{"id":"2706bb47-aecf-4b0c-84a8-6a598d34ea9e","arxiv_id":"2504.18328","paper_version":1,"verdict":"ACCEPT","confidence":"HIGH","novelty_score":4.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"A comprehensive survey concluding that AI safety assurance for automated vehicles should move from rule-based to data-driven, lifecycle-oriented methods, supported by a review of research, standards, and regulation.","lead":"This survey maps the current landscape of AI safety assurance for automated vehicles across research, standardization, and regulation, and argues that safety assurance must shift toward data-driven methods. It is a useful reference for researchers, safety engineers, and regulators who need a compact, holistic view of a fast-moving field.","discovery_kind":"review","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The survey's central claim that data-driven safety assurance is 'necessary' rests on the Section III.A premise that formal closed-form safety arguments for AI are contradictory; maturing neural-network verification methods challenge this premise, so the necessity claim is overstrong.","rationale":"The reader's weakest_assumption correctly identifies the Section III.A premise about formal closed-form solutions as the load-bearing point. My analysis agrees and sharpens the concern: the paper moves from 'formal closed-form assurance appears contradictory' to 'data-driven assurance is mandatory,' but the premise is contestable given the current state of neural-network verification, and the paper's own citation of ISO/IEC 24029-2:2023 (a formal-methods standard) undercuts any reading of absolute impossibility. The paper is a survey and position paper, not a proof of impossibility, so the central claim should be framed as a currently justified direction rather than a logical necessity. This does not warrant rejection, because the survey is comprehensive, well-organized, and valuable as a synthesis; however, the overstatement in the central claim is substantive enough that a conditional acceptance is appropriate: the authors should qualify the 'necessary' conclusion (e.g., to 'currently necessary given the state of the art') and engage explicitly with the possibility that scalable formal verification could provide a complementary assurance route. The concrete test proposed would settle whether the premise holds by checking the current empirical capabilities of formal verification on realistic AD components; if formal verification succeeds on such components, the argument for necessity loses its force and the paper would need revision. The concern is made in good faith, is directed at the argument rather than the authors, and is based on evidence cited within the paper itself plus established results in the verification community.","tokens_in":34191,"tokens_out":4257,"duration_ms":41381,"concrete_test":"Survey the neural-network verification literature, especially VNN-COMP results from 2021 to 2024, and identify the largest verified neural network used in an automated-driving perception or planning task (by parameter count and input dimensionality). If any such network is verified for a safety-relevant property (e.g., robustness to a specified input perturbation set, or satisfaction of a safety invariant) at a realistic subsystem scale, then the Section III.A premise that a formal closed-form solution is 'contradictory' is shown to be too strong.","verdict_should_be":"CONDITIONAL","load_bearing_attack":"The paper's central recommendation in Section VII ('The extension of familiar assurance methods, such as functional assurance to data-based functional assurance, as well as the transition from rule-based to data-based assurance are necessary') depends on the premise stated in Section III.A: 'Given that AI systems are designed to map highly complex, non-trivial relationships, the notion of a general, formal, closed-form solution appears contradictory.' This premise is used to conclude that 'regardless of the chosen safety approach, a data-based or data-dependent safety assurance approach is mandatory.' But the premise is a conjecture, not a demonstrated impossibility. Formal verification of neural networks has made measurable progress: SMT-based and abstract-interpretation tools, including those underlying ISO/IEC 24029-2:2023 which the survey itself cites, can certify robustness and other safety-relevant properties for networks of non-trivial size, and there are published examples of formally verified neural network controllers (e.g., ACAS Xu for aircraft collision avoidance). If such methods scale to the perception and planning networks used in automated driving, then assurance need not be exclusively data-driven; 'necessary' would weaken to 'currently advisable given today's verification limits.' Moreover, the paper itself acknowledges in Section VI that 'how a data-based analysis of AI systems can be conducted so that reliable statements about safety can be made' remains unresolved, so the proposed alternative is not yet a demonstrated replacement. The concern is not that the survey's direction is wrong, but that the central claim overstates the logical status of the recommendation relative to the evidence presented.