A false-alarm-preventing control method and system for manual takeover in an autonomous vehicle
Patent Information
- Application Number
- CN202611267687.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-08-20
- Publication Date
- 2026-09-25
AI Technical Summary
在该类系统中,当自动驾驶系统遭遇无法处理的驾驶场景时,通常需要由远程操作员或车内驾驶员通过方向盘、踏板或操控手柄等输入设备实施人工干预;同时,当驾驶员对系统当前决策的信任度不足时,也可能主动夺取车辆控制权
[0085]本发明实施例提供的技术方案带来的有益效果是:本发明通过将介入指令映射为带有轨迹时间窗的期望行驶轨迹,并与自动驾驶系统的规划轨迹进行双轨迹对比和动态时间规整距离计算,实现了对人机决策冲突程度的量化度量。相比现有技术中基于单一固定阈值的判断方式,本发明能够在同一度量维度上准确反映人机意图的偏差大小,从而为后续的差异化响应策略提供了可靠的决策依据。
Smart Images

Figure CN122808782A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of autonomous driving technology, and in particular to a method and system for preventing misjudgment during manual takeover control in autonomous vehicles. Background Technology
[0002] Currently, mass-produced Level 3 and above autonomous driving systems are gradually being applied to real-world road scenarios. In these systems, when the autonomous driving system encounters a driving scenario it cannot handle, manual intervention is typically required by a remote operator or the driver in the vehicle via input devices such as the steering wheel, pedals, or control levers. Simultaneously, when the driver lacks confidence in the system's current decisions, they may also actively seize control of the vehicle. In these takeover scenarios, regardless of whether the manual intervention originates from the driver's on-site operation or from a remote operator's remote control command, the system faces the same fundamental problem: how to determine the execution strategy for the intervention command—whether to fully execute, partially execute, or ignore the command.
[0003] To address the aforementioned issues, several solutions have been proposed in existing technologies. One direct approach is to preset an amplitude threshold; when the amplitude of the operating signal exceeds this threshold, takeover is triggered, and vice versa. However, this approach has the following drawbacks: if the threshold is set too high, in emergency situations, the rise rate of the operating signal may not be sufficient to reach the threshold within the limited reaction time, causing the intervention signal to be filtered out by the system; if the threshold is set too low, signal fluctuations caused by slight physical contact during normal driving, such as hands touching the steering wheel or feet accidentally touching the pedals, can easily be misinterpreted by the system as an attempt to take over. Therefore, a single fixed threshold is insufficient to achieve an effective balance between system sensitivity and interference resistance.
[0004] To further improve the accuracy of the judgment criteria, some existing solutions have introduced physiological signal monitoring methods, including hand torque detection, driver eye tracking, and heart rate variability analysis, to assess the driver's actual readiness to take over. While these signals can characterize the driver's physiological state to some extent, they cannot measure the degree of deviation between the driver's input and the system's current decision. For example, when the system executes an emergency braking strategy while the driver simultaneously operates the accelerator pedal, physiological parameters such as hand torque cannot effectively reflect the actual severity of the aforementioned operational conflict.
[0005] In addition, some solutions employ trajectory analysis methods, either by constructing a differential game model to solve for Nash equilibrium or by comparing the deviation between the actual driving trajectory and the predicted trajectory offline to identify operational errors. However, the computational complexity of differential game models is high, and the computing resources of existing vehicle controllers are insufficient to meet their real-time computation requirements; while offline trajectory comparison is a post-event analysis method and cannot provide a basis for real-time decision-making during vehicle operation.
[0006] In summary, the existing solutions all share common shortcomings: First, they fail to distinguish between "whether the operation input exists" and "whether the operation should be executed" as two independent dimensions; second, they fail to quantify and stratify the degree of conflict between operation instructions and the system's autonomous decision-making, thus failing to provide differentiated response strategies for different levels of conflict. In other words, there is currently a lack of a systematic processing mechanism capable of classifying and determining the conflict levels of intervention instructions. Summary of the Invention
[0007] To address the problems in the prior art, this invention provides a method and system for preventing misjudgment during manual intervention in autonomous vehicles.
[0008] On the one hand, a method for preventing misjudgment during manual takeover control in an autonomous vehicle is provided, the method comprising:
[0009] S1: When the vehicle is in autonomous driving mode and receives an intervention command from the human input interface,
[0010] The system acquires and temporarily stores a first expected driving trajectory generated by the autonomous driving system at the current moment, and simultaneously generates a second expected driving trajectory with a trajectory time window based on the control mode carried by the intervention command; and performs input safety detection on the intervention command.
[0011] S2: If the input safety check fails, the intervention command is blocked, the temporarily stored first expected driving trajectory is discarded, and the autonomous driving mode is maintained; if it passes, proceed to S3.
[0012] S3: Calculate the trajectory deviation measure between the first expected driving trajectory and the second expected driving trajectory, as the degree of human-machine decision-making conflict;
[0013] S4: If the degree of human-machine decision conflict is less than the first threshold D1, then the intervention command is executed; if the degree of human-machine decision conflict is greater than the second threshold D2, then the intervention command is smoothed or attenuated before execution, and a takeover prompt message is output, wherein the second threshold D2 is greater than the first threshold D1; if the degree of human-machine decision conflict is greater than or equal to the first threshold D1 and less than or equal to the second threshold D2, then the operator's intent is authenticated; if the authentication is successful, then the intervention command is executed; if the authentication fails, then the automatic driving mode is maintained.
[0014] Furthermore, the trajectory time window includes a longitudinal time window and / or a lateral time window; the longitudinal time window is the time required for the speed to transition from the current vehicle speed to the target vehicle speed; the lateral time window is the duration for which the path curvature continues to act.
[0015] The first expected driving trajectory is a sequence of desired driving states generated based on environmental perception information;
[0016] The second expected driving trajectory is obtained by converting the intervention command through the command-trajectory mapping rule. The command-trajectory mapping rule converts the intervention command into a desired driving state sequence based on the control mode identifier carried by the intervention command. The control mode includes: planning only speed information during longitudinal control, planning only path information during lateral control, and planning both speed information and path information during full control.
[0017] Furthermore, the longitudinal time window is determined in the following manner:
[0018] Calculate the target vehicle speed v_target:
[0019] v_target = v + a_req·T_predict or v_target = v-d_req·T_predict
[0020] Where v is the current vehicle speed, T_predict is the prediction time window, a_req is the expected acceleration, and d_req is the expected deceleration;
[0021] If v_target > v, then the longitudinal time window T_v = (v_target-v) / a_acc + t_margin; if v_target < v, then the longitudinal time window T_v = (v-v_target) / a_dec + t_margin, where a_acc is the preset maximum safe acceleration, a_dec is the preset maximum safe deceleration, and t_margin is the preset response margin time.
[0022] The longitudinal control, which only plans speed information, specifically includes:
[0023] Once the longitudinal time window T_v is determined, a speed plan is generated within the time interval [0, T_v]. The speed plan starts with the current vehicle speed v and ends with the target vehicle speed v_target, smoothly transitioning within the longitudinal time window T_v and satisfying the following constraints:
[0024] Acceleration amplitude constraint: Within the longitudinal time window T_v, the absolute value of acceleration in speed planning must not exceed the maximum safe acceleration a_acc or the maximum safe deceleration a_dec. At the same time, the target vehicle speed v_target must not exceed the current road speed limit and the vehicle's physical maximum speed, nor be lower than 0.
[0025] Acceleration rate of change constraint: The absolute value of the rate of change of acceleration in velocity planning must not exceed the preset comfort threshold. .
[0026] Furthermore, the lateral time window is determined based on the source type of the intervention command:
[0027] When the intervention command originates from a momentary position input via the steering wheel, there are two operating modes:
[0028] Position holding mode: The horizontal time window T_h is determined by the operator's continuous holding duration;
[0029] Goal-oriented model: The lateral time window T_h is calculated using the following formula:
[0030] T_h = Δθ_target / ω_max + t_margin_steer
[0031] Where Δθ_target is the change in the target heading angle, ω_max is the maximum yaw rate of the vehicle, and t_margin_steer is the steering response margin;
[0032] The path information planned during lateral control specifically includes:
[0033] Starting from the current rear axle center position of the vehicle and taking the current heading direction of the vehicle as the positive x-axis, generate a path point sequence through curvature integral within the time interval [0, T_h]:
[0034]
[0035]
[0036] Among them, heading angle θ0 is the vehicle's current heading angle, v(τ') is the speed planning value carried over from the first expected driving trajectory, v(τ) is the speed value at time τ, τ and τ' are time integration variables, representing the time offset calculated from the current time, t is the current time, and κ_cmd is the desired curvature, determined according to the intervention command.
[0037] Meanwhile, the following curvature constraints must be satisfied during the generation of the path point sequence:
[0038] Curvature amplitude constraint: Within the lateral time window T_h, the absolute value of the desired curvature κ_cmd must not exceed the vehicle's physical maximum curvature κ_max;
[0039] Curvature change rate constraint: the rate of change of the desired curvature κ_cmd . The absolute value must not exceed the preset comfort threshold κ. . _comfort.
[0040] Furthermore, the simultaneous planning of speed and path information during full-scale control specifically includes:
[0041] The overall time window T is the larger of the vertical time window T_v and the horizontal time window T_h;
[0042] Within the time interval [0, min(T_v, T_h)], speed information is executed according to longitudinal control planning, and path information is executed according to lateral control planning;
[0043] If T_v ends first after exceeding min(T_v, T_h), the speed information will be maintained at the target speed v_target after reaching the target speed v_target at time T_v until the end of the overall time window T.
[0044] If T_h ends first, the path information reaches the final path point at time T_h and continues to travel at a constant curvature with the curvature corresponding to that point until the overall time window T ends.
[0045] Furthermore, when the intervention command is a continuous holding command from a joystick or button, the intervention command is effective while the operator continues to input and returns to zero when the input is released; during the duration of the continuous holding command, the trajectory time window is recalculated and rolled over in each planning cycle based on the current vehicle state; after the continuous holding command is released, the longitudinal control switches to a coasting deceleration strategy, and the lateral control switches to a self-centering holding strategy with zero curvature.
[0046] Furthermore, the input security detection includes at least one of the following strategies:
[0047] When the same intervention command is received consecutively and the time interval between two adjacent intervention commands is less than the preset minimum interval, or the reception frequency of the same intervention command within a preset time exceeds the preset maximum frequency, the intervention command is determined to be abnormal and the intervention command is blocked.
