Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Vulnerability Analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 181 records · Page 10

MSW Variability Mapping and Conversion to Biofuel

MSW (Municipal Solid Waste) is a form of biomass which consists of categorized components of waste/trash. The general categories are paper, yard trash, construction & debris, appliances, tires, glass, metals, aluminum & steel cans, plastics, organics, inorganics, and HHW (Household Hazardous Waste). This project focuses on the factors within a region or population that contribute to variability in the composition of MSW and in turn MSW’s convertibility to biofuel. A list of contributors was determined (Social Vulnerability Index, Access to Public Transportation, Racial Distribution, GDP, Personal Income) and then JMP was used to perform a Multivariate analysis to determine correlations and a Partial Least-Squares regression to determine Variable Importance Plots for each MSW category. In addition to data analysis, the convertibility of MSW to biofuel was studied via microwave pyrolysis system in order to separate and characterize the various gaseous and bio-oil products.

09 BIOMASS FUELS↗

Cybersecurity for Distance Relay Protection

This project is a DOE follow-up effort on the CREDC workshop held on September 13, 2018 in Cambridge, MA to discuss cybersecurity of distance relays, which considered the benefits, vulnerabilities and risk mitigations for the use of communication systems in power system protection. The objectives of this project are to define the taxonomy of relay protection and associated communications; define use cases describing approaches to reduce the cyber-attack surface on those protective relays; and evaluate the loss of operational functional capability from changes to communication coverage. Mitigating controls will also be evaluated to understand if there are other approaches to reduce attack surfaces while maintaining communications or partial communications. Distance relays are used to protect transmission lines of approximately 10 to 300 miles in length, by detecting short circuits (i.e., faults) on the lines and then tripping circuit breakers in the substation. Such protection systems are a subset of the power system and they incorporate sensing, logic and communication functions. Protection system exposure to cyberattack could be drastically limited by disconnecting relays from all vulnerable communication systems, but this may adversely impact overall power system performance in the absence of cyberattack. This project began with a use case analysis of protection systems with communications, as summarized in this report. It continued with modeling, testing and evaluation in a miniature power system (MPS), located in the Western Area Power Administration (WAPA) Electric Power Training Center (EPTC). The project also incorporated feedback from two industry meetings held in February and September 2019. The suggested next steps account for and complement the work already underway with DOE/CESER funding: 1. Study the performance of LCD and PC vs. PUTT, which is less reliant on communication system performance and GPS timing references. The PUTT scheme could prove to be more resilient to cyberattack or communications-related disruption. It could also be more tolerant of message re-routing with SDN/SDR communication systems. On the other hand, it will be more vulnerable to false tripping during dynamic events or to loss of the voltage signal. The optimum choice of scheme may depend on the specific power system and risk assessment. This study could provide a new template for evaluation based on business functions. 2. Research and develop new methods to detect and monitor distributed physical attacks, possibly using drones, video sensors, thermal sensors, machine learning and other advanced techniques. This will help mitigate the impact of cyberattack on the protection system, and will also help mitigate the impact of wild fires. 3. Implement a scalable PKI for use in electric utility protection systems. This will encourage widespread adoption of secure authentication methods that are already available, but not widely used at present. This will help secure engineering access to the relays. 4. Investigate the use of SDN in combination with SDR to achieve better cybersecurity and electromagnetic security of the network, incorporating path variability. This would help secure both engineering access and peer-to-peer GOOSE messaging. 5. Perform additional testing, with operator evaluation of “red button” scenarios, PUTT vs. LCD, relay mis-operations, and other cyberattacks in the EPTC. This is an important advantage of testing in the EPTC rather than by computer simulation or even hardware-in-the-loop simulation; the EPTC is already dedicated to managing the situational awareness, operator response times and other human impacts. One of the project objectives was to settle on a common nomenclature for this problem space. We have concluded that the OSI layer model, supplemented by ANSI device numbers and other IEEE standards, is already well-accepted by the industry. The IEEE PSRC knowledge base provides a great deal of public information

