Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Cyberattack”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

Authentication of smart grid communications using quantum key distribution

Smart grid solutions enable utilities and customers to better monitor and control energy use via information and communications technology. Information technology is intended to improve the future electric grid’s reliability, efficiency, and sustainability by implementing advanced monitoring and control systems. However, leveraging modern communications systems also makes the grid vulnerable to cyberattacks. Here we report the first use of quantum key distribution (QKD) keys in the authentication of smart grid communications. In particular, we make such demonstration on a deployed electric utility fiber network. The developed method was prototyped in a software package to manage and utilize cryptographic keys to authenticate machine-to-machine communications used for supervisory control and data acquisition (SCADA). This demonstration showcases the feasibility of using QKD to improve the security of critical infrastructure, including future distributed energy resources (DERs), such as energy storage.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Design and evaluation of a cyber‐physical testbed for improving attack resilience of power systems

Abstract A power system is a complex cyber‐physical system whose security is critical to its function. A major challenge is to model, analyse and visualise the communication backbone of the power systems concerning cyber threats. To achieve this, the design and evaluation of a cyber‐physical power system (CPPS) testbed called Resilient Energy Systems Lab (RESLab) are presented to capture realistic cyber, physical, and protection system features. RESLab is architected to be a fundamental platform for studying and improving the resilience of complex CPPS to cyber threats. The cyber network is emulated using Common Open Research Emulator (CORE), which acts as a gateway for the physical and protection devices to communicate. The physical grid is simulated in the dynamic time frame using Power World Dynamic Studio (PWDS). The protection components are modelled with both PWDS and physical devices including the SEL Real‐Time Automation Controller (RTAC). Distributed Network Protocol 3 (DNP3) is used to monitor and control the grid. Then, the design is exemplified and the tools are validated. This work presents four case studies on cyberattack and defence using RESLab, where we demonstrate false data and command injection using Man‐in‐the‐Middle and Denial of Service attacks and validate them on a large‐scale synthetic electric grid.

Sahu, Abhijeet↗

FL‐ADS: Federated learning anomaly detection system for distributed energy resource networks

Abstract With the ongoing development of Distributed Energy Resources (DER) communication networks, the imperative for strong cybersecurity and data privacy safeguards is increasingly evident. DER networks, which rely on protocols such as Distributed Network Protocol 3 and Modbus, are susceptible to cyberattacks such as data integrity breaches and denial of service due to their inherent security vulnerabilities. This paper introduces an innovative Federated Learning (FL)‐based anomaly detection system designed to enhance the security of DER networks while preserving data privacy. Our models leverage Vertical and Horizontal Federated Learning to enable collaborative learning while preserving data privacy, exchanging only non‐sensitive information, such as model parameters, and maintaining the privacy of DER clients' raw data. The effectiveness of the models is demonstrated through its evaluation on datasets representative of real‐world DER scenarios, showcasing significant improvements in accuracy and F1‐score across all clients compared to the traditional baseline model. Additionally, this work demonstrates a consistent reduction in loss function over multiple FL rounds, further validating its efficacy and offering a robust solution that balances effective anomaly detection with stringent data privacy needs.

Purohit, Shaurya [Iowa State University Ames Iowa ↗

Overview and Recommendations for Cyber Risk Assessment in Nuclear Power Plants

Digital instrumentation and control (I&C) systems are being deployed in nuclear power plants (NPPs) for both existing and advanced reactor designs. As I&C systems become more digitized to allow features like near autonomous control and remote operation, they introduce greater cyber risk to NPPs. Cyberattacks targeting industrial control systems (ICSs) are growing in both qualities and capabilities, which indicates that cybersecurity needs to be an integral part of risk assessment in the industry. Although there are some risk assessment methods in traditional information technology (IT) cybersecurity, the differences between IT and ICS cybersecurity make it infeasible to apply these risk assessment methods directly to ICSs. Some research has focused on risk assessment methods for ICSs, but few studies focus on applications to NPPs. Ideal risk frameworks for the nuclear industry are dynamic and account for system dependencies; this survey review focuses on such risk assessment methods both in and outside the nuclear field. In this article, the major challenges in cybersecurity risk assessment research are pointed out, and further research suggestions and considerations for cyber risk assessment in I&C systems are identified.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Analysis of AP1000 Small-Break Loss-of-Coolant Accident Using Reactor Transient Simulator

