Current surveys indicate limited public and individual trust in autonomous vehicles despite a long tradition to ensure their (technical) trustworthiness in informatics and systems engineering. To address this trust gap, this article explores the underlying reasons. The article elaborates on the gap between trust understood as a social phenomenon and, in contrast, the research tradition aimed at guaranteeing (technical) trustworthiness. It discusses to what extent those research traditions in the social sciences and humanities have been recognized and reflected in systems engineering research to date. Trust, according to the current state of research in the social sciences and humanities, heavily relies on individual assessments of an autonomous vehicle's abilities, benevolence and integrity. By contrast, technical trustworthiness is defined as the sum of intersubjective, measurable, technical parameters. They describe certain abilities or properties of a system, often according to respective technical standards and norms. This article places the "explainability" of autonomous systems in a bridging role. Explainability can help to conceptualize an integrative trust layer to communicate a system's abilities, benevolence and integrity. As such, explainability should respect the individual and situational needs of users, and should therefore be responsive. In conclusion, the results demonstrate that "learning from life" requires extensive interdisciplinary collaboration with neighboring research fields. This novel perspective on trustworthiness aligns existing research areas. It delves deeper into the conceptual "how", dives into the intricacies and showcases (missing) interconnectedness in the state of research.
ABSTRACTThe newly established Institute of Systems Engineering for Future Mobility within the German Aerospace Center opened its doors at the beginning of 2022. Emerging from the former OFFIS Division Transportation after a two‐year transition phase, the new institute can draw on more than thirty years of experience in the research field of safety‐critical systems. With the transition to the DLR, the institute's new research roadmap focuses on technical trustworthiness for highly automated and autonomous systems. Within this field, the institute will develop new concepts, methods, and tools to support the integration and assurance of technical trustworthiness for automated and autonomous systems during their whole lifecycle – from the early development through verification, validation, and operation to updates of the systems in the field.
“Safe voyage from berth to berth”: This is the goal of all e-navigation strains, driven by new technologies, new infrastructures and new organizational structures on bridge, on shore as well as in the cloud. To facilitate these efforts suitable engineering and safety/risk assessment methods have to be applied. Understanding maritime transportation as a sociotechnical system allows system engineering methods to be applied. Formal and simulation based verification and validation of enavigation technologies are important methods to obtain system safety and reliability. The modelling and simulation toolset HAGGIS provides methods for system specification and formal risk analysis. It provides a modelling framework for processes, fault trees and generic hazard specification and a physical world and maritime traffic simulation system. HAGGIS is accompanied by the physical test bed LABSKAUS which implements a reference port and waterway. Additionally, it contains an experimental Vessel Traffic Services (VTS) implementation and a mobile integrated bridge enabling in situ experiments for technology evaluation, testing, ground research and demonstration. This paper describes an integrated seamless approach for developing new e-navigation technologies starting with virtual simulation based assessment and ending in physical real world demonstrations.
The 6 degrees of freedom (DOE) model with a high degree of complexity for capturing ship dynamics is generally able to track the nonlinear and coupling dynamics of ships. However, the 6 DOF model makes challenges in estimating model coefficients and designing the model-based control. Therefore, simplified ship dynamic models within allowed accuracy are essential. This paper simplified the 6 DOF nonlinear dynamic model of ships into two decoupled models including the speed model and the steering model through reasonable assumptions. Those models were tested through maneuvering simulations of a container ship with a 4 DOF dynamic model. Support vector machines (SVM) optimized by the artificial bee colony algorithm (ABC) was used to identify parameters of speed and steering models by analyzing the rudder angle, propeller shaft speed, surge and sway velocities, and yaw rate from simulated data extracted from a series of maneuvers made by the container ship. Comparisons with the first order linear and nonlinear Nomoto models show that the simplified nonlinear steering model can capture more complicated dynamics and performs better. Additionally, comparisons among three different parameter identification methods demonstrate similar identification results but the different performance involving the applicability and effectiveness. SVM optimized by ABC is relatively convenient and effective for parameter identification of ship simplified dynamic models. (C) 2017 Elsevier Ltd. All rights reserved.
