Papers
Topics
Authors
Recent
Search
2000 character limit reached

Load-Error Injection (LEI): Techniques and Applications

Updated 27 September 2026
  • Load-Error Injection (LEI) is a technique involving the deliberate modification of load forecasts, measurements, or execution workloads. This is to evaluate error propagation, exploit vulnerabilities, or mitigate risks in various systems, such as power grids and computing environments.
  • LIE involves mainly four types of injections: **forecast-input injection**, which modifies forecasting inputs to induce errors in subsequent computations, like altered deal forecasts for day-ahead unit commitment in power forecasting systems; **measurement injection**, which changes load measurements to manipulate apparent consumption, such as tampering with smart meters to shift usage to lower-price periods; **measurement or profile injection**, which changes between load profiles**, and **fault-oriented injection**, which tests system robustness by introducing numerical errors in valuable computation areas.
  • Variations of LEI can provide insights into system vulnerability, with direct applications in enhancing security. Example LEI applications include analyzing vulnerability in tool-using agents by injecting adversarial instructions into error paths, as seen in MCP-based tool-calling service evaluations

Load-Error Injection (LEI) is a term applied to several technically distinct mechanisms in which an externally supplied load, load-related signal, or execution workload is deliberately perturbed to study, exploit, or mitigate error propagation. In power systems, LEI commonly denotes malicious manipulation of load forecasts, load measurements, or non-dispatchable injection estimates. In computing and machine learning, the term is also used for perturbations of forecasting inputs, local mixture-of-experts loads, or error paths in tool-using agents. Across these domains, the common structure is a load or workload signal, an injected deviation, and an observable downstream consequence; the injection point, threat model, operational objective, and evaluation criteria differ substantially.

1. Terminology and conceptual scope

LEI is not a single standardized attack or testing protocol. The term encompasses at least four recurring interpretations.

Forecast-input injection modifies exogenous features or historical measurements before a forecasting model produces an output. In power-system forecasting, an attacker may alter temperature forecasts rather than metered load, state-estimation measurements, or market-clearing inputs. The forecast is then supplied to day-ahead unit commitment while real-time economic dispatch uses actual load, creating a strategically induced mismatch (Chen et al., 2019). A related microgrid study injects Gaussian noise directly into the historical load sequence presented to an LSTM during inference (Nazeri et al., 2023).

Measurement or profile injection alters a reported load time series. Smart-meter attacks may replace the profile with zeros or construct a nonzero reduced-cost spot attack intended to shift apparent consumption toward lower-price periods (Higgins et al., 2023). In economic modeling, the deviation between actual and scheduled non-dispatchable injection is represented by ΔPND\Delta P_{ND}; for load, if Li=L^i+eiL_i=\widehat L_i+e_i, the corresponding injection error is ΔPND,i=−ei\Delta P_{ND,i}=-e_i (Brooks et al., 2020).

Fault-oriented injection perturbs computational state, memory, registers, system-call returns, or numerical values to investigate error propagation. Phoebe derives realistic system-call error models from production-like observations (Zhang et al., 2020). LCFI injects statistically abstracted lossy-compression errors into LLVM-level values (Shan et al., 2020). Hardware and simulator frameworks inject transient bit corruptions into registers or memory, which may subsequently affect loads (Magliano et al., 2024, Lentini et al., 10 Jun 2026).

Error-path injection places attacker-controlled instructions inside tool error responses so that an autonomous agent interprets them as recovery instructions. VATS studies this mechanism in MCP-based tool-calling systems and characterizes it as indirect prompt injection delivered through a failure path (Patel et al., 6 Jun 2026).

The common abstraction can be expressed conceptually as

load or workload state⟶injected error⟶model, computation, or control response⟶observable consequence.\text{load or workload state} \longrightarrow \text{injected error} \longrightarrow \text{model, computation, or control response} \longrightarrow \text{observable consequence}.

The observable consequence may be forecast error, infeasible dispatch, increased balancing cost, anomalous billing, corrupted program output, a crash, loss of lock, expert-routing imbalance, or an unauthorized tool call. The term should therefore be qualified by its domain and injection boundary.

