SearcharxivSearch

arXiv subjects

Chen-Ching Liu

Publications and source records attributed to Chen-Ching Liu.

At least 19 recordsLinked to original sources

Strategy Phasing of Cyber Attacks on Digital Substations

Digital substations that comply with IEC 61850 have improved the operational efficiency of modern power systems. However, adversaries can abuse IEC 61850 communication to manipulate circuit breaker operations in substations, which can result in severe system impacts. These cyber attacks are crafted based on broader multi-phase strategies. The existing intrusion detection systems (IDSs) often flag only isolated symptoms. Thus, there is a lack of context in the attack phase to support the deployment of mitigation measures. This paper proposes Substation Cyber Attack Strategy Phasing (SubCASP), a Hidden Markov Model(HMM)- based method that fuses IDS data logs to infer the current attack phase, next attack phase, and retrospective attack path. The attack phases are derived from an ATT&CK-based threat modeling. The SubCASP model is trained and evaluated on a reproducible attack-graph dataset. Test results are presented to demonstrate the robustness of SubCASP for various IDS observability levels and missing IDS data logs scenarios.

cs.CR

Evaluation of Real-Time Mitigation Techniques for Cyber Security in IEC 61850 / IEC 62351 Substations

The digitalization of substations enlarges the cyber-attack surface, necessitating effective detection and mitigation of cyber attacks in digital substations. While machine learning-based intrusion detection has been widely explored, such methods have not demonstrated detection and mitigation within the required real-time budget. In contrast, cryptographic authentication has emerged as a practical candidate for real-time cyber defense, as specified in IEC 62351. In addition, lightweight rule-based intrusion detection that validates IEC 61850 semantics can provide specification-based detection of anomalous or malicious traffic with minimal processing delay. This paper presents the design logic and implementation aspects of three potential real-time mitigation techniques capable of countering GOOSE-based attacks: (i) IEC 62351-compliant message authentication code (MAC) scheme, (ii) a semantics-enforced rule-based intrusion detection system (IDS), and (iii) a hybrid approach integrating both MAC verification and Intrusion Detection System (IDS). A comparative evaluation of these real-time mitigation approaches is conducted using a cyber-physical system (CPS) security testbed. The results show that the hybrid integration significantly enhances mitigation capability. Furthermore, the processing delays of all three methods remain within the strict delivery requirements of GOOSE communication. The study also identifies limitations that none of the techniques can fully address, highlighting areas for future work.

cs.CR

Large Language Models for Power System Security: A Novel Multi-Modal Approach for Anomaly Detection in Energy Management Systems

This paper elaborates on an extensive security framework specifically designed for energy management systems (EMSs), which effectively tackles the dynamic environment of cybersecurity vulnerabilities and/or system problems (SPs), accomplished through the incorporation of novel methodologies. A comprehensive multi-point attack/error model is initially proposed to systematically identify vulnerabilities throughout the entire EMS data processing pipeline, including post state estimation (SE) stealth attacks, EMS database manipulation, and human-machine interface (HMI) display corruption according to the real-time database (RTDB) storage. This framework acknowledges the interconnected nature of modern attack vectors, which utilize various phases of supervisory control and data acquisition (SCADA) data flow. Then, generative AI (GenAI)-based anomaly detection systems (ADSs) for EMSs are proposed for the first time in the power system domain to handle the scenarios. Further, a set-of-mark generative intelligence (SoM-GI) framework, which leverages multimodal analysis by integrating visual markers with rules considering the GenAI capabilities, is suggested to overcome inherent spatial reasoning limitations. The SoM-GI methodology employs systematic visual indicators to enable accurate interpretation of segmented HMI displays and detect visual anomalies that numerical methods fail to identify. Validation on the IEEE 14-Bus system shows the framework's effectiveness across scenarios, while visual analysis identifies inconsistencies. This integrated approach combines numerical analysis with visual pattern recognition and linguistic rules to protect against cyber threats and system errors.

cs.CR

An Advanced Cyber-Physical System Security Testbed for Substation Automation

A Cyber-Physical System (CPS) testbed serves as a powerful platform for testing and validating cyber intrusion detection and mitigation strategies in substations. This study presents the design and development of a CPS testbed that can effectively assess the real-time dynamics of a substation. Cyber attacks exploiting IEC 61850-based SV and GOOSE protocols are demonstrated using the testbed, along with an analysis on attack detection. Realistic timing measurements are obtained, and the time frames for deploying detection and mitigation strategies are evaluated.

cs.CR

Detecting Zero-Day Attacks in Digital Substations via In-Context Learning

The occurrences of cyber attacks on the power grids have been increasing every year, with novel attack techniques emerging every year. In this paper, we address the critical challenge of detecting novel/zero-day attacks in digital substations that employ the IEC-61850 communication protocol. While many heuristic and machine learning (ML)-based methods have been proposed for attack detection in IEC-61850 digital substations, generalization to novel or zero-day attacks remains challenging. We propose an approach that leverages the in-context learning (ICL) capability of the transformer architecture, the fundamental building block of large language models. The ICL approach enables the model to detect zero-day attacks and learn from a few examples of that attack without explicit retraining. Our experiments on the IEC-61850 dataset demonstrate that the proposed method achieves more than $85\%$ detection accuracy on zero-day attacks while the existing state-of-the-art baselines fail. This work paves the way for building more secure and resilient digital substations of the future.

cs.LG

Machine Learning Based Cyber System Restoration for IEC 61850 Based Digital Substations

Substation Automation Systems (SAS) that adhere to the International Electrotechnical Commission (IEC) 61850 standard have already been widely implemented across various on-site local substations. However, the digitalization of substations, which involves the use of cyber system, inherently increases their vulnerability to cyberattacks. This paper proposes the detection of cyberattacks through an anomaly-based approach utilizing Machine Learning (ML) methods within central control systems of the power system network. Furthermore, when an anomaly is identified, mitigation and restoration strategies employing concurrent Intelligent Electronic Devices (CIEDs) are utilized to ensure robust substation automation system operations. The proposed ML model is trained using Sampled Value (SV) and Generic Object Oriented Substation Event (GOOSE) data from each substation within the entire transmission system. As a result, the trained ML models can classify cyberattacks and normal faults, while the use of CIEDs contributes to cyberattack mitigation, and substation restoration.

eess.SY

SDN-Based Smart Cyber Switching (SCS) for Cyber Restoration of a Digital Substation

In recent years, critical infrastructure and power grids have increasingly been targets of cyber-attacks, causing widespread and extended blackouts. Digital substations are particularly vulnerable to such cyber incursions, jeopardizing grid stability. This paper addresses these risks by proposing a cybersecurity framework that leverages software-defined networking (SDN) to bolster the resilience of substations based on the IEC-61850 standard. The research introduces a strategy involving smart cyber switching (SCS) for mitigation and concurrent intelligent electronic device (CIED) for restoration, ensuring ongoing operational integrity and cybersecurity within a substation. The SCS framework improves the physical network's behavior (i.e., leveraging commercial SDN capabilities) by incorporating an adaptive port controller (APC) module for dynamic port management and an intrusion detection system (IDS) to detect and counteract malicious IEC-61850-based sampled value (SV) and generic object-oriented system event (GOOSE) messages within the substation's communication network. The framework's effectiveness is validated through comprehensive simulations and a hardware-in-the-loop (HIL) testbed, demonstrating its ability to sustain substation operations during cyber-attacks and significantly improve the overall resilience of the power grid.

