Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Attack localization”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Dynamical chemistry: non-equilibrium effective actions for reactive fluids

Abstract We present two approaches for describing chemical reactions taking place in fluid phase. The first method mirrors the usual derivation of the hydrodynamic equations of motion by relating conserved—or to account for chemical reactions, non-conserved—currents to local-equilibrium parameters. The second method involves a higher-brow approach in which we attack the same problem from the perspective of non-equilibrium effective field theory (EFT). Non-equilibrium effective actions are defined using the in–in formalism on the Schwinger–Keldysh contour and are therefore capable of describing thermal fluctuations and dissipation as well as quantum effects. The non-equilibrium EFT approach is especially powerful as all terms in the action are fully specified by the symmetries of the system; in particular the second law of thermodynamics does not need to be included by hand, but is instead derived from the action itself. We find that the equations of motion generated by both methods agree, but the EFT approach yields certain advantages. To demonstrate some of these advantages we construct a quadratic action that is valid to very small distance scales—much smaller than the scales at which ordinary hydrodynamic theories break down. Such an action captures the full thermodynamic and quantum behavior of reactions and diffusion at quadratic order. Finally, taking the low-frequency and low-wavenumber limit, we reproduce the linearized version of the well-known reaction–diffusion equations as a final coherence check.

Mechanics↗

Intergranular corrosion of Ni-30Cr in high-temperature hydrogenated water after removing surface passivating film

Abstract High-resolution transmission electron microscopy and atom probe tomography are used to characterize the initial passivation and subsequent intergranular corrosion of degraded grain boundaries in a model Ni-30Cr alloy exposed to 360 °C hydrogenated water. Upon initial exposure for 1000 h, the alloy surface directly above the grain boundary forms a thin passivating film of Cr 2 O 3 , protecting the underlying grain boundary from intergranular corrosion. However, the metal grain boundary experiences severe Cr depletion and grain boundary migration during this initial exposure. To understand how Cr depletion affects further corrosion, the local protective film was sputtered away using a glancing angle focused ion beam. Upon further exposure, the surface fails to repassivate, and intergranular corrosion is observed through the Cr-depleted region. Through this combination of high-resolution microscopy and localized passive film removal, we show that, although high-Cr alloys are resistant to intergranular attack and stress corrosion cracking, degradation-induced changes in the underlying metal at grain boundaries make the material more susceptible once the initial passive film is breached.

(S)TEM↗

Emulation and detection of physical faults and cyber-attacks on building energy systems through real-time hardware-in-the-loop experiments

The increasing use of remote or mobile access, integrated wearable technologies, data exchange, and cloud-based data analytics in modern smart buildings is steering the building industry towards open communication technologies. The increased connectivity and accessibility could lead to more cyber-attacks in smart buildings. On the other hand, physical faults (e.g., HVAC -heating, ventilation, and air-conditioning faults) may have similar adverse impacts as those from the cyber-attacks on building energy systems, such as occupant discomfort, energy wastage, and equipment downtime. However, current physical behavior-based anomaly detection methods fail to differentiate between cyber-attacks and physical faults in building energy systems. Moreover, the challenge in collecting real-world threat data with ground truth has led researchers to rely on numerical models with user-defined assumptions, which may not accurately reflect real-world conditions due to the lack of in-situ experimental datasets. To address these challenges and gaps, this paper presents a flexible hardware-in-the-loop (HIL) testbed for generating cyber-attack and physical fault datasets and demonstrating threat detection algorithms in a real building automation system (BAS) environment. This testbed combines hardware (i.e., real BAS with local HVAC controllers and a physical network) with software (i.e., high-fidelity models to represent behaviors of building envelope and HVAC energy systems), enabling emulations of realistic threats. Five HIL experiments, including one baseline without any threats, two with physical faults, and two with cyber-attacks, were conducted to generate datasets containing detailed network traffic and system states. A joint classification framework, incorporating a network analyzer and a physical HVAC fault detector, was proposed to automatically detect cyber-physical abnormalities on BAS at both the network and the physical HVAC levels. The network analyzer comprises a conditional random fields (CRF) based command validator and a statistics-based detection strategy. The fault detector employs a weather and schedule-based pattern matching and feature-based principal component analysis (WPM-FPCA) method. Evaluation of the classification using four metrics from the multi-class confusion matrix revealed an average accuracy of 90.2%, recall of 89.7%, precision of 88.5% and F1-score of 89.2%. Finally, these results demonstrate that the proposed joint classification framework can effectively differentiate between specific types of cyber-attacks (e.g., device reinitialization attack, network Denial-of-Service attack) and physical faults (e.g., air handling unit operational fault, cooling coil valve stuck) in real time for improved building energy management.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Designing resilient IoT and Edge Computing with federated tinyML

