a known parameter to calculate the front and rear wheel slip angles, front and rear wheel lateral forces, resultant lateral force, yaw moment, and the rates of change of lateral error, heading error, slip angle, yaw rate, and steering actuator state with respect to path distance. Since the MRA controller does not optimize longitudinal forces, the front and rear axle normal loads can be approximated by static axle loads, thereby reducing the optimization scale and improving the real-time performance of risk takeover.

[0374] 2.5 MRA Controller Output After solving the problem, the MRA controller converts the optimized lateral state and steering commands into global trajectory points, and estimates the longitudinal force based on the desired deceleration and road resistance. It then outputs a sequence of control commands including the target steering wheel angle, longitudinal acceleration, and total longitudinal force. If the solution fails, the controller re-issues the control command sequence from the previous frame's MRA controller if the number of consecutive anomalies does not exceed a threshold; otherwise, it reports an error status, and a more conservative fallback control takes over.

[0375] It should be noted that the above vehicle dynamics model can be replaced with other nonlinear tire models, brush tire models, or tire models with parameter identification; the optimization solver can be a real-time iterative solver or other solvers suitable for nonlinear programming; delay compensation can use Euler integrals, trapezoidal integrals, or fourth-order Runge-Kutta integrals; the torque distribution between the front and rear axles can represent the proportion of longitudinal force on the front axle, the proportion of longitudinal force on the rear axle, the longitudinal force on the front axle, the longitudinal force on the rear axle, or equivalent torque requests between the front and rear axles; constraints can also be replaced with motor current, inverter power, battery power, or thermal management limits depending on the vehicle architecture; the desired deceleration of the MRA controller can be determined by the vehicle's current speed, yaw rate, lateral error, road curvature, boundary distance, or a combination thereof; command arbitration can be extended to more controller levels, such as comfort takeover, forced braking takeover, and parking takeover; weights and thresholds can be determined through calibration tables, path mileage segmentation tables, speed interpolation tables, or online learning models.

[0376] III. MRA Status Determination and Control Command Arbitration This disclosure also includes an MRA status determination module and a control command arbitration module. Among them, The MRA status determination module determines whether to enter MRA2 or MRA3 state based on the global reference trajectory, the vehicle's current position, vehicle speed, lateral error, heading error, the previous frame's driving state, remote communication delay, MRA configuration thresholds, and the validity of commands output by the NMPC controller. The MRA status determination module can query threshold parameters corresponding to different road segments by path mileage, including remote communication timeout thresholds, lateral error thresholds, heading error thresholds, and boundary margin thresholds. Each anomaly type corresponds to an anomaly counter: the counter increments when the anomaly persists and decrements when the anomaly disappears; MRA is only triggered when the counter value reaches the configured corresponding threshold parameter, thus avoiding frequent switching caused by transient noise.

[0377] The control command arbitration module receives the first control command sequence output by the NMPC controller, the second control command sequence of MRA2, and the fallback control command sequence of MRA3, and checks whether the commands are empty, timed out, and whether the control status is abnormal. When the planning is abnormal, the system is in MRA3 state, or both NMPC and MRA2 are abnormal, MRA3 (fallback control command sequence) is selected first. When the system is in MRA2 state, or NMPC is abnormal (i.e., the main controller's health status is incorrect) while MRA2 is normal, MRA2 (the second control command sequence output from the controller) is selected. In other cases, NMPC (the first control command sequence output by the main controller) is selected. Its implementation principle is shown in Table 1. MRA3 (fallback control command sequence) is calculated in real-time based on the vehicle speed, chassis yaw rate, and current steering wheel angle fed back from the chassis CAN signal. Under the premise of no lateral instability, it outputs the maximum permissible total braking torque of the vehicle and decomposes it into the vehicle motor negative torque and hydraulic braking torque, putting the vehicle into a more conservative, low-risk state. In other words, the core objective of MRA3 is to distribute braking torque based on friction limit constraints during high deceleration braking, while simultaneously stabilizing yaw rate to prevent vehicle skidding and loss of control, thus ensuring the stability of the braking process.

[0378] Table 1 Command Arbitration Principles

[0379] IV. Exemplary Embodiments Example 1: Normal High Dynamic Trajectory Tracking The vehicle is in intelligent driving mode, and the planning module outputs a planned trajectory including waypoints, speed, curvature, gradient, cross slope, and road boundaries. The main controller loads vehicle parameters according to the vehicle type, converts the rear axle positioning into the center of mass pose, finds the foot of the planned trajectory, and interpolates to obtain the predicted trajectory. The main controller constructs an initial state based on the current lateral error, heading error, speed, sideslip angle, yaw rate, steering angle, and steering speed, estimates the steering wheel offset and lateral error model offset, and performs delay compensation based on historical control commands. Subsequently, the NMPC constructs an optimization problem including a nonlinear vehicle dynamics model, tire sideslip, front and rear axle torque distribution, steering actuator dynamics, steering command rate, longitudinal force change rate, front axle longitudinal force ratio change rate, tire adhesion, total vehicle motor power, single axle motor power, and single axle maximum driving force constraints, and solves it within a real-time solution time limit. If the solution is successful, the main controller outputs a control command sequence containing the target steering wheel angle, total longitudinal force, and front axle longitudinal force ratio for the predicted interval to the downstream execution module.

[0380] Example 2: Mode Switching for Special Road Sections When motion markers in the planned trajectory indicate that the vehicle is about to enter a special area, or when the path mileage of the vehicle's current position exceeds a preset boundary point, the main controller switches to NMPC mode. After switching, the main controller changes the weights of lateral error, heading error, tire slip angle, and prediction space step size, making the main controller prioritize vehicle stability or tracking accuracy in that road segment. If switching from the normal mode to the special path mode, the constraint on the rate of change of the first longitudinal force can also be tightened to avoid sudden changes in longitudinal force during mode switching.

[0381] Example 3: Variable front and rear axle torque distribution When a vehicle is accelerating through a curve, undergoing forced traction, or experiencing energy recovery, the available adhesion, motor power, and maximum driving force on the front and rear axles may differ. The main controller simultaneously calculates the total longitudinal force F at each prediction point. L Ratio of front axle longitudinal force And convert both to F Lf and F Lr If a certain front axle longitudinal force ratio results in a violation of front axle power, rear axle power, front axle drive force, rear axle drive force, or tire adhesion constraints, the optimizer will adjust... Or the total longitudinal force, ensuring the control command falls within the vehicle's capability boundaries. (The solution results...) The control output link is encoded as a front axle torque ratio request, thereby enabling the vehicle power control unit to perform front and rear axle torque distribution according to the optimized result.

[0382] Example 4: MRA2 takeover after main controller malfunction When an NMPC command times out, the control state is abnormal, the lateral or heading error continuously exceeds the segment threshold, the remote communication delay continuously exceeds the segment threshold, or the vehicle is determined to be out of boundary margin, the MRA state determination module triggers MRA2. The slave controller corresponding to MRA2 generates the desired deceleration based on vehicle speed and yaw state, and constructs speed and path sampling points within the prediction interval according to this desired deceleration. The slave controller solves for the control command sequence under deceleration risk avoidance, targeting lateral error, heading error, tire sideslip, phase plane stability region, and steering ride comfort. The arbitration module selects MRA2 output after confirming that the MRA2 command is normal.

