Source-linked AI summary
Enhancing Cyber-Resiliency of DER-based SmartGrid: A Survey
Mengxiang Liu, Fei Teng, Zhenyong Zhang, Pudong Ge, Ruilong Deng, Mingyang Sun, Peng Cheng, Jiming Chen
TL;DR
DER digitization improves grid flexibility but exposes geographically dispersed resources to cyber threats, while fully secure networks are unlikely. This survey develops tailored threat modeling and risk assessment, reviews defense-in-depth strategies, and proposes a holistic CRE framework. It synthesizes five resiliency phases and emphasizes recovery alongside prevention, detection, and mitigation.
Problem
DER-based smart grids face hardware, software, communication, and personnel vulnerabilities, while existing surveys lack holistic cyber-resilience analysis and systematic threat modeling, risk assessment, or comprehensive defense-in-depth coverage.
Method
The survey presents hierarchical DER architecture, tailors integrated threat modeling and risk assessment, reviews prevention, detection, mitigation, and recovery strategies, and proposes a five-enabler CRE framework.
Results
The survey comprehensively synthesizes CRE developments and establishes a framework spanning threat modeling, risk assessment, defense-in-depth strategies, and five resiliency enablers.
Takeaways & Limitations
Cyber-resiliency planning for DER-based smart grids should consider identification, prevention, detection, mitigation, and recovery as an integrated process.
Abstract
from arXiv · showhide
The rapid development of information and communications technology has enabled the use of digital-controlled and software-driven distributed energy resources (DERs) to improve the flexibility and efficiency of power supply, and support grid operations. However, this evolution also exposes geographically-dispersed DERs to cyber threats, including hardware and software vulnerabilities, communication issues, and personnel errors, etc. Therefore, enhancing the cyber-resiliency of DER-based smart grid - the ability to survive successful cyber intrusions - is becoming increasingly vital and has garnered significant attention from both industry and academia. In this survey, we aim to provide a systematical and comprehensive review regarding the cyber-resiliency enhancement (CRE) of DER-based smart grid. Firstly, an integrated threat modeling method is tailored for the hierarchical DER-based smart grid with special emphasis on vulnerability identification and impact analysis. Then, the defense-in-depth strategies encompassing prevention, detection, mitigation, and recovery are comprehensively surveyed, systematically classified, and rigorously compared. A CRE framework is subsequently proposed to incorporate the five key resiliency enablers. Finally, challenges and future directions are discussed in details. The overall aim of this survey is to demonstrate the development trend of CRE methods and motivate further efforts to improve the cyber-resiliency of DER-based smart grid.
I. INTRODUCTION
DER-based smart grids improve power-system flexibility and efficiency but expand cyber exposure across dispersed devices, software, communications, and third-party access. The survey organizes cyber-resiliency around threat modeling, five resiliency phases, defense-in-depth technologies, and a holistic framework for surviving successful intrusions.
- Motivation: Digital-controlled DERs and advanced ICT improve power-supply flexibility and efficiency while introducing cyber threats to geographically dispersed resources.The transition includes inverter-based resources, smart inverters, 5G, EIoT, and SDN technologies.
- Motivation: Recent grid attacks and DER exposure can enable malicious control causing frequency or voltage instability, line overloading, and outages.The paper highlights limited operator awareness, weak physical security, and insufficient protection at numerous network access points.
- Motivation: Cyber-resiliency is the ability to survive successful cyber intrusions while limiting their impact, duration, and extent and maintaining critical electricity service.The paper frames resiliency as necessary because completely secure future power-grid networks are unlikely.
- Cyber-resiliency process: The DER-based smart-grid resiliency process has three stages—pre-event, during event, and post-event—and five phases: identification, prevention, detection, mitigation, and recovery.Identification and prevention address known attacks and prepare responses, while detection and mitigation respond after preventive defenses are bypassed.
