Technical Report on Resilient and Secure Large-Scale Energy Internet Systems
Ioannis Zografopoulos, Karen Largman, Isaac Ortega Romero, S M Zia Ur Rashid, Yexiang Chen, George Fragkos, Charalambos Konstantinou, Subhash Lakshminarayana, Juan Ospina, Airin Rahman, Suman Rath, Vivek Kumar Singh, Mucun Sun, Wei Sun
University of Massachusetts Boston · The University of Tulsa · University of Warwick · Sandia National Laboratories · King Abdullah University of Science and Technology · Orennia · University of Central Florida · National Laboratory of the Rockies · Idaho National Laboratory
eess.SY, cs.CR, cs.SY
Submitted: 2026-08-13
Updated: 2026-08-14
Comments: Task Force on Resilient and Secure Large-Scale Energy Internet Systems, August 2026
License: http://creativecommons.org/licenses/by/4.0/
Importance score: 95/100
The gist: This IEEE PES Task Force report examines the security and resilience of large-scale Energy Internet (EI) systems, in which electricity, information, and market layers are tightly coupled through
Terminology
Summary
This IEEE PES Task Force report examines the security and resilience of large-scale Energy Internet (EI) systems, in which electricity, information, and market layers are tightly coupled through pervasive digitalization. The report characterizes the EI cyberphysical threat landscape and surveys detection, assurance, and mitigation techniques; presents modeling, control, and decisionmaking frameworks that capture cyber-physical interdependencies, including storage integration, multi-dimensional resilience, and electricity price forecasting; examines adversarial risks and trustworthy deployment of artificial intelligence; and introduces graph-based, attack-resilient information routing. The report closes with recommendations for research, standardization, and regulatory efforts needed to realize a resilient and secure large-scale EI.
The report is organized into several key sections. Section 3, Cybersecurity and Assurance of Large-Scale Energy Internet Systems: Threat Landscape, Detection, and Resilience,
reviews the cyber-physical threat landscape of large-scale EI systems and the state of the art in assessment, detection, and resilience. The central premise is that "confidentiality-, integrity-, and availability-centric IT security is necessary but insufficient for the EI. Because attacks ultimately express themselves through physical quantities (frequency, voltage, power flows, and market prices), defense must be cyber-physical and must be evaluated against physical and economic impact rather than against information-layer indicators alone." The section develops a layered threat taxonomy covering False Data Injection Attacks (FDIA), Load-Altering Attacks (LAA), firmware/hardware/supply-chain attacks, communication/timing/availability attacks, and economic/market-layer attacks. It also discusses real-world incidents, including the 2015-2016 Ukrainian grid attacks and a 2025 wave of cyberattacks in Poland associated with a grid outage affecting roughly half a million people. The section examines vulnerabilities of inverter-based and DER-rich systems, including smart-inverter and synchronization-loop attacks, DER coordination and aggregation, and standards/interoperability as a security surface. It covers impact modeling and quantitative assessment, detection and localization methods (model-based, data-driven, and physics-informed/hybrid), and mitigation/defense/resilience mechanisms such as resilient and event-triggered control, Moving Target Defense (MTD), digital twins, hardware-rooted trust, and economic/risk-transfer mechanisms. Emerging challenges include large dynamic AI data-center loads, coupled markets and physics across TSO-DSO boundaries, quantum threats and post-quantum assurance, and AI as both shield and weapon.
Section 4, Modeling and Control of Transmission and Distribution Networks via Energy-Internet Systems,
discusses the evolution toward EI-enabled TnD networks, regulatory frameworks and data exchange across TnD systems, and mathematical modeling and intelligent control. It highlights that "the convergence of electrical infrastructure and digital communication has given rise to the concept of the Energy-Internet, in which DERs, network operators, market participants, and stakeholders interact through standardized communication protocols and interoperable information models. The section covers control and optimization across the TnD boundary, including mathematical vulnerabilities in State Estimation (SE) and Optimal Power Flow (OPF). It explains that
corrupted measurements or models do not simply degrade situational awareness, but they directly alter the mathematical models used to estimate the operating state of the power system and compute optimal control actions." The section also presents optimization mitigation frameworks, including Robust Optimization (RO), Homomorphic Encryption for Multi-Area OPF, and Feasibility-Restricted Slack Variables.
