Uber Self-Driving Car That Struck Pedestrian Wasn’t Set to Stop in an Emergency
ntsb.gov
ntsb.gov
According to data obtained from the self-driving system, the system first registered radar and LIDAR observations of the pedestrian about 6 seconds before impact, when the vehicle was traveling at 43 mph. As the vehicle and pedestrian paths converged, the self-driving system software classified the pedestrian as an unknown object, as a vehicle, and then as a bicycle with varying expectations of future travel path. At 1.3 seconds before impact, the self-driving system determined that an emergency braking maneuver was needed to mitigate a collision (see figure 2). 2 According to Uber, emergency braking maneuvers are not enabled while the vehicle is under computer control, to reduce the potential for erratic vehicle behavior. The vehicle operator is relied on to intervene and take action. The system is not designed to alert the operator.
So the question becomes why couldn't they get emergency braking solved before driving on the road? Maybe that requires collecting good data first, for training the system?
In no case would sudden braking be the cause of a rear-end collision. It's always the fault of the driver behind.
That's like creating HTML forms that only work with the common use case and crash spectacularly on unexpected input. Except that this time it's fatal. That's not the kind of software quality I want to see on roads.
This is beyond incompetence. There is a different level of software engineering when making a website vs making a pacemaker, rocket or flight avionics. You need the quality control of NASA, SpaceX or Boeing, not that of .. whoever they have running their self driving division.
The other thing about the system that sucks is that it's all optical (AFAIK) so when visibility is poor, it shuts off. They need to add more sensors because those are the conditions I would most like an extra set of eyes.
Yeah that's not how you design safety critical software. This isn't some web service. Either you're wrong (let's hope) or Uber is completely negligent.
Source: I write safety critical code for a living.
So you have a "driver" who has to be monitoring a diagnostic console, AND has to be separately watching for non-alerted emergency events to avoid a fatal crash? Why not hire two people? Good god.
> We decided to make this transition [from two to one] because after testing, we felt we could accomplish the task of the second person—annotating each intervention with information about what was happening around the car—by looking at our logs after the vehicle had returned to base, rather than in real time.
However, this seems to contradict the NTSB report which indicates that it still was the driver's responsibility to perform this event tagging task, which necessarily implies taking your eyes off the road.
[1] https://www.citylab.com/transportation/2018/03/former-uber-b...
Don't we have speech-to-text for this sort of thing?
"Uber moved from two employees in every car to one. The paired employees had been splitting duties — one ready to take over if the autonomous system failed, and another to keep an eye on what the computers were detecting. The second person was responsible for keeping track of system performance as well as labeling data on a laptop computer. Mr. Kallman, the Uber spokesman, said the second person was in the car for purely data related tasks, not safety."
[1] https://www.nytimes.com/2018/03/23/technology/uber-self-driv...
It feels like a typical coder rethrowing exception somewhere u_u
This gets your license yanked, herearound. Same goes for texting and driving if you're caught. Even in stop - go traffic.
I hope this won't stay unpunished (both at corporate and personal level) if confirmed.
For something this safety critical, you want the software engineering quality of Boeing, NASA, etc. This type of mistake is pretty inexcusable.
https://www.nbcnews.com/tech/innovation/emails-show-arizona-...
>The system is not designed to alert the operator.
>The vehicle operator intervened less than a second before impact by engaging the steering wheel.
>She had been monitoring the self-driving system interface
It seems like this was really aggravated by bad UX. Had the system alerted the user and the user had a big red "take whatever emergency action you think is best or stop ASAP if you don't know what to do" button to mash this could would have had a much better chance of being avoided.
Things coming onto the road unexpectedly isn't exactly an edge case when it comes to crash causing situations. I don't see why they wouldn't at least alert the user if the system detects a possible collision with an object coming from the side and the object is classified as one of a certain type (pedestrian, bike other vehicle, etc, no need to alert for things classified as plastic bags).
I don't see why they disabled the Volvo system. If they were setting up mannequins in a parking lot and teaching the AI to slalom around them I can see why that might be useful but I don't see why they would want to override the Volvo system when on the road. At the very least the cases where the systems disagree are useful for analysis.
Of course cars cannot change speed instantly anyway - it is likely that even if the button was hit in time the accident was still unavoidable at 1.3 seconds. The car should have been slowing down hard long before it knew what the danger was. (I haven't read the report - it may or may not have been possible for the computer to avoid the accident)
http://www.visualexpert.com/Resources/reactiontime.html has a good discussion (starting with why 1.5 seconds is not the answer)
Simply swerving left would have avoided the accident. Stopping is not the only thing the human driver could have done!
The whole thing is nuts. Imagine a human driver seeing the same thing the computer did, and responding the same way: they'd be in handcuffs.
As far as trains go, they do slow down when passing trough a track adjacent to a platform. There are some non-platform adjacent tracks the train companies use to avoid slowing down, however they will slow down or even stop if something is going on.
Similarly, high speed rail doesn't have level crossings due to safety considerations. Overall trains are very safe and they are _designed_ for safety. It is highly irresponsible and immoral to just wing it with people's life/safety.
100% agree.
> As far as trains go, they do slow down when passing trough a track adjacent to a platform. There are some non-platform adjacent tracks the train companies use to avoid slowing down, however they will slow down or even stop if something is going on.
The equivalency isn't 'trains slow down through stations' (That would be cars having lower speedlimit in pedestrian areas - they do and the ubers honor) , it would be 'train spikes breaks if someone takes a step toward the edge' (Which they don't, even though it would potentially save lives).
There's always a tradeoff between usability and absolute safety. I'm not saying the uber did nothing wrong, at a minimum it should have spiked it's breaks. The 'perfect world' solution would be the uber knowing mass and momentum of approaching objects, and whether they could stop in time. But honestly, here would that have helped? We'll never get rid of people walking in front of moving cars, just have to be find the happy balance (which we clearly haven't)
A train's deceleration under maximum braking is far, far lower than a car. [1] suggests 1.2m/s² (paragraph 8).
[2] says the deceleration of a low-speed train crashing into the buffers at the end of the line in a station should not be more than 2.45m/s² (paragraph 35). That caused "minor injuries" to some passengers.
Trains do slow down earlier if the platform they are approaching is very crowded, but there's not really anything else they can do.
[1] https://assets.publishing.service.gov.uk/media/547c906640f0b...
[2] https://assets.publishing.service.gov.uk/media/547c906640f0b...
With cars, there is an expectation that you have to share the road with other vehicles, objects, obstacles, pedestrians, etc.
No. That's my point. Take less drastic measures earlier, and only escalate when you have to. That's how I drive, and a self-driving car can do the same.
"It might move out of my way" is no reason to get so close at such a high speed that you can't avoid it when it doesn't!
> the self-driving system software classified the pedestrian as an unknown object, as a vehicle, and then as a bicycle with varying expectations of future travel path
Little different, huh? If you see something that looks like it might be in your way, and you aren't sure what it is, you just keep going?
And if I see a pedestrian in the middle of the road at a random spot, especially at night, I'm slowing down since I don't know WTF they're thinking. Or if I'm in a neighborhood with regular street crossings carved out of the sidewalk and someone's coming up to one of those - I don't know how well they're paying attention to their surroundings.
I think it comes down to the fact that the classification algorithms are not ready for primetime.
Also, my two year old will sometimes walk towards the curb, but she is very good with streets, so I am not worried. She always stops and waits to hold someone's hand before crossing. This behavior freaks some drivers out, causing them to slow or come to a complete stop, which is the nicest outcome because then I can take her hand and cross the street. When I am walking by myself drivers rarely yield even as I am stepping into the street, even at marked crossings.
I guess my point is if my two year old exhibits the behavior you ascribe to a hypothetical non-child pedestrian then how can you be sure your hypothetical pedestrian won't just "keep walking"? What if they are blind, or drunk, or reckless? Perhaps you have been lucky before and never struck a pedestrian but I strongly urge you to assess your behavior. Stop for pedestrians, it's the nice thing to do and it's probably the law where you live.
When I am driving I often see people standing at the curb just staring at their smartphone. Usually these people are wasting time because they don't expect traffic to stop. When I stop for them they are usually pleased, they cross the road and get on with their life. Sometimes these people are just waiting for an Uber or something, when I stop for them they get confused and look at me funny. I don't mind, I just smile at them and resume driving. I am in a car, so I can accelerate and travel very quickly with almost no effort. It is no trouble for me to spend a few seconds stopping for a false positive.
The speed limit is a reference to the maximum allowable speed of the roadway, not the minimum, only, or even recommended speed.
I didn't always drive like this, but I was in an accident that was my fault that totally upended my life, so I made an effort to change my ways. You can do it too, before you get in an accident that sets your life back, or irreparably shatters it...
I recommend taking an advanced drivers education course if you seriously decide you want to improve your driving. A lot of this stuff is covered.
Nobody's suggesting that anyone should slam the brakes every time a moving object intersects your vector of motion.
No, you did that:
> I often have pedestrians walk towards the street and I assume they will stop so I don't slow down unless they are children or similar. Almost every day I could hit pedestrians if they kept walking.
