MMODS: Detecting Threats Beyond the Limits of Human Sensor Sight (GeoINT Symposium 2025)
Explore the source record for details and available documents.
SEARCH · Engineering Papers
Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.
Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.
Explore the source record for details and available documents.
Explore the source record for details and available documents.
This report examines the application of artificial intelligence (AI) technologies for insider threat mitigation (ITM) programs in nuclear security facilities. Insider threat detection presents unique challenges due to the subtle and adaptive nature of these threats, the complex signatures involved, and the scarcity of available data for analysis. Traditional human-centered approaches, while essential, face limitations in processing large amounts of data continuously and detecting subtle patterns across multiple systems. AI technologies can potentially address these limitations by providing 24/7 monitoring capabilities, identifying complex patterns that might escape human observation, and offering consistent application of security criteria. However, the deployment of AI in nuclear security contexts introduces significant new risks, including workflow disruption, expanded attack surfaces, potential for misuse, and ethical concerns regarding privacy, fairness, transparency, safety, and security. The high-consequence nature of nuclear security decisions demands careful consideration of these risks and systematic approaches to their mitigation.
The increasing use of remote or mobile access, integrated wearable technologies, data exchange, and cloud-based data analytics in modern smart buildings is steering the building industry towards open communication technologies. The increased connectivity and accessibility could lead to more cyber-attacks in smart buildings. On the other hand, physical faults (e.g., HVAC -heating, ventilation, and air-conditioning faults) may have similar adverse impacts as those from the cyber-attacks on building energy systems, such as occupant discomfort, energy wastage, and equipment downtime. However, current physical behavior-based anomaly detection methods fail to differentiate between cyber-attacks and physical faults in building energy systems. Moreover, the challenge in collecting real-world threat data with ground truth has led researchers to rely on numerical models with user-defined assumptions, which may not accurately reflect real-world conditions due to the lack of in-situ experimental datasets. To address these challenges and gaps, this paper presents a flexible hardware-in-the-loop (HIL) testbed for generating cyber-attack and physical fault datasets and demonstrating threat detection algorithms in a real building automation system (BAS) environment. This testbed combines hardware (i.e., real BAS with local HVAC controllers and a physical network) with software (i.e., high-fidelity models to represent behaviors of building envelope and HVAC energy systems), enabling emulations of realistic threats. Five HIL experiments, including one baseline without any threats, two with physical faults, and two with cyber-attacks, were conducted to generate datasets containing detailed network traffic and system states. A joint classification framework, incorporating a network analyzer and a physical HVAC fault detector, was proposed to automatically detect cyber-physical abnormalities on BAS at both the network and the physical HVAC levels. The network analyzer comprises a conditional random fields (CRF) based command validator and a statistics-based detection strategy. The fault detector employs a weather and schedule-based pattern matching and feature-based principal component analysis (WPM-FPCA) method. Evaluation of the classification using four metrics from the multi-class confusion matrix revealed an average accuracy of 90.2%, recall of 89.7%, precision of 88.5% and F1-score of 89.2%. Finally, these results demonstrate that the proposed joint classification framework can effectively differentiate between specific types of cyber-attacks (e.g., device reinitialization attack, network Denial-of-Service attack) and physical faults (e.g., air handling unit operational fault, cooling coil valve stuck) in real time for improved building energy management.
SF-25-081 Utility software for creating high-performance data pipelines to extract, load, and transform raw electric power systems measurements. For use with anomaly detection models training workflows. The software supports the project: Adaptive Cybersecurity for DER: A Game-Theoretic and Machine Learning approach for Real-Time Threat Detection and Mitigation
The nuclear industry recognizes the difficulties involved in developing effective managerial and leadership skills in a highly technical and proficient workforce such as that found in nuclear facilities. Implementing an insider threat mitigation program (ITMP) within the nuclear industry is a complex and ongoing process that demands a comprehensive understanding of human behavior, an organization’s security culture, and rigorous regulatory requirements yet also accounts for facility characteristics, physical security, material flow, and activities involving nuclear material. Given the high-consequence nature of research reactor operations, even minor lapses can lead to safety, security, and reputational risks. An effective ITMP requires a defense-in-depth approach that incorporates behavioral analysis, robust vetting procedures, continuous monitoring, and cross-disciplinary coordination. It must also promote a culture of vigilance and accountability at all levels up to and including executive leadership but be flexible enough to adapt to evolving global threats and technological advances. Insider threat mitigation is not a one-time effort but rather a sustained commitment to excellence in safety and security. Establishing a culture in which personnel proactively report incidents and issues that could affect nuclear safety and security is vital to maintaining a safe and secure operational environment. This document was developed to guide senior management and research reactor organizations in creating comprehensive programs to effectively manage and mitigate insider threat behaviors and actions. It focuses on the key pillars of an effective ITMP, including the national legal framework, security culture, preventive and protective measures, cyber security, and performance evaluation. By using a systematic approach during implementation, facilities can foster environments conducive to insider threat detection and support long-term program sustainability. The document also provides strategies for improving communication across all levels of an organization, helping to eliminate barriers that hinder the development of robust ITMPs and enhance overall security culture. In today’s organizations, the concept of leveraging safety and security culture lessons to facilitate knowledge transfer is rapidly evolving to expedite insider threat management and security culture improvements. This document outlines the rationale for evaluating an ITMP based on national customs, culture, and stakeholders. The elements are all germane to reliability and trustworthiness and relate to security concerns that states may encounter. The document focuses not only on individual perceptions regarding security issues and capability building but also on team building and how to resolve concerns. The implementers of a facility’s ITMP may zero in on indicators of insider threats within their enterprise. This material will benefit organizations when it is applied using a systematic and structured approach as demonstrated throughout the document.
