As part of the GridLogic project, a Department of Energy-supported cybersecurity initiative, Georgia Tech researchers have developed a deep neural network that can evaluate the security of the power grid orders of magnitude faster than the traditional methods.

Blank Space (small)
(text and background only visible when logged in)

As the U.S. electric grid grows more complex, dynamic, and vulnerable to both cyber and physical threats, grid operators urgently need faster and more resilient tools for real-time decision-making.

Researchers at Georgia Tech have developed a deep neural network that can evaluate the security of the power grid orders of magnitude faster than the traditional methods grid operators currently use.

“Currently, operators have to wait for lengthy calculations to obtain an estimate of security,” School of Electrical and Computer Engineering (ECE) Professor Santiago Grijalva said. “Our approach will provide this information very fast, allowing operators to make quick decisions that are more well-informed and robust.”

During development, researchers trained the artificial intelligence (AI) using detailed simulations representing thousands of different operating conditions on large transmission systems. By learning the relationship between grid conditions and system security, the model can later estimate security in real time without performing the lengthy calculations traditionally required.

The tool is the next stage of the GridLogic project, which is supported by the Department of Energy Office of Cybersecurity, Energy Security, and Emergency Response (CESER). The initiative is led by Grijalva, along with Associate Professor Vincent Mooney and Georgia Tech Research Institute Senior Research Scientist Trevor Lewis.

A Data-Driven Breakthrough

Unlike conventional physics-based methods that require detailed information about grid infrastructure and operating conditions, the Georgia Tech model assesses grid security using only real-time demand and generation data.

This approach marks a significant shift from labor-intensive, model-heavy contingency screening toward efficient, data-driven inference, which has demonstrated a dramatic reduction in computational demands while preserving high accuracy, according to Grijalva.

During the training phase, done in collaboration with Marietta Power and OSIsoft, the AI tool analyzed data from a detailed model in a variety of system operating scenarios.

Once trained, the model can evaluate grid conditions in real time, delivering security estimates almost instantly —a capability Grijalva said no comparable system currently provides at the same speed.

Image
GridLogic

Researchers trained an AI model to estimate security in real time without performing the lengthy calculations traditionally required.

For example, if a cyberattacker attempted to remotely disconnect a transmission line, GridLogic could identify the command as a threat to system security and block it before it is executed.

“The implications for grid reliability and security are substantial,” Grijalva said. “Faster security assessments would sharpen operators’ situational awareness, enabling quicker responses to equipment outages, extreme weather, renewable generation swings, and sudden load changes.”

Because the model operates independently of detailed grid topology or parameter data, it could also function as a robust, independent validation layer detecting corrupted measurements or malicious control commands that might otherwise go unnoticed.

Built-in Cyber Defenses 

In a further innovation, the researchers integrated the AI model into a two-party authentication protocol.

 The protocol automatically intercepts control commands that the neural network flags as potentially harmful to grid security, routing them to a human operator or a second automated system for verification.

To harden the protocol against tampering, the team employed hardware-level security using a Physically Unclonable Function, which acts as an uncopiable digital fingerprint, to securely store signing and encryption keys.

By adding authentication and independent security verification, the approach reduces opportunities for attackers to manipulate critical grid operations.

“As cyber threats to critical infrastructure continue to escalate, AI-enabled tools like these could become essential building blocks of next-generation grid resilience,” Mooney said.

With the tool being the first of its kind, more testing is needed before widespread adoption in live systems. The next step is penetration testing by a third party of the GridLogic system, and a demonstration in the field in collaboration with Marietta Power.

Related Content