You are currently viewing a new version of our website. To view the old version click .
Energies
  • This is an early access version, the complete PDF, HTML, and XML versions will be available soon.
  • Article
  • Open Access

30 December 2025

Neural Network Method for Detecting UDP Flood Attacks in Critical Infrastructure Microgrid Protection Systems with Law Enforcement Agencies’ Rapid Response

,
,
,
,
,
,
,
,
and
1
Department of Scientific Activity Organisation, Kharkiv National University of Internal Affairs, 27, L. Landau Avenue, 61080 Kharkiv, Ukraine
2
Department of Combating Cybercrime, Kharkiv National University of Internal Affairs, 27, L. Landau Avenue, 61080 Kharkiv, Ukraine
3
Department of Automation and Computer Engineering, Cracow University of Technology, 24, Warszawska, 31-155 Cracow, Poland
4
Research Institute for Intelligent Computer Systems, West Ukrainian National University, 11, Lvivska Street, 46009 Ternopil, Ukraine
Energies2026, 19(1), 209;https://doi.org/10.3390/en19010209 
(registering DOI)
This article belongs to the Special Issue Cyber Security in Microgrids and Smart Grids—2nd Edition

Abstract

This article develops a hybrid neural network method for detecting UDP flooding in critical infrastructure microgrid protection systems. This method combines sequential statistics (CUSUM) and a multimodal convolutional 1D-CNN architecture with a composite scoring criterion. Input features are generated using packet-aggregated one-minute vectors with metrics for packet count, average size, source entropy, and HHI concentration index, as well as compact sketches of top sources. To ensure forensically relevant incident recording, a greedy artefact selection policy based on the knapsack problem with a limited forensic buffer is implemented. The developed method is theoretically justified using a likelihood ratio criterion and adaptive threshold tuning, which ensures control over the false alarm probability. Experimental validation on traffic datasets demonstrated high efficiency, with an overall accuracy of 98.7%, a sensitivity of 97.4%, an average model inference time of 5.3 ms (2.5 times faster than its LSTM counterpart), a controlled FPR of 0.96%, and a reduction in asymptotic detection latency with an increase in intensity from 35 to 12 s. Moreover, with a storage budget of 10 MB, 28 priority bins were selected (their total size was 7.39 MB), ensuring the approximate preservation of 85% of the most informative packets for subsequent examination. This research contribution involves the creation of a ready-to-deploy, resource-efficient detector with low latency, explainable statistical layers, and a built-in mechanism for generating a standardized evidence package to facilitate rapid law enforcement response.

Article Metrics

Citations

Article Access Statistics

Article metric data becomes available approximately 24 hours after publication online.