Papers
Topics
Authors
Recent
Search
2000 character limit reached

Enhanced Load Redistribution Attack Model

Updated 12 July 2026
  • Enhanced load redistribution attack model is a family of cyber-physical strategies that manipulate load measurements and control signals, often causing cascading failures and economic impacts.
  • The models extend traditional load attacks by incorporating dynamic, interdependent, and renewable-aware formulations to exploit vulnerabilities in state estimation and dispatch decisions.
  • Recent work highlights that adaptive defenses, game-theoretic strategies, and advanced detection mechanisms are essential to mitigate these sophisticated attack scenarios.

Enhanced load redistribution attack model denotes a class of cyber-physical attack formulations in which an adversary manipulates load measurements, load-bearing components, or load-responsive devices so that redistribution mechanisms, dispatch decisions, or protection delays produce overloads, cascading failures, uneconomic dispatch, blackout conditions, or privacy leakage. In the cited literature, the underlying mechanisms range from equal and partial load redistribution in mean-field flow networks to DC state-estimation false data injection, dynamic load-altering attacks on IoT-enabled loads, solar-aware security-constrained economic dispatch distortion, and bilevel attacks on integrated electricity-gas systems (Ozel et al., 2018, Ozel et al., 2018, Verma et al., 16 Sep 2025, Goodridge et al., 2023, Liu et al., 2023). This suggests that the topic is best understood as a family of related models rather than a single canonical formalism.

1. Classical core and conceptual scope

At transmission level, a classical load redistribution attack is a false data injection attack that changes estimated bus loads while preserving total system load and keeping the corrupted measurements consistent with the state-estimation model. In one standard formulation,

PAtk=P+ΔP,∑iΔPi=0,\boldsymbol{P}_{\text{Atk}} = \boldsymbol{P} + \Delta \boldsymbol{P}, \qquad \sum_i \Delta P_i = 0,

and, under the DC model,

ΔP=−Bc,a=Hc,\Delta \boldsymbol{P} = -\boldsymbol{B}\boldsymbol{c}, \qquad \mathbf{a} = \mathbf{H}\mathbf{c},

so the attack remains unobservable to the conventional bad data detector because the attack vector lies in the column space of the measurement matrix (Chu et al., 2020, Kaviani et al., 2019). In PTDF-based formulations, the attacker redistributes loads subject to per-bus bounds and net-load conservation to maximize flow on a target line:

max⁡ ±∑i∈N(Hi′c)PTDFl,iR,\max \ \pm \sum_{i \in N} \left(\mathbf{H_i^\prime c}\right) PTDF_{l,i}^R,

with

−αLi≤Hi′c≤αLi,∑i∈NHi′c=0-\alpha L_i \le \mathbf{H_i^\prime c} \le \alpha L_i, \qquad \sum_{i\in N}\mathbf{H_i^\prime c}=0

(Kaviani et al., 2019).

A broader line of work studies redistribution attacks in flow-network abstractions where the attacked objects are lines rather than measurements. There, each line ii has load LiL_i, free-space SiS_i, and capacity

Ci=Li+Si,C_i = L_i + S_i,

and failures trigger equal redistribution of the failed load over all surviving lines (Ozel et al., 2018, Gulcu et al., 2018). Another strand treats load-altering attacks on IoT-enabled devices, where an attacker directly changes physical demand instead of falsifying telemetry. In that setting, a static load-altering attack is a one-shot disturbance, whereas a dynamic load-altering attack is a sequence of disturbances at times tk=kIt_k=kI, often driven by the real-time frequency response of the grid (Goodridge et al., 2023). A plausible implication is that “load redistribution” now covers both cyber-only measurement attacks and cyber-physical manipulation of actual demand.

2. Mean-field redistribution and cascading-failure formulations

In mean-field flow-network models, the post-attack cascade is determined by how failed load is redistributed and how much free-space remains. Under max-load targeted attack, the largest-load pp-fraction of lines is removed at ΔP=−Bc,a=Hc,\Delta \boldsymbol{P} = -\boldsymbol{B}\boldsymbol{c}, \qquad \mathbf{a} = \mathbf{H}\mathbf{c},0; if ΔP=−Bc,a=Hc,\Delta \boldsymbol{P} = -\boldsymbol{B}\boldsymbol{c}, \qquad \mathbf{a} = \mathbf{H}\mathbf{c},1, then the average extra load generated by the initial targeted attack is

