Search NASA⌕ Search

SEARCH · Search NASA

Results for “Attack localization”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

High-Temperature Oxidation Behavior of FeCoCrNi+(Cu/Al)-Based High-Entropy Alloys in Humid Air

Previous studies showed some transition metal high-entropy alloy (HEA) compositions can have good oxidation resistance in air up to 800 °C. Four equiatomic HEAs have been developed based on FeCoCrNi with additions of Mn, Cu, Al or Al+Cu. The oxidation behavior of these HEAs was compared in humid (10 vol.% H2O) air at 800 °C for 100–500 h to investigate the influence of water vapor on the oxidation mechanisms. The Cu- and Al-containing alloys exhibited improved oxidation resistance over the Mn composition. For the Cu-containing alloy, a local attack of the Cu-rich phase was observed, which formed an Fe/Ni/Co/Cr spinel that was surrounded by Cr2O3. This oxide was thicker for the humid air atmosphere when compared to dry air, and the transition of the Cu oxide to the spinel was accelerated. The Al-containing HEA formed a thin Al2O3 scale with humidity suppressing AlN formation and forming a smoother oxide layer. The Al+Cu composition had the highest overall oxidation resistance (minimal local attack, no nitridation) and also showed a smooth oxide scale topography under humid air oxidation as opposed to a plate-like, rougher scale under dry air.

Crystallography↗

Influence of copper and aluminum substitution on high-temperature oxidation of the FeCoCrNiMn “Cantor” alloy

In this study, the oxidation behavior of FeCoCrNiMn (HEA + Mn) is compared to three modified HEAs manufactured by substituting Mn with Al, Cu, or Al + Cu. Oxidation tests were conducted between 600°C and 800°C for up to 500 h in synthetic air. Substitution of Mn leads to a significant improvement in the oxidation resistance for the three modified HEAs. For FeCoCrNiCu (HEA + Cu), a local attack of a Cu-rich phase was observed, leading to the formation of CuO blisters on the surface. The FeCoCrNiAl (HEA + Al) alloy was characterized by the formation of a thin Al 2 O 3 surface layer for all temperatures. However, for the HEA + Al alloy the formation of AlN was observed after 300 h at 800°C, leading to a partial breakdown of the protective scale. FeCoCrNiCuAl (HEA + Cu + Al) by far showed the best oxidation resistance, characterized by the formation of a highly protective Al 2 O 3 scale that effectively inhibited nitrogen penetration into the metal subsurface and local attack of the Cu-rich phase.

36 MATERIALS SCIENCE↗

Data Security Defense: Modeling and Detection of Synchrophasor Data Spoofing Attack for Grid Edge

Data security and cyberattack have become critical issues in the distributed power system where adversaries can swap the source information of sensors or even spoof and alter measurements. However, the cyber security of the power system is challenged by the unpredictability and stealth of the spoofing attacks. Here, to protect the data security at the grid edge, this paper developed a synchrophasor data spoofing attack detection framework based on the time-frequency feature extraction techniques including the short-time Fourier transform (STFT) and object detection network for real-time synchrophasor data categorization and spoofing attack localization. The proposed approach outperforms earlier work in terms of spoofing attack detection and offers a vital localization function employing distributed synchrophasor sensors.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Robust Resilient Signal Reconstruction under Adversarial Attacks

We consider the problem of signal reconstruction for a system under sparse signal corruption by a malicious agent. The reconstruction problem follows the standard error coding problem that has been studied extensively in the literature. We include a new challenge of robust estimation of the attack support. The problem is then cast as a constrained optimization problem merging promising techniques in the area of deep learning and estimation theory. A pruning algorithm is developed to reduce the "false positive" uncertainty of data-driven attack localization results, thereby improving the probability of correct signal reconstruction. Sufficient conditions for the correct reconstruction and the associated reconstruction error bounds are obtained for both exact and inexact attack support estimation. Moreover, a simulation of a water distribution system is presented to validate the proposed techniques.

