Power system security assessment traditionally relies on detailed mathematical models of generation, transmission, and control systems. However, obtaining and maintaining accurate models across complex interconnected grids remains challenging. A new data-driven approach addresses this limitation by computing security indices—metrics that quantify the minimum number of components that must be compromised to execute undetected stealth attacks—using only operational data.
The research establishes a theoretical framework showing that under specific conditions, a security index derived purely from input/output measurements matches the result obtained from model-based analysis. This equivalence is critical because it validates that operators can accurately assess true vulnerability levels without requiring comprehensive system knowledge.
The practical implications are substantial. Grid operators continuously collect massive volumes of operational data through SCADA systems, PMUs, and meters. Converting this wealth of information into actionable security metrics enables more targeted protection strategies. Rather than applying uniform security measures across all components, operators can prioritize resources on components with the highest attack susceptibility.
Stealth attacks—also called false data injection attacks—are particularly dangerous because they can manipulate state estimates while remaining undetected by conventional alarm systems. By identifying which combinations of measurements a potential attacker could compromise, operators can deploy monitoring systems or redundancy precisely where needed.
The research provides a practical algorithm for computing the data-driven security index, making the theoretical framework implementable in operational environments. This bridges the gap between complex cybersecurity theory and real-world grid operations where perfect system models are unavailable.
As grids modernize with increased renewable integration, distributed resources, and digitalization, the attack surface expands. Data-driven security assessment tools that work with existing operational information provide immediate value without requiring disruptive infrastructure changes or complete system redesigns.