24 POWER TRANSMISSION AND DISTRIBUTION↗

Climate-driven deoxygenation elevates fishing vulnerability for the ocean's widest ranging shark

Climate-driven expansions of ocean hypoxic zones are predicted to concentrate pelagic fish in oxygenated surface layers, but how expanding hypoxia and fisheries will interact to affect threatened pelagic sharks remains unknown. Here, analysis of satellite-tracked blue sharks and environmental modelling in the eastern tropical Atlantic oxygen minimum zone (OMZ) shows shark maximum dive depths decreased due to combined effects of decreasing dissolved oxygen (DO) at depth, high sea surface temperatures, and increased surface-layer net primary production. Multiple factors associated with climate-driven deoxygenation contributed to blue shark vertical habitat compression, potentially increasing their vulnerability to surface fisheries. Greater intensity of longline fishing effort occurred above the OMZ compared to adjacent waters. Higher shark catches were associated with strong DO gradients, suggesting potential aggregation along suitable DO gradients contributed to habitat compression and higher fishing-induced mortality. Fisheries controls to counteract deoxygenation effects on shark catches will be needed as oceans continue warming.

Vedor, Marisa↗

Investigating the opioid epidemic across the United States: Associations between county-level characteristics and overdose mortality

The opioid crisis remains a critical public health challenge in the United States. Despite national efforts that reduced opioid prescribing by nearly 44% between 2011 and 2021, opioid overdose deaths more than tripled during the same period. This alarming trend reflects a major shift in the crisis, with illegal opioids now driving the majority of overdose deaths instead of prescription opioids. Although supply-side factors fueling this transition have been widely studied, the structural and community-level conditions that shape overdose mortality are less well understood. To help address this gap, this study has three primary objectives: (1) overcome structural gaps in national data to construct a complete nationwide county-level dataset from 2010 to 2022; (2) using data analysis, identify and investigate spatiotemporal anomalies in overdose mortality; and (3) using two machine-learning models, quantify the importance of thirteen social vulnerability variables in predicting overdose mortality. Our results identify unemployment and limited vehicle access as key county-level predictors of overdose mortality. Higher levels of these vulnerabilities are associated with elevated mortality, whereas lower levels are associated with reduced mortality. These findings highlight factors that may be relevant for public health planning and policy prioritization within the context of the opioid crisis.

Anomaly analysis↗

Stem hydraulic conductivity and vulnerability to cavitation for 26 tree species in Panama

Stem hydraulic conductivity and vulnerability to cavitation were measured for 26 tree species located in Panama. The data were generated to better understand the ecology of the focal tree species. Complementary NGEE-Tropics datasets for these species include sap flow, leaf-level gas exchange, and leaf water potential. Stem samples were collected from distal branches of canopy trees, brought to the Smithsonian Tropical Research Institute laboratory in Gamboa, Panama, and allowed to dry to various water potentials before measurements. For each species, a Weibull function was fit to the 90% quantile of the relationship between stem area specific hydraulic conductivity (Ks) and stem water potential. From these functions, maximum Ks and vulnerability parameters were derived. The data files in the package include raw data, derived parameters, and the R script used for analysis.

54 ENVIRONMENTAL SCIENCES↗

tell: a Python package to model future total electricity loads in the United States

The purpose of the Total ELectricity Load (tell) model is to generate 21st century profiles of hourly electricity load (demand) across the Conterminous United States (CONUS). tell loads reflect the impact of climate and socioeconomic change at a spatial and temporal resolution adequate for input to an electricity grid operations model. tell uses machine learning to develop profiles that are driven by projections of climate/meteorology and population. tell also harmonizes its results with United States (U.S.) state-level, annual projections from a national- to global-scale energy-economy model. This model accounts for a wide range of other factors affecting electricity demand, including technology change in the building sector, energy prices, and demand elasticities, which stems from model coupling with the U.S. version of the Global Change Analysis Model (GCAM-USA). tell was developed as part of the Integrated Multisector Multiscale Modeling (IM3) project. IM3 explores the vulnerability and resilience of interacting energy, water, land, and urban systems in response to compound stressors, such as climate trends, extreme events, population, urbanization, energy system transitions, and technology change

