Next Article in Journal
Economic Emission Dispatch of Power Systems Using an Improved Multi-Objective Grey Wolf Optimizer
Previous Article in Journal
Techno-Economic and Reliability Assessment of Grid-Connected PV/Wind/Battery Hybrid Configurations for a Domestic District Under Unreliable Grid Conditions
 
 
Article
Peer-Review Record

Physics-Guided Data Fusion-Based Cyberattack Detection for Distributed Energy Resource Aggregators with Limited Observability

Electricity 2026, 7(3), 89; https://doi.org/10.3390/electricity7030089
by Celina Wilkerson 1,2, Qiuhua Huang 1,*, Burhan Hyder 2 and Rohit Jinsiwale 3
Reviewer 1: Anonymous
Reviewer 2: Anonymous
Reviewer 3: Anonymous
Reviewer 4: Anonymous
Electricity 2026, 7(3), 89; https://doi.org/10.3390/electricity7030089
Submission received: 9 July 2026 / Revised: 8 August 2026 / Accepted: 18 August 2026 / Published: 21 August 2026

Round 1

Reviewer 1 Report

Comments and Suggestions for Authors

This paper proposes a physics-guided data fusion framework for cyberattack detection in Distributed Energy Resource (DER) aggregators, which combines a data-driven forecasting method with a physical mechanism sensitivity analysis via machine learning algorithms. However, the paper has the following shortcomings in terms of theoretical self-consistency, mathematical rigor, and algorithmic evaluation, which require further clarification and revision by the authors:

  1. The authors state that DER aggregators "do not have access to the full distribution-system topology or all bus measurements". How, then, is a precise OpenDSS physical sensitivity matrix constructed?
  2. In Section 3.2, the paper describes the static and gradual cyberattack scenarios through text, but does not provide a mathematical modeling of the FDIA attack vector. It is recommended to supplement this to define the attack space and constraints explicitly.
  3. It is recommended to add comparative tests with classic small-sample time-series models (such as SARIMA and XGBoost) to further demonstrate the scientific validity of the algorithm selection.
  4. The detection threshold of the SAD module is set to the 97th percentile of the training residual mean squared errors. What is the basis for this selection method? The authors need to explain the rationale for selecting the 97th percentile as the threshold.

Author Response

We really appreciate your time and comments. Please see our responses in the attached PDF.

Author Response File: Author Response.pdf

Reviewer 2 Report

Comments and Suggestions for Authors

I think the issue is relevant and the novelty is acceptable. But I have few comments, see below. I mainly recommend softening the statement in the introduction, that “Integrating DER into microgrids can help maintain power supply longer during outages.” Photovoltaic solar systems have an important place in the energy mix, but they also have a number of disadvantages. The capacity is not enough, the power density per the area is low. The energy source is unstable and it depends on the weather. It can yield problems with the network stability. For example, the article doi:10.31545/intagr/192173 speaks about some next disadvantages (defects, short lifetime, recyclation cappacity ...) and it could be mentioned in references. I think, nuclear energy in combination with the renewable energy sources is the most effective energy solution for the future.

Comments:

Figs. 1, 2 – The text is only readable after a large magnification. Both the image and the text could be larger.

Fig. 5 – On the horizontal axis, the unit “Hour” is singular, but on the vertical axis the unit “Volts” is plural. In Fig. 6 there is only the symbol (V). This should be uniform in all figures.

- Tabs. 1, 3, 4 – The unit (%) should be in the table header and only the values ​​in the columns.

- Lines 450-500 – If abbreviations are used as physical quantities, they should be presented in the text in Italic font, similar to the one used in equations.

- Eqs. 12, 13, 14 – The abbreviations TP, TN, FP, FN are not in the list of abbreviations. It is not clear what values ​​these quantities represent. If it is a number of events, lines 462-468 should indicate "number of true positives (TP)", "number of false negatives (FN)", ...

- Citations should be titled "References".

- Some references (for example 2, 11, 18, 28, …) are strange. Important bibliographic information are missing. For example, Ref.11: Machines 202210(6), 446, doi:10.3390/machines10060446. Ref. 18: Energies 2024, 17(23), 5870, doi:10.3390/en17235870.

- Ref. 14, 15, 16, 24, 43 – When citing conference proceedings, the location and date of the conference must be given.

Author Response

We really appreciate your time and comments. Please see our responses in the attached PDF.

Author Response File: Author Response.pdf

Reviewer 3 Report

Comments and Suggestions for Authors

Please carefully address the following questions/comments before a decision can be made:

1) Why is gradient boosting machine (GBM) the most appropriate fusion model? The paper states that GBM optimizes the precision–recall tradeoff, but it does not compare GBM against alternative fusion strategies such as logistic regression, random forests, XGBoost, LightGBM, or neural-network-based ensembles. An ablation study quantifying the contribution of the fusion model relative to the individual detection modules would strengthen the justification for this design choice.

