Uncertainty-Matching Graph Neural Networks to Defend Against Poisoning Attack
Explore the source record for details and available documents.
SEARCH · Engineering Papers
Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.
Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.
Explore the source record for details and available documents.
This paper explores the detection and localization of cyber-attacks on power systems, focusing on comparing conventional machine learning (ML) and deep learning methods, and graph neural network (GNN)-based techniques. We assess the detection accuracy of these approaches and their potential to pinpoint the locations of specific buses under attack. Given the demonstrated success of GNNs in other time series anomaly detection applications, we aim to evaluate their performance within the context of power systems cyber-attack. Utilizing the IEEE 68-bus system, we simulated four types of attacks to test the selected approaches. Our results indicate that GNN-based methods outperform conventional machine learning and deep learning models in detection. Additionally, GNNs show promise in accurately localizing attacks for simple scenarios, although they still face challenges in more complex cases.
STIG is a revolutionary cybersecurity tool developed by researchers at the U. S. Department of Energy's Idaho National Laboratory and it is a software that allows utility owners and operators to easily visualize, create, and edit cyberthreat intelligence information. STIG uses Structured Threat Information eXpression (STIX) and converts complex data on cybersecurity vulnerabilities into a visualization that is easy to understand and act on. With STIG, utility owners and operators have a common system for sharing threat intelligence information, thus increasing the chances of detecting and mitigating cyber exploits before they lead to a cyberattack.
Distributed energy resources (DER) contribute to the operational stability of the larger power grid both at utility-scale as well as commercial and residential scales in aggregated forms. These DER in-turn are susceptible to increasing cyber threats. An adversary can plug into the same local network that a field photovoltaic (PV) system uses to interconnect its data loggers and inverters and manipulate certain measurements collected from the network or trick existing irradiance and inverter readings through false data injection attacks (FDIA). Control routines that rely on these measurements can propagate the false data, impacting critical decisions that result in a suboptimal operation or even cause intentional harm leading to inverter-tripping or unscheduled loads that need to be shed. To detect FDIA in PV systems, the paper introduces an attention-based graph neural network with node embeddings and applied it to a simple prototypical DC-coupled microgrid with PV, energy storage, and load. The algorithm shows a detection accuracy of up to 98.95%. The proposed FDIA detection technique will provide micro-grid operators with an effective method to safeguard their systems, guaranteeing the secure and reliable operation.
Distributed control has been extensively studied for a DC microgrid to coordinate multiple grid assets where each asset can generate its own control decisions based on communications within its neighborhood. Nevertheless, such a control strategy usually has a strong dependence on active information exchange and needs to always maintain a pre-determined communication graph. This makes it vulnerable to cyber attacks, especially denial of service (DoS) attacks that block communication channels that effectively change the communication graph. In this paper, we study two potential impacts of DoS attacks: the inability to maintain steady-state and dynamical generation-demand balance, i.e. the feasibility and stability issues. We develop a mathematical model to describe the cyber-induced system steady-state and dynamical performance. The model reveals the impacts of DoS attacks and enables formal analysis. Case studies are shown to verify the proposed work.
Here, we study the problem of designing a distributed observer for an LTI system over a time-varying communication graph. The limited existing work on this topic imposes various restrictions either on the observation model or on the sequence of communication graphs. In contrast, we propose a single-time-scale distributed observer that works under mild assumptions. Specifically, our communication model only requires strong-connectivity to be preserved over non-overlapping, contiguous intervals that are even allowed to grow unbounded over time. We show that under suitable conditions that bound the growth of such intervals, joint observability is sufficient to track the state of any discrete-time LTI system exponentially fast, at any desired rate. We also develop a variant of our algorithm that is provably robust to worst-case adversarial attacks, provided the sequence of graphs is sufficiently connected over time. The key to our approach is the notion of a "freshness-index" that keeps track of the age-of-information being diffused across the network. Such indices enable nodes to reject stale estimates of the state, and, in turn, contribute to stability of the error dynamics.
