Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “secure data transfer”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Secure Federated Learning Across Heterogeneous Cloud and High-Performance Computing Resources: A Case Study on Federated Fine-Tuning of LLaMA 2

Federated learning enables multiple data owners to collaboratively train robust machine learning models without transferring large or sensitive local datasets by only sharing the parameters of the locally trained models. Here, in this article, we elaborate on the design of our Advanced Privacy-Preserving Federated Learning (APPFL) framework, which streamlines end-to-end secure and reliable federated learning experiments across cloud computing facilities and high-performance computing resources by leveraging Globus Compute, a distributed function as a service platform, and Amazon Web Services. We further demonstrate the use case of APPFL in fine-tuning an LLaMA 2 7B model using several cloud resources and supercomputers.

97 MATHEMATICS AND COMPUTING↗

Countering Weapons of Mass Destruction (CWMD) Device Cybersecurity Characterization Process and Profile

Countering Weapons of Mass Destruction (CWMD) recognizes that threats in the cyberspace domain continue to grow, which requires CWMD devices and supporting systems to be both cybersecure (ability to protect or defend from cyber-attacks) and resilient (ability to maintain required capability in the face of adversity) to cyber threats. The CWMD cybersecurity characterization approach in this document supports existing cyber resilience activities within the Acquisition Lifecycle Framework. Similarly, this process supports existing Department of Homeland Security Cyber Resilience Test and Evaluation activities, which consist of iterative processes, starting at the initiation of system acquisition and continuing throughout the entire device and system life cycle. Cyber resilience is the ability of an information system to continue to operate while under attack, even if in a degraded or debilitated state, and to rapidly recover operational capabilities for essential functions after a successful attack. The goal of the security characterization task for CWMD is to support the development of a CBRN device-dependent profile that aligns with device network capabilities and maps to recommended security controls to create a characterization security profile impact levels. The impact levels for CWMD devices should be characterized as Low (L), Moderate (M), High (H) to align with the low, moderate, high control baselines. To estimate the impact levels, the device’s security-related attributes are translated into the security objectives: Confidentiality (C), Integrity (I), and Availability (A), known as the CIA triad. The potential impact for each device can be L, M, H, for devices that connect and transmit different types of data and may have different impact levels. National Institute of Standards and Technology Federal Information Processing Standards Publication 199 states, “the potential impact values assigned to the respective security objectives shall be the highest value from among those security categories that have been determined for each type of information resident on the information system.” As CWMD is determining the cybersecurity impact levels of CBRN devices based on network connections and data transfers, the impact levels are aligned with the associated attributes of network connections and communications. For example, if the device system is connected to a wireless network and transmits different data types based on the confidentiality of the data, the highest impact value for each security objective should represent the device’s CIA impact level. This document is intended to be used by test managers, test team, and program managers.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Countering Weapons of Mass Destruction (CWMD) Device Cybersecurity Characterization Process and Profile

Countering Weapons of Mass Destruction (CWMD) recognizes that threats in the cyberspace domain continue to grow, which requires CWMD devices and supporting systems to be both cybersecure (ability to protect or defend from cyber-attacks) and resilient (ability to maintain required capability in the face of adversity) to cyber threats. The CWMD cybersecurity characterization approach in this document supports existing cyber resilience activities within the Acquisition Lifecycle Framework. Similarly, this process supports existing Department of Homeland Security Cyber Resilience Test and Evaluation activities, which consist of iterative processes, starting at the initiation of system acquisition and continuing throughout the entire device and system life cycle. Cyber resilience is the ability of an information system to continue to operate while under attack, even if in a degraded or debilitated state,1 and to rapidly recover operational capabilities for essential functions after a successful attack.2 The goal of the security characterization task for CWMD is to support the development of a CBRN device-dependent profile that aligns with device network capabilities and maps to recommended security controls to create a characterization security profile impact levels. The impact levels for CWMD devices should be characterized as Low (L), Moderate (M), High (H) to align with the low, moderate, high control baselines. To estimate the impact levels, the device’s security-related attributes are translated into the security objectives: Confidentiality (C), Integrity (I), and Availability (A), known as the CIA triad. The potential impact for each device can be L, M, H, for devices that connect and transmit different types of data and may have different impact levels. National Institute of Standards and Technology Federal Information Processing Standards Publication 199 states, “the potential impact values assigned to the respective security objectives shall be the highest value from among those security categories that have been determined for each type of information resident on the information system.”3 As CWMD is determining the cybersecurity impact levels of CBRN devices based on network connections and data transfers, the impact levels are aligned with the associated attributes of network connections and communications. For example, if the device system is connected to a wireless network and transmits different data types based on the confidentiality of the data, the highest impact value for each security objective should represent the device’s CIA impact level. This document is intended to be used by test managers, test team, and program managers.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Multisource Mobile Transfer Learning Algorithm Based on Dynamic Model Compression

