Search NASA⌕ Search

SEARCH · Search NASA

Results for “data security defense”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Data Security Defense: Modeling and Detection of Synchrophasor Data Spoofing Attack for Grid Edge

Data security and cyberattack have become critical issues in the distributed power system where adversaries can swap the source information of sensors or even spoof and alter measurements. However, the cyber security of the power system is challenged by the unpredictability and stealth of the spoofing attacks. Here, to protect the data security at the grid edge, this paper developed a synchrophasor data spoofing attack detection framework based on the time-frequency feature extraction techniques including the short-time Fourier transform (STFT) and object detection network for real-time synchrophasor data categorization and spoofing attack localization. The proposed approach outperforms earlier work in terms of spoofing attack detection and offers a vital localization function employing distributed synchrophasor sensors.

24 POWER TRANSMISSION AND DISTRIBUTION↗

AI-based Detection and Defense Against Cyberattacks in Distributed Energy Resources

This study will provide comprehensive artificial intelligence (AI)-based solution tools for network security, malware prevention, and sensor data anomaly detection for distributed energy resource (DER) research, development, and demonstration. DER technologies are energy systems (e.g., solar panels, wind turbines, and energy storage systems) that are often connected to the internet and thus vulnerable to cyberattacks. Cybersecurity should be of primary concern for DERs, which is why we propose an integrated multi-layer cyber-defense system for DERs. This system encompasses risk assessments, network security, malware prevention, and detection of anomalies in the sensor data. Implementation of a comprehensive risk assessment with an overview of the model architecture should be the primary step, and should include the potential impact of experiencing, at a given time, one or more cyberattacks on the system. The second step is to ensure that the network security includes firewalls, intrusion detection, and malware prevention. The third step is to provide solution tools that enable sensor data anomaly detection for DERs. By incorporating these considerations into DER research, development, and demonstration, organizations can help ensure the safety and security of their systems and protect against potential cyberattacks.

20 FOSSIL-FUELED POWER PLANTS↗

Multilevel Cybersecurity for Photovoltaic Systems

The motivation behind this project is to protect critical infrastructure in electric power generation pertaining to solar photovoltaic (PV) systems. This growing renewable energy resource is becoming a more vital part of the nation’s energy portfolio, particularly since it has achieved grid-parity to existing generation methods in terms of cost. It is thus vital that steps be taken to ensure the cybersecurity of these assets. The project goal was to devise a multilevel cybersecurity solution to address PV security gaps at the inverter and system levels, and field test the solution under the supervision and review of a US-based solar inverter manufacturer and PV installer/operator. A two-level cyberattack defense approach was formulated whereby the first level, the solar inverter level, hardens individual devices and achieves a deeply cyber-secure inverter. The inverter level security involves a multi-layer defense-in-depth approach for securing the inverter while also providing data for the system level algorithms. The second level, the system level, addresses intrusion detection and restoration involving an ensemble of inverters and relevant systems.

14 SOLAR ENERGY↗

Rapid Monitoring and Defense Approach for Resilience Improvement of Grid Cyber Security

Cyber-physical systems and electric utilities significantly depend on the reliability and efficiency of information and operational technology. However, false data injection attacks based on synchrophasor measurement data pose a serious threat to the safe and reliable operation of modern power systems. Here, to mitigate this problem, a rapid monitoring and defense approach is proposed to defend against cyber attacks. Initially, the Time and Frequency based Convolutional neural Network (TFCN) is proposed to detect different types of attacks. Within the TFCN, the advances are that both time and frequency domain information can be fused without extra spectrum analysis methods, and can save detection time to speed the calculation efficiency using the developed time-frequency block. Next, a comprehensive defense strategy is developed for multiple cyber attacks to ensure the stability and resilience of the power system according to the feedback detection results. The advances of this strategy are that different control strategies can be automatically selected to recover the stability to the greatest extent according to the detected attacks. To verify the effectiveness of the proposed approach, the high-speed frequency measurements collected from the wide-area monitoring system are used. The results demonstrate that the cyber attack detection performance can reach 95.57% accuracy, outperforming both traditional and some advanced neural networks. Importantly, the defense strategy is conducted and verified in a modified IEEE 39 bus system as well, which illustrates profound performance in faster stability restoration.

