Browse Topic: Automated driving systems

Items (443)
North American CAV Performance Data StandardWP-00157/22/2026
As the deployment of connected and automated vehicles (CAVs) expands, the need for a consistent, cross-industry approach to performancerelevant CAV data exchange is becoming more pressing. Vehicle developers, infrastructure owners and operators (IOOs), and technology providers generate and consume data that support safety, mobility, and operational efficiency, yet much of the data remains fragmented, inconsistently formatted, and difficult to reuse across systems. To address these gaps, the Society of Automotive Engineers (SAE) and the Canadian Standards Association (CSA) convened a multi-stakeholder workshop on November 3, 2025, with participants representing original equipment manufacturers (OEMs), automated driving system (ADS) developers, state and local agencies, standards bodies, and technology partners. The workshop focused on identifying challenges, clarifying needs, and outlining a path toward a North American CAV Performance Data Standard. Key themes from the workshop included: -A shared data language is needed to support safe and interoperable CAV operations. -The current ecosystem lacks consistent formatting, labeling, and visibility regarding who produces and consumes data. -A “start small, iterate, and scale” approach is needed, beginning with well-defined use cases such as school zones or baseline work zones. -Progress depends on technical harmonization and governance structures that build trust and support sustained coordination. This white paper summarizes the key findings and outlines a practical approach to developing a Version 0.1 base-layer data standard that can support measurable progress in 2026 and beyond.
Nesheli, Mahmood
This document is intended to establish a procedure to certify AD fallback test driver skill levels as an endorsement to SAE J3300 foundational level certification. The SAE J3300/3 endorsement can be used by the individual driver to qualify their skills as a test driver of vehicles with automated driving features. The SAE J3300/3 endorsement levels may also be used by test facilities or other organizations when seeking test or professional drivers with these skills. This document provides directions for obtaining the endorsement, including associated AD fallback test driving skill examination requirements, through SAE J3300-certified Examiners (refer to SAE J3300 for definition). Endorsement registration and associated records are administered through Probitas Authentication®. Probitas Authentication® is the current Independent Program Administrator for the SAE J3300 series. This document is a supplement to SAE J3300, providing information specific to the AD fallback test driver skill endorsement and clarifying the application of the rules set forth in SAE J3300 to the AD fallback test driver endorsement. While the references, definitions, rules, and guidelines presented in SAE J3300 Sections 1 through 5 apply to the AD fallback test driver endorsement, they are not repeated in this document.
Driving Skills Standards Committee
This paper presents an innovative study in exploring, evaluating, and implementing deep-learning architectures for the calibration of multimodal sensor systems. The aim of this paper is to leverage the use of sensor fusion to achieve dynamic, real-time alignment between 3D LiDAR and 2D camera sensors. Static calibration methods are tedious and time-consuming, which is why we propose utilizing conventional neural networks (CNNs) coupled with geometrically informed learning to solve this issue. We leverage the foundational principles of extrinsic LiDAR–camera calibration tools such as RegNet, CalibNet, and LCCNet by exploring open-source models that are available online and compare our results with their corresponding research papers. Requirements for extracting these visual and measurable outputs involved tweaking source code, fine-tuning, training, validation, and testing of each of these frameworks for equal comparisons. This approach aims to investigate which of these advanced networks produces the most accurate and consistent predictions. Through a series of experiments, we reveal some of their shortcomings and areas for potential improvements. We find that LCCNet yields the best results among all the models that we validated.
Karramreddy, Venkat Sai RaxitMitchell, Liam
Simulation plays a significant role in the validation and verification of Automated Driving Systems (ADS). In a scenario-based validation strategy, the road and the actions of the traffic participants must be captured in a portable and flexible format for simulation. XML-based parametric models constitute a common combination upon which the static and dynamic aspects of the environment are captured. Although there are plenty of tools for generating these XML files there are few alternatives to verify their content. This paper suggests a method for converting and simplifying a synthetic road network into a graph for which the Chinese Postman Problem is solved. The resulting sequence can be converted back into a route that can be sampled to verify the drivability of the whole network. Once the network is verified, it can be safely used for simulation, increasing the speed at which ADS systems are developed. The graph representation can also be used to provide interactive feedback to LLMs (Large Language Model), which are increasingly used for automatic generation of roads and scenarios.
Vargas Rivero, Jose RobertoKern, AndreasMenken, StefanHarth, MichaelKuipou, Franck Russel
This study addresses the challenges of communication delays and system stability in autonomous obstacle avoidance (AOA) systems under next-generation vehicular electronic/electrical architectures. A centralized PON-based architecture is proposed, leveraging XGSPON technology to enhance bandwidth capacity and reduce electromagnetic interference, while rigorously analyzing worst-case in-vehicle communication (IVOC) delays. To mitigate latency impacts, a Software-Defined Networking (SDN)-driven dynamic scheduling strategy prioritizes safety-critical data streams (e.g., environmental perception, motion control) through adaptive resource allocation. Further integrated with a robust H-infinity LQR controller, the co-design framework ensures precise trajectory tracking and suppresses steering oscillations under communication uncertainties. Simulation tests validate the framework's efficacy, demonstrating significant reductions in loop delays and improved dynamic stability in complex scenarios. This work bridges communication efficiency and control robustness, offering a scalable solution for advancing safety-critical autonomous driving systems.
Wang, WenweiHan, MuchenCao, Wanke
Safety of Automated Driving Systems (ADSs) is arguably one of the main remaining barriers before widespread market deployment. While there exists a plethora of methods for planning a trajectory that fulfils certain constraints, what those constraints should look like, to enable effective planning of safe trajectories, is still being discussed. In this article, we generalize the concept of Precautionary Safety (PCS) and present a framework providing constraints on the tactical and operational decisions of the ADS. Such constraints consider the ADS’ capabilities, the external conditions, knowledge of statistically relevant events and behaviors of other traffic actors, as well as the controllability of these events. The proposed framework enables assessment of the statistical fulfilment of quantitative risk acceptance criteria (QRACs), including requirements on accident, injury, and fatality rates. The framework further provides a means to dynamically adapt the constraints used for trajectory planning, i.e., to adapt the driving to the situation at hand. A case study, considering a possible collision scenario with a jaywalking pedestrian and a rear-end collision with a trailing vehicle, is provided to showcase the applicability and usefulness of the presented framework. The simulation-based case study displays the safety benefits from considering QRACs with multiple injury risk levels and further shows how the proposed PCS framework can be applied in practice.
Gyllenhammar, Magnusde Campos, Gabriel RodriguesSandblom, FredrikTörngren, MartinFredriksson, Jonas
The development and validation of advanced driver-assistance systems (ADAS) and automated driving systems (ADS) are shifting from traditional linear V-model processes toward more iterative engineering cycles. Despite faster iteration, these safety-critical systems remain subject to stringent regulations. Standards and guidance, including UNECE UN Regulation No. 157 and ISO/TS 5083, emphasize traceability, transparency, and explainability throughout development and validation. Nevertheless, as ADAS/ADS are developed and validated in faster, more iterative release cycles, additional stakeholders become involved and new explainability requirements emerge. These requirements vary between stakeholders and across development, validation, and post-market deployment phases, yet they are not systematically captured in the current state of research and practice. Therefore, to ensure that explainability supports rapid iteration, it is essential to identify relevant stakeholders and specify their explainability needs. Standards such as IEEE Standard 7001-2021 provide a broad foundation for transparency in autonomous systems. However, their generic nature does not address the domain-specific complexities of ADAS/ADS. Furthermore, a conceptual gap remains between general transparency principles and explainability requirements in automotive development and validation. Building on IEEE Standard 7001-2021, this paper first offers a stakeholder taxonomy in the context of ADAS/ADS, then proposes a stakeholder-oriented analysis of explainability requirements within an automated driving use case and contexts. This analysis specifically focuses on the motivations for requiring explainability and the necessary explanation modalities. Finally, the paper discusses the limitations of the analysis and outlines directions for future research. The results of the paper provide a structured guideline for stakeholder-oriented explainability requirements in ADAS/ADS.