This report includes two main accomplishments of the peer-to-peer communication control for resilient operation of networked microgrids project in FY24, which include a scheme for cyberattack-aware coordination of networked microgrids for supporting voltages of bulk power systems and a scheme for price signal-based operations of EV-rich networked microgrids with mixed ownership. First, the cyberattack-aware scheme enables networked microgrids to distributedly determine the amount of reactive power injection to support the voltage of bulk power system (BPS) in a fair manner. In this scheme, a risk-informed algorithm is presented to generate the peer-to- peer (P2P) communication graph with minimal risk of attack on communication links. To deal with cyberattacks on MG controllers, the resilient consensus algorithm (CA) is utilized for MG controllers to robustly estimate the total reactive power headroom, from which the MGs can accurately provide the needed amount of reactive power injection for supporting the voltage of BPS. The CA implementation and performance within the P2P communication framework are demonstrated on the IEEE 39-bus system with 6 microgrids contained in the distribution feeder under different cyberattack scenarios. Second, the price-based scheme enables the usage of the real-time price signal for the operations of electric vehicle (EV)-rich networked-microgrids with mixed ownership, in which not all the microgrids can communicate with the distribution system operator (DSO). In this scheme, a max consensus is introduced to enable the real-time price signal to be propagated from the DSO to all the microgrids, from which each microgrid controller will manage the DERs to balance the load demand and the power injection from the EV charging stations within its microgrid. Numerical results over one day with 288 slots of 5-minute intervals on the modified 123-node test feeder including 3 microgrids with high penetration of EV are presented to evaluate how the price signal affects the operations of networked microgrids under different charging strategies of the EV charging stations. The result indicates that our proposed EVCS (dis)charging strategy, which leverages the flexibility of EVs to support the grid through discharging during peak demand, proves to be a cost-effective solution that reduces operational costs while improving the social welfare of EV charging.
Call graph or caller-callee relationships have been used for various kinds of static program analysis, performance analysis and profiling, and for program safety or security analysis such as detecting anomalies of program execution or code injection attacks. However, different tools generate call graphs in different formats, which prevents efficient reuse of call graph results. In this paper, we present an approach of using ontology and resource description framework (RDF) to create knowledge graphs for specifying call graphs to facilitate the construction of full-fledged and complex call graphs of computer programs, realizing more interoperable and scalable program analyses than conventional approaches. We create a formal ontology-based specification of call graph information to capture concepts and properties of both static and dynamic call graphs so different tools can collaboratively contribute to more comprehensive analysis results. Our experiments show that ontology enables merging of call graphs generated from different tools and flexible queries using a standard query interface. Index Terms—Callgraph, ontology, knowl
This is a poster for the 2023 intern poster session demonstrating the most effective way to use STIG, a publicly available graph tool, for more efficient cybersecurity. Responses to cyber attacks can be implemented sooner if those shared are more generally applicable.
Investigations are reported for the determination of aerodynamic effects of reducing the thickness of the reusable surface insulation located along the sides of the shuttle orbiter in order to allow weight reduction in the nose region. Six-component aerodynamic force and moment data were obtained at Mach numbers from 1.5 to 4.6 over an angle of attack range from about -1 deg to 28 deg. Additional tests were made over an angle of sideslip range from -6 deg to 6 deg at selected angles of attack. Test results are presented in graph and tables.
In cybersecurity, the ability to efficiently analyze and respond to vulnerabilities, weaknesses, attack patterns, and threat tactics is critical for effective defense strategies. With the increasing complexity and volume of cybersecurity data, traditional methods of querying and retrieving information are often inadequate. To address this challenge, we implemented Retrieval-Augmented Generation (RAG) systems—CyRAG and GraphCyRAG—that integrate large language models (LLMs) with both structured data from relational databases and knowledge graphs such as Neo4j. CyRAG is designed to handle structured data, focusing on CVE (Common Vulnerabilities and Exposures) and CWE (Common Weakness Enumeration) entities to generate accurate and context-rich responses. In contrast, GraphCyRAG leverages Neo4j knowledge graphs to retrieve interconnected information from CVE, CWE, CAPEC (Common Attack Pattern Enumeration and Classification), and ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) datasets. By utilizing Neo4j’s graph-based framework, GraphCyRAG enables deeper traversal of relationships between vulnerabilities and attack patterns, providing cybersecurity analysts with more comprehensive insights into potential attack vectors and mitigation strategies. Our preliminary results demonstrate that integrating knowledge graphs with RAG significantly enhances both the accuracy and depth of threat analysis, allowing for the retrieval of dynamic, real-time data and the generation of contextually aware responses. This approach helps analysts uncover hidden relationships between cyber entities, predict exploit paths, and prioritize mitigation efforts effectively. The integration of RAG with cybersecurity knowledge graphs represents a significant advancement in cybersecurity threat intelligence, enabling more informed decision-making and stronger defense strategies.
