Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “cyber spoofing”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

Cyber Spoofing Detection for Grid Distributed Synchrophasor Using Dynamic dual-Kernel SVM

Cyber spoofing with distributed synchrophasor adversely affects the decision-making and situational awareness of the power grid. To detect the spoofing trail, this letter proposes a composite signature-based cyber spoofing detection methodology. The intrinsic principal modes are first extracted from the distributed synchrophasor data. Then, multiple signatures of different intrinsic model components are derived to quantify the spoofing. Thereafter, the dynamic dual-kernel support vector machine is proposed to identify cyber spoofing using multiple signatures. Multiple experimental results using six spoofing methods have verified the validity of the methodology.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Time-frequency based cyber security defense of wide-area control system for fast frequency reserve

Global power systems are transiting from conventional fossil fuel energy to renewable energies due to their environmental benefits. The increasing penetration of renewable energies presents challenges for power system operation. The efficiency and sufficiency of responsive reserves have become increasingly important for power systems with a high proportion of renewable energies. The Fast Frequency Reserve (FFR), especially the Wide-area Monitoring System (WAMS)-based FFR, is a promising and effective solution to secure and enhance the stability of power systems. However, cyber security has become a new challenge for the WAMS-based FFR system. Cyber attacks on the FFR control system may threaten the safety of power system operation due to the rapid power controllability requirement of FFR. Therefore, to address this problem, a time-frequency based cyber security defense framework is proposed to detect the cyber spoofing of synchrophasor data in WAMS-based FFR control systems. This paper first introduces the Continuous Wavelet Transforms (CWTs) to decompose spoofing signals. Then, the Dual-frequency Scale Convolutional Neural Networks (DSCNN) is proposed to identify the time-frequency domains matrix from two frequency scales. Integrating CWTs and DSCNN, an identification framework called CWTs-DSCNN is further proposed to detect the spoofing attacks in the WAMS-based FFR system. Multiple experiments using the actual data from FNET/GridEye are performed to verify the effectiveness of the framework in securing WAMS-based FFR systems.

25 ENERGY STORAGE↗

Proactive Intrusion Detection and Mitigation System

SAND2023-05661O The proactive intrusion detection and mitigation system (PIDMS) provides grid-edge situational awareness for cybersecurity defense by capturing real-time distributed energy resource (DER) network traffic and performance data with a novel approach that improves the detection and prevention of cyber-physical attacks. The PIDMS addresses the grid-edge security gap with real-time analysis of both network traffic and photovoltaic performance data to deliver a novel, cyber-physical intrusion detection system (IDS) approach that increases the accuracy and effectiveness of detection and mitigation. This hybrid IDS analysis enables dual monitoring that increases the workload of the adversary; both cyber and physical data would have to be simultaneously spoofed to evade detection. Furthermore, monitoring and analyzing cyber data are insufficient in some cases. For example, in an insider threat aimed at disrupting inverter grid-support functions where proper credentials and authentication are achieved, only the altered PV performance would indicate abnormal behavior. All in all, the PIDMS provides novel capabilities for: • Distributed, real-time cyber-physical detection and mitigation analysis • Cybersecurity defense for grid-edge systems • Analysis framework that can provide situational awareness across the transmission, distribution, and DER systems The PIDMS sensor is designed to collect cyber-physical data, process the data using machine-learning algorithms, detect abnormal events, and deploy mitigations. With these goals, the main functional PIDMS objectives are: • Capability to collect cyber-physical data • Onboard storage of cyber-physical data • Peer-to-peer communication • Computationally efficient machine-learning algorithms • Online cyber-physical data analysis • Alerting/visualization capabilities • Mitigation deployment capability with bump-in-the-wire (BITW) implementation Each of these functional objectives enable PIDMS to perform effective cyber-physical intrusion detection and mitigation. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Jones, Christian↗

Data Security Defense: Modeling and Detection of Synchrophasor Data Spoofing Attack for Grid Edge

Data security and cyberattack have become critical issues in the distributed power system where adversaries can swap the source information of sensors or even spoof and alter measurements. However, the cyber security of the power system is challenged by the unpredictability and stealth of the spoofing attacks. Here, to protect the data security at the grid edge, this paper developed a synchrophasor data spoofing attack detection framework based on the time-frequency feature extraction techniques including the short-time Fourier transform (STFT) and object detection network for real-time synchrophasor data categorization and spoofing attack localization. The proposed approach outperforms earlier work in terms of spoofing attack detection and offers a vital localization function employing distributed synchrophasor sensors.

