Risk of Tesla camera-only self-driving

See, the difference is that a human can move their head and thereby see something in the blind spot if warranted.

A fixed camera mounted on an auto frame cannot.

Next?

1 Like

First, the design of many vehicles is such that even with rotating your head, there’s still blind spots due to B, C and rear pillars.

Second, human drivers, unless driving slowly, use rear view mirrors since rotating their head that far is actually dangerous, and mirror setups have blind spots.

Third, and my point, human drivers use their memory of what they’ve seen previously, such as passing a car that you actually can’t see even if you turn your head because it’s in your blind spot or too low, etc., but you know it’s there. Tesla’s software can do the same.

You’ve lost the original argument. Tesla’s cameras do a full 360 view with no obstructions and are looking in all directions at all times. The original argument was that the failure of a camera renders Tesla vehicles unable to even perform a DDT Fallback.

I’ve shown that to be a false argument. Again.

1 Like

That is not the contention, as I’ve explained several times. To the part in bold in particular, I’ve said “except in limited circumstances.” So yes, there are possibilities, but the claim that existing Telsas will be L4 (which Elon Musk has repeatedly stated, including on the last earnings call) has almost no basis in reality.

So, for example, if the single steering motor were to fail on a city street, that’s probably okay because the car can just stop. But that’s not okay on the freeway, because it isn’t safe to stop in the lane of travel on the freeway.

In rebuttal, we repeatedly heard the bizarre argument that Teslas have two steering motors so it is fail safe, even though the manual clearly states there is only one steering motor. Okay. Obviously, we should trust some rando on the internet over the Tesla manual.

And honestly @Tamhas, I’ve explained this before using that same example. You smart enough to know no one was claiming a “fully redundant alternative” was required. You’re making a silly straw man argument. I’ve read your other posts. You’re better than this.

I’ve come to realize there is no force on heaven or Earth that will motivate Tesla bulls to read the SAE standard (I think because they are absolutely terrified of what they might learn). Fine. But if you were to read it, you’d learn that for L4 the ADS must be fail operational, not necessarily fail safe.

So, your straw man arguments don’t land. No one is arguing what you are are arguing. No one is claiming, or has claimed, there needs to be fully redundant systems.

No one said anything about if radar or LIDAR are required at all. For the umpteenth time, the SAE standard is virtually silent about how performance criteria are met. It just says what those criteria are, not how to meet them.

I’m baffled why this concept is so hard to understand and why I need to keep repeating it. It is written out clearly on the first page.

I get why you guys are terrified of reading it, but reality is reality.

2 Likes

This of course is a silly straw man argument. The vehicle could have multiple overlapping cameras, it could have LIDAR and radar, and so on.

But if the vehicle only has cameras, and the cameras aren’t fully overlapping, then the cameras need to be unobstructed for the vehicle to be L4.

And again, current FSD will disengage if a camera is obstructed. So it is very silly to assume that a future software update will make so future FSD won’t disengage if a camera is obstructed.

Hence the reason we’re now seeing camera washers on Tesla taxis.

2 Likes

Not true. Quoting from the spec:

Level 4 and Level 5 ADS-equipped vehicles may also have a failure mitigation strategy of stop-in-place under certain rare, catastrophic failure conditions that render the ADS non-functional through, for example, loss of backup power after initial power failure or incapacitation of the ADS’s computing capability, which render it incapable of performing the fallback and achieving a minimal risk condition. Figure 14 displays a sample use case sequence.

So, SAE even gives an example of an L4 ADS not being “fail operational.” SAE wants it to be “rare,” but they do allow for it.

Not true. You can’t cite any part of the spec from which that conclusion is made. The desire is that in the case of an obstructed (or failed) camera, the system performs a DDT Fallback. But, if it can’t do that, then it can implement a failure mitigation strategy, which could even be “stop in place.”

You’re confusing SAE L4 with robotaxis, and helpful versus required.

Camera washers could fit into one of the following categories:

  1. Required for L4
  2. Helpful for L4
  3. Required for Robotaxi
  4. Helpful for Robotaxi
  5. Helpful just in general

What “current FSD” does is not related to what is required for L4, much less required for robotaxi. After all, FSD is not an L4 system, much less a robotaxi system.

Tesla’s robotaxi software is based on FSD, but it is different in some ways, particularly/especially in terms of not handing control over to a fallback ready driver, since there is none. While there are certainly circumstances in which FSD will warn the driver and disengage, that is not a behavior of any Tesla Robotaxi.

That “software update” has already happened and is in every Tesla Robotaxi today. It has not been back-ported to FSD.