24 POWER TRANSMISSION AND DISTRIBUTION↗

A Computational Review of Privacy-Preserving Mechanisms for the Smart Grid

Smart grid technologies have rapidly become one of the largest and most comprehensive sources of data for the modern utility. For the most part, data streams are seen as an essential tool that enable utilities to carry their day-to-day business operations, but they also create the need for efficient and secure data management strategies. In the context of the smart grid, ensuring data privacy is becoming an increasing concern due to a combination of factors that range from shifts in operational paradigms and rapid technology evolution to changes in legislation. Furthermore, researchers have highlighted the risks associated with improperly protected energy records. For example, energy consumption data from homes could be used to infer the behaviors and habits of home occupants through activity recognition or user profiling (Fan, 2017), which may lead to unfair service pricing, targeted advertising, or other personal security violations. Similarly, Electric Vehicles’ (EVs) charging metadata could be used to reveal private information about the owner such as their payment methods, preferred charging stations, and other locational and timing information that could be used to reconstruct the vehicle owner’s behaviors. The privacy of user data, even when used for statistical analysis or machine learning training processes, also needs to be carefully considered, as an individual’s private traits may still be vulnerable if their inclusion/exclusion greatly impacts the result or could be linked to a public dataset through cross-reference. The breach of user privacy also has severe impacts for organizations that store, transmit, or work on the data in the form of diminishing the public’s trust in them while potentially incurring legal consequences (e.g., fines and suspensions under the European Union General Data Protection Regulation, Health Insurance Portability and Accountability Act, etc.). Because of these risks, several privacy-preserving mechanisms are available to help organizations comply with privacy legislations and prevent the unauthorized and malicious use of user data. In light of these concerns, this report focuses on performing a computational review of privacy-preserving mechanisms that have received a significant amount of interest in literature. It specifically focuses on 1) homomorphic encryption, 2) zero-knowledge proofs, 3) differential privacy, and 4) federated learning. It is worth noting that although many of the methods presented in this document rely on cryptographic primitives, their intent is not to provide perfect secrecy, but rather to enable users to maintain privacy, and thus they shall not be compared or equated to other constructs that are aimed to address cybersecurity constructs.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Simulating Alpha Particles Incident on MKID Chips for Quantum Sensitivity Analysis

Superconducting quantum devices, such as microwave kinetic inductance detectors (MKIDs), are highly sensitive instruments used in quantum computing and advanced sensing technologies. However, their extreme sensitivity also makes them vulnerable to background noise from natural sources like radiation. One significant contributor to this noise is alpha particles emitted by 210Po, a radon decay daughter that accumulates on surfaces near the detector. This project investigates how alpha particles emitted from 210Po interact with MKID chips. These particles can deposit energy on the detector surface, disrupting its operation and generating false signals. Understanding the energy and behavior of these particles is crucial for improving the design and reliability of quantum devices. To explore this, we first modeled the decay chain starting from 210Pb to 210Po using differential equations. This allowed us to predict how the activity of alpha-emitting isotopes changes over time, reaching a steady state after about two years. Next, we simulated alpha particle interactions with the MKID chip using the Geant4 software toolkit. We built a detailed computer model of the detector housing, including the copper lid where alpha particles originate, the silicon chip, and a thin aluminum sensor layer. Alpha particles were emitted isotropically from just beneath the copper lid’s surface, mimicking natural decay conditions. The simulation tracked how these particles deposit energy on the chip, generating electron-hole pairs and phonons. The results provide insight into the behavior of the resultant electron-hole pairs and phonons, giving us a clear understanding of the energy deposition distribution on the chip. This work supports efforts to mitigate background noise in superconducting sensors, advancing their use in quantum computing and sensitive physics experiments.

