Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “False Data Injection”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Discovering the Most Severe K-Point Failure Based on Reinforcement Learning: Preprint

Smart devices are essential to ensure the stability of the power grid and resilience to intermittent energy production. However, smart devices can also be the target of cyber adversaries that may exploit false data injection attacks (FDIAs) to induce unstable grid conditions. A practical consideration of FDIA mitigation approaches is addressed here: given a finite available budget, for which smart device should cyber-threat mitigation be deployed first? In this work, this question is answered by identifying the so-called most-sensitive devices, i.e., the devices that, if compromised, can let an adversary induce the most serious grid instabilities. The method proposed utilizes an adversarial reinforcement learning (RL) framework to identify the k-mostsensitive smart devices (here, smart inverters). The adversarial agent can tamper with the compromised inverters' active and reactive operating power setup points, with the goal of maximizing voltage deviations. Numerical results show that the proposed RL method finds the optimal attack scenarios for 1-point failure and the near-optimal solution for the 2-point case. Additionally, the proposed RL method achieves an 8.8 speed-up ratio in running time compared to the brute force method for the 2-point case.

97 MATHEMATICS AND COMPUTING↗

Hybrid Data-Driven Based HVdc Ancillary Control for Multiple Frequency Data Attacks

The high voltage direct current (HVdc) intertie has been applied to provide ancillary-services for ac grids, utilizing the real-time feedback from phasor measurement units (PMUs). However, PMU data communication is vulnerable to false data injection attacks (FDIA) due to protocol defects, thus the HVdc ancillary control and system stability will be threatened. To address this issue, this article proposes a novel HVdc control strategy based on a hybrid data-driven (HDD) methodology. In this work, the HDD methodology is first proposed to detect the types and duration time of multiple frequency attacks. Specifically, the Hilbert Huang transform (HHT) is used to decompose the frequency data, using variational mode decomposition instead of the traditional empirical mode decomposition, to extract data features. Second, a multikernel support vector machine is proposed to classify the attacked data based on the designed distinctive features from HHT. Meanwhile, the attacking duration time is decided using an unsupervised technique. Third, an HDD-based HVdc ancillary control strategy is established to eliminate the effect of FDIAs on the HVdc frequency response. Comprehensive experiments of HDD-based HVdc ancillary controls under different FDIAs suggest that the proposed HDD could fast and accurately classify the FDIAs, and the HDD-based HVdc ancillary control strategy could significantly suppress the impact of the FDIAs.

97 MATHEMATICS AND COMPUTING↗

Robust Distribution State Estimation for Reliable Locational Marginal Pricing under Cyber-Attacks

Here this paper examines the impact of false data injection (FDI) cyber-attacks on distribution system state estimation (DSSE) and the resulting distribution locational marginal price (DLMP) in power markets. Two robust high-breakdown regression estimators, namely S- and MM- estimators, are implemented to provide resistance against FDI attacks targeting measurements and grid topology, creating leverage points. The introduced estimators are compared to the weighted least squares (WLS) with a bad data detection and rejection module (BDD) and the robust Huber M-estimator. The proposed estimators are shown to be effective and compare favorably to both existing Huber M- and the WLS with BDD in the presence of topology FDI attacks. Both the S- and MM-estimators provide good performance in the case of clean and corrupted measurements. Their performance is comparable in this case to the Huber M- and the WLS, followed by a BDD module. The simulation considered a modified distribution IEEE 13 and 34-bus systems where the impact of FDI attack scenarios is shown on the state and the DLMP pricing in the presence of distributed Generation.

24 POWER TRANSMISSION AND DISTRIBUTION↗

CANShield: Signal-based Intrusion Detection for Controller Area Networks

Modern vehicles rely on complex cyber-physical systems made up of hundreds of electronic control units (ECUs) connected through controller area network (CAN) buses. However, the CAN bus attack surface is increasing due to advanced features in automobiles, making it prone to injection attacks. The ordinary injection attacks disrupt the typical timing properties of the CAN data stream, and the rule-based intrusion detection systems (IDS) can easily detect them. However, advanced attackers can inject false data to the signal level, maintaining the regular pattern/frequency of the CAN messages. Such attacks can bypass the rule-based IDS or any anomaly-based IDS built on binary payload data. To make the vehicles robust against such intelligent attacks, we propose CANShield, a signal-based intrusion detection framework for the CAN bus that consists of three modules. A data preprocessing module handles the high-dimensional CAN data stream at the signal level and make them suitable for any machine learning model. A data analyzer module consists of multiple deep autoencoder networks, each analyzing the time series data from a different perspective. Finally, an attack detection module uses an ensemble method to make the final decision. Evaluation results on a standard signal-based dataset show the effectiveness of the CANShield in detecting five advanced attacks.

