REVIEW 2 major objections 2 minor 31 references
Cyber-Physical Co-Simulation of Load Frequency Control under Load-Altering Attacks
T0 review · 2 major / 2 minor · reviewed 2026-08-06 · deepseek-v4-flash
Pith's one-line read The paper presents an open-source cyber-physical co-simulation environment that models both the power grid and its communication network to analyze dynamic load-altering attacks in load frequency control and under-frequency load shedding…
desk verdict The supplied full text is a different paper, so the actual LFC/DLAA testbed paper cannot be evaluated from these materials; retrieve the real manuscript before any editorial decision. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The central object is the open-source co-simulation environment, which couples a power-grid simulator with a communication-network simulator and includes working implementations of load frequency control and under-frequency load shedding. The mechanism that carries the analysis is the dynamic load-altering attack model: a botnet of high-wattage devices whose aggregate consumption reacts to measured grid frequency, injecting load fluctuations into the same loop that LFC is trying to regulate. The communication-network side imposes realistic delays and data exchange on the control and protection signals, which is what makes the scenarios cyber-physical rather than purely electrical.
What would settle it
Run an identical, calibrated DLAA scenario in this co-simulation and in a hardware-in-the-loop testbed whose grid model and communication latency match; if the two frequency trajectories or UFLS trip times differ beyond a stated tolerance, the environment's claim to support detailed analysis of these attacks would need to be qualified.
Extended reading notes
Core claim
The paper's central claim is that the power grid and the communication network that carries its control and protection signals must be modeled jointly to understand dynamic load-altering attacks. A DLAA operates through a botnet of high-wattage devices whose aggregate load is manipulated in response to live frequency measurements, so the attack engages directly with the closed loop of frequency control. The environment implements LFC, which restores nominal frequency during ordinary load fluctuations, and UFLS, which disconnects load during emergencies, and exposes how these protective mechanisms behave when the communication network is part of the attack surface. On the paper's own terms, the contribution is this integrated, open-source testbed: a concrete setting in which the consequences of LAAs and DLAAs for frequency stability can be analyzed and compared across scenarios.
Load-bearing premise
The load-bearing premise is that the simulated grid dynamics, communication delays, and attacker behavior are faithful enough to real systems that conclusions about attack impact and protection performance drawn from the environment would hold on an actual grid.
Editorial extensions
If this is right
- The same scenarios can be reproduced by other researchers, allowing attack impact and protection behavior to be compared across studies without a shared physical testbed.
- Operators could use the environment to identify the botnet sizes and communication latencies at which a DLAA forces frequency below UFLS relay thresholds.
- The open-source structure makes it possible to extend the scenarios to different grid topologies, communication protocols, or protective settings and rerun the same attack analysis.
- Because the protective mechanisms are implemented alongside the network, the environment can show how communication delay alone changes whether LFC or UFLS responds in time.
Reading between the lines
- The same coupled modeling approach could be turned around to simulate attacks on the communication layer itself, such as delaying or dropping LFC messages, and directly compare their damage with load-altering attacks in the same scenarios.
- A natural extension would be to validate the environment's frequency trajectories against a hardware-in-the-loop testbed or phasor measurement unit data; the fidelity of the communication-delay model is likely what determines whether UFLS activation times match reality.
- The testbed could also support defensive research on deceiving the botnet's frequency measurements, for example by intentionally perturbing the published frequency signal, since the DLAA model is driven by that measurement.
- Results from such a platform could inform grid security guidance, for instance on redundant communication paths for LFC signals, if operators find the simulated consequences convincing.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The submission claims to present an open-source cyber-physical co-simulation environment for modeling power-grid dynamics and the associated communication network, with implementations of Load Frequency Control (LFC) and Under-Frequency Load Shedding (UFLS), enabling comprehensive analysis of dynamic load-altering attacks (DLAAs). However, the provided full text is the paper "Revisiting Adversarial Patch Defenses on Object Detectors" (arXiv:2508.00649v2), which is entirely unrelated to the abstract's claims. The manuscript as submitted therefore contains no description of the co-simulation environment, no models of power-grid or communication dynamics, no attack implementations, no validation results, and no code or repository information. The central claim of the abstract is unsupported by the submitted materials, and the actual scientific content of arXiv:2508.00637 cannot be assessed.
