Sandia Lab News

Fighting AI with AI to keep the lights on


Sandia research is reshaping how we protect the electrical grid

<strong>LOCALIZATION</strong> — Georgios said locating a threat is key to shutting down a potential cyber-physical attack to the grid.
LOCALIZATION — Georgios said locating a threat is key to shutting down a potential cyber-physical attack to the grid.

A process key to protecting our nation’s electrical grid is getting smarter and faster thanks to a team led by Sandia artificial intelligence researcher Georgios Fragkos.

Georgios, Sidney Wright and Birk Jones with the Communications and Cybersecurity for the Energy Edge team, known as C2E2, have been working on a system that uses generative AI and large language models to both detect and locate cyber-physical threats to the electrical grid.

“An adversary’s attack on the power grid, resulting in its shutdown, would have profound and far-reaching consequences,” said Alex Haddad, manager of Sandia’s Grid Security and Communication department. “Electricity is the foundation of modern life — it powers everything from delivering water to our homes, operating our communication networks and gas station pumps. Without electricity, gas stations cannot supply fuel, halting transportation and disrupting the delivery of essential goods like food, which also cannot be properly refrigerated. Critical services such as hospitals, police and fire departments would be severely impacted, triggering cascading failures across society. The Department of Homeland Security identifies 16 critical infrastructure sectors, none of which could function without reliable electrical power. The presence of adversaries within these systems, manipulating or disrupting operations, poses an immense risk to national security and could lead to widespread chaos.”

And C2E2 is just the tip of the iceberg in this space.

“This project is one part of our Electric Grid Security portfolio, in which we’re harnessing Sandia’s deep capabilities in threat detection, risk assessment and the development of new AI tools to ensure our grid is resilient to all forms of malicious and natural threats. This unique combination of capabilities helps us serve the U.S. Departments of Energy, Homeland Security and War in protecting and preserving our military and civilian infrastructures,” Sandia senior manager Charles Hanley said.

Location, location, location

Sandia’s work in grid security dates back decades but what it takes to keep the grid safe is quickly changing and AI is helping the Labs, as Alex puts it, “get as far left of zero as we can.”

Georgios has been a leader in this space.

“He’s the AI expert,” Birk said.

Georgios previously helped with the development of an AI algorithm — inspired by how the human brain works — to identify problems on the electrical grid caused by physical damage, such as a generator outage; cyberattacks, such as a hacking attempt; or even both happening simultaneously.

But those neural networks don’t have the ability to identify threat locations, and as Sidney adds, “Localizing a threat is key to shutting it down.”

“The energy grid is becoming more interconnected; more management commands are sent to devices that are tied to cloud connections. These connections create a larger attack surface and expose the devices to more potential attacks than ever before. With more cyberattacks we need better capabilities to detect when things are going wrong and understand where those attacks are happening,” Sidney said.

That’s where C2E2 comes in.

The project was proposed to, and funded by, DOE’s Office of Cybersecurity, Energy Security and Emergency Response, or CESER, in 2024 for this exact reason.

“Historically, we’ve focused on detection but not localization because that’s a much harder problem to solve,” Georgios said.

One of the things that makes it hard is the data engineering involved — collecting, cleaning and organizing raw data so that machine-learning models always have high-quality information to learn. This process takes time. A lot of time.

“This heavy lift is what we’re trying to simplify using LLMs,” Georgios said. “C2E2 will save time and money, improve threat detection and help us locate the exact spot of a threat.”

An anomaly problem

When the team started their work, they set out to create a machine-learning pipeline that could detect and locate threats by analyzing both cyber and physical data. But they kept running into the same problem.

“Traditional AI was having trouble detecting small anomalies that would pop up in the data because potential threats were sophisticated and continued to show up within normal ranges,” Georgios said. “I wanted to figure out how we could ensure these types of anomalies were still visible to the machine-learning model.”

The solution required data engineering, the above mentioned “heavy lift.”

“It literally took me two months of data engineering to make the AI models understand when something was normal or abnormal,” Georgios said. “After two months, we were able to achieve an 85% threat detection accuracy rate, and while that’s good, it’s not the best. So, we started thinking about how we could automate this, speed the process up and improve performance.

Pipeline A to B

“Right now, the pipeline requires machine-learning engineers to handle the data engineering after we gather the data. Once we have a clean dataset, we feed it into the machine-learning model — that’s the traditional AI part — and from there it can detect a threat and determine its location,” Georgios said. “From start to finish, this process takes about two months, and data engineering accounts for about 90% of that time.”

And as Georgios emphasizes, the data engineering has to be “really, really good,” because as they say in machine learning, “garbage in, garbage out.”

