Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “attack modeling”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Adversarial Attacks on Deep Neural Network-based Power System Event Classification Models

Online event classification is essential to strengthening the reliability of the power transmission system. Recently, deep learning based methods have achieved great success in numerous domains such as computer vision and natural language processing. Researchers began to adopt deep learning based methods to solve the power system event identification problem and achieved effective results. However, these previous works do not consider that deep learning models are vulnerable to adversarial attacks, potentially influencing real-world applications' reliability. In this paper, we adopt several adversarial attack mechanisms by adding tailored noise signal to the input Phasor Measurement Units (PMU) time series and make the deep learning model misclassify the power system event. This numerical study discloses that current state-of-the-art deep learning based power system event classifiers are extremely vulnerable to adversarial attacks, which may jeopardize the reliability of the power transmission system.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Dynamic probabilistic risk assessment and game theory for cyber security risk analysis in nuclear power plants

Nuclear Power Plants and energy systems have become more prone to cyber-attacks with their digitalization and the increased use of smart equipment. Hence, it is important to quantify the risk associated with cyber-attacks in such systems. Dynamic Probabilistic Risk Assessment which involves studying the evolution of a system due to random events and operator and attacker actions during a cyber-attack by employing a physics-based model of the system is a suitable framework to quantify cybersecurity risk in nuclear power plants. In addition to the plant dynamics, it is also important to model the strategies of the attackers and plant operators for an effective cybersecurity risk assessment. Game theory provides a set of necessary tools to model such strategic interactions. In this research, a framework that integrates dynamic probabilistic risk assessment with game theory for cybersecurity risk analysis in nuclear power plants is presented. The mathematical formulation is derived based on the theory of continuous event trees. We propose a game theory based action model, that utilizes physics-based rewards to define the strategies of attackers and operators at every decision epoch. As a case study, the risk associated with cyber-attacks on the digital components in the secondary side of a pressurized water reactor is studied using a reduced order model. A set of attacker actions and a set of operator actions are defined for the system. The operator and attacker interactions were modelled using simultaneous game, their action policies were computed using the concept of mixed strategy Nash equilibrium and the evolution of the system was studied.

97 MATHEMATICS AND COMPUTING↗

Autonomous System Subversion Tactics: Prototypes and Recommended Countermeasures

One of the fielding requirements for Advanced and Small Modular Reactors (AR/SMR) is the ability to support remote and autonomous operations. Autonomous Control Systems (ACS) are found on platforms such as Autonomous Space Vehicles, Cruise Missiles, and advanced driver-assistance systems. Each of these ACS implementations depends upon a set of decision support subsystems responsible for supporting Autonomous Mission Managers (names vary based upon field and author preferences). These Autonomous Mission Managers receive inputs from system sensors (e.g., LIDAR collection from an automobile travelling down a street; transients from a nuclear reactor), and perform a set of classifications (e.g., Red Traffic Light; Small Pedestrian at 10m; Load Rejection; Single Coolant Pump Trip), and then use these classifications in combination with recommendation algorithms to achieve platform goals (e.g., Stop the Vehicle at the Traffic Light, Avoid the Small Pedestrian; Trip the Reactor to prevent a Safety Event). The design, implementation, and fielding of an ACS capability will alter the cyber-attack surface such that existing risk management plans will need to be updated to include how to protect and defend against data-science and decision-support-system attack classes. These attack classes would include protection of the design and training environments where algorithm selection and testing and training data would be obvious attack vectors. These attack classes would also require an informed set of detection and response procedures to identify anomalous behaviors and document best practices for anomaly assessment and vulnerability mitigation and remediation. Last year we published a Cyber Threat Assessment Methodology for Autonomous and Remote Operations for AR/SMRs along with a companion publication on Cyber Attack and Defense Use Cases. The focus of the methodology was on describing and enumerating ACS processes, components, and functions such that security engineers could: evaluate subversion options against the target; identify threat actor attributes and capabilities derived from each subversion option; and identify security controls and response countermeasures. The Use Cases document offered detailed methodology examples including an assessment of a Military Base SMR, an Autonomous System Decision Loop, and implementation of AR/SMR Machine Learning algorithms. Our proposal at the end of last year was to focus on implementation of subversion prototypes related to the last Use Case area: AR/SMR Machine Learning (ML) Algorithms. We included six attack scenarios in our Use Cases paper: a Poisoning Attack against ML functions implemented using an FPGA; a Trojaning Attack against ML classifiers exploiting the excitability of Nuclear Engineers; a Backdooring Attack against ML Training environments to ensure persistence of an attack vector; a False Positive Evasion Attack against multi-factor Access Control Systems using clever inputs; an Inference Attack against ML models by an Insider with access to the Operational environment; and an Adversarial Reprogramming Attack against a Material Access Control Video Surveillance System. At the beginning of this year these six attack scenarios were provided to our research teams at Georgia Tech and Idaho State University and each team successfully implemented a subversion attack against a ML implementation to include transient misclassifications. While this is a notable outcome from this type of research, this paper offers the reader insight into not only how to structure and execute these types of attacks, but into the thought process behind how the researcher investigated the problem space, performed initial algorithm implementation, and the trial-and-error behind arriving at the successful subversion prototypes. We include in this paper a set of associated Scenarios on how these subversion prototypes could be implemented and an initial set of guidance for AR/SMR architects, Nuclear Regulators, and Cyber Defenders to implement awareness and defense capabilities into their current operational portfolios.