[0048] For intervention commands other than persistent commands, when multiple intervention commands are received within a preset time window, if an emergency command is included, all non-emergency commands are suppressed and only the emergency command is executed. If there is no emergency command but a pair of mutually exclusive commands is included, all intervention commands are suppressed.
[0049] If the intervention command is not a persistent command and is a repetitive command of the same type, only the first one that arrives will be executed, and the rest will be suppressed.
[0050] Furthermore, the degree of human-machine decision-making conflict is calculated using any one of the following methods: dynamic time warping algorithm, area integration method, average Euclidean distance, or Hausdorff distance.
[0051] The dynamic time warping algorithm specifically includes:
[0052] Each trajectory point in the first and second expected driving trajectories includes position (x, y), velocity v, and heading angle θ;
[0053] By dynamically programming, the minimum cumulative distance between each point on the first and second expected driving trajectories is calculated point by point. The recursive formula is as follows:
[0054] M(i,j)=d(a_i,b_j)+min{M(i-1,j), M(i,j-1), M(i-1,j-1)}
[0055] In this context, the three terms in min{} represent three different time alignment methods: vertical step M(i-1,j) means aligning the (i-1)th point of the first expected driving trajectory with the jth point of the second expected driving trajectory before matching the current point; horizontal step M(i,j-1) means aligning the i-th point of the first expected driving trajectory with the (j-1)th point of the second expected driving trajectory before matching the current point; and diagonal step M(i-1,j-1) means matching the current points of the two expected driving trajectories one-to-one, selecting the direction with the smallest cumulative distance from the three methods to advance, thus obtaining the degree of human-machine decision conflict.
[0056] The single-point distance d(a_i,b_j) is obtained by weighted summation after normalizing the position deviation, velocity deviation, and heading angle deviation: d(a_i,b_j)=w_p·Δp_norm+w_v·Δv_norm+w_θ·Δθ_norm; where Δp_norm, Δv_norm, and Δθ_norm are the normalized position deviation, velocity deviation, and heading angle deviation, respectively, and w_p, w_v, and w_θ are the corresponding weight coefficients, and the sum of the three is 1.
[0057] Furthermore, the first expected driving trajectory is one or more candidate trajectories; when there are multiple candidate trajectories, each candidate trajectory is assigned a corresponding probability value, and the sum of the probability values is 1. The degree of human-machine decision conflict is taken as the weighted average of the trajectory deviation measures between each candidate trajectory and the second expected driving trajectory.
[0058] Furthermore, the first threshold D1 and the second threshold D2 are pre-calibrated and dynamically adjusted thresholds, and their determination method is as follows:
[0059] D1 = D1_base · f
[0060] D2 = D2_base · f
[0061] Where D1_base and D2_base are pre-calibrated fixed reference values, and the dynamic coefficient f is:
[0062] f = 1 + k ·(a_y / a_y_max) or f = 1 + k ·(a_y / a_y_max) + k_r ·r
[0063] Where a_y = v² ·ρ, v is the current vehicle speed, ρ is the road curvature, a_y_max =μ· g, μ is the road surface adhesion coefficient, g is the gravitational acceleration, k is the lateral acceleration influence coefficient, r is the environmental risk level, and k_r is the environmental risk weight coefficient.
[0064] Furthermore, the specific steps of smoothing or attenuating the intervention command before execution include:
[0065] Based on the degree of human-machine decision-making conflict D, the human-machine co-driving weight coefficient w = 1 / (1+e^{k·(D-D2)}) is calculated using the Sigmoid function, where k is a preset slope coefficient;
[0066] Based on the human-machine co-driving weight coefficient w, the expected control quantity u_manual corresponding to the intervention command and the expected control quantity currently output by the autonomous driving system are weighted and fused to generate the target control command: u_target = w·u_manual + (1-w)·u_auto;
[0067] The authentication of the operator's intent specifically includes:
[0068] Behavioral features are extracted from the operation signals output from the manual input interface. The behavioral features include at least the operation duration, the consistency of the rate of change of the operation direction, and the energy distribution ratio of the operation signal in the low-frequency band and the high-frequency band.
[0069] The duration t is mapped to the first probability value P_duration=1-exp(-t / τ), the number of changes in the operation direction n within the preset time window is mapped to the second probability value P_consistency=exp(-λ·n), and the energy ratio R between the low-frequency band and the high-frequency band is mapped to the third probability value P_frequency=1 / (1+exp(-k_freq·(R-R0))), where τ is the time constant, λ is the attenuation coefficient, k_freq is the slope coefficient, and R0 is the decision boundary;
[0070] C = P_duration·P_consistency·P_frequency is used as a representation of the credibility of the operator's intent. When C exceeds the preset threshold C_th, the authentication is deemed successful; otherwise, the authentication fails.
[0071] Furthermore, the method also includes: when the collision time between the vehicle and surrounding obstacles is less than a preset safety threshold, and the current planned trajectory of the autonomous driving system does not contain effective avoidance measures:
[0072] If the degree of human-machine decision conflict is greater than the second threshold D2, then the smoothing or gain attenuation of the intervention command is cancelled, and the intervention command is executed in full directly.
[0073] If the degree of human-machine decision conflict is between the first threshold D1 and the second threshold D2, then the authentication of the operator's intention is skipped, and the intervention command is executed directly in full.
[0074] Furthermore, the method also includes continuous monitoring after takeover:
[0075] The deviation between the actual driving trajectory of the vehicle after takeover and the second expected driving trajectory is obtained;
[0076] When the deviation exceeds the third threshold D3 and the duration exceeds the threshold T_exceed, the manual takeover is automatically terminated and the automatic driving mode is restored.
[0077] The third threshold D3 is determined by the product of the basic deviation threshold D3_base and the dynamic environmental risk coefficient α: D3 = D3_base·α, where α = 1 + k1 / d_min + k2·max(v_rel,0), d_min is the minimum distance between the vehicle and surrounding obstacles, v_rel is the relative approach speed, and k1 and k2 are preset weighting coefficients; when there are multiple obstacles at the same time, the maximum value of α_i corresponding to each obstacle is taken.
[0078] On the other hand, a manual takeover prevention and misjudgment control system for autonomous vehicles is provided, the system comprising:
[0079] The trajectory acquisition module is used to acquire and temporarily store the first expected driving trajectory generated by the autonomous driving system at the current moment when the vehicle is in autonomous driving mode and receives an intervention command from the human input interface.
[0080] The trajectory mapping module is used to generate a second expected driving trajectory with a trajectory time window according to the control mode carried by the intervention command;
[0081] The security detection module is used to perform input security detection on the intervention command. If the detection fails, the intervention command is blocked. If the detection passes, a release signal is sent to the conflict measurement module.
[0082] The conflict measurement module is used to calculate the deviation measure between the first expected driving trajectory and the second expected driving trajectory after receiving the clearance signal, as a measure of the degree of conflict between human and machine decision-making.
[0083] The hierarchical decision-making module is used to execute the intervention command if the degree of human-machine decision conflict is less than a first threshold D1; if the degree of human-machine decision conflict is greater than a second threshold D2, the intervention command is smoothed or attenuated before execution, and a takeover prompt message is output, wherein the second threshold D2 is greater than the first threshold D1; if the degree of human-machine decision conflict is greater than or equal to the first threshold D1 and less than or equal to the second threshold D2, the operator's intent is authenticated; if the authentication is successful, the intervention command is executed; if the authentication fails, the automatic driving mode is maintained.
[0084] The processor integrates the trajectory acquisition module, trajectory mapping module, safety detection module, conflict measurement module, and hierarchical decision-making module. When the processor executes the program stored in the memory, it implements the manual takeover and misjudgment prevention control method in the autonomous vehicle.
[0085] The beneficial effects of the technical solution provided by the embodiments of the present invention are as follows: By mapping intervention commands to desired driving trajectories with trajectory time windows and comparing them with the planned trajectories of the autonomous driving system through dual-trajectory comparison and dynamic time warping distance calculation, the present invention achieves a quantitative measurement of the degree of human-machine decision-making conflict. Compared with the judgment method based on a single fixed threshold in the prior art, the present invention can accurately reflect the magnitude of the deviation between human and machine intentions on the same measurement dimension, thereby providing a reliable decision-making basis for subsequent differentiated response strategies.
[0086] This invention implements a tiered response to intervention commands with varying conflict levels by setting three mutually exclusive decision intervals divided by a first threshold and a second threshold: when the conflict level is low, the command is executed directly, balancing the driver's willingness to take over and response speed; when the conflict level is moderate, the operator's intention is authenticated using three-dimensional features in the time and frequency domains, effectively distinguishing between intentional intervention and accidental physical contact; when the conflict level is high, the manual command is smoothly attenuated through a weighted fusion method before execution, achieving a gradual transition in human-machine control. This mechanism fundamentally solves the inherent problem in existing single-threshold schemes where it is difficult to balance system sensitivity and anti-interference capabilities.
[0087] This invention achieves adaptive dynamic adjustment of threshold parameters for different driving conditions by associating a first threshold and a second threshold with current vehicle speed, road curvature, and environmental risk level. During high-speed driving or on curves, the system automatically raises the takeover threshold to reduce safety risks caused by driver error; during low-speed straight driving, the system appropriately relaxes the takeover conditions to ensure timely response to the driver's takeover intentions.
[0088] This invention integrates emergency avoidance priority logic. When the collision time between the vehicle and an obstacle is detected to be less than a safety threshold and the current planned trajectory does not include effective avoidance measures, the system can selectively cancel the smooth decay processing or skip the intent authentication step based on the current decision interval, and directly execute the full intervention command. This logic covers special situations where perception omissions or planning errors occur but the driver has reacted correctly, providing a final line of defense for the safety of the autonomous driving system. Attached Figure Description
[0089] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0090] Figure 1 This is an overall flowchart of a manual takeover control method for preventing misjudgment in an autonomous vehicle provided by the present invention;
[0091] Figure 2 This is a structural block diagram of a manual takeover prevention and misjudgment control system for an autonomous vehicle provided by the present invention.
[0092] Figure reference numerals: 100-Trajectory acquisition module; 200-Trajectory mapping module; 300-Safety detection module; 400-Conflict measurement module; 500-Hierarchical decision-making module; 600-Safety monitoring module; 700-Processor; 800-Manual input interface. Detailed Implementation
[0093] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0094] To make the objectives, technical solutions, and advantages of the present invention clearer, the embodiments of the present invention will be described in further detail below with reference to the accompanying drawings.
[0095] Example 1
[0096] like Figure 1 As shown, this embodiment provides a manual takeover control method to prevent misjudgment in an autonomous vehicle, which is applied to the vehicle's autonomous driving controller.