Robust, Signal reconstruction, Resilient estimator↗

Effect of Oxidizing Impurities on the Corrosion Behavior of Structural Alloys Exposed to MgCl 2 Molten Salt Vapor

The corrosion behavior of structural alloys SS304 and IN617 when exposed to vapors of MgCl 2 molten salt at 764 °C for 100 h in an argon atmosphere was investigated as a function of the level of oxidizing impurities (e.g., NaOH) present in the salt. Increasing the concentration of oxidizing impurities in the salt caused an increase in corrosion in both structural alloys, as measured by Cr depletion layers. A poorly adhered oxide scale layer containing Mg, Al, and Cr was observed on the surface of the metals, and local attack was observed as well. The Ni-based IN617 showed lower Cr depletion and less scale formation than the Fe-based SS304. These results demonstrate that oxidizing impurities in the molten salt will impact the vapor phase corrosion for structural members exposed to the molten salt headspace. This finding is highly relevant for understanding the effects of the vapor phase in molten salt applications, including molten salt thermal energy storage, molten salt nuclear reactors, and molten salt electrochemistry.

25 ENERGY STORAGE↗

Effect of thermal treatments on electrochemical behavior of binder jetted 17-4 PH stainless steel

Binder jetted 17–4 PH stainless steel was post-processed to relate heat treatment, microstructure, and corrosion in 3.5 wt% NaCl. Specimens were sintered at 1380 or 1400 °C, solution-annealed at 1055 °C for 1 h, and aged at 482 °C for 1 h. Here, as-sintered parts showed α′-martensitic matrix with a δ-ferrite network and Cu-rich precipitates in ferrite; inclusions (MnS, NbC) promoted localized attack. solutionizing redistributed elements and reduced ferrite, while aging generated coherent Cu nano-precipitates. Corrosion resistance was highly sensitive to post-processing in which aged specimens exhibited the lowest corrosion current density and formed a thicker, stable Cr 2 O 3 -rich passive film, whereas sintered specimens degraded most. Pitting potential depended on sintering temperature and microstructure, with 1400 °C sintering yielding more positive pitting potentials and the best overall performance after aging. Although the 1400-solutionized condition showed a relatively noble pitting response versus 1380-solutionized, it displayed unstable corrosion kinetics attributed to an imperfect passive film linked to higher NbC density. XPS depth profiles corroborated these trends, showing thicker, more continuous Cr 2 O 3 in aged states and discontinuous/thinning oxides in less resistant conditions. Practically, high-temperature sintering (∼1400 °C) followed by solutionizing and aging is recommended, with further gains expected from reducing NbC/MnS populations and porosity via powder and process control.

36 MATERIALS SCIENCE↗

Corrosion of Zinc Cold Spray Coatings in a Wet Sweet and Sour Gas Environment

Internal corrosion is a problem for steel pipelines transporting natural gas or CO 2 containing water and partial pressures of H 2 S higher than 0.3 kPa (0.05 psi). This work aims to mitigate internal corrosion in steel pipelines transporting natural gas containing H 2 S using cold spray coatings. Two types of the cold spray binary metallic coatings (zinc chromium [ZnCr]. zinc niobium [ZnNb]) were studied using electrochemical techniques: potentiodynamic polarization, linear polarization resistance, and electrochemical impedance spectroscopy. The corrosion resistance of cold spray coatings (ZnCr, ZnNb) was evaluated in an environment containing 4 bar CO 2 pressure, simulating the partial pressures found in gas transmission lines over a solution of 3.5 wt% NaCl heated to 40°C. A concentration of 0.003 M Na 2 S 2 O 3 ·5H 2 O, corresponding to H 2 S partial pressures around 0.079 bar (1.146 psi), was used to simulate sour conditions. Postcorrosion surface characterization was performed using a scanning electron microscope (SEM) equipped with an energy-dispersive x-ray spectroscope (EDS) and x-ray diffraction analysis. The data showed that the presence of 0.003 M Na 2 S 2 O 3 ·5H 2 O shifted the corrosion potential to more anodic values and decreased the corrosion current density. Both coatings showed similar behavior after 1 h of exposure in the CO 2 /H 2 S environment, indicating that similar electrochemical reactions were occurring on ZnNb and ZnCr. SEM images and EDS surface analyses for specimens showed a significant change in the surface chemical composition of carbon steel coated with ZnNb and ZnCr after 24 h of immersion. In the presence of thiosulfate (under sour conditions), the formation of corrosion product layers (ZnCO 3 and ZnS) on top of ZnNb and ZnCr coatings increased their corrosion resistance, which helped to reduce their corrosion by a factor of 2. Under a sweet environment, the corrosion rates for steel coated with cold spray coatings after 14 d of exposure are lower than that for galvanized steel by a factor of 5 due to the ZnCO 3 layer formed on top of the coatings. The ZnCO 3 layer formed on the steel surface acts as a physical barrier against corrosion by blocking the diffusion of corrosive species to the surface. No localized attack was observed. ZnCr Cold spray coating with defect showed promising corrosion protection against CO 2 corrosion (sweet corrosion) after 14 d of exposure to a CO 2 environment. Here, the scratch on the coating simulated damage created in service, and it was deep enough to expose the substrate material (steel). The formation of zinc oxide (ZnO) and zinc carbonate (ZnCO 3 ) on the scratch confirmed the cathodic protection of the steel by ZnCr and ZnNb coatings.

