Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Vulnerabilities”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 289 records · Page 16

Optimal vocabulary selection approaches for privacy-preserving deep NLP model training for information extraction and cancer epidemiology

With the use of artificial intelligence and machine learning techniques for biomedical informatics, security and privacy concerns over the data and subject identities have also become an important issue and essential research topic. Without intentional safeguards, machine learning models may find patterns and features to improve task performance that are associated with private personal information. The privacy vulnerability of deep learning models for information extraction from medical textural contents needs to be quantified since the models are exposed to private health information and personally identifiable information. The objective of the study is to quantify the privacy vulnerability of the deep learning models for natural language processing and explore a proper way of securing patients’ information to mitigate confidentiality breaches. The target model is the multitask convolutional neural network for information extraction from cancer pathology reports, where the data for training the model are from multiple state population-based cancer registries. This study proposes the following schemes to collect vocabularies from the cancer pathology reports; (a) words appearing in multiple registries, and (b) words that have higher mutual information. We performed membership inference attacks on the models in high-performance computing environments. The comparison outcomes suggest that the proposed vocabulary selection methods resulted in lower privacy vulnerability while maintaining the same level of clinical task performance.

59 BASIC BIOLOGICAL SCIENCES↗

A Survey on Cybersecurity Challenges, Detection, and Mitigation Techniques for the Smart Grid

The world is transitioning from the conventional grid to the smart grid at a rapid pace. Innovation always comes with some flaws; such is the case with a smart grid. One of the major challenges in the smart grid is to protect it from potential cyberattacks. There are millions of sensors continuously sending and receiving data packets over the network, so managing such a gigantic network is the biggest challenge. Any cyberattack can damage the key elements, confidentiality, integrity, and availability of the smart grid. The overall smart grid network is comprised of customers accessing the network, communication network of the smart devices and sensors, and the people managing the network (decision makers); all three of these levels are vulnerable to cyberattacks. In this survey, we explore various threats and vulnerabilities that can affect the key elements of cybersecurity in the smart grid network and then present the security measures to avert those threats and vulnerabilities at three different levels. In addition to that, we suggest techniques to minimize the chances of cyberattack at all three levels.

Tufail, Shahid↗

Series FACTS Devices for Increasing Resiliency in Severe Weather Conditions

Severe weather conditions are low-probability, high-impact events that affect grid operations. The majority of power outages are caused by severe weather conditions. Grid resiliency to weather events can be enhanced by decreasing the reliance on its affected sections. One way to do this is to reduce the power flow through lines vulnerable to severe weather. If a line is disconnected, its initial power flow is distributed through the neighbor lines, which may cause congestion in the grid. FACTS devices can be used to control the power flow of lines that have a higher chance of power outages. Most previous works do not consider weather events in power flow control. In this work, a linearized optimal power flow (OPF)–based algorithm is developed to minimize the real power flow of vulnerable lines considering the thermal limits of lines to prevent infeasible solutions; the simulation is fast, making it suitable for large-scale systems. The proposed optimization problem is presented as a mixed-integer linear program (MILP), making it capable of using short-term load forecasting due to its high solution speed. The proposed optimization problem considers multiple lines with different outage probabilities and the uncertainties of the weather forecast. Moreover, it estimates the power reduction in vulnerable lines due to changes in the series FACTS devices. The performance of the proposed optimization problem is tested on IEEE 14-, 30-, and 118-bus systems for several scenarios. The results are validated with the AC power flow results from MATPOWER.

24 POWER TRANSMISSION AND DISTRIBUTION↗

A Risk Assessment Framework for Cyber-Physical Security in Distribution Grids with Grid-Edge DERs

Integration of inverter-based distributed energy resources (DERs) is reshaping the landscape of distribution grids to fulfill the socioeconomic, environmental, and sustainability goals. Addressing the technological challenges of DER grid integration requires an adaptive communication layer for efficient DER management and control. This transition has given rise to a cyberphysical system (CPS) architecture within the distribution system, causing new vulnerabilities for cyberphysical attacks. To better address potential threats, this paper presents a comprehensive risk assessment framework for cyberphysical security in distribution grids with grid-edge DERs. The framework incorporates a detailed CPS model accounting for dynamic DER characteristics within the distribution grid. It identifies vulnerabilities in DER communication systems, models attack scenarios, and addresses communication latency crucial for inverter control timescales. Subsequently, the quantification of attack impacts employs an attack probability model including both the vulnerability and criticality of cyber components. The proposed risk assessment framework was validated through testing on the modified IEEE 13-node and 123-node test feeders.

