Power Grid Node Health Detection for Malicious Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Power grids face challenges in detecting malicious control, as cyber-attacks can mimic faults or anomalies, leading to unintended actions and potential system instability.

Innovation Solution

A system and method utilizing at least one node to detect power grid parameters for each power phase, generating signals from time-series sensor measurements, and a controller that uses deep-learning models to extract features, determine node health, and generate status tags indicating normal or malicious conditions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If deep-learning models and feature extraction are used to detect malicious control, then detection accuracy is improved, but device complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoiddevice complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the detection task into multiple components: nodes collect raw measurements, controllers perform feature extraction, and deep-learning models analyze patterns. This division allows high accuracy through sophisticated analysis while distributing complexity across multiple simpler components rather than requiring one complex centralized system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Feature extraction acts as an intermediary layer between raw sensor measurements and the deep-learning model. This intermediary transforms complex raw data into simplified features that are easier to analyze, reducing the computational complexity required at each stage while maintaining detection accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If real-time detection is implemented across all power grid nodes, then system reliability is improved, but loss of time for data processing increases

Engineering Contradiction:
Improvesystem reliabilityVSAvoiddata processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Nodes continuously collect and pre-process measurements in real-time, preparing data for analysis before malicious events occur. This preliminary action ensures that when anomalies are detected, the system can quickly analyze pre-prepared data rather than starting from raw measurements, reducing processing time while maintaining continuous monitoring for reliability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements detection with varying levels of sophistication at different nodes based on local needs. Not all nodes require full deep-learning analysis - only those detecting potential malicious events need the more complex analysis. This local differentiation maintains system reliability through comprehensive monitoring while reducing overall data processing time by applying complex analysis only where necessary.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12334730B2Systems and methods for malicious control detection in a power grid
Publication Date: 2025.06.17 GE INFRASTRUCTURE TECH LLC
  • US12334730B2 patent drawing
  • US12334730B2 patent drawing
  • US12334730B2 patent drawing

AI summary

The present application provides a system for malicious control detection in power grids. The system includes at least one node configured to detect power grid parameters for each power phase and generate a signal indicative of time-series sensor measurements for each power phase. A controller in communication with the node may be configured to receive from the at least one node, the respective signals, extract at least one feature from the respective signals, provide the at least one feature as an input to a deep-learning model, receive an output from the deep-learning model indicative of a relationship between the power grid parameters and a node health associated with the at least one node, generate a status tag associated with the at least one node based at least in part on the output, wherein the status tag is normal or malicious, and generate a status signal indicative of the status tag.