Robust Dynamic Watermarking for Cyber-Physical Security of Inverter-Based Resources in Power Distribution Systems
Not provided.
SEARCH · Search NASA
Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.
Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.
Not provided.
Due to the distributed nature of Federated Learning (FL) systems, each local client has access to the global model, which poses a critical risk of model leakage. Existing works have explored injecting watermarks into local models to enable intellectual property protection. However, these methods either focus on non-traceable watermarks or traceable but white-box watermarks. We identify a gap in the literature regarding the formal definition of traceable black-box watermarking and the formulation of the problem of injecting such watermarks into FL systems. In this work, we first formalize the problem of injecting traceable black-box watermarks into FL. Based on the problem, we propose a novel server-side watermarking method, TraMark, which creates a traceable watermarked model for each client, enabling verification of model leakage in black-box settings. To achieve this, TraMark partitions the model parameter space into two distinct regions: the main task region and the watermarking region. Subsequently, a personalized global model is constructed for each client by aggregating only the main task region while preserving the watermarking region. Each model then learns a unique watermark exclusively within the watermarking region using a distinct watermark dataset before being sent back to the local client. Extensive results across various FL systems demonstrate that TraMark ensures the traceability of all watermarked models while preserving their main task performance.
Watermarking language models is essential for distinguishing between human and machine-generated text and thus maintaining the integrity and trustworthiness of digital communication. Here, we present a novel green/red list watermarking approach that partitions the token set into “green” and “red” lists, subtly increasing the generation probability for green tokens. To correct token distribution bias, our method employs maximal coupling, using a uniform coin flip to decide whether to apply bias correction, with the result embedded as a pseudorandom watermark signal. Theoretical analysis confirms this approach’s unbiased nature and robust detection capabilities. Experimental results show that it outperforms prior techniques by preserving text quality while maintaining high detectability, and it demonstrates resilience to targeted modifications aimed at improving text quality. This research provides a promising watermarking solution for language models, balancing effective detection with minimal impact on text quality.
Streaming data processing is an exercise in taming disorder: from oftentimes huge torrents of information, we hope to extract powerful and timely analyses. But when dealing with streaming data, the unbounded and temporally disordered nature of real-world streams introduces a critical challenge: how does one reason about the completeness of a stream that never ends? In this paper, we present a comprehensive definition and analysis of watermarks, a key tool for reasoning about temporal completeness in infinite streams.First, we describe what watermarks are and why they are important, highlighting how they address a suite of stream processing needs that are poorly served by eventually-consistent approaches:• Computing a single correct answer, as in notifications.• Reasoning about a lack of data, as in dip detection.• Performing non-incremental processing over temporal subsets of an infinite stream, as in statistical anomaly detection with cubic spline models.• Safely and punctually garbage collecting obsolete inputs and intermediate state.• Surfacing a reliable signal of overall pipeline health.Second, we describe, evaluate, and compare the semantically equivalent, but starkly different, watermark implementations in two modern stream processing engines: Apache Flink and Google Cloud Dataflow.
Multi-bit watermarking has emerged as a promising solution for embedding imperceptible binary messages into Large Language Model (LLM)-generated text, enabling reliable attribution and tracing of malicious usage of LLMs. Despite recent progress, existing methods still face key limitations: some become computationally infeasible for large messages, while others suffer from a poor trade-off between text quality and decoding accuracy. Moreover, the decoding accuracy of existing methods drops significantly when the number of tokens in the generated text is limited, a condition that frequently arises in practical usage. To address these challenges, we propose XMark, a novel method for encoding and decoding binary messages in LLM-generated texts. The unique design of XMark’s encoder produces a less distorted logit distribution for watermarked token generation, preserving text quality, and also enables its tailored decoder to reliably recover the encoded message with limited tokens. Extensive experiments across diverse downstream tasks show that XMark significantly improves decoding accuracy while preserving the quality of watermarked text, outperforming prior methods. The code will be made publicly available upon acceptance.
