Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “vulnerability analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 145 records · Page 8

Retrospective Analysis and Bayesian Model Averaging of CMIP6 Precipitation in the Nile River Basin

The Nile River basin is one of the global hotspots vulnerable to climate change impacts because of a fast-growing population and geopolitical tensions. Previous studies demonstrated that general circulation models (GCMs) frequently show disagreement in the sign of change in annual precipitation projections. Here, we first evaluate the performance of 20 GCMs from phase six of the Coupled Model Intercomparison Project (CMIP6) benchmarked against a high-spatial-resolution precipitation dataset dating back to 1983 from Precipitation Estimation from Remotely Sensed Information Using Artificial Neural Networks–Climate Data Record (PERSIANN-CDR). Next, a Bayesian model averaging (BMA) approach is adopted to derive probability distributions of precipitation projections in the Nile basin. Retrospective analysis reveals that most GCMs exhibit considerable (up to 64% of mean annual precipitation) and spatially heterogenous bias in simulating annual precipitation. Moreover, it is shown that all GCMs underestimate interannual variability; thus, the ensemble range is underdispersive and is a poor indicator of uncertainty. The projected changes from the BMA model show that the value and sign of change vary considerably across the Nile basin. Specifically, it is found that projected changes in the two headwaters basins, namely, the Blue Nile and Upper White Nile, are 0.03% and -1.65%, respectively; both are statistically insignificant at α = 0.05. The uncertainty range estimated from the BMA model shows that the probability of a precipitation decrease is much higher in the Upper White Nile basin whereas projected change in the Blue Nile is highly uncertain both in magnitude and sign of change.

37 INORGANIC, ORGANIC, PHYSICAL, AND ANALYTICAL CH↗

Enabling Cybersecurity, Situational Awareness and Resilience in Distribution Grids with High Penetration of Photovoltaics (CARE-PV) (Final Report)

Since legacy distribution systems have very limited visibility beyond the substation, high penetration of PV at the grid edge presents some unique operational challenges. One approach to address these challenges is to use information from advanced metering infrastructure (AMI) and µPMUs. However, exploiting this information is impacted by a number of factors, including multi-timescale measurements, volume of data generated, communication network impairments (e.g., information loss and latency) and susceptibility to cyber-attacks. Therefore, one of the critical tasks involved in the management of a distribution grid is to develop complete situational awareness by integrating cyber-security mechanisms with state estimation strategies and leveraging this situational awareness to assure energy services at strategic locations while exploiting AMI/PV inverter/ µPMU data. This CARE-PV project addresses the fundamental challenges in situational awareness and resilience to cyber and physical vectors by exploiting the synergy between innovative modeling, estimation, data analytics, testing and validation using smart PV inverters designed at K-State and facilities at NREL. Specifically, the project involved the development, testing and validation of the following novel enabling technologies: (Thrust 1) Resilience to cyber vectors that impact data integrity was addressed via a two-level defense strategy that combines cyber intrusion detection using self-learning, cooperative smart PV inverters, and a novel moving target defense framework to combat data integrity attacks. (Thrust 2) Resilience to cyber-physical vectors that impact situational awareness by limiting data availability was addressed via novel centralized and decentralized, sparsity-based static and dynamic state estimation approaches that enhance observability even when the underlying system is unobservable. (Thrust 3) Leveraging a unique probabilistic sensitivity analysis approach accompanied by one-of-a-kind dominant influencer set computation, the vulnerability of critical infrastructure at strategic locations was evaluated so that proactive PV-based control strategies can be used to support operations under normal/outage scenarios. These CARE-PV project innovations were demonstrated on both small-scale IEEE and larger utility-scale testbeds (Thrust 4). Feedback from Industry Advisory Board members was used to formulate a commercialization pathway for a subset of CARE-PV technologies. These CARE-PV technologies will ultimately lead to reliable and secure, large-scale integration of renewable energy and mitigate the risk of energy disruption resulting from cyber incidents and other emerging threats within the energy environment.