2. Power-system LEI

Forecast manipulation

The principal power-system formulation treats the load forecast as a function of a historical feature sequence,

L^t+k=fθ(Xt−H,…,Xt),\hat L_{t+k}=f_\theta(X_{t-H},\ldots,X_t),

where the feature vector includes load-history features, temperature values or forecasts, and weather, seasonal, weekday/weekend, and hour-of-day indicators (Chen et al., 2019). The attacker perturbs temperature inputs,

ΔXt−itemp=X~t−itemp−Xt−itemp,\Delta X_{t-i}^{temp} = \tilde X_{t-i}^{temp}-X_{t-i}^{temp},

thereby inducing

L~t+k=fθ(X~t−H,…,X~t).\tilde L_{t+k} = f_\theta(\tilde X_{t-H},\ldots,\tilde X_t).

The directly altered quantity is therefore not necessarily a physical load measurement. It is an upstream feature whose effect propagates through the forecasting model.

The attack may be formulated with a direction variable γ∈{−1,1}\gamma\in\{-1,1\} and a norm-constrained perturbation:

∥Xt−itemp−X~t−itemp∥p≤ϵ.\left\|X_{t-i}^{temp}-\tilde X_{t-i}^{temp}\right\|_p\leq\epsilon.

The norm may be p=0p=0, Li=L^i+eiL_i=\widehat L_i+e_i0, or Li=L^i+eiL_i=\widehat L_i+e_i1, corresponding respectively to restrictions on the number of altered entries, aggregate perturbation magnitude, or maximum individual deviation. The principal experiments use an Li=L^i+eiL_i=\widehat L_i+e_i2 constraint, expressed as a maximum temperature deviation in degrees Fahrenheit (Chen et al., 2019).

Threat models

The power-system study considers white-box, black-box query, and substitute-model transfer settings. A white-box attacker knows the forecasting model and parameters. A black-box attacker knows the model family and can query a forecasting service with modified inputs, estimating gradients by finite differences. In the transfer setting, the attacker trains a substitute model using historical data drawn from the same feature distribution and transfers perturbations to the unknown target.

Topology knowledge is not required to create forecast-level errors, but it improves the ability to convert those errors into operational failures. With topology, line limits, generator capacities, and ramp constraints, the attacker can select vulnerable load buses and attack directions. Without such information, buses and directions are selected randomly (Chen et al., 2019).

Operational propagation

Day-ahead unit commitment is optimized against attacked forecasts Li=L^i+eiL_i=\widehat L_i+e_i3, producing an attacked commitment Li=L^i+eiL_i=\widehat L_i+e_i4. Real-time economic dispatch then uses the actual load Li=L^i+eiL_i=\widehat L_i+e_i5 while being constrained by the attacked commitment. The propagation chain is:

Li=L^i+eiL_i=\widehat L_i+e_i6

Underestimation may cause insufficient generator commitment, inadequate ramping capability, or omission of a generator required for a peak. Overestimation commonly produces redundant or expensive commitment. Underestimation is generally more damaging because it can produce physical infeasibility and load shedding, whereas overestimation primarily creates economic harm (Chen et al., 2019).

Experimental evidence

The power-system forecasting experiments use hourly Swiss load data, temperature forecasts for Swiss cities, and hour, weekday, and seasonal indicators. The principal forecasting model is a three-layer RNN with clean test MAPE of Li=L^i+eiL_i=\widehat L_i+e_i7. NN, RNN, and LSTM models are all evaluated.

A temperature perturbation of Li=L^i+eiL_i=\widehat L_i+e_i8 produces forecast deviations exceeding 500 MW at some times; a Li=L^i+eiL_i=\widehat L_i+e_i9 perturbation produces errors above 1,200 MW. With a ΔPND,i=−ei\Delta P_{ND,i}=-e_i0 budget, query-based gradient estimation raises MAPE to ΔPND,i=−ei\Delta P_{ND,i}=-e_i1 for NN, ΔPND,i=−ei\Delta P_{ND,i}=-e_i2 for RNN, and ΔPND,i=−ei\Delta P_{ND,i}=-e_i3 for LSTM, compared with clean values of ΔPND,i=−ei\Delta P_{ND,i}=-e_i4, ΔPND,i=−ei\Delta P_{ND,i}=-e_i5, and ΔPND,i=−ei\Delta P_{ND,i}=-e_i6, respectively (Chen et al., 2019).