Shahriar, Md Hasan↗

Self-Secure Inverters Against Malicious Setpoints

The next generation of grid-interactive inverters brings a communication feature that allows data sharing from utility supervisory controllers and smart devices that are connected to the same network. This feature enhances the control capabilities of grid-interactive inverters to provide services beyond active power injection. However, communication networks entail more vulnerable surfaces to malicious attacks that may result in modifying active and reactive power setpoints and causing weak-grid conditions or abnormal inverter operation. In this paper, steady-state and the dynamic behavior of the inverter for the incoming setpoints are analyzed to detect false data injection attacks and provide device-level security. The steady-state behavior of the inverter in the operating region is determined from the grid parameters such as the grid voltage and the grid impedance. These estimations are accomplished by the proposed self-security technique through a low-frequency signal injection-based approach combined with the recursive least square method. Moreover, a reduced fourth-order inverter model is used as the dynamic reference model, and grid parameters as well as the incoming setpoints are implemented to the reference model to verify whether the dynamic behavior of the inverter is inside the permissible region of operation. The validity and performance of the proposed method are verified experimentally through Allen-Bradley Powerflex 755 three-phase inverter and a 12 kW NHR 9410 regenerative power grid emulator. The results show that the self-secure smart-inverter is able to accept or reject the incoming commands and thus is protected from malicious cyber-physical attacks.

Hossen, Tareq↗

CyRRL (Cyber Resilient Reinforcement Learning for grid voltage control) [SWR-24-115]

This codebase contains a multi-agent, actor-critic reinforcement learning implementation for cyber-resilient grid voltage control. It uses a 123-bus OpenDSS system as the environment, with three-phase power flow translating nodal power injections into solved nodal voltages. The reward function penalizes deviations from nominal voltage as well as reactive power dispatch, while encouraging agents to take actions that result in fast convergence to nominal conditions. The codebase models false data injection attacks and includes functionality for training, testing, hyper-parameter tuning, and visualization.

Murphy, Sinnott [National Renewable Energy Laborat↗

Securing the Modern Grid: Federal Investments, Digitization, and Supply Chain Strategy

Across the United States (U.S.) grid expansion and modernization is underway, paving the way for accelerated load growth and intelligent resource management. Digitization of the grid is supported by several state and federal programs, providing support for utilities installing advanced metering infrastructure (AMI), AI-powered analytics systems, battery energy storage systems (BESS), and distributed energy resource management systems (DERMS) to transform the grid from a one-way power delivery system into an intelligent, responsive network that will enable faster load growth and power expansion of data centers for advanced artificial intelligence (AI) applications. The digital transformation of America's grid presents opportunity for increased efficiency and resiliency but also introduces new digital risks that require careful management. Digital equipment often contains several vulnerabilities such as unencrypted communication protocols, and persistent remote access capabilities that could be exploited to manipulate device settings, coordinate service disruptions, or inject false data into grid operations. These digital risks become particularly important as the grid must rapidly scale to support AI-driven data centers, which the administration has identified as essential for maintaining U.S. technological leadership and economic competitiveness. These vulnerabilities are compounded by supply chain realities: Chinese manufacturers currently produce 70-90% of essential grid components including inverters, batteries, and control systems, with the U.S. lacking domestic manufacturing capacity for critical assets like extra-high voltage transformers. Recent federal legislation has established Foreign Entity of Concern (FEOC) restrictions to address these risks, requiring projects to achieve escalating thresholds of non-FEOC content to receive tax credits while utilities work to expand sourcing channels for their supply chains and strengthen security measures. These restrictions arrive precisely when utilities face unprecedented electricity demand growth driven by the rapid growth in data centers, creating a considerable challenge: rapidly expanding infrastructure while navigating complex compliance requirements while lacking viable alternatives for many critical components. Idaho National Laboratory (INL) and its partners have developed practical approaches to help utilities navigate these intersecting challenges as they leverage federal investment to strengthen and grow the grid. These solutions include Cyber-Informed Engineering (CIE) principles that build resilience directly into systems, the Cirrus tool for secure cloud migration, and enhanced procurement guidance that embeds security requirements throughout equipment lifecycles. Federal initiatives, such as the Technical Assistance for Digital Assurance (TADA) project, provide direct support to utilities implementing these approaches while facilitating knowledge sharing across the industry. While these tools and frameworks cannot eliminate all risks inherent in foreign supply chain dependencies, they offer pragmatic pathways for strengthening security posture without sacrificing the deployment momentum essential to meeting surging electricity demand. Ultimately, securing America's digital energy infrastructure demands dedicated coordination across multiple fronts: building domestic supply chains, implementing robust digital assurance practices, and maintaining the aggressive modernization timeline necessary for reliability, resilience, and energy independence.