cs.CR

Defense against Joint Poison and Evasion Attacks: A Case Study of DERMS

There is an upward trend of deploying distributed energy resource management systems (DERMS) to control modern power grids. However, DERMS controller communication lines are vulnerable to cyberattacks that could potentially impact operational reliability. While a data-driven intrusion detection system (IDS) can potentially thwart attacks during deployment, also known as the evasion attack, the training of the detection algorithm may be corrupted by adversarial data injected into the database, also known as the poisoning attack. In this paper, we propose the first framework of IDS that is robust against joint poisoning and evasion attacks. We formulate the defense mechanism as a bilevel optimization, where the inner and outer levels deal with attacks that occur during training time and testing time, respectively. We verify the robustness of our method on the IEEE-13 bus feeder model against a diverse set of poisoning and evasion attack scenarios. The results indicate that our proposed method outperforms the baseline technique in terms of accuracy, precision, and recall for intrusion detection.

cs.CR

SDN-Based Dynamic Cybersecurity Framework of IEC-61850 Communications in Smart Grid

In recent years, critical infrastructure and power grids have experienced a series of cyber-attacks, leading to temporary, widespread blackouts of considerable magnitude. Since most substations are unmanned and have limited physical security protection, cyber breaches into power grid substations present a risk. Nowadays, software-defined network (SDN), a popular virtual network technology based on the OpenFlow protocol is being widely used in the substation automation system. However, the susceptibility of SDN architecture to cyber-attacks has exhibited a notable increase in recent years, as indicated by research findings. This suggests a growing concern regarding the potential for cybersecurity breaches within the SDN framework. In this paper, we propose a hybrid intrusion detection system (IDS)-integrated SDN architecture for detecting and preventing the injection of malicious IEC 61850-based generic object-oriented substation event (GOOSE) messages in a digital substation. Additionally, this program locates the fault's location and, as a form of mitigation, disables a certain port. Furthermore, implementation examples are demonstrated and verified using a hardware-in-the-loop (HIL) testbed that mimics the functioning of a digital substation.

cs.CR

Fast Inverter Control by Learning the OPF Mapping using Sensitivity-Informed Gaussian Processes

Fast inverter control is a desideratum towards the smoother integration of renewables. Adjusting inverter injection setpoints for distributed energy resources can be an effective grid control mechanism. However, finding such setpoints optimally requires solving an optimal power flow (OPF), which can be computationally taxing in real time. This work proposes learning the mapping from grid conditions to OPF minimizers using Gaussian processes (GPs). This GP-OPF model predicts inverter setpoints when presented with a new instance of grid conditions. Training enjoys closed-form expressions, and GP-OPF predictions come with confidence intervals. To improve upon data efficiency, we uniquely incorporate the sensitivities (partial derivatives) of the OPF mapping into GP-OPF. This expedites the process of generating a training dataset as fewer OPF instances need to be solved to attain the same accuracy. To further reduce computational efficiency, we approximate the kernel function of GP-OPF leveraging the concept of random features, which is neatly extended to sensitivity data. We perform sensitivity analysis for the second-order cone program (SOCP) relaxation of the OPF, whose sensitivities can be computed by merely solving a system of linear equations. Extensive numerical tests using real-world data on the IEEE 13- and 123-bus benchmark feeders corroborate the merits of GP-OPF.

eess.SP

Resilience-Motivated Distribution System Restoration Considering Electricity-Water-Gas Interdependency

A major outage in the electricity distribution system may affect the operation of water and natural gas supply systems, leading to an interruption of multiple services to critical customers. Therefore, enhancing resilience of critical infrastructures requires joint efforts of multiple sectors. In this paper, a distribution system service restoration method considering the electricity-water-gas interdependency is proposed. The objective is to provide electricity, water, and natural gas supplies to critical customers in the desired ratio according to their needs after an extreme event. The operational constraints of electricity, water, and natural gas networks are considered. The characteristics of electricity-driven coupling components, including water pumps and gas compressors, are also modeled. Relaxation techniques are applied to nonconvex constraints posed by physical laws of those networks. Consequently, the restoration problem is formulated as a mixed-integer second-order cone program, which can readily be solved by the off-the-shelf solvers. The proposed method is validated by numerical simulations on electricity-water-gas integrated systems, developed based on benchmark models of the subsystems. The results indicate that considering the interdependency refines the allocation of limited generation resources and demonstrate the exactness of the proposed convex relaxation.

