Mutual HPC Monitoring for Autonomous Vehicle Fault Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Autonomous vehicle systems face challenges in meeting safety standards due to the lack of safety mechanisms in conventional data-center class hardware and operating systems, and replicated diagnostic systems struggle with asynchronous signals, leading to potential failure in fault detection and response.
Innovation Solution
Implementing a computer-based system with two independent high-performance computing systems on separate CPU boards, where monitors for perception and planning functions reside on different CPUs, allowing for mutual monitoring and fault detection without affecting both systems simultaneously, thus enabling compliance with safety standards and preventing complete system failures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If replicated diagnostic systems are implemented for redundant HPC systems, then fault detection capability is improved, but the system cannot distinguish between asynchronous signal behavior and actual faults, leading to false positives
Solution Approach 1:
A central coordinator component is introduced as an intermediary between the distributed diagnostic systems. This coordinator receives diagnostic data from multiple HPC systems, synchronizes the evaluation timeline, and coordinates fault detection decisions. The intermediary enables asynchronous systems to work together effectively by providing a reference timeline that resolves the distinction between timing differences and actual faults.
Solution Approach 2:
Multiple distributed diagnostic systems are merged into a unified coordinated diagnostic framework. Instead of operating independently, the diagnostic systems are combined under a single coordination mechanism that aggregates their observations and makes collective fault detection decisions, allowing the system to leverage redundancy while maintaining accuracy.
2Productivity
If data-center class hardware and operating systems are used in autonomous systems, then compute resources and processing capability are improved, but safety mechanisms and documentation required by safety standards are lacking
Solution Approach 1:
The system is segmented into functionally independent HPC systems, each with its own diagnostic monitoring. This segmentation allows the use of powerful data-center hardware while creating isolated failure domains. Each segment can be independently monitored and evaluated for safety compliance, allowing high-performance hardware to be used without compromising overall system safety.
Solution Approach 2:
Distributed diagnostic systems continuously monitor each HPC system and provide feedback on their operational status. This feedback mechanism enables real-time detection of deviations from safe operation, allowing the system to maintain safety compliance while using high-performance hardware that would otherwise lack built-in safety mechanisms.
3Ease of manufacture
If conventional hardware and operating systems are used, then ease of manufacture and availability are improved, but safety mechanisms and documentation required by safety standards are not present
Solution Approach 1:
The system implements self-monitoring through distributed diagnostic components that automatically detect and report faults in each HPC system. This self-service approach allows conventional hardware to compensate for its lack of built-in safety mechanisms by providing autonomous safety monitoring and fault detection capabilities.
Data Source
AI summary
A diagnostic system of a vehicle may evaluate the output of a first monitor configured to identify conflicts with forecasts for objects in proximity to the vehicle generated by a first processor based on perception information that indicates the objects to determine whether there is a conflict with a forecast for an object of the objects in proximity to the vehicle. The diagnostic system may evaluate the output of a second monitor configured to identify conflicts with instructions for controlling an operation of the vehicle generated by a second processor based on the perception information to determine whether there is a conflict with the instruction. The diagnostic system may provide instruction for causing the vehicle to execute a maneuver responsive a conflict with the forecast for the object, the conflict with the instruction for controlling the operation of the vehicle, and/or the like.


