7 Intelligent and Connected Cyber-Physical Systems: A Perspective. . .
375
The number of poles to place, i.e., the number of eigenvalues in
A hol
1 + B hol
1 K 1
and
A hol
2 + B hol
2 K 2
, is 2l + 2. This is a constrained non-convex optimization
problem. The objective to maximize is the control performance of C i . Decision
variables are the poles and thus the number of dimensions in the decision space
is 2l + 2. Heuristics can be used to solve this pole-placement optimization problem.
Once poles are placed, K 1 and K 2 can be computed. Then F 1 and F 2 can be
calculated. With this method, both feedback gains are designed together taking all
the information into account. The maximum control performance can be obtained
if the optimization technique returns the optimal poles. However, when C i is
consecutively executed m i times in a sampling order, the number of dimensions
in the decision space becomes m i (l + 1), which compromises the scalability.
The above memory-aware CPS design is able to achieve better control performance with the same given memory resources or equivalently satisfies the control
performance requirement with fewer memory resources. This can be generalized to
other types of resources as well. Note that in this design process, the system safety
is always guaranteed, in the sense that the control performance requirements are
always met. Other aspects such as security and robustness can be also addressed by
this new cross-layer CPS design methodology.
For security properties, it is generally difficult to incorporate cryptographic
algorithms and message authentication code into the CPS, since they consume
substantial computational power and communication bandwidth. New approaches
can be developed that design the controllers together with cryptographic algorithms
with a thorough timing analysis of the complete system. A trade-off analysis
between the degree of security, control performance, and platform schedulability
can be performed.
For robustness properties, new techniques can be developed that the control
algorithms are able to tolerate the faults on the implementation side, such as from
sensors, actuators, processors, memory, bus, etc. There are mainly two directions.
First, the statistically expected performance of the CPS can be improved, taking all
sorts of possible faults into account. Second, certain performance of the CPS, e.g.,
the stability of a plant under control, is guaranteed for a limited set of faults.
7.3 Case Studies
7.3.1 Assuring the Safety of Machine Learning-Based
Perception for Highly Automated Driving
This case study describes how to assure the safety of machine learning approaches
using their application to the perception functions of highly automated driving as an
example. An assurance case strategy is described based on an understanding of the
causes of functional insufficiencies in machine learning. A number of techniques for
demonstrating the performance of the functions are discussed, and it is shown how
375
The number of poles to place, i.e., the number of eigenvalues in
A hol
1 + B hol
1 K 1
and
A hol
2 + B hol
2 K 2
, is 2l + 2. This is a constrained non-convex optimization
problem. The objective to maximize is the control performance of C i . Decision
variables are the poles and thus the number of dimensions in the decision space
is 2l + 2. Heuristics can be used to solve this pole-placement optimization problem.
Once poles are placed, K 1 and K 2 can be computed. Then F 1 and F 2 can be
calculated. With this method, both feedback gains are designed together taking all
the information into account. The maximum control performance can be obtained
if the optimization technique returns the optimal poles. However, when C i is
consecutively executed m i times in a sampling order, the number of dimensions
in the decision space becomes m i (l + 1), which compromises the scalability.
The above memory-aware CPS design is able to achieve better control performance with the same given memory resources or equivalently satisfies the control
performance requirement with fewer memory resources. This can be generalized to
other types of resources as well. Note that in this design process, the system safety
is always guaranteed, in the sense that the control performance requirements are
always met. Other aspects such as security and robustness can be also addressed by
this new cross-layer CPS design methodology.
For security properties, it is generally difficult to incorporate cryptographic
algorithms and message authentication code into the CPS, since they consume
substantial computational power and communication bandwidth. New approaches
can be developed that design the controllers together with cryptographic algorithms
with a thorough timing analysis of the complete system. A trade-off analysis
between the degree of security, control performance, and platform schedulability
can be performed.
For robustness properties, new techniques can be developed that the control
algorithms are able to tolerate the faults on the implementation side, such as from
sensors, actuators, processors, memory, bus, etc. There are mainly two directions.
First, the statistically expected performance of the CPS can be improved, taking all
sorts of possible faults into account. Second, certain performance of the CPS, e.g.,
the stability of a plant under control, is guaranteed for a limited set of faults.
7.3 Case Studies
7.3.1 Assuring the Safety of Machine Learning-Based
Perception for Highly Automated Driving
This case study describes how to assure the safety of machine learning approaches
using their application to the perception functions of highly automated driving as an
example. An assurance case strategy is described based on an understanding of the
causes of functional insufficiencies in machine learning. A number of techniques for
demonstrating the performance of the functions are discussed, and it is shown how