24 POWER TRANSMISSION AND DISTRIBUTION↗

WISP: Watching grid Infrastructure Stealthily through Proxies (Final Technical Report)

The complex interdependencies of cyber systems (sensors and communications), physical grids and associated electricity market operations make protecting electric power grids a significant challenge. The energy sector is constantly under new, targeted, advanced and dangerous cyber-attacks that have the potential to result in the loss of human life. These threats are further exacerbated by our need to modernize the grid. One focus of cyber security research in smart grids is the securing of the SCADA system through advanced intrusion detection systems (IDS) and bad data detection algorithms in state estimation. These methods either require full knowledge of the system topology and parameters or fail to understand the physical behaviors under attack. WISP (Watching grid Infrastructure Stealthily through Proxies) is designed to provide additional protection to the power grid using only publicly available data. In particular, WISP exploits the spatio-temporal nature of the real time locational marginal prices (LMPs), in conjunction with other information such as bids, weather, outages and load data to analyze anomalous power pricing behaviors and then correlate those observations to localize regions of interest and identify potential cyber events. WISP is non-intrusive as the tool is deployed as a service in the Cloud or on premise and provides reliable information to system operators for enhanced situational awareness, without impeding energy delivery functions. The WISP technology comprises three modules: the data-driven anomaly detection core, the vulnerability and risk analysis and the root cause analysis. The data-driven anomaly detection core performs the tasks of feature selection, anomaly detection and attack region localization. The vulnerability and risk analysis module provides system level information of the vulnerable variables and times, assisting the operators in selecting monitoring and protection nodes. The root cause analysis module takes the detection results and identifies potential operational conditions that contribute to the detected anomalies. In Phase I, we have demonstrated the feasibility and effectiveness of WISP. We developed a realistic electricity market simulator capable of generating normal and attack market data under various operational conditions. We developed a series of cyber-attack detection and analysis algorithms and evaluated them under multiple data sources. Finally, we integrated all modules into an end-to-end software, providing functions for data management, data analytics and visualization. Specifically, we have achieved: (i) real-time data acceptance from external utility interfaces with >99% acceptance rate; (ii) high performance anomaly detection algorithms with >98% detection accuracy and <0.1% false alarm rate; and (iii) ultra-low computing delay <50 milliseconds. Additionally, our team developed algorithms to identify the vulnerable variables in electricity market operations and root cause analysis functions to identify major contributors to the price spikes. These ancillary modules are necessary when deploying WISP in real world industry environment. In Phase II, we have demonstrated the effectiveness of WISP software on realistic largescale power systems. We performed red team testing for the Phase I WISP software and identified software vulnerabilities and implemented corresponding mitigation solutions. We adapted the electricity market simulator for the Texas synthetic 2000-bus system and generated datasets for the false data injection attacks. We created database and visualization interfaces for the Texas system and the ISO New England system. We performed software optimization in terms of operation efficiency, computing speed and detection accuracy. Finally, we tested the software on the Texas system and the ISO New England system and evaluated the detection performance. Overall, we achieved above 89% detection rate, below 3% false alarm rate and below 37 seconds of end-to-end detection delay.

24 POWER TRANSMISSION AND DISTRIBUTION↗

A Robust Method to Secure Multi-Inverter Grid Tied PV and Battery Energy Storage Systems Against Cyber Intrusions

This paper details a robust method to secure a multi-inverter grid tied system that interfaces photovoltaic (PV) and battery energy storage against potential cyber-attacks. The method can be applied to any third-party inverter systems without a need to modify their internal controls. A small random private excitation signal termed "watermark" is injected into the DC input voltage terminals (via a series transformer) connected to the PV/battery inverter system. An external robust cyber intrusion detector (CID) hardware consisting of a digital signal processor (DSP) generates the "watermark" and also receives the sensor signals that control the setpoints of the PV/battery grid tied system. The CID algorithm is shown to detect all possible cyber intrusions (such as false data injection(FDI)) on external sensor signals such as P and Q measured by a smart meter that control the overall system operation. The proposed CID computes online system ID and two variance tests in real time on each sensor signal and is able pinpoint intrusion location in a multi-inverter system. Results on a hardware in the loop (HIL) of a two-inverter grid connected system demonstrate effectiveness of the proposed CID system for FDI and unobservable FDI. Test results on a laboratory prototype will be discussed in the conference presentation.

