11 ms·
Self-Driving Cars Must Meet 15 Benchmarks in U.S. Guidance
- hughperkins 10y agoThis is excellent news! Guidelines to follow implies that if the manufacturers can meet these guidelines then they could plausibly have a somewhat legal basis for putting self driving cars on the roads.
- elicash 10y agoInfo here: https://www.transportation.gov/AV https://www.transportation.gov/AV (including noon Eastern livestream)
- mtgx 10y agoThe only regulation that really matters is making car manufacturers liable for accidents and they would have to pay a fine from $100,000 for the smallest accident (per car) up to $10 million per accident. When the manufacturers "can't explain" how the accident happened (after an audit was performed), they should be fined the maximum $10 million amount. Why? Because for one assuming it's just a glitch and "they don't know" about it, then they should pay for incompetence. And two, if the car was hacked by a nation state, then their security sucks, and they should again pay the maximum amount so they have the maximum incentive to ensure digital security of self-driving cars. Where third-party self-driving systems are involved (MobilEye, etc), the liability/fine should be split 50-50 between the car maker and the system vendor. Give car makers these "incentives" and the other regulations are more or less pointless (other than establishing common V2V and V2I standards and whatnot). Then you'll see just how hard they scramble to make their systems safe. EDIT: And here we go. Remote hack of Tesla Model S. https://blog.kaspersky.com/tesla-remote-hack/13027/ https://blog.kaspersky.com/tesla-remote-hack/13027/ We're only at the very beginning of self-driving cars. What happens when there are 100 million self-driving cars on the road? Will their security be as terrible as it is on our PCs? People should get scared a lot faster about this stuff, before all car makers start writing their software and then refuse to write it from scratch again and just tack on to the poorly written systems new security features in the future as a response to such hacking.
- jacquesm 10y ago> Then you'll see just how hard they scramble to make their systems safe. Chances are they'd opt-out of the opportunity altogether and wait for someone else to take the heat.
- DSingularity 10y agoThose who opt out are those we don't want setting the bar in this domain. If it becomes acceptable for security and safety to be secondary to "getting the cars on the road ASAP and capturing as much of the market as possible" we -- as in the consumers -- will pay the price. I understand that some of the innovations and progress will only come when we get the cars on the road at scale, but we should still build a giant -- exactly how the comment or suggested -- to loom over the shoulders of these car companies.
- kalleboo 10y agoAnd then Volvo will take the whole market http://fortune.com/2015/10/07/volvo-liability-self-driving-cars/ http://fortune.com/2015/10/07/volvo-liability-self-driving-c...
- mulletbum 10y agoWhat other industries, that run mechanical equipment that can kill people, do you feel these are already applied in?
- paulmd 10y agoErm, apart from the punitive damages this is pretty much any product liability suit. If you make life-critical systems and your product fails you are getting sued out the wazoo - which is why many products will specifically state that they are not to be used in life-critical systems. Most mechanical equipment is not reviewed on a case-by-case basis by a regulatory industry; however aircraft incidents are. Aircraft products - meaning any product that is used on an aircraft, right down to the bolts attaching the overhead bins - are expected to be serviceable in "expected conditions of flight". If they are not, the manufacturer is subject to compensatory and even punitive damages [1]. Manufacturers can even be liable for their design decisions, unless the design decisions are specifically constrained by regulations. Obtaining product certification is a strong indicator that a product is compliant, but it may nevertheless expose the manufacturer to liability [2]. These are obviously difficult standards to meet, but they are appropriate when life-critical systems are in question. [1] http://www.dailyreportingsuite.com/products-liability/news/_20_million_compensatory_damages_award_against_aircraft_engine_blade_maker_upheld_28_million_punitive_damages_award_restored http://www.dailyreportingsuite.com/products-liability/news/_... [2] http://www.mondaq.com/unitedstates/x/429650/Aviation/FAA+Weighs+In+On+Preemption+In+Product+Liability http://www.mondaq.com/unitedstates/x/429650/Aviation/FAA+Wei... > In response to the third and final question, the FAA explains that because an aircraft type certificate embodies the FAA's determination that an aircraft, engine, or propeller design complies with federal standards, it can play an important role in determining whether a manufacturer breached a duty owed to the plaintiff. The type certificate does not create a per se bar to suit, but ordinary conflict preemption principles apply to the particular design-defect claim. According to the FAA, the type certificate will preempt a state tort suit only where compliance with both the certificate and the claims made in the tort suit "is a physical impossibility" or where the claims "stand as an obstacle to the accomplishment of the full purposes and objectives of Congress."7 > Where the FAA has expressly approved the specific design aspect that a plaintiff challenges, that claim would be preempted. On the other hand, where the FAA has left a particular design choice to a manufacturer's