Browse Topic: Safety critical systems

Items (544)
Flexible cables are widely used in aircraft and are essential for ensuring the proper functioning of critical systems and flight safety. The design and validation of these cables represent a foundational technology in enabling the transmission of electrical power and signals throughout the entire aircraft. To achieve their intended service life, appropriate protective measures and experimental verification must be implemented. Drawing on the development experience of flexible cables for a specific domestic aircraft model, this paper proposes a combined protection method designed to extend the service life of flexible cables. Experimental analysis demonstrates the practicality and reference value of this approach.
Shi, LiqingHu, HuanghuaGe, Zengwen
This study addresses the challenges of communication delays and system stability in autonomous obstacle avoidance (AOA) systems under next-generation vehicular electronic/electrical architectures. A centralized PON-based architecture is proposed, leveraging XGSPON technology to enhance bandwidth capacity and reduce electromagnetic interference, while rigorously analyzing worst-case in-vehicle communication (IVOC) delays. To mitigate latency impacts, a Software-Defined Networking (SDN)-driven dynamic scheduling strategy prioritizes safety-critical data streams (e.g., environmental perception, motion control) through adaptive resource allocation. Further integrated with a robust H-infinity LQR controller, the co-design framework ensures precise trajectory tracking and suppresses steering oscillations under communication uncertainties. Simulation tests validate the framework's efficacy, demonstrating significant reductions in loop delays and improved dynamic stability in complex scenarios. This work bridges communication efficiency and control robustness, offering a scalable solution for advancing safety-critical autonomous driving systems.
Wang, WenweiHan, MuchenCao, Wanke
This paper investigates the integration of Artificial Intelligence (AI) within radar-based perception for Advanced Driver Assistance Systems (ADAS) under safety considerations aligned with ISO 26262 [1] for functional safety and ISO 21448 (SOTIF) [2] for performance-related safety of the intended functionality. The study evaluates a hybrid architecture in which AI-based perception modules are combined with deterministic supervisory mechanisms to maintain safety compliance. A simulation-based case study using CARLA with radar sensor modeling is presented to compare a deterministic radar perception pipeline with an AI-enhanced approach under nominal and degraded environmental conditions. Performance is evaluated using precision, recall, and F1 score metrics. Results indicate improved recall and F1 score under adverse scenarios for the AI-based perception module, accompanied by a moderate increase in false positives. The paper discusses architectural constraints required to limit non-deterministic behavior, including confidence gating, deterministic supervision, and scenario-based validation. The findings are limited to simulation and are intended to provide preliminary insights into the technical and safety implications of incorporating AI-based radar perception within ISO 26262-compliant ADAS architectures.
Jain, Yesha
The increasing complexity of modern software-intensive systems, particularly in the automotive domain, demands new approaches to bridge the gap between high-level engineering specifications and executable, safety-compliant code. This need is amplified by the rapid transition toward software-defined vehicles, where highly dynamic, updateable software functions significantly enlarge the scope and frequency of engineering activities and require scalable, transparent, and adaptive development processes. While recent advances in Large Language Models have demonstrated strong capabilities in automating tasks such as requirements analysis, code generation, and documentation, their deployment in safety-critical engineering workflows remains challenging due to the need for transparency, traceability, and controlled decision-making. This paper presents a modular multi-agent Large Language Model (LLM) pipeline that automates key steps of the systems engineering lifecycle - from requirement structuring and compliance checking to code and test generation - using specialized LLM agents orchestrated within a unified architecture. A central contribution of this work is the integration of a Human-in-the-Loop subsystem, which introduces configurable review checkpoints at critical stages such as requirements analysis, compliance assessment, code generation, and test creation. The human-in-the-loop module enables engineers to approve, reject, or modify intermediate results, ensuring human oversight, enhancing trustworthiness, and enabling adherence to functional safety standards. The system supports heterogeneous input formats and provides end-to-end traceability through structured outputs and detailed monitoring of performance metrics including model usage, token consumption, and automation efficiency. Initial evaluations indicate that the combination of multi-agent specialization and human-in-the-loop-guided oversight can significantly reduce engineering effort while maintaining the transparency and reliability required for regulated domains. By embedding controllable human supervision into the LLM-driven pipeline, this work offers a practical and scalable architecture for integrating Artificial Intelligence (AI) automation into safety-critical systems engineering processes, with particular relevance to automotive software development.
Padubrin, MarcelKulzer, André CasalGuerocak, Erol
1Systems level and integration testing are an integral part of the design and development of Automated Vehicles (AVs). Measurement science plays a pivotal role in testing to ensure the safe and efficient operation of AVs. This science establishes a common understanding of the units of measurement, crucial in linking human activities. This article describes the significance of measurement in studying interactions between key system technologies in AVs, including AI for perception, sensing, communications, and cybersecurity. To address the complexities of these interactions, a novel, adaptable, and interactive framework called the System Technology Interaction Model (STIM) is introduced. STIM considers both designed and emergent interactions between these system technologies, allowing AV developers to explore tailored experiments with the flexibility of filtering for focused testing. The framework currently models system interactions statically, not in real-time, to define potential relationships and influences during the design phase. The novelty of this framework comes from providing a holistic evaluation that captures testing of interactions between modules in addition to component-level testing, while other frameworks focus on testing individual component behaviors. It also assesses the equality of two interactions, meaning it ensures that two interactions behave the same way for consistent results. Moreover, the framework serves as a valuable tool for AV designers and safety regulators to aid in establishing robust design and assessment approaches. This work highlights the need for a common framework to thoroughly test AVs and gain a holistic understanding of system interactions. Finally, the framework aims to understand how to mitigate potential influences leading to AV malfunctions to advance the development and deployment of safe and reliable Automated Vehicles. The work focuses on level 1 and level 4 automated driving features to simplify the work, although it can be from level 1 to level 5. Although framework performance is inherently difficult to quantify, this framework’s performance can be reflected through its ability to accurately capture system interactions for improved AV design and support a broader usability among AV stakeholders. In the future, the framework can be expanded to include additional elements, such as infrastructure or other vehicles, to analyze information provided to AVs, allowing experts from various domains to collaborate, create similar models, integrate them when feasible, and model the interactions in real-time.
Griffor, Edward R.Arora, MahimaKootbally, ZeidNguyen, Vinh
In today’s global aviation industry, passenger experience is strongly influenced by effective communication. In-flight announcements, often limited to English and a single local language, can create confusion and stress for international travelers who may not be fluent in either. This communication gap not only impacts passenger comfort but also poses potential risks in conveying time-sensitive or safety-critical information. Recent advances in Generative Artificial Intelligence (GenAI), particularly in speech recognition, neural machine translation, and naturalistic text-to-speech, provide a pathway to overcome these challenges. This paper explores the concept of real-time multilingual in-flight announcements delivered in each passenger’s preferred language through connected headphones or personal devices. The proposed system architecture integrates speech-to-text conversion, language translation, and speech synthesis with aircraft infotainment platforms. Potential applications range from pre-generated multilingual safety messages to long-term visions of fully personalized, real-time translations with minimal latency. Benefits include improved inclusivity, accessibility for hearing-impaired passengers, and enhanced brand differentiation for airlines. Challenges such as regulatory certification, translation accuracy, latency constraints, and hardware integration must be addressed. Beyond aerospace, this capability has cross-domain relevance in automotive, railways, and public services, making it a promising area for future customer experience innovations.
