Browse Topic: Level 3 (Conditional driving automation)

Items (105)
Simulation plays a significant role in the validation and verification of Automated Driving Systems (ADS). In a scenario-based validation strategy, the road and the actions of the traffic participants must be captured in a portable and flexible format for simulation. XML-based parametric models constitute a common combination upon which the static and dynamic aspects of the environment are captured. Although there are plenty of tools for generating these XML files there are few alternatives to verify their content. This paper suggests a method for converting and simplifying a synthetic road network into a graph for which the Chinese Postman Problem is solved. The resulting sequence can be converted back into a route that can be sampled to verify the drivability of the whole network. Once the network is verified, it can be safely used for simulation, increasing the speed at which ADS systems are developed. The graph representation can also be used to provide interactive feedback to LLMs (Large Language Model), which are increasingly used for automatic generation of roads and scenarios.
Vargas Rivero, Jose RobertoKern, AndreasMenken, StefanHarth, MichaelKuipou, Franck Russel
Safety of Automated Driving Systems (ADSs) is arguably one of the main remaining barriers before widespread market deployment. While there exists a plethora of methods for planning a trajectory that fulfils certain constraints, what those constraints should look like, to enable effective planning of safe trajectories, is still being discussed. In this article, we generalize the concept of Precautionary Safety (PCS) and present a framework providing constraints on the tactical and operational decisions of the ADS. Such constraints consider the ADS’ capabilities, the external conditions, knowledge of statistically relevant events and behaviors of other traffic actors, as well as the controllability of these events. The proposed framework enables assessment of the statistical fulfilment of quantitative risk acceptance criteria (QRACs), including requirements on accident, injury, and fatality rates. The framework further provides a means to dynamically adapt the constraints used for trajectory planning, i.e., to adapt the driving to the situation at hand. A case study, considering a possible collision scenario with a jaywalking pedestrian and a rear-end collision with a trailing vehicle, is provided to showcase the applicability and usefulness of the presented framework. The simulation-based case study displays the safety benefits from considering QRACs with multiple injury risk levels and further shows how the proposed PCS framework can be applied in practice.
Gyllenhammar, Magnusde Campos, Gabriel RodriguesSandblom, FredrikTörngren, MartinFredriksson, Jonas
Rigorous validation of SAE Levels 3 and 4 autonomous systems increasingly relies on simulation. However, the simulation-reality gap remains a challenge for human-in-the-loop assessments. This study empirically quantifies the behavioral fidelity of the Car-Learning-to-Act (CARLA) simulator by recreating specific real-world traffic scenarios using the high-precision exiD drone dataset. Twenty-five participants performed a series of maneuvers, including lane changes and time-critical cut-ins. Their performance was analyzed using Dynamic Time Warping (DTW), driver profiling, and Time-to-Collision (TTC) metrics. The findings reveal a clear distinction between relative and absolute behavioral validity. In strategic decision-making tasks, the simulation demonstrated remarkably high temporal fidelity. DTW analysis explained 94% of the trajectory variance. Participants initiated lane changes with an average lag of -9 frames (0.36 s) compared to naturalistic references. These results indicate that, despite the absence of peripheral optical flow, the simulator successfully elicits temporally correlated decision-making patterns suitable for assessing strategic driver intent. However, physical execution in reactive scenarios revealed significant absolute discrepancies. Although the high Pearson correlation (r ≈ 0.89) in velocity profiles proves that drivers recognize and react to hazards with realistic timing, their physical inputs were exaggerated. Participants displayed digital, over-modulated braking responses and maintained a negative safety bias of -11.26 m, a deviation attributed to the lack of vestibular g-force feedback and geometric minification. Furthermore, distinct driver profiles emerged. Risk-oriented participants exhibited a gaming effect by neglecting safety margins. In conclusion, while CARLA is highly valid for testing the temporal logic of driver interactions, absolute dynamics require calibration functions, such as force-feedback (pedal) tuning and visual deceleration cues like camera shake, to compensate for sensory limitations before it can be used for safety-critical validation.
Rebling, PatrickAlphan, MetehanNenninger, Philipp
Level-3 and higher automated driving systems require longitudinal speed strategies that remain consistent with both physical stopping feasibility and realistic sensing constraints. This paper presents a route-based, sensor-aware speed planning method that supports safety validation and explicitly couples longitudinal driving strategy with sensor field-of-view coverage. Based on a concrete route extracted from digital maps and enriched with fleet data, point-wise maximum speeds are computed considering road curvature, speed limits, and comfort constraints. From the resulting drivable speed profile, physically consistent stopping paths and their endpoints are calculated for each route position, accounting for friction limits, scenario-dependent deceleration capabilities, and system delays between perception and braking. The set of stopping paths is aggregated into a region of interest (ROI) representing the spatial area that must be reliably perceived to guarantee safe stopping. This ROI is overlaid with the geometric fields of view of camera, radar, and lidar sensors, enabling the definition of a compact and interpretable key performance indicator (KPI) based on the number of sensor modalities covering critical regions. Rather than evaluating a specific sensor configuration, the proposed KPI establishes a geometric interface between braking-based perception requirements and multi-modal sensing coverage. The approach reveals the structural sensitivity of perception demands to route geometry and braking assumptions and provides a systematic basis for perception-aware speed release decisions. The method is applicable to highways, interchanges, and other route types, and contributes a modular geometric framework for sensor-aware safety analysis in Level-3 and higher automated driving systems.
Kohler, Paul LeonhardResch, Michael
As automation advances and occupants transition from active drivers to passive passengers, understanding how automated driving behavior is evaluated becomes increasingly important. While longitudinal and lateral vehicle dynamics are known to influence perceived comfort and safety, it remains unclear to what extent motion–perception relationships remain stable across urban traffic contexts. This study compares two real-world investigations of automated driving: a left-turn maneuver at a signalized intersection on a test track and a roundabout maneuver with a shuttle in public traffic. Both datasets include high-resolution vehicle dynamics and structured subjective ratings. A consistent objectification approach was applied to examine the transferability of motion–perception relationships across contexts. However, differences in vehicle platform, automation level, trajectory characteristics, and study design limit direct comparability and require cautious interpretation. Despite partially overlapping ranges in selected peak-based dynamic parameters, such as longitudinal acceleration, subjective comfort and safety ratings were consistently higher in the roundabout scenario. Furthermore, strong associations were observed between motion parameters and subjective evaluations in the intersection context (adj. R2 up to 0.891), whereas objective parameters showed only limited explanatory power in the roundabout scenario (adj. R2 ≤ 0.06). The results indicate that motion–perception relationships derived within a specific context may not be directly transferable across different traffic scenarios. The findings highlight limitations of globally derived motion-based evaluation models and underline the importance of validating objectification approaches across diverse operational environments.
Panzer, AnnaStrenge, EmmaIatropoulos, JannesHenze, Roman
Previous rear-facing post-mortem human subject (PMHS) studies utilizing a reinforced seat have prompted questions as to whether the seat could have been a contributing factor to the severe rib and pelvis injuries observed in those experiments. In response, a recent PMHS study used an unreinforced seat in a similar experiment, which was expected to mitigate severe injuries by dissipating energy from seatback deformations. However, the PMHS tested in the unreinforced seat sustained even more severe rib fracture numbers than in the reinforced seat. No studies have investigated how additional variables (i.e., countermeasures) may influence rib fractures in high-speed rear-facing frontal impacts (HSRFFI). Therefore, this study aimed to explore the effect of an airbag-equipped seat (AES) on male PMHS responses and injuries. Rear-facing sled tests were conducted using five mid-size male PMHS seated in the AES at ΔV of 56 km/h: PMHS1 with no airbag as a baseline, PMHS2 with a seatback airbag (SA), PMHS3 with an extended seatback airbag (ESA), and PMHS4 and 5 with ESA and a wedge airbag (ESA+WA). An instrument panel (IP) and windshield were installed behind the seat to mimic realistic interior vehicle compartments. A chestband at mid-sternum, 6-degree motion blocks at the head, T1, T4, T8, T12, pelvis, and extremities, as well as rib strain gages and rosettes were installed on PMHS to understand potential mechanisms of injuries. A motion capture system was used to quantify whole-body PMHS and seatback kinematics. Maximum seatback rotation was 38.1° in the baseline test and 20.3°–25.1° with AES. Peak chest A-P compression in the anterior-posterior (A-P) direction was 25.7 mm for baseline and 7.3 mm–35.2 mm with AES (23.7 mm for SA, 7.3 mm for ESA, 35.2 and 8.7 mm for ESA+WA). The number of rib fractures (NRF) was high in baseline (32), SA (25), and ESA (27) conditions, but was reduced in ESA+WA (6 and 13). Strain rosette data indicated upward directions of principal strains on the posterior ribs, likely due to I-S deformation of the PMHS thoraces. Responses from thorax instrumentation showed that peak chest deflection (A-P) alone did not fully explain NRF, especially as rib fractures in all tests occurred after peak deflection in this direction. Instead, maximum principal strains in the I-S direction (shear), confirmed by strain rosette data, likely influenced rib fractures. ESA+WA effectively supported PMHS, maintaining upright postures and minimizing I-S chest shear, which reduced NRF. Limitations include a small sample size, possible age-related injury effects, and seat designs intended for low-speed rear impacts, not HSRFFI. Compression and shear loading to the PMHS thoraces were observed in HSRFFI. The shear loading was likely due to the large upward thorax deflection induced by the ramping motion and seatback rotation. One of the AES, ESA+WA, effectively maintained an upright spine and reduced NRF. This study offers important information for improving current safety tools and designing rear-facing countermeasures for automated driving systems.