discretion, and no other conflict exists, the type certificate does not preempt a design-defect claim. In other words, where the FAA has not made an affirmative determination with respect to the challenged design, and has left that design aspect to the manufacturer's discretion, the claim would proceed by reference to the federal standards of care found in the Act and its implementing regulations. ... > The difficulty in applying the FAA's views on preemption to product claims lies in the fact that aircraft design specifications rarely require a specific design, but are instead couched in terms of performance or safety outcomes. For example, the certification standards for a stall warning system in a Part 23 aircraft requires "a clear and distinctive stall warning, with the flaps and landing gear in any normal position, in straight and turning flight" by a system "that will give clearly distinguishable indications under expected conditions of flight."9 A type certificate issued for a Part 23 aircraft would presumptively mean the FAA determined that the aircraft complied with these standards at the time the design was certified. However, would the type certificate preclude all product liability claims based on a defective stall warning system? What if the certification was actually wrong and the system did not comply with the standard when the FAA already said that it did? Can this type of claim actually be litigated or is it preempted? > Additionally, what if the claimed defect was that the stall warning system did not provide a warning when operated outside certification limits such as weight, speed, or center of gravity? Are these conditions outside the "expected conditions of flight" and therefore no federal standard exists? The FAA's Letter Brief to the Third Circuit in Sikkelee does not provide clear answers in the context of product liability litigation. Courts will continue to struggle with deciding these difficult issues in the future.
- dhagz 10y agoI'm astounded that it seems like these regulations are going to be sensible and promote the technology. It's a good thing that these are going into place, since autonomous vehicles should definitely not be legislated on a state-by-state basis.
- gumby 10y ago> I'm astounded that it seems like these regulations are going to be sensible... Was that hyperbole? I would say the majority of regulations (at least in OECD countries) are sensible, and many that are not are intended to be, are outdated, or are politicized.
- e40 10y agoMany people automatically assume a government can't make up sensible regulations. There are a lot of them in the US. It's a meme you hear all the time, especially in a POTUS election year.
- revscat 10y agoAnd is the fundamental belief of libertarians: that governments can do nothing right, either morally or pragmatically.
- travoc 10y agoThat's not accurate. They seem more concerned that every bit of power given to government to do something right will eventually be used to do something wrong.
- nommm-nommm 10y agoThat's exactly what the libertarians on HN post. I seriously hope it's a very vocal minority though.
- RHSeeger 10y ago
- etendue 10y agoN.B., this policy is mainly concerned with Highly Automated Vehicles (HAVs), which are defined as SAE Level 3 ("capable of monitoring the driving environment") and above. edit: as to SAE Level 2, it has this (and more) to say: > Furthermore, manufacturers and other entities should place significant emphasis on assessing the risk of driver complacency and misuse of Level 2 systems, and develop effective countermeasures to assist drivers in properly using the system as the manufacturer expects. Complacency has been defined as, “... [when an operator] over-relies on and excessively trusts the automation, and subsequently fails to exercise his or her vigilance and/or supervisory duties” (Parasuraman, 1997). also, > Manufacturers and other entities should assume that the technical distinction between the levels of automation (e.g., between Level 2 and Level 3) may not be clear to all users or to the general public.
- throwaway729 10y agoPages 14 - 30+ of the embedded report (pages 16 - of the PDF) are particularly interesting and promising, especially the portions about transparency around privacy and ethics issues. The report recommends that "Manufacturers and other entities should develop tests and verification methods...". Does anyone know whether verification here means software verification, or does it mean something else in this context? Edit: Just noticed that I got to the PDF via elicash's comment and not via the linked article. Here's a link to the PDF: https://www.transportation.gov/sites/dot.gov/files/docs/AV%20policy%20guidance%20PDF.pdf https://www.transportation.gov/sites/dot.gov/files/docs/AV%2...
- etendue 10y agoThe report makes reference to "Assessment of Safety Standards for Automotive Electronic Control Systems" by NHTSA, which itself reviews ISO 26262, MIL-STD-882E, DO-178C, the FMVSS, AUTOSAR, and MISRA C. In this context, they mean verification and validation in the systems engineering sense. Software would be included in that it is a part of the whole system.
- seren 10y agoI have a hard time understanding the current AV SW stack. On one hand, at the low level, sensor, motor control, etc you likely have traditional hard real time/MISRA C code, but on the higher layers you probably things like DNN, image recognition, which are much less deterministic. So I am not sure how do you reconcile these two worlds, and prove it is safe and always work in timely manner. It seems the only sound approach would be to validate the whole system on a real road.
