ConceptioArchivearXiv CS
arXiv CSopen access

Re-imagining ISO 26262 in the Age of Autonomous Vehicles: Enhancing Controllability through Transferability and Predictability

Unknown · 2026 · arxiv_cs
arXiv CS · Papers · License: Open Access · 2026
Open Source ↗Direct PDF ↓
artificialintelligenceknowledgerepresentationreasoning
artificial intelligence, reasoning, knowledge representation

Re-imagining ISO 26262 in the Age of Autonomous Vehicles Enhancing Controllability through Transferability and Predictability

arXiv:2606.07437v1 [cs.RO] 5 Jun 2026

Chaitanya Shinde1 , Hadi Hajieghrary2 , Paul Schmitt3 , Adam Shoemaker4 , Bodo Seifert5 , Steve Kenner6 Abstract— The ISO 26262 standard defines functional safety for road vehicles through risk assessments based on Severity, Exposure, and Controllability, grounded in a human-driven vehicle paradigm. In the context of autonomous vehicles (AVs), the absence of a human driver necessitates revisiting these principles. This paper decomposes the Controllability placeholder into two auditable evidence dimensions of ISO 26262 by introducing two measurable sub-concepts: Transferability and Predictability. Transferability extends Controllability to capture AV systems’ ability to hand off control to dedicated fallback safety mechanisms, while Predictability captures how easily external agents can anticipate AV behavior. Predictability is formally defined from human-robot interaction-inspired principles, and a mathematical framework is provided to quantify. A designed-versus-achievable gap ∆T is introduced to distinguish architectural fallback claims from scene-conditioned achievable fallback capability. The proposed metrics align with ISO 26262 and ISO/PAS 21448 (SOTIF), rendering fallback and interaction claims falsifiable and traceable across ODD slices. These dimensions complement rather than replace existing standards, and the enhancements preserve ISO 26262’s structure while extending its applicability to the driverless automated systems levels, SAE L4 and L5.

(FTTI). Predictability quantifies how accurately external road users can anticipate an AV’s behavior, thereby shifting part of the safety focus from the absent driver to surrounding humans—pedestrians, cyclists, and other drivers—whose understanding of the AV’s intent directly affects overall road safety. Together, these metrics expand Controllability into both the system-level and human-observer dimensions. ISO 26262 [1] primarily addresses malfunction-based functional safety, while ISO 21448:2022 (SOTIF) [2] considers risks arising from intended functionality. Within this combined framework, Transferability and Predictability serve as SOTIF-aligned key performance indicators that complement—not replace—existing processes. They provide measurable evidence of fallback performance and safety in external interactions, supporting integration into established functional safety lifecycles. Contributions. This paper makes three principal contributions to the methodology for assessing autonomous-vehicle safety:

I. I NTRODUCTION The ISO 26262 standard establishes a comprehensive framework for ensuring the functional safety of humanoperated road vehicles [1]. Its safety concept is fundamentally driver-centric: the standard repeatedly assumes the presence of a human who can mitigate hazards through corrective action; however, autonomous vehicles (AVs) operating at SAE Levels 4 and 5 challenge this foundational assumption. With no human driver available to intervene, responsibility for hazard mitigation and situational control shifts entirely to the vehicle’s system architecture. Consequently, Controllability, a core pillar of ISO 26262, requires systematic reinterpretation and augmentation. The analytical constructs introduced in this paper are proposed as supplemental tools for consideration by standards bodies; they are not intended as normative replacements for existing ISO 26262 processes. This paper introduces two complementary constructs that extend rather than replace Controllability. Transferability quantifies a system’s ability to safely transfer control to fallback mechanisms within the Fault-Tolerant Time Interval

1) We formalize Transferability by evaluating Minimal Risk Maneuver performance with respect to FaultTolerant Time Intervals, thereby extending the Controllability construct for driverless contexts. 2) We establish Predictability as a quantifiable dimension of external road-user safety, capturing both conformance to expected motion patterns and clarity of intent communication. 3) We propose acceptance criteria and validation methodologies, including fault-injection testing for Transferability and human-observer studies for Predictability, enabling their adoption as falsifiable metrics within ISO 26262 and SOTIF safety-lifecycle processes.

1 Chaitanya Shinde [email protected], 2 Hadi Hajieghrary [email protected], and 6 Steve Kenner [email protected] are with Torc Robotics, Inc., an independent subsidiary of Daimler Truck AG. 3 Paul Schmitt [email protected] is with Reynolds & Moore. 4 Adam Shoemaker [email protected]. 5 Bodo Seifert [email protected] is with Critical Systems Analysis, LLC.

II. R ELATED W ORKS This section positions the proposed extensions to ISO 26262 within the broader context of automotive safety standards, human-robot interaction (HRI) research, and empirical human-driver data. Together, these domains motivate the expansion of Controllability from a driver-centric construct to one encompassing both system fallback capability and external behavioral Predictability. A. Controllability in ISO 26262 ISO 26262 [1] defines Controllability as ”the ability to avoid a specified harm or damage through the timely reactions of the driver.” Within the standard’s risk frameworkSeverity (S), Exposure (E), and Controllability (C)-this parameter estimates the probability that a driver can mitigate a hazardous event. Four classes (C0-C3) reflect decreasing

