News

New AI Model Detects and Locates Cyberattacks in Large Power Networks

Dr. Rachad Atat and co-authors developed a new AI model to increase the security of large-scale smart grids against cyberattacks.

By Sergio Thoumi

Cyberattacks on critical infrastructure can disrupt essential services and, in severe cases, paralyze large parts of society. Modern power grids are particularly exposed as they rely on interconnected sensors, communication networks, and automated control systems.

Manipulating the data used to monitor and control a grid can be enough to mislead operators and automated systems into making the wrong decisions. Detecting such an intrusion is only part of the challenge; to respond effectively, operators must also be able to identify the targeted part of the grid. As many existing machine learning approaches analyze relationships between two connection points at a time, they might overlook coordinated attacks across larger groups of the network.

A broader approach was developed in research involving Dr. Rachad Atat, assistant professor of computer science at the School of Arts and Sciences. “Simplicial Graph-Based Detection and Localization of Cyber Attacks Against Large-Scale Smart Grids,” published in IEEE Transactions on Smart Grid, introduces a model that can also represent interactions among three or more points, allowing it to capture group-level patterns among buses, which are the electrical connection points used to model a power system, and transmission lines.

“Existing AI-based security approaches tend to examine either individual measurements or simple connections between pairs of components,” explained Dr. Atat. Large transmission grids, however, contain groups of buses and transmission lines whose behavior is closely interconnected, and a coordinated attack can exploit relationships extending beyond individual components or pairs. By modeling these “higher-order structures,” the researchers sought to develop a system capable of both detecting and localizing an attack, even in very large networks.

The researchers tested the model using simulated power flow data on three large-scale benchmark transmission systems, including European grid models and a 70,000-bus synthetic system designed to reflect the U.S. Eastern Interconnection.

Their model outperformed the machine learning methods across the large-scale tests. Against complex attacks, its detection rate improved by 9–39 percent, depending on the network and comparison, while its ability to localize the affected points improved by 8–35 percent.

The findings suggest that coordinated attacks leave a structural signature that pairwise models might not recognize. By carrying information through both ordinary connections and multi-point groupings over time, the model can distinguish normal changes in a large grid from malicious combinations and then narrow down their location. Rapid and accurate localization could help a control room focus verification and containment efforts instead of treating the entire network as equally suspect.

Dr. Atat sees particular relevance for countries such as Lebanon, where electricity infrastructure requires substantial modernization. Rebuilding the system, he said, presents an opportunity to introduce smart grid technologies while incorporating cybersecurity from the outset. Digital monitoring, sensors and real-time data could improve visibility across the grid and support the future integration of renewable energy, but they would also introduce new avenues for cyberattacks.

“The key is to consider cybersecurity alongside the deployment of new digital grid technologies, rather than adding it later,” he said. The approach developed in the study could eventually contribute as an intelligent monitoring layer capable of detecting attacks and directing operators toward affected locations.

Moving toward deployment, however, will first require testing the model with operational grid data, added Dr. Atat. 

“A key next step is hardware-in-the-loop testing,” he said, potentially using the OPAL-RT platform through collaborators at Florida State University. Such testing would allow the researchers to evaluate the model under conditions that more closely reproduce the interaction between physical power system equipment, control systems, and cyber monitoring before progressing toward operational use.

Cybersecurity tools for critical infrastructure must keep pace with the complexity of the systems they protect. This study shows that looking beyond one-to-one connections can strengthen both detection and response, offering grid operators a more informative view of coordinated threats.

To browse more scholarly output by the LAU community, visit our open-access digital archive, the Lebanese American University Repository (LAUR).