Liu, XuanhengBairy, AkhilaPaudel, BijayAdolph, LaurenzHeck, MelanieHettich, LennardNägele, Ann-ThereseRudolf, KorbinianBause, KatharinaDüser, TobiasSchwammberger, Maike
This paper investigates the integration of Artificial Intelligence (AI) within radar-based perception for Advanced Driver Assistance Systems (ADAS) under safety considerations aligned with ISO 26262 [1] for functional safety and ISO 21448 (SOTIF) [2] for performance-related safety of the intended functionality. The study evaluates a hybrid architecture in which AI-based perception modules are combined with deterministic supervisory mechanisms to maintain safety compliance. A simulation-based case study using CARLA with radar sensor modeling is presented to compare a deterministic radar perception pipeline with an AI-enhanced approach under nominal and degraded environmental conditions. Performance is evaluated using precision, recall, and F1 score metrics. Results indicate improved recall and F1 score under adverse scenarios for the AI-based perception module, accompanied by a moderate increase in false positives. The paper discusses architectural constraints required to limit non-deterministic behavior, including confidence gating, deterministic supervision, and scenario-based validation. The findings are limited to simulation and are intended to provide preliminary insights into the technical and safety implications of incorporating AI-based radar perception within ISO 26262-compliant ADAS architectures.
Jain, Yesha
Rigorous validation of SAE Levels 3 and 4 autonomous systems increasingly relies on simulation. However, the simulation-reality gap remains a challenge for human-in-the-loop assessments. This study empirically quantifies the behavioral fidelity of the Car-Learning-to-Act (CARLA) simulator by recreating specific real-world traffic scenarios using the high-precision exiD drone dataset. Twenty-five participants performed a series of maneuvers, including lane changes and time-critical cut-ins. Their performance was analyzed using Dynamic Time Warping (DTW), driver profiling, and Time-to-Collision (TTC) metrics. The findings reveal a clear distinction between relative and absolute behavioral validity. In strategic decision-making tasks, the simulation demonstrated remarkably high temporal fidelity. DTW analysis explained 94% of the trajectory variance. Participants initiated lane changes with an average lag of -9 frames (0.36 s) compared to naturalistic references. These results indicate that, despite the absence of peripheral optical flow, the simulator successfully elicits temporally correlated decision-making patterns suitable for assessing strategic driver intent. However, physical execution in reactive scenarios revealed significant absolute discrepancies. Although the high Pearson correlation (r ≈ 0.89) in velocity profiles proves that drivers recognize and react to hazards with realistic timing, their physical inputs were exaggerated. Participants displayed digital, over-modulated braking responses and maintained a negative safety bias of -11.26 m, a deviation attributed to the lack of vestibular g-force feedback and geometric minification. Furthermore, distinct driver profiles emerged. Risk-oriented participants exhibited a gaming effect by neglecting safety margins. In conclusion, while CARLA is highly valid for testing the temporal logic of driver interactions, absolute dynamics require calibration functions, such as force-feedback (pedal) tuning and visual deceleration cues like camera shake, to compensate for sensory limitations before it can be used for safety-critical validation.
Rebling, PatrickAlphan, MetehanNenninger, Philipp
Level-3 and higher automated driving systems require longitudinal speed strategies that remain consistent with both physical stopping feasibility and realistic sensing constraints. This paper presents a route-based, sensor-aware speed planning method that supports safety validation and explicitly couples longitudinal driving strategy with sensor field-of-view coverage. Based on a concrete route extracted from digital maps and enriched with fleet data, point-wise maximum speeds are computed considering road curvature, speed limits, and comfort constraints. From the resulting drivable speed profile, physically consistent stopping paths and their endpoints are calculated for each route position, accounting for friction limits, scenario-dependent deceleration capabilities, and system delays between perception and braking. The set of stopping paths is aggregated into a region of interest (ROI) representing the spatial area that must be reliably perceived to guarantee safe stopping. This ROI is overlaid with the geometric fields of view of camera, radar, and lidar sensors, enabling the definition of a compact and interpretable key performance indicator (KPI) based on the number of sensor modalities covering critical regions. Rather than evaluating a specific sensor configuration, the proposed KPI establishes a geometric interface between braking-based perception requirements and multi-modal sensing coverage. The approach reveals the structural sensitivity of perception demands to route geometry and braking assumptions and provides a systematic basis for perception-aware speed release decisions. The method is applicable to highways, interchanges, and other route types, and contributes a modular geometric framework for sensor-aware safety analysis in Level-3 and higher automated driving systems.
Kohler, Paul LeonhardResch, Michael
As automation advances and occupants transition from active drivers to passive passengers, understanding how automated driving behavior is evaluated becomes increasingly important. While longitudinal and lateral vehicle dynamics are known to influence perceived comfort and safety, it remains unclear to what extent motion–perception relationships remain stable across urban traffic contexts. This study compares two real-world investigations of automated driving: a left-turn maneuver at a signalized intersection on a test track and a roundabout maneuver with a shuttle in public traffic. Both datasets include high-resolution vehicle dynamics and structured subjective ratings. A consistent objectification approach was applied to examine the transferability of motion–perception relationships across contexts. However, differences in vehicle platform, automation level, trajectory characteristics, and study design limit direct comparability and require cautious interpretation. Despite partially overlapping ranges in selected peak-based dynamic parameters, such as longitudinal acceleration, subjective comfort and safety ratings were consistently higher in the roundabout scenario. Furthermore, strong associations were observed between motion parameters and subjective evaluations in the intersection context (adj. R2 up to 0.891), whereas objective parameters showed only limited explanatory power in the roundabout scenario (adj. R2 ≤ 0.06). The results indicate that motion–perception relationships derived within a specific context may not be directly transferable across different traffic scenarios. The findings highlight limitations of globally derived motion-based evaluation models and underline the importance of validating objectification approaches across diverse operational environments.
Panzer, AnnaStrenge, EmmaIatropoulos, JannesHenze, Roman
This article presents a data-driven pipeline for autonomous-vehicle (AV) safety testing. The pipeline integrates real-world traffic observations with model-guided scenario expansion and safety-metric evaluation to enable an end-to-end AV safety testing framework, demonstrated on a canonical highway scenario. The framework enhances test diversity, realism, and coverage by generating statistically informed variants of observed driving behaviors. Key parameters such as vehicle speed, trajectories, and headways are extracted from naturalistic data and used to train a probabilistic model of traffic dynamics. Scenario variants are sampled from this model and encoded as behavior trees (BTs) for modular, simulation-ready execution. Each scenario is simulated using a consistent AV control configuration, and safety metrics such as minimum safe distance violation, minimum safe distance factor, time to collision, and aggressive driving are applied to evaluate safety outcomes independently of system-specific tuning. A case study based on the highD dataset (110,000+ trajectories) demonstrates the framework’s ability to generate realistic and safety-relevant scenarios, providing an initial demonstration of pipeline feasibility and metric-based evaluation. This initial study is intentionally scoped to a single scenario class and a simplified parametric model to isolate and validate the end-to-end integration of the pipeline.
Elshenawy, MohamedAboudina, AyaAbdelmotaleb, AnharAmr, MariamEl-darieby, Mohamed
This article presents a cross-layer framework that integrates realistic vehicle-to-network-to-vehicle (V2N2V) delay characterization with a rigorous stability analysis of automated vehicle steering control. Both constant and network-induced time-varying delays modeled via deterministic bounds are addressed. For constant delays, delay-independent stability regions within the controller gain space are analytically derived. For time-varying delays with stochastic network origins, modeled using deterministic bounds, a refined Lyapunov–Krasovskii functional (LKF) incorporating augmented single- and double-integral terms is constructed. To establish delay-dependent linear matrix inequality (LMI) conditions, a reciprocally convex combination approach is employed to handle the delay interval partitioning, and the second-order Bessel–Legendre inequality is applied to tighten the integral quadratic bounds. The resulting LMI conditions explicitly capture the coupled effects of delay magnitude, delay variation rate, and control gains on closed-loop stability. Simulations of a lane-keeping scenario confirm that the predicted stability boundaries accurately match the closed-loop system behavior. Notably, incorporating a realistic time-varying V2N2V delay profile into the controller design reduces the lateral-state root-mean-square error (RMSE) by over 54% and decreases the settling time by a factor of 10 compared to designs relying on an average-delay assumption. However, high packet loss rates are shown to still induce residual oscillations due to information scarcity. Ultimately, these results elucidate delay-induced instability mechanisms and provide practical guidelines for designing delay-robust steering controllers for connected and automated vehicles.
