Showing posts with label Cruise. Show all posts
Showing posts with label Cruise. Show all posts

Monday, June 3, 2024

Five views into the Cruise Robotaxi Pedestrian Dragging Mishap

 On October 2, 2023, a Cruise robotaxi dragged a woman 20 feet underneath the vehicle in San Francisco. The circumstances of the mishap and everything else are complex. But the robotaxi industry was profoundly shaken.


Here are four descriptions of the events and what might be learned from those events. Each is in a different style, intended for a different audience.

Additional content:
  • A video podcast where I walk through the mishap events with Junko Yoshida & Bolaji Ojo: https://youtu.be/OaF6IbYoVHQ
  • Cruise also maintains a safety page. A the time of this writing the big fonts are used to say "transparent about safety" and "continuous improvement". So far not a lot of detail about what has changed and what transparency will mean as they get back on the road.


Monday, January 29, 2024

The Exponent Report on the Cruise Pedestrian Dragging Mishap

On October 2, 2023, a Cruise robotaxi Autonomous Vehicle (AV) in San Francis-co struck and then later – as part of different maneuver – dragged a pedestrian under the vehicle as part of a more complex road mishap. The circumstances included a different human-driven vehicle striking the pedestrian first and what amounts to an attempted cover-up by Cruise senior management of the final portion (the dragging part) of the mishap. High level Cruise leadership was largely sacked. A significant fraction of staff were let go as well. A 3rd party external review was commissioned. Now we have the report..

Quinn Emanuel Investigation report:  Original Link / Archive.org link

High level takeaways based on the Exponent analysis (just the technical portion of the report):

  • A computer-speed response could have avoided the initial crash between the Cruise AV and the pedestrian entirely. A slightly less quick response could have significantly reduced harm. This would have required the AV to recognize a person suddenly appearing in the travel lane in front of it, which it was not able to do. "Unavoidable" is not strictly true.
  • The Cruise AV accelerated toward a pedestrian it knew was directly in front of the AV in a crosswalk, apparently because its end-to-end neural network predicted the pedestrian would be out of the way by the time it got there. That additional speed contributed to having a tight reaction time.
  • The Cruise AV tracked the pedestrian through the collision with the adjacent Nissan. It continued accelerating even though a pedestrian had just been hit in an adjacent lane, additionally reducing available reaction time.
  • The Cruise vehicle had the legs of the trapped pedestrian in camera view during the entirety of the dragging event. In other words it had a sensor that saw the entrapment well enough that post-crash analysis confirmed that view. But that available sensor data did not result in a detection. Rather, the vehicle eventually stopped because of the resistance and excessive wheel spin caused by a rear wheel running up and over the pedestrian's legs and potentially other impediments to movement that might have been caused by the pedestrian trapped under the vehicle.
  • The Cruise vehicle definitely knew it had hit something, but decided to initiate a pull-over maneuver and restart motion for <reasons>. Exponent states: "an alert and attentive human driver would be aware that an impact of some sort had occurred and would not have continued driving without further investigating the situation"

Details follow:

Graph excerpt (page 83):

I'll start by saying it is good to see that Cruise released the 3rd party reports instead of keeping them secret. Sadly, the technical report is heavily redacted, but here is what I can see from what I have to work with.

Both the main report and the attachment are masterpieces of saying the most favorable thing possible given a situation that reflects poorly on the client sponsoring the project. I leave analysis of the lawyer-written portion to others. Here I focus on the technical portion written by Exponent. (Page numbers are from the Exponent report, which starts at page 1 of the appendix.) 

This is not an exercise in blaming Cruise technical workers for what happened. They were clearly pressured by those at the top to put technology into service before it was fully ripe. Rather, this is an exercise in showing how an apparently objective (superficially) technical report can severely skew the narrative. Perhaps some will say this analysis pushes the other way. But what the reader should not do is swallow the Cruise-sponsored narrative whole. Doing that will not serve the much-needed imperative to get Cruise on a track to safe deployment of this technology.

The Exponent report is written in what looks like an expert witness style for use in any potential court case. Exponent does a lot of work for car companies like that, and the "tell" is the phrase: "The findings presented herein are made to a reasonable degree of engineering and scientific certainty." (pg. 13)  This blog post is an informal look based on limited time (nobody paid me to do this post -- but I can assure you Exponent gets paid plenty for their work). Since the report is heavily redacted I might well change my thoughts based on further information or further consideration of the information already available. Nonetheless, here is what I got out of what I could see. I welcome any factual corrections.

  • Despite a previous statement by Cruise that Exponent's scope would be expanded to recommending safety engineering and process improvements, Exponent explicitly stated that these were out of scope for this report. Perhaps that is a separate effort, but that topic is explicitly out of scope for both this report and the Quinn Emmanuel main report.
    • Page 13: "A review of Cruise's overall safety systems, culture, and technology is beyond the scope of this investigation."
  • As documented by Exponent it seems the pedestrian was hurrying across an intersection right after the light had changed.
    • Page 44, table 6: 
      • Light changes at -10.0 seconds
      • Pedestrian visually appears to enter crosswalk at -7.9 seconds
      • 2.1 seconds have elapsed + dwell between opposing light changes, if any
      • Both Cruise and adjacent other vehicle have started moving at this point from the far side of the intersection.
  • The Cruise AV accelerated directly toward the pedestrian while that pedestrian was in a crosswalk in its own travel lane.
    • Page 83 figure 62: AV acceleration is positive between the times the pedestrian enters and exits the Cruise AV's lane. Speed increases from about 5 mph to about 13 mph during that time (visual approximate estimate from graph).
    • California Rules of the Road have an explicit that a vehicle in this situation should reduce speed:
      • "The driver of a vehicle approaching a pedestrian within any marked or unmarked crosswalk shall exercise all due care and shall reduce the speed of the vehicle or take any other action relating to the operation of the vehicle as necessary to safeguard the safety of the pedestrian." (21950(c))
  • Exponent both says that the pedestrian crash "may not have been avoidable" and that the vehicle could have avoided the crash. The word "may" is doing some really heavy lifting here. In fact, Exponent admits that the vehicle could have avoided the crash with a computer-speed fast response to a pedestrian in its path (the kind we have been promised every time an AV advocate says that computers can react faster than people to problems):
    • Page 16: "Calculations of potential AV stopping distance indicate that a collision of the AV with the pedestrian may not have been avoidable, even if the ADS had reacted to the collision between the Nissan and the pedestrian."
    • Page 66: "Accounting for brake system latency, the system would have needed to initiate a brake request no later than 0.78 seconds prior to AV-pedestrian contact in order to completely avoid contact. At this relative time, the pedestrian had just fallen into the AV’s travel lane, the AV was traveling at approximately 18.4 mph and the AV was approximately 6.55 m (21.5 ft) from the point at which AV-pedestrian contact occurred. It is noteworthy that a hypothetical brake activation occurring after this time (and prior to when the AV initiated braking at 0.25 s) would have potentially mitigated the severity of the initial collision between the AV and the pedestrian."
  • The Cruise vehicle maintained tracking with the pedestrian until almost a second after the impact with the adjacent vehicle. So it had the opportunity to detect that something very bad was happening in terms of a pedestrian hit by a vehicle a few feet from its lane, but it did not react to that available information.
    • Page 15: "As evidenced by the video and sensor data, the classification and tracking of the pedestrian became intermittent within 1.0 s after the initial contact between the pedestrian and the Nissan until the last correct object classification occurred at approximately 0.3 s prior to the collision between the AV and the pedestrian. This intermittent classification and tracking of the pedestrian led to an unknown object being detected but not accurately tracked by the automated driving system (ADS) of the AV and the AV detected occupied space in front of the AV."
    • Also see Table 6 on page 44:  0.9 seconds between Nissan contact and pedestrian track ID being dropped. Potentially much of that 0.9 seconds was waiting for tracking to recapture the pedestrian during an interval of missing detections.
  • The AV was accelerating during the entire event, including speeding up from 17.9 mph to 19.1 mph during the time the pedestrian was being struck by the adjacent Nissan.
    • Page 15: "At this separation time, the AV was traveling at a speed of approximately 17.9 mph and was approximately one car length behind the Nissan in the adjacent right lane."
    • Page 15: "This deceleration resulted in a vehicle speed reduction from approximately 19.1 mph, prior to the onset of braking, to approximately 18.6 mph at the time of impact with the pedestrian."
  • Exponent admits that lack of anticipation of a problem contributed to the mishap. It then attempts to excuse this by saying a human driver could not react to the pedestrian strike -- but we were promised robots would be better than humans.
    • Page 17: "The AV’s lack of anticipation of a potential future incursion of the pedestrian into its travel lane was a contributing factor to this incident. Reasonable human drivers would face challenges reacting to the pedestrian being projected into their lane of travel and would likely not have been able to avoid the collision under similar circumstances. This difficulty could be due to violations of expectancy, glare, or A-pillar obstruction, or a combination of these, as well as to a failure to predict the collision of the Nissan with the pedestrian in the adjacent lane and/or the resulting redirection of the pedestrian into their lane of travel. Moreover, reasonable human drivers would not likely have had adequate time to avoid the collision once the pedestrian was struck by the Nissan."
  • In fact, the AV did not realize it was hitting the pedestrian. Rather it noticed something ("occupied space") was in front of/beside it, which apparently it does treat as a Vulnerable Road User. It did not brake until 1/4 second before impact. The vehicle decelerated from 19.1 mph to 18.6 mph before the strike. It did in fact have a lidar observation of the pedestrian's leg, but did not classify this as a pedestrian. (A pedestrian prone in the travel lane after having fallen, tripped, been shoved, etc. is an eminently foreseeable road hazard.)  Any statement about initiating aggressive braking before impact is a bit over-stated. To be sure, it takes a while to put on the brakes due to physical constraints. It is more like a case of better late than never, with aggressive braking more properly characterized as initiating before impact but actually taking place after impact.
    • Page 15: "The ADS started sending steering and braking commands to the vehicle at approximately 0.25 s prior to the collision between the AV and the pedestrian due to the detection of occupied space in front of the AV. Consequently, just prior to the collision with the pedestrian, the AV’s heading momentarily changed rightward, and the vehicle began decelerating. This deceleration resulted in a vehicle speed reduction from approximately 19.1 mph, prior to the onset of braking, to approximately 18.6 mph at the time of impact with the pedestrian."
    • Page 16: "Only the pedestrian’s raised leg, which was bent up and out toward the adjacent lane, was in view of these lidar sensors immediately prior to collision."
    • Page 83 figure 62: braking force at best -0.4g or -0.5g at time of impact, spiking down to perhaps -1.2g right after impact.
  • Exponent gives <reasons> why the dragging occurred, but they admit that a human driver would not have made the mistake of dragging a pedestrian under the vehicle:
    • page 17: "After the AV contacted the pedestrian, an alert and attentive human driver would be aware that an impact of some sort had occurred and would not have continued driving without further investigating the situation."
  • Exponent confirms that the pedestrian was dragged approximately 20 feet at speeds of up to 7.7 mph. This dragging occurred entirely after the vehicle initially stopped post-impact. This does not include whatever dragging might have occurred during the initial impact and initial stop.
    • Page 16: "During this maneuver, the AV reached a speed of 7.7 mph and traveled approximately 20 feet while dragging the pedestrian before reaching its final rest position."
  • The AV had camera data that it had a pedestrian trapped under it the whole time, but failed to recognize the situation. So any claim that this was all due to lack of a "trapped pedestrian sensor" would not be the whole story.   
    • Page 16: "The pedestrian's feet and lower legs were visible in the wide-angle left side camera view from the time of the collision between the pedestrian and the AV through to the final rest position of the AV."
  • The vehicle did a degraded mode shutdown after the dragging started not because it explicitly recognized it hit a pedestrian, but rather because it noticed something was wrong with the spinning of the wheel that was over the pedestrian's legs. Note that they say the degraded state initiated an "immediate stop" which took 3 seconds to complete even though the speed was slow.
    • Page 16: " A traction control system event was recorded at approximately 3.8 s after the initial contact between the pedestrian and the AV due to the pedestrian physically resisting the motion of the vehicle. An accumulated offset between the wheel rotation of the left-rear wheel relative to the others from the wheel speed sensors led to the AV entering a degraded state approximately 5.8 s after the initial contact between the pedestrian and the AV. This degraded state caused the vehicle to initiate an immediate stop, and the vehicle reached its final point of rest approximately 8.8 s after the initial contact between the pedestrian and the AV."
  • Exponent claims they know of no failures or faults that contributed to the incident. This is an odd statement -- does that mean dragging a pedestrian is intended functionality? More likely if pressed their expert would say it was due to a "functional insufficiency." But if that is the case, it means they had deployed a vehicle into public use as a commercial service that was not fully capable of operating safely within its intended Operational Design Domain. In other words they seem to be saying it was not "broken" -- just unsafe.
    • Page 14: "Exponent did not identify any evidence of reported vehicle, sensor, actuator, or computer hardware failures or software faults that could have contributed to the incident."
    • Note that they did not opine there were no failures/faults, but rather that they "did not identify any evidence" -- which is a somewhat different statement since there is no sign they did a source code review, hardware diagnostics themselves etc. This limits the scope of their statement more than might be obvious at a quick read.

