Sahibzada Muhammad Ali*, Zahid Ullah
COMSATS University Islamabad; Politecnico di Milano
Cyberattacks against modern power grids are not purely point anomalies: their observable signatures can be spatially coordinated, persistent over time, partially masked, and heterogeneous in severity. Treating every event as a binary label discards structure that can be useful for localization and operational response. This paper formulates cyberattack evolution as a hierarchical spatiotemporal learning problem and proposes a Causal Hierarchical Temporal Graph Transformer (CHTGT) for joint attack detection, source localization, and severity estimation. The model maps PMU/SCADA telemetry onto a 300-bus electrical graph, performs bus-level attention, aggregates representations by four operating districts, applies causal temporal attention over 12-step windows, and feeds shared representations to detection, localization, and severity heads. A strict information-availability contract separates observable inference inputs from attack metadata used only for supervision and evaluation. The available benchmark contains 604,800 fixed bus--timestamp records, 30,240 attack records, three attack regimes, and 2,016 temporal states. Existing independently recomputed backbone evidence on a 121,200-sample held-out set gives 0.9940 accuracy, 0.8800 positive-class F1, 0.9941 AUROC, 0.9732 AUPRC, and 0.8724 MCC, while source localization reaches 0.509/0.514/0.526 for Top-1/3/5. An associated lightweight model shows severe validation-to-zero-day degradation, motivating explicit attack-evolution evaluation. These results are reported as auditable backbone evidence rather than fabricated CHTGT gains; severity estimation and component-level ablations remain the decisive experiments.
Data available on request
FistXiv: Engineering
Published 11 Oct 2026 · Technology Fist