OutRes Outlier Resilience
Applied research · Michigan

Test driving cannot prove safety.

Automated driving fails on the rare mile, and no fleet can drive enough of them. The evidence has to come before the road, for the conditions nobody sampled.

OutRes (Outlier Resilience LLC) is an early-stage applied research venture in Michigan. We work with teams that must validate an automated driving stack they did not write.

01The arithmetic doesn't work

Human drivers average 1.09 fatalities per 100 million miles. RAND calculated what proving an automated vehicle beats that would take.

275M
Failure-free miles, at 95% confidence.
12.5
Years for a 100-vehicle fleet driving 24/7.
8.8B
Miles to pin the rate within 20%. About 400 years.

“It is not possible to test-drive autonomous vehicles to demonstrate their safety to any plausible standard, even if we assume perfect performance.”

Kalra & Paddock, Driving to Safety, RAND, 2016

02The standards name the gap, not the answer

ISO 26262 covers hazards from things breaking. But a system can cause harm with every component working as designed. The design was insufficient for the situation.

ISO 21448 (SOTIF) covers that: risk from functional insufficiencies, no failure required. It asks you to shrink the set of unknown-unsafe scenarios. It does not tell you how to know how much you have eliminated.

03The tail is not exotic. It's Tuesday in February.

The conditions that degrade a perception stack are mundane, frequent and regional. A test program assembled somewhere sunny will under-weight them.

Degraded optics
Low sun, wet glare, spray, a salted lens. The image still arrives, degraded.
Vanishing road structure
Markings under snow or wear. Models that lean on paint inherit a dependency the road doesn't keep.
Shifted statistics
A model fitted to clear conditions meets one it wasn't trained on. The failure is quiet.
Compounding conditions
Dusk, precipitation and a worn surface at once. One-factor-at-a-time matrices miss the combinations.

04Finding out late is the expensive way

Early, a weakness is a design decision. In hardware-in-the-loop or on-road validation it is a schedule event. So the aim is to move the evidence earlier, onto conditions you have not sampled.

05Research

Claims here should arrive as papers with methods attached. Work in preparation will be posted here.

IEEE ITSCFormal verification of end-to-end steering under adverse weather perturbationIn preparation
SAE WCXSafety standards and assurance for automated driving in winter conditionsIn preparation

06Compare notes

If you validate an automated driving stack, your own or a supplier's, we'd like to hear where your process runs out of evidence. We're not selling anything yet.

[email protected]