Another Tesla on autopilot steers towards a barrier
reddit.com
reddit.com
If this theory turns out to be correct then Tesla is in deep trouble because this would be a very elementary mistake. The system should have known that the lanes split at this point, noticed that the distance between what it thought was the diamond lane marker and the right lane line (which was clearly visible) was wrong, and at least sounded an alarm, if not actively braked until it had a better solution.
This is actually the most serious aspect of all of these crashes: the system does not seem to be aware when it is getting things wrong. I dubbed this property "cognizant failure" in my 1991 Ph.D. thesis on autonomous driving, but no one seems to have adopted it. It's not possible to engineer an autonomous system that never fails, but it is possible to engineer one in such a way that it never fails to detect that it has failed. Tesla seems to have done neither.
This is a very good point: just like a human driver should slow down if they can't observe the road ahead well enough, an AI should slow down when it's not confident enough of its surroundings. This is probably very difficult to do, and I'm skeptical about your claim that an AI can be engineered to always detect its own failures. Further, I naively believe that Tesla is already doing a lot to detect conflicting inputs and other kinds of failures. Maybe being careful enough would prevent autopilot from working at all, so compromises have been made?
I probably don't understand AIs well enough to understand how they can be engineered to (almost) always recognize their own failures. But if a simple explanation exists, I'd love to hear it.
Basically it's a matter of having multiple redundant sensors and sounding the alarm if they don't all agree on what is going on, and also checking if what they think is going on is in the realm of reasonable possibility based on some a priori model (e.g. if suddenly all of your sensors tell you that you are 100 miles from where you were one second ago, that's probably a mistake even if all the sensors agree). That's a serious oversimplification, but that's the gist.
But it is more complicated than that when you're talking about algorithms and complex systems. If you had three of the same exact system, they'd likely all make the same mistake and thus you'd gain no safety improvement (except actual malfunctions, not logical limitations).
I would like to see auto-braking taken out of autopilot completely, so if autopilot drives you into a wall at least the brakes slow you.
On top of that, Kalman innately tracks the uncertainty of its combined estimate. So you can simply look at the Kalman uncertainty covariance and decide if it is too much for the speed you are going.
I really wonder if Tesla is doing that...
Sorta. There are ways to extract kinds of uncertainty and confidence from NNs: for example, Gal's dropout trick where you train with dropout and then at runtime you use an 'ensemble' of multiple dropout-ed versions of your model, and the set of predictions gives a quasi-Bayesian posterior distribution for the predictions. NNs can be trained directly via HMC for small NNs, and there are arguments that constant-learning-rate SGD 'really' implements Bayesian inference and an ensemble of checkpoints yields an approximation of the posterior, etc. You can also train RL NNs which have an action of shortcutting computation and kicking the problem out to an oracle in exchange for a penalty, which trains them to specialize and 'know what they don't know' so they choose to call the oracle when they're insufficiently sure (this can be done for computational savings if the main NN is a small fast simple one and the oracle is a much bigger slower NN, or for safety if you imagine the oracle is a human or some fallback mechanism like halting).
I have some cites on these sorts of things in https://www.gwern.net/Tool-AI and you could also look at the relevant tags https://www.reddit.com/r/reinforcementlearning/search?q=flai... and https://www.reddit.com/r/reinforcementlearning/search?q=flai...
In particular, it's possible to learn the variance of the return using TD-methods with the same computational complexity as learning the expected value (the value function). See [0] for how to do it via the squared TD-error, or [1] for how to estimate it via the second moment of the return, and my own notes (soon to be published and expanded for my thesis) here [2].
It turns out that identifying states with high variance is a great way of locating model error-- most of the real-world environments are fairly deterministic, so states with high variance tend to be "aliased" combinations of different states with wildly different outcomes. You can use this to improve your agent via either allocating more representation power to those states to differentiate between very similar ones, or have your agent account for variance when choosing its policy. For example, Tesla could identify when variance spikes in its model and trigger an alert to the user that they may need to take over.
Additionally, there's work by Bellemare [3] for estimating the distribution of the return, which allows for all sorts of statistical techniques for quantifying confidence, risk, or uncertainty.
---
0. https://arxiv.org/abs/1801.08287
1. https://arxiv.org/abs/1607.00446
Older ideas are http://mlg.eng.cam.ac.uk/yarin/blog_2248.html or http://papers.nips.cc/paper/7219-simple-and-scalable-predict...
Basically Bayesian neural networks were able to model confidence but are not applicable in current real-world scenarios. Thus, lots of methods rely on approximating bayesian methods.
I like that term. When I was involved in the medical instrumentation field, we had a similar concern: it was possible for an instrument to produce a measurement, e.g., the concentration of HIV in blood serum, that was completely incorrect, but plausible since it's within the expected clinical range. This is the worst-case scenario: a result that is wrong, but looks OK. This could lead to the patient receiving the wrong treatment or no treatment at all.
As much as possible, we had to be able to detect when we produced an incorrect measurement.
This meant that all the steps during the analyte's processing were monitored. If one of those steps went out of its expected range we could use that knowledge to inform the final result. So the clinician would get a test report that basically says, "here's the HIV level, but the incubation temperature went slightly out of range when I was processing it, so use caution interpreting it."
