Mohsen Ghafouri

dblp:254/6117 · DBLP profile ↗
← Back
9ranked-venue papers
1as first author
9since 2021 · last 2025
0000-0003-2184-5734ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Applied, interdisciplinary, general and emerging computing · 6 · 1 first-author · 6 since 2021Systems, architecture and hardware · 2 · 2 since 2021Security and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Electric Vehicle Switching Attacks Against Subsynchronous Stability of Power Systems
abstract
The deployment of electric vehicles (EVs) requires the integration of information and communication technologies, making power grids prone to cyber threats from EV cyber-infrastructure. On this basis, this paper studies the impact of a new family of EV-based load-altering attacks (EV-LAA) against the subsynchronous stability of the power grid. First, the cyber-physical connections between the EV ecosystem and the power grid are discussed to represent a threat model for coordinated electric vehicle switching attacks (EVSAs) that can excite torsional modes of the system. Then, it will be demonstrated that a traditional proportional-integral (PI)-based subsynchronous resonance damping controller (SSRDC) cannot stabilize the power grid. With the help of a customized unknown input observer (UIO), an adaptive control framework is developed based on a model predictive control (MPC). This framework can generate online control signals and add them to the internal control framework of the synchronous generators (SGs). A modified IEEE Second Benchmark (M-IEEE-SBM) is used to demonstrate the EV-LAAs' consequences and evaluate the effectiveness of the developed adaptive technique. The proposed strategy is also studied through real-time simulations under a testbed that integrates a virtual sphere (vSphere) for an EV ecosystem with power grids simulated in a real-time simulator (i.e., OPAL-RT 5650). To demonstrate the feasibility of this switching attack vector in an actual power system and its impact on SSR stability, the Palo Verde Nuclear Generating Station (PVNGS) is also simulated in this real-time simulator, and the effectiveness of the proposed adaptive control framework is validated under the EV-LAAs.
Ahmadreza Abazari, Khaled Sarieddine, Mohsen Ghafouri, Danial Jafarigiv, Ribal Atallah, Chadi Assi
IEEE Trans. Ind. Informatics3
2025 Measuring the Security Posture of IEC 61850 Smart Grid Substations Against Supply Chain Attacks
abstract
Recently, there has been a surge of interest in analyzing and modeling emerging cyberattacks resulting from supply chain vulnerabilities in smart grids. These vulnerabilities are deliberately injected into devices before shipment by a malicious or trustworthy but compromised vendor during supply chain attacks. As a result, those vulnerabilities possess unique characteristics, such as stealthiness. Such characteristics, together with the limited number of vendors, demand new techniques for measuring the security posture of smart grids in the presence of those vulnerabilities. On this basis, this article first defines a supply chain risk metric to measure the risks of different devices containing those vulnerabilities based on several risk factors. Afterward, we enhance the previously defined$kSupply$metric and propose a new metric, namely$kSupplier$to include vendors in the risk assessment. Finally, we evaluate the proposed metrics and models through simulations conducted on IEEE 14 and 39-bus systems.
Onur Duman, Mohsen Ghafouri, Lingyu Wang 0001, Marthe Kassouf, Ribal Atallah, Mourad Debbabi
IEEE Trans. Ind. Informatics2
2024 Mitigating False Data Injection Attacks in DC Microgrids with Multiple Interlinking Converters
abstract
The coordination among Multiple Interlinking Converters (MICs) is facilitated through a low-bandwidth, neighborhood communication-assisted, distributed cooperative control strategy. However, these systems are vulnerable to False Data Injection Attacks (FDIAs), which create significant challenges by maliciously falsifying communication signals, disrupting the coordination of MICs, and potentially rendering the entire microgrid inoperable. To address this threat, this paper proposes a signal estimation stategy based on the Adaptive Neuro-Fuzzy Inference System (ANFIS) to mitigate FDIAs in MICs within clustered DC microgrids. During the offline training phase, the ANFIS-based estimator is developed using the local voltage measurements from each bidirectional interlinking converter as inputs and the sum of communicated signals entering each converter as the output. For the online stage, a reference tracking approach is developed to restore the attacked signals using the estimated values from ANFIS, effectively mitigating the impact of FDIA. Through extensive simulations, we demonstrate the effectiveness of our proposed approach in handling various FDIAs, including time-varying attack signals and unbounded attacks.
