Betreuer/in: Al Sardy

Wireless demand-response communication creates a physical-layer availability risk that cryptographic protection cannot prevent. This thesis asks how strongly a reactive radio-frequency jammer with a replenishing sliding-window airtime budget impairs a smart-grid application in a GridLAB-D–ns-3 co-simulation and how effectively a recursive online exponentially weighted moving average (EWMA) intrusion detector identifies the attack.
The model extends the 73-house IEEE 13-node GridAttackSim scenario with spectrum-level reactive noise, packet- and controller-level tracing, and a centralized telemetry-assisted detector. The four attack configurations vary only the airtime budget. A disjoint training–validation–test workflow fixes the normal profile and the alarm rule before evaluation. The final experiment uses five previously unused 24-hour test seeds and paired baseline–attack runs, so the seed/run pair is the inferential unit.
The impact was threshold-like. Low increased paired target-downlink delay by 16.6 ms; Medium increased it by 55.2 ms. Neither caused final logical loss. High caused 1.73 % paired loss. Severe caused 88.3 % paired loss, 52.5 % attack-only stale proxy-market-ID samples, and 87.7 % missed controller rounds; it also changed market quantities, market price, and target-house load. The frozen λ= 0.4, L = 7, k= 1 detector identified 13.3 % of Low phases and every observed Medium, High, and Severe phase. The selected rule produced two benign alarm episodes across three 24-hour validation runs and none across five held-out clean 24-hour test runs, so its false-alarm tendency remains imprecisely estimated. A post-hoc feature replay showed that distributed target-group PHY-drop telemetry was decisive only for the weak Low detections under the frozen rule; all Medium-to-Severe phases remained detected without that feature.
The findings apply to one-shot UDP/FNCS delivery without end-to-end recovery, the inherited fixed operating day and feeder, and a centralized detector that aggregates distributed endpoint telemetry.
Raum 04.137, Martensstr. 3, Erlangen
oder
Zoom:
https://fau.zoom-x.de/j/68350702053?pwd=UkF3aXY0QUdjeSsyR0tyRWtLQ0hYUT09
Meeting-ID: 683 5070 2053
Kenncode: 647333