14 SOLAR ENERGY↗

Microbial Community Structure and Ecological Networks during Simulation of Diatom Sinking

Microbial-mediated utilization of particulate organic matter (POM) during its downward transport from the surface to the deep ocean constitutes a critical component of the global ocean carbon cycle. However, it remains unclear as to how high hydrostatic pressure (HHP) and low temperature (LT) with the sinking particles affects community structure and network interactions of the particle-attached microorganisms (PAM) and those free-living microorganisms (FLM) in the surrounding water. In this study, we investigated microbial succession and network interactions in experiments simulating POM sinking in the ocean. Diatom-derived 13C- and 12C-labeled POM were used to incubate surface water microbial communities from the East China Sea (ECS) under pressure (temperature) of 0.1 (25 °C), 20 (4 °C), and 40 (4 °C) MPa (megapascal). Our results show that the diversity and species richness of the PAM and FLM communities decreased significantly with HHP and LT. Microbial community analysis indicated an increase in the relative abundance of Bacteroidetes at high pressure (40 MPa), mostly at the expense of Gammaproteobacteria, Alphaproteobacteria, and Gracilibacteria at atmospheric pressure. Hydrostatic pressure and temperature affected lifestyle preferences between particle-attached (PA) and free-living (FL) microbes. Ecological network analysis showed that HHP and LT enhanced microbial network interactions and resulted in higher vulnerability to networks of the PAM communities and more resilience of those of the FLM communities. Most interestingly, the PAM communities occupied most of the module hubs of the networks, whereas the FLM communities mainly served as connectors of the modules, suggesting their different ecological roles of the two groups of microbes. These results provided novel insights into how HHP and LT affected microbial community dynamics, ecological networks during POM sinking, and the implications for carbon cycling in the ocean.

59 BASIC BIOLOGICAL SCIENCES↗

Deconstructing the Nuclear Supply Chain Cyber-Attack Surface

The nuclear supply chain cyber-attack surface is a large, complex network of interconnected stakeholders and activities. The global economy has widened and deepened the supply chain resulting in larger numbers of geographically dispersed locations and increased difficulty ensuring the authenticity and security of digital assets. Although the nuclear industry has made significant strides in securing facilities from cyber-attacks, the supply chain remains vulnerable. This paper provides further details on each of the elements in the Digital I&C System Supply Chain Cyber-Attack Surface, including supply chain lifecycle activities, key stakeholders, touchpoints, and attack types. Deconstructing this attack surface provides insights into supply chain threats, vulnerabilities, and consequences. These insights will lead to improvements in cybersecurity supply chain risk analysis, development of new cybersecurity supply chain processes and tools, and enhancement of overall supply chain resilience.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Beyond Binary: Automated PLC Memory Forensics through RGB Image Analysis and Deep Learning

The introduction of Industry 4.0 and the evolution of industrial control systems (ICS) to adopt Internet-based technologies enhanced productivity, but have inadvertently increased their vulnerability to cyber-based malicious attacks. When an ICS system is compromised, security analysts need to identify the root cause quickly to start the recovery process and develop mitigation strategies to safeguard against future instances. Memory forensics is critical in the analysis process to ascertain what occurred. To date, approaches to analyze the persistent memory in ICS devices are limited, and almost nonexistent for volatile memory. This paper proposes an automated methodology, COMA, for PLC memory dump analysis using computer vision and deep learning techniques. Specifically, COMA converts the sequences of bytes in a PLC memory dump to RGB pixels and creates a deep learning model that learns the underlying patterns and features of pre-labeled forensic artifacts in images and segments them into distinct regions. COMA then uses the trained model to automatically segment new memory images and extract forensic artifacts. We evaluate COMA on a Schneider Electric Modicon M221 PLC involving two cyber-based attack scenarios: (i) code injection and (ii) code modification. The empirical results show that COMA can successfully detect attack artifacts in memory dumps in both scenarios.

Asmar Awad, Rima↗

Model-based Hierarchical Reinforcement Learning for Improved Physical Security Design: A Prototype

Prior work in FY24 developed an adversarial AI agent aid in path analysis of physical protection systems. This agent, trained using a model-based reinforcement learning algorithm, was able to successfully learn the most vulnerable path in facilities. It was able to extend the current state of practice for physical protection design by exhibiting dynamic behavior based on current environmental conditions. Whereas PathTrace largely performs a static, graph-based analysis, the AI agent was able to make decisions based on relative position in the facility, current conditions (was the adversarial agnet discovered?), and proximity to secondary targets. The agent demonstrated some novel capabilities, but had limitations that need to be resolved before it can be used for production purposes. For example, the adversarial agent generalizes poorly and takes a relatively long time to train. Nonetheless, there is still considerable promise for developing the adversarial agent further in order to explore even richer, more dynamic behaviors (e.g., adversary motivations, environmental debris, and more). This work considers a complementary idea; development of a planning agent. The planning agent is envisioned as an auto-complete-like tool that can help accelerate security system design by human experts. The agent would respect existing barriers and sensors placed by a human expert while offering cost-effective suggestions (i.e., implicitly balancing effectiveness with cost) to improve the design. The goal is for this agent to be part of an expert’s toolbox, not to totally upend the current state-of-practice, or to displace human experts. The ultimate goal would be concurrent training of both the adversarial and planning agent together, to learn entirely through self-play. This would represent an entirely new way of performing system deign. We selected a hierarchical, model-based reinforcement learning algorithm to serve as the planning agent. This is an extension of concepts used in the prior FY24 adversarial agent work. There, we had a single agent acting an environment. Here, we have two different sub-agents (policies), working together, to form a complete agent. There is a manager policy, which can select abstract goals on slower time scales, and a worker, which performs primitive actions to reach goals selected by the manager. It is worth noting that this class of algorithm is challenging to work with. From our understanding, our work is one of the first successful uses of model-based reinforcement learning (MBRL) in nuclear energy1 , and likely the first hierarchical model-based reinforcement learning application in nuclear energy. Further, this work is one of the first known attempts to apply AI to perform a design tasks in nuclear energy. Consequently, there were significant implementation challenges and the bulk of the work was focused on successful implementation and algorithm design. The results presented here are very low technology readiness level as a consequence of the lack of related literature, but still represent a significant step forward in the pursuit of applied AI for design.

42 ENGINEERING↗

Assessing the energy equity benefits of energy storage solutions

Safety, reliability, efficiency, and affordability are no longer the sole tenets of electric grid planning. The evolving social and policy climate have placed new explicit requirements on the electric grid, including resilience, decarbonization, and energy equity and justice. Integrating energy equity strategies into modern grid design is intended to achieve a fair and just distribution of benefits within the energy system. This study aims to characterize the energy equity and community benefits of energy storage systems (ESS) under the following three use-case models: utility ESS that are operated within the distribution system; community-owned ESS; and behind-the-meter ESS that are customer-owned to serve the household. The goal of this energy equity analysis is to characterize the environmental, economic, and social benefits of ESS through applied metrics such as energy burden, energy poverty, energy vulnerability, job creation, and more. A 13.8 kV, 265 node representative feeder corresponding to the hot-humid climate of Louisiana, chosen for its high energy burden, frequent hurricanes and outage events, was used to perform a storage adequacy analysis for six different outage scenarios to determine energy storage access for each use-case. The results of this analysis are then used to characterize both the grid and equity benefits of storage solutions to inform a prioritization framework matching community needs with system preferences for utility planning processes, market regulations, and the wider network of energy system stakeholders.

Energy Equity, energy justice, equity, reliability↗

Braxton Marlatt Intern Poster

The Internet of Things (IoT) encompasses a vast network of interconnected devices embedded with software, sensors, and network connectivity, enabling data collection and exchange. While IoT technology revolutionizes various industries, it also introduces significant security challenges. This research focuses on enhancing IoT security through the implementation of Zero Trust Architecture concepts, specifically targeting the Network and Device pillars of the Cybersecurity and Infrastructure Security Agency’s Zero Trust Maturity Model. By generating Codified Attack Surfaces (CAS) using custom Structured Threat Information eXpression bundles, this project aims to provide enhanced visibility into network communications, detect vulnerabilities in device firmware, and improve the overall security posture for IoT devices and networks. The methodology involves defining custom STIX schema and objects, collecting data from intra-IoT traffic, external network traffic, and firmware analysis, and automating the conversion and correlation of this data into STIX bundles. The automated generation of attack surfaces offers comprehensive insights into activity, vulnerabilities, and anomalies within an IoT environment, enabling proactive threat identification and mitigation.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Nuclear Safety [Vol. 37, No. 2, April-June 1996]