With respect, I don't know what you meant to say but that sounds like a description of a bad (or at least inconsiderate) driver to me.
In any case, when I think about how I would design a self driving car, an "auto-auto", the first principle I came up with was that it should never travel so fast that it couldn't safely slow down or break to avoid a possible collision. This is the bedrock, foundational principal.
Self driving cars can emulate humans, but that won't bring them to human level performance without the ability to model other actors. If they try to mathematically rule out the possibility of accidents without such models, they won't be able to go anywhere.
They should have had it set to spike the breaks once collision was imminent though, that's (maybe) the biggest programming omission here.
I'm not sure that'd be a huge issue. The vectors have to be intersecting first of all, which most vectors emanating from sidewalks wouldn't be, and then a little hysteresis would smooth out most of the rest.
What's actually needed here is some notion of whether the pedestrian is paying attention and will correctly stop and not intersect the path of the car. Humans are constantly making that assessment based on sometimes very subtle cues (is the person looking at/talking on a phone, or are they paying attention, for example).
These autonomous systems are evaluating surrounding vectors every few milliseconds. A timescale of 3 seconds simply isn't important, as they would instantly detect you slowing down and conclude that you wouldn't intersect with their vector.
> But why didn't it brake from t minus 6 to t minus 1.3? Looks like it detected that the car's and object's paths were converging, so why didn't it brake during that interval?
Safe driving often does require slowing down in the face of insufficient information. If a human driver sees an inattentive pedestrian about to intersect traffic, they will slow down. “Drive until collision is unavoidable” is a failing strategy.
And anyway, jerky driving is a symptom of late braking, not early braking.
No it's not, the issue was jerky driving.
> “Drive until collision is unavoidable” is a failing strategy.
No kidding.
I see it as more than just jerkyness, I see a massive safety issue in traffic. If your autonomous car is slamming on the brakes spontaneously there's a lot more opportunities for other drivers to plow into you from behind.
That being said, I'm happy to find my assumptions about stopping time are incorrect and a car traveling at 25mph can stop in less than a second. So on busy NYC streets this wouldn't be an issue. Even at 50mph it appears that stopping time is sub 3s, so the vehicle could probably have avoided this collision if it were running a more intelligent program.
Right, collision is basic physics accounting for the stopping time and distance of pedestrians and cars. So the question is whether pedestrians on sidewalks really have so many collision vectors with traffic such that autonomous vehicles would be jerky all of the time as the initial poster suggested.
I claim reasonable defaults that would far outperform humans on average wouldn't have that property. Autonomous vehicles should be programmed to follow the rules of the road with reasonable provisions to avoid collisions when possible.
I think a major effort in self driving is solving the Goldilocks issue of reacting properly to impending accidents, but also not apply uncomfortable breaking if it’s not needed.
Seems like it was too insensitive at that distance.
[1] https://www.ted.com/talks/chris_urmson_how_a_driverless_car_...
This is also an issue with current production automatic braking system. One that was largely solved with on track testing, and on road testing logging false triggers with a driver driving. There's no need to risk lives unless you're just cutting corners to avoid the cost of a test track.
Shouldn't the brake application be not boolean but 0-100% strength based on confidence levels?
That's vanilla testing edge-case stuff, really, and it's known that uber are unter when it comes to this, but the removal of all the useful safety layers after that (braking, alert, second human, hardware system) is reckless and stupid.
But why the hell wouldn't you have the thing beep to alert the driver that the AI thinks there is a problem and they need to pay extra attention? In fact it seems like this would be helpful when trying to fine tune the system.
That buys you time for the ai classifier to do its thing and isn’t as dangerous as an emergency braking later on, so seems a sensible behavior all around.
This tech simply isn't there yet and I doubt it's all that close.
Doesn't sound dumb to me. The car should be going slow enough to emergency stop if the pedestrian enters the road.
that said, as I said above whenever a car sense a situation it doesn't understand it should slow down, that's enough to be safe later on as the situation develops and is different than hitting the brakes full force.
and anyway expecting autonomous car to drive full speed all the time is moronic, humans don't do that either, precisely because it's dangerous.
So, yeah: dumb.
If I think I saw children run around between cars on the parking lane, are the parents probably morons? Yes. Do I slow down and be prepare to slam the brakes in case a child suddenly runs in front of me? Ab-so-lute-ly.
Even if people behave idiotically on the street, it is obviously still my fault if I run them over.
And that's what I'm talking about. Computers aren't all that good at determining whether or not a person is going to jump into the street.
This tech simply isn't there yet and I doubt it's all that close.
In which case it's absolutely criminal by the government of Arizona to allow testing such tech on public roads.This has been a not-minor problem for autonomous cars and the Tesla-style autopilots / adaptive cruise controls that depend on vision only. You have to program it to ignore some types of things that seem like they might be an obstruction, such as road signs, debris in the road, etc. so they don't hit the brakes unnecessarily.
well tough shit then, a car that plows trough situation it doesn't understand should never be on the public road
it's a 60 zone and rain or smoke impairs the visibility? slow down.
it's a 45mph zone and something that's not a motor vehicle is in a lane that's supposed to only have motor vehicles on it? you slow down until you make sense of the situation.
you're near a playground and a mother is walking a children on the other side of the road and you can't see if she's holding his hand? you slow down.
a person walks near the kerb and it's not looking in your direction? you slow down. a bike is loaded with groceries? a car acting erratically? a person being pulled by his dog? a bus stopped unloading people? you don't drive past them at 30mph.
driving safely: super simple stuff.
If people did the super simple stuff, we'd have boundless peace, prosperity, liberty.
I remember a story - stop me if you've heard this one - about a God helping out a group of desperate people, freeing them from slavery, parting seas, feeding them in the desert. They were camped at the foot of a mountain with the God right there on top - right there! And they built the golden calf anyway. And that rule seems easier than all the other 9. WTF did they even need a golden calf for?
So sadly, the criteria of simplicity is irrelevant - people will find a hard way to do it.
There's a calculation here of balancing the perceived risk of an obstruction with the consequences of avoiding it or braking in time. Drivers have to make this decision all the time, on a highway they will generally assume it's safer to hit most things than swerve or panic brake, because it's mostly likely not that dangerous to collide with.
At least one stat I saw from AAA is that ~40% of the deaths from road debris result from drivers swerving to avoid them.
The way I see it,there is only way to make sense of a field where the most respectable R&D house (Google/Alphabet) limits their vehicle to a relative snail's pace while everyone else (including notoriously unethical shops like Uber) is taking a gung-ho, "the only limit is the speed limit" approach. That is to assume "everyone else" is cheating the game by choosing a development path that gives the appearance of being functional in the "rough but will get there with enough polish" sense while the truth is that it's merely a mountain of cheap and dirty hacks that will never achieve the goals demanded by investors.
The only reason a company would overlook such a simple safety protocol as "slow down until a potentially dangerous object is positively identified" is if their "AI" fails to positively identify objects so frequently that the car could never achieve what a human passenger would consider a consistent, normal driving pace. The same can be said for any "AI" that can't be trusted to initiate panic braking in response to a positively identified collision scenario with a positively identified object. The fact that they specifically wrote an "AI" absolving workaround for that scenario their software means the frequency of false positives must be so high as to make the frequency of "false alarm" panic braking incidents unacceptable for human passengers.
"As the vehicle and pedestrian paths converged, the self-driving system software classified the pedestrian as an unknown object, as a vehicle, and then as a bicycle with varying expectations of future travel path."
1. It seems like the classifier flipped state between pedestrian/unknown object/vehicle/bicycle; this seems like one of the well-known issues with machine learning. (I'm assuming the classifier is using ML simply because I have never heard of any other (semi-?) successful work on that problem.)
I suggest that the problem is that the rest of the driving system went from 100% certainty of A to 100% certainty of B, etc., with a resulting complete recalculation of what do to about the current classification. I make this hypothesis on the basis of the 4+ seconds when the car did nothing, while a response to any of the individual possibilities would possibly have averted the accident.
2. If the classifier was flipping state, I assume the system interrupted the Decide-Act phases of an OODA loop, resulting in the car continuing its given path rather than executing any actions. This seems like a reasonable thing to do, if the system contains no moment-to-moment state. Which would be strange; it seems like the planning system should have some case for having obstacles A, B, C, and D rapidly and successively appearing in the same area of its path.
3. Assuming the classifier wasn't flipping state, but presenting multiple options with probabilities, I can see no reason why the car wouldn't have taken some action in the 4+ seconds. (I note that the trajectory of the vehicle seems to move towards the right of its lane, which is a rather inadequate response and likely the wrong thing to do for several of the classification options.)
"According to Uber, emergency braking maneuvers are not enabled while the vehicle is under computer control, to reduce the potential for erratic vehicle behavior."
That's just idiotic and would be nigh-criminally unprofessional in most engineering situations.
I hope but do not know if the frequency and circumstances are logged and sent to Volkswagen when at the shop. Don't expect it though since it will first see the shop after 2 years. That would be too long for an improvement cycle.
What makes you think they aren't sent to VW all the time?
