Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “adversarial attack”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 199 records · Page 11

On the Abuse and Detection of Polyglot Files

A polyglot is a file that is valid in two or more formats. Polyglot files pose a problem for file-upload and generative AI web interfaces that rely on format identification to determine how to securely handle incoming files. In this work we found that existing file-format and embedded-file detection tools, even those developed specifically for polyglot files, fail to reliably detect polyglot files used in the wild. To address this issue, we studied the use of polyglot files by malicious actors in the wild, finding 30 polyglot samples and 15 attack chains that leveraged polyglot files. Using knowledge from our survey of polyglot usage in the wild---the first of its kind---we created a novel data set based on adversary techniques. We then trained a machine learning detection solution, PolyConv, using this data set. PolyConv achieves a precision-recall area-under-curve score of 0.999 with an F1 score of 99.20% for polyglot detection and 99.47% for file-format identification, significantly outperforming all other tools tested. We developed a content disarmament and reconstruction tool, ImSan, that successfully sanitized 100% of the tested image-based polyglots, which were the most common type found via the survey. Our work provides concrete tools and suggestions to enable defenders to better defend themselves against polyglot files, as well as directions for future work to create more robust file specifications and methods of disarmament.

Oesch, T [ORNL] (ORCID:0000000269091022)↗

Essence2.0 Development and Deployment (Final Report)

The objective of the project was to take two core technologies that have been developed under the Recipient’s solid laboratory products and integrate them into a single CyberPhysical awareness platform and complete development on current field-tested prototypes that will extend the integrated capability of the platform. During the final development phase, the Recipient development team and its selected industry partners tested and hardened the platform to ensure resilient and secure operation of the integrated platform. The team also executed substantial field testing and established the framework for defining the organization and/or commercial infrastructure needed to sustain operations and provide readiness for a national scale deployment. The focus of the project was (1) the improvement, refinement, and deployment of technology for the detection of cyber-attacks on utility operational technology (OT) and information technology (IT) networks and assets, including Supervisory Control and Data Acquisition Systems (SCADA) systems; and (2) support for containment and remediation of adversarial threats and actions against those systems and environments.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Bayesian Attack Model (BAM) User Story

This document presents a user story for the Bayesian Attack Model (BAM) tool designed to aggregate and analyze cyber-attack observables for operational technology (OT) systems. BAM aims to empower cybersecurity analysts by providing a streamlined interface for collecting observable data from various sources, enabling real-time analysis of potential adversary activity. By enhancing the response capabilities of security teams, BAM facilitates risk-informed decision-making and improves organizational security posture. This user story outlines the key functionalities, user interactions, and requirements necessary to successfully integrate BAM with other security information and event management (SIEM) technology and cybersecurity operations centers (CSOCs).

97 MATHEMATICS AND COMPUTING↗

Emulation and Adversarial Analysis of EV Charging Networks

In the effort of decarbonization and evolution of the modern electrical grid, electric vehicles (EVs) play a key part to transform the grid. However, due to the rapid adoption of EVs and the demand of the charging infrastructure required to power said EVs, risk of a cyber-attack may impose serious consequences. There is a need to analyze and protect the charging ecosystem infrastructure from cyber threats before it reaches wide-scale deployment. In an effort to secure vehicle to grid (V2G) communications, standardization is necessary for continued reliable system operation. The protocol ISO 15118 outlines controls and practices that should be implemented for secure vehicle to grid (V2G) communications. The standard is gaining momentum for American markets as the demand for EV infrastructure grows. The adoption of ISO 15118 in American markets poses several challenges: the deployment of a public key infrastructure (PKI) as outlined within the standard, interoperability of charging different EVs with chargers from different manufactures using the PKI, and scaling the ecosystem to meet the demand while managing risks. This project was created to understand potential cyber and scaling challenges of PKI for EV infrastructure through utilizing a series of emulated components mapping to what exists in the EV ecosystem today, and the components of the PKI that are under development. The key nodes within the emulation that are under development are: electric vehicle (EV), electric vehicle supply equipment (EVSE), charge network operator (CNO), certificate authority (CA), and online certificate status protocol (OCSP) that must all interact using secure and trusted communications. With these emulated components and utilizing orchestration methods to rapidly deploy and scale the components, the ability to analyze risks of the ecosystem and address gaps before the PKI ecosystem is fully deployed to production should yield a more robust and mature production charging infrastructure. Our approach will use a modular architecture of virtual machines within an orchestration platform and will target scales of 100s, 1000s, and 10,000s of entities interacting. The core research questions trying to be answered with this scope of work are: what are the impacts of a rogue CA, what are the risks of certificate revocation list (CRL) management, what is the value of OCSP stapling, what components are vulnerable to DOS attacks, and what test effective payloads may impact the components.