[0383] Example 5: MRA3 fallback after planning failure or multiple controller malfunctions When the planning state is abnormal, or both NMPC and MRA2 outputs are abnormal, or the vehicle enters a higher-level minimum risk state, the arbitration module selects the MRA3 command. MRA3 no longer uses zero steering and pure fixed torque; instead, it uses a lightweight fallback controller to output lateral and longitudinal commands. The lateral command determines the target steering wheel angle based on the PI controller and the vehicle's yaw rate. The longitudinal command uses a fixed upper limit of the vehicle's motor torque and the remaining hydraulic braking torque. When the vehicle approaches a stop, it can still maintain the stop by combining existing EPB / P gear request logic.

[0384] In summary, the technical solution provided in this disclosure has at least the following beneficial effects: 1. By introducing nonlinear tire models, load transfer, gradient, lateral slope, longitudinal force distribution, tire adhesion, and motor power constraints into the NMPC, the feasibility of control commands in high-dynamic scenarios is improved. 2. By using the front axle longitudinal force ratio as an optimization variable, the total longitudinal force is dynamically allocated under the premise of satisfying the constraints of front and rear axle adhesion, motor power, and maximum driving force, improving the utilization rate of the front / rear axle capacity and reducing the risk of single-axle saturation. 3. By constraining the rate of change of the front axle longitudinal force ratio and the proportional smoothness cost, abrupt changes in front and rear axle torque distribution are avoided, improving the smoothness of drive and braking execution. 4. By predicting the state of the actuator after delay through historical control commands and resampling the reference trajectory based on the predicted pose, tracking lag and oscillation caused by control delay are reduced. 5. By switching the prediction step size, weight, and constraints according to vehicle speed, action identifiers in the planned trajectory, and path mileage, the main controller can adapt to conventional, high-performance, and special road segment scenarios. 6. Enhance robustness in real-vehicle deployment by estimating steering wheel offset, lateral velocity offset, and lateral error model offset. 7. Reduce computational complexity in risk takeover scenarios by pre-rolling longitudinal velocity according to the desired deceleration using the MRA controller and optimizing only lateral state and steering commands. 8. Enhance robustness in real-vehicle deployment by estimating boundary cost, lateral cost, and... - The phase plane stability region cost ensures that the vehicle maintains both road boundary and lateral stability during deceleration takeover. 9. By using anomaly counting, health status, retention of the previous frame's control command sequence, and multi-controller arbitration, the system avoids frequent control command switching caused by transient anomalies and improves its fallback capability.

[0385] To implement the above embodiments, this disclosure also proposes a vehicle control device. Figure 12 This is a schematic diagram of the structure of a vehicle control device provided for an exemplary embodiment of the present disclosure. Figure 12 As shown, the vehicle control device 1200 may include: a first acquisition module 1210, a second acquisition module 1220, an arbitration module 1230, and a control module 1240.

[0386] The system comprises: a first acquisition module 1210, used to acquire a first control command sequence output by the vehicle's main controller based on the planned trajectory, current status information, historical control commands, and vehicle parameters; a second acquisition module 1220, used to acquire a second control command sequence output by the vehicle's slave controller based on the vehicle speed and yaw rate in the current status information; an arbitration module 1230, used to arbitrate the first, second, and third control command sequences to obtain a target control command sequence; wherein the safety risk level of the vehicle driving according to the third control command sequence is lower than a preset risk threshold; and a control module 1240, used to control the vehicle's driving according to the target control command sequence.

[0387] In one implementation of this disclosure, the arbitration module 1230 is configured to: obtain a threshold parameter corresponding to the path mileage of the vehicle's current driving position; wherein the threshold parameter is associated with at least one anomaly type, and the threshold parameter includes at least one of the following: lateral error threshold, heading error threshold, communication timeout threshold, and boundary margin threshold; perform anomaly detection on the vehicle's current state information based on the threshold parameter to determine the risk control state of the vehicle; and arbitrate commands for the first control command sequence, the second control command sequence, and the third control command sequence based on the risk control state, the health status of the master controller, and the slave controller.

[0388] In one implementation of this disclosure, the arbitration module 1230 is configured to: perform validity checks on the first control command sequence and the second control command sequence to obtain validity check results; perform availability checks on the first control command sequence and the second control command sequence based on the health status of the master controller and the slave controller to obtain availability check results; and arbitrate the first control command sequence, the second control command sequence, and the third control command sequence according to the risk control status, the validity check results, and the availability check results.

[0389] In one implementation of this disclosure, the arbitration module 1230 is configured to perform any of the following: In response to a risk control state that is not the minimum risk control state, and a validity check result indicating that the first control command sequence is valid, and an availability check result indicating that the first control command sequence is available, then the first control command sequence is used as the target control command sequence; In response to a risk control state that is not the minimum risk control state, and a validity check result indicating that the first control command sequence is invalid while the second control command sequence is valid, and an availability check result indicating that the second control command sequence is available, then the second control command sequence is used as the target control command sequence; In response to a risk control state that is not the minimum risk control state, and a validity check result indicating that the second control command sequence is valid, and an availability check result indicating that the first control command sequence is unavailable while the second control command sequence is available, then the second control command sequence is used as the target control command sequence; In response to a risk control state that is the minimum risk control state, and a validity check result indicating that the second control command is valid, and an availability check result indicating that the second control command sequence is available, then the second control command sequence is used as the target control command sequence; If the first control command sequence is available, then the second control command sequence is used as the target control command sequence; if the risk control state is not the minimum risk control state, and the validity check result indicates that both the first and second control command sequences are invalid, then the third control command sequence is used as the target control command sequence; if the risk control state is not the minimum risk control state, and the validity check result indicates that both the first and second control command sequences are invalid, then the third control command sequence is used as the target control command sequence; if the risk control state is not the minimum risk control state, and the availability check result indicates that both the first and second control command sequences are unavailable, then the third control command sequence is used as the target control command sequence; if the risk control state is the minimum risk control state, and the validity check result indicates that the second control command sequence is invalid, then the third control command sequence is used as the target control command sequence; if the risk control state is the minimum risk control state, and the availability check result indicates that the second control command sequence is unavailable, then the third control command sequence is used as the target control command sequence.

[0390] In one implementation of this disclosure, the first acquisition module 1210 is configured to: predict the predicted state information of the vehicle at the effective time of the control command based on historical control commands and current state information; project the predicted state information onto the path coordinate system corresponding to the planned trajectory to determine the target trajectory point closest to the predicted state information from each trajectory point of the planned trajectory; resample the planned trajectory starting from the target trajectory point to obtain a reference trajectory; and generate a first control command sequence based on the first optimization target associated with the main controller, according to the reference trajectory, predicted state information, vehicle parameters, and historical control commands, and output it.

[0391] In one implementation of this disclosure, the first acquisition module 1210 is configured to: determine a first objective cost function corresponding to a first optimization objective based on a reference trajectory, predicted state information, vehicle parameters, and historical control commands; wherein the first objective cost function uses a first state variable and a first control variable as decision variables; the first state variable is associated with the first control variable through an equality constraint defined by a nonlinear dynamic model, the nonlinear dynamic model being used to indicate the nonlinear mapping relationship between the coupled response of longitudinal and lateral forces and the vehicle motion state; under the constraints of the executable domain indicated by the objective constraint information associated with the vehicle, calculate the first control variable that can satisfy the first optimization objective indicated by the first objective cost function in the future prediction time domain, and obtain the predicted value of the first control variable; and generate a first control command sequence based on the predicted value of the first control variable.

