Cybersecurity/AI, & its Use in Grid Protection/Control
Iowa State University
Energy
05 / 01 / 2019

The Company
The Department of Electrical and Computer Engineering at Iowa State University is a leading institution in power systems research. Under the guidance of renowned cybersecurity expert Dr. Manimaran Govindarasu, PhD candidate Vivek-Kumar Singh conducts cutting-edge R&D at the intersection of power systems, artificial intelligence, and cyber-physical security to protect critical grid infrastructure from sophisticated cyber threats.
Everyone who’s doing or has done any sort of simulation in power systems and power electronics knows at the very least the name ‘OPAL-RT’… The generation of the datasets was one of the places where OPAL-RT saved our lives. We staged all types of attacks, observed system dynamics, and collected data to train our machine learning models in real time.
Vivek-Kumar Singh
PhD Candidate, Iowa State University
The Challenges
- Lack of Open-Source Cybersecurity Datasets: Due to security risks and corporate confidentiality, utilities cannot share operational attack data, leaving researchers without realistic datasets to train AI/ML models.
- Complex Threat Detection: Distinguishing between benign grid control commands and malicious cyber intrusions across Wide-Area Monitoring, Protection & Control (WAMPAC) systems requires high-fidelity dynamic modeling.
- Hardware & Dynamic Interaction: Relays and Synchrophasors (PMUs) cannot natively distinguish between physical faults and cyberattacks, necessitating realistic dynamic data injection.
- Multi-Site Telecom Latency: Simulating geographically distributed control centers and substations requires accounting for real-world communication delays and network latency without compromising model accuracy.
The OPAL-RT Solution
Iowa State University leveraged OPAL-RT’s real-time hardware, software, and communication protocols to create a comprehensive cyber-physical testbed:
- Attack Staging & Dataset Generation: Used OPAL-RT real-time simulators and ePHASORSIM to inject dynamic faults and stage cyberattacks, generating proprietary-safe “good and bad” training datasets for machine learning.
- Hardware-in-the-Loop (HIL) Integration: Connected physical relays and PMUs directly to OPAL-RT hardware, enabling realistic playback and real-time dynamic response observation.
- Multi-Protocol Communication Support: Utilized native OPAL-RT drivers for IEC 61850 GOOSE, DNP3 (via OPC drivers), and C37.118 PMU protocols to emulate real-world SCADA and synchrophasor network architecture.
- Remote Co-Simulation Federation: Connected two OPAL-RT simulators remotely—one in Iowa acting as the control center and one at the US Army Research Laboratory in Maryland modeling IEEE 39-bus substations—to measure 26.7 ms synchrophasor data latency under attack conditions.
The Results
- AI Anomaly Detection: Successfully developed and validated machine learning algorithms capable of real-time anomaly detection in WAMPAC environments despite real-world network latency.
- Utility Cyber Training: Provided practical SCADA cybersecurity training to major utilities including Cedar Falls Utilities (CFU), CIPCO, MidAmerican Energy, Idaho Power Company, and Corn Belt Power Cooperative (CBPC).
- Defense & Federal Collaboration: Established a multi-substation cyber-federated testbed in partnership with the US Army Research Laboratory for defense-grade grid protection research.
- Dataset Sharing for Scientific Progress: Plan to release non-proprietary PMU attack signature datasets to accelerate global smart grid cybersecurity R&D.



