提出可验证的交互修复机制,让自动驾驶系统判断对方是否该让行并给出修复方案。
CARVE: Certified Affordable Repair of Vetoed Maneuvers via Envelopes for Interactive Driving

- 构建无预测的证书层,用责任权重分配修复动作归属
- 98.64%被拒动作可修复,370/378人为误判被纠正
- 适合需高安全性与责任可解释的交互式自动驾驶场景
交互式驾驶中存在一种易被忽略的失效模式:即使车辆自身行为违反规则,只要非优先方做出小幅合法调整即可恢复可行性。现有规则库、防护盾和可达性过滤器擅长拒绝危险动作,但无法提供运行时证明,说明如何修复、谁应负责、是否符合路权、以及对方不配合时的备选方案。本文提出交互修复认证(Interactive Repair Certification)概念,并设计CARVE——在有限战术操作格上构建的无预测证书层。代理请求仅在$B_j(s) = β(π_j)α_j^{\max}(s)$合作包络内有效,分离运动可达性与规范优先级。证书记录绑定规则、修复类别、修复集、责任成本分配及后备策略。在589个基于Lanelet2几何的INTERACTION回放片段上,CARVE-Greedy成功接受98.64%初始被拒动作,恢复370/378人工修正的误拒,同时保持589/589路权尊重、零优先代理误报,且400/400负应力拒停正确保留。理论证明了证书保真性、结构路权尊重、有限格最小性、后备容错性和责问责一致性。CARVE无需预测他人行为合规性,仅验证提议交互在声明假设下是否边界可控、责任可归、规范可接受。
原文摘要 · Abstract (English)
Interactive driving exposes a failure mode that is easy to miss in rule-aware autonomous-driving stacks: a hard-rule margin can be negative for an ego candidate even though a small lawful accommodation by a non-priority agent would restore feasibility. Existing rulebooks, shields, and reachability filters are strong at vetoing unsafe actions, while prediction-based planners model likely responses. Neither returns a runtime proof object that states which bounded multi-agent edit repairs the maneuver, who owns the edit, whether the request is right-of-way affordable, and what ego fallback remains if the request is not observed. We formulate this missing object as *interactive repair certification* and introduce *CARVE*, a prediction-free certificate layer over a finite lattice of ego-owned and agent-owned tactical operators. Agent-owned requests are admissible only inside \(B_j(s) = β(π_j)α_j^{\max}(s)\), a cooperation envelope that separates kinematic reachability from normative priority. The resulting certificate records the binding rule, repair category, repair set, responsibility-weighted cost split, and fallback. On 589 Lanelet2-geometry-grounded INTERACTION replay episodes, CARVE-Greedy accepts 98.64% of initially vetoed maneuvers and recovers 370/378 human-resolved false vetoes, while preserving 589/589 right-of-way respect, zero priority-agent false positives, and 400/400 negative-stress vetoes. We prove certificate soundness, structural right-of-way respect, exact finite-lattice minimality, fallback contingency, and blame-consistency conditions. CARVE does not predict or require another driver's compliance; it certifies whether a proposed interaction is bounded, attributable, and normatively admissible under declared assumptions.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。