The instinct is to tighten the certificate. That fails, and the reason is worth understanding. The adversary's best channel was slowing down, and slowing down is the safe direction. A safety envelope is structurally unable to object to excess caution, so making it stricter pushes an adversary further into the region the envelope already blesses. A certificate that bounds danger does not bound waste. So look at what each layer actually bounds. The certificate bounds the trajectory. The energy monitor bounds instantaneous power. Neither bounds joules per unit of work completed. And a policy exploiting this channel is, by construction, spending more energy than its task requires. A monitor normalised by completed work sees that immediately, because dawdling is precisely what it measures. And that quantity is the one you already met in the very first module of the prerequisite course, as a gap: no published standard defines robot energy per task. It was a comparability problem. It turns out to be a security problem too.