36 MATERIALS SCIENCE↗

A distributed voltage inference framework for cyber-physical attacks detection and localization in active distribution grids

The transition to active distribution grids with real-time monitoring and control depends on the proliferation of advanced communication networks and devices. This paradigm shift towards a cyber-physical architecture also introduces new vulnerabilities for adversaries to exploit and launch sophisticated cyber-physical attacks targeting grid observability. Current research highlights the challenges in distinguishing attacks on voltage phasor or nodal injection measurements and isolating multi-source attack locations in a multiphase distribution grid. The attack detection and localization methods in literature face accuracy issues, applications across diverse attack scenarios, or scalability limits. Here, to bridge these gaps, this paper proposes a distributed Voltage Inference framework for real-time detection and localization of cyber-physical attacks, addressing scalability, adaptability, and accuracy challenges in state-of-the-art methods. The proposed methodology leverages the distributed nature of the Voltage Inference framework through a two-step process of prediction and correction, together with a tractable graph partitioning approach, providing a reliable solution to identify compromised measurement sources and facilitate isolation. Extensive testing on IEEE 13 and 123-node distribution feeders underscores the algorithm’s efficacy, enhancing the security and resilience of active distribution grids against evolving cyber threats. Additionally, Hardware-in-the-Loop (HIL) implementation validates the proposed strategy’s practical applicability in real-world scenarios.

active distribution grids↗

Machine Learning-based False Data Injection Attack Detection and Localization in Power Grids

Cyberattacks on critical infrastructures can be catastrophic and bring nations to their knees. Therefore, detecting these attacks is crucial and challenging. This paper presents a novel approach for detecting and locating cyberattacks affecting an electrical power system. The adversary employs a man-in-the-middle technique to inject false data into the communication between distributed energy resources (DER) and Microgrid Controller (MGC) with the goal of disrupting power delivery. The approach for detection and localization is based on integrating multiple machine learning-based anomaly detection models that combine network traffic data and grid measurements. Experiments are performed to assess the method's performance using a hardware-in-the-loop real-time simulation testbed which includes Modbus TCP/IP communication. Power system topology and operating conditions are based on actual topology and real-world data provided by the Holy Cross Energy utility network. Results confirm that the method can be successfully employed for detecting and localizing cyberattacks.

Leao, Bruno P.↗

Attack detection and localization with adaptive thresholding

According to some embodiments, a system, method, and non-transitory computer readable medium are provided comprising a plurality of real-time monitoring nodes to receive streams of monitoring node signal values over time that represent a current operation of the cyber physical system; and a threat detection computer platform, coupled to the plurality of real-time monitoring nodes, to: receive the monitoring node signal values; compute an anomaly score; compare the anomaly score with an adaptive threshold; and detect that one of a particular monitoring node and a system is outside a decision boundary based on the comparison, and classify that particular monitoring node or system as anomalous. Numerous other aspects are provided.