Ramin Babazadeh-Dizaji, Mohsen Ghafouri
IECON2
2024 A Real-time Monitoring Architecture for Enhanced Cybersecurity in the EV Ecosystem
abstract
Electric Vehicles (EV) have experienced a tremendous rise in popularity as they offer a sustainable alternative to conventional vehicles. However, the EV ecosystem is a complex system consisting of many interconnected components such as the EV Charging Station (CS) and the EV Charging Station Management System (CSMS). Given its connection to the smart grid and its direct impact on the transportation sector, securing the EV ecosystem is essential and requires the design of novel monitoring solutions. Previous studies proposed single-component detection mechanisms that cannot detect all potential anomalies across the system. Our work addresses this issue through the combination and correlation of monitoring data collected from the different EV ecosystem components. Our objective is to develop a real-time monitoring platform for attack detection in the public EV charging ecosystem that is based on the extension of the IEC 62351-7:2017 Network and System Management (NSM) standard. By adopting an international security standard, we ensure the monitoring platform is compatible with international power systems. To validate the utility of the approach, we integrate the monitoring framework with a real-time EV charging cosimulation testbed and discuss how it can be used to detect EV-based cyberattacks.
Rinith Reghunath, M. A. Sayed, Khaled Sarieddine, Ribal Atallah, Danial Jafarigiv, Marthe Kassouf, Chadi Assi, Mohsen Ghafouri
IECON8
2024 Mitigating Propagation of Cyber-Attacks in Wide-Area Measurement Systems
abstract
Wide Area Measurement Systems (WAMSs) are used in power networks to improve the situational awareness of the operator, as well as to facilitate real-time control and protection decisions. In WAMSs, Phasor Data Concentrators (PDCs) collect time-synchronized data of Phasor Measurement Units (PMUs) through the communication system, and direct it to the control center to be used in wide-area control and protection applications. Due to the dependence of WAMSs on information and communication technologies, cyber-attacks can target these systems and propagate through them, i.e., infect a greater number of components by accessing and controlling a few of them. On this basis, this paper initially develops a Learning-Based Framework (LBF) to estimate the required defense strategy to counter the propagation of cyber-attacks in WAMSs. Afterwards, through solving a linear Binary Integer Programming (BIP) problem, this paper develops a mitigation strategy to optimally reconfigure the communication network and reduce the contamination probability for critical PMUs and PDCs while maintaining the observability of the grid. The simulation results obtained from IEEE 14- and 30-bus test systems corroborate the effectiveness of the proposed LBF and communication network reconfiguration strategy in mitigating the propagation of cyber-attacks in WAMSs.
Hamed Sarjan, Mohammadmahdi Asghari, Amir Ameli, Mohsen Ghafouri
IEEE Trans. Inf. Forensics Secur.4
2024 Spatial-Temporal Data-Driven Model for Load Altering Attack Detection in Smart Power Distribution Networks
abstract
The widespread deployment of information and communication technologies in smart power distribution networks (SPDNs) exposes them to cyber threats. Among different types of cyber-attacks in such ICT-based SPDNs, load-altering attacks (LAAs) against high-wattage devices have received significant attention in recent years. In this context, this article proposes a data-driven detection model tailored for identifying and localizing LAAs in SPDNs. In this pursuit, first, the graph structure of an SPDN, which is obtained from the grid topology, and node features, i.e., measurements of the load's power, are fed to a graph attention network (GAT), and the spatial correlations among the nodes are captured. Alongside, the temporal correlations are captured using a long short-term memory model trained based on the graph representation obtained from the GAT. These spatial and temporal correlations are used by prediction and reconstruction models, i.e., a fully connected neural network and an auto-encoder. Finally, based on the error of the prediction and reconstruction blocks, an attack score for each load is calculated, and the compromised loads are detected and localized. To evaluate the performance of the proposed model, a co-simulation framework, which simulates the power system and emulates the communication network using real industrial protocols, i.e., IEC 60870-5-104, has been developed. The robustness of the model's performance against noisy data and non-attack outliers is confirmed with respect to different noise levels and data outliers. Also, the developed model's superior performance over existing models is demonstrated through various LAA scenarios applied to the IEEE 33- and the 123-Bus benchmarks.
