S. Jang, T. Zhao, and M. Yue
Brookhaven National Laboratory, New York, United States
Keywords: cybersecurity, smart grid, artificial intelligence, LLM
The increasing digitalization of modern power grids expands the cyberattack surface and creates opportunities for coordinated attacks spanning both cyber and physical domains. In this poster, we propose a multi-stage, multi-modal cyberattack detection and root-cause analysis framework that integrates power system measurements, network traffic data, and Large Language Models (LLMs). The first stage employs lightweight, modality-specific anomaly detectors to enable real-time detection. For physical grid measurements, we introduce a deep learning-based anomaly detector that leverages Pearson correlation matrix as a feature, enabling efficient anomaly detection using a lightweight neural network architecture. To identify sophisticated cross-domain attacks that may evade unimodal detection, we introduce a second-stage LLM-based detection and reasoning layer. We develop modality-specific encoders for both physical grid and network traffic data using BERT and Transformer architectures. These encoders generate embeddings that are trained to align with the semantic embedding space of LLMs, enabling joint reasoning across multi-modal data. The aligned embeddings, together with textual prompts, are provided to an LLM to perform advanced multi-modal anomaly detection and root-cause analysis. By combining the first-layer detection with LLM-driven cross-modal reasoning, the proposed framework aims to improve the detection and interpretation of coordinated cyber-physical attacks against smart grid.