Hall, Matthew [Fermilab; UCLA]↗

Accelerating Hanford Site Cleanup through Operations Research Modeling - 20238

The Hanford Site cleanup effort will require the integration of dozens of unique facilities and processes, many of which will be first-of-a-kind in implementation and design. Each facility will be governed by its own set of operating logic, configured with a unique array of unit operations, and subject to a set of constraints that will affect its behavior. The collection of facilities have multiple points of interface, making the operations of any one facility potentially significant to the operations of other up- or downstream processes. It is therefore highly desirable to accurately predict these operations, as it allows for Site officials to identify and preempt bottlenecks and vulnerabilities before they unexpectedly inhibit the cleanup mission. With the quantity and complexity of the processes that will be on Site, building a pen-and-paper or even a spreadsheet-assisted model of the cleanup mission quickly becomes overwhelming in scope and inaccurate in execution. The Engineering organization for the Site's Tank Operations Contract (TOC) has therefore implemented the use of operations research (OR) modeling to simulate and predict future operations of Site facilities. These models are created using a discrete event simulation tool that allows for the development of detailed, versatile, and robust models. Not only can these models account for complex logical behaviors, but they can also simulate process details down to the level of vessel sizing, labor utilization, equipment reliability, and resource availability. To date, the TOC has developed OR models for several facilities on Site, including for single-shell tank (SST) farms, double-shell tank (DST) farms, the Effluent Treatment Facility (ETF), and the waste transfer system. These models have focused on identifying bottlenecks and operational constraints, and have been used to quantify the effects of implementing process changes. This latter point is particularly valuable, as it allows for several alternatives to be studied in a virtual setting before committing resources to making a change in the field. The decision to develop OR models has gained tremendous support from the Site's stakeholders and the U.S. Department of Energy (DOE) management, and has prompted the use of the tool to support additional internal and external initiatives. Recently, an initiative was proposed to use the models to help identify and provide quantitative backing for risks and opportunities for the TOC. This application of OR could not only help inform how the TOC manages its risks (e.g. quantities and types of spare parts), but could also help drive process improvements whose benefits might otherwise be hard to quantify. The models have also been used to drive the TOC's cloud computing, artificial intelligence (AI), and machine learning (ML) initiatives. These initiatives will not only improve the ability of the TOC to more rapidly respond to the needs of its customers, but it will also aid in the ability of the TOC to analyze and improve the processes it studies. Partnership with two external software development and consulting companies (Lanner and Ynformed) has furthered not only the application of AI and ML within the TOC, but has also spurred the development of new/improved software tools and platforms used by the companies. These partnerships have proven to be mutually beneficial and productive, and have set a precedent for the types of gains that can be made by exploring such options. (authors)

12 MANAGEMENT OF RADIOACTIVE AND NON-RADIOACTIVE W↗

Requirements and Recommendations for a Physical Attack Characterization Framework