That simply means it should not be deployed. End of story.
Not fine on a public road with real people on it.
I have fired clients for doing reckless and stupid things orders of magnitude reckless and stupid than what Uber has done here and I would hope that I would walk the hell out were I confronted with "we disabled the brake for a smoother ride and then disabled the alarms because they were too noisy". Do thou likewise, yeah?
> "It's very clear it would have been difficult to avoid this collision in any kind of mode (autonomous or human-driven) based on how she came from the shadows right into the roadway," Moir told the San Francisco Chronicle after viewing the footage.
https://www.usatoday.com/story/tech/2018/03/20/tempe-police-...
I can't imagine doing what she did — even thoroughly stoned, as she may have been (she tested positive for methamphetamine and marijuana), I would have more sense of self-preservation than that.
The place for the product folks to override safety features is the test track. If the feature didn’t work, they should have pulled the drivers because they were not trained to properly operate the machine.
If you give the “driver” training on a car with an autonomous braking system, then give them a car without it, that’s not on the driver. Someone was negligent with safety in regards to the entire program.
I’m not saying anyone needs to go to jail over this, but there do need to be charges IMO. Personal liability needs to be involved in this or executives will continue to pressure employees to do dangerous things.
The police are in no position at assert that, nor do they know whether or not Uber is guilty of negligence. Police do not bring charges and they're not running the investigation.
And partially-at-fault, on one hand, means there's fault on the driver side too, and on the other hand, is a judge's decision to make, not the police, no?
That should be irrelevant. Even if the pedestrian is jay-walking, it's still not legal to hit them. Further, having solid evidence that the car detected the pedestrian and did nothing to avoid her mitigates the pedestrian's responsibility, no?
Also, the "center median containing trees, shrubs, and brick landscaping in the shape of an X" sure looks like it should have some crosswalks, from the aerial photograph. What's it look like from the ground?
The reason we were ultimately able to do this is because we were operating in a fully-segregated environment of our own design. We could be certain that every other vehicle in the system was something that should be fully under our control, so anything even slightly anomalous should be treated as a hazard situation.
There are a lot of limitations to this approach, but I'm confident that it could carry literally billions of passengers without a fatality. It is overwhelmingly safe.
Operating in a mixed environment is profoundly different. The control system logic is fully reversed: you must presume that it is safe to proceed unless a "STOP" signal received. And because the interpretation of image & LIDAR data is a rather... fuzzy... process, that "STOP" signal needs to have fairly liberal thresholds, otherwise your vehicle will not move.
Uber made a critical mistake in counting on a human-in-the-loop to suddenly take control of the vehicle (note: this is why Type 3 automation is something I'm very dubious about), but it's important to understand that if you want autonomous vehicles to move through mixed-mode environments at the speeds which humans drive, then it is absolutely necessary for them to take a fuzzy, probabilistic approach to safety. This will inevitably result in fatalities -- almost certainly fewer than when humans drive, but plenty of fatalities nonetheless. The design of the overall system is system is inherently unsafe.
Do you find this unacceptable? If so, then then ultimately the only way to address this is through changing the design of the streets and/or our rules about how they are be used. These are fundamentally infrastructural issues. Merely swapping out vehicle control systems -- robot vs. human -- will be less revolutionary than many expect.
Don't conflate that with Uber's screw-up here. This wasn't a situation where a fatality was unavoidable or where a very safe system had a once-in-a-blue-moon problem. It's one where they just drove around not-very-safe cars.
And that is why I am so mad at Uber. They are compromising the public trust in autonomous cars with their reckless release policy. And thereby potentially endangering even more lives, as we have to convince the public of the advantages of this technology.
This doesn't mean that Uber therefore did the right thing in disabling the system; it probably means that the system shouldn't have been given control of the car in the first place. But my point is that there is no readiness level where driverless cars will ever be safe -- not in the same way that trains and planes are safe. The driving domain itself is intrinsically dangerous, and changing the vehicle control system doesn't change the nature of that domain. So if we actually care about safety, then we need to be changing the way that streets are designed and the rules by which they are used.
That's an E-stop chain and that's exactly how it should work.
But the software as described in the NTSB report was apparently bad enough that they essentially hardwired an override on their emergency stop. The software equivalent of putting a steel bar into a fuse receptacle. The words that come to mind are 'criminal negligence'. The vehicle would not have been able to do an E-stop even if it was 100% sure it had to do just that, nor did it warn the human luggage.
The problem here is not that the world is so unsafe that you will have to make compromises to get anywhere at all, the problem here is that the software is still so buggy that there is no way to safely navigate common scenarios. Pedestrian on the road at night is one that I've encountered twice on my trips and they did not lead to any fatalities because when I can't see I slow down. If 6 seconds isn't enough to make a decision you have no business being on the road in the first place.
I've seen a few people comment on the footage that they too would have run the pedestrian over, to which my only response is: I sure hope you don't have a driver's license [anymore]!
The report is a bit ambiguous about that:
The videos show that the pedestrian crossed in a section of roadway not directly illuminated by the roadway lighting.
I don't think you can look at videos and judge the level of illumination well; their videos could be more or less accurate than Uber's, and what I see depends on codecs, video drivers, my monitor, etc. Also, any video can easily be edited these days.
Is there a way to precisely measure the illumination besides a light meter? Maybe we can use astronomers' tricks and measure it in relation to objects with known levels of illumination. Much more importantly, I'm not even sure what properties of light we're talking about - brightness? saturation? frequencies? - nor which properties matter how much for vision, for computer vision, and for the sensors used by Uber's car in particular.
I'm not taking a side; I'm saying I have yet to see reliable information on the matter, or even a precise definition of the question.
Very good write anyways... indeed many things will have to change - probably the infrastructure, the vehicles, the software, the way pedestrians move, and driver behavior as well.
That depends, there could simply be no traffic behind you, which an experienced driver and hopefully and automated one would be monitoring.
Besides, there are many situations on the highway where an E-stop is far safer than any of the alternatives even if there is traffic behind you. Driving as though nothing has changed in the presence of an E-stop worthy situation is definitely not the right decision.
That should be criminal.
I'm all for chalking this one up to criminal negligence and incompetence, outright malice is - for now - off the table, unless someone leaks meeting notes from Uber where they discussed that exact scenario.
My company didn't start with this zero tolerance thing in our minds, but it turns out our self-delivering electric bicycles have a huge advantage for real world safety because they weigh ~60lbs when in autonomous mode and are limited to 12mph. This equals the kinetic energy of myself walking at a brisk pace, or basically something that won't kill purely from blunt force impact. I think the future for autonomy will be unlocked by low mass and low speed vehicles, not cars converted to drive themselves.
It hasn't shown that at all. It has documented beyond reasonable doubt that Uber should not be allowed to participate in real world tests of autonomous vehicles.
There are plenty of situations where people would fully accept a self driving vehicle killing someone but this isn't one of those.
This is an analogy that cannot completely map to cycling.
A fall at any speed from a bike is literally a potentially crippling or deadly scenario.
For elderly people, I would guess that's accurate.
A friend of mine, in his 50's very fit, cycling to work and back every day, broke both his arms while doing literally a 10-meter test drive in front of a bike store.
The bike's brakes were setup reversed compared to what he used to, so he ended up breaking with the front brake, flipping the bike over and breaking both his arms while landing. His fault? Sure, but still a rather scary story how quickly even mundane things can go really wrong.
Uber had a fatality after 3 million miles of driving.
The mean fatality rate is approximately 1 per 100 million miles of driving.
It's a sample size of one, so the error bars are big, but it drives me insane that people are acting like the Uber cars are the ideal driverless cars of the imagined future, and are super safe. The available data (which is limited, but not that limited) is that Uber driverless cars are much, much, much more dangerous than mean human drivers.
That actually sounds like a really interesting concept, one of those ideas that seems obvious only after someone suggests it. What company is this?
Right now, in the Seattle area, we are basically seeing a new littering epidemic in the form of sharable bicycles being left to rust away, unused, at random places. If the bike could cruise to its next user autonomously, that would be really be a game-changer. "Bikes on demand" would turn bikesharing from (IMHO) a stupid idea into something that just might work.
Plus, the engineering challenges involved in automating a riderless bicycle sound fun.
The biggest challenge will probably be to keep people from screwing with the bikes, of course. :( An unoccupied bicycle cruising down the street or sidewalk will fire all sorts of mischievous neurons that onlookers didn't even know they had.
What the Uber crash has shown us is mostly the willingness of people on HN to excuse Silicon Valley darlings even when they actually demonstrably kill people.
Where is the almost-certainty coming from that the fatalities would be fewer compared to humans driving? And what does "almost" mean in this case?
And "almost" is always a good idea when talking about a future that looks certain. Takes into account the unknown unknowns. And the known unknowns (cough hacking cough).
Without the ability to understand its environment and react appropriately to it, all the good the fast reaction times will do to an AI agent is to let it take the wrong decisions faster than a human being.
