Search NASA⌕ Search

SEARCH · Search NASA

Results for “Intrusion detection”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Securing The Future: 2026 Manufacturing & Critical Infrastructure Threat Landscape

This report outlines the current state of manufacturing weaknesses introduced by the complexities of modern environments, including cloud services and Internet of Things (IoT) devices, with particular attention paid to the unique vulnerabilities encountered by SMMs. It also highlights CyManII’s strategic initiatives and collaborative solutions to mitigate these risks and strengthen the cybersecurity posture of the manufacturing ecosystem. Utilizing data from 2025 to inform forward-looking mitigation strategies, this report provides manufacturers with a clear understanding of both current and emerging cybersecurity threats, as well as practical opportunities to strengthen their cyber ecosystems. The following sections detail key vulnerabilities and threat vectors, along with actionable mitigation strategies, many of which have been developed or piloted through CyManII-led efforts. A thorough understanding of these risks and mitigation strategies is essential for manufacturers seeking to strengthen the security and resilience of their manufacturing operations.

3D Printing↗

Efficient Anomaly Detection Driven By Different Machine Learning Architectures And Models

The rapid growth and ubiquitous adoption of the internet and cyber-physical systems (CPS) have fundamentally transformed modern communication, work, and human-system interactions. While networks now form the backbone of critical digital ecosystems, enabling seamless data transmission across diverse, interconnected systems, this increased connectivity also expands the attack surface, making real-time detection of network intrusions and anomalies a pressing challenge. Detecting unusual activities within network infrastructure requires advanced data traffic analysis to differentiate between legitimate and malicious interactions. Traditional approaches to network anomaly detectionâ??such as rule-based and signature-based systemsâ??often depend on predefined patterns to identify known anomalies, limiting their effectiveness against emerging, stealthy, or previously unseen threats. These conventional methods suffer from high false alarm rates and fail to adapt to the ever-evolving nature of network traffic, particularly in large-scale, decentralized environments where data volume, velocity, and variety are constantly increasing. This dissertation presents artificial intelligence (AI)-driven approaches to anomaly detection that leverage graphics processing unit (GPU)-enabled high-performance computing (HPC) platforms for processing massive network traffic data and monitoring the components of cyber-physical systems (CPS) for potentially hazardous conditions. The research advances several key contributions: (1) Designing efficient machine learning techniques for CPS condition monitoring and anomaly detection; (2) enabling federated learning (FL) frameworks that enable distributed detection while preserving data privacy and system resilience; (3) exploring graph-based methodologies combining graph neural networks (GNN) and graph machine learning (ML) approaches for the Internet of Things (IoT) and automotive network security, and (4) performing distributed edge computing optimizations that integrate FL with scalable technologies for reduced communication overhead. Through extensive experiments, these methodologies demonstrate that complex anomaly detection and condition monitoring tasks can be achieved while balancing computational efficiency and detection accuracy through fine-grained network information processing. The frameworks developed in this research establish a robust foundation for network anomaly detection, providing scalable, adaptive, and privacy-preserving solutions for safeguarding CPS and IoT networks in an increasingly interconnected digital landscape. The practical implications of these research findings are significant, as they can inform the development of next-generation network security systems and contribute to the protection of critical infrastructure against sophisticated cyber attacks.

Marfo, William↗

A novel transient infrared imaging method for non-intrusive, low-cost, fast, and accurate air leakage detection in building envelopes

Air leakage through the building envelope in the U.S. accounts for about four quads of energy annually, costing approximately $40 billion per year. However, a high-fidelity and non-intrusive method to detect air leakage has not been demonstrated to date. Here, in this paper, we propose a novel non-intrusive and low-cost method called Transient Infrared (IR) Imaging (TIRI) that can rapidly and accurately identify air leakage locations and relative rates on building envelopes. When the interior and exterior temperatures are different, and a small internal pressure pulse is created by HVAC, the temperature at locations with air leakages will change rapidly, while the areas without a leakage do not change. Based on a heat transfer model, we have derived the temperature change as a function of time after the HVAC is turned on. By tracking the temperature change, which depends on leakage rate and size, we have obtained the air leakage map in the case studies. Using an exterior door as an example, we took transient IR images in different seasons and different times of the day, and successfully obtained the leakage map in all the scenarios. Successfully obtained the air leakage map even when the indoor-outdoor air temperature difference is as small as 2 °C. We have also realized a detection speed of 10s and demonstrated that this method also worked for windows, which have mirror-like IR reflections. Our TIRI method will accelerate the improvement of airtightness in buildings, save building energy, and help reduce greenhouse gas emissions.

