Traditional approaches to power system security treat cybersecurity and physical grid modeling as separate domains. Energy engineers rely on digital twins that capture thermal, electrical, and mechanical behavior; cybersecurity teams build threat models that simulate network attacks. The disconnect between these worlds creates blind spots: cyber-attacks can trigger physical failures that neither model anticipates alone.
This research addresses that fragmentation by proposing a tightly coupled Virtual Digital Twin (VDT) framework that merges both domains into a unified simulation environment. Rather than running loosely coupled co-simulations that introduce computational delays and miss rapid cross-domain feedback, the VDT integrates the precise mathematical, thermal, and electrical equations governing critical assets directly with attack vectors.
The researchers tested their methodology on two archetypal grid components: a power transformer and a microgrid inverter. For the transformer, they simulated supervisory-level attacks (false control commands), measurement attacks (sensor manipulation), and harmonic injection at the physical layer. For the inverter, they evaluated short-circuit exploits and hybrid phase-harmonic attacks designed to destabilize power quality.
Results revealed how subtle digital manipulation—such as delayed or corrupted sensor readings—propagates through the control layer to induce real physical stress. A measurement attack could cause a transformer to operate outside thermal safety margins, accelerating aging. Harmonic injection degrades power quality and can trigger protective relay misoperation.
By documenting the governing equations and providing sensitivity analyses, the framework offers utilities a transparent, quantitative methodology for vulnerability assessment. This enables grid operators and asset owners to prioritize hardening efforts on the most critical cyber-physical pathways and design defenses that account for both digital and physical constraints—essential for protecting aging infrastructure against sophisticated, asset-destructive attacks.



