
Zusammenfassung Zukünftige adaptive Rückhaltestrategien benötigen verlässliche Entscheidungen bereits vor dem Aufprall. Diese Dissertation zeigt, wie PreCrash-Sicherheitssysteme durch Umfeldsensorik unvermeidbare Kollisionen erkennen und irreversiblen Insassenschutz vorausschauend aktivieren können. Dazu werden Systemarchitektur und Anforderungen abgeleitet. Kernbeitrag ist ein Modell- und Methodenbaukasten zur Unvermeidbarkeitsbestimmung und Crashparameterprädiktion, einschlieβlich Sensitivitätsanalysen zur Quantifizierung von Toleranzeinflüssen und zur Ableitung von Sensoranforderungen. Ein darauf aufbauendes Prädiktions- und Kollisionserkennungsverfahren ermöglicht Aussagen über Crashkonstellationen sowie über den frühestmöglichen Zeitpunkt einer Auslöseentscheidung. Die Umsetzung in Echtzeit und erste integrale Crashversuche belegen die prinzipielle Eignung für reale Anwendungen.
This paper highlights the necessity of provable runtime safety mechanisms for integrating data-driven control methods into safety-critical systems operating in open environments. Since data-driven methods are often limited in providing formal guarantees, we argue for the use of formal methods, such as safety filters, to provide safety assurances. Safety filters denote a class of runtime mechanisms that ensure safety even if the nominal control method does not ensure safety, by constraining the system state to provably safe sets. The focus of this work is on analyzing safety filters from the perspective of functional safety as defined in industrial standards. We demonstrate how safety filters can provably reduce risks associated with hazardous behavior and how they operate as a monitoring and intervention mechanism for data-driven methods. Diese Arbeit hebt die Notwendigkeit nachweisbarer Sicherheitsmechanismen f & uuml;r die Integration datengetriebener Regelungsverfahren in sicherheitskritische Systeme hervor, die in offenen Umgebungen betrieben werden. Da datengetriebene Methoden h & auml;ufig nur eingeschr & auml;nkte formale Garantien liefern k & ouml;nnen, argumentieren wir f & uuml;r den Einsatz formaler Methoden, wie beispielsweise Safety Filter, zur Gew & auml;hrleistung der Sicherheit. Safety Filter bezeichnen eine Klasse von Mechanismen, die zur Laufzeit Sicherheit auch dann gew & auml;hrleisten, wenn die nominale Regelungsmethode dies nicht gew & auml;hrleistet, indem sie den Systemzustand auf nachweislich sichere Mengen beschr & auml;nken. Der Fokus dieser Arbeit liegt auf der Analyse von Safety Filtern aus der Perspektive der funktionalen Sicherheit im Kontext industrieller Normen. Es wird gezeigt, wie Safety Filter Risiken im Zusammenhang mit gef & auml;hrlichem Verhalten nachweisbar reduzieren k & ouml;nnen und als Mechanismus f & uuml;r Monitoring und Intervention f & uuml;r datengetriebene Verfahren fungieren.
Safe operation of autonomous inland vessels requires sensing and perception systems whose availability, reliability, and functionality can be quantified and linked to adaptive navigation control. This paper introduces a unified framework integrating these aspects into a certifiable approach. Sensor availability, perception reliability, and adaptive speed regulation are combined to ensure robust operation under changing conditions. To cope with degraded sensors, a pre-computed n-dimensional lookup table encodes dependencies of system and environment parameters, enabling validated control actions without online optimization. This reduces computational effort, ensures deterministic behavior, and supports certifiability. The methodology unites redundancy, reliability validation, and risk-oriented control into a coherent framework for autonomous inland navigation. Der sichere Betrieb autonomer Binnenschiffe erfordert Sensor- und Wahrnehmungssysteme, deren Verf & uuml;gbarkeit, Zuverl & auml;ssigkeit und Funktionalit & auml;t quantifiziert und mit einer adaptiven Navigationssteuerung verkn & uuml;pft werden k & ouml;nnen. Dieser Artikel stellt einen einheitlichen Rahmen vor, der diese Aspekte in einem zertifizierbaren Ansatz zusammenfasst. Die Verf & uuml;gbarkeit der Sensoren, die Zuverl & auml;ssigkeit der Wahrnehmung und die adaptive Geschwindigkeitsregelung werden kombiniert, um einen robusten Betrieb unter wechselnden Bedingungen zu gew & auml;hrleisten. Um mit beeintr & auml;chtigten Sensoren umzugehen, codiert eine vorab berechnete n-dimensionale Nachschlagetabelle die Abh & auml;ngigkeiten von System- und Umgebungsparametern und erm & ouml;glicht so validierte Steuerungsma ss nahmen ohne Online-Optimierung. Dies reduziert den Rechenaufwand, gew & auml;hrleistet deterministisches Verhalten und unterst & uuml;tzt die Zertifizierbarkeit. Die Methodik vereint Redundanz, Zuverl & auml;ssigkeitsvalidierung und risikoorientierte Steuerung in einem koh & auml;renten Rahmen f & uuml;r die autonome Binnenschifffahrt.