Nuclear Safety is a journal that covers significant issues in the field of nuclear safety. Its primary scope is safety in the design, construction, operation, and decommissioning of nuclear power reactors worldwide and the research and analysis activities that promote this goal, but it also encompasses the safety aspects of the entire nuclear fuel cycle, including fuel fabrication, spent-fuel processing and handling, and nuclear waste disposal, the handling of fissionable materials and radioisotopes, and the environmental effects of all these activities. Table of Contents for this issue follows. GENERAL SAFETY CONSIDERATIONS: 97 The Nuclear Community and the Public: Cognitive and Cultural Influences on Thinking About Nuclear Risk, M. A. Meyer; 109 Twenty-Third Water Reactor Safety Information Meeting, D. A. Copinger; ACCIDENT ANALYSIS: 126 Analysis of a PWR LBLOCA Without SCRAM, Trevor N. Tyler, Rafael Macian-Juan and John H. Mahaffy; DESIGN FEATURES: 139 Vulnerability of Multiple-Barrier Systems, N. C. Lind; ENVIRONMENTAL EFFECTS: 149 A Study of Wet Catalytic Oxidation of Radioactive Spent Ion Exchange Resin by Hydrogen Peroxide, Xingchao Jian, Tianbao Wu, and Guichun Yun; 157 A Comparison Study and Resolution of Differences Between Emergency Response and Safety Analysis Codes Used at the Savannah River Site, A. A. Simpkins; OPERATING EXPERIENCES: 164 Reactor Shutdown Experience, Compiled by J. W. Cletcher; RECENT DEVELOPMENTS: 167 Reports, Standards, and Safety Guides, D. S. Queener; 172 Proposed Rule Changes as of Dec. 31,1995; ANNOUNCEMENTS: 178 American Nuclear Society 1997 Annual Meeting; 178 American Nuclear Society Nuclear Criticality and Safety Division Topical Meeting; 176 The Authors.

05 NUCLEAR FUELS↗

Nuclear Safety [Vol. 37, No. 2, April-June 1996]

Nuclear Safety is a journal that covers significant issues in the field of nuclear safety. Its primary scope is safety in the design, construction, operation, and decommissioning of nuclear power reactors worldwide and the research and analysis activities that promote this goal, but it also encompasses the safety aspects of the entire nuclear fuel cycle, including fuel fabrication, spent-fuel processing and handling, and nuclear waste disposal, the handling of fissionable materials and radioisotopes, and the environmental effects of all these activities. Table of Contents for this issue follows. GENERAL SAFETY CONSIDERATIONS: 97 The Nuclear Community and the Public: Cognitive and Cultural Influences on Thinking About Nuclear Risk, M. A. Meyer; 109 Twenty-Third Water Reactor Safety Information Meeting, D. A. Copinger; ACCIDENT ANALYSIS: 126 Analysis of a PWR LBLOCA Without SCRAM, Trevor N. Tyler, Rafael Macian-Juan and John H. Mahaffy; DESIGN FEATURES: 139 Vulnerability of Multiple-Barrier Systems, N. C. Lind; ENVIRONMENTAL EFFECTS: 149 A Study of Wet Catalytic Oxidation of Radioactive Spent Ion Exchange Resin by Hydrogen Peroxide, Xingchao Jian, Tianbao Wu, and Guichun Yun; 157 A Comparison Study and Resolution of Differences Between Emergency Response and Safety Analysis Codes Used at the Savannah River Site, A. A. Simpkins; OPERATING EXPERIENCES: 164 Reactor Shutdown Experience, Compiled by J. W. Cletcher; RECENT DEVELOPMENTS: 167 Reports, Standards, and Safety Guides, D. S. Queener; 172 Proposed Rule Changes as of Dec. 31,1995; ANNOUNCEMENTS: 178 American Nuclear Society 1997 Annual Meeting; 178 American Nuclear Society Nuclear Criticality and Safety Division Topical Meeting; 176 The Authors.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

