Formal Methods will not Prevent Self-Driving Cars from Having Accidents

Similar documents
Automated Driving - Object Perception at 120 KPH Chris Mansley

AUTONOMOUS VEHICLES & HD MAP CREATION TEACHING A MACHINE HOW TO DRIVE ITSELF

Deep Learning Will Make Truly Self-Driving Cars a Reality

Case 1:17-cv DLF Document 16 Filed 04/06/18 Page 1 of 2 IN THE UNITED STATES DISTRICT COURT FOR THE DISTRICT OF COLUMBIA

Jimi van der Woning. 30 November 2010

University of Michigan s Work Toward Autonomous Cars

CSE 352: Self-Driving Cars. Team 14: Abderrahman Dandoune Billy Kiong Paul Chan Xiqian Chen Samuel Clark

Intelligent Mobility for Smart Cities

Connected Vehicles. The rise of safety innovations and intelligent mobility

Introduction Projects Basic Design Perception Motion Planning Mission Planning Behaviour Conclusion. Autonomous Vehicles

Autonomous Vehicles: Status, Trends and the Large Impact on Commuting

On the role of AI in autonomous driving: prospects and challenges

Autnonomous Vehicles: Societal and Technological Evolution (Invited Contribution)

MEMS Sensors for automotive safety. Marc OSAJDA, NXP Semiconductors

Traffic Operations with Connected and Automated Vehicles

WHAT DOES OUR AUTONOMOUS FUTURE LOOK LIKE?

The New Age of Automobility Metalforming Industry Implications

Automated Driving: The Technology and Implications for Insurance Brake Webinar 6 th December 2016

Safety Considerations of Autonomous Vehicles. Darren Divall Head of International Road Safety TRL

State of the art in autonomous driving. German Aerospace Center DLR Institute of transportation systems

2014 Traffic and Safety Conference

Future Mobility & Machine Learning

Autonomous Vehicles Meet Human Drivers: Traffic Safety Issues for States

Safety for Self-driving Cars

Unmanned autonomous vehicles in air land and sea

AUTONOMOUS CARS: TECHNIQUES AND CHALLENGES

Intelligent Transportation Systems. Secure solutions for smart roads and connected highways. Brochure Intelligent Transportation Systems

Claims - Addressing The Issues. SALTA Risk Mitigation Workshop April 1, 2009 Chicago, IL

Agenda. Industrial software systems at ABB. Case Study 1: Robotics system. Case Study 2: Gauge system. Summary & outlook

Keynote talk, Int. Conf. Innovations for Next Generation Automobiles Sendai (October 2014)

Speed Limit Reduction and Traffic Crashes: Empirical Evidence from São Paulo. Ciro Biderman UCL FSP/USP Event November, 2017 FSP, São Paulo, Brazil

Automated Driving: The Technology and Implications for Insurance. Matthew Avery Director of Insurance Research

Autonomous cars navigation on roads opened to public traffic: How can infrastructure-based systems help?

Active Driver Assistance for Vehicle Lanekeeping

Vehicle Dynamics Models for Driving Simulators

Cooperative Autonomous Driving and Interaction with Vulnerable Road Users

Situation Awareness & Collision Risk Assessment to improve Driving Safety

Lives Saved through Vehicle Design: Regulation, Consumer Information and the Future

COLLISION AVOIDANCE SYSTEM

AUTONOMOUS VEHICLES: PAST, PRESENT, FUTURE. CEM U. SARAYDAR Director, Electrical and Controls Systems Research Lab GM Global Research & Development

ZF Mitigates Rear-End Collisions with New Electronic Safety Assistant for Trucks

Toyota s トヨタの安全への取り組み

China Intelligent Connected Vehicle Technology Roadmap 1

Trends in der Fahrzeugsicherheit Vortragsreihe: Innovationen in der Fahrzeugtechnik. Dipl.-Ing. James Remfrey FH Joanneum, Graz, 2.

Technology Development Plan

Technology Development Plan

Modelling disruptions in mobility a BP perspective BP p.l.c.

The Road to Automated Vehicles. Audi of America Government Affairs

A Presentation on. Human Computer Interaction (HMI) in autonomous vehicles for alerting driver during overtaking and lane changing

Establishing a Standard List of Hazards for Automatic Driving

Greening our Community Speaker Series Craig E. Forman June 19, Craig E. Forman

White Paper. Compartmentalization and the Motorcoach

FUTURE BUMPS IN TRANSITIONING TO ELECTRIC POWERTRAINS

The Way Forward for Self Driving Cars

Control of Mobile Robots

D.J.Kulkarni, Deputy Director, ARAI

Onboard DC Grid. Jan Fredrik DP Conference 2011; Houston. for enhanced DP operation in ships

Crash Cart Barrier Project Teacher Guide

MaaS is Emerging in Michigan. February 15, 2017 Ann Arbor, Michigan USA

Challenges To The Future of Mobility

Applications of Machine Learning for Autonomous Driving & Challenges in Testing & Verifications. Ching-Yao Chan Nokia Workshop January 11, 2018