Just saying "computers" and waving our hands about won't magically solve the hard problems involved in full autonomy. Allegedly, the industry has some sort of plan to go from where we are now (sorta kinda level-2 autonomy) to full, level-5 autonomy where "computers" will drive more safely than humans. It would be very kind of the industry if they could share that plan with the rest of us, because for the time being it sounds just like what I describe above, saying "computers" and hand-waving everything else.
1.) Road safety -- as far as the current operating concept of cars is concerned (eg., high speeds in mixed environments) -- is not a problem that can be "solved". At best it can only ever be approximated. The quality of approximation will correspond to the number of fatalities. Algorithm improvements will yield diminishing returns: the operating domain is fundamentally unsafe, and will always result in numerous fatalities even when driven "perfectly".
2.) With regards to factors that contribute to driving safety, there are some things that computers are indisputably better at than humans (raw reaction time). There are other things that humans are still better at than computers (synthesising sensory data into a cohesive model of the world, and then reasoning about that world). Computers are continually improving their performance, however. While we don't have all the theories worked out for how machines will eventually surpass human performance in these domains, we don't have a strong reason to believe that machines won't surpass human performance in these domains. The only question is when. (I don't have an answer to this question).
3.) So the question is not "when will autonomous driving be safe" (it won't be), but rather: "what is the minimum level of safety we will accept from autonomous driving?" I'm quite certain that the bar will be set much higher for autonomous driving than for human driving. This is because risk perception -- especially as magnified by a media that thrives on sensationalism -- is based on how "extraordinary" an event seems, much more than how dangerous it actually is. Look at the disparities in sociopolitical responses to, say, plane crashes and Zika virus, versus car crashes and influenza. Autonomous vehicles will be treated more as the former than the latter, and therefore the scrutiny they receive will be vastly higher.
4.) So basically, driverless cars will only find a routine place on the road if and when they have sufficiently fewer fatalities than human driving. My assertion was a bit tautological in this respect, but basically, if they're anywhere near as dangerous as human drivers, then they won't be a thing at all.
5.) Personally, I think that the algorithms won't be able to pass this public-acceptability threshold on their own, because even the best-imaginable algorithm, if adopted on a global basis, would still kill hundreds of thousands of people every year. That's still probably too many. I expect that full automation eventually will become the norm, but only as enabled by new types of infrastructure / urban design which enable it to be safer than automation alone.
I'm too exhausted (health issues) to reply in as much detail as your comment deserves, but here's the best I can do.
>> 4.) So basically, driverless cars will only find a routine place on the road if and when they have sufficiently fewer fatalities than human driving. My assertion was a bit tautological in this respect, but basically, if they're anywhere near as dangerous as human drivers, then they won't be a thing at all.
Or at least it won't be morally justifiable for them to be a thing at all, unless they're sufficiently safer than humans- whatever "sufficently" is going to mean (which we can't really know; as you say that has to do with public perception and the whims of a fickle press).
I initially took your assertion to mean that self-driving AI will inevitably get to a point where it can be "sufficiently" safer than humans. Your point (2.) above confirms this. I don't think you're wrong, there's no reason to doubt that computers will, one day, be as good as humans at the things that humans are good at.
On the other hand I really don't see this happening any time soon- not in my lifetime and most likely not in the next two or three human generations. It's certainly hard to see how we can go from the AI we have now to AI with human-level intelligence. Despite the successes of statistical machine learning and deep neural nets, their models are extremely specific and the tasks they can perform too restricted to resemble anything like general intelligence. Perhaps we could somehow combine multiple models into some kind of coherent agent with a broader range of aptitudes, but there is very little research in that direction. The hype is great, but the technology is still primitive.
But of course, that's still speculative- maybe something big will happen tomorrow and we'll all watch in awe as we enter a new era of AI research. Probably not, but who knows.
So the question is- where does this leave the efforts of the industry to, well, sell self-driving tech, in the right here and the right now? When you said self-driving cars will almost certainly be safer than humans- you didn't put a date on that. Others in the industry are trying to sell their self-driving tech as safer than humans right now, or in "a few years", "by 2021" and so on. See Elon Musk's claims that Autopilot is safer than human drivers already.
So my concern is that assertions about the safety of self-driving cars by industry players are basically trying to create a climate of acceptance of the technology in the present or near future, before it is even as safe as humans, let alone safer (or "sufficiently" so). If the press and public opinion are irrational, their irrationality can just as well mean that self-driving technology is accepted when it's still far too dangerous. Rather than setting the bar too high and demanding an extreme standard of safety, things can go the other way and we can end up with a diminished standard instead.
Note I'm not saying that is what you were trying to do with your statement about almost certainty etc. Kind of just explaining where I come from, here.
I share your skepticism that AIs capable of piloting fully driverless cars are coming in the next few years. In the longer term, I'm more optimistic. There are definitely some fundamental breakthroughs which are needed (with regards to causal reasoning etc.) before "full autonomy" can happen -- but a lot of money and creativity is being thrown at these problems, and although none of us will know how hard the Hard problem is until after it's been solved, my hunch is that it will yield within this generation.
But I think that framing this as an AI problem is not really correct in the first place.
Currently car accidents kill about 1.3 million people per year. Given current driving standards, a lot of these fatalities are "inevitable". For example: many real-world car-based trolley problems involve driving around a blind curve too fast to react to what's on the other side. You suddenly encounter an array of obstacles: which one do you choose to hit? Or do you (in some cases) minimise global harm by driving yourself off the road? Faced with these kind of choices, people say "oh, that's easy -- you can instruct autonomous cars to not drive around blind curves faster than they can react". But in that case, the autonomous car just goes from being the thing that does the hitting to the thing that gets hit (by a human). Either way, people gonna die -- not due to a specific fault in how individual vehicles are controlled, but due to collective flaws in the entire premise of automotive infrastructure.
So the problem is that no matter how good the AIs get, as long as they have to interact with humans in any way, they're still going to kill a fair number of people. I sympathise quite a lot with Musk's utilitarian point of view: if AIs are merely better humans, then it shouldn't matter that they still kill a lot of people; the fact that they kill meaningfully fewer people ought to be good enough to prefer them. If this is the basis for fostering a "climate of acceptance", as you say, then I don't think it would be a bad thing at all.
But I don't expect social or legal systems to adopt a pragmatic utilitarian ethos anytime soon!
One barrier it that even apart from the sensational aspect of autonomous-vehicle accidents, it's possible to do so much critiquing of them. When a human driver encounters a real-world trolley problem, they generally freeze up, overcorrect, or do something else that doesn't involve much careful calculation. So shit happens, some poor SOB is liable for it, and there's no black-box to audit.
In contrast, when an autonomous vehicle kills someone, there will be a cool, calculated, auditable trail of decision-making which led to that outcome. The impulse to second-guess the AV's reasoning -- by regulators, lawyers, politicians, and competitors -- will be irresistible. To the extent that this fosters actual safety improvements, it's certainly a good thing. But it can be really hard to make even honest critiques of these things, because any suggested change needs to be tested against a near-infinite number of scenarios -- and in any case, not all of the critiques will be honest. This will be a huge barrier to adoption.
Another barrier is that people's attitudes towards AVs can change how safe they are. Tesla has real data showing that Autopilot makes driving significantly safer. This data isn't wrong. The problem is that this was from a time when Autopilot was being used by people who were relatively uncomfortable with it. This meant that it was being used correctly -- as a second pair of eyes, augmenting those of the driver. That's fine: it's analogous to an aircraft Autopilot when used like that. But the more comfortable people become with Autopilot -- to the point where they start taking naps or climbing into the back seat -- the less safe it becomes. This is the bane of Level 2 and 3 automation: a feedback loop where increasing AV safety/reliability leads to decreasing human attentiveness, leading (perhaps) to a paradoxical overall decrease in safety and reliability.
Even Level 4 and 5 automation isn't immune from this kind of feedback loop. It's just externalised: drivers in Mountain View learned that they could drive more aggressively around the Google AVs, which would always give way to avoid a collision.
So my contention is that while the the AIs may be "good enough" anytime between, say, now and 20 years from now -- the above sort of problems will be real barriers to adoption. These problems can be boiled down to a single word: humans. As long as AVs share a (high-speed) domain with humans, there will be a lot of fatalities, and the AVs will take the blame for this (since humans aren't black-boxed).
Nonetheless, I think we will see AVs become very prominent. Here's how:
1. Initially, small networks of low-speed (~12mph) Level-4 AVs operating in mixed environments, generally restricted to campus environments, pedestrianised town centres, etc. At that speed, it's possible to operate safely around humans even with reasonably stupid AIs. Think Easymile, 2getthere, and others.
2. These networks will become joined-up by fully-segregated higher-speed AV-only right-of-ways, either on existing motorways or in new types of infrastructure (think the Boring Company).
3. As these AVs take a greater mode-share, cities will incrementally convert roads into either mixed low-speed or exclusive high-speed. Development patterns will adapt accordingly. It will be a slow process, but after (say) 40-50 years, the cities will be more or less fully autonomous (with most of the streets being low-speed and heavily shared with pedestrians and bicyclists).
Note that this scenario is largely insensitive to AI advances, because the real problem that needs to be solved is at the point of human interface.
