Skip to main content
QUICK REVIEW

[Paper Review] Secure Integration of Electric Vehicles with the Power Grid

Chaitra Niddodi, S. Lin|arXiv (Cornell University)|May 3, 2019
Electric Vehicles and Infrastructure18 references5 citations
TL;DR

This paper proposes a novel Cyber-Physical Anomaly Detection Engine that secures Vehicle-to-Grid (V2G) systems by simultaneously monitoring V2G communication protocols, power measurements from physical sensors, and timing constraints of protocol messages. The engine detects anomalies in real time—within 0.165 seconds per packet—ensuring the aggregator, a critical grid component, remains resilient against cyber-physical attacks.

ABSTRACT

This paper focuses on the secure integration of distributed energy resources (DERs), especially pluggable electric vehicles (EVs), with the power grid. We consider the vehicle-to-grid (V2G) system where EVs are connected to the power grid through an aggregator. In this paper, we propose a novel Cyber-Physical Anomaly Detection Engine that monitors system behavior and detects anomalies almost instantaneously. This detection engine ensures that the critical power grid component (viz.,aggregator)remains secure by monitoring(a)cyber messages for various state changes and data constraints along with (b)power data on the V2G cyber network using power measurements from sensors on the physical/power distribution network. Since the V2G system is time-sensitive, the anomaly detection engine also monitors the timing requirements of the protocol messages to enhance the safety of the aggregator. To the best of our knowledge, this is the first piece of work that combines(a)the EV charging/discharging protocols, the(b)cyber network and(c)power measurements from physical network to detect intrusions in the EV to power grid system.

Motivation & Objective

  • Address the growing security risks in power grids due to increased integration of distributed energy resources (DERs), especially pluggable electric vehicles (EVs).
  • Identify the aggregator as a high-value target in V2G systems due to its central role in managing multiple EVs and direct grid connection.
  • Develop a detection system capable of identifying malicious activity at the aggregator level with minimal latency and high accuracy.
  • Integrate cyber and physical system data—communication protocols, power measurements, and message timing—to enhance intrusion detection beyond traditional cyber-only approaches.

Proposed method

  • Define correct command sequences in the SAE J3068 V2G communication protocol to construct a state machine for the aggregator.
  • Implement a real-time anomaly detection engine that monitors cyber messages for protocol compliance, data constraints, and timing violations (e.g., message frequency and subscription periods).
  • Incorporate physical power measurements from sensors on the distribution network to validate cyber behavior and detect inconsistencies.
  • Use a hybrid detection model combining specification-based rules (for protocol compliance) and sensor-based validation (for physical plausibility).
  • Leverage time-sensitive monitoring of periodic messages to detect protocol-level anomalies such as message delays or spoofing.
  • Design a lightweight, real-time prototype suitable for deployment in operational V2G environments with minimal computational overhead.

Experimental results

Research questions

  • RQ1How can anomalies in V2G communication protocols be detected in real time while ensuring system safety and security?
  • RQ2To what extent can physical power measurements improve the accuracy of cyber anomaly detection in V2G systems?
  • RQ3Can timing constraints of V2G protocol messages be used as a reliable indicator of malicious behavior?
  • RQ4How effective is a combined cyber-physical approach in detecting attacks targeting the aggregator compared to purely cyber-based detection?
  • RQ5What is the achievable detection latency when monitoring both cyber and physical system states in a V2G environment?

Key findings

  • The proposed Cyber-Physical Anomaly Detection Engine achieves sub-0.2 second detection latency, with worst-case inspection time of 0.165 seconds per packet.
  • The integration of physical power measurements with cyber protocol monitoring significantly improves anomaly detection accuracy by validating behavioral consistency.
  • Timing constraints such as message frequency and subscription periods are effective in identifying protocol-level anomalies, including message spoofing or replay attacks.
  • The detection engine successfully differentiates between legitimate system behavior and malicious activity by cross-validating cyber messages with physical power data.
  • The prototype demonstrates feasibility for real-time deployment, with a simple model enabling fast and accurate detection suitable for operational V2G systems.
  • To the best of the authors’ knowledge, this is the first system to jointly monitor V2G communication standards, cyber messages, and physical power measurements for intrusion detection in V2G systems.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.