The rapid growth of the Internet of Things (IoT) and Edge Computing (EC) has brought significant conveniences to modern society but has also greatly expanded the cyber attack surfaces, particularly as these technologies are being increasingly integrated into critical systems such as power grids, healthcare, and smart homes. Here, to improve IoT/EC’s cybersecurity posture, we leveraged Artificial Intelligence (AI) and Machine Learning (ML) by employing tinyML to monitor voluminous IoT data for cyber threats while addressing devices’ resource constraints, and utilizing Federated Learning (FL) to share local detection knowledge across the system while preserving privacy. Building on our three-layer architecture combining tinyML and FL to enhance autonomous cyber attack detection, this paper demonstrated that the architecture improves detection accuracy, reduces resource consumption, and enables lightweight, secure IoT device monitoring. These results were validated using the public N-BaIoT dataset as well as real IoT network traffic data collected under multiple attack scenarios from our testbeds. Additionally, we introduced an enhanced FL methodology with a novel preprocessing stage, including federated feature selection and global preprocessor construction, to address IoT/EC data heterogeneity. We developed a physical IoT testbed for attack simulations and data collection, implemented a tinyML-powered detector for realistic model validation, and also built a virtual testbed for scalable evaluations of FL models across diverse network environments.

Cognitive cyber↗

A Graph-Net with Node Embeddings to Detect False Data Injection Attacks in Photovoltaic Systems

Distributed energy resources (DER) contribute to the operational stability of the larger power grid both at utility-scale as well as commercial and residential scales in aggregated forms. These DER in-turn are susceptible to increasing cyber threats. An adversary can plug into the same local network that a field photovoltaic (PV) system uses to interconnect its data loggers and inverters and manipulate certain measurements collected from the network or trick existing irradiance and inverter readings through false data injection attacks (FDIA). Control routines that rely on these measurements can propagate the false data, impacting critical decisions that result in a suboptimal operation or even cause intentional harm leading to inverter-tripping or unscheduled loads that need to be shed. To detect FDIA in PV systems, the paper introduces an attention-based graph neural network with node embeddings and applied it to a simple prototypical DC-coupled microgrid with PV, energy storage, and load. The algorithm shows a detection accuracy of up to 98.95%. The proposed FDIA detection technique will provide micro-grid operators with an effective method to safeguard their systems, guaranteeing the secure and reliable operation.

Parvez, Imtiaz [Utah Valley University]↗

Field test of continuous-variable quantum key distribution with a true local oscillator

A continuous-variable quantum key distribution (CV QKD) using a true local (located at the receiver) oscillator (LO) has been proposed to remove any possibility of side-channel attacks associated with transmission of the LO as well as reduce the cross-pulse contamination. Here we report an implementation of true LO-CV QKD using “off-the-shelf” components and conduct QKD experiments using the fiber optical network at Oak Ridge National Laboratory. A phase reference and quantum signal are time multiplexed and then wavelength division multiplexed with the classical communications that “coexist” with each other on a single optical network fiber. Importantly, this is the first demonstration of CV QKD with a receiver-based true LO over a deployed fiber network, a crucial step for its application in real-world situations.

