Fault-Tolerant Model Predictive Control Algorithm for Path Tracking of Autonomous Vehicle

The fault detection and isolation are very important for the driving safety of autonomous vehicles. At present, scholars have conducted extensive research on model-based fault detection and isolation algorithms in vehicle systems, but few of them have been applied for path tracking control. This paper determines the conditions for model establishment of a single-track 3-DOF vehicle dynamics model and then performs Taylor expansion for modeling linearization. On the basis of that, a novel fault-tolerant model predictive control algorithm (FTMPC) is proposed for robust path tracking control of autonomous vehicle. First, the linear time-varying model predictive control algorithm for lateral motion control of vehicle is designed by constructing the objective function and considering the front wheel declination and dynamic constraint of tire cornering. Then, the motion state information obtained by multi-sensory perception systems of vision, GPS, and LIDAR is fused by using an improved weighted fusion algorithm based on the output error variance. A novel fault signal detection algorithm based on Kalman filtering and Chi-square detector is also designed in our work. The output of the fault signal detector is a fault detection matrix. Finally, the fault signals are isolated by multiplication of signal matrix, fault detection matrix, and weight matrix in the process of data fusion. The effectiveness of the proposed method is validated with simulation experiment of lane changing path tracking control. The comparative analysis of simulation results shows that the proposed method can achieve the expected fault-tolerant performance and much better path tracking control performance in case of sensor failure.


Introduction
Fault signal detection and isolation, as well as fault-tolerant control systems, are important contents in the research field of autonomous vehicle and prerequisites for ensuring the driving safety in complex traffic scenarios. The failure of autonomous vehicles mainly occurs in the process of sensing information acquisition and motion state transmission. Fault detection and isolation algorithms are widely used in various unmanned systems, such as ground autonomous vehicles [1], underwater robots [2], and autonomous helicopters [3]. For autonomous vehicle systems, fault signal detection and isolation algorithms play an important role in autonomous environment perception, decision making, and motion control. In order to effectively detect and isolate fault signals and perform stable motion control, many schemes and technologies have been proposed, which can be divided into: the nonlinear algorithms [4] and the linear algorithms [5,6]. With the continuous development of autonomous vehicle technology, the types and number of on-board sensors also continue to increase, and the fault sensor signals have become the main reason for vehicle failure [7][8][9].

Modeling and Problem Linearization
The impacts of the vehicle suspension characteristics are relatively small in relation to the research content of vehicle motion control. In this work, the vehicle-tire model is selected, which means no in-depth research on the characteristics of vehicle suspension. At the same time, the dynamic model established in this paper is mainly used to design the predictive model in the model predictive controller. It is required to simplify as much as possible on the basis of more accurately describing the vehicle's dynamic characteristics and reducing the amount of calculation. The following idealized assumptions are first proposed when performing dynamic modeling: (1) Ignoring road fluctuations and assuming that the vehicle is always driving on a flat road without vertical motion; (2) Ignoring suspension motion and the effect of the suspension structure on the coupling relationship; (3) The load movement of the front and rear axles is not considered, and the left and right transfer of the load is ignored; (4) Only the tire cornering characteristics are considered, and the vertical and horizontal coupling relationships are ignored; (5) Mechanical effects of steering system are also ignored. In this paper, a 3-degree-of-freedom single-track vehicle dynamics model is constructed, including longitudinal motion, lateral motion, and yaw (see Figure 2).

Modeling and Problem Linearization
The impacts of the vehicle suspension characteristics are relatively small in relation to the research content of vehicle motion control. In this work, the vehicle-tire model is selected, which means no in-depth research on the characteristics of vehicle suspension. At the same time, the dynamic model established in this paper is mainly used to design the predictive model in the model predictive controller. It is required to simplify as much as possible on the basis of more accurately describing the vehicle's dynamic characteristics and reducing the amount of calculation. The following idealized assumptions are first proposed when performing dynamic modeling: (1) Ignoring road fluctuations and assuming that the vehicle is always driving on a flat road without vertical motion; (2) Ignoring suspension motion and the effect of the suspension structure on the coupling relationship; (3) The load movement of the front and rear axles is not considered, and the left and right transfer of the load is ignored; (4) Only the tire cornering characteristics are considered, and the vertical and horizontal coupling relationships are ignored; (5) Mechanical effects of steering system are also ignored. In this paper, a 3-degree-of-freedom single-track vehicle dynamics model is constructed, including longitudinal motion, lateral motion, and yaw (see Figure 2).

