Engineering · Research topic

Open research questions in Smart Grid Security and Resilience

42 unresolved questions extracted from the limitations and future-work sections of 230 Smart Grid Security and Resilience papers in our library. Each links back to the study that raised it.

What the literature leaves open

  • This paper has presented EAGF, an engineering-operational framework that jointly formalizes, measures, and governs all four EU AI Act governance pillars, trans- parency (C), fairness (RP /F P RP ), privacy (P ), and accountability (A) within a unified adversarial-aware AI lifecycle for cybersecurity in 5G-connected RE-IoT and industrial IIoT systems. Three concrete engineering artefacts are provided: (i) four independently computable pillar metrics with formal definitions grounded in the EU AI Act, NIST AI RMF, GDPR, NIS2, IEC 62351, and ISO/IEC 42001:2023; (ii) a composite Trust Index serving as a single deployment-readiness KPI; and (iii) a Pareto-guided multi-objective training procedure with domain-adaptive fair- ness loss, jointly optimizing fairness and privacy via gradient descent with structural transparency control, and post-hoc accountability scoring. Empirical validation across two complementary domains confirms four principal findings. First, EAGF achieves a +38.97% relative TI improvement in the biometric domain (0.565 → 0.785) over ten seeds, at an accuracy cost of 6.0 percentage points, a non-negligible but operationally justified governance trade-off; accountability infras- tructure accounts for 77.6% of this gain. Second, in the real-world Edge-IIoTset IIoT benchmark, EAGF achieves a +69.3% TI improvement (0.358 → 0.606) over five seeds, with a +56.4% FPR parity gain across protocol classes via direct FPR-gap regularization, preserved differential privacy at ϵeff = 2.4, and only +0.2 ms forward- pass inference overhead; accountability infrastructure accounts for 67.2% of this gain. Third, model-level governance alone (T I = 0.612/0.425) falls substantially short of full joint governance (T I = 0.785/0.606), establishing that accountability infrastructure is necessary rather than optional. Fourth, the privacy–fairness coupling is modality- dependent: stronger in the image domain and substantially weaker in the tabular IIoT domain, with implications for the architecture of governance-aware training in different application areas.

    EAGF: a four-pillar ethical AI governance framework for trustworthy cybersecurity in 5G renewable energy IoT systems · 2026 · DOI
  • Priority future work includes: (a) direct stakeholder trust-perception studies correlat- ing TI with operator confidence ratings; (b) physical RE-IoT testbed validation on BATADAL or SWaT; (c) substitution of EFR with institutionally certified biomet- ric benchmarks; (d) formal AHP expert elicitation for domain-specific pillar weights; (e) extension of the external baseline comparison of Table 15 to the biometric domain and to prior two-pillar frameworks [15, 18, 49]; (f) fully factorial ablation isolating individual pillar contributions; (g) three-dimensional Pareto exploration varying the DP budget ϵ as a third grid dimension; (h) cross-validation Pareto selection to reduce the validation-to-test generalization gap; (i) evaluation of stronger MIA attackers (likelihood-ratio, shadow-model) to properly characterize DP empirical benefit in the tabular domain; (j) automated Pareto-front exploration via neural-architecture search to reduce the 25-run training overhead; (k) federated EAGF variants for privacy- preserving cross-operator cooperation in distributed energy systems; (l) extension of the accountability score to causal responsibility assignment under the EU AI Liabil- ity Directive; and (m) characterization of the cross-pillar couplings required to add adversarial robustness as a fifth pillar (Section 6.9).