In many different areas of application, dynamic system models can be decomposed into smaller subsystems according to either their physical or logical nature. Such kind of decomposition is typically helpful for the design and analysis of cyber-physical systems, where logical components - comprising control and state estimation algorithms - alter the dynamics of physical subsystems in a purposeful manner. The structured synthesis and the verification of such cyber-physical systems can be guided by means of methods from the domain of contract-based design. This approach allows for verifying the dynamic behavior of each of the interconnected components independently. Afterwards, conclusions on the behavior of the interconnected system can be made on the basis of operations such as contract composition and contract refinement. In this paper, we present a methodology that employs set-based contract specifications, determined with the help of techniques for reachability analysis to verify the overall system. These contracts are the basis for further stages of controller tuning. Our approach is essentially based on a two-stage procedure. Firstly, a set-based reachability analysis is conduced for models which are subject to uncertain but bounded parameters. These parameter intervals are then restricted further in a contract strengthening stage, complementing the classical concepts of contract refinement and composition, which, among others, allows for selecting optimal constant controller parameters or for determining optimal switching sequences between multiple control laws. Analogously, reconfigurations of the controlled plant can be performed in a similar manner, for example, with the aim to prove the admissibility of reconfiguration approaches in the case of faults that can be mapped onto bounded parameter variations. In vielen unterschiedlichen Anwendungsgebieten k & ouml;nnen dynamische Systemmodelle je nach ihrer physikalischen oder logischen Struktur in kleinere Teilsysteme unterteilt werden. Eine solche Zerlegung ist typischerweise bei der Gestaltung und Analyse von cyber-physischen Systemen hilfreich, bei denen logische Komponenten - bestehend aus Regelungs- und Zustandssch & auml;tzalgorithmen - die Dynamik physikalischer Teilsysteme gezielt beeinflussen. Der strukturierte Entwurf und die Verifikation solcher cyber-physischen Systeme k & ouml;nnen durch Methoden des kontraktbasierten Entwurfs geleitet werden. Dieser Ansatz erm & ouml;glicht die unabh & auml;ngige Verifikation des dynamischen Verhaltens jeder einzelnen miteinander verbundenen Komponente. Anschlie ss end k & ouml;nnen Schlussfolgerungen & uuml;ber das Verhalten des gesamten gekoppelten Systems auf Basis von Operationen wie Kontrakt-Komposition und Kontrakt-Verfeinerung gezogen werden. In diesem Artikel wird eine Methodik pr & auml;sentiert, die mengenbasierte Kontraktspezifikationen nutzt, die mit Hilfe von Techniken zur Erreichbarkeitsanalyse das Gesamtsystemverhalten verifizieren und die Basis zur Optimierung von Reglern bilden. Dieser Ansatz basiert im Wesentlichen auf einem zweistufigen Verfahren. Zun & auml;chst wird eine mengenbasierte Erreichbarkeitsanalyse f & uuml;r Modelle durchgef & uuml;hrt, die unsichere, aber beschr & auml;nkte Parameter enthalten. Diese Parameterintervalle werden dann in einer Phase der Kontraktversch & auml;rfung als Erg & auml;nzung zu den klassischen Konzepten der Kontrakt-Verfeinerung und -Komposition weiter eingeschr & auml;nkt, die unter anderem die Auswahl optimaler konstanter Reglerparameter oder die Bestimmung optimaler Schaltsequenzen zwischen mehreren Regelgesetzen erm & ouml;glicht. Analog k & ouml;nnen auch Rekonfigurationen von Streckenkomponenten auf & auml;hnliche Weise vorgenommen werden, beispielsweise mit dem Ziel, die Zul & auml;ssigkeit von Rekonfigurationsstrategien im Falle von Fehlerszenarien, die auf beschr & auml;nkte Parameter & auml;nderungen zur & uuml;ckgef & uuml;hrt werden k & ouml;nnen, zu validieren.