Modeling and Problem Linearization
The impacts of the vehicle suspension characteristics are relatively small in relation to the research content of vehicle motion control. In this work, the vehicle-tire model is selected, which means no in-depth research on the characteristics of vehicle suspension. At the same time, the dynamic model established in this paper is mainly used to design the predictive model in the model predictive controller. It is required to simplify as much as possible on the basis of more accurately describing the vehicle's dynamic characteristics and reducing the amount of calculation. The following idealized assumptions are first proposed when performing dynamic modeling: (1) Ignoring road fluctuations and assuming that the vehicle is always driving on a flat road without vertical motion; (2) Ignoring suspension motion and the effect of the suspension structure on the coupling relationship; (3) The load movement of the front and rear axles is not considered, and the left and right transfer of the load is ignored; (4) Only the tire cornering characteristics are considered, and the vertical and horizontal coupling relationships are ignored; (5) Mechanical effects of steering system are also ignored. In this paper, a 3-degree-of-freedom single-track vehicle dynamics model is constructed, including longitudinal motion, lateral motion, and yaw (see Figure 2).   The longitudinal force, lateral force, and yaw motions of the vehicle can be written as: where m is the vehicle mass; ϕ is the yaw angle; x and y are the longitudinal and lateral position, respectively; δ f is the front wheel rotation angle; I z is the z-axis moment of inertia; F x is the total longitudinal force on the vehicle; F y is total lateral force on the vehicle; M z is the total yaw moment on the vehicle; F c f , F cr are the lateral forces on the front and rear tires of the vehicle, and are related to the corner stiffness and corner angle of vehicle tires; F l f , F lr are longitudinal forces on the front and rear tires of the vehicle, which are related to the longitudinal stiffness and slip rate of the tire; F x f , F xr are the forces on the front and rear tires in the x direction; F y f , F yr are the forces on the front and rear tires in the y direction; L f and L r are the distances from the front and rear axis to the center of mass.
According to Equation (1), the vehicle dynamics model involves vehicle tire forces. The longitudinal and lateral forces are related to vertical load, road friction coefficient, slip rate, and tire corner angle: where F z is the vertical load; s is the slip rate; µ is the road surface adhesion coefficient; α is the tire cornering angle; w t is the wheel speed; r is the wheel radius; v l is the longitudinal speed; and v c is the lateral speed, which can be expressed by v x and v y : Generally, the tire speed of a vehicle is difficult to obtain directly, which can be obtained by calculating the vehicle speed: x v xr = .
x (4) When constructing the vehicle dynamics model, the front and rear axle load movements have been ignored. Therefore, the vertical load on the front and rear wheels of the vehicle can be calculated as: Generally, a vehicle in a stable driving state has a small variation angle and a slip rate. According to the Semi-Empirical Tire-Model [23], we know that the tire dynamics, including the tire longitudinal force, the tire lateral force, and the tire aligning torque, have obvious nonlinear characteristics, but the simulation results in References [24,25] show that the tire forces can be approximated by a linear equation when the longitudinal slip rate and the tire variation angle change in a small range. In addition, there are a large number of trigonometric functions in the vehicle dynamics model. Since each angle involved in the dynamics model is in a small angle interval, each trigonometric function can satisfy the following approximate conditions: cosθ ≈ 1, sinθ = 0, tanθ = θ. After introducing Sensors 2020, 20, 4245 5 of 20 the corner stiffness, corner angle, longitudinal stiffness, and slip rate, the tire force of the vehicle can be expressed as: where C c f , C cr are the lateral stiffness of the front and rear tires; C l f , C lr are the longitudinal stiffness of the front and rear tires; S f , S r are the slip ratio of the front and rear tires. Nonlinear vehicle dynamics model can be written as: x sin ϕ + . y cos ϕ . X = .
x cos ϕ − . y sin ϕ For the convenience, ξ dyn = . x, ϕ, X, Y T are system state quantities and u dyn = δ f is the system control quantity.

Linearization of Vehicle Dynamics Model
For autonomous vehicle, the lateral motion control is to control the front wheel rotation angle, and then realize path tracking. Therefore, this paper selects path tracking as the ultimate goal of autonomous vehicle lateral control, and the tracking accuracy as the main indicator to measure the performance of the control system. Model predictive control can be divided into linear time-varying model predictive control (LMPC) [26] and nonlinear model predictive control (NMPC) [27]. Compared with NMPC, the LMPC uses the linear predictive model and has better real-time performance, which is a very important character for the motion control of autonomous vehicles. Thus, the LMPC is used in this work.
The vehicle model established in this work is a nonlinear model, which needs to be linearized. The state quantity and control quantity of the system satisfy the following relationship: . ξ r = f (ξ r , u r ) (8) Perform Taylor expansion at (ξ r , u r ), retain the first-order terms, and ignore the higher-order terms, we get: The formula can be transformed into: .
Discrete the above formula using the first-order difference quotient method to obtain the discrete state space equation: where A(k) = I + TA(t), B(k) = I + TB(t), and T is sampling time.
After introducing the incremental model, the state-space equation can be written as:

Construct the Objective Function
This paper uses the following objective function: where ρ is the weight coefficient; ε is the relaxation factor; N p is the prediction time domain and N c is the control time domain; Q is the state weighting matrix; R is the control weighting matrix; ∆η(k + i k) is output deviation; and ∆u(k + i k) is control deviation.
Since the vehicle dynamic model is used and the number of constraints is increased, in order to avoid the occurrence of no optimal solution, a relaxation factor ε is added to the objective function.