In the IEEE 14-bus study, topology-aware attacks cause load shedding on more than 100 of 122 evaluated Swiss test days under a strategically injected ΔPND,i=−ei\Delta P_{ND,i}=-e_i7 perturbation. Even one compromised nodal forecast causes shedding on more than 40 days in the reported setting. In the IEEE 118-bus example, compromising a small subset of nodal forecasts changes commitment and produces system-wide effects, including overloaded lines, generators at capacity, and load shedding at a bus whose generator is offline (Chen et al., 2019).

3. Propagation, uncertainty, and economic consequences

Probabilistic load-flow propagation

Non-parametric probabilistic load flow using Gaussian-process learning provides a response-surrogate layer for analyzing uncertain or perturbed injections (Pareek et al., 2019). The method learns an inverse power-flow map from power injections to bus-voltage states,

ΔPND,i=−ei\Delta P_{ND,i}=-e_i8

using Gaussian-process regression and GP-UCB sample selection. It can evaluate perturbed input vectors such as

ΔPND,i=−ei\Delta P_{ND,i}=-e_i9

and estimate the corresponding voltage response through the GP posterior mean. It can represent additive, bounded, intermittent, or distributionally sampled perturbations, although the paper does not itself provide an LEI detector, causal attribution method, or explicit adversarial attack model.

The method supports arbitrary test-time input distributions provided their support is covered by the learned domain. Its probabilistic learning bound concerns approximation of the learned physical response, not the correctness of the underlying load measurements. It cannot distinguish a physical load change from a measurement error, communication fault, topology error, or adversarial injection (Pareek et al., 2019).

Locational cost of variability

The Locational Price of Variability (LPV) measures the marginal change in optimized system production and reserve cost resulting from a change in uncertainty standard deviation at a location:

load or workload state⟶injected error⟶model, computation, or control response⟶observable consequence.\text{load or workload state} \longrightarrow \text{injected error} \longrightarrow \text{model, computation, or control response} \longrightarrow \text{observable consequence}.0

It is particularly relevant to probabilistic LEI because it prices the system consequences of injection uncertainty rather than merely its magnitude. The effect of a deviation depends on network location, generator limits, congestion, AGC participation factors, and available regulation capacity (Brooks et al., 2020).

A load forecast error represented as load or workload state⟶injected error⟶model, computation, or control response⟶observable consequence.\text{load or workload state} \longrightarrow \text{injected error} \longrightarrow \text{model, computation, or control response} \longrightarrow \text{observable consequence}.1 corresponds to an injection error load or workload state⟶injected error⟶model, computation, or control response⟶observable consequence.\text{load or workload state} \longrightarrow \text{injected error} \longrightarrow \text{model, computation, or control response} \longrightarrow \text{observable consequence}.2. AGC response is distributed according to participation factors load or workload state⟶injected error⟶model, computation, or control response⟶observable consequence.\text{load or workload state} \longrightarrow \text{injected error} \longrightarrow \text{model, computation, or control response} \longrightarrow \text{observable consequence}.3, so an error has both a direct network effect and an indirect balancing effect. Two equal-magnitude errors can therefore produce different line-flow impacts and costs.

Chance-constrained formulations represent reserve and branch-flow security probabilistically. Under the paper’s Gaussian assumptions, uncertainty consumes generator headroom and transmission margin. An LEI-oriented charge may be based on load or workload state⟶injected error⟶model, computation, or control response⟶observable consequence.\text{load or workload state} \longrightarrow \text{injected error} \longrightarrow \text{model, computation, or control response} \longrightarrow \text{observable consequence}.4 or on an incremental uncertainty difference relative to a baseline, but LPV prices marginal uncertainty rather than necessarily the cost of one realized error. The distinction between ex-ante variability pricing and ex-post deviation settlement is therefore material (Brooks et al., 2020).

