Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “digital substation”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Zero-day Attack Detection in Digital Substations Using In-Context Learning

In this paper, we address the critical challenge of detecting zero-day attacks in digital substations that employ the IEC-61850 communication protocol to ensure the security and reliability of modern power systems. While many heuristic and machine learning (ML)-based methods have been proposed for attack detection in IEC-61850 digital substations, generalization to unknown or zero-day attacks remains a challenge. We propose an approach that leverages the in-context learning ability of transformer architecture, which enables the model to learn from a few examples of a new task without explicit retraining. Our experiments on the IEC-61850 dataset demonstrate that the proposed method achieves more than 87% detection accuracy on zero-day attacks while the existing baselines fail. We believe this work has the potential to enhance the security of digital substations by enabling the effective detection of zero-day attacks.

LIu, Chen-Ching [Virginia Tech] (ORCID:00000002894↗

Ransomware Attack Modeling and Artificial Intelligence-Based Ransomware Detection for Digital Substations

Ransomware has become a serious threat to the current computing world, requiring immediate attention to prevent it. Ransomware attacks can also have disruptive impacts on operation of smart grids including digital substations. This paper provides a ransomware attack modeling method targeting disruptive operation of a digital substation and investigates an artificial intelligence (AI)-based ransomware detection approach. The proposed ransomware file detection model is designed by a convolutional neural network (CNN) using 2-D grayscale image files converted from binary files. Here, the experimental results show that the proposed method achieves 96.22% of ransomware detection accuracy.

artificial intelligence↗

SDN-Based Smart Cyber Switching (SCS) for Cyber Restoration of a Digital Substation

In recent years, critical infrastructure and power grids have increasingly been targets of cyber-attacks, causing widespread and extended blackouts. Digital substations are particularly vulnerable to such cyber incursions, jeopardizing grid stability. This paper addresses these risks by proposing a cybersecurity framework that leverages software-defined networking (SDN) to bolster the resilience of substations based on the IEC- 61850 standard. The research introduces a strategy involving smart cyber switching (SCS) for mitigation and concurrent intelligent electronic device (CIED) for restoration, ensuring ongoing operational integrity and cybersecurity within a substation. The SCS framework improves the physical network’s behavior (i.e., leveraging commercial SDN capabilities) by incorporating an adaptive port controller (APC) module for dynamic port management and an intrusion detection system (IDS) to detect and counteract malicious IEC-61850-based sampled value (SV) and generic object-oriented system event (GOOSE) messages within the substation’s communication network. The framework’s effectiveness is validated through comprehensive simulations and a hardware-in-the-loop (HIL) testbed, demonstrating its ability to sustain substation operations during cyber-attacks and significantly improve the overall resilience of the power grid.

Liu, Chen-Ching (ORCID:0000000289417958)↗

Cybersecurity Enhancement in Digital Substations: Hidden Markov Model-Based Smart Cyber Switching and Threat Response

The rising incidence of cyber-attacks on critical infrastructure and power grids poses significant threats to the stability and reliability of electrical substations, with potentially devastating consequences such as extended blackouts. This paper introduces an advanced cybersecurity framework aimed at safeguarding IEC 61850-based substations through the integration of software-defined networking (SDN) and digital twin (DT) technologies. The proposed DT-based framework employs smart cyber switching (SCS) for proactive threat mitigation and concurrent intelligent electronic device (CIED) for swift system restoration, thereby maintaining continuous operational integrity and robust cybersecurity defenses. Central to this framework is the adaptive port controller (APC), which enables dynamic port management to adapt to evolving threats, and an intrusion detection system (IDS) designed to detect and neutralize malicious attacks on IEC 61850-based sampled value (SV) and generic object-oriented substation event (GOOSE) messages within the substation’s communication network. Further, novel predictive intrusion detection and response (PIDR) algorithm is implemented on a digital substation (DS) to predict the best route to be taken by the attacker. The efficacy of these comprehensive cybersecurity frameworks is validated through rigorous simulations and a hardware-in-the-loop (HIL) testbed, showcasing the system’s ability to sustain substation operations amidst cyber-attacks.