ΔP=−Bc,a=Hc,\Delta \boldsymbol{P} = -\boldsymbol{B}\boldsymbol{c}, \qquad \mathbf{a} = \mathbf{H}\mathbf{c},2

and the extra load per surviving line is

ΔP=−Bc,a=Hc,\Delta \boldsymbol{P} = -\boldsymbol{B}\boldsymbol{c}, \qquad \mathbf{a} = \mathbf{H}\mathbf{c},3

A surviving line then fails at the next stage if

ΔP=−Bc,a=Hc,\Delta \boldsymbol{P} = -\boldsymbol{B}\boldsymbol{c}, \qquad \mathbf{a} = \mathbf{H}\mathbf{c},4

and the final surviving fraction satisfies the upper bound

ΔP=−Bc,a=Hc,\Delta \boldsymbol{P} = -\boldsymbol{B}\boldsymbol{c}, \qquad \mathbf{a} = \mathbf{H}\mathbf{c},5

Under the paper’s assumptions, the optimal robustness against max-load targeted attack is achieved by equal free-space allocation,

ΔP=−Bc,a=Hc,\Delta \boldsymbol{P} = -\boldsymbol{B}\boldsymbol{c}, \qquad \mathbf{a} = \mathbf{H}\mathbf{c},6

rather than proportional allocation to heavily loaded lines (Ozel et al., 2018).

Partial redistribution introduces an absorption parameter ΔP=−Bc,a=Hc,\Delta \boldsymbol{P} = -\boldsymbol{B}\boldsymbol{c}, \qquad \mathbf{a} = \mathbf{H}\mathbf{c},7. When a line fails due to overloading, a ΔP=−Bc,a=Hc,\Delta \boldsymbol{P} = -\boldsymbol{B}\boldsymbol{c}, \qquad \mathbf{a} = \mathbf{H}\mathbf{c},8-fraction of the load it was carrying is redistributed equally among all remaining lines and an ΔP=−Bc,a=Hc,\Delta \boldsymbol{P} = -\boldsymbol{B}\boldsymbol{c}, \qquad \mathbf{a} = \mathbf{H}\mathbf{c},9-fraction is lost or absorbed. With random attack size max⁡ ±∑i∈N(Hi′c)PTDFl,iR,\max \ \pm \sum_{i \in N} \left(\mathbf{H_i^\prime c}\right) PTDF_{l,i}^R,0, the initial extra load per surviving line is

max⁡ ±∑i∈N(Hi′c)PTDFl,iR,\max \ \pm \sum_{i \in N} \left(\mathbf{H_i^\prime c}\right) PTDF_{l,i}^R,1

and the final alive fraction is denoted max⁡ ±∑i∈N(Hi′c)PTDFl,iR,\max \ \pm \sum_{i \in N} \left(\mathbf{H_i^\prime c}\right) PTDF_{l,i}^R,2. The paper shows that partial redistribution can change the order of transition at the critical attack size max⁡ ±∑i∈N(Hi′c)PTDFl,iR,\max \ \pm \sum_{i \in N} \left(\mathbf{H_i^\prime c}\right) PTDF_{l,i}^R,3 from first to second-order, while equal free-space allocation still maximizes the robustness area

max⁡ ±∑i∈N(Hi′c)PTDFl,iR,\max \ \pm \sum_{i \in N} \left(\mathbf{H_i^\prime c}\right) PTDF_{l,i}^R,4

(Ozel et al., 2018).