Like most software, the "happy path" was easy. The bulk of the work we did on those instruments was oriented towards the goal of detecting when something went wrong and either recovering in a clinically safe manner or refusing to continue.
With all the research into safety-critical systems over decades, it's hard to see how Tesla could not be aware of the standard practices.
there is no "slightly out of range". Its either in the range or outside. Valid or invalid, when it comes to critical tests like these.
if temperature deviation is outside of acceptable deviation range then thats a system fault and result should have been considered invalid.
Back in the days there was much less regulatory oversight and products like that could slip through the cracks, Resulting to deaths, missed diagnosis etc etc.
The same with Teslas AP: its either 100% confident in the situation or not. If the car is not confident in whats happening - it should shut down. If that happens too often then the AP feature should be removed / completely disabled.
How many more people have to get into accidents? I know, if Musk's mom (knock on wood) was a victim of this feature then things would be taken more seriously.
You do realize that I gave a much simplified view of the situation as this is a web forum discussing a related subject, not an actual design review of the instrument, right?
To any process I can set multiple "acceptable ranges" depending on what I want to accomplish. There can be a "reject" range, "ok, but warning" range, "perfect, no problem" range, or a "machine must be broken" range
Everything is context dependent; nothing is absolute.
Thanks!
That is an extremely surprising result. How is that possible? Are you really claiming that any control system can be engineered to detect that is has failed in any possible manner? What's an example of actual real-world system like that?
No, of course not. But it is possible to reduce the probability of non-cognizant failure to arbitrarily low levels -- at the expense of cost and the possibility of having a system that is too conservative to do anything useful.
Also: the lane markings are confusing but GPS and inertial readings should have clearly indicated that that is not a lane. If two systems give conflicting data some kind of alarm should be given to the driver.
GPS is not accurate enough to reliably pinpoint your location to a particular lane. Even WAAS (https://en.wikipedia.org/wiki/Wide_Area_Augmentation_System) can have up to 25 feet of error. Basic GPS is less accurate than that.
In fact, it's possible that GPS error was a contributing factor here but there's no way to know that from the video.
I have seen self-driving test cars in Silicon Valley (frequently, especially in the last year or so) using these types of systems, so they are at least being tested. I've also heard discussion of putting RTK base stations on cell-phone towers to provide wide area coverage, but I'm not sure if much effort has been put into that. I do know vast areas of the agricultural midwest are covered in RTK networks -- its used heavily for auto-steering control in agriculture.
Now the cars are relying on cameras, lidar to figure things out. What has happened to putting sensors on the road to broadcast what/where the roads is. Is that out of the question now because of cost?
So even if the error can be large in practice it often works very well.
It would be very interesting to see the input data streams these self driving systems rely on in case of errors, and in the case of accidents there might even be a legal reason to obtain them (for liability purposes).
My phone has GPS accurate to within 1 foot. I use it for mining location all the time. It uses differential GPS plus Inertial sensors.
[1] See https://www.ri.cmu.edu/pub_files/2009/6/aimag2009_urmson.pdf at 21-23.
This is not a field where 'move fast and break stuff' is a mantra worth anything at all, the stuff that is broken are people's lives and as such you'd expect a far more conservative attitude, akin to what we see in Aerospace and medical equipment software development practices.
But instead barely tested software gets released via over-the-air updates and it's anybody's guess what you'll be running the next time you turn the key.
I agree with you that the software should have been able to detect that something was wrong either way, either it was already halfway in the wrong lane or it was heading to be halfway in the wrong lane, a situation that should not have passed without the car at least alerting the driver.
And from what we have seen in the video it just gave one inferred situation priority over the rest and that particular one happened to be dead wrong about it's interpretation of the model.
That's what makes this example bizarre to me. I had thought that AutoPilot's ideal situation was having a moving vehicle in front of it. For example, AP does not have the ability to react to traffic lights, but can kind of hack it by following the pace of the vehicle ahead of it (assuming the vehicle doesn't run a red light):
I’m surprised self-driving systems don’t do this (do they?). One or more vehicles in front of you that have successfully navigated an area you are now entering is a powerful data point. I’m not saying follow a car off a cliff, but one would think the behavior of followed vehicles should be somehow fused into the car’s pathfinding.
Following this principle would probably result in a lot of people angry that their autopilot had gotten them a speeding ticket.
Aside from GPS’ accuracy as mentioned in other replies, also take into account the navigation’s map material. The individual lans are probably not individually tracked on the map, but a single track per road with meta data specifying the number of lanes amongst other featerus. So even if GPS would have provided very accurate position readings, the map source material might not even match that level of detail.
This seems to me to be a clearly incorrect (and self-contradictory) claim. It entirely depends on your definition of failure.
Your analysis seems fine. The big problem is that the "autonomous" driver is using one signal (where are the lines on the edge of the road?) to the near exclusion of all others (is there a large stationary solid object in front of me?)
Maybe Tesla should have hired George Hotz (sp?) if only to write a lightweight sanity-check system that could argue with the main system about whether it was working.
I guess that means I was able to pull the wool over the eyes of all five members of my thesis committee because none of them thought so.
> It entirely depends on your definition of failure.
Well, yeah, of course. So? There is some subset of states of the world that you label "failure". The guarantee is not that the system never enters one of those states, the guarantee is that if the system enters one of those states it never (well, so extremely rarely that it's "never" for all practical purposes) fails to recognize that it has done so. Why do you find that so implausible?