42 ENGINEERING↗

Quantifying the robustness of deep multispectral segmentation models against natural perturbations and data poisoning

In overhead image segmentation tasks, including additional spectral bands beyond the traditional RGB channels can improve model performance. However, it is still unclear how incorporating this additional data impacts model robustness to adversarial attacks and natural perturbations. For adversarial robustness, the additional in-formation could improve the model’s ability to distinguish malicious inputs, or simply provide new attack avenues and vulnerabilities. For natural perturbations, the additional information could better inform model decisions and weaken perturbation effects or have no significant influence at all. In this work, we seek to characterize the performance and robustness of a multispectral (RGB and near infrared) image segmentation model subjected to adversarial attacks and natural perturbations. While existing adversarial and natural robustness research has focused primarily on digital perturbations, we prioritize on creating realistic perturbations designed with physical world conditions in mind. For adversarial robustness, we focus on data poisoning attacks whereas for natural robustness, we focus on extending ImageNet-C common corruptions for fog and snow that coherently and self-consistently perturbs the input data. Overall, we find both RGB and multispectral models are vulnerable to data poisoning attacks regardless of input or fusion architectures and that while physically-realizable natural perturbations still degrade model performance, the impact differs based on fusion architecture and input data.

Deep learning, multispectral images, multimodal fu↗

A Dynamic Risk Framework for the Optimization of Physical Security Posture of Nuclear Power Plants

This paper describes an ongoing work within the Light Water Reactor Sustainability pathway at Idaho National Laboratory (INL) to optimize security and cost of nuclear power plants. It introduces the dynamic risk assessment tool developed at INL, Event Modeling Risk Assessment using Linked Diagrams (EMRALD). EMRALD was leveraged to optimize the security posture of a nuclear power plant by integrating force-on-force (FOF) simulations and operator mitigation actions including the dynamic and flexible coping strategies (FLEX). To illustrate the methodology, four attack scenarios were modeled in a commercially available FOF simulation tool using a hypothetical nuclear power plant facility. The simulation results provide valuable insights into possible attack outcomes, as well as the probabilistic risk of core damage event given these outcomes. Safety mitigation procedures were modeled in EMRALD dependent on the attack outcomes by considering human operator uncertainties. The results demonstrate that the number of armed responders can be optimized, while still maintaining the same protection level as the initial security posture. The proposed modeling and simulation framework of integrating FLEX equipment with FOF models enables the nuclear power plants to credit FLEX portable equipment in the plant security posture, resulting in an efficient and optimized physical security system.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

A Dynamic Risk Framework for the Physical Security of Nuclear Power Plants

This paper describes ongoing work within the Light Water Reactor Sustainability pathway at Idaho National Laboratory (INL) to optimize the security and cost of nuclear power plants. It introduces the dynamic risk assessment tool developed at INL, Event Modeling Risk Assessment using Linked Diagrams (EMRALD). EMRALD is leveraged to optimize the security posture of a nuclear power plant by integrating force-on-force (FOF) simulations and operator mitigation actions, including dynamic and flexible coping strategies (FLEX). To illustrate the methodology, four attack scenarios are modeled in a commercially available FOF simulation tool using a hypothetical nuclear power plant facility. The simulation results provide valuable insights into possible attack outcomes, as well as the probabilistic risk of a core damage event given these outcomes. Safety mitigation procedures are modeled in EMRALD dependent on the attack outcomes by considering human operator uncertainties. The results demonstrate that the number of armed responders can be optimized, while still maintaining the same protection level as the initial security posture. The proposed modeling and simulation framework of integrating FLEX equipment with FOF models enables the nuclear power plants to credit FLEX portable equipment in the plant security posture, resulting in an efficient and optimized physical security system.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Cyber-Attack Detection for Photovoltaic Farms Based on Power-Electronics-Enabled Harmonic State Space Modeling