This paper presents of an active detection scheme for detecting cyber attacks on sensors controlling a grid-tied PV systems. Several cyber vulnerabilities in Grid tied PV Systems are discussed. The defense mechanism introduces a private (secret) watermarking signal into the control inputs of the grid-tied inverter system. This will enable the detection of any malicious manipulation of sensor measurements. Based on the measured data, two statistical tests are conducted to identify anomalies in the system using the presence of the watermarking signal. It shown that when a sensor data is compromised and/or replaced by a pre-recorded healthy signal, both test 1 and 2 exhibit high values indicating a possible malicious activity. The robustness of the proposed algorithm is tested and validated with several attack scenarios on a grid tied PV system. Select results from an experimental setup are discussed.
This report summarizes the activities of this project, which aims at design and testing a scalable, robust, and online framework that provides secure monitoring of photovoltaic generation in the face of potential cyber-attacks.
In this article, we address the cyber-security problem of industrial control systems (ICSs) when their sensor measurements may be compromised due to an attacker who has intercepted those measurements via a network. We introduce a general-purpose method “Dynamic Watermarking (DW)” to detect potential cyber-intrusions on speed sensor measurements within industrial control systems, which deploy an adjustable speed drive (ASD) to control a critical process. The DW method is injecting a random private low-amplitude signal with a zero mean Gaussian distribution, “watermark”, into one of the input phase voltages powering the ASD system. The watermark signal propagates through the system including pulse width modulation (PWM) power conversion stage and motor, then ultimately appears in the speed sensor measurements. By deploying two statistical DW tests with two proper thresholds, the system can detect potential cyber-intrusions or unobservable cyber-attacks such as replay attacks and false data injection attacks (FDIA). The DW method tested on a laboratory-scale ASD system experimentally to protect the system against cyber-intrusions. This system, powered by a commercial PWM drive operating at 208 V, 3-phase, and 3.7 kW, served as our experimental platform.
In this paper an active detection scheme for sensor spoofing (manipulated externally via a cyber attack) in grid-tied PV systems is discussed. The core of the proposed active detection scheme is to introduce a private (secret) watermarking signal into the control inputs of the DC-DC converter and DC-AC inverter stages to detect any malicious spoofing (manipulation) of voltage/current sensor measurements controlling both the DC-DC converter maximum power point tracking (MPPT) stage and the DC-AC inverter of the grid-tied PV system. Several types of possible spoofing mechanisms (attack models) are discussed. The proposed sensor spoofing attack detector system consists of injecting a small magnitude of digital watermarking signal (DWS) and conduct three statistical watermark tests on the reported sensor measurements to determine if a) the proposed system is healthy and operating as expected b) if sensor signals were spoofed (manipulated) externally or c) if a particular sensor is malfunctioning due to a faulty hardware. It is shown via extensive simulations that the proposed DWS approach is robust in detecting malicious external manipulation of sensors controlling the grid tied PV system. A testing platform is currently under development and the experimental results will be discussed in the conference presentation.
In this paper, an intrusion proof adjustable speed drive system controlling a critical process in an industrial control system is detailed. In such a system, should the motor speed sensor signal data be compromised and/or altered via a cyber-attack, the system can potentially be unregulated, over speed and/or malfunction thereby disrupting the critical process. The proposed active detection scheme detailed in this paper introduces a private (secret) random signal termed as "watermark" into the inverter control signal that determines the PWM gating signals of the DC-AC inverter powering the motor. The watermarking signal introduced into the PWM modulation for the DC-AC inverter is shown to propagates its unique signature, which appears in all sensors signals at the inverter output such as voltage/current/speed used to control the motor. Now employing the measured data (from sensors), two statistical variance tests are conducted to identify anomalies if any in the presence of the watermarking signal. It is shown when an intrusion occurs to manipulate the sensor data to disturb and/or destabilize the process, the proposed tests immediately display a high value indicating a compromise in sensor data. It is shown that the proposed system is capable of immediate detection of a sophisticated attacks such as record/reply attack in which the actual speed sensor is disconnected and a prerecorded speed signal from the past of the same magnitude is played back to the controller. Several types of cyber-attacks such as speed reduction/increase including vibration have been tested. Extensive simulation results verify the proposed concepts. Experimental results will be discussed in the conference presentation.