    EAGF: a four-pillar ethical AI governance framework for trustworthy cybersecurity in 5G renewable energy IoT systems · 2026 · DOI
  • We introduced a hypergraph spatio-temporal graph atten- tion network HSTGAT-IDS, which is a hypergraph model of smart grid cyber attack detection with zero-day attacks. The representation of the cyber-physical grid as a dynamical hypergraph, multi-head attention on hyperedge neighbor- hoods and time series, and the training of an encoder-decoder reconstruction model with only normal data allow HSTGAT- IDS to overcome three important gaps in the literature: the higher-order structural modeling, time-based reasoning on dynamically evolving threats, and zero-day generalization with signature-free representations. On MSU-ORNL and IEEE 14/118/300-bus systems, experimental results are state of the art with 99.31% binary SN Computer ScienceSN Computer Science (2026) 7:562 Page 9 of 12 562 Fig. 6 Anomaly score analysis. a Global anomaly score S(t) over time with annotated attack zones (FDIA, LAA, zero-day APT) and thresh- old τ. b Per-node anomaly score heatmap on IEEE 14-bus during FDIA on buses 3–5. c Multi-head temporal attention weights for FDIA vs. APT attacks revealing distinct temporal focal patterns. d Precision- recall curves (AP = 0.997 for HSTGAT-IDS) SN Computer ScienceSN Computer Science (2026) 7:562 562 Page 10 of 12 Fig. 4 Simulation results I. a Binary classification accuracy comparison across all 10 methods on MSU-ORNL. b F1-score comparison. c FDIA detection accuracy vs. attack intensity on IEEE 118-bus. d FDIA detection accuracy on IEEE 14/118/300-bus systems at 10% attack intensity SN Computer ScienceSN Computer Science (2026) 7:562 Page 11 of 12 562 Fig. 5 Simulation results II. a Zero-day detection rate for LAA and APT by method. b Ablation study: F1-score and zero-day DR per added com- ponent. c ROC curves showing AUC = 0.9998 for HSTGAT-IDS. d Training convergence on MSU-ORNL binary task Fig. 7 Multi-class performance and scalability. a Per-class F1-score comparison between GraphKAN and HSTGAT-IDS across eight attack categories. b Detection accuracy and inference latency vs. grid size (14 to 500 buses). c False alarm rate vs. attack intensity on IEEE 118-bus. d Normalized confusion matrix for 6-class detection on IEEE 118-bus SN Computer ScienceSN Computer Science (2026) 7:562 562 Page 12 of 12 Author Contributions M. Sudha: Conceptualization, Methodology, Software, Formal analysis, Investigation, Writing—original draft, Writing—review & editing, Supervision, Project administration. R. Reenadevi: Methodology, Validation, Investigation, Data curation, Writing—review & editing. R. Jennie Bharathi: Formal analysis, Vali- dation, Visualization, Writing—review & editing. Ardly Melba Reena B: Software, Data curation, Investigation, Writing—review & editing. Akila Venkatraman: Validation, Resources, Writing—review & edit- ing, Supervision. Ayavarapu Karthik: Formal analysis, Investigation, Writing—review & editing, Supervision. All authors have read and approved the final version of the manuscript. Funding Authors declare that they have not received any funding for the present work. Data Availability All data supporting the results reported in the article are present in the paper.

    A Hypergraph Spatio-Temporal Graph Attention Network for Zero-Day Attack Detection in Smart Grids · 2026 · DOI
  • Although the method proposed in this article demonstrates superior performance in simu- lated environments, there are still certain lim- itations in terms of model assumptions, data dependencies, and experimental environments. First, the study models the attacker's later- al movement as a series of discrete actions. It assumes that, once an attack is successful, the attacker gains complete control of the node. However, in real advanced persistent threat scenarios, attack behavior has a high degree of temporal persistence, concealment, and un- certainty. The current SAG model has not fully captured these complex dynamic features. Sec- ond, the risk quantification module highly relies on the logical structure definition of FTA and CVSS vulnerability rating data. The construc- tion of FTA usually requires profound domain expert knowledge, which can easily introduce subjective bias. However, the universal CVSS score may not fully reflect the actual difficulty of utilization in specific industrial scenarios. In addition, due to legal and ethical considerations for the safe operation of critical infrastructure, research cannot conduct penetration testing on real operating subway lines. The experimental results are entirely based on a simulation en- vironment that complies with the IEEE 1474.1 standard. The robustness of the algorithm in practical deployment is affected by the diffi- culty of fully reproducing the hardware finger- prints, network jitter, and complex background traffic noise of real physical devices. In future research, the plan is to utilize the fea- ture extraction capabilities of graph convolu- tional networks or graph attention networks to achieve end-to-end learning and generalization of large-scale, dynamically changing network topologies. Meanwhile, this study considers expanding from a single-attack perspective to a dual-layer game model of attack and defense. It investigates how defense agents can dynami- A SARSA-Driven Cyber-Physical Risk Modeling Framework for Cloud-Based CBTC Systems 62 cally generate optimal network isolation or traf- fic cleaning strategies based on predicted attack paths. Finally, it considers combining threat in- telligence with honeypot log data to dynamical- ly adjust CVSS scores and FTA weights, thereby reducing reliance on static expert knowledge.

    A SARSA-Driven Cyber-Physical Risk Modeling Framework for Cloud-Based CBTC Systems · 2026 · DOI
  • increased storage scalability delays, and technologies. monitoring continuous systems, remains which such and can a https://thesesjournal.com | Watar & Ahmed, 2026 | Page 549 SPECTRUM OF ENGINEERING SCIENCES ISSN (E) 3007-3138 (P) 3007-312X geographically distributed energy supply chains therefore remains a difficult task for large-scale deployments.

    ADVANCING AI-DRIVEN SECURITY ARCHITECTURE FOR AUTOMATED ENERGY SUPPLY CHAINS IN THE UNITED STATES · 2026 · DOI
  • Future work should address the specific challenges of quantum-safe cryptography migration, AI-driven anomaly detection in process environments, and the development of OT-compatible zero-trust architectures. , “Digital twins for cyber-physical systems security: State of the art and open challenges,” IEEE Transactions on Industrial Informatics, vol.