Comprehensive defense strategy↗

How an Autonomous Offshore Power System Can Transform the Ocean Economy - A Hypothetical Case Study Utilizing an Autonomous Offshore Power System in Northern Lights Carbon Capture and Storage Project

An Autonomous Offshore Power System (AOPS) provides in-situ power, energy storage, real-time data and communications support, asset management, and other capabilities at sea. It has applications for all offshore industries: energy, defense and security, aquaculture, science and research, and communications. Furthermore, this paper highlights how an AOPS can reduce cost, complexity, and carbon-intensity for existing offshore operations and enable new capabilities for offshore industry leaders. This new AOPS technology has two primary advantages. First, it unlocks the autonomous, electric future of the ocean economy via ‘local’ power generation and energy storage, in addition to real-time connection to the data cloud. Second, it helps enable a material change in the global energy mix through cost-effective, reliable generation and storage technology for use cases including mobile/static data-gathering and reporting systems, operating equipment, and charging networks for uncrewed surface vessels. AOPS technology will help transform the ocean economy, and thus has implications for offshore industry leaders as they push to reduce costs today and make an autonomous and decarbonized future possible.

16 TIDAL AND WAVE POWER↗

Secure State Estimation with Asynchronous Measurements for Coordinated Cyber Attack Detection in Active Distribution Systems

Coordinated cyber attacks tamper with measurement data to disrupt the situational awareness of active distribution systems. Various sensors report measurements asynchronously at different rates, which introduces challenges during state estimation. In addition, this forces cyber intruders to exert greater effort to compromise multiple communication channels and launch coordinated attacks. Therefore, multi-channel and asynchronous measurements could be harnessed to develop more secure cyber defense strategies. In this paper, a prediction-correction-based multi-rate observer is designed to exploit the value of asynchronous measurements for the detection of coordinated false data injection (FDI) attacks. First, a time-function-dependent prediction-correction strategy is proposed to adjust the sampling interval for each sensor’s measurement. Then, an observer is designed based on the trade-off between estimation error and the optimal period of the most recent sampling instant, with the convergence of estimation error with the maximum permitted sampling interval. Moreover, the conditions for exponential stability are developed using the Lyapunov–Krasovskii functional technique. Next, a coordinated FDI attack detection strategy is developed based on the dual nonlinear minimization problem. The proposed attack detection and secure state estimation strategies are tested on the IEEE 13-node system. Simulation results show that these schemes are effective in enhancing attack detection based on asynchronous measurements or compromised data.

asynchronous measurements↗

WRS Capabilities Booklet [Slides]

WRS is the digital backbone of the Weapons Program—delivering trusted data assets, cyber-assured software and systems, and AI-enabling software—that transform insights into decisive action. We empower physicists, engineers, researchers, and scientists to think faster, act strategically, and stay ahead in an ever-evolving threat landscape. Our efforts ensure critical nuclear weapons data remains secure, accessible, and usable—supporting mission-critical work, informed decision making, and scientific advancement at LANL and across the Nuclear Security Enterprise (NSE).

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

A Cybersecurity Testbed for Smart Buildings

Smart buildings are equipped with a plethora of cyber-physical systems, such as Internet of Things (IoT) devices and building automation systems. These devices, especially in commercial buildings, use legacy communications and hardware that were not designed with cybersecurity in mind. With increasing cyber threats in recent years, smart buildings have become an increasing target for attacks, but not enough published data are available from these incidents to study or replicate the scenarios to defend buildings. As part of the U.S. Department of Energy-funded project focusing on developing the Building Intelligence with Layered Defense Using Security-Constrained Optimization and Security Risk Detection (BUILD-SOS) platform, we developed a cybersecurity test bed for smart buildings. This test bed includes a building simulation tool, virtual devices, emulated operational technology networks, and remote hardware-in-the-loop. Using this test bed, we performed different cyberattacks on the smart building model and collected both physical building data, to understand the impacts on the building, and network data, to aid in separating mechanical faults from cyberattacks during the detection. This test bed is a significant tool in protecting smart buildings from cyberattacks because it can aid in both cybersecurity analysis and the evaluation of other cyberattack detection tools by testing the tools in a secure environment without impacting the building operations.