Ibrahim, Hasan↗

Nominal and adversarial synthetic PMU data for standard IEEE test systems

GridSTAGE (Spatio-Temporal Adversarial scenario GEneration) is a framework for the simulation of adversarial scenarios and the generation of multivariate spatio-temporal data in cyber-physical systems. GridSTAGE is developed based on Matlab and leverages Power System Toolbox (PST) where the evolution of the power network is governed by nonlinear differential equations. Using GridSTAGE, one can create several event scenarios that correspond to several operating states of the power network by enabling or disabling any of the following: faults, AGC control, PSS control, exciter control, load changes, generation changes, and different types of cyber-attacks. Standard IEEE bus system data is used to define the power system environment. GridSTAGE emulates the data from PMU and SCADA sensors. The rate of frequency and location of the sensors can be adjusted as well. Detailed instructions on generating data scenarios with different system topologies, attack characteristics, load characteristics, sensor configuration, control parameters are available in the Github repository - https://github.com/pnnl/GridSTAGE. There is no existing adversarial data-generation framework that can incorporate several attack characteristics and yield adversarial PMU data. The GridSTAGE framework currently supports simulation of False Data Injection attacks (such as a ramp, step, random, trapezoidal, multiplicative, replay, freezing) and Denial of Service attacks (such as time-delay, packet-loss) on PMU data. Furthermore, it supports generating spatio-temporal time-series data corresponding to several random load changes across the network or corresponding to several generation changes. A Koopman mode decomposition (KMD) based algorithm to detect and identify the false data attacks in real-time is proposed in https://ieeexplore.ieee.org/document/9303022. Machine learning-based predictive models are developed to capture the dynamics of the underlying power system with a high level of accuracy under various operating conditions for IEEE 68 bus system. The corresponding machine learning models are available at https://github.com/pnnl/grid_prediction.

99 GENERAL AND MISCELLANEOUS↗

Designing an Intrusion Detection for an Adjustable Speed Drive System Controlling a Critical Process

In this article, we address the cyber-security problem of industrial control systems (ICSs) when their sensor measurements may be compromised due to an attacker who has intercepted those measurements via a network. We introduce a general-purpose method “Dynamic Watermarking (DW)” to detect potential cyber-intrusions on speed sensor measurements within industrial control systems, which deploy an adjustable speed drive (ASD) to control a critical process. The DW method is injecting a random private low-amplitude signal with a zero mean Gaussian distribution, “watermark”, into one of the input phase voltages powering the ASD system. The watermark signal propagates through the system including pulse width modulation (PWM) power conversion stage and motor, then ultimately appears in the speed sensor measurements. By deploying two statistical DW tests with two proper thresholds, the system can detect potential cyber-intrusions or unobservable cyber-attacks such as replay attacks and false data injection attacks (FDIA). The DW method tested on a laboratory-scale ASD system experimentally to protect the system against cyber-intrusions. This system, powered by a commercial PWM drive operating at 208 V, 3-phase, and 3.7 kW, served as our experimental platform.

42 ENGINEERING↗

Impact of cyber attacks on distributed compressive sensing based state estimation in power distribution grids

Modern power distribution grids suffer from multiple vulnerabilities due to the tight integration between the physical system and the cyber infrastructure. Sophisticated and malicious cyber attacks continue to adversely impact the grid operation leading to performance degradation, service interruption, and grid failure. State estimation plays an essential role in grid monitoring and advancing cyber-attack situational awareness. In this regard, this paper first proposes a distributed compressive sensing (CS) state estimation approach for an unobservable distribution grid. Further, the proposed distributed CS approach divides the distribution grid into sub-areas to perform local state estimation. Then an alternating direction method of multipliers (ADMM) based iterative information exchange among neighboring areas is employed to complete the estimation process. In this estimation process, the impact of loss of measurement data, false data injection (FDI), replay, and neighborhood cyber-attacks is analyzed. Extensive simulations are performed on the IEEE 37-bus and IEEE 123-bus standard networks to demonstrate the algorithm’s robustness to the aforementioned cyber-attacks. A quantitative analysis of computational complexity and simulation time of the distributed CS based approach is also presented.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cyberattack Detection and Mitigation on Central Volt‐VAr Using Circuit Law and Machine Learning