42 ENGINEERING↗

Pilot-Scale Validation of Distributed Optical Fiber Sensors for Underground Pipeline Monitoring

Distributed fiber optic sensing is a cutting-edge technology that has found extensive applications in the monitoring of Ensuring the safety, integrity, and operational efficiency of underground product pipelines is vital for maintaining the nation’s critical infrastructure. Monitoring parameters such as hoop strain, pressure, and acoustic vibrations is key to detecting potential leaks, intrusions, or structural issues. Distributed optical fiber sensor (DOFS) systems provide a compelling solution for continuous, real-time monitoring over long distances. This paper details the development and pilot-scale implementation of DOFS systems for underground pipeline monitoring, evolving from a proof-of-concept stage. Multiple custom-designed DOFS interrogator units—such as optical frequency-domain reflectometry (OFDR), Brillouin optical time-domain analysis (BOTDA), and multimodal interferometer-based fiber acoustic sensors—were employed to measure key parameters like hoop strain, pressure, and acoustic vibrations. The underground product pipeline's outer diameter is 30 inches, the wall thickness is 1.28 inches, and the 3-foot depth. The fiber deployment strategies, and sensing data acquisition methods for these systems are discussed. The results demonstrate the effectiveness of DOFS in detecting hoop strain, temperature changes, and acoustic vibrations, showcasing their potential for real-time monitoring and enhancing pipeline safety.

distributed fiber sensing↗

Pilot-Scale Validation of Distributed Optical Fiber Sensors for Underground Pipeline Monitoring

Monitoring parameters such as hoop strain, pressure, and acoustic vibrations is key to detecting potential leaks, intrusions, or structural issues. Distributed optical fiber sensor (DOFS) systems provide a compelling solution for continuous, real-time monitoring over long distances. This paper details the development and pilot-scale implementation of DOFS systems for underground pipeline monitoring, evolving from a proof-of-concept stage. Multiple custom-designed DOFS interrogator units—such as optical frequency-domain reflectometry (OFDR), Brillouin optical time-domain analysis (BOTDA), and multimodal interferometer-based fiber acoustic sensor systems were tested to measure the key parameters, such as hoop strain, pipe pressure, surrounding soil temperature, and acoustic vibrations. The underground product pipeline’s outer diameter is 30 inches, the wall thickness is 1.28 inches, and 3 feet deep from the surface. The fiber deployment strategies and sensing data acquisition methods for these systems are discussed. The results demonstrate the effectiveness of DOFS in detecting hoop strain, temperature changes, and acoustic vibrations, showcasing their potential for real-time monitoring and enhancing pipeline safety. These findings from pilot-scale testing offer valuable insights into advancing pipeline monitoring technologies and improving the reliability of underground pipeline systems.

fiber optic sensors↗

Resilience Through Data-Driven, Intelligent Designed Control: A Formal Methods Approach

The PNNL and GTRI team developed a strategy to integrate temporal logic rule specification for detection of cyber-intrusion in the source code and control algorithms of CPS using advanced cyber-data. The GTRI team utilized its capabilities in rule synthesis and temporal logic specifications for software assurance and verification to detect and predict impact of cyber-intrusions and malware in the computational and control algorithms of cyber-physical systems. The team also developed a testing and verification approach that could be used to validate the suggested approach against a realistic use-case CPS showcasing improvements in system impact prediction performance. Temporal logic offers a compact expression of events in absolute and relative time and has a formalized translation to state machines. As such, temporal logic rules can feasibly be synthesized to any system as a rule engine, with the process being formally verified to be correct. The goal here is to utilize temporal logic rules to detect cyber-attacks and manipulations in the computational algorithms and provide real-time software assurance and verification guarantees.

