{"id":"34b71dc1-0d59-4ea7-972f-2b85b74e31a3","arxiv_id":"2608.10645","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":5,"one_line_summary":"Coordinated attacks pairing AI-induced demand manipulation with inverter parameter tampering can destabilize AIDC microgrids, and an uncertainty-aware attack reachable domain framework can identify vulnerable time windows and attack vectors.","lead":"This paper studies whether coordinated cyberattacks that combine AI-induced demand manipulation with inverter control parameter tampering can destabilize an AI data center microgrid. The authors propose an uncertainty-aware framework to identify when and how such attacks could push the system into instability.","discovery_kind":"new_method","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The central claim rests on a harmonic-impedance surrogate that may not be a valid small-signal impedance, so the coordinated ARD crossing could be a fitting artifact.","rationale":"This stress-test pass does not identify a new concern beyond the reader's weakest assumption; instead, it finds that assumption to be the single most load-bearing point in the paper. The framework is internally coherent: the loop-gain construction, confidence-weighted ARD, and attack-vector definitions are logically consistent, and the use of a real dataset plus an EMT simulation is a genuine effort at validation. However, every quantitative conclusion about when and why coordinated attacks destabilize the microgrid flows through the fitted harmonic-impedance surrogate. The paper's own caveat that the harmonic impedance is 'not directly treated as the small-signal impedance' underscores that this premise is unverified. If the surrogate is wrong, the central claim about cooperative effects is unsupported. This reinforces the reader's conditional verdict rather than moving it: the manuscript should be accepted only if the impedance surrogate is validated against an independent dynamic AIDC load model or against measured small-signal admittance over the relevant frequency range. Secondary issues, such as the abstract's unquantified 20% frequency-excursion claim and the inconsistency between the 15% load-only bound and the 21-53% load increases in Table IV, are also worth fixing but are not as load-bearing as the impedance question.","tokens_in":15143,"tokens_out":7040,"duration_ms":86492,"concrete_test":"Rerun the ARD and five-day vulnerability assessment with the AIDC load represented in the EMT simulation by a validated dynamic data-center model (UPS dynamics, cooling loops, and IT power-electronics load, e.g., the model in reference [11]) rather than by Zfit, and check whether the coordinated ARD still crosses the stability boundary. If the crossing disappears or the identified high-confidence windows shift substantially, the central cooperative-effect claim is an artifact of the harmonic-impedance surrogate.","verdict_should_be":"UNCHANGED","load_bearing_attack":"Section IV-A constructs the AIDC small-signal impedance as Zfit(s, Pdc, Qdc) fitted from measured harmonic voltage/current phasors of a university data center [22], and Sections III-C and IV use this Zfit in every ARD and eigenvalue computation. The paper itself states that the measured harmonic impedance is 'not directly treated as the small-signal impedance' but is used to construct a surrogate. That surrogate is the load-bearing premise: if it is not a faithful small-signal terminal impedance, then the coordinated ARD crossing in Fig. 4, the vulnerable windows in Fig. 6, and the time-domain instability in Fig. 7 are not evidence of genuine converter-load interaction. Harmonic impedance at integer multiples of the fundamental does not sample the sub-synchronous and control-band frequencies (roughly 0.1-100 Hz) where inverter/VSG modes typically live, and it can be dominated by background harmonic sources rather than by the load's incremental dynamics. A fitted transfer function can place poles near the imaginary axis in unsampled frequency bands purely as an artifact of the fitting procedure. The claimed cooperative effect of coordinated attacks is therefore only as strong as this surrogate's validity, which is not established.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper proposes an uncertainty-aware framework for assessing the vulnerability of a low-carbon AIDC microgrid to a coordinated attack that combines AI-induced AIDC demand manipulation with tampering of PV inverter control parameters. The framework models PV forecast error and demand-response uncertainty through confidence-weighted realizations, maps them to source and load impedances, constructs an attack reachable domain (ARD) of critical closed-loop eigenvalues, and derives confidence-weighted attack time windows and attack vectors. A case study using a university data center harmonic-impedance dataset and a five-day PV trajectory reports that coordinated attacks cross the stability boundary while single-side attacks do not, that vulnerable windows are sparse and time-dependent, and that time-domain simulations show growing oscillations when the attack is launched inside an identified window.","tokens_in":15399,"tokens_out":3408,"duration_ms":41411,"significance":"If the load-modeling premise holds, the paper's contribution is