Identifiability-Aware, Cost-Aware Triage of Physical Faults and Measurement-Integrity Anomalies in Energy Cyber-Physical Systems
Highlights
- A strictly alarm-gated, run-disjoint protocol yields conditional physical-feature AUCs of 0.873 on TEP and 0.895 on the wind-farm simulation.
- A separate benign-sensor-fault stress test preserves process-versus-measurement-integrity ranking but forces matched sensor-fault/attack cause AUC to 0.500.
- Physical-consistency features provide auditable triage and reduce illustrative episode-level decision cost, but trail a raw-statistics XGBoost benchmark on clean data.
- Observationally equivalent causes require abstention or independent maintenance, sensor-quality, or security evidence rather than a forced telemetry-only label.
Abstract
1. Introduction
- We formulate post-alarm fault–anomaly triage as a sensor-data integrity problem and introduce a two-stage pipeline based on nine auditable physical-consistency features. The pipeline includes channel-concentration descriptors that may guide inspection and an innovation defense, but the present study does not validate exact channel or subsystem localization (Section 3.5).
- We characterize the monitoring limits through an SPE-only covert magnitude budget and support-size transition, an innovation result, and an attack-magnitude-independent estimation-error bound. We further prove an observational-equivalence limit for measurement-only cause attribution. Each result is separated from the empirical attribution claims it does not prove (Section 4).
- We evaluate the complete detection-gated pipeline at matched false-alarm rates, with a declared commissioning segment, five complete-run outer folds, nested calibration, run-bootstrap intervals, a paired-background check, and a learned baseline. The real-data study distinguishes ranking transfer, threshold transfer, and fully real cross-domain evidence rather than treating them as equivalent. A grouped three-class stress test adds synthetic benign sensor faults, exact causal-relabel controls, and selective review (Section 5 and Section 5.6).
- We connect run-level triage to operational response through exact episode-level EMC. Missed Stage-1 episodes are charged explicitly, and calibration and rejection are presented as exploratory analyses rather than as hidden improvements to the primary result (Section 6).
2. Related Work
2.1. Multivariate Statistical Process Monitoring and Fault Detection
2.2. Cyber-Physical System Attack Modeling and Detection
2.3. Resilient Estimation and Secure Control
2.4. Wind-Farm SCADA Condition Monitoring
2.5. The Fault-Versus-Attack Attribution Gap
2.6. Reliability and Safety-Consequence Perspectives
3. Materials and Methods
3.1. Problem Formulation and Threat Model
Measurements and Monitoring Model
3.2. Anomaly Regimes
- Healthy: and follows the normal-operation distribution.
- Physical fault: An internal degradation or component fault perturbs the plant state. The perturbation propagates through the process coupling (the plant Jacobian) and appears, correlated, across a broad set of physically coupled channels of ; still, (the sensors report truthfully).
- Benign sensor fault: The plant state may be healthy, but an instrument, acquisition buffer, or communication component corrupts one or more reported channels without malicious intent.
- Attack-consistent sensor anomaly: The plant is physically healthy ( normal) but an adversary corrupts the telemetered values on a subset of channels.
3.3. Threat Model
3.4. Problem Statement
- Detects an anomaly (Stage 1);
- Upon detection, triages it hierarchically as a process fault or a measurement-integrity anomaly and reports channel-concentration descriptors that may guide inspection, without claiming exact channel, subsystem, or support localization (Stage 2a);
- Attempts the lower-level decision only when the evidence supports it (Stage 2c).
