Distributed energy resource (DER) aggregators—systems that coordinate rooftop solar, batteries, and other flexible loads—are increasingly targeted by false data injection attacks (FDIA) that manipulate sensor readings to disrupt grid operations. A single compromised aggregator can cascade failures across dozens of enrolled customer devices, yet aggregators typically operate with only partial visibility into underlying network conditions, making traditional security methods ineffective.
Researchers have proposed a physics-guided data fusion framework that addresses this observability gap. The method combines two detection layers: first, a forecasting-assisted residual module that rapidly flags anomalies by comparing expected behavior against actual measurements; second, a photovoltaic-aware sensitivity method that diagnoses the root physical cause of detected deviations, distinguishing genuine equipment failures from deliberate attacks.
These complementary outputs are fused using gradient boosting machine learning to optimize the balance between detection sensitivity and precision. Testing on a microgrid system across multiple attack scenarios—including both sudden and gradual infiltration attempts—demonstrated 93.34% accuracy with an F1-score of 0.88 and 0.96 precision-recall area under the curve.
The innovation addresses a critical gap in DER security. Existing cyberattack detection relies on full system observability, assuming complete knowledge of all nodes and flows—impossible for aggregators managing third-party resources across distribution networks. By requiring only local measurements available to an aggregator, this method scales to real-world deployments where centralized visibility is infeasible.
As grid operators accelerate DER integration to meet renewable targets, cyberattack resilience becomes essential infrastructure protection. This framework enables aggregators to operate autonomously while maintaining detection of sophisticated threats, supporting the transition to distributed, flexible power systems without compromising reliability or security.