Furthermore, it is possible to have an SAE L4 system that utilizes a fallback-ready user. As the spec states:

Level 4 and 5 ADS-equipped vehicles that are designed to also accommodate operation by a driver (whether in-vehicle or remote) may allow a user to perform the DDT fallback, when circumstances allow this to be done safely, if s/he chooses to do so (see Figures 7 and 8).

So, if Tesla chooses to do so, they could make an L4 vehicle that hands control over to a driver to perform the DDT Fallback. At least as far as the SAE defines it.

TSLA is a significant holding for me.

Whole video is worth watching, but I’ve cued it here to the part about cameras only versus adding LiDAR:

1 Like

Of course, when a human “moves their head” to look backward into a blind spot, they CREATED another blind spot, and probably a larger one! That’s why cars that have cameras on both sides and in front and in back can “see better” almost all the time.

1 Like

Discussion on starting with more sensors and then reduce as safety is demonstrated.

Waymo gen 6 hardware reduces sensors from the prior generation.

From the internet:

As a retired control system engineer, what I remember is once you choose your boundary conditions (in this case map/no map, overlap/no overlap of sensors, no redundancy/redundancy) you run your tests and hope to converge. Since the first 3-4 nines are pretty easy, your early results are quite deceptive regardless of your approach. The reality is many times your original decisions mathematically determine whether your approach can converge to inherently safe or not. No one knows when they begin so the sensible [approach is to] overspec in the beginning and prune as necessary when reality converges. In my experience the worst scenario is oops, we should have been measuring pressure and temperature at these locations and our model has a big gap as a result. Back to the drawing board. Much easier to start with 3 pressure transducers and 3 thermocouples and trim them later once the science reveals it was overkill. Installing a plug for the extra sensors when you know is trivial. The opposite is always a nightmare.

A comment from another thread:

What good are eyes when the fog is so thick you can’t see the road?

Once, back in Venezuela, the rain got so strong I could not see the road ahead so I pulled over to the shoulder and waited to the rain to slow.

My guess is that for cameras no longer functional FSD should do something similar. FSD cannot command the weather. :slightly_smiling_face:

The Captain

Why you building a strawman?

It is not uncommon for a vehicle’s cameras to be blocked by things that DO NOT obscure my windows or otherwise impair one’s ability to drive.

1 Like

One would think. There are two problems though. One is that if the camera can’t see, there is a risk that the car can’t pull over safely. For example, if there is an object in the obscured field of view.

The other is that it appears the AI can’t always tell if a camera is obscured or not.

2 Likes

That’s your best defense?

Just replying to an idea that ignores reality.

The Captain

Well, don’t take my word for it, ask the experts.

I’m sure Waymo also evaluated camera-only and then chose multi-sensor.

Because, you know, “disciplined, careful, incremental approach.”

Nuro sensor debate

At Nuro, we have built and tested both vision-only systems and multi-sensor systems, and we compare them directly. Qualitatively, the perception outputs can look similarly high-quality, so much so that when watching video clips, it is not always obvious which system is which. Quantitatively, however, differences do emerge. When we look at object recall, especially at night and especially for pedestrians, systems that combine cameras with LiDAR and radar consistently perform better. These are precisely the scenarios that matter most for safety.

A common counterargument is that adding sensors increases system complexity. That is true to some extent. But complexity, in this case, is an engineering problem rather than a fundamental barrier. Sensor fusion, calibration, and redundancy are hard problems, but they are solvable ones. When solved well, they yield systems that are more robust across lighting conditions and environmental variability, with multiple sensing modalities providing complementary and redundant information.

There is also a broader principle at play. A common argument, often framed as a first-principles view, is that because humans drive using only their eyes, machines should do the same. While that observation is factually true, it does not follow that it is the most principled design constraint for machines. Autonomous systems are not bound by human biology. In many domains, machines achieve superior performance precisely because they use sensing and capabilities that humans do not have. Mimicking human limitations is not a requirement for building the safest or most capable system.

Over time, the cost of additional sensors like LiDAR and radar will continue to fall, as it already has. When viewed against the safety and performance gains they enable, their incremental cost becomes negligible. In that long-run equilibrium, particularly for true Level 4, fully driverless autonomy, I expect the best systems will include multiple sensing modalities.

2 Likes

Yeah, but aligning the video of “thermal”, or “infrared” video with visible spectrum video is quite a bit easier than aligning LiDar or Radar results with camera imaging.

So, while I’d agree that what a human can see should not be the limit of what is attempted to be used for vehicles systems, that doesn’t mean that all forms of other systems are just as useful nor just as easy as others to merge into a cohesive understanding of space.