With the development of the Internet of Things, the application of computer vision on mobile phones is becoming more and more extensive and people have higher and higher requirements for the timeliness of the recognition results returned and the processing capabilities of the mobile phone for image recognition. However, the processing capability and storage capability of the user terminal equipment cannot meet the needs of identifying and storing a large number of pictures, and the data transmission process will cause high energy consumption of the terminal equipment. At the same time, multisource deep transfer learning has outstanding performance in computer vision and image classification. However, due to the huge amount of calculation of the deep network model, it is impossible to use the existing excellent network model to realize image recognition and classification on the mobile terminal. In order to solve the abovementioned problems, we propose a multisource mobile transfer learning algorithm based on dynamic model compression, this algorithm considers the realization of multisource transfer learning computing in the case of multiple mobile device computing source domains, and the method also guarantees data privacy and security for each device (origin domain). Meanwhile, extensive experiments show that our method can achieve remarkable results in popular image classification datasets.

Gao, Peng↗

Deployment and Evaluation of SciStream on OLCF's Advanced Computing Ecosystem (ACE)

The growing demand for real-time analysis, experimental steering, and decision-making in scientific workflows has created a need for tightly coupled integrations between experimental facilities and high-performance computing (HPC) systems. The Department of Energy’s Integrated Research Infrastructure (IRI) initiative highlights data streaming as a key capability for enabling memory-to-memory data transfers, bypassing the limitations of traditional store-and-forward models. SciStream is a toolkit developed by researchers at Argonne National Laboratory (ANL) to support such streaming by addressing cross-domain security, delegated authentication, and application transparency. We deployed and evaluated SciStream on the Oak Ridge Leadership Computing Facility’s (OLCF) Advanced Computing Ecosystem (ACE) infrastructure, leveraging the Olivine OpenShift cluster and its high-bandwidth Data Streaming Nodes (DSNs) as gateway nodes. Our evaluation included synthetic streaming workloads derived from IRI science workflows, a streaming simulator, and integration with RabbitMQ to handle low-level messaging. This report documents the deployment process, performance evaluation, and challenges encountered, along with opportunities for future improvements.

97 MATHEMATICS AND COMPUTING↗

Tight-binding study of beryllium

In this work, we have applied the Naval Research Laboratory Tight-binding (NRL-TB) Method to the hcp alkaline-earth metal Beryllium. This approach consists of fitting to energy band and total energy data generated by the Linearized Augmented Plane Wave (LAPW) for the fcc, bcc, sc, and hcp structures as a function of volume. First, we found that using the Generalized Gradient Approximation (GGA) for the input data secures a better agreement to experimental volumes than the LDA. Second, we found that including small volumes to the fit is needed to get TB parameters that are transferable enough to successfully predict the energies of structures that were not fitted, and to perform molecular dynamics (MD) simulations. The non-orthogonal Hamiltonian obtained, is successful in correctly predicting the hcp lattice as the ground state of Be and finding eight other structures, that were not fitted to LAPW, positioned at higher energies. In addition, the NRL-TB produces accurate energy bands, densities of states, elastic constants, the Bain path and several quantities derived from MD simulations.

