Velodyne Lidar Inc. baffled by Uber crash
bloomberg.com
bloomberg.com
One, you're comparing this incident with an idealized human. Everybody thinks pilots and drivers are magical beings that don't make mistakes. And then 90 people die because one engine catches fire, pilot turns off the other engine and then banks the aircraft for make a quick emergency landing, obviously the plane loses lift immediately, drilled itself into a bridge, taking a taxi with it into the river below. No survivors, almost a hundred dead [1]. And I get it, the pilot needed to rapidly make a series of decisions under ridiculous levels of stress, that's the real cause. But when things go wrong close to the ground at 150km/h in an object that weighs 50 tons, they go wrong quickly, so you need to respond quickly. Needless to say, nothing prevents reoccurence. Quite simply, a plane will crash if you do this. There's nothing that can technically be done to prevent it. As for cars, over 10.000 people die every year because humans can't be bothered to wait until they sober up to drive [2]. Those are the human pilots that we should measure against.
Frankly, I don't understand how humans are allowed to drive cars or fly planes at all. We pass signals in our brain, they can cross from neuron to neuron in about 10ms. That means that in a second, a signal can affect, at most, a ball with radius 2cm in our brain. To spread out over the brain requires 7-8 seconds minimum in theory and in practice minutes is the more common scenario. That means, it's your spinal column that's driving the car/flying the plane and it gets updates "from upstairs" that are 2-5s old by the time they reach the control loops. Our brain is very good at predicting events so it doesn't look like that's the case, but it is.
Compare self-driving or other autopilots against realistic humans, who make these sorts of mistakes. An average autopilot needs to do better than a decent human driver. It should not need to outperform a magical how-we-imagine-ourselves perfect human driver.
That said, I do agree that we need some basic rules. Tesla's car did NOT stop after crashing into a truck after a lidar mistake (and a serious mistake by the truck driver that it was attempting to compensate for I might add), but not stopping, that's utterly unforgivable. Same here, obviously the car was obviously either driving with the lidar turned off or ignoring it's output. That's like a human driving with their eyes closed.
But certification must be functional. It can't be on the quality of individual components. It can't be on code review. It must be functional. We should have test tracks where autopilots get confronted with dozens of situations, preferably combining 5-6 individual problems at the same time. And then it needs to navigate it safely, under constant decision pressure. And then it needs to end with 5 cars being sacrificed to test their reactions when something heavy drops on them, when they drop off a cliff, when they get mechanically blocked, and when catastrophic mechanical failure occurs ... (so they don't put the pedal to the metal causing 10x the damage to others when they do have an accident).
But it needs to be a functional, practical test. Not the madness we currently have for aviation.
[1] https://www.youtube.com/watch?v=jKNREZ_u8E8&t=31s
[2] https://www.cdc.gov/motorvehiclesafety/impaired_driving/impa...
Could you clarify this point for a non-biologist? I understand the neuron-to-neuron transmission is not going to happen at the full electrical conductivity rate (something like 100 m/s) but this seems so much slower as to be hard to understand as a lay person.
Electrical conductivity is barely used at all. It is used in the processing of the resulting signal, but not in transmitting it. Even that part is very different from a current on a wire or through a transistor.
This video describes the 99.99% part well (99.99% in terms of distance, which is the axons): https://www.youtube.com/watch?v=C_H-ONQFjpQ
What we need to keep in mind is that sensing an object is different from deciding whether or not to take an action (e.g., hitting brakes, raising alarms, swerving, etc.).
Most LiDAR/RADAR/Camera manufacturers only provide input data. It's like saying "hey, I see this". It's up to the perception software to decide whether or not to make a decision.
In most cars, relatively simpler decisions are made by the car's perception software (e.g., adaptive cruise control, lane change warning, automatic braking, etc.).
Self-driving companies override such systems, and rewire the car such that it is their perception software that makes the decision. So the onus is completely on the self-driving company's software. In this case, it is the perception software developed by Uber to be critiqued - not Velodyne, not Volvo, not the camera manufacturer.
It looks like the engineers at Velodyne feel confident that they should (and would have) sensed the person, and hence their statement. I wouldn't doubt them much as they have been in the LiDAR game since DARPA days when self driving was considered experimental.
From a different angle, Velodyne may not have much to loose by throwing Uber under the bus - especially when compared to how much their reputation is at stake. This is because Velodyne has several big customers (e.g., Waymo, and almost every other self-driving, mapping company that is serious about getting big).