Here in this paper, a physics-data-based detection method is proposed to detect a variety of cyber-attacks in Photovoltaic (PV) farms using the power electronics-enabled harmonic state space (HSS) models, which, to our knowledge, is original. At the device level, HSS-based detection is developed to monitor harmonic vectors of individual PV converter with minimum sensor measurements, thus improving accuracy and robustness compared to Kalman Filter-based detection. At the system level that involves multiple PV converters, a clustering approach is developed to investigate attack propagation and accurately locate attack sources within a PV farm. The proposed approach is one of the first attempts to address PV security through interaction between the device and system, maximizing the accuracy and robustness at different levels. To verify the feasibility, a comprehensive attacks model is built, including single attack, coordinated attacks, and replay attacks. Besides, the impacts of irradiance changes are taken into consideration in the test scenarios. With the real-time data acquisition and hardware-in-the-loop testbed, comprehensive test results are provided to verify the feasibility of the proposed detection methodology.

42 ENGINEERING↗

AdvEP

AdvEP is a code repository which contains PyTorch implementations of various adversarial attacks on a deep neural network trained with Equilibrium Propagation (EP), which is a neuromorphic learning framework. AdvEP allows for the training, testing, and conducting white/black-box attacks of EP models on a wide variety of applications and datasets. AdvEP is based on the open-source code https://github.com/Laborieux-Axel/Equilibrium-Propagation which was developed to train energy models. AdvEP was created by modifying the original code to perform and test against adversarial attacks. AdvEP was developed in Python, a high-level programming language that takes advantage of the Python ecosystem of high-quality open-source packages for machine learning. AdvEP interfaces heavily with the open-source PyTorch Python package as well as the open-source Adversarial Robustness Toolbox (ART) package.

Mansingh, Siddarth↗

Multi-scale fission product release model with comparison to AGR data

TRistructural ISOtropic (TRISO) particle fuel is central to several advanced, high-temperature reactor designs. Each particle consists of a fuel kernel encapsulated by three layers of carbon and ceramics that prevent the release of fission products and ensure physical integrity. Despite outstanding retention properties, fission product release has been observed from intact particles. To better understand and quantify fission product release from TRISO particles, a multiscale, mechanistic model of fission product transport is being developed by the Nuclear Energy Advanced Modeling and Simulation (NEAMS) program. Previous work focused on silver (Ag) transport and improved Ag release predictions. The work described in this report builds on this experience to better understand cesium (Cs) transport in silicon carbide (SiC), the main barrier to the release of fission products. Atomistic simulations provide bulk and grain boundary (GB) Cs diffusivities in SiC, which are used by phase field simulations in the mesoscale code Marmot to determine the temperature, microstructure, and irradiation-dependent Cs diffusivity at the mesoscale in SiC. This approach attributes the different temperature regimes experimentally observed for Cs diffusivities in SiC to a transition from bulk-dominated diffusivity at high temperatures to a GB-dominated regime at low temperatures, providing new insight. The multiscale, mechanistic effective diffusivity is then implemented in the fuel performance code BISON and further validated by comparing Cs release predictions from Advanced Gas Reactor (AGR)-1 and AGR-2 post-irradiation measurements. The new model improves BISON’s predictability. This document also reports improvements made on Ag transport modeling by accounting for different GB types having different diffusivities. Moreover, this report details preliminary efforts to model palladium (Pd) attack of the SiC at the mesoscale using a phase field approach. Pd attack and its impact on accelerated Ag transport remains a misunderstood phenomenon, and we use the model to demonstrate that the formation of lamellae that has been observed in experiments can be explained by the reaction of Pd with SiC to form alternating layers of graphite and Pd 2 Si. This effort aims to improve our understanding of the reaction and eventually provide a model for BISON to account for Pd penetration and its effects on fission product release.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Hybrid Attack Graph Generation with Graph Convolutional Deep-Q Learning

