Beyond 49 Seconds: What Motorsport Rescue Chains Tell Us About AV Chain Collisions

It happened in Shanghai. On 5 September 2026, during a China GT race, a car was caught in a multi-car collision, caught fire, and the driver was trapped in the cockpit. The first person to reach him was not a firefighter. It was not a medical team. It was another racing driver. He stopped, ran across, took a fire extinguisher, tore away damaged bodywork, and pulled the trapped driver out. ...

September 9, 2026 · 14 min · 2952 words · 张玉新 Yuxin Zhang · 0

Cybersecurity–Safety Integration: L2 ADAS · L3/4 ADS · Mobile Physical AI

Abstract: L2 driver assistance, L3/L4 autonomous driving, and humanoid and passenger-carrying quadruped robots share one cybersecurity methodology yet differ in who is responsible, how they are regulated, and how deeply cybersecurity couples with safety. This post systematically maps the requirements, differences, standards/regulations, and best practices across the three families, with a focus on how deeply cybersecurity integrates with functional safety (FuSa), SOTIF, and whole-machine safety. Key takeaways All three families have entered the “cybersecurity is an entry gate” stage, but with a clear gradient: L2 is enforced, L3/L4 has the highest bar, and mobile physical AI is weakest yet fastest-moving. The essence: L2 treats the network as an information asset, L3/L4 as a safety system, and physical AI as a physical safety device. Integration: L2 is coordinated, L3/L4 is integrated/converging, and mobile physical AI is mechanistically unified but method-empty. The adversarial AI surface (data poisoning, evasion, model theft) is the common new gap in 2026, under-covered by 21434/62443. Best practices are highly shared (TARA, defense in depth, SBOM, secure OTA, monitoring, pentest, PIA) and transferable across bodies. 1. Framework: three threads + two axes Three threads decide requirements: whether a human bails out, what physical environment the system operates in, and what the regulator can grab. L2 has a human fallback, L3/L4 has none, and mobile physical AI controls the physical body and balance — deciding whether cybersecurity is an “information asset problem,” a “safety system problem,” or a “physical safety device problem.” ...

September 3, 2026 · 9 min · 1732 words · 张玉新 Yuxin Zhang · 0

Book Recommendation | Building Foundations for the Future with An Introduction to System Safety Engineering

Nancy G. Leveson’s An Introduction to System Safety Engineering does two things unusually well. It gives a systematic account of the foundations of classical safety engineering, and it uses systems thinking to address the new problems created by software, automation, complex systems, and organizations. The Chinese edition, 《系统安全工程导论》, was translated jointly by two teams led by Professor Hong Wang and me. ...

August 23, 2026 · 5 min · 896 words · 张玉新 Yuxin Zhang · 0

Durham's Last Lesson: Slow Down, Root Deep

Today is my last day staying in the lab at Durham University. On the way to the lab, I casually recorded two very ordinary scenes. I did not expect that these small fragments would become the clearest and most precious final lesson this old city gave me. The original two-minute video is slow. If you would like, you can watch it first and then read this reflection: Durham’s last lesson, originally shared on WeChat ...

July 9, 2026 · 5 min · 884 words · 张玉新 Yuxin Zhang · 0

CDV Crossing Domains: A Robot SOTIF Perspective

Abstract: Yoav Hollander is a world-class expert in chip verification. The company he founded, Foretellix, brought coverage-driven verification (CDV) into autonomous driving. Recently he wrote a post pushing the methodology into a much larger arena: AI alignment. This post reads that cross-domain migration from my own research field — the SOTIF four-quadrant model, the tree-like structure of Robot SOTIF, and the standards-driven Chinese context. The core question stays the same throughout: how do you know what you don’t know? ...

June 11, 2026 · 9 min · 1901 words · 张玉新 Yuxin Zhang · 0

Coverage-Driven Alignment: What 'Teaching Claude Why' Can Borrow from AV Verification (Chinese Translation)

This page hosts my Chinese translation of Yoav Hollander’s post on coverage-driven alignment, translated with the author’s permission. If you read English, please read the original directly: Coverage-driven alignment – What ‘Teaching Claude Why’ can borrow from AV verification — Yoav Hollander, LessWrong, June 8, 2026. For my own commentary on what CDV’s cross-domain migration means for SOTIF and robot safety, see CDV Crossing Domains: A Robot SOTIF Perspective. If you care about AI safety, Yoav’s The Foretellix CTO Blog is worth following — every post is a classic.

June 11, 2026 · 1 min · 89 words · 张玉新 Yuxin Zhang · 0

From 'Human' Driving to 'Human-like' Driving

Abstract: For intelligent driving to “drive like a human”, the prerequisite is understanding how humans actually drive. Starting from the concept of “human-like driving”, this post discusses five application directions for human driving behavior research, four paths to obtaining the answer, and the open-data practice our team is pursuing. First published on my WeChat channel in late March 2026; added to this blog in June 2026. Humans have always been fascinated by the study of their own behavior. ...

June 10, 2026 · 20 min · 4128 words · 张玉新 Yuxin Zhang · 0

ASIL E Is Not the Point. The No-Human-Fallback Safety Case Is.

Abstract: ASIL E is not a published standard. Its real value is not the name of a higher integrity level, but the question it forces Level 4 and Level 5 autonomous-driving safety arguments to answer: when there is no human fallback, can the safety case still credit a human controller? For me, the useful translation is not “ASIL E compliance.” It is a no-human-fallback review lens, four evidence fields in ADSafetyPilot, and a feedback loop connecting ROAM, DRIVEResearch, and a field-monitoring-backed safety case. ...

June 3, 2026 · 12 min · 2475 words · 张玉新 Yuxin Zhang · 0

Robots Need SOTIF Too

Abstract: On June 2, 2026, the Chinese national standard project 机器人预期功能安全实施指南 entered public notice, with the comment period scheduled to close on July 2, 2026. I have put this direction into OpenTopic as the second open research theme: Robot SOTIF. The goal is not to copy autonomous-driving SOTIF directly into robotics, but to build an evidence chain from standards, ODD, scenarios, triggering conditions, physical interaction, LLM/VLA decision safety, and finally to a defensible safety case. ...

June 3, 2026 · 7 min · 1393 words · 张玉新 Yuxin Zhang · 0

Does Intelligent Driving Need an Open Platform for Operating Boundaries?

Abstract: OpenODC is an open-source project that turns the Chinese national standard GB/T 45312-2025 (Intelligent Connected Vehicles — Operational Design Conditions for Automated Driving Systems) into a machine-readable public dataset. It currently includes a 144-element ODC schema, six public sample profiles (Tesla FSD Supervised, Tesla China ADAS, Huawei Qiankun ADS 4, Apollo Go Wuhan operations, XPeng XNGP, Pony.ai Gen-7 Robotaxi), a coverage matrix, dual developer-/consumer-views, and a planned OEM-evidence workbench. This post is both the project’s origin note and a public invitation — including the explicit option to hand the project off to a more suitable steward, free of charge. ...

May 9, 2026 · 9 min · 1749 words · 张玉新 Yuxin Zhang · 0