Secure control of technical-physical systems
Patent Information
- Application Number
- EP2023768194
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-09-20
- Filing Date
- 2023-09-05
- Publication Date
- 2025-07-30
AI Technical Summary
Machine-learned algorithms used to control technical-physical systems face challenges due to limited training data sets, leading to potential malfunctions and safety risks, especially in critical applications where human health or safety is at stake, as they may generate incorrect predictions for unseen examples.
The use of context data, such as Delaunay triangulation-based regions in the input vector space, to determine the reliability of predictions, allowing or blocking the estimation of hidden system states based on predetermined criteria, thereby ensuring safe operation and reducing uncertainty.
This approach enhances the safety and reliability of technical-physical systems by restricting unsafe control actions, transferring systems to safe modes, or issuing warnings when uncertainty is high, and targets the training of machine-learned algorithms to improve the frequency of reliable estimates.
Smart Images

Figure 1.1
Abstract
Description
[0001] SAFE CONTROL OF TECHNICAL-PHYSICAL SYSTEMS
[0002] TECHNICAL FIELD
[0003] Various examples concern techniques for enabling the control of technical-physical systems. Various examples concern techniques for estimating a hidden system state of such technical-physical systems and, where appropriate, determining an associated uncertainty.
[0004] BACKGROUND
[0005] Machine-learned algorithms are used in various application areas because the corresponding tasks to be solved by the machine-learned algorithm can be defined by describing requirements. For example, machine-learned algorithms can be used to control technical-physical systems (i.e., technical installations). The machine-learned algorithm can predict a hidden system state of the technical-physical system (inference).
[0006] For example, machine-learned algorithms can be used to control a vehicle, such as a motor vehicle or a train. Machine-learned algorithms can be used to monitor and, if necessary, adjust maintenance intervals for technical-physical systems such as vehicles or infrastructure (e.g., rails, switches, means of transport such as escalators or moving walkways, production facilities, etc.). In such scenarios, it is often possible, for example using the domain knowledge of an expert, to identify certain events in historical data that require an associated control action for the technical-physical system. This corresponds to the above description of requirements for the control task of the machine-learned algorithm.
[0007] Given input features (which are typically passed to the machine-learned algorithm in the form of an input vector), the machine-learned algorithm determines one or more output features (typically in the form of an output vector). To do this, the machine-learned algorithm is trained on the basis of one or more training data sets. A training data set comprises several training data pairs of an input vector and associated ground truths. The input vector comprises several entries, each of which encodes features of state data of the technical-physical system. The ground truths describe a target position in the vector space of the output vector of the machine-learned algorithm. Training the machine-learned algorithm ensures that the output vector obtained by the machine-learned algorithm matches the target position in the vector space as closely as possible.
[0008] Due to the success of machine-learned algorithms, they are increasingly being used in applications where human life, health, or the environment could be endangered by a malfunction of the machine-learned algorithm. Examples include autonomous vehicles participating in traffic.
[0009] It is therefore necessary to train the machine-learned algorithm as thoroughly as possible to avoid malfunctions. However, the available training data sets are limited. This means that not all positions in the vector space of the input vector (input vector space) have an associated ground truth. Therefore, generalization occurs during training of a machine-learned algorithm. This means that during inference (i.e., without an available ground truth), an output from the machine-learned algorithm is provided even for previously unknown examples.
[0010] With previously known systems, there is a risk that the life or health of people may be endangered during inference. This happens when incorrect outputs are generated, for example, when a hidden system state of a technical-physical system is incorrectly predicted.
[0011] SUMMARY
[0012] Therefore, there is a need for improved techniques for estimating hidden system states of a physical system using machine-learning algorithms. In particular, there is a need for techniques that mitigate the aforementioned drawbacks and limitations.
[0013] This problem is solved by the features of the independent patent claims. The dependent patent claims define embodiments.
[0014] According to various examples, a machine-learned algorithm can be used that determines output vectors based on input vectors. The input vectors can each encode state data of a technical-physical system. The output vectors can predict a respective hidden system state of the technical-physical system.
[0015] The machine-learned algorithm can predict discrete system states (classes), thus implementing a classifier. In some examples, the machine-learned algorithm could also perform regression.
[0016] The input vectors can have two or more dimensions. The output vectors can have two or more dimensions. The position of an input vector in the corresponding vector space (input vector space) defines the position of the corresponding output vector in the corresponding vector space (output vector space).
[0017] According to various examples, context data is used by the machine-learned algorithm for inference. The context data provides supplementary information to the machine-learned algorithm. The context data is determined in connection with the training of the machine-learned algorithm. The context data can help determine the reliability of an estimate of the hidden system state by the machine-learned algorithm.
[0018] In the various examples described herein, the information content of the context data may vary.
[0019] For example, the context data is indicative of regions in the input vector space of the machine-learned algorithm, thus defining hypervolumes of the input vector space. It is possible to check how the input vector is positioned relative to these regions. From this, it can be deduced whether the machine-learned algorithm has a reliable or unreliable prediction for this input vector.
[0020] The regions can be determined, for example, as a Delaunay triangulation of the input space, so that input vectors from training data pairs of a training data set form vertices of the respective surfaces (strictly speaking, hypersurfaces of any dimension; however, for the sake of simplicity, only surfaces are referred to). Thus, the regions interpolate between the input vectors for which ground truths are also available within the training data pairs.
[0021] The context data may also include a partitioning of the regions into those associated with low uncertainty in estimating the hidden system state and those associated with high uncertainty in estimating the hidden system state. Alternatively, such a partitioning could be generated for inference.
[0022] Alternatively or additionally, it would also be conceivable for the context data to indicate one or more permissible outcomes for the hidden system state for at least some regions. In other words, this means that the regions can indicate which output vectors of the machine-learned algorithm are permissible.
[0023] Such context data can therefore be used during inference - when no ground truth is available - to check the output of the machine-learned algorithm for plausibility.
[0024] The context data can be determined in connection with the training of the machine-learned algorithm. For example, it would be conceivable for the context data to be determined based on input vectors of a training dataset. For example, the above-mentioned regions indexed by the context data can be determined by interpolation between positions of the input vectors of the training dataset.
[0025] However, the context data can be used for more than just inference. For example, it would also be possible to use the context data to determine which positions in the input vector space require additional training data pairs—that is, combinations of an input vector and an output vector describing a ground truth.
[0026] By using context data, the technical-physical system can be controlled in a particularly safe manner. For example, if the control data reveals that an output of the machine-learned algorithm is subject to a comparatively high degree of uncertainty, the permissible control actions can be restricted and / or the technical-physical system can be transferred to a safe operating mode and / or a warning message can be issued. Furthermore, the training of the machine-learned algorithm can be particularly targeted, so that reliable estimates of the hidden system state can be obtained more frequently.
[0027] According to various examples, techniques are disclosed which make it possible to estimate a hidden system state of a technical-physical system. A machine-learned algorithm is used for this estimation. The estimation of the machine-learned algorithm for the hidden system state is optionally permitted or blocked, in each case for a corresponding input vector. This is based on at least one predetermined criterion. The at least one predetermined criterion takes into account a position of the input vector in the corresponding input vector space. This means that depending on the position of the input vector in the input vector space, the output of the machine-learned algorithm can be prevented. This can avoid uncertain outputs or uncertain estimates for the hidden system state.
[0028] A computer-implemented method for estimating a hidden system state of a technical-physical system using a machine-learned algorithm is disclosed. The method comprises obtaining an input vector. The input vector encodes state data of the technical-physical system. The method also comprises loading the machine-learned algorithm. The method further comprises loading predetermined context data. The predetermined context data is associated with the machine-learned algorithm. The predetermined context data indexes a plurality of regions in the vector space of the input vector. The method also comprises determining a relative position of the input vector with respect to the plurality of regions. The method further comprises optionally processing the input vector in the machine-learned algorithm to thereby estimate the hidden system state or outputting an error indicator.The choice between processing and outputting the error indicator is based on the relative position of the input vector with respect to the plurality of regions.
[0029] A device comprises at least one processor and a memory. The at least one processor is configured to load program code from the memory and to execute the program code. The at least one processor is configured to execute, based on the program code, a method for estimating a hidden system state of a technical-physical system using a machine-learned algorithm. The method comprises obtaining an input vector. The input vector encodes state data of the technical-physical system. The method also comprises loading the machine-learned algorithm. The method further comprises loading predetermined context data. The predetermined context data is associated with the machine-learned algorithm. The predetermined context data indexes a plurality of regions in the vector space of the input vector.The method also includes determining a relative position of the input vector with respect to the plurality of regions. The method further includes optionally processing the input vector in the machine-learned algorithm to thereby estimate the hidden system state or outputting an error indicator. The selection between processing and outputting the error indicator is based on the relative position of the input vector with respect to the plurality of regions.
[0030] A computer program or a computer program product or a computer-readable storage medium comprises program code. The program code can be loaded and executed by at least one processor. When the processor executes the program code, this causes the processor to perform a method for estimating a hidden system state of a technical-physical system using a machine-learned algorithm. The method comprises obtaining an input vector. The input vector encodes state data of the technical-physical system. The method also comprises loading the machine-learned algorithm. The method further comprises loading predetermined context data. The predetermined context data is associated with the machine-learned algorithm. The predetermined context data indexes a plurality of regions in the vector space of the input vector.The method also includes determining a relative position of the input vector with respect to the plurality of regions. The method further includes optionally processing the input vector in the machine-learned algorithm so as to estimate the hidden system state or outputting an error indicator. The choice between processing and outputting the error indicator is based on the relative position of the input vector with respect to the plurality of regions. A computer-implemented method for parameterizing a machine-learned algorithm is disclosed. By means of the machine-learned algorithm, a hidden system state of a technical-physical system can be estimated. The method includes obtaining a training data set. The training data set includes a plurality of training data pairs, which in turn include input vectors and ground truths.The input vectors encode state data of the technical-physical system. The ground truths relate to the hidden system state of the technical-physical system. The method further comprises performing a training of the machine-learned algorithm. The training is performed based on the training data set. By performing the training, parameter values for the machine-learned algorithm are obtained. The method further comprises determining a plurality of regions based on the input vectors. The plurality of regions comprises regions defined in the vector space of the input vectors. The method further comprises generating context data for the machine-learned algorithm such that the context data is indicative of the plurality of regions.The method also includes storing the machine-learned algorithm and storing the context data associated with the machine-learned algorithm.