Li, JialinLu, JianweiWei, HengAo, Di
Framing Rules of the Road Compliance for Driving Automation Systems from an Engineering StandpointDRRC-WP-01-20266/18/2026
Rules of the road were created to enable safe, predictable, and efficient road use by governing both individual vehicle operation and interactions among road users. Driving automation systems must be capable of complying with rules of the road to operate lawfully on public roads. Human drivers often rely on simplified guidance, such as state driver’s handbooks, together with tacit knowledge developed through experience and social norms to generalize behavior across jurisdictions. By contrast, driving automation systems must reasonably and explicitly account for the substantial volume of applicable legal requirements within its operational design domain (ODD). Accordingly, relevant legal requirements must be converted into explicit objective logic that can be utilized by driving automation systems. This paper proposes a method to address how driving behavior-related rules of the road can be consistently applied in engineering practice in a harmonized fashion across industry. Specifically, while rules of the road are expressed in natural language—often with subjective and context-dependent terms—driving automation systems require those rules to be interpreted and translated into unambiguous, testable engineering requirements. To address this, this white paper articulates key challenges and outlines systems-engineering approaches for engineering interpretation of rules of the road and their translation into objective requirements suitable for verification. Validation is also discussed as the process for ensuring that the requirements themselves remain appropriate over time.
Digital Road Rules Consortium
Trajectory tracking control is a core technology in intelligent vehicle autonomous driving systems, directly influencing both driving safety and control accuracy. To overcome the limitations of traditional model predictive control (MPC) in real-time performance under complex operating conditions, as well as the limited robustness of linear quadratic regulators (LQR) against system uncertainties, this article proposes a hybrid iterative LQR–MPC (ILQR-MPC) control strategy. First, a dynamic model of the intelligent vehicle is developed to capture its behavior during high-speed driving and cornering. Next, an ILQR-MPC hybrid framework is designed. By exploiting the rapid iterative optimization capabilities of the ILQR algorithm, an initial control sequence is generated for the MPC, thereby reducing the computational load during MPC’s online rolling-horizon optimization. This approach preserves MPC’s advantages in handling constraints and maintaining robustness against parameter variations and external disturbances. Finally, joint simulations using MATLAB/Simulink and CarSim are conducted to evaluate the proposed approach against conventional MPC under standard road conditions, curved sections, and sudden changes in road friction. The results show that the ILQR-MPC strategy reduces trajectory tracking errors, shortens computational time, and maintains excellent stability and robustness under complex operating conditions.
Lai, FeiSun, JunhaoHuang, Chaoqun
Identifying driving heterogeneity is critical for enhancing the strategy learning capabilities of autonomous driving systems, as well as improving their safety and efficiency. This research proposes a novel driving heterogeneity identification framework. The framework consists of three core processes: action phase extraction, action relationship modeling, and behavior heterogeneity identification. First, a rule-based segmentation method is employed to systematically decode and interpret the inherent variations in human driving behavior. Subsequently, an action relationship modeling method is introduced to characterize the temporal relations between the acquired action phases. Finally, to mitigate the inaccurate identification caused by the sparse distribution of critical driving events in long-sequence data, a semantic encoding method is applied to remap the driving behavior space. Experimental results on the Lyft level-5 dataset validate the effectiveness of the proposed framework, which outperforms multiple traditional clustering algorithms. This demonstrates its significant potential to enhance behavior detection and learning in personalized advanced driver-assistance systems (ADAS) and advanced autonomous vehicle (AV) design.
Yin, HuiZhang, QinyaoLi, XiaojianMo, Hangjie
Autonomous vehicles exhibit extremely strong nonlinearity during drift. However, existing autonomous drift algorithms often neglect previewed path curvature and offer only limited consideration of road surface uncertainty because of the influence of vehicle nonlinear dynamics, which can affect tracking accuracy and robustness of drift control. To solve these problems, this study proposes a robust optimal drift control framework based on curvature preview. First, a preview vehicle kinematic model is constructed, and a preview model predictive control path-tracking controller that considers the forthcoming curvature is designed. Through the analysis of equilibrium points with additional yaw moment, a robust optimal drift controller is developed, which employs a three-degrees-of-freedom vehicle model with an additional yaw moment. This controller adopts integral sliding mode control with a super-twisting algorithm (STA) and exhibits good stability, which is verified through Lyapunov analysis. The proposed control algorithm is validated through hardware-in-the-loop experiments. The experimental results demonstrate that the proposed method significantly improves path-tracking accuracy and robustness under uncertain road surface conditions, thereby providing an effective control solution for drift-based path-tracking maneuvers.
Gan, YurunSong, ZiyuGu, TongtongDing, HaitaoXu, NanZhang, Jianwei
Previous rear-facing post-mortem human subject (PMHS) studies utilizing a reinforced seat have prompted questions as to whether the seat could have been a contributing factor to the severe rib and pelvis injuries observed in those experiments. In response, a recent PMHS study used an unreinforced seat in a similar experiment, which was expected to mitigate severe injuries by dissipating energy from seatback deformations. However, the PMHS tested in the unreinforced seat sustained even more severe rib fracture numbers than in the reinforced seat. No studies have investigated how additional variables (i.e., countermeasures) may influence rib fractures in high-speed rear-facing frontal impacts (HSRFFI). Therefore, this study aimed to explore the effect of an airbag-equipped seat (AES) on male PMHS responses and injuries. Rear-facing sled tests were conducted using five mid-size male PMHS seated in the AES at ΔV of 56 km/h: PMHS1 with no airbag as a baseline, PMHS2 with a seatback airbag (SA), PMHS3 with an extended seatback airbag (ESA), and PMHS4 and 5 with ESA and a wedge airbag (ESA+WA). An instrument panel (IP) and windshield were installed behind the seat to mimic realistic interior vehicle compartments. A chestband at mid-sternum, 6-degree motion blocks at the head, T1, T4, T8, T12, pelvis, and extremities, as well as rib strain gages and rosettes were installed on PMHS to understand potential mechanisms of injuries. A motion capture system was used to quantify whole-body PMHS and seatback kinematics. Maximum seatback rotation was 38.1° in the baseline test and 20.3°–25.1° with AES. Peak chest A-P compression in the anterior-posterior (A-P) direction was 25.7 mm for baseline and 7.3 mm–35.2 mm with AES (23.7 mm for SA, 7.3 mm for ESA, 35.2 and 8.7 mm for ESA+WA). The number of rib fractures (NRF) was high in baseline (32), SA (25), and ESA (27) conditions, but was reduced in ESA+WA (6 and 13). Strain rosette data indicated upward directions of principal strains on the posterior ribs, likely due to I-S deformation of the PMHS thoraces. Responses from thorax instrumentation showed that peak chest deflection (A-P) alone did not fully explain NRF, especially as rib fractures in all tests occurred after peak deflection in this direction. Instead, maximum principal strains in the I-S direction (shear), confirmed by strain rosette data, likely influenced rib fractures. ESA+WA effectively supported PMHS, maintaining upright postures and minimizing I-S chest shear, which reduced NRF. Limitations include a small sample size, possible age-related injury effects, and seat designs intended for low-speed rear impacts, not HSRFFI. Compression and shear loading to the PMHS thoraces were observed in HSRFFI. The shear loading was likely due to the large upward thorax deflection induced by the ramping motion and seatback rotation. One of the AES, ESA+WA, effectively maintained an upright spine and reduced NRF. This study offers important information for improving current safety tools and designing rear-facing countermeasures for automated driving systems.
Kang, Yun-SeokDeWitt, TimothyWensink, TimothyMarcallini, AngeloJung, Yong HyunLee, Dong GilHarm, Jae JunKo, SeokhoonHunter, RandeeAgnew, Amanda M.