Smart-meter profile manipulation

The smart-meter anomaly-detection study normalizes 48 half-hourly observations and constructs business-conditioned behavioral models using agglomerative hierarchical clustering. Global, time-block, and index features describe each profile. A violation score identifies deviations outside a two-standard-deviation interval, while the incentive-weighted violation score combines profile deviation with relative spot-price variation:

load or workload state⟶injected error⟶model, computation, or control response⟶observable consequence.\text{load or workload state} \longrightarrow \text{injected error} \longrightarrow \text{model, computation, or control response} \longrightarrow \text{observable consequence}.5

The reduced-cost spot attack is intended to make apparent consumption more favorable under intraday prices. The method seeks to distinguish economically motivated injections from ordinary profile anomalies by combining behavioral deviation with financial incentive (Lu et al., 2023).

The reported evidence is qualitative and graphical. RCSA profiles are consistently detected in the displayed examples, while incentive weighting increases the visibility of price-aligned attacks. The study does not report detection rate, false-positive rate, precision, recall, ROC/AUC, F-score, confidence intervals, or a confusion matrix. Price alignment is evidence of a possible motive, not proof of maliciousness, because legitimate demand response may also shift consumption toward lower-price periods.

4. Computational and systems fault injection

Production-grounded system-call errors

Phoebe constructs realistic system-call error models from production-like observations. A model is represented as load or workload state⟶injected error⟶model, computation, or control response⟶observable consequence.\text{load or workload state} \longrightarrow \text{injected error} \longrightarrow \text{model, computation, or control response} \longrightarrow \text{observable consequence}.6, where load or workload state⟶injected error⟶model, computation, or control response⟶observable consequence.\text{load or workload state} \longrightarrow \text{injected error} \longrightarrow \text{model, computation, or control response} \longrightarrow \text{observable consequence}.7 is the system call, load or workload state⟶injected error⟶model, computation, or control response⟶observable consequence.\text{load or workload state} \longrightarrow \text{injected error} \longrightarrow \text{model, computation, or control response} \longrightarrow \text{observable consequence}.8 is the error code, and load or workload state⟶injected error⟶model, computation, or control response⟶observable consequence.\text{load or workload state} \longrightarrow \text{injected error} \longrightarrow \text{model, computation, or control response} \longrightarrow \text{observable consequence}.9 is the injection rate. The framework distinguishes sporadic, fluctuating, and steady errors and uses observed error-rate statistics to synthesize executable policies (Zhang et al., 2020).

The injector uses eBPF hooks at raw_syscalls/sys_enter and raw_syscalls/sys_exit, applying bpf_override_return at the system-call return event. It normally injects only on calls that would otherwise succeed, thereby adding failures rather than replacing naturally occurring failures. The workload determines which calls occur; Phoebe does not independently control request rate, concurrency, arrival distribution, or load intensity.

Phoebe evaluates application-level Behavioral Assessment Criteria. In the HedWig and TTorrent case studies, realistic system-call failures expose crashes, fetching failures, sending failures, checksum failures, stalls, and persistent state corruption. The framework demonstrates that low-level errors such as read:EAGAIN, read:ECONNRESET, and futex failures can produce high-level application failures, while some errors have no observed behavioral impact (Zhang et al., 2020).

