Engineering PapersSearch

SEARCH · Engineering Papers

Results for “identifying security consequences”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

A Framework for Building Security into the Design Process

This report presents guidance to support the implementation of security objectives during the design process for nuclear facilities using an organization’s quality management system. The guidance in this document is intended for design vendors and operators of nuclear power facilities. Additionally, this guidance document can be beneficial to regulatory bodies, industry partners, customers, and other stakeholders within the nuclear power market. This report aims to ensure security consequences are identified before designs are completed, which may lead to reduced costs and higher security effectiveness and efficiency.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS

A Framework for Building Security into the Design Process

This report presents guidance to support the implementation of security objectives during the design process for nuclear facilities using an organization’s quality management system. The guidance in this document is intended for design vendors and operators of nuclear power facilities. Additionally, this guidance document can be beneficial to regulatory bodies, industry partners, customers, and other stakeholders within the nuclear power market. This report aims to ensure security consequences are identified before designs are completed, which may lead to reduced costs and higher security effectiveness and efficiency.

22 GENERAL STUDIES OF NUCLEAR REACTORS

Data Centers and Digital Assurance Introduction to Supply Chain and Cybersecurity for Data Centers, Session 1

The first session of the TADA (Technical Assistance for Digital Assurance) Data Centers Cohort Workshop, held on October 30, 2025, introduced foundational concepts of Digital Assurance in the context of data center and grid integration. Sponsored by the U.S. Department of Energy, the workshop brought together utilities, data center operators, developers, and vendors to address cybersecurity and supply chain vulnerabilities. The session emphasized the growing criticality of data centers within the electric grid and the need for secure, real-time, bidirectional communication. Participants explored the principles of Digital Assurance, including cybersecurity, cyber-informed engineering (CIE), and lifecycle security, and applied a threat-vulnerability-consequence framework to identify and mitigate risks at the data center–grid interface. Discussions covered a range of threats such as spoofed dispatch signals and insider threats, architectural vulnerabilities like SCADA interfaces and insecure protocols, and potential consequences including cascading grid failures. The session also raised strategic questions about business value, vendor assurance, and defining cyber boundaries and responsibilities. This foundational workshop set the stage for deeper technical analysis and the development of actionable frameworks in subsequent sessions. Session 1 of 3.

24 - POWER TRANSMISSION AND DISTRIBUTION

Explainable Machine Learning for Functional Data

Black-box machine learning models are recognized as useful tools for prediction applications, but the algorithmic complexity of some models causes interpretation challenges. Explainability methods have been proposed to provide insight into these models, but there is little research focused on supervised modeling with functional data inputs. We argue that, especially in applications of high consequence, it is important to explicitly model the functional dependence in a black-box analysis to not obscure or misrepresent patterns in explanations. As such, we propose the V ariable importance E xplainable E lastic S hape A nalysis (VEESA) pipeline for training supervised machine learning models with functional inputs. The pipeline is an analysis process that includes the data preprocessing, modeling, and post-hoc explanations. The preprocessing is done using elastic functional principal components analysis, which accounts for vertical and horizontal variability in functional data and, ultimately, allows for explanations in the original data space that identify the important functional variability without bias due to correlated variables. Here, we demonstrate the pipeline on two high-consequence applications: explosives classification for national security and inkjet printer identification in forensic science. The applications exhibit the VEESA pipeline’s ability to provide an understanding of the characteristics of the functional data useful for prediction. Code for implementing the pipeline is available in the veesa R package (and supplemental python code).

Elastic Shape Analysis

SURVEILLANCE DETECTION FOR TRANSPORTATION OPERATIONS PERSONNEL TO PREVENT HIJACKING, THEFT, SABOTAGE, AND MALICIOUS SECURITY EVENTS DURING TRANSPORTING NUCLEAR MATERIAL

The secure transportation of high-consequence materials, including nuclear and radiological assets, is a critical global priority in the face of escalating terrorism, security threats, and violent protests targeting these operations. Effective surveillance detection—the ability to identify, assess, and respond to potential threats across a continuum of scenarios—is paramount in addressing these challenges. This paper outlines a phased, multi-tiered training program designed to strengthen the surveillance detection capabilities of organizations responsible for nuclear material transport. The proposed training program adopts a progressive approach, gradually increasing in technical complexity to provide participants with comprehensive knowledge and tools for implementing robust security strategies. It targets a wide spectrum of stakeholders, including competent authorities, regulators, inspectors, shippers, carriers, law enforcement, and emergency response personnel, equipping them to plan, evaluate, and safeguard nuclear material transportation effectively. Each phase of the program emphasizes distinct elements of the surveillance detection continuum and transport security, focusing on critical topics such as threat identification, adversary task timelines, protective methodologies, and attack mitigation strategies. The training framework is anchored in technical exchanges and scenario-driven courses that reflect real-world complexities and challenges. By addressing the surveillance detection continuum comprehensively—from early threat assessment to active countermeasures—the program reinforces global efforts to secure nuclear assets. It aligns with international security objectives and fosters a strong security culture within participating organizations, ensuring personnel are prepared to counter potential threats and maintain the safe, secure movement of these materials. Ultimately, this initiative aims to enhance preparedness, security, and response capabilities, supporting the global mission to safeguard high-consequence materials against evolving threats.

