Automated Vehicles (AVs) are rapidly maturing in the transportation domain. However, the complexity of the AV design problem is such that no single technique is sufficient to provide adequate validation of key properties such as safety, reliability or trustworthiness. In this vision paper, a combination of a spatial traffic logic and agent-based verification methods with a validation method that uses assertion checking of simulations is proposed. We sketch how to integrate the respective approaches within a methodological framework called Corroborative Verification and Validation (V&V).The Corroborative V&V framework identifies three different verification and validation levels for AVs (formal verification, simulation-based testing, real-world experiments) and specifies connections and evidence between these levels. We define specifications for the formal relationships that must be established between processes, system models and requirements models for the evidence from formal design verification and simulation-based testing to corroborate each other and enhance assurance confidence from verification and validation.
Safety and mission performance validation of autonomous vehicles (AVs) is a major challenge. In this paper we describe a methodology for constructing and applying assertion checks to validate the behaviour of an AV operating either in simulation or in the real world. We have identified a taxonomy of assertion types and the general format of their specification, and we have developed procedures for translating driving codes of practice to yield formal logical expressions that can be monitored automatically by computer, either by direct translation or by physical modelling. We have developed examples of assertions derived from the UK Highway Code (UKHC), as an example of a code of practice. We illustrate the approach with an example of assertion checking for vehicle overtaking, using a geospatial information system in an SQL database for validation and performance assessment. We present initial simulation and runtime monitoring experiments that apply assertions relevant in this overtaking scenario together with an analysis of the safety and mission performance characteristics measured.
This paper presents current progress in the development of Environmental Survey Hazard Analysis (ESHA), a method of preliminary hazard identification aimed at autonomous system application problems. In addition to performing their design mission, autonomous systems must be capable of reliable and predictable behaviour in their environments, particularly when facing potential hazards that are not explicitly included in their design specifications (’non-mission’ tasks). ESHA differs from conventional hazard identification methods in that its scope explicitly covers the identification of non-mission interactions between a system and its environment and any associated hazards. Although of general use as a safety analysis technique, ESHA has been designed primarily to support a ”so far as is reasonably practicable” (SFAIRP) style of safety argument. However, early versions of the method were based on informal models, and therefore provided only weak support. This paper reviews the development of a formal ontological framework for ESHA, intended to provide much stronger basis for arguing the completeness and consistency of analyses.
Robot manufacturers will be required to demonstrate objectively that all reasonably foreseeable hazards have been identified in any robotic product design that is to be marketed commercially. This is problematic for autonomous mobile robots because conventional methods, which have been developed for automatic systems do not assist safety analysts in identifying non-mission interactions with environmental features that are not directly associated with the robot’s design mission, and which may comprise the majority of the required tasks of autonomous robots. In this paper we develop a new variant of preliminary hazard analysis that is explicitly aimed at identifying non-mission interactions by means of new sets of guidewords not normally found in existing variants. We develop the required features of the method and describe its application to several small trials conducted at Bristol Robotics Laboratory in the 2011–2012 period.
The success of the human-robot co-worker team in a flexible manufacturing environment where robots learn from demonstration heavily relies on the correct and safe operation of the robot. How this can be achieved is a challenge that requires addressing both technical as well as human-centric research questions. In this paper we discuss the state of the art in safety assurance, existing as well as emerging standards in this area, and the need for new approaches to safety assurance in the context of learning machines. We then focus on robotic learning from demonstration, the challenges these techniques pose to safety assurance and outline opportunities to integrate safety considerations into algorithms “by design”. Finally, from a human-centric perspective, we stipulate that, to achieve high levels of safety and ultimately trust, the robotic co-worker must meet the innate expectations of the humans it works with. It is our aim to stimulate a discussion focused on the safety aspects of human-in-the-loop robotics, and to foster multidisciplinary collaboration to address the research challenges identified.
This paper presents a novel robot control architecture for use with personal robots, and argues its potential for improving the safety of these types of system, when compared to existing approaches. The proposed architecture design separates the control system into two distinct areas, one area responsible for safe operation and the other for coordinating tasks. The architecture design is formed in a hierarchical structure, composed of low-level deliberative control modules and high-level behavioural safety modules. It is argued that as a result of removing safety considerations from the design of task routines, increasingly complex tasks can be completed safely, which are both more flexible to environmental changes and easier to coordinate.
