Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “attack modeling”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 217 records · Page 12

Inferring adversarial behaviour in cyber‐physical power systems using a Bayesian attack graph approach

Abstract Highly connected smart power systems are subject to increasing vulnerabilities and adversarial threats. Defenders need to proactively identify and defend new high‐risk access paths of cyber intruders that target grid resilience. However, cyber‐physical risk analysis and defense in power systems often requires making assumptions on adversary behaviour, and these assumptions can be wrong. Thus, this work examines the problem of inferring adversary behaviour in power systems to improve risk‐based defense and detection. To achieve this, a Bayesian approach for inference of the Cyber‐Adversarial Power System (Bayes‐CAPS) is proposed that uses Bayesian networks (BNs) to define and solve the inference problem of adversarial movement in the grid infrastructure towards targets of physical impact. Specifically, BNs are used to compute conditional probabilities to queries, such as the probability of observing an event given a set of alerts. Bayes‐CAPS builds initial Bayesian attack graphs for realistic power system cyber‐physical models. These models are adaptable using collected data from the system under study. Then, Bayes‐CAPS computes the posterior probabilities of the occurrence of a security breach event in power systems. Experiments are conducted that evaluate algorithms based on time complexity, accuracy and impact of evidence for different scales and densities of network. The performance is evaluated and compared for five realistic cyber‐physical power system models of increasing size and complexities ranging from 8 to 300 substations based on computation and accuracy impacts.

Sahu, Abhijeet↗

Data-Based Resilience Enhancement Strategies for Electric-Gas Systems Against Sequential Extreme Weather Events

Some extreme weather events, such as the hurricane, pass through an area sequentially and thus are called sequential extreme weather events (SEWEs). This paper proposes a data-based robust optimization (RO) model to enhance the resilience of the integrated electricity and gas system (IEGS) against SEWEs. Specifically, the SEWE strikes the IEGS sequentially. After each attack, the system state is adjusted immediately to minimize the maximized expected system cost caused by the SEWE. The attack-defense procedures are repeated alternatively during the SEWE. Preventive measures, hardening, are made in advance to reduce the impact of sequential attacks. The entire process is formulated as a multi-period RO model. Furthermore, it is proved that the most effective resilience enhancement strategies for this model are the same as those for a two-stage RO model, which can be solved by the nested column-and-constraint generation (C&CG) algorithm. In addition, the property of SEWEs, sequentially endangering limited regions of the IEGS, is incorporated to build a data-based uncertainty set and reduce its conservativeness. Simulation results on two IEGSs validate the effectiveness of the proposed model.

24 POWER TRANSMISSION AND DISTRIBUTION↗

High-Order Wall-Modeled Large-Eddy Simulation of High-Lift Configuration

This paper presents the assessment of several recent enhancements for a high-order wall-modeled large-eddy simulation (WMLES) approach and demonstrates order independence with a fixed data exchange location in the wall model. The two enhancements include the use of isotropic tetrahedral elements to improve accuracy and an explicit subgrid-scale model, the Vreman model, to improve accuracy and robustness. The [Formula: see text] study focused on the high-lift Common Research Model (HL-CRM) at the angle of attack of 19.57 deg, a benchmark problem from the 4th AIAA High-Lift Prediction Workshop. Solution polynomial orders of [Formula: see text], and 5 were used in the study. The study demonstrated [Formula: see text] independence in integrated forces, pitch moment, velocity profile in the wall-normal direction, and surface flow topology. It also showed that a [Formula: see text] order of at least 3 ([Formula: see text]) was needed to correctly predict the external inviscid flow and the surface flow topology. Thereafter, [Formula: see text] simulations over several other angles of attack demonstrated that the high-order WMLES approach can correctly predict the maximum lift and flow separation regions for HL-CRM with about 40 million degrees of freedom (DOF) compared to at least 250 million DOF required by second-order methods.

Engineering↗

IoT Intrusion Detection Taxonomy, Reference Architecture, and Analyses

This paper surveys the deep learning (DL) approaches for intrusion-detection systems (IDSs) in Internet of Things (IoT) and the associated datasets toward identifying gaps, weaknesses, and a neutral reference architecture. A comparative study of IDSs is provided, with a review of anomaly-based IDSs on DL approaches, which include supervised, unsupervised, and hybrid methods. All techniques in these three categories have essentially been used in IoT environments. To date, only a few have been used in the anomaly-based IDS for IoT. For each of these anomaly-based IDSs, the implementation of the four categories of feature(s) extraction, classification, prediction, and regression were evaluated. We studied important performance metrics and benchmark detection rates, including the requisite efficiency of the various methods. Four machine learning algorithms were evaluated for classification purposes: Logistic Regression (LR), Support Vector Machine (SVM), Decision Tree (DT), and an Artificial Neural Network (ANN). Therefore, we compared each via the Receiver Operating Characteristic (ROC) curve. The study model exhibits promising outcomes for all classes of attacks. The scope of our analysis examines attacks targeting the IoT ecosystem using empirically based, simulation-generated datasets (namely the Bot-IoT and the IoTID20 datasets).

