Detection of Feature Interactions in Automotive Active Safety Features
Bibliographic record
Abstract
With the introduction of software into cars, many \nfunctions are now realized with reduced cost, \nweight and energy. The development of these software \nsystems is done in a distributed manner independently \nby suppliers, following the traditional approach of \nthe automotive industry, while the car maker takes \ncare of the integration. However, the integration can \nlead to unexpected and unintended interactions among \nsoftware systems, a phenomena regarded as feature \ninteraction. This dissertation addresses the problem \nof the automatic detection of feature interactions \nfor automotive active safety features. \nActive safety features control the vehicle's motion \ncontrol systems independently from the driver's request, \nwith the intention of increasing passengers' safety \n(e.g., by applying hard braking in the case of an \nidentified imminent collision), but their unintended \ninteractions could instead endanger the passengers \n(e.g., simultaneous throttle increase and sharp narrow \nsteering, causing the vehicle to roll over). \nMy method decomposes the problem into three parts: \n(I) creation of a definition of feature interactions \nbased on the set of actuators and domain expert knowledge; \n(II) translation of automotive active safety features \ndesigned using a subset of Matlab's Stateflow into the \ninput language of the model checker SMV; \n(III) analysis using model checking at design time to \ndetect a representation of all feature interactions \nbased on partitioning the counterexamples into \nequivalence classes. \nThe key novel characteristic of my work is exploiting \ndomain-specific information about the feature interaction \nproblem and the structure of the model to produce a \nmethod that finds a representation of all different \nfeature interactions for automotive active safety \nfeatures at design time. \n \n \nMy method is validated by a case study with the set \nof non-proprietary automotive feature design models \nI created. The method generates a set of counterexamples \nthat represent the whole set of feature interactions in \nthe case study.By showing only a set of representative \nfeature interaction cases, the information is concise \nand useful for feature designers. Moreover, by generating \nthese results from feature models designed in Matlab's \nStateflow translated into SMV models, the feature \ndesigners can trace the counterexamples generated by SMV \nand understand the results in terms of the Stateflow \nmodel. I believe that my results and techniques will \nhave relevance to the solution of the feature \ninteraction problem in other cyber-physical systems, \nand have a direct impact in assessing the safety of \nautomotive systems.
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame machine prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. The Gemma side is a direct model label for every work in the frame, read from the title-only record. The Codex side is a classifier learned from the 10,348 direct Codex labels and calibrated to design-weighted sample rates; fields without enough sample support carry no Codex call. Candidate is the union of the two sides; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels.
Distilled classifier scores by category (both heads)
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.000 | 0.002 |
| Meta-epidemiology (narrow) | 0.000 | 0.000 |
| Meta-epidemiology (broad) | 0.000 | 0.000 |
| Bibliometrics | 0.003 | 0.001 |
| Science and technology studies | 0.000 | 0.000 |
| Scholarly communication | 0.001 | 0.001 |
| Open science | 0.001 | 0.001 |
| Research integrity | 0.001 | 0.000 |
| Insufficient payload (model declined to judge) | 0.002 | 0.001 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; a candidate call from one source (direct Gemma or distilled Codex), not a consensus.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".