Pith. sign in

REVIEW 3 major objections 6 minor 37 references

AIDC Microgrid Vulnerability Assessment Under Computing-Power Coordinated Attacks

T0 review · 3 major / 6 minor · reviewed 2026-08-12 · deepseek-v4-flash

Pith's one-line read Coordinated AI-demand and inverter attacks can destabilize AIDC microgrids when either alone cannot

desk verdict Novel AIDC coordinated-attack scenario with a real load-model problem: the fit from harmonic impedance to small-signal transfer function is load-bearing and unvalidated. read the letter →

arxiv 2608.10645 v1 pith:M2D6225I submitted 2026-08-11 eess.SY cs.SY

classification eess.SYcs.SY
keywords AIdatacentermicrogridvulnerabilitycoordinatedcyberattacksmall-signalstabilityimpedancemodelinverterparametertamperingAI-induceddemandmanipulationattackreachabledomain
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper claims that a new class of cyber-physical attack against AI data center (AIDC) microgrids works by combining two individually bounded actions: tampering with inverter control parameters on the renewable side, and using malicious LLM prompts to manipulate AIDC power demand. The central claim is that the two attacks have a cooperative effect, reshaping the coupling between source and load impedances so that the coordinated attack reachable domain crosses the small-signal stability boundary even when each attack alone stays in the stable region. If true, this means attack surface assessments for low-carbon AIDCs must treat computing demand as a dynamic load-side attack vector, not just a passive uncertainty. The paper also claims that the vulnerability is time-dependent and sparse, concentrated in short high-confidence windows that can be identified from long-term operating trajectories, and that within those windows a fixed coordinated attack vector can remain destabilizing under joint uncertainty.

What carries the argument

The central object is the impedance-based loop-gain matrix $L^{(n,m)}(s,t+\tau,a) = Z_{eq}^{(m)}(s,t+\tau)\, \tilde{Y}_{pv}^{(n)}(s,t+\tau,a)$, whose closed-loop eigenvalues are obtained from $\det[I+L(\lambda_i)]=0$. The attack reachable domain (ARD) $D_{t+\tau}^{(n,m)}$ collects the critical closed-loop eigenvalue locations reachable by feasible coordinated attack vectors, and its real-axis projection $P_{t+\tau}^{(n,m)}$ decides attackability via intersection with $(0,\infty)$. The framework also uses an operating-point-dependent fitted impedance model $Z_{dc}(s,t)=Z_{fit}(s,P_{dc}(t),Q_{dc}(t))$ for the AIDC load and an irradiance-parameterized PV admittance $Y_{pv}(s,G_0)$, along with a confidence-weighted attackability score $A_{t+\tau}$ and a vector-effectiveness score $S_{t+\tau}(a)$ that respectively identify when and how the coordinated attack can destabilize the system under joint uncertainty.

What would settle it

Run an electromagnetic-transient simulation of the same PV-BESS-AIDC microgrid with a detailed switched or EMT-level AIDC load model (including UPS and cooling dynamics) and apply the paper's identified coordinated attack vectors inside and outside the reported windows; if no sustained frequency excursion or eigenvalue right-half-plane crossing occurs with the detailed load, the fitted-surrogate premise fails. Alternatively, measure the small-signal impedance of the specific AIDC directly at the reported vulnerable operating points (e.g., via broadband injection at the PCC) and check whether the loop gain predicted instability.

Watch

Extended reading notes

Core claim

The paper establishes that a coordinated attack, combining AI-induced AIDC demand manipulation with inverter control parameter tampering, can drive a low-carbon AIDC microgrid into small-signal instability under conditions where neither attack alone succeeds. The mechanism is impedance interaction: the load-side attack shifts the AIDC operating point and thus its equivalent impedance, while the inverter-side attack changes the source admittance, jointly moving the critical closed-loop eigenvalue of the loop-gain matrix $L^{(n,m)}(s,t+\tau,a)$ into the right-half plane. The paper demonstrates this through attack reachable domain (ARD) analysis at representative operating points, showing that the coordinated ARD expands and crosses the stability boundary, and through a five-day case study where coordinated attacks produce sustained inverter frequency excursions exceeding 20% of nominal and growing VSG rotor angle deviations only inside identified critical windows. The framework further assigns confidence weights to PV forecast-error realizations and AI-induced demand response realizations, defining an uncertainty-aware attack time window via a confidence-weighted attackability score and an uncertainty-aware attack vector that remains effective throughout the window. A real-world university data center harmonic impedance dataset is used to construct an operating-point-dependent impedance surrogate that serves as the load-side small-signal impedance model.

