Proving the Safety of Autonomous Systems with Formal Methods - What Can You Expect?

  • Theodor Tempelmeier
Part of the Studies in Computational Intelligence book series (SCI, volume 391)


This contribution briefly recapitulates the notions of autonomous systems and formal methods and clarifies their meaning as used in the following. Two examples of possible fallacies with formal syntax and semantics are given, but irrespectively of that, a perfect formal method is assumed for the rest of the paper. In the main part three examples are given, where even with a perfect formal proof of certain safety aspects, safety may nevertheless be compromised. The reasons for this are environmental influence, unaccounted world knowledge, and misbehaviour of neighbour systems. As conclusion, however, the use of formal methods is not discouraged at all, but awareness of the limitations of formal methods is requested from everybody.


Unify Modeling Language Formal Method Autonomous System Automate Guide Vehicle Neighbour System 
These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves.


Unable to display preview. Download preview PDF.

Unable to display preview. Download preview PDF.


  1. 1.
    ISO/IEC, IEEE, International Standard ISO/IEC 26702, IEEE Std 1220-2005, First edition 2007-07-15, Systems engineering – Application and management of the systems engineering process (2007)Google Scholar
  2. 2.
    INCOSE, A Consensus of the INCOSE Fellows – Definition of a system (2011), (accessed June 30, 2011)
  3. 3.
    Selic, B.: Counterpoint. UML 2: Designed for Architects. IEEE Software 27(6), 55–57 (2010)Google Scholar
  4. 4.
    OMG, UML Profile for MARTE: Modeling and Analysis of Real-Time Embedded Systems. Version 1.0. OMG Document Number: formal/2009-11-02. Standard document URL: Section F.8.15 (2009),
  5. 5.
    Frese, U., Hausmann, D., Lüth, C., Täubig, H., Walter, D.: Zertifizierung einer Sicherungskomponente mittels durchgängig formaler Modellierung. In: Maalej, W., Bruegge, B. (eds.) SoftwareEngineering 2008 – Workshopband. Proceedings Series of the Gesellschaft für Informatik (GI). LNI, vol. P-122, pp. 335–338 (2008)Google Scholar
  6. 6.
    Tempelmeier, T.: Microprocessors in Factory Automation – A Case Study of an Automated Guided Vehicle System and its Integration into a Hierarchical Control Structure. In: Proceedings EUROMICRO 1986, Microprocessing and Microprogramming, Venice, September 15-18, vol. 18, pp. 647–656 (1986)Google Scholar
  7. 7.
    Roßkopf, A., Tempelmeier, T.: Aspects of Flight Control Software – A Software Engineering Point of View. Control Engineering Practice 8, 675–680 (2000)CrossRefGoogle Scholar
  8. 8.
    Tempelmeier, T.: Formal Methods – An Informal Assessment. Technischer Report. Dasa MT36 SR-1775-a. Daimler-Benz Aerospace, Ottobrunn (May 1998)Google Scholar
  9. 9.
    Main Commission Aircraft Accident Investigation, Report on the Accident to Airbus A320-211 Aircraft in Warsaw (September 14, 1993) Warsaw (March 1994), (accessed June 30, 2011)
  10. 10.
    Bundesstelle für Flugunfalluntersuchung, Untersuchungsbericht AX001-1-2/02 (May 2004), (accessed June 30, 2011)
  11. 11.
    Einstein, A.: Geometrie und Erfahrung. Festvortrag in der Preußischen Akademie der Wissenschaften am 27 (January 1921) In: Mein Weltbild. Ullstein Buch Nr. 65, Berlin (1955)Google Scholar

Copyright information

© Springer-Verlag Berlin Heidelberg 2012

Authors and Affiliations

  1. 1.University of Applied SciencesRosenheimGermany

Personalised recommendations