ease of control, from ”generally controllable” to ”difficult or uncontrollable.” These definitions presuppose an attentive driver and therefore cannot apply directly to SAE L4-L5 systems. However, the probabilistic notion of avoiding harm remains valid if the scope of control is broadened: the driver’s reaction becomes the system’s fallback capability (Transferability), and the driver’s understanding of the vehicle’s intent becomes external observers’ ability to anticipate its behavior (Predictability). B. Related Safety Standards UL 4600 [3] provides a non-prescriptive assurance framework for autonomous products, emphasizing evidence-based safety arguments covering fallback performance and transparency. Transferability and Predictability align with its principles of behavioral explainability and safety-case completeness. The broader call for evidence-based, ODD-conditioned safety arguments has been mentioned in [4] as an interdisciplinary challenge spanning controls, machine learning, human factors, and assurance, and reinforced through the ODD-coverage analyses of ISO/TR [5]; the per-ODDslice reporting discipline used throughout this paper inherits directly from that line of work. ISO 21448:2022 (SOTIF) [2] extends safety analysis to hazards arising from correct but inadequate function. It addresses performance limitations in perception and decisionmaking that can yield unsafe behavior without faults. Predictability directly supports SOTIF by quantifying behavioral adequacy-how well other road users can interpret and anticipate vehicle motion-while Transferability captures the system’s robustness in known unsafe scenarios. Parallel autonomy architectures further demonstrate how supervisory safety layers can assume responsibility for maintaining minimal-risk system behavior when primary autonomy functions fail [6]. IEEE Std 2846-2022 [7] formalizes assumptions used in safety-related decision-making models for automated driving systems, including the reasonably foreseeable behaviors of other road users. The four-channel Predictability monitor of Section IV-C consumes this assumption layer from the AVas-observed side: whereas IEEE 2846 specifies what other agents may reasonably do, our framework specifies what affected road users may reasonably anticipate from the AV. Salay and Czarnecki [8] surveyed the gaps that arise when ISO 26262 process requirements are applied to systems containing machine-learned components, motivating the explicit calibration declarations and out-of-distribution rejection rules required of pref and p(g | ξ0:t , c, a) in Section IV-B. ISO 34502:2022 [4] defines a scenario-based safetyevaluation framework directly relevant to ODD-sliced evaluation of Transferability and Predictability evidence (Sections III and ??). ISO/TR 4804:2020 [5] provides safetyand cybersecurity-by-design guidance for SAE Level 3–4 automated driving systems, into which the proposed evidence channels can be embedded as concrete work products. Together, this set of standards forms the assurance landscape into which our framework slots: ISO 26262 for malfunctionbased functional safety, ISO 21448 for SOTIF, IEEE 2846

for assumption-layer formalization, ISO 34502 for scenariobased evaluation, ISO/TR 4804 for ADS-specific V&V, and UL 4600 for the overarching safety case. C. Predictability in Human-Robot Interaction HRI research defines Predictability as the extent to which humans can anticipate a robot’s motion, with studies showing that trust and coordination improve when trajectories conform to expected motion patterns [9]–[15]. Predictability is typically evaluated through observer experiments and quantified using trajectory-dissimilarity metrics or forecasterror statistics. These measures quantify how closely an autonomous system’s motion aligns with human expectations of smooth, rational, and context-appropriate behavior. Applied to driving, Predictability reflects how interpretable a vehicle’s motion is to surrounding road users-a prerequisite for reasonably safe, coordinated interaction. D. Human-Driver Datasets Large-scale naturalistic-driving datasets such as SAE J2944 [16] and NHTSA’s SHRP 2 [17] provide statistical baselines for normal driving behavior across diverse scenarios. Comparing autonomous-vehicle trajectories against these human distributions enables a quantitative assessment of Predictability through measures such as L2 trajectory norms or Kullback-Leibler divergence. Motion consistent with human norms indicates high Predictability; deviations suggest behaviors that may reduce external users’ confidence or increase the risk of interaction. III. I NTRODUCING T RANSFERABILITY This section introduces Transferability as a system-level enhancement to Controllability for autonomous vehicle (AV) safety assessment, addressing the practical limits of humancentric Controllability metrics for SAE J3016 Level 4–5 systems. Rather than replacing Controllability, Transferability extends it to capture an AV’s intrinsic capability to manage hazardous events without human intervention. A. Limitations of Traditional Controllability ISO 26262-1:2018 Clause 3.25 defines Controllability as the driver’s ability to avoid harm through timely reactions. ISO 26262-3:2018 Table 3 classifies Controllability (C0– C3) by the probability that a human driver can successfully intervene. For SAE Levels 4–5, this metric cannot be applied directly, as no human operator participates in the dynamic driving task. However, the conceptual foundation remains valid - avoiding harm within a bounded time frame. Transferability preserves this logic by reframing it from human action to system capability. B. Transferability: A System-Capability-Based Extension To address this fundamental incompatibility, we introduce Transferability as a theoretically grounded replacement construct for autonomous vehicle safety assessment: Transferability: The capability of an autonomous vehicle to execute a reasonably safe and timely transition from the primary autonomy function to a dedicated fallback mechanism, thereby achieving a minimal-risk condition or safe state within the Fault Tolerant Time Interval (FTTI) and without

introducing additional hazards to occupants or external road users. This definition enhances Controllability by internalizing the function of hazard mitigation. While human Controllability quantifies the probability of successful reaction from the driver, Transferability quantifies the probability of successful fallback execution by the system. The same probabilistic semantics, therefore, apply, but the responsibility shifts from the driver to the system. Two properties govern a valid transfer: safety (the transition must not introduce new hazards) and timeliness (completion must occur within the FTTI defined in ISO 26262-1:2018 Clause 3.61). An isolated success rate, however, is not by itself evidence of fallback capability: the claim must declare under what conditions it holds. We therefore formalize Transferability as a function of the operational context, T = T (o, f, s, m, τFTTI ),

(1)

with o the ODD slice, f the fault family, s the scene state at demand, m the minimal-risk maneuver (MRM) class, and τFTTI the fault-tolerant time interval. The perdemand evidence tuple captures evidence supporting any class assignment,  ET = o, f, s, m, τFTTI , tdetect , (2) tinit , tMRC , zstop , p̂succ , CI , recording detection latency tdetect , fallback initiation latency tinit , minimal-risk-condition achievement time tMRC , the realized stop zone zstop , the per-demand MRM success probability p̂succ , and its confidence interval CI. The tuple ET makes the conditioning of any Transferability claim explicit and supports independent reproduction or contestation; a class assignment unaccompanied by ET does not constitute complete evidence under this framework. C. Fallback Mechanisms in Autonomous Systems Fallback mechanisms embody the system’s embedded Controllability. They activate when the primary driving function fails or leaves its validated Operational Design Domain (ODD). Fallbacks can be categorized by their terminal states: Fail-Safe: Immediate transition to a safe state (ISO 262621:2018 Clause 3.131) through controlled immobilization or standstill. Fail-Degraded: Continued operation under restricted performance envelopes (e.g., controlled deceleration or shoulder pull-over), aligning with ISO 26262-1:2018 Clause 3.43”‘emergency operation’ Fail-Operational: Seamless redundancy maintaining full performance through duplicated or diverse architectures, consistent with ISO 26262-1:2018 Clause 3.122 and 3.37. These mechanisms represent increasing levels of intrinsic system Controllability, from degraded operation to uninterrupted safety-critical function. D. Transferability Classification Transferability is classified analogously to Controllability (C0–C3) to facilitate integration with existing ISO 26262 processes. Four qualitative classes (T 0-T 3) quantify the

robustness and reliability of system fallbacks. Point success thresholds are not by themselves statistically defensible; we therefore assign classes based on the lower confidence bound p̂LCB succ of the per-demand MRM success probability, conditioned on the declared (o, f ) pair from (1)–(2). These levels allow Transferability to be treated as a measurable sub-dimension of Controllability within ASIL risk assessment. A class assignment that does not also report p̂LCB succ , the declared (o, f ) slice, the FTTI assumption, the failure definition, and the sample size is not acceptable evidence. E. Designed Versus Achievable Transferability A Transferability class derived from architectural fallback design need not equal the class supported by scenarioconditioned evidence. Mismatches arise from environmental or contextual limitations, for example, blocked shoulders, degraded localization, sun glare, partial occlusion, etc, which must be explicitly analyzed within safety cases. Let Tdesigned (f ) denote the fallback capability claimed at design time for fault family f from architectural redundancy analysis, and Tachievable (o, s, f ) the capability supported by validated evidence under ODD slice o and scene state s. The designed-versus-achievable Transferability gap is ∆T (o, s, f ) = Tachievable (o, s, f ) − Tdesigned (f ),

(3)

taken on the ordinal scale {T 0, T 1, T 2, T 3} with T 0 < T 1 < T 2 < T 3, so T 0 denotes the most capable class and T 3 the least. The sign convention follows the engineering intuition that ∆T > 0 corresponds to evidence falling short of the architectural claim, ∆T = 0 to evidence matching the claim, and ∆T < 0 to evidence exceeding the claim. Table II summarizes the interpretation. A positive ∆T is not a defect indicator on its own; it is a routine outcome at the start of a validation campaign, but it must be auditable, ODD-sliced, and traceable rather than subsumed in an undifferentiated aggregate claim. F. Operationalizing Transferability via Minimal-Risk Maneuver (MRM) Performance Transferability is evaluated through three auditable indicators derived from MRM performance: 1) Initiation latency tinit relative to FTTI, 2) MRM success rate p̂succ with confidence interval, across fault scenarios, and 3) Final stop-zone compliance zstop with designated minimal-risk locations. These indicators complement ISO 26262 fault analyses rather than replace them. They provide quantifiable, ISO 21448:2022 SOTIF-aligned evidence for fallback robustness that can be verified through fault-injection testing, hardware-in-the-loop (HIL) simulation, or field data. Reporting ET together with ∆T captures fallback capability in a unified, auditable framework for AV safety assessment. IV. I NTRODUCING P REDICTABILITY This section introduces Predictability as a complementary sub-dimension of Controllability for autonomous-vehicle (AV) safety assessment. While Transferability internalizes

TABLE I: Non-normative Transferability reporting classes. Classes are evidence bins whose acceptance thresholds must be calibrated per vehicle class, ODD slice, scenario family, and stakeholder risk tolerance. Class

Description

Example Evidence Interpretation

T0 T1

Seamless, fully redundant, failoperational transition Reliable degraded fallback

T2

Partial or uncertain fallback

T3

No defined or achievable fallback capability

Transfer to the stated MRC is consistently achieved within the hazard deadline with low secondary risk across the declared ODD slice; fallback function is uninterrupted. Transfer is usually achieved within the hazard deadline; the outcome depends on the declared scene and degraded-mode assumptions; minor functional limitations are present. Transfer is conditional; identifiable ODD sub-slices show deadline, endpoint, or secondary-risk violations; the fallback endpoint may be limited to in-lane stop. Transfer is frequently unachievable in the relevant scene, the deadline is exceeded, or the endpoint creates unacceptable secondary risk.

TABLE II: Interpretation of the designed-versus-achievable Transferability gap ∆T defined in equation (3). Case

Interpretation

∆T ≤ 0

Validation evidence supports or exceeds the architectural fallback claim under the declared (o, s, f ). The claim is auditable and may be entered into the safety case as supplementary evidence of Controllability. Small ∆T (= The architectural claim outruns the achievable evidence 1) by one class. The claim must be qualified, the validation campaign extended, or the ODD restricted to slices where ∆T ≤ 0 is established. Large ∆T (≥ 2) The architectural claim is unsupported by the available evidence. The claim is invalid for the declared (o, s, f ) unless the design or the ODD is changed.

Controllability through the system’s fallback capability, Predictability externalizes it by capturing the extent to which affected road users can anticipate the AV’s near-future behavior from observable motion, signals, and scene context before they must commit to their own response. Together, these two dimensions extend ISO 26262 Controllability from driver reaction to system behavior and human interpretation. A. The Need for Predictability in Autonomous-Vehicle Safety We are interested in the safety of the interaction between an automated vehicle and the road users it shares space with. For most road users, a vehicle’s motion is the primary channel of communication. In the absence of direct cues such as gaze or gesture, pedestrians, cyclists, and other drivers infer vehicle intent through observable kinematics: changes in speed, trajectory, and position relative to the environment. Studies on external human–machine interfaces report that, while visual or auditory signals can supplement understanding, motion cues remain the most consistent indicator of intent across contexts [18], [19]. The timing and quality of motion further influence pedestrians’ perception of safety and confidence during interactions [19], [20]. Within this framework, Predictability quantifies how effectively an AV’s motion enables observers to anticipate its next maneuver before they must commit to a response. We therefore define: Predictability: The extent to which affected road users can anticipate an AV’s near-future behavior from observable motion, signals, and scene context, before they must commit to their own response. This definition is interaction-facing. It does not require the AV to imitate average human drivers, nor does it equate human-likeness with safety. We adopt a usage broader than

the narrower human-robot interaction (HRI) distinction between predictable motion and legible motion [9], [11]: AV safety needs both, since road users must first infer the vehicle’s intent and then judge whether the executed motion is consistent with that inferred intent. When motion departs from these expectations, accelerating abruptly, braking inconsistently, or failing to yield when the context calls for it, road users may hesitate or respond unpredictably, increasing interaction risk regardless of compliance with traffic rules. B. Reference Model and Observer Model Let ξ0:t denote the observed prefix of the AV trajectory, c the scene context, o the operational-design-domain (ODD) slice, and a the relevant observer class-pedestrian, cyclist, passenger-car driver, or professional truck driver. We note that a Predictability monitor should not collapse the observer to a single deterministic inferred trajectory: a road user maintains a belief over multiple plausible maneuvers, and that distribution is the object the monitor must address. We therefore work with a context-conditioned reference distribution over expected future motion, pref (ξt:t+H | ξ0:t , c, o, a),

(4)

together with an observer model for goal inference, p(g | ξ0:t , c, a),

g ∈ G,

(5)

where H is the prediction horizon (held distinct from the Transferability class symbols T 0–T 3) and G is the declared goal alphabet for the scenario family. The reference distribution in (4) may be constructed from naturalistic driving data, expert demonstrations, rulecompliant synthetic policies, learned motion-forecasting models, or validated simulator baselines [17]. We emphasize that these sources are evidence models, not ground truth about what the AV ought to do: human data may encode unsafe habits, synthetic policies may encode designer assumptions, and learned predictors may be poorly calibrated in rare situations. Departure from pref is therefore not automatically unsafe, but it is evidence requiring explanation. A monitor declaration must specify, for each scenario family, the prediction horizon (typically H = 3–5 s for urban interaction); the context variables used by the reference, such as lane topology, signal state, right-of-way, relative speed, and vulnerable-road-user proximity; the observer class a; the model class or dataset used to construct pref ; the calibration criterion, for instance held-out negative log-

TABLE III: Non-normative Transferability reporting classes with qualitative acceptance criteria.

