Search NASA⌕ Search

SEARCH · Search NASA

Results for “cyberattack”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Demystifying Cyberattacks: Potential for Securing Energy Systems With Explainable AI : Preprint

Modernization of energy systems has led to in- creased interactions among multiple critical infrastructures and diverse stakeholders making the challenge of operational decision making more complex and at times beyond cognitive capabilities of human operators. The state-of-the-art machine learning and deep learning approaches show promise of supporting users with complex decision-making challenges, such as those occurring in our rapidly transforming cyber-physical energy systems. However, successful adoption of data-driven decision support technology for critical infrastructure will be dependent on the ability of these technologies to be trustworthy and contextually interpretable. In this paper, we investigate the feasibility of implementing XAI for interpretable detection of cyberattacks in the energy system. Leveraging a proof-of-concept simulation use case of detection of a data falsification attack on a photovoltaic system using XGBoost algorithm, we demonstrate how Local Interpretable Model-Agnostic Explanations (LIME), a flavor XAI approach, can help provide contextual and actionable interpretation of cyberattack detection.

artificial intelligence↗

Impact of Cyber Threat Awareness on Driver Response to an Unexpected Vehicle Cyberattack

Here, the integration of advanced cyber-physical systems in heavy vehicles introduces new vulnerabilities by expanding the possibility of cyberattacks. The objective of this study is to evaluate (1) how threat awareness influences driver response to an unexpected cyberattack, (2) how the provision of a basic cyberattack response protocol influences driver performance, and (3) how professionally trained versus standard drivers compare in their responses to a cyberattack. An on-road driving study (N = 50) was conducted using a medium heavy-duty vehicle. Participants were divided into three groups: Control, which remained unaware of any potential cyberattack; Aware, which was informed about the potential cyberattack; and Aware + Protocol, which received the same warning as the Aware group with the addition of a basic cyberattack response protocol. An instrument cluster cyberattack was executed at the same location for all participants. The findings highlight the essential role of awareness and response protocol in enhancing driver response to an unexpected vehicle cyberattack. The Aware + Protocol group had the highest stop rate (100%) and the shortest stopping distances (224 m for standard drivers and 254 m for professionals), compared to the Control group (828 and 520 m, respectively). Aware + Protocol also had the fastest reaction time, averaging 7.53 s, versus 16.12 s (Aware) and 30.29 s (Control). These results emphasize that awareness alone is insufficient. Providing drivers with clear, actionable protocols significantly improves their ability to react quickly and safely to cyberattacks, enhancing overall road safety.

Cybersecurity↗

Forced Power Systems Oscillations Due to Cyberattacks: Threats, Detection and Partial Mitigation

Forced oscillations in power systems can be caused by misconfigured controllers at generator stations. They can also be caused by cyberattacks against the exciters or governors. This paper explores the effects of forced oscillations from cyberattacks on generator excitation and governor systems and the effectiveness of a novel control system for a static var compensator in mitigating those oscillations to enhance transmission system resilience. A brief overview of oscillations, especially forced oscillations, within power systems is presented, along with an overview of cyberattacks on power systems. This paper also examines and implements FACTS devices to partially mitigate the forced oscillations created by cyberattacks by reducing the magnitude of the oscillations caused by the attack. The proposed approach is more effective against attacks targeting exciters.

24 POWER TRANSMISSION AND DISTRIBUTION↗

AI-based Detection and Defense Against Cyberattacks in Distributed Energy Resources

This study will provide comprehensive artificial intelligence (AI)-based solution tools for network security, malware prevention, and sensor data anomaly detection for distributed energy resource (DER) research, development, and demonstration. DER technologies are energy systems (e.g., solar panels, wind turbines, and energy storage systems) that are often connected to the internet and thus vulnerable to cyberattacks. Cybersecurity should be of primary concern for DERs, which is why we propose an integrated multi-layer cyber-defense system for DERs. This system encompasses risk assessments, network security, malware prevention, and detection of anomalies in the sensor data. Implementation of a comprehensive risk assessment with an overview of the model architecture should be the primary step, and should include the potential impact of experiencing, at a given time, one or more cyberattacks on the system. The second step is to ensure that the network security includes firewalls, intrusion detection, and malware prevention. The third step is to provide solution tools that enable sensor data anomaly detection for DERs. By incorporating these considerations into DER research, development, and demonstration, organizations can help ensure the safety and security of their systems and protect against potential cyberattacks.

