Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “data security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 181 records · Page 10

United States Nuclear Power Reactor Used Nuclear Fuel Database and Applications

The Unified Database (UDB) within STANDARDS serves as the foundational data infrastructure for managing the United States' spent nuclear fuel inventory of 315,111 discharged assemblies totaling 91,036 metric tons of heavy metal. The database organizes this complex inventory through over 200 interconnected tables structured into eight primary attribute categories, supporting integrated analyses across storage, transportation, and disposal domains. Data enters the UDB through the GC-859 Nuclear Fuel Data Survey, which transitioned to web-based collection in 2023, improving data quality through real-time validation. The UDB enables automated generation of input files for nuclear safety analyses, reducing preparation time from weeks to hours while maintaining traceability. Applications include national inventory reporting, Certificate of Compliance assessments, and facility optimization. The three-tier distribution model balances accessibility with security requirements for federal agencies, national laboratories, and research organizations. The UDB provides essential data infrastructure as spent fuel management transitions from site-specific to integrated national campaigns.

Stefanovic, Peter↗

Predicting multiphase flow and tracer transport for an underground chemical explosive test

Detecting radionuclide gas seepage from clandestine underground nuclear tests is central to nonproliferation explosion monitoring research. Yet, early-time (<6 day) gas transport driven by the explosive pressure wave remains poorly constrained due to scarcity of field data. We simulate multi-phase gas transport in the vadose zone using pre-shot data from a recent chemical explosion in P-Tunnel at the Nevada National Security Site, USA. Despite using a simplified 2D-radial model, predictions of tracer arrival matched observations within one order-of-magnitude. Our results show how transient blast forcing rapidly mobilizes gases from the cavity into surrounding rock – critical for optimizing sensor placement and test planning. This unique integration of field data and modeling represents a significant improvement in our ability to predict gas migration from underground explosions. More broadly, it offers insights into the coupled dynamics of pressure waves and contaminant transport in the vadose zone, with implications for monitoring and hazard assessment.

54 ENVIRONMENTAL SCIENCES↗

Advanced Simulation and Computing: FY25 Implementation Plan

The DOE National Nuclear Security Administration (NNSA) Stockpile Stewardship Program (SSP) is an integrated technical program for maintaining the safety, security, and reliability of the U.S. nuclear stockpile. The SSP incorporates nuclear test data, computational modeling and simulation, and experimental facilities to advance understanding of nuclear weapons. The suite of data analyzed comes from activities including previous nuclear tests, stockpile surveillance, experimental research, and development and engineering programs. This integrated national program requires the continued use of experimental facilities and the computational capabilities to support the SSP missions. These component parts, in addition to an appropriately scaled production capability, enable NNSA to support stockpile requirements. The ultimate goal of the SSP, and thus of the Advanced Simulation and Computing (ASC) program, is to ensure that the U.S. maintains a safe, secure, and effective strategic deterrent.

97 MATHEMATICS AND COMPUTING↗

Evaluating lightweight unsupervised online IDS for masquerade attacks in CAN

Vehicular controller area networks (CANs) are susceptible to masquerade attacks by malicious adversaries. In masquerade attacks, adversaries silence a targeted ID and then send malicious frames with forged content at the expected timing of benign frames. As masquerade attacks could seriously harm vehicle functionality and are the stealthiest attacks to detect in CAN, recent work has devoted attention to compare frameworks for detecting masquerade attacks in CAN. However, most existing works report offline evaluations using CAN logs already collected using simulations that do not comply with the domain’s real-time constraints. Here we contribute to advance the state of the art by presenting a comparative evaluation of four different non-deep learning (DL)-based unsupervised online intrusion detection systems (IDS) for masquerade attacks in CAN. Our approach differs from existing comparative evaluations in that we analyze the effect of controlling streaming data conditions in a sliding window setting. In doing so, we use realistic masquerade attacks being replayed from the ROAD dataset. We show that although evaluated IDS are not effective at detecting every attack type, the method that relies on detecting changes in the hierarchical structure of clusters of time series produces the best results at the expense of higher computational overhead. We discuss limitations, open challenges, and how the evaluated methods can be used for practical unsupervised online CAN IDS for masquerade attacks.

