Full text
Assessing the Safety Impacts of Cooperative Awareness for Automated Driving 1st Marcel Sonntag Institute for Automotive Engineering (ika) RWTH Aachen University Aachen, Germany [email protected] 2nd Pramod Mallipudi RWTH Aachen University Aachen, Germany [email protected] 3rd Lutz Eckstein Institute for Automotive Engineering (ika) RWTH Aachen University Aachen, Germany [email protected] Abstract—Connected and automated driving is expected to increase road safety. Safety impact assessment is an approach to prospectively assess the potential safety benefits of systems before their introduction to market. As these assessments usually leverage model-in-the-loop simulations, it is required to model the involved road users’ behavior realistically. Current research on prospective safety impact assessment mainly focusses on automated driving functions (ADFs) not taking vehicle communication into account. When assessing ADFs incorporating collective awareness of other road users based on vehicle communication, the effects of the communication are to be modeled in addition. Cooperative awareness aims at overcoming perception shortcomings of ADFs due to limited sensor ranges or visual obstructions, as road users communicate their own dynamic state. This work presents a methodology for prospective safety impact assessment of cooperative awareness-enabled ADFs. The methodology includes cooperative awareness data analyses, generating realistic baseline scenarios, as well as modelling the accuracies of the communicated information. The developed methodology is evaluated for vehicle-to-vehicle communication of ETSI Cooperative Awareness Messages (CAM) based on real-world data from the V2AIX dataset. This use case is assessed for different ADFs at urban intersections affected by visual obstructions. The results show an increase in the crash occurrence for realistic CAM modelling compared to ideal CAMs. This implies that assessing cooperative awareness in simulations requires modelling it carefully to achieve reliable results. Index Terms—Connected and Automated Driving, Safety Impact Assessment, Cooperative Awareness, V2X I. INTRODUCTION Connected and automated driving functions are expected to increase the safety of road traffic. Achieving this safety gain requires careful design of driving function behaviors. Prospective safety impact assessment usually leverages model-in-theloop simulations to assess the safety potentials of driving functions before introduction to market [1]. Usually mature systems are assumed as this is required to be introduced to the market. Those systems are compared to human drivers or other system implementations as a baseline. Based on current accident data, the overall safety impacts, e.g., at the European level, are estimated [2]. However, for a valid statement about The research leading to these results has received funding from the European Union’s Horizon 2020 research and innovation program under grant agreement No 101006664. The sole responsibility for this publication lies with the authors. The authors would like to thank all partners within the Hi-Drive project (hi-drive.eu) for their cooperation and valuable contribution. the impact of a driving function, the scenarios as well as the behavior of the system under test (SuT) and other road users are to be modeled realistically. One key enabler of automated driving is vehicle-toeverything (V2X) communication. Especially, when V2X is utilized for cooperative awareness and collective perception use cases, positive effects on road safety are expected [3]. Cooperative awareness in this context means that road users are informed about each other’s position, dynamics, and attributes [4]. Connected road users might use this information to incorporate it in their behavior planning, achieving the ability to overcome their perception limitations due to limited sensor range and visual obstructions. While safety benefits for automated driving given ideal cooperative awareness seem obvious, it is not clear if such benefits can be achieved given actual cooperative awareness with errors in the transmitted data, e.g., due to imprecise localization. This might lead to a decrease in overall traffic safety, depending on the magnitude of these errors. Current research on cooperative awareness and collective perception mainly focusses on technical aspects, while trying to derive rough safety estimates based on these aspects [3], [5]–[7]. Thus, no proper safety impact assessment is performed. However, other research assesses safety impacts for other V2X use cases, that cannot be considered as cooperative awareness for automated driving. One study assesses the safety impacts of warnings for vulnerable road users (VRUs) via V2X [8]. If cooperative awareness use cases are investigated in safety impact assessment, it is assumed as ideal, neglecting errors in the transmitted data, which are also there for mature systems that can be introduced to the market. The authors are not aware of proper prospective safety impact assessment studies or respective methods investigating cooperative awareness-enabled ADFs incorporating realistic modelling of errors. As the consideration of cooperative awareness affects different steps of prospective safety impact assessment, starting from data preparation towards the simulation itself, the full process is to be extended. This work complements current research with the following contributions: •Extension of the methodology for the main steps of prospective safety impact assessment to the consideration This full-text paper was peer-reviewed at the direction of IEEE Instrumentation and Measurement Society prior to the acceptance and publication.