[0392] In one implementation of this disclosure, the first acquisition module 1210 is configured to: determine the vehicle's driving condition information based on at least one of the planned trajectory, the path mileage of the vehicle's current driving position, and the configuration mode; determine a target driving mode from multiple driving modes based on the driving condition information; adjust the weights of each cost function in the first target cost function and the executable boundaries of each constraint indicated by the executable domain based on the target driving mode; and calculate, under the constraints of the adjusted executable domain, a first control variable that can satisfy the first optimization objective indicated by the adjusted first target cost function in the future prediction time domain, thereby obtaining the predicted value of the first control variable.

[0393] In one implementation of this disclosure, the predicted value satisfying the first optimization objective indicated by the first objective cost function further includes the predicted values ​​of each first state variable in the future prediction time domain; the first acquisition module 1210 is used to: estimate the state bias of the nonlinear dynamics model based on the reference trajectory, vehicle parameters and historical control commands; compensate and correct the predicted values ​​of the first state variables using the state bias; compensate and correct the predicted values ​​of the first control variables based on the corrected predicted values ​​of the first state variables; and generate a first control command sequence based on the compensated and corrected predicted values ​​of the first control variables.

[0394] In one implementation of this disclosure, the first acquisition module 1210 is configured to: generate a predicted trajectory for the current control cycle based on the predicted value of the corrected first state variable; determine the trajectory offset between the predicted trajectory and the reference trajectory; and, in response to the trajectory offset being less than an offset threshold, generate a first control command sequence for the current control cycle based on the predicted value of the corrected first control variable.

[0395] In one implementation of this disclosure, the vehicle control device 1200 may further include: a processing module configured to perform at least one of the following: in response to the absence of a predicted value that satisfies the first optimization objective and the number of consecutive abnormal outputs by the main controller not exceeding a threshold, outputting a first control command sequence of the previous control cycle and setting the health status of the main controller to a warning; in response to the absence of a predicted value that satisfies the first optimization objective and the number of consecutive abnormal outputs exceeding the threshold, setting the health status of the main controller to an error; wherein the health status of the main controller is used as input for command arbitration.

[0396] In one implementation of this disclosure, the first state variable includes at least one of the following: lateral error, heading error, vehicle speed, vehicle sideslip angle, yaw rate, steering wheel angle, and steering wheel angular velocity; wherein the vehicle sideslip angle includes the front wheel sideslip angle and the rear wheel sideslip angle; and / or, the first control variable includes the target steering wheel angle, torque distribution amount, and total longitudinal force; wherein the torque distribution amount includes any one of the following: the front axle longitudinal force to be distributed to the front axle in the total longitudinal force, the rear axle longitudinal force to be distributed to the rear axle in the total longitudinal force, the proportion of the front axle longitudinal force, and the proportion of the rear axle longitudinal force.

[0397] In one implementation of this disclosure, the first objective cost function is determined based on at least one of the following cost functions: a state tracking cost function, determined based on the lateral error, heading error, and speed error in the first state variables, and the front axle longitudinal force proportional tracking error determined based on the torque distribution amount in the first control variables; a comfort cost function, determined based on the rate of change between two consecutively determined first control variables; a tire slip cost function, determined based on the front wheel slip angle and rear wheel slip angle in the first state variables; a road boundary intrusion cost function, determined based on the lateral error and error boundary value in the first state variables; and a super slip cost function, determined based on the vehicle slip angle determined by the first state variables. The cost function for the lateral convergence speed is determined based on the limit slip angle determined by the tire model in the vehicle parameters; the cost function for the lateral convergence speed is determined based on the lateral error and the expected lateral convergence speed in the first state variable; the cost function for the reference steering and reference longitudinal force is determined based on the deviation between the reference steering and reference longitudinal force at each trajectory point in the reference trajectory and the first control variable; the cost function for the aiming time is determined based on the deviation between the predicted driving time and the target aiming time under the target driving mode; wherein, the predicted driving time is the time required for the vehicle to travel the path distance corresponding to the future predicted time domain, determined based on the first state variable and the first control variable; the target aiming time is the expected driving time for the vehicle to travel the path distance under the target driving mode.

[0398] In one implementation of this disclosure, the target constraint information includes at least one of the following constraints: initial state constraints, used to instruct the first target cost function to determine each first control variable based on the predicted state information; equality constraints defined by the nonlinear dynamics model; rate of change constraint of the target steering wheel angle; rate of change constraint of the longitudinal force; rate of change constraint of the front axle longitudinal force ratio; constraint that both the front axle longitudinal force and the rear axle longitudinal force do not exceed the tire adhesion capacity; constraint that the product of the total longitudinal force and the vehicle speed does not exceed the total vehicle motor power; constraint that the product of the front axle longitudinal force and the vehicle speed does not exceed the front axle motor power; constraint that the product of the rear axle longitudinal force and the vehicle speed does not exceed the rear axle motor power; constraint that the front axle driving force does not exceed the maximum front axle driving force; and constraint that the rear axle driving force does not exceed the maximum rear axle driving force.

[0399] In one implementation of this disclosure, the second acquisition module 1220 is configured to: in response to the vehicle meeting a set first abnormal triggering condition, determine the vehicle's expected deceleration based on the vehicle speed and yaw rate; determine the speed sequence and path mileage sequence in the future prediction time domain based on the vehicle speed, expected deceleration, and prediction step time; and generate and output a second control command sequence based on a second optimization objective associated with the slave controller, according to the speed sequence, path mileage sequence, road boundary information of the vehicle's travel path, and planned trajectory.

[0400] In one implementation of this disclosure, the second acquisition module 1220 is configured to: determine a second objective cost function corresponding to a second optimization objective based on a speed sequence, a path mileage sequence, road boundary information, and a planned trajectory; wherein the second objective cost function uses a second state variable and a second control variable as decision variables; the second state variable is associated with the second control variable through a lateral dynamics model; the lateral dynamics model is used to indicate the nonlinear mapping relationship between the tire lateral force response and the vehicle yaw motion state; under the constraints of the lateral dynamics model, calculate the second control variable that can satisfy the second optimization objective indicated by the second objective cost function in the future prediction time domain, and obtain the predicted value of the second control variable; generate a second control command sequence for the current control cycle based on the predicted value of the second control variable, and output it.

[0401] In one implementation of this disclosure, the second acquisition module 1220 is further configured to: in response to the absence of a predicted value that satisfies the second optimization objective, and the number of consecutive abnormal outputs from the controller not exceeding the number threshold, output the second control command sequence of the previous control cycle.

