Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Attack localization”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Comparison of Socio-Technical Threat Models

Given the adoption of emerging technologies and the increasing complexity of managing such systems with a lifecycle much shorter than that of critical infrastructure systems, there is a practical need to be able to analyze sociotechnical dependencies and their associated evolving risks. Threat models based on social influence techniques can be used to implement adversarial tactics analogous to the cyber kill chain and attested to within the MITRE ATT&CK for ICS framework including Initial Access, Persistence, Collection, and Impact. Furthermore, as with cyber disruptions, the impact of social influence threat models can have an asymmetric impact that is not spatially-localized. Finally, unlike cyber attacks with a reasonably short duration (ransomware takes days to months), social influence based attacks have the potential to persist for much longer as they are based on long-term strategic infrastructure investments within the private sector. Given the increased importance of electric vehicle charging stations as a long-term, strategic infrastructure investment within the Energy and Transportation Sectors, we provide initial results that compare the impact of a Loss of Availability (T0826) realized through cyber and social influence based threat models. The analysis employs techniques from automated reasoning and measures of network complexity to understand evolving dominance of EV payment and charging networks within geographic region of interest. Within this context, we compare the impact of a loss of availability due to ransomware versus that of loss of support due to a merger and acquisition. Results across several different metro areas will be provided.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Exploiting the Local Parabolic Landscapes of Adversarial Losses to Accelerate Black-Box Adversarial Attack

Existing black-box adversarial attacks on image classifiers update the perturbation at each iteration from only a small number of queries of the loss function. Since the queries contain very limited information about the loss, black-box methods usually require much more queries than white-box methods. We propose to improve the query efficiency of black-box methods by exploiting the smoothness of the local loss landscape. However, many adversarial losses are not locally smooth with respect to pixel perturbations. To resolve this issue, our first contribution is to theoretically and experimentally justify that the adversarial losses of many standard and robust image classifiers behave like parabolas with respect to perturbations in the Fourier domain. Our second contribution is to exploit the parabolic landscape to build a quadratic approximation of the loss around the current state, and use this approximation to interpolate the loss value as well as update the perturbation without additional queries. Since the local region is already informed by the quadratic fitting, we use large perturbation steps to explore far areas. We demonstrate the efficiency of our method on MNIST, CIFAR-10 and ImageNet datasets for various standard and robust models, as well as on Google Cloud Vision. The experimental results show that exploiting the loss landscape can help significantly reduce the number of queries and increase the success rate. Our codes are available at https://github.com/HoangATran/BABIES.

Tran, Hoang↗

CONGO²: Scalable Online Anomaly Detection and Localization in Power Electronics Networks

Rapid and accurate detection and localization of electronic disturbances simultaneously are important for preventing its potential damages and determining potential remedies. Existing anomaly detection methods are severely limited by the low accuracy, the expensive computational cost and the need for highly trained personnel. There is an urgent need for a scalable online algorithm for in-field analysis of large-scale power electronics networks. Here in this paper, we propose a fast and accurate algorithm for anomaly detection and localization of power electronics networks: stratified colored-node graph (CONGO2). This algorithm hierarchically models the change of correlated waveforms and then correlated sensors using the colored-node graph. By aggregating the change of each sensor with its neighbors’ inputs, we can spontaneously identify and localize the anomaly that cannot be detected by data collected from a single sensor. As our proposed method only focuses on the changes within a short time frame, it is highly computational efficient and only needs small data storage. Thus, our method is ideal for online and reliable anomaly detection and localization of large-scale power electronic networks. Compared to existing anomaly detection methods, our method is entirely data-driven without training data, highly accurate and reliable for wide-spectrum anomalies detection, and more importantly, capable of both detection and localization. Thus, it is ideal for infield deployment for large-scale power electronic networks. As illustrated by a distributed energy resources (DERs) power grid with 37-node, our method can effectively detect and localize various cyber and physical attacks.

