System and method for determining the integrity of sensors installed in a rail vehicle
Patent Information
- Application Number
- PCT/IB2026/052960
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-03-27
- Filing Date
- 2026-03-26
- Publication Date
- 2026-10-01
Smart Images

Figure IB2026052960_01102026_PF_FP_ABST
Abstract
Description
[0001] " SYSTEM AND METHOD FOR DETERMINING THE INTEGRITY OF SENSORS INSTALLED IN A RAIL VEHICLE"
[0002] Cross-Reference to Related Applications This Patent Application claims priority from Italian Patent Application No. 102025000006372 filed on March 27, 2025, the entire disclosure of which is incorporated herein by reference.
[0003] Technical Field
[0004] The present invention relates to a system and method for determining the integrity of sensors installed in a railway vehicle.
[0005] State of the Art
[0006] In recent years, autonomous railway vehicles have been proposed that determine kinematic parameters (primarily position and speed) based on data provided by various sensors such as IMUs, GNSS receivers and RADAR, which collect realtime data on the aforementioned kinematic parameters. It is essential that the data produced by the sensors is reliable so that the autonomous vehicle can calculate its kinematic parameters and improve overall safety and operational efficiency.
[0007] However, as sensors are subj ect to failure or environmental disturbances, early detection of sensor faults is essential to ensure that malfunctioning sensors are not used to determine the required kinematic parameters.A sensor failure may be due to various reasons, including:
[0008] • sensor damage, for example physical damage causing a partial or complete loss of function;
[0009] • unexpected changes in sensor position: for example, a RADAR tilt angle or an accelerometer orientation may change unexpectedly;
[0010] • sensor wear: prolonged use may compromise sensor characteristics or settings;
[0011] • sensor calibration: regular calibration (e. g. every 6-12 months) is necessary to ensure accuracy, with schedules depending on the type of sensor and conditions of use.
[0012] The current state of the art provides only plausibility checks and / or only simple faults are detected in the sensors. Note that fusion algorithms have been proposed to combine the outputs of different sensors to improve the overall accuracy and reliability of the measurement.
[0013] Furthermore, when fusion algorithms are used, before feeding the sensor outputs into the fusion algorithm, it is necessary to verify whether the data provided by each sensor is acceptable and reliable, as faulty sensors negatively affect the fusion algorithm, thereby compromising safety and operational reliability, which are crucial factors for autonomous navigation systems.
[0014] There is therefore a need to provide a system and method for determining the integrity of sensors installed in a rail vehicle, as this constitutes a fundamental step in ensuringreliable and safe vehicle-based localisation.
[0015] Summary of the Invention
[0016] The scope described above is achieved by the present invention, as it relates to a system and a method for determining the integrity of sensors installed in a railway vehicle as defined in claims 1 and 6.
[0017] Brief Description of the Drawings
[0018] The invention will be described with reference to the accompanying drawings, which represent a non-limiting illustrative example of the invention, wherein:
[0019] Figure 1 schematically represents a railway vehicle implementing the system and method of the present invention; Figure 2 schematically shows the processing architecture of the system of the present invention; and
[0020] Figure 3 shows data processed by the system according to the invention.
[0021] Detailed Description of the Invention In Figure 1, the number 1 denotes a rail vehicle, for example a train, a tram or any other type of vehicle moving along a railway track 2. The vehicle 1 is shown schematically and partially by means of a front portion of the vehicle 1. Most preferably, the rail vehicle 1 is an autonomous vehicle. Vehicle 1 is equipped with a plurality of sensors Ai, A2,..., Ai,..., Anof different types, which provide output data used to determine kinematic parameters of the vehicle along the railway track 2.Typical kinematic parameters are the position of the vehicle along the railway track 2 and the speed of the vehicle along the railway track 2.
[0022] The sensors Ai, A2,, Ai,..., Anare of different types and may include, for example, RADAR, inertial navigation units ( IMU) and GNSS (Global Navigation Satellite System) receivers, or accelerometers or speed sensors.