Vehicle maneuver data are essential for perception and planning in advanced driver-assistance systems (ADAS) and automated driving systems (ADS). While high-quality annotations improve machine-learning performance, existing maneuver datasets remain fragmented, labor-intensive to annotate, and inconsistent in semantic richness. Challenges persist in scalability, interpretability, and contextual labeling. This article establishes a structured framework for maneuver data analysis by combining a systematic review of existing resources with the development of a new multimodal dataset. First, we conduct a systematic review of publicly available datasets such as HDD, KITTI, BDD-X, D2CAV, Brain4Cars, DrivingDojo, and the Driving Behavior Database. We further evaluate the data modality and sensor configurations including event data recorders, onboard logging systems, and smartphone sensing. We then propose the Matt3r Data Collection System with modern metadata management, which integrates video, GPS, and IMU signals into temporally coherent clips. Next, we outline the limitations of traditional annotation approaches, which rely on manual labeling and rule-based methods. To address the limitations of traditional manual and semi-automated labeling, we propose a Vision–Language Model (VLM)–driven annotation pipeline. VLMs generate maneuver categories and causal explanations through prompt-based reasoning, with selected outputs refined through human-in-the-loop verification. Finally, we propose an annotation quality evaluation based on accuracy, inter-annotator agreement, credibility, consistency, and efficiency gain. In summary, this article bridges the gap between the environment perception requirements of existing ADAS and ADS systems and the developing capabilities of generative artificial intelligence. By providing a novel and scalable research approach for AI-driven maneuver data annotation and analysis, this article supports data engineering efforts for both research and practical applications aimed at enhancing vehicle safety.
Bai, LingYuan, ChongyuOsman, IslamLin, ZiruiMirab, GhazalSaheb, AmirParnian, NedaShapiro, EvgenyShehata, Mohamed S.Liu, Zheng
Vehicles equipped with an Automated Driving System (ADS) have the potential to significantly reduce road collisions. To enable widespread adoption of ADSs, rigorous safety assessment is essential. Valuable insights for ADS safety validation can be gained by simulating scenarios across a broad range of feature variations. A common challenge in simulating these scenarios is known as the curse of dimensionality, where increasing the number of scenario features requires a near-infinite number of simulations to cover all variations. This issue of complexity presents a need for reducing scenario features. Most related work focuses on identifying important scenario features, while few evaluate how reducing these features impacts ADS failure estimation. The present study aims to address this gap by employing a wide range of feature reduction methods and assessing their effect on ADS failure estimation. Previous research generated datasets for three distinct scenario categories by performing virtual simulations using driver reference models on real-world data. In the present work, the machine learning classifiers such as extreme gradient boosting and random forest are applied to this data for predicting ADS failures. Ten dimensionality reduction techniques, including both feature selection and transformation approaches, are employed to reduce the scenario feature set. The optimal reduced feature set is selected based on classification performance measured by the area under the precision–recall curve. To assess the impact on ADS failure estimation, results are compared against those obtained with the full set of features. The findings indicate that reliable ADS failure estimates can be maintained, and even significantly improved, after substantially reducing the number of scenario features. By reducing scenario features, fewer virtual simulations may be required to reliably estimate ADS failures, which may enable more efficient scenario-based ADS safety assessment. Additionally, this study may offer guidance on selecting suitable dimensionality reduction techniques for scenario-based ADS safety assessment.
Lankhorst, Bramde Gelder, ErwinJanssen, Christian P.Scholich, Andre
SAE TOMORROW TODAY - Building Trust in AV Safety135644/17/2026
As AVs continue to grow in popularity, one question remains top of mind: How do we know autonomous driving systems are genuinely safe? The Automated Vehicle Safety Consortium (AVSC) is an industry collaboration group focused on improving the safe development and deployment of automated driving systems (ADS). By bringing together automakers, technology companies, suppliers, mobility providers, and government stakeholders, the AVSC develops voluntary best practices and technical guidance that fosters public trust and delivers consistent AV safety standards. Listen in as we sit down with Darcyne Foldenauer, Executive Director, AVSC, and Erin McCurry, Principal Engineer, AVSC, to explore two new publications: Best Practice for ADS-DV Assessment of Safety Claims, and the Information Report on ADS-DV Stopped Conditions. From the difference between minimal risk maneuvers and minimal risk conditions, to when it's actually safer for a vehicle to stay stopped in lane, this conversation sheds light on the complex decisions behind automated driving safety. We'd love to hear from you. Share your comments, questions and ideas for future topics and guests to podcast@sae.org. Don't forget to take a moment to follow SAE Tomorrow Today--a podcast where we discuss emerging technology and trends in mobility with the leaders, innovators and strategists making it all happen--and give us a review on your preferred podcasting platform. Follow SAE on LinkedIn, Instagram, Facebook, X, and YouTube. Follow host Grayson Brulte on LinkedIn, X, and Instagram.
Patterson, Lori
Precision control in Level 4 Automated Vehicles is essential for enhancing operational efficiency, accuracy, and safety. This work, conducted as part of ARPA-E’s NEXTCAR program, focuses on developing a robust hardware and software control solution to enable drive-by-wire functionality. A previous publication by the authors presented the hardware solutions for overtaking stock vehicle controls. This paper focuses on a model-based and data-driven control algorithm to enable drive-by-wire functionality for longitudinal and lateral motion control for a 2021 Honda Clarity Plug-In Hybrid Electric Vehicle. This vehicle was equipped with a set of sensors and an onboard processing unit to enable Level 4 automation. For lateral controls, an algorithm was developed to command steering torque to the electronic power steering module, ensuring the vehicle could attain the desired steering angle position at varying speeds. The system leveraged feedforward and feedback mechanisms. Feedback controller gains were identified through frequency response analysis of the steering torque assist electric motor and were further refined during track testing. To optimize the controller’s response time, a feedforward function was developed using a physics-aware model of the vehicle's steering system. The independent feature selection for the model was guided by using the physics of the system. For longitudinal control, the control inputs included the positions of the brake and accelerator pedals sent to the stock ECU, with the desired speed as the setpoint. The setup used a combination of feedforward and feedback control to achieve the target acceleration or deceleration. These algorithms underwent extensive dynamometer and track testing to perform various maneuvers in conjunction with the automated driving system.
Adsule, KartikBhagdikar, PiyushDrallmeier, JosephAlden, JoshuaGankov, Stanislav
Vision-language models (VLMs) are increasingly used in autonomous driving because they combine visual perception with language-based reasoning, supporting more interpretable decision-making, yet their robustness to physical adversarial attacks, especially whether such attacks transfer across different VLM architectures, is not well understood and poses a practical risk when attackers do not know which model a vehicle uses. We address this gap with a systematic cross-architecture study of adversarial transferability in VLM-based driving, evaluating three representative architectures (Dolphins, OmniDrive, and LeapVAD) using physically realizable patches placed on roadside infrastructure in both crosswalk and highway scenarios. Our transfer-matrix evaluation shows high cross-architecture effectiveness, with transfer rates of 73–91% (mean TR = 0.815 for crosswalk and 0.833 for highway) and sustained frame-level manipulation over 64.7–79.4% of the critical decision window even when patches are not optimized for the target model. We further find asymmetric architecture-level risk, with Dolphins most vulnerable to incoming transfer attacks (VS = 0.82) and LeapVAD producing the most transferable patches (TO = 0.882), while models sharing CLIP-based vision encoders exhibit stronger bidirectional transfer. Overall, these results indicate that current VLM-based autonomous driving systems share systematic cross-architecture weaknesses that architectural diversity alone does not resolve, underscoring the need for defenses and design principles that explicitly account for transferability in safety-critical deployment.
Fernandez, DavidMohajerAnsari, PedramSalarpour, AmirPese, Mert D.
As Automated Driving Systems (ADS) technology advances, ensuring safety and public trust requires robust assurance frameworks, with safety cases emerging as a critical tool toward such a goal. This paper explores an approach to assess how a safety case is supported by its claims and evidence, toward establishing credibility for the overall case. Starting from a description of the building blocks of a safety case (claims, evidence, and optional format-dependent entries), this paper delves into the assessment of support of each claim through the provided evidence. Two domains of assessment are outlined for each claim: procedural support (formalizing process specification) and implementation support (demonstrating process application). Additionally, an assessment of evidence status is also undertaken, independently from the claims support. Scoring strategies and evaluation guidelines are provided, including detailed scoring tables for claim support and evidence status assessment. The paper further discusses governance, continual improvement, and timing considerations for safety case assessments. Reporting of results and findings is contextualized within its primary use for internal decision-making on continual improvement efforts. The presented approach builds on state of the art auditing practices, but specifically tackles the question of judging the credibility of a safety case. While not conclusive on its own, it provides a starting point toward a comprehensive "Case Credibility Assessment" (CCA), starting from the evaluation of the support for each claim (individually and in aggregate), as well as every piece of evidence provided. By delving into the technical intricacies of ADS safety cases, this work contributes to the ongoing discourse on safety assurance and aims to facilitate the responsible integration of ADS technology into society.