Digital substation↗

SDN-Based Dynamic Cybersecurity Framework of IEC-61850 Communications in Smart Grid

In recent years, critical infrastructure and power grids have experienced a series of cyber-attacks, leading to temporary, widespread blackouts of considerable magnitude. Since most substations are unmanned and have limited physical security protection, cyber breaches into power grid substations present a risk. Nowadays, the susceptibility of SDN architecture to cyber-attacks has exhibited a notable increase in recent years, as indicated by research findings. This suggests a growing concern regarding the potential for cybersecurity breaches within the SDN framework. In this paper, we propose a hybrid intrusion detection system (IDS)-integrated SDN architecture for detecting and preventing the injection of malicious IEC 61850-based generic object-oriented system event (GOOSE) messages in a digital substation. Additionally, this program locates the fault’s location and, as a form of mitigation, disables a certain port. Furthermore, implementation examples are demonstrated and verified using a hardware-in-the-loop (HIL) testbed that mimics the functioning of a digital substation.

Liu, Chen-Ching [Virginia Tech] (ORCID:00000002894↗

ChatGPT and Other Large Language Models for Cybersecurity of Smart Grid Applications

Cybersecurity breaches targeting electrical substations constitute a significant threat to the integrity of the power grid, necessitating comprehensive defense and mitigation strategies. Any anomaly in information and communication technology (ICT) should be detected for secure communications between devices in digital substations. This paper proposes large language models (LLMs), e.g., ChatGPT, for the cybersecurity of IEC 61850-based communications. Multi-cast messages such as generic object oriented system events (GOOSE) and sampled values (SV) are used for case studies. The proposed LLM-based cybersecurity framework includes, for the first time, data pre-processing of communication systems and human-in-the-loop (HITL) training (considering the cybersecurity guidelines recommended by humans). The results show a comparative analysis of detected anomaly data carried out based on the performance evaluation metrics for different LLMs. A hardware-in-the-loop (HIL) testbed is used to generate and extract a dataset of IEC 61850 communications.

ChatGPT↗

SmallTAL: Real-Time Egocentric Online Temporal Action Localization for the Data-Impoverished

Abstract We propose a real-time, online temporal action localization system that requires a small amount of annotated data. The main challenges we address are high intra-class variability and a large and diverse background class. We address these using a flexible frame descriptor, dynamic time warping, and a novel approach to database construction. Our solution receives egocentric RGB-D streams as input and makes predictions at regular temporal intervals. We validate our approach by localizing actions in a digital twin of an electrical substation, in which certain objects have been replaced by functional virtual replicas.

Computer Science↗

CPS Testbed Architectures for WAMPAC using Industrial Substation and Control Center Platforms and Attack-Defense Evaluation

Advanced persistent threats and cyberattacks can impact wide-area monitoring, protection, and control (WAMPAC) system operation. Many cyber-physical system (CPS) testbeds have been developed for attack-defense experimentation and attack-resiliency tools evaluation for WAMPAC, but they are limited to a simulation-and-emulation based environment. This paper presents a quasi-realistic CPS attack-defense testbed-based framework for WAMPAC applications using the industrial substation and control center platforms such as eTerra integrated with the hardware-in-the-loop CPS smart grid testbed available at Iowa State University. The proposed framework includes various combinations of industry-grade substation and control center platforms, communication topologies, real-time digital simulators, and a novel cyber-physical distributed intrusion-and-anomaly detection system (D-IADS) for WAMPAC applications. The D-IADS includes a master at the control center and geographically distributed sensor devices at each substation. Each D-IADS sensor deployed at a substation or control center network monitors ingress and egress traffic, detect intrusions, and dispatch alerts to the D-IADS master. The D-IADS master centrally monitors and analyze the alerts and controls D-IADS sensors. We considered an EMP60 synthetic CPS grid as a case study to demonstrate the framework and proposed D-IADS for WAMPAC applications against cyberattack vectors such as Man-in-the-Middle DNP3 attack, denial-of-service, and data-integrity attacks.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Hardware-based Advanced Electromagnetic Transient Simulation for A Large-Scale PV Plant in Real Time Digital Simulator

Power electronics-based resources, such as high-voltage direct current (HVdc) substations, photovoltaic (PV) plants, wind plants, electric vehicle charging stations, and energy storage systems, are increasingly being integrated within the power grid. Recently, multiple reports have emphasized the necessity for high-fidelity electromagnetic transient (EMT) simulations of these large-scale power electronics-based resources to accurately understand their behavior in power grids. However, performing hardware-based EMT simulations with high-fidelity models for such large power electronics systems is challenging due to the small time-step requirements and the involvement of a large number of states. This paper presents the implementation of hardware-based high-fidelity EMT dynamic model of a large-scale PV plant, accomplished through custom model development using the specific-C language in real-time digital simulator hardware (RTDS) and software (RSCAD).