20 FOSSIL-FUELED POWER PLANTS↗

Decentralised Reinforcement Learning for Dynamic Cyberattack Response in Microgrid Networks

Microgrids rely on communication networks for reliable operation, which makes them inherently vulnerable to cyberattacks. Such attacks can destabilise system dynamics and drive states away from their nominal operating trajectories. Although several physics-informed and machine learning-based strategies have been developed to counter these threats, the rapidly evolving cyber landscape enables adversaries to bypass static defences or rules-based mitigation approaches. This paper proposes a dynamic, online-trained and fully decentralised reinforcement learning (RL)-based cyberattack response framework to protect microgrids from evolving cyberattacks. The proposed framework deploys multiple deep Q-networks (DQNs), each associated with a distributed energy resource (DER), to enable localised and adaptive attack mitigation. In this framework, each DQN processes local voltage and frequency measurements—combined with intrusion detection system (IDS) alerts—as observations and rewards to guide decision-making. Extensive simulation studies demonstrate the robustness of the proposed framework under diverse attack scenarios and varying IDS-induced detection delays. Comparative analysis highlights its superiority over existing static or preexisting rules-based mitigation approaches. Finally, we present an analysis that shows the framework's scalability to real-life microgrids with more interacting agents.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cyberattack Detection and Mitigation on Central Volt‐VAr Using Circuit Law and Machine Learning

ABSTRACT In a distribution grid, voltage is maintained within a nominal range through a Volt‐VAr function that controls capacitor banks, reactive power of distributed energy resources (DER), and on‐load tap changers (OLTC). Availability of communications helps with the implementation of central Volt‐VAr control; however, it also opens the system to cyberattacks, causing voltage disturbances. Previous work has shown the adverse impacts of false data injection (FDI) on the central Volt‐VAr control; however, very few works have studied methods to detect and mitigate FDI on Volt‐VAr control. This paper addresses gaps in the detection and mitigation of FDI on the measurement packets of a central Volt‐VAr control. This work uses a two‐stage algorithm for cyberattack detection since the accuracy of a single‐stage machine learning (ML)–based detection method decreases while dealing with unseen data. The first stage is based on the verification of measurements against circuit laws, and the second stage utilizes a tree search algorithm and an ML method to detect the falsified data. This paper compares long short‐term memory (LSTM) and bidirectional LSTM (BiLSTM) as the employed ML algorithms. Finally, the mitigation algorithm replaces the falsified data with the estimated output of the ML algorithm. The effectiveness of the proposed method is tested for several cases using the IEEE 13‐bus test system in PSCAD software.

Beikbabaei, Milad [Bradley Department of Electrica↗

Encrypted model predictive control design for security to cyberattacks

Abstract In recent years, cyber‐security of networked control systems has become crucial, as these systems are vulnerable to targeted cyberattacks that compromise the stability, integrity, and safety of these systems. In this work, secure and private communication links are established between sensor–controller and controller–actuator elements using semi‐homomorphic encryption to ensure cyber‐security in model predictive control (MPC) of nonlinear systems. Specifically, Paillier cryptosystem is implemented for encryption‐decryption operations in the communication links. Cryptosystems, in general, work on a subset of integers. As a direct consequence of this nature of encryption algorithms, quantization errors arise in the closed‐loop MPC of nonlinear systems. Thus, the closed‐loop encrypted MPC is designed with a certain degree of robustness to the quantization errors. Furthermore, the trade‐off between the accuracy of the encrypted MPC and the computational cost is discussed. Finally, two chemical process examples are employed to demonstrate the implementation of the proposed encrypted MPC design.

Suryavanshi, Atharva↗

Isolating Signatures of Cyberattacks under Stressed Grid Conditions

In a controlled cyber-physical network, such as a power grid, any malicious data injection in the sensor measurements can lead to widespread impact due to the actions of the closed-loop controllers. While fast identification of the attack signatures is imperative for reliable operations, it is challenging to do so in a large dynamical network with tightly coupled nodes. A particularly challenging scenario arises when the cyberattacks are strategically launched during a grid stress condition, caused by non-malicious physical disturbances.

Ghosh, Sanchita [BATTELLE (PACIFIC NW LAB)]↗

MaDEVIoT: Cyberattacks on EV Charging Can Disrupt Power Grid Operation

Extensive roll-out of electric vehicles (EVs) requires large-scale deployment of high-power EV Charging Stations (EVCSs). EVCSs are connected to the internet using Internetof- Things (IoT) such as smartphones, to improve the charging experience of users and increase their profitability. This paper studies the feasibility of demand-side cyberattacks launched on power grids via such internet-connected highpower EVCSs. The attack mechanism distorts power grid frequency and voltage, and has the potential to trigger systemwide outages. The case study, based on the power grid and EV deployment plans in Manhattan, New York, illustrates potential impacts of such attacks. The results show that such attacks will become feasible in Manhattan, New York in 2030, as EV adoption increases. Furthermore, the attacks in 2030 are feasible even compromising a single company’s EVCS server in Manhattan, New York. The attacks can cause line overloads and trip over-frequency protection relays, causing system-side blackout in the power grid in Manhattan, New York. The paper informs planning authorities and power grid operators involved with the roll-out of EV charging infrastructure about potential cyberthreats to power grids via manipulating internet-connected high-power EVCSs.

