Preprint
Article

This version is not peer-reviewed.

From Physical Grids to Cyber-Energy Digital Twins: Modeling Power System Components for Cyberattack Assessment

A peer-reviewed version of this preprint was published in:
Electricity 2026, 7(3), 85. https://doi.org/10.3390/electricity7030085

Submitted:

08 July 2026

Posted:

10 July 2026

You are already at the latest version

Abstract
Traditional Digital Twins (DTs) in energy sectors lack cyber-threat awareness, while cybersecurity DTs overlook downstream physical impacts. Loosely coupled co-simulations attempt to bridge this gap but introduce computational lags that mask critical cross-domain vulnerabilities. To address these limitations, this paper proposes a unified, tightly coupled DT framework that integrates energy systems and cybersecurity domains into a single environment. The methodology models the precise mathematical, thermal, and electrical constraints of key assets to capture cross-domain feedback loops. Specifically, a power transformer and a microgrid-connected inverter serve as case studies to map cyberattack vectors directly onto physical definitions. Numerical validation evaluates multiple threat scenarios, including supervisory, measurement, and physical-level (harmonic) attacks on the transformer, alongside short-circuit and hybrid phase-harmonic attacks on the inverter. Results demonstrate how subtle digital disruptions propagate past communication layers to induce physical degradation and operational stress. By explicitly detailing the governing equations and providing sensitivity analyses, this work delivers a transparent, high-fidelity methodology for protecting critical cyber-physical infrastructures from asset-destructive manipulations.
Keywords: 
;  ;  ;  

1. Introduction

A digital twin (DT) is defined as “a virtual representation of an object or system designed to reflect a physical object accurately”, as stated by IBM [1]. Going beyond a simple static 3D model, a DT relies on a continuous, two-way flow of information. Sensors installed on physical components collect real-time data regarding environmental and operating conditions. These data are then transmitted to the digital model, which leverages advanced algorithms to simulate scenarios and predict outcomes. In the context of energy systems and smart grids, energy-centric DTs act as real-time virtual replicas of electrical, thermal and multi-energy networks. They are primarily used to test strategies and models in a risk-free virtual environment without interrupting live operations. Numerous technical and scientific papers have already been published on DTs within the energy sector [2]; these studies primarily focus on optimizing energy distribution safely and efficiently [3], even in the presence of volatile renewable energy sources [4], and enabling predictive maintenance [5]. Furthermore, literature on DT applications in energy systems spans a wide spectrum, ranging from comprehensive system-level studies of entire networks [6] to highly detailed, component-level analyses of specific assets [7]. Therefore, energy-centric DTs possess deep, physics-based high-fidelity models capable of simulating precise thermodynamic behaviors, electrical transients, and mechanical stresses, yet they remain fundamentally blind to cyber threats, assuming all control inputs and operational setpoints are intrinsically trustworthy. DTs designed for cybersecurity operate almost exclusively within the digital and network domains. These cybersecurity-centric DTs are highly sophisticated in monitoring communication networks, detecting anomalous data traffic, identifying protocol violations, and tracing the propagation of cyber threats like False Data Injection or Distributed Denial of Service attacks. However, they consistently treat the underlying physical infrastructure as a static or generic boundary, entirely failing to capture the downstream physical consequences of these digital disruptions [8]. To bridge this operational divide, contemporary research has increasingly turned to co-simulation environments [9]. These frameworks attempt to link distinct cyber and physical simulators together, allowing them to exchange data at specified intervals. While co-simulation represents a step toward integration, it introduces severe structural limitations that prevent it from capturing true system-centric vulnerabilities. Because these environments simulate the cyber layer and the multi-vector energy network, or related management systems [10], as loosely coupled systems, they inherently miss the fine-grained, cross-domain physical feedback loops that dictate real-world cascading failures. The fundamental disadvantage of a loosely coupled co-simulation lies in its execution and synchronization constraints [11], as exchanging data back and forth through discrete time-steps creates a critical computational lag. This lag effectively masks non-linear, component-level physical realities, meaning that an intricate cyberattack on a thermal controller might dynamically violate the immediate hydraulic constraints of a linked gas network or trigger localized thermal degradation in an electrical sub-network without the co-simulation framework ever registering the vulnerability. These issues define the exact research gap this work aims to address. By isolating the cyber-detection capabilities from the deep, multi-vector physical realities, existing paradigms fail to protect critical infrastructure from stealthy, asset-destructive manipulations. There is an urgent, unfulfilled need for a unified, tightly coupled DT framework that transcends both the oversimplified “black box” physical assumptions of cybersecurity models and the blind trust of traditional energy simulators, establishing a truly holistic, system-centric paradigm for cyber-physical security. The primary objective of this work is to move beyond the state of the art by overcoming the traditional dichotomy of isolated energy-centric and cybersecurity-centric approaches. To achieve this, we design and develop a unified DT framework that seamlessly integrates energy systems and cybersecurity domains into a single, cohesive environment. Rather than maintaining the traditional, fragmented architecture where digital defenses and physical assets are simulated in isolation, this comprehensive ecosystem establishes a synchronized playground where cyber events and multi-vector energy flows directly interact. The core focus of this scientific paper is the rigorous definition of individual energy components along with their unique physical and operational properties. By detailing the inherent thermal and electrical constraints governing each asset, the proposed framework establishes a high-fidelity baseline capable of reflecting the true, dynamic state of the component. Crucially, the proposed study systematically maps potential cyberattack vectors directly onto these physical definitions, identifying exactly how malicious interventions like setpoint manipulations alter the internal behavior of each component. This deep integration reveals how subtle, stealthy cyber anomalies propagate past the communication layer to induce physical degradation, structural wear, or unpredicted operational stress. To ensure the scientific validity and practical utility of this approach, the paper provides an exhaustive description of the mathematical and logical modeling of these components. By explicitly detailing the governing equations, parameter dependencies, and cross-domain feedback loops, this work guarantees full transparency and replicability, offering a foundational methodology that other researchers and industry practitioners can readily implement and expand upon to secure critical cyber-physical infrastructures. While this paper establishes these foundational definitions and component-level modeling, the actual implementation and system-wide integration within the unified framework will be presented in a subsequent work. The remainder of this paper is organized as follows: Section II details the proposed methodology and the mathematical modeling of the cyber-energy components. Section III presents the case studies, while Section IV provides the numerical validation and discussion of the results. Finally, Section V concludes the paper and outlines future research directions.

