| Navigating the "Ghost Days" of Aviation: Why SOTIF is the Mathematical Key to eVTOL Safety |
| Date:2026-08-24 10:35:20 | Page view: |
The 99.99% Safety Fallacy: The Sunny-Day Testing Trap To understand why measuring hazardous cases—the core of Safety of the Intended Functionality (SOTIF / ISO 21448)—is critical, we must break down a simple probability trap[1, 6]. Suppose 80% of days in a city feature clear weather, while 20% experience severe, volatile weather[2, 7]. If an eVTOL manufacturer conducts physical test flights exclusively on sunny days and achieves an impressive 99.99% pass rate, claiming the aircraft is "99.99% safe" is a dangerous statistical illusion[1, 2]: ● Good Weather Operational Contribution: 80% of flights x 99.99% safety =80%[2] ● Untested Bad Weather Contribution (assuming a 50/50 baseline coin-flip rate of safety): 20% x50% = 10% ● Real-World True Safety Rate: 80% + 10% = 90% A 90% overall safety rate means 1 out of every 10 unexpected bad-weather flights faces catastrophic risk—a failure rate no commercial aviation authority or passenger can accept[1]. The Threat of Sandbox Testing Without Bad Weather Mandates The mathematical reality of the "90% illusion" highlights a critical flaw in some current regulatory sandbox testing approaches. If a regulatory sandbox allows an eVTOL operator to test and log flight hours exclusively during optimal weather conditions, it creates a dangerous blind spot. By not explicitly demanding and verifying performance during the 20% of "Ghost Day" bad weather conditions, these sandboxes fail to assess the aircraft's true resilience in open-world operations. Approving an aircraft for urban deployment based solely on sunny-day sandbox data ignores the catastrophic risk posed by sudden, unpredictable weather changes, effectively deploying an unproven system over densely populated areas. Laboratory Simulation: Bridging the Safety Gap
Because risking real passenger flights in unpredictable urban weather is unfeasible, we bring hazardous edge cases into controlled Hardware-in-the-Loop (HIL) laboratory environments like Hong Kong's PAIS-Lab. Instead of flying blindly into the 20% of bad weather "Ghost Days", we can simulate these severe conditions indoors. If a high-fidelity lab simulation can accurately recreate 90% of these adverse weather scenarios, and we engineer the eVTOL to achieve a 99.99% pass rate within that simulated environment, the mathematical safety landscape shifts dramatically: ● Good Weather Safety Baseline: 80% of flights x 99.99% safety = 80% ● Simulated "Ghost Day" Safety (Covering 90% of bad weather): 20% of flights x 90% lab coverage x 99.99% safety = 18% ● The Remaining Unknowns (The 10% lab gap, assuming a 50% coin-flip baseline): 20% of flights x 10% gap x 50% safety = 1% ● Total Realized System Safety Rate: 98.99% By leveraging advanced HIL simulation, we don't just guess what happens when the weather turns; we mathematically pull the overall system safety rate up from an unacceptable 90% to nearly 99%. The Safety Case and SMS: The Governance of RiskWhile testing physically validates safety, the overarching framework ensuring an ADS or LAE vehicle is safe to deploy is the Safety Case [5]. Unlike traditional type approval, a Safety Case is a structured, evidence-based argument asserting that a system is acceptably safe in a defined environment [5]. However, a Safety Case is only as credible as the organization producing it. This is where the Safety Management System (SMS) becomes critical [5, 6]. The SMS is the organization-wide framework ensuring safety is systematically managed across all operations [5]. The new UN GTR on ADS explicitly links the two: an audited SMS is a mandatory precondition before a Safety Case can be accepted by regulators [6]. Quantifying Risk: The SOTIF Index Formula As functional safety and SOTIF expert Dr. Jin Peng highlights alongside Tsinghua University's Prof. Hong Wang, SOTIF mathematically quantifies this exact relationship through the SOTIF Index[2, 3, 7, 8]: Where measures the mitigation completeness of known unsafe scenarios, and evaluates the verification credibility of unknown unsafe scenarios based on trigger condition coverage and operational domain coverage[2, 3]. By simulating "Ghost Days" before letting aircraft take to urban skies, we systematically convert unknown risks into proven safety[1, 7]. Conclusion: Beyond the Storm and the Mathematical Mandate for eVTOL Safety
Ultimately, the 99.99% safety figure used to illustrate the statistical fallacy of sunny-day testing serves merely as a conceptual baseline. In reality, the strict aviation safety requirement for commercial passenger transport—such as EASA's SC-VTOL Enhanced category—demands a catastrophic failure rate of 10^-9 per flight hour, equating to an uncompromising 99.9999999% safety threshold. Achieving this level of assurance requires the industry to redefine environmental operational constraints. What humans perceive as perfectly "good weather"—such as light fog, gentle rain, or sudden strong glare—can present unknown SOTIF hazards. Because testing perception and control algorithms against these specific urban micro-climates in open-area environments is impractical, the industry must transition from trial-and-error to high-fidelity, controlled Hardware-in-the-Loop (HIL) environments like PAIS-Lab. By mathematically simulating these volatile "Ghost Days" within our labs, we cease to rely on luck or fear. We don't just avoid the storm; we engineer our way through it, converting unpredictable risks into the rigorous, evidence-based safety cases that will ultimately define the future of the Low Altitude Economy.
Glossary● ADS (Automated Driving System): The hardware and software collectively capable of performing the entire Dynamic Driving Task on a sustained basis. ● eVTOL: Electric Vertical Takeoff and Landing vehicle. ● HIL (Hardware-in-the-Loop): A technique used in the development and testing of complex real-time embedded systems. HIL simulation provides an effective platform by adding the complexity of the plant under control to the test platform. ● LAE (Low Altitude Economy): Economic activities operating in the airspace below 1,000 meters (extendable to 3,000 meters), featuring autonomous or crewed aerial vehicles. ● ODD (Operational Design Domain): The operating conditions under which a given driving automation system or feature thereof is specifically designed to function. ● PAIS-Lab: Physical AI Safety Lab, a proposed facility in Hong Kong focused on HIL and environmental simulation for ADS and LAE testing. ● Safety Case: A structured, evidence-based argument demonstrating that a system is acceptably safe to operate in a defined environment. ● SMS (Safety Management System): A systematic, organization-wide framework for managing safety as an ongoing operational and development discipline. ● SOTIF (Safety of the Intended Functionality): The absence of unreasonable risk due to hazards resulting from functional insufficiencies of the intended functionality or by reasonably foreseeable misuse by persons (ISO 21448). References[1] Quat, E., Tang, W., Huang, L., Yeung, G., Tsang, K., Huang, A., Xu, L., Li, Y., Yan, X., Luo, D., Xing, S. Q., Li, X. Y., Lim, A., & Peng, J. (2026). Hong Kong First Five-Year Plan Innovation, Technology and Industrial Development: "Hong Kong Physical AI Lab (PAIS-LAB) and Related Policies" Proposal (2026-2030). Smart City Consortium & HKU. [2] International Organization for Standardization. (2022). ISO 21448:2022 Road vehicles — Safety of the intended functionality. [3] TÜV SÜD & Qualcomm. (2023). Safety in ADAS/AD – SOTIF, a risk-based approach: Towards a Probabilistic SOTIF Analysis as Basis for Road Release. [4] Wang, H. (2025). Research on SOTIF Index and its role in ADS Driving Safety Evaluation. Informal document GRVA-23-43, 23rd GRVA. Tsinghua University. [5] The Safety Case: Concept, History, and AV Relevance. (n.d.). [6] United Nations Economic Commission for Europe (UNECE). (2025). Proposal for a new United Nations Global Technical Regulation on Automated Driving Systems (ADS). ECE/TRANS/WP.29/GRVA/2026/2. [7] LAES SOTIF Calculation System. . Dr Jin Peng |
| Prev:Meet Us in Changchun | Digauto Attends ISC 2026 World Intelligent Safety Conference, Sincerely Inviting You to Visit Our Booth Next:Validating eVTOL Safety: Applying ADS Testing Rigor to the Low Altitude Economy |