Learning Enabled Components (LEC) have greatly assisted cyber-physical systems in achieving higher levels of autonomy. However, LEC's susceptibility to dynamic and uncertain operating conditions is a critical challenge for the safety of these systems. Redundant controller architectures have been widely adopted for safety assurance in such contexts. These architectures augment LEC "performant" controllers that are difficult to verify with "safety" controllers and the decision logic to switch between them. While these architectures ensure safety, we point out two limitations. First, they are trained offline to learn a conservative policy of always selecting a controller that maintains the system's safety, which limits the system's adaptability to dynamic and non-stationary environments. Second, they do not support reverse switching from the safety controller to the performant controller, even when the threat to safety is no longer present. To address these limitations, we propose a dynamic simplex strategy with an online controller switching logic that allows two-way switching. We consider switching as a sequential decision-making problem and model it as a semi-Markov decision process. We leverage a combination of a myopic selector using surrogate models (for the forward switch) and a non-myopic planner (for the reverse switch) to balance safety and performance. We evaluate this approach using an autonomous vehicle case study in the CARLA simulator using different driving conditions, locations, and component failures. We show that the proposed approach results in fewer collisions and higher performance than state-of-the-art alternatives.
翻译:学习使能组件(LEC)显著提升了信息物理系统的自主化水平。然而,LEC对动态与不确定运行条件的敏感性构成其安全性的关键挑战。为此,冗余控制器架构被广泛采用以保障系统安全。此类架构将难以验证的LEC"高性能"控制器与"安全"控制器及两者切换决策逻辑相结合。尽管这类架构能确保安全性,但我们指出其存在两点局限:第一,离线训练策略始终保守地选择能维持系统安全的控制器,限制了系统对动态非平稳环境的适应性;第二,即使安全威胁消失,系统也无法从安全控制器反向切换至高性能控制器。为突破这些局限,我们提出一种支持双向切换的动态单纯形策略,其在线控制器切换逻辑可双向操作。我们将切换问题建模为序列决策问题,并构建半马尔可夫决策过程模型。通过结合基于代理模型的近视选择器(前向切换)与非近视规划器(反向切换),实现安全与性能的平衡。在CARLA仿真器中基于不同驾驶场景、地理位置及组件故障的自动驾驶案例验证表明,该方法相较于现有最优方案能显著降低碰撞率并提升性能。