eess.SY

Bilateral Market for Distribution-level Coordination of Flexible Resources using Volttron

Increasing penetrations of distributed energy resources (DERs) and responsive loads (RLs) in the electric power distribution systems calls for a mechanism for joint supply-demand coordination. Recently, several transactive/bilateral coordination mechanisms have been proposed for the distribution-level coordination of flexible resources. Implementing a transactive market coordination approach requires a secure, reliable, and computationally efficient multi-agent platform. An example of such a platform is VOLTTRON, developed by the Pacific Northwest National Laboratories (PNNL). The VOLTTRON platform allows the market actors to exchange information and execute proper control actions in a decentralized way. This paper aims to provide a proof-of-concept of the transactive market coordination approach via a small-scale demonstration on the VOLTTRON platform. The steps needed to implement the proposed market architecture using virtual machines and VOLTTRON are thoroughly described, and illustrative examples are provided to show the market-clearing process for different scenarios.

eess.SY

Moving horizon-based optimal scheduling of EV charging: A power system-cognizant approach

The rapid escalation in plug-in electric vehicles (PEVs) and their uncoordinated charging patterns pose several challenges in distribution system operation. Some of the undesirable effects include overloading of transformers, rapid voltage fluctuations, and over/under voltages. While this compromises the consumer power quality, it also puts on extra stress on the local voltage control devices. These challenges demand for a well-coordinated and power network-aware charging approach for PEVs in a community. This paper formulates a real-time electric vehicle charging scheduling problem as an mixed-integer linear program (MILP). The problem is to be solved by an aggregator, that provides charging service in a residential community. The proposed formulation maximizes the profit of the aggregator, enhancing the utilization of available infrastructure. With a prior knowledge of load demand and hourly electricity prices, the algorithm uses a moving time horizon optimization approach, allowing the number of vehicles arriving unknown. In this realistic setting, the proposed framework ensures that power system constraints are satisfied and guarantees desired PEV charging level within stipulated time. Numerical tests on a IEEE 13-node feeder system demonstrate the computational and performance superiority of the proposed MILP technique.

eess.SY

Joint Grid Topology Reconfiguration and Design of Watt-VAR Curves for DERs

Operators can now remotely control switches and update the control settings for voltage regulators and distributed energy resources (DERs), thus unleashing the network reconfiguration opportunities to improve efficiency. Aligned to this direction, this work puts forth a comprehensive toolbox of optimization models leveraging the control capabilities of smart grid assets. We put forth detailed yet practical models to capture the operation of locally and remotely controlled regulators, and customize the watt-var DER control curves complying with the IEEE 1547.8 mandates. Maintaining radiality is a key requirement germane to various feeder optimization tasks. This requirement is accomplished here through an intuitive and provably correct formulation. The developed toolbox is put into action to reconfigure a grid for minimizing losses using real-world data on a benchmark feeder. The results corroborate that optimal topologies vary across the day and coordinating DERs and regulators is critical during periods of steep net load changes.

eess.SY

Bi-Level Volt-VAR Optimization to Coordinate Smart Inverters with Voltage Control Devices