charging ecosystem↗

Maximum-impact Adversary Design for Network-based Control System: A Case Study on Grid-interactive Efficient Buildings

The Internet of Things (IoT) technology has dramatically improved the efficiency of today's building operation and management. By connecting controllable devices into a communication network, control signals can be easily passed to the devices, and operating status can be acquired from measurable ends with minimal effort. However, this all-connected configuration could also expose the network-based control system (NBCS) to malicious actions, such as cyberattacks. One of the common NBCSs is the building automation system. With the promotion of grid-interactive efficient buildings (GEBs), there has been increasing attention on securing the buildings from the network perspective. This research proposes a maximum-impact adversary design framework so that the adversary can provide the most adversarial impact on the controlled system while remaining stealthy. The proposed framework is numerically demonstrated on a network-based building energy and control system. The building energy system is built in a Modelica-based simulation environment and controlled by the state-of-the-art ASHRAE Guideline 36 control sequences. The control commands at the supervisory level, generated from the Guideline 36 controller, are assumed to be sent to local devices through communication networks using the BACnet protocol. Simulation results show that the proposed maximum-impact adversary on such a system can stealthily affect the building system's performance to its maximum extent. It is anticipated that results can be used by researchers and practitioners in the building automation industry to design efficient and robust cyber-attack detection algorithms, especially for stealthy attacks.

Chu, Mengyuan↗

Reinforcement Learning Approach to Cybersecurity in Space (RELACSS)

Securing satellite groundstations against cyber-attacks is vital to national security missions. However, these cyber threats are constantly evolving. As vulnerabilities are discovered and patched, new vulnerabilities are discovered and exploited. In order to automate the process of discovering existing vulnerabilities and the means to exploit them, a reinforcement learning framework is presented in this report. We demonstrate that this framework can learn to successfully navigate an unknown network and detect nodes of interest despite the presence of a moving target defense. The agent then exfiltrates a file of interest from the node as quickly as possible. This framework also incorporates a defensive software agent that learns to impede the attacking agents progress. This setup allows for the agents to work against each other and improve their abilities. We anticipate that this capability will help uncover unforeseen vulnerabilities and the means to mitigate them. The modular nature of the framework enables users to swap out learning algorithms and modify the reward functions in order to adapt the learning tasks to various use cases and environments. Several algorithms, viz., tabular Q learning, deep Q networks, proximal policy optimization, advantage actor-critic, generative adversarial imitation learning, are explored for the agents and the results highlighted. The agent learns to solve the tasks in a light-weight abstract environment. Once the agent learns to perform sufficiently well, it can be deployed in a minimega virtual machine environment (or a real network) with wrappers that map abstract actions to software commands. The agent also uses a local representation of the actions called a ‘slot-mechanism’. This allows the agent to learn in a certain network and generalize it to different networks. The defensive agent learns to predict the actions taken by an offensive agent and uses that information to anticipate the threat. This information can then either be used to raise an alarm or to take actions to thwart the attack. We believe that with the appropriate reward design, a representative environment, and action set, this framework can be generalized to tackle other cybersecurity tasks. By sufficiently training these agents, we can anticipate vulnerabilities leading to robust future designs. We can also deploy automated defensive agents that can help secure satellite groundstation and their vital national security missions.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Comparison of Socio-Technical Threat Models