42 ENGINEERING↗

Machine Learning for Anomaly Detection in Neural Network Security and SRF Cavities

This dissertation explores the development and deployment of machine learning approaches to address critical challenges in anomaly detection across two distinct domains: neural network security in federated learning settings and cavity behavior analysis in particle accelerator operations at Jefferson Lab in Newport News, Virginia. Anomaly detection identifies deviations from expected patterns, safeguarding systems in cybersecurity, industry, and research against malicious activities and failures. This dissertation demonstrates how our machine learning approaches enhance detection accuracy and efficiency in both neural network security and industrial applications. First, we investigate vulnerabilities in deep neural networks deployed in federated learning. Although federated learning preserves user privacy by training models locally, it remains vulnerable to backdoor attacks, in which malicious participants embed hidden triggers that induce targeted misbehavior. We propose a self-supervised contrastive learning framework to detect and mitigate such backdoor attacks. In our experiments, this method achieves higher detection accuracy and lower false positive rates than existing defenses, while operating without access to local model updates or original training data and thus preserving the privacy guarantees of the federated setting. Second, we address the operational reliability of superconducting radio-frequency (SRF) cavities at the Continuous Electron Beam Accelerator Facility (CEBAF). Our research leverages an unsupervised learning approach, combined with Principal Component Analysis (PCA) and k-means clustering, to identify anomalous behaviors in SRF cavities. Our method detects subtle anomalous behavior by analyzing SRF signal data. This knowledge allows for the early detection and resolution of potential faults, significantly improving the efficiency and reliability of operations. Third, we extend these insights to time-series anomaly detection more broadly. We design a contrastive-learning based model tailored to increasingly dynamic environments and academic research. This model improves detection accuracy in settings that require real-time monitoring and predictive maintenance. Our research underscores the broader applicability and impact of advanced machine learning techniques in anomaly detection. By extracting meaningful patterns from complex data, machine learning can significantly enhance security in distributed neural networks and improve the efficiency of particle accelerator operations. This dissertation serves as a stepping stone for future investigations into the vast possibilities of anomaly detection, inspiring further exploration and development of machine learning techniques in this field.

Ferguson, Hal [Old Dominion University]↗

On Stability and Electrochemical Performance of 316 Stainless Steel in Wastewater: Implications for Resource Recovery

Electrochemical nutrient recovery systems rely on stable electrode materials capable of operating in chemically complex wastewater environments. We investigated corrosion resistance and interfacial electrochemical behavior of 316 stainless steel (SS316) in a synthetic wastewater matrix representative of centrate streams, a key knowledge gap in electrochemical phosphorus recovery. A comprehensive suite of electrochemical techniques (chronoamperometry, cyclic voltammetry, potentiodynamic polarization, and electrochemical impedance spectroscopy (EIS)) and surface characterization methods (scanning electron microscopy, X-ray diffraction) were employed. Results revealed that wastewater containing typical ionic constituents (such as PO 4 3- , NH 4 + , and divalent cations) exhibited enhanced cathodic activity and the formation of a more stable, protective surface film on SS316 that mitigated chloride-induced corrosion. In contrast, SS316 in the NaCl solution showed significant susceptibility to passive layer breakdown and localized corrosion. Time-resolved EIS further confirmed improved interfacial stability and restricted charge transfer in WW over time, in stark contrast to the progressive passive layer degradation in NaCl. Surface analyses corroborated these findings, showing limited surface attack in WW compared to distinct localized corrosion features in NaCl. These findings indicate that competing ionic species in WW effectively mitigate chloride aggressiveness, enhance SS316 stability, and demonstrate improved electrode longevity and reliability for sustainable wastewater-based electrochemical phosphorus recovery applications.

36 MATERIALS SCIENCE↗

Review of Electric Vehicle Charger Cybersecurity Vulnerabilities, Potential Impacts, and Defenses

Worldwide growth in electric vehicle use is prompting new installations of private and public electric vehicle supply equipment (EVSE). EVSE devices support the electrification of the transportation industry but also represent a linchpin for power systems and transportation infrastructures. Cybersecurity researchers have recently identified several vulnerabilities that exist in EVSE devices, communications to electric vehicles (EVs), and upstream services, such as EVSE vendor cloud services, third party systems, and grid operators. The potential impact of attacks on these systems stretches from localized, relatively minor effects to long-term national disruptions. Fortunately, there is a strong and expanding collection of information technology (IT) and operational technology (OT) cybersecurity best practices that may be applied to the EVSE environment to secure this equipment. In this paper, we survey publicly disclosed EVSE vulnerabilities, the impact of EV charger cyberattacks, and proposed security protections for EV charging technologies.