Anomaly detection↗

TrustDER: Trusted, Private and Scalable Coordination of Distributed Energy Resources

In this project, the Stanford and SLAC Teams have developed a Trusted, Private and Scalable platform for coordinating Coordination of Distributed Energy Resources (TrustDER). This is a layered system that ensures private, trusted and scalable coordination and monitoring of DERs. It accommodates a variety of resources, such as solar generation, gensets and loads, with a particular focus on battery systems-based resources, as they are a transformational technology experiencing fast growth in adoption by large critical facilities. The platform can be used as standalone or added to existing aggregation systems to enable trust, privacy and resilience. TrustDER consists of layers that address each of the shortcomings of the existing state of the art. Each layer in the platform can operate independently but provides information to the layers above it to enable a novel form of overall coordination architecture. The project consists of several tasks, with each task dedicated to the design of each layer. Task 2 Resource Virtualization defined a software abstraction layer for distributed energy resources (DERs). The goal of this abstraction was to simplify the implementation of algorithms utilizing cooperation of DERs resources in a variety of use cases. Task 3 is on Secure ID for Asset Authentication. Identity Management Systems (IDMS) are a foundational infrastructure for interactions between entities (organizations, users, devices, and services). Secure ID is blockchain-based a distributed identity management system allowing (1) identity provisioning, (2) authentication, (3) authorization, and (4) identity data sharing for IoT-enabled assets on the electricity grid. In this project, the SLAC team focused on designing and testing Keymaker, a protocol for authenticating device identity managed by Secure ID. Task 5 Private and Safe Integration is focused on the design and evaluation of a DER cooperation scheme which allows for the aggregation of DERs without impacting network reliability. The approach is designed based on realistic assumptions regarding data availability, communication infrastructure limitations, and privacy. Task 6 Scalable Distributed Privacy for Information explored how virtualized batteries could be managed privately. Specifically, it examined the case in which a principal provides a partitioned battery to multiple clients. Task 7 Use Cases was to ensure that this technology was applied in relevant situations and scenarios. Primarily, this means that virtualization needed to be employed in a manner that either improved flexibility, bolstered security or privacy, or decreased costs.

25 ENERGY STORAGE↗

Multi-Semester Mentoring and GPA Trajectories in SPINS: A Longitudinal Program Evaluation of STEM Scholars

This exploratory longitudinal program evaluation examined GPA trajectories among 14 STEM scholars participating in the Scholarly Partnership in Nuclear Security (SPINS) mentoring program at an HBCU. Using de-identified administrative data (37 scholar-semester observations), the study compared baseline and latest term GPAs anchored to each scholar’s first funded semester. A Wilcoxon signed-rank test was used to assess within-student change. Mean GPA increased modestly from 3.46 (SD = 0.30) at baseline to 3.61 (SD = 0.33) at the latest observed semester, with 12 of 14 scholars (85.7%) showing net improvement (median change = +0.12). The Wilcoxon signed-rank test indicated a statistically significant positive shift (W = 18, p = 0.030). However, scholars entered the program with a high baseline GPA, and ceiling effects were evident for several participants. Grounded in Social Cognitive Career Theory, findings suggest that multi-semester participation in SPINS is associated with GPA stability and modest improvement in an already high-performing cohort. Results should be interpreted cautiously given the small sample size and single-group design. The study highlights the value of sustained, culturally responsive mentoring at an HBCU while underscoring the need for larger evaluations with comparison cohorts and broader psychosocial outcomes. An evidence-informed mentoring framework is proposed to strengthen multi-semester support.

42 ENGINEERING↗

Data Centers and Digital Assurance Workshop 2 – Prioritizing Digital Assurance Challenges, Session 2

The second session of the TADA (Technical Assistance for Digital Assurance) Data Centers Cohort, held on November 10, 2025, focused on prioritizing digital assurance challenges at the intersection of data centers and the electric grid. Building on the foundational concepts introduced in Workshop 1, this session deepened the application of the Threat–Vulnerability–Consequence (TVC) framework and emphasized the urgency of addressing cybersecurity, supply chain integrity, and operational reliability. Participants explored the growing convergence of digital and physical systems, the expanding attack surface due to global supply chain dependencies, and the implications of AI-driven load behavior. Real-world incidents—including the Volt Typhoon campaign and vulnerabilities in Solarman and Deye platforms—were analyzed to illustrate the risks of unpatched systems, insecure APIs, and inadequate vendor oversight. Key themes included architecture and interface weaknesses, governance gaps, and human and procedural shortcomings. The workshop also examined the evolving regulatory landscape, highlighting new federal mandates around Foreign Entity of Concern (FEOC) compliance and large-load reliability standards. Through interactive exercises, stakeholders ranked and mapped digital assurance risks from their respective perspectives—utilities, operators, and vendors—laying the groundwork for mitigation strategies and shared accountability models to be developed in Workshop 3. Session 2 of 3.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