[0097] First, let's introduce the scenario in which this embodiment is situated: When the vehicle is in autonomous driving mode, the decision-making and planning module in its autonomous driving system continuously generates a first expected driving trajectory based on environmental perception information, denoted as Traj_auto. This trajectory includes the expected path point sequence (x, y coordinates), expected vehicle speed, and expected heading angle for a future period of time. Traj_auto is the output of the decision-making and planning layer. Unlike the underlying control signals sent to the steering / braking actuators, it does not contain the mechanical delays and noise of the actuators.
[0098] When the autonomous driving system receives a manual intervention command, it performs the following steps:
[0099] Step (1): In response to receiving the intervention command, perform the following operations in parallel.
[0100] (1a) Obtain and temporarily store the first expected driving trajectory Traj_auto generated by the decision planning module of the autonomous driving system at the current moment (i.e. the instant when the intervention command is received);
[0101] (1b) Simultaneously, a second expected driving trajectory Traj_manual with a trajectory time window is generated according to the control mode carried by the intervention command;
[0102] (1c) Simultaneously perform input security checks on the intervention command.
[0103] The three operations mentioned above are independent of each other, are executed synchronously, and do not cause any timing delays.
[0104] Step (2): Input security detection result judgment
[0105] If the input safety check fails, the intervention command is blocked, the temporarily stored Traj_auto is discarded, and the automatic driving mode is maintained without proceeding to the next step; if it passes, proceed to step (3).
[0106] In this step, the specific implementation method of input security detection is as follows:
[0107] Before calculating the degree of conflict, an input safety check is first performed on the intervention command. Intervention commands determined to be "blocked" or "suppressed" will not proceed to the subsequent trajectory generation, conflict measurement, and hierarchical decision-making processes; the system will directly maintain the current autonomous driving mode. Only intervention commands that pass all safety checks can proceed to the next stage.
[0108] (2a) Frequency anomaly detection
[0109] If the system receives consecutive intervention commands of the same type, such as acceleration or steering in the same direction, and the time interval between two adjacent intervention commands is less than a preset minimum interval, or the receiving frequency exceeds a preset upper limit, the intervention command is determined to be abnormal, and the command is temporarily blocked. In this embodiment, taking a remote control with a communication frequency of 50Hz as an example, the normal command interval is set to 20ms. The minimum interval is set to 10ms, corresponding to 100Hz. The normal command interval of 20ms > 10ms, which can pass detection; while the 1~2ms interval pulses generated by abnormal jitter are blocked. This method is mainly used to suppress abnormal intervention commands caused by signal interference, hardware failure, or malicious high-frequency injection.
[0110] (2b) Arbitration of conflicting instructions
[0111] For intervention commands other than continuous hold commands (such as steering wheel angle input, pedal travel input, etc.), when multiple commands are received within a preset time window:
[0112] If it includes an emergency braking command (e.g., a request for deceleration greater than 4 m / s²) or an emergency steering request (absolute curvature greater than 0.08 m). -1 If an emergency command is triggered, all non-emergency commands will be suppressed, and only emergency commands will be executed. Emergency commands still need to enter the subsequent conflict measurement and three-zone decision-making process to determine the degree of conflict with the autonomous driving system's trajectory and decide the final execution method. However, the operator intent authentication step within the takeover zone is skipped because the emergency attribute clearly defines the operational intent, and there is no need to determine whether it is a mis-trigger.
[0113] If there is no emergency instruction but there are mutually exclusive instruction pairs, such as left turn and right turn simultaneously, or acceleration and deceleration simultaneously, then all instructions are suppressed and feedback information is generated to the operator.
[0114] If the window receives repeated intervention commands of the same type, such as multiple acceleration commands or multiple steering commands in the same direction, only the first one that arrives will be executed.
[0115] (2c) Detection pass conditions
[0116] If the above frequency anomaly detection and the above instruction conflict arbitration intervention instruction are not triggered, it is determined that the input security detection is passed and proceeds to the next step (3); if any of the above anomalies are triggered, the instruction is determined to fail the detection and is blocked or suppressed, and does not proceed to the next step.
[0117] Step (3): Calculate the degree of human-machine decision-making conflict D
[0118] The trajectory deviation between Traj_auto (temporarily stored in step (1) and the generated Traj_manual) is calculated as the degree of human-machine decision conflict D.
[0119] In this step, the second expected driving trajectory Traj_manual is a complete sequence of expected driving states, including waypoint positions, speeds, and heading angles. The generation method of Traj_manual depends on the control mode of the intervention command: only speed information is planned during longitudinal control, only path information is planned during lateral control, and both speed and path information are planned during full control.
[0120] Traj_manual includes a trajectory time window, comprising a longitudinal time window T_v and / or a lateral time window T_h. The longitudinal time window determines the duration required for the speed to transition from the current vehicle speed to the target vehicle speed, while the lateral time window represents the duration for which the path curvature persists. The following sections detail the trajectory generation methods under longitudinal control, lateral control, and full control modes, and conclude with a summary of special handling for sustained control commands.
[0121] (3a) Longitudinal control
[0122] When the control mode is longitudinal control, the generation of Traj_manual only involves longitudinal speed planning. Its path information is not generated separately, and the path point positions and heading angles of Traj_auto are directly used.
[0123] (3a-1) Determination of target vehicle speed
[0124] Common sources of intervention commands include the accelerator pedal, joystick, and push-button switches. The pedal signal directly provides the desired acceleration a_req (when the accelerator pedal is depressed) or the desired deceleration d_req (when the brake pedal is depressed, with a positive sign); the joystick's longitudinal offset is normalized (mapped to the [-1, 1] interval) and multiplied by a preset maximum acceleration calibration value to obtain a_req; a button outputs a fixed acceleration or deceleration value (calibrated range 1.0~2.0 m / s²) while it is pressed, and returns to zero after being released.
[0125] After obtaining a_req or d_req from the above sources, the target vehicle speed is calculated using an integral prediction method:
[0126] v_target = v + a_req · T_predict or v_target = v -d_req · T_predict
[0127] Where v is the current vehicle speed (unit: m / s), and T_predict is the prediction time window (range: 0.5s~2.0s). When the calculated result exceeds the vehicle's physical limits, the speed is directly limited—if it exceeds the maximum design speed, it is limited to the maximum speed; if it is below 0, it is limited to 0.
[0128] (3a-2) Calculation of longitudinal time window T_v
[0129] After obtaining v_target, the longitudinal time window T_v is calculated according to the following formula:
[0130] If v_target > v (acceleration condition): T_v = (v_target - v) / a_acc + t_margin
[0131] If v_target < v (deceleration condition): T_v = (v - v_target) / a_dec + t_margin
[0132] Wherein, a_acc is the maximum safe acceleration (unit: m / s²), which depends on the power system capability and the current load state; a_dec is the maximum safe deceleration (unit: m / s²), which is the smaller value between the braking system capability a_brake_max and the road adhesion condition μ·g; μ is the road adhesion coefficient (dimensionless), which is estimated in real time by the environmental perception module according to the road type; g is the gravitational acceleration, which is taken as 9.8 m / s²; t_margin is the response margin (value range 0.3s~0.5s), which is used to compensate for braking / acceleration response delay and communication transmission delay.
[0133] In a single-trigger scenario, T_v is a fixed value, and the speed planning smoothly transitions from the current vehicle speed v to the target vehicle speed v_target within a fixed window [0, T_v]. After time T_v, the speed information in Traj_manual is automatically connected to the speed planning value of Traj_auto at the corresponding time.
[0134] (3a-3) Generation of velocity programming
[0135] Once a_req or d_req and T_v are determined, a speed plan is generated within the time interval [0, T_v]. This speed plan starts with the current vehicle speed v and ends with the target vehicle speed v_target, smoothly transitioning within the T_v time window. The transition method can be implemented using linear transition or first-order inertial filtering, and must satisfy the following constraints:
[0136] Acceleration amplitude constraint: Within the longitudinal time window T_v, the absolute value of acceleration in speed planning must not exceed the maximum safe acceleration a_acc (during acceleration) or the maximum safe deceleration a_dec (during deceleration). Simultaneously, the target vehicle speed v_target must not exceed the current road speed limit and the vehicle's maximum physical speed, nor be lower than 0.
[0137] Acceleration rate of change constraint: The rate of change of acceleration (i.e., jerk) also needs to be limited to prevent longitudinal jerking of the vehicle caused by sudden acceleration or braking commands. The absolute value of the rate of change of acceleration in the speed planning curve must not exceed a preset comfort threshold. In this embodiment, the comfort threshold The value ranges from 2.0 to 5.0 m / s³, and its calibration is based on the human body's tolerance to the rate of change of longitudinal acceleration, falling within the comfortable range acceptable to most occupants. The upper limit of the actual jerk is taken as the comfort threshold. The smaller of the two values, the physical maximum acceleration capability of the braking / driving actuator, is used to ensure that the planned speed curve simultaneously satisfies both comfort constraints and actuator capability constraints.
[0138] (3b) Lateral control
[0139] When the control mode is lateral control, the generation of Traj_manual only involves path planning, and its speed planning is not generated separately; the speed planning value of Traj_auto is directly used.
[0140] (3b-1) Determination of the expected curvature κ_cmd
[0141] The method for determining the expected curvature κ_cmd varies depending on the input type.
[0142] (i) Steering wheel input - position holding mode:
[0143] When the operator maintains the steering wheel at a certain angle, the system directly uses the curvature corresponding to that angle as the desired curvature. When the steering angle is small, the tire lateral slip characteristics are close to linear, and Ackermann steering geometry mapping is used.
[0144] κ_cmd=δ_sw / L
[0145] Where δ_sw is the steering wheel angle, with the center position as the zero point, positive on the left and negative on the right; L is the vehicle wheelbase. In this embodiment, δ_sw < 0.2 rad (approximately 11.5°) is taken as the effective range of this linear mapping. This boundary is determined based on a small-angle approximation of tan(δ) ≈ δ.
[0146] When δ_sw ≥ 0.2 rad, it exceeds the linear region, and the tire sideslip nonlinear effect is significant. The actual curvature is lower than the linear mapping value of Ackermann geometry, and nonlinear correction is required for the curvature calculation results.
[0147] κ_cmd_corrected = δ_sw / L · (1 + k_tire · δ_sw²)
[0148] Wherein, k_tire is the tire nonlinearity correction coefficient, used to compensate for curvature loss under large steering angles. Its value is determined by tire characteristic tests and ranges from 0.5 to 2.0.