of errors in cooperative awareness. •Exemplary application of the extended methodology to the safety impact assessment of ETSI Cooperative Awareness Messages (CAMs) [4] at urban intersections based on actual accident data. •Comparison of ADFs with no connectivity, cooperative awareness with errors, and ideal cooperative awareness at urban intersections. The developed methodology is first applied to CAMs as there are already series production vehicles on the market sending these messages, making utilizing these messages in ADFs realistic in the near future. Beyond that, the developed methodology is valid for assessing collective perception use cases, too, extending it to multiple erroneous object information from different sources. After elaborating on related work (Section II), the developed methodology is presented (Section III). It focusses specifically on data preparation, scenario generation, and system modelling. The presented methodology is applied in an experiment conducting safety impact assessment simulations for different SuTs at an urban intersection based on actual accident data and real-world V2X data (Section IV). The results of the experiment are provided and discussed in Section V. Finally, the work is concluded (Section VI). II. RELATED WORK Current related research focusses on general prospective safety impact assessment of automated driving on the one hand. On the other hand, it focuses on cooperative awareness and collective perception analysis, as well as the modelling of it. To prepare combining both fields in this work, they are presented in the following. A. Prospective Safety Impact Assessment Prospective safety impact assessment aims at assessing the potential safety benefits of a technology before broad introduction to market [1]. The systems incorporating this technology are assumed as mature systems, thus, fulfilling, e.g., functional safety requirements. By utilizing simulations, the change in frequency of defined scenarios is combined with detailed analyses on changed accident and injury risks for the individual scenarios. Based on statistics for the target accidents, it is scaled up to assess the potential impacts for a defined region, such as the EU [2]. When assessing cooperative awareness and collective perception use cases, the changed injury risk including full avoidance of conflicts in defined scenarios is of particular interest. Based on data and system specifications, concrete scenarios, as well as models, are derived (see Fig. 1). Based on that, the baseline and treatment are simulated and the injury risk for the individual concrete scenarios is evaluated utilizing injury risk functions (IRFs). The baseline generation is mainly based on in-depth accident data, such as GIDAS [9]. A distinction is made between three general approaches based on the data usage [1]: •Approach A: original cases without modifications. Scenario simulation Simulation Change in scenario frequency Changed scenario injury risk Impact on the number of accidents per severity Data System specification Scenarios Models Baseline Treatment Injury risk calculation Scaling up & Fig. 1. Abstracted safety impact assessment flow. Changes in scenario frequency and injury risk are combined in the scaling up with accident statistics. The lower part details the scenario simulation for the injury risk calculation. •Approach B: original cases with modifications. •Approach C: synthetically generated cases. These approaches can be further specified based on the detailed case generation process as well as the case instantiation process [1]. B. V2X and Cooperative Awareness The standard for cooperative awareness implemented in current series production vehicles is the ETSI CAM [4]. Messages are provided by vehicles with frequencies between 1 Hz and 10 Hz based on defined triggers, such as changes in the speed. Among other information, CAMs include information on the current position and the dynamic state of the corresponding road user. In addition, for each of the values, covariances are provided to reflect the precision. Cooperative awareness, as well as collective perception, are analyzed on various layers in simulation and in realworld testing. Often, the focus is on technical analyses of the communication [3], [5]. The focus of this work is on analyzing cooperative awareness in real-world applications as a basis for modeling for simulation. Different metrics are used in literature to describe the collective perception quality, which can be applied to cooperative awareness use cases, too. For example, the age of information aggregates all arising latencies, and the object tracking accuracy describes the accuracy of the transmitted object characteristics [3]. In addition, metrics on signal level, e.g., based on packet loss, are used in some studies focussing on detailed technical analyses. Related to the object tracking accurancy, one study investigated the accuracy of different data transmitted via CAMs of series production vehicles [10]. While different vehicles are analyzed based on a precise reference GNSS system, only average errors are provided. For detailed investigation of V2X use cases, different datasets are available [11]. The dataset used in this work is the V2AIX dataset [12], which includes CAMs provided by seriesproduction vehicles in real-world traffic in different locations.
