Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Cyber”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 199 records · Page 11

Cyber-Informed Engineering (CIE) Guide for States

The Cyber-Informed Engineering (CIE) Guide for States provides state energy offices, public utility commissions, and partner organizations with a structured framework for integrating cyber-resilient engineering practices into energy planning, grantmaking, interconnection processes, and workforce development. As grid digitalization and the adoption of distributed energy resources accelerate, states face expanding cyber-physical risks that traditional cybersecurity measures alone cannot fully address. CIE offers a proactive, consequence-focused engineering methodology that emphasizes eliminating or mitigating high-impact failure modes through design, physical controls, and operational safeguards. The guide outlines the 12 core CIE principles, demonstrates their application through state-focused use cases—including grant evaluation rubrics, interconnection reviews, allow-list development, and training programs—and provides practical tools such as scoring frameworks, impact assessment methods, and implementation checklists. It also highlights pathways for state–utility collaboration and opportunities for technical assistance from national laboratories. By adopting CIE, states can enhance grid reliability, reduce lifecycle costs, strengthen supply-chain assurance, and foster a security-aware engineering culture that aligns with broader resilience and modernization goals. November 2025

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Cyber-Informed Engineering (CIE) Guide for States

The Cyber-Informed Engineering (CIE) Guide for States provides state energy offices, public utility commissions, and partner organizations with a structured framework for integrating cyber-resilient engineering practices into energy planning, grantmaking, interconnection processes, and workforce development. As grid digitalization and the adoption of distributed energy resources accelerate, states face expanding cyber-physical risks that traditional cybersecurity measures alone cannot fully address. CIE offers a proactive, consequence-focused engineering methodology that emphasizes eliminating or mitigating high-impact failure modes through design, physical controls, and operational safeguards. The guide outlines the 12 core CIE principles, demonstrates their application through state-focused use cases—including grant evaluation rubrics, interconnection reviews, allow-list development, and training programs—and provides practical tools such as scoring frameworks, impact assessment methods, and implementation checklists. It also highlights pathways for state–utility collaboration and opportunities for technical assistance from national laboratories. By adopting CIE, states can enhance grid reliability, reduce lifecycle costs, strengthen supply-chain assurance, and foster a security-aware engineering culture that aligns with broader resilience and modernization goals. November 2025

29 - ENERGY PLANNING, POLICY AND ECONOMY↗

Cyber-Informed Engineering Briefing for ABET

Cyber-Informed Engineering (CIE) is an emerging method to integrate cybersecurity considerations into the conception, design, development, and operation of any physical system, energy or otherwise, to mitigate or even eliminate avenues for cyber-enabled attacks.?CIE concepts use design decisions and engineering controls to prioritize defense against the worst possible consequences of cyberattacks facing critical infrastructure systems and asset owners. These slides offer a deep dive into Cyber-Informed Engineering for engineering educators.

42 - ENGINEERING↗

Machine Learning Based Resilience Testing of an Address Randomization Cyber Defense

Moving target defenses (MTDs) are widely used as an active defense strategy for thwarting cyberattacks on cyber-physical systems by increasing diversity of software and network paths. Recently, machine Learning (ML) and deep Learning (DL) models have been demonstrated to defeat some of the cyber defenses by learning attack detection patterns and defense strategies. It raises concerns about the susceptibility of MTD to ML and DL methods. Here, in this article, we analyze the effectiveness of ML and DL models when it comes to deciphering MTD methods and ultimately evade MTD-based protections in real-time systems. Specifically, we consider a MTD algorithm that periodically randomizes address assignments within the MIL-STD-1553 protocol—a military standard serial data bus. Two ML and DL-based tasks are performed on MIL-STD-1553 protocol to measure the effectiveness of the learning models in deciphering the MTD algorithm: 1) determining whether there is an address assignments change i.e., whether the given system employs a MTD protocol and if it does 2) predicting the future address assignments. The supervised learning models (random forest and k-nearest neighbors) effectively detected the address assignment changes and classified whether the given system is equipped with a specified MTD protocol. On the other hand, the unsupervised learning model (K-means) was significantly less effective. The DL model (long short-term memory) was able to predict the future addresses with varied effectiveness based on MTD algorithm's settings.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Integrating Cyber-Informed Engineering into Enterprise Risk Management

This document supports the application of Cyber-Informed Engineering (CIE) within the context of Enterprise Risk Management (ERM) to enhance cyber-resilience. It highlights that many critical infrastructure organizations use ERM to manage business risks and emphasizes the importance of evaluating critical systems and assets. The proposed approach can be adopted independently of formal ERM processes and offers a starting point for integrating CIE alongside existing or new ERM practices. Both CIE and ERM are iterative, and their alignment fosters continuous improvement and supports the engineering and operations cultures of an organization.

