phdassistance

Anomaly Detection in SCADA Systems for Power Grid Cyberattack Prevention

Info: Anomaly Detection in SCADA Systems for Power Grid Cyberattack Prevention | phdassistance.com

Published: 5th August 2026 inAnomaly Detection in SCADA Systems for Power Grid Cyberattack Prevention | phdassistance.com

Share this:

Introduction

The increasing digitalisation of contemporary power grids, the prevalence of IIoT systems, and increasing interconnectivity of SCADA systems have made them more vulnerable to advanced cyberattacks on their infrastructure. The rise in the frequency of such attacks has prompted researchers to work on intelligent methods for detecting anomalous activity and reducing false detections to make SCADA systems more resilient to malicious activity. Intelligent techniques utilising advanced machine learning and artificial intelligence are effective means of SCADA Cyberattack Detection through their ability to recognise malicious activities and detect them in real time. These intelligent frameworks, however, face certain difficulties when it comes to their implementation on a large scale and detection of stealthy cyberattacks.

Proposed PhD Title 1: Hybrid Statistical–Deep Learning Framework for Detecting Stealthy False Data Injection Attacks in Modbus/TCP-Based SCADA Systems

Membrane-based techniques have been seen as an energy-efficient means of gas purification compared to existing traditional techniques owing to their capacity to cut costs and minimise the impact on the environment. The emergence of Graphene Membranes has shown much promise in molecular separation owing to the thin structure and high transport capabilities of the technology. According to Vallejos-Burgos et al. (2018), the flexibility of the nanowindow rim, as well as the functional groups, plays a vital role in influencing the molecular permeation that allows better oxygen-nitrogen separation compared to existing membranes. Although such developments have been made, the response of such pores when subjected to dynamic operations is not well studied. Adaptive membrane design capable of controlling molecular transportation through controllable pore chemistry would be of great benefit in the future for Filtration systems.

Problem Statement:
Current methods of detecting SCADA security threats utilise mostly rule-based monitoring, signature-based detection, and traditional network flow analysis, thus being less efficient when dealing with False Data Injection Attacks due to their highly similar characteristics to real communication. The lack of efficiency of SCADA Anomaly Detection causes delays in detecting the attack, increasing the number of false positives, as well as the risks associated with operational security.

Research Gap:

Current works prove the success of cyberattack detection by means of laboratory testbeds. Nevertheless, there is a lack of research involving hybrid statistical learning and deep neural networks in the field of ICS security.

Research Question:

Could a combination of statistical and deep learning models improve Intrusion Detection for stealthy attacks within Modbus/TCP-based SCADA systems?

Outcome:

As a result, anomaly detection becomes ineffective, delays in recognising the cyberattack and compromises the reliability of power grid infrastructures. The proposed research is anticipated to create a more effective detection system for stealthy cyberattacks that will prevent them.

Reference:

Prudhvi, B., Khare, P., & Maddikara Jaya Bharata Reddy. (2025). Real-Time Cyberattack Detection for SCADA in Power System. IET Energy Systems Integration, 7:e70005.

SCADA Intrusion Detection

Proposed PhD Title 2. Explainable Digital Twin and Knowledge Graph Framework for Cyber Threat Intelligence in Legacy IEC 61850 SCADA Networks

With an increase in the use of digital technology in smart grids, there is a need for intelligent cyber-threat monitoring and decision-support systems in SCADA. In the study carried out by Al-Qirim, Majdalawieh, Bani-Hani, and Al Hamadi (2025), the authors presented a Digital Twin and Machine Learning-based Cyber Threat Intelligence architecture, which utilises knowledge graphs for visualisation of false data injection attacks, remote-tripping command injection attacks, and system reconfiguration attacks on SCADA. The study showed successful cyberattack predictions and attack propagation visualisation. It is worth noting that the developed architecture addresses attack visualisation but does not offer explanations that can be used in decision-making by operators in the complex environment of the power grids. Hence, development of an explainable and intelligent Digital Twin framework will enhance Power Grid security.

