Autonomous-driving-based capability boundary processing method, and device and medium
By real-time detection of the environment and performance data of autonomous mobile devices and implementing degradation strategy control based on capability boundaries, the safety issues of the autonomous driving system during capability boundary detection are resolved, and the safe and stable operation of the equipment is achieved.
Patent Information
- Application Number
- PCT/CN2025/081027
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-02
- Filing Date
- 2025-03-06
- Publication Date
- 2025-10-09
AI Technical Summary
When existing autonomous driving systems detect the limits of their capabilities, they will directly exit autonomous driving mode, resulting in users being unable to take over operations in a timely manner, causing safety issues.
By real-time detection of the surrounding environment data and performance indicator data of autonomous mobile devices, it is determined whether the preset capability boundaries are violated. According to the degradation strategy corresponding to the target capability boundary, the device is controlled to perform degradation operations or minimum risk operations to ensure driving safety.
It effectively ensures the safety of autonomous mobile equipment during driving, avoids ignoring performance limitations caused by single trigger condition detection, and realizes dynamic adjustment and safety assurance of equipment.
Smart Images

Figure CN2025081027_09102025_PF_FP_ABST
Abstract
Description
Capability boundary processing method, device and medium based on autonomous driving
[0001] This application claims priority to the Chinese patent application filed with the China Patent Office on April 2, 2024, with application number 202410389381.0 and application name “Capability boundary processing method, device and medium based on autonomous driving”, all contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of autonomous driving system safety technology, and in particular to a capability boundary processing method, device, and medium based on autonomous driving. Background Art
[0003] With the rapid development of autonomous driving technology, various autonomous driving systems have been widely researched and developed, aiming to achieve autonomous driving of autonomous mobile devices through perception, decision-making and control technologies.
[0004] In the current autonomous driving technology architecture, these systems rely on sophisticated algorithms and sensor technology to accurately capture environmental information, identify road signs, other objects and pedestrians, and predict driving routes.
[0005] However, in the current autonomous driving system, when the autonomous driving system detects the limit of its capabilities, it will directly exit the autonomous driving mode, and the user cannot take over the operation in time, which can easily cause safety problems. Summary of the Invention
[0006] This application provides a capability boundary processing method, device and medium based on autonomous driving, which can effectively ensure the safety of autonomous mobile devices during driving.
[0007] In a first aspect, an embodiment of the present application provides a method for processing capability boundaries based on autonomous driving, which is applied to an autonomous mobile device, the method comprising:
[0008] determining, based on real-time acquired ambient environment data and performance indicator data of the autonomous mobile device, whether the autonomous mobile device violates at least one preset capability boundary, the at least one capability boundary comprising at least one performance boundary and / or environmental safety boundary for safe driving of the autonomous mobile device;
[0009] If the autonomous mobile device violates the target capability boundary, the autonomous mobile device is controlled to perform a downgrade operation according to a downgrade policy corresponding to the target capability boundary.
[0010] In a possible design of the first aspect, the method further includes:
[0011] If, within a first preset time period after executing the downgrade operation corresponding to the downgrade strategy, it is determined that the autonomous mobile device continues to violate the target capability boundary, adjusting the downgrade strategy based on current performance indicator data and / or surrounding environment data to obtain an updated downgrade strategy;
[0012] The autonomous mobile device is controlled to perform a downgrade operation according to the updated downgrade policy.
[0013] In a possible design of the first aspect, the method further includes:
[0014] If it is determined that the autonomous mobile device continues to violate the target capability boundary within a second preset time period after executing the updated degradation policy, the autonomous mobile device is controlled to execute a minimum risk operation corresponding to the target capability boundary.
[0015] In a possible design of the first aspect, the capability boundary includes:
[0016] At least one performance boundary and / or environmental safety boundary, wherein
[0017] The performance boundaries include an inter-frame consistency threshold of the autonomous mobile device position, an inter-frame consistency threshold of the autonomous mobile device speed, a threshold of the degree of deviation between the planned trajectory and the road centerline, and a threshold of the longitudinal position control error of the autonomous mobile device;
[0018] The environmental safety boundary includes a rainfall threshold, a snow threshold, a temperature threshold, a light intensity threshold, and a curve curvature radius threshold.
[0019] In a possible design of the first aspect, the degradation strategy includes at least one of the following control schemes:
[0020] Degradation through speed limit control;
[0021] Degradation of lane change control by inhibiting autonomous mobile equipment;
[0022] Control degradation by limiting lateral trajectory planning;
[0023] Push security prompts to allow users to control autonomous mobile device downgrades.
[0024] In a possible design of the first aspect, the minimum risk operation includes at least one of the following operations:
[0025] Limiting autonomous mobile device acceleration;
[0026] Limit the change of movement direction;
[0027] Control the autonomous mobile device to glide to a stop;
[0028] Control the autonomous mobile device to decelerate uniformly until it stops;
[0029] Controls the autonomous mobile device to pull over and stop.
[0030] In a possible design of the first aspect, before determining whether the autonomous mobile device violates at least one preset capability boundary based on the ambient environment data and performance indicator data of the autonomous mobile device acquired in real time, the method further includes:
[0031] In response to an expected functional safety configuration operation by a user, obtaining at least one capability boundary of the autonomous mobile device during driving, a degradation strategy corresponding to each capability boundary, and a minimum risk operation, wherein the at least one capability boundary is determined based on a safety analysis method and an autonomous mobile device test experiment;
[0032] The autonomous mobile device is configured to perform capability boundary detection and processing during the autonomous driving process based on the at least one capability boundary, the degradation strategy corresponding to each capability boundary, and the minimum risk operation.
[0033] In a possible design of the first aspect, before obtaining at least one capability boundary of the autonomous mobile device during driving in response to the user's expected functional safety configuration operation, the method further includes:
[0034] Based on each test scenario in a predefined test scenario set, performing a simulation test and / or an actual test on the autonomous mobile device, recording performance indicator data, surrounding environment data, and a timestamp of a user taking over control when a lateral hazard and / or a longitudinal hazard occurs at each moment;
[0035] The at least one capability boundary is determined by performing statistical analysis based on the performance indicator data at each moment, the surrounding environment data, and the timestamp of the user taking over control when the horizontal hazard and / or the vertical hazard occurs.
[0036] In a second aspect, an embodiment of the present application provides a device for processing capability boundaries based on autonomous driving, the device comprising:
[0037] a first processing module, configured to determine, based on real-time acquired ambient environment data and performance indicator data of the autonomous mobile device, whether the autonomous mobile device violates at least one preset capability boundary, the at least one capability boundary comprising at least one performance boundary and / or environmental safety boundary for safe driving of the autonomous mobile device;
[0038] The second processing module is configured to control the autonomous mobile device to perform a downgrade operation according to a downgrade policy corresponding to the target capability boundary if the autonomous mobile device violates the target capability boundary.
[0039] In a third aspect, an embodiment of the present application provides an autonomous mobile device, comprising: a processor, and a memory communicatively connected to the processor;
[0040] The memory stores computer-executable instructions;
[0041] The processor executes the computer-executable instructions stored in the memory to implement the capability boundary processing method based on autonomous driving as described in any one of the first aspects.
[0042] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, which stores computer execution instructions. When the computer execution instructions are executed by a processor, they are used to implement the capability boundary processing method based on autonomous driving as described in any one of the first aspects.
[0043] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program, which, when executed by a processor, implements the capability boundary processing method based on autonomous driving as described in any one of the first aspects.