Load-bearing premise

The fitted impedance model built from measured harmonic impedance of a university data center faithfully represents the true small-signal dynamics of the AIDC load for stability analysis; if that surrogate misses real load dynamics, the identified vulnerable windows may not correspond to genuine instability.

Editorial extensions

If this is right

  • If the central claim holds, cybersecurity assessments of AIDC microgrids must treat LLM-service demand manipulation as a first-class attack surface equivalent in importance to electrical-infrastructure access.
  • The time-dependence of vulnerability implies that blanket monitoring is suboptimal; defenders can focus on short, high-confidence vulnerable windows rather than the full operating horizon.
  • The impedance-based screening method provides a direct path from operating-point changes to stability margin erosion, enabling prediction of vulnerability from PMU measurements and load forecasts.
  • The identified fixed coordinated attack vectors that remain effective across uncertainty suggest that a single injection strategy can be reused across plausible future conditions within a window, simplifying attacker planning.
  • The results imply that BESS power-buffering does not by itself protect against stability-driven coordinated attacks, since the attack acts through impedance reshaping rather than direct power imbalance.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • A natural testable extension is to check whether the cooperative effect persists for other load types (e.g., cooling-dominated or UPS-dominated data centers) whose impedance spectra differ from the university center used here, which would clarify how general the mechanism is.
  • The confidence-weighted attackability score measures prevalence, not severity; a defender might combine it with the right-half-plane eigenvalue magnitude to prioritize windows where high-confidence and high-severity coincide.
  • The paper's assumption that PV prediction error and AI-induced demand response are conditionally independent given the BESS operating mode could be relaxed; correlated uncertainty would likely change window boundaries and may make some identified windows spurious.
  • The findings suggest an adversarial 'label-flip'-style inference: if the framework can predict vulnerable windows from public PMU-like measurements and irradiance forecasts, then attackers who can read such data do not need any insider electrical knowledge to time their AI-side prompts.
  • Whether the fitted impedance surrogate captures the real data center's small-signal dynamics (rather than harmonic steady-state behavior) is the paper's load-bearing premise; a mismatch could make the reported instability artifacts of the surrogate rather than of the physical system.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 6 minor

Summary. The paper proposes an uncertainty-aware framework for assessing the vulnerability of a low-carbon AIDC microgrid to a coordinated attack that combines AI-induced AIDC demand manipulation with tampering of PV inverter control parameters. The framework models PV forecast error and demand-response uncertainty through confidence-weighted realizations, maps them to source and load impedances, constructs an attack reachable domain (ARD) of critical closed-loop eigenvalues, and derives confidence-weighted attack time windows and attack vectors. A case study using a university data center harmonic-impedance dataset and a five-day PV trajectory reports that coordinated attacks cross the stability boundary while single-side attacks do not, that vulnerable windows are sparse and time-dependent, and that time-domain simulations show growing oscillations when the attack is launched inside an identified window.

Significance. If the load-modeling premise holds, the paper's contribution is novel and useful: it is the first to formulate the cross-domain coupling between adversarial LLM workload manipulation and inverter parameter tampering as a small-signal stability problem, and it provides a tractable probabilistic screening procedure that identifies sparse high-confidence vulnerable intervals. The workload-to-power conversion chain (Eqs. 19-25), the confidence-weighted attackability score (Eq. 42), and the ARD-based window/vector identification are clearly structured, and the paper includes time-domain confirmation of the instability inside identified windows. The main significance is therefore conditional on the validity of the AIDC impedance surrogate, which is the load-bearing element of the analysis.

