Perception System Safety
Engineer the subsystem the planner has to trust: requirements derived from hazards, a pipeline whose failures wear disguises, a contract that states its negative promises, and evidence that survives a skeptic.
- Chapters
- 14
- Chapters
- Pipeline stages
- 8
- Pipeline stages
- Monitor classes
- 5
- Monitor classes
- Assurance perspectives
- 4
- Assurance perspectives
- 01What Perception Owes the Planner
- 02Four Ways of Seeing
- 03From Vehicle Hazards to Perception Requirements
- 04Four Standards Perspectives, One Pipeline
- 05The Pipeline: From Photons to a Published World
Why it pays for itself
Requirements you can defend, not benchmark scores
Follow the derivation from a hazardous event at the bumper through braking physics to measurable perception requirements with classes, ranges, latencies, conditions and separate budgets for misses and false alarms.
Know which standard owes which evidence
Eight concrete perception failures routed across ISO 26262, ISO 21448, ISO/PAS 8800 and ISO/SAE 21434, so a fog case, a memory bit flip and a crafted sign each produce the right kind of evidence instead of the same argument three times.
An architecture argument, not a sensor shopping list
Fusion topologies compared on fault reachability, an environment model specified as a contract with negative promises, and a monitoring portfolio whose blind spots are named and carried into the residual-risk statement.
What you’ll be able to do
Derive Perception Requirements Instead of Inheriting Them
Trace vehicle hazards and braking physics down to measurable subsystem requirements with explicit classes, ranges, latencies, conditions and error budgets, and stop treating a benchmark score as a requirement.
Route Every Failure to the Right Assurance Perspective
Separate ISO 26262 malfunctions from ISO 21448 performance insufficiencies, ISO/PAS 8800 AI concerns and ISO/SAE 21434 threats, and recognise the cases where several perspectives apply at once.
Choose a Fusion Architecture With Your Eyes Open
Compare object-level, low-level and hybrid wirings on fault reachability, observability and what remains checkable, and identify the double counting and covariance inconsistencies that inflate confidence.
Specify the Environment Model as a Contract
Write semantics, units, frames, timing, uncertainty meaning and negative promises for every field, and treat misreadings such as absent-versus-unknown collapse as a failure class rather than a bug tracker entry.
Build a Monitoring Portfolio and Declare Its Blind Spots
Map failure modes against monitor classes with firing latencies, decide which detections can support a safety mechanism, and name the failures that stay silently plausible instead of hiding them.
Assemble Perception Evidence That Survives Review
Combine open-loop and closed-loop evidence, size rare-event claims honestly, report per-slice results, and structure the whole thing into a safety-case fragment whose residual risk is stated rather than implied.
Chapter by chapter
- 01
What Perception Owes the Planner
The uncomfortable starting fact: there is the physical world and there is the published environment model, and the planner lives entirely in the second one. Where the subsystem boundary sits, why a benchmark score is not a safety requirement, and the highway reference function that every later chapter traces back to.
- Two worlds, one interface
- Subsystem boundary
- Benchmarks versus requirements
- 02
Four Ways of Seeing
Camera, radar, lidar and ultrasonic as four pieces of physics with four different ways of being wrong. Angular sampling against lane width, geometric support that thins with range, and a modality by condition matrix that shows which weather hurts which sensor.
- Modality physics
- Angular resolution
- Condition matrix
- Limits of complementarity
- 03
From Vehicle Hazards to Perception Requirements
The derivation chain walked end to end: hazardous events at the vehicle, safety goals, braking physics, a required perception range, then measurable subsystem requirements. Why a missed object and a phantom object are separate hazardous-event paths with separate budgets that must never be traded silently.
- HARA to safety goal
- Required perception range
- Separate miss and false-alarm budgets
- 04
Four Standards Perspectives, One Pipeline
Route a perception failure before you fix it. How ISO 26262 malfunctions, ISO 21448 performance insufficiencies, ISO/PAS 8800 AI concerns and ISO/SAE 21434 threats apply to the same pipeline, where their scopes overlap, and why the routing decides which evidence you owe.
