{"id":{"repo_id":"vt","oai_identifier":"oai:vtechworks.lib.vt.edu:10919/134226"},"canonical_url":"https://search.dev.ndltd.org/etd/vt/oai:vtechworks.lib.vt.edu:10919/134226","repository":{"repo_id":"vt","name":"Virginia Tech","base_url":"https://vtechworks.lib.vt.edu/oai/request"},"display":{"title":"Detecting Zero-Day Attacks in IEC-61850 based Digital Substations via In-Context Learning","abstract":"The occurrences of cyber attacks, with novel attack techniques, on the electrical power grids have been increasing every year. In this thesis, we address the critical challenge of detecting novel/zero-day attacks in digital substations that employ the IEC-61850 communication protocol. While many heuristic and ML-based methods have been proposed for attack detection in IEC-61850 digital substations, generalization to novel or zero-day attacks remains challenging. We propose an approach that leverages the in-context learning (ICL) capability of the transformer architecture, the fundamental building block of large language models. The ICL approach enables the model to detect zero-day attacks and learn from a few examples of that attack without explicit retraining. Our experiments on the IEC-61850 dataset demonstrate that the proposed method achieves more than 85% detection accuracy on zero-day attacks while the existing state-of-the-art baselines fail. This work paves the way for building more secure and resilient digital substations of the future.","abstract_html":"The occurrences of cyber attacks, with novel attack techniques, on the electrical power grids have been increasing every year. In this thesis, we address the critical challenge of detecting novel/zero-day attacks in digital substations that employ the IEC-61850 communication protocol. While many heuristic and ML-based methods have been proposed for attack detection in IEC-61850 digital substations, generalization to novel or zero-day attacks remains challenging. We propose an approach that leverages the in-context learning (ICL) capability of the transformer architecture, the fundamental building block of large language models. The ICL approach enables the model to detect zero-day attacks and learn from a few examples of that attack without explicit retraining. Our experiments on the IEC-61850 dataset demonstrate that the proposed method achieves more than 85% detection accuracy on zero-day attacks while the existing state-of-the-art baselines fail. This work paves the way for building more secure and resilient digital substations of the future.","abstract_has_math":false,"creators":["Manzoor, Faizan"],"institution":"Virginia Tech","degree_name":"Master of Science","degree_level":"masters","degree_discipline":"Electrical Engineering","degree_department":"Electrical Engineering","school":null,"contributors":[],"advisors":[],"committee_chairs":["Jin, Ming"],"committee_members":["Liu, Chen-Ching","Viswanath, Bimal"],"year":2025,"date_issued":"2025-05-25","date_published":"2025-05-25","updated_at":"2026-07-22T22:19:21Z","subjects":["In-context learning","IEC-61850","intrusion detection systems","zero-day attacks","GPT-2 transformer"],"languages":["en"],"rights":["In Copyright"],"rights_urls":["http://rightsstatements.org/vocab/InC/1.0/"],"identifier_entries":[{"key":"dc:identifier.other","label":"Dc Identifier Other","values":["vt_gsexam:43657"],"render_values":[{"text":"vt_gsexam:43657","href":null,"code":true}]}]},"links":{"outbound_url":"https://hdl.handle.net/10919/134226","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.committeechair","label":"Committee Chair","values":["Jin, Ming"]},{"key":"dc:contributor.committeemember","label":"Committee Member","values":["Liu, Chen-Ching","Viswanath, Bimal"]},{"key":"dc:contributor.department","label":"Department","values":["Electrical Engineering"]},{"key":"dc:creator","label":"Author","values":["Manzoor, Faizan"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2025-05-26T08:00:15Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2025-05-26T08:00:15Z"]},{"key":"dc:date.issued","label":"Date","values":["2025-05-25"]},{"key":"dc:publisher","label":"Institution","values":["Virginia Tech"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Electrical Engineering"]},{"key":"thesis:degree_level","label":"Degree Level","values":["masters"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Master of Science"]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["Virginia Polytechnic Institute and State University"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["In-context learning","IEC-61850","intrusion detection systems","zero-day attacks","GPT-2 transformer"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language.iso","label":"Language (ISO)","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["In Copyright"]},{"key":"dc:rights.uri","label":"Rights URI","values":["http://rightsstatements.org/vocab/InC/1.0/"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.other","label":"Dc Identifier Other","values":["vt_gsexam:43657"]},{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://hdl.handle.net/10919/134226"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["The occurrences of cyber attacks, with novel attack techniques, on the electrical power grids have been increasing every year. In this thesis, we address the critical challenge of detecting novel/zero-day attacks in digital substations that employ the IEC-61850 communication protocol. While many heuristic and ML-based methods have been proposed for attack detection in IEC-61850 digital substations, generalization to novel or zero-day attacks remains challenging. We propose an approach that leverages the in-context learning (ICL) capability of the transformer architecture, the fundamental building block of large language models. The ICL approach enables the model to detect zero-day attacks and learn from a few examples of that attack without explicit retraining. Our experiments on the IEC-61850 dataset demonstrate that the proposed method achieves more than 85% detection accuracy on zero-day attacks while the existing state-of-the-art baselines fail. This work paves the way for building more secure and resilient digital substations of the future."]