major comments (3)
  1. [§IV-A and Eq. (18)] The central result that coordinated attacks cross the stability boundary depends entirely on Z_fit(s, Pdc, Qdc), a surrogate fitted from measured harmonic voltage and current phasors at a university data center PCC. The paper explicitly states that this harmonic impedance is "not directly treated as the small-signal impedance," but no independent validation is provided that the surrogate faithfully represents the incremental terminal dynamics of the AIDC in the frequency band relevant to inverter/VSG modes (roughly 0.1-100 Hz). Harmonic impedance samples at integer multiples of the fundamental do not constrain the fitted transfer function in that band, so poles near the imaginary axis in unsampled bands, and hence the ARD crossing in Fig. 4 and the vulnerable windows in Fig. 6, could be fitting artifacts. This is a load-bearing issue: the time-domain simulation in Fig. 7 uses the same model and therefore does not independently confirm the surrogate. I request a validation study comparing the surrogate with a detailed switched/electromagnetic model of the AIDC including UPS, cooling, and electronic-load dynamics, or with broadband small-signal impedance measurements; absent that, the claim should be substantially weakened.
  2. [§IV-A and Eqs. (27), (40), (42)] The confidence-weighted attackability score A_{t+tau} is the basis for the claimed sparse high-confidence vulnerable windows, but the confidence weight mappings C_dc(·) and c_pv are never specified. The text says the PV forecast error and demand response are zero-mean normal with standard deviations 15% and 5%, respectively, but it does not state how these distributions define c_pv and c_dc, nor whether the weights are normalized densities, quantile-based probabilities, or something else. Since A_{t+tau} is a weighted average over realizations, different reasonable weight mappings will change which windows exceed the threshold α. No sensitivity analysis is reported for the 15%/5% parameters or for the Gaussian assumption. This is load-bearing for the framework's central probabilistic claims, and the manuscript should either specify the mappings explicitly and justify the parameter values, or demonstrate that the identified windows are robust across a plausible range of these choices.
  3. [§III-D and Eq. (40)] The conditional-independence assumption between PV prediction error and AI-induced demand response given the BESS operating mode is stated without support, and the BESS operating mode is not included in the model or case study. The product-form joint weight in Eq. (40) is therefore an unverified structural choice. If the BESS arbitrage or state-of-charge constraints couple PV output and AIDC demand, the independent product can either over- or under-estimate the joint attackability score in a way that affects the identified windows. The authors note that correlated uncertainty can be incorporated, but they do not provide any comparison or bound showing that the independence assumption is not the driver of the high-confidence windows. This issue should be addressed either by adding a correlated-uncertainty case study or by an explicit argument for why BESS decoupling makes the independence assumption conservative.
minor comments (6)
  1. [§II-C] There is a typo in the threat model: "demadn responses" should be "demand responses."
  2. [§III-D] The phrase "Based on the the coordinated attack model" repeats "the" and should be corrected.
  3. [§IV-A] The manuscript refers to "a AIDC microgrid" and "a AIDC node"; since "AIDC" is pronounced as an acronym beginning with a vowel sound, it should be "an AIDC microgrid" and "an AIDC node."
  4. [§IV-A] In the text following Eq. (18), "V oltage" has a stray space and should be "Voltage."
  5. [Fig. 7] The frequency and rotor-angle axes in Fig. 7 are not labeled with units; since the abstract claims "frequency excursions exceeding 20% of the nominal value," the plot needs an explicit y-axis in Hz or per-unit and a clear indication of the nominal value.
  6. [§IV-B3, Table V] The procedure for selecting the window-specific coordinated attack vectors in Table V is not described in enough detail: the number of sampled candidates, the sampling distribution over the attack set Ω_a, and the stopping criterion for retaining a vector should be stated so that the table is reproducible.