Schnelle, ScottFavaro, FrancescaFraade-Blanar, LauraBroce, HollandMiranda, JustinWichner, DavidShrivastava, Mohit
Introducing machine learning (ML) into safety-critical systems presents a fundamental challenge, as traditional safety analysis techniques often struggle to capture the dynamic, data-driven, and non-deterministic behavior of learning-enabled components. To address this gap, the Machine Learning Failure Mode and Effects Analysis (ML FMEA) methodology was developed as an open-source framework tailored to ML-specific risks. This paper reports on the maturation of ML FMEA from an initial conceptual framework to a proven, practice-driven methodology. We make four primary contributions. First, we extend the ML FMEA pipeline with two new stages: a “Step Zero” for problem definition and system-level hazard analysis, and a “Step 5” for constructing ground truth or reward signals. Autonomous vehicle and humanoid robot applications are presented to illustrate the practical application and safety benefits of these additions. Second, we introduce tailored Severity, Occurrence, and Detection criteria for ML risk assessment, resolving ambiguities encountered when applying traditional FMEA metrics to ML development processes. Third, we demonstrate systematic alignment between ML FMEA artifacts and requirements from ISO/PAS 8800, ISO 21448 (SOTIF), ISO/TS 5083, ISO/IEC TR 5469, and UL 4600, providing a bridge between ML development practices and safety certification expectations. Fourth, we present cross-industry perspectives spanning automotive, aerospace, industrial robotics, and defense, highlighting deployment pathways and best practices for domain-specific adaptation. Through open-source collaboration and cross-industry validation, the ML FMEA has matured into a practical toolset that enables safety-informed ML workflows, supporting auditable, repeatable, and risk-aware development of learning-enabled systems.
Schmitt, PaulShinde, ChaitanyaDiemert, SimonPennar, KrzysztofSeifert, BodoPoh, JustinLopez, JerryMannan, FahimMohammed, MajedChalana, AkshayWadhvana, NeilWagner, Michael
The concept of the vehicle has changed as a result of many innovations over the last decade in the fields of connected, autonomous/automated, shared, and electric (CASE) technologies. At the same time, labor shortages in Japan are becoming more serious due to a decline in the working population. To help resolve these issues, a remote-controlled autonomous vehicle driving system called Telemotion has been developed that automates the movement of vehicles in production plants. This system is an autonomous driving and transportation system in which the recognition, judgment, and operation functions of driving are handled by a control system outside the vehicle that communicates wirelessly with the vehicle. This system utilizes artificial intelligence (AI) and other advanced technologies to realize safe unmanned autonomous driving, and is already in operation in production plants. Currently, efforts are under way to build a digital twin environment and conduct AI learning using computer graphics (CG) to configure the system and improve the accuracy of the AI models with the aim of expanding its use to other factories. Within this digital twin environment, it is possible to examine previous tasks by reproducing the vehicles, processes, cameras, and vehicle movements present at a production site. Utilizing this digital twin enabled a significant reduction in the labor required to implement the system.
Hatano, YasuyoshiIwazaki, NoritsuguNagafuchi, YuheiIwahori, KentoTanaka, AtsushiUezu, SatoruKanou, TakeshiInoue, GoOkamoto, YukiOka, YuheiKakuma, DaisukeChiba, HiroyaEgashira, KazukiIshikuro, MegumiSawano, Takuro
Reliable off-road autonomy requires operational constraints so that behavior stays predictable and safe when soil strength is uncertain. This paper presents a runtime assurance safety monitor that collaborates with any planner and uses a Bekker-based cost model with bounded uncertainty. The monitor builds an upper confidence traversal cost from a lightweight pressure sinkage model identified in field tests and checks each planned motion against two limits: maximum sinkage and rollover margin. If the risk of crossing either limit is too high, the monitor switches to a certified fallback that reduces vehicle speed, increases standoff from soft ground, or stops on firmer soil. This separation lets the planner focus on efficiency while the monitor keeps the vehicle within clear safety limits on board. Wheel geometry, wheel load estimate, and a soil raster serve as inputs, which tie safety directly to vehicle design and let the monitor set clear limits on speed, curvature, and stopping at run time. The method carries uncertainty analytically into the upper confidence cost and applies simple intervention rules. Tuning of the sinkage limit, rollover margin, and risk window trades efficiency for caution while keeping the monitor light enough for embedded processors. Results from a simulation environment spanning loam to sand include intervention rates, violation probability, and path efficiency relative to the nominal plan, and a benchtop static loading check provides initial empirical validation.
Naik, AkshayNorris, WilliamSreenivas, Ramavarapu S.Soylemezoglu, AhmetNottage, Dustin S.Patterson, Albert
Although SAE Level 2 Advanced Driver Assistance Systems (ADAS) and Automated Driving Systems (ADS) have been shown to provide some safety benefits, they have largely been constrained to specific driving contexts, namely motorways for ADAS and lower speed roadways for ADS. As more advanced systems are entering the roadways and their operating conditions are expanding, it remains an ongoing challenge to assess the safe operation of vehicles with automation in different roadway contexts and leverage lessons learned from real-world incidents to create safer and more robust systems. As of August 2025, NHTSA’s Standing General Order on Crash Reporting offers systematic data on such incidents, providing at least a cursory overview of where and how they occur. From this source, a total of 1,375 crash records were extracted, 657 for ADAS systems and 715 for ADS systems. Through the application of association rule mining and a novel metric termed influence, patterns in ADAS- and ADS-related crashes were examined within different roadway contexts. In general, it was found that subject vehicle and crash partner pre-crash movements as well as collision types were some of the most distinguishing factors between the two systems used. Differences in context specific rule summations also indicate distinct crash factor combinations between the two systems. The results offer an initial, exploratory perspective on the impact of vehicle automation on public roadways, providing insights that can inform system-specific safety assessments, risk mitigation strategies, and future research into the evolving dynamics of automated driving technologies.
Astle, W. AbramHaus, Samantha
Accurate perception of the surrounding environment is fundamental and essential to safe and reliable autonomous driving. This work presents an integrated vision-based framework that com bines object detection, 3D spatial localization, and lane segmentation to construct a unified bird’s-eye-view (BEV) representation of the driving scene. The pipeline provides geometric information on object position and orientation by employing Omni3D to infer 3D bounding boxes of objects from monocular camera frames. Detections are subsequently projected onto a 2D BEV canvas, where object instances are represented with respect to the ground plane for enhanced interpretability. To complement the object-level perception, we utilized YOLOPv2 to perform lane segmentation, producing both lane masks and lane line masks in the image domain for future coordinate transformation. By adopting a pinhole camera model, the coordinate transformation of these masks from the perspective image plane into the BEV canvas can be performed. The fusion of 3D object detections and geometrically transformed lane representations yields a coherent and structured spatial map of the vehicle’s surroundings. In addition, the BEV space is integrated into a local 2D map generated from Mapbox tool. This unified environment model enables explicit reasoning about drivable space and surrounding obstacles, facilitating its integration into downstream modules such as path planning and trajectory prediction. The framework demonstrates the feasibility of leveraging recent advances in monocular 3D perception and deep learning-based lane segmentation to construct a computationally efficient and semantically rich BEV representation, which is a potential core perception component in real-time autonomous driving systems.