[0031] A device comprises at least one processor and a memory. The at least one processor is configured to load program code from the memory and to execute the program code. The at least one processor is configured to execute a method for parameterizing a machine-learned algorithm based on the program code. A hidden system state of a technical-physical system can be estimated by means of the machine-learned algorithm. The method comprises obtaining a training data set. The training data set comprises a plurality of training data pairs, which in turn comprise input vectors and ground truths. The input vectors encode state data of the technical-physical system. The ground truths relate to the hidden system state of the technical-physical system. The method also comprises carrying out a training of the machine-learned algorithm.The training is performed based on the training dataset. By performing the training, parameter values for the machine-learned algorithm are obtained. The method further comprises determining a plurality of regions based on the input vectors. The plurality of regions comprise regions defined in the vector space of the input vectors. The method further comprises generating context data for the machine-learned algorithm such that the context data is indicative of the plurality of regions. Furthermore, the method comprises storing the machine-learned algorithm and storing the context data associated with the machine-learned algorithm.
[0032] A computer program or a computer program product or a computer-readable storage medium comprises program code. The program code can be loaded and executed by at least one processor. When the processor executes the program code, this causes the processor to carry out a method for parameterizing a machine-learned algorithm. By means of the machine-learned algorithm, a hidden system state of a technical-physical system can be estimated. The method comprises obtaining a training data set. The training data set comprises a plurality of training data pairs, which in turn comprise input vectors and ground truths. The input vectors encode state data of the technical-physical system. The ground truths relate to the hidden system state of the technical-physical system. Furthermore, the method comprises carrying out a training of the machine-learned algorithm.The training is performed based on the training dataset. By performing the training, parameter values for the machine-learned algorithm are obtained. The method further comprises determining a plurality of regions based on the input vectors. The plurality of regions comprise regions defined in the vector space of the input vectors. The method further comprises generating context data for the machine-learned algorithm such that the context data is indicative of the plurality of regions. Furthermore, the method comprises storing the machine-learned algorithm and storing the context data associated with the machine-learned algorithm.
[0033] The features set out above and features described below can be used not only in the corresponding explicitly set out combinations, but also in further combinations or in isolation, without departing from the scope of the present invention.
[0034] SHORT DESCRIPTION OF THE CHARACTERS
[0035] FIG. 1 schematically illustrates a system comprising a data processing system and a technical-physical system according to various examples.
[0036] FIG. 2 schematically illustrates a data processing pipeline with a machine-learned algorithm and associated context data according to various examples.
[0037] FIG. 3 illustrates details regarding the context data that indexes multiple regions in a vector space of input vectors for the machine-learned algorithm. FIG. 4 is a flowchart of an exemplary method.
[0038] FIG. 5A is a flowchart of an exemplary method.
[0039] FIG. 5B shows aspects related to a Delaunay triangulation.
[0040] FIG. 5C shows aspects related to a Delaunay triangulation.
[0041] FIG. 5D shows aspects related to min-max triangulation.
[0042] FIG. 5E shows aspects related to regions in the input vector space associated with different classes.
[0043] FIG. 5F shows aspects related to regions in the input vector space associated with different classes.
[0044] FIG. 5G shows aspects related to regions in the input vector space associated with different classes.
[0045] FIG. 5H shows aspects related to regions in the input vector space associated with different classes.
[0046] FIG. 51 shows aspects related to the plausibility check of context data.
[0047] FIG. 6 illustrates input vectors of a training data set in a corresponding vector space.
[0048] FIG. 7 illustrates a classification result of a machine-learned algorithm trained based on the training data set of FIG. 6, according to various examples.
[0049] FIG. 8 illustrates a classification result of a machine-learned algorithm trained based on the training data set of FIG. 6, according to various examples. FIG. 9 illustrates a classification result of a machine-learned algorithm trained based on the training data set of FIG. 6, according to various examples.
[0050] FIG. 10A illustrates several regions determined in the vector space of the input vectors of FIG. 6 according to various examples.
[0051] FIG. 10B illustrates details of one of the regions of FIG. 10A.
[0052] FIG. 10C illustrates an input vector space according to various examples.
[0053] FIG. 10D illustrates a region determined in the input vector space according to FIG. 10C.
[0054] FIG. 10E illustrates another region determined in the input vector space according to FIG. 10C.
[0055] FIG. 11 is a flowchart of an exemplary method.
[0056] FIG. 12 illustrates context data according to various examples.
[0057] FIG. 13 illustrates context data according to various examples.
[0058] DETAILED DESCRIPTION
[0059] The above-described properties, features and advantages of this invention, as well as the manner in which they are achieved, will become clearer and more readily understood in connection with the following description of the exemplary embodiments, which are explained in more detail in conjunction with the drawings. The present invention will now be explained in more detail using preferred embodiments with reference to the drawings. In the figures, like reference numerals designate like or similar elements. The figures are schematic representations of various embodiments of the invention. Elements shown in the figures are not necessarily drawn to scale. Rather, the various elements shown in the figures are shown in such a way that their function and general purpose will be understood by those skilled in the art.Connections and couplings between functional units and elements shown in the figures can also be implemented as indirect connections or couplings. A connection or coupling can be implemented wired or wirelessly. Functional units can be implemented as hardware, software, or a combination of hardware and software.
[0060] In the following, techniques are described to estimate a hidden system state of a technical-physical system using a machine-learning (ML) algorithm.
[0061] For example, the estimation of the hidden system state could be used to control the physical system. This means that the operation of the physical system can be adjusted accordingly based on the prediction of the ML algorithm.
[0062] The techniques described herein can be used in various application areas, i.e. for different technical-physical systems. For example, the techniques described herein could be used to control vehicles, e.g. in rail-bound transport, public road transport, in industrial plants or buildings, as well as ships, aircraft or spacecraft. The techniques described herein could be used to adapt maintenance intervals for traffic routes such as rail sections or switches. The techniques described herein can be used to detect fault conditions in rail vehicles or track infrastructure, to allow the release of certain rail / track sections to road users, or to control traffic in transport networks.The techniques described herein could be used to monitor the operation of production lines or industrial facilities, such as power plants or turbines, to control the distribution of energy or material flows, or to protect technical components (e.g., surge protection), people (e.g., in industrial manufacturing), corporate assets (e.g., in commercial transactions), or the environment (e.g., against fire). These are just a few examples, and other areas of application are conceivable.
[0063] The various techniques described herein utilize a machine-learned algorithm. For example, the machine-learned algorithm could be a classifier, that is, it could map continuous values of an input vector to discrete classes. The machine-learned algorithm could also provide regression, that is, it could have continuous values of an output vector.
[0064] Different types of machine-learned algorithms can be used in the various examples described here. For example, a deep neural network, for example with convolutional layers with a trained convolution kernel, could be used. A support vector machine (SVM) could also be used. Based on a training dataset, the input space is divided into classes so that the widest possible area remains free between the different classes. Another machine-learned algorithm that can be used would be the nearest neighbor classifier. For example, a parameter that describes the number of nearest neighbors to be considered can be learned during the training of the machine-learned algorithm.Another type of machine-learned algorithm that can benefit from the techniques disclosed herein is the multilayer perceptron or radial basis function (RBF) network.
[0065] Techniques are described that make it possible to obtain additional information related to the prediction of the machine-learned algorithm, so-called context data .
[0066] In particular, the techniques described herein make it possible to use the context data to check whether a prediction by the machine-learned algorithm for a specific input vector is reliable or unreliable. For example, depending on the context data, the input vector can then optionally be processed with the machine-learned algorithm (provided its output is reliable), or an error indicator could be output. The technical-physical system can also be controlled depending on the output of the error indicator. For example, a secure operating mode could be activated. A user check could be triggered. A warning signal can be output. An autonomously acting functionality such as an economic transaction could be aborted.In this way, the danger to the environment due to an unreliable prediction of the machine-learned algorithm can be avoided.
[0067] Using the context data, it is also possible to determine the positions in the input vector space where further training data pairs should be positioned. This information can also be determined based on an analysis of whether the machine-learned algorithm is providing an unreliable prediction for a specific area in the input vector space. This increases the sub-areas of the input space in which the machine-learned algorithm can make a reliable prediction, thus enabling greater availability of the technical system in “normal operation”. “Normal operation” refers, for example, to the state of the system in which the system is not in a safe state but is fulfilling a safety-relevant useful function; this could be, for example, a moving train that does not stop at a safe position at a station where passengers can board and alight safely.In particular, during training—for example, when collecting and recording examples, e.g., through a measurement in the real environment or through the use of a digital twin (e.g., a simulation)—specifically covers areas in the input vector space where the machine-learned algorithm would otherwise generalize by extrapolating training data pairs located far away in the input vector space. The recording of additional examples thus increases the reliability of the prediction by the machine-learned algorithm and the technical system.