[0402] In one implementation of this disclosure, the second objective cost function is determined based on at least one of the following cost functions: a lateral error and heading error tracking cost function, determined based on the lateral error and heading error in the second state variables; a boundary cost function, determined based on the lateral error and error boundary; a front and rear wheel sideslip cost function, determined based on the front wheel sideslip angle and rear wheel sideslip angle in the second state variables; a phase plane stable region cost function, determined based on the deviations between the yaw rate, front wheel sideslip angle, and rear wheel sideslip angle in the second state variables and the phase plane stable region; and a steering comfort cost function, determined based on the steering wheel angle and steering wheel angular velocity in the second control variables, as well as the steering wheel command changes between adjacent sampling points in the future prediction time domain and the steering wheel command changes between the current control cycle and the previous control cycle. The method for determining the phase plane stability region includes any of the following: determining the phase plane stability region based on the vehicle's maximum lateral acceleration and the rear wheel's limit sideslip angle; determining the phase plane stability region based on the vehicle's sideslip angle and yaw rate; or determining the phase plane stability region based on the vehicle's lateral acceleration and yaw rate.

[0403] In one implementation of this disclosure, the second state variable includes at least one of the following: lateral error, heading error, vehicle sideslip angle, yaw rate, steering wheel angle, and steering wheel angular velocity; wherein the vehicle sideslip angle includes the front wheel sideslip angle and the rear wheel sideslip angle; and / or, the second control variable includes the target steering wheel angle.

[0404] In one implementation of this disclosure, the second acquisition module 1220 is configured to: determine the total longitudinal force of the vehicle based on the desired deceleration and the vehicle model in the vehicle parameters; and generate a second control command sequence for the current control cycle based on the predicted value of the second control variable and the total longitudinal force.

[0405] In one implementation of this disclosure, the first abnormal triggering condition includes at least one of the following: abnormal output of the main controller; distance between the vehicle and the road boundary is less than a set distance; abnormal vehicle communication; the vehicle is in a minimum risk control state; or the tracking error of the vehicle on the planned trajectory exceeds a set error threshold.

[0406] In one implementation of this disclosure, the second acquisition module 1220 is configured to perform any of the following: determine the desired deceleration of the vehicle based on the vehicle speed, yaw rate, and configuration parameters; wherein the configuration parameters indicate the maximum lateral acceleration and maximum longitudinal acceleration associated with the wheels; determine the road curvature of the road on which the vehicle is currently traveling and the boundary distance between the vehicle and the road boundary, and determine the desired deceleration of the vehicle based on multiple of the vehicle speed, yaw rate, lateral error, road curvature, and boundary distance; wherein the lateral error is determined based on the current state information and the planned trajectory.

[0407] In one implementation of this disclosure, the third control command sequence is obtained through a third acquisition module. The third acquisition module is configured to: a first determining module, configured to determine the desired total braking torque of the vehicle based on vehicle speed, yaw rate, and vehicle mass in response to the vehicle meeting a set second abnormal triggering condition; a second determining module, configured to determine the vehicle motor torque and the hydraulic braking torque of the braking control system based on the total braking torque; a third determining module, configured to determine the target steering wheel angle based on the angular error between the yaw rate and the desired yaw rate; and a generating module, configured to generate the third control command sequence based on the target steering wheel angle, the vehicle motor torque, and the hydraulic braking torque.

[0408] In one implementation of this disclosure, the third acquisition module is configured to: acquire a set front axle longitudinal force ratio; wherein the front axle longitudinal force ratio is the ratio of the front axle longitudinal force to the total longitudinal force of the vehicle; allocate the vehicle motor torque according to the front axle longitudinal force ratio to obtain the front axle motor torque allocated to the front axle of the vehicle and the rear axle motor torque allocated to the rear axle of the vehicle; and generate a third control command sequence based on the target steering wheel angle, the front axle motor torque, the rear axle motor torque, and the hydraulic braking torque.

[0409] In one implementation of this disclosure, the third acquisition module is configured to: determine the actual lateral acceleration of the vehicle based on the vehicle speed and yaw rate; determine the desired longitudinal deceleration of the vehicle based on the lateral acceleration, the maximum permissible lateral acceleration of the vehicle, and the maximum longitudinal acceleration; and determine the desired total braking torque of the vehicle based on the longitudinal deceleration, the vehicle mass, and the vehicle speed.

[0410] In one implementation of this disclosure, the third acquisition module is configured to: determine the open-loop transfer function from the steering wheel angle to the yaw rate; wherein the open-loop transfer function indicates the transfer relationship between the steering wheel angle and the yaw rate; determine the adjustment controller and corresponding adjustment parameters based on the open-loop transfer function; wherein the adjustment controller is configured to establish a mapping relationship between the angle error between the yaw rate and the desired yaw rate and the target steering wheel angle; and determine the target steering wheel angle based on the angle error between the actual yaw rate and the desired yaw rate of the vehicle, as well as the adjustment controller and the adjustment parameters.

[0411] In one implementation of this disclosure, the second abnormality triggering condition includes at least one of the following: abnormal output from the main controller; abnormal output from the slave controller; abnormal vehicle planning module; wherein the planning module is used to output a planned trajectory; and the vehicle is in a minimum risk control state.

[0412] It should be noted that the foregoing explanation of any vehicle control method embodiment also applies to the vehicle control device of that embodiment, and will not be repeated here.

[0413] In the vehicle control device of this embodiment, the main controller generates a first control command sequence oriented towards task performance based on high-dimensional planned trajectory, current state information, historical control commands, and vehicle parameters, ensuring efficient and accurate trajectory tracking. A second control command sequence oriented towards vehicle stability and safety performance is generated from the controller, depending on the vehicle's current speed and yaw rate, forming a heterogeneous safety redundancy for the main controller. A third control command sequence containing a fallback safety strategy is introduced, and command arbitration is performed between the three, enabling the intelligent driving system to adopt the high-performance first control command sequence output by the main controller, and seamlessly switch to the safe and stable second control command sequence output by the controller when instability risks, critical scenarios, or extreme scenarios occur, or revert to the low-risk third control command sequence. Finally, the vehicle is controlled according to the arbitration result, significantly improving the vehicle's operational safety, robustness, and fault tolerance under complex or critical conditions.

[0414] To implement the above embodiments, this disclosure also proposes a vehicle, including: a processor; and a memory for storing processor-executable instructions; wherein the processor is configured to implement the vehicle control method as described in any of the foregoing embodiments. It should be noted that the foregoing explanations of the vehicle control method embodiments also apply to the vehicle of this embodiment, and will not be repeated here.

[0415] Figure 13 This is a block diagram illustrating a vehicle 1300 according to an exemplary embodiment. (Refer to...) Figure 13The vehicle 1300 may include various subsystems, such as an infotainment system 1310, a perception system 1320, a decision control system 1330, a drive system 1340, and a computing platform 1350. The vehicle 1300 may also include more or fewer subsystems, and each subsystem may include multiple components. Furthermore, each subsystem and component of the vehicle 1300 can be interconnected via wired or wireless means.

[0416] In some embodiments, the infotainment system 1310 may include a communication system, an entertainment system, and a navigation system, etc.

[0417] The perception system 1320 may include several sensors for sensing information about the environment surrounding the vehicle 1300. For example, the perception system 1320 may include a global positioning system (which may be a GPS system, a BeiDou system, or another positioning system), an inertial measurement unit (IMU), a lidar, a millimeter-wave radar, an ultrasonic radar, and a camera device.

[0418] The decision control system 1330 may include a computing system, a vehicle controller, a steering system, a throttle, and a braking system.

