Robust Dynamic Watermarking for Cyber-Physical Security of Inverter-Based Resources in Power Distribution Systems
Not provided.
SEARCH · Engineering Papers
Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.
Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.
Not provided.
Zero Trust is a cybersecurity paradigm centered on the idea that a network breach is inevitable and so no user or asset should be implicitly trusted. Entities on the network are continuously monitored and access-granting decisions are based on dynamic risk assessment using multiple inputs. To limit the damage from an attack, privileges and lateral access are constrained by default. This report provides an overview of current models and constructs employed in building out these concepts into a zero trust architecture.
Distributed control is an effective method to coordinate multiple components in a microgrid. It usually has mandatory requirements for communication graph topology; changing the topology unexpectedly could disrupt the operation of a distributed controller. A denial of service (DoS) attack blocks communication channels to cause variations in communication graph. Unforeseen topology changes render a controller to receive incomplete system information. Control decisions made based on incorrect information can lead to significantly reduced grid supporting capability. As a result, the vital power balance between generation and load may be challenged. Determining power balance requires steady-state power flow analysis; however, the cyber-induced steady-state analysis is not well studied in the literature. Here, in this article, we show that a cyber–physical microgrid with unknown DoS attacks has augmented uncertain power flow equations, whose special structure creates new computational issue to determining power balance. To deal with the issue, we develop a novel cyber-induced microgrid model: the cyber–physical system is transformed into a pure physical model, where the disruption effects of DoS in the cyber layer are shown to be equivalent to the variations of the physical model parameters. With the transformed system, we develop a sufficient condition to ascertain the system power balance under unknown DoS attacks. In addition, practical insights for resilient distributed control design are shown as well.
U.S. critical infrastructure is increasingly composed of integrated cyber-physical systems (CPS) whose components are operationally interdependent. These interdependencies can create additional vulnerabilities beyond those that are typically evaluated through independent physical and cyber risk assessments. These additional vulnerabilities, previously undetected at the sub-system and/or component level, could cause cascading effects across both the physical and cyber domains that could lead to infrastructure disruption or failure. This paper will review an initial mathematical framework developed to help understand the dynamics of these interfacing physical and cyber components at a holistic system level. The resulting framework also provides a method for modeling and assessing the resilience of CPS in complex and adaptive systems. It frames the system in terms of mission performance and the potential effects to performance caused by attacks that are cyber, physical, or blended in nature. The framework utilizes a systems-based, state-space modeling approach to reason about risk, resilience, and interdependencies in CPS. Probabilities are applied to each CPS component regarding a threat (both man-made and natural) and the likelihood of that particular component being impacted, along with indirect impact to other interdependent components. These component-level impacts from threats then translate into mission-level impact and systemic state change.
Perfluorosulfonic acids (PFSAs) are commonly used as solid polymer electrolyte membranes (PEMs) in electrochemical energy devices, where they are vulnerable to attack by radical species during operation. A popular strategy to combat this problem is to introduce radical scavengers like cerium (Ce) ions that neutralize these species before they attack the PFSA. Such cation doping creates a multi-ion system, in which understanding the mechanisms of cation solvation and transport becomes important for the effective design and utilization of PFSA–cation systems. Ce ions also provide a representative model system for multication-exchanged ionomers in electrochemical systems. In this study, hydration and conductivity measurements, along with X-ray fluorescence and scattering, are employed to elucidate how Ce ion exchange alters PFSA’s ionic solvation, as well as nano- and mesoscale morphologies, which ultimately control its ion transport properties. A molecular transport model is used to deconvolute the impact of Ce ions on the local solvation structure of water in the membrane from mesoscale changes of the transport pathways. The combined experimental and theoretical analysis reveals a nonlinear decrease in conductivity driven by cation solvation at the molecular level and morphological changes at longer length scales. Migration–diffusion coupling, its nonlinear dependence on ion exchange and hydration, and its overall implications for ionomer performance are also discussed. Finally, these findings have the potential to be translated into other mixed cation–ionomer systems for a wide range of energy and environmental devices.