Mishra, AshwiniKature, KartikPatil, Ashish
Aerospace products operate within highly complex, safety-critical environments and endure extended lifecycles, often spanning decades. Sustaining their operational value requires rigorous management of Safety, Reliability, and Availability (SRA), while global Environmental, Social, and Governance (ESG) mandates demand parallel progress toward sustainability goals. This paper introduces an AI-driven strategy that integrates these dual imperatives—Sustenance Management and Sustainability Management—within a unified Product Lifecycle (PLC) framework. The proposed approach leverages Artificial Intelligence across five PLC phases: Generative Design, Detailed Design & Verification, Manufacturing & Industrialization, Operations & Maintenance, and End-of-Life Circularity. Anchored by a certified Digital Thread, this framework ensures seamless, auditable data flow from concept to disposal. Using Life-Limiting Parts (LLPs)—such as high-stress turbine discs—as a case study, the paper demonstrates how AI interventions enhance operational efficiency while reducing embedded carbon emissions. For example, Generative AI optimizes component geometry for performance and material efficiency, Physics-Informed Machine Learning (PIML) improves Remaining Useful Life (RUL) predictions for certification readiness, and predictive analytics extend Time-on-Wing (ToW), deferring Scope 3 emissions from replacement manufacturing. At end-of-life, AI-guided valuation of Used Serviceable Material (USM) enables circularity and compliance with ISO 14067 and ISO 14040/14044 standards. The paper also discusses sustainability metrics such as Design Simulation Energy Intensity (DSEI) and the Sustainable AI Quotient (SAIQ) [25], to address the AI-energy paradox, ensuring that digital transformation remains net-positive for environmental stewardship. By positioning sustenance as the most immediate lever for sustainability, this AI-led framework delivers measurable improvements in lifecycle cost, operational resilience, and carbon footprint reduction. The discussion concludes with challenges in data governance, regulatory compliance, and model explainability, offering mitigation strategies for safe and scalable adoption.
Srinivasan, KarthikG.V.V., Ravi KumarVaderahobli, Devaraja HollaBhate, UjwalVeluri, Sastry
This paper presents an automated framework for security compliance and quality assurance in DevSecOps CI/CD pipelines, specifically designed for safety-critical avionics software. The framework integrates regulatory compliance checks, security validation, and robust verification directly into the software development lifecycle, supporting continuous integration and delivery for aerospace applications. Automated processes such as code compilation, coding standards compliance, Cyclomatic Complexity Measurement, Sources Line of Code and CRC validation on target hardware are seamlessly orchestrated to maintain consistency and reliability. The system generates comprehensive compliance reports, highlights coding standard violations and security issues, and notifies relevant stakeholders to facilitate timely resolution and corrective actions. As new code is checked in, the framework automatically initiates all verification and compliance tasks, ensuring that every software update is thoroughly validated without manual intervention. Daily automated testing and coding standards checks are performed to maintain ongoing software quality and compliance. By automating key verification and compliance activities, the framework minimizes human error and supports efficient regulatory compliance throughout the development process. Integration of these capabilities within DevSecOps pipelines enables rapid, repeatable, and auditable software releases, significantly reducing manual effort and accelerating delivery of high-quality builds to customers. The framework enhances digital verification, validation, and certification readiness by providing comprehensive evidence required for regulatory audits, ultimately improving overall project assurance and reducing technical debt for aerospace software teams. These automation techniques collectively help organizations achieve verification processes of DO-178C standards more effectively, ensuring that safety-critical software meets stringent industry requirements while streamlining the certification process, reducing time-to-market, and enabling faster deployment of reliable solutions to end users and stakeholders.
Bhagwat, Shashank RaviChangappa, Naveen KumarNath, Sunny
Why ADAS validation can't be solved with more miles alone. Modern advanced driver assistance systems (ADAS) are expected to operate reliably across an almost limitless range of real-world conditions, including changing weather, low lighting, unpredictable traffic behavior, and sensor noise. Validating performance across that level of variability has become one of the most demanding parts of ADAS development. Physical road testing, or even large-scale simulation, alone cannot provide sufficient coverage to meet these demands. This challenge is driven by increasing system complexity. Modern ADAS platforms rely on machine-learning-based perception, multi-sensor fusion, and tightly integrated software architectures that must interpret complex sensor data in real time. Each additional sensing modality, software update, or feature expansion drives a significant validation effort and, in many cases, increases the number of scenarios that must be evaluated.
Kuehnke, Lutz
This document provides methods and techniques for implementing a reliability program throughout the full life cycle of a software product, whether the product is considered as standalone or part of a system. This document is the companion to the Software Reliability Program Standard [JA1002]. The Standard describes the requirements of a software reliability program to define, meet, and demonstrate assurance of software product reliability using a Plan-Case framework and implemented within the context of a system application. This document has general applicability to all sectors of industry and commerce and to all types of equipment whose functionality is to some degree implemented by software components. It is intended to be guidance for business purposes and should be applied when it provides a value-added basis for the business aspects of development, use, and sustainment of software whose reliability is an important performance parameter. Applicability of specific practices will depend on the reliability-significance of the software, application domain, and life cycle stage of the software. Following guidelines in this document does not guarantee required reliability will be achieved, or that any certification authority will accept the results as sufficient evidence that requisite reliability has been achieved. Following guidelines in this document will provide insight into what level of reliability has been achieved. With proper customer, certification authority, and supplier negotiation and interaction in accordance with these guidelines, it is more likely that the achieved reliability will be acceptable.
G-41 Reliability
Developing high-integrity software is a complex process that involves meeting strict standards across various industries. For instance, in the avionics sector, the DO-178C Design Assurance Level A (DAL-A) sets the highest level of rigor, requiring comprehensive evidence that the software will perform its intended safety functions. Modern avionics systems are made up of hardware and software from different vendors, all integrated by prime contractors. By achieving modularity in these systems, we can reduce interface complexity, manage version control, address supply chain vulnerabilities, and significantly lower recertification costs. To support a high degree of integration and software reuse in avionics systems, certain architectural elements are necessary. These include a certified Real-Time Operating System (RTOS), open standards consortia like FACE® and MOSA, multicore partitioning strategies, deterministic networking, and hypervisor-based virtualization. The role of a certified RTOS, for example, is crucial in ensuring the reliable and efficient operation of safety-critical software components. Open standards consortia, on the other hand, facilitate the development of interoperable systems, while multicore partitioning strategies enable the efficient use of system resources. The use of deterministic networking and hypervisor-based virtualization also plays a key role in enabling the integration of multiple systems and reducing the complexity of system design. By leveraging these technologies, we can create a 'certify once, deploy anywhere' paradigm, which reduces development timelines, lowers lifecycle costs, and positions safety-critical software components for reuse across heterogeneous platforms. This approach not only improves the efficiency of system development but also enhances the reliability and safety of the resulting systems. In essence, the development of high-integrity software for avionics systems requires a comprehensive approach that considers the complex interactions between hardware and software components. By adopting modular architectures and leveraging open standards, certified RTOS, and advanced networking and virtualization technologies, we can create systems that are not only safe and reliable but also efficient and cost-effective. This, in turn, can help reduce the risks associated with system development and deployment, while also improving the overall performance and safety of the resulting systems.
Wildes, GreggGilliland, Gary
This paper introduces a robust supervised machine learning framework for estimating helicopter gross weight during the takeoff phase. The methodology leverages high-fidelity datasets from Airbus's global in-service fleet to ensure a reliable training foundation. At the core of the approach is a long short-term memory recurrent neural network, supported by a patented data-curation pipeline designed to maintain high data integrity. To align with rigorous aviation safety standards, the study outlines a learning assurance process compliant with EASA guidelines, specifically addressing safety assessment objectives for machine learning. A central innovation is the characterization and monitoring of the model's operational design domain through multidimensional functional principal component analysis. By projecting high-dimensional, non-linear sensor data into a manageable tabular subspace, this approach enables the definition of safety envelopes using explainable and efficient classical methods. Validated against diverse real-world flight profiles, the framework demonstrates high predictive accuracy, marking a significant milestone toward deploying the model on airborne targets for safety-critical functions such as condition-based maintenance.