In unattended monitoring scenarios, automated radiation detection algorithms must be able to detect low signal-to-noise ratio (SNR) anomalies in a potentially dynamic and noisy background and report these anomalies in a timely fashion. Dynamic and noisy backgrounds complicate the use of simple gross-counting algorithms because they can lead to either high false positive rates or low sensitivity. Algorithms that use the entire spectrum have been the most successful in this area; notable examples are the NSCRAD algorithm developed at Pacific Northwest National Laboratory and recently the nonnegative matrix factorization approach developed at Lawrence Berkeley National Laboratory (LBNL). These approaches use either spectral regions of interest or spectral decomposition to detect threat isotopes in the background.
The use of digital control systems and automation in advanced nuclear power systems introduces different types of vulnerabilities compared to legacy (i.e. analog) control systems that cyber adversaries can exploit. These vulnerabilities pose a challenge to reactor operators and cyber operations staff due to the dynamic nature of the event in which a human response or a lack of response can potentially evolve into a worsening plant condition. Using the Department of Homeland Security Cyber and Infrastructure Security Agency’s (CISA) critical infrastructure exercise framework, this document presents several cyber security scenarios typical of digital control systems that could be used in advanced reactor designs. These scenarios can be used in tabletop exercises to evaluate cyber security posture or conduct training on different aspects of cyber security, including detection, threat hunting using indicators of compromise, evaluating incident response, risk mitigation, incident reporting, information sharing and recovery.
Poster for CBDS&T conference
We developed multiple machine learning methods for the detection and classification of new wireless communication waveforms, which is critical for targeted attacks in wireless networks and electronic warfare. Our machine learning models are capable of dynamically detecting security threats in near real time through our advanced open set recognition (OSR) approach. This model has demonstrated significant improvements in the detection of unknown waveforms, thereby enhancing the security and reliability of mission critical communications. Our approach to detecting uncertain security threats is novel; we advanced OSR techniques by incorporating domain knowledge of wireless signals. Specifically, we combined time and frequency domain model features to enhance the model’s performance. Utilizing an OSR approach eliminates the need for training data to be distributed similarly to the deployment environment and removes the requirement for the training set to contains all possible threat classes. This is crucial because it is often infeasible to determine and characterize all potential security threats in advance. Our model were trained on simulated data, generated in partnership with the University at Albany, State of New York. The data set contained a diverse array of wireless signals, including those with additive white Gaussian noise and multipath signals, with and without line of sight. This comprehensive training set allowed us to optimize our models to detect unknown waveforms under various challenging scenarios, such as low signal-to-noise ratios. By training on various waveforms, varying signal-to-noise ratio, and different sample sizes under normal conditions, our models were fine tuned to perform effectively in challenging environments.
The continued emergence of pathogens, whether novel, re-emerging, or engineered, poses a persistent global biosecurity and public health challenge. Recent outbreaks, including COVID-19, Lassa fever, Marburg virus, mpox, and avian influenza, underscore the urgent need for robust systems that enable rapid surveillance, early diagnosis, and timely countermeasures before widespread human transmission occurs. In this article, we focus on early detection technologies and systematically evaluate current diagnostic and sensing modalities. We highlight sequencing and spectroscopy as two complementary approaches capable of providing broad, agnostic detection and rich biological insight. Our analysis emphasizes that scientific innovation alone is insufficient: effective preparedness also requires improved data curation, integration, and sharing to build AI-ready resources that accelerate future responses. We argue for coordinated advances in both technological capabilities and supporting infrastructure to enable the rapid identification and characterization of emerging pathogens and to fully leverage modern science against evolving infectious threats.
The Collection and Analysis of Telemetry for CyOTE Heuristics (CATCH) provides a framework for augmenting an organization’s existing security controls with CyOTE developed analyses. CATCH collects, stores, analyzes, and creates STIX reports on anomalous data. CATCH connects the CyOTE analysis framework together with the MITRE ICS ATT&CK® patterns and highlights areas of improvement and further research. This tool is designed to enhance an organization’s security controls by providing a structured approach to collecting, storing, analyzing, and reporting anomalous data.
Most virus infection assays have indirect readout such as virus number following entry (e.g., PCR, cell lysis). While effective, these technologies are labor‐intensive, require specialized environments (e.g., sterile or RNA‐free), and detect later‐stage viral events like lysis or cell death, lacking sensitivity to early fusion events. To address these limitations, we present biologically relevant 2D membrane materials, host‐cell‐derived supported lipid bilayers (hcd‐SLBs), integrated with organic microelectrode arrays (OMEAs) for detection of severe acute respiratory syndrome coronavirus 2 (SARS‐CoV‐2) fusion. By overexpressing angiotensin‐converting enzyme 2 (ACE2) receptors on the native membranes, the platform functions as a viral sensor capable of detecting virus pseudo particles (VPPs) through the late pathway. Additionally, hcd‐SLBs extracted from human lung epithelium expressing native ACE2 detect fusion events through the early pathway. The platform's utility as a drug‐screening tool is demonstrated by testing antibodies targeting either the ACE2 on the host membrane or the viral spike (S) proteins. To enhance the throughput, microfluidics are integrated for automation and OMEAs are incorporated within each channel, miniaturizing the testing units. This system supports high‐throughput data generation, automation, and scalability, providing an efficient platform for viral fusion detection that advances the study of pathogen‐host interactions and accelerates antiviral drug discovery.
Abstract Electric power systems are composed of physical and cyber sub‐systems. The sub‐systems depend on each other. If the cyber sub‐system is compromised by a cyber threat, what is the impact on the physical system? This paper presents a case study that shows the steps of a multi‐stage cyber threat involving a database injection attack, and what happens to the power system if this threat is not detected in its early stages. The threat first affects one utility but it can spread to the balancing authority, which is responsible for keeping the voltage and frequency stable in the power grid. During the cyber threat, the authors also show defence tools, such as a cyber‐physical data fusion tool that displays and analyses power and cyber telemetry.
Explore the source record for details and available documents.
Comprehensive space force protection must include effective and trustworthy laser threat warning (LTW). Effective LTW will detect and characterize threats to space assets and thus enhance space deterrence. LTW must be trustworthy: able to categorize threats and non-threats by being both sensitive to true events and resistant to false alarms. Outside of the laboratory, the statistics and even the roles of lasers become unclear. In the chain of events leading to an attack, the laser may be the last link to be understood. Human situational awareness and informal reasoning must blend statistics with circumstantial evidence to visualize these chains before they are clear. This paper sets out an industrial model for an enterprise that will routinely produce trustworthy LTW. By incorporating psychology and economics, this enterprise can overcome the difficulties and perils of cooperation in networked defense and intelligence. This roadmap suggests how the enterprise can incentivize distracted actors with different goals to share what they know and coordinate what they do.
Detection of novel threat agents presents several challenges, a principle one being the development of untargeted methods to screen an increasing number of threat chemicals whose exact structures are unknown. With the use of Machine Learning (ML) tools, we can guide the development of analytical methods for broad-spectrum detection of unbounded threat chemical families in complex mixtures. Toward this goal, we used nominal mass and high-resolution mass spectrometry data for hundreds of synthetic opioids and non-opioid compounds. We tested two ML techniques, logistic regression and random forest, to develop models towards a practical, implementable method for opioid detection. We found that of these tested ML methods, random forest models resulted in the highest validation accuracy (95+%) for both nominal mass and high-resolution classification of opioids versus non-opioids, with low false positive and false negative rates. The RF models were then used to successfully predict the classification of 10 compounds—five opioids and five non-opioids not part of the training and validation analysis. This application of ML is a critical step towards the development of field-deployable nominal mass spectrometers with ML-driven analyses for classification of emergent threats.
Detection of novel threat agents presents several challenges, a principle one being the development of untargeted methods to screen an increasing number of threat chemicals whose exact structures are unknown. With the use of Machine Learning (ML) tools, we can guide the development of analytical methods for broad-spectrum detection of unbounded threat chemical families in complex mixtures. Toward this goal, we used nominal mass and high-resolution mass spectrometry data for hundreds of synthetic opioids and non-opioid compounds. We tested two ML techniques, logistic regression and random forest, to develop models towards a practical, implementable method for opioid detection. We found that of these tested ML methods, random forest models resulted in the highest validation accuracy (95+%) for both nominal mass and high-resolution classification of opioids versus non-opioids, with low false positive and false negative rates. The RF models were then used to successfully predict the classification of 10 compounds—five opioids and five non-opioids not part of the training and validation analysis. This application of ML is a critical step towards the development of field-deployable nominal mass spectrometers with ML-driven analyses for classification of emergent threats.