Re-imagining ISO 26262 in the Age of Autonomous Vehicles: Enhancing Controllability through Transferability and Predictability
This paper proposes re-imagining the ISO 26262 Controllability criterion for autonomous vehicles by decomposing it into measurable dimensions of Transferability and Predictability, thereby creating a mathematical framework to quantify and falsify fallback capabilities and interaction behaviors in driverless systems.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Imagine you are teaching a new driver how to handle a car. The current safety rules (called ISO 26262) were written for humans. They ask three big questions to decide how dangerous a situation is:
- How bad could the crash be? (Severity)
- How often does this happen? (Exposure)
- Can the driver steer or brake to avoid it? (Controllability)
The third question, "Can the driver avoid it?", works great for humans. But what happens when you take the human driver out of the car and replace them with a robot? The robot can't "steer" in the same way a human reacts, and there is no human to "take over" if the robot gets confused.
This paper proposes a new way to answer that third question for self-driving cars. Instead of asking "Can a human control this?", it splits the answer into two new, measurable parts: Transferability and Predictability.
Here is the breakdown using simple analogies:
1. Transferability: The "Emergency Backup Plan"
In a human car, "Controllability" is about how fast a human can react. In a self-driving car, we need to know: If the main brain fails, can the car's backup system take over safely?
- The Analogy: Imagine a pilot flying a plane. If the autopilot fails, the pilot must be able to grab the controls and land the plane safely. In a self-driving car, the "pilot" is the backup software.
- The Paper's Claim: The authors call this Transferability. It measures how well the car can hand off control from its main system to a "safety net" (a fallback mechanism) before a disaster happens.
- The "Gap" (∆T): The paper introduces a concept called the "Designed vs. Achievable Gap."
- Designed: What the engineers think the backup system can do on paper.
- Achievable: What the backup system actually does when tested in real, messy situations (like rain, blocked roads, or glare).
- If the real-world performance is worse than the design, there is a "gap." The paper argues we must measure this gap honestly rather than just trusting the design drawings.
2. Predictability: The "Clear Intent"
The second part of the problem is that self-driving cars don't just need to be safe internally; they need to be safe with other people. If a car stops suddenly or moves weirdly, pedestrians and other drivers might get confused and panic.
- The Analogy: Imagine you are walking down a busy street. You can tell a person is about to cross the road because they look at you, step forward, and wave. You can "predict" their move. If someone walked toward you, stopped, spun in a circle, and then ran backward, you wouldn't know what they were doing, and you might trip or get hurt.
- The Paper's Claim: The authors call this Predictability. It measures how easy it is for a pedestrian or another driver to guess what the self-driving car will do next.
- How it works: The paper suggests checking four things to see if the car is "predictable":
- Context: Is the car moving like a normal car in this situation?
- Intent: Is it clear what the car wants to do? (e.g., turning left vs. going straight).
- Signals: Do the turn signals and brake lights match the car's actual movement?
- Surprise: Did the car make a sudden, jerky move that no one could explain?
Putting It Together: The New Safety Score
The paper suggests combining these two new scores (Transferability and Predictability) to create a new, upgraded version of the old "Controllability" score.
- The Logic: If a car has a great backup plan (High Transferability) but drives in a confusing, jerky way (Low Predictability), it is still dangerous.
- The Result: The paper creates a mathematical formula to mix these scores. If the car is good at both, it gets a "safe" rating. If it fails at either, the safety rating drops, and the car needs to be fixed or restricted to simpler roads.
Why This Matters
The authors aren't saying the old rules are wrong; they are saying the old rules were built for humans, and self-driving cars are different.
- Old Rule: "Can the human driver fix this?"
- New Rule: "Can the car's backup system fix it (Transferability) AND can the people around it understand what the car is doing (Predictability)?"
By measuring these two things, regulators and engineers can prove that a self-driving car is safe not just because it has good sensors, but because it has a reliable backup plan and behaves in a way that humans can understand.
Important Note from the Paper:
The authors are very careful to say this is a proposal for how to update the rules, not a finished law. They emphasize that these new scores are meant to add to the existing safety checks, not to let companies skip the hard work of making cars safe. They also warn that you can't just use the same computer program to design the car and then test if the car is predictable; the test must be independent to be trusted.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.