This allows detailed investigations, e.g., on pattern of errors and transmitted covariances. C. Modelling Cooperative Awareness Cooperative awareness can be modeled for simulations on different levels, starting at modelling the individual sensors including the object detection and detailed message transmission [13]. For safety impact assessment, this can be abstracted to achieve a model-in-the-loop simulation. This saves computation resources and eliminates errors caused by current immaturities in simulation environments, perception algorithms, or signal transmission simulation. One way of abstracting is applying cooperative perception error models [14] to cooperative awareness. This approach includes modelling the individual perception errors without simulating sensors in detail, as well as fusing perceptions from multiple sources, such as the transmitted objects and the SuT’s own perception. III. METHODOLOGY Extending prospective safety impact assessment to the consideration of V2X in general or cooperative awareness in particular requires extending the relevant steps by layer 6 (digital information) of the 6-layer-model (6LM) [15]. This includes extending the safety impact assessment by errors which are inherent in cooperative awareness, even in mature systems. The main steps that require extended approaches are the data preparation, the scenario generation, and the model generation and simulation. As the details of the application of the methodology are highly dependent on the available data and the considered SuTs, this section provides first guidance while it is applied to an example in Section IV. A. Data preparation Generating scenarios for safety impact assessment is usually based on accident data. As cooperative awareness aims at overcoming limited sensing, e.g., because of visual obstructions, it is essential to have elements influencing sensing incorporated as representative as possible in the cases that are to be simulated. In addition to ensuring applicable data for the scenario generation itself, actual cooperative awareness data need to be analyzed to model the cooperative awareness in the simulation. This includes modelling the transmitted corrupted vehicle states, their covariances, the logic for sending messages, and the latencies in transmission. For the error model of the transmitted vehicle states, it is important to consider the error distribution as well as the underlying systematics, i.e., is the error independent per sent message or are the errors across the individual messages correlated. This might be the case when there is, e.g., a constant lateral error in the positioning for a given time. As the transmitted covariances per state in real applications are only estimated by the system, they can differ from the actual error models. Thus, it is required to model these covariances as well based on real-world data. As the model to apply is dependent on the data, there cannot be a general error model defined. On example model is developed in Section IV-B. In addition to the imprecisions in the variables, the age of information for the transmitted data is to be modeled. This includes modelling the frequencies or triggers of transmission as well as the latencies in communication. While the first can be derived from message specifications, the latter might be derived from real-world data. B. Scenario generation A crucial part of the safety impact assessment is generating the driving scenarios to be simulated to achive a valid baseline. When prospectively assessing cooperative awareness for automated driving, digital information is to be considered especially in the scenario generation, as layer 6 of the 6LM needs to be added. This includes especially information that might directly influence the SuT’s reaction, such as the object tracking accuracy and the age of information. Applying this to approach A is not an option, as original cases that include cooperative awareness data do not exist yet. Instead, approaches B and C are applicable based on available data and tools. For approach B, the original cases are to be extended by the V2X information. In addition to modifications to the scenarios itself, an error model is to be added to generate the errors for the individual cases. For approach C, the error model can be added already for the initial case generating, not just sampling, e.g., vehicle states, but also concrete errors. For both approaches, it is important to consider the systematics behind the error, i.e., is the error randomly generated for each time step or is it consistent for multiple time steps. C. Models and simulation Based on the generated scenarios, the SuT can be analyzed in simulation. It requires modelling the behavior of the SuT based on the perceived information. The behavior is mainly defined by the perception of the environment including the digital information provided and the trajectory planning based on the perceived information. The perception can be modeled based on cooperative perception error models, which