Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Adversarial attacks”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

Bennett-Brassard 1984 quantum key distribution using conjugate homodyne detection

Optical homodyne detection has been widely used in continuous-variable (CV) quantum information processing for measuring field quadrature. In this paper we explore the possibility of operating a conjugate homodyne detection system in “photon counting” mode to implement discrete-variable (DV) quantum key distribution (QKD). A conjugate homodyne detection system, which consists of a beam splitter followed by two optical homodyne detectors, can simultaneously measure a pair of conjugate quadratures X and P of the incoming quantum state. In classical electrodynamics, X 2 + P 2 is proportional to the energy (the photon number) of the input light. In quantum optics, X and P do not commute and thus the above photon-number measurement is intrinsically noisy. This implies that a blind application of standard security proofs of QKD could result in pessimistic performance. We overcome this obstacle by taking advantage of two special features of the proposed detection scheme. First, the fundamental detection noise associated with vacuum fluctuations cannot be manipulated by an external adversary. Second, the ability to reconstruct the photon number distribution at the receiver's end can place additional constraints on possible attacks from the adversary. As an example, we study the security of the BB84 QKD using conjugate homodyne detection and evaluate its performance through numerical simulations. This study may open the door to a family of QKD protocols, complementary to the well-established DV-QKD based on single-photon detection and CV-QKD based on coherent detection.

71 CLASSICAL AND QUANTUM MECHANICS, GENERAL PHYSIC↗

Introduction to ALERT: A User-Interface Tool for Resilient Optimization

As the cyber-physical systems grow in complexity, there is a need for proactive resilience strategies that involve online, adaptive control actions to best prepare for any impending adversarial events. In this technical effort, supported by RD2C LDRD initiative, the project team designed and demonstrated online strategies – referred to as ALERT controls – for proactive and adaptive tuning of existing optimal controls in a microgrid, with quantifiably assured margins of resilience to various cyber-physical adversarial events. This ALERT functionality is made available to the end-users, e.g., the system operators, via an interactive user-interface. The end-users will not only be able to use the interface to visualize the system’s operation under various cyber-physical adversarial scenarios, but also evaluate the amount of tolerance the system has against selected adversarial perturbations of interest (e.g., malfunctioning sensors, suspected attacked measurements) via the adversarial plots. In this technical report, we briefly outline the algorithmic modules of the developed ALERT control technology, and introduce the user-interface tool that allows end-users (e.g., microgrid operators) to enter their system description, specify various operational and resilience requirements, and evaluate the impact of the control decisions via illustrative plots.

97 MATHEMATICS AND COMPUTING↗

Understanding Impacts of Data Integrity Attacks on Transactive Control Systems

With the rapid growth of internet-connected smart devices capable of exchanging energy price information and adaptively controlling energy consumption of connected loads, the role of transactive control is expected to become more prominent in the modern grid. Transactive control systems integrate the wholesale and retail energy markets, and enable active participation of end users, thereby playing a key role in managing the rising number of distributed assets in the smart grid. The use of internet for the communication of data between the controllers at the building, distribution, and transmission levels makes the system susceptible to cyber-attacks. A skilled adversary can potentially manipulate the exchanged data with the intention of inflicting damage to the system. In this paper, four categories of metrics are put forth for evaluating the performance of the system when under data integrity attacks. A model for scaling-based data integrity attack has been described, and co-simulations have been performed on a 240 bus WECC transmission system model with detailed modeling of distribution systems at specific buses. Our results show that scaling-based data integrity attacks can have non-trivial impacts on the operational, financial, and comfort aspects of the transactive control system.

Smart grid, transactive control system, Buildings-↗

Cyber-Physical Tabletop Exercise for Small Modular Reactor Facilities

U.S. nuclear power facilities face increasing challenges in meeting dynamic security requirements caused by evolving and expanding threats while keeping costs reasonable to make nuclear energy competitive. This evolving threat landscape includes adversaries having offensive cyber capabilities to attack information technology (IT) systems and operation technology (OT) systems. These adversaries may have the ability to attack the physical protection system (PPS) networks with potential consequential impacts that could degrade the effectiveness of the PPS. These cyber attacks may also be used to attack the safety and operational systems used to operate and ensure the safety of the reactor. Additionally, adversaries may gain access to unmanned aerial systems (UAS) that may be used to provide reconnaissance and surveillance of the facility, provide information to the adversaries, and be equipped with kinetic capabilities such as explosives or weapons that can be used to directly attack the facility. The Department of Energy’s Office of Nuclear Energy’s Advanced Reactor Safeguards and Security (ARSS) program funded Sandia National Laboratories (SNL) and Idaho National Laboratory (INL) to develop a cyber-physical tabletop exercise (TTX). This exercise was conducted on a hypothetical small modular reactor (SMR) facility, and only considered a potential adversary cyber attack on the PPS to a physical attack on the hypothetical facility to achieve a radiological release. This cyber-physical TTX is meant to provide lessons learned to integrate the cyber security system design and the physical protection system (PPS) design to decrease design, operation, and maintenance costs as well as increase effectiveness for defending against design basis threat attacks at the facility. This TTX will also provide a framework and method for SMR and microreactor vendors to conduct their own cyber-physical TTX and gain impactful insights to improving the cyber and physical protection system design for their SMR or microreactor facility design.