cyber-physical systems↗

A Cybersecurity Testbed for Smart Buildings

Smart buildings are equipped with a plethora of cyber-physical systems, such as Internet of Things (IoT) devices and building automation systems. These devices, especially in commercial buildings, use legacy communications and hardware that were not designed with cybersecurity in mind. With increasing cyber threats in recent years, smart buildings have become an increasing target for attacks, but not enough published data are available from these incidents to study or replicate the scenarios to defend buildings. As part of the U.S. Department of Energy-funded project focusing on developing the Building Intelligence with Layered Defense Using Security-Constrained Optimization and Security Risk Detection (BUILD-SOS) platform, we developed a cybersecurity test bed for smart buildings. This test bed includes a building simulation tool, virtual devices, emulated operational technology networks, and remote hardware-in-the-loop. Using this test bed, we performed different cyberattacks on the smart building model and collected both physical building data, to understand the impacts on the building, and network data, to aid in separating mechanical faults from cyberattacks during the detection. This test bed is a significant tool in protecting smart buildings from cyberattacks because they can aid in both cybersecurity analysis and the evaluation of cyberattack detection tools by testing the tools in a secure environment without impacting the building operations.

alfalfa↗

Achieving Cyber-Resilience for Power Systems using a Learning, Model-Assisted Blockchain Framework

The secure integration and management of distributed energy resources (DER) and power aggregators in the electric grid requires secure communications and a physics-aware Command and Control (C2) strategy. A Blockchain (BC)-based overlay network was developed to provide a security layer for the existing power grid network that mitigates risks in current and legacy network and C2 protocols. By integrating a Model-Assisted Machine Learning (MAML) framework with a Secure Blockchain Overlay Network (SBON) a defense-in-depth strategy was achieved. In our approach, the MAML framework leveraged a smart contract framework to gather network data and learn the dynamics of DER to develop detection strategies for attacks targeting sensors and actuators used by DER. The MAML framework learned dynamical systems models for individual DERs to detect sensor attacks. For DER we utilized a Digital Twin (DT) to accelerate the learning process for a model resistant to stealthy attacks. The project created DT for PV inverters and BESS. The DTs were coupled with a model-assisted, data-driven learning of DER behavior. Specifically, we evaluated architectures for model-based learning with model-free fine-tuning. Additionally, differential privacy techniques were used to obfuscate data, while still allowing the computation of attack detection results based on obfuscated data. The SBON developed leverages a private permissioned blockchain network orchestrated with the Hyperledger Fabric framework. To connect the cyber world, which orchestrates the blockchain fabric, and the physical world where the power network resides, we developed a system implementation to enable the secure interaction of the physical world and the abstracted blockchain.

97 MATHEMATICS AND COMPUTING↗

High-Reliability Systems and the Control of National Security Data and Information

High-reliability systems are characterized by catastrophic implications in the event of failure. These implications can include substantive damage to the environment, social order, and loss of life. Examples of high-reliability systems include nuclear submarines, nuclear reactors, the electric grid, and nuclear weapons. Due to the catastrophic implications of failure, there are heightened awareness and control mechanisms surrounding related data and information. However, defining the difference between data and information is often ambiguous across scholarly disciplines and in United States policy and legislation. For high-reliability systems, the implications of ambiguity between data and information may affect the security of United States interests and even cost lives. For security, data are raw facts or figures without context, while information is the compilation or articulation of data that forms context. Security depends on clarity in the differences between data and information and how to control them. Control is necessary to ensure that data and information are not unintentionally released to foreign governments, the public, or those without need-to-know. A primary concern in the practice of security is the control of data to avoid the unintended conversion to information. Intra-institutionally, this control is highly complex given the amalgam of legacy data systems and the numerous and constantly evolving nature of modern data systems that were not necessarily designed to be integrated. The complexity of this concern is augmented when institutions are part of interinstitutional collaborations or networks of public-private partnerships that share data and information. Additionally, institutions that share data as a function of policy and legislative action— particularly formally integrated data and information system infrastructures—may be at higher security risk. This paper will present an intra-institutional paradigm that utilizes and integrates concepts from numerous disciplines to frame a critical and underspecified practical issue in security—controlling for the unintended conversion of data to information.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Quantum adversarial learning for kernel methods