<strong>AI LEADER</strong> — Georgios Fragkos leads the team behind Cybersecurity for the Energy Edge, which uses generative AI and LLMs to detect and locate threats on the electrical grid.
AI LEADER — Georgios Fragkos leads the team behind Cybersecurity for the Energy Edge, which uses generative AI and LLMs to detect and locate threats on the electrical grid.

“Locating the threat is the hardest part because it requires us to process structural information,” he said. “We have to understand the topology and physics of the system, and traditional AI is not great with that.”

In this context, topology refers to how power equipment and cyber systems are connected and how they work together.

That heavy lift falls to machine-learning engineers and demands significant time and manpower.

Enter large language models.

“Large language models are really good with text, so we can describe something, write a text file, provide information on the components, where they’re located, what they connect with, and include physical measurements, cyber information and topology data,” Georgios said. “We’ve figured out a way to use LLMs and generative AI to automate the data engineering step, which takes up the bulk of our time.”

C2E2 creates a new pipeline that starts with feeding data into the model, which automates the data engineering, and outputs a clean dataset to a machine-learning model. That model then outputs whether there’s a threat and where it’s happening, vital information for security operators at utility companies. The training process takes a couple of hours and has a 95% accuracy rate.

The team is just a year and a half into their research, and they’re already getting external recognition. A paper on their findings won the Best Paper Award at the Institute of Electrical and Electronics Engineers International Workshop on Computer Aided Modeling and Design of Communication Links and Networks last October.

Understanding hallucinations  

The next phase of the group’s research is adding an additional layer of understanding around hallucinations, or instances when a model produces data that is incorrect or fabricated. In this context, a hallucination could cause the system to flag a threat that doesn’t exist or miss an actual threat by misreading the data entirely. Georgios says the key to addressing hallucinations is making those mistakes visible and measurable, so researchers can work toward building a more reliable and trustworthy generative AI-powered solution.

“When the LLMs spit out data, we want to be able to explain what it produces so we can avoid hallucinations in the data — that’s still a big question mark,” he said.

From there, Georgios says he wants to take this research into the private sector and test it with a utility company.

AI vs AI

“We have found a way to keep the nation safer by making machine learning more robust,” Georgios said. “Having better accuracy in detecting threats is critical to national security and grid stability.

“Cyber-physical attacks are stealthy and a very real threat to all of us. In 2015, hackers triggered a power outage in Ukraine that left more than 200,000 customers without power for hours.”

As Alex mentioned earlier, a worst-case electric grid cyber-physical attack could have potentially devastating consequences for national security, public safety and the economy.

And to prevent that, sometimes you need to fight AI with, well, AI.

“Hackers are using AI in their attacks — they’re fast and they propagate quickly,” Georgios said. “If you have 10 different AI agents attacking your system, you need something that can look at all the data very, very fast. These attacks are becoming more sophisticated, and our tools need to match that. They need to look at data fast, with trust and high accuracy — and that’s exactly what we’re building.”

IEEE Laureate Forum

Georgios was also one of 50 young professionals selected to attend the 2026 IEEE Laureate Forum & Honors Ceremony in New York City in April. Georgios’ work on this project and other AI-related research helped him stand out among thousands of scientists across the globe.

“Georgios and his team are rockstars, we’re lucky to have such great talent,” manager Alex Haddad said. “The work and research he’s helped lead is building Sandia’s reputation as one of the top national labs to contact when you need AI work in the energy space.”

AI for electric grid security

By Diana Hackenburg

Sandia is engaged in multiple research and development efforts that use AI to secure the electric grid against intentional and natural threats, as well as problems created by aging infrastructure and unprecedented load growth. In addition to C2E2 and DERMS, which was featured in the June 18 edition of Lab News, projects in this portfolio include:

  • A cyber-physical AI-driven response capability that analyzes cyber and physical data and selects, coordinates and deploys response actions, increasing the speed and accuracy needed to combat AI-enabled adversaries and complex cyber-physical attacks. This is funded by the DOE Office of Cybersecurity, Energy Security, and Emergency Response.
  • AI-driven, traveling-wave protection technology designed to improve electric grid fault detection, protection speed, and fault location accuracy in modern distribution systems and microgrids, particularly those with high renewable penetration and wildfire risk. This work is funded by the DOE Office of Cybersecurity, Energy Security, and Emergency Response.
  • Multiagent reinforcement learning framework with Deep Q-Network models to train AI agents to optimize load-shedding accuracy under uncertainty, allowing utilities to meet critical system needs during major contingencies without triggering costly mass evacuations and controlled power outages. The DOE Office of Electricity funds this work.

Several additional projects funded by the Resilient Energy Systems Mission Campaign use AI to increase resilience of the electric grid and energy infrastructure to intentional threats. Sandia also supports DOE’s GENESIS Mission, which brings together the national laboratories, industry and academia to accelerate AI for national and energy security.

Recent articles by Magdalena Krajewski

Top