The experimental procedure and aerodynamic force and moment measurements for wind tunnel testing of the three lifting surface configuration (TLC) are described. The influence of nonelliptical lift distributions on lift, drag, and static longitudinal stability are examined; graphs of the lift coefficient versus angle of attack, the pitching moment coefficient, drag coefficient, and lift to drag ratio versus lift coefficient are provided. The TLC data are compared with the conventional tail-aft configuration and the canard-wing configuration; it is concluded that the TLC has better lift and high-lift drag characteristics, lift to drag ratio, and zero-lift moments than the other two configurations. The effects of variations in forward and tail wind incidence angles, gap, stagger, and forward wind span on the drag, lift, longitudinal stability, and zero-lift moments of the configuration are studied.
This paper presents a continuous-time resilient distributed optimization algorithm based on competitive interaction design method on connected graphs in the presence of adversaries. Here, the competitive interaction method allows us to design a network that protects the multi-agent systems from adversaries without requiring high network connectivity. In addition, the proposed algorithm does not require the global information about the number of adversaries. First, we show that the proposed distributed algorithm solves the resilient distributed optimization problem with no attack on the communication links. Second, we show that the proposed continuous-time distributed optimization algorithm on connected graphs converges to the small neighborhood of the optimal solution in the presence of cyber-attacks onto the communication channel. Simulations are presented to illustrate our theoretical results.
The lateral directional characteristics of an F-18 aircraft was investigated. Aerodynamic derivatives associated with pure roll rate, or the 'p' derivatives were obtained. The model is described and the procedures used to obtain and correct the data, and a graphical presentation of the results are presented. These results include graphs of the lateral directional static stability derivatives versus angle of attack, and the lateral directional force and moment coefficients versus nondimensional roll rate. Results are presented for several configurations including complete, complete without vertical tails, complete without horizontal tails, fuselage wing and fuselage alone. Each of these configuations was tested with and without wing leading edge extensions. The basic control surfaces were deflected and the results were investigated.
This is a submission for the 2022 Intern Poster Session. The abstract of the poster is: Smart buildings are getting more common, and so are hackers that target them. The physical systems in our businesses and homes are now vulnerable to cyber attacks. Using STIG, an INL program that turns cybersecurity data into graphs, buildings can be better protected.
Network traces are considered a primary source of information to researchers, who use them to investigate research problems such as identifying user behavior, analyzing network hierarchy, maintaining network security, classifying packet flows, and much more. However, most organizations are reluctant to share their data with a third party or the public due to privacy concerns. Therefore, data anonymization prior to sharing becomes a convenient solution to both organizations and researchers. Although several anonymization algorithms are available, few of them allow sufficient privacy (organization need), acceptable data utility (researcher need), and efficient data analysis at the same time. This article introduces a condensation-based differential privacy anonymization approach that achieves an improved tradeoff between privacy and utility compared to existing techniques and produces anonymized network trace data that can be shared publicly without lowering its utility value. Our solution also does not incur extra computation overhead for the data analyzer. A prototype system has been implemented, and experiments have shown that the proposed approach preserves privacy and allows data analysis without revealing the original data even when injection attacks are launched against it. When anonymized datasets are given as input to graph-based intrusion detection techniques, they yield almost identical intrusion detection rates as the original datasets with only a negligible impact.
This work proposes a deep graph learning framework to identify, locate, and classify power, cyber, and cyber power events at the distribution system level. The proposed algorithm jointly exploits spatial, temporal, and node-level cyber and physical data features. The developed graph neural network, together with a deep autoencoder, utilizes physical measurements from distribution level phasor measurement units and cyber data from communication network logs. The spatial structure of the synchrophasor measurements and network is incorporated through a weighted adjacency matrix. The temporal structure is incorporated by defining a spatial operation in the gated recurrent unit. This spatio-temporal learning element resides inside a power event detection, localization, and classification module that provides the degree of confidence for an event label. To accurately pinpoint the location of an event to the nearest bus equipped with a measurement unit, a combination of squared error and proximity score is utilized. Also included is a cyber event detection module that employs heteroskedasticity to analyze the significance of various cyber features during different types of attacks. Finally, a dual-bit cyber-power decision table determines the nature of the event. The proposed method is validated on two distribution systems modeled in OPAL-RT/Hypersim with limited phasor measurement units for different possible physical and cyber events. Further analyses include comparison with other state-of-the-art methods and validation in the presence of measurement noise. As a result, our method outperforms existing approaches and achieves an average detection accuracy of 97.97%, F1-score of 96.88%, precision of 96.53%, and recall of 98.57%.
An analysis of the influence of engine response characteristics on the approach and landing of an externally blown flap aircraft was conducted using flight simulator facilities. The configuration of the aerodynamic model is described. The aerodynamic characteristics as a function of angle of attack, thrust coefficient, and flap deflection are presented in tabular form and as graphs.