The Westinghouse Electric Company’s Advanced Passive Reactor (AP1000) is characterized by the incorporation of passive safety systems (PSSs) designed to ensure core cooling during transient events. The assessment of PSSs requires evaluation of their performance through a combination of experiments and simulations employing various thermal-hydraulic codes. In addition, detailed evaluation of PSSs for a specific reactor system transient analysis such as loss-of-coolant-accident analysis supports understanding representative integral effects test facility development and the further evolution model development and assessment process. Developing a reactor system code is a complex and time-consuming process that requires significant engineering expertise and effort. It can take several months to even years to complete in the early stages of reactor system design and analysis. However, this process can be expedited through the use of transient simulator models for similar reactor systems, which can be used for lesson learning and training purposes. This study uses the Personal Computer Transient Analyzer (PCTRAN) code. The main advantage of PCTRAN is its ease of use and ability to run faster than real time. This study presents the results obtained for a small-break loss-of-coolant accident (SBLOCA) for two breaks using the full version (licensed) of PCTRAN. The purpose of this investigation is to evaluate the overall system behavior during the postulated SBLOCA event as well as assess the capability of the PCTRAN code to reproduce the system response during transient events. The obtained results were compared with the Westinghouse NOTRUMP system code. The PCTRAN code proved to be reliable in predicting the qualitative behavior of the system in both transient cases. As for the system response, it was found that it is contingent on the activation time of the PSSs. The differences in reactor coolant system pressure between the two codes were attributed to the critical flow model and simplification of mass and energy balance. Despite PCTRAN’s limitations, it can still provide a reasonable prediction of various reactor parameters such as pressure, mass flow rate, and void fraction during a SBLOCA scenario. It is worth noting that PCTRAN currently employs a bulk approach similar to that of the Modular Accident Analysis Program (MAAP) and MELCOR codes. However, the upcoming version of PCTRAN will include an artificial intelligence–based detection and accident prevention system, as well as different models for different reactor components. Consequently, PCTRAN has the potential to be upgraded to match the system thermal-hydraulic codes of the U.S. Nuclear Regulatory Commission and become more widely used in cybersecurity to safeguard nuclear power plants from cyberattacks.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Evaluating Methods of Software Bill of Materials Generation to Enhance Nuclear Power Plant Cybersecurity

Instrumentation and control (I&C) systems in nuclear power plants (NPPs) are potential targets of cyberattacks and can prove deleterious for the safety of the NPPs. A Software Bill of Materials (SBOM) provides a detailed list of the various components and their dependencies in software, which helps in vulnerability and risk assessment for cyber hygiene and situational awareness. For an NPP, the process of generating an accurate SBOM report can be complex due to the legacy systems and firmware binaries involved. While most current SBOM tools are focused more on modern internet technology software, this research provides insights and guidelines for an NPP to generate an accurate and efficient SBOM. Here, the paper proposes a new methodology to help NPPs categorize software and use appropriate tools to generate SBOMs for their digital I&C systems.

SBOM↗

Feature Engineering and Ensemble Methods for Imbalanced ICS Intrusion Detection: Pipeline Audit and Constrained Evaluation

