Sajib Debnath, Md. Rashed Buiya, Ma Bin, Md Robiul Islam, M. Akter, Md Shohail Uddin Sarker, Badruddowza, A. N. Laskar, Santosh Pant
tlooto Summary
These findings demonstrate that integrating energy data into anomaly detection improves detection reliability, interpretability, and resilience, providing a viable pathway toward scalable, edge-deployable cybersecurity for renewable energy infrastructures.
Abstract
Renewable-powered data centers present a dual challenge for anomaly detection in the USA. The inherent variability in solar, wind, battery, and grid signals can mask or imitate cyber intrusions, rendering network-only intrusion detection methods unreliable. This study addresses this challenge by developing a multimodal detection pipeline that combines energy telemetry with network security metrics. Using a dataset of over 2,000 operational records, which has been augmented with synthetic cyber, energy, and coordinated joint adversarial anomalies, we benchmark various classical and deep learning models, including Logistic Regression, Random Forest, XGBoost, LightGBM, and a Multi-Layer Perceptron (MLP). We evaluate these models across network-only, energy-only, and fused feature sets. Our assessment is enriched with causality-driven attribution using Granger causality and feature-level explanations via SHAP. Additionally, we test model resilience against synthetic adaptive perturbations and carry out adversarial retraining. The results indicate that fused models significantly outperform single-domain baselines, achieving higher recall and improved precision-recall performance while reducing false positives in imbalanced settings. The attribution analysis uncovers temporal causal pathways linking energy fluctuations to specific network anomalies, facilitating clear classification of events as energy-driven, cyber-driven, or joint. Adversarial training also notably enhances robustness against subtle evasion attempts. Furthermore, latency benchmarks indicate the practicality of deploying compact models at the edge for near-real-time operation. Overall, these findings demonstrate that integrating energy data into anomaly detection improves detection reliability, interpretability, and resilience, providing a viable pathway toward scalable, edge-deployable cybersecurity for renewable energy infrastructures.
Citation format
DEBNATH, Sajib, et al. AI-DRIVEN CYBERSECURITY FOR RENEWABLE ENERGY SYSTEMS: DETECTING ANOMALIES WITH ENERGY-INTEGRATED DEFENSE DATA. International Journal of Applied Mathematics, 2025.