2 Likes

It’s worth noting that even SAE Level 5 tops out at what a “typically skilled human driver” can do. Additionally:

There may be conditions not manageable by a driver in which the ADS would also be unable to complete a given trip (e.g., white-out snow storm, flooded roads, glare ice, etc.) until or unless the adverse conditions clear. At the onset of such unmanageable conditions the ADS would perform the DDT fallback to achieve a minimal risk condition (e.g., by pulling over to the side of the road and waiting for the conditions to change).

From what I’ve presonally seen with autonomous and semi-autonmous vehicles, from Waymos to Teslas to other brands, is that software is the main problem, not sensor ability to perceive the environment. I’ve personally seen Waymos cross a yellow line into an oncoming traffic lane on a bend to pass a bicyclist, only to encounter a oncoming vehicle! And this when its map should have told it that a dedicated bike lane was upcoming in just a couple hundred feet. Luckily, the oncoming car was able to brake in time to let the Waymo squeeze by. Other vehicles sometimes make bad choices too, but not because they’re not seeing something they should have.

The problem with LiDAR, radar, etc. is that even together, they can’t perceive the whole environment. LiDAR may be able to detect a pedestrian crossing the road in heavy snow/rain, but it can’t tell whether the traffic light is green or red, it can’t see lane markings, construction signs, flashing emergency lights, etc. Autonomous vehicles still need cameras for that, so if the cameras are limited, no amount of additional hardware sensors will be sufficient to continue safe driving. IOW, the vehicle will always be limited by its cameras’ abilities.

A proper autonomous system will recognize when it is not operating within its ODD, and refuse to continue to drive. The question becomes whether LiDAR or other sensor tech provide enough additional information to expand the system’s ODD. Since LiDAR can’t see signs, paint color, light state, etc., the expansion of a system’s ODD is pretty small.

Now, it might still be worth the money and effort to add LiDAR to a fully and properly functioning autonomous system (as prices drop and development matures), but right now software is the main impediment, not hardware.

2 Likes

I don’t claim “just as easy” and neither does Nuro.

In fact, quite the opposite:

Applying foundational principles from statistics and information theory, multiple modalities should be at minimum just as good as a single modality (from a pure information content perspective), and most times better for well-thought sensor fusion.

In another thread, I argued that sensor-fusion can have an analytical processing cost:

Some posters are more amenable and open-minded to other ideas than their own, other posters, not so much.

I don’t “block” other posters, because I don’t want to exclude information, of whatever quality, from my purview.

I’m swayed by what the available data and known theory in machine learning tells us.

I’m much less persuaded by marketing ploys and anecdotes.

One in a million accident rates needed for better-than-human safety in AVs cannot be estimated from anecdotes nor inferred from marketing stunts.

Waymo is doing 4 million true autonomous miles per week, and accelerating. Everyone else, in the US at least, is basically near zero such miles.

That’t the most telling data point on what technological approach actually works today and in the near term.

1 Like

What with Artemis in the news these past few days, I wondered about the original Apollo program. Do we think they used just one kind of sensor so determine acceleration, speed, position, habitability, and so on? I don’t think so. In fact,

Yes, the Apollo Command and Service Module (CSM) utilized multiple, often redundant sensors for propulsion, habitability, and positioning to ensure mission success and crew safety

. Redundancy was a core design principle to prevent single-point failures, particularly in critical navigation and life support systems

For positional guidance, for example, they had both gyroscopes and accelerometers, not to mention telescopes and sextants. There were likewise multiple systems to monitor fuel, fuel intake, attitude, temperature, and more in the propulsions systems.

But doesn’t using multiple sources take a toll on computing power?

A modern smartphone is millions of times more powerful than the, possessing over million times more RAM and processing speeds thousands of times faster. While the AGC operated at ]0.043MHz with roughly 72KB of ROM, today’s phones operate at over 3,000MHz with gigabytes of RAM.

I note that in aerospace, “redundant systems” may refer to two or more identical systems to provide backup in case one fails, but it is also used to refer to two or more different systems which provide the same information in different ways, and it is up to the controlling mechanism to make a judgment on which system to accept or to accept neither and alert the human at the controls.

1 Like

I like this distinction.

Camera and LIDAR will have some level of information redundancy.

Although, one must bear in mind that prior to some months ago the two companies were actually trying to solve different problems – Waymo the taxi problem and Tesla the drive everywhere problem. Tesla’s recent stress on the taxi problem doesn’t really change this difference in focus.

This is, of course, a claim which needs backing by evidence … particularly since there are at least two very different sorts of fusion. One is where the camera is showing you a thin streak of gray and the LIDAR is showing a sharp edge and one fuses into an image of a pole. The other is where the camera and the LIDAR see completely different things and no “fusion” is possible, merely voting which one is right.