This is a wonderfully concise way of describing a phenomenon that I have not been able to articulate well. Thank you.
I hope that whoever was responsible for this piece of crap software loses a lot of sleep over it, and that Uber will admit that they have no business building safety critical software. Idiots.
For 6 seconds the system had crucial information and failed to relay it, for 1.3 seconds the system knew an accident was going to happen and failed to act on that knowledge.
Drunk drivers suck, but this is much worse. This is the equivalent of plowing into a pedestrian with a vehicle while you're in full control of it because you are afraid that your perception of the world is so crappy that you will over-react to such situations often enough that the risk of killing someone you know is there is perceived as the lower one.
Not to mention all the errors in terms of process and oversight that allowed this p.o.s. software to be deployed in traffic.
This is so tragic. Even Volvo's own collision avoidance system would (could?) have mitigated the crash a fair bit. From Volvo's own spec. sheet [1]: "For speeds between 45 and 70 km/h, the collision is mitigated." In this case, the NTSB reports mentions that the car was traveling at 43mph, i.e. 68.8 kmph :(.
What bothers me is that these systems are on public roads, without public oversight. Sure, Uber got permission from the local authorities, but getting an independent team of technologists and ethicists to sign off on the basic parameters should have been the bare minimum ... yes, that would take time, but do we really want to give companies, especially ones like Uber with a history of ethical transgressions, the benefit of the doubt?
[1] https://tinyurl.com/y9sp2fmu (WARNING: This open/downloads a PDF that I referred to above. Page 5 has the paragraph on pedestrian collision detection specs)
If you want to compare it with a car operating on cruise control you'd have to sedate the driver.
(Subaru's doesn't do active lanekeeping, but lots of other manufacturers like BMW and Ford do.)
The newer cruise controls have lane-keep assist and adaptive cruise control - you don't have to actively steer or brake. On an open road, there's effectively little difference from the Uber vehicle, which would also let you disengage autonomous mode by breaking or otherwise interacting with the controls. (The newest mass-market cruise controls are "stop and go", which means they'll even bring the car to a full stop, then start driving again.)
Or at least it should be. That's why there is a v_max that a car is not allowed to exceed and a faster or heavier car will have better breaks. And 70 km/h as here should be far away from v_max.
> 1.3 seconds before impact ... emergency braking maneuver was needed ... not enabled ... to reduce the potential for erratic vehicle behavior
This wind-up toy killed a person.
Transport is a waking nightmare anyway. Every time you get in your car, every mile you drive, you're buying a ticket in a horrifying lottery. If you lose the lottery you reach your destination. If you win... blood, pain, death.
Into this we're setting loose these badly-programmed projections of our science-fiction.
- - - -
A sane "greenfield" transportation network would begin with three separate networks, one each for pedestrians, cyclists, and motor vehicles. (As long as I'm dreaming of sane urban infrastructure, let me sing the praises of C. Alexander's "Pattern Language" et. al., and specifically the "Alternating Fingers of City and Country" pattern!)
My mom has dementia and is losing her mind. We don't trust her to take the bus across town anymore, and she hasn't driven in years. If I wanted an auto-auto[1] to take her places safely I could build that today. It would be limited to about three miles an hour with a big ol' smiley sign on the back saying "Go Around Asshole" in nicer language. Obviously, you would restrict it to routes that didn't gum up major roads. It would be approximately an electric scooter wrapped in safety mechanisms and encased in a carbon fiber monocoque hull. I can't recall the name now but there's a way to set up impact dampers so that if the hull is hit most of the kinetic energy is absorbed into flywheels (as opposed to bouncing the occupant around like a rag doll or hitting them with explosive pillows.) This machine would pick its way across the city like "an old man crossing a river in winter." Its maximum speed would at all times be set by the braking distance to any possible obstacle.
[1] I maintain that "auto-auto" is the obviously cromulent name for self-driving automobiles, and will henceforth use the term unabashedly.
If you can't give your "self-driving software" full access to the brakes because it becomes an "erratic driver" when you do that, you do not have self-driving software. You just have some software that is controlling a car that you know is an inadequate driver. If the self-driving software is not fully capable of replacing the driver in the car you have placed it in, as shipped except for the modifications necessary to be driven by software, you do not have a safe driving system.
That sounds like a terrible idea.
Independently-working override-capable systems are the base of engineering redundancy safety. See airborne collision avoidance systems (ACAS), which will automatically and forcefully steer an aircraft to avoid a collision if necessary: https://en.wikipedia.org/wiki/Airborne_collision_avoidance_s...
Redundant safety systems are a great idea, evidently Uber needed more of them, and integrating with the Volvo system might have been a reasonable option. It's silly to suggest that the integration would necessarily have been trivial, though. That's what I'm objecting to.
(Were any Professional Engineers even involved in this? Or was it just a bunch of "software engineers"?)
There is no "guarantee" that uber "engineers"/engineers put more thought into this than "their system is inconvienent, tear it out" or "we don't need their system because ours will be better, tear it out." Nobody can guarantee Uber engineers were not stupendously negligent until the investigation is complete. Anybody who thinks they can guarantee that has an irrational basis for thinking they can provide such a guarantee.
The above traits aren’t exclusive to Uber’s “engineers”, but are lethal when applied to the engineering of life safety systems.
A lot more than one, that's for sure.
See how that holds up in civil court in front of a jury, or any legislative body Uber might need to convince to allow their operation in a jurisdiction in the future.
“Just think of how many more people we would’ve killed if we didn’t care at all!”
I had thought an audience of developers would "get it," since we deal with fallout from ill-conceived integrations every day, although admittedly in a far less spectacular form than control system engineers.
Unfortunately, the uber hate train has already left the station and there's no slowing it down until the investigation finds (or doesn't) actual evidence of negligence rather than clickbait guesswork by armchair engineers. Too bad.
You do a disservice to the audience by assuming it would be understanding of grossly negligent behavior.
Failures happen, that is to be expected. If you're building self-driving vehicles, you're supposed to be engineering for those failures. Disabling two life safety systems (Volvo's AEB and Uber's own AEB) and relying on a single inattentive human driver? I don't understand how that's understandable or justifiable in any scenario besides a carefully controlled test track.
If any of the systems are vulnerable to any such false positives, and equipped to enable emergency braking to avoid them, even on the highway, it's not hard to imagine why they might be disabled, especially during testing phases.
I think it's fair to say that at this early stage in product development, there's probably no 'always right' answer for how to handle a given obstacle without considering locality, driving speed, road conditions, likelihood of false positives and negatives, etc.
Hey there's an idea for Uber, maybe instead of disabling the forward collision system entirely they could just decrease the sensitivity to lessen false positives (like in our Jeeps)?
Instructions from TCAS are near absolute in their priority. If ATC says to do something different, you ignore ATC and do what TCAS says. If the pilot in command says to do something different, you ignore the pilot in command and do what TCAS says. If somehow God Himself is on your plane and tells you to do something different, you ignore Him and do what TCAS says. Compliance with TCAS is non-negotiable, and the Überlingen disaster[1] is the bloody example of why it's that way.
Self-driving/autonomous-car systems need to have a similar absolute authority built in. If Uber disabled theirs because of false positives, it's a sign Uber shouldn't be running those cars on public roads.
[1] https://en.wikipedia.org/wiki/2002_%C3%9Cberlingen_mid-air_c...
Somehow, it works out.
The point is that so far most (all?) of these computer systems don't have a failure mode where it kills pedestrians, because their scope is very limited.
Same with power steering: it won't steer into a different directorion. You don't have to "fight" with it.
Please re-write this for clarity.
1. Regulators want aggressive breaking but carmakers want smoother driving
2. Manually tuning all the edge cases for cases where the software is uncertain what's happening will lead to fragile monolith black boxes
These kind of tradeoffs were things every self-driving car software developer KNEW they were going to have to deal with - the most extreme being the one where the software has to decide who to kill and who to save:
https://www.theglobeandmail.com/globe-drive/culture/technolo...
The regulators should only test for false negatives, where the car should have stopped, but did not detect the obstacle (false negative), because there, it is a clear threat to safety, and the car company's incentive, while definitely still present, is less pure, as the amount of false negatives is a direct trade off with the quantity of false positives (because it is a treshold: a minimum confidence level from which you decide that there is indeed something in front of the car and you need to break), which make driving more awkward for 99% of drivers
Nobody disagrees with you and that is explicitly the reason why a human is on board, so I am not sure what you are arguing against.
I think it's very clear that a human driving a normal vehicle is different from a human sitting at the wheel of a self-driving (semi-self-driving?) vehicle. You simply cannot expect a human to remain as engaged and attentive in such a passive situation.
It's baffling to me that they chose to deactivate emergency braking without substituting a driver alert. If the false-positives are so frequent as to render the alert useless (i.e. it's going off all the time and you ignore it) I don't think these vehicles are suitable for on-road testing.
You can lean fairly heavily on the 'still dangerous, but better' argument in the face of 40,000 US vehicle fatalities each year, but there are limits.
It seems that Uber wasn't actually verifying that, though.