Choi, Jongchan↗

Random Forest Regressor-Based Approach for Detecting Fault Location and Duration in Power Systems

Power system failures or outages due to short-circuits or “faults” can result in long service interruptions leading to significant socio-economic consequences. It is critical for electrical utilities to quickly ascertain fault characteristics, including location, type, and duration, to reduce the service time of an outage. Existing fault detection mechanisms (relays and digital fault recorders) are slow to communicate the fault characteristics upstream to the substations and control centers for action to be taken quickly. Fortunately, due to availability of high-resolution phasor measurement units (PMUs), more event-driven solutions can be captured in real time. In this paper, we propose a data-driven approach for determining fault characteristics using samples of fault trajectories. A random forest regressor (RFR)-based model is used to detect real-time fault location and its duration simultaneously. This model is based on combining multiple uncorrelated trees with state-of-the-art boosting and aggregating techniques in order to obtain robust generalizations and greater accuracy without overfitting or underfitting. Four cases were studied to evaluate the performance of RFR: 1. Detecting fault location (case 1), 2. Predicting fault duration (case 2), 3. Handling missing data (case 3), and 4. Identifying fault location and length in a real-time streaming environment (case 4). A comparative analysis was conducted between the RFR algorithm and state-of-the-art models, including deep neural network, Hoeffding tree, neural network, support vector machine, decision tree, naive Bayesian, and K-nearest neighborhood. Experiments revealed that RFR consistently outperformed the other models in detection accuracy, prediction error, and processing time.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Use of Machine Learning on PMU Data for Transmission System Fault Analysis

Synchrophasor technology has been used for monitoring, control, and protection of bulk power system for over 10 years. Deployment of phasor measurement units (PMUs) in the USA power system has surpassed 3000 units installed in the transmission substations as stand-alone intelligent electronic devices (IEDs) or as a software add-on to other devices such as digital protective relays (DPRs) or digital fault recorders (DFRs). By now, thousands of terabytes of PMU data may have been captured and stored by various transmission system operators (TSOs) and independent system operators (ISOs). This creates an opportunity to deploy advanced machine learning (ML) techniques to detect and classify faults recorded by PMUs automatically to be used by the system operators for rapid, critical decision-making when manual analysis of the past or unfolding events is not feasible. In this paper we offer a brief background on how the automated fault analysis may be done using DPR and/or DFR data, and compare some of the legacy approaches to the new ML approaches in the context of the system-wide PMU recordings. We then offer insights from developing practical ML solutions that have been applied on field recordings captured by close to 450 PMUs from all three US interconnections (Western, Eastern and ERCOT) over two years (2016-2017). We identify and illustrate ML challenges we addressed: inaccurate data, data with scarce and temporally imprecise fault labels, data recorded by PMUs sparsely located at substations resulting in the fault records taken afar from the ends of the faulted lines, data containing only positive sequence values, and data taken at different voltage levels. We then illustrate the ML model results for fault analysis under different application scenarios. The novelty of this study is not only in the design, implementation, and performance analysis of the ML algorithms, but also in the use of advanced fault modelling and simulation approaches to improve the training results when developing supervised ML models for fault detection and classification. Extensive simulations of faults were conducted on a 14-bus power system to create a training dataset with over 1400 accurately labelled faults. This dataset was applied to enhance the accuracy of fault detection and classification of machine learning-based models trained with small number of labelled faults in large datasets recorded in the grid interconnections ranging from 5,000 to 70,000 buses.

Synchrophasors, Machine Learning, Fault Analysis, ↗

Equipment Self-Assessment Guide Checklist

This Equipment Self-Assessment Checklist is designed for asset owners and operators (AOOs) responsible for the deployment, operation, maintenance, or cybersecurity oversight of grid systems and digital energy technologies. It provides a structured inspection checklist for evaluating the security, integrity, and operational trustworthiness of equipment across substations, generation sites, distributed energy resources (DERs), and control environments.