Kang, Yun-SeokDeWitt, TimothyWensink, TimothyMarcallini, AngeloJung, Yong HyunLee, Dong GilHarm, Jae JunKo, SeokhoonHunter, RandeeAgnew, Amanda M.
The objective of this research was to understand the impact of transition window duration on success and performance during nominal transitions from conditional driving automation (SAE level 3). Because the driver can be disengaged from driving when conditional driving automation is engaged, the central challenge is how to safely transition from automated control to human control. Past research from the literature on Level 3 Automated Driving Systems (L3 ADS) has focused on safety-critical event responses (e.g., responding to a hazard) and on automation that operates at high speeds, which is not representative of the systems currently deployed that operate in lower-speed traffic jam situations [4, 5]. This article presents an analysis of data from several transition-of-control studies with conditional driving automation in a high-fidelity driving simulator. A range of transition window durations were compared, and different transition-of-control behaviors were coded from video data. Transition windows for 4, 6, 8, and 10 s conditions resulted in failures by the drivers to resume control. Success rates by condition were lowest with 4 s transition windows, but also lower with 10 s windows, compared to 6 s, 8 s, or 15 s windows (potential explanations appear in the discussion). Time to first glance back at the forward road and time to first-hand on the steering wheel were predictors of transition of control success across all transition windows. Survival analyses showed that drivers needed to begin the transition process within a few seconds to make successful transitions, even with longer transition windows. The results demonstrate the impact of different transition window durations on transition of control and provide unique insights into the factors influencing transition success in situations representative of those happening on the road now. These results help shape understanding of the requisite time needed for safe transition from automated to manual control and speak to the design recommendations for human–automation interactions.
Gaspar, JohnAhmad, OmarSchwarz, ChrisFincannon, ThomasJerome, Christian
Vehicles equipped with an Automated Driving System (ADS) have the potential to significantly reduce road collisions. To enable widespread adoption of ADSs, rigorous safety assessment is essential. Valuable insights for ADS safety validation can be gained by simulating scenarios across a broad range of feature variations. A common challenge in simulating these scenarios is known as the curse of dimensionality, where increasing the number of scenario features requires a near-infinite number of simulations to cover all variations. This issue of complexity presents a need for reducing scenario features. Most related work focuses on identifying important scenario features, while few evaluate how reducing these features impacts ADS failure estimation. The present study aims to address this gap by employing a wide range of feature reduction methods and assessing their effect on ADS failure estimation. Previous research generated datasets for three distinct scenario categories by performing virtual simulations using driver reference models on real-world data. In the present work, the machine learning classifiers such as extreme gradient boosting and random forest are applied to this data for predicting ADS failures. Ten dimensionality reduction techniques, including both feature selection and transformation approaches, are employed to reduce the scenario feature set. The optimal reduced feature set is selected based on classification performance measured by the area under the precision–recall curve. To assess the impact on ADS failure estimation, results are compared against those obtained with the full set of features. The findings indicate that reliable ADS failure estimates can be maintained, and even significantly improved, after substantially reducing the number of scenario features. By reducing scenario features, fewer virtual simulations may be required to reliably estimate ADS failures, which may enable more efficient scenario-based ADS safety assessment. Additionally, this study may offer guidance on selecting suitable dimensionality reduction techniques for scenario-based ADS safety assessment.
Lankhorst, Bramde Gelder, ErwinJanssen, Christian P.Scholich, Andre
Precision control in Level 4 Automated Vehicles is essential for enhancing operational efficiency, accuracy, and safety. This work, conducted as part of ARPA-E’s NEXTCAR program, focuses on developing a robust hardware and software control solution to enable drive-by-wire functionality. A previous publication by the authors presented the hardware solutions for overtaking stock vehicle controls. This paper focuses on a model-based and data-driven control algorithm to enable drive-by-wire functionality for longitudinal and lateral motion control for a 2021 Honda Clarity Plug-In Hybrid Electric Vehicle. This vehicle was equipped with a set of sensors and an onboard processing unit to enable Level 4 automation. For lateral controls, an algorithm was developed to command steering torque to the electronic power steering module, ensuring the vehicle could attain the desired steering angle position at varying speeds. The system leveraged feedforward and feedback mechanisms. Feedback controller gains were identified through frequency response analysis of the steering torque assist electric motor and were further refined during track testing. To optimize the controller’s response time, a feedforward function was developed using a physics-aware model of the vehicle's steering system. The independent feature selection for the model was guided by using the physics of the system. For longitudinal control, the control inputs included the positions of the brake and accelerator pedals sent to the stock ECU, with the desired speed as the setpoint. The setup used a combination of feedforward and feedback control to achieve the target acceleration or deceleration. These algorithms underwent extensive dynamometer and track testing to perform various maneuvers in conjunction with the automated driving system.
Adsule, KartikBhagdikar, PiyushDrallmeier, JosephAlden, JoshuaGankov, Stanislav
The validation of Advanced Driver Assistance Systems (ADAS) and Automated Driving (AD) Systems, especially at higher automation levels such as SAE Level 3 or 4, demands the testing of a vast array of scenario variants far exceeding the scope of standard safety specifications like Euro NCAP (The European New Car Assessment Programme). Autonomous vehicles require thorough real-world testing to ensure automotive safety. However, public road tests are costly and risky. Instead, virtual scenarios - digital twins of real environments - offer a safe, cost-effective testing alternative. Exhaustive simulation across this high-dimensional scenario space, which includes variations in actor behavior, environmental conditions, and event characteristics, is computationally infeasible. We propose a constraint-solving approach to address this challenge that leverages mathematical and geometric techniques to analytically assess the existence and validity of scenario variants prior to simulation. Two primary methods are explored: (1) random or sequential generation of scenario variants with a pre-simulation pruning step to eliminate invalid cases, and (2) direct generation of valid variants by solving constraint systems that ensure the desired events occur under specified conditions. Importantly, maintaining an effective balance between these two approaches is central to our methodology, as the optimal mix depends on the specific testing goals and requirements. This framework implemented using MATLAB®, Simulink®, the Automated Driving ToolboxTM, and the Euro NCAP Support Package®, systematically reduces the scenario space by excluding impossible cases. Our approach aims to significantly reduce reliance on extensive simulation and enable more targeted and efficient validation for safety compliance.
Karve, OmkarSaurav, SaketPurwar, Prabhanshu
Automated Driving Systems (ADS) rely on AI algorithms, machine learning, and sensor fusion to perform autonomous driving tasks. Safety challenges arise due to the probabilistic behavior of AI/ML algorithms and the need to ensure safety within defined Operational Design Domains (ODDs). Traditional standards such as ISO 26262[3] (Functional Safety) and ISO 21448[4] (SOTIF) address hardware and software failures or functional deficiencies but are insufficient for higher-level autonomous systems (SAE Levels 3–5). To close this gap, additional standards such as UL 4600[1] and ISO 5083[2] provide complementary frameworks for ADS safety assurance. UL 4600[1] establishes a claim-based safety case encompassing the vehicle, infrastructure, and processes, emphasizing structured arguments supported by evidence and reasoning. It offers guidance on autonomy functions, V & V, tool qualification, dependability, and safety culture. ISO 5083[2] focuses on design, verification, and validation of ADS, extending safety lifecycles with system-level principles, risk criteria, and validation metrics. It defines the ADS safety case as proof of acceptable safety for specific features and environments, stressing safety-by-design, layered verification, and post-deployment monitoring, including cybersecurity. Together, UL 4600[1] and ISO 5083[2] enable a unified approach to safety assurance, aligning with Functional Safety and SOTIF principles. Their integration helps manufacturers evaluate ADS systematically, demonstrate risk acceptance, and maintain safety throughout the lifecycle.