Graph Neural Networks (GNNs) have gained significant attention owing to their ability to handle graph-structured data and the improvement in practical applications. However, many of these models prioritize high utility performance, such as accuracy, with a lack of privacy consideration, which is a major concern in modern society where privacy attacks are rampant. To address this issue, researchers have started to develop privacy-preserving GNNs. Despite this progress, there is a lack of a comprehensive overview of the attacks and the techniques for preserving privacy in the graph domain. In this survey, we aim to address this gap by summarizing the attacks on graph data according to the targeted information, categorizing the privacy preservation techniques in GNNs, and reviewing the datasets and applications that could be used for analyzing/solving privacy issues in GNNs. We also outline potential directions for future research in order to build better privacy-preserving GNNs.
While evasion attacks on computer vision systems have been widely studied, creating attacks that remain effective under significant changes in viewpoint continues to be challenging. Traditional approaches often rely on affine transformations of images, but these approaches degrade at larger perspective shifts and often produce unrealistic or ineffective perturbations. Recent methods use differentiable renderers to improve viewpoint robustness, but they typically depend on manually constructed 3D models. We introduce a semi-automated pipeline that generates physically printable and perspective-invariant adversarial patches using only a small set of 2D images. Our method integrates 3D reconstruction, neural rendering, adversarial patch optimization, and an object detection victim model into a unified workflow. We use 2D Gaussian Splatting for high fidelity mesh reconstruction and FlexPara for surface parameterization that produces texture maps suitable for patch editing. Together, these components form a fully differentiable pipeline in PyTorch3D that links texture modification to model outputs, enabling efficient optimization of patches that remain effective across many viewpoints. The complete process, from image capture to patch printing and physical evaluation, can be completed within a few hours. We demonstrate the effectiveness of the resulting patches through attacks on the YOLOv8 object detection model and discuss remaining challenges and opportunities for improving robustness and scalability.
Critical infrastructure and other operational technology (OT) environments face increasing cybersecurity risks from adversarial behavior. This paper describes the development of a risk model using a Bayesian network to enhance the comprehension of observable cyber events caused by malicious activity in OT environments. The core of the Bayesian network is a process model that describes the stages of adversary behavior. The remainder of the model is based on the MITRE ATT&CK® for Industrial Control Systems (ICS) taxonomy, which includes tactics and techniques that may be used by the adversary. The observables provide evidence for adversary behavior through the intermediary technique and tactic nodes. One challenge in constructing this model is a lack of open-source data from cyber-attacks on OT systems. This paper discusses learning from limited data, the elicitation of expert opinion to construct the conditional probability tables when data is scarce, and the refinement of the most difficult conditional probabilities tables using several forms of sensitivity analyses. Finally, the Bayesian network is demonstrated using two historical case studies: the DarkSide ransomware attack on the Colonial Pipeline and the destructive cyberattack targeting the ThyssenKrupp blast furnace. Index Terms—Cybersecurity, industrial control systems, operational technology
In this report, lower length scale simulations to inform an engineering-scale model of fuel-cladding chemical interaction (FCCI) conducted under the auspices of the Nuclear Energy Advanced Modeling and Simulation (NEAMS) program in FY22 are described. An overall strategy for the implementation of the BISON model is described, and the past and current lower length scale work on FCCI formation is put into the context of this overall strategy. Density functional theory and kinetic Monte Carlo simulations are used to determine the diffusion coefficient of neodymium in iron. Density functional theory calculations are also used to parameterize a parabolic approximation for the dependence of free energy on composition for the intermetallic compound Fe 17 Nd 2 . A phase-field model of the Fe-Nd system was developed that includes the random solid solution body-centered cubic phase and the intermetallic Fe 17 Nd 2 . The model was used to simulate growth of the intermetallic layer in a diffusion couple and the results were compared to experiment. The model’s prediction of the parabolic growth constant is within 40 % of the experimental value. The model is also used to simulate the formation of a grain boundary attack layer that is observed in experiment. The simulations show enhanced Nd concentration along the grain boundaries, but do not clearly show formation of a Fe 17 Nd 2 layer