Determination of ship maneuvering models is a tough task of ship maneuverability prediction. Among several prime approaches of estimating ship maneuvering models, system identification combined with the full-scale or free- running model test is preferred. In this contribution, real-time system identification programs using recursive identification method, such as the recursive least square method (RLS), are exerted for on-line identification of ship maneuvering models. However, this method seriously depends on the objects of study and initial values of identified parameters. To overcome this, an intelligent technology, i.e., support vector machines (SVM), is firstly used to estimate initial values of the identified parameters with finite samples. As real measured motion data of the Mariner class ship always involve noise from sensors and external disturbances, the zigzag simulation test data include a substantial quantity of Gaussian white noise. Wavelet method and empirical mode decomposition (EMD) are used to filter the data corrupted by noise, respectively. The choice of the sample number for SVM to decide initial values of identified parameters is extensively discussed and analyzed. With de-noised motion data as input-output training samples, parameters of ship maneuvering models are estimated using RLS and SVM-RLS, respectively. The comparison between identification results and true values of parameters demonstrates that both the identified ship maneuvering models from RLS and SVM-RLS have reasonable agreements with simulated motions of the ship, and the increment of the sample for SVM positively affects the identification results. Furthermore, SVM-RLS using data de-noised by EMD shows the highest accuracy and best convergence.
Parameter identification techniques assorted from the system identification technology is a sufficient and commonly used approach for estimating the parameters of ship dynamic models. It is not tough to find an identification method to identify the parameters of linear or nonlinear ship dynamic models, but how to select a suitable parameter identification approach with high accuracy and low complexity for special cases is necessary to be studied. This contribution aims at determining a relatively suitable parameter identification method for estimation ship response models via selecting and comparing one intelligent method with the classic least squares method (LS) from a methodological point of view. Support vector machines (SVM) as an intelligent method is chosen because it is a kind of batch identification technique requiring no initial estimation of identified parameters. For well-confirming parameters in SVM, the artificial bee colony (ABC) algorithm instead of the empirical method is used to optimize the parameters in SVM. With the measurement zigzag test data from a scaled-model ship as training and verification samples, the maneuvering indices of ship response models are respectively identified using LS and SVM, and the verification of the identified models are sufficiently proceeded through comparing the prediction and measurement results. It is shown that the two different categories of ship response models are analytically and numerically consistent with each other. Comparison between the measured and predicted maneuvers demonstrates that SVM optimized by ABC algorithm is also an effective parameter identification technique.
Technology is changing the way of navigation. New technologies for communication and navigation can be found on virtually every vessel. System architectures define structure and cooperation of components and subsystems. IMO, IALA, costal authorities, technology provider and many more actually propose new architectures for e-Navigation. This paper looks at other transportation domains and technical as normative requirements for e-Navigation architectures. With the aim of identifying possible synergies in the research, development, certification and standardization, this paper sets out to compare requirements and approaches of these two domains with respect to safety and security aspects. Since from an autonomy perspective, the automotive domain has started earlier and therefore has achieved a higher degree of technical progress, we will start with an overview of the developments in this domain. After that, the paper discusses the requirements on automation and assistance systems in the maritime domain and gives an overview of the developments into this direction within the maritime domain. This then allows us to compare developments in both domains and to derive recommendations for further developments in the maritime domain at the end of this paper.
‘Safe voyage from berth to berth’ — this is the goal of all e-navigation strains, driven by new technologies, new infrastructures and new organizational structures on bridge, on shore as well as in the cloud. To facilitate these efforts suitable engineering and safety/risk assessment methods have to be applied. Understanding maritime transportation as a sociotechnical system allows system engineering methods to be applied. Formal and simulation based verification and validation of e-navigation technologies are important methods to obtain system safety and reliability. The modelling and simulation toolset HAGGIS provides methods for system specification and formal risk analysis. It provides a modelling framework for processes, fault trees and generic hazard specification and a physical world and maritime traffic simulation system. HAGGIS is accompanied by the physical test bed LABSKAUS which implements a reference port and waterway. Additionally, it contains an experimental Vessel Traffic Services (VTS) implementation and a mobile integrated bridge enabling in situ experiments for technology evaluation, testing, ground research and demonstration. This paper describes an integrated seamless approach for developing new e-navigation technologies starting with virtual simulation based assessment and ending in physical real world demon-strations.
E-Navigation aims to enhance the safety and security of maritime activities by exchanging, integrating and analyzing the data between and in ship-side and shoreside systems. In this paper, we present the main characteristics of our semantic data exchange concept developed in the COSINUS project. In addition to the main task of exchanging data written in a variety of formats between on-board and onshore systems, each semantic data processor, which is related to a maritime system like ECDIS (Electronic Chart Display and Information System) or VTS (Vessel Traffic Service), defines a context model, which itself concludes information from the transient streams of data, registers the current state and the history of the ships, assigns some important meta-data such as data quality information and applies semantic compression by sending the interesting patterns only. Therefore, the context models in our data exchange represent cooperatively the navigation situation and this enables cooperative control and monitoring on such navigation and ensures the integration between different marine data sources.