Critical infrastructures such as power grids have become increasingly complex, connected, and vulnerable to adverse scenarios, including cyber and physical attacks and faults. Effective risk mitigation for such cyber-physical energy systems (CPES), requires preemptive knowledge of likely adversarial attack scenarios. Hybrid Attack Graph (HAG) is a structured way to represent an adversarial scenario as an attack sequence using a threat model. However, the scarcity of documented attack sequences hinders analysts and CPES planners’ ability to identify credible attack scenarios for a given CPES. We propose a data-driven Graph Convolutional Deep-Q Network (GCDQ) to address this data challenge through generating HAGs. By leveraging limited real-world observations from the MITRE ATT&CK knowledge base, our GCDQ model synthesizes realistic graphs with the targeted attribute of minimum detectability via reinforcement learning. This generative model is the first step in creating a tool to substantially boost the attack sequence dataset and enhance the performance of CPS defense-related tasks by providing insights into likely attack sequences with given attributes.

deep learning, artificial intelligence↗

Hybrid Cyber-attack Detection in Photovoltaic Farms

Here, to address the cyber-physical security in PV farms, a hybrid cyber-attack detection is proposed in this manuscript. To secure PV farms, the proposed method integrates model-based and data-driven methods by fusing the detection score at the device and system levels. First, a model-based cyber-attack detection method is developed for each PV inverter. A residual between the estimation of the Kalman filter and measurement is calculated. By leveraging the calculated residual from all inverters, a squared Mahalanobis distance is developed for device detection score generation. At the system level, a convolutional neural network (CNN) is proposed to detect cyber-attack using the waveform data at the point of common coupling (PCC) in PV farms. To improve the CNN detection accuracy, a set of well-designed features are extracted from the raw waveform data. Finally, a weighted detection score fusion method is proposed to combine device and system detection scores by using their complementary strength. The feasibility and robustness of the proposed method are validated by testing cases and a comparative experiment.

14 SOLAR ENERGY↗

A tri-level optimization model for interdependent infrastructure network resilience against compound hazard events

Resilient operation of interdependent infrastructures against compound hazard events is essential for maintaining societal well-being. To address consequence assessment challenges in this problem space, we propose a novel policy-guided tri-level optimization model applied to a proof-of-concept case study with fuel distribution and transportation networks – encompassing one realistic network; one fictitious, yet realistic network; as well as networks drawn from three synthetic distributions. Mathematically, our approach takes the form of a defender-attacker-defender (DAD) model—a multi-agent tri-level optimization, comprised of a defender, attacker, and an operator acting in sequence. Here, in this study, our notional operator may choose proxy actions to operate an interdependent system comprised of fuel terminals and gas stations (functioning as supplies) and a transportation network with traffic flow (functioning as demand) to minimize unmet demand at gas stations. A notional attacker aims to hypothetically disrupt normal operations by reducing supply at the supply terminals, and the notional defender aims to identify best proxy defense policy options which include hardening supply terminals or allowing alternative distribution methods such as trucking reserve supplies. We solve our DAD formulation at a metropolitan scale and present practical defense policy insights against hypothetical compound hazards. We demonstrate the generalizability of our framework by presenting results for a realistic network; a fictitious, yet realistic network; as well as for three networks drawn from synthetic distributions. Additionally, we demonstrate the scalability of the framework by investigating runtime performance as a function of the network size. Steps for future research are also discussed.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Online and Offline Identification of False Data Injection Attacks in Battery Sensors Using a Single Particle Model

The cells in battery energy storage systems are monitored, protected, and controlled by battery management systems whose sensors are susceptible to cyberattacks. False data injection attacks (FDIAs) targeting batteries’ voltage sensors affect cell protection functions and the estimation of critical battery states like the state of charge (SoC). Inaccurate SoC estimation could result in battery overcharging and over discharging, which can have disastrous consequences on grid operations. This paper proposes a three-pronged online and offline method to detect, identify, and classify FDIAs corrupting the voltage sensors of a battery stack. To accurately model the dynamics of the series-connected cells a single particle model is used and to estimate the SoC, the unscented Kalman filter is employed. FDIA detection, identification, and classification was accomplished using a tuned cumulative sum (CUSUM) algorithm, which was compared with a baseline method, the chi-squared error detector. Online simulations and offline batch simulations were performed to determine the effectiveness of the proposed approach. Throughout the batch simulations, the CUSUM algorithm detected attacks, with no false positives, in 99.83% of cases, identified the corrupted sensor in 97% of cases, and determined if the attack was positively or negatively biased in 97% of cases.