are based on individual perception error models [14]. This includes the fusion of multiple perceptions. As safety impact assessment usually investigates abstract functions as model-in-the-loop simulations, the trajectory planning is usually abstracted as well. Extending to cooperative awareness, the main change in the trajectory planning is how to consider received locations of surrounding dynamic objects incorporating the available covariances. This can be done for intersection conflicts based on identifying the position of the object (ˆx, ˆy), considering the covariance, which would lead to the earliest conflict assuming constant velocities and therefore requires the earliest reaction by the SuT. Fig. 2 illustrates the relevant variables. The timing of the conflict is determined by the time-to-conflict-point TTCP of the SuT: TTCP(ˆy) = sSuT,entry −ˆy vSuT (1)
SuT 𝑠𝑜𝑏𝑗,𝑒𝑛𝑡𝑟𝑦 𝑠𝑜𝑏𝑗,𝑒𝑥𝑖𝑡 𝑠𝑆𝑢𝑇,𝑒𝑛𝑡𝑟𝑦 𝑠𝑆𝑢𝑇,𝑒𝑥𝑖𝑡 𝜉 ∙ 𝑐𝑜𝑣𝑦 𝑥 𝑦 (ො𝑥, ො𝑦) 𝜉 ∙ 𝑐𝑜𝑣𝑥 Fig. 2. Sketch for abstracting the trajectory planning problem based on the TTCP and pPET. SuT in blue, conflicting object (obj), which is sending the CAM, in orange. It is dependent on the distance to travel sSuT,entry for the SuT to enter the conflict area, the y-coordinate of the considered object position ˆy, and the SuT’s velocity vSuT . The SuT needs to stop before entering the conflict area to avoid a predicted collision. (1) represents an actual conflict, only when the object vehicle is occupying the conflict area for the given timing or is entering it while the SuT is occupying this area. Adding a safety margin in the form of a minimum predicted post-encroachment-time pPETmin results for the case, that the object arrives first, in the constraint for a conflict: sobj,exit −ˆx vobj ≧sSuT,entry −ˆy vSuT −pPETmin (2) It is determined by the distance sobj,exit the object needs to travel to clear the conflict area and it’s velocity vobj as well as the distance sSuT,entry the SuT needs to travel to enter the conflict area and it’s velocity vSuT . Similarly, in case the SuT would reach the conflict area first, the constraint for a conflict is: sSuT,exit −ˆy vSuT ≧sobj,entry −ˆx vobj −pPETmin (3) While the distances sare related to the transmitted point of the object, both equations, (2) and (3), include the actually considered object position in relation to the transmitted position in the CAM to consider the covariances in longitudinal direction covxand lateral direction covy. The object position considered for the conflict prediction needs to lie inside the scaled covariance ellipse: ˆx ξ·covx2 +ˆy ξ·covy2 ≦1(4) The variable ξis used to scale the ellipse to determine which probabilities of possible points should still be considered. These three equations define the constraints for finding the position of the object to minimize the TTCP: min{TTCP(ˆy) : (2),(3),(4)}(5) Wall Fig. 3. Scenario visualization - SuT in black, conflicting object approaching from right in red. Visual obstruction due to wall. Screenshot from CARLA simulator. This way, a cautiously driving SuT would be considered, as it reacts based on the position within a given covariance requiring the earliest reaction to avoid a conflict. IV. EXPERIMENT The implementation of the described method depends on the investigated use case, the system, the investigated scenarios as well as the available data. For this reason, the method is illustrated based on a concrete example. A connected and automated driving function is investigated that utilizes CAMs at urban intersections to overcome visual obstructions. The focus of this experiment is on investigating the influence of transmitted positioning errors as well as the age of information. In addition, not a full safety impact assessment is conducted, including the scaling up to achieve absolute effects. Instead, the focus is on assessing the relative effects in a defined scenario for different SuTs. A. Experiment setup The scenario investigated in this experiment is an intersection scenario. The SuT intends to cross the intersection straight, while there are potentially conflicting vehicles that try to cross the intersection from the right (see Fig. 3). The intersection has four arms and is located in an urban area, leading to investigating the speed limits of 30 km/h and 50 km/h. Visual obstructions are placed based on actual accident data from GIDAS. The SuT enters the intersection for some scenarios from a minor and for others from a major road, influencing the right-of-way situation. The SuT is controlled by an ADF (cf. Section IV-D). The conflicting vehicle is human-driven and provides CAMs based on the ETSI specifications [4]. B. CAM Data Preparation The V2AIX dataset is utilized to analyze CAM data and derive the error model. While transmitted covariances of the individual vehicle states can be directly derived from the data, the actual errors cannot be derived directly due to lacking ground truth. This especially holds true for the positioning error, which is in the focus of the investigations of this work.
This shortage can be overcome by looking at the lateral errors first for specific road segments in the data. We extract CAMs from a road segment which allows only very limited lateral deviation from the reference path, i.e. narrow one-way-streets. Once the road section is determined, 28 vehicle tracks, identified by the station ID in the CAM, are selected for a more detailed analysis (see Fig. 4, providing an excerpt). The distance from the road center line to each instance of the transmitted position in this road segment is calculated. For each vehicle, the average error in the transmitted CAMs along the road section is calculated. The resulting histogram of the mirrored absolute values including a fitted Gaussian distribution is visualized in Fig. 5. The derived standard deviation is 1.41 m which is in line with the findings in [10]. Additionally, it matches the transmitted covariances in the analysed CAMs of on average 3 m. The covariance value represents covering 95 %, which is equal to around two standard deviations. The transmitted standard deviations are always around 3 m for lateral as well as longitudinal covariance, with only minor variations of a few centimeters. Based on this, the transmitted covariances for the error model are assumed constant with 3 m for the experiment. In addition to the average error, from Fig. 4 we derive that there is a systematic error present in the messages and not a random error per time steps. This matches the assumption that the provided positions in the CAMs were filtered using a Kalman filter. Based on the findings from [10], which investigate similar errors for lateral and longitudinal errors, the findings of this work for lateral errors are also applied to the longitudinal errors. This way, a complete error model for the positioning including the transmitted covariances is defined to model the object tracking accuracy. In addition, the age of information is considered. For this work, it is modeled via two main components: the latency in information transmission and processing, and the triggers for sending CAMs. While the first is modeled with a constant value of 50 ms based on literature [16], the latter is modeled using the ETSI specifications for CAMs [4]. The messages are sent with a frequency between 1 Hz and 10 Hz, depending on the triggers defined in the standard: a new CAM is generated if the heading changes by more than 4◦, the position changed by more than 4 m, or the velocity changed by more than 0.5 m s−1. This results in additional AoI of up to 0.1 s to 1.0 s, depending on the CAM triggering and the time when the resulting CAM is accessed. C. CAM Scenario Generation The basis for the scenario generation are 375 intersection accidents from the GIDAS database. This includes cases where the reference vehicle had the right of way and cases where it had to yield. According to the baseline generation approach B (cf. Section III-B), these original cases are modified to fit the intended use. The reference vehicle is replaced by the SuT, while the behavior of the conflicting vehicle is not changed. In fact, it Fig. 4. Tracks of different vehicles communicated via CAMs at a narrow road section, not allowing high deviations from the reference line. Reference line dashed. Fig. 5. Histogram of the average lateral deviation of each vehicle from the reference line. Absolute values mirrored at 0 m. Fitted Gaussian with standard deviation of 1.41 m. is following a predefined trajectory coming from the original case. For the case generation process, each original case is varied three times regarding the timing when the conflicting vehicle reaches the conflict point relative to the SuT. The difference in timing is sampled from a uniform distribution from −3 s to 3 s. The distribution is chosen uniform, as it is assumed that the initial timing of approaching the intersection of both participants before reacting to each other is independent of each other. Sampling the timing ensures that the generated baseline includes actual conflicts as well as close encounters. In addition, for each of the resulting 1,125 cases, three position errors are sampled from the distribution derived in Section IV-B. The sampled error is kept constant throughout the duration of the individual cases, as the data analysis revealed systematic errors for short segments of driving. The lateral and longitudinal errors are sampled independently for each of these cases. This results in up to 3,375 cases that are simulated for the different SuTs. The resulting detailed baseline approach is B2P [1]. D. Systems under test The goal of this experiment is to assess the impacts of cooperative awareness in relation to a non-connected ADF. Two different treatment systems are compared to one common baseline: •Baseline ADF (BADF): the ADF uses the own perception only.