Mudunuri, Venkateswara RajuAlmasri, HossamFan, Hsing-Hua
This paper presents the integration and validation of Adaptive Cruise Control (ACC) algorithms on a student-team-developed vehicle as part of the U.S. Department of Energy EcoCAR EV Challenge. The competition provided each team with a 2023 Cadillac Lyriq, which was modified to an all-wheel-drive configuration and re-architected to support the development of SAE Level 3 autonomous features including Adaptive Cruise Control (ACC), Automatic Intersection Navigation (AIN), Lane Centering Control (LCC), and Automatic Parking (AP). The scope of this paper, however, is limited to the development, implementation, and validation of a Level 2 longitudinal ADAS function. Higher-level automation requirements such as Operational Design Domain (ODD) definition and Driver Monitoring System (DMS) enforcement are addressed at the vehicle architecture and competition level but are not the focus of this work. The major contribution of this work is the development of ACC with Vehicle-to-Infrastructure (V2I) integration, highlighting the end-to-end implementation of the ACC algorithm and its interaction with key actuation systems in the modified vehicle architecture. The ACC algorithm encompassed multiple applications: conventional cruise control to maintain speed, adaptive cruise control to respond to a lead vehicle, and initial deceleration handling for intersection navigation in a single straight lane. By implementing a unified algorithm, transitions between these modes were smooth and more efficient compared to developing separate algorithms for each application. Track-based testing and calibration were conducted to validate these modes under real-world scenarios, ensuring safe operation while addressing the challenges of blended actuation. Multiple track tests were used to measure stopping distances at intersections for different entry speeds, evaluate controller performance during different driving scenarios, and identify system limitations. Results demonstrated that the controller maintained steady-state speed error within +/- 1 km/hr, preserved a minimum following distance of 8 m at a complete stop, and limited acceleration within +/- 2 m/s2 to support driver comfort. The work demonstrates the progression from simulation to real-world deployment using an empirical approach to system-level validation of ACC with V2I integration. The findings provide insights into calibration methodology, mode transition, and the benefits of a unified control framework for advancing software-defined vehicle features.
Gupta, IshikaEstrada, TylerTambolkar, PoojaMidlam-Mohler, Shawn
The intersection of Safety of Intended Functionality (SOTIF) and Functional Safety (FuSa) analysis of driving automation features has traditionally excluded Quality Management (QM) components from rigorous safety impact evaluations. While QM components are not typically classified as safety-relevant, recent developments in artificial intelligence (AI) integration reveal that such components can contribute to SOTIF-related hazardous risks. Compliance with emerging AI safety standards, such as ISO/PAS 8800, necessitates re-evaluating safety considerations for these components. This paper examines the necessity of conducting holistic safety analysis and risk assessment on AI components, emphasizing their potential to introduce hazards with the capacity to violate risk acceptance criteria when deployed in safety-critical driving systems, particularly in perception algorithms. Using case studies, we demonstrate how deficiencies in AI-driven perception systems can emerge even in QM-classified components, leading to unintended functional behaviors with critical safety implications. By bridging theoretical analysis with practical examples, this paper argues for the adoption of comprehensive FuSa, SOTIF, and AI standards-driven methodologies to identify and mitigate risks in AI components. The findings demonstrate the importance of revising existing safety frameworks to address the evolving challenges posed by AI, ensuring comprehensive safety assurance across all component classifications spanning multiple safety standards.
Abbaspour, Ali RezaMahadevan, ShabinZwirglmaier, KilianStafford, Jeff
Avoiding and mitigating any potential collision is dependent on (1) road user ability to avoid entering into a conflict (conflict avoidance effect) and (2) road user response should a conflict be entered (collision avoidance effect). This study examined the collision avoidance effect of the Waymo Driver, a currently deployed SAE level 4 automated driving system (ADS), using a human behavior reference model, designed to be representative of a human driver that is non-impaired, with eyes on the conflict (NIEON). Reliable performance benchmarking methodologies for assessing ADS performance are an essential component of determining system readiness. This consistently performing, always-attentive driver does not exist in the human population. Counterfactual simulations were run on responder collision scenarios based on reconstructions from a 10-year period of human fatal crashes from the Operational Design Domain of the Waymo ADS in Chandler, Arizona. Of 16 simulated conflicts entered, 12 (75%) were prevented by the Waymo Driver, and 10 (62.5%) were prevented by the NIEON model. The NIEON Model mitigated an additional 5 collisions and did not mitigate 1 collision. In these 16 conflicts entered, 93% of serious injury risk was reduced by the Waymo Driver, whereas 84% of serious injury risk was reduced by the NIEON model. Further, in a case-by-case evaluation, the Waymo Driver’s collision avoidance led to reduced serious injury risk when compared to the NIEON model in every simulated event. The results of this paper demonstrate that a reference model like NIEON can be used to benchmark ADS responder performance in response to high-risk initiating behaviors performed by the current driving population.
Scanlon, John M.Kusano, Kristofer D.Engstrom, JohanVictor, Trent
This paper presents crash rate benchmarks for evaluating US-based automated driving systems (ADSs) for multiple urban areas, distinguishing between freeway and surface street crash rates, and breaking them down by crash severity and type. The purpose of this study was to extend prior benchmarks focused only on surface streets to additionally capture freeway crash risk for future ADS safety performance assessments. Using publicly available police-reported crash and vehicle miles traveled (VMT) data from Arizona, California, Georgia, and Texas, the methodology details the isolation of in-transport passenger vehicles, road type classification, and crash typology. Key findings revealed that freeway crash rates exhibit large geographic dependence variations with any-injury-reported crash rates being approximately three times higher in Atlanta (2.3 IPMM; the highest) when compared to San Diego (0.7 IPMM; the lowest). The results show the critical need for location-specific benchmarks to avoid biased safety evaluations and provide insights into the VMT required to achieve statistical significance for various safety impact levels. The distribution of crash types depended on the outcome severity level. Higher severity outcomes (e.g., fatal crashes) had a larger proportion of single-vehicle, vulnerable road users (VRUs) and opposite-direction collisions compared to lower severity (police-reported) crashes. Given heterogeneity in crash types by severity, performance in low-severity scenarios may not be predictive of high-severity outcomes. These benchmarks are additionally used to quantify at the required mileage to show statistically significant deviations from human performance. Future work investigating the underlying factors influencing crash rates in each geographical area will further enhance future benchmarking efforts (by identifying potential confounders to account for when matching exposure between baseline and ADS data). This is the first paper to generate freeway-specific benchmarks for ADS evaluation and provides a foundational framework for future ADS benchmarking by evaluators and developers.
Scanlon, John M.McMurry, Timothy L.Chen, Yin-HsiuKusano, Kristofer D.Victor, Trent
Automotive Engineering: February 202626AUTP022/5/2026
Qualcomm expands partnerships for more Snapdragons Bosch is ready to bring AI to your vehicle, likely to still be ICE-powered in 2035 Etching for a greener future How chemical etching is helping enable next-gen automotive technologies. Rewriting the engineer's playbook: What OEMs must do to spin the AI flywheel The automotive industry's future hinges on a new AI-native engineering workflow that accelerates iteration, strengthens system thinking, and preserves human judgment. From redundancy to resilience: building smarter safety systems through sensor collaboration ADAS sensor fusion can provide improved and required safety technologies by rethinking the best strategy for allowing a car to sense the world. Open Safety is the shortcut to safer ADAS/AD An open safety stack, shared scenarios, benchmarks, and core validation tools can speed certification, reduce duplicated V&V and build public trust while preserving vendor differentiation. Editorial Robots, physical AI shift the focus at CES Supplier Eye A re-regionalized industry GM announces SAE Level 3 autonomy and SDV technology Survey: QNX finds challenges, openings in SDV work Engineering flexibility into EV powertrains Poland making moves to be larger automotive supplier Now playing: MUSiC, the first multi-user SiC fabrication facility in the U.S. Mercedes brings music production into the backseat 2026 Nissan Leaf is fun now. But more importantly, efficient. 2026 Nissan Sentra review: putting the pieces together Product Briefs Spotlight: Inspection software, ADAS detection Q&A DarkSky One wants to make the world a darker place
The rapid introduction of new Automated Driving Systems (ADS) in the last years has led to an urge for robust methodologies for the type approval of vehicles equipped with such technologies. As a result, different Regulations addressing this field have been adopted. These Regulations are mainly based in the New Assessment and Testing Methodology (NATM) developed within the World Forum for the Harmonisation of Vehicle Regulations (WP29). However, the complexity of the regulatory ecosystem extends beyond type approval. This complexity requires a thorough analysis in order to avoid any possible gap which may jeopardise the feasibility of Automated Driving Vehicles deployment. This paper analyses the possible mismatches among the different regulations currently in place or under development and proposes a holistic approach, where the concept of the Operational Design Domain (ODD) takes a relevant role.