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"This survey jointly reviews research, standardization, and regulation for AI safety assurance in automated vehicles. It argues that current assurance methods are inadequate for AI-based systems and recommends a shift toward data-driven safety assurance over the full lifecycle, with data as the central element. The paper is organized around three pillars: AI safety research (Section III), AI safety standardization (Section IV, including ISO 26262, ISO 21448, ISO/IEC TR 5469, ISO/IEC 24029-2, and the work-in-progress landscape in Table III), and AI regulation (Section V, covering the EU AI Act, US federal and state actions, China, and several other countries). Section VI lists open questions, and Section VII states the paper's perspective that rule-based assurance must transition to data-based assurance.","tokens_in":34433,"tokens_out":9646,"duration_ms":93568,"significance":"The paper's strength is its holistic, well-referenced synthesis: it connects research, standardization, and regulation in a way that earlier surveys do not, and its account of the EU AI Act timeline and the standards landscape is accurate. The authors are explicit that the central recommendation is a perspective ('in our perspective') and they acknowledge in Section VI that a general method for data-based safety analysis is not yet available. The survey thus offers a useful orientation and research agenda rather than a formal proof, which is appropriate for its genre. The paper does not provide machine-checked proofs or quantitative predictions, and it does not need to; its value lies in the structured map of the field and the clearly stated thesis.","major_comments":[],"minor_comments":[{"comment":"The words 'mandatory' in Section III.A and 'necessary' in Section VII are stronger than the immediately hedged premise ('appears contradictory') and than the survey's own acknowledgment in Section VI that no general breakthrough in data-based safety analysis is yet apparent; please temper these terms to 'currently necessary given the state of the art' or 'necessary in the authors' assessment' so that the claim is not read as ruling out scalable formal verification in principle.","section":"Section III.A / VII"},{"comment":"Section VI explicitly leaves open how a data-based analysis of AI systems can yield reliable safety statements and states that no general breakthrough is apparent; the conclusion should explicitly connect this to the 'necessary' phrasing by describing data-based assurance as a necessary research direction rather than an established method.","section":"Section VI"},{"comment":"The paragraph beginning 'Overall, as it can be seen from Table III...' is duplicated almost verbatim by the following paragraph beginning 'Overall, as shown in Table III...'; one of the two should be deleted.","section":"Section IV.C"},{"comment":"In the discussion of the European Parliament's June 2023 position, the sentence beginning 'The most important adjustments include...' is repeated verbatim after 'Beyond that, another crucial adjustment is...'; please remove the duplicate.","section":"Section V.A"},{"comment":"There are several typos: 'troughout' should be 'throughout', 'emphasiszed' should be 'emphasized', 'Publicil' (reference [177]) should be 'Public', 'Morover' in Section IV.B should be 'Moreover', and 'and the and the final part' in Section V.A should read 'and the final part'.","section":"Section V.B"},{"comment":"The phrase 'in accordance with the title, twice' is unclear; please rephrase to state explicitly which standards have titles that address data.","section":"Section IV.C"},{"comment":"In Table II, 'A VP' in the title of ISO/TS 23374-2 should be 'AVP'.","section":"Table II"}],"recommendation":"minor_revision","confidential_remarks":"I see no citation-pattern concerns: the only self-citation ([112]) is peripheral and does not support a central claim. The paper is already published in IEEE TIV; this report treats the arXiv version as the submitted manuscript. The fit with a journal on intelligent vehicles is appropriate."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Quick take: this is a competent and genuinely useful survey, and the reader's ACCEPT verdict is reasonable. The three-pillar structure — research, standardization, regulation — fills a real gap; most surveys stop at one. The standards tables (I–III) are thorough and current, with work-in-progress standards included, and the regulation overview (EU AI Act timeline, US state patchwork, China) is accurate and well sourced. If you need a compact map of this landscape, this is a good place to start.\n\nWhat the paper does well: it reads the interdependencies between the three pillars rather than listing them separately. The argument that data dependency undermines classical functional-safety assumptions is made clearly, and the call for lifecycle-oriented, data-based assurance is well grounded in cited literature. The paper is also honest about its own open questions — Section VI explicitly asks how data-based analysis can yield reliable safety statements and admits no general breakthrough exists.