Mechouche, AmmarFabre, LouisValot, Nicolas
Automated Vehicles (AV) pose new challenges in road safety, multimodal interaction, and urban planning, requiring a holistic approach that prioritizes sustainability and protects all road users. The KASSA.AST project addresses this by deploying and evaluating an automated shuttle in southern Austria on three routes. The study area is a Park & Ride zone near a train station, enabling seamless transfers and higher transit use. To assess the safety impacts of the automated shuttle, four Mobility Observation Boxes (MOBs) were deployed. These AI-based systems detect and classify road users, track their trajectories and geospatial coordinates, and identify safety-critical events via Surrogate Safety Measures (SSMs). Over 10 days, a trajectory dataset captured interactions among vehicles and the shuttle. The resulting real-world dataset is a core contribution. This dataset underpins microscopic behavior modeling. Trajectory pairs yield car-following and interaction metrics (relative distance, relative speed, acceleration) to calibrate custom models for realistic mixed traffic. Simulations generate a structured interaction database with time spans, trajectories, conflict points, and SSMs (such as Time-to Collision—TTC, Post-Encroachment Time—PET, and Deceleration-rate-to-avoid-crash—DRAC). These outputs support detailed analysis of shuttle interactions, including near misses. To reveal patterns, clustering identified three interpretable safety-relevant regimes: (i) a low-demand background regime (n = 96) with low speeds and near-zero deceleration demand, (ii) a fast-and-tight regime (n = 33) with reduced TTC, elevated critical-event speeds, and high DRAC/Modified (M)DRAC demand, and (iii) an AV-regulated regime (n = 10) dominated by the shuttle as adversary, showing short TTC but stable moderate speeds (~4 m/s) and conservative headway policies. Ensemble-tree supervised learning reproduced these regimes with high accuracy and revealed that critical-event speeds and counterpart headway are the strongest discriminators, while AV role metadata contributes marginally. This integrated approach—linking field data, behavior modeling, simulation, and machine learning—provides a robust framework for assessing AV safety in urban contexts.
Losada Arias, ÁngelRosenkranz, PaulHula, AndreasAleksa, MichaelSaleh, PeterErdelean, Isabela
Software is driving major changes in automotive design. The rise of the software-defined vehicle, combined with increasing automation, is dramatically increasing software complexity. Automotive teams must deliver larger volumes of safety-critical code on tighter schedules while maintaining strict compliance with functional safety standards. In this environment, effective testing and verification are more important than ever. Development teams are increasingly adopting shift-left testing strategies, where defects are identified early at the unit level before software progresses down the development pipeline. Detecting issues earlier reduces risk, lowers remediation costs, and improves development velocity.
Camacho, Ricardo
Vision-language models (VLMs) are increasingly used in autonomous driving because they combine visual perception with language-based reasoning, supporting more interpretable decision-making, yet their robustness to physical adversarial attacks, especially whether such attacks transfer across different VLM architectures, is not well understood and poses a practical risk when attackers do not know which model a vehicle uses. We address this gap with a systematic cross-architecture study of adversarial transferability in VLM-based driving, evaluating three representative architectures (Dolphins, OmniDrive, and LeapVAD) using physically realizable patches placed on roadside infrastructure in both crosswalk and highway scenarios. Our transfer-matrix evaluation shows high cross-architecture effectiveness, with transfer rates of 73–91% (mean TR = 0.815 for crosswalk and 0.833 for highway) and sustained frame-level manipulation over 64.7–79.4% of the critical decision window even when patches are not optimized for the target model. We further find asymmetric architecture-level risk, with Dolphins most vulnerable to incoming transfer attacks (VS = 0.82) and LeapVAD producing the most transferable patches (TO = 0.882), while models sharing CLIP-based vision encoders exhibit stronger bidirectional transfer. Overall, these results indicate that current VLM-based autonomous driving systems share systematic cross-architecture weaknesses that architectural diversity alone does not resolve, underscoring the need for defenses and design principles that explicitly account for transferability in safety-critical deployment.
Fernandez, DavidMohajerAnsari, PedramSalarpour, AmirPese, Mert D.
The proven usefulness of large language models (LLMs) as tools for software development and the recent rapid increase in their capabilities have made it possible and attractive to extend their scope of application to almost all tasks in the engineering of complex and even safety-critical systems. While these tools promise substantial efficiency gains and improved engineering productivity, they remain prone to errors, and the generated artifacts may not meet the stringent quality requirements for safety-critical systems. In this paper, we systematically analyze potential applications of LLMs throughout the engineering lifecycle of safety-critical systems and identify associated risks as well as practical approaches to risk mitigation. We classify LLM-supported use cases according to LLM autonomy, impact, and artifact observability, and compare the corresponding mitigation strategies with established approaches used for traditional engineering automation. In addition, we examine the cultural and psychological aspects influencing trust in LLM-based engineering tools and the risks of both over-reliance and unwarranted rejection. Our analysis shows that LLMs can provide substantial benefits as engineering support tools, but they also represent a significant source of development risk if applied without appropriate safeguards. Based on these findings, we propose guidelines for responsibly using LLM-based tools in the engineering of safety-critical systems.
Thomas, CarstenWagner, Michael
Introducing machine learning (ML) into safety-critical systems presents a fundamental challenge, as traditional safety analysis techniques often struggle to capture the dynamic, data-driven, and non-deterministic behavior of learning-enabled components. To address this gap, the Machine Learning Failure Mode and Effects Analysis (ML FMEA) methodology was developed as an open-source framework tailored to ML-specific risks. This paper reports on the maturation of ML FMEA from an initial conceptual framework to a proven, practice-driven methodology. We make four primary contributions. First, we extend the ML FMEA pipeline with two new stages: a “Step Zero” for problem definition and system-level hazard analysis, and a “Step 5” for constructing ground truth or reward signals. Autonomous vehicle and humanoid robot applications are presented to illustrate the practical application and safety benefits of these additions. Second, we introduce tailored Severity, Occurrence, and Detection criteria for ML risk assessment, resolving ambiguities encountered when applying traditional FMEA metrics to ML development processes. Third, we demonstrate systematic alignment between ML FMEA artifacts and requirements from ISO/PAS 8800, ISO 21448 (SOTIF), ISO/TS 5083, ISO/IEC TR 5469, and UL 4600, providing a bridge between ML development practices and safety certification expectations. Fourth, we present cross-industry perspectives spanning automotive, aerospace, industrial robotics, and defense, highlighting deployment pathways and best practices for domain-specific adaptation. Through open-source collaboration and cross-industry validation, the ML FMEA has matured into a practical toolset that enables safety-informed ML workflows, supporting auditable, repeatable, and risk-aware development of learning-enabled systems.