[0419] The drive system 1340 may include components that provide powered motion to the vehicle 1300. In one embodiment, the drive system 1340 may include an engine, an energy source, a transmission system, and wheels. The engine may be one or a combination of internal combustion engines, electric motors, and compressed air engines. The engine is capable of converting energy provided by the energy source into mechanical energy.

[0420] Some or all of the functions of the vehicle 1300 are controlled by a computing platform 1350. The computing platform 1350 may include at least one processor 1351 and a memory 1352, the processor 1351 being able to execute instructions 1353 stored in the memory 1352.

[0421] Processor 1351 can be any conventional processor. Processors may also include graphics processing units (GPUs), field-programmable gate arrays (FPGAs), systems on chips (SoCs), application-specific integrated circuits (ASICs), or combinations thereof.

[0422] The memory 1352 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk.

[0423] In addition to instruction 1353, memory 1352 can also store data, such as road maps, route information, vehicle position, direction, speed, and other data. The data stored in memory 1352 can be used by computing platform 1350.

[0424] In this embodiment of the disclosure, processor 1351 may execute instructions 1353 to complete all or part of the steps of any of the above method embodiments.

[0425] To implement the above embodiments, this disclosure also proposes a chip, wherein the chip includes an interface circuit and a processing circuit coupled to each other. The interface circuit is used to input or output signals, and the processing circuit is configured to execute the vehicle control method provided in any of the foregoing embodiments. It should be noted that the foregoing explanation of any vehicle control method embodiment also applies to the chip of this embodiment, and will not be repeated here.

[0426] Figure 14 This is a schematic diagram of the structure of a chip according to an exemplary embodiment of this disclosure. See also... Figure 14 The diagram shown is a schematic representation of the structure of chip 1400, but it is not limited to this.

[0427] Chip 1400 includes processing circuitry 1401, which is configured to execute any of the above vehicle control methods.

[0428] In some embodiments, chip 1400 further includes one or more interface circuits 1402. As one possible implementation, the interface circuit 1402 is connected to memory 1403, and can be used to receive signals from memory 1403 or other devices, and to send signals to memory 1403 or other devices. For example, the interface circuit 1402 can read instructions stored in memory 1403 and send those instructions to processing circuit 1401.

[0429] In some embodiments, the interface circuit 1402 performs at least one of the communication steps such as sending and / or receiving in the above method, while the processing circuit 1401 performs other steps.

[0430] In some embodiments, the terms interface circuit, interface, transceiver pin, transceiver, etc., can be used interchangeably.

[0431] In some embodiments, chip 1400 further includes one or more memories 1403 for storing instructions. Optionally, all or part of the memories 1403 may be located outside of chip 1400.

[0432] To implement the above embodiments, this disclosure also proposes a non-transitory computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the vehicle control method as described in any of the foregoing method embodiments.

[0433] It should be noted that the foregoing explanation of any vehicle control method embodiment also applies to the non-transitory computer-readable storage medium of that embodiment, and will not be repeated here.

[0434] To implement the above embodiments, this disclosure also proposes a computer program product having a computer program stored thereon, which, when executed by a processor, implements the vehicle control method as described in any of the foregoing method embodiments.

[0435] It should be noted that the foregoing explanations and descriptions of any vehicle control method or embodiment of a vehicle control method also apply to the computer program product of that embodiment, and will not be repeated here.

[0436] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of this disclosure. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.

[0437] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this disclosure, "a plurality of" means at least two, such as two, three, etc., unless otherwise explicitly specified.

[0438] Any process or method description in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of code comprising one or more executable instructions for implementing custom logic functions or processes, and the scope of preferred embodiments of this disclosure includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order depending on the functions involved, as will be understood by those skilled in the art to which embodiments of this disclosure pertain.

[0439] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-including system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can be any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution system, apparatus, or device. More specific examples (a non-exhaustive list) of computer-readable media include: an electrical connection having one or more wires (electronic device), a portable computer disk drive (magnetic device), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and compact disc read-only memory (CDROM). Alternatively, the computer-readable medium may be paper or other suitable media on which the program can be printed, since the program can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpreting, or otherwise processing as necessary, and then stored in a computer memory.

[0440] It should be understood that various parts of this disclosure can be implemented in hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented in software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.

[0441] Those skilled in the art will understand that all or part of the steps of the methods in the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, the program includes one or a combination of the steps of the method embodiments.

[0442] Furthermore, the functional units in the various embodiments of this disclosure can be integrated into a processing module, or each unit can exist physically separately, or two or more units can be integrated into a module. The integrated module can be implemented in hardware or as a software functional module. If the integrated module is implemented as a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium.

[0443] The storage medium mentioned above can be a read-only memory, a disk, or an optical disk, etc. Although embodiments of the present disclosure have been shown and described above, it is to be understood that the above embodiments are exemplary and should not be construed as limiting the present disclosure. Those skilled in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present disclosure.

Claims

1. A vehicle control method, characterized in that, include: The first control command sequence output by the vehicle's main controller based on the planned trajectory, current status information, historical control commands, and vehicle parameters is obtained. Obtain the second control command sequence output by the vehicle's slave controller based on the vehicle speed and yaw rate in the current state information; Command arbitration is performed on the first control command sequence, the second control command sequence, and the third control command sequence to obtain a target control command sequence; wherein the safety risk level of the vehicle driving according to the third control command sequence is lower than a preset risk threshold; The vehicle is controlled to drive according to the target control command sequence.

2. The method according to claim 1, characterized in that, The command arbitration of the first control command sequence, the second control command sequence, and the third control command sequence includes: Obtain a threshold parameter corresponding to the path mileage of the vehicle's current driving position; wherein, the threshold parameter is associated with at least one anomaly type, and the threshold parameter includes at least one of the following: lateral error threshold, heading error threshold, communication timeout threshold, and boundary margin threshold; Based on the threshold parameter, anomaly detection is performed on the current status information of the vehicle to determine the risk control status of the vehicle. Based on the risk control status, the health status of the master controller and the slave controller, command arbitration is performed on the first control command sequence, the second control command sequence and the third control command sequence.

3. The method according to claim 2, characterized in that, The step of arbitrating the first control command sequence, the second control command sequence, and the third control command sequence based on the risk control status, the health status of the master controller, and the slave controller includes: Perform a validity check on the first control command sequence and the second control command sequence to obtain the validity check result; Based on the health status of the master controller and the slave controller, an availability check is performed on the first control command sequence and the second control command sequence to obtain the availability check result. Based on the risk control status, the effectiveness check result, and the availability check result, command arbitration is performed on the first control command sequence, the second control command sequence, and the third control command sequence.