Zineddin, Dr. Z. [ORNL] (ORCID:0009000848740725)

Autonomous Fueling System for Heavy-Duty Fuel Cell Electric Trucks

The motivation for this project stemmed from the challenges associated with rapidly refueling heavy-duty hydrogen fuel cell electric trucks (FCETs). Current manual refueling processes for fast refueling involve large, heavy equipment (e.g., hoses three times heavier than standard) and pose ergonomic risks and potential for equipment damage. The goal was to develop and test an autonomous fueling system to improve ergonomics, enhance safety, increase equipment durability through design improvements, and potentially speed up the fueling process. This project aimed to add to the understanding of autonomous systems in the context of heavy-duty hydrogen refueling, evaluating the technical effectiveness of potential concepts. A successfully developed system would benefit the public by facilitating the adoption of zero-emission heavy-duty transport, reducing reliance on manual labor for a physically demanding task, and potentially improving the safety and efficiency of hydrogen refueling infrastructure. The major accomplishment during the project's active period was the completion of the system-level architecture task. This involved establishing a detailed list of system requirements covering interfaces, environmental conditions, regulatory compliance, industry standards, safety, security, performance capabilities, and optional features. Five key use cases for the autonomous system were also identified. However, due to internal restructuring at Nikola, the necessary resources could not be allocated to continue the project. Consequently, Nikola opted to discontinue the project. The award was mutually terminated by Nikola and the DOE.

08 HYDROGEN

Responsible Artificial Intelligence for Insider Threat Mitigation

This report examines the application of artificial intelligence (AI) technologies for insider threat mitigation (ITM) programs in nuclear security facilities. Insider threat detection presents unique challenges due to the subtle and adaptive nature of these threats, the complex signatures involved, and the scarcity of available data for analysis. Traditional human-centered approaches, while essential, face limitations in processing large amounts of data continuously and detecting subtle patterns across multiple systems. AI technologies can potentially address these limitations by providing 24/7 monitoring capabilities, identifying complex patterns that might escape human observation, and offering consistent application of security criteria. However, the deployment of AI in nuclear security contexts introduces significant new risks, including workflow disruption, expanded attack surfaces, potential for misuse, and ethical concerns regarding privacy, fairness, transparency, safety, and security. The high-consequence nature of nuclear security decisions demands careful consideration of these risks and systematic approaches to their mitigation.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF

ARCADE Technical Pathway and Industry Impact

The Advanced Reactor Cyber Analysis and Development Environment (ARCADE) simplifies the evaluation and assessment of robustness factor and cyber resilience that support secure-by-design for advanced reactor nuclear power plants. In this manner, ARCADE supports risk-informed performance based (RIPB) evaluations of cybersecurity through its integration of plant physics with high-fidelity emulations of control systems. This cross domain approach enables comprehensive analysis of control system sensitivities, cyber-attack scenarios, and their consequences. ARCADE has been custom developed to meet the demands identified in Tier 1 of the Tiered Cyber Analysis (TCA) as outlined in NRC Draft Regulation Guide (RG) 5.96, which provides a RIPB cybersecurity approach for new reactors.

97 MATHEMATICS AND COMPUTING

Data Centers and Digital Assurance Workshop 3 – Mitigations for Digital Assurance Risks