novel and useful: it is the first to formulate the cross-domain coupling between adversarial LLM workload manipulation and inverter parameter tampering as a small-signal stability problem, and it provides a tractable probabilistic screening procedure that identifies sparse high-confidence vulnerable intervals. The workload-to-power conversion chain (Eqs. 19-25), the confidence-weighted attackability score (Eq. 42), and the ARD-based window/vector identification are clearly structured, and the paper includes time-domain confirmation of the instability inside identified windows. The main significance is therefore conditional on the validity of the AIDC impedance surrogate, which is the load-bearing element of the analysis.","major_comments":[{"comment":"The central result that coordinated attacks cross the stability boundary depends entirely on Z_fit(s, Pdc, Qdc), a surrogate fitted from measured harmonic voltage and current phasors at a university data center PCC. The paper explicitly states that this harmonic impedance is \"not directly treated as the small-signal impedance,\" but no independent validation is provided that the surrogate faithfully represents the incremental terminal dynamics of the AIDC in the frequency band relevant to inverter/VSG modes (roughly 0.1-100 Hz). Harmonic impedance samples at integer multiples of the fundamental do not constrain the fitted transfer function in that band, so poles near the imaginary axis in unsampled bands, and hence the ARD crossing in Fig. 4 and the vulnerable windows in Fig. 6, could be fitting artifacts. This is a load-bearing issue: the time-domain simulation in Fig. 7 uses the same model and therefore does not independently confirm the surrogate. I request a validation study comparing the surrogate with a detailed switched/electromagnetic model of the AIDC including UPS, cooling, and electronic-load dynamics, or with broadband small-signal impedance measurements; absent that, the claim should be substantially weakened.","section":"§IV-A and Eq. (18)"},{"comment":"The confidence-weighted attackability score A_{t+tau} is the basis for the claimed sparse high-confidence vulnerable windows, but the confidence weight mappings C_dc(·) and c_pv are never specified. The text says the PV forecast error and demand response are zero-mean normal with standard deviations 15% and 5%, respectively, but it does not state how these distributions define c_pv and c_dc, nor whether the weights are normalized densities, quantile-based probabilities, or something else. Since A_{t+tau} is a weighted average over realizations, different reasonable weight mappings will change which windows exceed the threshold α. No sensitivity analysis is reported for the 15%/5% parameters or for the Gaussian assumption. This is load-bearing for the framework's central probabilistic claims, and the manuscript should either specify the mappings explicitly and justify the parameter values, or demonstrate that the identified windows are robust across a plausible range of these choices.","section":"§IV-A and Eqs. (27), (40), (42)"},{"comment":"The conditional-independence assumption between PV prediction error and AI-induced demand response given the BESS operating mode is stated without support, and the BESS operating mode is not included in the model or case study. The product-form joint weight in Eq. (40) is therefore an unverified structural choice. If the BESS arbitrage or state-of-charge constraints couple PV output and AIDC demand, the independent product can either over- or under-estimate the joint attackability score in a way that affects the identified windows. The authors note that correlated uncertainty can be incorporated, but they do not provide any comparison or bound showing that the independence assumption is not the driver of the high-confidence windows. This issue should be addressed either by adding a correlated-uncertainty case study or by an explicit argument for why BESS decoupling makes the independence assumption conservative.","section":"§III-D and Eq. (40)"}],"minor_comments":[{"comment":"There is a typo in the threat model: \"demadn responses\" should be \"demand responses.\"","section":"§II-C"},{"comment":"The phrase \"Based on the the coordinated attack model\" repeats \"the\" and should be corrected.","section":"§III-D"},{"comment":"The manuscript refers to \"a AIDC microgrid\" and \"a AIDC node\"; since \"AIDC\" is pronounced as an acronym beginning with a vowel sound, it should be \"an AIDC microgrid\" and \"an AIDC node.\"","section":"§IV-A"},{"comment":"In the text following Eq. (18), \"V oltage\" has a stray space and should be \"Voltage.