We show that hybrid quantum classifiers based on quantum kernel methods and support vector machines are vulnerable against adversarial attacks, namely small engineered perturbations of the input data can deceive the classifier into predicting the wrong result. Nonetheless, we also show that simple defense strategies based on data augmentation with a few crafted perturbations can make the classifier robust against new attacks. Our results find applications in security-critical learning problems and in mitigating the effect of some forms of quantum noise, since the attacker can also be understood as part of the surrounding environment.

71 CLASSICAL AND QUANTUM MECHANICS, GENERAL PHYSIC↗

High-Reliability Systems and the Control of National Security Data and Information

High-reliability systems are characterized by catastrophic implications in the event of failure. These implications can include substantive damage to the environment, social order, and loss of life. Examples of high-reliability systems include nuclear submarines, nuclear reactors, the electric grid, and nuclear weapons. Due to the catastrophic implications of failure, there are heightened awareness and control mechanisms surrounding related data and information. However, defining the difference between data and information is often ambiguous across scholarly disciplines and in United States policy and legislation. For high-reliability systems, the implications of ambiguity between data and information may affect the security of United States interests and even cost lives. For security, data are raw facts or figures without context, while information is the compilation or articulation of data that forms context. Security depends on clarity in the differences between data and information and how to control them. Control is necessary to ensure that data and information are not unintentionally released to foreign governments, the public, or those without need-to-know. A primary concern in the practice of security is the control of data to avoid the unintended conversion to information. Intra-institutionally, this control is highly complex given the amalgam of legacy data systems and the numerous and constantly evolving nature of modern data systems that were not necessarily designed to be integrated. The complexity of this concern is augmented when institutions are part of inter-institutional collaborations or networks of public-private partnerships that share data and information. Additionally, institutions that share data as a function of policy and legislative action—particularly formally integrated data and information system infrastructures—may be at higher security risk. This paper will present an intra-institutional paradigm that utilizes and integrates concepts from numerous disciplines to frame a critical and underspecified practical issue in security—controlling for the unintended conversion of data to information.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

