Addressing SOTIF with a runtime monitor ensemble for AI-based perception systems

Abstract AI-based environment perception systems are a key enabler of autonomous driving, yet assuring their safety remains a fundamental challenge. Just like human drivers, such perception systems will never be completely safe to use, in the same way as human driving will never be completely safe. Due to the inherent limitations of machine-learned models operating in open and only partially foreseeable environments, complete correctness cannot be guaranteed, making it necessary to argue the absence of unreasonable risk rather than absolute safety. To help with such a proof, the concept of Safety of the Intended Functionality was introduced with ISO norm 21448 (SOTIF), which concerns making a structured safety argument of the correct functioning of a system component of an autonomous vehicle in the operational domain it was designed for. The SOTIF norm defines a set of activities for this purpose, but leaves considerable freedom regarding how such a proof is made. In this paper, we present a conceptual and process-oriented framework that integrates an ensemble of runtime monitors into a SOTIF-oriented development process for AI-based environment perception systems.The proposed monitoring ensemble consists of complementary monitor types that address different sources of uncertainty in perception systems, including inconsistencies between redundant systems, deviations from known input–output behavior, and unfamiliar internal activation patterns. We analyze how these monitors may support selected SOTIF activities, including risk identification, verification and validation, and operational-phase feedback.Rather than providing an implementation or quantitative evaluation, this work focuses on the systematic integration of monitoring into the SOTIF lifecycle and its role in structuring safety arguments. The monitoring ensemble is intended to facilitate the identification of potential near-failure situations, support scenario discovery, and provide additional evidence that may be used when assessing residual risk. As such, it contributes to concretizing the activities in a SOTIF-based development process for AI-based perception systems.

Authors

Institutions

Publication Details

Journal
Discover Artificial Intelligence
Published
2026-09-18
DOI
https://doi.org/10.1007/s44163-026-02186-z
Primary Topic
Safety Systems Engineering in Autonomy
Type
article
Field-Weighted Citation Impact
0.00

Funders

Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Addressing SOTIF with a runtime monitor ensemble for AI-based perception systems

Amit Deshpande, Wissal Guedri, Nour Habib, Ralf Gräfe et al.
Discover Artificial Intelligence
Safety Systems Engineering in Autonomy
article

Addressing SOTIF with a runtime monitor ensemble for AI-based perception systems

Amit Deshpande, Wissal Guedri, Nour Habib, Ralf Gräfe, Rüdiger Ehlers, Iqra Aslam, Syed Sha Qutub, Nikita Maslov, Felix Schaller, Meng Zhang, Andreas Rausch
article en

Abstract

Abstract AI-based environment perception systems are a key enabler of autonomous driving, yet assuring their safety remains a fundamental challenge. Just like human drivers, such perception systems will never be completely safe to use, in the same way as human driving will never be completely safe. Due to the inherent limitations of machine-learned models operating in open and only partially foreseeable environments, complete correctness cannot be guaranteed, making it necessary to argue the absence of unreasonable risk rather than absolute safety. To help with such a proof, the concept of Safety of the Intended Functionality was introduced with ISO norm 21448 (SOTIF), which concerns making a structured safety argument of the correct functioning of a system component of an autonomous vehicle in the operational domain it was designed for. The SOTIF norm defines a set of activities for this purpose, but leaves considerable freedom regarding how such a proof is made. In this paper, we present a conceptual and process-oriented framework that integrates an ensemble of runtime monitors into a SOTIF-oriented development process for AI-based environment perception systems.The proposed monitoring ensemble consists of complementary monitor types that address different sources of uncertainty in perception systems, including inconsistencies between redundant systems, deviations from known input–output behavior, and unfamiliar internal activation patterns. We analyze how these monitors may support selected SOTIF activities, including risk identification, verification and validation, and operational-phase feedback.Rather than providing an implementation or quantitative evaluation, this work focuses on the systematic integration of monitoring into the SOTIF lifecycle and its role in structuring safety arguments. The monitoring ensemble is intended to facilitate the identification of potential near-failure situations, support scenario discovery, and provide additional evidence that may be used when assessing residual risk. As such, it contributes to concretizing the activities in a SOTIF-based development process for AI-based perception systems.

Discover Artificial IntelligenceVol. 6(1)
Intel (Germany) (DE), AMS (Germany) (DE), Clausthal University of Technology (DE), University of Regensburg (DE)
Bundesministerium für Wirtschaft und Klimaschutz
Openalex Percentile: Top 11%
Safety Systems Engineering in Autonomy
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.