TABLE IV: Transferability–Predictability mapping for Unified Controllability (SAE L4–L5).

Class

Initiation latency

Example Final stop-zone

T\P

P0

P1

P2

P3

T0 T1 T2 T3

≪ τh < τh < τh ≥ τh or unknown

Minimal-risk location consistently reached Safe-harbor or shoulder Controlled in-lane stop Non-compliant or undefined endpoint

T0 T1 T2 T3

C0 C1 C2 C3

C0 C1 C2 C3

C1 C2 C3 C3

C2 C3 C3 C3

likelihood, reliability of maneuver probabilities, or scenariofamily false-alarm rate; and an out-of-distribution rejection rule. These declarations are recommended for a complete safety argument. Without them, the reference reduces to an unverifiable appeal to “normal driving” and may not support a safety-case argument. C. Vector Monitor Channels We report Predictability through four diagnostic channels, each addressing a distinct facet of observer-facing anticipatability. The first channel is contextual conformity. Within the declared pref , the raw negative log-likelihood Snll (ξt:t+H ) = − log pref (ξt:t+H | ξ0:t , c, o, a)

(6)

is informative within a fixed model, but its scale depends on the entropy and parameterization of the reference. For reporting, we therefore use a calibrated tail statistic,   ′ Qconf = ′ Pr Snll (ξt:t+H ) ≥ Snll (ξt:t+H ) . (7) ξt:t+H ∼pref

Small Qconf places the observed AV behavior in the lowlikelihood tail of the declared reference. We note that Qconf is comparable only within the declared model, coordinate convention, ODD slice, and scenario family; it is not a universal measure of safety, and aggregations across declarations are not meaningful. The second channel is intent clarity. Let the observer model estimate p(g | ξ0:t , c, a) over the fixed alphabet G. We define a normalized intent-clarity score H(g | ξ0:t , c, a) , (8) Sintent (t) = 1 − log |G| where H(·) denotes Shannon entropy (typeset to remain distinct from the prediction horizon H), Sintent = 1 indicates low ambiguity, and Sintent = 0 indicates maximal ambiguity under the chosen alphabet. Distinct from this instantaneous measure, the first-confidence time is tθ ≜ inf{t : p(g ⋆ | ξ0:t , c, a) ≥ θ} ,

(9)

and the decision-margin acceptance condition is tθ ≤ tdecision − ∆tresponse .

(10)

Equation (10) asks whether the correct intent becomes clear before the affected road user must commit to a response. The response margin ∆tresponse is observer-class dependent and must be calibrated against the relevant perception– response literature for the declared observer class [21], [22]. Because (8) depends on |G|, the goal alphabet must be declared and held fixed for each scenario family. Remark 4.1 (Relation to Dragan-style legibility): The intent-clarity construct is operationally close to the legibility formalism of Dragan et al. [9], [11]. Their

legibility functional integrates the observer’s posterior on the true Rgoal g ⋆ along the observed  prefix,  trajectory R p(g ⋆ | ξ0:t , c, a) f (t) dt / f (t) dt , with L(ξ) = f (t) a time-discounting weight. Equation (8) replaces the marginal posterior with a normalized entropy on G, retaining ambiguity reduction as the central object while accommodating multimodal posteriors with no privileged ground-truth goal at runtime. The first-confidence time (9) is the time-to-decision dual of L: rather than averaging confidence over the prefix, it asks when confidence in the true goal first crosses an observer-relevant threshold, which is the quantity the decision-margin condition (10) consumes. The third channel is signal consistency. It assesses whether turn signals, brake lights, lateral motion, gap choice, and right-of-way behavior agree. A lane-change monitor, for instance, reports  Ssignal = ∆tsig , Nconflict , ∆tsig = tmotion − tsignal , (11) where ∆tsig is the signal lead time and Nconflict counts signal–motion conflicts within a fixed window. The fourth channel is kinematic surprise. It measures context-unexplained jerk, hard braking, lateral drift, or hesitation, X  Skin = 1 |j(t)| > jmax ∧ ¬E(t) , (12) t

where E(t) denotes an observable or validated explanation, such as an occluded pedestrian, lead-vehicle braking, or a sudden obstacle. We note that the monitor does not penalize abrupt motion when an explanation is available; abrupt braking for an occluded pedestrian is safety-justified, while abrupt braking in free traffic without an observable trigger is a separate evidentiary item. The four channels assemble into the vector   MP = Qconf , Sintent , Ssignal , Skin . (13) Because the components carry heterogeneous units and admit different mitigations, MP is the primary evidentiary object archived in the safety case. Any scalar derived from MP for ranking or class assignment must be accompanied by its calibration basis and treated as a derived report, not as the underlying evidence. D. Aggregation to an Ordinal Predictability Class Sections V and VI consume Predictability through an ordinal class P ∈ {P 0, P 1, P 2, P 3}, parallel to the Transferability classes T0–T3. We therefore introduce an explicit aggregation rule from the vector monitor MP to the ordinal P . The rule is declared, ODD-conditioned, and calibrated; it is not derived from first principles.

TABLE V: Predictability classes derived from the vector monitor MP via the worst-channel aggregation rule of equation (14). Class

Evidence interpretation

P0

All four channels of MP remain within calibrated bounds for the declared ODD slice and observer class. Channels are usually within bounds, with isolated and explained excursions tied to declared assumptions. One or more channels fail on identifiable ODD sub-slices or observer classes; the anticipation claim is fragile and must be qualified. A channel fails systematically, or multiple channels fail concurrently; observer anticipation cannot be claimed without redesign or ODD restriction.