cyberattack↗

Analyzing Insider Risk Threat to the Internet of Things (IoT)

Recent technological advancement has created a growing convergence of innovation. From machine learning to ubiquitous computing to wireless networks and automation, the world is seeing new technology increasingly capable of connecting with each other. Devices and systems use open communications networks to interact, process information, and react. This is called the Internet of Things (IoT) and is comprised of physical devices that exchange data over networks, creating revolutionary possibilities. The most common way most people interact with an IoT is through ‘smart home’ products like Amazon’s Alexa, which use microphones, speakers, and phones to control a variety of devices, from lights and thermostats, to cameras, to appliances and vacuum cleaners. But the open nature of IoT networks—necessary for their ability to communicate and operate—also introduces privacy and security concerns. At a personal level, this might mean a hack into a home to steal private information, but when applied in broader industries like healthcare, transportation, manufacturing, or the military, this vulnerability can have serious consequences. As IoT usage and interconnectivity increases, so too does the susceptibility to malicious actors. And the entire system is only as secure as its least secure member. This creates particular risk and vulnerability to radiological material industries, as a competent insider adversary could utilize the IoT to potentially steal or access classified or sensitive information about employees, sites, or systems; or simply sabotage security or maintenance from a more remote—and less secure—device. The IoT relies on a secure network across the entire system, especially in transport which may lack the security of more permanent locations; if one device fails, it can create a ripple effect and an insider threat may seek to exploit that connectivity. While IoT benefits drive increased innovation and usage, there are also vulnerabilities an insider threat could exploit; this risk of an IoT to radiological material must be addressed in any mitigation effort.

Kinney, Justin↗

Software Bill of Materials in the Nuclear Industry

Nuclear power plants (NPP) have thousands of digital assets throughout their facility. Typically, NPPs have asset and configuration management programs that capture the make, model, and version of a component. This information, however, usually only includes first- or second-tier components and does not capture the complete enumeration of software components and their dependencies within operational technology (OT) equipment. As seen with recent cyberattacks, this level of detail is insufficient for identifying if and where an exploitable vulnerability exists within a facility. A software bill of materials (SBOM) provides this detailed enumeration. Further, integrating SBOMs with vulnerability data sources and vulnerability attestation reports can provide improved awareness leading to better cyber risk management and incident response. Preferably, SBOMs are provided by the supplier; however, when an NPP already owns a device, it is less likely they will have a supplier provided-SBOM. Fortunately, SBOMs can be generated on installed digital assets. This paper provides an introduction to the U.S. Department of Energy Office of Nuclear Energy paper titled “Towards Software Bill of Materials in the Nuclear Industry,” which describes the SBOM ecosystem and provides a suggested approach to methodically and seamlessly integrate an SBOM program in an NPP.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

A Real-Time ANPC Inverter Digital Twin with Integrated Design-For-Trust

The demand for renewable energy has increased over the last few years, and so has the demand for greater expectations within the energy market. This increasing trend has been accompanied by more significant usage of internet-connected devices (IoT), leading to critical electrical infrastructure being connected to the internet. Implementing internet connectivity with such devices and systems provides benefits such as improving the system's performance, facilitating irregularity and anomaly mitigation, and providing additional situational awareness for enhanced decision-making. However, enhancing the connected system with IoT introduces a drawback – a greater vulnerability to cyber-attacks. Cyber-attacks targeting critical infrastructure in the electrical sector have occurred in the United States and Ukraine. These cyber-attacks highlight and expose vulnerabilities that a system inherits when connecting to the internet. These attacks left thousands of customers without electricity for hours until operators could regain control of the electric utility grid. Therefore, to address the vulnerabilities of an internet-connected power electronic device, this work focused on the hardware layer of the system. Implementing a cyber-control system inside the hardware layer can significantly reduce the possibility of an attacker patching malicious controller firmware into a photovoltaic grid-connected inverter, thus mitigating the likelihood that the inverter becomes inactive a cyber-attack scenario. With this mitigation technique, if a cyberattack is successful and an attacker gains control of the network, a cyber-defense technique is in place to mitigate the impact of the cyber-attack. This additional protection layer was developed based on an innovative concept known as Digital Twin (DT). A DT, in this case, replicates an Active-Neutral Point Clamped (ANPC) inverter and was designed using a hardware language known as VHDL (Very High-Speed Integrated Circuit Hardware Description Language) and applied to Field-Programmable-GateArray (FPGA). The DT is embedded within the FPGA and contained in a controller board, the UCB (Unified Controller Board), developed by the University of Arkansas electrical engineering team. This UCB also contains two Digital Signal Processors (DSPs) responsible for generating associated signals to control an authentic physical inverter. These DSP signals are received and processed by the FPGA that implements the DT of an ANPC; in other words, it simulates in realtime the expected output of an actual ANPC inverter using the signals from the DSP. When a new firmware is ready to be patched, the DT provides output signals simulating behavior that a real ANPC inverter would generate with the new firmware. The new firmware is tested to check if it meets all the operational requirements established using a Design-For-Trust technique (DFTr). If the new firmware fails in at least one of the DFT tests, it is considered malicious and must be rejected. This work is divided into sections, such as Background, which explains the pieces that were used and the strategy behind this work; Process and Procedure, which explains the methodology that was adopted to prove the reliability and effectiveness of this work; Results and Discussion, where the simulations and results are described and explained; followed by Conclusion and Future work section, which concludes this work and adds possible future projects to continue this work further.