33 ADVANCED PROPULSION SYSTEMS↗

WISP: Watching grid Infrastructure Stealthily through Proxies (Final Technical Report)

The complex interdependencies of cyber systems (sensors and communications), physical grids and associated electricity market operations make protecting electric power grids a significant challenge. The energy sector is constantly under new, targeted, advanced and dangerous cyber-attacks that have the potential to result in the loss of human life. These threats are further exacerbated by our need to modernize the grid. One focus of cyber security research in smart grids is the securing of the SCADA system through advanced intrusion detection systems (IDS) and bad data detection algorithms in state estimation. These methods either require full knowledge of the system topology and parameters or fail to understand the physical behaviors under attack. WISP (Watching grid Infrastructure Stealthily through Proxies) is designed to provide additional protection to the power grid using only publicly available data. In particular, WISP exploits the spatio-temporal nature of the real time locational marginal prices (LMPs), in conjunction with other information such as bids, weather, outages and load data to analyze anomalous power pricing behaviors and then correlate those observations to localize regions of interest and identify potential cyber events. WISP is non-intrusive as the tool is deployed as a service in the Cloud or on premise and provides reliable information to system operators for enhanced situational awareness, without impeding energy delivery functions. The WISP technology comprises three modules: the data-driven anomaly detection core, the vulnerability and risk analysis and the root cause analysis. The data-driven anomaly detection core performs the tasks of feature selection, anomaly detection and attack region localization. The vulnerability and risk analysis module provides system level information of the vulnerable variables and times, assisting the operators in selecting monitoring and protection nodes. The root cause analysis module takes the detection results and identifies potential operational conditions that contribute to the detected anomalies. In Phase I, we have demonstrated the feasibility and effectiveness of WISP. We developed a realistic electricity market simulator capable of generating normal and attack market data under various operational conditions. We developed a series of cyber-attack detection and analysis algorithms and evaluated them under multiple data sources. Finally, we integrated all modules into an end-to-end software, providing functions for data management, data analytics and visualization. Specifically, we have achieved: (i) real-time data acceptance from external utility interfaces with >99% acceptance rate; (ii) high performance anomaly detection algorithms with >98% detection accuracy and <0.1% false alarm rate; and (iii) ultra-low computing delay <50 milliseconds. Additionally, our team developed algorithms to identify the vulnerable variables in electricity market operations and root cause analysis functions to identify major contributors to the price spikes. These ancillary modules are necessary when deploying WISP in real world industry environment. In Phase II, we have demonstrated the effectiveness of WISP software on realistic largescale power systems. We performed red team testing for the Phase I WISP software and identified software vulnerabilities and implemented corresponding mitigation solutions. We adapted the electricity market simulator for the Texas synthetic 2000-bus system and generated datasets for the false data injection attacks. We created database and visualization interfaces for the Texas system and the ISO New England system. We performed software optimization in terms of operation efficiency, computing speed and detection accuracy. Finally, we tested the software on the Texas system and the ISO New England system and evaluated the detection performance. Overall, we achieved above 89% detection rate, below 3% false alarm rate and below 37 seconds of end-to-end detection delay.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Decentralised Reinforcement Learning for Dynamic Cyberattack Response in Microgrid Networks

Microgrids rely on communication networks for reliable operation, which makes them inherently vulnerable to cyberattacks. Such attacks can destabilise system dynamics and drive states away from their nominal operating trajectories. Although several physics-informed and machine learning-based strategies have been developed to counter these threats, the rapidly evolving cyber landscape enables adversaries to bypass static defences or rules-based mitigation approaches. This paper proposes a dynamic, online-trained and fully decentralised reinforcement learning (RL)-based cyberattack response framework to protect microgrids from evolving cyberattacks. The proposed framework deploys multiple deep Q-networks (DQNs), each associated with a distributed energy resource (DER), to enable localised and adaptive attack mitigation. In this framework, each DQN processes local voltage and frequency measurements—combined with intrusion detection system (IDS) alerts—as observations and rewards to guide decision-making. Extensive simulation studies demonstrate the robustness of the proposed framework under diverse attack scenarios and varying IDS-induced detection delays. Comparative analysis highlights its superiority over existing static or preexisting rules-based mitigation approaches. Finally, we present an analysis that shows the framework's scalability to real-life microgrids with more interacting agents.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Demystifying Cyberattacks: Potential for Securing Energy Systems With Explainable AI : Preprint