42 ENGINEERING↗

Vind: A Blockchain-Enabled Supply Chain Provenance Framework for Energy Delivery Systems

Enterprise-level energy delivery systems (EDSs) depend on different software or hardware vendors to achieve operational efficiency. Critical components of these systems are typically manufactured and integrated by overseas suppliers, which expands the attack surface to adversaries with additional opportunities to infiltrate into EDSs. Due to this reason, the risk management of the EDS supply chain is crucial to ensure that we are knowledgeable about the vulnerabilities in software and hardware components that comprise any critical part, quantifiable risk metrics to assess the severity and exploitability of the attack, and provide remediation solutions that can influence a prioritized mitigation plan. There is a need to realize cyber supply chain risk management for industrial control systems’ hardware, software, and computing and networking services associated with bulk electric system (BES) operations. This article proposes a blockchain-based cyber supply chain provenance platform (“Vind”) for EDSs to realize data provenance in a cyber supply chain ecosystem.

Bandara, Eranga↗

Cybersecurity Considerations for Grid-Connected Batteries with Hardware Demonstrations

The share of renewable and distributed energy resources (DERs), like wind turbines, solar photovoltaics and grid-connected batteries, interconnected to the electric grid is rapidly increasing due to reduced costs, rising efficiency, and regulatory requirements aimed at incentivizing a lower-carbon electricity system. These distributed energy resources differ from traditional generation in many ways including the use of many smaller devices connected primarily (but not exclusively) to the distribution network, rather than few larger devices connected to the transmission network. DERs being installed today often include modern communication hardware like cellular modems and WiFi connectivity and, in addition, the inverters used to connect these resources to the grid are gaining increasingly complex capabilities, like providing voltage and frequency support or supporting microgrids. To perform these new functions safely, communications to the device and more complex controls are required. The distributed nature of DER devices combined with their network connectivity and complex controls interfaces present a larger potential attack surface for adversaries looking to create instability in power systems. To address this area of concern, the steps of a cyberattack on DERs have been studied, including the security of industrial protocols, the misuse of the DER interface, and the physical impacts. These different steps have not previously been tied together in practice and not specifically studied for grid-connected storage devices. In this work, we focus on grid-connected batteries. We explore the potential impacts of a cyberattack on a battery to power system stability, to the battery hardware, and on economics for various stakeholders. We then use real hardware to demonstrate end-to-end attack paths exist when security features are disabled or misconfigured. Our experimental focus is on control interface security and protocol security, with the initial assumption that an adversary has gained access to the network to which the device is connected. We provide real examples of the effectiveness of certain defenses. This work can be used to help utilities and other grid-connected battery owners and operators evaluate the severity of different threats and the effectiveness of defense strategies so they can effectively deploy and protect grid-connected storage devices.

25 ENERGY STORAGE↗

Inferring adversarial behaviour in cyber‐physical power systems using a Bayesian attack graph approach

Abstract Highly connected smart power systems are subject to increasing vulnerabilities and adversarial threats. Defenders need to proactively identify and defend new high‐risk access paths of cyber intruders that target grid resilience. However, cyber‐physical risk analysis and defense in power systems often requires making assumptions on adversary behaviour, and these assumptions can be wrong. Thus, this work examines the problem of inferring adversary behaviour in power systems to improve risk‐based defense and detection. To achieve this, a Bayesian approach for inference of the Cyber‐Adversarial Power System (Bayes‐CAPS) is proposed that uses Bayesian networks (BNs) to define and solve the inference problem of adversarial movement in the grid infrastructure towards targets of physical impact. Specifically, BNs are used to compute conditional probabilities to queries, such as the probability of observing an event given a set of alerts. Bayes‐CAPS builds initial Bayesian attack graphs for realistic power system cyber‐physical models. These models are adaptable using collected data from the system under study. Then, Bayes‐CAPS computes the posterior probabilities of the occurrence of a security breach event in power systems. Experiments are conducted that evaluate algorithms based on time complexity, accuracy and impact of evidence for different scales and densities of network. The performance is evaluated and compared for five realistic cyber‐physical power system models of increasing size and complexities ranging from 8 to 300 substations based on computation and accuracy impacts.