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: the vulnerability assessment is a model-based reachability analysis, and the fitted impedance surrogate is an input assumption rather than a fitted prediction.

full rationale

The paper's derivation chain is self-contained in the sense required for a circularity finding. The fitted impedance surrogate Z_fit(s, P_dc, Q_dc) is an input modeling assumption built from measured harmonic phasors [22]; it is not the output that the paper claims to predict. The stability margins, attack reachable domains, and attack time windows are computed by substituting this surrogate and the PV/admittance models into the loop-gain determinant (Eqs. 18, 32, 33), which is a standard model-based reachability computation rather than a reduction of the conclusion to the input. The coordinated ARD comparison in Section IV-B compares attacks over the product feasible set Omega_a; the fact that the coordinated set can cross the stability boundary while axis-restricted sets do not is a non-tautological interaction result, though its validity inherits the surrogate's fidelity. The self-citations [14], [15], [23] attribute the individual tampering attack model, the impedance-estimation assumption, and the ARD concept, but the present paper redefines the ARD in Eq. (37) and computes all eigenvalues and simulations itself; none of these citations is invoked as an external theorem that forces the central claim. The main caveat, whether harmonic impedance is a valid small-signal impedance at control-band frequencies, is a correctness and validity risk rather than circularity, because the fitted model is not fitted to the stability outcome and the time-domain simulation provides an internal consistency check on the same model. Therefore no circular step is exhibited.

Assumptions & free parameters 5 free parameters · 7 assumptions · 0 invented entities

The paper introduces no new physical entities. The 'computing-power coordinated attack' is a scenario combining existing attack types. The main load-bearing elements are the fitted impedance model and the chosen uncertainty distributions, which are free parameters. The attack capabilities and the conditional independence assumption are domain assumptions specific to this study.

free parameters (5)
  • Fitted AIDC impedance model parameters (Z_fit) = not disclosed
    The AIDC load impedance is represented by a model fitted to harmonic impedance measurements from a real university data center [22]. The fitting procedure and parameters are not provided, and the model is used as a small-signal surrogate without validation.
  • PV forecast error standard deviation = 15% of predicted PV output
    Set in Section IV.A based on 'common Gaussian-error approximation'; not estimated from the actual PV dataset.
  • Demand response uncertainty standard deviation = 5% of nominal load variation
    Chosen in Section IV.A; no empirical basis given for this value.
  • Attack parameter bounds = 5%, 5%, 5%, 10%, 10% for k_pv, k_iv, k_pi, J, D_p
    Chosen in Section IV.B.1 as bounded tampering limits; arbitrary.
  • Workload amplification parameters (A_w, r, rho_N, A_b, eta_C, T_a/T_r) = A_w=13.12, r=4-9%, rho_N=5-45%, A_b=1.00-1.50, eta_C=0.40, T_a/T_r=0.75-1.00
    Table IV; A_w from reference [27], others chosen for sensitivity scenarios. These parameters determine the load-side attack intensity.
assumptions (7)
  • standard math Small-signal linearization around equilibrium is valid for stability analysis.
    Used in Section II.A.2 to derive PV admittance; standard for power system small-signal stability.
  • domain assumption The BESS power-buffering partially decouples PV and AIDC load dynamics.
    Section II preamble: 'short-term workload variations in the AIDC are mainly absorbed or balanced through the BESS interface, rather than directly changing the PV operating point.' This enables separate source and load models.
  • domain assumption The AIDC load can be represented by an equivalent impedance (series R-L branch or fitted model).
    Section II.B; the entire stability analysis uses Z_dc(s,t) as the load model. No validation against a detailed data center dynamic model.
  • standard math Closed-loop stability is determined by the loop-gain matrix L = Z_eq * Y_pv via det(I+L)=0.
    Section III.C, Eq. (32)-(33). This is a standard impedance-based small-signal criterion, but it assumes the system can be partitioned at the PCC.
  • ad hoc to paper PV prediction error and AI-induced demand response are conditionally independent given the scheduled BESS operating mode.
    Section III.D: 'In the present implementation, the PV prediction error and AI-induced demand response are treated as conditionally independent... adopted to obtain a tractable confidence-weighted formulation.'
  • domain assumption Forecast errors and demand response uncertainty follow zero-mean Gaussian distributions with specified standard deviations.
    Section IV.A: 'following the common Gaussian-error approximation... PV forecasting error and the demand response uncertainty are modeled as zero-mean normal random variables.'
  • domain assumption Attacker has the stated capabilities (compromised inverter interface, user-level AI access, PMU read access, bounded parameter changes).
    Section II.C and Table I; the threat model defines the attack surfaces but assumes these are achievable.