97 MATHEMATICS AND COMPUTING↗

Federated Machine Learning-Based Anomaly Detection System for Synchrophasor Network Using Heterogeneous Data Sets: Preprint

Synchrophasor technology is widely deployed in the energy management system to monitor the grid health at micro level and perform necessary corrective actions in real time; however, integrated phasor devices and data aggregators are exposed to several cybersecurity threats. This paper proposes a federated ML(FML)-based ADS to detect several data integrity attacks in the synchrophasor network. The proposed approach integrates the horizontal FML technique and consists of substation-based local models and a control center-based global model. The proposed methodology includes training local models using heterogeneous data sets that include network and grid information and updating the global model through multiple iterations by sharing model gradients. Finally, the trained global model is applied to identify cyberattacks, normal operation, and physical events. To validate the proof of concept, we used synthetic data sets generated by Mississippi State University and Oak Ridge National Laboratory for training and testing the classification models using the National Renewable Energy Laboratory's high performance computing resources. Our experimental results, computed through several performance measures, reveal that the proposed approach shows consistent performance during the binary, three-class, and multiclass classifications while ensuring privacy of synchrophasor data.

anomaly detection system↗

Digital Twin for Self-Security of Smart Inverters

Smart inverters connected to a communication network are susceptible to man-in-the-middle attacks. In this paper, a self-security approach is implemented using the digital twin concept for smart inverters. The digital twin is formed using the inverter’s normal operating region and the inverter’s dynamic model. Then, the incoming setpoints are autonomously examined using the digital twin, and only the safe setpoints are engaged to the inverter’s local controller. This paper demonstrates how the inverter’s normal operating region and dynamic model are formed. In particular, the normal operation region is experimentally verified by changing the P and Q setpoints engaged to the local controller, using a laboratory setup including a three-phase 3-kVA SiC-MOSFET inverter and a 12-kW NHR 9410 regenerative power grid emulator. The results demonstrate that the self-security technique can potentially protect inverters from man-in-the-middle attacks by examining the incoming commands (new setpoints) using the inverter’s digital twin before engaging the setpoints to the local controller.

Hossen, Tareq↗

Impact of cyber attacks on distributed compressive sensing based state estimation in power distribution grids

Modern power distribution grids suffer from multiple vulnerabilities due to the tight integration between the physical system and the cyber infrastructure. Sophisticated and malicious cyber attacks continue to adversely impact the grid operation leading to performance degradation, service interruption, and grid failure. State estimation plays an essential role in grid monitoring and advancing cyber-attack situational awareness. In this regard, this paper first proposes a distributed compressive sensing (CS) state estimation approach for an unobservable distribution grid. Further, the proposed distributed CS approach divides the distribution grid into sub-areas to perform local state estimation. Then an alternating direction method of multipliers (ADMM) based iterative information exchange among neighboring areas is employed to complete the estimation process. In this estimation process, the impact of loss of measurement data, false data injection (FDI), replay, and neighborhood cyber-attacks is analyzed. Extensive simulations are performed on the IEEE 37-bus and IEEE 123-bus standard networks to demonstrate the algorithm’s robustness to the aforementioned cyber-attacks. A quantitative analysis of computational complexity and simulation time of the distributed CS based approach is also presented.