[0023] An electronic processing unit 3 (on-board computer) is provided which receives measurement data from sensors Ai, A2,..., Ai,..., An, analyses the input data and provides, for each sensor, a binary output that can represent two alternative hypotheses, HO and Hl, respectively:
[0024] - hypothesis HO means that the measurement data provided by the sensors are such as to guarantee their integrity; - hypothesis Hl means that the measurement data provided by the sensors are not such as to guarantee their integrity, i. e. a sensor error is detected.
[0025] Note that two types of errors are possible: type I errors ( ) with probability a, which occur when hypothesis HO (integrity) is rej ected even though it is actually true (although the acquired data indicate that the sensor is intact, the test concludes by rej ecting the sensor data). This error defines the probability of a false alarm (PFA), given that, although HO is true, Hl is chosen, i. e.:
[0026] a = PFA= P Reject H0\H0is true)• Type II error with probability p, which occurs when hypothesis HO (integrity) is accepted when it is in fact false (although the acquired data indicate that the sensor is not intact, the test concludes with the acceptance of the sensor data). This error defines the probability of a false positive ( PMD ), since, although the hypothesis Hl is true, the hypothesis HO is chosen. Of the two error probabilities, the probability of a false positive PMD is the most critical from a safety perspective as it is associated with the dangerous condition whereby the loss of sensor integrity is not detected, namely:
[0027] FT = PMD = P(Accept H0\H0is false)
[0028] Given the probabilities of false alarms and detection error a and p, the following can be defined:
[0029] • ( 1-a) confidence level (probability of accepting hypothesis HO when hypothesis HO is actually true);
[0030] • ( 1-p) power (probability of rej ecting the null hypothesis HO when the null hypothesis HO is in fact false). The optimal solution would be to minimise both error probabilities a and p simultaneously, but this is not mathematically possible.
[0031] In fact (referring to Figure 3), a decrease in the value of a would necessarily correspond to an increase in the valueof p, and vice versa. Therefore, it is necessary to adopt values of a and p capable of minimising the probability of a false positive ( PFA) as much as possible, whilst keeping the probability of a false alarm ( PFA) below acceptable levels ( e. g. 10%).
[0032] The significance of the two types of errors mentioned above is shown graphically in Figure 3, where the false alarm probability p is represented in light grey and the miss probability a is shown in dark grey.
[0033] The functions of electronic processing unit 3 for determining sensor integrity will be described with reference to Figure 2. These operations are designed to ensure that each sensor operates correctly in accordance with its design specifications. These operations are implemented to ensure the early detection of any fault that might compromise the correct detection and measurement of the entire range of values.
[0034] Electronic processing unit 3 is configured to receive data SI supplied by a first sensor Al under test and data S2 supplied by a second sensor A2 under test of the same type as sensor Al. For example, both sensors Al and A2 are velocity sensors, or they are acceleration sensors, or they are position sensors. Both sensors SI and S2 measure the same physical quantity. In particular, sensors of the same type refer to sensors which, whilst not being of the same brand or manufactured using the same technology, are used tomeasure the same kinematic quantity (e. g. position velocity).
[0035] The electronic processing unit 3 is designed to perform a normality test (Block 10) to verify whether the data SI and S2 provided by sensors Al and A2 both have a Gaussian distribution. The normality test is performed independently on the data streams SI and S2 generated by sensors Al and A2.
[0036] More specifically, a difference AS between the data SI and S2 (AS = ABS (S1-S2 ) ) is calculated in a subtraction node 12, and the difference AS between SI and S2 is tested to check whether the difference AS also has a Gaussian distribution. Indeed, as is well known, if the data SI and S2 have a Gaussian distribution, the difference AS also has a Gaussian distribution.
[0037] If the normality check 10 fails, an error is detected in one or both of the sensors Al and A2.