In this paper, we propose an AC optimal power flow (ACOPF) model considering distributed flexible AC transmission system (D-FACTS) devices, in which the reactance of D-FACTS equipped lines are introduced as decision variables. This is motivated by increasing interests in using D-FACTS devices to address system operational and cyber-security concerns. First, D-FACTS devices can be incorporated in real-time operations for economic benefits such as managing power congestions and reducing system losses. Second, D-FACTS devices can be utilized by moving target defense (MTD), an emerging concept against cyber-attacks, to prevent attackers from knowing true system configurations. Therefore, system operators can use the proposed ACOPF model to achieve economic benefits and provide the setpoints of D-FACTS devices for MTD at the same time. In addition, we rigorously derive the gradient and Hessian matrices of the objective function and constraints, which are further used to build an interior-point solver of the proposed ACOPF. Numerical results on the IEEE 118-bus transmission system show the validity of the proposed ACOPF model as well as the efficacy of the interior-point solver in minimizing system losses and generation costs.
Proper functioning of nuclear power plants relies on a mix of well-regulated human and machine-driven workflows. This regulation supports nuclear safety through a series of processes and many of the tasks that support these processes have a repetitive nature that make artificial intelligence (AI) informed by machine learning (ML) a potential aid in a variety of tasks. AI is being evaluated for activities that include inspections, fuel processing, monitoring, and other activities. The introduction of any new technology presents a potential new attack vector. In the case of AI/ML, there are many attacks that have already been discovered and over time the attacks can be expected to follow the growth pattern observed in cyber security. While future planning is necessary, current efforts need to be established now to predict the threat emergence over the next year 10 years and mitigate potential threats. Based on these observations, AI/ML will need to become trustworthy, which corresponds to techniques and procedures that emphasize AI explainability along with resilience techniques to data, algorithms, models, and systems. This kind of system robustness is the foundation for defenses against AI/ML-specific attacks. Attempting to look forward and take a broad view of capabilities provides input to research roadmaps and the ability to distill vulnerabilities into specific use cases may provide greater assistance in understanding the technology benefits while introducing new risks. The impact of current and future AI in three areas—capabilities, challenges, and recovery strategies—represents an initial attempt at balancing both.
Given the adoption of emerging technologies and the increasing complexity of managing such systems with a lifecycle much shorter than that of critical infrastructure systems, there is a practical need to be able to analyze sociotechnical dependencies and their associated evolving risks. Threat models based on social influence techniques can be used to implement adversarial tactics analogous to the cyber kill chain and attested to within the MITRE ATT&CK for ICS framework including Initial Access, Persistence, Collection, and Impact. Furthermore, as with cyber disruptions, the impact of social influence threat models can have an asymmetric impact that is not spatially-localized. Finally, unlike cyber attacks with a reasonably short duration (ransomware takes days to months), social influence based attacks have the potential to persist for much longer as they are based on long-term strategic infrastructure investments within the private sector. Given the increased importance of electric vehicle charging stations as a long-term, strategic infrastructure investment within the Energy and Transportation Sectors, we provide initial results that compare the impact of a Loss of Availability (T0826) realized through cyber and social influence based threat models. The analysis employs techniques from automated reasoning and measures of network complexity to understand evolving dominance of EV payment and charging networks within geographic region of interest. Within this context, we compare the impact of a loss of availability due to ransomware versus that of loss of support due to a merger and acquisition. Results across several different metro areas will be provided.