97 MATHEMATICS AND COMPUTING↗

Robust Restoration From Cyber-Physical Attacks in Active Distribution Grids With Grid-Edge IBRs

The inverter-based resources (IBRs) have enabled the integration of renewable energy at the grid edge with enhanced control capabilities to support the reliable operation of power grids. Different control frameworks, such as hierarchical or distributed architecture, have been proposed with the expansion of cyber networks for real-time monitoring and control. This evolution of critical infrastructure into cyber-physical systems also brings more vulnerabilities for the broadened attack surfaces, and significantly increases the possibility of physical system failures or outages caused by cyberattacks. Among tremendous efforts in the defense-in-depth approach, it remains challenging to provide prompt detection and accurate location of attack entry points or paths. Therefore, the prevailing restoration framework may struggle to fully consider the cyber-physical interdependence, successfully isolate the compromised cyber and physical components, and safely recover the systems without the potential risks leading to secondary outages. This paper is motivated to develop a cyber-physical restoration framework for distribution grids to recover from cyber attacks by harnessing grid-edge IBRs. The framework is first built on the operational guidelines of IBRs considering the compromised cyber layer. Then, an ambiguity set is established to represent the uncertainty of attack scenarios and their possibility levels. Next, a distributionally robust optimization model is developed to provide the optimal load restoration strategy across all scenarios. The effectiveness of the proposed model is demonstrated through various use cases on the modified IEEE 13-node and 123-node test systems. Finally, simulation results demonstrate the effectiveness and advancement of developed post-attack restoration strategies.

Cybersecurity↗

A dataset of cyber-induced mechanical faults on buildings with network and buildings data

We have collected data of cyber-induced mechanical faults on buildings using a simulation platform. A DOE reference building model was used for running the simulation under a Rogue device attack and collected the network data as well as the physical buildings data to better understand the impacts of cyber attacks on the building and help identify the source of the mechanical fault with the network data. Alfalfa is the tool used for simulating the DOE reference buildings and acts as an interface to the model for querying the status and providing input externally. The Building Automation System (BAS) is the centralized controller providing control commands to other BACnet devices on the network based on the building status received from Alfalfa. The BACnet devices like damper will listen for the control commands from BAS on the BACnet network and implement it. The attacker is the malicious actor on the network creating disruptions by placing cyber-attacks.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cyber threat assessment of machine learning driven autonomous control systems of nuclear power plants

We report advanced cyber-attacks against critical infrastructure and the energy sector are becoming more common. With the invention of autonomous control systems (ACS) within advanced nuclear reactor designs, system designers, reactor operators, and regulators must consider cybersecurity during the design and operational phases. This article provides a cyber threat assessment of machine learning (ML)-based digital twinning (DT) technologies in the context of advanced reactor ACS. A cyber–physical testbed was created to emulate nuclear reactor digital instrumentation and controls (I&C) and act as a basis for the ACS. The ACS was designed as two plant-level DTs predicting reactor malfunctions and determining control actions and two component-level DTs responsible for classifying component states and forecasting component inputs and outputs (I/O). Two duplicate ACS designs– one using a traditional ML framework and one using an automated ML (AutoML) framework– were created and tested against cyber-attacks on training data, real-time process data, and ML model architectures to determine their respective qualitative cyber-risk in terms of likelihood and impact. Both frameworks showed similar cyber-resilience against training, real-time, and ML architecture attacks, proving that neither is inherently more secure. Recommended safeguard and security measures are posed to system designers, reactor operators, and regulators to maintain the cybersecurity of ML-based DT technologies such as ACS, prompting a holistic view of shared responsibility for maintaining cyber-secure ML-based systems.

99 GENERAL AND MISCELLANEOUS↗

Ultrafast Early Warning of Heart Attacks through Plasmon‐Enhanced Raman Spectroscopy using Collapsible Nanofingers and Machine Learning

Abstract As the leading cause of death, heart attacks result in millions of deaths annually, with no end in sight. Early intervention is the only strategy for rescuing lives threatened by heart disease. However, the detection time of the fastest heart‐attack detection system is >15 min, which is too long considering the rapid passage of life. In this study, a machine learning (ML)‐driven system with a simple process, low‐cost, short detection time (only 10 s), and high precision is developed. By utilizing a functionalized nanofinger structure, even a trace amount of biomarker leaked before a heart attack can be captured. Additionally, enhanced Raman profiles are constructed for predictive analytics. Five ML models are developed to harness the useful characteristics of each Raman spectrum and provide early warnings of heart attacks with >98% accuracy. Through the strategic combination of nanofingers and ML algorithms, the proposed warning system accurately provides alerts on silent heart‐attack attempts seconds ahead of actual attacks.

