SEARCH · Engineering Papers
Results for “FDIA”
Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.
Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.
Sequential Perturbation-based FDIA Detection using DERs for Unbalanced Distribution System
The power distribution system with its reliance on automated monitoring and control infrastructure makes it a complicated cyber-physical system and vulnerable to various cyber-attacks. This paper proposes a moving target defense inspired false data injection attack (FDIA) detection mechanism for an unbalanced distribution system. In the proposed grid diagnosis service framework, the distribution system operator judiciously manipulates power outputs of a subset of inverter-based distribution energy resources (DERs) to create secret low magnitude voltage perturbations which are inconsequential to the normal operation of the grid. A mixed-integer-linear-programming algorithm is developed to select the optimal set of DERs that can create a voltage perturbation signal of the required magnitude at each sensor location at a minimum cost. Then, a sequential detector is applied that detects for the FDIA as measurements are received from individual sensors. The performance of the proposed perturbation-based FDIA detection framework is demonstrated via simulation of the IEEE 123 bus test system.
Detection of False Data Injection Attacks (FDIA) on Power Dynamical Systems With a State Prediction Method
Not Available
Cyber-Impact Analysis for ISO Revenue Adequacy Considering FDIA in Real-Time Market Operations
Not provided.
Moving-horizon false data injection attack design against cyber–physical systems
Systematic attack design is essential to understanding the vulnerabilities of cyber–physical systems (CPSs), to better design for resiliency. In particular, false data injection attacks (FDIAs) are well-known and have been shown to be capable of bypassing bad data detection (BDD) while causing targeted biases in resulting state estimates. However, their effectiveness against moving horizon estimators (MHE) is not well understood. In fact, this paper shows that conventional FDIAs are generally ineffective against MHE. One of the main reasons is that the moving window renders the static FDIA recursively infeasible. Here, this paper proposes a new attack methodology, moving-horizon FDIA (MH-FDIA), by considering both the performance of historical attacks and the current system’s status. Theoretical guarantees for successful attack generation and recursive feasibility are given. Numerical simulations on the IEEE-14 bus system further validate the theoretical claims and show that the proposed MH-FDIA outperforms state-of-the-art counterparts in both stealthiness and effectiveness. In addition, an experiment on a path-tracking control system of an autonomous vehicle shows the feasibility of the MH-FDIA in real-world nonlinear systems.
Hybrid Data-Driven Based HVdc Ancillary Control for Multiple Frequency Data Attacks
The high voltage direct current (HVdc) intertie has been applied to provide ancillary-services for ac grids, utilizing the real-time feedback from phasor measurement units (PMUs). However, PMU data communication is vulnerable to false data injection attacks (FDIA) due to protocol defects, thus the HVdc ancillary control and system stability will be threatened. To address this issue, this article proposes a novel HVdc control strategy based on a hybrid data-driven (HDD) methodology. In this work, the HDD methodology is first proposed to detect the types and duration time of multiple frequency attacks. Specifically, the Hilbert Huang transform (HHT) is used to decompose the frequency data, using variational mode decomposition instead of the traditional empirical mode decomposition, to extract data features. Second, a multikernel support vector machine is proposed to classify the attacked data based on the designed distinctive features from HHT. Meanwhile, the attacking duration time is decided using an unsupervised technique. Third, an HDD-based HVdc ancillary control strategy is established to eliminate the effect of FDIAs on the HVdc frequency response. Comprehensive experiments of HDD-based HVdc ancillary controls under different FDIAs suggest that the proposed HDD could fast and accurately classify the FDIAs, and the HDD-based HVdc ancillary control strategy could significantly suppress the impact of the FDIAs.
Frequency Injection Based HVDC Attack-Defense Control Via Squeeze-Excitation Double CNN
Due to the independent controllability and fast power regulation capability, the High Voltage Direct Current (HVDC) system could be a prospective technology to provide multiple ancillary services to the system besides conventional bulk power transmission. However, with the increase of False Data Injection Attacks (FDIAs) on PMU data, the HVDC system could have the wrong response once the collected data that the HVDC system relied on is attacked, thus threatening the system operating security. How to ensure the security of the PMU-based HVDC ancillary service control become an urgent issue. To mitigate the risk, this paper proposed an HVDC attack-defense control based on the FDIAs detection method. Firstly, the Squeeze-Excitation based Double Convolutional Neural Networks (SE-DCNN) is proposed to realize fast identification of the attacking frequency type based on the time and frequency domain signals. Furthermore, the duration time of FDIAs is detected by the local outlier factor. Then, utilizing the results from SE-DCNN, HVDC ancillary service control framework is reorganized and an HVDC attack defense control is proposed for suppressing the potential influence of various types of FDIAs on the HVDC system ancillary service. Different experiments results demonstrate that the proposed method has the ability to significantly mitigate the frequency deviation and oscillation under the FDIA.