42 ENGINEERING↗

Cyber-physical security framework for Photovoltaic Farms

With the evolution of PV converters, a growing number of vulnerabilities in PV farms are exposing to cyber threats. To mitigate the influence of cyber-attack on PV farms, it is necessary to study attacks' impact and propose detection methods. To meet this requirement, a cyber-physical security framework is proposed for PV farms. Data integrity attacks (DIAs) are studied on different control loops. As μPMU is gaining in popularity, a lower sampling rate of μPMU data is applied to develop a detection algorithm. We have evaluated two data-driven methods, which are support vector machine (SVM) and long short-term memory (LSTM). Lastly, the data-driven methods verify the feasibility of μPMU data in attack detection.

Attack Impact Analysis↗

A Robust Method to Secure Multi-Inverter Grid Tied PV and Battery Energy Storage Systems Against Cyber Intrusions

This paper details a robust method to secure a multi-inverter grid tied system that interfaces photovoltaic (PV) and battery energy storage against potential cyber-attacks. The method can be applied to any third-party inverter systems without a need to modify their internal controls. A small random private excitation signal termed "watermark" is injected into the DC input voltage terminals (via a series transformer) connected to the PV/battery inverter system. An external robust cyber intrusion detector (CID) hardware consisting of a digital signal processor (DSP) generates the "watermark" and also receives the sensor signals that control the setpoints of the PV/battery grid tied system. The CID algorithm is shown to detect all possible cyber intrusions (such as false data injection(FDI)) on external sensor signals such as P and Q measured by a smart meter that control the overall system operation. The proposed CID computes online system ID and two variance tests in real time on each sensor signal and is able pinpoint intrusion location in a multi-inverter system. Results on a hardware in the loop (HIL) of a two-inverter grid connected system demonstrate effectiveness of the proposed CID system for FDI and unobservable FDI. Test results on a laboratory prototype will be discussed in the conference presentation.

Ibrahim, Hasan↗

Machine Learning-based Cyber-Physical Anomaly Detection in Wide Area Voltage Control Systems

Wide-area voltage control systems (WAVCS) are widely deployed in power grid to improve the voltage stability in transmission system using Flexible AC Transmission System (FACTS) devices. The WAVCS relies on wide-area measurement and control signals for closed-loop control of FACTS devices to improve the transient voltage stability in power grid in real-time. Since the WAVCS utilizes a cyber-layer communication during its normal operation, they are susceptible to cyber attacks from adversaries which can lead to a voltage collapse if the attacks go undetected and unmitigated. This paper proposes a supervised machine learning (ML)-based anomaly detection algorithm for detecting various stealthy cyber attacks in the context of WAVCS cybersecurity. In particular, a fuzzy logic-based wide-area controller, as proposed by the Bonneville Power Administration (BPA), is implemented on the Kundur’s four machine two-area system that is integrated with a static var compensator (SVC) to improve voltage profile on sensitive buses. Later, different types of data integrity attacks, including pulse and ramp attacks, are considered on the wide-area measurement and control signals to analyze the performance of the proposed anomaly detector. Our experimental evaluation shows a promising performance with a high true-positive rate (more than 99%) and low false-negative rate (less than 1%) while exhibiting a small prediction time.

24 POWER TRANSMISSION AND DISTRIBUTION↗

A Cryptographic Method for Defense Against MiTM Cyber Attack in the Electricity Grid Supply Chain

Critical infrastructures such as the electricity grid can be severely impacted by cyber-attacks on its supply chain. Hence, having a robust cybersecurity infrastructure and management system for the electricity grid is a high priority. This paper proposes a cyber-security protocol for defense against man-in-the-middle (MiTM) attacks to the supply chain, which uses encryption and cryptographic multi-party authentication. A cyber-physical simulator is utilized to simulate the power system, control system, and security layers. The correctness of the attack modeling and the cryptographic security protocol against this MiTM attack is demonstrated in four different attack scenarios.

