SearcharxivSearch

arXiv subjects

Niklas Braun

Publications and source records attributed to Niklas Braun.

4 recordsLinked to original sources

Approaching Safety-Argumentation-by-Design: A Requirement-based Safety Argumentation Life Cycle for Automated Vehicles

Despite the growing number of automated vehicles on public roads, operating such systems in open contexts inevitably involves incidents. Developing a defensible case that the residual risk is reduced to a reasonable (societally acceptable) level is hence a prerequisite to be prepared for potential liability cases. A "safety argumentation" is a common means to represent this case. In this paper, we contribute to the state of the art in terms of process guidance on argumentation creation and maintenance - aiming to promote a safety-argumentation-by-design paradigm, which mandates co-developing both the system and argumentation from the earliest stages. Initially, we extend a systematic design model for automated driving functions with an argumentation layer to address prevailing misconceptions regarding the development of safety arguments in a process context. Identified limitations of this extension motivate our complementary design of a dedicated argumentation life cycle that serves as an additional process viewpoint. Correspondingly, we define literature- and expert-based process requirements. To illustrate the safety argumentation life cycle that we propose as a result of implementing these consolidated requirements, we demonstrate principles of the introduced process phases (baselining, evolution, continuous maintenance) by an argumentation example on an operational design domain exit response.

eess.SY

Safety Blind Spot in Remote Driving: Considerations for Risk Assessment of Connection Loss Fallback Strategies

As part of the overall goal of driverless road vehicles, remote driving is a major emerging field of research of its own. Current remote driving concepts for public road traffic often establish a fallback strategy of immediate braking to a standstill in the event of a connection loss. This may seem like the most logical option when human control of the vehicle is lost. However, our simulation results from hundreds of scenarios based on naturalistic traffic scenes indicate high collision rates for any immediate substantial deceleration to a standstill in urban settings. We show that such a fallback strategy can result in a SOTIF-relevant hazard, raising the question whether this design decision is acceptable. Therefore, from a safety perspective, we call this problem a safety blind spot, as safety analyses in this regard seem to be very rare. In this article, we first present a simulation on a naturalistic dataset that shows a high probability of collision in the described case. Second, we discuss the severity of the resulting potential rear-end collisions and provide an even more severe example by including a large commercial vehicle in the potential collision.

eess.SY

A Concept for Semi-Automatic Configuration of Sufficiently Valid Simulation Setups for Automated Driving Systems

As simulation is increasingly used in scenario-based approaches to test Automated Driving Systems, the credibility of simulation results is a major concern. Arguably, credibility depends on the validity of the simulation setup and simulation models. When selecting appropriate simulation models, a trade-off must be made between validity, often connected to the model's fidelity, and cost of computation. However, due to the large number of test cases, expert-based methods to create sufficiently valid simulation setups seem infeasible. We propose using design contracts in order to semi-automatically compose simulation setups for given test cases from simulation models and to derive requirements for the simulation models, supporting separation of concerns between simulation model developers and users. Simulation model contracts represent their validity domains by capturing a validity guarantee and the associated operating conditions in an assumption. We then require the composition of the simulation model contracts to refine a test case contract. The latter contract captures the operating conditions of the test case in its assumption and validity requirements in its guarantee. Based on this idea, we present a framework that supports the compositional configuration of simulation setups based on the contracts and a method to derive runtime monitors for these simulation setups.

eess.SY

Consensus ranking for multi-objective interventions in multiplex networks

High-centrality nodes have disproportionate influence on the behavior of a network; therefore controlling such nodes can efficiently steer the system to a desired state. Existing multiplex centrality measures typically rank nodes assuming the layers are qualitatively similar. Many real systems, however, are comprised of networks heterogeneous in nature, for example, social networks may have both agnostic and affiliative layers. Here, we use rank aggregation methods to identify intervention targets in multiplex networks when the structure, the dynamics, and our intervention goals are qualitatively different for each layer. Our approach is to rank the nodes separately in each layer considering their different function and desired outcome, and then we use Borda count or Kemeny aggregation to identify a consensus ranking - top nodes in the consensus ranking are expected to effectively balance the competing goals simultaneously among all layers. To demonstrate the effectiveness of consensus ranking, we apply our method to a degree-based node removal procedure such that we aim to destroy the largest component in some layers, while maintaining large-scale connectivity in others. For any multi-objective intervention, optimal targets only exist in the Pareto-sense; we, therefore, use a weighted generalization of consensus ranking to investigate the trade-off between the competing objectives. We use a collection of model and real networks to systematically investigate how this trade-off is affected by multiplex network structure. We use the copula representation of the multiplex centrality distributions to generate model multiplex networks with given rank correlations. This allows use to separately manipulate the marginal centrality distribution of each layer and the interdependence between the layers and to independently investigate the role of the two using both analytical and numerical methods.

physics.soc-ph