2. Methodology

To bridge the operational gap between cybersecurity paradigms and energy asset modeling, the presented methodology introduces a unified framework where each DT component is constructed via a concurrent four-layer architecture. This foundational structure systematically isolates and couples the distinct domains governing a cyber-physical energy system. The first stratum is the Physical Layer (System Dynamics), which models the high-fidelity physical behavior of the asset. It is strictly governed by immutable differential equations that define core processes such as electrical power flow, electromagnetic relationships—including inductances and resistances—and thermodynamic state transitions, such as heat dissipation in transformers or the State of Charge (SOC) evolution in energy storage systems. Serving as the absolute ground truth, this layer establishes what the exact, uncompromised physical state of the component should be at any given moment. Directly interacting with this dynamic baseline is the Measurement and Signal Processing Layer, which represents the observed reality of the DT. Functioning as the primary informational interface of the component, this stratum manages the acquisition, conditioning, and discretization of system data, translating continuous physical phenomena into discrete telemetry governed by the specific control logic of the instrumentation. Furthermore, power system components are typically governed by an overarching Supervisor Layer, which acts as the centralized algorithmic entity responsible for macro-scale process regulation; this layer can be functionally instantiated as an Energy Management System (EMS) for power dispatch optimization, a SCADA network for wide-area telemetry aggregation, or a master Battery Management System (BMS) for multi-rack safety interlock execution.
The core novelty of this methodology lies in the integration of the third stratum, designated as the Attack Layer (Cyber Stratum). This abstraction layer is explicitly engineered to model the cyberattacks by modifying the signals exchanged between the “Measurement and Signal Processing Layer” and the “Physical Layer”. The Attack Layer does not function as a rudimentary state switch; instead, it acts as an endogenous variable capable of altering how physical parameters are perceived by the Physical Layer. Under these compromised conditions, the component continues to operate in a seemingly correct manner while the monitoring system receives entirely falsified telemetry, stealthily driving the critical infrastructure toward unstable or dangerous operating points.
Within this framework, the proposed research utilizes this layer to investigate the dynamic correlation between logical data integrity and physical process stability (e.g., thermal, electric, etc.), specifically aiming to bridge two critical knowledge gaps. First, it addresses the propagation of transient effects by analyzing how the malicious manipulation of control signals translates into measurable deviations of physical quantities—such as pressures, temperatures, and voltages—thereby mapping the exact transition from the digital domain to the analog physical realm.
Second, it evaluates multi-physical interdependencies within the component itself or different components of a system, analyzing how an alteration of a specific operational parameter cascades into other domains through non-linear feedback loops. For instance, a cyberattack manipulating the regulation signal of a cooling fan (i.e., a secondary component of a transformer system), which causes anomalous thermodynamic overheating and subsequently degrades the transformer’s electrical infrastructure.
The overall architecture of the multi-layered Cyber-Energy DT framework is schematically mapped in Figure 1.
As shown in Figure 1, to systematically operationalize the convergence of cybersecurity dynamics (i.e., CYBERSECURITY DT in literature) and energy asset modelling (i.e., ENERGY DT in literature), the proposed methodology instantiates a unified simulation architecture that formalizes the interactions between data integrity and physical process stability (CYBER-ENERGY DT). Moving beyond the fragmented paradigms found in literature (pp. 2-3) —which isolate cyber-telemetry from power systems engineering—this framework encapsulates the DT component within a concurrent, three-layer stratification. The foundation of this architecture relies on the rigorous decoupling of the absolute physical ground truth, governed by mathematical equations at the Physical Layer, from the discretized operational data processed at the Measurement and Signal Processing Layer. The critical methodological advancement is achieved through the formal definition of the Attack Layer not as an exogenous binary perturbation, but as an endogenous mathematical variable embedded directly within the signal exchange interface. By modulating the transfer functions between the measurement instrumentation and the physical dynamics, the Attack Layer alters the parameter perception of the asset. Crucially, this stealthily falsified telemetry can be simultaneously injected into two distinct operational vectors: it can feed directly into the differential equations governing the physical processes at the Physical Layer, forcing the asset to respond to malicious inputs, while concurrently penetrating the management and governance equations executed at the Supervisor Layer, thereby blinding the overarching control framework to the ongoing degradation.

3. Case Study

This section details the practical implementation and operational development of the proposed cyber-energy DT framework across two critical grid components: a power transformer and an inverter. To demonstrate the high-fidelity multi-physics coupling of the system, the models and their corresponding mathematical structures are implemented and validated within the Dymola (Dynamic Modeling Laboratory) environment [12], leveraging its advanced object-oriented modeling capabilities. However, a defining feature of this methodology is that it remains inherently software-agnostic. Because the underlying multi-layer architecture relies strictly on universal differential equations, standardized conditional logic, and explicit cross-domain feedback loops, the foundational principles and component behaviors formalized in this work can be seamlessly replicated and deployed across any modern industrial simulation platform or DT ecosystem.

3.1. Power Transformer

In this section, the proposed methodology is applied to a power transformer asset to analyze cross-domain vulnerability propagation. The cyber-physical interactions of the system are structured into four interconnected layers, mapping how continuous-time electro-thermal dynamics are influenced by discrete logical control and cyber-manipulations. The conceptual architecture of the multi-layered Cyber-Energy Transformer DT is schematically mapped in Figure 2.
  • The Physical Layer
The Physical Layer encapsulates the core electro-thermal dynamics of the transformer, instantiating a high-fidelity lumped-parameter topology to couple electrical stress with thermodynamic degradation. The electrical domain models the grid-tied infrastructure based on the following specific topological characteristics:
  • Primary and Secondary Windings: These components are configured as a transformer magnetically coupled through a high mutual inductance k . To account for real-world grid imperfections and core behavior, each winding is limited and protected by a series resistance representing the actual line impedance of the branches.
  • Magnetic Coupling: The transformation ratio N rigorously defines the voltage dynamics of the system, while the high mutual inductance governs the continuous energy transfer between the primary and secondary sides.
Under normal operating conditions, the primary power source is represented by a stable AC voltage source generating a sinusoidal wave with a nominal amplitude V at a standard frequency. Unlike standard static transformer representations, this system computes the internal oil temperature (Toil) in real time, shifting the asset from an abstract electrical node to a component subject to degradation. Fundamentally, the thermal energy within the transformer is generated by these electrical losses and dissipated by the oil-based cooling system. The active power losses (ploss) are calculated instant by instant by summing the Joule losses ( v r i r ) of both the primary and secondary windings, as:
P loss = V 1 i 1 + V 2 i 2
Where:
V1: Primary Voltage [V]
V2: Secondary Voltage [V]
i1: Primary Current [A]
i2: Secondary Current [A]
The core and the insulating oil are modeled as a unified thermal capacity ( C ). The differential equation governing the oil temperature (Toil) is:
C d T oil d t = P loss G eff T oil T amb
Where:
C : Thermal Capacity [J/K]
Toil: Internal Oil Temperature [K]
T amb : Ambient temperature [K]
Geff: Effective Thermal Conductance toward the external environment [W/K].
2.
The Measurement and Signal Processing Layer
This layer bridges the continuous physical domain and the supervisory framework. It captures physical variables—such as the true current and the absolute oil temperature—and conditions them into discretized telemetry (i.e., signals).
In this layer, the Current Sensor reads the source current from the Main AC Source. Simultaneously, the Internal Oil Temperature (Toil) is converted into a readable telemetry signal (Toil State). Under normal operating conditions, this layer maps the exact boundaries of observability, transmitting telemetry packages upward to the Supervisor Layer (SCADA system).
3.
The Supervisor Layer (SCADA)
Acting as the centralized algorithmic entity for macro-scale process governance, the Supervisor, a SCADA system, monitors the transformer’s telemetry vectors and enforces operational thresholds. Based on the temperature, the SCADA layer dynamically regulates the cooling state by executing safety interlocks and sending the cooling configuration commands back to the Physical Layer.
4.
The Attack Layer and Multi-Vector Cross-Domain Feedback Loops
The core of the vulnerability analysis resides in the Attack Layer, which implements three distinct, concurrent threat vectors aimed at decoupling the physical reality from the SCADA perception, forcing malicious closed-loop behaviour:
  • ATTACK 1: Fan system attack
This attack reduces the fan operation (potentially leading to a complete stall) and, consequently, compromises the system’s cooling capacity. The Supervisor Layer will only become aware of the attack following the subsequent rise in the oil temperature. To simulate this attack, it clamps the effective cooling conductance to a fraction of its nominal value (Geff), forcing a severe reduction in heat dissipation while the physical asset continues to generate heavy Joule losses. When Attack 1 is triggered, the actual Gcooling is replaced by a reduced value equal to:
G e f f = x %   · G c o o l i n g
Where:
x% = Reduction percentage of G e f f   to simulate cyberattack 1
G c o o l i n g : Effective Thermal Conductance toward the external environment [W/K].
Finally, this attack can lead to rapid thermal runaway, potentially destroying the insulation and windings.
  • ATTACK 2: Sensor Masking (Telemetry Falsification):
This type of attack masks the values measured by the sensors. Functioning as a False Data Injection (FDI) attack, it targets the Measurement and Signal Processing Layer by communicating temperature values that deviate from the actual ones. Consequently, it misleads the supervisor into making operational decisions that result in the incorrect regulation of the transformer’s cooling systems. When Attack 2 is triggered, the signal measured by the realOilTemp is replaced by a reduced value equal to:
T m e a s u r e d = T r e a l O i l T sensorTampering
Where:
T m e a s u r e d : Temperature measured by the sensor [K]
T r e a l O i l : Actual oil temperature [K]
T sensorTampering : Tampered temperature value [K]
In a similar manner to Attack 2, this scenario can induce rapid thermal runaway, potentially compromising both insulation and windings.
  • ATTACK 3: Harmonics Generator:
Operating on the electrical domain, this attack injects high-frequency distortions (ExpSine Waves modulated by a Gain Multiplier) into the current feedback loop via a Dynamic Distortion Solver. This malicious injection feeds distorted grid power directly back into the primary windings of the Physical Layer, significantly elevating the core and winding Joule losses.
The mathematical formulation for the corrupted feedback signals and the compromised telemetry vectors is expressed as:
v harmonic = i 1 v a t t a c k ( t )
Where:
v a t t a c k ( t ) = K A e ( t 30 ) s i n ( 2 π f ( t 30 ) )
i1: Primary Current [A]
K : Gain factor applied by the res_multiplier block.
A : Amplitude.
e ( t 30 ) : Exponential decay term, defined by the damping value of 1.
f : frequency [Hz].
As a result of this attack, short-lived temperature fluctuations occur. Since these oscillations do not exceed safe operational thresholds, they evade detection by the supervisor system, thereby subtly accelerating the transformer’s degradation.
These three attacks can be executed either individually or in a coordinated manner across the system.