Paul, Shuva↗

Cyber-Physical Power Systems Protection: The Byzantine Cybersecurity Framework

Cybersecurity of smart grids have been topic of much interest in recent years. As this critical infrastructure operation increases dependency on automated processes and controls, exposure to cyber-physical threats become inevitable. Considering cyber-physical security of the grid, much focus of attention has been made towards smart grids real-time monitoring solutions, including the state estimation process. Analyzing the relevant literature, one can note though that seldom research has been done on cyber-physical security of smart grids protection systems. Protection systems have intangible value towards grid reliability. This paper presents a cybersecurity framework for smart grids protection systems. A physics-based inspired machine learning solution is at the core process of the framework. Processed relay inputs and outputs are used by a deep predictive coding network. Formal models, a quasi-static state estimator, provides an oracle when low confidence decision is reached. Evolving knowledge is derived through reinforcement learning. Implementation aspects considering the Pacific Northwest National Laboratory Electricity Infrastructure Operations Center are presented. Built as an extra control layer to protection systems, without hard-to-derive parameters, highlights potential aspects towards real-life applications.

Bretas, Arturo Suman↗

Cyber Attack Sequences Generation for Electric Power Grid

Security assessment of cyber-physical energy systems (CPESs) such as the electric power grid is a critical operation to maintain availability, reliability, and quality of service in the presence of persistent threats from malicious cyber actors. Existing security assessment approaches such as penetration testing and red teaming rely on subject matter expert experience and forensic cyber analysis of historical events to perform realistic, threat-informed assessments of CPES defense. CPESs have a large attack surface because of the heterogeneity and complexity of underlying topology, devices, measurements, and vulnerabilities. The aforementioned approaches lead to partial coverage of the attack surface with a large set of unknown but possible exploits. There is a need to automate the CPES attack surface discovery and contextualize it for relevant, highly probable, real-world attack scenarios. We propose a methodology and framework to facilitate the discovery of the CPES attack surface. We present a multilayer attack graph with ranked attack sequences to describe CPES failure scenarios. We present a work-in-progress framework that lists key components to automate the attack modeling and sequence generation. We demonstrate the published National Electric Sector Cybersecurity Organization Resource CPES failure scenario to highlight the trustworthiness of generated attack sequences.

Dutta, Ashutosh↗

Online Dynamic Cyber-Attack Diagnosis in Power Electronics Systems Based on Few-Shot Learning

With increasing exposure to software-based sensing and control, power electronics systems are facing higher risks of cyber-physical attacks. To ensure system stability and minimize potential economic losses, it is critical to monitor the operating states and detect those attacks at the early stage. However, anomaly detection and diagnosis of attacks are still challenging, especially when labeled anomaly data is difficult or even infeasible to obtain. To overcome this problem, we propose a Few-Shot Learning (FSL) based approach for cyber-attack diagnosis leveraging the waveform data. To the best of our knowledge, this work is the first attempt at leveraging FSL for cyber-attack diagnosis in power electronics systems. Extensive experimental results demonstrate that our proposed approach can achieve comparable diagnosis accuracy with the state-of-the-art data-driven methods using less than 0.04% of the training samples.

Li, Qi↗

Guest Editorial: Special section on Resilient Control of Cyber-Physical Power and Energy Systems

Our power and energy systems are becoming more and more integrated and interconnected. The increasing integration of edge devices and dependence on cyber infrastructure provides both the potential for benefits and risks. The integration enables more dynamic and flexible control paradigms while at the same time increasing the cyberattack surface and uncertainty of behavior. Control methodology in this new world must be designed for resilience and must have the ability to withstand, react, and respond to both physical faults and cyber-induced threats. Finally, understanding system resilience under adverse conditions requires studying control performance and how cyber infrastructure can integrate with and support the overall resilience of the system.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Automated Adversary-in-the-Loop Cyber-Physical Defense Planning

Security of cyber-physical systems (CPS) continues to pose new challenges due to the tight integration and operational complexity of the cyber and physical components. To address these challenges, this article presents a domain-aware, optimization-based approach to determine an effective defense strategy for CPS in an automated fashion—by emulating a strategic adversary in the loop that exploits system vulnerabilities, interconnection of the CPS, and the dynamics of the physical components. Our approach builds on an adversarial decision-making model based on a Markov Decision Process (MDP) that determines the optimal cyber (discrete) and physical (continuous) attack actions over a CPS attack graph. The defense planning problem is modeled as a non-zero-sum game between the adversary and defender. We use a model-free reinforcement learning method to solve the adversary’s problem as a function of the defense strategy. We then employ Bayesian optimization (BO) to find an approximate best-response for the defender to harden the network against the resulting adversary policy. This process is iterated multiple times to improve the strategy for both players. We demonstrate the effectiveness of our approach on a ransomware-inspired graph with a smart building system as the physical process. Numerical studies show that our method converges to a Nash equilibrium for various defender-specific costs of network hardening.