P1 P2

P3

For each channel k ∈ {Qconf , Sintent , Ssignal , Skin } we declare a thresholding map πk : R → {P 0, P 1, P 2, P 3} that assigns the channel value to a four-level evidence band given the scenario family, the ODD slice, and the observer class. The per-channel thresholds are calibrated on a held-out reference set with a stated false-alarm rate; their numerical values are not universal and must accompany any reported P. We adopt the worst-channel aggregation rule  P = max πQconf (Qconf ), πSintent (14)  (Sintent ), πSsignal (Ssignal ), πSkin (Skin ) , where the ordering on {P 0, P 1, P 2, P 3} is P 0 < P 1 < P 2 < P 3. Equation (14) is conservative by construction: a single-channel failure dominates the class assignment, mirroring the safety-engineering convention that the weakest evidence governs the claim. The interpretive semantics of the four bands are summarized in Table V. The vector MP remains the underlying evidence archived in the safety case. The ordinal P is the derived report consumed by the unified Controllability computation in Section V. Both must be reported together: a P -class assignment without the underlying MP and the accompanying calibration declaration does not constitute complete evidence under this framework. E. Calibration Limits and Composition with Transferability Predictability thresholds are not universal constants. A truck entering a highway work zone, a robotaxi negotiating a pedestrian crossing, and a passenger car changing lanes in free-flow traffic expose different observer populations, available cues, response times, and acceptable motion envelopes. Calibration is therefore scenario-family and ODDslice-specific. The monitor must declare the observer class, available cues, decision point, response margin, and goal alphabet. When human-subject evidence is unavailable, an observer model may serve as a provisional surrogate, but the safety case must state the residual uncertainty rather than treat the model as settled human behavior. This calibration discipline mirrors the per-ODD treatment of Transferability evidence introduced in Section III. Both Predictability and Transferability are reported and calibrated independently for each ODD slice, and only then composed into the unified Controllability of Section V; the integrity

of the composition depends on the integrity of each input. Predictability metrics are accordingly proposed as auditable evidence artifacts under Parts 3-6 of ISO 26262, and as key performance indicators for ISO 21448:2022 SOTIF validation, with the accompanying declaration of model, ODD slice, observer class, and calibration basis carried as part of the work product. V. U NIFIED E NHANCED C ONTROLLABILITY This section formalizes how Transferability and Predictability jointly extend ISO 26262 Controllability into a unified, auditable construct for hazard and risk assessment. The objective is to preserve the original three-parameter ISO 26262 risk logic-Severity (S), Exposure (E), and Controllability (C)-while decomposing C into two measurable sub-dimensions representing internal and external Controllability. A. Unified Controllability Computation For SAE Levels 0–2, Controllability (Ch ) remains humancentric as defined in ISO 26262. For higher automation, the unified Controllability evidence class (Cu ) is computed by composing the Transferability class with the Predictability class through an additive-penalty rule:  Cu = min 3, T + ∆P , (15) where T ∈ {0, 1, 2, 3} is the Transferability class assigned per Section III-D, and   0, P ∈ {P 0, P 1}, (16) ∆P = 1, P = P 2,   2, P = P 3, with the ordinal P -class derived from the underlying vector monitor MP by the worst-channel aggregation rule of Section IV-D. The additive-penalty rule is one of several admissible composition policies; alternatives are discussed in Section V-B. The resulting Cu preserves ISO 26262’s ordinal scaling (C0–C3) and satisfies three properties any candidate alternative in Section V-B must also preserve: severity dominance (S0 remains QM regardless of Cu ); monotonicity (degrading T or P never improves Cu ); and bounded compensation within Cu (a strong T can partially absorb a weakened P in the Controllability-evidence report, but Cu does not relax ASIL elsewhere in the safety case). B. Candidate Composition Policies Equations (15)–(16) are one of several reporting policies that satisfy monotonicity and the ordinal range {C0, . . . , C3}. Three candidates spanning the practical design space are summarized in Table VI. We adopt the additive-penalty rule as an illustrative reporting convention only; standardization of Cu would require empirical and consensus-based calibration against scenarioconditioned hazardous-event data. The asymmetry between T and P in equation (15) is not a derived result; it reflects an operational asymmetry in the underlying evidence. Transferability evidence is collected from controlled fault-injection campaigns whose (o, f ) conditioning, FTTI

TABLE VI: Candidate composition policies for the unified Controllability evidence class Cu . The additive-penalty rule is used in this paper as an illustrative reporting convention and is not proposed as a normative standardization choice. Policy

Formula

Properties

= Simple, monotonic, treats Transfer+ ability as the base class with Predictability as a graded penalty; the asymmetry assumes that fallback evidence carries primary weight in the Controllability rationale. Max rule Cu = Symmetric and conservative; the max(T, Pord ) weakest evidence governs the report. May over-penalize when only one channel of MP fails on a narrow sub-slice. Safety-case ma- Expert-declared Most flexible and auditable; permits trix T × P table per scenario-specific weighting. Requires scenario family explicit governance and consensus calibration. Additive penalty (this paper)

Cu min(3, T ∆P )

assumption, and lower confidence bound are declarable on demand; Predictability evidence is observer-conditioned, channel-heterogeneous, and admits greater residual uncertainty in calibration. The additive-penalty rule encodes the engineering preference that the better-instrumented evidence stream sets the base class, while the more uncertain stream contributes a graded penalty. A reviewer or standards body unconvinced by this preference may substitute the symmetric max rule of Table VI or the safety-case-matrix policy without disturbing the rest of the framework. C. Integration into Hazard and Risk Assessment In the enhanced HARA process, each identified hazard records both sub-dimensions: Transferability evidence: the tuple ET of (2) including the (o, f ) slice, FTTI, p̂succ with confidence interval, and the gap ∆T of (3), verified through FTTI analysis, redundancy tests, and fault-injection campaigns. • Predictability evidence: the vector monitor MP of (13) with its calibration declaration and per-channel thresholds, validated through trajectory-conformity metrics and human-observer studies. •

