Cybersecurity–Safety Integration: L2 ADAS · L3/4 ADS · Mobile Physical AI

Abstract: L2 driver assistance, L3/L4 autonomous driving, and humanoid and passenger-carrying quadruped robots share one cybersecurity methodology yet differ in who is responsible, how they are regulated, and how deeply cybersecurity couples with safety. This post systematically maps the requirements, differences, standards/regulations, and best practices across the three families, with a focus on how deeply cybersecurity integrates with functional safety (FuSa), SOTIF, and whole-machine safety. Key takeaways All three families have entered the “cybersecurity is an entry gate” stage, but with a clear gradient: L2 is enforced, L3/L4 has the highest bar, and mobile physical AI is weakest yet fastest-moving. The essence: L2 treats the network as an information asset, L3/L4 as a safety system, and physical AI as a physical safety device. Integration: L2 is coordinated, L3/L4 is integrated/converging, and mobile physical AI is mechanistically unified but method-empty. The adversarial AI surface (data poisoning, evasion, model theft) is the common new gap in 2026, under-covered by 21434/62443. Best practices are highly shared (TARA, defense in depth, SBOM, secure OTA, monitoring, pentest, PIA) and transferable across bodies. 1. Framework: three threads + two axes Three threads decide requirements: whether a human bails out, what physical environment the system operates in, and what the regulator can grab. L2 has a human fallback, L3/L4 has none, and mobile physical AI controls the physical body and balance — deciding whether cybersecurity is an “information asset problem,” a “safety system problem,” or a “physical safety device problem.” ...

September 3, 2026 · 9 min · 1732 words · 张玉新 Yuxin Zhang · 0

ASIL E Is Not the Point. The No-Human-Fallback Safety Case Is.

Abstract: ASIL E is not a published standard. Its real value is not the name of a higher integrity level, but the question it forces Level 4 and Level 5 autonomous-driving safety arguments to answer: when there is no human fallback, can the safety case still credit a human controller? For me, the useful translation is not “ASIL E compliance.” It is a no-human-fallback review lens, four evidence fields in ADSafetyPilot, and a feedback loop connecting ROAM, DRIVEResearch, and a field-monitoring-backed safety case. ...

June 3, 2026 · 12 min · 2475 words · 张玉新 Yuxin Zhang · 0

Harness Engineering: User Experience vs Safety Compliance — A Direction Mainstream Roadmaps Have Collectively Skipped

Abstract: In Q1 2026, “Harness Engineering” surfaced almost simultaneously at OpenAI, Anthropic, and the Chinese startup Nextie, and the “12 Primitives” converged in the open-source community as a shared taxonomy. This essay argues that essentially all mainstream investment in Harness has concentrated in a single dimension — user experience, performance, efficiency — while the dimension that actually determines market access in Safety-Critical domains (autonomous driving, medical AI, financial risk control) has been collectively skipped: safety compliance. By constructing a two-way mapping between the 12 Harness Primitives and SOTIF (ISO 21448), this essay identifies 12 concrete research directions, offered as a starting point for standardization bodies, corporate R&D, third-party institutions, and academic labs to jointly fill in this commons. A ~3000-word Chinese short form is available on the author’s WeChat channel. ...

April 19, 2026 · 24 min · 4944 words · 张玉新 Yuxin Zhang · 0