Stated so, that is plausible. However, "it is possible to engineer a system that never fails to detect that it has failed" is not; I claim that any subset of states which is amenable to this level of detectability will exclude some other states that any normal person would also consider to be "failure".
> my 1991 PH.D. thesis on autonomous driving
Going to hide in a corner and stay quiet on HN until I forget about this comment!
Just in case you're interested:
https://vtechworks.lib.vt.edu/handle/10919/38880
and the associated conference paper:
http://www.flownet.com/gat/papers/aaai92.pdf
Most of the work was done on a Mac II with 8MB (that's megabytes, not gigabytes) of RAM.
The progress that has been made since those days boggles my mind.
Im going to go hide in the corner as well.
The same is happening with chatbots - more and more businesses think they can put a chatbot on their site and assume it'll handle everything when in fact it's meant to assist you rather than take over things for you.
Apparently, we're not, as Waymo has shown.
> The term 'Autopilot' gives off the wrong idea that the driver can sit back and relax while the car brings you from point A to point B safely.
Agreed, the "but that's not how autopilots work in airplanes" canned response is irrelevant.
The only things Waymo has shown so far are a bunch of marketing videos and a few tightly controlled press rides.
Does Waymo drive at high speeds all the videos I have seen are at low speeds.
Can you point me to a website or store where I can buy my fully autonomous waymo car? I doubt waymo is even at par with tesla, considering tesla is actually selling cars. Waymo is just vaporware at this point.
Although serious, this is working as designed. Level II self-driving doesn't have automation that makes guarantees about recognizing scenarios it cannot handle. At level III, the driver can safely close their eyes until the car sounds the alarm that it needs emergency help. Audi plans to release a level III car next year, so we'll see how liability for accidents actually shakes out.
Unfortunately level II is probably the most dangerous automation even with drivers that understand the limitations of the system. They still need constant vigilance to notice failures like this and react quickly enough to avoid collisions. Just imagine poorly marked or abrupt and ramps or intersections that drivers hardly have enough time to react when they're already driving. Add in the delay to notice the computer is steering you into a wall and yank the wheel can turn some of these accident prone areas into accident likely areas.
I'll go further and say that level II is worse than useless. It's "autonomy theatre" to borrow a phrase from the security world. It gives the appearance that the car is safely driving itself when in fact it is not, but this isn't evident until you crash.
You can't possibly determine what hardware is required for Level 4 until you have proven a hardware/software combination, so that's just empty puffery, but even if it was true...
> So you’d think their level II would still be smart enough to detect these problems to some degree.
No, because the smartness of their system is about the software. They could have hardware sufficient to support Level 4 autonomy and better-than-human AI running software that only supports a less-thsn-adequate version of Level 2 autonomy. What their hardware could support (even if it was knowable) gives you no basis for belief about what their current software on it supports, except that it won't exceed the limits set by the hardware.
I've been skeptical of autonomous driving since it started to become a possibility. I spend a fair amount of time making corrections while driving that have nothing to do with what's happening in my immediate vicinity. If it can't handle an obstruction in the road, how will it handle sensing a collision down the road, or a deer that was sensed by the side of the road, or even just backing away from an aggressive driver in a large grouping of vehicles in front of you? I've had to slow down and/or move off on to the shoulder on two lane country roads because someone mistimed it when passing a vehicle. I don't have much faith in how this system would handle that. Not to mention handling an actual emergency failure like a tire blowing out.
I'm sure they will get there eventually, but it looks like they have conquered all the low-hanging fruit and somehow think that's enough. I'm now officially adding "staying away from vehicles studded with cameras and sensors" to my list of driving rules.
That sounds highly dubious. Here's a hypothetical scenario: there's a very drunk person on the sidewalk. As a human driver, you know he might act unexpectedly so you slow down and steer to the left. This will help you avoid a deadly collision as the person stumbles into the road.
Now let's take a self driving car in the same scenario, where, since it doesnt have general intelligence, it fails to distinguish the drunk person from a normal pederstrian and keeps going at the same speed and distance from the sidewalk as normally. How, in this scenario, does the vehicle 100% know that it has failed (like you say is always possible)?
"Failure" must be defined with respect to a particular model. If you're driving in the United States, you're probably not worried about bazookas, and being hit by one is not a failure, it's just shit happening, which it sometimes does. (By way of contrast, if you're driving in Kabul then you may very well be concerned with bazookas.) Whether or not you want to worry about drunk pedestrians and avoid them at all possible costs is a design decision. But if you really want to, you can (at the possible cost of having to drive very, very slowly).
But no reasonable person could deny that avoiding collisions with stationary obstacles is a requirement for any reasonable autonomous driving system.
Let's not pretend that anticipating potentially dangerous behaviour from subtle clues is some once-in-a-lifetime corner case. People do this all the time when driving -- be it a drunk guy on the sidewalk, a small kid a tad bit too unstable when riding a bike by the roadside, kids playng catch nex to the road and not paying attention, etc etc. Understanding these situation is crucial in self driving if we want to beat the 1 fatality per 100M mile that we have with human drivers. For such scenarios, please explain how the AI can always know when it failed to anticipate a problem that a normal human driver can.