\"","section":"§IV-A"},{"comment":"The frequency and rotor-angle axes in Fig. 7 are not labeled with units; since the abstract claims \"frequency excursions exceeding 20% of the nominal value,\" the plot needs an explicit y-axis in Hz or per-unit and a clear indication of the nominal value.","section":"Fig. 7"},{"comment":"The procedure for selecting the window-specific coordinated attack vectors in Table V is not described in enough detail: the number of sampled candidates, the sampling distribution over the attack set Ω_a, and the stopping criterion for retaining a vector should be stated so that the table is reproducible.","section":"§IV-B3, Table V"}],"recommendation":"major_revision","confidential_remarks":"The paper's novelty is appropriately positioned relative to [7], [14], [15], and [23], although the ARD machinery is inherited from [23] and the new contribution is the cross-domain AIDC coupling plus the uncertainty-aware aggregation. The main risk is scientific rather than stylistic: the harmonic-impedance surrogate is the load-bearing element, and without independent small-signal validation the coordinated-attack crossing could be a fitting artifact. I would not recommend rejection because the framework is well-structured and the validation gap is, in principle, addressable within the manuscript's scope."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Short version: the paper's contribution is real, but the load model is the problem. It is the first to tie malicious LLM prompts to AIDC demand shifts and combine that with inverter parameter tampering, and the confidence-weighted ARD formulation is a reasonable extension of the authors' earlier work. The workload-to-power chain (Eqs. 19–25, Table II) is thoughtful and shows they thought about latency, queueing, and autoscaling. The use of a real university data center harmonic impedance dataset is a nice touch, and the time-domain plots inside versus outside the detected windows support the qualitative point that vulnerability is time-dependent. Credit where due: this is a serious, well-structured attack-scenario paper.\\n\\nThe soft spot is the one the stress test flags, and it is load-bearing. Section IV-A builds Zfit(s,Pdc,Qdc) from measured harmonic impedance at integer multiples of the fundamental, then uses it as the small-signal terminal impedance in all eigenvalue and ARD computations. Harmonic measurements do not sample the 0.1–100 Hz control band where inverter/VSG modes typically live, and a fitted transfer function can place poles near the imaginary axis in unsampled bands as a fitting artifact. The paper is honest that this is a surrogate, not a measured small-signal impedance, but it never validates the surrogate against, say, the EMT model they already have. Without that, the ARD crossing in Fig. 4 and the vulnerable windows in Fig. 6 are not established as real converter–load interaction; they are conditional on the surrogate. That is a major-revision issue, not a desk-reject issue.\\n\\nLesser issues: the 15% and 5% uncertainty parameters and attack bounds get no sensitivity analysis; the abstract's \"over 20% frequency excursions\" is not quantified anywhere in the case study text; no code or fitted model is released beyond the public impedance dataset. I would not call the framework circular, as the reader report does—model-based assessment is normal—but it is unvalidated, and that is the honest statement.\\n\\nWho should read it: people working on cyber-physical security for data-center-connected grids. It is a good scenario paper and a useful framework template, but I would not yet use its numeric findings as evidence of real attack impact. Send it to review, and ask for validation of the load model, sensitivity analysis, and a correction of the abstract claim.","headline":"Novel AIDC coordinated-attack scenario with a real load-model problem: the fit from harmonic impedance to small-signal transfer function is load-bearing and unvalidated.","tokens_in":15903,"tokens_out":3616,"would_cite":true,"duration_ms":38635,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"Coordinated AI-demand and inverter attacks can destabilize AIDC microgrids when either alone cannot","keywords":["AI data center","microgrid vulnerability","coordinated cyberattack","small-signal stability","impedance model","inverter parameter tampering","AI-induced demand manipulation","attack reachable domain"],"falsifier":"Run an electromagnetic-transient simulation of the same PV-BESS-AIDC microgrid with a detailed switched or EMT-level AIDC load model (including UPS and cooling dynamics) and apply the paper's identified coordinated attack vectors inside and outside the reported windows; if no sustained frequency excursion or eigenvalue right-half-plane crossing occurs with the detailed load, the fitted-surrogate premise fails. Alternatively, measure the small-signal impedance of the specific AIDC directly at the reported vulnerable operating points (e.g., via broadband injection at the PCC) and check whether the loop gain predicted instability.","tokens_in":14920,"feed_emoji":"⚡","tokens_out":1762,"duration_ms":19232,"temperature":0.7,"pith_summary":"This paper claims that a new class of cyber-physical attack against AI data center (AIDC) microgrids works by combining two individually bounded actions: tampering with inverter control parameters on the renewable side, and using malicious LLM prompts to manipulate AIDC power demand. The central claim is that the two attacks have a cooperative effect, reshaping the coupling between source and load impedances so that the coordinated attack reachable domain crosses the small-signal stability boundary even when each attack alone stays in the stable region. If true, this means attack surface assessments for low-carbon AIDCs must treat computing demand as a dynamic load-side attack vector, not just a passive uncertainty. The paper also claims that the vulnerability is