Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Vulnerability Analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 235 records · Page 13

Hot corrosion behavior of 304 & P91 graded composite transition joint under molten sulfate salts

A novel graded composite transition joint (GCTJ) between AISI 304 stainless steel and ASTM A335 P91 steel, has been demonstrated remarkablely superior creep performance compared to the conventional dissimilar metal weldment (DMW) under equivalent conditions. However, this advance is challenged by hot corrosion under salt deposition at elevated temperatures. Here, this study investigates the hot corrosion behavior of 304&P91 GCTJ exposed to sulfate salts at 700°C. Compared to the 304 steel, corrosion attacks initiate in the P91 triangle, where the dual-phase microstructure of ferrite and tempered martensite significantly influences pitting initiation. Anodic dissolution mainly occurs within the tempered martensite due to more vulnerable sites within the tempered martensite. With prolonged exposure, corrosion propagates across both phases, and the corrosion depth within the P91 triangle is related to the exposed surface area ratio between 304 and P91. Electrochemical analysis reveals the occurrence of galvanic corrosion between the 304 and P91, with a positive linear relationship between anodic dissolution current density (I a ) and the exposed surface area ratio between 304 and P91 in molten salts, further emphasizing the critical impact of this ratio on the corrosion severity in the P91 triangle. These findings underscore the importance of transition zone design optimization in mitigating localized corrosion.

Galvanic corrosion↗

Attribution of the Australian bushfire risk to anthropogenic climate change

Abstract. Disastrous bushfires during the last months of 2019 and January 2020 affected Australia, raising the question to what extent the risk of these fires was exacerbated by anthropogenic climate change. To answer the question for southeastern Australia, where fires were particularly severe, affecting people and ecosystems, we use a physically based index of fire weather, the Fire Weather Index; long-term observations of heat and drought; and 11 large ensembles of state-of-the-art climate models. We find large trends in the Fire Weather Index in the fifth-generation European Centre for Medium-Range Weather Forecasts (ECMWF) Atmospheric Reanalysis (ERA5) since 1979 and a smaller but significant increase by at least 30 % in the models. Therefore, we find that climate change has induced a higher weather-induced risk of such an extreme fire season. This trend is mainly driven by the increase of temperature extremes. In agreement with previous analyses we find that heat extremes have become more likely by at least a factor of 2 due to the long-term warming trend. However, current climate models overestimate variability and tend to underestimate the long-term trend in these extremes, so the true change in the likelihood of extreme heat could be larger, suggesting that the attribution of the increased fire weather risk is a conservative estimate. We do not find an attributable trend in either extreme annual drought or the driest month of the fire season, September–February. The observations, however, show a weak drying trend in the annual mean. For the 2019/20 season more than half of the July–December drought was driven by record excursions of the Indian Ocean Dipole and Southern Annular Mode, factors which are included in the analysis here. The study reveals the complexity of the 2019/20 bushfire event, with some but not all drivers showing an imprint of anthropogenic climate change. Finally, the study concludes with a qualitative review of various vulnerability and exposure factors that each play a role, along with the hazard in increasing or decreasing the overall impact of the bushfires.

van Oldenborgh, Geert Jan (ORCID:0000000268989535)↗

Hydropower Resilience Database for Assessing Microgrid Formation Capability and Enhancing Power Grid Resilience

In the face of increasing frequency of extreme events, enhancing resilience and reliability of energy infrastructure demands innovative solutions. Hydropower, with its inherent generation flexibility and grid-forming capability, offers significant potential for enhancing power grid resilience through the establishment of microgrids. To enable informed decision-making and strategic planning, we present the Hydropower Resilience Database (HRD) that integrates data from various sources such as Oakridge National Laboratory (ORNL) HydroSource, National Inventory of Dams, and US Western Grid database. By integrating relevant information on hydropower plant characteristics, including dams, reservoirs, and connected electrical grid, this resource enables hydropower plant owners, utilities, and community stakeholders to identify and evaluate the feasibility of using hydropower resources in microgrids to support nearby communities and critical infrastructure in various challenging scenarios. Using HRD, a set of metrics are evaluated to quantify the capability of hydropower plants to support essential microgrid functions. An interactive tool is developed using ArcGIS, enabling the visualization and analysis using HRD. Our research contributes to strategic planning efforts for fortifying energy infrastructure, ensuring reliable power supply during disruptions, and advancing the development of robust and resilient energy systems in regions susceptible to grid vulnerabilities.