60 APPLIED LIFE SCIENCES↗

Data-Driven Probabilistic Anomaly Detection for Electricity Market under Cyber Attacks

Information and communication technologies have been widely used in smart grid for efficient operation. However, these technologies are vulnerable to malicious cyber attacks, which may lead to severe reliability and economic issues. Recently, a variety of data-driven anomaly detection approaches have been explored to detect potential cyber attacks in smart grids. In this paper, we researched on the electricity market data aiming to identify anomalies from the locational marginal prices (LMPs) and provide a new indicator for potential cyber attacks in power grids. Specifically, a novel data-driven probabilistic anomaly detection framework is proposed for electricity market, which consists of three major components: long short-term memory (LSTM) based deterministic electricity price forecasting, probabilistic electricity price forecasting and anomaly detection. This framework is tested on a model-based electricity market simulator under two types of cyber attacks, i.e., load redistribution attack (LRA) and price responsive attack (PRA). Numerical results on the simulated LMPs show that the proposed framework is capable of detecting data anomalies over these attacks.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Model-Based Diagnostics and Mitigation of Cyber Threats

The report summarizes key tasks performed to develop a toolkit for detecting cyber-attack events in instrumentation and control (I&C) systems of nuclear power plants. The toolkit connects the state-of-the-art GPWR Simulator with the RELAP5 code providing best-estimate nuclear steam supply system (NSSS) analyses, via the application programming interface (API), and allows users to introduce potential cyber-attack scenarios into power plant operational simulation. This summary for the project reflects topical reports submitted during the project as well as a journal paper published in 2022. The focus areas of the summary include: (1) modeling I&C systems for the AP1000 Generation III+ nuclear plant and GPWR simulator, (2) simulation and monitoring of plant response to cyber-attack events, (3) API structure for the toolkit interfacing the GPWR simulator and RELAP5 code, and (4) restructuring of the three-loop NSSS software of GPWR to model the two-loop AP1000 structure. Discussed in some details are (a) the attack tree analysis assessing the susceptibility of the AP1000 I&C system, resulting in reactor trips, in terms of the attack possibility and component sensitivity and (b) realistic estimation of the time to steam generator trip due to cyber-intrusions in the GPWR Simulator. Finally, sample demonstrations of the cyber-security tool kit, in the form of the GPWR-RELAP5 API, are summarized.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

A Micro-Mechanical Constitutive Model to Predict Hygrothermal Aging of Cross-Linked Polymers

Abstract A multi-physics material model is presented to describe the effects of temperature, oxygen, and humidity on the constitutive response of cross-linked polymers. The effect of hygrothermal damage on the mechanical integrity of the polymer matrix can be considered as the result of damage accumulation of two independent aging mechanism namely, i) thermo-oxidative, and ii) hydrolytic aging. In order to capture the mutual effects of thermo-oxidative and hydrolytic aging, an assumption has been made that each of the aging phenomenon can be superposed to each other. In fact, each of them works independently and as a result, they can compete with each other. Utilizing the theory of network decomposition, all phenomena and their correlation were modeled and thus, the strain energy function of the polymer matrix is written with respect to four independent mechanisms, i) the shrinking original matrix that has neither been attacked by water nor oxygen, ii) conversion of the first network to two new network due to the reduction and formation of cross-links, and iii) energy loss from network degradation due to attack of the water molecules to polymer active agents. Moreover, the proposed model is micro-mechanically based and is mainly relevant on thin samples due to our underlying assumption of homogeneous diffusion of oxygen and water throughout the matrix. The model has been validated against extensive data-sets obtained from experiments we specifically designed for concept validation.

Bahrololoumi, Amir↗

Effects of pH on the nano/micro structure of calcium silicate hydrate (C-S-H) under sulfate attack

Calcium silicate hydrate (C-S-H), the most important Portland cement hydration product, determines the mechanical properties and durability of cementitious materials. In marine environment, C-S-H often suffers from sulfate attack – one of the most common and severe degradations for concrete. pH is considered as a critical factor in determining the deterioration behavior of C-S-H during sulfate attack, of which the significance may be overlooked. This study focused on the role of pH on the deterioration of C-S-H in terms of the composition and nano/micro structure under sulfate attack. The results show that lowering pH aggravates the decalcification of C-S-H, whereas a strong alkaline condition is beneficial to increase the resistance to deterioration. An increase in the mean chain length together with the proportion of large pores (>10 nm) is observed when C-S-H is subjected to low-pH sulfate attack (pH = 10–12), resulting in a relatively loose structure. The deep analysis on defective tobermorite model reveals that calcium at the interlayer of C-S-H nanostructure is readily removed under sulfate attack, thereby improving the potential of Si-O-Si groups formation and increases the mean chain length of C-S-H.