Sahu, Abhijeet↗

Evasion Attacks

Evasion Attacks are cases when an adversary is trying to hide something, or fool, a machine learning system. See reference here: Goodfellow, Shlens, Szegedy, Explaining and Harnessing Adversarial Examples. You can think of evasion attack as similar the little boy from the story, “A Wolf in Sheep’s Clothing”. The little boy appears as one thing (a wolf), but is actually just a little boy. Below are a few more examples that have appeared in literature and the media.

97 MATHEMATICS AND COMPUTING↗

Resilient State Recovery Using Prior Measurement Support Information

Resilient state recovery of cyber-physical systems has attracted much research attention due to the unique challenges posed by the tight coupling between communication, computation, and the underlying physics of such systems. By modeling attacks as additive adversary signals to a sparse subset of measurements, this resilient recovery problem can be formulated as an error correction problem. To achieve exact state recovery, most existing results require less than 50% of the measurement nodes to be compromised, which limits the resiliency of the estimators. In this paper, we show that observer resiliency can be further improved by incorporating data-driven prior information. Here, we provide an analytical bridge between the precision of prior information and the resiliency of the estimator. By quantifying the relationship between the estimation error of the weighted ℓ 1 observer and the precision of the support prior, this quantified relationship provides guidance for the estimator’s weight design to achieve optimal resiliency. Several numerical simulations and an application case study are presented to validate the theoretical claims.

24 POWER TRANSMISSION AND DISTRIBUTION↗

CCE Case Study: Baltavia Substation Power Outage

In this case study, we will examine a fictional event broadly inspired by the real power outages in Ukraine that took place in December 2015 and December 2016 - both the result of cyber-enabled sabotage. The actual events of 2015 and 2016 were well-documented - the adversaries in these attacks gained access to a few power companies’ corporate networks, pivoted to industrial control system (ICS) networks, and created widespread physical effects in the form of power outages.

24 POWER TRANSMISSION AND DISTRIBUTION↗

CCE Case Study: Baltavia Substation Power Outage

In this case study, we will examine a fictional event broadly inspired by the real power outages in Ukraine that took place in December 2015 and December 2016—both the result of cyber-enabled sabotage. The actual events of 2015 and 2016 were well-documented—the adversaries in these attacks gained access to a few power companies’ corporate networks, pivoted to industrial control system (ICS) networks, and created widespread physical effects in the form of power outages.

24 POWER TRANSMISSION AND DISTRIBUTION↗

A Privacy-Preserving Strategy for the Trust Layer of the Energy Grid of Things Distributed Energy Resource Management System

Emergent from the shadows of the traditional grid flaws, the Smart Grid (SG) idea was born and led by government mandates toward cleaner energy production. The SG represents the next generation of electricity distribution systems that subsume recent technological innovations. It uses digital communication between its components and entities to attain more automation, self-sufficiency, and reliability. Unfortunately, this relatively new concept is not flawless; the intrinsic reliance on increased digital communication spreads open attack paths for adversaries. Therefore, finding solutions that address information exchange vulnerabilities has become imperative. The Energy Grid of Things (EGoT) is Portland State University’s (PSU’s) implementation of a Distributed Energy Resource Management System (DERMS). The EGoT DERMS requires access to customers’ information to achieve operational objectives. The system’s access to customers’ information needs to be restricted such that it does not violate customers’ privacy. Applying privacy protection models such as K-anonymity to EGoT DERMS sub-components safeguards that privacy. This thesis work proposes a strategy to ensure communication in the EGoT DERMS is privacy-preserving and secure. Specifically, it provides an approach to applying the Mondrian Algorithm to ensure data within the system excludes Personally Identifiable Information (PII) and provides means for securing the communication according to industry standards (IEEE 2030.5). Results suggest that the generalization hierarchy derived for the EGoT DERMS exhibits an Identical Generalization Hierarchy structure. Guarantees of sameness manifested in the test feeder topology would not hold in real-world scenarios. This thesis work proposes a strategy to ensure communication in the EGoT DERMS is privacy-preserving and secure. Specifically, it provides an approach to applying the Mondrian Algorithm to ensure data within the system excludes Personally Identifiable Information (PII) and provides means for securing the communication according to industry standards (IEEE 2030.5). Results suggest that the generalization hierarchy derived for the EGoT DERMS exhibits an Identical Generalization Hierarchy structure. Guarantees of sameness manifested in the test feeder topology would not hold in real-world scenarios.