13 HYDRO ENERGY↗

Hydropower Resilience Database for Assessing Microgrid Formation Capability and Enhancing Power Grid Resilience

In the face of increasing frequency of extreme events, enhancing resilience and reliability of energy infrastructure demands innovative solutions. Hydropower, with its inherent generation flexibility and grid-forming capability, offers significant potential for enhancing power grid resilience through the establishment of microgrids. To enable informed decision-making and strategic planning, we present the Hydropower Resilience Database (HRD) that integrates data from various sources such as Oakridge National Laboratory (ORNL) HydroSource, National Inventory of Dams, and US Western Grid database. By integrating relevant information on hydropower plant characteristics, including dams, reservoirs, and connected electrical grid, this resource enables hydropower plant owners, utilities, and community stakeholders to identify and evaluate the feasibility of using hydropower resources in microgrids to support nearby communities and critical infrastructure in various challenging scenarios. Using HRD, a set of metrics are evaluated to quantify the capability of hydropower plants to support essential microgrid functions. An interactive tool is developed using ArcGIS, enabling the visualization and analysis using HRD. Our research contributes to strategic planning efforts for fortifying energy infrastructure, ensuring reliable power supply during disruptions, and advancing the development of robust and resilient energy systems in regions susceptible to grid vulnerabilities.

13 HYDRO ENERGY↗

Advanced Reactor Designs Security Analysis, Risk, and Recommendations: Risks, Consequences, and Possible by-Design Mitigation Approaches Associated with Select Advanced Reactors

Next-generation advanced reactors (ARs) incorporate enhanced safety systems, have smaller source terms, and feature compact modular designs, which should lessen their collective risk profiles. However, to fully evaluate risk, security needs to be a part of the equation. Without taking security into consideration, safety systems and components in the new ARs may be vulnerable to sabotage. These base attributes, coupled with enhanced security features specific to AR design through sound engineering and security-by-design (SeBD), should provide developers and operators with lower inherent security risk profiles. Building security early into the AR design may remove or passively secure potential critical targets from an adversary’s reach , thereby increasing overall safety and security. An integrated approach and diverse design team that includes engineering, operations, and security experts are fundamental to building security into the design without sacrificing fundamental operational efficiencies and principles. The objective of this project was to evaluate the security and safety interfaces for five classes of reactors, identify potential security vulnerabilities of structures, systems, and components (SSC), and underscore the need to consider security alongside safety in the design o f these concepts. The five reactor classes evaluated in this project and presented in this report are molten-salt reactors (MSR), high temperature gas reactors (HTGR), sodium-fast reactors (SFR), advanced light-water reactors (ALWR), and microreactors. These designs were selected because they reflect the concepts that are closest to market deployment and have received significant resource investments from the public and private sector. This project assesses the inherent security risks posed by common classes of ARs, provides a methodology and framework to assess security along with safety, and offers an analysis of potential mitigation strategies that could be incorporated. For each AR technology, the SSCs that relate to radionuclide source safety functions are discussed to understand the SSC contribution to safety and relative importance in the protective strategy for the design. The assumptions that went into evaluating each reactor concept originated from generic publicly available nonproprietary information and should not directly be used to qualify an absolute risk profile nor to rank specific AR designs. Instead, the purpose of the analysis is to understand and compare the generic inherent security risks of different AR technologies.

98 - NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL↗

Machine Learning for Anomaly Detection in Neural Network Security and SRF Cavities

This dissertation explores the development and deployment of machine learning approaches to address critical challenges in anomaly detection across two distinct domains: neural network security in federated learning settings and cavity behavior analysis in particle accelerator operations at Jefferson Lab in Newport News, Virginia. Anomaly detection identifies deviations from expected patterns, safeguarding systems in cybersecurity, industry, and research against malicious activities and failures. This dissertation demonstrates how our machine learning approaches enhance detection accuracy and efficiency in both neural network security and industrial applications. First, we investigate vulnerabilities in deep neural networks deployed in federated learning. Although federated learning preserves user privacy by training models locally, it remains vulnerable to backdoor attacks, in which malicious participants embed hidden triggers that induce targeted misbehavior. We propose a self-supervised contrastive learning framework to detect and mitigate such backdoor attacks. In our experiments, this method achieves higher detection accuracy and lower false positive rates than existing defenses, while operating without access to local model updates or original training data and thus preserving the privacy guarantees of the federated setting. Second, we address the operational reliability of superconducting radio-frequency (SRF) cavities at the Continuous Electron Beam Accelerator Facility (CEBAF). Our research leverages an unsupervised learning approach, combined with Principal Component Analysis (PCA) and k-means clustering, to identify anomalous behaviors in SRF cavities. Our method detects subtle anomalous behavior by analyzing SRF signal data. This knowledge allows for the early detection and resolution of potential faults, significantly improving the efficiency and reliability of operations. Third, we extend these insights to time-series anomaly detection more broadly. We design a contrastive-learning based model tailored to increasingly dynamic environments and academic research. This model improves detection accuracy in settings that require real-time monitoring and predictive maintenance. Our research underscores the broader applicability and impact of advanced machine learning techniques in anomaly detection. By extracting meaningful patterns from complex data, machine learning can significantly enhance security in distributed neural networks and improve the efficiency of particle accelerator operations. This dissertation serves as a stepping stone for future investigations into the vast possibilities of anomaly detection, inspiring further exploration and development of machine learning techniques in this field.

Ferguson, Hal [Old Dominion University]↗

A geospatial environmental and techno-economic framework for sustainable phosphorus management at livestock facilities

Nutrient pollution of waterbodies is a major worldwide water quality problem. Excessive use and discharge of nutrients can lead to eutrophication and algal blooms in fresh and marine waters, resulting in environmental problems associated with hypoxia, public health issues related to the release of toxins and freshwater scarcity. A promising option to address this problem is the recovery of nutrient releases prior to being discharged into the environment. Driven by the sustainable materials management concept, the COW2NUTRIENT (Cattle Organic Waste to NUTRIent and ENergy Technologies) framework is developed for the techno-economic evaluation and selection of nutrient recovery systems at livestock facilities. Furthermore, environmental vulnerability to nutrient pollution determined through a geographic information system (GIS)-based model and techno-economic information of different state-of-the-art nutrient management technologies are combined in a multi-criteria decision analysis (MCDA) model, resulting in the selection and economic analysis of the most suitable process for each studied livestock facility. This framework has been employed for studying the implementation of sustainable phosphorus management systems at 2,217 livestock facilities in the Great Lakes area, resulting in capital expenses of 2.5 billion USD if only phosphorus recovery technologies are installed, and up to 5.2 billion USD if nutrient management is combined with biogas and power production. However, considering potential economic incentives for the recovery of phosphorus, net revenues up to 230 million USD per year can be achieved. Therefore, the framework presented reveals the potential of implementing nutrient management systems at regional scale for the abatement of phosphorus releases from livestock facilities.

54 ENVIRONMENTAL SCIENCES↗

Cyber-Physical Event Emulation-Based Transmission-and-Distribution Co-Simulation for Situational Awareness of Grid Anomalies (SAGA)

Energy management of transmission and distribution networks (T&D) is becoming more challenging with the accelerated adoption of distributed energy resources (DERs)-such as distributed photovoltaic generation and battery energy storage systems (BESS)-on the electric grid. To better analyze the impacts of DERs on both transmission and distribution systems, a comprehensive T&D co-simulation platform is developed. Further, with DERs more actively participating in system operation-e.g., by providing real-time grid services-their cyber vulnerability needs to be better understood to maintain system reliability. This paper discusses a cyber-physical events emulation-based T&D co-simulation platform to perform comprehensive cyber events emulations, physical simulation, and analysis of interdependent impacts. Results from the case studies-which show how cyber events on a synthetic distribution network can impact operations on the transmission and distribution network-validate that the proposed T&D cosimulation platform can perform cyber-physical events emulation and produce response in near realtime; therefore, with extensive simulation using the proposed co-simulation platform, the system operators can accumulate adequate training data for system situational awareness of grid anomalies.

