Results show that GridCAD-LLM provides a resilient, explainable, and scalable foundation for securing DNP3-based smart-grid communications.
Abstract
Legacy Distributed Network Protocol 3 (DNP3) communications remain widely used in modem smart grids, but they expose geographically distributed power infrastructure to coordinated cyberattacks that combine protocol-level command abuse with network-layer disruption. These threats require a defense framework that can detect multi-class attacks with low latency while also reasoning over source authorization, command semantics, and topology context to produce safe, auditable mitigation actions. This thesis presents GridCAD-LLM, a distributed software-defined networking framework for resilient DNP3 defense that integrates cloud-assisted multiclass traffic detection, source-aware event interpretation, and topology-grounded policy synthesis through a large language model. The framework combines distributed ONOS controllers, an Atomix-backed consensus layer, and a cloud-hosted multilayer perceptron to detect ten DNP3 attack classes and coordinate mitigation across grid regions. For administrative command-abuse events involving masteronly function codes, GridCAD-LLM uses DNP3 command semantics, victim-response evidence, and live ONOS topology context to generate validated SDN enforcement blueprints under explicit safety constraints. Evaluation in a geo-distributed AWS-based testbed shows 99.5 percent classification accuracy for routine attack classes, cloud-offloaded inference latency under 100 ms, and coordinated policy-update latency below 15 ms. Across 100 balanced command-abuse simulations, the policy-synthesis pipeline achieves 99 percent correctness with average inference latency below 2 s, while live retrieval-augmented updates improve heldout correctness from 94 percent to 100 percent. These results show that GridCAD-LLM provides a resilient, explainable, and scalable foundation for securing DNP3-based smart-grid communications.
An AI-assisted, cross-layer security orchestration framework that integrates epoch-wise telemetry with ML-based risk estimation and formalizes mitigation as a Constrained Markov Decision Process (CMDP), and empirical evidence that adaptive mitigation can reduce security risk without sacrificing service guarantees is provided.
F. Philip-Kpae, A. Imoize, K. .. Okafor et al.· E3S Web of Conferences· 0 citations
A 5G network slicing intrusion detection mechanism, called the DDoS Defense Model on 5G Network Slices (2D5NS) which integrates machine learning and real-time traffic monitoring techniques to detect and mitigate DDoS attacks within an O-RAN is proposed.
Kun-Lin Tsai, Shih-Ting Chiu, Chihhsiong Shih et al.· Computer Modeling in Enginee...· 0 citations
A reproducible pre-deployment analytics framework for physical/MAC-layer assessment of RF900, G3-PLC, GPRS CS2–CS3, hybrid PLC–GPRS, and renewable-event communication profiles is presented.
A. Villarroel, Milton Ruiz· Electronics· 0 citations
Distributed Spectrum Compliance and Orchestration (DISCO) is introduced, a hierarchical architecture that separates local spectrum learning from edge-level compliance regulation and slower cloud or non-terrestrial-network context adaptation.
L. S. Saoud, Moussa Ayyash· arXiv.org· 0 citations
The exponential growth of the Internet of Things (IoT) has magnified vulnerability to Distributed Denial-of-Service (DDoS) threats, particularly advanced TCP flooding attacks that exploit protocol weaknesses to disrupt services and overwhelm constrained devices. Existing Software-Defined Networking (SDN) defenses often suffer from scalability bottlenecks, high controller overhead, and limited adaptability to evolving traffic dynamics. To overcome these challenges, this paper proposes APATCP, a P4-enabled, multi-controller SD-IoT framework for real-time adaptive detection and mitigation of TCP flooding. APATCP integrates four coordinated modules: Adaptive Collaborative Intrusion Defense (ACID) for decentralized intelligence sharing; Dynamic Traffic Anomaly Mitigation (DTAM) for adaptive thresholding and flow isolation; Dynamic Threat-Adaptive Classifier (DTAC), which leverages 24 P4-extracted features and an adaptive weighted ensemble classifier for complex multi-type attack classification; and FlowGuard-AP, a context-aware mitigation engine with dynamic response strategies. Evaluation across three IoT-centric datasets—CICIoT2024, Edge-IIoTset, and ToN_IoT—demonstrates superior performance, with APATCP achieving 99.3–99.98% accuracy, 98.2–99.5% recall, F1-scores up to 99.2%, and false positive rates as low as 0.4%. In binary classification, it consistently outperformed baselines such as LightGBM (97.5–97.8%) and XGBoost (96.7–97.1%). In multi-class evaluations spanning eight adversarial scenarios—including burst floods, hybrid multi-vector campaigns, and stealthy microbursts—the framework maintained > 98% accuracy while remaining operationally stable. Live emulations confirmed resilience under > 100k packets/s attack rates, keeping CPU load below 30%, packet loss under 2%, and end-to-end latency below 100 ms, while restoring throughput to over 95% of baseline within seconds. These results establish APATCP as a scalable, adaptive, and resource-efficient framework that delivers high detection accuracy, low overhead, and robust mitigation, ensuring reliable defense for next-generation SD-IoT infrastructures against increasingly sophisticated TCP flooding threats.
Ashraf Alyanbaawi, A. Hassan, Marwa M. Khashaba et al.· Scientific Reports· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.