This report presents an analysis of the Emergency Core Cooling System (ECCS) for a generic Boiling Water Reactor (BWR)-4 NPP. The Electric Power Research Institute (EPRI) developed Hazards and Consequences Analysis for Digital Systems (HAZCADS) process is applied to the ECCS and its subsystems to identify unsafe control actions (UCAs) which act as possible cyber events of concern. The analysis is performed for two design basis events: Small-break Loss of Coolant Accident (SLOCA) and general transients (TRANS), such as unintended reactor trip. In previous work, HAZCADS UCAs were combined with other cyber-attack analysis to develop a risk-informed approach; however, this was for a single system. This report explores advanced systems engineering modeling approaches to model the interactions between digital assets across multiple systems which may be targeted by cyber adversaries. The complex and interdependent design of digital systems has the potential to introduce emergent cyber properties that are generally not covered by hazard analyses nor formal nuclear Probabilistic Risk Assessment (PRA). The R&D and supporting analysis presented here explores approaches to predict and manage how interdependent system properties effect risk. To show the potential impact of a successful cyber-attack to formal PRA event tree probabilities, HAZCADS analysis was also used. HAZCADS was also used to model the automatic depressurization system (ADS) automatic actuation. This analysis extended to an integrated system analysis for common-cause failure (CCF). In this aspect, the HAZCADS analysis continued by analyzing plant design details for system connectivity in support of critical plant functions. A dependency matrix was developed to depict the integrated functionality of the interconnected systems. Areas of potential CCF are indicated. Future work could include adversary attack development to show how CCF could be caused, resulting in PRA events. Across the multiple systems that comprise the ECCS, the analysis shows that the change in such probabilities was very different between systems. This indicates that some systems have a larger potential risk impact from successful cyber-attack or digital failure, which indicates a need for these systems to have a higher priority for design and defensive measures. Furthermore, we were able to establish that a risk analysis using any arbitrary threat model establishes an ordering of components with regard to cyber-risk. This ordering can be used to influence the overall system design with an eye to lowering risk, or as a way to understand real-time risk to operational systems based on a current threat landscape. Expert knowledge of both the analysis process and the system being analyzed is required to perform a HAZCADS analysis. The need for a tiered risk analysis is demonstrated by the results of this report.
The rapid growth of the Internet of Things (IoT) and Edge Computing (EC) has brought significant conveniences to modern society but has also greatly expanded the cyber attack surfaces, particularly as these technologies are being increasingly integrated into critical systems such as power grids, healthcare, and smart homes. Here, to improve IoT/EC’s cybersecurity posture, we leveraged Artificial Intelligence (AI) and Machine Learning (ML) by employing tinyML to monitor voluminous IoT data for cyber threats while addressing devices’ resource constraints, and utilizing Federated Learning (FL) to share local detection knowledge across the system while preserving privacy. Building on our three-layer architecture combining tinyML and FL to enhance autonomous cyber attack detection, this paper demonstrated that the architecture improves detection accuracy, reduces resource consumption, and enables lightweight, secure IoT device monitoring. These results were validated using the public N-BaIoT dataset as well as real IoT network traffic data collected under multiple attack scenarios from our testbeds. Additionally, we introduced an enhanced FL methodology with a novel preprocessing stage, including federated feature selection and global preprocessor construction, to address IoT/EC data heterogeneity. We developed a physical IoT testbed for attack simulations and data collection, implemented a tinyML-powered detector for realistic model validation, and also built a virtual testbed for scalable evaluations of FL models across diverse network environments.
Bidirectional wireless communication is employed in various smart grid components such as smart meters and control and monitoring applications where security is vital. The Trusted Third Party (TTP) and wireless connectivity between the smart meter and the third party in the key management-based encryption techniques for the smart grid are expected to be totally trustworthy and dependable. In a wired/wireless medium, however, a man-in-the-middle may seek to disrupt, monitor and manipulate the network, or simply execute a replay attack, revealing its vulnerability. Recognizing this, this study presents a novel authentication management (model) comprised of two layer security schema. The first layer implements an efficient novel encryption method for secure data exchange between meters and control center with the help of two partially trusted simple servers (constitutes the TTP). In this setting, one server handles the data encryption between the meter and control center/central database, and the other server administers the random sequence of data transmission. The second layer monitors and verifies exchanged data packets among smart meters. It detects abnormal packets from suspicious sources. To implement this node-to-node authentication, One class support vector machine algorithm is proposed which takes advantages of the location information as well as the data transmission history (node identification, packet size, and data transmission frequency). This schema secures data communication, and imposes a comprehensive privacy throughout the system without considerably extending the complexity of the conventional key management scheme.