3.5. The Detect-Then-Discriminate Framework
3.6. Stage 1: Calibrated MSPM Detection
3.7. Stage 2: Physical-Consistency Discrimination
| Algorithm 1 Online detect-then-discriminate monitoring |
|
3.8. Stage 2c: Benign-Sensor-Fault and Identifiability Protocol
3.9. Stage 2b: Residual-Innovation Defense for Stealthy Attacks
3.10. Use of Generative Artificial Intelligence
4. Detectability, Causal Identifiability, and Resilient Estimation
4.1. Covert Magnitude Budget
4.2. The Undetectable Phase Transition (SPE Monitor)
- If , then generically (for supports not aligned with the principal subspace) has full column rank, so ; by Remark 1 the attack pays a finite, strictly positive SPE-detectability cost, and a sufficiently large injection necessarily forces the SPE over its limit. This direction is the positive guarantee of the proposition (below , every support- attack is SPE-detectable at large enough magnitude). However, we flag its quantitative content explicitly: “strictly positive” is an algebraic statement, and near the transition the margin can be so small that the covert budget (5) is enormous in practice. On TEP, at is , so the SPE monitor is already effectively blind one step before the transition (a covert budget of order standard deviations). On the wind farm the margin at is , a meaningful but modest cost. The engineering boundary is therefore where becomes small relative to plausible injection magnitudes (read off the -versus-s curve of Section 5), not the algebraic collapse point itself.
- If , then , so has a nontrivial null space: there exists with . The corresponding injection produces zero SPE residual contribution at arbitrary magnitude: an SPE-monitor-undetectable attack exists. As Remark 2 shows, this same injection is generally not silent under the deployed monitor, because it necessarily has a nonzero component in (the SPE-null space and the -monitored subspace are complementary), so case 2 is a statement about the SPE channel specifically, not about detectability of the deployed system.
4.3. Stealthy Direction and Its Innovation Signature
4.4. Physical-Consistency Separation: A Modeling Assumption
- Coupling (F1/F3): A physical fault perturbs the plant state, which propagates through the process Jacobian to a dense set of correlated channels; its normalized residual-contribution vector therefore has low concentration (small Gini, large entropy) and broad correlation-matrix deviation. A support- attack injects only on and, absent genuine physical coupling, cannot manufacture correlated residuals on unattacked channels, so is concentrated and the correlation deviation is narrow.
- Noise (F2): A DoS/freeze attack collapses innovation variance on below the physical floor that a real fault preserves; replay reinstates normal-looking values with the wrong temporal autocorrelation.
4.5. Observational Equivalence of Sensor Faults and Attacks
4.6. Resilient Innovation-Saturating Estimator
5. Results
5.1. Evaluation Cases and Locked Protocol
5.2. Strict End-to-End Performance
5.3. Construction-Artifact Diagnostics and Learned Comparator
5.4. SPE Detectability and Resilient-Estimation Checks
5.5. Operating-Envelope Limitation
5.6. Field-Data Transfer and Cross-Domain Evidence
5.6.1. CARE Wind-Turbine SCADA
5.6.2. Auxiliary and Cross-Domain Datasets
5.7. Interpretation of the Learned Baseline
5.8. Cross-Fitted Probability Calibration
5.9. Benign-Sensor-Fault and Causal-Identifiability Stress Test
6. Risk-Aware Decision Consequences
6.1. Consequence Model
6.2. Exact Episode-Level Accounting
7. Discussion
7.1. What the Strict Evaluation Establishes
7.2. Field Transfer and Decision Meaning
7.3. Generalizability and Deployment Boundary
7.4. Limitations and Priorities
8. Conclusions
Supplementary Materials
Author Contributions
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Acknowledgments
Conflicts of Interest
Abbreviations
| CPS | Cyber-physical system |
| SCADA | Supervisory control and data acquisition |
| MSPM | Multivariate statistical process monitoring |
| PCA/DPCA/KPCA | Principal/dynamic principal/kernel principal component analysis |
| CVA | Canonical-variate analysis |
| SPE | Squared prediction error |
| CUSUM | Cumulative sum |
| FAR | False-alarm rate |
| EMC | Expected misattribution cost |
| UUB | Uniformly ultimately bounded |
| TEP | Tennessee Eastman Process |
| RF | Random forest |
| OOF | Out-of-fold |
| AUC | Area under the receiver-operating-characteristic curve |
References
- Ku, W.; Storer, R.H.; Georgakis, C. Disturbance detection and isolation by dynamic principal component analysis. Chemom. Intell. Lab. Syst. 1995, 30, 179–196. [Google Scholar] [CrossRef] [Scilit]
- Russell, E.L.; Chiang, L.H.; Braatz, R.D. Fault detection in industrial processes using canonical variate analysis and dynamic principal component analysis. Chemom. Intell. Lab. Syst. 2000, 51, 81–93. [Google Scholar] [CrossRef] [Scilit]
- Venkatasubramanian, V.; Rengaswamy, R.; Kavuri, S.N.; Yin, K. A review of process fault detection and diagnosis: Part III: Process history based methods. Comput. Chem. Eng. 2003, 27, 327–346. [Google Scholar] [CrossRef] [Scilit]
- Yin, S.; Ding, S.X.; Xie, X.; Luo, H. A Review on Basic Data-Driven Approaches for Industrial Process Monitoring. IEEE Trans. Ind. Electron. 2014, 61, 6418–6428. [Google Scholar] [CrossRef] [Scilit]
- Yuan, S.; Reniers, G.; Yang, M. Integrated management of safety and security barriers in chemical plants to cope with emerging cyber-physical attack risks under uncertainties. Reliab. Eng. Syst. Saf. 2024, 250, 110320. [Google Scholar] [CrossRef] [Scilit]
- Wang, Z.; Wang, J.; Wei, Z.; Ye, W.; Zhang, L. Safety integrity level assessment for safety instrumented system in oil and gas station with cyber threat. Reliab. Eng. Syst. Saf. 2026, 265, 111614. [Google Scholar] [CrossRef] [Scilit]
- Ji, C.; Sun, W. A Review on Data-Driven Process Monitoring Methods: Characterization and Mining of Industrial Data. Processes 2022, 10, 335. [Google Scholar] [CrossRef] [Scilit]
- Badihi, H.; Zhang, Y.; Jiang, B.; Pillay, P.; Rakheja, S. A Comprehensive Review on Signal-Based and Model-Based Condition Monitoring of Wind Turbines: Fault Diagnosis and Lifetime Prognosis. Proc. IEEE 2022, 110, 754–806. [Google Scholar] [CrossRef] [Scilit]
- Wang, S.; Vidal, Y.; Pozo, F. Recent advances in wind turbine condition monitoring using SCADA data: A state-of-the-art review. Reliab. Eng. Syst. Saf. 2026, 267, 111838. [Google Scholar] [CrossRef] [Scilit]
- Liu, Y.; Ning, P.; Reiter, M.K. False data injection attacks against state estimation in electric power grids. ACM Trans. Inf. Syst. Secur. 2011, 14, 13. [Google Scholar] [CrossRef] [Scilit]
- Pasqualetti, F.; Dorfler, F.; Bullo, F. Attack Detection and Identification in Cyber-Physical Systems. IEEE Trans. Autom. Control 2013, 58, 2715–2729. [Google Scholar] [CrossRef] [Scilit]
- Fawzi, H.; Tabuada, P.; Diggavi, S. Secure Estimation and Control for Cyber-Physical Systems Under Adversarial Attacks. IEEE Trans. Autom. Control 2014, 59, 1454–1467. [Google Scholar] [CrossRef] [Scilit]
