Computer-implemented method for checking at least one fault class

A computer-implemented method for error classification and management in autonomous vehicles addresses the challenge of reliable obstacle detection by defining error classes and deriving measures, enhancing system safety and reliability.

WO2025228615A1PCT designated stage Publication Date: 2025-11-06SIEMENS MOBILITY GMBH
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2025/059207
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-05-02
Filing Date
2025-04-04
Publication Date
2025-11-06

AI Technical Summary

Technical Problem

Existing systems for autonomous vehicles, particularly autonomous trains, face challenges in reliably detecting obstacles and initiating appropriate countermeasures due to the complexity and increasing automation, necessitating a more efficient and reliable method for checking error classes to ensure safety and reliability.

Method used

A computer-implemented method for checking error classes by defining error criteria, assigning errors to specific classes, and deriving measures to address these errors, utilizing flexible sensor units and data processing to ensure efficient and reliable error classification and management.

Benefits of technology

The method enhances the reliability and safety of autonomous systems by effectively classifying and managing errors, reducing their frequency and improving the overall system's safety and performance through targeted measures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025059207_06112025_PF_FP_ABST
    Figure EP2025059207_06112025_PF_FP_ABST
Patent Text Reader

Abstract

The invention relates to a computer-implemented method for checking at least one fault class, comprising the steps of: a. providing at least one fault class having at least one fault in relation to at least one object or at least one feature of the at least one object (S1), the at least one object or the at least one feature of the at least one object being sensed by at least one sensing unit of a technical system, and the at least one fault being assigned to a corresponding fault class of the at least one fault class on the basis of at least one fault criterion; b. providing at least one predefined criterion (S2); c. deriving at least one measure for each fault class of the at least one fault class by comparing the at least one fault criterion of the at least one fault class with the at least one predefined criterion with regard to a deviation (S3); and d. providing the at least one derived measure (S4). In addition, the invention relates to a technical system and to a corresponding computer program product.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Description

[0002] Computer-implemented method for checking for at least one class of errors

[0003] 1. Technical field

[0004] The invention relates to a computer-implemented method for checking at least one class of defects. Furthermore, the invention relates to a corresponding technical system and a computer program product.

[0005] 2. State of the art

[0006] Autonomous driving is becoming increasingly important. Various autonomous vehicles, such as cars and trains, are already known in this context. The degree of automation and the complexity of autonomous vehicles are also increasing significantly. These autonomous vehicles are designed to operate without a driver; they are therefore self-driving.

[0007] As autonomous trains and their control systems are further developed, train control is being gradually transferred from the train driver to a technical system with automated control (also called train control). Obstacles on the track still pose serious risks to rail traffic. Train drivers sometimes have to react very quickly to prevent major damage to the train and passengers. Obstacles can include parts of track infrastructure damaged by severe weather, such as overhead lines or masts, but also fallen trees or people. Reliable automated obstacle detection and the initiation of appropriate countermeasures, such as emergency braking, remain a significant challenge.

[0008] Therefore, there is a need to design such systems to be sufficiently safe and reliable, and to evaluate the safety and quality of such safety-relevant technical systems. For this reason, system evaluation aims to uncover errors or deficiencies in a system architecture with regard to system safety, or to design the system according to these error classes, depending on the environment and the sensors used. Typically, such safety evaluations or analyses of systems or system architectures are carried out using a bottom-up safety analysis, such as a Failure Mode and Effects Analysis (FMEA), or a top-down safety analysis, such as a Fault Tree Analysis (FTA).

[0009] To this day, it remains a challenge to provide evidence that the safety-relevant applications of technical systems are also sufficiently reliable.

[0010] The present invention therefore aims to provide a computer-implemented method for checking at least one class of defects, which is more efficient and reliable.

[0011] 3. Summary of the invention

[0012] The above-mentioned problem is solved according to the invention by a computer-implemented method for checking at least one defect class, comprising the steps of: a. providing at least one defect class with at least one defect relating to at least one object or at least one feature of the at least one object; wherein the at least one object or the at least one feature of the at least one object is detected by at least one detection unit of a technical system; wherein the at least one defect is assigned to a corresponding defect class of the at least one defect class based on at least one defect criterion; b. providing at least one predetermined criterion; c.The invention relates to a computer-implemented method for checking at least one error class by comparing the at least one error criterion of the at least one error class with the at least one predetermined criterion with regard to a deviation; and to providing the at least one derived measure. Accordingly, the invention relates to a computer-implemented method for checking at least one error class. In other words, the method checks at least one error class.