We also learned (page 29): "The Cruise ADS employs an end-to-end deep learning-based prediction model in order to interpret the motion of tracked objects and contextual scene information in order to generate predicted object trajectories."   I have no idea how they might validate an end-to-end model for life critical applications used in a system which, apparently, is happy to accelerate toward a pedestrian in a crosswalk because the black box model says it will work out fine.  (Maybe there is a deterministic safety checker, but it obviously did not work well enough in this mishap.)

Thursday, January 25, 2024

Cruise Pedestrian Dragging Incident Report

Cruise has released materials from an investigation into the pedestrian dragging incident and related external communication transparency failures of last October. There is a lot to unpack, but remarkably little of it truly has to do with safety. Most of it seems to be an exercise in blaming senior leadership (who have largely been sacked) and explaining why the problems were more due to misguided individuals and poor leadership rather than malefaction. 

Cruise Blog post: Original Link / Archive.org link
Quinn Emanuel Investigation report:  Original Link / Archive.org link

The explanations in the report include some pretty remarkable events. Repeated internet disruptions across multiple meetings only for the regulatory audience when showing the videos that affected the pedestrian dragging part.  Combined with intentionally not showing the disrupted portions to others, including especially the press. And failing to correct mistaken impressions that were favorable to Cruise (while aggressively trying to fix ones that were unfavorable). And leaving the bad part out of public statements. And a paralegal who just didn't realize they should be putting the pedestrian dragging part into a report to NHTSA. Twice. And not talking to external parties who attended meetings to hear their side of the story in preparing this very investigative report when some key points had mixed evidentiary support.

Regardless of what you might think of the report veracity, my safety takeaways are:

  1. These reports do not actually address safety and safety processes. Initially Cruise said those topics would be addressed. However the Quinn Emanuel report specifically states those are out of scope, and instead limits inquiry to regulatory compliance and media relations issues. The Exponent report is clearly limited to root cause for that specific crash. Perhaps someone is working on an independent look at safety and safety processes, but it is not mentioned anywhere I could find.
  2. A pivotal moment (perhaps this will be the pivotal moment in retrospect) was in the timeline (page 12) Oct 3, 3:21 AM where the Director of Systems Integrity for Cruise created a video that, at the request of Cruise government affairs, left out the strike of the pedestrian and subsequent dragging. My recollection from listening to at least one journalist is that this video was later shown to journalists. An intentional decision not to tell the whole truth to the public gave regulators ammunition to blame Cruise for holding back regardless of the ultimate facts of those discussions.
  3. The significantly redacted Exponent report has some new information about the crash dynamics, including the vehicle speed at impact. Those are of interest to understanding the root cause, but have little to do with much bigger safety concerns. The very final sentence of the report is the most telling, and accurately summarizes the big safety concern for this particular mishap: "After the AV contacted the pedestrian, an alert and attentive human driver would be aware that an impact of some sort had occurred and would not have continued driving without further investigating the situation."
Cruise's narrow technical problem boils down to their vehicle continuing driving even though it knew that some sort of impact had occurred. Their regulatory/governance problem of the moment is the scope and intent of the cover-up.

Cruise's bigger safety problems are out of scope for this report, and from everything I've seen remain unaddressed. That topic will have to be resolved for Cruise to remain viable.

Saturday, October 28, 2023

A Snapshot of Cruise Crash Reporting Transparency: July & August 2023

A comparison of California Cruise robotaxi crash reports between the California DMV database and the NHTSA SGO database reveals significant discrepancies in reporting. 31 crashes reported to NHTSA do not appear in the California DMV database. This includes seven unreported injury crashes. Of special note is the Cruise crash with a fire truck that caused serious injury to an occupant of the Cruise robotaxi does not appear as a California DMV crash report. To be sure, Cruise might not be legally required to file these reports, but the situation reveals an apparent lack of transparency.