3.2. Microgrid-Connected Inverter

In this section, the proposed methodology is applied to a microgrid-connected inverter. Figure 3 illustrates the conceptual architecture of the multi-layered Cyber-Energy DT framework. Designed to emulate the complete Cyber-Physical System (CPS), the DT integrates the photovoltaic power source, the electrical power stage, and the semiconductor thermal dynamics. Furthermore, in this case study, the supervisor layer embeds both a core control loops and a robust cyber-security monitoring layer tailored to detect and counteract cyber-physical intrusions.
  • ThePhysical Layer
The analyzed case study consists of a comprehensive microgrid architecture, whose main components are outlined below:
  • Photovoltaic (PV) source: Two series-connected PV panels.
  • DC Bus: A bipolar DC bus stabilized by two capacitor banks, featuring a grounded neutral point.
  • Inverter and Grid connection: An inverter connected to the main AC grid—modeled as an ideal sinusoidal generator—via a line impedance.
The photovoltaic (PV) string supplying the DC-link is modeled through the implicit characteristic single-diode equation; in particular, according to this equation, the Output current is given by:
I = I s c I 0 e x p q V n k T 1
Where:
  • I is the Output current (or Cell output current / Terminal current) [A].
  • I s c - Short-circuit current: represents the maximum current generated by the PV module when its terminals are short-circuited [A].
  • I 0 - Reverse saturation current: serves as a key indicator of panel quality and internal recombination losses [A].
  • V : The voltage applied across the terminals of the solar cell [V].
  • q (Elementary Charge): The fundamental electric charge of an electron ( q 1.602 × 1 0 19 C )
  • n - Diode ideality factor: It is a dimensionless parameter (typically ranging between 1 and 2) that quantifies the deviation of the physical cell's diode from the ideal p-n junction behavior.
  • T - absolute temperature: 298.15 K (equivalent to 25°C, the Standard Test Condition - STC temperature).
  • k- Boltzmann constant: 1,380649 × 10 23 [ J / K ]
The inverter is modeled as a half-bridge converter, utilizing two complementary power semiconductor switches (e.g., IGBTs or MOSFETs) – S1 and S2 – to perform DC-to-AC conversion. These switches act as high-frequency actuators: when the upper switch (S1) is ON, the load is connected to the positive DC bus (Vdc); when the lower switch (S2) is ON, the load is connected to ground. The control logic relies on Pulse-Width Modulation (PWM), where a modulating reference signal is continuously compared against a triangular carrier wave to determine the switching states. This comparison dynamically toggles the switches, generating a high-frequency square wave pulse train. When applied to an inductive load, this pulsed voltage results in an averaged, sinusoidal current, enabling precise control over the output power profile.
The load consists of a series RL circuit. The resulting current i t   is governed by the following first-order differential equation:
V o u t ( t ) = R i ( t ) + L d i ( t ) d t
Where:
V o u t ( t ) : The instantaneous output voltage supplied by the inverter to the load [V]
R : The electrical resistance of the load [Ω].
i ( t ) : The instantaneous electrical current flowing through the load [A].
L : The inductance of the load [H]
Beyond the electrical dynamics, the inverter model incorporates a thermal behavior subsystem to evaluate the temperature profiles of the switching devices. Specifically, a Lumped-Parameter Thermal Network (LPTN) is implemented, establishing a direct analogy between heat transfer and electrical current flow.
C d T c h i p d t = P l o s s T c h i p T a m b R t o t a l _ t h e r m a l
Where:
  • C - Thermal Capacitance: represents the thermal inertia of the component [J/K].
  • Rtotal_thermal - Thermal Resistance: represents the thermal resistance between the junction-to-case and case-to-ambient [K/W].
  • P l o s s   Power Dissipation: calculated as the energy lost during conduction, where P l o s s = i 2 t R o n   [ W ] .
  • i(t): Instantaneous current flowing through the switch [A].
  • R o n : On-state resistance of the semiconductor switch [Ω].
  • Tchip: Instantaneous temperature of the semiconductor junction [K].
  • Tamb: Ambient temperature surrounding the device [K]
To bolster system resilience, the architecture incorporates an additional, high-level protection layer featuring a primary circuit breaker on the DC side (i.e., Protection Breaker). Rather than relying solely on conventional hardware overrides, this secondary defense mechanism is dynamically triggered upon explicit mitigation commands issued by the physics-based IDS (CyberMonitor), which is integrated into the Measurement and Signal Processing Layer. The corresponding switching control loop logic, which governs the breaker state based on the calculated phase and frequency anomalies, is detailed in the subsequent section.
2.
The Measurement and Signal Processing Layer
Beyond standard measurement sensors, this layer integrates a dedicated physics-based Intrusion Detection System (IDS), referred to as the CyberMonitor. This block ingests the physical grid voltage signal and the internal inverter voltage reference signal to continuously compute the instantaneous voltage discrepancy:
e ( t ) = V grid t V r e f t
Where:
  • e(t) : Instantaneous voltage discrepancy [V]
  • V grid t : Instantaneous voltage measured on the physical power grid [V]
  • V r e f t :   Internal voltage reference signal generated by the inverter control logic [V]
  • t :   time instant (s)
A non-zero value of e(t) implies a frequency or phase anomaly; if this condition persists over a specified interval, it indicates a loss of synchronization. Consequently, the protection breaker is triggered to isolate the system from the grid.
3.
The Supervisor Layer
The Supervisor Layer in the proposed model performs critical tasks for the system’s operational control and safety. In a real-world implementation, this layer corresponds to the Control Board, which utilizes a DSP (Digital Signal Processor) or a high-performance MCU (Microcontroller) as the electronic “brain” to manage logic decisions.
Its main tasks, as defined in the proposed model, are broken down as follows:
  • Switching Control (Controller – Figure 3): Within the model, the Controller block represents the algorithm executed by the DSP/MCU to manage the inverter’s operational logic. It generates the gate signals (gate_S1, gate_S2) required to drive the power switches and implements PWM logic (PWM Carrier & Dead-Time Logic) to modulate the reference voltage (v_ref_final), ensuring the precise execution of switching commands.
  • Safety and Protection Management (Breaker Logic): In the proposed model, the supervisor layer is responsible for the emergency intervention logic through the Breaker Logic block. It receives the monitor alert signal originating from the CyberMonitor (located in the Measurement and Signal Processing Layer) to detect phase or frequency discrepancies. Moreover, it receives the thermal_trip signal from the Thermal Model (located in the Physical Layer), which indicates if the junction temperature has exceeded the safety limits set in the model.
4.
The Attack Layer
The layer is designed to simulate attack scenarios that directly manipulate the inverter’s critical parameters:
  • Phase Shift: this attack triggers a loss of phase synchronization in the inverter, resulting in a non-zero e(t) value.
  • Frequency Alteration: this attack aims to induce instability in the DSP/MCU control loop; therefore, it triggers a loss of frequency synchronization in the inverter.
  • Shoot-Through (Intentional Short Circuit): This is the most critical attack. The layer forces the simultaneous activation of the gate_S1 and gate_S2 switches. Since both are conducting, a low-impedance path is created between the DC bus and ground, causing a short circuit (Shoot-Through) that can lead to immediate physical damage to the semiconductors.
Attacks 1 and 2 are injected directly into the simulation models by inserting a disturbance block to modify the phase (Attack 1), the frequency (Attack 2), or both in the case of a combined attack. At the trigger execution (defined via a time step or a specific condition), the block adds an offset (Δf, ΔΦ) to the actual signals.
To simulate Attack 3, the Ideal Switch Control (Physical Layer) method is applied. Specifically, the gate driver signals of the phase leg switches within the simulation model were directly overridden using a step or a conditional trigger to inject a high signal into both gates at the same time stamp. This approach successfully simulates the instantaneous low-impedance short-circuit path without requiring modifications to the complex gate-driver logic.

