4 ms·
I liked this article, and this is only a small point in the context of how interesting the rest of it is, but it would be reckless to say that you need to excee
by angusb 13y ago
I liked this article, and this is only a small point in the context of how interesting the rest of it is, but it would be reckless to say that you need to exceed only 1M driving hours accident free to be better than humans. Of course this would lead to a lower empirical accidents:mile ratio for your new tech, but you still wouldn't have enough data to be confident that your accidents:mile ratio fairly represents the chances of the new tech causing crashes. I'm not well read enough on p-values/confidence intervals/chi-squared tests to explain why, so maybe someone who is can explain this if there's enough interest. Basically someone needs to get all Evan Miller on this (e.g. http://www.evanmiller.org/tesla-fires.html http://www.evanmiller.org/tesla-fires.html )
- ivankirigin 13y agoThe Tesla fire situation makes me the most worried here, because the facts on the ground don't matter. The press ran with the story because it was explosive. So even if you had a much more confident estimate, you think the press is going to grok your math? The analysis I did was horribly incomplete, as I mentioned. The branding and marketing for the startup is going to matter a lot because of how emotional this whole robotic story can be.
- angusb 13y agoSadly you're right. But my point grapples with a larger issue too: should a startup launch if they aren't confident about the safety of their product?
- ivankirigin 13y agoThey should launch when they are safer than the average driver.
- Qworg 13y agoNot only that, but simply testing your system will not provide any sort of safety guarantee. Software errors are not just "show stopping bug" variety, but critical errors in odd corner cases that are not exercised until there's a fatal crash. See the Toyota unintended acceleration discussion: https://news.ycombinator.com/item?id=6636811 https://news.ycombinator.com/item?id=6636811 There's an entirely different way to write safety critical code that also specifies a process (IEC61508, MISRA C, etc). It isn't a guarantee, but it is required to have any sort of certainty in your system. This is before testing and validation.