That’s exactly my experience as a driver:
You learn to anticipate that the ‘autopilot’ will disengage or otherwise fail. I have been good enough at this, obviously, but it is sometimes frightening how close you get to a dangerous situation …
Odd how your "armchair diagnosis" matches perfectly with the top ranked comment in the reddit thread that was posted 1 day ago.
courtlandreOwner 815 points 1 day ago
It sees the white line on the left, the white line on the right and thinks its a big lane. Its trying to center the car in the lane.
>My guess is that the autopilot mistook these lines for the diamond lane marker and steered towards them thinking it was centering itself in the lane.
It sees the white line on the left, the white line on the right and thinks its a big lane. Its trying to center the car in the lane.
Wouldn't the system doing the checking be considered an autonomous system...that could also fail?
If you are referring to assigning confidences/probabilities to decisions, this is standard in ML.
There's a little more to it than that but yeah, pretty much.
> this is standard in ML.
Yes, I know. But not, apparently, standard in embedded autonomous systems.
It might be fixable in software. I'm a bit annoyed at Tesla for over reliance over painted lines. They fade, they can be covered, be outdated ..
That old fail video of a SDV stuck inside a circle is not funny anymore.
Off topic: I never understood why this video was discussed that much, especially in order to blame SDVs. It's an example of pointless road markings and a perfectly behaving vehicle. It's like driving into a one way street that turns out to have no exit. The driver can't be blamed.
We'd expect at least 'cycle' detection ;)
> Yep, works for 6 months with zero issues. Then one Friday night you get an update. Everything works that weekend, and on your way to work on Monday. Then, 18 minutes into your commute home, it drives straight at a barrier at 60 MPH.
> It's important to remember that it's not like you got the update 5 minutes before this happened. Even worse, you may not know you got an update if you are in a multi-driver household and the other driver installed the update.
Very glad the driver had 100% of their attention on the road at that moment.
Remember Tesla's first press release on the crash and how it mentioned "Tesla owners have driven this same stretch of highway with Autopilot engaged roughly 85,000 times"? I imagine the number that have driven it successfully in that lane since that update was rolled out sometime in mid-March is rather smaller...
So, now regarding that previous crash: did that driver (or should I say occupant) get lulled into a false sense of security because he'd been through there many times in the past and it worked until that update happened and then it suddenly didn't?
Now that these other videos are showing up, and further details (the update) are emerging, that PR should bite them in the ass hard enough that they decide never to handle an incident that way again.
I don't want this to kill Tesla -- I sincerely hope they make their production goals and become a major automobile manufacturer -- but their handling of this should hurt them.
I'm also curious if any of the people at Tesla saying, "we call it autopilot even though we expect the human driver to be 100% attentive at all times" have studied any of the history of dead man's vigilance devices.
Tesla PR knows nothing about what updates the engineering team did. At least some people in Tesla PR probably don't even know the cars update their software regularly.
It's bad practice for them to speak out of turn, but I can absolutely see the PR team not having a good grasp of what really indicates safety and their job is to just put out the best numbers possible.
Yes, and 100% is critical. That required pretty quick and smooth reactions. The car started to follow the right-hand lane, then suddenly re-centered on the barrier. The driver had about a second to see that and correct. That's just the sort of situation where even a slightly inattentive driver might panic and overcorrect, which could cause a spinout if the roads were wet or icy or cause a crash with parallel traffic.
People shouldn't use it.And if there had been a crash, Tesla probably would have said that the driver had an unobstructed view of the barrier for several seconds before impact (conveniently omitting at what point AP started to swerve).
He was likely prepared for it, which kinda makes it even scarier in a way. An inattentive driver would have totally botched this.
1) root
2) control over updates
3) everything to be completely open
Or to put it differently, I don't want to be driving on the same road as you with your rooted self driving car. You can be great sysadmin/coder, tesla guys may be too, but both of you changing random stuff without any communication with each other.. I've seen enough servers.
While, in principle, users could organize their own communal verification programs for open software, that does not happen in practice, even when the software is widely used and needs to be safe (or at least secure - OpenSSL...)
If you're supposed to keep your hands on the wheel, and given videos like this that show you really need to keep your hands on the wheel and pay attention, is automatic steering really that big of a deal?
Cruise control, now, that really is useful because it automates a trivial chore (maintaining a steady speed) and will do it well enough to improve your gas mileage. The main failure condition is "car keeps driving at full speed towards an obstacle" but an automatic emergency brake feature (again, reasonably straightforward, and standard in many new cars) can mitigate that pretty well.
It seems to me that autopilot falls into an uncanny valley, where it's not simple enough to be a reliable automation or a useful safety improvement, but it also isn't smart enough to reduce the need for an alert human driver. So what's the point?
If you're excited about self-driving cars because they'll reduce accidents, as many people here claim, what you should really be excited about is the more mundane incremental improvements like pedestrian airbags. Those will actually save lives right now.
My VW has Adaptive Cruise Control (ACC) which does the normal cruise control, plus basic distance keeping (with an alarm if the closing speed changes dangerously).
My parents' Subarus have ACC plus lane-keeping. The car will only do so much correction, plus alarms.
These seem like much better solutions, given the current state of driving "AI".
It can help keep me in a lane, either by beeping or nudging the steering wheel if I drift - I only turn on active lane assist on long highway stretches, it is more of a security blanket than anything else - just in case I space out for a sec, here's another layer of defense.
Adaptive cruise is also great. Between the two, in long road trips I can put the car in a travel lane and just go. I still have to attend to my surroundings, but it is a lot easier to focus on that when I'm not worried about accidentally creeping up to 90 mph because suddenly there's nobody in front of me.
I also had the auto brake feature activate once when a car in front of me stopped unexpectedly. I was in the middle of braking, but the brake pedal depressed further and there was a loud alarm beep.
None of these are autopilot, and honestly I wouldn't want autopilot until it is legit reliable. Instead, these are defense in depth features. The computer helps prevent certain mistakes as I make them, but never is in primary control of the vehicle.
Lame keep assist is very subtle, I describe it like wind blowing on the side of the car. You can trivially over-power it and it will beep if you exit the lane (without blinker on) with or without lane keep assist active.
The whole package of safety features is wonderful and impressive for something starting at around $22K.
Lanekeeping is actually very nice. The system in Teslas and most (all?) others do require you to keep your hands on the wheel and pay attention, but having to constantly manually steer the car is much more fatiguing than you would think. It's really annoying to drive cars without lanekeeping now.
I don't find steering onerous, but it requires just enough attention to keep you alert.
(I've never used a lanekeeping system, though. Maybe I'd like it, I dunno)
Plus, lanekeeping can be really annoying if you rely on it all the time. The car sometimes tends to drift back and forth in a lane a little between corrections, instead of just going straight. So: you're still steering. It's just that you're steering less and have a defense in depth against loss of focus, and can drive without exhausting yourself.
Naturally, I tried the auto pilot feature on a highway but I wasn't to impressed. There is a major "bump" (negative G-forces), and the car tried to swirl into the other lane (this was within the first 40 minutes of my drive), and that made me distrust the auto steering feature.
As I think you're onto, I DO feel that auto pilot is the future, but we're not there yet - let's improve the existing life saving features (and not disconnect them, looking at you, Uber).
Trying to maintain a steady speed and conserve gas is a fun challenge, but a bit pointless, because a) it's a distraction from more important tasks, and b) the computer can usually do it better than I can.
I did a 6 hours trip with a friend continuously putting his foot up and down on the throttle, and it was the most gruelling car trip I've had I think.
When I asked he said it was "to keep control on the car". I'm a patient friend.
Anti-lock brakes were the first such system. Before, you had to pump the brakes in an emergency, a practice that was difficult to execute even without the shock of an impeding accident. That system alone certainly saves thousands of lives every year.
The star usecase is to set cruise to be very near the speed limit, such that after acceleration events like overtaking, you coast back to highway speed.
It's a low-effort way of ensuring that one will be compliant with speed laws most of the time, yet maintaining a steady pace. I too prefer to be 'actively engaged' while driving, but in my opinion the reduction of constant acceleration input is a welcome convenience.
'Adaptive' cruise control, on the other hand, feels to me like riding on a tenuous rollercoaster. It's intended to let cruise control be usable in packed traffic, but it requires one to cede a lot of trust and control to the machine in ways that physically make me uneasy -- and it doesn't help that the exact behavior differs between models and manufacturers, so that trust doesn't automatically transplant into a different car.
Part of the problem is, again, with terminology. Ever since Adaptive Cruise Control proliferated as a term, it drew a parallel to classic 'Cruise Control', which I think is a mistake. Classic Cruise Control is a fire-and-forget, non-safety feature that's simple to reason about: do I want the car to gun it at a constant 70 mph, or no? You can run a quick mental judgement call and decide whether to engage it or leave it off.
'Adaptive' cruise control fundamentally about maintaining following distance, i.e. tailgating restriction. It's a safety feature. It's a button to "proceed forward not exceeding target speed", but if it gets disengaged for any reason then you can easily overrun into the car ahead. It's a safety feature with the UI/UX of a non-safety feature, so it's always opt-in (!) -- which is simply horrific.
All safety features in vehicles should be either always-on, or opt-out, and NEVER opt-in. On a modern car, tailgate restriction should be on by default, with a button unlocking the car into free-throttle mode. Braking -- alone -- should never disable a safety feature.
On ceding trust - at least with the ICC system in Nissans, it's A) far back, which gives more reaction time B) quite easy to tell when it sees the car in front vs when it doesn't. You're ceding trust, sure, but you can also verify easily.
Your 'tailgate restriction' bit is effectively a more agressive form of collision warning/forward emergency braking, and FCW+FEB as far as I know is available on all or at least most vehicles with ACC/ICC. Unfortunately, the realities of city driving means that 'maintaining distance' is a goal in some cases (i.e. just got cut off, tight merges, etc) rather than an absolute directive - frankly, something trying to force me to a certain distance away from the car in front of me would be more aggravating than useful.
Are there cars that have ACC and don't have AEB (Automatic Emergency Braking)?
The Subaru system will not let you let go of the wheel for more than 15 seconds (after that it will instantly disengage), so it's more to save your effort of continual minor corrections. It also disengages as soon as it's confused in the slightest (faded lines, lines at an angle etc)
Guess what computers excel at? Driving consistently on consistent highways.
The Tesla Autopilot is supposed to be the always aware and paying attention portion on these cases where a human driver would be very likely to start texting or dozing off. Now, it's not fully autonomous and may well decide it can't handle a situation (or apparently try to drive you into a barrier to see if you're still awake...). In this case the human driver who is somewhat zoned out needs to take control instantly and correct the situation, until they can safely re-engage autopilot (or pull over and make sure they're still alive, etc).