Given the adoption of emerging technologies and the increasing complexity of managing such systems with a lifecycle much shorter than that of critical infrastructure systems, there is a practical need to be able to analyze sociotechnical dependencies and their associated evolving risks. Threat models based on social influence techniques can be used to implement adversarial tactics analogous to the cyber kill chain and attested to within the MITRE ATT&CK for ICS framework including Initial Access, Persistence, Collection, and Impact. Furthermore, as with cyber disruptions, the impact of social influence threat models can have an asymmetric impact that is not spatially-localized. Finally, unlike cyber attacks with a reasonably short duration (ransomware takes days to months), social influence based attacks have the potential to persist for much longer as they are based on long-term strategic infrastructure investments within the private sector. Given the increased importance of electric vehicle charging stations as a long-term, strategic infrastructure investment within the Energy and Transportation Sectors, we provide initial results that compare the impact of a Loss of Availability (T0826) realized through cyber and social influence based threat models. The analysis employs techniques from automated reasoning and measures of network complexity to understand evolving dominance of EV payment and charging networks within geographic region of interest. Within this context, we compare the impact of a loss of availability due to ransomware versus that of loss of support due to a merger and acquisition. Results across several different metro areas will be provided.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Systems and methods for detecting and mitigating cyber attacks on power systems comprising distributed energy resources

Extensive deployment of interoperable distributed energy resources (DER) on power systems is increasing the power system cybersecurity attack surface. National and jurisdictional interconnection standards require DER to include a range of autonomous and commanded grid-support functions which can drastically influence power quality, voltage, and the generation-load balance. Investigations of the impact to the power system in scenarios where communications and operations of DER are controlled by an adversary show that each grid-support function exposes the power system to distinct types and magnitudes of risk. The invention provides methods for minimizing the risks to distribution and transmission systems using an engineered control system which detects and mitigates unsafe control commands.

97 MATHEMATICS AND COMPUTING↗

Systems and methods for detecting and mitigating cyber attacks on power systems comprising distributed energy resources

Extensive deployment of interoperable distributed energy resources (DER) on power systems is increasing the power system cybersecurity attack surface. National and jurisdictional interconnection standards require DER to include a range of autonomous and commanded grid-support functions which can drastically influence power quality, voltage, and the generation-load balance. Investigations of the impact to the power system in scenarios where communications and operations of DER are controlled by an adversary show that each grid-support function exposes the power system to distinct types and magnitudes of risk. The invention provides methods for minimizing the risks to distribution and transmission systems using an engineered control system which detects and mitigates unsafe control commands.

Johnson, Jay Tillay↗

Proactive Intrusion Detection and Mitigation System

SAND2023-05661O The proactive intrusion detection and mitigation system (PIDMS) provides grid-edge situational awareness for cybersecurity defense by capturing real-time distributed energy resource (DER) network traffic and performance data with a novel approach that improves the detection and prevention of cyber-physical attacks. The PIDMS addresses the grid-edge security gap with real-time analysis of both network traffic and photovoltaic performance data to deliver a novel, cyber-physical intrusion detection system (IDS) approach that increases the accuracy and effectiveness of detection and mitigation. This hybrid IDS analysis enables dual monitoring that increases the workload of the adversary; both cyber and physical data would have to be simultaneously spoofed to evade detection. Furthermore, monitoring and analyzing cyber data are insufficient in some cases. For example, in an insider threat aimed at disrupting inverter grid-support functions where proper credentials and authentication are achieved, only the altered PV performance would indicate abnormal behavior. All in all, the PIDMS provides novel capabilities for: • Distributed, real-time cyber-physical detection and mitigation analysis • Cybersecurity defense for grid-edge systems • Analysis framework that can provide situational awareness across the transmission, distribution, and DER systems The PIDMS sensor is designed to collect cyber-physical data, process the data using machine-learning algorithms, detect abnormal events, and deploy mitigations. With these goals, the main functional PIDMS objectives are: • Capability to collect cyber-physical data • Onboard storage of cyber-physical data • Peer-to-peer communication • Computationally efficient machine-learning algorithms • Online cyber-physical data analysis • Alerting/visualization capabilities • Mitigation deployment capability with bump-in-the-wire (BITW) implementation Each of these functional objectives enable PIDMS to perform effective cyber-physical intrusion detection and mitigation. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Jones, Christian↗

Summary Report for the Anti-Climb Coating Test Project: Simulated Attack and Skid-Resistance Tests

The Sandia National Laboratories Physical Security Center of Excellence (PSCOE) has been tasked by the Department of State (DOS) Bureau of Diplomatic Security Research and Development branch to investigate the potential anti-climb benefits of newly developed skid-resistant paint coatings - one light base and one dark base. DOS is interested in studying the application of the coatings on passive barriers commonly used at diplomatic facilities. The purpose of the anti-climb coating in this context is to deter and delay adversaries from climbing onto the passive barriers. PSCOE was tasked to perform delay testing that focused on the effectiveness of the coatings on the two DOS perimeter passive barriers - the DS-41 anti-ram fence and a 9 foot high by 1 foot thick reinforced concrete wall intended to mimic the DS-30 anti-ram perimeter wall. PSCOE was also tasked in performing skid-resistance testing using a British Pendulum skid-resistance tester. Delay testing and skid-resistance testing were also performed on two different passive barriers without any anti-climb coating to determine a baseline.

