Skip to main content

Search...

Autonomics: A New Discipline for Autonomous Systems

Autonomics is a new discipline for autonomous systems, drawing on control engineering, computer science and sensors. Their safety must hold at runtime.

• • Updated: • 10 min read
Cover of the expert talk on 'Autonomics: A New Discipline for Autonomous Systems' with Peter Liggesmeyer and Richard Seidl.

Autonomics is a proposed engineering discipline devoted to building autonomous systems: systems that maintain certain properties on their own, without human intervention. It brings together computer science, control engineering, sensor technology and mechanical engineering. Applications range from mass-customized manufacturing to smart grids and personalized cancer therapies.

Key Takeaways

  • Autonomous systems are not just a convenience. In pharmaceutical manufacturing, for example, only fully autonomous production can make life-saving cancer therapies affordable for large parts of the population.
  • Classic safety certification at development time loses its value for autonomous systems, because the system changes itself after deployment and safety has to be ensured continuously at runtime.
  • As a new leading discipline, autonomics would focus on the core of autonomous systems and draw on computer science, electrical engineering, mechanical engineering and law, without absorbing those fields entirely.
  • Testing autonomous systems follows the logic of agile development: every reconfiguration at runtime has to pass regression testing before the system accepts it.

Autonomous Systems Engineering Needs a Discipline of Its Own

Computer science on its own can no longer build the systems of the coming years. Autonomous systems engineering draws on too many fields for that, and Peter Liggesmeyer argues for founding a new discipline, which he calls autonomics, by analogy with the German word for computer science, Informatik. Its core is the ability of a system to take care of certain properties by itself, without anyone stepping in from outside.

The historical parallel is close at hand. Computer science grew out of mathematics or electrical engineering, depending on the university, and took over from them as the leading discipline, just as mechanical engineering shaped the age of the steam engine and electrical engineering the era after it. Autonomics would be the next link in that chain.

A discipline like this wouldn’t have to carry every part of the subjects it builds on. A computer scientist knows their work runs on hardware without being able to make microchips. The microelectronics specialists stay in electrical engineering. In the same way, autonomics could concentrate on what makes a system autonomous and draw on computer science, electrical engineering, mechanical engineering, business administration and, in places, even law.

Why Several Disciplines Have to Come Together

Autonomous systems are rarely pure software. They need control engineering, traditionally part of electrical engineering, plus sensors and actuators to collect data and act on their environment, and often mechanical engineering as well.

You can already see this today. Plenty of topics look like computer science but turn out to be systemic on closer inspection. Certifying the safety of a medical device has a software component, but it also raises mechanical, electrical and medical questions. A reliable answer only comes from combining these fields.

What stays constant across every use case is autonomy itself: guaranteeing certain properties, optimizing, and staying within defined corridors for settings. That property dominates the architecture of such systems so strongly that it justifies a discipline of its own.

Where Autonomous Systems Are Already Needed

Self-driving cars are the best-known example and the weakest. Liggesmeyer classes autonomous driving as a pure convenience feature. Most people can drive reasonably well most of the time; it would simply be nice not to have to concentrate constantly.

The fields where autonomy is a prerequisite rather than an option are more convincing. In a smart grid, thousands of small producers, private households among them, feed energy into the grid or draw from it depending on how much sun there is. These grids are volatile and so hard to oversee that people can barely control them by hand anymore. The energy balance still has to add up, so autonomous operation is the only option left.

At its core, Industry 4.0 aims at mass-customized products: made individually, yet at low cost by the principles of mass production. The much-discussed networking is only the means, comparable to the steam engine or the assembly line in earlier industrial revolutions. The goal is to act and react better, for example to compensate for a failed component with a plan B instead of shutting down the entire plant.

Cancer Therapies as a Case of Mandatory Autonomy

The most striking example comes from pharmaceutical manufacturing. CAR-T and NK cell therapies are produced for individual patients or small patient groups, and personalized products are made from the patient’s own blood. Certain cells are extracted and genetically modified so that they attack tumor cells directly.

The therapy is highly effective, and a single infusion bag costs around 250,000 euros today. It is made by hand under extreme hygiene conditions: qualified staff in protective suits count cells under a microscope, assess their condition and decide on the next process steps. Because the starting material varies widely with each patient’s medical history, the process can’t be locked into a fixed sequence of steps.

Here, autonomous production technology is the condition for bringing costs down and making the therapy widely available. That is exactly the line between mandatory autonomy and mere comfort.

Safety Has to Be Established at Runtime, Not Only at Development Time

The classic paradigm for safety-critical systems no longer works for autonomous ones. Until now the rule was: develop the system well, convince the certification body, switch it on and never touch it again. A system that adapts itself dynamically is the exact opposite.

So activities move from development time to runtime. Liggesmeyer calls this principle “X at runtime”, where X stands for any development task. With “safety at runtime”, the system itself has to look after its operational safety while it is running.

“Certifying the safety of a system like this, only for the certificate to be invalid five minutes after you switch it on because the system has changed, makes no sense at all.”