4. Numerical Validation and Results

4.1. Simulation Objectives

To evaluate the performance of the proposed cyber-energy DT methodology, a multi-domain simulation framework was implemented within the Dymola environment. Leveraging the object-oriented and multi-physics capabilities of the Modelica language, Dymola provides a rigorous computational platform to capture the non-linear, bidirectional dependencies between the physical power grid assets (energy domain) and their communication and control logic (cyber domain).
The numerical validation presented in this work serves as a crucial proof-of-concept to verify the mathematical and logical alignment of the cross-domain models before deployment on physical hardware. Within this virtual testing environment, the framework's capabilities are benchmarked across the following fundamental pillars:
  • Model Fidelity: Traditional, single-domain DTs fail to accurately reflect the behavioral deviations caused by cyber-physical anomalies. In this work, fidelity is evaluated by the DT’s capacity to dynamically replicate cross-domain damage propagation. The simulation demonstrates how a purely digital perturbation (e.g., data packet tampering or malicious control commands) accurately translates into realistic physical and thermal stress within the energy asset model.
  • Methodological Effectiveness: The effectiveness of the framework is verified by its ability to quantify the downstream energetic impacts of a security breach. Rather than merely detecting a generic system fault, the proposed methodology successfully translates cyber-attacks into concrete power-domain metrics, such as asset degradation rates, thermal runaway margins, and localized power quality fluctuations.
  • Framework Replicability: To ensure widespread industrial applicability, the methodology is designed as a modular, library-based framework of models. Thanks to the object-oriented nature of the implementation, the cyber-physical mapping layers developed in this study are highly replicable. While this section focuses on a specific power transformer and a microgrid-connected inverter, the underlying architecture can be seamlessly instantiated and adapted to other critical grid assets—such as circuit breakers or energy storage systems—or scaled to accommodate different power ratings and dimensions of the same type of device by simply adjusting their physical and operational parameters (e.g., low voltage, medium voltage or high voltage tranformers).

4.2. Simulation of a Power Transformer DT

The transformer under analysis is a secondary distribution three-phase power transformer, modeled via its single-phase equivalent circuit. From a grid perspective, the machine is classified as a Medium-Voltage to Low-Voltage (MV/LV) step-down transformer designed to operate interconnected to a grid at a nominal frequency of 50   Hz . To validate the proposed methodology, the transformer DT models a small-to-medium oil-immersed distribution transformer rated at 500   kVA . The electrical configuration of the asset features a primary voltage ( V 1 ) of 2.3   kV (Medium-Voltage class) and a secondary voltage ( V 2 ) of 230   V (Low-Voltage class), yielding a transformation ratio ( n ) of 10:1.
The equivalent electrical parameters of the windings include a lumped winding resistance R winding = 0.05   Ω , while the primary and secondary winding inductances are established at L 1 = 10   H and L 2 = 0.1   H , respectively, perfectly satisfying the ideal scaling law L 1 / L 2 = n 2 .
From a thermal perspective, the baseline environmental condition is defined by a constant ambient temperature T amb = 293.15   K ( 20 C ). The heat dissipation mechanism of the cooling infrastructure is characterized by a nominal thermal conductance G cooling = 50   W / K . Due to the significant physical mass of the iron core, copper windings, and insulating oil in a standard 500   kVA unit, the nominal physical thermal capacitance is relatively high, with a realistic baseline value of C th = 1.000.000   J / K ( 1000   kJ / C ). Coupled with an equivalent thermal resistance to the ambient environment of R th = 1 / G cooling = 0.02 C / W , the real-world asset exhibits a slow thermal transient response, characterized by a baseline thermal time constant ( τ ) of approximately 20.000   s ( 5.56   hours ).
Simulating such extended real-world timeframes to observe cyber-physical attacks is computationally impractical and limits the resolution of monitoring tests. Therefore, to align these long-term real-world thermal transients with a computationally efficient evaluation window, the DT incorporates an accelerated simulation methodology by applying a temporal scaling factor of k s c a l e = 100 . This acceleration compresses the transient behaviour by scaling down the equivalent thermal capacitance used within the simulation environment as follows:
C th ,   acc = C th k s c a l e = 10.000   J / K
This modification represents the accelerated equivalent thermal capacity (the combined oil and core mass within the simulation domain), safely compressing the operational thermal time constant within the simulation window to τ acc = C th ,   acc / G cooling = 200   s . Because the equivalent thermal resistance ( R th ) and the underlying electrical loss profiles remain unaltered, the steady-state temperature thresholds, the absolute physical temperature limits, and the operational boundaries of the hysteresis cooling control loop ( 65 C activation and 55 C deactivation) are entirely preserved. This scaling technique ensures a high-resolution observation of the post-attack divergence and cooling oscillations within a compact simulation timeframe of 2000   s , maintaining the strict mathematical integrity of the DT’s residual generation.
To analyze the transformer’s behaviour, the active power losses (ploss) are calculated instantaneously according to Eq.(1), and the oil temperature (Toil) is determined according to Eq.(2). Toil, the initial top-oil temperature of the transformer is set to 60 C . This represents a pre-existing steady-state condition, commonly referred to as a hot start. From a physical perspective, the transformer has already been in service for several hours, supplying electrical loads; consequently, internal losses—specifically Joule heating in the windings and core losses within the iron—have already elevated the oil temperature to its nominal operating level. For standard 500 kVA distribution transformers operating under rated load, the steady-state top-oil temperature typically ranges between ab. 65°C and 80°C. According to international standards, this ensures that the winding hot-spot temperature remains below the critical 98°C threshold, thereby preventing accelerated insulation degradation.
Geff corresponds to Gcooling when no cyberattack occurs.
The performed simulation focuses on the thermal degradation and operational reliability of this transformer when exposed to cyber-attacks. Specifically, the analysis contrasts normal operation (i.e. baseline)—assumed under constant load and ambient temperature conditions—against the transformer’s performance under three critical attack vectors: Cooling System Manipulation (Fan Failure), Sensor Spoofing (tampering), and Harmonic Injection (Power Stress).

4.2.1. Scenario 1: Cooling System Manipulation

This scenario simulates the consequences of unauthorized access to the cooling control system, which results in a sudden reduction in heat dissipation and an accelerated thermal buildup within the oil/core assembly. From a physical perspective, this cyber-physical attack directly targets the actuation infrastructure of the cooling system. By maliciously restricting fan operation—potentially leading to a complete stall—the attack severely compromises the system’s overall heat rejection capacity. Because this malicious intervention manipulates the physical actuators while potentially spoofing status feedback, the Supervisory Layer remains oblivious to the ongoing cyber-anomaly. Consequently, the intrusion can evade immediate detection until an anomalous, physical rise in oil temperature is observed or cross-checked.
To model this vulnerability, the attack is represented by clamping the effective thermal conductance ( G eff ) to a predefined fraction of its nominal value ( G cooling ). This forcing function induces a severe reduction in heat dissipation while the physical asset continues to generate heavy Joule losses under operational loads. Mathematically, once the attack is triggered, the effective thermal conductance toward the external environment is governed by Eq. (3). In this validation setup, the cooling efficiency is reduced by 99% ( x = 1 % in Eq. (3)), capturing a worst-case scenario such as a complete fan stall or a blocked ventilation intake. In the simulation environment, this attack vector is step-triggered at a specific timestamp ( t = 1000   s ). The sudden collapse of the thermal conductance abruptly disrupts the continuous thermal equilibrium of the system described by Eq. (2). By shifting this thermal balance, the energy generated by internal losses becomes trapped within the transformer.
The graph in Figure 4 presents the outcomes of the simulated scenario, demonstrating how the fan control system attack affects the transformer’s thermal behaviour. Under constant operational load and ambient temperature conditions (Normal Operation), the transformer maintains a stable thermal equilibrium, with the top-oil temperature remaining nearly constant at around 65°C. Under standard operational policies designed to optimize energy consumption, the first group of cooling fans is typically activated within this 60–65°C range.
However, following the attack trigger at t = 1000   s , the Fan Control Attack curve exhibits a significantly steeper slope, indicating accelerated thermal growth. Consequently, the area between the blue curve (attack scenario) and the red curve (normal operation) highlights the additional cumulative thermal stress resulting from the compromised effective thermal conductance. Because the system can no longer reject the internal losses generated under operational loads, this thermal energy remains trapped within the asset. In standard transformer configurations, reaching a threshold of 80–85°C would automatically trigger a second stage of cooling, activating additional fan groups or oil circulation pumps to force a higher heat exchange rate and mitigate dangerous temperatures. When the temperature approaches these critical safety limits, the adversary can dynamically modulate the control input parameter ( x t ) to temporarily allow the asset to cool down before restarting the cycle. This sophisticated, cyclic manipulation is designed to avoid triggering SCADA high-level alarms or hardwired trip thresholds while progressively inducing severe thermal fatigue and degradation of the transformer’s physical paper insulation. Rather than causing an immediate, catastrophic network failure, the adversary’s objective is to stealthily erode the asset's Remaining Useful Life (RUL) while remaining entirely undetected by standard monitoring systems.

4.2.2. Scenario 2: False Data Injection

This scenario simulates a data-integrity attack targeting the measurement chain. By injecting a false negative offset into the temperature sensor readings, the attacker conceals the transformer’s actual thermal state from the control system. This manipulation effectively bypasses automatic safety interventions, allowing the asset to operate within hazardous temperature ranges. In more detail, the attack directly compromises the Measurement and Signal Processing Layer by broadcasting altered temperature data, misleading the supervisory system into faulty operational decisions, such as inadequate regulation or the complete non-activation of the cooling infrastructure.
In practice, once the attack is triggered at a specific timestamp ( t attack = 1000 s ), the sensor signal is manipulated by subtracting a constant offset ( T sensorTampering in Eq. (4)). In the analysed scenario, the cooling system is governed by a PID controller, which continuously modulates the thermal conductance (Geff) to maintain the target temperature of 65°C. Due to this manipulated feedback, the controller is unable to compensate for the actual heat accumulation, leading to a progressive and uncontrolled rise in the transformer's oil temperature despite the manipulated (falsified) measurement.
Figure 5 presents the outcomes of the simulated scenario.
The simulation illustrates the following dynamics for the scenario with T sensorTampering = 6 ° C :
  • Pre-attack Phase ( t < t a t t a c k ): the system operates under normal conditions, with the cooling system regulating the temperature (red curve) effectively
  • Trigger Point ( t = t a t t a c k = 1000 s ) : The attack is activated, introducing a malicious negative offset directly into the oil temperature measurement.
  • Post-attack Divergence ( t > t a t t a c k ): the injected offset causes the PID controller to perceive a temperature lower than the true thermal state. Since the PID interprets this "fake" lower temperature as a reduced cooling demand, it improperly scales down the cooling power. This results in a continuous, uncontrolled increase in the actual oil temperature (red curve). The system reaches a new, higher equilibrium point where the PID controller stabilizes the perceived temperature (blue curve), but at the cost of exposing the transformer to a much higher actual oil temperature (red curve), thereby inducing significant thermal stress on the asset.
In conclusion, the simulated scenario effectively demonstrates the vulnerability of closed-loop control systems to stealthy data-integrity attacks. By strategically injecting a negative constant offset into the temperature sensor readings, the adversary successfully exploits the physical dependencies of the process without triggering standard, static threshold-based anomaly detection. The PID controller, blinded by the falsified feedback, autonomously reduces the necessary cooling infrastructure (Geff), driving the transformer into a thermal runaway state while maintaining a seemingly nominal status on the supervisory layer. These findings underscore that traditional safety interventions and boundary checks could be insufficient to secure critical cyber-physical assets. Consequently, this study highlights the urgent need for advanced defence mechanisms, such as analytical redundancy, digital-twin-based state estimation, and cryptographic data authentication at the measurement layer, to ensure the resilience of modern electrical grids.

4.2.3. Scenario 3: Harmonic Injection

This scenario simulates a cyber-induced electrical disturbance designed to degrade a medium-voltage to low-voltage (MV/LV) distribution transformer’s insulation through severe power stress. By manipulating the input voltage profile to inject harmonics at 250 Hz, the attacker targets the 5th harmonic of the nominal 50 Hz grid frequency. This specific frequency is highly relevant for MV/LV assets [13], as the 5th harmonic is naturally and frequently generated by non-linear low-voltage loads, such as industrial variable frequency drives (VFDs), electric vehicle charging stations, and large inverter systems. By injecting this component with a peak amplitude of 20 V, the attacker generates substantial additional internal losses, exacerbating the thermal stress on the core and windings beyond their nominal design limits. Operating within the electrical domain, this attack injects high-frequency distortions into the power feed according to Eq. (5) and Eq. (6). A 20 V amplitude corresponds to approximately 1% of the nominal primary voltage (2300 V), a standard voltage class widely utilized in heavy industrial distribution networks and MV-fed plant machinery. This value is intentionally chosen to remain within the typical individual harmonic distortion limits allowed by standard power quality regulations (such as [14,15]), ensuring that the disturbance is not immediately flagged as an anomaly. Since 250 Hz distortions are often tolerated as background noise from heavy industrial operations, the attack successfully avoids triggering standard over-voltage protection relays or supervisory alarms. Despite the relatively low voltage amplitude, the injection frequency of 250 Hz significantly enhances the energy dissipation within the asset. Despite the relatively low voltage amplitude, the injection frequency of 250 Hz significantly enhances the energy dissipation within the asset. This is primarily driven by winding stray and eddy current losses within the conductors, which scale quadratically with frequency (f2) relative to the harmonic current. Due to the increased AC resistance of the windings at this frequency (driven by skin and proximity effects), the localized thermal stress on the insulation is significantly amplified compared to the 50 Hz fundamental baseline, accelerating insulation degradation without triggering core-saturation protections.
The harmonic injection attack is triggered at t = 1000 s and terminated at t = 1600 s, as clearly marked in Figure 6. These harmonic distortions alter the magnetic operating point, driving the core into non-linear magnetic saturation. This mechanism significantly elevates core losses—specifically due to intensified eddy currents and hysteresis. As a direct result of this coordinated injection, the oil temperature profile exhibits an immediate thermal surge. However, as illustrated in Figure 6, the asset's automated PID controller actively mitigates this thermal spike by modulating the cooling system to track the 65°C target temperature. By forcing the cooling loops to continuously fight and compensate for the induced internal losses, the malicious activity successfully evades standard supervisory temperature alarms while subtly accelerating the long-term thermal degradation of the transformer’s internal insulation. The graph in Figure 6 presents the outcomes of the simulated scenario, demonstrating how the harmonic injection attack affects the transformer’s overall thermal behavior under closed-loop control.
  • Initial Transient Phase (   0 s 500   s ): The system starts at 60 C and experiences a natural thermal overshoot up to 66.7 C during standard startup or load activation. The PID controller reacts to this overshoot, successfully stabilizing the oil temperature at its nominal steady-state target of 65 C by t = 500 s .
  • Attack Initiation ( t = 1000   s ): At the onset of the 5th harmonic injection (20 V peak amplitude at 250 Hz), a sharp, immediate rise in oil temperature is observed. The steep slope verifies the rapid accumulation of high-frequency core losses (eddy currents).
  • PID Masking Effect ( 1000 s 1600 s ): The temperature peaks again near 66.7 C . The PID controller detects the deviation from the 65 C setpoint and forces the cooling fans/pumps to operate at an increased duty cycle. This counteraction successfully drives the temperature back down toward the baseline, effectively "masking" the attack from standard high-temperature alarms.
  • Attack Termination & Undershoot ( t = 1600 s ): Once the harmonic injection ceases at t = 1600 s , the sudden drop in internal heat generation—combined with the fact that the cooling system was still operating at maximum capacity—causes a significant temperature undershoot down to 63.3 C .
  • Recovery Phase ( 1600 s 2000 s ): The PID controller throttles back the cooling mechanism, allowing the transformer's oil temperature to gradually recover and converge back toward the designated 65 C target line.
Figure 6. Oil temperature profile of the transformer under Harmonic Injection attack.
Figure 6. Oil temperature profile of the transformer under Harmonic Injection attack.
Preprints 222246 g006
The simulation indicates that operating within the low-order power grid harmonics does not yield immediate or visually apparent physical damage. Instead, at these lower frequencies, the asset operates within a “thermal degradation window”. Here, the primary threat is the formation of localized hot-spots within the windings, driven by increased AC resistance from skin and proximity effects. Over time, this chronic thermal stress may accelerate the degradation of the paper and oil insulation, progressively reducing the transformer’s overall operational lifespan. However, quantifying the exact reduction in useful life would require a dedicated, long-term thermal-aging study.