[0149] Regardless of whether linear mapping or nonlinear correction is used, the final value of κ_cmd must not exceed κ_max.
[0150] (ii) Steering wheel input – target-oriented mode:
[0151] Unlike the steering wheel position holding mode described above, when the operation signal contains a specific target heading angle change Δθ_target (unit: rad), the system processes it in target guidance mode, that is, it first calculates the target curvature κ_target required to achieve that heading angle change:
[0152] κ_target = Δθ_target / (v · T_h)
[0153] Where v is the current vehicle speed, and the specific calculation of the lateral time window T_h is shown in 3b-2. The final calculated κ_target needs to be limited to the interval [-κ_max, κ_max], and the limited κ_target is the target value of the curvature smoothing strategy.
[0154] (iii) Joystick or button input:
[0155] For joystick input, the lateral offset of the joystick is normalized to the range [-1, 1] and then multiplied by κ_max to obtain κ_cmd. For steering button input, a preset fixed curvature command is directly output, the absolute value of which is less than or equal to κ_max. The specific calibration value is determined according to the vehicle's steering response characteristics, for example, it can be preset to ±0.6·κ_max.
[0156] (3b-2) Determination of the horizontal time window T_h
[0157] The determination of the horizontal time window T_h depends on the source type of the intervention command.
[0158] When the intervention command originates from a momentary position input via the steering wheel, there are two operating modes:
[0159] (i) Position holding mode: When the operator holds the steering wheel at a certain angle, the system continues to drive at the curvature corresponding to that angle. T_h is determined by the duration of the operator's holding position.
[0160] (ii) Target-oriented mode: When the operator's intention is to achieve a specific target heading angle change Δθ_target, T_h is calculated according to the following formula:
[0161] T_h = Δθ_target / ω_max + t_margin_steer
[0162] Wherein, ω_max is the maximum yaw rate of the vehicle (unit: rad / s), and its determination method is described later; t_margin_steer is the steering response margin, with a value range of 0.1~0.3s, which is used to compensate for the response delay of the steering actuator.
[0163] The two steering wheel operation modes are distinguished by the operation signal parameters: when the operation signal contains the target heading angle change Δθ_target, it is processed as target guidance mode; when the operation signal only contains the steering wheel angle δ_sw, it is processed as position holding mode.
[0164] (3b-3) Generation of path point sequences
[0165] For any input type, after κ_cmd(t) is determined in the time interval [0, T_h], a path point sequence is generated by taking the current rear axle center position of the vehicle as the starting point (x(0)=0, y(0)=0 at t=0) and the current heading direction of the vehicle as the positive x-axis direction:
[0166]
[0167]
[0168] The heading angle θ(τ) is given by the following formula:
[0169]
[0170] In the formula, θ0 is the vehicle's current heading angle (unit: rad), provided by the integrated navigation system or inertial measurement unit; v(τ') is the speed planning value carried over from Traj_auto; τ and τ' are time integration variables (unit: s), representing the time offset calculated from the current moment; t is the current moment.
[0171] The above integration is performed numerically with a fixed discrete time step Δt (typically 20ms~100ms). Each path point (x(k·Δt), y(k·Δt)) corresponds to the desired position at time k·Δt from the current time, and the endpoint of the path point sequence is t=T_h. When the input type is the target heading angle input, the cumulative change in heading angle at the end of the time window θ(T_h)-θ0 is equal to Δθ_target, thus ensuring that the change in target heading angle is accurately realized.
[0172] In a single-trigger scenario, T_h is a fixed value. After time T_h, the path information in Traj_manual is automatically appended with the path point position and heading angle of Traj_auto at the corresponding time.
[0173] Meanwhile, the following curvature constraints must be satisfied during the generation of the path point sequence:
[0174] (i) Curvature amplitude constraint: Within the lateral time window T_h, the absolute value of κ_cmd must not exceed the vehicle's physical maximum curvature κ_max, where κ_max = ω_max / v. ω_max is determined by the following formula:
[0175] ω_max = min(v·tan(δ_max) / L, μ·g / v)
[0176] In the formula, δ_max is the maximum steering wheel angle (unit: rad), determined by the physical travel of the steering actuator; L is the vehicle wheelbase (unit: m). ω_max takes the smaller of the two terms because the vehicle's steady-state steering is subject to two physical constraints: one is the mechanical angle limit of the steering mechanism, described by Ackermann steering geometry; the other is the tire-road adhesion limit. Exceeding this limit will cause tire slippage, and steady-state steering cannot be maintained. The actual achievable yaw rate is determined by the more stringent of the two. μ is the road adhesion coefficient (dimensionless, ranging from 0 to 1), estimated in real time by the environmental perception module or road condition estimation algorithm based on the road type; g is the gravitational acceleration, taken as 9.8 m / s².
[0177] (ii) Curvature Change Rate Constraint: The desired rate of change of curvature also needs to be constrained to prevent sudden changes in steering commands from causing vehicle yaw instability. The rate of change of curvature κ in path planning. . That is, the derivative of curvature with respect to time, in meters. -1 ·s -1 Its absolute value must not exceed the preset comfort threshold κ. . _comfort. In this embodiment, the threshold value ranges from 0.05 to 0.1 m. -1 ·s -1Its calibration is based on the human body's tolerance to the rate of change of lateral acceleration—corresponding to a lateral acceleration of approximately 0.5~1.0 m / s³, which is within the comfortable range acceptable to most occupants. The upper limit of the actual rate of change of curvature κ... . _max is taken as the comfort threshold κ . The smaller of _comfort and the maximum rate of change of physical curvature of the steering actuator is used to ensure that the planned path shape simultaneously meets both comfort constraints and actuator capability constraints.
[0178] (3c) Full control
[0179] When longitudinal and lateral control are both in effect, the speed and path information in Traj_manual are generated independently. The longitudinal time window T_v and the lateral time window T_h may be different, and the overall time window takes the larger of the two, T = max(T_v, T_h).
[0180] Within the time interval [0, min(T_v, T_h)], information from both dimensions is valid simultaneously: speed information is executed according to vertical speed planning, and path information is executed according to horizontal path planning.
[0181] After exceeding min(T_v, T_h), the dimension that ends first enters the "preservation state"—specifically:
[0182] If T_v ends first (i.e., T_v < T_h), the speed information will be maintained at a constant speed of v_target after reaching the target vehicle speed v_target at time T_v until the end of the overall time window T.
[0183] If T_h ends first (i.e., T_h < T_v), after the path information reaches the final path point at time T_h, it continues to travel at a constant curvature with the curvature corresponding to that point (i.e., maintaining the final rate of change of heading angle) until the overall time window T ends.
[0184] The aforementioned "state maintenance" ensures that Traj_manual remains a complete and continuous trajectory throughout the overall time window T. After time T, the speed and path information of Traj_manual are automatically integrated with the planned values of Traj_auto at the corresponding time, and the vehicle returns to the original plan of the autonomous driving system.
[0185] When the longitudinal and lateral step sizes are inconsistent (e.g., longitudinal recursion every 50ms and lateral integration every 100ms), interpolation alignment is performed based on the smaller step size to ensure that the two trajectories can be compared point by point under the same time reference.
[0186] Trajectory generation under (3d) continuous holding command
[0187] In (3a) and (3b) above, the joystick and button have been mentioned as sources of commands, but the above description only applies to single-trigger scenarios (i.e., the command is determined immediately after the operator's transient operation). When the joystick or button is operated in a continuous mode—the command is valid when the operator holds the input and the command is reset to zero when the input is released—the processing logic of its trajectory time window is fundamentally different from that of the single-trigger scenario, as follows:
[0188] In this scenario, the trajectory time windows T_v and T_h are not fixed values, but rather dynamically updated variables. Apart from the "rolling update" and "post-release strategy," the rest of the trajectory generation (including target vehicle speed calculation, speed planning constraints, curvature integral formula, waypoint generation, etc.) are the same as described above, and will not be repeated here.
[0189] (i) Longitudinal control
[0190] During button presses or joystick operations, the system continuously updates the target vehicle speed in steps of trajectory planning cycles (e.g., 50ms). Each planning cycle re-reads the current vehicle speed v(k) and the current desired acceleration a_req(k), and recalculates the target vehicle speed v_target(k) and longitudinal time window T_v(k) according to the formula above. At this time, the endpoint of T_v(k) continuously shifts backward with the operator's continued input (i.e., "rolling extension"), and its physical meaning is always "the duration for which speed planning needs to continue from the current moment."
[0191] The acceleration command corresponds to pushing the joystick forward or pressing the acceleration button. The target vehicle speed update formula is:
[0192] v_target(k) = v(k) +a_req(k) · T_predict
[0193] The deceleration command corresponds to pulling back the joystick or pressing the deceleration button. The target vehicle speed update formula is as follows:
[0194] v_target(k) = v(k) - d_req(k) · T_predict
[0195] The system continuously monitors the vehicle speed change rate. If the speed change is less than the preset minimum change threshold (speed increase of less than 1 km / h during acceleration, speed decrease of less than 1 km / h during deceleration) within a continuous period of 3 to 5 seconds (3 seconds in this embodiment), it indicates that the vehicle has reached the speed limit under the current road conditions. The system then automatically stops updating the speed and sets the current speed as the target speed, maintaining stable driving at that speed while awaiting further instructions from the operator. If the operator releases the controller during this period, coasting deceleration is triggered. If the vehicle consistently achieves effective acceleration or deceleration, the system continues updating until the speed approaches the vehicle's maximum speed or the current road speed limit, at which point it automatically stops.
[0196] The speed transitions smoothly from the current value to the target value (if the target value continues to change, it is actually manifested as continuous acceleration or deceleration with an approximately constant acceleration). The absolute value of the acceleration does not exceed a_acc (during acceleration) or a_dec (during deceleration), and the jerk does not exceed the preset maximum jerk J_max (in this embodiment, the value range is 3~5 m / s³). If v_target exceeds the vehicle's maximum speed or is lower than 0, the speed is directly limited.
[0197] After the operator releases the command, the longitudinal control automatically switches to the coasting deceleration strategy. Coasting deceleration refers to gradually reducing the vehicle speed at a preset small deceleration rate (e.g., 0.5~1.5m / s²), simulating the process of the vehicle naturally decelerating due to driving resistance when the driver releases the accelerator pedal without driving force.
[0198] (ii) Lateral control
[0199] While the joystick is continuously deflected or the turn button is held down, the system uses κ_cmd(t) = κ_max · u_steer as the desired curvature, where u_steer is the normalized turn command, ranging from -1 to 1, with positive values corresponding to right turns and negative values corresponding to left turns.
