Engineering PapersSearch

SEARCH · Engineering Papers

Results for “coordinated attacks”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

Model-Based Detection of Coordinated Attacks (DCA) in Distribution Systems

The fast-paced growth in digitization of smart grid components enhances system observability and remote-control capabilities through efficient communication. However, enhanced connectivity results in heightened system vulnerability towards cybersecurity risks in the cyber-physical power system. Coordinated cyber-attacks (CCA), when undetected, lead to system-wide impact in terms of large disturbances or widespread outages. Detecting CCA in the cyber layer is critical to thwart cyber-attacks in real-time before the attack impacts the physical system. The challenge of locating CCA stems from the complex grid dynamics, making it difficult to distinguish between normal operational variations and cyber-attack impact. CCA often employs multiple attack vectors targeting geographically distributed components, further complicating CCA identification. Existing research in intrusion detection is primarily focused on the transmission network and limited to detecting individual attacks. In this paper, a novel proactive DCA strategy is proposed for early detection of CCA by establishing correlations among distinct attack events through model-based reinforcement learning that utilizes abductive reasoning to conclude the attacker goal. The solution includes understanding the system model, learning the system dynamics, and correlating individual cyber-attacks to extract the attacker’s objective. The developed learning algorithm identifies the most probable attack path to reach the attacker’s objective by predicting the next attack steps. A DNP3-based cyber-physical co-simulation testbed is developed to test the proposed algorithm using the IEEE 13-node test feeder.

24 POWER TRANSMISSION AND DISTRIBUTION

Secure State Estimation with Asynchronous Measurements for Coordinated Cyber Attack Detection in Active Distribution Systems

Coordinated cyber attacks tamper with measurement data to disrupt the situational awareness of active distribution systems. Various sensors report measurements asynchronously at different rates, which introduces challenges during state estimation. In addition, this forces cyber intruders to exert greater effort to compromise multiple communication channels and launch coordinated attacks. Therefore, multi-channel and asynchronous measurements could be harnessed to develop more secure cyber defense strategies. In this paper, a prediction-correction-based multi-rate observer is designed to exploit the value of asynchronous measurements for the detection of coordinated false data injection (FDI) attacks. First, a time-function-dependent prediction-correction strategy is proposed to adjust the sampling interval for each sensor’s measurement. Then, an observer is designed based on the trade-off between estimation error and the optimal period of the most recent sampling instant, with the convergence of estimation error with the maximum permitted sampling interval. Moreover, the conditions for exponential stability are developed using the Lyapunov–Krasovskii functional technique. Next, a coordinated FDI attack detection strategy is developed based on the dual nonlinear minimization problem. The proposed attack detection and secure state estimation strategies are tested on the IEEE 13-node system. Simulation results show that these schemes are effective in enhancing attack detection based on asynchronous measurements or compromised data.

asynchronous measurements

Coordinated Thermal Safety Attack and Defense on EV Battery Management Systems

Battery temperature sensor and battery current sensor data which are key sensing inputs to the Battery Management Controllers in electric vehicles, are vulnerable to possible cyber/ physical manipulation due to known vulnerabilities inherited from CAN bus technology that is used for in-vehicle communications between electronic control units that transfer sensing and control data. In this paper, we first create a simulation that enables us to evaluate impact of cyber physical attacks on electric vehicle battery management system in a controlled environment that violates thermal safety. Specifically, we emulate a Level 3 - DC fast charging system with SAE J1772/CCS, integrated with standard charging controls and thermal safety controls on EVs, and various sensing data flows. Second, we propose a coordinated current and battery temperature attack that has crippling economic, and safety impacts. Third, we quantify the usability, economic and safety impacts of such attacks as a function of the extent of data manipulation. Finally, we propose a physics model driven detection technique to detect presence of such attacks.

