
Editorial
Select search scope: search across all journals or within the current journal

Formal Methods are mathematically-based techniques for software design and engineering, which enable the unambiguous description of and reasoning about a system’s behaviour. Autonomous systems use software to make decisions without human control, are often embedded in a robotic system, are often safety-critical, and are increasingly being introduced into everyday settings. Autonomous systems need robust development and verification methods, but formal methods practitioners are often asked:
A methodology for automatic simulation-based testing of control systems for autonomous vessels is proposed. The work is motivated by the need for increased test coverage and formalism in the verification efforts. It aims to achieve this by formulating requirements in the formal logic Signal Temporal Logic (STL). This enables automatic evaluation of simulations against requirements using the STL robustness metric, resulting in a robustness score for requirements satisfaction. Furthermore, the proposed method uses a Gaussian Process (GP) model for estimating robustness scores including levels of uncertainty for untested cases. The GP model is updated by running simulations and observing the resulting robustness, and its estimates are used to automatically guide the test case selection toward cases with low robustness or high uncertainty. The main scientific contribution is the development of an automatic testing method which incrementally runs new simulations until the entire parameter space of the case is covered to the desired confidence level, or until a case which falsifies the requirement is identified. The methodology is demonstrated through a case study, where the test object is a Collision Avoidance (CA) system for a small high-speed vessel. STL requirements for safety distance, mission compliance, and COLREG compliance are developed. The proposed method shows promise, by both achieving verification in feasible time and identifying falsifying behaviors which would be difficult to detect manually or using brute-force methods. An additional contribution of this work is a formalization of COLREG using temporal logic, which appears to be an interesting direction for future work.
Although the safety of prospective Maritime Autonomous Surface Ships will largely depend on their ability to detect potential hazards and react to them, the contemporary scientific literature lacks the analysis of how to achieve this. This could be achieved through an application of leading safety indicators. The aim of the performed study was to identify the research directions of leading safety indicators in three safety-critical operational aspects of Maritime Autonomous Surface Ships: collision avoidance, intact stability, and communication. To achieve this, literature review is performed, taking into account scientific documents including journal and conference papers. The results indicate that the need for establishing operational leading safety indicators is recognized by numerous scholars, who sometimes make suggestions of what the set of indicators shall consist of. Some leading safety indicators for autonomous vessels are readily identifiable in the scientific literature and used in current practice. However, the research effort is lacking a holistic approach to the issue.
Autonomous systems, including airborne, land-based, marine, and underwater vehicles, are increasingly present in the world. One important aspect of autonomy is the capability to process information and to make independent decisions for achieving a mission goal. Information on the level of risk related to the operation may improve the decision-making process of autonomous systems. This article describes the integration of risk analysis methods with the control system of autonomous and highly automated systems that are evaluated during operation. Four main areas of implementation are identified; (i) risk models used to directly make decisions, (ii) use of the output of risk models as input to decision-making and optimization algorithms, (iii) the output of risk models may be used as a constraint in or modifying constraints of algorithms, and (iv) the output of risk models may be used to inform representations or maps of the environment to be used in path planning. A case study on a dynamic positioning controller of an offshore supply vessel exemplifies the concepts described in this article. In addition, it demonstrates how risk model output may be used within a hybrid controller.
The advent of automated vehicles (AVs) will provide opportunities for safer, smoother, and smarter road transportation. During the transition from the current human-driven vehicle (HV) to a fully AV traffic environment, there will be a mixed traffic flow including both HVs and AVs. The impact of introducing AVs into existing traffic, however, has not yet been fully understood. In this paper, we advance this understanding by conducting mixed traffic safety evaluation from the perspective of car-following behavior using real-world AV operational data of mixed traffic. To understand how the AVs impact other vehicles on the road, we analyzed the operational behaviors of HV-following-HV, AV-following-HV, and HV-following-AV. A selected car-following model is calibrated, and results show that there are significant differences between the HV-following-HV and the other two groups, indicating safe AV behavior and changes in HV behavior (i.e. less aggressive, safer) after the introduction of AVs into the traffic. Additionally, to understand AV behavioral safety, we investigate behavior predictions (one of the most critical inputs for AVs to make car-following decisions) of AVs and their surrounding vehicles using a mature baseline model and a new Conditional Variational Autoencoder (CVAE) framework. The result shows potential risks of inaccurate predictions of the baseline model and the necessity to consider additional factors, such as vehicle interactions and driver behavior, into the prediction for risk mitigation. Arterial vehicle trajectory data from the Lyft Level 5 Dataset is applied to test the proposed methodological framework to understand the car-following safety risks of HVs and AVs in the mixed traffic stream.