This study seeks to identify existing frameworks or develop requirements and recommendations for a new framework that can consistently characterize physical attacks, analogous to MITRE ATT&CK®. MITRE ATT&CK is widely used across government, research organizations, and the cyber security community to characterize cyber attack tactics, techniques, and procedures (TTPs) in a consistent and commonly understood manner. While physical attack taxonomies, methodologies, and other tools for evaluating physical security do exist, many are sector and/or facility-type specific—and therefore not able to provide comparable scenarios across sectors—or are more focused on security assessment instead of the characterization of attacks themselves. A MITRE ATT&CK analog for physical attacks on critical infrastructure would provide a common language and structure for analysis of physical attacks. Existing attack characterization methodologies do not robustly address cyber-physical security risks. To fully understand a facility’s security needs, it is important to understand the entire vulnerability landscape from both a physical and a cyber perspective. To underscore this need, organizations such as the Cybersecurity and Infrastructure Security Agency (CISA) are calling for a coordinated approach to cyber and physical security, which they refer to as cyber and physical security convergence. A physical attack characterization framework that could be used jointly with MITRE ATT&CK would help support a more robust analysis in support of convergence, enabling the consistent characterization of attacks that utilize both cyber and physical tactics and techniques. This could provide analysts and stakeholders with a clearer understanding of how security mitigations deployed in the physical realm impact security risks in the cyber realm, and vice versa. In this study, the project team evaluates existing physical security taxonomies and methodologies to assess whether an existing method can be used to create a “physical half” of MITRE ATT&CK. This study then provides requirements and recommendations for a framework that can leverage aspects of existing methodologies. The goal of the final framework is for it to be widely adopted and referenced, regardless of critical infrastructure sector, facility type, or facility components. This study also identifies applicable use cases for when and how a framework could be applied across the various critical infrastructure sectors for a variety of attack types or motivations. Through a literature review of existing security-focused methodologies and taxonomies, engagement with relative stakeholders, evaluation of potential physical attack framework use cases, and subsequent identification of requirements, this study identified the following key findings and recommendations: There is a need for a new physical attack characterization framework; A physical attack framework should be interoperable with the MITRE ATT&CK framework; A physical attack framework should be broadly applicable, but with detailed tactics, techniques, and procedures that encompass the entire attack path; A physical attack framework should be based on observed or feasible events; A physical attack framework should adapt features from existing methodologies, frameworks, and taxonomies; A physical attack framework should be owned, overseen, and maintained by one organization.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Evaluation of Hardware and Software Bill of Materials (HBOMs/SBOMs) Extraction Methods

Hardware and software bills of materials (HBOMs and SBOMs) provide important visibility into the components, dependencies, and supply chain relationships within programmable digital devices. This visibility is critical for advanced nuclear reactor applications, where use of common or shared hardware components, software libraries, suppliers, or manufacturing processes may create common cause failure (CCF) vulnerabilities despite apparent diversity. This paper evaluates current approaches for obtaining and analyzing HBOMs and SBOMs in support of CCF, diversity and defense-in-depth (D3) assessments, and begins to explore potential methods for artificial intelligence/machine learning-based analysis. The availability of BOM information from advanced reactor manufacturers and vendors, representative hardware and software categories found in advanced reactor systems continues to limit research [13]. This paper compares commonly used BOM formats, including CycloneDX, SPDX, and SWID. It also surveys publicly available tools for generating BOMs from source code, compiled binaries, and hardware-related information, noting limitations in language coverage, system age, and format interoperability. Finally, this paper evaluates methods for correlating BOM data with vulnerability and exploitability information, including VEX, CVE, and CWE resources. The findings indicate that publicly available nuclear-vendor BOMs are limited, making third-party extraction and research into novel analysis techniques necessary.

Cybersecurity↗

Firmware Tampering Detection in Heavy-Duty Vehicles through J1939 CAN Analysis

Modern heavy-duty vehicles rely on complex networks of Electronic Control Units (ECUs) that communicate using the J1939 protocol. While this system makes it easier to update and configure vehicle components, it also opens the door to serious cybersecurity risks if not properly secured. This work investigates the potential for firmware tampering through the J1939 communication protocol, which enables ECU configuration and reprogramming over the Controller Area Network (CAN) bus. By monitoring CAN traffic during legitimate maintenance operations and reverse-engineering OEM diagnostic software, we identified common and proprietary J1939 message identifiers, authentication patterns, and vulnerabilities within Unified Diagnostic Services (UDS). These findings demonstrate that inadequate authentication mechanisms can allow malicious actors to alter ECU firmware or disable safety functions, posing severe operational and safety risks. Our analysis contributes to the development of vehicle intrusion detection systems capable of recognizing abnormal reprogramming activity and future firmware fingerprinting methods to verify software integrity across ECUs. This work highlights the importance of standardizing secure firmware authentication across manufacturers to strengthen cyber resilience in heavy-duty vehicle systems.