SoK: A Framework for and Analysis of Software Bill of Materials Tools

Modern software development has gradually become more complex, leveraging available open-source software and third party components. This practice has raised questions about the provenance, licensing, versioning and compliance of reused code and its dependencies. Furthermore, it is par ticularly important to review such code fragments and third party components for known-vulnerabilities before they are included in a software product. A Software Bill of Materials (SBoM) is a mechanism to achieve such an analysis, provid ing transparency and visibility into a software product to both the software developer and its respective consumer. An SBoM lists information and details about all the elements constituting a piece of software and can, therefore, be used to evaluate associated security risk. While the concept of SBoMs is growing in popularity, it is still fairly new to many organizations, causing them to potentially struggle with pro ducing and processing SBoMs and limiting their widespread adoption. In this work, we delve into the area of SBoMs and present the state-of-the-art SBoM tools, creating a framework for analysis and categorizing them based on a diverse set of features and functionalities. We are the first to provide a detailed analysis of 83 open-source SBoM tools along with a perspective on how a potential SBoM user can select a tool based on their specific requirements. Our work aims to help promote understanding of this domain, thereby encouraging and furthering its overall adoption. We additionally seek to pave a path for future work in this area by providing recommendations to tool developers and users, researchers, and standardizing organizations.

99 GENERAL AND MISCELLANEOUS↗

Automation of Vulnerability and Patch Management: Information Extraction, Association, and Optimization

Vulnerability and patch management is an integral part of a robust cybersecurity program, yet it grows increasingly complex due to the sheer amount of data that must be analyzed. Particularly in Operational Technology (OT) environments, analysis must be done manually because of the lack of automated solutions. Additionally, there are many steps in this process, from the initial discovery of the vulnerability to the implementation of its remediation, and each step in the process requires different data in order to be performed effectively. In this work, we provide approaches and strategies to assist operators in industrial or OT environments throughout the vulnerability management cycle. Security advisories provide key information about mitigation strategies, or actions that can be taken when a patch is unavailable or cannot be installed. Details of these strategies are not shared in public vulnerability databases and must be found manually. We approach this problem by designing a solution to automatically identify that information within vendor security advisories and retrieve it for operator use. We start with an approach that requires domain-specific knowledge of certain frequently-seen reference websites. Next, an approach that can work on an arbitrary website but relies on certain keywords. Finally, an approach that uses Natural Language Processing (NLP) methods and does not require specific knowledge or keywords. Each of these approaches is more general than its predecessor; we demonstrate high accuracy for all approaches Advisories also often contain details of affected products in non-standard or natural language formats. While this information can be easily understood when read by an operator, the non-standard format acts as a barrier to effective automation. We provide an approach for the first step in this process: identifying vendors in security advisories and mapping them to a standard framework for representing digital assets and software products. We evaluate five established string similarity algorithms, plus one of our own design that combines string similarity and information theory, on the task of mapping vendors to their corresponding entries in the Common Platform Enumeration (CPE) repository. Our results show that our proposed metric outperforms all others. Due to the constraints on time, finances, and personnel for organizations, Large Language Models (LLMs) may seem like attractive opportunities for security operators to speed up information gathering; however, it is still not clear whether LLMs can handle vulnerability management tasks well. To answer this question, we perform an empirical study of LLMs’ ability to provide consistent, accurate information about vulnerabilities in order to guide organizations in their adoption of LLMs. We observe poor performance for all models tested, suggesting that these models are not well-suited to the consistent retrieval of accurate vulnerability information. Finally, once vulnerabilities have been identified and any additional information has been obtained, operators must decide which remediation actions to implement based on their available resources. This already-complex problem becomes even more so when we consider that a vulnerability may have multiple avenues for remediation. We formulate this scenario as two knapsack problems and provide solutions, which we then compare against several existing strategies for vulnerability prioritization seen in real operational environments.