Self-Driving Cars: The Next Revolution. Los Angeles Auto Show. November 28, Gary Silberg National Automotive Sector Leader KPMG LLP

Autonomous Vehicles in California. Brian G. Soublet Deputy Director Chief Counsel California Department of Motor Vehicles

EMERGING TRENDS IN AUTOMOTIVE ACTIVE-SAFETY APPLICATIONS

Focus on the Road. Dangers of distracted driving Tips for avoiding common distractions Costs and consequences

Environmental Envelope Control

CSE 352: Self-Driving Cars. Team 2: Randall Huang Youri Paul Raman Sinha Joseph Cullen

ST.MARY S CATHOLIC HIGH SCHOOL, DUBAI

What they're saying about autonomous technology

#6 IN A SERIES SHARING THE ROAD. How to stay safe.

Control Design of an Automated Highway System (Roberto Horowitz and Pravin Varaiya) Presentation: Erik Wernholt

Uber autonomous vehicle death raises questions for UK law review

SIMULATING A CAR CRASH WITH A CAR SIMULATOR FOR THE PEOPLE WITH MOBILITY IMPAIRMENTS

VOLUNTEER DRIVER TRAINING PRESENTATION

Injuries from Motor Vehicle Crashes 48,000 46,000

Smart Control for Electric/Autonomous Vehicles

Citi's 2016 Car of the Future Symposium

Pedalling into a driverless world: opportunities and threats

Intelligent Vehicle Systems

REGULATORY APPROVAL OF AN AI-BASED AUTONOMOUS VEHICLE. Alex Haag Munich,

Modeling Driver Behavior in a Connected Environment Integration of Microscopic Traffic Simulation and Telecommunication Systems.

Outline WHY ARE SELF DRIVING VEHICLES GETTING INVOLVED IN CRASHES?

Leveraging AI for Self-Driving Cars at GM. Efrat Rosenman, Ph.D. Head of Cognitive Driving Group General Motors Advanced Technical Center, Israel

b. take a motorcycle-riding course taught by a certified instructor.

FLYING CAR NANODEGREE SYLLABUS

The connected vehicle is the better vehicle!

POWER, PARALLEL AUTONOMY, AND PEOPLE Gill Pratt CEO at Toyota Research Institute GTC 2016

The Future is Bright! So how do we get there? Council of State Governments West Annual Meeting August 18, 2017

Copyright 2016 by Innoviz All rights reserved. Innoviz

The Future of Transit and Autonomous Vehicle Technology. APTA Emerging Leaders Program May 2018

Devices to Assist Drivers to Comply with Speed Limits

Systems-Theoretic Process Analysis: AUTOMOBILE FEATURES FOR LANE MANAGEMENT

CONNECTED AUTOMATION HOW ABOUT SAFETY?

Le développement technique des véhicules autonomes

GWR SAFETY SYSTEMS SAVING LIVES SINCE 1982

Regeneration of the Particulate Filter by Using Navigation Data

Defensive Driving. Monthly Training Topic NV Transport Inc. Safety & Loss Prevention

Will robots drive our cars soon? Smart sensors smart data

CASCAD. (Causal Analysis using STAMP for Connected and Automated Driving) Stephanie Alvarez, Yves Page & Franck Guarnieri

Road Vehicle Automation: Distinguishing Reality from Hype

Transcription:

Formal Methods will not Prevent Self-Driving Cars from Having Accidents Thierry Fraichard INRIA, LIG-CNRS and Grenoble University Forum Méthodes Formelles Mardi 10 octobre 2017

From Mobile Robots to Self-Driving Cars Shakey [66-72] Darpa Urban Challenge [Nov. 07] Thierry Fraichard Forum Méthodes Formelles - October 10, 2017 2

Why Self-Driving Cars? Google Official Blog: What we re driving at, S. Thrun, 9 October 2010 Larry and Sergey founded Google because they wanted to help solve really big problems using technology. And one of the big problems we re working on today is car safety and efficiency. Our goal is to help prevent traffic accidents, free up people s time and reduce carbon emissions by fundamentally changing car use. Safety has been our first priority in this project 2014: 1.25 million deaths worldwide (94% human errors in the US) Thierry Fraichard Forum Méthodes Formelles - October 10, 2017 3

Absolute Motion Safety for Self-Driving Cars Thierry Fraichard Forum Méthodes Formelles - October 10, 2017 4

Self-Driving Cars and Accidents Thierry Fraichard Forum Méthodes Formelles - October 10, 2017 5

A Fatal Misunderstanding Tesla Model S crash in Autopilot mode, May 2016 The sensors failed to differentiate the white side of the tractor trailer against a brightly lit sky Thierry Fraichard Forum Méthodes Formelles - October 10, 2017 6

