---
title: 'Load-Error Injection (LEI): Techniques and Applications'
url: https://www.emergentmind.com/topics/load-error-injection-lei
type: topic
---

# Load-Error Injection (LEI): Techniques and Applications

Load-Error Injection (LEI) is a term applied to several technically distinct mechanisms in which an externally supplied load, load-related signal, or execution workload is deliberately perturbed to study, exploit, or mitigate error propagation. In power systems, LEI commonly denotes malicious manipulation of load forecasts, load measurements, or non-dispatchable injection estimates. In computing and machine learning, the term is also used for perturbations of forecasting inputs, local mixture-of-experts loads, or error paths in tool-using agents. Across these domains, the common structure is a load or workload signal, an injected deviation, and an observable downstream consequence; the injection point, threat model, operational objective, and evaluation criteria differ substantially.

## 1. Terminology and conceptual scope

LEI is not a single standardized attack or testing protocol. The term encompasses at least four recurring interpretations.

**Forecast-input injection** modifies exogenous features or historical measurements before a forecasting model produces an output. In power-system forecasting, an attacker may alter temperature forecasts rather than metered load, state-estimation measurements, or market-clearing inputs. The forecast is then supplied to day-ahead unit commitment while real-time economic dispatch uses actual load, creating a strategically induced mismatch [1906.04926]. A related microgrid study injects Gaussian noise directly into the historical load sequence presented to an LSTM during inference [2304.13104].

**Measurement or profile injection** alters a reported load time series. Smart-meter attacks may replace the profile with zeros or construct a nonzero reduced-cost spot attack intended to shift apparent consumption toward lower-price periods [2301.10628]. In economic modeling, the deviation between actual and scheduled non-dispatchable injection is represented by $\Delta P_{ND}$; for load, if $L_i=\widehat L_i+e_i$, the corresponding injection error is $\Delta P_{ND,i}=-e_i$ [2001.01302].

**Fault-oriented injection** perturbs computational state, memory, registers, system-call returns, or numerical values to investigate error propagation. Phoebe derives realistic system-call error models from production-like observations [2006.04444]. LCFI injects statistically abstracted lossy-compression errors into LLVM-level values [2010.12746]. Hardware and simulator frameworks inject transient bit corruptions into registers or memory, which may subsequently affect loads [2401.08397; 2606.12011].

**Error-path injection** places attacker-controlled instructions inside tool error responses so that an autonomous agent interprets them as recovery instructions. VATS studies this mechanism in MCP-based tool-calling systems and characterizes it as indirect prompt injection delivered through a failure path [2606.07992].

The common abstraction can be expressed conceptually as

$$
\text{load or workload state}
\longrightarrow
\text{injected error}
\longrightarrow
\text{model, computation, or control response}
\longrightarrow
\text{observable consequence}.
$$

The observable consequence may be forecast error, infeasible dispatch, increased balancing cost, anomalous billing, corrupted program output, a crash, loss of lock, expert-routing imbalance, or an unauthorized tool call. The term should therefore be qualified by its domain and injection boundary.

## 2. Power-system LEI

### Forecast manipulation

The principal power-system formulation treats the load forecast as a function of a historical feature sequence,

$$
\hat L_{t+k}=f_\theta(X_{t-H},\ldots,X_t),
$$

where the feature vector includes load-history features, temperature values or forecasts, and weather, seasonal, weekday/weekend, and hour-of-day indicators [1906.04926]. The attacker perturbs temperature inputs,

$$
\Delta X_{t-i}^{temp}
=
\tilde X_{t-i}^{temp}-X_{t-i}^{temp},
$$

thereby inducing

$$
\tilde L_{t+k}
=
f_\theta(\tilde X_{t-H},\ldots,\tilde X_t).
$$

The directly altered quantity is therefore not necessarily a physical load measurement. It is an upstream feature whose effect propagates through the forecasting model.

The attack may be formulated with a direction variable $\gamma\in\{-1,1\}$ and a norm-constrained perturbation:

$$
\left\|X_{t-i}^{temp}-\tilde X_{t-i}^{temp}\right\|_p\leq\epsilon.
$$

The norm may be $p=0$, $1$, or $\infty$, corresponding respectively to restrictions on the number of altered entries, aggregate perturbation magnitude, or maximum individual deviation. The principal experiments use an $L_\infty$ constraint, expressed as a maximum temperature deviation in degrees Fahrenheit [1906.04926].