[0200] The lateral time window T_h extends continuously as the operation continues (in steps of 0.2~0.5s). Each planning cycle generates a new waypoint by integrating κ_cmd starting from the current heading angle. The heading is continuously accumulated, and its update formula is the same as above:
[0201] θ(t) = θ0+ ∫κ_cmd · v · dt
[0202] In practice, T_h is determined using the aforementioned rolling dynamic method. Each planning cycle recalculates the endpoint of T_h based on the current operator's continuous input state—that is, the end point of the time window is shifted forward by one step each frame. Therefore, T_h does not have a single fixed duration upper limit preset in traditional control schemes (e.g., a fixed timeout of 5 seconds for forced exit); its upper limit is dynamically determined entirely by the operator's actual continuous input duration. When the operator continues to input, T_h increases with the holding time; when the operator releases the command, the rolling update of T_h terminates, and the system immediately switches to the subsequent self-aligning holding strategy.
[0203] This processing method not only meets the needs of long-duration operation scenarios such as continuous turning or circling, but also precisely corresponds to the aforementioned definition of the "physical meaning of the time window" through "rolling dynamic determination"—T_h always represents "the duration for which path planning needs to continue to be executed from the current moment." When the vehicle reaches the physical maximum curvature κ_max, κ_cmd is automatically limited and cannot continue to increase the curvature. The vehicle continues to turn at the maximum curvature, waiting for further instructions from the operator.
[0204] After the operator releases the command, κ_cmd returns to zero, and the vehicle continues to travel in a straight line along the current heading for a preset holding window, such as 0.5~1.5s, i.e., self-centering and holding. If a new lateral command is received within the holding window, the straight-line travel is immediately interrupted, and the vehicle switches back to follow mode; if no new command is received after the holding window ends, the straight-line travel state is maintained, waiting for further operation from the operator.
[0205] (iii) Full control
[0206] When both vertical and horizontal inputs are continuous, they are updated independently according to the rules described above, without affecting each other. The overall trajectory time window is the larger of the two values, T = max(T_v, T_h). Within the interval [0, min(T_v, T_h)], both vertical velocity information and horizontal path information are valid simultaneously. Beyond this interval, the dimension that ends first retains the value of its endpoint (vertical velocity remains constant, horizontal curvature remains constant) until the other dimension also ends, thus completing the entire trajectory. When the vertical and horizontal step sizes are inconsistent, interpolation alignment is performed based on the smaller step size, and the specific implementation method is the same as above.
[0207] In this step, the specific calculation method for the degree of human-machine decision-making conflict, D, is as follows:
[0208] Compare Traj_auto and Traj_manual to calculate the degree of human-machine decision-making conflict, D. The larger the value of D, the more serious the human-machine disagreement.
[0209] This embodiment employs Dynamic Time Warping (DTW) to calculate the conflict severity value. This is because takeover scenarios commonly involve operator reaction delays, communication transmission delays, and actuator lags, leading to uncertain misalignments between `Traj_manual` and `Traj_auto` on the time axis. Area integration and mean Euclidean distance methods both require forced time alignment point-by-point, which may incorporate time-delay-induced misalignments into trajectory deviation calculations in such scenarios. Hausdorff distance focuses on the maximum single-point distance, which may amplify local deviations due to instantaneous jumps in such scenarios. DTW can automatically seek the optimal time alignment path between two trajectories through dynamic programming, effectively absorbing time-delay misalignments; therefore, it is the preferred solution in this embodiment.
[0210] The specific method for calculating the conflict level value using the Dynamic Time Warping (DTW) algorithm is as follows:
[0211] Let the trajectory point sequence of Traj_auto be A={a1,...,a_m}, and that of Traj_manual be B={b1,...,b_n}, where each point contains position (x,y), velocity v, and heading angle θ.
[0212] Construct a cumulative distance matrix M with dimensions (m+1)×(n+1), and initialize it with M(0,0)=0 and M(i,0)=10. 6 (i=1...m), M(0,j)=10 6 (j=1...n). Setting a sufficiently large constant ensures that illegal paths will not be selected when the trajectory points match an empty sequence.
[0213] The minimum cumulative distance between points on the two trajectories is calculated point by point using dynamic programming. The recursive formula is: M(i,j)=d(a_i,b_j)+min{M(i-1,j), M(i,j-1), M(i-1,j-1)}.
[0214] The core function of this recursive formula is to find the optimal time alignment path between two trajectories. The three terms in min{} represent three different time alignment methods: vertical step M(i−1,j) means aligning the (i−1)th point of Traj_auto with the jth point of Traj_manual before matching the current point (i.e., repeated matching of the current point in Traj_manual); horizontal step M(i,j−1) means aligning the i-th point of Traj_auto with the (j−1)th point of Traj_manual before matching the current point (i.e., repeated matching of the current point in Traj_auto); diagonal step M(i−1,j−1) means matching the current points of the two trajectories one-to-one. The algorithm selects the direction with the minimum cumulative distance from the three methods and proceeds, ultimately calculating M(m,n), which represents the degree of human-machine decision conflict D.
[0215] The single-point distance d(a_i,b_j) is calculated as follows:
[0216] First, calculate the deviations of Traj_auto and Traj_manual in the three dimensions:
[0217] Positional deviation: Δp=(x_i-x_j)²+(y_i-y_j)², in meters;
[0218] Speed deviation: Δv = |v_i - v_j|, in meters per second;
[0219] Heading angle deviation: Δθ=min(|θ_i-θ_j|,2π-|θ_i-θ_j|), in radians;
[0220] Where (x_i, y_i), v_i, and θ_i are the position coordinates, velocity, and heading angle of the i-th point in Traj_auto; (x_j, y_j), v_j, and θ_j are the corresponding values of the j-th point in Traj_manual; the heading angle deviation formula is used to limit the deviation to the range of 0 to π in order to handle the problem of angle jumps across the 0° / 360° boundary.
[0221] Then, the deviations are normalized and mapped to the [0,1] interval:
[0222] Position deviation normalization: Δp_norm = Δp / Δp_max, where Δp_max is the preset maximum allowable position deviation;
[0223] Speed deviation normalization: Δv_norm = Δv / Δv_max, where Δv_max is the preset maximum allowable speed deviation;
[0224] Normalization of heading angle deviation: Δθ_norm = Δθ / π, since the maximum heading angle deviation is π radians;
[0225] Finally, the weighted sum of the three dimensionless deviations after normalization is taken to obtain the single-point distance:
[0226] d(a_i,b_j) = w_p·Δp_norm + w_v·Δv_norm + w_θ·Δθ_norm
[0227] Among them, w_p, w_v, and w_θ are the weighting coefficients of position deviation, speed deviation, and heading angle deviation, respectively, and the sum of the three is 1. Their values are determined by the control mode and the current vehicle speed.
[0228] Under different control modes, the weights of deviations in the three dimensions of position, speed, and heading angle on driving safety vary. Therefore, the basic weights for each control mode are pre-calibrated as follows:
[0229] For longitudinal control: w_p=0.25, w_v=0.60, w_θ=0.15;
[0230] When used for lateral control: w_p=0.50, w_v=0.20, w_θ=0.30;
[0231] When full control is enabled: w_p=0.40, w_v=0.35, w_θ=0.25.
[0232] Based on this, under high-speed conditions, the same absolute speed deviation corresponds to higher collision energy and a shorter avoidance distance, and its impact on driving safety should be weighted accordingly. However, under low-speed conditions, positional deviation has a dominant impact on safety, while the impact of speed deviation is relatively limited. Therefore, w_v needs further correction based on the current vehicle speed, while w_p and w_θ are adjusted synchronously with w_v to maintain their relative proportional relationship, ensuring that the sum of the three is always 1.
[0233] Specifically, first determine the basic weights w_p, w_v, and w_θ under the current control mode according to the table above, and then correct w_v for vehicle speed according to the following formula:
[0234] w_v′ = w_v·(1+λ·v / v_ref)
[0235] Where v is the current vehicle speed, v_ref is set to 80 km / h as the reference speed, and λ∈[0.1, 0.3] is the correction strength coefficient, the specific value of which is determined by the vehicle manufacturer through actual vehicle testing. After correction, w_p and w_θ are renormalized with w_v′ according to the following formula to obtain the final weights at the current vehicle speed:
[0236] w_p(v) = w_p / (w_p + w_v′ + w_θ)
[0237] w_v(v) = w_v′ / (w_p + w_v′ + w_θ)
[0238] w_θ(v) = w_θ / (w_p + w_v′ + w_θ)
[0239] After normalization, w_p(v) + w_v(v) + w_θ(v) = 1 always holds true, and the ratio of w_p to w_θ remains unchanged. When the vehicle speed is below 30 km / h, the speed deviation has a limited impact on driving safety, so the above speed correction is not performed, and the basic weights are used directly.
[0240] As an alternative to DTW, trajectory deviation can also be measured using any of the following methods: area integration, mean Euclidean distance, or Hausdorff distance. Area integration measures the degree of deviation by calculating the area enclosed between the two trajectory curves; mean Euclidean distance calculates the average positional deviation point by point; and Hausdorff distance focuses on the maximum deviation between the two trajectories. Before using any of these methods, the two trajectories must be aligned to the same sampling sequence along the time axis (using the one with more sampling points as the baseline, and interpolating the other to complete the sequence). The specific calculation formulas are common knowledge in this field and will not be elaborated here. In practical engineering applications, the appropriate method can be flexibly selected based on computing resources and real-time requirements.
[0241] Processing multiple candidate trajectories:
[0242] The distance metrics described above are comparisons between single trajectories. In real-world scenarios, the decision planning module may output multiple candidate trajectories simultaneously, each assigned a probability value p_i (Σp_i=1) reflecting the confidence level of that trajectory under the current environmental perception. In this case, the conflict level is calculated as a weighted average of the DTW distances of all candidate trajectories:
[0243] D = Σ(p_i · d_i)
[0244] Where d_i is the DTW distance between the i-th candidate trajectory and the manually instructed trajectory. p_i is updated every frame with environmental perception information.
[0245] Step (4): Three-interval hierarchical decision making
[0246] Compare D with the preset first threshold D1 and second threshold D2. If the second threshold D2 is greater than the first threshold D1, map the intervention command to one of the three mutually exclusive decision intervals:
[0247] (4a) If D < D1, it means that the intentions of the human and machine are basically consistent, and the machine directly enters the takeover zone and directly executes the intervention command.