Interdependent flow networks extend the same logic across two systems max⁡ ±∑i∈N(Hi′c)PTDFl,iR,\max \ \pm \sum_{i \in N} \left(\mathbf{H_i^\prime c}\right) PTDF_{l,i}^R,5 and max⁡ ±∑i∈N(Hi′c)PTDFl,iR,\max \ \pm \sum_{i \in N} \left(\mathbf{H_i^\prime c}\right) PTDF_{l,i}^R,6. When a line fails in max⁡ ±∑i∈N(Hi′c)PTDFl,iR,\max \ \pm \sum_{i \in N} \left(\mathbf{H_i^\prime c}\right) PTDF_{l,i}^R,7, an max⁡ ±∑i∈N(Hi′c)PTDFl,iR,\max \ \pm \sum_{i \in N} \left(\mathbf{H_i^\prime c}\right) PTDF_{l,i}^R,8-fraction of its load is redistributed to alive lines in max⁡ ±∑i∈N(Hi′c)PTDFl,iR,\max \ \pm \sum_{i \in N} \left(\mathbf{H_i^\prime c}\right) PTDF_{l,i}^R,9 and a −αLi≤Hi′c≤αLi,∑i∈NHi′c=0-\alpha L_i \le \mathbf{H_i^\prime c} \le \alpha L_i, \qquad \sum_{i\in N}\mathbf{H_i^\prime c}=00-fraction stays in −αLi≤Hi′c≤αLi,∑i∈NHi′c=0-\alpha L_i \le \mathbf{H_i^\prime c} \le \alpha L_i, \qquad \sum_{i\in N}\mathbf{H_i^\prime c}=01; failures in −αLi≤Hi′c≤αLi,∑i∈NHi′c=0-\alpha L_i \le \mathbf{H_i^\prime c} \le \alpha L_i, \qquad \sum_{i\in N}\mathbf{H_i^\prime c}=02 are treated symmetrically with parameter −αLi≤Hi′c≤αLi,∑i∈NHi′c=0-\alpha L_i \le \mathbf{H_i^\prime c} \le \alpha L_i, \qquad \sum_{i\in N}\mathbf{H_i^\prime c}=03. If random attack removes −αLi≤Hi′c≤αLi,∑i∈NHi′c=0-\alpha L_i \le \mathbf{H_i^\prime c} \le \alpha L_i, \qquad \sum_{i\in N}\mathbf{H_i^\prime c}=04-fraction of lines in −αLi≤Hi′c≤αLi,∑i∈NHi′c=0-\alpha L_i \le \mathbf{H_i^\prime c} \le \alpha L_i, \qquad \sum_{i\in N}\mathbf{H_i^\prime c}=05 and −αLi≤Hi′c≤αLi,∑i∈NHi′c=0-\alpha L_i \le \mathbf{H_i^\prime c} \le \alpha L_i, \qquad \sum_{i\in N}\mathbf{H_i^\prime c}=06-fraction in −αLi≤Hi′c≤αLi,∑i∈NHi′c=0-\alpha L_i \le \mathbf{H_i^\prime c} \le \alpha L_i, \qquad \sum_{i\in N}\mathbf{H_i^\prime c}=07, the initial extra loads are

−αLi≤Hi′c≤αLi,∑i∈NHi′c=0-\alpha L_i \le \mathbf{H_i^\prime c} \le \alpha L_i, \qquad \sum_{i\in N}\mathbf{H_i^\prime c}=08

−αLi≤Hi′c≤αLi,∑i∈NHi′c=0-\alpha L_i \le \mathbf{H_i^\prime c} \le \alpha L_i, \qquad \sum_{i\in N}\mathbf{H_i^\prime c}=09

and the final surviving fractions are

ii0

The model exhibits interesting transition behavior: the final collapse is always first-order, but it can be preceded by a sequence of first and second-order transitions, and robustness is maximized at non-trivial ii1 values in general (Zhang et al., 2017). This directly enlarges the attack surface: cross-network coupling can amplify or buffer the effect of a given initial shock.

3. Transmission-level optimization and economic attack objectives

In transmission LR attacks, the central optimization problem is to choose load perturbations that remain stealthy yet induce damaging redispatch. A core PTDF formulation maximizes target-line loading under load-shift bounds and net-load conservation (Kaviani et al., 2019). More elaborate models embed the system operator’s DCOPF or SCED as a lower-level problem, producing a bilevel attacker-defender optimization. For cost-maximization and line-overflow attacks, the lower level solves dispatch under attacked loads, generator limits, and line limits, while the upper level chooses the attack vector subject to

ii2

A salient empirical result is that intelligently designed LR attacks are more detectable than random attacks at the same ii3, because they deviate more strongly from learned spatial-temporal patterns; with the SVR+SVM framework, detection probability for cost-maximization and line-overflow attacks is approximately ii4 for ii5 (Chu et al., 2020).

The solar-aware extension relaxes the traditional assumption that generator-side measurements are secure. The attacker now chooses both a load deviation vector ii6 and a solar generation deviation vector ii7, with line-flow deviations

ii8

subject to

ii9

Solar output is time-varying through irradiance, so attack leverage varies over the day. On the IEEE 118-bus system, the proposed enhanced model with solar manipulation reaches a post-attack cost of LiL_i0, and LiL_i1 MW load shedding at peak solar, whereas at night the model reduces to a standard load-only LR attack (Verma et al., 16 Sep 2025). This explicitly extends LR from load-only spatial reshaping to coordinated generation-load falsification.