Construct the Constraints
The most prominent feature of the model predictive control is that it can easily handle the multi-constraint problem. In order to ensure that the reference path can be smoothly tracked, this paper uses the front wheel declination constraint, the front wheel declination incremental constraint, and the tire lateral angle dynamic constraints.

Front Wheel Declination and Its Incremental Constraints
Restrictions on the front wheel deflection angle and front wheel deflection angle of the vehicle can be set according to the actual physical parameters of the vehicle. The control quantity constraint expression is: The expression of the incremental constraints is: In the objective function and constraints, the optimized variable is the control quantity increment in the control time domain. Therefore, the control variable must first be converted into the matrix form of ∆u.
The relationship between the control increment and the control quantity can be obtained: Convert Equation (18) The constraints of control quantity and control increment ensure that the control output generated by the model prediction controller is physically achievable, but for driving safety and comfort, the dynamic constraints of the vehicle also need to be introduced.

Dynamic Constraint of Tire Cornering
The vehicle sideslip due to wet or slippery roads may cause various accidents. Therefore, it is particularly important to increase vehicle dynamics constraints and reduce the possibility of vehicle sideslip.
The sideslip of the vehicle is closely related to the tire slip angle. When the vehicle runs straight on a horizontal road, the tire slip angle α = 0; when the tire is elastically deformed by lateral force without lateral slip, α ≤ α max ; when the tire is subjected to excessive lateral force, the vehicle slips, α > α max . It can be concluded that the slip angle of the vehicle tire directly reflects whether the vehicle is slipping, and limiting the tire slip angle limits the occurrence of sideslip.
Since the established vehicle dynamics state-space equation does not take the tire slip angle as a state quantity and cannot directly constrain the tire slip angle, this paper needs to find the relationship between the tire slip angle α and the state quantity ξ(k,t). The relationship is to restrain the tire slip angle by imposing a specific relationship constraint on the state quantity.
By Equations (2)-(4), the available tire front and rear wheel angles are: y Sensors 2020, 20, 4245 8 of 20 Using ξ dyn as the state quantity and u dyn as the control quantity, linearize the above formula to obtain: where α = α f , α r T is the tire corner angle matrix, F = [−1, 0] T is the direct transfer matrix, and E is the output matrix.
Based on the above objective function and constraints, the optimization problem of the controller can be described as: Solving the above formula can get the incremental sequence of control input in each control time domain: Apply the first element of the incremental sequence to the controller as the actual input increment: Repeating the above process, the optimal control input to the front wheel angle can be obtained.

Multi-Sensor Information Data Fusion and Fault Signal Isolation
If multi-sensors are used to measure one vehicle motion parameter, we can fuse the outputs of all sensor system using the weight assignment method [28], which can be written as follows: where O is the result of data fusion; W = [w 1 , w 2 , · · · , w n ] is the weight matrix; I = [i 1 , i 2 , · · · , i n ] T is outputs of each sensor; n is the number of sensors; and M is fault detection matrix. The principle of the method can be written as follows: where σ i and σ j are the output error dispersion of the i-th and j-th sensors; i, j = 1, 2, . . . n.
The true values of vehicle motion states cannot be obtained, and the traditional methods determine the average value of the different sensors outputs as the true value. However, these methods are not suitable in our situation, since different sensors in different conditions can give a deliberately low accuracy or even failure; due to this reason, the average value may have a large difference with the true value, which is extremely harmful to vehicle safety. If at moment k, the sensor j gives the measured value T j (k), then: where ∆T j (k) is the measurement error of the j-th sensor at time k; ∆T j is the average value of the j-th sensor at moment k; σ j (k) is the variance of the output error of the j-th sensor at time k;T j (k) is prognostic assessment obtained using the Kalman filter; N is the number measurements from each sensor. Since the following filtering process includes the isolation of unreliable data sources and error correction, we can approximately consider the estimated information as the true value.  and are the output error dispersion of the i-th and j-th sensors; , = 1,2, … . The true values of vehicle motion states cannot be obtained, and the traditional methods determine the average value of the different sensors outputs as the true value. However, these methods are not suitable in our situation, since different sensors in different conditions can give a deliberately low accuracy or even failure; due to this reason, the average value may have a large difference with the true value, which is extremely harmful to vehicle safety.