Problem Statement:
Present Cyber Threat Intelligence Frameworks based on the Digital Twin model are quite successful in attack prediction and visualisation; however, they cannot explain how certain threats have been recognised and their impacts on decision-making processes. Thus, the efficiency of anomaly detection is impaired due to this problem.

Research Gap:
The current threat intelligence approaches based on Digital Twin technologies mainly concentrate on cyber attack prediction and visualisation, whereas they fail to integrate explainable AI mechanisms to enhance Industrial Control System Security. Moreover, they lack transparency in decision-making and help in real-time threat interpretation with operator involvement.

Research question:

Can an explainable Digital Twin – Knowledge Graph architecture help intrusion detection and provide transparent cyber threat intelligence for legacy substations built on the IEC 61850 standard?

Outcome:

It is anticipated that the research would result in the development of an explainable Digital Twin architecture that uses knowledge graphs and artificial intelligence to provide transparent threat intelligence and enhance decision-making processes as part of cyberattack prevention.

Reference:

Al-Qirim, N., Majdalawieh, M., Bani-hani, A., & Al Hamadi, H. (2025). Cyber Threat Intelligence for Smart Grids Using Knowledge Graphs, Digital Twins, and Hybrid Machine Learning in SCADA Networks. International Journal of Engineering Business Management.

Proposed PhD Title 3. Lightweight GWO-Optimized Deep Learning Framework for Real-Time SCADA Anomaly Detection on Edge Devices

Due to the fast development of smart grids, it is becoming increasingly important to ensure real-time cyber situational awareness to maintain a secure and resilient SCADA system. The study by Chen et al. (2026) developed the IGWO-LSTM model for improving the security situation awareness through optimisation of LSTM hyperparameters to provide a more accurate cyberattack prediction. The authors managed to achieve better prediction results and minimise the number of false alarms when compared to traditional methods. Nevertheless, the developed method mainly concentrates on centralised security situation prediction and does not consider lightweight nature and autonomy in decision-making. Thus, development of lightweight deep learning systems with optimisation would help to improve Power Grid Cybersecurity.

Problem Statement:
The existing approaches for situation awareness security have high prediction accuracy; however, they consume large amounts of computational resources as well as are highly centralised, which makes their implementation in SCADA edge devices very difficult. This limitation reduces the efficiency of the anomaly detection system and delays the detection of cyber-attacks.

Research Gap:
The existing GWO-LSTM-based situational awareness models for security purposes have attained high levels of precision; however, they lack lightweight edge intelligence and autonomous reaction mechanisms for improving ICS Security. Moreover, there has not been much work done on developing an architecture that can be deployed in real time.

Research Question:
Will the combination of a lightweight GWO-optimized LSTM model enhance the capability of Intrusion Detection and make it possible for autonomous threat response on edge SCADA systems?

Outcome:
It is anticipated that this research will lead to the development of an effective security framework for edge-computing which incorporates deep learning and autonomous responses to ensure better threat detection and enhance Cyberattack Prevention.

Reference:

Chen, Z., Zheng, H., Gao, L., Qiu, F., Huang, H., & Liu, S. (2026). Design of Security Situation Awareness Power Grid SCADA System Based on Improved GWO-LSTM. Scientific Reports, 16, 8788.

Proposed PhD Title 4. Spatiotemporal Graph Neural Network Framework for Detection and Localisation of Coordinated Cyberattacks in Smart Grid SCADA Systems

The rising complexity of today’s smart grids has necessitated a need for intelligent cyberattack detection mechanisms that can perform analysis of not only the spatial topology but also temporal behaviour of power system measurements. Haghshenas, Hasnat, and Naeini (2022) introduced a TGNN framework that combines message passing based on graphs with gated recurrent units to detect and locate False Data Injection and ramp attacks in smart grids. The model successfully captures the topological connections between components in the smart grid and is able to improve the accuracy of detecting attacks. Nevertheless, the introduced framework is mostly oriented at single- or few-point attacks with little ability to detect multi-point coordinated attacks in the transmission network. Thus, advanced graph learning models are needed to reinforce Power Grid security.

