Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Attack localization”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Application of Cyber-Informed Engineering for Protecting BESS

This white paper synthesizes an array of crucial grid services provided by BESS technology, assesses its architecture and communications, and presents a case study for analysis against the principles introduced by Cyber-Informed Engineering (CIE). Furthermore, in walking through the analysis, this paper presents a framework to evaluate risks and solutions when considering BESS components. Asset owners and buyers could perform this analysis to assess their BESS product implementations, alternative inverter-based resources (IBR), and energy management systems (EMS). Battery systems fulfill various roles contingent on the unique market demands and the specific challenges presented by regional grid infrastructures. These roles also vary due to the differing utility models for ownership and operation, which are adapted to meet regional and local capabilities and requirements. Concerns have been raised regarding the potential for adversaries to exploit knowledge of battery operational patterns to orchestrate decisive attacks. However, the security of operational data for these systems may not be the primary vulnerability, as much of this information is already well-understood within the community. Applying a modest degree of subject matter expertise can often yield valuable predictions regarding how a battery will respond under certain conditions, such as grid emergencies, high or low-temperature days, Public Safety Power Shutoff (PSPS) events, and outages. The operational characteristics of batteries are well-documented, and their capabilities, including the risks associated with misoperation and the resulting consequences, are published and understood within the industry. CIE practices represent the next step in gaining functional assurance and providing an acceptable level of risk, regardless of whether a battery vendor can support a trusted and validated supply chain. While this issue has exacerbated supply chain challenges, it is not an isolated condition. This foreign supply route is the primary source of BESS for the U.S. market. Significant efforts are underway through the Bipartisan Infrastructure Law (BIL) to change that. Still, strategic short-term operational mitigations are needed to ensure the security of our operational technology (OT) systems, which are enhanced by instilling trust and are separate from vendors implementing CIE principles.

25 ENERGY STORAGE↗

On the Feasibility of Market Manipulation and Energy Storage Arbitrage via Load-Altering Attacks

Around the globe, electric power networks are transforming into complex cyber–physical energy systems (CPES) due to the accelerating integration of both information and communication technologies (ICT) and distributed energy resources. While this integration improves power grid operations, the growing number of Internet-of-Things (IoT) controllers and high-wattage appliances being connected to the electric grid is creating new attack vectors, largely inherited from the IoT ecosystem, that could lead to disruptions and potentially energy market manipulation via coordinated load-altering attacks (LAAs). In this article, we explore the feasibility and effects of a realistic LAA targeted at IoT high-wattage loads connected at the distribution system level, designed to manipulate local energy markets and perform energy storage (ES) arbitrage. Realistic integrated transmission and distribution (T&D) systems are used to demonstrate the effects that LAAs have on locational marginal prices at the transmission level and in distribution systems adjacent to the targeted network.

25 ENERGY STORAGE↗

A Randomization-Based, Zero-Trust Cyberattack Detection Method for Hierarchical Systems

This paper demonstrates a novel randomization-based approach for verifying power system control signals with application to detecting cyberattacks. We consider fully connected hierarchical systems containing multiple local agents and a global "trust" agent. The global agent uses a time-varying randomized assignment scheme to identify corrupt network links based on principles of zero trust and majority rule. To evaluate the performance of this detection approach, we implement our algorithm in MATLAB and run it against nearly 43 million unique attack scenarios spanning a range of system sizes. For each scenario, the algorithm determines whether the identified corruptions satisfy a set of validity constraints reflecting network topology and uses that result to say whether the recovered state value for one or more local agents is malicious. We compare the algorithm's determination to the true state of the system to assess performance and find that classification accuracy converges to 100% as system size increases, suggesting that the validity constraints become more difficult to satisfy for larger systems. We further explore the scenarios that evade detection to understand practical implications for employing this detection approach.

cybersecurity↗

Multi-Source Data Aggregation and Real-Time Anomaly Classification and Localization in Power Distribution Systems