2) How sensitive is the proposed framework to forecasting model inaccuracies? Since the anomaly detector relies on forecasting-assisted residuals, its performance may deteriorate under forecast errors caused by rapidly changing irradiance, load uncertainty, or DER operational changes rather than cyberattacks. The paper should quantify detection robustness under varying forecasting accuracies and distinguish between forecast-induced residuals and attack-induced residuals. Useful references: 10.3390/electronics15091894.

3) What assumptions are made regarding the attacker's knowledge and capabilities? Clarifying the threat model and evaluating adaptive attackers who optimize against the proposed detector would provide a more rigorous security assessment.

4) The sensitivity-based diagnosis module appears to depend on PV physical characteristics. How well does the approach generalize to heterogeneous DER aggregators that include batteries, electric vehicles, controllable loads, or mixed DER portfolios?

5) The evaluation is conducted on a single microgrid test system under different observability levels. This raises concerns about external validity. The paper would benefit from experiments on multiple network topologies, different feeder sizes, varying DER penetration levels, and real-world measurement datasets to demonstrate that the reported PR-AUC of 0.91–0.93 is not specific to the chosen test system.

6) Why is precision–recall AUC the primary evaluation metric, and how does the proposed method perform with respect to operational metrics such as detection latency, false alarm rate per day, missed detection probability, and computational overhead?

Author Response

We really appreciate your time and comments. Please see our responses in the attached PDF.

Author Response File: Author Response.pdf

Reviewer 4 Report

Comments and Suggestions for Authors

The manuscript proposes a novel cyberattack detection framework tailored specifically for Distributed Energy Resource (DER) aggregators operating under limited system observability. In generak, the paper addresses a critical and highly relevant problem in smart grid cybersecurity. The narrative is well structured, and the technical contribution of bridging physics-based explainability with machine learning data fusion is strong.

The paper provides a strong conceptual framework, relevant test setups, and compelling latency analysis for real-time DER aggregator applications. However, several methodology details, performance reporting inconsistencies, and presentation issues require clarification before the paper can be accepted for publication. In particular:

1.- In Table 4 (Overall Confusion Matrix), the "Acc." and "Prec." values for several models appear inverted or mismatched with the reported confusion matrices. For instance, GBM Fusion at 25 % observability (TP=522, FP=465, TN=1023, FN=18), in the standalone GBM row at 25 % observability, Accuracy is listed as 52.92 % and Precision as 76.23 %, despite TP=525, FP=467, TN=1021, FN=15. Please, could you clarify this issue? Please audit every column in Table 4. Ensure Accuracy, Precision, and Recall formulas are calculated uniformly without interchanging column headers or swapping Precision and Accuracy values.

2.- The test dataset contains 1,488 normal cases and 540 attack cases (approx 73.4 % normal, 26.6 % attack). While the recall of the proposed method is exceptional (96.67 % – 98.89 %), the number of False Positives remains relatively high (340 – 465 FPs out of 1,488 normal cases). This results in Precision values around 52.89 % – 60.75 %. Please, discuss the operational implications of a 23 % – 31 % false alarm rate in a real-world DER aggregator setting.

3.- Please, explain why the threshold optimization (tau*) maximizing the F1 score yields a bias toward recall over precision, and whether adjusting class weights or probability decision thresholds could further mitigate false positives.

4.- Section 2.2.1 notes that the operating point x0 is updated at hourly intervals. Please elaborate briefly on how x0 is chosen under limited observability when full-network state estimation is unavailable.

5.- In Algorithm 1, parameters such as h (finite difference step), lambda (ridge penalty), PVBoost, and PVgate are introduced. Please, state the exact numerical values or selection criteria used for these parameters in the case study.

6.- The use of TabPFN for time-series forecasting is novel and interesting. However, TabPFN is historically trained on independent tabular datasets. Please, clarify whether TabPFN v1 or v2 (or TabPFN-Time / time-series extension) was utilized. Pleasee, specify the input sequence length, training window duration, and how missing covariate measurements are handled if a sensor fails.

7.- In Fig. 1 and 2, please regenerate high-resolution vector images with corrected labels.

8.- The results shown in Figure 6 are confusing. Please, improve the quality of this figure.

9.- Please, define all abbreviations upon first mention in the main text (e.g., OLS, AGC).

 

Author Response

We really appreciate your time and comments. Please see our responses in the attached PDF.

Author Response File: Author Response.pdf

Round 2

Reviewer 1 Report

Comments and Suggestions for Authors

The manuscript’s deficiencies have been effectively fixed and it meets the publication criteria. I recommend accepting the manuscript in its present form.

Reviewer 2 Report

Comments and Suggestions for Authors

I think, my comments were accepted and the article was improved. The future of the energy mix can only be guessed at and I understand that the authors have a different opinion on the matter. I thought that supplementing the introduction with the suggested note and reference would be good, but I do not insist on it. I can recommend the article for publication.

Reviewer 3 Report

Comments and Suggestions for Authors

The revised version has substantially been improved. Good attempt! No further comments at this point. 

Reviewer 4 Report

Comments and Suggestions for Authors

According to the manuscript authors' responses, in the reviewer's opinion, this new version of the paper can be accepted for publication in the Journal.

 

Back to TopTop