\n\nThe soft spot is the one the stress-test flags. The necessity claim in Section VII ('transition from rule-based to data-based assurance is necessary') rests on the Section III.A premise that a general, formal, closed-form safety argument for AI 'appears contradictory.' That is a conjecture, not a demonstrated impossibility. Neural-network verification has matured — SMT and abstract-interpretation tools, including those in ISO/IEC 24029-2:2023, which the paper cites, can certify robustness for nontrivial networks, and there are verified controllers (ACAS Xu) in aerospace. So 'necessary' overstates the case; 'currently the most practical path given today's verification limits' would be more accurate. The paper's own admission that data-based assurance is not yet a demonstrated replacement cuts both ways — it makes the proposal honest, but it weakens the 'mandatory' framing. For a survey/position paper, this is a fixable calibration issue, not a fatal flaw.\n\nMinor issues: a duplicated passage in Section V-A (the Parliament amendments paragraph repeats itself), and a few typos ('Morover', 'troughout'). Nothing that affects the substance.\n\nWho it's for: graduate students, safety engineers, and researchers wanting a quick orientation in AV AI safety standards and regulation. It won't change your research direction unless you work in this area, but it's a solid reference. I'd bring it to reading group and would cite it for the standards overview.\n\nRecommendation: yes, it deserves peer review — and it already went through it at IEEE TIV. If this were a fresh submission, I'd send it out and ask the authors to soften the necessity claim to a conditional agenda and merge the duplicated paragraph.","headline":"A solid, useful survey of AV AI safety assurance across research, standards, and regulation; the 'data-driven assurance is necessary' thesis is a well-argued agenda but overstates its logical status.","tokens_in":34979,"tokens_out":2784,"would_cite":true,"duration_ms":26065,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"AI safety assurance for automated vehicles must become data-driven and lifecycle-wide, not rule-based and design-time.","keywords":["AI safety assurance","automated vehicles","data-driven assurance","functional safety","SOTIF","AI lifecycle","standardization","regulation"],"falsifier":"A concrete demonstration that a production-scale neural network used in automated driving, such as a perception or trajectory-prediction model, can be formally verified to satisfy safety properties across its full operational data distribution would falsify the premise that a general closed-form solution is contradictory; conversely, showing that such verification remains intractable or incomplete would support the paper's case.","tokens_in":34003,"feed_emoji":"🚗","tokens_out":5907,"duration_ms":56418,"temperature":0.7,"pith_summary":"This paper argues that safety assurance for AI-based automated vehicles cannot remain a design-time, rule-based exercise. Because modern AI systems learn implicit, data-dependent relationships, the authors maintain that a general, formal, closed-form safety proof is contradictory, so assurance must become data-driven and lifecycle-wide. The survey reaches this conclusion by jointly reviewing safety research, standardization, and regulation, and it identifies data dependency, lifecycle consideration, and safety abstraction as the three core features any future assurance approach must address. If the argument is right, future safety cases will center on data quality, data lifecycle, and operational monitoring rather than only on inherited functional-safety artifacts.","feed_headline":"AV safety assurance must shift from rules to data","feed_subtitle":"Safety cases for AI-driven cars must center on data quality and lifecycle monitoring, not just design checks.","key_machinery":"The central mechanism is the idea of data-driven AI safety assurance, defined as an assurance approach that builds on implicit assumptions embedded in data and on data-based verification and validation of those assumptions, extending to data-based system analysis over the lifecycle. Its named counterparts are functional safety and SOTIF, which the paper proposes to extend into data-based functional safety and data-based SOTIF, together with the emerging AI-SIL classification. This mechanism does the work of turning the premise that AI systems are implicit and data-dependent into a constructive alternative: assurance becomes a repetitive cycle of exploration, observation, and mitigation, supported by out-of-distribution detection, simulation-based validation, and periodic offline updates.","core_discovery":"The central discovery is the thesis that safety assurance for automated vehicles must shift from rule-based, design-time methods to data-based assurance across the entire AI lifecycle. On the paper's own terms, familiar assurance methods such as functional safety and SOTIF should be extended into data-based functional safety and data-based SOTIF, with data itself pivotal. The authors ground this in the observation that AI behavior is determined both by training data and by operational data, and that fine-tuning or updates invalidate earlier proofs, so verification and validation must become a repetitive cycle of exploration, observation, and mitigation. They also contend that the current gap in automotive standardization and the heterogeneity of global regulation make this shift necessary for any practical deployment, and they propose non-legally-binding open standards and closer networking of research, standardization, and regulation as the way