Road crashes remain a major societal challenge, and automated driving will only earn public trust if its software behaves safely and predictably in every situation—not just in typical tests. Today’s collision-avoidance features are largely validated by extensive road testing, which is costly, time-consuming, and cannot cover every rare but dangerous scenario. The result is a gap between what vehicles do in practice and the high level of assurance regulators, manufacturers, and road users expect at higher automation levels.
CertiCar addresses this gap partially by developing Advanced Collision Avoidance System (ACAS) software that is correct-by-design. Instead of relying mainly on after-the-fact testing, CertiCar encodes safety rules, comfort constraints, and traffic-law requirements in precise, machine-checkable form and then automatically generates the corresponding control software. The approach rigorously explores how the ego vehicle and surrounding traffic could evolve, taking into account uncertainty in sensors, models, and the behaviour of other road users. This delivers formal guarantees that the vehicle’s decisions (e.g. braking or evasive manoeuvres) keep it within specified safety limits while maintaining ride comfort and regulatory compliance.
To realize this, the project integrates a suite of developed tools that (i) accelerate heavy computations on modern hardware, (ii) compute mathematically sound bounds on how complex, high-dimensional systems can evolve, and (iii) synthesize software controllers from high-level specifications. Together, these capabilities make it feasible to bring formal methods out of theory and into practical ACAS design, helping the automotive ecosystem move beyond “test until failure is unlikely” toward provably safe operation by construction.
Overall objectives:
1- Capture ACAS requirements in formal, unambiguous terms that reflect safety, comfort, and traffic-rule compliance.
2- Automatically synthesize ACAS source code that implements those requirements with correctness guarantees.
3- Validate in realistic conditions, combining high-fidelity simulators and hardware testbeds to demonstrate safety across representative scenarios.
Expected impact:
1- Safety and trust: By guaranteeing correct behaviour rather than only testing for it, CertiCar targets a measurable reduction in crash risk, particularly in high-speed or complex edge cases.
2- Efficiency and cost reduction: Orders-of-magnitude fewer test miles are needed to reach confidence targets, shortening development cycles and lowering costs for industry.
3- Regulatory readiness: The method supports emerging safety-of-the-intended-functionality practices and helps align automated-driving software with rigorous assurance expectations.