time-dependent and sparse, concentrated in short high-confidence windows that can be identified from long-term operating trajectories, and that within those windows a fixed coordinated attack vector can remain destabilizing under joint uncertainty.","feed_headline":"Coordinated AI-demand and inverter attacks can break a microgrid","feed_subtitle":"Either attack alone stays stable; together they cross the stability boundary, and the vulnerable windows are sparse and predictable.","key_machinery":"The central object is the impedance-based loop-gain matrix $L^{(n,m)}(s,t+\\tau,a) = Z_{eq}^{(m)}(s,t+\\tau)\\, \\tilde{Y}_{pv}^{(n)}(s,t+\\tau,a)$, whose closed-loop eigenvalues are obtained from $\\det[I+L(\\lambda_i)]=0$. The attack reachable domain (ARD) $D_{t+\\tau}^{(n,m)}$ collects the critical closed-loop eigenvalue locations reachable by feasible coordinated attack vectors, and its real-axis projection $P_{t+\\tau}^{(n,m)}$ decides attackability via intersection with $(0,\\infty)$. The framework also uses an operating-point-dependent fitted impedance model $Z_{dc}(s,t)=Z_{fit}(s,P_{dc}(t),Q_{dc}(t))$ for the AIDC load and an irradiance-parameterized PV admittance $Y_{pv}(s,G_0)$, along with a confidence-weighted attackability score $A_{t+\\tau}$ and a vector-effectiveness score $S_{t+\\tau}(a)$ that respectively identify when and how the coordinated attack can destabilize the system under joint uncertainty.","core_discovery":"The paper establishes that a coordinated attack, combining AI-induced AIDC demand manipulation with inverter control parameter tampering, can drive a low-carbon AIDC microgrid into small-signal instability under conditions where neither attack alone succeeds. The mechanism is impedance interaction: the load-side attack shifts the AIDC operating point and thus its equivalent impedance, while the inverter-side attack changes the source admittance, jointly moving the critical closed-loop eigenvalue of the loop-gain matrix $L^{(n,m)}(s,t+\\tau,a)$ into the right-half plane. The paper demonstrates this through attack reachable domain (ARD) analysis at representative operating points, showing that the coordinated ARD expands and crosses the stability boundary, and through a five-day case study where coordinated attacks produce sustained inverter frequency excursions exceeding 20% of nominal and growing VSG rotor angle deviations only inside identified critical windows. The framework further assigns confidence weights to PV forecast-error realizations and AI-induced demand response realizations, defining an uncertainty-aware attack time window via a confidence-weighted attackability score and an uncertainty-aware attack vector that remains effective throughout the window. A real-world university data center harmonic impedance dataset is used to construct an operating-point-dependent impedance surrogate that serves as the load-side small-signal impedance model.","pith_inferences":["A natural testable extension is to check whether the cooperative effect persists for other load types (e.g., cooling-dominated or UPS-dominated data centers) whose impedance spectra differ from the university center used here, which would clarify how general the mechanism is.","The confidence-weighted attackability score measures prevalence, not severity; a defender might combine it with the right-half-plane eigenvalue magnitude to prioritize windows where high-confidence and high-severity coincide.","The paper's assumption that PV prediction error and AI-induced demand response are conditionally independent given the BESS operating mode could be relaxed; correlated uncertainty would likely change window boundaries and may make some identified windows spurious.","The findings suggest an adversarial 'label-flip'-style inference: if the framework can predict vulnerable windows from public PMU-like measurements and irradiance forecasts, then attackers who can read such data do not need any insider electrical knowledge to time their AI-side prompts.","Whether the fitted impedance surrogate captures the real data center's small-signal dynamics (rather than harmonic steady-state behavior) is the paper's load-bearing premise; a mismatch could make the reported instability artifacts of the surrogate rather than of the physical system."],"forward_implications":["If the central claim holds, cybersecurity assessments of AIDC microgrids must treat LLM-service demand manipulation as a first-class attack surface equivalent in importance to electrical-infrastructure access.","The time-dependence of vulnerability implies that blanket monitoring is suboptimal; defenders can focus on short, high-confidence vulnerable windows rather than the full operating horizon.","The impedance-based screening method provides a direct path from operating-point changes to stability margin erosion, enabling prediction of vulnerability from PMU measurements and load forecasts.","The identified fixed coordinated attack vectors that remain effective across uncertainty suggest that a single injection strategy can be reused across plausible future conditions within a window, simplifying attacker planning.","The results imply that BESS power-buffering does not by itself protect against stability-driven coordinated attacks, since the attack acts through impedance reshaping