[0038] If the normality test 10 is successful, the electronic processing unit is designed to perform a further hypothesis test (block 20) on the difference AS between the data SI and S2. Hypothesis test 20 is based on the assumption that, if both sensors Al and A2 are functioning correctly, the data SI and S2 exhibit similar dynamic behaviour and the mean value PAS of the difference AS is close to zero, and the variance is equal to the sum of the variances of the data SI and S2, which can be expressed in terms of variance as:σA2+ σB2
[0039] where OA and OB are the standard deviations of the data SI and S2 (it should be noted that the variance is represented by o2where o is the standard deviation).
[0040] In other words, it has already been verified in Section 10 that the data SI and S2 have a Gaussian random distribution;
[0041] SI (t) ~ N( IA,A)
[0042] S2 (t) ~ N( iB,aB)
[0043] By subtracting the two random processes in 12, the following Gaussian random process can be obtained, which is assumed to have a mean of zero P S (or below a threshold value close to zero) and a variance equal to:
[0044] c
[0045]
[0046] rA2+ aB2
[0047] If the hypothesis test (block 20) is verified and successful, the electronic processing unit 3 is designed to identify both sensors Al and A2 as functioning correctly, i. e. both sensors Al and A2 satisfy the same null hypothesis HO (see the indication 'PASSED' in Figure 2 ).The normality check and the hypothesis test constitute an initial homogeneity test between sensors SI and S2 of the same type (as defined above) and which measure the same physical quantity.
[0048] If the hypothesis test (block 20) fails (see the 'FAILED' indication in Figure 2 ), the electronic processing unit 3 is designed to perform a further check (TEST 2 or heterogeneous test) to identify which of the sensors Al or A2 is faulty by comparing the data SI or S2 with additional data S3 provided by a sensor A3 of a different type (TEST 2 or heterogeneous test, as a different type of sensor is used in the test). It should be noted that the heterogeneous test will only be performed if the integrity of sensor A3 has already been verified, ensuring that the S3 data is valid ( for example, via a similar homogeneous test between two sensors, A3 and A4, using S3 and S4 data). For example, if both sensors Al and A2 are acceleration sensors, sensor A3 is a velocity sensor.
[0049] The additional verification provides the following operations:
[0050] providing a second normality check (Block 30) to verify whether the subtraction between the SI and S3 data provided by the different types of sensors Al and A3 also has a Gaussian distribution.
[0051] If the second normality check 30 is successful, the electronic processing unit 3 is designed to perform a furthersecond hypothesis test (block 40) on the subtraction between data SI and S3. Furthermore, in this case, the second hypothesis test 40 assumes that, if both sensors Al and A3 are functioning correctly, the data SI and S3 will exhibit similar dynamic behaviour and the mean value of the difference will be close to zero and the variance equal to:
[0052] <^A2+ OC2
[0053] where OA and oc are the standard deviations of data SI and S3. If the second hypothesis test 40 is successful, sensor Al is considered to be functioning correctly (" Passed") as data SI shows significant similarity with data S3 from a sensor of a different type.
[0054] If the second hypothesis test 40 fails, sensor Al is considered defective (" Failed") when the data SI show a significant difference from the data S3 of a sensor of a different type.
[0055] After performing TEST 2 between sensors Al and A3, it is also crucial to perform the heterogeneous analysis between sensors A2 and A3, even if the first test is successful. This step ensures that potential simultaneous failures of both sensors Al and A2 are ruled out and helps to avoid false positives in the homogeneous test.
[0056] The additional verification provides the following operations:providing a third normality check (Block 50) to verify whether the subtraction between the S2 and S3 data provided by the different types of sensors A2 and A3 also has a Gaussian distribution.
[0057] If the third normality check 50 is successful, the electronic processing unit 3 is designed to perform a further third hypothesis test (block 60) on the difference between the data S2 and S3. Again, the third hypothesis test 60 predicts that, if both sensors A2 and A3 are functioning correctly, the data S2 and S3 will exhibit similar dynamic behaviour and the mean value of the difference will be close to zero and the variance equal to:
[0058] c
[0059]
[0060] σB2+ σC2
[0061] where OB and oc are the standard deviations of data S2 and S3.