97 MATHEMATICS AND COMPUTING↗

Improving Robustness of Spectrogram Classifiers with Neural Stochastic Differential Equations

Signal analysis and classification is fraught with high levels of noise and perturbation. Computer-vision-based deep learning models applied to spectrograms have proven useful in the field of signal classification and detection; however, these methods aren't designed to handle the low signal-to-noise ratios inherent within non-vision signal processing tasks. While they are powerful, they are currently not the method of choice in the inherently noisy and dynamic critical infrastructure domain, such as smart-grid sensing, anomaly detection, and non-intrusive load monitoring. Currently, these models can be brittle, which makes them susceptible to noisy input. This also means they have sub-optimal stability of explanation outputs. Experts and technicians using these models to make decisions in real world scenarios need assurance that a model is performing as it is supposed to. The classification or prediction outputs it generates should be sound and grounded, not likely to change in the presence of shifting noise landscapes. In this work, we explore the idea of Neural Stochastic Differential Equations (NSDE's) to improve the robustness of models trained to classify time series data and the effect of NSDE's on the explainability of outputs. We then test the effectiveness of these approaches by applying them to a non-intrusive load monitoring (NILM) dataset that consists of simulated harmonic signals injected into a real building.

Brogan, Joel↗

A polarimetry-based field-deployable non-interruptive mirror soiling detection method

The soiling level of heliostat mirrors in Concentrated Solar Power (CSP) fields is one of the key factors that significantly influences optical efficiency. State-of-the-art methods of monitoring heliostats soiling levels still face various challenges, including slow speed, labor-intensive operations, resolution and accuracy constraints or interruptions to solar field operations. Here, we present a rapid, cost-effective, and non-intrusive method for mirror soiling detection based on polarimetric imaging, referred to as Polarimetric Imaging-based Mirror Soiling (PIMS). The compact PIMS device is designed for integration with unmanned aerial vehicles (UAVs), enabling rapid, large-area assessments of heliostat mirrors for efficient soiling detection. Our method utilizes the correlation between the Degree of Linear Polarization (DoLP) and surface soiling level based on Mie scattering theory and Monte Carlo simulations. Field deployment of the PIMS method requires minimal device installation, and its UAV-based operation allows for soiling detection without interrupting plant activities. The PIMS method holds the potential for mirror soiling detection across various concentrated solar power (CSP) plants and can be further adapted for other types of solar fields, such as parabolic trough systems.

CSP Field↗

A monolithic antineutrino detector for non-intrusive reactor monitoring

Recent advances in organic detection media have found applications in reactor antineutrino physics. One example is the Precision Oscillation and Spectrum Experiment (PROSPECT), which leveraged pulse-shape sensitivity to enable a successful surface deployment at the High Flux Isotope Reactor (HFIR), achieving a signal to background of 4:1. PROSPECT utilized almost 4 tonnes of 6 Li-doped pulse-shape sensitive liquid scintillator in a two-dimensional segmented array. It used a combination of pulse-shape sensitivity and position sensitivity via segmentation to reduce the most prominent form of correlated background for surface detectors — cosmogenic fast neutrons. These new liquids may enable detector designs that bring additional tools for reducing backgrounds while reducing engineering complexity. In this paper, we present an investigation into a detector design that exploits properties of these liquids by maximizing spectral and pulse-shape sensitivity via highly efficient photon detection. The detector utilizes photomultiplier tubes (PMTs) placed at the top and bottom of a right cylinder, with highly reflective white walls. This design sacrifices some position sensitivity for maximal photon efficiency. In conclusion, the design choice has consequences for the identification of the background and antineutrino sensitivity, which we examine.