Fault Signal Detector Design
If at moment k, the sensor j gives the measured value ( ) , then: where ∆ ( ) is the measurement error of the j-th sensor at time k; ∆ is the average value of the jth sensor at moment k; ( ) is the variance of the output error of the j-th sensor at time k; ( ) is prognostic assessment obtained using the Kalman filter; N is the number measurements from each sensor. Since the following filtering process includes the isolation of unreliable data sources and error correction, we can approximately consider the estimated information as the true value.  Each filter in this detector is standard, we take the Sub_Kalman_Filter_1 for GPS signal channel as an example. The state vector and measurement vector can be written as:

Fault Signal Detector Design
The state-space and measurement-space equations of Kalman Filter from moment k-1 to moment k can be written as: Each filter in this detector is standard, we take the Sub_Kalman_Filter_1 for GPS signal channel as an example. The state vector and measurement vector can be written as: The state-space and measurement-space equations of Kalman Filter from moment k − 1 to moment k can be written as: where F GPS,k is the state transition matrix, W GPS,k is the process noise, H GPS,k is the measurement transition matrix, and v GPS,k is the measurement noise. The equations of Kalman Filter can be written as: where P GPS,k|k is covariance matrix, K GPS,k is the gain matrix, Q GPS,k is the process noise covariance matrix, and R GPS,k is the measurement noise covariance matrix. The equation of state propagator can be written as: The χ 2 test method is widely used to detect faults in stochastic dynamic systems based on correspondence between the observed and reference signals [29]. This method can be divided into three types: χ 2 test for residual error; χ 2 test for state with a single state propagator; χ 2 test for state with double state propagators. These methods have their own advantages and disadvantages: (1) If the test statistics are calculated using the residual error, it is almost impossible to detect the fault in the state transfer process, although the fault of the sensors can be easily detected; (2) If the test statistics are calculated using the state vector, it is possible to detect the fault in the state transfer process and to evaluate the fault of the sensor indirectly. If only one state propagator is used for correction of the state prediction error, the error accumulates and may diverge with time increases; (3) If two state propagators are used and alternately reset the outputs, then accumulation of errors can be avoided. However, for this method, if M sub-filters are used, then 2M state propagators should be used, which not only complicates the structure of the algorithm but also affects the speed of calculations.
It can be seen that these methods have their advantages and disadvantages. In this work, a novel robust fault detector is proposed with a structure that simultaneously implements a χ 2 test for residual error and a χ 2 test for state. Double state propagators are used only for the main Kalman filter (see Figure 3), which allows to simplify the structure of the algorithm and increase the speed of calculations. As an example, Figure 4 shows the diagram of the Fault_Dignal_Detector_1.
where , | is covariance matrix, , is the gain matrix, , is the process noise covariance matrix, and , is the measurement noise covariance matrix. The equation of state propagator can be written as: The test method is widely used to detect faults in stochastic dynamic systems based on correspondence between the observed and reference signals [29]. This method can be divided into three types: test for residual error; test for state with a single state propagator; test for state with double state propagators. These methods have their own advantages and disadvantages: 1) If the test statistics are calculated using the residual error, it is almost impossible to detect the fault in the state transfer process, although the fault of the sensors can be easily detected; 2) If the test statistics are calculated using the state vector, it is possible to detect the fault in the state transfer process and to evaluate the fault of the sensor indirectly. If only one state propagator is used for correction of the state prediction error, the error accumulates and may diverge with time increases; 3) If two state propagators are used and alternately reset the outputs, then accumulation of errors can be avoided. However, for this method, if M sub-filters are used, then 2M state propagators should be used, which not only complicates the structure of the algorithm but also affects the speed of calculations.
It can be seen that these methods have their advantages and disadvantages. In this work, a novel robust fault detector is proposed with a structure that simultaneously implements a test for residual error and a test for state. Double state propagators are used only for the main Kalman filter (see Figure 3), which allows to simplify the structure of the algorithm and increase the speed of calculations. As an example, Figure 4 shows the diagram of the Fault_Dignal_Detector_1.  As long as one test channel detected a fault, it can be considered as fault signal. In addition, since the state vectors of all filters are the same, we use only two state propagators. Derive the state χ 2 test with two state propagators and define error state vectors as: where X k is true state vector,X GPS,k is estimation from Sub_Kalman_Filter_1 for GPS signal channel, andX i,k is estimation error from state propagator i. In this paper, we consider the following variable to detect fault signal from Sub_Kalman_Filter_1 for GPS signal channel: Sensors 2020, 20, 4245 11 of 20 The variance of this variable can be written as: T GPS,k = E β GPS,k β T GPS,k = E e GPS,k e T GPS,k − e GPS,k e T i,k − e i,k e T GPS,k + e i,k e T i,k = P GPS,k − P GPS_i,k − P i_GPS,k + P i,k where P GPS_i,k and P i_GPS,k is the cross-covariance. We set the same initial conditions for the Sub_Kalman_Filter_1 for GPS signal channel and the state propagator i, then we can obtain P GPS_i,k = P i_GPS,k = P i,k , therefore, the variance can be written as: Define the fault detection function: The fault decision criteria can be written as: where the threshold ε β is determined by the function of false alarm rate based on statistical results.
In this paper, we use the state χ 2 test with two state propagators. The working principle can be described as follows: during period t k a fault occurs and the switch K 1 is located at position " L 1 ", switch K 2 is located at position " L 2 ", the output of State_Propagator_1 is uncorrected due to this fault, but the output of State_Propagator_2 is obtained using the previous correct state, which can be used for fault correction. During period t k+1 , errors in State_Propagator_1 are corrected using the outputs of Kalman filter. After a time period ∆t, the K 1 switch is located at position "L 2 ", the switch K 2 is located at position "L 1 ", and the State_Propagator_2 is used to correct the fault.
Test χ 2 residual error of Sub_Kalman_Filter_1 can be written as: Covariance residual error: Define the fault detection function: Fault decision criteria can be written as: where the threshold ε d is determined by the function of false alarm rate based on statistical results. If the state χ 2 test or the residual error χ 2 test detected a fault, then m g = 0, otherwise m g = 1.

