Artificial-Intelligence-based Confidentiality, Integrity, and Availability of Wirelessly Transmitted Data in Nuclear Industry
Innovative federated learning approach enables secure and reliable wireless communication in critical infrastructure.
Engineering topics
Publications and source records attributed to Eggers, Shannon Leigh.
Innovative federated learning approach enables secure and reliable wireless communication in critical infrastructure.
Cyber-informed engineering and security-by-design frameworks are important in promoting the need to identify cybersecurity concerns early in the systems engineering lifecycle so risks from adversarial cyber-attacks can be eliminated or reduced through engineering design practices. In addition to adversarial risk, risk in operational technology systems also includes non-adversarial and unintentional risk from other factors such as human performance errors, environmental conditions, design flaws, and device degradation or failure. This paper introduces a new concept for characterizing digital risk, both adversarial and non-adversarial, and provides the basis for initial research into a novel digital risk analysis approach focused on incorporating attack difficulty into a multi-attribute analysis technique using robust decision-making. This digital risk characterization is also used to frame a discussion on the challenges of competing objectives and competing stakeholder requirements in an integrated energy system project that incorporates a small modular reactor and industrial facility.
We present a novel Bayesian learning approach to outdoor radio heatmap construction utilizing deep Gaussian process (GP). The proposed approach employs a two-layer hierarchy which consists of two cascaded Gaussian processes that are capable of modeling more complex input-output relations than standard single-layer Gaussian processes. Since deriving the exact model likelihood is challenging, a lower bound is optimized instead so that gradient descent-based methods can be performed to find out the optimal model parameters. Typically, inducing points are used in GPs to facilitate low-rank approximation of covariance (kernel) matrices for computation speedup. However, the inaccuracy induced by inducing points can accumulate when stacking multiple layers of GP which may hinder the performance of deep GP. Moreover, since inducing points need to be learned, having them at all layers of deep GP also incurs computational burden. To overcome the above challenges, in contrast to the canonical deep GP model, we use a modified architecture where a full standard GP resides in the first layer and inducing points are only introduced for the second layer. This modified architecture strikes a balance between model accuracy and training complexity. In the proposed model, the noise parameter of the first GP layer is also eliminated to improve the training efficiency as the noise parameter at the output of the second layer suffices to model the uncertainty in the output. The proposed approach is evaluated on real-world datasets, in the form of location-Received Signal Strength (RSS) pairs, collected from the Platform for Open Wireless Data-driven Experimental Research (POWDER) located at the campus of the University of Utah. Experiment results show that the proposed approach can achieve smaller prediction errors on various training and testing data configurations than DNN-based and GP-based methods.
Many engineers and scientists researching modeling and analysis methods for nuclear energy advancement are focused on proof-of-concept and early-stage development for new reactor designs. Since instrumentation and control (I&C) systems are traditionally developed later in the systems engineering lifecycle, researchers may be unfamiliar with modern digital technology used in these I&C systems. It is even more likely that they are unfamiliar with the cyber risks associated with them. This paper provides a brief overview of nuclear digital I&C systems before examining the importance of cyber risk management at nuclear reactors and the benefits of including Cyber-Informed Engineering throughout the systems engineering lifecycle. The primary goal is for engineers and scientists to develop a mindset that incorporates cybersecurity as another discipline alongside safety when designing and developing new technologies, regardless of technology readiness level.
Considerable efforts are underway to ensure cybersecurity is integrated into the systems engineering lifecycle. Cyber-informed engineering and security-by-design frameworks are intended to identify and engineer out cybersecurity risks throughout the lifecycle. While these approaches are valuable for promoting the need to include cybersecurity considerations in early design phases to create more secure systems, they may not consider the entirety of digital risks. Digital risks in a digital instrumentation and control system include adversarial and unintentional risks from internal and external factors, such as human performance errors, design flaws, environmental conditions, and equipment degradation or failure. This report provides a detailed discussion on digital risk prior to describing the background and concept of operations for a small modular reactor-driven integrated energy system connected to industrial applications. The challenges of competing objectives and competing stakeholder requirements are discussed and the impacts on digital engineering, security considerations, and interdependencies are evaluated for mission-level, facility-level, and system-level decisions.
Software supply chain attacks are becoming increasingly more prevalent in both information communications technology and operational technology environments. Often, a supplier or other entity discloses vulnerability information about software components and subcomponents used in a digital asset, but an asset owner is unable to quickly ascertain if the vulnerable component is installed in their facility. The generation and use of a software bill of materials (SBOM) for installed digital assets can enable an asset owner to quickly identify if and where a component is used, allowing them to evaluate the risk and determine necessary risk treatments. The integration of an SBOM program into a nuclear facility not only improves vulnerability management and risk management processes, it also benefits asset and configuration management, cybersecurity, and supply chain programs. This paper reviews the U.S. Department of Energy Office of Nuclear Energy Cybersecurity Crosscutting Technology Development program’s work on integrating an SBOM program into a nuclear facility. It also provides a discussion on the benefits of such a program.
Research and development into applications for improving equipment condition monitoring programs at nuclear facilities has been around since the 1990s. However, while the field has moved from using data-driven machine learning (ML) algorithms for detection and prediction of equipment degradation and failure to prognostic capabilities, these applications are still not widely used in the U.S. nuclear industry. Additionally, there has been significant effort in designing both data-driven and physics-based artificial intelligence (AI) and ML models for many other potential applications in the nuclear industry, including cyber intrusion detection systems (IDS). However, as the last twenty years in condition-based maintenance research has shown us, there are significant hurdles that must be overcome for deployment of IDS on plant systems. This paper provides a discussion on the practical recommendations that researchers should consider for successful adoption of AI/ML IDS in the nuclear industry.