[0013] In the first step of the process, one or more error classes are defined. The errors that occur are then assigned to the corresponding error class based on the error criterion. Accordingly, an error class comprises all errors that meet this criterion. In other words, the errors are sorted into error classes. The errors are thus assigned to specific error classes according to a given criterion. For example, errors can be sorted based on the distribution of their durations, their frequencies, their locations, or specific patterns of occurrence. If errors cannot be assigned to any error class, it may be necessary to define additional error classes into which the errors can then be categorized.

[0014] The fault is associated with the object. The fault can relate to the entire object or only to a part of it, such as individual features or properties. The object can be any type of object, such as a physical object or a technical component. In other words, the fault criterion, and therefore the fault classes, can relate to the behavior of the overall system or a subsystem, as well as to specific observed scenarios, specific objects, or their features or properties.

[0015] The object is preferably a physical object that is detected by the detection unit of the technical system. The detection unit is preferably a sensor unit. The sensor unit can consist of a sensor for observing an object and its properties, or of a combination of sensors. This could be, for example, a camera unit, a lidar or radar sensor, or a combination thereof. The sensor unit can therefore be selected flexibly, for example, depending on the task to be performed by the technical system. A specific sensor system with its associated evaluation unit can generate characteristic errors in a particular environment, resulting from the limitations of the sensor system or its sensor data evaluation for the chosen operating environment. The detection process can be supplemented with tracking.

[0016] The technical system can be designed as a perception system as part of an autonomous means of transport, such as an autonomous rail- or road-bound autonomous vehicle. Other examples of technical systems include industrial plants. The technical system typically comprises multiple technical components, such as hardware components and / or software components.

[0017] In a further procedural step, the predetermined criterion is provided.

[0018] Input data, such as the error class, can be received via one or more input interfaces. Additionally or alternatively, output data, such as the derived action, can also be sent via one or more output interfaces. This ensures efficient data transfer between computing units.

[0019] In a further procedural step, at least one measure is derived for each error class. This measure can also be referred to as an action. The derived measure can therefore also be interpreted as an action to be carried out. For this purpose, the at least one error criterion of the at least one error class is compared with the at least one predetermined criterion. This comparison determines whether the criteria match and / or whether a deviation exists. Furthermore, it can also be determined whether the deviation is still tolerable or not.

[0020] First, the measures can be derived. Then, the measures can be assigned to the error classes.

[0021] In the final step of the process, the derived measure is provided. For example, the error classes with their derived and assigned measures can be provided.

[0022] The present invention therefore ensures that the error classes are checked reliably and efficiently. The error classes are provided with corresponding measures.

[0023] The advantage lies in the fact that each error class can be addressed by means of the assigned measure after the measures have been derived. Furthermore, the effectiveness of the measures can be verified by comparing characteristic error classes before and after their implementation. Statistical methods and metrics, and possibly predefined thresholds, can be used for this purpose. The same approach can also be used to avoid implementing ineffective measures. Overall, the reliability and safety of the technical system can be significantly improved. The relevance of the error classes, or rather the frequency of their occurrence, can be considerably reduced by the measures.

[0024] In one embodiment, at least one error criterion is an error duration, an error location or an error frequency and / or at least one predetermined criterion is a predetermined duration, a predetermined location or a predetermined frequency.

[0025] Accordingly, various criteria can be considered. The advantage lies in the fact that the criteria can be selected flexibly, for example, depending on the technical system, the error classes, the errors themselves, and / or other criteria such as user preferences. The patterns of occurrence and distribution (temporal, spatial, etc.) can also be taken into account.

[0026] In one implementation, at least one error class covers the entire error spectrum. Accordingly, the error classification is implemented in such a way that the classes also cover the entire error spectrum.

[0027] In one embodiment, the at least one error is an error selected from the group consisting of: the at least one object or the at least one characteristic is not recorded, and the at least one object or the at least one characteristic is recorded incorrectly.

[0028] Accordingly, an error can occur if the object or characteristic is not recorded. An error can also occur if the object or characteristic is recorded, but not sufficiently or incorrectly.