25 ENERGY STORAGE

Edge ML for CAN bus intrusion detection in AVs

Autonomous Vehicles (AVs) are revolutionizing transportation, but their reliance on interconnected cyber-physical systems exposes them to unprecedented cybersecurity risks. This study addresses the critical challenge of detecting real-time cyber intrusions in self-driving vehicles by leveraging a dataset from the Udacity self-driving car project. We simulate four high-impact attack vectors, Denial of Service (DoS), spoofing, replay, and fuzzy attacks, by injecting noise into spatial features (e.g., bounding box coordinates) to replicate adversarial scenarios. We develop and evaluate two lightweight neural network architectures (NN-1 and NN-2) alongside a logistic regression baseline (LG-1) for intrusion detection. The models achieve exceptional performance, with NN-2 attaining an AUC score of 93.15% and 93.15% accuracy, demonstrating their suitability for edge deployment in AV environments. Through explainable AI techniques, we uncover unique forensic fingerprints of each attack type, such as spatial corruption in fuzzy attacks and temporal anomalies in replay attacks, offering actionable insights for feature engineering and proactive defense. Visual analytics, including confusion matrices, ROC curves, and feature importance plots, validate the models' robustness and interpretability. This research sets a new benchmark for AV cybersecurity, delivering a scalable, field-ready toolkit for Original Equipment Manufacturers (OEMs) and policymakers. By aligning intrusion fingerprints with SAE J3061 automotive security standards, we provide a pathway for integrating machine learning into safety-critical AV systems. Our findings underscore the urgent need for security-by-design AI, ensuring that AVs not only drive autonomously but also defend autonomously. This work bridges the gap between theoretical cybersecurity and life-preserving engineering, offering a leap toward safer, more secure autonomous transportation.

97 MATHEMATICS AND COMPUTING

Overview and Commentary on Applying the Coordinated Vulnerability Disclosure Process to Photovoltaic System Devices

The rapid expansion of photovoltaic (PV) systems, particularly inverters, has introduced new cybersecurity challenges that threaten both local operations as well as the broader electrical grid’s stability. PV inverters, integrated into critical energy infrastructure are potential targets for cyber attacks due to vulnerabilities in firmware, remote access systems, and communication protocols. The Coordinated Vulnerability Disclosure (CVD) process, as defined by the Cybersecurity and Infrastructure Security Agency (CISA), provides a framework for identifying, reporting, and addressing these vulnerabilities in a transparent and collaborative manner. This report outlines the CVD process as it applies to PV systems, detailing the roles of key stakeholders, such as manufacturers, grid operators, and security researchers. The report also highlights specific challenges in managing vulnerabilities for new and legacy PV systems, which includes those introduced by insecure communications and third-party supply chain components. By adhering to the CVD process, the PV industry can mitigate cybersecurity risks, ensure regulatory compliance, and maintain consumer trust, while safeguarding the operational resilience of the energy grid. Ultimately, the effective coordination of vulnerability management is crucial for securing the future of PV systems within the critical electric grid infrastructure landscape.

14 SOLAR ENERGY

Virtual Agents-Based Attack-Resilient Distributed Control for Islanded AC Microgrid

Due to its dependence on a communication network, distributed secondary control of microgrids is susceptible to denial-of-service (DoS) attacks in channel shutdown mode, which may negatively impact the network connectivity and thus deteriorate the coordination and power sharing among distributed generators (DGs). Honeypot is a common method for cyber deception by introducing fake targets. However, in the context of microgrid, the misleading information spread by honeypots will also impact the system performance. This paper proposes an attack-resilient distributed control for AC microgrids utilizing virtual agents (VAs) to counteract both DoS edge and node attacks. The VAs are designed to not impact the system’s steady state during normal operation but to share information among neighboring real agents and serve as dummy targets for DoS attacks. The control with VAs is implemented by a primal-dual gradient based distributed algorithm to efficiently obtain a practical solution for voltage/frequency regulation and power sharing. The simulation results on a 4-DG test system and a modified IEEE 34-bus system show that 1) VAs do not impact the normal functionality of the test system, and 2) deploying VAs can enhance the resilience of the microgrid control against DoS edge and node attacks.

24 POWER TRANSMISSION AND DISTRIBUTION

Enabling Secure and Resilient XFC: A Software/Hardware-Security Co-Design Approach

Extremely fast charging (XFC) has the potential to reduce the charging time of battery electric vehicles (BEV) to be equivalent to the filling time of internal combustion engine vehicles (ICEV), thus eliminating one of the few advantages ICEV still poses for light- and heavy-duty vehicles. Enabling XFC will, however, require coordination and cooperation between the grid, charging stations, and the vehicles themselves, which leads to an inevitable increase in the attack surface for all systems combined. In securing the overall system, we must not only embrace traditional cybersecurity, which is chiefly concerned with communications and the operation of digital systems, but also cyber-physical systems security as the proper operation of XFC is critically dependent on systems’ abilities to know about (sense) and interact with (actuate) the physical world. The project team consists of academic and industry researchers with backgrounds in cybersecurity, cyber-physical systems security, learning in adversarial environments, transportation security, grid security and resilience, wireless power transfer, converter design, and battery management systems.

33 ADVANCED PROPULSION SYSTEMS

Residential Vehicle-to-Home Backup Power Capabilities: Key Findings from a ComEd Beneficial Electrification R&D Pilot

This report summarizes key findings from a collaborative technical study of residential, non-grid-tied vehicle-to-home (V2H) backup power systems in Commonwealth Edison’s (ComEd’s) service territory. The work integrates (1) a feeder-level technoeconomic analysis (TEA) using historical outage-event data and simulated electric-vehicle (EV) driving/charging profiles to estimate potential reliability and customer interruption-cost impacts under V2H and vehicle-to-grid (V2G) adoption scenarios; (2) controlled laboratory performance testing of a representative V2H backup ecosystem to characterize transfer-to-backup behavior, sustained power delivery, efficiency trends, and repeatable reliability limitations; and (3) a cybersecurity assessment aligned with NIST Cybersecurity Framework (CSF) 2.0 and ISO/SAE 21434 to evaluate interface-level risk drivers and identify program-relevant mitigations. Results indicate that V2H can provide measurable resilience value, but outcomes are strongly context dependent on outage patterns and the share of events that are “V2H-applicable.” Typical transfer-to-backup behavior clustered on the order of minutes, but rare long-delay edge cases were observed (including an event approaching 30 minutes) and should be treated as a reliability risk. High-power testing showed that peak-rated output is not necessarily continuously deliverable; stable operation may require operation below nameplate ratings and attention to thermal and installation constraints. The cybersecurity assessment highlights a broad attack surface spanning commissioning, home networks, embedded services, and cloud/OTA pathways, motivating minimum controls for secure onboarding, signed updates, patch cadence, and coordinated vulnerability response for any scaled deployment.

24 POWER TRANSMISSION AND DISTRIBUTION

Advanced Computational Techniques for Improving Resilience of Critical Energy Infrastructure under Cyber-Physical Attacks

In this chapter, we present recent advances in improving the resilience of cyber-physical systems, especially with regards to energy systems. We provide discussions around various types of cyber-physical events that can cause disruptions and new advances in optimization, control, and reinforcement learning (RL) to deal with the challenges posed by such cyber-physical events. The presented methods range from distributed robust optimization, autonomous and coordinated control, reinforcement learning based resilient control and topology reconfiguration in Inter-System resilient control.

Nazir, Mohammad Nawaf [BATTELLE (PACIFIC NW LAB)]

Concerted Electron-Ion Transport by Polyacrylonitrile Elucidated with Reactive Deep Learning Potentials

Charge transport in polymers, such as polyacrylonitrile (PAN), is crucial for electronics and energy storage. For instance, PAN can transport cations e.g., Li + , by facilitating dynamic cation-nitrile coordination in batteries. However, little is known regarding the underlying role of complex reactive polymer configurations. Herein, we develop a deep-learning potential, trained on ab initio energies and forces of nonequilibrium reactive PAN configurations, to unravel the kinetics of PAN cyclization initiated by a nucleophile (OH – dissociated from LiOH) attacking the terminal nitrile carbon. We find, based on the reaction free-energetics, rates, and charge analysis, that the nucleophile attack producing the first ring is the rate-limiting step, which subsequently triggers Li + -coupled electron transfer along the PAN backbone, causing ∼10 4 times faster sequential ring-formation of the remaining nitriles. PAN’s extended configurations, where dipolar and H-bonding interactions are minimal, enable such rapid kinetics. By validating our computational findings with IR and NMR experiments, we establish a pathway for designing reactive polymers with enhanced charge transport for energy applications.

Chahal-Crockett, Rajni [Oak Ridge National Laborat

FOILPOLARS (Grassmannian Foil Shape Sweeps for Polar Generation) [SWR-26-095]

FOILPOLARS (Grassmannian Foil Shape Sweeps for Polar Generation): Multifidelity aerodynamic polar data generation for hydrofoil/tidal-turbine airfoil sections. Foilpolars ties together three pieces: *AeroSandbox supplies the baseline airfoil coordinates (UIUC database). *G2Aero parameterizes those shapes on a Grassmannian manifold (Karcher mean + PGA basis) and samples new perturbed shapes around that basis. *XFoil (panel method) and NeuralFoil (neural-network surrogate, shipped with AeroSandbox) each solve the resulting shapes for lift, drag, moment, and pressure at the swept angles of attack, Reynolds numbers, and n_crit values. Design optimization of foil shapes in a computationally efficient way requires polars data across many candidate shapes, not just a handful of baseline foils. However, high-fidelity CFD at that scale is too costly, and naive shape perturbation strays from realistic geometries. FOILPOLARS addresses this by loading baseline airfoils (via AeroSandbox) and mapping them onto a Grassmannian manifold (via G2Aero), computing a Karcher mean and principal geodesic analysis (PGA) basis. New shapes are sampled by perturbing PGA coefficients, keeping them close to the manifold of realistic foils. Each sampled shape is evaluated across a configurable sweep of angle of attack, Reynolds number, and critical amplification factor using two solvers: XFoil (panel method) and NeuralFoil (neural-network surrogate), producing a paired dataset of lift, drag, moment, pressure, convergence, and confidence, indexed alongside each shape's PGA coefficients and shared Grassmannian basis in a single xarray dataset. From this, FOILPOLARS produces convergence summaries and comparison plots per shape, Reynolds number, and n_crit. A command-line interface exposes each pipeline stage independently, supporting data-driven design, optimization, and machine-learning workflows for foils.