•Ideal cooperative awareness ADF (ICA-ADF): the ADF receives ground truth position of the conflicting object without any latencies. I.e., the age of information is always 0. •Real cooperative awareness ADF (RCA-ADF): the ADF receives corrupted positions of dynamic objects in case they are not visible to its own sensors. The ADF is aware of the age of information from the CAM timestamp and predicts the object’s movement. The baseline system for the experiment is the Baseline ADF (BADF) from the Hi-Drive project [2]. The relevant sensors of the overall sensor setup for this experiment are a front facing long-range camera and LiDAR, a long-range front radar, and mid-range corner radars at the two front corners. This gives the BADF the ability to detect dynamic objects from 150 m distance, as long as they are not visually obstructed. Based on the perceived objects, decision-making is performed. As long as no conflicts are detected, the BADF approaches the intersection with the speed limit as target speed, when it is on a major road. Driving on a minor road, the BADF approaches the stop line at 10 km h−1. If in this case a conflict is detected, it adjusts the desired speed at the stop line to 0 km h−1. The BADF tries to leave a gap of 2 s in case it needs to yield. In case a collision is predicted, independent of the road, an automated emergency braking system (AEB) is activated based on the time-to-collision (TTC). Two different treatment systems are compared to this baseline. The general driving strategy is the same as for the BADF, just the object information used for decision-making differs. The first treatment system is an ADF with ideal cooperative awareness (ICA-ADF), meaning that is has access to the ground truth information of all dynamic objects at any time. This treatment represents the maximum impacts that could be achieved utilizing cooperative awareness. The other treatment system is an ADF which can receive CAMs from visually obstructed objects (RCA-ADF). The CAMs contain the corrupted object state according to Section IV-C for the time a message was triggered. The messages can only be accessed by the ADF as soon as the constant latency has passed. Based on the transmitted timestamp, it predicts the object movement using a constant velocity model. As long as the SuT cannot perceive the object with the own sensors, it takes the transmitted information including covariances from the CAM for the decision-making. Considering the covariances is crucial as the example in Fig. 6 shows. Based on the transmitted position and the covariance values in longitudinal and lateral position, one defined point is calculated, which requires the earliest reaction of the SuT (cf. Section III-C). This is achieved by solving the optimization problem (5). ξis set to one, meaning the covariance ellipse is not scaled, to cover the 95 % most probable positions. A safety gap of pPETmin = 0.5sis used, covering also very close misses in prediction, where a safely designed ADF would still brake. As soon as the SuT can perceive the object with its own sensors, it is deciding based on this perception, as the Visual obstruction SuT (A) Object ground truth (B) CAM object position (C) Object position considered by SuT Error model from CAM data analysis Transmitted covariance ellipsis Fig. 6. Visualization of object positions - not at scale for clearer visualization. The position transmitted via the CAM (B) is calculated based on the ground truth (A) and the error sampled from the error model derived from data. Based on (B) and the transmitted covariance, the SuT considers the point requiring the earliest reaction (C). transmitted covariances in the CAMs are rather high, leading to a higher trust in the own perception. V. EXPERIMENT RESULTS AND LIMITATIONS The scenarios generated based on Section IV-C were simulated with the three systems defined in Section IV-D. In addition, as a baseline, the generated cases were simulated incorporating the original reactions of the human drivers (Manual) in