LLVM-level numerical perturbations

LCFI injects numerical perturbations into LLVM-level values to emulate error-bounded lossy-compression reconstruction errors (Shan et al., 2020). Its fault models combine absolute or relative error bounds with uniform or normal error distributions. Tested relative bounds are L^t+k=fθ(Xt−H,…,Xt),\hat L_{t+k}=f_\theta(X_{t-H},\ldots,X_t),0, L^t+k=fθ(Xt−H,…,Xt),\hat L_{t+k}=f_\theta(X_{t-H},\ldots,X_t),1, L^t+k=fθ(Xt−H,…,Xt),\hat L_{t+k}=f_\theta(X_{t-H},\ldots,X_t),2, L^t+k=fθ(Xt−H,…,Xt),\hat L_{t+k}=f_\theta(X_{t-H},\ldots,X_t),3, and L^t+k=fθ(Xt−H,…,Xt),\hat L_{t+k}=f_\theta(X_{t-H},\ldots,X_t),4; tested absolute bounds are L^t+k=fθ(Xt−H,…,Xt),\hat L_{t+k}=f_\theta(X_{t-H},\ldots,X_t),5, L^t+k=fθ(Xt−H,…,Xt),\hat L_{t+k}=f_\theta(X_{t-H},\ldots,X_t),6, L^t+k=fθ(Xt−H,…,Xt),\hat L_{t+k}=f_\theta(X_{t-H},\ldots,X_t),7, L^t+k=fθ(Xt−H,…,Xt),\hat L_{t+k}=f_\theta(X_{t-H},\ldots,X_t),8, and L^t+k=fθ(Xt−H,…,Xt),\hat L_{t+k}=f_\theta(X_{t-H},\ldots,X_t),9.

The user specifies a function, variable, occurrence, array status, loop status, and loop iteration. Each LLVM instruction receives an llfi_index, enabling stable instrumentation and dynamic targeting. Baseline and faulted executions are compared through application outputs, convergence, crashes, checksums, execution time, and trace differences.

The same nominal perturbation can be benign or harmful depending on its dynamic location. In HPCCG, errors injected in an early loop may be tolerated, whereas errors in a later loop prevent convergence. Black-Scholes exhibits crashes and corrupted results; XSBench exhibits output changes and increased execution time; NPB-MG produces corrupted outputs for all tested fault types (Shan et al., 2020).

Hardware and architectural-state injection

The microarchitectural-events-aware injector uses a Python host, Xilinx XSCT, JTAG, FreeRTOS, and a Xilinx Zynq/PYNQ-Z2 board. It halts execution at a breakpoint, modifies a CPU register or RAM word, resumes execution, and observes both program output and PMU events (Magliano et al., 2024).

The implemented fault is a single-bit upset. Conceptually, a target word ΔXt−itemp=X~t−itemp−Xt−itemp,\Delta X_{t-i}^{temp} = \tilde X_{t-i}^{temp}-X_{t-i}^{temp},0 is changed to ΔXt−itemp=X~t−itemp−Xt−itemp,\Delta X_{t-i}^{temp} = \tilde X_{t-i}^{temp}-X_{t-i}^{temp},1. The mechanism does not directly corrupt a load instruction, cache response, memory-bus transaction, load/store queue, or memory-data return path. RAM corruption may later be consumed by a load; register corruption may approximate post-load corruption, but the fault site remains architectural state rather than the load pipeline.

Across Dijkstra, QuickSort, and SHA, memory and register campaigns classify executions as benign, SDC, or crash/hang. Register campaigns produce SDC rates of ΔXt−itemp=X~t−itemp−Xt−itemp,\Delta X_{t-i}^{temp} = \tilde X_{t-i}^{temp}-X_{t-i}^{temp},2, ΔXt−itemp=X~t−itemp−Xt−itemp,\Delta X_{t-i}^{temp} = \tilde X_{t-i}^{temp}-X_{t-i}^{temp},3, and ΔXt−itemp=X~t−itemp−Xt−itemp,\Delta X_{t-i}^{temp} = \tilde X_{t-i}^{temp}-X_{t-i}^{temp},4, respectively; memory campaigns produce ΔXt−itemp=X~t−itemp−Xt−itemp,\Delta X_{t-i}^{temp} = \tilde X_{t-i}^{temp}-X_{t-i}^{temp},5, ΔXt−itemp=X~t−itemp−Xt−itemp,\Delta X_{t-i}^{temp} = \tilde X_{t-i}^{temp}-X_{t-i}^{temp},6, and ΔXt−itemp=X~t−itemp−Xt−itemp,\Delta X_{t-i}^{temp} = \tilde X_{t-i}^{temp}-X_{t-i}^{temp},7. PC campaigns are dominated by crashes and hangs (Magliano et al., 2024).

