A new Stanford/Airbus preprint applies the same error bounding math that lets certified GPS flag a bad satellite to camera based landing systems, deriving probabilistic bounds whose tightness depends on the aircraft's position, orientation, and
Aviation didn't earn public trust in GPS by trusting the satellites. It earned it by trusting the satellites plus a probabilistic bound on how wrong they could still be. A new Stanford and Airbus preprint applies that same "integrity math" to cameras, asking the question regulators will eventually face: how wrong can a runway camera be, and still be safe enough to land on?
The paper, "Protection Levels for Vision-Based Pose Estimation," by Olivia Beyer Bruvik, Romeo Valentin, Marc R. Schlichting, and Mykel J. Kochenderfer, with Don Walker of A3 by Airbus, derives probabilistic error bounds — called protection levels — that stay valid even when the vision system has undetected faults. The framework extends a prior paper from the same group that brought Receiver Autonomous Integrity Monitoring (RAIM), the math that lets certified GPS receivers reject a bad satellite, into vision-based landing.
The new method works on the nonlinear Perspective-n-Point problem — reconstructing an aircraft's six degrees of freedom (three positions, three orientations) from camera pixels of known runway landmarks — and analyzes how measurement redundancy, pixel-level prediction uncertainty, and distance to the runway each change the resulting bound. The authors demonstrate the tradeoffs on a single illustrative runway scenario, not a flight test or certified system.
The work is a preprint, not peer-reviewed, and the authors frame it as methodology, not a near-term certification step. The question it puts on the table is concrete: when GPS is jammed, spoofed, or unavailable, can a camera-based approach produce error bounds tight enough to satisfy the same integrity standards that govern a certified GPS approach?