how reviews work

0 comments
Cite this review

Pith. "Pith review of AIDC Microgrid Vulnerability Assessment Under Computing-Power Coordinated Attacks." pith.science (2026). https://pith.science/paper/M2D6225I

@misc{pith2026260810645,
  author       = {Pith},
  title        = {Pith review of: AIDC Microgrid Vulnerability Assessment Under Computing-Power Coordinated Attacks},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/M2D6225I}},
  note         = {Machine review of arXiv:2608.10645}
}
read the original abstract

The rapid growth of large language model (LLM) services is accelerating the expansion of AI data centers (AIDCs), intensifying concerns over power system resource adequacy and rising carbon emissions. The integration of renewable energy provides a pathway toward addressing these pressures, but it also introduces new cross-domain stability challenges to low-carbon AIDCs. For example, variability in renewable generation affects reliability on the supply side, whereas fluctuations in AIDC workloads affect reliability on the demand side, jointly creating interconnected stability risks in AIDC microgrids. To address this problem, this paper is the first to explore computing-power coordinated attacks against low-carbon AIDCs. First, we propose an uncertainty-aware AIDC microgrid vulnerability assessment framework to capture two interacting attack surfaces: inverter control parameter tampering attacks, and AI-induced demand manipulation attacks. Then, accounting for renewable-side forecast uncertainty and AIDC-side demand response uncertainty, we introduce confidence-weighted realizations and construct a long-term attack reachable domain analysis. Furthermore, an impedance-based screening method is utilised to map generation and load variations to erosion of stability margin, thereby identifying vulnerable attack time windows and attack vectors. In addition, case studies show that computing-power coordinated attacks induce sustained inverter frequency excursions exceeding 20% of the nominal value and reach instability conditions unattainable by single attacks. The results also demonstrate that the proposed framework can extract sparse, high-confidence vulnerable periods from long-term operating trajectories.

Figures

Figures reproduced from arXiv: 2608.10645 by the authors.

Figure 1
Figure 1. Architecture of the low-carbon AIDC microgrid [PITH_FULL_IMAGE:figures/full_fig_p002_1.png] view at source ↗
Figure 2
Figure 2. Uncertainty-aware AIDC microgrid vulnerability assessment framework under computing-power coordinated attacks. [PITH_FULL_IMAGE:figures/full_fig_p004_2.png] view at source ↗
Figure 3
Figure 3. Measured harmonic impedance characteristics of a real-world univer [PITH_FULL_IMAGE:figures/full_fig_p008_3.png] view at source ↗
Figures from the paper (3 more)
Figure 4
Figure 4. Figure 4: Attack reachable domains of oscillatory modes under three attack [PITH_FULL_IMAGE:figures/full_fig_p008_4.png]
Figure 6
Figure 6. Figure 6: Five-day uncertainty-aware vulnerability assessment under coordinated attacks. [PITH_FULL_IMAGE:figures/full_fig_p009_6.png]
Figure 7
Figure 7. Figure 7: The impacts of coordinated attacks under different time windows: (a) [PITH_FULL_IMAGE:figures/full_fig_p009_7.png]

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

37 extracted references · 31 canonical work pages

  1. [1]

    Energy and AI,

    International Energy Agency, “Energy and AI,” International Energy Agency, Paris, France, Tech. Rep., Apr. 2025

  2. [2]

    Powering Intelligence: Updated U.S. Data Center Scenarios,

    Electric Power Research Institute, “Powering Intelligence: Updated U.S. Data Center Scenarios,” Electric Power Research Institute, Palo Alto, CA, USA, Tech. Rep., Feb. 2026

  3. [3]

    Implementation opinions on deepening the “east data west computing

    National Development and Reform Commission, “Implementation opinions on deepening the “east data west computing” project and accelerating the construction of an integrated national computing network,” Dec. 2023. [Online]. Available: https://www.ndrc.gov.cn/ xxgk/zcfb/tz/202312/t20231229 1363000.html