This paper describes a new non-charge-based data storing technique in NAND flash memory called watermark that encodes read-only data in the form of physical properties of flash memory cells. Unlike traditional charge-based data storing method in flash memory, the proposed technique is resistant to total ionizing dose (TID) effects. To evaluate its resistance to irradiation effects, we analyze data stored in several commercial single-level-cell (SLC) flash memory chips from different vendors and technology nodes. These chips are irradiated using a Co-60 gamma-ray source array for up to 100 krad(Si) at Sandia National Laboratories. Experimental evaluation performed on a flash chip from Samsung shows that the intrinsic bit error rate (BER) of watermark increases from 0.8% for TID = 0 krad(Si) to 1% for TID = 100 krad(Si). Conversely, the BER of charge-based data stored on the same chip increases from 0% at TID = 0 krad(Si) to 1.5% at TID = 100 krad(Si). Overall, the results imply that the proposed technique may potentially offer significant improvements in data integrity relative to traditional charge-based data storage for very high radiation (TID > 100 krad(Si)) environments. These gains in data integrity relative to the charge-based data storage are useful in radiation-prone environments, but they come at the cost of increased write times and higher BERs before irradiation.
This paper details a robust method to secure a multi-inverter grid tied system that interfaces photovoltaic (PV) and battery energy storage against potential cyber-attacks. The method can be applied to any third-party inverter systems without a need to modify their internal controls. A small random private excitation signal termed "watermark" is injected into the DC input voltage terminals (via a series transformer) connected to the PV/battery inverter system. An external robust cyber intrusion detector (CID) hardware consisting of a digital signal processor (DSP) generates the "watermark" and also receives the sensor signals that control the setpoints of the PV/battery grid tied system. The CID algorithm is shown to detect all possible cyber intrusions (such as false data injection(FDI)) on external sensor signals such as P and Q measured by a smart meter that control the overall system operation. The proposed CID computes online system ID and two variance tests in real time on each sensor signal and is able pinpoint intrusion location in a multi-inverter system. Results on a hardware in the loop (HIL) of a two-inverter grid connected system demonstrate effectiveness of the proposed CID system for FDI and unobservable FDI. Test results on a laboratory prototype will be discussed in the conference presentation.
In this portion of the TrojAI evaluation, we focus on the cyber-network-c2-mar2024 dataset. Recall that in this round ResNet18 and ResNet34 neural networks (NN) were trained on the USTC-TFC2016 dataset with the aim of distinguishing between benign versus botnet command and control (c2) packets. A range of bytes from each packet was reformatted into a 28x28 pixel image, and the collection of reformatted packets served as the training (and testing) data for the two ResNet models. For some of the data a trigger watermark was strategically placed to affect various inputs to the NNs. This watermarked, or poisoned, data in turn created a poisoned, or trojaned NN. The data were poisoned in different ways ultimately creating different trojaned NNs. This collection of trojaned NNs was combined with various versions of not trojaned NNs and served as the training and testing data for the performers. The performers’ task was to construct a classifier to distinguish between the trojaned and not trojaned models. It was previously noted that the performers struggled with the cyber-network-c2-mar2024 dataset, motivating this investigation of potential reasons the performers experienced challenges.