### Threat models

The power-system study considers white-box, black-box query, and substitute-model transfer settings. A white-box attacker knows the forecasting model and parameters. A black-box attacker knows the model family and can query a forecasting service with modified inputs, estimating gradients by finite differences. In the transfer setting, the attacker trains a substitute model using historical data drawn from the same feature distribution and transfers perturbations to the unknown target.

Topology knowledge is not required to create forecast-level errors, but it improves the ability to convert those errors into operational failures. With topology, line limits, generator capacities, and ramp constraints, the attacker can select vulnerable load buses and attack directions. Without such information, buses and directions are selected randomly [1906.04926].

### Operational propagation

Day-ahead unit commitment is optimized against attacked forecasts $\tilde L_d^t$, producing an attacked commitment $\tilde G_t$. Real-time economic dispatch then uses the actual load $L_d^t$ while being constrained by the attacked commitment. The propagation chain is:

$$
\Delta X^{temp}
\longrightarrow
\Delta\hat L
\longrightarrow
\tilde G_t\neq G_t
\longrightarrow
\text{different generator availability and dispatch}
\longrightarrow
\text{ramp, capacity, or line-flow violations}
\longrightarrow
LS_d^t>0.
$$

Underestimation may cause insufficient generator commitment, inadequate ramping capability, or omission of a generator required for a peak. Overestimation commonly produces redundant or expensive commitment. Underestimation is generally more damaging because it can produce physical infeasibility and load shedding, whereas overestimation primarily creates economic harm [1906.04926].

### Experimental evidence

The power-system forecasting experiments use hourly Swiss load data, temperature forecasts for Swiss cities, and hour, weekday, and seasonal indicators. The principal forecasting model is a three-layer RNN with clean test MAPE of $1.58\%$. NN, RNN, and LSTM models are all evaluated.

A temperature perturbation of $1^\circ\mathrm F$ produces forecast deviations exceeding 500 MW at some times; a $5^\circ\mathrm F$ perturbation produces errors above 1,200 MW. With a $4^\circ\mathrm F$ budget, query-based gradient estimation raises MAPE to $13.09\%$ for NN, $11.68\%$ for RNN, and $11.87\%$ for LSTM, compared with clean values of $1.68\%$, $1.58\%$, and $1.51\%$, respectively [1906.04926].

In the IEEE 14-bus study, topology-aware attacks cause load shedding on more than 100 of 122 evaluated Swiss test days under a strategically injected $5^\circ\mathrm F$ perturbation. Even one compromised nodal forecast causes shedding on more than 40 days in the reported setting. In the IEEE 118-bus example, compromising a small subset of nodal forecasts changes commitment and produces system-wide effects, including overloaded lines, generators at capacity, and load shedding at a bus whose generator is offline [1906.04926].

## 3. Propagation, uncertainty, and economic consequences

### Probabilistic load-flow propagation

Non-parametric probabilistic load flow using Gaussian-process learning provides a response-surrogate layer for analyzing uncertain or perturbed injections [1911.03093]. The method learns an inverse power-flow map from power injections to bus-voltage states,

$$
\mathbf y=f(\mathbf x),
$$

using Gaussian-process regression and GP-UCB sample selection. It can evaluate perturbed input vectors such as

$$
\mathbf x_{\mathrm{err}}=\mathbf x_0+\Delta\mathbf x
$$

and estimate the corresponding voltage response through the GP posterior mean. It can represent additive, bounded, intermittent, or distributionally sampled perturbations, although the paper does not itself provide an LEI detector, causal attribution method, or explicit adversarial attack model.

The method supports arbitrary test-time input distributions provided their support is covered by the learned domain. Its probabilistic learning bound concerns approximation of the learned physical response, not the correctness of the underlying load measurements. It cannot distinguish a physical load change from a measurement error, communication fault, topology error, or adversarial injection [1911.03093].

### Locational cost of variability

The Locational Price of Variability (LPV) measures the marginal change in optimized system production and reserve cost resulting from a change in uncertainty standard deviation at a location:

$$
LPV_i=\frac{\partial C^*}{\partial\sigma_i}.
$$

It is particularly relevant to probabilistic LEI because it prices the system consequences of injection uncertainty rather than merely its magnitude. The effect of a deviation depends on network location, generator limits, congestion, AGC participation factors, and available regulation capacity [2001.01302].

A load forecast error represented as $e_i$ corresponds to an injection error $\Delta P_{ND,i}=-e_i$. AGC response is distributed according to participation factors $\beta_i$, so an error has both a direct network effect and an indirect balancing effect. Two equal-magnitude errors can therefore produce different line-flow impacts and costs.