24 POWER TRANSMISSION AND DISTRIBUTION↗

A hardware-in-the-loop (HIL) testbed for cyber-physical energy systems in smart commercial buildings

In recent years, there has been a growing trend toward the development of smart buildings that rely on cyber-physical systems (CPS) to optimize occupant comfort, safety, and energy efficiency. To ensure the reliable and efficient operation of CPS with designed control strategies, it is important to evaluate their performance under various scenarios before deploying them in the real world. This is where a Hardware-in-the-loop (HIL) testbed designed for studying sensor and control-related studies in smart buildings can be highly valuable. With the growing threat of cyber-attacks and physical faults targeting smart buildings, it is essential to ensure the security of building operations. A HIL testbed can emulate cyber-attack and physical fault scenarios, allowing researchers to develop and test threat detection and mitigation algorithms. This enables researchers to identify potential issues and optimize the algorithms in a safe and controlled environment before they are deployed in real-world settings, reducing the risk of failures that can negatively impact occupant comfort, safety, and energy efficiency. Therefore, this paper developed a HIL testbed designed for cyber-physical energy systems (e.g. buildings automation system (BAS)) in smart commercial buildings. The HIL testbed is comprised of a real-time building and Heating, Ventilation, and Air-Conditioning (HVAC) emulator using Modelica-based dynamic models, a set of BAS controllers, and a BAS computer server. The data generation capability of the HIL testbed is demonstrated by tracking normal and faulty operating data in the BAS, as well as monitoring detailed network traffic in the local BAS network. Here, this study further demonstrates the HIL testbed’s capability by conducting case studies on real-time physical fault and cyber-attack experiments using a Department of Energy (DOE) prototype commercial building. It is anticipated that the fully functional HIL testbed will be utilized for a variety of sensor and control-related studies, including but not limited to testing, developing, validating of different HVAC control strategies, fault detection & diagnosis, energy monitoring and analysis, cyber security study, etc.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

Overview and Commentary on Applying the Coordinated Vulnerability Disclosure Process to Photovoltaic System Devices

The rapid expansion of photovoltaic (PV) systems, particularly inverters, has introduced new cybersecurity challenges that threaten both local operations as well as the broader electrical grid’s stability. PV inverters, integrated into critical energy infrastructure are potential targets for cyber attacks due to vulnerabilities in firmware, remote access systems, and communication protocols. The Coordinated Vulnerability Disclosure (CVD) process, as defined by the Cybersecurity and Infrastructure Security Agency (CISA), provides a framework for identifying, reporting, and addressing these vulnerabilities in a transparent and collaborative manner. This report outlines the CVD process as it applies to PV systems, detailing the roles of key stakeholders, such as manufacturers, grid operators, and security researchers. The report also highlights specific challenges in managing vulnerabilities for new and legacy PV systems, which includes those introduced by insecure communications and third-party supply chain components. By adhering to the CVD process, the PV industry can mitigate cybersecurity risks, ensure regulatory compliance, and maintain consumer trust, while safeguarding the operational resilience of the energy grid. Ultimately, the effective coordination of vulnerability management is crucial for securing the future of PV systems within the critical electric grid infrastructure landscape.

14 SOLAR ENERGY↗

Application of Cyber-Informed Engineering for Protecting BESS

This white paper synthesizes an array of crucial grid services provided by BESS technology, assesses its architecture and communications, and presents a case study for analysis against the principles introduced by Cyber-Informed Engineering (CIE). Furthermore, in walking through the analysis, this paper presents a framework to evaluate risks and solutions when considering BESS components. Asset owners and buyers could perform this analysis to assess their BESS product implementations, alternative inverter-based resources (IBR), and energy management systems (EMS). Battery systems fulfill various roles contingent on the unique market demands and the specific challenges presented by regional grid infrastructures. These roles also vary due to the differing utility models for ownership and operation, which are adapted to meet regional and local capabilities and requirements. Concerns have been raised regarding the potential for adversaries to exploit knowledge of battery operational patterns to orchestrate decisive attacks. However, the security of operational data for these systems may not be the primary vulnerability, as much of this information is already well-understood within the community. Applying a modest degree of subject matter expertise can often yield valuable predictions regarding how a battery will respond under certain conditions, such as grid emergencies, high or low-temperature days, Public Safety Power Shutoff (PSPS) events, and outages. The operational characteristics of batteries are well-documented, and their capabilities, including the risks associated with misoperation and the resulting consequences, are published and understood within the industry. CIE practices represent the next step in gaining functional assurance and providing an acceptable level of risk, regardless of whether a battery vendor can support a trusted and validated supply chain. While this issue has exacerbated supply chain challenges, it is not an isolated condition. This foreign supply route is the primary source of BESS for the U.S. market. Significant efforts are underway through the Bipartisan Infrastructure Law (BIL) to change that. Still, strategic short-term operational mitigations are needed to ensure the security of our operational technology (OT) systems, which are enhanced by instilling trust and are separate from vendors implementing CIE principles.