24 POWER TRANSMISSION AND DISTRIBUTION↗

An Active Detection Scheme for Sensor Spoofing in Grid-tied PV Systems

In this paper an active detection scheme for sensor spoofing (manipulated externally via a cyber attack) in grid-tied PV systems is discussed. The core of the proposed active detection scheme is to introduce a private (secret) watermarking signal into the control inputs of the DC-DC converter and DC-AC inverter stages to detect any malicious spoofing (manipulation) of voltage/current sensor measurements controlling both the DC-DC converter maximum power point tracking (MPPT) stage and the DC-AC inverter of the grid-tied PV system. Several types of possible spoofing mechanisms (attack models) are discussed. The proposed sensor spoofing attack detector system consists of injecting a small magnitude of digital watermarking signal (DWS) and conduct three statistical watermark tests on the reported sensor measurements to determine if a) the proposed system is healthy and operating as expected b) if sensor signals were spoofed (manipulated) externally or c) if a particular sensor is malfunctioning due to a faulty hardware. It is shown via extensive simulations that the proposed DWS approach is robust in detecting malicious external manipulation of sensors controlling the grid tied PV system. A testing platform is currently under development and the experimental results will be discussed in the conference presentation.

Ibrahim, Hasan↗

Synchrophasor spoofing detection and remediation for wide-area damping control

Evolving cyber-attack threats put at risk automatic closed-loop systems to be incorporated in the smart grid. Wide-area control systems are particularly vulnerable to signal spoofing attacks due to sensor remoteness and dependence on satellite communication for time synchronization. A successful cyber-attack on a wide-area controller has the potential to reduce relative stability of the power system or worse, destabilize it. As such, detection algorithms must be deployed as defense against such attacks with the ability to autonomously correct for detected tampering or misoperation. The Spoof Catch and Restore Routine (SCR 2 ), a combination of three real-time spoof detectors, each requiring limited information about the plant, is reported here. Nonlinear simulations of a compromised wide-area control system deployed in the Western Interconnection show the effectiveness of SCR 2 in detecting both delay-type and counterfeit-type spoofing attacks on wide-area sensors.

42 ENGINEERING↗

Multifractal Characterization of Distribution Synchrophasors for Cybersecurity Defense of Smart Grids

“Source ID Mix” spoofing emerged as a new type of cyber-attack on Distribution Synchrophasors (DS) where adversaries have the capability to swap the source information of DS without changing the measurement values. Accurate detection of such a highly-deceptive attack is a challenging task especially when the spoofing attack happens on short fragments of DS recorded within a relatively small geographical scale. Herein this letter proposes an effective approach to detect this cyber-attack by realizing the multifractal characteristics of DS measurements. First, the multifractal cross-correlation of DS measured at multiple intra-state locations is revealed. Then the derived correlation is integrated with weighted two-dimensional multifractal surface interpolation to reconstruct quasi high-resolution signals. Finally, informative location-specific signatures are extracted from the high-resolution DS and they are integrated with advanced machine learning techniques for source authentication. Experiments using the real-life DS are performed to verify the proposed method.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Use of Legacy Maritime Protocols Increases Exploitability of Virtual Aids to Navigation