You misunderstood. The Uber software had sole control of the brakes (plus the human of course). The Volvo factory system was disabled so that it didn’t have negative interaction with the Uber system.
Your mistake is understandable. The article was poorly written, perhaps due to a rush to publish, as is the norm these days. Even if the NTSB report was unclear, that doesn’t excuse clumsy reporting.
If you’ve ever done significant mileage in a car with an emergency braking system you probably have experienced seemingly random braking events. The systems favor false positives over false negatives.
That's not how I read it, or how any of the journalists who are reporting the story are reading it. Uber disabled the self driving software's ability to do an emergency stop when it detected it was going to crash. The Volvo system is separate and also was disabled when the car was in self driving mode.
https://www.bloomberg.com/news/articles/2018-05-24/uber-self...
>Sensors on an Uber SUV being tested in Tempe detected the woman, who was crossing a street at night outside a crosswalk, eventually concluding “an emergency braking maneuver was needed to mitigate a collision,” the National Transportation Safety Board said in a preliminary report released Thursday.
>But the system couldn’t activate the brakes, the NTSB said.
That's the only reading that makes sense to me, otherwise why did the car fail to attempt to stop when it detected the pedestrian and knew it was going to hit them?
> At 1.3 seconds before impact, the self-driving system determined [...]
Unless this is exceptionally poorly worded, it certainly sounds like self-driving system was the one doing the determination.
The NTSB report is pretty unclear, I had to re-read it several times and I think you're correct that the "emergency braking maneuvers" they refer to are the Volvo ones. It's strange though that they word it as
> At 1.3 seconds before impact, the self-driving system determined that an emergency braking maneuver was needed to mitigate a collision
Is the Uber self-driving system able to interact with the Volvo system? Or are they calling the Volvo safety features a second "self-driving system"? And what were the steps, Uber realizes it needs an emergency braking maneuver and sends a signal to the Volvo system which then responds with "I'm disabled" ?
I understand why the Volvo features may be disabled, but it's alarming that the self-driving system made no attempt to brake at all when it was fully "aware" it would hit someone.
The report does mention the Volvo braking features by name a few paragraphs earlier though... So I'm still not entirely sure.
This isn't horseshoes, as the old saying goes. I unapologetically have a high bar here.
The charitable interpretation of this is that the industry believes that self-driving AI is a safety feature of greater quality than, say, lane assist or auto-breaking.
The less charitable one is that they find it too much work to integrate their AI to other safety systems. Which, to be fair, is really going to be a lot of extra work, on top of developping self-driving.
If what you said is true, then the vehicle operator would not be relied on to intervene because the Uber self-driving software would apply the brakes. Since the vehicle operator is relied on to intervene, this indicates the Uber self-driving software has its emergency braking disabled.
This is not my experience with VW's 2016-model-year system.
Soemtimes it stops a second or two before I would've. I haven't had any false positives, though.
"At 1.3 seconds before impact, the self-driving system determined that an emergency braking maneuver was needed to mitigate a collision (see figure 2). According to Uber, emergency braking maneuvers are not enabled while the vehicle is under computer control, to reduce the potential for erratic vehicle behavior."
I believe you are the one who has misunderstood.
"emergency braking maneuvers" refers to an additional automated (software) system for automatically applying the brakes in an emergency (that's detected by that additional system).
>2 In Uber’s self-driving system, an emergency brake maneuver refers to a deceleration greater than 6.5 meters per second squared (m/s^2).
So, Uber's self-driving system has command to brake normally, but it cannot "slam" the brakes. The other system from Volvo's is deactivated when Uber's is working and cannot brake at all. Thus, since Volvo's is deactivated and Uber's won't brake if it judges that a deceleration of >6.5 m/s^2 is needed, it turns out that in automated mode, the car actually lacks the ability to trigger emergency braking at all, hoping instead that the driver will somehow notice. But in a sadistic twist, no warning is given to the driver at any moment that they need to slam the brakes.
However, if the safety driver was trained to brake immediately upon warnings it could have worked quite well. But that would negate the removal of e-brake actuation.....
Volvo has it right: human driver, computer backup. Uber's idea of a human acting as a last-second backup to a computer gets the relative strengths and weaknesses of each exactly wrong.
This accident should have been avoided. No excuses.
That's enough time to play a bell that alerts the driver and for the driver to manually react, press the brakes, and come to a complete stop.
And this was a pretty easily preventable scenario (which just makes it more tragic of course). Software is nowhere near ready to drive cars on real roads.
UBER software is nowhere near ready to drive cars on real roads. There are multiple competitors in this space (Waymo and Argo immediately come to mind); they don't generally have Uber's reputation of "move fast and break things" or of "cut human costs as soon as feasible."
In my initial assessment, I was reasoning the other direction---from practices I was familiar with from stories of those companies to Uber---and falsely assumed Uber was behaving more responsibly than they were. This Uber tragedy doesn't significanly update my prior assumptions about its competitors.
The risk of fatality would have been severely reduced if the car was (at most) travelling at 30mph (likely around ~10% - instead of between 25% and 60% for the speed at the time of impact depending on what study you choose).
> Although toxicological specimens were not collected from the vehicle operator, responding officers from the Tempe Police Department stated that the vehicle operator showed no signs of impairment at the time of the crash.
> Toxicology test results for the pedestrian were positive for methamphetamine and marijuana.
So they tested the victim for drugs but not the Uber employee in the car??
Other than that, Uber's so-called "self-driving" system sounds like crap and should never have been allowed to be used in that state.
Maybe it reports so many false positives that Uber turned those off and just collects the data to improve the algorithm?
> The vehicle was factory equipped with several advanced driver assistance functions by Volvo Cars, the original manufacturer. The systems included a collision avoidance function with automatic emergency braking, known as City Safety, as well as functions for detecting driver alertness and road sign information. All these Volvo functions are disabled when the test vehicle is operated in computer control but are operational when the vehicle is operated in manual control.
However, that appears to be separate from emergency braking under Uber's self-driving system:
> At 1.3 seconds before impact, the self-driving system determined that an emergency braking maneuver was needed to mitigate a collision (see figure 2).[2] According to Uber, emergency braking maneuvers are not enabled while the vehicle is under computer control, to reduce the potential for erratic vehicle behavior. The vehicle operator is relied on to intervene and take action. The system is not designed to alert the operator.
> [2]: In Uber’s self-driving system, an emergency brake maneuver refers to a deceleration greater than 6.5 meters per second squared (m/s^2).
It sounds like Uber didn't trust their own self-driving system enough to allow it to initiate sudden crash stops. Too many false positives, I guess? Of course, simply disabling the function leads to other obvious problems, as shown.
I think the better interpretation is that the Uber system disabled another separate (non-Uber) system.
Volvo has automatic driver-assistance emergency braking. That's turned off while Uber's self driving system is on, because obviously the two systems are not built to work together.
Uber also disabled emergency braking from their own system. That was because it would "drive erratically" when it was turned on.
There are two systems in the vehicle. One is the manufacturer's, let's call it System V after Volvo, and the other is System U, for Uber.
System V provides collision detection and emergency braking. It played no part in this incident, since it's inactive if the car is under control of System U, which it was at the time.
System U can decide that the car should slow down in some situations. Let's call gradual slowdown Action U1, and emergency slowdown Action U2. The incident called for Action U2, by Uber's criteria. What Uber said is that a) they disabled automatic execution of Action U2, punting it to the driver (really, a bored passenger in driver's seat), and b) that the driver would get no indication of emergency situations from the system.
The idea is, presumably, that driver should watch the road and react in emergencies. But we also know that the driver had the duty of working with the onboard console, which must have been quite a distraction. Effectively, Uber has set themselves up for failure, and it happened.
So assuming the driver knows all of this (and that's a big assumption), then you have the blame shared two ways, and it's hard to tell who deserves more.
(1) You'd have the driver being at fault, since they were responsible for controlling the vehicle at the time, even though the computer was doing the majority of the driving. In this case, the driver should not have been using their phone and ignoring the road and their duties to control the car.
(2) Uber should share some blame for not building alerts to the driver into the system.
But how much of these responsibilities Uber made clear to the driver is very much worth knowing, because however you slice it this was not so much a failure of technology as human negligence.
If the claim is that Volvo's system is intervening in valid cases where Uber's system would (arguably) have handled it, then Uber's system is driving too aggressively or is too slow in responding. Humans, when paying attention, can drive Volvo's cars without often triggering the emergency braking.
> At 1.3 seconds before impact, the self-driving system determined that an emergency braking maneuver was needed to mitigate a collision[..]
[emphasis mine]
> In Uber’s self-driving system, an emergency brake maneuver refers to a deceleration greater than 6.5 meters per second squared (m/s2).
But then again these systems also make people lazy when the vehicle drives perfectly 99% of the time...
Fact of the matter is, the person was not allowed to cross there. Not only was it not allowed [0], it was also extremely dangerous. Why would she do this?
That's one part of the conversation.
The other part of the story is that the self-driving car was mismanaged and misprogrammed, and that this was likely also a reason why the woman died.