Abbaszadeh, Masoud↗

Advancing Cyber-Attack Detection in Power Systems: A Comparative Study of Machine Learning and Graph Neural Network Approaches

This paper explores the detection and localization of cyber-attacks on power systems, focusing on comparing conventional machine learning (ML) and deep learning methods, and graph neural network (GNN)-based techniques. We assess the detection accuracy of these approaches and their potential to pinpoint the locations of specific buses under attack. Given the demonstrated success of GNNs in other time series anomaly detection applications, we aim to evaluate their performance within the context of power systems cyber-attack. Utilizing the IEEE 68-bus system, we simulated four types of attacks to test the selected approaches. Our results indicate that GNN-based methods outperform conventional machine learning and deep learning models in detection. Additionally, GNNs show promise in accurately localizing attacks for simple scenarios, although they still face challenges in more complex cases.

artificial intelligence↗

Adaptive Cyber-Physical Resilience for Building Control Systems

The main goal of the project is to develop an AI-based process layer cybersecurity suite for detection, isolation and mitigation of cyber-attack effects on operation of building energy management systems (BEMS). The following constituent key technologies were developed under the program towards fulfilling the program objectives: (1) developed a high fidelity BEMS testbed for generation of training data and validation of developed technologies; (2) developed a physics informed ML based attack detection and localization module (ADL) capable of detecting high impact stealthy attacks (HISA - attacks causing 30% energy utilization but no immediate visible impact otherwise) with 98% accuracy; (3) developed a methodology to determine ’representative days’ to limit the data required for training; (4) developed a virtual sensing system that can reconstruct affected sensors with 10% error for the same HISA set; (5) developed a resilient model predictive control system that can continue operation of the BEMS without jeopardizing stability for the HISA set; and (6) integrated and deployed all the constituent modules and demonstrated the efficacy of the technology in real-time in a hardware in loop simulation.

42 ENGINEERING↗

Aerodynamic characterization of two tandem wind turbines under yaw misalignment control using actuator line model

Yaw control has proven to be promising in alleviating the wake effects that plague the efficiency of wind farms. In this work, the actuator line modeling (ALM) method is adopted to simulate the flows over two tandem turbines distanced by 3–7 rotor diameters, with the yaw angle of the upstream rotor varying from γ 1 = 0° to 50°. The aim is to provide a comprehensive aerodynamic characterization of this simple wind farm under yaw misalignment control. With increasing yaw angle, the power generated by the downstream rotor increases, compensating the power loss in the upstream rotor, and resulting in significantly higher total power of the two turbines than that without yaw control. The maximum power output is achieved as the upstream wake of the yawed rotor is redirected away from the downstream rotor plane. Behind the downstream rotor, the secondary steering phenomenon is observed, where the wake is also redirected from the centerline. The use of the actuator line model also reveal unsteady aerodynamic characteristics that cannot be captured by lower-fidelity models. For the upstream rotor, the yaw misalignment results in time-varying change in the local angle of attack on the blade, giving rise to unsteady loading. The downstream rotor is partially submerged in the deflected wake incurred by the yawed upstream rotor. As the blade revolves into and out of the wake deficit, the blade experiences cyclic loading, leading to even stronger fluctuations in the aerodynamic loads than the upstream rotor. These analysis provides a comprehensive understanding of the yaw control effects on the two tandem rotors from the perspectives of aerodynamic performance, wake profiles, and unsteady characteristics. In conclusion, the insights gained from the present study can aid the design of collective yaw control strategies of wind farms, and lay the foundation for assessing the fatigue damage associated with yaw misalignment.

17 WIND ENERGY↗

Performance Evaluation of Vertical Federated Machine Learning Against Adversarial Threats on Wide-Area Control System: Preprint

Federated machine learning (FL) is gaining significant popularity to develop cybersecurity solutions in power grids because of its advanced capability to support decentralized data handing at local devices, its privacy preservation, and its low-bandwidth requirement. However, the evolving adversarial machine learning (AML) threats raise significant concerns for the cybersecurity of FL architectures. The FL-based split neural network (SplitNN) achieves high performance through the decentralized training of local neural network models while preserving data privacy across multiple entities. In this paper, we propose a methodology for evaluating the performance of a vertical FLbased anomaly detector against different types of AML attacks, including denial-of-service attacks, adversarial data injection attacks, and replay attacks on the trained local models deployed in the grid network. For a case study, we consider the modified IEEE 13-bus system, and we develop SplitNN-based binary and multiclass classification models to detect, locate, and identify different types of data integrity attacks on the volt-watt control with two pooling layers: maximum pooling and AvgPool. Our experimental results, computed through performance metrics, reveal that the severity of these AML attacks varies with the integrated pooling mechanism, the type of classification model, and the nature of the cyberattack. Further, the AML attacks negatively impacted the prediction time per sample for the pretrained SplitNN during the online testing.

