Plan Execution in Mission-Critical Domains

David J. Musliner · 1996

... In this paper, I take the position that the best way to address these issues is through the use of an inherently self-validating planning and execution system. That is, a system in which the planner generates plans satisfying certain verifiable properties (e.g., timeliness and correctness), which are then predictably and reliably executed by the executive. In abstract form, this type of system is essentially a high-level automatic programming paradigm: the system designer provides a description of primitive sensing and control actions, a description of the domain and its dynamics, and a description of the system's goals. Then, conceptually at least, the system generates and executes a plan composed of primitives and combination functions (control logic) to reliably achieve the goals. Once the system code itself has been certified, the only further verification /certification requirements apply to the input models of primitives and the domain; each plan (program) is itself verified automatically during generation. The popularity of such classical planner/executor architectures waned during the 1980s as reactive systems dawned, but more recently the community has almost converged on multi-layer architectures incorporating planners with reactive plan execution engines. In the transition, however, many of the advantages of the classical architecture have been lost: some planners now "advise" rather than "program," and execution engines themselves are frequently running complex, handcoded, unbounded skeletal/hierarchical plans. These systems do not provide the advantages of the "automatic programming" paradigm. So, let this position paper act as a call to arms:

Read the paper · More papers on PaperTik