Conservation voltage reduction(CVR) uses Volt-VAR optimization(VVO) methods to reduce customer power demand by controlling the feeders' voltage control devices. The objective of this paper is to present a VVO approach that controls the systems' legacy voltage control devices and coordinates their operation with smart inverter control. An optimal power flow (OPF) formulation is proposed by developing linear and nonlinear power flow approximations for a three-phase unbalanced electric power distribution system. A bi-level VVOapproach is proposed where Level-1 optimizes the control of legacy devices and smart inverters using a linear approximate three-phase power flow. In Level-2, the control parameters for smart inverters are adjusted to obtain an optimal and feasible solution by solving the approximate nonlinear OPF model. Level-1 is modeled as a Mixed Integer Linear Program(MILP) while level-2 as a Nonlinear Program(NLP) with a linear objective and quadratic constraints. The proposed approach is validated using 13-bus and 123-bus three-phase IEEE test feeders and a 329-bus three-phase PNNL taxonomy feeder. The results demonstrate the applicability of the framework in achieving the CVR objective. It is demonstrated that the proposed coordinated control approach help reduce feeders' power demand by reducing the bus voltages, the proposed approach maintains an average feeder voltage of 0.96 pu. A higher energy saving is reported during the minimum load conditions. The results and approximation steps are thoroughly validated using OpenDSS.

math.OC

A Two-Layer Distributed Control Method for Islanded Networked Microgrid Systems

This paper presents a two-layer, four-level distributed control method for networked microgrid (NMG) systems, taking into account the proprietary nature of microgrid (MG) owners. The proposed control architecture consists of a MG-control layer and a NMG-control layer. In the MG layer, the primary and distrib-uted secondary control realize accurate power sharing among distributed generators (DGs) and the frequency/voltage reference following within each MG. In the NMG layer, the tertiary control enables regulation of the power flowing through the point of common coupling (PCC) of each MG in a decentralized manner. Furthermore, the distributed quaternary control restores system frequency and critical bus voltage to their nominal values and ensures accurate power sharing among MGs. A small-signal dynamic model is developed to evaluate dynamic performance of NMG systems with the proposed control method. Time-domain simulations as well as experiments on NMG test systems are performed to validate the effectiveness of the proposed method.

math.OC

Coordinating Multiple Sources for Service Restoration to Enhance Resilience of Distribution Systems

When a major outage occurs on a distribution system due to extreme events, microgrids, distributed generators, and other local resources can be used to restore critical loads and enhance resiliency. This paper proposes a decision-making method to determine the optimal restoration strategy coordinating multiple sources to serve critical loads after blackouts. The critical load restoration problem is solved by a two-stage method with the first stage deciding the post-restoration topology and the second stage determining the set of loads to be restored and the outputs of sources. In the second stage, the problem is formulated as a mixed-integer semidefinite program. The objective is maximizing the number of loads restored, weighted by their priority. The unbalanced three-phase power flow constraint and operational constraints are considered. An iterative algorithm is proposed to deal with integer variables and can attain the global optimum of the critical load restoration problem by solving a few semidefinite programs under two conditions. The effectiveness of the proposed method is validated by numerical simulation with the modified IEEE 13-node test feeder and the modified IEEE 123-node test feeder under plenty of scenarios. The results indicate that the optimal restoration strategy can be determined efficiently in most scenarios.

math.OC

Optimal Distribution System Restoration with Microgrids and Distributed Generators

Increasing emphasis on reliability and resiliency call for advanced distribution system restoration (DSR). The integration of grid sensors, remote controls, and distributed generators (DG) brings about exciting opportunities in DSR. In this context, this work considers the task of single-step restoration of a single phase power distribution system. Different from existing works, the devised restoration scheme achieves optimal formation of islands without heuristically pre-identifying reference buses. It further facilitates multiple DGs running within the same island, and establishes a coordination hierarchy in terms of their PV/PQ operation modes. Generators without black-start capability are guaranteed to remain connected to a black-start DG or a substation. The proposed scheme models remotely-controlled voltage regulators exactly, and integrates them in the restoration process. Numerical tests on a modified IEEE 37-bus feeder demonstrate that the proposed mixed-integer linear program (MILP) takes less than four seconds to handle random outages of 1-5 lines. The scalability of this novel MILP formulation can be attributed to the unique use of cycles and paths on the grid infrastructure graph; the McCormick linearization technique; and an approximate power flow model.

math.OC