The third session of the TADA (Technical Assistance for Digital Assurance) Data Centers Cohort, held on November 18, 2025, focused on developing mitigation strategies for digital assurance risks identified in previous workshops. Hosted by Idaho National Laboratory (INL) and ScottMadden, the session emphasized the application of Cyber-Informed Engineering (CIE) to data center infrastructure, particularly at the utility–data center interface. Participants revisited and ranked key digital assurance risks, including architecture and interface weaknesses, governance gaps, and AI-enabled threats. The workshop introduced the 12 principles of CIE, advocating for consequence-focused design, engineered controls, and secure information architecture to proactively reduce cyber-physical vulnerabilities. These principles were applied to critical data center systems such as power distribution, UPS, cooling, SCADA/BMS, and grid-forming batteries. The session also addressed governance challenges at the interconnection boundary, highlighting the need for clear roles in telemetry sharing, firmware management, and trip settings. Special attention was given to emerging risks from behind-the-meter (BTM) generation, including reverse-power flow and the integration of small modular reactors (SMRs), which shift data centers from large loads to complex generation nodes. Participants explored how interconnection agreements can serve as enforceable instruments for digital assurance, and reviewed gaps in current standards such as NERC CIP, IEC 62443, and IEEE 1547. The workshop concluded with pathways to standardization, including model agreement language, state-level programs, and expanded NERC guidance. INL also presented tools and frameworks for secure procurement and supplier risk management, reinforcing the need for integrated engineering and policy solutions to secure the evolving data center–grid ecosystem. Session 3 of 3.

24 - POWER TRANSMISSION AND DISTRIBUTION

SoK: What does it Mean to Benchmark Database Forensics?

Relational Database Management Systems are the backbone of modern enterprises and public-sector services, and are thus frequent targets of security incidents, insider threats, and thorough regulatory audits. Consequently, databases have become key sources of digital evidence, requiring investigators to reconstruct past activity from audit logs, transaction logs, and backups. Although benchmarking frameworks such as those developed by the Transaction Processing Performance Council (TPC) are widely used to evaluate database performance, they do not capture forensic requirements such as evidentiary completeness, tamper-evidence, chain of custody, or regulatory compliance under GDPR and CCPA. This survey examines the emerging domain of forensic database benchmarking. We gathered prior research on database forensics, secure logging, and tamper-evident data structures; we analyze modern forensic-ready features in commercial and open-source systems (SQL Server Ledger, Oracle Blockchain Tables, PostgreSQL pgAudit, Db2 Audit, Aurora Database Activity Streams, Oracle Real Application Security and IBM Guardium) and assess why existing benchmarks are insufficient. We propose forensic workloads, metrics, and methodologies that incorporate adversarial stressors, deleted-record recovery, and backup analysis. We also identify open research problems and call for a community-driven forensic benchmark suite. The result is an idea for evaluating not only database performance but also forensic soundness, bridging the gap between system engineering, compliance, and digital investigations.

Lenard, Ben

Advanced Reactor Designs Security Analysis, Risk, and Recommendations: Risks, Consequences, and Possible by-Design Mitigation Approaches Associated with Select Advanced Reactors

Next-generation advanced reactors (ARs) incorporate enhanced safety systems, have smaller source terms, and feature compact modular designs, which should lessen their collective risk profiles. However, to fully evaluate risk, security needs to be a part of the equation. Without taking security into consideration, safety systems and components in the new ARs may be vulnerable to sabotage. These base attributes, coupled with enhanced security features specific to AR design through sound engineering and security-by-design (SeBD), should provide developers and operators with lower inherent security risk profiles. Building security early into the AR design may remove or passively secure potential critical targets from an adversary’s reach , thereby increasing overall safety and security. An integrated approach and diverse design team that includes engineering, operations, and security experts are fundamental to building security into the design without sacrificing fundamental operational efficiencies and principles. The objective of this project was to evaluate the security and safety interfaces for five classes of reactors, identify potential security vulnerabilities of structures, systems, and components (SSC), and underscore the need to consider security alongside safety in the design o f these concepts. The five reactor classes evaluated in this project and presented in this report are molten-salt reactors (MSR), high temperature gas reactors (HTGR), sodium-fast reactors (SFR), advanced light-water reactors (ALWR), and microreactors. These designs were selected because they reflect the concepts that are closest to market deployment and have received significant resource investments from the public and private sector. This project assesses the inherent security risks posed by common classes of ARs, provides a methodology and framework to assess security along with safety, and offers an analysis of potential mitigation strategies that could be incorporated. For each AR technology, the SSCs that relate to radionuclide source safety functions are discussed to understand the SSC contribution to safety and relative importance in the protective strategy for the design. The assumptions that went into evaluating each reactor concept originated from generic publicly available nonproprietary information and should not directly be used to qualify an absolute risk profile nor to rank specific AR designs. Instead, the purpose of the analysis is to understand and compare the generic inherent security risks of different AR technologies.