There is therefore reason to believe both parties could have prevented this death. You're not sure. Perhaps drugs weren't a factor. And perhaps a driving person could not have braked quickly enough either to save her. You don't really know. But when you have information which lets you speculate plausibly to explain unknowns, I think it's relevant to include that information as a journalist. Meth use falls within that range of relevant information in this case, if you ask me.
It feels a bit analogous to saying a woman got shot and killed at a gun range. She ran into the shooting range and got shot. Why would she do this? The person shooting wasn't paying attention and was just firing casually down the range. Knowing the woman was on meth helps explain a lot. As a journalist I'd think that was relevant, and as a reader it offers a possible explanation for this kind of behaviour. It doesn't negate the fact the shooter didn't follow procedure and could have prevented this death, too.
I thought it was fitting at the very end of the article like it was in the original analysis that they refer to. Not so much in the subtitle, I feel that was in poor taste and driven by clickbait. It shouldn't be the focus of the article.
[0] http://darychuklaw.com/legal-services/personal-injury-claims...
Have you seen the intersection in question?
https://pbs.twimg.com/media/DYrspoFVwAAtJCs.jpg
I think the pedestrian is very low on the list of who to blame, with the intersection designers and Uber engineers high above her.
I really hate to defend this position because I feel terrible for her and it's quite obvious uber made some very bad calls here. (in fact I even used the very loaded word murder in another comment, see my post history). I'm definitely not arguing to put all or even most of the blame on the woman.
The intersection is indeed absolutely terrible. It makes no sense. You're not allowed to cross there, there are even signs which state it on both sides, referring to a crosswalk a minute walking up ahead. i.e., there is just no way you're allowed to cross there, despite the island in the middle having the cosmetic design of a walkway, you're not supposed to get on the island or get off it or cross the roads at that location. It's a terrible design choice, both inviting people to cross (in a dangerous spot), while also saying it's illegal. With better infrastructure planning you could have railing there preventing crossing, and no island at all.
That having been said, I can't for the life of me imagine crossing there and not seeing an oncoming car with its headlights on, assuming I was paying attention to the road I was illegally crossing. The fact meth is involved is a helpful possible explanation for why this kind of attention was not given.
You can check out the road on google street view, it definitely helps. I think you'd agree on two things, one is that it's not allowed to cross there and two that if you were to cross there, it'd be pretty easy to see cars. The reverse isn't necessarily true if you wear dark clothing at night.
Since it’s a no pedestrian zone, it has a higher speed limit posted
A higher speed limit causes a linear reduction in detection time, a sensor that detects a pedestrian 2 second away at 20mph will detects a pedestrian 1 second away at 40mph
Braking distance and impact energy are both quadratic and that’s part of how/why speed limits are defined
There are a lot of engineering issues that will arise from the need to cope with people violating limits and restrictions around autonomous vehicles.
I’m not defending uber here btw, they definitely jumped the gun deploying the system as described, just thinking out loud. There are decades of crashes that went into the driving code and road regulations, which humans kinda understand by relating to road design and getting cues from the environment that ais will need to learn
- 70mph to 0 around 184 ft. [1]
- 43mph = 63.066667 Feet per Second
- At 6 seconds the car was 378 ft. away.
[1] http://media.caranddriver.com/files/2016-volvo-xc90-t6-awd-i...It's not clear at what point the car ascertained a collision would occur between detection 6s before and the determination that emergency breaking was necessary 1.3 seconds before.
Was there any other determination in between, and when? What I'd like to see is Uber's modelling of the woman's trajectory and the likeliness of collision across the 6 second window. That's completely left unsaid.
The average braking distance of a car is about 24m at 40mph, which is approximately the distance between the woman and the car at 1.3 seconds out. So perhaps the 1.3s figure wasn't the first moment the car determined a brake was necessary, but rather, the last moment the car could have braked to prevent a substantial collision. I want to know the first moment the car determined a brake was necessary at all. It's likely not 6s, but it's also likely not 1.3 seconds. It seems this was entirely preventable, or at least the collision impact could have been mitigated severely, had there been a braking and/or warning system in place.
Shutting off brakes on literally the only driving agent tasked with full attention is inexcusable. But that's what they did. To me that's murder. They used to have two passengers, one for tagging circumstantial data, the other to override the car when necessary and keep eyes on the road at all times. Either keep that and shut off emergency brakes from the car and put a warning system in place for the 'driver'. Or do not shut off emergency brakes. Instead they put a single person in the car, tasked to do things that kept her eyes off the road half of the time, and shut off brakes for the AI. That's insane.
Yes, you could -- that's how I drive. Do you not? If I detect a mobile object that might be moving into my path, I slow down to give myself time to react until I am reasonably certain of safety. When doing so I take into account my situation-specific knowledge -- have I made eye contact with the pedestrian and do they know I'm coming? Is the dog on a leash and is the owner being attentive? Does the cyclist seem aware of my presence?
I would expect no less from anyone licensed to drive a car, be they human or software.
I didn't say you can't drive a car without being cautious.
I said you can't drive it without constantly braking the moment you detect an object, irrespective of what the object is doing. (e.g. moving into or away from the driving path).
i.e., just because an object was detected 6 seconds before impact did not mean the car ought to have started braking at that moment. It could be that the object was 200 feet away and moving away from the car's driving path, 6 seconds before impact. It'd be absolutely ridiculous to brake in that situation.
We have no information about this context, e.g. the car's data or determinations within the 6 second window. We only know it detected an object 6 seconds before impact.
It appears like the person I was replying to implied 'the braking distance was 180 feet, but the person was 380 feet away, thus uber could have prevented killing this woman had it not shut off the brakes'. In reality, the 6 second figure isn't relevant. What is relevant is the context that allowed a reasonable driver/AI to determine at a particular point in time, that the car should have slowed/braked. And we don't have that information yet. That's what I'm interested in.
But we're asking a lot from this software (for good reasons), but humans commit similar leaps of faith of various severity on the roads daily -- failure to yield, failure to maintain following distance, assuming other drivers immediately adjacent to you will keep driving safely and carefully -- and only a small subset of these situations results in accidents. We're expecting an algorithm coded by humans to perform better than a complicated bioelectric system we barely understand.
Waymo has opted to commit to thoroughly understand its environment, which is why their cars drive in a manner that bears no resemblance to how humans actually drive. We as a society have to eventually reconcile the implications of the disconnect.
Deer hits a major cause of fatality out in the country. If your driving at night in deer country and you aren't eyes wide open then you are going to have an unhappy experience at some point. Their instincts are essentially the exact opposite of what they should do when encountering a car. They will stay in the middle of the road, and they will jump in front of you if startled.
This crash didn't have a single cause. Any one of those factors being handled correctly would have prevented it.
It is not the fault of the pedestrian for having been slaughtered, especially due to the immense amount of time after the car saw the pedestrian until the time that the accident occurred.
I guess they didn't have to include it, but it's in the report.
But then they turned their own safety feature off, because it failed to be as good as Volvo's. And then did not turn Volvo's feature back on.
I'm still disappointed that the system has to use underlying maps to know where lanes are and what the speed limits are in them. What happens when the map is less than 100% perfect?
I've ridden in these self driving Ubers. When I rode in one, the driver drove almost the entire time, except on a few straight stretches of road. They always had their hands ready to grab the wheel, were always attending to what was happening etc.
It seems like the marketing and the engineering got crossed here. Marketing says these were self driving, but anybody who rode in them knew they weren't. They were supposed to be getting driven by real drivers. From the report, it sounds like the drivers were listening to the marketing instead of the engineering team (who presumably would have told them that the system doesn't brake on its own).
It sounds like the real driver wasn't driving as they were supposed to be. From the video, it looked like they were reading something on their phone[1] instead of driving the car.
Compare this to a pilot flying in an autopilot. They don't shut their radios off and stop paying attention to the flight, they still fly the airplane and remain attentive to what is happening with it. That's what this driver should have been doing, not looking at their phone.
It frustrates me that this level of negligence could set self driving tech, something that will save countless lives, back. This was the Chernobyl moment for self driving tech. It's safer than alternatives, but now this is all people are associating it with.
[1]:the driver states that they were interacting with the Uber self driving system, not their phone.
Unlike for nuclear power, this is currently nowhere near true for self-driving tech.
According to the NSTB report, they were looking at a separate diagnostic panel and flagging messages which Uber asked them to do as part of self-driving training duties.
> It's safer than alternatives
The system also decided it should have applied the emergency brakes, but then didn't. I don't think this system is safer than alternatives.
If it can not be done securely at scale, it better be set back, especially on public roads.
I am deeply skeptical of how safe and realistic self-driving vehicles are. Even with such less amount of cars dubbed autonomous on the roads, we've seen up until now a great multitude of fatal accidents or near misses already.
This putting internet and AI in everything reminds me of a recent Vsauce video I saw which shows radium chocolate bars and underwear: a new fascinating thing that in future will probably prove more harmful than it is useful, because of how we overestimate it's practical utility.
if (personDetected())
- break();
+ brake(); for (;;) {
if (detect_obstacle()) break;
move_forward();
}The driver has to look down on a console to see warnings like this AND drive the car? This and that the emergency system was off tells me that the accident was 100 % the fault of Uber even if the "driver" were dancing in the backseat.
https://ec.europa.eu/transport/road_safety/specialist/knowle...
The point I was trying to make is that I believe the noteworthy event is that a self-driving car struck a person, without even attempting to avoid it. That she was killed is a tragic twist to the story. I believe that even if she wasn't killed it would still be a noteworthy event because, again, the car did not attempt to avoid it.
I do not at all intend to diminish the fact that Uber killed someone.
But how much work the software does is not what makes it remarkable. What makes it remarkable is how well the software works. This software never crashes. It never needs to be re-booted. This software is bug-free. It is perfect, as perfect as human beings have achieved. Consider these stats : the last three versions of the program — each 420,000 lines long-had just one error each. The last 11 versions of this software had a total of 17 errors. Commercial programs of equivalent complexity would have 5,000 errors.
Also from the article: “If the software isn’t perfect, some of the people we go to meetings with might die."
I don't think it's really similar to this accident, since it'd kind of be like the driver realizing they have to break, but gassing it instead.
Also interesting is that in a Boeing, this likely would have never happened. In an Airbus control inputs are averaged together, so the captain had no idea his copilot was pulling back during a stall warning. In a Boeing, the control gear provides feedback (physically moves) to the pilots, so they would have been able to realize they were giving opposite inputs.
Source: https://www.popularmechanics.com/flight/a3115/what-really-ha...
Excerpt below: 02:13:40 (Robert) Remonte... remonte... remonte... remonte...
Climb... climb... climb... climb...
02:13:40 (Bonin) Mais je suis à fond à cabrer depuis tout à l'heure!
But I've had the stick back the whole time!
At last, Bonin tells the others the crucial fact whose import he has so grievously failed to understand himself.
02:13:42 (Captain) Non, non, non... Ne remonte pas... non, non.
No, no, no... Don't climb... no, no.
* Ice clogs the aircraft's pitot tube, so the computer loses airspeed sensor data. This causes the autopilot to turn off and the flight computer to change to "alternate law". This is very important because normally the computer does not allow a pilot to stall the aircraft. Under alternate law the pilot has more direct/traditional control, and can stall.
* The pilots didn't clearly understand why the autopilot went out, or that they were in alternate law. The copilot (who was flying the aircraft) began pulling back on the stick, without communicating his action.
* The pilots started to get stall warnings, but didn't understand how they could be stalling, because they didn't know they were in alternate law.
* The captain tried to take control to recover. Despite verbally acknowledging the control hand-off (IIRC) the co-pilot continued pulling back on his stick.
* The captain didn't realize that his control inputs are being overridden by the co-pilot and becomes increasingly confused about why the aircraft isn't responding to his inputs.
* By the time the captain does realize what is happening, it's far too late to recover.
Those cars are not ready for public roads. If your sensors give too many false alarms then you should improve them.
Also I think initially there should be a speed limit for self-driving cars. For example, 15-20 mph should be enough for driving in the city and won't cause too much harm in the case of an accident.
It's worth remembering that the video of the acciedent that Uber made available showed a pitch-black road with very little lighting, something that is not corroborated by the NTSB report. Given that the only comment about visibility in the preliminary report is that "(r)oadway lighting was present" it sounds very likely that Uber deliberately tried to create a misleading impression.
>> The forward-facing videos show the pedestrian coming into view and proceeding into the path of the vehicle
This is a little less clear-cut but it also seems to cast doubt onto the initial statement by the Tempe police chief, that Uber was not at fault because the pedestrian dashed onto the road suddendly and the crash was basically "unavoidable". [1]
______________
[1] https://www.sfchronicle.com/business/article/Exclusive-Tempe...
If that strategy produces too many false positives, it's time to go back to the drawing board. The right answer in that case is absolutely NOT to say, "Ah, just fuck it" and deploy the system in the field.
1. Ones where a human pilots them most of the time, but a computer steps in in emergencies. 2. Ones where a computer pilots them most of the time, but a human steps in in emergencies (hopefully).
For some reason I don't understand, people treat (2) as an evolution of (1). But it is the inverse.
There's only one car certified for SAE L3 / "eyes off" and it's the 2018 Audi A8, only up to 60kmph - this is still not self-driving.
The primary concern here is false advertising as pervasive as it is blatant.
BMW has collision detection system that makes a loud beep when it determines an imminent collision. The beep alerts the driver regardless of false positives or false negatives. Its a simple solution which many cars have had for over 10 years.
Why Uber engineers chose to not alert the driver is beyond me.
Wow. So the vehicle and these tests were run knowing full well that an accident like this would not be preventable. This isn't manslaughter, this is murder. Uber was letting its car drive without any safety systems, without even an alert driver behind the wheel because her job was to monitor the panel. Fuck me. Wow. They should never be allowed to operate another autonomous vehicle again. The ceo should go to fucking jail. Fucking murderers.
So, let's see what will happen to the Uber personnel involved.
By the way, it's insane to be an Uber test driver under these circumstances. They're going to hang you out to dry. Quit.
Of course, every human drivers with experience knows that you pass pedestrians behind, not ahead. The Artificial Intelligence obviously was not smart enough.
In other words, as suspected, the self driving cars are a pipe dream. One can't just mix a bunch of statistical woodoo into a neural net and hope it will work. It may work most of the time, but the mistakes would be catastrophic and incredibly stupid.
Think they also own a piece of Lyft.
All of those things are bad things to hit, why not slow down?
b. 1.3 seconds before impact, the self-driving system determined that an emergency braking maneuver was needed
Too late for either a human or computer.
c. operator is responsible for monitoring diagnostic messages
There is superseding responsibility to drive the car safely. Uber's policy sets up the test driver for failure, and puts people's lives at risk.
d. emergency braking maneuvers are not enabled while the vehicle is under computer control
The pedestrian had no chance.
The very feature that should make the car safer was disabled, but also the judgement was poor and too late, and Uber policy sabotaged the car driver judgement as the exclusive (not merely primary) safety mechanism by distracting them with data that in most every way would have been more diverting than talking on a cell phone or fiddling with the radio.
I hope the family got a lot of money in the settlement.
Hopefully they will get the book thrown at them and then a couple of chairs.
This time, I don't think they should get it.
(Not that I, for one, should have received it, previously.)
I hope this accident weighs on the people who made these decisions so that they will be more careful in the future. I would hope they would not see it simply as a bug in the system.
Especially something as powerful as a ton of steel moving like a missle on our roads.
Absolutely stunningly stupid that there are teams that built this and felt incentivized to put this on our roads without any concerns or safety mechanism. Shameful.
Legally, it will be amazing in the future to hold these people - the engineers, product managers, the PR people and the CEO (ex and current) all accountable. We did for something far less serious with VW...
At some point you need to have a regulatory body in place that sets standard for safety, otherwise people are going to die.
If you're an engineer at Uber and you're facing this kind of pressure that's causing you to take safety shortcuts, walk away. Go work somewhere else.
Real engineers are responsible for their decisions they can't just defer personal responsibility to management.
If you build a bridge you know is unsafe because the company you work for will go under if it doesn't get built, it's still your fault when the bridge fails and kills people.
Walk away.
Stopping in time to not run over an unexpected pedestrian crossing the road would be item number one on any sensible person's agenda. Uber needs to be liquidated.
Just appears Waymo is well ahead of everyone else.
While everyone else is trying to be the Uber of X... Uber doesn’t even want to be Uber. Their latest thing is taking funding from the US Military for some project iirc.
This “technology” company has no idea what it really is.
I think they were floundering -- until the new CEO took over. Their approach appears to now be building an Expedia for local travel which includes ridesharing, JUMP bikes and Getaround.
These side projects (self-driving, logistics, etc) I believe are the holdovers of the earlier era before they knew what they were doing. They always struck me as more of as a way of distracting everyone else until they did.
This is not a mistake. This is straight up manslaughter.
(Besides, relying solely on an unassisted human driver - even an attentive one - is dangerous enough that the industry wants to make automatic emergency braking systems mandatory on all new cars as soon as it's practical.)
https://www.reuters.com/article/us-uber-crash/ntsb-uber-self...
This is actually a good use-case for that pay-per-article site/app (but I can't remember its name off the top of my head). Unfortunately, I don't know how easily I could find the article in it. I emailed them about that and they told me they were working on integrating with publisher sites; maybe they should look into integrating with aggregator sites instead.
https://blendle.com/i/wsj-com/uber-self-driving-car-that-str...
https://www.google.com/search?q=Uber+Self-Driving+Car+That+S...
https://www.ntsb.gov/news/press-releases/Pages/NR20180524.as...
https://arstechnica.com/cars/2018/05/emergency-brakes-were-d...
> The agency, which investigates deadly transit accidents, said Uber’s self-driving system determined the need to emergency-brake the car 1.3 seconds before the deadly impact. The NTSB report said that, according to Uber, automatic emergency braking isn’t enabled in order to “reduce the potential for erratic vehicle behavior” and that the system also isn’t designed to alert the operator in case of an emergency.
I guarantee that driver was on her phone. Just watch.