Schmitt, PaulShinde, ChaitanyaDiemert, SimonPennar, KrzysztofSeifert, BodoPoh, JustinLopez, JerryMannan, FahimMohammed, MajedChalana, AkshayWadhvana, NeilWagner, Michael
Ensuring safe operation and reliable control of mobility systems remains a significant challenge, particularly for nonlinear and high-dimensional applications subject to external disturbances with hard constraints and limited computational resources in real-time implementations. A reference governor (RG) can enforce constraints using an add-on scheme that preserves the pre-stabilizing controller while balancing the need to satisfy other requirements, including reference tracking and disturbance rejection. Thus, in this paper, we exploit RG-based strategies focusing on nonlinear mobility systems. While the method is generalizable to other applications, such as waypoint following for autonomous driving, the flight dynamics of a quadrotor system with twelve states are used as an example. We implement a disturbance rejection RG to satisfy safety constraints and track set points. To handle nonlinearity, we propose an optimal strategy to quantify the maximum deviation between the nonlinear plant and the linearized prediction model, which are then incorporated into the RG’s disturbance bounds for safety margins. Simulation results demonstrate that the RG guarantees the satisfaction of constraints while maintaining desirable tracking performance and being computationally feasible. Furthermore, the framework effectively mitigates the impact of disturbances, thereby enhancing system robustness. The findings confirm that the RG can be successfully applied to complex nonlinear aerial vehicles, providing a promising solution for the extensions to other safety-critical mobility applications.
Dong, YilongLi, Huayi
The emergence of AI-driven autonomy in modern vehicles marks a pivotal evolution in transportation, but it also introduces deep system-level vulnerabilities that span from sensor interface tampering to compute unit compromise and untrusted communication links. Autonomous vehicles (AVs) operate as distributed intelligent systems, relying on real-time data exchange between zonal gateways, AI compute platforms, and safety-critical electronic control units (ECUs). These interactions must be protected from hardware-based attacks that could compromise functional safety, system integrity, or operational availability. The deployment of AI-driven AVs introduces unprecedented levels of complexity. Sensors, AI compute clusters, and actuators communicate over multiple interfaces including Ethernet, PCIe, and MIPI, exposing vehicles to potential cybersecurity attacks. This paper proposes a unified, layered hardware security architecture tailored for AI-powered automated vehicles. Grounded in current automotive Ethernet and zonal architectures, it provides end-to-end trust using hardware interface security, accelerated- cryptography, and SRAM PUF-based key provisioning. All security primitives are anchored to hardware root of trust, delivering cryptographic identity, secure boot enforcement, and trusted key storage across the entire vehicle lifecycle.
C Suriyanarayanan, PavIacob, Radu
Patching vulnerabilities in safety-critical domains such as automotive and aerospace is costly and complex. A small code modification can trigger a complete rebuild, producing a binary with widespread changes. This inflates patch size, complicates regression testing, and makes over-the-air (OTA) updates inefficient, as traditional binary patches often replace large portions of the executable. We present a binary rewriting–based experiment that shows the feasibility of a patch that updates only the affected bytes by computing the impact of a code change at the binary level. This produces minimal, localized patches rather than regenerated executables. The preliminary experiment shows that a single source change, which leads to thousands of modified bytes after recompilation, can be captured with only a few bytes using our method. For automotive and aerospace systems, this technique reduces patch size, conserves bandwidth, and minimizes disruption to certified software, offering a promising direction for efficient and reliable vulnerability remediation.
Awadhutkar, PayasSauceda, JeremiasTamrawi, Ahmed
Traffic roundabouts, as complex and safety-critical road scenarios, present significant challenges for autonomous vehicles. In particular, predicting and managing dilemma zone (DZ) encounters at roundabout intersections remains a pivotal concern. This paper introduces an AI-driven system that leverages advanced trajectory forecasting to anticipate DZ events, specifically within traffic roundabouts. At the core of our framework is a modular, graph-structured recurrent architecture powered by graph neural networks (GNNs). By modeling agent interactions as a dynamic graph, our approach integrates heterogeneous data sources - including semantic maps - while capturing agent dynamics with high fidelity. This GNN-based forecasting model enables accurate prediction of DZ events and supports safer, data-driven traffic management decisions for both autonomous and human-driven vehicles. We validate our system on a real-world dataset of roundabout intersections, where it achieves high precision with an exceptionally low false positive rate of 0.1. Our work highlights the potential of AI and graph-based deep learning methods for advancing roundabout safety, offering a robust step toward more reliable and intelligent intersection management in the era of autonomous transportation.
Lu, DuoSatish, ManthanFarhadi, MohammadChakravarthi, BharateshYang, Yezhou
Autonomous platforms such as self-driving vehicles, advanced driver-assistance systems (ADAS), and intelligent aerial drones demand real-time video perception systems capable of delivering actionable visual information at ultra-low latency. High-resolution vision pipelines are often hindered by delays introduced at multiple stages—sensor acquisition, video encoding, data transmission, decoding, and display—undermining the responsiveness required for safety-critical decision making. This study introduces a holistic system-level optimization framework that systematically reduces end-to-end video latency while maintaining image fidelity and perception accuracy. The proposed approach integrates hardware-accelerated encoding, zero-copy direct memory access (DMA), lightweight UDP-based RTP transport, and GPU-accelerated decoding into a unified pipeline. By minimizing redundant memory copies and software bottlenecks, the system achieves seamless data flow across hardware and software boundaries. Evaluations demonstrate a latency reduction from a baseline of 45.3 milliseconds to an optimized 23.5 milliseconds, representing a 48.1% improvement without sacrificing spatial resolution or detection robustness. Under optimized configurations, the framework sustains frame rates above 60 FPS at both Full HD and 4K resolutions, with frame drop rates held to approximately 3%. Perceptual evaluation further confirms that object detection accuracy consistently exceeds 91% within the <35 ms latency range, while collision-prediction delays are reduced to below 12.4 ms, ensuring timely responses in dynamic scenarios. These improvements collectively validate the critical importance of hardware-software co-design for embedded vision systems. The results highlight that ultra-low-latency perception is achievable on edge platforms when pipelines are designed with cross-layer optimization, bridging sensor interfaces, video codecs, network transport, and GPU computation. The proposed architecture provides a scalable foundation for future embedded vision deployments in autonomous driving, robotics, and unmanned aerial systems, where low latency is a non-negotiable requirement for safety, reliability, and operational efficiency.
Indrakanti, Rama Kiran Kumar
The intersection of Safety of Intended Functionality (SOTIF) and Functional Safety (FuSa) analysis of driving automation features has traditionally excluded Quality Management (QM) components from rigorous safety impact evaluations. While QM components are not typically classified as safety-relevant, recent developments in artificial intelligence (AI) integration reveal that such components can contribute to SOTIF-related hazardous risks. Compliance with emerging AI safety standards, such as ISO/PAS 8800, necessitates re-evaluating safety considerations for these components. This paper examines the necessity of conducting holistic safety analysis and risk assessment on AI components, emphasizing their potential to introduce hazards with the capacity to violate risk acceptance criteria when deployed in safety-critical driving systems, particularly in perception algorithms. Using case studies, we demonstrate how deficiencies in AI-driven perception systems can emerge even in QM-classified components, leading to unintended functional behaviors with critical safety implications. By bridging theoretical analysis with practical examples, this paper argues for the adoption of comprehensive FuSa, SOTIF, and AI standards-driven methodologies to identify and mitigate risks in AI components. The findings demonstrate the importance of revising existing safety frameworks to address the evolving challenges posed by AI, ensuring comprehensive safety assurance across all component classifications spanning multiple safety standards.
