Engineering & Technologyarticle2026-08-21

Physics-Guided Data Fusion-Based Cyberattack Detection for Distributed Energy Resource Aggregators with Limited Observability

Open access0 citations

Abstract

False data injection attacks (FDIA) pose a growing threat to distributed energy resources (DER) aggregators because a compromised aggregator can expose and affect a number of enrolled DERs. However, DER aggregators only have access to limited measurements from DERs and the systems. This makes existing FDIA detection methods ineffective in this setting due to two main limitations: 1) they are grounded in full observability of a microgrid or distribution system, therefore are incompatible with the limited observability of a DER aggregator; 2) they can only either detect anomalies or explain why a deviation occurs, but not both of them simultaneously. To address these limitations, we propose a physics-guided fusion-based cyberattack detection method specifically designed for DER aggregators. This approach integrates two complementary modules: a forecasting-assisted residual method for rapidly anomaly detection, and a PV-aware sensitivity-based method to diagnose and explain their underlying physical causes. A gradient boosting machine (GBM) is then leveraged to fuse these output, optimizing the precision-recall tradeoff. The proposed method is tested on one microgrid test system across static and gradual attack scenarios with multiple levels of attack sophistication. Across the scenarios, the proposed method achieves a 93.34% accuracy, 0.88 F1-score, and 0.96 precision-recall area under the curve score (PR-AUC), demonstrating the method's effectiveness in securing DER aggregators with partial system visibility.

// Source

View paper (DOI)Open access versionOpenAlexElectricityPublished 2026-08-21

Authors: Celina Wilkerson, Qiuhua Huang, Burhan Hyder, Rohit Jinsiwale