[0044] The capability boundary processing method, device and medium based on autonomous driving provided in this application relate to the field of autonomous driving system safety technology. Among them, the capability boundary processing method based on autonomous driving is applied to autonomous mobile devices. Specifically, the method determines the capability boundary of the autonomous mobile device by combining safety analysis and test verification, so as to avoid the problem of imperfect capability boundary analysis that may be caused by relying solely on expert experience. At the same time, the autonomous mobile device is monitored in real time through an online detection scheme to see whether it exceeds the capability boundary. When it exceeds the target capability boundary, the device is controlled to perform a downgrade operation or a minimum risk operation according to the corresponding downgrade strategy, avoiding the situation where relying solely on a single trigger condition detection may cause certain performance limitations to be ignored. On this basis, the method uses the risk rebalancing principle to adjust the driving status of the autonomous mobile device online to ensure driving safety. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0046] FIG1 is a schematic diagram of an application scenario of the method for processing capability boundaries based on autonomous driving provided by this application;
[0047] FIG2 is a flowchart of a first embodiment of a method for processing capability boundaries based on autonomous driving provided by this application;
[0048] FIG3 is a flowchart of a second embodiment of a method for processing capability boundaries based on autonomous driving provided by this application;
[0049] FIG4 is a flowchart of a third embodiment of a method for processing capability boundaries based on autonomous driving provided by this application;
[0050] FIG5 is a flowchart of a fourth embodiment of a method for processing capability boundaries based on autonomous driving provided by this application;
[0051] FIG6 is a schematic diagram of identifying vehicle performance limitations and triggering conditions based on a causal decision tree provided by this application;
[0052] FIG7 is a flowchart of a fifth embodiment of a method for processing capability boundaries based on autonomous driving provided by this application;
[0053] FIG8 is a schematic diagram of the overall process of a method for processing capability boundaries based on autonomous driving provided by this application;
[0054] FIG9 is a schematic structural diagram of a first embodiment of a capability boundary processing device based on autonomous driving provided by the present application;
[0055] FIG10 is a schematic structural diagram of a second embodiment of a capability boundary processing device based on autonomous driving provided by the present application;
[0056] FIG11 is a schematic structural diagram of an autonomous mobile device for processing capability boundaries based on autonomous driving provided in this application.
[0057] The above drawings illustrate specific embodiments of the present application, which will be described in more detail below. These drawings and the textual description are not intended to limit the scope of the present application in any way, but rather to illustrate the concepts of the present application to those skilled in the art by reference to specific embodiments. DETAILED DESCRIPTION
[0058] To make the purpose, technical solutions, and advantages of the embodiments of this application more clear, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0059] With the continuous advancement of autonomous driving technology, various autonomous driving systems are attracting widespread attention and in-depth research. Based on this trend, more and more devices are achieving autonomous movement by configuring autonomous driving systems.
[0060] In the current autonomous driving technology framework, autonomous driving systems leverage intelligent algorithms and sensor technology to not only capture real-time information about the surrounding environment but also accurately identify road signs and traffic signals. By analyzing and processing this data, autonomous driving systems can predict optimal driving paths, including lane selection, turn determination, and speed adjustment, enabling fully autonomous driving for mobile devices.
[0061] However, current autonomous driving systems still have limitations when faced with complex and unexpected traffic situations. In particular, when the system detects that its capabilities have been exceeded, it automatically exits autonomous driving mode and requires the user to immediately take over control to ensure safety. However, in some cases, the user may not be able to respond and take over in a timely manner, which can pose a safety risk.
[0062] In response to the above issues, the inventors discovered during their research on autonomous driving systems that, during real-time operation, once the system detects that the current driving scenario exceeds its capability boundaries, it will directly exit autonomous driving mode without outputting the control signals required to address the capability boundaries or providing clear and logical user takeover prompts. This makes it difficult to effectively ensure safety. Based on this, the inventors considered whether it would be possible to use online detection methods to detect the capability boundaries of autonomous mobile devices in real time during real-time driving, based on the predefined capability boundary degradation and minimum risk operations, to ensure that the autonomous mobile devices dynamically adjust their driving status, thereby ensuring driving safety.
[0063] Figure 1 is a schematic diagram of an application scenario for the autonomous driving capability boundary processing method provided by this application. As shown in Figure 1, the application scenario of the solution provided by this application includes an autonomous mobile device 100. Autonomous mobile device 100 includes a detection system 101 and a processing system 102, which interact with each other in real time. Autonomous mobile device 100 can be an autonomous vehicle equipped with an autonomous driving system or a robot equipped with an automatic control device, without limitation.
[0064] While the autonomous mobile device 100 is actually driving, the detection system 101 configured in the autonomous mobile device 100 obtains real-time environmental information surrounding the autonomous mobile device 100 and obtains performance indicator information of the autonomous mobile device 100 to determine whether the autonomous mobile device 100 currently violates at least one preset capability boundary. The capability boundary includes at least one performance boundary and / or environmental safety boundary for the safe driving of the autonomous mobile device 100.
[0065] Based on the real-time detection results of the detection system 101, if the autonomous mobile device 100 currently violates at least one preset capability boundary, the processing system 102 configured in the autonomous mobile device 100 controls the autonomous mobile device 100 to perform a degraded operation or a minimum risk operation according to the degradation strategy corresponding to the target capability boundary, thereby ensuring the driving safety of the autonomous mobile device 100.
[0066] Although only one autonomous mobile device 100 is shown in FIG. 1 , it should be understood that two or more autonomous mobile devices 100 may be present.
[0067] The technical solutions shown in this application are described in detail below through specific embodiments. It should be noted that the following embodiments can exist independently or in combination with each other, and the same or similar contents will not be repeated in different embodiments.
[0068] FIG2 is a flow chart of a first embodiment of a method for processing capability boundaries based on autonomous driving provided by this application. As shown in FIG2 , the process of the method for processing capability boundaries based on autonomous driving may include:
[0069] S201: Determine whether the autonomous mobile device violates at least one preset capability boundary based on real-time acquired ambient environment data and performance indicator data of the autonomous mobile device, where the at least one capability boundary includes at least one performance boundary and / or environmental safety boundary for safe driving of the autonomous mobile device.
[0070] In this step, to ensure the safety of the autonomous mobile device during real-time driving, a control system must be preconfigured within the autonomous mobile device. This control system can acquire real-time data about the autonomous mobile device's surroundings and performance indicators, determine whether the autonomous mobile device violates at least one pre-set capability boundary, and thereby ensure that the autonomous mobile device can meet various driving conditions and maintain safety during driving. For example, the autonomous mobile device could be a self-driving car, for which the corresponding control system would be an autonomous driving system. Alternatively, the autonomous mobile device could be a robot, for which the corresponding control system would be a robot control system.
[0071] Specifically, ambient data refers to various information about the surrounding environment of an autonomous mobile device during real-time driving. This data can be acquired in real time by various sensors within the autonomous mobile device. This ambient data includes visual data, acoustic data, distance data, position data, and environmental parameter data. For example, visual data includes images and depth information acquired by sensors such as cameras or lidar, which can be used to detect and identify objects, obstacles, and road signs around the autonomous mobile device. Acoustic data includes sound signals acquired by sound acquisition devices such as microphones or sonar sensors, and is used for sound recognition and ambient noise detection. Distance data includes object distance information acquired by distance detection devices such as ultrasonic sensors or laser rangefinders, and is used for obstacle avoidance and navigation. Position data includes the current position and direction of the autonomous mobile device acquired by sensors such as the Global Positioning System and inertial navigation devices. Environmental parameter data includes measurement results of environmental parameters such as temperature, humidity, and air pressure. Environmental parameter data can be acquired through environmental sensors and used for environmental monitoring and adaptive control.
[0072] By acquiring and analyzing these surrounding environment data, autonomous mobile devices can perceive and understand the surrounding environment in order to make corresponding decisions and actions, thereby achieving safe and efficient autonomous navigation and interaction.
[0073] Performance indicator data refers to the data on various performance indicators of autonomous mobile devices during real-time driving. These data can reflect the performance status of autonomous mobile devices in real time. For example, common performance indicator data include speed, energy consumption, stability, and fault diagnosis data. Among them, speed includes the current speed and acceleration of the autonomous mobile device, which is used to control the operating status of the autonomous mobile device. Energy consumption includes information such as energy consumption and battery power during the current driving of the autonomous mobile device, which is used to optimize energy management and extend the operating time of the autonomous mobile device. Stability includes information such as the driving posture and vibration of the autonomous mobile device during driving, which is mainly used to judge the stability and control accuracy of the autonomous mobile device. Fault diagnosis data includes information such as fault codes and sensor anomalies generated by the autonomous mobile device during driving, which is used to monitor the operating status of the autonomous mobile device.
[0074] The capability boundary includes at least one performance boundary and / or environmental safety boundary for safe driving of the autonomous mobile device. These capability boundaries can be determined based on the hardware and software capabilities of the autonomous mobile device, environmental conditions, and safety considerations.
[0075] Performance boundaries refer to the limitations of an autonomous mobile device's ability to process and execute tasks and functions under specific conditions. For example, performance boundaries include the maximum permissible speed, maximum load, and continuous operating time of an autonomous mobile device during driving.
[0076] The environmental safety boundary refers to the range within which autonomous mobile devices can safely operate in a specific environment. For example, the environmental safety boundary includes the minimum safe distance from obstacles, the temperature tolerance threshold, and the light tolerance threshold.