Guess what computers excel at? Driving consistently
on consistent highways.
Watching the video, would you say the computer was excelling, or that the road was radically unusual? I wouldn't.Possibly on paper. In reality, as of right now, computers are clearly far from excelling at this specific task.
Now, I realise people in old-fashioned non-autopilot cars can and do doze off, and that's very dangerous. But it's not clear to me how the autopilot improves that situation. Relying on the autopilot actually encourages you to doze off.
We already have simple remedies like "pull over if you feel tired" and "never ever pick up your phone while driving (or you'll lose your licence)"
the first being people are being put in harms way by either false sense of trust invoked by the name or the mixed messages from Tesla
the second is that if the first is left unchecked Tesla could single handily set back Autonomous driving for all by souring public and government opinion.
it needs a new name that aligns better with what it can do. it could be a safety system which gently corrects a driver and takes over in an obvious emergency internal or external. as it stands now it is just dangerous
I don't know what the answer is but it feels like GM's super cruise does a more adequate job of acknowledging the realistic limits of the technology and explicitly white lists roads where the technology is available for use.
I personally think that without some sort of sensors or beacons in the road, autonomous driving via camera and LIDAR sesnors is ever going to be good enough to achieve level 5 autonomous operation.
It's the sophisticated behaviors necessary to safely drive through that world model that are the issue.
The success of emergency breaking systems (that aren't advertised as "driving" assist) are pretty good evidence that the sensors can serve well as input to safe behaviors.
And what about beacon maintenance? Seems like most cities have a hard enough time keeping up with pot holes, lines, etc. as is.
Following the beacons safely would be a vastly easier problem than trying to completely replace a human driver in all situations, but it would still give you about 90% of the benefits.
Yes, you still need to pay attention. It is hard for me to believe that any Autopilot user doesn't know this because you learn it by experience almost immediately. People text and drive all the time in manual cars, but for some reason when they do it in a Tesla, we declare that Autopilot lulled them into it.
While I agree that you need to be ready to grab the wheel or hit the brake on short notice, I disagree about what that means. There is a big difference between having to be ready to do those things and actually having to do them every few seconds. This difference wasn't intuitive to me, but in practice I've found it to be extremely mentally liberating and true beyond question.
I've also found that Autopilot makes it easier to take in all of your surroundings and drive defensively against things you otherwise wouldn't see. One thing that has struck me, as I now see more drivers than just the one in front of me, is how many people are distracted while driving. If I glance continually at an arbitrary driver on my way to work, there is a greater likelihood than not that within 10 seconds they'll look at a phone. That is terrifying to me, but it is also good information to have as I drive -- I am now able to drive defensively against drivers around me, not just the one in front of me.
I've also found I'm more able to think or listen to music or podcasts than I was before Autopilot. I could never get much out of technical audiobooks, for instance, while driving manually. But Autopilot has changed that. I hesitate to say this because I worry that I will give the impression that I am focusing less on the road, but I don't think that's what's happening. My mental abilities feel much higher when I am not constantly turning a wheel or adjusting a pedal. I'm listening to music, podcasts, or audiobooks either way -- I just get a lot more out of them with Autopilot. I think it goes back to the lack of mental fatigue.
Whatever you make of my experience, I urge you to try it on a long drive if you ever get an opportunity. I have put over 60k miles on Autopilot, I have taken over on demand hundreds if not thousands of times, and I've never had a close call that was Autopilot's fault.
That's a very unfortunate choice of words.
> I have taken over on demand hundreds if not thousands of times, and I've never had a close call that was Autopilot's fault.
Maybe you are an exceptional driver, to be able to be vigilant at all times even when AP is active.
Even so, it would probably only take one instance where you weren't in time to change your mind on all this (assuming you'd survive) so until then it is a very literal case of survivors bias.
Which makes me wonder how that person that died the other week felt about their autopilot right up to the fatal crash.
Solid lol, but I stand by it!
> Maybe you are an exceptional driver, to be able to be vigilant at all times even when AP is active.
I've had driving moments I'm not proud of. But it's because I was being dumb, not because Autopilot made me do it.
I think the relevant question is: does Autopilot make people less attentive? I have no data on this. My personal experience is that most drivers are already inattentive, and Autopilot (1) makes it easier to be attentive (for a driver who chooses to be); and (2) is better than the alternative in cases where a driver is already inattentive.
> Even so, it would probably only take one instance where you weren't in time to change your mind on all this (assuming you'd survive) so until then it is a very literal case of survivors bias.
I hope I'd be more thoughtful and independent than that, but maybe you're right. But I don't think my view in the face of a terrible accident should be what drives policy, either.[1]
On the issue of survivorship bias, I would add that "Man Doesn't Text While Driving, Resulting in No Accident" isn't a headline that you're likely to read. I see a much greater quantity of bias in the failure cases that are reported and discussed than in the survivorship stories told (as evidenced by the proportions of comments and opinions here, vs in a user community like TMC or /r/teslamotors). I posted my experience because I think it brings more to this comment thread in particular than my survivorship bias detracts from it.
> Which makes me wonder how that person that died the other week felt about their autopilot right up to the fatal crash.
