5 ms·
It does sound silly at first, but I think suspending the one car is actually a rather elegant solution on several counts. 1. Easy to implement 2. Doesn't puni
by hakuseki 4y ago
It does sound silly at first, but I think suspending the one car is actually a rather elegant solution on several counts.
1. Easy to implement
2. Doesn't punish fleet scale (compare: suspending the whole fleet means a fleet that's twice as large would be suspended twice as often)
3. Punishes the fleet owner in proportion to the frequency of the error
4. Is exactly correct when the cause is really a hardware problem specific to the car
- tiku 4y agoBut the software "that did the crime" is all the same..
- hakuseki 4y agoYes, and that's why suspending the one car might seem counterintuitive. But that doesn't mean it's a bad solution.
- AvocadoPanic 4y agoCan we have lawn darts back if we suspend the darts that maim or kill?
- eru 4y agoYou can't even have Kinder Surprise..
- AvocadoPanic 4y agoSometimes the Indian supermarket has contraband imported Kinder Surprise, not the shitty domestic versions.
- FabHK 4y agoJust sell guns without any controls whatsoever, and if a gun is used to shoot someone, impound that gun. Problem solved. Right?
- logifail 4y ago> suspending the one car is actually a rather elegant solution If the software in a commercial aircraft were to be found defective, would we really be OK if only the individual aircraft in which the fault manifested itself gets grounded (assuming that aircraft isn't itself already on the ground in thousands of pieces spread all over a hillside...) Surely the FAA (or international equivalents) would issue an airworthiness directive which would apply to every single example of that specific type of aircraft?
- snovv_crash 4y agoIt depends. If it's an issue with just that vehicle then yes, you don't ground the whole fleet. If it's non-safety-critical, then it needs to be fixed asap but nothing gets grounded. If it's safety critical, then yes, all planes are grounded. But, I'd argue FAA levels of safety aren't suitable for cars. If a car has an engine failure or even a structural failure, they can usually just stop. Planes don't have that option.
- logifail 4y ago> I'd argue FAA levels of safety aren't suitable for cars. If a car has an engine failure or even a structural failure, they can usually just stop. Planes don't have that option. I had supposed we were thinking primarily about software faults and specifically those relating to the self-driving bit of a self-driving car. Best case: self-driving car gets lost and is found with flat battery miles from "home" (?) Worst-case: self-driving car kills cyclist/pedestrian and doesn't even notice or stop. We should spend some thought on how to handle the latter because it will happen sooner or later. To be blunt: if the algo kills, why wouldn't you ground the algo (all instances of it)?
- eru 4y agoI wonder whether that would just lead to people using slightly tweaked variants of the same algorithm branded to be different? (Of course, you don't want to fork too much, because there's probably a certification per algorithm needed. But it might make sense for Google to officially field a thousand 'different' algorithms, so that a single incident doesn't ground the entire fleet?)
- NovemberWhiskey 4y agoWhy would you treat a software problem that's specific to the car (and, by extension, specific to all cars running the same software version) differently from a hardware problem that's specific to the car?
- bee_rider 4y agoThe whole fleet should be grounded until the issue is debugged. Without debugging the issue * It might be a software issue (maybe the cars self-destruct when they encounter a solar eclipse -- silly example, but if the cars malfunction on events which are rare but wide-spread and correlated this could cause an emergency). * If it is a hardware issue, it must be understood how a hardware failure can put the device in a dangerous, still semi-functional state. If one car was able to get itself pulled over for driving dangerously, then there'd be an unknown number of cars driving themselves dangerously. * It is good that the fleet is punished disproportionately to the frequency of errors. We shouldn't accept a linear disincentive for putting dangerous vehicles on the road.
- eru 4y ago> * It is good that the fleet is punished disproportionately to the frequency of errors. We shouldn't accept a linear disincentive for putting dangerous vehicles on the road. We already do.. Putting driverless cars to a much higher standard, makes perfect the enemy of the better. Human drivers are not all that great.
- dotnet00 4y agoYet we sort of do accept a linear disincentive for putting dangerous drivers on the road, worst case we take that driver off the road and very rarely do anything to increase the standard all drivers need to meet such that it would weed out all the drivers that are as bad as or worse than the ones taken off the road. I think you're letting perfect be the enemy of good. In an ideal world we'd stop everything for debugging. Realistically all we need to have a net benefit right now is for the cars to be safer drivers than human drivers on average. As long as the issue isn't suspected of being intentionally triggered or correlated with some sort of large scale event, the world is still paying less of a cost than now even when not grounding the fleet. A reasonable compromise would be to require autonomous vehicles moving in especially risky areas like highways to have a human inside with at least a "stop or slow down safely" override. In places where the vehicle would be moving too slowly to cause serious injury we can allow them to be human-less. By defining clear and objective criteria, the decision to ground a fleet becomes much easier to make (particularly for the machine, since you don't need advanced AI to check GPS against a database and apply appropriate speed limiters). If the incident was a serious malfunction of a basic function like ignoring the criteria for human-less operation, the fleet should be grounded. In other cases it wouldn't justify preemptively grounding the entire fleet (but may justify it after the severity of the issue has been assessed, probably by a group independent of the company responsible for the vehicles).