Integration of information and communication technology (ICT) offers new opportunities in improving the management and operation of critical infrastructures such as power systems as it allows connection of different sensors and control components via a communication network, leading to the so-called networked control systems (NCS). However, the use of open and pervasive ICT such as the Internet or wireless communication technologies comes at a price of making NCS vulnerable to cyber intrusions/attacks which may cause physical damage. Here, this chapter presents control algorithms to ensure resilient and safe operation of NCS under unknown cyberattacks. Specifically, a variant of dynamic watermarking strategies is presented by embedding encoding/decoding components of chaotic signals into the NCS for secure control for critical locations where the measurement/control signals are transmitted to/from the control center via a communication network. In addition, resilient cooperative control algorithms are discussed to ensure safe operation at edge of the NCS which consists of a large number of distributed controllable devices. Several numerical examples are provided to illustrate the proposed control strategies.
Solar photovoltaic (PV)-rich power distribution systems are networked Cyber-Physical Systems (CPS). These are control systems where multiple computing nodes and diverse intelligent agents interact with the physical world in real-time. However, the presence of networked components renders them vulnerable to potential cyber-attacks, cyber-intrusions, and other malicious events. This is because these systems depend on the measurements reported from their heterogeneous sensors. This makes them vulnerable to potential cyber-attacks where malicious agents can compromise the sensors or the communication networks carrying the sensor measurements. This paper proposes a novel methodology for enhancing the cyber-security and cyber-resilient post-attack safe operation of solar PV-rich power distribution systems against potential cyber-attacks through the Dynamic Watermarking (DW), using online system identification. The resiliency of the proposed technique is tested and validated with several attack scenarios on both a lab-scale 3kW grid-connected PV inverter and a Hardware-in-the-Loop (HiL) system. The proposed approach can be applied to other types of power distribution systems to enhance their cyber-secure and cyber-resilient safe operation. This paper thereby contributes to the field of cyber-security of Cyber-Physical Energy Systems (CPES).
In this paper, we propose two new approaches aimed at enhancing the security of industrial control systems (ICS) that utilize programmable logic controllers (PLCs) for the control of critical processes. The first approach involves the addition of a unique digital watermark to the PWM control that adjusts the motor speed to control the critical process. This enables efficient detection and identification of any unauthorized modifications to the sensor signals responsible for controlling the plant. The second approach focuses on monitoring the input current (i.e power) drawn by the PLC during the execution of critical process control tasks. Malicious intrusions to change the PLC parameters and/or unauthorized firmware updates can be rapidly detected. Both approaches demonstrate a substantial improvement in the security of ICS, effectively safeguarding against potential cyber-attacks. Experimental results from a laboratory scale water tank level controlled via PLC showcases rapid intrusion detection capabilities.
Surface drying is a critical process in microelectronics wafer fabrication. In order to reduce and eliminate watermarks, many surface drying processes have been studied and used. Most of the wafer foundries currently use drying processes based on Isopropyl Alcohol (IPA), which causes serious safety (fire), health, environmental, and energy efficiency issues. The long-term goal of this project is to develop a fast, effective, chemical-free, and extremely energy efficient wafer drying technology that employs nanosecond laser-induced sub-surface evaporation and explosion. The objectives of this project are to 1) experimentally develop and verify the laser surface drying method, explore and identify how and to what extent various physical parameters influence the drying efficiency and effectiveness; and 2) understand and optimize the underlying thermodynamics in the proposed laser surface drying, including micro/nanoscale sub-surface superheating, evaporation, explosion, and photo/thermochemical bond breaking via atomistic modeling and experimental characterization. Toward these objectives, five tasks have been accomplished successfully, including 1) develop in-lab laser surface drying setup and study the effect of varied laser parameters, 2) use multiscale hybrid-modeling to study and understand the physics of water behavior during drying toward process optimization, 3) investigate the effect of drying conditions on the drying effectiveness, 4) develop a large-scale laser drying scanning system with automatic scanning, and 5) conduct large-scale simulation to study the effect of dopant level and develop strategies for system development toward industry deployment.
Not Available