Working Conditions Description
In order to verify the feasibility and effectiveness of the proposed method, the Driving Scenario Designer was used to build a simulated driving environment with two straight lanes, and the reference path and yaw angle were collected, as shown in Figure 5a. The system model was built in the Matlab/Simulink environment.
In order to verify the feasibility and effectiveness of the proposed method, the Driving Scenario Designer was used to build a simulated driving environment with two straight lanes, and the reference path and yaw angle were collected, as shown in Figure 5a. The system model was built in the Matlab/Simulink environment.
In Figure 5a, the simulation vehicle starts from the right lane and then changes lanes to the left. From Figure 5b, we can observe that the simulation vehicle is initially located at x = -10, y = 0, and then changes lanes at x = 0, y = 0. The lane changing process is completed at x = 80m, and the position of the center of mass on the Y-axis reaches y = 4m.  Figure 6a shows the values of vehicle yaw angle obtained by different sensors in the simulation process. Figure 6b shows the reference yaw angle of the vehicle and the yaw angle after data fusion.  In Figure 5a, the simulation vehicle starts from the right lane and then changes lanes to the left. From Figure 5b, we can observe that the simulation vehicle is initially located at x = −10, y = 0, and then changes lanes at x = 0, y = 0. The lane changing process is completed at x = 80 m, and the position of the center of mass on the Y-axis reaches y = 4 m. Figure 6a shows the values of vehicle yaw angle obtained by different sensors in the simulation process. Figure 6b shows the reference yaw angle of the vehicle and the yaw angle after data fusion.
If the state test or the residual error test detected a fault, then = 0, otherwise = 1.

Working Conditions Description
In order to verify the feasibility and effectiveness of the proposed method, the Driving Scenario Designer was used to build a simulated driving environment with two straight lanes, and the reference path and yaw angle were collected, as shown in Figure 5a. The system model was built in the Matlab/Simulink environment.
In Figure 5a, the simulation vehicle starts from the right lane and then changes lanes to the left. From Figure 5b, we can observe that the simulation vehicle is initially located at x = -10, y = 0, and then changes lanes at x = 0, y = 0. The lane changing process is completed at x = 80m, and the position of the center of mass on the Y-axis reaches y = 4m.  Figure 6a shows the values of vehicle yaw angle obtained by different sensors in the simulation process. Figure 6b shows the reference yaw angle of the vehicle and the yaw angle after data fusion.  The horizontal axis represents time, and the vertical axis represents the values of yaw angle. It can be seen that from moment 0s to 3s, the measured values of Vision, GPS, and LIDAR systems are similar. In the simulation process, we assume that the GPS signal has interfered from 3 to 6 s, and the obtained yaw angle value has a large deviation. After 6s, the GPS signal returns to normal.
It can be seen that the fused yaw angle is always less than the value of the reference yaw angle before 2.3s and the fused yaw angle is greater than the value of the reference yaw angle between 2.3s to 5s. According to the trend of the two curves in the image, we know that the path tracking control performance of straight line is significantly better than the curve line during the process of lane change.
The type of simulated autonomous vehicle used in our paper is passenger car. The simulation environment and initial simulation condition settings are shown in Table 1:

Effectiveness of the Proposed Method
The yaw angle errors are shown in Figure 7.
performance of straight line is significantly better than the curve line during the process of lane change.
The type of simulated autonomous vehicle used in our paper is passenger car. The simulation environment and initial simulation condition settings are shown in Table 1:

