Skip to the report
Institute for Physical AI @ Bailey Military Institute · The Charlot Lab
Security · autonomy
Technical Report TR-2026-38
Research / Position · Preprint v1
13 August 2026

Security · autonomy

A Certificate That Bounds Danger Does Not Bound Waste

A safety certificate constrains where a machine may go. It does not constrain what the machine may spend getting there, and the gap between those two is a channel.

The Charlot Lab · Institute for Physical AI @ Bailey Military Institute
Third in the Security cluster, after TR-2026-36 and TR-2026-37.

computed from measured inputs cross-checked on 2 action dimensions a limit of our own detector the mitigation is a gap we already named
Certificate-gated control is a strong answer to a compromised policy: a backdoor grants an adversary an arbitrary policy, but not an arbitrary trajectory, because every action must still pass a check made on the device. This report asks what that leaves open, and answers with a number. A certificate distinguishes safe from unsafe actions; it does not distinguish cheap ones from expensive ones. On a measured autonomous mobile robot, angular speeds of 1.2 and 0.4 rad/s draw 92.1 W and 19.4 W, a 72.7 W span in which every point is certified safe, since slowing down is the safe direction. Treated as a Gaussian channel against the 2.9 W whole-system prediction residual at the platform's own 3 Hz decision rate, that carries 13.9 bits per second. The result that matters is at the other end: a policy modulating at the three-sigma threshold where an energy monitor would flag it still carries 5.0 bits per second, roughly 18 kbit per hour. The detection floor does not close the channel, and that is a statement about the detector this Institute described in TR-2026-36. A cross-check on a second and genuinely certificate-constrained dimension, detection rate at 6 versus 3 Hz, gives 5.4 bits per second, the headline varies by 2.6x across dimensions and the conclusion does not. The mitigation is not a stricter certificate, because strictness pushes an adversary further into the direction the certificate already blesses. It is the task denominator: joules per unit of work completed, which PAI-280 identifies as absent from every published measurement standard, and which is precisely the quantity that distinguishes a machine doing its job from a machine dawdling.

1. What certificate-gating actually buys

An adversary who poisons a policy obtains something powerful and something limited. Powerful: the ability to induce a chosen action on a chosen trigger while the policy remains near-optimal on its nominal task. Limited: if every action must clear an on-device certificate before dispatch, the reachable set is bounded by the certificate rather than by the policy. A backdoor grants an arbitrary policy; it does not grant an arbitrary trajectory.

That is a genuinely strong posture, and it does not require detecting the backdoor. It is the posture the lab's own certificate work assumes 3. This report asks the complementary question: what remains reachable when the certificate holds?

What this report does not claim. Backdoor attacks against reinforcement-learning policies are an active and crowded field, and the question of whether a policy can be backdoored is answered there, repeatedly, by others 4. This report claims no attack, no trigger design, and no detector. It computes a bound on a channel, which is the standard defensive form: you cannot mitigate a channel whose capacity you have not priced.

2. The gap a certificate leaves

A safety certificate answers one question about each candidate action: is it safe. It has no opinion on how much energy the action costs, and among actions that are all safe there is usually a wide spread of cost. So a compromised policy that never once violates its certificate can still choose which safe action to take, and thereby modulate the machine's power draw.

This is far from a subtle effect: it is the difference between a robot doing its job briskly and the same robot doing the same job slowly, and no stability or collision certificate distinguishes them.

3. The span, measured

TR-2026-36 1 reports, from a profiled autonomous mobile robot 2, that reducing angular speed from 1.2 to 0.4 rad/s reduces system power from 92.1 W to 19.4 W. Both are ordinary operating speeds. Since a slower robot is a safer robot, a safety certificate permits the entire range. verified

The observer's side is also measured: whole-system power prediction on that platform is reported at better than 96 % accuracy, which against a ~74 W operating point gives a residual of about 2.9 W. The platform's own perception tasks run at 3 to 6 Hz, which sets the symbol rate available to a policy that re-decides each cycle. verified

4. The capacity

Treating the modulation as a Gaussian channel, capacity per use is ½·log₂(1 + (A/σ)²) for amplitude A against residual σ.

Modulation amplitudeS/Nbits/usebits/s @ 3 Hzbits/s @ 6 Hz
72.7 W, the full safe span6284.6513.927.9
18.2 W, a quarter of it392.678.016.0
8.7 W, at the 3σ detection floor91.665.010.0
3.6 W, 5 % of the span1.60.682.04.1

Table 1. Every row is a sequence of individually certified-safe actions. computed from the §3 inputs

The finding, and it is about our own detector. The three-sigma threshold at which the energy monitor of TR-2026-36 would raise an anomaly sits at 8.7 W, which is 12 % of the safe span. A policy that modulates right at that threshold, never tripping it, still carries 5.0 bits per second, about 18 kbit in an hour. That is ample for a key, a credential, or a model fingerprint. The detection floor does not close the channel. Stating that plainly about our own architecture is the point of the report.

5. Cross-check on a second dimension

One action dimension is one data point, and angular speed is the most favourable one available, precisely because slowing is the safe direction. The check is whether the result survives on a dimension the certificate genuinely constrains.

