AI-Driven Cybersecurity Testbed for Nuclear Infrastructure: Comprehensive Evaluation Using METL Operational Data
Benjamin Blakely, Yeni Li, Akshay Dave, Derek Kultgen, and Rick Vilim

TL;DR
This paper evaluates AI-based cybersecurity detection methods on nuclear reactor control systems using realistic operational data, establishing benchmarks and reference architectures to enhance security in critical cyber-physical infrastructure.
Contribution
It introduces a systematic evaluation framework for AI cybersecurity methods applied to nuclear infrastructure, including comprehensive attack scenarios and performance benchmarks.
Findings
Change Point Detection achieved highest mean AUC of 0.785
Multi-site coordinated attacks were most detectable
Detection of trust decay attacks remains challenging
Abstract
Advanced nuclear reactor systems face increasing cybersecurity threats as sophisticated attackers exploit cyber-physical interfaces to manipulate control systems while evading traditional IT security measures. This research presents a comprehensive evaluation of artificial intelligence approaches for cybersecurity protection in nuclear infrastructure, using Argonne National Laboratory's Mechanisms Engineering Test Loop (METL) as an experimental platform. We developed a systematic evaluation framework encompassing four machine learning detection paradigms: Change Point Detection, LSTM-based Anomaly Detection, Dependency Violation analysis, and Autoencoder reconstruction methods. Our comprehensive attack taxonomy includes 15 distinct scenarios targeting reactor control systems, each implemented across five severity tiers to evaluate detection performance under varying attack intensities.…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSmart Grid Security and Resilience · Network Security and Intrusion Detection · Infrastructure Resilience and Vulnerability Analysis