[0068] According to the various techniques disclosed herein, it is thus possible to either allow or block the estimation of the hidden system state by the machine-learned algorithm depending on at least one predetermined criterion. Blocking the prediction can correspond to the above-described output of the error indicator or otherwise suppressing further processing of the output of the machine-learned algorithm. Allowing the estimation can correspond to handing it over to subsequent processing steps of a corresponding data processing pipeline. The at least one criterion for blocking or allowing can take into account the position of the corresponding input vector - which forms the basis of the estimation of the machine-learned algorithm.For example, the prediction could be blocked if the position of the input vector corresponds to an extrapolation of the machine-learned algorithm based on state data of the technical-physical system that is contained in a training data set for the machine-learned algorithm. This state data can mark corresponding positions ( e.g. nearest) in the input vector space; this can be indicated by the context data. Then the input vector can have a position in the input vector space that is spaced from regions that extend between positions in the input vector space corresponding to the state data. Conversely, a prerequisite for allowing the estimation of the machine-learned algorithm can be that there is no extrapolation at all, i.e. that there is interpolation.This means that the input vector has a position in the input vector space that is located in a region that extends between the positions of the state data from the training data set (if the input vector space has the dimension D, then a hypervolume T of the input space is defined by D+1 input vectors that span a space of dimension D). The boundary of the hypervolume T is then delimited by hypersurfaces that connect three neighbors of the state data. If the input vector lies within a hypervolume that is delimited by examples of the training set as described above, then this is referred to as interpolation based on the training data; if this is not the case, it is referred to as extrapolation.In addition to interpolation, it can also be required that the longest distance between the two or more state data of the technical-physical system between which interpolation is carried out is not greater than a predetermined threshold value. This means that an upper threshold value can be required for the side length of the hypersurfaces delimiting a region. Another example criterion that can lead to a blockage of the prediction would be if a minimum distance to uncertain positions in the input vector space is not reached. These uncertain positions could, for example, be determined based on the course of a class boundary between different predicted classes in the input vector space. The positions can therefore be labeled as uncertain.
[0069] Various criteria for blocking or allowing the prediction of the machine-learned algorithm were explained above. As a general rule, it would be conceivable to check sequentially whether one or more of such criteria for blocking or allowing are met. For example, a predefined sequence could be processed which specifies the order in which the different criteria are to be checked. The prediction of the machine-learned algorithm can then be blocked if a first check produces a negative result; the subordinate second check then no longer needs to be carried out. In particular, it would be conceivable, for example, to first check whether the minimum distance to uncertain positions in the input vector space is not met.Only subsequently could it be checked whether the position of the input vector corresponds to an extrapolation or an interpolation, as described above.
[0070] From the above, it is clear that the regions in the input vector space can be determined that have different confidence levels with respect to the prediction of the machine-learned algorithm. This is summarized in Table 1.
[0071]
[0072] TAB . 1 : Different levels of security that can be achieved in connection with the prediction of a machine-learned algorithm . Such levels can be described in relation to specific regions in the input vector space, which are defined by context data . The regions can be divided into the different security levels using an evaluation metric . This can be done either for inference or during training . The determination of the regions and the application of the evaluation metric can be quality-assured, whereby dangerous loss or corruption of the information can be reliably avoided .
[0073] FIG. 1 illustrates aspects relating to a system 90. The system 90 comprises a data processing system 91 and a technical-physical system 95 (e.g., an industrial plant, an air, water, space, or ground vehicle, a power plant, a means of passenger transport such as an elevator or escalator, a manufacturing machine, a factory, a production line, a system for distributing energy or material flows, or a system for controlling traffic, to give just a few examples).
[0074] The data processing system 91 has a processor 92 and a non-volatile memory 93. In addition, the data processing system 91 comprises a communication interface 94. The processor 92 can communicate with the technical-physical system via the communication interface 94. For example, it would be possible for status data 81 of the technical-physical system 95 to be received via the communication interface 94. The status data
[0075] 81 could, for example, be measured values of a sensor that monitors certain operating parameters of the technical-physical system 95. The status data 81 could also be operating values of the technical-physical system 95, for example certain control specifications for actuators of the technical-physical system 95. It is also possible that the processor 92 receives control data via the communication interface 94.
[0076] 82 to the technical-physical system 95. The operation of the technical-physical system can be adjusted using the control data 82.
[0077] While only one processor 92 is shown in FIG. 1, the data processing system 91 may generally have several processors.
[0078] To process the state data 81, the processor 92 can load and execute program code from the memory 93. The program code can define a machine-learned algorithm that is configured to process input vectors that encode the state data 81. The machine-learned algorithm can then provide an output vector that estimates a hidden system state of the technical-physical system. A corresponding data processing pipeline is also shown in FIG. 2. FIG. 2 illustrates aspects related to a machine-learned algorithm 89. The machine-learned algorithm 89 processes an input vector 85 that encodes state data 81 of the technical-physical system 95. The machine-learned algorithm 89 then provides an output vector 86 that predicts the hidden system state of the technical-physical system 95. This corresponds to an inference.
[0079] Using various techniques described herein, it is possible to verify whether the prediction of the hidden system state by the machine-learned algorithm 89 is reliable. In particular, it can be verified a priori, i.e., before or independently of the execution of the machine-learned algorithm, whether this prediction is reliable.
[0080] The verification may be performed based on the position of the input vector 85 in the input vector space and using corresponding context data 50. The context data 50 is associated with, but different from, the machine-learned algorithm 89. Different machine-learned algorithms 89 have different context data 50. The context data 50 may, for example, be determined in connection with the training of the machine-learned algorithm 89, which will be explained in detail later.
[0081] In the following, aspects related to checking the position of the input vector 85 in the input vector space using the context data 50 are shown in connection with FIG. 3.
[0082] FIG. 3 illustrates aspects relating to the position of the input vector 85 in the corresponding input vector space 71 (for illustration purposes, the input vector space 71 is shown two-dimensionally, but can be higher-dimensional; the input vector space is therefore strictly speaking a hyperspace). FIG. 3 also shows a plurality of regions 72 in the input vector space 71. The regions 72 are delimited from one another by hypersurfaces (or lines in the two-dimensional case shown). The input vector 85 has a specific position with respect to these regions 72 (in the example in FIG. 3, the input vector 85 is arranged in one of the regions 72).
[0083] The regions may be indexed by context data 50 associated with the machine-learned algorithm 89. For example, the context data 50 could indicate the areas between the regions 72.
[0084] The areas can be associated with different security levels as shown in Table 1.
[0085] In the various examples described herein, it is possible to determine such a relative position of the input vector with respect to a plurality of regions 72 and then, based on this relative position, to optionally process the input vector of the machine-learned algorithm 89 and thus estimate the hidden system state (for example, if security level I or II is involved), or to output an error indicator (for example, if security level III is involved, see TABLE 1). The regions 72 can be indexed by the context data 50 of the machine-learned algorithm 89. The context data 50 can be loaded by the processor 92, for example, from the memory 93. The context data 50 can be created in connection with the training of the machine-learned algorithm, i.e., when parameterizing the machine-learned algorithm; see FIG. 4.
[0086] FIG. 4 is a flowchart of an exemplary method. FIG. 4 illustrates various phases of using a machine-learned algorithm, such as the machine-learned algorithm 89.
[0087] Parameterization takes place in Box 3001.
[0088] This includes, for example, the training of the machine-learned algorithm 89 . The training can be carried out based on a training data set . The training data set contains training data pairs , each comprising an input vector and an associated output vector . The output vector represents the ground truth for the output of the machine-learned algorithm for the respective input vector . A ground truth can, for example, be obtained based on manual annotation by an expert with domain knowledge . There are also techniques to automatically obtain ground truths, although this can vary depending on the application area, e.g. by means of a simulation of the technical-physical system .
[0089] Based on the training, parameter values for the machine-learned algorithm are obtained. Different parameter values can be obtained for different types of machine-learned algorithms (for example, for a deep neural network with one convolutional layer, the convolution kernel can be determined).
[0090] The training can be carried out using basically previously known techniques which typically comprise an iterative optimization of the various parameter values to minimize a loss function. A gradient descent method for the optimization with backward adaptation of the parameters (backpropagation) can be carried out. The loss function describes a distance of the output vector of the machine-learned algorithm in the current separation state compared to the corresponding vector of the ground truth of a corresponding training data pair. The parameterization 3001 can also comprise the generation of the context data 50 for the machine-learned algorithm. This can be determined based on the input vectors of the training data set. This means that the context data is specific to the respective machine-learned algorithm which has undergone a particular training.Different machine-learned algorithms then have different context data (see also vertical dashed arrow in FIG. 2).
[0091] It is then possible to store both the machine-learned algorithm and the context data 50 for the machine-learned algorithm in a memory such as the memory 93 for later inference in box 3002.
[0092] Inference takes place in box 3002. This inference takes into account both the previously trained machine-learned algorithm 89 to estimate a hidden system state of the technical-physical system, if applicable, and the context data 50 to determine whether an output of the machine-learned algorithm is safe or unsafe. No ground truth is available during the inference in box 3002. This means that the machine-learned algorithm 89 outputs an output vector 86 that cannot be compared to a ground truth.
[0093] Below, aspects related to Box 3001 are first described. Aspects related to Box 3002 are then described.
[0094] FIG. 5A is a flowchart of an exemplary method. FIG. 5A illustrates aspects related to parameterizing a machine-learned algorithm according to box 3001 of FIG. 4. For example, the method of FIG. 5A could be executed by processor 92 based on program code loaded from memory 93 and then executed by processor 92.
[0095] First, a training data set is received in box 3505. The training data set comprises several training data pairs. Each training data pair has a corresponding input vector, corresponding to the input vector 85 (see FIG. 2). The input vector encodes state data of a technical-physical system. Each input vector is assigned a ground truth for a corresponding hidden system state of the technical-physical system. The ground truths are available in the form of output vectors (see output vector 86 in FIG. 2).
[0096] In Box 3510, the machine-learned algorithm is then trained based on the training dataset. This is done to obtain parameter values for the machine-learned algorithm. Details of the training have already been described above in connection with Box 3001.
[0097] Subsequently, in box 3515, several regions are determined based on the input vectors of the training data set.
[0098] At least some of the regions are determined in such a way that they are arranged between the positions of the input vectors in the corresponding input vector space. This means that the input vectors each define outer boundaries of the regions. This means that the regions extend between the input vectors. To determine the regions, interpolation is carried out between the positions of the input vectors in the input vector space.
