VerSACE - Verification Strategies and Safety Assurance of Continuously Evolving Automated Driving Systems.
VerSACE develops methods for the continuous safety assurance of automated driving systems that evolve through frequent software updates. The aim is an industrially adoptable methodology that lets safety assurance keep pace with continuous integration and deployment (CI/CD).
erSACE builds upon the
TADDO2 project
.
Motivation
Modular, service-oriented architectures and continuous integration and deployment (CI/CD) can reduce development costs and shorten time to market for modern, software-centric automotive systems. Advanced driver assistance and automated driving systems (AD(A)S) benefit from these trends, as their complex functionality comes with a need for frequent and fast software updates. Such vehicles are safety-critical cyber physical systems (CPS) that operate in complex open traffic environments which also change over the system life cycle. Modern ADS architectures combine classic model-based algorithms with data-driven approaches.
Assurance cases established before market introduction therefore rest on assumptions that may not hold over time, while classic V&V methods cannot cover every safety-critical scenario a vehicle will encounter in the real world. Current assurance processes are often slow and rely on manual assessments, implying that safety assurance is an activity before start of production.
VerSACE closes the gap between these perceived assurance practices and the high-frequency releases that are enabled by CI/CD approaches. It takes a verification-aware approach to design, coupling design-time safety analyses with pre-deployment testing and after-deployment field data, so that development assumptions stay verifiable across the lifecycle. Making data a first-class citizen of a continuously valid assurance argument lets evidence be generated where it is needed, reducing verification and validation cost without compromising safety.
Project Goals
The methodology builds on five key goals, refined and validated against industrial use cases:
- Modular, contract-based product structures built for safe continuous deployment, including AI- and ML-based functions.
- Forward-planned verification and argumentation that defines the evidence, criteria and methods for several deployment steps ahead.
- A contract-based framework that keeps requirements, verification and the assurance case aligned across abstraction levels and organizational boundaries.
- Falsification techniques — learning-based black- and grey-box testing — that challenge development assumptions and expose risks conventional tests miss.
- Tool support that lets safety cases be partially automated and continuously maintained.
KTH Mechatronics Contributions
WP2 · Evolutionary product–argumentation–verification
Modelling for change impact analysis
An automated driving system evolves throughout its life, for instance when a sensor is replaced or the platform changes. Such a change can propagate to the functionality, the system architecture, the information and data models, the required test cases, and the assurance case. KTH contributes to methods to trace which artefacts a change affects and to assess its consequences within a CI/CD pipeline, together with the capabilities and metrics needed to plan and evaluate such changes.
WP3 · Data architecture (lead)
Connecting semantic ODD concepts to recordable operational data
Field evidence confirms or falsifies the assumptions behind a safety claim, provided the data recorded in operation can be tied back to the concepts used at design time. KTH contributes to the design of data architectures and metadata formats that map the semantic vocabulary of the operational design domain and the expected system behavior onto measurable data in the field. Once this link exists, field evidence can be matched to specific assurance claims, and data-collection campaigns can be limited to the evidence a release requires.
Project Facts
KTH Contacts:
Marcus Nolte
and
Martin Törngren
Main project manager: Stina Carlsson (Volvo Cars)
Scientific coordination: KTH
Funding: Vinnova, FFI programme (Safe Automated Driving)
Project duration: Two years (2026–2028)
Project partners: AdamAI, Aptiv, Chalmers, KTH, Lund University, Magna Electronics, RemotiveLabs, Traton, Volvo Cars, Zenseact