The e-navigation strategy of the International Maritime Organization (IMO) aims to improve the safety of maritime traffic by increasing cooperation between several maritime stakeholders. The COSINUS (Bolles et al., 2014) project contributes to such a strategy by enabling an automated data exchange (observations, routes and maneuver plans) between ship-side and shore-side navigational systems, developing useful sensor fusion applications upon the new information available from data exchange and introducing new Human Machine Interfaces (HMIs) to support the users of navigation systems.The project shows potential for improvement in maritime traffic safety by ensuring continuous awareness to all participants involved through sensor fusion applications, i.e. by providing all participants (mobile and stationary navigation systems) with a complete view at all times. These applications include detection of critical situations like radar shadowing areas, early and accurate prediction of potential collisions or closest point of approach (CPA) based on the exchanged routes, and improving the accuracy of radars by ensuring high quality data for obstructed or far away routes. The new HMI concepts introduced within the COSINUS project aim at highlighting critical maritime traffic situations. Thus, the users of such navigation systems supported with COSINUS facilities can easily detect such critical situations and react efficiently to avoid collisions, possible crowded areas and inefficient routes.
Critical Systems, i.e., systems whose failure either endangers human life or causes drastic economic losses, form the technological backbone of today's society and are an integral part in such vastly diverse industrial sectors as automotive, aerospace, maritime, automation, energy, health care, banking, and others. The Interdisciplinary Research Center on Critical Systems Engineering for Socio-technical Systems addresses critical systems, which rely on synergistically blending human skills with IT-enabled capabilities of technical systems to jointly achieve the overarching societal and industrial objectives. We focus on instances of such socio-technical systems in the transportation domain, where the overarching objectives are to achieve safe and green mobility, through cooperative semi-autonomous guidance of vehicles with humans in the loop, such as in their roles as drivers, operators, navigation officers, flight controllers, etc., and consider two industrial sectors key in Lower Saxony, the automotive and maritime domains. Such systems are safety critical – human errors, technical failures and malicious manipulation of information can cause catastrophic events leading to loss of life. Creating sufficiently precise real-time mental or digital images of real-world situations, and assuring their coherence among all involved actors (both humans and technical systems) as a basis for coordinated action is a major challenge in socio-technical system design. This calls for constructive approaches involving intuitive and scalable patterns of cooperation, between humans and technical systems, seeking for a balanced sharing of tasks best matching both the abilities of humans and technical systems, or between technical systems. It calls for insights in understanding humans in their interaction with technical systems. It calls for layered approaches in aggregating information along both spatio-temporal and cognitive dimensions. It calls for robust and adaptable designs, seamlessly catering with adverse and changing environmental conditions. It calls for executable and composable models of socio-technical systems, both human and technical, allowing to adaptively, as it were, “zoom” into detailed levels, when reaching critical states to provide fine-grained views of the actual interactions, as well as the need to aggregate to coarse views in order to cope with the sheer complexity of such models.
Abstract‘Safe voyage from berth to berth’ — this is the goal of all e-navigation strains, driven by new technologies, new infrastructures and new organizational structures on bridge, on shore as well as in the cloud. To facilitate these efforts suitable engineering and safety/risk assessment methods have to be applied. Understanding maritime transportation as a sociotechnical system allows system engineering methods to be applied. Formal and simulation based verification and validation of e-navigation technologies are important methods to obtain system safety and reliability. The modelling and simulation toolset HAGGIS provides methods for system specification and formal risk analysis. It provides a modelling framework for processes, fault trees and generic hazard specification and a physical world and maritime traffic simulation system. HAGGIS is accompanied by the physical test bed LABSKAUS which implements a reference port and waterway. Additionally, it contains an experimental Vessel Traffic Services (VTS) implementation and a mobile integrated bridge enabling in situ experiments for technology evaluation, testing, ground research and demonstration. This paper describes an integrated seamless approach for developing new e-navigation technologies starting with virtual simulation based assessment and ending in physical real world demonstrations.