InjectV extends this architectural approach in gem5-based RISC-V simulation. It uses checkpoints, golden and divergent execution traces, candidate injection points, and parallel campaigns. Its current experimentally supported faults are transient register and physical-memory corruptions. The framework identifies security-relevant branches, comparisons, write-before-use relationships, and memory regions. In VerifyPIN experiments, guided injection discovers 48 successful security violations compared with two under random injection, with a reported 95.8% time-saving advantage over brute-force random injection (Lentini et al., 10 Jun 2026).

Neither framework, as described, implements a dedicated load-result fault model. Explicit LEI would require hooks at address generation, memory request, memory response, writeback, or load/store-queue stages.

5. Analysis, mitigation, and defense

Forecast and measurement defenses

Power-system LEI defenses include anomaly detection, robust statistics, validation of external weather inputs, and joint evaluation of forecasting and downstream UC/ED consequences rather than MAPE alone (Chen et al., 2019). A complete defense must detect both anomalous features and implausible forecast-to-operation combinations. Reserve, commitment, and dispatch procedures should remain safe under bounded forecast manipulation.

The GP-based probabilistic load-flow method can serve as a nonlinear forward surrogate for scenario analysis and uncertainty propagation, but it does not itself detect or localize an injection (Pareek et al., 2019). LPV can quantify the economic value of reducing uncertainty through storage, improved forecasting, or controllable load, but it does not identify malicious deviations (Brooks et al., 2020).

The smart-meter detector uses business-type clustering and price-aware weighting to reduce false positives caused by ordinary profile variation. Its limitations include incompletely specified distances and linkage, absent numerical thresholds, simplified economic assumptions, and the possibility that legitimate demand response resembles an attack (Lu et al., 2023).

Signal-processing mitigation

For Gaussian noise injection against an LSTM load forecaster, an FFT-based low-pass filter suppresses higher-frequency components before inference (Nazeri et al., 2023). The healthy MAE is ΔXt−itemp=X~t−itemp−Xt−itemp,\Delta X_{t-i}^{temp} = \tilde X_{t-i}^{temp}-X_{t-i}^{temp},8 MW, increasing to ΔXt−itemp=X~t−itemp−Xt−itemp,\Delta X_{t-i}^{temp} = \tilde X_{t-i}^{temp}-X_{t-i}^{temp},9 MW at SNR L~t+k=fθ(X~t−H,…,X~t).\tilde L_{t+k} = f_\theta(\tilde X_{t-H},\ldots,\tilde X_t).0 dB. A cutoff of L~t+k=fθ(X~t−H,…,X~t).\tilde L_{t+k} = f_\theta(\tilde X_{t-H},\ldots,\tilde X_t).1 Hz reduces average attacked MAE from L~t+k=fθ(X~t−H,…,X~t).\tilde L_{t+k} = f_\theta(\tilde X_{t-H},\ldots,\tilde X_t).2 MW to L~t+k=fθ(X~t−H,…,X~t).\tilde L_{t+k} = f_\theta(\tilde X_{t-H},\ldots,\tilde X_t).3 MW. The filter is more effective against lower-SNR attacks and less promising for small noise, where filtering may remove legitimate load dynamics.

This defense is specific to spectral assumptions. It does not address bias, ramps, replayed values, bursts, temporally correlated errors, or targeted perturbations whose spectrum overlaps legitimate dynamics. It is a mitigation mechanism rather than a detector.

Agentic error-path defenses

VATS demonstrates that tool errors should be treated as untrusted data rather than as automatically authoritative recovery instructions (Patel et al., 6 Jun 2026). Recommended defenses include separating machine-readable error codes from free-form help text, validating provenance, flagging action words, requiring human approval for sensitive error-directed actions, enforcing least privilege and tool isolation, and maintaining functional alternatives.