adversarial threats↗

Real-World Cyber Security Demonstration for Networked Electric Drives

In this article, we present the design and implementation of a cyber-physical security testbed for networked electric drive systems, aimed at conducting real-world security demonstrations. To our knowledge, this is one of the first security testbeds for networked electric drives, seamlessly integrating the domains of power electronics and computer science, and cybersecurity. By doing so, the testbed offers a comprehensive platform to explore and understand the intricate and often complex interactions between cyber and physical systems. The core of our testbed consists of four electric machine drives, meticulously configured to emulate small-scale but realistic information technology (IT) and operational technology (OT) networks. This setup both provides a controlled environment for simulating a wide array of cyber-attacks, and mirrors potential real-world attack scenarios with a high degree of fidelity. The testbed serves as an invaluable resource for the study of cyber-physical security, offering a practical and dynamic platform for testing and validating cybersecurity measures in the context of networked electric drive systems. As a concrete example of the testbed's capabilities, we have developed and implemented a Python-based script designed to execute step-stone attacks over a wireless local area network (WLAN). This script leverages a sequence of target IP addresses, simulating a real-world attack vector that could be exploited by adversaries. To counteract such threats, we demonstrate the efficacy of our developed cyber-attack detection algorithms, which are integral to our testbed's security framework. Furthermore, the testbed incorporates a real-time visualization system using InfluxDB and Grafana, providing a dynamic and interactive representation of networked electric drives and their associated security monitoring mechanisms. This visualization component not only enhances the testbed's usability but also offers insightful, real-time data for researchers and practitioners, thereby facilitating a deeper understanding of cyber-physical security dynamics in networked electric drive systems.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Comparison of Socio-Technical Threat Models

Given the adoption of emerging technologies and the increasing complexity of managing such systems with a lifecycle much shorter than that of critical infrastructure systems, there is a practical need to be able to analyze sociotechnical dependencies and their associated evolving risks. Threat models based on social influence techniques can be used to implement adversarial tactics analogous to the cyber kill chain and attested to within the MITRE ATT&CK for ICS framework including Initial Access, Persistence, Collection, and Impact. Furthermore, as with cyber disruptions, the impact of social influence threat models can have an asymmetric impact that is not spatially-localized. Finally, unlike cyber attacks with a reasonably short duration (ransomware takes days to months), social influence based attacks have the potential to persist for much longer as they are based on long-term strategic infrastructure investments within the private sector. Given the increased importance of electric vehicle charging stations as a long-term, strategic infrastructure investment within the Energy and Transportation Sectors, we provide initial results that compare the impact of a Loss of Availability (T0826) realized through cyber and social influence based threat models. The analysis employs techniques from automated reasoning and measures of network complexity to understand evolving dominance of EV payment and charging networks within geographic region of interest. Within this context, we compare the impact of a loss of availability due to ransomware versus that of loss of support due to a merger and acquisition. Results across several different metro areas will be provided.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Exploiting the Local Parabolic Landscapes of Adversarial Losses to Accelerate Black-Box Adversarial Attack

Existing black-box adversarial attacks on image classifiers update the perturbation at each iteration from only a small number of queries of the loss function. Since the queries contain very limited information about the loss, black-box methods usually require much more queries than white-box methods. We propose to improve the query efficiency of black-box methods by exploiting the smoothness of the local loss landscape. However, many adversarial losses are not locally smooth with respect to pixel perturbations. To resolve this issue, our first contribution is to theoretically and experimentally justify that the adversarial losses of many standard and robust image classifiers behave like parabolas with respect to perturbations in the Fourier domain. Our second contribution is to exploit the parabolic landscape to build a quadratic approximation of the loss around the current state, and use this approximation to interpolate the loss value as well as update the perturbation without additional queries. Since the local region is already informed by the quadratic fitting, we use large perturbation steps to explore far areas. We demonstrate the efficiency of our method on MNIST, CIFAR-10 and ImageNet datasets for various standard and robust models, as well as on Google Cloud Vision. The experimental results show that exploiting the loss landscape can help significantly reduce the number of queries and increase the success rate. Our codes are available at https://github.com/HoangATran/BABIES.

Tran, Hoang↗