<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "JATS-journalpublishing1-3.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" dtd-version="1.3" article-type="preprint" xml:lang="en">
<front>
<journal-meta>
<journal-id journal-id-type="publisher">fistxiv-engineering</journal-id>
<journal-title-group>
<journal-title>FistXiv: Engineering</journal-title>
</journal-title-group>
<publisher>
<publisher-name>Technology Fist</publisher-name>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">fistxiv-engineering-pap-002</article-id>
<title-group>
<article-title>Cyberattack Evolution Modeling in Smart Grids: A Hierarchical Temporal Graph Transformer for Detection, Localization, and Severity Estimation</article-title>
</title-group>
<contrib-group>
<contrib contrib-type="author" corresp="yes">
<name>
<surname>Ali</surname>
<given-names>Sahibzada Muhammad</given-names>
</name>
<xref ref-type="aff" rid="aff1"/>
<email>hallianali@cuiatd.edu.pk</email>
</contrib>
<contrib contrib-type="author">
<name>
<surname>Ullah</surname>
<given-names>Zahid</given-names>
</name>
<xref ref-type="aff" rid="aff2"/>
</contrib>
<aff id="aff1">COMSATS University Islamabad</aff>
<aff id="aff2">Politecnico di Milano</aff>
</contrib-group>
<history>
<date date-type="received">
<day>01</day><month>10</month><year>2026</year>
</date>
<date date-type="accepted">
<day>11</day><month>10</month><year>2026</year>
</date>
</history>
<pub-date date-type="pub" publication-format="electronic">
<day>11</day><month>10</month><year>2026</year>
</pub-date>
<permissions>
<copyright-statement>© 2026 The Authors. Published by Technology Fist.</copyright-statement>
<copyright-year>2026</copyright-year>
<license license-type="open-access" xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>Creative Commons Attribution 4.0 (CC BY)</license-p>
</license>
</permissions>
<abstract>
<p>Cyberattacks against modern power grids are not purely point anomalies: their observable signatures can be spatially coordinated, persistent over time, partially masked, and heterogeneous in severity. Treating every event as a binary label discards structure that can be useful for localization and operational response. This paper formulates cyberattack evolution as a hierarchical spatiotemporal learning problem and proposes a Causal Hierarchical Temporal Graph Transformer (CHTGT) for joint attack detection, source localization, and severity estimation. The model maps PMU/SCADA telemetry onto a 300-bus electrical graph, performs bus-level attention, aggregates representations by four operating districts, applies causal temporal attention over 12-step windows, and feeds shared representations to detection, localization, and severity heads. A strict information-availability contract separates observable inference inputs from attack metadata used only for supervision and evaluation. The available benchmark contains 604,800 fixed bus--timestamp records, 30,240 attack records, three attack regimes, and 2,016 temporal states. Existing independently recomputed backbone evidence on a 121,200-sample held-out set gives 0.9940 accuracy, 0.8800 positive-class F1, 0.9941 AUROC, 0.9732 AUPRC, and 0.8724 MCC, while source localization reaches 0.509/0.514/0.526 for Top-1/3/5. An associated lightweight model shows severe validation-to-zero-day degradation, motivating explicit attack-evolution evaluation. These results are reported as auditable backbone evidence rather than fabricated CHTGT gains; severity estimation and component-level ablations remain the decisive experiments.</p>
</abstract>
</article-meta>
</front>
<back>
<notes notes-type="data-availability">
<title>Data availability</title>
<p>Data available on request</p>
</notes>
</back>
</article>
