Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Cyberattack”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

Data recovery via covert cognizance for unattended operational resilience

One of the important premises of unattended operation, a highly promoted characteristic of fission batteries and advanced microreactors, is the ability to automate the analysis of sensors data used in support of operational monitoring and control. Here, to meet this vision, this work proposes a new monitoring and data recovery paradigm to ensure resilience against data corruption which may be the result of malicious intrusion into the reactor operational network. This is paramount to ensure 100% availability under contingency scenarios such as cyberattacks. In support of this vision, earlier work has presented the concept of covert cognizance and demonstrated its mathematical ability to identify and embed cognizance parameters under the noise-dominated null space of the sensors data. This work extends this concept and applies it in real-time to demonstrate three key characteristics: zero-impact, zero-observability, and data recovery, where the first characteristic is to ensure no impact on operation, the second is immunity to discovery by pattern recognition techniques, and the third is to allow recovery of corrupt or falsified data. Recognizing that fission batteries are designed to operate under steady state most of the time, we elect to employ a small modular reactor model under transient operational conditions to demonstrate the operational resilience enabled by the covert cognizance paradigm. Specifically, the PI controller is augmented with the covert cognizance modules to develop self-awareness and enable automatic data recovery. The developed modules are expected to be equally applicable to a wide range of advanced reactor technologies relying on full or partial unattended control.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Time Sequence Machine Learning-Based Data Intrusion Detection for Smart Voltage Source Converter-Enabled Power Grid

Smart inverters of distributed energy resources can enable cloud computing, condition monitoring, result visualization, remote control, and peer-to-peer energy trading in advanced power systems. However, the advent of data injection attacks in the communication architecture can alter measurement characteristics of power grids and have devastating consequences. In this article, we propose a time sequence machine learning-based anomaly detection methodology for detecting cyber intrusion into control signal setpoints and dc voltage signal measurement bias of the voltage source converter (VSC) in wind generators. We first investigated the effects of four types of denial of service, tampering signal, and stealthy-type data intrusion attacks on smart VSCs and overall wind farms. We then proposed a novel time sequence machine learning-based intrusion detection framework that can be implemented to detect different cyberattacks in the VSCs. The performance of the proposed framework has been compared with that of autoencoder and clustering-based intrusion detection framework. The proposed framework was validated by using the IEEE 39 bus power system in the presence of four wind farms in different locations. Using several metrics for intrusion detection performance, we validated the effectiveness of the proposed framework.

42 ENGINEERING↗

Advanced Research on Integrated Energy Systems (ARIES) Cyber Range Overview and Threat-to-Consequence Demonstration

This presentation was presented at the Aggregation and Grid Security Workshop - held on June 17-18, 2025, at NREL in Golden, Colorado. The goal of the two-day workshop was to address the critical cybersecurity challenges for the future electric grid. The threat-to-consequence demonstration showcases NREL's capability to model, simulate, test, and evaluate cyberattacks targeting energy systems that coincide with natural hazards, as well as the ramifications for the energy grid as a whole.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Evidence-based Graph Adversary Mapping (EGRAM) [Poster]

Cybersecurity companies such as CrowdStrike, Dragos, Microsoft and Unit 42 categorize Advanced Persistent Threats (APTs) using their own naming schemes. As a result, these APTs are mapped to different malware sources and campaigns, all from differing sources, leading to inconsistent mapping. Inconsistent mapping causes confusion and adds further obscurity around these groups, making it difficult to track and mitigate APT cyberattacks. The Evidence-based Graph Adversary Mapping (EGRAM) tool remediates the mapping challenge by collecting, updating and converting adversary data and their sources into a valid, codified STIX v2.1 bundle which is then stored in a Neo4j graph database. It utilizes graph traversal methods and centrality analysis to generate actionable information as a Structured Threat Intelligence Graph (STIG), based on user queries. EGRAM exists as Python code and a Jupyter Notebook that acts as a searchable, evidence-based, source of intelligence for APT groups’ artifacts and cyber campaigns.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Microgrid's Role in Enhancing the Security and Flexibility of City Energy Systems