Chance-constrained formulations represent reserve and branch-flow security probabilistically. Under the paper’s Gaussian assumptions, uncertainty consumes generator headroom and transmission margin. An LEI-oriented charge may be based on $LPV_i\sigma_i$ or on an incremental uncertainty difference relative to a baseline, but LPV prices marginal uncertainty rather than necessarily the cost of one realized error. The distinction between ex-ante variability pricing and ex-post deviation settlement is therefore material [2001.01302].

### Smart-meter profile manipulation

The smart-meter anomaly-detection study normalizes 48 half-hourly observations and constructs business-conditioned behavioral models using agglomerative hierarchical clustering. Global, time-block, and index features describe each profile. A violation score identifies deviations outside a two-standard-deviation interval, while the incentive-weighted violation score combines profile deviation with relative spot-price variation:

$$
WSP=\frac{CSP-FP}{FP}.
$$

The reduced-cost spot attack is intended to make apparent consumption more favorable under intraday prices. The method seeks to distinguish economically motivated injections from ordinary profile anomalies by combining behavioral deviation with financial incentive [2301.08397].

The reported evidence is qualitative and graphical. RCSA profiles are consistently detected in the displayed examples, while incentive weighting increases the visibility of price-aligned attacks. The study does not report detection rate, false-positive rate, precision, recall, ROC/AUC, F-score, confidence intervals, or a confusion matrix. Price alignment is evidence of a possible motive, not proof of maliciousness, because legitimate demand response may also shift consumption toward lower-price periods.

## 4. Computational and systems fault injection

### Production-grounded system-call errors

Phoebe constructs realistic system-call error models from production-like observations. A model is represented as $(s,e,r)$, where $s$ is the system call, $e$ is the error code, and $r$ is the injection rate. The framework distinguishes sporadic, fluctuating, and steady errors and uses observed error-rate statistics to synthesize executable policies [2006.04444].

The injector uses eBPF hooks at `raw_syscalls/sys_enter` and `raw_syscalls/sys_exit`, applying `bpf_override_return` at the system-call return event. It normally injects only on calls that would otherwise succeed, thereby adding failures rather than replacing naturally occurring failures. The workload determines which calls occur; Phoebe does not independently control request rate, concurrency, arrival distribution, or load intensity.

Phoebe evaluates application-level Behavioral Assessment Criteria. In the HedWig and TTorrent case studies, realistic system-call failures expose crashes, fetching failures, sending failures, checksum failures, stalls, and persistent state corruption. The framework demonstrates that low-level errors such as `read:EAGAIN`, `read:ECONNRESET`, and futex failures can produce high-level application failures, while some errors have no observed behavioral impact [2006.04444].

### LLVM-level numerical perturbations

LCFI injects numerical perturbations into LLVM-level values to emulate error-bounded lossy-compression reconstruction errors [2010.12746]. Its fault models combine absolute or relative error bounds with uniform or normal error distributions. Tested relative bounds are $1\%$, $5\%$, $10\%$, $50\%$, and $100\%$; tested absolute bounds are $0.01$, $0.05$, $0.1$, $0.5$, and $1$.

The user specifies a function, variable, occurrence, array status, loop status, and loop iteration. Each LLVM instruction receives an `llfi_index`, enabling stable instrumentation and dynamic targeting. Baseline and faulted executions are compared through application outputs, convergence, crashes, checksums, execution time, and trace differences.

The same nominal perturbation can be benign or harmful depending on its dynamic location. In HPCCG, errors injected in an early loop may be tolerated, whereas errors in a later loop prevent convergence. Black-Scholes exhibits crashes and corrupted results; XSBench exhibits output changes and increased execution time; NPB-MG produces corrupted outputs for all tested fault types [2010.12746].

### Hardware and architectural-state injection

The microarchitectural-events-aware injector uses a Python host, Xilinx XSCT, JTAG, FreeRTOS, and a Xilinx Zynq/PYNQ-Z2 board. It halts execution at a breakpoint, modifies a CPU register or RAM word, resumes execution, and observes both program output and PMU events [2401.08397].

The implemented fault is a single-bit upset. Conceptually, a target word $x$ is changed to $x\oplus2^b$. The mechanism does not directly corrupt a load instruction, cache response, memory-bus transaction, load/store queue, or memory-data return path. RAM corruption may later be consumed by a load; register corruption may approximate post-load corruption, but the fault site remains architectural state rather than the load pipeline.

