Multiple teams receive funding to protect energy infrastructure against AI-enabled threats

The Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER) has funded four Sandia National Laboratories-led projects to drive innovation in AI for energy security.

The Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER) has funded four Sandia National Laboratories-led projects to drive innovation in AI for energy security (see below for project names and goals).

Through these projects, Sandia will develop advanced AI technologies that enhance the security, resilience, and trustworthiness of critical energy infrastructure against AI-enabled cyber-physical threats. The goal is to create integrated AI-driven detection, response, and evaluation tools to protect and strengthen the nation’s critical energy systems from evolving adversarial attacks.

“AI-FORTS embodies Sandia’s commitment to advancing resilient and adaptive security for the nation’s critical infrastructure by integrating cutting-edge AI-driven cyber-physical threat detection and explainability,” said Alex Haddad, manager of Sandia’s Grid Security and Communication department.

“By harnessing generative large language models, edge-optimized analytics, and AI-enhanced emulated testbeds, AI-FORTS empowers human decision-makers with actionable insights and confidence metrics. This work enables proactive anticipation and mitigation of evolving risks to the grid’s cybersecurity and operational integrity,” said Haddad.

The award is through CESER’s Artificial Intelligence For Operationally Resilient Technologies and Systems (AI-FORTS) program, whose mission is to “reduce exposure to AI-enabled threats through systematic evaluation and countermeasures, increase AI-enabled defensive capabilities, and ensure that AI used in energy systems is trustworthy, secure, and resilient.”

Sandia works to deliver grid security and modernization through research, development, and evaluation of solutions to maintain operations in a compromised environment. This project leverages previous efforts, including LDRD work funded by the Resilient Energy Systems Mission Campaign’s Vulnerability Toolset research area. For example, the GANDALF team will build on the Communications and Cybersecurity for the Energy Edge (C2E2) work to create a system that uses generative AI and large language models to both detect and locate cyber-physical threats to the electrical grid.  


Sandia-led AI-FORTS Funded Projects

Project NameProject Goal
CyPhyAI
  • Create a cyber-physical AI-driven response capability that analyzes both cyber and physics-based (physical) data, selects and coordinates cyber-physical response, and deploys autonomous and/or recommended response actions.
  • CyPhyAI will radically increase the speed and accuracy needed to combat AI-enabled adversaries and complex cyber-physical attacks.
  • Leveraging AI, CyPhyAI will unveil cyber-physical interdependencies and select-coordinate-deploy cyber-physical responses that effectively counter threats and prevent cascading failures/outages.
CALYPSO
  • Create an end-to-end AI-driven cyber-physical security framework that provides security operators and defenders with actionable insights, confidence metrics, and human-in-the-loop interfaces to detect and explain the root causes of the sophisticated cyber-physical threats and eventually trust the predictions of “black-boxes” AI models.
  • This framework will be optimized to run on edge computing platforms and will be an easy-to-deploy solution for potential customers.
STAISYS
  • Create realistic, scalable test environments to evaluate how AI/ML integrated into critical energy infrastructure perform against cyber threats. By integrating AI technologies into emulated energy systems and simulating adversarial attacks, STAISYS helps understand vulnerabilities and readiness for operational use.
  • This project will develop realistic threat models, AI kill chains, and design statistical evaluations of experiments at scale to quantify impacts and uncertainties of various attack vectors.
GANDALF
  • Design and develop a Generative AI pipeline with Large Language Models for cyber-physical anomaly detection in the power grid to capture rich cross-field structure in the data and text-rich explainability.
  • The team will evaluate the Generative AI’s potential for tabular anomaly detection, its performance in terms of accuracy and speed and it will also develop methods to quantify hallucinations end enhance trust.

August 18, 2026