Skip to main content
QUICK REVIEW

[Paper Review] Sensors, Safety Models and A System-Level Approach to Safe and Scalable Automated Vehicles

Jack Weast|arXiv (Cornell University)|Sep 4, 2020
Autonomous Vehicle Technology and Safety6 references4 citations
TL;DR

This paper proposes a system-level approach to automated vehicle (AV) safety that prioritizes redundant and independent sensing subsystems—such as cameras, radar, and lidar—combined with verifiable safety models like Reasonable and Responsible Safety (RSS). By focusing only on sensing failures that could lead to non-compliance with safety models, it argues that AVs can achieve a failure rate 10,000× better than human drivers, making safety scalable and trustworthy through architectural design rather than isolated sensor accuracy.

ABSTRACT

When considering the accuracy of sensors in an automated vehicle (AV), it is not sufficient to evaluate the performance of any given sensor in isolation. Rather, the performance of any individual sensor must be considered in the context of the overall system design. Techniques like redundancy and different sensing modalities can reduce the chances of a sensing failure. Additionally, the use of safety models is essential to understanding whether any particular sensing failure is relevant. Only when the entire system design is taken into account can one properly understand the meaning of safety-relevant sensing failures in an AV. In this paper, we will consider what should actually constitute a sensing failure, how safety models play an important role in mitigating potential failures, how a system-level approach to safety will deliver a safe and scalable AV, and what an acceptable sensing failure rate should be considering the full picture of an AV's architecture.

Motivation & Objective

  • To redefine what constitutes a safety-relevant sensing failure in automated vehicles beyond isolated sensor performance.
  • To demonstrate that system-level redundancy and independence across sensing modalities significantly improve AV safety and scalability.
  • To establish a verifiable safety model (RSS) that distinguishes meaningful sensing failures from benign ones.
  • To define an acceptable sensing failure rate for AVs that exceeds human performance, using MTBF as a benchmark.
  • To show that achieving ultra-high reliability (e.g., MTBF of 10^8 hours) is feasible through independent subsystems, avoiding infeasible validation timelines.

Proposed method

  • Adopt a system-level design where multiple independent sensing subsystems (e.g., camera-only and radar+lidar) operate in parallel to ensure continued operation if one fails.
  • Use the Reasonable and Responsible Safety (RSS) model to define safety compliance, ensuring that only failures impacting RSS adherence are considered critical.
  • Apply probabilistic modeling to calculate the joint failure rate of independent subsystems, showing that p² reduces overall failure probability significantly.
  • Set a target MTBF of 10^7 hours for the full AV system, achievable by requiring each independent subsystem to achieve a more feasible MTBF of 10^4 hours.
  • Leverage fleet-scale testing with 100 vehicles to validate failure rates in months, rather than centuries, by distributing validation across independent channels.
  • Introduce safety margins in decision-making (e.g., adding buffer distance) to mitigate transient or minor sensing inaccuracies without compromising safety.

Experimental results

Research questions

  • RQ1What defines a safety-relevant sensing failure in an automated vehicle, and when can a failure be considered irrelevant?
  • RQ2How can system-level redundancy and independence across sensing modalities reduce the probability of a safety-critical failure?
  • RQ3To what extent can a verifiable safety model like RSS distinguish between benign and dangerous sensing failures?
  • RQ4What MTBF target is necessary for an AV to be significantly safer than a human driver, and is it achievable through system design?
  • RQ5Can the validation burden for ultra-reliable AV sensing be reduced by using independent subsystems instead of a single high-reliability channel?

Key findings

  • A system with two independent sensing subsystems, each with an MTBF of 10^4 hours, achieves an overall MTBF of 10^8 hours, which is 10,000× better than the human driver’s MTBF of 50,000 hours.
  • Only sensing failures that prevent compliance with the RSS safety model are considered meaningful; false positives and distant false negatives do not count as safety failures.
  • Achieving an MTBF of 10^8 hours through a single sensing channel would require 10,000 years of daily driving (2 hours/day), making it practically impossible to validate.
  • With a fleet of 100 AVs operating in parallel, validating a 10^4-hour MTBF for each independent subsystem can be achieved in a few months, reducing validation burden significantly.
  • The use of RSS allows for safe operation even during transient classification errors, as long as worst-case assumptions are respected in decision-making.
  • System-level design with independent sensing channels enables a scalable, trustworthy AV safety framework that exceeds human performance without requiring near-zero failure rates from individual sensors.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.