do Amaral Custodio, Paulo Vitor↗

Trends in Cybersecurity Threats to Clean Energy

As deployments of clean energy generation and storage assets continue to grow, the increased attack surface creates a greater risk for cyber threats, but is clean energy truly a target for cyber adversaries? This poster will present research on the trends in cyber incidents that have affected clean energy companies and assets as well as the trends in disclosed and exploited vulnerabilities. From a series of ransomware attacks on European wind manufacturers, to vulnerabilities exploited in solar assets to turn controllers into botnets, to attacks on communication infrastructure that have resulted in extended outages of remote control and monitoring, we explore the techniques used and the impacts to the clean energy sector. Key takeaways include understanding of how OT-focused malware is becoming more flexible and more destructive, how known vulnerabilities are being exploited, the growing number of IT and OT attacks that use built in tools and functionalities. Additionally, we highlight the presumed motivations and targeted sectors for various identified cyber adversaries. Viewers will leave with an understanding of how recent headlines fit into the development of cyberattack trends and what preventions they may need to take to protect against increasingly popular tactics.

14 SOLAR ENERGY↗

Forensic Analysis of SOHO Router Binaries

Small Office/Home Office (SOHO) routers are used by millions of consumers across the United States, and are commensurately vulnerable. Forensic analysis of SOHO router firmware helps to understand and mitigate those vulnerabilities. This poster focused particularly on analysis of BusyBox executables, a software suite that provides several Unix utilities in a single file. Three main tools were used to analyze the binaries. BinWalk was used to extract the files, but also to build entropy graphs, extract Linux kernel images, and identify CPU architectures; WiiBin processed the binaries to find endianness, architecture, the percent compressed/encrypted, and compiler data; and @DisCo, a machine learning tool used to determine function similarity in disassembled binaries, analyzed similarities and determined versions of extracted BusyBox files from each router. These tools found that venders from all five routers utilized the same version of the BusyBox software across different firmware updates, demonstrating the importance of constant firmware scrutiny to protect against security vulnerabilities.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Data Centers and Digital Assurance Introduction to Supply Chain and Cybersecurity for Data Centers, Session 1

The first session of the TADA (Technical Assistance for Digital Assurance) Data Centers Cohort Workshop, held on October 30, 2025, introduced foundational concepts of Digital Assurance in the context of data center and grid integration. Sponsored by the U.S. Department of Energy, the workshop brought together utilities, data center operators, developers, and vendors to address cybersecurity and supply chain vulnerabilities. The session emphasized the growing criticality of data centers within the electric grid and the need for secure, real-time, bidirectional communication. Participants explored the principles of Digital Assurance, including cybersecurity, cyber-informed engineering (CIE), and lifecycle security, and applied a threat-vulnerability-consequence framework to identify and mitigate risks at the data center–grid interface. Discussions covered a range of threats such as spoofed dispatch signals and insider threats, architectural vulnerabilities like SCADA interfaces and insecure protocols, and potential consequences including cascading grid failures. The session also raised strategic questions about business value, vendor assurance, and defining cyber boundaries and responsibilities. This foundational workshop set the stage for deeper technical analysis and the development of actionable frameworks in subsequent sessions. Session 1 of 3.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Securing The Future: 2026 Manufacturing & Critical Infrastructure Threat Landscape

This report outlines the current state of manufacturing weaknesses introduced by the complexities of modern environments, including cloud services and Internet of Things (IoT) devices, with particular attention paid to the unique vulnerabilities encountered by SMMs. It also highlights CyManII’s strategic initiatives and collaborative solutions to mitigate these risks and strengthen the cybersecurity posture of the manufacturing ecosystem. Utilizing data from 2025 to inform forward-looking mitigation strategies, this report provides manufacturers with a clear understanding of both current and emerging cybersecurity threats, as well as practical opportunities to strengthen their cyber ecosystems. The following sections detail key vulnerabilities and threat vectors, along with actionable mitigation strategies, many of which have been developed or piloted through CyManII-led efforts. A thorough understanding of these risks and mitigation strategies is essential for manufacturers seeking to strengthen the security and resilience of their manufacturing operations.

