Integrated Cyber-Physical Resiliency for Power Grids under IoT-Enabled Dynamic Botnet Attacks
Yuhan Zhao, Juntao Chen, Quanyan Zhu
TL;DR
This work addresses the vulnerability of power grids to IoT-enabled botnet attacks by coupling a mean-field SIS epidemic model for cyber risk with cross-layer game-theoretic defenses and a dynamic physical controller. The authors present a tractable epidemic framework to quantify cyber risk $\bar{I}$, analyze cyber defense NE and its dependence on attacker and defender efforts ($\gamma(u_d),\zeta(u_a)$), and design a dynamic min-max control at the physical layer to counteract attacks. The approach is validated on the IEEE-39 bus system, showing that cyber-physical coordination yields explicit NE strategies and improved stability under strategic load-altering attacks. The results demonstrate that integrated cyber-physical resilience can significantly enhance grid operation in the presence of IoT botnets, with practical implications for real-time defense and policy planning.
Abstract
The wide adoption of Internet of Things (IoT)-enabled energy devices improves the quality of life, but simultaneously, it enlarges the attack surface of the power grid system. The adversary can gain illegitimate control of a large number of these devices and use them as a means to compromise the physical grid operation, a mechanism known as the IoT botnet attack. This paper aims to improve the resiliency of cyber-physical power grids to such attacks. Specifically, we use an epidemic model to understand the dynamic botnet formation, which facilitates the assessment of the cyber layer vulnerability of the grid. The attacker aims to exploit this vulnerability to enable a successful physical compromise, while the system operator's goal is to ensure a normal operation of the grid by mitigating cyber risks. We develop a cross-layer game-theoretic framework for strategic decision-making to enhance cyber-physical grid resiliency. The cyber-layer game guides the system operator on how to defend against the botnet attacker as the first layer of defense, while the dynamic game strategy at the physical layer further counteracts the adversarial behavior in real time for improved physical resilience. A number of case studies on the IEEE-39 bus system are used to corroborate the devised approach.