36 MATERIALS SCIENCE↗

Sequence-Based Anomaly Detection in Critical Infrastructure Networks

United States critical infrastructure faces new cyber threats from adversarial nation-state actors in the form of malware-free attacks. Traditional cybersecurity techniques use rules-based methods to identify indicators of compromise on networks, often missing these sophisticated attacks. Our approach leverages multiple state of the art machine learning models in a pipeline to identify abnormal network events through sequential analysis. We combine both device and packet-level information into individual events to characterize anomalous network actions. The model is trained and tested on real network traffic from the Idaho National Lab High Performance Computing (HPC) with greater than 98% precision. It is capable of flagging malicious tactics used by adversaries in malware-free attacks, severe changes to the network, and abnormal user activity by network devices.

99 - GENERAL AND MISCELLANEOUS↗

Multifidelity Approach to Sensitivity Estimation in Large-Eddy Simulation

A novel approach to compute affordable approximate sensitivities in a large-eddy simulation (LES) is proposed and assessed. The approach is based on solving a Reynolds-averaged Navier–Stokes (RANS) problem that has been linearized around the mean LES solution, with closure modeling required for the linearized changes in turbulent Reynolds stresses. In the present study, the closure modeling is based on a linearized algebraic turbulence model. The method is assessed for the flow over a NACA0012 airfoil at a fixed angle of attack, with the Reynolds number as the variable parameter. The results show that, provided an accurate linearized closure model, the method predicts the correct sensitivity of the skin friction coefficient and the mean velocity field at the cost of a linearized RANS, which provides an important proof-of-concept for this approach. Here, the linearized algebraic turbulence model with standard model coefficients produces a reasonably accurate sensitivity, but the results also suggest that accuracy could be gained from recalibrating the model coefficients for this new use of the model.

42 ENGINEERING↗

Autonomous reconfigurable virtual sensing system for cyber-attack neutralization

An industrial asset may be associated with a plurality of monitoring nodes, each monitoring node generating a series of monitoring node values over time representing current operation of the industrial asset. An abnormality detection computer may determine that at least one abnormal monitoring node is currently being attacked or experiencing a fault. A virtual sensing estimator may continuously execute an adaptive learning process to create or update virtual sensor models for the monitoring nodes. Responsive to an indication that a monitoring node is currently being attacked or experiencing a fault, the virtual sensing estimator may be dynamically reconfigured to estimate a series of virtual node values for the abnormal monitoring node or nodes based on information from normal monitoring nodes and appropriate virtual sensor models. The series of monitoring node values from the abnormal monitoring node or nodes may then be replaced with the virtual node values.

97 MATHEMATICS AND COMPUTING↗

Adaptive, self-tuning virtual sensing system for cyber-attack neutralization

An industrial asset may have a plurality of monitoring nodes, each monitoring node generating a series of monitoring node values over time representing current operation of the industrial asset. An abnormality detection computer may determine that an abnormal monitoring node is currently being attacked or experiencing a fault. An autonomous, resilient estimator may continuously execute an adaptive learning process to create or update virtual sensor models for that monitoring node. Responsive to an indication that a monitoring node is currently being attacked or experiencing a fault, a level of neutralization may be automatically determined. The autonomous, resilient estimator may then be dynamically reconfigured to estimate a series of virtual node values based on information from normal monitoring nodes, appropriate virtual sensor models, and the determined level of neutralization. The series of monitoring node values from the abnormal monitoring node or nodes may then be replaced with the virtual node values.

Abbaszadeh, Masoud↗

Automated Membership Inference Attacks: Discovering MIA Signal Computations using LLM Agents

Membership inference attacks (MIAs), which enable adversaries to determine whether specific data points were part of a model's training dataset, have emerged as an important framework to understand, assess, and quantify the potential information leakage associated with machine learning systems. Designing effective MIAs is a challenging task that usually requires extensive manual exploration of model behaviors to identify potential vulnerabilities. In this paper, we introduce AutoMIA -- a novel framework that leverages large language model (LLM) agents to automate the design and implementation of new MIA signal computations. By utilizing LLM agents, we can systematically explore a vast space of potential attack strategies, enabling the discovery of novel strategies. Our experiments demonstrate AutoMIA can successfully discover new MIAs that are specifically tailored to user-configured target model and dataset, resulting in improvements of up to 0.18 in absolute AUC over existing MIAs. This work provides the first demonstration that LLM agents can serve as an effective and scalable paradigm for designing and implementing MIAs with SOTA performance, opening up new avenues for future exploration.

Tran, Toan Viet [Emory University]↗