Towards distinguishing cybersecurity attacks and safety faults in distributed energy resources-rich smart grids: a systematic literature review
Abstract
This study presents a Systematic Literature Review (SLR) of methods and challenges related to distinguishing cybersecurity attacks and safety faults in Distributed Energy Resources (DER)-rich smart grids. The increasing integration of DERs has improved grid flexibility and sustainability, but has also introduced greater operational complexity and expanded the attack surface of smart grid infrastructures. In such environments, cyber-attacks and safety faults may produce similar anomalies, making accurate distinction a critical requirement for resilient and secure grid operation. This review examines the literature on anomaly detection and event classification in DER-rich smart grids towards distinguishing these anomalies and events, with a particular focus on approaches that could support the differentiation of malicious and non-malicious events. It analyzes the main categories of data used in the literature, including sensor data, smart meter data, network traffic, phasor measurements, and weather-related information. It also reviews machine learning and artificial intelligence techniques, including supervised, unsupervised, and deep learning approaches, and discusses their applicability, strengths, and limitations within different contexts. Furthermore, the review synthesizes evaluation practices, operational application domains, and key open challenges, including limited dataset realism, data quality issues, explainability, scalability, and model generalization. Existing testbeds are highlighted as essential for reproducing realistic grid conditions and validating approaches; however, in their current state, no testbed framework is directly applicable to distinguishing cybersecurity attacks from operational safety faults in an informed manner. Importantly, only 6 of the 25 included primary studies explicitly attempt to distinguish cyber-attacks from physical safety faults within a single evaluation setting. The review is therefore explicitly positioned as a combined systematic mapping and gap analysis: rather than demonstrating a mature solution space, it documents how sparsely the central distinction problem is addressed, characterizes the few existing attempts in depth, and derives a research agenda from this gap. Overall, the review identifies major research gaps and outlines directions for developing more safe and secure solutions for DER-rich smart grids.