This paper proposes a real-time anomaly location and classification framework for power distribution systems to simultaneously determine the type of anomaly (i.e., short-circuit fault, cyber attack, DER switching) and its location. The proposed framework employs the data aggregation module to collect the measurement data from multiple field devices operating at different sampling rates, such as protection relays and D-PMUs. The output of the data aggregation is then fed into a multi-task learning-based long-based short-term memory (MTL-LSTM) to classify the type of anomaly and the location in two separate tasks. The proposed MTL-LSTM approach can be utilized in real-time operation in order to distinguish between normal and several anomalous operations and locate the anomaly. The proposed framework is tested on a modified IEEE 33-bus test feeder benchmark that integrates solar generation and energy storage. Furthermore, the results show that the proposed framework can locate and classify anomalies for several operation conditions with more than 96% accuracy. Further experiments highlight the impact of aggregating multiple sources of data on the performance of the proposed model.

24 POWER TRANSMISSION AND DISTRIBUTION↗

A Localized Cyber Threat Mitigation Approach For Wide Area Control of FACTS

We propose a localized oscillation amplitude monitoring (OAM) method for the mitigation of cyber threats directed at the wide area control (WAC) system used to coordinate control of Flexible AC Transmission Systems (FACTS) for power oscillation damping (POD) of active power flow on inter-area tie lines. The method involves monitoring the inter-area tie line active power oscillation amplitude over a sliding window. We use system instability - inferred from oscillation amplitudes growing instead of damping - as evidence of an indication of a malfunction in the WAC of FACTS, possibly indicative of a cyber attack. Monitoring the presence of such a growth allows us to determine whether any destabilizing behaviors appear after the WAC system engages to control the POD. If the WAC signal increases the oscillation amplitude over time, thereby diminishing the POD performance, the FACTS falls back to POD using local measurements. The proposed method does not require an expansive system-wide view of the network. We simulate replay, control integrity, and timing attacks for a test system and present results that demonstrate the performance of the OAM method for mitigation.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Electrochemical metrics for corrosion resistant alloys

Abstract Corrosion is an electrochemical phenomenon. It can occur via different modes of attack, each having its own mechanisms, and therefore there are multiple metrics for evaluating corrosion resistance. In corrosion resistant alloys (CRAs), the rate of localized corrosion can exceed that of uniform corrosion by orders of magnitude. Therefore, instead of uniform corrosion rate, more complex electrochemical parameters are required to capture the salient features of corrosion phenomena. Here, we collect a database with an emphasis on metrics related to localized corrosion. The six sections of the database include data on various metal alloys with measurements of (1) pitting potential, E pit , (2) repassivation potential, E rp , (3) crevice corrosion potential, E crev , (4) pitting temperature, T pit , (5) crevice corrosion temperature, T crev , and (6) corrosion potential, E corr , corrosion current density, i corr , passivation current density, i pass , and corrosion rate. The experimental data were collected from 85 publications and include Al- and Fe-based alloys, high entropy alloys (HEAs), and a Ni-Cr-Mo ternary system. This dataset could be used in the design of highly corrosion resistant alloys.

36 MATERIALS SCIENCE↗

A Cyber Threat Mitigation Approach For Wide Area Control of SVCs using Stability Monitoring

We propose a stability monitoring approach for the mitigation of cyber threats directed at the wide area control (WAC) system used for coordinated control of Flexible AC Transmission Systems (FACTS) used for power oscillation damping (POD) of active power flow on inter-area tie lines. The approach involves monitoring the modes of the active power oscillation on an inter-area tie line using the Matrix Pencil (MP) method. We use the stability characteristics of the observed modes as a proxy for the presence of destabilizing cyber threats. We monitor the system modes to determine whether any destabilizing modes appear after the WAC system engages to control the POD. If the WAC signal exacerbates the POD performance, the FACTS falls back to POD using local measurements. The proposed approach does not require an expansive system-wide view of the network. We simulate replay, control integrity, and timing attacks for a test system and present results that demonstrate the performance of the SM approach for mitigation.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Local carbon reserves are insufficient for phloem terpene induction during drought in Pinus edulis in response to bark beetle–associated fungi

