{"title":"MaDIoT 3.0:对电力系统中分布式能源和需求的攻击评估","authors":"Néstor Rodríguez-Pérez;Javier Matanza;Lukas Sigrist;José Rueda Torres;Gregorio López","doi":"10.1109/OAJPE.2025.3595631","DOIUrl":null,"url":null,"abstract":"The increasing penetration of Distributed Energy Resources (DER) expands the cyberattack surface of power systems. This paper analyses, using PowerFactory, the impact and success of MaDIoT 3.0 attacks in the PST-16 model, a simplified model of the European system. MaDIoT 3.0 attacks are a novel type of attack that manage to compromise both high-wattage IoT demand devices and DER devices at the same time. The results indicate that the inclusion of distributed solar PV generation in the PST-16 system reduces the success ratio and impact of load-altering MaDIoT attacks when compared to the same system without DER, mainly due to an increment of the initial voltages. For MaDIoT 3.0 attacks, the demand had a more significant influence on the attack’s success than DER in the PST-16 system. Distributing the attacked demand across more buses or targeting the demand from other areas would decrease the success ratio of the attack. Therefore, the local scalability and replicability of vulnerable high-wattage demand devices in the analysed system become more critical than their distributed deployment in larger areas.","PeriodicalId":56187,"journal":{"name":"IEEE Open Access Journal of Power and Energy","volume":"12 ","pages":"552-563"},"PeriodicalIF":3.2000,"publicationDate":"2025-08-04","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=11112612","citationCount":"0","resultStr":"{\"title\":\"MaDIoT 3.0: Assessment of Attacks to Distributed Energy Resources and Demand in a Power System\",\"authors\":\"Néstor Rodríguez-Pérez;Javier Matanza;Lukas Sigrist;José Rueda Torres;Gregorio López\",\"doi\":\"10.1109/OAJPE.2025.3595631\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The increasing penetration of Distributed Energy Resources (DER) expands the cyberattack surface of power systems. This paper analyses, using PowerFactory, the impact and success of MaDIoT 3.0 attacks in the PST-16 model, a simplified model of the European system. MaDIoT 3.0 attacks are a novel type of attack that manage to compromise both high-wattage IoT demand devices and DER devices at the same time. The results indicate that the inclusion of distributed solar PV generation in the PST-16 system reduces the success ratio and impact of load-altering MaDIoT attacks when compared to the same system without DER, mainly due to an increment of the initial voltages. For MaDIoT 3.0 attacks, the demand had a more significant influence on the attack’s success than DER in the PST-16 system. Distributing the attacked demand across more buses or targeting the demand from other areas would decrease the success ratio of the attack. Therefore, the local scalability and replicability of vulnerable high-wattage demand devices in the analysed system become more critical than their distributed deployment in larger areas.\",\"PeriodicalId\":56187,\"journal\":{\"name\":\"IEEE Open Access Journal of Power and Energy\",\"volume\":\"12 \",\"pages\":\"552-563\"},\"PeriodicalIF\":3.2000,\"publicationDate\":\"2025-08-04\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=11112612\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"IEEE Open Access Journal of Power and Energy\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://ieeexplore.ieee.org/document/11112612/\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q3\",\"JCRName\":\"ENERGY & FUELS\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"IEEE Open Access Journal of Power and Energy","FirstCategoryId":"1085","ListUrlMain":"https://ieeexplore.ieee.org/document/11112612/","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q3","JCRName":"ENERGY & FUELS","Score":null,"Total":0}
MaDIoT 3.0: Assessment of Attacks to Distributed Energy Resources and Demand in a Power System
The increasing penetration of Distributed Energy Resources (DER) expands the cyberattack surface of power systems. This paper analyses, using PowerFactory, the impact and success of MaDIoT 3.0 attacks in the PST-16 model, a simplified model of the European system. MaDIoT 3.0 attacks are a novel type of attack that manage to compromise both high-wattage IoT demand devices and DER devices at the same time. The results indicate that the inclusion of distributed solar PV generation in the PST-16 system reduces the success ratio and impact of load-altering MaDIoT attacks when compared to the same system without DER, mainly due to an increment of the initial voltages. For MaDIoT 3.0 attacks, the demand had a more significant influence on the attack’s success than DER in the PST-16 system. Distributing the attacked demand across more buses or targeting the demand from other areas would decrease the success ratio of the attack. Therefore, the local scalability and replicability of vulnerable high-wattage demand devices in the analysed system become more critical than their distributed deployment in larger areas.