Tan, LinArjmanzdadeh, ZibaWang, HanchenLi, TaozheHajnorouzali, YasamanBurch, CollinLee, VictoriaXu, Bin
Ensuring the safety of Vulnerable Road Users (VRUs) is a critical challenge in the development of advanced autonomous driving systems in smart cities. Among vulnerable road users, bicyclists present unique characteristics that make their safety both critical and also manageable. Vehicles often travel at significantly higher relative speeds when interacting with bicyclists as compared to their interactions with pedestrians which makes collision avoidance system design for bicyclist safety more challenging. Yet, bicyclist movements are generally more predictable and governed by clear traffic rules as compared to the sudden and sometimes erratic pedestrian motion, offering opportunities for model-based control strategies. To address bicyclist safety in complex traffic environments, this study proposes and develops a High-Order Control Lyapunov Function–High-Order Control Barrier Function–Quadratic Programming (HOCLF-HOCBF-QP) control framework. Through this framework, CLFs constraints guarantee system stability so that the vehicle can track its reference trajectory, whereas CBFs constraints ensure system safety by letting vehicle avoiding potential collisions region with surrounding obstacles. Then by solving a QP problem, an optimal control command that simultaneously satisfies stability and safety requirements can be calculated. Three key bicyclist crash scenarios recorded in the Fatality Analysis Reporting System (FARS) are recreated and used to comprehensively evaluate the proposed autonomous driving bicyclist safety control strategy in a simulation study. Simulation results demonstrate that the HOCLF-HOCBF-QP controller can help the vehicle perform robust, and collision-free maneuvers, highlighting its potential for improving bicyclist safety in complex traffic environments.
Chen, HaochongCao, XinchengGuvenc, LeventAksun Guvenc, Bilin
Safety isn’t just the absence of accidents - it’s the presence of trust, empowerment, and accountability at every level. The result is a high-trust culture where process becomes practice and safety is a shared achievement. When people closest to the work feel supported to act on what they see, safety becomes the standard. Thus, the deployment of autonomous driving systems (ADSs) requires not only technical rigor but also a resilient organizational safety culture that supports continuous learning, accountability, and transparent communication. This paper examines how safety culture can be operationalized in ADS development and operations by integrating guidance from standards such as UL 4600 and best practices from SAE AVSC. UL 4600’s requirements for systematic hazard analysis, safety case maintenance, and safety performance indicators (SPIs) are used as a foundation for quantifying organizational behavior within a Just Culture framework. This work draws on Human and Organizational Performance (HOP) research, including foundational contributions from Hollnagel, Reason, Dekker, Conklin, and Rasmussen, linking cultural dynamics to workforce involvement and effective safety controls. We propose a taxonomy of seven safety-culture SPIs that trace directly to UL 4600 § 16.2.5 and demonstrate how they can be deployed within an incident-handling process. Each SPI is defined mathematically and mapped to process steps, enabling both leading- and lagging-indicator assessment of safety culture maturity. This proposed framework, which requires formal research validation, transforms SPIs from compliance metrics into qualitative diagnostic tools for trust, empowerment, and system learning. The approach aligns organizational processes with Just Culture principles, distinguishing human error, at-risk behavior, and reckless conduct, while supporting continuous improvement and evidence-based conformance with UL 4600 and related ADS safety standards.
Wagner, MichaelGittleman, Michele
Rapidly upcoming deployment of autonomous vehicles (AVs), including robotaxis and trucks, has intensified the need for rigorous safety assessment of complex AI-driven systems. While considerable effort has been invested in constructing safety cases for AVs, systematic approaches for evaluating these safety cases remain underdeveloped. This paper presents a three-stage methodology for assessing AV safety cases. A process for assessing argumentation is presented that involves traceability to pre-reviewed and peer-reviewed safety cases such as the Open Autonomy Safety Case (OASC). Next, we present a structured process for evaluating the quality of evidence supporting these arguments. We applied this methodology to evaluate safety cases from multiple AV developers, enabling iterative refinement throughout the development lifecycle. Our agile approach supports efficient assessments by establishing clear traceability to industry standards and enabling early identification of potential gaps. This work provides regulators, operators, and developers with a practical framework for systematically evaluating AV safety cases and identifies lessons learned and areas for continued improvement.
Wagner, Michael
Reliable environmental perception under adverse and contaminated conditions is a critical requirement for autonomous driving systems. Although LiDAR sensors play a central role in such perception, their performance is significantly degraded by surface contamination caused by environmental factors such as rain, snow, dust, anti-icing materials, and bug splatter impacts. However, most existing public datasets and prior studies rely on simulated or laboratory-generated contamination scenarios, which limit their applicability to real-world autonomous driving. To address this gap, we construct a large-scale real-world dataset collected from approximately 22,000 km of on-road driving across diverse regions of the United States, covering a wide range of naturally occurring environmental contamination conditions. The dataset was acquired using a multimodal sensing platform integrating LiDAR, perception RGB cameras, infrared camera sensors, and external monitoring systems, enabling comprehensive observation of sensor behavior under realistic operating environments. Based on this dataset, we propose a scalable contaminant classification framework that focuses on LiDAR surface contamination. A key contribution of this study is the introduction and exploitation of near-field point cloud features, which capture backscattered laser signals caused by surface contamination and exhibit a strong correlation with contamination severity and type. Using raw LiDAR signals, we utilize sixteen feature functions and train supervised learning models to classify seven distinct contaminant categories. Experimental results demonstrate that the proposed approach achieves classification accuracy exceeding 95% under real-world driving conditions, significantly outperforming prior laboratory-based studies. Furthermore, the framework is designed for practical deployment and can be extended to additional contaminant types and geographic regions through incremental data collection and learning. The proposed methodology enables real-time identification of LiDAR contamination sources, providing a critical foundation for adaptive sensor-cleaning strategies. By supporting contamination-aware sensor maintenance, this work contributes to cost- and weight-efficient sensor system design and represents an essential step toward achieving reliable Level 4 autonomous driving.
Kim, Hunjae
Automated Driving Systems (ADS) rely on AI algorithms, machine learning, and sensor fusion to perform autonomous driving tasks. Safety challenges arise due to the probabilistic behavior of AI/ML algorithms and the need to ensure safety within defined Operational Design Domains (ODDs). Traditional standards such as ISO 26262[3] (Functional Safety) and ISO 21448[4] (SOTIF) address hardware and software failures or functional deficiencies but are insufficient for higher-level autonomous systems (SAE Levels 3–5). To close this gap, additional standards such as UL 4600[1] and ISO 5083[2] provide complementary frameworks for ADS safety assurance. UL 4600[1] establishes a claim-based safety case encompassing the vehicle, infrastructure, and processes, emphasizing structured arguments supported by evidence and reasoning. It offers guidance on autonomy functions, V & V, tool qualification, dependability, and safety culture. ISO 5083[2] focuses on design, verification, and validation of ADS, extending safety lifecycles with system-level principles, risk criteria, and validation metrics. It defines the ADS safety case as proof of acceptable safety for specific features and environments, stressing safety-by-design, layered verification, and post-deployment monitoring, including cybersecurity. Together, UL 4600[1] and ISO 5083[2] enable a unified approach to safety assurance, aligning with Functional Safety and SOTIF principles. Their integration helps manufacturers evaluate ADS systematically, demonstrate risk acceptance, and maintain safety throughout the lifecycle.
Mudunuri, Venkateswara RajuAlmasri, HossamFan, Hsing-Hua
The intersection of Safety of Intended Functionality (SOTIF) and Functional Safety (FuSa) analysis of driving automation features has traditionally excluded Quality Management (QM) components from rigorous safety impact evaluations. While QM components are not typically classified as safety-relevant, recent developments in artificial intelligence (AI) integration reveal that such components can contribute to SOTIF-related hazardous risks. Compliance with emerging AI safety standards, such as ISO/PAS 8800, necessitates re-evaluating safety considerations for these components. This paper examines the necessity of conducting holistic safety analysis and risk assessment on AI components, emphasizing their potential to introduce hazards with the capacity to violate risk acceptance criteria when deployed in safety-critical driving systems, particularly in perception algorithms. Using case studies, we demonstrate how deficiencies in AI-driven perception systems can emerge even in QM-classified components, leading to unintended functional behaviors with critical safety implications. By bridging theoretical analysis with practical examples, this paper argues for the adoption of comprehensive FuSa, SOTIF, and AI standards-driven methodologies to identify and mitigate risks in AI components. The findings demonstrate the importance of revising existing safety frameworks to address the evolving challenges posed by AI, ensuring comprehensive safety assurance across all component classifications spanning multiple safety standards.