  4. [4]

    Commission Delegated Regulation (EU) 2024/1364 of 14 March 2024 on the first phase of the establishment of a common Union rating scheme for data centres,

    European Commission, “Commission Delegated Regulation (EU) 2024/1364 of 14 March 2024 on the first phase of the establishment of a common Union rating scheme for data centres,” Mar

  5. [5]

    Ai data centres as grid-interactive assets,

    P. Colangelo, A. K. Coskun, J. Megrue, C. Roberts, S. Sengupta, V . Sivaram, E. Tiao, A. Vijaykar, C. Williams, D. C. Wilsonet al., “Ai data centres as grid-interactive assets,”Nature Energy, vol. 11, no. 2, pp. 254–261, 2026

  6. [6]

    Grid frequency stability support potential of data center: A quantitative assessment of flexibility,

    P. Ren, W. Sun, Y . Wang, and G. Harrison, “Grid frequency stability support potential of data center: A quantitative assessment of flexibility,” IEEE Transactions on Industry Applications, 2026

  7. [7]

    Sponge examples: Energy-latency attacks on neural networks,

    I. Shumailov, Y . Zhao, D. Bates, N. Papernot, R. Mullins, and R. An- derson, “Sponge examples: Energy-latency attacks on neural networks,” in2021 IEEE European symposium on security and privacy (EuroS&P). IEEE, 2021, pp. 212–231

  8. [8]

    Resource Consumption Threats in Large Language Models

    Y . Zhang, X. Wang, Z. Chen, W. Wang, Z. Zhang, Z. Gong, Z. Zhou, K. Wang, L. Sun, Y . Liuet al., “Resource consumption threats in large language models,”arXiv preprint arXiv:2603.16068, 2026

Show all 37 references
  1. [9]

    Analysis on data center power supply system based on multiple renew- able power configurations and multi-objective optimization,

    W. He, Q. Xu, S. Liu, T. Wang, F. Wang, X. Wu, Y . Wang, and H. Li, “Analysis on data center power supply system based on multiple renew- able power configurations and multi-objective optimization,”Renewable Energy, vol. 222, p. 119865, 2024

  2. [10]

    Dynamic modeling of a data center for power system stability studies,

    P. P. Gyang, P. Chakraborty, L. Meegahapola, and X. Yu, “Dynamic modeling of a data center for power system stability studies,”IEEE Transactions on Power Systems, 2025

  3. [11]

    Data center model for transient stability analysis of power systems,

    A. Jimenez-Ruiz and F. Milano, “Data center model for transient stability analysis of power systems,”arXiv preprint arXiv:2505.16575, 2025

  4. [12]

    Destabilizing attack and robust defense for inverter-based microgrids by adversarial deep reinforcement learning,

    Y . Wang and B. C. Pal, “Destabilizing attack and robust defense for inverter-based microgrids by adversarial deep reinforcement learning,” IEEE Transactions on Smart Grid, vol. 14, no. 6, pp. 4839–4850, 2023

  5. [13]

    Fostering trust in smart inverters: A framework for firmware update management and tracking in vpp context,

    T. Dayaratne, C. Rudolph, T. Shirley, S. Levi, and D. Shirley, “Fostering trust in smart inverters: A framework for firmware update management and tracking in vpp context,”IEEE Transactions on Smart Grid, 2025

  6. [14]

    Exploring smart grid vulnerability against intelligent inverter parameter tampering attack,

    Z. Yu, M. Liu, and M. Sun, “Exploring smart grid vulnerability against intelligent inverter parameter tampering attack,”IEEE Transactions on Smart Grid, vol. 16, no. 6, pp. 5541–5555, 2025

  7. [15]

    Admittance-guided inverter dispatch command manipulation attack: A grid stability-oriented approach,

    H. Zhen, Z. Yu, X. Xiang, M. Sun, and W. Li, “Admittance-guided inverter dispatch command manipulation attack: A grid stability-oriented approach,”arXiv preprint arXiv:2605.14509, 2026

