---
title: Enhanced Load Redistribution Attack Model
url: https://www.emergentmind.com/topics/enhanced-load-redistribution-attack-model
type: topic
---

# Enhanced Load Redistribution Attack Model

Enhanced load redistribution attack model denotes a class of cyber-physical attack formulations in which an adversary manipulates load measurements, load-bearing components, or load-responsive devices so that redistribution mechanisms, dispatch decisions, or protection delays produce overloads, cascading failures, uneconomic dispatch, blackout conditions, or privacy leakage. In the cited literature, the underlying mechanisms range from equal and partial load redistribution in mean-field flow networks to DC state-estimation false data injection, dynamic load-altering attacks on IoT-enabled loads, solar-aware security-constrained economic dispatch distortion, and bilevel attacks on integrated electricity-gas systems [1811.08070][1802.07664][2509.13567][2306.06511][2312.16712]. This suggests that the topic is best understood as a family of related models rather than a single canonical formalism.

## 1. Classical core and conceptual scope

At transmission level, a classical load redistribution attack is a false data injection attack that changes estimated bus loads while preserving total system load and keeping the corrupted measurements consistent with the state-estimation model. In one standard formulation,
$$
\boldsymbol{P}_{\text{Atk}} = \boldsymbol{P} + \Delta \boldsymbol{P}, \qquad \sum_i \Delta P_i = 0,
$$
and, under the DC model,
$$
\Delta \boldsymbol{P} = -\boldsymbol{B}\boldsymbol{c}, \qquad \mathbf{a} = \mathbf{H}\mathbf{c},
$$
so the attack remains unobservable to the conventional bad data detector because the attack vector lies in the column space of the measurement matrix [2003.06543][1907.13294]. In PTDF-based formulations, the attacker redistributes loads subject to per-bus bounds and net-load conservation to maximize flow on a target line:
$$
\max \ \pm \sum_{i \in N} \left(\mathbf{H_i^\prime c}\right) PTDF_{l,i}^R,
$$
with
$$
-\alpha L_i \le \mathbf{H_i^\prime c} \le \alpha L_i, \qquad \sum_{i\in N}\mathbf{H_i^\prime c}=0
$$
[1907.13294].

A broader line of work studies redistribution attacks in flow-network abstractions where the attacked objects are lines rather than measurements. There, each line \(i\) has load \(L_i\), free-space \(S_i\), and capacity
$$
C_i = L_i + S_i,
$$
and failures trigger equal redistribution of the failed load over all surviving lines [1811.08070][1804.01351]. Another strand treats load-altering attacks on IoT-enabled devices, where an attacker directly changes physical demand instead of falsifying telemetry. In that setting, a static load-altering attack is a one-shot disturbance, whereas a dynamic load-altering attack is a sequence of disturbances at times \(t_k=kI\), often driven by the real-time frequency response of the grid [2306.06511]. A plausible implication is that “load redistribution” now covers both cyber-only measurement attacks and cyber-physical manipulation of actual demand.

## 2. Mean-field redistribution and cascading-failure formulations

In mean-field flow-network models, the post-attack cascade is determined by how failed load is redistributed and how much free-space remains. Under max-load targeted attack, the largest-load \(p\)-fraction of lines is removed at \(t=0\); if \(L_i\sim U[0,1]\), then the average extra load generated by the initial targeted attack is
$$
Q_0(p) = p - \frac{p^2}{2},
$$
and the extra load per surviving line is
$$
F(p) = \frac{Q_0(p)}{1-p}.
$$
A surviving line then fails at the next stage if
$$
L_i + F(p) \ge L_i + S_i \quad \Longleftrightarrow \quad S_i \le F(p),
$$
and the final surviving fraction satisfies the upper bound
$$
n_\infty(p) \le (1-p)\,\mathbb{P}[S \ge F(p)].
$$
Under the paper’s assumptions, the optimal robustness against max-load targeted attack is achieved by equal free-space allocation,
$$
S_i^* = S_B,
$$
rather than proportional allocation to heavily loaded lines [1811.08070].

Partial redistribution introduces an absorption parameter \(\varepsilon\in[0,1]\). When a line fails due to overloading, a \((1-\varepsilon)\)-fraction of the load it was carrying is redistributed equally among all remaining lines and an \(\varepsilon\)-fraction is lost or absorbed. With random attack size \(p\), the initial extra load per surviving line is
$$
Q_0 = \mathbb{E}[L]\frac{p}{1-p},
$$
and the final alive fraction is denoted \(n_\infty(p,\varepsilon)\). The paper shows that partial redistribution can change the order of transition at the critical attack size \(p^{*}\) from first to second-order, while equal free-space allocation still maximizes the robustness area
$$
\mathcal{R}(\varepsilon) = \int_0^1 n_\infty(p,\varepsilon)\,dp
$$
[1802.07664].

