Source-linked AI summary
Public Plug-in Electric Vehicles + Grid Data: Is a New Cyberattack Vector Viable?
Samrat Acharya, Yury Dvorkin, Ramesh Karri
TL;DR
The paper asks whether public information about high-wattage PEV and EVCS demand can enable a cyberattack on power-grid frequency stability. It collects Manhattan data from public sources and designs a state-feedback attack using partial eigenvalue relocation; the attack is infeasible at current PEV penetration but becomes practical as PEV numbers increase.
Problem
The study addresses whether publicly available PEV, EVCS, and power-grid information creates a viable demand-side cyberattack vector against urban-grid stability.
Method
The study collects public Manhattan PEV, EVCS, and grid data, reconstructs the system, and designs a data-driven state-feedback attack using partial eigenvalue relocation.
Results
The attack can be designed to destabilize grid frequency in the case study, but current PEV penetration does not provide enough load for a feasible attack.
Takeaways & Limitations
The findings identify an emerging power-grid vulnerability that may become practical as more high-wattage EVCSs and PEVs charge simultaneously.
Takeaways & Limitations
Demand-side attack detection and mitigation must account for utilities’ limited observability of high-wattage appliances and privacy restrictions on PEV users.
Abstract
from arXiv · showhide
High-wattage demand-side appliances such as Plug-in Electric Vehicles (PEVs) are proliferating. As a result, information on the charging patterns of PEVs is becoming accessible via smartphone applications, which aggregate real-time availability and historical usage of public PEV charging stations. Moreover, information on the power grid infrastructure and operations has become increasingly available in technical documents and real-time dashboards of the utilities, affiliates, and the power grid operators. The research question that this study explores is: Can one combine high-wattage demand-side appliances with public information to launch cyberattacks on the power grid? To answer this question and report a proof of concept demonstration, the study scrapes data from public sources for Manhattan, NY using the electric vehicle charging station smartphone application and the power grid data circulated by the US Energy Information Administration, New York Independent System Operator, and the local utility in New York City. It then designs a novel data-driven cyberattack strategy using state-feedback based partial eigenvalue relocation, which targets frequency stability of the power grid. The study establishes that while such an attack is not possible at the current penetration level of PEVs, it will be practical once the number of PEVs increases.
I. INTRODUCTION
The paper examines whether attackers can combine publicly available PEV, EVCS, and power-grid information to target urban-grid stability. It frames demand-side attacks as difficult to monitor and assesses a realistic, data-driven attack rather than an omniscient worst-case scenario.
- Demand-side attacks expose more access points because PEV users, EVCSs, and grid operators manage a complex multi-actor cyberspace.
- High-wattage PEVs and EVCSs are not continuously monitored by grid operators, complicating attack detection and traditional isolation defenses.
- IoT-connected appliances can support demand-side attacks, although comparable attacks have been observed in other sectors rather than executed on power grids.
- Prior studies model generic appliances and customized test beds, whereas this paper uses specific PEV and public-EVCS attack vectors with limited attacker knowledge.
- The study evaluates a public-data-derived demand-side cyberattack using Manhattan PEV, EVCS, and power-grid information to manipulate loads and target frequency instability.
- EVCSs connect the power grid and PEVs through charging equipment, communications, and publicly accessible operational data.
2) Cyber Layer:
The cyber layer links PEVs, EVCSs, centralized servers, users, and grid-facing systems through wired and networked communications. These interfaces also generate charging-session and availability data that can be collected through public applications.
- 2) Cyber Layer:: EVCSs communicate with PEVs through wired channels that exchange charging availability, current, battery state of charge, and related control information.
- 2) Cyber Layer:: Commercial L2 and L3 EVCSs use WAN-connected centralized servers for authentication, session monitoring, data collection, and grid interfacing.
- 2) Cyber Layer:: PEV users access EVCS servers through smartphone applications, while servers can coordinate demand-response interactions with building energy systems.
- 2) Cyber Layer:: PEVs contain numerous CAN-connected electronic control units and communicate externally through wired and wireless technologies, including cellular networks.
- 2) Cyber Layer:: ChargePoint aggregated 319 L2 and L3 EVCSs in Manhattan as of March 2019, including locations, ratings, real-time availability, and historical hourly usage profiles.
2) Power grid data:
The study reconstructs Manhattan’s transmission grid and EVCS demand from fragmented public sources, combining topology, operational data, and inferred parameters to support attack modeling.