Abbaspour, Ali RezaMahadevan, ShabinZwirglmaier, KilianStafford, Jeff
Avoiding and mitigating any potential collision is dependent on (1) road user ability to avoid entering into a conflict (conflict avoidance effect) and (2) road user response should a conflict be entered (collision avoidance effect). This study examined the collision avoidance effect of the Waymo Driver, a currently deployed SAE level 4 automated driving system (ADS), using a human behavior reference model, designed to be representative of a human driver that is non-impaired, with eyes on the conflict (NIEON). Reliable performance benchmarking methodologies for assessing ADS performance are an essential component of determining system readiness. This consistently performing, always-attentive driver does not exist in the human population. Counterfactual simulations were run on responder collision scenarios based on reconstructions from a 10-year period of human fatal crashes from the Operational Design Domain of the Waymo ADS in Chandler, Arizona. Of 16 simulated conflicts entered, 12 (75%) were prevented by the Waymo Driver, and 10 (62.5%) were prevented by the NIEON model. The NIEON Model mitigated an additional 5 collisions and did not mitigate 1 collision. In these 16 conflicts entered, 93% of serious injury risk was reduced by the Waymo Driver, whereas 84% of serious injury risk was reduced by the NIEON model. Further, in a case-by-case evaluation, the Waymo Driver’s collision avoidance led to reduced serious injury risk when compared to the NIEON model in every simulated event. The results of this paper demonstrate that a reference model like NIEON can be used to benchmark ADS responder performance in response to high-risk initiating behaviors performed by the current driving population.
Scanlon, John M.Kusano, Kristofer D.Engstrom, JohanVictor, Trent
This paper describes Waymo's Collision Avoidance Testing (CAT) methodology: a scenario-based testing method that evaluates the safety of the Waymo Driver Automated Driving Systems' (ADS) intended functionality in conflict situations initiated by other road users that require urgent evasive maneuvers. Because SAE Level 4 ADS are responsible for the dynamic driving task (DDT), when engaged, without immediate human intervention, evaluating a Level 4 ADS using scenario-based testing is difficult due to the potentially infinite number of operational scenarios in which hazardous situations may unfold. To that end, in this paper we first describe the safety test objectives for the CAT methodology, including the collision and serious injury metrics and the reference behavior model representing a non-impaired eyes on conflict human driver used to form an acceptance criterion. Afterward, we introduce the process for identifying potentially hazardous situations from a combination of human data, ADS testing data, and expert knowledge about the product design and associated Operational Design Domain (ODD). The test allocation and execution strategy is presented next, which exclusively utilize simulations constructed from sensor data collected on a test track, real-world driving, or from simulated sensor data. The paper concludes with the presentation of results from applying CAT to the fully autonomous ride-hailing service that Waymo operates in San Francisco, California and Phoenix, Arizona. The iterative nature of scenario identification, combined with over ten years of experience of on-road testing, results in a scenario database that converges to a representative set of responder role scenarios for a given ODD. Using Waymo's virtual test platform, which is calibrated to data collected as part of many years of ADS development, the CAT methodology provides a robust and scalable safety evaluation.
Kusano, KristoferBeatty, KurtSchnelle, ScottFavaro, FrancescaCrary, CamVictor, Trent
This paper presents crash rate benchmarks for evaluating US-based automated driving systems (ADSs) for multiple urban areas, distinguishing between freeway and surface street crash rates, and breaking them down by crash severity and type. The purpose of this study was to extend prior benchmarks focused only on surface streets to additionally capture freeway crash risk for future ADS safety performance assessments. Using publicly available police-reported crash and vehicle miles traveled (VMT) data from Arizona, California, Georgia, and Texas, the methodology details the isolation of in-transport passenger vehicles, road type classification, and crash typology. Key findings revealed that freeway crash rates exhibit large geographic dependence variations with any-injury-reported crash rates being approximately three times higher in Atlanta (2.3 IPMM; the highest) when compared to San Diego (0.7 IPMM; the lowest). The results show the critical need for location-specific benchmarks to avoid biased safety evaluations and provide insights into the VMT required to achieve statistical significance for various safety impact levels. The distribution of crash types depended on the outcome severity level. Higher severity outcomes (e.g., fatal crashes) had a larger proportion of single-vehicle, vulnerable road users (VRUs) and opposite-direction collisions compared to lower severity (police-reported) crashes. Given heterogeneity in crash types by severity, performance in low-severity scenarios may not be predictive of high-severity outcomes. These benchmarks are additionally used to quantify at the required mileage to show statistically significant deviations from human performance. Future work investigating the underlying factors influencing crash rates in each geographical area will further enhance future benchmarking efforts (by identifying potential confounders to account for when matching exposure between baseline and ADS data). This is the first paper to generate freeway-specific benchmarks for ADS evaluation and provides a foundational framework for future ADS benchmarking by evaluators and developers.
Scanlon, John M.McMurry, Timothy L.Chen, Yin-HsiuKusano, Kristofer D.Victor, Trent
Automotive Engineering: March 202626AUTP033/12/2026
Mercedes unveils S-Class amidst celebrating 140 years Classic design with the latest tech. Faraday Future says new robot business not a pivot, but a plus At NADA, Faraday Future introduced the FF Futurist, FF Master and FX Aegis, robots that it hopes to sell with the help of, among other things, auto dealerships. How higher-quality gasoline keeps modern engines clean and efficient Gasoline direct injection (GDI) engines are the most common technology on American roadways in 2025, and soon, an industrywide gasoline quality standard will better reflect their unique operational needs. Mobility for All with Christopher Borroni-Bird How can we make vehicles more sustainable for those who can afford to buy a new car, and how can we make mobility more affordable for the remaining 90%? Editorial Politics hits engineering, but harder Supplier Eye Feast, then famine Riding Along with Mercedes and its in-city driver assistance system Microvision acquires Luminar, plans relationship restoration, multi-industry push Startup Neumo says it can detect impaired drivers by scanning brain waves Sony Honda Afeela Prototype 2026 was the easier engineering challenge Mobileye, VW gearing up for 100,000 AVs by 2033 Aumovio's remote temp sensor far more accurate for e-mobility First Drive: 2027 Mercedes-Benz CLA Hybrid Kia makes minor updates to 2026 Sportage Hybrid, wringing out five more hp First Drive: Drifting in the electric 2027 Mercedes GLC 400 Product Briefs Spotlight: Analysis tools, sensors Q&A GM's Barra: EVs are still the future
This article presents an eco-driving algorithm for electric vehicles featuring multi-speed transmissions. The proposed controller is formulated as a co-optimization problem, simultaneously optimizing both vehicle longitudinal speed and powertrain operation to maximize energy efficiency. Constraints derived from a connected vehicle–based traffic prediction algorithm are used to ensure traffic safety and smooth traffic flow in dynamic environments with multiple signalized intersections and mixed traffic. By simplifying the complex, nonlinear mixed-integer problem, the proposed controller achieves computational efficiency, enabling real-time implementation. To evaluate its performance, traffic scenarios from both Simulation of Urban MObility (SUMO) and real-world road tests are employed. The results demonstrate a notable reduction in energy consumption by up to 11.36% over an 18 km drive.
He, SuiyiSun, Zongxuan
ADS-DVs promise to expand transportation options for individuals who have been historically underserved in personal transportation. However, for this to be truly realized, the unique needs of persons with disabilities (PWDs; including those who are deaf and hard of hearing, blind, have low vision, have upper body limitations, have lower body limitations, are wheelchair users, and have cognitive disabilities) should be understood at the design stage of vehicle development. This document presents a list of recommendations for use in the design and development of ADS-DVs based on the identified needs of PWDs. It considers the accessibility of services used to interact with the ADS-DV before the trip and the complete trip (including planning the trip and requesting the vehicle, determining a pickup location, finding the vehicle, authenticating the user, entering the vehicle, interacting with the vehicle while inside, determining a drop-off location, exiting the vehicle, and finding the destination). The presented recommendations attempt to address most disabilities and enable independent travel. However, it is understood that certain populations may not be included due to technical or other limitations. The focus is on those who are willing and able to travel independently. Additionally, while some accessibility recommendations can benefit everyone, it is worth acknowledging that some may involve trade-offs among individuals or groups. Although this document does not explicitly address such trade-offs, they should be considered when applying any of the presented recommendations.
