Detection and mitigation of cyber attacks in microgrid secondary control systems
Abstract
Communication-assisted secondary control is essential for restoring the voltage and
frequency deviations that remain after primary control in renewable-integrated microgrids.
While primary control provides rapid local stabilization and power sharing, secondary
control coordinates distributed energy resources (DERs) to restore system-level voltage and
frequency toward their nominal values. However, its dependence on communication networks
exposes both the measurement-feedback and command-actuation pathways to false-data
injection (FDI) attacks. Compromised measurements can mislead supervisory control
decisions, while manipulated commands can drive DERs toward unsafe operating conditions.
Effective cybersecurity mechanisms must therefore detect compromised information and
prevent it from propagating through the closed-loop secondary-control system.
This thesis develops a lightweight, model-free, dual-pathway Koopman-based framework
that integrates real-time attack detection and mitigation into communication-assisted
secondary control.
The proposed framework deploys independent local Koopman predictors on the measurement
and command sides. Identified from attack-free operational data, these predictors
capture relationships between communicated signals and locally available cyber–physical
information without requiring an explicit analytical model of the complete microgrid. During
online operation, each received sample is compared with its locally predicted value.
The resulting prediction residual is processed through a recursive compensation mechanism
that estimates and removes the anomalous signal component on a sample-by-sample basis.
Consequently, measurements and control commands are continuously safeguarded before
being delivered to the supervisory controller or executed by the DERs. In parallel, consecutive
residual evaluations establish robust attack and recovery states. This confirmation
mechanism prevents brief threshold exceedances caused by measurement noise, prediction
uncertainty, or normal system transients from producing false attack-state transitions,
without delaying the sample-by-sample signal safeguarding process.
The proposed framework is evaluated on a protocol-aware Power Systems Computer
Aided Design (PSCAD)–Graphical Network Simulator-3 (GNS3) cyber–physical cosimulation
platform that captures the closed-loop interactions among electrical dynamics,
supervisory control, IEC 60870-5-104 communication, cyber-attack propagation, and
cybersecurity actions.
Simulation results demonstrate the potential of local Koopman-based cyber–physical
consistency validation and recursive signal mitigation as a modular cybersecurity framework
for communication-assisted microgrid secondary control.
Description
Thesis is embargoed until September 18 2027.
Keywords
Distributed generation of electric power, Power resources, Energy development, Microgrids (Smart power grids)