4.2.4. Sensitivity Analysis for a Multi-modal Attacks

This section presents a comprehensive sensitivity analysis conducted to evaluate the transformer’s thermal behavior—specifically focusing on oil temperature dynamics—under a composite cyber-physical assault. This coordinated threat model simultaneously deploys the attack vectors hypothesized in Scenarios 1, 2, and 3, combining cooling system manipulation, False Data Injection (sensor masking), harmonic injection attacks.
The numerical outcomes of this analysis are shown in Figure 7, which illustrates the intersection between cooling status (Fan Manipulated vs. Fan Normal Operation), Harmonic Injection at three levels of frequency ( 500 Hz , 1000 Hz , and 1500 Hz ), and Fault Data Injection for four levels of “masking offset” (sensor tampering levels: Δ T mask 0 ° C , 2 C , 4 C , 6 C ).
As demonstrated by the red-shaded regions on the left side of Figure 7, the concurrent execution of harmonic injection attacks and a direct physical fault (i.e., a cooling fan fault) triggers severe, non-linear thermal escalations. In this regime, the system suffers a total loss of thermal regulation. The empirical data confirm that the fan fault acts as the dominant catalyst for critical thermal stress, rapidly driving the top-oil temperature past the 100 C safety threshold.
A key finding is that the duration required to breach this safety limit is strictly dictated by the severity of the harmonic payload, showing a stark non-linear progression. At a baseline harmonic frequency of 500 Hz , the safety threshold is exceeded in 89.0 s . Increasing the payload to 1000 Hz accelerates the breach, reducing the time to 53.0 s , while under peak harmonic stress ( 1500 Hz ), catastrophic failure occurs within a critical window of 38.0 s . Notably, these Time-To-Failure (TTF) remains entirely invariant across all sensor masking levels ( 0 C ,   2 C , 4 C , 6 C ). This invariance proves that when the cooling infrastructure is physically compromised, physical degradation entirely dominates the system state. Consequently, sensor-based concealment strategies (False Data Injection - Mask Attacks) become redundant, as they do not accelerate nor delay the underlying physical collapse.
Conversely, as illustrated by the green-shaded regions on the right side of Figure 7, the transformer exhibits robust thermal resilience as long as the cooling fans remain operational (Fan Normal Operation). Even under maximum harmonic excitation ( 1500 Hz ), the cooling infrastructure successfully maintains thermal stability, constraining the peak and steady-state oil temperatures to a safe plateau of 92 C .
However, within this safe operating envelope, the insidious impact of the Mask Attack becomes clearly observable. By falsifying the temperature telemetry, the cyber attacker tricks the PID controller into underestimating the actual thermal state. This induces a proportional misreaction in the cooling control loop, leading to a steady-state temperature drift that scales with the masking severity.
For instance, at a harmonic frequency of 500 Hz , the baseline condition without cyber manipulation ( Δ T mask = 0 ° C ) yields a maximum temperature of 68 C and a steady-state value of 65 C . As the masking severity ( Δ T mask ) increases to 2 C , 4 C , and 6 C , the peak temperatures shift upward to 69 C , 71 C , and 73 C , respectively, while the corresponding steady-state temperatures rise to 67 C , 69 C , and 71 C . A matching trend is observed under a 1000 Hz harmonic load, where the uncompromised system ( Δ T mask = 0 ° C ) peaks at 72 C with a steady state of 65 C . This behavior degrades progressively under attack, culminating in a maximum temperature of 78 C and a steady state of 71 C at a 6 C masking level. This linear correlation confirms that the Mask Attack successfully enforces a silent, sub-critical thermal degradation.
Interestingly, at 1500 Hz , the temperature converges identically to a maximum and steady-state value of 92 C regardless of the masking level. This phenomenon indicates control loop saturation: at this extreme harmonic load, the PID controller has already driven the cooling fans to their maximum volumetric capacity ( 100 % operational output). Therefore, further sensor falsification yields no additional thermal escalation, establishing the physical upper bound of the system’s active mitigation capability.
Figure 7. Impact of multi-vector cyber-physical attacks on transformer oil temperature.
Figure 7. Impact of multi-vector cyber-physical attacks on transformer oil temperature.
Preprints 222246 g007

4.3. Simulation of a Microgrid-Connected Inverter DT

The second case study analized in this paper focuses on the simulation of the developed Inverter DT. Specifically, the conducted simulations assess the model’s capability to detect multi-domain degradation during the execution of three distinct cyber-physical attack scenarios: Shoot-Through Injection (Hardware Fault/Short Circuit), Hybrid Harmonic Phase Manipulation (Grid Instability), and Hybrid Harmonic Frequency Tampering (Power Stress).
The inverter under analysis represents a single-phase half-bridge power inverter, built using commercial-grade Silicon (Si) semiconductor technology (such as standard IGBT or power MOSFET modules). From a grid perspective, the machine is classified as a low-voltage grid-connected or microgrid conversion unit designed to operate at a nominal fundamental frequency ( f nominal ) of 50 Hz . The core nominal characteristics of the system include:
  • DC Bus Voltage ( V DC ): 400   V (Nominal input voltage).
  • AC Output Frequency ( f nominal : 50   Hz (Standard utility frequency).
  • Carrier Switching Frequency ( f sw ): 5000   Hz (Sinusoidal Pulse Width Modulation).
  • Modulation Index ( m ): 0.95 .
  • Power Stage Technology: Silicon-based solid-state switches with a nominal on-state resistance ( R on ) of 50 m Ω and a calibrated switching energy loss ( E sw ) of 0.15 mJ per event.
  • Safety software protection: the inverter trips and isolates from the microgrid when the junction temperature exceeds 150°C.
The remaining Inverter DT characteristics are detailed above in Section 3.2.
Under nominal operating conditions ( T amb   = 25 ° C ), the heat evacuation mechanism from the power module to the surrounding environment is dominated by conductive and convective heat transfer, macroscopically modeled via a two-node lumped thermal resistance network comprising the junction-to-case resistance ( R jc = 0.5   K / W ) and the case-to-ambient resistance ( R ca = 0.8   K / W ); radiative heat transfer is assumed to be negligible or linearised within these parameters.
  • The transient response of the junction temperature ( T j ) exhibits a non-linear, asymptotic increase driven by the structural thermal time constants of the system:
  • Transient Phase: The temperature rises rapidly during the first 300   sec onds of the simulation, reflecting thermal energy accumulation within the power stage’s lumped thermal capacity ( C = 50   J / K ).
  • Steady-State Phase: Beyond 300   sec onds , the curve asymptotically stabilizes at a steady-state thermal equilibrium value of approximately 93 C .
This trajectory describes the formal attainment of thermal equilibrium for the power stage. At this state, a perfect balance is achieved between the total internal power dissipated—resulting from a combination of continuous conduction losses ( P cond ) and switching losses ( P sw )—and the thermal network’s ability to dissipate heat to the environment ( P cooling ):
P cooling = T j T amb R jc + R ca
Consequently, during this baseline operation (running unperturbed until the cyber-attack window opens at t = 400   s ), the device operates entirely within safe thermal limits well below the software protection trip threshold ( 150 C ), confirming that the cooling system is correctly sized for the applied nominal electrical load.
Unlike the transformer case study, an explicit parameter scaling is unnecessary in this framework. The inverter system is inherently fully scaled and balanced, as the nominal power dissipation mathematically aligns with the lumped thermal parameters ( R jc , R ca , and C ) to yield a realistic steady-state junction temperature of 93 C , achieved well within the 300-second transient window.
Figure 8. Baseline junction temperature profile of the inverter under normal operating conditions.
Figure 8. Baseline junction temperature profile of the inverter under normal operating conditions.
Preprints 222246 g008

