AI Could Help Protect Grid From AI-Driven Attacks

A dashboard for an AI-enabled security operations center shows various metrics for monitoring and protecting the power grid from cyberattacks.
A dashboard for an AI-enabled security operations center shows various metrics for monitoring and protecting the power grid from cyberattacks. Image provided by Manimaran Govindarasu, electrical and computer engineering.

Quick look

Iowa State's Manimaran Govindarasu is an invited co-editor of a magazine special issue devoted to cybersecurity of the power grid. The special issue's theme: Use AI security tools against AI attack tools.

AMES, Iowa - The cover illustration shows a front-and-center, top-to-bottom rip.

On one side of the divide, an artificial intelligence agent creates dark chaos; the collage includes explosions, skulls and crossbones, warning signs over cities, solar panels and wind turbines. On the other, a lone defender at a control station watches over peaceful, remote power plants, substations, wind farms, a hydropower dam and towering transmission lines.

"On High Alert: Securing the Grid," announces bright text on the cover of the September/October issue of IEEE Power & Energy Magazine published by the Institute of Electrical and Electronics Engineers, the world's largest technical professional organization.

Invited to be co-editors of the magazine's special issue dedicated to cybersecurity of the grid are Iowa State University's Manimaran Govindarasu, an Anson Marston Distinguished Professor in Engineering and the Murray J. and Ruth M. Harpole Professor in Electrical and Computer Engineering; and the University of Idaho's Brian Johnson, the Schweitzer Engineering Laboratories Endowed Chair in Power Engineering and a Distinguished Professor.

The two worked on the special issue for nearly a year.

Their theme: Use AI security tools against AI attack tools.

"While the adversaries increasingly leverage AI for developing attacks, the system defenders have a huge responsibility and opportunity to adopt AI models, algorithms, and agentic frameworks for developing robust cyber defense solutions and countermeasures for the entire cybersecurity lifecycle - attack deterrence, attack prevention, anomaly detection, attack mitigation, system resilience, attack attribution, and forensics," Govindarasu and Johnson wrote in a guest editorial introducing the special issue.

"The key is we have to stay ahead," Govindarasu said. "We can use the power of AI for protection and security."

Of particular concern are AI attack tools finding "zero-day exploits," or digital vulnerabilities that were previously unknown and have yet to be patched. Attacking such vulnerabilities "could result in severe consequences to the grid's operational security and reliability," Govindarasu and Johnson wrote.

Security operations centers

The cover image of the IEEE Power & Energy magazine's special issue about grid cybersecurity.

Govindarasu has a long history of working to protect critical infrastructure from cyberattacks - especially Midwest grids that contain connections to solar and wind power systems. Each of those connections distributed across the grid can be a point of vulnerability for cyberattacks.

One such project is applying a zero-trust principle - never trust, always verify - to protect energy infrastructure. Another is creating a new, Iowa State-based cybersecurity center to study the protection of grids connected to renewable energy and local microgrids. Both are supported by grants from the U.S. Department of Energy's Office of Cybersecurity, Energy Security and Emergency Response.

As part of the special issue, Govindarasu and members of his research group contributed a research paper based on their studies. They call for development of AI-enabled security operations centers (known as SOCs) to help protect the grid.

"The increasing complexity of modern power systems and the evolution of cyber threats require a fundamental rethinking of how security operations are designed and integrated into grid operations," the researchers wrote. "This work articulates the emerging concept of a grid SOC that embeds cybersecurity directly within power system operations through integrated visibility, intelligence-driven analytics, and human-governed decision support."

Adam Hahn - a paper co-author, Iowa State graduate and current principal critical infrastructure security engineer for the MITRE Corp. - emphasized the need to move quickly to adopt new ideas.

"Critical infrastructure operators increasingly need to defend against sophisticated cyberthreats, and the rapid adoption of AI will be essential if defenders are to keep pace with these attacks."

Other papers featured in the special issue are from authors around the world:

  • "Building a cyber-resilient smart grid with artificial intelligence-driven defense"
  • "Cybersecurity of the control room of the future"
  • "Improving network-based security and resilience of the power grid"
  • "Guarding digital substations"
  • "Beyond the checklist: Modernizing cybersecurity regulation for the U.S. power grid"
  • "When the grid fights back"

The special issue's goal is to present these new ideas and potential best practices to researchers and leaders at universities, laboratories and industries around the world. The special issue can also help inform workforce training and development.

"We're not addressing these topics to scare people," Govindarasu said. "We're asking, 'How do we protect the grid?'"

/Public Release. This material from the originating organization/author(s) might be of the point-in-time nature, and edited for clarity, style and length. Mirage.News does not take institutional positions or sides, and all views, positions, and conclusions expressed herein are solely those of the author(s).View in full here.