Search NASA⌕ Search

SEARCH · Search NASA

Results for “Vulnerability”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 163 records · Page 9

Screening Tool for Equitable Adoption and Deployment of Solar (STEADy Solar)

The Screening Tool for Equitable Adoption and DeploYment of Solar (STEADy Solar) is a database and mapping tool designed to promoting clean energy investments for low-income communities across the United States. The tool indicates locations that may be eligible for the Investment Tax Credit bonus adders defined in the 2022 Inflation Reduction Act (IRA) and combines this information with demographics, social vulnerability, solar technical potential, solar economics (modeled net present value), and building counts by use-type. It can be used by states, municipalities, community-based organizations, developers, and researchers to identify sites where solar projects may be economical and where federal incentives may be available to support equitable adoption of solar. Specific values include: Areas eligible for the Energy Communities Tax Credit Bonus Program (including brownfield site counts) Areas eligible for the Low Income Communities Bonus Credit Program (including Tribal Lands, and covered affordable housing project counts) Areas categorized as disadvantaged by Justice40 Commercial and Residential Solar economics characterized by the Net Present Value and Simple Payback Period Total Population, Race, and Ethnicity Median Household Income, Poverty rate, Household Tenure Social Vulnerability Count of buildings, developable rooftop solar capacity (in kWdc) and estimated annual generation potential (in kWh) on four building types: Government General Services, Government Emergency Response, Grade Schools, and Colleges/Universities. The linked report describes the STEADy dataset metadata and presents high level insights from the data. The downloadable and formatted excel dataset makes it easy for users to gain insights for their locations. Supporting .csv and shapefiles provide users with the full data to run their own analyses on equitable solar siting.

14 SOLAR ENERGY↗

Preventive Power Outage Estimation Based on A Novel Scenario Clustering Strategy: Preprint

The increasing occurrence of extreme weather events is challenging the power grid operation. In front of the extreme weather, the system operator is responsible for estimating the power outage and scheduling the restoration resources. This paper proposes an outage evaluation framework to identify the possible unserved load profiles, vulnerable areas, and mobile energy adequacy. The predicted vulnerable lines of an outage prediction model tool are utilized to generate numerous faulted line scenarios. Next, each scenario's nodal unserved load profile is obtained by solving a three-phase restoration model that considers the schedule of repair crews and mobile energy resources. Then, a novel scenario clustering strategy is developed to cluster the unserved load profiles into multiple representative ones for straightforward analysis. Finally, case studies on a distribution system evaluate the damage level brought by extreme weather and verify the effectiveness of the proposed scenario clustering strategy.

mobile energy resources↗

The Meaning of Risk for Safety, Security, and Safeguards in the Design of Advanced Nuclear Reactors

What is the meaning of risk as it applies to the design of advanced reactors in the disciplines of safety, security, and safeguards? How can we find common terminology for the concept of risk and how can we find interfaces between these disciplines? These are important questions that should be explored in order that they may be applied in an integrated manner for the most effective and efficient design approaches. Eliminating or minimizing risks is a key design driver that motivates and informs the development of nuclear reactors. For safety, risk is well understood and applied in Probabilistic Risk Assessments. For security, the risk-based concepts of vulnerability assessments and vital areas are all considered in designing security systems. For safeguards, the concept of risk is not formally defined, as it relates to the design and operation of nuclear reactors. International nuclear safeguards seek to reduce the risk of proliferation in the nuclear fuel cycle and as such the concept of risk does exist. Therefore, the current understanding of the “3S’ approach, which seeks to find the interfaces and conflicts between safety, security, and safeguards requires a thorough understanding of the role that the reduction of risk plays in all three disciplines. The intersection of risk for safety and security is now being developed as there is a strong correlation between reactor design and operations and their vulnerability to sabotage. The intersection of risk for security and safeguards has to date chiefly been focused on the nuclear material control and accounting systems, which are relied on by both the operator (State) and the IAEA. This paper explores the concept of risk in each of the three disciplines, how they interact, potential conflicts and interfaces , how these might be addressed and leveraged, and a notional framework for how this could be achieved.

Kovacic, Donald N↗

Hiding-in-Plain-Sight (HiPS) Attack on CLIP for Targetted Object Removal from Images

Machine learning models are known to be vulnerable to adversarial attacks, but prior works have mostly focused on single-modalities. With the rise of large multi-modal models (LMMs) like CLIP, which combine vision and language capabilities, new vulnerabilities have emerged. However, these multimodal targeted attacks aim to completely change the model's output to what the adversary wants. In many realistic scenarios, an adversary might seek to make only subtle modifications to the output, so that the changes go unnoticed by downstream models or even by humans. We introduce Hiding-in-Plain-Sight (HiPS) attacks, a novel class of adversarial attacks that subtly modifies model predictions by selectively concealing target object(s), as if the target object was absent from the scene. We propose two HiPS attack variants, HiPS-cls and HiPS-cap, and demonstrate their effectiveness in transferring to downstream image captioning models, such as CLIP-Cap, for targeted object removal from image captions.