[0077] Based on the preset capability boundaries, the control system built into the autonomous mobile device can obtain real-time surrounding environment data and performance indicator data under the current driving state, analyze and process them, and compare them with the preset capability boundaries in real time. Based on different comparison results, the control system built into the autonomous mobile device will execute different control functions to ensure driving safety.
[0078] S202: If the autonomous mobile device violates the target capability boundary, the autonomous mobile device is controlled to perform a degradation operation according to a degradation policy corresponding to the target capability boundary.
[0079] In this step, based on step S201, after the autonomous mobile device acquires real-time ambient data and performance indicator data, it analyzes and processes this data and compares it with the corresponding capability boundary in real time. If the autonomous mobile device violates the target capability boundary, the device is controlled to perform a downgrade operation according to the corresponding downgrade policy.
[0080] It's important to note that there may be multiple capability boundaries. Whenever an autonomous mobile device is detected violating at least one capability boundary, a corresponding degradation strategy is implemented. For example, autonomous mobile device A has three preset capability boundaries: capability boundary 1, capability boundary 2, and capability boundary 3. During real-time driving, if the acquired ambient environment data and performance indicator data are analyzed and processed and a violation of capability boundary 1 is detected, the control system built into autonomous mobile device A will control autonomous mobile device A to perform a degradation operation based on the degradation strategy corresponding to capability boundary 1.
[0081] Optionally, the control system built into the autonomous mobile device has pre-configured driving strategy levels. Each level corresponds to a different driving strategy for the autonomous mobile device, including various parameters and instructions. If a performance boundary is violated during driving, the autonomous mobile device will be downgraded from the current higher level. Higher-level strategies have higher decision-making capabilities than lower-level strategies, such as higher speeds, stronger autonomous lane-changing capabilities, and more flexible overtaking capabilities. This configuration ensures that the autonomous mobile device can operate safely and stably in various driving scenarios, making the most appropriate driving decisions based on the specific situation. For example, a vehicle is currently operating in a high-level autonomous driving mode and needs to change lanes to avoid an obstacle ahead. The autonomous driving system will control the vehicle to perform an autonomous lane change after detecting surrounding traffic conditions. However, a sudden, rapidly approaching vehicle could make the lane change risky. In this case, the autonomous driving system will determine whether the current autonomous lane change capability exceeds the preset performance boundary. If so, the autonomous driving system will switch to a lower-level mode and notify the driver through an audible alarm or display screen indicating the risk of autonomous lane change, suggesting that the driver take over control.
[0082] Specifically, degradation strategies refer to control measures taken when an autonomous mobile device violates its target capability boundaries. These measures aim to mitigate potential driving risks and ensure the safety of autonomous driving. For example, degradation strategies might include reducing the speed of the autonomous mobile device or rerouting it. By implementing appropriate degradation strategies, abnormalities in the autonomous mobile device can be promptly addressed, ensuring the safety of the autonomous mobile device and its surroundings.
[0083] The capability boundary processing method based on autonomous driving provided in this embodiment can determine whether an autonomous mobile device meets pre-set safe driving standards based on real-time data on the surrounding environment and performance indicators of the autonomous mobile device. These safe driving standards are set based on target capability boundaries. If the autonomous mobile device fails to meet the standards, that is, violates any target capability boundary, it is controlled according to the set degradation strategy. This processing method can promptly detect and process violations of capability boundaries by autonomous mobile devices, improve the safety of the autonomous mobile device's driving process, and reduce the potential for accidents.
[0084] FIG3 is a flow chart of the second embodiment of the method for processing capability boundaries based on autonomous driving provided by this application. As shown in FIG3 , based on the above embodiment, the process of the method for processing capability boundaries based on autonomous driving also includes:
[0085] S301: If it is determined that the autonomous mobile device continues to violate the target capability boundary within a first preset time period after executing the downgrade operation corresponding to the downgrade strategy, the downgrade strategy is adjusted according to the current performance indicator data and / or surrounding environment data to obtain an updated downgrade strategy.
[0086] In this step, based on step S202, when the autonomous mobile device violates the target capability boundary, according to the demotion strategy corresponding to the target capability boundary, the autonomous mobile device is controlled to perform a demotion operation within the first preset time period. If the autonomous mobile device still continues to violate the target capability boundary, it is necessary to adjust the demotion strategy according to the current performance indicator data and / or surrounding environment data to obtain an updated demotion strategy.
[0087] The degree of persistent violations by autonomous mobile devices is categorized into temporal and spatial dimensions. The temporal dimension refers to the duration of the violation, while the spatial dimension refers to the degree to which the autonomous mobile device consistently violates the target capability boundary within a specific spatial range. Examples include the number of times the autonomous mobile device deviates from the designated planned route, the distance traveled beyond a defined area, the frequency or number of times it failed to correctly identify traffic signals, and the speed limit exceeded.
[0088] Specifically, to avoid incorrectly determining that an autonomous mobile device continuously violates the target capability boundary, a specific time period needs to be set. That is, within the first preset time period after the downgrade policy is executed, only when the autonomous mobile device continuously violates the target capability boundary can it be accurately determined that the downgrade policy needs to be adjusted.
[0089] When an autonomous mobile device violates a target capability boundary, the control system built into the autonomous mobile device controls the autonomous mobile device to perform a degradation operation while also acquiring, analyzing, and processing the performance indicator data and surrounding environment data of the current autonomous mobile device in real time, and continues to detect whether the current autonomous mobile device violates at least one capability boundary.
[0090] If the autonomous mobile device does not continue to violate the target capability boundary within the first preset time period after executing the downgrade operation corresponding to the downgrade strategy, the control system built into the autonomous mobile device does not need to perform other control operations, but only needs to continue to detect whether the current autonomous mobile device violates at least one capability boundary.
[0091] If, within a first preset time period after executing a downgrade operation corresponding to the downgrade policy, the autonomous mobile device is determined to continue violating the target capability boundary, the downgrade policy is adjusted based on the current performance indicator data and / or surrounding environment data to obtain an updated downgrade policy. When adjusting the downgrade policy, the control system within the autonomous mobile device considers the latest performance indicator data and / or surrounding environment data to update the downgrade policy, thereby ensuring that the autonomous mobile device adapts to the current driving conditions. During this process, the control system only adjusts the limit value of the operation, not the operation type, thereby ensuring stable operation of the autonomous mobile device under abnormal conditions.
[0092] For example, if an autonomous mobile device is speeding, the original downgrade strategy is to limit the maximum speed to 120 kilometers per hour. If the autonomous mobile device continues to exceed the speed limit for a period of time after implementing the downgrade strategy, the control system within the autonomous mobile device will adjust the downgrade strategy based on the latest performance indicator data and surrounding environment data. For example, the control system within the autonomous mobile device will analyze factors such as current road conditions and weather conditions, and combine the autonomous mobile device's own status (such as the degree of deviation from the lane centerline) to determine whether to further limit the autonomous mobile device's speed. For example, based on real-time driving conditions, the control system within the autonomous mobile device may dynamically adjust the downgrade strategy, adjusting the maximum speed limit to a value that adapts to the current driving conditions, such as adjusting the speed to 80 kilometers per hour based on the level of road congestion, to ensure the autonomous mobile device's safe driving and avoid accidents.
[0093] S302: Control the autonomous mobile device to perform a downgrade operation according to the updated downgrade policy.
[0094] In this step, based on step S301, the degradation strategy is adjusted according to the current performance indicator data and / or surrounding environment data. After obtaining the updated degradation strategy, the autonomous mobile device is controlled to perform degradation operations according to the updated degradation strategy.
[0095] Specifically, when executing the updated degradation policy, the control system within the autonomous mobile device may implement the policy requirements by controlling the autonomous mobile device's power system, braking system, or steering system. For example, if the maximum driving speed is limited, the control system within the autonomous mobile device may adjust engine output power or braking force to ensure that the autonomous mobile device travels at the speed specified by the updated degradation policy.
[0096] For restricted steering and lane change scenarios, the autonomous mobile device's built-in control system adjusts the steering system to meet the new degradation policy. This can limit the maximum steering angle or steering speed to reduce the steering amplitude or speed to ensure the autonomous mobile device complies with the updated degradation policy requirements for steering and lane change.
[0097] Autonomous mobile devices continuously monitor and analyze the latest data, adjusting their degradation strategies in real time to respond to different situations and ensure driving safety. This real-time degradation strategy adjustment improves the intelligence and adaptability of autonomous mobile devices, enabling them to operate safely in a variety of situations.