DICER: A new instrument at LANSCE to constrain neutron capture rates on radionuclides

With very few exceptions, direct measurements of neutron capture rates on radionuclides have not been possible. A number of indirect methods have been pursued such as the surrogate method, the γ-ray strength function method, the Oslo method and the β-Oslo method. Substantial effort has been devoted to quantify the usually large systematic errors that accompany the results from these techniques. A new instrument has been developed at the Los Alamos Neutron Science Center (LANSCE) to provide more accurate data on several radionuclides relevant to nuclear criticality safety, radiochemical diagnostics, astrophysics, nuclear forensics and nuclear security, by measuring the transmission of neutrons through radioactive samples and studying resonance properties. The Device for Indirect Capture on Radionuclides (DICER) and associated radionuclide production at the Isotope Production Facility (IPF), both at LANSCE, as well radioactive sample fabrication, have been under development the last few years. A description of the new apparatus, data on a few mid-weight stable isotopes and efforts on radionuclide measurements will be presented.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

DICER: A new instrument at LANSCE to constrain neutron capture rates on radionuclides

. With very few exceptions, direct measurements of neutron capture rates on radionuclides have not been possible. A number of indirect methods have been pursued such as the surrogate method, the γ-ray strength function method, the Oslo method and the β-Oslo method. Substantial effort has been devoted to quantify the usually large systematic errors that accompany the results from these techniques. A new instrument has been developed at the Los Alamos Neutron Science Center (LANSCE) to provide more accu rate data on several radionuclides relevant to nuclear criticality safety, radiochemical diagnostics, astrophysics, nuclear forensics and nuclear security, by measuring the transmission of neutrons through radioactive samples and studying resonance properties. The Device for Indirect Capture on Radionuclides (DICER) and as sociated radionuclide production at the Isotope Production Facility (IPF), both at LANSCE, as well radioactive sample fabrication, have been under development the last few years. A description of the new apparatus, data on a few mid-weight stable isotopes and efforts on radionuclide measurements will be presented.

Nuclear Criticality Safety Program (NCSP)↗

Unraveling the Noise: An Investigation Plan for Signal Interference in Hearing Aids

Bluetooth Low Energy (BLE) has revolutionized the performance of hearing aids with functionalities like seamless audio streaming and enhanced auditory functions. However, BLE operates within the highly congested 2.4 GHz frequency band, making it susceptible to signal interference that can degrade performance, reduce audio quality, and impact user experience. This paper documents interference patterns in BLE communication and introduces practical mitigation techniques aimed at improving the reliability of hearing aids. Attack vectors associated with Bluetooth enabled hearing aids include communication jamming, the interception of data between target devices, and GATT handle exploitation. Attackers could also use the vulnerabilities to block communications or intercept sensitive audio streams, posing significant security and privacy risks. These threats compromise two critical components of the CIA triad: (1) availability, by causing persistent connectivity issues, and (2) integrity, by enabling unauthorized data modifications. It is necessary to deal with these problems to ensure hearing aids work well and safely. This study investigates the impact of BLE signal interference on hearing aids, using tools such as HackRF [1], a Python tool to simulate interference scenarios, and Ubertooth [2] to sniff Bluetooth traffic between hearing aids and the device with the application. This paper investigates testing of BLE traffic in search of specific interference patterns that would impact the functionality of hearing aids, including jamming and flooding. This research focuses on developing robust mitigation techniques with the aim of securing BLE-enabled hearing aids against those vulnerabilities.

Baldwin, David [Savannah River National Laboratory↗

AI-based Cyber Event OSINT via Twitter Data

Open-Source Intelligence (OSINT) is largely regarded as a necessary component for cybersecurity intelligence gathering to secure network systems. With the advancement of artificial intelligence (AI) and increasing usage of social media, like Twitter, we have a unique opportunity to obtain and aggregate information from social media. In this study, we propose an AI-based scheme capable of automatically pulling information from Twitter, filtering out security-irrelevant tweets, performing natural language analysis to correlate the tweets about each cybersecurity event (e.g., a malware campaign), and validating the information. This scheme has many applications, such as providing a means for security operators to gain insight into ongoing events and helping them prioritize vulnerabilities to deal with. To give examples of the possible uses, we present three case studies demonstrating the event discovery and investigation processes.