    A Comparative Review of Cybersecurity Frameworks for Industrial Control and SCADA Systems · 2026 · DOI
  • Future research will focus on expanding the dataset to include more diverse attack scenarios, integrating attention mechanisms to enhance feature representation, and exploring lightweight yet robust model architectures for deployment in resource-constrained industrial environments.

    <p>Performance Enhancement of Supervisory Control and Data Acquisition (SCADA) IEC 60870-5-104 Intrusion Detection Using Sequence-Aware and Hybrid Deep Learning Models: A Comparative Evaluation</p> · 2026 · DOI
  • Future research will focus on bridging gaps in the Water and Transport sectors through the development of interpretable AI models suitable for resource-constrained edge devices, thereby strengthening the resilience of distributed Industrial IoT and cyber- physical systems against adversarial AI threats.

    AI-driven cybersecurity in critical infrastructure: A bibliometric analysis (2015–2025) · 2026 · DOI
  • By bridging operational semantics with adversarial threat models, BRIDG-ICS vulnerability knowledge, addresses a key limitation of earlier industrial security knowledge graphs, which often lacked the cross-domain alignment necessary for consistent, context-aware, and intelligence-driven threat analytics.

    Bridg-ics: AI-grounded knowledge graphs for intelligent threat analytics in industry 5.0 cyber-physical systems · 2026 · DOI
  • Despite the advantages of the proposed BRIDG-ICS framework, several limitations should be acknowledged. First, the current evaluation relies on synthetic logs and controlled environments, which may not fully capture the variability and scale of real industrial deployments. While useful for experimentation, real-world infrastructures may exhibit greater complexity and unpredictable behaviour. Second, communication relationships are modeled as undirected edges. Although this enables exploration of potential propagation paths, it may overestimate reverse traversal that would typically be restricted by protocol roles or access controls in operational ICS environments. into generic Entity and DetailAct classes to simplify graph construction. While this supports efficient integration and reasoning, it may limit the semantic granularity of cyber–physical relationships. Third, extracted artefacts are consolidated Finally, the CWE prediction process introduces a degree of uncertainty into the knowledge graph. Since predicted CWEs link vulnerabilities with CAPEC patterns and ATT&CK techniques, misclassifications may propagate and result in incorrect or incomplete attack paths. Although partially mitigated by multi- source integration and graph-based reasoning, the knowledge graph still provides a structured foundation for analysis, offering more reliable grounding than unstructured approaches in LLM-based analysis.

    Bridg-ics: AI-grounded knowledge graphs for intelligent threat analytics in industry 5.0 cyber-physical systems · 2026 · DOI
  • The analytics presented in this paper explore the fundamental problems of the proposed DER cyber security system. Advanced mathematics and statistical sciences can aid in solving these problems in the future because Cyber security has become increasingly complex, as it deals with integrated information systems and networks Accessing real-world data are necessary to understand these large and complex systems The proposed methodologies are based on validating experiments and models with mathematical ideas, focusing on the most widely used mathematical theories. These models can simulate the different properties of the systems studied by comparing them to the behavior of the existing system. However, the chosen mathematical approach is heuristic and depends on the researcher's background.

    Cyber security for smart inverters and distributed energy resources (DER) · 2026 · DOI
  • The framework needs to be validated through its practical application and implementation, and as new uses of AI and agent technology continue to emerge, and novel quantum threats become evident, the framework must be continuously reassessed and adapted.

    A Framework for Securing Agentic AI Workflows and Quantum-Resistant Communication in U.S. Critical Infrastructure Networks · 2026 · DOI
  • The Digital Twin (PINN) model integrates physics-informed neural networks but does not discuss the generalizability of the physics constraints across different fuel station designs, tank geometries, or climate conditions.

    Cyber-Resilient IoT-Driven SCADA Integration for Secure and Intelligent Fuel Station Monitoring and Predictive Analysis · 2026 · DOI
  • Cybersecurity evaluation employed synthetic intrusions using Metasploit and Scapy; testing against advanced persistent threats (APTs) and zero-day exploits specific to SCADA/ICS environments remains unexplored.