Alsiad, Mohammed↗

Cybersecurity Considerations and Research Pathways for Grid-Interactive Efficient Buildings

Federal facilities serve critical missions and functions that require safe, reliable, and efficient operations. Digitization of several facility operations has increased the cost-effectiveness of energy usage and optimization of energy system performance. As the building controls landscape shifts to become more connected and smarter, building operators now face unique opportunities and challenges to adopt smart enabled devices that can lower energy usage while also optimizing building system performance. The grid-interactive efficient buildings (GEB) initiative aims to make buildings cleaner and more flexible through these smart devices. Smart enabled devices allow greater connectivity and control through remote operations and provide crucial data for analytics and increased efficiency. GEBs enable demand flexibility that has the potential to reduce electrical costs and transform the grid edge where buildings connect to power grids. This operation of interconnected systems, if not designed with cybersecurity practices, causes security gaps and introduces potential attack paths by adversarial and non-adversarial entities leading to disruption of operations.

building controls↗

3D reconstruction and neural rendering for adversarial machine learning

While evasion attacks on computer vision systems have been widely studied, creating attacks that remain effective under significant changes in viewpoint continues to be challenging. Traditional approaches often rely on affine transformations of images, but these approaches degrade at larger perspective shifts and often produce unrealistic or ineffective perturbations. Recent methods use differentiable renderers to improve viewpoint robustness, but they typically depend on manually constructed 3D models. We introduce a semi-automated pipeline that generates physically printable and perspective-invariant adversarial patches using only a small set of 2D images. Our method integrates 3D reconstruction, neural rendering, adversarial patch optimization, and an object detection victim model into a unified workflow. We use 2D Gaussian Splatting for high fidelity mesh reconstruction and FlexPara for surface parameterization that produces texture maps suitable for patch editing. Together, these components form a fully differentiable pipeline in PyTorch3D that links texture modification to model outputs, enabling efficient optimization of patches that remain effective across many viewpoints. The complete process, from image capture to patch printing and physical evaluation, can be completed within a few hours. We demonstrate the effectiveness of the resulting patches through attacks on the YOLOv8 object detection model and discuss remaining challenges and opportunities for improving robustness and scalability.

Singhvi, Vivaan [ORNL] (ORCID:0009000586288221)↗

Precursor Analysis Report: JBS Foods Ransomware Attack 2021

The JBS Foods 2021 Ransomware Attack Precursor Analysis Report leverages publicly available information about the JBS ransomware cyber attack and catalogs anomalous observables for each technique employed in the attack. This analysis is based upon the methodology of the Cybersecurity for the Operational Technology Environment (CyOTE) program. In late May 2021, one of the world’s largest meat producers, JBS Foods, announced they had fallen victim to a worldwide ransomware attack, later found to be REvil ransomware. In the United States alone, JBS Foods accounts for nearly 25% of beef and roughly 20% of pork production. Adversaries initially launched a Distributed Denial of Service (DDoS) attack on the company’s Information Technology (IT) networks in Australia, but the attack impacted operations in Brazil, Canada, and the United States, as well. The attack caused plant operations in all four countries to shut down for at least one day. All nine of the U.S. meatpacking plants temporarily shut down because of the attack. The adversaries initially demanded a $\$$22 million ransom for the company’s data, but later negotiated the ransom down to $\$$11 million even after JBS Foods restored most of their systems. JBS Foods eventually paid the $\$$11 Million for reassurance from the adversaries that none of their customers’ data would be compromised in the future. Despite its short duration, the attack still caused large stocks of meat to spoil. The incident also underscored how adversaries can simultaneously compromise and move laterally through global subsidiaries of an organization. Researchers and analysts identified 22 unique techniques (in a sequence of 21 steps) utilized during the attack with a total of 361 observables using MITRE ATT&CK® for Industrial Control Systems. The CyOTE program assesses observables accompanying techniques used prior to the triggering event to identify opportunities to detect malicious activity. If observables accompanying the attack techniques are perceived and investigated prior to the triggering event, earlier comprehension of malicious activity can take place. Sixteen of the identified techniques used during the JBS Foods cyber attack were precursors to the triggering event. Analysis identified 308 observables associated with these precursor techniques, 163 of which were assessed to have an increased likelihood of being perceived in the 75 days preceding the triggering event. The response and comprehension time could have been reduced if the observables had been identified earlier. The information gathered in this report contributes to a library of observables tied to a repository of artifacts, data sources, and technique detection references for practitioners and developers to support the comprehension of indicators of attack. Asset owners and operators can use these products if they experience similar observables or to prepare for comparable scenarios.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Resilient Operating Constraints for Power Distribution Systems under Setpoint Attacks