Abbaspour, Ali RezaMahadevan, ShabinZwirglmaier, KilianStafford, Jeff
This paper presents the first systematic examination of Large Language Model (LLM) capabilities for automating the development of Failure Mode and Effects Analysis (FMEA) utilizing architectural diagrams as input. Although prior research has examined LLMs for FMEA tasks, our methodology incorporates innovative aspects, such as the direct analysis of architectural diagrams for component extraction, prediction of failure modes, causes, estimation of risk and a human-in-the-loop (Hu-IL) validation framework. We examine the capability of general-purpose LLMs to accurately automate the creation of FMEA by formulating a methodology that extracts components and signals from architectural diagrams, conducts automated component classification, and produces a comprehensive FMEA form sheet encompassing Severity, Occurrence, and Detectability (S/O/D) scoring. Our methodology is grounded in structured prompt engineering theory, utilizing scope bounding techniques to reduce hallucination while preserving extraction accuracy. Assessment against expert-validated ground truth (over 12 years of functional safety experience) across several automotive system diagrams indicates a 92% accuracy rate for signal extraction and component categorization, with S/O/D scoring obtaining an accuracy range of 70–90%. The results demonstrate substantial potential to reduce manual FMEA development processes (as compared to prior studies). Key limitations include sensitivity to diagram complexity and quality, as inadequately designed diagrams markedly affect output precision along with the inability of LLMs to create new detection measures reliably. Our Hu-IL validation process mitigates these limitations while preserving the advantages of automation. This study provides baseline performance indicators for LLM-based FMEA automation and demonstrates significant potential in transforming traditional FMEA workflows in safety-critical industries.
Diwakaruni, Sundara Sasi KoushikKrishnamurthy, Anunay
Military and aerospace applications have become increasingly complex real-time systems. Multi-core SoCs improve performance but create new challenges in maintaining and verifying deterministic behavior. Connected systems require exceptional security to protect code from external cyberattacks. Evolving functional safety and reliability standards that keep raising the bar mean developers need to begin comprehensive testing sooner if they are going to meet tighter design schedules. Finally, certifying these complex systems has become even more difficult. To help OEMs meet these challenges, the RISC-V architecture has been designed with unique capabilities that support reliability and security in the development of safety-critical applications. With its open instruction set architecture, modularity, and extensibility, RISC-V accelerates the design of functionally safe systems while reducing the complexity, cost, and risk associated with certification to standards like DO-178C and ISO 26262.
Software-defined vehicles are those whose functionalities and features are primarily governed by software, thus allowing continuous updates, upgrades, and the introduction of new capabilities throughout their lifecycle. This shift from hardware-centric to software-driven architectures is a major transformation that reshapes not only product development and operational strategies but also business models in the automotive industry. An SDV operating system provides the base platform to manage vehicle software and enable those advanced functionalities. Unlike traditional embedded or general-purpose operating systems, it is designed to meet the particular demands of modern automotive architectures. Reliability, safety, and security become crucial because even minor faults may have serious consequences. Key challenges to be handled by the SDV OS include how to handle software bugs, perform real-time processing, address functional safety and SOTIF compliance, adhere to regulations, minimize attack surface exposure, and protect against remote access and data breaches. This is achieved via sound architectural principles, including a CSM for fine-grained access control, a lean and minimal kernel to reduce vulnerabilities, secure and efficient inter-process communication, and user-level drivers to provide better fault isolation. The key novelty of this approach rests on the fact that it uses open-source kernels, libraries, and tools that guarantee flexibility, clarity, and community-driven innovation. It provides a flexible runtime environment and OS-level isolation using virtualization, safe hardware sharing, and adherence to safety standards to set up the SDV OS as a resounding, secure, and future-ready base for next-generation automotive systems.
Khan, Misbah UllahGupta, Vishal
This SAE Aerospace Recommended Practice (ARP) defines lightning strike zones and provides guidelines for locating them on particular aircraft, together with examples. The zone definitions and location guidelines described herein are applicable to Parts 23, 25, 27, and 29 aircraft. The zone location guidelines and examples are representative of in-flight lightning exposures.
AE-2 Lightning Committee
Treat foundational AV safety like seatbelts - make it non-proprietary and universal. An open safety stack, shared scenarios, benchmarks, and core validation tools can speed certification, reduce duplicated V&V and build public trust while preserving vendor differentiation. The bottleneck isn't compute - it's verification. Autonomous features are shipping in more vehicles and markets, but the gating factor is no longer raw compute. It's whether developers and regulators can verify systems against requirements and validate them against real-world operating design domains (ODDs) with confidence and repeatability. Today, many safety-critical components, from scenario libraries to pass/fail criteria, live in proprietary silos. That fragmentation slows regression testing, complicates regulator audits across regions, and duplicates effort across the industry. The result is an expensive, bespoke path to certification for every program and geography.
Musa, MohammadKhawaja, Muhammad Zain
The modern vehicle is no longer a mechanical appliance—it has transformed into a software-defined cyber-physical system, integrating OTA updates, cloud-connected diagnostics, V2X services, and telematics-driven personalization. While this evolution promises unprecedented value in consumer experience and fleet operations, it also surfaces a dramatically expanded and evolving attack perimeter, especially across safety-critical ECUs and communication buses. Cyber vulnerabilities have shifted from isolated IT threats to real-time, embedded exploits. Controller area network (CAN), the backbone of vehicle bus systems, remains intrinsically insecure due to its lack of authentication and encryption, making it highly susceptible to message injection and denial-of-service by low-cost tools. Similarly, OEM implementations of BLE-based passive entry systems have proven vulnerable to replay and spoofing attacks with minimal hardware. In the Indian context, the transition to connected mobility is advancing rapidly under national mandates such as FAME II, PM e-DRIVE, and the National Electric Mobility Mission Plan (NEMMP). However, field-level assessments of Indian and international vehicle models—including ICE cars, electric two-wheelers, and fleet EVs—reveal critical gaps in CAN architecture connected to critical ECUs, Cloud API and Endpoints and RF controls. Notably, many of these vulnerabilities materialized after vehicle homologation, propagating through OTA updates or third-party app integrations. This reality underscores the inadequacy of static, pre-market cybersecurity assessments in effectively mitigating operational risk. This paper introduces a novel, scalable methodology that addresses this critical gap by enabling empirical, attack-informed validation, aligned with both Indian priorities and international best practices
Shah, RavindraAwasthi, Vibhu VaibhavKarle, Ujjwala
The transition to electric vehicles (EVs) has brought about significant advancements in automotive technology, with inverters playing a crucial role in converting DC power from the battery to AC power for the electric motor. Ensuring the functional safety of these inverters is paramount, as any failure can have severe implications for vehicle performance and passenger safety. This case study explores the successful implementation of ISO 26262 standards in the development and validation of EV traction inverters. This paper begins by outlining the functional requirements and safety goals specific to EV inverters, followed by a detailed analysis of the potential hazards and risks associated with their operation. Using ISO 26262 as a framework, we describe the systematic approach taken to identify, assess, and mitigate these risks. Key methodologies such as Hazard Analysis and Risk Assessment (HARA), Failure Mode and Effects Analysis (FMEA), and Fault Tree Analysis (FTA) are employed to ensure comprehensive safety coverage. This case study showcases the integration of key safety mechanisms—such as redundancy, fault tolerance, and real-time monitoring—to significantly enhance the reliability and robustness of the inverter system. It also explores the challenges encountered during implementation, including the complexity of managing safety critical high-voltage systems and the need to stay aligned with evolving safety standards.