Interdependent flow networks extend the same logic across two systems \(A\) and \(B\). When a line fails in \(A\), an \(a\)-fraction of its load is redistributed to alive lines in \(B\) and a \((1-a)\)-fraction stays in \(A\); failures in \(B\) are treated symmetrically with parameter \(b\). If random attack removes \(p_1\)-fraction of lines in \(A\) and \(p_2\)-fraction in \(B\), the initial extra loads are
$$
Q_{0,A} = \frac{(1-a)\mathbb{E}[L_A]p_1 + b\mathbb{E}[L_B]p_2}{1-p_1},
$$
$$
Q_{0,B} = \frac{a\mathbb{E}[L_A]p_1 + (1-b)\mathbb{E}[L_B]p_2}{1-p_2},
$$
and the final surviving fractions are
$$
n_{\infty,A} = (1-p_1)\mathbb{P}[S_A>Q_A^\star], \qquad
n_{\infty,B} = (1-p_2)\mathbb{P}[S_B>Q_B^\star].
$$
The model exhibits interesting transition behavior: the final collapse is always first-order, but it can be preceded by a sequence of first and second-order transitions, and robustness is maximized at non-trivial \(a,b\) values in general [1709.01651]. This directly enlarges the attack surface: cross-network coupling can amplify or buffer the effect of a given initial shock.

## 3. Transmission-level optimization and economic attack objectives

In transmission LR attacks, the central optimization problem is to choose load perturbations that remain stealthy yet induce damaging redispatch. A core PTDF formulation maximizes target-line loading under load-shift bounds and net-load conservation [1907.13294]. More elaborate models embed the system operator’s DCOPF or SCED as a lower-level problem, producing a bilevel attacker-defender optimization. For cost-maximization and line-overflow attacks, the lower level solves dispatch under attacked loads, generator limits, and line limits, while the upper level chooses the attack vector subject to
$$
-\tau \boldsymbol{P} \le \boldsymbol{B}\boldsymbol{c} \le \tau \boldsymbol{P}.
$$
A salient empirical result is that intelligently designed LR attacks are more detectable than random attacks at the same \(\tau\), because they deviate more strongly from learned spatial-temporal patterns; with the SVR+SVM framework, detection probability for cost-maximization and line-overflow attacks is approximately \(100\%\) for \(\tau \ge 4\%\) [2003.06543].

The solar-aware extension relaxes the traditional assumption that generator-side measurements are secure. The attacker now chooses both a load deviation vector \(\Delta\mathbf{D}\) and a solar generation deviation vector \(\Delta\mathbf{R}\), with line-flow deviations
$$
\Delta f_l = \mathbf{S}_l \cdot \mathbf{U} \cdot \Delta\mathbf{R}
             - \mathbf{S}_l \cdot \mathbf{V} \cdot \Delta\mathbf{D},
$$
subject to
$$
\mathbf{1}^T \Delta\mathbf{D} = 0, \qquad \mathbf{1}^T \Delta\mathbf{R} = 0.
$$
Solar output is time-varying through irradiance, so attack leverage varies over the day. On the IEEE 118-bus system, the proposed enhanced model with solar manipulation reaches a post-attack cost of \(1.595 \times 10^5 \,\$/h\), a cost increase of \(24.1 \times 10^3 \,\$/h\), and \(126\) MW load shedding at peak solar, whereas at night the model reduces to a standard load-only LR attack [2509.13567]. This explicitly extends LR from load-only spatial reshaping to coordinated generation-load falsification.

Integrated electricity-gas systems generalize the same bilevel structure to coupled energy carriers. The upper level attacks falsified electricity loads \(\Delta P_d\) and gas loads \(\Delta G_d\), while the lower level minimizes total operating cost over power generation, gas well outputs, unit commitment, power and gas load shedding, DC power flow, gas nodal balance, compressor constraints, and a piecewise-linear approximation of the Weymouth equation. Under a mild assumption, the model does not exclude any possible upper-level attack, because the lower-level feasible region is always nonempty after adding unit commitment and full-shedding recourse [2312.16712]. In the 39-bus/20-node case, the attack raises operating cost from \(\$43847.2\) to \(\$50559.0\), and in a tighter-gas-transmission scenario to a \(25.6\%\) increase [2312.16712]. A plausible implication is that “enhancement” in LR modeling increasingly means economic co-optimization over coupled infrastructures rather than only physical overload on a single electric network.