As vehicles become smarter and more autonomous, they increasingly depend on advanced sensors and communication technologies to operate securely. However, such growing dependence on technology—whether it’s CAN (Controller Area Network) for internal communication or LiDAR (Light Detection and Ranging) for sensing the world around them—also expands the attack surface for the types of cyber attacks. Traditional intrusion detection systems (IDS) typically monitor these systems in isolation, limiting their ability to detect sophisticated, crosssystem attacks. To address this, we propose a multi-modal fusion approach that combines real-world CAN FD signals (from the HCRL dataset) with LiDAR features (from the nuScenes dataset) to enhance attack detection. Our method employs a twostage ensemble approach. Calibrated XGBoost and LightGBM models initially process CAN FD (Fuzzing Data) and LiDAR data independently, detecting timing anomalies and space abnormalities. They are subsequently logarithmically combined with a logistic regression meta-model along with 17 engineered features capturing cross-modal behavior, prediction conflicts, and nonlinear interactions. This approach achieves an AUC of 0.87 and an F1-score of 0.82, surpassing single-modality baselines and early fusion methods, at merely 2 ms inference latency. Compared with deep learning competitors, it is 3 times more efficient, providing a lightweight, interpretable, and real time solution to automotive cybersecurity.
This report presents the results of the “Foundations of Rigorous Cyber Experimentation” (FORCE) Laboratory Directed Research and Development (LDRD) project. This project is a companion project to the “Science and Engineering of Cyber security through Uncertainty quantification and Rigorous Experimentation” (SECURE) Grand Challenge LDRD project. This project leverages the offline, controlled nature of cyber experimentation technologies in general, and emulation testbeds in particular, to assess how uncertainties in network conditions affect uncertainties in key metrics. We conduct extensive experimentation using a Firewheel emulation-based cyber testbed model of Invisible Internet Project (I2P) networks to understand a de-anonymization attack formerly presented in the literature. Our goals in this analysis are to see if we can leverage emulation testbeds to produce reliably repeatable experimental networks at scale, identify significant parameters influencing experimental results, replicate the previous results, quantify uncertainty associated with the predictions, and apply multi-fidelity techniques to forecast results to real-world network scales. The I2P networks we study are up to three orders of magnitude larger than the networks studied in SECURE and presented additional challenges to identify significant parameters. The key contributions of this project are the application of SECURE techniques such as UQ to a scenario of interest and scaling the SECURE techniques to larger network sizes. This report describes the experimental methods and results of these studies in more detail. In addition, the process of constructing these large-scale experiments tested the limits of the Firewheel emulation-based technologies. Therefore, another contribution of this work is that it informed the Firewheel developers of scaling limitations, which were subsequently corrected.
The optimization of physical security in nuclear power plants requires sophisticated methodologies that integrate operator actions and plant behavior through advanced simulation tools. Idaho National Laboratory has developed the Modeling and Analysis for Safety and Security using the Dynamic EMRALD Framework (MASS-DEF) methodology, an approach that integrates force-on-force simulations, dynamic probabilistic risk assessment, and thermal hydraulics modeling to enhance security planning while reducing costs. A reduced order model for thermal hydraulic simulations performed by the Modular Accident Analysis Program (MAAP) was developed to evaluate reactor core behavior during attack scenarios. MAAP simulations are computationally intensive and must be run in a secure environment, complicating analysis and validation. By pre-computed scenario outcomes for a small number of modified parameters, the reduced order model significantly decreases the computational cost and enables offsite review of the results.