This article focuses on filtration processes and AI models for forecasting membrane fouling, measured by the pressure drop (TMP) at the membrane. While conventional AI models can achieve accurate TMP forecasts, they require large amounts of training data and time-consuming training procedures. However, the amount of filtration data to train AI models is very sparse, leading to an industrial need for self-learning forecasting models. With those self-learning abilities, built-in guarantees for adequate forecasts are mandatory. The main contribution is a self-learning ARIMA model with an adaptive training data selection and a built-in guard mechanism that guarantees process-technically logical TMP forecasts by ensuring their adherence to expert-defined rules on the TMP curve's dynamic. Evaluation results confirm that the guard improves the forecasting performance. Dieser Artikel befasst sich mit Filtrationsprozessen und KI-Modellen zur Vorhersage von Membranverschmutzungen, welche anhand des Druckabfalls (TMP) an der Membran gemessen werden. Herk & ouml;mmliche KI-Modelle k & ouml;nnen zwar genaue TMP-Vorhersagen liefern, erfordern jedoch gro ss e Mengen an Trainingsdaten und zeitaufw & auml;ndige Trainingsverfahren. Die Menge an Filtrationsdaten zum Trainieren von KI-Modellen ist jedoch sehr gering, was zu einem industriellen Bedarf an selbstlernenden Vorhersagemodellen f & uuml;hrt. Bei diesen selbstlernenden F & auml;higkeiten sind zus & auml;tzliche Garantien f & uuml;r ad & auml;quate Vorhersagen unerl & auml;sslich. Der Hauptbeitrag ist ein selbstlernendes ARIMA-Modell mit einer adaptiven Auswahl der Trainingsdaten und einem integrierten Schutzmechanismus (Guard), der prozesstechnisch logische TMP-Vorhersagen garantiert, indem dieser die Einhaltung von Expertenregeln f & uuml;r die typische Dynamik von TMP-Kurven sicherstellt. Die Evaluationsergebnisse best & auml;tigen, dass der Guard die Vorhersagen erheblich verbessert.
In Surface Mount Technology (SMT) processes, high-dimensional datasets pose significant computational and interpretability challenges. This work presents an extended root cause selection pipeline within a Yield Management framework, which reduces the execution time by 66 %, selects more suitable root causes, and maintains the same predictive accuracy as traditional approaches. This is achieved by explicitly integrating engineering knowledge in the form of root and cause separation into the data preprocessing, thus enhancing the suitability of detected root causes and decreasing computational time. Additionally, a dedicated confidence evaluation based on engineering knowledge quantifies the reliability of identified causes, ensuring that domain expertise guides interpretation. In Surface-Mount-Technology (SMT)-Prozessen entstehen hochdimensionale Datens & auml;tze, die aufw & auml;ndig auszuwerten sind. Der Beitrag stellt eine erweiterte Pipeline zur Fehlerursachenauswahl im Rahmen eines Ertragsmanagementsystems vor, welche die Laufzeit um 66 % reduziert, geeignetere Ursachen identifiziert und dabei die Vorhersagegenauigkeit im Vergleich zu klassischen Ans & auml;tzen beibeh & auml;lt. Die Pipeline integriert dabei dom & auml;nenspezifische Expertise, wie die Trennung von Ursache und Effekt, in die Datenvorverarbeitung. Somit steigt die Qualit & auml;t der identifizierten Ursachen und die Rechenzeit sinkt. Eine gezielte, ebenfalls auf Dom & auml;nenwissen basierende Konfidenzanalyse quantifiziert die Zuverl & auml;ssigkeit der identifizierten Ursachen und erm & ouml;glicht die Ableitung prozess- und datengest & uuml;tzter Empfehlungen zur Ertragsverbesserung.
This article presents a unifying perspective on absolute stability concepts. In particular, it develops a Lyapunov-like explanatory framework for a nonscalar circle criterion with its small-gain and strict-passivity special cases. To this end, a general defining inequality for a Lyapunov-like function is proposed that avoids strict definiteness conditions, enabled by a strengthening of the sector constraint. We discuss different ways to derive a quadratic solution: via a linear matrix inequality (LMI), an algebraic Riccati equation, and a matrix equation. By exploiting the Kalman-Yakubovich-Popov (KYP) lemma, classical frequency-domain results are recovered. A passivity-index-based result is derived that simplifies the evaluation. Overall, the presented interrelations may be useful for both analysis and teaching.
The increased use of Artificial Intelligence (AI) in safety-critical systems such as Automated Driving Systems (ADS) requires a reevaluation of established Systems and Safety Engineering processes to accommodate AI characteristics. Datasets determine an AI system's (potentially hazardous) behavior significantly. Hence, ISO/PAS 8800 demands dataset requirements, safety analyses, and validation activities in an AI safety lifecycle. This article investigates commonalities between Safety Engineering Activities specified in ISO 21448 and dataset-related activities specified in ISO/PAS 8800. We introduce a model-based approach to support traceability from knowledge about an Operational Design Domain to required dataset requirements and data labels for training and testing AI systems in the scope of ISO/PAS 8800. The approach is demonstrated in an example safety analysis for an L4 hub-to-hub scenario.