McClanahan, Kylie↗

The cardiac molecular setting of metabolic syndrome in pigs reveals disease susceptibility and suggests mechanisms that exacerbate COVID-19 outcomes in patients

Abstract Although metabolic syndrome (MetS) is linked to an elevated risk of cardiovascular disease (CVD), the cardiac-specific risk mechanism is unknown. Obesity, hypertension, and diabetes (all MetS components) are the most common form of CVD and represent risk factors for worse COVID-19 outcomes compared to their non MetS peers. Here, we use obese Yorkshire pigs as a highly relevant animal model of human MetS, where pigs develop the hallmarks of human MetS and reproducibly mimics the myocardial pathophysiology in patients. Myocardium-specific mass spectroscopy-derived metabolomics, proteomics, and transcriptomics enabled the identity and quality of proteins and metabolites to be investigated in the myocardium to greater depth. Myocardium-specific deregulation of pro-inflammatory markers, propensity for arterial thrombosis, and platelet aggregation was revealed by computational analysis of differentially enriched pathways between MetS and control animals. While key components of the complement pathway and the immune response to viruses are under expressed, key N6-methyladenosin RNA methylation enzymes are largely overexpressed in MetS. Blood tests do not capture the entirety of metabolic changes that the myocardium undergoes, making this analysis of greater value than blood component analysis alone. Our findings create data associations to further characterize the MetS myocardium and disease vulnerability, emphasize the need for a multimodal therapeutic approach, and suggests a mechanism for observed worse outcomes in MetS patients with COVID-19 comorbidity.

60 APPLIED LIFE SCIENCES↗

Where to cool off: a geospatial framework for placement of cooling centers

Indoor cooling is essential to reduce heat stress and increase passive survivability during heatwaves. Although air conditioning (AC) is recommended for maintaining indoor thermal comfort, low- and medium-income households in the U.S. often do not own an AC and/or limit AC usage to reduce energy consumption and associated costs, thereby risking their health and safety. With the frequency and intensity of heatwaves increasing, cooling centers are considered an appropriate alternative to indoor cooling and a possible mitigation strategy to prevent adverse health impacts of heat exposure. However, these centers are limited in numbers and not always accessible. This requires (i) developing a geospatial framework using physical and social factors for optimal siting of cooling centers to meet future needs and (ii) ranking of existing and potential cooling centers (schools, libraries, religious institutions) based on their accessibility among vulnerable populations and proximity to healthcare facilities. We developed and deployed a geospatial framework based on the Multi-criteria Decision Analysis approach in five U.S. cities (Los Angeles (LA), Phoenix, Austin, Atlanta, Miami) to evaluate the effectiveness of the framework in ranking cooling centers based on accessibility and population coverage. The results revealed that (i) access to cooling centers varies across cities and 32.2–50.7% of centers are within walking distance of the most vulnerable populations, (ii) vulnerable populations exposed to Urban Heat Island (UHI) effects are more likely to experience energy burden, and (iii) about 21.2–49.4% of population with high energy burden have access to these centers. Considering that more cooling centers are needed to assist energy burdened households alleviate heat exposure impacts, the framework developed herein could be adapted to incorporate other factors (e.g. health impacts, policies) to assess site suitability of existing shelters, identify potential sites for new cooling centers, and geo-target communities where energy efficient emerging technologies could be deployed to reduce heat stress.

