Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “cyber detection”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Cyber-attack detection and neutralization

The example embodiments are directed to a system and method for neutralizing abnormal signals in a cyber-physical system. In one example, the method includes receiving input signals comprising time series data associated with an asset and transforming the input signals into feature values in a feature space, detecting one or more abnormal feature values in the feature space based on a predetermined normalcy boundary associated with the asset, and determining an estimated true value for each abnormal feature value, and performing an inverse transform of each estimated true value to generate neutralized signals comprising time series data and outputting the neutralized signals.

97 MATHEMATICS AND COMPUTING↗

Stealthy Cyber Anomaly Detection On Large Noisy Multi-material 3D Printer Datasets Using Probabilistic Models

As Additive Layer Manufacturing (ALM) becomes pervasive in industry, its applications in safety critical component manufacturing are being explored and adopted. However, ALM's reliance on embedded computing renders it vulnerable to tampering through cyber-attacks. Sensor instrumentation of ALM devices allows for rigorous process and security monitoring, but also results in a massive volume of noisy data for each run. As such, in-situ, near-real-time anomaly detection is very challenging. The ideal algorithm for this context is simple, computationally efficient, minimizes false positives, and is accurate enough to resolve small deviations. In this paper, we present a probabilistic-model-based approach to address this challenge. To test our approach, we analyze current measurements from a polymer composite 3D printer during emulated tampering attacks. Our results show that our approach can consistently and efficiently locate small changes in the presence of substantial operational noise.

Yoginath, Srikanth↗

Reliable cyber-threat detection in rapidly changing environments

In some embodiments, a plurality of monitoring nodes each generate a series of current monitoring node values over time that represent a current operation of the industrial asset. An attack detection computer platform may receive the series of current monitoring node values and generate a set of current feature vectors including a current feature for capturing transients (e.g., local transients and/or global transients). The attack detection computer platform may also access an attack detection model having at least one decision boundary that was created using at least one of a set of normal feature vectors and/or a set of attacked feature vectors. The attack detection model may then be executed such that an attack alert signal is transmitted by the attack detection computer platform, when appropriate, based on the set of current feature vectors (including the current feature to capture transients) and the at least one decision boundary.

Abbaszadeh, Masoud↗

Cyber-attack detection, localization, and neutralization for unmanned aerial vehicles

In some embodiments, an Unmanned Aerial Vehicle (“UAV”) system may be associated with a plurality of monitoring nodes, each monitoring node generating a series of monitoring node values over time that represent operation of the UAV system. An attack detection computer platform may receive the series of current monitoring node values and generate a set of current feature vectors. The attack detection computer platform may access an attack detection model having at least one decision boundary (e.g., created using a set of normal feature vectors a set of attacked feature vectors). The attack detection model may then be executed and the platform may transmit an attack alert signal based on the set of current feature vectors and the at least one decision boundary. According to some embodiments, attack localization and/or neutralization functions may also be provided.

Mestha, Lalit Keshav↗

Federated Learning for Efficient Condition Monitoring and Anomaly Detection in Industrial Cyber-Physical Systems

Detecting and localizing anomalies in cyber-physical systems (CPS) has become increasingly challenging as systems grow in complexity, particularly due to varying sensor reliability and node failures in distributed environments. While federated learning (FL) offers a foundation for distributed model training, existing approaches lack mechanisms to handle these CPS-specific challenges. This paper presents an enhanced FL framework that introduces three key innovations: adaptive model aggregation based on sensor reliability, dynamic node selection for resource optimization, and Weibull-based checkpointing for fault tolerance. Our framework enables reliable condition monitoring while addressing the computational and reliability challenges of industrial CPS deployments. Experiments on NASA Bearing and Hydraulic System Datasets demonstrate superior performance over state-of-the-art FL methods, achieving 99.5% AUC-ROC in anomaly detection and maintaining accuracy under node failures. Statistical validation using Mann-Whitney (U) test confirms significant improvements (p < 0.05) in both detection accuracy and computational efficiency across diverse operational scenarios.1

Marfo, William [University of Texas at El Paso,Dep↗

Securing Smart Manufacturing: Detection of Cyber-Physical Attacks in CNC-Based Systems