Across Dijkstra, QuickSort, and SHA, memory and register campaigns classify executions as benign, SDC, or crash/hang. Register campaigns produce SDC rates of $4.4\%$, $2.6\%$, and $11.2\%$, respectively; memory campaigns produce $0.7\%$, $0.9\%$, and $3.9\%$. PC campaigns are dominated by crashes and hangs [2401.08397].

InjectV extends this architectural approach in gem5-based RISC-V simulation. It uses checkpoints, golden and divergent execution traces, candidate injection points, and parallel campaigns. Its current experimentally supported faults are transient register and physical-memory corruptions. The framework identifies security-relevant branches, comparisons, write-before-use relationships, and memory regions. In VerifyPIN experiments, guided injection discovers 48 successful security violations compared with two under random injection, with a reported 95.8% time-saving advantage over brute-force random injection [2606.12011].

Neither framework, as described, implements a dedicated load-result fault model. Explicit LEI would require hooks at address generation, memory request, memory response, writeback, or load/store-queue stages.

## 5. Analysis, mitigation, and defense

### Forecast and measurement defenses

Power-system LEI defenses include anomaly detection, robust statistics, validation of external weather inputs, and joint evaluation of forecasting and downstream UC/ED consequences rather than MAPE alone [1906.04926]. A complete defense must detect both anomalous features and implausible forecast-to-operation combinations. Reserve, commitment, and dispatch procedures should remain safe under bounded forecast manipulation.

The GP-based probabilistic load-flow method can serve as a nonlinear forward surrogate for scenario analysis and uncertainty propagation, but it does not itself detect or localize an injection [1911.03093]. LPV can quantify the economic value of reducing uncertainty through storage, improved forecasting, or controllable load, but it does not identify malicious deviations [2001.01302].

The smart-meter detector uses business-type clustering and price-aware weighting to reduce false positives caused by ordinary profile variation. Its limitations include incompletely specified distances and linkage, absent numerical thresholds, simplified economic assumptions, and the possibility that legitimate demand response resembles an attack [2301.08397].

### Signal-processing mitigation

For Gaussian noise injection against an LSTM load forecaster, an FFT-based low-pass filter suppresses higher-frequency components before inference [2304.13104]. The healthy MAE is $0.047$ MW, increasing to $0.097$ MW at SNR $=6$ dB. A cutoff of $2.5\times10^{-5}$ Hz reduces average attacked MAE from $0.079$ MW to $0.073$ MW. The filter is more effective against lower-SNR attacks and less promising for small noise, where filtering may remove legitimate load dynamics.

This defense is specific to spectral assumptions. It does not address bias, ramps, replayed values, bursts, temporally correlated errors, or targeted perturbations whose spectrum overlaps legitimate dynamics. It is a mitigation mechanism rather than a detector.

### Agentic error-path defenses

VATS demonstrates that tool errors should be treated as untrusted data rather than as automatically authoritative recovery instructions [2606.07992]. Recommended defenses include separating machine-readable error codes from free-form help text, validating provenance, flagging action words, requiring human approval for sensitive error-directed actions, enforcing least privilege and tool isolation, and maintaining functional alternatives.

In controlled model-layer experiments, aggregate action compliance rises from $16.7\%$ for matched successful-response injections to $50\%$ for the seed error-path injection, while one mutation generation reaches 100% action compliance for each tested model. The strongest mutation places the malicious instruction between an error explanation and a benign continuation. Production CLI frameworks tested in isolated environments achieve zero reported action compliance and explicitly flag the payloads, illustrating the distinction between base-model vulnerability and framework-layer protection [2606.07992].

### Efficient protection analysis

FastFlip combines empirical injection within program sections with symbolic SDC propagation [2403.13989]. It reuses unaffected section analyses when programs evolve and selects instructions for protection through a cost-constrained optimization. The method reports a $3.2\times$ geometric-mean speedup for modified programs.

FastFlip is evaluated using transient register bit flips rather than explicit load faults. Its compositional structure could be adapted to LEI by expanding section interfaces to include memory objects, addresses, loaded values, aliases, and load-use dependencies. Such an extension would allow local load-error experiments to be cached and propagated symbolically across evolving programs, while retaining explicit treatment of side effects and downstream masking.