In controlled model-layer experiments, aggregate action compliance rises from L~t+k=fθ(X~t−H,…,X~t).\tilde L_{t+k} = f_\theta(\tilde X_{t-H},\ldots,\tilde X_t).4 for matched successful-response injections to L~t+k=fθ(X~t−H,…,X~t).\tilde L_{t+k} = f_\theta(\tilde X_{t-H},\ldots,\tilde X_t).5 for the seed error-path injection, while one mutation generation reaches 100% action compliance for each tested model. The strongest mutation places the malicious instruction between an error explanation and a benign continuation. Production CLI frameworks tested in isolated environments achieve zero reported action compliance and explicitly flag the payloads, illustrating the distinction between base-model vulnerability and framework-layer protection (Patel et al., 6 Jun 2026).

Efficient protection analysis

FastFlip combines empirical injection within program sections with symbolic SDC propagation (Joshi et al., 2024). It reuses unaffected section analyses when programs evolve and selects instructions for protection through a cost-constrained optimization. The method reports a L~t+k=fθ(X~t−H,…,X~t).\tilde L_{t+k} = f_\theta(\tilde X_{t-H},\ldots,\tilde X_t).6 geometric-mean speedup for modified programs.

FastFlip is evaluated using transient register bit flips rather than explicit load faults. Its compositional structure could be adapted to LEI by expanding section interfaces to include memory objects, addresses, loaded values, aliases, and load-use dependencies. Such an extension would allow local load-error experiments to be cached and propagated symbolically across evolving programs, while retaining explicit treatment of side effects and downstream masking.

6. Training and architectural applications

Mixture-of-experts routing

In a separate machine-learning use, LEI denotes Load-Error Injection for local mixture-of-experts balancing rather than an adversarial fault. For a local microbatch L~t+k=fθ(X~t−H,…,X~t).\tilde L_{t+k} = f_\theta(\tilde X_{t-H},\ldots,\tilde X_t).7, the hard load fraction of expert L~t+k=fθ(X~t−H,…,X~t).\tilde L_{t+k} = f_\theta(\tilde X_{t-H},\ldots,\tilde X_t).8 is

L~t+k=fθ(X~t−H,…,X~t).\tilde L_{t+k} = f_\theta(\tilde X_{t-H},\ldots,\tilde X_t).9

with uniform target γ∈{−1,1}\gamma\in\{-1,1\}0. The relative local load error is

γ∈{−1,1}\gamma\in\{-1,1\}1

Positive γ∈{−1,1}\gamma\in\{-1,1\}2 indicates an overloaded expert; negative γ∈{−1,1}\gamma\in\{-1,1\}3 indicates an underloaded expert (Neitemeier et al., 23 Sep 2026).

Because hard top-γ∈{−1,1}\gamma\in\{-1,1\}4 routing is nondifferentiable, LEI uses a straight-through formulation. It leaves the forward pass unchanged and injects the observed local load error into router-score gradients:

γ∈{−1,1}\gamma\in\{-1,1\}5

The stabilized residual is

γ∈{−1,1}\gamma\in\{-1,1\}6

An overloaded expert receives a positive gradient increment, so gradient descent decreases its score; an underloaded expert receives a negative increment, increasing its score. LEI therefore responds to the current local microbatch, whereas token-independent expert biases and EQB primarily address systematic or global imbalance.