Effectiveness of the Proposed Method
The yaw angle errors are shown in Figure 7. It can be seen that except GPS, the deviation between other measurement data and reference value is extremely small, and their absolute values are not more than 0.01 rad. However, when it comes to GPS data, the deviation is about 0.7rad at 3s, which is unacceptable considering the maxim yaw angle about 0.09 rad. It can be seen that except GPS, the deviation between other measurement data and reference value is extremely small, and their absolute values are not more than 0.01 rad. However, when it comes to GPS data, the deviation is about 0.7rad at 3s, which is unacceptable considering the maxim yaw angle about 0.09 rad. Figure 8 shows the value of simultaneous interpreting of three different sensors based on Chi-square test.  the calculated values of state chi-square test of GPS channel sharply increase at 3s, reaching more than the order of magnitude 5× 10 . In Figure 8b, the calculated values γ of state residuals test of Vision, GPS, and LIDAR channels are generally not exceed 2 × 10 , when all sensor systems work without fault. However, in the period of 3s-5s, when the GPS signal has fault, the calculated values γ of residuals error chi-square test of GPS signal channel is much higher, and even reaches more than 5 × 10 at 3s. Figure 9a shows the lateral position changes of the vehicle obtained by Vision, GPS, and LIDAR sensor systems. Figure 9b shows the reference lateral position of the vehicle and the lateral position after data fusion.   Figure 8b is the value obtained by residuals error chi-square test. In Figure 8a, the calculated values λ of state chi-square test of Vision, GPS, and LIDAR channels are very small, which are always below the order of magnitude 10 −7 , when all sensor systems work without fault. In contrast, when the fault of GPS signal occurs, the calculated values of state chi-square test of GPS channel sharply increase at 3s, reaching more than the order of magnitude 5× 10 −6 . In Figure 8b, the calculated values γ of state residuals test of Vision, GPS, and LIDAR channels are generally not exceed 2 × 10 −8 , when all sensor systems work without fault. However, in the period of 3s-5s, when the GPS signal has fault, the calculated values γ of residuals error chi-square test of GPS signal channel is much higher, and even reaches more than 5 × 10 −7 at 3 s. Figure 9a shows the lateral position changes of the vehicle obtained by Vision, GPS, and LIDAR sensor systems. Figure 9b shows the reference lateral position of the vehicle and the lateral position after data fusion. It can be seen from Figure 9 that the lateral position obtained by GPS signal has obvious deviation in the time period of 3-6s, and the lateral position obtained by multi-sensor data fusion method is basically consistent with the reference lateral position. However, a small deviation between the reference and fused lateral position still exists due to the performance of path tracking controller. Figure 10 shows the deviation of the measured lateral position by different sensor systems. It can be seen from Figure 10 that the measurement deviations of vision and LIDAR have remained at a very small range, while the measurement error of GPS data gradually increases from about 1.5m to more than 3m in the period of 3-6s due to sensor failure. Considering that the lane width is only 4m, the GPS sensor fault is unacceptable and needs to be isolated. Figure 11 shows the value of the fault detection function calculated by chi-square test for different sensor systems. Figure 11a shows the value obtained by state chi-square test and Figure 11b shows the value obtained by residuals chi-square test.
In Figure 11a, it can be seen that the calculated values of λ state chi-square test of vision and LIDAR channels are very small, basically below 2× 10 , occasionally exceeding the order of magnitude 10 , but they are still extremely small. Comparatively, the data of GPS channel reaches the order magnitude of 10 at 3s, or even more than 10 at 6s, which is much larger than that of vision and LIDAR channels. In Figure 11b, the calculated value γ of vision channel reaches about 1× 10 at the initial stage but always below the order magnitude of 10 in the following time. The calculated value γ of GPS data is extremely large from 3s to 6s, reaching the order magnitude of It can be seen from Figure 9 that the lateral position obtained by GPS signal has obvious deviation in the time period of 3-6s, and the lateral position obtained by multi-sensor data fusion method is basically consistent with the reference lateral position. However, a small deviation between the reference and fused lateral position still exists due to the performance of path tracking controller. Figure 10 shows the deviation of the measured lateral position by different sensor systems. It can be seen from Figure 9 that the lateral position obtained by GPS signal has obvious deviation in the time period of 3-6s, and the lateral position obtained by multi-sensor data fusion method is basically consistent with the reference lateral position. However, a small deviation between the reference and fused lateral position still exists due to the performance of path tracking controller. Figure 10 shows the deviation of the measured lateral position by different sensor systems. It can be seen from Figure 10 that the measurement deviations of vision and LIDAR have remained at a very small range, while the measurement error of GPS data gradually increases from about 1.5m to more than 3m in the period of 3-6s due to sensor failure. Considering that the lane width is only 4m, the GPS sensor fault is unacceptable and needs to be isolated. Figure 11 shows the value of the fault detection function calculated by chi-square test for different sensor systems. Figure 11a shows the value obtained by state chi-square test and Figure 11b shows the value obtained by residuals chi-square test.
In Figure 11a, it can be seen that the calculated values of λ state chi-square test of vision and LIDAR channels are very small, basically below 2× 10 , occasionally exceeding the order of magnitude 10 , but they are still extremely small. Comparatively, the data of GPS channel reaches the order magnitude of 10 at 3s, or even more than 10 at 6s, which is much larger than that of vision and LIDAR channels. In Figure 11b, the calculated value γ of vision channel reaches about 1× 10 at the initial stage but always below the order magnitude of 10 in the following time. The calculated value γ of GPS data is extremely large from 3s to 6s, reaching the order magnitude of It can be seen from Figure 10 that the measurement deviations of vision and LIDAR have remained at a very small range, while the measurement error of GPS data gradually increases from about 1.5m to more than 3m in the period of 3-6s due to sensor failure. Considering that the lane width is only 4m, the GPS sensor fault is unacceptable and needs to be isolated. Figure 11 shows the value of the fault detection function calculated by chi-square test for different sensor systems. Figure 11a shows the value obtained by state chi-square test and Figure 11b shows the value obtained by residuals chi-square test. 10 due to the GPS sensor failure. The calculated values γ of LIDAR data fluctuate greatly, but they are all below 1× 10 , which is also a reasonable interference situation. From the above description and analysis of Figure 7 to Figure 11, it can be seen that the proposed method can detect the fault signal robustly when the sensor failure occurs. Figure 12 shows the simulation results of path tracking control with and without fault isolation. The three curves in Figure 12a represent the reference lateral position, after fault isolation and before fault isolation. Figure 12b shows the lateral position error before and after fault isolation in the simulation process. From Figure 12a,b, it can be seen that without fault isolation, it is almost impossible to realize the path tracking control due to sensor faults. After fault isolation, the deviation between the actual lateral position and the reference lateral position is maintained within a very small range, which validates the effectiveness of the proposed fault-tolerant MPC algorithm for path tracking of autonomous vehicle. Figure 12c,d show the yaw angle obtained before and after fault isolation and the yaw angle error with respect to the reference values. From Figure 12c,d, it can be seen that with fault isolation, actual yaw angle of vehicle almost coincides with the reference yaw angle, while without fault isolation the yaw angle error is extremely large after 1s. From Figure 12d, the yaw angle error without fault isolation can reach -0.5rad to 1.1rad, while the reference value of yaw angle is always below 0.1rad, which means yaw angle error without fault isolation may reach 5-10 times more than the reference, and vehicle cannot track the reference path under this condition, which may lead to serious In Figure 11a, it can be seen that the calculated values of λ state chi-square test of vision and LIDAR channels are very small, basically below 2 × 10 −5 , occasionally exceeding the order of magnitude 10 −5 , but they are still extremely small. Comparatively, the data of GPS channel reaches the order magnitude of 10 −3 at 3 s, or even more than 10 −2 at 6 s, which is much larger than that of vision and LIDAR channels. In Figure 11b, the calculated value γ of vision channel reaches about 1 × 10 −6 at the initial stage but always below the order magnitude of 10 −6 in the following time. The calculated value γ of GPS data is extremely large from 3 s to 6 s, reaching the order magnitude of 10 −3 due to the GPS sensor failure. The calculated values γ of LIDAR data fluctuate greatly, but they are all below 1 × 10 −5 , which is also a reasonable interference situation.
From the above description and analysis of Figure 7 to Figure 11, it can be seen that the proposed method can detect the fault signal robustly when the sensor failure occurs. Figure 12 shows the simulation results of path tracking control with and without fault isolation. The three curves in Figure 12a represent the reference lateral position, after fault isolation and before fault isolation. Figure 12b shows the lateral position error before and after fault isolation in the simulation process. From Figure 12a,b, it can be seen that without fault isolation, it is almost impossible to realize the path tracking control due to sensor faults. After fault isolation, the deviation between the actual lateral position and the reference lateral position is maintained within a very small range, which validates the effectiveness of the proposed fault-tolerant MPC algorithm for path tracking of autonomous vehicle.
Sensors 2020, 20, x FOR PEER REVIEW 17 of 19 consequences. On the contrary, after fault isolation processing, the yaw angle error is always below 0.02 rad, which is extremely small for path tracking control.