[0062] If the second hypothesis test 60 is successful (" Passed"), sensor A2 is considered to be functioning correctly as the S2 data show significant similarity with the S3 data from a sensor of a different type.
[0063] If the third hypothesis test 60 fails (" Failed"), sensor A2 is considered faulty as the data S2 show a significant difference from the data S3 of a sensor of a different type. Situations in which both heterogeneous tests consistently result in two failures or two successes are considered indeterminate, making it impossible to validate theintegrity of the sensors.
[0064] If the cross-check between A2 and A3 also yields a positive result, an ambiguous scenario arises where it is not possible to determine which sensor should be identified as faulty: both Al and A2? A false positive in the test? Or perhaps a fault in S3?
[0065] REFERENCE NUMBERS
[0066] 1 railway vehicle
[0067] 2 railway tracks
[0068] 3 electronic processing units
[0069] 10 normality check
[0070] 12 subtraction node
[0071] 20 hypothesis tests
[0072] 30 second normality check
[0073] 40 second hypothesis test
[0074] 50 third normality test
[0075] 60 third hypothesis test
Claims
CLAIMS1. A system for determining the integrity of sensors installed in a railway vehicle ( 1 ) moving along a track (2 ) and equipped with a plurality of sensors (Ai, A2,, Ai,..., An) of different types used to determine at least one kinematic parameter of the vehicle along the track; the system comprising an electronic processing unit (3) configured to receive data SI supplied by a first sensor Al under test and data S2 supplied by a second sensor A2 under test of the same type as sensor Al, namely both sensors SI and S2, manufactured using different technologies, measure the same physical quantity; the electronic processing unit is configured to perform a normality check (block 10) to verify whether the data SI and S2 supplied by sensors Al and A2 both have a Gaussian distribution; if the normality check ( 10) is successful, the electronic processing unit is designed to perform a further hypothesis test (block 20) carried out on the difference AS between the data SI and S2; the hypothesis test (20) involves checking whether the mean value of the difference AS is below a threshold value close to zero and the variance of the difference AS is equal to:cσA2+ σB2where OA and OB are the standard deviations of the data SI and S2; if the hypothesis test (block 20) is successful, theelectronic processing unit (3) is designed to identify both sensors Al and A2 as functioning correctly; and, if the hypothesis test (block 20) fails, the electronic processing unit (3) is configured to perform a further check to identify which of the sensors Al or A2 is faulty by comparing the data SI or S2 with further data S3 provided by a sensor A3 of a different type.
2. - A system as claimed in claim 1, wherein the electronic processing unit (3) is designed to calculate a difference AS between the data SI and S2 (AS = ABS (S1-S2) ) and it is verified whether the difference AS between SI and S2 has a Gaussian distribution.
3. - A system as claimed in claim 1 or 2, wherein the electronic processing unit (3) is configured to detect a fault in one or both of the sensors Al and A2 if the normality check ( 10) is unsuccessful.
4. - A system as claimed in one of the preceding claims, wherein the further verification comprises the following steps: performing a second normality test (Block 30) to verify whether the difference between data SI and S3 provided by sensors Al and A3 of different types also follows a Gaussian distribution; if the second normality check is successful, the electronic processing unit is designed to perform a further second hypothesis test (Block 40) on the subtraction between data SI and S3, checking whether the mean value of the subtraction is below a threshold close tozero and whether the variance is equal to:°σA2+ σC2where OAand ocare the standard deviations of the SI and S3 data;if the second hypothesis test (40) is successful, sensor Al is considered to be functioning correctly as data SI shows significant similarity with data S3 from a sensor of a different type; if the second hypothesis test (40) fails, sensor Al is considered defective as data SI shows a significant difference from data S3 of a different type of sensor.
5. - A system as claimed in claim 4, wherein the further verification comprises the following operations: performing a third normality check (Block 50) to verify whether the difference between data S2 and S3 provided by sensors A2 and A3 of a different type also has a Gaussian distribution; if the third normality check (50) is successful, the electronic processing unit (3) is designed to perform a further third hypothesis test (block 60) on the difference between data S2 and S3; the third hypothesis test ( 60) involves checking whether the mean value of the subtraction is below a threshold close to zero and the variance is equal to:cσB2+ σC2where OB and oc are the standard deviations of the data S2 and S 3;if the second hypothesis test ( 60) is successful, sensor A2 is considered to be functioning correctly as the S2 data show significant similarity with the S3 data from a sensor of a different type;if the third hypothesis test ( 60) fails, sensor A2 is considered faulty as the data S2 show a significant difference from the data S3 of a sensor of a different type.
6. - Method for determining the integrity of sensors installed in a railway vehicle ( 1 ) moving along a track (2 ) and equipped with a plurality of sensors (Ai, A2,... Ai,... An) of different types used to determine at least one kinematic parameter of the vehicle along the railway track, comprising the following steps:receiving data SI provided by a first sensor Al under test and data S2 provided by a second sensor A2 under test of the same type as sensor Al;perform a normality test (block 10) to check whether the data SI and S2 provided by sensors Al and A2 both follow a Gaussian distribution; if the normality test ( 10) is successful, a further hypothesis test (block 20) is performed on the difference between the data SI and S2; the hypothesis test (20) involves checking whether the mean value of the difference is below a threshold value close to zero and the variance of the difference is equal to:σA2+ σB2where OA and OB are the standard deviations of the data SI and S2; if the hypothesis test (block 20) is successful, the electronic processing unit (3) is designed to identify both sensors Al and A2 as functioning correctly; and, if the hypothesis test (block 20) fails, the electronic processing unit (3) is configured to perform a further check to identify which of the sensors Al or A2 is faulty by comparing the data SI or S2 with further data S3 provided by a sensor A3 of a different type.
7. - A method as claimed in claim 6, comprising the step of calculating a difference AS between the data SI and S2 (AS = ABS (S1-S2 ) ) and verifying whether the difference AS between SI and S2 has a Gaussian distribution.
8. - A method as claimed in claim 6 or 7, wherein a fault in one or both of the sensors Al and A2 is detected if the normality check ( 10) fails.
9. - A method as claimed in any one of the preceding claims 6 to 8, wherein the further check comprises the following operations:performing a second normality check (Block 30) to verify whether the subtraction between data SI and S3 provided by sensors Al and A3 of the different type also has a Gaussian distribution; if the second normality check is successful, perform a further second hypothesis test (Block 40) on the subtraction between data SI and S3, checking whether themean value of the subtraction is below a threshold close to zero and the variance is equal to:cσA2+ σC2where OA and ocare the standard deviations of the SI and S3 data;if the second hypothesis test (40) is successful, sensor Al is considered to be functioning correctly as the SI data show significant similarity with the S3 data from a sensor of a different type; if the second hypothesis test (40) fails, sensor Al is considered defective as the data SI show a significant difference from the data S3 of a sensor of a different type.
10. - A method as claimed in claim 9, wherein the further verification comprises the following steps:performing a third normality check (Block 50) to verify whether the difference between data S2 and S3 provided by sensors A2 and A3 of a different type also has a Gaussian distribution;if the third normality check (50) is successful, perform a further third hypothesis test (block 60) on the difference between data S2 and S3; the third hypothesis test ( 60) involves checking whether the mean value of the difference is below a threshold close to zero and whether the variance is equal to:cσB2+ σC2where OB and oc are the standard deviations of the data S2 and S 3;if the second hypothesis test ( 60) is successful, sensor A2 is considered to be functioning correctly, as the S2 data show significant similarity with the S3 data from a sensor of a different type;If the third hypothesis test ( 60) fails, sensor A2 is deemed faulty, as the S2 data show a significant deviation from the S3 data of a sensor of a different type.