- 2) Power grid data:: Public power-grid data is fragmented across multiple sources, requiring manual review to reconstruct topology and component characteristics.Grid topology and electrical characteristics are assembled from public documents, dashboards, and utility materials.
- 2) Power grid data:: Figures characterize Manhattan’s public EVCS infrastructure, hourly demand variability, and its relationship to the transmission network.The figures cover EVCS counts and outlets, hourly consumption and standard deviation, and EVCS locations over the grid topology.
- 2) Power grid data:: Grid-data availability varies across systems, with market-operated grids publishing real-time demand, generation, flow, and price data.Grid topology can also be mined online, while remaining parameters may be inferred from IEEE and IEC standards.
- 2) Power grid data:: The Manhattan model combines EIA topology and capacity data, utility cross-checks, NYISO operational data, and node-level load allocation.The reconstructed network includes 345 kV and 138 kV transmission infrastructure.
- 2) Power grid data:: The attack-development workflow acquires public data, reconstructs grid configuration and EVCS demand, models parameters, and prepares an optimized attack.The workflow can incorporate additional openly accessible information and data brokers when needed.
1) Internal Vulnerabilities:
Internal PEV and EVCS interfaces expose physical and communication access points that can enable manipulation of vehicle or charging-system operations.
- 1) Internal Vulnerabilities:: PEV ECUs can be reached through peripherals, the CAN bus, or compromised external entities that communicate with the vehicle.The paper identifies manufacturers, EVCSs, and BEMS as examples of external entities.
- 1) Internal Vulnerabilities:: The OBD2 port provides a standardized interface to the CAN bus for monitoring and reporting vehicle operational status.It is typically located under the dashboard and can be used by mechanics, users, and regulators.
- 1) Internal Vulnerabilities:: CAN-bus access through OBD2 can support attacks on vehicle ECUs, including denial-of-service against brake-control systems.The OBD2 scanner is also paired with service portals and smartphone applications that may enable remote intrusion.
- 1) Internal Vulnerabilities:: Additional PEV access points include USB, SD-card, and optical-drive ports, as well as supply-chain and maintenance pathways.These routes can involve physical access or malicious devices and compromised vehicle parts.
- 1) Internal Vulnerabilities:: PEV back-end and EVCS communication links can expose charging commands and charging-current signals to spoofing, alteration, or related attacks.EVCSs may also be compromised through on-site interaction or remote communication interfaces.
- 1) Internal Vulnerabilities:: Public L3 EVCSs have greater physical exposure and physical access points than lower-level stations.Once hardware or firmware is accessed, attackers may affect service integrity, confidentiality, availability, or remote control.
2) External Vulnerabilities:
The paper models how compromised EVCS demand could perturb grid frequency through a data-driven state-space representation and eigenvalue-based stability analysis.
- 2) External Vulnerabilities:: The attack vector targets urban grids where PEV density, EVCS availability, and consumption density provide sufficient public data for modeling.The described strategy can trigger over-frequency events that activate relays, disconnect equipment, and cause load shedding.
- 2) External Vulnerabilities:: Small, rapid malicious load alterations are analyzed with linearized stability theory to assess their effect without alarming operators.The approach assumes disturbances are small relative to total system demand and swift in duration.
- 2) External Vulnerabilities:: The DC power-flow model is used as a conservative least-possible attack scenario, while the attack scheme is stated to extend to other power-flow models.The model includes generator inertia and damping and uses a 60 Hz synchronous reference.
- 2) External Vulnerabilities:: The model combines DC power flow with generator swing dynamics, automatic generation control, load damping, and EVCS demand alterations.The altered EVCS demand is represented at load nodes within the resulting dynamic equations.
- 2) External Vulnerabilities:: Public data can populate much of the linearized grid model, while undisclosed AGC gains are manually adjusted to keep the pre-attack model stable.Power-grid parameters and EVCS demand are obtained from public sources and standards.
- 2) External Vulnerabilities:: The grid is represented as a regularized LTI state-space system whose eigenvalues determine stability and can be related to state responses through participation factors.The state includes generator angles and speeds plus load-node voltage angles, while the attack input is associated with a launch node.
B. Data-driven Demand-Side Cyberattack
The paper’s data-driven demand-side attack is designed as a staged process that turns public infrastructure and demand data into an optimized grid attack.