Comparison Results:

39 crashes were identified across both databases for the date-of-crash months of July 2023 through August 2023. The comparison was performed on October 28, 2023, so there was adequate time for all such crashes to have been reported.

Each database was missing one or more crashes found in the other database:

  • 39 crashes in the NHTSA base, including 8 also found in the CA DMV database.
  • 31 crashes reported to NHTSA were not in the California DMV database
  • The California DMV database was in particular missing SEVEN (7) crash reports which indicated an injury had occurred or might have occurred.
  1. NHTSA 30412-5968: Other car ran a red light striking Cruise; passenger of other vehicle treated on scene for minor injury.
  2. NHTSA 30412-5982: Other car ran into Cruise; passenger of other vehicle transported by EMS for further evaluation. Possible injury ("unknown" injury status).
  3. NHTSA 30412-6144: Cruise crash with fire truck; serious injury reported to passenger
  4. NHTSA 30412-6145: Cruise reversing contacted cyclist; minor injury reported to cyclist
  5. NHTSA 30412-6167: Cruise rear-ended after braking; minor injury reported to other vehicle driver
  6. NHTSA 30412-6175: Cruise hit pedestrian crossing in front of it (said to be crossing against light); moderate injury to pedestrian
  7. NHTSA 30412-6270: Cruise hit from behind after stopping to yield to pedestrian in crosswalk; minor injury to passengers inside AV
Two crashes involved non-motorists:
  • 30412-6145 with a cyclist
  • 30412-6175 with a pedestrian

        Why the Disparity?

        The thing that makes this complicated is that CA DMV does not require reporting crashes for "deployment" operation -- just for "testing" operation. Apparently when the regulations were written they did not anticipate that companies would "deploy" immature technology, but that is exactly what has happened.

        It is difficult from available information to check how Cruise is determining which crashes must be reported to California DMV (testing) and which do not have to be reported (deployment). In practice it might boil down to a management decision which ones they want to report, although there might be some less arbitrary internal decision criterion in use.

        CA DMV should require all companies to provide them with unredacted copies of all NHTSA SGO reports to provide improved transparency. For the foreseeable future, making a distinction between "testing" and "deployment" with no driver in the vehicle serves no useful purpose, and impairs transparency. If there is no driver it is a deployment, and should be held to the standards of a production vehicle, including reporting both crashes and driving behavior that puts other road users at undue risk. This is true for all companies, not just Cruise.

        Other notes:

        • CA DMV reports have the street names, yet Cruise redacts this same information from reports filed with NHTSA claiming it is "confidential business information." It is difficult to understand how information publicly reported by California can be classified as "confidential."
        • The NHTSA database does not have the date of the crash, although the California database has that information.
        • Crashes considered were for reported incident dates of July & August 2023, considering only uncrewed (no safety driver) operation.
        • It is our understanding that Cruise is not required to report all crashes that occur during deployment to California DMV. So it is possible that these reporting inconsistencies are still in accordance with applicable regulations.
        • All crashes on this spreadsheet in the NHTSA database list the "driver/operator type" as "Remote (Commercial / Test)" so it is not possible to distinguish whether the vehicle was considered in commercial service at the time of the crash. 
        • At the time of this posting the tragic Oct. 2nd severe injury crash that involved a Cruise robotaxi dragging a pedestrian who had been trapped under the vehicle has also not been reported, while another crash on Oct 6th has. There is nothing on the Oct 6th CA DMV form to indicate that the reported crash was specific to a testing permit vs. deployment permit.

        Review status: 

        This data has not been peer reviewed. Corrections/additions/clarifications are welcome to improve accuracy. The data analysis results are included below.

        Google Spreadsheet link:  https://docs.google.com/spreadsheets/d/1o9WWzMpiuum-QHZk9goY68gnBZuRC1InxUSMa7-h4DU/edit?usp=sharing

        Data sources: 






        Updated 10/30/2023 to incorporate three more crash reports found in a wider search of the SGO database. All CA DMV crash reports have now been identified in the SGO database.






        Friday, October 27, 2023

        The Cruise Safety Stand-Down -- What Happens Next?