36 MATERIALS SCIENCE↗

RouteE: A Vehicle Energy Consumption Prediction Engine

The emergence of connected and automated vehicles and smart cities technologies create the opportunity for new mobility modes and routing decision tools, among many others. To achieve maximum mobility and minimum energy consumption, it is critical to understand the energy cost of decisions and optimize accordingly. The Route Energy prediction model (RouteE) enables accurate estimation of energy consumption for a variety of vehicle types over trips or sub-trips where detailed drive cycle data are unavailable. Applications include vehicle route selection, energy accounting and optimization in transportation simulation, and corridor energy analyses, among others. The software is a Python package that includes a variety of pre-trained models from the National Renewable Energy Laboratory (NREL). However, RouteE also enables users to train custom models using their own data sets, making it a robust and valuable tool for both fast calculations and rigorous, data-rich research efforts. The pre-trained RouteE models are established using NREL's Future Automotive Systems Technology Simulator paired with approximately 1 million miles of drive cycle data from the Transportation Secure Data Center, resulting in energy consumption behavior estimates over a representative sample of driving conditions for the United States. Validations have been performed using on-road fuel consumption data for conventional and electrified vehicle powertrains. Transferring the results of the on-road validation to a larger set of real-world origin-destination pairs, it is estimated that implementing the present methodology in a green-routing application would accurately select the route that consumes the least fuel 90% of the time. The novel machine learning techniques used in RouteE make it a flexible and robust tool for a variety of transportation applications.

47 OTHER INSTRUMENTATION↗

Deep Cyber-Physical Situational Awareness for Energy Systems: A Secure Foundation for Next-Generation Energy Management

This document provides the final report for the CYPRES project. The purpose is (1) to highlight and summarize its major accomplishments and (2) to provide guidance on how its outcomes have informed and can inform important additional research and technology transfer. The goal of CYPRES was the research, development, and demonstration of a security-oriented next generation cyber-physical EMS for electric power systems that detects malicious and abnormal events through the fusion of cyber and physical data. To achieve this, the CYPRES project team researched, developed, and built a prototype of the solution, referred to as the CYPRES EMS. The CYPRES EMS is a proof-of-concept cyber-physical platform that demonstrates the management of the energy system, communications, security, and cyber-physical grid modeling and analytics. As part of the capabilities of the CYPRES EMS, the team designed and developed a suite of power system applications for monitoring, risk analyses, detection, and control that are inherently cyberaware. At its core, the project aimed to research, develop, and demonstrate a security-oriented next-generation cyber-physical Energy Management System (EMS) capable of detecting malicious and abnormal events through the innovative fusion of cyber and physical data. This approach represents a fundamental shift from traditional EMS, reimagining how critical infrastructure can be protected through unified cyber-aware and physics-aware secure data flow pipelines. The project’s cornerstone deliverable, the CYPRES EMS, serves as a proof-of-concept cyber-physical platform that revolutionizes the management of energy systems, communications, security, and cyber-physical grid modeling and analytics. This prototype implements a comprehensive suite of power system applications for monitoring, risk analyses, detection, and control, all designed with inherent cyber awareness. The system’s architecture extends from end-devices in the field through to control center applications, establishing a secure and resilient control framework that addresses the challenges posed by diverse devices of unknown trustworthiness connecting to modern power systems. Through this innovative approach to deep cyber-physical situational awareness, the CYPRES project not only advances the state-of-the-art in energy infrastructure protection but also establishes a new paradigm for how EMS can be designed, deployed, and operated in an increasingly complex threat landscape. The findings and developments from this project provide crucial insights for stakeholders across the energy sector, offering a blueprint for enhancing the reliability and resilience of our nation’s critical energy infrastructure in the face of evolving cyber threats.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Adoption of a token-based authentication model for the CMS Submission Infrastructure