Stomatal closure during drought inhibits carbon uptake and may reduce a tree's defensive capacity. Limited carbon availability during drought may increase a tree's mortality risk, particularly if drought constrains trees' capacity to rapidly produce defenses during biotic attack. We parameterized a new model of conifer defense using physiological data on carbon reserves and chemical defenses before and after a simulated bark beetle attack in mature Pinus edulis under experimental drought. Attack was simulated using inoculations with a consistent bluestain fungus (Ophiostoma sp.) of Ips confusus, the main bark beetle colonizing this tree, to induce a defensive response. Trees with more carbon reserves produced more defenses but measured phloem carbon reserves only accounted for c. 23% of the induced defensive response. Our model predicted universal mortality if local reserves alone supported defense production, suggesting substantial remobilization and transport of stored resin or carbon reserves to the inoculation site. Our results show that de novo terpene synthesis represents only a fraction of the total measured phloem terpenes in P. edulis following fungal inoculation. Without direct attribution of phloem terpene concentrations to available carbon, many studies may be overestimating the scale and importance of de novo terpene synthesis in a tree's induced defense response.

59 BASIC BIOLOGICAL SCIENCES↗

Impact Analysis of Data Integrity Attacks on FACTS-based Wide-Area Voltage Control System

Energy management system (EMS) consists of several wide-area control applications that serve as a backbone for security, stability, and reliability of the power system. Wide-area voltage control system (WAVCS), one of the critical wide-area applications, operates in coordination with local Flexible AC Transmission System (FACTS) devices to provide voltage security and optimal management of active and reactive power resources. Since the WAVCS relies on wide-area communication and data sharing devices, possible cybersecurity vulnerabilities have to be addressed to ensure the closed-loop operation of WAVCS. In this paper, we present a methodology for performing an impact analysis of cyber-attacks in WAVCS cybersecurity. In particular, different types of data integrity attacks, such as malicious tripping, fault replay, and signal altering attacks, are considered, and detailed impact analysis is conducted in a testbed environment using the Kundur's four machine two-area system. For performing an impact analysis, the transient voltage stability of the sensitive bus voltage is studied, followed by the quantitative assessment and severity ranking using the voltage profile index. Our experimental evaluation reveals that the data integrity attacks on control signals exhibit a higher attack severity than on the measurement signals. Further, the severity of these attacks varies with nature (static or dynamic), location, and types of attacks.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Secure Route: Roadway Risk Mapping for Transportation Planners

The secure transport of sensitive materials across U.S. road networks pose unique challenges for local, state, and federal agencies. Threats range from random events (e.g., accidents, medical emergencies, mechanical failures) to opportunistic or organized tactical assaults. Although the probability of such attacks is very low, the consequences of material loss to foreign states or terrorists can be catastrophic, qualifying these scenarios as “grey swan” events—low-probability, high-impact occurrences that are predictable but difficult to quantify. Traditional risk assessments struggle in these contexts, necessitating a shift toward subjective risk perception to inform planning. Risk perception in transport planning is shaped by various factors, including knowledge of adversarial capabilities, vehicle defenses, manifest details, and geographic features along the route. Geographic features such as bridges, tunnels, roadside elevation, and gaps in cellular coverage introduce vulnerabilities, while mitigative features include safe havens, police stations, and medical services. Temporal variables such as congestion, accidents, and weather further complicate route planning. Despite their importance, existing routing tools like Google Maps and commercial software do not explicitly account for geographic risk features, requiring planners to rely on personal familiarity with routes—a time-intensive, non-scalable approach. This work addresses these gaps by: (1) developing datasets that catalog geographic risk features along U.S. roadways, (2) eliciting risk perceptions from experienced transportation security experts, and (3) linking these perceptions to roadway conditions and geographic data. We implement these capabilities within Secure Route a novel mapping tool for classifying route segment risks associated with roadway conditions. This system provides transportation planners with an intuitive interface to assess and contextualize risk along potential routes, improving decision-making for secure transport. We present current progress in this effort and identify next steps.