[0099] For example, it would be conceivable for the regions to be formed based on triangular surfaces of a triangular network, whose nodes are determined by the input vectors. A triangulation, e.g. a Delaunay triangulation, could be used. Context data 50, which is indicative of the regions, can then be generated. For example, context data 50 could contain the triangular surfaces of the triangular network. The regions can therefore be bounded by surfaces (more precisely: hypersurfaces) that extend between the positions of adjacent input vectors in the corresponding input vector space.
[0100] As a general rule, the so-called KD-Trees algorithm could be used to find nearest neighbors. However, there are a variety of other possibilities. Other classic tree structures are conceivable, such as quadtrees or R-trees. For particularly high-dimensional data, approximate nearest neighbor methods such as locality-sensitive hashing are suitable.
[0101] In some examples, it would be conceivable for at least some of the areas to be defined in such a way that a position in the input vector space that is recognized as unsafe is surrounded. If a position is recognized as unsafe, the extent of such an area can be determined based on a specified distance measure (parameter "b"). The parameter b supports the management of problems at class boundaries in applications with a strong imbalance regarding the significance of certain error types. One example is a safety-relevant function that regulates driving through a traffic light. Driving through a red light can endanger the life and health of people. If, on the other hand, a vehicle stops at a green light, this only represents an availability problem for the vehicle, as it does not always move at that time. The parameter "bk" then defines a "safety distance" from an example from a class "k".All examples that are less than bk away from an example of class "k" in the input space are then assigned to class "k". Accordingly, for examples that are less than bk away from an uncertain position, the use of the prediction of the machine-learned algorithm is blocked, i.e., for example, no prediction is calculated or the prediction is discarded. It is not necessary in all variants that the regions around uncertainly detected positions are also determined. Sometimes the regions that extend between positions of input vectors could also be evaluated accordingly using an evaluation metric (cf. Box 3520) (this will be explained later).
[0102] In some examples, it would be conceivable for the context data 50 to also be indicative of permissible results of the machine-learned algorithm if a corresponding input vector is assigned to one of the regions. These permissible results can be determined in box 3516. There are various techniques for determining the permissible results in box 3516. For example, a special algorithm could be used which determines the permissible results depending on geometric properties of the respective region. For example, a corresponding further machine-learned algorithm could be used. A multi-layer perceptron or a support vector machine could be used. A classic rule-based algorithm could also be used.The allowed outcomes could, for example, be determined based on ground truths for the input vectors of the training data pairs used to determine the regions. For example, if a certain region is bounded by three input vectors associated with the ground truths "yellow", "yellow", and "blue", the corresponding region could be marked in the context data such that the output vectors of the machine-learned algorithm may display either "yellow" or "blue". In other words, for regions formed by a triangular mesh, the allowed outcomes of the hidden system state can be determined based on the ground truths associated with the nodes of the triangular mesh. Relevant aspects will be explained in more detail later in connection with FIG. 12 and FIG. 13.
[0103] Optionally, in box 3520, the areas could be partitioned into first areas and second areas based on a predetermined evaluation metric, for example according to TAB . 1 , security level I or security level II . For example, the first areas can be associated with a comparatively low uncertainty for the estimation of the hidden system state by the machine-learned algorithm with regard to the evaluation metric; while the second areas can be associated with a comparatively high uncertainty for the estimation of the hidden system state with regard to the evaluation metric. The context data that is subsequently stored can also be indicative of the partitioning of the areas . The context data could e.g. display the security level according to TAB . 1 .
[0104] It is not necessary in all examples for the partitioning of the areas to be performed as part of the parameterization in box 3001. Rather, it would be conceivable for the partitioning of the areas to be performed as part of the inference in box 3002. The explanations presented above and below in connection with the determination of the partitioning in box 3520 can be applied accordingly to a partitioning that is only performed for inference (see, for example, FIG. 11: box 3020).
[0105] In principle, there are different options for implementing the evaluation metric. For example, the evaluation metric could include a component that evaluates the plurality of areas based on their distance from positions identified as unsafe. For example, if an area lies within a distance bk from a position identified as unsafe, the area can be classified as unsafe.
[0106] For example, the evaluation metric could include a component that partitions the multitude of regions based on the edge length of the regions' edges (cf. TABLE 1: Security Level I vs. II). For example, the longer the individual edges of a region, the more likely there is to classify a corresponding region as unsafe. This is based on the realization that the larger the regions, i.e. the longer the edge length of the edges of the region, the greater the probability of a significant change in the output of the machine-learned algorithm. The longer the edge length, the greater the probability of a double class change along the respective edge, e.g. from a first class to a second class and back.In other words, a critical threshold a could be set which defines a distance in the input vector space below which the ML algorithm can safely generalize. This is based, among other things, on the assumption that if the distance in the input vector space is smaller than a, there will be no double change of output class. Regions classified as safe then have edge lengths which are all smaller than the threshold value a. Regions classified as unsafe have at least one side edge which is larger than the threshold value a.
[0107] In some examples, the threshold a could be fixed for different positions in the input space. However, it would also be possible for the threshold to be chosen as a function of the position in the input space.
[0108] If the input vector space has D dimensions (i.e. the input vector contains D entries), then for a number of D+1 training data pairs there will also be a corresponding number of input vectors. These are arranged at different positions in the input vector space. The connecting vectors from one input vector to the other input vectors span an e-dimensional hypervolume of the input vector space if the connecting vectors are linearly independent of one another, i.e. none of the connecting vectors can be formed by a linear combination of the other connecting vectors. Mathematically speaking, the “D+1” positions of the input vectors are then said to be in a “general position” to one another. It can happen that the connecting vectors are non-linearly independent.If the D + l input vectors do not yet span a D-dimensional hypervolume, neighboring points in the input space can be added until a D-dimensional space is spanned. This set of points then defines a hypervolume for which a generalization can be performed and the domain evaluated.
[0109] This initial situation enables the construction of the triangulation. The triangulation divides the input vector space into hypervolumes (or regions), where the boundary of each hypervolume is defined by the area (more precisely: hypersurface) that lies between three points of the triangulation. The respective hypervolume (i.e. the respective region in the input vector space) is then delimited between the areas of D+l points neighboring in the triangulation (which, according to the specifications of the triangulation, lie in a general position to one another). Different types of triangulation can be used in the various examples described here. This means that different algorithms can be used to determine a triangulation. Depending on the choice of triangulation, different regions can be obtained; e.g. FIG.5B shows how four points can be triangulated differently (solid vs. dashed lines).
[0110] One example of triangulation is the Delaunay triangulation. The Delaunay triangulation can be carried out using the Bowyer-Watson algorithm. An example of a Delaunay triangulation is shown in FIG. 5C. The Delaunay triangulation is formed using the so-called circumcircle condition. The following applies: The circumcircle of a triangle in the mesh must not contain any other points from the given point set. In mathematical terms, this maximizes the smallest interior angle across all triangles. This means that the smallest angle in the triangles is as large as it can be in this triangular mesh. However, no statement is made about the other angles. Another example of triangulation is the so-called min-max triangulation. This is explained in connection with FIG. 5D for three different examples (in FIG.5D, different examples are associated with different positions in the input vector space; the positions in the input vector space are marked by crosses. In min-max triangulation, for example, the triangles are chosen such that the largest edge of the triangle is minimized. This helps to choose the maximum side length of the area as small as possible, which is helpful with regard to the threshold comparison with threshold a. However, it can sometimes happen that several possible triangulations can occur and thus a certain position in the input vector space can be assigned to different areas - depending on the triangulation. If there are several possible assignments and at least one of these assignments can be associated with an uncertain state, the output of the machine-learned algorithm (e.g. a classifier) can be blocked.Accordingly, when multiple possible outputs are present, there are two possibilities. The classifier can be configured to favor either the safest or the most useful output. In the second case, one would obviously have to define "usefulness" using, for example, prioritized outputs.
[0111] In other words: There is potential for optimization in the possible ambiguity when determining the ranges. If, for an input vector for which inference is to be made, the position vector in the input vector space lies in two ranges, both of which allow a reliable assignment (e.g., all edge lengths less than "a", see TABLE 1: Example I), then the output of the two ranges that is more "useful" for the application (i.e., the one with the lower costs) can be used. This would be the case, for example, in Figure 5D if the top point were "yellow" and the bottom three points were "blue" (as examples of a class assignment). In this case, the output "blue" or "yellow" would be possible when evaluating the upper triangle (left part of FIG. 5D). However, the triangle in the middle representation allows the safe conclusion that the output is "blue."Then the ML algorithm is allowed to output "blue," as this output is generated by a secure interpolation, since all edge lengths are smaller than a. This variant increases the availability of the system without compromising security.
[0112] In summary, ambiguities can arise in a general triangulation without additional conditions. The Delaunay triangulation resolves this ambiguity with the circumcircle condition: there must be no other point in the circumcircle of a triangle. This reduces the occurrence of very acute triangles, but does not necessarily ensure the smallest possible edge length. On the other hand, in order to comply with the edge length threshold mentioned above, it may be desirable in the various examples described here to determine triangles with the shortest possible edge length. This is achieved by min-max triangulation. This minimizes the largest edge of a triangle ("MinMaxEdge"). The choice of the triangle containing a point depends solely on the position of this point.
[0113] If there is not enough training data pairs to define the regions, additional training data pairs can be acquired. If, for example, problems arise during the triangulation process (e.g. because examples are not in a suitable position relative to one another), then additional neighboring points are added to the set under consideration until the input vectors span this set of examples into a space with the same dimension as the input space. The positions of the input vectors then define the boundary of a hypervolume for which an output and an assessment of the certainty of the output can be determined (see Table 1).