[0098] FIG4 is a flow chart of the third embodiment of the method for processing capability boundaries based on autonomous driving provided by this application. As shown in FIG4 , based on any of the above embodiments, the process of the method for processing capability boundaries based on autonomous driving also includes:
[0099] S401: If it is determined that the autonomous mobile device continues to violate the target capability boundary within a second preset time period after executing the updated degradation policy, the autonomous mobile device is controlled to execute a minimum risk operation corresponding to the target capability boundary.
[0100] In this step, based on step S302, if the autonomous mobile device still continues to violate the target capability boundary within the second preset time period after executing the updated degradation policy, the autonomous mobile device is controlled to execute the minimum risk operation corresponding to the target capability boundary.
[0101] To avoid erroneous judgments that an autonomous mobile device continues to violate the target capability boundary after executing the updated downgrade policy, another specific time period is required. Specifically, during the second preset time period after executing the updated downgrade policy, only if the autonomous mobile device continues to violate the target capability boundary can it be accurately judged that the device requires the minimum risk action.
[0102] Optionally, to avoid potential dangers in a timely manner, when the autonomous mobile device executes the updated degradation strategy, the time it violates the target capability boundary should be shorter than the first preset time period, that is, the first preset time period is greater than the second preset time period.
[0103] Minimum risk operations refer to the safest possible actions to be taken after an autonomous mobile device continuously violates its target capability boundaries. Minimum risk operations include slowing down to a stop, manually adjusting the driving direction, and triggering the emergency braking system.
[0104] Optionally, when setting the minimum risk operation, you can specify a corresponding minimum risk operation for each target capability boundary, or you can specify a corresponding minimum risk operation for all target capability boundaries.
[0105] Specifically, if an autonomous mobile device continues to violate the target capability boundary and the control system within the autonomous mobile device fails to improve after implementing the updated degradation strategy, the autonomous mobile device will be controlled to perform the minimum risk operation corresponding to the target capability boundary. This measure aims to minimize potential safety issues and ensure the safety of the autonomous mobile device and its surrounding environment.
[0106] For example, the autonomous mobile device is a self-driving truck that experiences persistent navigation system failures on mountain roads, unable to accurately identify road conditions and the surrounding environment. If the problem persists after multiple attempts to update and adjust the built-in control system, the control system will initiate minimal risk actions, such as limiting the truck's speed to the minimum safe speed. By monitoring the truck's position, speed, and direction in real time, the control system adjusts the steering angle and steers the truck along the safest, pre-planned route, avoiding dangerous areas such as sharp turns and narrow passages to ensure the truck remains within a safe range.
[0107] For example, an autonomous mobile device, such as an autonomous aircraft, may experience persistent high-temperature alarms during a mission, and the built-in control system may be unable to stably control the aircraft's temperature. If no improvement is seen after implementing an updated degradation strategy, the built-in control system may direct the aircraft to perform the minimum-risk maneuver within its target capability, such as reducing altitude, adjusting speed, or searching for the nearest safe landing point.
[0108] If, after a certain period of time, the built-in control system detects that the autonomous mobile device continues to violate the target capability boundary, it will control the autonomous mobile device to perform the minimum risk action corresponding to the target capability boundary. By performing the minimum risk action, the built-in control system can quickly respond to persistent issues with the autonomous mobile device, ensuring the safety of the autonomous mobile device and its surrounding environment.
[0109] Optionally, based on any of the above embodiments, in a process of determining whether the autonomous mobile device violates at least one preset capability boundary based on the surrounding environment data and performance indicator data of the autonomous mobile device acquired in real time, the capability boundary includes at least one performance boundary and / or environmental safety boundary, wherein the performance boundary includes but is not limited to an inter-frame consistency threshold of the autonomous mobile device's position, an inter-frame consistency threshold of the autonomous mobile device's speed, a threshold of the degree of deviation between the planned trajectory and the road centerline, and a threshold of the longitudinal position control error of the autonomous mobile device;
[0110] Environmental safety boundaries include but are not limited to a rainfall threshold, a snow threshold, a temperature threshold, a light intensity threshold, and a curve curvature radius threshold.
[0111] Specifically, the inter-frame consistency threshold for the autonomous mobile device's position and velocity, included in the performance boundaries, refers to a preset standard used to ensure the consistency and logic of the autonomous mobile device's position and velocity changes during its driving process. That is, within a series of consecutive time frames, the autonomous mobile device's position and velocity changes must remain within a reasonable range to ensure the continuity and accuracy of its driving. The inter-frame consistency of the autonomous mobile device's position is generally defined by parameters such as the direction change rate and position change rate, namely the rate of change in the autonomous mobile device's driving direction and position coordinates between adjacent time points. Based on the direction change rate and position change rate, the autonomous mobile device can be ensured to remain stable during driving, thereby maintaining inter-frame position consistency. For example, if the inter-frame consistency threshold for the autonomous mobile device's position is set to 2 meters, then the distance change between the position coordinates of adjacent time points during driving should be controlled within 2 meters.
[0112] The inter-frame consistency of autonomous mobile devices is typically defined by parameters such as the velocity change rate and acceleration change rate, i.e., the rate of change of the autonomous mobile device's velocity and acceleration between adjacent time points. For example, if the inter-frame consistency threshold for the autonomous mobile device's velocity is set to 0.5 m / s, then the velocity change between adjacent time points should remain within 0.5 m / s during the autonomous mobile device's movement.
[0113] For example, a self-driving car continuously senses and calculates data about its surroundings to determine its position and make appropriate driving decisions. During this process, the inter-frame consistency thresholds for the vehicle's position and velocity ensure the accuracy of the vehicle's position and velocity. If these inter-frame consistency cannot be guaranteed, the vehicle may experience positional or velocity jumps between different time frames, leading to an unstable driving path and compromising driving safety.
[0114] The deviation threshold between the planned trajectory and the road centerline refers to the distance difference between the planned route and the road centerline for the autonomous mobile device. This performance boundary measures whether the autonomous mobile device can accurately follow the pre-defined trajectory during actual movement. By monitoring the deviation between the planned trajectory and the road centerline, deviations can be promptly detected during the autonomous mobile device's driving and appropriate corrective measures can be taken to ensure safe and stable operation of the autonomous mobile device.
[0115] The longitudinal position control error threshold for an autonomous mobile device refers to the threshold at which the error between the actual position of the autonomous mobile device and a predefined position must be less than the preset threshold when the autonomous mobile device is moving in the direction of travel. This performance boundary measures the control precision and accuracy of the longitudinal position of the autonomous mobile device. In the field of autonomous driving, this control error is categorized into two types: the longitudinal position control error for stable following conditions and the longitudinal position control error for unstable conditions with a small following distance. Following conditions are determined based on the relative speed and acceleration between the following vehicles. Generally, stable following is considered when the speed and acceleration of the following vehicle are similar to those of the preceding vehicle. However, unstable conditions may exist when the speed and acceleration of the following vehicle differ significantly from those of the preceding vehicle, and the following distance is small. For example, in stable following conditions, the longitudinal position control error is between 0.5 and 1 meters to ensure that the vehicle maintains an appropriate safety distance from the preceding vehicle. Alternatively, in unstable conditions with a small following distance, the longitudinal position control error is between 0.2 and 0.5 meters to avoid collisions.
[0116] The environmental safety boundary, including thresholds for rain, snow, temperature, light intensity, and curve radius, is pre-set to define the safe range of the driving environment. Specific thresholds are set for rain and snow. If the corresponding indicator exceeds these thresholds, it indicates that the amount of precipitation or snowfall has reached a certain level, potentially affecting the slipperiness of the road or the depth of snow, thus affecting the driving safety of the autonomous mobile device.
[0117] Temperature thresholds are pre-set to indicate the ambient temperature range. High or low temperatures can affect the operation and performance of autonomous mobile devices, so setting temperature thresholds helps provide early warning of potential problems.
[0118] Light intensity thresholds help determine ambient lighting conditions so that autonomous mobile devices can adapt to varying lighting conditions, ensuring the proper functioning of visual sensors and safe driving. For example, if the ambient light intensity remains below 50 lux for 20 consecutive seconds, the autonomous mobile device can adjust accordingly.
[0119] The threshold setting for the curve curvature radius is used to determine the curvature of the road. Different curvature radii may require different vehicle speeds or steering operations. Therefore, pre-setting the threshold helps autonomous mobile devices better adapt to road conditions during driving.