This paper is an overview of the work being performed by the ISO committee TC184/SC2 “Robots and Robotic Devices”. SC2 is developing safety standards for robotic applications in personal and medical care, as well as revising existing industrial robot standards with requirements for new applications. A key driver of the new standards is the need for safety guidelines for human robot interaction, as the new applications involve much more extensive HRI behavior than previous generations of industrial robots. The paper summarizes the content of a revision to ISO 10218 for industrial robots, the development of a new standard ISO/NP 13482 for service robots in personal care, and discusses future work in standards for medical care robots and other areas.
The standard McDonald jar was compared with a large volume jar for striped bass, Morone saxatilis, egg incubation. The McDonald jar measured 16 cm in diameter by 45 cm in height and had a volume of 6 L. The experimental jar measured 0.4 m in diameter by 1.3 m in height and had a volume of 200 L. The hypothesis is that there is no difference in percent survival of fry hatched in experimental jars compared with McDonald jars. Striped bass brood fish were collected from the Coosa River and spawned using the dry spawn method of fertilization. Four McDonald jars were stocked with approximately 150 g of eggs each. Post-hatch survival was estimated at 48, 96, and 144 h. Stocking rates resulted in an average egg loading rate (+/- 1 SE) in McDonald jars of 21.9 +/- 0.03 eggs/mL and in experimental jars of 10.9 +/- 0.57 eggs/mL. The major finding of this study was that average fry survival was 37.3 +/- 4.49% for McDonald jars and 34.2 +/- 3.80% for experimental jars. Although survival in experimental jars was slightly less than in McDonald jars, the effect of container volume on survival to 48 h (F = 6.57; df = 1,5; P > 0.05), 96 h (F = 0.02; df = 1, 4; P > 0.89), and 144 h (F = 3.50; df = 1, 4; P > 0.13) was not statistically significant. Mean survival between replicates ranged from 14.7 to 60.1% in McDonald jars and from 10.1 to 54.4% in experimental jars. No effect of initial stocking rate on survival (t = 0.06; df = 10; P > 0.95) was detected. Experimental jars allowed for incubation of a greater number of eggs in less than half the floor space of McDonald jars. As hatchery production is often limited by space or water supply, experimental jars offer an alternative to extending spawning activities, thereby reducing labor and operations cost. As survival was similar to McDonald jars, the experimental jar is suitable for striped bass egg incubation.
The area of robotics is moving from its traditional roots in the industrial sector as the entire robotic community is keen to develop new types of robots for new environments. This change is emphasis is being driven by many factors and it is now widely accepted that robots must become mass market products in order that they may fulfil their full potential in providing assistive capabilities to humans in a wide range of applications. This shift has been noticed and the International Standards Organisation (ISO) has set up new standardization groups to investigate the robot standardization activities that need to be encouraged to facilitate the commercialisation of new types of robots throughout the world. The robotic community has been developing prototype robotic systems for a variety of new applications and many new sectors are causing concern and if they should be encouraged or not. This has started an ethical debate on what should be encouraged and if there are robot applications that should be discouraged. It is accepted that robot applications that generically improve the quality of life for humans should be encouraged but areas which promote unethical areas of human activities should be looked at more closely to determine of robots should be allowed to enter these sector or not; this includes applications such as military applications, sex robots, fully autonomous robots, etc. In view of these developments, discussions have commenced within ISO so that internationally accepted views can be formulated and accepted. This paper presents the start of these deliberations and raises some of the important issues that need to be debated so that internationally accepted views can be agreed at the ISO level so that commercialisation of only the accepted systems is permitted across international boundaries.
With the emergence of mobile robots, including service robots for use in public, domestic and industrial environments, a more comprehensive standard to cover the new robots and associated technologies is needed. New scopes of the robots applications involve almost in every case an autonomous system that can potentially cause harm to the environment, including people or malfunction and fail the mission completely. ISO has developed a set of standards supporting aspects of robot design such as performance measurement, safety assurance, user interfaces and similar for industrial robots manipulators. Evolving robot applications require the standards to be revised to incorporate requirements for new robotic domains. This prompted a group of international robotics experts in 2007 to initiate a development of new terms and regulations and modify the current robotics standard, ISO 8373, to include terms that are applicable to the new generation of robots. This paper provides an outline of the progress of the working group and the associated challenges in updating the international robotics vocabulary standard.
This paper presents a design methodology for behaviour-based intelligent control systems, which we argue is suited to safety critical applications. The methodology has a formal basis, and uses dynamical systems theory to prove system safety properties that are expressed in terms of Lyapunov stability. We propose a new computational model for implementation of these systems, which offers a reduction in complexity due to its non-symbolic structure. Reduced complexity is attractive because it allows improved depth of failure analysis, and potentially increased system reliability.
Swarm Intelligence provides us with a powerful new paradigm for building fully distributed decentralised systems in which overall system functionality emerges from the interaction of individual agents with each other and with their environment. Such systems are intrinsically highly parallel and can exhibit high levels of robustness and scalability; qualities desirable in high-integrity distributed systems. Making use of a laboratory based swarm robotic system as a case study, this review paper explores dependability, robustness and reliability modelling in swarm based systems, and argues that there is considerable merit in further investigating their application to distributed safety-critical systems.
This paper presents a design methodology for a class of behaviour-based control systems, arguing its potential for application to safety critical systems. We propose a formal basis for subsumption architecture design based on two extensions to Lyapunov stability theory, the Second Order Stability Theorems, and interpretations of system safety and liveness in Lyapunov stability terms. The subsumption of the new theorems by the classical stability theorems serves as a model of dynamical subsumption, forming the basis of the design methodology. Behaviour-based control also offers the potential for using simple computational mechanisms, which will simplify the safety assurance process.
This review paper sets out to explore the question of how future complex engineered systems based upon the swarm intelligence paradigm could be assured for dependability. The paper introduces the new concept of ‘swarm engineering’: a fusion of dependable systems engineering and swarm intelligence. The paper reviews the disciplines and processes conventionally employed to assure the dependability of conventional complex (and safety critical) systems in the light of swarm intelligence research and in so doing tries to map processes of analysis, design and test for safety-critical systems against relevant research in swarm intelligence. A case study of a swarm robotic system is used to illustrate this mapping. The paper concludes that while some of the tools needed to assure a swarm for dependability exist, many do not, and hence much work needs to be done before dependable swarms become a reality.
In this paper we propose a new procedure for construction of motor schema typically used in behaviour-based robotics. The procedure reverses the standard stability analysis approach by searching for a control function to fit a pre-defined Lyapunov function. In order to improve the applicability of this procedure, a new second-order extension to Lyapunov's second method is proposed, allowing a stable schema to be defined directly in terms of actuator force demands. We propose a synthesis procedure called direct Lyapunov design, which searches for motor schema maps whose set points satisfy the second-order theorem. The procedure has been applied to a simple subsumption architecture controller for an inverted pendulum simulation, yielding stable behaviour.
Software-based systems usually have complex functionality, and are required to meet very high integrity and reliability requirements. Testing a software-based system to determine whether it meets such requirements is impractical, requiring test runs whose accumulated time is much greater than 109 hours, in order to demonstrate the above reliability requirement. Software does not fail in a random manner; if a program produces an incorrect output (assuming that no hardware failure corrupted the program, which is a different scenario to a software failure), then such an output is inherent in its structure, i.e. the software contains a design error. This makes the use of traditional analysis methods unsuitable, because they are generally suited to assessing random failures in hardware. We present an approach which shows promise in enabling software to be assessed directly for safety. The approach is centred on the use of certain technologies, drawn from the artificial intelligence domain, namely decision trees and behaviour based architectures (e.g. subsumption architecture). The paper describes the features of these technologies, which will be useful in the design and construction of safety critical systems
Safety critical systems are those whose failure may cause damage or even fatality. System safety must be certi- fied -the properties of a system must be known in advance of its entry into service, to understand the risk associated with its operation. This paper presents a design methodology for intelligent systems in safety critical applications. Certification presents a formidable challenge for intelligent systems, because adaptive systems may undergo unpredictable changes to their behaviour. A new methodology has been developed for the con- struction of Subsumption Architecture systems, a specific class of intelligent control scheme also known as bheaviour- based control. The methodology employs novel techniques for Lyapunov stability analysis to prove safety and liveness properties in Subsumption Architecture systems. The research is also investigating new hardware tech- nologies for behaviour-based systems, which may be partic- ularly useful for robotic applications in space, oceanic, or high-radiation environments.