A Harmless Misreasoning Google Self-Driving Car Project Monthly Report, February 2016 Our car had detected the approaching bus, but predicted that it would yield to us because we were ahead of it. Thierry Fraichard Forum Méthodes Formelles - October 10, 2017 7

Why Collisions Happen? Hardware failures Software bugs Misunderstanding Misreasoning Focus on misreasoning in dynamic environments Can motion safety be guaranteed? Thierry Fraichard Forum Méthodes Formelles - October 10, 2017 8

Outline of the Talk 1. Case study Gaining insight into motion safety 2. Inevitable collision states Furthering the analysis in a formal framework 3. Motion safety in the real world Houston, we have a problem 4. Weaker motion safety levels Less is better than nothing Thierry Fraichard Forum Méthodes Formelles - October 10, 2017 9

1 Case Study Gaining insight into motion safety Thierry Fraichard Forum Méthodes Formelles - October 10, 2017 10

The Compactor Scenario Reasoning about the future Collision time Escape time Limited decision time Appropriate time horizon Thierry Fraichard Forum Méthodes Formelles - October 10, 2017 11

2 Inevitable Collision States Furthering the analysis in a formal framework Thierry Fraichard Forum Méthodes Formelles - October 10, 2017 12

Inevitable Collision States [Fraichard 03] Collision States (CS) vs. Inevitable Collision States (ICS): Whatever the future trajectory of the robot, a collision will happen Key to motion safety: stay away from ICS Thierry Fraichard Forum Méthodes Formelles - October 10, 2017 13

From Cartesian Space to State-Time Space Thierry Fraichard Forum Méthodes Formelles - October 10, 2017 14

Collision States Thierry Fraichard Forum Méthodes Formelles - October 10, 2017 15

Inevitable Collision States Thierry Fraichard Forum Méthodes Formelles - October 10, 2017 16

Inevitable Collision States Teachings 1. Obstacles are not independent 2. Decision time 3. Time Horizon Static/freezing/periodic environments δ d not infinite Thierry Fraichard Forum Méthodes Formelles - October 10, 2017 17

Obstacles are not Independent Thierry Fraichard Forum Méthodes Formelles - October 10, 2017 18

Decision Time and Time Horizon Thierry Fraichard Forum Méthodes Formelles - October 10, 2017 19

What Have We Learned? 1. Global reasoning about the future evolution of the environment until an appropriate time horizon δ h, limited decision time δ d 2. Absolute motion safety = stay away from ICS 3. ICS = f(cs[0, δ d ]) 4. CS = g(b[0, δ d ]) 5. δ d infinite (except for static/freezing/periodic environments) [Martinez & Fraichard 08]: robot controller in a static/freezing/periodic environment guaranteed absolute motion safety Thierry Fraichard Forum Méthodes Formelles - October 10, 2017 20

3 Motion Safety in the Real World Houston, we have a problem Thierry Fraichard Forum Méthodes Formelles - October 10, 2017 21

What about Real World Situations? Incomplete information & uncertainty Thierry Fraichard Forum Méthodes Formelles - October 10, 2017 22

Modeling the Future Deterministic Conservative Probabilistic Thierry Fraichard Forum Méthodes Formelles - October 10, 2017 23

Consequences wrt. Motion Safety For guaranteed motion safety: Conservative model Every state is an ICS (δ h = ) What can be done then? Weaker motion safety levels Thierry Fraichard Forum Méthodes Formelles - October 10, 2017 24

4 Weaker Motion Safety Levels Less is better than nothing Thierry Fraichard Forum Méthodes Formelles - October 10, 2017 25

Passive Motion Safety Should a collision take place, the robot will be at rest Braking ICS [Bouraine & Fraichard, 11] Key to passive motion safety: stay away from Braking ICS Finite time horizon: max{t b } Everybody enforces it no collision at all Thierry Fraichard Forum Méthodes Formelles - October 10, 2017 26

Passive Motion Safety can be Guaranteed [Provably Safe Navigation for Mobile Robots with Limited Field-of-Views in Dynamic Environments, Bouraine et al., AR, 12] Dynamic system Braking ICS Thierry Fraichard Forum Méthodes Formelles - October 10, 2017 27

What about Formal Methods? [Formal Verification of Obstacle Avoidance and Navigation of Ground Robots, Mitsch et al., IJRR, 17] Hybrid system Differential dynamic logic Thierry Fraichard Forum Méthodes Formelles - October 10, 2017 28

Passive Motion Safety and Self-Driving Cars Thierry Fraichard Forum Méthodes Formelles - October 10, 2017 29

Time to Conclude In the real world, forget guaranteed absolute motion safety Guaranteed lesser motion safety possible but Possible improvements: V2V, V2I,roadway engineering Self-Driving cars: ~1.4 million miles (Google, up until now), 1 death Regular cars: ~3 trillion miles, 30 057 deaths (USA, 2014) 1 death/100 million miles Technology still has to prove itself Thierry Fraichard Forum Méthodes Formelles - October 10, 2017 30