376
W. Chang et al.
these can contribute to a structured assurance case. Finally, we reflect on the current
state of the art in this area and the overall potential for providing a convincing
argument for using machine learning technique in safety-critical applications.
7.3.1.1 Introduction
The transition from hands-on (Levels 1–2 of [8]) driver assistance to hands-off
highly automated driving (HAD) (Levels 3–5) requires a number of changes to
system safety concepts. For example, a higher level of component availability is
required as the system cannot be simply deactivated upon detection of a component
hardware fault. The conditions for being acceptably safe with respect to functional
safety for passenger vehicles are set by ISO 26262 [9]. Adherence to this standard
remains a necessary prerequisite in order to ensure a reliable and fault-tolerant
implementation of the system with respect to random hardware and systematic
failures. For highly automated driving, demonstrating the sufficiency of the system
to meet its overall safety goals becomes more challenging due to the inherent
complexity and unpredictability of the operational design domain. This continually
evolving environment is in itself observed via channels that are imperfect due
to the technical limitations of the sensors. Thus, the understanding and decisionmaking components of the system are presented with noisy, incomplete, and partly
inconsistent data about the current situation. Based on this partial understanding
of the environment, the system must make the decisions required to implement a
driving strategy capable of safely navigating the vehicle to its ultimate destination.
The dominating challenge facing the safety assurance of highly automated driving
systems is the derivation and validation of adequate system safety goals and the
demonstration of their fulfilment under all feasible situations. This needs to be
achieved despite the complexity and uncertainty inherent in the domain, sensing and
understanding/decision algorithms. The issue of the insufficiency of the system to
meet the safety goals, due to inherent performance limitations in sensors or actuators
or the inadequacy of the intended function itself, is not directly addressed by ISO
26262. The “Safety of the Intended Functionality” (SOTIF) approach described
in the draft standard ISO 21448 [10] aims to address these issues. However, the
standard was developed with driver assistance (Levels 1 and 2 of SAE model)
systems in mind. It is therefore unclear whether or not the approaches defined by the
standard scale to the level of complexity of HAD systems (Levels 3 and upwards).
The performance limitations in the perception task are typically counteracted
by using multiple sensing channels and finely tuned heuristics. Recent advances
in machine learning algorithms and the availability of increased computing power
have led to the promise of such algorithms being able to solve the perception
tasks required by highly automated driving functions operating in unrestricted
environments. Algorithms such as deep neural networks [11] can make sense of
unstructured data using efficient computations in real time. By providing enough
labelled images as training data, the algorithms learn to identify and classify
objects such as vehicles and pedestrians with accuracy rates that can surpass
Précédent

- 381/647

Suivant