On-Road Automated Driving (ORAD) Committee
Treat foundational AV safety like seatbelts - make it non-proprietary and universal. An open safety stack, shared scenarios, benchmarks, and core validation tools can speed certification, reduce duplicated V&V and build public trust while preserving vendor differentiation. The bottleneck isn't compute - it's verification. Autonomous features are shipping in more vehicles and markets, but the gating factor is no longer raw compute. It's whether developers and regulators can verify systems against requirements and validate them against real-world operating design domains (ODDs) with confidence and repeatability. Today, many safety-critical components, from scenario libraries to pass/fail criteria, live in proprietary silos. That fragmentation slows regression testing, complicates regulator audits across regions, and duplicates effort across the industry. The result is an expensive, bespoke path to certification for every program and geography.
Musa, MohammadKhawaja, Muhammad Zain
Autonomous vehicles require drivers to assume control of the vehicle in situations where the vehicle control system cannot perform its intended task. A shared control-based approach to driving authority transfer can effectively mitigate the driving risks associated with diminished driver capability due to prolonged disengagement, but it may readily precipitate human–machine conflicts—oscillatory steering behavior, excessive driver workload, and unstable control during weight transitions. Addressing the characteristics of driver capability variations during takeover tasks, a shared control strategy incorporating real-time driving ability, termed the real-time driving ability strategy (RDAS), is proposed. Initially, a real-time capability assessment strategy based on an expected steering angle model is developed. By collecting driving data under conditions of adequate driver capability to train an adaptive neuro-fuzzy inference system (ANFIS) neural network, the expected steering angle is predicted, and the deviation between actual and expected steering angles in takeover scenarios of varying difficulty is used to evaluate real-time driver capability. Subsequently, we design a dynamic weight allocation strategy, integrating real-time driving ability and the phased characteristics of driver capability changes during the takeover process. Simulation analysis of driver takeover scenarios demonstrates that, compared to other strategies, even in the case of the smallest performance difference, the RDAS reduces the conflict load (Cl) index by 71.15%, thereby enhancing driving safety and stability in the early and late stages of takeover weight transitions.
Qi, ZhenliangLiu, PingDuan, HaotianZhou, ZilongHuang, Haibo
The rapid introduction of new Automated Driving Systems (ADS) in the last years has led to an urge for robust methodologies for the type approval of vehicles equipped with such technologies. As a result, different Regulations addressing this field have been adopted. These Regulations are mainly based in the New Assessment and Testing Methodology (NATM) developed within the World Forum for the Harmonisation of Vehicle Regulations (WP29). However, the complexity of the regulatory ecosystem extends beyond type approval. This complexity requires a thorough analysis in order to avoid any possible gap which may jeopardise the feasibility of Automated Driving Vehicles deployment. This paper analyses the possible mismatches among the different regulations currently in place or under development and proposes a holistic approach, where the concept of the Operational Design Domain (ODD) takes a relevant role.
Lujan Tutusaus, CarlosHidalgo, JustinFlix, Oriol
Robust validation of Advanced Driver Assistance Systems (ADAS) considering real-world conditions is a vital for ensuring safety. Mileage accumulation is a one of the validation method for ensuring ADAS system robustness. By subjecting systems to diverse real-world driving environments and edge-case scenarios, engineers can evaluate performance, reliability, and safety under realistic conditions. In accordance with ISO 21448 (SOTIF), known hazardous scenarios are explicitly tested during robustness validation in combination of virtual and physical testing at component, sub system and vehicle level, while unknown hazards may emerge through extended mileage by running vehicles on roads, allowing them to be identified and classified. However, defining a mileage target that ensures comprehensive safety remains a significant engineering challenge. This paper proposes a data-driven approach to define mileage accumulation targets for validating Autonomous Emergency Braking Systems (AEBS), using detailed analysis of real-world accident data in India along with ISO 21448 (SOTIF) validation framework. National-level accident data from MoRTH and the RASSI database, along with statistics for medium and heavy commercial vehicles, are utilized to derive the base incident rate for frontal collisions that AEBS is intended to mitigate. The framework integrates critical factors such as hazardous behavior probability, controllability, and severity to calculate a target incident rate, which then informs the required test mileage needed to statistically validate AEBS performance at a specified confidence level. The study outlines the derivation of mileage requirements by considering both accident and fatality reduction as primary safety metrics. This approach provides engineering guidance for defining test mileage requirements with respective to the defined acceptance criteria that ensure AEBS system robust validation considering the real world scenarios in India.
Koralla, SivaprasadRavjani, AminTatikonda, VijayGadekar, Ganesh
This paper examines the challenges and opportunities in homologating AI-driven Automated Driving Systems (ADS). As AI introduces dynamic learning and adaptability to vehicles, traditional static homologation frameworks are becoming inadequate. The study analyzes existing methodologies, such as the New Assessment/Test Methodology (NATM), and how various institutions address AI incorporation into ADS certification. Key challenges identified include managing continuous learning, addressing the "black-box" nature of AI models, and ensuring robust data management. The paper proposes a harmonized roadmap for AI in ADS homologation, integrating safety standards like ISO/TR 4804 and ISO 21448 with AI-specific considerations. It emphasizes the need for explainability, robustness, transparency, and enhanced data management in certification processes. The study concludes that a unified, global approach to AI homologation is crucial, balancing innovation with safety while addressing ethical considerations and public trust. Future research directions include developing real-time monitoring techniques and certification processes for adaptive systems.
Lujan Tutusaus, CarlosHidalgo, Justin
Accurate and realistic simulation of LiDAR data is critical for the development and validation of autonomous driving systems. However, existing simulation approaches often suffer from a significant sim-to-real gap due to oversimplified modelling of physical interactions and environmental factors. In this work, we present a physics-informed deep learning framework that bridges this gap by enhancing the realism of simulated LiDAR data using generative adversarial networks guided by domain-specific physical constraints for LiDAR intensity. Our method incorporates key physical factors such as range, surface material properties, angle of incidence, and environmental conditions along with their underlying physical relationships as constraints into the Cycle-Consistent GAN architecture, enabling it to learn realistic transformations from synthetic to real-world LiDAR intensity data without requiring paired samples. We demonstrate the effectiveness of our approach across multiple datasets, showing consistent improvements in statistical similarity metrics and downstream perception tasks such as semantic segmentation. The proposed algorithm has been integrated into the Sim-DaaS simulation engine, providing a robust tool for the research and industrial community to generate high-fidelity LiDAR data for training and evaluation of autonomous systems.
Anand, VivekYadav, SouravLimba, MohitPandey, GauravLohani, Bharat
This article provides an overview of how the determination of absence of unreasonable risk can be operationalized. It complements previous theoretical work published by existing developers of automated driving systems (ADS) on the overall engineering practices and methodologies for readiness determination. Readiness determination is, at its core, a risk assessment process. It is aimed at evaluating the residual risk associated with a new ADS deployment. The article proposes methodological criteria to ground the readiness review process for an ADS release. Specifically, it lists 12 readiness criteria connected with system safety, cybersecurity, verification and validation, collision avoidance testing, predicted collision risks, impeded progress, rules of the road compliance, vulnerable road users interactions, high-severity assessment, conservative estimate of severity, risk management, and field safety. The criteria presented are agnostic of any specific ADS technological solution and/or architectural choice, to support broad implementation by others in the industry. While intended to support the readiness evaluation for the deployment of an SAE Level 4 ADS, their use can also be generalized for lower levels of automation and combined with the unique human interaction challenges applicable to those levels. Following the presentation of the proposed criteria, the article continues with a discussion on governance and decision-making toward approval of a new release candidate for the ADS, inclusive of a discussion on factors that affect residual risk and risk management practices. The implementation of the presented criteria requires the existence of appropriate safety management practices in addition to many other cultural, procedural, and operational considerations. As such, the article is concluded by a statement of limitations for those wishing to replicate part or all of its content. The content presented here serves to inform important ongoing conversations on the topic of ADS certification and the standardization of approval guidelines in international regulatory contexts.
Favaro, Francesca MargheritaSchnelle, ScottFraade-Blanar, LauraVictor, TrentPeña, MauricioWebb, NickBroce, HollandPaterson, CraigSmith, Daniel
Items per page:
1 – 50 of 443