Search NASA⌕ Search

SEARCH · Search NASA

Results for “Intrusion detection”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Digital Assurance Checklist for Homeowners and Installers

This document provides a comprehensive Digital Assurance Checklist for securing behind-the-meter energy assets, focusing on both installers and homeowners. As distributed energy resources (DERs) such as solar PV and battery storage become integral to residential energy systems, cybersecurity emerges as a critical component of reliability and safety. The guide outlines actionable steps for installers during pre-installation, commissioning, and post-installation phases, emphasizing practices like network segmentation, credential management, firmware validation, and homeowner education. For homeowners, the document introduces a tiered approach to cyber hygiene—from essential measures like strong Wi-Fi credentials and automatic updates to advanced strategies such as network segmentation, DNS filtering, and intrusion detection. By adopting these practices, stakeholders can mitigate cyber risks, safeguard energy infrastructure, and ensure resilient, secure operation of DER systems. Additional resources and references to industry standards are included to support implementation.

99 - GENERAL AND MISCELLANEOUS↗

Quality metrics for sensor images

Methods are needed for evaluating the quality of augmented visual displays (AVID). Computational quality metrics will help summarize, interpolate, and extrapolate the results of human performance tests with displays. The FLM Vision group at NASA Ames has been developing computational models of visual processing and using them to develop computational metrics for similar problems. For example, display modeling systems use metrics for comparing proposed displays, halftoning optimizing methods use metrics to evaluate the difference between the halftone and the original, and image compression methods minimize the predicted visibility of compression artifacts. The visual discrimination models take as input two arbitrary images A and B and compute an estimate of the probability that a human observer will report that A is different from B. If A is an image that one desires to display and B is the actual displayed image, such an estimate can be regarded as an image quality metric reflecting how well B approximates A. There are additional complexities associated with the problem of evaluating the quality of radar and IR enhanced displays for AVID tasks. One important problem is the question of whether intruding obstacles are detectable in such displays. Although the discrimination model can handle detection situations by making B the original image A plus the intrusion, this detection model makes the inappropriate assumption that the observer knows where the intrusion will be. Effects of signal uncertainty need to be added to our models. A pilot needs to make decisions rapidly. The models need to predict not just the probability of a correct decision, but the probability of a correct decision by the time the decision needs to be made. That is, the models need to predict latency as well as accuracy. Luce and Green have generated models for auditory detection latencies. Similar models are needed for visual detection. Most image quality models are designed for static imagery. Watson has been developing a general spatial-temporal vision model to optimize video compression techniques. These models need to be adapted and calibrated for AVID applications.

Ahumada, AL↗

EV SALaD 2023 Demonstration: Best Practices and Mitigations for Protecting EVSE Infrastructure

The Electric Vehicle Secure Architecture Laboratory Demonstration (EV SALaD) program is a demonstration of cybersecurity best practices for high-power electric vehicle (EV) charging infrastructure led by Idaho National Laboratory (INL), in collaboration with other DOE National Laboratories participating in the EVs at Scale Consortium.a Sandia National Laboratories (SNL) and Pacific Northwest National Laboratory (PNNL) participated in the first 2-year (FY22-23) demonstration cycle for EV SALaD. This report documents the FY23 demonstration, the second in a series of demonstrations and collaborations in deploying and operating cybersecure EV charging infrastructure. It includes a summary of improvements from the FY22 demonstration, technical analysis of the FY23 demonstration, how the research demonstrates cyber-physical and cybersecurity best practices for high-power EV charging infrastructure, and related impacts to national and energy security. For EV SALaD, the FY22 demonstration focused on the detection, ranking, and prioritization of anomalous events for high-power EV charging. The FY23 demonstration additionally included the demonstration of cybersecurity best practices, which included protection and mitigation solutions to prevent, respond, and recover from anomalous events. During the demonstrations, the multi-lab EV SALaD team conducted a Test Effect Payload (TEP)b evaluation on extreme fast charger (XFC) hardware equipped with Cerberus, a detection and response solution, to demonstrate anomaly detection and mitigation cybersecurity best practices against cyber-enabled events.

33 ADVANCED PROPULSION SYSTEMS↗

Threat Hunt Guide for BESS Environments

The rapid digitalization of the electric grid - driven by the integration of inverter-based resources (IBRs), battery energy storage systems (BESS), and advanced grid control platforms - has significantly enhanced grid efficiency, visibility, and flexibility. However, this evolution also introduces new cybersecurity risks, particularly through supply chain dependencies and operational blind spots at the grid edge. To address these challenges, Idaho National Laboratory (INL), through the Department of Energy (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER) Rapid Risk initiative, conducted a series of rapid risk assessment engagements with energy organizations across the United States. Drawing on lessons learned from these engagements, INL developed the following threat hunting guide for asset owners and operators (AOOs) to enhance their cybersecurity visibility within BESS and IBR systems. The guide demonstrates how to use passive network monitoring to baseline device behavior, detect adversarial activity, and investigate anomalies without disrupting operations. By implementing these practices, energy sector stakeholders can improve coordination between cybersecurity and operations teams and strengthen the resilience of distributed energy resources (DERs) within the modern power grid. Prior to implementing any network monitoring, packet capture, or threat hunting activity described in this guide, AOOs are strongly advised to review applicable governance frameworks, legal requirements, and organizational policies. This guide is intended for informational and educational purposes only. It does not replace compliance with any federal, state, or local cybersecurity mandates or industry standards. Implementation of described configurations, technologies, or analytic workflows is performed at the discretion and responsibility of the asset owner and operator.

25 - ENERGY STORAGE↗

Designing resilient IoT and Edge Computing with federated tinyML

The rapid growth of the Internet of Things (IoT) and Edge Computing (EC) has brought significant conveniences to modern society but has also greatly expanded the cyber attack surfaces, particularly as these technologies are being increasingly integrated into critical systems such as power grids, healthcare, and smart homes. Here, to improve IoT/EC’s cybersecurity posture, we leveraged Artificial Intelligence (AI) and Machine Learning (ML) by employing tinyML to monitor voluminous IoT data for cyber threats while addressing devices’ resource constraints, and utilizing Federated Learning (FL) to share local detection knowledge across the system while preserving privacy. Building on our three-layer architecture combining tinyML and FL to enhance autonomous cyber attack detection, this paper demonstrated that the architecture improves detection accuracy, reduces resource consumption, and enables lightweight, secure IoT device monitoring. These results were validated using the public N-BaIoT dataset as well as real IoT network traffic data collected under multiple attack scenarios from our testbeds. Additionally, we introduced an enhanced FL methodology with a novel preprocessing stage, including federated feature selection and global preprocessor construction, to address IoT/EC data heterogeneity. We developed a physical IoT testbed for attack simulations and data collection, implemented a tinyML-powered detector for realistic model validation, and also built a virtual testbed for scalable evaluations of FL models across diverse network environments.

Cognitive cyber↗

Securing The Future: 2026 Manufacturing & Critical Infrastructure Threat Landscape

This report outlines the current state of manufacturing weaknesses introduced by the complexities of modern environments, including cloud services and Internet of Things (IoT) devices, with particular attention paid to the unique vulnerabilities encountered by SMMs. It also highlights CyManII’s strategic initiatives and collaborative solutions to mitigate these risks and strengthen the cybersecurity posture of the manufacturing ecosystem. Utilizing data from 2025 to inform forward-looking mitigation strategies, this report provides manufacturers with a clear understanding of both current and emerging cybersecurity threats, as well as practical opportunities to strengthen their cyber ecosystems. The following sections detail key vulnerabilities and threat vectors, along with actionable mitigation strategies, many of which have been developed or piloted through CyManII-led efforts. A thorough understanding of these risks and mitigation strategies is essential for manufacturers seeking to strengthen the security and resilience of their manufacturing operations.

3D Printing↗

Conflict Detection Using Variable Four-Dimensional Uncertainty Bounds to Control Missed Alerts

Decision-support tools for maintaining pairwise aircraft separation rely on conflict detection to alert the operator when the predicted trajectories of aircraft will result in a loss of separation. But aircraft frequently do not follow their predicted trajectories exactly. This can cause missed alerts and the failure of strategic separation procedures. We present a technique for modeling a bounded region of uncertainty around a four-dimensional predicted trajectory and an algorithm for detecting conflicts between trajectories modeled in this way that avoids missed alerts as long as the aircraft remain within the specified regions of uncertainty. In addition, we present an algorithm for detecting the intrusion of a trajectory modeled in this way into an area hazard modeled as a polygonal region. The size of the region of uncertainty can vary along the trajectory continually and independently in the along-path, cross-track, and vertical dimensions, providing an opportunity to reduce the likelihood of false alerts while protecting against typical prediction errors. The algorithm has been implemented in the Autonomous Operations Planner, a NASA Langley prototype decision support tool for airborne self-separation.

Karr, David A.↗

Efficient Anomaly Detection Driven By Different Machine Learning Architectures And Models

The rapid growth and ubiquitous adoption of the internet and cyber-physical systems (CPS) have fundamentally transformed modern communication, work, and human-system interactions. While networks now form the backbone of critical digital ecosystems, enabling seamless data transmission across diverse, interconnected systems, this increased connectivity also expands the attack surface, making real-time detection of network intrusions and anomalies a pressing challenge. Detecting unusual activities within network infrastructure requires advanced data traffic analysis to differentiate between legitimate and malicious interactions. Traditional approaches to network anomaly detectionâ??such as rule-based and signature-based systemsâ??often depend on predefined patterns to identify known anomalies, limiting their effectiveness against emerging, stealthy, or previously unseen threats. These conventional methods suffer from high false alarm rates and fail to adapt to the ever-evolving nature of network traffic, particularly in large-scale, decentralized environments where data volume, velocity, and variety are constantly increasing. This dissertation presents artificial intelligence (AI)-driven approaches to anomaly detection that leverage graphics processing unit (GPU)-enabled high-performance computing (HPC) platforms for processing massive network traffic data and monitoring the components of cyber-physical systems (CPS) for potentially hazardous conditions. The research advances several key contributions: (1) Designing efficient machine learning techniques for CPS condition monitoring and anomaly detection; (2) enabling federated learning (FL) frameworks that enable distributed detection while preserving data privacy and system resilience; (3) exploring graph-based methodologies combining graph neural networks (GNN) and graph machine learning (ML) approaches for the Internet of Things (IoT) and automotive network security, and (4) performing distributed edge computing optimizations that integrate FL with scalable technologies for reduced communication overhead. Through extensive experiments, these methodologies demonstrate that complex anomaly detection and condition monitoring tasks can be achieved while balancing computational efficiency and detection accuracy through fine-grained network information processing. The frameworks developed in this research establish a robust foundation for network anomaly detection, providing scalable, adaptive, and privacy-preserving solutions for safeguarding CPS and IoT networks in an increasingly interconnected digital landscape. The practical implications of these research findings are significant, as they can inform the development of next-generation network security systems and contribute to the protection of critical infrastructure against sophisticated cyber attacks.

Marfo, William↗

Remote sensing of coastal environmental hazards

Examples of the application of NOAA High Resolution Picture Transmission (HRPT) data to natural hazards and disasters are reviewed. The examples discussed include flooding of the Ganges River Delta; detecting effects of salt water intrusion into freshwater marshes; detecting fires, smoke plumes, and oil slicks; and monitoring of ocean currents and eddies. The present limitations of the HRPT data and future prospects are briefly discussed.

Huh, Oscar K.↗

A novel transient infrared imaging method for non-intrusive, low-cost, fast, and accurate air leakage detection in building envelopes

Air leakage through the building envelope in the U.S. accounts for about four quads of energy annually, costing approximately $40 billion per year. However, a high-fidelity and non-intrusive method to detect air leakage has not been demonstrated to date. Here, in this paper, we propose a novel non-intrusive and low-cost method called Transient Infrared (IR) Imaging (TIRI) that can rapidly and accurately identify air leakage locations and relative rates on building envelopes. When the interior and exterior temperatures are different, and a small internal pressure pulse is created by HVAC, the temperature at locations with air leakages will change rapidly, while the areas without a leakage do not change. Based on a heat transfer model, we have derived the temperature change as a function of time after the HVAC is turned on. By tracking the temperature change, which depends on leakage rate and size, we have obtained the air leakage map in the case studies. Using an exterior door as an example, we took transient IR images in different seasons and different times of the day, and successfully obtained the leakage map in all the scenarios. Successfully obtained the air leakage map even when the indoor-outdoor air temperature difference is as small as 2 °C. We have also realized a detection speed of 10s and demonstrated that this method also worked for windows, which have mirror-like IR reflections. Our TIRI method will accelerate the improvement of airtightness in buildings, save building energy, and help reduce greenhouse gas emissions.

