AMS home Members Help
Technology Fist Digital Library
Search publications Finder Submit a paper →

← FistXiv: Engineering

This is a preprint. It has been moderated for scope and content but has not been peer reviewed - findings should be treated as preliminary until formally reviewed and published.
Preprint · Open access

Cyberattack Evolution Modeling in Smart Grids: A Hierarchical Temporal Graph Transformer for Detection, Localization, and Severity Estimation

Sahibzada Muhammad Ali*, Zahid Ullah

COMSATS University Islamabad; Politecnico di Milano

Received
1 Oct 2026
Screened
11 Oct 2026
Published
11 Oct 2026
Version history
v1 - original version (11 Oct 2026) · Download v1 (PDF)
The PDF below is the latest version (v1); earlier versions remain on record and can be downloaded above.

Cyberattacks against modern power grids are not purely point anomalies: their observable signatures can be spatially coordinated, persistent over time, partially masked, and heterogeneous in severity. Treating every event as a binary label discards structure that can be useful for localization and operational response. This paper formulates cyberattack evolution as a hierarchical spatiotemporal learning problem and proposes a Causal Hierarchical Temporal Graph Transformer (CHTGT) for joint attack detection, source localization, and severity estimation. The model maps PMU/SCADA telemetry onto a 300-bus electrical graph, performs bus-level attention, aggregates representations by four operating districts, applies causal temporal attention over 12-step windows, and feeds shared representations to detection, localization, and severity heads. A strict information-availability contract separates observable inference inputs from attack metadata used only for supervision and evaluation. The available benchmark contains 604,800 fixed bus--timestamp records, 30,240 attack records, three attack regimes, and 2,016 temporal states. Existing independently recomputed backbone evidence on a 121,200-sample held-out set gives 0.9940 accuracy, 0.8800 positive-class F1, 0.9941 AUROC, 0.9732 AUPRC, and 0.8724 MCC, while source localization reaches 0.509/0.514/0.526 for Top-1/3/5. An associated lightweight model shows severe validation-to-zero-day degradation, motivating explicit attack-evolution evaluation. These results are reported as auditable backbone evidence rather than fabricated CHTGT gains; severity estimation and component-level ablations remain the decisive experiments.

Data availability

Data available on request

Published in

FistXiv: Engineering

Published 11 Oct 2026 · Technology Fist