Pulse shape↗

Wintertime extreme warming events in the high Arctic: characteristics, drivers, trends, and the role of atmospheric rivers

Abstract. An extreme warming event near the North Pole, with 2 m temperature rising above 0 °C, was observed in late December 2015. This specific event has been attributed to cyclones and their associated moisture intrusions. However, little is known about the characteristics and drivers of similar events in the historical record. Here, using data from European Centre for Medium-Range Weather Forecasts Reanalysis, version 5 (ERA5), we study these winter extreme warming events with 2 m temperature over a grid point above 0 °C over the high Arctic (poleward of 80° N) that occurred during 1980–2021. In ERA5, such wintertime extreme warming events can only be found over the Atlantic sector. They occur rarely over many grid points, with a total absence during some winters. Furthermore, even when occurring, they tend to be short-lived, with the majority of the events lasting for less than a day. By examining their surface energy budget, we found that these events transition with increasing latitude from a regime dominated by turbulent heat flux into the one dominated by downward longwave radiation. Positive sea level pressure anomalies which resemble blocking over northern Eurasia are identified as a key ingredient in driving these events, as they can effectively deflect the eastward propagating cyclones poleward, leading to intense moisture and heat intrusions into the high Arctic. Using an atmospheric river (AR) detection algorithm, the roles of ARs in contributing to the occurrence of these extreme warming events defined at the grid-point scale are explicitly quantified. The importance of ARs in inducing these events increases with latitude. Poleward of about 83° N, 100 % of these events occurred under AR conditions, corroborating that ARs were essential in contributing to the occurrence of these events. Over the past 4 decades, both the frequency, duration, and magnitude of these events have been increasing significantly. As the Arctic continues to warm, these events are likely to increase in both frequency, duration, and magnitude, with great implications for the local sea ice, hydrological cycle, and ecosystem.

54 ENVIRONMENTAL SCIENCES↗

Regional and Temporal Variability of Atmospheric River Seasonality: Influences of Detection Algorithms and Moisture Transport Dynamics

Abstract Understanding the regional and temporal variability of atmospheric river (AR) seasonality is crucial for preparedness and mitigation of extreme events. While ARs were thought to peak in winter, recent research shows they exhibit region‐specific seasonality and are heavily influenced by the chosen detection algorithm. This study examines the link between the year‐to‐year consistency of peak‐AR activity to the presence of a dominant seasonal pattern, considering both location and algorithm choice. Regions are categorized by their temporal characteristics: consistent patterns (e.g., East Asia), patterns with occasional outliers (e.g., British Columbia coast), and regions lacking a clear dominant peak season (e.g., South Atlantic, parts of Australia). Hence, not all regions display a consistent seasonal cycle of AR activity. This study quantifies the extent to which a region experiences a dominant peak season of AR activity (or lacks one) and offers insights to enhance decision‐making in water management, natural hazard preparedness, and forecasting. Furthermore, given our finding that detection algorithms influence the peak season of AR activity, we also examine two diagnostic variables representative of moisture transport to corroborate our results. Integrated vapor transport, which captures meridional and zonal moisture transport, and Moist Wave Activity, representing moisture intrusions from lower to higher latitudes, are examined. Our analysis indicates that inconsistencies in the seasonal cycle of AR activity are not solely due to discrepancies in detection algorithms but also arise from changes in moisture transport. Plain Language Summary Atmospheric rivers (ARs) are critical weather phenomena that can cause extreme events like heavy rainfall and flooding. Understanding when and where ARs are most likely to occur throughout the year is essential for preparing and responding to these events. Traditionally, ARs were thought to peak in winter, but recent studies show this varies by region. Our study helps address the challenge decision‐makers face in anticipating and preparing for AR events by providing insights into the consistency of peak seasonal patterns across different areas. Some regions, like East Asia, and the British Columbia coast, show a consistent peak season, while others, like the South Atlantic and parts of Australia, have significant year‐to‐year variations, making it hard to identify a dominant season. To better understand these changes over time, the study also examines how moisture moves in the atmosphere, using Integrated Vapor Transport (which looks at moisture movement in various directions) and Moist Wave Activity (which tracks moisture shifts from lower to higher latitudes). The findings suggest that inconsistencies in AR patterns are due not only to detection methods but also due to changes in moisture transport. Key Points The peak season of atmospheric river activity can change depending on the year in some areas Interannual variations in the peak season can make identifying a dominant season challenging for some regions Frequent shifts in peak season across years reflect inconsistencies tied to detection algorithms and to underlying dynamics