Stewart, Robert [ORNL] (ORCID:0000000281867559)↗

Degradation science: Integrating modeling and experiments to predict localized corrosion processes (Annual Progress Report)

Additively manufactured (AM) eutectic high-entropy alloys (EHEAs), such as nano-lamellar AlCoCrFeNi 2.1 , have excellent strength, ductility, and wear resistance even at elevated temperatures, but their corrosion behavior in aggressive acids at different length scales remain poorly understood. This work investigates the corrosion behavior of laser powder bed–fused (L-PBF) AlCoCrFeNi 2.1 as a function of annealing temperatures, probing degradation mechanisms from nanoscopic to macroscopic length scales. The alloy is dual phase consisting of a ductile FCC L1 2 phase and a high-strength BCC B2 phase. Rapid solidification during L-PBF produces a far-from-equilibrium nano-lamellar structure with nearly homogeneous elemental distribution, which tends to evolve upon annealing toward Cr/Co/Fe-enriched FCC and Al/Ni-enriched B2. Three conditions were studied: as-printed, 600 °C/5 h, and 1000 °C/1 h, over which B2 lamellae coarsen, lamellar spacing increases, and elemental segregation becomes more prominent. Microstructure and chemistry were characterized by scanning electron microscopy (SEM) and energy-dispersive spectroscopy (EDS), while in-situ electrochemical atomic force microscopy (EC-AFM) was used to link early (<5 h) local dissolution to microstructure after exposure in sulfuric acid. EC-AFM highlights preferential dissolution of the BCC/B2 phase where the surrounding matrix is Cr-depleted and directly quantifies the dissolution rates within individual phases, tracks the transition from early nano-scale attack to partial repassivation, to correlate height differences with current and impedance responses. To monitor longer-term behavior (up to 96 h), ex-situ AFM, SEM, and confocal imaging were combined with conventional bulk electrochemical tests, bridging nanoscale observations to micro/meso-scale damage morphologies. At the meso-scale, the deepest dissolution channels align with the build-direction lamellae and melt-pool boundaries, indicating that printing directionality guides the propagation of these localized corrosion sites. Annealing modifies corrosion by restructuring BCC/FCC phase fractions, lamellar spacing, and Cr/Al segregation, thereby changing the cathode/anode ratio and passive film stability. The results clarify how as-printed and annealed nano-lamellar architectures differ in their susceptibility to selective dissolution; how elemental segregation competes with residual stresses along the build direction. With these insights, future work will use CALPHAD-guided alloy modification to stabilize higher Cr contents in the B2 phase while retaining a dominant FCC+B2/BCC microstructure, with the goal of designing mechanically robust, corrosion-resistant EHEAs for safety-critical applications to leverage the LLNL’s broader national and global security mission.

36 MATERIALS SCIENCE↗

Impact of lanthanide ion complexation and temperature on the chemical reactivity of N , N , N ', N '-tetraoctyl diglycolamide (TODGA) with the dodecane radical cation

The impact of trivalent lanthanide ion complexation and temperature on the chemical reactivity of N,N,N',N'-tetraoctyl diglycolamide (TODGA) with the n-dodecane radical cation (RH˙+) has been measured by electron pulse radiolysis and evaluated by quantum mechanical calculations. Additionally, Arrhenius parameters were determined for the reaction of the non-complexed TODGA ligand with the RH˙ + from 10–40 °C, giving the activation energy (E a = 17.43 ± 1.64 kJ mol –1 ) and pre-exponential factor (A = (2.36 ± 0.05) × 10 13 M –1 s –1 ). The complexation of Nd(III), Gd(III), and Yb(III) ions by TODGA yielded [LnIII(TODGA)3(NO3)3] complexes that exhibited significantly increased reactivity (up to 9.3× faster) with the RH˙ + , relative to the non-complexed ligand: k([Ln III (TODGA) 3 (NO 3 ) 3 ] + RH˙ + ) = (8.99 ± 0.93) × 10 10 , (2.88 ± 0.40) × 10 10 , and (1.53 ± 0.34) × 10 10 M –1 s –1 , for Nd(III), Gd(III), and Yb(III) ions, respectively. The rate coefficient enhancement measured for these complexes exhibited a dependence on atomic number, decreasing as the lanthanide series was traversed. Preliminary reaction free energy calculations—based on a model [Ln III (TOGDA)] 3+ complex system—indicate that both electron/hole and proton transfer reactions are energetically unfavorable for complexed TODGA. Furthermore, complementary average local ionization energy calculations showed that the most reactive region of model N,N,N',N'-tetraethyl diglycolamide (TEDGA) complexes, [Ln III (TEGDA) 3 (NO 3 ) 3 ], toward electrophilic attack is for the coordinated nitrate (NO 3 – ) counter anions. Furthermore, it is possible that radical reactions with the complexed NO 3 – counter anions dominate the differences in rates seen for the [Ln III (TODGA) 3 (NO 3 ) 3 ] complexes, and are likely responsible for the reported radioprotection in the presence of TODGA complexes.

