Energy as Evidence: What a Machine Can Prove About Itself
Software asserts. Energy is spent. A power trace is the one account of a machine's activity its own code cannot simply write, which makes energy the natural substrate for a machine that has to demonstrate its behaviour rather than claim it. This course builds that argument and then bounds it, on measured data: which measurement plane can see what, how far a physics model of a body actually predicts, and the two places the meter goes blind. Then it follows one candidate mechanism, a machine proving it is the machine it claims to be, from plausible to nearly dead to rescued, ending at the question that is still open: and at the specific, ordinary engineering change that would answer it. Then it turns around and asks what a fully compliant machine can still conceal, and finds the fix is the measurement gap the sequence opened with. Every figure carries its source.
▶ Start the course ← All coursesWhere this sits, and what moves it.
Binding constraint · What a power trace can resolve. Energy is the one account of a machine's activity its own software cannot simply write, and how much it proves is set by the bandwidth and placement of the meter, not by how badly you want the answer.
A machine's report of what it did was a machine's report. Auditing it meant trusting the same software stack that would be lying, and the alternative -- an independent physical channel -- had no established method behind it.
A metered plane gives evidence the code cannot forge, and this course builds the argument and then bounds it on measured data. The bounding is the part: the instrument goes blind in two specific places, and the course names both rather than selling around them.
What closes the remaining gap is a measurement, and the course ends by specifying it rather than gesturing at it. That is the shape of a live research question handed to a student in a state where they could actually go and answer it.
Every hard thing was impossible until the constraint that made it impossible was named. How we read a frontier →
What the meter can prove
Establish that an energy claim is a claim about a measurement plane, and that the body being measured decides whether computation is visible in the joules at all.
- L3The body decides what the joules revealA mobile robot navigating autonomously. What share of its electrical power do the motors draw?Show that the compute-to-actuation ratio is set by the workload, not the chassis, and that it inverts the common assumption.→
- L3Which plane can see itSame robot, same 12 W hidden load, two correctly-functioning meters on different rails. How far apart are the detection margins?Show that a hidden load is visible or invisible depending on which rail the meter sits on, with both readings correct.→
- L4The joule you cannot forgeA physics-based model of a humanoid arm predicts its electrical power. What fraction of that power is actually mechanical work?Build the expected-power model for a body and use its residual as the detection floor.→
Where the meter runs out, and what extends it
Find the two places a working instrument goes blind, and in each case name the specific thing that would extend its reach: a second sensing modality, a known-load check, and a measurement method for the bodies no standard covers.
- L4The leak you find with an IMUA humanoid's arm power is measured on a dedicated arm rail. What fraction of trials had to be discarded because leg energy leaked onto it?Show that energy crossing a subsystem boundary is undetectable electrically, and that a second sensing modality is what finds it.→
- L2Verify the instrumentA laptop battery gauge reads 67.2 W at idle. Ten cores are then pinned at 100%. What does it read?Show that an energy monitor can be entirely dead while producing confident output, and that only a known load reveals it.→
- L3Who gets to define the methodISO published the first international method for measuring robot energy consumption in 2026. Who is required to follow it?Show that a measurement method is adopted, not imposed, and locate the morphologies whose method is still unwritten.→
Can a machine prove it is itself?
Follow one candidate mechanism from plausible to nearly dead to rescued, and end at the question that is still open: so the shape of a live research problem is visible, not just its conclusion.
- L3The difference between twinsYou want to know how much two identical-model motors differ. What is the cheapest way to find out?Establish that two motors of the same model differ measurably, and find that number without buying anything.→
- L4Which number can be a nameA model has four fitted coefficients. How many can serve as a hardware identity?Show that a coefficient can only serve as an identity if it is individually identifiable, and find which one is.→
- L4The fingerprint that meltsManufacturing makes two identical motors differ by about 21% in one coefficient. How much does that coefficient move when a motor warms 40 degC in normal use?Show that the identity dissolves under ordinary operation, find the crossover temperature, and rescue it with the cheapest possible instrument.→
The gap still open, and the measurement that closes it
Follow one candidate mechanism from plausible to nearly dead to rescued, then find that the remaining gap is closed not by better technology but by a measurement definition the field has not yet agreed on.
- L3What a certificate does not checkA safety certificate checks every action before it runs. What does it say about an action that is safe but wasteful?Show that a safety certificate sorts actions into safe and unsafe and has no opinion about their cost.→
- L4Under the alarmA compromised policy stays below the energy monitor's alarm threshold at all times. How much can it still transmit?Compute how much a compromised policy can transmit through its power draw while never tripping the energy monitor.→
- L4The denominator that closes itA covert channel runs under the energy alarm. What closes it?Show that the fix is not a stricter certificate but the missing task denominator, and close the loop back to the course's first module.→