## 6. Training and architectural applications

### Mixture-of-experts routing

In a separate machine-learning use, LEI denotes Load-Error Injection for local mixture-of-experts balancing rather than an adversarial fault. For a local microbatch $\mathcal B_{\mathrm l}$, the hard load fraction of expert $e$ is

$$
F_e=\frac{f_e(\mathcal B_{\mathrm l})}{K|\mathcal B_{\mathrm l}|},
$$

with uniform target $Q_e=1/E$. The relative local load error is

$$
\rho_e
=
\frac{f_e(\mathcal B_{\mathrm l})}
{K|\mathcal B_{\mathrm l}|/E}
-1.
$$

Positive $\rho_e$ indicates an overloaded expert; negative $\rho_e$ indicates an underloaded expert [2609.28053].

Because hard top-$K$ routing is nondifferentiable, LEI uses a straight-through formulation. It leaves the forward pass unchanged and injects the observed local load error into router-score gradients:

$$
\operatorname{grad}_{s_{t,e}}
\leftarrow
\operatorname{grad}_{s_{t,e}}
+
\eta\widetilde\rho_e.
$$

The stabilized residual is

$$
\widetilde\rho
=
\rho
\frac{\tanh(\|\rho\|_\infty/c)}
{\|\rho\|_\infty/c}.
$$

An overloaded expert receives a positive gradient increment, so gradient descent decreases its score; an underloaded expert receives a negative increment, increasing its score. LEI therefore responds to the current local microbatch, whereas token-independent expert biases and EQB primarily address systematic or global imbalance.

In 100-billion-token ablations, EQB plus normalized LEI achieves Local MaxVio $3.52$, compared with $4.30$ for EQB plus normalized GShard, while mean BPB is $0.6720$ versus $0.6758$. In 500-billion-token experiments, normalized LEI reduces Local MaxVio from $5.14$ to $4.15$ and increases average accuracy from $48.25\%$ to $48.56\%$, while Global MaxVio increases from $0.44$ to $0.63$ [2609.28053]. These results show that global and local balance are distinct objectives and that improving one can affect the other.

### Physical load-reflection perturbation

A magnetron study provides another load-related interpretation: controlled perturbation of the complex load through reflection coefficient magnitude [2512.18304]. The reflection coefficient is

$$
\Gamma=\frac{Z_L-Z_0}{Z_L+Z_0}.
$$

An E–H tuner varies load reflection between a magnetron and circulator. Increasing reflection changes external coupling, effective injection, locking bandwidth, phase noise, output power, and efficiency. Moderate mismatch can suppress sideband energy and phase noise; excessive mismatch weakens coupling, narrows locking bandwidth, reduces output power, excites unwanted modes, and may cause loss of lock.

The experiment is not a general LEI framework. It principally varies $|\Gamma|$ rather than independently controlling reflection phase, complex impedance, or time-varying mismatch. Nevertheless, it demonstrates a physical injection mechanism in which a controlled load perturbation produces measurable system-level responses.

## 7. Limitations and distinctions

LEI studies differ fundamentally in whether the injection is adversarial, stochastic, diagnostic, economic, or algorithmic.

**Adversarial versus ordinary uncertainty**: ordinary forecast uncertainty is unintentional and may be stochastic; power-system LEI is intentionally optimized and directionally biased [1906.04926]. LPV prices uncertainty variance and does not necessarily price one malicious realization [2001.01302].

**Input perturbation versus state corruption**: altering a temperature forecast, smart-meter profile, or LSTM history differs from corrupting RAM, a register, a cache response, or a system-call return. A later erroneous load may be a consequence of memory corruption rather than a direct load fault [2401.08397; 2606.12011].

**Detection versus propagation**: GP-based probabilistic load flow propagates uncertain injections but does not detect their origin [1911.03093]. LCFI and FastFlip analyze propagation and masking but do not provide general causal diagnosis [2010.12746; 2403.13989].

**Economic alignment versus maliciousness**: a price-aligned smart-meter profile may be fraudulent, but legitimate demand response can produce similar behavior [2301.08397].

**Model-layer versus system-layer security**: VATS exposes model-level susceptibility to error-path instructions, whereas production agent frameworks may block the same behavior through provenance checks, approval requirements, least privilege, or alternative tools [2606.07992].

**Global versus local balancing**: in MoE training, LEI corrects local routing imbalance through backward-gradient modification, while EQB addresses exact global quantile balancing [2609.28053].

Across domains, the most general methodological requirement is to specify the injection boundary, perturbation model, timing, target, observability, and consequence metric. A technically complete LEI evaluation should distinguish the injected quantity from the downstream error, report whether the perturbation is direct or indirect, and evaluate both local propagation and system-level impact.

Source: https://www.emergentmind.com/topics/load-error-injection-lei