Afshin Ebtia, Dhiaa Elhak Rebbah, Mourad Debbabi, Marthe Kassouf, Mohsen Ghafouri, Arash Mohammadi 0001, Andrei Soeanu
IEEE Trans. Ind. Informatics5
2024 Resilient Event-Triggered Observer-Based Periodic Wide-Area Control for Oscillation Damping in WAMPAC Systems Under Time Synchronization Attacks
abstract
In this article, we address the problem of delay-causing time synchronization (DC-TS) attacks against wide-area damping controllers (WADCs). To enhance smart grid stability against such threats, we present a realistic and secure design procedure for WADCs. To this end, we follow a methodology that utilizes the state-space model of the entire grid to design a periodic observer-based event-triggered controller by formulating the problem as a set of linear matrix inequalities, solved by the looped-Lyapunov functional (LLF) technique. The event-triggered scheme applied in this design procedure improves communication efficiency. Plus, the periodic sampled-data approach makes the design better suited to the operational reality of digital systems and their constraints. As such, the contributions of this work include developing an event-triggered mechanism to reduce unnecessary data transmissions, applying LLF for less conservative stability analysis, and utilizing the Guardian map theorem and Rekasius substitution to assess the WADCs resilience under DC-TS attacks. We conducted extensive simulations on the Kundur two-area and New England 39-bus systems to validate our approach. These simulations, along with comparisons to existing methods and tests on the RT-Lab real-time platform, demonstrate the superior performance of our WADC in maintaining grid stability and improving damping under considered attacks.
Saghar Vahidi, Mohsen Ghafouri, Minh Au, Arash Mohammadi 0001, Mourad Debbabi
IEEE Trans. Ind. Informatics3
2022 Coordinated Charging and Discharging of Electric Vehicles: A New Class of Switching Attacks
abstract
In this work, we investigate that the abundance of Electric Vehicles (EVs) can be exploited to target the stability of the power grid. Through a cyber attack that compromises a lot of available EVs and their charging infrastructure, we present a realistic coordinated switching attack that initiates inter-area oscillations between different areas of the power grid. The threat model as well as linearized state-space representation of the grid are formulated to illustrate possible consequences of the attack. Two variations of switching attack are considered, namely, switching of EV charging and discharging power into the grid. Moreover, two possible attack strategies are also considered (i) using an insider to reveal the accurate system parameters and (ii) using reconnaissance activities in the absence of the grid parameters. In the former strategy, the system equations are used to compute the required knowledge to launch the attack. However, a stealthy system identification technique, which is tailored based on Eigenvalue Realization Algorithm (ERA), is proposed in latter strategy to calculate the required data for attack execution. The two-area Kundur, 39-Bus New England, and the Australian 5-area power grids are used to demonstrate the attack strategies and their consequences. The collected results demonstrate that by manipulation of EV charging stations and launching a coordinated switching attack to those portions of load, inter-area oscillations can be initiated. Finally, to protect the grid from this anticipated attack, a Support Vector Machine (SVM) based framework is proposed to detect and eliminate this attack even before being executed.
Mohsen Ghafouri, Mohammad Ekramul Kabir, Bassam Moussa, Chadi Assi
ACM Trans. Cyber Phys. Syst.1
2022 Security Monitoring of IEC 61850 Substations Using IEC 62351-7 Network and System Management
abstract
According to the IEC 62351-7 standard, data collection using network and system management (NSM) can be used to support the security monitoring of the smart grid. In this article, an NSM security monitoring platform for a realistic IEC 61850 substation model is developed using the specifications provided in IEC 62351-7. In the developed model, grid measurements are ready to take operative decisions, whereas collected NSM data are leveraged to detect cyberattacks and/or identify anomalies. The model includes power components (e.g., transformers, lines, and generators), controllers (e.g., voltage control), protection devices (e.g., overcurrent, distance, differential, and under/overvoltage), communication protocols (e.g., sampled value and generic object-oriented substation event), and NSM (e.g., agents and managers) applications. Moreover, a two-step deep learning framework is proposed for anomaly detection and cyberattack identification with enhanced accuracy. The first step can apply long short-term memory, recurrent neural network, and gated recurrent units, each in combination with an autoencoder. Then, the ensemble learning technique is used in the second step to augment the outputs of these deep learning models. To evaluate the effectiveness of the proposed cyberattack and anomaly detection framework, we detail and simulate potential cyberattacks targeting the performance of the IEEE 9-bus system. The proposed anomaly detection scheme can identify these threats using NSM data in a hardware-in-the-loop testbed. Finally, based on our assessment results, recommendations are provided for cybersecurity guidelines concerning IEC 62351-7.
Abdullah Albarakati, Chantale Robillard, Mark Karanfil, Marthe Kassouf, Mourad Debbabi, Amr M. Youssef, Mohsen Ghafouri, Rachid Hadjidj
IEEE Trans. Ind. Informatics7