Autonomous Vehicles (AVs), also known as self-driving cars, are a potentially transformative technology, but developing and demonstrating AV safety remains an open question. AVs offer some unique challenges that stretch the limits of traditional safety engineering practices. Most current safety standards and methodologies in the AV industry were not originally intended for application to autonomous vehicles, and they have significant limitations and shortcomings. In this article, we analyze the literature to first build an argument that a new safety framework is needed for AVs. We then use the identified limitations of current methodologies as a basis to formulate a set of fundamental requirements that must be met by any proposed AV safety framework. We propose a new AV safety framework based on the Hybrid Causal Logic (HCL) methodology, which combines Event Sequence Diagrams (ESDs), Fault Tree Analysis (FTA), and Bayesian Networks (BNs). The HCL framework is developed at a conceptual level and then evaluated versus the identified fundamental requirements. To further illustrate how the framework may meet the requirements, a simple example of an AV perception system scenario is developed using the HCL framework and evaluated. The results demonstrate that the HCL framework provides an integrated approach that has the potential to satisfy more completely the fundamental requirements than the current methodologies.
The recent social trends and accelerated technological progress culminated in the development of autonomous vehicles (AVs). Reliability assessment for AV systems is in high demand before its market launch. In safety-critical systems (SCSs) such as AV systems, the reliability concept should be broadened to consider more safety-related issues. In this paper, reliability is defined as the probability that the system performs satisfactorily for a given period of time under stated conditions. This paper proposes a reliability assessment framework of AV, consisting of three main stages: (i) modeling the safety control structure through the Systems-Theoretic Accident Model and Processes (STAMP); (ii) mapping the control structure and functional relationships to a directed acyclic graph (DAG); and (iii) construct a Bayesian network (BN) on DAG to assess the system reliability. The fully automated (level 5) vehicle system is shown as a numeric example to illustrate how this suggested framework works. A brief discussion on involving human factors in systems to analyze lower levels of automated vehicles is also included, demonstrating the need for further research on real case studies.
Research on autonomous ships has led to several ideas about how they could be operated in terms of level of automation and human presence. However, all seem to point towards systems that will be more complex due to issues such as the tighter integration with software and the interactions with humans-in-the-loop. These ships will likely be completely different compared to conventional ones, which puts into question the usefulness of our current understanding of risk and how it is managed for ensuring safe operation. By a critical review of the literature, this paper highlights the need for advanced methods that will combine machine learning and simulation for dynamically assessing risk in a life cycle context and effectively transferring acquired operational knowledge back to the design phase. The main objective of this paper is to describe a novel life cycle risk framework for developing algorithms inspired by the biological immune system, which provides lifetime protection from harmful pathogens. This framework can be used to construct machine learning algorithms for dynamic risk monitoring and adaptive risk control that address different types of risk, while enabling faster future response to previously unencountered risks and operational feedback to design through learning. We demonstrate the feasibility of our approach in a specific maritime context with a case study on collision risk identification. Considering the lack of experience for autonomous ships, the benefit of our immune-inspired approach is that it departs from the classic risk scenario concept and that it does not rely on safety performance data for identifying risk factors and training the algorithms. We suggest this framework is particularly suitable for autonomous ships with high levels of autonomy, although applicable to conventional ships as well, as it can contribute to empowering them with risk awareness and the capability to deal with any risk environment.