- Teixeira, A.; Shames, I.; Sandberg, H.; Johansson, K.H. A secure control framework for resource-limited adversaries. Automatica 2015, 51, 135–148. [Google Scholar] [CrossRef] [Scilit]
- Pan, S.; Morris, T.; Adhikari, U. Developing a Hybrid Intrusion Detection System Using Data Mining for Power Systems. IEEE Trans. Smart Grid 2015, 6, 3104–3113. [Google Scholar] [CrossRef] [Scilit]
- Amin, B.M.R.; Hossain, M.J.; Anwar, A.; Zaman, S. Cyber Attacks and Faults Discrimination in Intelligent Electronic Device-Based Energy Management Systems. Electronics 2021, 10, 650. [Google Scholar] [CrossRef] [Scilit]
- Gupta, K.; Sahoo, S.; Mohanty, R.; Panigrahi, B.K.; Blaabjerg, F. Distinguishing Between Cyber Attacks and Faults in Power Electronic Systems–A Noninvasive Approach. IEEE J. Emerg. Sel. Top. Power Electron. 2023, 11, 1578–1588. [Google Scholar] [CrossRef] [Scilit]
- Semertzis, I.; Goyel, H.; Rajkumar, V.S.; Presekal, A.; Stefanov, A.; Palensky, P. Towards Real-Time Distinction of Power System Faults and Cyber Attacks on Digital Substations Using Cyber-Physical Event Correlation. In Proceedings of the 2024 12th Workshop on Modeling and Simulation of Cyber-Physical Energy Systems (MSCPES); IEEE: New York, NY, USA, 2024; pp. 1–6. [Google Scholar] [CrossRef] [Scilit]
- Roy, T.; Dey, S. On Distinguishability of Anomalies as Physical Faults or Actuation Cyberattacks. ASME Lett. Dyn. Syst. Control 2024, 4, 031003. [Google Scholar] [CrossRef] [Scilit]
- Chen, T.; Guestrin, C. XGBoost: A Scalable Tree Boosting System. In KDD ’16: Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining; Association for Computing Machinery: New York, NY, USA, 2016; pp. 785–794. [Google Scholar] [CrossRef] [Scilit]
- Pilario, K.E.S.; Cao, Y. Canonical Variate Dissimilarity Analysis for Process Incipient Fault Detection. IEEE Trans. Ind. Inform. 2018, 14, 5308–5315. [Google Scholar] [CrossRef] [Scilit]
- Lee, J.M.; Yoo, C.; Choi, S.W.; Vanrolleghem, P.A.; Lee, I.B. Nonlinear process monitoring using kernel principal component analysis. Chem. Eng. Sci. 2004, 59, 223–234. [Google Scholar] [CrossRef] [Scilit]
- Narasimhan, S.; El-Farra, N.H.; Ellis, M.J. Detectability-based controller design screening for processes under multiplicative cyberattacks. AIChE J. 2022, 68, e17430. [Google Scholar] [CrossRef] [Scilit]
- Yin, S.; Ding, S.X.; Haghani, A.; Hao, H.; Zhang, P. A comparison study of basic data-driven fault diagnosis and process monitoring methods on the benchmark Tennessee Eastman process. J. Process Control 2012, 22, 1567–1581. [Google Scholar] [CrossRef] [Scilit]
- Wei, Y.; Chen, Z.; Ye, Z.S.; Pan, E. High-dimensional process monitoring under time-varying operating conditions via covariate-regulated principal component analysis. Reliab. Eng. Syst. Saf. 2024, 252, 110440. [Google Scholar] [CrossRef] [Scilit]
- Mo, Y.; Sinopoli, B. Secure control against replay attacks. In Proceedings of the 2009 47th Annual Allerton Conference on Communication, Control, and Computing (Allerton); IEEE: New York, NY, USA, 2009; pp. 911–918. [Google Scholar] [CrossRef] [Scilit]
- Giraldo, J.; Urbina, D.; Cardenas, A.; Valente, J.; Faisal, M.; Ruths, J.; Tippenhauer, N.O.; Sandberg, H.; Candell, R. A Survey of Physics-Based Attack Detection in Cyber-Physical Systems. ACM Comput. Surv. 2018, 51, 76. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Zhang, J.; Zio, E.; Ma, C.; Liu, K.; Wang, W. A probabilistic cost-benefit analysis approach for cyberattack path evaluation. Reliab. Eng. Syst. Saf. 2025, 263, 111255. [Google Scholar] [CrossRef] [Scilit]