4. The method according to claim 3, characterized in that, The step of arbitrating the first control command sequence, the second control command sequence, and the third control command sequence based on the risk control status, the effectiveness check result, and the availability check result includes any one of the following: In response to the risk control state being a non-minimum risk control state, and the validity check result indicating that the first control command sequence is valid, and the availability check result indicating that the first control command sequence is available, then the first control command sequence is taken as the target control command sequence. In response to the risk control state being a non-minimum risk control state, and the validity check result indicating that the first control command sequence is invalid while the second control command sequence is valid, and the availability check result indicating that the second control command sequence is available, then the second control command sequence is taken as the target control command sequence. In response to the risk control state being a non-minimum risk control state, and the validity check result indicating that the second control command sequence is valid, and the availability check result indicating that the first control command sequence is unavailable while the second control command sequence is available, then the second control command sequence is taken as the target control command sequence. In response to the risk control state being the minimum risk control state, and the validity check result indicating that the second control command is valid, and the availability check result indicating that the second control command sequence is available, then the second control command sequence is taken as the target control command sequence. In response to the risk control state being a non-minimum risk control state, and the validity check result indicating that both the first control command sequence and the second control command sequence are invalid, the third control command sequence is taken as the target control command sequence. In response to the risk control state being a non-minimum risk control state, and the availability check result indicating that both the first control command sequence and the second control command sequence are unavailable, the third control command sequence is taken as the target control command sequence. In response to the risk control state being the minimum risk control state and the validity check result indicating that the second control command sequence is invalid, the third control command sequence is taken as the target control command sequence. In response to the risk control state being the minimum risk control state and the availability check result indicating that the second control command sequence is unavailable, the third control command sequence is used as the target control command sequence.

5. The method according to claim 1, characterized in that, The main controller outputs the first control command sequence in the following manner: Based on the historical control commands and the current status information, predict the predicted status information of the vehicle at the time when the control command takes effect; The predicted state information is projected onto the path coordinate system corresponding to the planned trajectory to determine the target trajectory point closest to the predicted state information from each trajectory point of the planned trajectory; Starting from the target trajectory point, the planned trajectory is resampled to obtain a reference trajectory; Based on the first optimization objective associated with the main controller, the first control command sequence is generated and output according to the reference trajectory, the predicted state information, the vehicle parameters, and the historical control commands.

6. The method according to claim 5, characterized in that, The step of generating the first control command sequence based on the reference trajectory, the predicted state information, the vehicle parameters, and the historical control commands includes: Based on the reference trajectory, the predicted state information, the vehicle parameters, and the historical control commands, a first objective cost function corresponding to the first optimization objective is determined; wherein, the first objective cost function uses a first state variable and a first control variable as decision variables; the first state variable is associated with the first control variable through an equality constraint defined by a nonlinear dynamic model, and the nonlinear dynamic model is used to indicate the nonlinear mapping relationship between the coupled response of longitudinal and lateral forces and the vehicle motion state; Under the constraints of the executable domain indicated by the target constraint information associated with the vehicle, the first control variable that can satisfy the first optimization objective indicated by the first target cost function in the future prediction time domain is calculated, and the predicted value of the first control variable is obtained. The first control command sequence is generated based on the predicted value of the first control variable.

7. The method according to claim 6, characterized in that, The step of calculating the first control variable that satisfies the first optimization objective indicated by the first objective cost function in the future prediction time domain under the constraints of the executable domain indicated by the target constraint information associated with the vehicle, and obtaining the predicted value of the first control variable, includes: The vehicle's driving condition information is determined based on at least one of the planned trajectory, the path mileage of the vehicle's current driving location, and the configuration mode. Based on the driving condition information, the target driving mode is determined from multiple driving modes; Based on the target driving mode, adjust the weights of each cost function in the first target cost function and the executable boundaries of each constraint indicated by the executable domain; Under the constraints of the adjusted executable domain, the first control variable that can satisfy the first optimization objective indicated by the adjusted first objective cost function within the future prediction time domain is calculated, and the predicted value of the first control variable is obtained.

8. The method according to claim 6, characterized in that, The predicted value that satisfies the first optimization objective indicated by the first objective cost function also includes the predicted values ​​of each first state variable in the future prediction time domain; The step of generating the first control command sequence based on the predicted value of the first control variable includes: Based on the reference trajectory, the vehicle parameters, and the historical control commands, the state bias of the nonlinear dynamics model is estimated. The predicted value of the first state variable is compensated and corrected using the state bias. Based on the corrected predicted value of the first state variable, the predicted value of the first control variable is compensated and corrected. The first control command sequence is generated based on the predicted value of the first control variable after compensation and correction.

9. The method according to claim 8, characterized in that, The step of generating the first control command sequence based on the compensated and corrected predicted value of the first control variable includes: Based on the corrected predicted value of the first state variable, the predicted trajectory of the current control cycle is generated. Determine the trajectory offset between the predicted trajectory and the reference trajectory; In response to the trajectory offset being less than the offset threshold, the first control command sequence for the current control cycle is generated based on the predicted value of the first control variable after compensation and correction.

10. The method according to claim 9, characterized in that, The method further includes at least one of the following: In response to the absence of a predicted value that satisfies the first optimization objective, and the number of consecutive abnormal outputs by the main controller not exceeding the number threshold, the first control command sequence of the previous control cycle is output, and the health status of the main controller is set to warning. If there is no predicted value that satisfies the first optimization objective, and the number of consecutive occurrences exceeds the number threshold, then the health status of the main controller is set to error. The health status of the main controller is used as input for the command arbitration.

11. The method according to any one of claims 6-10, characterized in that, The first state variable includes at least one of the following: lateral error, heading error, vehicle speed, vehicle sideslip angle, yaw rate, steering wheel angle, and steering wheel angular velocity; wherein the vehicle sideslip angle includes the front wheel sideslip angle and the rear wheel sideslip angle; And / or, The first control variables include the target steering wheel angle, torque distribution, and total longitudinal force; The torque distribution includes any one of the following: the front axle longitudinal force to be distributed to the front axle in the total longitudinal force, the rear axle longitudinal force to be distributed to the rear axle in the total longitudinal force, the proportion of the front axle longitudinal force, and the proportion of the rear axle longitudinal force.

12. The method according to any one of claims 6-10, characterized in that, The first objective cost function is determined based on at least one of the following cost functions: The state tracking cost function is determined based on the lateral error, heading error, and speed error in the first state variables, as well as the front axle longitudinal force proportional tracking error determined based on the torque distribution in the first control variables. The comfort cost function is determined based on the rate of change between two consecutive determinations of the first control variable; The tire slip cost function is determined based on the front wheel slip angle and the rear wheel slip angle in the first state variable; The road boundary intrusion cost function is determined based on the lateral error and error boundary value in the first state variable; The overslip cost function is determined based on the vehicle slip angle determined by the first state variable and the limit slip angle determined based on the tire model in the vehicle parameters; The cost function for lateral convergence speed is determined based on the lateral error in the first state variable and the expected lateral convergence speed. The reference steering and reference longitudinal force cost functions are determined based on the deviations between the reference steering and reference longitudinal force at each trajectory point in the reference trajectory and the first control variable; The aiming time cost function is determined based on the deviation between the predicted driving time and the target aiming time under the target driving mode; wherein, the predicted driving time is the time required for the vehicle to travel the path distance corresponding to the future predicted time domain, determined based on the first state variable and the first control variable; and the target aiming time is the expected driving time for the vehicle to travel the path distance under the target driving mode.

