927 karma · joined January 6, 2015
For some reason, it does not catch up with the mainstream but it truly would make sense for such application, albeit at the cost of a computational overhead and more work for the compiler.
I am a signalling engineer, with experience in design and delivery of autonomous trains (really autonomous, no driver, no nothing). Seriously, the conclusion makes me want to scream:
> Shouldn’t ADS developers be required to prove an ADS is at least as safe as a human driver for a specific ODD before allowing it out onto public roads?
To deliver an ADS thou shall:
1/ Identify the standards you are going to comply to (and I am talking about real standards, like EN 50126, SMS compliant with AS9100, not a Waymo brochure)
2/ Define your safety objectives (hint: for an ADS, it's going to be way way waaaaaay higher than human error rate). You don't self-define these. You need to talk to the safety authorities of the area were you intend to circulate.
3/ Build a safety case explaining how you achieve credibly these objectives (spoiler: testing will not be enough)
4/ Have your case examined by an independant safety assessor, accredited by a relevant national or trans-national authority
5/ Put your ego on a shelf.
Otherwise, thou shall kill people.
Simple. But it seems the automotive industry is ready to go to any length to avoid going through the concept of an independant safety assessor.
EDIT: Bullet points syntax
One of the limiting factor is to avoid giving the said lobbies unlimited funding. That is one of the reason for taxing corporations.
But it is not a lofty ideal, it has been done before. And in the field of transportation. Trains used to crash all the time. Driverless trains don't. Why? Because fail safe systems have been added on railroads that nearly totally prevent this.
Don't take my word for it, the bar for rail safety is defined in well documented standards (namely, EN 50129, EN 50126 and EN 50128). It is 10-9 hourly probability of fatal failure. You can also look up "CBTC" on the Internet. This is the reference bar for driverless.
The real reason Tesla and friends don't want to go there is because fail-safe systems like a CBTC requires some form of collaboration with devices installed on the ground infrastructure, meaning Tesla should accept to become part of a system, and not "the" system. Obviously a paradigm change for the car industry.
How long will the public authority require to understand that they must step in to force a systemic collaboration and standards between infrastructure and cars to ensure driverless safety, I don't know, but I think it's time to call bullshit on the concept that you can have an acceptably safe driverless car system without it.
1/ « Keep an eye on » is different than « Intervene ». We have to have satellites out there mapping this stuff in excruciating detail, and spies tracking who is responsible for what, and special forces hit them if they step out in a zone where they can be hit. The people who perpetrate this must live in fear.
2/ The UN is full of problems, but if a resolution grants universal asylum to Uighurs anywhere in the world, then at least those people will know there is somewhere they can escape to. That’s something.
3/ Your kids might one day be in a position to do something about it. Telling them why this is wrong, and why they should care, might just be the most important thing you do in your life.
I don’t want to start a big argument. I just want to say that we can all do little things that do matter collectively.
Ahem. No.
There is no collision hazard in elevators (essentially each elevator is on its own dedicated track). In railway, collision hazards are everywhere because you can change track and there are multiple trains on the same track, possibly (yikes) in head to head movements.
If you want to see the specs of a real Automatic Train Protection, the European one is public [1]. And that is only the protection part. There is no automatic pilot in there.
[1] https://www.era.europa.eu/content/set-specifications-3-etcs-...