25 ENERGY STORAGE↗

A Distributed Trust Model Simulator for Energy Grid of Things Distributed Energy Resource Management System

The evolution of networks into more distributed, self-reliant nodes has mitigated single-point failures that plagued traditional centralized networks. Applied to power grids, distributed systems can increase the integrity and availability of grid services while also offering a power management solution. However, while distributed networks provide scalability, security, and sustainability compared to centralized networks, their distributed nature makes them harder for anomaly detection and prevention. Incorporating a Distributed Trust Model (DTM) System into an Energy Grid of Things Distributed Energy Resource Management System (EGOT DERMS) allows grid participants to be characterized and their communication to be analyzed for possible attacks. A Trust Model simulator is needed to evaluate and improve the DTM System.Trustworthiness is calculated using a Trust Model. While many trust models exist, most only consider 2-3 matrices to evaluate trust. The TM proposed in this thesis uses a Metric Vector of Trust (MVoT) monitoring 17 parameters when assessing trust. Moreover, unlike standard trust models, the proposed trust model establishes a method to test the trust between various actors within the network and probe the trust model itself. Using a Trust Model Simulator, MVoT calaculations, initial values, and parameters are fine-tuned to achieve high-confidence message classifications and minimize false positives. The DTM System and Trust Mode Simulation Suite allow for distributed trust evaluation with a real-time classification of EGOT DERMS actors, providing additional security for distributed systems.

32 ENERGY CONSERVATION, CONSUMPTION, AND UTILIZATI↗

A Four-Layer Cyber-Physical Security Model for Electric Machine Drives Considering Control Information Flow

Despite the IEEE Power Electronics Society (PELS) establishing Technical Committee 10 on Design Methodologies with a focus on the cyber-physical security of power electronics systems, a holistic design methodology for addressing security vulnerabilities remains underdeveloped. This gap largely stems from the limited integration of computer science and power/control engineering studies in this interdisciplinary field. Addressing the inadequacy of unilateral cyber or control perspectives, this article presents a novel four-layer cyber-physical security model specifically designed for electric machine drives. Central to this model is the innovative control information flow (CIF) model, residing within the control layer, which serves as a pivotal link between the cyber layer's vulnerable resources and the physical layer's state-space models. By mapping vulnerable resources to control variable space and tracing attack propagation, the CIF model facilitates accurate impact predictions based on tainted control laws. The effectiveness and validity of this proposed model are demonstrated through hardware experiments involving two typical cyber-attack scenarios, underscoring its potential as a comprehensive framework for multidisciplinary security strategies.

97 MATHEMATICS AND COMPUTING↗

AdversarialTensors

This library builds a framework for defending ML models against adversarial attacks. The library will be developed at various stages leading to publication and software release at each stage. We employ tensor decomposition strategies as preprocessing stages for the first stage to provide robustness against the prominent adversarial noise. In the second stage, we develop a latent noise generator capable of generating novel adversarial noise that threatens the existing state-of-the-art defense strategy. In the third stage, we develop a UNSUP-GAN model, where the generator is trained to denoise against latent noise and most adversarial noises. This generator can provide a robust adversarial attack against any unseen attack.

Bhattarai, Manish↗

Data Security Defense: Modeling and Detection of Synchrophasor Data Spoofing Attack for Grid Edge

Data security and cyberattack have become critical issues in the distributed power system where adversaries can swap the source information of sensors or even spoof and alter measurements. However, the cyber security of the power system is challenged by the unpredictability and stealth of the spoofing attacks. Here, to protect the data security at the grid edge, this paper developed a synchrophasor data spoofing attack detection framework based on the time-frequency feature extraction techniques including the short-time Fourier transform (STFT) and object detection network for real-time synchrophasor data categorization and spoofing attack localization. The proposed approach outperforms earlier work in terms of spoofing attack detection and offers a vital localization function employing distributed synchrophasor sensors.

24 POWER TRANSMISSION AND DISTRIBUTION↗