98 - NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL

Energy Leaders: The Catalyst for Strategic Energy Management

This study investigates the crucial role energy leaders play in driving strategic energy management (SEM) and accelerating cost savings within a manufacturing organization and consequently, the industrial sector. Whereas energy efficiency can be seen as an innovative business practice with irrefutable cost benefits, its effective implementation requires strategic leadership and a structured approach. This research analyzes data collected from 120 participants representing 71 companies attending the Energy Bootcamp events organized by the U.S. Department of Energy’s (DOE) Better Plants program. The collected data focused on the state of SEM implementation, the presence and responsibilities of energy leaders, and the formation and function of energy teams. The findings reveal a significant gap between the perceived importance of SEM and its actual adoption, highlighting the need for strong leadership to drive behavioral changes by championing energy efficiency initiatives. Results indicate that effective energy leaders possess a diverse skill set, including the ability to secure top management buy-in, foster a culture of energy consciousness, and collaborate across departments. This study emphasizes the importance of empowering energy leaders with clearly defined roles and responsibilities as well as the authority to build and lead cross-functional energy teams. Furthermore, integrating energy management into existing organizational structures and leveraging readily available resources are identified as key factors for successful implementation. This research underscores how dedicated leadership and effective SEM practices help achieve industrial energy efficiency goals, providing practical insights for organizations seeking to improve performance and contribute to a resilient future.

energy leader

Secure Route: Roadway Risk Mapping for Transportation Planners

The secure transport of sensitive materials across U.S. road networks pose unique challenges for local, state, and federal agencies. Threats range from random events (e.g., accidents, medical emergencies, mechanical failures) to opportunistic or organized tactical assaults. Although the probability of such attacks is very low, the consequences of material loss to foreign states or terrorists can be catastrophic, qualifying these scenarios as “grey swan” events—low-probability, high-impact occurrences that are predictable but difficult to quantify. Traditional risk assessments struggle in these contexts, necessitating a shift toward subjective risk perception to inform planning. Risk perception in transport planning is shaped by various factors, including knowledge of adversarial capabilities, vehicle defenses, manifest details, and geographic features along the route. Geographic features such as bridges, tunnels, roadside elevation, and gaps in cellular coverage introduce vulnerabilities, while mitigative features include safe havens, police stations, and medical services. Temporal variables such as congestion, accidents, and weather further complicate route planning. Despite their importance, existing routing tools like Google Maps and commercial software do not explicitly account for geographic risk features, requiring planners to rely on personal familiarity with routes—a time-intensive, non-scalable approach. This work addresses these gaps by: (1) developing datasets that catalog geographic risk features along U.S. roadways, (2) eliciting risk perceptions from experienced transportation security experts, and (3) linking these perceptions to roadway conditions and geographic data. We implement these capabilities within Secure Route a novel mapping tool for classifying route segment risks associated with roadway conditions. This system provides transportation planners with an intuitive interface to assess and contextualize risk along potential routes, improving decision-making for secure transport. We present current progress in this effort and identify next steps.

Stewart, Robert [ORNL] (ORCID:0000000281867559)

ARCADE Analysis Methods & Validation Pathway

The Advanced Reactor Cyber Analysis and Development Environment (ARCADE) provides an automated analysis system which supports risk-informed performance based (RIPB) evaluations of nuclear control systems. Every possible cyber threat which could lead to consequence is identified by simulating the unsafe control action sequences which transform digital harm into physical harm. Eliminating the simulation of complex digital cyber attack chains cuts out unnecessary computational overhead and focuses directly on the physics of cyber-physical attacks. This focus enables designers to make informed decisions which can entirely eliminate categories of cyber threats against advanced reactors through the physical nature of the plant design. This narrowing of cyber threat against nuclear power plants through the physics of the system is intended to make any remaining threat management and cost efficient. This is the goal of the Tiered Cyber Analysis (TCA) outlined in NRC Draft Regulation Guide (RG) 5.96, which provides a RIPB cybersecurity approach for new reactors. ARCADE has been custom developed to meet the demands of the rigorous analysis required in Tier 1 of the TCA, which forms the foundation of the TCA process. Currently, ARCADE is still under development, but has made significant leaps in capability. A pilot analysis on the opensource Asherah simulator was performed which demonstrated key functionality goals. The next stage of ARCADE development involves improvements to the applications which support the analysis system, and enabling the analysis system to utilize the full suite of unsafe control action simulations. Since the analysis method’s core functions are complete, validation of the analysis method will be started concurrent to the next development stages. The automated analysis ARCADE will provide can radically change the cybersecurity design process for advanced reactors, reducing the cost of security implementation while enhancing cyber resilience. The pathway for ARCADE’s development to this goal has become much clearer. The majority of technical hurdles have been cleared, and the remaining development needs have been solidified. ARCADE is now capable of assisting the advanced reactor design process and directly support advanced reactor industry RIPB practices.

22 GENERAL STUDIES OF NUCLEAR REACTORS