Lujan Tutusaus, CarlosHidalgo, JustinFlix, Oriol
The automotive industry is rapidly advancing towards autonomous vehicles, making sensors such as Cameras, LiDAR, and RADAR critical components for ensuring constant information exchange between the vehicle and its surrounding environment. However, these sensors are vulnerable to harsh environmental conditions like rain, dirt, snow, and bird droppings, which can impair their functionality and disrupt accurate vehicle maneuvers. To ensure all sensors operate effectively, dedicated cleaning is implemented, particularly for Level 3 and higher autonomous vehicles. It is important to test sensor cleaning mechanisms across different weather conditions and vehicle operating scenarios to ensure reliability and performance. One crucial aspect of testing is tracking the trajectory of the cleaning fluid to ensure it does not cause self-soiling of vehicles and affects the field of view or visibility zones of other components like the windshield. While wind tunnel tests are valuable, digitalizing this process is vital for making design decisions early in vehicle development. This work presents a digital methodology to test the self-soiling of a vehicle due to the cleaning systems present on vehicle exterior components, e.g. during mud cleaning at different vehicle speeds. The cleaning mechanism involves multiple water nozzles positioned above, below, or on the sides of these components, which spray water jets to remove dirt or mud deposits. The developed numerical method models the motion of cleaning fluid and contaminants after component cleaning. Steady-state aerodynamic simulations using the Finite Volume Method (FVM) are used to capture airflow, while the interaction of air with cleaning fluid and components is analyzed using a Smoothed Particle Hydrodynamics (SPH) solver. Correlations from this study and wind tunnel tests reveal potential optimization opportunities for existing cleaning systems by inspecting surrounding airflows at various vehicle speeds. Preliminary design evaluations indicate a specific vehicle speed range where self-soiling of vehicle components such as the windshield occurs due to mud cleaning. The proposed numerical method provides the capability to evaluate and qualitatively compare vehicle self-soiling due to various cleaning system designs of exterior components, offering valuable insights for optimizing cleaning mechanisms in autonomous vehicles.
Mane, SuvidyaMakam, Sri Lalith MadhavVarghese, RixsonDesu, Harsha
This paper examines the challenges and opportunities in homologating AI-driven Automated Driving Systems (ADS). As AI introduces dynamic learning and adaptability to vehicles, traditional static homologation frameworks are becoming inadequate. The study analyzes existing methodologies, such as the New Assessment/Test Methodology (NATM), and how various institutions address AI incorporation into ADS certification. Key challenges identified include managing continuous learning, addressing the "black-box" nature of AI models, and ensuring robust data management. The paper proposes a harmonized roadmap for AI in ADS homologation, integrating safety standards like ISO/TR 4804 and ISO 21448 with AI-specific considerations. It emphasizes the need for explainability, robustness, transparency, and enhanced data management in certification processes. The study concludes that a unified, global approach to AI homologation is crucial, balancing innovation with safety while addressing ethical considerations and public trust. Future research directions include developing real-time monitoring techniques and certification processes for adaptive systems.
Lujan Tutusaus, CarlosHidalgo, Justin
The automotive industry is rapidly extending the capabilities of automated systems by incorporating connectivity and cooperation features that enable real-time information exchange between vehicles and road infrastructure. Within the Connected, Cooperative, and Automated Mobility (CCAM) framework, Vehicle-to-Vehicle (V2V) communication is expected to play a key role in improving road safety, traffic efficiency, and driving comfort. This work addresses a practical implementation of the standardized Manoeuvre Coordination Messages (MCMs), as defined in the ongoing ETSI standard (ETSI TS 103 561). The proposed approach is demonstrated through a cooperative cut-in use case in which two vehicles negotiate a lane change manoeuvre. In the considered scenario, the ego vehicle, driven by a Highway Pilot (HWP) system, receives the intention to cut-in from a neighbouring cooperative vehicle through an MCM. In response, the ego vehicle adapts its behaviour by decelerating to generate a safe longitudinal gap, which allows the cooperative vehicle to merge the ego’s lane. The negotiation process relies on the bidirectional exchange of MCMs to coordinate the timing and trajectories, ensuring both vehicles complete the manoeuvre safely. Additionally, the Cooperative Awareness Messages (CAMs) allow the vehicles to share real-time information such as position, speed and heading. This connected-enhanced approach extends the capabilities of local perception systems, enabling an improved performance and reaction time to surround traffic participants. The described use case is implemented and validated in a prototype vehicle equipped with V2V communication capabilities and a Highway Pilot (HWP) SAE level 3 driving automation system. Proving ground tests demonstrate that the system can successfully negotiate cut-in manoeuvres in real time, enhancing both safety and traffic flow. The results confirm the feasibility of deploying standardized V2V coordination mechanisms within operational automated driving functions and lay the groundwork for broader integration into future CCAM applications.
Leiva Ricart, GiselaDomingo Mateu, Bernat
Highway Pilot (HWP) systems, classified as SAE Level 3 Automated Driving Systems (ADS), represent a potential advancement for safer and more efficient highway drives. In this work, the development of a connected HWP prototype is presented. The HWP system is deployed in a real test vehicle and designed to operate autonomously in highway environments. The implementation presented in this paper covers the complete setup of the vehicle platform, including sensor selection and placement, hardware integration and communication interfaces for both autonomous functionality and Vehicle-to-Everything (V2X) connectivity. The software architecture follows a modular design, composed of modules for perception, decision-making and motion control to operate in real-time. The prototype integrates Vehicle-to-Vehicle (V2V) communication, such as Cooperative Awareness Messages (CAM), to enhance situational awareness and improve the overall system behaviour. The modular structure allows new functionalities to be developed and integrated into the same platform, so it becomes a beta testing platform for the early-stage experimentation of innovative features. To validate the prototype, execution of scenario-based testing on a proving ground is used, which is part of the Safety Assurance Framework (SAF), which provides structured methods to help define test scenarios to cover the system’s Operational Design Domain (ODD). Experimental results demonstrate the prototype’s ability to operate in varied highway scenarios.
Domingo Mateu, BernatLeiva Ricart, GiselaFacerias Pelegri, MarcPerez, Marc
This article provides an overview of how the determination of absence of unreasonable risk can be operationalized. It complements previous theoretical work published by existing developers of automated driving systems (ADS) on the overall engineering practices and methodologies for readiness determination. Readiness determination is, at its core, a risk assessment process. It is aimed at evaluating the residual risk associated with a new ADS deployment. The article proposes methodological criteria to ground the readiness review process for an ADS release. Specifically, it lists 12 readiness criteria connected with system safety, cybersecurity, verification and validation, collision avoidance testing, predicted collision risks, impeded progress, rules of the road compliance, vulnerable road users interactions, high-severity assessment, conservative estimate of severity, risk management, and field safety. The criteria presented are agnostic of any specific ADS technological solution and/or architectural choice, to support broad implementation by others in the industry. While intended to support the readiness evaluation for the deployment of an SAE Level 4 ADS, their use can also be generalized for lower levels of automation and combined with the unique human interaction challenges applicable to those levels. Following the presentation of the proposed criteria, the article continues with a discussion on governance and decision-making toward approval of a new release candidate for the ADS, inclusive of a discussion on factors that affect residual risk and risk management practices. The implementation of the presented criteria requires the existence of appropriate safety management practices in addition to many other cultural, procedural, and operational considerations. As such, the article is concluded by a statement of limitations for those wishing to replicate part or all of its content. The content presented here serves to inform important ongoing conversations on the topic of ADS certification and the standardization of approval guidelines in international regulatory contexts.
Favaro, Francesca MargheritaSchnelle, ScottFraade-Blanar, LauraVictor, TrentPeña, MauricioWebb, NickBroce, HollandPaterson, CraigSmith, Daniel
For driver-automation collaborative driving, accurately monitoring driver state in smart cockpits is crucial for enhancing safety, comfort, and human-computer interactions. However, existing research lacks clarity regarding the relationships among driver states, and there is no consensus on the optimal physiological channels to reliably capture these states. This study examined three critical psychological constructs (i.e., perceived risk, trust in the automated driving system, and driver fatigue) using a 37-participant driving simulation experiment. We manipulated multiple factors to induce distinct driver states among participants and recorded subjective scale ratings, heart rate variability, galvanic skin response, and eye movement data. Subjective scale ratings were adopted as the ground truth to examine the corresponding measurement relationships between different physiological signals and the three targeted dimensions of driver states. Our results proved that perceived risk, trust, and fatigue were independent constructs and exhibited distinct and significant associations with physiological metrics from corresponding measurement channels. Specifically, perceived risk correlated with sympathetic and parasympathetic activation, as reflected by heart rate variability metrics such as standard deviation of normal-to-normal intervals and root mean square of successive differences. Trust exhibited negative correlations with galvanic skin response indicators of physiological arousal, including skin conductance level and skin conductance responses, etc. Fatigue, meanwhile, showed consistent correlations with eye movement metrics like percentage of eye closure and mean fixation duration. These findings validate the specificity of physiological metrics as objective indicators for each driver state construct, highlighting their potential for real-time in-cabin monitoring, and contributes to improving traffic safety and comfort of automated vehicles.