[0114] If D+l input vectors of the training data set are all separated by less than the critical threshold a, then these examples B define a hypervolume for the hypervolume H enclosed by the hypersurfaces connecting them, for which a reliable statement about the internal system state is possible (cf. TAB. 1). In this case, it may be possible in some examples to consider permissible results for the prediction or the hidden system state. For example, it would be conceivable that the predicted hidden system state may only take on values that can also be assumed by the examples B bounding the hypervolume in the output; or when estimating the hidden system state, the output value can only take on values that are no more than from such examples B . The approximated function is continuous in this hypervolume H, in special embodiments even Lipschit continuous . If all "D+1" input vectors belong to the same class K (i.e., they have the same ground truth K ), then, according to the above explanations, all other input vectors that lie within the hypervolume can be safely assigned to this class K .
[0115] The above describes a scenario in which the evaluation metric partitions the regions based on their edge length. Alternatively or additionally, the evaluation metric could evaluate the multitude of regions based on a local variation in the ground truth. This means, for example, that it is possible to check whether and, if so, how much the ground truth changes within or at the edge of the respective region. For example, it could be checked whether there is a double change in an output class for a classifier as a machine-learned algorithm. This is based on the realization that a greater variation in the ground truth in a certain region in the input vector space of the input vector can be indicative of a correspondingly increased uncertainty in the prediction of the machine-learned algorithm.
[0116] In various examples, it would be conceivable for the evaluation metric used in box 3520 to be parameterized. This means that there can be a parameter whose value influences the evaluation results. The parameter value can then be selected depending on the application area or situation. For example, a predefined threshold for the side edges (the value a) could be selected based on at least one criterion.
[0117] Below are some exemplary criteria that can serve as a basis for selecting the threshold for the edge length. The following explains how the threshold can be determined.
[0118] The criterion could, for example, include a minimum distance between the different input vectors of the training dataset that are associated with the different system states. This means that an analysis of the distances between the different input vectors in the training dataset can be performed. In particular, it can be checked what the minimum distance is for input vectors that yield different results, e.g., different classes, for the hidden system state. Then, the predetermined threshold could be chosen to be less than or equal to this minimum distance.
[0119] A corresponding example is shown in FIG. 5E. FIG.
[0120] 5E is a two-dimensional representation of the input vector space (generally speaking, the input vector space could also have a higher dimensionality) and shows different regions 691-694, in each of which input vectors belonging to a specific class are arranged. For example, the input vectors arranged in region 691 of the input vector space belong to a first class (e.g., "green"), while the input vectors arranged in a region 692 of the input vector space belong to a different, second class (e.g., "red"). Also shown in FIG. 5E is the minimum distance 699 between two positions in the input vector space that are associated with input vectors of different classes (in the example shown in FIG. 5E, this distance 699 is defined by two input vectors in regions 691 and 693).For example, corresponding information could be obtained using a histogram-like analysis. The distance between all pairs of input vectors belonging to different classes can be plotted in the histogram. The smallest distance between two input vectors assigned to different classes can then be determined from the histogram. Similarly, a histogram can also be created showing the distance at which a double class change occurs. To do this, for every two examples it is determined whether there is an example that lies between these examples (i.e. it has a smaller distance to the first two examples) and that has a different class to at least one of the first examples.This distance 699 can then be chosen as a predetermined threshold between the smallest distance between two examples assigned to different classes and the smallest distance with a double class change.
[0121] The example in FIG. 5E is characterized by a good separation of the regions 691-694 in the input vector space. As a result, the distance 699, and thus the threshold value, is comparatively large. This allows a reliable prediction of the hidden system state of the technical-physical system to be made using the machine-learned algorithm in comparatively large parts of the input vector space.
[0122] In some examples, it may be possible to improve such a separation of regions associated with different classes by suitable preprocessing of state data; so that the input vectors determined based on the state data of the technical-physical system have a correspondingly large separation. Such progressive separation through different preprocessing is shown in the examples of FIG. 5F, FIG. 5G and FIG. 5H. For example, it would be possible to define a corresponding quality indicator that is indicative of the separation of the different regions 691-694. Then, an optimization of the preprocessing with regard to an optimization function that includes the quality indicator could take place. For example, certain transformations of the state data could take place to determine the input vectors. Transformations could also take place in the output space.Corresponding examples are described, for example, in: German patent application 10 2021 207 613 . 0 .
[0123] Alternatively or additionally, the at least one criterion could be determined based on domain knowledge. For example, with a comparatively low dimensionality of the input vector space, a minimum distance between different classes could be determined based on domain knowledge. For example: e.g., a camera-based track recognition system for rail vehicles could recognize features in images that relate, firstly, to parallel rails (possibly corrected by an optical transfer function of a camera), secondly, to rail sleepers arranged at a certain distance from one another, and thirdly, to the presence of ballast of a defined size between the sleepers.As a concrete example: Using a Hough transformation, the radius of curvature of the rails can be determined using extensive parallel line-shaped structures; using a Garbor filter, the frequency of the sleeper sequence and the size of the ballast can be determined. If in this 3D input space (radius of curvature of long, slender, line-shaped parallel objects, frequency of the sleepers, size of the ballast) three examples differ by less than the threshold value set on the basis of domain knowledge, then a track has been detected. It would then be conceivable to define the permissible feature range for detected rails / tracks using this domain knowledge and to select the threshold value based on this.
[0124] Alternatively or additionally, the at least one criterion for determining the threshold value could, for example, comprise a design requirement of a development process for the technical-physical system. For example, the at least one criterion could specify which safety level is to be achieved for the operation of the technical-physical system. If, for example, a certain safety level – for example, a probability of misclassification or incorrect control action – is required as part of the development process for the technical-physical system, a more or less strict criterion can be used for parameterizing the evaluation metric depending on this requirement.
[0125] In Box 3525, a plausibility check of the areas determined in Box 3515 and optionally assessed in Box 3520 can optionally be performed. This means that it can be checked / validated whether the classification, for example, into "safe" and "unsafe," is correct or incorrect.
[0126] For example, the threshold value for the edge length (i.e., the parameter a) can be checked for plausibility based on one or more additional training data pairs. These one or more additional training data pairs can therefore extend beyond the training data set and have additional input vectors at positions that are closer to a position of an input vector of the training data pairs of the original training data set than the minimum distance. These additional training data pairs can then be used to check whether the output of the machine-learned algorithm matches the corresponding ground truth. If this is not the case, the plausibility check can produce a negative result.
[0127] This is also shown in FIG. 51. In FIG. 51, the circles represent input vectors of the training data set in a first class (e.g., "green") and the triangles represent input vectors of the training data set in a second class.
[0128] (e.g. "red"). The areas identified as safe for the first class are then shown with a dashed fill (bottom left to top right) and the areas identified as safe for the second class are shown with a different dashed fill (top left to bottom right), cf. TABLE 1: Safety level I. Areas classified as unsafe (here TABLE 1: Safety level II) - due to class changes at the corners and / or edge lengths that are too large - are shown without filling. The edge region (TABLE 1: Safety level III) is also shown; for corresponding input vectors (diamonds) no reliable prediction can be made because this would correspond to an extrapolation based on input vectors of the training data set.
[0129] The plausibility of the classification into the areas identified as secure is then verified using additional training data pairs, i.e., additional input vectors for which ground truths are known. These additional input vectors are identified by the crosses and circles. An error is detected for one of these additional input vectors (highlighted with an arrow): The ground truth indicates the second class, while this input vector is located in an area classified as secure with respect to the first class.
[0130] If an error is detected during the plausibility check in box 3525, the feedback loop could be executed via box 3526. In this case, the threshold value for the side edges (the value a) can be reduced in box 3526 and the areas can be reclassified.
[0131] In box 3530, one or more additional positions in the input vector space can optionally be determined where additional training data pairs should be positioned. In other words, this means that it can be determined where additional training data pairs would be helpful to promote a reliable prediction of the hidden system state by the machine-learned algorithm. The training data set can thus be expanded in a targeted manner.
[0132] In particular, the evaluation of the regions within the framework of a corresponding partitioning from box 3520 can be used. Within the framework of such an evaluation, regions in the input vector space can be determined that are associated with a high degree of uncertainty with respect to a corresponding evaluation metric. It would then be possible for additional training data pairs to be arranged in such a way that they lead to a re-evaluation of these regions with a high degree of uncertainty.
[0133] The one or more additional positions can be chosen in the vector space such that, after redefining the plurality of regions, taking into account the training data pairs and the additional training data pairs, the total size of the first regions increases to a maximum. This could be determined, for example, within the framework of an optimization algorithm.
[0134] There are different ways to obtain such additional training data. For example, a human-machine interface could be controlled to obtain an annotation of ground truth for the hidden system state for the additional training data. This means that in a labeling process, those labeling candidates from the set of available input vectors can be given higher priority that are determined to be helpful based on the partitioning. This can result in a particularly steep learning curve that describes the accuracy of the machine-learned algorithm as a function of the annotation iterations. The number of annotations required can be comparatively small.A software simulation of the technical-physical system could also be suitably configured to obtain the ground truth for the hidden system state for the further training data pairs.
[0135] If further training data pairs are obtained, box 3510 and the subsequent boxes can be executed again (shown in FIG. 5A by the feedback dashed arrow).
[0136] In box 3535, it is then possible to store the trained machine-learned algorithm obtained by executing box 3510, as well as the context data 50 obtained from box 3515 and, if applicable, box 3520.
[0137] Above, in connection with FIG. 5A, aspects were explained which concern the determination of context data which indicate regions. On the basis of these regions, it can be determined whether a prediction of the machine-learned algorithm is reliable or unreliable. This effect of the regions is explained in more detail below, using a practical example according to FIGS. 6-10 (also shown here in two dimensions for illustration; in practical examples, a higher dimensionality of the corresponding input vector space 71 is present).
[0138] FIG. 6 illustrates an example of the positioning of input vectors 511-513 and 521-523 in the input vector space 71. The true hidden system state can be divided into two classes corresponding to regions 531, 532. For example, region 531 could correspond to a correctly functioning motor for a railway switch; while region 532 could correspond to a blocked motor. The input vectors 511-513 and 521-523 could, for example, be based on measured values for a current flow through the motor and measured data from a vibration sensor. This is only a concrete example and other examples are possible.
[0139] The input vectors 511-513 and 521-523 are part of a training data set. The training data set thus comprises several training data pairs, each containing a corresponding input vector 511-513 and 521-523, as well as a corresponding output vector as ground truth, which indicates a first output class (e.g., "engine defective") for the input vectors 511-513 and a second output class (e.g., "engine not defective") for the input vectors 521-523.
[0140] FIG. 6 also shows another input vector 550. This input vector 550 is not part of the training data set. This means that there is no ground truth for the input vector 550. The input vector 550 actually corresponds to the second output class, just like the input vectors 521-523. However, it will be shown below that different machine-learned algorithms 89, which are trained based on the input vectors 511-513 and 521-523, can make an incorrect prediction for the input vector 550.
[0141] This is first shown in FIG. 7 for a nearest-neighbor classifier. The input vector 550 is in the immediate vicinity of the input vector 513, which was learned during training to belong to the first output class. The nearest-neighbor classifier would therefore incorrectly predict the first class based on the input vector 550.
[0142] This also applies to a machine-learned algorithm 89 implemented by a multilayer perceptron, as shown in FIG. 8. FIG. 8 shows how such a machine-learned algorithm 89—trained based on the input vectors 511-513, 521-523—predicts the class boundary 565. A discrepancy arises in the region of the input vector 550, resulting in an incorrect prediction.
[0143] The same applies to an SVM implementation of the machine-learned algorithm, see FIG. 9. The corresponding class boundary 567 is shown in FIG. 9. Here, too, a misclassification results for the input vector 550.
[0144] The following shows how, based on the areas indicated by the context data 50, such an uncertain prediction can be anticipated by the machine-learned algorithm 89 in the implementations according to FIGS. 7-9.
[0145] FIG. 10A shows the regions 571-574 resulting from an interpolation between the input vectors 511-513 and 521-524. The regions are obtained by triangulation, whereby, as already described above, different triangulations can be used.
[0146] Examples are a min-max triangulation or a Delaunay triangulation.
[0147] Also shown in FIG. 10A is the critical edge length 590. In the example shown, this critical edge length 590 is determined to correspond to the smallest distance between two input vectors 511-513 and 521-524 of the training data set for which a class change is observed (that is, between input vector 512 and input vector 523). As a general rule, different distance metrics can be used in the various examples described herein. For example, the Euclidean distance can be used. However, the so-called p-norm could also be used.
[0148] As a general rule, the critical edge length 590 can be chosen such that no double class change for the output of the machine-learned algorithm can occur within the corresponding length in the input vector space. See Table 1: Security Level I.
[0149] In FIG. 10A, it can be seen that the regions 571, 572, and 574 have edge lengths that are not less than the critical edge length 590. Accordingly, these regions 571, 572, and 574 (cf. TABLE 1: Safety Level I) are rated as unsafe. For example, for region 574, FIG. 10B shows an enlarged view of how a different class can occur along the connecting line between the input vectors 524 and 522 in the region 574--1; thus, there is a double class change. An input vector that lies within these regions 571, 573, and 574 causes an unsafe prediction of the associated hidden system state by means of the machine-learned algorithm. An error indicator can then be output, based on which, for example, a warning or a transition of the controlled technical-physical system to a safe operating state can occur.
[0150] A different situation exists for area 573 (see FIG. 10A). Area 573 only has edges that are shorter than the critical edge length 590. Area 573 can therefore be assessed as safe (see TABLE 1, Safety Level I).
[0151] From FIG. 10A, it is also evident that the additional input vector 550 does not lie within any of the ranges 571-573. Therefore, no reliable prediction can be made for the additional input vector 550 using the machine-learned algorithm (see TABLE 1: Security Level III) - which is consistent with the observations presented above according to FIG. 7, FIG. 8, and FIG. 9.
[0152] A variant was explained above in which the regions are arranged between positions of input vectors. Another variant is shown in FIG. 10C. There, the input vector space 71 is shown, along with the positions of input vectors 662 for a first class and of input vectors 663 for a second class, as well as the class boundary 660. Inference for an input vector 661 could yield an incorrect result (first class). This could be incorrectly classified as safe if the threshold value for the edge length of the regions extending between the positions of the input vectors 662 is chosen too large (cf. TABLE 1: Example I). To prevent this, a region 670—cf. FIG. 10D—can be determined that surrounds the position of the input vector 663 marked with a cross and delimits a distance b from this position.The inference for all input vectors (including input vector 661) within this region 670 can then be identified as uncertain. Alternatively, the interpolated region 671 (see FIG. 10E) could also be identified as uncertain by the evaluation metric because the distance to the position of the uncertain input vector 663 is less than b, i.e., less than a distance threshold 679. The region 670 could, for example, be determined based on a course of the class boundary 660. For example, a corresponding region 670 could be located where no ground truth is available in training near a known class boundary.
[0153] The context data 50 indicates the regions. This can be exploited during inference (see FIG. 4: box 3002). This is explained below. FIG. 11 is a flowchart of an exemplary method. FIG. 11 can, for example, implement box 3002. FIG. 11 relates to inference using a previously trained machine-learned algorithm based on an input vector for which no ground truth is available. For example, the method of FIG. 11 could be executed by processor 92 after it loads and executes appropriate program code from memory 93.
[0154] First, an input vector is received in box 3005. This can encode state data of the technical-physical system. For example, the input vector could be determined based on corresponding state data (see FIG. 1: state data 81) received from the technical-physical system. The input vector can be loaded from a memory.
[0155] The machine-learned algorithm is loaded into box 3010. Corresponding program code can be loaded from memory.
[0156] The machine-learned algorithm is already trained at this point, meaning parameter values are set. Techniques such as those described above in connection with box 3001, for example, in FIG. 5A, and also in connection with FIG. 4, can be used for training.
[0157] Then, context data is loaded into box 3015. The context data is associated with the machine-learned algorithm. In addition, the context data indicates several regions in the vector space of the input vector. This was discussed above in connection with FIG. 10A. The regions can be determined as part of the parameterization of the machine-learned algorithm, as described above in connection with FIG. 5A: box 3515. There are different ways in which the context data can index regions in the input vector space. For example, the context data could specify the regions directly, i.e., define corresponding boundaries for each region. It would also be conceivable for the context data to specify the corner points; and then, from these, the regions are determined using a Delaunay triangulation or another triangulation or another scheme. The context data can specify the interfaces between the regions.
[0158] The context data can also be optimized. The context data can specify the regions in a compressed form. For example, regions that have the same property can be combined to achieve the most efficient determination of the hidden system state. Such a combination of regions or other optimization / compression of the context data can be performed in FIG. 5A: box 3515.
[0159] In some examples, the context data may also display additional information beyond the scopes.
[0160] The regions can be divided into first regions and second regions. The first regions (cf. FIG. 10A: regions 573) can be associated with a low uncertainty in estimating the hidden system state using the machine-learned algorithm; while the second regions are associated with a comparatively high uncertainty in estimating the hidden system state (cf. FIG. 10A: regions 571, 572).
[0161] In principle, it is possible for the context data to already include an indicator which indicates a corresponding partitioning of the areas into the first and second areas. This means that a corresponding partitioning of the areas can already be carried out in connection with the parameterization of the machine-learned algorithm and then, as part of the inference, this previously performed partitioning can be used (corresponding aspects were explained, for example, in connection with box 3520 in FIG. 5A). However, in some examples it would also be conceivable for the corresponding partitioning to only be determined as part of the inference, namely, for example, in box 3020. This means that in box 3020 each of the areas indexed by the context data can be evaluated based on a corresponding evaluation metric.Corresponding evaluation metrics have already been described above in connection with box 3520. The same evaluation metrics or components of the evaluation metric can also be applied during the inference in box 3020. Such evaluation metrics relate, for example, to an evaluation of the regions based on an edge length of edges of the regions, wherein this edge length can be compared with a size threshold. The size threshold was discussed, for example, in connection with FIG. 10A: critical length 590. The size threshold can be indicated by the context data. Another exemplary component of the evaluation metric could, for example, relate to the classification of an region as safe or unsafe based on a distance to positions in the input vector space recognized as unsafe.Such positions in the input vector space that are recognized as uncertain could be determined based on a progression of class boundaries, as described above.
[0162] If the evaluation metric comprises several components, these components can be hierarchically ordered. This can mean that the partitioning treats a first criterion with a higher hierarchy than a second criterion (the first criterion therefore has a higher hierarchy level than the second criterion). For example, such a criterion could be checked first; and if it is then determined that a certain area is to be classified as unsafe, for example, it might be unnecessary to assess the area with regard to other criteria of the evaluation metric. For example, it may be particularly desirable to primarily check the distance to positions in the input vector space identified as unsafe with regard to a threshold value (the parameter b; distance 679 in FIG. 10D); and only secondarily to check whether the edge lengths of the edges of the areas are taken into account in relation to the size threshold value (the parameter a).In general, taking b into account can take precedence over the other components of the evaluation metric, including the side length with regard to the threshold value a. In this way, a safety ring can first be placed around all critical states (i.e., unsafe positions in the input vector space). This allows even complex separation surfaces to be treated safely. In the remaining input vector space, a comparatively larger threshold value for the edge length (parameter a) can then be used (compared to a scenario without taking the distances to positions classified as unsafe into account), as this can restrict the occurrence of new clusters away from the dividing line between classes. In this way, safe treatment of the separation surfaces can be ensured, but a large threshold value for the edge length a can also be used to prevent the occurrence of new clusters.Therefore, it may be desirable to first apply the distance threshold b to classify the areas with the highest priority and then, secondarily, to evaluate the areas with regard to the edge length with regard to the threshold a .