Security Enhancement of Network Constraint Grid-Edge Energy Management System
Network constrained grid edge energy management system (EMS) provides economic solution for active and reactive power dispatch of distributed energy resources (DERs) at the grid edge level. Grid edge EMS ensures secure interconnection of a circuit segment to the distribution system by maintaining grid code requirements (e.g. IEEE 1547–2018). Grid edge EMS is dependent on communication to receive load measurement, which brings a risk of unobservable false data injection attacks (FDIAs). To mitigate the risk, this paper proposes a framework to enhance resilient operation of grid edge EMS by detecting the unobservable FDIAs on loads and replacing them with forecasted values. In this work, a two-step detection algorithm is proposed. In first step, conventional residual based algorithm is deployed. Autoencoder (AE) based data driven mechanism is included in second step to detect the presence of unobservable FDIAs. After ensuring the presence of FDIA, its specific location is detected by checking the maximum residue values till the predefined threshold value is reached. Detected false data injected loads are then replaced with forecasted load values following long-short term memory (LSTM) based forecast to ensure resilient performance of grid edge EMS in the presence of attacks. This proposed security enhancement framework for grid edge EMS is evaluated in IEEE 13 bus system with three integrated DERs. Numerical simulation shows the validation of the proposed framework by reducing voltage violation in real operation of grid edge EMS.
Detection of False Data Injection Attacks in Battery Stacks Using Input Noise-Aware Nonlinear State Estimation and Cumulative Sum Algorithms
Grid-scale battery energy storage systems (BESSs) are vulnerable to false data injection attacks (FDIAs), which could be used to disrupt state of charge (SoC) estimation. Inaccurate SoC estimation has negative impacts on system availability, reliability, safety, and the cost of operation. In this article a combination of a Cumulative Sum (CUSUM) algorithm and an improved input noise-aware extended Kalman filter (INAEKF) is proposed for the detection and identification of FDIAs in the voltage and current sensors of a battery stack. The series-connected stack is represented by equivalent circuit models, the SoC is modeled with a charge reservoir model and the states are estimated using the INAEKF. Further, the root mean squared error of the states’ estimation by the modified INAEKF was found to be superior to the traditional EKF. By employing the INAEKF, this article addresses the research gap that many state estimators make asymmetrical assumptions about the noise corrupting the system. Additionally, the INAEKF estimates the input allowing for the identification of FDIA, which many alternative methods are unable to achieve. The proposed algorithm was able to detect attacks in the voltage and current sensors in 99.16% of test cases, with no false positives. Utilizing the INAEKF compared to the standard EKF allowed for the identification of FDIA in the input of the system in 98.43% of test cases.
A Graph-Net with Node Embeddings to Detect False Data Injection Attacks in Photovoltaic Systems
Distributed energy resources (DER) contribute to the operational stability of the larger power grid both at utility-scale as well as commercial and residential scales in aggregated forms. These DER in-turn are susceptible to increasing cyber threats. An adversary can plug into the same local network that a field photovoltaic (PV) system uses to interconnect its data loggers and inverters and manipulate certain measurements collected from the network or trick existing irradiance and inverter readings through false data injection attacks (FDIA). Control routines that rely on these measurements can propagate the false data, impacting critical decisions that result in a suboptimal operation or even cause intentional harm leading to inverter-tripping or unscheduled loads that need to be shed. To detect FDIA in PV systems, the paper introduces an attention-based graph neural network with node embeddings and applied it to a simple prototypical DC-coupled microgrid with PV, energy storage, and load. The algorithm shows a detection accuracy of up to 98.95%. The proposed FDIA detection technique will provide micro-grid operators with an effective method to safeguard their systems, guaranteeing the secure and reliable operation.
