为自动驾驶安全设计可解释性方法评估标准,强调不同阶段需匹配不同证据类型。
Output Type Before Quality: A Standards-Derived XAI Admissibility Rubric for Autonomous-Driving Safety

- 基于安全标准构建19条可验证的证据准则,按生命周期阶段评估XAI方法
- 因果类方法在危险识别等三阶段必须使用,可减少62%的证据缺口
- 建议根据安全流程阶段选择XAI方法,而非依赖流行度
ML驱动的自动驾驶系统安全标准要求保证案例包含特定类型的证据(如因果链、量化干预效应、根因变量),但现有可解释性研究多按输出类型和方法族(显著图、特征归因、反事实、因果图、语言痕迹)组织。尽管SHAP是最推荐的自动驾驶可解释方法,其输出的特征排序无法转化为有向因果链(图1)。我们称此为证据类型差距。基于AMLAS、ISO 26262、ISO 21448、ISO/PAS 8800,推导出跨7个生命周期阶段的19条可测试证据标准,并对六类XAI方法进行结构化评分。结果显示,因果类XAI在危险识别(+62%证据缺口)、事故调查(+50%)和数据管理(+50%)阶段为结构性必需;结论在阈值T∈(0%, 50%]下稳定,且在最坏单单元翻转下仍维持至T=25%。其余四阶段中,相关或语言类方法可替代或足够。该评估框架定义了结构性可接受性(合规必要但不充分):方法输出内容可能错误,验证其精确性(拟合结构因果模型的边、痕迹命名的因果)仍是开放挑战。基于1,996段真实驾驶视频(79,840行,十折划分)的单视觉语言模型验证显示,各方法输出类型与框架预测一致。自动驾驶安全保证中的XAI方法选择应以生命周期阶段的证据需求为导向,而非方法流行度。
原文摘要 · Abstract (English)
Safety standards for ML-based autonomous driving specify the kind of evidence an assurance case must contain (directed cause-and-effect chains, quantified interventional effects, named root-cause variables), yet the XAI literature is organised by output type and technique family (saliency maps, feature attribution, counterfactuals, causal graphs, language traces). SHAP, the most-recommended ADS XAI method, returns a ranked feature list that no implementation effort can convert into a directed chain (Fig.1). We name this mismatch the evidence-type gap. From AMLAS, ISO 26262, ISO21448, ISO/PAS 8800 we derive 19 testable evidentiary criteria across 7 lifecycle stages with representative clause-cited derivations and score six XAI method classes structurally. Causal XAI emerges as structurally required to satisfy the derived criteria at three stages: hazard identification (+62% rubric gap), incident investigation (+50%), and data management (+50%); the verdict set is stable across thresholds T in (0%, 50%]$ and survives a worst-case single-cell flip down to T = 25%. At the remaining four stages, correlational or language-based methods are comparable or sufficient. The rubric identifies structural admissibility (necessary but not sufficient for compliance): an admissible method's specific output content may still be wrong, and validating that fidelity (the edges a fitted SCM produces, the cause a trace names) is the open assurance challenge. A single-VLA proof of concept on 1,996 real-world driving clips (79,840 rows, ten splits) is consistent with each method's observed output type matching its rubric prediction. XAI method selection for ADS safety assurance should be driven by lifecycle-stage evidence demand, not by method popularity.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。