Modernization of energy systems has led to in- creased interactions among multiple critical infrastructures and diverse stakeholders making the challenge of operational decision making more complex and at times beyond cognitive capabilities of human operators. The state-of-the-art machine learning and deep learning approaches show promise of supporting users with complex decision-making challenges, such as those occurring in our rapidly transforming cyber-physical energy systems. However, successful adoption of data-driven decision support technology for critical infrastructure will be dependent on the ability of these technologies to be trustworthy and contextually interpretable. In this paper, we investigate the feasibility of implementing XAI for interpretable detection of cyberattacks in the energy system. Leveraging a proof-of-concept simulation use case of detection of a data falsification attack on a photovoltaic system using XGBoost algorithm, we demonstrate how Local Interpretable Model-Agnostic Explanations (LIME), a flavor XAI approach, can help provide contextual and actionable interpretation of cyberattack detection.

artificial intelligence↗

Legionella pneumophila modulates host energy metabolism by ADP-ribosylation of ADP/ATP translocases

The intracellular pathogen Legionella pneumophila delivers more than 330 effectors into host cells by its Dot/Icm type IV secretion system. Those effectors are essential for the biogenesis of the Legionella-containing vacuole (LCV) that permits its intracellular survival and replication. It has long been documented that the LCV is associated with mitochondria and a number of Dot/Icm effectors have been shown to target to this organelle. Yet, the biochemical function and host cell target of most of these effectors remain unknown. Here, we found that the Dot/Icm substrate Ceg3 (Lpg0080) is a mono-ADP-ribosyltransferase that localizes to the mitochondria in host cells where it attacks ADP/ATP translocases (ANTs) by ADP-ribosylation and blunts their ADP/ATP exchange activity. The modification occurs on the second arginine residue in the -RRRMMM- element, which is conserved among all known ADP/ATP carriers from different organisms. Our results reveal modulation of host energy metabolism as a novel virulence mechanism for L. pneumophila.

59 BASIC BIOLOGICAL SCIENCES↗

Dynamic, resilient virtual sensing system and shadow controller for cyber-attack neutralization

An industrial asset may have monitoring nodes (e.g., sensor or actuator nodes) that generate current monitoring node values. An abnormality detection and localization computer may receive the series of current monitoring node values and output an indication of at least one abnormal monitoring node that is currently being attacked or experiencing a fault. An actor-critic platform may tune a dynamic, resilient state estimator for a sensor node and output tuning parameters for a controller that improve operation of the industrial asset during the current attack or fault. The actor-critic platform may include, for example, a dynamic, resilient state estimator, an actor model, and a critic model. According to some embodiments, a value function of the critic model is updated for each action of the actor model and each action of the actor model is evaluated by the critic model to update a policy of the actor-critic platform.

Roychowdhury, Subhrajit↗

Operational resilience of additively manufactured parts to stealthy cyberphysical attacks using geometric and process digital twins