4.3.1. Scenario 1: Short Circuit Attack

This scenario simulates the catastrophic physical breakdown triggered by a malicious cyber-attack on the inverter’s switching logic. While the system operates safely in nominal thermal equilibrium ( T j 93 C ) up to t = 400 s , the attack profile is activated at that exact millisecond via a dedicated pulse generator that manipulates the controller's logic into a shoot-through configuration. This unauthorized command completely overrides the standard, complementary pulse-width modulation (PWM) sequences, forcing both gate signals to become true simultaneously and commanding both power switches to close at the same moment.
Consequently, the 400 V DC bus is short-circuited directly to ground through the inverter leg. Because the resulting current path is limited only by a small 1   Ω parasitic resistance and the internal on-state resistance of the silicon modules, a massive electrical current surge immediately floods the power stage, causing conduction losses to explode quadratically.
This near-instantaneous thermal breakdown occurs because the massive short-circuit energy is injected directly into the silicon junction layer—where the local thermal capacity is virtually negligible compared to the lumped system capacity ( C = 50 J / K )—causing the local thermal time constant to plummet from 65 s to mere microseconds. The resulting thermal runaway is so violent that the junction temperature experiences a vertical surge, breaching the critical physical destruction threshold of 150 C almost within the same simulation step and the safety protection loop is triggered to prevent hardware damage.
Figure 9 illustrates this behavior, clearly capturing the transition from steady-state operation to catastrophic failure. Prior to the disruption (t < 400s), the curve confirms the nominal thermal equilibrium at 93°C. Immediately following the attack trigger, the plot displays a vertical, near-instantaneous temperature step, visually demonstrating how the thermal runaway outruns the microcontroller’s sampling execution to breach the critical failure threshold ( T c r i t > 150 °C) in a fraction of a second.
Figure 9. junction temperature profile of the inverter under short circuit attack.
Figure 9. junction temperature profile of the inverter under short circuit attack.
Preprints 222246 g009

4.3.2. Scenario 2: Hybrid Phase-Harmonic Attack

The “Hybrid Phase-Harmonic Attack” is a stealthy cyber-physical manipulation strategy designed to destabilize the inverter by compromising both its grid synchronization and its switching efficiency. Acting as a man-in-the-middle within the control loop, the attacker simultaneously injects a time-varying angular offset and a high-frequency harmonic disturbance into the reference signal [16].
This dual-layered manipulation induces the following critical effects:
  • Synchronization Instability: The angular offset creates a dynamic phase misalignment with the grid, inducing anomalous circulating currents that do not contribute to active power output but significantly increase power dissipation ( I 2 R o n ) within the switches.
  • Harmonic Stress Injection: The injected harmonic disturbance, synchronized with the switching frequency ( f s w ), forces the PWM controller to generate erratic switching patterns. This results in unintended high-frequency harmonic distortion, which exacerbates switching losses and increases thermal stress on the power semiconductors.
Unlike a shoot-through fault, this attack is subtle and difficult to detect via conventional overcurrent protection, as the system remains within nominal voltage and current margins while sustaining cumulative, non-linear thermal stress.
As illustrated in Figure 7, the system response is characterized by three distinct phases:
  • Pre-attack phase ( t < 400 s): The system follows the nominal heating curve, reaching a steady-state thermal equilibrium of approximately 93°C, defined by the balance between conduction/switching losses and the thermal network (R_jc = 0.5, R_ca = 0.8).
  • Trigger point ( t = 400 s): Upon activation of the attackPulse signal, an immediate increase in the heating rate is observed. The combined phase shift and harmonic injection force the PWM controller to increase the total power loss causing the junction temperature to rise from the nominal equilibrium.
  • Cumulative thermal effect ( 400 s < t < 900 s): The junction temperature exhibits a progressive thermal buildup, reaching a new, higher thermal plateau of approximately 104°C. This demonstrates that even with an intermittent attack, the system’s significant thermal time constant ( τ 65 s) prevents effective cooling between pulse cycles, leading to a dangerous accumulation of heat.
  • Recovery phase ( t > 900 s): Once the attack is deactivated, the junction temperature begins an asymptotic decline, returning toward the original nominal operating temperature as the excess energy is dissipated through the thermal resistance network
Figure 10. junction temperature profile of the inverter under Hybrid Phase attack.
Figure 10. junction temperature profile of the inverter under Hybrid Phase attack.
Preprints 222246 g010
Unlike the previously analyzed shoot-through fault, which represents an immediate, catastrophic hardware destruction within microseconds, the hybrid phase-harmonic attack operates as a stealth strategy of physical attrition. Instead of inducing an instantaneous blowout, the attacker aims to slowly degrade the converter while completely evading electrical protection routines.
This electrical evasion exploits the fundamental operating principles of conventional protection systems, which typically monitor peak currents or total active power anomalies. By introducing a subtle angular offset relative to the grid, the attacker induces phase misalignment, forcing the inverter to exchange non-productive circulating and reactive currents with the network. While the total current magnitude remains strictly within safe, sub-trip boundaries to avoid triggering standard overcurrent alarms, the increased current throughput passing through the MOSFETs/IGBTs silently drives up conduction losses ( P cond ).
This electrical manipulation is coupled with a sophisticated thermal deception that weaponizes the system's structural time constants. Because the attack profile is applied intermittently via periodic pulses, the junction temperature rises during the activation windows and attempts to decline during the pauses. However, due to the system's significant thermal inertia ( τ = 65   s ), the physical heat dissipation through the heatsink occurs at a much slower rate than the electrical excitation. When the attack pulses are delivered with a sufficiently tight repetition interval, the lumped thermal capacity fails to evacuate the trapped energy before the next cycle begins. This triggers a cumulative heat rectification effect, forcing the junction temperature to stabilize at a new, elevated thermal plateau of 104 C .
The long-term consequences of this thermal buildup are severe. Although this new equilibrium remains safely below the 150 C software protection trip threshold, operating the power semiconductor with a continuous 11 C overhead drastically accelerates thermal degradation. Over extended operating periods, this sustained thermal stress may induce severe thermo-mechanical fatigue, leading to irreversible structural failures such as solder joint delamination and wire-bond lifting, effectively destroying the power module without ever triggering a single software alarm.
  • Sensitivity Analysis for a Hybrid Phase-Harmonic Attack
To evaluate the precise physical impact of the previously described multi-vector attack, a comprehensive sensitivity analysis was conducted. This assessment maps the inverter's thermal response by systematically sweeping its two core control-domain manipulation variables: Harmonic Injection Amplitude and Phase Rate.
As previously noted, the Harmonic Injection Amplitude governs the intentional distortion of the fundamental sinewave within the current control loops, which elevates the root-mean-square (RMS) currents and subsequently inflates both conduction and switching losses within the semiconductors. Concurrently, the Phase Rate dictates the speed at which the attacker modulates the inverter’s phase angle relative to the utility grid, inducing a continuous, dynamic phase misalignment.
The resulting thermal sensitivity mapping, illustrated in the heatmap in Figure 11, reveals a highly non-linear relationship between these cyber-domain perturbations and physical-layer thermal degradation:
  • Baseline Regime (Harmonic Injection = 0.0): In the absence of harmonic manipulation, the inverter exhibits robust thermal stability. Varying the Phase Rate from 0.0 to 60.0 deg/s yields negligible temperature fluctuations, maintaining a safe baseline between 98.0°C and 98.5°C. This confirms that dynamic phase shifting alone does not compromise the hardware's thermal integrity.
  • Intermediate Exploitation & Auto-Mitigation (Harmonic Injection = 0.05 and 0.1): The introduction of harmonic noise shifts the system into a volatile state. Interestingly, at an amplitude of 0.05, a static phase shift (Phase Rate = 0.0 deg/s) induces severe localized stress, spiking the temperature to 107.6°C. However, as the Phase Rate increases toward 60.0 deg/s, the maximum temperature paradoxically decreases to 101.2°C. A similar cooling trend is visible at an amplitude of 0.1 (dropping from 106.8°C to 104.0°C). This indicates a localized "auto-mitigation" window where rapid phase variations introduce transient destructive interferences within the control loop, effectively distributing switching energy and disrupting localized heat accumulation.
  • Thermal Saturation Regime (Harmonic Injection = 0.2): At an aggressive attack amplitude of 0.2, this phase-driven mitigation mechanism completely breaks down. The system reaches thermal saturation, trapping severe energy across all operational states. The maximum temperature stabilizes at a critical plateau ranging from 106.2°C to 107.4°C, regardless of the Phase Rate.
The sensitivity matrix in Figure 11 ultimately proves that while intermediate multi-vector configurations trigger complex control-loop interactions, an aggressive, high-amplitude harmonic attack completely neutralizes phase-related dynamics, forcing the hardware to its absolute physical thermal limit.