[0120] This embodiment primarily describes the capability boundary, which includes the performance boundary and the environmental safety boundary. This capability boundary covers the operational limitations and safety ranges for autonomous mobile devices, ensuring they can operate effectively and safely in various situations, thereby reducing the likelihood of accidents.
[0121] Optionally, based on any of the above embodiments, after the autonomous mobile device violates the target capability boundary, the autonomous mobile device is controlled to perform a downgrade operation according to the downgrade strategy corresponding to the target capability boundary. The downgrade strategy includes at least one of the following control schemes:
[0122] Degrade control by limiting speed; degrade control by inhibiting lane changes of autonomous mobile devices; degrade control by restricting lateral trajectory planning; and push safety prompts to enable users to control the degradation of autonomous mobile devices.
[0123] Specifically, speed limit control degradation refers to a degradation strategy that slows down the autonomous mobile device to ensure driving safety when the vehicle's current speed exceeds a pre-set performance limit. Methods for implementing speed limits include adjusting control parameters, limiting power output, using a deceleration device, and changing the gear ratio.
[0124] Lane change control degradation by inhibiting an autonomous mobile device means preventing the autonomous mobile device from changing lanes on the road. For example, when approaching an intersection, a curve, or a construction zone, the autonomous mobile device may need to inhibit lane changes to avoid danger.
[0125] Control degradation through restricted lateral trajectory planning refers to limiting or adjusting the planning of the lateral trajectory of the autonomous mobile device. This control can be used to avoid collisions, maintain the stability of the autonomous mobile device, etc. For example, when an autonomous vehicle needs to pass through a narrow road, the control system may implement restricted lateral trajectory planning control to ensure that the vehicle does not deviate from the road or collide with roadside obstacles. For example, when the vehicle deviates from the centerline of the road, the control system can adjust the steering angle or apply lateral force to bring the vehicle back to the correct driving trajectory.
[0126] Pushing safety reminders to enable users to control the autonomous mobile device to downgrade means that the control system informs the driver of the current system status and asks the driver to concentrate and control the autonomous mobile device. For example, when an obstacle or other autonomous mobile device in front is too close to the autonomous mobile device, the control system can remind the driver to maintain a safe distance or take evasive action through sound, vibration, or warning information on the display. In this embodiment, the specific content of the downgrade operation is mainly introduced in detail. After the autonomous mobile device violates the target capability boundary, the control system implements the downgrade operation based on at least one downgrade strategy corresponding to the target capability boundary, thereby enhancing the stability of the autonomous mobile device and effectively avoiding potential dangerous areas and complex traffic conditions.
[0127] Optionally, based on any of the above embodiments, if it is determined that the autonomous mobile device continues to violate the target capability boundary within a second preset time period after executing the updated degradation policy, the autonomous mobile device is controlled to perform a minimum risk operation corresponding to the target capability boundary, and the minimum risk operation includes at least one of the following operations:
[0128] Limit the acceleration of autonomous mobile devices; limit the change of movement direction; control the autonomous mobile devices to glide to a stop state; control the autonomous mobile devices to decelerate uniformly to a stop state; control the autonomous mobile devices to stop by the side of the road.
[0129] Specifically, limiting the acceleration of the autonomous mobile device means that when the autonomous mobile device continuously violates the target capability boundary, the control system limits the autonomous mobile device from performing acceleration operations based on actual conditions, thereby ensuring the driving safety of the autonomous mobile device.
[0130] Restricting direction changes means that if an autonomous mobile device violates its target capability boundaries, the control system prevents it from arbitrarily changing direction to ensure safe operation and avoid accidents. For example, if a drone needs to fly around a tall building during a mission, the flight control system will limit the range of the drone's direction changes to ensure it does not approach the building to minimize collision risk. Another example is when an autonomous vehicle is in heavy traffic or poor road conditions, the system can restrict lane changes to reduce collision risk.
[0131] Controlling an autonomous mobile device to coast to a stop means that when an autonomous mobile device continuously violates its target capability boundaries, the control system, based on the actual situation, restricts the autonomous mobile device from accelerating or performing other actions, ultimately causing it to coast to a stop. For example, an autonomous mobile vehicle might suddenly detect an obstacle ahead while driving, but for some reason, it continues to accelerate and cannot stop in time. In this case, the control system intervenes, restricting the vehicle's acceleration and gradually slowing it down to a complete stop to avoid collision with the obstacle, which could cause damage or safety issues.
[0132] Controlling an autonomous mobile device to a uniform deceleration state refers to the process by which a control system gradually slows the vehicle down to a complete stop at a relatively uniform rate over a specified period of time. For example, if a self-driving car detects a red light or an obstacle ahead and requires stopping, the control system will initiate a uniform deceleration process. The car will gradually slow down at a relatively uniform rate until it comes to a complete stop at the appropriate location. This method ensures a stable and smooth stopping process, preventing sudden braking that could cause the vehicle to lose control.
[0133] Pulling an autonomous mobile device to the side of a road or area while in motion means the control system directs the device to park safely and appropriately. This method is primarily used in road emergencies, while waiting for a stop, or in temporary parking situations to ensure driving safety.
[0134] It should be understood that the above minimum risk operations can be combined with each other, for example, limiting the acceleration of the autonomous mobile device while limiting the change of movement direction.
[0135] This embodiment mainly introduces the specific content of the minimum risk operation. When the autonomous mobile device continuously violates the target capability boundary, the minimum risk operation is executed to ensure driving safety and improve user experience.
[0136] FIG5 is a flow chart of a fourth embodiment of the method for processing capability boundaries based on autonomous driving provided by the present application. As shown in FIG5 , based on any of the above embodiments, before determining whether the autonomous mobile device violates at least one preset capability boundary based on the real-time acquired surrounding environment data and performance indicator data of the autonomous mobile device, the process of the method for processing capability boundaries based on autonomous driving further includes:
[0137] S501: In response to a user's expected functional safety configuration operation, obtaining at least one capability boundary of an autonomous mobile device during driving, a degradation strategy corresponding to each capability boundary, and a minimum risk operation, wherein the at least one capability boundary is determined based on a safety analysis method and an autonomous mobile device test experiment.
[0138] In this step, before determining whether the autonomous mobile device violates at least one preset capability boundary based on the surrounding environment data and performance indicator data of the autonomous mobile device obtained in real time, the control system built into the autonomous mobile device needs to respond in advance to the user's expected functional safety configuration operation, and obtain in real time at least one capability boundary of the autonomous mobile device during driving, as well as the degradation strategy and minimum risk operation corresponding to each capability boundary.
[0139] Specifically, at least one capability boundary is determined based on security analysis methods and autonomous mobile device testing experiments. Security analysis methods may include threat modeling and attack path analysis. These methods can identify the various threats and attack paths that autonomous mobile devices may face in different scenarios, thereby determining their capability boundaries. For example, a causal decision tree analysis method can be used to identify performance limitations and triggering conditions. Performance limitations and triggering conditions are prerequisites for determining capability boundaries. Specifically, performance limitations refer to functional limitations or deficiencies of autonomous mobile devices under specific conditions, while triggering conditions refer to specific circumstances that lead to performance limitations.
[0140] For example, an automated robot is used to transport goods outdoors. To determine the robot's load capacity, it is tested with objects of varying weights. After testing and verification, the maximum weight the robot can withstand is 10 kg, representing a performance limitation. If the weight exceeds 10 kg, some of the robot's components may deform, compromising its structural integrity and stability. Therefore, the robot's load capacity is limited to a maximum weight of 10 kg. Similarly, to determine the robot's temperature capacity, it is tested under different temperature conditions. After testing and verification, the robot's maximum temperature tolerance is 40 degrees Celsius. However, if the temperature exceeds 40 degrees Celsius, the robot's internal electronic components may overheat, leading to circuit failure. Therefore, the robot's temperature capacity is limited to a maximum temperature tolerance of 40 degrees Celsius. Figure 6 is a schematic diagram of identifying vehicle performance limitations and trigger conditions based on a causal decision tree, as provided in this application. As shown in Figure 6, the performance limitations identified in the causal decision tree include missed detection of a preceding vehicle 601 and inaccurate perception of the preceding vehicle's speed 602. The triggering conditions include bad weather 603 and the vehicle ahead stopped 604. The resulting hazard is lost braking 605.
[0141] In the case of bad weather 603, the vehicle ahead cannot be accurately perceived or detected. This may be because poor visibility, rain, snow, or other bad weather conditions affect the control system's perception of the road ahead, resulting in an inability to timely detect or identify the vehicle ahead, i.e., a missed detection of the vehicle ahead 601.
