Skip to content
Review Open access

Towards distinguishing cybersecurity attacks and safety faults in distributed energy resources-rich smart grids: a systematic literature review

Sep 2026 · International Journal of Information Security · Vol 25 · 0 citations · 35 references

Abstract

This study presents a Systematic Literature Review (SLR) of methods and challenges related to distinguishing cybersecurity attacks and safety faults in Distributed Energy Resources (DER)-rich smart grids. The increasing integration of DERs has improved grid flexibility and sustainability, but has also introduced greater operational complexity and expanded the attack surface of smart grid infrastructures. In such environments, cyber-attacks and safety faults may produce similar anomalies, making accurate distinction a critical requirement for resilient and secure grid operation. This review examines the literature on anomaly detection and event classification in DER-rich smart grids towards distinguishing these anomalies and events, with a particular focus on approaches that could support the differentiation of malicious and non-malicious events. It analyzes the main categories of data used in the literature, including sensor data, smart meter data, network traffic, phasor measurements, and weather-related information. It also reviews machine learning and artificial intelligence techniques, including supervised, unsupervised, and deep learning approaches, and discusses their applicability, strengths, and limitations within different contexts. Furthermore, the review synthesizes evaluation practices, operational application domains, and key open challenges, including limited dataset realism, data quality issues, explainability, scalability, and model generalization. Existing testbeds are highlighted as essential for reproducing realistic grid conditions and validating approaches; however, in their current state, no testbed framework is directly applicable to distinguishing cybersecurity attacks from operational safety faults in an informed manner. Importantly, only 6 of the 25 included primary studies explicitly attempt to distinguish cyber-attacks from physical safety faults within a single evaluation setting. The review is therefore explicitly positioned as a combined systematic mapping and gap analysis: rather than demonstrating a mature solution space, it documents how sparsely the central distinction problem is addressed, characterizes the few existing attempts in depth, and derives a research agenda from this gap. Overall, the review identifies major research gaps and outlines directions for developing more safe and secure solutions for DER-rich smart grids.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.