Ramachandra, ShwethaV, Sushmitha
Accurate trajectory prediction of traffic agents is critical for enabling safer and more reliable autonomous driving, particularly in urban driving scenarios where close-range interactions are most safety critical. High-definition (HD) and standard-definition (SD) maps play a vital role in this process by providing lane topology and directional cues for forecasting agent movements. However, HD maps are expensive and resource-intensive to create, often requiring specialized sensors, while SD maps lack the precision needed for reliable autonomous navigation. To address this, we propose a novel framework for trajectory prediction that leverages online reconstruction of HD maps using vehicle-mounted cameras, offering a scalable and cost-effective alternative. Our method achieves improvements in predicting accuracy, particularly in close-range scenarios, the most crucial for urban driving, while also performing robustly in settings without pre-built maps. Furthermore, we introduce a new safety-aware evaluation metric that incorporates heuristic weights based on agent relevance and distance, enhancing traditional metrics like Brier-minFDE with a stronger focus on safety-critical scenarios. Extensive experiments demonstrate that our approach outperforms state-of-the-art map-less methods, particularly in close-range prediction, while our proposed metric establishes a more domain-relevant benchmark for assessing trajectory prediction in autonomous driving.
Upreti, MinaliGirijal, RahulB A, NaveenKumarThontepu, PhaniGhosh, ShankhanilChakraborty, BodhisattwaBhardwaj, Ritik
Crash test plays a very crucial role in determining the passenger safety along with driver safety in most modern vehicles. This has become a prominent factor for many buyers to choose a safe car. During crash test, many components tend to fail. Amongst them, the major safety critical component which hampers the drivability of a vehicle is Wheel and Tyre Assembly. With the introduction of low aspect tyres, the failure rate of these assemblies has increased. A very high importance is given to ensure these parts withstand the subject load as it is directly related to function of vehicle. Many methods are available to test the Wheel and Tyre assembly to ensure they pass the crash criteria. We have developed a novel test method which can simulate the crash pattern in the rig/bench level. The method employs a mechanical actuator which can be operated at designated load application to ensure the assembly undergoes the anticipated failure. The process is repeated with different types of contact surfaces along with different tyre pressures to ensure all evaluation criteria which are observed at vehicle level are captured and translated to rig level. We have used two different types of contact surfaces which are designed and developed exclusively for this test procedure. The results of these tests are used as benchmark to evaluate the new assemblies. In conclusion, the main advantage with this test procedure is one can predict the crash failure at rig level rather than going to vehicle level test which in turn reduces the cost of vehicle building and testing. Once the failure is predicted at component level corrective actions can be initiated and design improved components can be used for vehicle level test. This will not only help in reducing the lead time as well as improve the safety of the overall vehicle.
Medaboyina, HarshaVardhanSingh, Ram KrishnanSundaram, RaghupathiJithendhar, Ashokan
The rapid evolution of modern automotive systems—powered by advancements in autonomous driving and connected vehicle technologies— pose fundamental challenges to design and integration. A specific challenge of these highly interconnected, software-driven systems is in ensuring their safety while avoiding spiralling costs and development times. This challenge calls for a more structured and rigorous approach to safety assurance than traditional methods. Traditional safety cases tend to take a linear, justification-focused approach that mainly focuses on positive assertions —compliance to safety —while giving limited attention to potential weaknesses, or gaps in supporting evidence. This practice may lead to criticism that such arguments are “too positive,” portraying an overly biased or optimistic view of system safety without sufficiently acknowledging areas of unresolved risk. As a result, conventional approaches for developing a safety case may overlook complex interactions, assumptions, and uncertainties that require critical examination, not default acceptance. As opposed to traditional methods of developing safety cases through justification, the dialectic approach emphasizes critical analysis and scrutiny of weak points using open challenges, counterarguments, and alternative perspectives. It encourages a deliberate effort to explore not just what works in a design, but what might fail— anticipating negative aspects, design vulnerabilities, and areas where safety assumptions may fail. Rather than simply validating assumptions, it aims to uncover hidden flaws, inconsistencies, and evidence gaps that could compromise system safety. Constructing a safety case early in a project, and allowing constructive criticism through dialectic argument, transforms the safety case into a living, questioning tool that evolves with improving system understanding—becoming increasingly transparent, robust, and credible. In the paper, we demonstrate 3SK’s practical application of a dialectic methodology for developing safety cases. By this approach, we were able to pick out important safety gaps that would otherwise have gone unnoticed, hence enhancing the completeness, credibility, and robustness of our safety assurance practices.
Kumar, AmrendraBagalwadi, SaurabhMcMurran, Ross
The work completed on “System level concepts to test and design integrated EV system involving power conversion to satisfy ISO26262 functional safety requirement” is included in the paper. Integrating power conversion and traction inverter subsystems in EVs is currently popular since it increases dependability and improves efficiency and cost-effectiveness. Maintaining safety standards is at danger due to the growing safety requirements, which also raise manufacturing costs and time. The three primary components of integrated EV systems are the PDU, DC-DC converter, and onboard charger. Every part and piece of software is always changing and needs to be tested and validated in an economical way. Since the failure of any one of these components could lead to a disaster, the article outlines the economical approaches and testing techniques to verify and guarantee that the system meets the functional safety criterion.
Uthaman, SreekumarMulay, Abhijit BGadekar, Pundlik
As vehicles evolve toward increased automation and comfort, Power Operated Tailgate (POT) have become a common feature, especially in premium and mid-segment vehicles. These systems, although user-friendly on the surface, involve complex interactions between electronic control units (ECUs), sensors, actuators, and mechanical systems. Ensuring the reliability, safety, and robustness of these features under diverse operating conditions presents a significant validation challenge. Traditional testing methods, which rely heavily on physical prototypes and manual interaction, are often time-consuming, expensive, and prone to human error. Moreover, testing certain safety [3] features, such as anti-pinch or stall protection, under real physical conditions poses inherent risks and limitations. This paper presents a Hardware-in-Loop (HiL)[1] based testing approach for POT [2] systems, offering a safer, faster, and more comprehensive alternative to conventional validation methods. The HiL platform is built around a real-time test environment using Real Time Software, framework, integrated with MATLAB/Simulink [5] based plant models representing motor behaviour, hall sensors, and tailgate dynamics. The ECU under test communicates via CAN [4] and other physical I/Os, while the plant models simulate realistic vehicle responses in real time. The HiL approach enables full automation of functional, diagnostic, and safety validation of the tailgate system including open/close commands, fault injections (open circuit, short faults), latch and sensor logic, and anti-pinch scenarios. This methodology significantly reduces prototype dependence, accelerates ECU software validation, and increases overall test coverage. Results show substantial improvements in fault detection, regression testing efficiency. The proposed solution demonstrates how HiL [1] testing is not only a cost-effective validation method but also a strategic enabler for scalable and safe development of automotive mechatronic systems. This paper concludes by discussing the long-term benefits and future scope of enhancing the HiL setup with remote diagnostics, and seamless integration with other systems. The automotive industry is undergoing a transformation with a growing emphasis on comfort, convenience, and automation. Power Operated Tailgate (POT) have become an integral part of modern vehicles, offering hands-free access, anti-pinch
More, ShwetaGhanwat, HemantShetti, SurajJape, AkshayKulkarni, ShraddhaJagdale, Nitin
The precise validation of radar sensor is necessary due to surging demand for reliable Advanced Driver-Assistance Systems (ADAS) and autonomous driving technologies. Over-the-Air (OTA) Hardware-in-the-Loop approach is the optimal solution for the current challenges facing with traditional on road testing. This approach supports productive, controllable and repetitive environment because of its lab-based setup which will eliminates the drawbacks such as high costs, limited repeatability, safety related issues. Key parameters of radar such as accurate detection of objects, analysis of doppler velocity, range estimation, angle of arrival measurement, can be tested dynamically. And this test setup offers wide range of testing scenarios, including varying distance of target, relative speeds, simulation of objects and environmental effects also supported.OTA provides the flexibility to eliminate the physical test tracks or targets so that developers can simulate the errors, by introducing faults into the systems and validate the compliances as per the industry standards, OTA HIL testing completely reduces development time and costs through enhancing test coverages, which will increase radar performance. This paper describes the system architecture, test plans, experimental results, demonstrate the critical role of OTA HIL in advancing automotive radar workflows and ensuring reliable ADAS and autonomous driving functionalities.
Jadhav, TejasKarle, UjjwalaPaul, HarshitSNV, Karthik
As vehicles are becoming more complex, maintaining the effectiveness of safety critical systems like adaptive cruise control, lane keep assist, electronic breaking and airbag deployment extends far beyond the initial design and manufacturing. In the automotive industry these safety systems must perform reliably over the years under varying environmental conditions. This paper examines the critical role of periodic maintenance in sustaining the long-term safety and functional integrity of these systems throughout the lifecycle. As per the latest data from the Ministry of Road Transport and Highways (MoRTH), in 2022, India reported a total of 4.61 lakh road accidents, resulting in 1.68 lakh fatalities and 4.43 lakh injuries. The number of fatalities could have been reduced by the intervention of periodic services and monitoring the health of safety critical systems. While periodic maintenance has contributed to long term safety of the vehicles, there are a lot of vehicles on the road which are not serviced regularly. This paper aims to fill this critical gap by proposing a system where the government agencies actively collect and monitor vehicle maintenance data and diagnostics data ensuring that all vehicles on the road undergo mandatory periodic servicing to uphold the integrity of safety-critical systems. This paper concludes by proposing a centralized framework for data sharing and proactive monitoring to ensure the sustained performance of safety-critical systems—ultimately reducing preventable road fatalities and improving overall vehicular safety across India.
HN, Sufiyan AhmedKhan, FurqanSrinivas, Dheeraj
As the automotive industry moves from conventional function oriented embedded ECU-based systems to Code-driven system, the core electrical and electronic (E&E) architecture is also being redesigned to support more software-driven functionality. Modern and centralized architectures promise scalability and software-driven flexibility, but they also introduce significant challenges in power distribution—an area that remains underexplored despite its critical role in overall vehicle safety and performance. Our paper aims at the adoption of the traditional power distribution approach for Next Gen vehicle architecture. It requires a fresh look at how power is distributed. In a novel E&E architecture, a single power harness supplies battery voltage to each zone. If there's a failure or voltage drop, it can affect multiple functions within that zone at once, and management of voltage regulation, thermal dissipation, and EMI/EMC compliance becomes crucial. Adding to the complexity, safety-critical systems need power redundancy and isolation to meet Functional Safety standards. Mixed-criticality designs further complicate power management, as they demand strict segregation between critical and non-critical power loads to preserve functionality under fault conditions. The integration of software-controlled power switching and dynamic power management introduces additional failure modes previously unrecognized. Consequently, real-time monitoring and power fault detection are becoming vital for maintaining the health of a vehicle’s power distribution network. Traditional diagnostics, such as On-Board Diagnostics, offer limited checks and periodic alerts, primarily for engine and transmission faults. Advanced capabilities are essential. Through an investigative lens, this paper identifies the key bottlenecks in power distribution and proposes areas for further research and innovation aimed at ensuring resilience, safety, and performance in next-generation vehicles.
Borole, AkashWarke, UmakantChakra, PipunJaisankar, Gokulnath
System robustness and performance are essential considerations in controller design to ensure reference tracking, disturbance rejection, and resilience to modeling uncertainties. However, guaranteeing that the system operates within safe bounds becomes a priority in safety-critical applications, even if performance must be compromised temporarily. One prominent example is the thermal management of lithium-ion battery packs, where temperature must be strictly controlled to prevent degradation and avoid hazardous thermal runaway events. In these systems, temperature constraints must consistently be enforced, regardless of external disturbances or control errors. Traditional strategies, such as Model Predictive Control (MPC), can explicitly handle such constraints but often require solving high-dimensional optimization problems, making real-time implementation computationally demanding. To overcome these limitations, this study investigates the use of a Constraint Enforcement strategy to manage the temperature of a safety-critical battery pack system. This approach reduces computational complexity using a single-step horizon, making it suitable for real-time applications. We applied Constraint Enforcement to a battery pack thermal system to assess this strategy’s effectiveness and practical implications in a thermal management context. We compared its performance to a conventional PID controller commonly used in industrial applications. Numerical simulations demonstrate that the Constraint Enforcement approach successfully maintains battery temperature within safe operational limits under varying load and environmental conditions, outperforming the PID controller in critical scenarios where constraint violations would occur. Furthermore, the results highlight the trade-offs between responsiveness and constraint satisfaction, offering valuable insights into the practical deployment of constraint-aware controllers in battery management systems. This study shows that Constraint Enforcement provides a promising alternative for safety-critical thermal control, balancing performance and safety with manageable computational demand, as well as demonstrating the ease of implementing it into an existing controlled system.
Ebner, Eric RossiniFernandes, Lucas PasqualLeal, Gustavo NobreNeto, Cyro AlbuquerqueLeonardi, Fabrizio
With more 5G base stations coming into play, making an accurate assessment of RF-EMF exposure currently faces increasing demand to check if they meet regulatory requirements and ensure people’s safety. We present here PSF-Net, a novel deep learning network by uniting TabPFN’s meta-learned prior knowledge and SAINT’s dual attention structure; its use makes it particularly suitable to deal with applications like prediction of downlink power density and radiation level classification under different conditions within various kinds of 5G cell. A major component in the design of this approach is an uncertainty-aware gating block that determines the optimal weighting for each model output—TabPFN or SAINT—based on the estimated prediction variance as quantified via Monte Carlo sampling during training or the prediction variance calculated using inference-time dropout. In addition, a residual multi-layer perceptron (MLP) is also included to extract refined fused features and maintain a steady gradient flow. We evaluated the PSF-Net on a public data set of 3,624 georeferenced base stations, each of which has 34 features. Compared with Transformer, GNN, XGBoost and other strong baselines (Random Forest, Extra Trees, MLP, kNN, and SVR), the model shows improvement in all metrics – macro-averaged F1 and MAE and RMSE – for both classification and regression problems. Ablation studies have shown that the uncertainty gate and both encoder branches are important: removal of any one of them produces significantly worse performance. Further analysis of the calibration shows that the network tends to moderate overconfidence, especially on high exposure instances. Taken as a whole, the study results suggest that PSF-Net is a practical means of achieving a reliable large-scale RF-EMF exposure assessment with both correct predictions and proper calibrated probabilities/uncertainty; moreover, it can provide useful inputs for how to advance safety-critical tabular modeling when facing difficult questions of safety on large datasets.
Zhang, YanjinYu, Zefeng
.
Xie, DongxuanLi, DongyangZhang, YoukangZhao, YingjieHong, BaofengWang, Nan
The rapid evolution of autonomy in Off-Highway Vehicles (OHVs)—spanning agriculture, mining, and construction—demands robust cybersecurity strategies. Sensor-control systems, the cognitive core of autonomous OHVs, operate in harsh, connectivity-limited environments. This paper presents a structured approach to applying threat modeling to these architectures, ensuring secure-by-design systems that uphold safety, resilience, and operational integrity.