Section 5, Decision-Aware Cyber-Physical Resilience for Storage-Integrated Energy Internet Systems,
proposes a decision-aware admissibility framework for storage-integrated EI resilience. The framework introduces an admissibility layer between state estimation and resilience action execution, screening each candidate action using three coupled conditions: storage adequacy, information integrity, and physical feasibility. The key principle is that EI resilience actions should be selected only after jointly checking storage adequacy, information integrity, and physical feasibility.
The section introduces metrics such as the Storage Adequacy Index (SAI), the Decision Integrity Gap (DIG), and the physical security margin. It presents case studies showing that hydrogen LDES improves the Resilience Index (RI) to 96.0% and reduces restoration time to two hours, compared with 79.5% RI and seven hours without storage. It also demonstrates that energy-state-driven adaptive restoration improves RI from 54.2% to 65.2%, and that security-region-constrained restoration feasibility is critical, as restoration trajectories can reach inverter overcurrent, modulation-voltage, or solvability boundaries before stored energy is exhausted.
Section 6, Multi-dimensional Resilience Considerations in Energy-Internet Systems,
develops a quantitative Multidimensional Resilience Index (MDRI) that aggregates cross-dimensional degradation under simultaneous stress interactions. The framework characterizes resilience through five dimensions: physical, operational, digital-cyber, climate-external, and regulatory. The MDRI decomposes degradation into an additive and a coupling contribution, where "the coupling term captures additional degradation arising from simultaneous cross-dimensional compromise; it collapses to zero whenever any single dimension remains uncompromised, and reaches its maximum only when all dimensions are jointly and severely degraded, encoding the cascading failure mechanism. The section validates the framework on the IEEE 39-bus test system under two attack scenarios: a single-plant baseline attack and a multi-vector cascading attack. The results show that
a coordinated multi-vector attack raises the endogenous core roughly 8 times over a single-vector baseline through cross-dimensional coupling alone, while climatic and regulatory stressors add a further 84%, yielding an approximately 15 times overall increase in resilience loss."
Section 7, Electricity Price Forecasting in the Energy Internet Era,
examines EPF from the perspective of resilient and secure EI operation. The central argument is that EPF is evolving into a market intelligence layer that supports operational reliability, resilience, and security under uncertain and potentially adversarial conditions.
The section discusses the evolution of EPF from a market-participant decision tool into a critical enabling technology, covering representation learning, physics-informed and topology-aware learning, probabilistic forecasting and uncertainty quantification, cyber-resilient forecasting and anomaly detection, and foundation models. It emphasizes that forecasting and cyber monitoring should not be separate afterthoughts. A resilient forecasting platform must understand when it does not trust its inputs or its own predictions.
Section 8, Adversarial Risks from AI Integration to Energy Systems,
discusses how AI-based systems can become attractive targets for cyber attackers. It highlights that adversarial attacks in power systems are constrained not only to bypass the ML model's detection, but also by the underlying physical laws governing power system operation.
The section compares adversarial attacks in image processing with those in power systems, noting that "gradient-based perturbations that are highly effective for attacking image classifiers may no longer remain effective against FDIA detectors in power systems because they must simultaneously satisfy the physical constraints and stealthiness requirements of the power system. The section also discusses defenses, particularly MTD, which
adopts a fundamentally different philosophy by continuously invalidating the attacker's knowledge rather than attempting to identify every possible attack."