25 ENERGY STORAGE↗

On the Feasibility of Market Manipulation and Energy Storage Arbitrage via Load-Altering Attacks

Around the globe, electric power networks are transforming into complex cyber–physical energy systems (CPES) due to the accelerating integration of both information and communication technologies (ICT) and distributed energy resources. While this integration improves power grid operations, the growing number of Internet-of-Things (IoT) controllers and high-wattage appliances being connected to the electric grid is creating new attack vectors, largely inherited from the IoT ecosystem, that could lead to disruptions and potentially energy market manipulation via coordinated load-altering attacks (LAAs). In this article, we explore the feasibility and effects of a realistic LAA targeted at IoT high-wattage loads connected at the distribution system level, designed to manipulate local energy markets and perform energy storage (ES) arbitrage. Realistic integrated transmission and distribution (T&D) systems are used to demonstrate the effects that LAAs have on locational marginal prices at the transmission level and in distribution systems adjacent to the targeted network.

25 ENERGY STORAGE↗

A Randomization-Based, Zero-Trust Cyberattack Detection Method for Hierarchical Systems

This paper demonstrates a novel randomization-based approach for verifying power system control signals with application to detecting cyberattacks. We consider fully connected hierarchical systems containing multiple local agents and a global "trust" agent. The global agent uses a time-varying randomized assignment scheme to identify corrupt network links based on principles of zero trust and majority rule. To evaluate the performance of this detection approach, we implement our algorithm in MATLAB and run it against nearly 43 million unique attack scenarios spanning a range of system sizes. For each scenario, the algorithm determines whether the identified corruptions satisfy a set of validity constraints reflecting network topology and uses that result to say whether the recovered state value for one or more local agents is malicious. We compare the algorithm's determination to the true state of the system to assess performance and find that classification accuracy converges to 100% as system size increases, suggesting that the validity constraints become more difficult to satisfy for larger systems. We further explore the scenarios that evade detection to understand practical implications for employing this detection approach.

cybersecurity↗

Multi-Source Data Aggregation and Real-Time Anomaly Classification and Localization in Power Distribution Systems

This paper proposes a real-time anomaly location and classification framework for power distribution systems to simultaneously determine the type of anomaly (i.e., short-circuit fault, cyber attack, DER switching) and its location. The proposed framework employs the data aggregation module to collect the measurement data from multiple field devices operating at different sampling rates, such as protection relays and D-PMUs. The output of the data aggregation is then fed into a multi-task learning-based long-based short-term memory (MTL-LSTM) to classify the type of anomaly and the location in two separate tasks. The proposed MTL-LSTM approach can be utilized in real-time operation in order to distinguish between normal and several anomalous operations and locate the anomaly. The proposed framework is tested on a modified IEEE 33-bus test feeder benchmark that integrates solar generation and energy storage. Furthermore, the results show that the proposed framework can locate and classify anomalies for several operation conditions with more than 96% accuracy. Further experiments highlight the impact of aggregating multiple sources of data on the performance of the proposed model.