38 RADIATION CHEMISTRY, RADIOCHEMISTRY, AND NUCLEA↗

Combining four-point bending and corrosion to map stress-dependent corrosion susceptibility of 316H stainless steel in FLiNaK

Understanding the effect of stress on the corrosion of steels in molten salts is important for material screening and safety assessment of molten salt reactors. We present a method that combines four-point bending with corrosion testing, enabling the mapping of corrosion susceptibility as a function of local stress from a single specimen. Guided by finite element analysis, a four-point bending setup was used to bend a 316H stainless-steel bar under controlled elastic stress during a 100-hour exposure in FLiNaK at 700 °C. Post-exposure characterization using scanning electron microscopy and energy-dispersive X-ray spectroscopy revealed a pronounced correlation between stress and corrosion. Regions under tensile stress exhibited significantly deeper attack depths and greater chromium depletion along grain boundaries, whereas compressive zones showed shallower corrosion cracks. The stress effect is attributed to stress concentration under tensile loading, which promotes chromium dissolution and crack propagation. This technique can be readily applied to other structural alloys, enabling quantitative measurement of corrosion susceptibility as a function of local stress.

316H↗

Cybersecurity Considerations for Hydrogen Infrastructure in Airport Environments

This report explores key cybersecurity concerns and best practices within environments that serve as reference points for the development of hydrogen fueling infrastructure for aviation. This cybersecurity analysis leverages prior NREL studies: 1) hydrogen fueling station component validation to identify vulnerabilities and failure events documented in physical equipment, and 2) electric aircraft charging infrastructure analysis to explore primary cybersecurity vulnerabilities. It reviews the criticality of digitized technologies in sustaining hydrogen fuel production, storage, and fueling systems, noting cybersecurity concerns that are universal to power systems and industrial control systems in general. In considering cybersecurity vulnerabilities within a future landscape of hydrogen energy for aviation applications, a reference architecture was intended to reveal the points of connection between assets and the potential sensors that are vulnerable to manipulation in the event of compromised access or communication within a SCADA system. A generalized reference architecture can help stakeholders, engineers, or strategists understand connections, criticalities, and standard practices when it comes to designing and planning for new systems. There are several gaps to account for in assessing the future of hydrogen production, storage, and fueling for aviation. Engaging stakeholders, including aircraft manufacturers, electric utilities, site property owners, and local communities, will inform decision-making around site structure, operations, and resources for future hydrogen fueling infrastructure to understand operational needs and cybersecurity awareness. Cybersecurity mitigation strategy must consider physical attack vectors that emerge with the integration of hydrogen systems into existing airport security requirements. The cybersecurity risk assessment contained in this report is an entry point into potential future granular-level analyses to be conducted as part of hazard and risk assessments for safe aviation hydrogen infrastructure, determining how the scale of hydrogen fuel infrastructure for aviation impacts the volume of cyber attack vectors, and what, if any, are the vulnerabilities associated with different types of on-board hydrogen systems. In this nascent development phase, assessing how best to integrate cybersecurity practices into an evolving U.S. aviation landscape provides critical insights into building increased awareness and stakeholder engagement to support a cyber-resilient infrastructure.