Smart cities depend on flexible and secure energy systems to ensure resilient power for critical infrastructure; however, recent weather-related events and cyberattacks have highlighted weaknesses in our energy systems, with the potential for widespread economic and security impacts. As stated by the Executive Office of the President, "the resilience of the US electric grid is a key part of the nation's defense against severe weather." To address the energy delivery security challenge, microgrids are rising as a viable solution that enhances the flexibility and resilience of the distribution grid and boosts the reliability of the local supply for the end-user. Traditionally, high capital investment has been a barrier to large-scale adoption of microgrid technology. Understanding the flexibility and resilience benefits of microgrids and accounting for the associated value streams can make the microgrid's proposition economically viable. In this chapter, microgrids' utility and their potential to serve as a flexible and resilient resource for the utility grid by providing capabilities such as peak shaving, demand response, and frequency regulation is presented. Moreover, other value streams, such as (1) their ability to island during a disaster and sustain critical loads which makes them a robust resilience solution for end-users, in the event of the utility grid outage and (2) microgrids also provide a flexible platform for integrating distributed energy resources in conjunction with storage and conventional generation technologies, strengthen microgrid's role in reducing the over-arching goal of emission reduction. Given the myriad of benefits associated with microgrids, we present strategies which can be employed for making microgrid itself resilient against physical and cyberthreats by employing hardware, software, and personnel training solutions to operate the microgrid before, during, and after a potential disaster. This chapter, thus, provides a holistic study of the microgrid as a resilience resource, for the utility grid, and a self-contained end-user for the end-user.

cyber-physical system↗

Resilient Hierarchical Networked Control Systems: Secure Controls for Critical Locations and at Edge

Integration of information and communication technology (ICT) offers new opportunities in improving the management and operation of critical infrastructures such as power systems as it allows connection of different sensors and control components via a communication network, leading to the so-called networked control systems (NCS). However, the use of open and pervasive ICT such as the Internet or wireless communication technologies comes at a price of making NCS vulnerable to cyber intrusions/attacks which may cause physical damage. Here, this chapter presents control algorithms to ensure resilient and safe operation of NCS under unknown cyberattacks. Specifically, a variant of dynamic watermarking strategies is presented by embedding encoding/decoding components of chaotic signals into the NCS for secure control for critical locations where the measurement/control signals are transmitted to/from the control center via a communication network. In addition, resilient cooperative control algorithms are discussed to ensure safe operation at edge of the NCS which consists of a large number of distributed controllable devices. Several numerical examples are provided to illustrate the proposed control strategies.

96 KNOWLEDGE MANAGEMENT AND PRESERVATION↗

Microgrid Resilience: A Holistic and Context-Aware Resilience Metric

Microgrids present an effective solution for the coordinated deployment of various distributed energy resources and furthermore provide myriad additional benefits such as resilience, decreased carbon footprint, and reliability to energy consumers and the energy system as a whole. Boosting the resilience of distribution systems is another major benefit of microgrids. This is because they can also serve as a backup power source when the utility grid's operations are interrupted due to either high-probability low-impact events like a component failure or low-probability high-impact events - be it a natural disaster or a planned cyberattack. However, the degree to which any particular system can defend, adapt, and restore normal operation depends on various factors including the type and severity of events to which a microgrid is subjected. These factors, in turn, are dependent on the geographical location of the deployed microgrid as well as the cyber risk profile of the site where the microgrid is operating. Therefore, in this work, we attempt to capture this multi-dimensional interplay of various factors in quantifying the ability of the microgrid to be resilient in these varying aspects. This paper, thus, proposes a customized site-specific quantification of the resilience strength for the individual microgrid's capability to absorb, restore, and adapt to the changing circumstances for sustaining the critical load when a low-probability high-impact event occurs - termed as - context-aware resilience metric. We also present a case study to illustrate the key elements of our integrated analytical approach.