13. The method according to any one of claims 6-10, characterized in that, The target constraint information includes at least one of the following constraints: Initial state constraints are used to instruct the first objective cost function to determine each first control variable based on the predicted state information; The equality constraints defined by the nonlinear dynamic model; Constraint on the rate of change of the target steering wheel angle; Constraint on the rate of change of longitudinal force; Constraint on the rate of change of the longitudinal force ratio of the front axle; Both the longitudinal forces on the front axle and the longitudinal forces on the rear axle do not exceed the constraints on tire adhesion. The product of the total longitudinal force and the vehicle speed shall not exceed the constraint of the vehicle's motor power. The product of the longitudinal force on the front axle and the vehicle speed shall not exceed the constraint of the power of the front axle motor; The product of the longitudinal force on the rear axle and the vehicle speed shall not exceed the constraint of the power of the rear axle motor; The front axle driving force is constrained to not exceed the maximum front axle driving force. The rear axle driving force is constrained to not exceed the maximum driving force of the rear axle.

14. The method according to claim 1, characterized in that, The controller outputs the second control command sequence in the following manner: In response to the vehicle meeting a set first abnormal triggering condition, the desired deceleration of the vehicle is determined based on the vehicle speed and the yaw rate. Based on the vehicle speed, the expected deceleration, and the predicted step time, determine the speed sequence and path mileage sequence in the future prediction time domain; Based on the second optimization objective associated with the slave controller, the second control command sequence is generated and output according to the speed sequence, the path mileage sequence, the road boundary information of the vehicle's travel route, and the planned trajectory.

15. The method according to claim 14, characterized in that, The second control command sequence, generated and output based on the second optimization objective associated with the slave controller, according to the speed sequence, the path mileage sequence, the road boundary information of the vehicle's travel route, and the planned trajectory, includes: Based on the speed sequence, the path mileage sequence, the road boundary information, and the planned trajectory, a second objective cost function corresponding to the second optimization objective is determined; wherein, the second objective cost function uses a second state variable and a second control variable as decision variables; the second state variable is associated with the second control variable through a lateral dynamics model; the lateral dynamics model is used to indicate the nonlinear mapping relationship between the tire lateral force response and the vehicle yaw motion state; Under the constraints of the lateral dynamics model, the second control variable that can satisfy the second optimization objective indicated by the second objective cost function in the future prediction time domain is calculated, and the predicted value of the second control variable is obtained. Based on the predicted value of the second control variable, generate and output the second control command sequence for the current control cycle.

16. The method according to claim 15, characterized in that, The step of generating and outputting the second control command sequence based on the second optimization objective associated with the slave controller, according to the speed sequence, the path mileage sequence, the road boundary information of the vehicle's travel route, and the planned trajectory, further includes: In response to the absence of a predicted value that satisfies the second optimization objective, and the number of consecutive abnormal outputs from the controller does not exceed the number threshold, the second control command sequence of the previous control cycle is output.

17. The method according to claim 15 or 16, characterized in that, The second objective cost function is determined based on at least one of the following cost functions: The cost function for tracking lateral and heading errors is determined based on the lateral and heading errors in the second state variable. The boundary cost function is determined based on the lateral error and the error boundary. The front and rear wheel slip cost functions are determined based on the front wheel slip angle and the rear wheel slip angle in the second state variables; The phase plane stable region cost function is determined based on the deviations between the yaw rate, front wheel sideslip angle, and rear wheel sideslip angle in the second state variables and the phase plane stable region, respectively. The steering smoothness cost function is determined based on the steering wheel angle and steering wheel angular velocity in the second control variables, as well as the steering wheel command changes between adjacent sampling points in the future prediction time domain and the steering wheel command changes between the current control cycle and the previous control cycle. The method for determining the stable region of the phase plane includes any one of the following: The phase plane stability region is determined based on the vehicle's maximum lateral acceleration and the rear wheel's limiting sideslip angle. The stable region of the phase plane is determined based on the vehicle's sideslip angle and yaw rate; The stable region of the phase plane is determined based on the lateral acceleration and yaw rate of the vehicle.

18. The method according to claim 15 or 16, characterized in that, The second state variable includes at least one of the following: lateral error, heading error, vehicle sideslip angle, yaw rate, steering wheel angle, and steering wheel angular velocity; wherein the vehicle sideslip angle includes the front wheel sideslip angle and the rear wheel sideslip angle; And / or, The second control variable includes the target steering wheel angle.

19. The method according to claim 18, characterized in that, The step of generating a second control command sequence for the current control cycle based on the predicted value of the second control variable includes: The total longitudinal force of the vehicle is determined based on the desired deceleration and the vehicle model in the vehicle parameters; Based on the predicted value of the second control variable and the total longitudinal force, a second control command sequence for the current control cycle is generated.

20. The method according to any one of claims 14-16, characterized in that, The first abnormality triggering condition includes at least one of the following conditions: The main controller output is abnormal; The distance between the vehicle and the road boundary is less than a set distance; The vehicle communication is abnormal; The vehicle is under minimum risk control. The vehicle's tracking error on the planned trajectory exceeds a set error threshold.

21. The method according to any one of claims 14-16, characterized in that, Determining the desired deceleration of the vehicle based on the vehicle speed and the yaw rate includes any one of the following: The desired deceleration of the vehicle is determined based on the vehicle speed, the yaw rate, and configuration parameters; wherein the configuration parameters indicate the maximum lateral acceleration and the maximum longitudinal acceleration associated with the wheels. The curvature of the road on which the vehicle is currently traveling and the boundary distance between the vehicle and the road boundary are determined. Based on multiple factors including the vehicle speed, yaw rate, lateral error, road curvature, and boundary distance, the desired deceleration of the vehicle is determined. The lateral error is determined based on the current state information and the planned trajectory.

22. The method according to claim 1, characterized in that, The method for generating the third control command sequence includes: In response to the vehicle meeting a set second abnormal triggering condition, the desired total braking torque of the vehicle is determined based on the vehicle speed, the yaw rate, and the vehicle mass. Based on the total braking torque, determine the vehicle motor torque and the hydraulic braking torque of the braking control system; The target steering angle is determined based on the angular error between the stated yaw rate and the desired yaw rate. The third control command sequence is generated based on the target steering wheel angle, the vehicle motor torque, and the hydraulic braking torque.

23. The method according to claim 22, characterized in that, The step of generating the third control command sequence based on the target steering wheel angle, the vehicle motor torque, and the hydraulic braking torque includes: Obtain the set front axle longitudinal force ratio; wherein, the front axle longitudinal force ratio is the ratio of the front axle longitudinal force to the total longitudinal force of the vehicle; Based on the longitudinal force ratio of the front axle, the torque of the vehicle motor is distributed to obtain the front axle motor torque distributed to the front axle of the vehicle and the rear axle motor torque distributed to the rear axle of the vehicle. The third control command sequence is generated based on the target steering wheel angle, the front axle motor torque, the rear axle motor torque, and the hydraulic braking torque.

24. The method according to claim 22, characterized in that, Determining the desired total braking torque of the vehicle based on the vehicle speed, the yaw rate, and the vehicle mass includes: Based on the vehicle speed and the yaw rate, determine the actual lateral acceleration of the vehicle; The desired longitudinal deceleration of the vehicle is determined based on the lateral acceleration, the maximum permissible lateral acceleration of the vehicle, and the maximum longitudinal acceleration. The desired total braking torque of the vehicle is determined based on the longitudinal deceleration, vehicle mass, and vehicle speed.

