skip to content

What does a total-energy budget over a forecaster's input window permit that a per-step cap forbids?

level: middleimportance: should knowfreq 44%

answer

  1. each forbids what the other permits
  2. spike against sustained drift
  3. the whole allowance on one step
  4. every step moves, none looks odd
  5. spread thin: divide by root T

basics

~20 s

A total-energy budget can be spent entirely on one step, giving a spike the per-step cap forbids. The cap forbids that spike but lets every step shift by the full cap together, which the energy budget does not.

solid answer

~50 s

Each of the two forbids what the other permits, so they are different attackers rather than tighter and looser versions of one. Over a window of `T` recent steps, a per-coordinate cap of `c` (an L-infinity ball) allows all `T` steps to shift by `c` together: the window mean moves by the full `c` and a horizon sum by `c` times `T`, with no single point ever looking anomalous. A total-energy bound (an L-2 ball) of radius `r` allows one step to absorb the whole `r` -- a visible spike -- or a coherent shift of only about `r` divided by the square root of `T` per step. The shapes have different detection profiles too: the spike trips an outlier check, the sustained drift sits inside normal variation. And when the window mixes units, one radius over standardized coordinates buys a different physical change in each of them.

go deeper

for a junior

Know that a bound on each value separately and a bound on the total change are not the same rule, and that one number can mean either.

for a middle

Be ready to work the arithmetic aloud: all steps shifting by the cap moves the window mean by the full cap, while a total-energy allowance spread over the window leaves far less per step.

for a senior

Show you connect the permitted shape to what your monitoring can see, and that you convert a permitted change into the decision it moves rather than leaving it as a radius.

for a principal

Own the choice of which bound the organisation states, knowing it decides which attack shape gets declared negligible and therefore never tested.

## Two bounds, two shapes Take a short-horizon forecaster whose input is a rolling window of the last `T` steps of recent market history -- posted quantities and quoted prices that the market's own participants supply. An adversary here is an enrolled participant who can write into that window by posting. The question is what bound you place on what they write, and the answer is not a single number. **A per-coordinate cap** (an L-infinity ball of radius `c`) says: no step of the window may move by more than `c`. It says nothing about how many steps move. All `T` of them may move by `c`, in the same direction. The window's mean then shifts by the whole `c`, and anything the model aggregates over the horizon shifts by roughly `c` times `T`. No single point of the series ever looks unusual, because none of them is. **A total-energy bound** (an L-2 ball of radius `r`) says: the squared changes must sum to no more than `r` squared. That allowance can be spent any way at all. Put it on one step and that step moves by the full `r` -- a spike. Spread it evenly and each step moves by about `r` divided by the square root of `T`, which for a window of a few dozen steps is a small fraction of `r`. So at the *same numeric value*, the two bounds buy very different attacks: the cap buys persistence, the energy bound buys concentration. Neither is the strict weakening of the other, and there is no ordering that makes one "a bit stricter". ## Why the shape decides whether anyone notices A concentrated change is the one a monitoring pipeline is already built for: outlier filters, range checks and plausibility rules on a single reading exist and will fire. A coherent small shift across the whole window is the one nothing fires on, because every value is individually ordinary and only their *joint* direction is not. If you bound an attacker by a per-coordinate cap because it sounds conservative, you have licensed exactly the shape your monitoring cannot see -- and quietly declared a bias across the entire window to be negligible. That is the silent permission worth naming. A change that the radius describes as tiny is not tiny at the decision. A forecast that is biased by a small amount across the whole horizon commits capacity or settles money differently, and "the perturbation was within a small radius" is not an answer to "how much did the decision move". ## The unit problem inside one window A window like this rarely carries one kind of number. Quantities in energy units and prices in currency sit in the same vector, and models usually standardize before consuming them. A single radius applied to the standardized window then means "this many standard deviations" for every coordinate -- which is a *different* real-world allowance for each, set by how wide that coordinate's historical spread happens to be. A coordinate that is normally stable receives a tight physical allowance; a coordinate that is normally volatile receives a large one. Nobody chose that ranking; it fell out of the data's variance. The same trap appears in reverse when the radius is quoted in raw units. A radius that is small for a price is enormous for a quantity, or vice versa, and one number cannot be small for both. The honest treatments are: bound each unit group separately in its own units, or express the radius per coordinate as a fraction of that coordinate's own legal range, and state the mapping either way. What you cannot do is state one standardized number and let readers assume it is uniformly modest. ## Sign, granularity and reachability One more asymmetry: real postings are sign-constrained and granular. A ball is symmetric and continuous, so part of it corresponds to values nobody can post, and some values anyone may legally post lie outside it. The ball is an approximation of the reachable set in both directions at once, which is why the bound should be stated together with the coordinates it applies to, not as a free-floating number. ## The short version Over a window, the norm decides the *shape* of the permitted change; the radius decides its size in whatever units the model consumes. Persistence and concentration are different attacks with different detection profiles and different costs at the decision, and quoting one number without saying which shape it permits tells the reader nothing about either.

  • Which of the two shapes is easier for a monitoring pipeline to catch?
    The concentrated one. A single step carrying the whole allowance is exactly what outlier filters, range checks and plausibility rules are built for. A coherent small shift on every step of the window is individually ordinary at every point, so nothing fires -- only the joint direction is unusual, and few pipelines look at that.
  • You must bound an attacker on a window that mixes energy quantities and prices. What do you do?
    Bound each unit group separately in its own units, or state the per-coordinate radius as a fraction of that coordinate's legal range. A single radius over standardized inputs silently gives each coordinate an allowance set by its historical spread, which nobody chose and which does not correspond to what a participant can post.

saying these in an interview costs you the question

  • Treats the two bounds as strict and loose versions of one attacker
  • Assumes a per-coordinate cap bounds the window mean by cap divided by steps
  • Thinks standardizing makes one radius fair across mixed units
  • Calls a change negligible without converting it to the decision it moves
  • Ignores that a sustained shift evades per-point outlier checks

context