42 ENGINEERING↗

A holistic cyber-physical security protocol for authenticating the provenance and integrity of structural health monitoring imagery data

Modern infrastructure systems, such as bridges, dams, power generation stations, and buildings increasingly have an intrinsic cyber-physical nature to them. Infrastructure now commonly, includes actuators, network connections, sensors, control systems, and computational resources. It is of increasing concern that modern infrastructure is vulnerable to cyber-attacks that can damage both the cyber and physical nature of the infrastructure. To date, the physical and cyber health of infrastructure has been considered separately. However, the increasing concerns associated with the cyber-physical security of infrastructure coupled with the emergence of 5G networks made using components that are not universally considered trustworthy, and the emergence of techniques for creating deepfakes and adversarial examples suggests the time has come to begin considering cyber health and structural health with a more holistic approach. In this work, a protocol is developed for ensuring the imagery data captured by a structural health monitoring system can be unambiguously attributed to legitimate sensors associated with the structural health monitoring system. A computer vision approach based on the idea of mutual information is then presented to detect damage in an image. This work presents the protocol for authenticating the provenance of imager data and demonstrates that this protocol does not have overly adverse effects when used with the mutual information-based technique for detecting damage in the resulting imagery data.

Jung, HweeKwon↗

Clean Energy Cybersecurity Accelerator Cohort 1: Authentication and Authorization

In the 2023 National Cybersecurity Strategy, the Biden-Harris Administration defines the need for a "defensible, resilient digital ecosystem where it is costlier to attack systems than defend them." The strategy cites the Clean Energy Cybersecurity Accelerator (CECA) as an exemplary effort to bolster the security and resilience of clean energy generation. These efforts help "secure the clean energy grid of the future and [generate] security best practices that extend to other critical infrastructure sectors" and promise broad and far-reaching impacts to bridge the capabilities of private industry and the needs of energy production. Cohort 1 of CECA launched in the fall of 2022 with a focus on solutions that provide strong authentication and authorization for industrial control systems to mitigate attacks on the energy grid. Authentication and authorization verify that the identity (authentication) and permissions (authorization) of a user or device are aligned with their assigned roles. Weaknesses in either can have serious repercussions. To assess the strength of Cohort 1's solutions, CECA devised threat scenarios grounded in historical precedents: the CECA team reviewed exploits from real-world case studies of state-sponsored actors to match the assessment's attack paths and targets. Cohort 1 results provided the energy industry, product vendors, and related agencies valuable insights into the efficacy and applicability of solutions in common system configurations under realistic threat scenarios. The results of the assessment highlight points for interrogation and improvement in subsequent technology iterations. CECA's evaluations are part of an ongoing conversation and collaboration to bolster U.S. cyber resilience against adversaries today and in the future.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Defending the Homeland: Growing Foreign Challenges to the U.S. Missile Defense Posture

