Protecting the grid with artificial intelligence (2025)

bryanrasmussen2 pts0 comments

Protecting the grid with artificial intelligence – LabNews

LabNews

Lab News

Topics

Past Articles

Sandia Lab News

Download This Issue (PDF)

Contact Us

Subscribe to the Lab News email

Subscribe to the LabNews email

New issues every two weeks. Unsubscribe at any time.<br>Email addresses are never shared.

Subscribe

Subscribe Successful<br>Thank you for subscribing!

Close

Sandia Lab News&ensp;|&ensp;https://www.sandia.gov/labnews/2025/09/04/protecting-the-grid-with-artificial-intelligence/

New neural network detects physical issues, cyberattacks

EYE ON THE GRID — Watch a three-minute video about Sandia’s neural-network AI and how it can detect physical problems, cyberattacks and both at the same time in the electric grid. (Video by Mark Means)

The electric grid powers everything from traffic lights to pharmacy fridges. However, it regularly faces threats from severe storms and advanced attackers.

Sandia researchers have developed brain-inspired AI algorithms that detect physical problems, cyberattacks and both at the same time within the grid. And this neural-network AI can run on inexpensive single-board computers or existing smart grid devices.

“As more disturbances occur, whether from extreme weather or from cyberattacks, the most important thing is that operators maintain the function and reliability of the grid,” said Shamina Hossain-McKenzie, a cybersecurity expert and leader of the project. “Our technology will allow the operators to detect any issues faster so that they can mitigate them faster with AI.”

The importance of cyber-physical protection

As the nation adds more smart controls and devices to the grid, it becomes more flexible and autonomous but also more vulnerable to cyberattacks and cyber-physical attacks. Cyber-physical attacks use communications networks or other cyber systems to disrupt or control a physical system such as the electric grid. Potentially vulnerable equipment includes smart inverters that turn the direct current produced by solar panels and wind turbines into the alternating current used by the grid, and network switches that provide secure communication for grid operators, said Adrian Chavez, a cybersecurity expert involved in the project.

DEPLOYING SECURITY — Sandia cybersecurity expert Adrian Chavez, left, and computer scientist Logan Blakely work to integrate a single-board computer with their neural-network AI into the Public Service Company of New Mexico’s test site. (Photo by Bret Latter)" class="wp-image-39428" data-description="" data-title="gridna" data-caption="DEPLOYING SECURITY — Sandia cybersecurity expert Adrian Chavez, left, and computer scientist Logan Blakely work to integrate a single-board computer with their neural-network AI into the Public Service Company of New Mexico’s test site. (Photo by Bret Latter)" srcset="https://www.sandia.gov/app/uploads/sites/81/2025/09/gridna.jpg 1000w, https://www.sandia.gov/app/uploads/sites/81/2025/09/gridna-300x200.jpg 300w, https://www.sandia.gov/app/uploads/sites/81/2025/09/gridna-768x512.jpg 768w, https://www.sandia.gov/app/uploads/sites/81/2025/09/gridna-640x427.jpg 640w, https://www.sandia.gov/app/uploads/sites/81/2025/09/gridna-165x110.jpg 165w, https://www.sandia.gov/app/uploads/sites/81/2025/09/gridna-407x271.jpg 407w" sizes="(max-width: 1000px) 100vw, 1000px" />DEPLOYING SECURITY  — Sandia cybersecurity expert Adrian Chavez, left, and computer scientist Logan Blakely work to integrate a single-board computer with their neural-network AI into the Public Service Company of New Mexico’s test site. (Photo by Bret Latter)

Because the neural network can run on single-board computers, or existing smart grid devices, it can protect older equipment as well as the latest equipment that lack only cyber-physical coordination, Shamina said.

“To make the technology more accessible and feasible to deploy, we wanted to make sure our solution was scalable, portable and cost-efficient,” Adrian said.

The package of code works at the local, enclave and global levels. At the local level, the code monitors for abnormalities at the specific device where it is installed. At the enclave level, devices in the same network share data and alerts to provide the operator with better information on whether the issue is localized or happening in multiple places, Shamina said. At the global level, only results and alerts are shared between systems owned by different operators. That way operators can get early alerts of cyberattacks or physical issues their neighbors are seeing but protect proprietary information.

The Sandia team collaborated with experts at Texas A&M University to create secure communication methods, particularly between grids owned by different companies, Shamina said.

Developing the neural network

The biggest challenge in detecting cyber-physical attacks is combining the constant stream of physical data with intermittent packets of cyber data, said Logan Blakely, a computer science expert who...

sandia grid physical network neural https

Related Articles