DimensionSpanbits/s @ 3 HzCertificate-gated?
Angular speed, 1.2 → 0.4 rad/s72.7 W13.9no, slower is safer, the whole range is permitted
Detection rate, 6 → 3 Hz9.7 W5.4partly, a lower rate cuts the safety margin, so a time-to-collision certificate does bound it

Table 2. Both land in the same order. The headline varies by 2.6x across dimensions; the conclusion does not. computed

The asymmetry is itself the result. The adversary's best channel is the direction the certificate is structurally unable to object to. Excess caution is always permitted by a safety envelope, so tightening the envelope does not close this, it pushes an adversary further into the region the envelope already blesses. A certificate that bounds danger does not bound waste.

6. The mitigation, which is a gap this Institute already named

Three layers are in play and none of them bounds the relevant quantity. The certificate bounds the trajectory. The energy monitor of TR-2026-36 bounds instantaneous power. Neither bounds joules per unit of work completed.

A policy exploiting this channel is, by construction, spending more energy than its task requires. A monitor normalised by completed work sees that immediately; a monitor watching watts cannot, because every individual reading is legitimate.

And that quantity is exactly the one PAI-280 identifies as missing. That course's reporting-record lesson finds that no published standard defines robot energy per task: ISO 20140 defines efficiency as a ratio and leaves both terms to the user; the newly published ISO/TS 25213 specifies how to measure a six-axis industrial arm's consumption and does not supply a task denominator either. The gap was identified as a comparability problem. This report finds it is also a security problem: the missing denominator is the quantity that would close a channel a safety certificate cannot. That is the constructive result, and it should be read as the report's main claim.

7. Limitations

The Gaussian-capacity form is an upper bound on what a cooperative receiver could extract; a real eavesdropper does worse, and no attempt is made here to construct a decoder.

Both dimensions come from one platform in one published profiling study. The numbers are a worked example, not a general capacity result, and a different robot with a different power envelope would give different spans.

The analysis assumes a policy free to choose among safe actions at the decision rate. Any task-performance monitor already in place narrows the effective span, which is the §6 mitigation restated as a limit rather than a separate finding.

The prior-art survey of §1 was a single sweep and none of the works located were read in full. That is recorded rather than implied away, and it bounds how firmly this report can position itself against that literature.

8. Conclusions

Certificate-gated control converts an unbounded software compromise into a bounded physical one, which is worth having. The bound it provides is on danger, and the quantity it leaves free is cost. On measured inputs from one autonomous mobile robot, the resulting channel carries 13.9 bits per second at full amplitude and 5.0 bits per second while remaining below the threshold at which an energy monitor would raise an alarm. A cross-check on a second, genuinely constrained dimension gives 5.4 bits per second, so the conclusion is robust to the choice of dimension even though the headline is not.

The mitigation is a measurement the field does not yet standardise rather than a stricter safety envelope: joules per unit of work completed. This Institute identified that absence as a comparability problem in PAI-280; it is also the thing that closes this channel.

9. The forcing function

A channel that survives a detector is not a reason to stop; it is a specification for the instrument that would close it. The value of pricing this channel is that the closing move becomes obvious and small.

What is boundedThe physics that sets itThe change that moves itWhat becomes possible
A safety certificate cannot bound spendThe certified-safe action set has an energy span, and excess caution is always inside itA task denominator: joules per unit of work completed, a measurement definition, not a technologyAn autonomous machine whose expenditure is as accountable as its safety, which is what makes autonomy auditable rather than merely permitted
A power monitor cannot see a compliant adversaryEvery individual reading is legitimate; only the ratio to work done is notNormalising the monitor by completed workA monitor that flags dawdling, which is also the monitor that flags inefficiency, the same instrument serves safety and economics

Table 3. The mitigation is a definition the field has not agreed on, which is the cheapest class of obstacle: it needs consensus, not invention.

The trajectory reads plainly. Bounding an autonomous machine's behaviour was impossible before certificate-gated control; it is routine now. Bounding its expenditure is where behaviour-bounding was a decade ago, desirable, not yet standardised, and blocked by a missing denominator rather than by any physical limit. That is the next thing to define, and defining it costs nothing but agreement.

References

  1. Institute for Physical AI @ BMI, TR-2026-36, Energy Observability in Embodied Systems. Supplies the residual floor, the plane dependence and the power figures used here. Institute publication
  2. L. Liu, W. Shi and K. G. Shin, "Power-Efficient Autonomous Mobile Robots," arXiv:2511.20467v1, 25 November 2025. Source of the 92.1/19.4 W angular-speed figures and the 36.5/26.8 W detection-rate figures. read in full
  3. Institute for Physical AI @ BMI, TR-2026-07, Provable by construction, and PAI-280, Measuring Energy in Physical AI. Institute publications
  4. Backdoor attacks against reinforcement learning — an active field including TooBadRL (arXiv:2506.09562), SleeperNets (arXiv:2405.20539), BACKDOORL (arXiv:2105.00579), and the test-time defence Plan2Cleanse (arXiv:2605.09638). located by one sweep; not read in full
The companions

What the certificate permits is the instrument behind this report: drag the modulation amplitude and watch the channel survive below the alarm line. TR-2026-36 supplies the detection floor this report tests against. TR-2026-37 asks whether the machine is the machine. The lessons are PAI-290.