24 POWER TRANSMISSION AND DISTRIBUTION↗

A Localized Cyber Threat Mitigation Approach For Wide Area Control of FACTS

We propose a localized oscillation amplitude monitoring (OAM) method for the mitigation of cyber threats directed at the wide area control (WAC) system used to coordinate control of Flexible AC Transmission Systems (FACTS) for power oscillation damping (POD) of active power flow on inter-area tie lines. The method involves monitoring the inter-area tie line active power oscillation amplitude over a sliding window. We use system instability - inferred from oscillation amplitudes growing instead of damping - as evidence of an indication of a malfunction in the WAC of FACTS, possibly indicative of a cyber attack. Monitoring the presence of such a growth allows us to determine whether any destabilizing behaviors appear after the WAC system engages to control the POD. If the WAC signal increases the oscillation amplitude over time, thereby diminishing the POD performance, the FACTS falls back to POD using local measurements. The proposed method does not require an expansive system-wide view of the network. We simulate replay, control integrity, and timing attacks for a test system and present results that demonstrate the performance of the OAM method for mitigation.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Local carbon reserves are insufficient for phloem terpene induction during drought in Pinus edulis in response to bark beetle–associated fungi

Stomatal closure during drought inhibits carbon uptake and may reduce a tree's defensive capacity. Limited carbon availability during drought may increase a tree's mortality risk, particularly if drought constrains trees' capacity to rapidly produce defenses during biotic attack. We parameterized a new model of conifer defense using physiological data on carbon reserves and chemical defenses before and after a simulated bark beetle attack in mature Pinus edulis under experimental drought. Attack was simulated using inoculations with a consistent bluestain fungus (Ophiostoma sp.) of Ips confusus, the main bark beetle colonizing this tree, to induce a defensive response. Trees with more carbon reserves produced more defenses but measured phloem carbon reserves only accounted for c. 23% of the induced defensive response. Our model predicted universal mortality if local reserves alone supported defense production, suggesting substantial remobilization and transport of stored resin or carbon reserves to the inoculation site. Our results show that de novo terpene synthesis represents only a fraction of the total measured phloem terpenes in P. edulis following fungal inoculation. Without direct attribution of phloem terpene concentrations to available carbon, many studies may be overestimating the scale and importance of de novo terpene synthesis in a tree's induced defense response.

59 BASIC BIOLOGICAL SCIENCES↗

Secure Route: Roadway Risk Mapping for Transportation Planners

The secure transport of sensitive materials across U.S. road networks pose unique challenges for local, state, and federal agencies. Threats range from random events (e.g., accidents, medical emergencies, mechanical failures) to opportunistic or organized tactical assaults. Although the probability of such attacks is very low, the consequences of material loss to foreign states or terrorists can be catastrophic, qualifying these scenarios as “grey swan” events—low-probability, high-impact occurrences that are predictable but difficult to quantify. Traditional risk assessments struggle in these contexts, necessitating a shift toward subjective risk perception to inform planning. Risk perception in transport planning is shaped by various factors, including knowledge of adversarial capabilities, vehicle defenses, manifest details, and geographic features along the route. Geographic features such as bridges, tunnels, roadside elevation, and gaps in cellular coverage introduce vulnerabilities, while mitigative features include safe havens, police stations, and medical services. Temporal variables such as congestion, accidents, and weather further complicate route planning. Despite their importance, existing routing tools like Google Maps and commercial software do not explicitly account for geographic risk features, requiring planners to rely on personal familiarity with routes—a time-intensive, non-scalable approach. This work addresses these gaps by: (1) developing datasets that catalog geographic risk features along U.S. roadways, (2) eliciting risk perceptions from experienced transportation security experts, and (3) linking these perceptions to roadway conditions and geographic data. We implement these capabilities within Secure Route a novel mapping tool for classifying route segment risks associated with roadway conditions. This system provides transportation planners with an intuitive interface to assess and contextualize risk along potential routes, improving decision-making for secure transport. We present current progress in this effort and identify next steps.

Stewart, Robert [ORNL] (ORCID:0000000281867559)↗