  8. [16]

    Cyberattack on phase-locked loops in inverter-based energy resources,

    A. Bamigbade, Y . Dvorkin, and R. Karri, “Cyberattack on phase-locked loops in inverter-based energy resources,”IEEE Transactions on Smart Grid, vol. 15, no. 1, pp. 821–833, 2023

  9. [17]

    Design and defense of modal resonance-oriented cyber-attack against wide-area damping control,

    Z. Wang and S. Bu, “Design and defense of modal resonance-oriented cyber-attack against wide-area damping control,”IEEE Transactions on Smart Grid, vol. 15, no. 2, pp. 2164–2178, 2023

  10. [18]

    Experimental cybersecurity evaluation of distributed solar inverters: Vulnerabilities and impacts on the australian grid,

    A. S. Musleh, J. Ahmed, N. Ahmed, H. Xu, G. Chen, S. Kerr, and S. Jha, “Experimental cybersecurity evaluation of distributed solar inverters: Vulnerabilities and impacts on the australian grid,”IEEE Transactions on Smart Grid, 2024

  11. [19]

    Assessment of cyber- physical inverter-based microgrid control performance under communi- cation delay and cyber-attacks,

    O. Ali, T.-L. Nguyen, and O. A. Mohammed, “Assessment of cyber- physical inverter-based microgrid control performance under communi- cation delay and cyber-attacks,”Applied Sciences, vol. 14, no. 3, p. 997, 2024

  12. [20]

    Exploiting the inherent cyber resilience of inverter- dominated microgrids against pll attack,

    A. Kontou, M. Syed, A. Paspatis, Z. Feng, C. Konstantinou, and N. Hatziargyriou, “Exploiting the inherent cyber resilience of inverter- dominated microgrids against pll attack,”IEEE Transactions on Indus- trial Electronics, 2025

  13. [21]

    Analyzing the pn junction impedance of crystalline silicon solar cells across varied illumination and temperature conditions,

    D. A. van Nijen, S. Naoom, M. Muttillo, P. Procel, M. Zeman, O. Is- abella, and P. Manganiello, “Analyzing the pn junction impedance of crystalline silicon solar cells across varied illumination and temperature conditions,”Solar Energy Materials and Solar Cells, vol. 279, p. 1...

  14. [22]

    Garrido-Zafra, R

    J. Garrido-Zafra, R. D. Rodriguez-Cantalejo, A. G. de Castro, and A. Moreno-Mu ˜noz. Three-Phase Power System Harmonic Dataset from a University Data Center. [Online]. Available: https://github.com/ joaquinjgz/Dataset university data center

  15. [23]

    Quantifying cyber- vulnerability in power electronics systems via an impedance-based attack reachable domain,

    H. Zhen, Z. Yu, X. Xiang, W. Li, and M. Sun, “Quantifying cyber- vulnerability in power electronics systems via an impedance-based attack reachable domain,”IEEE Transactions on Power Electronics, pp. 1–6, 2026

  16. [24]

    Analysis of{Large-Scale}{Multi-Tenant}{GPU}clusters for{DNN}training workloads,

    M. Jeon, S. Venkataraman, A. Phanishayee, J. Qian, W. Xiao, and F. Yang, “Analysis of{Large-Scale}{Multi-Tenant}{GPU}clusters for{DNN}training workloads,” in2019 USENIX Annual Technical Conference (USENIX ATC 19), 2019, pp. 947–960

  17. [25]

    Burstgpt: A real-world workload dataset to optimize llm serving systems,

    Y . Wang, Y . Chen, Z. Li, X. Kang, Y . Fang, Y . Zhou, Y . Zheng, Z. Tang, X. He, R. Guoet al., “Burstgpt: A real-world workload dataset to optimize llm serving systems,” inProceedings of the 31st ACM SIGKDD Conference on Knowledge Discovery and Data Mining V . 2, 2025, pp. 5831–5841

  18. [26]