Integration and operation of distributed generation (DG) and energy storage (ES) in power distribution systems are enabled by communication networks and embedded sensor and control devices that increase the vulnerability of the systems to cyber-threats, broadening the attack surface and making adversary actions more unpredictable. This paper proposes a methodology that uses ellipsoidal approximations to quantify the potential damage caused by successful attacks that affect, directly or indirectly, the desired operation setpoints and may drive the power distribution operation to unsafe states by violating the limits of voltage or line flows. More specifically, a new methodology is introduced to find the optimal non-symmetric operating constraints that can be imposed to each DG and ES in order to guarantee that the power distribution system is resilient to any malicious setpoints. The proposed method takes as inputs the system topology, DG and ES capabilities, and load limits to solve a convex optimization problem formulated using linear matrix inequalities (LMIs) and the power flow equations. The proposed solution is agnostic to the attacker's action or load profile and it does not require any assumption about the location or means of the attack. The numerical results on a test distribution feeder with several DG and ES illustrate how the proposed resilient operating constraints guarantee the security of the power distribution system under setpoint attacks.

Giraldo, Jairo↗

Evaluation of Joint Cyber/Safety Risk in Nuclear Power Systems

This report presents an analysis of the Emergency Core Cooling System (ECCS) for a generic Boiling Water Reactor (BWR)-4 NPP. The Electric Power Research Institute (EPRI) developed Hazards and Consequences Analysis for Digital Systems (HAZCADS) process is applied to the ECCS and its subsystems to identify unsafe control actions (UCAs) which act as possible cyber events of concern. The analysis is performed for two design basis events: Small-break Loss of Coolant Accident (SLOCA) and general transients (TRANS), such as unintended reactor trip. In previous work, HAZCADS UCAs were combined with other cyber-attack analysis to develop a risk-informed approach; however, this was for a single system. This report explores advanced systems engineering modeling approaches to model the interactions between digital assets across multiple systems which may be targeted by cyber adversaries. The complex and interdependent design of digital systems has the potential to introduce emergent cyber properties that are generally not covered by hazard analyses nor formal nuclear Probabilistic Risk Assessment (PRA). The R&D and supporting analysis presented here explores approaches to predict and manage how interdependent system properties effect risk. To show the potential impact of a successful cyber-attack to formal PRA event tree probabilities, HAZCADS analysis was also used. HAZCADS was also used to model the automatic depressurization system (ADS) automatic actuation. This analysis extended to an integrated system analysis for common-cause failure (CCF). In this aspect, the HAZCADS analysis continued by analyzing plant design details for system connectivity in support of critical plant functions. A dependency matrix was developed to depict the integrated functionality of the interconnected systems. Areas of potential CCF are indicated. Future work could include adversary attack development to show how CCF could be caused, resulting in PRA events. Across the multiple systems that comprise the ECCS, the analysis shows that the change in such probabilities was very different between systems. This indicates that some systems have a larger potential risk impact from successful cyber-attack or digital failure, which indicates a need for these systems to have a higher priority for design and defensive measures. Furthermore, we were able to establish that a risk analysis using any arbitrary threat model establishes an ordering of components with regard to cyber-risk. This ordering can be used to influence the overall system design with an eye to lowering risk, or as a way to understand real-time risk to operational systems based on a current threat landscape. Expert knowledge of both the analysis process and the system being analyzed is required to perform a HAZCADS analysis. The need for a tiered risk analysis is demonstrated by the results of this report.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Optimal Mitigation Planning For Adversarial Scenarios

We propose a generalized framework which performs an optimal partitioning of a limited budget into various organizational sectors in order to improve the cybersecurity of a smart device or component in the Cyber Physical Energy System (CPS). The framework identifies the adversarial threats and possible attack sequences which can be performed to exploit cyber vulnerabilities of the component. Thereafter, we formulate an Mixed Integer Linear Programming (MILP) optimization problem which aims to evaluate the optimal budget partitions in order to minimize the number of highly likely attack sequences. Though we provide results for using the framework in CPES, the proposed methodology can be extended for multiple domains with a set of known adversarial and mitigation actions.

Purohit, Sumit [Pacific Northwest National Laborat↗