Dale, Dakota↗

Open Source Intelligence for Cybersecurity Events via Twitter Data

Open-Source Intelligence (OSINT) is largely regarded as a necessary component for cybersecurity intelligence gathering to secure network systems. With the advancement of artificial intelligence (AI) and increasing usage of social media, like Twitter, we have a unique opportunity to obtain and aggregate information from social media. In this study, we propose an AI-based scheme capable of automatically pulling information from Twitter, filtering out security-irrelevant tweets, performing natural language analysis to correlate the tweets about each cybersecurity event (e.g., a malware campaign), and validating the information. This scheme has many applications, such as providing a means for security operators to gain insight into ongoing events and helping them prioritize vulnerabilities to deal with. To give examples of the possible uses, we present three case studies demonstrating the event discovery and investigation processes. We also examine the potential of OSINT for identifying the network protocols associated with specific events, which can aid in the mitigation procedures by informing operators if the vulnerability is exploitable given their system’s network configurations.

Dale, Dakota↗

Implementation and Demonstration of the Digital Twin Certification System Remote Operations Framework

Microreactors are one promising advanced-reactor concept being pursued by the nuclear industry. They are distinguished by a relatively low power output of 20 MWth or less. These microreactors are intended for deployment in applications where conventional small-capacity power solutions, such as diesel generators, are either economically unfeasible or logistically challenging. Such applications include providing electric power and/or heat for remote communities, mining sites, defense installations, and humanitarian and disaster-relief missions. An important feature for the successful deployment of microreactors is their capability to be operated remotely. This capability can significantly reduce staffing costs by eliminating the need for licensed operators to be physically present at each reactor site. Instead, operators can be centralized in a single remote operations center placed in an economically advantageous location, thereby optimizing resources by consolidating expertise and enhancing operational efficiency. However, the implementation of a remote operation system for nuclear reactors raises new concerns regarding the security, reliability, and resilience of such a system. One way in which remote operations can be supported in a manner that maintains system security, reliability, and resilience is through the use of digital twins in a novel framework designed to verify and validate sensor data and commands communicated between the remote operations center and reactor. This framework, known as the Digital Twin Certification System (DTCS), has previously been proposed as an operations architecture that can bring security and resiliency levels of remote nuclear-reactor operations to a level acceptable for commercial deployment. This paper moves the proposed DTCS architecture from concept to reality by presenting the implementation and testing of the system. The rationale and implementation of the DTCS using tools such as DeepLynx and Apache Airflow, is covered in-depth. This is followed by a demonstration of the DTCS by applying the implemented system architecture to the Single Primary Heat Extraction and Removal Emulator, a small-scale non-nuclear test bed that emulates thermal behavior of a microreactor. The demonstration includes both normal and abnormal operating scenarios to highlight how the DTCS can increase the security, reliability, and resilience of a remote operations system.

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

Implementation and Demonstration of the Digital Twin Certification System Remote Operations Framework

Microreactors are one promising advanced-reactor concept being pursued by the nuclear industry. They are distinguished by a relatively low power output of 20 MWth or less. These microreactors are intended for deployment in applications where conventional small-capacity power solutions, such as diesel generators, are either economically unfeasible or logistically challenging. Such applications include providing electric power and/or heat for remote communities, mining sites, defense installations, and humanitarian and disaster-relief missions. An important feature for the successful deployment of microreactors is their capability to be operated remotely. This capability can significantly reduce staffing costs by eliminating the need for licensed operators to be physically present at each reactor site. Instead, operators can be centralized in a single remote operations center placed in an economically advantageous location, thereby optimizing resources by consolidating expertise and enhancing operational efficiency. However, the implementation of a remote operation system for nuclear reactors raises new concerns regarding the security, reliability, and resilience of such a system. One way in which remote operations can be supported in a manner that maintains system security, reliability, and resilience is through the use of digital twins in a novel framework designed to verify and validate sensor data and commands communicated between the remote operations center and reactor. This framework, known as the Digital Twin Certification System (DTCS), has previously been proposed as an operations architecture that can bring security and resiliency levels of remote nuclear-reactor operations to a level acceptable for commercial deployment. This paper moves the proposed DTCS architecture from concept to reality by presenting the implementation and testing of the system. The rationale and implementation of the DTCS using tools such as DeepLynx and Apache Airflow, is covered in-depth. This is followed by a demonstration of the DTCS by applying the implemented system architecture to the Single Primary Heat Extraction and Removal Emulator, a small-scale non-nuclear test bed that emulates thermal behavior of a microreactor. The demonstration includes both normal and abnormal operating scenarios to highlight how the DTCS can increase the security, reliability, and resilience of a remote operations system.