Nuclear power plants (NPP) have thousands of digital assets throughout their facility. Typically, NPPs have asset and configuration management programs that capture the make, model, and version of a component. This information, however, usually only includes first- or second-tier components and does not capture the complete enumeration of software components and their dependencies within operational technology (OT) equipment. As seen with recent cyberattacks, this level of detail is insufficient for identifying if and where an exploitable vulnerability exists within a facility. A software bill of materials (SBOM) provides this detailed enumeration. Further, integrating SBOMs with vulnerability data sources and vulnerability attestation reports can provide improved awareness leading to better cyber risk management and incident response. Preferably, SBOMs are provided by the supplier; however, when an NPP already owns a device, it is less likely they will have a supplier provided-SBOM. Fortunately, SBOMs can be generated on installed digital assets. This paper provides an introduction to the U.S. Department of Energy Office of Nuclear Energy paper titled “Towards Software Bill of Materials in the Nuclear Industry,” which describes the SBOM ecosystem and provides a suggested approach to methodically and seamlessly integrate an SBOM program in an NPP.
Traditionally, cybersecurity is not considered in the design process. Design engineers typically focus on building safety and reliability into their products and applications. Security against malicious cyber incidents is often an afterthought, resulting in deployment of security solutions during installation or operation. Unfortunately, waiting to consider cybersecurity until later in the systems engineering lifecycle often results in less effective and more expense security. Idaho National Laboratory (INL) developed the concept of Cyber-Informed Engineering (CIE) in 2015 to provide a framework that enables cybersecurity to be built into systems beginning at the conceptual design stage. In addition to ongoing research by INL, the U.S. Department of Energy (DOE) Office of Cybersecurity, Energy Security, and Emergency Response has recently developed a National CIE Strategy document for incorporating CIE into the design and operation of infrastructure systems reliant on digital monitoring or controls. This paper provides a brief review of this National CIE Strategy as well as a roadmap to historical, current, and future CIE research by INL through the U.S. DOE Office of Nuclear Energy (NE) Cybersecurity Crosscutting Technology Development Program. A near-term focus of the DOE-NE’s research and development is to extend the foundational CIE work into detailed guidance for implementation during initial systems engineering stages in nuclear digital instrumentation and control projects and to demonstrate use of the guidance in an integrated energy systems project.
To support the reliable and resilient operation of modular reactors and microreactors, anticipatory control strategies have been proposed for achieving faster-than-real-time predictions and decision-making capabilities in anticipation of potential anomalies, including setpoint changes and cyber incidents. Here this work presents how anticipatory control strategies can be implemented via model predictive control (MPC) of a single heat pipe’s temperature. Considering the uncertainty in developing and applying MPC, this work evaluates MPC performance given three different model forms: a linear response surface model, an artificial neural network (ANN), and an autoregressive model with exogenous input (ARX). This work also evaluates the impacts of different input biases and variance on MPC performance in order to account for potential sensor reading variations due to cyber incidents. We observe that nonparametric models such as the ANN and ARX result in more fluctuated control actions compared to the MPC applied to the linear response surface model. However, when the cyber incidents are of a large magnitude, the linear response surface model produces smaller feasible regions than the nonparametric models under identical constraints.
The advancement of cyber resilience requires a preliminary stage of characterizing the trade-off space of mitigation options and how these might affect the stability and determinism of an operational technology (OT). This first step will set the stage for the proper cyber-secure and cyber-resilient design and confirm the affects that can be considered and approved by the OT and the security groups. To provide a baseline for this discussion, this paper provides a consideration of the cyberphysical interactions, possible mitigation steps against certain attacks and their corresponding affects that lend to the security design planning and evaluation process. As an integral part of the proposed scheme this work introduces the concept of systemwide fuzzer, i.e., a tool that manipulates the system state in an effort to determine mitigation response sequences that minimize detriments and maximize benefit in accordance with specified operational requirements.
Large, modern industrial facilities often incorporate thousands of digital assets in their operational technology. Regulated facilities, such as nuclear power plants (NPPs), maintain robust cybersecurity and configuration management programs that often use bills of materials (BOMs) for these assets, including make, model, and version of hardware, firmware, and software. However, these BOMs typically capture only first- or second-tier information provided by the original equipment manufacturer (OEM). Unfortunately, as indicated by the increasing number and sophistication of software supply chain attacks, this level of detail is insufficient for identifying all the potential vulnerabilities and risks in software applications. Software BOMs (SBOMs) provide detailed enumeration of components and dependencies within the product or devices, including firmware. SBOMs can be combined with vulnerability data sources and vendor vulnerability attestations to improve vulnerability management and enable rapid identification of affected components when new software vulnerabilities are discovered. Ideally, SBOMs are created by the OEM prior to installation. However, since this practice is not yet commonplace and since NPPs are typically slow to adopt new technology, most NPPs do not incorporate SBOMs into their asset or configuration management programs. Fortunately, SBOMs can be generated by NPPs on existing digital assets to provide further insight into risk management decisions. This report provides an overview of the current SBOM ecosystem and recommends guidance on how to get started in a “crawl, walk, run” manner to develop and implement a sustainable SBOM program for digital assets in an NPP.