Autonomously navigating the real world: lessons from the PG&E outage

123 points by scoofy 17 hours ago on hackernews | 95 comments

ChrisArchitect | 16 hours ago

Related context:

Waymo halts service during S.F. blackout after causing traffic jams

https://news.ycombinator.com/item?id=46342412

jtchang | 14 hours ago

How is this mode not a standard part of their disaster recovery plan? Especially in sf and the bay area they need to assume an earthquake is going to take out a lot of infrastructure. Did they not take into account this would happen?

vlovich123 | 13 hours ago

> While we successfully traversed more than 7,000 dark signals on Saturday, the outage created a concentrated spike in these requests. This created a backlog that, in some cases, led to response delays contributing to congestion on already-overwhelmed streets. We established these confirmation protocols out of an abundance of caution during our early deployment, and we are now refining them to match our current scale. While this strategy was effective during smaller outages, we are now implementing fleet-wide updates that provide the Driver with specific power outage context, allowing it to navigate more decisively.

Sounds like it was and you’re not correctly understanding the complexity of running this at scale.

jeroenhd | 7 hours ago

Sounds like their disaster recovery plan was insufficient, intensified traffic jams in already congested areas because of "backlog", and is now being fixed to support the current scale.

The fact this backlog created issues indicates that it's perhaps Waymo that doesn't understand the complexity of running at that scale, because their systems got overwhelmed.

shafyy | 6 hours ago

They probably do, they just don't give a shit. It's still the "move fast and break things" mindset. Internalize profits but externalize failures to be carried by the public. Will there be legal consequences for Waymo (i.e. fines?) for this? Probably not...

atherton94027 | 5 hours ago

Waymo cars have been proven safer than human drivers in California. At the same time, 40k people die each year in the US in car accidents caused by human drivers.

I'm very happy they're moving fast so hopefully fewer people die in the future

browningstreet | 5 hours ago

What Waymo profits?

They're one-of-one still. Having ridden in a Waymo many times, there's very little "move fast and break things" leaking in the experience.

They can simulate power outages as much as they want (testing) but the production break had some surprises. This is a technical forum.. most of us have been there.. bad things happened, plans weren't sufficient, we can measure their response on the next iteration in terms of how they respond to production insufficiencies in the next event.

Also, culturally speaking, "they suck" isn't really a working response to an RCA.

kotaKat | 4 hours ago

DR always stands for "didn't realize" in the aftermath of an event.

That's what they're learning and fixing for in the future to give the cars more self-confidence.

vlovich123 | an hour ago

What about San Francisco allowing a power outage of this magnitude and not being able to restore power for multiple days?

This kind of attitude to me indicates a lack of experience building complex systems and responding to unexpected events. If they had done the opposite and been overly aggressive in letting Waymo’s manage themselves during lights that are out would you be the first in line criticizing them then for some accident happening?

All things being considered, I’m much happier knowing Waymo is taking a conservative approach if the downside means extra momentary street congestion during a major power outage; that’s much rarer than being cavalier with fully autonomous behavior.

Animats | 11 hours ago

If the onboard software has detected an unusual situation it doesn't understand, moving may be a bad idea. Possible problems requiring a management decision include flooding, fires, earthquakes, riots, street parties, power outages, building collapses... Handling all that onboard is tough. For different situations, a nearby "safe place" to stop varies. The control center doesn't do remote driving, says Waymo. They provide hints, probably along the lines of "back out, turn around, and get out of this area", or "clear the intersection, then stop and unload your passenger".

Waymo didn't give much info. For example, is loss of contact with the control center a stop condition? After some number of seconds, probably. A car contacting the control center for assistance and not getting an answer is probably a stop condition. Apparently here they overloaded the control center. That's an indication that this really is automated. There's not one person per car back at HQ; probably far fewer than that. That's good for scaling.

gorfian_robot | 6 hours ago

relying on essentially remote dispatch to resolve these errors states is a disaster

michaelt | 5 hours ago

> For example, is loss of contact with the control center a stop condition?

Almost certainly no - you don’t want the vehicle to enter a tunnel, then stop half way through due to a lack of cell signal.