Future adaptive restraint strategies require reliable decisions already before impact. This dissertation shows how pre-crash safety systems can use environment perception to detect inevitable collisions and to proactively activate irreversible occupant protection. Based on this, a generic system architecture and requirements are derived. The core contribution is a toolbox of models and methods for inevitability assessment and crash-parameter prediction, including sensitivity analyses to quantify uncertainty influences and to derive sensor requirements. Building on this, a prediction and collision-detection approach enables statements about crash constellations as well as the earliest possible point in time for a trigger decision. Real-time implementation and first integral crash tests demonstrate principal suitability of the system chain for real-world applications.
Safeguarding autonomous vehicles is a constant challenge, since unknown circumstances that the system may not be able to handle can always arise in real-world traffic. This work proposes a monitoring framework for automotive perception sensors to detect such situations. The objective is to detect anomalous behavior from LiDAR and camera sensors at the level of object state estimations. A contrastive embedding method is used to map object states into a structured latent space. An intelligent trigger utilizes this representation space to perform anomaly detection. A key feature of the monitoring framework is that no anomaly labels are required during the training. Further, the proposed monitoring framework can be applied online, complying with ISO 21448 regarding operation phase activities. Experiments are performed on the publicly available real-world nuScenes dataset.
Simulative and scenario-based testing are crucial methods in the safety assurance for automated driving systems. To ensure that simulation results are reliable, the real world must be modeled with sufficient fidelity, including not only the static environment but also the surrounding traffic of a vehicle under test. Thus, the availability of traffic agent models is of common interest to model naturalistic and parameterizable behavior, similar to human drivers. The interchangeability of agent models across different simulation environments represents a major challenge and necessitates harmonization and standardization. To address this challenge, we present a standardized and modular simulation integration architecture that enables the tool-independent integration of traffic agent models. The architecture builds upon the Open Simulation Interface (OSI) as a structured message format and the Functional Mock-up Interface (FMI) for dynamic model exchange. Rather than introducing yet another model or simulation tool, we provide a reusable reference implementation that translates these standards into a practical integration blueprint, including clear interfaces, data mappings, and execution semantics. The generic nature of the architecture is demonstrated by integrating an exemplary agent model into three widely used simulation environments: OpenPASS, CARLA, and CarMaker. As part of the evaluation, we show that the model yields consistent behavior in all simulation platforms, thereby validating the interoperability, modularity, and standard compliance of the proposed architecture. The reference implementation lowers integration barriers, serves as a foundation for future research, and is made publicly available at github.com/ika-rwth-aachen/agent-model-integration
Hydraulic excavators remain among the least automated construction machines due to nonlinear hydraulics, varying environment interactions, and strict real-time requirements. We present a physics-informed online learning framework that provides a standardized velocity-level control interface, abstracting machine-specific hydraulics and enabling integration with higher-level automation. A physics-motivated base model is augmented with an online residual learner to compensate nonlinearities in real time. Experiments on a 12-ton excavator in leveling, grading, and a demanding 4-point cycle show substantial improvements over the base model alone: maximum absolute tracking error is reduced by up to 63 % in leveling and 70 % in the 4-point cycle, while RMSE is reduced by up to 54 % and 69 %. Hydraulische Bagger z & auml;hlen nach wie vor zu den am wenigsten automatisierten Baumaschinen. Gr & uuml;nde hierf & uuml;r sind die Nichtlinearit & auml;ten der Hydraulik, variierende Interaktionen mit der Umgebung sowie strenge Echtzeitanforderungen. Wir stellen ein physik-informiertes Online-Lernframework vor, das eine standardisierte Regelungsschnittstelle auf Geschwindigkeitsebene bereitstellt. Dadurch werden maschinenspezifische hydraulische Eigenschaften abstrahiert und die Integration in & uuml;berlagerte Automatisierungsfunktionen erm & ouml;glicht. Ein physikalisch motiviertes Basismodell wird um einen online trainierten Residual-Lerner erweitert, der Nichtlinearit & auml;ten in Echtzeit kompensiert. Experimente mit einem 12-Tonnen-Bagger bei Planier- und Gradierungsaufgaben sowie in einem anspruchsvollen 4-Punkt-Zyklus zeigen deutliche Verbesserungen gegen & uuml;ber dem alleinigen Basismodell: Der maximale absolute Regelfehler wird beim Planieren um bis zu 63 % und im 4-Punkt-Zyklus um bis zu 70 % reduziert, w & auml;hrend der RMSE um bis zu 54 % bzw. 69 % sinkt.