        Cruise has announced a fleet-wide safety stand-down. This involves suspending driverless operations in all cities, reverting to operation only with in-vehicle safety drivers.

        I'm glad to see this step taken. But it is crucial to realize that this is the first step in what it likely to prove a long journey. The question is, what should happen next?


        Loss of public trust is an issue as they say. And perhaps there was an imminent ban in another state forcing their hand to be proactive. But the core issues almost certainly run deeper than mismanaging disclosure of the details of a tragic mishap and doing damage control with regulatory trust. 

        The real issues will be found to have their roots in the culture of the company. Earnest, smart employees with the best of intentions can be ineffective at achieving acceptable safety if the corporate culture undermines their official company slogan of "safety first, always."

        This is the time to ask the hard questions. The answers might be even harder, but they need to be understood for Cruise to survive long term. It is questionable whether they could survive a ban in another state. But escaping that via a stand-down only to implement a quick fix won't be enough. If we see business as usual restored in the next few weeks, that is almost certainly a shallow fix. It will simply be a matter of time before a future adverse situation happens from which there will be no recovery. 

        This is the moment for Cruise to decide to lean into safety.

        The details are too much for a post like this, but the topics alone indicate the scope of what has to be considered:
        • Safety engineering -- Have they effectively identified and mitigated risks?
        • Operational safety -- Safety procedures, inspections, maintenance, management of Operational Design Domain limits responsive to known issues, field data feedback, etc.  This includes ensuring their Safety Management System (SMS) is effective.
        • System engineering -- Do the different pieces work together effectively? This includes all the way from software in 3rd party components to vehicle integration to ability of remote operators to effectively manage gaps in capabilities ... and more
        • Public messaging and regulatory interface -- Building genuine trust, starting with more transparency. Stop the blame game; accept accountability. Own it.
        • Investor expectations -- Determine a scaling plan that is sustainable, and figure out how to fund it in the likely case it is longer than what was previously promised
        • Definition of acceptable safety -- More concrete than seeing how it turns out based on crash data, with continual measurement of predictive metrics
        • Safety culture -- Which underlies all of the above, and needs to start at the top.
        And I'm sure there are more; this is just a start.

        Near-term, the point of a safety stand-down is to stabilize a situation during uncertainty. The even more important part comes next: the plan to move forward. It will take weeks to take stock and create a plan, with the first days simply used to organize how that is going to happen. And months to execute that plan. Fortunately for Cruise there is an existing playbook that can be adapted from Uber ATG's experience with their testing fatality in 2018. Cruise should already have someone digging into that for initial ideas.

        An NTSB-style investigation into this mishap could be productive. I think such an investigation would be likely to bring to light new issues that will be a challenge to the whole industry involving expectations for defensive driving behaviors and post-crash safety. If NTSB is unable to take that on, Cruise should find an independent organization who can do something close. But such an investigation is not the fix, and cultural improvements at Cruise should not wait for one to conclude. However, an independent investigation can be the focal point for deeper understanding of the problems that need to be addressed.

        ------------------------------------------------

        Philip Koopman is a professor at Carnegie Mellon University in Pittsburgh Pennsylvania, USA, who has been working on self-driving car safety for more than 25 years.   https://users.ece.cmu.edu/~koopman/

        Saturday, October 21, 2023

        Safety Analysis of Two Cruise Robotaxi Pedestrian Injuries

        Cruise has now had two pedestrian injuries in San Francisco, with the more severe one being complicated because it involved a pedestrian first hit by another vehicle.  NHTSA has launched an investigation based on those injuries and at least two other public video reports of close encounters. This makes available the relevant crash reports, so we have more direct information about what happened. The question asked in this piece is what can be done to avoid similar crashes in the future.


        On a numbers basis, two pedestrian injuries in a span of fewer than six weeks for a fleet of a couple hundred vehicles in San Francisco is a concern, so this is worth some analysis based on available information.