42 ENGINEERING↗

Pilot-Scale Validation of Distributed Optical Fiber Sensors for Underground Pipeline Monitoring

Distributed fiber optic sensing is a cutting-edge technology that has found extensive applications in the monitoring of Ensuring the safety, integrity, and operational efficiency of underground product pipelines is vital for maintaining the nation’s critical infrastructure. Monitoring parameters such as hoop strain, pressure, and acoustic vibrations is key to detecting potential leaks, intrusions, or structural issues. Distributed optical fiber sensor (DOFS) systems provide a compelling solution for continuous, real-time monitoring over long distances. This paper details the development and pilot-scale implementation of DOFS systems for underground pipeline monitoring, evolving from a proof-of-concept stage. Multiple custom-designed DOFS interrogator units—such as optical frequency-domain reflectometry (OFDR), Brillouin optical time-domain analysis (BOTDA), and multimodal interferometer-based fiber acoustic sensors—were employed to measure key parameters like hoop strain, pressure, and acoustic vibrations. The underground product pipeline's outer diameter is 30 inches, the wall thickness is 1.28 inches, and the 3-foot depth. The fiber deployment strategies, and sensing data acquisition methods for these systems are discussed. The results demonstrate the effectiveness of DOFS in detecting hoop strain, temperature changes, and acoustic vibrations, showcasing their potential for real-time monitoring and enhancing pipeline safety.

distributed fiber sensing↗

Pilot-Scale Validation of Distributed Optical Fiber Sensors for Underground Pipeline Monitoring

Monitoring parameters such as hoop strain, pressure, and acoustic vibrations is key to detecting potential leaks, intrusions, or structural issues. Distributed optical fiber sensor (DOFS) systems provide a compelling solution for continuous, real-time monitoring over long distances. This paper details the development and pilot-scale implementation of DOFS systems for underground pipeline monitoring, evolving from a proof-of-concept stage. Multiple custom-designed DOFS interrogator units—such as optical frequency-domain reflectometry (OFDR), Brillouin optical time-domain analysis (BOTDA), and multimodal interferometer-based fiber acoustic sensor systems were tested to measure the key parameters, such as hoop strain, pipe pressure, surrounding soil temperature, and acoustic vibrations. The underground product pipeline’s outer diameter is 30 inches, the wall thickness is 1.28 inches, and 3 feet deep from the surface. The fiber deployment strategies and sensing data acquisition methods for these systems are discussed. The results demonstrate the effectiveness of DOFS in detecting hoop strain, temperature changes, and acoustic vibrations, showcasing their potential for real-time monitoring and enhancing pipeline safety. These findings from pilot-scale testing offer valuable insights into advancing pipeline monitoring technologies and improving the reliability of underground pipeline systems.

fiber optic sensors↗

Resilience Through Data-Driven, Intelligent Designed Control: A Formal Methods Approach

The PNNL and GTRI team developed a strategy to integrate temporal logic rule specification for detection of cyber-intrusion in the source code and control algorithms of CPS using advanced cyber-data. The GTRI team utilized its capabilities in rule synthesis and temporal logic specifications for software assurance and verification to detect and predict impact of cyber-intrusions and malware in the computational and control algorithms of cyber-physical systems. The team also developed a testing and verification approach that could be used to validate the suggested approach against a realistic use-case CPS showcasing improvements in system impact prediction performance. Temporal logic offers a compact expression of events in absolute and relative time and has a formalized translation to state machines. As such, temporal logic rules can feasibly be synthesized to any system as a rule engine, with the process being formally verified to be correct. The goal here is to utilize temporal logic rules to detect cyber-attacks and manipulations in the computational algorithms and provide real-time software assurance and verification guarantees.

97 MATHEMATICS AND COMPUTING↗

Improving Robustness of Spectrogram Classifiers with Neural Stochastic Differential Equations

Signal analysis and classification is fraught with high levels of noise and perturbation. Computer-vision-based deep learning models applied to spectrograms have proven useful in the field of signal classification and detection; however, these methods aren't designed to handle the low signal-to-noise ratios inherent within non-vision signal processing tasks. While they are powerful, they are currently not the method of choice in the inherently noisy and dynamic critical infrastructure domain, such as smart-grid sensing, anomaly detection, and non-intrusive load monitoring. Currently, these models can be brittle, which makes them susceptible to noisy input. This also means they have sub-optimal stability of explanation outputs. Experts and technicians using these models to make decisions in real world scenarios need assurance that a model is performing as it is supposed to. The classification or prediction outputs it generates should be sound and grounded, not likely to change in the presence of shifting noise landscapes. In this work, we explore the idea of Neural Stochastic Differential Equations (NSDE's) to improve the robustness of models trained to classify time series data and the effect of NSDE's on the explainability of outputs. We then test the effectiveness of these approaches by applying them to a non-intrusive load monitoring (NILM) dataset that consists of simulated harmonic signals injected into a real building.

