Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Attack detection”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 181 records · Page 10

Electrical Fault Detection, Power Quality, Distributed Energy Resource Use Cases, and Cyber Event Applications with the Cyber Grid Guard System Using Distributed Ledger Technology

Electrical utilities continue to deploy more intelligent electronic devices (IEDs) inside and outside electrical substation and are associated with distributed energy resources (DERs). The integrity and confidentiality of data from IEDs is crucial, and distributed ledger technology (DLT) could improve the resilience of microgrids by helping to make these data more secure. The most popular applications using blockchain technology for electrical utilities is in the field is based on energy trading. However, the dynamism of the penetration of customer owned DERs and the deployment of sensors with IEDs have led to the identification of new applications using DLT that are focused on other areas, such as monitoring, operation and management of the grid and its assets. In addition, the majority of studies on electrical grid applications with blockchain were validated with software simulations. Although general monitoring of power systems for using DLT could be evaluated in operational electric grids, other DLT research applications such as defense against cyber-attacks and/or electrical fault detection are not likely to be performed in a real infrastructure because of possible risks to the network/equipment security. This report summarizes the application of power system applications using distributed ledger technology (DLT), providing a secure DLT framework for collecting data from IEDs like power meters and protective relays inside and outside of an electrical substation and/or between two different electrical utilities. In this study, the use case scenarios were created and assessed for different power system application by using DLT. The electrical fault detection for faulted phases (1), power quality monitoring of phase voltage magnitudes, frequency levels and load power factor (2), DERs use case monitoring (3), and cyber-event applications (4) were performed in a test bed with a Cyber-Grid Guard (CGG) system using DLT. It had a real-time simulator with power meters and protective relays in-the-loop. The first section of this report presents a literature review of power system applications using blockchain at research level. The second section shows the theory and equations used on this report. The third section shows the description of the test bed, equipment, architecture, and electrical grid diagrams. The fourth section shows the experimental models and use case scenarios that were performed for the electrical fault detection, power quality, DERs use case, and cyber event applications with the CGG system using DLT. The fifth section shows the results collected from the tests based on comparing the time stamped events of the analog signals from the IEDs, DLT computer and real time simulator. The sixth section performed the discussion of the results for the use case scenarios. Finally, section seven presents the conclusions for this report were presented.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Federated Machine Learning-Based Anomaly Detection System for Synchrophasor Network Using Heterogeneous Data Sets: Preprint

Synchrophasor technology is widely deployed in the energy management system to monitor the grid health at micro level and perform necessary corrective actions in real time; however, integrated phasor devices and data aggregators are exposed to several cybersecurity threats. This paper proposes a federated ML(FML)-based ADS to detect several data integrity attacks in the synchrophasor network. The proposed approach integrates the horizontal FML technique and consists of substation-based local models and a control center-based global model. The proposed methodology includes training local models using heterogeneous data sets that include network and grid information and updating the global model through multiple iterations by sharing model gradients. Finally, the trained global model is applied to identify cyberattacks, normal operation, and physical events. To validate the proof of concept, we used synthetic data sets generated by Mississippi State University and Oak Ridge National Laboratory for training and testing the classification models using the National Renewable Energy Laboratory's high performance computing resources. Our experimental results, computed through several performance measures, reveal that the proposed approach shows consistent performance during the binary, three-class, and multiclass classifications while ensuring privacy of synchrophasor data.

anomaly detection system↗

Community detection robustness of graph neural networks

Graph neural networks (GNNs) are increasingly widely used for community detection in attributed networks. They combine structural topology with node attributes through message passing and pooling. However, their robustness or lack thereof with respect to different perturbations and targeted attacks in conjunction with community detection tasks is not well understood. To shed light on latent mechanisms behind GNN sensitivity on community detection tasks, we conduct a systematic computational evaluation of six widely adopted GNN architectures graph convolutional network, graph attention network, graph sample and aggregate (GraphSAGE), differentiable pooling (DiffPool), minimum cut pooling (MinCUT), and deep modularity networks (DMoN). The analysis covers three perturbation categories: node attribute manipulations, edge topology distortions, and adversarial attacks. We use element-centric similarity as the evaluation metric on synthetic benchmarks and real-world citation networks. Our findings indicate that supervised GNNs tend to achieve higher baseline accuracy, while unsupervised methods, particularly DMoN, maintain stronger resilience under targeted and adversarial perturbations. Furthermore, robustness appears to be strongly influenced by community strength, with well-defined communities reducing performance loss. Across all models, node attribute perturbations associated with targeted edge deletions and shifts in attribute distributions tend to cause the largest degradation in community recovery. These findings highlight important trade-offs between accuracy and robustness in GNN-based community detection and offer insights into selecting architectures resilient to noise and adversarial attacks.