Significance. If the claimed co-simulation environment exists and is faithful to real power-grid and communication behavior, it could be a valuable community resource for security research: it would allow concrete, repeatable evaluation of DLAAs under LFC and UFLS protective mechanisms, addressing a real gap in the literature where communication-network effects are often abstracted away. However, because the submitted manuscript does not contain the described work, the significance, validity, and usability of the claimed environment are entirely unverifiable from the materials provided. No credit can be given for implementation, validation, or reproducibility because none of these elements appear in the submitted text.
major comments (2)
- [Full Text (all sections)] The entire full text of this submission is the paper "Revisiting Adversarial Patch Defenses on Object Detectors" (arXiv:2508.00649v2), which is about computer-vision adversarial patches and shares no content with the abstract of arXiv:2508.00637. None of the claimed contributions—the co-simulation environment, power-grid and communication-network models, LFC/UFLS implementations, dynamic load-altering attack models, or open-source code—appear anywhere in the manuscript. This is a load-bearing failure: I cannot evaluate the correctness, fidelity, or reproducibility of the claimed environment, nor even confirm that the described tool exists. This defect cannot be fixed by a local revision; the correct full text must be submitted for review.
- [Abstract] Even taken in isolation, the abstract asserts that the environment "allows the comprehensive analysis of the attacks in concrete LFC and UFLS scenarios," but it provides no validation, no comparison to existing co-simulation tools, and no specification of the modeling assumptions (e.g., power-system dynamic order, communication delay models, or attacker capabilities). While such details might reasonably be deferred to the body of a paper, the absence of the body in this submission leaves the central claim with no evidentiary basis whatsoever.
minor comments (2)
- [Abstract] The abstract claims the environment is "open-source" but does not provide a repository URL, a project page, or even a placeholder for one; if the correct manuscript is later supplied, this availability statement should be made concrete.
- [Abstract] The phrase "concrete LFC and UFLS scenarios" is undefined; without specifying representative frequency disturbance magnitudes, load-step sizes, or communication delay ranges, the reader cannot gauge the scope of the claimed analysis.
Circularity Check
No circularity in the supplied full text; the text mismatch with the abstract is an evidentiary gap, not a circular derivation.
full rationale
The circularity axis asks whether a paper's claimed derivation or prediction reduces by construction to its inputs or to a load-bearing self-citation chain. In the supplied full text, which is 'Revisiting Adversarial Patch Defenses on Object Detectors' rather than the abstract's power-grid co-simulation paper, there is no such reduction. The main empirical claims are benchmark construction, dataset release, retraining experiments, and observations about patch frequency distributions versus data distribution. These are supported by measurements and experiments, not derived from fitted parameters renamed as predictions. The improvement of 15.09% AP@0.5 is an experimental outcome of retraining on the proposed dataset, not a quantity forced by definition. The suggestion that patch detection accuracy is less suitable than AP is supported by consistency measurements. The one self-citation in the reference list (Zheng et al., CVPR 2024) is cited only as an example of adversarial attacks on depth estimation and is not load-bearing for any derivation. The supplied abstract and full text are different papers, so the central claim of the abstract—an open-source co-simulation environment for LFC and UFLS scenarios—is unverifiable from the provided materials. That mismatch is a serious evidence and provenance concern, but it is not a circular step: no claim in the supplied text is equivalent to its own input by construction. Therefore the appropriate circularity score is 0, with the caveat that the scientific assessment of the abstract's claim requires the actual manuscript rather than the text provided.
Assumptions & free parameters
assumptions (2)
- domain assumption The power grid dynamics relevant to LFC and UFLS are adequately captured by the chosen simulation models.
- domain assumption The communication network model faithfully represents delays, losses, and attack effects that influence LFC information exchange.