Cyberphysical attacks on the digital backbone of Additive Manufacturing (AM) can compromise the printed part’s functionality. They can alter features in the digital geometry to introduce geometric defects (e.g., missing fillets) or alter process parameters to create local defects (e.g., voids). Addressing the downtime, waste, and quality deterioration associated with existing solutions requires operational resilience, i.e., rapid elimination or disruption of defect formation (to retain part function) without production stoppage or part disposal (to retain yield). This need is unmet due to the inherently unpredictable nature of attack-induced alterations, lack of access to the original geometric model for identification of altered geometric features, and in-process imposition of unknown process dynamics via attack-driven alteration of real-time-uncontrolled (or exogenous) parameters. This work establishes the above-mentioned operational resilience for the first time by creating two Digital Twins (DT). The Geometric DT (Geo-DT) is based on a unique physical-field-driven soft sensor and topology optimization method. The Process Digital Twin (Pro-DT) combines local defect quantification with a novel Reinforcement Learning formulation and training method. The importance of these methodological advances and the scalability of our approach are examined on a real AM testbed. It is shown that Geo-DT can correct geometric defects without access to the original digital geometry or explicit knowledge of attack-altered geometric features. Further, Pro-DT can accelerate real-time disruption of local defects despite attack-driven imposition of unknown process dynamics. We discuss how our framework goes beyond the contemporary focus on pre-attack security and in-attack detection towards resilience for AM and beyond.

Additive Manufacturing↗

Small-Signal Angle Stability-Oriented False Data Injection Cyber-Attacks on Power Systems

The small-signal angle stability (SSAS) of a power system is determined by the property of operation points. The widely applied false data injection (FDI) cyber-attack, however, is able to stealthily mislead the optimal power flow (OPF) and thus compromise operation points, leading to damages to the SSAS margin. Here, to provide insights for cyber defenders, this paper proposes and investigates a stealthy SSAS-oriented FDI cyber-attack focusing on two attacking purposes, i.e., the SSAS margin and operation cost, with higher priority on the former one. First, this paper establishes a novel bi-level model with an implicit SSAS constraint based on a structure preserving model to compromise operation points. Then, for the SSAS interarea mode in a typical two-area system, this paper formulates closed-form expressions of how the SSAS margin and operation cost behave with respect to stealthy injections. By comparison, for the SSAS local mode in general power systems, this paper proposes a moving target cyber-attack-based hierarchical solution algorithm. Simulation results on a two-area system, a Kundur 11 bus system, and a modified IEEE 14 bus system demonstrate the significant damaging effects of the proposed SSAS-oriented FDI cyber-attack and the conflict between the two attacking purposes.

Benders decomposition↗

Synchrophasors-based Master State Awareness Estimator for Cybersecurity in Power Grid: Testbed Implementation & Field Demonstration

The integration of distributed energy resources(DERs) and expansion of complex network in the distribution grid requires an advanced distributed state estimator to monitor the grid health at micro-level. The distribution state estimator will improve the situational awareness and resiliency of distributed power system. This paper proposes a synchrophasors-based master state awareness (MSA) estimator to enhance the cybersecurity in distribution grid by providing a real-time estimation of system operating states to control center operators. In this paper, the proposed MSA estimator utilizes only phasor measurements, bus magnitudes and angles, from phasor measurement units (PMUs),deployed in local substations, to estimate the system states and also detects data integrity attacks, such as load tripping attack that disconnects the load. To validate the proof of concept, we implement the proposed methodology in cyber-physical testbed environment at the Idaho National Laboratory (INL) Electric Grid Security Testbed. Further, to address the “valley of death” and support technology commercialization, field demonstration is also performed at the Critical Infrastructure Test Range Complex(CITRC) at the INL. Our experimental results reveal a promising performance in detecting load tripping attack and providing an accurate situational awareness through an alert visualization dashboard in real-time

42 ENGINEERING↗

Cyber-Attack Detection and Accommodation for the Energy Delivery System

The goals of this project were to create a software system with a suite of key algorithms for cyber-attack detection and accommodation providing domain layer protection for critical power generation assets. Example assets included gas and steam turbines, heat recovery steam generators, and electrical generators. The aggressive algorithm goals were aimed at reducing the false positive rates in threat detection to <1% using learnings from many evolving disciplines (power turbine and generator physics, power system modeling, modern control theory, system identification, machine learning, deep learning, mathematics and data science). Additional goals for the algorithms involved localizing threats on-the-fly to know in which monitoring node the effects of attacks are present, and then providing accommodation to keep the system running uninterrupted much of the time in the presence of the attack. Accommodation had a performance goal of providing resiliency when up to 50% of monitoring nodes are in an attack state.

cybersecurity, cyber-physical↗

Precursor Analysis Report: Conti Ransomware Attack on the Health Service Executive of Ireland 2021