Integrated electricity-gas systems generalize the same bilevel structure to coupled energy carriers. The upper level attacks falsified electricity loads LiL_i2 and gas loads LiL_i3, while the lower level minimizes total operating cost over power generation, gas well outputs, unit commitment, power and gas load shedding, DC power flow, gas nodal balance, compressor constraints, and a piecewise-linear approximation of the Weymouth equation. Under a mild assumption, the model does not exclude any possible upper-level attack, because the lower-level feasible region is always nonempty after adding unit commitment and full-shedding recourse (Liu et al., 2023). In the 39-bus/20-node case, the attack raises operating cost from LiL_i4, and in a tighter-gas-transmission scenario to a LiL_i5 increase (Liu et al., 2023). A plausible implication is that “enhancement” in LR modeling increasingly means economic co-optimization over coupled infrastructures rather than only physical overload on a single electric network.

4. Dynamic, topology-aware, and distribution-level extensions

Dynamic load-altering attacks replace one-shot falsification with closed-loop temporal control. In the three-area IEEE-39 bus analysis, the attacker applies impulses at times LiL_i6 and updates the load change using a reverse-governor law driven by local frequency:

LiL_i7

The resulting cascades combine under-frequency load shedding, RoCoF-induced generation shedding, over-frequency generation shedding, and line disconnections. The paper identifies two vulnerable regimes: small magnitude but rapid dynamic attacks with LiL_i8, average cascade size LiL_i9 MW, and SiS_i0 MW; and large magnitude but static attacks with SiS_i1, average cascade size SiS_i2 MW, requiring SiS_i3 MW (Goodridge et al., 2023). This is an explicit enhancement from static load redistribution to time-dependent destabilization.

A second dynamic extension targets voltage instability through HVAC manipulation. In the AC-power-flow model, the attacker falsifies temperature readings so that

SiS_i4

then selects the most unstable bus using

SiS_i5

The attack is defined as a stealthy load alteration sequence that drives voltage toward collapse while keeping

SiS_i6

until just before blackout. The interaction with the adaptive voltage protection system is posed as a zero-sum Stackelberg game,

SiS_i7

with DDPG for the attacker and Q-learning/DQN for the defender (B. et al., 2024). On IEEE 14-bus with HIL, a temperature manipulation at bus 3 around the 2-minute HVAC peak increases power by SiS_i8 MW, drives the bus-3 voltage near SiS_i9 at Ci=Li+Si,C_i = L_i + S_i,0 minutes under static protection, and is mitigated by the adaptive scheme before blackout (B. et al., 2024).

Distribution-level models shift the focus from transmission LR to radial distribution networks with voltage-dependent ZIP or ZP loads and switchable topology. In the LinDistFlow approximation, attacks increase active and reactive power at targeted buses, and closed-form formulas show that attacks launched on the deepest nodes in the distribution network have the most detrimental effect on the grid voltage profile (Maleki et al., 2024). The resulting attacker-defender interaction is formulated as a Stackelberg game in which the attacker chooses the attacked bus and the defender reconfigures the network subject to radiality, connectivity, flow, and voltage constraints (Maleki et al., 2024). This suggests that topology-aware “enhancement” is not limited to transmission PTDF structure; it also includes path-depth sensitivity and reconfiguration-aware attack design in radial feeders.

5. Detection, privacy, and adaptive defense

A substantial part of the literature enhances LR models by making detection and internal adversaries explicit. One line of work uses nearest-neighbor anomaly detection in load space, with group-wise nearest-neighbor distances

Ci=Li+Si,C_i = L_i + S_i,1

and thresholds Ci=Li+Si,C_i = L_i + S_i,2, then labels a load vector anomalous if any group raises an alarm. A subsequent localization stage assigns each load a risk measure Ci=Li+Si,C_i = L_i + S_i,3, interpreted as the posterior likelihood that the load is attacked, and fits conditional likelihood functions by minimizing average log-loss (Pinceti et al., 2019). Another line combines a multi-output SVR load predictor with an SVM detector: the SVR predicts Ci=Li+Si,C_i = L_i + S_i,4 from spatial and temporal features, and the SVM classifies

Ci=Li+Si,C_i = L_i + S_i,5

which then supports mitigation by redispatching with SVR-predicted loads (Chu et al., 2020). A physics-based detector instead leverages the greedy PTDF structure of the LR optimization problem, counts the Number of Proper Deviations at Sensitive Buses, and flags attacks when the ratio NPDSB/TNSB exceeds a threshold such as Ci=Li+Si,C_i = L_i + S_i,6 (Kaviani et al., 2019). A common misconception is that unobservable LR attacks are therefore undetectable in practice; the cited work shows that they evade residual-based BDDs but remain vulnerable to topology-aware, data-driven, or physics-informed detectors (Kaviani et al., 2019, Pinceti et al., 2019, Chu et al., 2020).