Due to the fact that currently operating autonomous vehicles can observe only a limited area with their onboard sensors, safety regulations often dictate a very slow speed. However, as more and more sensors in the environment are available, we can fuse their information and provide extended information as a shared context model to support the autonomous vehicles. In this paper, we consider a scenario with a publicly accessible area that is populated with autonomous transport vehicles, human guided vehicles like trucks or bicycles, and pedestrians. We analyze requirements and challenges for highly dynamic context models in this scenario. Furthermore, we propose a comprehensive system architecture that can cope with these challenges, namely deterministic processing of multiple sensor updates with high throughput rates, prediction of moving objects, and on-line quality assessments, and demonstrate the feasibility of this approach by implementing the generic system architecture with laser scanners for object detection.
One of the main challenges in the development of traffic systems is to assure safety for all road users. Hence, especially expensive vehicles are equipped with advanced driver assistance systems (ADAS) that use data about the vehicle and information about objects in the proximity of the vehicle to execute the assistance function. These objects have to be detected by sensors and they have to be tracked over multiple scans to keep the object's state up-to-date. Usually, such ADAS are developed as proprietary systems that are tailored for the specific assistance function and the specific sensors in use. Indeed, that leads to a very efficient system. However, changing system properties, e. g. an exchange of sensors, is very expensive. In this case, very often at least some parts of the system code have to be reimplemented. To solve this problem of bad maintainability which arises especially during the development of new assistance functions in this work a new architecture for ADAS is presented. The relevant information for the assistance function is no longer provided by hard coded, predefined processes, but by flexible continuous operator plans in a datastream management system. These operator plans build up a dynamic context model of the vehicle's environment. The context model is kept up-to-date by object tracking operators in these operator plans and is then used as a data source to extract information for different assistance functions. This extraction is also done by operator plans that produce only relevant information and discard other information.
Kontextsensitive Anwendungen benötigen ein möglichst exaktes Modell der Umgebung. Zur Ermittlung und regelmäßigen Aktualisierung dieses Kontextmodells werden typischerweise Sensordaten verwendet. Datenstrommanagementsysteme (DSMS) bilden die ideale Basis, um mit den durch die Sensoren generierten, potentiell unendlichen Datenströmen umzugehen. Leider bieten bisherige DSMS keine native Unterstützung für dynamische Kontextmodelle. Insbesondere die bei der Aktualisierung entstehenden Zyklen im Anfrageplan bedürfen einer besonderen Koordination, um Aktualität und Konsistenz des Kontextmodells zu gewährleisten. Diese Arbeit präsentiert eine Lösung, die einen Broker zur Koordination der verschiedenen Zugriffe auf das Kontextmodell als neuen Operator im DSMS einführt. Wir zeigen dazu eine semantische Beschreibung und eine abstrakte Implementierung des Brokers.
Die Ve rarbeitung vo nk ontinuierlichen Datenstr¨ omen, bspw .a us Senso- ren, gewinnt zunehmend an Bedeutung. Flexible M¨ oglichkeiten zur Ve rarbeitung sol- cher Daten werden durch Konzepte des Datenstrommanagements (DSM) bereitge- stellt. Bisherige prototypische Datenstrommanagementsysteme (DSMS) wurden je- weils zur Evaluation bestimmter Ve rarbeitungskonzepte entwickelt. Der Ve rgleich oder die kombinierte Betrachtung dieser verschiedenen Konzepte ist bisher nur unter grosem Aufwand m¨ oglich, da hierzu verschiedene DSMS integriert werden m¨ ussen. An der UniversitOldenbur gw ird daher ein Datenstrommanagementframework (DSMF) na- mens Odysseus entwickelt, welches es ermnahezu beliebige Aspekte des DSM zu implementieren und zu evaluieren. Dieses Framework wird noch 2010 als Open Source DSMF ver¨ offentlicht. Die vorliegende Arbeit stellt Odysseus und dessen Er- weiterbarkeit vo ru nd erl¨ autert Fragestellungen, die bei der Ver ¨ offentlichung auftreten.
Modern datastream management system (DSMS) assume sensor measurements to be constant valued until an update is measured. They do not consider continuously changing measurement values, although a lot of real world scenarios exist that need this essential property. For instance, modern cars use sensors, like radar, to periodically detect dynamic objects like other vehicles. The state of these objects (position and bearing) changes continuously, so that it must be predicted between two measurements. Therefore, in our work we develop a new bi-temporal stream algebra for processing continuously changing stream data. One temporal dimension covers correct order of stream elements and the other covers continuously changing measurements. Our approach guarantees deterministic query results and correct optimizability. Our implementation shows that prediction functions can be processed very efficiently.