Section 9, Trustworthy AI-Driven Cyber-Physical Security for a Resilient Energy Grid,
examines AI as an enabling capability for cyber-physical security in EI-enabled grid systems. The section emphasizes that the most relevant anomalies often appear as inconsistencies between cyber inputs, control actions, and physical response, rather than as isolated cyber events or isolated physical deviations.
It covers supervised learning, unsupervised and semi-supervised learning, temporal and sequence-based models, physics-informed and hybrid AI approaches, and generative AI. The section also addresses explainability, trustworthiness, and model governance, including SHAP-based explanations and custom-made explanations for unsupervised models. It concludes that "trustworthy AI in the electric grid should not be treated as an isolated analytics capability. It should be managed as an operational cyber asset, governed under the same discipline applied to other security-critical functions."
Section 10, Graph Algorithms for Attack-Resilient Information Routing in the Energy Internet,
explains how communication networks supporting the EI can be represented as a graph, and how a combination of intrusion detectors and graph routing algorithms can help achieve cyber-resilience. The section describes edge-level intrusion detection in Trusted Execution Environments (TEEs), and attack-resilient routing via epsilon-greedy graph search. It covers classical graph algorithms (Prim's, Kruskal's, and Dijkstra's) applied to weighted graphs where edge weights represent manipulation scores. The section also discusses multi-path delivery for critical traffic, scheduling exploration, behavior when no clean path exists, and resilience under active manipulation. It concludes that the system does not need to depend on a compromised device to keep functioning. It just needs another path to exist somewhere in the network for information rerouting in the presence of one or more adversarial entities.
The report concludes with recommendations, emphasizing that security and resilience should be treated as coupled, cross-layer design objectives rather than isolated attributes,
and that the community should invest in realistic validation infrastructure, including real-time co-simulation, controller-in-the-loop and HIL testbeds, and digital twins.
It also recommends systematically leveraging the flexibility inherent to DERs, energy storage, controllable loads, and adaptive control schemes as a resilience resource, deploying AI with explicit consideration of adversarial risks, and ensuring a coordinated approach to operation and stability control supported by secure communication protocols and resilient information routing.
Improvements for AI systems
Improvements to AI Systems:
- Physics-Constrained Adversarial Defense for AI Detectors
-
Integrate power-system physical laws (e.g., power flow equations, voltage stability limits) directly into the training and inference of AI-based anomaly detectors (e.g., FDIA detection).
-
Add a
physical feasibility
filter that rejects AI predictions or classifications that violate grid constraints, even if the AI model's confidence is high. -
Improved AI system: Detects and blocks cyber-physical attacks that would otherwise evade purely data-driven detectors by ensuring all flagged anomalies are consistent with observable physical behavior.
- Cross-Dimensional Resilience-Aware AI Decision Making
-
Extend AI controllers and optimizers to use the Multidimensional Resilience Index (MDRI) as a real-time objective or constraint, explicitly modeling coupling terms between physical, cyber, climate, and regulatory stressors.
-
Train reinforcement learning agents to avoid actions that increase cross-dimensional coupling degradation (e.g., a control action that improves voltage but worsens cyber vulnerability).
-
Improved AI system: Chooses control and restoration actions that minimize cascading failures across multiple simultaneous stress vectors, rather than optimizing a single dimension in isolation.
- Decision-Aware AI for Storage-Integrated Resilience
-
Modify AI-based state estimators and restoration planners to include an
admissibility layer
that checks storage adequacy, information integrity, and physical feasibility before executing any suggested action. -
Use the Storage Adequacy Index (SAI) and Decision Integrity Gap (DIG) as additional input features to AI models, enabling them to reject actions that would fail under data corruption or insufficient stored energy.
-
Improved AI system: Recommends only restoration or load-shedding actions that are guaranteed to be physically feasible and information-secure, reducing the risk of cascading failures due to bad data or overestimated storage.