08 HYDROGEN↗

Radio Frequency Spectrum Audit to Inventory Private Cellular Base Station Infrastructure

The ever-changing cellular communication landscape makes it difficult to identify, map, and localize cellular base stations. Localizing cellular base stations provides various advantages, including information security, cybersecurity, spectrum management, and interference detection. For example, the MITRE ATT&CK® (Adversarial Tactics, Techniques, and Common Knowledge architecture) [1] and Common Attack Pattern Enumeration and Classification [2] emphasize the importance of being able to minimize the cyber security threat presented by unregulated private cellular base stations (PCBS). The majority of published research looks at the malicious use of PCBSs and focuses on using data retrieved from user equipment (UE), data obtained from an application on the UE, or data shared between the UE and a mobile network to locate it. This innovative strategy, however, focuses on the passively discovered uniqueness of radio frequency (RF) transmissions from commercial cellular infrastructure received in a designated monitoring position (DMP).

42 ENGINEERING↗

Localized high concentration electrolytes decomposition under electron-rich environments

Localized high concentration electrolytes have been proposed as an effective route to construct stable solid–electrolyte interphase (SEI) layers near Li-metal anodes. However, there is still a limited understanding of decomposition mechanisms of electrolyte components during SEI formation. In this work, we investigate reactivities of lithium bis(fluorosulfonyl)imide (LiFSI, salt), 1,2-dimethoxyethane (DME, solvent) and tris(2,2,2-trifluoroethyl)orthoformate (TFEO, diluent) species in DME+TFEO mixed solvents and 1M LiFSI/DME/TFEO solutions. By supplying excess of electrons into the simulation cell, LiFSI is initially reduced via a 4-electron charge transferring reaction yielding F - and N(SO 2 ) 2 3- . The local solvation environment has little effect on the subsequent TFEO reaction, which typically requires 6 |e| to decompose into F - , HCOO - , CH2CF and - OCH 2 CF 3 . Besides, TFEO dehydrogenation reaction mechanism under the attack of anions is also identified. Unlike salt and diluent, DME shows good stability with any excess of electrons. Here, the energetics of most relevant reactions are characterized. Most reactions are thermodynamically favorable with low activation barriers.

37 INORGANIC, ORGANIC, PHYSICAL, AND ANALYTICAL CH↗

Service-Based, Segmented, 5G Network-Based Architecture for Securing Distributed Energy Resources: Preprint

As the number of connected devices in the energy grid increase exponentially, so too are the cybersecurity risks. With the development of modern communications standards such as 5G and beyond the extent to which devices will continue to connect will continue to increase exponentially along with the inherent risks. However, 5G also includes features to help address cybersecurity concerns and therefore helping to mitigate many of these risks. This paper proposes a new service-based network architecture implementing network-slicing capabilities for connected systems and devices to improve performance, availability, security, and reliability of the grid devices and services. This paper considers the quality of service requirements and criticality of services needed for securely monitoring, operating, and securing Distributed Energy Resource (DER) devices. From developed use cases, network slicing is implemented based on these requirements and resource allocations. This work then highlights examples of how slicing can help prevent standard existing attack methods such as a denial-of-service or similar attack which limits resource availability and network bandwidth to the service and thus limiting its ability to affect other services by misbehaving. The designed network architecture use case will be further tested on a local virtualized testbed to verify secure operation and availability of services. Using hardware-in-the-loop devices and systems on this local testbed, this fully segmented, secure network may be realized and evaluated. Finally, this paper presents the results of this testing.

5G↗

Variable Resource Resilience: How Systems Experience Increased Resilience from Variable and Hybrid Resources

Variable resources like wind and solar are often seen as detriments to system resilience rather than benefits because they may not be available with the capacities or services required during a high-impact low-frequency (HILF) event, whether that is a physical threat, natural disaster, or cyber attack. However, resilience goals and metrics are inadequate for electric energy delivery systems with inverter-based resources. Examination of this topic reveals that renewable resources are well suited to combat many resilience hazards due to local resource availability. Metrics that demonstrate the resilience value of variable resources are presented and categorized for resource (wind, solar, storage, hybrid) and installation type (bulk utility scale, behind-the-meter, front-of-the-meter, isolated). Distributed and hybrid systems can further enhance resilience benefits my maximizing resource potential for a locality. A case study demonstrating quantitative resilience benefits from wind alone is provided for St. Mary's, AK, which concludes that hundreds of thousands of dollars are saved by the addition of a wind turbine in the face of realistic fuel shortage and extreme winter weather scenarios.

17 WIND ENERGY↗