the initial accident data used for baseline generation. A. Experiment Results For the three conditions that don’t consider V2X errors (Manual, BADF, ICA-ADF), the 1,125 scenarios resulting from the timing variation according to the selected approach B2P were simulated. For the RCA-ADF, for each of these scenarios, three errors were sampled based on the model derived in Section IV-B, resulting in 3,375 simulated scenarios. The focus of the evaluation of the conducted simulations is on the resulting crash rates. Even though a different number of scenarios were simulated for different SuTs, the individual crash rates are still comparable as they are relative to the number of simulated scenarios. The resulting crash rates per SuT are visualized in Fig 7. For the Manual baseline, 48.1 % of the simulated scenarios result in crashes. This indicates that the baseline includes collisions as well as near misses, resulting in both situations where the SuTs need to react to avoid collisions and situations where no reaction is needed when the SuT has the right information available. The BADF reduces the crash rate to 18.4 %. This shows that also non-connected ADFs have the possibility to increase safety at urban intersection conflicts. Still, there are some situations in which the BADF cannot avoid a conflict. This is especially the case when an object is disregarding the right of way and visual obstructions are present. The ICA-ADF achieves to overcome this shortage of the BADF by reducing the resulting crash rate to 5.3 % as it is expected for cooperative awareness. Also fast approaching
Fig. 7. Experiment results including the human-driven baseline as reference (Manual), the baseline ADF without V2X (BADF), the ideal cooperative awareness ADF (ICA-ADF), and the real cooperative awareness ADF (RCAADF) using CAMs with errors. vehicles which are visually obstructed can be detected early enough to avoid conflicts. When realistic errors are added, the crash rate results for the RCA-ADF to 6.7 %. Even though this SuT is designed to react as safe as possible to the transmitted position and covariances (cf. Section IV-D), there is an increase in crash rate compared to the ideal data transmission. In addition, falsepositive activations of the AEB might increase, leading to potential new conflicts with following traffic which would be avoidable. Still, using the realistic CAMs outperforms not using connectivity at all. B. Experiment Limitations The experiment results were generated looking at one conflict type only. In addition, the data considered to build up the CAM error model is limited. Considering more data and more influencing factors such as location and surrounding infrastructure influencing GNSS signals could enhance validity. The SuT considered in the model-in-the-loop simulations is heavily abstracted, as it is usual for prospective safety impact assessment. Especially the trajectory planning considering the covariance provided within the CAM might have a major influence on the results. Within this work, one reasonable approach was assumed, not necessarily representative for all possible approaches. VI. CONCLUSION The presented work developed an extended methodology to consider cooperative awareness, including inaccuracies, in safety impact assessment. The method was demonstrated based on the provision of ETSI CAMs by human-driven vehicles at visually obstructed urban intersections. Based on data from the V2AIX dataset, the positioning error in current CAMs was modeled using a Gaussian distribution with a standard deviation of 1.41 m with a systematic error samples for each simulated case. Different SuTs were investigated, covering no connectivity, ideal cooperative awareness, and actual cooperative awareness including positioning errors. The results revealed a clear safety gain for ideal cooperative awareness compared to the nonconnected ADF. The safety decreased compared to the ideal cooperative awareness, when errors to the CAMs were added, while the crash rate was still lower