See: [1]
BUT...I feel like autopilot should only be for traffic jams on highways. It's downright dangerous the way it forces the driver to disengage. The adaptive cruise control is much better as at least you still have to pay attention but the car manages the throttle and following distances efficiently.
Adaptive cruise control also helps; if the system detects a car in front slowing, it'll slow at a roughly equivalent pace to avoid a collision.
This self-driving car craze would be in a very different place if Silicon Valley had halfway decent mass transit...
I'm out on the road too, and I don't get to make "consumer choices" for other people I share the road with. People are putting their market power into companies that lack the basic integrity to build these technologies with safety and transparency as the first priority, who evidently see peoples' lives as necessary sacrifices.
Please remember that we are talking about vehicles speeding down the road at 70+ MPH.
That's a pretty important point. We aren't going to ban alcohol are we? Aren't we even trying to allow marijuana consumption? Both of theses put you in dangerous situation on the road, yet we aren't talking about blocking their consumption.
It still the responsibility of the adopters, just like it's the responsibility of the drinkers.
At least doing it safely actually improve security in long term. Theses systems NEED to be driven to improve their performances.
Ford was put on market trial after the Pinto started going up in flames. Tesla should be held to similar if not greater standards.
You can't push an update to stop humans from endangering themselves and/or others.
Tesla, however, is able to do exactly that with their cars.
That they haven't, when their technology has been proven to be fatally dangerous, is unconscionable.
I realize it adds more regulation...and I'm sure there can be a middle ground. But I foresee a scenario where an OTA update is pushed and the next morning there are car crashes everywhere.
Not necessarily one as simple as OTA updates whenever the manufacturer feels like it.
As far as regulations preventing use of the tech, if level 2/3 systems end up causing more crashes than human drivers, we shouldn't allow use of them.
This is why the idea of self-updating cars terrifies me. I'd never allow autopatching on a production server - Why would I allow it on hardware I'm betting my life on?
https://www.wired.com/story/tesla-autopilot-why-crash-radar/
People should start to vote with their purse. In other words, stop buying these cars, or start selling their stocks.
However, for a wall or highway barrier, it's probably almost always worthwhile to shed as much energy as possible. You're going to pitch yourself under the barrier where the bumper won't take the hit, like you might when colliding with another vehicle.
Eh? The vast majority of real frontal impacts will be under heavy braking. If a few degrees of dive under brakes is enough to compromise the crumple zones' effectiveness then your car is bad (and I don't believe any Teslas are bad in this way.)
Small Overlap tests: this is where only a small portion of the car's structure strikes an object such as a pole or a tree, or if a car were to clip another car. This is the most demanding test because it loads the most force onto the structure of the car at any given speed. These are usually conducted at 15-20% of the front vehicle structure.[1]
Modern cars are surprisingly good at small over crash tests, see this video someone linked on HN a few days ago https://www.youtube.com/watch?v=DHlj8-JcWa8
Generally the pitch won't matter that much in vehicle-to-vehicle collisions. Only when the pitch would angle the front bumper completely under the other vehicle, which I admit isn't much of a concern. And not really a concern at all in vehicle-to-barrier collisions.
However, if we're talking about idealized automated driving systems, I hold by my original assertion. I would expect such a system to be able to correctly analyze when releasing the brake right before collision to reduce pitch would be beneficial.
Not to mention your car already has software that can kill you, even if it doesn't steer.
Even ignoring software, hardware can have "bugs" in it too that kill you. I'm not sure why you think engineering mistakes are "worse" when they are in the software vs the hardware.
Basically, no matter what it "feels" like, you are subjected to many many many forces outside your personal control.
2. You're using "proprietary" as a pejorative. It's not proprietary, compiled code that has bugs. All software is guaranteed to have bugs.
3. An entirely insignificant number of accidents are caused by bugs in the drive-by-wire control system. (Even taking into account that an insignificant fraction of cars on the road are drive-by-wire as you mean it.)
There's a non-neglible chance that will actually happen.
The punchline was that all the other cars also fell off the cliff because they were following the line instead of looking at the road.
It's crazy to think, that's where we are now with so-called self-driving cars.
I have personally watched this happen, last year (I think?) the where repainting the lines on interstate 64 near shortpump and for ~ a week that summer my commute there was insane, just a bunch of cars going 70MPH with no real lanes.
Here in the UK I am insured to drive vehicle A as specified on my insurance documents. If I modify that vehicle my insurance policy is void and I need to inform the insurance co. and probably pay a premium.
In your scenario the same could be true on a software update.
To use it safely and according to Tesla's instructions, you have to remain 100% vigilant at all times - so you might as well just drive yourself.
And if you fail to remain vigilant, which is likely since you are sitting passively in the drivers seat, you might kill somebody.
Where's the upside? Why on Earth would I want to use such a product?
I use it because it makes my driving less stressful. The car and I work together which means I don't have to work so hard to keep to the speed limit, to keep a sensible distance from the car in front and stay in lane.
"All Tesla did is say, 'It is beta so we are not responsible. It doesn't necessarily work, so you have to be in control.' "Well you that is kinda a cheap way out of it."
Pay an extremely high cost including your life to ensure technological advancement. Is that not part of their marketing? If not SNL needs to do a skit!
I can see the skit now, "You looked S3XY in that Telsa," "Did you get the update last night?" "Oh your right and it made me feel so S3XY until it drove me straight into a barrier at 60 MPH."