Discussion of the Background and Outcomes of Our Work
With the continuous increasing requirements for the safety and environmental adaptability of autonomous vehicles, the on-board environmental perception systems have become more and more complex, and the types and numbers of sensors have also increased. The risk of sensor failures is also increased, which has a serious impact on vehicle safety. Therefore, the detection of faulty sensor signals and fault-tolerant control mechanism is very important to autonomous driving safety. In our work, we established a single-track 3 DOF vehicle dynamics model and based on this model, a faulttolerant model predictive control method was developed. Our motivation for designing this algorithm is to enable the autonomous vehicle to effectively detect and isolate the fault signal and to perform robust longitudinal path tracking motion control when the sensor failure occurs.
In order to verify the effectiveness of the method proposed in this paper, we set up a single lane changing path tracking control condition in Driving Scenario Designer. The vehicle motion state information, such as the lateral position and yaw angle, can be obtained by the GPS integrated navigation system, LIDAR perception system, and visual perception system. We assume that there is interference in the simulation environment, which causes the GPS signal to be temporarily lost. The description and analysis of simulation results show that the proposed fault-tolerant MPC algorithm can effectively detect the fault signal when the sensor failure occurs. The value of fault detection functions of fault yaw angle signal and fault lateral position signal is 10 and 100 times, respectively, more than that of normal signals. This means that we can easily detect the fault signal by setting the appropriate threshold and generate the corresponding fault detection matrix. The fault isolation is accomplished in the process of data fusion, which is one of the innovations of our work. With the fault signal isolation, the path tracking control performance of autonomous vehicle can be significantly improved, further confirming the effectiveness and robustness of the proposed algorithm in this work.   Figure 12c,d, it can be seen that with fault isolation, actual yaw angle of vehicle almost coincides with the reference yaw angle, while without fault isolation the yaw angle error is extremely large after 1s. From Figure 12d, the yaw angle error without fault isolation can reach-0.5 rad to 1.1 rad, while the reference value of yaw angle is always below 0.1rad, which means yaw angle error without fault isolation may reach 5-10 times more than the reference, and vehicle cannot track the reference path under this condition, which may lead to serious consequences. On the contrary, after fault isolation processing, the yaw angle error is always below 0.02 rad, which is extremely small for path tracking control.

