Wide-area monitoring systems built on phasor measurement units (PMUs) underpin real-time stability assessment in transmission grids, yet their measurement and communication paths present an attack surface that conventional intrusion detection addresses only partially. Three constraints compound the problem: transmission operators are commercially and legally restricted from pooling raw measurements; the public-key cryptography protecting inter-operator links has a finite lifetime against quantum adversaries; and a collaboratively trained detector is itself a target for poisoning. This paper presents an integrated framework addressing all three within a single deployment model. Regional phasor data concentrators train a physics-informed spatio-temporal detector locally and exchange only model updates, which are encapsulated under ML-KEM-768, encrypted with AES-256-GCM, signed with ML-DSA-65, and committed to a SHA3-256 hash-chained consortium ledger under a Byzantine-tolerant validator quorum. The detector couples a graph attention network over the electrical topology with a temporal convolutional network over a two-second window, and is evaluated on 7.6 million synchrophasor measurements from a hardware-in-the-loop testbed on the IEEE 39-bus system. The admittance model underpinning the graph is validated against the solved base case to a mean bus-injection error of 1.24 MW on a 6,088 MW system, against 1,338 MW for a reduced model omitting transformer taps. Against a graph-free ablation the spatial branch reduces false alarms on undisturbed operation from 8.99% to 1.20% while raising macro-F1 from 0.893 to 0.968, and raises no false alarms on benign grid disturbances in held-out evaluation at reduced attack magnitudes. The post-quantum layer adds 109 ms per update, 0.342% of federated round time.
Divyam Tank, Dr. Sushil Kumar Singh· Zenodo (CERN European Organi...· 0 citations
Wide-area monitoring systems built on phasor measurement units (PMUs) underpin real-time stability assessment in transmission grids, yet their measurement and communication paths present an attack surface that conventional intrusion detection addresses only partially. Three constraints compound the problem: transmission operators are commercially and legally restricted from pooling raw measurements; the public-key cryptography protecting inter-operator links has a finite lifetime against quantum adversaries; and a collaboratively trained detector is itself a target for poisoning. This paper presents an integrated framework addressing all three within a single deployment model. Regional phasor data concentrators train a physics-informed spatio-temporal detector locally and exchange only model updates, which are encapsulated under ML-KEM-768, encrypted with AES-256-GCM, signed with ML-DSA-65, and committed to a SHA3-256 hash-chained consortium ledger under a Byzantine-tolerant validator quorum. The detector couples a graph attention network over the electrical topology with a temporal convolutional network over a two-second window, and is evaluated on 7.6 million synchrophasor measurements from a hardware-in-the-loop testbed on the IEEE 39-bus system. The admittance model underpinning the graph is validated against the solved base case to a mean bus-injection error of 1.24 MW on a 6,088 MW system, against 1,338 MW for a reduced model omitting transformer taps. Against a graph-free ablation the spatial branch reduces false alarms on undisturbed operation from 8.99% to 1.20% while raising macro-F1 from 0.893 to 0.968, and raises no false alarms on benign grid disturbances in held-out evaluation at reduced attack magnitudes. The post-quantum layer adds 109 ms per update, 0.342% of federated round time.
Divyam Tank, Dr. Sushil Kumar Singh· Zenodo (CERN European Organi...· 0 citations