This paper presents an overview of Waymo's approach to building a reliable case for safety - a novel and thorough blueprint for use by any company building fully autonomous driving systems. A safety case for fully autonomous operations is a formal way to explain how a company determines that an AV system is safe enough to be deployed on public roads without a human driver, and it includes evidence to support that determination. It involves an explanation of the system, the methodologies used to develop it, the metrics used to validate it and the actual results of validation tests. Yet, in order to develop a worthwhile safety case, it is first important to understand what makes one credible and well crafted, and align on evaluation criteria. This paper helps enabling such alignment by providing foundational thinking into not only how a system is determined to be ready for deployment but also into justifying that the set of acceptance criteria employed in such determination is sufficient and that their evaluation (and associated methods) is credible. The publication is structured around three complementary perspectives on safety that build upon content published by Waymo since 2020: a layered approach to safety; a dynamic approach to safety; and a credible approach to safety. The proposed approach is methodology-agnostic, so that anyone in the space could employ portions or all of it.
翻译:本文概述了 Waymo 构建可靠安全案例的方法——这是一套新颖且详尽的蓝图,适用于任何开发全自动驾驶系统的公司。全自动驾驶运营的安全案例是一种正式方式,用于解释公司如何判定自动驾驶系统能够在没有人类驾驶员的情况下安全地部署于公共道路,并包含支持该判定的证据。它涉及对系统的说明、开发系统所采用的方法论、用于验证系统的指标以及验证测试的实际结果。然而,要构建一个有价值的安全案例,首先必须理解是什么让一个安全案例可信且构思精良,并在评估标准上达成共识。本文有助于促成这种共识,其提供的基理性思考不仅涉及如何判定系统已准备好进行部署,还涉及如何论证在此类判定中所使用的一组验收标准是充分的,并且这些标准(及相关方法)的评估是可信的。本文围绕三个互补的安全视角展开,这些视角建立在 Waymo 自 2020 年以来发布的内容基础之上:分层安全方法、动态安全方法以及可信安全方法。所提出的方法是方法论无关的,因此该领域的任何人都可以采用其中的部分或全部内容。