Brogan, Joel↗

A polarimetry-based field-deployable non-interruptive mirror soiling detection method

The soiling level of heliostat mirrors in Concentrated Solar Power (CSP) fields is one of the key factors that significantly influences optical efficiency. State-of-the-art methods of monitoring heliostats soiling levels still face various challenges, including slow speed, labor-intensive operations, resolution and accuracy constraints or interruptions to solar field operations. Here, we present a rapid, cost-effective, and non-intrusive method for mirror soiling detection based on polarimetric imaging, referred to as Polarimetric Imaging-based Mirror Soiling (PIMS). The compact PIMS device is designed for integration with unmanned aerial vehicles (UAVs), enabling rapid, large-area assessments of heliostat mirrors for efficient soiling detection. Our method utilizes the correlation between the Degree of Linear Polarization (DoLP) and surface soiling level based on Mie scattering theory and Monte Carlo simulations. Field deployment of the PIMS method requires minimal device installation, and its UAV-based operation allows for soiling detection without interrupting plant activities. The PIMS method holds the potential for mirror soiling detection across various concentrated solar power (CSP) plants and can be further adapted for other types of solar fields, such as parabolic trough systems.

CSP Field↗

A monolithic antineutrino detector for non-intrusive reactor monitoring

Recent advances in organic detection media have found applications in reactor antineutrino physics. One example is the Precision Oscillation and Spectrum Experiment (PROSPECT), which leveraged pulse-shape sensitivity to enable a successful surface deployment at the High Flux Isotope Reactor (HFIR), achieving a signal to background of 4:1. PROSPECT utilized almost 4 tonnes of 6 Li-doped pulse-shape sensitive liquid scintillator in a two-dimensional segmented array. It used a combination of pulse-shape sensitivity and position sensitivity via segmentation to reduce the most prominent form of correlated background for surface detectors — cosmogenic fast neutrons. These new liquids may enable detector designs that bring additional tools for reducing backgrounds while reducing engineering complexity. In this paper, we present an investigation into a detector design that exploits properties of these liquids by maximizing spectral and pulse-shape sensitivity via highly efficient photon detection. The detector utilizes photomultiplier tubes (PMTs) placed at the top and bottom of a right cylinder, with highly reflective white walls. This design sacrifices some position sensitivity for maximal photon efficiency. In conclusion, the design choice has consequences for the identification of the background and antineutrino sensitivity, which we examine.

Pulse shape↗

Monitoring of catalyst performance in CO2 lasers using frequency modulation spectroscopy with diode lasers

Closed-cycle CO2 laser operation with removal of O2 and regeneration of CO2 can be achieved by catalytic CO-O2 recombination. Both parametric studies of the optimum catalyst formulation and long-term performance tests require on line monitoring of CO, O2 and CO2 concentrations. There are several existing methods for molecular oxygen detection. These methods are either intrusive (such as electrochemical method or mass spectrometry) or very expensive (such as CARS, UV laser absorption). Researchers demonstrated a high-sensitivity spectroscopic measurement of O2 using the two-tone frequency modulation spectroscopy (FMS) technique with a near infrared GaAlAs diode laser. Besides its inexpensive cost, fast response time, nonintrusive measurements and high sensitivity, this technique may also be used to differentiate between isotopes due to its high spectroscopic resolution. This frequency modulation spectroscopy technique could also be applied for the on-line monitoring of CO and CO2 using InGaAsP diode lasers operation in the 1.55 microns region and H2O in the 1.3 microns region. The existence of single mode optical fibers at the near infrared region makes it possible to combine FMS with optical fiber technology. Optical fiber FMS is particularly suitable for making point-measurements at one or more locations in the CO2 laser/catalyst system.

Wang, Liang-Guo↗