[0142] When the vehicle ahead stops 604, the control system may have difficulty accurately sensing the speed of the vehicle ahead. This is because the vehicle ahead is not moving and lacks a reference for speed changes, which may result in the control system being unable to accurately determine the speed of the vehicle ahead, resulting in inaccurate speed sensing 602.
[0143] Due to bad weather conditions 603 or a stopped vehicle 604 ahead, the control system may fail to take braking measures in time when necessary, ie, lose braking 605 , thereby causing potential safety issues.
[0144] The autonomous mobile device testing experiment is mainly based on actual driving scenarios. It collects experimental data related to the capability boundaries through predefined test scenarios, and conducts statistical analysis on the data of autonomous mobile devices under normal and abnormal conditions to determine their capability boundaries under normal and abnormal conditions.
[0145] After determining the capability boundaries, a corresponding degradation strategy needs to be developed for each capability boundary. A degradation strategy refers to the corresponding measures taken to reduce potential risks when an autonomous mobile device exceeds its capability boundaries. These measures may include limiting the functionality or performance of the autonomous mobile device, switching to a backup system, or initiating an emergency stop.
[0146] Furthermore, when determining a deescalation strategy, it's important to consider the least-risk action. This refers to the safest course of action after an autonomous mobile device exceeds its capabilities. This minimizes potential danger and loss. For example, when an autonomous vehicle exceeds its capabilities, the least-risk action might be to quickly return control to the driver or park in a safe location.
[0147] S502: Based on at least one capability boundary, a degradation strategy corresponding to each capability boundary, and a minimum risk operation, configure the autonomous mobile device to perform capability boundary detection and processing during the autonomous driving process.
[0148] In this step, based on step S501, in response to the user's expected functional safety configuration operation, at least one capability boundary of the autonomous mobile device during driving, as well as the degradation strategy and minimum risk operation corresponding to each capability boundary are obtained. Then, based on the at least one capability boundary, the degradation strategy and minimum risk operation corresponding to each capability boundary, the autonomous mobile device is configured to perform capability boundary detection and processing during the autonomous driving process.
[0149] Specifically, during autonomous driving, autonomous mobile devices can detect and process capability boundaries based on pre-configured code modules to ensure driving safety. When the control system built into the autonomous mobile device calculates performance data based on real-time ambient environmental data and performance indicators using code modules, if it detects that the data is approaching or reaching a capability boundary, the control system will immediately take appropriate measures, such as reducing the autonomous mobile device's speed, adjusting the driving route, changing the driving mode, or issuing a warning signal. The specific type of action taken will depend on the degradation strategy and minimum risk operation corresponding to the target capability boundary reached.
[0150] For example, an autonomous mobile device is a self-driving car. When the self-driving car detects sudden icy road conditions while driving, its control system identifies this as a capability boundary violation and handles it according to pre-defined degradation strategies and minimal risk actions. For example, the control system might immediately reduce speed, adjust the vehicle's handling to ensure better grip, or even trigger the emergency braking system to slow down and stop the vehicle as quickly as possible. These actions are all designed to respond to unexpected road conditions and ensure the vehicle's safe operation within its capability boundaries.
[0151] The capability boundary processing method based on autonomous driving provided in this embodiment can help autonomous mobile devices operate safely in various complex environments by timely identifying and processing various capability boundaries. This reflects the importance of expected functional safety configuration operations and ensures that autonomous mobile devices can respond correctly in various driving conditions.
[0152] FIG7 is a flow chart of a fifth embodiment of the method for processing capability boundaries based on autonomous driving provided by this application. As shown in FIG7 , based on any of the above embodiments, before obtaining at least one capability boundary of the autonomous mobile device during driving in response to the user's expected functional safety configuration operation, the process of the method for processing capability boundaries based on autonomous driving further includes:
[0153] S701: Based on each test scenario in a predefined test scenario set, perform simulation testing and / or actual testing on the autonomous mobile device, and record performance indicator data, surrounding environment data, and timestamps of when the user takes over control when lateral hazards and / or longitudinal hazards occur at each moment.
[0154] In this step, based on step S501, in response to the user's expected functional safety configuration operation, before obtaining at least one capability boundary of the autonomous mobile device during driving, it is necessary to perform simulation testing and / or actual testing on the autonomous mobile device based on each test scenario in a pre-defined test scenario set, and record the performance indicator data, surrounding environment data, and the timestamp of the user taking over control when lateral hazards and / or longitudinal hazards occur at each moment.
[0155] Specifically, the expected functional safety configuration operations of autonomous mobile devices require actual data support. Therefore, before performing the expected functional safety configuration operations on autonomous mobile devices, depending on different test scenarios, you can choose to perform either simulation testing or actual testing, or a combination of the two. Among them, the test scenario is a collection of test scenarios that trigger various capability boundaries. Before performing simulation testing and / or actual testing, the code for calculating performance indicators needs to be pre-deployed into the control system configured in the autonomous mobile device to ensure that the performance indicators can be calculated and counted in real time after the test begins.
[0156] The simulation test method is convenient and efficient, and it is easy to reproduce the more dangerous scenarios of actual testing, but the confidence of the simulation test results is lower than that of the actual test. The confidence of the actual test results is higher, but the test cost is high and the test efficiency is low. Therefore, this application associates the simulation test with the actual test, that is, first conduct a large number of tests based on the simulation test to converge to the "approximate performance boundary", and then verify the simulation test results based on the actual test, and clarify the final performance boundary.
[0157] In simulation testing, virtual reality technology is used to simulate various complex driving scenarios for autonomous mobile devices, such as highways, urban roads, and inclement weather, to determine their performance in virtual environments. Simultaneously, actual testing is conducted in real-world road traffic environments to obtain real-world data and performance metrics.
[0158] During testing, performance metrics, surrounding environment data, and the timestamps of user re-takeover when lateral and / or longitudinal hazards occur are recorded in real time to comprehensively assess the operational performance of the autonomous mobile device in various scenarios. Lateral hazards include veer-off-road, driving over the lane, and driving within the road. Longitudinal hazards include loss of braking, insufficient braking, and late braking. Through simulation and actual testing in various test scenarios, detailed data support is obtained, providing a reliable basis for the expected functional safety configuration and operation.
[0159] For example, imagine testing the performance of a self-driving car on city roads. First, test scenarios must be predefined, such as daytime driving, nighttime driving, driving in rainy weather, driving in sunny weather, and driving in heavy and light traffic conditions. Then, based on these predefined test scenarios, the self-driving car undergoes both simulation and real-world testing.
[0160] During simulation testing, computer simulation software is used to simulate various road and environmental conditions, allowing the autonomous vehicle to drive in a virtual environment to determine its performance in different situations. Simultaneously, the autonomous vehicle records performance indicators and surrounding environmental data at every moment while driving in the virtual environment.
[0161] In actual testing, autonomous vehicles are placed on real roads and driven in realistic traffic conditions. During driving, the vehicle's performance in various test scenarios is recorded in real time. The timestamp of when the user takes over control when a lateral or longitudinal hazard occurs is recorded to facilitate analysis and improvement of the system's safety performance.
[0162] Through these simulation tests and actual tests, the operation status of autonomous vehicles in various situations can be obtained, providing data support to ensure its safe operation and providing a basis for formulating expected functional safety configuration operations.
[0163] S702: Perform statistical analysis based on the performance indicator data at each moment, the surrounding environment data, and the timestamp of the user taking over control when the horizontal hazard and / or the vertical hazard occurs, to determine at least one capability boundary.
[0164] In this step, based on step S701, after simulation testing and actual testing are performed on the autonomous mobile device according to each test scenario in the pre-defined test scenario set, statistical analysis is performed on the performance indicator data, surrounding environment data at each moment, and the timestamp when the user takes over control when horizontal hazards and / or vertical hazards occur to determine at least one capability boundary.
[0165] Specifically, based on whether harmful behavior has occurred and whether a user has taken over, performance indicator statistics are divided into those calculated without harmful behavior and takeover, and those calculated with harmful behavior or takeover. Clearly unreasonable outlier values are removed. This removal of clearly unreasonable outlier values can be based on prior experience, pre-defining a reasonable range for the data, and removing abnormal data that falls outside this reasonable range.