[0163] Performing the partitioning for inference in box 3020 can have certain advantages over performing the partitioning during the parameterization of the machine-learned algorithm (cf. FIG. 5A: box 3520). In particular, it would be conceivable for the evaluation metric to be adapted during the inference based on the current circumstances of the physical-technical system. This means that, depending on the operating situation of the physical-technical system, a different partitioning can be determined for the multiple areas, so that, depending on the operating situation of the physical-technical system, certain areas can be classified as safe or unsafe. In this way, an adapted safety level for the control system based on the machine-learned algorithm can be achieved, tailored to the current operating situation of the physical-technical system.
[0164] For example, it would be conceivable for the evaluation metric to be parameterized based on an operating mode of the technical-physical system. The operating mode can be associated with the status data. This means that the status data (see FIG. 1: status data 81) are always provided by the physical-technical system, and their values depend on which operating mode is activated.
[0165] For example, the evaluation metric could be parameterized based on an operational reliability level of the function to be performed by the technical-physical system, which is specific to the operating mode. This is based on the realization that certain technical-physical systems can be operated in different operating modes, which require different operational reliability levels for automatic control. One example would be semi-autonomous versus fully autonomous driving. With semi-autonomous controls (e.g., "Level 2" - partially automated driving), the driver retains access to the vehicle, so the operational reliability level for the control may be reduced compared to fully autonomous controls (e.g., "Level 5" - autonomous driving).Accordingly, it would be conceivable that a different evaluation metric would be used to partition the areas for the reliability of the prediction, depending on whether semi-autonomous or fully autonomous driving is implemented based on the prediction of the machine-learned algorithm.
[0166] For example, if the regions are classified based on the edge length compared to a predefined size threshold (see FIG. 10A: critical length 590), it is conceivable that this edge length could be chosen to be shorter or longer depending on the operating mode of the technical-physical system. A larger size threshold would then result in a larger number of regions for which a reliable prediction of the machine-learned algorithm is assumed.
[0167] Examples were described above in which the context data indicates further information beyond the regions; in particular, an example was described above in which it is possible for the context data to indicate the partitioning of the regions. In addition to such further information provided by the context data, other information could also be provided by the context data.
[0168] In some scenarios it would be conceivable for the context data to indicate one or more permissible results for the hidden system state for at least some of the plurality of regions. This means that - in addition to indicating the various regions in the input vector space - it can also be specified which permissible output values the output vector may assume, provided the input vector is positioned in a corresponding region. For example, FIG. 12 shows a scenario in which the context data 50 describe a plurality of regions 771-776 (the regions form a triangular network and are separated by corresponding triangular surfaces - in FIG.12 (limited by the lines due to the two-dimensional representation) and specify an indicator 751 for each of the regions 771-776, which describes the partitioning of the regions into those with a low uncertainty and others with a high certainty of estimating the hidden system state using the machine-learned algorithm. In addition, a further indicator 752 is present, which indicates one or more permissible results for the estimated hidden system state. A corresponding description was also provided in FIG. 5A in connection with box 3516.
[0169] Outside the ranges 771-776, extrapolation (e.g. for point 779) could be present (cf. TAB. 1: Security level III), so that a reliable prediction is not possible here.
[0170] In box 3025 in FIG. 11, it is then possible to determine the relative position of the input vector with respect to the regions. For example, it could be checked whether the input vector lies within a specific region or outside all regions. For example, if the context data indexes the regions by the boundaries between the regions, a corresponding check could involve forming subspaces in the input vector space based on the corresponding boundaries.
[0171] Based on this relative position, it can then be checked in box 3030 whether either - box 3035 - an error indicator should be output (i.e. the output of the machine-learned algorithm is blocked) or in box 3040 the input vector of the machine-learned algorithm should be processed (i.e. the output of the machine-learned algorithm is allowed and processed further).
[0172] For example, the error indicator in box 3035 could be output precisely when the input vector is not located in any area (in such a case, it may be unnecessary to partition the areas). It would also be conceivable for the error indicator to be output even when the input vector lies in an area associated with a large uncertainty in estimating the hidden system state, for example as indicated by the corresponding indicator 751 in the context data 750; or as determined by the partitioning in box 3020. If the error indicator is output in box 3035, this can be taken into account in box 3050 for controlling the technical-physical system. For example, the technical-physical system could be transferred to a safe operating state. A warning could be issued to an operator of the technical-physical system.An error log file could be supplemented accordingly.
[0173] When the machine-learned algorithm processes the input vector in box 3040, the machine-learned algorithm then produces an output vector that is indicative of the hidden system state of the technical-physical system. In some examples, this output could then be used to control the technical-physical system, box 3050.
[0174] Optionally, it would also be conceivable in box 3045 to adapt the hidden system state obtained as output from the machine-learned algorithm in box 3040 based on permissible results for the system state indicated by the context data (cf. FIG. 12: indicator 752). For example, averaging could occur, for example when a regression task is performed by the machine-learned algorithm. In a regression task, in addition to the prediction value, information concerning a probability distribution of the prediction value can also be output. This probability distribution can depend on the distance to areas with indicators of other values from the position of the input vector in the input space.
[0175] Another example is illustrated in FIG. 13. FIG. 13 basically corresponds to FIG. 12. In the example of FIG. 13, however, the context data 50 are structured such that a corresponding indicator 753 is provided in connection with each corner of the areas 771-776, which indicator indicates a respective permitted result for the estimated system state or the output of the machine-learned algorithm. It would then be possible to determine a distance between the position of the input vector in relation to the various corners of the areas 771-776 and to select the respective permitted result (or - for a regression task - the probability distribution) based on these distances. The corners of the areas 771-776 correspond to the positions of corresponding input vectors of the underlying training data set; the permitted results could be selected here based on the corresponding ground truths.For example, the nearest corner could be considered in each case and then, based on the indicator 753 associated with that corner, the permissible result for the output of the machine-learned algorithm could be determined (for the input vector 85 shown in FIG. 13, this would be "blue").
[0176] The scenarios shown in FIGS. 12 and 13 are only examples. Other techniques would also be conceivable to determine the permissible results for the system state. For example, it would be conceivable that the predicted hidden system state may only assume values that are no further than from the allowed results indicated by the context data 50. This can be particularly helpful for regression tasks
[0177] Referring again to FIG. 11, there may be situations where the output of the machine-learned algorithm from box 3040 does not match the one or more allowed results determined from the context data 750. It is possible to compare the hidden system state estimated by processing the input vector in the machine-learned algorithm with the corresponding allowed results for the range from the context data, box 3045. If the comparison indicates no or only a reduced match, an error indicator may be output.
[0178] Boxes 3040 and 3045 thus correspond to a two-stage approach. First, in Box 3040, candidate results are determined using the machine-learned algorithm; these can then be corrected, if necessary, in Box 3045 based on the context data.
[0179] In box 3050, the technical-physical system can then be controlled based on the error indicator (from box 3035 or, if applicable, from box 3045) and / or the estimated hidden system state from box 3040. For example, corresponding control data could be sent to the technical-physical system.
[0180] In summary, techniques were described above in which context data is generated in connection with the training of a machine-learned algorithm. The context data is indicative of regions in the input vector space that are associated with certain or uncertain predictions of the machine-learned algorithm. The regions can, for example, be generated as a Delaunay triangulation between positions of input vectors of a training dataset. The regions therefore form hyperspace volumes. Each hyperspace volume can be assigned the set of output classes of the examples that form the corner points of the hyperspace volume as a marking. If the distance between all points in the input space is less than "a", the attribute "certain" is additionally set for the marking. The attribute "certain" for the marking means that exactly the outputs that are present in the examples that bound the hyperspace volume can occur.Other outputs may not occur in this case because of the assumption regarding "a" that no double class change occurs.
[0181] Of course, the features of the previously described embodiments and aspects of the invention can be combined with one another. In particular, the features can be used not only in the described combinations, but also in other combinations or on their own, without departing from the scope of the invention.
Claims
Patentan's Sayings 1. A computer-implemented method for estimating a hidden system state of a technical-physical system using a machine-learned algorithm, the method comprising: - Obtaining an input vector (85, 511, 512, 513, 521, 522, 523, 550) encoding state data (81) of the technical-physical system (95), - Loading the machine-learned algorithm (89) , - loading predetermined context data (50) associated with the machine-learned algorithm (89) and indexing a plurality of regions (72, 571, 572, 573, 574, 771-776) in the vector space (71) of the input vector (85, 511, 512, 513, 521, 522, 523, 550), - determining a relative position of the input vector (85, 511, 512, 513, 521, 522, 523, 550) with respect to the plurality of regions (72, 571, 572, 573, 574, 771-776), and - based on the relative position, either processing the input vector in the machine-learned algorithm to estimate the hidden system state or outputting an error indicator.
2. The computer-implemented method of claim 1, wherein one or more first regions (571, 572) of the plurality of regions are associated with a comparatively low uncertainty of estimating the hidden system state, wherein one or more second regions (573) of the plurality of regions are associated with a comparatively high uncertainty of estimating the hidden system state.
3. The computer-implemented method of claim 2, wherein the context data (50) comprises an indicator (751) indicating a partitioning of the plurality of regions into the one or more first regions and the one or more second regions.
4. A computer-implemented method according to claim 2, wherein the method further comprises: - after loading the context data (50) and based on a predetermined evaluation metric, determining (3020) a partitioning of the plurality of areas into the one or more first areas and into the one or more second areas.
5. A computer-implemented method according to claim 4, wherein the method further comprises: - parameterizing the evaluation metric based on an operating mode of the technical-physical system associated with the state data (81).
6. The computer-implemented method according to claim 5, wherein the evaluation metric is parameterized based on an operational reliability level of the technical-physical system (95) that is specific to the operating mode.
7. The computer-implemented method of claim 5 or 6, wherein the evaluation metric comprises a component that partitions the plurality of regions based on an edge length of edges of the regions of the plurality of regions, wherein a size threshold (590) for the edge length that decides between an assignment to the plurality of first regions and the plurality of second regions is selected based on the operating mode.