Daw, Arka [ORNL] (ORCID:0009000633191271)↗

Coordinated Thermal Safety Attack and Defense on EV Battery Management Systems

Battery temperature sensor and battery current sensor data which are key sensing inputs to the Battery Management Controllers in electric vehicles, are vulnerable to possible cyber/ physical manipulation due to known vulnerabilities inherited from CAN bus technology that is used for in-vehicle communications between electronic control units that transfer sensing and control data. In this paper, we first create a simulation that enables us to evaluate impact of cyber physical attacks on electric vehicle battery management system in a controlled environment that violates thermal safety. Specifically, we emulate a Level 3 - DC fast charging system with SAE J1772/CCS, integrated with standard charging controls and thermal safety controls on EVs, and various sensing data flows. Second, we propose a coordinated current and battery temperature attack that has crippling economic, and safety impacts. Third, we quantify the usability, economic and safety impacts of such attacks as a function of the extent of data manipulation. Finally, we propose a physics model driven detection technique to detect presence of such attacks.

25 ENERGY STORAGE↗

Open Source Intelligence for Cybersecurity Events via Twitter Data

Open-Source Intelligence (OSINT) is largely regarded as a necessary component for cybersecurity intelligence gathering to secure network systems. With the advancement of artificial intelligence (AI) and increasing usage of social media, like Twitter, we have a unique opportunity to obtain and aggregate information from social media. In this study, we propose an AI-based scheme capable of automatically pulling information from Twitter, filtering out security-irrelevant tweets, performing natural language analysis to correlate the tweets about each cybersecurity event (e.g., a malware campaign), and validating the information. This scheme has many applications, such as providing a means for security operators to gain insight into ongoing events and helping them prioritize vulnerabilities to deal with. To give examples of the possible uses, we present three case studies demonstrating the event discovery and investigation processes. We also examine the potential of OSINT for identifying the network protocols associated with specific events, which can aid in the mitigation procedures by informing operators if the vulnerability is exploitable given their system’s network configurations.

Dale, Dakota↗

ILLICIT TRANSIT INTERDICTION GLOBAL ANALYSIS

This study aims to enhance the security of radioactive materials during transport by analyzing commonalities in cargo thefts conducted by non-state groups such as thieves and terrorists. This research focuses on identifying patterns and trends in the methods used to steal high-value cargo, with the goal of applying these insights to improve transport security of radioactive materials. Key questions addressed include the frequency of specific tools, techniques, and insider involvement in thefts, as well as the use of weapons, electronic jamming equipment, and specialized tools. Findings will inform security design improvements and industry practices to mitigate vulnerabilities. The study involves a comprehensive review of literature and case studies, utilizing data sources from 2018 to 2023. Articles will be selected based on their relevance to thefts of valuable cargo in transit, with a focus on incidents involving non-state actors. The methodology will include statistical and inferential analysis to identify trends, with results visualized through pie charts, frequency analyses, and terrain maps. The discussion will highlight the implications of findings and provide actionable recommendations for strengthening security measures. Limitations such as data availability and reporting inconsistencies will be acknowledged. Suggestions for future improvements will be constructed using existing case studies and expert feedback. The study’s outcomes aim to raise awareness within the industry, inform policy decisions, and enhance security protocols for radioactive material transport. Metrics for impact include the potential publication of findings, presentations at conferences to raise awareness, and the subsequent actions taken by stakeholders based on the research. By identifying trends and vulnerabilities and suggesting improvements, this research contributes to preventing the illicit use of nuclear and radiological materials.