33 ADVANCED PROPULSION SYSTEMS↗

Uncertainty quantification and reliability assessment for intermodal freight transportation

Intermodal freight optimization models support cost-effective, low-emission, and timely goods movement by coordinating trucks, rail, and barges. These models determine optimal flows, routing, and modal switches while respecting infrastructure and operational constraints. However, their real-world utility is often undermined by pervasive uncertainties-such as fluctuating transportation costs and emissions, variable terminal capacities, and uncertain freight demand-that distort key performance outcomes, including total system cost, carbon footprint, and transit time reliability. This study presents a structured framework for quantifying uncertainty in intermodal freight transportation (IFT) optimization. The framework evaluates how input uncertainty affects system performance and reliability, a critical need for ensuring that model-based decisions remain robust under real-world variability, especially amid volatile fuel prices, shifting demand, and growing disruptions. It integrates three complementary methods: (1) Sobol-based global sensitivity analysis to identify influential parameters affecting cost, emissions, and transit time, (2) Monte Carlo-based capacity perturbation analysis to assess robustness under probabilistic facility disruptions, and (3) Monte Carlo filtering with Bayesian inference to detect threshold-based performance vulnerabilities. The results highlight diesel truck unit cost as the dominant driver of variability. To improve system resilience, planners should prioritize uncertainty in fuel-related parameters when designing intermodal strategies.

Intermodal freight transportation↗

RADAMS: Resilient and adaptive alert and attention management strategy against Informational Denial-of-Service (IDoS) attacks

Attacks exploiting human attentional vulnerability have posed severe threats to cybersecurity. In this work, we identify and formally define a new type of proactive attentional attacks called Informational Denial-of-Service (IDoS) attacks that generate a large volume of feint attacks to overload human operators and hide real attacks among feints. Here, we incorporate human factors (e.g., levels of expertise, stress, and efficiency) and empirical psychological results (e.g., the Yerkes-Dodson law and the sunk cost fallacy) to model the operators’ attention dynamics and their decision-making processes along with the real-time alert monitoring and inspection. To assist human operators in dismissing the feints and escalating the real attacks timely and accurately, we develop a Resilient and Adaptive Data-driven alert and Attention Management Strategy (RADAMS) that de-emphasizes alerts selectively based on the abstracted category labels of the alerts. RADAMS uses reinforcement learning to achieve a customized and transferable design for various human operators and evolving IDoS attacks. The integrated modeling and theoretical analysis lead to the Product Principle of Attention (PPoA), fundamental limits, and the tradeoff among crucial human and economic factors. Experimental results corroborate that the proposed strategy outperforms the default strategy and can reduce the IDoS risk by as much as 20%. Besides, the strategy is resilient to large variations of costs, attack frequencies, and human attention capacities. We have recognized interesting phenomena such as attentional risk equivalency, attacker’s dilemma, and the half-truth optimal attack strategy.

97 MATHEMATICS AND COMPUTING↗

Integrated Water-Power System Resilience Analysis in a Southeastern Idaho Irrigation District: Minidoka Case Study

This study investigates the joint water–power system resilience of an irrigation district in southeastern Idaho. Irrigation districts face difficulties in the delivery of water to farmers under drought conditions, during equipment failures, or unplanned infrastructure disruptions. The resilience of interconnected water and power systems can be better analyzed and understood through an integrated approach, using a model that connects the dependencies between the two halves of the system. Using a multi-agent system model capturing both water and power system components, as well as their linkages, we capture the interdependencies of these systems and highlight opportunities for improvement when faced with disruptions. Through simulation scenarios, we examine the system resilience using system performance, quantified as the percentage of met demand of the power and water system, when subjected to drought water year, an unforeseen water demand increase, power outage and dam failure. Scenario results indicate that the effects of low flow years are mostly felt in the power system; unexpected increases in water demand marginally impact irrigation system performance; dams and pumps present vulnerabilities of the system, causing substantial unmet demand during disruptions. Noting the interdependencies between the water–power system halves while leveraging an integrated simulation allows for an insightful analysis of the system impacts during disruptions.