The derived Cu value is reported alongside conventional HARA attributes as supplementary evidence of Controllability for driverless ADS items. It does not replace the ISO 26262 Controllability classification or alter the normative ASIL determination procedure; it provides traceable evidence linking internal system design (Transferability) and external behavioral comprehension (Predictability) within a single ISO 26262-compatible safety argument. Transferability and Predictability evidence must not be double-counted: a fallback mechanism credited to Transferability as a pre-mitigation Controllability factor cannot also be credited as a post-HARA safety measure satisfying the resulting ASIL, unless its availability is part of the item definition and is justified under the hazardous-event assumptions. The same restriction applies to Predictabilityenhancing motion behaviors. Cu therefore stands as supplementary Controllability evidence, not as a substitution that

relaxes ASIL. D. Outcome The unified Controllability construct maintains the interpretability of ISO 26262’s risk classification while embedding autonomy-specific evidence streams. It directly supports cross-standard alignment between ISO 26262 (functional safety) and ISO 21448:2022 (SOTIF) by quantifying both intrinsic system control and external human understanding within a consistent, auditable framework. VI. ASIL D ETERMINATION WITH E NHANCED C ONTROLLABILITY This section extends the ISO 26262 ASIL determination process to incorporate the enhanced Controllability construct, integrating Transferability (internal fallback capability) and Predictability (external behavioral intelligibility). The goal is to maintain ISO 26262’s original three-parameter logicSeverity (S), Exposure (E), and Controllability (C)-while decomposing C into its system and human-interaction components for autonomous vehicle (AV) applications. A. Extended ASIL Assessment Framework The proposed approach retains the standard definitions of Severity (S0–S3) and Exposure (E0–E4) from ISO 26262. Controllability is evaluated through its measurable subdimensions: Transferability (T 0–T 3) and Predictability (P 0– P 3). The resulting unified Controllability evidence class Cu is obtained from the additive-penalty rule of equation (15) and the mapping shown in Table IV. Cu is reported alongside the standard Controllability parameter and feeds the (S, E, Cu ) tuple into the ASIL determination of ISO 262623:2018 Clause 6 Table 4 as supplementary Controllability evidence; it does not replace the normative Controllability parameter but informs its classification through auditable, scenario-conditioned evidence. A high Transferability (T 0–T 1) combined with a high Predictability (P 0–P 1) yields a low Cu class, which in the standard ASIL mapping is associated with reduced ASIL designations under matching S and E. Conversely, poor fallback or erratic behavior (T 3, P 3) yields a high Cu class, escalating ASIL requirements consistent with ISO 26262’s monotonic risk progression. The compensation operates strictly inside the Controllability rationale: T and P do not offset Severity or Exposure, which remain independent risk factors determined by the hazardous event itself. B. Integration Logic The framework preserves ISO 26262’s core risk principles: Severity dominance: S0 scenarios remain Quality Management (QM), unaffected by T or P . • Monotonicity: Increasing severity or exposure, or degrading T or P (raising Cu ), never decreases ASIL. • Bounded composition within Cu : Strong T can partially absorb weakened P inside the Controllabilityevidence report, but Cu is never used to relax ASIL elsewhere in the safety case (see the double-counting prohibition of Section V-A). •

C. Implementation During Hazard Analysis and Risk Assessment (HARA), practitioners record evidence for each sub-dimension: Transferability: the evidence tuple ET of equation (2) including validated FTTI, redundancy data, fault-injection results, lower confidence bounds p̂LCB succ , and the gap ∆T of equation (3). • Predictability: the vector monitor MP of equation (13) with the calibration declarations of Section IV-E, conformity metrics, observer-study data, or telematics comparison results.

The computed Cu is reported in the Controllability column of the ISO 26262-3:2018 Clause 6 Table 4 ASIL determination as supplementary evidence informing the C classification. Concretely, for a hazardous event characterized by Severity S and Exposure E, the safety case records (S, E, Cu ) together with the underlying ET , MP , ∆T , and the calibration declarations of Sections III-D and IV-E, so that any reviewer can trace the Controllability classification back to the underlying fault-injection and observer evidence rather than to an opaque C-class assignment. D. Outcome This extended ASIL determination method embeds AVspecific attributes within the established ISO 26262 risk structure. It quantifies both the vehicle’s intrinsic capability to manage hazards and its clarity of interaction with the environment, providing auditable, evidence-based inputs for functional safety assessment without altering the underlying ASIL methodology. VII. P ROPOSED A MENDMENTS TO ISO 26262 Note: The proposed amendments are the authors’ individual research recommendations to the ISO standards body and do not reflect any organization’s compliance obligations. This section outlines concise modifications across ISO 26262 Parts 1–10 proposed to operationalize the enhanced Controllability framework. The goal is not to replace existing processes but to introduce measurable evidence paths for Transferability and Predictability, ensuring that functional safety analyses remain applicable to SAE L3–L5 autonomous vehicles and explicitly include external roaduser safety. The amendments are not intended to alter the standard’s normative HARA, ASIL, or item-definition semantics, but rather to extend its applicability and evidence base. A. General Amendment Principles Amendments follow four principles: (1) extend the scope of safety to include external road users; (2) integrate Transferability and Predictability where Controllability is referenced, supported by the per-demand evidence tuple ET of (2) and the gap ∆T of (3); (3) reinforce architectural requirements for autonomous fallback and fault-tolerant design; and (4) enable data-driven verification using simulation, naturalistic driving datasets, and human-observer studies. These principles ensure continuity with ISO 26262’s structure while expanding its evidence base.

B. Part 1 – Vocabulary Add formal definitions for Transferability, Predictability, Fallback Mechanism, External Road User, and the gap ∆T . Clarify that a Safe State must balance occupant and external-user safety and that the Fault-Tolerant Time Interval (FTTI) also bounds the period within which the AV must complete reasonably safe fallback to protect nearby actors. C. Part 2 – Functional Safety Management Recommend dedicated organizational roles for externalroad-user safety and cross-team interfaces linking functionalsafety, human-factors, and autonomy disciplines. Impact analyses for design changes shall evaluate effects on ET and on the four channels of the Predictability monitor MP . D. Part 3 – Concept Phase Update Hazard Analysis and Risk Assessment (HARA) to record both Transferability (T ) and Predictability (P ) ratings as a part of Controllability (C), alongside Severity (S) and Exposure (E). For each hazard, the work product carries ET , MP , the derived P -class, Cu , and the calibration declarations of Sections III-D and IV-E. Safety goals can be a function of Predictability and fallback-performance requirements, including the response margin ∆tresponse -validated through empirical testing and observer studies. E. Part 4-6 – Product Development System level: decompose safety goals into verifiable requirements addressing fallback initiation timing, FTTI compliance, observer-facing intent clarity, and signal consistency. Hardware level: define redundancy and diversity evidence criteria consistent with the claimed Transferability class, reported with their lower confidence bounds. Software level: propose isolation between primary and fallback functions, and motion-planning constraints whose effect on the four Predictability channels is independently monitored (Section VIII). F. Part 7-8 – Production and Supporting Processes Operational data collection includes monitoring outputs for Transferability and Predictability under field conditions, with explanations for any channel excursions. Tool qualification and change-management clauses reference the datasets, simulators, and observer models used for MP and p̂succ calibration, thereby making the calibration basis itself traceable. G. Part 9 – Safety Analyses Controllability in risk classification becomes an enhanced parameter represented by Cu , derived from T and P via (15)–(16) and reported alongside the standard Controllability entry. Dependent-failure analysis must consider faults that simultaneously degrade fallback reliability and behavioral anticipatability, since a single root cause may compromise both. H. Part 10 – Informative Guidance Introduce a new appendix on Predictability Operationalization, providing: (i) the calibration protocols of Section IV-E; (ii) recommended scenario families-unprotected turns, crosswalk yields, highway merging, work-zone narrowing-following the scenario-based evaluation discipline of ISO 34502:2022 [4] and the ADS V&V guidance of ISO/TR 4804:2020 [5]; and (iii) reporting templates that