forward.","pith_inferences":["If data-driven assurance becomes the norm, a safety case becomes a living artifact that must be re-established after every retraining or over-the-air update, turning certification into a continuous process rather than a one-time event.","Operational data collection would become a regulatory requirement, which will likely conflict with privacy rules and data-sharing incentives; a useful test is whether fleet-wide data pooling can support assurance without introducing new biases or liability.","The paper's conclusion depends on the infeasibility of formal closed-form assurance; if scalable formal verification for neural networks matures, the necessity of the data-driven shift weakens, though data-driven monitoring may still be needed as a complement.","A concrete extension would be a side-by-side safety case for one perception function, one built on data-driven out-of-distribution monitoring and one on formal verification of a simplified model, tested against the same distribution shift to see which assurance style degrades more gracefully."],"forward_implications":["Future safety cases for automated vehicles will center on data quality, data lifecycle, and operational monitoring, not only on design-level functional safety.","Functional safety and SOTIF standards would need to be extended into data-based functional safety and data-based SOTIF, following the direction already sketched by the AI-SIL concept.","Regulatory approval would become iterative: periodic offline updates and continuous monitoring would replace one-time certification, analogous to regular vehicle technical inspections.","Standardization bodies would need to accelerate automotive-specific AI standards that address data and lifecycle, since general AI standards are ahead of automotive ones.","A technology-agnostic, data-centered methodology would let safety methods transfer across AI architectures and hardware, accommodating future innovations."],"supporting_citations":[{"why":"Supplies the baseline list of unresolved AI safety challenges that the paper argues are still present for modern systems.","marker":"[7]"},{"why":"Provides the systematic literature review of AI safety assurance that frames the paper's state-of-the-art assessment and open research questions.","marker":"[10]"},{"why":"Establishes that AI system behavior depends on development and operational data, supporting the paper's data-dependency premise.","marker":"[30]"},{"why":"Addresses uncertainty in the safety assurance of machine learning and assigns greater importance to input data, a step the paper builds on.","marker":"[45]"},{"why":"Serves as the functional safety backbone that the paper argues must be extended into data-based functional safety.","marker":"[46]"},{"why":"The SOTIF standard, which the paper says provides useful safety abstraction but does not sufficiently address AI data challenges.","marker":"[47]"},{"why":"Introduces the AI-SIL concept, which the paper cites as a first positive example of transformation toward future data-driven assurance.","marker":"[67]"},{"why":"Provides the analysis of complexity and uncertainty gaps in automated driving assurance that the paper agrees with but answers with a different solution.","marker":"[68]"},{"why":"Argues that neither functional safety nor SOTIF sufficiently addresses AI-based automotive systems, reinforcing the paper's call for a fundamental methodological shift.","marker":"[146]"}],"fun_headline_variants":["Data-driven assurance: the new AV safety paradigm","AV safety must pivot to data-based assurance","From rule-based to data-based: AV safety shift","AV safety assurance: data is the new rulebook","AV safety must be data-driven across AI lifecycle"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The argument hinges on the premise that a general, formal, closed-form safety proof for AI systems is contradictory because these systems implicitly map highly complex, non-trivial, data-dependent relationships; if scalable formal verification for neural networks matures, the necessity of the data-driven shift is weakened.","fun_headline_variants_meta":{"raw":{"variants":["Data-driven assurance: the new AV safety paradigm","AV safety must pivot to data-based assurance","From rule-based to data-based: AV safety shift","AV safety assurance: data is the new rulebook","AV safety must be data-driven across AI lifecycle"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000628,"raw_usage":{"total_tokens":2880,"prompt_tokens":901,"completion_tokens":1979,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":517,"completion_tokens_details":{"reasoning_tokens":1907}},"tokens_in":517,"tokens_out":1979,"duration_ms":12419,"temperature":1.0,"reasoning_tokens":1907,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-16T10:18:18.730542+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"A concrete demonstration that a production-scale neural network used in automated driving, such as a perception or trajectory-prediction model, can be formally verified to satisfy safety properties across its full operational data distribution would falsify the premise that a general closed-form solution is contradictory; conversely, showing that such verification remains intractable or incomplete would support the paper's case.","supporting_citations":[],"review_version":1}