- Four overlapping scopes
- Routing worked cases
- Evidence follows the routing
- 05
The Pipeline: From Photons to a Published World
Eight processing layers between a photon and the model the planner reads, each holding state and each failing in a distinctive downstream disguise. The confirmation logic that dominates the latency budget, and why an object list that stays silent about unobserved space is a design error, not a shortcut.
- Eight stages and payloads
- Failures wear disguises
- The confirmation trade
- Unknown is not free
- 06
Fusion Architectures and What They Do to the Safety Argument
Object-level, low-level and hybrid fusion compared on what they cost the safety argument rather than on accuracy. How far one sensor fault travels in each wiring, the failure modes fusion invents including double counting, and why overconfident covariance quietly shrinks a planner safety margin.
- Three topologies
- Fault reachability
- Double counting
- Diversity you can defend
- 07
The Environment Model Is a Contract
The handover from perception to planning treated as a specified interface rather than a message with fields: semantics, units, frames, timing, and a statement of what each value may be relied upon for. The negative promises matter most, and contract violations form a failure class of their own.
- Field-by-field semantics
- Standardized versus project interfaces
- Negative promises
- Per-sector range claims
- 08
Uncertainty a Planner Can Act On
Why a ranking score and a calibrated probability are different promises, and what happens when a consumer mistakes one for the other. Existence, state and class uncertainty each drive a different planner lever, and noise that averages away is not the same as ignorance that does not.
- Scores versus probabilities
- Calibration diagnostics
- Three uncertainties, three reactions
- Aleatoric versus epistemic
- 09
Time, Frames and Calibration
Every measurement is a value, a coordinate frame and a time, and corrupting any of the three places a perfectly correct value in the wrong world. Timestamp skew, extrinsic drift that grows with range, the transform chain and its owners, and freshness as a field the consumer must check.
- Coherent, not random, errors
- Time skew
- Drift with range
- Freshness as a promise
- 10
Degradation Without Failure
Six ways to see less with nothing broken: blockage, contamination, weather, glare, mutual interference and simply leaving the validated envelope. Why the stack must estimate and publish its own reach, and how availability pressure on suppression thresholds pushes one safety budget against another.
- Degradation without fault codes
- Estimating your own reach
- The suppression see-saw
- Edge of the validated world
- 11
Monitors, Diversity and the Simple Channel That Says No
Perception cannot self-certify, because the estimate and the estimate of its quality fail together. Five monitor classes with their characteristic blindness and speed, a coverage matrix that doubles as a specification tool, the doer and checker pattern, and the silent set nobody catches in time.
- Five monitor classes
- Coverage matrix
- Doer and checker
- Naming the silent set
- 12
Degraded Modes and the Perception Bench
Between driving at full speed while blind and braking for every doubt sits an engineered ladder of partial function, entered on declared capability and health rather than on fault codes. Asymmetric transitions, hysteresis and debounce, and a bench that wires the whole page together so failures can be injected against it.
- Health-driven mode ladder
- Hysteresis and debounce
- Injecting failures on a bench
- 13
Building the Perception V&V Evidence
What each layer of evidence can honestly claim, from open-loop replay through re-simulation and scenario exploration to road driving. The arithmetic of rare events, why slice metrics must come before averages, and how field monitoring keeps the argument current after start of production.
- Open loop versus closed loop
- Rare-event arithmetic
- Slices before averages
- Field monitoring loop
- 14
A Worked Safety-Case Fragment
One perception requirement argued end to end in goal-structuring form, with context, strategy and solution nodes drawn from the analyses the earlier chapters built. The residual-risk statement written out loud, why a safety case goes stale rather than wrong, and an honest account of what the fragment does not show.
- Argument assembled from evidence
- Residual risk stated openly
- Change impact and staleness
Who this guide is for
- Perception and sensor-fusion engineers moving from accuracy metrics to safety requirements
- Safety engineers who must review a perception subsystem they did not build
- System architects deciding sensor sets, fusion topology and degraded-mode strategy
- Verification and validation leads planning perception evidence campaigns
- Assessors and reviewers reading a perception safety case for the first time
Frequently Asked Questions
Common questions about Perception System Safety
Start the course today
A free account unlocks one full concept guide, 3 work product templates, 1 guided process, the Markov simulator, and 5 practice exams per month. The Pro and Expert plans unlock more of the 77-guide library. No credit card required.