- Tang, D.; Fang, Y.P.; Zio, E. Vulnerability analysis of demand-response with renewable energy integration in smart grids to cyber attacks and online detection methods. Reliab. Eng. Syst. Saf. 2023, 235, 109212. [Google Scholar] [CrossRef] [Scilit]
- Zheng, H.; Li, X.; Li, F. Unsupervised cyberattack detection in smart grids: A novel approach integrating horizontal federated learning for the control center and substations. Reliab. Eng. Syst. Saf. 2025, 264, 111444. [Google Scholar] [CrossRef] [Scilit]
- Zhang, B.; Du, M.; Zheng, H.; Liu, K.; Lu, B. Detection framework for bidirectional false data injection attacks to enhance reliability in cyber-physical power systems. Reliab. Eng. Syst. Saf. 2026, 271, 112267. [Google Scholar] [CrossRef] [Scilit]
- Wu, W.; Zhang, L.; Fu, H.; Wang, K.; Li, X. Safety Impact Analysis Considering Physical Failures and Cyber-Attacks for Mechanically Pumped Loop Systems (MPLs). Sensors 2022, 22, 4780. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Sztyber-Betley, A.; Syfert, M.; Kościelny, J.M.; Górecka, Z. Controller Cyber-Attack Detection and Isolation. Sensors 2023, 23, 2778. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Zou, X.; Liu, W.; Huo, Z.; Wang, S.; Chen, Z.; Xin, C.; Bai, Y.; Liang, Z.; Gong, Y.; Qian, Y.; et al. Current Status and Prospects of Research on Sensor Fault Diagnosis of Agricultural Internet of Things. Sensors 2023, 23, 2528. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Xing, W.; Shen, J. Security Control of Cyber–Physical Systems under Cyber Attacks: A Survey. Sensors 2024, 24, 3815. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Shoukry, Y.; Tabuada, P. Event-Triggered State Observers for Sparse Sensor Noise/Attacks. IEEE Trans. Autom. Control 2016, 61, 2079–2091. [Google Scholar] [CrossRef] [Scilit]
- Forti, N.; Battistelli, G.; Chisci, L.; Sinopoli, B. Joint attack detection and secure state estimation of cyber-physical systems. Int. J. Robust. Nonlinear Control 2019, 30, 4303–4330. [Google Scholar] [CrossRef] [Scilit]
- Ye, L.; Zhu, F.; Zhang, J. Sensor attack detection and isolation based on sliding mode observer for cyber-physical systems. Int. J. Adapt. Control Signal Process. 2020, 34, 469–483. [Google Scholar] [CrossRef] [Scilit]
- Schlechtingen, M.; Santos, I.F.; Achiche, S. Wind turbine condition monitoring based on SCADA data using normal behavior models. Part 1: System description. Appl. Soft Comput. 2013, 13, 259–270. [Google Scholar] [CrossRef] [Scilit]
- Bindingsbø, O.T.; Singh, M.; Øvsthus, K.; Keprate, A. Fault detection of a wind turbine generator bearing using interpretable machine learning. Front. Energy Res. 2023, 11, 1284676. [Google Scholar] [CrossRef] [Scilit]
- Zheng, M.; Man, J.; Wang, D.; Chen, Y.; Li, Q.; Liu, Y. Semi-supervised multivariate time series anomaly detection for wind turbines using generator SCADA data. Reliab. Eng. Syst. Saf. 2023, 235, 109235. [Google Scholar] [CrossRef] [Scilit]
- Staggs, J.; Ferlemann, D.; Shenoi, S. Wind farm security: Attack surface, targets, scenarios and mitigation. Int. J. Crit. Infrastruct. Prot. 2017, 17, 3–14. [Google Scholar] [CrossRef] [Scilit]
- Viasat Inc. KA-SAT Network Cyber Attack Overview. Viasat Corporate Incident Statement. 30 March 2022. Available online: https://www.viasat.com/perspectives/corporate/2022/ka-sat-network-cyber-attack-overview/ (accessed on 30 August 2026).
- Barenhorst, F.; Klein, F.; Barth, S. Report 2022: Germany. IEA Wind TCP Annual Report 2022, Country Report; IEA Wind Technology Collaboration Programme. 2023. Available online: https://iea-wind.org/wp-content/uploads/2023/10/Germany_2022.pdf (accessed on 30 August 2026).