Privacy-centric smart-grid models extend the same attack surface from integrity to collusion. In E-DPNCT, each smart meter adds DP noise, splits it into Ci=Li+Si,C_i = L_i + S_i,7 partial noises using a Dirichlet distribution, and sends the shares to multiple master smart meters. A successful collusion attack on meter Ci=Li+Si,C_i = L_i + S_i,8 at time Ci=Li+Si,C_i = L_i + S_i,9 requires aggregator access to tk=kIt_k=kI0 and all tk=kIt_k=kI1 partial noises, so if the malicious-meter fraction is tk=kIt_k=kI2, the probability that all chosen MSMs are malicious is

tk=kIt_k=kI3

The paper reports that for tk=kIt_k=kI4 meters and tk=kIt_k=kI5 malicious meters, tk=kIt_k=kI6 MSMs suffice to keep leakage below tk=kIt_k=kI7, while for tk=kIt_k=kI8 malicious meters, tk=kIt_k=kI9 are needed for the same leakage target (Hafeez et al., 2021). The model focuses on collusion-based privacy attacks, but it explicitly points toward data integrity attacks, which are described as a natural setting for load redistribution attacks (Hafeez et al., 2021). This expands the meaning of enhancement: the attacker may control not only EMS measurements but also smart meters, aggregators, and privacy-noise channels.

Adaptive defenses increasingly take game-theoretic form. The adaptive voltage protection system learns threshold policies against a DRL load alteration adversary (B. et al., 2024), while distribution-system reconfiguration solves a Stackelberg equilibrium that minimizes voltage deviation and switching cost under attack localization uncertainty (Maleki et al., 2024). These defenses do not eliminate LR-style attack models; rather, they redefine them as sequential games over thresholds, topology, and uncertainty sets.

6. Metrics, synthesis, and research directions

Across the literature, enhanced LR models are evaluated with several non-equivalent metrics. Cascading-failure models use the final surviving fraction pp0, the critical attack size pp1, or the robustness area

pp2

(Ozel et al., 2018, Ozel et al., 2018). Dynamic load-altering models use cascade size pp3, average network load change pp4, blackout occurrence, or false-positive behavior under noisy conditions (Goodridge et al., 2023, B. et al., 2024). Transmission and multi-energy LR models use post-attack SCED or dispatch cost, overload magnitude, and load shedding (Verma et al., 16 Sep 2025, Liu et al., 2023). Privacy-oriented smart-grid models use percentage of leaked data, billing MAE, load-monitoring MAE, and correlation between original and masked load profiles (Hafeez et al., 2021). This suggests that “severity” depends on whether the model’s target is physical collapse, economic damage, cyber stealth, or data leakage.

Several recurring enhancements define the present state of the topic. One is the move from random or static attacks to targeted and adaptive attacks: max-load targeted removal in flow networks, PTDF-targeted FDI in EMSs, FVSI-guided HVAC load alteration, and worst-case bilevel LR attacks in IEGSs (Ozel et al., 2018, Kaviani et al., 2019, B. et al., 2024, Liu et al., 2023). Another is the move from isolated electric networks to interdependent and renewable-rich infrastructures, where partial redistribution, solar measurement manipulation, and electricity-gas coupling alter both feasible attack sets and optimal defensive policies (Ozel et al., 2018, Zhang et al., 2017, Verma et al., 16 Sep 2025, Liu et al., 2023). A third is the incorporation of imperfect information: inaccurate admittance values most often lead to suboptimal cyber-attacks that still compromise the grid security, while inaccurate capacity values result in notably less effective attacks, and common attacked cyber-assets and common affected physical-assets appear repeatedly across imperfect attacks (Karangelos et al., 2021).

A plausible implication is that no single mathematical backbone dominates every enhanced model. Mean-field order statistics and concavity arguments remain central when equal redistribution or partial redistribution is assumed; PTDF- and DCOPF-based bilevel models remain central when the objective is economic manipulation; AC power flow, FVSI, and temporal control become central when voltage instability and blackout induction are targeted; and piecewise-linear gas physics become essential in multi-energy settings (Ozel et al., 2018, Verma et al., 16 Sep 2025, B. et al., 2024, Liu et al., 2023). What unifies these formulations is the strategic use of redistribution—of failed load, measured load, apparent generation, or responsive demand—to induce a downstream system response that is damaging, difficult to detect, or both.

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to Enhanced Load Redistribution Attack Model.