Wang, ZhenyuanLi, QingkunWang, WenjunLiu, WeiminSun, ZhaocongCheng, Bo
With the advancement of automated driving system levels, corner scenarios characterized by low probability and high risk have become critical for the safety validation of automated vehicles. However, due to the typical long-tail distribution of such scenarios, data-driven mining approaches face significant challenges in achieving efficient generation. To address this issue, this study proposes a feature-optimized combination-based method for generating corner scenarios in automated driving systems. Key scenario features related to functional failures are first identified using a combined approach of system theoretic process analysis (STPA) and hazard and operability analysis (HAZOP). Based on these features, an adaptive genetic algorithm is employed to optimize feature combinations and generate large numbers of corner scenario types that meet specified constraints. The proposed method is validated using cut-in and pedestrian-crossing scenarios as baseline cases. The results show that this method enables large-scale generation of corner scenario types grounded in regulatory scenarios and provides significant support for the development of comprehensive corner scenario libraries for automated vehicle testing.
Zhou, ShiyingZhang, DongboZhao, DeyinZhu, BingZhang, Peixing
This study presents a structured evaluation framework for reasonably foreseeable misuse in automated driving systems (ADS), grounded in the ISO 21448 Safety of the Intended Functionality (SOTIF) lifecycle. Although SOTIF emphasizes risks that arise from system limitations and user behavior, the standard lacks concrete guidance for validating misuse scenarios in practice. To address this gap, we propose an end-to-end methodology that integrates four components: (1) hazard modeling via system–theoretic process analysis (STPA), (2) probabilistic risk quantification through numerical simulation, (3) verification using high-fidelity simulation, and (4) empirical validation via driver-in-the-loop system (DILS) experiments. Each component is aligned with specific SOTIF clauses to ensure lifecycle compliance. We apply this framework to a case of driver overreliance on automated emergency braking (AEB) at high speeds—a condition where system intervention is intentionally suppressed. Initial numerical analysis suggested that the scenario narrowly satisfies the acceptance criteria. Applying the proposed framework to this scenario reveals that significant safety risks can persist even when the system functions according to its design intent. Our findings demonstrate that foreseeable misuse can be formally modeled, simulated, and empirically validated within the SOTIF framework. The proposed approach enables system developers to quantify behavioral risk and assess human-centered edge cases with greater rigor. This work contributes to operationalizing SOTIF for behavioral safety assurance and lays the foundation for future research on risk mitigation through adaptive HMI and context-aware alerts.
Kang, Do WookKim, WoojinJang, Eun HyeChang, MiYoon, DaesubJang, Youn-Seon
Takeover safety in conditional automation depends heavily on effective Takeover Requests (TORs). This study investigated the implication of the temporal distribution of takeover interface elements (temporal distribution: takeover cues appear first/last, spatial distribution: left/center/right) on driving trust in scenarios with different levels of urgency (low: road construction/high: traffic accidents). The results suggest that driver perceptions of the reliability of an automated driving system during control transitions may be influenced by the temporal characteristics of the distribution of human-machine interface elements. Drivers need to supervise the operation status of the autopilot system, and presenting timely information about the system at critical nodes can help improve driver trust. The central spatial distribution contributes to trust in high emergencies, while the right spatial distribution enhances driver trust more in low emergencies. This study informs takeover interface design to enhance control-transition safety in automated vehicles.
Wu, JianfengLi, Zihan
This SAE Recommended Practice provides DA metrics used to quantify the DDT performance of ADS-operated vehicles.3 Here, the primary focus is on the safety-related DDT performance and includes definitions, taxonomy, characteristics, and usage (along with alternatives) for each metric. DDT performance is a subset of overall operational performance of ADS-operated vehicles. Thus, assessments of DDT Fallback [1], cybersecurity, maintenance, interactions with passengers, etc., while important and could have an indirect impact on the DDT, are out of scope for this document. Note that the DA metrics do not specify the actions and/or maneuvers to be executed by the (ADS-operated) subject vehicle (SV). While this document presents a set of individual DA metrics, it is important to note that it is out of the scope of this document to describe how these metrics should be applied in practice. This is because the overall context of the scenario or deployment must be considered during DA metrics implementation and different DA metrics could be applicable for different ADS applications. Implementation of the DA metrics recommended in this document may inform a safety assessment of an ADS’s performance of the DDT, and this assessment in turn may inform a broader safety assessment of an ADS-operated vehicle. However, these metrics could be supplemented by additional input for both types of assessments. A literature review of DA metrics that have been proposed and, in some cases, used in previous studies was conducted. From this literature review, a set of DA metrics has been created with example usage. Evidence of prior research indicating that a metric has a meaningful relationship with safety outcome(s) is included where applicable.4 The set of DA metrics is not necessarily comprehensive, and there may be additional metrics that can be used to assess DDT performance, particularly metrics that measure ADS subsystem performance.5 DA metrics might use parameterized variables, assumptions, and thresholds6 in their formulation. Defining or recommending values for these quantities used in the metrics formulation is outside the scope of this document. It is expected that the methodologies for collecting and assigning such values for these metrics will be developed based on implementation of the metrics in this document in field and other learned experiences with production and prototype vehicles and systems. Values could also be established by regulation, industry best practices, improved technology development, and academic research, among others, and may change based on the operating conditions within the operational design domain (ODD). In the interim, it will be the responsibility of the implementer of these metrics to choose values for these quantities. The DA metrics can be implemented in both testing and commercialization phases and for various purposes, including for ADS-equipped vehicle development, third-party evaluation, and event reconstruction and analysis. For example, the metrics can be used as part of an ADS-equipped vehicle verification and validation (V&V) scenario-based testing process wherein individual scenarios are tested. A third-party evaluator could also aggregate measurements of the metrics measurements over a period of time or number of scenarios (i.e., a period of time could be considered to be a sequence of scenarios) in on-road operation (which could be during testing or commercialization) in order to monitor driving performance of an ADS-operated vehicle.
On-Road Automated Driving (ORAD) Committee
SAE TOMORROW TODAY - What Happens After a Crash? The Push for Safer AVs135237/11/2025
What happens after an AV crashes? That split-second response can make all the difference--and that's exactly what the Automated Vehicle Safety Consortium (AVSC) is focused on. Backed by decades of engineering and mobility expertise, the AVSC brings together top minds in AV development to align on critical safety issues. Their latest work tackles one of the most urgent: how these vehicles should react and communicate after a crash. As AVs expand from test fleets to real-world deployments, the industry needs clear guidance now more than ever. Listen in as we sit down with Jonathan Barentine, Principal Engineer at the AVSC, to discuss the organization's just-released best practices for automated driving systems in the moments following a collision. You'll learn how the AVSC is working with first responders, manufacturers, and policymakers to develop scenario-based protocols that prioritize effective communication, safety management, and a culture of accountability. We'd love to hear from you. Share your comments, questions and ideas for future topics and guests to podcast@sae.org. Don't forget to take a moment to follow SAE Tomorrow Today--a podcast where we discuss emerging technology and trends in mobility with the leaders, innovators and strategists making it all happen--and give us a review on your preferred podcasting platform. Follow SAE on LinkedIn, Instagram, Facebook, Twitter, and YouTube. Follow host Grayson Brulte on LinkedIn, Twitter, and Instagram.
Patterson, Lori
Human driver errors, such as distracted driving, inattention, and aggressive driving, are the leading causes of road accidents. Understanding the underlying factors that contribute to these behaviors is critical for improving road safety. Previous studies have shown that physiological states, like raised heart rates due to stress and anxiety, can influence driving behavior, leading to erratic driving and an increased risk of accidents. In this study, we conducted on-road tests using a measurement system based on the Driver-Driven vehicle-Driving environment (3D) method. We collected physiological signals, specially electrocardiography (ECG) data, from human drivers to examine the relationship between physiological states and driving behaviors. The aim was to determine whether ECG can serve as an indicator of potential risky driving behaviors, such as sudden acceleration and frequent steering adjustments. This information enables automated driving (AD) systems to intervene in dangerous situations. We collected measurements from 22 participants, each tested for 15 minutes on the highway, resulting in a dataset of 330 minutes of physiological data and over 500 km of driving data. The data was segmented into 15-second intervals for detailed analysis. Each segment was labeled twice: physiological states classified as ’stress’ or ’relaxation’ based on heart rate derived from ECG, and driving styles categorized as ’defensive’, ’average’, or ’sporty’ based on CAN-Bus data. Preliminary findings revealed a significant correlation between overall driving behavior on the highway and physiological states. We selected key driving parameters, including velocity, acceleration, lateral acceleration, and yaw rate. We found that acceleration in longitudinal and lateral direction can best indicate driver control and intention, and they vary significantly under two physiological states. This study focuses on how physiological signals change during aggressive driving and aims to establish these signals as indicators for alerting drivers, ultimately reducing the risks of accident associated with aggressive driving behaviors.
Ji, DejieFlormann, MaximilianBollmann, JulianHenze, RomanDeserno, Thomas M.
While semi-autonomous driving (SAE level 3 & 4) is already partially a reality, the driver still needs to take over driving upon notice. Hence, the cockpit cannot be designed freely to accommodate spaces for non-driving related activities. In the following use case, a mobile workplace is created by integrating a translucent acrylic glass pane into the cockpit and introducing joystick steering of the car. By using the technology Virtual Desktop 1, which is a software layer, any desktop application can be represented freely transformable on arbitrary physical and virtual surfaces. Thus, a complete Windows environment can be distributed across all curved and flat surfaces of an interior. The concept is further enhanced by a voice-driven generative AI which helps to summarize documents. A physical and a virtual demonstrator are created to experience and assess the mobile workspace, the well-being of the driver, external influences, and psychological aspects. The physical demonstrator is a 1:1 partial interior mockup with projection-based interactive surfaces. The virtual demonstrator represents the same interior model using the simulation technology TRONIS® and is perceptible through virtual reality (Apple Vision Pro). The demonstrators enable a user-centered design process and facilitate the creation of innovative designs that can be experienced realistically. The technological concepts can also be adapted for other non-driving related activities such as relaxation and entertainment, allowing for the application of many use cases and a broad variety of potential users.
Beutenmüller, FrankReining, NineRosenstiel, RetoSchmidt, MaximilianLayer, SelinaBues, MatthiasMendonca, Daisy
In the automobile industry, ensuring the safety of automated vehicles equipped with the automated driving system (ADS) is becoming a significant focus due to the increasing development and deployment of automated driving. Automated driving depends on sensing both the external and internal environments of a vehicle, utilizing perception sensors and algorithms, and electrical/electronic (E/E) systems for situational awareness and response. ISO 21448 is the standard for Safety of the Intended Functionality (SOTIF) that aims to ensure that the ADS operate safely within their intended functionality. SOTIF focuses on preventing or mitigating potential hazards that may arise from the limitations or failures of the ADS, including hazards due to insufficiencies of specification, or performance insufficiencies, as well as foreseeable misuse of the intended functionality. However, the challenge lies in ensuring the safety of vehicles despite the limited availability of extensive and systematic literature on SOTIF. To address this challenge, a systematic literature review (SLR) on SOTIF for the ADS is performed following the preferred reporting items for systematic reviews and meta-analyses (PRISMA) guidelines. The objective is to methodically gather and analyze the existing literature on SOTIF. The major contributions of this paper are: (i) presenting a summary of the literature by synthesizing and organizing the collective findings, methodologies, and insights into distinct thematic groups, and (ii) summarizing and categorizing the acknowledged limitations based on data extracted from an SLR of 51 research papers published between 2018 and 2023. Furthermore, research gaps are determined, a comparative analysis of methods supporting SOTIF is provided, and supplementary insights from recent publications that address these gaps are presented. Based on the findings, future research directions are proposed.
Patel, MilinJung, RolfKhatun, Marzana
Safety Management Systems (SMSs) have been used in many safety-critical industries and are now being developed and deployed in the automated driving system (ADS)-equipped vehicle (AV) sector. Industries with decades of SMS deployment have established frameworks tailored to their specific context. Several frameworks for an AV industry SMS have been proposed or are currently under development. These frameworks borrow heavily from the aviation industry although the AV and aviation industries differ in many significant ways. In this context, there is a need to review the approach to develop an SMS that is tailored to the AV industry, building on generalized lessons learned from other safety-sensitive industries. A harmonized AV-industry SMS framework would establish a single set of SMS practices to address management of broad safety risks in an integrated manner and advance the establishment of a more mature regulatory framework. This paper outlines a proposed SMS framework for the AV industry based on robust taxonomy development and validation criteria and provides rationale for such an approach.
Wichner, DavidWishart, JeffreySergent, JasonSwaminathan, Sunder
The recent advancements in fields such as sensors, AI, and IoT are majorly impacting the automotive industry. Automated Driving Systems (ADS) are developing rapidly, meaning that SAE J3016 Level 3 and above vehicles are quickly becoming a reality. As a result, maintenance of such systems becomes essential to ensure their safe and efficient operation. Prognostic techniques in particular are crucial to monitor the state of health and predicting the end of life for components. Prognostics engineering is being applied in many industries and for conventional automotive applications, but ADS is new technology, and the prognostics for these systems are still being developed and adapted. In this paper, we first present a review of the most used prognostic techniques across different safety-critical domains such as aerospace, power, and manufacturing. Then, we summarize the main challenges that must be faced to successfully develop novel approaches for prognostics of ADS components and provide a set of recommendations to support future research in the field. Finally, we present a future project consisting of a scenario-based prognostic framework for ADS-equipped vehicles.
Merola, FrancescoHanif, AtharLami, GiuseppeAhmed, QadeerMonohon, Mark
The rapid development of open-source Automated Driving System (ADS) stacks has created a pressing need for clear guidance on their evaluation and selection for specific use cases. This paper introduces a scenario-based evaluation framework combined with a modular simulation framework, offering a scalable methodology for assessing and benchmarking ADS solutions, including but not limited to off-the-shelf designs. The study highlights the lack of clear Operational Design Domain (ODD) descriptions in such systems. Without a common understanding, users must rely on subjective assumptions, which hinders the process of accurate system selection. To address this gap, the study proposes adopting a standardised ISO 34503 ODD description format within the ADS stacks. The application of the proposed framework is showcased through a case study evaluating two open-source systems, Autoware and Apollo. By first defining the assumed system’s ODD, then selecting a relevant scenario, and establishing pass/fail criteria, the framework provides objective data to highlight performance differences between both systems. The proposed methodology provides an unbiased foundation for informed decision-making, promoting the safe and effective integration of ADS technologies.
Chodowiec, EmilZhang, XizheMitchell, JoeBaker, PeterKhastgir, SiddarthaJennings, Paul
As longitudinal Automated Driving System (ADS) technologies, such as Adaptive Cruise Control (ACC), become more prevalent, robust testing frameworks that encompass both simulation and vehicle-in-the-loop (VIL) methodologies are essential to ensure system reliability, safety, and performance refinement. Although significant research has focused on ACC algorithm development and simulation testing, existing VIL dynamometer testing frameworks are typically tailored to specific vehicle models and sensor simulation tools. These highly customized approaches often fail to account for broader interoperability while overlooking energy consumption as a key performance metric. This paper presents a novel modular framework for ACC dynamometer testing, designed to enhance interoperability across a diverse range of vehicle platforms, simulation tools, and dynamometer facilities with a focus on evaluating impacts of automated longitudinal control on the overall energy consumption of the vehicle. The platform leverages a standardized interface to facilitate seamless communication between the simulation environment, vehicle control systems, and the dynamometer. This interface synchronizes virtual test environments with physical dynamometer setups, enabling versatile testing configurations and allowing any vehicle to be evaluated within the simulation environment of choice, tested under the driving scenario of choice. The framework’s architecture and the standard interface are detailed, alongside initial experimental results that demonstrate improvements in testing efficiency, flexibility, and a brief energy performance evaluation. This framework was successful in demonstrating the ACC performance, energy consumption performance, and the propulsion system performance on a single vehicle tested under three different scenarios.
Goberville, NicholasHamilton, KaylaDi Russo, MiriamJeong, JongryeolDas, DebashisOrd, DavidMisra, PriyashrabaCrain, Trevor
Vehicles with SAE J3016TM Level 3 systems are exposed to road infrastructure, Vulnerable Road Users (VRUs), traffic and other actors on roadways. Hence safe deployment of Level 3 systems is of paramount importance. One aspect of safe deployment of SAE Level 3 systems is the application of functional safety (ISO 26262) to their design, development, integration, and testing. This ensures freedom from unreasonable risk, in the event of a system failure and sufficient provisions to maintain Dynamic Driving Task (DDT) and to initiate Minimum Risk Maneuver (MRM), in the presence of random hardware and systematic failures. This paper explores leveraging ISO 26262 standard to develop architectural requirements for enabling SAE Level 3 systems to maintain DDT and MRM during fault conditions and outlines the importance of fail-operability for Level 3 systems, from a functional safety perspective. At a high-level, UN Regulation No. 157 – Automated Lane Keeping Systems (ALKS) is used as a baseline for deriving safety goals for SAE Level 3 systems, to ensure that the operation of Level 3 systems with failure conditions are free from unreasonable risk. This paper discusses the process by which these safety goals are manifested into architectural requirements for safely deploying SAE Level 3 systems. It highlights how fail -operability is a necessary characteristic to sustain DDT to tolerate safety-critical failures (single point, plausible dual point, or common cause failures) and to initiate MRM to bring the vehicle to a safe state or until the driver takes over.
Mudunuri, Venkateswara RajuJayakumar, Namitha
When vehicle accidents occur, investigators rely on event data recorders for accident investigations. However current event data recorders do not support accident investigation involving automated or self-driving vehicles when there is state information that needs to be recorded, for example ADS modes, changes in the ODD that the vehicle operates under, and the various states of vehicle features such as intelligent cruise control, automated lane changes, autonomous emergency braking, and others. In this paper, we propose a model to design new types of event data recorders that supports accident investigations involving automated vehicles when there is state information to be recorded. The model is generic enough to be adapted to any automation level and any set of automated vehicle functional features. The model has been instantiated to a specific ADAS system.
Pimentel, Juan
One of the major issues facing the automated driving system (ADS)-equipped vehicle (AV) industry is how to evaluate the performance of an AV as it navigates a given scenario. The development and validation of a sound, consistent, and transparent dynamic driving task (DDT) assessment (DA) methodology is a key component of the safety case framework (SCF) of the Automated Vehicle – Test and Evaluation Process (AV-TEP) Mission, a collaboration between Science Foundation Arizona and Arizona State University. The DA methodology was presented in earlier work and includes the DA metrics from the recently published SAE J3237 Recommended Practice. This work extends and implements the methodology with an AV developed by OEM May Mobility in four diverse, real-world scenarios: (1) an oncoming vehicle entering the AV’s lane, (2) vulnerable road user (VRU) crossing in front of the AV’s path, (3) a vehicle executing a three-point turn encroaches into the AV’s path, and (4) the AV exhibiting aggressive acceleration through an intersection. The assessment of each scenario navigation by the May Mobility AV is provided by two versions of the DA Score: (1) a simple, single grade that incorporates the applicable DA metrics violations and severity of the violations, (2) the DA Score modified by weighting factors of the scenario complexity and relevance to the AV’s ODD, along with the test method fidelity. The objective of the work is to demonstrate the DA methodology in an actual OEM AV application in a variety of scenarios. The aggregation of DA Scores (unweighted and weighted) is a key input to the AV-TEP SCF that provides safety assurance of the AV under development.
Wishart, JeffreyRahimi, ShujauddinSwaminathan, SunderZhao, JunfengFrantz, MattSingh, SatvirComo, Steven Gerard
The Automated Mobility Partnership (AMP) is a consortium of industry and academic stakeholders dedicated to advancing Automated Driving Systems (ADS) through a comprehensive suite of tools, datasets, and methodologies. The AMP portal integrates events from over 35 million miles of naturalistic driving data including thousands of annotated crashes and near-crashes and a decade of U.S. police-reported crash data curated by the Virginia Tech Transportation Institute. The portal enables data discovery, visualization, processing, and analysis through secured web access. This paper briefly describes the AMP portal and examines its utility in developing and evaluating the safety of ADS using standardized processes. For the examination, we provide examples based on generic automated driving functions, guided by the Safety of the Intended Functionality (SOTIF) framework. The results show that AMP is instrumental in identifying recorded real-world cases in which the hazardous behavior of a system can lead to harm, through the AMP case browser and advanced filtering capabilities. The portal uses the naturalistic driving data to generate essential exposure, controllability, and severity metrics for defining risk-based acceptance criteria and evaluating a system against these criteria. By combining vehicle sensor data with environment and driver face video recordings, AMP can also provide evidence to develop driver glance-based criteria for monitoring systems linked to the automated driving functions. Further, the work elaborates on the potential for AMP data-driven scenario generation to support verification and validation activities, as well as on the potential of the data to provide human reference to support post-release monitoring activities.
Antona-Makoshi, JacoboWilliams, VickiAli, GibranSullivan, KayeTerranova, PaoloKefauver, KevinHatchett, Alex
The rapid development of autonomous vehicles necessitates rigorous testing under diverse environmental conditions to ensure their reliability and safety. One of the most challenging scenarios for both human and machine vision is navigating through rain. This study introduces the Digitrans Rain Testbed, an innovative outdoor rain facility specifically designed to test and evaluate automotive sensors under realistic and controlled rain conditions. The rain plant features a wetted area of 600 square meters and a sprinkled rain volume of 600 cubic meters, providing a comprehensive environment to rigorously assess the performance of autonomous vehicle sensors. Rain poses a significant challenge due to the complex interaction of light with raindrops, leading to phenomena such as scattering, absorption, and reflection, which can severely impair sensor performance. Our facility replicates various rain intensities and conditions, enabling comprehensive testing of Radar, Lidar, and Camera sensors. By simulating real-world rain scenarios, we can measure key performance metrics, including accuracy, response time, reliability, and the rate of false positives and negatives. The Digitrans Rain Testbed employs advanced measurement techniques to characterize rain, including droplet size distribution, intensity, and homogeneity. These parameters are critical for understanding how different sensors react to rain and for optimizing their design and functionality. Our findings demonstrate the importance of realistic rain testing in improving the resilience and reliability of automotive sensors. By addressing the specific challenges posed by rain, we can enhance the safety and trustworthiness of autonomous vehicles. The Digitrans Rain Testbed represents a significant step forward in the development of robust testing methodologies, ensuring that future autonomous vehicles can navigate safely and effectively, even in the most challenging weather conditions. This research underscores the necessity of rigorous, real-world testing in advancing autonomous vehicle technology and paves the way for safer and more reliable automated driving systems.
Feichtinger, Christoph Simon
Lane-keeping is critical for SAE Level 3+ autonomous vehicles, requiring rigorous validation and end-to-end interpretability. All recently U.S.-approved level 3 vehicles are equipped with lidar, likely for accelerating active safety. Lidar offers direct distance measurements, allowing rule-based algorithms compared to camera-based methods, which rely on statistical methods for perception. Furthermore, lidar can support a more comprehensive and detailed approach to studying lane-keeping. This paper proposes a module perceiving oncoming vehicle behavior, as part of a larger behavior-tree structure for adaptive lane-keeping using data from a lidar sensor. The complete behavior tree would include road curvature, speed limits, road types (rural, urban, interstate), and the proximity of objects or humans to lane markings. It also accounts for the lane-keeping behavior, type of adjacent and opposing vehicles, lane occlusion, and weather conditions. The algorithm was evaluated using experimental lidar data collected from driving around Georgia Southern’s campus on one of the behavior tree’s most intensive inputs: oncoming vehicle lane-keeping behavior in two-way, two-lane highways with no physical barriers. Preliminary results include demonstrating one behavior-tree module recognizing an oncoming vehicle’s lane-keeping ability, showing a promising future for interpretable algorithms when using lidar. Existing and novel methods were combined to acquire behavior metrics: Distance to Lane Marking (DTLM), trajectory prediction error (pE), the relative distance between ego- and target vehicles, predicted dividing lane crossings, and the number of vehicle points tracked (NoP).
Soloiu, ValentinMehrzed, ShaenKroeger, LukePierce, KodySutton, TimothyLange, Robin
A significant challenge to the scalability of automated driving systems is the potential unavailability of GPS information for localization. To address this issue, a methodology using a static 2D map of road and lane geometry and vehicle on board sensors data is proposed to ensure reliable localization and navigation for automated vehicles in GPS-denied situations. In this study, a dead reckoning system based on vehicle kinematics is implemented by using onboard sensor data from the vehicle's Controller Area Network (CAN). However, the kinematic dead reckoning estimate has error accumulation, the drift in the dead reckoning position estimate is eliminated by using an arc-length based map matching approach. This innovative approach was tested and validated at various safety-critical intersection scenarios, including four-way intersection, roundabout, slip-lane intersection, and curved road. This approach ensures the continuous and reliable localization of automated vehicles, thereby significantly enhancing their safety and operational reliability in environments with compromised or unavailable GPS signals. The reliability of the map matching approach is quantified by calculating the 95% confidence intervals of error for various scenarios.
Javed, Nur UddinSingh, YuvrajTan, ShengzheAhmed, Qadeer
Systematic testing of Automated Driving Systems (ADS) requires finding relevant test cases. The extraction of critical cases, also called edge or corner cases, from naturalistic driving data is a complex task and often prone to multiple errors. Large Language Models (LLMs) have been employed for virtual testing of ADS in recent years; however, quantitatively benchmarking LLMs’ performance in this task has been barely investigated. In this paper, based on the characteristics of different LLMs, six LLMs were selected for benchmarking the LLMs’ ability to understand ADS functional scenarios on motorways. A novel scenario classification model was introduced to enhance the granularity of data categorization for motorway driving scenarios. Different driving scenarios, described in natural language, were defined for testing the capability of these LLMs to understand various scenarios and convert them into standardized structured data. To perform the benchmarking in a standardized manner, the same prompt engineering and the same dataset were used to interact with each selected LLM and explore the LLMs’ sensitivity to language style variation. For each group of classified driving scenarios, two different formats of natural language descriptions were fed to the LLMs for splitting the testing data. The test results indicate that “gpt-4-1106-preview” model achieves the highest accuracy, followed by “gpt-3.5-turbo”, and “llama3-70b-instruct”, while other LLMs show error consistency between 40% and 60%. The LLMs “gpt-4-1106-preview” and “llama3-70b-instruct” feature lower error consistency in their outputs under the two different formats of natural language, indicating greater robustness in handling varying textual inputs. The outcome of this work contributes to applications of LLMs on scenario extraction for ADS testing.
Zhou, JiZhao, YongqiYang, AixiEichberger, Arno
Scenario-based testing has become a central approach of safety verification and validation (V&V) of automated driving. The standard ISO 21448: Safety of the intended functionality (SOTIF) [1] proposes triggering conditions (e.g., an occluded traffic sign) as a new aspect to be considered to organize scenario-based testing. In this contribution, we discuss the requirements and the strategy of testing triggering conditions in an iterative, SOTIF-oriented V&V process. Accordingly, we illustrate a method for generating test scenarios for evaluating potential triggering conditions. We apply the proposed method in a two-fold case study: We demonstrate how to derive test scenarios and test these with a virtual automated driving system in simulation. We provide an analysis of the testing result to show how triggering condition-based testing facilitates spotting the weakness of the system. Besides, we exhibit the applicability of the method based on multiple triggering conditions and nominal scenarios from an industrial context.
Zhu, ZhijingPhilipp, RobinHowar, Falk
Vehicles equipped with automated driving systems (ADS) may have non-traditional seating configurations, such as rear-facing for front-row occupants. The objectives of this study are (1) to generate biomechanical corridors from kinematic data obtained from postmortem human subjects (PMHS) sled tests and (2) to assess the biofidelity of the Global Human Body Models Consortium (GHBMC) 50th male (M50-O) v6.0 seated in an upright (25-deg recline) Honda Accord seat with a fixed D-ring (FDR) in a 56 km/h rear-facing frontal impact. A phase optimization technique was applied to mass-normalized PMHS data for generating corridors. After replicating the experimental boundary conditions in the computational finite element (FE) environment, the performance of the rigidized FE seat model obtained was validated using LSTC Hybrid III FE model simulations and comparison with experiments. The most recent National Highway Traffic Safety Administration (NHTSA) Biofidelity Ranking System (BRS) method was used to assess the biofidelity of the GHBMC M50-O. The occupant response score for GHBMC was 2.00. The average normalized root mean squared deviation (NRMSD) for seat reaction loads in the GHBMC simulation was less than 10%. Peak T-spine accelerations (avg. BRS = 2.28) and anterior-to-posterior (AP) chest deflection (BRS = 2.61) were underestimated. No rib fractures were predicted in the GHBMC using the default failure strain criteria of 1.8%; however, fractures were predicted in the 3rd rib (both left and right sides) using an updated failure strain criteria of 0.52%. Ramping up the seat back, as indicated by pelvis Z-displacement, was underestimated using a coefficient of contact friction of 0.2 (BRS = 3.65) but improved using a coefficient of 0.1 (BRS = 1.44). Local strain hotspots were predicted at the pubic rami locations in the GHBMC, corresponding well with fracture sites in the PMHS.
Pradhan, VikramRamachandra, RakshitStammen, JasonKracht, CoreyMoorhouse, KevinBolte, John H.Kang, Yun-Seok
While weaponizing automated vehicles (AVs) seems unlikely, cybersecurity breaches may disrupt automated driving systems’ navigation, operation, and safety—especially with the proliferation of vehicle-to-everything (V2X) technologies. The design, maintenance, and management of digital infrastructure, including cloud computing, V2X, and communications, can make the difference in whether AVs can operate and gain consumer and regulator confidence more broadly. Effective cybersecurity standards, physical and digital security practices, and well-thought-out design can provide a layered approach to avoiding and mitigating cyber breaches for advanced driver assistance systems and AVs alike. Addressing cybersecurity may be key to unlocking benefits in safety, reduced emissions, operations, and navigation that rely on external communication with the vehicle. Automated Vehicles and Infrastructure Enablers: Cybersecurity focuses on considerations regarding cybersecurity and AVs from the perspective of V2X infrastructure, including electric charging infrastructure. These issues are examined in the context of initiatives in the US at all levels of government and regulatory frameworks in the UK, Europe, and Asia. Click here to access the full SAE EDGETM Research Report portfolio.
Coyner, KelleyBittner, Jason
A look at who's doing what when it comes to sensors for an L3 world. SAE Level 3 automated driving marks a clear break from the lower levels of driving assistance since that is the dividing line where the driver can be freed to focus on other things. While the driver may sometimes be required to take control again, responsibility in an accident can be shifted from the driver to the automaker and suppliers. Only a few cars have met regulatory approval for Level 3 operation. Thus far, only Honda (in Japan), the Mercedes-Benz S-Class and EQS sedans with Drive Pilot and BMW's recently introduced 7 Series offer Level 3 autonomy. With more vehicles getting L3 technology and further automated driving skills being developed, we wanted to check in with some of the key players in this tech space and hear the latest industry thinking about best practices for ADAS and AV Sensors.
Dinkel, John
Autonomous vehicles (AVs) provide an effective solution for enhancing traffic safety. In the last few years, there have been significant efforts and progress in the development of AVs. However, the public acceptance has not fully kept up with technological advancements. Public acceptance can restrict the growth of AVs. This study focuses on investigating the acceptance and takeover behavior of drivers when interacting with AVs of different styles in various scenarios. Manual and autonomous driving experiments were designed based on the driving simulation platform. To avoid subjective bias, principal component analysis (PCA) and the Gaussian mixture model (GMM) were used to classify driving styles. A total of 34 young participants (male-dominated) were recruited for this study. And they were classified into three driving styles (aggressive, moderate, and conservative). And AV styles were designed into three corresponding categories according to the different driving behavior characteristics. This study reveals that drivers generally prefer driving scenarios with lower risk levels. When drivers perceive safety, they are more likely to adopt more efficient AVs. Additionally, drivers tend to accept AVs that align better with their driving styles. However, it is not found that more aggressive or conservative AVs have a significant impact on their acceptance. Takeover behavior has been identified as a significant mediator of acceptance, with the potential to influence drivers’ perceptions and attitudes. There is a marked decline in acceptance when takeover behavior happens. The results show that regulating takeover behavior is essential for the development of AVs that promote greater acceptance. And this study contributes theoretical support to the development of adaptive AVs.
Li, GuanyuYu, WenlinChen, XizhengWang, WuhongGuo, HongweiJiang, Xiaobei
In the evolving landscape of automated driving systems, the critical role of vehicle localization within the autonomous driving stack is increasingly evident. Traditional reliance on Global Navigation Satellite Systems (GNSS) proves to be inadequate, especially in urban areas where signal obstruction and multipath effects degrade accuracy. Addressing this challenge, this paper details the enhancement of a localization system for autonomous public transport vehicles, focusing on mitigating GNSS errors through the integration of a LiDAR sensor. The approach involves creating a 3D map using the factor graph-based LIO-SAM algorithm, which is further enhanced through the integration of wheel encoder and altitude data. Based on the generated map a LiDAR localization algorithm is used to determine the pose of the vehicle. The FAST-LIO based localization algorithm is enhanced by integrating relative LiDAR Odometry estimates and by using a simple yet effective delay compensation method to enable operation at higher velocities. To robustly fuse LiDAR- and GNSS-based position estimates, an emperical motivated geobased adjustment scheme for the covariances of the two datasources is presented. The performance of the mapping and localization components is validated with real driving data, demonstrating improved stability and accuracy compared to the GNSS-based localization system.
Kramer, MarkusBeierlein, Georg
What are the differences between the traditional automotive companies and “new mobility” players—and even more importantly, who will win? Those are the questions that this report discusses, taking a particular focus on engineering aspects in the automotive/mobility sector and addressing issues regarding innovation, business, market, and regulation Two Approaches to Mobility Engineering was developed with input from nearly 20 industry experts from new and established companies to gain an overview of the intricacies of newcomers and incumbents, to see where the industry stands, and to provide an outlook on where the sector is headed. It provides recommendations as to what respective players should do to master their future and stay at the forefront of mobility innovation. Click here to access the full SAE EDGETM Research Report portfolio.
Beiker, Sven
Items per page:
1 – 50 of 105