Goel, Jaidev [Virginia Polytechnic Inst. and State↗

Safe and Robust Binary Classification and Fault Detection Using Reinforcement Learning

In this paper, we propose a learning-based method utilizing the Soft Actor-Critic (SAC) algorithm to train a binary Support Vector Machine (SVM) classifier. This classifier is designed to identify valid input spaces in high-dimensional, highly constrained systems while minimizing the total runtime of offline simulations. The simulations adapt their runtime based on the likelihood that a given training input will be informative to the classifier. Furthermore, we introduce a method for using the trained SAC model to predict whether a desired system input is likely to violate constraints, along with a technique to adjust the input as necessary. Additionally, we explore the potential of this model to detect faults or adversarial attacks within the system. The effectiveness of our approach is demonstrated through various simulations of challenging classification problems and a constrained quadrotor model.

Netter, Josh [Georgia Institute of Technology, Atl↗

Deception-Based Cyber Attacks on Hierarchical Control Systems using Domain-Aware Koopman Learning

Industrial control systems are subject to cyber attacks that produce physical consequences. These attacks can be both hard to detect and protracted. Here, we focus on deception-based sensor bias attacks made against a hierarchical control system where the attacker attempts to be stealthy. We develop a a data-driven, optimization-based attacker model and use the Koopman operator to represent the system dynamics in a domain-aware and computationally efficient manner. Using this model, we compute several different attacks against a high-fidelity commercial building emulator and compare the impacts of those attacks to each other. Finally, we discuss some computational considerations and identify avenues for future research.

koopman operator, Cyber-Physical Security, machine↗

Cyote Research Tool Library

The software is a library of individual proof-of-concept tools to be further developed in research efforts with partner utilities to detect indicators of Cyber Attacks within the Operational Technology Environments.

Wellman, LawrenceR.↗

Essence2.0 Development and Deployment (Final Report)

The objective of the project was to take two core technologies that have been developed under the Recipient’s solid laboratory products and integrate them into a single CyberPhysical awareness platform and complete development on current field-tested prototypes that will extend the integrated capability of the platform. During the final development phase, the Recipient development team and its selected industry partners tested and hardened the platform to ensure resilient and secure operation of the integrated platform. The team also executed substantial field testing and established the framework for defining the organization and/or commercial infrastructure needed to sustain operations and provide readiness for a national scale deployment. The focus of the project was (1) the improvement, refinement, and deployment of technology for the detection of cyber-attacks on utility operational technology (OT) and information technology (IT) networks and assets, including Supervisory Control and Data Acquisition Systems (SCADA) systems; and (2) support for containment and remediation of adversarial threats and actions against those systems and environments.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

System and method associated with expedient detection and reconstruction of cyber events in a compact scenario representation using provenance tags and customizable policy

A system associated with detecting a cyber-attack and reconstructing events associated with a cyber-attack campaign, is disclosed. The system performs various operations that include receiving an audit data stream associated with cyber events. The system identifies trustworthiness values in a portion of data associated with the cyber events and assigns provenance tags to the portion of the data based on the identified trustworthiness values. An initial visual representation is generated based on the assigned provenance tags to the portion of the data. The initial visual representation is condensed based on a backward traversal of the initial visual representation in identifying a shortest path from a suspect node to an entry point node. A scenario visual representation is generated that specifies nodes most relevant to the cyber events associated with the cyber-attack based on the identified shortest path.A corresponding method and computer-readable medium are also disclosed.

Source record↗

Model-Agnostic Algorithm for Real-Time Attack Identification in Power Grid using Koopman Modes

Malicious activities on measurements from sensors like Phasor Measurement Units (PMUs) can mislead the control center operator into taking wrong control actions resulting in disruption of operation, financial losses, and equipment damage. In particular, false data attacks initiated during power systems transients caused due to abrupt changes in load and generation can fool the conventional model-based detection methods relying on thresholds comparison to trigger an anomaly. In this paper, we propose a Koopman mode decomposition (KMD) based algorithm to detect and identify false data attacks in real-time. The Koopman modes (KMs) are capable of capturing the nonlinear modes of oscillation in the transient dynamics of the power networks and reveal the spatial embedding of both natural and anomalous modes of oscillations in the sensor measurements. The Koopman-based spatio-temporal nonlinear modal analysis is used to filter out the false data injected by an attacker. The performance of the algorithm is illustrated on the IEEE 68-bus test system using synthetic attack scenarios generated on GridSTAGE, a recently developed multivariate spatio-temporal data generation framework for simulation of adversarial scenarios in cyber-physical power systems.