[0166] Based on the calculated values of indicators without harmful behavior and under takeover, their mean and standard deviation are calculated, and based on the "2sigma principle" of Gaussian distribution, an initial capability boundary with a confidence level of 95.44% is obtained. Then, based on the calculated values of indicators with harmful behavior or takeover, the initial boundary is revised to obtain the capability boundary of autonomous mobile devices under triggering conditions.
[0167] Optionally, when determining the capability boundary, data visualization and analysis tools can be used to visualize performance indicator data, surrounding environment data, and timestamp data of user control takeovers at each moment of lateral and / or longitudinal compromise to observe data distribution and anomalies. For handling abnormal data, appropriate methods are selected based on its type. For example, abnormal data caused by obvious errors or abnormal conditions can be deleted. For minor or repairable abnormal data, interpolation or repair techniques can be used to replace the outliers. Abnormal data that cannot be repaired or requires special processing can be marked as an outlier. The preprocessed data is then input into a deep neural network model to preliminarily determine the capability boundary of the autonomous mobile device. The determined capability boundary is then used for validation testing to examine the performance of the autonomous mobile device under capability boundary scenarios. Based on the validation results, the model is optimized, and the definition of the capability boundary is continuously refined and adjusted to determine the capability boundary of the autonomous mobile device.
[0168] The capability boundary processing method based on autonomous driving provided in this embodiment mainly explains how to confirm and quantify the capability boundary of autonomous mobile devices under triggering conditions. Specifically, by performing simulation tests and actual tests on each predefined test scenario, at least one capability boundary can be determined. This method can identify potential safety risks and control system limitations in advance, and provide an important basis for formulating corresponding safety strategies and improvement measures. At the same time, the combination of safety analysis and test verification can sort out the performance limitations and performance boundaries in detail, avoiding the incomplete performance limitation analysis based solely on expert experience, so as to better plan and manage the operating range of autonomous mobile devices and ensure their safe and reliable operation in actual applications.
[0169] In one possible implementation, FIG8 is a schematic diagram of the overall process of a method for processing capability boundaries based on autonomous driving provided by this application. As shown in FIG8 , the overall process of the method for processing capability boundaries based on autonomous driving is as follows:
[0170] S801: Start;
[0171] S802: Degradation and minimal risk operation for predefined performance limitations;
[0172] Specifically, performance-limited degradation and minimal risk actions are predefined based on the risk rebalancing principle. This principle refers to the practice of reassessing and adjusting policies when autonomous mobile devices face risks to minimize negative impacts and ensure continued normal operation. This principle emphasizes flexible response to risk situations and timely measures to rebalance risks to minimize potential negative impacts.
[0173] When applying the risk rebalancing principle, the control system will evaluate the degree of violation of performance boundaries and trigger conditions. The greater the violation, the higher the risk. At the same time, it will also estimate the severity of the accident and the driver's controllability (estimated time to leave the lane, immediate collision time). The greater the severity of the collision, the higher the risk. The shorter the driver's controllability time, the less controllable the driver is, and the risk increases accordingly. Based on the risk level, the control system will implement corresponding degradation strategies and minimum risk operations. For example, the control system may adjust the performance boundaries of certain functions or enhance safety measures to ensure system stability and user safety. When faced with high risks, the control system will choose the minimum risk operation to minimize potential losses and ensure that the system can still operate effectively in extreme situations.
[0174] For example, during normal driving, autonomous mobile device A encounters autonomous mobile device B, which is making an emergency lane change. The control system of autonomous mobile device A must balance avoiding a collision with autonomous mobile device B with ensuring user safety. Based on the risk rebalancing principle, the control system will comprehensively consider accident severity and driver controllability. Specifically, in terms of accident severity, if a collision with autonomous mobile device B could result in a serious accident, including casualties or equipment damage, the control system will consider it a high-risk event. Regarding driver controllability, the control system will determine whether autonomous mobile device A has sufficient time and resources to avoid a collision with autonomous mobile device B. Taking these factors into consideration, the control system may instruct autonomous mobile device A to immediately take emergency evasive measures to reduce the likelihood of an accident.
[0175] S803: Performance boundary or trigger condition violation;
[0176] Specifically, during driving, the autonomous mobile device online checks whether predefined autonomous driving system performance indicators and trigger conditions are violated. If not, step S809 is executed; if violated, step S804 is executed.
[0177] S804: Implementing offline predefined performance-limited degradation or minimum risk operations;
[0178] S805: The performance boundary or trigger condition is continuously violated and the system is implementing a degradation operation;
[0179] Specifically, during the process of implementing the degradation operation, the system continuously detects whether the corresponding performance boundary or trigger condition is continuously violated. If it is continuously violated, step S806 is executed; if not, step S809 is executed.
[0180] S806: Online adjustment of downgrade strategy;
[0181] S807: Performance boundary or trigger condition is continuously violated;
[0182] Specifically, after executing the online adjustment strategy, it is necessary to continue to detect whether the performance boundary or trigger condition is continuously violated. If so, step S808 is executed; if not, step S809 is executed.
[0183] S808: Implement minimal risk operations;
[0184] S809: End.
[0185] By taking specific measures to adjust the degradation strategy online based on performance indicators, we can achieve a rebalance between risks and capabilities as much as possible while ensuring safety, thereby improving the availability of autonomous driving and truly enabling the autonomous driving system to achieve the effect of "safe use within performance boundaries", "cautious use near performance boundaries", and "unusable outside performance boundaries".
[0186] FIG9 is a schematic diagram of a first embodiment of a device for processing capability boundaries based on autonomous driving provided by the present application. As shown in FIG9 , the device 900 for processing capability boundaries based on autonomous driving includes:
[0187] A first processing module 901 is configured to determine whether the autonomous mobile device violates at least one preset capability boundary based on real-time acquired ambient environment data and performance indicator data of the autonomous mobile device, where the at least one capability boundary includes at least one performance boundary and / or environmental safety boundary for safe driving of the autonomous mobile device;
[0188] The second processing module 902 is configured to control the autonomous mobile device to perform a downgrade operation according to a downgrade policy corresponding to the target capability boundary if the autonomous mobile device violates the target capability boundary.
[0189] Optionally, the second processing module 902 is further configured to:
[0190] If, within a first preset time period after executing the downgrade operation corresponding to the downgrade policy, it is determined that the autonomous mobile device continues to violate the target capability boundary, adjusting the downgrade policy based on current performance indicator data and / or surrounding environment data to obtain an updated downgrade policy;
[0191] The autonomous mobile device is controlled to perform a downgrade operation according to the updated downgrade policy.
[0192] Optionally, the second processing module 902 is further configured to:
[0193] If it is determined that the autonomous mobile device continues to violate the target capability boundary within a second preset time period after executing the updated degradation policy, the autonomous mobile device is controlled to execute a minimum risk operation corresponding to the target capability boundary.
[0194] Optionally, capability boundaries include:
[0195] At least one performance boundary and / or environmental safety boundary, wherein the performance boundary includes an inter-frame consistency threshold of the autonomous mobile device position, an inter-frame consistency threshold of the autonomous mobile device speed, a threshold of the degree of deviation of the planned trajectory from the road centerline, and a threshold of the longitudinal position control error of the autonomous mobile device;
[0196] Environmental safety boundaries include rain threshold, snow threshold, temperature threshold, light intensity threshold, and curve radius threshold.
[0197] Optionally, the degradation strategy includes at least one of the following control schemes:
[0198] Degradation through speed limit control;
[0199] Degradation of lane change control by inhibiting autonomous mobile equipment;
[0200] Control degradation by limiting lateral trajectory planning;
[0201] Push security prompts to allow users to control autonomous mobile device downgrades.
[0202] Optionally, the minimum risk operation includes at least one of the following:
[0203] Limiting autonomous mobile device acceleration;
[0204] Limit the change of movement direction;
[0205] Control the autonomous mobile device to glide to a stop;
[0206] Control the autonomous mobile device to decelerate uniformly until it stops;
[0207] Controls the autonomous mobile device to stop by the side of the road.
[0208] The capability boundary processing device based on autonomous driving provided in this embodiment can be used to execute the capability boundary processing method based on autonomous driving in any of the aforementioned method embodiments. Its implementation principles and technical effects are similar and will not be repeated here.
[0209] FIG10 is a schematic diagram of a second embodiment of a device for processing capability boundaries based on autonomous driving provided by this application. As shown in the figure, the device 900 for processing capability boundaries based on autonomous driving further includes:
[0210] An acquisition module 903 is configured to obtain, in response to a user's expected functional safety configuration operation, at least one capability boundary of the autonomous mobile device during driving, a degradation strategy corresponding to each capability boundary, and a minimum risk operation, wherein the at least one capability boundary is determined based on a safety analysis method and an autonomous mobile device test experiment.