Industries are becoming increasingly connected and are more vulnerable to cyberattacks due to the widened attack surface. Industrial Control Systems (ICS) are among the most critical sectors that malicious actors can target, as such attacks can cause significant operational disruption and physical damage. It is imperative to detect such attacks as early as possible. This paper evaluates constraint-conditioned optimistic performance estimates for traditional ML models in ICS intrusion detection (i.e., estimates obtained under contiguous, non-shuffled temporal evaluation without test-set alteration, but with pre-split feature engineering that may introduce temporal leakage, due to dataset constraints). Our findings are threefold. First, we quantify how iterative feature engineering affects tree-based ensemble performance and examine how pipeline decisions (split strategy, sampling scope, and cleaning policy) can inflate or reduce reported IDS results under constraint-bound evaluation. Second, we compare intrinsic class-imbalance handling across ensemble models. Third, under our current pipeline constraints (including pre-split feature engineering), CatBoost achieves the best performance on Water Storage Tank (accuracy: 0.9831, class-1 F1: 0.9682), while Light- GBM achieves the best performance on Gas Pipeline (accuracy: 0.9618, class-1 F1: 0.9086).

97 MATHEMATICS AND COMPUTING↗

The Impact of Time-Aware Design Choices in ICS Anomaly Detection

Industrial control systems (ICS) remain vulnerable to increasingly sophisticated cyberattacks, yet evaluating anomaly detection models in these environments is challenging due to temporal dependencies, missing-not-at-random patterns, and extremely imbalanced datasets. These factors make common practices—especially random data splits and na¨ıve imputation— prone to severe temporal leakage, which can inflate reported performance and obscure real-world limitations. In this work, we systematically examine classical machine learning models, temporal deep learning architecture, and tensordecomposition– based methods on a gas-pipeline dataset using a fully temporally separated evaluation pipeline designed to mimic realistic deployment conditions. Our findings show that proper temporal handling and MNAR-aware preprocessing significantly alter the relative performance of popular anomaly-detection methods, providing practical guidance for designing reliable, leakage-resistant ICS intrusion-detection systems.

97 MATHEMATICS AND COMPUTING↗

Smart Inverter Twin Model for Anomaly Detection

Smart inverters connected to a communication network are vulnerable to various anomalies in the form of cyberattacks. In this paper, a self-security approach is implemented using the digital twin concept for smart inverters. The digital twin is formed using the inverter’s dynamic model. Then, the incoming setpoints are autonomously examined using the digital twin, and only the safe setpoints are engaged to the inverter’s local controller. This paper demonstrates the details of the self-security algorithm and how the inverter’s digital twin is formed. In particular, the stable and unstable operation region is experimentally verified by changing the power setpoints engaged to the local controller, using a laboratory setup including a three-phase 1.5-kVA SiC-MOSFET inverter and a 12-kW NHR 9410 regenerative power grid emulator. The results demonstrate that the digital twin model can potentially protect inverters from abnormal operation by examining the incoming commands (new setpoints) using the inverter’s digital twin before engaging the setpoints to the local controller.

Hossen, Tareq↗

Defensive Islanding to Enhance the Resilience of Distribution Systems Against Cyber-Induced Failures

The extensive integration of communication, computation, and control technologies into cyber-physical power systems (CPPSs) has increased the vulnerabilities of CPPSs to cyberattacks. This calls for developing solutions that assess and reduce the impacts of cyber-induced failures on CPPSs. This paper proposes a defensive islanding strategy to isolate impacted parts of the CPPS and form self-sufficient islanded grids with an objective of minimum load curtailment. The defensive islanding aims to split a power system into smaller grids to improve its resilience against a potential extreme event. A clustering approach that leverages the hierarchical spectral clustering method is utilized for the optimal defensive islanding. The proposed approach captures the fragility behavior and loading conditions of power system components due to cyber-induced failures. A graphical-based coupling framework is used to map the impacts of cyber failures into operation of power system components. The proposed method is demonstrated on a modified 33-node distribution feeder system integrated with distributed energy resources. The amount of load curtailment and radiality constraints have been used to evaluate the performance of the proposed clustering strategies. The results show the capability of the proposed algorithm to create islands considering the cyber-induced failures for enhanced resilience.

cyber-induced failures↗

Blockchain-Enabled Secure Device-to-Device Communication in Software-Defined Networking