Nandanoori, Sai Pushpak↗

Faster-than-real-time Simulation with Demonstration for Resilient DER Integration

The US electric grid is facing operational, stability, and security challenges. Transmission system operators need some measure of visibility into distribution system renewable generation. Distribution system generation needs to support transmission system voltage. The grid is experiencing an expansion in measurement systems. How to take full advantage of this expansion and defend against attacks, both cyber and physical, poses additional challenges. The Faster-than-real-time Simulation with demonstration for Resilient DER Integration project set out to do the following: a. Flatten the voltage profile through the feeders and system for cost saving and voltage stabilization needs. b. Increase the amount of intermittent distributed energy resources (IDERs) that could be deployed on a utility feeder and provide 100% or more energy needed for the demands on that feeder, and c. based on an accurate model (Digital Twin) of the utilities system, be able to detect any abnormalities on the utilities distribution system. To manage the voltage and increase IDER penetration (a,b), Graph Trace Analysis is employed in a time-series, optimal power flow to coordinate the time-varying feedback control setpoints of a distribution feeder’s utility control devices. Under the coordinated control are a Load Tap Changing Transformer, a voltage regulator, and five switched capacitor banks. The feeder serves over 2000 customers, the feeder secondaries are modeled, and the feeder has 2.3 MW of PV generation, corresponding to a 17.4% penetration of PV generation. The feeder model has over 12,000 components, where every customer load bus and PV generator are modeled. The accuracy of the power flow solution is compared against historical meter voltage measurements, the improvement in conservation voltage reduction energy savings as a function of the coordinated control desired voltage profile is investigated, and the increase in PV penetration of the coordinated control over the existing control is presented. To achieve improved control performance while observing system operation constraints, bellwether Advanced Metering Infrastructure (AMI) voltage measurements are used to adjust the desired voltage profile used by the optimal power flow analysis. To detect and alleviate or negate attacks or failures on the distribution and transmission utility grids (c) the grid needs to be resilient and self-healing. In this project software was designed to do just that. At the center of the software is an Integrated System Model (ISM) that spans from transmission to secondary distribution. The ISM is employed in real-time abnormality detection, voltage stability forecasting, and multi-mode control. Testing results are presented for: 1—attacks on utility infrastructure; 2—energy savings from optimal control; 3—distribution system control response during a low voltage transmission system event; 4—cyber-attacks on PV inverters, where physical inverters are used in hard-ware-in-the-simulation-loop studies. Contributions of this work include real-time analysis that spans from three-phase transmission through secondary distribution; an approach for detecting abnormalities that employs measurements from three independent measurement systems; and a multi-mode distribution system control that responds to cyber-attacks, physical attacks, equipment failures, and transmission system needs.

Integrated System Model, Graph Trace Analysis, Adv↗

Cyber-Attack Identification of Synchrophasor Data Via VMD and Multifusion SVM

A large amount of synchrophasor data in the wide area measurement system (WAMS) needs to be collected and transmitted to the phasor data concentrator, thereby increasing the possibility of being attacked by hackers. The attacked data are therefore hidden into the normal synchrophasor data so that the synchrophasor data based application will be affected. To remedy this problem, an identification framework is proposed to detect the data cyber-attack in WAMS utilizing variational mode decomposition (VMD) and multifusion support vector machine (MSVM). First, VMD is used to transform the attacked data into multiple modal components. Thereafter, a novel MSVM is employed to classify the deterministic features using the proposed linear combined multikernel (LCM). Further, this LCM can fuse multiple types of features, including the time, frequency, and statistical domains of the synchrophasor data. Utilizing the actual data from FNET/GridEye, different experiments are conducted under multiple attack strengths and types. The results demonstrate that the identification framework has higher precision and robustness compared with other conventional classifiers.

97 MATHEMATICS AND COMPUTING↗

Robust Restoration From Cyber-Physical Attacks in Active Distribution Grids With Grid-Edge IBRs

The inverter-based resources (IBRs) have enabled the integration of renewable energy at the grid edge with enhanced control capabilities to support the reliable operation of power grids. Different control frameworks, such as hierarchical or distributed architecture, have been proposed with the expansion of cyber networks for real-time monitoring and control. This evolution of critical infrastructure into cyber-physical systems also brings more vulnerabilities for the broadened attack surfaces, and significantly increases the possibility of physical system failures or outages caused by cyberattacks. Among tremendous efforts in the defense-in-depth approach, it remains challenging to provide prompt detection and accurate location of attack entry points or paths. Therefore, the prevailing restoration framework may struggle to fully consider the cyber-physical interdependence, successfully isolate the compromised cyber and physical components, and safely recover the systems without the potential risks leading to secondary outages. This paper is motivated to develop a cyber-physical restoration framework for distribution grids to recover from cyber attacks by harnessing grid-edge IBRs. The framework is first built on the operational guidelines of IBRs considering the compromised cyber layer. Then, an ambiguity set is established to represent the uncertainty of attack scenarios and their possibility levels. Next, a distributionally robust optimization model is developed to provide the optimal load restoration strategy across all scenarios. The effectiveness of the proposed model is demonstrated through various use cases on the modified IEEE 13-node and 123-node test systems. Finally, simulation results demonstrate the effectiveness and advancement of developed post-attack restoration strategies.

