K6.12.4salient automation degradationdesignresearch

Temporary capability degradation must be as salient as a full shutdown

Aliases: silent degradation · automation surprise · capability drop

What it is

Rain, a dirty camera, a momentarily lost lane line, a capped top assist speed—the system can still be nominally on while doing one thing less. If that temporary drop is only a line of small type, or a slightly dimmer halo, people keep driving the undegraded envelope. It has to be as salient as turning the feature fully off: the encoding must jump, not wait to be close-read as “still on, but no longer centering.” This is not a takeover request. The person may not be asked to take the whole vehicle; follow may remain while lateral has already been returned. It is also not the standing everyday status lamp. If that lamp looks about the same before and after the drop, that is this failure.

Why it happens

Shutdown is an edge: from something to nothing, lamp off, force back in the hands, a schema for “it’s gone.” Degradation is a slope: the icon stays, some torque stays, copy still uses the assist name, only the envelope shrank. Intermittent supervision is sensitive to edges, not slopes, especially a slope that happens in the seconds the person is watching the road or the stack. Sensors worsen gradually in rain and fog; an interface that fades with them has no transient, and is not noticed. Then comes automation surprise: at the conflict the person still thinks lateral is on, and only longitudinal remains. Making degradation jump as hard as shutdown is artificially adding an edge to a slope, so intermittent supervision has something to catch.

Studying it

Insert a recoverable drop in a simulator (centering leaves, follow stays; top assist speed cut; a class of objects no longer handled). Compare small-type only, a color change that keeps the old icon, and a jump identical to shutdown plus a line that lateral has been returned.

Independent variables: similarity of degradation encoding to full off, whether the drop can recover in seconds, whether recovery jumps again. Dependent variables: time still driving the undegraded envelope, whether people report that a capability is missing, whether they still think they are degraded after recovery.

Recoverable drops are easily built as flicker, which people mute; measure salient separately from nagging. Do not substitute a takeover task for a degradation task—the first demands immediate driving, the second an immediate change of expectation.

Where it stops holding

If the drop already triggers a minimal-risk stop or a full takeover, the problem is the handoff window, not cue salience. Millisecond sensor jitter that jumps every time turns the edge into noise and people habituate; hysteresis should fold a brief glitch into one real degradation before announcing. Professional drivers in a test mode expect drops and need less salience. Shutdown and degradation may be different events in a regulatory log; for the driver they must still be equally distinguishable—log grading is not interface grading. A robot’s drop in grasp confidence is the same slope aimed at a different object; in-vehicle degradation rewrites lateral and longitudinal at highway speed, so the edge has to be harder.

Applying it

  • When either lateral or longitudinal leaves, use the same primary encoding jump as “feature off,” then one short itemized line for what remains—do not only dim the halo.
  • Put hysteresis on enter and exit so the cue does not strobe at a threshold; jump again on recovery, and do not silently restore an omnipotent look.
  • Keep the degraded look for the whole duration of a recoverable drop; do not collapse back to small type after a few seconds.
  • Verify on rain or a covered camera: count how many people still do not take the wheel after centering has left. If they would take it when the same feature is fully off, and they do not when it is degraded, the drop is not salient enough.

Related

  • Within the group: K6.12.1 OEMs do not share one functional boundary for the same automation level · K6.12.2 Misjudging the capability envelope is the most common outcome of mode confusion · K6.12.3 Multi-channel status cues prevent misjudgment better than a single cue
  • Adjacent: K6.08 Automated Driving Takeover Requests · K6.09 Expressing Automation State · X3.04 Failure and Help-Seeking
  • Search terms: silent degradation · automation surprise · ODD exit · capability drop

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/K6.12.4