record the evidence tuple ET of (2), the vector monitor MP of (13), the gap ∆T of (3), and the calibration basis for each declared (o, s, f, a). This appendix provides practical guidance on implementing human-perception-based safety validation in ISO 26262 projects. I. Summary These concise amendments integrate Transferability and Predictability throughout the ISO 26262 lifecycle, extending the standard’s applicability from driver-controlled to autonomous systems. The revisions preserve ISO 26262’s core philosophy while embedding measurable, evidencebased assurance of both internal fallback performance and external behavioral intelligibility. VIII. P LANNER D ESIGN I MPLICATIONS The four channels of the Predictability monitor MP introduced in Section IV-C, together with the Transferability indicators of Section III, can inform planner design. We note, however, that they should not be confused with safety evidence. A planner may employ contextual conformity, intent clarity, signal consistency, or kinematic-surprise penalties as candidate-trajectory filters, as terms in a constrainedoptimization objective, or as reward-shaping signals for a learned policy. Such use can encourage smoother, more legible, and better-signaled behavior during development, and the monitor declarations of Section IV-B-reference model, observer class, ODD slice, calibration criterion, transfer directly to the planner’s specification of its own objective. Similarly, the Transferability indicators-initiation latency tinit , MRM success probability p̂succ , and stop-zone compliance zstop -can inform fallback trigger thresholds and redundancy design; for instance, a planner aware of τFTTI can maintain a continuously feasible fallback trajectory to reduce tinit at demand time. Nevertheless, planner-internal rewards, costs, and constraints are not independent evidence that the executed behavior is predictable or that fallback capability is achieved. Three failure modes are of particular concern. First, a learned policy optimized against Sintent may commit early to one goal interpretation in ways that are locally legible but difficult to abort-surrogate overfitting that improves a scalar metric while leaving real observer-facing ambiguity unresolved. Second, a reward derived from Qconf is only meaningful within the declared ODD slice; outside it, the planner may receive reward signals that are uncorrelated with actual anticipatability. Third, and most critically, using MP as both a training signal and a safety-case evidence artifact introduces a circular dependency that invalidates the independence assumption underlying the safety argument. The evidence tuple ET of (2) should be populated from independent faultinjection campaigns and hardware-in-the-loop evaluation, not from simulations that share assumptions with the primary driving function; a ∆T computation drawn from the same environment used to train fallback-awareness constraints is not a valid ∆T measurement. Any planner who uses Transferability or Predictability during optimization must therefore be evaluated by an in-

dependent monitor on executed closed-loop behavior, with the safety case reporting the monitor outputs, calibration basis, detection power, false-positive rate, and ODD-sliced failure diagnosis separately from the planner’s objective. We emphasize that this independence is not a procedural nicety: it is the only mechanism that distinguishes a predictable planner from one that has merely learned to satisfy its surrogate. IX. C ONCLUSION This paper enhances the ISO 26262 functional safety framework by extending its Controllability construct to address the operational realities of autonomous vehicles. Rather than replacing established principles, the proposed approach decomposes Controllability into two measurable and complementary sub-dimensions: Transferability, representing the autonomous system’s intrinsic fallback capability, and Predictability, representing the degree to which external road users can anticipate its behavior. Together, these extensions preserve the intent of ISO 26262:2018 while enabling its direct application to SAE L4-L5 automation. The framework developed in this document aligns with ISO 26262’s risk factors: Severity, Exposure, and Controllability. However, it enhances Controllability by using measurable indicators grounded in system reliability, human factors science, and behavioral data. Mathematical definitions and validation methods are used to connect Transferability to fault-tolerant fallback performance and Predictability to trajectory clarity and human understanding. This is compatible with the ISO 26262:2018 standard and broadens risk assessment to include both the system’s internal control and human understanding. Comprehensive lifecycle integration points are identified throughout ISO 26262:2018 Parts 1-10, ensuring that evidence of fallback performance and behavioral intelligibility is incorporated into standard work products. These targeted amendments harmonize functional safety with ISO 21448:2022 SOTIF and bridge classical safety engineering, human-robot interaction research, and real-world autonomous vehicle validation. By embedding Transferability and Predictability within the ISO 26262 structure, this work provides a scalable, evidencedriven pathway for certifying the safety of highly automated and fully autonomous systems. The proposed enhancements maintain the rigor of functional safety while aligning its assurance framework with the distributed, data-intensive, and human-interactive nature of modern autonomous driving. Limitations. The numerical targets of Tables III and V, and the per-channel thresholds of (14), are scenario-family, ODD-slice-, and observer-class-specific; they must be reported with their calibration basis and are not transferable across declarations without re-calibration. Naturalistic driving data may encode behaviors that may not reflect optimal safety practices and culturally specific norms-it is an evidence model, not a normative target. Where humansubject evidence is unavailable, an observer model serves as a reasonably approximate model, subject to validation

