Electric power system security: the case for an integrated cyber-physical risk management framework
Efthymios Karangelos, Louis Wehenkel

TL;DR
This paper proposes an integrated cyber-physical risk management framework for electric power systems, emphasizing the importance of jointly optimizing physical and cyber-security measures to enhance grid resilience against sophisticated attackers.
Contribution
It introduces a tri-level decision model that co-optimizes preventive physical and cyber-security strategies considering attacker uncertainty, highlighting their complementary roles in grid security.
Findings
Physical and cyber-security measures are non-exchangeable and complementary.
Joint optimization improves overall grid security.
Uncertainty management is crucial in decision-making.
Abstract
This paper concerns the security of the electric power transmission grid facing the threat of malicious cyber-physical attackers. We posit that there is no such thing as perfectly effective cyber-security. Rather, any cyber-security measure comes with the possibility that a highly skilled attacker could (eventually find a way to) bypass it. On these grounds, we formulate a tri-level decision making problem seeking to co-optimize preventive physical and cyber-security measures under uncertainty on the ability of an exogenous cyber-physical attacker to overcome the latter. Preventive physical security measures refer to the \emph{ex-ante} procurement of reserve capacity, which translates into ramping restrictions in real-time. Cyber-security measures refer to updating the firewall rules so as to impede an intruder from taking over the cyber infrastructure of the grid and disconnecting…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSmart Grid Security and Resilience · Information and Cyber Security · Infrastructure Resilience and Vulnerability Analysis
MethodsADaptive gradient method with the OPTimal convergence rate · Focus