The Internet of Things (IoT) continues to increase the demand for seamless communication among IoT devices. The rapid growth of IoT devices has led to an exponential increase in device-to-device (D2D) communication within the Software-Defined Networking (SDN), though it enables a flexible archi-tecture for managing network resources. However, traditional security models face challenges (e.g., Security, privacy, and trust) in addressing the dynamic and decentralized nature of these communications. Despite of these challenges, this paper proposes a novel approach that leverages blockchain technology to enhance the security, privacy, and trustworthiness of D2D communication within an SDN environment. The proposed approach integrates blockchain nodes in sDN components to establish a decentralized ledger for transparent and verifiable records. Smart contracts enforce authentication rules to ensure that only authenticated devices can access the network and engage in transactions securely. It also automates the security policies to ensure temper resistance execution using the cryptographic mechanism for data integrity and authentic communication. The Implementation of the proposed algorithms validates the resilience of the proposed approach against cyberattacks. Overall, the proposed approach enables efficient and secure D2D communication for resilient SDN infrastructure in IoT ecosystems.

Das, Debashis↗

Power System Resilience Evaluation Framework and Metric Review

Power system resilience has been an emerging hot topic in recent years to investigate the increasing threats of extreme events, such as natural disasters, severe weather, and cyberattacks. Although much research has been done to define, model, and quantify resilience from different aspects, the lack of universally accepted evaluation methods and resilience metrics makes it difficult to assess and compare resilience across different power systems, such as what is typically done in power system reliability studies. In this paper, first, we review the definitions of resilience, and we summarize two core concepts shared by most of the literature. Then, we develop a new framework to assess power system resilience from two perspectives - i.e., pre-event estimation and post-event evaluation - to capture system resilience performance in both general and specific fashions. We conduct a thorough review of existing resilience metrics and categorize them using the proposed framework, where recommendations are also proposed to capture core concepts of resilience.

power system resilience↗

Prediction of Power Measurements Using Adaptive Filters

With the advent of smart grid concept, Internet of Things (IoT) and the deployment of smart meters, the cyberattack threats on power networks have increased due to the use of communication systems that can be accessed by adversaries. Attackers will have the ability to manipulate the outcomes of smart meters which in turn influence the core application of Energy Management System 9EMS): State Estimation (SE). Bad data analytic tools may fail to detect some attacks into measurements. Meanwhile, Machine Learning (ML) solutions have been proposed for detecting False Data Injection (FDI) attacks. However, there is a lack of ML time-series solutions presented in the state-of-the-art that is yet to be complex. In signal processing, time-series solutions do not only consider the signal, but also the statistics of the signal over time. Therefore, in this paper, a machine learning for time-series solutions is presented as an application to model the measurements of the power grid that are used in SE. The presented model takes into account adaptive linear and non-linear filters: Finite Impulse Response (FIR), and Infinite Impulse Response (IIR). The presented models are implemented and performed on the IEEE-118 bus system. The results indicate the advantage of applying those filters over the state-of-the-art machine learning solutions.

Hamad, Khaled↗

Resilient Communication Scheme for Distributed Decision of Interconnecting Networks of Microgrids

Networking of microgrids can provide the operational flexibility needed for the increasing number of DERs deployed at the distribution level and supporting end-use demand when there is loss of the bulk power system. But, networked microgrids are vulnerable to cyber-physical attacks and faults due to the complex interconnections. As such, it is necessary To design resilient control systems to support the operations of networked microgrids in responses to cyber-physical attacks and faults. This paper introduces a resilient communication scheme for interconnecting multiple microgrids to support critical demand, in which the interconnection decision can be made distributedly by each microgrid controller even in the presence of cyberattacks to some communication links or microgrid controllers. This scheme blends a randomized peer-to-peer communication network for exchanging information among controllers and resilient consensus algorithms for achieving reliable interconnection agreement. The network of 6 microgrids divided from a modified 123-node test distribution feeder is used to demonstrate the effectiveness of the proposed resilient communication scheme.