Zineddin, Dr. Z. [ORNL] (ORCID:0009000848740725)↗

Data Centers and Digital Assurance Workshop 2 – Prioritizing Digital Assurance Challenges, Session 2

The second session of the TADA (Technical Assistance for Digital Assurance) Data Centers Cohort, held on November 10, 2025, focused on prioritizing digital assurance challenges at the intersection of data centers and the electric grid. Building on the foundational concepts introduced in Workshop 1, this session deepened the application of the Threat–Vulnerability–Consequence (TVC) framework and emphasized the urgency of addressing cybersecurity, supply chain integrity, and operational reliability. Participants explored the growing convergence of digital and physical systems, the expanding attack surface due to global supply chain dependencies, and the implications of AI-driven load behavior. Real-world incidents—including the Volt Typhoon campaign and vulnerabilities in Solarman and Deye platforms—were analyzed to illustrate the risks of unpatched systems, insecure APIs, and inadequate vendor oversight. Key themes included architecture and interface weaknesses, governance gaps, and human and procedural shortcomings. The workshop also examined the evolving regulatory landscape, highlighting new federal mandates around Foreign Entity of Concern (FEOC) compliance and large-load reliability standards. Through interactive exercises, stakeholders ranked and mapped digital assurance risks from their respective perspectives—utilities, operators, and vendors—laying the groundwork for mitigation strategies and shared accountability models to be developed in Workshop 3. Session 2 of 3.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Smart Inverters, Dumb Risk: Taking Control of IBR Security in the Digital Age

This presentation addresses the security challenges posed by Inverter-Based Resources (IBRs) in the modern energy landscape. The presentation highlights the vulnerabilities and risks associated with IBRs, including the potential for cyber-attacks, the impact of insecure defaults, and the systemic risks posed by supply chain dependencies. Key topics covered include: 1) The increasing digital transformation in energy systems and the associated security risks. 2) Specific vulnerabilities in IBRs, including weak passwords, hardcoded credentials, and insecure web application interfaces. 3) The implications of persistent connectivity and the strategic risks posed by foreign-manufactured components. 4) The role of regulatory frameworks, such as NERC CIP, in addressing these challenges and the limitations of current oversight. 5) Practical solutions for mitigating risks, including secure design practices, vendor risk assessments, and the importance of strong passwords and role-based access control. The presentation underscores the necessity of a comprehensive, system-of-systems approach to securing IBRs, emphasizing the need for collaboration across various stakeholders, including operators, developers, and regulators, to ensure the resilience and security of the energy grid.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Braxton Marlatt Intern Poster

The Internet of Things (IoT) encompasses a vast network of interconnected devices embedded with software, sensors, and network connectivity, enabling data collection and exchange. While IoT technology revolutionizes various industries, it also introduces significant security challenges. This research focuses on enhancing IoT security through the implementation of Zero Trust Architecture concepts, specifically targeting the Network and Device pillars of the Cybersecurity and Infrastructure Security Agency’s Zero Trust Maturity Model. By generating Codified Attack Surfaces (CAS) using custom Structured Threat Information eXpression bundles, this project aims to provide enhanced visibility into network communications, detect vulnerabilities in device firmware, and improve the overall security posture for IoT devices and networks. The methodology involves defining custom STIX schema and objects, collecting data from intra-IoT traffic, external network traffic, and firmware analysis, and automating the conversion and correlation of this data into STIX bundles. The automated generation of attack surfaces offers comprehensive insights into activity, vulnerabilities, and anomalies within an IoT environment, enabling proactive threat identification and mitigation.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Advanced Transmission Technologies – GETs and HPCs Session 2: Advanced Power Flow Control and Transmission Topology Optimization

The INL TADA GETs Cohort Session 2, held on November 7, 2025, conducted in collaboration with ScottMadden, focused on two core Advanced Transmission Technologies (ATTs): Advanced Power Flow Control (APFC) and Transmission Topology Optimization (TTO). These technologies are pivotal in enhancing grid flexibility, reliability, and cybersecurity resilience. APFC, particularly through modular FACTS devices like Modular Static Synchronous Series Compensators (M-SSSCs), enables dynamic voltage injection to reroute power flows. The session highlighted the deployment benefits of APFC, such as rapid installation, minimal civil works, and re-deployability. Regulatory drivers like FERC Order 2023 mandate the inclusion of Grid-Enhancing Technologies (GETs) in interconnection studies. Case studies from Central Hudson, CAISO, and National Grid (UK) demonstrated APFC’s effectiveness in congestion relief and cost savings. The session also addressed cybersecurity concerns, including firmware vulnerabilities, SCADA integration risks, and supply chain dependencies. Participants engaged in interactive exercises to rank cybersecurity and supply chain risks, emphasizing the need for robust digital assurance strategies. TTO involves software-based reconfiguration of transmission networks to optimize power flow without new infrastructure. The session showcased its operational value, with examples from SPP, PJM, and MISO showing significant congestion cost reductions. Cybersecurity vulnerabilities were discussed, particularly in API security and software supply chains, referencing incidents like SolarWinds and attacks on Danish utilities. Digital assurance exercises explored worst-case scenarios, attack paths, and mitigation responsibilities between vendors and utilities. Reliability challenges such as algorithm stability, vendor dependency, and operator trust were also examined. Cross-cutting themes emphasized the importance of digital assurance tools, including Software Bills of Materials (SBOMs) and hardware-in-loop testing. Human performance, training, and operational confidence were identified as critical enablers of technology adoption. The session concluded with a preview of Session 3, which will focus on High Performance Conductors (HPCs) and risk-based cybersecurity tools. Session 2 of 3.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Yesterday’s extremes, today’s new normal: flood risk in the Kathmandu Valley, Nepal