32 - ENERGY CONSERVATION, CONSUMPTION, AND UTILIZA↗

Digital Assurance for Grid Reliability in the Era of Large Load Growth

The rapid expansion of large electric loads is reshaping the operational and regulatory landscape of the U.S. electric grid. These facilities are reaching new scales of expansion, now exceeding a gigawatt per site, and their highly sensitive, digitally driven behaviors introduce new reliability risks. Recent grid events, including large load losses following routine transmission disturbances, highlight the consequences of limited ride-through capability, inconsistent protection settings, inadequate modeling, and lack of behind-the-meter visibility. Parallels to earlier integration challenges of new grid technologies suggest that the grid’s existing processes, standards, and interconnection frameworks are no longer adequate for emerging large loads. This brief synthesizes lessons from the evolution of inverter-based resource regulation and applies them to large-load integration. It identifies critical gaps in modeling accuracy, interconnection processes, performance standards, and compliance mechanisms. Technical recommendations emphasize advanced monitoring, improved modeling, coordinated communication protocols, modernized substations, and structured behind-the-meter control schemes. Collectively, these measures provide a roadmap to maintain bulk power system reliability while enabling the continued growth of large, electrified digital infrastructure.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Real-Time Testbed for Transmission Line Protection

Hardware in the loop (HIL) testing is crucial for designing and managing electric power grids. These grids are becoming larger and more complex. The importance for students to have safe and intuitive ways to interact with the devices associated with the power grids has never been more crucial. Since most of these tests involve high voltages, this can be a deterrent for instructors and students in undergraduate programs. HIL testing is a solution to these common issues. This method has become one of the most popular methods for testing these power systems. With the use of Western Michigan University’s (WMU) Real-Time Digital Simulator (RTDS) and SEL-421-7 protection relay, a HIL testbed has been created. These devices were interconnected using the communication protocol known as Generic Object-Oriented Substation Event (GOOSE). A simulated transmission line system was modeled in an RTDS software RSCAD as the basis for this testbed. This model simulated different types of faults that could occur in a transmission line while in operation. The SEL-421-7 relay is connected to the RSCAD simulation via GOOSE to protect our simulated transmission line. This testbed was set up to give students a clear understanding of how distance protection works as well as how the SEL-421-7 will react to various kinds of faults, in addition to how useful the RTDS can be when testing different power systems.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Achieving American Leadership in the Electric Grid Supply Chain Factsheet

The U.S. electric grid consists of more than 22,000 generators; 55,000 substations; 642,000 miles of high-voltage lines; and 6.3 million miles of distribution lines that serve 153 million customers. To date, much of the smart grid transformation has focused on applying advanced digital information and communication technologies to the power grid to improve the system’s efficiency, flexibility, and security. To achieve the full value of grid modernization, we also need advances in grid hardware. Many critical components supporting the power grid have limited to no domestic manufacturing capacity and face complex challenges in supporting a rapid expansion of the grid to meet multiple objectives, including decarbonization goals.

Source record↗

Black-Starting Microgrids Using Inverter-Based Distributed Energy Resources

Recent trends in power systems show increasing deployment of inverter-based distributed energy resources (DERs) at the distribution level. Efforts have also been made to use inverter-based DERs for system restoration of critical sections of distribution feeders. In the past few years, there has been active consideration of using local grid-forming (GFM) DERs, which can form their own voltage and frequency, to black-start microgrids instead of waiting for the bulk system for supply restoration. However, using current-limited inverter-based DERs for black-start operations with high inrush currents can pose some technical challenges. This paper presents detailed electromagnetic transient studies on a digital real-time simulator to assess the operational feasibility of using local inverter-based GFM DERs for microgrid black-start operations as a bottom-up approach instead of a top-down approach where the substation is used to restore critical sections of the feeder. The paper presents key modeling details for distribution system components for studying GFM DER-based microgrid black-start operations. The paper presents simulation results comparing different black-start approaches using GFM DERs for two test systems: i) a simple test microgrid and ii) a real-world utility microgrid currently being designed and deployed by Holy Cross Energy in Colorado.

black start↗

Multiple-Ring Digital Communication Network

Optical-fiber digital communication network to support data-acquisition and control functions of electric-power-distribution networks. Optical-fiber links of communication network follow power-distribution routes. Since fiber crosses open power switches, communication network includes multiple interconnected loops with occasional spurs. At each intersection node is needed. Nodes of communication network include power-distribution substations and power-controlling units. In addition to serving data acquisition and control functions, each node acts as repeater, passing on messages to next node(s). Multiple-ring communication network operates on new AbNET protocol and features fiber-optic communication.

Kirkham, Harold↗