[0029] In this latter case – faulty detection – the object or feature is, for example, incompletely detected. The object or feature may be partially obscured, and the detection unit therefore only captures a portion of the object, or the feature may be only partially determined. Alternatively, the sensors of the detection unit or the detection unit itself may be defective and / or capture data incorrectly. Furthermore, non-existent objects, so-called ghost objects, may be detected by mistake. The objects detected by the sensors can be merged into an environmental model, a digital representation (digital twin) of the environment, and tracked over time and updated with new measurements. The environmental model thus represents a digital twin of the real environment.In other words, the environment model may be incomplete, faulty, and / or uncertain, for example, due to the following reasons: the real objects in the environment are not recognized, incorrect object hypotheses are recognized and entered into the environment model (ghost objects), the object attributes (e.g., object widths) are incompletely recorded (e.g., due to occlusion of the observed object), the object attributes (e.g., object position or object width) have a measurement uncertainty, and the object classes are incorrectly determined.

[0030] In one embodiment, the at least one error depends on at least one condition, wherein the at least one condition is a condition selected from the group consisting of: a type of the at least one detection unit, a setup or configuration of the at least one detection unit, a characteristic of the at least one detection unit, a distance between the technical system and the at least one object, an operating environment of the at least one detection unit, and a location or substrate of the at least one detection unit.

[0031] Accordingly, an error can depend on a condition. Preferably, this condition is an environmental or weather condition. This also applies, additionally or alternatively, to the error criterion, which, for example, assigns errors to different error classes based on the distribution of their durations, frequencies, locations, or specific patterns of occurrence. The detection unit, or parts thereof, may be positioned in a location or on a surface that is not optimal for object detection and consequently makes detection more difficult.

[0032] In other words, the occurrence of errors can depend on the specific sensor setup, the operating environment, and / or the measurement location. For example, obstruction situations typically occur at the edge of the path (e.g., due to parked cars), measurement errors often depend on the distance of the observed object, and the number of ghost objects depends on the surface (asphalt road vs. open track).

[0033] In a given configuration, a deviation exists if at least one error criterion exceeds or falls short of at least one predetermined criterion.

[0034] Accordingly, the criteria are compared with regard to deviations. The criteria can either match or differ. A deviation occurs when the criteria are exceeded or not met. For example, errors may occur more frequently than expected, and the error frequency thus exceeds the predetermined frequency.

[0035] Short-term errors occur, for example, when the error duration is less than the observation time, or significantly shorter than the observation time. These are typically random errors. Transient errors can occur, for example, when the error duration is approximately the same as the observation time. Longer-term errors occur, for example, when the error duration significantly exceeds the observation time, or when the error duration is greater than the observation time (duration significantly longer than the evaluation period, e.g., hardware failure).

[0036] In one embodiment, the computer-implemented method further exhibits

[0037] - Outputting at least one derived measure, at least one error class and / or associated data on a display unit or a computing unit,

[0038] - Storing at least one derived measure, at least one error class and / or associated data in a storage unit,

[0039] - Transmitting at least one derived measure, at least one error class and / or associated data to a computing unit,

[0040] - Analyzing at least one derived measure, at least one error class and / or associated data,

[0041] - Evaluating at least one derived measure, at least one error class and / or associated data; wherein the analysis and / or evaluation preferably includes a hazard assessment with regard to persons and / or the technical system, and / or

[0042] - Initiating or carrying out at least one derived measure, preferably after analysis and / or evaluation.

[0043] Accordingly, one or more process steps can be initiated after the derived measure has been provided as an output of the process according to the invention. The process steps can be carried out simultaneously, sequentially, or in stages.

[0044] First, the derived action can be displayed to the user on a display unit of a computing unit. For example, the user is shown the error classes with their assigned actions. Furthermore, the derived action can be stored in a storage unit. This storage unit can be volatile or non-volatile, preferably a database or cloud storage. The storage unit enables reliable and fast data backup. Finally, the action itself, or in the form of a corresponding message or notification, can be transmitted to another unit, such as an end device, a control unit, or another computing unit.

[0045] Furthermore, the derived measure can be analyzed or evaluated with regard to its effectiveness, preferably with regard to potential hazards to people and / or the availability of the technical system. This subjects the fault class to a further additional review, preferably before the assigned measures are initiated and implemented. This additional review increases the reliability of the measures and thus also the safety of people and the technical system.

[0046] In one configuration, the measure is a measure selected from the group consisting of:

[0047] - Treating at least one error class,

[0048] - Tolerating at least one error class,

[0049] - Performing a reaction depending on at least one error class, and - Adapting the technical system, at least one technical component of the technical system and / or a function of the technical system.

[0050] Accordingly, measures can aim to address the error classes and thus the errors themselves, for example, by rectifying them or reducing their relevance to a tolerable level. Measures may be omitted if the error is tolerated. Alternatively or additionally, a measure can be taken in response to the error class and the error itself. For example, it may be recognized that certain error classes occur too frequently, and the driver of the autonomous train or an operator in the control room may be contacted. Alternatively or additionally, the technical system or its operation may be adjusted. This adjustment may involve removing or replacing system components (e.g., individual sensors) or the entire detection unit. Furthermore, maintenance or a maintenance measure may be initiated. Finally, the control or control function of the technical system may be adapted.For example, it is recognized that certain error classes occur too frequently and operation is then continued with predefined restrictions, such as reduced speed.

[0051] Furthermore, the invention relates to a technical system for carrying out the above method.

[0052] The invention further relates to a computer program product comprising a computer program which includes means for carrying out the method described above when the computer program is executed on a program-controlled device.

[0053] A computer program product, such as a computer program tool, can be provided or delivered from a server on a network, for example, as a storage medium such as a memory card, USB stick, CD-ROM, DVD, or as a downloadable file. This can be done, for example, in a wireless communication network by transmitting the corresponding file containing the computer program product or tool. A suitable program-controlled device is, in particular, a control unit such as an industrial control PC, a programmable logic controller (PLC), or a microprocessor for a smart card or similar device.

[0054] 4. Brief description of the drawings In the following detailed description, preferred embodiments of the invention are further described with reference to the following figures.

[0055] FIG 1 shows a schematic flowchart of the method according to the invention.

[0056] 5. Description of preferred embodiments

[0057] Preferred embodiments of the present invention are described below with reference to Figure 1.

[0058] Figure 1 schematically represents a flowchart of the process according to the invention with process steps S1 to S4.

[0059] In the first process step, at least one error class is provided with at least one error relating to at least one object or at least one characteristic of the at least one object (S1). The at least one object or at least one characteristic of the at least one object is detected by at least one detection unit of the technical system. The at least one error is assigned to a corresponding error class of at least one error class based on at least one error criterion. In a further process step, at least one predetermined criterion is provided (S2). In a further process step, at least one measure for each error class of at least one error class is derived by comparing the at least one error criterion of the at least one error class with the at least one predetermined criterion with regard to a deviation (S3).In the final procedural step, at least one derived measure S4 is provided.

[0060] Safety-related verification

[0061] The safety-related verification can initially be carried out separately for each failure class. According to one embodiment of the invention, the frequency of occurrence of a failure class and / or, derived from this, the unavailability of the technical system or the frequency of a potentially safety-critical event can be supported or verified using research results, tests, field observations, and / or data tables (e.g., in the case of classic hardware failures). Systematic failures triggered by statistical processes can be included in the modeling as statistical phenomena. When defining the failure classes, it is possible to prioritize them. If failure classes occur simultaneously or together, measures for the dominant failure classes can be prioritized.For example, transient errors can be prioritized over random errors, since random errors can be filtered out during the subsequent processing.

[0062] According to one embodiment of the invention, the results can be combined in a common model, such as the RAMS (Reliability, Availability, Maintainability and Safety) model (fault tree, Markov chain).

[0063] The method according to the invention therefore significantly improves the proof of safety.

[0064] The system architecture (for example, regarding the selection or monitoring of the sensors) as well as the data processing process (e.g., fusion process using a caiman filter) can be adapted.

[0065] To correct or reduce the consequences of errors, the time thresholds for confirming or rejecting objects in object management can be adjusted according to the error classes, such as specific sensor paths or sensor modalities or sensor installations (mounting locations with different fields of view), and / or specific detection locations or detected object classes.

[0066] Data processing processes, such as a fusion process based on a caiman filter, can be optimized with respect to error classes. According to one embodiment of the invention, the analysis of the frequency of transient errors can be supported not only by purely quantitative methods but also by deductive methods such as FMEA (Failure Modes and Effects Analysis), optionally involving the component manufacturer, and literature research.

[0067] The technical system can be designed and monitored in such a way that any persistent errors are detected very quickly, for example, by comparison with reference points or reference patterns. Qualitative and quantitative analyses can be generated and supported by simulations (e.g., using fault insertion).

[0068] diagnosis of the

[0069] For the perception system based on the fusion of multiple sensor data, it is possible to check whether the detected object hypotheses correspond to the normally known error patterns. The errors can be determined by comparing the recorded object hypotheses from the individual sensor paths. If the error patterns at the output of the perception system deviate from the normally known error patterns, a malfunction of the technical system can be assumed. This malfunction can be reported to the technical system. A measure can be assigned to each error class (for example, emergency stop or maintenance entries in the diagnostics). If there is a deviation in the observed distributions of the error classes for individual sensor paths or the acquisition unit as a whole, a malfunction of this sensor path or the acquisition unit can be concluded.

[0070] If a persistent deviation in the error classes is observed, a change in the operating environment can be inferred, for example, a different location or a change due to weather conditions, structural modifications, or the type of objects to be detected ("data drift" or even "concept drift"). This allows for verification of the validity of the evidence.

Claims

Patent claims 1. A computer-implemented method for checking at least one defect class, comprising the steps of: a. providing at least one defect class with at least one defect relating to at least one object or at least one feature of the at least one object (S1); wherein the at least one object or the at least one feature of the at least one object is detected by at least one detection unit of a technical system; wherein the at least one defect is assigned to a corresponding defect class of the at least one defect class based on at least one defect criterion; b. providing at least one predetermined criterion (S2); c. deriving at least one measure for each defect class of the at least one defect class by comparing the at least one defect criterion of the at least one defect class with the at least one predetermined criterion with regard to a deviation (S3); and d.Providing at least one derived measure (S4).

2. Computer-implemented method according to claim 1, wherein the at least one error criterion is an error duration, an error location or an error frequency and / or the at least one predetermined criterion is a predetermined duration, a predetermined location or a predetermined frequency.

3. Computer-implemented method according to claim 1 or claim 2, wherein the at least one error class covers the total error spectrum.

4. Computer-implemented method according to any of the preceding claims, wherein the at least one error is an error selected from the group consisting of: the at least one object or the at least one feature is not detected, and At least one object or at least one characteristic is recorded incorrectly.

5. Computer-implemented method according to any of the preceding claims, wherein the at least one error is dependent on at least one condition, wherein the at least one condition is a condition selected from the group consisting of: a type of the at least one detection unit, a setup or configuration of the at least one detection unit, a characteristic of the at least one detection unit, a distance between the technical system and the at least one object, an operating environment of the at least one detection unit and a location or substrate of the at least one detection unit.

6. Computer-implemented method according to one of the preceding claims, wherein a deviation exists if the at least one error criterion exceeds or falls below the at least one predetermined criterion.

7. Computer-implemented method according to any one of the preceding claims, further comprising - Outputting at least one derived measure, at least one error class and / or associated data on a display unit or a computing unit, - Storing at least one derived measure, at least one error class and / or associated data in a storage unit, - Transmitting at least one derived measure, at least one error class and / or associated data to a computing unit, - Analyzing at least one derived measure, at least one error class and / or associated data, - Evaluating at least one derived measure, at least one error class and / or associated data; wherein the analysis and / or evaluation preferably includes a hazard assessment with regard to persons and / or the technical system, and / or - Initiating or carrying out at least one derived measure, preferably after analysis and / or evaluation.

8. Computer-implemented method according to any one of the preceding claims, wherein the measure is a measure selected from the group consisting of: - Treating at least one error class, - Tolerating at least one error class, - Performing a reaction depending on at least one error class and - Adapting the technical system, at least one technical component of the technical system and / or one function of the technical system.

9. Technical system for carrying out the method according to one of the preceding claims.

10. Computer program product comprising a computer program comprising means for carrying out the method according to any one of claims 1 to 8, when the computer program is executed on a program-controlled device.

Citation Information

Patent Citations

  • Method for locating surface defects

    EP2463175A2

  • Railroad track survey system

    EP3138753A1

  • Apparatus and method for performance and fault data analysis

    WO2001031450A1

  • Self-assembling wireless network, vehicle communications system, railroad wheel and bearing monitoring system and methods therefor

    WO2007103016A2