Rather, areas where signal dropouts are common would be made into no-go areas for route planning purposes.

rdiddly | 14 hours ago

No one seems sufficiently outraged that a private company's equipment blocked the public roads during an emergency.

doctorpangloss | 13 hours ago

On the contrary, I would prefer HN detach all threads expressing "concern." That way we don't have to make a subjective call if a comment is "concern" or "concern trolling" at all - they are equally uninteresting and do not advance curiosity.

ACCount37 | 12 hours ago

Based. Anyone complaining about HN being "insufficiently outraged" should go to Twitter and never return.

rdiddly | 11 hours ago

I was actually wondering more about the people whose streets they are. Didn't mean to indicate that I or anyone cares what HN thinks.

rcxdude | 2 hours ago

The internet lens tends to distort what's happening on the ground quite a lot. I would expect the people living there have different things to direct their ire to.

tengbretson | 13 hours ago

> No one seems sufficiently outraged

Harvesting outrage is about the only reliable function the internet seems to have at this point. You're not seeing enough of it?

rdiddly | 11 hours ago

I've seen plenty but about the wrong things.

jlebar | 11 hours ago

No one seems sufficiently outraged that human drivers kill 40,000 people a year in the US.

It's approximately one 9/11 a month. And that's just the deaths.

Worldwide, 1.2m people die from vehicle accidents every year; car/motorcycle crashes are the leading cause of death for people aged 5-29 worldwide.

https://www.transportation.gov/NRSS/SafetyProblem

https://www.who.int/news-room/fact-sheets/detail/road-traffi...

[OP] scoofy | 10 hours ago

Seriously. People are outraged about the theoretical potential for human harm while there is a god damn constant death rate here that is 4x higher than every other western country.

I mean really. I’m a self driving skeptic exactly because our roads are inherently dangerous. I’ve been outraged at Cruise and Tesla for hiding their safety shortcomings and acting in bad faith.

Everything I’ve seen from Waymo has been exceptional… and I literally live in a damn neighborhood that lost power, and saw multiple stopped Waymos in the street.

They failed-safe, not perfect, definitely needs improvement, but safe. At the same time we have video of a Tesla blowing through a blacked out intersection, and I saw a damn Muni bus do the same thing, as well as a least a dozen cars do the same damn thing.

People need to be at least somewhat consistent in their arguments.

paddleon | 10 hours ago

Hey, I hear you. And I'm sad. Because I'd like to say that the right way is to:

build infrastructure that promotes safe driving, and

train drivers to show respect for other people on the road

However, those are both non-starters in the US. So your answer, which comes down to "at least self-driving is better than those damn people" might be the one that actually works.

citrin_ru | 7 hours ago

I've spend some time driving in both the US and the UK and while infrastructure in the US could be improved I don't think that's the main issue.

What's different is driver training and attitude. Passing a driving test in the US is too easy to encourage new drivers to learn to drive. And an average American driver shows less respect to pedestrians, cyclists and other drivers, aggressive driving is relatively common. Bad drivers can be encountered in the UK of course but on average British drive better.

Huge SUV and pickup trucks are also part of the problem - they are more dangerous for everyone except people in such vehicle.

ACCount37 | 5 hours ago

Your "right way" is to try to fix human nature. A complete nonstarter.

If we could do anything like "train drivers to show respect for other people on the road" at scale, then we'd live in a different world by now.

forshaper | 4 hours ago

I currently live in a place where, when walking on the street, I routinely almost get hit by vehicles while crossing crosswalks with the cross light on.

However, I used to live in a place where every local driver did an 'after you' that included pedestrians, regardless of road rules, and generally drove the speed limit (and usually less).

Both of these places in the United States!

The latter is not impossible, just rare.

TylerE | 9 hours ago

Why lie? If you have a valid point, make it. Don't pull made up stats out of your ass.

The US isn't close to being the highest per traffic fatality rate in the western hemisphere.

I count 14 countries higher.

https://en.wikipedia.org/wiki/List_of_countries_by_traffic-r...

DharmaPolice | 8 hours ago

When people say "western" they often don't mean "western hemisphere" but the "first world". So Peru wouldn't be "western" by this definition but Australia might be.

throwaway2037 | 7 hours ago

Yeah, HN just loves the term "The West" / "Western", which weirdly includes Australia and New Zealand, but excludes Japan, South Korea, and Taiwan. (What about South Africa? Unsure.) To me, it is better to say something like "G7-like" (or OECD) nations, because that includes all highly developed nations.

trollbridge | 6 hours ago

It’s referring to a specific culture of people.

potato3732842 | 3 hours ago

No, what they really mean is "a subset of typically rich typically western europe that I can cherry pick to prove my point" though anywhere formerly colonized by a European power and any developed nation in Asia is fair game depending on context.