13 HYDRO ENERGY↗

Convex Relaxations of Maximal Load Delivery for Multi-Contingency Analysis of Joint Electric Power and Natural Gas Transmission Networks

Recent increases in gas-fired power generation have engendered increased interdependencies between natural gas and power transmission systems. These interdependencies have amplified existing vulnerabilities in gas and power grids, where disruptions can require the curtailment of load in one or both systems. Although typically operated independently, coordination of these systems during severe disruptions can allow for targeted delivery to lifeline services, including gas delivery for residential heating and power delivery for critical facilities. To address the challenge of estimating maximum joint network capacities under such disruptions, we consider the task of determining feasible steady-state operating points for severely damaged systems while ensuring the maximal delivery of gas and power loads simultaneously, represented mathematically as the nonconvex joint Maximal Load Delivery (MLD) problem. To increase its tractability, we present a mixed-integer convex relaxation of the MLD problem. Then, to demonstrate the relaxation’s effectiveness in determining bounds on network capacities, exact and relaxed MLD formulations are compared across various multi-contingency scenarios on nine joint networks ranging in size from 25 to 1191 nodes. The relaxation-based methodology is observed to accurately and efficiently estimate the impacts of severe joint network disruptions, often converging to the relaxed MLD problem’s globally optimal solution within ten seconds.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Machine Learning-based Intrusion Detection for Smart Grid Computing: A Survey

Machine learning (ML)-based intrusion detection system (IDS) approaches have been significantly applied and advanced the state-of-the-art system security and defense mechanisms. In smart grid computing environments, security threats have been significantly increased as shared networks are commonly used, along with the associated vulnerabilities. However, compared to other network environments, ML-based IDS research in a smart grid is relatively unexplored, although the smart grid environment is facing serious security threats due to its unique environmental vulnerabilities. In this article, we conducted an extensive survey on ML-based IDS in smart grids based on the following key aspects: (1) The applications of the ML-based IDS in transmission and distribution side power components of a smart power grid by addressing its security vulnerabilities; (2) dataset generation process and its usage in applying ML-based IDSs in the smart grid; (3) a wide range of ML-based IDSs used by the surveyed papers in the smart grid environment; (4) metrics, complexity analysis, and evaluation testbeds of the IDSs applied in the smart grid; and (5) lessons learned, insights, and future research directions.

SCADA↗

Adapting Traditional Hazards Analysis Methods to Address Cyber Risks

Traditional hazards analysis (HA) methods, originally developed to address physical and operational risks, often fall short when it comes to identifying and mitigating cyber threats. These cyber threats pose unique and evolving risks to critical infrastructure and industrial control systems (ICS). This report explores the integration of Cyber-Informed Engineering (CIE) principles into existing HA methods to enhance their ability to address cyber-induced risks. CIE provides organizations with a practical, cost-effective approach to closing the gap between traditional HA methods and the need for cyber risk mitigation. By leveraging existing safety processes and controls, CIE allows users to examine and mitigate cyber vulnerabilities without overhauling existing HA methods. This report identifies areas where HA and CIE naturally align and where their approaches diverge. It emphasizes how CIE principles can be used to adapt HA methods, broadening their scope to include cyber risks and enabling the mitigation of cyber- induced impacts alongside traditional hazards and failure scenarios. This report examines how CIE can be applied across various HA methods—such as Hazard and Operability Studies (HAZOP), Probabilistic Risk Assessment (PRA), Failure Modes and Effects Analysis (FMEA), Systems-Theoretic Process Analysis (STPA), Hazard and Consequence Analysis for Digital Systems (HAZCADS), and Layers of Protection Analysis (LOPA). It provides strategies for integrating CIE to strengthen the identification, assessment, and mitigation of cyber-induced risks. The findings offer a structured entry point for organizations to embed CIE concepts into hazards and safety analyses, as well as broader engineering processes, ultimately supporting the design and operation of a more resilient infrastructure.

42 ENGINEERING↗