The Conti Ransomware Attack on the Health Service Executive (HSE) of Ireland 2021 Precursor Analysis Report leverages publicly available information about the attack and catalogs anomalous observables for each technique employed by the adversary. This analysis is based upon the methodology of the Cybersecurity for the Operational Technology Environment (CyOTE) program. The HSE provides public healthcare corporate services and operational services throughout Ireland, with critical functions including the acute national ambulance service, acute hospital service, and community healthcare service. On 14 May 2021, Conti ransomware encrypted 80 percent of the HSE’s Information Technology (IT) infrastructure across corporate, hospital, community, and electronic health record services. Conti is a ransomware-as-a-service operation that encrypts local files, uses double extortion against victims, and is facilitated by many intrusion tools. The attack forced the HSE to shut down its entire IT infrastructure to contain the ransomware, forcing employees to revert to pen and paper recordkeeping and leading to the cancellation of many appointments and procedures. The adversary also exfiltrated 700 GB of data, compromising the confidentiality of patients’ protected health information. Had the adversary targeted the COVID-19 cloud systems or operational technology assets, such as Internet of Medical Things medical devices or smart building management systems, the impact of the attack would almost certainly have been far more severe. Researchers and analysts identified 21 unique techniques (used in a sequence of 23 steps) likely utilized during the attack with a total of 1,185 observables using MITRE ATT&CK® for Industrial Control Systems. The CyOTE program assesses observables accompanying techniques used prior to the triggering event to identify opportunities to detect malicious activity. If observables accompanying the attack techniques are perceived and investigated prior to the triggering event, earlier comprehension of malicious activity can take place. Twenty-one of the identified techniques used during the attack on the HSE were precursors to the triggering event. Analysis identified 1,086 observables associated with these precursor techniques, 850 of which were assessed to have an increased likelihood of being perceived in the 57 days preceding the triggering event. The response and comprehension time could have been reduced if the observables had been identified earlier. The information gathered in this report contributes to a library of observables tied to a repository of artifacts, data sources, and technique detection references for practitioners and developers to support the comprehension of indicators of attack. Asset owners and operators can use these products if they experience similar observables or to prepare for comparable scenarios.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Cooperative Systems in Presence of Cyber-Attacks: A Unified Framework for Resilient Control and Attack Identification

Here, this paper considers a cooperative control problem in presence of unknown attacks. The attacker aims at destabilizing the consensus dynamics by intercepting the system’s communication network and corrupting its local state feedback. We first revisit the virtual network based resilient control proposed in our previous work and provide a new interpretation and insights into its implementation. Based on these insights, a novel distributed algorithm is presented to detect and identify the compromised communication links. It is shown that it is not possible for the adversary to launch a harmful and stealthy attack by only manipulating the physical states being exchanged via the network. In addition, a new virtual network is proposed which makes it more difficult for the adversary to launch a stealthy attack even though it is also able to manipulate information being exchanged via the virtual network. A numerical example demonstrates that the proposed control framework achieves simultaneously resilient operation and real-time attack identification.

97 MATHEMATICS AND COMPUTING↗

STATISTICAL ANALYSIS OF IN-SERVICE ULTRASONIC INSPECTION DATA OF WASTE TANKS AT THE SAVANNAH RIVER Site-25021

Liquid radioactive waste has been stored in large, underground carbon steel tanks of 4.92-million-liter capacity at the United States Department of Energy's Savannah River Site (SRS) in Aiken, South Carolina since the 1950s. The In-service inspection of the Savannah River Site High Level Waste tanks will be reviewed as well as Ultrasonic testing (UT) for detecting for general wall thinning, pitting and interface attack through accessible regions of the tanks. In-service inspection [1] of the Savannah River Site (SRS) High Level Waste (HLW) tanks is an essential element of a comprehensive structural integrity program. Inspection confirmed the effectiveness of chemistry and temperature controls used to preclude localized and general corrosion of the tanks. Ultrasonic testing is used to detect general wall thinning, pitting and interface attack, as well as vertically oriented cracks through inspection of a 21.59 cm (8.5-in.) wide strip extending over the accessible height of the primary tank wall.

Harris, Stephen P.↗