The Office of the Secretary of Defense (OSD) for Policy requested that Lawrence Livermore National Laboratory conduct a Congressionally directed study on homeland missile defense, pursuant to Section 1692 of the fiscal year 2020 National Defense Authorization Act. In accordance with the statutory language, this study considers whether the security benefits obtained by deployment of homeland missile defenses of the United States are undermined or counterbalanced by adverse reactions of potential adversaries, and considers the effectiveness of homeland missile defense efforts of the United States to deter the development of ballistic missiles. Almost a half-century has elapsed since the United States and the Soviet Union signed the Anti-Ballistic Missile (ABM) Treaty, and almost two decades since the former withdrew. Since withdrawing, the United States has sought to develop and deploy a layered missile defense system to defend against regional threats to U.S. and allied interests abroad and to counter limited threats to the U.S. homeland. As such, missile defense supports key national defense policy objectives. Protecting the U.S. homeland, forces abroad, allies, and partners. Deterring attacks against the United States, its allies, and partners. Assuring allies an strengthening U.S. diplomatic activities in peacetime and crisis. We offer five key findings: 1. The primary benefit of the Ground-based Midcourse Defense (GMD) system is the protection it provides the U.S. homeland against a limited but evolving rogue-state missile threat. While this system has never been tested in combat, it appears thus far to have effectively paced North Korea’s development and deployment of intercontinental ballistic missiles (ICBMs). In the absence of such a defensive capability, the United States would likely have been more heavily exposed to North Korean actions, would have operated at a much higher-risk posture, and would have had less negotiating room with which to navigate coercive tactics and crises. Its allies would have been more concerned about U.S. willingness in time of crisis and war to run the risks of protecting them. The GMD system also serves as a hedge against Iranian breakout. 2. Potential adversaries continue to develop long-range ballistic missiles despite deployment of a U.S. homeland missile defense system. This includes both rogue states and major power rivals whose long-range missile programs predated the deployment of U.S. missile defenses. While North Korea has continued its long-range missile developments and achieved an intercontinental capability, Iran has not yet reached this threshold. The broader proliferation of long-range missiles anticipated in the late 1990s has not materialized. 3. While Russia has used the existence of a U.S. homeland missile defense system as a justification for its substantial and continuing weapon modernization program, neither Russian force modernization nor the limited U.S. homeland missile defense system has altered the strategic balance. Russia has long considered U.S. missile defenses—both theater and homeland—as directed against its strategic forces and as a capability that could rapidly advance, thereby eroding Russian confidence in its nuclear deterrent. Russia’s political and military actions appear excessive and negatively impact areas such as arms control, but they do not undermine the primary benefit of the U.S. system cited in Key Finding 1. 4. China’s expansion and diversification of nuclear and missile forces has been influenced by its concerns about U.S. homeland missile defense, but those concerns are only one of many factors in China’s force planning. Although China’s actions to preserve and expand its assured retaliation prospects have not fundamentally altered the strategic balance, its buildup and lack of transparency about its force modernization goals are troubling. Taken together, the aggregate pattern of China’s modernization activities over the past two decades strongly suggests a concerted effort to develop a modern military force commensurate with its intended geopolitical status. Whatever China’s legacy concerns over the survivability of its strategic nuclear forces, its ability to overwhelm the GMD system appears intact today and will be further strengthened in the years ahead as it continues its long-term modernization program. China’s political and military actions negatively affect U.S. security interests but do not undermine the primary benefit of the U.S. system cited in Key Finding 1. 5. The basic finding that benefits have not so far been undermined by adverse reactions is a function of circumstances that are increasingly in flux. The existing GMD-centered system is under increasing pressure from the pace and scope of North Korean missile deployments. The proposed “layered” system seeks to mitigate this impending capability gap in the near term and to complement future capabilities, such as the Next Generation Interceptor, when they come online. Given the pace of U.S. missile defense developments since 2000, it is possible that adversary advances in capability will outpace the U.S. system’s ability to adapt. Additionally, because this layered system is in principle more readily scaled, it will almost certainly be viewed skeptically by China and Russia. In a context of growing great-power security competition, the Department of Defense (DoD) should consider undertaking a broader net assessment of the U.S., Russian, and Chinese force balance.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Mitigating Extremist Maritime Threats to Radiological Material Transport Vessels

The 21st century has experienced a rise in the threat of global radicalism and extremist organizations, and there has been oft-reported interest from these groups in obtaining or exploiting radiological materials. The threat of extremists acquiring radiological materials while in transit or sabotaging a transport vessel carrying materials at sea is one that requires increased attention. Transport is already one of the most vulnerable times for any cargo but including the difficulties in securing a large ship on the open ocean makes oceanic transport of radiological materials a space of elevated vulnerability for sabotage, theft, or other attacks. The risks of violent extremist attacks on trade ships and trading routes are serious, as shipping routes sustain the global economy, but an attack on a radiological transport vessel could be a magnitude worse, impacting national and international security. While radicalists have largely remained on land in the past due to minimal maritime expertise or inability to project power out of their immediate vicinity, the world has witnessed past attacks on ships such as the USS Cole and the MV Limburg and it is likely only a matter of time before groups extend further into the sea and engage in more maritime campaigns against material transport vessels. This paper suggests methods for increasing safety and security on oceanic transport voyages through behavioral science principles and insider threat recognition training, as well as a better understanding of adversarial and extremist psychology. By providing transport personnel with the knowledge and support to identify and respond to unique maritime threats by extremists, these principles and training suggestions should advance and increase security on the high seas.