Cite this review
Pith. "Pith review of Cyber-Physical Co-Simulation of Load Frequency Control under Load-Altering Attacks." pith.science (2026). https://pith.science/paper/ERYTS2HA
@misc{pith2026250800637,
author = {Pith},
title = {Pith review of: Cyber-Physical Co-Simulation of Load Frequency Control under Load-Altering Attacks},
year = {2026},
howpublished = {\url{https://pith.science/paper/ERYTS2HA}},
note = {Machine review of arXiv:2508.00637}
}
read the original abstract
Integrating Information and Communications Technology (ICT) devices into the power grid brings many benefits. However, it also exposes the grid to new potential cyber threats. Many control and protection mechanisms, such as Load Frequency Control (LFC), responsible for maintaining nominal frequency during load fluctuations and Under Frequency Load Shedding (UFLS) disconnecting portion of the load during an emergency, are dependent on information exchange through the communication network. The recently emerging Load Altering Attacks (LAAs) utilize a botnet of high-wattage devices to introduce load fluctuation. In their dynamic form (DLAAs), they manipulate the load in response to live grid frequency measurements for increased efficiency, posing a notable threat to grid stability. Recognizing the importance of communication networks in power grid cyber security research, this paper presents an open-source co-simulation environment that models the power grid with the corresponding communication network, implementing grid protective mechanisms. This setup allows the comprehensive analysis of the attacks in concrete LFC and UFLS scenarios.
Reference graph
Works this paper leans on
-
[1]
Anish Athalye, Nicholas Carlini, and David Wagner. Obfus- cated gradients give a false sense of security: Circumventing defenses to adversarial examples. In International confer- ence on machine learning, pages 274–283. PMLR, 2018. 5
work page 2018
-
[2]
Yolov4: Optimal speed and accuracy of object detection
Alexey Bochkovskiy, Chien-Yao Wang, and Hong- Yuan Mark Liao. Yolov4: Optimal speed and accuracy of object detection. arXiv preprint arXiv:2004.10934, 2020. 2
arXiv 2004
-
[3]
Apricot: A dataset of physical adversarial attacks on ob- ject detection
Anneliese Braunegg, Amartya Chakraborty, and Krumdick. Apricot: A dataset of physical adversarial attacks on ob- ject detection. In European Conference on Computer Vision, pages 35–50. Springer, 2020. 2, 3
work page 2020
-
[4]
End-to- end object detection with transformers
Nicolas Carion, Francisco Massa, Gabriel Synnaeve, Nicolas Usunier, Alexander Kirillov, and Sergey Zagoruyko. End-to- end object detection with transformers. In European confer- ence on computer vision, pages 213–229. Springer, 2020. 1, 2, 4
work page 2020
-
[5]
End-to-end autonomous driving: Challenges and frontiers
Li Chen, Penghao Wu, Kashyap Chitta, Bernhard Jaeger, An- dreas Geiger, and Hongyang Li. End-to-end autonomous driving: Challenges and frontiers. IEEE Transactions on Pat- tern Analysis and Machine Intelligence, 2024. 1
2024
-
[6]
Adversarial objectness gradient attacks in real-time object detection systems
Ka-Ho Chow, Ling Liu, Margaret Loper, Juhyun Bae, and Gursoy. Adversarial objectness gradient attacks in real-time object detection systems. In 2020 Second IEEE Interna- tional Conference on Trust, Privacy and Security in Intel- ligent Systems and Applications (TPS-ISA) , pages 263–272. IEEE, 2020. 2
work page 2020
-
[7]
Histograms of oriented gra- dients for human detection
Navneet Dalal and Bill Triggs. Histograms of oriented gra- dients for human detection. In 2005 IEEE computer soci- ety conference on computer vision and pattern recognition (CVPR’05), pages 886–893. Ieee, 2005. 3
work page 2005
-
[8]
Centernet: Keypoint triplets for object detection
Kaiwen Duan, Song Bai, Lingxi Xie, Honggang Qi, Qing- ming Huang, and Qi Tian. Centernet: Keypoint triplets for object detection. In Proceedings of the IEEE/CVF inter- national conference on computer vision , pages 6569–6578,
Show all 31 references
-
[9]
Digging into self-supervised monocular depth estimation
Cl ´ement Godard, Oisin Mac Aodha, Michael Firman, and Gabriel J Brostow. Digging into self-supervised monocular depth estimation. In Proceedings of the IEEE/CVF inter- national conference on computer vision , pages 3828–3838,
-
[10]
Eval- uating the adversarial robustness of semantic segmentation: Trying harder pays off
Levente Halmosi, B ´alint Mohos, and M ´ark Jelasity. Eval- uating the adversarial robustness of semantic segmentation: Trying harder pays off. In European Conference on Com- puter Vision, pages 1–18. Springer, 2025. 3
2025
-
[11]
Mask r-cnn
Kaiming He, Georgia Gkioxari, Piotr Doll ´ar, and Ross Gir- shick. Mask r-cnn. In Proceedings of the IEEE international conference on computer vision, pages 2961–2969, 2017. 2
2017
-
[12]
Naturalistic physical adversarial patch for object de- tectors
Yu-Chih-Tuan Hu, Bo-Han Kung, Daniel Stanley Tan, and Chen. Naturalistic physical adversarial patch for object de- tectors. In Proceedings of the IEEE/CVF International Con- ference on Computer Vision (ICCV), 2021. 2, 6, 7
2021
-
[13]
Adversarial texture for fooling person detectors in the physical world
Zhanhao Hu, Siyuan Huang, Xiaopei Zhu, Fuchun Sun, Bo Zhang, and Xiaolin Hu. Adversarial texture for fooling person detectors in the physical world. In Proceedings of the IEEE/CVF conference on computer vision and pattern recognition, pages 13307–13316, 2022. 2, 7
2022
-
[14]
T-sea: Transfer-based self-ensemble attack on object detection
Hao Huang, Ziyan Chen, Huanran Chen, Yongtao Wang, and Kevin Zhang. T-sea: Transfer-based self-ensemble attack on object detection. In Proceedings of the IEEE/CVF con- ference on computer vision and pattern recognition , pages 20514–20523, 2023. 2, 6, 7
2023
-
[15]
Adversarial yolo: Defense human detec- tion patch attacks via detecting adversarial patches
Nan Ji, YanFei Feng, Haidong Xie, Xueshuang Xiang, and Naijin Liu. Adversarial yolo: Defense human detec- tion patch attacks via detecting adversarial patches. arXiv preprint arXiv:2103.08860, 2021. 1, 2, 3, 5, 6, 7, 8
2021 arXiv
-
[16]
Pad: Patch-agnostic defense against adversarial patch attacks
Lihua Jing, Rui Wang, Wenqi Ren, Xin Dong, and Cong Zou. Pad: Patch-agnostic defense against adversarial patch attacks. In 2024 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), pages 24472–24481, 2024. 1, 2, 3, 4, 5, 6, 7, 8
2024
-
[17]
Diffender: Diffusion-based ad- versarial defense against patch attacks in the physical world
Caixin Kang, Yinpeng Dong, Zhengyi Wang, Shouwei Ruan, Hang Su, and Xingxing Wei. Diffender: Diffusion-based ad- versarial defense against patch attacks in the physical world. arXiv preprint arXiv:2306.09124, 2023. 1, 2, 3, 5, 6, 7
2023 arXiv
-
[18]
Lavan: Localized and visible adversarial noise
Danny Karmon, Daniel Zoran, and Yoav Goldberg. Lavan: Localized and visible adversarial noise. In International conference on machine learning, pages 2507–2515. PMLR,
-
[19]
A style-based generator architecture for generative adversarial networks
Tero Karras, Samuli Laine, and Timo Aila. A style-based generator architecture for generative adversarial networks. In Proceedings of the IEEE/CVF conference on computer vi- sion and pattern recognition, pages 4401–4410, 2019. 1, 2
2019
-
[20]
Defending physical adversarial attack on object detection via adversar- ial patch-feature energy