Kamnani, Diya↗

Model-observation discrepancies in Arctic moisture intrusions: causes and pathways for improved simulation

Arctic moisture intrusions (MIs), narrow filaments of strong moisture transport, are key drivers of poleward moisture flux and Arctic weather extremes, yet their representation in climate models is poorly understood. Using a new Arctic MI detection algorithm, we document persistent biases across three CMIP generations (CMIP3–CMIP6): models overestimate MI occurrence over the Pacific sector and underestimate it over the Atlantic sector. These errors stem from misrepresented midlatitude westerly jets, with an equatorward North Atlantic jet associated with too few Atlantic MIs, and a poleward, weakened North Pacific jet linked to too many Pacific MIs. Experiments that correct sea surface temperature and sea ice concentration biases and increase atmospheric resolution improve jet structure and MI statistics, while a cloud-locking simulation indicates that better high-frequency cloud–radiation–circulation interactions can yield further gains. Our results clarify pathways to reducing long-standing MI and jet biases, providing guidance for improving simulations of Arctic and midlatitude climate.

54 ENVIRONMENTAL SCIENCES↗

Advancing Industry 4.0: Multimodal Sensor Fusion for AI-Based Fault Detection in 3D Printing

Additive manufacturing, particularly fused deposition modeling, is transforming modern production by enabling rapid prototyping and complex part fabrication. However, its layer-by-layer process remains vulnerable to faults such as nozzle clogging, filament runout, and layer misalignment, which compromise print quality and reliability. Traditional inspection methods are costly, time-intensive, and often limited to post-process analysis, making them unsuitable for real-time intervention. In this current study, the authors developed a novel, low-cost, and portable faultdetection system that leverages multimodal sensor fusion and artificial intelligence for real-time monitoring in FDM-based 3D printing. The system integrates acoustic, vibration, and thermal sensing into a non-intrusive architecture, capturing complementary data streams that reflect both mechanical and process-related anomalies. Acoustic and thermal sensors operate in a fully contactless manner, while the vibration sensor requires minimal attachment such that it will not interfere with printer hardware, thereby preserving portability and ease of deployment. The multimodal signals are processed into spectrograms and time-frequency features, which are classified using convolutional neural networks for intelligent fault detection. The proposed system advances Industry 4.0 objectives by offering an affordable, scalable, and practical monitoring solution that improves faultdetection accuracy, reduces waste, and supports sustainable, adaptive manufacturing.

42 ENGINEERING↗

Expandable Log Analyzing Framework

Prior to my internship, I was informed that a previous intern had built a tool to analyse MongoDB logs and look for invalid access attempts, which served as a great reference point for my project. I was initially tasked with expanding on her prototype and filling in the gaps such as integrating it with the main monitoring tool the lab uses. Eventually, the scope grew, expanding to support other databases and a growing collection of tools. I organized the framework around an observer pattern, meaning one point in the program sending updates to the rest of the framework. Every time a log was read and parsed, it was sent to be processed by the tools, using the type of event as a means to determine which tools should get a chance to act on the log. This decouples the tools from the log reader, making future updates and additions much easier. The framework processes MongoDB logs at ~135,000 entries per second and PostgreSQL logs at ~170,500 entries per second, accurately detecting anomalies such as slow queries and connections from unknown addresses. This framework serves to fill gaps in database monitoring tools currently implemented at the lab, such as tracking failed authentication for PostgreSQL and MongoDB which had very minimal or none before this framework. National labs such as Fermilab hold sensitive data and valuable computing resources, making them attractive targets. Monitoring intrusion attempts on databases is made much easier by this comprehensive monitoring suite.

