384
W. Chang et al.
the particular learning algorithm and its system context (e.g., camera resolution
and therefore distance at which pedestrians of a given size can be detected). The
allocation of performance requirements should also take into account the ability to
perform plausibility checks based on domain knowledge (e.g., maximum speed of
pedestrians) and alternative sensing channels (such as radar). The verification of
the function itself should consider attributes of the training data as well as diverse
analysis and test methods. Due to inherent robustness issues resulting from the high
dimensional input space and unpredictable manner in which features are learnt,
black-box, statistical testing evidence is not seen as a convincing argument on its
own. The more diverse the set of evidence that can be collected, the greater the
chance that all causes of potential deficiencies in the function are covered. Ideally,
verification and validation activities will provide insight into residual performance
limitations of the trained function to allow for system-level measures to be argued
that compensate these allowing for an overall safe system design.
Some of the approaches described in this case study have yet to be proven in
a series production context, and therefore their ability to predict the performance
of machine learning for safety-critical highly automated driving applications is as
yet unclear. Furthermore, it is expected that the safety arguments will need to be
application specific. For this reason it is crucial that a robust safety argument based
on a diverse set of complementary evidence is made. Such safety argumentation
approaches also need to be supported by further research to validate the effectiveness of techniques at reducing and detecting various classes of insufficiencies.
An industry consensus must also be developed in order to identify strategies
and methodologies that would form the basis of future internationally recognized
development standards.
7.3.2 Assuring the Security and Robustness of Connected
Vehicle Applications
7.3.2.1 Introduction
In recent years, automotive makers, high-tech companies, startups, and even
governments are developing autonomous vehicles aggressively. At the same time,
connected vehicles (or Internet of Vehicles) are another spotlight of this recent
automotive technology revolution. In most cases, connectivity and autonomy can
and should work together and realize a good application. For example, as shown in
Fig. 7.12, at an intelligent intersection controlled by its intersection manager, the
approaching vehicles and the manager can communicate with each other so that
the vehicles can go through the intersection in a safe and much more efficient way
without traffic lights. Here, “connectivity” is necessary to provide environmental
information (e.g., the coming vehicles blocked by buildings and obstacles) that the
sensors on a single vehicle cannot sense, while “autonomy” is necessary to provide
W. Chang et al.
the particular learning algorithm and its system context (e.g., camera resolution
and therefore distance at which pedestrians of a given size can be detected). The
allocation of performance requirements should also take into account the ability to
perform plausibility checks based on domain knowledge (e.g., maximum speed of
pedestrians) and alternative sensing channels (such as radar). The verification of
the function itself should consider attributes of the training data as well as diverse
analysis and test methods. Due to inherent robustness issues resulting from the high
dimensional input space and unpredictable manner in which features are learnt,
black-box, statistical testing evidence is not seen as a convincing argument on its
own. The more diverse the set of evidence that can be collected, the greater the
chance that all causes of potential deficiencies in the function are covered. Ideally,
verification and validation activities will provide insight into residual performance
limitations of the trained function to allow for system-level measures to be argued
that compensate these allowing for an overall safe system design.
Some of the approaches described in this case study have yet to be proven in
a series production context, and therefore their ability to predict the performance
of machine learning for safety-critical highly automated driving applications is as
yet unclear. Furthermore, it is expected that the safety arguments will need to be
application specific. For this reason it is crucial that a robust safety argument based
on a diverse set of complementary evidence is made. Such safety argumentation
approaches also need to be supported by further research to validate the effectiveness of techniques at reducing and detecting various classes of insufficiencies.
An industry consensus must also be developed in order to identify strategies
and methodologies that would form the basis of future internationally recognized
development standards.
7.3.2 Assuring the Security and Robustness of Connected
Vehicle Applications
7.3.2.1 Introduction
In recent years, automotive makers, high-tech companies, startups, and even
governments are developing autonomous vehicles aggressively. At the same time,
connected vehicles (or Internet of Vehicles) are another spotlight of this recent
automotive technology revolution. In most cases, connectivity and autonomy can
and should work together and realize a good application. For example, as shown in
Fig. 7.12, at an intelligent intersection controlled by its intersection manager, the
approaching vehicles and the manager can communicate with each other so that
the vehicles can go through the intersection in a safe and much more efficient way
without traffic lights. Here, “connectivity” is necessary to provide environmental
information (e.g., the coming vehicles blocked by buildings and obstacles) that the
sensors on a single vehicle cannot sense, while “autonomy” is necessary to provide