The CMS Submission Infrastructure (SI) is the main computing resource provisioning system for CMS workloads. A number of HTCondor pools are employed to manage this infrastructure, which aggregates geographically distributed resources from the WLCG and other providers. Historically, the model of authentication among the diverse components of this infrastructure has relied on the Grid Security Infrastructure (GSI), based on identities and X509 certificates. In contrast, commonly used modern authentication standards are based on capabilities and tokens. The WLCG has identified this trend and aims at a transparent replacement of GSI for all its workload management, data transfer and storage access operations, to be completed during the current LHC Run 3. As part of this effort, and within the context of CMS computing, the Submission Infrastructure group is in the process of phasing out the GSI part of its authentication layers, in favor of IDTokens and Scitokens. The use of tokens is already well integrated into the HTCondor Software Suite, which has allowed us to fully migrate the authentication between internal components of SI. Additionally, recent versions of the HTCondor-CE support tokens as well, enabling CMS resource requests to Grid sites employing this CE technology to be granted by means of token exchange. After a rollout campaign to sites, successfully completed by the third quarter of 2022, the totality of HTCondor CEs in use by CMS are already receiving Scitoken-based pilot jobs. On the ARC CE side, a parallel campaign was launched to foster the adoption of the REST interface at CMS sites (required to enable token-based job submission via HTCondor-G), which is nearing completion as well. In this contribution, the newly adopted authentication model will be described. We will then report on the migration status and final steps towards complete GSI phase out in the CMS SI.

Pérez-Calero Yzquierdo, Antonio↗

2020 Postclosure Groundwater Monitoring and Inspection Report, Central Nevada Test Area, Subsurface Corrective Action Unit 443

This report presents the groundwater monitoring data collected by the U.S. Department of Energy (DOE) Office of Legacy Management (LM) from the Central Nevada Test Area (CNTA), Nevada, Site, Subsurface Corrective Action Unit (CAU) 443 in Nye County, Nevada (Figure 1). The CNTA is the site of an underground nuclear test in 1968 that resulted in residual contamination near the detonation depth of 3200 feet (ft); the contamination requires long-term monitoring. Responsibility for the environmental restoration and long-term monitoring was transferred from DOE’s National Nuclear Security Administration, Nevada Field Office, to LM on October 1, 2006. The environmental restoration and site closure process were completed in 2015 in accordance with the amended 1996 Nevada Federal Facility Agreement and Consent Order (FFACO) (State of Nevada et al. 1996, as amended) and all applicable Nevada Division of Environmental Protection (NDEP) policies and regulations. The Closure Report, Central Nevada Test Area, Subsurface Corrective Action, Unit 443 (DOE 2018), also called the Closure Report, originally was completed in January 2016 and revised in October 2018; it describes LM’s plan for long-term postclosure monitoring. This includes monitoring of the radioisotopes of interest and water elevations, inspecting the site and maintaining the institutional controls (ICs), evaluating and reporting data, and documenting the site’s records and data management processes (DOE 2018).

54 ENVIRONMENTAL SCIENCES↗

Towards an IPv6-only WLCG: More successes in reducing IPv4

The Worldwide Large Hadron Collider Computing Grid (WLCG) community’s deployment of dual-stack IPv6/IPv4 on its worldwide storage infrastructure has been very successful. Dual-stack is not, however, a viable longterm solution; the HEPiX IPv6 Working Group has focused on studying where and why IPv4 is still being used, and how to flip such traffic to IPv6. The agreed end goal is to turn IPv4 off and run IPv6-only over the wide-area network to simplify both operations and security management.This paper reports our work since the CHEP2023 conference. Firstly, we present our campaign to deploy IPv6 on CPU services and Worker Nodes, with a deadline of end of June 2024. Then, the WLCG Data Challenge (DC24) performed in February 2024 was an excellent opportunity to observe the percentage of data transfers carried by IPv6. We observed the predominance of IPv6 in data transfers during DC24 and were able to understand yet more reasons for the use of IPv4 and areas for remedial action.The paper ends with the working group’s plans for moving WLCG to “IPv6- only”. One aspect of this is the possible automated use of IPv6-only clients configured with a customer-side translator, or CLAT, together with a deployment of NAT64 using what is often known as “IPv6-Mostly”, enabling IPv6-only sites to connect to non-WLCG IPv4-only services.