3D Printing↗

FIND: A Synthetic weather generator to control drought Frequency, Intensity, and Duration

Water systems worldwide are experiencing climate change-induced shifts in drought properties like frequency, intensity, and duration, affecting water security and reliability. To develop and test effective drought preparedness plans, researchers often use synthetic weather generators to create hydrological scenarios that explore drought variability beyond historical records. Existing weather generators typically allow users to adjust streamflow statistics like percentiles or temporal correlation but do not directly control drought properties of frequency, intensity, and duration. To fill this gap, we propose FIND (Frequency, INtensity, and Duration) synthetic weather generator. FIND incorporates a standardized drought index to directly and in dependently control drought frequency, intensity, and duration in generated streamflow time series while preserving observed hydrological variability. Use cases for FIND include i) water systems analysis applications that seek to train and test drought strategies under historical and plausible future drought conditions, and ii) bottom-up vulnerability studies relating system vulnerability outcomes to specific changes in drought properties of frequency, intensity, and duration. Here, we demonstrate FIND’s versatility through three experiments: replicating historically observed drought properties, generating streamflow scenarios for multiple sites preserving correlation between their drought conditions, and generating a set of scenarios with direct and independent changes in drought properties. FIND source code is openly available for applications beyond the scope of this paper.

42 ENGINEERING↗

Investigating the Determinants of Household Capabilities Burden During Power Outages: The Case of Winter Storm Uri

Existing research primarily uses census data to identify the vulnerability of communities to hazards. These vulnerability indices provide aggregated data and are not hazard-specific nor well-validated with post-event data. In contrast, our study uses household survey data (n=1065) to understand which Texan households suffered the greatest loss of their capabilities due to power outages and other utility service disruptions during Winter Storm Uri. Inspired by the Capabilities Approach, our measures of burden include the number of household capability types disrupted during the outages (e.g., cooking, heating, refrigeration), the severity of impact for each disrupted capability, and the additional time and financial costs of coping with these disruptions. We perform a clustering analysis, and find two distinct groups in our data, consisting of ‘lesser burden' and ‘heavier burden' households. Results indicate that the households experiencing the heaviest capabilities burden were most likely to experience longer power outages and the loss of water services. They were also more likely to have a Hispanic-Latino household member, lack access to a generator, live in a rented home, have larger households with more young children, fewer adults over 65, lower household incomes, been impacted by the COVID-19 pandemic, and more family characteristics that made life harder. We also fit a logistic regression model to assess the role of outage, household, and community characteristics in predicting differences in capabilities burden. Our results offer insights into enumerating the consequences of utility service disruptions on households, which can inform more targeted and equitable resilience strategies.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Emergency department visits in California associated with wildfire PM 2.5 : differing risk across individuals and communities

The threats to human health from wildfires and wildfire smoke (WFS) in the United States (US) are increasing due to continued climate change. A growing body of literature has documented important adverse health effects of WFS exposure, but there is insufficient evidence regarding how risk related to WFS exposure varies across individual or community level characteristics. To address this evidence gap, we utilized a large nationwide database of healthcare utilization claims for emergency department (ED) visits in California across multiple wildfire seasons (May through November, 2012–2019) and quantified the health impacts of fine particulate matter <2.5 μm (PM 2.5 ) air pollution attributable to WFS, overall and among subgroups of the population. We aggregated daily counts of ED visits to the level of the Zip Code Tabulation Area (ZCTA) and used a time-stratified case-crossover design and distributed lag non-linear models to estimate the association between WFS and relative risk of ED visits. We further assessed how the association with WFS varied across subgroups defined by age, race, social vulnerability, and residential air conditioning (AC) prevalence. Over a 7 day period, PM 2.5 from WFS was associated with elevated risk of ED visits for all causes (1.04% (0.32%, 1.71%)), non-accidental causes (2.93% (2.16%, 3.70%)), and respiratory disease (15.17% (12.86%, 17.52%)), but not with ED visits for cardiovascular diseases (1.06% (–1.88%, 4.08%)). Analysis across subgroups revealed potential differences in susceptibility by age, race, and AC prevalence, but not across subgroups defined by ZCTA-level Social Vulnerability Index scores. These results suggest that PM 2.5 from WFS is associated with higher rates of all cause, non-accidental, and respiratory ED visits with important heterogeneity across certain subgroups. Notably, lower availability of residential AC was associated with higher health risks related to wildfire activity.