},{"key":"dc:description.abstractgeneral","label":"General Abstract","values":["Cyber attacks targeting electrical power grids are becoming increasingly frequent, with attackers continuously developing new methods. In this paper, we focus on the crucial challenge of detecting previously unknown, or ``zero-day\", cyber attacks in digital substations that use a specific communication standard known as IEC-61850. While existing machine learning methods are effective at detecting known threats, they typically struggle with attacks they have not encountered before. To overcome this limitation, we propose a novel approach that uses a powerful type of neural network called a transformer. Transformers, known primarily for their role in large language models, possess an ability called ``In-Context Learning,\" which allows them to rapidly adapt to and detect new attack patterns using just a few examples, without needing extensive retraining or updates. Our experiments demonstrate that our method successfully identifies zero-day attacks with an accuracy of over 85%, significantly outperforming current state-of-the-art techniques. This research offers a promising direction toward more secure and resilient future digital substations."]},{"key":"dc:description.degree","label":"Dc Description Degree","values":["Master of Science"]},{"key":"dc:format.medium","label":"Dc Format Medium","values":["ETD"]},{"key":"dc:title","label":"Title","values":["Detecting Zero-Day Attacks in IEC-61850 based Digital Substations via In-Context Learning"]}]}],"canonical_facts":{"dc:contributor.committeechair":["Jin, Ming"],"dc:contributor.committeemember":["Liu, Chen-Ching","Viswanath, Bimal"],"dc:contributor.department":["Electrical Engineering"],"dc:creator":["Manzoor, Faizan"],"dc:date.accessioned":["2025-05-26T08:00:15Z"],"dc:date.available":["2025-05-26T08:00:15Z"],"dc:date.issued":["2025-05-25"],"dc:description.abstract":["The occurrences of cyber attacks, with novel attack techniques, on the electrical power grids have been increasing every year. In this thesis, we address the critical challenge of detecting novel/zero-day attacks in digital substations that employ the IEC-61850 communication protocol. While many heuristic and ML-based methods have been proposed for attack detection in IEC-61850 digital substations, generalization to novel or zero-day attacks remains challenging. We propose an approach that leverages the in-context learning (ICL) capability of the transformer architecture, the fundamental building block of large language models. The ICL approach enables the model to detect zero-day attacks and learn from a few examples of that attack without explicit retraining. Our experiments on the IEC-61850 dataset demonstrate that the proposed method achieves more than 85% detection accuracy on zero-day attacks while the existing state-of-the-art baselines fail. This work paves the way for building more secure and resilient digital substations of the future."],"dc:description.abstractgeneral":["Cyber attacks targeting electrical power grids are becoming increasingly frequent, with attackers continuously developing new methods. In this paper, we focus on the crucial challenge of detecting previously unknown, or ``zero-day\", cyber attacks in digital substations that use a specific communication standard known as IEC-61850. While existing machine learning methods are effective at detecting known threats, they typically struggle with attacks they have not encountered before. To overcome this limitation, we propose a novel approach that uses a powerful type of neural network called a transformer. Transformers, known primarily for their role in large language models, possess an ability called ``In-Context Learning,\" which allows them to rapidly adapt to and detect new attack patterns using just a few examples, without needing extensive retraining or updates. Our experiments demonstrate that our method successfully identifies zero-day attacks with an accuracy of over 85%, significantly outperforming current state-of-the-art techniques. This research offers a promising direction toward more secure and resilient future digital substations."],"dc:description.degree":["Master of Science"],"dc:format.medium":["ETD"],"dc:identifier.other":["vt_gsexam:43657"],"dc:identifier.uri":["https://hdl.handle.net/10919/134226"],"dc:language.iso":["en"],"dc:publisher":["Virginia Tech"],"dc:rights":["In Copyright"],"dc:rights.uri":["http://rightsstatements.org/vocab/InC/1.0/"],"dc:subject":["In-context learning","IEC-61850","intrusion detection systems","zero-day attacks","GPT-2 transformer"],"dc:title":["Detecting Zero-Day Attacks in IEC-61850 based Digital Substations via In-Context Learning"],"dc:type":["Thesis"],"thesis:degree_discipline":["Electrical Engineering"],"thesis:degree_level":["masters"],"thesis:degree_name":["Master of Science"],"thesis:institution_name":["Virginia Polytechnic Institute and State University"]},"updated_at":"2026-07-22T22:19:21Z"}