Computer-implemented method and system for generating test data for computer-implemented automated driving functions
A computer-implemented method for generating test data for computer-implemented automated driving functions. The method includes: provision of a computer-implemented automated driving function in the form of a software component; specification of an environment model with boundary conditions that limit the state space of the software component; provision of a model checker representation of the software component that is limited by the environment model; specification of a formal requirement as an input for a model checking method; and application of the model checking method to the model checker representation to analyze the software component with respect to compliance with the specified formal requirement. If the specified formal requirement is not complied with, the model checking method provides the states and state transitions of the software component that contribute to non-compliance as edge case parameters. Based on the edge case parameters, test data are then generated.
1 . A computer-implemented method for generating test data for computer-implemented automated driving functions, the method comprising performing, with a processor system that includes at least one processor, the following steps:
a) converting, by the processor system, a computer-implemented automated driving function in the form of a software component into a finite state machine (FSM) that defines states of the software component and state transitions between the states and that is constrained by a given environment model that specifies boundary conditions that limit states and state transitions of the FSM that can be traversed;
b) performing, by the processor system, model checking by automatically traversing in a systematic manner all of the states and state transitions of the FSM, as constrained by the limit, at least until at least one of one or more specified formal requirements is identified to be violated;
c) checking, by the processor system and during the traversing, whether any of the one or more specified formal requirements is violated in any of the traversed states or state transitions;
d) in response to identifying that one of the formal requirements is violated:
(I) recording, by the processor system, a counterexample trace includes a sequence of the states and state transitions that lead to the violation, the counterexample trace forming edge case parameters; and
(II) modifying, by the processor system, the counterexample trace to generate a test simulation in a simulation-scenario format that is executable in a driving simulator and that instantiates the edge case parameters as a simulation characterizing a set of environment and vehicle conditions; and
e) executing, by the processor system, the test simulation in the driving simulator to test the software component or of a different component of an automated driving system.
2 . The method according to claim 1 , wherein, when the one or more specified formal requirements are complied with, at least one of the formal requirements is responsively modified in a defined manner and the checking is performed again to the FSM of the software component.
3 . The method according to claim 1 , further comprising:
in response to a first iteration of step (b) and step (c) in which none of the one or more specified formal requirements is identified to be violated, automatically modifying, by the processor system, the obtained environment model in a defined manner to generate a modified environment model, and repeating steps (b) and (c) using the modified environment model to constrain traversal of the states and state transitions of the FSM.
4 . The method according to claim 3 , wherein the environment model is specified in the form of an environment model program code and environment parameters, and wherein the environment model is modified by modifying the environment program code and/or the environment parameters in the defined manner.
5 . A computer-implemented system for generating test data for computer-implemented automated driving functions, the system comprising a processor system that includes at least one processor and that is programmed to:
a) convert a computer-implemented automated driving function in the form of a software component into a finite state machine (FSM) that defines states of the software component and state transitions between the states and that is constrained by a given environment model that specifies boundary conditions that limit states and state transitions of the FSM that can be traversed;
b) perform model checking by automatically traversing in a systematic manner all of the states and state transitions of the FSM, as constrained by the limit, at least until at least one of one or more specified formal requirements is identified to be violated;
c) check, during the traversing, whether any of the one or more specified formal requirements is violated in any of the traversed states or state transitions;
d) in response to identifying that one of the formal requirements is violated:
(I) record a counterexample trace that includes a sequence of the states and state transitions that lead to the violation, the counterexample trace forming edge case parameters; and
(II) modify the counterexample trace to generate a test simulation in a simulation-scenario format that is executable in a driving simulator and that instantiates the edge case parameters as a simulation characterizing a set of environment and vehicle conditions; and
e) execute the test simulation in the driving simulator to test the software component or a different component of an automated driving system.