rather than direct power imbalance."],"supporting_citations":[{"why":"Supplies the real-world university data center harmonic impedance dataset from which the operating-point-dependent AIDC impedance surrogate is fitted.","marker":"[22]"},{"why":"Defines the impedance-based attack reachable domain concept that the paper extends to joint source-load uncertainty.","marker":"[23]"},{"why":"Provides the admittance-guided inverter attack formulation and the historical-measurement-based impedance estimation approach used for the attacker model.","marker":"[15]"},{"why":"Establishes the inverter parameter tampering attack class that the coordinated attack's source-side component builds on.","marker":"[14]"},{"why":"Supplies the maximum token-consumption amplification value (A_w=13.12) used in the load-side attack sensitivity analysis.","marker":"[27]"},{"why":"Demonstrates energy-latency attacks on neural networks, the basis for treating AI-service request manipulation as a load-side attack vector.","marker":"[7]"},{"why":"Justifies the zero-mean Gaussian error approximation used for PV forecast and demand response uncertainty in the case study.","marker":"[35]"},{"why":"Provides the public PV generation dataset used for the five-day operating trajectory.","marker":"[36]"}],"fun_headline_variants":["Coordinated attack breaks microgrid where single ones fail","AI demand plus inverter attack: microgrid instability combo","Two-pronged attack on microgrid: AI loads and inverter tampering","Coordinated cyber attacks push microgrid past stability edge","Single attack safe, coordinated attack breaks microgrid"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The fitted impedance model built from measured harmonic impedance of a university data center faithfully represents the true small-signal dynamics of the AIDC load for stability analysis; if that surrogate misses real load dynamics, the identified vulnerable windows may not correspond to genuine instability.","fun_headline_variants_meta":{"raw":{"variants":["Coordinated attack breaks microgrid where single ones fail","AI demand plus inverter attack: microgrid instability combo","Two-pronged attack on microgrid: AI loads and inverter tampering","Coordinated cyber attacks push microgrid past stability edge","Single attack safe, coordinated attack breaks microgrid"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000473,"raw_usage":{"total_tokens":2407,"prompt_tokens":1056,"completion_tokens":1351,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":672,"completion_tokens_details":{"reasoning_tokens":1271}},"tokens_in":672,"tokens_out":1351,"duration_ms":10539,"temperature":1.0,"reasoning_tokens":1271,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-12T20:14:44.027393+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Run an electromagnetic-transient simulation of the same PV-BESS-AIDC microgrid with a detailed switched or EMT-level AIDC load model (including UPS and cooling dynamics) and apply the paper's identified coordinated attack vectors inside and outside the reported windows; if no sustained frequency excursion or eigenvalue right-half-plane crossing occurs with the detailed load, the fitted-surrogate premise fails. Alternatively, measure the small-signal impedance of the specific AIDC directly at the reported vulnerable operating points (e.g., via broadband injection at the PCC) and check whether the loop gain predicted instability.","supporting_citations":[{"cited_title":"Photovoltaic data acquisition (pvdaq) public datasets,","cited_arxiv_id":null,"evidence_quote":"Provides the public PV generation dataset used for the five-day operating trajectory."},{"cited_title":"Modeling forecast errors for microgrid operation using gaussian process regression,","cited_arxiv_id":null,"evidence_quote":"Justifies the zero-mean Gaussian error approximation used for PV forecast and demand response uncertainty in the case study."},{"cited_title":"Garrido-Zafra, R","cited_arxiv_id":null,"evidence_quote":"Supplies the real-world university data center harmonic impedance dataset from which the operating-point-dependent AIDC impedance surrogate is fitted."},{"cited_title":"Quantifying cyber- vulnerability in power electronics systems via an impedance-based attack reachable domain,","cited_arxiv_id":null,"evidence_quote":"Defines the impedance-based attack reachable domain concept that the paper extends to joint source-load uncertainty."},{"cited_title":"Admittance-Guided Inverter Dispatch Command Manipulation Attack: A Grid Stability-Oriented Approach","cited_arxiv_id":"2605.14509","evidence_quote":"Provides the admittance-guided inverter attack formulation and the historical-measurement-based impedance estimation approach used for the attacker model."},{"cited_title":"Inference cost attacks for retrieval-augmented large language models,","cited_arxiv_id":null,"evidence_quote":"Supplies the maximum token-consumption amplification value (A_w=13.12) used in the load-side attack sensitivity analysis."},{"cited_title":"Sponge examples: Energy-latency attacks on neural networks,","cited_arxiv_id":null,"evidence_quote":"Demonstrates energy-latency attacks on neural networks, the basis for treating AI-service request manipulation as a load-side attack vector."}],"review_version":1}