[0248] (4b) If D > D2, it indicates a serious conflict between human and machine intentions, and the system enters the safety constraint takeover zone. Within this zone, the system does not directly execute the intervention command, nor does it completely block it. Instead, it calculates the human-machine co-driving weight, weights and fuses the human command and the autonomous driving command, and then executes them to achieve smooth processing and gain attenuation of the intervention command, thus achieving a safety compromise control under conflict conditions.
[0249] (4c) If D1 ≤ D ≤ D2, it means that there is a disagreement between the human and the machine but no verification is performed. The machine enters the verification and takeover zone and the operator's intention needs to be further authenticated. If the authentication is successful, the intervention command is executed. If the authentication fails, the automatic driving mode is maintained.
[0250] The above D1 and D2 are pre-calibrated and dynamically adjusted thresholds, which are determined as follows:
[0251] D1 and D2 are obtained by multiplying the base thresholds D1_base and D2_base by the dynamic coefficient f. D1_base and D2_base are pre-calibrated fixed baseline values. During calibration, multiple test conditions with different vehicle speeds and road curvatures are set in a simulation environment or real-world vehicle testing. DTW distance values representing the differences in human-machine trajectory are collected under each condition, establishing a DTW distance distribution for conflict samples. The 5th percentile of this distribution is designated as D1_base, and the 50th percentile as D2_base. f is calculated in real-time based on the current vehicle speed, road curvature, and environmental risk to achieve adaptive adjustment of the thresholds for different driving conditions.
[0252] The adaptive adjustment method is as follows. First, the dynamic coefficient f is calculated based on the current driving state:
[0253] f = 1 + k · (a_y / a_y_max)
[0254] Where a_y = v² · ρ, v is the current vehicle speed, and ρ is the road curvature (unit: m). -1 The value of ρ is provided by the environmental perception module or high-precision map and is defined as the curvature of the road centerline at the vehicle's current location, i.e., the reciprocal of the road radius; a_y_max = μ·g, where μ is the road adhesion coefficient and g is the gravitational acceleration; k is the lateral acceleration influence coefficient, which physically represents the sensitivity of the threshold increase when the lateral acceleration approaches the adhesion limit, with a value range of 0.5~2.0, and the specific value is calibrated through actual vehicle testing. When |ρ| < 10 -6 m -1 When the road is on a straight or near-straight road segment, ρ=0 is set to avoid interference from perceived noise on the threshold adjustment. When the vehicle is traveling on a straight road, ρ≈0, a_y≈0, f≈1, and the threshold remains at the base value. When a_y / a_y_max increases, f increases accordingly, D1 and D2 are raised simultaneously, and the threshold for direct execution of manual commands is increased.
[0255] If the environmental perception module also provides an environmental risk level r (generated in real time by the environmental perception module based on current weather, light intensity, traffic density, and other environmental information, with a value ranging from 0 to 1), then the above formula is further modified as follows:
[0256] f = 1 + k · (a_y / a_y_max) + k_r · r
[0257] Where k_r is the environmental risk weighting coefficient, which physically represents the sensitivity of environmental risk to threshold adjustment, and its value ranges from 0.2 to 0.5. The specific value is determined through simulation or real vehicle testing and calibration. When there is no environmental risk information, r=0, and the above formula automatically degenerates into the previous formula.
[0258] The final thresholds are as follows:
[0259] D1 = D1_base · f
[0260] D2 = D2_base · f
[0261] Regarding the above (4b) when entering the security constraint takeover zone, the specific implementation method of the weighted fusion involved is as follows:
[0262] Specifically, the system calculates the human-machine co-driving weight w using the Sigmoid function:
[0263] w = 1 / (1 + e^{k·(D - D2)})
[0264] The function follows an S-shaped curve: when D is slightly greater than D2, w is around 0.5, with human and machine control each having roughly equal control; as D further increases, w continuously decreases along the S-shaped curve; when D is much greater than D2, w approaches 0, almost entirely relying on the autonomous driving system. This continuous change mechanism avoids abrupt changes in control at the interval boundaries, preventing vehicle malfunctions. Using D2 as the center point of the Sigmoid function ensures a smooth transition of control as soon as the conflict level exceeds the second threshold.
[0265] Where k is a preset slope coefficient, the specific value of which is determined through actual vehicle testing. During calibration, the rate of change of the vehicle's yaw rate during the control handover process does not exceed a preset comfort threshold ω. . _comfort (in this embodiment, the value ranges from 0.3 to 0.8 rad / s², calculated based on the upper limit of lateral acceleration comfort of 0.6 to 0.9 m / s³) is used as a constraint, and a k value is selected to make the system response smoother. The larger the k value, the more concentrated the change of weights within the transition band, and the faster the control switching; the smaller the k value, the smoother the transition and the gentler the switching. Typically, the value of k ranges from 2.0 to 5.0, and in this embodiment, k=3.0 is preferred.
[0266] After determining w, let u_manual be the desired control quantity corresponding to the intervention command, and u_auto be the desired control quantity currently output by the autonomous driving system. Then, the fused target control quantity is:
[0267] u_target = w·u_manual + (1-w)·u_auto
[0268] The system dynamically updates the weights according to the trajectory planning cycle and performs comfort verification on u_target: it calculates the corresponding acceleration change rate (jerk) and curvature change rate, ensuring that the absolute value of the jerk does not exceed the preset maximum jerk J_max, and the absolute value of the curvature change rate does not exceed the preset maximum curvature change rate κ˙_max. The specific values of both are pre-calibrated based on the vehicle's dynamic characteristics and ride comfort requirements to prevent jitter caused by weight changes on the time axis. Simultaneously, it outputs takeover prompts to the operator.
[0269] Regarding the above (4c) entry into the verification takeover zone, the specific implementation method of operator intent authentication is as follows: At this time, there is a disagreement between the human and machine, but it is not serious yet. It is necessary to distinguish between "intentional intervention" and "accidental touch" through operator intent authentication. The operation intent is reflected in the behavior pattern of the operation signal. In this embodiment, three features are extracted from the operation signal for comprehensive judgment:
[0270] (i) Duration characteristics
[0271] Map the duration t to a probability:
[0272] P_duration = 1 - exp(-t / τ)
[0273] Where τ is the time constant, which is 150ms in this embodiment. The physical meaning of this function is: the longer the duration, the higher the probability of intentional operation, and the growth rate gradually slows down, which conforms to the characteristics of an exponential distribution.
[0274] (ii) Directional consistency feature
[0275] Let n be the number of times the operation direction changes within a preset time window (e.g., 500ms), and map the consistency of direction to probability:
[0276] P_consistency = exp(-λ · n)
[0277] Where λ is the attenuation coefficient, which is taken as 0.5 in this embodiment. The physical meaning of this function is: the fewer the changes in direction, the more likely the operation is intentional, and the probability decreases exponentially with the number of changes.
[0278] (iii) Frequency domain energy ratio characteristics
[0279] Perform a Fast Fourier Transform on the operating signal and calculate the ratio R = E_low / E_high, which represents the energy in the low-frequency band (0~5Hz) to the energy in the high-frequency band (>15Hz). Map R to a probability:
[0280] P_frequency = 1 / (1 + exp(-k_freq · (R - R0)))
[0281] Where R0 is the decision boundary, which is 3.0 in this embodiment; k_freq is the slope coefficient, which is 1.5 in this embodiment. This sigmoid function maps energy ratio smoothness to probability, and its physical meaning is: the higher the proportion of low-frequency components, the smoother the operation, and the more likely it is to be an intentional operation.
[0282] The three features described above characterize the behavioral patterns of the operation signal from the dimensions of time, direction, and frequency, respectively. They have different physical meanings and are not necessarily coupled with each other. In this embodiment, during the calibration process, Pearson correlation analysis was performed on 2000 sets of valid operation samples: the correlation coefficient between duration and rate of change of direction was approximately -0.15, the correlation coefficient between duration and frequency domain energy ratio was approximately 0.08, and the correlation coefficient between rate of change of direction and frequency domain energy ratio was approximately 0.12, all showing weak correlation or no correlation (|r|<0.3). Therefore, using a product-based fusion method is reasonable. The reliability characterization C is calculated as follows:
[0283] C = P_duration · P_consistency · P_frequency
[0284] C∈[0,1], when C exceeds the preset threshold C_th (0.5 in this embodiment), the authentication is deemed successful and the intervention command is executed; otherwise, the automatic driving mode is maintained and feedback information is generated.
[0285] For example: When remotely parking, if the driver moves the joystick to the left for 500ms without changing the direction, and the frequency domain energy ratio R=6, the calculated C≈0.95, and the authentication passes. If it is a mis-touch—pressed for only 60ms, with 4 direction changes, R=1.5, C≈0.005, the system will not respond.
[0286] Step (5): Emergency Evacuation Priority Logic
[0287] The emergency avoidance priority logic is as follows: when the emergency avoidance conditions are met, depending on the current decision-making interval, selectively cancel the processing steps that should have been executed in the corresponding interval, and directly execute the intervention command in full.
[0288] Specifically, in step (4b) within the interval D > D2, the system should smooth or attenuate the manual commands; in step (4c) within the interval D1 ≤ D ≤ D2, the system should authenticate the operator's intent. If, during the above process, the collision time between the vehicle and any obstacle is detected to be less than a preset safety threshold, and the current planned trajectory of the autonomous driving system does not contain effective avoidance measures, then the emergency avoidance priority logic is triggered—skipping the above-mentioned restrictions in their respective intervals and directly executing the full amount of manual commands.
[0289] Taking a forward collision as an example: TTC = d_rel / v_rel (no collision risk when v_rel ≤ 0), the safety threshold is 2s, and effective avoidance measures refer to expected deceleration of not less than 0.1g or a steering avoidance command. When the conditions are met, if D > D2, the smooth decay is skipped; if D1 ≤ D ≤ D2, authentication is skipped and full execution is performed directly.
[0290] This logic addresses scenarios where a system fails to respond effectively due to a perceived oversight (such as an irregular obstacle) or a planning error, while the driver has reacted correctly. The logic also applies to other collision scenarios, such as vehicles approaching from the side or obstacles behind the vehicle while reversing.
[0291] It should be noted that the full execution of manual commands in the emergency avoidance priority logic is a trade-off made based on engineering judgments that the system has no effective avoidance options and the avoidance time window is limited, rather than pre-setting that manual commands are superior to the autonomous driving system's decisions in all circumstances. If post-event analysis confirms that the operation was inappropriate, it can serve as data for system calibration optimization and operator training.