anomalies detection↗

DER Digital Supply Chain Gap Analysis

Solar photovoltaic (PV) cybersecurity is a growing field of research. As deployments of solar PV have increased, cyber risk has also increased. Utility solar PV installations, however, are not required to comply with the North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) plan unless they meet a minimum generation threshold of 75 MW. Individual residential-scale solar PV deployments will not meet that generation threshold and are therefore excluded from the NERC CIP requirements. With most solar installations less than 75 MW, solar PV has been deployed with minimal oversight and highly variable cybersecurity maturity. The resources that comprise the digital supply chain can include software, code, data, and other digital components. But as clean energy technologies advance, cybersecurity threats and vulnerabilities continue to evolve and grow in sophistication. Supply chain cybersecurity represents a critical area for ensuring safe operations as the U.S. moves toward a clean energy future.

cybersecurity↗

Evaluating Supply Prioritization Strategies for Risk-Informed Decision Making in an Arbitrary Gas Network

Supply disruptions and infrastructure failures in natural gas networks present critical challenges to energy reliability and risk-informed planning. This study evaluates two supply prioritization strategies, Maximum Delivery Prioritization (MDP) and Demand-Based Prioritization (DBP), within an arbitrary natural gas network under conditions of supply shortage. Model performance under both strategies is assessed in response to node and edge failure using demand satisfaction metrics, system-wide and localized dependency scores, and geographic information system (GIS)-based spatial analysis. Results show that DBP better preserves supply for high-demand nodes, while MDP offers broader coverage. The underlying network topology plays a critical role in shaping prioritization outcomes. Integrated GIS visualization enhances the interpretability of vulnerability assessments, revealing structurally critical components and localized vulnerabilities. The proposed framework supports scalable, data-driven decision-making for infrastructure planners and engineers, enabling improved disruption recovery and efficiency in constrained natural gas networks. These insights contribute to the development of more robust energy systems capable of withstanding stress and disruptions.

Peterson, Steven [ORNL] (ORCID:0000000287672998)↗

Retrieval Augmented Generation for Robust Cyber Defense

In cybersecurity, the ability to efficiently analyze and respond to vulnerabilities, weaknesses, attack patterns, and threat tactics is critical for effective defense strategies. With the increasing complexity and volume of cybersecurity data, traditional methods of querying and retrieving information are often inadequate. To address this challenge, we implemented Retrieval-Augmented Generation (RAG) systems—CyRAG and GraphCyRAG—that integrate large language models (LLMs) with both structured data from relational databases and knowledge graphs such as Neo4j. CyRAG is designed to handle structured data, focusing on CVE (Common Vulnerabilities and Exposures) and CWE (Common Weakness Enumeration) entities to generate accurate and context-rich responses. In contrast, GraphCyRAG leverages Neo4j knowledge graphs to retrieve interconnected information from CVE, CWE, CAPEC (Common Attack Pattern Enumeration and Classification), and ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) datasets. By utilizing Neo4j’s graph-based framework, GraphCyRAG enables deeper traversal of relationships between vulnerabilities and attack patterns, providing cybersecurity analysts with more comprehensive insights into potential attack vectors and mitigation strategies. Our preliminary results demonstrate that integrating knowledge graphs with RAG significantly enhances both the accuracy and depth of threat analysis, allowing for the retrieval of dynamic, real-time data and the generation of contextually aware responses. This approach helps analysts uncover hidden relationships between cyber entities, predict exploit paths, and prioritize mitigation efforts effectively. The integration of RAG with cybersecurity knowledge graphs represents a significant advancement in cybersecurity threat intelligence, enabling more informed decision-making and stronger defense strategies.