- Arsal, M.; Kamel, T.; Asad, H.; Khan, A. A systematic review of cyber risk analysis approaches for wind power plants. Energies 2026, 19, 677. [Google Scholar] [CrossRef] [Scilit]
- Hink, R.C.B.; Beaver, J.M.; Buckner, M.A.; Morris, T.; Adhikari, U.; Pan, S. Machine learning for power system disturbance and cyber-attack discrimination. In Proceedings of the 7th International Symposium on Resilient Control Systems (ISRCS); IEEE: New York, NY, USA, 2014; pp. 1–8. [Google Scholar] [CrossRef] [Scilit]
- Abukhousa, E.; Afroz, S.S.F.S.; Alsaeed, F.; Qwbaiban, A.; Meliopoulos, A.P.S. Centralized Dynamic State Estimation Algorithm for Detecting and Distinguishing Faults and Cyber Attacks in Power Systems. In Proceedings of the 2025 IEEE Power & Energy Society General Meeting (PESGM); IEEE: New York, NY, USA, 2025; pp. 1–5. [Google Scholar] [CrossRef] [Scilit]
- Vaddi, P.K.; Diao, X.; Zhao, Y.; Smidts, C. Dynamic probabilistic risk assessment and game theory for cyber security risk analysis in nuclear power plants. Reliab. Eng. Syst. Saf. 2026, 266, 111702. [Google Scholar] [CrossRef] [Scilit]
- Xue, X.; Shen, D.; Ding, S.X.; Zhao, D. Dual Detection Framework for Faults and Integrity Attacks in Cyber-Physical Control Systems. arXiv 2025, arXiv:2510.14052v1. [Google Scholar] [CrossRef] [Scilit]
- Ahsan, M.S.; Wang, H.; Motakatla, V.R.; Zhu, M.; Liu, P. Differentiation Between Faults and Cyberattacks through Combined Analysis of Cyberspace Logs and Physical Measurements. arXiv 2026, arXiv:2601.03289v2. [Google Scholar] [CrossRef] [Scilit]
- Das, L.; Gjorgiev, B.; Sansavini, G. Uncertainty-aware deep learning for monitoring and fault diagnosis from synthetic data. Reliab. Eng. Syst. Saf. 2024, 251, 110386. [Google Scholar] [CrossRef] [Scilit]
- Fleming, K.N.; Silady, F.A. A risk informed defense-in-depth framework for existing and advanced reactors. Reliab. Eng. Syst. Saf. 2002, 78, 205–225. [Google Scholar] [CrossRef] [Scilit]
- Xing, L.; Distefano, S. Reliability and performance of cyber-physical systems. Reliab. Eng. Syst. Saf. 2022, 225, 108642. [Google Scholar] [CrossRef] [Scilit]
- Yao, P.; Yang, Q.; Wang, W. Dynamic cross-layer security risk assessment and mitigation for cyber-physical power systems. Reliab. Eng. Syst. Saf. 2025, 261, 111027. [Google Scholar] [CrossRef] [Scilit]
- Thapa, M.; Missoum, S. Uncertainty quantification and global sensitivity analysis of composite wind turbine blades. Reliab. Eng. Syst. Saf. 2022, 222, 108354. [Google Scholar] [CrossRef] [Scilit]
- Zhu, D.; Huang, X.; Ding, Z.; Zhang, W. Estimation of wind turbine responses with attention-based neural network incorporating environmental uncertainties. Reliab. Eng. Syst. Saf. 2024, 241, 109616. [Google Scholar] [CrossRef] [Scilit]
- Zhou, T.; Zhang, L.; Han, T.; Droguett, E.L.; Mosleh, A.; Chan, F.T.S. An uncertainty-informed framework for trustworthy fault diagnosis in safety-critical applications. Reliab. Eng. Syst. Saf. 2023, 229, 108865. [Google Scholar] [CrossRef] [Scilit]