8. The computer-implemented method of any one of claims 4 to 7, wherein the evaluation metric comprises a component that partitions the plurality of regions based on a distance (679) to positions (663) in the input vector space that are identified as unsafe.
9. A computer-implemented method according to any one of claims 4 to 8, wherein the evaluation metric comprises a plurality of components that are hierarchically ordered.
10. The computer-implemented method of any preceding claim, wherein the predetermined context data (50) comprises an indicator (752) indicating one or more permissible outcomes for the hidden system state for at least some of the plurality of regions.
11. A computer-implemented method according to claim 10, wherein the method further comprises: - adjusting (3045) the hidden system state estimated by processing the input vector in the machine-learned algorithm (89) based on the allowed results for the system state for that region of the plurality of regions in which the input vector is positioned.
12. The computer-implemented method of claim 11, wherein the method further comprises: - Determining a distance of the position of the input vector with respect to edges or corners of that region of the plurality of regions in which the input vector is positioned, wherein the predetermined context data for this region, in in which the input vector is positioned, indicate multiple allowed outcomes for the hidden system state, wherein different ones of the multiple allowed outcomes in the context data are associated with different edges or corners of this region in which the input vector is positioned, and - selecting the one of the plurality of allowed outcomes that is associated with the edges or corners of the region in which the input vector is positioned to which the position of the input vector is closest, wherein the hidden system state is corrected based on the selected allowed outcome.
13. A computer-implemented method according to claim 11 or 12, wherein the method further comprises: - Comparing the hidden system state estimated by processing the input vector in the machine-learned algorithm with the corresponding allowed system state results for that region of the plurality of regions in which the input vector is positioned, and optionally outputting the error indicator based on the comparison.
14. Computer-implemented method according to one of the preceding claims, wherein the context data describe a triangular mesh, wherein the regions of the plurality of regions are bounded by triangular surfaces of the triangular mesh.
15. A computer-implemented method according to any one of the preceding claims, wherein the method further comprises: - controlling (3050) the technical-physical system (95) based on at least one of the estimated hidden system state or the error indicator.
16. A computer-implemented method for parameterizing a machine-learned algorithm (89) by means of which a hidden system state of a technical-physical system (95) can be estimated, the method comprising: - Obtaining (3505) a training data set comprising several training data pairs of input vectors (85, 511, 512, 513, 521, 522, 523, 550) encoding state data of the technical-physical system (95) and ground truths for the hidden system state of the technical-physical system (95), - performing (3510) training of the machine-learned algorithm (89) based on the training data set in order to obtain parameter values for the machine-learned algorithm, - based on the input vectors (85, 511, 512, 513, 521, 522, 523, 550), determining (3515) a plurality of regions (72, 571, 572, 573, 574, 771-776) in the vector space (71) of the input vectors, - generating context data (50) for the machine-learned algorithm so that it is indicative of the plurality of areas, and - storing the machine-learned algorithm (89) and storing the context data (50) associated with the machine-learned algorithm (89).
17. A computer-implemented method according to any one of the claims, wherein the method further comprises: - based on a predetermined evaluation metric, determining (3520) a partitioning of the areas of the plurality of areas into first areas and second areas, wherein the first areas are associated with a low uncertainty for the estimation of the hidden system state with respect to the evaluation metric, wherein the second areas of the plurality of areas are associated with a high uncertainty for the estimation of the hidden system state with respect to the evaluation metric, and - based on the partitioning, determining (3530) one or more further positions in the vector space (71) at which further training data pairs are to be positioned.
18. A computer-implemented method according to claim 17, wherein the method further comprises: - Driving a human-machine interface to obtain a ground truth annotation for the hidden system state for the further training data pairs.
19. A computer-implemented method according to claim 17 or 18, wherein the method further comprises: - Setting up a software simulation of the technical-physical system in order to obtain the ground truth for the hidden system state for the further training data pairs.
20. Computer-implemented method according to one of claims 17 to 19, wherein the one or more further positions in the vector space (71) are selected such that after a redetermination of the plurality of regions taking into account the training data pairs and the further training data pairs, a total size of the first regions increases to a maximum.
21. Computer-implemented method according to one of claims 16 to 20, wherein at least some of the plurality of regions are arranged between positions of the input vectors in the corresponding vector space ( 71 ) .
22. A computer-implemented method according to any one of claims 16 to 21, wherein at least some regions of the plurality of regions surround positions of an input vector in the corresponding vector space that are recognized as uncertain.
23. A computer-implemented method according to claim 22, wherein the method further comprises: - Identification of the more uncertain positions based on a progression of class boundaries.
24. A computer-implemented method according to any one of claims 16 to 23, the method further comprising: - based on a predetermined evaluation metric, determining a partitioning of the plurality of regions into first regions and second regions, wherein the first regions are associated with a low uncertainty for the estimation of the hidden system state with respect to the evaluation metric, wherein the second regions of the plurality of regions are associated with a high uncertainty for the estimation of the hidden system state with respect to the evaluation metric, wherein the context data is indicative of the partitioning of the regions.
25. The computer-implemented method of claim 24, wherein the evaluation metric comprises a component that partitions the plurality of regions based on an edge length of edges of the regions of the plurality of regions.
26. A computer-implemented method according to claim 24 or 25, wherein the evaluation metric comprises a component that partitions the regions based on a local variation of the ground truths for the hidden system state.
27. A computer-implemented method according to any one of claims 24 to 26, wherein the evaluation metric comprises a component that evaluates the regions based on a distance (679) to a position (663) recognized as unsafe in the vector space of the input vectors.
28. A computer-implemented method according to claim 27, further comprising: - Detection of uncertain positions in the vector space of the input vectors based on a progression of class boundaries.
29. A computer-implemented method according to any one of claims 16 to 28, wherein the regions are bounded by areas extending in vector space between the positions of adjacent input vectors.
30. A computer-implemented method according to any one of claims 16 to 29, the method further comprising: - Determining the regions (72, 571, 572, 573, 574, 771-776) of the plurality of regions (72, 571, 572, 573, 574, 771-776) based on triangular surfaces of a triangular network whose nodes are formed by the input vectors (85, 511, 512, 513, 521, 522, 523, 550).
31. A computer-implemented method according to claim 30, wherein the triangular mesh is formed by a Delaunay triangulation or a min-max triangulation.
32. Computer-implemented method according to one of claims 24 to 28, and according to claim 30 or 31, wherein the one or more first regions are bounded only by triangular surfaces which do not have a side edge which is longer than a threshold value predetermined by the evaluation metric.
33. Computer-implemented method according to claim 32, wherein at least one of the one or more second regions is each bounded by at least one triangular surface having at least one side edge that is longer than the predetermined threshold value.
34. A computer-implemented method according to claim 32 or 33, wherein the method further comprises: - Parameterizing the evaluation metric, wherein the parameterizing of the evaluation metric comprises: determining the predetermined threshold based on at least one criterion.
35. The computer-implemented method of claim 34, wherein the at least one criterion comprises a minimum distance between two different input vectors of the training data set that are associated with different hidden system states.
36. A computer-implemented method according to claim 35, wherein the method further comprises: - Plausibility check of the minimum distance based on one or more additional training data pairs that have input vectors at positions that are at a distance from a a position of an input vector of the training data pairs that is smaller than the minimum distance.
37. Computer-implemented method according to one of claims 34 to 36, wherein the at least one criterion comprises a design specification of a development process of the technical-physical system.
38. Computer-implemented method according to one of claims 34 to 37, wherein the at least one criterion comprises a specification for an operational safety level of the technical-physical system.
39. Computer-implemented method according to one of claims 34 to 38, wherein the at least one criterion comprises domain knowledge.
40. A computer-implemented method according to any one of claims 24 to 39, wherein the context data is generated such that it is indicative of permissible results of the hidden system state for at least some of the plurality of regions, the method further comprising: - for each of the at least some regions: determining (3516) the allowed results of the hidden system state based on the ground truths for the hidden system state associated with the nodes of the triangular faces of the triangular network bounding the respective region.
41. A computer-implemented method for estimating a hidden system state of a technical-physical system using a machine-learned algorithm, the method comprising: - depending on at least one predetermined criterion, optionally allowing or blocking an estimation of the machine-learned algorithm for the hidden system state for an input vector, wherein the at least one predetermined criterion takes into account a position of the input vector in the corresponding input vector space.
42. A computer-implemented method according to claim 41, wherein the prediction is blocked if the position of the input vector corresponds to an extrapolation of the machine-learned algorithm based on state data of the technical-physical system included in a training data set for the machine-learned algorithm.
43. Computer-implemented method according to claim 41 or 42, wherein the prediction is blocked if the position of the input vector corresponds to an interpolation of the machine-learned algorithm between two or more state data of the technical-physical system included in a training data set for the machine-learned algorithm, and if a distance between the positions in the input vector space corresponding to the two or more state data is greater than a predetermined threshold value. 44 . Computer-implemented method according to one of claims 41 to 43 , wherein the prediction is allowed if the position of the input vector corresponds to an interpolation of the machine-learned algorithm between two or more state data of the technical-physical system included in a training data set for the machine-learned algorithm, and if a distance between the positions in the input vector space corresponding to the two or more state data is smaller than a predetermined threshold value.
45. Computer-implemented method according to one of claims 41 to 44, wherein the prediction is blocked if the position of the input vector falls below a minimum distance (679) to positions (663) in the input vector space that are labeled as uncertain.
46. A computer-implemented method according to any one of claims 41 to 45, wherein the at least one criterion comprises a plurality of criteria, the method further comprising: - sequential checking of multiple criteria.
47. Apparatus comprising at least one processor and a memory, wherein the at least one processor is configured to load and execute program code from the memory, wherein the at least one processor is configured to execute a computer-implemented method according to one of claims 1 to 46 based on the program code. 48 . A computer program comprising program code that can be loaded and executed by at least one processor, wherein the at least one processor is configured to execute the Program codes carry out a computer-implemented method according to one of claims 1 to 46.