Unplanned urban growth has left many cities increasingly vulnerable to extreme rainfall events, particularly in regions with inadequate drainage infrastructures and development encroaching on natural floodplains. Here, in this perspective paper, we examine the September 2024 floods that struck Central Nepal, triggered by a persistent low-pressure system and enhanced by converging moisture flows from the Arabian Sea and the Bay of Bengal which led to widespread catastrophic damage. In the Kathmandu Valley, floodwaters expanded to more than 2.5 times the bankfull water extent, causing significant damage to housing, transportation network, and critical infrastructure, displacing thousands of residents, and severely disrupting urban services. This event highlights the urgent need for improved flood management strategies that integrate both structural and non-structural measures into the infrastructure development. While early warning systems provided critical lead time, challenges remain in reducing forecasting uncertainties and improving communication across government agencies and with local communities. A forward-looking approach is essential, including probabilistic flood forecasting systems, sustainable floodplain management, risk-sensitive land use planning, climate- and disaster- resilient infrastructure development, and the integration of nature-based solutions like urban green and blue spaces to mitigate flood impacts. By involving local communities in planning and preparedness efforts, particularly through citizen science initiatives, and engagement with underserved and disadvantaged communities, Nepal can better adapt to the growing risks posed by extreme rainfall and urban flooding and enhance long-term disaster resilience in rapidly urbanizing areas like Kathmandu Valley.

Kathmandu Valley↗

Data Repository for Multi-Objective Urban Observational Strategies: A risk-based framework for expanding flood sensor networks.

These data support the manuscript "Multi-Objective Urban Observational Strategies: A risk-based framework for expanding flood sensor networks." These data are generated to allow water managers to reason about optimal locations to expand a flood observation system from multiple perspectives, specifically focusing on flood hazards, and population exposure to flooding. The data included are a) a shapefile of individual sensor locations b) a shapefile of river reach catchments, c) raster of FEMA flood likelihood layers d) shapefile of population locations and population socioeconomic characteristics. The code is written in R and includes all files necessary to generate the figures for the associated manuscript. Interactive maps of the final calculated maps of hazard, vulnerability, exposure, and risk are also included as html files.

54 ENVIRONMENTAL SCIENCES↗

Adapting Traditional Hazards Analysis Methods to Address Cyber Risks

Traditional hazards analysis (HA) methods, originally developed to address physical and operational risks, often fall short when it comes to identifying and mitigating cyber threats. These cyber threats pose unique and evolving risks to critical infrastructure and industrial control systems (ICS). This report explores the integration of Cyber-Informed Engineering (CIE) principles into existing HA methods to enhance their ability to address cyber-induced risks. CIE provides organizations with a practical, cost-effective approach to closing the gap between traditional HA methods and the need for cyber risk mitigation. By leveraging existing safety processes and controls, CIE allows users to examine and mitigate cyber vulnerabilities without overhauling existing HA methods. This report identifies areas where HA and CIE naturally align and where their approaches diverge. It emphasizes how CIE principles can be used to adapt HA methods, broadening their scope to include cyber risks and enabling the mitigation of cyber- induced impacts alongside traditional hazards and failure scenarios. This report examines how CIE can be applied across various HA methods—such as Hazard and Operability Studies (HAZOP), Probabilistic Risk Assessment (PRA), Failure Modes and Effects Analysis (FMEA), Systems-Theoretic Process Analysis (STPA), Hazard and Consequence Analysis for Digital Systems (HAZCADS), and Layers of Protection Analysis (LOPA). It provides strategies for integrating CIE to strengthen the identification, assessment, and mitigation of cyber-induced risks. The findings offer a structured entry point for organizations to embed CIE concepts into hazards and safety analyses, as well as broader engineering processes, ultimately supporting the design and operation of a more resilient infrastructure.