[0292] Step (6): Continuous monitoring and feedback information generation after takeover
[0293] (6a) Continuous monitoring after takeover
[0294] After the operator takes over the vehicle, the system continuously compares the deviation between the vehicle's actual driving trajectory and Traj_manual. If the deviation exceeds the third threshold D3 and the duration exceeds the threshold Δt_exceed (0.5s in this embodiment), it indicates that the operator may have deviated from the original operating direction or that there is a problem with the operation itself. The system automatically exits manual takeover and resumes automatic driving mode.
[0295] The deviation is based on the start time of takeover. The actual driving state of the vehicle at the current time is compared point by point with the expected driving state at the same time offset in Traj_manual. The weighted comprehensive deviation is calculated in the same way as the single-point distance calculation method defined in step (3).
[0296] The third threshold D3 is determined by the product of the base deviation threshold D3_base and the dynamic environmental risk coefficient α:
[0297] D3 = D3_base · α
[0298] The calibration method for D3_base is as follows: A weighted comprehensive deviation sample between the actual trajectory of the target vehicle and Traj_manual under various typical normal takeover scenarios is collected. The 95th percentile of this sample distribution is used as the initial calibration value of D3_base. Then, it is verified and fine-tuned through typical erroneous operation scenarios to ensure that D3_base simultaneously meets the dual requirements of a false exit rate below a preset threshold under normal operation and reliable triggering of the safety fallback logic under erroneous operation. In this embodiment, the typical value range of D3_base is 0.05~0.20 (dimensionless).
[0299] α is calculated based on the minimum distance d_min between the vehicle and surrounding obstacles and the relative approach speed v_rel, as shown in the following formula:
[0300] α = 1 + k1 / d_min + k2·max(v_rel, 0)
[0301] Where k1∈[0.5, 2.0], k2∈[0.1, 0.5]. If multiple obstacles exist at the same time, calculate α_i for each obstacle, and take α = max(α_i) as the comprehensive risk coefficient.
[0302] For example, when the vehicle is surrounded by open space, α ≈ 1, and D3 remains at its baseline value, making the system relatively sensitive to operational deviations. When the vehicle approaches an obstacle or an obstacle approaches rapidly, d_min decreases, v_rel increases, α increases accordingly, and D3 increases accordingly, increasing the system's tolerance for operational deviations and preventing frequent exits from interfering with the operator in scenarios requiring precise control. If the deviation duration exceeds Δt_exceed, exit and takeover are still triggered to ensure a safety fallback. If, after resuming autonomous driving mode, the system determines based on environmental perception information that it cannot continue to maintain safe operation under the current driving conditions, it automatically triggers the minimum risk operation, controlling the vehicle to decelerate and pull over.
[0303] (6b) Feedback information generation
[0304] When an intervention command is suppressed or smoothed out, the system generates feedback information and sends it to the human input interface, informing the operator of the current processing status and reason for the command. The correspondence between feedback and decision intervals is as follows:
[0305] (1) When the authentication in steps (4a) and (4c) is successful, the unified feedback is "Takeover successful, in progress".
[0306] (2) If authentication fails in step (4c), it is further divided into two situations and corresponding prompts are given:
[0307] When it is a "mistaken operation", that is, the operation time is significantly shorter and the direction changes frequently, the message "operation too short, ignored" will be displayed.
[0308] When it is a "hesitant operation," meaning the characteristics are between intentional and unintentional, the message "Operation unclear, ignored" is displayed.
[0309] (3) When the weighted fusion is performed in step (4b), it is classified as "conflict with the current decision" and the message "the instruction conflicts with the system decision and has been safely attenuated" is displayed.
[0310] (4) When the emergency avoidance priority logic in step (5) is triggered, the feedback is "Emergency avoidance, in progress".
[0311] (5) When the takeover is triggered in step (6a) due to the deviation exceeding the third threshold D3 and the duration exceeding the threshold Δt_exceed, the feedback is "Takeover failure, automatic driving has been restored".
[0312] The aforementioned feedback information can be sent through one or more of the following methods: dashboard text or icons, head-up display projection, voice broadcast, steering wheel vibration, remote control vibration, and mobile terminal push notification.
[0313] Example 2
[0314] A manual takeover prevention and control system for autonomous vehicles is provided for executing the manual takeover prevention and control method for autonomous vehicles in Embodiment 1.
[0315] like Figure 2 As shown, the system includes: a trajectory acquisition module 100, a trajectory mapping module 200, a safety detection module 300, a conflict measurement module 400, a hierarchical decision-making module 500, and a safety monitoring module 600. All these modules are integrated into a processor 700 and are uniformly scheduled and executed by the processor 700. The system also includes a manual input interface 800 as an external input device. The first expected driving trajectory is provided in real time by the decision-planning module.
[0316] The data flow between modules is as follows:
[0317] When the manual input interface 800 receives an intervention command, it simultaneously sends the intervention command to the trajectory acquisition module 100, the trajectory mapping module 200, and the safety detection module 300, triggering the parallel execution of the three.
[0318] After receiving an intervention instruction trigger, the trajectory acquisition module 100 acquires and temporarily stores the first expected driving trajectory Traj_auto at the current moment, and sends it to the conflict measurement module 400; the trajectory mapping module 200 generates a second expected driving trajectory Traj_manual with a trajectory time window according to the control mode of the intervention instruction, and sends it to the conflict measurement module 400; the safety detection module 300 performs input safety detection on the intervention instruction, shields the instruction and discards the temporarily stored Traj_auto if the detection fails, and sends a release signal to the conflict measurement module 400 after the detection passes.
[0319] After receiving the release signal, the conflict measurement module 400 calculates a trajectory deviation measure based on Traj_auto and Traj_manual as the human-machine decision conflict degree D, and sends the human-machine decision conflict degree D to the hierarchical decision module 500.
[0320] The hierarchical decision module 500 makes a corresponding decision according to the interval where the human-machine decision conflict degree D lies: when D<D1, direct takeover is executed; when D1≤D≤D2, it enters a verification takeover interval, invokes an internally integrated intention authentication sub-module, extracts time-domain and frequency-domain behavior features from the operation signal, and calculates a credibility representation C. If C exceeds the threshold C_th, the authentication is determined to be passed, and the intervention instruction is executed, otherwise the automatic driving mode is maintained; when D>D2, it enters a safety-constrained takeover interval, and outputs a control instruction after smoothing processing or gain attenuation. The hierarchical decision module 500 sends the decision result to the safety monitoring module 600, and outputs a control command to the vehicle actuator. The safety monitoring module 600 acquires the deviation between the actual driving trajectory of the vehicle after takeover and the second expected driving trajectory; when the deviation exceeds D3 and the duration exceeds the threshold T_exceed, it automatically exits manual takeover and restores the automatic driving mode.
[0321] The processor 700 executes program instructions stored in an internal memory to implement the functions of the above modules. Data interaction between each module is performed through a vehicle bus.
[0322] The above serial numbers of the embodiments of the present invention are only for description, and do not represent the advantages or disadvantages of the embodiments.
[0323] The above description is only a preferred embodiment of the present invention, and is not intended to limit the present invention. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A method for preventing misjudgment during manual takeover control in an autonomous vehicle, characterized in that, The method includes: S1: When the vehicle is in autonomous driving mode and receives an intervention command from the human input interface, The system acquires and temporarily stores a first expected driving trajectory generated by the autonomous driving system at the current moment, and simultaneously generates a second expected driving trajectory with a trajectory time window based on the control mode carried by the intervention command; and performs input safety detection on the intervention command. S2: If the input safety check fails, the intervention command is blocked, the temporarily stored first expected driving trajectory is discarded, and the autonomous driving mode is maintained; if it passes, proceed to S3. S3: Calculate the trajectory deviation measure between the first expected driving trajectory and the second expected driving trajectory, as the degree of human-machine decision-making conflict; S4: If the degree of human-machine decision conflict is less than the first threshold D1, then the intervention command is executed; if the degree of human-machine decision conflict is greater than the second threshold D2, then the intervention command is smoothed or attenuated before execution, and a takeover prompt message is output, wherein the second threshold D2 is greater than the first threshold D1; if the degree of human-machine decision conflict is greater than or equal to the first threshold D1 and less than or equal to the second threshold D2, then the operator's intent is authenticated; if the authentication is successful, then the intervention command is executed; if the authentication fails, then the automatic driving mode is maintained.
2. The method for preventing misjudgment during manual takeover in an autonomous vehicle according to claim 1, characterized in that, The trajectory time window includes a longitudinal time window and / or a lateral time window; the longitudinal time window is the time required for the speed to transition from the current vehicle speed to the target vehicle speed; the lateral time window is the duration for which the path curvature continues to act. The first expected driving trajectory is a sequence of desired driving states generated based on environmental perception information; The second expected driving trajectory is obtained by converting the intervention command through the command-trajectory mapping rule. The command-trajectory mapping rule converts the intervention command into a desired driving state sequence based on the control mode identifier carried by the intervention command. The control mode includes: planning only speed information during longitudinal control, planning only path information during lateral control, and planning both speed information and path information during full control.
3. The method for preventing misjudgment during manual takeover in an autonomous vehicle according to claim 2, characterized in that, The longitudinal time window is determined as follows: Calculate the target vehicle speed v_target: v_target = v + a_req·T_predict or v_target = v-d_req·T_predict; Where v is the current vehicle speed, T_predict is the prediction time window, a_req is the expected acceleration, and d_req is the expected deceleration; If v_target > v, then the longitudinal time window T_v = (v_target-v) / a_acc + t_margin; if v_target < v, then the longitudinal time window T_v = (v-v_target) / a_dec + t_margin, where a_acc is the preset maximum safe acceleration, a_dec is the preset maximum safe deceleration, and t_margin is the preset response margin time. The longitudinal control, which only plans speed information, specifically includes: Once the longitudinal time window T_v is determined, a speed plan is generated within the time interval [0, T_v]. The speed plan starts with the current vehicle speed v and ends with the target vehicle speed v_target, smoothly transitioning within the longitudinal time window T_v and satisfying the following constraints: Acceleration amplitude constraint: Within the longitudinal time window T_v, the absolute value of acceleration in speed planning must not exceed the maximum safe acceleration a_acc or the maximum safe deceleration a_dec. At the same time, the target vehicle speed v_target must not exceed the current road speed limit and the vehicle's physical maximum speed, nor be lower than 0. Acceleration rate of change constraint: The absolute value of the rate of change of acceleration in velocity planning must not exceed the preset comfort threshold. .
4. The method for preventing misjudgment during manual takeover control in an autonomous vehicle according to claim 3, characterized in that, The lateral time window is determined by the source type of the intervention command: When the intervention command originates from a momentary position input via the steering wheel, there are two operating modes: Position holding mode: The horizontal time window T_h is determined by the operator's continuous holding duration; Goal-oriented model: The lateral time window T_h is calculated using the following formula: T_h = Δθ_target / ω_max + t_margin_steer; Where Δθ_target is the change in the target heading angle, ω_max is the maximum yaw rate of the vehicle, and t_margin_steer is the steering response margin; The path information planned during lateral control specifically includes: Starting from the current rear axle center position of the vehicle and taking the current heading direction of the vehicle as the positive x-axis, generate a path point sequence through curvature integral within the time interval [0, T_h]: Among them, heading angle θ0 is the vehicle's current heading angle, v(τ') is the speed planning value carried over from the first expected driving trajectory, v(τ) is the speed value at time τ, τ and τ' are time integration variables, representing the time offset calculated from the current time, t is the current time, and κ_cmd is the desired curvature, determined according to the intervention command. Meanwhile, the following curvature constraints must be satisfied during the generation of the path point sequence: Curvature amplitude constraint: Within the lateral time window T_h, the absolute value of the desired curvature κ_cmd must not exceed the vehicle's physical maximum curvature κ_max; Curvature change rate constraint: the rate of change of the desired curvature κ_cmd . The absolute value must not exceed the preset comfort threshold κ. . _comfort.
5. The manual takeover control method for preventing misjudgment in an autonomous vehicle according to claim 4, characterized in that, During full-scale control, the simultaneous planning of speed and path information specifically includes: The overall time window T is the larger of the vertical time window T_v and the horizontal time window T_h; Within the time interval [0, min(T_v, T_h)], speed information is executed according to longitudinal control planning, and path information is executed according to lateral control planning; If T_v ends first after exceeding min(T_v, T_h), the speed information will be maintained at the target speed v_target after reaching the target speed v_target at time T_v until the end of the overall time window T. If T_h ends first, the path information reaches the final path point at time T_h and continues to travel at a constant curvature with the curvature corresponding to that point until the overall time window T ends.
6. The method for preventing misjudgment during manual takeover in an autonomous vehicle according to claim 5, characterized in that, When the intervention command is a continuous holding command from a joystick or button, the intervention command is effective while the operator continues to input and returns to zero when the input is released; during the duration of the continuous holding command, the trajectory time window is recalculated and rolled over in each planning cycle based on the current vehicle state; after the continuous holding command is released, the longitudinal control switches to the coasting deceleration strategy, and the lateral control switches to the self-centering holding strategy with zero curvature.
7. The manual takeover control method for preventing misjudgment in an autonomous vehicle according to claim 1, characterized in that, The input security detection includes at least one of the following strategies: When the same intervention command is received consecutively and the time interval between two adjacent intervention commands is less than the preset minimum interval, or the reception frequency of the same intervention command within a preset time exceeds the preset maximum frequency, the intervention command is determined to be abnormal and the intervention command is blocked. For intervention commands other than persistent commands, when multiple intervention commands are received within a preset time window, if an emergency command is included, all non-emergency commands are suppressed and only the emergency command is executed. If there is no emergency command but there is a pair of mutually exclusive commands, all intervention commands are suppressed. If the intervention command is not a persistent command and is a repetitive command of the same type, only the first one that arrives will be executed, and the rest will be suppressed.
8. The method for preventing false judgment during manual takeover in an autonomous vehicle according to claim 1, characterized in that, The degree of human-machine decision-making conflict is calculated using any one of the following methods: dynamic time warping algorithm, area integration method, average Euclidean distance, or Hausdorff distance. The dynamic time warping algorithm specifically includes: Each trajectory point in the first and second expected driving trajectories includes position (x, y), velocity v, and heading angle θ; By dynamically programming, the minimum cumulative distance between each point on the first and second expected driving trajectories is calculated point by point. The recursive formula is as follows: M(i,j)=d(a_i,b_j)+min{M(i-1,j), M(i,j-1), M(i-1,j-1)}; In this context, the three terms in min{} represent three different time alignment methods: vertical step M(i-1,j) means aligning the i-1th point of the first expected driving trajectory with the jth point of the second expected driving trajectory before matching the current point; horizontal step M(i,j-1) means aligning the i-th point of the first expected driving trajectory with the j-1th point of the second expected driving trajectory before matching the current point; and diagonal step M(i-1,j-1) means matching the current points of the two expected driving trajectories one-to-one, selecting the direction with the smallest cumulative distance from the three methods to advance, thus obtaining the degree of human-machine decision conflict. The single-point distance d(a_i,b_j) is obtained by weighted summation after normalizing the position deviation, velocity deviation, and heading angle deviation: d(a_i,b_j)=w_p·Δp_norm+w_v·Δv_norm+w_θ·Δθ_norm; where Δp_norm, Δv_norm, and Δθ_norm are the normalized position deviation, velocity deviation, and heading angle deviation, respectively, and w_p, w_v, and w_θ are the corresponding weight coefficients, and the sum of the three is 1.
9. The manual takeover control method for preventing misjudgment in an autonomous vehicle according to claim 1, characterized in that, The first expected driving trajectory is one or more candidate trajectories; when there are multiple candidate trajectories, each candidate trajectory is assigned a corresponding probability value, and the sum of the probability values is 1. The degree of human-machine decision conflict is taken as the weighted average of the trajectory deviation measurement between each candidate trajectory and the second expected driving trajectory.
10. The method for preventing misjudgment during manual takeover in an autonomous vehicle according to claim 1, characterized in that, The first threshold D1 and the second threshold D2 are pre-calibrated and dynamically adjusted thresholds, and their determination method is as follows: D1 = D1_base · f; D2 = D2_base · f; Where D1_base and D2_base are pre-calibrated fixed reference values, and the dynamic coefficient f is: f = 1 + k ·(a_y / a_y_max) or f = 1 + k ·(a_y / a_y_max) + k_r ·r; Where a_y = v² ·ρ, v is the current vehicle speed, ρ is the road curvature, a_y_max =μ· g, μ is the road surface adhesion coefficient, g is the gravitational acceleration, k is the lateral acceleration influence coefficient, r is the environmental risk level, and k_r is the environmental risk weight coefficient.
11. The manual takeover control method for preventing misjudgment in an autonomous vehicle according to claim 10, characterized in that, The specific steps of smoothing or attenuating the intervention command before execution include: Based on the degree of human-machine decision-making conflict D, the human-machine co-driving weight coefficient w = 1 / (1+e^{k·(D-D2)}) is calculated using the Sigmoid function, where k is a preset slope coefficient; Based on the human-machine co-driving weight coefficient w, the expected control quantity u_manual corresponding to the intervention command and the expected control quantity currently output by the autonomous driving system are weighted and fused to generate the target control command: u_target = w·u_manual + (1-w)·u_auto; The authentication of the operator's intent specifically includes: Behavioral features are extracted from the operation signals output from the manual input interface. The behavioral features include at least the operation duration, the consistency of the rate of change of the operation direction, and the energy distribution ratio of the operation signal in the low-frequency band and the high-frequency band. The duration t is mapped to the first probability value P_duration=1-exp(-t / τ), the number of changes in the operation direction n within the preset time window is mapped to the second probability value P_consistency=exp(-λ·n), and the energy ratio R between the low-frequency band and the high-frequency band is mapped to the third probability value P_frequency=1 / (1+exp(-k_freq·(R-R0))), where τ is the time constant, λ is the attenuation coefficient, k_freq is the slope coefficient, and R0 is the decision boundary; C = P_duration·P_consistency·P_frequency is used as a representation of the credibility of the operator's intent. When C exceeds the preset threshold C_th, the authentication is deemed successful; otherwise, the authentication fails.
12. The method for preventing misjudgment during manual takeover in an autonomous vehicle according to claim 1, characterized in that, The method further includes: when the collision time between the vehicle and surrounding obstacles is less than a preset safety threshold, and the current planned trajectory of the autonomous driving system does not contain effective avoidance measures: If the degree of human-machine decision conflict is greater than the second threshold D2, then the smoothing or gain attenuation of the intervention command is cancelled, and the intervention command is executed in full directly. If the degree of human-machine decision conflict is between the first threshold D1 and the second threshold D2, then the authentication of the operator's intention is skipped, and the intervention command is executed directly in full.
13. The method for preventing misjudgment during manual takeover in an autonomous vehicle according to claim 1, characterized in that, The method also includes continuous monitoring after takeover: The deviation between the actual driving trajectory of the vehicle after takeover and the second expected driving trajectory is obtained; When the deviation exceeds the third threshold D3 and the duration exceeds the threshold T_exceed, the manual takeover is automatically terminated and the automatic driving mode is restored. The third threshold D3 is determined by the product of the basic deviation threshold D3_base and the dynamic environmental risk coefficient α: D3 = D3_base·α, where α = 1 + k1 / d_min + k2·max(v_rel,0), d_min is the minimum distance between the vehicle and surrounding obstacles, v_rel is the relative approach speed, and k1 and k2 are preset weighting coefficients; when there are multiple obstacles at the same time, the maximum value of α_i corresponding to each obstacle is taken.
14. A manual takeover prevention and control system for an autonomous vehicle, characterized in that, The system includes: The trajectory acquisition module is used to acquire and temporarily store the first expected driving trajectory generated by the autonomous driving system at the current moment when the vehicle is in autonomous driving mode and receives an intervention command from the human input interface. The trajectory mapping module is used to generate a second expected driving trajectory with a trajectory time window according to the control mode carried by the intervention command; The security detection module is used to perform input security detection on the intervention command. If the detection fails, the intervention command is blocked. If the detection passes, a release signal is sent to the conflict measurement module. The conflict measurement module is used to calculate the deviation measure between the first expected driving trajectory and the second expected driving trajectory after receiving the clearance signal, as a measure of the degree of conflict between human and machine decision-making. The hierarchical decision-making module is used to execute the intervention command if the degree of human-machine decision conflict is less than a first threshold D1; if the degree of human-machine decision conflict is greater than a second threshold D2, the intervention command is smoothed or attenuated before execution, and a takeover prompt message is output, wherein the second threshold D2 is greater than the first threshold D1; if the degree of human-machine decision conflict is greater than or equal to the first threshold D1 and less than or equal to the second threshold D2, the operator's intent is authenticated; if the authentication is successful, the intervention command is executed; if the authentication fails, the automatic driving mode is maintained. The processor integrates the trajectory acquisition module, trajectory mapping module, safety detection module, conflict measurement module, and hierarchical decision-making module. When the processor executes the program stored in the memory, it implements the manual takeover anti-misjudgment control method in the autonomous vehicle as described in any one of claims 1 to 13.