- Li, H.; Jiao, J.; Liu, Z.; Lin, J.; Zhang, T.; Liu, H. Trustworthy Bayesian deep learning framework for uncertainty quantification and confidence calibration: Application in machinery fault diagnosis. Reliab. Eng. Syst. Saf. 2025, 255, 110657. [Google Scholar] [CrossRef] [Scilit]
- Page, E.S. Continuous inspection schemes. Biometrika 1954, 41, 100–115. [Google Scholar] [CrossRef] [Scilit]
- Downs, J.J.; Vogel, E.F. A plant-wide industrial process control problem. Comput. Chem. Eng. 1993, 17, 245–255. [Google Scholar] [CrossRef] [Scilit]
- Gück, C.; Roelofs, C.M.A.; Faulstich, S. CARE to Compare: A Real-World Benchmark Dataset for Early Fault Detection in Wind Turbine Data. Data 2024, 9, 138. [Google Scholar] [CrossRef] [Scilit]
- EDP–Energias de Portugal. Wind Turbine SCADA Signals and Historical Failure Logbook (Open Data). EDP Open Data. 2017. Available online: https://www.edp.com/en/innovation/wind-farm-1-wind-turbine-scada-signals-2017 (accessed on 30 August 2026).
- Clerc, A.; Lingkan, E. Hill of Towie Wind Farm Open Dataset, Version 2.0.0. 2026. Available online: https://zenodo.org/records/20204946 (accessed on 30 August 2026). [CrossRef]
- Hadjidemetriou, L.; Asprou, M.; Ciornei, I.; Charalambous, C.; Tekki, E. Dataset SUC1/S1–S4: Cyberattack Scenarios on DER Energy Management and Control. 2024. Available online: https://zenodo.org/records/12773981 (accessed on 30 August 2026). [CrossRef]
- Cibin, N.; Kabbara, N.; Presekal, A.; Semertzis, I.; Rajkumar, V.; Goyel, H.; Palensky, P.; Stefanov, A. Cyber-Physical Power System Dataset for Cyber Security of Digital Substations. 2025. Available online: https://zenodo.org/records/15371179 (accessed on 30 August 2026). [CrossRef]







| Work | Domain | Real Fault–Attack Attribution | Measurement Only | UQ | Cost | Theory |
|---|---|---|---|---|---|---|
| Hink/Pan [14,45] | Power testbed | ✓ | × | × | × | × |
| Roy et al. [18] | Actuation layer | – | – | × | × | ✓ |
| Xue et al. [48] | CPS control loop | – | – | × | × | ✓ |
| Vaddi et al. [47] | Nuclear | – | × | × | ✓ | × |
| Zheng et al. [40] | Wind SCADA | × | ✓ | × | × | × |
| This work | Wind SCADA + TEP | × | ✓ | ✓ | ✓ | ✓ |
| Mechanism | Severity | Temporal Pattern | Representative Received-Signal Form |
|---|---|---|---|
| Calibration drift | Soft | Gradual or persistent | with slowly varying (or gain-like drift) |
| Noise inflation | Soft precision loss | Persistent/time-varying | , above its nominal level |
| Stuck-at output | Hard when complete | Persistent constant | on the affected channel |
| Intermittent sample hold | Hard during each hold | Intermittent | during declared hold intervals |
| Quantization | Soft resolution loss | Persistent nonlinear | |
| Isolated spikes | Soft/impulsive unless saturated | Intermittent impulsive | with sparse outlier sequence |
| Metric | TEP | Wind Farm |
|---|---|---|
| Stage-1 episode coverage, fault (%) | 100.0 | 90.0 |
| Stage-1 episode coverage, anomaly (%) | 97.9 | 100.0 |
| Alarm-window fraction, fault (%) | 80.6 | 38.9 |
| Alarm-window fraction, anomaly (%) | 91.4 | 92.4 |
