Detection and mitigation of cyber attacks in microgrid secondary control systems

dc.contributor.advisorAmeli, Amir
dc.contributor.authorZhang, Rubin
dc.contributor.committeememberNasir Uddin, Mohammad
dc.contributor.committeememberWei, Qiang
dc.date.accessioned2026-09-17T12:00:19Z
dc.date.created2026
dc.date.issued2026
dc.descriptionThesis is embargoed until September 18 2027.
dc.description.abstractCommunication-assisted secondary control is essential for restoring the voltage and frequency deviations that remain after primary control in renewable-integrated microgrids. While primary control provides rapid local stabilization and power sharing, secondary control coordinates distributed energy resources (DERs) to restore system-level voltage and frequency toward their nominal values. However, its dependence on communication networks exposes both the measurement-feedback and command-actuation pathways to false-data injection (FDI) attacks. Compromised measurements can mislead supervisory control decisions, while manipulated commands can drive DERs toward unsafe operating conditions. Effective cybersecurity mechanisms must therefore detect compromised information and prevent it from propagating through the closed-loop secondary-control system. This thesis develops a lightweight, model-free, dual-pathway Koopman-based framework that integrates real-time attack detection and mitigation into communication-assisted secondary control. The proposed framework deploys independent local Koopman predictors on the measurement and command sides. Identified from attack-free operational data, these predictors capture relationships between communicated signals and locally available cyber–physical information without requiring an explicit analytical model of the complete microgrid. During online operation, each received sample is compared with its locally predicted value. The resulting prediction residual is processed through a recursive compensation mechanism that estimates and removes the anomalous signal component on a sample-by-sample basis. Consequently, measurements and control commands are continuously safeguarded before being delivered to the supervisory controller or executed by the DERs. In parallel, consecutive residual evaluations establish robust attack and recovery states. This confirmation mechanism prevents brief threshold exceedances caused by measurement noise, prediction uncertainty, or normal system transients from producing false attack-state transitions, without delaying the sample-by-sample signal safeguarding process. The proposed framework is evaluated on a protocol-aware Power Systems Computer Aided Design (PSCAD)–Graphical Network Simulator-3 (GNS3) cyber–physical cosimulation platform that captures the closed-loop interactions among electrical dynamics, supervisory control, IEC 60870-5-104 communication, cyber-attack propagation, and cybersecurity actions. Simulation results demonstrate the potential of local Koopman-based cyber–physical consistency validation and recursive signal mitigation as a modular cybersecurity framework for communication-assisted microgrid secondary control.
dc.identifier.urihttps://knowledgecommons.lakeheadu.ca/handle/2453/5650
dc.language.isoen
dc.subjectDistributed generation of electric power
dc.subjectPower resources
dc.subjectEnergy development
dc.subjectMicrogrids (Smart power grids)
dc.titleDetection and mitigation of cyber attacks in microgrid secondary control systems
dc.typeThesis
etd.degree.disciplineEngineering : Electrical & Computer
etd.degree.grantorLakehead University
etd.degree.levelMaster
etd.degree.nameMaster of Science in Electrical and Computer Engineering

Files

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
2.23 KB
Format:
Item-specific license agreed upon to submission
Description: