Physics-Informed Anomaly Detection in IEC 61850 Sampled-Value Networks: A Dual-Threshold Kirchhoff Residual Approach Without Machine Learning
Real-time integrity monitoring of Sampled-Values in IEC 61850-9-2 is critical for detecting cyber-physical attacks, yet the unauthenticated multicast ASN.1/BER transport leaves every in-transit frame exposed to undetected modification. However, machine-learning-based detectors require labeled attack corpora that are unavailable in field deployments and remain brittle to novel attack patterns, while IEC 62351 cryptographic authentication schemes impose computational overhead incompatible with the sub-millisecond frame-delivery constraints of IEC 61850-9-2 process buses. This paper proposes K-Quality, a physics-informed, training-free real-time integrity monitor that exploits Kirchhoff’s Current Law (KCL) for per-cycle residual computation across Merging Units (MUs), requiring no labeled data, no cryptographic infrastructure, and no additional hardware. The core innovation lies in its dual-threshold window-FPR classifier, which synergistically combines rolling-mean residual accumulation, a within-window false positive rate gate, and an instantaneous fast-path trigger to achieve defense-in-depth anomaly classification. A single libpcap capture thread ingests IEC 61850-9-2 Ethernet frames from three MUs at 4800 Sa/s and computes per-cycle three-phase RMS currents. It derives three topology-coupled KCL residuals per cycle. This classifier evaluates three independent bad conditions: sustained residual elevation, frequent per-cycle threshold crossings, and impulsive fast-path spikes --before assigning each cycle a good, degraded, or bad label. It achieved a Detection Rate of 1.0000 (95 % CI: [0.9957, 1.0000]) and a False Positive Rate (FPR) of 0.0000 (95 % CI: [0.0000, 0.0044]), eliminating all 4 false alarms produced by the residual-only baseline (FPR = 0.0046), with end-to-end latency P99 = 0.39 ms. These results highlight the potential of topology-constrained, physics-informed monitoring as a viable training-free framework for SV integrity assurance in resource-constrained substations, requiring neither machine-learning infrastructure nor cryptographic key management.
Authors
- Muhammad Nasar (ORCID: https://orcid.org/0000-0002-5966-8430)
- János Csatár (ORCID: https://orcid.org/0000-0003-4430-9280)
Institutions
- Budapest University of Technology and Economics (HU)
- Universitas Muhammadiyah Malang (ID)
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-09-21
- DOI
- https://doi.org/10.5281/zenodo.22872008
- Primary Topic
- Smart Grid Security and Resilience
- Type
- preprint