[0211] The configuration module 904 is used to configure the autonomous mobile device to perform capability boundary detection and processing during the autonomous driving process based on at least one capability boundary, a degradation strategy corresponding to each capability boundary, and a minimum risk operation.
[0212] The third processing module 905 is configured to perform a simulation test and / or an actual test on the autonomous mobile device based on each test scenario in the predefined test scenario set, and record the performance indicator data, surrounding environment data, and the timestamp of the user taking over control when the lateral hazard and / or the longitudinal hazard occurs at each moment;
[0213] At least one capability boundary is determined by performing statistical analysis based on performance indicator data at each moment, surrounding environment data, and timestamps of when the user takes over control when horizontal hazards and / or vertical hazards occur.
[0214] The capability boundary processing device based on autonomous driving provided in this embodiment can be used to execute the capability boundary processing method based on autonomous driving in any of the aforementioned method embodiments. Its implementation principles and technical effects are similar and will not be repeated here.
[0215] FIG11 is a schematic diagram of the structure of an autonomous mobile device for processing capability boundaries based on autonomous driving provided by this application. As shown in FIG11 , the autonomous mobile device may specifically include a receiver 1100, a transmitter 1101, a processor 1102, and a memory 1103. The receiver 1100 and transmitter 1101 are used to implement data transmission between the autonomous mobile device and the control system, the memory 1103 stores computer-executable instructions, and the processor 1102 executes the computer-executable instructions stored in the memory 1103 to implement the capability boundary processing method based on autonomous driving in the above embodiment.
[0216] This embodiment provides a computer-readable storage medium, which stores computer-executable instructions. When the computer-executable instructions are executed by a processor, they are used to implement the capability boundary processing method based on autonomous driving in the above embodiment.
[0217] This embodiment also provides a computer program product, including a computer program, which, when executed by a processor, implements the capability boundary processing method based on autonomous driving provided by any of the above embodiments.
[0218] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some or all of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the scope of the technical solutions of the embodiments of the present application.
Claims
1. A method for processing capability boundaries based on autonomous driving, characterized in that: Applied to an autonomous mobile device, the method comprises: determining, based on real-time acquired ambient environment data and performance indicator data of the autonomous mobile device, whether the autonomous mobile device violates at least one preset capability boundary, the at least one capability boundary comprising at least one performance boundary and / or environmental safety boundary for safe driving of the autonomous mobile device; If the autonomous mobile device violates the target capability boundary, the autonomous mobile device is controlled to perform a downgrade operation according to a downgrade policy corresponding to the target capability boundary.
2. The method according to claim 1, characterized in that The method further comprises: If, within a first preset time period after executing the downgrade operation corresponding to the downgrade strategy, it is determined that the autonomous mobile device continues to violate the target capability boundary, adjusting the downgrade strategy based on current performance indicator data and / or surrounding environment data to obtain an updated downgrade strategy; The autonomous mobile device is controlled to perform a downgrade operation according to the updated downgrade policy.
3. The method according to claim 2, characterized in that The method further comprises: If it is determined that the autonomous mobile device continues to violate the target capability boundary within a second preset time period after executing the updated degradation policy, the autonomous mobile device is controlled to execute a minimum risk operation corresponding to the target capability boundary.
4. The method according to any one of claims 1 to 3, characterized in that The capability boundaries include: At least one performance boundary and / or environmental safety boundary, wherein The performance boundaries include an inter-frame consistency threshold of the autonomous mobile device position, an inter-frame consistency threshold of the autonomous mobile device speed, a threshold of the degree of deviation between the planned trajectory and the road centerline, and a threshold of the longitudinal position control error of the autonomous mobile device; The environmental safety boundary includes a rainfall threshold, a snow threshold, a temperature threshold, a light intensity threshold, and a curve curvature radius threshold.
5. The method according to any one of claims 1 to 3, characterized in that The degradation strategy includes at least one of the following control schemes: Degradation through speed limit control; Degradation of lane change control by inhibiting autonomous mobile equipment; Control degradation by limiting lateral trajectory planning; Push security prompts to allow users to control autonomous mobile device downgrades.
6. The method according to claim 3, characterized in that The minimum risk operation includes at least one of the following operations: Limiting autonomous mobile device acceleration; Limit the change of movement direction; Control the autonomous mobile device to glide to a stop; Control the autonomous mobile device to decelerate uniformly until it stops; Controls the autonomous mobile device to pull over and stop.
7. The method according to any one of claims 1 to 3, characterized in that Before determining whether the autonomous mobile device violates at least one preset capability boundary based on the ambient environment data and performance indicator data of the autonomous mobile device acquired in real time, the method further includes: In response to an expected functional safety configuration operation by a user, obtaining at least one capability boundary of the autonomous mobile device during driving, a degradation strategy corresponding to each capability boundary, and a minimum risk operation, wherein the at least one capability boundary is determined based on a safety analysis method and an autonomous mobile device test experiment; The autonomous mobile device is configured to perform capability boundary detection and processing during the autonomous driving process based on the at least one capability boundary, the degradation strategy corresponding to each capability boundary, and the minimum risk operation.
8. The method according to claim 7, characterized in that Before obtaining at least one capability boundary of the autonomous mobile device during driving in response to the user's expected functional safety configuration operation, the method further includes: Based on each test scenario in a predefined test scenario set, performing a simulation test and / or an actual test on the autonomous mobile device, recording performance indicator data, surrounding environment data, and a timestamp of a user taking over control when a lateral hazard and / or a longitudinal hazard occurs at each moment; The at least one capability boundary is determined by performing statistical analysis based on the performance indicator data at each moment, the surrounding environment data, and the timestamp of the user taking over control when the horizontal hazard and / or the vertical hazard occurs.
9. A capability boundary processing device based on autonomous driving, characterized in that: Applied to an autonomous mobile device, the device comprises: a first processing module, configured to determine, based on real-time acquired ambient environment data and performance indicator data of the autonomous mobile device, whether the autonomous mobile device violates at least one preset capability boundary, the at least one capability boundary comprising at least one performance boundary and / or environmental safety boundary for safe driving of the autonomous mobile device; The second processing module is configured to control the autonomous mobile device to perform a downgrade operation according to a downgrade policy corresponding to the target capability boundary if the autonomous mobile device violates the target capability boundary.
10. The device according to claim 9, characterized in that The device further comprises: an acquisition module, configured to acquire, in response to a user's expected functional safety configuration operation, at least one capability boundary of the autonomous mobile device during driving, a degradation strategy corresponding to each capability boundary, and a minimum risk operation, wherein the at least one capability boundary is determined based on a safety analysis method and an autonomous mobile device test experiment; a configuration module for configuring the autonomous mobile device to perform capability boundary detection and processing during autonomous driving based on at least one capability boundary, a degradation strategy corresponding to each capability boundary, and a minimum risk operation; a third processing module, configured to perform a simulation test and / or an actual test on the autonomous mobile device based on each test scenario in a predefined test scenario set, and record performance indicator data, surrounding environment data, and a timestamp of a user taking over control when a lateral hazard and / or a longitudinal hazard occurs at each moment; At least one capability boundary is determined by performing statistical analysis based on performance indicator data at each moment, surrounding environment data, and timestamps of when the user takes over control when horizontal hazards and / or vertical hazards occur.
11. An autonomous mobile device, characterized in that include: a processor, and a memory communicatively connected to the processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory to implement the capability boundary processing method based on autonomous driving as described in any one of claims 1 to 8.
12. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the capability boundary processing method based on autonomous driving as described in any one of claims 1 to 8.
13. A computer program product, characterized in that It includes a computer program, which, when executed by a processor, implements the capability boundary processing method based on autonomous driving as described in any one of claims 1 to 8.
Citation Information
Patent Citations
Method and system for ensuring operation of limited-ability autonomous driving vehicles
CN102233877A
Risk assessment method and device, electronic equipment and storage medium
CN114529131A
Intelligent vehicle driving ability boundary defining method and related equipment
CN116560988A
Limit driving function-oriented dynamic safety filtering control method and domain control architecture
CN116834775A
Capability boundary processing method and device based on automatic driving and medium
CN117962931A
Cited By
Auxiliary driving control method and device based on visual distance detection
CN121084432A
Assisted driving control method and device based on visual distance detection
CN121084432B