- euroclydon 10y agoI'm surprised that self-driving technology is focusing on replacing the driver as an autonomous actor, processing visual and radar/lidar signals in order to know about its surroundings. I've always thought we'd get further faster by having automobiles also talk to other vehicles nearby, and design roads to support the computer driven vehicles. Two examples are: 1) If the vehicle is talking to the cars in front of it, it can know they are braking before it senses that visually. Also, the vehicles can speed up in a gridlock scenario more in unison, like a train. 2) On the interstate, markers in the pavement can be specifically designed for computer sensors rather than human eyeballs. Also, cars can draft together to save fuel.
- Conlectus 10y agoI think that concern over malicious communicators will at least slow this down. If not implemented correctly, it could give hackers a dangerous amount of control over traffic.
- leereeves 10y agoThe first self-driving cars will have to coexist with humans driving old cars without such communications.
- Matthias247 10y agoThe reason is that there are and for the foreseeable future will be things that are not networked. Lots of legacy cars, bicycles, pedestrians, trains. In some areas probably even animals on the road. If cars don't work in these environments they are pretty much useless.
- helthanatos 10y agoAnd when an old vehicle can't be driven on the road? I can't see laws to prevent old vehicles for at least 40 years... You can still not wear a seatbelt if your car was manufactured without one, so I would think anything complementing only autonomous vehicles would be met with public outcry.
- rjsw 10y agoCar manufacturers were discussing this kind of thing about 15 years ago. We were working on diagnostic and emissions checking standards but there was the expectation that we would be able to make use of secure network links to cars at some point in the future. The question at the time was which would come first. Would a requirement to do emissions testing under real-world conditions push the introduction of radio networks that could also be used for cars to talk to each other or would the road-train type applications be the initial use case.
- owyn 10y agoIt wasn't mentioned in the bloomberg article, but the 15 areas covered are: • Data Recording and Sharing • Privacy • System Safety • Vehicle Cybersecurity • Human Machine Interface • Crashworthiness • Consumer Education and Training • Registration and Certi cation • Post-Crash Behavior • Federal, State and Local Laws • Ethical Considerations • Operational Design Domain (operating in rain, etc) • Object and Event Detection and Response • Fall Back (Minimal Risk Condition) • Validation Methods Not sure if they're specifically ordered, but it seems positive that Data recording and Privacy are up at the top.
- 2bitencryption 10y agoThis seems suspiciously like government getting something right... with regards to a quickly-evolving new technology market... has this ever happened before?
- plandis 10y agoI'm cynically imagining that since it's a collection of big automakers, it is pretty easy for them to affect policy. It looks like consumers and automakers are both wanting driverless cars so putting any enevitable regulations quickly benefit both parties.
- yoav_hollander 10y agoLive streaming just started here: https://www.transportation.gov/AV https://www.transportation.gov/AV
- yoav_hollander 10y agoJust ended. And here is Obama's call for safe automated vehicles: https://www.post-gazette.com/opinion/Op-Ed/2016/09/19/Barack-Obama-Self-driving-yes-but-also-safe/stories/201609200027 https://www.post-gazette.com/opinion/Op-Ed/2016/09/19/Barack...
- Animats 10y agoFrom the regulations: "Fall back strategies should take into account that—despite laws and regulations to the contrary—human drivers may be inattentive, under the influence of alcohol or other substances, drowsy, or physically impaired in some other manner." NHTSA, which, after all, studies crashes, is being very realistic. Here's the "we're looking at you, Tesla" moment: "Guidance for Lower Levels of Automated Vehicle Systems" "Furthermore, manufacturers and other entities should place significant emphasis on assessing the risk of driver complacency and misuse of Level 2 systems, and develop effective countermeasures to assist drivers in properly using the system as the manufacturer expects. Complacency has been defined as, “... [when an operator] over- relies on and excessively trusts the automation, and subsequently fails to exercise his or her vigilance and/or supervisory duties” (Parasuraman, 1997). SAE Level 2 systems differ from HAV systems in that the driver is expected to remain continuously involved in the driving task, primarily to monitor appropriate operation of the system and to take over immediate control when necessary, with or without warning from the system. However, like HAV systems, SAE Level 2 systems perform sustained longitudinal and lateral control simultaneously within their intended design domain. Manufacturers and other entities should assume that the technical distinction between the levels of automation (e.g., between Level 2 and Level 3) may not be clear to all users or to the general public. And, systems’ expectations of drivers and those drivers’ actual understanding of the critical importance of their “supervisory” role may be materially different." There's more clarity here on levels of automation. For NHTSA Level 1 (typically auto-brake only) and 2 (auto-brake and lane keeping) vehicles, the driver is responsible, and the vehicle manufacturer is responsible for keeping the driver actively involved. For NHTSA Level 3 (Google's current state), 4 (auto driving under almost all conditions) and 5 (no manual controls at all), the vehicle manufacturer is responsible and the driver is not required to pay constant attention. NHTSA is making a big distinction between 1-2 and 3-5. This is a major policy decision. Automatic driving will not be reached incrementally. Either the vehicle enforces hands-on-wheel and paying attention, or the automation has to be good enough that the driver doesn't have to pay attention at all. There's a bright line now between manual and automatic. NHTSA gets it.