97 MATHEMATICS AND COMPUTING↗

Advanced Computational Techniques for Improving Resilience of Critical Energy Infrastructure under Cyber-Physical Attacks

In this chapter, we present recent advances in improving the resilience of cyber-physical systems, especially with regards to energy systems. We provide discussions around various types of cyber-physical events that can cause disruptions and new advances in optimization, control, and reinforcement learning (RL) to deal with the challenges posed by such cyber-physical events. The presented methods range from distributed robust optimization, autonomous and coordinated control, reinforcement learning based resilient control and topology reconfiguration in Inter-System resilient control.

Nazir, Mohammad Nawaf [BATTELLE (PACIFIC NW LAB)]↗

U.S. and Allied Cyber Security Cooperation in the Indo-Pacific (Workshop Summary)

On March 30, 31, and April 1, 2021, the Center for Global Security Research (CGSR) at Lawrence Livermore National Laboratory (LLNL) hosted a workshop titled "U.S. and allied Cyber Security Cooperation in the Indo-Pacific". This session brought together participants drawn across the policy, military, and private sector in the United States and among allied countries in Europe and the Indo-Pacific. The workshop evaluated threat perceptions, assessed cyber power in a regional context, and explored opportunities for building capacity and trust with allies, partners, and the private sector. The region's cyber threat landscape is marked by increasing malicious activity, with threats persistent and ever-growing. Grounded by this strategic reality, the workshop advocated for 1) a concerted push into the arena of norm setting from the bottom up, 2) an agreed metric by which to assess progress, and 3) the creation of future lines of collaborative effort for the United States and its allies to ensure an open, interoperable, and secure internet.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Design and Development of a High Fidelity Cyber-Physical Testbed

In order to ensure that future critical infrastructure systems are resilient to various types of such advanced and persistent threats, it is important to develop and integrate tailored solutions that holistically address cyber-attack detection and mitigation in a timely manner such that adverse system impacts that impact a large population are avoided. Further, it is essential to create environments that allow control, protection and communication to exist within a realistic environment to analyze the effects of adverse conditions and system operating modes. This project aims to establish a high-fidelity testbed environment for modeling and simulating a single microgrid all the way up to a network of microgrids along with baseline controls, protection, and associated cyber communication. This is an important activity because accurately modeling and simulating the various power-electronics-based DERs and loads in a microgrid is critical to adequately capturing their behaviors over a wide range of off-normal conditions, as well as to evaluate the resilience of the system using the developed controls. The work presented in this report focuses on the process of building this high-fidelity testbed and the associated experimentation it enables. The model enables the creation of high-fidelity use cases and associated datasets that have been used extensively within the initiative to study resilience and support novel control development and prototyping. The work heavily leverages existing capability that is part of the high-fidelity cyber-physical system experimentation lab to create a power hardware-in-the-loop setup. The report also details the creation of an automated model building platform that can enable high-fidelity real-time models to be built without much effort allowing existing low-fidelity models to be analyzed in higher fidelity. Lastly, the report also discusses efforts center around scaling to large complex power system models to make the experimentation more effective.

97 MATHEMATICS AND COMPUTING↗

Modeling Communication Infrastructures of Cyber Physical Systems

This effort explores modeling cyber infrastructure, including communication devices like switches, routers, sensors, and controllers, and physical media attributes like propagation of radio signals, in coordination with power distribution system model layouts. To do this, the project studies real-world configurations to define axioms of how different communication media is deployed with control equipment. These axioms will be used to develop tools to generate realistic cyber infrastructure models from starting power system models. This effort leverages and builds on the co-simulation platform developed by the other RD2C projects. The axioms and tools will be validated and demonstrated with the NS3 simulation tool as part of a co-simulation to show the behavior/impacts of cyber infrastructure on control operations.

24 POWER TRANSMISSION AND DISTRIBUTION↗