25. The method according to claim 22, characterized in that, Determining the target steering angle based on the angular error between the yaw rate and the desired yaw rate includes: Determine the open-loop transfer function from steering wheel angle to yaw rate; wherein the open-loop transfer function is used to indicate the transfer relationship between the steering wheel angle and the yaw rate; Based on the open-loop transfer function, the adjustment controller and corresponding adjustment parameters are determined; wherein, the adjustment controller is used to establish the mapping relationship between the yaw rate and the angular error between the desired yaw rate and the target steering wheel angle; The target steering wheel angle is determined based on the angular error between the vehicle's actual yaw rate and the desired yaw rate, as well as the adjustment controller and the adjustment parameters.

26. The method according to any one of claims 22 to 25, characterized in that, The second abnormality triggering condition includes at least one of the following: The main controller output is abnormal; The controller outputs an error; The vehicle's planning module malfunctioned; the planning module is used to output the planned trajectory. The vehicle is under minimum risk control.

27. A vehicle control device, characterized in that, include: The first acquisition module is used to acquire the sequence of first control commands output by the vehicle's main controller based on the planned trajectory, current status information, historical control commands, and vehicle parameters; The second acquisition module is used to acquire the second control command sequence output by the vehicle's slave controller based on the vehicle speed and yaw rate in the current state information; The arbitration module is used to arbitrate the first control command sequence, the second control command sequence, and the third control command sequence to obtain a target control command sequence; wherein the safety risk level of the vehicle driving according to the third control command sequence is lower than a preset risk threshold; The control module is used to control the vehicle's movement according to the target control command sequence.

28. The apparatus according to claim 27, characterized in that, The arbitration module is used for: Obtain a threshold parameter corresponding to the path mileage of the vehicle's current driving position; wherein, the threshold parameter is associated with at least one anomaly type, and the threshold parameter includes at least one of the following: lateral error threshold, heading error threshold, communication timeout threshold, and boundary margin threshold; Based on the threshold parameter, anomaly detection is performed on the current status information of the vehicle to determine the risk control status of the vehicle. Based on the risk control status, the health status of the master controller and the slave controller, command arbitration is performed on the first control command sequence, the second control command sequence and the third control command sequence.

29. The apparatus according to claim 28, characterized in that, The arbitration module is used for: Perform a validity check on the first control command sequence and the second control command sequence to obtain the validity check result; Based on the health status of the master controller and the slave controller, an availability check is performed on the first control command sequence and the second control command sequence to obtain the availability check result. Based on the risk control status, the effectiveness check result, and the availability check result, command arbitration is performed on the first control command sequence, the second control command sequence, and the third control command sequence.

30. The apparatus according to claim 27, characterized in that, The first acquisition module is used for: Based on the historical control commands and the current status information, predict the predicted status information of the vehicle at the time when the control command takes effect; The predicted state information is projected onto the path coordinate system corresponding to the planned trajectory to determine the target trajectory point closest to the predicted state information from each trajectory point of the planned trajectory; Starting from the target trajectory point, the planned trajectory is resampled to obtain a reference trajectory; Based on the first optimization objective associated with the main controller, the first control command sequence is generated and output according to the reference trajectory, the predicted state information, the vehicle parameters, and the historical control commands.

31. The apparatus according to claim 30, characterized in that, The first acquisition module is used for: Based on the reference trajectory, the predicted state information, the vehicle parameters, and the historical control commands, a first objective cost function corresponding to the first optimization objective is determined; wherein, the first objective cost function uses a first state variable and a first control variable as decision variables; the first state variable is associated with the first control variable through an equality constraint defined by a nonlinear dynamic model, and the nonlinear dynamic model is used to indicate the nonlinear mapping relationship between the coupled response of longitudinal and lateral forces and the vehicle motion state; Under the constraints of the executable domain indicated by the target constraint information associated with the vehicle, the first control variable that can satisfy the first optimization objective indicated by the first target cost function in the future prediction time domain is calculated, and the predicted value of the first control variable is obtained. The first control command sequence is generated based on the predicted value of the first control variable.

32. The apparatus according to claim 27, characterized in that, The second acquisition module is used for: In response to the vehicle meeting a set first abnormal triggering condition, the desired deceleration of the vehicle is determined based on the vehicle speed and the yaw rate. Based on the vehicle speed, the expected deceleration, and the predicted step time, determine the speed sequence and path mileage sequence in the future prediction time domain; Based on the second optimization objective associated with the slave controller, the second control command sequence is generated and output according to the speed sequence, the path mileage sequence, the road boundary information of the vehicle's travel route, and the planned trajectory.

33. The apparatus according to claim 32, characterized in that, The second acquisition module is used for: Based on the speed sequence, the path mileage sequence, the road boundary information, and the planned trajectory, a second objective cost function corresponding to the second optimization objective is determined; wherein, the second objective cost function uses a second state variable and a second control variable as decision variables; the second state variable is associated with the second control variable through a lateral dynamics model; the lateral dynamics model is used to indicate the nonlinear mapping relationship between the tire lateral force response and the vehicle yaw motion state; Under the constraints of the lateral dynamics model, the second control variable that can satisfy the second optimization objective indicated by the second objective cost function in the future prediction time domain is calculated, and the predicted value of the second control variable is obtained. Based on the predicted value of the second control variable, generate and output the second control command sequence for the current control cycle.

34. The apparatus according to claim 27, characterized in that, The third control command sequence is obtained through a third acquisition module, wherein the third acquisition module is used to: In response to the vehicle meeting a set second abnormal triggering condition, the desired total braking torque of the vehicle is determined based on the vehicle speed, the yaw rate, and the vehicle mass. Based on the total braking torque, determine the vehicle motor torque and the hydraulic braking torque of the braking control system; The target steering angle is determined based on the angular error between the stated yaw rate and the desired yaw rate. The third control command sequence is generated based on the target steering wheel angle, the vehicle motor torque, and the hydraulic braking torque.

35. The apparatus according to claim 34, characterized in that, The third acquisition module is used for: Determine the open-loop transfer function from steering wheel angle to yaw rate; wherein the open-loop transfer function is used to indicate the transfer relationship between the steering wheel angle and the yaw rate; Based on the open-loop transfer function, the adjustment controller and corresponding adjustment parameters are determined; wherein, the adjustment controller is used to establish the mapping relationship between the yaw rate and the angular error between the desired yaw rate and the target steering wheel angle; The target steering wheel angle is determined based on the angular error between the vehicle's actual yaw rate and the desired yaw rate, as well as the adjustment controller and the adjustment parameters.

36. A vehicle, characterized in that, include: processor; Memory used to store processor-executable instructions; The processor is configured as follows: The steps of implementing the method as described in any one of claims 1-26.

37. A non-transitory computer-readable storage medium having computer program instructions stored thereon, characterized in that, When executed by a processor, the program instructions implement the steps of the method according to any one of claims 1 to 26.

38. A computer program product, characterized in that, It includes a computer program, which, when executed by a processor, implements the steps of the method according to any one of claims 1 to 26.

39. A chip, characterized in that, The chip includes an interface circuit and a processing circuit that are coupled to each other. The interface circuit is used to input or output signals, and the processing circuit is used to implement the steps of the method according to any one of claims 1 to 26.