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

Enhancing Cloud Cybersecurity: Prescriptive Controls for Operational Technology

This whitepaper provides strategic insights and recommendations into security cloud-based solutions for electric utilities, encompassing operational technology (OT), virtual power plants (VPP), distributed energy resources (DERs), applications, networks, and data storage as they transition to and leverage cloud infrastructure through managed service providers (MSPs) and cloud service providers (CSPs). Principles derived from established frameworks serve as a foundation for best practices across cybersecurity projects and remove the constraints of settling on a single framework. For organizations that prefer not to integrate a specific framework altogether, elements of the proposed approach could be adopted or tailored to best fit defined requirements and expected functionalities. The Cirrus assessment, a utility cloud feasibility tool, and the roadmap it provides serve as a precursor to this paper, which seeks to be a valuable resource for defining next steps following cloud technology integration feasibility appraisal. With its comprehensive approach to adoption, the Cirrus framework offers strategic guidance on responsibly preparing for or deploying a utility cloud solution. The previously published whitepaper, “Use Case-Informed Framework for Utility Cloud Migration,” details the guiding strategy, research, and deployment of cloud solutions within electric and interconnected grid systems. Before implementing the controls suggested in this document, it is recommended that stakeholders complete Cirrus's cloud integration assessment and pair the results with their unique cybersecurity controls to form a comprehensive cloud-based utility cybersecurity plan. The Cirrus outcome will consider a series of future architectures for the grid before and after the energy transition and evaluate the arguments for and against cloud applications for each electric and interconnected grid layer. This document is a companion to the original whitepaper, "Use Case-Informed Framework for Utility Cloud Migration" to further identify and recommend security controls based on Cirrus’s cloud integration assessment output. The following whitepaper outlines the cybersecurity controls that secure cloud-service models pertinent to the electric sector using the predefined categories identify, protect, detect, and respond and recover. The objective is to outline prescriptive security controls based on the type of architecture and data stored in the cloud. The focus includes dissecting the shared responsibility model and elucidating what on-premises Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) entail. A pivotal consideration in this context is allocating responsibility for foundational cybersecurity aspects—having used Cirrus for the cloud integration assessment. The ensuing controls detailed herein also represent a checklist of controls necessary for a secure cloud transition, equipping utilities with the knowledge to navigate this digital transformation with confidence and strategic foresight in a safe and responsible manner.

42 ENGINEERING↗

Closure Report for Corrective Action Unit 572: Test Cell C Ancillary Building and Structures, Nevada National Security Site, Nevada, Revision 0

The purpose of this CR is to provide documentation supporting the completed corrective actions and data confirming that the closure objectives for CAU 572 were met. To achieve this, the following actions were performed: • Corrective action investigation (CAI) activities were performed from August 2020 through May 2023, as set forth in the SAFER Plan for CAU 572; and in accordance with the Soils Activity Quality Assurance Plan, which establishes requirements, technical planning, and general quality practices. • Corrective actions were completed during decontamination and demolition (D&D) and disposal activities, and were performed from August 2022 through September 2025.

54 ENVIRONMENTAL SCIENCES↗

Detecting Unclassified Electromagnetic Signals for Secure Wireless Communication Using Open Set Recognition

We developed multiple machine learning methods for the detection and classification of new wireless communication waveforms, which is critical for targeted attacks in wireless networks and electronic warfare. Our machine learning models are capable of dynamically detecting security threats in near real time through our advanced open set recognition (OSR) approach. This model has demonstrated significant improvements in the detection of unknown waveforms, thereby enhancing the security and reliability of mission critical communications. Our approach to detecting uncertain security threats is novel; we advanced OSR techniques by incorporating domain knowledge of wireless signals. Specifically, we combined time and frequency domain model features to enhance the model’s performance. Utilizing an OSR approach eliminates the need for training data to be distributed similarly to the deployment environment and removes the requirement for the training set to contains all possible threat classes. This is crucial because it is often infeasible to determine and characterize all potential security threats in advance. Our model were trained on simulated data, generated in partnership with the University at Albany, State of New York. The data set contained a diverse array of wireless signals, including those with additive white Gaussian noise and multipath signals, with and without line of sight. This comprehensive training set allowed us to optimize our models to detect unknown waveforms under various challenging scenarios, such as low signal-to-noise ratios. By training on various waveforms, varying signal-to-noise ratio, and different sample sizes under normal conditions, our models were fine tuned to perform effectively in challenging environments.

99 - GENERAL AND MISCELLANEOUS↗