As Industry 4.0 advances, the integration of computer numerical control (CNC) machines and advanced manufacturing technologies is transforming production into smart manufacturing systems that blend physical and digital processes as cyber-physical systems. However, this increased cyber-physical connectivity exposes manufacturing systems to cyber threats that can cause severe operational and financial disruptions. This paper presents a comparative study on cyber attacks and anomaly detection techniques in manufacturing, focusing on network traffic from CNC machines. The data extracted from network packets includes machine commands and control signals exchanged between the machine's interface and control system, crucial for maintaining operational integrity. We explore two types of cyber attacks, design modification and command injection, which pose substantial risks to CNC machine productivity and system integrity. Our investigation involves experiments on a real CNC system, highlighting the urgent need for effective detection mechanisms. To address these threats, we evaluate three anomaly detection methods: dynamic time warping (DTW), rolling average, and a deep learning, long short-term memory (LSTM) time-series-based autoencoder. Each is assessed for its effectiveness in identifying anomalous behaviors caused by the attacks. Our findings demonstrate the unique strengths and limitations of each detection technique, providing a deeper understanding of their applicability in realworld manufacturing environments. The comparative analysis indicates that while certain methods are highly effective against specific attack types, others offer broader applicability across different attacks. This study contributes to the accurate detection of anomalies in CNC machining processes, thereby enhancing the reliability and security of smart manufacturing systems against diverse cyber threats.

Williams, Bethanie [Tennessee Technological Univer↗

Building Intelligence with Layered Defense Using Security-Constrained Optimization and Security Risk Detection (BUILD-SOS): A Probabilistic Approach

In this project, we employ a layered protection strategy incorporating advanced optimization and detection techniques using a probabilistic approach. The probabilistic approach is not only applied when detecting cyber attacks, but also incorporated in control strategies, which greatly increases the attacking difficulties. Hackers need to understand both probabilistic detection algorithms and uncertainty modeling methods in control in order to execute any effective attacks. The end-to-end solutions enable us to provide Building Intelligence with Layered Defense using Security-Constrained Optimization and Security Risk Detection (BUILD-SOS).

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Communication Network Layer State Estimation Measurement Model for a Cyber-Secure Smart Grid

Network communication has been proven to be a very important tool and a key factor in the recent development and progress of the power grid operation. It is also considered as the foundation for the smart grid because information and communication are integrated into electricity distribution to achieve reliable and accurate knowledge of the power grid. In previous years, absorbing energy from substations and delivering it to customers was the only type of interaction we knew between utility companies and customers. Presently, the growing connections of small distributed generation units caused by the cost reduction of most of the technologies used in generation and storage of electrical energy, along with the potential benefits of renewable energy have pushed many researchers to look into the improvement of information and communication technologies (ICT) in order to ensure a bidirectional flow of power and data. Moreover, the evolution of information and communication technologies and its applications to smart grid have converted the smart grid into a cyber-physical system where vulnerabilities and additional security challenges such as cyber-threats and cyber-attacks have emerged. Previously, we have demonstrated that using machine learning-based processing on data gathered from communication networks and the power grid was a promising solution for detecting cyber threats by implementing a co-simulation of cyber-security for cross-layer strategy. Since the majority of the challenges observed can only be solved in the network communication layer, we present in this work a physics-based state estimation model of the communication network system towards enhanced cyber-physical security of the smart grid. Information integration with the previously developed machine learning model is developed, providing a enhanced cyber-physical security application for the smart grid. Easy-to-implement model, without hard-to-derive parameters, highlight potential aspects of the model for real-life applications.

Mathieu, Reynold↗

Bayesian GAN-Based False Data Injection Attack Detection in Active Distribution Grids With DERs

Advancements in information and communication technologies have revolutionized monitoring and control capabilities within smart grids. However, it also brings new vulnerabilities to data acquisition systems and state estimation functions, which attackers can subtly tamper with the measurement data through compromising the communication network. Moreover, the high penetration of renewable energy sources with the inherited characteristics of uncertainty and variability further complicates the design of effective intrusion detection systems. In this paper, a Bayesian deep learning-based approach is developed to detect cyber attacks and maintain the security of smart grids. Our method specifically addresses the prevalent issue of imbalanced data in real power systems, which arises from the predominance of normal system operations over compromised or attacked states. Employing a novel Bayesian GAN-based technique, our approach successfully discriminates between secure and compromised measurement data, even in scenarios with significant data imbalance. Furthermore, the proposed method accommodates various practical application factors, ensuring accurate intrusion detection despite the presence of measurement noise. The feasibility and effectiveness of the proposed detection mechanism are validated by testing on IEEE 13-node and 123-node test systems. Simulation results and comparisons with literature methods demonstrate the superiority of proposed cybersecurity solutions.

Bayesian GAN↗