(Peter Liggesmeyer)

For that, these systems need a valid model of themselves, a priori. They have to know not only their current state but also whether a planned change will lead to a safe state. Having the system make that prediction itself is still largely a vision of the future.

Autonomy Means Trading Off Competing Goals

Autonomous systems solve an optimization problem in which properties work against each other. If there were always one best solution, each property could be optimized separately. It isn’t that simple.

The classic tension is safety versus availability. In a given situation, an autonomous vehicle can keep driving or stop. If it keeps going and decides wrongly, safety suffers, because it may be moving in an unsafe state. If it stops, safety goes up and availability goes down. If the car ends up parked at the roadside too often, people won’t accept it.

Often two properties can be improved together, but only at the expense of a third, such as cost. The system has to make these trade-offs itself, again and again. That is the hard core of autonomics.

Trust Comes From Repeated Testing at Runtime

Testing has always been a way to build trust: someone checked things by hand and ticked the box. When test decisions move into the system, that trust has to be built differently. Agile processes show the way.

Repeated testing is central to agile development, because the product is updated continuously and every update risks pushing existing properties in an unwanted direction. An autonomous system does essentially the same thing, just without people involved.

Applied to runtime, this means that before a system accepts a reconfiguration, it runs extensive tests. Full regression testing confirms that the system still responds the way it did before. Only then does it take on the change.

How to Prepare for Autonomics Today

If you want to move in this direction, you can start with established sub-disciplines. Artificial intelligence is now an established field, and the German Informatics Society (Gesellschaft für Informatik) has curriculum recommendations for data science, from continuing education to applied and undergraduate degree programs.

Neither field is an optional extra. Both are required ingredients. Autonomous systems get their information from data that has to be processed intelligently. If you know AI and data science, you already cover a large part of the future autonomics core.

Existing programs in autonomous systems and robotics are a starting point, but they are often tied too closely to one application area, for example the electrical engineering side of robots. An independent discipline of autonomics should keep a core of its own, detached from individual applications, just as computer science has a core that doesn’t depend on its applications. A discipline like this doesn’t appear overnight. It develops along a visible path, so you can position yourself for it now.

Frequently Asked Questions

Why Is Computer Science Alone Not Enough to Build Autonomous Systems?

Autonomous systems are rarely pure software. They require control and regulation technology from electrical engineering, as well as sensor and actuator technology to collect data and interact with the environment, and often mechanical engineering as well. Even topics that appear to be purely computer science in nature have a systemic character: The safety certification of a medical device raises mechanical engineering, electrical engineering, and medical questions. Robust answers can only emerge from the combination of these disciplines.

Would a new engineering discipline need to fully cover all of its foundational subjects?

No. A computer scientist knows that their work is based on hardware, without being able to manufacture microchips themselves; specialists in microelectronics remain within the field of electrical engineering. Similarly, autonomics could focus on the core of autonomous systems and draw upon computer science, electrical engineering, mechanical engineering, business administration, and, to some extent, law, without having to encompass these disciplines themselves.

Is autonomous driving the most important application area for autonomous systems?

It’s the best-known, but the weakest. Most people can drive a car reasonably well most of the time; the only real convenience would be not having to concentrate constantly. Thus, autonomous driving remains a convenience feature. More compelling are fields where autonomy is a prerequisite rather than an option, such as smart grids or the production of personalized cancer therapies.

Why can’t smart grids be controlled manually anymore?

Because thousands of small generators (such as private households) feed energy into or draw energy from the grid depending on sunlight levels. Such grids are volatile and so complex that humans can hardly regulate them manually anymore. The energy balance must still be correct, so autonomous operation is the only option: The system guarantees certain characteristics on its own while remaining within defined parameters.

Why is autonomy essential, and not merely convenient, in personalized cancer therapies?

CAR-T and NK-cell therapies are produced for individual patients or small groups, sometimes using the patient’s own blood. Production takes place as artisanal work under extreme hygienic conditions: Qualified personnel count cells under a microscope and decide on the next steps. A single infusion bag costs around 250,000 euros. Because the source material varies greatly, a fixed sequence of steps is of no help; only autonomous production technology works.

Why is safety certification at the development stage insufficient for self-adapting systems?

The old paradigm was: develop it well, get it certified, turn it on, and never touch it again. A system that adapts dynamically is the opposite of that. A certification that becomes invalid five minutes after startup is worthless. Safety must therefore be ensured at runtime, which requires the system to have a valid self-image and to be able to predict whether a change will end safely.

What conflicting goals must an autonomous system weigh on its own?

The classic trade-off is safety versus availability. A vehicle can continue driving and, if it makes a wrong decision, end up in an unsafe state, or it can stop and gain safety, while availability decreases. If it breaks down too often on the side of the road, users won’t accept it. Often, two characteristics can only be improved at the expense of a third, such as cost.

How do you perform testing on a system that changes itself at runtime?

It checks every change before implementing it. Before a reconfiguration, extensive testing is performed, including full-scope regression testing that confirms that previously existing behaviors continue to occur as expected. Agile processes serve as a model: there, repeated testing prevents an updated version from shifting existing characteristics in an unintended direction.

Share this page