Safety standards for ML-based autonomous driving specify the kind of evidence an assurance case must contain (directed cause-and-effect chains, quantified interventional effects, named root-cause variables), yet the XAI literature is organised by output type and technique family (saliency maps, feature attribution, counterfactuals, causal graphs, language traces). SHAP, the most-recommended ADS XAI method, returns a ranked feature list that no implementation effort can convert into a directed chain (Fig.1). We name this mismatch the evidence-type gap. From AMLAS, ISO 26262, ISO21448, ISO/PAS 8800 we derive 19 testable evidentiary criteria across 7 lifecycle stages with representative clause-cited derivations and score six XAI method classes structurally. Causal XAI emerges as structurally required to satisfy the derived criteria at three stages: hazard identification (+62% rubric gap), incident investigation (+50%), and data management (+50%); the verdict set is stable across thresholds T in (0%, 50%]$ and survives a worst-case single-cell flip down to T = 25%. At the remaining four stages, correlational or language-based methods are comparable or sufficient. The rubric identifies structural admissibility (necessary but not sufficient for compliance): an admissible method's specific output content may still be wrong, and validating that fidelity (the edges a fitted SCM produces, the cause a trace names) is the open assurance challenge. A single-VLA proof of concept on 1,996 real-world driving clips (79,840 rows, ten splits) is consistent with each method's observed output type matching its rubric prediction. XAI method selection for ADS safety assurance should be driven by lifecycle-stage evidence demand, not by method popularity.
翻译:针对基于机器学习的自动驾驶安全标准规定了保证案例必须包含的证据类型(定向因果链、量化干预效应、命名根因变量),而可解释人工智能文献体系却是按输出类型和技术类别(显著性图、特征归因、反事实、因果图、语言追踪)组织的。SHAP作为最受推荐的自动驾驶系统可解释人工智能方法,返回的排序特征列表无法通过任何实现手段转化为定向链(图1)。我们将这一错位称为"证据类型鸿沟"。从AMLAS、ISO 26262、ISO 21448、ISO/PAS 8800标准中,我们推导出覆盖7个生命周期阶段的19项可测试证据标准,并附有代表性条款引证推导过程,对6类可解释人工智能方法进行结构性评分。因果可解释人工智能在三个阶段的推导标准满足中显现结构性需求:危害识别阶段(+62%评估缺口)、事故调查阶段(+50%)、数据管理阶段(+50%);评估结论在阈值区间T∈(0%,50%]保持稳定,并在最坏情况单单元翻转条件下可维持至T=25%。在其余四个阶段,相关性方法或语言类方法具有可比性或充分性。该评估框架识别了结构性准入资格(合规的必要非充分条件):合规方法的具体输出内容仍可能错误,验证其保真度(拟合结构因果模型生成的边、追踪指称的因果关系)是当前开放性保证挑战。基于单一视觉语言模型的概念验证,在1996个真实驾驶视频片段(79840行数据,十重划分)上的实验结果,与每种方法的观测输出类型匹配其评估框架预测的结果一致。用于自动驾驶系统安全保证的可解释人工智能方法选择,应依据生命周期阶段的证据需求,而非方法流行度。