Smart Grids integrate many interconnected IoT components such as protection relays, remote terminal units (RTUs), smart meters, communication modules, IoT sensors, and EV chargers into electricity infrastructure that serves millions of people. This convergence of traditional operational technology (OT) and IoT has dramatically expanded the cyber-attack surface of these critical infrastructures. A successful cyberattack can cause not only data loss, but can also have physical consequences such as blackouts, equipment destruction, or cascading failures across regions. A cyberattack on Ukraine’s power grid in December 2015 caused outages affecting approximately 230,000 consumers. Securing these infrastructures is now an urgent need to ensure their resilience and optimal performance. However, the community lacks a systematic and evidence-based understanding of what vulnerabilities exist in smart grids, which device classes carry the highest risk, which types of threats they are exposed to the most, and how that risk is evolving over time across interconnected system components.
This project addresses this gap directly. We hold a unique asset: a curated, and high-quality labeled dataset of Common Vulnerabilities and Exposures (CVEs) annotated as IoT or non-IoT from 2013 up to 2025, covering all sectors (e.g., consumer IoT, industrial IoT) which will form the empirical backbone of the smart-grid vulnerability analysis. This proposal explicitly addresses in-depth understanding of the threat surface of growing smart grids using extracted domain knowledge, an IoT vulnerability dataset, and AI models.
Key objectives: (1) to understand the smart grid vulnerability landscape by identifying smart-grid-relevant CVEs from a large IoT-labeled CVE dataset, and characterizing those vulnerabilities, revealing which device classes carry the highest risk, which weaknesses are the most common and how the risk is evolving over time; (2) to produce a compliance audit for smart grid devices, cross-referencing identified vulnerabilities against standards and regulations (e.g., IEEE 1686, and IEC 62351-9) to assess whether published security standards prevent the vulnerability types they claim to address; and (3) to develop a comprehensive dashboard of smart grid vulnerabilities and their characteristics to disseminate the acquired understanding and findings among researchers and stakeholders to help them towards building a more secure smart grid.
Team: Roland van Rijswijk-Deij (UT), Tina Rezaei (UT), Carlos Hernandez Ganan (TU Delft), Savio Sciancalepore (TU/e)