## 4. Dynamic, topology-aware, and distribution-level extensions

Dynamic load-altering attacks replace one-shot falsification with closed-loop temporal control. In the three-area IEEE-39 bus analysis, the attacker applies impulses at times \(t_k=kI\) and updates the load change using a reverse-governor law driven by local frequency:
$$
\Delta_i(t_k) =
\begin{cases}
- P_{L,i,\max} + C \omega_i(t_k), & \text{if } L_- - C\omega_i(t_k)\in [0,P_{L,i,\max}],\\
P_{L,i,\max}, & \text{if } L_- - C\omega_i(t_k) > P_{L,i,\max},\\
0, & \text{if } L_- - C\omega_i(t_k) < 0.
\end{cases}
$$
The resulting cascades combine under-frequency load shedding, RoCoF-induced generation shedding, over-frequency generation shedding, and line disconnections. The paper identifies two vulnerable regimes: small magnitude but rapid dynamic attacks with \(I<10\,\mathrm{s}\), average cascade size \(\approx 9{,}000\) MW, and \(p(X)\ge 300\) MW; and large magnitude but static attacks with \(I>50\,\mathrm{s}\), average cascade size \(\approx 4{,}000\) MW, requiring \(p(X)\gtrsim 1{,}550\) MW [2306.06511]. This is an explicit enhancement from static load redistribution to time-dependent destabilization.

A second dynamic extension targets voltage instability through HVAC manipulation. In the AC-power-flow model, the attacker falsifies temperature readings so that
$$
\Delta P_i^{(t)} = k\,\Delta T_i^{(t)},
$$
then selects the most unstable bus using
$$
(i^\*,j^\*) = \arg\max_{i,j} FVSI_{ij}.
$$
The attack is defined as a stealthy load alteration sequence that drives voltage toward collapse while keeping
$$
V_{Th_i}^l \le |V_i^{(t)}| \le V_{Th_i}^u, \qquad
59.5 \le f^{(t)} \le 60.5
$$
until just before blackout. The interaction with the adaptive voltage protection system is posed as a zero-sum Stackelberg game,
$$
\pi^*_{laa}, \pi^*_{avps}
=
\underset{\pi_{avps}}{\arg\min}\;
\underset{\pi_{laa}}{\arg\max}\;
\mathbb{E}\!\left[\sum_{t=1}^{L}\gamma^t
f(s^{(t)},a_{laa}^{(t)},a_{avps}^{(t)})\right],
$$
with DDPG for the attacker and Q-learning/DQN for the defender [2411.15229]. On IEEE 14-bus with HIL, a temperature manipulation at bus 3 around the 2-minute HVAC peak increases power by \(\sim 4\) MW, drives the bus-3 voltage near \(0\) at \(\sim 2.1\) minutes under static protection, and is mitigated by the adaptive scheme before blackout [2411.15229].

Distribution-level models shift the focus from transmission LR to radial distribution networks with voltage-dependent ZIP or ZP loads and switchable topology. In the LinDistFlow approximation, attacks increase active and reactive power at targeted buses, and closed-form formulas show that attacks launched on the deepest nodes in the distribution network have the most detrimental effect on the grid voltage profile [2407.07065]. The resulting attacker-defender interaction is formulated as a Stackelberg game in which the attacker chooses the attacked bus and the defender reconfigures the network subject to radiality, connectivity, flow, and voltage constraints [2407.07065]. This suggests that topology-aware “enhancement” is not limited to transmission PTDF structure; it also includes path-depth sensitivity and reconfiguration-aware attack design in radial feeders.

## 5. Detection, privacy, and adaptive defense

A substantial part of the literature enhances LR models by making detection and internal adversaries explicit. One line of work uses nearest-neighbor anomaly detection in load space, with group-wise nearest-neighbor distances
$$
d_j = \min_r \|\mathbf{p}^j - \mathbf{h}_r^j\|_2
$$
and thresholds \(\tau_j\), then labels a load vector anomalous if any group raises an alarm. A subsequent localization stage assigns each load a risk measure \(q_l\), interpreted as the posterior likelihood that the load is attacked, and fits conditional likelihood functions by minimizing average log-loss [1912.09453]. Another line combines a multi-output SVR load predictor with an SVM detector: the SVR predicts \(\hat{\boldsymbol{P}}\) from spatial and temporal features, and the SVM classifies
$$
\boldsymbol{u}_j =
[mo, wd, hr, \hat{\boldsymbol{P}}, \boldsymbol{P}]
\quad \text{or} \quad
[mo, wd, hr, \hat{\boldsymbol{P}}, \boldsymbol{P}_{\text{Atk}}],
$$
which then supports mitigation by redispatching with SVR-predicted loads [2003.06543]. A physics-based detector instead leverages the greedy PTDF structure of the LR optimization problem, counts the Number of Proper Deviations at Sensitive Buses, and flags attacks when the ratio NPDSB/TNSB exceeds a threshold such as \(0.5\) [1907.13294]. A common misconception is that unobservable LR attacks are therefore undetectable in practice; the cited work shows that they evade residual-based BDDs but remain vulnerable to topology-aware, data-driven, or physics-informed detectors [1907.13294][1912.09453][2003.06543].

