Enhancing Smart Grid Cybersecurity Through Intelligent, Data-Driven Monitoring

As Europe accelerates its transition towards smarter, more connected energy systems, cybersecurity is becoming a central concern for society, industry and policymakers alike.

Smart grids – digital electricity networks that balance generation, distribution and consumption in real time, form part of our most critical infrastructure. Any disruption to these systems, whether accidental or malicious, could have serious economic and social consequences.

A newly MARE journal publication, explores how advanced data-driven techniques can significantly improve the cybersecurity of smart grids. The research addresses a growing challenge in modern energy systems – that of “Detecting cyber threats that originate within the network itself, rather than only at its perimeter”.

Today’s smart grids rely heavily on Industrial Control Systems (ICS), which coordinate substations, control centres and intelligent electronic devices. These systems were originally designed for reliability and efficiency, often with limited built-in security. While traditional cybersecurity solutions such as firewalls and intrusion detection systems remain important, they are typically positioned at the edges of a network. As a result, they can struggle to identify threats caused by compromised devices that are already operating inside the grid.

The journal publication introduces an alternative approach that focuses on continuous monitoring of communication behaviour within the grid. Instead of inspecting the full content of every message, the system observes patterns in how devices normally communicate with one another. By learning what “normal” behaviour looks like, it becomes possible to quickly identify unusual or suspicious activity.

This approach is particularly valuable in complex, high-traffic environments such as smart grids, where enormous volumes of data are exchanged every second. Monitoring communication patterns allows security mechanisms to operate efficiently, without interfering with the real-time operation of the energy network.

A key strength of the proposed method is its ability to detect unknown or unexpected threats. Rather than being trained to recognise only specific attack signatures, the system identifies anomalies – behaviours that deviate from normal operation. This means it can detect a wide range of issues, from equipment malfunctions and misconfigurations to cyberattacks such as denial-of-service attempts or unauthorised control actions.

The researchers validated their approach using real-world datasets based on two widely used international smart grid communication standards. Across multiple scenarios, the system demonstrated a very high ability to detect abnormal activity, showing that a single, adaptable monitoring solution can work effectively across different technologies and operational environments.

For the MARE project, these results are particularly significant. MARE aims to develop a programmable, modular, and disaggregated security plane for future digital ecosystems, including those enabled by 6G technologies. Energy networks are a key examples of systems that require flexible and intelligent security mechanisms, capable of adapting to new threats without constant manual reconfiguration.

The work highlighted in this paper aligns closely with MARE’s vision of increasing visibility, resilience and trust in critical infrastructures. By enhancing awareness of what is happening inside a network – and not just at its borders, such approaches enable faster detection, better response, and ultimately more reliable services for citizens.

Beyond the energy sector, the findings are relevant to many other domains that depend on industrial control systems, including transport, manufacturing, water management and smart cities. As digitalisation continues to blur the boundaries between operational technology and IT networks, intelligent monitoring solutions will play a crucial role in safeguarding essential services.

In an era where cyber threats are growing in sophistication and frequency, this research demonstrates how machine-learning-based monitoring can strengthen the foundations of secure, resilient infrastructure. By supporting innovations like this, the MARE project contributes to a safer digital future where critical systems can evolve with confidence and trust.

Publication Details

Machine Learning-Enriched Cybersecurity in Smart Grids

Authors: G. Amritha, Manjula G. Nair, Fabrizio Granelli

MARE Partner: Consorzio Nazionale Interuniversitario per le Telecomunicazioni (CNIT)

Journal: IEEE Access, June 2025. Journal website.

Abstract: A smart grid is one of the critical infrastructures that, when targeted by a cyber-attack, could have disastrous effects on the economy and disrupt the lives of the population. Firewalls and Intrusion detection systems, the conventional protective schemes and cyber threat mitigation systems in smart grids, are usually deployed to analyse incoming and outgoing traffic. Although these approaches are capable of detecting external attacks, they are ill-suited to detect threats originating from a compromised device [internal to the grid] infected with malware or malicious software. To mitigate such threats, Industrial Control System (ICS) traffic monitoring and the implementation of anomaly detection systems based on the traffic data are crucial. We propose an anomaly detection system for monitoring the ICS traffic data based on IP traffic flows extended with application layer data obtained from the ICS packet headers. Unlike conventional methods that utilise statistical properties of the communication profiles of the dataflows to identify unknown threats, this study proposes an Autoencoder-based threat detection model. The dataset considered for the scope of this research was generated for the project at Brno University of Technology: Security monitoring of Industrial Control System (ICS) communication in the smart grid (Bonnet), 2019–2022, funded by the Ministry of Interior of the Czech Republic. The proposed solution was validated on diverse cyber-attack datasets, in conformance with IEC (International Electrotechnical Commission) 104 and IEC 61850 standards. The proposed model is efficient with an average anomaly detection rate of 99% in IEC 104 dataset and 97% in IEC 61850 dataset.