Clark, Dylan [Unlisted, IL]↗

Expandable Log Analyzing Framework

Prior to my internship, I was informed that a previous intern had built a tool to analyse MongoDB logs and look for invalid access attempts, which served as a great reference point for my project. I was initially tasked with expanding on her prototype and filling in the gaps such as integrating it with the main monitoring tool the lab uses. Eventually, the scope grew, expanding to support other databases and a growing collection of tools. I organized the framework around an observer pattern, meaning one point in the program sending updates to the rest of the framework. Every time a log was read and parsed, it was sent to be processed by the tools, using the type of event as a means to determine which tools should get a chance to act on the log. This decouples the tools from the log reader, making future updates and additions much easier. The framework processes MongoDB logs at ~135,000 entries per second and PostgreSQL logs at ~170,500 entries per second, accurately detecting anomalies such as slow queries and connections from unknown addresses. This framework serves to fill gaps in database monitoring tools currently implemented at the lab, such as tracking failed authentication for PostgreSQL and MongoDB which had very minimal or none before this framework. National labs such as Fermilab hold sensitive data and valuable computing resources, making them attractive targets. Monitoring intrusion attempts on databases is made much easier by this comprehensive monitoring suite.

Clark, Dylan [Unlisted, IL]↗

Database-Agnostic Log Analysis and Monitoring Framework

Prior to my internship, I was informed that a previous intern had built a tool to analyse MongoDB logs and look for invalid access attempts, which served as a great reference point for my project. I was initially tasked with expanding on her prototype and filling in the gaps such as integrating it with the main monitoring tool the lab uses. Eventually, the scope grew, expanding to support other databases and a growing collection of tools. I organized the framework around an observer pattern, meaning one point in the program sending updates to the rest of the framework. Every time a log was read and parsed, it was sent to be processed by the tools, using the type of event as a means to determine which tools should get a chance to act on the log. This decouples the tools from the log reader, making future updates and additions much easier. The framework processes MongoDB logs at ~135,000 entries per second and PostgreSQL logs at ~170,500 entries per second, accurately detecting anomalies such as slow queries and connections from unknown addresses. This framework serves to fill gaps in database monitoring tools currently implemented at the lab, such as tracking failed authentication for PostgreSQL and MongoDB which had very minimal or none before this framework. National labs such as Fermilab hold sensitive data and valuable computing resources, making them attractive targets. Monitoring intrusion attempts on databases is made much easier by this comprehensive monitoring suite.

Clark, Dylan [Unlisted, US, IL; Fermilab]↗

Heliostat optical error inspection with polarimetric imaging drone

On a Concentrated Solar Power (CSP) field, optical errors have significant impacts on the collection efficiency of heliostats. Fast, cost-effective, labor-efficient, and non-intrusive autonomous field inspection remains a challenge. Approaches using imaging drone, i.e., Unmanned Aerial Vehicle (UAV) system integrated with high resolution visible imaging sensors, have been developed to address these challenges; however, these approaches are often limited by insufficient imaging contrast. Here, in this study, we report a polarimetry-based method with a polarization imaging system integrated on UAV to enhance imaging contrast for in-situ detection of heliostat mirrors without interrupting field operation. We developed an optical model for skylight polarization pattern to simulate the polarization images of heliostat mirrors and obtained optimized waypoints for polarimetric imaging drone flight path to capture images with enhanced contrast. The polarimetric imaging-based method improved the success rate of edge detections in scenarios which were challenging for mirror edge detection with conventional imaging sensors. We have performed field tests to achieve significantly enhanced heliostat edge detection success rate and investigate the feasibility of integrating polarimetric imaging method with existing imaging-based heliostat inspection methods, i.e., Polarimetric Imaging Heliostat Inspection Method (PIHIM). Our preliminary field test results suggest that the PIHIM hold the promise to enable sufficient imaging contrast for real-time autonomous imaging and detection of heliostat field, thus suitable for non-interruptive fast CSP field inspection during its operation.

CSP Field↗