Kotal, Amit
Direct current (DC) systems are increasingly used in small power system applications ranging from combined heat and power plants aided with photovoltaic (PV) installations to powertrains of small electric vehicles. A critical safety issue in these systems is the occurrence of series arc faults, which can lead to fires due to high temperatures. This paper presents a model-based method for detecting such faults in medium- and high-voltage DC circuits. Unlike traditional approaches that rely on high-frequency signal analysis, the proposed method uses a physical circuit model and a high-gain observer to estimate deviations from nominal operation. The detection criterion is based on the variance of a disturbance estimate, allowing fast and reliable fault identification. Experimental validation is conducted using a PV system with an arc generator to simulate faults. The results demonstrate the effectiveness of the method in distinguishing fault events from normal operating variations. The method is compared with a recursive least squares estimator, showing improved performance in terms of sensitivity. The approach offers a cost-effective and robust solution to improve safety in DC power systems, particularly in PV and electric mobility applications.
Winkler, AlexanderMayr, StefanGrabmair, Gernot
Known as FOSS (for fiber optic sensing system), NASA’s patented, award-winning technology portfolio combines advanced sensors and innovative algorithms into a robust package that accurately and cost-effectively monitors a host of critical parameters in real time. These include position/deformation (displacement, twist, rotation), stiffness (bending, torsion, vibration), operational loads (bending moments, shear loads, torques), strength/stress (pressure/fatigue, breakage prediction), and magnetic fields (cracks or other flaws in safety-critical metal structures) for structural health monitoring applications. In addition to monitoring the structure of a tank, FOSS is capable of sensing the tank’s inventory, including amounts, temperatures, and stratification.
The development of cyber-physical systems necessarily involves the expertise of an interdisciplinary team – not all of whom have deep embedded software knowledge. Graphical software development environments alleviate many of these challenges but in turn create concerns for their appropriateness in a rigorous software initiative. Their tool suites further enable the creation of physics models which can be coupled in the loop with the corresponding software component’s control law in an integrated test environment. Such a methodology addresses many of the challenges that arise in trying to create suitable test cases for physics-based problems. If the test developer ensures that test development in such a methodology observes software engineering’s design-for-change paradigm, the test harness can be reused from a virtualized environment to one using a hardware-in-the-loop simulator and/or production machinery. Concerns over the lack of model-based software engineering’s rigor can be mitigated at each point in the development cycle – setting the stage for the methodology’s power in safety-critical software systems; it is an approach that is proven in use at aerospace companies flying rockets and some leading-edge automotive companies.
McBain, Jordan
The emergence of Software Defined Vehicles (SDVs) has introduced significant complexity in automotive system design, particularly for safety-critical domains such as braking. A key principle of SDV architecture is the centralization of control software, decoupled from sensing and actuation. When applied to Brake-by-Wire (BbW) systems, this leads to decentralized brake actuation that demands precise coordination across numerous distributed electronic components. The absence of mechanical backup in BbW systems further necessitates fail-operational redundancy, increasing system complexity and placing greater emphasis on rigorous system-level design validation. A comprehensive understanding of component interdependencies, failure propagation, and redundancy effectiveness is essential for optimizing such systems. This paper presents a custom-built System Analysis Tool (SAT), along with a specialized methodology tailored for modeling and analyzing BbW architectures in the context of SDVs. The operation of the SAT is described in detail, and its application is demonstrated through illustrative examples derived from a representative BbW system model. The SAT enables systematic evaluation of individual component failures, their logical and functional interdependencies, and the cumulative impact of multiple simultaneous faults. It provides structured, data-driven insights that support early trade-off decisions between cost, complexity, and safety, and facilitates the generation of robust, traceable functional requirements. Additionally, the SAT quantifies the relationship between component failure rates, expressed in Failures in Time (FIT), and system-level performance degradation across multiple defined operational states. By enabling a rigorous, model-based approach to design exploration and fault analysis, the SAT enhances system engineers' ability to validate fail-operational behavior, identify design weaknesses, and refine brake system architecture. This supports a more efficient development process for safety-critical systems and contributes to the overall reliability and performance of BbW implementations within SDV platforms.
Heil, EdwardZuzga, SeanBabul, Caitlin
Advanced motion control technologies are essential to modern aerospace design, supporting a wide range of safety-critical and comfort-driven applications. In aerospace, motion control components such as gas springs, actuators, and dampers are integral to nearly every commercial aircraft, rocket, satellite, and space vehicle. These critical elements support flight safety and transport functions, from the dependable deployment of landing gear and cargo doors to the smooth, ergonomic operation of seating for pilots and passengers.
Experimental testing in automotive development sometimes relies on ad hoc approaches like ‘One Factor at a Time’, particularly in time- and resource-limited situations. While widely used, these approaches are limited in their ability to systematically capture parameter interactions and system complexities, which poses significant challenges in safety-critical applications like high-voltage battery systems. This study systematically investigates the factors influencing thermal runaway in lithium-ion battery cells using a statistical full-factorial experimental design. Key parameters, including state of charge, cell capacity and heating trigger power, have been analyzed under controlled conditions with an autoclave setup, enabling precise measurement of thermal and mechanical responses. The use of automotive-grade lithium-ion cells ensures relevance for next-generation applications. By employing factorial regression and statistical analysis, the study identifies critical temperatures, gas evolution rates, and energy release mechanisms during thermal runaway. The results highlight the dominant influence of the state of charge on the severity and onset of thermal events. These findings underscore the necessity of comprehensive testing strategies to improve the safety and reliability of high-energy battery systems. This work advances understanding of thermal instability in lithium-ion cells and provides actionable insights for mitigating risks through design optimization. Future research will explore enhanced thermal management strategies to further reduce battery failure risks in applications like electric vehicles.
Ceylan, DenizKulzer, André CasalWinterholler, NinaWeinmann, JohannesSchiek, Werner
Brake-by-wire (BBW) systems, characterized by fast response, high precision, ease installation, and simplified maintenance, are highly likely to become the future braking systems. However, the reliability of BBW is currently inferior to that of traditional hydraulic braking systems. Considering ECE R13 regulations, actuator reliability, and braking efficiency, this article first proposes a new braking force distribution strategy to prevent braking failure and enhance vehicle safety without modifying the actuator itself. The strategy reduces the operating frequency of rear actuators during low- and medium-intensity braking, thereby extending their service life and operational reliability. Then, the co-simulation model combining Simulink and AMESim was established for simulation validation based on direct drive braking actuator. Additionally, the real-vehicle test platform was built for typical braking scenarios. The simulation and experimental results show that this strategy significantly reduces the operating rate of rear actuators while maintaining braking performance. This ensures that the rear actuators have a longer service life and can be used for emergency braking. In the event of front actuators’ failure, the rear actuators can provide the necessary and emergency braking force, thereby enhancing the overall safety of the vehicle.
Li, TianleGong, XiaoxiangHe, ChunrongDeng, ZhenghuaZhang, HongXu, RongHe, HaitaoWang, XunZhang, Huaiyue
Driven by the vast consumer marketplace, the electronics megatrend has reshaped nearly every sector of society. The advancements in semiconductors and software, originally built to serve consumer demand, are now delivering significant value to non-consumer industries. Today, electronics are making inroads into traditionally conservative, safety-critical sectors such as automotive and aerospace. In doing so, electronics—now further propelled by artificial intelligence—are disrupting the functional safety architectures of these cyber-physical systems. Electronics have created the world of cyber-physical systems, raising broader concerns about the broader category of product assurance. Product Assurance in the Age of Artificial Intelligence continues the work of previous SAE Edge Research Reports in examining open research challenges arising from this shift, particularly in automotive systems, as core electronic technologies (e.g., the combination of software and communications) have even redefined what it means to be a "product." Click here to access the full SAE EDGETM Research Report portfolio.
Razdan, Rahul
Items per page:
1 – 50 of 544