Autonomous transportation is an increasingly popular concept and is gradually becoming a reality. This transformation also changes the way people travel. For example, the autonomous ferry is an emerging alternative for residents living in coastal areas. To evaluate the safety of an autonomous ferry, a thorough safety review is necessary. This paper makes an initial attempt by developing a model for performing a risk assessment of collisions between an autonomous ship with manned vessels and applying this to a specific ferry operating in a canal. The safety barriers to prevent a collision are identified, as well as the respective failure modes. A Bayesian belief network is employed to model the collision and to quantitively assess the collision risk of the autonomous ferry. Relevant data are collected to perform a quantitative risk analysis. By running the model, the likelihood of a collision is calculated. A sensitivity analysis is also performed to identify the most contributing causes.
Effectively addressing safety, security and cyber-security challenges is quintessential for progressing the development of next generation maritime autonomous shipping. This study aims at developing a novel hybrid, semi-structured process for the hazardous scenarios identification and ranking. This method integrates the operational and functional hazard identification approaches, whilst considering the safety, security and cybersecurity hazards. This method is applied to comprehensively assess the safety of an autonomous inland waterways ship at a preliminary design phase. The hazardous scenarios are identified and ranked by a number of experts participating in a series of sessions. The identified hazards risk is estimated considering the frequency and severity indices, whereas their uncertainty is estimated by employing the standard deviations in these two indices among the experts ranking results. Epistemic uncertainty is also considered during ranking. Risk control measures are proposed to de-risk the critical hazards. The results reveal that the most critical hazards from the safety, security and cybersecurity perspectives pertain to the situation awareness, remote control and propulsion functions. Based on the derived results, design enhancements along with high-level testing scenarios for the investigated autonomous ship are also proposed.
Novel innovations have been witnessed in the past few years in the field of technology for autonomous vehicles. These have been exploited in various applications in the maritime domain; one such application is the proposal to develop autonomous passenger ships (APS) or ferries for carrying passengers in urban waterways. Such technology requires the integration of several components to support the safe and secure operation of the ferries. In this paper, a communication architecture is proposed, that satisfies pre-established communication requirements and supports autonomous and remotely controlled functions of an APS. The architecture was designed using the Architecture Analysis and Design Language (AADL); this enabled an iterative design process to be followed and allows for future improvements. The proposed architecture is verified by showcasing the role of the different architectural components in addressing the requirements and in supporting the expected functions in a number of operational scenarios based on the expected operations of an APS use case called “Autoferry.” Furthermore, the proposed architecture has been evaluated by demonstrating its ability to achieve the expected performance according to the requirements, in simulated experiments using the network simulator GNS3.
Automation and an increasing level of autonomy are not novelties in aircraft cockpits. One of the main goals of automation in aviation is to increase pilots’ situation awareness (SA) and reduce their workload – both of high importance for a safe flight. Increasing automation has historically reduced aviation accident rates and improved efficiency. Yet, currently implemented systems have also contributed to accidents, when failed, or were insufficient to increase pilots’ SA for improving their decision-making. This paper discusses the need for an enhanced decision-support system and its potential benefits for safer aviation. A model-based decision support system that leverages artificial intelligence, Integrated Flight Advisory System (IFAS), is presented. Further, the conceptual design of this system is described. The overview and roadmap provided in this paper consist of an effort toward a more holistic, pilot-centered, AI-based decision-support that can contribute to safer aviation.
The advent of artificial intelligence and deep learning has provided sophisticated functionality for sensor fusion and object detection and classification which have accelerated the development of highly automated and autonomous ships as well as decision support systems for maritime navigation. It is, however, challenging to assess how the implementation of these systems affects the safety of ship operation. We propose to utilize marine training simulators to conduct controlled, repeated experiments allowing us to compare and assess how functionality for autonomous navigation and decision support affects navigation performance and safety. However, although marine training simulators are realistic to human navigators, it cannot be assumed that the simulators are sufficiently realistic for testing the object detection and classification functionality, and hence this functionality cannot be directly implemented in the simulators. We propose to overcome this challenge by utilizing Cycle-Consistent Adversarial Networks (Cycle-GANs) to transform the simulator data before object detection and classification is performed. Once object detection and classification are completed, the result is transferred back to the simulator environment. Based on this result, decision support functionality with realistic accuracy and robustness can be presented and autonomous ships can make decisions and navigate in the simulator environment.