- Survey contributions: The survey tailors integrated threat modeling and risk assessment to hierarchical DER systems, then reviews defense-in-depth technologies and proposes a framework incorporating five resiliency enablers.Its coverage includes prevention, detection, mitigation, and recovery, with short- and long-term resiliency assessment based on system dynamics and flexibility.
- Survey contributions: Cyber-recovery is identified as necessary for high-impact, low-probability attacks, while the proposed framework treats overall resiliency as limited by the worst-performing phase.The survey also presents the hierarchical architecture and discusses challenges and future directions.
II. RELATED SURVEYS
Existing surveys cover smart-grid cybersecurity and selected DER vulnerabilities, but a holistic cyber-resiliency analysis for DER-dominated smart grids remains lacking. This survey addresses gaps in threat modeling, defense-in-depth coverage, and recovery scheduling.
- Earlier smart-grid surveys review security requirements, vulnerabilities, prevention, defense countermeasures, and secure communication protocols.
- DER-focused surveys examine device, communication, converter-control, cyberphysical, and communication-protocol vulnerabilities.
- Existing DER-related surveys incompletely cover prevention technologies, intrusion detection systems, intrusion mitigation systems, and recovery scheduling.
- The paper provides threat modeling, risk assessment, and a systematic review of defense-in-depth strategies for DER-based smart-grid cyber-resiliency enhancement.
A. Hierarchical Framework of DER-based Smart Grid
The proposed DER-based smart-grid framework organizes geographically dispersed resources and stakeholders into four operational levels, while mapping their functions, protocols, and vulnerabilities. Its integrated threat model combines IT and OT perspectives to connect adversaries, vulnerabilities, attack techniques, and impacts.
- Hierarchical architecture: The hierarchical architecture has four levels: DER resources and management, utility and third-party operations, distribution utility analysis and operations, and transmission and market operations.
- Hierarchical architecture: Level 1 integrates renewable and non-renewable generation, storage, and management systems through standard, proprietary, and IoT communication protocols.
- Framework novelty: The framework specifies actors, functions, communication protocols, and emerging entities to clarify vulnerabilities and possible consequences across layers.
- Threat modeling: The threat model integrates IT and OT perspectives through adversary, vulnerability, and attack models.
- Vulnerability sources: Hardware, software, communication, and personnel are identified as vulnerability sources in this human-in-the-loop cyber-physical system.
- Communication vulnerabilities: Communication weaknesses include insufficient SunSpec Modbus security, IEEE 2030.5 scalability gaps, and inadequate availability protection in DNP3-SA and DNP3Sec.
3) Attack Model:
The attack model classifies techniques and links cyber vulnerabilities to security and privacy impacts across DER-based smart-grid operations. It emphasizes that coordinated and adversarially manipulated inputs can produce substantially larger operational and economic consequences than isolated compromises.
- Attack techniques: Attack techniques are organized into initial access acquisition, information discovery, and execution and implication phases.
- Machine-learning attacks: A 10% meteorological-input error makes PV forecasting mean absolute error three times larger, with average economic loss exceeding 700$/10min.
- Machine-learning attacks: Adversarial perturbations can reduce voltage and transient-stability assessment accuracy by more than 20% and enlarge AC state-estimation root-mean-square error tenfold.
- Coordinated attacks: Coordinated attacks can cause longer and more severe impacts than compromising a single point.
- Coordinated attacks: An EIoT botnet can increase total load demand by 30%, frequency instability by 1%, and generation cost by 5%, producing cascading failures.
- Attack impacts: Attack impacts span security and privacy, including frequency or voltage deviations, power-quality violations, equipment wear, load-generation imbalance, outages, and household-information leakage.
C. Risk Assessment Matrix
The risk assessment matrix combines attack implementation likelihood with attack consequences to classify threats against DER-based smart grids. Attack graphs and high-fidelity simulations support these assessments, which show that coordinated or skilled attacks can still produce meaningful impacts despite current limits on severe DER-only effects.
- Risk assessment framework: The risk matrix assesses each attack scenario using implementation likelihood and attack consequences.Likelihood is estimated from adversary knowledge, funding, time, and attack-graph requirements; consequences are evaluated by impact scale and severity.