5. Conclusions

This paper has presented a novel, multi-layered Cyber-Energy DT framework engineered to bridge the operational and conceptual gap between cybersecurity paradigms and high-fidelity energy asset modeling. By decoupling the absolute physical ground truth from the discretized measurement space, and formally embedding an Attack Layer as an endogenous mathematical variable within the signal transfer functions, the proposed methodology successfully captures the complex, non-linear propagation of cyber-physical vulnerabilities within critical infrastructure. The proposed methodology and related framework were rigorously validated in the Dymola/Modelica environment across two highly critical grid assets, specifically a 500 kVA oil-immersed power transformer operating at a nominal frequency of 50 Hz (2.3 kV to 230 V class) and a microgrid-connected photovoltaic inverter.
The numerical validation demonstrated how digital manipulations translate into concrete physical and thermal stress metrics—such as the rapid elevation of top-oil temperature in the power transformer and severe variations of the inverter (i.e. junction temperature). The framework successfully captured how these compromised states can either cause immediate, catastrophic structural failures or stealthily erode the asset's operational lifespan while remaining entirely undetected by conventional supervisory and monitoring systems.
Crucially, the integration of this specialized Cyber Stratum (Attack Layer) establishes a direct, previously missing mathematical link between predictive operational baselines (e.g., photovoltaic generation forecasting) and the characteristics of cyber-attacks In general, a DT can detect functional anomalies by comparing field data (coming from real physical sensors) with predictive data (the state estimation). The insertion of a specialized cyber-energy layer allows for a direct link between these predictive baselines and possible cyber-attacks, connecting the two phenomena in a way that currently does not exist in literature. Consequently, this Cyber Layer provides a framework to test the DT against a diverse range of cyber-attacks and to build comprehensive synthetic datasets specifically designed to train and refine the DT itself. Finally, the next fundamental step will be experimental validation using field data and hardware-in-the-loop co-simulation environments, combined with the integration of artificial intelligence algorithms for Anomaly Detection.

Author Contributions

Conceptualization: R.C.; methodology: R.C.; model implementation: R.C. a; data curation: R.C., M.V.; writing—review and editing: R.C., M.V. All authors have read and agreed to the published version of the manuscript.

Funding

This work has been funded by the Research Fund for the Italian Electrical through the project “Accordo di Programma 2025–2027—Project 2.1” between ENEA and the Ministry of the Environment and Energetic Safety (MASE).

Data Availability Statement

The data presented in this study are available on request from the corresponding author.

Acknowledgments

During the preparation of this work, the authors used Gemini (Google) in order to improve the English language, grammar, and overall readability of the manuscript. After using this tool/service, the authors reviewed and edited the content as needed and take full responsibility for the content of the publication.

Conflicts of Interest

The authors declare no conflict of interest.

References

  1. https://www.ibm.com/think/topics/digital-twin, Updated 17 October 2025, downloaded 01 June 2026.
  2. J.V.S. do Amaral, C.H. dos Santos, J.A.B. Montevechi, A.R. de Queiroz, Energy Digital Twin applications: A review, Renewable and Sustainable Energy Reviews, Volume 188, 2023, 113891, ISSN 1364-0321. [CrossRef]
  3. Ba, L.; Tangour, F.; El Abbassi, I.; Absi, R. Analysis of Digital Twin Applications in Energy Efficiency: A Systematic Review. Sustainability 2025, 17, 3560. [CrossRef]
  4. Kim, M.; Ghobadi, F.; Tayerani Charmchi, A.S.; Lee, M.; Lee, J. Digital Twins for Clean Energy Systems: A State-of-the-Art Review of Applications, Integrated Technologies, and Key Challenges. Sustainability 2026, 18, 43. [CrossRef]
  5. M. Singh, V. Yadav, D. S. Pal, M. A. Ansari, O. Singh and V. Patel, "Digital Twins for Predictive Maintenance in Renewable Energy Grids with Tokenized Transactions: A Review," 2025 International Conference on Cognitive Computing in Engineering, Communications, Sciences and Biomedical Health Informatics (IC3ECSBHI), Greater Noida, India, 2025, pp. 31-36. [CrossRef]
  6. Muhammed Cavus, Jing Jiang, Adib Allahham, Awagan Goyal Rameshrao, Eamon Scullion, Bruce D. Malamud, Hongjian Sun, Wai Pang Ng, Digital twins for hazard-resilient power grids: A systematic review and roadmap, Renewable and Sustainable Energy Reviews, Volume 235, 2026, 116947, ISSN 1364-0321. [CrossRef]
  7. Heluany, J.B., Gkioulos, V. A review on digital twins for power generation and distribution. Int. J. Inf. Secur. 23, 1171–1195 (2024). [CrossRef]
  8. Barreto, N.E.M.; Aoki, A.R. Cyber-Physical Power System Digital Twins—A Study on the State of the Art. Energies 2025, 18, 5960. [CrossRef]
  9. P. Palensky, P. Mancarella, T. Hardy and M. Cvetkovic, "Cosimulating Integrated Energy Systems With Heterogeneous Digital Twins: Matching a Connected World," in IEEE Power and Energy Magazine, vol. 22, no. 1, pp. 52-60, Jan.-Feb. 2024. [CrossRef]
  10. K. Pan, A. Teixeira, C. D. López and P. Palensky, "Co-simulation for cyber security analysis: Data attacks against energy management system," 2017 IEEE International Conference on Smart Grid Communications (SmartGridComm), Dresden, Germany, 2017, pp. 253-258. [CrossRef]
  11. Fan H, Wang H, Xia S, Li X, Xu P and Gao Y, Review of Modeling and Simulation Methods for Cyber Physical Power System. Front. Energy Res. 9:642997, 2021. [CrossRef]
  12. https://www.3ds.com/products/catia/dymola.
  13. Ciavarella R., Gradit G., Valenti M., Strasser T.I., Innovative Frequency Controls for Intelligent Power Systems, (2018) SPEEDAM 2018 - Proceedings: International Symposium on Power Electronics, Electrical Drives, Automation and Motion, art. no. 8445275, pp. 656 - 660. [CrossRef]
  14. IEEE Recommended Practice and Requirements for Harmonic Control in Electric Power Systems, IEEE Standard 519-2022, 2022.
  15. Voltage characteristics of electricity supplied by public distribution networks, European Standard EN 50160:2010, 2010.
  16. Graditi G., Ciavarella R., Valenti M., Ferruzzi G., Zizzo G., Frequency stability in microgrid: Control strategies and analysis of BESS aging effects, (2016) 2016 International Symposium on Power Electronics, Electrical Drives, Automation and Motion, SPEEDAM 2016, art. no. 7526033, pp. 295 - 299. [CrossRef]
Figure 1. architecture of the multi-layered Cyber-Energy DT framework.
Figure 1. architecture of the multi-layered Cyber-Energy DT framework.
Preprints 222246 g001
Figure 2. Transformer Cyber-Energy DT.
Figure 2. Transformer Cyber-Energy DT.
Preprints 222246 g002
Figure 3. Inverter Cyber-Energy DT.
Figure 3. Inverter Cyber-Energy DT.
Preprints 222246 g003
Figure 4. Oil temperature profile of the transformer under Fan Failure attack.
Figure 4. Oil temperature profile of the transformer under Fan Failure attack.
Preprints 222246 g004
Figure 5. Oil temperature profile of the transformer under Sensor masking attack with T sensorTampering = 6 ° C .
Figure 5. Oil temperature profile of the transformer under Sensor masking attack with T sensorTampering = 6 ° C .
Preprints 222246 g005
Figure 11. sensitivity map of the inverter under multi-vector attack.
Figure 11. sensitivity map of the inverter under multi-vector attack.
Preprints 222246 g011
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.
Copyright: This open access article is published under a Creative Commons CC BY 4.0 license, which permit the free download, distribution, and reuse, provided that the author and preprint are cited in any reuse.