Discussion of the Background and Outcomes of Our Work
With the continuous increasing requirements for the safety and environmental adaptability of autonomous vehicles, the on-board environmental perception systems have become more and more complex, and the types and numbers of sensors have also increased. The risk of sensor failures is also increased, which has a serious impact on vehicle safety. Therefore, the detection of faulty sensor signals and fault-tolerant control mechanism is very important to autonomous driving safety. In our work, we established a single-track 3 DOF vehicle dynamics model and based on this model, a fault-tolerant model predictive control method was developed. Our motivation for designing this algorithm is to enable the autonomous vehicle to effectively detect and isolate the fault signal and to perform robust longitudinal path tracking motion control when the sensor failure occurs.
In order to verify the effectiveness of the method proposed in this paper, we set up a single lane changing path tracking control condition in Driving Scenario Designer. The vehicle motion state information, such as the lateral position and yaw angle, can be obtained by the GPS integrated navigation system, LIDAR perception system, and visual perception system. We assume that there is interference in the simulation environment, which causes the GPS signal to be temporarily lost. The description and analysis of simulation results show that the proposed fault-tolerant MPC algorithm can effectively detect the fault signal when the sensor failure occurs. The value of fault detection functions of fault yaw angle signal and fault lateral position signal is 10 and 100 times, respectively, more than that of normal signals. This means that we can easily detect the fault signal by setting the appropriate threshold and generate the corresponding fault detection matrix. The fault isolation is accomplished in the process of data fusion, which is one of the innovations of our work. With the fault signal isolation, the path tracking control performance of autonomous vehicle can be significantly improved, further confirming the effectiveness and robustness of the proposed algorithm in this work.

Conclusions
In this paper, a novel and robust fault-tolerant model predictive control algorithm was proposed, which can be used for robust vehicle lateral motion control in case of sensor failures. First, by constructing the objective function and considering dynamic constraints, the linear time-varying model predictive control algorithm for path tracking control of vehicle was designed. Second, an improved weighted data fusion algorithm was proposed for multi-sensor information fusion and fault signal isolation. Then, based on Chi-square detectors and Kalman filters, we designed a novel fault signal detection algorithm, which can produce the fault detection matrix used in data fusion algorithm for fault signal isolation. Finally, a lane changing path tracking control simulation was carried out for validation of the effectiveness and correctness of the proposed algorithm. The simulation results show that the proposed algorithm can efficiently detect the fault signal. After the fault signal isolation, the reference path can be effectively tracked by using the proposed fault-tolerant MPC algorithm. In further studies, this method can be combined with reinforcement learning to improve fault detection and isolation performance. We will explore the effectiveness of the proposed method for fault detection in electronic fuel injection system, automatic steering control system, suspension systems, etc. Meanwhile, we will extend our fault-tolerant model predictive control algorithm into the fault diagnosis fields that are out of the real driving environment, for instance, fault diagnosis in complex driving scenarios and strong environmental noise conditions. In addition, considering the longitudinal speed changes and the adaptive MPC algorithm can be used to improve the path tracking performance of motion controller. It is worth noting that we approximately use the fused multi-sensor data as the real motion states of vehicle, which means that when faults occur to most or all sensors, our proposed method is invalid. In addition, the robustness is weak by using the thresholds to detect the fault signal in our method. For solving these two problems, using the convolutional neural network to automatically extract the features of the fault detection function and detect the sensor fault could be a reliable solution.