Kinney, Justin↗

Secure Route: Roadway Risk Mapping for Transportation Planners

The secure transport of sensitive materials across U.S. road networks pose unique challenges for local, state, and federal agencies. Threats range from random events (e.g., accidents, medical emergencies, mechanical failures) to opportunistic or organized tactical assaults. Although the probability of such attacks is very low, the consequences of material loss to foreign states or terrorists can be catastrophic, qualifying these scenarios as “grey swan” events—low-probability, high-impact occurrences that are predictable but difficult to quantify. Traditional risk assessments struggle in these contexts, necessitating a shift toward subjective risk perception to inform planning. Risk perception in transport planning is shaped by various factors, including knowledge of adversarial capabilities, vehicle defenses, manifest details, and geographic features along the route. Geographic features such as bridges, tunnels, roadside elevation, and gaps in cellular coverage introduce vulnerabilities, while mitigative features include safe havens, police stations, and medical services. Temporal variables such as congestion, accidents, and weather further complicate route planning. Despite their importance, existing routing tools like Google Maps and commercial software do not explicitly account for geographic risk features, requiring planners to rely on personal familiarity with routes—a time-intensive, non-scalable approach. This work addresses these gaps by: (1) developing datasets that catalog geographic risk features along U.S. roadways, (2) eliciting risk perceptions from experienced transportation security experts, and (3) linking these perceptions to roadway conditions and geographic data. We implement these capabilities within Secure Route a novel mapping tool for classifying route segment risks associated with roadway conditions. This system provides transportation planners with an intuitive interface to assess and contextualize risk along potential routes, improving decision-making for secure transport. We present current progress in this effort and identify next steps.

Stewart, Robert [ORNL] (ORCID:0000000281867559)↗

Strategy for distributed controller defence: Leveraging controller roles and control support groups to maintain or regain control in cyber-adversarial power systems

Distributed controllers play a prominent role in electric power grid operation. The coordinated failure or malfunction of these controllers is a serious threat, where the resulting mechanisms and consequences are not yet well-known and planned against. If certain controllers are maliciously compromised by an adversary, they can be manipulated to drive the system to an unsafe state. The authors present a strategy for distributed controller defence (SDCD) for improved grid tolerance under conditions of distributed controller compromise. The work of the authors’ first formalises the roles that distributed controllers play and their control support groups using controllability analysis techniques. With these formally defined roles and groups, the authors then present defence strategies for maintaining or regaining system control during such an attack. A general control response framework is presented here for the compromise or failure of distributed controllers using the remaining, operational set. The SDCD approach is successfully demonstrated with a 7-bus system and the IEEE 118-bus system for single and coordinated distributed controller compromise; the results indicate that SDCD is able to significantly reduce system stress and mitigate compromise consequences.

97 MATHEMATICS AND COMPUTING↗

Enabling Secure and Resilient XFC: A Software/Hardware-Security Co-Design Approach

Extremely fast charging (XFC) has the potential to reduce the charging time of battery electric vehicles (BEV) to be equivalent to the filling time of internal combustion engine vehicles (ICEV), thus eliminating one of the few advantages ICEV still poses for light- and heavy-duty vehicles. Enabling XFC will, however, require coordination and cooperation between the grid, charging stations, and the vehicles themselves, which leads to an inevitable increase in the attack surface for all systems combined. In securing the overall system, we must not only embrace traditional cybersecurity, which is chiefly concerned with communications and the operation of digital systems, but also cyber-physical systems security as the proper operation of XFC is critically dependent on systems’ abilities to know about (sense) and interact with (actuate) the physical world. The project team consists of academic and industry researchers with backgrounds in cybersecurity, cyber-physical systems security, learning in adversarial environments, transportation security, grid security and resilience, wireless power transfer, converter design, and battery management systems.

33 ADVANCED PROPULSION SYSTEMS↗