microgrid↗

JTAG-based PLC memory acquisition framework for industrial control systems

In industrial control systems (ICS), programmable logic controllers (PLC) are the embedded devices that directly control and monitor critical industrial infrastructure processes such as nuclear plants and power grid stations. Cyberattacks often target PLCs to sabotage a physical process. A memory forensic analysis of a suspect PLC can answer questions about an attack, including compromised firmware and manipulation of PLC control logic code and I/O devices. Given physical access to a PLC, collecting forensic information from the PLC memory at the hardware-level is risky and challenging. It may cause the PLC to crash or hang since PLCs have proprietary, legacy hardware with heterogeneous architecture. This paper addresses this research problem and proposes a novel JTAG (Joint Test Action Group)-based framework, Kyros, for reliable PLC memory acquisition. Kyros systematically creates a JTAG profile of a PLC through hardware assessment, JTAG pins identification, memory map creation, and optimizing acquisition parameters. It also facilitates the community of interest (such as ICS owners, operators, and vendors) to develop the JTAG profiles of PLCs. Further, we present a case study of Kyros implementation over Allen-Bradley 1756-A10/B to help understand the framework's application on a real-world PLC used in industry settings. The sample PLC memory dumps are shared with the research community to facilitate further research.

Rais, Muhammad Haris↗

Authentication of smart grid communications using quantum key distribution

Smart grid solutions enable utilities and customers to better monitor and control energy use via information and communications technology. Information technology is intended to improve the future electric grid’s reliability, efficiency, and sustainability by implementing advanced monitoring and control systems. However, leveraging modern communications systems also makes the grid vulnerable to cyberattacks. Here we report the first use of quantum key distribution (QKD) keys in the authentication of smart grid communications. In particular, we make such demonstration on a deployed electric utility fiber network. The developed method was prototyped in a software package to manage and utilize cryptographic keys to authenticate machine-to-machine communications used for supervisory control and data acquisition (SCADA). This demonstration showcases the feasibility of using QKD to improve the security of critical infrastructure, including future distributed energy resources (DERs), such as energy storage.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Design and evaluation of a cyber‐physical testbed for improving attack resilience of power systems

Abstract A power system is a complex cyber‐physical system whose security is critical to its function. A major challenge is to model, analyse and visualise the communication backbone of the power systems concerning cyber threats. To achieve this, the design and evaluation of a cyber‐physical power system (CPPS) testbed called Resilient Energy Systems Lab (RESLab) are presented to capture realistic cyber, physical, and protection system features. RESLab is architected to be a fundamental platform for studying and improving the resilience of complex CPPS to cyber threats. The cyber network is emulated using Common Open Research Emulator (CORE), which acts as a gateway for the physical and protection devices to communicate. The physical grid is simulated in the dynamic time frame using Power World Dynamic Studio (PWDS). The protection components are modelled with both PWDS and physical devices including the SEL Real‐Time Automation Controller (RTAC). Distributed Network Protocol 3 (DNP3) is used to monitor and control the grid. Then, the design is exemplified and the tools are validated. This work presents four case studies on cyberattack and defence using RESLab, where we demonstrate false data and command injection using Man‐in‐the‐Middle and Denial of Service attacks and validate them on a large‐scale synthetic electric grid.

Sahu, Abhijeet↗

FL‐ADS: Federated learning anomaly detection system for distributed energy resource networks

Abstract With the ongoing development of Distributed Energy Resources (DER) communication networks, the imperative for strong cybersecurity and data privacy safeguards is increasingly evident. DER networks, which rely on protocols such as Distributed Network Protocol 3 and Modbus, are susceptible to cyberattacks such as data integrity breaches and denial of service due to their inherent security vulnerabilities. This paper introduces an innovative Federated Learning (FL)‐based anomaly detection system designed to enhance the security of DER networks while preserving data privacy. Our models leverage Vertical and Horizontal Federated Learning to enable collaborative learning while preserving data privacy, exchanging only non‐sensitive information, such as model parameters, and maintaining the privacy of DER clients' raw data. The effectiveness of the models is demonstrated through its evaluation on datasets representative of real‐world DER scenarios, showcasing significant improvements in accuracy and F1‐score across all clients compared to the traditional baseline model. Additionally, this work demonstrates a consistent reduction in loss function over multiple FL rounds, further validating its efficacy and offering a robust solution that balances effective anomaly detection with stringent data privacy needs.

Purohit, Shaurya [Iowa State University Ames Iowa ↗

Lyapunov stability of smart inverters using linearized distflow approximation

Fast-acting smart inverters that utilize preset operating conditions to determine real and reactive power injection/consumption can create voltage instabilities (over-voltage, voltage oscillations and more) in an electrical distribution network if set-points are not properly configured. In this work, linear distribution power flow equations and droop-based Volt–Var and Volt–Watt control curves are used to analytically derive a stability criterion using Lyapunov analysis that includes the network operating condition. The methodology is generally applicable for control curves that can be represented as Lipschitz functions. The derived Lipschitz constants account for smart inverter hardware limitations for reactive power generation. A local policy is derived from the stability criterion that allows inverters to adapt their control curves by monitoring only local voltage, thus avoiding centralized control or information sharing with other inverters. The criterion is independent of the internal time-delays of smart inverters. Simulation results for inverters with and without the proposed stabilization technique demonstrate how smart inverters can mitigate voltage oscillations locally and mitigate real and reactive power flow disturbances at the substation under multiple scenarios. The study concludes with illustrations of how the control policy can dampen oscillations caused by solar intermittency and cyberattacks.

42 ENGINEERING↗

Overview and Recommendations for Cyber Risk Assessment in Nuclear Power Plants

Digital instrumentation and control (I&C) systems are being deployed in nuclear power plants (NPPs) for both existing and advanced reactor designs. As I&C systems become more digitized to allow features like near autonomous control and remote operation, they introduce greater cyber risk to NPPs. Cyberattacks targeting industrial control systems (ICSs) are growing in both qualities and capabilities, which indicates that cybersecurity needs to be an integral part of risk assessment in the industry. Although there are some risk assessment methods in traditional information technology (IT) cybersecurity, the differences between IT and ICS cybersecurity make it infeasible to apply these risk assessment methods directly to ICSs. Some research has focused on risk assessment methods for ICSs, but few studies focus on applications to NPPs. Ideal risk frameworks for the nuclear industry are dynamic and account for system dependencies; this survey review focuses on such risk assessment methods both in and outside the nuclear field. In this article, the major challenges in cybersecurity risk assessment research are pointed out, and further research suggestions and considerations for cyber risk assessment in I&C systems are identified.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Analysis of AP1000 Small-Break Loss-of-Coolant Accident Using Reactor Transient Simulator

The Westinghouse Electric Company’s Advanced Passive Reactor (AP1000) is characterized by the incorporation of passive safety systems (PSSs) designed to ensure core cooling during transient events. The assessment of PSSs requires evaluation of their performance through a combination of experiments and simulations employing various thermal-hydraulic codes. In addition, detailed evaluation of PSSs for a specific reactor system transient analysis such as loss-of-coolant-accident analysis supports understanding representative integral effects test facility development and the further evolution model development and assessment process. Developing a reactor system code is a complex and time-consuming process that requires significant engineering expertise and effort. It can take several months to even years to complete in the early stages of reactor system design and analysis. However, this process can be expedited through the use of transient simulator models for similar reactor systems, which can be used for lesson learning and training purposes. This study uses the Personal Computer Transient Analyzer (PCTRAN) code. The main advantage of PCTRAN is its ease of use and ability to run faster than real time. This study presents the results obtained for a small-break loss-of-coolant accident (SBLOCA) for two breaks using the full version (licensed) of PCTRAN. The purpose of this investigation is to evaluate the overall system behavior during the postulated SBLOCA event as well as assess the capability of the PCTRAN code to reproduce the system response during transient events. The obtained results were compared with the Westinghouse NOTRUMP system code. The PCTRAN code proved to be reliable in predicting the qualitative behavior of the system in both transient cases. As for the system response, it was found that it is contingent on the activation time of the PSSs. The differences in reactor coolant system pressure between the two codes were attributed to the critical flow model and simplification of mass and energy balance. Despite PCTRAN’s limitations, it can still provide a reasonable prediction of various reactor parameters such as pressure, mass flow rate, and void fraction during a SBLOCA scenario. It is worth noting that PCTRAN currently employs a bulk approach similar to that of the Modular Accident Analysis Program (MAAP) and MELCOR codes. However, the upcoming version of PCTRAN will include an artificial intelligence–based detection and accident prevention system, as well as different models for different reactor components. Consequently, PCTRAN has the potential to be upgraded to match the system thermal-hydraulic codes of the U.S. Nuclear Regulatory Commission and become more widely used in cybersecurity to safeguard nuclear power plants from cyberattacks.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Evaluating Methods of Software Bill of Materials Generation to Enhance Nuclear Power Plant Cybersecurity