With increased reliance on Virtual Aid(s) to Navigation (VAtoN) - also known as electronic Aid(s) to Navigation (eAtoN), or virtual buoys - a cyber event is likely to cause disruption to international maritime shipping. VAtoN has no physical hardware for visual reference and displays only on a vessel’s Electronic Chart Display Information System (ECDIS) and Automatic Radar Plotting Aid (ARPA); therefore, mariners must rely on the accuracy of the information provided. As VAtoN uses the National Maritime Electronics Association (NMEA) 0183 protocol for both Global Navigation Satellite System (GNSS) and Automatic Identification System (AIS), an insecure protocol that has been proven susceptible to spoofing, denial, and manipulation, the likelihood of a cyber-related event increases substantially.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Data Centers and Digital Assurance Introduction to Supply Chain and Cybersecurity for Data Centers, Session 1

The first session of the TADA (Technical Assistance for Digital Assurance) Data Centers Cohort Workshop, held on October 30, 2025, introduced foundational concepts of Digital Assurance in the context of data center and grid integration. Sponsored by the U.S. Department of Energy, the workshop brought together utilities, data center operators, developers, and vendors to address cybersecurity and supply chain vulnerabilities. The session emphasized the growing criticality of data centers within the electric grid and the need for secure, real-time, bidirectional communication. Participants explored the principles of Digital Assurance, including cybersecurity, cyber-informed engineering (CIE), and lifecycle security, and applied a threat-vulnerability-consequence framework to identify and mitigate risks at the data center–grid interface. Discussions covered a range of threats such as spoofed dispatch signals and insider threats, architectural vulnerabilities like SCADA interfaces and insecure protocols, and potential consequences including cascading grid failures. The session also raised strategic questions about business value, vendor assurance, and defining cyber boundaries and responsibilities. This foundational workshop set the stage for deeper technical analysis and the development of actionable frameworks in subsequent sessions. Session 1 of 3.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Impact of cyberattacks on safety and stability of connected and automated vehicle platoons under lane changes

Connected and automated vehicles (CAVs) offer a huge potential to improve the operations and safety of transportation systems. However, the use of smart devices and communications in CAVs introduce new risks. CAVs would leverage vehicle to vehicle (V2V) and vehicle to infrastructure (V2I) communication, thus providing additional system access points compared to traditional systems. Automation makes these systems more vulnerable and increases the consequences of cyberattacks. This study utilizes an infrastructure-based communication platform consisting of cooperative adaptive cruise control and lane control advisories developed by the authors to perform cyber risk assessment of CAVs. The study emulates three types of cyberattacks (message falsification, dedicated denial of service, and spoofing attacks) in a representative traffic environment consisting of multiple CAV platoons and lane change events to analyze the safety and stability impacts of the cyberattacks. Simulation experiments using VISSIM reveals that traffic stream and CAV string is unstable under all three types of cyberattacks. The worst case is represented by the message falsification attack. Increases in volatility are observed over a no attack case, with variations increasing by an average of 43%–51% along with an increase of over 3000 crash conflicts. Similarly, lane change crash conflicts are observed to be more severe compared to rear end crash conflicts, showing a higher probability of severe injuries. Further, the case of slight cyberattack on a single CAV also creates significant disruption in the traffic stream. Analysis of variance (ANOVA) reveals the statistical significance of the results. Furthermore, these results pave the way for future design of secure systems from a monitoring perspective.

97 MATHEMATICS AND COMPUTING↗

CONTROL AND DATA ACQUISITION IN A CYBER-PHYSICAL MIDSTREAM TESTBED

This thesis presents the development of a laboratory-scale cyber–physical midstream pipeline testbed designed to address this gap and support research in industrial control systems security. The platform integrates pumps, valves, sensors, programmable logic controllers (PLCs), and a human–machine interface (HMI) to emulate the monitoring and control architecture of real pipeline operations. The physical process is implemented as a closed-loop liquid circulation system designed to replicate flow behavior characteristic of midstream pipeline infrastructure. The testbed enables real-time data acquisition of key process variables, including flow rate and pressure facilitating the generation of datasets representative of normal pipeline operation. A threat model encompassing common ICS attack vectors was developed, including sensor spoofing, command injection, false data injection, denial-of-service attacks, and relay manipulation. Multiple attack scenarios were implemented and evaluated to demonstrate how cyber intrusions targeting sensors, actuators, networks, and software propagate into measurable physical consequences in pipeline flow and pressure. The developed platform serves as a practical, cost-effective environment for experimentation, education, and future cybersecurity research in midstream pipeline systems.