Problem Statement:
Despite the efficacy of the current GNN-based detection models for detecting individual cyber attacks, there are difficulties in detecting coordinated attacks where multiple attacks are launched against different points of the interconnected transmission network. Such difficulties make Anomaly Detection less efficient since the localisation is delayed.

Research Gap:
Temporal graph neural networks have been developed to identify isolated False Data Injections and ramp attacks; however, their capacity to detect and localise coordinated multi-point attacks is relatively poor. This significantly constrains their ability to contribute to industrial control systems security within smart grid settings.

Research Question:

Is there an enhancement to the SCADA Intrusion Detection for coordinated False Data Injection Attacks by applying a Graph Neural Network framework in transmission networks?

Outcome:

This research would be able to deliver an intelligent spatiotemporal graph learning system that can accurately detect and locate cyberattacks, enhance situational awareness of grids, reduce detection time and enhance Cyberattack Prevention.

Reference:

Haghshenas, S. H., Hasnat, M. A., & Naeini, M. (2022). A Temporal Graph Neural Network for Cyber Attack Detection and Localization in Smart Grids. arXiv:2212.03390.

Proposed PhD Title 5. Koopman Learning-Based Explainable Anomaly Detection Framework for Cyberattack Identification under Stressed Power Grid Conditions

The increase in complexity of cyber-physical power systems has been identified as one of the key problems, making it hard to distinguish malicious cyberattacks from natural power grid disruptions. Ghosh, Naqvi, Nandanoori, and Kundu (2024) suggested an innovative approach of using a Koopman Mode decomposition-based method to detect signs of cyberattacks while under a stressed grid environment through time-series measurements. The proposed model can successfully detect signs of cyber attacks by capturing the complex non-linear spatiotemporal signals while also separating the anomalies caused by the attacks from the ordinary disturbances in the grid operation without using any specific attack signatures. Moreover, the proposed technique provides visualisation of the cyber attack signatures which helps in, understanding the impact of such attacks on the power grid operation. However, the proposed technique is mainly focused on detection of attacks along with their visualisation and lacks in providing explanation and actionability of the detected signs of cyber-attacks.

Problem Statement:
The current approaches to detection based on learning in Koopman have proven useful in differentiating between cyberattacks and physical perturbations but are not effective at facilitating explanations of detection results and helping operators make decisions when such events occur in the grid. Thus, the efficiency of Anomaly Detection is greatly reduced.

Research Gap:                   
Currently, Koopman-based machine learning approaches mainly concentrate on signature detection of cyber-attacks in stressed grid scenarios but do not have explainable intelligence and decision-support capability for improving the security of Industrial Control Systems. There is limited work on developing explainable nonlinear anomaly detection in SCADA systems.

Research Question:

Is it possible for a Koopman learning-based approach to explainability to enhance Intrusion Detection in stressed power grid environments?

Outcome:
The result of the proposed research will be to design a Koopman learning explainability approach that can distinguish cyberattacks from natural grid disturbances and increase confidence of operators in analysing cyber threats and Cyberattack Prevention in Power Grids.

Reference:

Ghosh, S., Naqvi, S. A. R., Nandanoori, S. P., & Kundu, S. (2024). Isolating Signatures of Cyberattacks under Stressed Grid Conditions. Pacific Northwest National Laboratory (PNNL), arXiv:2408.02011.

Need assistance finalising your dissertation topic in “Anomaly Detection in SCADA Systems for Power Grid Cyberattack Prevention”? Selecting a strong, researchable topic can be challenging — but you don’t have to do it alone.
Our research consultants can help refine your ideas, identify literature gaps, and guide you toward a topic that aligns with current academic trends and your programme requirements.
Contact us to begin one-on-one topic development and refinement with PhdAssistance.com Research Lab.

Share this:

Cite this work

Study Resources

Free resources to assist you with your university studies!