为自动驾驶感知系统设计运行时监控框架,提升故障下的安全运行能力。
Connected Dependability Cage: Run-Time Function and Anomaly Monitoring for the Development and Operation of Safe Automated Vehicles

- 通过功能与异常双监控机制,实时检测感知系统不一致与未知物体。
- 在发现关键异常时支持降级处理,最终进入最小风险操作策略。
- 自动记录安全预警数据,助力系统迭代优化,适合高阶自动驾驶研发使用。
自动驾驶技术的发展带来了复杂的安全挑战,尤其在动态不可预测环境中,依赖AI的感知系统必须保持可靠运行。符合ISO 26262和ISO/PAS 21448(SOTIF)等安全标准对应对系统故障和未知场景中的不安全行为至关重要。随着自动化等级提升,车辆需超越传统功能安全,具备故障可运行能力,以在组件失效或面对陌生、退化工况时仍能安全运行。为此,本文提出「连接可靠性笼」(Connected Dependability Cage)架构,支持AI感知系统的分层故障可运行行为。该框架集成两种互补的监控机制:功能监控器负责管理多个异构的AI感知流水线,通过投票机制检测不一致;异常监控器则评估感知可靠性,识别可能未出现在训练数据中的未知或新物体。当出现严重差异时,系统支持平稳降级,最终实现最小风险操作策略。此外,任一监控器触发安全警报后,将自动启动数据记录流程,以支持系统的持续迭代与改进。两项监控机制已在实车测试中实现并验证,展现出在真实场景中的实际有效性。
原文摘要 · Abstract (English)
The advancement of automated vehicles introduces complex safety challenges, particularly in dynamic and unpredictable environments where AI-enabled perception systems must operate reliably. Ensuring compliance with safety standards such as ISO 26262 and ISO/PAS 21448 (SOTIF) is essential for addressing system malfunctions and mitigating unsafe behavior in unknown scenarios. However, as automation levels increase, vehicles must go beyond conventional functional safety by incorporating fail-operational capabilities that enable continued safe operation during system or component failures and the handling of unfamiliar or degraded operational conditions. To address these safety concerns, we propose the Connected Dependability Cage, an architectural framework designed to enable hierarchical fail-operational behavior in AI-enabled perception systems. This framework integrates two complementary monitoring mechanisms: a Function Monitor that oversees multiple heterogeneous AI-based perception pipelines and detects inconsistencies through a voting mechanism, and an Anomaly Monitor that evaluates the reliability of AI perception by detecting unknown or novel objects in scenes that may be excluded from the training dataset. In the presence of critical discrepancies, the system supports graceful degradation, ultimately enabling a transition to a minimal-risk maneuver strategy. Furthermore, whenever either monitor raises a safety flag, an automated data recording process is initiated to facilitate iterative system development and continuous improvement. Both monitors have been implemented and validated through extensive vehicle testing, demonstrating their practical effectiveness in real-world applications.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。