Vu, Thanh Long↗

Characterizing HVDC Transmission Flexibility under Extreme Operating Conditions

System operators rely on system flexibility, traditionally mainly from generation, to handle unexpected reliability and resilience events, ranging from excessive resource forecast errors to extreme events like heatwaves, earthquakes, and cyberattacks. Flexible transmission, such as controllable high voltage direct current (HVDC) transmission systems present an opportunity to increase overall system flexibility to accommodate operational challenges. This paper provides a methodology to study contributions to system flexibility by controllable, power electronics based transmission. The Western Electricity Coordinating Council (WECC) system is used as an example to study contributions from existing and future HVDC lines. Under extreme system conditions, it is identified that HVDC transmission flexibility can contribute with 24.8 to 28% of avoided unserved energy, and in some areas, the benefits amount to 50 to 70%.

HVDC transmission, PCM, Balancing authorities↗

Data Security Defense: Modeling and Detection of Synchrophasor Data Spoofing Attack for Grid Edge

Data security and cyberattack have become critical issues in the distributed power system where adversaries can swap the source information of sensors or even spoof and alter measurements. However, the cyber security of the power system is challenged by the unpredictability and stealth of the spoofing attacks. Here, to protect the data security at the grid edge, this paper developed a synchrophasor data spoofing attack detection framework based on the time-frequency feature extraction techniques including the short-time Fourier transform (STFT) and object detection network for real-time synchrophasor data categorization and spoofing attack localization. The proposed approach outperforms earlier work in terms of spoofing attack detection and offers a vital localization function employing distributed synchrophasor sensors.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Envisioning the Future Renewable and Resilient Energy Grids—A Power Grid Revolution Enabled by Renewables, Energy Storage, and Energy Electronics

Today’s power grids are facing tremendous challenges because of the ever-increasing power demand, system complexity, infrastructure cost, knowledge base, and policy and regulatory issues to achieve supply–demand power balance and resiliency with respect to more frequent extreme weather events and cyberattacks. It is particularly challenging when the transition toward 100% intermittent renewable energy sources is considered. Many countries are calling for building up more transmission and distribution lines to increase power delivery capacities. This article is an attempt to answer two urgent questions: Is more transmission and distribution infrastructure really needed to meet the increasing power demand? What kind of future grid infrastructure should we envision and build? This article attempts to answer these questions and proposes the concept of community-centric asynchronous renewable and resilient energy grids. By clearly differentiating the concepts of grid resilience and reliability, the importance of building resilient power electronics’ devices and robust system-level control algorithms to achieve 100% renewable energy integrated resilient grids is presented. To identify the shortcomings and propose advancements, power electronics’ technologies are categorized using the proposed concepts of natural source frequencies (NSf), energy storage, direct energy conversion/control and fault protection (DeCaFp), and high-efficiency energy consumption and buffering (heECaB) technology. The ability of networked microgrids to greatly reduce power outages and power system restoration time is demonstrated by leveraging robust decentralized and centralized control algorithms, identified through a comprehensive literature review. Future research areas are proposed to further enhance grid stability, controllability, cybersecurity, and protection against faults in the presence of 100% renewable sources by leveraging the advanced capabilities of NSf, DeCaFp, and heECaB devices and system-level control algorithms.

14 SOLAR ENERGY↗

On Self-Security of Grid-Interactive Smart Inverters

The capability to exchange information with utility operators, aggregators, and nearby smart devices can make a grid-interactive inverter an intelligent cyber-physical device. However, the capability of exchanging information can also put the inverters at the risk of insecure operation. In this paper, possible software manipulations into the inverters are studied to understand their vulnerability to cyberattacks. Moreover, the state-of-the-art system-level and device-level cyber-defense measures are discussed, and advantages and drawbacks of each technique are provided. Studies show that a reference model can be implemented in device-level security to effectively examine incoming setpoints for detecting and preventing malicious or harmful actions. This paper particularly underlines the significance of device-level self-security and its advantages for grid-interactive inverters. Finally, recommendations for future studies are provided.

Gursoy, Mehmetcan↗