Online and Offline Identification of False Data Injection Attacks in Battery Sensors Using a Single Particle Model
The cells in battery energy storage systems are monitored, protected, and controlled by battery management systems whose sensors are susceptible to cyberattacks. False data injection attacks (FDIAs) targeting batteries’ voltage sensors affect cell protection functions and the estimation of critical battery states like the state of charge (SoC). Inaccurate SoC estimation could result in battery overcharging and over discharging, which can have disastrous consequences on grid operations. This paper proposes a three-pronged online and offline method to detect, identify, and classify FDIAs corrupting the voltage sensors of a battery stack. To accurately model the dynamics of the series-connected cells a single particle model is used and to estimate the SoC, the unscented Kalman filter is employed. FDIA detection, identification, and classification was accomplished using a tuned cumulative sum (CUSUM) algorithm, which was compared with a baseline method, the chi-squared error detector. Online simulations and offline batch simulations were performed to determine the effectiveness of the proposed approach. Throughout the batch simulations, the CUSUM algorithm detected attacks, with no false positives, in 99.83% of cases, identified the corrupted sensor in 97% of cases, and determined if the attack was positively or negatively biased in 97% of cases.
Detecting False Data Injection Attacks in Smart Grids: A Semi-Supervised Deep Learning Approach
The dependence on advanced information and communication technology increases the vulnerability in smart grids under cyber-attacks. Recent research on unobservable false data injection attacks (FDIAs) reveals the high risk of secure system operation, since these attacks can bypass current bad data detection mechanisms. To mitigate this risk, this paper proposes a data-driven learning-based algorithm for detecting unobservable FDIAs in distribution systems. We use autoencoders for efficient dimension reduction and feature extraction of measurement datasets. Further, we integrate the autoencoders into an advanced generative adversarial network (GAN) framework, which successfully detects anomalies under FDIAs by capturing the unconformity between abnormal and secure measurements. Also, considering that the datasets collected from practical power systems are partially labeled due to expensive labeling costs and missing labels, the proposed method only requires a few labeled measurement data in addition to unlabeled data for training. Numerical simulations in three-phase unbalanced IEEE 13-bus and 123-bus distribution systems validate the detection accuracy and efficiency of this method.
Robust detection, isolation, and accommodation for sensor failures
Recent advances in multivariable robust control system design are extended to sensor failure, detection, isolation, and accommodation (FDIA) and estimator design. A new concept called threshold selector is introduced. It represents a significant and innovative tool for the analysis and synthesis of FDIA algorithms. Analytical results are obtained for the SISO case to compute optimal thresholds and size of minimum detectable failures, and a computer-aided technique is developed for the multivariable case. The techniques have been applied to sensor FDIA for an aircraft turbine engine control system.
Discovering the Most Severe K-Point Failure Based on Reinforcement Learning: Preprint
Smart devices are essential to ensure the stability of the power grid and resilience to intermittent energy production. However, smart devices can also be the target of cyber adversaries that may exploit false data injection attacks (FDIAs) to induce unstable grid conditions. A practical consideration of FDIA mitigation approaches is addressed here: given a finite available budget, for which smart device should cyber-threat mitigation be deployed first? In this work, this question is answered by identifying the so-called most-sensitive devices, i.e., the devices that, if compromised, can let an adversary induce the most serious grid instabilities. The method proposed utilizes an adversarial reinforcement learning (RL) framework to identify the k-mostsensitive smart devices (here, smart inverters). The adversarial agent can tamper with the compromised inverters' active and reactive operating power setup points, with the goal of maximizing voltage deviations. Numerical results show that the proposed RL method finds the optimal attack scenarios for 1-point failure and the near-optimal solution for the 2-point case. Additionally, the proposed RL method achieves an 8.8 speed-up ratio in running time compared to the brute force method for the 2-point case.
Designing an Intrusion Detection for an Adjustable Speed Drive System Controlling a Critical Process
In this article, we address the cyber-security problem of industrial control systems (ICSs) when their sensor measurements may be compromised due to an attacker who has intercepted those measurements via a network. We introduce a general-purpose method “Dynamic Watermarking (DW)” to detect potential cyber-intrusions on speed sensor measurements within industrial control systems, which deploy an adjustable speed drive (ASD) to control a critical process. The DW method is injecting a random private low-amplitude signal with a zero mean Gaussian distribution, “watermark”, into one of the input phase voltages powering the ASD system. The watermark signal propagates through the system including pulse width modulation (PWM) power conversion stage and motor, then ultimately appears in the speed sensor measurements. By deploying two statistical DW tests with two proper thresholds, the system can detect potential cyber-intrusions or unobservable cyber-attacks such as replay attacks and false data injection attacks (FDIA). The DW method tested on a laboratory-scale ASD system experimentally to protect the system against cyber-intrusions. This system, powered by a commercial PWM drive operating at 208 V, 3-phase, and 3.7 kW, served as our experimental platform.