In 100-billion-token ablations, EQB plus normalized LEI achieves Local MaxVio γ∈{−1,1}\gamma\in\{-1,1\}7, compared with γ∈{−1,1}\gamma\in\{-1,1\}8 for EQB plus normalized GShard, while mean BPB is γ∈{−1,1}\gamma\in\{-1,1\}9 versus ∥Xt−itemp−X~t−itemp∥p≤ϵ.\left\|X_{t-i}^{temp}-\tilde X_{t-i}^{temp}\right\|_p\leq\epsilon.0. In 500-billion-token experiments, normalized LEI reduces Local MaxVio from ∥Xt−itemp−X~t−itemp∥p≤ϵ.\left\|X_{t-i}^{temp}-\tilde X_{t-i}^{temp}\right\|_p\leq\epsilon.1 to ∥Xt−itemp−X~t−itemp∥p≤ϵ.\left\|X_{t-i}^{temp}-\tilde X_{t-i}^{temp}\right\|_p\leq\epsilon.2 and increases average accuracy from ∥Xt−itemp−X~t−itemp∥p≤ϵ.\left\|X_{t-i}^{temp}-\tilde X_{t-i}^{temp}\right\|_p\leq\epsilon.3 to ∥Xt−itemp−X~t−itemp∥p≤ϵ.\left\|X_{t-i}^{temp}-\tilde X_{t-i}^{temp}\right\|_p\leq\epsilon.4, while Global MaxVio increases from ∥Xt−itemp−X~t−itemp∥p≤ϵ.\left\|X_{t-i}^{temp}-\tilde X_{t-i}^{temp}\right\|_p\leq\epsilon.5 to ∥Xt−itemp−X~t−itemp∥p≤ϵ.\left\|X_{t-i}^{temp}-\tilde X_{t-i}^{temp}\right\|_p\leq\epsilon.6 (Neitemeier et al., 23 Sep 2026). These results show that global and local balance are distinct objectives and that improving one can affect the other.

Physical load-reflection perturbation

A magnetron study provides another load-related interpretation: controlled perturbation of the complex load through reflection coefficient magnitude (Chen et al., 20 Dec 2025). The reflection coefficient is

∥Xt−itemp−X~t−itemp∥p≤ϵ.\left\|X_{t-i}^{temp}-\tilde X_{t-i}^{temp}\right\|_p\leq\epsilon.7

An E–H tuner varies load reflection between a magnetron and circulator. Increasing reflection changes external coupling, effective injection, locking bandwidth, phase noise, output power, and efficiency. Moderate mismatch can suppress sideband energy and phase noise; excessive mismatch weakens coupling, narrows locking bandwidth, reduces output power, excites unwanted modes, and may cause loss of lock.

The experiment is not a general LEI framework. It principally varies ∥Xt−itemp−X~t−itemp∥p≤ϵ.\left\|X_{t-i}^{temp}-\tilde X_{t-i}^{temp}\right\|_p\leq\epsilon.8 rather than independently controlling reflection phase, complex impedance, or time-varying mismatch. Nevertheless, it demonstrates a physical injection mechanism in which a controlled load perturbation produces measurable system-level responses.

7. Limitations and distinctions

LEI studies differ fundamentally in whether the injection is adversarial, stochastic, diagnostic, economic, or algorithmic.

Adversarial versus ordinary uncertainty: ordinary forecast uncertainty is unintentional and may be stochastic; power-system LEI is intentionally optimized and directionally biased (Chen et al., 2019). LPV prices uncertainty variance and does not necessarily price one malicious realization (Brooks et al., 2020).

Input perturbation versus state corruption: altering a temperature forecast, smart-meter profile, or LSTM history differs from corrupting RAM, a register, a cache response, or a system-call return. A later erroneous load may be a consequence of memory corruption rather than a direct load fault (Magliano et al., 2024, Lentini et al., 10 Jun 2026).

Detection versus propagation: GP-based probabilistic load flow propagates uncertain injections but does not detect their origin (Pareek et al., 2019). LCFI and FastFlip analyze propagation and masking but do not provide general causal diagnosis (Shan et al., 2020, Joshi et al., 2024).

Economic alignment versus maliciousness: a price-aligned smart-meter profile may be fraudulent, but legitimate demand response can produce similar behavior (Lu et al., 2023).

Model-layer versus system-layer security: VATS exposes model-level susceptibility to error-path instructions, whereas production agent frameworks may block the same behavior through provenance checks, approval requirements, least privilege, or alternative tools (Patel et al., 6 Jun 2026).

Global versus local balancing: in MoE training, LEI corrects local routing imbalance through backward-gradient modification, while EQB addresses exact global quantile balancing (Neitemeier et al., 23 Sep 2026).

Across domains, the most general methodological requirement is to specify the injection boundary, perturbation model, timing, target, observability, and consequence metric. A technically complete LEI evaluation should distinguish the injected quantity from the downstream error, report whether the perturbation is direct or indirect, and evaluate both local propagation and system-level impact.

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to Load-Error Injection (LEI).