[论文解读] On the validation of complex systems operating in open contexts
本文提出了一种基于系统视角的系统性验证方法(sys2val),用于在开放、非结构化环境中运行的复杂自主系统。该方法通过结构化算法形式化迭代开发与验证流程,填补了ISO/PAS 21448(SOTIF)在高级自动化方面的空白,并强调整体证据整合,以确保自主系统的安全性、社会接受度以及长期可行性。
In the recent years, there has been a rush towards highly autonomous systems operating in public environments, such as automated driving of road vehicles, passenger shuttle systems and mobile robots. These systems, operating in unstructured, public real-world environments (the operational design domain can be characterized as open context) per se bear a serious safety risk. The serious safety risk, the complexity of the necessary technical systems, the openness of the operational design domain and the regulatory situation pose a fundamental challenge to the automotive industry. Many different approaches to the validation of autonomous driving functions have been proposed over the course of the last years. However, although partly announced as the solution to the validation challenge, many of the praised approaches leave open crucial parts. To illustrate the contributions as well as the limitations of the individual approaches and providing strategies for 'viable' validation and approval of such systems, the first part of the paper gives an analysis of the fundamental challenges related to the valid design and operation of complex autonomous systems operating in open contexts. In the second part, we formalize the problem statement and provide algorithms for an iterative development and validation. In the last part we give a high level overview of a practical, holistic development process which we refer to as systematic, system view based approach to validation (in short sys2val) and comment on the contributions from ISO26262 and current state of ISO/PAS 21448 (SOTIF).
研究动机与目标
- 解决在开放、非结构化环境中验证高度自主系统的基本挑战,此类环境因无限复杂的上下文而存在高安全风险。
- 识别现有验证方法(尤其是ISO/PAS 21448(SOTIF))的关键局限性,其在3级及以上自动化及开放环境中的适用性不足。
- 开发一种形式化、迭代的验证流程,将功能安全、SOTIF、机器学习安全与安全整合到统一的系统视图中。
- 通过持续监控、证据收集与反馈回路,实现持续验证与抗脆弱性系统演化。
- 提供一种实用的整体性开发框架(sys2val),为产业界与监管机构提供指导,推动自主系统获得可行且社会可接受的批准。
提出的方法
- 采用系统之系统视角形式化验证问题,使用{Rep_i}表示不同抽象层级的知识片段,并设定证据整合约束。
- 引入用于开发与验证的迭代算法,确保所有安全方面(功能安全、SOTIF、安全等)在循环中系统性地得到处理。
- 提出整体性验证循环(sys2val),通过整合现实世界观测、假设监控与功能修改,弥合代表性差距。
- 将触发事件用作不足性分析的代表性刺激,而非万能解决方案,以确保覆盖罕见但关键的场景。
- 将概率性与系统性证据类型整合到统一的论证框架中,解决证据整合缺乏正式理论的问题。
- 通过在开发生命周期中嵌入持续验证与抗脆弱性原则,扩展ISO 26262与ISO/PAS 21448。
实验结果
研究问题
- RQ1当操作设计域表现出∞-复杂性且随时间演变时,如何验证在开放环境中运行的复杂自主系统?
- RQ2现有方法(如ISO/PAS 21448(SOTIF))在应对3级及以上自主系统在开放环境中的安全性方面存在哪些关键局限性?
- RQ3如何形式化一种系统性、迭代的验证流程,以确保开发过程中不遗漏任何安全关键方面?
- RQ4代表性触发事件在验证系统行为中扮演什么角色?为何代表性是根本性挑战?
- RQ5如何将来自多个安全领域(SOTIF、功能安全、安全等)的碎片化、动态演化的证据,整合为一致且形式化的批准论证?
主要发现
- 现有验证方法(包括ISO/PAS 21448)对3级及以上自主系统不足,因其依赖基于统计的、以触发事件为驱动的方法,无法应对∞-复杂性与动态演变的上下文。
- 本文指出,仅靠现实世界的触发事件无法成为验证的万能解,因其面临代表性挑战,且需要更深层次的不足性分析。
- 形式化迭代开发与验证流程对管理跨抽象层级的日益增长且相互关联的知识片段至关重要,可防止疏漏。
- sys2val框架通过整合现实世界数据、假设监控与功能修改循环,实现持续验证与抗脆弱性演化。
- 统一的证据整合理论——结合概率性与系统性证据——仍不存在,这构成了形式化、广泛接受的安全论证的主要障碍。
- 社会对自主系统的接受度取决于其可证明的长期安全运行能力以及避免致命事故的能力,这要求超越现有标准的、基于系统视角的整体性验证策略。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。