Acharya, Samrat S.↗

A Randomization-Based, Zero-Trust Cyberattack Detection Method for Hierarchical Systems

This paper demonstrates a novel randomization-based approach for verifying power system control signals with application to detecting cyberattacks. We consider fully connected hierarchical systems containing multiple local agents and a global "trust" agent. The global agent uses a time-varying randomized assignment scheme to identify corrupt network links based on principles of zero trust and majority rule. To evaluate the performance of this detection approach, we implement our algorithm in MATLAB and run it against nearly 43 million unique attack scenarios spanning a range of system sizes. For each scenario, the algorithm determines whether the identified corruptions satisfy a set of validity constraints reflecting network topology and uses that result to say whether the recovered state value for one or more local agents is malicious. We compare the algorithm's determination to the true state of the system to assess performance and find that classification accuracy converges to 100% as system size increases, suggesting that the validity constraints become more difficult to satisfy for larger systems. We further explore the scenarios that evade detection to understand practical implications for employing this detection approach.

cybersecurity↗

Hypothetical Solar Cyberattack Scenarios and Impacts

This report offers approachable, plausible scenarios of cyberattacks affecting photovoltaic assets and interconnected infrastructure. It may be used by State Energy Officials and Public Utility Commission Staff to educate themselves on the potential consequences of these scenarios and the practical, high-level actions that may be implemented now to mitigate future impacts. It highlights plausible consequences of inadequate cyber provisions for PV systems and offers potential state actions to alleviate the identified risks.

14 SOLAR ENERGY↗

Real-Time Testbed for Studying Cyberattacks and Defense in DER-integrated Smart Inverter Systems

In this paper, we propose a Hardware-in-the-Loop (HIL) simulation testbed suitable for the implementation and testing of realistic cyberattacks on grid-tied smart inverter systems integrated with Distributed Energy Resources (DER) that use the Distributed Network Protocol-3 (DNP3) protocol for communications between grid components. Specifically, our testbed combines a Real-Time Digital Simulator (RTDS) NovaCor device, outfitted with GNETx2 network interface cards, a gridtied DER topology implemented via the RTDS software package RSCAD, and a custom virtual network that emulates a man in the middle attacker. The Man-in-the-Middle (MITM) attacker captures DNP3 traffic and falsifies telemetry data in DNP3 packets to trigger unwarranted commands from a DNP3 controller that exploit smart inverter grid support functions. We choose DNP3 and implement grid support functions according to the IEEE Std. 1547-2018 mandated for the interconnection and interoperability of DER power systems with associated power components. Furthermore, we develop a protocol payload agnostic attack detection framework that leverages the round-trip time (RTT) anomalies between DNP3 requests and responses and can detect the presence of attacks without having to analyze the payload’s contents, while balancing trade-offs between false alarm counts, missed detections, and time to detection. To facilitate further research, we publicly release benign and attack network traffic exchanged between various sensors, controllers, and actuators in our grid-tied inverter testbed.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Robust Power System Stability Assessment Against Adversarial Machine Learning-Based Cyberattacks via Online Purification

The increasing complexity associated with renewable generation brings more challenges to power system stability assessment (SA). Data-driven approaches based on machine learning (ML) techniques for stability assessment have received significant research interest and shown their promising performance. However, ML-based models are recognized to be vulnerable to adversarial disturbances, where a slight perturbation to power system measurements could lead to unacceptable errors. To address this issue, this paper develops a novel lightweight mitigation strategy, i.e., robust online stability assessment (ROSA), to enhance the ML-based assessment model against both white-box and the black-box adversarial disturbances (i.e., purification) in the online implementation. The ROSA involves a supervised learning-based module for the primary stability assessment and a self-supervised learning-based module. Further, the two modules are trained jointly with different objective (loss) functions and implemented in sequence. A suitable purification objective and various time-series data augmentation methods are designed for SA applications to tackle adversarial disturbances adaptively. Case studies are performed, and the comparative results have clearly illustrated the competitive, robust accuracy against various adversarial scenarios and verified the effectiveness of the proposed online purification strategy.

24 POWER TRANSMISSION AND DISTRIBUTION↗