DOE CESER 6 GHz Interference Study

DOE CESER has sponsored Idaho National Laboratory (INL) to conduct an objective and independent study of potential 6 GHz interference from outdoor operation of unlicensed devices in the 6 GHz band on fixed service (FS) microwave communication links operated by electrical sector incumbents in that band. INL is collaborating with University of Notre Dame (UND), Electric Power Research Institute (EPRI), Lockard & White, Southern Company, and AT&T, to gather data with real-world 6 GHz interference experiments and identify (1) the potential for interference from unlicensed devices and (2) the interference necessary to cause harm to the incumbents. In addition to the functional assessment, a security assessment of the FCC mandated Automatic Frequency Coordination (AFC) System to regulate use of unlicensed 6 GHz standard power devices is also being conducted. A major objective is to create a science-based and defensible methodology used to produce the necessary data and to derive objective conclusions. This proven methodology can then be used to produce objective data and conclusions for other spectrum bands with similar incumbent uses including 4.4 – 4.9 GHz and 7.125 – 7.4 GHz, identified in the reconciliation bill that was adopted on July 4, 2025, as well as the National Spectrum Strategy discussions that are ongoing. This report contains 6 GHz field experiments and findings in the following real-world scenarios with commercial unlicensed standard power (SP) 6 GHz devices regulated by Automated Frequency Coordination (AFC): • University of Notre Dame (UND) Stadium with a capacity of 80,000 spectators, where Wi-Fi operating in 6 GHz has been deployed recently • Southern Company 6 GHz FS microwave link between Columbus and Fortson, Georgia Following are the following key findings from this study. 1. The AFC is under-protective of FS when line-of-sight exists along the path centerline. Data collected at Southern’s 6 GHz fixed link site shows significant erosion of as much as 21.4-24.4 dB of under-protection that can lead to potential service degradation under typical operating conditions. This first key finding is most likely the result of erroneous use of the RF propagation model. INL will collaborate with EPRI and the AFC Functional Requirements Working Group to submit a change request to the WinnForum TS-1014 standard towards correct use of the propagation model by the AFC. 2. There is additive interference effect of about 3 dB from nearly equal power interferers measured from simultaneous operation of two SP AP's operating co-channel with the FS receive from different locations along the path. This second key finding should be used to add the impact of additive interference of operation of multiple APs in the same geographical area, to the next generation of AFCs. INL will collaborate with FCC on the need for the AFC to consider additive interference. We also recommend that additional experiments are conducted on 6 GHz spectrum interference to further improve the AFC operation as the number of outdoor Wi-Fi devices continues to increase. These proposed steps and recommendations will make the co-existence of the incumbents and the 6 GHz outdoor Wi-Fi providers possible without any impact on the incumbents with a win-win outcome for all.

6 GHz↗

Multi-phenomenology Yield Characterization

This report serves as the first delivery of a four-year applied science effort to transform and advance the error bounds for the yield estimate of an explosion. Each year’s delivery will be in this form, culminating in the submission of this work for peer review to a scientific journal. Importantly, the yearly progress reports can then also be viewed as expanding drafts working towards a formal journal article submission. For the first tranche of funding, we collaborated with Air Force Technical Applications Center (AFTAC) scientists to identify unclassified real-world data that demonstrate and validate our advanced error propagation methods. Collaboration includes visits to AFTAC and telecons. For this development, we illustrate the fusion of seismic, acoustic, optical, and surface effect signatures from an explosion. The mathematics and code being adapted to this specific application (Williams et al., 2021) involves physics models of multiple sensor signatures. We have also identified related physics models and have integrated them into code. Current methods of underground explosion yield estimation for the Threshold Test Ban Treaty (TTBT) have served the US treaty monitoring mission well for decades. A research objective of the Defense Nuclear Nonproliferation Research and Development (DNN R&D) office of the National Nuclear Security Administration (NNSA) has always been to provide new technical capabilities for monitoring lower thresholds. The general model and error propagation code to be developed in this project is based on significant advances in error modeling and propagation needed to analyze data at lower detection thresholds. The second tranche of funding for this project began on May 1, 2022, and planned work for the second tranche includes: i) completing the integration of physical model code into the general error model framework; this code accommodates a wide range of linear/nonlinear source models, fixed/ random effects, and frequentist/Bayesian analyses (the purpose of which is not to dictate to users how to analyze data, but instead to allow users the maximum flexibility in their work); ii) illustrative application of code to identified data, and; iii) initial planning with AFTAC researchers on delivery of code to the Common Development Environment at AFTAC, and continued writing of the planned final journal article submission (year two of this progress report), with particular emphasis on descriptions of data identified for this effort.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Electrical Fault Detection, Power Quality, Distributed Energy Resource Use Cases, and Cyber Event Applications with the Cyber Grid Guard System Using Distributed Ledger Technology