- Attack implementation likelihood: Attack graphs model malicious firmware deployment through payload crafting, network access, lateral movement, firmware insertion, and shutdown triggering.The graph supports estimation of the skill and time required for different attack scenarios.
- Risk assessment findings: Almost-certain attacks are currently considered infeasible because no public scripts or tools can directly impact the power system.The assessment therefore distinguishes theoretical attack paths from currently demonstrated capability.
- Risk assessment findings: Skilled actors can cause insignificant or minor impacts, including privacy leakage and frequency or voltage deviations in isolated microgrids.The latter can occur when multiple primary or secondary controllers are compromised.
- Risk assessment findings: At current DER penetration, purely manipulating DER actions cannot produce moderate, major, or severe impacts, although this threat may become possible as deployment grows.Approximately 30% DER deployment relative to peak load is identified as a threshold for infrequent but potential grid-level consequences.
IV. DEFENSE-IN-DEPTH STRATEGIES: PREVENTION
Prevention strategies combine cyber controls from IT environments with physics-based protections in operational technology. The survey emphasizes layered architectures, access control, standardized communications, secure patching, and moving-target techniques, while noting tradeoffs with DER processing and latency constraints.
- Prevention strategy classification: Preventive technologies are divided into cyber-based controls and physics-based methods applied to DER smart-grid environments.Cyber controls operate across host, protocol, system, and network levels, whereas physics-based methods exploit control robustness or add OT protection devices.
- Network architecture: Network guidelines organize DER communications through criticality-based zones, security gateways, boundary protection, and partitioned communications.Resources are assigned high, medium, or low impact levels, with different headends and controlled paths for separate critical groups.
- Access control: Role-based access control restricts DER data and control functions according to organizational roles and responsibilities.The surveyed implementation requires detailed hardware and software information and includes user authentication mechanisms such as Kerberos and digital signatures.
- Secure communications: Standardized communication security includes TLS v1.3 bulk-traffic protection, mutual X.509v3 authentication, and coordinated key management.These measures are intended to secure information flows across public or private DER networks while supporting interoperability standards.
- Secure communications: DER processing limitations can make encryption, authentication, and hashing costly for communication-based control, although reported latency increases are on the order of milliseconds.Less-online/more-offline signatures are proposed to reduce expensive online verification operations.
- Software and adaptive defenses: Code signing verifies firmware source identity and integrity, while moving target defense dynamically changes the attack surface to increase adversarial uncertainty and cost.Moving-target implementations can randomize application ports, IP addresses, and communication paths in industrial-control networks.
B. Physical Prevention Methods
Physical prevention methods limit the operational consequences of cyberattacks by exploiting controller robustness, protecting strategically selected meters, incorporating cyber risk into dispatch, and deploying virtual DER decoys. Their use should be matched to vulnerability, security demand, and cost constraints.
- Robust control: Robust control treats bounded injected biases as unknown uncertainties and designs controllers that keep tracking error bounded under attack.The approach typically adds computation burden without requiring other investments.
- Meter protection: Meter protection bounds attack impact by strategically protecting selected smart meters under a constrained defense budget.The surveyed work addresses both which meters to protect and how much budget to allocate to each.
- Operating-point dispatch: Operating-point dispatch incorporates cyberattack risk into security-constrained optimal power flow and develops robust strategies against stealthy data attacks.The methods target significant bias injections and dummy-data attack construction.
- Virtual DER devices: Virtual DER devices redirect adversary attention away from critical assets and generate alerts when attackers interact with artificial equipment.They provide deception-based protection and detection functions for studying adversary tactics and DER vulnerabilities.
- Lessons learned: No combination of cyber and physical prevention methods guarantees 100% security, and stronger physical prevention can degrade control performance.The survey recommends cost-benefit analysis and scenario-specific deployment rather than maximizing prevention indiscriminately.
V. DEFENSE-IN-DEPTH STRATEGIES: INTRUSION DETECTION SYSTEM
Intrusion detection systems identify malicious activity by monitoring behavioral features from hosts, network devices, and physical-side sensors. The survey classifies IDSs according to the origin of their monitored data.
- IDS classification: An IDS detects malicious activities by monitoring and analyzing behavioral features from hosts, network devices, or physical-side sensors.This data-origin view provides the basis for the classification presented in the survey.
- Host-based detection: Host-based intrusion detection examines host features such as system files, system calls, processes, memory utilization, and firmware version.HIDS focuses on the integrity and behavior of the host itself.
A. Host-based IDS
Host-based intrusion detection systems are deployed on critical hosts, workstations, servers, and IEDs, with research concentrated on upper hosts and smart meters. Renewable-energy converters remain under-addressed because their limited resources make comparable performance difficult.
- Deployment and focus: HIDSs are typically deployed on critical hosts, servers, workstations, and IEDs to detect cyber intrusions.Signature-based tools such as Fail2Ban, DenyHosts, AIDE, Tripwire, OSSEC, and Samhain can be installed on upper hosts.
- Deployment and focus: Current HIDS research mainly focuses on upper hosts and smart meters.
- Limitations: Energy conversion devices interfacing renewable sources with the grid have received insufficient attention.
- Limitations: Strictly limited resources on energy conversion devices make comparable HIDS performance challenging.
- Deployment and focus: NIDS deployment may require additional communication components, making deployment cost important across geographically dispersed terminal devices.
C. Physics-based IDS
Physics-based IDSs detect attacks by modeling physical dynamics, using data-driven, model-based, or blended approaches and sometimes proactive perturbations. They provide a final detection layer, but each approach has distinct data, computation, explainability, and robustness trade-offs.
- Detection approaches: PIDSs use physical measurements, specifications, or extracted features to capture normal behavior near field devices.
- Limitations: Adversarial perturbations can substantially degrade detection accuracy, with targeted attacks achieving success rates as high as 80% at small attack scales.
- Layered detection: HIDSs and NIDSs generally detect host or network traces faster, while PIDSs provide a last detection layer through physical impacts.
- Detection approaches: Data-driven PIDSs can detect diverse attacks without model knowledge, but depend on training-data diversity and incur computation and explainability costs.
- Detection approaches: Model-based PIDSs offer timely, reliable, and explainable detection with acceptable computation burden, but degrade when system parameters vary.
- Detection approaches: Data-and-physics-blended PIDSs are increasingly used because DER grids provide extensive measurement data and known physical dynamics.
A. Cyber-based Detection-triggered IMS
Cyber-based detection-triggered mitigation excludes malicious network components through actions such as packet dropping, traffic blocking, or channel switching. Its suitability depends on the control setting, because aggressive data removal can threaten closed-loop stability.
- Cyber-based mitigation: Cyber-based IMSs use packet dropping, traffic blocking, or channel switching to restrict attack propagation.
- Cyber-based mitigation: When a DER faces a DoS attack, protective mode can permit only outgoing traffic, and broader protective activation can cover all DER units.
- Trade-offs: Cyber-based strategies suit pure IT systems but can be too aggressive for closed-loop control, where data loss may cause severe stability issues.
- Physics-based mitigation: Detection-triggered IMSs include compensation-, isolation-, scenario-, adaptability-, and schedule-based strategies.
- Physics-based mitigation: Compensation-based strategies address both FDI and DoS attacks, whereas isolation-based strategies address FDI attacks and depend on attack count.
- Physics-based mitigation: Schedule-based IMSs can mitigate FDI and DoS attacks by using additional flexible resources.
- Evaluation limitations: Comparative evaluation remains difficult because the literature lacks benchmark testbeds and datasets, constrained by cost and sensitive real-world data.
VII. DEFENSE-IN-DEPTH STRATEGIES: RECOVERY
Cyber-recovery restores both electricity service and compromised communication infrastructure after mitigation. Its schedule must account for cyber-physical coupling, prioritize timely power restoration, and then address longer-term infrastructure repair and malware removal.
- Recovery scope: Recovery scheduling restores degraded system states after mitigation, including isolated areas, malicious payloads, and damaged electrical devices.
- Recovery scheduling: The recovery schedule prepares personnel and communication, learns attack and mitigation conditions, then determines the recovery order.
- Recovery scheduling: Power-supply restoration has first priority and should be completed within hours using cyber reconnection and physical emergency-generation actions.
- Recovery scheduling: Full infrastructure restoration takes days or weeks and includes repairing or replacing compromised software and hardware.
- Recovery scope: Cyber-recovery differs from physical recovery by combining grid energization, communication-network reestablishment, and cyber-malware removal.
- Challenges: Cyber-recovery scheduling is complicated by cyber-side modeling and strong cyber-physical coupling.
- Defense compatibility: Defense-in-depth mechanisms are mostly neutral but can be dependent or conflicting, particularly when encryption burden degrades later defenses.
VIII. CHALLENGES AND FUTURE DIRECTIONS
The paper discusses challenges and future directions across the cyber-resiliency enhancement process, spanning identification, prevention, detection, mitigation, and recovery.
- Challenges and future directions are organized across the cyber-resiliency enhancement process.The section covers identification, prevention, detection, mitigation, and recovery.
- Threat identification is one of the phases considered in the discussion.
- Recovery is included alongside prevention, detection, and mitigation as a future-direction area.
A. Threat Identification
The survey identifies gaps in integrated threat modeling, resource-aware intrusion detection, and cyber-physical prevention for DER-based smart grids. Future work emphasizes automation, cross-domain fusion, and coordination under constrained resources.
- Threat identification: Integrated and automated frameworks are still needed to identify vulnerability-exploitation paths that create critical hazards under specific configurations.Such modeling requires combined IT and OT expertise and must represent heterogeneous DER devices and complicated couplings.
- Threat identification: Current adversarial-attack studies emphasize model-oriented attacks, while privacy- and platform-oriented attacks receive limited attention.Membership inference can expose economic conditions and user preferences when sensitive data support machine-learning training.
- Prevention: Prevention research should improve grid-edge blockchain, moving-target defense, virtualized DER, and cyber-physical integrated technologies.Key concerns include blockchain energy and response costs, adaptive MTD triggering, realistic physical emulation, and cyber-physical interaction modeling.
- Intrusion detection: Intrusion detection should move from add-on, single-domain systems toward embedded, multi-domain, and coordinated designs.Challenges include restricted inverter computation and memory, feature-fusion design, local-centralized coordination, physical interpretability, and adversarial robustness.
D. Impact Mitigation System
The survey presents impact mitigation as a coordinated process combining data and model-based reconstruction, adaptive decision-making, and grid-edge and SCADA responses. It also identifies unresolved challenges in cost, coordination, uncertainty, and cyber-physical recovery.
- Impact mitigation system: Impact mitigation systems still require improved cost-efficiency, cross-level coordination, and adaptability.
- Impact mitigation system: Data and model blending can improve bad-data recovery while reducing the need for extra hardware.Statistical and spatio-temporal correlations predict intervals, while semantic models estimate values within them.
- Impact mitigation system: Deep reinforcement learning is proposed for mitigation decisions under cyberattacks with uncertain and changing types, durations, and intensities.This requires high-fidelity DER environments that support real-time interaction.
- Impact mitigation system: Grid-edge methods provide timely seconds-to-minutes responses, while SCADA safe-mode operations provide minutes-to-hours responses when edge controllability is insufficient.The coordinated framework isolates and replaces bad data, then schedules flexible DER resources and reconfigures communications when needed.
- Impact mitigation system: Recovery research must address cyber-physical interdependence, uncertainty, and decentralized coordination after high-impact cyberattacks.Proposed directions include cyber-physical repair sequencing, data-driven recovery under uncertainty, and multi-agent learning across DERs or DER clusters.
- Impact mitigation system: The survey finds that existing CRE research often prioritizes security performance and local single-domain resources over security cost and cross-domain coordination.