Chapter VII: Rules of the Road 3
7.5 Safety Guarantees
Safety is guaranteed when agents do not collide with one another. An agent causes collision when it takes an action that satisfies the following conditions.
Definition 7.5.1(Collision). An agent Ag that takes an actionπ β π΄ππ‘Agwill cause collision if either of the following conditions hold:
1. GAg,π‘(π , π) β© (βͺAg0GAg0(π 0, π0)) β β .
2. GAg,π‘(π , π) β©πst) β β , whereπst = {π β πΊ | π .π = 0}, i.e. the set of all undrivable grid points.
In other words, when Agβs actionπcauses it to overlap in the occupancy grid with another agentβs occupancy grid or a static obstacle. Note when the agent Ag0 is not simultaneously taking an action with Ag, the occupancy set GAg0(π 0,Β·) is the singleton set for the agent Ag0, representing the single grid point Agβ is occupying.
A strategy where agents simply take actions that avoid collision in the current time- step is insufficient for guaranteeing safety because of the inertial properties of the agent dynamics. The Agent Protocol is thus also defined to avoid violating the safety of its own and any other agentβs backup plan actionππ π defined in Section 7.4. An agentβs backup plan actionππ πis evaluated to be safe when the following conditions hold:
Definition 7.5.2. [Safety of a Backup Plan Action] Let us define the safety of an agentβs backup plan actionπAg,π π :U =B, whereB={T,F}is an indicator variable that determines whether an agentβs backup plan action is safe or not. It is defined as follows:
ππ΄π,π π(π’) =β§πβππ(π , ππ π, π’),
where the set π is the set of all oracles in the top three tiers of the agent profile defined in Section 7.4.
An agent Ag takes an actionπ β π΄ππ‘Ag that violates the safety backup plan action of another agent Ag0when the following conditions hold:
Definition 7.5.3(Safety Backup Plan Violation Action). Let us consider an agent Ag that is taking an actionπ β π΄ππ‘Ag, and another agent Ag0. The action(Ag, π)β₯Ag0, i.e. agent Ag violates the safety backup plan of an agent Ag0when by taking an action πwhereπ’0is the state of the game after Ag has taken its action, thenπAg0
,π π(π’0) =F.
Note, when Agβ Ag0, then Ag can only violate the backup plan action of the agent Ag0with its actionπif the following conditions hold:
1. GAg(π , π) β© GAg0(π 0, π0) β β , 2. Letπ π‘+1=ππ΄π(π , π)andπ 0
π‘+1=ππ΄π0(π 0, π0): IfGAg(π π‘+1),GAg0(π π‘+1)are in the same lane and ifπ(π π‘+1, π 0
π‘+1) < ππ πreq, whereπ(π π‘+1, π 0
π‘+1)andππ πreqare the same as defined in Section 7.4.4.
The safety proof is based on the premise that all agents only take actions that do not collide with other agents and maintain the invariance of the safety of their own andother agentsβ safety backup plan actions. The safety theorem statement and the proof sketch are as follows.
We can treat the quasi-simultaneous game as a program, where each of the agents are separate concurrent processes. A safety property for a program has the form πβπ, whereπandπare immediate assertions. This means if the program starts with πtrue, then π is always true throughout its execution (Owicki and Lamport, 1982).
Theorem 5 (Safety Guarantee). If all agents Ag β π in the quasi-simultaneous game select actions in accordance to the Agent Protocol specified in Section 7.4, then we can show the safety propertyπβπ, where the assertionπis an assertion that the state of the game is such thatβπ΄π, πAg,π π(π , π’) = T, i.e. each agent has a backup plan action that is safe, as defined in Section 7.5.2. We denote ππ‘ as the assertion over the state of the game at the beginning of the time-stepπ‘, before agents take their respective actions. π is the assertion that the agents never occupy the same grid point in the same time-step (e.g. collision never occurs when agents take their respective actions during that time-step). We denoteππ‘as the assertion for the agent states/actions taken at time-stepπ‘.
Proof. To prove an assertion of this form, we need to find an invariant assertion πΌ for which i)πβ πΌ, ii)πΌ βπΌ, and iii)πΌ βπhold. We defineπΌto be the assertion that holds on the actions that agents select to take at a time-step. We denoteπΌπ‘ to be the assertion on the actions agents take at timeπ‘such thatβπ΄π, Ag takesπ β π΄ππ‘Ag where 1) it does not collide with other agents, and 2)βAg, πAg,π π(π’0) = T where π 0 = πAg(π , π), and π’0 is the corresponding global state of the game after each Ag has taken its respective actionπ.
It suffices to assume:
1. Each Agβπhas access to the traffic light states.
2. There is no communication error in the conflict requests, token count queries, and the agent intention signals.
3. All intersections in the road networkπ are governed by traffic lights.
4. The traffic lights are designed to coordinate traffic such that if agents respect the traffic light rules, they will not collide.
5. Agents follow the agent dynamics defined in Section 7.4.
6. Forπ‘ =0,βAgβπin the quasi-simultaneous game is initialized to:
β’ Be located on a distinct grid point on the road network.
β’ Have a safe backup plan actionππ πsuch thatπAg,π π(π , π’)=T.
We can proveπβ πby showing the following:
1. ππ‘ β πΌπ‘. This is equivalent to showing that if all agents are in a state where π is satisfied at timeπ‘, then all agents will take actions at time π‘ where the πΌ holds. This can be proven using arguments based on the Agent Protocol showing each agent will always take actions that 1) do not collide with other agents and 2) will not violate the safety of its own or other agentsβ backup plan action.
2. πΌ β πΌ. If agents take actions at timeπ‘ such that the assertionπΌπ‘ holds, then by the definition of the assertionπΌ, agents will end up in a state where at time t+1, assertionπholds, meaningπΌπ‘ β ππ‘+1. Sinceππ‘+1β πΌπ‘+1from 1, we get πΌ βπΌ.
3. πΌ βπ. This is equivalent to showing that if all agents take actions according to the assertions in πΌ, then collisions will not occur. This follows in the immediate time-step from Condition 1, and the fact that all Ag have a safe backup plan action ππ π to choose from when Condition 2 holds, and will always be able to (and will) take an action from which it can avoid collision in future time steps.
Proof of safety alone is not sufficient reason to argue for the effectiveness of the protocol, as all agents could simply stop for all time and safety would be guaranteed.
A liveness guarantee, i.e. proof that all agents will eventually make it to their final destination, is critical. In the following section, we present liveness guarantees.