Instrumentation and control (I&C) systems in nuclear power plants (NPPs) are potential targets of cyberattacks and can prove deleterious for the safety of the NPPs. A Software Bill of Materials (SBOM) provides a detailed list of the various components and their dependencies in software, which helps in vulnerability and risk assessment for cyber hygiene and situational awareness. For an NPP, the process of generating an accurate SBOM report can be complex due to the legacy systems and firmware binaries involved. While most current SBOM tools are focused more on modern internet technology software, this research provides insights and guidelines for an NPP to generate an accurate and efficient SBOM. Here, the paper proposes a new methodology to help NPPs categorize software and use appropriate tools to generate SBOMs for their digital I&C systems.

SBOM↗

Feature Engineering and Ensemble Methods for Imbalanced ICS Intrusion Detection: Pipeline Audit and Constrained Evaluation

Industries are becoming increasingly connected and are more vulnerable to cyberattacks due to the widened attack surface. Industrial Control Systems (ICS) are among the most critical sectors that malicious actors can target, as such attacks can cause significant operational disruption and physical damage. It is imperative to detect such attacks as early as possible. This paper evaluates constraint-conditioned optimistic performance estimates for traditional ML models in ICS intrusion detection (i.e., estimates obtained under contiguous, non-shuffled temporal evaluation without test-set alteration, but with pre-split feature engineering that may introduce temporal leakage, due to dataset constraints). Our findings are threefold. First, we quantify how iterative feature engineering affects tree-based ensemble performance and examine how pipeline decisions (split strategy, sampling scope, and cleaning policy) can inflate or reduce reported IDS results under constraint-bound evaluation. Second, we compare intrinsic class-imbalance handling across ensemble models. Third, under our current pipeline constraints (including pre-split feature engineering), CatBoost achieves the best performance on Water Storage Tank (accuracy: 0.9831, class-1 F1: 0.9682), while Light- GBM achieves the best performance on Gas Pipeline (accuracy: 0.9618, class-1 F1: 0.9086).

97 MATHEMATICS AND COMPUTING↗

The Impact of Time-Aware Design Choices in ICS Anomaly Detection

Industrial control systems (ICS) remain vulnerable to increasingly sophisticated cyberattacks, yet evaluating anomaly detection models in these environments is challenging due to temporal dependencies, missing-not-at-random patterns, and extremely imbalanced datasets. These factors make common practices—especially random data splits and na¨ıve imputation— prone to severe temporal leakage, which can inflate reported performance and obscure real-world limitations. In this work, we systematically examine classical machine learning models, temporal deep learning architecture, and tensordecomposition– based methods on a gas-pipeline dataset using a fully temporally separated evaluation pipeline designed to mimic realistic deployment conditions. Our findings show that proper temporal handling and MNAR-aware preprocessing significantly alter the relative performance of popular anomaly-detection methods, providing practical guidance for designing reliable, leakage-resistant ICS intrusion-detection systems.

97 MATHEMATICS AND COMPUTING↗

Smart Inverter Twin Model for Anomaly Detection

Smart inverters connected to a communication network are vulnerable to various anomalies in the form of cyberattacks. In this paper, a self-security approach is implemented using the digital twin concept for smart inverters. The digital twin is formed using the inverter’s dynamic model. Then, the incoming setpoints are autonomously examined using the digital twin, and only the safe setpoints are engaged to the inverter’s local controller. This paper demonstrates the details of the self-security algorithm and how the inverter’s digital twin is formed. In particular, the stable and unstable operation region is experimentally verified by changing the power setpoints engaged to the local controller, using a laboratory setup including a three-phase 1.5-kVA SiC-MOSFET inverter and a 12-kW NHR 9410 regenerative power grid emulator. The results demonstrate that the digital twin model can potentially protect inverters from abnormal operation by examining the incoming commands (new setpoints) using the inverter’s digital twin before engaging the setpoints to the local controller.

Hossen, Tareq↗