Notice eastern europe is nearly always left out of social issue discussions.

Some Mediterranean bordering nations are always left out of government efficacy discussions.

It's not about comparing like-ish for like-ish. It's about finding a plausibly deniable way to frame the issue so that the US gets kneecapped by the inclusion of West Virginia or 'bama New Mexico or Chicago or whatever else it is that is an outlier and tanks its numbers while the thing on the other side of the comparison exempts that analogue entirely and this makes whatever policy position the person doing the framing is advocating for look good.

You see this slight of hand up and down and left and right across every possible topic of discussion in communities composed of american demographics that generally look towards Europe for solutions for things.

verteu | an hour ago

No, they're generally referring to the set of countries depicted in these maps [1], for the reasons described in the article [2].

[1] https://en.wikipedia.org/wiki/Western_world#/media/File:West...

[2] https://en.wikipedia.org/wiki/Western_world

xnorswap | 8 hours ago

I thought the UK ranked well, I didn't realise it ranked that well.

Maybe there's something to be said for left-hand driving, I see Japan ranks very highly too. ;)

The real reason is I guess we take road safety seriously, we have strict drink-driving laws, and our driving test is genuinely difficult to pass.

I seem to remember road safety also featuring prominently throughout the primary national curriculum.

And of course, our infamous safety adverts that you never quite forget, such as: https://www.youtube.com/watch?v=mKHY69AFstE

TylerE | 8 hours ago

The US is just a big place. We drive a lot. Average annual mileage is about 13k vs 7k in the UK.

adrianN | 7 hours ago

The USA don’t do very well on the deaths per km metric either.

throwaway2037 | 7 hours ago

    > Maybe there's something to be said for left-hand driving
Is this written in jest, or is there something more serious behind it? Off the top of my head, I cannot think of an obvious reason why "road handedness" (left vs right) would matter for road safety. Could it something about more people are right-handed so there is some 2nd order safety effect that I am overlooking?

xnorswap | 6 hours ago

Yes, it was in jest.

  ;)
Their comment was in jest, but I've wondered before if left vs right hand driving could affect safety. As you note right-handed people are more common. The countries with the highest percentages of left-handed people are around 12-13%.

In countries that drive on the right then drivers use their dominant hand for any controls that are on the inward side and their other hand for the control that are on the outward side of the driver.

Generally that means that the non-dominant hand handles exterior lighting, turn signals, windows, and locks. The dominant hand handles windshield wipers, transmission, and anything on the center console such as the climate and entertainment systems, and often also the navigation system.

In left drive counties that is mostly reversed for right-handed people, with the possible exception of the exterior lighting, turn signals, and windshield wipers. Those exceptions are the controls that are usually on stalks attached to the steering column. From what I've read sometimes manufactures use the same stalk positions in left and right drive models instead of reversing them like they do the rest of the controls.

Could dominant vs non-dominant hand for operating things on the center console make a difference? If everyone obeyed safety recommendations I'd expect it to not make enough difference to be noticeable, but not everyone obeys safety recommendations 100% of the time.

If someone for example tried to type in a destination using the on-screen keyboard on the navigation system console while driving I'd expect that they would take longer to do so if they were using their non-dominant hand, so they would be distracted longer.

TulliusCicero | 8 hours ago

> The US isn't close to being the highest per traffic fatality rate in the western hemisphere.

Is this a serious comment? Is that actually what you think they meant by "Western"? When people talk about Russia vs "the West", do you also think they mean Russia vs the Western hemisphere?

[OP] scoofy | an hour ago

nkrisc | 6 hours ago

The difference is those human-driven cars all have a driver who can be held accountable.

If I kill someone with my car, I’m probably going to jail. If a Waymo or otherwise kills someone, who’s going to jail?

> If I kill someone with my car, I’m probably going to jail

This is rarely true in the US. A driver's license is a license to kill with near impunity.

https://www.cbsnews.com/chicago/news/man-gets-10-days-in-jai...