Cybersecurity↗

Synchrophasor spoofing detection and remediation for wide-area damping control

Evolving cyber-attack threats put at risk automatic closed-loop systems to be incorporated in the smart grid. Wide-area control systems are particularly vulnerable to signal spoofing attacks due to sensor remoteness and dependence on satellite communication for time synchronization. A successful cyber-attack on a wide-area controller has the potential to reduce relative stability of the power system or worse, destabilize it. As such, detection algorithms must be deployed as defense against such attacks with the ability to autonomously correct for detected tampering or misoperation. The Spoof Catch and Restore Routine (SCR 2 ), a combination of three real-time spoof detectors, each requiring limited information about the plant, is reported here. Nonlinear simulations of a compromised wide-area control system deployed in the Western Interconnection show the effectiveness of SCR 2 in detecting both delay-type and counterfeit-type spoofing attacks on wide-area sensors.

42 ENGINEERING↗

Security Enhancement of Network Constraint Grid-Edge Energy Management System

Network constrained grid edge energy management system (EMS) provides economic solution for active and reactive power dispatch of distributed energy resources (DERs) at the grid edge level. Grid edge EMS ensures secure interconnection of a circuit segment to the distribution system by maintaining grid code requirements (e.g. IEEE 1547–2018). Grid edge EMS is dependent on communication to receive load measurement, which brings a risk of unobservable false data injection attacks (FDIAs). To mitigate the risk, this paper proposes a framework to enhance resilient operation of grid edge EMS by detecting the unobservable FDIAs on loads and replacing them with forecasted values. In this work, a two-step detection algorithm is proposed. In first step, conventional residual based algorithm is deployed. Autoencoder (AE) based data driven mechanism is included in second step to detect the presence of unobservable FDIAs. After ensuring the presence of FDIA, its specific location is detected by checking the maximum residue values till the predefined threshold value is reached. Detected false data injected loads are then replaced with forecasted load values following long-short term memory (LSTM) based forecast to ensure resilient performance of grid edge EMS in the presence of attacks. This proposed security enhancement framework for grid edge EMS is evaluated in IEEE 13 bus system with three integrated DERs. Numerical simulation shows the validation of the proposed framework by reducing voltage violation in real operation of grid edge EMS.

cyber attack detection↗

Programmable intrusion detection for distributed energy resources in cyber–physical networked microgrids

We present a programmable intrusion detection method is presented to identify the malicious attacks to distributed energy resources (DERs) in the cyber-physical networked microgrids. The proposed method injects small programmable signals into the system and uses the response to identify abnormal conditions. Because of the low or even zero inertia induced by integrations of DER power-electronic-interfaces, microgrids have very limited resilience capability; and thus, being sensitive to attacks. One microgrid's malfunction caused by attacks can easily propagate to its neighboring systems when several microgrids are connected, leading to catastrophic electricity supply failures. Through the presented method, malicious intrusions can be effectively detected, located, and defended for securing microgrids. Theoretical derivations are provided to define the programmable detection rules. The detection rule is easy and flexible to update, making it difficult for attack actors to gain the knowledge of the detection rules, in order to avoid being detected. Numerical results on a cyber-physical networked microgrids system show that the proposed method is effective and efficient in precisely locating intrusion attacks to the microgrids system.

42 ENGINEERING↗

Data-based and secure switched cyber–physical systems

In this work, we develop a completely model-free moving target defense framework for the detection and mitigation of sensor and/or actuator attacks in cyber–physical systems with dynamics that evolve in discrete-time. We incorporate an intrusion detection mechanism based on an approximate dynamic programming technique that learns the policies for optimal regulation and optimal tracking while simultaneously defending against actuator and sensor attacks in a model-free fashion. Switching rules are leveraged to force proactive and reactive defense mechanisms as well as, guarantee the stability of the equilibrium point. Finally, as a case study, we apply the proposed moving target defense framework to a DC–DC converter that is used in electric vehicles.

42 ENGINEERING↗