Cybersecurity Anomaly Detection in SCADA-Assisted OT Networks Using Ensemble-Based State Prediction Model
The cybersecurity threats of power system gradually grow due to the increased sophisticated interactions between Information Technology (IT) and Operational Technology (OT) networks. False data injection attack (FDIA) that aims to compromise the Supervisory Control and Data Acquisition (SCADA) measurement and disturb the system operation is one of such cyber threats. Such attacks can potentially lead to significant operational issues at the control centers and substations, and hence, result in severe physical consequences. To avoid catastrophic failure across the power grid resulting from these attacks, it is essential to arm the OT network with real-time vulnerability assessment tools. To this end, this paper outlines various drawbacks of the Purdue architecture model to defend against cyberattacks in the OT network. Furthermore, a novel ensemble-based state prediction model is proposed to detect cybersecurity anomalies in SCADA assisted OT networks. The proposed model uses control center level generation and load forecasts, scheduled, and forced outages, power flow solutions, and the substation level historical data. The hypothesis of the proposed scheme relies on the fact that additional control center and substation data can hardly be accessed and compromised by attackers. One of the vital features of the proposed scheme is an hour-ahead prediction of the operational feasibility of the SCADA measurement range at the control center and substation in real time helps in detecting anomalies in measurements across both substation and the control center.
Attack-Resilient Weighted $\ell_{1}$ Observer with Prior Pruning
Security related questions for Cyber Physical Systems (CPS) have attracted much research attention in searching for novel methods for attack-resilient control and/or estimation. Specifically, false data injection attacks (FDIAs) have been shown to be capable of bypassing bad data detection (BDD), while arbitrarily compromising the integrity of state estimators and robust controller even with very sparse measurements corruption. Moreover, based on the inherent sparsity of pragmatic attack signals, ℓ1 -minimization scheme has been used extensively to improve the design of attack-resilient estimators. For this, the theoretical maximum for the percentage of compromised nodes that can be accommodated has been shown to be 50%. In order to guarantee correct state recoveries for larger percentage of attacked nodes, researchers have begun to incorporate prior information into the underlying resilient observer design framework. For the most pragmatic cases, this prior information is often obtained through some data-driven machine learning process. Existing results have shown strong positive correlation between the tolerated attack percentages and the precision of the prior information. In this paper, we present a pruning method to improve the precision of the prior information, given corresponding stochastic uncertainty characteristics of the underlying machine learning model. Then a weighted ℓ1 -minimization is proposed based on the pruned prior. The theoretical and simulation results show that the pruning method significantly improves the observer performance for much larger attack percentages, even when moderately accurate machine learning model used.
Trust-Based Detection and Mitigation of Cyber Attacks in Distributed Cooperative Control of Islanded AC Microgrids
In this study, we address the challenge of detecting and mitigating cyber attacks in the distributed cooperative control of islanded AC microgrids, with a particular focus on detecting False Data Injection Attacks (FDIAs), a significant threat to the Smart Grid (SG). The SG integrates traditional power systems with communication networks, creating a complex system with numerous vulnerable links, making it a prime target for cyber attacks. These attacks can lead to the disclosure of private data, control network failures, and even blackouts. Unlike machine learning-based approaches that require extensive datasets and mathematical models dependent on accurate system modeling, our method is free from such dependencies. To enhance the microgrid’s resilience against these threats, we propose a resilient control algorithm by introducing a novel trustworthiness parameter into the traditional cooperative control algorithm. Our method evaluates the trustworthiness of distributed energy resources (DERs) based on their voltage measurements and exchanged information, using Kullback-Leibler (KL) divergence to dynamically adjust control actions. We validated our approach through simulations on both the IEEE-34 bus feeder system with eight DERs and a larger microgrid with twenty-two DERs. The results demonstrated a detection accuracy of around 100%, with millisecond range mitigation time, ensuring rapid system recovery. Additionally, our method improved system stability by up to almost 100% under attack scenarios, showcasing its effectiveness in promptly detecting attacks and maintaining system resilience. These findings highlight the potential of our approach to enhance the security and stability of microgrid systems in the face of cyber threats.