ABSTRACT In a distribution grid, voltage is maintained within a nominal range through a Volt‐VAr function that controls capacitor banks, reactive power of distributed energy resources (DER), and on‐load tap changers (OLTC). Availability of communications helps with the implementation of central Volt‐VAr control; however, it also opens the system to cyberattacks, causing voltage disturbances. Previous work has shown the adverse impacts of false data injection (FDI) on the central Volt‐VAr control; however, very few works have studied methods to detect and mitigate FDI on Volt‐VAr control. This paper addresses gaps in the detection and mitigation of FDI on the measurement packets of a central Volt‐VAr control. This work uses a two‐stage algorithm for cyberattack detection since the accuracy of a single‐stage machine learning (ML)–based detection method decreases while dealing with unseen data. The first stage is based on the verification of measurements against circuit laws, and the second stage utilizes a tree search algorithm and an ML method to detect the falsified data. This paper compares long short‐term memory (LSTM) and bidirectional LSTM (BiLSTM) as the employed ML algorithms. Finally, the mitigation algorithm replaces the falsified data with the estimated output of the ML algorithm. The effectiveness of the proposed method is tested for several cases using the IEEE 13‐bus test system in PSCAD software.

Beikbabaei, Milad [Bradley Department of Electrica↗

A Proactive Stochastic Framework for Cyber-Physical Power Systems Security

This paper presents a framework for cyberphysical power systems security in which defensive action is proactive, striving to mitigate the harm from strategic cyber attacks before they occur. The prospect is formulated in a previously-studied context of state estimation via the Kalman filter under false data injection attacks. Assuming a cognitive attacker who is both advanced and persistent, the proactive defense rests upon stochastically influencing the sensors, Phasor Measurement Units, such that subsequent falsification attacks are countered. Examples are crafted to illustrate both the efficacy of the proactive approach in ideal situations and the practical challenges implied by non-ideal situations.

El Mezyani, Touria↗

SNNPG: Using Spiking Neural Networks to Detect Attacks in the Power Grid

We explore the potential of Spiking Neural Networks (SNN) to enhance the security of power grid operations by detecting False Data Injection (FDI) attacks. These attacks manipulate PMU readings, leading to erroneous control decisions and grid disruptions. We develop a method to convert Phase Measurement Unit (PMU) data into spike trains, capturing both temporal and spatial dimensions. Using an SNN model, we conduct evaluations with simulated power grid data, showcasing accuracy in detecting FDI attacks. SNN models rapidly identify anomalies in real-time PMU data, safeguarding grid operations by alerting operators to irregular readings and preventing incorrect decisions.

artificial intelligence↗

Prediction of Power Measurements Using Adaptive Filters

With the advent of smart grid concept, Internet of Things (IoT) and the deployment of smart meters, the cyberattack threats on power networks have increased due to the use of communication systems that can be accessed by adversaries. Attackers will have the ability to manipulate the outcomes of smart meters which in turn influence the core application of Energy Management System 9EMS): State Estimation (SE). Bad data analytic tools may fail to detect some attacks into measurements. Meanwhile, Machine Learning (ML) solutions have been proposed for detecting False Data Injection (FDI) attacks. However, there is a lack of ML time-series solutions presented in the state-of-the-art that is yet to be complex. In signal processing, time-series solutions do not only consider the signal, but also the statistics of the signal over time. Therefore, in this paper, a machine learning for time-series solutions is presented as an application to model the measurements of the power grid that are used in SE. The presented model takes into account adaptive linear and non-linear filters: Finite Impulse Response (FIR), and Infinite Impulse Response (IIR). The presented models are implemented and performed on the IEEE-118 bus system. The results indicate the advantage of applying those filters over the state-of-the-art machine learning solutions.

Hamad, Khaled↗

Cybersecurity Challenges in Low-Inertia Power-Electronics-Dominated Grids

Here, the low inertia characteristics of the power electronics dominated grid (PEDG) introduces challenges while restoring voltage and frequency to their nominal values. These stability challenges create new cybersecurity vulnerabilities that are not thoroughly discussed in the literature. Cyber events such as false data injection (FDI), denial of service (DoS), man-in-the-middle attacks, stealthy attacks, and advanced persistent threats target PEDG to disrupt grid stability or gain financial benefits. The low inertia of PEDG (< 2s) compared to traditional grids (~10s) exacerbates these vulnerabilities. In response to stealthy attacks on state variables that supervisory layers cannot detect until significant harm occurs, the low inertia characteristics of PEDG offer substantial stealthy attack surfaces. To counteract such threats, PEDG must be equipped with ultra-fast real-time anomaly detection system and trajectory prediction mechanism to achieve effective cyberattack resiliency.

24 POWER TRANSMISSION AND DISTRIBUTION↗