Attebury, Garhan [U. Nebraska, Lincoln]↗

Airborne hyperspectral imaging of nitrogen deficiency on crop traits and yield of maize by machine learning and radiative transfer modeling

Nitrogen is an essential nutrient that directly affects plant photosynthesis, crop yield, and biomass production for bioenergy crops, but excessive application of nitrogen fertilizers can cause environmental degradation. To achieve sustainable nitrogen fertilizer management for precision agriculture, there is an urgent need for nondestructive and high spatial resolution monitoring of crop nitrogen and its allocation to photosynthetic proteins as that changes over time. Here, we used visible to shortwave infrared (400–2400 nm) airborne hyperspectral imaging with high spatial (0.5 m) and spectral (3–5 nm) resolutions to accurately estimate critical crop traits, i.e., nitrogen, chlorophyll, and photosynthetic capacity (CO 2 -saturated photosynthesis rate, V max,27 ), at leaf and canopy scales, and to assess nitrogen deficiency on crop yield. We conducted three airborne campaigns over a maize (Zea mays L.) field during the growing season of 2019. Physically based soil-canopy Radiative Transfer Modeling (RTM) and data-driven approaches i.e. Partial-Least Squares Regression (PLSR) were used to retrieve crop traits from hyperspectral reflectance, with ground truth of leaf nitrogen, chlorophyll, V max,27 , Leaf Area Index (LAI), and harvested grain yield. To improve computational efficiency of RTMs, Random Forest (RF) was used to mimic RTM simulations to generate machine learning surrogate models RTM-RF. The results show that prior knowledge of soil background and leaf angle distribution can significantly reduce the ill-posed RTM retrieval. RTM-RF achieved a high accuracy to predict leaf chlorophyll content (R 2 = 0.73) and LAI (R 2 = 0.75). Meanwhile, PLSR exhibited better accuracy to predict leaf chlorophyll content (R 2 = 0.79), nitrogen concentration (R 2 = 0.83), nitrogen content (R 2 = 0.77), and V max,27 (R 2 = 0.69) but required measured traits for model training. We also found that canopy structure signals can enhance the use of spectral data to predict nitrogen related photosynthetic traits, as combining RTM-RF LAI and PLSR leaf traits well predicted canopy-level traits (leaf traits × LAI) including canopy chlorophyll (R 2 = 0.80), nitrogen (R 2 = 0.85) and V max,27 (R 2 = 0.82). Compared to leaf traits, we further found that canopy-level photosynthetic traits, particularly canopy V max,27 , have higher correlation with maize grain yield. This study highlights the potential for synergistic use of process-based and data-driven approaches of hyperspectral imaging to quantify crop traits that facilitate precision agricultural management to secure food and bioenergy production.

54 ENVIRONMENTAL SCIENCES↗

GeoCricket

SAND2025-12229O Geospatial Critical Infrastructure and Census Data Stockpile Tool (GeoCricket) is a set of functions that collect critical infrastructure and census data for use in the Resilient Node Cluster Analysis Tool (ReNCAT) and Quantum Geographic Information System Social Burden Calculator. It can also act to inform other place-based work. The code queries public-facing Representational State Transfer (REST) servers to collect geospatial data related to a specific area. It then exports that data as standard geographic information system file types or as a .csv file. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Haines, John↗

Sparse-Data Deep Learning Strategies for Radiographic Non-Destructive Testing

Radiography is an imaging technique used in a variety of applications, such as medical diagnosis, airport security, and nondestructive testing. We present a deep learning system for extracting information from radiographic images. We perform various prediction tasks using our system, including material classification and regression on the dimensions of a given object that is being radiographed. Our system is designed to address the sparse-data issue for radiographic nondestructive testing applications. It uses a radiographic simulation tool for synthetic data augmentation, and it uses transfer learning with a pre-trained convolutional neural network model. Using this system, our preliminary results indicate that the object geometry regression task saw an improvement of 70% in the R-squared value when using a multi-regime model. In addition, we increase the performance of the object material classification tasks by utilizing data from different imaging systems. In particular, using neutron imaging improved the material classification accuracy by 20% when compared to x-ray imaging.

convolutional neural networks↗

An Overview of the Usefulness of Machine Learning Techniques on Network Packet Data

Understanding the health and behavior of a computer network allows for better network efficiency and security. We present an overview of various machine learning techniques for classifying network packet data via packet metadata. While some classical machine learning approaches achieve reasonable results, the most accurate classification can be achieved with deep learning. On the four data sets studied herein, a basic deep learning model achieved at or near 100\% classification accuracy. We also propose a method for determining variable importance as a means for potential transfer learning applications to classifying yet unseen network packet data.