Sandhu, Rimple [National Laboratory of the Rockies

Cybersecurity Standards for Distributed Energy Resources: Gaps and Harmonization Strategy

This report examines cybersecurity standards for Distributed Energy Resources (DERs) in light of their rapid growth and increasing integration into energy systems. It identifies critical gaps in existing frameworks, including inadequate coverage of DER-specific challenges, complexities in implementing comprehensive standards, integration issues with legacy systems, adoption hurdles for newer standards, and a lack of harmonization across regulatory landscapes. The analysis highlights vulnerabilities such as data integrity risks, unauthorized device control, and denial-of-service attacks across various DER technologies like solar PV, wind turbines, energy storage systems, and hydrogen fuel cells. The report proposes a harmonization strategy to address these deficiencies by developing unified cybersecurity requirements, certification programs, and training resources while fostering collaboration among stakeholders such as government agencies, industry groups, DER operators, manufacturers, and research institutions. A phased roadmap is outlined to refine and implement these measures through pilot testing and widespread adoption. Ultimately, the report underscores the urgent need for coordinated efforts to enhance DER cybersecurity and ensure the reliable operation of future energy systems.

29 ENERGY PLANNING, POLICY, AND ECONOMY

Peer-to-peer communication control for resilient operations of networked cyberphysical systems

This report includes two main accomplishments of the peer-to-peer communication control for resilient operation of networked microgrids project in FY24, which include a scheme for cyberattack-aware coordination of networked microgrids for supporting voltages of bulk power systems and a scheme for price signal-based operations of EV-rich networked microgrids with mixed ownership. First, the cyberattack-aware scheme enables networked microgrids to distributedly determine the amount of reactive power injection to support the voltage of bulk power system (BPS) in a fair manner. In this scheme, a risk-informed algorithm is presented to generate the peer-to- peer (P2P) communication graph with minimal risk of attack on communication links. To deal with cyberattacks on MG controllers, the resilient consensus algorithm (CA) is utilized for MG controllers to robustly estimate the total reactive power headroom, from which the MGs can accurately provide the needed amount of reactive power injection for supporting the voltage of BPS. The CA implementation and performance within the P2P communication framework are demonstrated on the IEEE 39-bus system with 6 microgrids contained in the distribution feeder under different cyberattack scenarios. Second, the price-based scheme enables the usage of the real-time price signal for the operations of electric vehicle (EV)-rich networked-microgrids with mixed ownership, in which not all the microgrids can communicate with the distribution system operator (DSO). In this scheme, a max consensus is introduced to enable the real-time price signal to be propagated from the DSO to all the microgrids, from which each microgrid controller will manage the DERs to balance the load demand and the power injection from the EV charging stations within its microgrid. Numerical results over one day with 288 slots of 5-minute intervals on the modified 123-node test feeder including 3 microgrids with high penetration of EV are presented to evaluate how the price signal affects the operations of networked microgrids under different charging strategies of the EV charging stations. The result indicates that our proposed EVCS (dis)charging strategy, which leverages the flexibility of EVs to support the grid through discharging during peak demand, proves to be a cost-effective solution that reduces operational costs while improving the social welfare of EV charging.

24 POWER TRANSMISSION AND DISTRIBUTION

Watching for light: An enterprise roadmap for trustworthy laser threat warning (LTW) to protect national assets

Comprehensive space force protection must include effective and trustworthy laser threat warning (LTW). Effective LTW will detect and characterize threats to space assets and thus enhance space deterrence. LTW must be trustworthy: able to categorize threats and non-threats by being both sensitive to true events and resistant to false alarms. Outside of the laboratory, the statistics and even the roles of lasers become unclear. In the chain of events leading to an attack, the laser may be the last link to be understood. Human situational awareness and informal reasoning must blend statistics with circumstantial evidence to visualize these chains before they are clear. This paper sets out an industrial model for an enterprise that will routinely produce trustworthy LTW. By incorporating psychology and economics, this enterprise can overcome the difficulties and perils of cooperation in networked defense and intelligence. This roadmap suggests how the enterprise can incentivize distracted actors with different goals to share what they know and coordinate what they do.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF