Source-linked AI summary

Exposing the Invisible: Detecting Stealthy Parameter-Based Cyber-Attacks on Inverter Synchronization Loops

Zaint A. Alexakis, Michal M. Drewniak, Charalambos Konstantinou

arXiv:2608.30574v1eess.SY

TL;DR

The paper addresses stealthy PLL gain tampering in IoT-connected grid-supporting GFL converters, where unchanged steady-state behavior can conceal attacks. It models the threat and its stability and transient effects, then proposes an RSU-based PLL whose equilibrium shifts reveal gain changes. Experiments validate detection under normal, unbalanced, and distorted operating conditions.

  • Problem

    PLLs are vulnerable because they interact with multiple IBR control loops, while existing analyses and detectors do not fully characterize or detect general stealthy gain tampering.

  • Method

    The paper combines small- and large-signal threat analysis with an RSU-based PLL that monitors internal equilibrium points while preserving conventional PLL behavior.

  • Results

    The proposed scheme detects both proportional and integral PLL gain tampering through equilibrium-point shifts, with validation under normal, unbalanced, and distorted conditions.

  • Takeaways & Limitations

    Equilibrium-based monitoring exposes attacks that can remain invisible in conventional PLL states without compromising nominal GFL control performance.

Abstract

from arXiv · show

The increasing integration of Internet-of-Things (IoT) technologies for monitoring and control of inverter-based resources (IBRs) has expanded the attack surface, enabling stealthy manipulation of controller parameters through vulnerable supervisory control interfaces. Phase-locked loops (PLLs) emerge as prime targets, as they interact with all control loops and critically influence the dynamic response of grid-following (GFL) converters. This paper analyzes the underlying threat model to elucidate the mechanisms enabling such stealthy behavior and conducts a thorough stability and transient response analysis to characterize how PLL tampering can degrade system performance without necessarily destabilizing the system. The results reveal critical interactions among frequency estimation, control, and synchronization that can significantly reduce stability margins. To counter the stealthy nature of these attacks, a modified PLL is proposed that exposes gain variations through shifts in its equilibrium points while preserving conventional PLL performance. Experimental results validate the effectiveness of the proposed approach in detecting PLL cyber-attacks.

I. INTRODUCTION

The paper frames PLL gain tampering as a stealthy cyber threat to grid-supporting GFL converters and develops analyses and an equilibrium-based detection architecture to address it.

  • IoT-enabled supervisory interfaces expand attack surfaces in IBR infrastructure, while reduced inertia and damping increase operational challenges.
  • PLLs are especially consequential targets because they interact with multiple control loops and supply frequency estimates for grid-supporting GFL control.
  • Steady-state PLL tampering can leave systems apparently unaffected until later disturbances, making the attack mechanism difficult to detect.
  • Prior detection approaches are limited to integral-gain nullification, degrade conventional performance, or eliminate the PLL.
  • The proposed RSU-based PLL exposes proportional and integral gain changes through equilibrium-point shifts while preserving conventional PLL small-signal behavior.

B. Line, Load and Network Dynamics

The network model combines local converter frames with a common global rotating frame to represent line, load, and converter interactions for stability analysis.

  • Transmission lines are modeled as strictly resistive-inductive elements, while loads are represented through the same line-based formulation.
  • The global reference frame provides a common rotating coordinate system for interconnecting converter-local reference frames and represents grid frequency at steady state.
  • Local and global dq-frame states are related through phase-dependent rotation transformations.
  • At steady state, global-frame dq quantities remain constant when converter-local frames reach consensus on a common system frequency.

III. ANCILLARY SERVICES-ORIENTED IBR CONTROLLERS

The ancillary-services-oriented GFL controller uses frequency estimation, droop-like power control, deadbands, and rate limiting, making PLL dynamics central to frequency-support response.

  • Revised grid regulations require GFL converters to adjust power output according to system frequency through a droop-like characteristic.
  • The controller uses measured and nominal grid frequency, PCC voltage, droop gains, and a deadband function to determine ancillary-service behavior.
  • The deadband threshold is limited to 0.5 Hz by the cited ENTSO-E grid code, and zero disables the deadband.
  • A rate limiter constrains reference-power derivatives to satisfy physical plant restrictions and grid-code requirements.
  • Synchronization and frequency-estimation PLLs are structurally equivalent to a synchronization PLL augmented with additional estimation loops, enabling separate bandwidth and damping characterization.
  • Interactions among the frequency estimator, synchronization PLL, grid components, rate limiters, and deadband can degrade or destabilize network behavior when gains are manipulated.

IV. ATTACK MODEL FORMULATION

The attack model defines stealthiness by unchanged monitored equilibria after PLL gain manipulation, explaining why integral-action-preserving attacks can evade conventional monitoring.

  • Attackers may overwrite proportional and integral gains through compromised supervisory interfaces such as SCADAs and PLCs.
  • An attack is stealthy when operators or monitoring systems cannot distinguish post-attack states from expected steady-state values.
  • The equilibrium difference ηs compares monitored phase-error and internal-state equilibria before and after gain tampering.
  • When integral action is preserved, gain tampering leaves the equilibrium unchanged and produces no steady-state transient after an attack at equilibrium.
  • Nullifying the integral gain can create phase error and expose tampering through controller-state deviations and converter disconnection.
  • For the considered threat model, stealthiness is characterized exactly by ηs = 0, while detection requires ηs ≠ 0.

V. PLL IMPACT ON STABILITY AND TRANSIENT RESPONSE

The analysis explicitly examines how frequency-estimator dynamics affect both GFL-converter performance and small-signal behavior, alongside a simulation study of grid-supporting services.

  • V. PLL IMPACT ON STABILITY AND TRANSIENT RESPONSE: Frequency-estimator dynamics critically influence GFL-converter dynamic response and small-signal behavior.The study combines explicit small-signal stability analysis with simulation of frequency-estimator effects on grid-supporting services.

A. Small-Signal Analysis

The small-signal analysis shows that PLL and frequency-estimator tuning can either stabilize or destabilize coupled GFL–GFM systems, with grid strength and controller interactions determining the outcome.

  • A. Small-Signal Analysis: Poor PLL or network parameter combinations can make the coupled GFL–GFM system unstable.The simplified model identifies instability arising from the GFL converter and its outer-loop PLL, while an infinite-bus connection decouples the subsystems.
  • A. Small-Signal Analysis: Lower frequency-estimator bandwidth can destabilize weak-grid systems, while increasing it initially stabilizes them through frequency and voltage regulation.In the 2.9 SCR weak-grid case, further bandwidth increases eventually destabilize the system because inner controllers and the PLL cannot track ancillary-service outputs quickly enough.
  • A. Small-Signal Analysis: Reducing controller bandwidth broadens the stable range and achieves stability at a lower estimator bandwidth.Without the frequency-support mechanism, the system remains unstable in the reduced-bandwidth analysis.
  • A. Small-Signal Analysis: A dedicated 1 Hz synchronization PLL mitigates small-signal instability and low-frequency oscillatory modes, but excessive PLL bandwidth again causes instability.With an infinite bus replacing the GFM converter and the line removed, dominant eigenvalues coincide and stability holds for all tested PLL bandwidths.
  • A. Small-Signal Analysis: Improper frequency-support and estimator-gain tuning can degrade performance or induce instability, creating an avenue for stealthy compromise of IBR behavior.The analysis links this vulnerability to interactions among frequency support, estimator dynamics, and coupled converter controls.

B. Large-Signal Analysis

The large-signal study evaluates voltage-sag recovery after a load change across controller and frequency-estimator settings, revealing strong interactions that can improve or degrade response.

  • B. Large-Signal Analysis: Voltage-sag duration is evaluated after a +0.15 MW load change across deadbands, RL derivative limits, and frequency-estimator bandwidths.The disturbance occurs at bus 3, where the grid-supporting IBR is located.
  • B. Large-Signal Analysis: No deadband gives the shortest recovery times by allowing immediate controller response to the disturbance.Tight RL derivative constraints improve low-bandwidth responses by suppressing excessively aggressive control actions.
  • B. Large-Signal Analysis: With deadbands and RL limits combined, low estimator bandwidth degrades recovery, intermediate bandwidth improves it, and high bandwidth produces recovery-time saturation.At low bandwidths, the controller may not contribute to recovery or may operate counter-productively; restrictive RL action causes high-bandwidth saturation.
  • B. Large-Signal Analysis: In predominantly resistive networks with X/R = 0.6, recovery times range from 0.1 ms to 300 ms and depend critically on estimator dynamics.With RLs, lower bandwidths reduce recovery time, whereas increasing bandwidth gradually increases recovery time.
  • B. Large-Signal Analysis: Improper tuning of primary control, nonlinear protection, and frequency estimation can degrade disturbance response and counteract frequency-support services.The study emphasizes that deliberate controller-parameter manipulation can render the support mechanism counterproductive.

VI. RSU-BASED DETECTION OF PLL GAIN TAMPERING

The RSU-based PLL detects gain tampering by making PLL gain changes visible as shifts in internal equilibrium points, while preserving the conventional SRF PLL’s small-signal behavior and tracking performance.

  • Performance preservation: Properly tuned PLLs require significant proportional-gain, integral-gain, or combined alterations to meaningfully change plant small-signal behavior.Marginal gain changes may evade thresholding only when their equilibrium shifts and PLL-response effects are negligible.
  • Equilibrium-based detection: ωN is a private tunable feed-forward constant that does not affect the PLL’s small-signal dynamic response but strengthens detection and privacy.Without knowledge of ωN, an interceptor cannot fully reconstruct the PLL gains; increasing |ωg −ωN| enlarges equilibrium offsets and improves distinguishability.
  • Equilibrium-based detection: The RSU equilibrium vector captures PLL gain tampering because the equilibrium points depend on both proportional and integral gains.Changes in controller gains also induce transients in the IBR response, providing an additional anomalous-event signal.
  • Detection pipeline: Detection sensitivity depends on the observation window, dwell time, thresholds, filter response, PLL settling time, and tuning of ωN.Short dwell times detect earlier but can confuse transients with tampering; longer dwell times reduce false declarations at the cost of delayed detection.
  • Detection pipeline: The detector compares equilibrium vectors across an observation window and declares a gain-change event when threshold exceedance persists for the dwell time.Algorithm 1 filters the equilibrium vector, computes element-wise windowed differences, accumulates dwell time, and sets component flags after Td.
  • Performance preservation: The proposed PLL is small-signal equivalent to the conventional SRF PLL and can be integrated into existing GFL configurations without changing tracking performance.It has the same number of states as the SRF PLL and retains compatibility with QSG-based positive- and negative-sequence separation under unbalanced and distorted grids.

A. Extension of the Detection Scheme to Multi-Layer IBR Control

The detection concept extends beyond PLLs by modifying other IBR controllers so that gain changes produce unique, recoverable equilibrium-point mappings known only to the plant operator.

  • Extension of the Detection Scheme to Multi-Layer IBR Control: Other IBR controllers can be modified so each controller-gain change produces a unique effect on internal-state equilibrium points.The extension relies on the uniqueness of the power system’s equilibrium points.
  • Extension of the Detection Scheme to Multi-Layer IBR Control: A modified PI controller yields nonlinear equilibrium-point mappings that enable gain recovery from the solutions of g = 0.The plant operator alone can recover the gains because only the operator knows the controller structure and masking parameter a.

VII. EXPERIMENTAL RESULTS

CHIL experiments evaluate the proposed detection scheme under balanced and unbalanced, distorted grid conditions, testing equivalence, real-time applicability, and threat-model detection.

  • VII. EXPERIMENTAL RESULTS: The CHIL validation examines balanced and unbalanced, distorted grid scenarios under realistic operating conditions.Each scenario assesses small-signal equivalence between the RSU-based and conventional SRF PLLs.
  • VII. EXPERIMENTAL RESULTS: The experiments demonstrate the real-time applicability of the proposed PLL and its ability to detect the adopted threat model.

A. Operation and Attack Detection under Balanced Grid Conditions

Under balanced-grid conditions, the proposed PLL matches conventional SRF-PLL behavior while detecting integral, proportional-integral, and proportional gain tampering through shifted internal equilibrium points. Detection remains effective during disturbances and provides a bounded response delay.

  • Nominal operation: The proposed and conventional PLLs perform practically identically during reference-power and load-change contingencies.Active and reactive power responses and frequency estimation validate the theoretical analysis.
  • Balanced-grid attack detection: Integral-gain tampering shifts the internal phase-error and z equilibrium points, triggering both detection flags approximately 0.8 s after the attack.Active power and estimated frequency are perturbed but subsequently converge to the same equilibrium point.
  • Balanced-grid attack detection: The prior phase-estimation-error detector fails to detect integral-gain manipulation and remains unaware during more complex gain-tampering scenarios.The proposed detector instead identifies gain changes through equilibrium-point shifts.
  • Balanced-grid attack detection: Both proportional-integral and proportional gain modifications are detected through shifted z and phase-error equilibria, despite continued frequency tracking.Active power is significantly disturbed before converging to the original equilibrium.
  • Detection timing: Approximately 0.38 s is a conservative lower bound for detection delay when conditioning-filter and PLL settling occur in series.The dwell time can range from this floor to a few seconds; the experiment uses a higher value to cover plausible PLL configurations.
  • Distorted-grid validation: Under unbalanced and distorted voltage, the two PLL implementations remain practically identical while the system tracks frequency-support commands and recovers from voltage sag.Reactive power saturates at 14 kVar during the sag and returns to its pre-fault value after clearance.
  • Distorted-grid attack detection: During distorted-grid proportional-gain tampering, equilibrium-point dependence on grid frequency and gains prevents sag and harmonics from masking the attack.The proposed detector activates, whereas the prior detector remains unperturbed; the minimum delay is approximately 0.08 s.

VIII. CONCLUSION

The paper characterizes how compromised PLL gains can affect grid-supporting GFL IBRs and develops an RSU-based PLL that preserves SRF performance while detecting proportional and integral tampering. The analysis identifies control-layer interactions that can improve margins when well tuned but cause severe degradation or instability when poorly tuned.

  • VIII. CONCLUSION: An adversary who bypasses local defenses can manipulate PLL gains responsible for synchronizing and controlling grid-supporting GFL IBRs.Such manipulation can limit ancillary services and, in severe cases, destabilize the underlying IBR infrastructure.
  • VIII. CONCLUSION: The explicit cyber-physical analysis includes line and grid dynamics and reveals a roadmap for stealthily compromising IBR resources.The analysis accounts for the interconnected converter and control-system aspects of the threat.
  • VIII. CONCLUSION: The additional frequency-support loop improves stability margins and overall small-signal behavior, but poor tuning can cause severe control-layer interactions and instability.
  • VIII. CONCLUSION: The RSU-based PLL preserves SRF-PLL performance, has low computational complexity, and detects proportional and integral gain tampering through shifted internal equilibrium points.The proposed implementation is intended for application to existing GFL infrastructure.
Loading 2608.30574v1…