Aug 2026· Applied Sciences· Vol 16, pp. 7847· 0 citations· 35 references
TL;DR
A tri-level defender–attacker–defender (DAD)-based attack strategy optimization model is proposed that identifies the most damaging coordinated cyber–physical attack strategies and that BTA-induced topology changes and cascading failure propagation significantly affect attack target selection.
Abstract
Deliberate coordinated cyber–physical attacks, which combine cyber intrusions with physical disruptions, pose growing risks to the secure and reliable operation of power systems. To identify highly disruptive coordinated cyber–physical attack strategies under pre-attack defense allocation and post-attack emergency dispatch responses, a tri-level defender–attacker–defender (DAD)-based attack strategy optimization model is proposed. First, based on the association between substation automation control systems and transmission line operation, the mechanism of breaker-tripping attacks (BTAs) through compromised digital relays in substations is investigated. Second, a tri-level DAD model is developed to optimize coordinated BTA and physical line attack strategies while accounting for pre-attack cyber and physical defense, cascading failure propagation, and post-attack emergency dispatch responses. Then, based on duality theory, network flow models, and the column-and-constraint generation (C&CG) algorithm, an iterative solution framework consisting of a defense master problem and an attack-dispatch subproblem is constructed to capture post-attack topology updates, cascading line outages, generator redispatch and load-shedding responses. Finally, the proposed method is validated using the IEEE 39 bus and IEEE 118 bus power systems. Case study results demonstrate that the proposed model identifies the most damaging coordinated cyber–physical attack strategies and that BTA-induced topology changes and cascading failure propagation significantly affect attack target selection. The proposed solution method obtains the accurate optimal objective value while reducing computational time by 92.91% for IEEE 39 bus power system, and it successfully obtains a converged solution for IEEE 118 bus power system.
Active cyber defense offers a promising approach to addressing the longstanding asymmetry between rapidly evolving cyber threats and static defense systems. However, active cyber defense requires fast responses and proactive reconfigurations that must be verified and tailored to observed attacker behaviour. Formal methods rely on rigorous mathematical and logical frameworks for verifying system specifications under welldefined assumptions. In particular, multi-agent system (MAS) verification, which examines formal properties of open systems, is well-suited for cybersecurity where attacker-defender interactions are central. This paper bridges the gap between system security modelling and MAS verification, providing active defense orchestration with formal guarantees. Our contributions are (i) a general methodology for controlling active cyber defenses with formally verified specifications based on the attack-defense movement model (ADM), a new model of attacker and defender actions, (ii) an application of this methodology for adaptive honeypot control, which relies on a MAS logic contribution to express strategic properties such as attacker attribution, and (iii) VeriPot, a tool which implements the honeypot adaptation strategy extraction from the ADM.
Gabriel Ballot, E. Borde, Vadim Ma Lvone et al.· IEEE Computer Security Found...· 0 citations
With the increasing frequency of extreme weather events and cyber attacks, the secure operation of power distribution networks faces severe challenges. Man-in-the-Middle attack is cyber attack method in which attacker intercepts and alters the communication data, potentially leading to power outages. This paper proposes a comprehensive strategy to address this attacks during the restoration process of power distribution networks. Firstly, the principles and target objects of attacks are analyzed, and their propagation mechanisms within power distribution networks are studied. Further, a model for the cyber-physical coordinated restoration of power distribution networks considering communication-physical coupling is established to optimize the restoration process and mitigate the impact of the attack. Finally, the effectiveness of the proposed method is validated through simulation experiments on the IEEE-33 bus power system.
Jianming Jiang, Chunxiang Liu, Tao Zhang et al.· International Conference on...· 0 citations
This paper proposes Substation Cyber Attack Strategy Phasing (SubCASP), a Hidden Markov Model(HMM)- based method that fuses IDS data logs to infer the current attack phase, next attack phase, and retrospective attack path.
Akila Herath, Chen-Ching Liu, Junho Hong et al.· arXiv.org· 0 citations
In parallel to the cyber attack that manipulates the reference points of distributed energy resources (DERs) by maliciously accessing the remote monitoring and control system, the vulnerability of voltage/current sensors to electromagnetic interference (EMI) in the physical domain has been widely discussed. Existing research efforts against sensor spoofing attacks can be classified into physical prevention and cyber detection/mitigation. These defence methods each have strengths and weaknesses in balancing cost, security, and performance in a single DER, yet systematic research on their multi-layer efficient coordination across DERs remains limited. Towards this end, this paper proposes a hierarchical framework to detect and mitigate sensor spoofing attacks in networked microgrids (NMGs) via {multi-layer cyber-physical coordination}. It requires only to deploy physical prevention technologies at critical points, i.e., the local points of common coupling (PCC) of MGs, such that cyber detection/mitigation algorithms can be adopted based on the secured sensor readings to counter sensor spoofing attacks in DERs. The framework employs an MG-DER coordinated proactive detection scheme to strategically trigger parameter perturbations, under which the intelligent sensor spoofing attacks can be {effectively} disclosed. Afterwards, mitigation schemes based on MG-DER coordination are activated to recursively and accurately estimate sensor biases. Experiments on a cyber-physical DC NMG testbed confirm the framework's effectiveness across diverse attack scenarios.
Mengxiang Liu, Xin Zhang, Shiyi Zhao et al.· IEEE Transactions on Smart G...· 0 citations
A Markov-enhanced hybrid IDS that integrates physics-based modeling, data-driven anomaly detection, and statistical sequence analysis to secure a two-turbine cyber-physical wind farm, offering an analytically scalable architectural path toward more secure renewable energy infrastructures, while larger-farm empirical validation remains future work.
Mahdi Esmaeelihesari, M. Davoudi, N. Pariz· International Journal of Dyn...· 0 citations
Cyber-physical systems (CPSs) are widely used in safety-critical applications, where both control reliability and communication efficiency are essential. However, open networks make CPSs vulnerable to false data injection (FDI) attacks, which threaten system stability. Existing event-triggered control methods often fail to simultaneously ensure attack resilience, stability, and $H_\infty$ performance. This paper addresses the secure control problem of CPSs under FDI attacks by proposing an observer-based dynamic event-triggered control framework. To counteract the adversarial disturbances, a novel attack-resilient observer is designed to simultaneously estimate both the system states and the injected attack signals, enabling the synthesis of a secure observer-based controller. An advanced dynamic event-triggered mechanism (DETM) is developed by incorporating an internal dynamic variable, which adaptively adjusts triggering thresholds to significantly reduce communication frequency while avoiding Zeno behavior. Through Lyapunov-Razumikhin analysis, the closed-loop system is proven to achieve asymptotic stability and guaranteed $H_\infty$ performance, ensuring robustness against bounded FDI attacks. Theoretical results are validated via numerical simulations, demonstrating the effectiveness of the proposed method in mitigating attack impacts and conserving network resources.
Lei Liu, Ruonan Ren, Baoling Miao· IEEE Transactions on Industr...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.