97 MATHEMATICS AND COMPUTING↗

Optimizing Heat Recovery with Storage: Control Validation and Sensitivity Analysis of the Time-Independent Energy Recovery Plant Using Modelica

Heat recovery in large building central plants saves energy but traditionally requires simultaneous heating and cooling. The Time-Independent Energy Recovery (TIER) plant shifts this paradigm by integrating thermal energy storage (TES) to enable heat recovery regardless of concurrent demand, offering a highly efficient, space-saving solution to achieve California’s energy goals. However, its integration of heat recovery chillers, cooling-only chillers, cooling towers, and trim air-source heat pumps (ASHPs) creates growing control and sizing complexity. To overcome this, this study employs high-fidelity Modelica dynamic simulation to validate TIER control sequences and optimize equipment sizing. We translated the written Sequences of Operation into executable Control Description Language (CDL) to test logic against sub-hourly loads. This verification workflow successfully identified and resolved critical vulnerabilities, such as thermal storage freezing and equipment short-cycling, in a virtual environment prior to physical deployment. Then, the study analyzes TIER plant performance across three simulated building types in three locations, and a real building load profile, ensuring variety in heating and cooling loads, and simultaneity factors and explores sizing rules for the TES and ASHP capacity. The analysis shows that the TIER plant operates equipment efficiently leading to a plant SCOP of around 7.5 across all scenarios, higher than a traditional ASHP plant, and a viable pathway to de-risk complex system design and control through simulation to identify optimal designs that maximize energy efficiency, minimize operational costs, and ensure robust operation in varied environmental conditions, thereby facilitating the broader adoption of such a solution for large buildings.

Zanetti, Ettore↗

Correlating Time-Resolved Pressure Measurements With Rim Sealing Effectiveness for Real-Time Turbine Health Monitoring

Purge flow is bled from the upstream compressor and supplied to the under-platform region to prevent hot main gas path ingress that damages vulnerable under-platform hardware components. A majority of turbine rim seal research has sought to identify methods of improving sealing technologies and understanding the physical mechanisms that drive ingress. While these studies directly support the design and analysis of advanced rim seal geometries and purge flow systems, the studies are limited in their applicability to real-time monitoring required for condition-based operation and maintenance. As operational hours increase for in-service engines, this lack of rim seal performance feedback results in progressive degradation of sealing effectiveness, thereby leading to reduced hardware life. To address this need for rim seal performance monitoring, this study utilizes measurements from a one-stage turbine research facility operating with true-scale engine hardware at engine-relevant conditions. Time-resolved pressure measurements collected from the rim seal region are regressed with sealing effectiveness through the use of common machine learning techniques to provide real-time feedback of sealing effectiveness. Two modeling approaches are presented that use a single sensor to predict sealing effectiveness accurately over a range of two turbine operating conditions. Here, the results show that an initial purely data-driven model can be further improved using domain knowledge of relevant turbine operations, which yields sealing effectiveness predictions within 3% of measured values.

42 ENGINEERING↗

Correlating Time-Resolved Pressure Measurements With Rim Sealing Effectiveness for Real-Time Turbine Health Monitoring

Purge flow is bled from the upstream compressor and supplied to the under-platform region to prevent hot main gas path ingress that damages vulnerable under-platform hardware components. A majority of turbine rim seal research has sought to identify methods of improving sealing technologies and understanding the physical mechanisms that drive ingress. While these studies directly support the design and analysis of advanced rim seal geometries and purge flow systems, the studies are limited in their applicability to real-time monitoring required for condition-based operation and maintenance. As operational hours increase for in-service engines, this lack of rim seal performance feedback results in progressive degradation of sealing effectiveness, thereby leading to reduced hardware life. To address this need for rim seal performance monitoring, the present study utilizes measurements from a one-stage turbine research facility operating with true-scale engine hardware at engine-relevant conditions. Time-resolved pressure measurements collected from the rim seal region are regressed with sealing effectiveness through the use of common machine learning techniques to provide real-time feedback of sealing effectiveness. Two modelling approaches are presented that use a single sensor to predict sealing effectiveness accurately over a range of two turbine operating conditions. Results show that an initial purely data-driven model can be further improved using domain knowledge of relevant turbine operations, which yields sealing effectiveness predictions within three percent of measured values.