42 ENGINEERING↗

Edge ML for CAN bus intrusion detection in AVs

Autonomous Vehicles (AVs) are revolutionizing transportation, but their reliance on interconnected cyber-physical systems exposes them to unprecedented cybersecurity risks. This study addresses the critical challenge of detecting real-time cyber intrusions in self-driving vehicles by leveraging a dataset from the Udacity self-driving car project. We simulate four high-impact attack vectors, Denial of Service (DoS), spoofing, replay, and fuzzy attacks, by injecting noise into spatial features (e.g., bounding box coordinates) to replicate adversarial scenarios. We develop and evaluate two lightweight neural network architectures (NN-1 and NN-2) alongside a logistic regression baseline (LG-1) for intrusion detection. The models achieve exceptional performance, with NN-2 attaining an AUC score of 93.15% and 93.15% accuracy, demonstrating their suitability for edge deployment in AV environments. Through explainable AI techniques, we uncover unique forensic fingerprints of each attack type, such as spatial corruption in fuzzy attacks and temporal anomalies in replay attacks, offering actionable insights for feature engineering and proactive defense. Visual analytics, including confusion matrices, ROC curves, and feature importance plots, validate the models' robustness and interpretability. This research sets a new benchmark for AV cybersecurity, delivering a scalable, field-ready toolkit for Original Equipment Manufacturers (OEMs) and policymakers. By aligning intrusion fingerprints with SAE J3061 automotive security standards, we provide a pathway for integrating machine learning into safety-critical AV systems. Our findings underscore the urgent need for security-by-design AI, ensuring that AVs not only drive autonomously but also defend autonomously. This work bridges the gap between theoretical cybersecurity and life-preserving engineering, offering a leap toward safer, more secure autonomous transportation.

97 MATHEMATICS AND COMPUTING↗

Cybersecurity Certification Recommendations for Interconnected Grid Edge Devices and Inverter Based Resources

Escalating deployment of PV and grid-edge devices on the distribution grid has increased the sustainability and efficiency of the electric grid. However, the increasing number of distributed energy resources (DERs) deployed creates a heightened cyber-physical interdependency on the distribution grid and thus creates more vectors for cyber-attacks to exploit through information and communication technology (ICT) systems and networks. For example, control signal packets can be modified, intercepted, or corrupted due to vulnerabilities in communication protocols used by microgrid controllers and grid edge devices for power control. Therefore, to mitigate and prevent cyber-attacks on grid edge devices and the inverter-based resources connected to the distribution grid, the U.S. Department of Solar Energy Technologies Office (SETO) awarded funding to the National Renewable Energy Laboratory and Sandia National Laboratory (SNL) to research, develop, and harmonize cybersecurity standards for Photovoltaic (PV) systems and for other kinds of DERs. To help develop a standard for DER cybersecurity, NREL established certification recommendations and test cases, in consensus with the solar industry and UL, for ensuring intrinsic design security for DERs. These recommendations were developed to bolster the cybersecure functionalities such as TLS, MAC, CRL, session resumption/renegotiation, and password, system, and service security management within the DER devices. The proposed test cases verify authentication, authorization, confidentiality, and data integrity for data and communications of DERs that use Transmission Control Protocol/Internet Protocol (TCP/IP). They were also developed to protect DER communications from eavesdropping, replay, man-in-the-middle, denial of service (DoS), spoofing through security certificates, least-privilege violation, and brute-force credentials. This report, which has been validated and reviewed by UL, expands upon those test cases to provide DER cybersecurity certification recommendations which increase DER resiliency and help to mitigate cyber-attacks. UL's collaboration with NREL and approval of this document will accelerate the adoption of a UL standard for DER cybersecurity.