- Practicality 10y agoExcellent analysis. It makes me optimistic that we as a society are going to be able to work this out. We might not of course, but it's possible.
- pmyjavec 10y agoWhat is it about self-driving cars that has HN readers so incredibly excited? Sorry if it's a little off-topic. The reason I ask is there are plenty of other countries in the world where cars just aren't that important, let's take Netherlands for example. If you have automatic cars, society here is not just going to be that excited AFAIK. Public transport here is great and most people cycle everywhere, because it's fun, easy and good exercise. Not to mention a lot of people are employed as drivers. Same for many Asian countries where population density is high, people just don't have the money/room for cars. Scooters are the way to go because of traffic congestion. Besides, don't people enjoy driving? I don't own a car but when I get behind the wheel, it's a lot of fun. Will people really be able to handle the car doing the speed limit? I understand technologically it's pretty interesting, but we've had commercial airliners that fly themselves (mostly) for a long time, same for ships and drones and we don't marvel over those things all the time, though I agree they are great innovations. So apart from the tech what is the actual excitement about? - Concern for those who will lose their jobs. - Concern for others safety. - Privacy concerns. - Excitement about the safety benefits. - Economic opportunity. - Fundraising hype. - All of the above? As a Silicon Valley outsider sometimes I read HN and it feels like some context is missing. Sure it's going to change industries, but is this really good progress, necessary progress, or just the next thing we're told we need? I mean can a self-driving car really replace a delivery person yet, a person who can do things like leave packages with a neighbor and build relationships, trust etc? Sorry if this is a little off-topic, but I'm genuinely curious because it's hard to understand, to me as an outsider, it really looks like some kind of ride-sharing turf war hype battle more than anything else? I dare to say it, but it's the same for machine learning, a lot of it is fascinating, interesting, exiting tech, but how many product recommendations does one need? How good do my friend recommendations have to be? How smart does Siri need to be? Will a patient really feel better without being treated by a human? Are we really going to trust these things handling nuclear warheads? Maybe I live a strange life and have unusual views, but I just don't really see the need most of these things when so many problems could be solved using other means. Using this stuff to help people is great, but how much of this effort is actually being put towards that end? If I'm a little naive, apologies. I'm not having a go but these are just honest questions I often find myself asking when reading HN lately. Agreed this might not be the place to ask but I'm prepared to wear the down votes :)
- kragen 10y agoBrad Templeton, who's been working on self-driving cars for a few years now, analyzed this in http://ideas.4brad.com/critique-nhtsas-newly-released-recommendations-states-and-regulations http://ideas.4brad.com/critique-nhtsas-newly-released-recomm.... He says, "Broadly, this is very much the wrong direction... the progress of robocar development in the USA may be seriously negatively affected." This is a big deal.
- tstrimple 10y ago> I have written that having 50 sets of rules may not be that bad an idea because jurisdictional competition can allow legal innovation and having software load new parameters as you drive over a border is not that hard. I'm not sure I would put much weight behind what he has to say.
- mrfusion 10y agoSo what are the 15 bench marks?
- megablast 10y agoWoohoo, lets get the lawyers involved!
- nojvek 10y agoI'm really excited by US govt outlining what it would take to make a legal self driving car. I'm also hoping that one of the options is to upgrade an old car to a self driving car with an open source kit that you can buy and install it via a certified mechanic. I think that would be an interesting future I'd like to be part of.
- KKKKkkkk1 10y agoIt's nice that these regulations sound sensitive and not heavy handed. I'm wondering whether they are needed at all though. They've been formulated in heavy collaboration with the market leaders Uber, Google etc. Is there a risk they will help shut out upstarts, similarly to how the FDA makes drug development astronomically expensive?
- nitin_flanker 10y agoI am commenting here as a token of appreciation for Etendue and also so that I can bookmark this awesome share by him. Thanks.
- yoav_hollander 10y agoFinally posted my initial comments on the verification implications of all this here: https://blog.foretellix.com/2016/09/21/verification-implications-of-the-new-us-av-policy/ https://blog.foretellix.com/2016/09/21/verification-implicat...