Compressors↗

Delamination and Buckling Analysis of a Laminated Component in a High-speed Permanent Magnet Motor

High-speed permanent magnet (PM) machines are widely used because of their high-power density and high efficiency. The high rotation speed also inevitably subjects the PMs to high centrifugal load, which might damage them due to their inherent mechanical vulnerability, such as a much lower tensile strength than the compressive strength. To robustly transfer the torque from the magnet to the shaft, the outer diameter of the laminated rotor core is larger than the inner diameter of the rotor frame to ensure tight contact while working at 20,000 rpm. Motor manufacturing requires the shrink-fit method to assemble the rotor frame and rotor core. However, after the shrink-fit assembly, unexpected local delamination and buckling are observed on the rotor core part. Utilizing finite element simulation, we study the internal stress of assembling these two parts at the provided interference. Simulation results indicate the reasons for the delamination and buckling of the rotor core part and provide suggestions for improving the assembly.

Lin, Lianshan↗

Towards generic memory forensic framework for programmable logic controllers

A Programmable Logic Controller (PLC) is a microprocessor-based controller that is used to automate physical processes in critical infrastructure and various other industries and manufacturing sectors. Initially, PLCs were completely isolated from the Internet, and cyber security was not incorporated at the time of development. The introduction of industry 4.0 and the evolution of ICS systems to communicate over public IP addresses from the Internet enhanced productivity and efficiency, but Internet connectivity exposed the systems and their vulnerabilities, which led to an increase in cyber attacks. When a system is sabotaged/compromised, security analysts need to get to the root cause of the attack as quickly as possible to recover the system. To do so, memory forensic analysis is critical to provide a unique insight into the run-time memory activities and extract a reliable source of evidence. In this paper, we analyze the memory structure of the Schneider Electric Modicon M221 PLC. To build a memory profile, we reverse engineer the communication protocol and conduct differential analysis to gain knowledge about the structure of the memory and the low-level representation of control logic instructions. We then identify dynamic and static memory regions by modifying different project fields and conducting differential analysis, which allows us to identify boundaries of critical memory structures and extract important forensic artifacts that can be found in the memory. The Python implementation of the memory profile can help reduce the time and effort required for manual analysis in case of cyber incident or system failure.

97 MATHEMATICS AND COMPUTING↗

AI-based Cyber Event OSINT via Twitter Data

Open-Source Intelligence (OSINT) is largely regarded as a necessary component for cybersecurity intelligence gathering to secure network systems. With the advancement of artificial intelligence (AI) and increasing usage of social media, like Twitter, we have a unique opportunity to obtain and aggregate information from social media. In this study, we propose an AI-based scheme capable of automatically pulling information from Twitter, filtering out security-irrelevant tweets, performing natural language analysis to correlate the tweets about each cybersecurity event (e.g., a malware campaign), and validating the information. This scheme has many applications, such as providing a means for security operators to gain insight into ongoing events and helping them prioritize vulnerabilities to deal with. To give examples of the possible uses, we present three case studies demonstrating the event discovery and investigation processes.

Dale, Dakota↗

Unsupervised Detection of SOC Spoofing in OCPP 2.0.1 EV Charging Communication Protocol Using One-Class SVM

The electric vehicles (EVs) market keeps growing globally; thus, it is critical to secure the EV charging communication protocols in order to guarantee reliable and fair charging operations among the customers. The Open Charge Point Protocol (OCPP) 2.0.1 supports the communication between the Electric Vehicle Supply Equipment (EVSE) and Charging Station Management Systems (CSMSs); therefore, it becomes vulnerable to several types of attacks, which aim to jeopardize smart charging, billing, and energy management. Specifically, OCPP 2.0.1 allows the self-reporting of the State of Charge (SOC) values, which makes it vulnerable to spoofing-based cyberattacks, which target manipulating the scheduling priorities, distorting the load forecasts, and extending the charging sessions in an unfair manner. In this paper, we try to address this type of attack by providing a comprehensive analysis of the SOC spoofing attacks and introducing a novel unsupervised detection framework based on the One-Class Support Vector Machine (OCSVM) algorithm. Specifically, two types of attack scenarios are analyzed (i.e., priority manipulation and session extension) by deriving engineered features that capture the nonlinear relationships under normal charging behavior. Detailed simulation-based results are derived by utilizing the DESL-EPFL Level 3 EV charging dataset. Our results demonstrate high F1-score and recall in identifying spoofed SOC values and that the proposed OCSVM model demonstrates superior performance compared to alternative clustering and deep-learning based detectors.

EV charging↗