It seems that sophisticated LIDAR is currently the best way to achieve this, but LIDAR is expensive. So companies like Uber and Tesla skimp on the LIDAR, and build self-driving cars that can more or less follow lanes but plow right into obstacles? Whoa.
The feasibility of widespread "self-driving" tech is going to advance only as the cost of LIDAR falls.
Most companies are pursuing a Lidar approach because dev_speed(Lidar approach) > dev_speed(camera approach). Tesla is pursuing a camera approach because max(camera approach) > max(lidar approach).
On a similar note, shouldn't customers be getting release notes for these updates? I let my customers know when we're updating a web page. Tesla should surely be informing them when cars are going to start lane centering.
So this steering update would take you 0.3 degrees to the right. So what? Well those 0.3 degrees might change the angle of the line which influences the car to steer another 0.3 degrees, etc. But without that followup video (which you can't simulate from a 2D recording) you don't know how it would react to the change in environment.
The only way to regression test these things is in a simulated 3D environment (or miles and miles of real test track)
Previous autopilot versions didn't do this. 10.4 and 12 do this 90% of the time. I didn't post it until I got .12 and it did it a few times in case it was a bug in 10.4.
It looks like software updates will soon won't just break your workflow. They might break your spine or your head or take away your life entirely.The car did an admirable job trying to stay in that left lane. Each time it saw a red and white diagonal lined barrier, it gracefully edged a comfortable distance away.
The problem is, most humans catch on, "Gee, three scary-looking barriers in a row! Maybe they're trying to tell me something. "Maybe this road is closed."
But I assume the car's system perceived each one as in individual, isolated obstacle to be handled without making inferences. And it did that much well, and when it realized the third or 4th barrier was impassable, it had to cross the other side of the yellow barrier and it did that well, too.
With the right tooling this does not need to be expensive.
I hope that incidents like this encourage people to develop open source tooling to support safer software and higher levels of quality.
We can see how lives might depend on it.
https://www.pacermonitor.com/public/case/21195146/Dean_Sheik...
2) dont hit other objects
3) obey traffic laws
Then that devil that is the details shows up...
To me it doesn’t capture the gravity of the situation.
If so, it seems like it would be fairly easy to add this situation to the corpus... especially if they are recording data from their cars live.
They should have 100 people going out there and recording this lane split situation into their test data ASAP.
See https://en.wikipedia.org/wiki/Tesla_Autopilot#Hardware_2
Still, I suspect that may not be enough - a new weird road condition or construction site can be created at any time. This is why I believe self-driving companies would be better off spending their budget upgrading and certifying specific routes as safe for automation. Certified routes could be subject to special construction protocols and regular road quality audits that ensure automated cars won't run into a non-automatable condition on those routes. It's also easy to verify and confirm that a car works on all certified routes, rather than trying to test the entire North American road network.
Actually, I stand corrected. Their stock gamble is about as dumb too.
Cheaper insurance may have nothing to do with the quality or safety of autopilot in Tesla vehicles.
When aircrafts crash all planes of that model are grounded until the root cause is found. Self driving cars need similar processes.
* fix issue where "Marvin" autopilot keeps complaining (rip out voicebox)
* Boost intelligence of "Marvin" autopilot. This car now has the brain the size of a planet.
* test new smarter "Marvin" autopilot
Google has been at this for years, and with far better sensors, and even they aren’t there yet.
Sounds similar to tech bros who want to radically "disrupt" carbon sequestration. Here's an actually proven idea: plant a tree.
If there isn't a car smashed into the middle of the north/south Y junction, you'll get the chance to count the skid marks at that Y junction from humans making this exact same error.
Tl dr; humans make the same mistake, at a higher frequency, which is why the accordian barrier exists.
Does Tesla run some sort of regression suite on this stuff? Can they get a copy of the sensor data from when this happened so they can reproduce those conditions as part of their test suite?
If the overall shape of the road wasn't veering slightly to the right, the car would probably not have chosen to swerve to the left into a barrier, but the car sees the lane widening equally in both directions. Simple as that.
From my point of view all accidents until this time could be attributed to the civil engineer that build the road as much as the driver of the car.
You make a pedestrian pass between roads made only for aesthetic purposes so you put a sign forbidding the pass and call it done. But people of course use it and get killed.
You put concrete barriers between roads but make it so people could crash frontally against it, something you won't find in any European high speed road without deflectors that will make vehicles not crash against concrete.
Self driving will give us scientific evidence of what creates accidents like black boxes did with airplanes. Thanks to that we know that what looks like insignificant details like the color and placement of buttons, turns out to be essential.
We've been debugging roads since Roman times. This is mostly about debugging software, and even more about crappy software development processes. After all, if your update is not monotonically improving things you have a real problem if your product is mission critical and lives are at stake.
You find those on the German highway between Berlin and Poland, for example.
> From my point of view all accidents until this time could be attributed to the civil engineer that build the road as much as the driver of the car.
On the other hand, other solutions would provide other "bugs", to stick with your terminology.
>Self driving will give us scientific evidence of what creates accidents like black boxes did with airplanes.
No, it will only give us data on what causes accidents for self-driving cars. Most new cars apparently are already fitted with EDRs[0], the only difference with self-driving cars is the number if sensors involved.
Thank you.