54 ENVIRONMENTAL SCIENCES↗

Cyber-Informed Engineering Case Study of an Integrated Hydrogen Generation Plant

Strategies for securing digital instrumentation and control (I&C) systems within the nuclear industry are provided by multiple standards and guidance documents. However, since selection and use of security controls outlined in these documents are frequently only considered during or after installation, there are often limitations on their use, such as technological constraints related to design or operation. Furthermore, alternative controls intended to provide the same or similar security countermeasure as the primary control may also be infeasible at these stages, leaving the I&C system vulnerable to cyber-attacks. The limitations associated with ‘bolting on’ security controls late in the systems engineering lifecycle can be reduced by integrating Cyber-Informed Engineering (CIE) into the process. This paper evaluates the use of CIE during the high-level design stage of a hydrogen generation project where heat and electricity are provided by a nuclear power plant. Applying CIE to this project highlighted potential cyber vulnerabilities of the initial design, leading to recommendations for process flow and I&C system design modifications to reduce, and at times eliminate, the risk from both deliberate and unintentional cyber incidents.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

A Functional All-Hazard Approach to Critical Infrastructure Dependency Analysis

The critical infrastructures protection landscape is a vast and varied pattern of independent, but interconnected infrastructure systems that are essential to the function of our modern society. The U.S. policy on critical infrastructure protection has been continually evolving since the “President’s Commission on Critical Infrastructure Protection” was published in 1997. In response to these policies, federal, state, and local governments, along with research institutions, have invested a substantial amount of time and effort into identifying and analyzing critical infrastructure, their functions, and dependencies/interdependencies to better understand their vulnerabilities. To date, the ability to assess vulnerabilities, resiliency, and priorities for protecting interdependent critical infrastructure systems from an all-hazards perspective remains a difficult problem. In this paper we introduce the All-Hazards Analysis (AHA) methodology, which provides an integrated functional basis across infrastructure systems, through the implementation of a common language and a scalable level of decomposition to effectively evaluate the resilience of interconnected infrastructure systems. AHA models infrastructure systems as directed multidimensional graphs, which enable the evaluation of cross-sector interdependencies prior to, during, and after disruptive events. Finally, and by design, AHA enables the cross linking of data taxonomies to enable more effective data sharing, such as the National Critical Functions (NCF) and Infrastructure Data Taxonomy (IDT).

02 PETROLEUM↗

Data-driven modeling of municipal water system responses to hydroclimate extremes

Sustainable western US municipal water system (MWS) management depends on quantifying the impacts of supply and demand dynamics on system infrastructure reliability and vulnerability. Systems modeling can replicate the interactions but extensive parameterization, high complexity, and long development cycles present barriers to widespread adoption. To address these challenges, we develop the Machine Learning Water Systems Model (ML-WSM) – a novel application of data-driven modeling for MWS management. We apply the ML-WSM framework to the Salt Lake City, Utah water system, where we benchmark prediction performance on the seasonal response of reservoir levels, groundwater withdrawal, and imported water requests to climate anomalies at a daily resolution against an existing systems model. The ML-WSM accurately predicts the seasonal dynamics of all components; especially during supply-limiting conditions (KGE > 0.88, PBias < ±3%). Extreme wet conditions challenged model skill but the ML-WSM communicated the appropriate seasonal trends and relationships to component thresholds (e.g., reservoir dead pool). The model correctly classified nearly all instances of vulnerability (83%) and peak severity (100%), encouraging its use as a guidance tool that complements systems models for evaluating the influences of climate on MWS performance.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Lac du Flambeau - Climate Change Resilience Initiative (Final Report)

The goals of this project were to create a comprehensive Environmental Resiliency Plan and to increase the capacity of all Lac du Flambeau Tribal Program Managers to incorporate environmental impact thinking into the everyday management of their departments. Environmental Resiliency Planning utilized current Tribal documents, which include the Integrated Resource Management Plan (IRMP), the Lac du Flambeau Tribal Emergency Management Plan (EMP), and the Lac du Flambeau Strategic Energy Plan, as guidance throughout the process. A vulnerability assessment initiated our technical process and allowed us to identify, quantify, and prioritize (or rank) the vulnerabilities in our system. This set the stage for a reduction and resilience plan as well as providing insight for revisions of existing management plans such as the Energy and Integrated Resources Management Plans

54 ENVIRONMENTAL SCIENCES↗