97 MATHEMATICS AND COMPUTING↗

Distributed ADMM Using Private Blockchain for Power Flow Optimization in Distribution Network With Coupled and Mixed-Integer Constraints

The optimization problem for scheduling distributed energy resources (DERs) and battery energy storage systems (BESS) integrated with the power grid is important to minimize energy consumption from conventional sources in response to demand. Conventionally this optimization problem is solved in a centralized manner, limiting the size of the problem that can be solved and creating a high communication overhead because all the data is transferred to the central controller. These limitations are addressed by the proposed distributed consensus-based alternating direction method of multiplier (DC-ADMM) optimization algorithm, which decomposes the optimization problem into subproblems with private cost function and constraints. The distribution feeder is partitioned into low coupling subnetworks/regions, which solves the private subproblem locally and exchanges information with the neighboring regions to reach consensus. The relaxation strategy is employed for mixed-integer and coupled constraints introduced in the optimal power flow (OPF) problem by stationary and transportable BESS because DC-ADMM convergence is only guaranteed for strict convex problems. The information exchange and synchronization between subnetworks/regions are vital for distributed optimization. In this work, both of these aspects are addressed by the blockchain. The smart contract deployed on the blockchain network acts as a mediator for secure data exchange and synchronization in distributed computation. The blockchain-based distributed optimization problem’s effectiveness is tested for a 0.5-MW laboratory microgrid for one hour ahead and day-ahead for the IEEE 123-bus and EPRI J1 test feeders, and results are compared with a centralized solution.

25 ENERGY STORAGE↗

Bayesian Estimation of Oscillator Parameters: Toward Anomaly Detection and Cyber-Physical System Security

Cyber-physical system security presents unique challenges to conventional measurement science and technology. Anomaly detection in software-assisted physical systems, such as those employed in additive manufacturing or in DNA synthesis, is often hampered by the limited available parameter space of the underlying mechanism that is transducing the anomaly. As a result, the formulation of anomaly detection for such systems often leads to inverse or ill-posed problems, requiring statistical treatments. Here, we present Bayesian inference of unknown parameters associated with a generic actuator considered as a representative vital element of a cyber-physical system. Via a series of experimental input-output measurements, a transfer function for the actuator is obtained numerically, which serves as our model for the proposed method. Linear, nonlinear, and delayed dynamics may be assumed for the actuator response. By devising a code-based malicious signal, we study the efficacy of Bayesian inference for its potential to produce a detection, including uncertainty quantification, with a remarkably small number of input data points. Our approach should be adaptable to a variety of real-time cyber-physical anomaly detection scenarios.

47 OTHER INSTRUMENTATION↗

Operational Evolution of FTS3: A DevOps Driven Approach to Elastic Operations

The File Transfer Service (FTS3) is a distributed data movement service developed at CERN and widely used to transfer data across the Worldwide LHC Computing Grid (WLCG). At Fermilab, FTS3 supports data transfers for multiple experiments, including Intensity Frontier experiments such as DUNE, enabling reliable data movement between WebDAV endpoints in Europe and the Americas.​ At CHEP 2021, we reported on the initial containerized deployment of FTS3 on OKD, the community Kubernetes distribution of Red Hat OpenShift. In this work, we present the subsequent evolution of this deployment, focusing on new operational capabilities introduced to improve scalability, robustness, and long-term maintainability.​ We describe the adoption of more secure and reproducible container build workflows, the integration of DevOps-driven operational practices, and enhancements in monitoring and automation. A key new result is the introduction of horizontal scaling and elastic resource management, allowing FTS3 components to dynamically adapt to workload variations while maintaining service reliability. We also discuss improvements in fault tolerance and operational procedures derived from production experience.​ Finally, we summarize lessons learned from operating FTS3 as a Kubernetes-native service and outline how these developments have improved the resilience and efficiency of data movement operations at Fermilab.

Munoz Flores, Victor Leopoldo [Fermilab]↗