    Taming{Throughput-Latency}tradeoff in{LLM}inference with{Sarathi-Serve},

    A. Agrawal, N. Kedia, A. Panwar, J. Mohan, N. Kwatra, B. Gulavani, A. Tumanov, and R. Ramjee, “Taming{Throughput-Latency}tradeoff in{LLM}inference with{Sarathi-Serve},” in18th USENIX symposium on operating systems design and implementation (OSDI 24), 2024, pp. 117–134

  19. [27]

    Inference cost attacks for retrieval-augmented large language models,

    C. Liu, L. Ning, Y . Ding, and W. Fan, “Inference cost attacks for retrieval-augmented large language models,” inProceedings of the ACM Web Conference 2026, 2026, pp. 7564–7575

  20. [28]

    An engorgio prompt makes large language model babble on,

    J. Dong, Z. Zhang, Q. Zhang, T. Zhang, H. Wang, H. Li, Q. Li, C. Zhang, K. Xu, and H. Qiu, “An engorgio prompt makes large language model babble on,” inInternational Conference on Learning Representations, vol. 2025, 2025, pp. 67 280–67 307

  21. [29]

    Power attack: An increasing threat to data centers

    Z. Xu, H. Wang, Z. Xu, and X. Wang, “Power attack: An increasing threat to data centers.” inNDSS, 2014

  22. [30]

    Rethinking latency denial-of-service: Attacking the llm serving framework, not the model,

    T. Wang, H. Fan, Y . Shu, P. Cheng, and C. Wang, “Rethinking latency denial-of-service: Attacking the llm serving framework, not the model,” arXiv preprint arXiv:2602.07878, 2026

  23. [31]

    Autonomy comes with costs: Detecting denial-of-service vulnerabilities caused by resource abusing in llm-based agents,

    J. Luo, J. Dai, F. Liu, S. Peng, Y . Shi, T. Bu, G. Hong, X. Pan, and Y . Zhang, “Autonomy comes with costs: Detecting denial-of-service vulnerabilities caused by resource abusing in llm-based agents,” in35th USENIX Security Symposium (USENIX Security 26), 2026

  24. [32]

    Beyond max tokens: Stealthy resource amplification via tool calling chains in llm agents,

    K. Zhou, Y . Zheng, Y . He, M. Xue, X. Gong, Y . Wang, X. Zhang, and K.-Y . Lam, “Beyond max tokens: Stealthy resource amplification via tool calling chains in llm agents,”arXiv preprint arXiv:2601.10955, 2026

  25. [33]

    Energy- latency attacks via sponge poisoning,

    A. E. Cin `a, A. Demontis, B. Biggio, F. Roli, and M. Pelillo, “Energy- latency attacks via sponge poisoning,”Information Sciences, vol. 702, p. 121905, 2025

  26. [34]

    {ServerlessLLM}:{Low-Latency}serverless inference for large language models,

    Y . Fu, L. Xue, Y . Huang, A.-O. Brabete, D. Ustiugov, Y . Patel, and L. Mai, “{ServerlessLLM}:{Low-Latency}serverless inference for large language models,” in18th USENIX Symposium on Operating Systems Design and Implementation (OSDI 24), 2024, pp. 135–153

  27. [35]

    Modeling forecast errors for microgrid operation using gaussian process regression,

    Y . Yoo and S. Jung, “Modeling forecast errors for microgrid operation using gaussian process regression,”Scientific Reports, vol. 14, no. 1, p. 2166, 2024

  28. [36]

    Photovoltaic data acquisition (pvdaq) public datasets,

    C. Deline, K. Perry, M. Deceglie, M. Muller, W. Sekulic, and D. Jordan, “Photovoltaic data acquisition (pvdaq) public datasets,” Open Energy Data Initiative (OEDI), NREL, https://doi.org/10.25984/1846021, 2021, accessed: 2026-07-08. [Online]. Available: https://data.openei.org...

  29. [2024]

    Available: https://eur-lex.europa.eu/legal-content/EN/ TXT/?uri=OJ:L 202401364

    [Online]. Available: https://eur-lex.europa.eu/legal-content/EN/ TXT/?uri=OJ:L 202401364

Pith tools

Reviewed August 12, 2026 · model on record in the stance chip above.