and project-specific calibration, for p(g | ξ0:t , c, a), with the substitution and residual uncertainty declared as part of the safety case. The framework does not propose ASIL relaxation based on high T or P ; the unified Controllability evidence class Cu supplements, rather than replaces, the normative ISO 26262 Controllability parameter. High-confidence Transferability claims for safety-critical fault families require statistical care: a finite fault-injection campaign cannot establish lower confidence bounds beyond a level dictated by sample size, and rare-event estimation, accelerated testing, and scenario-coverage arguments are required for the higher classes of Tables I and III. Both MP and Tachievable may degrade silently outside their declared ODD slices; the outof-distribution rejection rule required by Section IV-B is part of the calibration declaration, not an optional extension. Future Work. In the future, we are interested in the calibration methodology for Sections III and IV - ODDslice-specific thresholds, observer-model validation against human-subject data, and rare-event estimation for highconfidence class assignments remain open for the field. The composition policies of Table VI merit empirical comparison against hazardous-event data to replace the illustrative Cu convention adopted here. Finally, the coupling between legibility-oriented planning and the ∆T gap warrants explicit study, provided that the independence requirement of Section VIII is preserved throughout. DISCLAIMER This publication reflects the individual research views of the named authors and does not constitute the official position, policy, or design philosophy of any author’s employer or affiliated organization. The proposed frameworks, mathematical formulations, acceptance criteria, and amendment recommendations are research contributions offered for consideration by standards bodies and the broader research community; they do not describe the current or intended internal processes, safety cases, compliance posture, or product architecture of any author’s employer. For the avoidance of doubt, this publication is not intended and shall not be construed to establish a maximum or minimum requirement for dependability, safety, or performance for any automated driving system, nor shall it restrict any organization from adopting approaches that differ from those described herein. Its contents may require revision as technology, regulatory guidance, and community understanding evolve. Where the views of any individual author may appear to conflict with the positions of their employer, the employer’s own published materials, official documentation, and design decisions shall prevail. R EFERENCES [1] Road vehicles — Functional safety (ISO 26262), International Organization for Standardization Std., 2018, iSO 26262 series. [Online]. Available: https://www.iso.org/standard/43464.html [2] Road vehicles — Safety of the intended functionality (SOTIF) (ISO 21448:2022), International Organization for Standardization Std., 2022. [Online]. Available: https://www.iso.org/standard/77490.html [3] Underwriters Laboratories (UL), UL 4600: Standard for Safety for the Evaluation of Autonomous Products, Underwriters Laboratories Std., 2023, covers safety case development, behavioral transparency, and system-level assurance for autonomous systems.

[4] Road vehicles — Test scenarios for automated driving systems — Scenario based safety evaluation framework, International Organization for Standardization Std. ISO 34 502:2022, 2022. [Online]. Available: https://www.iso.org/standard/78951.html [5] International Organization for Standardization, “Road vehicles — safety and cybersecurity for automated driving systems — design, verification and validation,” International Organization for Standardization, Tech. Rep. ISO/TR 4804:2020, 2020. [Online]. Available: https://www.iso.org/standard/80363.html [6] D. Garikapati, S. Poovalingam, W. Hau, R. De Castro, and C. Shinde, “A comprehensive review of parallel autonomy systems within vehicles: applications, architectures, safety considerations and standards,” IEEE Access, 2024. [7] IEEE, IEEE Standard for Assumptions in Safety-Related Models for Automated Driving Systems, Institute of Electrical and Electronics Engineers Std. IEEE Std 2846-2022, 2022. [Online]. Available: https://standards.ieee.org/ieee/2846/10831/ [8] R. Salay and K. Czarnecki, “Using machine learning safely in automotive software: An assessment and adaption of software process requirements in ISO 26262,” arXiv preprint arXiv:1808.01614, 2018. [Online]. Available: https://arxiv.org/abs/1808.01614 [9] A. Dragan, “Legible motion for robot planning and control,” Ph.D. dissertation, Carnegie Mellon University, 2015. [10] A. D. Dragan and S. S. Srinivasa, “Integrating human observer inferences into robot motion planning,” Autonomous Robots, vol. 37, no. 4, pp. 351–368, 2014. [11] A. D. Dragan, K. C. T. Lee, and S. S. Srinivasa, “Legibility and predictability of robot motion,” in ACM/IEEE Int. Conf. on HumanRobot Interaction (HRI), 2013. [12] A. D. Dragan, S. Bauman, J. Forlizzi, and S. S. Srinivasa, “Effects of robot motion on human-robot collaboration,” in Proceedings of the 10th ACM/IEEE International Conference on Human-Robot Interaction (HRI), 2015, pp. 51–58. [13] S. Nikolaidis, A. D. Dragan, and S. S. Srinivasa, “Viewpoint-based legibility optimization,” in Proceedings of the 11th ACM/IEEE International Conference on Human-Robot Interaction (HRI), 2016, pp. 271–278. [14] D. Sadigh, S. S. Sastry, S. A. Seshia, and A. D. Dragan, “Planning for autonomous cars that leverage the effects on human drivers,” in Proceedings of Robotics: Science and Systems (RSS), 2016. [15] A. Zhou, D. Hadfield-Menell, A. Nagabandi, and A. D. Dragan, “Expressive robot motion timing,” in Proceedings of the 2017 ACM/IEEE International Conference on Human-Robot Interaction (HRI), 2017, pp. 22–31. [16] Society of Automotive Engineers (SAE) International, Road Vehicle – Human-Centric Driving Data Acquisition for Research and Development, Std., 2015, sAE J2944 201503. Standard issued 2015-03-31. [17] National Highway Traffic Safety Administration (NHTSA), “Strategic highway research program 2 (shrp 2) naturalistic driving study (nds) data,” Dataverse, various years. [18] J. Jenness, A. K. Benedick, J. P. Singer, S. Yahoodik, E. Petraglia, J. Jaffe, and J. M. Sullivan, “Automated driving systems’ communication of intent with shared road users,” U.S. Department of Transportation, National Highway Traffic Safety Administration, Tech. Rep. DOT HS 813 148, 11 2021. [19] P. Schmitt, N. Britten, J. Jeong, A. Coffey, K. Clark, S. S. Kothawade, E. C. Grigore, A. Khaw, C. Konopka, L. Pham, K. Ryan, C. Schmitt, and E. Frazzoli, “Can cars gesture? a case for expressive behavior within autonomous vehicle and pedestrian interactions,” IEEE Robotics and Automation Letters, vol. 7, no. 2, pp. 1416–1423, 2022. [20] A. Block, S. Joshi, W. Tabone, A. Pandya, S. Lee, V. Patil, N. Britten, and P. Schmitt, “The road ahead: Advancing interactions between autonomous vehicles, pedestrians, and other road users,” in 2023 32nd IEEE International Conference on Robot and Human Interactive Communication (RO-MAN), 2023, pp. 16–23. [21] B. J. Schroeder and N. M. Rouphail, “Estimating pedestrian behavior at crosswalks: Stated preference and behavioral models for engineering applications,” in Transportation Research Record, vol. 2264, no. 1, 2011, pp. 90–98. [22] Transportation Research Board, Highway Capacity Manual, 5th ed. Washington, DC: National Academies Press, 2010, pedestrian perception–response time guidance, Chapter 17.

Record · ID 266209 · SHA-256 df1751fb0262fb64
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.