| Conditional physical-feature AUC | 0.873 (0.772–0.950) | 0.895 (0.806–0.966) |
| Conditional physical-feature balanced accuracy | 0.815 | 0.829 |
| End-to-end balanced accuracy | 0.805 | 0.792 |
| Pre-commissioning source AUC | 0.594 | 0.637 |
| Exact episode-level EMC | 10.83 | 10.40 |
| Reduction versus best blanket action (%) | 18.4 | 28.9 |
| Dataset | Evidence Type | Result |
|---|---|---|
| CARE A/B/C | Real wind faults; synthetic attacks | AUC 0.941; balanced accuracy 0.500 at and 0.813 after plant-normal anchoring (fault/attack recall 0.969/0.658) |
| EDP; Hill of Towie | Wind interpretability and FAR stability | Named-channel interpretability audit (not localization accuracy); annual FAR 1.3–4.2% |
| SUC1 | Wind-specific attack testbed | Stage-1 detects 3/4 attack events |
| MSU/ORNL | Real attacks and physical events | Balanced accuracy 0.954 [0.933, 0.975]; AUC 0.995 |
| TU Delft | Real substation attacks | Balanced accuracy 0.738; AUC 0.871 |
| Dataset | Score | Brier | Log Loss | ECE | Bal. Acc. |
|---|---|---|---|---|---|
| TEP | Raw | 0.120 | 0.382 | 0.082 | 0.815 |
| Platt | 0.116 | 0.377 | 0.097 | 0.775 | |
| Wind farm | Raw | 0.120 | 0.386 | 0.109 | 0.829 |
| Platt | 0.122 | 0.378 | 0.103 | 0.802 |
| Metric | TEP | Wind-Farm Simulation | ||
|---|---|---|---|---|
| Physical | Raw XGBoost | Physical | Raw XGBoost | |
| Three-class balanced accuracy | 0.543 | 0.522 | 0.535 | 0.593 |
| 95% interval | [0.459, 0.622] | [0.445, 0.593] | [0.458, 0.606] | [0.518, 0.669] |
| Three-class macro-F1 | 0.530 | 0.515 | 0.497 | 0.599 |
| End-to-end macro recall | 0.539 | 0.517 | 0.513 | 0.574 |
| Process fault vs. measurement integrity AUC | 0.820 | — | 0.853 | — |
| Matched sensor fault vs. attack AUC | 0.500 | 0.500 | 0.500 | 0.500 |
| Distinctive sensor-fault recall | — | — | 0.778 | 0.889 |
| Policy | TEP | Wind Farm |
|---|---|---|
| Always maintenance after alarm | 35.09 | 32.27 |
| Always isolation after alarm | 13.26 | 14.62 |
| Physical-score policy | 10.83 | 10.40 |
| Reduction versus better blanket response | 18.4% | 28.9% |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Ma, F.; Dang, Y.; Liu, Y.; Zhou, T. Identifiability-Aware, Cost-Aware Triage of Physical Faults and Measurement-Integrity Anomalies in Energy Cyber-Physical Systems. Sensors 2026, 26, 5585. https://doi.org/10.3390/s26175585
Ma F, Dang Y, Liu Y, Zhou T. Identifiability-Aware, Cost-Aware Triage of Physical Faults and Measurement-Integrity Anomalies in Energy Cyber-Physical Systems. Sensors. 2026; 26(17):5585. https://doi.org/10.3390/s26175585
Chicago/Turabian StyleMa, Fuliang, Yuzhen Dang, Yuanming Liu, and Tiezhuang Zhou. 2026. "Identifiability-Aware, Cost-Aware Triage of Physical Faults and Measurement-Integrity Anomalies in Energy Cyber-Physical Systems" Sensors 26, no. 17: 5585. https://doi.org/10.3390/s26175585
APA StyleMa, F., Dang, Y., Liu, Y., & Zhou, T. (2026). Identifiability-Aware, Cost-Aware Triage of Physical Faults and Measurement-Integrity Anomalies in Energy Cyber-Physical Systems. Sensors, 26(17), 5585. https://doi.org/10.3390/s26175585