    Cyber-Resilient IoT-Driven SCADA Integration for Secure and Intelligent Fuel Station Monitoring and Predictive Analysis · 2026 · DOI
  • Even with these promising findings, there are still a number of areas that may be investigated further. First, the hybrid ensemble framework's practical applicability and scalability would be further demonstrated by real-time deployment and validation in live or hardware-in-the- loop smart grid systems. Second, in order to dynamically modify model contributions in response to changing assault patterns, future research may investigate adaptive ensemble weighting techniques and online learning methods. Additionally, by offering interpretable insights into detection choices, using explainable AI (XAI) approaches might increase model transparency and operator confidence. REFERENCES Abbassy, M. M., Satya Sai Kumar, A., Ead, W. M., Mohamed Aboalndr, A. A., Alsheref, F. K., Abdalla, M., & Shivani, A. (2025). Hybrid deep learning framework for detection of anomalies in cyber-physical systems. International Journal of Information Technology. https://doi.org/10.1007/s41870-025-02633-7 Alguliyev, R., Imamverdiyev, Y., & Sukhostat, L. (2021). Hybrid DeepGCL model for cyber-attacks detection on cyber-physical systems. Neural Computing and Applications, 33(16), 10211–10226. https://doi.org/10.1007/s00521-021-05785-2 Alomari, M. A., Al-Andoli, M. N., Ghaleb, M., Thabit, R., Alkawsi, G., Alsayaydeh, J. A. J., & Gaid, A. S. (2025). Security of smart grid: cybersecurity issues, potential cyberattacks, major incidents, and future directions. Energies, 18(1), 141. Arumugam, S. R., Paul, P. M., Issac, B. J. J., & Ananth, J. P. (2024). Hybrid deep architecture for intrusion detection in cyber- physical system: An optimization-based approach. International Journal of Adaptive Control and Signal Processing, 38(9), 3016–3039. https://doi.org/10.1002/acs.3855 Bhuiyan, T. (2025). AI in Smart Grid Cybersecurity: A Systematic Review of Machine Learning and Deep Learning Approaches against False Data Injection and Other Emerging Attacks. Journal of Computer Science and Technology Studies, 7(8), 1207- 1295. Bitirgen, K., & Filik, Ü. B. (2023). A hybrid deep learning model for discrimination of physical disturbance and cyber-attack Infrastructure Protection, 40, Article 100582.

    Hybrid ANN–DNN–LSTM Deep Learning Architecture for Botnet Detection in Smart Grid Cyber-Physical Systems · 2026 · DOI
  • While sparsity-based batch approaches, which collect multiple measurements and run offline, are relatively mature, online secure state estimation, for real-time state/attack recovery, is still an open problem.

    Online sparse observers for cyber-physical systems under sensor bias · 2026
  • Abstract Cyber range exercises are an effective instrument for cybersecurity training and evaluation, yet exercises specifically tailored to hydroelectric power plants remain scarce.

    Design and evaluation of a cyber range exercise for hydroelectric power plants · 2026 · DOI
  • The paper evaluates leaks at 2 L/min and meter tampering scenarios but does not address detection of slower leaks, sophisticated fraud techniques, or combined attack vectors.

    Cyber-Resilient IoT-Driven SCADA Integration for Secure and Intelligent Fuel Station Monitoring and Predictive Analysis · 2026 · DOI
  • The testbed prototype was deployed on a medium-scale fuel station with four tanks and six dispensers; evaluation on larger, multi-site fuel station networks with heterogeneous equipment is needed.

    Cyber-Resilient IoT-Driven SCADA Integration for Secure and Intelligent Fuel Station Monitoring and Predictive Analysis · 2026 · DOI
  • CPU growth becomes nonlinear beyond 5,000 sensors due to QoS 2 acknowledgement overheads, validating the need for distributed broker clustering.

    Cyber-Resilient IoT-Driven SCADA Integration for Secure and Intelligent Fuel Station Monitoring and Predictive Analysis · 2026 · DOI
  • The paper lacks analysis of resilience to advanced adversarial attacks such as Byzantine attacks, distributed denial-of-service attacks, or zero-day exploits.

    Artificial intelligence driven approach for securing backup data and enhancing cyber resilience in sustainable smart infrastructure · 2026 · DOI
  • We conclude the paper by discussing today's open issues, which need to be addressed to cope with the increasing complexity of ICS security.

    Industrial cyber-physical systems protection: A methodological review · 2023 · DOI
  • As cyber security expertise and exercise are lacking and integration into European natural gas and electricity systems is not completed, blackout scenario in the Baltic States remains possible.

    Mitigating Risks of Hybrid War: Search for an Effective Energy Strategyin The Baltic States · 2018 · DOI

Most-cited papers in Smart Grid Security and Resilience

Most recent work

Find a gap in your own Smart Grid Security and Resilience sub-topic

This page shows what the Smart Grid Security and Resilience literature already flags as unresolved. To narrow it to your specific question, run the guided finder — it searches the gap library on demand and checks candidates against 250M+ OpenAlex works.

Open the Research Gap Finder →

Related topics in Engineering

42 open questions have been extracted from the limitations and future-work passages of 230 Smart Grid Security and Resilience papers in our library. Each one below links back to the study that raised it, so you can read the original claim in context.

Tools for your next paper

Compare the categoryHonest roundups of the AI research tools, ours listed alongside the alternatives.

Command palette

Jump anywhere, run any action.