Privacy-centric smart-grid models extend the same attack surface from integrity to collusion. In E-DPNCT, each smart meter adds DP noise, splits it into \(m\) partial noises using a Dirichlet distribution, and sends the shares to multiple master smart meters. A successful collusion attack on meter \(i\) at time \(t\) requires aggregator access to \(X_{i,t}\) and all \(m\) partial noises, so if the malicious-meter fraction is \(\alpha\), the probability that all chosen MSMs are malicious is
$$
p_{\text{all mal}}=\alpha^m.
$$
The paper reports that for \(N=2000\) meters and \(50\%\) malicious meters, \(m=7\) MSMs suffice to keep leakage below \(1\%\), while for \(75\%\) malicious meters, \(m=16\) are needed for the same leakage target [2110.11091]. The model focuses on collusion-based privacy attacks, but it explicitly points toward data integrity attacks, which are described as a natural setting for load redistribution attacks [2110.11091]. This expands the meaning of enhancement: the attacker may control not only EMS measurements but also smart meters, aggregators, and privacy-noise channels.

Adaptive defenses increasingly take game-theoretic form. The adaptive voltage protection system learns threshold policies against a DRL load alteration adversary [2411.15229], while distribution-system reconfiguration solves a Stackelberg equilibrium that minimizes voltage deviation and switching cost under attack localization uncertainty [2407.07065]. These defenses do not eliminate LR-style attack models; rather, they redefine them as sequential games over thresholds, topology, and uncertainty sets.

## 6. Metrics, synthesis, and research directions

Across the literature, enhanced LR models are evaluated with several non-equivalent metrics. Cascading-failure models use the final surviving fraction \(n_\infty(p)\), the critical attack size \(p^\star\), or the robustness area
$$
\mathcal{R} = \frac{1}{N}\sum_{i=1}^{N} n_\infty(p_i)
\quad \text{or} \quad
\mathcal{R}(\varepsilon)=\int_0^1 n_\infty(p,\varepsilon)\,dp
$$
[1811.08070][1802.07664]. Dynamic load-altering models use cascade size \(X'\), average network load change \(p(X)\), blackout occurrence, or false-positive behavior under noisy conditions [2306.06511][2411.15229]. Transmission and multi-energy LR models use post-attack SCED or dispatch cost, overload magnitude, and load shedding [2509.13567][2312.16712]. Privacy-oriented smart-grid models use percentage of leaked data, billing MAE, load-monitoring MAE, and correlation between original and masked load profiles [2110.11091]. This suggests that “severity” depends on whether the model’s target is physical collapse, economic damage, cyber stealth, or data leakage.

Several recurring enhancements define the present state of the topic. One is the move from random or static attacks to targeted and adaptive attacks: max-load targeted removal in flow networks, PTDF-targeted FDI in EMSs, FVSI-guided HVAC load alteration, and worst-case bilevel LR attacks in IEGSs [1811.08070][1907.13294][2411.15229][2312.16712]. Another is the move from isolated electric networks to interdependent and renewable-rich infrastructures, where partial redistribution, solar measurement manipulation, and electricity-gas coupling alter both feasible attack sets and optimal defensive policies [1802.07664][1709.01651][2509.13567][2312.16712]. A third is the incorporation of imperfect information: inaccurate admittance values most often lead to suboptimal cyber-attacks that still compromise the grid security, while inaccurate capacity values result in notably less effective attacks, and common attacked cyber-assets and common affected physical-assets appear repeatedly across imperfect attacks [2110.00301].

A plausible implication is that no single mathematical backbone dominates every enhanced model. Mean-field order statistics and concavity arguments remain central when equal redistribution or partial redistribution is assumed; PTDF- and DCOPF-based bilevel models remain central when the objective is economic manipulation; AC power flow, FVSI, and temporal control become central when voltage instability and blackout induction are targeted; and piecewise-linear gas physics become essential in multi-energy settings [1811.08070][2509.13567][2411.15229][2312.16712]. What unifies these formulations is the strategic use of redistribution—of failed load, measured load, apparent generation, or responsive demand—to induce a downstream system response that is damaging, difficult to detect, or both.

Source: https://www.emergentmind.com/topics/enhanced-load-redistribution-attack-model