58 GEOSCIENCES↗

The Future of X-ray Irradiation: Addressing Supply Chain Risks and Opportunities (UUR Edition)

This study supports the Office of Radiological Security’s (ORS) mission of eliminating cesium irradiators by analyzing the supply chain for self-shielded X-ray irradiators (SSXIs), identifying potential risks, and proposing mitigation measures. The research focuses on the primary components of SSXIs, including X-ray tubes, controllers, generators, and coolers or chillers, and evaluates their vulnerabilities using a comprehensive risk matrix framework. The methodology includes subject matter expert (SME) interviews with relevant manufacturers and major stakeholders, a deep literature review, and a meta-analysis of maintenance reports provided by SSXI end users. Results show that while the SSXI market is small, it’s growing, and the highly global nature of the supply chain may create vulnerabilities for critical SSXI components (X-ray tubes are the most vulnerable, followed by generators and controllers). This research communicates necessary information to address concerns of current and future end users, especially those interested in transitioning away from radioactive sources, and informs future policy aimed at supporting the irradiation industry.

07 ISOTOPE AND RADIATION SOURCES↗

Vulnerabilities in Artificial Intelligence and Machine Learning Applications and Data

Artificial intelligence (AI) applications driven by machine learning (ML) are transformational technologies within the international nuclear security regime. Advancements realized by AI—faster and improved data insights, more efficient and automated processes, reductions in human error—enable nuclear security applications such as behavior analysis for insider threat mitigation, source tracking of stolen nuclear material, and facial recognition software for physical protection. In addition to the advantages, however, there are also inherent vulnerabilities and threats associated with its use and risk mitigations must be built into any AI/ML-enabled systems. This work provides a background on AI and ML and different data types used in the field, including open-source intelligence information (OSINT) that is discoverable by AI tools and application data that are used by AI tools for decision-making and automation. Current and potential AI applications and vulnerabilities related to their use within the nuclear security regime are also discussed.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Survey of Cyber Risk Analysis Techniques for Use in the Nuclear Industry

Using traditional probabilistic risk analysis methods for severe accident safety risk management on non-digital systems, structures, and components at nuclear power plants is well-established. In contrast, cyber risk analysis of digital assets is still an immature field with unproven techniques due, in part, to the continuously changing threat environment and the challenge of digital assets failing in unexpected ways. As the nuclear fleet continues to adopt digital instrumentation and control systems, it is increasingly important to have effective and efficient cyber risk analysis techniques to support risk management decisions, such as risk elimination by system redesign or risk mitigation by implementation of prioritized security controls. To understand the state of the art in cyber risk analysis for future research, we surveyed 36 publications across ten application domains. We describe our survey methodology and rate each technique based upon scope, adoptability, and repeatability. In this work, we examine the unique constraints of the nuclear industry and outline the strengths and weaknesses of using the cyber risk analysis techniques in the industry, highlighting gaps with current techniques. We also discuss challenges and potential research directions for advancing the science for both existing and new advanced reactors.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Continental-scale integration of soil metagenomes and organic matter chemistry reveals ubiquitous microbial capacity for chemically-recalcitrant carbon decomposition

Soil organic matter (SOM) decomposition by microorganisms is a major uncertainty in predicting terrestrial carbon–atmosphere feedbacks, partly because we lack understanding of the microbial diversity involved in depolymerizing different carbon pools across environmental gradients. We address this gap using a continental-scale dataset pairing shotgun metagenomes with high-resolution SOM chemistry, assembling 0.76 Tbp of prokaryotic MAGs (828 genomes) and identifying 66,727 SOM molecules from 47 standardized U.S. soil cores selected using respiration rates from 106 soils. Integrating these datasets reveals widespread microbial potential for depolymerizing chemically-recalcitrant SOM previously considered stable. We uncover complementary metabolic specialization between genera affiliated with two abundant bacterial orders, Rhizobiales and Chthoniobacterales, and an archaeal order, Nitrososphaerales. This metabolic partitioning is consistent across soil depths and activity levels, suggesting coordinated decomposition of complex SOM through distinct but complementary biochemical strategies. The metabolic potential for depolymerization of chemically-recalcitrant compounds is supported by the abundance of these molecules across the soils, as indicated by Fourier-Transform Ion Cyclotron Resonance Mass Spectrometry (FTICR-MS), and by flux balance analysis of metabolic models. Our results show that a substantial portion of ostensibly stable SOM remains vulnerable to microbial decomposition, a mechanism not captured in current Earth System Models.

Song, Young C. [Pacific Northwest National Laborat↗