- B. Data-driven Demand-Side Cyberattack: The proposed attack design uses full state feedback and proceeds through data acquisition, reconstruction and modeling, and attack preparation.The preparation stage designs and optimizes the attack using the reconstructed cyber-physical model and public EVCS demand data.
1) Data-Driven Attack Mechanism:
The attack uses public EVCS data to construct a state-feedback demand-side control model. It adjusts compromised EVCS demand through attacker-selected gains while accounting for changing grid states and publicly disclosed operating changes.
- Data-Driven Attack Mechanism:: Attacker-selected gains Ka are proportional to the amount of manipulated EVCS demand in the state-feedback model.The compromised system is represented by modifying the load-control input using Ka.
- Data-Driven Attack Mechanism:: System stability depends on the eigenvalues of A − BKa, which the attacker can influence by selecting Ka.The feasible gain values are constrained by the available EVCS demand that can be compromised.
- Data-Driven Attack Mechanism:: The attack uses x = [δ, ω, θ]T during preparation to represent whole-grid dynamics and calculate the required manipulated EVCS demand.Including these dynamics enables a more accurate calculation of ΔP_L.
- Data-Driven Attack Mechanism:: Public disclosures about outages, maintenance, schedules, and other operational changes can update the attacker’s grid model without real-time state measurements.The paper notes that grid topology modifications are rare and manual, allowing the attacker to track and modify the attack model.
2) Data-Driven Attack Optimization:
The optimization relocates selected power-grid eigenvalues toward instability while minimizing the attacker’s gain vector. Controllability determines how many eigenvalues can be relocated, and the gain remains bounded by available compromised demand.
- Data-Driven Attack Optimization:: The attacker minimizes Ka while making at least one compromised-model eigenvalue have a nonnegative real part.This balances instability creation against keeping load alterations small enough to reduce detection risk.
- Data-Driven Attack Optimization:: The original model is assumed stable with Re(eo) < 0, while adjusting Ka can make selected eigenvalues in ep real positive.The characteristic equations o(s) and p(s) represent the pre-attack and compromised models, respectively.
- Data-Driven Attack Optimization:: Figure 7 depicts the state-feedback attack in which the attacker adjusts Ka to calculate the amount of compromised loads.The diagram corresponds to the gain-selection mechanism used to influence the compromised system’s eigenvalues.
- Data-Driven Attack Optimization:: rank(Mc) upper-bounds the number of eigenvalues that can be arbitrarily relocated for a given EVCS input.Partial controllability means only rank(Mc) eigenvalues can be relocated on the complex plane.
- Data-Driven Attack Optimization:: The attacker specifies eigenvalues ea for relocation and retains the remaining eigenvalues er, then derives polynomial coefficients for the compromised model.The number of relocated eigenvalues satisfies m ≤ rank(Mc).
- Data-Driven Attack Optimization:: The controllability-based equations produce linear constraints in Ka that enforce the desired relocated eigenvalues.Matrices V and W, vector h, and controllability matrix Mc are parameterized from the grid model matrices A and B.
3) Parameter Uncertainty in the Data-Driven Attack:
The attack can be robustified against uncertainty in public EVCS data and learned grid parameters. This is done by modeling demand-capacity error probabilistically and adding an error margin to the constraint.
- Parameter Uncertainty in the Data-Driven Attack:: Model uncertainty is represented as ΔP_L(ϵ) = ΔP_L,max + ϵ, where ϵ captures parameter uncertainty or inaccuracy.The uncertainty may include Gaussian noise in the estimated maximum compromised EVCS demand.
- Parameter Uncertainty in the Data-Driven Attack:: The deterministic demand constraint is replaced with a probabilistic constraint to account for erroneous EVCS data.The attacker chooses η according to confidence in the learned data, and the reformulated constraint becomes second-order conic.
- Parameter Uncertainty in the Data-Driven Attack:: The error margin is α = φ^-1(η)Stdev(ϵ), where φ^-1 is the inverse standard-Gaussian cumulative distribution function.α adjusts the estimate of ΔP_L,max for uncertainty in ϵ.
V. CASE STUDY
The Manhattan case study evaluates attack feasibility using public EVCS and power-grid data under a generator-tripping operating condition. The setup uses node B7 as the reference and treats the optimization as computationally tractable.
- V. CASE STUDY: Node B7 is selected as the reference because it is Manhattan’s largest power supplier from New Jersey.The case study uses 100 MVA base power and a rated system frequency of 60 Hz.