24 POWER TRANSMISSION AND DISTRIBUTION↗

PUF-Based Two-Factor Authentication Protocol for Securing the Power Grid Against Insider Threat

Recent advances in smart grid technologies have enabled additional distributed control paradigms that allow more efficient and reliable operation. However, this creates new security concerns for the grid, such as attackers using spoofed grid control devices to generate false measurements. This paper introduces a two-factor authentication protocol leveraging standard public-key cryptography as one authentication factor and a hardware-based fingerprint, known as a Physical Unclonable Function, as a second authentication factor. This protocol incurs a small overhead and prevents cyber-attacks even when an adversary is able to compromise the cryptographic keys stored in the non-volatile memory of an intelligent control device.

42 ENGINEERING↗

Supporting Cyber Security of Power Distribution Systems by Detecting Differences Between Real-time Micro-Synchrophasor Measurements and Cyber-Reported SCADA (Final Report)

As modern power grids tend towards greater levels of automation and communication, the challenges of identifying and mitigating vulnerabilities to cyber-attacks are ones that are increasingly demanding attention. Today’s power system has evolved to form the foundational bedrock of modern society, and an attack on this infrastructure could prove disastrous. In this project we were tasked to investigate the use of distribution synchrophasors as an independent isolated sensor network with which we can corroborate, or flag potentially spoofed,Supervisory Control And Data Acquisition (SCADA) data. We adapted an approach to marry the underlying physical properties of power systems with the network communications used by power systems in order to offer insights unattainable by either data stream isolation. While the concept of intrusion detection systems (IDS) is well understood for monitoring network traffic and traditional IT computing systems, the approach discussed in this report is motivated by several key notions: first, current SCADA communications alone presents an incomplete view of the grid. Second, the power grid, and the equipment controlling it, is grounded by laws of physics. Given this, we leverage high-frequency physical grid measurements to understand the physical condition of the grid, and combine this with SCADA. While high-frequency physical grid measurements and SCADA communication over Internet Protocol (IP) networks are fundamentally disparate information sources, when collectively examined through appropriate lenses, they offer a much more nuanced depiction of the grid.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Estimation of the time for steam generator trip due to cyber intrusions

The time required to trip a pressurized water reactor (PWR) by inserting malicious signals into its steam generator (SG) control system has been studied using the Generic PWR (GPWR) Simulator. A semi-analytical model is developed to approximately reproduce the simulator response and understand the dynamics of the control unit. A series of two proportional-integral controllers determines control action according to preset constants, the readings from the feedwater level sensor, and those from feedwater and steam flowrate transmitters. It is observed that the most important factor that determines whether a trip will occur is how much additional water is added to or withheld from the SG over time compared to normal operating conditions. In order to determine the effects of control action on the SG, changes in mass inventory are considered. This approach models the SG water level as a function of mass inventory and has a backward temporal memory. A Python interface is developed for the GPWR framework to automatically simulate different spoofing scenarios and post-process the related data. We observe that the trip times predominantly depend on flow mismatch and/or level errors. Controller parameters, including the integral time and gain constants, either speed up or slow down the rate of progression to a trip setpoint but do not cause a trip by themselves. The reactor can trip on a high-level signal when the reading crosses above 78%, increased from its reference level of 57%, or a low-level reading when it is below 25%. The present results show roughly how long the operators would have to respond to an attack, given a specific set of spoofing signals within the issue space analyzed. Furthermore, we have generated a simple surface by fitting a combination of exponential functions to the data obtained from the GPWR Simulator. In general, trips on a low level have been observed to occur faster than those on a high level.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Cyber Resilience in the Cast Timing System

Our task within the DarkNet project was to test the cyber resiliency of the Center for Alternate Synchronization and Timing’s (CAST) framework. We focused our testing on two of the core pieces of CAST’s implementation, a Juniper MX204 router and the Precision Time Protocol (PTP). In this report, we cover the following attempted methods of attack on our targets: ping flood, fork bomb, network protocol fuzzing, ARP poisoning, and IGMP spoofing. We found that delaying certain packets, specifically Delay Request, had a significant impact on the Offset from Master and Observed Drift timing statistics.

97 MATHEMATICS AND COMPUTING↗