NTSB should and will get access to the point clouds. Uber has a choice of releasing the point clouds to the public - but I highly doubt they will.
These problems probably should not have prevented detecting this obstacle, though. But, a lot depends on factors like the range of the pedestrian/bike, the particular Velodyne unit used, and the mode it was used in.
One key thing is that lidar reflections off the bike would have been spotty, but lidar off the pedestrian's body should have been pretty good. That's a perhaps 50-cm wide solid object, which is pretty large by these standards. But the number of lidar "footprints" on the target depends on range.
You'd have to estimate the range of the target (15m?) and compute the angle subtended by the target (0.5m/15m ~= 0.03 radian ~= 2 degrees), and then compare this to the angular resolution of the Velodyne unit to get a number of footprints-on-target.
Perhaps a half dozen, across a couple of left-to-right scan lines. Again, depending on the scan pattern of the particular Velodyne unit in use. The unit should make more than one pass in the time it took to intersect the pedestrian.
This should be enough to detect something, if the world-modeling and decision-making software was operating correctly, hence the puzzlement.
To give an example how big (or small) this noise would have been in this situation I did a very simple virtual scan of a person with a bicycle at a distance of 15 meters [1]
It was scanned with a virtual scanner inside our sensor simulation software, so this is not the real data and should be taken with a grain of salt.
I think half the people commenting on this incident have misspelled "brake". It's odd, because that's not something I've observed as a common error before.
"Radar is robust against bad weather, rain and fog; it can measure speed and distance of an object, but it does not provide enough data points to detect obstacle boundaries, and experimental results show that radar is not reliable to detect small obstacles like pedestrians."
This would be because the wavelength of lidar is in the micron range while that of vehicle-detection radar is in the mm-cm range. You won't be able to reliably get radar reflections off of mm/cm-scale objects or object elements, or accurately (<1cm) localize object boundaries. Good navigation would require tighter localization.
Radars are really good, though, for detection of objects, including identifying moving objects, close up -- canonical examples being walls and other vehicles. Radar sensors are rather cheap (having been in mass production for a long time) so it's common to have one on every bumper or corner.
And a 10 kg. metal object placed in the path of an autonomous car should cause all kinds of emergency measures to engage.
Many high end cards have auto braking systems based on radar (and additional sensors). Mercedes even has a similar scenario on their product page [1]
Volvo does so too, as far as I could find.
So not only did they not detect the obstacle with two different sensor technologies they may have deactivated the already existing safety features in that car as well.
[1] https://www.mercedes-benz.com/en/mercedes-benz/innovation/on...
This is not exactly throwing Uber under the Bus as they themselves have an interest in being able to tell that story later on: "Our analysis concluded that our algorithms didn't put enough weight on the data coming from the lidar, which worked as intended and should have been weighted higher in these specific circumstances, we will adjust our efforts accordingly and will Donate $largeSum to CarsAgainstHumanity to bribe everyone into forgetting how bad we fucked up."
Who knows what other greater context the particular statements were in. After this past election I never trust these types of one-line quotes taken from a larger interview.
The headline could easily have been:
- Uber's Lidar manufacturer just as "baffled" why pedestrian not detected before crash
The responsible thing to do is wait for the results of the investigation.
> “In addition to Lidar, autonomous systems typically have several sensors, including camera and radar to make decisions,” she wrote. “We don’t know what sensors were on the Uber car that evening, if they were working, or how they were being used.”
There's still a ton of variables here besides whether or not the Lidar detecting the pedestrian. Including the other sensors, how the software works, etc. All things out of the scope of Velodynes knowledge.
Velodyne is not saying that they are certain the car should/could have stopped in time or avoided the crash. Their perspective is merely regarding the functionality of Lidar being able to detect the person.
Not to mention we don't even know whether the Lidar malfunctioned yet either...
"Why is it OK for the LIDAR company to make a blanket statement of innocence without proof, but not OK for Uber to do the same?"
This is a disingenuous question. It assumes facts not in evidence, to use the legal aphorism. Velodyne did not "make a blanket statement of innocence without proof". It made a very narrow and defensible claim, namely, that its product, when working properly under the conditions at the time, should have been able to detect the pedestrian. It is obviously true that there are "a ton of other variables" but that is a red herring with respect to the original question.
I agree, if anything I supported this statement with my comment.
The difference is that regardless of the narrowness of their claim, it will have a broader impact on how people judge Uber. Nor do we even know if the Lidar was functioning properly, which is an assumption Velodyne is making when they made their claim.
We simply need more evidence before we can fully judge Uber. And before we can give Velodyne a complete pass in terms of the functionality of their Lidar.
The airline, the manufacturer, the engine manufacturer, the part(s) suppliers, the pilots... will all point at each other. Usually the pilots lose because they don't have any money whether they were at fault or not.
You have to wonder why everyone isn't pointing at the safety driver in this case.
Here's an example of everyone blaming everyone else, and the manufacturer lost despite it not actually being their fault:
I think it makes sense to for Velodyne to get a head of the message before any client throw Velodyne under the bus. If Velodyne takes the hit, all their suppliers have leverage over them. Staying ahead keeps the clients confident in Velodyne products.
Also scale-wise, the market is tiny at this point. Nobody cares the sales from quarter to quarter because whenever self-driving cars hit mainstream, all previous numbers will be scribbles in the margin.
Velodyne has a finger in practically every major self driving car pie slice. It's pretty much heads you lose, tails I win for them (Assumption:nobody can bring a better laser to market).
If they're sure it's not their fault it's a good idea to get that information out before people start questioning LIDAR technology. If Uber leaves they'll lose sales in the short term. If everybody else gets scared away then they're toast.
Could lidar/cameras/etc on the vehicle be obscured by road debris or worse, things being bumped/moved, smudged, or even foul play?
The analogy doesn't stand up - there's a non-trivial chance that a memory module or your hard drive in your laptop will fail over the lifetime of the device.
Furthermore, a LIDAR unit is complex and has firmware and lower-level software embedded that may be at fault.
EDIT: https://www.nytimes.com/interactive/2018/03/20/us/self-drivi...
https://www.azcentral.com/story/news/local/tempe-breaking/20...
edit: Errr..... http://money.cnn.com/2018/03/20/news/companies/self-driving-...
"the car was going approximately 40 mph in a 35 mph zone, according to Tempe Police Detective Lily Duran."
So... was it 40 in a 45, or 40 in a 35? It would seem this is critical information.
edit Now it makes sense.
I went through Google Street View. Northbound on Mill Ave, from before Curry Road to afterward, is 45mph. https://www.google.com/maps/@33.4350531,-111.941492,3a,75y,3...
Southbound on Mill Ave, and on Center Parkway, there are no southbound speed limit signs posted. But after the Curry Road intersection, there is a 35mph sign. https://www.google.com/maps/@33.4371031,-111.9433154,3a,75y,...
I thought the Uber was north of Curry Road going south, but after comparing the video to the map, it looks like the Uber was south, heading north to the intersection. The road opens up and there are two metal signs. https://www.google.com/maps/@33.4362927,-111.9424451,3a,75y,...
So, yes, the speed limit on the road in the direction the Uber was traveling on the stretch of road it was traveling was indeed 45mph.
Also, very sadly, at the point of impact, there was actually a sign that said "Do not cross; Use Crosswalk ->". https://www.google.com/maps/@33.4365489,-111.942659,3a,22.9y... Although not facing the direction the bicyclist was crossing from. I'm willing to bet an accident had happened here before.
Really? This is really common. Think about a road connecting a town and a rural area. In the half-mile adjacent to the town, the into-town direction will be limited lower to get drivers to slow down as they approach town, and the out-of-town direction will be posted at the higher rural limit.
Lidar's see everything in a specific plane that's originated at their sensor. This situation is exactly what lidars are made for ...
Remember the Tesla accident ? A lidar was scanning planes in front of the Tesla and there was a large truck in front of it. A truck hangs low at the front and at the back, and the tesla autopilot saw both of them. Presumably because it was using lidar it decided that the front of the truck was a car, and that the rear of the truck was a car, and then when the truck changed direction it compensated by doing a high speed maneuver directing the car beteen the front and the read wheels of the truck. Needless to say, results were less than optimal (and then came the unforgivable: after the crash the autopilot was still in control, but it did NOT stop until it was mechanically blocked from going on). That's the sort of mistake you'd expect a lidar to make : it misses objects that are very close to the ground, or "far" off the ground. It sees things starting at 50cm high until 1m30 or so (also depends on the distance to the sensor. The closer the sensor, the narrower the range), no more. That's the weakness of lidars.
That unfortunately means what they do miss is ... well, let's put it this way : you can't mount it low in the car, because at that height it'll think large pebbles are telephone poles (plus mud will splatter up and block the sensor). So you don't do that. You can also mount it high but that means those detection planes don't get very close to the ground. And that means, what it'll miss is anything that's close to the ground. Dogs. Children. Parking poles. Stairs (or any kind of abyss). That's where you'd expect mistakes.
An adult crossing the street ... there's no way.
See discussion here, "Why Tesla's autopilot can't see a stopped firetruck": https://news.ycombinator.com/item?id=16239010
As the victim was traveling perpendicular to the movement of the vehicle, I wonder whether that had anything to do with it. If so, quite a severe limitation.
That smells like BS. I can't imagine any serious players in the self-driving field that can't replay all their sensor inputs into models offline to see how things behave. If they wanted to test without LiDAR, they would run this simulations without LiDAR input. No reason to disable it when there's actual consequences.
That being said, I suppose it's possible that Uber have done what I already said, so much so that they were confident it would work and were willing to deploy it. But it still smells funny to me because I would sincerely hope the LiDAR (and other non-visible light sensor input) would be used as a failsafe.
My very limited understanding of autonomous car implementations is that you mix in all your input together to determine your surrounding environment (and all your "what do I do" logic deals with information derived from this input aggregation), so in order to safely test a new model with less input in your car, you'd need at least 2 models (one with all input, one with reduced) running at the same time.
It still seems like it'd be viable to me, and something you'd certainly want to do to avoid situations exactly like this. If you've got 2 models running, it seems like it'd be pretty straightforward to have the "all input" model assume control if it's trying to avoid an immediate collision, basically having it perform a similar role to that of a human behind the wheel during "disengagements".
I refuse to believe that they would just disable it on public roads to see if it could manage.
I've not heard anything of it before you brought it up.
A software bug is still the most plausible explanation, given the evidence we have.
Looking at the video, the quality of the current self-driving technology is really questionable, especially if i recall also the other non-fatal road traffic offences publicized so far.
And alongside being untrue, it ignores the differing severity of collisions. Even if the car had to use its normal video camera instead of Lidar for some reason, the second or two of applying the brakes that would provide can easily -- and will likely -- turn a fatal collision into a non-fatal collision.
From https://eng.uber.com/sbnet/
"By applying convolutional neural networks (CNNs) and other deep learning techniques, researchers at Uber ATG Toronto are committed to developing technologies that power safer and more reliable transportation solutions."
"CNNs are widely used for analyzing visual imagery and data from LiDAR sensors. In autonomous driving, CNNs allow self-driving vehicles to see other cars and pedestrians"
If your system that processes the pointcloud and creates this data does not detect faulty (or missing) data from the sensor the higher level logic will happily hum along believing that nothing is amiss.
And some LIDARs even have the option to do the processing on the device itself (i.e. IBEO). In which case you can theoretically work with only a list of obstacles reported back by the sensor.
Move fast and break things...?
https://arstechnica.com/cars/2018/03/police-chief-said-uber-...
That might sound a lot, and in some applications it is a lot, but please keep in mind that after one full rotation the sensor has scanned an area of up to 45000 square meters ( maximum scanning distance is 120 meters). So each rotation gives you a pretty good situational awareness of your surroundings (barring any occlusions that prevent the sensor from seeing certain spots). Unless the person is covered in IR absorbing material (some black materials do a quite good job at that) it should be impossible for a pedestrian to sneak up on the car without it being sweeped multiple times by the laser beams
After viewing the video of the incident, I strongly believe that human driver would NOT have done better.
Therefore, I believe that any attempt to blame or spread mistrust in these technologies because of this incident is (at best) misguided and (at worst) alarmist.
From this you can see how good the visibility is. We know that the visibility on this stretch of road was pretty good for nighttime driving. We know that the pedestrian that got hit had crossed an entire (empty) lane of traffic before entering the Uber vehicle's lane. I would say that any competent driver who was paying attention and who was driving a car with working headlights (or perhaps even without) would have spotted the pedestrian well in advance and been able to avoid the collision fairly easily.
The fact that the Uber vehicle did not do so despite having an abundance of opportunity and despite having not only visible light data but also lidar and radar is almost certainly a massive failure on its part. Almost certainly this is due to a failure to integrate sensor data properly or to fail to categorize a pedestrian correctly.
I have no faith that the local PD will do a good job here, but I do have faith that the NTSB will be exquisitely thorough, and I would bet hard-earned dollars that they are going to tear Uber's self-driving technology up one side and down the other.
https://arstechnica.com/cars/2018/03/police-chief-said-uber-...