Taeheon Kim, Youngjoon Yu, and Yong Man Ro. Defending physical adversarial attack on object detection via adversar- ial patch-feature energy. In Proceedings of the 30th ACM International Conference on Multimedia, pages 1905–1913,
1905
-
[21]
Segment any- thing
Alexander Kirillov, Eric Mintun, Nikhila Ravi, Hanzi Mao, Chloe Rolland, Laura Gustafson, Tete Xiao, Spencer White- head, Alexander C Berg, Wan-Yen Lo, et al. Segment any- thing. In Proceedings of the IEEE/CVF International Con- ference on Computer Vision, pages 4015–4026, 2023. 6
2023
-
[22]
Defense against adversarial attacks using high-level representation guided denoiser
Fangzhou Liao, Ming Liang, Yinpeng Dong, Tianyu Pang, Xiaolin Hu, and Jun Zhu. Defense against adversarial attacks using high-level representation guided denoiser. In Proceed- ings of the IEEE conference on computer vision and pattern recognition, pages 1778–1787, 2018. 2
2018
-
[23]
Diffusion to confusion: Naturalistic ad-
Shuo-Yen Lin, Ernie Chu, Che-Hsien Lin, Jun-Cheng Chen, and Jia-Ching Wang. Diffusion to confusion: Naturalistic ad-
-
[49]
Adversarial examples for se- mantic segmentation and object detection
Cihang Xie, Jianyu Wang, Zhishuai Zhang, Yuyin Zhou, Lingxi Xie, and Alan Yuille. Adversarial examples for se- mantic segmentation and object detection. In Proceedings of the IEEE international conference on computer vision, pages 1369–1378, 2017. 2
2017
-
[50]
Adversarial t-shirt! evading person detectors in a physical world
Kaidi Xu, Gaoyuan Zhang, Sijia Liu, Quanfu Fan, and Sun. Adversarial t-shirt! evading person detectors in a physical world. In European Conference on Computer Vision, pages 665–681. Springer, 2020. 2, 7
2020
-
[51]
Quantization aware attack: Enhancing transferable ad- versarial attacks by model quantization
Yulong Yang, Chenhao Lin, Qian Li, Zhengyu Zhao, Haoran Fan, Dawei Zhou, Nannan Wang, Tongliang Liu, and Chao Shen. Quantization aware attack: Enhancing transferable ad- versarial attacks by model quantization. IEEE Transactions on Information Forensics and Security, 19:3265–3...
2024
-
[52]
Seeing isn’t believing: To- wards more robust adversarial attack against real world ob- ject detectors
Yue Zhao, Hong Zhu, Ruigang Liang, Qintao Shen, Shengzhi Zhang, and Kai Chen. Seeing isn’t believing: To- wards more robust adversarial attack against real world ob- ject detectors. In Proceedings of the 2019 ACM SIGSAC conference on computer and communications security, pages...
2019
-
[53]
Towards large yet imperceptible adversarial image perturbations with perceptual color distance
Zhengyu Zhao, Zhuoran Liu, and Martha Larson. Towards large yet imperceptible adversarial image perturbations with perceptual color distance. In CVPR, 2020. 1
2020
-
[54]
On suc- cess and simplicity: A second look at transferable targeted attacks
Zhengyu Zhao, Zhuoran Liu, and Martha Larson. On suc- cess and simplicity: A second look at transferable targeted attacks. In NeurIPS, 2021. 1
2021
-
[55]
Breaking semantic arti- facts for generalized ai-generated image detection.Advances in Neural Information Processing Systems, 37:59570–59596,
Chende Zheng, Chenhao Lin, Zhengyu Zhao, Hang Wang, Xu Guo, Shuai Liu, and Chao Shen. Breaking semantic arti- facts for generalized ai-generated image detection.Advances in Neural Information Processing Systems, 37:59570–59596,
-
[56]
Physical 3D adversarial attacks against monocular depth estimation in autonomous driv- ing
Junhao Zheng, Chenhao Lin, Jiahao Sun, Zhengyu Zhao, Qian Li, and Chao Shen. Physical 3D adversarial attacks against monocular depth estimation in autonomous driv- ing. In Proceedings of the IEEE/CVF Conference on Com- puter Vision and Pattern Recognition (CVPR), pages 24452– ...
2024
Reviewed August 6, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.