42 ENGINEERING↗

Adapting Traditional Hazards Analysis Methods to Address Cyber Risks

Traditional hazards analysis (HA) methods, originally developed to address physical and operational risks, often fall short when it comes to identifying and mitigating cyber threats. These cyber threats pose unique and evolving risks to critical infrastructure and industrial control systems (ICS). This report explores the integration of Cyber-Informed Engineering (CIE) principles into existing HA methods to enhance their ability to address cyber-induced risks. CIE provides organizations with a practical, cost-effective approach to closing the gap between traditional HA methods and the need for cyber risk mitigation. By leveraging existing safety processes and controls, CIE allows users to examine and mitigate cyber vulnerabilities without overhauling existing HA methods. This report identifies areas where HA and CIE naturally align and where their approaches diverge. It emphasizes how CIE principles can be used to adapt HA methods, broadening their scope to include cyber risks and enabling the mitigation of cyber- induced impacts alongside traditional hazards and failure scenarios. This report examines how CIE can be applied across various HA methods—such as Hazard and Operability Studies (HAZOP), Probabilistic Risk Assessment (PRA), Failure Modes and Effects Analysis (FMEA), Systems-Theoretic Process Analysis (STPA), Hazard and Consequence Analysis for Digital Systems (HAZCADS), and Layers of Protection Analysis (LOPA). It provides strategies for integrating CIE to strengthen the identification, assessment, and mitigation of cyber-induced risks. The findings offer a structured entry point for organizations to embed CIE concepts into hazards and safety analyses, as well as broader engineering processes, ultimately supporting the design and operation of a more resilient infrastructure.

42 - ENGINEERING↗

Supporting U.S. National Security Through Cybersecurity Partnerships

At NLR, we're studying energy evolutions and threats to understand the challenges they pose and uncover ways to leverage grid advancements to achieve more secure, defensible, and reliable systems. Our integrated research approach bridges the gap between cyber threats and real-world consequences to deliver actionable solutions that reduce vulnerabilities and help strengthen U.S. national security.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Quantifying Twist Angles in Cuprate Heterostructures with Anisotropic Raman Signatures

Artificially engineered twisted van der Waals (vdW) heterostructures have unlocked new pathways for exploring emergent quantum phenomena and strongly correlated electronic states. Many of these phenomena are highly sensitive to the twist angle, which can be deliberately tuned to tailor the interlayer interactions. This makes the twist angle a critical tunable parameter, emphasizing the need for precise control and accurate characterization during device fabrication. In particular, twisted cuprate heterostructures based on Bi 2 Sr 2 CaCu 2 O 8 + x (BSCCO) have demonstrated angle-dependent superconducting properties, positioning the twist angle as a key tunable parameter. However, the twisted interface is highly unstable under ambient conditions and vulnerable to damage from conventional characterization tools such as electron microscopy or scanning probe techniques. In this work, a fully non-invasive, polarization-resolved Raman spectroscopy approach is introduced for determining twist angles in artificially stacked BSCCO heterostructures. By analyzing twist-dependent anisotropic vibrational Raman modes, particularly utilizing the out-of-plane A 1g vibrational mode of Bi/Sr at ≈116 cm −1 , clear optical fingerprints of the rotational misalignment between cuprate layers are identified. The high-resolution confocal Raman setup, equipped with polarization control and RayShield filtering down to 10 cm −1 , allows for reliable and reproducible measurements without compromising the material's structural integrity.

75 CONDENSED MATTER PHYSICS, SUPERCONDUCTIVITY AND↗

Humins-Derived Hard Carbon as a Low-Cost Material for Sodium-Ion Battery Anodes

The growing demand for sodium-ion batteries (SIBs) in grid storage underscores the need for electrode materials that balance performance and cost, including sustainable and robust carbon sources. The equitable and abundant distribution of materials for SIBs, along with their superior low-temperature performance, safety, and fast-charging capability, further distinguishes them from lithium-ion batteries (LIBs). Hard carbon (HC) is the state-of-the-art anode for SIBs, but current commercial HC production is localized mostly to one region of the world, raising concerns about supply chain vulnerability, critical material dependency, and environmental aspects. Here, the first demonstration of humins, an abundant biorefinery byproduct, as a precursor for HC anodes for sodium-ion storage is reported. Humins were carbonized at 1100 degrees C-1300 degrees C, and the resulting materials were subjected to comprehensive materials and electrochemical characterization. Among the temperatures studied, humins-derived hard carbon synthesized at 1200 degrees C delivers an initial reversible capacity 270mA h g-1 , with stable cycling performance up to 500 cycles and excellent rate capability, representing the optimal performance. This study establishes humins as a promising and low-cost carbon source that provides a route to mitigate supply chain risks and valorizes an underutilized biorefinery waste stream for high-performance SIB anodes.

25 ENERGY STORAGE↗