ACCount37 | 5 hours ago

Should Waymo hire an "accountable" human who would go to jail if a Waymo car kills someone?

"Accountability" is fucking worthless, and I am tired of pretending otherwise.

benlivengood | 5 hours ago

Presumably, like Cruise, if the safety rate is appalling then they get their permits revoked which is 99% the same as jail for a company that only does self driving cars.

[OP] scoofy | an hour ago

> If I kill someone with my car, I’m probably going to jail.

So this is very much not at all true.

https://freakonomics.com/podcast/the-perfect-crime/

My entire point is that we don’t care about human lives on our roads. So yelling about the safety concerns about Waymos makes no sense.

jeroenhd | 7 hours ago

Road casualties are tied to geographical areas and America is an infamously dangerous place to live in when it comes to traffic. By fixing education, road design, and other factors, those 40k killed can be reduced by seven times before you even need to bother with automation. There's a human driver problem, but it's much smaller than the American driver problem.

Also, that still doesn't excuse Waymo blocking roads. These are two different, independent problems. More people die in care crashes than they do in plane crashes but that doesn't mean we should be replacing all cars by planes either.

mensetmanusman | 5 hours ago

Exactly, I tell people every order of magnitude more we spend on infrastructure reduces the self driving complexity as much likewise.

The education bit can’t be fixed by the government though in the short term, as the outcomes correlate too strongly with stable home life conditions (which are in free fall over the past 50 years).

mrguyorama | 4 hours ago

And also because America has an extremely strong anti-education demographic that is very well represented in congress and presidents.

"Parental authority" should not be an educational goal.

gruez | 4 hours ago

>By fixing education, road design, and other factors, those 40k killed can be reduced by seven times before you even need to bother with automation.

1. [citation needed]

2. Just because it's theoretically possible, doesn't mean it's an option that actually exists. I'm sure you can dream up of some plan for a futuristic utopia where everybody lives in a 15 minute city, no private cars are needed, and the whole transportation system is net zero, but that doesn't mean it's a realistic option that'll actually get implemented in the US, nor does it mean that we we should reject hybrid or EVs on the basis that they're worse than the utopian solution, even though they're better than the status quo of conventional ICE cars.

jeroenhd | 22 minutes ago

> 1. [citation needed]

Traffic-related death rate statistics for Denmark (being 7x lower than the US), Sweden, Norway, Japan. The US does remarkably bad on this statistic, even compared to Canada.

> 2. Just because it's theoretically possible, doesn't mean it's an option that actually exists.

Denmark exists. I've been there. There were cars.

I think the west in general is lagging behind when it comes to EV adoption (and given the politico-corporate interests of many governments, I don't expect that to change). I don't think anybody wants to completely abolish cars in general and I think the drive to maintain ICE cars with all of their downsides just to support a fledgling industry is a ridiculous waste of taxpayer money.

hackable_sand | 5 hours ago

I believe that is caused by having lots of cars driving around.

mikeyouse | 5 hours ago

American roads are uniquely dangerous for passengers in cars and for pedestrians compared to other developed countries..

TeMPOraL | 11 hours ago

> a private company's equipment blocked the public roads

That would be like every traffic incident ever? I don't think US has public cars or state-owned utilities.

adammarples | 10 hours ago

Typically people move aside for emergency vehicles

jdietrich | 8 hours ago

Ask any EMT or paramedic - an astonishingly large proportion of human drivers panic in the presence of an ambulance and just slam their brakes on.

SequoiaHope | 8 hours ago

My concern is that one company can have a malfunction which shuts down traffic in a city. That seems new or historically rare. I understand large scale deployment will find new system design flaws so I’m not outraged, but I do think we should consider what this means for us, if anything.
I think the blog is strongly hinting us to focus on the real problem -- the electrical utility and I have to agree.

The only other option I can think of is to build some kind of high density low power solar powered IoT network that is independent of current infrastructure but then where is the spectrum for that?

trollbridge | 6 hours ago

A power outage should not cause robot cars to block intersections.

TeMPOraL | 4 hours ago

Lack of Internet access should not prevent cars - or any other devices - from starting, yet here we are.

gruez | 4 hours ago

>My concern is that one company can have a malfunction which shuts down traffic in a city.

That's hardly new. What do you think happens to traffic when a semi flips over on a busy interstate, or electricity goes out, turning all traffic lights into 4 way stops and severely limiting throughput?

mrguyorama | 4 hours ago

It blocks a single road and yet that makes the news and people have to route around it and it disrupts a day.

What happens when one company's engineering failure does that to most roads?

For reference, the US considers tactically blocking traffic to be something that smart terrorists or nation state adversaries would want to do to significantly harm the US economically.

What do these cars do if Google's entire self driving infrastructure falls over because some component gets misconfigured? It will happen eventually.

throwawaysoxjje | 5 hours ago

Why would I be, when I don’t have any standard for comparison.

How many human drivers did similar because the power went out?

Papazsazsa | 14 hours ago

The symbolic irony of this situation is almost too rich to bear.
Interesting that some legacy safety/precaution code caused more timid and disruptive driving behavior than the current software route planner would've chosen on its own.
I suspected this. They were moving, but randomly to an observer. I’d seen about 2 out of maybe 20 stopped Waymos navigating around Arguello and Geary area in SF Saturday at 6PM. What was worse was that there was little to no connectivity service across all 3 main providers deeper in the power outage area as well - Spruce and Geary or west of Park Presidio (I have 2 phones, with Google Fi/T-Mobile, AT&T, and Verizon).

ec109685 | 12 hours ago

Do Waymo’s have Starlink or another satellite based provider backup? Otherwise, what do they if cell service goes down and they need to phone home for confirmation?

apexalpha | 12 hours ago

Cell services is usually around for a while when power goes down.

I doubt they have more than that.

trollbridge | 6 hours ago

That seems like a major oversight. Adding Starlink wouldn’t add that much marginal cost.

snake_doc | 5 hours ago

Cell towers just need power to keep functioning, starlink adds no utility in an urban dense environment with fiber.

multjoy | 4 hours ago

It would encourage Starlink to put yet more crap into Low Earth Orbit and see them fill the atmosphere with barely understood pollutants.

voidUpdate | 10 hours ago

> "the resulting congestion required law enforcement to manually manage intersections"

Does anyone know if a Waymo vehicle will actually respond to a LEO giving directions at a dark intersection, or if it will just disregard them in favour of treating it as a 4 way stop?

fc417fc802 | 10 hours ago

I suddenly find that I really want an answer to this as well because I'm now imagining what might ensue if one of these attempted to board a car ferry. Typically there's a sign "turn headlights off", you're expected to maintain something like 5 mph (the flow of traffic should never stop), and you get directed by a human to cross multiple lane markings often deviating from the path that the vehicle immediately in front of you took.

voidUpdate | 10 hours ago

I think that Waymo isn't concerned about those types of scenario because they only operate in a limited area, and can tune their systems to operate best in that area (EG not worrying about car ferries, human-operated parking lots etc)

jvanderbot | 7 hours ago

Right. People still imagine that Level 5 is going to happen, and it is at best a long way off. You're talking full AI at some point.

nashashmi | 10 hours ago

This was found to be one of the early challenges of self driving: reading traffic signal gestures of traffic agents. It does it. But the jury is out if it does it well.

throwaway2037 | 7 hours ago

Your scenario seems to have a lot of overlap with a construction worker directing traffic around a road construction site. I have no idea if Waymo is any good at navigating these, but I am sure there is a lot of model training around these scenarios because they are common in urban driving environments.

voidUpdate | 7 hours ago

Don't they just have a stop/go board? Whereas an LEO at a crossing would have to use hand signals

testfrequency | 6 hours ago

The amount of times this has been asked with no confirmation leads me to believe they still do not.

Tesla fanboys gush about how FSD can understand LEO at irregular traffic conditions, but no company I’m aware of has confirmed their systems are capable.

HarHarVeryFunny | 6 hours ago

Teslas currently have a driver in the front who could take over in these situations.

Waymo said they normally handle traffic light outages as 4-way stops, but sometimes call home for help - perhaps if they detect someone in the intersection directing traffic ?

Makes you wonder in general how these cars are designed to handle police directing traffic.

It kind of makes sense. Why program or train on such a rare occurrence. Just send it off to a human to interpret and be done with it. If that's the case then Tesla is closer to Waymo then previously thought. Maybe even ahead.

krisoft | 5 hours ago

> The amount of times this has been asked with no confirmation leads me to believe they still do not.

They do follow hand signals from police. There are many videos documenting the behaviour. Here is one from waymo: https://waymo.com/blog/2024/03/scaling-waymo-one-safely-acro...

Look for the embed next to the text saying “The Waymo Driver recently interpreting a police officer’s hand signals in a Los Angeles intersection.”

Or here is a video observing the behaviour in the wild: https://youtu.be/3Qk_QhG5whw?si=GCBBNJqB22GRvxk1

Do you want confirmation about something more specific?

moomoo11 | 8 hours ago

Tesla FSD would never have this issue according to Elon Musk.

bagels | 8 hours ago

- written from my flying roadster

joshribakoff | 8 hours ago

This reads to me, an angry resident, as an AI generated article that attempts to leverage the chaos that they caused, for marketing purposes — not as any sort of genuine remorse — underscoring why we shouldn’t be banning AI regulation in the USA.

nzoschke | 6 hours ago

> we are now implementing fleet-wide updates

That ~1000 drivers on the road are all better trained on what to do in the next power outage is incredible.

There will always be unexpected events and mistakes made on the roads. Continual improvement that is locked in algorithmically across the entire fleet is way better than any individual driver's learning / training / behaviorior changes.

imoverclocked | 6 hours ago

Humans seemed to navigate this just fine, even with all the Waymo road blocks and without extra training. If every unknown requires a software update, this system is doomed to repeat this behavior over and over in the long term.

charcircuit | 6 hours ago

>seemed to navigate this just fine

From my understanding the reason the Waymos didn't handle this was because humans were breaking traffic rules and going when they shouldn't have been. If most humans navigated it correctly, then waynos would have handled this better.

potato3732842 | 3 hours ago

This attitude is exactly how the Waymos came to handle the problem so poorly in the first place. The principal Skinner "everyone else else is wrong" bit is just icing on the cake.

Can't just program it to be all "when confused copy others" because it will invariably violate the letter of the law and people will screech. So they pick the legally safe but obviously not effective option, have it behave like a teenager on day 1 of drivers ed and basically freeze up. Of course that most certainly does not scale whatsoever, but it covers their asses so it's what they gotta do.

Humans do dumb stuff like drive their cars into flowing floodwaters and they show no signs of stopping. The Waymo Driver (the name for the hardware and software stack) is getting smarter all the time.

docjay | 3 hours ago

Humans do indeed drive into floodwaters like fools, but a critical point that’s often missed when talking about how self-driving cars will make the roads safer: you don’t. Self-driving cars can potentially be safer in general, but not necessarily for you in particular.

Imagine I created a magic bracelet that could reduce bicycling related deaths and injuries from 130,000 a year to 70,000. A great win for humans! The catch is that everyone would need to wear it, even people that do not ride bikes, and those 70,000 deaths and injuries would be randomly distributed among the entire population. Would you wear it?

I don't understand the analogy. No one is being forced to stop driving and take autonomous rides. If I am a better than average driver (debatable), I'm glad to have below average drivers use autonomous vehicles instead.

UltraSane | 3 hours ago

The average human driver is much worse than waymo.

yonran | 5 hours ago

The blog post makes no mention of the cellular network congestion/dropped packets that affected people during the power outage. I had bars but was unable to load websites for most of the day. Were Waymos unaffected by the network problems, or were request timeouts encompassed in the word “backlog” used by the blog post?

AlotOfReading | 4 hours ago

The networking on AVs is usually redundant across multiple cellular networks to deal with coverage and outage issues. They also use business sims, which usually have a slightly higher network priority than consumers. If waymo's also negotiated to use one of the infrastructure QCIs instead, it would take some seriously disastrous network conditions for them to experience meaningful congestion.

schwede | 4 hours ago

Sending power outage context to the vehicles does not seem like enough of a response. I hope at least they have internal plans for more. For large, complex systems, you want multiple layers of protections. The response feels way too reactive when they could use this incident to guide improvements across the board.

hnburnsy | 27 minutes ago

>The situation was severe enough that the San Francisco Department of Emergency Management advised residents to stay home, underscoring the extraordinary nature of the weekend’s disruptions.

Waymo cannot point to this as an extenuating circumatance when they where a major contributing factor.