        • First injury: Aug. 26, 2023.  A pedestrian stepped off the curb into a crosswalk right in front of a Cruise vehicle at the change of a traffic light. The Cruise swerved, then braked. Impact at 1.4 mph. Pedestrian transported by EMS.
        • Second injury: Oct 2, 2023. A pedestrian crosses on the opposite side of a cross-street in front of the Cruise vehicle and another vehicle next to it. Both vehicles proceeded through the intersection as a pedestrian was in a crosswalk across their paths. The other vehicle struck the pedestrian at an undisclosed speed, who was then run over by the Cruise vehicle and trapped under it with severe injuries.
        In both cases the injuries were severe enough to require transport. For the second crash the pedestrian was almost completely underneath the rear of the vehicle.  (It is worth noting these descriptions are written 100% by Cruise. The reader should assume the most favorable-to-Cruise possible interpretation of events has been presented. If something obviously relevant is omitted, such as the impact speed for the second injury, one is justified in assuming it would be unfavorable to Cruise if disclosed.)

        Cruise, predictably, blames others for both crashes, although in both cases without review of the video it is difficult to be sure that is really true. However, we set blame aside and instead ask the question: what can be done to avoid the next pedestrian injury in similar circumstances.

        First Pedestrian Crash


        For the first crash, the question is whether a reasonable human driver would have had contextual clues that this pedestrian was about to enter the crosswalk even though the light had changed. For example, were they running to catch a bus pulling up to a stop across the street?  Were they "distracted walking?" Or were they at a complete stop on the curb and literally jumped out into the street? Opportunities for improvement include asking these questions:
        • Were there obvious contextual clues that the pedestrian would attempt a last second crossing? What are common cases, and are they covered by the Cruise AV design?
        • Why did the vehicle swerve before stopping instead of doing both at once?
        • Could/should the Cruise vehicle have followed a less aggressive acceleration profile given the likely risk of a pedestrian entry into the crosswalk in that type of circumstance?

        Second Pedestrian Crash


        For the second crash, things are more complicated. Let's break down the sequence, taking into account the initial setup sketched below (note that both vehicles are in the middle of an intersection, but the sketch tool I used did not make this easy to represent):

        1. There are two vehicles starting through an intersection, side by side, with two lanes in that direction of travel. From a top view the other, human driven, dark-colored vehicle is on the left (faster lane) and the lighter-colored Cruise is on the right (curb lane).
        2. A pedestrian is walking across the far side of the intersection in the crosswalk. At the same time, both vehicles accelerate into the intersection. The most likely situation is the Cruise vehicle was a bit behind the other vehicle (although this is an educated guess based on the description of the events).
        3. Cruise says the pedestrian entered the crosswalk after the light changed, crossed in front of the Cruise vehicle, then stopped in the other vehicle's lane. The other driver presumably thought the pedestrian would clear the travel lane in time, and did not slow down.
        4. The other vehicle hit the pedestrian. Cruise says the pedestrian was deflected back into the Cruise vehicle's lane.
        5. The Cruise vehicle "braked aggressively" in response to a surprise pedestrian appearing in its lane, but hit the pedestrian shortly after.
        6. The Cruise vehicle had sufficient forward speed that it ran over the pedestrian and came to a stop with the pedestrian trapped under the rear axle. Both of the pedestrian's feet protruded from under the vehicle by the left rear tire, with that tire on top of one leg. (Photo link below.)
        7. The pedestrian was severely injured by a combination of the two vehicle strikes. Information about the ultimate outcome for that pedestrian is not currently available, although we hope that a recover is quick and as complete as possible.

        California Rules of the Road have an interesting requirement for crosswalks:

        "(c) The driver of a vehicle approaching a pedestrian within any marked or unmarked crosswalk shall exercise all due care and shall reduce the speed of the vehicle or take any other action relating to the operation of the vehicle as necessary to safeguard the safety of the pedestrian."  (emphasis added)

        It is interesting to ask if the Cruise vehicle actually exhibited "all due care."  It likely did not reduce speed from its normal green light acceleration, or Cruise would have taken credit for having done so.  (If they want to provide more details I will gladly update this statement.)