compared to the nonconnected ADF. Future work will focus on detailed modeling of the fusion of the SuT’s own perception with the received V2X information and modeling other traffic participants which might be exposed to danger due to false-positive reactions of the SuT. REFERENCES [1] F. Fahrenkrog, A. Das, D. Sander, J. B¨ argman, M. Urban, M. Pohl, C. Glasmacher, and et al., “Deliverable D2.1 - prospective safety assessment framework - instruction,” V4SAFETY, Tech. Rep., 2024. [2] L. Vater, E. Aittoniemi, A. Bjorvatn, F. Fahrenkrog, C. Felchon, S. Innamaa, E. Lehtonen, S. Rahmani, and H. Weber, “Deliverable D4.5 - effects evaluation methods,” Hi-Drive Project, Tech. Rep., 2023. [3] F. A. Schiegg, I. Llatser, D. Bischoff, and G. Volk, “Collective perception: A safety perspective,” Sensors (Switzerland), vol. 21, pp. 1–24, 1 2021. [4] ETSI, “ETSI EN 302 637-2 - intelligent transport systems (ITS); vehicular communications; basic set of applications; part 2: Specification of cooperative awareness basic service,” Tech. Rep., 2014. [5] A. Bazzi, B. M. Masini, and A. Zanella, “Cooperative awareness in the internet of vehicles for safety enhancement,” EAI Endorsed Transactions on Internet of Things, vol. 3, no. 9, 1 2017. [6] M. Karoui, V. Berg, and S. Mayrargue, “Assessment of V2X communications for enhanced vulnerable road users safety,” in IEEE Vehicular Technology Conference, vol. 2022-June. Institute of Electrical and Electronics Engineers Inc., 2022. [7] M. Shan, K. Narula, Y. F. Wong, S. Worrall, M. Khan, P. Alexander, and E. Nebot, “Demonstrations of cooperative perception: Safety and robustness in connected and automated vehicle operations,” Sensors (Switzerland), vol. 21, pp. 1–31, 1 2021. [8] L. Schories, N. Dahringer, U. Piram, A. Raut, S. Nikolaou, I. Gragkopoulos, I. Tsetsinas, and M. Panou, “Safety performance assessment via virtual simulation of V2X warning triggers to cyclists with models created from real-world testing,” Sustainability (Switzerland), vol. 16, 1 2024. [9] Bundesanstalt f¨ ur Straßenund Verkehrswesen and Forschungsvereinigung Automobiltechnik, “GIDAS (German In-Depth Accident Study),” https://www.gidas.org/, accessed: 2025-04-09. [10] M. Bauder, A. Festag, T. Kubjatko, and H. G. Schweiger, “Data accuracy in vehicle-to-x cooperative awareness messages: An experimental study for the first commercial deployment of C-ITS in europe,” Vehicular Communications, vol. 47, 6 2024. [11] B. S. Bari, D. Puthal, and K. Yelamarthi, “Datasets in vehicular communication systems: A review of current trends and future prospects,” SN Computer Science, vol. 6, 3 2025. [12] G. Kueppers, J.-P. Busch, L. Reiher, and L. Eckstein, “V2aix: A multi-modal real-world dataset of etsi its v2x messages in public road traffic,” 2024. [Online]. Available: https://arxiv.org/abs/2403.10221 [13] C. Geller, B. Haas, A. Kloeker, J. Hermens, B. Lampe, T. Beemelmanns, and L. Eckstein, “CARLOS: An open, modular, and scalable simulation framework for the development and testing of software for C-ITS,” in IEEE Intelligent Vehicles Symposium, Proceedings. Institute of Electrical and Electronics Engineers Inc., 2024, pp. 3100–3106. [14] A. Piazzoni, J. Cherian, R. Vijay, L. P. Chau, and J. Dauwels, “CoPEM: Cooperative perception error models for autonomous driving,” in IEEE Conference on Intelligent Transportation Systems, Proceedings, ITSC, vol. 2022-October. Institute of Electrical and Electronics Engineers Inc., 2022, pp. 3934–3939. [15] M. Scholtes, L. Westhofen, L. R. Turner, K. Lotto, M. Schuldes, H. Weber, N. Wagener, C. Neurohr, M. H. Bollmann, F. Kortke, J. Hiller, M. Hoss, J. Bock, and L. Eckstein, “6-layer model for a structured description and categorization of urban traffic and environment,” IEEE Access, vol. 9, pp. 59 131–59 147, 2021. [16] Z. Liu, Z. Liu, Z. Meng, X. Yang, L. Pu, and L. Zhang, “Implementation and performance measurement of a V2X communication system for vehicle and pedestrian safety,” International Journal of Distributed Sensor Networks, vol. 12, 09 2016.