- V. CASE STUDY: Generator tripping is assumed when frequency exceeds 62 Hz for more than 0.16 seconds, following IEEE Standard 1547.The state vector used in optimization is conservatively obtained for this tripping condition.
- V. CASE STUDY: The required manipulated EVCS demand is case-specific because the dynamic state vector changes with grid operating conditions and with the attack node.The paper states that changes in A are trackable and B varies with the interested attack node.
- V. CASE STUDY: The convex optimization is solved on a MacBook Air, with all reported instances completed within tens of seconds.The implementation uses CVX under MATLAB with a 2.2 GHz Intel Core i7 processor and 8 GB RAM.
A. Ability of the Attacker to Relocate Eigenvalues
The attack uses optimization to relocate selected pre-attack eigenvalues to prescribed real-positive-plane locations, producing unstable oscillations. At the current EVCS demand, however, the attack optimization is infeasible.
- The attacker uses optimization to move pre-attack eigenvalues to predetermined locations in the real-positive plane, causing system instability.The modeled system has 12 eigenvalues, and node B4 is selected as the attack location.
- Relocating 2 eigenvalues to 0.5 ± j5 corresponds to a damping ratio of ξ = −10% and a natural oscillation frequency of ωn = 5 rad/s.The relocation causes 2 of 12 state variables to oscillate with increasing amplitude at angular frequency ωn.
- ≈600 kW of current maximum daily EVCS demand cannot relocate any eigenvalue to the target locations, making the optimization infeasible.The observed peak and standard deviation both occur at 14:00 in the cited case.
B. Minimum EVCS Demand to Destabilize the Power Grid
The required EVCS demand depends on the target instability region, eigenvalue controllability, and attack location. Higher-severity target instabilities require more manipulated EVCS demand, while node B4 is the demonstrated destabilizing location.
- The attacker computes target eigenvalues across a discretized vulnerability region and minimizes the EVCS load needed to move eigenvalues into that region.Target locations are parameterized by ξ and ωn, with target eigenvalues ˆea = ˆa ± jˆb.
- Because rank(Mc) < card(x), the attacker can directly impact only some state variables and cannot always relocate eigenvalues precisely.The relocation error is measured as ε = ||˜ep−ˆea||2 for the two post-attack eigenvalues nearest the targets.
- As ξ and ωn increase, relocation accuracy improves toward ε →0, while the minimum EVCS load required for attack decreases.The relocation error is more sensitive to ˆωn than to ˆξ; scenarios with ε < 0.1 are used for load calculations.
- More EVCS demand must be manipulated for higher oscillations and negative damping in the time-domain response.The paper links greater instability severity with a larger amount of EVCS load needing compromise.
- Attacks from nodes B3, B5, and B6 do not destabilize the grid because their loads cannot move eigenvalues into the vulnerability region.The analysis assumes the attack is launched from node B4.
C. Sensitivity of the Data-driven Attack Model
The sensitivity analysis evaluates how inaccurate public grid data affects the data-driven attack. Greater parameter error generally increases the EVCS demand required for destabilization, and 100% error makes the attack infeasible.
- The attack model uses public-data-based power-grid parameters together with manually adjusted AGC parameters and EVCS demand.The AGC parameters are adjusted so the open-loop model is stable before attack design.
- With parameter errors other than +5% and −5%, the attack relocates eigenvalues to the same vulnerability-region location as the no-error case with ε ≤10%.The study introduces error uniformly across all power-grid parameters.
- Greater error in estimated grid parameters requires greater EVCS demand because eigenvalue relocation is nonlinear.At 100% parameter error, the demand-side cyberattack is not feasible.
- The Manhattan case study concludes that current PEV penetration does not appear sufficient to threaten grid stability, while higher future penetration creates an emerging vulnerability.The conclusion anticipates more simultaneous charging through additional high-wattage EVCSs and PEVs.
- The study identifies limited utility observability of high-wattage demand-side appliances and PEV privacy restrictions as detection and mitigation constraints.Developing methods that accommodate these constraints remains ongoing work.
- Future work includes extending the attack to other high-wattage appliances, improving public-data grid-model accuracy, and incorporating power-grid nonlinearities.Examples include air-conditioners, heat pumps, boilers, AC power flows, generator saturation, and inverter-based renewable resources.