- AI-Enhanced Cyber-Resilient Forecasting
-
Build forecasting models that output both predictions and a
trust score
based on input data integrity and model uncertainty, using physics-informed and topology-aware learning. -
Integrate anomaly detection into the forecasting pipeline so that the AI automatically flags when its inputs (e.g., market prices, sensor data) are corrupted or manipulated.
-
Improved AI system: Provides electricity price and load forecasts that are robust to cyberattacks, with automatic degradation warnings when the AI detects that its own inputs or predictions are unreliable.
- Graph-Based AI for Attack-Resilient Routing
-
Combine graph neural networks (GNNs) with epsilon-greedy exploration to learn routing policies that dynamically reroute critical EI communication traffic around compromised nodes, using edge weights derived from intrusion detection scores.
-
Train the AI to balance exploration (finding new paths) and exploitation (using known-good paths) in real time, even when no clean path exists.
-
Improved AI system: Maintains communication integrity for grid control signals even under active cyber manipulation, by continuously discovering and switching to alternative paths without relying on compromised devices.
- Adversarially Robust AI for Market and Physical Layer Attacks
-
Train AI models (e.g., for state estimation or market price forecasting) using adversarial examples that respect physical constraints, such as load-altering attacks or economic manipulation.
-
Incorporate moving target defense (MTD) as a training strategy, where the AI learns to operate under continuously changing system parameters, invalidating attacker knowledge.
-
Improved AI system: Maintains accurate state estimation and market predictions even when attackers have partial knowledge of the system, because the AI is robust to perturbations that satisfy physical laws and stealthiness constraints.
- Trustworthy AI as an Operational Cyber Asset
-
Implement AI models with built-in explainability (e.g., SHAP) and model governance, treating them as security-critical components that are monitored, versioned, and audited like other grid assets.
-
Add a
cyber-physical consistency check
layer that compares AI outputs against physical measurements and control actions, flagging inconsistencies as potential anomalies. -
Improved AI system: Provides actionable, explainable security alerts that highlight mismatches between cyber inputs, control actions, and physical responses, enabling operators to trust and verify AI decisions under adversarial conditions.
Abstract
This IEEE PES Task Force report examines the security and resilience of large-scale Energy Internet (EI) systems, in which electricity, information, and market layers are tightly coupled through pervasive digitalization. The report characterizes the EI cyber-physical threat landscape and surveys detection, assurance, and mitigation techniques, presents modeling, control, and decision-making frameworks that capture cyber-physical interdependencies, including storage integration, multi-dimensional resilience, and electricity price forecasting, examines adversarial risks and trustworthy deployment of artificial intelligence, and introduces graph-based, attack-resilient information routing. The report closes with recommendations for research, standardization, and regulatory efforts needed to realize a resilient and secure large-scale EI.
Sources
- Load-Altering Attacks Against Power Grids under COVID-19 Low-Inertia Conditions
- When Market Prices Drive the Load: Modeling, Grid-Security Analysis, and Mitigation of Data Center Workload Scheduling
- Multidimensional Resilience for Electrical Power Systems: Systematic Review, Integrated Index, and Validation under Real-World Cyber-Physical Attack Scenarios
- Day-Ahead Electricity Price Forecasting for Volatile Markets Using Foundation Models with Regularization Strategy
- Risks of Practicing Large Language Models in Smart Grid: Threat Modeling and Validation
- Explaining and Harnessing Adversarial Examples
- Adversarial Machine Learning at Scale
Related papers
- One Request, Multiple Experts: LLM Orchestrates Domain Specific Models via Adaptive Task Routing
- A Geometric Decision Procedure for STL Feasibility and Repair
- Submodular Multi-Agent Policy Learning for Online Distributed Task Allocation in Open Multi-Agent Systems
- Policy-Level Recursive Self-Improvement for Embodied AI with a Criticality World Model
- Minimal Experiments for Robust Stabilization: Information, Spectral Geometry, and Duration
- Decentralized Power-Optimal Coordination for Spacecraft Swarms Using Time-Varying Magnetorquer Actuation