        Of note is the Cruise position that their vehicle stopped as quickly as possible once the pedestrian was in their lane, in effect claiming the collision was unavoidable. But that position is not necessarily true in the larger context, especially if one learns from this crash for the next potential pedestrian crosswalk collision. The question is when the Cruise AV could have stopped. There are at least three possible decision points for stopping to avoid this collision with the pedestrian, and the Cruise vehicle appears not to have exercised the first two:

        • The light changes green, but there is a pedestrian still in the crosswalk in the Cruise vehicle's direction of travel in front of the Cruise vehicle. Did it slow down?  Or execute a normal acceleration because it predicted the pedestrian would be clear by the time it got there?   A prudent human driver would have waited, or more likely crept forward while waiting to signal cars behind it not to honk for failing to recognize a green light.
        • The pedestrian clears the Cruise lane, but the Cruise vehicle clearly sees the pedestrian about to be hit by the adjacent vehicle. The Cruise vehicle could have (I would argue should have) stopped to avoid being close to an injury event. Expecting it to predict a pedestrian collision trajectory is asking a lot -- but it should have stopped precisely because it cannot predict what will happen after such a collision. Safety demands not going fast past a pedestrian who is about to be hit by another vehicle in an adjacent lane. But this is precisely what the Cruise vehicle did.
        • The pedestrian lands in the Cruise lane and the Cruise vehicle has not slowed down yet. By then it is too late, and it runs over the pedestrian.  This could likely have been avoided by a prudent driving strategy that addresses the previous two decision points.

        The Redacted Confidential Business Information

        (This section added October 25, 2023 based on new information.)

        California DMV issued an order suspending the driverless operating permits for Cruise robotaxis on October 24, 2023 as a response to the circumstances of this second crash.  Link to order here.

        This order brought to light that after the vehicle had stopped post-crash, it started movement again with the pedestrian still under the vehicle, dragging that victim about 20 feet at a speed up to 7 mph, which was said to contribute to severe injuries. This strongly suggests the vehicle did not account for a pedestrian being trapped underneath it when deciding to move. (It is possible a remote operator was unaware of the trapped pedestrian and remotely commanded a pull-to-side maneuver. We'll have to see what is revealed during any investigation.)

        Cruise also published a blog post with additional information that day. A straightforward update to the crash report is to add at the end as at least part of the "redacted confidential business information" the following (quoted from the Cruise blog post): 
        "The AV detected a collision, bringing the vehicle to a stop; then attempted to pull over to avoid causing further road safety issues, pulling the individual forward approximately 20 feet."

        This certainly makes Cruise look bad, but that is not an acceptable reason for a redcation. It is difficult to understand how this can reasonably be characterized as "confidential business information" in a mandatory crash report.

        Calling Emergency Services

        Also crucial for practical safety, but barely talked about, is notification of emergency services ("call 911"). News reports indicate that a passer-by called 911, not Cruise. In fact, in neither collision report do they take credit for notifying emergency services. This is a glaring omission that needs to be addressed.

        Consider: they had a vehicle tire on top of a pedestrian's leg and did not call 911. (Again, if this is incorrect I will update this statement when I get that information.) That's a HUGE problem nobody is talking about. A human driver would have realized they just ran someone over and either called 911 or asked someone to do so. If there had been no passer-by, how many minutes would that pedestrian have been trapped under the car before help was summoned?

        The Cruise AV and its support team need to realize an injury has happened and take immediate action. It would be no surprise if the remote operators had no idea what the vehicle had run over. By the time they download and review video logs (or whatever) that pedestrian has been trapped under the vehicle for a while. That's not acceptable. They need to be able to do better.

        Cruise Safety Record

        The first pedestrian injury happened just over two weeks after the August 10th California PUC meeting that granted operating permits to Cruise. That report was overshadowed by the crash apparently due to failure to yield to a fire truck on August 17th. That night also saw another injury involving a collision to a different vehicle driver.  So we are seeing a steady stream of injuries.

        Cruise blames crashes on other parties to the maximum degree possible, and ignores injuries where it is less than 50% at fault (there have been others; notably a very ill-advised left turn maneuver by a Cruise robotaxi that resulted in multiple injuries).  Safety is not achieved by blaming others. If Cruise vehicles are crashing and injuring people more often than other vehicles, then that is an increased rate of injury regardless of blame.

        A company with a responsible safety culture would be asking what they can do to reduce the risk of future injuries -- regardless of blame. We will have to wait to see the outcome of this NHTSA investigation, and whether Cruise proactively improves safety or waits for NHTSA to force the issue.

        As a note to likely responses to this analysis: comparisons to human driver errors are not productive. Indeed, another driver hit the pedestrian first in the second crash. But another driver being negligent does not forgive imprudent driving behavior from a robotaxi that is being relentlessly touted as safer than human drivers. They should be continuously improving, and our hope is that this analysis highlights areas that they and other robotaxi companies need to improve.

        Supporting Information