Electrical utilities continue to deploy more intelligent electronic devices (IEDs) inside and outside electrical substation and are associated with distributed energy resources (DERs). The integrity and confidentiality of data from IEDs is crucial, and distributed ledger technology (DLT) could improve the resilience of microgrids by helping to make these data more secure. The most popular applications using blockchain technology for electrical utilities is in the field is based on energy trading. However, the dynamism of the penetration of customer owned DERs and the deployment of sensors with IEDs have led to the identification of new applications using DLT that are focused on other areas, such as monitoring, operation and management of the grid and its assets. In addition, the majority of studies on electrical grid applications with blockchain were validated with software simulations. Although general monitoring of power systems for using DLT could be evaluated in operational electric grids, other DLT research applications such as defense against cyber-attacks and/or electrical fault detection are not likely to be performed in a real infrastructure because of possible risks to the network/equipment security. This report summarizes the application of power system applications using distributed ledger technology (DLT), providing a secure DLT framework for collecting data from IEDs like power meters and protective relays inside and outside of an electrical substation and/or between two different electrical utilities. In this study, the use case scenarios were created and assessed for different power system application by using DLT. The electrical fault detection for faulted phases (1), power quality monitoring of phase voltage magnitudes, frequency levels and load power factor (2), DERs use case monitoring (3), and cyber-event applications (4) were performed in a test bed with a Cyber-Grid Guard (CGG) system using DLT. It had a real-time simulator with power meters and protective relays in-the-loop. The first section of this report presents a literature review of power system applications using blockchain at research level. The second section shows the theory and equations used on this report. The third section shows the description of the test bed, equipment, architecture, and electrical grid diagrams. The fourth section shows the experimental models and use case scenarios that were performed for the electrical fault detection, power quality, DERs use case, and cyber event applications with the CGG system using DLT. The fifth section shows the results collected from the tests based on comparing the time stamped events of the analog signals from the IEDs, DLT computer and real time simulator. The sixth section performed the discussion of the results for the use case scenarios. Finally, section seven presents the conclusions for this report were presented.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Characterization of Infrasonic Signatures of Earth-Grazing Fireballs as Analogues to Hypersonic Vehicles (Final Report)

Accurate detection, discrimination, and characterization of high-altitude hypersonic events using infrasonic monitoring are critical to planetary defense and global strategic surveillance. This report synthesizes recent advances achieved through rigorous analysis of infrasonic signatures from natural meteoroids, emphasizing shallow entry-angle meteoroids as essentially proxies for artificial hypersonic systems. Meteoroids naturally encompass diverse velocities, trajectories, altitudes, and fragmentation behaviors, enabling systematic validation of empirical period–yield relationships, waveform morphology classifiers, and trajectory-induced back-azimuth deviation models. Integration of adaptive array-processing enhancements within Cardinal software further extends infrasonic detection sensitivity and signal classification reliability. Collectively these advances, based solely on infrasonic signatures or limited optical data, offer robust methodologies for distinguishing natural from artificial hypersonic sources, significantly reducing event geolocation uncertainties and refining source-function determination. The outcomes detailed herein lay foundational groundwork for improved global hypersonic event-surveillance frameworks, supporting improved security preparedness and informing strategic monitoring and defense policies.

54 ENVIRONMENTAL SCIENCES↗

Life Cycle Inventories and Data Gap Analysis for Rare Earth Elements: Neodymium and Dysprosium from Mining to Magnets

The United States demand for Neodymium-Iron-Boron (NdFeB) magnets, produced from rare earth elements (REEs) such as (Nd) and Dysprosium (Dy), far exceeds its nascent domestic production capacity, rendering it reliant on vulnerable global supply chains dominated by China. To guide research and development investments in securing U.S. REE supply, defensible benchmark metrics across environmental, economic, and social dimensions are needed. In this study, we built globally-representative, process-based cradle-to-cradle life cycle inventories for Nd and Dy in NdFeB magnets lifecycles, encompassing primary material acquisition, beneficiation, smelting and refining, metal processing, specialty alloy and chemical transformation, subcomponent manufacturing, consumer application (use phase) and end-of-life management. We carried out detailed literature review, and applied process engineering principles to build industry-representative upscaled life cycle inventories for both metals. We used these models to conduct bottom-up literature review and gap analysis on existing literature, compilation of data sources for each life cycle stage (and transformations where necessary), and a preliminary technoeconomic analysis (TEA)/life cycle costing analysis (LCCA). Findings from this work emphasize the need for metal specific, representative REE LCIs to establish robust benchmarks for advancing sustainable REE technologies and guiding R&D in REE supply chains.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